Navigating Cybersecurity and IT Operations – Kristin Hazlewood, HCL Software
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Kristen Hazelwood, who, senior vice president and general manager for Big Fix at HCL Software.
And we're talking about the challenges involved with melding IT and security operations. Kristen, welcome to the show. Hi Mike.
Thanks for having me today. We have seen this trend where more responsibility for SecOps is being moved over to the IT folks because, well, there's not enough cybersecurity people around to manage the whole thing. And clearly they're more involved in that end of the process, so it makes sense.
But I feel like there's a lot of challenges involved thereof. A lot of the IT folks don't know security stuff. And maybe we're kind of tripping over each other, but what's your sense, uh, where are we and how much further do we need to go?
Well, the short answer is we have a long way to go. Uh, but we are, uh, down this journey. Um, when you look at IT organizations today, they're definitely tasked with remediating vulnerabilities and security is tasked with finding and identifying those, uh, vulnerabilities.
And the communication between those two teams is extremely challenged and that's causing, um, causing longer time to remediate vulnerabilities, which ultimately increases risk for organizations. Do we need to train the IT folks or are they just kind of executing workflows? I mean, is the cybersecurity workflow any different than the workflows they have been doing?
I mean, how big a hurdle is it really? So I think it's a, I think if you think about an IT organization, they are tasked with keeping all the digital assets up and running. And one of those elements is delivering against the requirements that security provides.
Security is very much focused on reducing risk of the organization so that you have these two teams that have different, um, different goals, but ultimately as an organization they share a common goal, right? Nobody wants your company to be hacked. And I think if you approach it from the standpoint that IT wants to do the right thing, and we need to be providing them with the tools and visibility to help them prioritize, uh, the activities that are needed.
It does not have to be a cybersecurity expert. If they're provided the proper tools and prioritization they can take, they can make the right choices, uh, to take action to remediate vulnerabilities faster. It seems like we're just collectively challenged trying to figure out what to prioritize when it comes to remediation, 'cause we can't get to it all.
So the question is, how do the security people inform the IT people as to what to do first and what's important? Yeah, so what we see typically today is spreadsheet and email mania. So you see the, the security team sending over, um, spreadsheets from this week's scan or last week's scan.
And it's, it's usually just a, um, I have a friend who calls it a heap of anxiety that goes from security to it. And sometimes that data is prioritized, sometimes it's not. Um, we recently did a, um, a survey, a joint survey with Tenable, and it's seen, um, 57% of organizations view it as it's responsibility to prioritize which patches to roll out.
Which, if you think about it, it's a little bit crazy when security's the one that understands the, the ultimate risk. So the, the key is to bring that visibility into the IT team and provide automated tools to take the, the vulnerability scan data, the threat feed data, and bring that into the same dashboard that it is using to actually roll out the patches. It's crazy to think that, uh, most organizations use multiple tools to share the information and then ultimately comes down to spreadsheets and PowerPoints.
It's 2023. We can be doing better with automated feeds and, and the prioritization, um, bringing all of that together in the same place where it is actually able to remediate. Are we getting any better at patching?
'cause a lot of the IT folks I know are terrified of applying a patch 'cause they figure something's gonna break and, um, they're not quite entirely sure how to roll it back for that matter. And that could be worse off in their mind. So how do we kind of approach that?
Are there best practices for this now? Yeah, so there's absolutely best practices and we're starting to see organizations, the sharing of data, right? The, hey, we were successfully able to deploy these patches without issue.
Um, many companies don't wanna be the first one to, you know, just massively roll out a patch. So you, you, you phase it, you, um, test it before deploying it more broadly. Um, and we're seeing organizations sharing data along with, um, you know, patch quality to ensure that you're not bringing down your systems.
Uh, so it's definitely a challenge, but we're seeing, um, sharing of data and automation is really helping there These days. Everybody and his brother's talking about some great new AI thing. Can AI help us smooth the transition here in the handoffs between these folks?
So AI can help in the, the handoff as well as the prioritization. When you think about all the different factors that come into play in determining the prioritization of remediating vulnerabilities, you know, you've got the location of the system, the criticality of the system, what software's running on that system, who has access to the machine, um, how many vulnerabilities that machine has, what attacks are active in the industry at the time, right? So AI can really help with the prioritization as well as the insights, again, into which patches, um, are safe to deploy in which patches should be held off.
There seems to be a debate about whether the bad guys are getting smarter or is it just more a case of we keep adding more and more things to secure and the odds that something's gonna go wrong just increase as we continue to add things and the attack surface is just too hard to defend. Yeah. Is it a little bit of both or is it one more than the other?
Uh, it's a, it's definitely a little bit of both, but what we're seeing is the monetization of the attacks. So you think way back, right? You were attacking to try to get information to, to get some sort of advantage, but now you're seeing the organizations are able to monetize the attacks and so you're seeing attacks in more and more places, places that you typically wouldn't, wouldn't think that would be subject to an attack.
So every organization has had some sort of digital transformation and has assets and you're seeing more and more threat actors being willing to go after any type of organization, not just the banks and the government institutions and, and things along those lines. You're seeing, you know, home builders restaurants, you run the gamut, right? What is your sense of, um, the security people?
Do they like this transition or are they a little wary of giving up control of the security operations themselves because they think, well, um, you know, if I want something done, I should just do it myself? Well, so there's definitely a lot of friction between security and it. And, um, anytime I'm speaking to a group, I like to, you know, show of hands, who's security, who's it, okay, who's friends with their counterpart on the other side?
And typically there's, there's a lot of friction, right? Security doesn't wanna give up control and they shouldn't be giving up control. It should be absolutely be a partnership.
And in the past it's been a challenge, you know, security will feel that it is not moving fast enough and it says, well, you don't understand what's gonna happen to me if I, you know, take down the ordering systems on Black Friday or, you know, things like that. So it's, it's not necessarily security handing it over to it. There's always been this collaboration or necessary collaboration, whether the, it's actually good.
Collaboration is debatable, but there's always been a collaboration between the two teams. But what we're seeing is the realization that there needs to be clarity and automation, you know, clarity of ownership and responsibility as well as automation to help the two teams because both teams have more that more to do than they can possibly do. Um, and we need to find ways to support them through, through automation.
But security's not giving it up. It's not a, not handing it off completely. How do we achieve that automation?
'cause the darnedest thing in the world is that we use it to automate everything in the world, but the management of it itself is far more manual than anybody cares to admit. Yeah. The best way to scare an IT admin is to tell them, oh, we created an easy button for patching, just hit it and it'll pull out all your patches across all your systems instantaneously, right?
They can immediately jump to realizing that that's, that's not the best way. I mean, it's the best way to take down your environment. It's not the best way to secure your environment.
So it's about, um, having smarter automation and make and, and finding the right way to leverage automation and share information across teams. If you think about it today, security has one tool set that they're using to identify vulnerabilities and report risk to the business. It has a different tool set that they're using to manage those assets, and it needs to have the visibility in their tool set where they're actually taking action.
They need that security visibility. So the key is to build integrations between those two tools to bring that insight so that they can make smarter decisions in real time without having to wait for that email from the security team to tell them what to do. So it's, it's bringing the two tool sets together will help bring the organizations together.
Do you think security folks are becoming more reasonable about the things that they call out? Because it seemed like, you know, they're used to be at least known as the, uh, office of no. And now we have a lot more flexibility in the part of the end users for better or worse, but how do I kind of sort this out in a way that doesn't result in, um, locking everything down or at least doing some things that are based more on say, their actual risk?
Well, I think that's, um, an ongoing challenge, right? If you ask the security team, they would have everything disconnected off the network and, you know, it'd be very secure, but it's about finding a balance. You have to find, uh, ways to open things up as well as secure them.
And it's, it's a ultimately comes down to be a business decision about the risk level that's, that's tolerable for that organization. So, um, it's, it can't be security alone making those decisions. It needs to be a collaboration between security IT and the business to determine, you know, how open should things be.
You have to be open in, in some sense, or you can't get, you can't get your work done. What's your best advice for bringing these teams together? Do I just take everybody and throw 'em in a room and lock the door until common sense prevails?
Or is there some other way to think about this? Well, that would certainly be, uh, very entertaining if you were to do that, right? I think so leadership needs to, um, really emphasize the business impact of cybersecurity risk and the shared responsibility between IT and security.
And then the two teams need to be provided automated tooling to help them speak, you know, have the same access to information as well as speak the same language and have a common reporting metric. So, you know, I've, I've been, uh, with organizations while the security team's preparing to go, you know, report to their leadership and it's, you know, I scanned and I found these thousands of vulnerabilities. And then on the others flip side, you have the patch team coming and saying, well, I've patched, you know, 10,452 patches in the last month.
Well, what, what business outcome do either one of those reports actually represent? You don't know. So you need to be able to, to bring those two views together to show what is your real risk posture, what is your mean time to remediation?
And if an organization, if you determine, you know, for this severity level, the remediation time is one week or, and for this, uh, severity level, remediation time is one month, then those two teams can be reporting, um, against those standards. Where today we're finding that those standards and businesses are not consistently defined and enforced. So until you give the two organizations common ground to report to their leadership, there's always gonna be, uh, a tension and a friction between the two teams.
One of the things that those two teams can always seem to agree on is that it's some application developer's fault somewhere. How do we make this software folks get involved in this in a more meaningful way? Absolutely.
So the, the teams building software, you know, there's definitely a push to the application security scanning. There's pushes now for, uh, SOM, which is the secure bill of materials so that organizations building software are needing to, um, basically, you know, state all the software that, that was pulled in to that software. And you can look at the Log four J vulnerability as one of the things that really kind of drove some of those initiatives, um, being that it was an open source component and included in so many applications.
So I think it's, it, the software developers absolutely play a part. And, um, yeah, everybody, everybody plays a part in security here. We have seen a lot more regulations in the last few years and they seem to be getting more stringent as they go along.
Do you think that these regulations, for better or worse, are gonna force this collaboration issue? Yes, I think, I think they will, right? So the SEC regulation that you have to report a material breach within four days of its discovery, we're already starting to see that change the way that that businesses are, are addressing this risk.
Um, so yeah, it's gonna definitely start to make changes. You know, I don't think that organizations should wait for regulation to, to implement things like this. All they have to do is look around and, and there's probably an example of a, a peer in their industry who's been very negatively impacted by, um, a ransomware attack that should be motivation enough to, to start these initiatives.
But regulation can certainly help. We've seen in a lot of organizations there's ACIO and then there's also a ciso and they don't always report to each other. But, um, how should these teams be structured?
Should there be one leader for them all, or, um, do maybe the CIO and the CISO just need to set the example? I Think the CIO and the CISO need to set the example. Um, 80% of boards see that, um, cybersecurity is a risk to their, to their business, and they should be holding the, the CISO and the CIO accountable to that jointly.
Um, I have seen organizations where there's a, a reporting structure, you know, one's reporting into the other, I don't know that one's one way or the other is better. I think it all, it comes down to, you know, you've got two teams that have separate and distinct missions, but also a joint mission, uh, to secure the enterprise. And so whether that comes together at a leadership level below the board or comes together at the, at the board level, um, it needs to come together and, and organizations can make, can make that call on what works best for them.
All right folks. Well, you heard it here. Somebody needs to write the book that says how to talk to an IT person or a cybersecurity person so the other will understand each other and maybe something good will ultimately happen.
Hey Kristen, thanks for being on the show. Absolutely. Thanks for having me, Mike.
All right. Back to you guys in the.