Cybersecurity in the Age of Connected Devices – Jim Hyman, Ordr
Recently appointed Ordr CEO Jim Hyman explains what cybersecurity needs to start with a thorough understanding of an ever-increasing attack surface in the age of connected devices.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Jim Hyman who's been recently appointed CEO for order and we're talking about connected devices in the security there of Jim welcome the show. Thank you very much. Thanks for having me.
So what attracting you to order in the first place? What do you think is unique about the company and what do you think? Maybe you're gonna see in the coming year?
Yeah, thanks. So when I look at the security landscape, I spent the last 20 plus years in the security space everything from applications to network security Cloud security API security camera across the board and one of the things that we're seeing whether it's you know, it's going to continue is a is an obvious thing, which is this proliferation of devices and people all talk about it. I think when you think about the the actual volume of devices, it's more staggering when you when you look at the real numbers.
And from a security perspective, you know, I spent the last seven seven years or so looking at kind of a networking application Securities specifically as an attack vector and really thinking through the attack surface kind of what are people going after and when I looked at order, you know, they are trying to solve a different problem, which is the attack surface used to be thought of as your network perimeter now. It's thought of as your network as a whole and yeah these companies and Enterprises and Healthcare organizations have millions and millions of devices that were never considered part of the attack service. So much.
So even in a lot of organizations today, it's not owned by the same security teams. They're different folks that own that device security. And so, you know, we're just trying to solve a problem which I think is is a beauty and I think it's going to become even bigger in the next few years, which is you know, I would say the first order of business is just understanding what devices you have.
And so we think about that internally is just this, you know, kind of see no with the secure as the journey and so I look at and say the first step is to see what do you have what's even in your network? And you know, I did a lot of work with the pharmaceutical company. We spent years working on our application security and then they got attacked through their cameras their security cameras that they're manufacturing facilities.
And it was just a different Beast to them. So seeing what you have is the first step Second Step, which is harder is knowing what you have and this is where I think I was attracted to order where they're you know from a technology perspective. You know knowing what software is running on it.
Is it an outdated Windows 7 machine that can't be patched. Is it you know a pump is it a camera is that you know, what? What is the device and then the biggest one for me is how do you secure and that's a big problem, you know understanding what a device is supposed to do and how it's supposed to do.
It is a really hard problem. And so I like that I think from a security perspective. My my DNA is very, you know, very deep security and I think or is really in the Forefront of that especially on the device side.
Is in your sense that the bad guys are getting smarter or is it just a question of the attack surface is getting so broad that we can't defend against it. He unfortunately, I think it's both. I think the you know, the the Bad actors in the world are no longer random third parties.
They are very well organized. They're well funded and in a lot of cases, you know, they're not going after incredibly sophisticated attacks. There are examples of attacks that have been successful that take years to plan but a lot of attacks, you know, they're going after a a, you know, a VPN infrastructure that's not up to up just enough and then covid hits and everybody's connecting remotely or they're going after, you know, all unpassed machines or credentials and even basic kind of fishing attacks that are still happening.
And so I think part of it is that they are just going after, you know Enterprises more aggressively but the second part of it is true and that is the attack surface is expanding exponentially at this point. And so whether it's devices alone, if you look at a hospital for instance, you know, they now have over 15 to 20 connected devices per bed in the hospital. That's incredible.
If you think about the the attack surface that someone can go after and the cloud has made that a different problem because it's no longer as I said before. You know your word if you're talking to you know, you've been small kind of regional Banks. They no longer have everything in a data center that they control they're, you know, their data their access.
Their apis are tied to all sorts of third-party services. And so the attack service has definitely grown and there's a whole industry around just a tax surface Discovery and a tax service management. And I think that's great that people are starting to recognize that but I think you really need to make sure you're securing it as well.
So I think it's a unfortunately it's a two-pronged approach to the problem. What is your sense of the relationship between the OT folks that normally run a lot of these devices and the internal security teams. Are they coming together?
Because it feels like for many years they kind of went out of their way not to engage each other. So I think they're converging. I don't think they're converging as fast as it feels sometimes and I say that because it's a I think it certain times the OT devices and the IT devices are very different in terms of how they act and who's using them and so take health care for instance, you know connected medical devices or sometimes very very complicated devices.
And so for a general security organization, all of a sudden have control over pumps and MRI machines and ventilators. Is it different problem than saying you now have control over laptops or you have control over, you know, the VPN infrastructure and so I don't think it's as simple as just saying that it and OT converge because I think there's a complexity of the device type and if you look at you know, you know attacks that we all know well that Colonial Pipeline and things of that sort, you know, this was an attack that started at OT and then merged over to it right in affected both. And so I think while they are converging, I don't think it's a simple answer of saying why don't you just On both but there's no doubt about it at least the decision-making and the strategy around the city how to secure all of that is starting to fall under one umbrella, which I think is a good thing.
You know, I'm I remember the days where you know, the security teams and the sea salt organizations didn't have a voice of the board meeting. That's not true in the last 10 years. They have a very loud voice at the board meeting.
And so I think it's gonna continue to evolve to a point where security needs security kind of regardless of the type of the device. Of course the bad guys don't distinguish between OT and it to them they're all equal opportunity targets. So maybe they have an advantage in that regard.
But what is your sense of do we really need to rethink cybersecurity maybe flatten the whole thing or is it more about putting together different segmented solutions for different vertical plays and kind of think about it anymore that line or or for that matter. Do we have the right structure and it's just that we're over well. Think maybe we can approach it from a different angle.
And that is this, you know, there's a journey that everybody is favored a favorite term of zero trust and I I think that you know, if I think about how to approach the problem, I think zero trust is a is the right answer. I think zero trust is a journey not necessarily a destination and when you look at how this problem gets solved, you know, think about a device again in a medical facility or enemy Factory facility understanding what that device is meant to do is really important and you know is it meant to have external internet connectivity is it meant to be calling back and relaying data to a phone Home Server somewhere understanding what those devices do can tell you a lot about how to secure the device. And so when you look at things like Network segmentation It solves a lot of the problems because you can just you can make decisions in an automated fashion based on what a device is meant to do.
I think that the attack surface is so broad at this point. I don't see that Jeanie getting back in the bottle to the point where networks become so flat that you can just say no to to a device or to a type of connectivity. I think you have to solve it a layer deeper at the at the device level at the application Level in terms of who should be allowed to do what along with kind of network, you know Network Control Systems your neck Knack software and other things I think it's definitely the right angle and it's a good start.
How do we close the loop I get there? We're gonna discover devices and their level of security. But how do we turn that into something that can be remediated and maybe regularly updated and patched?
yes, so the the biggest issue with that being the reason that's a hard question is because you know, they're two ways to think of the problem one is you you approach it from a reactive security tool and that is how do you make these devices either segmented or control to the point where any new device gets plugged in it automatically gets recognized for what it is, you know the past levels, you know the software running on it, you know who's allowed to use it and that's where you utopian you that when you're all kind of moving towards the other side of it, which if you look at some of the regulation that's getting passed around the patch act and other things. They're trying to get the vendor community and the manufacturing Community to build some of this security into the devices in the first place. And I think that's a good thing that they're doing.
And I think it's a very hard ask, you know, a lot of these attacks don't necessarily take advantage of a known vulnerability in a router or in a firewall or anything else. These are attacks that are propagated against a company using Ingenuity and logic that maybe just a logic flaw in the code was written as opposed to a true security hole. And so I think I think you have to come back from both angles.
I think that the idea of maintaining control of what's in your network who gets to use it and why is is the biggest piece of the puzzle but I do think it's good that we're working more with the manufacturers to try to figure out how to make security aspect to a product when it gets delivered. But that's that's gonna be a lifelong struggle. I think for the manufacturing Community because it does you know, and their minds can slow down kind of the route from Market, but I think it's necessary component to the problem for sure.
We are of course seeing the government get more involved in these various regulations and requirements. Is that a good thing or a bad thing? Because sometimes you know, there's an old joke that says, you know, the nine most dangerous words in the world English language or hello.
I'm from the government. I'm here to help. It's exactly right and that's a that's a fair statement.
And I understand it. I I will say from my perspective having spent the last 10 years doing a lot of work with the government in the security space. I like the direction.
They're heading I think that they understand the need for this. I think they are being very open-minded in terms of how they solve the problem and I think they're taking baby steps to mandate how companies secure the networks and secure their devices. So as of now, I think they've taken a measure Approach at the end of the day security is not our government regulated thing.
And nor should it be it should be something that both from a company perspective but more so, I mean it fracturing perspective. It should be part of the everyday discussion chemicals back to my comment, you know, 10 years ago, you know talk to see shows that didn't have a voice of the board. It's really an amazing thing to look at now.
When you when you look at what companies think of them, you know, the biggest threats to their organizations over the next 10 years security is always on the list and I think that's because you know, the Bad actors and the groups that are formed now to make these attacks happen. They're very well organized and it's no longer just the banks that are in in danger. And I think the financial institution was the first to really step up and work together.
They shared a lot of data. They shared a lot of best practices and you see the same thing happening now the retail industry you see happening in manufacturing you see it happening in healthcare organizations are going to be together and working together to make sure they work to solve the problem. So I think it's a combination.
I think the government so far has been pretty measured in their actions. So I think it's a good thing. As you kind of put it all together.
Have we gotten past what I would call the checkbox compliance area of security and now we've kind of moved up to a level of interest and awareness that people just aren't doing the bare minimum. I think we're way past it. To be honest.
I used to you know, you call it checkbox compliance. I always thought of that as you know, what do I have to do to not end up on the front page of the Wall Street Journal here boxing you have to check and I think we're past that. I think when I talked to Chief security officers now of global 500 companies Global 2000 companies.
They have a real problem that they know exists and they need to solve around protecting their customers data protecting their infrastructure protecting their uptime. And so I I think we have crossed that the street of do I just want to check the box and be compliant. I just don't see that very often now as a reason to not do something as it was 10 or 15 years ago.
I think really reach the point now with the stakes are so high from a data perspective and a business continuity perspective. It depends on the industry. I think to Michael because you know when you talk to a retail see so, you know, they will tell you that the number one thing they cannot have happened is downtime.
So if you are a you know a retailer that does 90% of your business that way you can't have everything go down actually talk to a bank. Obviously. It's the financial systems Healthcare.
It's the data. So I think the stakes now would become too high to just think about it as a compliance checkbox having said that compliance I still think is a very necessary thing, but it's no longer the driver for these projects that we see. All right, of course, we're at the beginning of a new year.
What's your sense of the coming year predictions anything that you think people should be aware of before they get hit with it smack in the face as they say. Yeah, the biggest prediction for me coming out of what has been a very strange kind of two and a half three years for for all of us is that these you know this notion that I you know devices and the number of devices growing. I think we're all underestimating the extent to which those number devices will grow.
I think you look at the number of devices per household the number devices or organization Enterprise Global 2000 Enterprise. I think we're gonna see an absolute explosion of those devices and I think that the next two or three years is gonna it's gonna play that out and so, you know, I'm an organization now, I just want to make sure that the security posture. Yeah.
I'm looking at my attack surface and that attack surface should include devices. However, you decide to go about doing that. I think you know over the last five years attack surface as meant, you know, the new network perimeter because people were moving so much to what they do to the cloud I think going forward my prediction is that the explosion of devices is real.
And I think it needs to be added to that to that checkbox as you put it in terms of you know, what needs to be addressed going forward. All right, folks here to hear the attack surface is bigger than you think so you might want to start getting out there and count those devices. Hey, Jim.
Thanks for being on the show. Yeah, I really appreciate it. Thanks so much for having me.
All right back to you guys in the studio.