Focusing on the Edge in 2023 – Theresa Lanowitz, AT&T Business
Theresa Lanowitz, head of cybersecurity evangelism for AT&T Business, goes through some of their 2023 predictions. She and Mike Rothman focus on edge computing use cases, and the impact on application security as all of this code increases the attack surface, regardless of where it’s deployed.
Transcript
This is Textron TV. Hi everybody. Welcome to another tech strong TV interview.
It is prediction season. I know it's hard to believe we're kind of wrapping up the year. It's prediction season.
So I expect we're gonna have a lot of our interviews focused on where people think they want to be going over the next year or so. I'm pleased to be joined by three solanoix who is the head of security or cyber security evangelism or AT&T business that is quite a mouthful, but I think I got it kind of right and we want to talk a little bit about what 18 team business thinks is gonna happen, you know from a security standpoint moving forward into 2023. So Teresa, welcome to Tech strong TV why you tell us a little bit about yourself and you kind of your role within 18 business everybody kind of understanding businesses, but what you kind of do on a daily based then we'll talk about some of the high level predictions that that you guys think will happen in, you know, kind of the next year to 18 months.
Well, I might think so much. It's great to be here. So just a little bit about what I do as head of cybersecurity evangelism.
So at AT&T, we want to help make it safer for your business to innovate. So whether you are building airplanes running a financial services company or selling flowers on Main Street, you want to have those better outcomes for your customer and that's really what we focus on it AT&T cyber security within AT&T business and my job is really this whole idea of cyber security evangelism. So going out creating Market awareness events doing interviews with great people like yourself as well as the component of thought leadership and one of the things I do from the thought leadership perspective is every year AT&T cyber security.
We release the annual AT&T cyber security insights report. So that's a an event that happens and for 2023. We will release it on January 24th, 2023 and what we're focused on this for 2023 is the Ecosystem.
So everything that goes into making that edge work looking at what the organizational structure looks like looking at how people are saying you know what this is kind of a little too big to have it be a do-it-yourself project. So who they're working with that sort of thing. So that's coming up end of January.
See so you're gonna keep us in suspense until until the middle of January for for your record. Well, we do right we've got our annual predict conference happening in January 12th. So we're gonna keep everybody at suspense in terms of where we think so but I think we're gonna allude to some some different things that that we expect that and you kind of mentioned want one of my first Topic's right because Edge is certainly something that is because becoming a lot more common in in our vernacular, but to be honest, I sometimes I have a hard time understanding what those real use cases are we know they're these big networks.
We know that folks are moving compute, you know much closer to the user but why I mean, you know, we just spend so much time trying to move everything to the cloud and centralize it as opposed to having it, you know kind of with it all different distributed centers and heart and now we're like, oh let's distributed again. So it's just the pendulum swinging back and forth or they're really new Innovative, you know, kind of edge types of use cases that are really gonna unlock value become. Or definitely Innovation that is definitely what the edge is going to bring us and it's interesting when you mentioned Edge, it means different things to different people and what organizations are really focused on now is outcomes.
They want to be able to show some outcome for what they're doing some sort of business outcome some sort of customer outcome. And when you think about Edge Edge means different things to different people and it usually tends to Trend to the tech staff that somebody is using whether it's a vendor talking about the tech stack that they're selling or somebody on the customer side really focused on the tech stack that they're using. So what we found out in our 2022 182 cyber security insights report research is exactly that and so when we write about Edge we say there are these three characteristics that you should really think of one is it's a distributed model of management intelligence and networks.
The second is you're putting that that those applications those workloads closer to That data is being generated and consumed because edges all about data as you mentioned and thirdly it's software defined and that can be on-prem or in the cloud. So we'll keep thinking about those characteristics. If you think about some of the use cases that edge really derives In our 2022 research the two biggest use cases that came out of it were in the retail sector for loss prevention and then in the manufacturing sector or real-time visual Quality Inspection on the assembly line, so think about what that means that means you're building something on that assembly line and with a variety of sensors and cameras you can see exactly what you're building when you're building it in your real time.
So if there's some sort of production defect that enters you can stop that assembly line and remediate that defect initially it immediately rather than waiting until it rolls off the assembly line and then having to say, oh, you know, we had this defect enter and then having to do a recall. So those new real time events are really really powerful. We also found Financial Services.
They're using it you're concierge services. And of course everybody probably has experienced this Telehealth, you know, the pandemic really accelerated that any idea of Telehealth is something that Health Care. Organizations what they told us in 2022 is you know what we're using this idea of edge for Telehealth.
So I think people are there there using Edge applications. They're using Edge use cases and in many cases not even thinking about it. It's more seamless interaction, right and and you know, so I hear a couple things there, right, you know one is obviously kind of making sure that you can be more efficient in terms of and and find issues and identify issues closer, you know to where it happens.
Those are all advantageous from a velocity standpoint. But the last one, you know started to pick my interest a little bit being a 30 plus year security professional right? And when you start to say Telehealth and and Phi and some of these other, you know types of environments, I mean, let's we're not very good at protecting things that we've centralized right now you start to distribute stuff all over the place and it doesn't seem to get better.
Right? That's you know, you're losing money and every unit You're not going to make it up in volume. So I kind of get the same approach or perspective on some of the edge security stuff, which is we're not good enough on doing things that we know where the stuff is.
Now you start to distribute it out to you know, the four corners of the universe and and how is that going to get better? So is there our improvements that you guys see? Is it something that needs to be baked into kind of the edge platform kind of the network in terms of how we access that so so where do you see kind of a lot of the protection aspects of edge Computing starting to shake out?
Yeah a couple of things and especially from the security perspective we've gone from those days of security is nefarious hacker and a hoodie City in the corner working in the shadows to security is now part of a business plan and that was really Spirit on by the pandemic the pandemic made security bill from a technical issue to a business issue. So it's a requirement of the business, but if you also think about what's Cutting with Edge we have this new ecosystem that's about to emerge and what we're seeing and we're seeing this especially through the research that we did for our 2023 report organizational silos are starting to erode, you know for so long. We had the application development Silo.
We had the network side. We had the security team and none of them talked and what we started to see with people bringing in 5G networks is the line of business was saying we need to do this because we need to be more competitive. However, we're not going to do this unless we are in lockstep with our security team.
So those organisms are those silos that have been erected over the past 40 50 plus years. They're now starting to erode and starting is the key word. And so, you know eroding those organizational silos, we'll have some effect on this but what we're all so seeing is that The mechanics of what we're doing is starting to change.
So for example from a development perspective. If you look at these Edge use cases that I just identified. So real-time visual Quality Inspection loss prevention Telehealth that sort of thing the application suddenly start to be a little bit different.
They're no longer gooey types of applications their headless types of applications and developers are now going to start to participate in this ecosystem and they're going to have to build security from the beginning and focus on these non-gui types of applications that they're going to put out there for the edge. So it's going to be a change for many people in terms of what the organization looks like how the organization performs and also in many cases what you're actually doing, you know, if you look at application security, it's it's one of those things. Everybody says, yeah application security.
It's great. We have to have application security. But if you look at the old lost top 10, you'll want to talk 10 has not really changed.
A 20 years that oh wasp has been around to two or three right two or two or three the attacks change every year. But yeah, yeah and so it in our current situation, you know, if you take care of cross-site scripting SQL injection, you can take care of a lot of things but now we're going to start to see different things, you know. Oh, what's last year?
They put out the owoss API top 10. So, you know, we have to really start to focus on what we're doing with apis as well and make sure that yeah, you know, one of the things that has been so so popular this year, especially for software developers is this whole concept of the software building materials or the s bomb. So those S bombs are going to continue to be extremely important and hopefully we're going to get away from this, you know, roll out a new API, but the security team doesn't know about it.
So eliminate that that leg well, yeah, let's just say I'm I'm a little skeptical of all that stuff but just because I'm old and jaded and I'd be doing it for a long time and we've been we've been hoping that You know kind of publication security right and we would build it in and all this other stuff and again part of what we're gonna be talking about. January is is that's bomb. We've got a whole panel on application security and and the evolution of you know, kind of s bomb really as a catalyst to force folks to revisit a lot of what the components of their applications on I think all this stuff is is very healthy, right but I think again we just we're on this constant pendulum right?
Where is he, you know for the last couple of years. We've been talking about shift left and the importance of you know, getting developers involved into the security process and building the tools into the items and you know kind of making everything run through a pipeline so that we can you know, build testing mechanisms within the integration and the deployment process and and all that kind of stuff and and again, you know now we're kind of thing in the backlash that right developers are like I got to write code folks right? I'm incentive to deliver code and now you want me to do all this.
Already stuff to what the hell are you doing every day? Right? So, you know one of our Concepts is, you know, do we have to actually start to shift right a little bit in terms of you know, bringing some of those motions back to you know, kind of more of a central or at least a centrally managed capability to you know, enforce some certain kind of hygienic policies around the code.
So it's gonna be interesting because you know, we've been finding this battle for a long time right? I've been talking about the importance of application security for a long time right is we look at where devops and Cloud native and now security has to Overlay, you know into that to enable digital transformation, which is really what extra long is about. You know, it's just again we see positive motion but you know kind of getting those actual activities to stick and be consistently done all the time especially during crunch time, right that's still you know to me seems pretty problem.
You guys see in a similar type of thing or are you more optimistic than I am Teresa. I have an optimist. So just in general, I'm an optimist and I've been reading about application security since 2001 when I was an analyst.
So I've been writing about it for a long time. As you mentioned, you know, you've been kind of talking about application security for a long time a couple of things. I think that we're going to see change, you know, you talked about shift shift left and that was the idea initially for software developers to say.
Oh we need to make sure that we're writing better quality software code and we can do things like unit testing earlier this after I cycle so we're not shipping these defects later putting these defects out there because it's the cost of rework becomes very very high. But I think what we're going to see with this idea of security being built into everything that a software developers doing so security by Design this comes down to some organizational shifts and so having that person on that software development team who can act as that 30 Ambassador because I'm with you I mean software developers have a very very difficult job and there's not a software developer in the world that's going to raise their hand and say yes, let me take on security because my job of developing software is oh so good. That's a very difficult task.
And we've seen this play out over the past couple of decades since 2001 or so when software Security application security really became a thing because people said, well, this is really the last mile of protecting what we're going to do. It's through our applications and software developers said, yes, but make it easier put it into our IDE. So we've done all of those things, but sometimes still it is an impediment to the developer.
But what organizations have not necessarily done completely is had that security Ambassador embedded if you will with the software developers and it is a change and it's going to have to come from the top down to say that all of our software has to be secure and then putting things in like yes, Bob really is a forcing function in many cases to make that happen but changing the complexion changing the makeup a little bit of what that software development team. Looks like having that person who is only focused on security rather than software developers creating their source code and having somebody from a quote unquote security team outside of their organization at this that governance checkpoint. We know that doesn't work.
So we'll start to see those changes. And also I think one of the things we'll start to see Is that well have these born on the edge types of companies and by definition they will disrupt the incumbents what in whatever industry that is so if you have a company born on the web and we born on the web born on the cloud born on the internet, we've seen this in the past. So having these born on the edge types of companies where they have application security and data security data security is a really important component of that as well.
So having that data security and that application security built in from the beginning that will suddenly start to disrupt the incumbents and the incumbents will say in order to remain competitive we have to do this. So I think there are really positive things ahead in the application security world and by association in the data security world because edges all about that data. You bet and and and I I really hope you're right Teresa because we need it as as an industry but being a security person right, you know kind of my fabric.
I I know all too. Well that hope is not a strategy. So we have a lot of you have a lot of evangelizing to do right?
We have a lot of you know interviews and content and Trends and and other you know mechanisms to continue to train the industry as to why a lot of these things are important. I know you have a bunch of other things like threat in town and and other you know, kind of aspects that are part of your predictions. So how to folks find the Rapport right how to folks find the AT&T business predictions that that you and your team have put out there.
So my predictions will be published on our AT&T cyber security blog. com/blog you'll be able to see it. That that's fantastic.
So Teresa. Thanks so much for your time. It always a great conversation love application security very curious about the eggs.
So glad in the middle of January. You folks will be be really talking about the edge ecosystem and and starting to you know, really get get a sense of what that is part. What what's possible relative to the edge and what some of the constraints and impediments are going to be so I'm looking forward to seeing that maybe we'll have you back on the the tech strong TV for another interview.
We can dig into that a little bit deeper. I think that would be great. So thank you for your time.
Thank you very much. Mike the Great to visit with you. And now let's head back to the studio for our next interview.