Federal Agency Infiltration and Supply Chain Attacks – Mike Lyborg, Swimlane
Mike Lyborg, chief information security officer of Swimlane, discusses why we’ll see supply chain attacks become much more debilitating to infiltrate federal agencies despite the increased focus on cybersecurity.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Mike lyborg. Who's CSO for swim Lane. And we're talking about the progress that government agencies are making on securing their software Supply chains, Mike.
Welcome the show. Thank you. Mike.
Good to be here. I think it's been about a year since the government issued their famous executive order and we've been kind of waiting for the downstream impact of that to play out because it takes a while for government agencies to get their act together in terms of new regulations new requirements. And then everybody gets a long lead time.
What's your sense of are we making enough progress here? And is it happening fast enough? I think so all in all it's such a massive scope that that impacts all of the federal agencies as well as us the software developers, right?
So I think moving forward there's a lot still to be uncovered on different formats and templates and everything else that we should use and best practices but overall is definitely a step in the right direction. Is it your sense that the development teams are taken charge of this or is it the security folks who are leading the way or are we actually starting to see some level of collaboration among them both? Maybe that's a great question.
A lot of the friction generally comes from where the developers want to move with speed and ease. They have a job to do just as well. So the security teams do and obviously the security teams wants to have greater observability visibility into the whole supply chain and everything that is going on that could negatively impact our products our customers.
So it is definitely a joint effort and a lot of Education that comes with it to make everybody aware of the risks that are inherited by using free and open source, or just your general supply chain, but with vulnerabilities and secrets and all the management that comes as part of those vehicles. Have you seen any best practices for achieving that goal in terms of bringing those teams together are there tips and tricks that you've seen people do I mean do I just throw them all in a room and lock the door and buying pizza and hope for the best there? Is there some other way to think about this?
It is definitely. Do small iterations of of improvements? So focus on the biggest risks first and then kind of drill that down and then get better there.
There's a really interesting or not really interesting but a pretty solid framework that's called the secure supply chain consumption framework. So the S2 c2f that's readily available for for people to consume or companies to consume and it it clearly kind of go step by step on. things to consider as we ingest all of this data and and kind of how we scan and inventory it and even goes into s bomb which is a whole topic on itself, but equally important S-bombs, of course are where people start with this whole process but it seems to me we're creating a lot of s-bombs maybe but we haven't really thought through how to operationalize those S bombs.
I mean once I create the s bomb everybody's got an s bomb. How do I know what's in the s bomb? And how do I figure out what to do as a result?
The one is surfaced in the asphal? Yeah, I think it here at swim Lane. We're still going through that maturity process because there's so many different standards.
So Especially when it comes to some of the vulnerability and findings on how do we measure how do we make sure and which standards did we follow? So we're still kind of waiting a little bit on on the government to tell us but that doesn't mean that we shouldn't continue moving in the right direction of picking us bomb that works by with and through your environment if it can be automated through third-party tools to give you greater visibility and and ability to flex. I think we want to get example is there there's Cyclone DX right?
They have a down exchange API that I can allows you to stay fluid as as the process matures and then there's the software package that exchange and There's there's several isobodies as well and documents that kind of call out the best practices on what? What do we need to track in that s bomb but they're now additional considerations as far as like, what are the hashes of everything? So how can you confirm that the the information that you consuming or your customers are consuming is identical to what you're delivering right as well as what you're bringing into your pipeline the whole life cycle where you at in the the phases of of this development and also signature so you're gonna sign it we can see for years that There's some for signatures even by some of the largest companies in the world that are not greatly being adopted.
So, how do we how do we lean on the right standards and formats to make sure that what we are moving towards is in fact the best practice. Sometimes when we focus on something we inadvertently shine a light on an issue that the bad guys can then exploit. So my question is do you think that we're seeing more criminals looking at ways to compromise these Supply chains in part because we've been talking about it so much for the last year.
Yeah, I think that there was a study last year by sonatype at the stated that we've seen an increase in the last couple of years by over 7 the 700 percent when it comes to supply chain attacks. So that is definitely one of our fears as well. As anybody else is well when we fully disclose and make this bill of material readily available for anyone now that can go through that pick list and say, okay.
Well what's an easy Vector in so still think that there should be some sort of controls around on how and who can consume that information on all the products in the world. Is it your sense that government agencies are ahead of or behind traditional Enterprises in terms of securing their software Supply chains? I think they're getting there.
They're probably getting ahead of it, especially with a lot of the large, you know, some burst or Orion and and these really large third party compromises that have occurred in the last couple of years. The visibility is definitely there and everybody's it's kind of scrambling towards. What's the next Milestone and how do we protect and prioritize the highest risk right now?
Do you think as a result of that prioritization we're seeing more organizations Embrace devsecops. I mean, I think we were down that path as it was but is that pace accelerated? Absolutely.
So there's a lot of really great tooling out there right now that wasn't here a couple of years ago when we really started talking about it. So I think as long as we as consumers as well, as you know producers bring these tools into our stack and and do the proper selection and batting on making sure that it's going to fit whatever operating model that we're under they'll definitely help us all out in the long run. What do you think is the single biggest issue?
Then that organizations are kind of looking at because it seems to me at least that half of this is technical on the other half is cultural. But which one is the more challenging? I think culture is is really a big challenge.
It's you can obviously consume these or you can you can procure these these tools to help you out. But if you don't update and kind of shift your your culture to have everybody Embrace third party and and supply chain risks and manage everything accordingly. Then you just have a bunch of tools that may or may not be doing you any good.
Right? There's also a big step in in the later part of some of these Frameworks that you go kind of from auditing of knowing. Okay.
Here's everything that we have. Let's order and make sure that our processes are kind of working to when you start enforcing it. I think that you that's definitely where friction is going to come in because when you stop blocking teams from being productive possibly because of a a risk introduced into the systems that takes away a lot of the fun for our developer friends, right?
So big culture shift a lot of education and figure out how to do this with the least amount of impact to people's creativity and productivity. when we think about friction, of course the topic of AI almost always comes up because people are basically trying to figure out ways to use AI to remove the friction and eliminate a lot of the toil. So what's your sense of?
What is the state of AI as we apply it to software Supply chains? I think we could definitely lean on it. There's a lot to be kind of still learned from artificial intelligence in general.
But as we as we start using it more and more I'm hoping that we'll see some favorable results. You're a long time see so and you've been working with Dev teams forever. What's that?
One thing you see developers doing over and over again. That just makes you shake your head and say folks. I think we can be better than that.
I think a lot of actually comes comes down to the development framework or sdlc or whatever. We want to call over the supply chain right as not so much where I'm currently at but in other places I've seen where maybe a team goes in with identify a vulnerability and we go ahead and remediate that and we test it everything's good everybody's happy and then because of some drift in some of the the systems someone later goes and adds another reassess same vulnerability back into the pipeline, right? I think that's one of the most common that you see another one talking to a lot of my peers is Secrets management.
So credentials as they're testing and devving. Unfortunately, sometimes people do not follow best practice and they just inject a secret into part of their code. And if that makes it through the pipeline now, this could be a really high.
square area of exposed and these credentials to Anybody out there? How do I go about shifting left to your point here about educating the developers? Because a lot of them when they were in school security was an elective.
Most of them didn't take it. So how do we go back in and kind of give them that appreciation for security in a way that they'll actually do it because we keep seeing the same classes of vulnerabilities over and over again at the application layer. So what is it that's gonna make them actually embraced the ship love.
I think we have to use a bit of a maybe Karen a stick or as might not be the right kind of way to look at it. But we have to award Obviously good behavior and we have to use training and and kind of like workshops. I think is probably a really good way of of putting people in a In a conference room.
I think you said early unlocking the door maybe in that fashion, but having the ability to sit down go through a Sprint interactively and say, okay. Let's go ahead and bring this in have we kind of cloned it how we ingesting it how we scanning it other process improvements and kind of make everybody be aware of everything that the security teams are doing and seeing as as code is flowing through whether that is on open source or container images that are being brought in to show them all the steps that this is what the security teams are doing and monitoring while you're going through your next Sprint for example, and that way they see that when tickets are generated and they now have, you know, created some technical debt and they see what it takes to resolve it and Using that as part of the education of saying hey if we would have could have should have done this at the very entry point. We could have mitigated a lot of this Downstream and and Technical Network that now is holding up the next release or whatever that may be All right, folks, you're hurting here positive reinforcement goes a long way and if we're all focused on new features developers will focus on new features and not security.
So maybe the problem is we're just don't give the developers enough incentive to focus on security. Hey Mike. Thanks being on the show.
Thank you, Michaels. My pleasure. All right, and back to you guys in the studio.