Zero-Trust Cybersecurity – Michael Gray, Thrive
Thrive CTO Michael Gray explains what it really takes to implement a zero-trust cybersecurity model across what has become highly distributed computing environments.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Michael Graves the CTO for Thrive networks. And we're talking about zero trust. It's all the rage these days.
The issue is it's not something you can actually go out and buy it's something you kind of have to build and enforce. So let's get into what it takes to actually achieve some zero trust Michael. Welcome the show.
Hey, thanks for having me. I think this concept's been around forever in a day. I think we tried to do with Hardware back in the day when we were gonna lock down systems and everybody Rebel, but it's not like I can actually buy something that just is zero trust from the get-go.
So what exactly do security folks and it people need to be thinking about as they move to zero trust and how do we get there from here? Yeah, well first and foremost, I think that yes reminds me of sd-wan from five years ago it meant 10 different things to five different people. And so, you know, the first thing I think about is what what trust trust what trust who You know and I really think Believe It or Not zero trust begins with a little bit of asset management.
All right. So what are the what are the the resources that we're trying to protect and who are the identities that are trying to access those things? I think you can answer that question even conceptually.
I'm not talking about running out buying a bunch of asset management software, but literally sitting down Excel or even you know, good old-fashioned pen and pencil and saying these are my most critical assets and these are the identity identities that need to access them. I think that's a fantastic starting point before we go on by any solutions. It's just trying to understand what the landscape is and the things we're trying to protect.
A lot of this also sounds like to me. It's really a focus on identity. I mean, it may be a machine identity.
It may necessarily be a user or could even be an application. But is this kind of the variation of an identity Centric approach to security that we've been talking about forever. We're just now calling in zero trust.
Well, I think it's identity plus the flow of data. Okay, so you've got those identities sitting out there and you're managing them. That's great.
Well, what data do they need to access and how do they get there? And I think what a lot of people end up finding is, you know, there's still some Legacy applications out there and that flow of data is not as straightforward as they maybe hoped it would be when they set upon trying to implement zero trust so I certainly agree with you when it comes to the fact of yes, this is identity management at a somewhat the precursor to everything else you're trying to do. But again, how do those identities get from where they're going to that that data that they need to do their jobs?
Hmm. Do you think as we get to this whole idea that people go? Well, that sounds great.
But then when they start investigating and becomes rather complex, so can they actually do that today and who can do it? Is it really large Enterprises? And you know, what is the market for this at the moment?
Yeah, I think they can you know, it's sort of mentioned that it meaning a bunch of different things a bunch of different people. A lot of times people will start with I want to make sure that only corporate laptops can attach to my corporate Network and they'll call that zero trust and I certainly understand that, you know, there's certainly much deeper Integrations of zero trust. I think they can get there.
I don't think they can get there a hundred percent. Even on the SMB side. You don't necessarily need to be just an Enterprise to get there.
I think the area that most organizations can get to is well, I know I have the read these three critical SAS applications and I can make sure that it's a corporate identity on a corporate device going through a secure channel to get there. I think when it comes to trying to have zero trust to cross every single application and every single instance of the user trying to get there that might be Difficult, but what I think in the end, they'll probably end up driving to is well, maybe it's time to get rid of some of those other applications and try and consolidate down to a top five or six. So that I can achieve my plan of getting to zero trust across, you know, the majority of my environment.
Is a lot of this also therefore gonna be a reason or an excuse for that matter. It's a kind of revisit a lot of the security policies that have been in place and things that people kind of, you know, almost ignored or didn't want to deal with because it was too complex and now they're realizing that it just can't be ignored anymore. Yeah, and that's absolutely the case and I see elimination a lot of those Legacy platforms because what they're finding is there's Security State or their potential Security State is just too large trying to close all these doors.
So instead of trying to close all the doors. Why don't I shrink the number of towards that need to be closed and you know that we're seeing a lot of success and you know, maybe a couple years ago people might have said well, it's too hard to go to a SharePoint or a Dropbox away from my on-prem file server. And then when they think about the complexity of securing that old Legacy Channel They say well maybe it wouldn't be so hard for our employees to change and transform.
You know that. Once they become open to it, they start to see some possibilities and then they also see that on top of all this little simpler to secure maybe than some of those Legacy channels. So, you know that people I think are really coming around, you know, where we are now with hybrid work.
I think they're seeing possibilities that they didn't see before maybe they got forced into it a little bit but that's not the worst thing that could happen to technology anyway, so yeah, I think it's actually pretty exciting that you know, maybe zero trusts. Is fueling some digital transformation. I think that's fantastic.
I think it's easier. For security people to have this conversation because not too long ago was security wasn't really high on the list of things that people use for buying criteria for anything and is now the nature that conversation starting to shift because the sea level folks are starting to realize and appreciate the enormity of the issue. I I do and obviously, you know people have certainly woken up certainly at the sea level the risks around security.
I do think what's underlying zero trust in a way especially if it's done, you know in a somewhat delicate manner thoughtful manner. It's actually can more convenient for folks, you know here if you're set up a very specific way and you're zero trust is is not adding a lot of friction. I think people might actually like it a little bit better.
Oh it recognizes who I am and thus I can get right to the data that I want to get to without having to jump through a bunch of Hoops. I think people actually appreciate that even if they have to change a little bit. Hey, you can't use your your home machine anymore, or you can only use your home machine to get to your email and nothing else.
I do actually think unlike some other security controls that see level or or it. You may try It in place zero trust. There's a convenience factor underlying it if you can get it, right?
when you go down this path What's your sense of how long will it take to get to zero trust? I mean most organizations and do they realize that we're really talking about maybe not weeks and months but several years before we sorted all up. Yeah, and I think the reason that sort of where I started which is do you know what you're trying to secure, you know saying security if you don't know what it is.
You can't secure it right? If I don't know where the doors are. How can I lock them?
And it's those organizations that have an understanding where they are with technology that can actually move a lot faster towards zero trust. Otherwise, you are spending quite a bit of time doing simple things like inventory applications and inventory data inventory identities these things taken off a long time because I think when those organizations that have not been doing that kind of asset management, they start to play catch up a little bit. They start to step back and realize how much they have and then they want to clear up how much they have or consolidate how much they have and then set off on zero trusting.
A lot of that precursor is where all the time gets consumed. You know, you may say, hey, let's go to zero trust and realize you have five or six other large. I keep products before you can even start that process and that's why these things drag on for years.
Do you think that as we go along we're going to need to rely more on machine learning algorithms to find all this stuff because the estate is so big and we don't necessarily know what all these assets are and what the apps are or even for that matter. What users are doing what when and where and maybe it's too big a job for human to figure out so maybe we need a machine it is it is and what I would say is you know that Foundation is usually shifting underneath you. So while you're trying to close and consolidate all these old Solutions, there's new Solutions being brought in so it requires certainly a lot of agility on it teams.
But yes, I think if you're gonna go down the path of zero trust you do want to include some amount of machine learning based on risk. So is there something about this user that seems risky to Me Maybe the IP address they're coming from is malicious and many of the zero trust Solutions, especially when it comes to Identity already have some basic Learning in the background that can do some of those analytics on the Fly for you. And again, I think this ultimately helps end users right?
Maybe they don't have to MFA six times because it's just something about me that the machine learning sees that knows I'm safer unsafe and bring all these factors together with machine learning. Yes, that's impossible for a human to do and you will actually need some technology to help you there. Do you think the bad guys are well aware of all this and they kind of just look at us and smile to themselves and go.
Yeah, we're talking about all this wonderful stuff that you guys can buy and use to defend yourself. But fundamentally, you know, the lowest hanging fruit is pretty simple to exploit. So they're not even going to bother going to do all the more complicated stuff.
Yeah, I don't I don't think the arms race is coming to any sort of end between us and and the bad guys sort of speak. But you know, what I think is happening is people are waking up a little bit is is not just about the technology but it's about the implementation of the technology because that's where I see a lot of weaknesses where you went and bought the highest end piece of technology and it was not implemented correctly or it was missed as far as something that needed to be protected was not protected and I see that over and over again and that's really the human element when it comes to security. It's fantastic to make an investment in a SAS solution.
He's a software piece of Hardware, but if it's not implemented and monitored, yeah that guys will just sit there and laugh and say yeah, but you know, you left this other door unlocked and I can easily go through it. I have all the bells and whistles, but there's just, you know one chick in the armor so to speak. Are we getting better at turning this more into a team sport on our side?
Because you know, we've got the it operations people are more involved. The application folks are more involved. So is this becoming something where it's just not left up to the security guys by themselves to figure out I do I do actually see progress being made, you know, maybe if you can imagine for a moment it presenting on a project to you know, move things forward from a digital transformation standpoint, whereas before people might look at it say well that you know, we drive a lot of value for our business.
I think now that those sea Suites are saying this is all great but is it secure right and you know five years ago, they might not have been saying that and I do feel like it is getting a little bit more support it operations getting a little bit more support than they used to and organizations are realizing where they used to take chances around risk it it's not gonna work out right that that's a casino game that they're gonna lose. And so they're asking the right questions now that we still have a long ways to go. So a lot of really insecure things happening, but there is a little bit of a tide turning here that hey maybe we can come together at least attempt to make things more secure whereas before it was a little bit more of an afterthought.
Huh? So what's your best advice to folks to figure out how to get to this zero trust Nirvana that we're all seeking. How do I get?
Where's the beginning? Yeah, you know, it's super basic and it's it's an interesting term that people, you know may not in the C Street may not hear every day. But it's threat modeling.
You can do threat modeling on the back of a napkin you can sit down and say to yourself. What is our most critical asset our most critical data and what would happen if that were compromised and then sit down and sort of talk through that as a team. It is a very basic thing that people can do the things that come out of it are well, what is that critical asset?
And how are we protecting? It? It really drums up a lot of really good questions and say, okay.
Well, how do we know the people that are accessing that critical piece of data? How do we trust the people getting to it? You know, it's it's a pretty simple thing to do.
It is not something that takes 10 12 hours. You can actually do a threat modeling in 45 minutes. It's a very straightforward exercise and of course it can help you they would actually probably welcome that discussion of yes.
Well, what do you feel are critical assets are C Suite versus what do we think they are? And how do we come together and actually say as a as a team as a whole company, this is what's most critical and this is how we secure the users that are getting to it. All right, folks.
Well, you heard it here. The good news is zero trust is really an opportunity to start over think of it as a giant Mulligan in the land of cybersecurity. But as always you still got to start at the beginning.
Hey, Michael. Thanks for being on the show. Thank you.
Good to see it. All right back to you guys in the studio.