Managing ATM Security and Vulnerability Challenges at NCR with Theo Bowman
Theo Bowman discusses his role at NCR, focusing on the challenges of vulnerability management within the Leos division, which specializes in ATMs. He highlights the complexities of managing vulnerabilities, the use of Qualys for scanning, and the impact of AI on security risks. Budget constraints are acknowledged, and Bowman emphasizes the importance of community engagement and continuous learning in the field.
Transcript
We're back here live at Qualys Rock on in Houston, day two. Let me introduce you to my next guest. This gentleman's name is Theo, TO Bowman.
Theo Bowman, yes. If you follow what we do with Qualys, I actually spoke to Theo last year in San Diego. I'm pretty sure.
Uh, Theo, I'm gonna let you introduce yourself. Why don't you tell people a little bit about kind of your journey, what you do, where you work, stuff like that. Oh, I, so I'm, I'm Theo Bowman.
Uh, been working with, uh, NCR at Leos now for, uh, five years. Just hit my five year mark, um, in charge of the, the vulnerability management program there. Uh, the journey we, we've take, we, it's been, it's been long, but it's, it's good.
You know, we got a lot of buy-in. We got a good, we got good management, you know, leadership likes what we, you know, help us out by supporting us and things. So it's, it's, it's good.
Good. Um, you know, for those who aren't, I think everyone knows NCR right? But they don't necessarily know NCR at Leos.
At Leos. Talk to us about what that is. Well, so the company split into two different SI remember.
So basically at Leos is the, at m portion of, of the split. So we do everything at M Wise. We service ATMs, we make ATMs.
So there's nothing that vulnerabilities would be too important for. Right, right. Right, right, right, right.
Um, you know, the, you know, the life of a vulnerability management person is tough. Right. I, it's 20 years ago when I had founded a company in vulnerability management, we used to call our vulnerability management too, the bad news generator, because it just generates bad news.
You know, you never get a report that says, Theo, congratulations. You don't have any vulnerabilities. Right.
Right. There's always something in this decisions to be made in trade offs and priorities and everything else. You've been using Qualys for a while now.
Correct. Um, are you using it just to scan and find vulnerabilities? Are you patching, remediating with it?
What, you know, if, if you can talk about it? So, so we use it generally to, to scan and find vulnerabilities, but also to consolidate the other sources that we have. Uhhuh tech vulnerabilities like this.
Sure. Products like, uh, Wiz or Yeah. BitSight or something.
And so consolidate that to, to one platform and to, so we don't have to go logging in everywhere, you know, everywhere at once. Yeah. Almost like a sim, but not, you know, it's not a true sim, but it, it's, it's, it's, it's amalga, Amal, I can't even pronounce the word.
It's bringing in all the different Yeah. Feeds, if you will, of, of vulnerabilities and, and threat. Right.
Um, so I guess the big difference between this year to last year, Theo, is ai. Right? Right.
We're seeing a lot more vulnerabilities. We're seeing a lot code. Right.
That ai, you know, may is touching, let's say. How has, has that kind of impacted your day to day yet, or? No.
So we use, so we do scanning for, um, software component scanning, third party SC Yeah. SCA. Right.
So we use that, which it's all, it's all over the board. Right. And so, uh, it makes you, our vulnerabilities jump up to Anane number because of all the different softwares, all the different technologies and where they pulling the, their data from or they code from.
It's, it's, it's challenging. It is. It is.
Um, what about Rock on here, right? This new, this new conference? How, how's that?
What have you learned here? So, so rock on. I like it.
I like it. I like the direction that they're going with, uh, ETM. Yeah.
Right, right. So we use it currently. You do?
Yes, yes, yes. Okay. So I like the, the path forward that they have.
And I already, and, and we like, and that's the consolidation part of, uh, the vulnerabilities from other other sources. You know, we use ETM for that. So, and then to, to break it out into different, uh, business entities so we can say, Hey, these guys for their risk posture, Hey, you're, this environment is doing good.
Well, you, you guys are above the curve or the limit if we want our risk to be at, you know, so it's, it's good. I wanna come back to the conference. You know, they had two days of training.
Right. Did you take advantage of it at all, or one day of training? The second day I was in the, the product advisory board meeting, so, oh, really?
Alright. Good for you. Training was good though.
Training was good. Right. So, um, last year's training, I felt like it was more on a higher level.
Yeah. Right. Uh, for people that's been using Qualis for a while and this year's training, I feel like they did a good job of, it's a lot of people that's new to Qualis.
Yeah. They did a good job of, you know, explaining how to set it up and, and all that. So it it is, it is good.
Yeah. Yeah. We were talking before we went live.
You, you had a, a bit of an emergency back at the, at the, uh, job over the new, uh, new, I don't even want to mention names on here 'cause that gets into things. Right. But the new vulnerability situation you had to address mm-hmm.
No matter how much technology we have, no matter how good these tools are, when stuff hits the fan stuff hits the fan, it hits the fence. Right. And, and you gotta get on it.
Yeah. So we say, we say security is a lifestyle. Right.
Got a job. Right. Yeah.
It's a lifestyle. So that's a good way of putting it. Right, right.
Good way of putting it. Because vulnerability never stop, right? No.
It always come up getting worse and worse, more and more. Man, it's, it's fast and furious. Let me ask you a question about your company though.
'cause we, we've spoken to a lot of security people, CISOs, you know, there was a period over the last couple years where I think a lot of the boards, you know, governing boards, executives were saying, Hey, we've been giving you a lot of money for a long time for new security tools, and I don't see our security any better than it was. We still vulnerable, we still got risk. You know, there's still stuff going on.
But now this year we've seen a little change. Mm-hmm. We've seen boards and, and exec teams saying, look, we gotta use, we gotta leverage ai, we gotta combat ai, enhanced security.
We've gotta do a better job of knowing what our risk is. Right. Has that, again, without giving out, you know, confidential information, has that loosened up the strings budget wise for you guys to maybe do a little more?
Uh, I think our budget's still pretty much the same. Really flat. It, it, it is pretty much the same.
Um, more of a what can we do with what we have to make our, to, to know what our risk is and then understand our environment better. Right. How can we put all those things together?
So that's, that's more of what the push is, that that's where it's at. Mm-hmm. Um, is that enough for you?
It's gonna have to be Right. Right, right. So when you start thinking outside the box, we, we, and, and, you know, you have all these, all these different tools that, that, that really good at doing certain things.
If it, it's enough, it's enough if we put it together. Right. Yeah.
You gotta be, you gotta be a little witty about it, right? Yeah. You gotta think, you gotta be, you gotta be smart about it.
You gotta be smart about it. Yeah. All right.
Um, just trying to think what else is going on in your world that you think our audience might want to know What's going on in the world? I, Hey, if you want to get into vulnerability management, hey, just know you can't sleep. We gotta keep you alone.
Right. It's a, it's a lifestyle. It's a lifestyle, not a job.
It's, it is a lifestyle. Yeah. Yeah.
Yeah. You know, in some ways though, Theo, you're out here. So our audience are hardcore tech people, right.
Cyber people, developers, cloud native, you know, and then in some ways you represent them here. Right. And, um, it, it's good to see that they have real practitioners who are here.
Not just soaking up what they're pushing, but pushing back on what you need and what, what you are seeing and what Right. You know, the, you see as the market. So thank you for doing that, man.
Appreciate it. Yep. And, uh, maybe we'll see you next year.
I don't know where, I don't think they announced next year's, uh, venue yet. I, I don't think they have either. But wherever it is, God willing, I hope we see you there, man.
And keep, keep living the good, you know, putting up the good fight and doing what you gotta do. Okay. Thank, all right.
Theo Bowman here at Qualys Rock On. We'll be back with more in a bit.