National Cybersecurity Strategy: What it Means for Cybersecurity Professionals – Meredith Bell, AuoRABIT
AutoRABIT CEO Meredith Bell dives into what the National Cybersecurity Strategy outlined by the Biden administration actually means for cybersecurity professionals.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Meredith Bell CEO for auto rabbit. And we're talking about the new cybersecurity strategy document that the US government published at least the White House did And the question it comes to mind in. A lot of people's thoughts immediately is Is this a document?
That's just more of a suggestion. Is it like a vitamin or is there actually something that feels rather prescriptive in here that people are supposed to be doing Meredith you had a chance to look at it? What's your sense of you know how deep does this document really get?
Like I think it's a set of Clues. So it's telling us where they're going. It's it's giving an advance warning that it's time to get your house together.
It doesn't tell you exactly what to do. but really if you're a see-so if you're a CIO you you have a good sense of what you need to do, right? You need to embed your your security much deeper than it ever has been embedded.
Right? You can't just download some security. It's not about downloading security.
It's embedding it deeply into all your processes and everything you do. It tells us that it tells us that we're going to get some very tangible. Ideas, not just ideas.
We're gonna get some dictates, but we don't know what they're going to be exactly, but we know they're coming. What exactly should I be doing? If I'm a security person then do I just print this document out and hand it out to everybody and tell them to read it or do I start putting some things in place today and anticipation of more stringent requirements tomorrow?
You can have to do the ladder. It's not about saying oh this is important stuff. And that's I think what we're gonna see is platitudes don't cut it anymore.
Right? We know the world has changed. It's gotten more dangerous and it's only getting more dangerous in the future.
So things are gonna get harder. It means that you have to build your security way deeper than you ever have before. You got to go look into every software development process.
You have and figure out how you can automate scans early people talk about shift left, right? But you gotta take that very seriously. You got to move it way left to the developer and make sure that nothing.
Nothing is left unchecked. There's there's no room for we download it. Oh, we got we got this company.
We got this coming. You know, you own it your vendors. Don't own it you own it.
And that means you need to be very very deep and everybody in your company has to become really close to Security Experts. We talk a lot about ship left and SecOps. But what's your sense of how many people are really doing it?
I think there's a lot of nodding of heads, but I'm not quite clear that there's a lot of actual changes to the processes. What's your sense of what's going on and as an arms race, so I do think a lot of people are doing it but doing it doesn't mean you're doing it enough. It doesn't mean you've been as broad as you need to to be in in moving and shifting left and it doesn't mean you've gone as deep as you need to go.
Does your Sia does your CEO know what shift left means does she know why that's so important right does every single developer understand that you cannot just scan for security issues. You have to build in security and compliance right there at the start. So it's it's not yeah, we're doing it right.
There's gonna be no end to it. How safe are you how safe you want to be? You want to be so safe?
Because yeah, we told people to be more safe that doesn't cut it that doesn't do anything. So you have to have everybody in your in your company who touches software everybody who can do any kind of change they need to be part of this and it has to be more serious than ever been. One of the things that document really touches on is liability and it's suggests that the government is going to attempt to at the very least come up with more liability requirements than shift the owners out of the people who are building and deploying software versus those that are consuming it.
What's your sense of how real can that be done? Because we are dealing with a Congress. That is somewhat hesitant when it comes to any kind of regulatory policies.
So what's gonna be real here? As far as going and I'm not going to comment on. a Grid, like I always seen this before with financial regulations.
That was what happened with sarbanon's Oxley and it changed the world and it didn't it was it wasn't just it wasn't a slow change. Once they made that very clear that you as a CFO a CEO that you're liable for your financials representing reality. I think the same thing is Gonna Come and that's why I'm smiling because I think we're gonna see this and I think if I were well, we're all in this right all of us are in this so we have to we have to believe it's coming if we don't there's there's something else that can happen and that's called the breach.
So you better do it for Regulatory and compliance reasons and you also better to do it for security reasons and protect all your data and your customers data. We used to make a lot of distinctions between a heavily regulated environment semi-regulated and organizations that were regulated. Are we moving down a path now where for all intents and purposes just about everything is regulated.
Absolutely, you know what's regulated? Pii that's what's regulated is the way you handle your customers personally identifiable information that's regulated. And then there's so that's on one hand on a different dimension.
Every company's becoming a software company. Right, there are banks who say well, we're not really a bank or a software company. So on the one hand everything's regulated and you're right.
It doesn't matter. If you're a bank or a med device manufacturer or Construction Company you have information there that is against the law for you to not take care of so every every company is regulated. Also, all these companies are software companies and that's the important thing is you got to understand that that's the danger.
That's what our enemies are doing is they're trying to get into our software because there's gold in there. When we talk about shift left, some people would say we're trying to shift everything onto the developer and that's not going to be feasible. Most of them don't have a lot of cybersecurity expertise in the first place and other people interpret that to say what we really need to do is shift left by injecting more security people into the application development process, but there's not enough of them to go around.
So what exactly do we mean by ship left these days? It means you find things earlier and I agree with people you can't put it all in the developers. That's not the idea.
But you also can't not put it on the development process. And those are distinct things right because developers are human beings and human beings can only concentrate on two to seven things at a time. You can consecrate on one but you can carry just a small number of ideas in your head.
So you can't have them trying to be better be better doesn't help what you need are processes. It's got to be embedded. That's what I'm saying.
Like you can't download security. You can't just enforce some ideas on on your developers and say well is there all is another fault. No, it's the people in charge.
It's whoever is in charge of the highest level. It has to be embed at all the way into where the code is is being created in the first place. And and it's another way of looking at it is is quality if your quality isn't great, then you're not secure.
So do we want developers to not be great equality. It's there's a lot of evidence you can look around that if you try to hold quality or detect for quality issues later on that's very different than building it in early. And so same thing with security you can try to screen for it later, or you can build in processes.
You can embed those processes early on and it makes it much easier to stay clean all the way through. How much is this just comes down or lack of contact sometimes when I talk to developers? They're like when I'm building the code, I'm in the moment now go address whatever issues that somebody tells me about but what seems to be happening is, you know Weeks Later somebody shows up with a list of vulnerabilities and they've already moved on at three other projects and they don't have the context that they had when they were writing the code originally and it's just too hard to go back and capture all that and first and then secondarily, I don't even know which of these vulnerabilities are really severe or they just on somebody's list.
There are lessons that we can look at so the devops industry really likes looking at airplanesafety and it's just utterly mind-boggling how safe it has become to fly commercially unbelievable. They do it through processes through checklists. And we need to do the same in the software development world, right?
There's no option to say it's okay. It's too hard. No, sometimes you're gonna have to slow down or do things in smaller bites.
That's how you increase your release velocity. So you just need earlier checks more often It's gotta be process. It's got to be automated test.
It's got to be security scans everything. There's not this or that or that it's this and this and this and this Once your best advice to folks about how to achieve that goal because it seems like it's going to require more than just throwing everybody in a room and lock in the door and hoping reason prevails. Are there kind of a baby steps to get along the way?
Well, I think the biggest thing is to understand that you as an organization as a company you're responsible for it. There's no Outsourcing it. I think that's it starts there and it doesn't start just at the sea cell right or just even at the CIO level.
It has to go all the way to the CEO who has to understand that's your company. And those are your customers. And there's nothing more important than taking care of your customers which means taking care of information about your customers.
So it's strategic and you're right. There's not a blueprint for it. There really isn't and every company has to figure out what's right for them.
There's no checklist because as soon as you do that, like I said, it's an arms race. Is there a bad guys over there? And that's the important thing to remember is it's an arms race and this is the most important thing that any company does at this point.
You think the bad guys are kind of laughing at us? Because all they really doing is compromising and developers credentials and then stick in malware in somewhere or their typos squatting on some component somewhere. This is not heavy lifting on their side.
You are absolutely correct. So do I think they're laughing at us? Yeah, and I think it's unbelievable that they're doing things like going after hospitals.
It's it's hard to believe but it is happening. So why and you said you said is not super heavy lifting and a lot of cases that's still true. There is going to be some more heavy lifting but you're right.
And that means what it means that somebody's not paying attention. That's what that means. If you sort of go back and think how did this happen people are taking shortcuts and that's someone's responsibility and it's not just the responsibility people who took the shortcuts.
That's my viewpoint. It's not okay to just blame it on the Developers. If you want a company if you run a company you have to take responsibility for making sure that you're doing everything you can and it's hard right, but I think it's really really not fair to say.
Oh is the developer's fault? I don't think it's fair to put it on the individual like that. If we have a scenario where there's liability and then there's risk to the business.
Do you think investors in Wall Street will pay more attention to application security for the companies that they do invest in because they'll be saying this is a risk. We need to see that you're minimizing. And you know, and I think that's happening already.
And I think it works on both sides of of the coin. I think that companies that are really have the house in order. I think they're getting rewarded for it.
And I think also if you look at longer term investment companies that are doing things about this. There's a lot of interest in companies like them or us. Yes, do you think you know maybe next year or the year after?
Somebody's going to be made an example of to drive the point home. Is that where it comes next? I hope not because I don't think that's the way to do this, but probably so I think there will be examples made and whether that's intentional or not.
I think it's going to happen. I'll tell you this. There are breaches that I know about that haven't gotten publicized.
but some of them are gonna are gonna get out and it's not going to be fun and it's not in my personal opinion the best way for us to get everybody aware of the threats, but I think it's it's gonna happen. Yeah. So how much time the organizations have before these policy recommendations, you know become a real fact of life in their organizations.
or not that's politics, but I'll tell you this. You can't wait for that because the threats already here anyway, so if you're waiting for Congress or the White House to tell you what to do, you're too late. All right, folks.
You heard it here. We're probably behind the eight ball more than we care to admit. The question is is what are we going to do about it now versus next year Meredith.
Thanks for being on the show. Thanks Mike. Thanks for your work.
All right and back to you guys in the studio.