Edgio’s Tom Gorup on Combatting Rising Cyberattacks
With clients all over the world and across all industries, Edgio has seen attacks escalate since the second half of 2022. KillNet and Anonymous Sudan are still quite active and Tom Gorup, Edgio VP of Security Services Group, discusses aspects of their programs along with details that will help watchers thwart them.
Transcript
This is Techstrong tv. Hey everyone, welcome back here to techron tv. We're happy to have you back with us.
Our next, uh, guest, it's actually his first time on the show, so let's welcome him, him to Techstrong tv. His name is Tom Goup. Tom is the VP of Security services at a company called Ed.
And if you haven't heard of Edo, it's okay. It's kind of our job to tell you about them and hopefully you'll learn something new today. Tom, welcome to Tech Drunk tv.
It's great to have you on here. Thanks, Alan. Uh, I'm excited to be on here.
I think it's gonna be a great conversation. Absolutely. Tom, before we, we jump into kind of what our topic of discussion is today, I, I wanted to take a moment be or two because I, I'm, I'm assuming a lot of our audience is probably not familiar with Edo, and, and it is your first time on.
So let's start with you, Tom. Like, kind of give us your journey a bit. Sure.
Yeah. I, I think, uh, my journeys might be a little bit unorthodox, but I think that's the way of security, uh, these days. It's still, it's, I'd say it's in its adolescence, you know, maybe it's, its teenage years right now.
So, um, it not being very old, I think probably still have a lot of people that have come about it in a very unorthodox, uh, uh, not really non-standard way. So, where I, my background, uh, I was in the Army six years serving the infantry with Iraq, Afghanistan. And so doing a lot of shooting guns, I was doing a whole lot of typing on computers.
Uh, but as I was, since I was a kid, uh, I've been into technology. I think I built my first website when I was like 12 or 13, uh, years old using Angel Fire and GeoCities. I don't know if anybody remembers.
I remember 'em Really well, man. It was great. Yeah.
So you do an advanced website converted to a, a basic, or excuse me, do a basic website converted to advanced, and you learn HTML. Uh, that's how we kind of figured things out. Um, fell off.
That ended up in the Army for, for a while. But as I was getting outta the military, uh, I was trying to figure out what I wanted to do. I knew I wanted to get into technology 'cause I loved it, and the thought of, uh, the internet fascinated me that I was in Afghanistan talking to my wife over Skype.
It just blew my mind that I was able to speak to her by video as if she was in the same room and she's on the other side of the country. So I knew the internet, I new technology. So I ended up buying the CCNA study guide, uh, by a Todd Lamel, uh, Laley.
Mm-Hmm. Uh, great book. But I couldn't get past the, like, first four chapters.
I didn't have a lab in Afghanistan. I got caught and I just read it. I have no idea what it's saying.
And finally one day I got to the security section and it was like, this makes sense. Uh, I realized at that point, like I could take what I've learned in the military and apply it, uh, to computer networks. I just had to learn my tools.
I'm not using, uh, machine guns didn't claymores anymore. I'm using antiviruses and firewalls. So once that, like, I made that connection, I got really excited, got back from Afghanistan, started gonna school, and ended up, uh, going for an internship.
Got a full-time job, and eventually became co-founder of a company called Rook Security. Uh, where we did, we were one of the first MDR providers. Uh, I ran the, the stock as a whole, built it from the ground up along with a whole bunch of technology.
It was a ton of fun and exhausting at the same time, right around the time, you know, we sold to Sophos. Uh, so Sophos today has their mt r managed threat response while that team is seeded from Brooke. And I went over to a company called Alert Logic.
I know him well, I, so I ran the Socket Alert. Do You know, was that when Gray was Gray Hall, still CEO back then? Or this was after that?
No, it was just, just after that. Uh, I knew Gray, uh, I know Gray Hall. We were, um, so Rook, we were partners with Alert Logic, so Sure.
Bunch Of work. So Gray, gray and Misha were both, are both good friends of mine. Okay, Awesome.
Yeah, I know Misha as well, so that's great. That's when Year in Houston. Yeah, Yeah, yeah.
Uh, so yeah, I came on, uh, just afterwards, uh, it was with, with them for about, uh, over six years or so we sold to Fort, uh, which at the time was known as Help Systems. No, I don't think anybody heard of Help Systems before. I was like, who, who is this company?
Uh, but they had, They've made an impact, huh? Yeah. Yeah, they have in various ways.
You know, they have like cobalt strike, you know, things that you wouldn't even have thought, um, that they had. Um, yep. So we sold to, to Fort was there for a little while, and I've just recently come over to Edo where what I like to say is we make your websites faster and stronger.
And, and that's what was really exciting and compelling to me and coming onto this team, was that we have a powerful tool, uh, and set of technologies that can actually solve the web app security problem for, for businesses all over the planet. Uh, because, you know, when you think about your business as a whole, your website availability is critical. Your website integrity is critical.
You don't want defacement, you want denial service, but you also want to have very fast, right? Why wouldn't you combine those two solutions and solve real business problems rather than just trying to piecemeal your way to, to solving that. So I think a GO has a, has a sliver of the security sector that can actually make a difference.
And I've come on board to really build out our security services, uh, our soc, our threat intelligence and everything that kind of encompasses that. That's great. com, right?
Because I was back in 20 13, 20 12, I, I fell in love with DevOps, but my reasons was much as you said, right? The idea of being able to go faster, but in a more secure way, right? To go faster and let's make security synonymous with quality, right?
And so being able to do it faster with higher quality, that's, that's nirvana. I mean, that's, that's what we want. And, and, um, you know, I thought DevOps gave us a shot at doing that, right?
By building it better from the, from the get go, right. Than, than doing it kind of after the fact, after it was deployed and running and, and it was already kind of, you know, s um, and, and I think, yeah, we all, I, I think a lot of us, I mean, we recognize that's what we wanna do. Getting there is of course the, the issue.
Um, so, you know, Tom, what a, first of all, thank you for your service and what a great story this is of, of a vet, you know, an infantry guy picking up books while he's in Afghanistan and, and kinda learning enough to be dangerous, right? And then coming back and making a career out of it and, and really digging in. So, so congratulations and thank you.
Um, we live in interesting times, right? It's, you know, I know, you know, the, we got great economic news this past week or whatever, and it's all good, but in our tech industry, we we're seeing layoffs that we haven't seen in a long time. I, I mean, I've seen these cycles and I do believe they're, it is just cycles, but we're also seeing the world in a crazy place.
Democracy is sort of being pushed to the edge of the precipice almost, right? And we have, everybody's a hacktivist today. Everybody's a social warrior.
Everybody, you know, they, the first thing is, I don't like what you're doing first, I'm gonna boycott you, and then when I don't, you know, boycotting you, then I'm going to cyber attack you and, or, or, and that's just civilized people, right? Then there's the crazies of the world that are doing really, you know, destructive things, right? And, and hacking, whether it's, whether it's in the name of hacktivists or these hacktivists are, are actually being supported by, in some cases, nation state type organizations and resources.
Um, it, it just seems not more dangerous, but there's more, there's more stirring of the pot than ever, right? There's, there's more bad guys out there. It seems It, it might feel that way.
And I would also say it is more dangerous. I mean, uh, we, you may or may not have seen middle December, towards the end of December, we had dozens of, uh, emergency medical vehicles being redirected because of ransomware attacks, right? Yeah.
ERs were shut down. We're, we're talking about life at risk because of maybe minutes, uh, of a difference between which er and ambulance could go to. So the more connected we become, we become the more dangerous these attacks are as well.
So yeah, I think it's, it's, it's a mix factor. There might be more attackers that might be true. And I also think the availability of information, it, anything, anything used for good can be used for bad.
And that's the world we've seen over and over and over again from, you know, nuclear power to, uh, to, I mean, even recently, ai, AI has such amazing powers to improve our world, and yet is being used for nefarious things when you have fraud, GPT and other sorts of, um, uh, LLMs built specifically to do bad things like write ransomware, write phishing emails and all these, uh, other sorts of things. So, um, I don't know, the, it's a mixed, it's a mixed bag. I don't know if there's necessarily more attackers, but the availability to, to become one is there, and, you know, if, I know we had some, you know, positive economic news, but a lot of people are still feeling the struggle.
So if you're kinda stuck in that tough spot, you know, do you choose to maybe leverage some of these tools to make a little bit more money? I mean, how many more texts do you get these days that are, uh, hey, check your UPS package, uh, over here, and how many phone calls do you get are trying to coerce you out of money? You know, it's a funny thing, and maybe it's just my age or my preconceived notions, but I always, like, when I look, we all get these calls and smishing, you know, SMS phishing and, and all of this stuff.
And to me, I, my my, my first reaction is, oh, this is some call center in India or Malaysia, or, or the Philippines, or, you know, it's not here in the us it, it's those guys who are doing the bad things, right? And, and I guess that's something we, we as a world need to learn. It's, it's just as likely to be in your backyard as it is to be around the globe, right?
It could be anywhere. 100%. Yeah.
It's, it's mixed, right? Uh, if you, so I've been looking at a lot of data lately, especially when it comes to the attacks that we've seen at GIO over the past, you know, year plus and a, and a large percentage of those attacks are actually sourced from America from the United States. Now, it doesn't necessarily mean the person sitting at the end of that keyboard lives and sits in, in America, but to your point, um, a lot of the traditional ways that we might have put borders around our technology are aren't as effective because these attackers are seeing that they can, they can subvert that by coming from different angles.
But to your point too, is in these other countries, they, a lot of, uh, there's an article recently released about, um, talking about human trafficking and slavery that still exists in different parts of the world. And part of those are, these call centers, uh, are made up of people that are effectively enslaved to these nefarious actors that are deploying ransomware. And that's, that's what blew my mind.
I mean, they, a few years back, they have six, seven years ago when I found out there was a call center, if my grandma were to get ransomware and she had to send Bitcoin, which she has no idea how to buy Bitcoin, she could call this number and this person could help her buy the, the, the card she needs to buy to go buy Bitcoin to then send it to a wallet. There was a help center for ransomware attacks. Yeah.
And it just like blew my mind. But as you dig, you pull on that string a little bit. It's not necessarily the, the two that these people that are doing that are bad.
They, they could be stuck in that situation too. So, man, we live in such a fallen world, uh, and a lot of challenges come from, from different angles, you know? Yeah.
And, and let's be clear, but there also is a lot that does come from, you know, there's anonymous Sudan and kil net and some of the, the, the most recent or the, you know, attack du jours or the vector du jour, let's call it. Right? Um, and a lot of it does originate, and part of it is look, what, what's going on in the world and in, you know, with you Ukraine, Russia war, and in the Middle East, and it, it, it, it's just, you know, the world.
What, what was, when I was younger, there used to be a sign, it was always in day glow yellow, it said, war's not healthy for children in other living things, right? And, and it's not, it's, it's not healthy and it, it kind of spawns this kind of stuff. But Tom, our audience out here, mostly B2B people, right?
They have organizations they work for, they're targets. They're targets of a lot of these attacks. What can they do to defend against some of the, you know, and I used to say DDoS and we used to think of DDoS and okay, I'm just flooding you with traffic and overwhelming your, your, your, your infrastructure.
But DDoS, look, there's, DDoS is ransomware is DDoS, there's the traditional DDoS. There's phishing, there's, you know, there's a lot of different vectors that they use. How do we defend ourselves against this, you know, scourge?
Yeah, that's a great question. Uh, it, we've seen some pretty prolific attacks from the likes of anonymous Sudan and, and crews similar to that, where, you know, DDoS for ransom is, is a thing, right? There's these, uh, we talked about lowering the barrier of entry almost, uh, for doing something nefarious.
Ransomware as a service, DDoS as a service, these things are available. So it's not just for these exclusive groups like a non Sudan. And, and similar with these big names, potentially nation state backed actors.
Anybody could go purchase one of these and, and, and, and, and execute on it. The, the challenge I've seen a lot of businesses have is sometimes taking a like point solution approach. And I think that's something that, uh, that we have that has a great opportunity is making websites faster and more secure.
Because it is a layered approach. It's not just one tool, one silver bullet that's all of a sudden like, Hey, I'm protected against DDoS attacks. It, it's, it's not that case.
We have, you know, bots that can cause outages, that can cause, you know, increased costs. You wanna talk about denial of service, how about draining your bank account because you've had too many requests you can't afford, uh, to pay the bill on it, right? So blocking some of that traffic allows you more freedom and mo movement within your organization as well.
So I think what's important is that businesses are taking, I was just having a conversation, uh, probably right, right before, uh, this meeting is we were talking about, um, availability. So when we look at the security aspect of availability, obviously what's really important is that the website stays up. That's just part of the CIA tri act.
Confidentiality, integrity, and availability. We want websites to be highly available from a business standpoint, from maybe the app owner, the engineer, they want it up because it makes money, right? Both individuals, both a security person with the security hat on, your engineer and apps owner with the, their, their, their hat on are trying to achieve the same outcome.
A highly available, trusted website. They want it to be in, have, uh, consistency. They don't want it to be defaced, right?
Integrity's important. They don't want any data stolen. So whatever sits there should be confidential.
Confidential. So it's bringing these two together and aligning on, on these outcomes and not having one or the other. Uh, and I think that's a, that's a challenge that businesses face today, is they, a lot of these approaches are siloed in that way, and then we try to solve them in individual ways, but the reality is they're trying to achieve the same outcome.
So looking for solutions that can help you achieve that same outcome, make it con, make ensure that there can be confidentiality. Ensure that the site can have integrity and be highly available. So, um, it's the layered approach.
You want DDoS protection, you want bot management, you want a waf, you want your website to propagate the entire internet. You know, you wanna CDN it's, it's piecing these together to drive to, to the business outcome that you're trying to, to get to. I want a website that people can trust that's always available.
Absolutely. So anything that's approach that many businesses can take, that's the opportunity. Yeah.
So I will tell you, one of the things I see, Tom, 'cause look, I, I first got involved in the internet in 1996, I think maybe even 95. Netscape was in beta. It was Mosaic.
And, um, you know, that's when I commercially got involved with the internet. And what I've seen is a very similar, this pattern emerges with this kind of stuff where first you start cobbling together, just as you mentioned, I, I cobbled together. I have a, a DDoS protection, I have a ransomware, anti ransomware app.
You know, I have this for that, that for this. But it's almost like the power, you know, Einstein's relativity theory of gravity starts, these things start attracting each other and they, they, you know, it's like building planets. You, you start building bigger and bigger, uh, uh, applications.
They, you become a platform and, or you become sort of like edo, right? Where you have this lineup of, of soup to nuts, if you will, type of, of protections. And, and I think that's what people gravitate towards, right?
They don't want to necessarily, you know, do that. I call it a Chinese food menu, take one from A two from B and three from C, right? Of, of solutions.
They want one throat to choke. They want, they want one provider who can give them that range of, of protection that, you know, allows 'em to sleep at night as best they can. Y yeah, it, excuse me.
And the other part of that too is making sure that you have the people to be able to manage those. And it, I mean, that's my bias, right? Is, is services.
Right now we have a security skill, uh, security, security skills, short, short shortage, right? Yep. A gap across the board.
And to be able to pick up all these point solutions and then train somebody on those point solutions. And most businesses don't have a big enough security team to promise or, or really guarantee somebody to have a career path. It's very difficult for businesses to protect, especially their web apps in this, in this way.
So for me, you know what, keep, what, what drives me is, uh, actually a number of years back after I got outta the Army, I was gonna, the doctor for some reason, and I always make the joke that I went from shooting guns to typing on computers, and usually joke, that's better on the back. That isn't until you sit in the chair for 10, 12 hours a day. Then, I don't know, maybe the ruck sack is better.
He chuckled. But then he turned around and he said, but you're still protecting people. And that was that, that was that light bulb moment for me.
The light bulb. Yeah. That, uh, really was like, that is, that's my why.
And that, and that's where I believe services has the opportunity to bring in people to help others protect other people. And what, I mean, what better, uh, outcomes could you have than knowing that a business is more secure based on your input? So in, in a big challenge that our industry has is all these points solutions.
I was talking about it earlier, again, talking about like the traditional MSSP model. And we've seen a lot of businesses try to like, I'll take whatever you got. You got this endpoint tool, you got that waf, you got that firewall, this sim, and they struggled.
And they struggled because the technology sprawl, you can't find somebody that knows all those tools. It's next to impossible. So having services to overlay a powerful technology stack like gio, that's where the opportunity comes in, where I'm training my team on the GIO product, right?
So they're gonna have the depth and understanding to ensure that businesses are getting the most out of that solution. But to your point, it's a platform. Uh, so it is not just a point solution.
There's a lot of levers and, and, and knobs to be able to turn, you need an expert to be able to, to deliver on that. And I think that's what, what's, what's powerful, and we see a lot of this, A lot of businesses are gra gravitating this direction because they're seeing the same thing, right? That, uh, hey, I got a great piece of technology.
I'm finding that businesses aren't able to maximize the potential. And it just, it, it comes back to the shortage. It comes back to capacity.
How much time does your three security analysts actually have within your business to understand not only the technology stack, but understand your business, understand your architecture, and then keep up with the constant evolving threat landscape. That's a lot for a small team. Absolutely.
And, and, you know, a metric I always give to people, because I've had my experience in the MSSP world as well, is, is basically, you know, it, it used to be, and it's probably gone up a little bit, but you know, rule of thumb, 10% of your employees are in the IT de department. Unless you're an IT company, that's a different story. But your average kind of company, 10% of your employees are probably it.
1% of those might be security, right? So when you're talking about a company that has three full-time security people, you know, that's probably a company of a couple thousand people maybe, right? It it's crazy when you think about that.
But that, that's the reality of, of how security is staffed at a lot of organizations. And, you know, it's, it's a hard job. And I came to this conclusion a long time ago that unless you're a Fortune 50 and you could, you have that kind of resources at your disposal, you gotta get outside help for security.
It's, it's almost impossible to do in-house. Yeah. And, and that's, it's, that's so important.
Yeah. It, uh, uh, not to deviate too much, but right now I'm studying a, a tower babble. I, I gotta teach Mm-Hmm.
This Sunday and, and this, and this. One of the, uh, storylines part of that was, uh, that God changed our language in order that we'd humble ourselves to learn about another culture. That we'd have to learn another language, uh, to, to, to help, to get to a point where we could build a tower babble again, right?
And I, I think sometimes, you know, we, we should be able to humble ourselves and know that we need help. And also to humble ourselves, to help other people to know that hey, they need, uh, they have a different need than most other businesses. How can we, uh, adjust our technology, adjust their services to make sure that they're getting the outcomes that they need?
It, it, it requires everybody coming together to solve a problem and not trying to do it all on your own or, or, or, or build it all out. Like leverage your partners, leverage other resources because they speak a language that you don't. Right?
Uh, and how can we come together to a common outcome, which is a more secure, uh, business? Uh, maybe it's a parallel top of mind for me, but that's kind of where I was. Uh, Yeah, no.
Hey, mention, mention. I said Sunday School this week. Um, it's a great analogy, right?
And for those of you who think that just happened a long time ago, it's relevant today when we talk about technology and security. Anyway, Tom, we are, we're way past time, but I, it was a pleasure having you on here. We'd love to have you back on.
Maybe you'll come back and visit us and we can continue this conversation. Happy to, Alan. This was a, this was a good time.
Uh, I enjoyed it and thanks for having me on it. I'm glad, I'm glad you enjoyed it. You know what we didn't mention though, for people who wanna get more information about Ed io, where did they go?
io. Love it. io.
Excellent, man. Tom, thank you so much. We're gonna take a break here on, uh, text Drunk tv.
io. Thanks for being here. We'll see you again.
Stay tuned. We'll be right back. Everyone.