Focusing on Strategic Investments – Bob Maley, Black Kite
Bob Maley, chief security officer (CSO) for Black Kite, a provider of a risk monitoring platform, explains why despite economic pressures it’s not likely cybersecurity teams will be able to do more with less so the focus needs to be on making the right strategic investments.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Bob Maley who's cheap security officer or black kite and we're talking about how to survive essentially. We are in an era where there's a lot of struggles going on in terms of I can't find enough people and now folks want me to reduce costs. If you're a Security executive and Bob has some thoughts on how to maybe approach that whole thing Bob.
Welcome the show. Thanks for having me. So how do I actually do more with less because it doesn't seem like the bad guys have any concern about the economy.
They got more money than they know what to do with and all the resources to go with it. And we're now asking security folks to do more with less. And what does that look like?
And how do we get there? well We can. I've been in the industry for a while and I remember two specific times where I was asked to do that and when you try to do that, it just makes things more fragile and it doesn't really work and and I think that today if that's the focus of people with information security.
It's gonna be a problem and there's a different way really you have to look at it. You can't really do more with less. It just doesn't work that way and you're right the bad guys, they they have more and more while we have less and less.
All right, but the boss at the top of the food chain is telling everybody to do more with less. So what can I do if I'm a security professional? I know we've been telling people automate functions forever in a day, but it doesn't seem like we made all that much progress on that front.
So where should we be looking towards to at least become maybe a little more efficient than we are today. Well that whole automation processes. We could probably do a whole other talk about that, you know, there's a lot of automation but it's it's are you automating the things that actually our productive and give you valued and I think a lot of times people are just doing automation just to you know, make appearances but what's interesting, you know, you say about the folks at the top, you know singing, you know do more with less and I was in a sea, so chat group yesterday in this topic came up and they conducted an informal poll.
And what was interesting is that nobody was actually told to do with less one. Third of them weren't even weren't even affected but two-thirds did actually have management give them some advice that said as we go through the year if we want to do something just make sure the money we're spending actually has effective return on our security posture and you know, what's I guess the outlier for that is the group of cisos that I was with the fact that they were together discussing challenges puts them in a higher level of information security in my book a lot of a lot of folks. I know they're out there trying to you know, do this whole fight on their own and that they don't have that that Network they might be challenged but I I think the majority is I don't think it's gonna be a challenge to be honest with you.
All right, and yet they are being asked to come up with something that feels like maybe a return that can be justified and I've always felt it's very difficult to come up with something that looks like an Roi in the security space because you are trying to prove a negative essential. Exactly. So there's a lot of new thought and and some old thought around that something it called a quantitative risk assessment process, you know, essentially with that is it's an effective way that you can look at a particular scenario that you want to address.
So let's say I want to I want to spend money to add a specific control to protect, you know, the jewels of the crown jewels of the company and you going through this this process I can't actually do a methodology that you know, I input and then I can understand what's the likelihood of this happening but more so than that, what's the probable Financial impact so, you know essentially I can show well if this control is not in place, here's the probable Financial impact. We'll see in the next 12 months. But if I do put this control in place, here's the reduction in that and now I have a business convers.
Because well if the cost of the control is 10x less than the probable impact I've now shown. To leadership that what I'm doing is going to be very effective and if they don't want to fund it well then I've also showed them. Well, here's here's that that risk that we're gonna face and as a business decision, well, they're more than welcome to accept it.
But now I've converted what I'm doing into a business decision talking about the bottom line as opposed to yeah. I've been around long enough to to know that fear uncertainty and doubt 20 years ago was very effective in getting budget today not so much. Do you think folks are trying to consolidate this security tools and platforms?
They have to at least maybe not about reducing costs as much as it is. I just don't have enough people to master all these tools. So maybe I need more centralized approach that doesn't require and you know, I'm team number of tools that each team remember has to figure out how to master.
Yeah, and again, there's two sizes of that coin there. There are those folks that They're dependent upon the tools to do their job and they think that adding another tool to their to their tool belt will make them more effective without really understanding. What's what's the value of me putting that tool in place.
So if I've developed a program that I'm always looking at value of those tools as we Implement them. I don't think I'm gonna have that same type of a aha moment that I don't have enough people. But if I've just been throwing throwing money at things I remember being in a an organization well that they had a tendency they had a lot of money and they threw a lot of money at at devices at tools and projects, but they weren't able to move that that bubble, you know to to reduce that risk.
And so it's just how you look at that and if you're looking at when you evaluate tools and you may if you are in that crunch understand what those tools are doing for you are they actually bringing any value to your program or they just doing a compliance check mark now here in the the financial world. Yeah, maybe a compliance check mark, you don't have much choice and getting rid of it. But in the real world that compliance check mark may or may not really reduce that risk.
So start understanding the value. What are those tools bring to you? And I I just saw a graphic.
It's called the the Cyber zoo. And it's a graphic of all the Cyber companies that have an animal in their name. The reason I saw it obviously black kite, you know, that's a hawk and so we're in that Zoo, but I'm looking at it.
I'm going wow. I know there's a lot of cyber companies and and there's a lot that don't have an animal in their logo, but there's a lot to do. So there's so many companies out there that are producing tools, you know, a good information security practitioners got to get really down in the weeds and understand where you implement that tool.
Is it really gonna bring you there don't listen to the vendor vendors will tell you things that have absolutely no connection to your business and your bottom line, you know understand is it really gonna help you. Are we too enamored with tools and platforms and not focused enough on process? Well, yes and process is always good because where does everything usually break down?
It's either people or processed and if tools can help you effectively execute processes that and one of those processes is data analysis. We are in non data with data these days. There are so many sources of threat Intel of Open Source intelligence of threat feeds everybody.
You know, it's it's a nightmare and tools that can intelligently sift through that information and find out what's relevant and what's important tools like that I see value but yeah, you know you talk about a process and you know in the world that I live in you know with our company third party risk management. The Big Tool is questionnaires. And you know, if you're a vendor you you have invariably in that sales process have been asked to fill out a long and burdensome questionnaire and we go through that process because well we've been doing that process for a long time questionnaires have been around for almost 20 years now and you know the federal government had guidance that that was the best way to assess third parties and we're still doing that and Well, there's companies now that are automating that process that they say.
Well you don't have to send spreadsheets to do your questionnaires. You can just go out to a website and we've automated that and it makes it easier to fill out the questionnaires and and but nobody's asking the question well. Are they valuable are they actually doing anything what I'm assessing the risk for that third party is the information in that questionnaire.
Number one. It's point in time. The second thing is it's aspirational at best whoever's filling it out at the organization.
But you know from my point of view. Well, you know, how valuable is that is a bad actor gonna look at those answers in that questionnaire when they're trying to figure out a way to hack me and the answer is no that actors. Don't do question errors.
Speaking of processes we cannot walk down the street without somebody touting artificial intelligence in one form or another. What's your sense of? How real is AI is it applies to cybersecurity these days?
So up until about two hours ago. Yeah, it's did some some value, but I finally got into what is that chat at apt and he I think that gbt and I asked it a couple questions. and it scared me.
I'll be totally totally honest with you. If if it can where where was that when I was going through college and Oh it is it's scary. And you know, there's the whole concept between machine learning and AI, you know, they're not the same thing obviously and machine learning is is extremely valuable in a lot of scenarios, but it it's also machine learning that needs to be trained and it needs to be effective.
You know, we do some machine learning things in our platform, you know, and and part of that is analyzing all those artifacts and documents that you know, the sock two reports in those questionnaires and yeah fairly effective but to keep it valuable and relevant it has to continually learn so it's valuable when you're doing that and what this next level this this Chatbot that it's like wow, I need to look more into it. It has changed my thought about the future of the influence of AI it's going to be interesting. And of course the bad guys are looking at those same tools and going.
Oh boy. Yeah exactly. They yeah and and they won't have any hesitancy and using it and acting on it.
Whereas in the corporate world before we use something we have to go through a process to get it approved. And before we act on it, it's just it takes us so long to make decisions, you know the agility and I talk a lot about this is there's an agility gap between what the Bad actors doing what we do and and they're far more agile. They can pivot in a heartbeat and and they do it's obvious to watch.
You know, we just saw a very unique shift in It's a combination of spearfishing and social engineering that you know, they launched against us and it's like we some research and we hadn't seen anything like this yet. This is the first time that we've seen it and the the package that the malware package. We haven't completely analyzed it yet, but it's It's a slow roll when if you executed it doesn't do anything for quite some time because it's waiting for antivirus and things to you know, say oh, yeah, you're not doing anything.
You're you're cool. So they've really gotten good and they're they just keep getting good. So yeah that agility Gap.
We've got to learn to think like they do. Speaking of that agility Gap. Do you think that the business execs?
And I understand that we are engaged in something of an arms race here or do they think that you know, they're just going to throw money at security and expect you know and outcome without understanding that there's somebody on the other side of that that's constantly adjusting their Game Boy. Well again, I think there's you know, the those different types of exacts out there. I know some of the you know, the the ladder that yeah, you just throw money at it then and and any you should be able to solve the problem.
But that doesn't work you look at some of the companies that have spent a lot of money on on security and their names are coming up being breached, you know household names that we all know and yeah, that's not just a one-off it just continues to occur. But then I do know exacts that that they have very astute Information Security leaders that don't just understand security but the understand business and why that's so important is that you know businesses are complex, you know, every business there's so many complexities in a business that if as a security leader if you don't understand where in your business structured your most vulnerable and the biggest impact that could really hurt your business throwing money at security. Doesn't do anything if you can't connect it to what's going on in your business.
So do you think there's any correlations in the amount of money you spend on security versus your outcome, or is it simply you know, I could be you know, the biggest company in the world with the biggest budget, but then you know, I wind up being like the Yankees of the Red Sox. I don't win the championship because then matter how much I spend I got beat by a team with you know, aim, perhaps not the smallest budget but a reasonable buddy. Yeah, what's the movie Moneyball?
Yeah that they introduced statistics and and it wasn't it wasn't just averages, you know, averages, you know aren't very effective. If you based decisions on averages the outcome is always going to be bad but you know, they actually did statistical modeling they fed data in and you know, it's it's not the amount of dollars that you're spending. It's are the dollars that you're spending effective.
And if you have a modeling methodology that you can tell that you're gonna be ahead of the game just because you have a big security budget again, look at some of these companies that have been breached huge security budgets, but you know, it didn't didn't help them. All right. Folks you heard it here.
It's all about the proverbial fight in the dog and the size of the dog. Hey Bob. Thanks for being on the show.
My pleasure. All right back to you guys in the studio.