Kirsty Paine on Quantum Computing and Today’s Cybersecurity Priorities
Kirsty Paine, field CTO for EMEA at Splunk, an arm of Cisco, assesses quantum computing and other arguably more pressing challenges cybersecurity teams face today.
Transcript
Hey guys. Thanks for the throw. We're here with Kirsty Paine, who's field CTO for EMEA for Splunk, and we're having a little chat about quantum computing and cybersecurity.
Kirsty, welcome to the show. Thank you. Thanks for having me, Mike.
Great to be here. I think everybody's a buzz about quantum computing 'cause Well, there were Nobel prizes awarded and it seems like it's more real and it's gonna happen. We just don't know exactly when the, uh, Q Day is gonna be, which is the day we think when somebody's gonna start breaking all of our encryption schemes.
But from your perspective, how real is quantum computing and what are the cybersecurity issues? Well, I mean, quantum computing exists today, right? They, they're smaller scale, but they do exist and they're not yet going to, um, cryptographically relevant, right?
That's the thing that we're waiting for that Q day that you mentioned. Um, and in truth, no one knows when that will be, which is a bit tough, you know, to deal with the uncertainty. Should we prepare today?
Can we leave it for 20 years? And in truth, nobody knows. The best estimates say it's about 15 years away, but whenever that quantum day arrives, that Q Day arrives, um, they have the power to break all of our encryption, essentially, all of our cryptographic methods that we use to keep things secret, for example, on the internet.
And that's what people are really quite worried about. Um, the idea that an adversary today could be storing things, harvesting them off and saving them so that they can decrypt them when that Q day arrives. So it's, it's a big deal.
Um, and I think it's important we prepare, but also don't panic. Mm-hmm. Well, for all we know, Uday may have already arrived, right?
Because we don't know exactly what other nation states are up to in this whole space either. Well, That is part of the paranoia, I think, is people think the first person or the first organization to create a constant computer won't necessarily be shouting about it, but usually acade, academia industry keep a close parity with whatever's happening. So we see it so far away that, I mean, I don't think one exists today.
And actually we are not sure one will ever exist. Right. We are not sure how, um, the interaction between qubits will change as things scale.
It doesn't scale linearly. And, and we don't know if Moore's law applies to quantum computers either. So we can't even predict the rate of advancement.
So it is all this big guessing game. Everyone's trying to make their best estimates. Um, but of course that uncertainty makes it fun, doesn't it?
This is true. But nevertheless, it does seem like the bad guys are collecting encrypted data on the assumption that they will be able to crack it someday. And there's this whole issue going on about how much they are hoarding that data for some future event.
I mean, are you actually seeing that occurring out there? To be honest with you, no. Um, because at the moment the security picture is so bleak that there's no need to attack an organization in that way.
It, it, you know, hackers are logging in. Once they log in, they have your encrypted data or they could, they have access to all your keys. They can decrypt what they want, they can, um, access what they want as well.
So at the moment, um, we're not seeing, I'm not seeing that threat. It's, um, a bit of a sad state of security really. But as an attacker, I'm thinking about my ROI I'm thinking about what's easiest.
And currently it's quite difficult. You have to be quite a sophisticated adversary to be storing lots of data, uh, saving it for years and years to think that hopefully some of it will be interesting and relevant. And you can create a quantum computer to then decree that data.
That's quite a niche attack vector. But that's not to say we shouldn't prepare for the eventuality. Yeah.
So what should we be concerned about then from a cybersecurity perspective? What's keeping you up at night, if anything? Oh, I mean, I actually sleep really well, which I think is the side of a good security professional.
But, um, I, I think the things that worry me still the basics, we still see issues with, you know, patching and all that stuff that it, it's so basic that we almost don't say it anymore. You know, implement MFA pervasive MFA everywhere attacks are logging in, not hacking in. It's, it would be helpful just to have the basics.
But the new kind of novel threats that worry me, um, are kind of around ai. I think we've seen proof of concepts developed on polymorphic AI enabled malware, which is terrifying, that can evade EDR. And that tells me that we can no longer, um, defend in the same way in five years time, we're gonna have to start adapting our methodologies here.
I I also worry about the talent, what will happen to the talent in cybersecurity because as AI takes on more and more of that burden, how do we train newer analysts and how do we reward more experienced analysts when that kind of drudge work is taken away? And you see two analysts with very different experiences and knowledge bases, but they look equally productive. I think that's quite a concern for me.
And then if we talk about the quantum horizon, that's 10 to 15 years, maybe. There's lots happening in the next 10 to 15 years. You know, Mike, we've got, we've got ai, we've got Y 2K 38, which people forget is coming, but that is coming.
That has a date. We have um, passwordless, you know, the shift of passwordless and biometrics. There's quite a lot going on in the space, even on the strategic level.
So I sleep well, but you know, if metaphorically those things keep me up. So what's your best advice to folks? 'cause uh, it's, it's easy to be overwhelmed by all these things and how do you prioritize what you're gonna focus on?
Because on the one hand, maybe we're involved in an AI arms race, on the other hand we don't have infinite budgets. Exactly. I mean, look at the constraints you have and also just be realistic about the threat picture, right?
I think it's very cool to think that someone is harvesting all your data 'cause they have a quantum computer and they want to attack you. And if that gets you budget and it gets you time with the key stakeholders, I don't blame you for talking about that, but to be realistic about it, what is your biggest threat? Where is your weakness?
Where can attackers go for you? And that would be where I would start. So if you don't have MFA, that would be the first thing.
I mean that's really, that has to be. Um, but also looking at how you detect and how you respond. So for a long time in security, we haven't said, you know, judge us if we get attacked, but judge us by how we respond, how we recover.
And I think that's really the picture of cyber resilience, making sure that you're able to continue the operations you have, um, even in the face of these attacks. But it's not to say it's easy, of course, that's the thing with prioritization, right? You have to make difficult choices.
But being really realistic about what is your threat model, what you should do first, that will really help to prioritize the right thing. What, um, are you seeing in terms of how cybersecurity folks are working with IT folks? Are they working more hand in glove a little more closely?
'cause it always felt like SecOps was off here on the side and the rest of it was just doing its thing. But I wonder, you know, to your point about cyber resiliency, are those teams coming together in a more cohesive way? Uh, we've always been best friends, haven't we?
I dunno what you're talking about. Yeah, I mean, I, I think that there is a lot of synergy and I don't use that word lightly 'cause I kind of hate it, but there is a lot of synergy between what IT and security teams are trying to achieve, right? We're trying to avoid incidents, we're trying to remediate quickly.
We're trying to make the business money at the end of the day. We're trying to keep things performant and secure. Um, and I do see a lot more kind of embedding secure by design principles, you know, starting from the start of the process, even on the people level.
So mixing these teams a bit more and making sure that you do have security kind of everywhere and making it more of a culture thing. So it's everyone's responsibility no longer that department, the security department, you know, the department of no, whatever people call them, it's all about mixing us up a bit more. Um, and that crosspollination is good for people too, because they get better skills, better perspective, and they can learn a lot more from each other than just working in these silos.
So I mean, we say the phrase, you know, an incident is an incident because in the end it's something broken. You don't really, you know, as a stakeholder, you don't mind if it's IT or security, it doesn't really bother you, which you just want it fixed. And, uh, it's not helpful to kind of throw things over the fence with no context and say that's your problem, you know, should be everyone pitching in together.
Do you think with the rise of AI and now especially AI agents, um, are these technologies gonna benefit the attackers more than the defenders? Or will the defenders finally get a Lego Ah, this is cat and mouse, isn't it? Um, we've said that for decades, but every technology, I, I always think, and I see this play out with cloud and with previous things, right?
But the attackers can adopt quicker because they don't have policy guidelines, ethics, right? They, they can go after the new shiny stuff, they usually get the edge first. And we've seen that with phishing, right?
Like volumes of phishing changing cra like crazy and making your defenders need to have a good phishing strategy and phishing defense if they didn't already. So the attackers always get the, the head start. But I think we as an industry, and I'm optimistic here, have a lot of power behind us, right?
We have a lot of talent, we have a lot of money, a lot of vendors there working to help with ai for defense and for security. And also we have a lot of creativity. Let's not forget that we're quite, um, a lot of ingenuity how we use ai.
I've already seen, um, some soc um, security operations sensors using AI LLMs to scrape ticket to have a look at ticket quality and target training for their analysts, right? To make, um, you know, do things in a qualitative way that they just couldn't do before. So this imagination and creativity I think will win out.
Um, attackers just go for the money, right? They just go for what's quick, what's cheap, and what works. And they're all about ROI and AI helps with that, but it, I don't think it can match what defenders will do in the future.
So it is a long answer to your question, but I think attackers get the head start and then defenders, we have the, the gains for the long term. All right. So it sounds like you're optimistic about all this.
I am. I I'm a natural optimist, but I also think, I mean, I, I see the, the talent and I, uh, talent really it's talent that we have in the industry. Incredibly smart people that have seen lots of new technologies come, lots of challenges over the years.
Um, we always rise to the challenge. You know, I think it's, um, you only have to look at major outages or bigger attacks that hit the headlines. And through all that, there's a team behind it.
There are groups of people combating it. And I, I really do have a faith in that, that whatever we do with ai, we still have a fantastic set of talent that we can draw from and bolster with AI productivity and efficiency. Um, to your point about the staffs and the people and the analysts, there's just an inordinate amount of, uh, tedious work that they need to do every day.
And, um, will that just start to go away over time and maybe they might enjoy their jobs and we'll see less turnover and burnout? What do you say? I mean, I hope so.
Don't you hope? I think that would be, that'd be great. Um, I think you have to be willing to adopt the technology, right?
To start with a lot of people despite just saying, oh, it's very boring and I hate doing this. It's quite comforting to do something, you know, you know, and it's comfortable. You're not pushed outta your comfort zone and you know, you can do what you can do.
And if technology comes and takes that away, you're gonna have to grow. You're gonna have to change and adapt what you're doing. So it will push our analysts to do these more strategic tasks to hopefully get more joy out of what they're doing.
And when you think about why you hire an analyst, you almost never hire them just to click the same few buttons in the same few order, that same order several times a day, right? You normally have required recruited them because they are intelligent, inquisitive, curious. They, they are very good analytical brains.
And so just think about that origin, why you recruited them and try and put them on those kind of tasks that I, I hope automation already is actually taking away a lot of these boring tasks from people. AI will continue generating instant reports and the stuff no analyst loves after an investigation to write an instant report. It's so boring, isn't it?
It's such a waste of talent and, and yet I can't automate it 'cause it's niche and specific enough, but I have to do it unless I use ai and it's great to free up the time. Also, the head space of our analysts, it's not just about time and productivity and efficiency. It's again, unburdening them and letting their brains work in the way that we've hired them to.
So I'm again, optimistic maybe, but that, that's what I, that's generally what I think. Do you think also this whole conversation about the fact that we have so many open job positions in cybersecurity might finally go away because, well, we're relying more on AI to do these tasks and so maybe we can get some, uh, balance back in the system, as they say, Get a bit of a boost, uh, in terms of AI filling the skills gap? Yeah, I, I think so.
Uh, we have had for the longest time that we have this, um, you know, gap and we don't have enough people to do the things we are doing. And at the moment, that just means things fall by the side. I think what will happen is that AI will pick up that extra workload, right?
And we already see this, that more tickets are being worked than have been worked before when you're using AI because you can just get through the volume so much quicker. Um, I think we will still have cybersecurity jobs. We'll still probably have a small deficit and perhaps what we will recruit for will change as well.
Uh, I think we'll probably be able to leverage AI to take on those boring tasks more of the level one work. So we won't have as many job vacancies at that level, but, um, we may have to create a sort of level four, you know, in the SOC so we can elevate those analysts that are leveraging and create new tasks that we, we don't currently think of. If we have AI in the SOC who managing that, those agents who is working on the strategy, and that could be a sort of level four analyst role.
So we may just have to reorganize a bit and I think we'll still have some vacancies, but they will be different vacancies looking for different skills as well. Mm-hmm. So at the end of the day, um, when you think about the current state of cybersecurity, what kind of makes you shake your head a little bit and go, folks, I wish we could just be a little bit smarter about this one thing.
Oh, that's a really tough question because quite a few things. Okay. To avoid sounding like a stuck record and saying MFA again, because really I think we should just implement MFA, um, I would like to see probably less of this cynicism.
And I, I am very optimistic and I know that that could really come across, uh, permanent, sunny. But I, I do think actually if we, if we take an optimistic view at things and try to embrace new technology, embrace new ideas from people in your team, look at new talent you've recruited. They may have only started a month ago, but perhaps they do have a good idea and a fresh perspective on what's happening.
Um, I think if I could, I would say strip away some of the cynicism. That's one of the things I think we shoot ourselves in the foot by. It's good to be critical and, you know, uh, really consider what is best.
But I don't think we have to be so cynical about everything. Um, I think that that kind of mindset shift is nothing technical, is it? It's just on the people side, which is great.
'cause it means it's in everyone's gift to just change a little bit and be a bit more open to trying new things. Maybe that is the way you've always done it, but what if there is a better way? You won't necessarily know unless you give it a try or you are open to that kind of different process.
So I think that's probably, as a community, I wish we did more of, we were more open to trying new things and a bit less cynical. All right, folks, you heard it here. It's time to rediscover our joy 'cause maybe we've lost sight of that, Mike.
I do. I sense some sarcasm. Hey Kirsty, thanks for being on the show.
Oh, thank you so much. Great to talk to you. All right, and back to you guys in studio.