Chris Ong, Jabil | Qualys QSC22
Chris Ong, senior manager of information security operations at Jabil, joins Alan Shimel at Qualys Security Conference 2022 to discuss Qualys Cloud Agent.
Transcript
This is texturong TV. Alrighty. Hey, we're back.
We're back in Las Vegas. We are at the Venetian Hotel the site of QSC 2022 qualysis security conference. One of the nice things I love about doing the QSC is you know, we get to speak to real life security people people who are pregnant are practitioners who are who are on the front lines protecting stuff.
I got someone like that to introduce you to here. His name is Chris on Chris. Well welcome.
Thank you so much for having me. Appreciate it. Absolutely Chris even before we get into jail you the company you work with give people a little bit of your background sure thing.
I've been in it for about 20 something years and with a primary focus on information security and Assurance for about 17, so just have a couple certifications from vendors such as soccer competea Cloud security Alliance and have a versatile background from Department of Defense to manufacturing and pharmaceuticals can tell you how happy you Me saying information security and not cyber. Yeah, that was my generation too. We called it info second.
Yeah, and my company now is focusing on saying cybersecurity. So I'm kind of having to change up my speakers. All right talk to talk but it's information security.
Anyway, Chris talk about you company a little bit perfect. Yeah, so I work at jabel used to be called jayble circuit primarily founded in 1960s, and it was on a Michigan and now they're headquartered in Saint Petersburg, Florida and primarily I mean manufactured Global manufacturer from Plastics to chips and branching out into medical and automotive and things like that and broken up into new divisions and in about 30 countries. Not broken up into separate companies, but you know different not many years.
Yeah, we have big manufacturing presidents in Mexico China some of our big manufacturing plants were overseas, and we're in Europe as well South America Brazil, so that's great great stuff. And what I'm sorry, if I didn't ask before what's your role there? My role is a global cybersecurity manager and I take care of the engineering and operation.
So any of the products that we purchase at JBL that keep the lights on so your antivirus your firewalls anything that keeps the company safe my team and I handle the operations. So something breaks an outage is reported my team and I will jump on it and you know put out the outage to keep the lights on so it's 24/7. We have a follow the sun approach.
So that's why we have a large team in Penang Malaysia some representatives and Ukraine and a large percentage and you know the United States so we do try to follow well with the footprint you guys have you have to absolutely absolutely sorry. So what brings you to the QSC quality show. Well, we've been using call us for about nine years at jabel when I came on board to jabal and 2015 we were using it.
So I've Using it for about seven years now, and we've built up a really good partnership with koalas and they invited me out to talk about how their agent software has benefited us and reduced risk, which is a great thing. Absolutely and you know, that was a big Look, I've also been in the information security business a long time. You know the move to an agent to do scanning so it once upon a time we used to have host space scanning.
And network-based game, right? Yeah, and that Network base scan you gave you that, you know, I in the sky yes hackers. I view agent base scanning was something different for host space scanning it.
And it was kind of never the twain shall meet but then someone put peanut butter in the chocolate, right and and we realized this isn't a bad idea because I want to get both views. I want that 360 Degrees view. It's funny.
You mentioned that because that's what I'm gonna be speaking about tomorrow is we have taken a hybrid approach to vulnerability management scanning because there are certain things that cannot have an agent. That the appliance scanning Works optimal for then you also have things that the agent works even better because you have real time scanning. We have threshold set to where instead of some of our csos and executive teams would say hey get me a vulnerability report.
Well, it would take hours to do and scanning Cycles would take sometimes a week for some of our larger manufacturing plants that have maybe over 10 to 20,000 assets. Whereas Now with an agent the Manifest following the agent every four hours. It says, hey, I have a new vulnerability send it if nothing after four hours, you're good to go why that's effective is because real time so when log4j and print nightmare came out so many Security Professionals if they didn't go agent based you're like, okay.
Well, you know, my skin is gonna finish maybe in three days. Tell me what see so security professional can wait those three days wait 72 hours and go. Okay.
We'll see what happens. You gotta have closer real-time as possible information on your assets in the security status. So that's why it's benefited us and we've driven risk down absolutely, you know to me this story here is is part of this whole movement to what continue is security.
Right, we can't afford to say well boss when I did a snapshot two weeks ago. This is what it showed right when something like a log4j, you know, that was unknown. Or you know, that was last year's War whatever the next one is.
Yeah. We've done information continuously near real time. And that's why we partnered with quality and are very happy with the product because I think it like anything the security as you said you came from security background as well.
The company and the status of vulnerability Management in 2015. When I started a table is Light Years different now old methods of old detections. And as you said well, we'll get a report to you soon.
I don't think companies can afford that anymore because of ransomware attacks the complication of things that are out there. You got to have a tool that can Empower you to get as close to real time because that's how you're respond and I remember being in the office when I forgot what it's called. The ransomware attack that locked.
The machines was 2017. I forgot what the nine heart, please. Yeah, I think it was yeah.
Yeah when pet you came out that I was a Friday afternoon and I was like, oh my God come out, right. We we got P1 P2 calls and you almost like wow, how come we couldn't detect certain things like that sooner and that's where the agents helping us out the no dad. The agent part of that is huge.
You know the other thing In what you were talking about here that we can't afford how the things have changed quite frankly. The speed of business has changed right when you're updating applications multiple times a day when the average lifespan of a container using containerized apps. It's something like five or seven seconds right when they sure.
Can't afford to tell me what you scanned yesterday, right so stuff change today and with that speed of business. They're not gonna wait for you. They're gonna if you don't have that but it's Full Speed Ahead Damn the Torpedoes, right?
They're not waiting for your vulnerability report. Well plus it. So in manufacturing okay time is money, right?
I know I know that for a lot of companies don't know but it really is so if you look at a if you look at an assembly line, okay, and let's just say we have servers that control a widget maker whatever you want to call it. If that is compromised a subnet of servers goes down that happened to control an electronical arm or something that cuts a diagram or whatnot. If that's down we are contracted to these companies that we have to get so many widgets out the door.
If we do not meet those those contractual obligations. Why do you want to do business with jable go do it with somebody else. So that's why time is money.
0 or something like that. We know about it by using dashboards by proactive scanning real-time thresholds. Hey, I might not be able to tackle it immediately, but I can be in the ballpark instead of waiting too mitigating.
Yeah, right. Actually nobody get all the patches that it may have to test. Yeah, of course, but I can mitigate and when my sister comes to me and says, hey, you know, by the way, are you aware of the new threat we can say?
Yes, sir. We pulled up we pulled up the cve we have information. I like to get you I can get you a quantity of that and I can least get you an idea of the scope what we're dealing with.
Absolutely. I I agreement and that is that's where Security's heading and quite frankly look, you know, I've been in this vulnerability space a long time. That's the difference between where we were 10 years ago seven years ago and today it is that real-time continuous.
Would not fixing everything immediately right blow smoke up anybody right? You know, but We have much more insight real time. Yeah into our posture and I think it breaks down.
You know, what we're working at at jabal is there's it's one to punch. There's vulnerability management, which is your detection and then there's vulnerability remediation and and there are different focuses sla's when it comes to that. So, you know, it is different Beast.
Absolutely. Spell jaybo j a b i l. com.
Yes, sir. All right, you check it out Chris. Thanks for stopping by.
Absolutely. I simply you have a great presentation looking forward to it. If you're in town tomorrow is he doing these?
I will all right so much. Chris are from jabal here at qualysis QSC 2022. We're gonna take a break and we'll be right back.





