Economic Downturn & Insider Threats – Chad McDonald, Radiant Logic
Chad McDonald, chief of staff and CISO for Radiant Logic, explains how an economic downturn will make maintaining cybersecurity even more challenging as staff reductions increase insider threats.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Chad McDonald who's ciso for radiant logic, we're gonna be talking about some of the more unfortunate issues that have to be dealt with when we do have a downturn in the economy and there are folks who wind up leaving a company and some of them are not too happy about it and what you got to do to kind of protect yourself from that kind of shall we say Insider threat Then you're not quite expecting Chad. Welcome to Chef. Thanks, Mike for having me.
So we have seen a couple instances already where some it folks kind of vented their anger on a company by you know, helping to reach some of that stuff that they had access to it's probably not overly common but it does happen and it can certainly happen when folks other than it should organizations be thinking through right now as we kind of go through this downturn. We are seeing people resize their companies and you know, it's a difficult process, but when you got to do to kind of think this through completely, Sure, first off, you know open your eyes understand sort of that. There are potential for employees or staff contractors even to be not so happy with with what's going on in organization, whether it's you know, they themselves being impacted by a reduction force or their coworker, you know being in that situation or frankly even just being asked to do more work longer hours.
Lots of scenarios can sort of lead to what we call The Insider threat as you mentioned. It isn't exclusive to sort of the Post exit so if someone gets gets laid off or leaves the organization where that's not the only opportunity for Insider threat can be existing employees that are well with inside your organization your security parameter that you know, you should be concerned about as well. You know, the biggest thing that you can do for Insider threat You know the consider sort of the existing employee scenario is security awareness and it's always the cheapest and easiest way to sort of, you know, enable your staff to deal with security problems.
But I mean, it's really if you see something say something if someone is not a happy camper with, you know their pay or whatever, you know, there's an increased opportunity for that person to do things that aren't necessarily about board and so it has to be considered. earn different types of insiders representing different types of threats and are the it guys maybe Deserving more scrutiny because a lot of times they're creating back doors in the systems for their own convenience. But you know when things go wrong that may become something that only they know the way into right.
Yeah, I mean it's easy to Target sort of the IT staff as sort of the the 800 pound big bad gorilla or whatever you want to call it, but it's not the problems on exclusive to that group. It can be you know, Salesforce it, you know stealing sort of a Rolodex if you will or a list of sales contacts, it could be developers, you know. Adding that doors into an application they wish to you know deal with later on or you know, someone just manipulating a database for their own particular gain.
It really depends on your business model, but the problem is not exclusive to one group. The challenge with the IT staff is they generally have privileges that are elevated. Well above what your normal staff member may have and so there's obviously more risk there.
So I think that's why that group gets sort of a little more scrutiny than others. NASA seems like we don't really do a great job of managing privilege that it seems like everybody has access to everything and anything whenever they want that seems to be our default. So is that part of our problem is that we didn't really think through who should have access to what when and where It I mean it's absolutely part of the problem.
It's probably foundational to the problem the the reality and and I've you know been CIO a few different organizations. The reality is when you have sort of the Joiner move reliever scenario with the staff member a new hire joining the organization moving within the organization or leaving. Those are always opportunities for there to be sort of a Delta if you will with what they're Intended privileges are within an organization.
So if someone joins it's easier to say just copy my visitors account, you know, they're gonna be working in a similar role. We'll give them whatever permissions that person may not realize that you might or the administrator for a particular system. And so they've just inadvertently given this new employee administrator access.
And again the problem sort of expands out greatly in the scope and scale of this can get pretty pretty complex with larger organizations as people move around within different apartments. Typically, you don't see a lot of security around ingesting those privileges and entitlements as people move within the organization. They typically look at the new hire status and the leaves status primarily, but that moving that pivoting within an organization can you know as a blind spot for most places right?
And by the time an employee with a dozen years of experience leaves the company they've got access to just about everything there is because they've been in so many Functions and roles and no one thought to keep track of that because the IT people will just give people access to whatever the business people tell them to right. Exactly and you know you you add into the problem Mike when the reality now is that anyone with a credit card can go and subscribe to a cloud service or SAS platform that may or may not you know end up holding critical data, whether it's pii or personally identifiable information credit card information, whatever developers it admins, you know people in marketing can subscribe to a different system. They they're the administrator because they're paying for it.
Well, they leave there's company data in that system and no no one that they are the organization knows about it. So you've got this it for all and identities for all that tends to happen as organizations get complex and you know, our migration to the cloud hasn't really done a great job of corralling all of that access and one spot for many many organizations. We hear a lot about this shift towards identity is kind of the New Foundation for zero trust.
Is that how we're going to go and kind of solve this problem and it's not clear to me that people even understand what that means because you know, they understand that I have access to a password. Well, you know, their assumption is that you're already managing by identity. So what do we mean by this new construct for identity management and what's required?
Sure, and it's probably best explained if we do a little very quick history lesson on sort of, you know security and how Security started so I've been doing this a billion years, it feels like and when I started you had a Data Center and a data center had a firewall and all of the it systems were in that data center behind the firewall and you had a very almost tangible perimeter around systems that you wanted to secure an access that you had. Well today everything's in the cloud either an AWS or is your Google Google cloud or SAS platforms like Salesforce. There is no perimeter around that.
There is no controllable access no points. You can choke off if someone sort of leaves the organization or moves. The only thing that we have that is.
Consistent between those systems is your identity. So there has to be an evolution with an it to consider again. As you stated very eloquently identity has to effectively take the role of that firewall and that physical parameter that we had on our data center identity has to become the new perimeter or we really don't have a great shot of providing, you know, appropriate levels of security for organizations.
When this ultimately replace the whole username password construct then I mean are we kind of moving away from that model because frankly it seems to me anyway, the biggest problem we have with security these days is people's credentials get stolen. They're on the dark web and people have that stuff and they can log in anywhere and nobody's changed their password and God knows how long so um, yeah, is that what we're kind of getting in and moving to in how long will that Journey take? I don't know if we're getting away from it completely.
I think where we're seeing is an evolution. I I do expect I don't know for how much longer we'll always have username password type scenarios. But what you're also seeing as you know consumers see now, if you go to your bank's website and you attempt to log in from a new browser, it's gonna ask you some contextual questions where it's going to send a code over to your email address or to your phone or frankly, you're asked using authentication device to provide some additional information.
That's your multi-factor. That's sort of that. That was the next Evolution.
Now, you're seeing contextual based access where you know, you provide some information that you have or you know, but it's also saying what are you trying to do? And where are you trying to do it from does this make sense with your normal behavior? So you're seeing some intelligent supplied even beyond that to help.
Add a layer of security if you will to just that old worn out sort of username and password that we had back in the you know, the 90s that is effectively. Effectively useless these days from a security perspective. I mean, I forget that the math on how complex your password needs to be these days to stand up against modern Computing, but username and passwords against a computer these days.
It's relatively trivial to crack that and so you're always looking for some other information to help provide real security to credentials. I think we've all experienced that banking login thing that you just describe there but a lot of people are starting to feel like this is getting a little clunky because and not only is the banking thing. I got about 30 different other apps and every time I go in there someone's asking me for some additional info and you know, it's every time it comes across now, even I who know why it's there going, you know, we'll let out a little sigh and go ah, so is there a better way to think about this or do this as we move along here because it seems like there's a little fatigues there that said it already sure and I think the fatigue is warranted because they're there's you know, if you considered myself as a consumer, I probably have 40 different accounts across all the things that I just use in my home.
And I've got to do you know some various? I don't dance to get into these various accounts and it gets confusing and painful to deal with you can use things like password around, you know, password storage things like maybe a LastPass or one password or something like that. Even that gets just tiring.
I think what we're starting to see if you take the iPhone as an example, but not certainly the only example you're seeing face ID, right? So you provide some type of login initially to let's say your bank and then the bank application says would you like to use face ID to log in going forward? So what you're seeing is, you know, some sort of validation initially and then move to a device something you've always got that's doing some advanced level of authentication or I guess credential verification for you with your your Biometrics there.
I think that's what you're gonna see is an evolution for consumers. Organizations are probably gonna track something along those lines, but I think yeah, I think that as you mentioned the I guess the fatigue with the various constructs around how to log in is Weighing on a lot of people myself included and I I long for the day that I just have to worry about, you know, having a thing like a house key that I can I can use to log into sites. So coming back full circle.
Do you think that we need to set a best practices for not just onboarding folks but also off boarding them and we haven't really defined that. back end offboarding process all that well, because you know, there's all this excitement when somebody's a new employee, but when they're either quit or they're leaving there's this whole kind of you know, oh, sorry to see you go, but it's not, you know nearly as shall we say uplifting so sure but do we need to think that through I think we need to think that through and the move verse situation in the organization. I think there has to be sort of a renewed sense of so, you know seriousness about how we take these things and understanding that the environment or sort of the IT world has changed.
It's not you know, this this monolithic perimeter anymore. It's everywhere your your it systems are everywhere around the world at this point. And so there has to be sort of some amount of vigor with with how we sort of Define how we're going to do that and there has to be a very granular process for ensuring that we've you know adjusted permissions or remove permissions as a period as people bounce around to leave the organization.
It's a different model because it warrants the today's it environment warrants it be a different model than it used to do. You think the bad guys are studying our workflows and understand and how things operate before they strike because it seems like yeah stealing a credential and I use your past where it is one thing but it seems like they can get in there and start watching business processes and figure out exactly what that Has access to and you know, it might be they might be there for months before anybody realized to bring. Oh sure.
I mean you can just look at the headlines. I think you know not to. Call call attention to Samsung but they had a situation where I think they were breached in June and they didn't do a notification until September October which indicates that the bad guys as you know, we're in that environment for a substantial period of time and that was a short period of time we've seen cases where we're the attackers dwelled if you will and maybe even harvested information for months, I think sometimes over a year I've seen for the bad guys have been sort of inside that perimeter.
Whatever that may be just doing whatever or monitoring. So there is the opportunity for them to you know, monitor email look for business processes try to Pivot and and sort of find accounts with elevated privileges. I mean all kind of in various things and and the longer these guys.
Well the worst it is. How do we Elevate this conversation? If you're the security team you got a million things going on the business people have a million things going on.
How do I kind of make this a priority for folks where they're going to sit down and actually do that because to your earlier point, it's not just like I go buy a tool and solve this it's a people and process thing and that means everybody's kind of got to be involved. yeah, I mean it's it's so security has always sort of been tripped up by technology right technology is wonderful thing and solves, you know, a great number of security problems, but as you know, It's not the only it's not a fantasy. It's not a silver bullet that there are people in process issues that have to be addressed in sort of the security Paradigm.
If you will and until security teams your csos really recognize that identity is effectively foundational to pretty much every aspect of security. We're going to continue to see these problems there has to be sort of administrative controls around as United early or the processes with which we deal with joint removers and Believers from an identity perspective. There has to be sort of technical validation that users are only have the appropriate privileges and that's where something like AI or machine learning or behavioral analytics may come into play to help augments for the human element.
but until all of that happens these this this is what we're going to see you know, it sort of the The transition to SAS platforms into the cloud is not making this easier on anyone and we can't continue to rely on sort of outmoded processes for security to sort of deal with and evolving very advanced technology problem. All right in here, there's always gonna be a lot of external factors that influence people's behavior and we need they expect the proverbial unexpected Chad. Thanks for being on the show.
Thanks, Mike. Have a good day. All right back to you guys in the studio.