Optimism in Cybersecurity in 2023 – Emilio Escobar, Datadog
Datadog CISO Emilio Escobar explains why despite challenges there is still plenty of room for optimism when it comes to cybersecurity in 2023.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Emilio Escobar. Who's the ciso for data dog? And we're talking about what 2023 will bring from a cybersecurity perspective Amelia.
Welcome the show. Oh, thanks for having me pleasure to be here. I feeling every year we start out with the same conversation.
It's gonna be the best and worst at times in cyber security. But this year seems like things are a little different. There's this nasty little cat gbt thing running around and everybody's freaking out about and then it seems like the attacks themselves are increasing in volume, but maybe not just volume but diversity in classes and things are a little trickier than usual or am I just imagining things?
I think you're right. I think every year we start with the same the same tone. I I don't think the attacks are getting higher in volume.
I think maybe we're talking about them a little bit more than we used to but but the attacks have been quite the same for for quite a while. All right, we hear a lot about how stressful it is to be a seiso and in being the security industry these days you look like you're relatively calm. So is there some secret to your approach or you just hiding it better than most?
Well, if I have a secret, I will be to me we won't share it. But no no, I I sleep well at night. you know, I think the secret if any is a surround yourself with people that you trust and and rely on on your teammates.
You know the job can be stressful at times. but I I truly believe in that saying that's that not everything is as good or as bad as it seems so there's always there's always something better or something worse. I could happen.
So take it day by day, but trust the system and trust your teammates. I think to me has been pretty clear. I think one of the main stress factors for most ecos is when when they're tasked with a lot of responsibilities that they can't delegate.
And I happy to be one of the lucky ones who can't delegate quite a bit and I have good partners on the engineering side that help us quite a bit. So I think I think I'm one of the luckiest ones. One of the other things we do here about all the time is the cybersecurity skills shortage is that just a question of we don't have enough people or is it just more that we don't have enough well-trained people and that's part of our problem.
Um, I think it's a it's a little bit of everything in my opinion. I I think you know Some some of those pain points. We we introduce in ourselves one example.
I've seen plenty of job openings for entry level security roles that require five years of experience or requires a assist certification which by Nature requires five years of experience or we ask for somebody to have 15 years of experience in kubernetes when that technology hasn't been around even for that long to begin with so we call someone that sex but I you know second of it. I do believe Talent is out there. I just think that most security teams are aren't great at exposing opportunities where they need to be.
and also, we could do a lot better about giving people chances that maybe don't come from that like the straight technical linear path into security that would address some of the quote-unquote gaps that we have in hiring but I believe there's Two jobs for every person that's out there and and you know, we're just not hiring. So I I don't truly agree with we have a skill shortage. I think we just need to change about what we think.
What a security person is and what they can do and and what are we require them before they come in? On the converse of that. We also tell people they should automate more and we've been talking about security automation forever in a day, but yet seems like it's a challenge.
So from your perspective, why don't we automate more of the security functions? You know, I think we should definitely automate the things that we feel comfortable with some of the challenges when it comes to security automation is a lot of what that automation would do. requires some judgment But then second to that were the systems that these automation will take actions on.
Most of the times are not systems that are owned by security. So if you're going to build an automation for example takes a system offline. Then that's something that you might not want to do freely because you don't really understand what the impact of the business is.
But I do truly believe that there is a a set of low-hanging fruit items that security really good automate and some of that could be how do you automate the enrichment of giving the context of the security person I need to respond say a four in the morning with something happens. So you can automate the data data Gathering and provide the context. So that person can make a decision pretty quickly about do I wake somebody else up about this or not or or what else needs to happen.
So there's there's some various things there so not but but yeah some of the deeper automation are really difficult to do because of what I mentioned is it requires a lot of judgment, sometimes there's impact that security is not fully aware of and there's always that fear of taking that action and then costing a business outage. And then having to respond to that rather than then the security issue in itself. So it's a combination of things but we could automate some more and I think Security in general could also benefit with with more software resource engineering resources as well.
So our people so that we could actually build meaningful automation rather than just out of the box automation that some of the industry products provide it seems as of late. You cannot walk down the street without somebody telling you how AI will change their life. We've been hearing about Ai and cybersecurity for some time now and yet the progress is been relatively uneven once your sense of just how applicable is AI to cyber security.
Yeah, you're right. I I don't think I've seen much. Movement there or much improvement since since we've been using some AI for security.
I I you know, I think So I think the answer the question is a little bit twofold right of of other security impacts when it comes to Ai and and more of the easier access to AI products like chat GPT as you mentioned before and second of it is from a security standpoint. How come we don't use Mori for the latter part? You know, I I am very excited about seeing some of the Innovation that is happening were were some Founders are actually trying to apply meaningful AI to security and I think some of the models can be easily trained.
I think some of the challenges there is how do you get the data to train the models and where the data comes from? So for you to be able to have a good AI product it needs to have good data and most companies are not willing to share some of that data naturally. So this is some of the struggles that I see some of these startups have is how do you gather data?
So luckily some some newer companies have adapted a better design partner program and things like that where some companies are now opening some of the data to share, you know, if you want to use data to the tech and attack, then you need to be able to have the data that shows the Baseline over the network activity and then what happens during attack so that way you can train the model but I think in a couple years we see a product which you see more progress there and I think some of their restrictions that we seen in the past has been because of what I just mentioned above about automation is what do you want the AI to do and I think some of the applications initially work here towards last half the AI automate telling us what's going on or doing something about it when I think in reality what the AI should do is Hey out of the 30,000 things that you you see every day and in your screens or or your whatever security controls you have these are the top three things that you should worry about that we think you should pay closer attention to so I think that application of AI will be more beneficial than what we originally I think intended towards AI products and security Now the other part of the question about security implications on on AI products like chat GPT. you know the way I think about it is a we're not We're Not Gonna 100% prevent people from playing, you know playing with it. It's it's a new toy people are gonna use it.
There's good value coming out of those of those of these products. So I think there's gonna be more of an emphasis around awareness and guidance for how to for what you should use this product what you should feed or send to that product. I believe I don't know if you've seen it, but I believe Amazon sending announcements saying how like let's not put intellectual property in this systems and and query and use that to query because obviously that's data that they're gonna use to learn the two concerns that I have.
Given a type of company that we are around AI is the that notion of having AI right? source code for you and and the two concerns with that or with that are the quality of the security quality of that source code that train the data used to train the model which is sample code that they've captured from from multiple sources may not be up to par with what we want internally the teams to drive one example, I play well explain one of those products and I asked it to give build me a function that compare it function that store use in him and password when somebody's register and it was using a week encryption method to to encrypt the past or rather than using one way hashes, right? So these are some of the things that security teams need to be aware of that if you do have Engineers or employees that are Grabbing source code from the internet generated by AI which has a higher level of trust ironically than say.
Hey, I copy and paste this from stack Overflow to to be mindful of like what are the requirements or what are the guidance that we need to give them around? What's proper from a security standpoint or not? The second aspect to it is is a license in friction.
That's something that maybe we don't talk a whole lot about but again these AI models capture source code from different samples. I don't really know what the license of the source code that train the model is and then if if it's spitting out a module that was written with a more restrictive license and when some of our Engineers are just copying and pasting it to our internal products, then we could run into a legal issue. There is if we do go through licensing freshman claims.
So those two are my biggest concerns when it comes to Ai and it happens to be with when he generate source code based on a prompt now having AI write you a You know an essay or or a blog post or things like that. I'm not really thinking about it from a security standpoint right now. I'm just think focusing on What do we use AI for?
I mean see the relationship between cybersecurity teams and the rest of the organization evolving and we'll start with this whole notion of Shifting left. And then of course, there's a ship Right Movement where we want developers more involved. We want the it operations team to take responsibility for more security operations.
So how do cyber security people kind of engage and change their mindset says that Trend evolves in both directions. yeah, so I I am a firm believer of both shift left and shift, right? and I think house this is gonna be one of the bigger challenges that security is going to see particularly in a year like this or a market like this where They may not be able to hire as many people as they have or if they can hire at all right or get budget for buying security technology, and I think we're going to see some.
A trend around consolidation of tools specially for an industry that is known for just buying hundreds and hundreds of products. And a small percentage of them actually being fully operational. So Chief left I think is is great because mistakes are cheaper to solve before they say you you find a vulnerability in an aptly in a Piece of software or a piece of code that I developer writes he sees is cheaper to fix that the moment the developer tries to save that source code into the Version Control System then allowing the engineer to push out a production and then having to fix that later, right especially if you're not a company that is it has a good engineering practice of deploying many multiple times a day to production.
That means that that issue is going to be left in production for however long it takes them to solve it. So shift left is great. Also, I think shift left influences shift, right?
Because and again I'm associating that to a business like ours will we do write software for a business? Right? That's our our what we what they did not does is when you have a good shift left approach, you're providing Engineers all the context that they need to know around.
What is it that they're writing the quality the code they're writing say they're writing source code to build infrastructure. What are the guard rails that are authorized there and you build In path to allow the developers to just do their day-to-day, but without the risk of of the safety risk that comes with it. If you allow them to freely do whatever why does that influence shift right is because then for you to be able to successfully deliver shift left, you will need to have the collaboration in their relationship with this team to be able to get them to adopt the things that security wants them to use.
That then when you go and say hey, by the way now we need you more involved. In say investigating the security alarms that we're signals that we're getting you already have those bridges built. So you're not approaching a team that you've never talked to before and say oh hi.
I'm Emilio from security. I've never talked to you for the last five years, but I need you to do this which is a point of contention and friction that I've seen in other places. So I think one of them benefits the other but I actually think this is gonna be more and more of the direction that security teams are gonna have to go not only because it's better for the business, but also If you look at the adoption of Technology.
Is always being I want value in a more immediate fashion, right? So I want to get the value out of this product or this technology now rather than later. So we're gonna apply that of security and it's going to be seen across the board where security needs to be able to deliver value sooner rather than I did all this work.
And then now that we're out there and running at live with it. Now, I'm hearing from security that we did everything wrong or I did all this work and the day before that we're supposed to go live with the security is telling me I have this 30 issues that I need to fix. So the value of now is going to be the team that I think security teams are gonna have to adapt to do to solve for and it's gonna be a challenge because that's gonna require hiring different type of persona, you know, you're gonna have unique and have a good mix of people non technical people in your security team were I think it's going to be a challenge for a lot of companies to get there.
All right. Well that sounds like a diplomatic effort and speaking of diplomacy. How is cybersecurity getting along with the rest of the business in terms of the Business Leaders the business units do they get it?
Do you think they have a greater appreciation order? Is it still something that they're kind of looking at it and going? Yeah, where's that lowest level checkbox and get me that and we're good to go.
Well, you know, I think there there definitely. Is more awareness and I think one of the good things about your point earlier. That you can you know, you can't really walk around the corner without hearing about AI but the same thing applies to you can't really walk around the corner without hearing about some security thing that's in the in the news.
So this is bringing more awareness and and I see other Business Leaders being more concerned about security because it's been pretty clear that if mistakes are made, you know from a public perception aspect from a trust aspect things can just get pretty hairy. So I think there's more of that I think were the wrong meets the road is how much of that security should they care and what's actually meaningful Now versus later right in every business has that Journey we talk about acceptable level of risk anywhere in security you go to or talk to you say security. It's all about like maintaining like acceptable levels of risk.
Well that bar of accepting for acceptable risk changes with time and as the businesses grow or they transition so I think it's also not just getting security or Business Leaders who understand about security. It's also the work for security to work with them to understand. What is that level right now?
And where they'll say what is healthy for it to be right now versus where it needs to be. Right and I think a lot of the challenges that I see is when What either of this scenarios happen the business leader absolutely does not care. And security is always fighting the feels like they're always the only ones fighting the fight or were security come the person cares, but security comes in and says, well you only care to this much we care about this much more and then there have disagreements about like how much security is appropriate at the moment.
So I think there needs to be better conversation and communication there, but the getting people are worried about the implications of security. I think it's the new stories are hoping us there in my opinion. It also seems to me flat out that it environments are getting more complex.
We see containers and serverless Frameworks and all these other things that are floating in and the old stuff doesn't seem to go away. So the question then becomes, you know, are we up to really securing all these environments because frankly I've never seen so many being used at the same time. Yeah.
Yeah, so yeah, it's interesting right because technology seems to evolve quite a bit but I think security for whatever reason keeps trying to solve the problems the same way. And and just like we moved from having physical servers to moving to Virtual machines. So not moving to Containers.
I believe security also needs to move along that Journey as well and understand. Okay, when we had a server these were the threats that applied to that server now, they was a virtual machine This Is How They changes and now that it's a container. This is what the ecosystem looks like and what threats apply to it.
So there needs to be different threat models for each of those. So I believe the teams need to adjust but to your point and I believe I got a if I if I got your question on this your question correctly, you're asking me also about what do we do with Legacy versus what do we do with new? Everyone has to take that and I think Tech that is a good thing in the sense of it shows that the company is growing if you don't have no Tech that means that you're probably not doing much as far as like playing with new things and and innovating.
So I see Tech that as a result of like we're actually innovating. So we need to align with that Innovation for legacy systems. You know in my to me goes back to that message that I what I answered before is what is acceptable for those systems.
So if I have a legacy system that is being worked on to be replaced and how much security do we need there versus do we just focus on the new thing if we have a legacy system that nobody knows and it's not going to get touched then maybe the how much security there will be will be a different bar in my opinion. Especially if it's going to continue being business critical. So again, he has to be around.
What are the you know, you threat model. The systems and and how much security of it is necessary and you can do good enough security for a legacy system just like and you can do good enough security for for containers and new systems. But the trajectory we see everyone going is it stores?
Like you said moving to the cloud adopting containers? Faster Innovation, we want to deploy multiple times a day because our customers or demanding it it goes back to the demand for of now. So that's a lot of what our focus is and a lot of my team emphasizes on that because datadog is is completely containerized.
All right. It's 2023. I'm sure you've had pet peeves for a number of years.
What's that one that you would like to see resolved in this new year that basically would make your life easier. That's a question. I think.
You know following the theme of what I've been I've been talking about. we talk a lot about the plethora of security products out there Last time I looked at a slide that had the logo of every security company out there. I believe the size of the logos were like one pixel because the otherwise you couldn't fit it into one single slide.
So imagine joining as a security professional and thinking about what a special breed out there. And what should I deploy and again coming from an industry that is totally acceptable to buy 30 of them because the more you buy the more security you are and that's the perception that I think is incorrect. So, I think my pet peeve is my pet piece or twofold.
Is one pet peeve that applies to both angles is I think security teams you spend more time understanding. What are the actual threats that that impact the organization and then what is that ecosystem of technology that you need to build so that when you would when you then start talking about people and process it all aligns. Well rather than like all this disparate ad hoc technology products and then you ask somebody to change from screen a to screen Z in one day to resolve one single problem.
But we also need more products to take security into account and actually build products that take into consideration. Not just the continuity load that you're putting into the users that use your products. So security products is a perfect example, if it were my security team brings a technology product, but we're not the ones dealing with the day-to-day of it.
It's like some infrastructure team that has to pay pay the piper at that point. So if I'm I'm building that product I need to think about okay, if I'm not if security is not the user but security is the buyer who is the user and how to actually make a great experience for the user. So that's one pet peeve that I love to see solved and second of it is You know, if you're if you're building a platform that your customers rely on.
Then then think of trust as the number one element that you want your customers to have not just from the product will work. The product will solve our problems. But also the problem the product is not going to cost security things for customers and make it extremely difficult to secure their own implementation of my product if I'm building one of them, so think about their level of responsibility that you have towards your customer and then put a trust hat on as as a key driver for for business for you.
So those that's my pet pee but it applies to not just security products but also any other commercial product as well think of your user and how much Connolly flow you're putting on them. All right, folks shared in here. If you don't know who's gonna deploy it or manage it perhaps you might not want to buy it.
Hey, right you thanks for being on the show. Yeah. Thanks for having me good questions and back to you guys in the studio.