Insights on SOAR – Leonid Belkind, Torq
Leonid Belkind, CTO of Torq, joins Mike Rothman to discuss the state of SOAR, why automation is critical to scaling security operations, and how gathering telemetry and analyzing it provides data to substantiate the value of security automation. He also highlights Torq’s new Insights product and addresses some of the organizational headwinds preventing widespread SOAR adoption.
Transcript
This is Textron TV. Hi everybody, Mike Rothman here with another tech strong TV interview. I am pleased to be joined by Leonid Belkin.
He is CTO. Is that right? Lean at CT?
Yes, sir of torque twerk's a pretty exciting company in these security automation space. So we're gonna talk about all sorts of things around security automation. This is a you know topic that's near and dear to my heart.
I've you know, kind of been calling for folks to figure out a way to leverage their people better and it would seem the machines are a good option for that. So we'll dig in all that we'll dig into a new offering that that work is introduced to give you some perspective on what you should and shouldn't be automated but I shouldn't stealing it's under leaning. Welcome to text on TV.
How are you doing today doing great. Thank you so much for inviting me like, yeah, you bet. So what you just explain a little bit about your background, you know kind of where you're at me, you know, the the pretty bad scene in in the back of your office.
Absolutely, you know, I'm definitely not going to take the credit for the office design that's been done by someone else my role in the company is indeed a chief technology officer prior to co-founding this company. I was actually a co-founder and spaghetta CTO of another security innovator eliminate security. We were Among The Front Runners in zero trust network access approach driven this company from inception all the way to its adoption by Fortune 500 companies and acquisition eventually by cinematic Corporation prior to that spends many many years with World leading Enterprise security Veterans.
For example, Jeff Woods offer Technologies Etc. So, that's me thork. As you mentioned dork is a security automation company and we are trying to finally bring security automation as a Mainstay to organizations by the first enabling Everyone not just your security developers team.
Not just Professional Services people you bring in to develop some automation for you. But literally every security subject matter experts that is familiar with the process process consists of Step a step B, step C. Once you know, that's with our platform.
You'll be able to express it in an automated workflow. Make security issues resolved faster collaborate with your colleagues alongside actually, true your day from being defensive into being proactive right creating something working proactively to improve the security posture rather than chasing your tail and trying to clean your table from the incoming events because that's not secretary for a lot of people that have been chasing their tail for the better part of the last couple of decades that certainly definitely feel the pain and we we come from this background ourselves. It's a it is very real.
Hundred percent. So again, you know automation is is definitely something that that I've taken an interest in. I'm what some of the you know kind of use cases or you know kind of activities that folks get started with, you know, using torque, you know, I think traditionally when you tell somebody in the Enterprise security organization about automation think somehow starts to thinking about fishing emails analytics, right one of your employees Flags, one of the incoming emails as a potential fishing attempt and then you analyze the Investments you analyze the links you don't always the content you do some other searches you respond to them Etc right how historically this has become the first Blockbuster I should say for automating.
For us quite frankly. The reality is that there are so many. Maybe even Lord ending fruits with much quicker or why consider automating things such as users suspicious Behavior.
Have you might recently reset your passwords or acquired a new mobile device for your second Factor authentication. How about just you know, you see your regular access to a lot of sensitive resources and providing you if you look at meaning tools for just in time access or how about for example helping you with processing results of a vulnerabilities camp for your own environment for your own practices environment, right? You have received a bunch of vulnerabilities for each and every one of them.
You need to understand it was the overall the asset. What is the exposure maybe introduce its Journal Tax Service scan, maybe full up with the asset owner, etc. Etc.
If you're a larger organization, you would have chance of these processes. So lots of security processes that are not just incident response. And be very very about valuable in automation.
But also traditional is an response across all of its stages every time. Yep. So how do you get started?
Sorry, you gotta pick a use case and are there templates that you guys bring to the table is the Professional Services driven thing where somebody's got to get you, you know on board and then hold your hand through the process of building a few couple of them because I get big impediment is always been the wow. I would automate things If I Only Had the Time, right, you know, but you're spending too much time doing the crap that you should be automating. So it becomes one of these, you know chicken and egg type things.
So so, how do you on board? How do you get value quickly? So first of all, I think you hit the problem right on the hat indeed the challenge with security automation.
So far has been the ramp up time and the sort of like challenging return on investment drives. Wait a second. Do I have time?
So we start indeed by first and foremost by a library of blueprints. Now These Blueprints say are taxonomized according to the pillars in your cyber security program, you know security identity security data loss prevention application security, etc. Etc, etc.
The platform itself. And that's one of our biggest. Let's say one of the biggest things we keep on investing in is such that any security partitioner on a level from Junior analysts all the way to Seasons analysts Architects and engineer and actually leverage the platform to express whatever they need automated.
Obsessed right? We are in many ways shapes or forms anti-professional services company now, definitely we're not against having someone join and build things for you. If you really do not have the capacity but it's not because the tool is complex, right?
We suddenly turn it from something that you absolutely cannot use yourself the need Professional Services, you know something that you definitely can use and if you'd like, we have a lot of partners that can come on board and complement your team giving you a much faster much faster. The loss of Team having said, that's just to just to get us to some sort of married to comparative. We've seen not huge teams teams of three four five experienced security and years build up to 50 automated processes in the first month of product adoption, right?
That is a lot and what we keep seeing and we are very adamant on investigating. The product usage is that this base actually doesn't Doesn't go down as the product used goes longer but actually goes up. One of our proudest moments is getting the feedback that the value of the product grows with the time it stays in your organization.
That is an old lasting effect. That that again that that would be great. Right because we all know that you need to automate more rather than less and if you can make it easy and accessible to a lot of the you know, folks internal to the organization that's certainly helps from that statement what I want to hit into another impediment that I know but I want to make sure that we talk about inside right because you know you so you've automated 50 things.
You've automated 70 things, right? How do you know whether you're automating the right stuff? How do you know if it's actually triggering, you know where things are getting held up.
I take it that that's what you know kind of your new in such product is really focused around. First of all, absolutely. Yes, and even more many of our users.
Have a challenge by the way it very relevant one on how do they quantify their investments in building automation making tangible to their managers? Okay next quarter. What would you like me to be doing and what will be the outcomes that I deliver with the Investments and this is exactly where insights comes in with a very very important fundamental idea.
It has to be for it to work. It's very easy for you to drive that information without bringing overheads on the people that are actually going and automating things. Right.
If you have to increase the work they need to be doing by animal 10% in order to be able to drive the insights. My country is that most of the people won't do it and any will remain in the dark. So first very important property of this Insight is that every time you create an automated process in the backgroundated, we create a let's call.
It better data representation of a process. We'll look at the steps you're taking and we architecturizing is it what is it like a threat intelligence enrichment or is it an application security finding follow-up or maybe it's a service improvement checkbox. That's also an option.
Naturally. We suggest these categories to the person as the workflows being delivered the personal can of course override and say yeah, I know it looks like X, but actually it's why just perfectly fine. Second Point.
Yes, you know. The person that is building an automated process is probably the same person that used to run this process manually day after day after day so they would be the most experts to say how much time does this automation save them. Is it like one minutes perfectly fine, if you're running 10,000 times a day, that's a lot of minutes right there, right or is it more and the sort of like the small Delta of writing down information along the way that will cost much wanted allows us to do is later on to look at the Telemetry right of what the system is operating Etc, but on a meta data level and we will be able to tell you that's your investment for example in they get a loss prevention saved you as many working days this many working hours Etc.
And by the way, he has commonly healed on investing this many minutes in building these workflows naturally again a parameter. We already have in the system. Right and we will be able to show this data historically so I would be able to tell you that.
Key in the first quarter of this year you invested in automating endpoint threat detection events and afterwards we handle this May events saving you that many hours. Versus the Investments of this many our students and then make it to troubleshooting Etc having this come fully automated try to solve an analysis that you need to make. It's not a bi tool that requires you a lot of manipulations of the data.
It's pretty much As autopilot as it can be that I think is the key here that's process the threshold between you know, just the dashboards every process every every product has a dashboard into something that people actually derive this aha moment from right? That's why we call it insights or not dashboard Telemetry or any of the superlatives of good reviews here. So so folks get these insights, you know, guess what it packaged up is a report that then they can go talk to, you know, the operational folks that they're helping out is it, you know used to, you know, make a case for more automation internally all of the above.
Um, so I think the three main users is a present. The return on investments could be to your colleagues could be to your managers sponsors of the project Etc. It also can show you where your next investment should go.
Thanks to the fact that again there is a very clear taxonomy based on Nest Frameworks. For example on what pillars does your cyber security program have and by showing you which of them you have already introduced automation also show you which others are still left subjects to manual processes so that can definitely be driven for that. And of course, I think that's The real-time parts of it sure.
I mean the report could be exported as any any documents, but the beauty of it is that it is constantly life, right and you could see not only a single position in time. But what are we doing today since the morning but actually how they've been doing this month as opposed to last month, right? What are we doing this water as opposed to previous work at the end of the day if organization in any area right security or reliability adopts automation.
It is always a journey right? It's not a switch you flip and even for my new law made it and this journey. Needs to have some sort of a monitoring how fast are you going?
Are you in the right direction that I think is the biggest value that insights can introduce. Interesting. Well, that's cool.
That's cool. So so good adoption so far and you just introduced it, but, you know kind of a lot of the existing customers interested so far. Actually thanks to the facts that that's the overheads to start using it is so small.
We see a very very strong pace of adoption. I'm not existing customers furthermore. It's surprisingly enough or maybe not surprisingly enough.
It also serves as an accelerator to adults maybe thanks to the fact that it makes investments in automation more tangible you more confidence to adopt to share it with more teams. Once you know that you have this sort of like Shining lights and he definitely oversee what goes on right to you you're less afraid of of this thing going wild and see you not getting the right address. Yeah and speaking of that.
Right? So so one of the last topics I want to head on is is kind of my own personal experience with Automation and that's really just who is empowered to make a number of these changes. Right?
I mean historically security when it was a command and control environment. They were in charge of the firewalls. They could block.
Yeah, right, you know, they were in charge of quarantining this they could get in the way of that now with cloud and with devops and a lot of these distributed teams. It's not as obvious, right the Ops folks the security folks certainly have to say they can you know provide an opinion they can certainly you know, where things are problematic but can they make changes right? Can they start to impact, you know operating production systems, which is obviously a critical requirement in order to you know, really?
Accept and adopt any kind of automation technology. So this is actually both a challenge and an opportunity and this duality of security teams being now more responsible for detection, but not necessarily having the same ability as they used to think. Let's just close the firewall ports.
These days are long gone. This is actually what the death sick ops philosophy is talking about how do we involve additional role players in the organization? Let's say infrastructure devops, like reliability people your example Google all the way deeper into application Engineers, right the people who the business logic how do we involve them in security processes with the very important game at the end of the day security processes for them to scale for them to be maintain strong security posture.
They have to be streamlined the Paradigm where he would be a security guy. He would be an expert and then you would what's open a ticket for me to fix it, right? This is a normal working paradigm.
Your mission to keep those organizations secure is unachievable by you because you have no tools to actually deliver it and students. This is a pitfall but then again you brought up the challenge would I really trust you to provide food access to starting changes in my production environment? Not really because that I would be harming my mission which is keep the business the general infrastructure is what we so what would we do?
You see the technological Works has already sold this problem why providing interfaces if I provide you an interface and we agree with you as a security Warner in infra what would be the operations that you would be doing? I will be actually implementing them providing you. Automations building blocks that you can now trigger in order to perform the relevance containments remediation, etc.
Etc. This is actually where an organization would make a huge lead in the efficiency of its security because now we are working together. I'm not bugging you because you actually have the relevant interfaces from me to deliver on your goals and you are not harming me because these interfaces they work within money tools within my permission set Etc best and most efficients Automation implementations in hybrid environments actually function like this.
And this is what deaf sync Ops right connecting these two in a continuous cycle. This is what it actually means. Okay good, you know, that's I I look forward to that day, right and and a lot of it gets back to you know, making the Ops people feel like it's their idea, right?
The time no kind of it's It's you know that yeah, this is a thing that I want to do right happens to be a security use case security problem, you know this type of Technology, but it's not just like the security hand or you know or is coming in and you know making changes to your you know, kind of operational environment so title the province is fail rights whole notion of modern clouds Digital Services is that they're so streamlines siled approach just kills older man. That's great. That's great.
But listen, I think this is a great stuff right? I mean, I think we need it from the standpoint of really improving the efficiency of how we do things. I mean scale complexity all this stuff has to be addressed be automation.
So exciting stuff coming from tour. I had a folks get in touch with you lean it if they want to, you know, learn more about the product or insights or just, you know, kind of have a chat. Oh, absolutely.
First of all, you can always approach or don't know website and use contact us personally or are you right to your correct you or are you You can find me directly leonids. io. That's great.
Well, it's laying it really appreciate you being on Tech strong TV today good stuff again huge fan of automation. So hopefully we'll you know continue to make progress on this front because as an industry, we all need it would love to share where we're getting with it later. Have a great look forward to the next discussion.
We'll have my friend. All right, and with that thank you and we will send it back to the studio for our next. Thank you.