Navigating Budgets, Tools and AI with GoTo CISO Attila Török
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Attila Turro, who's CSO for GoTo, and we're talking about this fundamental conflict that exists between, I need to become more efficient with cybersecurity spending, but I can't back off on the mission.
Hey, Atila, welcome Michelle. Thank you, Michael. It's good.
Great to be here. I think everybody in cybersecurity is having this conversation these days to one degree or another, depending on what vertical industry you're in. But in your experience, are these two goals that just cannot be achieved simultaneously?
Or is there some way to think about cybersecurity in a way that is maybe smarter than we have been doing? Yeah, I mean, it's, it's a hard conversation for for sure. You know, in one hand I do need to cut back some on some of the expenses.
On the other hand, while I do need all this money to spend on, on protecting the company, but I think there is, there's a way to, let's call it better, to optimize the system. It's um, 'cause if you really look into all the things that we're spending, uh, money for, uh, you know, in terms of security, sometimes you can dig out things that, oh, how come this, this stuff is still around, right? And I didn't know that we are still using it.
So by starting just with that is looking into, well, what are the things that you're not fully utilizing, uh, that can, that can help yourself as, as well. And I think in this time, you know, when the, the, the economy is, uh, is a little bit, a little bit of, of struggling, uh, there's a lot more scrutiny coming into, into security, and you have to be really diligent of, well, how am I spending the money that I'm given to, uh, wisely? Do we just have too many tools and we're spending too much time integrating them, and we need to, some people say we need to shift to a more platform mentality.
What's your take on what's going on? Oh, yeah, that's, that's definitely true. Um, like we just, uh, we just did an inventory of our, of our own tools, looking through every single one of them that we use for security.
And if you look at them, you know, one by one, oh, this is important. We use this tool to scan our source code. Oh, this other tool is important.
We use this tool for something else. So one by one, they are all very important, but then you add them all together, it's like 8, 10, 12, even more tools that, that you have to maintain, that you have to pay for, that you, well have to actually do something about, uh, the findings that they produce. So, so yes, it's, I fully agree and I, I'm totally on board with, uh, with the mentality of, of we can do this smarter by, by integrating things together.
Now there's a, there's of course a little bit of caveat there. Uh, Michael, like when you think in a, in a platform, sometimes you do lose that specialty that you would otherwise get from a, like a purpose built single use tool. But on the other end, the gain that you get is actually things that you can now have time and resources to address and, and work on.
Um, you can have the best SaaS tool in the world if you just don't have the resources to, to fully utilize it than what's the point. It's better to have that in a, in a platform that actually you can fully utilize because it's all about not the findings, but what are you going to do about them. And it seems like every tool is accompanied by somebody have to hire to watch the tool.
So that doesn't really help. 'cause as far as I can tell, the cost of labor is still the biggest issue in the whole budget. Oh, yeah.
A hundred, a hundred percent. A hundred percent. And, and that's, that's another thing is, uh, that I've seen in my own career.
I was guilty doing that, uh, in earlier in, in my career. I hope that I'm, I'm getting better at this is, is really not just looking at, oh, here's a problem and here's a tool that fixes that problem and thinking that the problem is solved. Because exactly there is that, that part you were just talking about, Michael, is somebody has to watch that tool that the maintenance part needs to be there.
And that's, again, where going back to, to using a, a platform that potentially, uh, provides more services all at once is, uh, on the long run, it's actually more feasible because you can, you can maintain it better and easier. Uh, instead of maintaining, you know, five, 10, uh, a hundred different tools. What do you think the impact of AI is gonna be on this cost equation?
Because I scratched my head a little bit, and I get the notion that we can automate things and we'll make people more efficient, but last time I looked into it, you have to write a large check up front to get the benefits on the back end. So, um, how do you make that conversation work for the business? Yeah, yeah.
That's a, that's a, that's a fair point. And, and really it's, it's again about using the things that we have, um, smartly. Because sometimes you can, you can see that, okay, well if I get that extra, uh, you know, AI feature for this tool that I'm using, now all of a sudden it's gonna be so much better and, and so much more efficient.
But then, well, you just add it to the cost, uh, while you're actually trying to save. So it's kind of controversial, but where AI can actually help is, again, you using it at smarter. So for example, within, within my team, we use ai, um, quite a lot.
And when, when I say ai, I, right now I'm thinking about the, the generative, uh, AI that is all over the place, you know, chat, GPT or pinging chat and, and, and et cetera. So you can use these tools to actually correlate a large chunk of chunks of data, um, into smaller, understandable pieces, helping you with, with detection without necessarily have to go and buy the, the expensive AI add-on to, to your tool. So sometimes you, you have to be more, uh, diligent or smarter yourself and, and use the tools that are, that are available for you.
Are there things that can be cut sooner than others? Because frequently a lot of the times we're cutting things, but the impact of that might not be felt for months, if not years. And the board is sitting there going, well, we need something that we can cut in the next 30 days.
Oh, yeah, yeah. That's, that's a, that's a good point. I mean, it's, the root cause of that is, is, uh, that the secretary, uh, team, uh, the secretary program still seen as a cost center many, many times, uh, by the board, by the, by the leadership.
But it's, uh, it's a secretary leaders, it's a CISO's job to show that actually we are, we are driving revenue, we are, we are helping our sales team to close businesses. And I'm not just only talking about, you know, the obvious things where, but the secretary team is helping, you know, answer secretary questionnaire from a customer. I'm talking about actual requirements, whether that's regulatory or within a contract.
So you can go back and look at your, your own tool set and, and the contracts that you have with, uh, especially larger customers. And you can easily make this conversation, not a cost conversation, but a revenue conversation, for example, um, we mentioned in our, uh, in our, uh, contracts with many of our customers that we cover our source code with static, um, uh, source code analysis. So now I can bring the, some of those bigger contracts in and show to the board of members that, Hey, this is how much revenue we're, we're helping to gain by having this tool in place.
And, and all of a sudden it can be a different conversation. And this is also what can help you to drive down, okay, well, what are the things that I can cross off the list? Uh, well, you definitely cannot cross off the list that, uh, you are contractually and regulatory ob obligated to do.
So then you can keep going down and, and see, okay, well, what are the things that we are not utilizing? What are the things that we are not, that are not driving any kind of outcome? And sometimes it's gonna be this tool is in place for years, and we are really not doing anything with the findings.
So how about, you know, replacing it with something else going towards a platform Also seems there's a tendency, like the first thing that people wanna cut is training. And I can't help but wonder if that's not cutting your nose off spite your face. Yeah, that's, that's, that's a very good phrase, Michael.
Yeah. In, in fact, we just talked about how, um, you know, large the, the cost of labor is, and it's because sometimes we have more people than what we actually need because we might not have the, the best people for, for the job, but providing them training, you can actually have a much more lean, yet more productive security team. So, uh, cutting training is, is definitely among the things that I, I would put at the very end of the list of, uh, of things to cut because it's, uh, on itself, it is not a big gain to be honest, but it's, it has a huge negative impact on, on your team's productivity and, and just, you know, getting them smarter and better at their job.
Now, if we look at secretary training as a whole, like secretary training for the company, like awareness and, and phishing training and, and, and et cetera, it's again, going back to showing how valuable they are. Maybe there is a reason to cut your security training because it really doesn't drive any kind of change or it, there is no outcome of that. It's just boring.
And, and people don't even, you know, think about that. But if it, if they do, if it has an impact, you have to show that. Like, you have to show that look, because we are doing the secretary awareness training or the phishing test, this is how much we are, you know, click-through rates decreased, this is how much, you know, how much more reports we are starting to see from, uh, from our end users.
So it's really about trying to change the, the conversation and showing that, well, not, not the cost, but the gain. One of the things I think we've seen early on was in order to cope with the shortage of cybersecurity personnel, we've essentially been deputizing the IT operations team developers and anybody else who can move to do something and help us out with cybersecurity, is that gonna accelerate during a downturn? Because we're not gonna be able to hire additional security folks, so do we just need to make this everybody's problem?
Yeah, I would say it, it's, um, regardless of, of the, the shortage of, uh, of, of, of secretary talent, I think this should be the way, because if you think about it, Michael, uh, a good engineer, whether that's an IT engineer or a software engineer, like if you want to be a good engineer, you've got to know about security a little bit. And actually, the more you know about it, the better an engineer you're gonna be, which means, you know, you can, you can get better offers, you can hit, you can get better jobs for yourself. So it's, again, it's our jobs, it's the secretary leader's jobs to show that side of, of the story, that it's not just, I'm putting work on you because I don't have enough people to, to do the work.
Instead, this is actually enabling you to become a better engineer, to become, you know, um, uh, just a better, um, better worker, better engineer overall. Mm-Hmm. Do we also need to have a, an honest conversation with the business and say, we are not gonna be able to defend everything.
It's just not feasible. Or as Frederick the great one said, he who defends everything, defends nothing. Um, and do we need to pick our spots and figure out, you know, what is essential and what is nice to have?
Yeah. Yeah. Michael, I mean, all in all this, this whole business, uh, the, you know, this whole business of security is, is, is a bet, right?
Like, uh, I'm, I'm trying to bet on the things that, um, um, you know, the attackers might go after, but they have to be lucky only once I have to, you know, put my betts on the right things all the time. So it's, it's definitely a conversation with the business of, look, these are the things that, with the budget I've been given, with the resources that we have that we can, we can cover and really turn it into, into a risk conversation. I'll give you an example.
So let's look at, um, you know, reliance or, or, um, just, uh, disaster recovery. Like if your product, if, if if your product get, uh, gets, uh, ransomware attack and you say that, well, I can only recover probably in two weeks, and if the business says it's okay, then you just had a a risk based conversation and everybody is happy with it. It's really having about having these honest conversation that, look, if you say, we don't do ransomware protection, this is what can happen.
Can you deal with it? And if they say yes, then we go with that. I might argue that the only perfectly recession resistant business in the world is your enemies, right?
They don't really care about downturns in the economy and they kind of laugh it off. So, um, is the playing field getting decidedly less level than it ever was because they have more resources than ever and you're kinda having to pick your spots? Yeah.
Yeah. And what, what's so funny about that, Michael, is, is how much they are actually going off to technologies that sometimes security leaders are kind of afraid of. Like generative AI is, is a perfect example.
Like, we, we try to find ways within, within security of, okay, how can we get that out of our, out of the way? How can we not have it within, within the component because it just brings in so much headaches. But on the other hand, like that's exactly what, um, uh, what the attackers are doing.
Like, they are using generative AI all the time, like the phishing emails that we see nowadays and we are going to see next year. Like they, they, they chew the roof in terms of quality. Like they can even mimic the style that your CEO has.
It's, it's pretty, pretty amazing. And that's why we also have to go and, and take that risk. Okay, let's bring in ai, let's bring in, um, generative ml and, and see what we Can learn from it.
All right, folks. Well, you heard it here. Just making wholesale cuts, probably not a good idea.
Somebody, you know, on the CFO usually shows up and says, cut 10%, but it's, go figure out where that needs to be and to play smarter, because the only way to be more cost effective is to get ahead of this with some cognitive thought versus just wholesale chopping. Hey, Atilla, thanks for being on the show. Thank you, Michael.
All right, back to you guys in the studio.