Quod Orbis’s Gary Penolver on Simplifying Cybersecurity Risks
Quod Orbis CTO Gary Penolver dives into how cybersecurity teams need to frame risks in a way that both CIOs and CFOs can comprehend.
Transcript
This is Techron tv. Hey guys, thanks for the throw. We're here with Gary Pender, who's CTO for Quad Orbis, and we're talking about, um, how to get the budget kind of justified.
There's a lot of pressure these days on cybersecurity costs, and yet the threats keep rising, so we're kind of in a rock and a hard place. So Gary's gonna walk us through how to maybe have those conversations. Gary, welcome to show.
Thanks for having me. And, uh, good to chat. I, How do security folks kind of have a conversation about ROI?
Because in a lot of cases we're still trying to improve the proverbial negative, right? So it's something didn't happen, but we spent money, but how do we know what that cost? And we have to explain that to CIOs and CFOs who are asking these questions about, are we any more or less secure than we were?
But it's hard to quantify. So how do we get there? That's quite a big question, but yeah, it's, um, it's, it is exactly what you said.
It's that, yeah, there's, there's an element of, um, uh, justifying that spent, um, which I think, you know, a lot of organizations really struggle with, um, front, understandably, because if you're doing a good job, then how do you know if it's just by pure luck or, or by, by the volume of what you've spent? Um, I think kind of interestingly, you know, in that setting, what we've seen in the last, um, 18 months or so is, you know, with a slight economic downturn, um, actually, you know, even CFOs being a bit more, um, challenging in terms of, um, you know, some of the spend that, that, that goes on in this area. I mean, you know, sort of pre, pre 18 months ago, I think it would've been a brave CFO that would've challenged the spend on cyber, but actually certain to see a lot more, a lot more challenging in that space.
And I think it's, it's kind of a combination of they're more savvy, um, um, in terms of, um, uh, uh, challenging, but equally the, the, um, the fact that it, they, they have gotta justify the spend as well. Um, and it, and it, and it is hard to put that number on. Um, and I think, you know, part of the problem is that CIOs CISOs aren't always that great at kinda explaining some of, uh, the reasons why they wanna do certain things.
Um, yeah, they kind of very much focus on the technical aspects versus the, you know, the, the tangible business aspects of that thing. So it's, it is a challenge definitely, It feels like to me as well that, um, we've been spending money on cybersecurity platforms and tools for years now, and spending more doesn't always equate to better. So as part of this exercise to figure out how to maybe rationalize some of the stuff that we have out there to spend less, but be better, So recalibrate.
Yeah, no, I, I, I'd agree with that sentiment. I think, I forget what the stat is, but I think it's something like most, most organiz, most enterprises have got between 20 and 30 security tools, um, something in that kind of region. And that's, that is a lot of spend, right, as you say.
And that is, that isn't necessarily helping in a lot of cases. I think if you look at, if you look at not all, but a lot of large breaches, a lot of the kinda stuff that makes it to the press, um, it's actually not doing the basics properly. Um, so if you look at, you know, good sort of good hygiene, you look at the United Health, um, um, incident that I think affected, I understand a lot of Americans, the majority of Americans in some, some fashion over the last few months, um, that was down to lack of multifactor authentication just on a, on a, on a system.
Um, so it's again, sort of those basics that, that everybody knows what they are, um, aren't always focused on. You organizations don't necessarily, um, have the, the visibility and assurance of those basic controls. They're kind of focused on the shiny new tech that claims it can solve, solve everything.
I think, I think that is, there is a recalibration that needs to happen in that respect. I'd agree. Speaking of shiny new tech, we have AI everywhere.
Is this gonna force that recalibration because there's just a lot of things that will be automated, there'll be things that we couldn't do before. So is this kind of one of those seminal moments? It's obviously very cool and buzzy, you know, AI at the moment and, uh, agreed.
It's, um, and I think, you know, there's a lot of products that are throwing AI against the problem and hoping some of it sticks, and clearly some of it will, right? You know, some of it's gonna stick. Um, the trouble is, is that it'll probably, you, you'll probably get some of the lands on both sides of the coin in the sense of, you know, both attackers and defenders can, can leverage some of that ai.
You know, if you, if you look at kind of phishing for example, um, you know, obviously one of the things that most people are told to look out for in regards to phishing is, um, the tone, the language, you know, spelling mistakes, et cetera, et cetera. Well, you know, just running these, you know, what, what should our attackers do these days? Running them through a, you know, a chat GPT or similar actually results in some pretty decent English sounding and convi more convincing sounding, uh, phishing emails.
So it kind of works, it works in both sides, unfortunately. But yes, it should help sort of that, that kind of speed of response aspect and um, uh, you know, that kind of, uh, meantime to detect meantime to, to, to, to, to respond, et cetera. But, but equally it's gonna help the attackers too.
Mm-Hmm. Well, speaking of helping the attackers, it feels like we're trying to have a conversation about being smarter with the budget at a time when the attacks themselves, as you pointed out, are increasing in both sophistication and for that matter volume. So sometimes I feel like we're always kind of evaluating our spending against, you know, yesterday's war instead of tomorrow's war.
Yeah, yeah, I think so. I think, um, and as you touched upon right at the very beginning, I think sort of a lot of organizations struggle to defend those budgets. So they, I think was, you know, what, what probably doesn't help in, in some respects is, um, the lack of really solid information out there for a lot of enterprises to be able to help benchmark themselves in terms of are we spending too little too much, you know, for our industry?
Um, I think that doesn't help in terms of some of that justification of why, you know, that the, you know, where you started at the very beginning, really the kind of CIO um, uh, CFO kind of conversations. Um, but you're absolutely right. You know, so much of the security space is selling on that, that futures that kind of, you know, the, the, the, the, the a PT, the adv, advanced persistent threat, kind of the, the, you know, the, the nation state, well nation states are going to attack lots of organizations clearly.
But, um, as I keep coming back to it's, those, doing those basics properly, I think is what, what a lot of organizations struggle to do. Um, um, and if they just focused on those, I think actually they would have a, a much better chance of, of, um, securing themselves against, you know, 90% of the tax act. We have, uh, been dealing with this shortage of cybersecurity expertise for as long as anybody can remember, and it seems like we're pushing more responsibility for security operations over to the IT team.
We're deputizing developers making them more responsible. Um, is that working or is there a new demarcation between who's responsible for certain tasks versus others? What we're certainly seeing in, in, in our space is, is people adopting more automation.
Um, so even quite simple automation in terms of, you know, collecting, um, uh, um, control information. So, you know, if you think of the examples you gave their own security operations teams, et cetera, they're, they're being, they've got responsibilities to ensure that they operate first line controls for things like, um, have we got antivirus on all of our, on all our desktops, you know, quite a key control, for example. Um, and they, they, they've got to, uh, you know, keep on top of that in first instance, but equally demonstrate that kind of assurance piece to, to the wider organization.
And equally, again, that kind of upwards reporting, um, that helps justify why we're spending on certain areas and why we need, you know, some, um, uh, you know, additional drive to try and, you know, increase our coverage, for example, um, of, of security controls. Um, so there's a bigger burden on them to, to deliver those kind of things. But automation really does help, you know, to kind of get that kind of a visibility in the first place and reduce that manual burden of some of those responsibilities so that those kind of people that you mentioned can actually focus on the more rewarding pe the your work for themselves, actually the, the real risks that they're servicing rather than the, you know, are we covered type questions?
How should security people be talking to the CFO and the ccio o because for years they were talking about, well, we need to have a seat at the C level and the board, and we need to talk to these people. And now many of them got in there and are surprised to discover that nobody knows what they're talking about. So how do we have that conversation?
I think, I think in most cases there's, it's a combination of, um, education for, for the board, um, and helping them understand the, you know, the macro level, um, aspects of it. Um, and equally the, the, the CISOs and CIOs to be less technical in terms of the way they talk about some of these problems and the, the, you know, the, the challenges they face, the things that need to be the remediated. I think it's the combination of those two things that I think are, that are, um, that need to be addressed, you know, that need to be worked on In general, do you think that maybe our security spending is still somewhat misaligned?
And I'm asking the question because security people will allocate budget to things that they control, and since they have more control over the network edge, you'll see a lot more firewalls. And yet, application security has always been something of the redheaded stepchild because the security team thought the development team was doing something about it, then the development team thought the security people were doing something about it, and nobody allocated anything for anything. Um, so are we just kind of fundamentally misaligned?
I think there's, there's probably an aspect of that, and obviously movements like DevOps and DevSecOps have tried to address some of those, some of those aspects. Um, but yeah, I think it's a, it's quite a common problem that, that, um, that the organizations have faced is that, that, as you said, that demarcation, that kind of, who's responsible for which part? Um, and I think the push to the cloud, obviously, you know, that kind of agility, that kind of, you know, that kind of DevOps mentality of re release faster, you know, um, um, and trying to automate those checks and balances along the way, I think again, starts to address some of those.
But that doesn't, doesn't apply to all industries, obviously. It doesn't apply to all, all scenarios. Do you think we'll ever start talking about security at the front of the conversation instead of chasing after what's ever happened?
'cause it seems like every morning somebody walks in and the attack surface has expanded yet again because somebody did some cool and interesting new thing without actually thinking through what the security implications are. Yeah, I mean, it's, it's an interesting one, isn't it, because you've got, you've got, um, again, uh, that's probably sound like a broken record, but again, all those new and cool things that come out, they're quite often similar kind of methods of attack that's kind of similar kind of things that are happening. And again, if those, you know, basic hygienes being done properly, um, and you get some good visibility of it, I think that really does help to address, you know, address a lot of those, even the new things that come out.
Um, um, you know, um, tools are always, so techniques are always adapting, but the tools and the, the defense mechanisms will always be catching up to, um, I just think the, the meth, the, you know, the approaches that people take, you know, they need to focus on that kind of, that, that, the, the good hygiene piece as I mentioned. What's your best advice then, as security folks? Because, you know, it's always amazed me is given the challenges they faced, they are by and large eternal optimists, they always think that somehow or other there's gonna be a different outcome, and yet contrary to all the evidence, they still believe.
So, um, is that just the nature of the person required for this job, or is there something else at work here That's an ask? You've, you've obviously spoken to different security people to me than, you know, a lot of 'em are. Lot of 'em are definitely pessimists.
I think, uh, they're definitely glass half, half empty, but, but, um, it is, I think it is in the nature, isn't it. I think you, you, you know, the, the kind of that kind of constantly playing catch up trying to, to defend against things is, is in the nature of the job, unfortunately. You know, it's, um, and it probably does take a certain type of mentality to do that, and you're absolutely right.
So, um, there's a lot of burnout in the security space, obviously, and the high levels of turnover. Is there something to be done about that, or is that just the nature of the beast? I think I, again, there's, there's been some interesting trends.
Again, I think in terms of, um, you know, the kind of economic downturn as I mentioned over the last 18 months, which has probably, um, de powered a lot of CISOs in a lot of ways. So some of that decision making about the spend and things like that, that we mentioned, it's kind of taken away from them because as I say, the budget's just just cut. Um, and, um, I think that that in itself probably puts quite a large amount of additional pressure than they're already facing on, on top of those, those types of, um, you know, the defenders, the people that are trying to look after the organization.
Um, so yeah, I think there is, um, there is, there is a lot of that in the, in the industry. Um, but um, in terms of what can be done about it, I think it's, uh, I think it's sort of, um, again, I think it's the nature of the job, I think, isn't it? You know, it's, um, you know, there's obviously certain things that can be done from a, from a wellbeing perspective, but I think unfortunately there is a lot of pressure that goes with defending and, uh, and, and being on the back foot probably a lot of the time, This is a nascent trend, but it seems like at least I'm seeing a lot more newly appointed CIOs who used to be the ciso.
And so are we bringing these two things together? Yeah, it's interesting, isn't it, how, um, you know, sort of the shift in the, in the kind of, in that kind of exec and, uh, c-suite, um, area. Um, and as I mentioned before, you know, I think the, even the CFO is becoming a lot more savvy in a lot of organizations to, um, some of the spend, um, and the justification that goes with some of these things on, on security tools in particular, and it spend.
Um, so I think that is, there is a general, um, uh, uplift going on in terms of the education and the kind of the awareness within, within that, well, that space. I haven't seen that many CISOs become CIOs personally. Um, um, but um, I'm sure it happens.
Yeah. So you were now granted one wish for cybersecurity. You can just magically transform things overnight.
What's that one thing that you would do that kind of, would make everybody's life of just that much more tenable? Um, well, selfishly, obviously, I think yeah, in terms of what, what we, what we do in this space in terms of how people to look at, um, making sure that, that the things they thought they had in place from a controls perspective, and when we say controls, we mean, you know, anything that might be there for, um, uh, compliance, but equally might be there for, um, you know, protecting against ransomware or, or something like this. Um, some, some sort of key control, making sure that those are in what you think is in place, stays in place and actually, you know, is, is continually performing the way that you want it to be, including those basic hygiene controls that we mentioned.
So again, taking, you know, automating as much of that as possible and helping organizations to, to say focus on the more, the more value piece, the more interesting parts, parts of their job, or actually what comes out of all this, what are the risks that we need to actually address? I think that's the, that's, that's the magic wand they've got. I'd love to, to help people to work on more meaningful stuff, um, and actually have confidence that the basics are being done properly and when they're not, be alerted to them straight away so they can actually fix them rather than finding out when they've been breached or as such.
All right, folks. Well, it doesn't look like things are gonna get any easier anytime soon, but, so maybe just maybe the most important attribute of all is plain old fortitude. Hey, Gary, thanks for being on the show.
Yeah, well, thanks for your time. All right, We're speaking And back to you guys in the studio.