Cybersecurity in Israel – Rubi Aronashvili, CYE
CYE CEO Rubi Aronashvili explains why so much of cybersecurity today revolves around Israel.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Ruby our on a Chevrolet CEO. Forsy. They may tools that help you figure out what your actual level of risk is and we're gonna be talking about the difference between the US and Israel when it comes to cybersecurity Ruby, welcome the show.
Thank you very much. Loving means my pleasure really looking forward. It's often difficult to make comparisons, but I am curious.
I mean Israel, of course has a rather large cybersecurity industry at this point, but what is the difference between how organizations and Israel approach cybersecurity and what you guys may see in the United States? I think that the industry in Israel is actually relatively loud as you mentioned with I think that most of the Israeli companies I'm not targeting the Israeli Market as the men the main target, you know, so when you see a lot of Israeli Solutions Technologies are being sold to the US so on the protection side, I think that the US maturity in general or us organizations majority is something that is evolving very rapidly. However, I think that the main difference is maybe coming from the perception of security right in Israel.
One thing that is Very clear here that people are going in a journey that starts with the Army and in the Army you learn a lot about how security from physical security and then cyber security how important it is. And then it's you know something that you see in your culture. So the behavior and the concept of cyber security is part of your daily or standard operating procedures.
That's something that you see more. However, we have to say, right they also in the Israeli Market you see a lot of situations in which organizations are by definition immature in their approach and I'm doing less than required in order to protect the organizations think that one advantage that we have maybe is the size well much smaller than the US and the US, you know is A huge country with multiple multinational organizations are very interesting Target for attackers and that's it starts with intent. What people are trying to achieve and also the size factor that is by definition correlated to how vulnerable the organization can or is there can be or is you know when it comes to cyber security, but if you ask me the number one difference between the countries will be maybe that coach that is you know integrated in the Israeli culture.
That's something that in in the US it's a little bit in a way less in the culture, but I have to say that organizations in the US from cyber security standpoint there become more and more and more mature actually World leading when it comes to cyber Security Solutions and capabilities. Do you mention that fact that everybody in Israel is in the armed forces at some point and maybe that everybody in the country is more used to being on something that feels like a war footing. Do you think that we in the US maybe you're not quite as cognizant of the fact that so many folks are trying to attack us and we just don't think it through all the way to it's logical conclusion.
So I think that Wellness into US is definitely high. But again, it's very hard to be honest, right? It's very hard to To protect organizations in the size and scale that you have in the in the US just to explain that for second the difference between being and an offensive player right to be a defensive player is a quite a significant difference because as an attacker, you need to identify a single point of several points in which you can get access to the organization and you know pay your way to the business critical assets as a Defender.
You need to anticipate everything in order to make sure that there is no let's see mistake get misconfiguration that you left out that will be then used against so it's really not a fair game. Now, I really think that the majority level of the US is improving significantly. I really think that the awareness is there and we see that by our daily walk.
I have to say right we're walking a lot with the US based customer. You see that the consideration cyber security considerations are now part of the board discussion. There's something that you need to report to your board on a continuous basis.
So definitely something that is there and from the federal perspective of federal government perspective. We see also changes we see President Biden coming with a different proposals on how to improve the connections between the government and the industry. So things are really focusing there.
But again the size the the magnitude of the organization of the country still something that is very hard to protect them. So, you know when you compare it to Israel in Israel, it's much easier. There's a lot of talk these days about maybe becoming more offensive in our defensive approach and maybe going after some folks.
Are you starting to see more organizations? Yeah thinking about going after Bad actors themselves, or is that just generally a bad idea? Um, I think that there is a motion in the market.
I hear a lot of Buzz around let's be proactive and try to to attack who is taking us. They think that is an idea. It might be an interesting one or whatever.
I think that the main problem that you have first is that in some cases. It might be significantly problematic. Keeping it.
Just as an example. Let's assume that an attacker is compromising an asset in an organization. That is a legitimate organization and attacking you from the Now you're trying to attack back.
You're going to attack an organization. That is. Right.
It's part of the process, but the organization was is not your target. You know, so trying to to attack back might have consequences that are starting from. Let's say just disturbing other organizations and can come to a false illegal things that you're able to do to other organizations.
So that's not that easy. And generally speaking. I think that being proactive if you already want to be proactive people active on yourself try to anticipate whether your gaps are and act accordingly other than trying to attack who is attacking you because First being able to detect someone that is attacking you that's already a capability that you need to develop.
Right? How do you know that you're under attack? That's something it's usually organizations know about it too late.
And when it's too late attacking back won't help you with this situation. You need to First recover the organization. So for my point of view as an idea, it's an interesting idea.
However, I don't think that will allow or provide a lot of benefit today victim organization already at the point of attack. It seems like to us at least that every time I turn around there's yet another startup company coming out of Israel focused on cybersecurity and the people involved all seem to have worked for some sort of Defense organizations. So yeah, is there people standing around with a lot of money handing it out as people come out of the military or what drives all that?
You know. because I think People compare again the US to Israel. One of the things that I think that is a huge advantage in Israel, not only with the us but in general in the world is that Israel Has Talent manufacturing engine, right?
And this is the Israeli Army the idea if you think about it the technology units in Israel that are quite large technology units and recording thousands of people. For every every year that means every year that they're coming into the army. They get training that is quite significant one and then six years later.
Usually that's on average you'll find these people after a very long training very intense training in the army that you get to play with the most Advanced Technologies you get out and then you you have a decision point right you need to decide either. I'm going to walk in a corporate or in an organization that I really want to be there. Oh, I'm going to be and more Innovative in a way and try to to create my own thing.
Right and that's something that you see quite a lot. So people are getting and The Innovation spirit in the Army because you you are getting this this kind of atmosphere around you because you're continuously pushed to invent more to do more in order to deal with the challenges that we have a small country against multiple enemies around us. You have to be Innovative in order to to really make bogus in in the world and in disciple security capabilities that we have.
So when you finalize your army service and you have those talents out there you have a very high percentage related with that are going to the own journey. And yes, there are a lot of organizations there VCS private equities that are standing with the money there and just trying to invest in everything that is coming out of the army. I can tell you that there are a lot of initiative and most of them are actually getting funding that's interesting to see One of the things we do here about all the time is the shortage of cybersecurity expertise there is and you know, maybe in Israel.
It's not quite as dire as it is in other places, but at some point should we be rethinking whether or not we as an organization want to enforce security or should we just Outsource that to somebody who's an expert in the space and maybe we should rethink our entire approach? I think that that's a that's a question that we hear on a daily basis. What makes most sense.
So I continue to answer is really depends on the organization. It's what stage organization easy, right? So also saying is something that can walk very well if the post says and procedures are aligned.
For example, right. Let's assume that you want to Outsource your cease seesaw as a service. That's something that we do as a company and a lot of companies are doing up.
involved in A procedures right in the daily operational capabilities and decision-making then it won't be as efficient. Right? So yes, that's something that can walk in the given structure.
But I think that the best structure that works today and that's based on our experiences the hybrid mode. So a lot of things you can Outsource because you need really experts and it will be very expensive to try and do that yourself and you know, if those are things that you need to do periodically or even continuously but then that requires really an expertise. That's one thing that you can Outsource but The overall Process Management the capability itself being able to report and measure yourself.
That's something that we usually recommend to have in-house because otherwise you have and we see that quite a lot. Unfortunately self-governing organizations. So you're also seeing everything it and security to a third party.
That's great. But then this is a self-governing body and when you come to a situation that you have an incident, then the people start to ask questions and then they say how can it be that we didn't have the element auditing there everyone posts us to to monitor what happens there everyone capabilities, you know to understand the cyber security maturity and so on and so forth. So my recommendation usually in this case would be have The relevant forces owners the capability owners in-house and everything that requires a special capability.
You can Outsource that's that's the way that makes the most sense right from a large organization perspective small organizations, by the way, that's different because you can Outsource a lot of what you do and that's easy because you're a small organization but in large organization, it's just it's very hard for that to completely without us. That's all my personal point of view, of course, so it makes about perhaps. Um, we also hear a lot about AI these days and there's a lot of people who are skeptical and there are others who are saying, you know, this is the future of the world.
What's your sense of where does AI fit in the cyber security landscape? What is the state of the art? And how good is it?
So no doubt that Ai and machine learning are very powerful tools that are being used and utilized in the industry quite a lot. The problem that I see is that with every tool that you have for defense think about the same tool being used in the offense side, right? And as I said, this is not an even game to start with and now you add those AI capabilities to the offensive players, for example, think about AI based fishing campaigns in which your collecting the data creating the emails.
For example, if you emails in an industrial way that is based on AI. The history that you'll get will be much higher and then you are able to walk in huge scale which will be very hard to defend against right, but then those capabilities are being used also on the defensive side. I can say that there is no doubt that the future of a lot of things that we do is based on machine learning and AI, however and with the progress that we make on the on the defensive side, we see that the offensive side is progressing faster unfortune.
That's something that is quite consistent with every technology break for that. We had in the past right every time we've seen a new tool or new capability that we thought. Okay.
That's great. That is going to help a lot in mitigating some of the risk. We've seen the same tools who used also by the offensive side and then you know, you haven't even game in a way think about Quantum Computing in the future where people think Quantum Computing will be great because we are able to and to and And load a lot of calculations and a lot of processes and processing on the data that we are collecting and do that in Quantum Computing.
But that works the same way for the attackers as well because once the data will or the capabilities will increase you need to then deal with a different level of offensive capabilities, you know, so the problem that we have that we have is in general. We plan Security Solutions for the past. And the offensive was always looking to the Future.
So that's a gapping that is built in the industry that we need to solve. So the technology focus in general is very good. And we say that those ai-based capabilities artificial intelligence in general is being used quite a lot but keep in mind that it's not going to change the game right?
It's just going to make it. Even more even because we are going to experience different level of of offensive capabilities. Um, what is the level of sophistication of the bad guys these days?
I mean we yeah tend to flip out every time there's a new zero day vulnerability and everybody runs around with their hair on fire and yet if I look at the breaches and the attacks, they are all still pretty much rudimentary stuff and stuff. We've known about for more than a decade. So yeah or the bad guys laughing out of this or what That's that's a very good question.
So, you know, there is a huge difference for my point of view between a zero day, which is maybe the foothold to the organization to the full attacks. And now that is then taking place. So as you just mentioned, right if you analyze the most common mistakes misconfigurations gaps vulnerabilities that we see exploited.
You always find the same. Household hygiene or use an hygiene? Right you find network segmentations segregation administrative interfaces that are exposed and you know privileged accounts that are being used.
It's always the same you see lateral movement you see and and compromise of privileged accounts. And then from this privilege account you get access today better than this is critical assets, whether it's when somewhere whether it's data exploitation, whether it's Integrity, whatever the impact is, it's always the same from some point. So yes to your question, there are basic things basic that are still not we see that still not being executed and done.
Correct, right? And again, those are basic hygiene things. We always say back to the basics, right?
If you have the basics, right then your cyber security majority will be by definition higher than what we see on average in the market. So the zero day for my point of view, that's not the one thing that you need to be concerned right because see what they will get you in. But then the fact that someone managed to get to get into the organization the fact that this is equivalent or equal to the fact that the full organization is compromised.
That's the problem was just getting the photo. If you're able to detect it, if even if you're not aware of the vulnerability because it's 0 you don't know that but the fact that from this point that I can use the same account to do lateral movement to execute their own tools command and control Channel and a lot of things that you can identify the fact that that's not identified all mitigated or prevented. That's the problem.
So zero day again always every time that you haven't opportunity to to mitigate it. That's great. But that's not the main problem.
The main problem is the basic things that we see the top five vulnerabilities that we see today are related to easy password or guessable password accounts that are not using multifact authentication. Then it's only possible base. Then we have Network segmentation segregation administrative interfaces that are exposed and in the end privilege accounts that are being used on non-privileged environments.
Those are the top five. Okay. So ultimately what's your best advice to folks as they kind of figure out their risk levels and spending levels and how to strike a balance.
so from our point of view the two critical elements in the posts. The first is getting visibility into the into the technical risk profile. That means Use an offensive point of view multiple organizations out there.
We are one of them right that are using either red teaming capabilities the penetration testing capabilities to map the risk profile. That means where I'm vulnerable and what is the least level of this vulnerability? That's a very technical discussion.
Second thing that you need to do is to correlate this technical data with the business considerations. In other world, assuming this attack scenario is going to happen What will be the impact to my business? And again, it doesn't have to be accurate on the dollar value.
Right? Just even an estimation that's significant damage non-significant damage. And so even this kind of analysis it's enough to start and at least prioritize in a smart way where you want to invest your your next dollar.
Today we see a lot of emphasis on. Let's call it compliance-based security. And I want to say that very clearly compliance is not secured.
If you have security you can have compliance that means that derived from security. But if you have compliance you don't have security. Right, and that's something that is very important to understand again compliance government regulation and so on all of those are good things in order to create some kind of structure but that's not enough right if you want.
If you go to the nest flame and you say you take the box right? You say hey EDR great. I have MDR great.
I have a cloud protection great. I have my sister in place. We are great.
That's not the case because the fact that you have the controls of the tools doesn't mean that you have the capabilities the fact that you have capabilities doesn't mean that those key capabilities are optimized that means that they are providing full coverage and the protection level that you need and I just remind you just need one mistake that that the attacker will be able to identify in order to get access to the organization. So for my point of view. Security First of all lists a continuous effort that's number one second.
You need to understand your risk profile said covid to the business and based on that make the decisions. It's it has to be at least and data driven approach. Otherwise it will All right.
Well Ruby, let's hope that we're all gonna collaborate more aggressively across borders to win this battle eventually, but in the meantime Circle those wagons. Hey Ruby, thanks for being on the show. Thank you very much.
My pleasure. All right back to you guys in the studio.