IoT Security Challenges – Greg Murphy, Ordr
Ordr CEO Greg Murphy explains what makes IoT security so challenging.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Greg Murphy. Who's the CEO for order? And we're going to be talking about iot security.
And what are the challenges and what's going on in this whole Space Greg? Welcome the show. Thanks so much really pleasure to be here with you today.
we've been talking about iot security now for a while and we've been talking about iot, but maybe you can explain for a couple of seconds here. At least what is making this more difficult than any other security challenge. We may have encountered over the years.
Is there something unique about this particular space or is it simply just a matter of size and scope? You know, it's it's a matter of size and scope but there are some unique challenges when it comes to to iot devices. So we just think about the the sheer volume of these devices is growing kind of exponentially year over year where your traditional you know, it estate to be think about your laptops and your mobile phones and tablets.
Those are typically driven by growth in employees or number of people whereas the iot devices are really growing that's being driven by just the pace of innovation. The number of sensors cameras connected devices is expanding exponentially so that the attack surface from a security perspective is growing very very fast. The other thing that you know, I think is some what unique about you know iot devices is that they tend to have useful lives that are measured in you know, many years unlike a typical it device where you might think of a laptop or a mobile phone that's gonna be around for two or three years if you think about yeah Healthcare you may have You know MRI imaging systems that are designed for a 15-year life and similarly you'll find that in manufacturing as well.
And so you end up with a lot of Highly variable devices, you know with you know, many generations of technology and operating systems and that makes for a very challenging kind of Defense environment from a security perspective. A lot of these devices are also managed by people who are and then what we call the operations technology side of the house and they may not have as much security expertise is the traditional it folks do so is there a disconnect between the cultures who are managing these organizations and what needs to happen in terms of cyber security Hey, you do find sometimes that there are disconnects in culture and you know in goals if you look at folks on the the OT side of the house whether you're talking manufacturing or Health Care are these they are typically very very focused on reliability and performance and uptime the worst thing that can happen. If you're in the OT world and your responsible for keeping the pepperoni slicer running at a manufacturing facility, if that device goes down, you're losing your production capacity and that is money, you know in your your pocket money up the door, you know, whereas you think of the focus on the the it side of the house are typically more focused on things like security.
They are responsible for protecting the corporations data and the assets and so they have different priorities that they approach that conversation with and really part of that. The challenge here is providing a common set of Solutions Common Technologies and platforms that can serve the needs of both of those. Organizations that can help the OT organizations keep the devices operational and running while providing the it and the security organizations that the visibility and the control they need to ensure that the corporations data and their assets are protected adequately.
Is there some sort of centralized it team that's taken over responsibility for securing these devices or are we just trying to figure out a way to make the OT guys do it more efficiently? There there have been you know in some organizations we deal with there have been some shifts in in organizational structure where we see as more and more of these, you know iot and OT devices are being connected, you know and secured in cybersecurity becomes one of the critical considerations. We see operational responsibility sometimes shifting under the the CIO and the siso, but that's you know, we're in the the early days of that that's certainly not, you know the case in every organization work we're dealing with and I think there's going to be a mix of different approaches to this to this problem.
And I think the key here is making sure that all of these different groups are using common data common information that we don't have the OT organization with it's in I own set of inventory and asset records and the IT organization with theirs because then you're in a constant game of having to reconcile one database against another To get conflicting potentially conflicting information. The key is getting one common system in platform that can say okay here is that the inventory of the devices that we have? Here's the software that's running on those devices the vulnerabilities that might be associated with those devices and make that information visible to everybody that's shared fashion.
So that's that's one of the things that we really emphasize is how do you use a common platform as opposed to siloid tools which always creates conflict, you know in the huge Challenge and reconciling disparate information. We've been at iot now for a couple years at least in any meaningful kind of effort. But are we chasing after this from a security perspective yet again, or are we trying to get in front of this?
I think there is a lot of effort to to get in front of this and you've started to see that even in some you know, that the regulatory programs that are coming out of the US federal government and a standards bodies, you know, pushing, you know manufacturers to adopt a kind of standard. Yeah best practices and enabling. Yes security capabilities in the solutions that they bring to Market.
So there is an effort to make sure that you look across this the broad spectrum of Industries in effort to make sure that best practices are being followed. But this is always going to be a very complex area. We have multiple, you know, literally hundreds or thousands of Manufacturers that are supplying, you know, a hospital and Manufacturing organization and trying to make sure that common practices are being used across all of those manufacturers is always gonna be a challenge.
So I think there is a an effort. Yeah from a regulatory perspective to get ahead of this. It's also very incumbent.
On the manufacturers on the healthcare providers and others to implement visibility and monitoring tools. So they understand what's in their environment that they understand their risks and vulnerabilities so they can ensure that they're taking appropriate steps to protect themselves. We've been talking about The Chronic shortage of cybersecurity people for quite some time.
Now is this just going to get worse as we kind of go into this whole realm of iot security where there are thousands of endpoints? I think that it poses very unique challenges when you have the number of yeah endpoints that has increasing so dramatically which means the attack surface is getting larger and larger and I've never heard any. Yes, so say that it's easy and for them to attract, you know cybersecurity talent in their organizations to be able to you know, Implement plans to address these kind of challenges.
I think the the real way out of this frankly and the only way out of this is to enable automation. If you have you know, someone in the comes into to work in the morning needs to look at a console and has a list of 9,000 blinking red lights, you know vulnerabilities and and no ability to understand, you know, the priority the impact of those, you know, it's going to be impossible for them to get their job done the real key here is how do we automate routine tasks? And how do we help organizations understand the true risks and vulnerability.
So when they come in the morning they can look and say okay. Here are you know the top priority that the most significant vulnerabilities and by the way, these are ones that I can do something about because there is a patch that I can apply. There's a remediation a step that I can take as opposed to just sitting back and admiring that the Christmas tree that is lit up with all of the red lights.
Hmm the bad guys, are they tracking these deployments or they start in a launch unique attacks aim specifically at them or and what's the level of sophistication that's required for them to compromise and iot environment. You know, the the truth of the matter is if you look at the the attacks the simplest and easiest attacks for any adversary, you know is very often not to go after the iot devices themselves. It's yeah to get an employee of the organization to open an email to go someplace.
They can't the problem is that once these adversaries are inside that the network the way networks are designed. It's often very easy for them to Traverse. Yeah from you know, penetrating and employee laptop into and getting into critical infrastructure.
And that's really the problem is it's very easy for adversaries to move laterally across networks. And so the blast radius of an instant when it happens can be quite large and we are seeing this this week. We saw the Los Angeles Unified School District, you know, the adversaries are paying attention.
They know, you know that the day on which the school starts for the year. They know that the it organization is probably going to be stretched helping, you know, teachers students get connected. Doing all of the start of day of the year activities.
And so they know when organizations are most vulnerable. They're just looking for weak spots and looking to do the things that are most disruptive and very often if I can get to critical infrastructure if I can get to your Building Systems if I can impact the AC I can impact the ability to use, you know, online Medical Systems and critical medical devices. I can shut down a hospital.
I can shut down a school or manufacturing plant to prevent them from having normal day-to-day operations. And that's going to put them a very vulnerable position where they're very likely to pay me the rent so that I'm demanding. So yeah, I think you kind of think of the adversaries as chaos chunks.
All they want to do is get into the network and cause as much you know challenge as much operational difficulty as they can because they know that's gonna create a vulnerability for the organization that needs to be addressed. It seems like the malware is getting nastier as well because nation states are attacking critical infrastructure. And then that malware gets shared in the next thing, you know, it's on some as a service platform.
So this just become more routine where we should expect every I don't know nine months that they'll be another rev of malware. That's a little more lethal than the previous generation and it becomes kind of some version of Moore's law for cyber security. Yeah, I think it's it's a scary Prospect when you see nation states that are applying.
Yes significant resources into penetrating particular organizations. But the the thing that's even scarier for me is just the the commercialization, you know this and how how relatively and easy it is for even non-sophisticated actors to get their hands on malware to be able to use and exploit that you know in a fairly routine way. You have to think think of the people that are scaring me most the nation states are always out there but it's these, you know ransomware gangs others that operate yes, you know as rational businesses they're going up there and they're looking and trying to say which are the the most vulnerable organizations that have the least resources to apply to defending themselves where we can get in quickly cause chaos and force them to you know, pay your Ransom or to take some action that so it's that the profit motive that motivates a lot of these Bad actors, you know is scary because it means that there is no organization out there.
That's safe. You might think to yourself. Oh, I'm a mid-sized School District or a relatively small rural community hospital or mid-sized manufacturer who's who's gonna go after me and that the odds are it's probably not a nation state that's going to be targeting you but if there's a ransomware gang that can spend a few hundred dollars launching an attack and they have a probability that they can get you to pay a 2550,000 ransom.
That's a that's a pretty good business model. So I think we need to make sure that these organisms have all of those types of organizations are equipped to understand their vulnerabilities and can be proactive taking measures to defend themselves because as you put this problem is not going away. There will be continued Innovation at the adversaries and frankly like, you know any area, you know with Innovation it typically gets easier and easier for them to launch attacks on certain attack has been successful you tend to see it repe.
Over and over and over again just like and you know in our business we like to find products that we can sell and problems that we can solve for customers and do that over and over again the adverter adversaries take that exact same approach. Are there a center best practices or things that people should be doing to get ready for iot to get in front of it or there are things that you wish that people would do or for that matter things to just make you shake your head when you see people either doing them or not doing? You know, I think there's this really a focus on kind of the the fundamentals the basic hygiene here, you know first is making sure that you as an organization truly do have visibility to everything that's that's connected to your environment because by definition the most vulnerable device is the device that you as an IT practitioner is a system don't know is connected because you're probably not taking many steps to protect that device.
You're not if you don't know what's there you're probably not patching it. You're probably not following all the manufacturers recommendations. And so we find this.
Yeah all the time. There are devices in a hospital environment that maybe we're brought in by a manufacturer or rep or connected to the guest network of the hospital for a brief demo and get left in the environment that you know, you find that doctors have connected their their Tesla's to the to the Enterprise and the network environment those types of things. If you're not aware of them can be a significant.
Risk, so we put a real emphasis on on visibility know what's in your environment know what the the vulnerabilities are associated with those devices and then make sure that you're you're applying good cyber hygiene. You want to make sure that you don't have you know, a critical device, you know that critical manufacturing device or a medical device that's sitting on the guest Network that could be vulnerable to anybody who comes into the the environment. So making sure that you've got visibility, you know and making sure that you understand the vulnerabilities devices and that you're doing the basic measures to segment devices.
So you don't have a flat Network or becomes, you know, once malware gets into an environment it in Traverse, you know laterally across the entire Enterprise and in fact every aspect of operations, so more segmentation that you can apply the more you can control the blast radius of that occurs. Yeah, those fundamental building blocks in place. You're a lot better off here when you're facing the adversaries like we are today.
All right, lastly, we hear a lot about AI. Well AI come and save us from ourselves or is that just all wishful thinking? you know, there's you know, I think that there is a AI place and machine learning place where the good news when you think about you know, iot devices their behavior patterns tend to be fairly predictable and deterministic.
Yeah a video surveillance camera connected to your environment doesn't wake up on Wednesday morning and suddenly decide that it's going to communicate to a new destination or to use a new protocol. Yeah. Once you understand what these devices are you can use things like machine learning and AI to build behavioral models say, okay.
Now we know what a video surveillance camera when connected in this manufacturing environment what it typically does day after day after day that makes it possible to flag, you know, an anomalous Behavior. Hey, we've got a video surveillance camera. It's suddenly reaching out to communicate to a server in Russia that we have never seen a video surveillance camera, you know communicate with that's the type of thing where we're AI where machine learning can be very valuable to protecting, you know, anomalies and learning the organization that something different is Happening here, but you know, all of all of that said that's not going to be a substitute for having done the basic hygiene having you know, an organization having a strategy in place to make sure that you're seeing all these devices that your segmenting your networks and so forth.
So AI isn't going to be the Silver Bullet that solves but it can be a very useful tool or making sure focusing the organizations attention on the most critical vulnerabilities Metroid identifying vulnerabilities that are being exploited as soon as humanly possible. All right. Well guys it's one more case of Eternal vigilance all the way out to the edge and back Greg.
Thanks for being on the show. Really appreciate it. Thanks so much for putting a spotlight on this topic.
It's really important. All right and back to you guys in the studio.