ID-Verification Solution for Help Desks with HubSpot’s Eric Richard
Eric Richard, CISO and senior vice president of engineering operations at HubSpot, explains why his organization is using a new approach to thwarting phishing attacks against help desks developed by Nametag.
Transcript
This is Techron tv. Hey guys, thanks for the throw. We're here with Eric Richards, the senior Vice President in CISO for HubSpot, and we're talking about how he's using an innovative approach to secure help desks from, uh, social engineering attacks.
And some of those include nasty things like deep fakes. And we're gonna dive into that in a second. Eric, welcome to show.
Thanks so much for having me. What exactly are you guys up to? 'cause a lot of times people don't think of the help desk or any other part of an application as the target for these attacks, per se.
They think it's gonna be something else that the bad guys are after, and yet the help desk may be the first point of entry to all our serious data. So walk us through what you guys are up to. Sure.
Uh, I think when you think about attackers out there, they're always looking for the easiest way to get into an environment. And we've seen things like phishing attacks, password spraying attacks, but as companies have gotten their, uh, security mechanisms more tight, the attackers have to go somewhere else. And what you've started to see over the last year is them getting into more novel attacks where they're doing social engineering attacks against your employees, um, including pretending to be help desk or social engineering attacks against your help desk pretending to be employees where they're trying to bypass things like your two FA mechanisms that you've put in place to try to secure your environment.
You guys have partnered with a vendor who has a new innovative technology. Walk us through why you selected them, who they are and how you found 'em. Sure.
Uh, so the, the vendor that we're working with is a company called Name tag. And the re we're working them in actually two different ways. One way is on our customer facing, uh, technology, and one is in our internal facing technology.
Both of them are relatively similar. Um, in both cases, uh, we have customers who have two of a set up with, with HubSpot, um, and we have employees who have two FA set up with HubSpot. Uh, in both of those cases, you'll get into situations where an employee might get locked out or a a a, a customer might get locked out, they lose their device, whatever.
Um, and so somehow they need to do a password reset. This is exactly where the opportunity is for a bad actor. Uh, bad actor can pretend to be.
That employee can call up either our support organization or IT organization, pretend to be that employee or that customer, and try to do a reset and use that to get their device registered in. What Nametag does is it provides a strong identification verification using a combination of government issued ID like a driver's license or a passport and a selfie together. The two of those together allow you to prove that this is the person that they say they are, and that there's not just like taking a picture of a driver's license and sending that to you and, and not proving that they are who they are.
This really allows a support organization or help this organization to be able to make, uh, good decisions when they're doing something sophisticated like a pa uh, a two FA reset. There's been a lot of, uh, hit or misses with multifactor authentication or we kind of trying to find a way to take, take the friction out of the process. 'cause it seems to me at least that people tend to resist because there is too much effort.
Sure. Um, I, I think that nametag can offer, uh, a frictionless way of doing MFA, but there are also, uh, other opportunities for friction MFA. So if you think about more, uh, some of the, uh, passwordless opportunities out there, um, those provide to, uh, to a FA three you in a very frictionless way, but you still have the same challenge of, of doing a reset there.
Uh, so name tan can certainly takes friction out of the reset process. So if you lose access to that second, uh, that factor, What's your best advice to your fellow CISOs then about how to go about doing this? 'cause um, not every asset is the same in terms of, uh, the threat vectors you might face and the level of security that gets applied to it, but it's hard to distinguish what's at risk and for how much.
Sure. Um, I think if you look over the last year of attacks that have been out there, uh, the bad actors, they're making very strong efforts to do account takeovers. And so my advice is really twofold.
The first one is run, do not walk to implementing, uh, Phish resistant MFA. Uh, so we're, we're learning that not all MFA is the same that some some MFA can get, uh, can help block bad actors and other MFA doesn't. And so move towards Phish resistant MFA, and as soon as you do that, the next angle of attack is gonna be against your help desk.
And so move to a solution like Nametag that provides you strong identification verification when you're doing something like a two FA reset or something where a bad actor could wedge in there if you weren't being careful. Are there use cases for things like biometrics or are we kind of moving along here where we can basically use something that's quite not as complex and costly to implement? Sure.
I mean, so just as an example, nametag does use biometrics because they're leveraging, if I had my phone right here, they're leveraging the biometric functionality in your phone here to be able to do some of the, I don't, I don't actually know what's in here, but the kind of the 3D recognition of your face, and then they're comparing that to the photo itself. So they are taking advantage of that. Um, I think in general, you're starting to get to the point that whether it's your touch ID on your, on your keyboard or your face ID on your phone, you're starting to get to the point that biometrics are becoming pretty consumer grade and as if we as security practitioners can make sure we're incorporating that in, that certainly is useful.
Is this affordable? I mean, uh, we see people are more sensitive to cost than ever when it comes to cybersecurity. And a lot of business execs are asking questions like, we've been investing in this for years, and are we any more secure?
But how do I make the financial case? Great, great question. The primary reason we implemented Nametag was actually to offset the existing support costs that we had either in our support organization or in our IT organization.
Your support organization is already fielding these requests, whether it's a password for, you know, password reset or a MFA reset, they're already feeling those and this actually decreases the cost of it. So I actually think one of the great pieces here is you can actually really look at this as a cost savings mechanism, not a cost expansion. And ultimately in my reducing the stress load for both the IT people and the security people as part of this conversation.
Absolutely. One of the things that was great when we rolled this out for our, our customers is they went from a process that would take 24 to 48 hours where they had to interact with somebody, go back and forth, send information back and forth to a system that was automated real time and got back to them within a matter of seconds. Right.
That's a delightful experience. And on the security side, I now know that the, I'm actually more secure than I was before. So it's a win-win, both from a security perspective and the end user perspective.
So how much is the fact that the bad guys have access to generative AI tools keeping you up at night? And is, is that gonna ultimately force this issue? I think you're starting to see the very early stages of, uh, affordable, uh, deepfake videos.
I think we've seen a case in the news relatively recently here. Uh, that definitely does worry me as a security practitioner of like, how are bad actors going to use that? If I hop on a Zoom with someone who looks like my boss and sounds like like my boss and acts like my boss and they're asking me to do something, I'm relatively likely to do that.
Um, again, I think using something like name tag to do strong identification verification in that moment where you're asked to do something of high blast radius, whether that's a financial transaction or whether that's, you know, changing a security control. I think making sure that you have policies in place for how you're gonna handle that and not just trust what you're seeing on the other side of that camera, I think is where we're gonna have to get to. All right, folks.
You heard in here the game is changing once again and we just gotta keep pace with everything that's going on out there because Well, the bad guys never sit still, so neither can we. Hey Eric, thanks for being on the show. Awesome.
Thank you so much. All right. Back to you guys in the studio.