Zero-Trust Adoption Admist Economic Uncertainty – Andrew Hollister, LogRhythm
Andrew Hollister, CISO at LogRhythm and VP of LogRhythm Labs, asserts that it’s no longer a question of why you need zero-trust, but how soon can you adopt the strategy. Andrew will discuss why zero-trust adoption will continue to be slow in the face of economic uncertainty and what organizations need to consider in 2023.
Transcript
This is texturing TV. Hey everyone, welcome back to Tech strong TV. I'm really happy to have our next guest on his name is Andrew Hollister and Andrew's going to tell you a little bit about himself and its company here in a second.
Hey, Andrew, welcome to Tech strong TV. Thanks Ellen. It's great to be here great to have you on so Andrew.
Yeah don't want to embarrass you. But tell us the Andrew Hollister story a bit Yeah. Okay, I'll try to so, um, yeah, I've got a white background in infrastructure and programming and support and all kinds of different things and kind of fell into the security space Oh getting on for 20 years ago.
So I've worked both in the financial sector and defense and a few other places besides and found myself looking at logarithm about 10 years ago and and really interested in the The kind of both the visibility that logarithm gave into the kind of cybersecurity problems that I was seeing but also the opportunity to to dig in to kind of surface the problems that we say and also to respond to them in different ways. And you know, I think in terms of lock with rhythm what what we're really seeing is, you know, we have got an Ever evolving threat landscape right digital transformation geopolitics the economic situation and wanting in another just can't constantly a changing the the digital landscape and of course that impacts the threat landscape right and and security teams ultimately trying to deal with this kind of ever evolving threat landscape and finding it impossible really to effectively defend against attacks. So what we're trying to do is provide that platform which gives teams both the kind of overall visibility.
And the detailed analytics they can kind of cut through the noise and quickly secure their environments. Fair enough excellent, excellent. Excellent so Andrew You know, it's funny.
I was working this morning planning for our RSA conference every year at RSA conference. We do a deaf set cops event on Monday. Okay of RSA we go last year was Tuesday, but You know certainly last year at RSA conference.
I would say the big. Big words on everyone's math with this zero trust the idea of zero just and it's not the first year. It's we've we've heard zero just for a couple of years now, but I think you know, there's a there's a crossing the chasm when it comes to security Concepts.
So I think last year was kind of zero trust across the chasm to mainstream. I think I think mainstream organizations are now understanding that zero trust by default or zero church should be your default. Security posture and then you turn on as needed.
Of course. The zero trust in the zero trust right? There's there's levels and layers if you will of zero, which I think I think a lot of organizations are having a Tough time like they agree with the concept.
They understand the logic of it. the implementation sometimes leaves a little to be desired. One number one.
Do you agree with that? Number two? What what can we do to help these folks?
Yeah, I I do agree with that. And and I think it's kind of almost a vein of the cyber security industry, right every time A New Concept comes out everybody rushes to adopt it and it's kind of becomes whatever you want it to be or whatever your marketing. Yeah Grace and extended right you say that we friends and extended.
Yeah. Yeah. I think that's definitely the case here and I think what's confusing for people is is that kind of what is it?
Can I go and buy one? And and I think this point really that zero trust isn't a product. It's not something you can go out there and and buy off the shelf and and kind of implement and you know big check we're done.
I'm now zero trust it's it's more a set of guiding principles or I mean almost a philosophy of an approach to cybersecurity versus an actual product or or implementation and you know, you talked about it being kind of up and coming. I think it's been up and coming for a very long time. I I actually did some research on this recently and you can actually trace the principles back at least as far as 1994 when a site was security white paper was written about trying to adopt these principles, but nobody had the capability to It back then and I think there were probably two big triggers for more visibility one was John kindergart's kind of seminal work on on zero trust and that was back in 2019.
And of course. A Google had the operation Aurora against the right and they spend almost seven years developing their own in-house zero trust model. And of course no Technologies really existed to do it.
They had to invent the whole thing from scratch. So, you know, it has been around for a while and I think that's possibly part of the challenge people look at zero trust approaches and think well, you know, I recognize some of this and I've seen some of that so what is this thing really and you know our ultimately I think to boil it down. I think it's kind of generally recognized there's really three pillars.
So it's that all entities are untrusted by default. Um, so kind of in the good old days you had your your castle and moat right? Everything was on the inside and and you trusted the Insight.
So we're in this kind of assume breach as the one pillar the second one being that least privilege is enforced. So rather than a single a single access and I've got access to everything. I need to verify identity every time I go and do something new.
And the third pillar is really around that comprehensive broad security monitoring so that everything is logged and and then everything is analyzed and and you know with those three as pillars then you're you're not so much having it a product conversation as a outcomes and an architecture type conversation. Don't disagree with you at all. You know exactly.
I mean, I know John and I remember when he first put forth to zero church thing and of course Aurora, but you know Andrew what amazes me so it's been 10 years and we yeah, you know, we've got a chance to Come to grips with it if you will, but you look at like, you know some recent breaches around like and I'm not here to blame a point fingers. But like the last pass reach right? Yeah where they were able to compromise evidently a person who for whatever reason had access to the cloud resources that the hashed up encrypted vaults were on and they were able to empty literally empty the volts, right?
scary scary Why would someone have that level of access and you know 12 years after this whole concept came up? And I think that's the issue is I think from a from a concept point of view people accept it. And agree with it.
The devil's in the details. about what that really means right because you because here's the other complicating factor. It's easy to do zero.
Zero trust when I've got everything in my own little castle with a moat behind it around it and I could very easily segment out my networks and decide who has what and I got a big fat DLP thing at the drawer bridge and I'm watching what's coming. Reality anymore. We live in a do anything from anywhere world?
Yeah, so yeah, that's every access. You know, we have IAM identity and access management. Well access is peeled off from Identity in a lot of places now, right?
It's not enough to know that it's Andrew. What does that mean from your access to this resource versus that resource and it every single resource. There's a zero.
Trust decision to be made. Yeah, and it's complicated it can get real complicated real quick. Right the amount of people by the amount of access decisions.
Yeah, it's undoubtedly complex. And and I think I kind of look at it in this way. If you're starting a brand new company today with no Legacy architecture.
Probably be quite easy the tools are there green greenfields are always easy. Yeah, absolutely the brownfields that you know that that is the Big Challenge and I think the very interesting thing I actually read through Google published all of their documentation. I think it was seven different documents on how they approached their zero trust journey and and it was very interesting to see that kind of focus.
They had on not breaking existing business processes. So they they really put thought into it, you know and and spent time understanding. Okay.
We've got this data here and In this kind of particular Silo who uses that how do they use it they spent time to to actually map that out. And and I think this is where the the kind of challenges for organizations in all that sprawl in those brown field sites, who knows actually who's using the data through what tools in what ways to what purpose typically you don't really know that so it does take a little bit of a structured approach in order to identify. Okay?
What are my most critical assets out of all this data sprawl? Where do I need to focus my attention and and you know from from our own experience as a doctor of zero trust ourselves you you've got to kind of give it time to go through that Journey. And kind of take the winds along the way, you know you in a Brownfield site, you're not going to go from your legacy perimeter remote architecture to a full zero trust information over here implementation overnight.
It takes time, right and understanding here is my most critical data. These are the people who access it that that's really the foundation for the rest of it. But I think those kind of Quick wins them away things like Implement multi-factor and syndication, you know numbers of organizations.
Haven't even taken that step. So in some senses, it's no wonder we're still seeing so many breaches and compromises that gives you a very quick win manage your kind of employee onboarding an off-boarding. So, you know who it is who has access and you haven't got lots of accounts kicking around that really should have been closed down perhaps weeks or months or years beforehand and I think in general the industry struggles with this zero trust really takes a lot of basic principles and weaves them together and history shows the industry is not that good getting the basics done and doing the reliably well.
So I think there's like some laws of physics at play here. It's one basic thing. We got a shot.
Two basic things make it three times as hard three basic things make it nine times as hard four things that were weaving together. Probably make it impossible. Yeah, that's that's more of the the reality I guess but you know, The other thing though as we said here 12 years after John kindergart first thought about it, and we've had a chance to ferment on this.
You would think we'd have some really good Solutions out there. Right. Well, what's your take on that?
I said I think it's this that Because zero trust is a principle rather than a product in and of its own, right it Demands a broader way of thinking and the products integrate with each other well, and certainly we started off on this journey back in around 2018 when gdpr was just coming out because it provided us some good synergies there and that time you have to do a lot of work in terms of building your own Integrations and scripting and all this kind of thing to make the different tooling integrate with each other nicely. I think as we here we are in in 2023, I think vendors in general are recognizing much more than needs to be more easy integration. We need to A nicely with a lot of other Technologies and provide the capabilities to do that.
And I think as that happens then we'll see it's it's easier for organizations to integrate, you know, for example, your HR on boarding system with your active directory or your other identity and access management is those kind of Integrations which really help organizations to deploy a an architecture that it that is that a d is to zero trust principles. a time I apologize. We let you know this is something I Can talk about all day.
I imagine I will be RSA is coming up in April as I mentioned that the outset will be a broadcast alley all week doing videos. If you're there, maybe come Bible continue this conversation. Yeah, I'd love to come by Alan.
Yeah, well be it my skoney West, you know by broadcast alley they call it there and we'll be doing right video thought to it. Yeah, let's make sure we get in there in the meantime though for people want to find out more. About what you and the company you doing?
Where can we send them? com. You can find out about what we do and we've also put together a set of resources that help organizations with their own zero trust Journey.
We don't sell something else that's branded zero trust, but we have been on this journey and hopefully can share some some useful insights. regarding logarithm Chris's CEO now The CEO of logarithm is Mr. Chris O'Malley.
That's right. So give him my regards always I was glad to see Chris go over there if he's going to be around at RSA told to stop by and see me as well. I haven't moved over.
All right, he will. Did you Hollister from logarithm here talking zero trust with us on take strong TV. We're gonna take a break.
We'll be right back.