Safeguarding Critical Infrastructure with Benny Czarny
Benny Czarny, founder & CEO of OPSWAT, addresses the alarming surge in critical infrastructure cyberattacks and shares his perspective on 2025 cybersecurity trends. Benny provides actionable strategies to safeguard critical systems against escalating threats and offers a forward-looking view on protecting infrastructure from emerging risks.
Transcript
This is Techstrong tv. Hey everyone, welcome back here to another techron TV interview. You know, my next guest is, is someone in, he doesn't get enough credit, quite frankly, in the security world for what he's done.
I first met Benny Zaney Sarney probably 2019 years ago. He was starting a company called Ops Swat. Then, uh, he's still there.
He's still the CEO. He's, he's the treasurer. He's great to have on here.
Let me introduce you, Benny Sarney. Benny, how are you? It's good to have you here on Techron.
It is so great to be here in Ellen, and so great to see you again, and I am, uh, very excited to be here. Thanks for the opportunity. Absolutely, man.
I don't mean to embarrass you or anything, but give people a sense of your journey, right? How did you come to, in essence, put ops SWAT together, found it, and what have you been doing with it over the last 20 years? So, I found Ox Oxford 20 years ago.
So my, the, the, my first big idea was to create a cybersecurity language like we speak right now. So, so imagine that you have cybersecurity product that can communicate with each other. So A VPN can communicate with an antivirus, with encryption software and so on.
And that was the first product called Oasis. Really successful. Initially, we were an OEM company and we, OEM, that language to many companies such as Cisco, Palo Alto Networks, hp, you name it, uh, with, and it, it, it got really great momentum with more than a hundred million, uh, installation.
However, as we build the language, we found out something really interesting about the cybersecurity field, which was that as we tested integration with Antiviruses, we learned that antiviruses were actually built in two different modes. One is protect the device. So this is what the original intent and number two is.
So there are two operational mode for an antivirus, and lots of folks in the industry confuse the efficacy of anti mauer and ai, anti mauer about the ability to protect the device and ability to predict whether a file is malicious or not. And so the second big aha moment for us is that, again, we tried to research threats and threats flying into organizations, a threat point organization, and we found out that a lot of them are originated based on the data. So whether it's a data channel flowing into the organization and file, upload, file download, email flow, MFT flow, um, A USB.
And so the second big idea for the company was to create the firewall of data to create a way to capture all of the data flow to and from an organization. And so we did, and the original idea to do that was to create a multi scanner to harness all of the anti Mars out there. So CrowdStrike and Sophos and e set and everybody all together.
So more than 30 on the data flow. And we released that and it was really successful. And really quickly, we moved from an OEM company into an enterprise company.
However, although we put more than 30 different antivirus engines on the data flow, still various smartware sneak through. So we tried to put a sandbox, we tried to put all kinds of technologies still, we failed to provide the absolute prevention that we expected. And then came the third big idea, which was to regenerate the data to and from an organization.
So we invented the technology called CDR or deep CDR, like we call, like you call it. So we regenerate the data flow. So for example, Ellen, the email you sent me is actually, we end up dumping it, creating a new email, look exactly like the original email, just without the bad stuff.
And then that's, that took really well. And then five years ago, we, we, we looked at our customer landscape and so on, and we decided to position the company for critical infrastructure protection. And the reason for that is that critical infrastructure are the organization that can, can, can really, uh, cannot really afford to have a single threat.
You can't really afford to have a power outage. You can't have, you need your, your ATM operating, you need the manufacturing to flow to fly. So, and we pivoted to that.
And then since then, we even further enhanced our platform, not only to have a firewall of data, we extend the platform to more than 20 products. Uh, all, all available on our website, the full platform for that. That is not only, uh, capturing the data, we expand to endpoint, to network access control, to, uh, we expand that, uh, into, uh, access to network visibility to provide the holistic solution for critical infrastructure route, not to protect only data flow, to have various, uh, various aspects of cyber to critical.
Um, so for that, we have the platform. Uh, we have, uh, more than, uh, 10 different pur purposely built technologies such as the CDR, the mood scanning, DLP sandboxing. That is, especially for that.
And also, uh, uh, four years ago we founded the OP Oxford Academy. Op Oxford Academy is an online training. We have more than 400,000 certified students there that are, that the, the whole origin of the academy was to, is to train cybersecurity and IT professionals to, uh, to protect critical infrastructure out there.
Um, so we grew to have nearly 2000 customers. We have close to 1000 employees. We operate in more than 80 countries.
Actually. We, we, uh, we have office in less than that. However, we, we, we support more than 80 countries critical infrastructure.
And this number is growing. Um, and yeah, we take a lot of pride is what we do. So it's a very kinda interesting journey.
So since we met my, my, I, I feel like my position changed a lot. So it's a different to manage a 20 peer organization to 200 to near, near to, uh, close to a thousand or so. Absolutely.
And you know what, Benny, it's a testament to you and your vision for what's needed out there in security. Congratulations to you. And that, that's a great story.
Just real quickly, the ops SWAT website, what's the website? com. Do com.
You got it. Absolutely. Okay.
com. What a great story. And I said it in the beginning, right?
This is a amazing story of world of security cyber. Now we call it cyber. 20 years ago we called it security, um, InfoSec.
But let, let's talk now about our topic of discussion today, Benny, and that is around credit critical infrastructure threats. And, you know, it's the end of the year. We're all kind of naval gazing, looking at what the year ahead holds.
And so what do we see in 2025 cybersecurity trends and even, you know, specifically around, uh, critical infrastructure. Talk to us a little bit. Yeah.
So we see actually, uh, various threats happen in others. So the, the so hackers now, it's much easier to write mware now, why? Because, uh, the usage of generative ai, it's so much easier.
So for example, if you're trying to automate a phishing script or you are trying to, uh, create a payload, it's much easier. It's very easy. I can do a different live session with you to demonstrate how we can use multiple generative ai, including, uh, bypassing their protection to speed up malware creation.
Uh, and that's actually emphasizing, uh, common threats we had, or we had in 2024 just accelerating their creation. So whenever we see, uh, any, any attack on regular data channels that, uh, we, we see that more such as file upload organization, we still see, um, uh, uh, pretty much increasing attacks if we see email flow, if we see, um, a supply chain flow. So, uh, at least the leveraging of AI among the healthcare and he community is just speeding up.
And, and also, uh, we, we see more flows in defense and we expect to see more flows in defense. Um, the, a part of the, uh, uh, critical infrastructure we see, and we saw that, uh, in, uh, previous years is the significance on, uh, leveraging cybersecurity companies as a attack vector. Again, we've seen that in the past with FireEye.
We've seen it in the past with, uh, solar wind. It can happen to anybody. Nobody's immune here.
Uh, however, the leveraging and leveraging cybersecurity products to penetrate organization, um, we see at least, uh, and we see that by plus because we see an increase in terms of vulnerabilities in our own cybersecurity companies dis disclosed. And also we, we, we talk to others. We have various cybersecurity companies that actually became our customers because they find their manufacturing as critical.
Um, so these are kind of a couple of things that I think we can, uh, touch on. The third one is in terms of a trend that I see is, uh, a regulation compliant regulated compliance. And, and, and the, the, the compliance, the, the way I see, um, a compliance is that I think there's a lot of hacks are taking advantage of fraud compliance and will continue to take advantage of fraud compliance.
So if you, for example, read the New York 6 0 0 7, or the lack of definition within the compliance mandates is actually opening a can of form of cybersecurity attack, and we start seeing some of them. For example, uh, the regulator may not, I identify, uh, the specific configuration of cybersecurity products on a spec or specific certification. Uh, so, and, and Heckers are well aware that sometimes organizations are just checking the box on the compliance versus doing it right.
And by doing that same inventing uh, uh, critical infrastructure specifically, Uh, absolutely. Um, you know, I, I agree with you. The, the AI thing is a game changer right now.
The, the good news is there's a double sort to the ai as much as the bad guys are going to use it, we, we get to use it too, and a little fighting fire with fire. And at, at some point you hope that this sorta cancels it out, right? But certainly we're seeing, we're seeing better phishing attacks, we're seeing better done malware, right?
It's a, a terrific tool for them. You know, Benny, but we're seeing some other trends, I think pop up for 20 25, 1 of which is, uh, the, the, the whole thing around data security. I, I don't know if this has come up on your radar, but, you know, for a long time it seems like we were very focused on AppSec now with data security, the whole zero trust kind of paradigm of way of looking at things.
Um, we're, we're moving stuff to the cloud, but at the same time, we're moving to the cloud, we're moving to the edge, and we're doing anything from anywhere, right? All like, do you think the mission's gotten is getting harder? Are we getting better at it?
Are we, 'cause that's something a lot of executives and enterprises are asking. I've been spending a lot of money on cyber for 10 plus years. Are we any safer now?
Are we any more secure? Are we going to get better? What do you think?
I think the biggest change that we have for CISOs that are very much kind of influence by brands, so it's like you're going to a fashion show, right? Oh, I'm gonna get a Gucci mm-hmm. Or what I'm gonna go and get, right?
Oh, I'm gonna go and buy the, the, the product from the company with the biggest booth. Why? Because looks like they spend a lot of money.
So if they spend a lot of money on that, they must have a good product, right? So yeah. Then there is also a lot of kind of thing around the ai, oh, they've looks like they were really, okay, so let's say this company, company A has a better AI in company BY because they have a nicer booth.
I mean, what, what are the measurements that were really kind of what, what really drives our decision on budget span, right? Is that the brand or is that the pitch, or is that, unfortunately, I think it is Now. I think we're moving to that where they, they want one big company controlling the whole thing, right?
And, and, and that's, that's, that, that's, from my perspective, that's gonna be a disaster. Why? Because kind of if you control the per and control the brands and what did you do?
So I haven't seen enough CISOs and I meet with a lot of CISOs really looking at cybersecurity reports, like from cybersecurity testing companies such as ev comparatives a test, uh, se, uh, uh, SE labs, it's the all companies, the whole purpose would is to test the efficacy of cybersecurity products. This is how decision needs to be made. Now, specifically, I do believe that there is a lack of adoption of CDR content design and reconstruction among the industry, because this is, I would say one of the best ROI and I can support formulas for that.
The best ROI in cybersecurity is to use and implement CDR content in some, this is by preventing data not based on detection, is pretty much by prevention, by regeneration is very much the future. And again, think about it, you block all executable to touch your organization and all of the data flow to your organization is gonna be regenerated. What does it mean?
It mean that, again, all of the five flow, whether it's, whether it's video files, images, documents, PDFs, AutoCAD files, all of the life is gonna be regenerated. By doing that, you immediately, you eliminate a, a huge variety of AI based attacks. So why?
Because you're regenerating the data. So you, you are not investing in AI detection. You are, you're investing in regeneration.
That is very, very hard for any AI or anything else to, to consider penetrating, because again, it's like everything is eliminated and structured. So, uh, to its structure, it's kind of to, to the beats, to the beats and bytes, to a point that, uh, um, and the, the, so, so my call to action for, you know, for 2025 and, and for for years to come, is to accelerate the adoption of that. At least we have seen customers adapting that.
We've seen not only, uh, effectiveness in terms of less breaches. We've seen also that attackers actually, there was also a decrease in the global attack on that specific organization. The change with CDR is that it's a mindset, it's psychology mindset.
So, uh, because think about that, I'm, I'm gonna tell the ciso, oh, I'm gonna change up the chat to 56 of all of the fly rot organization. I mean, I'm gonna go and change the document. So that's, that's a big kind of undertaking because some folks will be kind of most respectable to why, why should they do that?
I don't want to change the files. I'm gonna lose usability. I'm gonna lose.
No, you are not gonna lose usability. Just you're eliminating threats. Uh, it's gonna be very hard for you to go to your CEO and say, Hey, this is the amount of threats we detected because everything is eliminated, though, the good news, you will not have breaches.
So, so anyways, back to the trends. I see that adoption of CDR, we see that kinda growing. We have actually, uh, uh, over 70% of our customers adopting it.
Uh, although it's a model within the really product. And, uh, we see this percentage keep increasing and increasing. Um, and, and I think the trend about KANA data and CDR is all about the data.
We touch data. So I don't want to touch that. So the trend about regenerating data, I think is very, very key.
Agreed. Excellent. We're just about outta time, but I got 1, 1, 1 other question I wanted to ask you if we could keep it in just a couple minutes.
As we look at 2025, much like 2024, the world's in a crazy place. We've got war in Europe, we've got war in the Middle East. Got a new administration here in the US that's threatening all kinds of tariffs and trade wars with China.
And, and, you know, there's the axis of evil with Iran and North Korea and, and all of these things. And critical infrastructure is right in the cross hair, right in the bullseye. What is 2025?
What can we do to, to really, you know, because it's one thing to attack critical infrastructure for financial gain, right? You want a ransomware or something, you want to get paid, whatever, but I, to me, the bigger threat is nation state warfare by, you know, not by guns and rockets, but by steber. What do you think, Benny?
I I, I, I do agree by, by the way, I think both are kinda, um, so, uh, everything is relevant and, uh, so we are in cybersecurity and discussion about cybersecurity. So let's kind of stay focused on, on that, on that point. Uh, though I am, uh, I, I, I've gone, I've, so first I second that because we see attacks on critical infrastructure now we see with the war in Ukraine and also in the Middle East, a lot of cyber attacks, uh, on, on, uh, multiple cyber attacks.
And some of them actually got, uh, uh, very successful. Um, so my kind of point in terms of, uh, for any critical, any CSO managing critical infrastructure, and my tips to this person would be, number one, segregate your network. Don't rely on firewall to do that.
Use a data diod, use their, their diode or unit Russian gateway. The difference between their diode and new Russian gateway, their diodes can, can physically prove data is working from one area to another, using fiber optics to do that. So you don't use a regular firewall, use it optical firewall, uh, use it their iio.
So this is my, my, and definitely segregate your network and add this discipline within your organization to segregate this network. So all of the critical assets, just put it in an error gap. Don't trust anything.
Trust no file, trust, no firewall. Okay. So that's kind of there.
Mm-hmm. Number two is create a process to regenerate the data that you're planning to use in your critical network. If you do these two things, you are immediately eliminating a lot of many, many attack vectors.
And, uh, and number three, try to do it really well. Don't try to check the box. Take a certified data, take a a, a high quality, uh, data security platform that will be able to give you the, the assurance that, that the data is, is, is flowing from point A to point B in an extremely secure way.
So that will be my kind of my my, my three tips to anybody. I Think it's great. Great advice.
I think it's perfect. Benny, we're out of time. Hey, thank you for coming on.
Have a happy, happy New Year, great holiday season. Let's make sure we don't wait too long to have you back here on text Drunk tv. Okay.
Right. Thank you, Ellen. We, we Good to see you.
Happy holidays and Happy New Year. Absolutely. com.
O-P-S-W-A-T, check it out. Benny Sarney here on Text Drunk tv. We're gonna take a break.
We'll be back with more text Drunk TV in a moment.