Geopolitical Impact on Cybersecurity with Performanta’s Guy Golan
Guy Golan, executive chairman and CEO for Performanta, explains the role geopolitics is playing, as Africa emerges as a test ground for novel cyberattacks.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Guy Golan, who's CEO for, for Fermento, and we're talking about, well, Africa and cybersecurity.
'cause I think everybody's tends to focus on, well, US AsiaPac Pacific, Europe, but it turns out that Africa is now a testing ground for the next big wave of attacks. So guy's gonna explain what's going on. Guy, welcome to the show.
Well thanks for having me, Michael. Great to be on the show. So it seems like we're using Africa kinda as a sandbox for testing new types of cyber attacks.
What's going on? Explain. Yeah, the Africa is quite an interesting point.
Uh, ferta has been in Africa for over a decade. We actually were founded in Africa dealing with local companies and branched out to Europe and to the United States. And we started seeing some abnormal type of attacks that are attributed to Africa, but not yet arriving in the Western hemisphere, if I'm gonna call it that, that way, which we didn't know if it's a coincidence or not.
And I've asked my research team to start analyzing and see if there's any recurring pattern. Um, we, we analyzed it and we saw that there is, and the, as the, as assumption was initially was these bricks, you know, with, there's Brazil, Russia, India, China, South Africa. Uh, we know that China is using a lot of, um, what I call it, commercial or financial ransom, uh, those countries.
Um, so what would be their motive in trying and achieving attacks that are pretty much predominant in Africa as opposed to directly in the Western hemisphere? What we also know is that the Chinese way of attacking is pretty much a gut, a a shotgun approach. They go and they spray their attacks, scan anything, they can collect as much data and information as possible.
It's also well entrenched in the CCP manifest that any company that is dealing with China that is being breached has to must report back to China with the full, um, forensics of what just happened there. So any of that is predominantly, um, led us to the assumption that it is not just a once off. There is a recurring pattern here and our team, uh, that has great access into threat intelligence in Africa, which is lacking with the, the American or the European providers because they see Africa as a small, in small, uh, continent and they don't get to level of granularity of industry and countries.
Our team start analyzing that and then so that basically there is a a amongst many other activities which happen directly in Western Europe directly against industries of this sort or another nature governments and so on. Another tool is to test and stress test their methods in Africa as well. We've seen it from four years ago.
That's when we started monitoring it. It now we've got the proof of that. So let's say I am running security in the US or Europe or wherever it should be.
Should I be paying more attention to what's going on in Africa as kind of an early warning system? I would, I would urge that. Um, and the reason is for two reasons.
Uh, we, we started seeing that the, the attacks happening in ha in Africa are against, uh, as a bridge are against companies that are American companies with footprint in Africa. And nobody's looking through that door at all through that window in whatsoever way. So the assumption again, which we got the proof for is that if we, if the the eastern block is attacking Africa, test the casing, their situation in Africa, they will have a relatively easy access to American and European companies as opposed to directly engaged because of third party relationship 'cause of trust relationship that is happening between local companies in Africa, namely South Africa, Nigeria, Kenya and so on.
And the American or the European presence that is in place, that means that not only are they using it as a test case, they're also using it as a bridge. So American companies that have vested interest into Africa, I would predominantly tell them just strengthen your ability to understand what's happening in your affiliated branches in Africa and understand what's happening from an attack nature and compare notes. Besides that, I would just say go and look at what's happening in Africa and try and understand the nature of the attacks that's happening there.
It also seems like there's a lot more economic growth in Africa than people realize in that kind of activity. Always attracts the attention than the backends. Oh, guaranteed.
Uh, I would, I would take your statement, Michael and take it one step ahead. Um, the, when I started by mentioning that China is holding African nations or African countries to some kind of a financial ransomware or ransom, it is because that level of investment that is in place, um, whether it is the, the Chinese method is to look at things in five layers underground, on ground above ground air and out outer space. And they control the, they in their mentality, you have to have a square meter of all five to be controlled of.
So where they get into Africa and they just invest in a road, they're actually not investors in a road they invest in the mine that is underneath that they invest in the air, which means cell phone connectivity. They invest in um, flights and rides, they invest in satellite communications, everything that is allowing them to collect as much information as possibly can. Um, and that they do it with a very good notion that this is a modus of opera operandi to achieve their goal.
That brought to Africa a great level of growth, but on the other side it gave the eastern block a great level of threat intelligence that is second to none today. Do you think, uh, the businesses in Africa are able to defend themselves? Do they have the cybersecurity expertise required or will they need some assistance?
It depends pretty much about whether you are above the poverty line or not. If you are a large enterprise, you are behaving like a first world country. You've got the means, you've got the funds, you've got the people and you can defend yourself.
The large banks, the large telecoms, the large retailers are doing a fairly good job in defending themselves. The small and mainly medium enterprise are the ones that lack and they will suffer, um, severe consequences. Um, the interesting thing about the, the difference between an African approach and an American approach is an example which I'm quite privy to discussing with quite a few CISOs in the US and same goes in Africa because the means are quite lacking.
There's a great level of I will make a plan and I'll try and work without the resources that I've got. The American method is a lot of, I'll throw money and people at the problem, the uh, African way is I will make sure it is bolted well and bolted for a long time. So we see more innovation happening, we see more level of growth because of that.
I always give that example Michael and say when, when, when we go to the UK and they said, how do you do that? And I said, you know how difficult it is to beat the world record freestyle swimming in a pond because we are, we are having basically there's, you know, murky waters there, there, there's rocks underneath you, there are no swim lanes, there's no agreed temperature. The ref doesn't squeeze any trigger and you have to swim.
And then you get to Europe and you get to the US and there are swim lanes, optimal temperature, there are rules. So it make us be more innovative and uh, doing that. And we are not the only ones in doing it.
I would the American method, um, as an example when there is a cyber attack and I say to them, how do you recover? And they say, well we follow NIST recommendations. And they, I said, what, what exactly is that?
And they said, if after five days we cannot recover, we basically rebuild the entire network building the entire network. And I'm not talking about small companies, I'm talking about big banks that the CSO confirm that to me. I'm not gonna mention names obviously, but we get to the point that you say if you rebuild your network first it's a lot of money.
Secondly, it's more time, but more importantly, aren't you aware that the back doors that exist in, in your existing network will exist when you rebuild it. So why aren't you taking it back properly and invest a little bit more time and thought about it? That's what the Africans are doing because they don't have the funds to do it Well, necessity is the mother of invention as they say.
So they got away. Absolutely. Um, We hear a lot about AI these days.
What's your sense of how that might play out both for the defenders and the attackers? That is not the million dollar question and not the the billion dollar question. That's probably the trillion dollar question, um, from what we gathered because we are, um, we were on the early adoption of co-pilot for security since September.
It became available on the 1st of April. We are one of five companies around the world and we played around with security, uh, well co-pilot for security. And we looked at it with initially a lot of criticism, ands and, and and pot, potentially some sarcasm, not understanding what it can do and try to understand what the, the, the use cases are to truly use it for a benefit.
That's on the defense side. Um, Microsoft made a declaration that it's to enrich the, the analyst's life. Um, our innovative team basically took it 10 steps away, uh, ahead and changed it to a way that, um, what is called today meantime to respond, which is according to the CTO of Cs A is about six, seven days and it's confirmed around the world.
We brought it to below than six minutes. Now at the average attack is about two to three minutes. So if you use Inno innovation properly with copilot, you're gonna get the defense.
Funny enough is if I were to show you a live demo, we have to stop the demo because it runs too fast. We can't talk and explain to you what just happened there. And, and the na the nature of attacks that will be far bigger, far stronger in your face in magnitudes that we've never seen before, has to be dealt with something of the same magnitude.
AI is the assisting one to it. Now on the offensive side, guaranteed that's what's gonna happen. You'll have more AI usage because you can get a lot more, let's understand.
It's, it's a business whether it is run for political reasons or for uh, commercial reasons, it's a business. And the idea is to get as much as possible in, in a finite amount of time. Um, I would always, as I I always say that the attackers, they've got way more r and d than the average Joe.
So they invest the money in understanding what they can do more and I don't see them stopping there. Um, as, as a side note, the moment that governments will start behaving ethically is the moment that a lot of that is gonna be receding. Right now, the ethical, most of the ethical people that behave are private companies and governments are the non-ethical when it comes to cyber.
So to your point, has this game moved beyond our ability as humans to manage it? Because everything is happening in, um, microseconds versus our and days like we may look back at the last few years with some sort of sense of quaint nostalgia. The answer is we cannot, we cannot respond to it.
As humans, we can manage it. Mm-hmm. We can make AI our biggest ally as opposed to leave it in the dark, not understanding and fearing it.
And we should do it and manage it. That the last, say the last word is a human word. And for the record, AI cannot get better if a human cannot feed back to it.
That's the nature it learns from humans. That's machine learning. So they have to learn from an input provided by a human being.
If we just leave it to AI to do it, we're gonna get a mishmash of complete garbage. Unfortunately, because a lot of the services provided nowadays are garbage in, garbage out type of services. So I do see for as long as we manage it and we are in control.
And the last word is our word, AI would become a great ally to us. What is your sense of the level of cooperation across the various governments around the world that have a vested interest in all of this? 'cause sometimes I feel like, to be honest, every government kind of gives as good as it gets.
But do they need to collaborate better on the defensive side? I mean what I feel like it's still somewhat disjointed. Okay, so there are, there are two points into your question.
One is, um, probably the hypocrite, the hypocritical part of thi of things, which is I need to defend, but at the same time I'm attacking, which if I am to attack, I will go to jail. Uh, so that's one thing and I understand the necessity behind that. The other part is collaboration.
The collaboration is happening amongst western world countries. It is also happening amongst eastern world blocks. And they are collaborating unfortunately one against the other.
The moment that the eastern and the west would start collaborating between themselves and say, what am I, what I'm allowed to do and what I'm not allowed to do, where am allowed to behave, where I need to stop behaving? Because it's almost like hitting the red button on a nuclear, you know, missile. But then you would start seeing drop quite a lot of drop in where we are today in that thing called cyber crime and cyber attacks.
So collaboration is a must, I would urge a collaboration between blocks as opposed to just, you know, as the Scotland Yard Interpol, um, NSA or FBI are collaborating. It happened before, it's still happening. There's not much benefit into that in my view.
There's a benefit on the defense side. I think there's a great, great benefit in a sound form of a Cold War agreement of what we are agreeing to do and what we are not agreeing to do anymore. Aren't we on the cusp of some sort of mutually assured destruction here because um, the people who are doing the attacking regardless of block have as much to lose as the folks who are doing the defending.
So at the end of the day, do we not just kinda harm each other's economies to the point where it's kind of a pointless exercise and maybe more rational minds need to prevent? Yeah, so I will, I will answer that question. Um, I'm not a poker player but I've watched one or two games.
Uh, um, you've got your chips on your side, somebody else has got the chips. Now if you're willing to go all in, you need to make sure that at least you've got more chips than the other one. No matter if they wipe you out, you're still alive.
And I think this is where the game is right now. Who's got got more chips? Um, as opposed to truly understand what the benefits are, people understanding what the loss may, may be and how I can cut my loss, my losses.
If you look at, at the grid, the national grid of the United States, the national grid of the of, of, uh, Chi China and of Russia, every country, whether they would admit to it or not, is controlling the other, the other country's grid. It's almost like three friends squeezing each other's whatever, not. And, and if you lose your grip, it doesn't mean the others will would do that.
But if you squeeze other, it means the others would squeeze harder. But, and so there's some kind of a balance, but what would happen if a fourth friend of yours that hasn't squeezed or been squeezed is squeezing now everybody that will, that will ruin the whole, the whole equilibrium that is in place. My view is that as if we are moving forward, that level of equilibrium has to be maintained not from a balance of terror, but a balance of respect that is in place right now.
It's a balance of terror and they are controlling now about the chips that I mentioned, if the US is without the grid for two weeks, it's gonna be colossal. If Russia or China is without maybe Russia more for without the grid for two weeks, they will prevail. They've got no problems.
They've been like that for years. They don't have an issue. Go to South Africa, we have low shading in Johannesburg or all over South Africa, six, eight hours a day without electricity.
Well, are you kidding me? We've been like that for years. We know how to, to survive without electricity.
The US without that electricity on a repetitive basis is a crippled economy. Alright, so to the average IT or security executive that's playing this great game, what's your best advice? Look, don't fall into what I call the snake oil in the industry because we invest more money than ever before and we are failing more than ever before.
Understand where your problems are, take the time, understand the risks, and then get either a team internally or externally that will understand how to reduce this risk of yours, speak a business risk language, not a language, which is it language or cyber language, because the majority of the decision makers don't understand that justifiably. So that would be the first case. The next point get true visibility so you can assess how good or bad my situation is and have a proper debate between business owners and technical people represented by the CIO and the CISO to truly understand what's the best way forward.
Not falling into the trap that buying another technology will solve my problems, which we see it over and over again. That's why the market is sick. We spend more money than ever before and we lose more money than ever before.
All right folks, while you heard it here, it's not about how much you spend, it's about how well you play the game. Hey guy, thanks for being on the show. Thank you so much, Michael.
Appreciate it. All right, and back to you guys in the studio.