Cloud-Native & Pentesting – Caroline Wong, Cobalt
Whether it’s keeping pace with the accelerated delivery speed organizations demand or covering the breadth of an organization’s application portfolio, penetration testing at scale is vital to every organization’s security strategy. Caroline Wong, Cobalt’s chief strategy officer, previews her three security pentesting sessions at Techstrong Group’s CloudNativeDay 2022, AppSec/API Security 2022 and Cloud Container Sec Summit 2022 virtual events. Register at techstrongevents.com or check them out on demand at techstrong.tv/videos/techstrong-conferences.
Transcript
Of the great pleasure today being joined by Caroline Wong. You've seen Carolina another activities matter fact, we're going to talk about some upcoming things that are happening with Caroline Caroline is Chief strategy officer with Cobalt. Welcome.
Thank you. It's so great to be here with you Mitch the great pleasure for the folks that may not know you tell a little bit about yourself and talking about coal. My name is Caroline Wong.
I'm the chief strategy officer at Cobalt Cobalt is a pen testing as a service company. I myself have been in the information security field since 2005 starting my career off leading security teams at eBay and Zynga. I host a podcast called humans of infosec and I teach cybersecurity courses on LinkedIn learning particularly the owasp top 10.
Those are all great topics love all of it. We could take about any of those. Well, you're you're speaking in some text wrong events that are coming up to my mp when people watch this coming or have happened.
Well, tell us a little bit about some of the topics that you're going to be talking about. So one of them is about security testing at speed. It's actually called move fast and don't break things.
It's a panel featuring myself as well as a couple of really good friends of mine Kim Jones with into it and swathi Joshi with Oracle. And we're talking about practical ways that software development folks and security practitioners can think about and also Implement actionable behaviors in order to do security testing at speed Our intention is to banish the myth that you cannot do security testing at speed. It's also get rid of the myth of we're only stop perpetuating the myth of security to land of.
No, right if we're operating it. Absolutely. Yeah, the process part of the software delivery flow, right?
Yes, we've got to collaborate. We've got to partner with our engineering teams. Otherwise, it doesn't work.
It's interesting. Yeah, so you're doing this panel. I think a cloud-native day, which is the Box our 10th of August right coming coming up soon.
And then depending on when viewers are watching this may have been in the past. So that's that's number one. Another one that I've got is called.
Pen testing at scale. So organizations, you know Enterprise organizations have thousands of software applications and historically have really struggled to do the pen testing across the entire application portfolio in order to get the comprehensive coverage and the periodic testing that's really needed to keep up with the pace of modern software development. So whereas the panel really focus on this is on the speed aspect this one really focuses on the scale aspect.
How do you do effective security testing at scale? And this one is something that's very near and dear to my heart. I actually start the talk by telling about years ago when I was doing be Sim assessments BSI, mm stands for building Security in maturity model that time frame for me was 2013 to 2016 and during that time frame I found out after doing B Sims for 36 plus organizations worldwide that organizations were only doing manual pen testing on 10% of their software performance.
Even if that's scary even then it's terrifying. You know, when you think about how pervasive software is in all of our lives and you think gosh are these folks only doing security testing for 10% of the software that I use, you know, it's sort of terrifying so things have gotten better and my talk is about why have they gotten better and what can organizations do to get it really where it needs to be? We're nowhere near where it needs to be.
I can imagine you could do 10 talks on that topics. But one of the dementor there's several Dimensions to one is you have applications that are still being delivered on a monthly quarterly. Whatever kind of basis that others that if the organization is that mature in their kind of devops, you know, maybe daily maybe weekly sometimes even more frequent than daily.
So yeah, you have this frequency, you know, this this philosophy this all this all over the map trying to do Fantastic Four and then you're talking about whatever environment from a legacy or Mainframe application to so to you know, apply native. That's yeah. So the complexity that we're dealing with for the variables we're dealing with seem really challenging.
Yeah. It's very exciting and I think you know really things have changed in the last several years to enable folks to do this kind of thing. It's scale which really was pretty impossible before given teams capacity for the sort of thing.
As well as money, you know, but but things have shifted and I'm thrilled to share my perspective on that. It's going forward to that. So that is let's see September 4th, I believe is the end.
I'm sorry absec API sick this the conference you're doing this, right? Okay, that's on September 13th. So cool.
All right you doing the third one, right? Yeah, and then I've got a third one and the third one is is gonna be really extra fun. So the third one is the 2021 OST top 10 presented as a series of parenting analogies.
Mmm. Okay, everything I learned a kid in the garden. I know how to I can use for my OS top 10.
That's right. Interesting. How did you come up with that as an idea?
You know, mostly, you know, I think that the OS top 10 the whole point is for Education awareness, you know, and and if if I can if I can tell a story about one of the security vulnerabilities in the OST top 10, which Not to me and I know not to you Mitch, but to some people stuff about security vulnerabilities is boring. And and I don't you know, I don't I don't subscribe to that. But as a parent of young children myself often when I think about security vulnerabilities, I actually can't help but immediately jump to a parenting analogy.
And so I figured Why not put them together and share them in a little talk? Truly one of the traits that they share between security vulnerabilities and parenting children is it's constant change and you never know what to expect right? Yes.
So many things I I thought about you know, if it's kind of parenting or you know, you know shortly before we started recording this Mitch and I were just talking about our furry children our furry four-legged dog children for which there are also many applicable analogies. I'm sure Oh, yeah, we could that could be a whole another session right four-legged friends. Well, excellent, the the last talk is part of our Cloud container security Summit on the October 4th.
com and register for any of these events if it's happened. It's also available on demand. You can also now go to Textron TV and the sessions the sessions we have available online right here on Textron dot TV.
So easy way to check those out and go right to your session and see or the others that you'd like to see as part of that what I'm curious Caroline what what is sort of the theme, you know when you and I and others are doing speaking right you kind of get on these tracks of this is sort of what I'm talking about now and you're always thinking about what the next thing you're ideas might be coming. What would you describe as the theme for now that can represent with these topics? And what do you thinking about topics might be upcoming for you?
Yeah. For me the themes are consistent. They are themes of optimism and hope I think they you know, sometimes when we're talking about these security topics, it's easy to focus on what's really Bleak or what's going wrong, but I really choose to focus on the partnership opportunities the collaboration between the different teams that are making devsecops happen and they're super bright future that I believe that we have when it comes to cybersecurity so themes of optimism and hope running throughout And I can count concur with that and actually at Cloud native day.
I'm doing a panel just to put in a plug for when I'm doing actually with Mike Rothman with tech strong research and also gentleman named Donald Lutz who's been a software architect for any large organizations in which he's with towels that IBM right now. It is interesting. It was just the three of us and help folks will check that out too.
Because when you get two folks with very deep, you know, many many years, you know, like yourself with myself. Well, maybe need more because I'm not older than you are but it got the greater to show it when you get two experts together in what our complementary disciplines but now you need to be more than complimentary. They kind of need to be integrated intersecting and collaborating.
It's interesting the places of synergy but also the places have been great have agreement. It isn't just you know, you got a secure your stuff and you're so what you got to do or you need to get out of my way because I need you to Software it's like no we're all in this together. And here's some things we can do like Cloud centers of excellence or helping the organization whether it's the platform engineering or the security engineering teams to really kind of elevate all of our skills because we all have to be there to deliver for the organization.
Absolutely. Well, I can't wait to see your talk as well. Great.
Well, thanks for joining us and look forward to our definitely be checking on your sessions and other folks will as well and working folks find out more about call ball and you and maybe some of the activities you have going on there. io. Um, also if you follow me on LinkedIn, I post content quite a lot.
We also recently published a book so you can Google the P task book by Caroline Wong and that I'll give folks a little hint is basically the long form version of my pen testing at scale talk. Okay, interesting. Well, you're always looking to come back on and talk more about your book.
If you want and your podcast too tell us about the podcast. So the podcast I just happen to have a copy. So I just grab it and show it I'm done and then actually the super silly thing it's full of cartoons.
So it's pretty small. But I wonder if you can see me as a cartoon and then you know, really really the best part of this of this book. I mean, it's like it's exactly the right size to read on an airplane full of cartoons and then humans of infosec.
My favorite thing about working in this industry for almost two decades now is the people that I get to meet I get to meet such passionate smart quirky weird amazing people and on humans of infosec. I talked to people about their careers about their work and you know, it's really intended to show a different side of security. You know, we're always talking about the breaches and the vulnerabilities and those are very important things to talk about but this podcast really focuses on the people in the industry.
The technology doesn't happen by itself right up people in the end. Well Caroline great to have you won again and good luck with your your talks and lots of folks will check that out. Thank you.
Thanks so much, Mitch you bet.