Cybersecurity Divide – Richard Barretto, Progress
Progress CISO Richard Barretto explains why the divide between cybersecurity and the rest of the business is finally starting to narrow.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Richard burrito. Who's the Cecil from progress? We're going to be talking about the historic divide between cybersecurity the business and for that matter the rest of it and what should be done about it Richard.
Welcome the show. Thanks. Thanks for having me.
This issue is playing this for longer than anybody can remember and frankly security. People are not always the most popular people within their organizations. Is the relationship between security and the business and if that matter even it starting to change for the better and if so why?
No, definitely has changed over the years and and security for 20 plus years and I've seen it evolve where security was just a cost center. And now it's it's being recognized as a neighborhood to the business and it has a line to the business. and how is the business side viewing security differently?
Are you feeling that those folks understand security or appreciated more in the wake of say covid-19 and digital business transformation initiatives, but is their mindset changing as well? Yeah, for sure, especially in high-tech and if you're you know, it's post. We're not even posted but during the pandemic a lot of organizations started going through the digital transformation.
And as as you call it or you could say your digital footprint widens out on the internet that just leads more opportunity for hackers to to either, you know, deface your website or you know, disrupt your business take it down. And so it definitely has changed the tension from from leaders from the board to your execs are now I would say understand security. It's it's an essential part of how they operate and it has the lines strategically with with the business strategy.
We hear the phrase enabler a lot and that's not always a good thing in certain contexts. So What's your sense of what does it mean for security teams to be an enabler of the business? How do you become one of those?
Yeah, that's great. It's a great question because you know for me it's if I can if I can help. The business secure their you know called their environment your network their the way the operate business so that for our customers especially enable trust because the way I've always seen security especially us being a software organization and providing Services.
We're an extension of any company in any of our customers so they have to trust us and if we can if we can't give that confidence and that trust and evidence of that trust we're gonna fail right we need we need to be, you know, we need to be aligned with our our business our strategy but also with our customers needs and obviously security is becoming that much more important to to the business and to our customers. How do you do that in a world where everybody values speed and flexibility and a lot of times security is viewed as getting in the way of those things. So how do you kind of strike that balance?
Yeah. It's been a journey to get there to get that balance. But degree thing I would say about especially with the technology now is that Has enabled that to move us faster the tools have enabled us to move faster.
And when I mean faster means we can now we even bake security through Automation and because now we have automation it wasn't, you know, we we're not relying on humans and humans will always be the the weakest link in the chain for security. So if we could if we can automate that and and we even bake security so that it becomes, you know, part of the process part of the design and it doesn't have to be an afterthought where it becomes much more costly for any business. We've done a great thing.
Do you think that there's also shifting left of security responsibilities is also changing some of the relationships between security and developers and it and it's becoming more of a team sport or people receptive to that idea or is that you know tough sledding still. It's definitely a team sport and they are receptive to it. Yeah for the longest time even even Security even put engineers and developers on the side even between it there was you would call tension between 19 Security net and that's gotten better over the years.
And now that's all beyond beyond the IT team. It's now, you know a developers even with the business and HR legal and so if we're not good partners, if you don't have good relationships, we're never going to achieve our you know, our comment objective and it is just I can't so the way I always when I talk to especially Engineers, they make more security decisions on a daily basis than I do as security professional and this is my main this is my main business is my main job and role but there they have hands on the keyboard. So they're constantly making security decisions.
So it is my it is my responsibility to be sure that they're equipped to to make good security decisions. We're not making decisions at all because It's already baked into the process and and that will hopefully, you know, especially through automation will allow them to faster. It's hard to talk about automation these days without bringing up the fabulous concept of AI.
We all think that somehow or other AI is going to save ourselves from ourselves. But what is the state of cybersecurity AI these days? What should we really expect?
Yeah. Helping you know AI means different things to different people. There's definitely some you know new technologies, especially a lot of startups coming up specifically in the AI space.
I don't know enough about it to say, you know, like I'm an expert in it, but definitely seeing some Trends and you know, we've got to just be careful that eventually AI will will be you know, a major thing in our in our environment. Do you think security people understand how business people think about risk and I'm asking the question because if you go to business school from day one, they teach you that every decision you make involves evaluating some level of risk and and they strike a balance for that and move forward and cybersecurity from their perspective. It was just one more type of risk in do you think that security people on the other hand seem to view everything with you know possible Calamity is going to end you any minute now, so, you know, how do those two parties have that conversation about risk and talk about the same thing?
Yeah, so I've learned to over my career that you got to live in the grace is nothing. Everything is black and white and even in Gray there's shades are gray. Right?
It really depends on the business. It really depends on the individual one of the one of the toughest Parts, you know, as I was growing into this role and throughout my career is is understanding what's tolerable to the business right from our risk perspective like dude, you know the concept of you know, there's a vulnerability and it's exploitable. But then when you start to you know, you start to decompose that say right?
Well, what's the likelihood of that? You know how exposes that the internet, you know, is it is it attached to critical assets? And so when you start to have that conversation do you compose what risk is like likely that impacted Etc.
You start to realize that yeah, there's there's certain risk you can live with I think we do it all every day, you know our daily lives, you know, like there's always a chance that someone's gonna break in my house or there's always a chance that someone's gonna you know break into my car. Or you know or even get into my bank account, but you have to have certain controls in place that gives you comfort to try to reduce that risk. My job is to try to communicate that risk of the business.
So they understand. Hey, here's the risk that we're living with also highlight the areas that we need to get better at risk, but also give them opportunities to make that risk tolerable for the business so that they they feel comfortable that you know, we have our we have our we'll call prepared for any potential attacks or anything like that. Our security teams kind of changing the way they evaluate risks accordingly because not too long ago.
The motion was here's a list of vulnerabilities and a spreadsheet throw it over the wall and you should mix all of these would know any context system What mattered and when and why and so surprisingly nothing had done. Yeah. I I went through that pain.
It was it wasn't fun and I didn't make good friends after that it you're absolutely right. I think what's missing is so security tools are designed to do one thing check if it's if it's you know, green or check if it's red. All right, it's it's very binary the thing that it's missing and this is the the art of security professional is you have to start to take in the context of the business.
You have to start to take the context of the operations. Yeah, we talk about how much it we have to translate risk to the business or security risk and Technology risk of the business, but also seeing applies by subversa to technologist. We need to understand the business and there is that they're taking and how does that impact the technology and decisions that we make around building our systems and so if you can do both and and have you know be that translator between both the business and technology, you're you're in a great spot.
As normal as all this sounds we are putting more at risk through digital business transformation initiatives and the bad guys are getting smarter and launching more attacks with more sophistications. So what's your sense of? Hey, are we are we winning or losing?
I you know to tell you the truth. I think we're losing. I think we're losing because the difference between so I started this and I started my career in the dotcom era, right?
This sophistication and the resources and the investment to learn how to attack an environment or a business is it's just it's just crazy. It's exponential. It's like a hockey stick and so like what I first started off early my security security career as a pen Tester the things that you're doing now today, especially with the tools that they have is far beyond what I knew what I was capable of doing and for me to just learn some of the techniques and tactics that they're doing today would take me years to to relearn What what we just again going back to your to your question.
I think we're losing in a sense that it's just there's we're now fighting against nation state. We're now fighting against, you know, organized crimes in the early 2000s. They may have existed but not as not as big as it is today.
There is there's definitely an economy around cyber security hacking and and threats and you how do you compete with that? And the only way we can compete against that is my job is to be able to defend my my house as best as possible to shift the most secure products as possible, but then also have good detection and response so that I can make it costly or for our attackers so that we become unattractive to attack. Is perfect security attainable or is that a pipe dream that we all have is part of this issue is instead of trying to achieve that goal.
Maybe we should just take a giant step back and say, you know, we need reasonable security. Now it's it's a pipe dream. It's like saying you're you're the World's free a crime.
It just it does not exist. However, there's a certain again tolerance that we have to to live with insurance controls that we have to have a place that we just make it part of our daily living right like we have locks on our doors. We have, you know security systems that are monitoring our our environment the same Applause Just there's no perfect.
You know, I think I forget who I'm sure one security, you know a famous security leader or an executive said the best way to secure something is just unplug it from the internet. And even that in my opinion, it's still it's still hackable. Right, especially if you worked in Aerospace defense.
There's a lot of folks who are dabbling security they get into it for a couple years and then they burn out and leave you've been at this for a while. What's your seat? Yeah longevity.
yeah, it's a real thing that I've been sitting in a lot around tables lately and One of the discussions it's coming up, you know more than more than often is US burnout not just at the Cecily like it. I think to your point is even Security Professionals now, like, how do you how do you again we're fighting this fight, right? There's threats all the time.
There's another log for Jay. There's another solar winds, you know, it's like your firefighting all day the key is it's first of all to get into this field. You have to love it.
You have to be curious. You have to enjoy it because if you do if you if it's just a job what a nine to five you're gonna burn out very quickly but having good work life balance. You're making sure that yeah, you keep you know, you you balance the amount of work that you have but also balance it with life and family and but you can't you can't consume yourself into work.
I think this just goes for everyone but for me if you enjoy your job if you're passionate about that's great, but good work life balance good, you know, like if you're medit, Need to exercising. I'm a big I love sports. So I put on a big tennis fan.
So I play tennis at least once a week and that that helped me is maintain. I'll try to get up early in the morning for a jog or do some like cardio that that helps maintain that stress levels and if you you know, it's all about, you know, balance between mind body and spirit. One of the issues of course is the bad guys got to be right once and the security get people have to be right all the time.
But do we need to change the definition of what winning is because it's impossible to be right all the time. So do we need the cuts security people a little bit of slack so they're not losing their months. Yeah, it's again.
It's having a good conversation with the business trying to trying to be empathetic to them. But they also obviously have to be empathetic to us and we're all we're all trying to work with, you know, you know, everyone will say yeah, I don't have enough time. I don't have enough research.
I have no enough money. Well, you can have all the money in the world. You can have all the resources but it doesn't what's the true value there.
So once you understand that value and then you can really focus on exactly what time and resources and effort you have to put around security. And Richard would you tell your nieces and nephews or Sons and Daughters to get into this field? Day, if they're curious if they have you know, if they have an attitude to it, actually I get a great story, you know, my brother.
He was a music DJ for 20 something years traveled the world. I think by the time he was 20 he had seen the world three times and so the pandemic really hurt his industry and hurt his his source of income and he came to me he says hey, you know, I I dabble a lot with technology and especially in the you know, production software and stuff like that. You know, do you think it would be good?
That's like, yeah. Absolutely. I think yeah the attitude you deal with applications all day.
Why not and then he started asking me questions about security and as like, okay. All right, don't do it because your brother does it I want you to do it because you actually like it then he goes. Well, you know, it's really cool about security and I see is that it's very Community.
It's a very tight community and it is it's true and he says it reminds him very much other music industry. It's a very tight community and Lo and behold he took a few tests. He got a job in it and now he's a cybersecurity engineer for for a major company and he's been doing it for the last I would say like eight or nine months and he's enjoying every single moment of it.
So I I recommend it for anyone that's that's enjoyed that enjoys it enjoys a good challenge. If there are problem solvers that they want to be creative and it's a dynamic field very like Technology's constantly changing. So, how do you keep up with those changes?
And I think if if you're a person who does who gets bored very easily. This is a great place to be and security is not just yeah. It's just not always technology you can be in security sales.
You can be in security business development. You can be in security training and awareness and education. Those are all great opportunities.
And you know, I I sit on a nonprofit and I'm trying to I'm trying to get the next level or next generation of Security Professionals, and hopefully, you know, I hope that there's you know, I can provide Opportunities for those for those next, you know next generation of leaders. All right. Well, maybe it's in the DNA.
Hey Richard. Thanks for being on the show. Thanks.
Thanks a lot. All right back to you guys in the studio.