FireMon’s Rich Mogull Breaks Down Cloud-Driven Changes in SecOps
Cloud impacts SecOps in ways both obvious and subtle, and since most organizations still have datacenters and offices, teams need to add new skills and update operations while still supporting everything already on their plate. It’s a daunting challenge, but one that is a lot easier to tackle by distilling down the core of how cloud changes things and taking lessons from the successes of early adopters.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
You know, I came up into the security world about 20, 25 years ago now, and at the time there were a lot of guys who had a lot, we all had hair back then. It was different color for most of us. And we were young and didn't know better about, uh, you know, the worlds of business and security.
But we thought we could do better in security. And some of us did do better in security. Some of us really had a, a kind of major impact in, in our, in this what we call today, cybersecurity world.
You know, I see it when I see people like our friend Andy Ellis get inducted into the Cybersecurity Hall of Fame. I didn't know there was one, or Ron Gula or whatever. My next guest is one of those guys too.
He is, I, I don't know if people really realize the full extent of where his tentacles reach, but whether it's, it's developing the, the curriculum for the Cloud Security Alliance training or teaching a black hat for, I don't know, it's gotta be 15 years, maybe 20 years of teaching a black hat, uh, Gartner analyst, he kind of, for many people was the DLP dude at Gartner and, and stuff like that. But then started Securosis with our good friend Mike Rothman, my friend. Rich Mogull needs no, uh, introduction.
I think beyond that, if you're a cyber person, if you're one of our DevOps or Cloud native folks, well look up Rich Mogull and his background. Or you could, but after this interview, rich, I hope I didn't embarrass the heck outta you here. You did.
Um, mostly 'cause you mentioned DLPI would like to apologize to the world for any involvement I ever had with the, Hey, look, I, I talk about nac. You know, it it, it happens, right? It it seems like a good idea at the time we're here, which is why we're, there's Work it's place for everything.
There's a time place for everything. It was college. It probably wasn't those, those days.
Yeah. Well, like I said, well, don't even go there. Anyway, for those who don't know, rich, uh, was analysts at Securosis along with Mike Rothman and then they start, started a company called Disrupt Ops that came out, it was actually a pretty early cloud security, cloud DevSecOps tool.
Uh, kind of put guardrails onto your, uh, cloud environment from a security perspective. Disrupt Ops was then acquired, well, d Disrupt Rich and, and Mike kind of combined with, uh, Jodi Brazil and, uh, Brandy Peterson, who had come from Firemont and they were running Disrupt ops. And then the folks of Firemont brought it in right?
And acquired Disrupt Ops. Disrupt Ops. Rich joined the com, the firm at Fireman where Rich, I think it's VP of Cloud Security, is that, Yeah.
SVP of cloud security. And he's been there, what about three years now? How rich?
Four years? Uh, Just about two years full time. I actually, okay.
Didn't go over completely at the start and, uh, yeah. Mm-Hmm. Alright, so I laid what we call the foundation down, giving them all the background rich Look, you've been working on, on the, on the, this Disrupt Ops project product, now firemont, it's gotta be about eight years, seven years of, of, you know, life in it.
And it's, and it's, you know, it's a product that is now pretty mature, right? Because you've had seven years to really kind of work on it, get the feedback, iterate, reiterate, et cetera. But for people who aren't familiar, why don't you kind of describe what, what, what, what you do here?
What, what, well, not what you do, but what the product does. Yeah. So the first thing is, is actually, I don't think anything is ever mature in cloud.
Like the moment you say you're mature, Amazon, Microsoft, Google, they're gonna change something. And you're, you're back to the drawing board again. So I think we're on like the fifth version of our architecture at this point.
'cause we're constantly like taking advantage of the new things. Uh, but anyway, so where we fit is we're kind of in that, that cmap realm, uh, cloud network, uh, uh, whatever that means these days. So we have kind of three major categories where our capabilities are.
One is on the cloud, security posture management piece of it. We're one of the only real-time tools on the market. I think there might only be like two others maybe that operate in real time.
So we have a real-time inventory. It tracks changes, it attributes who made those changes, checks for Misconfigurations. And if you misconfigure something in AWS, we're gonna send you a Slack or a teams message in about 15 seconds.
Uh, Azure's more like two minutes. 'cause you know, Azure's a little slower. That's, that's not our fault.
That's Azure only one so fast. Uh, so that's kind of, uh, and we're very, very DevOpsy focused. com, uh, back in the early days, 10 years ago.
Yeah. So we designed this to be very DevOpsy in the sense of like, you will get that slacker teams message. If you're the DevOps person, you're only gonna get that for the stuff you want to see, like critical and high issues.
You can fix it and remediate it right then and there. And you don't have to deal with security at all. Security of course, is still able to see all of that stuff, but it's like, it's in your hands as the DevOps person.
And we think that's a win for both sides. And it's kind of one of the, our philosophical differences in the market. It's, you know, let's let security be great at security.
Let's let DevOps be great at DevOps, and let's build a platform that works for both of them to allow them to communicate with each other. So that's that misconfiguration security assessment side. Uh, we got other goals stuff, uh, sorry, uh, kid got me sick.
It's okay. Like we have a, the cloud security maturity model, we just added that capability. So you can actually check the maturity of your program with KPIs as opposed to just looking at a sea of vulnerabilities.
That's really good for like the security manager building their program out, because it helps you figure out like, where am I weak? Where am I strong? Instead of just giving you like, again, a pile of misconfigurations and vulnerabilities.
The next thing is, is cloud detection response. And we're really operations focused. That's kind of our bread and butter.
The, the thing that we'd like to do that we think makes us different than, you know, a regular old CSPM on the market, because, uh, we have, we're real-time monitoring activity. Uh, we're real-time assessing that activity. We've got threat detectors and in the platform itself, a lot of tools to help a security responder investigate an incident.
So if there's the misconfiguration, we're gonna show you all the changes that led to that misconfiguration, we're gonna show you who made those changes. We're gonna show you the actual differences at each stage of those changes, the before and the after. Uh, and that really enables those security operators to move more quickly.
And then when security does need to jump in, or DevOps wants to use this as well, we do just in time, uh, privilege escalations. So now attack our privilege escalations, but, uh, adjust in time privilege system where right in Slack you can say request access with power user to this account for one hour window. And then that'll go around to approvers also in Slack.
And you can like self approve or auto approve for lower value stuff. But it's your choice. You set the policies up.
So like, if I want to go into any of our production environments, I have to submit a request and one of the other senior people has to approve it. I can't jump in. And then it gives me temporary credentials to access the environment for my window.
And then it tracks all of the activity during that session. So we think it's a really cool like security operations package, uh, where we're taking like what is often just like vulnerability assessment, vulnerability scanning things, and we're making that really an operational tool. Let's do it all in real time.
Let's track the changes that led to that. Let's communicate it to the people that matter, and let's give you some response capabilities if you need to go ahead and jump in and remediate. Or you can just let the, the DevOps team remediate it themselves.
Excellent. Rich, you know, I, I apologize. We never said the name of the tool.
Oh yeah. Service Fireman, cloud Defense. Uh, and actually as of yesterday, we put up a new website, defense FireMon Cloud, just to kind of focus on that so people don't get confused with our network products or the other things that we have.
Yeah. So I, you know, I was gonna say that a lot of people may know Fireman, Fireman's been around, geez, I I I'm gonna say 2005, 2006, two, you know, the genesis of it was fishnet security, I think, or in the early two thousands. Yeah, Fireman's been around for about 15 years.
Yeah. Stable company or, you know, the main product of FireMon is network security, policy management. That's really the bread and butter.
Uh, we also have an asset management product. It was lume, like the first thing to actually map the internet, which is for really, like, if you have millions of devices that you need to track on your, on your assets, on your resources, like that's the cybersecurity asset management tool that'll scale to that. Uh, and, but those are, you know, have been traditional, more data center focused.
They can't plug in cloud, uh, no NSPM Security Manager. It can, you know, manage security groups and Azure firewalls and Amazon firewalls and stuff. The asset manager can do cloud assets, but cloud defense is really, if you're the cloud person, the cloud security team, you know, we're the product we're focused on you where the one, uh, is gonna be focused more for the network team and the other, more for the, uh, asset management team.
But what's interesting is they all give you sort of that configuration management, policy management, but, but the, the, the cloud defense product though, gives you sort of a real time defense posture, right? So they, it detects attacks. It's not just the configuration or your policy management.
It actually detects when, when something's hitting the fan there and as you said, alerts you pretty quickly. Um, yeah. And Everything is like around security, operations, all of these tools.
Uh, and then just with cloud defense, 'cause the way cloud works, we can kind of look in real time at a broader set of stuff. I honestly, I don't know why more products don't do the real time piece. I mean, it is hard.
Uh, we, the, the tech we've got on the backend is pretty wild. It's all like serverless, event driven, born in the cloud, cloud native stuff. And maybe that's why, uh, 'cause some of the, you know, there, there are a couple of others that do this.
We're not the only ones, but most don't, they're like, you know, they do like hourly or 15 minute scans, which I don't know, that's not an operational tool in my book. Not for cloud. Well, not in today's world where just stuff happens too quick.
Right? Yeah. Um, rich, if you wouldn't mind give a, a sense to our audience of how do they engage?
How did they get started with this? Yeah, so it's really easy for us. cloud, or I mean the main website we have, uh, you can self onboard with our free trial.
So you don't have to talk to sales or anything else. We only collect an email just so we can get you provisioned in the system. Uh, and if you sign up there, you'll get 30 days of our pro tier, which is all the real time.
Uh, but we actually have a free version. And the free version is indefinite. And you can onboard as many Amazon accounts or Azure subscriptions as you want.
Uh, and well, I think Google, um, and that is, uh, the difference is is that the free tier, it just does a once a day like it. So if you just want to check in once a day and see what your stuff looks like, you can do free tier, you could load a thousand Amazon accounts, Azure subscriptions. We don't care.
Like, we don't put any limits on it. Well copy out. We have a 200 deployment limit when you first onboard.
Uh, then we ask if you want more than that, just submit a support request just for our capacity scanning purposes. So you could onboard a thousand accounts pretty quickly and do it, use it for free and use that forever. You just get a once a day assessment, but it's still all the same security checks, none of the realtime operational stuff, the pro tier, that's all the realtime operational stuff.
You get to check that out for 30 days. You need an extension, drop me a line, you know, uh, yeah. Drop Alan's name and uh, yeah, I'm, I'm good for a free exchange shape.
We Can, we can push that out 60 or 90 days. But the, uh, and you can do the prot, but we're, if you need onboarding help, we can help you. But it's, uh, I had to do a, I did an onboarding video yesterday.
Uh, it took me 90 seconds to onboard an Amazon account, start to finish. It's all, you know, very cloud native as you would expect. Cloud formation templates or Terraform, whatever you want to use.
You know what? There's really no need, no excuse to not go try it out. Rich.
I know you've, you've been working on a series of, of, of articles. com as well as Security Boulevard, as well as we're gonna be putting them all together into sort of an ebook, if you will, that people will be able to download. com.
But we'll, you know, we'll, the, the place to start, it's, it's, uh, cloud no defense. cloud. Was that it?
com, it'll redirect you. com. Uh, defense spelled the American way for our B European colleagues with the S, not the C.
You know what, 30%, 32% of people watching this probably live in, in emea. So, uh, that's a good, it's a good way to point out. 'cause I forget that all the time.
They, they spell it with the C. Anyway. Hey, rich, I appreciate you coming on and telling us about this.
And I'd like to have you back on maybe where you can maybe show a couple of screenshots. Actually, I think we're gonna do a webinar on this as well. Yeah.
Do we don't have a date for that or do we No, we haven't booked a date for it, but yeah, happy to do like demos and, and I really wanna emphasize too, for everyone, like we really mean it. The free is free. No strings attached.
You don't get a ton of marketing And no sales involved. People get freaky when the salespeople reach out. Yeah, yeah, yeah.
That was one of the things is we're very judicious about making sure that, uh, in fact, there's a checkbox. If you don't check it, we can't have marketing mail you. Uh, so, um, jump on, use free for as long as you want and join the first 30 days of Pro where you get all the real time adventure driven stuff.
Uh, and if that's all you need, we're fine with it. Honestly, we think CSPM has been fully commoditized, which is why we gave that part away for free. I don't know if it's fully commoditized, but it, there's certainly a no, no lack of, of, of solutions you could play with.
But you know what I, I, I would just emphasize and is look, of the three modules, they're all wor each one on its own is probably worthwhile going to check this out, putting them together. It really is. It's a great deal.
Go, go have a look at it. I'd love to hear what you, what you all say about it, rich. Keep doing what you're doing.
We'll have you back on soon. And, and we'll get that date on the webinar up on our site as well. Thank you so much.
Thank you very much. Appreciate it as always. All Righty.
Rich mogul, security rockstar here on Tech Drunk tv. We're gonna take a break. We'll be back in just a minute.