Cyber Response Automation with TacitRed’s Jeremy Turner
Jeremy Turner, who is head of cyber and risk at Cogility TacitRed, discusses how security operations teams are under mounting pressure to improve their security posture and automate cyber response, and where are we today with continuous threat management and threat intelligence – The Good, The Bad, The Ugly… And The Future
Transcript
This is Text Strong tv. Hey everyone, welcome back here to Techstrong TV for another segment. Our next guest, first time person here on uh, Textron tv.
It's Jeremy Turner. Jeremy is the head of cyber Risk of cyber and Risk, excuse me, at codility. Jeremy and I should mention local South Florida guy here.
We could've done this in person. We may do it next time. Jeremy, welcome to Techstrong tv.
It's great to have you on. Yeah, it's, uh, really, really happy to have the opportunity. Um, you know, this is, it's great to get this message out and I think that, you know, especially what we're doing and kind of is part of a fundamental shift in, uh, cybersecurity strategy for specifically for different types of threat intelligence analysis.
Um, you know, I, I have a, a long background going back into, I've done some defense contracting doing, uh, computer network defense operations at the Pentagon. Uh, worked in some management consulting for, you know, different international conglomerates. Um, was part of a, uh, kind of unicorn startup called, uh, coalition, which is a cyber insurance company.
So it was a, in the very early days of coalition through the, the fun rocket ride there. And, uh, my role was, was really doing, um, uh, automating the underwriting process and bringing as many different intelligence signals as we could to understand risk better. Um, and it was actually when I was at coalition, I had this idea that, hey, why don't, why instead of like just underwriting one company at a time, why don't we just underwrite every company in the US market continuously?
Um, and this is kind of a thought that I got stuck on, and of course everybody thought it was crazy, but I, uh, I found a really good technology that I thought could really enable this. Um, and it really represents a fundamental shift in, uh, how analysis is done instead of storing all the data and then querying it. Um, you know, what we're doing at Coil with Tat Red is really processing all that data in near real time.
And because we're processing data streams, we don't have to store these immensely large, uh, data sets. Uh, we can do all of the analysis in real time and we can persist the facts that matter and the rest of the data, that's just noise. We can just let it go.
Um, so this really enables that much more scalable approach to analysis. And I think this is kind of a, a trend that's gonna be emerging more broadly within the, the cybersecurity industry as a kind of a fundamental change to how we do intelligence analysis. 'cause everybody's overwhelmed with data.
Absolutely. Well, the, the, there's overwhelmed and over budgeted, right? Absolutely.
I mean, and and there's both of those, you know, it's interesting. I, um, yeah, I've been in cyber 25 plus years myself, I exp founded a couple of security companies. Um, it, it, it, it never ceases to amaze me.
You know, no matter how many dollars we throw, no matter how many new shiny objects we come up with, we, we, we, we kind of fall into the same hamster wheel pattern of, of, of what we do here. And, you know, uh, it is what it is. Now.
Cyber risk insurance is something, you know, look, I've seen the rise of it, right? I remember I had started a company called Still Secure 2001, and one of the early things we came up with back then was, look, if you use our product, we'll insure you up to a million bucks or something. You know, if something happened and, you know, there were no cyber risk insurance companies, then you couldn't get really Aon a ON was the only company back then.
And they, you know, they had so many, you know, distinguishing loopholes built in that you would never get paid from them. But now we've seen that cyber risk or, or cyber insurance has really made for the, you know, risk, cyber risk a real thing. And it's had of an actually a positive effect on the industry because in many ways they've become the arbiter of are you doing enough?
Are you, what you're doing is reasonable, right? Because that's always the, the, the, the the measuring stick. Is this a reasonable thing?
And do you, do you have intrusion prevention or do you do regular vulnerability management? What's your endpoint security? You know, all of the things that good security hygiene, cyber hygiene are about.
Um, and now you've taken this a step further, right? With, with it and, um, with task originating where underdoing the whole thing, how are you doing? I mean, obviously in that kid palace trade secret, but how are you doing that?
Oh, Yeah. I mean, I mean, it's a great take on, you know, the rule of cyber insurance as a, you know, as it fits into the ecosystem. And I think it really speaks to, you know, how free market can actually kind of self-manage.
You know, we look at the evolution from where insurance was, you know, some cyber stuff was kind of crime policies, and then they decided we wanna exclude those things. So then that along came standalone cyber. Um, and certainly, you know, for, for businesses out there, I think it's probably the best cybersecurity product you can buy.
And that's really what I, I look at cyber insurance as a, it's a product, um, because it'll actually, it's actually going to help you recover all the other products, try to prevent everything, but in, you know, the insurance coverage is the thing that's actually gonna get you back on your feet and, uh, you know, get the business back functioning. Um, you know, and, and it was really, you know, I I look at the, the fundamental, uh, reasons why we still have, you know, even when we have all these other measures, cyber insurance, new cyber products, everything else, we still seem to be suffering relatively the same amount of losses. You know, it's, it's shifted around a little bit, you know, for, you know, the, the folks that are weaker better, the brunt of it versus the ones that are more sophisticated and have coverage and have good, you know, monitoring programs.
Um, but where we still see a lot of, uh, the losses occurring are in those small to mid-size range. Of course, you still have the big yes issues all the time. Yeah.
But it's, it's typically even those headline breaches, if we look at 'em, they're usually, it's a smaller third party supplier or contractor that's still, you know, what's really causing the issue for those, those big headlines. Uh, and that's really where, you know, we can shine as a product with Tassa Red is because we're looking at every single company that's out there. It doesn't need to be a company that's applying for cyber insurance.
It doesn't need to be a company that you, you know, you have as a supplier currently. Um, you know, you can put punch in the domain for any company out there, and you can immediately get not just what's there today, but also what's been there the last couple years. Um, and you know, when you're receiving updates on that, it's, it's, it's real time.
So as soon as we have the data that matches a certain condition for that risk profile, you'll see it populate immediately. Um, but I think that's a key differentiator. You know, it's like that, that's one of the things that you can only do with stream processing.
You know, a lot of other companies, I think are doing, you know, batch processes where they collect lots of data and at some interval they update the information. Mm-Hmm. Um, you know, that's, it's, it's incredibly, uh, costly.
Um, so You're doing it in real time, truly in stream processing It in true stream processing? Yeah, we, it's, we could call it like stateful stream processing. Um, in some ways, you know, what we really do at a, at a very high level is we have all of the entities that we know about, uh, you know, all the commercial entities, and you can look at this like the left hand side of a Venn diagram.
Uh, and we also do the same enumeration process, understanding all the IP assets, domains, everything for the threat actors. So you have these two big sets, the threat actors and the companies. And then what we have in the middle is a whole bunch of different signals and different types of telemetry that can help us identify when there's an interaction or an event that correlates from what's going on on one side to the other.
Um, and that, that's a, that's a, a signal. And so we can, you know, both validate that and we can provide the context that, you know, hey, here's, uh, a threat actor, they have this info stealer or malware infection, here's the companies that are affected, um, and, and here's the information that you can use to remediate this problem. Um, so it's, it's really about providing much more actionable, very specific factual information, um, in a, in a way that's different from just traditional attack surface monitoring, where you see vulnerabilities.
Um, but, but as an analyst, you still have to make some analytic assumptions about what's the most important vulnerability, uh, what should I really focus on? And what we're trying to do is add in the context of what, what the bad guys are doing so that you can see the interaction, you can see their targeting process if they, if they've actually compromised something. And as an analyst, you know, immediately, you know, with all those facts in one place, you can see, oh, this is what I need to do right now.
Um, and I think that's the biggest difference. Um, you know, just like cyber insurance, we're really trying to help solve the problem that's in the industry. And we recognize that attack surface extends beyond just a company's network boundaries.
There's BYOD, there's third party suppliers, there's contractors, um, and what we're really trying to do is provide the solution to those companies so they could really manage their, you know, extended attack surface. Got it. Again, you know, one of the, at RSA this year, I think one of the cards I picked up on was that look for a lot of companies and RSA is a big company show, right?
So we're talking probably larger enterprises, but for a lot of companies, their attitude has been, you know, the security industry has been coming to the well year after year saying, oh, if I just had this latest new trinket, if I just had this latest new technology, this gadget, this training, this, this is the last time, this is really gonna move the needle, right? This is gonna make us more secure. And look, I, as someone who's been in the security industry a long time, I do believe it's a lot harder to get hacked today than it was, let's say 10, 20 years ago, right?
It's a lot harder. But that being said, our attack surfaces are a lot bigger. Uh, there's a lot more bad guys out there.
And when you look at the total number of attacks and breaches, incidents, whatever you want to call them, all of the money we've thrown at security hasn't fundamentally changed that equation. Now, one could say it would be a lot worse if we didn't put all that money into it, and I don't disagree, but if you're a business exec, you're saying, man, my security budget grows 12%, 15%, 20% a year, and I'm not any safer. What do I do to change that equation?
Yeah, I mean, it's, it's, it's tough to manage. Um, you know, I think in, in any of these cases, the, in my opinion, the the factor that's always kind of been lacking is a real integration between threat intelligence. And I know that there's an overplayed term in the industry, but like actual threat intelligence, not just data, but something that can actually inform a strategy or compel an action that's, it's obvious in a way what the risk is and the company can remediate it.
I think that business owners, you know, if they, if they could be informed properly, um, and they could really understand the risk and have real intelligence products to, to, to reference, um, you know, they'd be able to make much more, uh, you know, tactical decisions about managing that cyber risk. Um, because I do think that often, you know, companies are kind of flying blind and they're trying to guess what's gonna be the most effective security control or the most effective security product to try to buy down some risk in their organization. Um, but a lot of times they're just lacking good information in order to be able to make informed decisions or really develop a strategy.
Uh, and that's where I do think we have a lot of, uh, you know, reactionary spending, uh, more than, you know, uh, proactive spending that's spending in the right areas to make, have the largest impact. Um, and I really think that it's, you know, as an industry, we just need to evolve to produce better intelligence products that are geared towards enabling more strategic level guidance, you know, for the boards and executives, uh, where a lot of the threat intel products, I think are more data products and they're focused more on the SOC and like data feed kind of stuff. Um, and that's kinda one of the paradigms we're hoping to shift with TASA Red is to make this something where we can provide factual data in a way that the information can be interpreted by, you know, multiple layers of audiences within the organization, and that we're giving the defenders everything that they need so that when they report something, you know, it's not just a vulnerability or a maybe, you know, that they have something concrete, uh, supported by factual evidence that they can really use to make the case about what security controls or changes they need to make in their environment.
Sure. You know, Jeremy, I think part of it is that when we look at a lot of the threat management, you know, threat intelligence industry from a historical point of view, it, it almost seemed to be more forensics than it did proactive. Yep.
Right? It was like, Hey, how did that happen? Well, let me go back to the tape here and, you know, take a look and, and figure out how, you know, how this took place.
Um, and now, you know, there are, and then there are threat intel folks who would, you know, rewarding and giving you that advanced notice. But, you know, the whole idea of just storing all of this information and data so that I could do forensics later on or something and, and pay a fortune of money. Yeah.
And doing so, and I, I, you know, when we talk to executives who say, I've spent too much money on security, it's that kind of stuff that I think draw drains the bucket of budget there. It, it gets, it's, it's just a never ending thing. Let, let's talk it.
So COIL is the name of the company, tat Red is kind of the product or service, um, venture backed company at this point, or still, you know, early On at, at this stage, we are, we are backed by a, an amazing group of investors. Um, you know, we're, we are not venture backed currently, um, but we have some, some really, uh, really good investors that really committ Like strategic folks or, Yeah, these are strategic folks that are committed long term to the company's success. Um, and they've, you know, anytime that we've, we've needed to, you know, funding for a new, you know, project or to support a new contract or something, you know, they've always, they've always come through.
Um, they've really, how, How long are you doing this? Um, so I've been a part of the company for about two years. I was originally came on as an advisor and then, uh, you know, got in the weeds full time.
Uh, but COIL has been in this space for about seven years. Um, okay. There's a, there's a longer tail behind the company.
Um, they did a lot of work in the defense, uh, industry doing things like counter IED detection, but always on themes of intelligence analysis and then, and data processing. Um, and really I think that a lot of those contracts were more like, you know, you know, build to fit a solution. And what they developed over the last seven years is a much more robust, universally applicable, uh, system and process for doing stream processing.
Um, where instead of having to have developers, you know, developing the code to deploy it, to analyze certain data, um, one of the greatest strengths, and the reason why I joined is that COIL has an interface, uh, that's a no-code interface that extends all that capabilities of doing real-time stream processing to analysts. So I can, you know, as an analyst, I can go and develop processes and patterns and a, and a user interface and deploy them, uh, without having to write any code. Um, and that's something that's enabled us to accelerate the development of the TA at Red Product, you know, very rapidly, uh, is because, you know, we can, we can sample all kinds of different data sources, we can integrate them and, you know, the integration process of a new data source is less than a day.
You know, we develop the patterns, we deploy it. Um, and if I think if we had to incorporate a traditional development cycle of engineering to go along with these processes, you know, this is something that could get drawn out for years easily. Um, you know, where we've been able to do that in a much shorter period of time because of all the work that went into the product, uh, by the coil team.
Uh, and it's kind of when I saw it, you know, I immediately fell in love with it because I realized I can analyze all those humongous big volume data sets that just have a, a crazy signal to noise ratio. Things like DNS and net flow and other stuff where it's just like, you know, you're, you're, you're drowning in data if, and especially if you try to store that it's incredibly expensive. Um, but now I saw a solution where I don't have to store it.
I can, I know what I want to look for in this data. I can design a pattern to identify that condition. I can deploy it, and now I can stream, you know, terabytes or petabytes worth of logs and distill that down to the, you know, couple hundred gigs worth of findings that are actually interesting.
Um, you know, it makes those data sets that are unruly, um, very easy to tame. And, you know, that's, it just makes the internet feel much smaller when you can really accomplish, you know, analysis, tasking at that scale. Um, you know, you're, you're really not restricted by, oh, we can't handle that, or we can't ingest that, or we can't deal with that.
And instead you're, you know, coming up with, oh, wow, we can, we can find this in there. We can, you know, there's a lot of different ways you can, um, um, you know, get value out of different data sources like DNS and NetFlow, where traditionally, you know, the, you're dealing with such a high volume of data in very low reward, uh, you know, when comparative scales that, uh, it hasn't really been feasible before. Very cool.
Jeremy for people wanna get more information on coil. What's the website? com is the website.
Uh, and this is, uh, co G-I-L-I-T-Y. Correct. com is the, uh, okay.
The cyber product. Uh, so it's, it's this kind of like it's own little product. It's been kind of shrink wrapped into a SaaS solution, uh, but it's still powered by the same technology on the backend.
Uh, it just enables us as a product team to move very rapidly whenever there's a new condition, new group of threat actors, new data source, whatever it might be, you know, we can integrate that stuff and get it into the platform in days instead of months. Uh, so it's, it's, it's great it for us on that product side. Very cool.
Yeah. Good stuff. Hey, I wanna thank you for coming on.
Um, sounds like interesting stuff. You could more than welcome, as I said, pop in here and we can continue the conversation in person and keep our audience up to date on the latest goings on at tacit red. Yeah, I'd love to.
Thank you very much. Alright. Jeremy Turner, head of cyber and Risk at Coil and their tacit red kinda security SaaS product.
com. We're gonna take a break. We'll be back in a moment.