Cybersecurity Insights with Illumio ‘s Gary Barlet
Gary Barlet, Public Sector CTO at Illumio, shares his expertise in cybersecurity, focusing on microsegmentation and breach containment. He discusses the recent Salt Typhoon attacks linked to China, targeting government and telecom sectors. Barlet highlights the persistent challenges in cybersecurity, where attackers often have the upper hand. He points out the potential of AI in defense strategies but stresses the importance of addressing internal vulnerabilities and building resilience against cyber threats.
Transcript
Hey everyone. Alan Shimel here. We're back at Techstrong tv.
I'm happy to have my next guest back on here. I don't know if you'll remember him from the last time he is on, but not to worry. I'll give you his name.
It's Gary Bartlett. Gary Bartlett is public sector CTO for Illumio, the microsegmentation people, and well, and more than that, that's when they first started. But anyway.
Hey, Gary, welcome back. How you been Doing? Great.
Thanks for having me back, Alan. Appreciate it. I appreciate having you on.
We were talking off camera a bit. We didn't get a chance to hook up. You missed black hat this year.
I did. Unfortunately, I had a, um, uh, conflict that just prevented me from being there this year. Well, I could give you the load down, but you didn't miss a heck of a lie.
It was just another black hat. Um, on other news, RSA is earlier this year, uh, you know, speaking, uh, uh, the speaking session submissions are closed. I expect that'll be coming out soon, but maybe we'll see you there.
Yeah, definitely. We'll be at RSA this year. Very cool.
So, Gary, before we get into Illumio, and we're gonna talk a little salt typhoon and stuff like that, give people a, i, I remember your background, but you know, not everyone out here does give people a little sense of your background. Sure. Well, as you mentioned, I'm the public sector CTO here at Illumio, uh, about three and a half years now.
Uh, prior to joining Illumio, I was the, uh, CIO at the office of the Inspector General for the United States Postal Service. Uh, so I served as a Fed CIO for just shy of 10 years, right. At 10 years.
Um, and before that I was a cyberspace operations officer in the Air Force. Did that for a short 20 years, A short 20 As opposed to a long 20. Right.
Yeah, I get you. I, uh, you know, I'll tell you when one of the companies I had helped co-found still secure, we did a lot of work with DOD and some of the agencies, and we did some bit of work with the Air Force. We were out in Colorado.
So it was a lot of bases out that way. A Lot of bases out there. Yeah.
And, um, that would that look, the Air Force had it going on, right? It was, And they still do, they're still in, in my opinion, leading the DOD as far as zero trust and, and those types of things. Not that the other services are lagging, uh, but, you know, I'm, I'm a little, I'm a little partial.
Right. I can't, I can't claim to be completely impartial. So yeah.
Maybe there's a little bit of a blue tinted lenses there that are, that are affecting my outlook. Well, we, we gotta get out of the, calling it the DOD now, right? That it's not that the DW or whatever he did Department of War now, right?
Yeah. Let's not go there. Um, so Gary, let's talk a little bit about Illumio.
You know, know a little tongue in cheek. I said the microsegmentation company, but not so tongue in cheek. It is kind of what Illumio does at its heart, right?
Uh, is, is, you know, kinda segment. Absolutely. So, so, yeah.
And we, we really look, uh, view ourselves as the breach containment company, right? So we're all about doing a couple of things. Number one, uh, given our customers, uh, really granular visibility of what's actually going on, on their enterprise.
Uh, specifically when you're talking about application to application communications, uh, looking at how things are actually, uh, communicating and how they're interconnected, um, from a net, from a network agnostic perspective. And by that I mean that we look at, we look at enterprises the same way that adversaries look at enterprises. When an adversary comes in and starts trying to map out your enterprise, they're not really interested in the routers and switches part of it.
They're interested in what devices can talk to which effort, which, which other devices, right? It doesn't matter if they're in the same rack, in the same data center or on opposite sides of the world. If they can talk to each other, that's what adversaries care about, right?
That lateral Lu and be able to compromise one box, and then where can I go from here? You know, what other devices can I touch? They don't care how those things are communicating.
Uh, they care that they are communicating with each other. And that's what we do, is we provide our customers with visibility that they can actually see that. Um, it helps, uh, like security teams and CISOs, uh, be able to really understand and start to map attack vectors and shut down attack vectors.
And that's where the segmentation piece comes in, is really being able to start to isolate things and shut down a lot of unnecessary communications that are in place on most enterprises that really don't need to be there. And they're nothing but an open avenue, uh, for adversaries. Absolutely.
Absolutely. com. Yes, Sir.
Thank you. Okay. Let me kind of switch gears a little bit here.
And we're gonna talk kind of public sector security or public sector cyber, if you will. Um, you know, salt Typhoon is, uh, you Ms. Black hat.
They had all kinds of robots that were projecting to be salt typhoon and, and all of this stuff. There was a lot of soul typhoon going on there, but clearly this is something that targeted our government though. It, it wasn't just the government.
Right. But, you know, not everyone on our audience is a security expert as we've got DevOps people and Cloud native for those. Maybe let's start here.
For those who don't know sa Typhoon, what, when we say soul typhoon, what are we talking about? Sure. So, SA Typhoon is a, is a name for a, uh, series of attacks that attributed it back to China, back to the, uh, uh, intelligence sector of, of the Chinese government.
Uh, and it was primarily, as you mentioned, right? Targeted towards, um, governmental, uh, you know, department of Defense, department of War, uh, entities. Um, they went after the telecoms.
That's where they were first discovered, is going after the telecoms, the, the, all the big telecommunications, uh, uh, companies. Uh, and people were like, well, what does that have to do with DOD? Well, they were specifically going after, uh, you know, government officials, right?
They were, they were literally looking for conversations, relationships, locations, identity information of government officials, right? And looking to get access to where were they, what were they talking about? Who were they talking to?
Um, you know, so it was, it was very, from a, from a national perspective, um, it was quite the, you know, quite the effort, uh, to, to attribute to the Chinese government that they were going after civilian companies that obviously are supporting the government, uh, and, and using them as a target of opportunity to get to, to try to compromise or get information about our government officials. Um, and then it expanded into, uh, going after National Guard units. Um, state local governments have, have been affected.
Uh, so it's been a very widespread campaign, uh, of, of espionage. I mean, there's no other way to, no, no other word for it other than it was, is literally espionage of going in and looking for what information could be stolen. Uh, and then, you know, you, you can talk about what they do with it once they steal it, but that's really, it was about targeting, uh, companies to steal information.
So, let me say, I, I have been in the cyber world a long time, and this is though the name Sol Typhoon may be relatively new. This behavior is not, you know, I remember, uh, it's gotta be almost 20 years ago, maybe 18 years ago, but one of the companies I helped found were NAC Network Access Control. Yes, sir.
And, and so we had the ability to kind of quarantine any devices coming on the network, test them, make sure they, you know, met a, you know, golden sort of config rule. Well, we could, we could test them for anything you want to tell you truth, right? And then if they did, put 'em on the network, if not, keep 'em off the network or put 'em on a guest thing or whatever.
And I remember we got a call from SEC D'S office one day and said, can you check, can you check to see if the USB ports are enabled on laptops? I said, yeah, it shouldn't be too hard, but why would you want 'em all disabled? How are you gonna get stuff on and off?
They said, well, don't worry about that. We just wanted make sure they're disabled. You know?
And then a couple years later, of course, we all, most of us in the cyber arena know there was this campaign of people just through USB thumb drives in the parking lot at the Pentagon. Right. And how many people were silly enough to pick 'em up and plug them in there in their machines and thereby give access some claim.
You know, the, the plans for the stealth fighter that China, China's first gen stealth fighters, Right. Airplanes were stolen that way. Yeah.
Wasactually, I was actually on the Air Force CIO staff when that happened. Um, and it was quite the, uh, uh, it was quite the event to deal with, uh, and, and to try to figure out, you know, how to deal with it. And, and, and like you said, it was a very, um, widespread attack, uh, that was executed in, in a way that people weren't thinking about, um, necessarily.
Uh, and unfortunately, you know, that continues today. Right. You know, you know, that's where we always talk about the fact that, you know, the adversaries are always gonna be ahead of the defenders, right?
They, they're, they're just, they can be more creative. They can, they can think of ways around defenses. Uh, you know, it's just, it's, it's always gonna be an ongoing cat and mouse game.
Unfortunately, A great, a great it, you know, it's enough to make security pros depressed, but A little bit. Yeah. Gary, I, I, I feel like compel to draw a distinction though, you know, there are nation state actors, I think, which is the case in Soul Typhoon.
It's really coming out of, most of the Chinese stuff come out of the people's arm, PPLA, right? Um, and then there are not state sponsored, per se, but under the cover of a benevolent state, you know, wink, wink, they let them operate under their umbrella in their country, though they're not officially part of the state. Usually those are more with financial, uh, packing, right.
Financial benefit, right? Yeah. You're looking at ransomware that, you know, that's where you get into Yeah.
That kind of Thing. Making financial demands. And, you know, and there's lots of conversations about, you know, I've been asked repeatedly by people, you know, well, why would a country, you know, allow that?
Well, depends on what kind of kickback you're getting, right? It depends on, you know, what kind of, you know, the individuals that are involved, right? What kind of financial incentive are, are, are they receiving as, as a benefit of it?
And not to mention the fact that, um, just imagine the other intelligence that they're able to gather, you know, while being about, you know, while officially it's not them, uh, you know, but you know, I'm, I'm sure they've got access to information that's being compromised, and I'm sure that, that, you know, they're talking to, you know, potential groups and, and talking about potential targets. So, you know, it's a very symbiotic relationship that you can understand why they're doing it Well, just the chaos that they sow. Absolutely.
Yes. Alone, you know, it is weakening, weakening your ad adversary or a friend of me, or whatever you want to call them, right? Um, and then there are some, you know, they estimate that the North Korea may, may, in fact, 25, 30% of their GDP may in fact come from cyber hacking in theft.
Right? And like I say, it is, it is still big money, right? It is, unfortunately, uh, you know, and, and again, it goes back to, I think still today, unfortunately, there's a lot of companies out there, uh, that are still very focused on keeping the bad guys out.
They think that if they just throw enough money, buy the right piece of technology, implement the, the, the right piece of governance or guidance or policy, that somehow they're gonna magically keep the bad guy out. You know, I've been doing this for 35 years. We've been talking about keeping the bad guys out for 35 years, haven't been successful yet, right?
Um, and, and you know, and that's the problem, right? Is we, we, I don't believe are ever gonna keep the bad guys out. Uh, I think the best that we can do is figure out how do we fight through the attack?
You know, how do we, how do we maintain resilience? How do we ensure that that an attack doesn't turn into a disaster, right? That they don't get to the crown jewel information they're looking for.
Sure. They compromise a web server, or they compromise somebody's laptop, but they couldn't get from there to the actual data that you're after, right? The actual server that contains the, the crown jewels, right?
That's, that's really to, you know, in my opinion, you know, that's where the focus ought to be, is how do we, how do we stop these attacks from spreading as opposed to thinking that we're somehow gonna magically stop all these attacks. I agree, agree with you. Um, you know, I, again, thinking back to when I was actively involved in this market, I, I don't know if people realize the, just the sheer number of attacks, the sheer amount of, of attack.
I mean, back then we were, you know, we were helping to protect one of the largest private networks in the world that was run by a couple of service, well, one service branch, right? And, um, back then, and this is again, 2005, 2006, seven, back then they were seeing four to 600,000 intrusion attempts a day. A day.
Yeah, absolutely. I mean, I was, you know, I was in a similar role back in the early two thousands, uh, you know, defending the networks of the Pacific when I was a, uh, uh, network, operat security center, uh, uh, in charge of the Pacific nos. And we were receiving hundreds and hundreds of thousands of attacks, you know, like you said, every Day.
It was, it was very routine. Yeah. It, so it, it, it really does get like that.
But, you know, Gary, we live in interesting times. We're living in an area of budget cuts and AI will do it for us. Uh, just frankly, political infighting.
You know, we ceases the, the very charter for csar and its funding was almost extinguished and then turned back on at the last second. Uh, who's maintaining the CVE database n their funding? How do you think this all plays into the future of US intelligence and cyber cry?
Cyber defense? So, I'm, I'm an optimist, right? I'm, I'm not gonna lie, I'm an optimist.
Um, here, here's my hope, right? I, my hope is the fact that, you know, sometimes in, in austere times, you know, things become more efficient because out of necessity, right? You stop doing, uh, things that maybe aren't, aren't as mission focused.
Um, I know in my experience in the military, anytime we went through budget cuts, uh, you know, a lot of things that a lot of us looked at and said, why are we doing this? Those, the, those are the things oftentimes that went away first. Uh, you know, so again, I'm an optimist, right?
I'm hoping that, you know, you know, maybe with some of this focus on, you know, trying to be good steward of tax dollars, uh, you know, try to look for efficiencies. I'm hoping that maybe we'll cut out some redundancies. Um, you know, we'll cut out a lot of, I think in the government, there's a lot of overlapping responsibilities, uh, you know, and, and you know, the, the whole too many chefs in the kitchen kind of kind of thing.
Uh, so I'm trying to look, I'm trying to be optimistic, looking forward and hoping that things are gonna become a little more streamlined, a little more mission focused, you know, less distractions on, on maybe ancillary things. Uh, so I'm, I'm, like I say, I'm trying to be optimistic. I, I, I'm hoping that that's the way things are gonna play out.
I, I hope so too, my friend. In the meantime, for our friends in the public sector, or, you know, if you, as we mentioned as you mentioned, the phone companies that service public sector, the, you know, so-called Beltway Bandits, the big contractors, the, the, uh, the Northrop's and the s aics and the, you know, so forth. Uh, what, what can they do, Gary, to China to it is a cat and mask, and we are playing catch up.
What's your advice to them short of going out and buying a lumio? Of course. Okay, well, you just stole my thunder.
I don't know what now, now, now I'm out of advice, Uhhuh, you know, so, so I think there's a couple things, right? Number one is, and you know, I think some of this is common sense, right? Number one is, uh, don't get trapped into believing that there's a, a magic button out there that's gonna solve all your woes, right?
You know, don't, don't buy into some of the marketing hype of out there. Uh, if, you know, there are companies out there that say, oh, if you just buy us, you'll be a hundred percent safe. You know, that's, that's just not true, right?
Let's just be honest. That's not true. I wouldn't say that about Illumio.
I, I, you know, you know, I don't think there's any company out there that should be touting themselves as saying, if you just buy us, you know, we're you're, you're gonna be, you're gonna be secure, right? Um, there's got to be a, uh, combined effort of both tools, you know, uh, people, you know, let's not forget, I, I worry a little bit that, that people think AI is gonna be the magic solution for everything. Um, it's not, no, I'm sorry.
Hate, hate, hate to burst everybody's bubble. It's not gonna be the magic, magic solution for everything. Uh, you know, can it be a, a huge enhancing tool for cyber defense?
Absolutely. I think it can. Um, but is it gonna solve everything?
Is it gonna make every, every company, you know, 100% secure? Absolutely not. Uh, you know, 'cause the, the attackers are using AI just like the defenders are, and I hate to break it to the defenders out there.
Uh, the attackers are going to gonna always have a, an edge because they're not constrained by law. They're not constrained by morality. Uh, right?
So they, they can get all, they can be a lot more creative, uh, than, than the defenders can. I think. Uh, so AI's not gonna solve it, right?
So for the companies out there, I would say, you know, think about asking the question of, you know, what am I doing from a defensive perspective? How am I looking at my tools, integrations? And then, you know, what next, what happens when there is a breach?
How do I ensure things like that? I don't have to shut my company down? How do I minimize the impact of the attack?
Um, you know, what kind of rings of defenses do I have internally? Uh, you know, I really worry that companies spend so much time focusing externally that they're not looking inwards, right? I would love to see CIOs out there and CISOs out there be graded on.
Yes, it's great if you were, if if you're, if you get a, a passing grade on, I was never attacked. I was never, never compromised. That's getting a harder test for anybody to pass.
I think that really it should be a ma a matter of how successful were you in, in, in surviving the attack, right? What had you done in place to protect the company, protect the data, right? Ensure that didn't get exfiltrated, you know, what have you put in place to prevent those types of things?
Got it. Excellent, excellent advice. Gary.
Hey, we're about outta time, Gary. So we mentioned seeing each other at RSA, but that's March. Yeah.
We'll have, you'll have news before then, so come back on and keep us posted. Okay. Absolutely.
Would love to. Anytime Alrightyy Gary Bartlett, public sector CTO at Illumio here on Textron tv, talking Soul typhoon and more. We're gonna take a break here on the Textron tv.
We'll be right back.