White House Cybersecurity Strategy: Achieving Resilience in our Digital World – Nicko van Someren, Absolute Software
Absolute Software CTO Nicko van Someren, Ph.D, discusses the latest trends out of Washington D.C., including the White House’s new push for greater accountability from security software vendors. Nicko delves into how this new government directive will impact the cybersecurity landscape and innovations organizations are adopting to ensure resilience against modern threats, helping them to meet challenges created by increasing regulatory pressures and demands for security accountability.
Transcript
This is texturing TV. Hey everyone, welcome back to techstrong TV. My next guest is Dr.
Nico van someran and I hope I did Justice to his name. Nico is the CTO for absolute software, Nico or Dr. Nico.
Welcome. Welcome to techstruck TV. It's a place to be here.
Thank you for having me. It's our pleasure. So.
Why don't we give away? I guess we'll start. Let's have a little background on Nick event summer in.
And we can go from there. Sure. I've been in the the security industry for nearly 30 years now having been in the the networking technology space and a variety by the places before that.
I got involved in Building cryptographic Systems back in the mid 90s building cryptographic human Management systems that led into a whole bunch of network security technology. So I found it a company in the UK called ensifer that built Hardware security modules. Chief security architect Juniper Networks.
Then I went to company called good technology who did mobile security I worked for the Linux Foundation as their CTO leading up projects to improve the security of Open Source software. I've worked in fintech and now I work for a company based in Canada called absolute software and absolute builds a platform of technologies that really around making security more manageable and more resilient for our customers. And when I say resilient, we find that when we are analyzed data from the tens of millions of devices that we manage we see a lot of security controls deployed with our customers.
You know, they'll have an antivirus tool sometimes too. They'll have some anti-malware. They'll have some encryption technology.
They might have some VPN or vpna technology and all of these tools get installed by it, but they often have no idea whether they're actually working, you know, they they get pushed out there and now you've got devices out in the field and especially in this hybrid work world that we have now where you know most users are probably not in the office anymore. They have very little view of how well these security controls are working and when they go out of compliance, they have they they don't have a good way to know that they're out of compliance and they certainly don't have a good way to fix it. So so we build a platform of Technologies, which allow you to have visibility of these endpoints control over them, but also automate some resilience of those endpoints so that you can better be more confident about whether the devices performing correctly from a security standpoint.
We also monitor a variety of Ip Centric information as well so that you can actually be confident that your your employees are working. Well when they're out in the field Love it. Fantastic, you know, Nico.
Just hearing you call it security and not cyber. Did my heart good because I think we're from an age where we it was in cyber. It was security.
Maybe you want to call it infosec. A lot of us came from the network space and and it's good. It's good to hear that.
So one thing we didn't mention for people who want to get more information on absolute software. What's the website? com.
And that's absolutely with an E. com so Nico, I I thought we would start off today. You know recently the the White House came out with this latest cyber security strategy.
And this look to give credit where credit is due. This has been a relatively active Administration in terms of cyber security. They you know, they they're leading with their with their chin so to speak and putting some You know platforms out there.
So this latest one, you know White House cybersecurity strategy achieving resilience. I wanted to you know, what do you think? Well, I I was very glad that they used the word resilience in there and strategy because it's a word that we've been using for a while.
I think the the one of the key things that people have talked about in this latest round of of executive orders is really about the the liability that that's being potentially placed on organizations. And I think that that's got a lot of press because it's got a lot of people worried, you know, the prospect of more liability for your organization never goes down. Well.
And I think it's important to understand where the administration seems to be coming from about this. There's been a number of breaches over the years where we can look at them and we say frankly that was just bad luck. That was you know, they did the right things and and you know the best laid plans of mice and men often go to Rye but then there's been a number of breaches where frankly you could have expected that this was gonna happen because the controls were not in place.
They were not monitored. They were not being diligent. So I'm I'm hopeful that the administration as they go from primary legislation into the regulation stage are going to be drawing that distinction and I think that if we read the actual narrative in the those releases that it's pretty clear that they're not trying to go after every breach and say you you had a breach therefore you're going to be in big trouble.
What they're trying to do is make sure that people do the right thing and if you don't do the right thing, you know, it's like if you don't maintain the brakes on your car and you crash into somebody then you're gonna be in trouble, but if you are if you're doing the right thing, you know speeding and you're not, you know running red lights, then you don't get in trouble. When you have an accident, you know, we clean up the mess we learn from it. That's one of the other areas which I'm really excited about in this this legislation is is Trying to really promote this concept of treating cyber incidents as learning experiences rather than just treating them as things that we should be ashamed of.
There is that tendency to sort of you know, people sweep it under the carpet because they're worried about what's going to happen. Whereas if you have an airplane accident the NTSB have a whole process for for a zero blame post-talk analysis of aircrafted accidents and we learn from it and this is why flying in a plane now is so much safer than it was 50 years ago. So I think that you know, the the area of you know liability we have to sort of understand that this is really coming from a you know, when you're another negligent.
There's going to be some liability when you're doing the right thing then we're going to try and make sure that we keep doing the right thing and we learn better what the right thing should be. Absolutely, you know a couple of thoughts in regard to that. com here and deaf secopsis something that's pretty important to us.
So in devops, there's this concept of what we call the blameless post mortem. Yeah, right. That's exactly what we need in security.
It's not about someone losing their job it, you know, yes stock prices can be impacted and valuations. I mean if you did something really wrong, but we need that concept of a blameless postmortem. Right to to figure out what went wrong and how do we improve because that's the only way you learn 10 times more from your mistakes than you do from doing it, right?
You at times really do and and I think that the the tendency to to say, well, you know, we're gonna try and you know hide our shame, you know. It's expected. You know, if a bank gets Rob we expect that it's value is going to go down because the whole bunch of money just left the building if you if you have a reach it's inevitable that there's going to be some negative consequence but the negative consequence needs to be proportionate to to the the Damage Done and we shouldn't really be looking at punitive damages unless there was genuine negligence and I think that if we can make we need to make sure that as this legislation proceeds that we draw a clear distinction there because I do think that there's attention between the whole sort of potential liability side and this idea of trying to get people to open up and be clear about when things went wrong.
Here's what actually went wrong because we can't learn if we don't have that openness. So I do this is one of the few things that worries about me worries me about this legislation is that there is a fundamental tension between those two sides. Well, I think we're complicates that to Nico is is look full confession.
I went to law school. I graduated right we live in a very litigious. Please don't I got I got out of that one thirty five forty years ago.
35 anyway We live in a litigious society and when we talk about negligent or negligent negligence is a reasonable this test. Did they do what a reasonable person we would expect a reasonable person to do and that leaves it to the discretion of a judge in a jury. And I think that's where you run into trouble quite frankly, right because you could form shop you can you know, who knows the who has a better lawyer?
Who's this that I almost wish there were there was some not arbitration Clause, but some Something that made it very cut and dry. Right, whether it was truly like was it gross negligent, which is a very high bar. Or was it just normal course of business stuff?
Right? And I think that kind of uncertainty is what hurts these things. Yeah, I I agree and I think that we we do need to have a lot of clarity about where the lion should be drawn and consistency to avoid that Forum Shopping.
I do think that as we go through this process we need to make sure that the the set of lines that are being drawn are being drawn by industry rather than bureaucrats because I I the pace of the pace of development inside bureaucracy and it's not just the US government. It happens all the way around the world and yeah government in general government in general. I mean, if you think the the US is slow, you know in Washington you should try Brussels and the European Union.
So so I do think that getting industry involved to Define what is what is reasonable and what is not and we certainly don't want, you know, the the fox policing the hen house but we do want to make sure that that people who are knowledgeable about the field are the ones who are setting these policies. So that and that's always been a thing. You know, look the EU though, at least the gdpr.
They have Dora coming out. There are some national red, you know, because this is just a executive order coming out of the White House. It's not Congress congressionally approved but there are some bipartisan bills and Congress right now around cyber and identity access and so forth, but you know historically we've always taken the approach of hey if we do a good job as an industry of policing ourselves, we won't need the bureaucracies to come in and police.
So it's because when they do, you know, too often it becomes the lowest common denominator type of line rather than what we should aspire to and you know, I but again, I think the White House has done a good job of drawing in Private Industry on these things and I I'm optimistic as I think it sounds like you are as well. I am optimistic and I think you know, we need to make sure that there's industry buy-in. We need to make sure that there's industry consultation.
I also think that we need to make sure that there's flexibility both in terms of you know, we don't want you know, as we were just discussing we don't want huge amounts of flexibility in interpretation, but I do think that we need to be able to move with the times it's you know, there are many pieces of legislation that we see are simply outdated because technology has moved much faster than the pace of government. And so I do want to do hope that we will we will achieve the flexibility in terms of having a sort of rolling refresh of any guidelines and policies around Book we can't talk about refreshing and progress and Technology changing. It seems you can't walk 10 feet without tripping over some iterative Ai and and gpt's and all these things.
What what role do you think this may have going forward? Well, I think that it's you know, like all tools it will cut both ways. So I know that you know, we look at the the history of the internet and and over the last 30 40 years.
We know that the bad guys are often very Swift to take up new technologies. And you know, I think that certainly, you know, large language models with generative capabilities for generating code have a lot of potential for misuse particularly. You know, what if you go and play with chat GPT for a while you'll realize that it's very good at regurgitating the information that's out on the Internet.
It's actually quite good at summarizing and reinterpreting it, but it's not actually innovating. So my biggest concern with tools like that in the attack side is that it's it's going to make being a script Kitty much easier. I think that it's going to make it much easier for for somebody who is not highly technically Savvy to to create new tools that will rapidly be able to exploit information that gets out there on the internet about attack techniques.
I'm also really optimistic that we're going to be able to start to use these sorts of techniques, too. Analyze information. I mean just as what we were talking about the learning experience of when there's a breach, you know, if we fed everything we know about every breach into one of these models as a sort of post-training fine-tuning Step.
It could probably tell us some really useful stuff about commonalities and you know how might we find, you know, especially if we've got some if each team gave there in the site as to what they think might have worked better. It could probably automatically come up with some great ideas as to how we can all improve our security and so so I'm you know, I'm not concerned. All right.
Yeah progress tends to move these things forward progress tends to build tools that go faster and often have more impact but they work for both sides. And so so I am you know, I'm fundamentally and Optimist and I think that the opportunities for for generative models like this to to give us more insight into what's going on in our networks and our systems and help us with ways to secure them. I think I'm I'm hopeful for that.
As am I think I told you the 15th or not nickel, excuse me, either 15 minutes goes incredibly quick here. We're overtime and I want to thank you for coming on though. You know, I can't believe we haven't run into each other along the way here at all the different because a lot of the places you are at.
I've been around those places. Are you gonna be maybe out of the RSA conference? I will be at the RSA conference.
I think and that come in Sunday night and go out Thursday afternoon. So well good. It's yeah, so we are streaming live from broadcast alley there all week.
I'd love maybe you can come by in person and we'll continue the conversation. That would be fantastic. I look forward to it.
All right, we'll have your people call. My people will make it happen. Okay, right.
Okay, they go bad summer in here. CTO of absolute software. I take strong.
We're gonna take a break. We'll be right back.