Utilizing Offensive Security Tools – Tom Eston, Bishop Fox/Shared Security Podcast
Transcript
This is Techstrong tv. Hey everyone, welcome back to techstrong tv. I'm real excited to introduce you to our next guest.
He's Tom Eston. Tom is the VP of Consulting and Cosmos Delivery at Bishop Fox. Tom is also the founder and co-host of the Shared Security podcast.
Hey, Tom, how are you? Welcome to Textron tv. I'm great, Alan.
Thanks for having me quite Enough. My pleasure. It's, uh, no, it's not an honor.
It's, but thank you, uh, anyway. Hey, Tom, you know what, let's start a little bit. I, I gave people your titles and stuff, but give people a flavor of the Tom story and your journey.
Yeah, sure. Um, so I have been in the industry for well over 18 years now. Um, I've, I kind of grew up in the industry, the, the early cybersecurity industry, or as it used to be known as the info information security industry.
Mm-hmm. Um, so I've done everything from, from, uh, working on logs to network administration. Uh, I was a pen tester for a very long time.
And then, uh, I was presented with, uh, that ultimate question that a lot of us that are, uh, tech savvy get is, Hey, do you wanna be a manager? Do you wanna lead people? You're kind of good at that.
Uh, yep. And, uh, I decided that, uh, I'm gonna make a little bit of a career change and jump into management and leadership. And, uh, it's, uh, I've been doing that, uh, now for today's probably well over 12 years or so now.
So, uh, it's been a great experience. Uh, always a challenge, uh, managing leading people, but I love it. Uh, and it's been great.
And then while I've been doing all of that, I've also, uh, been running the podcast, uh, which is the Shared Security Podcast. We've been doing that for about 14 years now. So, uh, I'm in that small group of almost original, I guess, security podcasters.
I, I guess I, I just talked to Paul Aian from Security Weekly, and we kind of shared some more stories. com. Yeah.
Yes, those guys. So, uh, it's been great. So Cool stuff.
Um, yeah. You know, it brings me back to, I, I, I started blogging and podcasting in 2003, 2004, and just started Security Bloggers Network way back then. And, uh, we used to do the security bloggers awards, which I hope to, whenever RSA comes back where there's like restaurants and bars around Moscone again, and we can make a real get together.
I'd like to do the bloggers awards and podcast awards again. But, um, you know, Paul was a kid then, right? This is what, 15 Yeah.
Almost 20 years ago. I know. com hack naked and all that stuff.
Yeah. And, uh, wow. That vex some memories.
Oh, yes. Anyway, Tom Bishop Fox, it's a name. Yeah.
You know, I'm familiar with, I, I'll be honest, I'm most familiar with it because our friend Kevin Kosh Yes. Kevin Kosh and Kevin Kosh is for those, you know, kind of one of the ultimate insiders in the security world. Yes.
Right. Connecting people and nice Rolodex, longtime PR person. Um, but I, I've had the pleasure of intro of interviewing now several of the Bishop Fox folks, including ceo, and I mean, it's a great story.
It's kind of James Bondish and, and everything else. Yes. But, um, for those out here who aren't familiar, why don't you give 'em a little Bishop Fox background?
Sure. Yeah. Bishop Fox is, uh, we are a leading offensive security organization.
So we provide, uh, security consulting and offensive security services for, for many, uh, large and small, uh, organizations across the world. Uh, we're a global organization, so we have a presence in Europe. We have a large presence in Mexico as well, um, which is a little bit unique for, uh, an American based cybersecurity company.
Um, we also, um, have an attack surface management product, which is called Cosmos. Um, and so I run the delivery organization for Bishop Fox, which is both consulting and the cosmos side of the business. Um, and so yeah, we're, we've been around, uh, well over, uh, 12, 13 years now.
Um, still going strong and, uh, we do a lot of things, uh, especially around the security community itself. So we're very big on, uh, contributing back to the community through open source tooling. Um, you may have seen the recent news where we did a whole post about a discovery we had in the fort, uh, SSL v PN vulnerabilities.
So, uh, that was all us, uh, contributing that valuable information back to the community. And, uh, and yeah, so that's a little bit about Bishop Fox and what we do. Just before we jump in, uh, to what we want to talk about, people want to get more information on Bishop Fox, the website.
Yep. com could find everything there. All right.
So you guys recently worked on a survey as well, some research and survey and analysis. Why don't, if you don't mind, share with the audience? Yeah, sure.
So, uh, we did a, uh, really the, the first of its kind survey with, uh, the Mann Institute, um, who's obviously well known for, uh, conducting various types of surveys in the technology space. Um, so they partnered with us to do a survey on offensive security and specifically offensive security testing and how practitioners are purchasing offensive security, um, how they are implementing offensive security testing in their organization, and what types of offensive security testing are they conducting. So it was really that first of a kind survey, um, around offensive security.
What it is, um, it's obviously grown even further than what traditional penetration testing is. I mean, it's kind of its own category now. When we talk about security testing, it encompasses all types of security testing.
So everything from red teaming to purple teaming to your app pen testing, um, all of those types of things now encompass that offensive security space. So this survey, um, we, we asked, uh, it was about 660 some, um, IT security, uh, practitioners. Um, and one of the things that we found interesting about this survey was, uh, we were really going after organizations that have certain maturity level of, uh, security program.
So, uh, for example, uh, the majority, I think it was like 39% of the survey, uh, said that they were fully mature organizations, um, meaning they have very robust security programs in place, uh, established security policies, procedures, those types of things. Uh, and so it was really good to get their insights, I think, into, um, how they use offensive security in these large, um, and, and global organizations. Excellent, man.
Very cool. Um, you know what, just, just as a point of fact, so I found out we're based down here in South Florida. Larry Pony man.
Yeah, he's actually right here as well. Oh, Really? Oh, Wow.
And we're not, this isn't a hotbed of of tech insecurity, though. It's getting better than it was. Yeah.
But the fact, I mean, he's like right here, and it, it kind of blew my mind that there's actually, you know, more than one. Um, whoop, I think I lost my AirPod there, but hold on. So Tom, let's talk about the survey results.
Yeah. So what would, what do you think, yeah, I always ask people what are the top three takeaways from this that our audience should be aware of? Yeah, I think the first one is around, uh, you know, what are the reasons that organizations are investing in, uh, offensive security testing?
And the number one response that came back was adoption of new technologies. So, uh, there is a constant, uh, change right? In organizations that need to find this new technology.
Um, I, I go back to kind of the pandemic, right? When we saw a lot of organizations move their entire infrastructures up to the cloud. And by doing that, there was all types of new technologies that were introduced into the organization.
And I think that was a, a area that, you know, people had a lot of concerns with. You know, now that we're moving people all remote, there's things that we have to address from a security perspective that I think a lot of organizations haven't had to deal with before. I think it's kind of ironic now that we see a lot of organizations moving back to the office.
And I think now that presents a whole lot other set of challenges as well, um, with other technologies that will have to be tested as well. Um, so, you know, that's a big concern, um, with organizations. Um, the other one I'd say too is, um, you know, organizations are constantly looking for how do I get ahead of zero days vulnerabilities that I don't know about?
And offensive security testing is, is one big way to do that. Um, and specifically out of the survey, we found that red teaming in particular is the most popular method that's being used in offensive security testing with these mature and well-established organizations. Um, red team in particular is interesting because a lot of people will say, well, I just wanna get a red team.
I wanna find everything out I can about how vulnerable we are as an organization. But red teaming is really reserved, and it should be reserved for those organizations that are at a certain maturity level that can handle honestly the results that you would get from an engagement where we're literally going after, you know, we we're simulating things of a nation state attacker as an example, or doing ransomware type of testing. Things that are really complicated.
And for a lot of organizations that don't have the proper security controls or the per procedures or processes in place, they're gonna be overwhelmed by the results of a red team. And so a red team is really reserved, and I tell people all the time, for mature organizations, you may not need a red team. You may wanna take a step back and do more traditional external internal network pen testing as an example, or get your applications tested before you jump into a red team.
So from the survey, it was very interesting to see those results that more mature organizations are using red teaming while more or the less mature organizations are doing more of that traditional kind of offensive security testing. Really interesting, cool stuff there. Um, I always like to ask people, Tom, what surprised you about this survey?
Any surprises in there? Um, so the top three threats that really drive investment in, uh, offensive security testing, uh, number one was ransomware. Um, just squeaked by at 41%, which was followed by, uh, social engineering at 40%.
So really what's surprising to me is ransomware is still top of mind for organizations. It's still a large and major problem. We've seen some things shift recently, like with, uh, the move it vulnerability.
They're, yeah, you know, they're kind of leveraging aspects of RAN ransomware and how malware is being delivered, but, um, it doesn't get like the media attention anymore that it kind of used to be, uh, or used to. So organizations are still very concerned about that. And then social engineering, right?
We, we talk a lot about this all the time. I mean, this is, uh, the area in terms of phishing and, um, text-based, uh, types of scams and other things that we see, uh, that these attackers are going after. Um, they're, you know, executives are very concerned about that.
So we're seeing a lot of that at Bishop Fox too, where red teams are, were being asked to do phishing simulations more, uh, attack simulations using the human elements because, um, this is how attackers are still getting in. So, um, and then the third was cloud vulnerabilities, um, is a huge concern and drives that investment in offensive security as well. No surprise there with everything that is in the cloud.
Um, and companies have such a huge presence in aws, uh, and, and the other organizations that, uh, host cloud, uh, it, it's just no surprise that those would be the, the top areas of focus. Absolutely. Tom, for people who maybe want to dive a little deeper, get the whole report, you know, read it at their leisure, what's their best bet to go get it?
Yep. com and there'll be a link right at the top of the page where you can, uh, you can, uh, download the full report. Um, I also did a webinar with Larry, um, a couple weeks ago, which you can also, uh, check that out as well.
Larry had a lot of great insights as well in terms of how the survey was conducted. Um, Larry's a great guy. Um, he's, uh, extremely knowledgeable in this space.
Probably one of the, one of the best, uh, in terms of survey and research, uh, data, um, that I've met in my career. So I definitely encourage people to check out that webinar if you're interested in more of the details. Very cool.
Tom, I want to thank you for coming on today, giving us a little bit of your story, Bishop Fox, and sharing some of the results from this survey with us. com. But for now, hey man.
Thanks. Say hello to all our friends at Bishop Fox. Hopefully we'll have you back on soon.
Sounds great. Thank you, Alan. All right, we'll be back in a moment here on Techstrong tv.
Stay, stay tuned. A lot more coming.