Fleming Shi Analyzes the Financial Impact of Cybersecurity Breaches
Barracuda Networks CTO Fleming Shi dives into a Cybernomics report detailing the real financial impact cybersecurity breaches are having on organizations.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Fleming, she, who is CTO for Barracuda Networks, and we're talking about cyber economics in a report that they have come out with that kind of has some interesting details in it that are both partnering and well, let's be honest, a little disheartening.
Fleming, welcome to show. Thank you for having me. Let's start with some of the more difficult things in here.
And the one that leap out at me was, I think the report finds it takes the average hacker about a day to crack something, and it takes the average cybersecurity team about 53 days to fix it. And of course, there's a lot more hackers out there than there are a cybersecurity team. So is there just fundamentally a major imbalance in the proverbial force, and how do we kind of fix that?
Definitely. I, I think the, the obvious, uh, signs in, in the sense of how easy is it for the hackers to, to get the, uh, to get into this environment and get the, get the ball rolling for them. Uh, it is being assisted.
Um, you know, obviously in the past there were data breaches as well as not the tooling, uh, involved in for them to actually get, get moving. It's, it is, uh, it's obviously, uh, uh, make, make it easier. Um, and, and, and if you think about it, uh, you know, it is when they come in and, and start using, uh, these tools, um, not everyone's prepared, right?
And it's also, uh, they're sort of in the advantage of having those data breaches in the past to actually give them the, the means and, and, and the routes. Um, and a again, I think the key here is the imbalance, uh, lies with the tooling, lies with, uh, uh, what they already have, um, on us, uh, to give them the upper hand. Um, so yeah, um, to some degree, uh, we're still getting excited about generative AI last year and, um, doing more stuff in production and, and, and deployment this year.
Um, but, uh, they already have gone ahead and operated in a, in a sense where they're, uh, starting to attack using these new tools, right? Mm-Hmm. So, yeah, so overall exciting technology is always, uh, um, gonna bring some, uh, additional challenges, uh, especially for the, uh, uh, for what we have to do in the, in the digital world and protecting our, uh, ourselves.
Yeah. Well, at the forefront of those technologies is ai and it cuts both ways. The bad guys are using it, but the good guys will be using it as well.
Who do you think is gonna gain more from ai? Will it be the bad guys or the good guys? And, and how will it manifest?
Um, I, you know, at, at the moment, if you look at generative ai, it's, uh, sort of the, the new form that, uh, that that's exci. It's exciting. Um, it's the innovation that's gonna get very strong.
It's gonna get very powerful. Uh, especially companies like philanthropic, open ai, these guys are gonna continue to make them powerful. Um, I think in this stage it's gonna be, um, challenging to say who, you know, who's gonna win, but you know, right now regulations haven't really caught on.
It's starting to, um, and, and it's gonna be making it more difficult for the good guys to, uh, to, to prevent, uh, these tools getting, um, getting abused or overused by the, by the attackers. So I, I think eventually it's gonna be always, I personally always, uh, sees it as, uh, the good guys will be able to use generative ai, um, and utilize it to, to do correlations and helping using natural languages to actually do, uh, data extraction for analytics, for security. All those things will be really coming, but at the moment, we're, we're gonna sit behind the scene a little bit because the bad guys are already activating and, and, and providing, um, a speed and a volume in their attacks, uh, these days, right.
Especially construction of these weapons are made much easier now. Yeah. Right.
And they have virtually unlimited resources, and our cybersecurity folks all work for a company that has some finite resources. So, speaking of that, are you hearing more from organizations about their sensitivity to cyber costs? I mean, it's clear that we are maybe spending more on cybersecurity than ever, but at the same time, we have more risk than ever.
So how are people having that conversation, or how do they understand the return on investment in cybersecurity these days? Definitely, as you can see, uh, especially if you think about, uh, the different, uh, mechanisms. So methods in the Mitre attack framework, if you think about, uh, uh, a way to map out the, the keys and the ways for the bad guys to get in, uh, it's over, right?
It's going, um, it's over 250 different type of methodologies that can be utilized for them. So it's very complex. Um, so the spending where to spend and how you actually, uh, respond, uh, once you get that detection, um, requires, uh, not only investment in terms of dollars, but also, uh, the time to put in, to plan, to test, and to, to really kind of run these, uh, run books, uh, to make sure you're really prepared.
Um, I think, um, these are all coming in. Um, you know, as you know, being in the industry for 20 years for Barracuda, we have seen, um, every attack surface being activated. Um, you know, like from the web application perspective, from uh, phishing perspective.
Um, and, uh, to that degree, I mean, if you look at the report we're talking about, um, the, uh, basically the, uh, in terms of damage, uh, it's o on average it's over 5 million, uh, per incident. On average, the ransom mask is over a million. 3 million as we talked about in the, in the report.
Um, but there's a gap, right? For the damage to actual ransom masks. So where's all that is really, uh, think about, uh, business continuity, uh, really, uh, loss of business, um, you know, operating through the incident.
Uh, that's also a major, uh, expense, um, beyond just paying the bad guys, right? Because if you're brand gets damaged or you're not able to operate, um, it is, it is, uh, gonna be equally painful. So, so that said, I think, um, these concepts are starting to come to light.
Um, and especially, uh, uh, there's, I think, you know, earlier report, um, percu Kuda had on the ransomware, um, uh, it is related to like 70 plus percent of the, all of all the different organizations in, uh, that we surveyed have already been attacked. Um, so the point there is it's, uh, uh, it's not a new thing. Uh, I think it's about how you resilience, uh, and it's no longer just about paying the ransom, but resilience should reduce the cost, uh, involved in, uh, getting your business back on, uh, um, back on track at the same time, uh, handling the, the ransomware incident or data breaches, or, because ransomware is no longer just getting the file back, right?
It's also about explosion afterwards. So all these things are starting to become more, uh, uh, I think, you know, very tangible in terms of, uh, dollar amount. So I think investment to reduce, uh, the damage should be focused on, uh, resilience.
Basically. Meaning if you are under attack, how do you actually, uh, short circuit the kill chain or basically take out the, the, the incident in, in a sense where you stop the attack earlier in the, in the kill chain, uh, it will be more economically viable. Um, and investment in that area is important.
Are we still having the wrong conversation? 'cause cybersecurity folks tend to think in terms of threats, and, um, they may evaluate those threats in terms of their severity, but the business side seems to think in terms of risk and recovery. So, um, you know, do we need to bring everybody to the table and start talking about the same thing at the same time?
Still? I think we do. As you can see in the report, we talk about what we call the high performers, and in the sense where they have seen, uh, and have created, you know, a better posture related to security.
Um, and though these type of, um, uh, I, I think, uh, activities involving, uh, beyond just the security team, because the security team is gonna be incident, uh, response base, right? Like, Hey, there's an incident, let me do these things. Um, but really assess your business in terms of exposure.
Uh, what are, the data has already been gone out in the past against you. Uh, you know, the, the security awareness training exposing, uh, who's at risk and vulnerability, uh, uh, perspective, all those things need to be put into play. And again, if you think about, um, tooling, it's not just one attack surface.
It's not just one area you have to focus on. It's, it is, it's broader. Um, and I think from that perspective, if you have those conversations about business continuity, about, uh, you know, uh, not only just for, you know, having enough budget for incident response, but also address the redundancy you need, uh, related to your business, uh, during an attack and, and, uh, uh, really, uh, test your, uh, you know, recovery, uh, time objective and point objective, uh, all these things, uh, at the end of the day, without a business, the security wouldn't matter, right?
I mean, this is the important to really have, uh, the two, uh, sort of the bound together and look for the solution that, that, um, addresses. Um, everything related to the business In terms of the economics and the cost. Are we getting better at deputizing other folks?
And I asked a question 'cause we have this chronic shortage of cybersecurity going on forever and today, but it seems like we are marshaling resources where the IT operations teams are more involved, the application developers are more involved. So is this becoming much more of a team effort? Definitely.
Uh, I think we talk about the cost of resources and, uh, the staffing related to, uh, to, to, to, to cybersecurity in our report. Uh, but in general, um, you know, there are, there are millions of jobs open. I think it's a, it's a large number across the world.
Uh, cybersecurity resources are, um, are scars, um, in, in especially, um, you know, having, um, having to face these attacks in different parts and different phases of the Mitre attack framework and having to be able to recover, right? If you think about all that, um, I think the key here is it might be too much, uh, to just get tools and hire people to do the job. It might take a long time to be ready.
So this is why, um, a lot of the things that we do at Barracuda is, one of the key things is we try to get certain tools, um, to, through our MSP and MSSP, uh, partners, because we wanna make these tools more accessible. And we do that is instead of just, yeah, hey, this is a, a great set of tools, go do what you need to do. It's hard.
And so what we, what we offer is basically SOC as a service right? Security operation center, which means that you have to think about, um, the analyst that needs to, uh, to review the data, uh, also the ingestion of the different type of data coming from your environment. So Barracuda, obviously we're into, um, XDR, we call the open next d where we are actually ingesting, um, uh, the information from any vendor doesn't have to be very good and correlate all those information through and build the, uh, build the capabilities to, to respond to incidents.
Now, this is the part that we're, we do talk about it in, in a, in a sense of generative ai. It will be a powerful add-on to a platform like XDR, because we now can, uh, ingest data much quicker, map the, the components and information much quicker, because large language models also have been trained beyond just natural languages, but also have been trained on terminology or even, uh, uh, machine data, uh, related to IP addresses in user agents and, and, and geolocations, all those things, right? So it, it is, uh, very capable, uh, and having that, uh, extra layer of, uh, uh, gene capability on top of XDR, uh, for example, uh, makes the job much easier, and therefore translating to savings, um, to, uh, end users and providing, uh, access to very powerful tools without having to deal with the staff shortage, right?
And, and that's, that's one area we're absolutely focused on. Are we in the middle of some great reset? And I asked the question because it seems like we have a mess of tools and they're not well integrated and we swivel between interfaces all day long.
And are we moving to more of a cloud-based kind of centralized platform approach that is both, uh, more effective and less costly? Definitely. I think there's always a little challenge, um, in a sense where we always talk about the data sovereignty and ownership, right?
So privacy related things as we break, uh, grounds on having more regulations, uh, and allowing us to certify against those, um, us as in vendors and, uh, obviously service providers, um, uh, certify against those regulations, you're gonna see, um, uh, you know, basically use, utilizing the elasticity of the cloud, uh, the, the overall, um, you know, savings in terms of spinning up data lakes, getting the, uh, the right AI models trained and, uh, applied into, uh, all different ca uh, use cases. Uh, it's gonna be, um, it's gonna be cloud future, it's gonna be, uh, you know, ingesting data from, um, uh, SaaS applications beyond just network devices and network, um, uh, you know, infrastructure components. I give you one example.
Um, there's one thing I would like to point out. Uh, in fact, uh, I think it's a great thing. It's, uh, it's a open source, uh, uh, situations called Open cybersecurity schema framework.
It's allowing us all the vendors to speak the same language, uh, defining our signals in the same format, and publish the signals in a way that tools can be used. Um, and in a, in a very large environment, uh, one of those tools will be, uh, uh, you know, Barracuda XDR actually is able to consume the data from, uh, AWS F, uh, F fabric and, uh, AWS, uh, security Lake, for example. The reason I say that is because this community of, um, uh, vendors, not only the security vendors and the, but also the SaaS providers, the builders for the SaaS applications are starting to work together.
So security signals don't just have to come from one set of tools, but also from all the SaaS applications, uh, that is kind of taking the world by, by storm, right? Everyone's using some type of SaaS. And, uh, um, and I, to me, I think from that perspective, uh, if we are speaking the same language, we're able to get data into the play place very efficiently, um, such as, uh, security Lake, um, and it gives us the, the ability to do correlation better and, and provide the services, uh, in a way that, uh, it's more affordable.
Um, and, uh, and if we can get that signal early in the Mitre attack framework, we can, we can basically prevent more expensive mistakes, uh, in those attack phases, uh, later on, right? So, so I think overall, I, I'm very positive in that type of collaboration between, uh, between vendors and SaaS applications. Yeah, The report itself, there's a lot of dense content in here, lots of numbers, lots of things to chew on.
What surprised you most in here? Um, it's actually, uh, the quick, how, how quickly we have broke the record in, uh, in the number of, uh, uh, uh, compromises. In, in 2023, we saw just the first three quarters of seeing over 2100, um, uh, you know, data breaches and all these, that was, the record was set in 2021, I think was in the middle of the, uh, the pandemic.
It was in the 18, uh, 18 hundreds and, uh, close to 1900. But overall, you can see that's at least a 10%, uh, increase. Uh, and 2023 to me is, uh, sort of the, um, the first year kind of, we really got back to normal, right?
And, and, uh, yeah, and where generative AI is playing a role now you can, you're gonna probably have to see, uh, a lot more volume. Um, that's a, that's a staggering growth in, in my, in my view. Uh, also, um, uh, you, you can see, uh, the cyber attacks, um, you know, based on the, the feedback, um, majority believe, um, the cyber attacks are getting more complex, uh, and, and exploiting, you know, obviously, uh, vulnerabilities.
Uh, and that's a good sign to me. And I will say, if majority folks are paying attention to this, that means they're gonna start focusing on, uh, detection and response and build that resilience, resilience that I was talking about. Uh, that's a good sign because we're in the post breach era where bad guys have lots of our data and, and people are being more aware, uh, will help shift the investment to the, in the, in the, in the prevention detection and response versus just have to pay the ransom later on and having a whole bunch of damage, uh, each incident.
So I will point those out. Yeah. So are you optimistic at the moment, or pessimistic?
'cause everybody I talk to is always walking around the same question, going, are we winning or losing this fight? Uh, it's hard to say winning and losing, but I, I am always pretty optimistic, partially because, um, I know I've seen what we can do with generative AI and, uh, this is the year we're gonna deploy a lot of the capabilities into our tools, our products, um, and, uh, yeah, when the exciting technology comes, comes along, again, generative AI is a new form that, you know, in the form of chat bots and using natural languages, parsing data easily and writing code, all that good stuff, right? So to me, it's exciting technology.
It's always gonna be misused. Now when something like that comes along. Now I think we need, we need a lot of help from the governments, um, in terms of regulating how gene AI is being used, uh, not only just for security, but also for risk and, and ethics, uh, perspective.
But those regulations are gonna, um, come a long way to help us in terms of actually put guard rails in places, uh, you know, putting, uh, the large language model, uh, creators, uh, uh, uh, you know, uh, innovation into, into the good guy sense safely, because they have to actually do certain things to prevent misuse of the, those large language models they're training. Um, so all those things to me is a positive, uh, future. And I, we, uh, and I believe, uh, any nation state actually helps with regulation eventually get to certification, uh, of, uh, generative ai and, you know, it will, um, actually drive better adoption, a more safer adoption.
And to me, it's a positive thing. So, um, yeah, so I, I'm, I I'm definitely on the positive side. All right, folks, you're heard here, the economics are getting better, but as always, the price of freedom and opportunity is eternal vigilance and cybersecurity is no different.
Fleming, thanks for being on the show. Absolutely. Thank you very much, Mike.
All right. And back to you guys in the studio.