Eugene Ostapenko, Illion | Qualys QSC22
Eugene Ostapenko, the head of information security, risk and compliance at Illion, joins Alan Shimel at Qualys Security Conference 2022 to share how to provide better security, and how to better understand costs involved and how to be more efficient with spending.
Transcript
This is texturong TV. Hi everyone. We're back here live in Vegas for the koalas QSC 2022 show where we're in the home stretch kind of right?
We're in the afternoon of the second day. One of the nice things we've had the last couple days though is we've got a good mix of guests on here. We've had some interesting security practitioners.
We've had quality people. We've had analysts. We've had good mix of people.
I'm really happy to introduce you right now. Eugene osteopenko Yes. Yes.
Okay. Got it. Right Eugene is a seesaw and he from all the way from Melbourne, Australia.
Which is a bit of a ride from here and we're happy to have them Eugene. Welcome. Why not you if you don't mind tell the people a little bit about your background and your company?
Yeah. Thanks Ellen. Thanks for the introductions.
So as as Ellen said, I'm Eugene espinos. I'm currently head of information security risking compliance for alien. It's about a month full of my of my official title.
But in effectively I run information security practice some acting as I'm working as a size for the company size will be saying in Australia not see so yeah, I know Toronto, okay. Yes, but it's been beautiful learnings for me. So Elon is their data analytics company.
So we Our data is is there set on consumer commercial bureaus? So what the bureau is we received their financial transactions from the institutions around Australia in New Zealand. Then we compute this data.
We apply out our analytical. Logic in there and we generate credit rating scores. So when the individual or the organizations want to take a loan they would request their the credit rating score from ourselves and provide for individuals.
It's for business credits for both. It's their individuals. Yes.
Well, that's right because as you say here in the US, of course Diamond Bradstreet does a lot of the business ones where the personal is more experience you expect Equifax the other one and for those of you who may not be familiar with the company a lot of companion. Gene was telling me it it was the Australian New Zealand Dunham Bradstreet. Yes indeary, that was spun out.
Exactly. Yeah, so they're done in Broad Street in 2015 private Equity company have purchased done in Broad Street and they renamed it as Elon and since then we've been in the competition so it's just oh good. Absolutely.
So to put it in context, we have 25 million of our personal records in our database total astronomy population is 30 million about 2 million of their commercial energy. So the dates are security is fair amount for us. It's it's so life blood really absolutely.
Well look we served here in the US with the Equifax breach a few years ago. It was a crazy number like 400 million records. Yeah, something like that and you know, so when when someone in your line of business gets breached, it's big it will be good.
It's bad. That being said you're here you presented at QSC this year. If you wouldn't mind, would you share with the audience a little bit about what you presented?
Yes. So as a sizer my role is to keep the company secure. I'm responsible for that in order to do so, I need to operate as a business stakeholders a business member.
So therefore for me it is important to operate within the funds. I'm allocated for a year and to do this as cost effective as possible. So what I was presenting the callous conference is how to do more with security and example, I was giving is using a call this Cloud platform as a way to consolidate the security processes into a single platform and thus reducing the total cost of ownership.
So I was looking at their direct savings the course savings associated with the licenses as well as their personal savings where they're the time freed by my team is a reinvested into the into addressing other risks outside of the platform. So that was their all I thought I thought was taking well and yeah, there's a lot of questions from from people just are outside of their out of the side of the presentation, you know. I've been insecurity for a long time 30 years.
I've had this discussion with a lot of security people. First of all, it's near you know, could you actually prove an Roi on security? It's a very kind it used to be very controversial subject.
But that goes hand in hand with kind of what you was speaking about, which is how do we get a handle on our costs of security because traditionally funny I would sumed this some quality. Yes was our last guest and we were talking about this very issue. Right managing risk with security.
It's a question of dollars and cents and for too long, and I'm not blaming you but too many cisos insecurity. say if only I had this new technology that new tool this many more people. I could I could really.
do the job And then six months or a year later. Well, I need one more thing. It's new thing.
There's a new thing that that's actually you're right. I mean it in that's where I think are. The sizes would differentiate, you know, we have our sizes who are very focused on technology and they believe they're, you know, a technical solution is gonna solve the problem, right?
It is not so it's a combination of the factors always people always processes always technology sure now none of those three guarantee absence of a security breach. So the bridge is inevitable it would happen to any organization as much as I hate to say that that might happen to Ilan my job as a sizer for company make this bridge. As you know as rare as possible, so trying to reduce the likelihood of the bridge.
Seeing if you know if that breaches I could occur then. My next stage is actually to reduce their their to use the impact have a faster response. So, I'm quite.
Clear in my mind that it is impossible. No matter how many tools we have how many how many? You know things with throw with security It's never enough.
I mean if they're you know, large corporations governments get breached. I mean, we are mid-sized companies. So I'm being realistic there.
We will not we will not be able to compete where we will be able to compete is actually, you know, doing things smarter doing things faster having more agile response practices having maybe, you know easier access to the products and and just just work smarter not harder but breaches and absolutely life. So without giving out any confidential data or trade secrets. I've got a whole audience out there.
It's probably about three to five thousand people watching this right now. What can they do to? Be more efficient with their security spend.
Right and get a better return on what they're spending. I think I strongly believe that the one of the best investments the company can make it's actually their breach response plan. It's not technology.
It's not people it's the process and these Bridge response plans should should absolutely be developed in conjunction with their with the sea level with the board. So you have to take your business through our certain Thinking process around what would be the business response to security Bridge? Yes there the team and security and decisive will work to as I saying to mitigate the likelihood and integrate to impact it's available.
So where where I believe that there are more resilient companies differentiate from our from the companies that fell apart. Is there the leadership of the executive team the leadership of the board and being able to manage public relations and be managed to you know, the customers and that that's that I think that's that's one of the most Vise Investments and it's not that expensive can considering that you deploying the tools tools are important absolutely but they're not guarantee. So absolutely and look there are but it goes back also to what you said people process technology.
This isn't strictly a security Back, somebody people processing technology is what we used to solve many business processes. Yes. But you know what you're right process sometimes.
If I had to put a dollar value on what it costs to implement these things process is probably a little structurally today a lot less money than people people are maybe your biggest exactly. Yes and Technology, you know, as I said, there's always another tool. There's always another new drink it some shiny thing.
They want to buy In God now what I was going to say that in 2022. To be absolutely Frank. Most of their security Technologies could be considered as a commodity.
So go on the market. There are thousands of the products really there. So can replace one product with the other.
So it's it's really what do you do with the technology how you've integrate with your environment? You know, what what while you driving from that and what that value costs you are how much how much effort actually spend so and I think that's that's a real art really of security to take those Liga but blocks and just put them into our shape. Yeah real thing.
So we're here at the koalas conference. Let's talk about koala specifically. What are you doing with the and there's the koalas platform, but there's like 20 different products.
Yes, right that are all part of this platform if again without saying anything You know proprietary. What are you doing to help save money while it's you know, I'm assuming you are utilizing these qualities. How are you doing that to save money?
ah, well the biggest Savings Factor there in college we've been using calls from 2019 and we started with the vulnerability management module. That's what was our initial requirement and as covid heat and other things developed within within within the industry within Ilion, we started, you know, bringing more and more modules. So I think there are two major factors in consolidating the tool set including qualis.
The first one is their cost. It's more cost effective to purchase a license to extend existing solution than to build a whole new solution. So as an example callus has a patch management module.
Are we using for subset of our assets? It's much more cost effect. It's more cost effective for us than to bring another another totally separate Solution that's on the licensing front and the implementation cost.
The other factor to consider is actual a personal cost associated with training people getting to use the product again in the maintenance and and other other activities done. So human capital is yes, one of the most expensive categories on Securities. So optimizing their effectiveness of the information security team is a big plus of consolidation another our factor that we found useful in integrated tool is there Ability to have a better relationship with other teams around the technology.
So the security operations or security systems teams are usually focused on detecting vulnerabilities. Now, we have operations team that you know are tasked to resolve them to patch them. It is very powerful.
security collaboration where I would go to my infrastructure team and I'll say well you can patch that. I will give you not just the ability to well. I'm detecting vulnerabilities, but I'll give you the an option to do patching more effectively with the patch management.
It's then we are focusing on the single source of Truth in this case call us vulnerability dashboard. So we also look at the same data we'll work with the same input information and therefore it just makes it easy for everyone across the board. So and yeah since impeachment management we keep we keep expanding this the quality.
It's it's a natural growth for us. We looking at different modules and yeah bringing more and more teams on the journey and saying well let's let's work together on a single platform, which I believe is very powerful and brings the brings people together. I love it Gina.
I want to thank you for coming all the way here for more, Australia. To be on text drug TV. Thanks.
Seriously. Thank you for coming. Thank you very much sharing with us.
Best of luck. Oh, thanks. Let's hope we don't hear about any breaches at your place and meet you're on the job.
So it's all right. Thank you. Alrighty here nice today.
All right, we're gonna take a break here. We'll be back in a moment from Las Vegas for Quality QSC. Stay tuned.





