Zero Trust Network Operations with BackBox’s Josh Stephens
In a significant stride toward enhancing network security, BackBox, a leader in security-centric automation for network teams, introduced Zero Trust Network Operations (ZTNO). This groundbreaking offering is a best practice framework with six actionable pillars to automate cybersecurity considerations at the network layer for NetOps teams.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
I've got another first time guest on Textron TV here for you. I wanna introduce you all to Josh Stevens. Josh is the, uh, CTO with a company called BackBox.
Hey, Josh, welcome to Tech Drunk tv. Thanks, Alan. It's it's great to be here.
Pleasure to have you on my friend. So, Josh, let's start with back box, right? Because I, I, I'm gonna assume our audience, a lot of people in our audience are not familiar.
You know, we have black box, we have box, you know, but back box. Tell us about Box BackBox. BackBox is a tech company that was originally founded in Tel Aviv, Israel, uh, about a dozen years ago.
And we got our start building automation for firewalls, uh, specifically being used within very large MSPs, managing financial services companies. And over the years, the product has evolved and become a robust platform for automation, really focused on network teams and solving the needs they have around automating firewalls, you know, routing and switching equipment, access points, and other types of devices like that. We moved headquarters to the US to Dallas, Texas about two years ago.
Uh, r and d is still centered in Tel Aviv, uh, where a lot of our people were still existing today. And we are, we are laser focused on really making the lives of network engineers and the security teams that manage those firewalls easier, uh, and helping 'em do their jobs better. So would this be in the same category as, let's say, like the folks at Fireman or AlgoSec or TwoFin, or are those No, those, Those products are oriented primarily for security teams who provide, you know, results and data sets and guidance to the network team that actually manages the configurations of the firewalls we're selling to the network teams.
Now, there may be a network engineer on the security team responsible for that, or there may be a security specialist as a part of the network team, but our products are geared toward that network engineer, the network operations team member, that type of a user. Got it. Okay.
Um, that, that's helpful. And of course, look, you know, I, who, who, I forgot who I was talking to recently about, you know, network operations and how it's changed like during the, my, you know, my career, right? Because when, when I first got involved, I, I'm in security 25 years, I'm in tech 30 something years, and back then most of what security folks actually came from the network side of things.
That's right. Because That's right. A lot of security was network.
You were either a network security guy or maybe you were an endpoint security guy running, you know, playing with antivirus and stuff like that. Um, of course, you know, so much has changed the cloud being a big part of that and the, the whole way we design our networks and stuff. But, um, though it's changed, it, it hasn't necessarily gotten any easier.
No, I would say it's gotten harder. Um, last week I had my 31st anniversary of becoming a network engineer in cybersecurity specialist in the US Air Force. And you're right.
You know, in the old days, uh, cybersecurity was mostly handled by the network team, uh, because your security was mostly about your firewall at the edge. Mm-Hmm. And in, in those days, in many cases, your firewall was just sort of a specialized router that was dedicated toward traffic filtering and blogging.
Um, but that's evolved a lot in the last several years. And now you're going to have both a cybersecurity team focused on incident response and, and, and policy administration. And you're going to have cybersecurity experts within each functional area, within the network team, within your DevOps team, within r and d, within your help desk and desktop support teams, because cybersecurity now is everyone's responsibility.
And so it's, it's a common skillset that everyone needs to have, you know, within their repertoire. And it's something that I've always found really fascinating. Uh, and that intersection of the network engineering skillset and the cybersecurity skillset is a tough one to find, which is part of why we focus on automating those types of things for those network teams to help them scale.
Yeah. Uh, absolutely. Absolutely.
Hey, before we jump into this ZTNO stuff for people, want to get more information on BackBox, what's the website? com. Easy.
Okay. Easy to find. So, Jo.
Yeah. Uh, Josh BackBox recently introduced something they calling zero trust network operations, TNO, and it's to help, like most of back boxes charter, we are gonna automate a zero trust security for network operations. And zero trust is a big buzz word, right?
I very hyped. That's Right. A lot of our audience is familiar, but, you know, let's peel the hype back and get down to the rubber meeting in the road here.
What exactly is ZTNO? Well, when you, when you hear about Zero trust, you're, you're usually gonna hear it framed within, uh, sort of ZTNA zero trust network access, where you're managing and limiting access, validating in real time user level access to the network. Or you're going to hear about it as it relates to locking down security for r and d.
I read an article today around container security, for example. Um, and, and you, and it's a very important concept there, but what a lot of teams struggle with is, Hey, our company or our CISO has said that we are going to march down the zero trust path. How does that apply to me in my role in my department?
And I think that's especially true for the network team. And so what we've done at Bag Box is we've identified six core pillars that we believe are instrumental in implementing Zero Trust from a network operations perspective, so that those teams understand how do they honor the zero trust principles within their everyday operational roles. Get it, get it.
And, um, well let, let's dive into the offering itself. Yeah. Can we, can we peel it back a minute?
And let's Talk about that. So the six pillars that we talked about are first privileged access management for the network teams. What this means is, even though a lot of changes on networks today are automated and are done programmatically, it's very important to lock down and manage in a zero trust way anytime that someone needs to, from a keyboard, from an app, or from a website, access a device intentionally.
Now that might be to make a, a change that needs to be made in real time. It might be for troubleshooting purposes, but in a zero trust world, it's not just about ensuring that you are authenticating them via a multifactor process with attack Acts or Radius. It's not just about network access control, it's also about locking down where this change is made from.
It's about making sure that those changes are logged into an immutable log. It's about making sure that if necessary, you're recording that session so you can play it back later. And really ensuring that you can lock down where administrative or root level access is being done to your network infrastructure.
The second pillar of ZTNO is audit and control. And that's really about auditing the changes that are done by who, when, what, why, what's changing the system? And do we have that log?
Can we control it? Can we audit it? Whether it's changed by an automated process, a script that you've written, an automation platform like BackBox or an engineer.
The third pillar of ZTNO is about device onboarding. Products like BackBox do a continuous discovery of the network to find new devices that have been plugged in. And when you have a new device that appears on the network, a new ethernet switch or a wireless access point, for example, one of the important things to do is to audit that device in real time to determine does it introduce new vulnerabilities or new secur issues to your network?
If so, you should maybe not onboard that device yet, automate some remediation, maybe using our product, the network vulnerability manager so that you don't lower your security posture or reduce your security hygiene as that device is onboarded. Secondly, you want to think about how you manage vulnerability management, so not vulnerability management at the endpoint level. Remember we're talking about the network operations teams and the network engineers.
So how are you managing vulnerabilities across all of your firewalls, your routing and switching equipment, your access points, all of those devices that are going to be agentless, they're going to be difficult to access. And how do you prioritize that? How do you ensure that you're doing it along the lines of zero trust?
Fifth is continuous assessment. How do you continuously assess your network so that all of your infrastructure is being evaluated for vulnerabilities, for configuration issues, to ensure that the zero trust rules and guidelines that you've built in those configurations haven't been backed out or changed? What if, what if you've locked down your infrastructure so that you are ensuring that it's honoring ZTNO or ZTNA in that case, and someone changes it and disables that setting so that they can now log in from home and do something malicious?
Are you auditing that? Are you managing that drift? Are you automating the remediation through a platform?
And then last but not least, is reporting and visibility, whether you're reporting internally to take action or to provide those reports to your executive team, providing, you know, detailed reports and dashboards is a really important part of, of what we're trying to enable here. Agreed. Excellent stuff right there.
Um, so I I, you know, I I, excuse me. I was, my last interview before you Josh, I was talking to the, actually the chief security officer at CloudFlare, and we were talking about how hard it is for most organizations to kind of secure their attack surfaces and secure, you know, 50, 57% of traffic now is actually via API, for instance. That's right.
Right. Most organizations just can't do this in-house. They need help.
I mean, it's one thing to buy a tool and use a tool, but even, you know, what, are you gonna have 50 tools with 20 people and, and think it's gonna work? I wonder what you guys are seeing around that, especially as it like, let's say zero choice network operations. Well, we're seeing a similar issue.
We did a, we commissioned a survey with Wakefield Research last year, and we found that 92% of networks out there, and I might be misquoting this, I don't have the data in front of me, but if I recall, it was 92% of respondents said that they have more changes to make to the network than they can possibly keep up with. And over 50% of the respondents said that they're only able to update their devices quarterly or less often. So what typically happens in these environments is the security team does a scan, they provide the network team with a giant list of all the CVEs that they found on their firewalls and edge devices.
And the network team who's already overwhelmed, they look at that list and say, wow, great, we'll, we'll get to that when we can, but we also have other fires burning right now. Yep. And that's part of why we deliver not just a, a single, uh, you know, point solution, but an automation platform that includes our network automation manager, our network vulnerability manager, and our network privileged access manager.
Those things together really enable those teams to keep up. Also, a lot of our customers are managed service providers providing managed network or managed firewall services. So in those cases, you know, many of those customers have their own network team and they're doing what they can to keep up, but they've decided to outsource the, the backups, the, the monitoring, the vulnerability management, you know, os updates, the sort of standard care and feeding that you need to do in order just to maintain your, your security hygiene for your infrastructure devices.
And so in many cases, you know, you may be a, you know, a regional bank and you may have your own network team, and you may outsource, you may be using BackBox to automate, uh, config changes. You may outsource your network monitoring and your patch management to an MSP who's also using BackBox to do that for you. And so it's, it takes, it takes a village, as they say, um, because we've all gotta kinda work together here.
And trust me, the bad guys are working together, they're collaborating in their own environments on the dark web, out about better ways to attack. And we have to work together to collaborate around better ways to protect. Agreed, man.
Agreed. Josh, we're about outta time. Oh, I wanna thank you.
You got, well, it goes quick. You know, Really Quick. You start talking sharp, and there you go.
com is the, is the main domain. Could they just go there and get information on ZTNO from there? You can go there and get information on ZTNO.
You can also check us out on YouTube. Uh, we have lots of free educational content on the website. You can check out, you know, if you're a new network engineer or you're new to network automation specifically, check this out.
You can spin up, uh, an eval right there in our cloud. It's free. You can check it out.
You don't have to download anything. Uh, it's, it's very, very easy to use products. We really strive on making sure our products are exceptionally easy to use, high performing, and ultra reliable.
And, and that's the promise we make to network teams all around the world today. And Alan, thank you so much for having us on the show. Our pleasure.
Josh Stevens, chief Technology Officer BackBox here on uh, tech Trunk tv. We're gonna take a break. We'll be back in a minute.