CISOs Board Conversations – Mariano Nunez, Onapsis
Mariano Nunez, CEO of enterprise application security company Onapsis joins Mike Rothman to discuss how CISO’s need to have more business-oriented discussions with the board, given the high profile nature of data breaches, emerging regulations, and increasingly targeted enterprise applications.
Transcript
This is texturing TV. Hi everybody, Mike Rothman here general manager of tech strong research for another techstrom TV interview. I'm ecstatic to be joined by Mariano Nunes.
Who is CEO and founder. I didn't found right you found it of allapsis. All right, so he'll talk a little bit about the company a second and really what we're gonna focus on is the opportunity that Cisco's have moving forward to get bored level visibility what they should do with it, right?
You know, we've been talking for years about, you know, kind of getting in front and and really trying to talk about why Securities important at the board level and now there are a couple of compliance drivers and a number of other initiatives that really are starting to get these folks in front of them. But before we jump into it my Rihanna water get introduce yourself tell us a little bit about this and just your background a bit. That would be great.
Absolutely Monica. It's a pleasure to be here. Thanks for having me.
I'm one of the founders of announces really they found in team is all think about us cyber security EXP. We were not experts in business applications or sap Oracle or a Europe apps and really we funded announces upon this covering that and a little bit of an irony was going on there in the industry where everyone was protecting everything but the crown jewels right a lot of the largest companies in the planet when we found that the business but over a decade ago, they were doing endpoint security. They were doing work on a network security infrastructure that we're doing database security but no one was really looking at the crown jewels like the Erp Financial applications your HR Solutions really what runs the most clinical processes and hosts and most critical data of Enterprise.
And in many cases actually many ways. It supports really the digital economy. When you think about the amount of Revenue and critical process run by these applications globally we talk about a little bit of a kind of microeconomic impacts and really balance of these of these applications my background, so I was born and raising Argentina in Buenos Aires.
I believe in here in Boston, Massachusetts for the last 10 years. That's where announces get. Twitter we have operations across Argentina and office in Germany as well.
What about 300 employees worldwide and really again our mission is to protect this business critical apps for the largest companies in the planet. So we have many of the fortune 10 for to 100 close to 30% of the force 100 or our customers today and really our focuses ensuring that the same way they're protecting all their other applications infrastructure, like Network. They can integrate their business critical apps into their security and compliance programs on the way from a from a vulnerability management and thread detection perspective from a secure devops perspective as well as like everything that's like moving these applications to the cloud and transforming them.
They can accelerate those initiates and do that securely. Yeah, and you know, I've been advising sees those for Golden past 25 years or so, right and it's really been an interesting and transition as it was very tactical and you know again just you know, we got to protect ourselves from the internet. And now it's really kind of transition much more to a business Centric role, right?
It's not about you know, kind of how many phones did we patch over the last, you know month or or how many endpoint attacks have we blocked or fishing messages? Have we you know kind of insured didn't get to the mailboxes right? See those are increasingly being asked to get in front of the board talk about business Concepts right talk about risk to the business.
I didn't get how do you kind of work? I mean, I know you're sitting there with a lot of your customers. They are in charge of protecting again the crown jewels, right your P, you know, which is not just manufacturing but accounting general ledger, you know, HR and many cases Sales Force and and more Tech and a lot of those other environments.
What are those discussions, you know look like now with your scene so customers they're increasingly being asked. Yeah cases to the board. Yeah.
Absolutely. That's a great question like and I think the things change I would say over like five years a little bit over five years ago because when we started the business, it was really it was basically status quo, like all companies have this business critical applications, but for the most part they were behind the firewalls. They were like an internal Network.
There was not a lot of change happening. And again, we all know and a lot of the systems know like that really there's no internal Network and nothing is security but it's kind of quote unquote behind the firewall, but it was of course like a lower priority in many ways and because like a less mind shirt I think what's like what we started seeing over the last years is this perfect cyber security storm forming on business apps right if you think about That from one side you have this move to the cloud why we're all companies are trying to kind of move to the cloud whether it's a lift and shift to get some efficiencies or really like on the next side apply a digital transformation initiative. So really introducing devops RPA AI like a really mobile into this applications.
So let's create a lot of pressure points in this apps. As you mentioned compliance is also a Big Driver here where we have traditionally like socks like CCPA gdpr that again everyone talks about socks in the security industry when you talk about earpie, that's where socks kids. I literally audited right we talk about gdpr.
Now you have HR System crn systems. That's where all that Pi is. So it's a lot of really pressure from a regular perspective in this applications as well now with SEC and our things are coming out at the board level as well.
But I think the other thing that really changed the last five years is Redlands game we've seen over the last five years really and evolution of the cyber security threat actors or going specifically and targeting year B and business applic. Using Erp specific exploits Erp specific capabilities to the point that cisa BSI and many search organizations globally have been increasingly releasing alerts around Erp and business application specific attacks. So to your point on the board and discussion with the ciso, I think the good news with many seasons really really like the partnership with announces because we also give them personally at the professional level and opportunity to have a business conversation with the board by by the definition right because they're not going into the board and trying to explain what an active directory hack would be or like why why they need to secure like a piece of firewall.
They talking about their business processes everyone at the board level knows that they may be invest in those things or hundreds of millions of dollars in a transformation whether it's sap Oracle Salesforce, so they know how much investment is going into the systems and that it really enables the system to have a conversation like we can distance lenses, right and really helping the board and management understand that by doing this securely they are really securing that in protecting that investment that they really putting so much weight behind. So it's a pretty unique situation for for the Cisco to be able to have that conversation. We hear a lot of really good people that is Refreshing for them and for the board to be able to have those type of discussions, right?
Right and you mentioned compliance a little bit and you know, it's and I get being a security guy just like you right, you know growing up this, you know, 20 something years seeing the evolution of it. Um, you know compliance to me was an interesting, you know, basically a bat that I could use in order to push my security right forward. But I mean, I think that now we're at the point now and and we're gonna see more regulation and obviously with the big svb blow up.
These would be focused on risk management and a lot of these other things that get get back to the importance of the security program the importance of thinking, you know, risk Centric. I mean, we spend a lot of time with application teams and and you know as they're initiating a lot of devops motions what you increase your attack service again, I mean, I I think compliance continues to be a thing right. So how much are the You know is is going towards these compliance targeted and issue David versus you know, and you said the threat actors are different but can they tell the difference when we're dealing with you know, somebody's Enterprise applications.
I mean it is all just security and my compliance budget just pays for it or the folks say, well, we really have to report on this stuff and we're gonna you know kind of devote some of those resources more towards a true compliance type. Yes. Yeah.
I think it's a great question. It depends quickly very much from the mainly on the house. What's the security maturity of the organization and specifically we see that across the industries like we see industries were more kind of more leaning thinking maybe more from a risk based perspective.
Even if you don't have the regulatory pressure specifically on this type of initiatives by definition based on what we do for the most part. This is basically both is a component around compliance, but we're seeing more and more where the biggest driver is less of complex, which was the case in the past more now realizing that purely for my risk-based perspective these Like this is a priority that when you think about like when we have customers doing a crown jewel assessment or doing a high value Asset assessment this applications where you can Erp supply chain pln systems, they usually fall in the top five if not the top three. So even when you started which I think is the right way to prioritize but if you do in Risk base, you need to start with kind of the value of the ass and I want what is the impact of a potential kind of really negative event there.
So when you look at the potential the probability or so the impact of that event and now what I think's changed is a probability right now, it's it's more evident. There's more data about specific attacks against this applications. So we're seeing the risk based conversation really taking a front kind of front seat at the table special when they're migrating or moving this applications to the cloud, right?
That's where everyone I think at the senior leadership table knows that when I don't want to be the guy that says no to cyber security in this maybe 500 million dollar like transformation that we're doing company why like five years project? Now we really afford not to have the right controls from a cyber security perspective. Even if we don't have a compliance requirement to really drive it.
Yeah, I think the benefit is as a side product. Even if you're not doing it for compliance with some of the capabilities that you end up implementing you get efficiencies from a compliance perspective. So a lot of like use cases around hey and not only get a security controls, but now I can make my audience more efficient.
I get like I remove a lot of money on work and automate compliance requirements and already requirements, which makes everyone super happy even the admin and the Auditors, right? Yeah, you better and I guess I've always come from the perspective that if you do security right compliance should be pretty straightforward. If you generate a report now, some folks have a hard time generating report.
So, you know, I shouldn't be a little bit flippant on that. But the reality is strong security program tends to you know, kind of result in in decent compliance our conversation from from that scene. But again, it is an interesting time you mentioned Cloud, right you mentioned digital transformation and you know that being the Catalyst for a lot of of investment.
I'm still fascinating by, you know, your perspectives on on asset value and what's important because I sit with these folks a lot too and you know historically they had no idea what was more important than another and we all be you know, we really focus our controls on a horizontal situation not on, you know, kind of applications and and use cases. Have you seen that store to change a little bit? It folks can you know obviously you guys you know Focus specifically on your piece.
So that's one thing right but you know in general I'm still you know, not seeing enough for folks, you know, really looking at a specific application to go. Hey, we got some really sensitive stuff in here. We're gonna lock this down tighter then then, you know kind of it's although one and maybe doesn't have yeah.
Absolutely. Yeah. No, I think it's been historically the industries been more kind of reactive and more Rich driven, right?
Okay. What are we see in the bridge where we seen that dogs? Let's go secure that I think we're seeing that shift were okay especially times like now we're like limited budget Copa companies trying to be more efficient.
I cannot afford to do everything as a sea. So right what I'm really gonna prioritize and I think is that you know, rich and what's happening in the threat landscape but also adjusting that because it's still kind of protect. There's more hacks and more attacks and people going after more things that I can protect right?
I'm gonna protect the things that matter the most right and that's where we see that adjustment on kind of high value uses and Crown Jewel. Really protecting those type of Investments and again back to the same point is what does my board care about? What does my leadership was?
This was on the CEO care about and what's happening a lot is that you see this companies were internal initiative strategic initiatives that are reporting to Wall Street where they talk about their like digital transformation Journey, right? So there is like that convergence of What's the right thing to do for the business plus what has leadership and more attention on me as a Cisco while what's my like my position and my opportunity to do the right thing for a company Elevate myself how the right conversation with my leadership team and have to appoint a business-centric discussion that is really focused on risk and not purely purely compliance. Right?
So we've seen we're seeing more of that where that's really changed in the landscape, but I think it only happened because it's not it's not a security lab conversation. It's a conversation driven by the business about really modernized in this applications changing changing the start of call, which is driving the conversation, right? Yeah.
I don't think as much as we like to be like and security geek I I written a security industry. I think the bigger voice is usually that like most Industries end up being really the business, right and the teams driving business outcomes. So every industry, right if they want to stay in business.
Anyway, I mean You know, listen, I mean, you know, we certainly have a very, you know, specific view of the importance of security because this is what we've done right and it's just like don't ask me, you know, oh my review at risk or you know, what's the worst thing that can happen? It's just like don't ask that question, right? You don't you don't want to know that that question but all the same if we can't figure out how to translate that risk that we understand at an intrinsic level, right?
We can't translate that risk into business speak and and really dollars and sense that a um, you know or whatever currency you're working and I know you guys, um, you know, if you can't translate this something that a board level, you know, kind of person is gonna understand we're always going to be relegated to this, you know, both that on later, you know, build out the thing make sure it's not gonna get hacked and then, you know get thrown under the bus when something bad happens. So I think it's an opportunity to both reset in terms of the discuss. It we have with the senior folks, but also we're security gets plugged into the initiative right when we're talking about digital transformation.
It shouldn't be something that oh, we've got to put some controls in at the end. It should be one more designing what those processes look like when we're selecting the software. We're gonna go SAS.
We need to make sure that our endpoints are are tightly controlled that we've got this ability over. You know, what those Cloud assets are obviously that we're you know, kind of looking at transaction level stuff and and ensuring that you know, kind of those Core Business Systems or protected so there's a lot of layers there. But if the seaso can't have that discussion at the board level, it really doesn't flow down here.
I think that's really the key Point here. Yeah, and I think you bring up like great points. They're like, I think the translation piece I think it's in in another dimension as well one is like the translation to the business and to the board can upstream and there's so Translation were like we help a lot of ceases because they simply don't know what's going on in this in this world.
It's almost I think this part of this segments were used to be like operation technology a few years ago right where the ciso is put in an infosec in general is putting a lot of faith and trust in the operational teams managing the systems because they are the experts. It's very obscure technology very complicated. So it's very hard for the security team to have the right governance and visibility into this systems.
So we're seeing the same with Erp and business apps where you have strong teams managing and running the systems. We're really of course, which is pretty hard to keep in running modernize them and not but now really what it was happening like over the last 20 years. I would say is that most security teams were just trusting but not very fine.
Right? So we go to the back like trust my very fine. Like there was no way for infosec to verify that the systems were actually curious it could be and it was this full sense of security there because most people were doing access controls use the roles and profiles in Erp and supply chain.
In an HR systems, that was Secure right? So I think now we kind of fast forward. We see this Gap in the industry where the ciso doesn't fully know.
How the most important applications in the company are secure now which is a pretty and comfortable position to be in and to your point the way to solve it like holistically is which will see more of now today's is not the ciso ducamina the 11th hour and try to stop the digital transformation because they did append this or an assessment and like of course, it's not what it should be is really bringing it by kind of my by default by Design, right and we're seeing a lot of that were the board is excited and partnering with the sea. So the CEO is excited because that transformation is going smoothly and going faster and staying on time and on budget because security was part like from the beginning we've seen a lot of devops like in ER peace and environments. They introducing Devils just now right things happening a bit later in this in this type of environments and that's where like if you can like get security, you know, right like would you get really Security in bed in devops in the beginning?
You know that all that new custom code is secure for from day one and you save a lot of time money and risk. So those sort of things exactly what we're seeing that is starting to really change the game in how people can secure this and just keep it secure afterwards. Well, that's good.
So good Mario. Thank you. Really appreciate the conversation again.
I'll just kind of sum it up as Back to the Future, right? This is something where we would we you know, we should have been doing this many many years ago. And now we're finally getting an opportunity to do it in order to bring us forward.
So I think that's great. How do folks get in touch with you guys at own absence if they're interested in you know, something that Erp security things that you guys yeah enough. com.
So happy to talk with anyone and really help them so their security posture and help them with this more forward. That's great because yeah again as you said, right it is kind of the crown jewels. Those are in our Erp systems for a long time.
We didn't really understand the security posture of those and now we don't have a choice right because this stuff is moving into the cloud and we really have to make sure that we have more understanding of who's doing what where and where that very sensitive data is. So. Thanks again Mario.
As own apps just really appreciate it. Now. Let's send it back to the studio for our next interview.
Thanks a lot, Mike.