Navigating Cybersecurity Challenges with Scott Richards at OpenText World 2024
Transcript
This is Textron tv. Hello. We're back at OpenText World in Las Vegas, and we're gonna be talking about cybersecurity with my new best friend.
Scott, how you doing? I'm doing great, thank you. Right.
Everybody I talk to kind of has the same question about cybersecurity, and they don't have a sense of are we winning or losing? We know we're spending more money, but we don't know if we're getting an ROI on that. Uh, execs are talking about whether or not it's the, we're spending the right money in the right place.
They wanna know what the value proposition is. How should we be thinking about cybersecurity and, and are we winning or losing? Or is this just the way it's always gonna be?
Yeah, it, it's a good question. It, it definitely feels like, and it, and it's easy to get overwhelmed and get a little discouraged because it definitely feels like we're, uh, we're constantly playing catch up. Mm-Hmm.
I mean, the, the reality is there's, there's a lot of bad actors out there. There's a lot of, uh, there's a lot of people that are trying to, to do malicious things, and the attacks are becoming more sophisticated. Uh, they're becoming much more difficult to recognize, and they're becoming much more catastrophic if we don't recognize them and, and mitigate those risks.
Um, and, and I think that, um, we, we have this history of, of organizations that have tried to deploy sort of disparate solutions that each, uh, sort of mitigate against one specific threat vector. And we're finding that, um, that approach just isn't a very good approach. Uh, it, it leads gaps.
It, it, it creates vendor fatigue where you've gotta go and try to figure out, you know, what vendors do I use? What products do I deploy? And I think that's where, um, where, where we're becoming optimistic is in more of a holistic approach, right?
Where we're, we're trying to identify ways that we can link solutions together from protection through detection and response all the way to kind of forensics based feedback loops that feed into those systems and adapt to the changing environment. And, and that's really, you know, in my opinion, the only way that we're gonna be able to keep up, um, because, um, the threats are gonna continue to advance if we don't continue to advance our threat protection, we're gonna just constantly fall behind. And, and we've got to bring sort of, um, you know, we can't continue to bring humans to, to combat machines.
We've gotta be, we've gotta bring AI and sophisticated machine learning capabilities to the fight, or we'll lose. But I think we can do that. And, and, and, and OpenText is pioneering some of that to, to really make sure that we're bringing machines to fight machines.
I'm not even sure I could find the humans in the first place to fight the fight without the machines. Y Yeah. And, and in fact, um, you know, it's a great point because what we're finding with our customers is, um, there are just not enough smart, educated, threat hunting capable type resources available, um, to, to combat all of these threats there.
They're just not enough of us, us around to go on to go and do this. So we've gotta be able to, um, we've gotta be able to augment humans with ai, with machine learning, with other capabilities in order to succeed. I feel like when I talk to a lot of the security organizations, they will concede that perhaps they got a little tool happy, and we have so many tools, but then they wind up spending all their time integrating these things, and then they gotta support the integration.
So, um, do we need to kind of take a step back to a more of a platform centered approach? Yeah, I think so. And, and it's a, it's a great question, and it's actually exactly what we've been focused on at OpenText for, for about a year now.
So we, we found ourselves in that same boat through, um, through a, a bunch of very strategic acquisitions that OpenText has done over the course of many years. Um, we found ourselves with this massively broad portfolio of, of point solutions, uh, everything that, that, you know, spanning every spectrum of the security, uh, ecosystem. We had solutions from data privacy to data protection, to identity and access management, to detection, to response to, to forensics, um, to network detection and response threat intelligence.
And we, we have everything. Um, but what we found was, um, a lot of these solutions were built in, uh, you know, um, across multiple decades of time. Um, they didn't interact well with each other.
Um, some of them were, were too heavy to take to the cloud as is. And, and many of our customers are moving towards, um, or have moved to the cloud or to a multi-cloud environment. And so we took a step back, just like you described, and said, okay, how, how do we build a platform that eases some of this pain?
And so, rather than just continue to try to enhance each of those point solutions, we took a step back. We, we, we've stripped away the user interface. We've changed some of these heavier solutions into cloud optimized, microservice based containerized solutions, and created a platform.
Um, that, and we talk about composable security now, um, being able to pick and choose the pieces of that security platform that you need to deploy. Um, best case scenario, you deploy all of them. That's the best for us, right?
As OpenText, but it's not a zero sum game to us, right? Most of our customers already have pieces of security built into their ecosystem. And so what this composable platform allows us to do is plug in our pieces where they have gaps.
And so, you're exactly right. Um, we feel like we've built the platform that's gonna take us into, you know, the next 10 years of cybersecurity and provide more of a holistic, integrated approach with feedback loops that allow protection and detection to adapt as threats change and new things are launched at our customers. You can't walk down the street these days without somebody talking about their new great AI thing.
But, um, we've seen AI applied to defense. We are also becoming more aware of the bad guys are starting to use ai. Um, are we in some sort of AI arms race in cybersecurity?
Uh, yeah, I think we are. Um, I, I, I think we, we are, the, the AI is changing the game in terms of the threat, uh, vectors that we have to cover. Um, threats are becoming significantly more sophisticated.
Um, you know, maybe, maybe one example would be phishing, right? Where if you think about, um, phishing of yesterday, um, someone would, would create an email, a generic email, they would send it to a hundred people, and they would hope that one or two of those people were, were tricked by what was in that email. But it was, it was pretty generic.
Most people could recognize the fact that, hey, this probably wasn't intended for me. What AI's done is, is it's created, um, it's, it's just as cheap to do very targeted spear phishing with very personalized messages. It's just as cheap to do that now as it is to create a generic message.
So I can leverage AI to create, instead of one email that goes to a hundred people, I can create a hundred very personalized emails that go to each one of those a hundred individuals and much more difficult to detect, um, much more tricky for people to, to, to, um, to be kind of taken advantage of. And so, absolutely, there is a dark side to ai, there's no question. Mm-Hmm.
And, and the good guys that wear the white hats are not the only people that have access to this technology. And, and that's too bad. But the good news is, is that we have a lot of people on our side that are developing solutions, leveraging AI to, again, like I said, combat machine versus machine.
And, and we're doing, we're doing some amazing work in, um, in, in AI across, across all of our solutions. Um, from, you know, we have a application security solutions where we've, we've always been really good at detecting, uh, vulnerabilities in code. We we're, we we're, we're pioneers in that space.
We're really good at it. Now, we're leveraging AI to actually provide AI generated code suggestions. So developers no longer have to spend time in trying to rewrite code.
They can just cut and paste code in. Um, another example of that is in, in the space of, of user and, and entity based, um, behavioral analysis where, you know, we, we've been pioneers in that space. We're really, really good at it.
Um, but the, the number of events that are coming in now has breached the billions, right? It is beyond the capability of any reasonable team of humans to be able to sift through. It's just too massive of a haystack.
And so where we're leveraging a AI is putting it on top of areas where we're already, we already have an advantage where we're already differentiated. We already have capabilities, and we're just taking those capabilities to a scale that is, you know, unimaginable, sifting through billions and billions and billions of events to find these little needles in the haystack that we can string together to identify patterns that we recognize as threats. And then being able to automate the response to those threats.
I kind of feel like we've come full circle on cybersecurity and ai. Initially there was a lot of skepticism, and now I think people are coming around to the side where they're saying, I don't think I wanna do this job without ai. I agree.
And in fact, I think it's probably, just to take it one step further, I think they've realized it's impossible to keep up without ai. Uh, you, you, you just, you know, and I, and I keep saying it, you, we, we can't continue to think that we're gonna be able to bring a human to combat machine-based threats. It's just impossible.
We have some of the, you know, employed at OpenText, we have some of the brightest, smartest, most experienced threat hunters on the planet, and they've always been really good at finding threats, uncovering patterns. We're trying to take that intelligence that they have and, and build AI around that to do it at scale, to do it at, at, at, you know, at at massive scale. That, that, you know, if we hired a thousand of those types of people, they still wouldn't be able to sift through this data.
But AI can do it. ai, AI doesn't need a coffee break. AI doesn't need a, a vacation.
AI doesn't go to sleep. It's 24 7. And, and that's the way the threats are coming in.
Mm-Hmm. The, the threat actors aren't taking those breaks either because they're using AI as well. I think a lot of the folks in cybersecurity, you know, they enjoy the adrenaline that comes with kind of the, the hunt and the game, but, um, after a while, they burn out.
So, will we get to the point maybe where with the help of ai, we'll see less burnout and we'll get people who are able to hang in there longer because they won't just, you know, eventually hit a wall? Yeah, I think so. I think it's, it's just like any technology, right?
Technology, um, is leveraged to, uh, augment humans, right? Augment our capabilities. And, and I'm, I'm certainly not a believer that, um, will reach anytime soon a position where it completely replaces humans.
We're still gonna need these, these really smart threat hunting capabilities in humans. Someone's gotta write the ai, someone has to tune the ai. Someone has to, um, someone has to make sure that we're sifting through the, and, and looking for false positives and, and false negatives.
We have to still do all of that. We need human intervention and interaction with this technology. And, and that's, I think, the stance that OpenText has taken across all of our, all of our ai, not just in insecurity, it's augmenting human behavior.
But, but absolutely. I mean, I mean, the thing that we've uncovered with, um, the soc analysts and the CISOs and the, the security administrators across all of our customers and massive enterprises is, you know, they were, they were starting to reach this point where it was, was it was almost hopeless, right? It was like, we, we just can't keep up Mm-Hmm.
We can't possibly employ enough people. We can't keep up with the new innovative threat, um, attacks that are coming our way. And through our technology, through ai, um, we're able to, we're able to really give them that hope, right?
That, hey, I'm not in, I'm not, I'm not at this by myself. I've got technology that can assist me. Um, and so, yeah, I, I think you're right that the burnout is a, is a concern for sure.
Um, we've gotta keep giving the good guys the tools that they need to stay in the game. Mm-hmm. There's, um, a shift a little bit in mindset too that seems to be happening.
It's not just about protecting, I think we're trying to make the organization more cyber resilient, and maybe that means making the platforms more secure and stronger. So have we kinda moved a little bit from, you know, investing in cybersecurity as kind of like an overlay that we put around everything to maybe looking at the core platforms and making them more secure? I know you guys are changing the, um, the, over the next two years, you're gonna move to biometrics and you'll probably embrace multiple forms of data masking, but that seems to be about making the platforms more resilient to attacks rather than just constantly investing in the overlay.
Yeah, I, I think you're right. And, and, um, I, I, I guess I'd call out a, a few, um, a few phases of that. Um, so, so first of all, for, for a company like ours, I already described these, you know, multiple point solutions.
And, and step number one is to make sure that those systems are, are rather than individual point solutions. They're an ecosystem. They're a platform.
They work together, they educate each other so we can continually adapt and change and, and, and grow and be flexible to the threats. That's, that's number one. Uh, number two is, and, and OpenText happens to have a significant advantage here, but we need to make sure that we're integrating into content systems as well, right?
So we, we are, we're, we obviously do really, really well in content and data management. That's, um, that's sort of the, that's our sweet spot within OpenText, but integrating the, the solutions so that security is, um, is job one when it comes to considering that content, um, that needs to happen. And, and we, we've taken steps there.
We have many more steps to take to make sure that when you purchase a content solution, when you, when you use a content solution, that security is just inherent within that solution. It just happens. I, I think the third, the third area is to, um, is to, is to really make sure that we're integrating into other ecosystems as well, right?
So at OpenText, we, we certainly don't believe that, um, that security is a, a zero sum game, right? There are, um, Microsoft Defender, you've got Microsoft, uh, security copilot, you've got CrowdStrike, you've got Palo Alto, you've got all of these other organizations that are trying to do good things, trying to solve problems. And we need to make sure that we're integrating, that we're working together, that we have bilateral communication through these, um, solutions so that we're passing information to them, they're passing information to us.
I think only from doing that sort of holistic approach across the en, across the en entire sort of ecosystem, um, that's where we're gonna, we're really gonna see sort of some, some leapfrogs in technology and, and really arm our customers with the best chance of, of combating these, uh, these threats. All right. We're on the cusp of 2025.
Looking into your crystal ball, you know, what do you think is gonna happen in the next year? Do you have any sense of, are we gonna see some fundamental changes or is it gonna be more, um, understanding of the cybersecurity challenges on the business side? Or will the cybersecurity people get better at explaining it to the business side?
I mean, how, how's this all gonna evolve? Yeah, so I, I think, uh, a number of things are gonna happen. Um, number one, uh, we're gonna see this evolve even further and faster from sort of the on-prem off cloud version of all of these things to the cloud, to a multi-cloud environment.
And we, we basically have almost no customers that are, um, that, that only work on one cloud, right? We, we have to solve the multi-cloud problem. And, and certainly that's a focus at OpenText.
We have to make sure that we're creating, uh, frame security frameworks that can then plug into multiple cloud variations without having to rewrite everything we've done, right? And so that's a focus of ours. That's, that's a, the journey we're on.
Um, we're, we're well down that path. We, we consider, you know, we're, we're agnostic to the cloud that's being used. Um, but each one of those clouds also has different policies, different tools, different frameworks.
And so our job is to make sure that a customer can use one framework across all of those clouds. So that's one. I think the second thing we're gonna find is that, um, more and more of these integrations I've talked about are, are necessary, right?
So, um, people that have Microsoft Defender but wanna use OpenText, advanced threat detection and behavioral analysis can, um, you know, we need to make sure that, that the CrowdStrike works with our solutions. So we've gotta make sure those, sure, those integrations are in place. And then I think, uh, finally, and, and you're seeing this, we've talked about it, but analytics AI is gonna play a, a massive role moving forward.
It, it just has to, and, and we're, we're pioneers in this space. We've, we've been doing analytics for a long time. We leverage AI across many of our products.
You've heard about our aviator strategies. Um, but you're gonna see more and more and more, not just from us, but from everyone in this space. And it's gonna go beyond sort of, um, descriptive analytics that are sort of reactively telling you what's happened.
It's going to go to more proactive prescriptive analytics that are telling you, Hey, this is what's going to happen, and this is how you mitigate that risk. And so it's going to go from, you know, again, reactive. What's happened to this is how you can change the future by taking these steps to protect yourself.
All right, folks, you heard it here. Hey, once upon a time, cybersecurity, trying to make it robust and simple, we're diametrically opposed ideas. But perhaps no longer.
Scott, thank you for being on. Appreciate it. Yep.
Thank you very much. We'll be back In a minute.