Overcoming IT and Cybersecurity Challenges with Barracuda’s Siroui Mushegian
Siroui Mushegian, Barracuda CIO, discusses the challenges faced by IT professionals amid the emergence of new technologies and budget constraints. Siroui Mushegian emphasizes the importance of strategic prioritization, risk assessments, employee training and effective communication between cybersecurity and IT teams to navigate the evolving landscape of cybersecurity.
Transcript
This is Textron tv. Hey guys, thanks for the throne. We're here with Barracuda, CIO, Siri Mache, and we're gonna be talking about some of the challenges that it folks are facing in light of, well, there's a lot of new emerging technologies and simply not enough budget to go around.
Siri, welcome to the show. Thank you very much, Mike. Nice to be here.
Thank you for having me. Every time we turn around, the attack surface gets bigger. There are now new AI platforms in the mix.
There's a new SaaS application. It seems like every day people are putting stuff out of the network edge. There's all kinds of interesting new emerging technologies in the cloud native space.
And for joy, we're experiencing some economic headwinds. So we're supposed to secure all this stuff with using theoretically less money. How do you kind of balance those things?
It seems like they are competing issues that are gonna be at loggerheads forever. Yeah, those are all pretty substantial challenges that as a leader in technology you face, um, you've said it all, you kind of covered the entire plethora of challenges. You've got people that wanna introduce, um, their particular, uh, point solution.
You've got, um, all kinds of, uh, systems that might be of various ages that need to be secured. Um, you have projects that need to be completed, and they might be sucking some budget dollars out of, uh, what you need to kind of cordon off to the side to make sure that you keep things safe and sound. So there are a few creative ways that I like to make sure that we, um, keep things prioritized and, uh, and carefully.
So, um, uh, one of the ways that I like to do that is by trying to start with a risk assessment. So those I, I make sure that we do those regularly and by a risk assessment, that can be something that we do internally or we can engage with a third party that will come in and take a look at everything from, uh, the perimeter of our networks to the way that we have, um, uh, the way that we've configured our own internal business systems to the way that we are engaging with, uh, with processes and our employees. So, um, you know, looking at it internally with our own internal audit functions is, is a way that we can do that kind of on a rinse and repeat basis, but engaging with third parties kind of keeps us honest.
Um, but these risk assessments are really important to start with, to kind of figure out a baseline of where we wanna start our budget. Uh, so that's, that is one, one place to begin, and then I've got kind of a, a good long list of other areas that we like to cover. So, um, where would you like to begin?
Well walk through a couple of those. And while you're at it, how do you get the business people to appreciate that? Because a lot of times they seem to want magic to happen and they want it to happen in a way that, you know, the security folks don't get in the way, but we're not gonna have an issue down the road.
Well, I think it's important to get people to understand how important security is. So, uh, you know, Barracuda, we're a 20-year-old company. We just, we just actually had our 20 year anniversary, and I've been here six months so far.
Um, it was, it was pretty great to be part of the celebrations, but a 20-year-old company, we've got a brand to protect and it's gonna take some budget dollars in order to do that. So it's, um, it, it is incumbent upon me to be able to explain why we need to spend some budget dollars on certain things, but I myself have, uh, kind of grown up in, in the world of trying to be as careful to spend budget dollars as possible. So that kind of precedes, um, precedes me and, and talking about the way that I want to craft my budget.
So I'm not coming in trying to ask for a whole bunch of bells and whistles where those might not be important. There are fundamentals that I wanna spend my budget dollars on. And so kind of punctuating on things that are really important, I think kind of gets people, people's ears and they understand the concept of protecting our brand and making sure that our employees understand the importance of that is really a good place to start.
Sounds like one of the most important skills you can have is the ability to simply communicate exactly what's going on in a way that folks who are not security experts can understand. If that's the case, what else is on your list? What else are you looking at here for helping people navigate these issues?
Yeah, so, so you know, the, the common theme here for me, wherever I've been, but definitely here at Barracuda would say, here you are at Barracuda. I've been at so many different types of companies. This is my first time working at a cybersecurity company.
Um, I've, I spent my year working in media. I've worked, uh, for the NBA, I've worked at luxury retail, you know, just really kind of banning, um, all kinds of industries and wherever I go, it doesn't matter what type of company I'm in. Employee training is something that is incredibly important.
So ensuring that we spend our budget dollars on employee training is, is something that I wanna make sure that we do. Um, that can happen in all kinds of ways. I like to use the multi-pronged approach to make sure that we engage our employees so they understand the importance of protecting our brand.
Um, sometimes it's the smallest little wave that they can be astute and understand the, the importance that they play in making sure that they behave in a way that, um, keeps us safe and sound. So, you know, they need to understand the products that we sell and that we, uh, engage with our customers so that they kind of get the point of, okay, we, we need to be acting a certain way when we're reading our email and make sure not to click on certain links and, um, make sure not to do certain things when we're kind of operating in our day-to-day activities. Um, and, and ensuring that we, uh, engage with employees regularly to remind them is super important.
So that is, uh, that's a big area for me to make sure it's not a very expensive part of the budget, but employee training can be done, as I said, a multi-pronged approach. Um, and, and that's something that I take very seriously. So that's, uh, that's certainly one area.
Well, Are it, and security people under more stress than ever. It seems like there's been some folks who are being threatened with, uh, even jail time. But I guess is the question to me is part of the job is getting to the point where do you feel like you can win?
Or is it just so stressful now that we're gonna see a lot of folks just saying, Hey, I can do something else for a living? It definitely is more stressful now than I've ever seen it before. Um, I saw cybersecurity emerge as an industry long ago, and, uh, it had become increasingly more important through the years.
Obviously, uh, there are corporations like Barracuda that, uh, you know, base our entire enterprise on ensuring that companies stay safe and secure. It is. Um, but, you know, it is my responsibility to ensure that we stay safe and secure.
And it's something that certainly keeps me up at night. It is, it is a little bit stressful, but making sure that you take into consideration all of the areas of your responsibility and remit, and you do all the things that you possibly can to the best of your ability is, uh, you know, what kind of keeps you in check. So are people leaving the industry because it feels stressful?
I'm not seeing that. I'm seeing people enter the industry because it is, uh, it is such a strong place to be. Um, I'm seeing, uh, a lot of women enter the industry because there are so many opportunities and it is still an incredibly exciting place to be, even though it's very stressful.
What's your take on ai? Is this gonna save us from ourselves, or is this the root of our undoing? Uh, that is such a good question.
It is something that I talk about almost every day, and it's, um, and, and in fact, I was talking about it with, uh, with one of our team members yesterday. Um, is it gonna make us smarter or not as smart? That that's a, something that I'm wondering and your question, is it gonna be our undoing or is it gonna make us better?
It really depends on how we want to approach it and how we wanna incorporate it. In our day-to-Day lives, I think there's an importance that, uh, you know, our own governmental structures need to take. And, and in terms of, um, kind of providing some guidance in the way that we, uh, consume AI and the, and the way that we incorporate it into our enterprises, um, and, and daily lives, um, we, we definitely need to make sure that we are careful about its use.
Um, that, you know, I definitely wanna make sure that we are not, uh, overusing it and that we're, uh, we're engaging in with it in a way that it can be helpful and not harmful. Uh, and that's a, that is a daily pursuit because, uh, ai, um, depending on who is offering it, um, you know, depending on, um, the way that you wanna consume it, it could be very, very helpful, but it can also sort of take over things. And, um, and you, you definitely want to make sure that you set up the boundaries that are appropriate.
Is it your sense that the bad guys are indeed getting smarter and more sophisticated, or is it really more just a question of the attack surface keeps expanding and it's beyond our capabilities to defend, but the attacks themselves aren't really changing all that much? I think it's, it's both. But the, the attacks are definitely changing.
They're, they're different every day. So the attack surface becomes larger with every passing second. And that's simply because, uh, one of the things that makes it larger is that data is tremendous.
The amount of data that we collect and consume becomes bigger with every passing second on a, you know, a multiple of a scale. So that's an attack surface that just grows over time, exponentially. Then there's the amount of technology there, amount of point solutions, and there's the internet of things and all of that together, and I'm leaving a bunch of things out, but that's an attack surface that grows every, every passing moment.
So that's getting bigger. Definitely the cyber, uh, bad guys are also learning more creative ways of engaging with humans and with ai, using AI to break through the boundaries of people's lives, whether it's their personal lives or whether it's the confines of an enterprise. But definitely it's both.
It's, uh, you know, they're not using the, the same, you know, your, uh, the same types of, um, you know, attacks of, of yesteryear. They're being more creative with every passing day. And, you know, like one thing I wanna say is it's getting to be that time of year when it's the holidays, it's, it's gonna be as tax season soon.
Everybody, uh, you know, all the bad guys are using every, every tool in their toolkit and then some to try to take advantage of us. Um, and we've all gotta be super duper vi vigilant because we don't know the next way that they're gonna try to infiltrate or the next, uh, you know, creative maneuver that they're going to to make on us. But we've got to keep ahead of that curve to the best we possibly can.
I think there's no shortage of, uh, issues in terms of technology, but there's also a lot of cultural issues that seem to be at work where the security team is trying to get the IT operations team to handle more tasks. We wanna deputize the development community so they take on more responsibility. What's your best advice for getting all these folks to kind of play nice with each other and kind of work together?
'cause it seems sometimes they're not even speaking the same language. Do you work here, Mike? How do you know these folks?
Uh, that is, that seems to be the age old. Um, I don't wanna call it a problem, but I wanna call it an opportunity because that's the way I like to look at it. So let's start with the, uh, kind of the faith off between the cybersecurity information security team and an it.
Let's start there. Uh, because, you know, the cybersecurity team is often not the ones with the, the, they're not the ones with the remote hands. They're not the ones who are putting their hands on the infrastructure and on the systems to make the changes.
They're, they're relying on the technology and the IT teams to be doing that. They're the ones who are relying on IT teams to be, um, you know, acting on all of the patch management and staying on, uh, you know, on top of all of those things and putting in place all of the new, uh, tools and bells and whistles and all of this stuff that they wanna put in place to keep us safe and sound. How does that happen?
How do they stay, uh, connected? It is, um, it's important that they feel like they're part of the same team. And what I've noticed is when they don't feel connected, when they feel like there is an adversarial kind of, um, at environment, that that's when it doesn't work out that well.
There has to be some sort of common goal that everybody feels like they're achieving. And it seems like that is just, uh, you know, an easy thing to say, but it's really important that it comes from, uh, the leadership level and kind of filters down to everybody around us because it's not just the information security team and ip, it's the entire environment that has to be kind of, um, you know, closely connected to make sure that we are all working together on being good stewards of cybersecurity. So I have to be good about making sure I don't click on bad links on in my email, and I have to make sure that the IT team is doing the best job they can to, uh, you know, push all the patches and make sure they're tested and to ensure that all of our endpoints are protected.
Um, and that the cyber team understands the, you know, maybe the challenges, uh, that the IT team has with the amount of, uh, people that they have or resources that they have to do the work that needs to be done. And if everybody stays in communication with each other and they have an understanding for the work that needs to be done, and there is kind of the prevailing kindness that needs to happen kind of on a day-to-day basis, then I feel like that's pretty helpful. One of the things we also hear everybody talking about is the skill shortage in cybersecurity.
And I just have to ask the question, is there something to be done about that or do we just have to find ways to cope? And, you know, it's just one of those kind of suck it up buttercup modes. So there is definitely a lot to be done in terms of, um, you know, skill shortage and there, uh, we, we as leaders have to stay on top of that because we're not going to, um, you know, wanna completely replace our teams all the time because there are new skills that need to be obtained.
You know, we need to make sure that we keep, uh, upleveling our own teams. It's important that training is part of our budget. Talk about, uh, you know, a budget line item training for not only for our employees to be, you know, good stewards of, uh, you know, operating in an environment, but we need to have really solid training programs for our information security teams, for engineering teams, and for our IT teams.
We've gotta make sure that we uplevel their, their skills. We have to re-skill them. We have to make sure that we have cross training programs so that people in IT understand the skills that are needed in information security.
And maybe not, maybe they're not getting to the depth of an information security analyst, but they need to understand kind of at a high level what's required there. Um, other things that need to happen is we've gotta kind of keep our eye on competitive salaries as, you know, somebody who needs to make sure that we keep our com our employees engaged, we wanna make sure that we're paying them well, um, that we're, you know, constantly engaging with them. And there's also the matter of partnerships that we can maintain with some of the vendors that we use.
So there's a way of kind of having cross pollination with information they can get with some of our vendors, uh, you know, because we wanna keep them here. We've got excellent employees that are interested in learning and, uh, you know, it's important for us to keep them engaged. And so yes, skills can be a shortage, but we as leaders can help that through education and, and, and leveling people up.
All right, folks, you heard it here. We spend a lot of time worrying about what the bad guys are doing and that's helpful and interesting, but there's a lot we can do on our own just to make life a lot easier and more secure if we're all concerned. We just need to focus what limited resources we have on the right things at the right time.
Reen, thanks for being on the show. Thank you so much for having me, Mike. I've really enjoyed it.
All right, back to you guys in the studio.