Zero-Trust Principles for Critical Infrastructure with Josh Woodruff
The Cloud Security Alliance has published a guide offering a tailored roadmap for implementing zero-trust (ZT) in operational technology and industrial control systems (ICS), ensuring a secure and resilient infrastructure. This interview will examine how ZT principles can safeguard the most vital systems supporting public services.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
Our next guest is Josh Woodruff. Josh is the founder and CEO of Massive Scale Consulting Corporation. And he's also a lead in a recent report coming out of the CSA Cloud Security Alliance and, uh, around Zero Trust.
And we're gonna talk to Josh about it now. Hey, Josh, welcome to Techstrong tv. It's great to have you on.
Thanks, Alan. Great to be here. Thanks for having me.
Thank you. Um, so Josh, I, I guess let's start about Josh. We'll, we'll get to this other stuff in a little bit, but, you know, our audience always likes to know who, who's talking to him.
As I mentioned, your founder, CEO of massive Scale Consulting Corp. You working with CSA, but you know, beyond that, who's Josh Woodruff? Yeah.
Well, thanks Alan, appreciate the opportunity. Um, yeah, as you mentioned, founder and CEO of massive scale consulting. Um, but really what led me here is, is, um, uh, background primarily in Silicon Valley, um, building and leading global teams of DevOps, SRE Security Cloud operations, anywhere from tech giants such as Cafe, uh, such as Microsoft and eBay to startups like Cafe Press and, and Zuora.
Um, always focused on transformation and, and helping them accelerate innovation with security, with resiliency. I'm also a co-lead of the Cloud Security Alliance Zero Trust working group, which is why I'm here with you today about the, the paper that JJ and I have written along with a, a group of fabulous contributors, uh, that all members of the Cloud Security Alliance Zero Trust working group. I am also an Ions faculty member, a part of Ions Research, um, consortium of security practitioners advising Fortune 100 companies on cybersecurity strategy, how to strengthen and protect and even respond to, uh, incidents and events.
Um, about 10 years ago, I relocated to New York City area from Silicon Valley, where I kind of shifted into continuing to drive transformation at organizations around financial services, um, biotech, aerospace, even critical infrastructure organizations, always through a combination of zero trust from a security perspective, AI through an enablement and innovation perspective, along with cloud and DevOps continues to be the theme. Um, uh, really what we find at massive scale consulting and, and, and how we're different, what we're bringing to market is we believe the combination of these three transformational drivers, I would say each one of them, zero trust, AI, and cloud, each one of them on their own are transformational. We believe there's a, a complimentary, um, aspect of these three disciplines where if you're doing one great time to incorporate another, uh, to accelerate innovation, to get more secure, to be more agile, adjust and adapt to market needs, deliver value to your customers much faster with resilience, um, with quality and, and with security.
Um, I started massive scale about a few years ago. Um, before that I was CIO and CISO of a B2B online, um, travel platform. But, um, yeah, that's me.
That's, that's what massive scale does. Um, and the reason I'm talking to you here is the work we've, we've done in Cloud Security Alliance and love to talk about critical infrastructure and, and why that's so important and why people should care. I gotta be honest, Alan, I I didn't know why, why I should care, um, up until a few years ago, so I'm really eager to talk about that, uh, and look forward to sharing that with your audience.
Love it. Thank you. Thanks for that, Josh.
Um, so I, I just wanna spend a little bit of time on massive scale consulting. If, if it's okay, you mentioned, you know, you have a long history leading transformation and different areas from Silicon Valley and New York City, and it sounds like once you get to New York, focus shifted more to financial services as, as one does into New York area, right? Being a New Yorker myself, um, massive scale consulting, give us kind of, I mean, obviously you're founder and CEO of it, is it, is it kind of your foil or, you know, is there, you know, scale how, you know, how big a company is it or where else are you guys doing stuff?
Yeah, well, thank you. A, um, really the name comes from my background of, you know, eBay and Microsoft at, at the time. I mean, I'm, I'm old, we're doing this a while.
At the time, they were some of the largest online infrastructures on the planet, um, specifically eBay in, in the late nineties, early two thousands. So we were pioneering new ways of doing things. Uh, we were melting gear.
NetScaler would give us equipment that we would melt. I mean, we were helping them build their products because we were the only one that saw traffic like that at the time. It was six to seven gigabits a second.
Um, that was huge, uh, back, back then. So we, we were constantly pioneering and trying to find new ways of solving tough problems. Um, moving into Microsoft and working for this will age me, but it was the Hotmail storage team.
What became Windows Live Mail. Hey, I still use my Hotmail. I'm a Hotmail, you know, my personal mail.
So yes, you're right, I'm right there with you, man. Still, still works, still classic. Yeah.
Um, but we were building out the storage backend. I was part of the team that was building and scaling. We were scaling about two petabytes a month, and at the time we didn't have cloud.
We were stamping out about 12 racks at a time in, in various data centers. We started to build our own data centers within Microsoft. Um, and in fact, we were talking to the product unit manager within our group about exposing our block, block-based storage platform that's exposed by APIs to the internet to sell it.
And he was like, oh, I just talked to Jeff Bezos and he's talking about S3. I think that's stupid. That idea will never work.
Like, okay, now Microsoft never Work number two, which is why we're, we're still working Now, we're now Microsoft's number two. You know, I hate to say I should have listened, but you know, what do I know? Anyway, um, we, we kind of all have a chat about that, but I, I think all of this experience has led into really getting good at solving problems in unchartered territories, pioneering new ways of solving problems.
In the early days, it was with Data Center, later it became with Cloud, uh, really by embracing DevOps to take full advantage of a cloud operating model to deliver value faster. Um, and that really became a galvanizing point of every company I was working for was kind of running into the same challenges. They all wanted to figure out how to use technology to deliver value to your customers, whether in the early days with data center computing later with cloud, and then, oh my gosh, we gotta secure all of this stuff.
And now there's this thing called DevOps. I have no idea what that means. Um, it's just a bunch of tools, right?
Where, where, so every company I started to solve very similar problems. It, it wasn't about the technology, it was really about the people. Um, the tech is always the easy part, I think is my opinion.
Um, it's getting humans to embrace change because a lot of transformation is a all about change, and you've got a lot different folks with different tolerances to change through a pretty significant cycle of change, whether it's Cloud Zero trust, and, and more recently with ai. So we got really good, I and a lot of my partners here at Massive Scale. Uh, we, we came together, started this organization because we wanted to help more than just the company we're working for at the time.
And so we love what we do. Uh, we named it massive scale because we believe we can help every one of our customers achieve massive scale. And we hope every one of our customers is successful and needs massive scale.
So it's why we named it massive scale consulting. You don't have to be massive scale to, to use our services. We have customers come to us needing help with security.
Um, they've been told or mandated by their executive team, they need to do ai and they have no idea where to start. Um, or even similarly, they've been told they need to embrace cloud and, and not quite sure how to do that. Or maybe they've embraced it and have found that it's just a more expensive data center.
Because if you don't embrace the cloud operating model and a DevOps transformation, that that is really what it is. It's just a more expensive data center. You're not getting any value.
So you, you really have to look at these things differently. Uh, but that's really where we're helping our customers across all three of those transformational drivers. And, and I think our differentiator is bringing the complementary aspects of these together where if you're doing one, we slowly and, you know, if appropriate, introduce the others to accelerate that transformation and to, you know, uh, get more advantage from a cycle of change than just one transformational driver.
If you're gonna do one, consider the other two. And as you're walking all of your culture and your teams and changing things through this massive cycle of change, you're, you're achieving not just one transformational aspect. You're achieving security, AI, and cloud.
So we believe that's a differentiator. We find great value. Our customers have great success with our outcomes.
Absolutely. Um, you know, talking about things that took me back 25, 30 years without thinking, but I, Josh, I wanted to just spend another quick moment talking a little bit about CSA right Cloud Security Alliance. Look, I, I was there at RSA, I think for the first organizational meeting there.
Jim, Jim was there, Chris HI think James Erhart, a bunch of, a bunch of the security folks. And you know, I think part of the successive CSA was sort of the organizational structure that really came about right away, real early of working groups, right? Tax and, and working groups on specific areas.
You mentioned you're the, uh, was it co-chairman of the Zero Trust working group? Was that it? Or, Um, one of the co-leads of of a Zero Trust Working group.
Yes. Yeah. Yep.
And, you know, and that's one of several, probably a dozen I bet, working groups, right? Something like that. Yeah.
org? The latter. Yep.
org. org. Right.
But I, I think Cloud Security Alliance is is the one that will come up for you. Yeah, I swear we've always gone. org.
If you want to take in the full breath. Josh, I wanna zero in, no pun intended, I wanna zero in now on this, on Zero Trust and this recent report you guys released. And, and maybe you can educate us a little bit about it.
Absolutely. And Alan, thank you for, for re erasing the Cloud Security Alliance. I know before I joined the group, I was a big user, very appreciative of its insights, its output, um, so such key guidance.
And, and you, I think you touched on why it's so successful and valuable. It's composed of practitioners, it's composed of folks who've been there, done that kind of battle. Hardened veterans who got all the scars to show how not to do things, because that's where all the lessons are, is in failure.
Um, and then they come to Cloud Security Alliance and try to share all of those lessons learned. And, and it's such a privilege to be working amongst, uh, such an esteemed group of professionals from all different walks of life, all different levels. Uh, we have such a great time and it is, uh, primarily volunteer driven.
So we invite anybody to, to reach out. Um, we're always taking on new members. Um, there's a few key areas right now of Crowd Security Alliance Zero Trust.
It's one of them. Uh, the AI working Group is another one that started a, a couple years back. That's another growing body of knowledge.
And there's a few others as you mentioned now. And there's, there's the DevSecOps Working Group, um, there's the IOT working group. And what's been interesting about the critical infrastructure work we've been doing, and where I've been focusing within the Cloud Security Alliance Zero Trust working group, is that in and of itself was kind of cross-functional.
We, we actually poached a few members from the IOT working group in into our critical infrastructure group. 'cause it's, it's a headless device. It's kind of another device that's that's sometimes considered ot.
You see IOT and operational technology environments. And by the way, ot, operational technology, I don't want to use acronyms that we all just assume people know what we're talking about. Um, but critical infrastructure is primarily operational technology and industrial control systems.
OT and ICS, um, ot, iot, internet of things, headless devices, things you have in your home, smart R ring doorbells, um, I mean sensors, even even certain valves or or monitoring equipment. There's a lot of IOT devices. In fact, a lot more IOT devices out there in the world.
And I would say they cross both IT and ot, stone Mar used in information technology areas. Some are used in operational technology areas. We actually have a separate paper we're currently working on, um, around zero trust guidance specifically for iot.
'cause it's such a separate large body. But the one that we've recently published at the end of October is critical infrastructure focused on OT and, and ICS industrial control systems. So really what we focused on is we're trying to debunk the common myth that zero trust is just for it.
Um, we can't use this in OT and I dunno about you, Alan. I I know I I talk to customers all the time of any one of these disciplines, whether it's zero trust or ai or even cloud and DevOps. It's like, well, that's not for, that won't work here.
We're too special. We're, we're too unique. You know, we're a special snowflake that'll never work.
And and I I I chuck about that. I I get it. I understand everybody's very unique and very complex, and so much aspects are, are are different.
Um, but time and time again, we continue to prove that no, it does work. There is a way to make this work. And the, one of the reasons we wrote this paper was that to, to show that zero trust, the zero trust security strategy can be applied to critical infrastructure.
This was specifically focused on OT and ICS. Um, another, I would say driver of this paper came out of a huge demand, um, driven, I would say globally. But I know the US government had quite the wake up call with the colonial pipeline attack, uh, where the, the, you know, Darkside ransomware group shut down the, uh, oil and gas supply pipeline, primarily the East coast.
Um, you know, uh, this was, this was pretty big. I mean, suddenly kids couldn't get to school 'cause her buses couldn't get fuel. Um, and gosh forbid my wife couldn't even get a coffee at Starbucks.
You know, talk about chaos. Uh, no, but seriously, I, I think the, the bigger impact there Was the end of civilization as we know it. Yeah, that's Really, yeah.
Talking to her, that that would be the case. My, my, I got one of those too. Um, and I don't even drink coffee, but yeah, no, that, that was the, you know, look, colonial was an eyeopener.
There, there, there was another thing around some water, uh, uh, public water utility potential. I, you know, thank God didn't really get off the ground, but it was enough to scare the heck outta you. Yeah.
You Know, I mean, sand worms, you Mentioned it Bolt, typhoon, like there's a lot, a lot of attacks increasing Critical, you, those of us in the security space know that, you know, this is kind of a ticking time bomb that sooner or later there's going to be probably unfortunately, you know, a catastrophic kind of incident. Um, you know, and I mean, we, we try to get in front of it. We try to prevent it.
We also have to put in place plans to react to it. Response. That's one of our key points.
Yes. Very key points of, of our guidance, Alan, that's, that's so true. And I think the dig, the big difference with these, with the critical infrastructure industry itself is it's not just revenue impacting and business impacting.
This is what civilization depends on. These are, human lives are at stake. Yep.
Like we're talking, you mentioned water, healthcare. I mean, people can't get drugs. The, the, they need to save their lives.
Um, you can't power energy. I mean, look at what happened with Ukraine and, and, uh, the big attack there that, uh, that was coincided with a missile strike. I mean, that wasn't on coinci.
Yeah. That wasn't a coincidence. So there's, there's very effective ways to protect yourself.
And one of the reasons I love Zero Trust, and as you learn about it, and this paper does a great job of teaching you about, well, what is, let's start, let's just first start about what is Zero Trust. But even before that, we say, well, let's, let's start with what is critical infrastructure? Um, and so let's, let's spend a moment on that.
I think the, the paper introduces critical infrastructure. It talks about the 12 critical infrastructure sectors that are most common globally. And then of course, the 16 that we def that CISA defines within the United States.
Um, we talk about the differences between OT and it, um, some of the unique threat vectors, uh, around OT and critical infrastructure. Um, the unique challenges in securing critical infrastructure. So we kind of paint the picture of, you know, here's, here's critical infrastructure, OT and ICS.
You don't need to know anything about these things, uh, to get value outta this paper. In fact, we hope this paper educates you on, on exactly what those things are and how they're different. Um, our target audiences, it could be it practitioners, it could be OT practitioners, could be CISOs, it could be, um, third party service providers.
You know, we believe anybody can get value out of this paper on first learning what critical infrastructure is and how it's different, what its unique challenges are, why they're so important to human safety and civilization as we know it. Um, and then we shift into defining zero trust. Here's what Zero Trust is.
And then the last part of the paper really focuses on here's how you apply this zero trust strategy to critical infrastructure. And there's a lot of differences. There's a lot of similarities, but there's a lot of differences.
So, um, I, I think it, it couldn't be more needed in the market. One of the things I'm mentioning earlier about why I like Zero Trust, and as a prior ciso, when you learn about Zero Trust, it's kind of like a wait. It's like, why wait, what do we, I felt like an idiot.
Like, why haven't I done security this, this way the whole time? Um, in fact, uh, you may know Chase Cunningham, uh, doctor Zero Trust, he asked me once, um, once Zero Trust is really an identity based security model as opposed the traditional model being a, a, a perimeter based security model, the firewall right outside your untrusted, inside your trusted, that's the traditional Perimeter. No, this goes back to the Jericho.
I don't know if you remember the foundation, you know Oh Yeah. Yes. Deep pri The ization of Seagates and, and, and micro perimeters and all of that stuff.
Yeah. Hey, Josh, we're about outta time. I actually have our next guest in, in the green room, um, for people who want to get this, uh, well, someone's gotta pay the bills here for people who want to, uh, get this report.
You can go to the CSA Zero Trust working group and, um, you could probably get the link, get it from there. We'll try to put the link into our notes on this as well. If you're watching this on Textron tv or maybe in a podcast format, it'll be in the notes.
But you know what, Josh, the other great thing about CSA that makes it great is people like you, right? You don't get necessarily paid for being a volunteer at CSA. Right?
But people put a lot of their valuable time and energies into making CSA so that it's, we all benefit from it, right? It's that rising tide that lift all the boats. So thank you for your work at CSA, great work on the Zero Trust, uh, paper and come back and keep us posted.
And if not, maybe we'll see you at RSA We'll, we'll, we'll be there at Broadcast Alley, and actually we do our dev set ops thing Monday the same time as the CSA event every year. We're usually in the room next door, and, uh, people hop back and forth depending who's talking. When this year we'll be doing AI and, and DevSecOps as, as one would when AI is grabbing everything, right?
Yes. It's Josh, thank you very much. And again, thank you to you and the whole, uh, working group from CSA and CSA itself.
Thanks for being here. Yeah, Thanks Ellen. It's an honor and privilege.
Appreciate the time. Thank you. Josh was your founder, CEO massive Scale Consulting Corp as well.
Working group leader for the Zero Trust Group at the, uh, cloud Security Alliance. org here on Tech Drunk tv. We're gonna take a break.
We'll be right back.