Cybersecurity Threat Exposure Management with Picus Security’s Volkan Ertürk
After picking up an additional $45 million in funding, Picus Security CTO Volkan Ertürk explains why a different approach to cybersecurity threat exposure management is needed.
Transcript
This is Techron tv. Hey guys, thanks for the throw. We're here with Boken Uck, who's CTO for Pike is Security and they're fresh off raising $45 million in additional funding.
And the question is for what? Because they are, at least as I understand it, involving continuous threat exposure management. But I always thought we were always exposed to threats.
But I'm gonna let Vulcan explain what exactly is continuous threat exposure management. Uh, hi Michael. Uh, thank you very much having me.
Um, continuous threat exposure management, uh, is any concept, um, you can think about like we are in the business for the last 15 years. Um, like what is being asked to us? Hey, we are doing penti automation.
We are doing breach tax simulation. Um, so help us understand how this will be taken to the next level. Um, we are sharpening our tool set.
We have more controls. We are buying new technologies, but, uh, what's the next thing? So I have reducing my tax surface, improving my return on investment, but what's the ultimate value adding to my business?
So I guess, uh, continuous threat exposure management is the answer for that. How these things get together. Um, and the answer is if you have better security controls, can this add value to your vulnerable to management program?
Or can this add value to your other findings in your environment? Definitely if you have, uh, security controls, then you need the discount. So, um, currently for most of the organizations, these findings are managed in silos.
I call them different islands. Um, so you have different islands of information, how you're gonna build the bridges. Organizations that's been doing, like, they develop their own middle layer or they do the heavy lifting through the spreadsheets, it doesn't scale and it's very, uh, person depend on.
Then if that person is not there anymore or they're, uh, out for some reasons, then this does, this process doesn't really scale or even execute. So continuous threat exposure management is putting things together in an, uh, let's say in action vulner management approach, putting all the not only vulnerabilities, I'm talking about vulnerabilities and weaknesses, but also putting other findings like your cloud gaps, your infrastructure yet like weak passwords or your active directory vulnerabilities or your gaps from your security controls, like your missing firewall, missing IPS controls or your misconfiguration, your EDR or your SIM is not consuming the lock or it's consuming, it's not parsing the lock. So we are putting everything together and we run a process on that one.
Uh, so this is how I, how the industry is moving forward and this is how we have been working on this one for the last two years. And yeah, this is, I give a long answer. Uh, does it help you, Michael, there, I can give a short version too, but as a kickstart, I want to really share a longer story.
And I think your point is, is that we need a more proactive approach and too often all these silos result in us being reactive and we get a lot of alerts that are hard to correlate, and by the time we get off our heels and figure out what's going on, the game's already over, right? Exactly. Yeah, you nicely, uh, summarize it, reframe it, that the name of the game is proactive security, like, uh, incident response is very expensive.
And the results are, as we all know, very disruptive for the business. So we are looking into what we can do ahead of time and we can do a lot. So how we can really make our plate manageable and still letting value for the business.
To your point about, uh, the business and the value of cybersecurity, there's been a lot of conversation maybe bordering on criticism of the amount of money we've invested in cybersecurity and what the return on that investment is. And to your point, I think you're getting at the heart of the issue, which is all these things that we've previously invested in or, um, data silos, but we have yet to have any comprehensive way of kind of pulling all that together in some sort of plan. Yeah, exactly.
My master TE thesis, uh, was about security metrics. So I spent good number of years to measurement and monitoring, and my PhD is about like, okay, we can measure things, but no one would like to get the bad news. Everyone is looking into, okay, I have the metrics, I have the visibility, now I need a better plan to iterate and execute.
So that's the reason, uh, we established because to help this one out, and as you mentioned, um, we need to, uh, have that visibility about our controls, like what we are doing. But, uh, always the business is asking like, eh, uh, you need additional million dollar budget. If I release that one, what will be the return on investment in terms of how you gonna reduce my risk?
So still we are in the year of 2024, but the cyber risk is not still manageable. It's not still tangible. So we cannot list like 10 items.
So we are trying to really help organizations what are the 10 risky items we can list? It's not like earthquake, it's not like hurricanes. It should be like, Hey, and, uh, landing into your, um, secretary's computer, can it reach into a PCI network?
Can they infiltrate your critical data or work from home network if there's a compromise that what may be the, uh, impact or, or for the organization? And it's all tied to different pieces to get together. It's not only, hey, my vulnerabilities are there.
It's not only my security controls are there effective or not. Like we need to really blend this together. So that's the reason we build a and uh, data fabric.
We call it exposure data fabric. And we are building attack pads on those, uh, which helps organizations plan an understanding about, um, vulnerabilities overlay to asset criticality overlaid into security controls. So that is, uh, called how we can do the validation on the exposures because we don't want to, organizations, our stakeholders doesn't want to attack on the vulnerabilities theoretical exposure.
So everyone is looking into, Hey, I want to spend a dollar of investment, or I want to spend one hour of my time, it has to have a positive impact for my organization, how we can make this happen. Because today, uh, everything is about agility. Everything is about, uh, being on time.
So we are here to really answer that question. So is if we, uh, instrument this one to the organization and they can take it to the leadership team, make like more meaningful conversation saying like, this is the problem. If we miss this one, this is how we gonna reduce the problem.
Um, that, that's the direction we are moving to. And I guess, um, that's the round riverwood, uh, build a partnership with us. The, that they're very motivated with this vision and definitely our partners and customers too.
What made it possible to build this data fabric now? Because this issue's been with us for as long as I can remember it in cybersecurity. So, um, what changed?
Yeah, I, I love your hard questions. Um, actually, um, what's changed, everyone was very super focused on, hey, if I extend my island, if I build an additional lead, it'll gonna solve the problem. The tool gonna solve the problem.
I guess currently, uh, we try every single option in any of those solutions and what everyone really figure out that each one of the product cannot solve this problem. So, but we are in the same boat and we need to communicate and collaborate. We is not a vendor and a customer, no, it's like the organization and all the partners and all the vendors they need to be together.
So in order to make that collaboration, like we need to unify the data and we are not saying like, Hey, we are the best data fabric, like we need to consume everything and we are gonna make this happen. No, because it'll be the same, same story. Uh, the pick version, what we're saying is here an open platform, uh, if you want, we have this functionality, this flexibility, we can consume data and we can help you about exposure management exposure, validation, or we say that we are an open platform, we have APIs, we can, we can, uh, ingest data to other vendor technologies.
So if you're using a vulnerable management program, you're using a cyber set attack surface management program, which we have been in talks with, uh, quite a bunch of those folks. Um, so we can ingest that data there. So, um, we can be part of the solution.
We don't have to be the solution. That's our view. Um, and there's no single bo silver ball here.
Um, there are small co organizations, medium, large, very large organizations. Everyone has different needs s limitations, so there shouldn't be a single solution solving all the problems. And they're pretty adaptive with our partnerships, with our technology alliance program to tap into what is needed for that organization.
Did we forget somewhere along the line that cybersecurity, when you peel it all apart, a lot of it is a data management problem. It's, uh, we have anomalies and behaviors and things are changing in real time and uh, we need to correlate that against our controls and maybe we just have been looking at it the wrong way. Yeah, no, maybe like, I don't like talking about like ballpark parts, uh, sentences or approaches because like everything, uh, is right in a certain context.
So definitely as an industry, can we do better, like ai, better data stacks, uh, data management solutions, better technologies, makes things happen easier, faster. Definitely cloud technologies help us to accelerate, um, help o me as the vendors definitely. So I believe like gen AI make things also swift for better to explain, express and interact with the users.
So I guess, uh, definitely we can do a retro conversation to look into what we can do right for the next 10 years. Uh, that, that's a great conversation. Uh, we can have some thought into that, but, uh, what I'm also looking into, um, if there's something not working, there's a sun code for that, but let's Note those learnings and be open-minded about not increasing ourself.
Let's be agile, let's be flexible. Let's look into an open platform like a multi-vendor collaboration, um, to make this happen. That that is where we are looking into what we opt to and we're working closely with maybe like 50 vendors to make this happen.
And when we see, um, a partner, uh, or a, a organization coming up saying like, Hey, I have this technology and I believe that this will add value integrating with you guys, we definitely follow that guidance and if it is meaningful and we do the heavy lifting there does make sense, Michael. Yeah. Well, to your point about looking to the future, so what is the intersection between things like gen AI and a data fabric?
Is that gonna be where I collect and aggregate the data that I'm gonna use to train the models? Or how does this all come together in your mind? Uh, definitely.
Uh, great question, but you need data, as you mentioned, to, to leverage the gene AI models, to train your models and to add value to your, uh, stakeholders. Um, so you need to know which data and how to get, make things get together nicely and you need to build the relations there. So we saw this trend that we built an a team, eight people, um, team, like a data science team.
Uh, we have data engineers, uh, uh, which is really, uh, building a unified data model and we put everything on a knowledge graph. So that is, you know, very, um, instrumental to leverage the gene AI technologies. And we are not really looking into single gene AI technology.
We are working with multiple of them. And, and definitely when you're building such a technology and the structure, you need to be sure that the privacy and security concerns of the organizations is critical. So you need to consider a lot of stuff while building this one, uh, which we have been doing.
And, uh, you had a good piece of, uh, article, I appreciate that, but about new AI because new ai, our virtual security analyst, um, so what we, we released like this four or five months ago, what talking to CSOs and the other security stakeholders, what I hear is like, um, they enjoy, um, not everyone is enjoying because to be transparent, not everyone is stepping up saying like, Hey, let me talk to virtual secure tenants. We need to break the ice more. Uh, but let's say for the early adapters who have more day-to-day operations, uh, they enjoy it because like, hey, now I don't need to think about which screen I need to go, which report I need to customize, which, uh, widget I need to build to get that visibility.
They're just chatting with Numi AI and getting that answer. So the critical part I guess is if you know your scope, like which is threats, um, exposures and, uh, infrastructure and the mitigations for pickup, uh, if we can really answer those questions for our clients and make the moldy needle for the needs, uh, that is like a, a huge achievement for us. And I can say that definitely there's room for improvement, but we are in a good spot, uh, with the, uh, pico data fabric and the know witchcraft we build on that.
And working with the G AI technologies, uh, we are pretty in a good spot and we always welcome anyone to to, to register into pick of product and interact with Numi AI from our free trial in the company page. Uh, so that's where we are. And like I don't talk too much about the future roadmap and what we opt to, but I hope it helps.
Like, I'm not sure how much time we have. I can talk more, I can give more light into that one too. Well describe what you think is the future of the cybersecurity team then.
'cause it seems like from where I sit, there's gonna be a bunch of AI agents that are trained for specific tasks and then there'll be humans working alongside of them and somehow or another this is all gonna get orchestrated. But, you know, how do you see this kind of evolving? Uh, in my conversations generally, I mean to like, guys, you need to do less and get more results.
So generally the organizations reflect is like, hey, how I can develop it, right? How I can customize a thread. 'cause you don't need to customize the thread, you don't need to build your own thread.
If you want to really build muscle to have more experience, you can. But if it is part of your day operations don't do that. We have the num, we have all the pick of red team, we have the thread library, we can build unlimited variants and we can do, uh, good, uh, curating your simulations and building your assessment programs in an automated manner.
So that's the direction we are going into. So I believe as you mentioned, like there's the virtual security analyst, they're doing the, uh, operational part like running a simulation. Hey, if we see that a security device block certain type of simulations or in a penance automation, if we see couple of road blockers there, then the AI agent needs to really curate the simulation to bypass those techniques and so that we have better results.
So, and not only that on the operation level, but on the high level, um, currently, uh, looking at the PDF reports, like we all have the charts and lists and the trend graphs, that's great, but it's also problem because people need to understand, analyze, and make, uh, analysis on that. What what I see is like we need to have like a executive report, uh, which I mean, um, in another level of executive reporting. So someone just imagine read, digest everything and just send a voice memo or just record the visual video saying like, Hey, this is the weekly report.
This is what you have been doing, this is the integration you have, this is the incident you have and this is how it goes. So the executive reporting, I believe it'll be like a one minute or five minute, uh, based on the audience. Is it like financial focus?
Is it business criticality focus? It it's just tech focus kind of reporting we're gonna get into and then it'll be two-way interaction, the from the report, Hey, what do you think about that? What do you want to do?
The security analysts we're gonna ask and the uh, leadership team or the manager will gonna say like, Hey, I want this action to be taken, uh, into consideration, or I want this to happen. Then actually the virtual analyst need to, if there's a, uh, change management process kick into that change management process or they're comfortable with moving forward, then make things happen. So I believe it'll be two way, uh, less friction or no friction conversation.
So we will boost the creativity of people in the organization because, you know, 70, 80% of the security engineers time is doing operational stuff that doesn't add add value to their skillset and not adding value to the business. So the idea is if we can really offload all the operational, not validated, not creative task to the virtual analyst, then we can make the security engineers job to be more enjoyable, less churn business and, uh, a better, uh, outcomes for the business. That's how I see that one.
So let me ask you this then. Um, how many breaches do you think are, and you know, it's an inexact science, but are not being discovered because security engineers are spending so much time on all this paperwork and scut work and all this other backend reporting stuff, when they should be ideally hunting down threats? Oh, good.
Great question. I believe if the compliance, uh, teams let us ask the security teams to do their job and to focus on what they need to do, not doing less paperwork, but more focused work, definitely fulfill the security, uh, programs will be on a different level, I guess. Uh, we are trying to really introduce processes like governance, but we are approaching from the wrong angle.
I guess the rules of the game are set by non-security guys doesn't understand the real value add, uh, of the security teams there. So maybe AI or maybe better visibility, uh, translating what has been happening in security to that language or will help or it doesn't help, like let's automate that stuff, the boring stuff so we can free up the time of the secret engineers. That, that, that is a hard problem.
I guess both venues may is promising moving forward. I'm excited for that feature. All right, folks, you're hearing in here.
Hey, if it's boring, if it's tedious, automated, and then move on from there. Hey Vulcan, thanks for being on the show. Thank you Michael.
All right, and back to you guys in the studio.