Current State of SIEM – Tyler Farrar, Exabeam
Tyler discusses the current state of SIEM at US Organizations. Most security professionals display great confidence in their solutions being able to minimize the risk of cyberattack but when challenged, their confidence wanes. According to a recent SIEM survey conducted by Exabeam, when respondents were asked if they’d feel very confident telling a manager or the board that no adversaries had breached the network at that time, only 62% say yes, leaving more than a third with doubts.
Transcript
This is texturing TV. Hey everyone, welcome back to techstrong TV. I am happy to have he's the first time he's been on Tech show on TV.
So let's welcome him. Tyler Farrar. Tyler is the CSO ciso over in xdbeam Vendor.
We've covered a few times here on text drunk. Hey, Tyler welcome. How are you?
I'm doing well. Good morning. Great good to have you on so Tyler.
Um, well, why don't we start with a little bit of your background if it's okay. I mean I said you were to see so next to be but give a little who's Tyler. Yeah.
Absolutely on side. I joined examine about a year and a half ago. I am responsible at Exit being for Enterprise security incorporate security products security and then overall helping customers move to our our Cloud platform.
We provide Cloud scale security log management behavioral analytics and automated investigation for security operations teams and all Cloud native Sim before examine. I worked at a clear defense contractor called Max our Technologies doing satellite manufacturing and satellite imagery work and then before that it did some Consulting with KPMG, and then I have a sense of background with the US. Maybe working as a cryptologic Warfare officer.
a very cool Takes me back to my days or east we used to provide security to nmci. I don't know if you remember the oh yes that I do, but I can see your eyes growing. Yeah, that was an interesting.
I was an interesting gag, you know the Navy and the Marines and you but good times nevertheless. Anyway. Hey man, welcome and thanks to the background on extra beam in yourself.
Tyler exit being recently did a survey and report I guess on the state of sim is is that fair? That's right. Very cool.
I love hearing about these things share with our audience a little bit if you will about it, and maybe some of the results. Yeah, this survey actually highlighted that a significant majority of organizations that have adopted a cloud-based Sim to gain advantages like faster deployments scalability cost reduction about 80% have now gone to Cloud at this point. It's really good news.
However, half of the respondents that took our survey operate more than one sin today and that's there's reasons for that could be because of a corporate merger and acquisition. They have Legacy tools and Technologies, but what's interesting is that those that have one platform worse about 64% of them were very confident that they could detect a Cyber attack just based on adversary Behavior alone and that that figure continues to decrease for those respondents that had one or more platform. And so you take talking two three Sim platforms lastly.
There was a small percentage about 4% of our respondents that actually reported that they don't use a SIM at all. Yet 81% of those those respondents were still confident that they could detect a Cyber attack. So there were really four main themes that were revealed from this survey.
Number one was that prevention is a focus over detection yet reaches are continuing to rise number two is that the confidence is prevailing until it comes time to go talk to the board. Number three The burnout's Reel and we're seeing that over and over again and then number four is around compromised credentials. I can't repeat that enough compromise credentials compromise credentials.
Absolutely, you know, I'm surprised to hear about the multiple Sims because generally look in my experience. Just standing a Sim up and getting it working is is no trivial matter. Right whether it's in the cloud.
Which has made it a little easier or or on-prem right standing up a Sim and connecting all the various feeds and so forth. I mean the idea of having multiple stems kind of boggles my mind. I get it, you know holistically you buy a company.
They had it same you buy another company. They had their own Sim now of a sudden we got two three different platforms, but I would think one of the top priorities at that point would be to consolidate. Yeah, that's really.
Yeah, absolutely. And it's it's difficult to do. So because to your point when you when you're spread already thin and you have multiple Sims that are monitoring different areas.
It takes a long time to actually go and invest in order to consolidate and centralize on one sim and what happens then is it may become so hard that folks move to focusing on just prevention prevention in some cases can be easier to implement, you know for almost 40% of our survey respond and said that prevention is the most important security goal that they even have and the difference in their security goals between preventing an attack versus being able to detect investigate and respond to it. Just highlights that ongoing debate between prevention and detection I think Those who prioritize prevention they're trying to keep the attackers out, but the breaches are inevitable and they're not able to detect and/or respond to them quickly. So I'm not saying prevention is is not a good thing to focus on prevention can be effective in stopping most attacks, but it's not foolproof and attackers are going to find ways in so you have to also focus and take a balanced approach that incorporates both prevention and detection which is one of the most effective ways to mitigate cybersecurity risk.
I just Tyler I'll be honest with you as being you having been in the security space a long time. I'm surprised the prevention number. Was that low, you know, if you would tell me 50 to 60 percent said it was the most important thing.
I would have said that seems reasonable 40% seems like hey, but make them progress because you know for two longer period of time it was all about prevention. We had this notion that we were actually going to be able to prevent. You know the over overwhelming majority of attacks and and getting people to say no you got to talk about response.
You got it, you know, you got to focus on response. You got a budget for response you got to detect and response has to be Where you where you're you know bread and butter are. I mean that was that was.
You know wasn't always a given. Right, and so we I think we have made progress. I'm not sure what the right balance is between prevention and then detection and response.
right You know as you see so of actually being where do you think what is the right kind of balance there? It's it's not just a balance of a goal. And so our respondents about that 40% said that's our number one security goal.
But now you're looking at closer to the 70% range of respondents. Who said hey, the majority of my budget is focused on prevention tools. So, oh it is eventually it's still the most so it has changed.
You got me excited man. So, all right. I mean, you know, I think that the fact that most of these respondents are citing that they're unable to prevent bad things from happening and they said it as being one of the worst parts of their job makes them at least aware of the limitations of a prevention focused approach and you know going back to either multiple Sims or just overall the inability to gain visibility and again, that could be because of a Product integration issue or the inability to centralize that could also be hampering them.
They can't centralize to begin with they don't understand the full scope of a security incident. They're being flooded with false alerts all of that can contribute to this feeling of being overwhelmed and burnt out. I think that that also leads to the Lesser focus on the detection because it's hard it is hard to do.
So to answer your question. I don't I don't think there is a, you know, a tried and true 50% 50% prevention versus detection. You have to keep that constant pulse on your organization and your risk posture and tolerance on where you need to to apply prevention versus detection type Solutions.
Yep, I mean look. It's easy to say you need it all I want everything right but it but it's a case where I think you do need to put resources on both sides of that. You mentioned credentials forged credentials credential security is being Really a number one job?
Wait, you know, I think I think quite frankly the rise of the cloud. Has made identity and access management intense credentials and so forth. The killer app of cloud security right and and there's almost a bifurcation is identity.
And then there's access management. They're not necessarily 100% the same why you know, you you gave it a ton of emphasis. Why?
So you already mentioned Cloud, you know mobile devices is another big one remote work is another big one but that is a major theme that was highlighted as a major concern from our survey. We had 90% of our respond and say that they have dealt with or are dealing with compromise credential cases. And so I think that highlights they overall severity ubiquity of this issue.
It's a very common tactic and it's used by an attacker to gain unauthorized access with a legitimate account. Right? It's it it becomes just almost too easy.
It's it's very easy to obtain credentials from from users and social engineering and tricking them into providing access, right? It's all due to like you said with identity and access management. We're the use of week past words, Maybe.
Are not using multi-factor authentication and just the overall poor user security awareness. All of that needs to be taken to account. So implementing strong authentication mechanisms, like multi-factor authentication prioritizing security training not just on strong passwords, but also how to avoid phishing emails and then lastly employing your technology like with you know with actually being Sim and having user and device behavioral analytics to be able to detect when compromise credentials do occur.
a great I mean this this is a real problem and I think you know as an industry. We're still kind of. Coming to grips with the whole zero trust thing is I think part of that as well.
You know Tyler with every survey that's and I reported on a ton of them been involved in a lot. There's always sort of one question or one response that the the respondentsy gives you sort of. Wow.
I wouldn't have thought that maybe it's counterintuitive or it just surprised me. Any any kind of surprise to you in looking at the survey like what was kind of maybe unexpected? to see and it also for some self-reflection on just how how real the burnout is and the concern that all Security Professionals have around burnout certainly because of things like the, you know, false alerts or blind spots that can cause mental fatigue.
I was actually very surprised by the number of respondents. We had close to 85% of our respondents that said they were concerned about burnout from productivity issues like alert fatigue or overwork and over half said that they were extremely concerned about that and you know, you take some self reflection as a sea so to see you know, how am I feeling about my day today? How's my team feeling about their day to day?
How much do I put Reliance on a single analyst right that was another big thing is am I putting too much pressure on a single individual what happens if he or she departs the company or gets sick. It has to go and extended leave Etc. I was very surprised by by how how real of a concern that was for our respondents.
Unfortunately, it's been a concern in the industry. I had the pleasure of injured of interviewing a woman a couple of years ago, Dr. Christina Maslow.
I forgot what university she's with I think out in San Francisco area and she's like one of the preeminent authorities on workplace burnout and burnout is real right bearing out Israel. It's a recognized from the World Health Organization. You know, it's a recognized.
Not a disease, I forget what they call it simple. Whatever. It's recognized by who?
And in the security industry we are. doubly susceptible to it right because You know it it's just the nature of our Beast. Yes.
That's the desensitization because we're flooded with alerts and You know and there's more security issues than we could deal with and it becomes a question of triage like working in a mash Hospital right ones who are gonna die. I got to kind of Let Die who can I save and making those kinds of decisions our prioritization with because I don't have unlimited resources. But on top of that the nature of our business.
You know, the bad guys are so bad, but they're so smart and they're so well organized and it's and it's like we're always playing that Mousetrap game where where the cat but the mouse is one step ahead and and after a while it just grates on you and it's just man and and see so even more than the analysts right because the, you know the pressure of being a sea so and answering to the board and and you know the exact team and making sure I mean quite frankly you don't wind up in jail for covering something up or something, right? There's no doubt. There's not a doubt in my mind burnout Israel.
And it's one of the major problems we face in our industry. So I you know. It's crazy.
It's been happening and it continues. I don't know what the answer is. I mean that that's and I don't know if you know what the hell or have any guesses what we could do, but it's it's a real problem.
That's for sure. Yeah, and and I I've said the same thing that you just said, it's a cat and mouse game and and unfortunately there is decentralization across your security operations teams as well not to mention the pressure placed on security leadership. My my only the way that I think about it is more from a kind of a mental state of there's no Finish Line.
Yes, as you remove that that thinking of there's there is no Finish Line every day. Something new is gonna happen whether it be some detection within the Sim all the way up to the next, you know, third party data breach that you're reading about every day. Something new is gonna happen.
There's gonna be a fire you have to put out or just something that you have to address and that mindset knowing that it's gonna be something new. It's never gonna stop. It does help try to you know, at least avoid the the trend towards burnout and knowing that that this is the this is the nature of the job and accepting that does help with respect to how you think about your day to day.
Yeah, I think part of it is what is wind look like right what success here? Because we have a weird job. If you don't if nothing happened we did our job, right?
Oh, we think we did or we just got lucky. But but if nothing right when something happens, it's usually bad and and that that that's part of the nature of it, too. Anyway, man, I'm sorry for getting on my soapbox.
I'm gonna get off of that now and give that guy here where can people go get more information about the extra beam survey. Yeah, so we published the survey on our website and we can absolutely share that as well. com the surveys posted there.
We also released a LinkedIn live session along this and and had a few other folks from exube Come Together discuss the survey and some of these key findings as well that are pretty interesting. So, so please check that out. com.
Excellent. Hey Tyler. Thanks for coming on the show.
Thanks anything you guys have? Yeah, anytime you have some news or stuff. You want to talk about come on back.
Wonderful. Thank you so much. Alrighty, you're gonna be at RSA conference.
Planning on it. Yeah. All right.
Well, we're we're streaming live all week from there. So if you're there come on by and we'll try to get you on one, right? All right.
Tyler Farrar here on Tech strong see so it texted me. We're gonna take a break. We'll be right back.