Enhancing Cyber Resilience with Barracuda’s Siroui Mushegian
Barracuda released a special CIO Report that delves deeper into new data and findings on organizations’ cyber resilience postures and perceptions. Siroui Mushegian, chief information officer of Barracuda, talks about how the report evaluates challenges relating to security policies, management support, third-party access, and how supply chains can undermine a company’s ability to withstand and respond to cyberattacks.
Transcript
This is Textron tv. Hey everyone, welcome back here to techron tv. I, uh, you know, I, I take it as a personal challenge to try to get my guest names right.
This is not that hard. Once they give you the little pneumonic that helps. But we're, if I mess up and I'll apologize in advance, I want to introduce you to Ou Ache, chief Information Officer, a Barracuda, ou.
I apologize for my thick tongue, but it sometimes it just doesn't work the way I want it to. And I, you know, I, I come at everything from a crazy New York accent of listening and hearing, so it, it's, it makes it even harder sometimes. But anyway, welcome to Text Drug tv.
It's great to have you on. Yes, thank you so much for having me. It's great to be here, and it's very nice to be speaking with you today, Alan.
Thank you. So, I always like to let our audience in on who's sitting on, who they're watching, who they're listening to, beyond their name and their title. You know, everyone has names and titles, but if we had to ask you, describe your journey right, to becoming CIO at Barracuda.
You know, there, there's young people out there saying, I I, I'd like that job one day. Yeah, I, I am, um, think it's a great story and I'll give you my elevator pitch. Um, so I started off thinking that I wanted to follow in my father's footsteps in finance as a young person in college.
That's sort of the trajectory I thought I would take, and I did in the beginning, I actually got a, a role working as an analyst in a municipal bond insurance company. I was there for a short period of time before I realized that was not really my calling, and I decided that I was gonna try something else. I wound up working for a small New York, uh, office of a French software company, just really quite by accident.
And that led me into my career in it. Uh, in that role, I was able to do some of everything. That was back in the day when you could build computers, and that's what I did.
That's what got me started, was learning how to build computers from all the components and going to the customers we had and making the installations, building networks, and then understanding from the product side how to build software. And from there, I got the opportunity, and this was in New York City, and I had the opportunity to work with some incredible companies. Uh, from there I worked at Time Inc.
Which at that time, sadly no longer exists, but at that time was the magazine division of Time Warner. I was also there during the a OL merger with Time Warner. Absolutely.
And the subsequent dissolution, very fascinating. From there, I worked at Ralph Lauren, which was an incredible opportunity. I've also worked at the National Basketball Association, traveling the Globe, supporting all kinds of events and the employees of the NBA.
And from there, I got a chance to work as the CTO for the New York based PBS, uh, station. W-N-E-T-W-N-E-T-W-N-E-T Is such an, what is the best incredible flagship. It's the, it's the best, produces the most content for all PBS.
And from there, I came out west working for a company called BlackLine, which does, uh, accounting software automation. And now I'm here at Barracuda as the CIO. And it's been an incredible journey, all meant to be here, uh, doing all kinds of amazing things for this company.
That's what an incredible story, sort of a quintessential New York story too, right? So an accidental tourist, and I, I actually have a similar background. I went to law school, I went, you know, I went to St.
John's University undergrad and then New York law and hated it. Hated law school. Hated, hated practicing law.
But I became the word perfect dude in our law firm. That's how long ago this was. Right?
I get it. And, uh, yeah, and that started off my computer hobby. And by 1995 or so, I was, I thought I was a digital real estate vocal.
I was hoping, you know, I was storing websites on servers. This is before we called it hosting. And, um, and that was it.
My life took a left turn and I never looked back. And, and the same kind of thing. Um, but you know what, I think one of the great things about tech, especially in these day, in those days, I don't know if this is true today, maybe I hope it is, but back then you could, you could just follow your dream, right?
And follow your passion and, and do that, you know, come from a finance back guy to wind up being a CIO or a CTO. And, and it was the same thing in security. I mean, of course, Barracuda is huge in security.
When I first got into security 25 plus years ago, there was no security degrees or majors or concentrations in school. Most of the people were self-taught 'cause they were passionate. They liked to break things and make sure they couldn't be broken again when they put 'em back together.
Um, it's a different world now in many ways. Maybe it's better, maybe it's not. I I don't, I don't know.
But, you know, you can probably make an argument both ways on that. But anyway, great having you on. It's a great story.
We were talking off camera. com days. And, and Dean was the founder of Barracuda, or he is, he's gone many, many years.
Last time I checked on Dean, he had some kind of surveillance, home surveillance company or something like that. But, um, Barracuda is many ways, in many ways kinda revolutionized security. They were doing, you know, they were selling, originally it was, let's call it what it was, cheap servers that sat right at your perimeter and basically did email security.
They added a little av, you know, a little of this and that UTM, which was big at the time, u unified threat management. And then, you know, did their credit pivoted to a big SaaS type of, of, of, uh, lineup. But today, Barracuda's so much more, if you wouldn't mind, give our audience a little bit of the scope, the breadth of the solutions that Barracuda brings to market.
So many. And that was really a draw for me in this role is, uh, I remember hearing about the position and thinking Barracuda, and that's a name that I've known for 20 years. And to, to kind of bend a fly on the wall to observe the, the growth and trajectory of the whole cybersecurity industry.
But then to be associated with it directly was very cool and super exciting. And of course, we all remember, like you're saying, where we all started. We all started as the appliance based business, email protection firewalls, and where do we go from there?
Of course, we're all moving to the cloud because that's where people are going today. That's where this company is going. We still have some appliance-based business, but we're still very focused on email protection and on cloud to cloud backup application protection, zero trust applications, um, which is, you know, a very hot topic these days.
Data protection. We've got managed XDR and SOC services, got our MSP arm. Uh, the list goes on and on.
Uh, we are not just a, you know, a one trick pony anymore. We have got the full spate of cybersecurity products and solutions that can help many companies and protecting themselves in developing their cybersecurity programs. Absolutely.
Absolutely. com? No, they switched a while.
Barta com. Barracuda ComCom. Yeah, I remember when that happened.
com. Yep. Um, let's dive in though to today's topic of discussion.
You guys recently released a new special CIO report looking into, uh, organization cyber resilient PO postures and perceptions, and Yes. You know, I've seen a trend where, you know, we always think the worst of security for so long, these reports would say, oh, you know, a majority of of CIOs are just waiting for the hammer to fall. Right?
Right. We're, we're vulnerable and it could happen at any time. And woes me over the last two, three years, I've seen some optimism, right?
They, they got more budget, they had a new, a new class of solutions, a new generation of solutions, and there's been a little bit more optimism that, hey, we're not impenetrable. We, we know bad things happen, but we're more resilient. We have better response processes and so forth, put in place and a little bit, a little bit more optimistic.
Mm-Hmm. And maybe reception's not reality, maybe it is. I'm, I'm interested in what this year's report shows.
Well, we work together, um, earlier, well, in 2023 to, uh, with the pun one institute, and we came up with the cyber NOS report, cyber NOS 1 0 1 report, and that report is helping surface companies. We, we had, uh, respondents of almost 2000 companies and the people that did the responding on behalf of those companies, either CIO C-level people or reporting up to the CIO. So you had a bunch of people that were providing survey responses, helping us understand how individuals in those companies and the companies themselves have been able to develop their programs and how they're feeling in general about their cybersecurity and the threat landscape out there.
The responses were, um, you know, that I would call them kind of varying degrees on the spectrum of really interesting earth shattering, kind of very cool to see how different companies respond and think all the way to the things that you would understand and just assume the, the responses would be the, the CIO report that, uh, dives a little bit deeper is the one we're talking about today. It's called the CIO report, leading Your Business through Cyber Risk. And that came out in April.
Um, that report, as you said, does dive in a little bit more deeply into how organizations are seeing their security posture. And interestingly, companies that are larger, that are like the financial institutions, um, those are the ones that feel the most solid. They're the ones that feel, they're the ones that have the bigger budget.
They're also the ones that have these interesting silos that present challenges for them to roll out their cybersecurity programs. So that's on one end. And then on the other end, you've got these smaller companies out there that have even more interesting, and as you would assume, challenges related to being a small company where you might have a very small budget and you might have leadership that has no real idea what the threat landscape is out there.
So all of this stuff kind of, uh, came to surface in these statistics that we have. Um, so that's sort of like the, the broad brush stroke of what we have here. Absolutely.
You know, much like the US economy is driven by consumer confidence, I think a lot of security posture and budget and, and just outlook is driven by the equivalent of consumer confidence, DIO or CSO confidence in their ability to meet, meet the mission, right? And, and, and make no mistake, right, I've been at security 25 years. It used to be the mission was 90% prevention and only 10% response.
I think one of the big changes is, I don't know if it's 50 50, but we, we, there's a lot more around resilience and response than pure prevention. I think we all realize that putting all our eggs in that basket's probably not a great strategy. Yeah.
I'd like to double click on that a little bit. So part of the report has a checklist that helps you create a roadmap of the way that you compare yourself in your cyber resilience program. This is connected to the latest nist, uh, framework that was released.
0, and it helps companies see how they should be building out their cybersecurity programs. 1 was really focused on the tooling that you had. So exactly like what you're saying, Alan, people focused more on, you know, what should I be doing to institute the different tools that I've got inside?
How am I gonna ratchet down my spam filters or do my, uh, you know, like, um, phishing tests and all that stuff, which is absolutely, positively very, very important. 0 is more around the people and process side of things. So it's the way you behave through a cyber threat.
It's the way that you prepare yourself on a process point of view, and then the way you see yourself out from the other side of it, it's how you're withstanding and responding to the threat or the incident itself. And so that's really the big difference. It just, you know, double just doubling down on what you said, Ellen, that's so important.
It's not just the tools that you're putting in place, but it's the programs that you're building internally, it's how you're training your employees. They're your biggest asset, they're also your biggest risk. So all of that.
Yeah, they are. I actually read an, an interesting article, I guess was last week on, um, is that always going to be the case? Is, is the human at the keyboard or the input always gonna be that weak link?
It's true. Probably, yeah. You know, I, it is what it is, right?
The weak, look, we've gotten better on that on that front too, you know? Am I close? Zero E?
Yeah, Zero E. You got it. I say a good after you say it, zero E zero e with these reports, there's always one thing that kind you look at and say, wow, I, I didn't see that coming.
Right. Well, well, what would you say was the big surprise Gotcha. In, in this, in this particular report?
You know, I, I would say that I wasn't taken by, I wasn't shocked by all of it, but the thing, if I could, if I could tweak the question just ever so slightly, which is more as what kind of pulled at my heartstrings as a cybersecurity leader, let me say it that way. Okay. The part of the part about it that, you know, when you work at big organizations, you take for granted the programs that you can build.
Yet we have our, you know, the world is made up of much smaller companies. There's not, you know, that's why there's the Fortune 500, the Fortune 1000, And there's only 500 of them. There's Only 500 of 'em.
You've got thousands upon thousands of smaller companies out there that have to rely on bubblegum and duct tape to put together their cybersecurity programs. And, and you know, I will say the, the thing that struck me the most is that their continue to be executives at organizations of all shapes and sizes that just do not know what's going on out there in the cybersecurity landscape. They don't know what the threats are.
And so, if you wanna say yes, surprised and also disappointed, a little discarded and, and definitely feeling for my compatriots who work at these smaller companies, these are the ones that have to focus the most on trying to get their executives, their leadership up to speed. And so you can't, you can't just assume that because you are so plugged in. You, the collective, we are so plugged in to the new stories and to the events out there.
It's these smaller companies where you've got the owner of the company, they're very focused on trying to get revenue, grow their brand, all of those things. And then they forget that cybersecurity is just lingering out there, not even in the background, in the foreground. It's not a matter of if, it's a matter of when, and that's the part to me that I just wanna drive home, is just the indoctrination to all levels of the organization or the threats that companies face out there.
So that's the answer. I, I, I, I, you know what, and unfortunately that's not a new thing, right? So I, I had founded a security co-founded a security company in Colorado back in 2001, called Still Secure.
60% of our business was DOD, which of course is cyber, very cyber focused. Um, the other 40% was commercial, mostly large enterprises. But then as we saw to expand and we, you know, went down market, if you will, um, it became painfully, painfully obvious to me that if you really, even in the Fortune 500, the finance guys and maybe the top 50 of the Fortune 500 have the, the, the, the manpower, the, the ammunition.
You kind of do their own security. But for the vast majority of the SMB market, the SME market, small medium enterprise market, even if they know what they need to know, they don't have the, they don't have the resources to, to do it. Which is why we, we, you know, I wanted to go to the board and saying, Hey, let's become an MSSP.
We should just, because they'll never gonna be able, even if they buy our tools, they're not gonna be able to use 'em. They don't have that expertise. They don't have 24 7 stocks.
They don't have, you know, all the things you need to really be up on it. And I thought MSPs were the, the answer, right? Or the vast majority of companies.
'cause security was just too damn hard. And you wanna know what, unfortunately, it's still damn heart. And then that's true.
Yeah. And I, I don't know what the answer is because you bring up even another threshold question. They don't even know what they don't know.
That's right. Right. The, once you know what you, or at least you realize you don't know something, you could then know some, you know, then learn it if you will.
If you don't know what you don't know, you're just ignorant, you know, ignorance and bliss until catastrophe strikes. Right. And you're a ransomware victim or something.
Yeah. Um, and that's the world we live in, unfortunately. Well true.
Yeah. It, it is. People who want to get this report, what's their best angle for this?
com and it's right there with all of our other assets. You can download the report, you can download the checklist separately. Uh, you can also get the Cyber NOS 1 0 1 report, which is a lot longer and has all the detail in there.
Um, I also encourage people to, uh, subscribe to our blog posts. They're very topical, they come out often, and I find a fascinating reading, even though, uh, whether or not I work at Barracuda, I think our content's excellent. com.
I love it. And what about you? What's next?
I know you mentioned you were just in Europe, not, not, not in a job. I'm not into meeting you leaving Barracuda. Take it easy.
Nothing else. Um, but what, what, what's next on your plate here? Well, we have, you know, we have to drink our own champagne.
So we are customer zero for many of our products, and I won't go into the details of which ones we are currently working with our engineering teams on. But suffice it to say, we, uh, work very closely with our product and engineering teams because we wanna provide direct feedback to the products that we're releasing. So that's a big area for this year.
Also, just, just continuing to make sure that our employees are very plugged in to everything they need to know. As I mentioned before, biggest asset, biggest risk. And so we just wanna keep building out those programs as well.
That's on the docket for this year. Enough to keep you busy. Absolutely.
Thank you so much for coming on Text on tv. Thank you. You a, it's been A pleasure.
We this one more time. Thank you, sir. Rui Mo.
There you go. GaN Ache. Yes, you got it.
GaN. All right, well, you're from New York, so I, I could relate. Um, Indeed.
All right, have a great time. We're gonna take a break here on Text Trunk tv. We're back in a moment with our next, uh, in interview, I think is coming up next.