Challenges of Defending Attack Surfaces with IONIX’s Marc Gaffan
After raising an additional $42 million in funding, IONIX CEO Marc Gaffan explains why defending attack surfaces has become more challenging than ever for understaffed cybersecurity teams.
Transcript
This is Techron tv. Hey guys, thanks for the throw. We're here with Mark Gaffen, who is CEO for Iion, and they just picked up $42 million to help us better protect our attack services.
And he can explain why we need that and maybe what is going on with our attack services 'cause they seem to be expanding exponentially. Mark, welcome to the show. Thanks, Mike.
Good morning. Great to be on the show. Well, I don't think a lot of people know much about your company, but why don't we dive in with the problem you're trying to solve for us, because, well, we've been trying to defend these attack services for a while.
So what's different? So what's really changed over the last, I would say five or 10 years, but it's really gotten worse recently, are three things across our practice that are changing so quickly. The, the first thing is just the amount of new assets that are, that organizations are spinning up on an ongoing basis.
Research is showing that on a monthly basis, there's the fluctuation of more than 5% across the assets of the attack surface of an organization. Compound that annually you're getting into the 50, 60, 70% growth, um, of the attack surface. The second thing of the number of changes that we're making across the attack surface, we're changing things.
We changing software, we're changing configurations, um, huge amount of change. And the third is the attack landscape is changing, meaning more vulnerabilities are being disclosed more. Um, the bad guys are coming up with new techniques in order to, uh, compromise our, uh, our environments.
And when you take those three change vectors essentially, and you combine them together, you get a very chaotic attack surface management, uh, or a attack surface problem. What Iion helps companies do essentially is manage their exposure across their very, very hard to manage, um, attack surface, specifically the external attack, which are the, all the internet facing assets that an organization has, which are the prime target for an attacker to go after. Why don't we know more about these platforms as they get attached to the internet?
It would seem logical that if I was working for a company that I'm gonna connect something to the internet. I might tell somebody in cybersecurity, but apparently not. So what's going on?
So in a perfect world, yes, everyone should know about you connecting something to the internet or you spinning up a new piece of infrastructure. Um, spoiler, the world's not perfect. Um, and what we're seeing today, first of all, teams are moving very, very, very quickly.
Um, not only are the teams moving quickly, but not all my infrastructure actually is owned and controlled by me. So I may, uh, contract a, uh, a tiny vendor that's helping me spin up a bunch of landing pages for my marketing organization, and they will spin up, you know, the $10,000 project. They're spinning up a few landing pages, they're collecting leads for me, but I've also given them access to my CRM, so I've given them access to a crown jewel of mine, or I've done a $25 million project with a massive vendor that's building a, you know, huge piece of infrastructure for me.
Both of those are in, are assets that belong to me. I have my ip, they have my brand there, I have my data there, but they're not managed by me. And therefore it becomes more difficult to keep tabs on, um, on your attack surface.
What's also made the problem even worse is a lot of our attack surface is, is by definition not even owned by us. So we essentially are reliant on a very big, what we call digital supply chain, which are all the services and systems that our systems and our vendor systems rely on. Cloud infrastructure, web infrastructure, DNS infrastructure from an attacker perspective, they actually don't care if they can break into a piece of infrastructure and then figure out, hey, through this piece of infrastructure, I can let, then I can now attack a certain, uh, target.
They're going to do that. Which means that we're essentially assuming some of the liability or the attack surface challenges that we have due to the fact that we were so connected today. Ultimately, how often are we changing these platforms?
And I asked the question because it wasn't too long ago where, you know, somebody would set up something on the edge and maybe didn't touch it for three or four years. How frequently are these platforms now being updated? Very, very, uh, frequently.
There's, there's a couple of things that are driving the change. Cloud has changed the speed. Everything is today by code.
So it's infrastructure by code and configuration by code. You basically have code that's doing all this. So code is spinning up more and more assets on an ongoing basis.
If you want to change the code, you're spinning up an asset now in a different way. So that asset yesterday was spun up in a certain way. It's tomorrow spun up in a different way with a different configuration someone may introduce, have introduced an issue to the way they, they, they, they configured the script that essentially bolds that certain asset.
That's why so much change is happening. Um, and where it's coming to, um, to hurt us essentially is the time dimension. Once upon a time we said we, you know, let's check something every, every quarter, every quarter we go in, we'll do a scan, or maybe we'll do it every six months or every year we'll kind of do a, you know, like an inventory check in our, in our, in our, in our grocery store.
Um, it's just not good enough. You've gotta do it all automatically today and on an ongoing basis because the changes are so frequent that the exposure that's created, um, the more it lingers out there, the more likelihood it, um, you ought to be breached. What ultimately differentiates one platform for tracking down what the scope of our attack surface is versus another, because, uh, as we stated at the top of the show, people have been at this for a while.
So what makes it different? There's, there's some really good reasons why we've been told that, that, you know, customers have chosen us. Um, some of the biggest considerations for customers are, one, how the attack surface is presented.
Can you present it to me in a way that I can consume it from an organizational perspective effectively? And, uh, what they typically want is you to take your attack surface and to divide it into three areas, the assets that are owed and controlled by you, which is really what your, it is responsible and is really in the sphere of, you know, your sphere of influence. Second is what do I, what do my vendors own?
Because if I have an issue there, if you detect an issue there, I know that I need to contact my vendors. And third is my digital supply chain. Having that attack surface divided into three areas is key for customers.
The second thing that's key for them is that they, they want solutions to be very, it's in we call, um, they don't want them to create a lot of noise, meaning, um, they need to be very accurate in detecting all the, all the assets that belong to you. So very, very low level false positives. And also when they report on a problem, that problem should rarely be exploitable or really be significant because no one is fixing everything anymore.
It's impossible to fix every single misconfiguration or every single update, every single piece of software because they theoretical vulnerability has been introduced or been disclosed. Organizations are looking to get the most or, um, with the resources that they have and therefore prioritizing effectively of what's really urgent and important are some key criteria for, uh, for selection. When they look at solutions, um, like we provide, Is the nature of the game changing fundamentally?
And I asked the question because it seems like not only is the attack surface expanding, but the attacks themselves are increasing in frequency and sophistication. And it's almost like this fight needs to occur in near real time. And do we understand that and appreciate that?
So I think that your observation that this needs to happen in near re near real time is, is spot on. Um, the, the, the attackers, they're using code, they're using ai, they're using, um, infrastructure to recon environment. So whatever we are, we are doing to, um, to detect the issues at the speed we're doing it is because it's a, it's a, it's an alarm race.
Um, I also say that the, the geopolitical world in which we live in today in which you have, uh, so much cyber warfare going on creates a, a village of technology into the, um, the hacker ecosystem. Think about it. I am a nation state attacker.
I go, you know, I work for a certain government, I go and I produce really good tools. A those tools get reverse engineered by hacker. When they do make their way onto the market, um, people are moving around.
They take that expertise and, and, and knowhow that they've learned in certain areas, and they, they take that to the private market. So there's a lot of research being, uh, spent or dollars being spent into offensive fiber, which essentially leaks essentially, you know, outside into the, you know, the, the, the, uh, the non nation state world, which makes it very difficult for, um, organizations that are not necessarily threatened by nation, by nation states to also have to deal with these type of high-end threats. What's your best advice to folks then?
I feel like a lot of them are, shall we say, um, casting about for what to do next. I don't think that they understand, per se, um, how to get from where they are to where they need to be because, well, it requires funding, it requires different skill sets. I mean, are we kinda caught in vice here in some respects?
So I think that the, the key here is to be proactive and, um, not wait to get hit of course, but to be proactive on trying to identify where your potential exposures are. Um, there's technology around that can help organizations do it. There checklists around on the internet that they can, you know, they can find on how to compare between different vendors.
Um, there's a lot of efficiency that can be introduced from using tools, um, like iion in terms of helping organizations reduce their exposure on multiple fronts. There's a huge amount of hyper automation that's been introduced into these tools. So once, so you, today you have organizations that have got people that are doing some of this themselves.
You can literally take those people and, um, give them better tools to do what they're doing, which means you're freeing up time for them to do other things. Uh, there's tools that today that you're using that I would say are, are more older school tools that test things periodically in a very limited scope. You can do away with those tools and you can replace them with tools that are constantly testing unbounded or un scope, meaning they're, they're really looking everywhere for the assets that could potentially belong to an organization.
So there's a generation shift that happening here, um, that can, you know, uh, can help organizations fund and, um, determine where they want to go from a, uh, from a product perspective. And we've been doing asset management forever in a day. So is that function now kind of converging with cybersecurity as part of this whole, you know, IT ops meets SecOps kinda movement that we're seeing?
So the asset management to, uh, uh, space is definitely adjacent to the, the, you know, the world in which we play. Um, the problem is that asset management typically a, is driven off the, the processes that an organization has. So you use a, what's known as A-C-M-D-B or an outward and asset inventory tool, um, they're typically accurate to a certain level, again, depending on how fast or how, how fast there are to get updated by the people that are changing the infrastructure where it's not giving you enough coverage are the assets that don't belong to you, but they are part of your infrastructure.
So it's kind of outta your scope and you don't have the capabilities even to to, to, to inventory them. But from a data perspective, your data's resigning in those assets that you, you own them, but you don't control them and therefore your CMDB is not gonna have any, you know, any, uh, um, any record of them, especially as we talk about third party services and asset management is all about assets today. A lot of where, or the of the, the assets that we have are actually services, the third party services or services that someone else has spun up.
So it's not even an asset that you need to track, it's a service and that falls into a completely different, um, you know, wheelhouse in terms of responsibilities. You need something that looks at everything. You've got assets and services, um, in a single, single pane of glass.
And you mentioned ai, of course, the bad guys are using ai, but well, AI kind of save us from ourselves here. Can we apply AI to better manage all our various platforms? We definitely can.
We use AI in our, in our solution to essentially help us find the asset that belong to an organization. Um, if you think about it, the, the finding the assets that belong to an organization from the outside, like an attacker would, like a team of attackers would, takes a lot of time and resources. And often you see, you see a resource or you see a website or you see a thibo or you see another asset that looks similar to an asset that belongs to the organization, but it's actually not.
And we use AI today to make that determination. We look at hundreds of different characteristics of assets, where they're hosted, what their domains are, where, what's in their certificates, what's in their, who is records or their DNS data. We look at hundreds of different parameters, and then all that gets fed into a machine learning algorithm that makes a binary determination of does that asset belong to that organization or not?
With very, very high levels of, you know, of accuracy, obviously, you know, a model that are getting trained and optimized all the time, but that's where we, we are using machine learning to, to, to essentially, um, very accurately hone in on the tax surface of an organization. So what's that one thing that you see organizations doing today that just makes you shake your head a little bit and goes, folks, we need to be better than this. Um, doing things not continuously, meaning doing things that are, you know, once a quarter, once every six months, once a year is just not gonna cut it anymore.
And the other thing is, um, projects that are scoped, meaning, help me find the issues here, uh, won't last anymore because it's the problems, it's the, it's the, it's the unknowns, it's, it's what about all the other assets that we don't know about. Um, that's what is driving, uh, organizations to, to fix solutions that are continuous and unbound in their scope, um, of operation. All right folks, you heard it here.
No matter how fast the fight gets, you cannot defend what you don't know about in the first place. So ultimately, that's the first step to any cybersecurity strategy. Hey Mark, thanks for being on the show.
Great, great. Very nice being here. Thank you.
And back to you guys in the studio.