Collective Defense – James Turgal, Optiv
James Turgal, former executive assistant director for the FBI’s Information and Technology branch (CIO) and current Optiv VP of Cyber Risk, Strategy and Board Relations talks about the fear of brand damage, regulatory scrutiny and financial repercussions prevents many organizations from reporting attacks and why we need collective defense (cross-industry collaboration and intelligence sharing) to stay one step ahead of cybercriminals
Transcript
This is texturing TV. Hi everyone. Welcome to another tech Strunk TV segment.
My guess this segment's another first time guests here on texture on TV. I'm excited to have them on his name is James turgel James is with optav where he's the VP and if I missed some of these James, I apologize cyber risk and board relations. Yes.
All right. Yeah, I think hey James welcome. I feel like we're at a meeting, right?
My name's James. Give us a little bit of background here. What would well, obviously I gave your title with optav.
But let's hear you know, you have quite a history some experience in this industry share with our audience if you don't mind. Yeah, absolutely. I'll thanks for having me so James tergel.
I'm as you said a vice president and our board relations. I'm actually been with octave about a year and a half now prior to that three and a half years with Deloitte and touch running there cyber board relations program as well prior to that 22 years with the FBI. So I came in the mid-90s.
I work in you name it Colombian Mexican cartel hardcore drug cases started my career working cyber in the FBI. When in 2002 when the FBI really started to understand that cyber was going to be a part of everything that they did every kind of case. I was the one sent out to our Cincinnati Ohio field office to create a cyber task force out there.
So I've been working cyber, you know since the Inception of the program, you know early botnet malware cases. You name it move throughout my career. Was the special agent charge of our Arizona office during crisis situations like The Gabby Gifford shooting The Fast and Furious ATF gun Scandal and things like that.
Also did a stint as the chief human capital officer when director Mueller brought me back to run HR, but I ended my career as the executive assistant director for Global it and the FBI's Chief Information officer. Wow. And I'm sure there are stories to be told here that would go way above our 15 minute timeline, but maybe we can catch it an event or something and do a live interview a little longer.
I'm sure they're great a lot. You could share a lot you can share. Yeah, that'd be great.
Yeah. Um while we're at it look not everyone here in our audience is going to be familiar with optav. Why don't you tell a little bit about what octave does?
Thanks. Yeah. So octave is a we are actually owned by KKR private Equity Firm Optive is the cyber security and and solutions leader right?
There are there's nobody else. We are what we call a category of one because we not only have the ability to go out and have we have some 400 different partners out there that actually we can resell the products to particular client. But we do the integration we do that the applications we can actually monitor it so it is this whole, you know design operate and and actually take it to the next level which is what I do on the whole advisory piece where I'm actually advising boards and audit committees every day about the value and buying down risk for the the cyber security in in money that they're spending and those types of Investments.
so that's to me like you guys do everything from Look, we used to call it in the it business the Service Center Greater, right or a value add service in a greater. Yeah, but you guys also add sort of an act of saying almost like an MS SP road to it. You're actually managing security for some of the clients.
Absolutely. So, you know, it's it's Cradle to grave kind of security it is it's and and Yeah, we originally started as a as a value added reseller, but we've expanded so much further than that with our services line and our integration and now our you know, again the ability to to execute and really play at the board level. Patient been opted James.
Where do you suggest they go? com that's oh ptiv. All right, we've got that out of the way James.
Let's let's dive in here one thing to talk today about You know, look our audience has a lot of cyber folks in them who are very familiar with. Let's call it evil ink or whatever, you know, whatever you want to call the bad guys system. Well, we all have a lot of people who aren't cyber experts.
They're developers. They're Ops folks there helped us there It generalists Business Marketing sales, and they may not be familiar. Would really have what?
a full featured ecosystem exists ecosystem exists on you know, the black hat side of things on the dark side of the internet the underbelly here, you know, and we're talking everything from like state-sponsored. Espionage cyber terrorism just creating chaos. to finance people, you know financial gain folks who are looking to basically steal money, whether it be through crypto, which is one of the latest greatest kind of things or good old-fashioned credit card bill for England or identity theft and stuff like that to all the way down to the you know, the the Cyber activists who want to make a statement right, but And what people don't realize is really the width and breath.
of that whole ecosystem of that whole Evil link kind of thing. That is just my ran somewhere. Of course is the new stuff software Supply chainsaw.
There's a lot of attack vectors James. Give us a you know, I tried to paint it, but you have a much better. picture than I do Well it is it is absolutely a business Alan and you know, I've worked this for you know, many many years a couple of decades on the investigative side and and it has morphed throughout the last few years, you know historically it was the you know, the low level organized crime groups.
It is always been the nation states right China Russia North Korea Iran, you know, certainly the those organizations put a ton of money. And again, it's it State sponsors. So the their actual governments are paying to do this, but there's something in the middle that has a morph throughout the last few years.
And what I call a crowdsource tacking you now have organizations out there. The nation states are still doing what they're doing and they're doing it at an alarming rate. The concept of crowdsource hacking is really you've got individuals who are really good at a particular type of activity.
Right? So you'll have a group that is just good at doing the penetration and once they're done with that penetration, right? They they hand it off to the next guy who's really good at moving through the laterally through a network and can pick a network apart and what this does it makes it very difficult for law enforcement.
Because now you've got individuals who don't know each other right? You can't attribute one to the other but they're they're really good at what they're doing. So they're infiltrating.
They're handing off. They're moving through the network. Right?
A third one will come in and they'll give it back to the original client. They'll drop the payload and and now you're you're off and running on a ransomware or whatever it is. And so it's it has really a morphed to these specialists in these areas and then it then rolls back up to again you having nation states using these crowdsourced activities, but certainly the organized crime groups are proliferating in this area.
It's crazy the age of specialist, right? You know, and I I think a lot of people. you know, they still think of the kitty scriptures as we use the call, right those people are history and that they're not out there the break things because they can't but you know, it's such a sophisticated business today and and not only that like, you know, you you could buy that I forgot the name of the term, but you can buy software that's meant to break into people's.
I saw a machines or turn machines into zombie there. They're actually people selling software on the dark web the same way you would buy software. you know aren't any exchange or in you know, above board so to speak and it really I mean it's a Huge you have James.
I know there's numbers out there how big an industry is sort of evil ink if you will. Well, so it depends on on how you look at it, but certainly the right now it is in the billions of dollars right with a billion with a B billions of dollars and what they're making every year and they've actually created this they've actually created storefronts, you know, things like alpha alpha base Silk Road. I can actually go out right now.
On the dark web and some of these forums I can buy 30 days of botnets, right? Those are the little zombie computers that have been that have been converted and and tell the the individual right store guy. I want to I want to attack this set of IP addresses or this company or this this group.
I want to attack this group for 30 days. And they'll give you the malware the loan you the malware. They'll give you the botnet 30 days worth of botnet use.
And then they'll let you know how it went. I can get that for two grand on the dark web right now. crazy crazy as if things were weren't bad enough on the other side of the coin.
We still seem to have this stigmatization stigmatization stigmatization around. Coming forward and saying I was the victim. I I was I was hacked.
I was attacked I suffered a loss. Who is the latest one that seemed to God off people were really bitching and moaning. It was an Uber had a huge a huge breach.
They didn't disclose. Until years later and we just found out about it and it seems they're not. You know being held accountable as in industry or as a just as you know, a rule of thumb even though we've passed laws that say Hey, you got to disclose a breach.
You gotta let people know that their data is at risk. You got to provide credit monitoring something. We've done a really lousy job.
It seems yes of enforcing that of of making that. the the norm Yeah, it's it is really it's really difficult to understand. I mean having worked these cases and been with set with victims, you know for excuse me, the last two decades they are most of them are are ill equipped to to understand the whole concept of cyber materiality, right?
When does that breach become material and then they also with the whole there's a lot of misconceptions about there about the impact of sharing information, right and what we were talking about earlier about the whole concept of collective defense, right? They believe that If they if they give the information away if they let the world know that they've been attacked, right they're giving away a competitive advantage or they're placing their data privacy at risk or right. None of this is true.
Right? It's just their perception of that and and let's face it. There are as you say, there's a number of rules and regulations.
There's a brand new at brand new SEC rules that are about to come out and be promulgated about actually a four-day a four-day rule disclosure rule on, you know, material cyber incidents and board education on Cyber. So unfortunately because the the companies out there and The especially the publicly traded ones are have refused to provide this kind of information right now. You've got a legislative fix right now the government's going to mandate it and the SEC has got a pretty big stick.
Yeah, you know what though? We I don't want to be a doubting Thomas, but I've seen regulations before and you know, it's not a crime if no one finds out, right so and some people really have that. I think You know, we could regulate to the cows come home.
But we've got to do a better job look. We've got to remove the stigma from being the victim or the you know, someone who is hacked for at a corporate level as well as an individual. Yeah, there's some negligence there.
There are stupid cases James. I'm sure you have feel books of stupid things companies have done and have gotten, you know paid the price but You know, you could be the smartest organization the smartest people on Earth and you'll still be a victim of security incident right these things happen. It's it's part of doing business and you know, we've got to remove the the stigma around coming forward and whether that's Financial.
You know financially motivated. I'm afraid my share price is going to take a hit or or something like that, right? Or you know the the fear of what the repercussions are.
We've got to remove that. It has to be. you know just this is the normal course of doing business.
You are you a hit you were the victim of security incident you disclose. period I mean I look at like responsible disclosure right when I first got into security many years ago. There was a fight around just responsible disclosure.
You had Cowboys who will finding vulnerabilities and 24 hours fix it around disclosing it. I want to get my name out there. Right and there was a lot of that nonsense and and you know, you wind up creating zero days and stuff today.
We for the most part have a decent responsible disclosure kind of protocols that most researchers and companies follow. Yeah, yeah. We haven't seen that we haven't seen that with with.
Response, let's call it responsible disclosure of being a of being hacked of being a victim even with ransomware as rampant as it is today. You still don't hear, you know, I was like, oh this this one's off. This website's down.
Why is it down? Yeah, it's down for me. It's right.
It's not down for me. It's in today's world. We don't need to shut websites down for me.
It's anymore. We were pretty good at that continuous delivery thing. Right, right.
It it, you know, one of the things that that is is always amazed me is when I would sit with I would sit with actual victim right when you're in the middle of a ransomware case, I would sit with you know, the CIO or the CEO and they they absolutely just not want to to disclose any information and I I kept trying to get from the FBI standpoint. It's really important for for your listeners to understand if that one company is in the middle of that crisis that that let's say. It's a ransomware attack.
I guarantee you from Decades of experience that that's not the only victim from that particular threat actor, right? I agree those being launched at the same time and what I couldn't get through to these to these companies was look if you can just give me the the base intelligence of of how they got in there. Right?
So, you know, how did they enter your system? You know, how did they transmit and and move through the network? What kind of tgps were they using because guess what if I is a law enforcement, you know cyber investigator.
Can take that information and then I can take the other four 500 companies that I know are victims as well that gives us a common operating picture and certainly better attribution and I can go stop these people but all the data all the information of where it starts unfortunately is in those victim companies and unless they're willing to and now being forced to disclose it. I mean, that's how we that's how we get ahead of the threat. a great I agree and that you know, you said They never attacked just one company.
I mean sometimes if you're a target for nation-states up maybe but you know, if you're the victim of the ransomware believe me, there's other victims out there and the more we know collectively the better. We are here's another Trend. I see James and that is the old cyber Insurance somewhere.
So the offloading the dealing with this stuff to the insurance company, let them negotiate with the ransomware. Let them worry about disclosure. What's your view on that?
Good thing bad thing. Depends, you know insurance is insurance is designed to to not you know to mitigate certain types of risk. Right.
And so if you look at the historically, you know, it's cyber insurance came around, you know, really in in Mass probably 10 12 years ago. And now, you know, it was fairly easy to get and there wasn't a whole lot of you know restrictions right now now go out and try to get a cyber insurance policy right? There are because of all the attacks out there, especially in the last two three years the ransomware hits.
Right, the premiums have gone Sky High and and there are a number of insurance companies who have decided to not not play in the playground anymore because they've they've had too many losses and it's it's something that you're it's very difficult from, you know, most people to understand but it is it is the concept of look I'm trying to ensure the fact that I'm not going to get attacked by some other third party that I don't even know who they are where they are. And so you're trying to ensure against this and and it's it's odd to me that you know, you should be doing all of the the normal cyber hygiene, right? You should look at a framework like nist or others.
You should be doing all of those, you know, like good good things within your infrastructure or ecosystem to secure it. Well, that's what that's what now cyber insurance companies are requiring you to do before that even think about ensuring you. Here at some level if that's what it takes to get you, you know.
Getting on the stick here. Yeah, maybe it's kind of terrible thing James. We're over our 15 minutes.
I got to apologize to you man. We we talked a bit. Hey, it was a pleasure having you on we invite you back on anytime.
You want to chat got some good stuff to talk about are we always a pleasure to talk, you know cyber and and we'd love to hear maybe some more stories at some point from yours. Yeah. No.
Hey, I love it. I love to be on again and trust me. I got all I guess a really good cyber work story.
We'll do it. All right, man. Hey James Sturgill from off to here on Tech stroke TV.
We've got to take a break. We've got another great guest coming up.