Cybersecurity Context – Paul Giorgi, XM Cyber
Paul Giorgi, director of sales engineering for XM Cyber, explains how the acquisition of Cyber Observer will add cybersecurity context that is often sorely missing.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Paul George who's director of sales engineering for exam cyber and they just bought cyber Observer which Paul is going to explain to us exactly how these two come together equals two plus two equals something like eight plus right Paul. All right. Paul Walk us through what's the driver for the merger?
What's going on? Yeah, so XM cyber, we do what's called attack path management. It's this idea of being able to figure out how a an attacker's campaign looks starting from a breach point and then compromising critical assets.
So we're showing how an attacker could leverage this configurations and user behaviors and leveraging things. I can vulnerabilities to get to compromise critical assets. So a really common question from our customers is saying hey, you're showing me all these misconfigurations and vulnerabilities and how an attacker could string them together and these four steps lead to this compromises critical asset, but I have security controls.
I've spent all this money on my EDR solution and my micro segmentation tools and my privilege access management solution. So there's all these security controls that they keep dumping money into with the hopes of kind of hey, we're fixing the problem, but it's enough of remediation to so it's not as much of a risk to us. The problem with what we were doing is we didn't have any way to weigh.
Is saying that hey this one attack path looks really bad, but we weren't really considering that. Hey, you have six of these really strong controls configured really securely that would probably never make it so that would happen. We just never really assessed that cyber Observer what their whole world is is they integrate from an API perspective with security controls and make sure that they're configured.
So now what we can do is through these attack paths, wait them saying that this one seems like it's more complex, but this one's actually one that should be affecting you the most because it is something that you don't have any security controls tied to or this one's really easy, but you have a lot of security controls preventing it from happening. So now our attack path management is going to be security control aware making sure that those security controls are configured in the right way to prevent the stuff that we're showing Could Happen doesn't ever happen. So that's the main goal which I'm really excited about because like I said a lot Customers are saying yes, that's a really relevant attack path.
But look at all this money. I've thrown in my security controls. I really wish that you would throw that into the equation of saying is this likely to happen that makes sense, right it does and do you think that a lot of times when people are describing things to be false positives there but they're really after is saying hey a lot of the things are getting just like the context or just not relevant.
So it's not necessarily that there isn't an issue. It's just that they're basically saying it didn't matter to us. So do we need a little more granularity into our viewpoints of what exactly is a security threat because otherwise I feel like, you know, we just throw spreadsheets at people and they Rebel Yeah, I think that you like look at Legacy risk-based assessment or is based management.
There has been a lot of those. Hey, here's a list of a million things go ahead and go ahead and deal with it. And that's really what we're trying to do with attack path management, but the focus has always been to give a perspective that an attacker has in the environment and our perspective always was correlating misconfigurations vulnerabilities and users Behavior to see what could happen from an attacker standpoint.
But now we have a whole other component into that equation like you're talking about being able to correlate to be able to say hey, but you have these security controls. So this is something you need to be more aware of or this is an attack path that is not really ever something that's going to actually affect you because of the way you have your security controls configured. I feel like there's more misconfigurations than ever.
But that just made me do you think that that's a function of we just have so many more things out there or is there something else going on? So I I completely agree with you the misconfigurations. I think is our world of SAS pass and IAS and Cloud adoption because there isn't as many vulnerabilities in the world of AWS like hey my ec2 instance and I've got all my things configured.
Yes, there are vulnerabilities within operating systems and applications within it but you think about like a this user role that has rights to this ec2 instance can be misconfigured to allow yourself to do things like privilege escalation. So there's a whole other Bucket of variables that we didn't really have to worry about 10 15 years ago because misconfigurations were usually things relegated to hey, you've got a misconfigured permission that was usually the misconfiguration or hey rdps enabled but you don't have Network layer authentication nla enabled on it. So you should have that it turned on.
Well well now we have this whole other world of SAS and paths and IAS solutions that have a bunch of just nothing but configuration and we have a lot of newbies in the space and not not talking about newbies being a bad thing. But in the world that we're living in there aren't any 20 year cybersecurity professionals that have experience with an a/bus like they just don't exist because 20 years ago. No one is really doing Security in AWS.
That wasn't something we need to worry about. So now we have not a lot of familiarity not a lot of talent and then millions and millions of configurations where sometimes just one small one really is the difference between you getting compromised and being completely. Be secure so now being aware of that is a big thing when it comes to the world of misconfigurations.
What's your sense of is observability coming to cybersecurity we talk a lot about observability in the sense of devops and maybe even devsecops. But you know, is that now shifting to the security side of the house who wants to also be able to see what's going on? The world from the security side has gotten bigger as we're tying things into devops you look at like cicd pipelines and security controls getting built within those pipelines.
That's an area that we really didn't have to play with before most of the time security teams are really relegated to maybe some web application scanning maybe a little bit of like source code scanning. Like Hey, we're going to Tech sequel injection in the source code and then make it you aware of it before it actually gets to post but now we're tying into these pipelines and we're able to stop the deployment of code to production because of things that are not aligning with the way the security team should be working we're saying hey, there's a vulnerability that is in this open source module. There's a vulnerability in this code.
We're going to not allow that to get into the doctor. So I think overall the security team Visibility or observative observability has gotten a lot bigger. So yeah, there's a lot of other things to really for the security teams to be aware of and check that really weren't within the scope of security before.
We talk a lot about shift left these days. How automated do you think all this will get and do we need the shift left or can we automate things to the point where developers can just focus on their code and they don't need to be cyber Security Experts. Yeah, I've I've had a mantra there was a friend of mine about 10 years ago who said one thing to me that stuck with me says if it's not automated it's broken.
I think that we've now continued to see that that's the world that we have to live in. I mean, we just don't have enough cybersecurity professionals to investigate everything. There's not a lot of ability for us to carry out playbooks the way that we need to correlation of a different events and even the development and security from like a a proactive approach is something that we we just have to have automated.
So yeah, I think that we're seeing that starting to take off you look at like security orchestration platforms that are starting to get a little bit more more attraction. You're seeing this shift away from Legacy investigations within like simpliforms and really tying into this whole response around. Hey, this was this type of events we run this Playbook and all of that be automated in a sense that there was thought into every single step that needs to play out.
It's put together in a way that's automated and all these things are happening at a really fast space and Now these analysts are just providing input on how to do the playbooks and then monitoring as the playbooks are happening. So yeah, there's definitely a shift to be able to have it more automated and there's a lot of reasons for that. But I would continue to say it again and it's never more relevant today than it was 10 years ago if it's not automated it's broken.
Um, do you think AI will play a role in all this in the future? And what is that gonna look like? Man, that's a million dollar question.
I hate using the term AI machine learning. I think like there's so many people are like, oh you said AI. All right, like another marketing buzz word.
I just was at RSA a couple weeks ago and it would be fun to walk around the vendor booth and see how many times you hear Ai and machine learning. We all know that it's it's the Manifest Destiny of security like, yes, we would love that to be a to play a role in it. I think we've still got a few more years before that actually plays into everything.
I think that most commonly we're going to have to leverage like supervised machine learning to start like getting all of the analysts feedback and decision-making and then train these machine models say like hey, if this happens, this is our response and then this type of response happens from that then we have to shift and then be able to accommodate this new strategy. So I think yeah, it's going to eventually be here but I still think we got a few more years before we actually start using the term AI with an attack path management for right now, I think overall attack Task management and within the world of like what cyber Observer is doing to complement it is just giving the both red and the blue teams inside into attackers playing out within kind of their perspective and how we're going to leverage that within AI. I mean, there's a ton of ways that I could speculate but overall.
I think that we still have a a few more years before attack path management gets the AI of fight if that's a term. Do you think that we don't spend enough time thinking about things from their perspective of the attacker and that all our focus is a kind of on that, you know, let's defend the perimeter per say but we're not really thinking through the way an attacker would think about things Yeah, there's a guy over at Microsoft. His name's John Lambert and he has an awesome quote.
I like to refer to it when I'm thinking about your question. It's this idea or the way, he says that I'm not gonna be able to quote it exactly but he says something along the lines of Defenders think and lists and attackers think and graphs until we start thinking the way Defenders are thinking we're always going to lose and I think that that dials down into the core root of the problem that we're starting to see where we've been generating millions and millions of or list with millions and millions of lines of these are the vulnerabilities you need to fix with this myopic view around a log for Shell or spring for shell and log4j and Felina that just came out a few weeks ago. I have to patch it Without Really any awareness of how an attacker would operationalize that vulnerability then also correlate it with some sort of other misconfiguration or vulnerability or just a problem with insecurity and then be able to use both of those two together to compromise critical assets.
So yeah. I think we have to shift the way that we're thinking and start looking at things the way an attacker would and that isn't in the form of a vulnerability list. That isn't in the form of a cspm tool and whether or not I'm PCI Compliant like these things are really important, but overall, there's this perspective of how an attacker thinks that we really aren't considering and I think that that's definitely something that that needs to change for us to really be secure and really get the benefit of all the tools that we're using all the effort and can making sure things are secure and just making sure that we're staying up with the world that we live in if you think about like filino that just came out a few weeks ago being able to say how many machines are vulnerable is one thing and that's old world thinking that's the list I'm talking about.
But if you look at the way attackers looking at is like how can I use this vulnerability to be able to carry out an extra step in a campaign that I couldn't care out yesterday and that's that the Opera realization operatizationalized. Oh man. I'm trying to make a crazy order the operationalizing.
A new vulnerability within a bigger campaign and assessing the risk and assessing how that new variable in that larger equation is impacted by that new variable and so being able to say hey Felina came out. Yes, we have these these machines but this is the risk to me and this is the risk my critical assets and that's something that I think that most organizations aren't doing for the most part today and I think would have a huge impact in just assessment of risk understanding vulnerabilities in the landscape understanding how secure their critical assets are fortunately most organizations only get that perspective when they're dealing with some sort of issue. when there is a real ransomware campaign when there is some sort of data breach then you look at this and go like Man, it was only three steps to compromise my critical assets and it was this really basic one correlated with there's really other basic one, too.
I wish it would have known that by before and if you talk to anybody who's dealt with one of those big breaches you the the term I wish I would have known that or I wish I would have comes up all the time and we're giving that perspective. So you never have that situation of I wish I would have known that or I wish I would have done that because you now have that that perspective before it becomes a problem. Well, what is that one thing that you wish people would know before they got started so that you didn't have to constantly answer the same question over here.
I have that one answer if the answer was just 42 or whatever. The answer is to that big question. Then we would all be out of a job like in every environment it's different and everybody struggles with different things in our solution.
We have remember at those three buckets. I was talking about the misconfigurations of vulnerabilities and user behavior on the main dashboard. It shows you what your main problems are in the environment and I have a lot of perspective and a lot of different tenets of ours and the different environments and it's different in every single one.
Some organizations are really good at patching and there's not a lot of vulnerabilities. Some are really really bad that just basic configuration things like local passwords and cash credentials and just AWS access key sitting on people's desktops and SSH keys that don't have past phrases on it that are just accessible for anybody to take that then expose a 5,000 node kubernetes for I'm like there's stuff like that. So every environments a little different but if you get that perspective of okay.
I wish I would have known and if I can look at these are the things most impacting me, at least you're doing that due diligence of assessing kind of what the environment looks like. What is the most riskiest entities in my environment? And what are the most likely attack paths and doing something about it before it comes a problem is a is a discipline that I wish that more people would adhere to All right.
It's combination of Art and Science. Hey, Paul. Thank you on the show.
Yeah. Thank you. All right back to you guys in the studio.