Exploring Enterprise Cybersecurity Trends – Kanwar Preet Sandhu, Tata Consultancy Services
Dr. Kanwar Preet (KP) Sandhu, head of global strategic initiatives for the cybersecurity practice at Tata Consultancy Services (TCS), dives into the security trends that are having the biggest impact on enterprise IT organizations.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Kenmar, Pret Sandhu, otherwise known as kp, and he is head of global strategic initiatives for Cybersecurity for Tata Consultancy Services.
And we're talking about what to expect in 2024 because, well, if it's anything like 2023, hold onto to your chairs. Hey kp, welcome to show. Hey Mike, you said it.
Uh, if it's anything like 2023, you're in for rocking there, but thank you for having me and I look forward to an insightful conversation. I think the biggest change in the last year has just been the rise of generative ai and we know it's gonna help the bad guys and the good guys. We're just not quite sure to what extent, so what's your take on what we should expect with generative ai and then we'll dive into how the threat landscape is evolving from there.
Absolutely. So generative AI is really, you know, is new kid on the block, which has caught the fancy of everybody. It creates tremendous security opportunities, but at the same time, the potential threats are immense.
I mean, we are seeing an increasing number of frequency and complexity of cyber attacks, right, which are creating new pressures on the enterprise in terms of advanced threats, in terms of, uh, self, uh, evolving malware. You know, you have deep fakes, um, spearfishing to the next level and enterprises really need to fight fire with fire and they'll need to take and leverage the same technology to fight these kind of, uh, advanced threats. So I think while there is a lot of challenges and there is an imminent danger in terms of how AI is being used, but I think at the same time, enterprises have the opportunity to be able to proactively leverage AI to fight, uh, this threat.
So have we stumbled into something that feels like a cybersecurity AI arms race? Is, that's what's going on? I think you said it.
Uh, everybody's looking to harness this, uh, but I think AI brings a lot more benefits to organizations in terms of the competitive edge that business gets out of it. So businesses are also racing to adopt this into their environments and leverage it to, you know, uplift customer service or uplift analytics, uplift insights, engage with the value system that they have better, but at the same time, these threats are there and there is an expanded surface attack surface that is coming to being. So we need to leverage AI and we are seeing that you need to keep pace with these attackers so that they're gonna try and, uh, get into this attack surface, get a hold of all of these vulnerabilities that are coming in, whether they be within the models themselves or the attack surface of how these models are integrated or interact with users, right?
Data loss or inference based attacks. So I think there is, uh, a tremendous race out there to be able to get to the right kind of, uh, detection and response control. So yes, we are in a form of race with these kind of attackers.
I think the bad guys may benefit sooner than the good guys 'cause it just takes a while for the good guys to get their arms around things. But we've been dealing with this cybersecurity skill shortage for such a long time. Do you think ultimately AI might help us level the playing field a little bit?
'cause right now I'd say it's decidedly uneven. You said it. I think we've got things like worm GPT that are already out there and I think it's, it they're being leveraged quite effectively.
And I I've seen AI as a service in the wild on the dark web being leveraged for quite some time, right? But on the, on the good side of it, right, it can be used to vastly improve cyber resilience. You can have self-healing autonomous systems.
You can have automatic configuration hardening stuff, which is mundane can get. So you can reduce your false positives of there are various applications, both of whether it is Sufi supervised machine learning or otherwise classification. So I think there are some immense applications in terms of being able to support analysts in terms of being able to identify excessive privileges within the environment.
So these are all vectors that have really impacted organizations to a great deal, right? And I think AI can bring, uh, it can literally be the silver bullet for these kind of critical problems. As part of that, can I reduce the time it takes to train somebody to become effective in cybersecurity with these tools?
Because I think that's one of the big issues is when you hire somebody, it can take six months to a year to get them rolling. And by then I may have lost some of my other analysts 'cause there's a lot of stress in the whole job in the first place and they becomes this kind of flywheel effect. But can we kind of have a different dynamic here when it comes to skills and training?
Yeah, a fantastic point and very true in the sense that you can have, uh, adaptive training systems that are able to adapt to the kind of learning environments and individual requires, right? And, and also it lowers the threshold that one needs to start with, right? So you need, you can start at a lower, your entry barrier to become a SOC analyst reduces so in the sense that while you would still need to cover the essentials, right?
But because there is so much support that something like a a, a co-pilot, an AI co-pilot would give you, right? That, that it is actually able to support you in doing some of the advanced analysis, et cetera. So it's like having a buddy who's able to continuously support you and uplift you.
So as a result, you, you'll find that the stress and pressure of, you know, having to find the right answers and being able to look at multiple knowledge repositories goes down. I think, uh, it's a fantastic point you make and I think going forward AI will definitely make the difference in being able to bring consistency, automation, and the right kind of support to, to our talent. Part of the issue as far as I can tell is that there's a disconnect between the cybersecurity folks and the rest of the IT organization.
Do you think that generative AI might help bridge that a little bit? Because I can explain to people whether they're developers or IT operations people, not just what needs to be done, but why it needs to be done and maybe even suggest ways to go fix things and we can just close that loop faster. Absolutely.
I think that, uh, understanding and the knowledge that needs to be created in terms of developing a baseline across the enterprise will also become faster. And I think because you're able to adapt and, uh, adopt the technology much faster and it, it reduces the cycle time in being able to bring things as an outcome. I think that is definitely a point.
What is your assessment of the current threats that we're facing? Are they getting more sophisticated? 'cause Well, they're clearly increasing in volume, but um, historically a lot of the attacks have been fairly low level and with some decent amount of hygiene, they would've been thwarted in the first place.
But are the bad guys getting smarter, Way smarter, I think, like I mentioned earlier, so it would take some time to create a polymorphic low and slow attack earlier. But today I think, uh, AI brings that capability and research has proven right that you can use these kind of systems to develop that kind of malware that is extremely advanced, stealy sophisticated, it evolves by itself and it is polymorphic in nature. So it allows you to combine multiple strains and be able to lay dormant and learn more within the environment before it actually decides what kind of threat vector to instigate, right?
So I think, uh, these attacks will definitely become far more sophisticated, which is why enterprises need to look to start adopting AI and look at the slightest in inflection within these kind of environment. So you need to have a much broader telemetry that you're able to assimilate into, uh, a large security data lake and a unified platform and be able to orchestrate this telemetry that generate the right kind of insights, these kind of advanced attacks with the slightest of inflection you're able to detect. Plus you will find that wherever privileges are, uh, escalated or user behavior becomes different.
So, uh, you, we always had user entity behavior analytics for quite some time now, but AI will, or advanced AI rather, will take it to the next level. You'll be able to actually figure out that, uh, if there is a difference between how critical systems were accessed earlier and how they're accessed now, and those kind of inflections in the environment will allow to fight such sophisticated attacks, but you're spot on. These threats are going to become more and more sophisticated and we are going to need far more sophisticated approaches and tools to be able to detect and protect against them.
You've been doing this for a while. What's that one thing you know, that you just see organizations keep doing and just makes you shake your head and, you know, and, and maybe it's a bit of a pet peeve? Well, I think it varies from organization to organization, but, uh, within security, the, the one thing I I think, and everybody's now looking at it, is that we try and throw too many technologies at a problem, right?
And sometimes the problem could easily be solved with a process, and I think the simpler your environment is, the better off you are, the more complexity you add in terms of the number of tools that you have and you try and orchestrate across siloed tools, I think that is something that is, uh, that that really, uh, brings a lot of difficulty to the environment because all of those integrations bring certain chinks to your armor, right? I think it, it is definitely, uh, given that the more complex security ecosystem is, and the more integrations you bring in and the more difficult it is to, uh, do, and you're also TCO also, uh, goes up, right? You're not able to manage those tools more effectively and you have that many more points of management to handle.
So I think the, the future is going to take care of this problem. We see a lot of, uh, leading analysts, a lot of enterprises today because we see a large extended digital ecosystem, right? And there is integrated supply chains that are there.
So this digital infotech supply chains, security supply chains are all going to get far more consolidated and tools are going to get integrated and, uh, simplified. I think that's, that's where the market is headed. So we're shifting to more of a platform centric approach I've taken, is the reason for that because I can make my team more productive or is there just a kind of a reaction to the fact that the CFO wants to reduce costs?
So we're finally figuring out that platforms might be the way to go? I think more the former, but it is, it is a, I wouldn't attribute it to a single reason, right? I think that there are multiple reasons, uh, and uh, a unified defense platform or a unified platform for being able to manage your security services is provide you multiple benefits and a reduced total cost of ownership is obviously one.
But I think, uh, the, the key, the key aspect that I want to highlight is that it reduces the kind of chinks in the armor that you have. I mean, it, it allows you to have a much better security posture. You're able to orchestrate telemetry across and get insights into a single pane of glass much easily, right?
And you today, with the increased spotlight on CISOs and the kind of pressure that is there and uh, you know, they're talking to the boards directly, there is a need for them to communicate the right language. When you have a right orchestrated platform that gives you a single pane of glass, it allows you to manage all kinds of reporting, right? So your executive dashboard reporting can be at a certain level and it gives you those kind of metrics which the board or your c-suite would be looking at.
And then from the same dashboard you would be able to drill down to a certain level, which lets you know, what is the patch compliance or what are my 10 riskiest assets, or which are the most vulnerable assets or which are the most critical vulnerabilities in my environment? I think it's a combination of all of those. You mentioned pressure on CISOs and there's been some high profile legal cases as of late.
Do CISOs need to kind of rethink their relationship with the organization a little bit? What, what ultimately will be the downstream reaction from the CISOs as they kind of see these cases proceed? Yep.
Yeah, I think with, I think that quote from Spider-Man, right? So with the I increased responsibility comes, right? Uh, if you're in the spotlight and you're, you're given the responsibility to, uh, fortify the kingdom, I mean, you need to step up and with that spotlight will come that responsibility of being able to manage and be able to secure the organization and take a step back and not be tactical or look at just enforcing compliance and, but talk strategy and see how cyber delivers, uh, competitive advantage.
And that, that simply boils down to be able to inspire trust with regulators, with your customers, with your larger stakeholders. I think if you can leverage cyber, uh, from a strategic mindset, allow it to deliver competitive advantage to the enterprise and inspire trust across your ecosystem, I think, uh, and, and that is a fair ask from a cso and like you rightly said, there are certain, uh, issues with that increased responsibility. I think, uh, holding CSOs and even higher than those in the csuite personally responsible is something that we are now seeing.
But, um, I think that that accountability is not just stopping there, it's going to go up to the boards as well, right? And in the next two or three years, we'll see that, uh, almost, uh, 70% of boards will have a cyber seat, um, on, on within that forum who will be dedicated to looking at this risk and bringing the right kind of inputs to them. So it, it's all good if you ask me.
I think the emphasis is required and we need to be able to, uh, get this kind of, uh, traction and that seat at the table to be able to deliver the kind of results that are expected from us. Alright, folks, you heard in here if your spidey senses are not tingling, you're not paying attention. So it's gonna be an interesting year.
Buckle in and get prepared now because if you're waiting until next year, it's gonna be way too late. Hey kp, thanks for being on the show. Thank you, Mike.
Thanks for having me. It's a pleasure. Thank you All.