Securing the Summer Olympics with ePlus’s Lee Waskevich
Lee Waskevich, vice president of security for ePlus, dives into the challenges cybersecurity teams trying to protect the Summer Olympics will face, as the volume of cyberattacks steadily increases.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Lee Wa Keech, who's vice president of security for e plus, and we're talking about the Olympics and what's happening from a cybersecurity perspective because, well, it's a big event, gets a lot of attention and not all of it's good.
Hey, Lee, welcome to the show. Hey, good to be here. Thank you very much.
Looking forward to speaking about it, We have seen these big events become targets of all kinds of miscreants, including all the cybersecurity criminals that are out there. But is there something different about this Olympics coming up that people should be paying more attention to? Is the attack surface different?
Are the tactics and techniques evolving? What's going on? My friend?
Yeah, so I'd say nothing specific to this actual event, but I think as we've seen attacks, uh, continue to evolve over the years, I, I read a recent stat just today, um, that there were, in the 2021 Tokyo Olympics, there were about 450 million potential attacks that were happening, and they're expecting this year to be about eightfold to that. So because of the nature and the way that these attacks are, are launched, um, it, it spurs on that increase in the, the amount of attacks that, that are available. I think, I think what we're seeing is that because it's such a high profile event, a lot of people are drawn in by the media attention, both obviously over, over the air, but also, uh, now interactively through various means on the internet and, and email and, and chat rooms and other things, uh, that people are using to communicate about the event that's happening.
And this is a gold mine for attackers because they're able to then get in, leverage their techniques, um, to be able to, to, to spoof various email addresses, to be able to impersonate, uh, different people in different organizations and use that, uh, to gather people's credentials or to, to trick them into giving away, um, access to specific accounts. And, and that's quite serious. Do you think that the folks who are running the Olympics are prepared?
Do they understand the scope of that threat and 'cause it seems like just from four years ago, it's a extraordinary increase in the number of potential attacks? Yeah, I, I think they're definitely, uh, aware of the seriousness that this poses and they engage with, with various technology companies and, and firms to help shore up their specific security, uh, architecture, their defenses that, that are put in place. So I know, uh, Cisco systems has been one that's been involved over the years.
Um, they're also look at things relative to, uh, denial of service types attacks, right? Because, because this is a lifestyle event, um, when there's denial of service, uh, attacks that do take place, this disrupts, uh, the broadcast, the streaming and other means of, of interactivity, uh, with the event, which causes, you know, frustration on the end user parts. And oftentimes sometimes we see, uh, cyber criminals in other organizations using distributed denial of service attacks to be a, to be kind of a, a mask or a, a, a distraction from what they're actually trying to accomplish.
So it really serves two purposes for them. But to your question and your point, I think yes, they, they recognize a seriousness and they leverage, uh, both their own, uh, technologies, tech, uh, and architectures as well as partnering out with various firms to help shore up their defenses and making sure that they're taking into account the latest threats that are out there. Not too long ago, we used to talk about increasing the cost of launching an attack and trying to make it more expensive, and maybe hopefully the attacker will go somewhere else based on the volume of attacks we're seeing.
It almost feels to me like the cost of launching attack must be nearing zero because there's so many of these attacks that are out there. So, um, you know, are the bad guys just gonna overwhelm us? Um, I think relative to the cost of the attack, um, a lot of it before had to be, these attacks had to be manually created, right?
And, and that took a lot of time and effort on the cyber criminals or the malicious actors' part. I think what we're seeing today is because of the advent of, of artificial intelligence and other tool sets that can help rapidly create code, automate the delivery of these types of, of, of malicious packages, it, it's a lot lower barrier to entry. So it's, uh, these effects, these, uh, attacks are often less sophisticated, uh, but they're also more widely distributed.
So at that point, you know, anyone with a, with a credit card or means of access to, uh, to, to, to, to spin these up and buy these are able to launch them. We've seen the rise of as a service platforms for launching these types of attacks. Um, are the people who are launching the attacks, you know, are they really professional cyber criminals or are they just kinda folks that have somehow other stumbled into this and they're using a credit card and launching these attacks, but they're not, you know, the hardcore cyber criminals that we've known in the past?
I, I think there's always an element of the cyber criminal gangs and other nation states that are putting together the, the majority of these platforms. But the accessibility, again, in the lower cost as, as you referred to this, makes it enticing for those that are trying to more or less dabble in this. Um, you see challenges coming in from, uh, from, from the economy and things like that, and people see the money that that presents itself within cybersecurity.
I saw another stat recently, it, it might have been on the, the world economic foreign site on the, the cost of cyber crime and how that's increasing. It's at, uh, three and a half trillion today, but rising to about 8 trillion over the next four years. So people see that amount of money and that amount of potential, they feel many times that because of the anonymity that presents itself with the types of attacks that they're protected, and the, again, the accessibility becomes key for those that are not necessarily hardened criminal criminals to, to dabble in this space.
It kind of reminds me, or sounds like street crime, right? All the people hanging out on the edges of the corner block there, they're not the major wheeler dealers of the crime ring and you'll never see those people. And it seems like the hardcore folks have found a way to insulate themselves, but maybe a lot of, for lack of a better phrase, amateurs, I i, is that how we're seeing this kind of play out?
Yeah, there's definitely levels that you see from, from an ins installation standpoint. Again, anonymity is key here. So whether it's, it's the back channel communication, leveraging the dark web, whether it's the, the use of of cryptocurrency to help, to help hiding in transactions.
Um, and then those obviously also too that are a bit younger and have grown up on technology and have ease of access and, and a lot of time on their hands. So many times we see more juveniles and, and young adults, uh, getting involved in this because their friend did it, it was successful, it was quick and easy money, and they don't believe that there's a, you know, a strong, um, a strong result from, from ever being caught. Are we winning and losing?
And, and I'm asking this question because it seems like the number of attacks has exponentially increased and there's probably more breaches as a result, but the ratio of attacks to breaches, is that changing or, you know, are we staying even with that? Because sometimes I feel like we're losing and yet I can see that there's so many more attacks, so maybe we're winning. I don't know.
Um, I would say the ratio is, has stayed a bit the same or even a bit lower due to the exponential amount and growth of attacks versus what's actually successful. Um, a lot of times the, again, because of the accessibility and the unsophisticated nature of some of these attacks, organizations that have taken the proper steps to secure their environments or, or leverage consulting like we offer at e plus to help set up, uh, and secure their overall security posture, they're in a better position where even as these attacks are launched, they're basically, you know, think of it as a, in, in medieval times of having shields and the attacks kind of bouncing off the shields, right? It's, it's that same type of approach where if the technologies are, are Laird in properly configured properly, they're able to withstand even the exponential growth of the types of attacks because of the, the lack of sophistication of this volume.
Um, so it speaks really to the importance of cyber within organizations and how they're placing a critical role on maturing their security defenses, getting a strong security foundation, and then making sure that they've upgraded their defenses to deal with these, these more modern style attacks. We've been talking about the chronic shortage of security expertise for as long as I can remember. Is that becoming less of a factor?
'cause we're relying more on automation and is that helping us even the odds a little bit? And for that matter, is AI gonna take that to the next level? Um, it's definitely assisting organizations that have strong processes in play that can rely on some of the automation techniques within AI to shore up their defenses and their security operations program.
I think we're still gonna, we're still gonna have a consistent need for security professionals because we need those individuals who have the experience in the security sector to be able to help train these models to be able to generate the, the manual playbooks and processes, as I mentioned, that the tools use. Um, it also then can free the, the individuals up from not spending as long being, uh, you know, tier one, tier two analyst, but they can progress in their career paths and their abilities to help in the company to, to be more resilient overall. Maybe that's a movement in the over to the governance risk and compliance sector.
Maybe that's a move over into more advanced integration type work. Those pieces are still a very manual and a very, uh, resource intensive process. But I think the a leaving the, the, uh, just the, the event, uh, fatigue that we've seen over the years in security operations, AI and automation has a great potential there for us.
Has the conversation fully moved over to a lot more focus on cyber resilience? It's the assumption maybe that I am gonna see some type of breach, but I should not reach to the point where I can no longer operate in. Is that kind of the level of maturity that we're finally getting to?
Yeah, I think cyber resilience has been a strong theme now for probably this past one to two years across, across our space and our segment in general. Um, you know, we, we see that that companies are starting to place a lot more emphasis on what I call basic and foundational cyber hygiene, which is inclusive of inventory, vulnerability management, um, and then the way the, the process and the, uh, the tools to detect modern threats, but we can't let fall by the wayside the, the aspects around response and recovery. So with an e plus and, and what we approach it from a, our program around compromise nothing, it's really about putting in those core fundamentals and then it's making sure we can help to build them a strong recovery, uh, and response platform and even testing that on behalf of the customer through tabletop exercises and others.
So that from a resiliency standpoint, yes, when something does get in, when something does get passed, uh, the investments that have been made, it's not a business, uh, outage situation, and it's something that's more quickly recoverable without having to pay ransom as we've seen many, uh, organizations having to do over the past year. We've been talking about this as well for a while, but there's a, a balance that seems that people are trying to figure out is to what degree do I need to hire my own security professionals and have those on staff versus relying on an external service provider who may be a specialist in that. Is there, you know, a perfect number there?
I mean, is it shifting what's going on there? Um, I would say that it, there's no perfect formula when it, when it comes to that shift and that blend, a lot of it has to do with the, the identified risk to the organization. So many times when we're going in, in a security consultancy type engagement, we're helping the organization to number one, identify the risks that cyber poses to the business and what does that mean from a a dollars and cents perspective to their bottom line.
And then based on that, that helps, uh, them to justify the investments required, um, to help in protecting their organization even from, uh, uh, whether they do it in-house or whether they outsource that component. So organizations that maybe have less intellectual property or, or PII information or something that is, is, uh, critical to business operations, they may tend to, to outsource those components to areas where it's not under their direct control. So what we often do is, is work with customers, number one, to get that risk clearly identified.
Um, and as we can then quantify that to business value, translate that to what budgets can look like and where outsourcing makes sense versus, uh, building in-house teams to, to support that going forward. We often see much more in the, especially in like the financial sector, where internal security operations teams are definitely something that they make and invest in, but, but in other segments, in other business verticals, um, we see them leveraging security out, out tasking and outsourcing as part of their overall program, because that's what makes sense based on the risk identified. Does that calculus change when I have an event like the Olympics, or for that matter, a political convention or I'm launching a new product, do we need to think about how we scale security resources as the events that we're trying to launch online or in person adjust and 'cause the Olympics, the committee exists all the time, but the Olympics only come around every four years, Right, exactly.
It's definitely something to keep an eye on. Sometimes we look at it where organizations have specific events that are relevant just to their organization. A new product launch, a new software, a new, a new branch, or a new, a new headquarter, something like that, which could trigger changes in the environment.
These more macro style events like the Olympics and, and other larger, uh, both na, you know, regional, national, global type events, you know, those would, at that time, they would put the organization on maybe higher alerts to be critical of, of spear phishing emails and other types of attacks that could associate with that. Every year, for example, around the holidays, most many organizations beef up their security awareness training for, for their, their staffs and users, because at that time, people are more susceptible to clicking on things and more fraud tends to take place. So seasonality, large events, all of those pieces, you know, definitely heighten the awareness within the security, uh, the security team within an organization.
And along with that, they take then the necessary steps to help making sure their employees, partners, customers, et cetera, may be more vigilant, uh, around the potential for, uh, for bad actors and for, uh, for breaches at that time. So what's your best advice to folks? And the converse of that is, you know, what do you see people doing today that still makes you shake your head and go, we need to be better than that?
Um, the best advice, I, I still am very, am very keen on, on the fundamentals. So many people get kind of starstruck with some of the, the new latest security technologies that are out there. Um, but without the fundamentals in place, those are oftentimes money that's, that's often misspent.
So having, having strong foundations within your security program, again, inventory from hardware and software, vulnerability management, building on that with identity access control, things like that, those are all key things, um, that can help just make you more resilient overall. Um, and then how that extends out in your organization with permeating a culture of cybersecurity. So that's where sometimes you mentioned the shake your head moment, you know, organizations that maybe are lax at helping their users to understand that everyone has a role to play when it comes to cyber.
If you have access to electronic device, if you have a company email or, or access to a specific application, you are a part of that cybersecurity chain and the better prepared that you are, even if, if it, and, and, and cyber is not your role to understand and recognize when something is, is not right. That's something that, that helps organizations overall. So again, as we many times are consulting with organizations, we're helping them to stand up these programs, test these programs, making sure that it's constantly at a maturing level.
Um, and that's really the best thing that you can do. We're always going to see this because we're, we're such an interconnected world. So whether it's business email compromise, or stolen credentials or phishing, phishing, you know, text, uh, text phishing, all the things that come along with that, the more that we can be more astute and aware, uh, of what's, what's not real is going to help everyone in the long run.
All right, folks. Well, you heard it here. They don't give out gold medals for cybersecurity at the Olympics, but hey, maybe they Do, unfortunately not.
All right, Lee, thanks for being on the show. All right. Appreciate it, Michael.
Take care. Thank you. All Right.
All right. And back to you guys in the studio.