Team8’s 2024 CISO Village Survey Report with Ross Young
Ross Young, CISO in Residence at Team8, discusses the key findings of Team8’s 2024 CISO Village Survey Report, providing valuable perspectives on navigating the evolving cybersecurity landscape in the age of AI.
Transcript
This is Textron tv. Hey everyone, it's Alan Shimmel here for Textron tv. Again, I'm really happy to have my next guest on.
It's the first time he's been on with us, but he's no straight injury to the security world. Hi, his name is Ross Young. I'm sorry.
His name is Ross Young. And, and Ross is, um, CSO in residence at Team Eight. And we're gonna find out all about Team eight in a little bit.
But let's find out first a little bit about Ross Young. Hey Ross, how are you? Thanks for joining us.
I know you got up ungodly early out there, but you, you're used to it anyway you said, right? Yeah, it's a pleasure to meet you. My name's Ross Young.
I'm currently the CISO in residence at Team Eight. Prior to doing this role, I was the CISO at Caterpillar Financial for four years, and I spent over a decade at CIA, uh, having fun breaking into places and securing our national interests Absolutely so offensive as well as defensive security over, over there. Yeah, I did five years on the offensive side and I also had fun running the DevOps organization as well.
Oh, very cool. They're very, very, uh, apropos to our audience. Ross, besides that, you, you've done some work with Oasp as well?
That's right. Uh, so I created this framework called the Oasp Threat and Safeguard Matrix, which I open source, you can just Google search and find it. Essentially, it's a framework where anybody can start to put a list of threats on one side of the matrix and use the nist, uh, cybersecurity functions to see how to identify, protect, detect, respond, and recover on those.
And then there's also some really cool things of how do you do threat modeling, how do you do, uh, report cards and metrics and things that can really help improve cyber programs. Very cool. So Ross, as I mentioned, uh, when you first came on, you're the CISO in residence over at Team eight.
And, um, we're gonna get into what a CISO in residence is exactly in a moment. But first, let's start with Team eight. Yeah.
So Team eight is this very emerging innovative venture capital company. Uh, particularly what we do is we take investments from a lot of the Fortune 500 companies and we invest in the next generations of startups and FinTech and cyber and DevOps and all different types of emerging tech sectors. Uh, I'll just focus on cyber today.
So imagine my role is I meet with hundreds of CISOs and I talk to them, what's working well? What's not working well? What tools do you wish existed that hadn't been invented?
And then we take all that guidance and then we also go to other security fairs, RSAs, the black hats, and we see all the vendors of the latest tax, uh, stacks that are coming out. And we combine that into our model and we basically say, here's some gaps in the op in the market space that we think need to be addressed. Maybe it's better AI security, maybe it's improving data loss prevention, whatever it is.
We take all of those ideas, then we kind of prioritize and rank those and we go back to our community of CISOs that we've created and we say, here are three ideas we're thinking about. Would these help you? How should we tweak these ideas so that they better help you?
And things like that. Until eventually we say, we're going to form a company that does this problem. We're gonna partner with some early design partners so that we can make sure we're solving the right product market fit, and then we help those portfolio companies become successful.
So that's the teammate in a nutshell of what we do. It's a really cool place because emerging tech, great communities with CISOs and DevOp leaders and professionals, and then bringing back content to help our CISOs, uh, advocate be influenced by the latest technology and make a difference to make their lives easier. So, so this is a little less accurate than the usual VC sort of formula, which is, Hey, I have money and I wait for a founder group, you know, founders to come to me with a cool idea.
And based upon my knowledge of the market, I I, you know, I make a bet whether or not that really is a cool idea and that's a company we wanna invest in here. You first go to market, determine need, and then pull in, I guess from your community and contacts the people to, to satisfy that need in the market who are gonna build their company and product or service that fills that niche in the market. So Yeah, that's exactly right.
It's that product market fit. It's that design partnership and just getting that understanding is what we're going to build going to be successful. If not, let's abandon it and find out one that will be Absolutely.
I I guess the key to that is having a pool of, you know, potential founders if you wanna call them, or founding teams or, or talent, right? Both engineering business, the whole thing that you can kind of build these companies based upon their, the need that you identify in the market. Yeah, that's part of our other piece that we have.
All of our founders are basically former Israeli 8,200 members. Uh, probably the most famous is Nadav. Uh, he was the head of 8,200.
So we have a large, uh, relationship with a lot of those people coming out of the Israeli NSA who are very skilled, very technical, and very proficient. And, and those people become, you know, the early founders, uh, in our models. We also, uh, have American founders as well, but we take that so that we can get really good smart people along with an active audience of CSO villagers who want to engage and build that partnership of technology that's gonna help our customers.
And, you know, not to get too far down in the weeds, but about how many companies have you guys, you know, started like this and, and funded? Yeah, so, uh, I would say we're in the dozen sub 100 companies. You know, we've been at this, uh, for, for over 10 years.
And, and in this time we've actually had a lot of very successful companies. Probably the most known in the cyber space is a company called Clarity. They're one of the biggest OT security companies.
That was one that we founded and we built, uh, from the ground up. Uh, and so lots of, uh, companies have gone through this. Uh, at any point in time, there's about 10 to 12 different cybersecurity companies that were, uh, let's say in in our portfolio and actively helping grow.
And do you have an incubator accelerator or, you know, once you put the teams together and you just kind of let them do their thing? Absolutely. We, we do have the incubator model.
A couple of the things that we do that are unique with Team eight, uh, the first thing is we have a CISO summit. Uh, and so we bring together a hundred plus, uh, very, very large c uh, enterprise CISOs. So think of CISOs from Walmart and other big places like that all meeting together.
And at that time, uh, once a year, we're meeting with them, we're talking to them, we're presenting late edge, cutting edge talent, and we're also connecting them with our portfolio companies so they can see the emerging tech that we're building out. Another thing that we also do is, uh, really help with the design partnership. A lot of CISOs, as they get towards the later end part of their careers, they really want to fix what's broken, right?
They want to be in an advisory role. And so we help, you know, bridge that gap where they can not just complain about the tools and and, but actually start to fix them by helping some of our young founders see their perspective, see where the current capabilities in the marketplace are lacking. And so those are some of the things we do.
We really help our companies get to successful a RR in the millions of dollars. And and that's really what we do. That's different than just, let's call it dumb money from angel investors that, you know, it comes from a doctor or a lawyer, but they can't really help you with your business plan, with your marketing, with your, you know, CISO engagement, things like that.
And the nice thing about this model is you guys are in real early, right? Almost at that angel stage before traditional vc, you know, a round kinda stuff a B round. And, and so you, you do have a, an outsized role in the, in the formation of these companies.
All great stuff. Fascinating. And I, you know, I, I've heard of of team April before, but I don't think I've ever actually spoken to someone from there who explained the model to me.
It's a great model. I don't want to take all that. We probably took too much time on that already.
Uh, 'cause I wanted to turn, you guys recently did a survey of CISOs. You know, you mentioned you speak to many, many CISOs. Why don't you give us a little, you know, uh, high level on that we can dive in from there.
Yeah. So as part of our community, we're always looking to curate really good content to help our CISOs, including surveys from our village. So we did something called the 2024 CISOs survey report, where we started asking our, our CISOs a lot of different questions.
Like, Hey, what's happening with your budgets? Are they going up? Are they going down?
What do you see as the new emerging types of attacks that you're worried about? And where do you see yourself really wanting to improve the tooling in the space? So those are some of the questions we really start to look at and, and get answers and insights from our CISOs so that we can help all the CISOs out there.
So you don't have to be a member of our village to receive the report. You can go on teammate's website and just, uh, search and download the, the CISO report. But it's something that's can really help a lot of CISOs.
Absolutely. Um, so let's, how many years, I'm sorry, how many years are you doing, is this the first one or you've been doing this a while? You know, I'm not sure how many years it's been in existence.
I, I would say at least multiple. I know this is certainly not the first year we've done it. Fair enough.
Um, how long have you been with teammate, by the way, Ross? I'm a short timer. I actually started in June.
Prior to that I was the CISO at Caterpillar Financial. So a lot of it was how do I take the lessons learned as a CISO and take into a role where I can influence and help, you know, the whole industry. Got it.
Then let's, that's a great gig too. So, let, let's talk a little bit about this year's survey and report, though. You know, there's always key findings.
There's always at least two or three major things that you want people to take out of it. For you, what were the key findings in this report? So, the first thing that I would say is in 2023 and 2024, that's really when we started seeing the emergence of sophisticated phishing attacks, incorporating deep fakes.
And so you think of this example of, Hey, I can clone somebody's voice. I can clone somebody's video. I can actually do a live zoom meeting and make my face look just like the chief financial officer and try to trick somebody else in the company to wire money the wrong way.
So we, we saw a lot of insights around that. And really CISOs are saying that's one of our biggest threats we have to worry about. I mean, the, the Singapore bank with the fake zoom deep fake, uh, guy, uh, I forgot how many millions of dollars they wired.
I mean, that's an extreme case, but I will tell you, just garden variety phishing has gotten so much better with these people using ai. You know, a lot of the, just the quality of these phishing emails have gotten really believable. Where even then I've been, you, you know, in security.
And I check my mails pretty good. I'm pretty, you know, I look at editors, I look at everything. But it used to be so easy to spot the language and, and, you know, what was written or some things, I mean, there's, there's a lot of really good phish people who aren't up on it are gonna be fooled.
Yeah, you're, you're absolutely right. If you were to rewind maybe 10 years ago, you would have a Nigerian, you know, email scam and you could almost find very simple typos. And other weird in that text was they're, they're not native English speakers in, in a lot of the areas, but now they take that same spam, phishing scam email, and they say, chat, GPT make it catchy, make it, you know, viral or whatever.
And now it's spits it out and better English than I can write. And so that ability to spot scams by reading for inaccuracies or grammar, uh, let's say inaccuracies as well is, is long gone, right? We're really going to have to say, who sent this email?
Do I have things like D Kim and other email protections saying, this came from a legitimate source, or is this something that's bad? You, you don't even need to read the message. 'cause that can be perfect these days.
It really can. It's scary, scary stuff. Um, yeah, I think I'm for, you know, we, we discuss this a lot here at Tech Trunk AI's a double-edged sword.
The bad guys can use it just as well, or sometimes better than we can. And, and we we're going to need to kind of build our defense strategies with that in mind, right? What, what they're doing.
Ross, you know, with every survey I've ever been involved in, there's always one thing that's sort of counterintuitive or, man, I didn't see that coming. Was there anything in this survey that kind of jumped out at you saying, well, that, that was surprising? I think the biggest thing that really stuck out to me is just how broken third party risk management is as an industry.
Basically, we're all filling out forms lying to each other about how good our security programs are. Because if we don't, then from there, we're not gonna get business. And, and I'm not saying that every person is a liar from every company, but we ask very vague questions in our questionnaires, and we expect absolute perfect security, which is impossible to do for any company.
And so, given those two things people are gonna put in, you know, here's the things that are good enough so that I can win a business proposal. And, and I think that is something that is really big in our industry that has to change. I'll, I'll be quite honest to say I don't have the magic, uh, let's call it future in my head, where I know exactly what that future solution looks like.
But it is something we are hearing time and time again from our CISOs. I'm worried about our third party risk. Third party has, you know, hundreds or thousands of vendors with my data that can lose it at any point in time.
And I have no idea what they're doing to really secure my data. You know, you're a hundred percent correct and, and I'll go one better. It's not just the data.
You mentioned DevOps and a couple times it's the whole software supply chain, right? Because our software is built, it's like cars, right? How, you know, you buy a Chevy, but how many, how much of the parts are actually made by Chevy?
Right? The over over overwhelming majority of those parts are made by third party manufacturers. Some domestic, some international, they're assembled by Chevy, let's say they're assembled by shopping.
Our software is the same way, right? 75, 80 5% of our software is made up of open source components or third party components, whether it be, uh, a containerized payload or a artifact or a JavaScript, you know, something. And the dependencies on these third parties, I mean the, you know, the list goes on and on.
You want to pick, you know, the SolarWinds, the the log J four or any other ones, and this is why the whole sbo, right? Yeah. The whole SBO thing and, and open source supply.
So it, it's not just third party providers to the companies themselves, to a particular company. It's the third party dependencies that are built right into our software that oftentimes or most recently have become the back doors for, you know, everything from nation state kind of, uh, events to garden variety, financial, you know, FETs. Um, and, and yeah, I think this is the bane of, of our existence.
I'll tell you something else though, Ross, and I'm interested in your opinion. I was out at the QUALIS security conference a couple weeks ago, and I know qua the folks at Qualis for a long, long time. And it, and for the first time in a long time at a security conference, I saw a shift in focus from how many vulnerabilities do I have?
How fast am I patching and remediation? How many intrusions do I see, right? To managing risk, right?
Risk management. When I first got into security 25, 30 years ago, security wasn't part of it very much. It was, it was part of risk, right?
And then over the years, compliance checkbox compliance, I call it least common denominator security, right? Checkbox. Check this, check that.
Yeah, I filled out the form, I'm good. Took over and security moved more into it. Sec.
And I'm not saying that's necessarily a bad thing, security needs to be in it, but we've, we've lost the art, if you will, of, of risk management. What's, you know, you mentioned it a little bit, but let's dive deeper. What's your thoughts on that?
I think we're seeing that, that maturity in our industry, you know, to, to your point at the beginning stages, it was, here's the number of vols on all of our systems from all of our scans. Yep. And we gotta remember that the role of the CISO and the senior leadership is to communicate risk up to the leadership team so they can make business informed decisions.
Exactly. Sometimes that means they're gonna rule against security because it's not profitable for the company. Sometimes they're gonna say, this is absolutely the right thing to follow.
So they get to make those decisions and we get to give them the wisdom to make informed decisions, right? And, and I think as we see that maturity, we're going to, you know, change the way we do things. You know, the chief finance officer doesn't really understand what 10,000 vulnerabilities means to the company, but if you tell them, Hey, remember when we identified the 10 business, the 10 business critical processes, and you said the ability to, you know, take an invoice from a customer is, is number one.
And you said, here's the two IT systems that you use to do that. And oh, by the way, these two IT systems have internet facing vulnerabilities that may make us take that system down. Now you can have a very informed risk decision in a way that they're gonna relate to versus some number of VULs that doesn't mean anything to them.
I'll go one further. I think job, the job of CSO of today and tomorrow is to go to that CFO and say, Mr. CFO, this billion dollar line of business, right?
One of many businesses within a large enterprise, this billion dollar line of business, you know, based upon our security stuff, we think there's a 20% chance, right? That we could have a serious incident here that would impact that billion dollar line of business severely. And we think by doing, you know, layout or not layout, we think we can do some remediation that'll cost X dollars.
That will reduce that risk from 20% to 10%, right? That's the kind of language CFOs understand, I got a billion dollar line of business, I've got a 20% risk factor there. I could cut that risk factor in half dollars and cents.
What's that worth to me? That's what the board wants to hear. That's what the CFOs want to hear you.
7 days or whatever. You know what I mean? Um, I hope I'd like to see the role of the CSO move in that direction.
I'd like to see us as an industry, you know, begin to move in that direction a little bit more, but at the same time, we, you know, security pros still have to focus on those 7,356 vulnerabilities, right? We gotta figure out, prioritize and, you know, do what we need to do, but we need to talk business to the business is Yeah. Is the point.
I think that's right. You know, we, we really have three audiences we have to speak to. The first is we have to speak to the worker bees, all the developers, to making sure they're implementing secure coding practices and fixing their VMs.
Then there's the, the second one, which is, let's call it the CIO and all of his or her direct reports, you know, those are the ones who are going to hold all the developers in those roles accountable. And so how do we show them how they're trending as an organization across applications and saying, is this okay? And then to your, to your former point of absolutely, we want to have a risk focused conversation to the executive leadership team that's tailored for them.
So really three different conversations with three different levels of technical specificity between them. And that's what makes being a CSO fun. Right.
Um, anyway, Ross, I promise you we'd only be 15 minutes and we're probably at 25 minutes. I apologize, but it's been a great conversation. People maybe who want to, is the report, uh, publicly available?
Can people download this or take a look at it online? Yeah, absolutely. If you just, uh, Google search team eight, you will see we have a CISO survey report for 2024.
Uh, it's a quick download. I think they just ask for your, your email address so that they can make sure that gets mailed to you. Uh, but it, it's, it's completely available online.
For anybody who's interested in learning more about what's happening in the cybersecurity community, what are the top security challenges? What are the year over year changes in budgets and how do we defend against AI and these new novel attacks that we're seeing? Absolutely.
vc, like venture capital. Okay. vc.
Very cool. Alright. Hey Ross, I hope I didn't bore you or keep you on here too long, but I appreciate you coming on and, and informing us a little bit.
Keep up the great work. Best of luck, your teammate. Come back and visit us.
Keep us, keep us posted. Of course. It's been my pleasure.
Thank you so much for your time. All right, Russ Young, team eight here on uh, tech Drug tv. We're gonna take a break.
We're gonna be back in a bit.