ConnectSecure’s Krishna Kottekkat on NIST’s National Vulnerability Database
Krishna Kottekkat, CISO of ConnectSecure, delves into NIST’s National Vulnerability Database (NVD), and how its lack of funding is affecting CISOs. They have effectively lost a critical resource, as many vulnerability scanners and other vulnerability management tools rely on the CPE entries set by the NVD to pinpoint and address security vulnerabilities affecting an organization’s systems.
Transcript
This is Textron tv. Hello everyone. Welcome back here to techron tv.
You know, coming off of RSA two weeks ago, it's, uh, still in that security state of mind, and certainly as always, no lack of news insecurity. It's funny, this next guest and, and interview was actually scheduled. I scheduled it prior to RSA and the, uh, there's been a lot of development since we scheduled this, but luckily it's gonna bring us up to date on this important story.
I want to introduce you to Krishna. Krishna is the CISO, CISO over at Connect Secure Krishna, welcome to Tech Trunk tv. It's great to have you on here.
Thank you, Ellen. It's my pleasure to be on, on, on the channel, and, uh, it's great seeing you again. So, uh, thank you for having me on on more today.
Yeah, Absolutely. So, Christian, you know, I always like to give the audience a sense of who they're talking to. Sure.
Uh, if you wouldn't mind, give us a little bit of your background, a little bit of your journey to becoming CSO at Connect Secure. Sure. So though, uh, thanks.
So, uh, I started my journey like a regular SS admin kind of role, few years back or a decade back. Then moving through the different security, I mean, have been through those generation and evolution of security. So as to say from a standards admin role, a network administrator role, then becoming a network consultant and, you know, product delivery and all that.
Then suddenly turning into compliance. So I was heavily involved with SOX SAS 70 during those times, during the SOX four, four and all that. Uh, then I also look after those, uh, I was working closely for the, uh, FIFA up in the infrastructure site for, uh, which was held in Qatar.
Then I moved in as, uh, a CSO for Connect Secure a year Back. Excellent. Where, where are you based?
I'm based in Abu Dhabi right now. UAE. Okay, sure.
Very good. Um, Krishna, a little bit about Connect Secure, maybe, oh, I don't know if everyone in our audience, you know, is familiar. Sure, sure.
Connect Secure. We are a vulnerability management and a compliance platform focused specifically on MSPs and the small and medium businesses. And they're small and medium businesses.
So they, we are specifically a platform that helps MSPs to improve their operations by providing it as an all in one platform. So we help them identify the problem, remediate it on a single platform that helps, gives them visibility on the assets they manage, and also help the customers of the MSPs to, uh, have a better security posture. So in a way, we offer, you know, all in one platform for the MSPs to manage a security program for the customers.
So that's, that's in a natural, natural what we do. com. That's where that's, that's a, uh, that's our website where you can find all the details of the product.
Excellent. You know, the, the, the small medium business segment has always, unfortunately been an underserved segment in the security world. You know, they don't necessarily have the resources to do a lot of it in-House, so they are almost perfect candidates for M-S-B-M-S-S-B, you know, managed security service providers and, uh, without, you know, how, how, how else can they keep up.
And compliance is also a big thing and, and for that market as well. And, um, so it, it's, it's good that Kinex Secure serves that market. It it's a market that desperately needs.
Absolutely. So, Alan Matthew actually point, as you rightly pointed out, the SMBs have the largest, uh, uh, risk, not risk. I mean, they don't have that kind of budgets to drive it, and that's why when I say that we provide everything on the same platform, makes them easier to have the entire security postal managed.
You know, you detect a problem, you solve the problem from the same platform, so you don't have to hire or train. Multiple people have multiple skill sets to solve a problem. So we provide solutions upfront for their problems after listening to them and understanding to them, and we work as a community to support them for their operations, security related masks.
Excellent. com. That's correct, yes.
An secure order. Fantastic. Krishna, let's turn to our topic of discussion.
Sure. As I hinted at, in the opening when we originally scheduled this, which was before RSA mm-Hmm. Um, you know, the, the word had come down a few months ago that, uh, nist, the National Institute of Standards Trust, uh, had had budget cuts, like if many other organizations and had the, your word had come down that they were no longer gonna fund the National Vulnerability database, the NVD, which, you know, I think most of our audience out here is familiar with, but it, it was, it's been maintained by NIST from day one, and it was, it was kind of the authority, the a, you know, a tremendous asset for CISOs of companies, large and small.
But of course, you know, when you're a large enterprise, you could afford a threat intel platform and, and threat research and, and all of these things where maybe it's not as important, it's not as threatening not to have an UpToDate sort of NVD for you to, to work off of, um, for the SMB market, the mid-market, MSPs and, and still even enterprises, you know, not having this asset, uh, maintained was, was a, you know, it was a tremendous hurdle, a tremendous problem for CISOs. And that, you know, not, not every company even has a ciso, but for every security team out there saying, okay, how am I gonna work around this? And, um, I know that's what we were originally gonna talk about.
But then as you mentioned, as we were talking off camera, May 8th, uh, thesis came out, you know, neither this is a fish, sort of, this is semi quasi-governmental, if you will, CSA is, is certainly part of the US government. And, and, you know, why don't you take it from there because it's your story. Sure, sure.
Not a problem. I think, uh, as all the people in the security community would know, NVD is like the, uh, uh, the most trusted source of information that you have when it comes to vulnerability. And everybody relies heavily on that.
The kind of analysis that they do. They kind of, uh, uh, uh, study they do before publishing an information about the vulnerability is enormous. And like you would've seen in the last few years here on here, there's around 25 to 28% growth on the vulnerability study they published.
So, I, if I, if I recollect, I think recent, uh, we, we were looking at the, uh, the dynamics. They chose around 25,000 last year, somewhere around that number that was published. And, uh, now the, in addition to that, the most, uh, important thing about the vulnerability is the contextualization and the effectiveness.
I mean, what does it mean to who that, that is what NVD used to provide? I think now with the May 8th announcement where CS a said that they would expose their world enrichment program, that's what they call it, it's World Enrichment Program, that they would open up for the community and that would help all the CSOs and all the security people to clear the backlogs that they have so far. And also, the CS a is coming up with the direct JSON files that they can, starting operating into the vulnerability program to make the adaptability faster.
So this is where we are right now. If as, as I mentioned before, if this had not come out last week on the eighth, we would be discussing about the issues that we are going to face in the future, the amount of time all the security vendors and others have to spend on the analysis, testing of, of vulnerability, and finding a patch for it. I mean, that would've been a different topic altogether, and we are go in a different direction, but absolutely, I think this is come at the right time, and it's, it's a very good initiative, which is comforting for the community.
Uh, there's something to look forward. I think it's, and, and it's a decision in the right direction, because I was, I mean, the discussion in various groups and forums about this NVD not being, it getting was leading to a direction where build some vendors from a consortium and make it a paid service. This is something that everybody was scared of because it's something that everyone needs.
So this was one, one, uh, talk that was happening. Then the other side was will the vendors, I mean, major vendors form a consortium to do this for themselves, because it's also a matter of their existence. So these were the kind of, uh, talks and dialogues for that that was happening in the forum.
So I think the announcement by CSA has come at the right time as solution for the problem that would've grown beyond, uh, you know, it's, it's a problem that you cannot, you cannot, uh, ize the impact that it would, uh, create in the, in the security community. No, I mean, look, having the security vendors and the community kind of take over the NVD as a public private community funded thing long term, there would've been some short term disruption and, and heartache, right? Heartburn.
Mm-Hmm. But long term, it might not have been a bad thing, frankly. Right?
Because I, I am a big believer in, in that, you know, industry government cooperation. It shouldn't be just the government alone. And my, my question to you is, okay, CISA is doing that now, but are we just kind of putting it off, you know, have we kicked the can down the road here a little bit, or do you think this is really a long term solution to this and we don't have to worry about it?
No, I think like how you mentioned, maybe this could be an interim solution for some time, because the sheer, sheer volume of vulnerabilities that come out every year, you see at least 25% now maybe with all these AI and other things coming, everything is stopping IP now. I mean, anything and everything is talking up with the number of devices increasing on the network, the number of kind of spinoff operating systems that are coming in, I think in the due course over a longer period. What I personally feel is that it'll come up with some kind of a, you know, as they call in the, in the management terms of PPP model, you know, public, private funded model, that would, again, I mean, the funding would be generated, but this would be like a consortium that would come along with CSA to work towards, and also the diversification.
I mean, where all the IOTs and all those coming in at a later stage with AI and all, I think this is where the road would lead to probably in a 10 earliest time. This is what I feel, but Cs a commuting in is an instant solution to the problem that we were facing as a security community. And this would help us clear all the backlogs that we have in this NVD.
Uh, it's, I mean, there might be slight hiccup hiccups in adapting to a new, uh, kind of system and how these things operate, but I think they speak all speak the same language rating CVSS, CV and all that. So it's, it shouldn't be a problem. Absolutely.
And, and, you know, I, I think, look, let's give credit to csa, right? CSA is a, I mean, a fairly new government agency, right? But certainly over like the, you know, let's say the last seven, eight years, it's really, uh, cast a big shadow on the industry.
It's made a big impact on the industry and, and what they're doing and what they're saying and, and so forth. Um, of course, some people look, you know, you can't please all the people all the time, right? There are some people say, well, look, the whole rating system of vulnerabilities and everything else, it creates sort of an artificial kind of environment.
Companies need to rate their own vulnerabilities based upon factors that don't get taken into account in, uh, an NVD or a CVE kind of description or even in what thesis is doing. And the better off everybody, you know, we'll all be better off if we kind of did it without that system. I, I don't believe that, right?
I remember when all of this came about, I guess it was 25 years, maybe 28 years ago. Um, I, I was doing security at the time. It was already out there.
I think nist, not only nist, but Mitre as well. These organizations have been doing fantastic work, largely unheralded, right? Over all these years that enabled so many organizations, so many CISOs, so many companies like Connect Secure to come to market, right?
Based upon the great work they were doing. And, you know, now, as I said, it may be time where private industry has to pick up some of the tab here, some of the burden. But nevertheless, we need these kinds of infrastructure, you know, uh, security, uh, uh, infrastructure for the industry, for vendors, for end users, for CISOs, for everyone, right?
Because it, it, it helps everyone. It really does, Right? As you rightly said, I think the key words I would use in the context of NBD or cst, contextualization and prioritization.
So what they have done is by setting those ratings levels and the benchmarks, they've put a standard framework that you use to contextualize, send, prioritize a vulnerability that helps the business or the end user to take an action on what needs to be done. I think that's the key. If that framework is established and can be replicated with all the private vendors or the, or the private, uh, consortiums that come in, the foundation is already done.
Now, it's just an operating model they can work on and take it forward. I think, uh, uh, then this will, this will, you know, uh, make sure that there is a robust infrastructure of those basic services that are required for security as a function to operate. You know?
Absolutely. Christian, we're about outta time. The time goes quick here.
Um, I, um, I think we're all breathing a little bit easier that cis a cis a has jumped into this. Let's see how it works out though. And hey, man, come back on soon and keep us posted.
Keep up the great work at Connect Secure. Will do that. Thank you so much.
I thank you for this opportunity and for this, uh, fruitful discussion. Thank you very much. Thank you.
Thank You. Me too. Krishna Koko Seeso at Connect Secure here on Text Drug.
We'll be back with more text drug TV in just a minute.