Cybersecurity Post-Invasion of Ukraine – Dave Stapleton, CyberGRX
Dave Stapleton, CISO for CyberGRX, explains how the cybersecurity game has changed since the invasion of Ukraine.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Dave Stapleton. Who's the seaso for cyber grx? We're gonna be talking about what is the state of cybersecurity post the conflict in Ukraine.
There's a lot more going on in Asia these days. There's just that entirely different landscape Dave. Welcome the show.
Thank you for having me. So happy to be here not too long ago. It seemed like our biggest problem where script kiddies and people who run around just trying to kind of hack into our systems and it was a it felt like a game, I guess today.
It's no longer a game. There's a Nation States involved. There are people trying to do serious damage.
What impact does this having on cybersecurity people who are stressed out even before all this happened? That's right. I wish I could go back to the script Kitty days sometimes yeah state sponsored.
I'm cyber attacks are a real I think threat to the United States and to other nations. I think, you know usually talk about a few different actors here Russia China North Korea are typically top of mind for a lot of folks and I think anyone who's paying attention, they see this kind of a clear and present danger. I think we can take a look at some some recent headlines for some clear indicators here some things that have just popped up quite recently, you know, the state department just announced that they thwarted a pretty significant rain somewhere and the calling at Maui.
I was associated with North Korea and a couple things. I like to point out with that is they recovered Ransom payments, which is really cool. I love when I am when I hear that and those Ransom payments were paid by medical providers and in Kansas and in, Colorado.
So two things there one it was thanks to kind of the rapid reporting and the willingness to collaborate with the doj from these, you know, private sector organizations that really allowed the doj and FBI specifically to get in and start to take action. I think that's probably something we'll talk about a little bit more later. The other thing that I like to highlight is that this points out the real human impact of these cyber security attacks and particularly, we think about health care facilities.
You know, you have to imagine that the folks who were, you know scheduled for certain types of procedures or screenings or that kind of thing that maybe had to get postponed and having worked in cyber security and healthcare for a little while. I know that these organizations have Disaster Recovery plans and play books so that they can switch from digital to paper if they need to do that, but it definitely slows things down. And I think it's just really important for us to take a minute and when we can and realize that human impact, it's not always just you know, a corporation get slam of a fine or has to pay out a ransom There's real people behind these attacks as well.
It also seems like there's more transparency. It feels like a lot of organizations if they got hacked they were inclined. They're quietly pay their Ransom.
Is that changing or we seeing folks more willing to engage law enforcement just because they're kind of starting to realize that this isn't just a one-off smash and grab crime. This is a wave of cyber criminal gang activity that won't stop unless we all get together and align our defenses. That's absolutely right.
I think stories like the one I was just talking about contribute to that in this case. These organizations were actually able to get their money back. We're talking about hundreds of thousands of dollars.
That's not insignificant particularly for your small and midsize businesses. So there's that. Of course, the FBI has always recommended that no one pay a ransom in the first place.
We kind of feeding the Beast and that sort of a way so they'd want to pull that back and then we're seeing changes in regulation, you know, the SEC has some proposals that would require notification to certain for certain types of financial institutions to the government within a certain amount of time after an incident as has occurred. So I think there's a combination of just the messaging getting out there seeing some positive results and having that be a real motivator and then also using where we need to regulation or religion to, you know, get organizations to act in a way. It's a little bit more responsible and helpful collectively.
What is your sense of the mental health of the cybersecurity professionals these days are they just so stressed out that we're seeing turnover rates that are really high. And what's the average life cycle span for someone in this field or do they feel pretty good All Things Considered? Wow, I feel like you you must have been eavesdropping on some of my one-on-one conversations with my boss recently.
The topic that's kind of top of mind. It is a stressful industry to be in and there's a lot of weight and pressure that cybersecurity professionals feel and we have a lot of responsibility and The cybertax can have significant impacts particularly, I think for your small and medium sized businesses. You know it depending on you know, what kind of industry you're in what your business model looks like.
The Cyber attack can have a significant impact on the trust or kind of the reputation of your organization and that can you potentially be existential and it's through so it's quite something when you're let's say, you know a security analyst who's been on the job for a year year and a half and when you go home at night you get this idea in your head like, oh there was a bunch of things that I didn't get to yet today because there's always more work and we have time for and then you know the thought that follows right after that is oh my God. I hope it's not one of those things that potentially exposes this to some kind of a breach and maybe puts my company out of business, you know, that that's a lot of pressure. And so I think that cyber Security Professionals certainly are just do the nature of our job in a place where there's a lot of threats to our mental health.
One of the things we're doing here at Cyber grx is really encouraging a number of different initiatives to address that one thing that we we've been doing all along is just talk it out. I mean we have really open Dialogue and it's interesting. How much will come out in those conversations?
We spend quite a bit of time talking about burnout. I mentioned a second ago that there's always more work than there is hours in the day to get done. So we had to have some way to have clear prioritization understand what the real risks are that require immediate attention and what can wait and then also just encouraging and in some cases even kind of proactively moving our employees to take time off.
I think a lot of cyber Security Professionals are very passionate and which is great. We don't want to discourage that but at the same time it can subconsciously influence the way that they kind of treat their own personal health and quality of life and we have to sometimes as managers and leaders be a little more forceful and getting them to take that time they need Is cyber security becoming more of a team sport or is this just something we say in an aspirational tone? Because historically, you know, the cyber security people were kind of off the side on their own doing some dark art magic kind of thing.
But you know are we starting to see it operations teams more involved. They're developers more involved that we shift more stuff to the left here and they focus more on application security. So yeah, is it less lonely being the cyber security yet?
Yeah, it is and and for good reason and thank God and I personally see quite a bit of interaction and collaboration between other teams. I think the preponderance of devsecups and in the past five years is a good indicator of this people recognize the value. And as you said shifting left making sure that security is baked into our products and solutions rather than trying to bolt it on later.
And my opinion and my experience that bolt on mentality that we may be have had in the past is always less efficient more expensive less effective and causes a lot of frustrations internally and extremely for companies and their and their customers. So 100% more people are recognizing I think due to maybe some of the scary headlines maybe some of the real impacts on their organization that cybersecurity and privacy and have a real significant impact and have consequence on the success of their business and it needs to be integrated more even see that in the elevation of the siso role for example and over time as you say that's become a role that has come out of the the Dark Shadows and the basement office where we used to sit and do things that no one fully understood. And more and more is being elevated as a business partner at the executive level.
So I think all those things combine are making it a less lonely place and are making sure that we have a security as at least an undercurrent throughout our entire business operations. A lot of folks will say the best defense is a good offense is the nature of the strategies changing a little bit where people are going after the bad guys a little more aggressively. Where is that line of defense because as you will know any battle that has fought within your borders is usually going to have some collateral damage, right?
That's right. I have mixed feelings on this and this is my my personal opinion. There has been quite a bit of conversation and in the past year about the concept of hacking back.
Which is maybe part of what you're alluding to here. And my worries about this stem from a couple of things one. Attribution is very difficult.
It is something that even you know, large nation state cybersecurity programs with exceptional amounts of funding and armies of cyber professionals and struggle to do and with any kind of real Clarity or accuracy. I worry about you know some business in Oklahoma with an overzealous cyber security team thinking that a good way to address ransomware would be to try to launch their own ransomware attack against China or something and seems like that gets borrow a lot of control and I don't want to be a FOID proponent here, but it seems like there's a lot of problems with that if it's not done in very tight and close coordination with our own US Government. So as far as offensive type attack, I think that's that's something that again I have mixed feelings on what I do like that I'm seeing is a conversation about prevention.
And in most organizations that it's really highlighted and emphasized and and prioritized. I'm rather than only thinking of kind of an after the fact. Okay.
Now that I know this that exists I should go patch all of my assets trying to get ahead of it with various preventative techniques. but then having a firm understanding of a successful Cyber attack is there's almost destined to happen and most organizations. We don't really say if it's more a question of when so I guess that balance not necessarily offensive, but definitely proactive is something that I like to see.
And now you're scaring me because I'm thinking about one good guy with a ransomware kit. And the problem is that we don't really have control over these attacks. Once they get launched.
I mean some of them are more targeted than others, but it seems like one of the things we are dealing with is the tax themself, they're still largely indiscriminate. So even if we launched an attack with the best interest, we may not know where that thing might wind up right? It's a great point and then what tools do we develop that we want to launch the attack with and in many cases what intelligence do we give to our adversary about the kinds of capabilities that they could develop and can they reverse engineer the malicious software that we you know install in their in their networks have we basically handed them the nuclear bomb that we created?
And so there's proliferation and collateral impact and there's this idea that and we're actually exchanging very dangerous weapons particularly in some cases that gives me pause. All of those things are I think worth a lot of consideration before anyone went down that path. Do you think Business Leaders better understand the risks that we're facing?
I mean we are seeing a lot more digital business transformation initiatives, but I'm not sure they really understand how well organized the bad guys are. No, I I think that in general Business Leaders are still a little behind the times and not very well informed on the actual risks and understanding not that there's just this General threat. I think we have to be careful.
I don't want to just try to make people paranoid in general about oh my God, you know China's gonna hack us that's not productive. It's not actionable information, but understanding what the real threats are to each of our individual organizations and that is tricky that requires thoughtful risk-based approach within your organization because my wrist tolerance and my wrists are a threat profile is never gonna be the same as someone else's so and we have to have a very customized kind of bespoke approach to this. And if cybersecurity professionals aren't able to adequate communicate that information up to the leaders in their businesses and there's always going to be a disconnect and I think that's you know, the responsibility lies on on all of us for one.
We have to as cybersecurity professionals have to find good ways to communicate those messages. I can't walk into a room with a bunch of execs or the board and start spouting off about a particular CDE. That's not that's not gonna be effective.
So how do I communicate well, and then from, you know, the board of directors and executive side they have to give time and space for that kind of communication to actually occur. So a lot of responsibility goes in there, but I think we have a lot of ground for improvement. Do you think security people understand how to have that conversation because this is exact, you know largely went to business school.
They are taught about risk from day one and evaluating risk, and they look at cybersecurity and they'll say yeah, I mean there are risk, but are they any more worse or than the ones that we deal with for the rest of the business and to cybersecurity just need to be one more of the business risk that get assessed but you know necessarily need the panic. Yeah, I think there's maybe some truth in that. I I always want to avoid Panic right that's usually doesn't as humans.
Don't react very well. We're in a panic state. So I don't want to go to that that level I do think that cybersecurity the industry as a whole has not found a consistent and effective way to communicate risk to folks outside of the industry internally we seem to have a jar again or maybe a intuition because he's been a fair amount of time.
So we're communicating to our within that Community. I think we have some sense of what we're talking about the level of granularity of the risk, but if I go to a CFO, I need to try to be able to translate that conversation into something like dollars. So instead of saying something qualitative like we have a critical risk that I believe needs to be addressed within the next, you know, we and I need this amount of funding in order to do it.
I need to say something more along the lines of And based on the information we have at hand. There's X probability that this particular threat might be exploited and ironment over the course of the next year and if it were successfully exploited we estimate that it would have this kind of financial impact on us. So I want to spend this amount of money to prevent this financial impact.
I think that's a conversation that CFO for example can better understand rather than the more qualitative kind of conversations. What is that one thing that you see over and over again? That just makes you shake your head and go.
How come we cannot seem to get Beyond this particular issue? Authentication I think is is the one I would point to it's interesting for years and years. I think every cyber security professional I know has been pounding the drum MFA MFA MFA, you've got to implement multi-factor authentication.
It is one of the key ways to prevent significant portion of cyber attacks. And now we have a lot of organizations who can't seem to get their head around it. Perhaps they Implement here or there, you know a couple of key applications that are easy enough to set up.
But they don't think about it comprehensively and so we just keep hearing reports of cyber attacks that take advantage of someone's password and I if I'd never hear about a password based attack again, that will be a great day. I think what we need to be talking about interestingly enough. Is what comes after the MFA that we know now and even though it is still a very strong control and it's highly recommended that everyone no matter the size of your company Implement is Thoroughly as you possibly can.
We're already starting to see cracks in that armor as well. There's MFA bypass attacks man in the middle attacks. There's MFA bombing, which is you know, basically just sending a bunch of requests to people who know where MFA who are going to get a push prompt on their phone.
Maybe they just don't think anything of it like, oh, I must be getting realthenticated for some reason. They just hit accept. And so there's a bunch of different weaknesses even in MFA that we're starting to see and we need to start having conversations about passwordless authentication in my opinion things like the 502 protocol.
So yeah, it's it's I think authentication is going to be a big one for me for a long time. I hope someday that changes but I would remind everybody that we've been using passwords since the first caveman grunted who goes there to the next guy coming up the road. So I'm pretty sure passwords will be the with this for some time to come.
Hey Dave. Thanks for being on the show. I really appreciate it.
Thanks so much for having me. All right back to you guys in the studio.