Frank Dickson, IDC | Qualys QSC22
Frank Dickson, the group vice president of security and trust for IDC, joins Alan Shimel at Qualys Security Conference 2022 to share the services IDC provides as well as discuss data and network security and the four control points of digital transformation, among other topics.
Transcript
This is texturong TV. Hey everyone. We're back here live in the Venetian for qualysis QSC 2022 conference.
I hope you've enjoyed our first morning of coverage. This is our first interview after lunch. I want to introduce you to Frank Dixon of IDC Frank.
Welcome. Thank you. Thank you for having me.
It's a pleasure to have you on actually why not you introduce yourself, I'd okay. All right. Yeah, so I'm Frank Dixon.
I lead the security practice at EC so they technically call me group vice president, which means I run a team of 19 to 20 different people covering everything from network security and firewalls all through risk and compliance and Trust. I mean we cover the gamut 20 people can do a lot. Absolutely that's a huge research team.
You know, that works security and firewall is that It really has I mean for so long we was so focused on the app SEC appsec abstract abstick, but we're starting, you know, data is becoming important. Yes security. And network security Yeah, we actually as so in about the 2018 time frame we start articulating how what we thought were the four new control points of digital transformation.
Right? So we talked about endpoint security, right because we saw like if everything is encrypted Like you can't see anything, right? And so you're going to have to be able to apply security where things are not encrypted where you can see and we can Implement something.
So we said the end point is going to be important. We talked about application security. Right if if all our applications are moving out of data center and going to the Cloud app set because especially as you start moving to sass so there was a second Point third one right data, you mentioned it, right?
That's what everyone's trying to get to and then the fourth one which we it's funny. Well my first presentations at IDC what six seven years ago was identity is a new perimeter. Guess what?
So it's still it's like a friend of mine went to the the share farewell tour and he said hey, I'm going to share for world. My other buddy goes. Well, I went to that door five years ago.
Same thing with the Elton John. Yeah for Pro for being in Vegas. Yeah.
We take a long time. Goodbye. All right, and so yeah, so like the money.
Yeah, but you know, if you know mine, let's dive in on sure identity thing for sure. So I owe you know lately the last couple years I call it I am because that's what I did an accident. Absolutely.
But what I've seen in the last year is sort of identity and access being bifurcated like okay first, let me prove your Frank and that's a whole different. Right one set of facts proving you really Frank right now that I know you're Frank. Where do I want you to go and want to you know from the zero trust the whole thing.
What are you gonna have access to what data and everything else and where it used to be identity and access we're joined it to hip. I see it kind of breaking out. We're just because like there's a separate control plane if you will for your access from your identity.
and maybe because where you're at your accessing stuff all over the place, right third party sasaps and and cloud and here and data and So it's a really great. It was a really great observation. I was pausing for second to let your concept breathe because you're exactly right we talked about identity in the first thing we do is go MFA.
right like Well MFA is great. I'm not like I don't know MFA but yes, there is a there is a separate plane about access and there's also the really really smart people are not just talking about access to talk about authorization and authorization platforms and how we're authorizing and as we talk about and so that the a lot of the issue that we deal with the identity. Is it identity lived in this cluster over here.
It was an identity person and we left them alone because it was I was ugly. Like let's face it identity is not been well maintained. So we you know, we talk about directories rights and directories, right?
Yeah, and so it's not maintained life cycle management. Okay. Didn't mind it was the hidden Microsoft right?
But there's I I almost add a third. Third piece your triangle. So as you're talking about you're right.
There is this whole idea issue of are we authenticating to that directory right in in some of the smart people actually talking about proofing that identity to make sure we are who we say we are right and so once we get to that directory, how do we manage that? And then once we manage that how do we authorize it? There's another context now and it's that need of security people to ingest identity context to be talking about threat mitigation, right?
And so if we if we look at a really basic example, right the one of the key trends now is living off the land attacks, right? We're not going to use any malware. We're just going to use power shell or Cobalt strike or maybe cats.
Yep, like all legitimate applications that we use maliciously well a Powershell script I don't know if that's benign or malicious. Unless I know the identity contract that's it could be both good but you know, it could be both Schrodinger's cat depending up like if I'm if I'm an IT administrator, I'm using it. Yes of and so this we're seeing a lot of cyber security companies now either buying identity companies or launching identity feature right this event right quality, you know, they've launched a whole bunch of identity-centric features not for the identity folks, but for the security folks, right, we're gonna apply identity context and it's it's a it's a quiet movement, but it's big it's just rolling powerful it is I agree with you and I think this goes to what I was talking about this bifurcation.
Yeah. So you heard it here from Frank Dixon first, finally the year of identity here. Yeah.
It was a 2010 but it's coming it's coming. Let's talk a little bit more about the the quality thing. Sure, you mentioned the areas look.
and point I'm of an age you're a contemporary. There was a time where I was so soured on endpoint security that I virtually gave up on it. I'll be honest.
I feel like you know at Microsoft's giving me free stuff the max pretty safe. I'm done playing with this bloated. Pig where they want me to put on the machine, right?
We are we went through that and it doesn't work. Anyway, what does it really stop and here in Vegas bloatware went to Pig wear but okay good. We're good.
Well, but anyway love it, but you know with this whole xdr and and EDR we we've seen a Renaissance of endpoint security I think. Yes, okay, I think so. One of the things it's it's funny.
So we we have this snarky comment. We make when new things come out we often talk about. Okay, is this is this PowerPoint or is this product right?
And so I think for a long time xdr was no doubt was popular. We just got done with the survey and we were asking about ransomware. Okay, and so for your recent ransomware attack, how did you detect it?
We've actually run this three times. And so we asked about the tools. Well about six months ago.
There's always potpourri of tools. two things in this recent swing happened one was We saw this massive increase in terms of the leveraging of sim. EDR ndr and if you believe it or not full pcap solutions for detection of rents aware.
It was like weird because some of these other ones like deception didn't change or some of the other ones like they're only features like it's interesting that those kind of activity-centric tools and detected the second kind of thing that we noticed is and I go oh kind of interesting the math didn't seem to work for me for a second and I was like all these tools and so I added up the number of tools per detection. 6 which means more tools which is directly and what is what is xdr. We're linking tools to become up with detections, right?
And so it's like this vaporware, but as you talk about endpoint Solutions once again for new control points, You know, how do you detect? Ransomware or any other without having visibility at the end point right? And so I think I think that's a critical point.
Yeah. I know she gave up on it, but come on. Oh, I have we've come back.
Well, I'm talking look. I got a little bit so the company but where we're on the xdr train and and the detection. endpoint EDR train an interesting thing that you know, it's funny that survey you mentioned.
I'm pretty sure Mike wazard on our team must have interviewed someone because I remember reading about it and on Security Boulevard at some point. Yeah. Yeah.
It's it's but it is I mean look ransomware. Ransomware was probably one of the two big stories in 2022. I think insecurity along with maybe supply chain software.
I don't know why change I don't know if I necessarily no, it's huge. It's a huge story but like here's like So I I went back I actually wrote a report just because of the kind of that engine. So when did ransomware start 1989?
Oh, it's been around forever. Yeah, so we always talk about like why was huge last year like it was 50% as big last year, but it was 50% as big the year before and 50% But and if you look at the ransomware the ransoms we've gone from like 2013 where the average Renton was about 150 bucks to millions, and it doesn't it didn't go like this, but for me what happened Frank It became like Murder Inc. It became like organized the the ransomware industry if you will not yes, you should yes the bad guys the bad guys.
They went corporate. I mean they're organized man. They are and in the thing about ransomware.
I think that gets misunderstood is we we talk about ransomware like it's software. Is not the ransomware it's the attackers to your point. It went corporate.
And so it's all about what we discovered is if we launched at ransomware when we're connected to a network store, like people are going to pay right. So let's go find the Network store and let's go find the network Store where the more money and then let's exfiltrate the valuable data. Like it's just like they're not dumb.
They're really smart clever folks the whole concept of negotiating with terrorists and honor among Thieves, right? So let's think about this. You so big ransomed me.
Right? Well, you know, yes encrypted all my crown jewels. Yeah, and you're asking for money.
Yep, like a kidnapper and you're gonna send me my son's year or finger to prove you have all you don't have to because it's I could see my stuff's all encrypted. And now I'm gonna trust you. Yeah to pay you the money and then you're gonna unrans somewhere me or you can unencrypt me and I'm I'm not worried about you leaving anything behind that's gonna allow you to do it again.
I'm not worried that maybe you downloaded a copy of it and sold it to the next bad guy to do something and he sold it and so on down this chain, you know of the bad guys. But it's okay. I'm gonna write you a check for a couple million bucks or a hundreds of thousands of dollars.
Yeah. The whole thing to me is wrong, right? I feel like Al Pacino and just as well the whole system is the system is screwy.
I don't know and I don't but I don't have an answer. I hate to like point the problems and not even have a clue on now you fix it. But it the whole thing is crazy it is it is and you point to some like the last survey we did 15% of people that paid the ransom didn't get their day back.
Then because you negotiating with terrorists, right and I'll tell you another thing that I see is a problem in the industry is that hey, don't worry about it. Just get insurance what the insurance company worry about it, right? I interviewed.
I'm not gonna name their name, but I interviewed one of the Cyber insurance providers at RSA last year. They were like, oh where where the rent somewhere experts if you get ransomware don't even talk to them come to us. We know all the different gangs.
We know what the going rate is. We'll make sure it gets done and it's almost like are you an insurance company? Are you my ransomware negotiator?
Yes. Because I don't think one's necessarily the other but and that's and that I'll say it on lifetime. That's a s***** solution.
To Red so well, it's an insurance guy was about to Temporary solution. Right? The one the one thing that we learned is that digital transformation it business evolves faster than the protections and so it'll evolve like what we're here we're talking about.
How do we start evaluating risk and then and as and it is interesting because when you start talking about risk Transform the whole conversation right now. It's not about security it's about risk and what is risk being risk implies and outcome, right and risk implies a business outcome. So now we can start elevating these conversations.
So hey, if I'm more secure then theoretically my wrist goes down. My premium should go down right? So now awesome we got to cause effect.
I really think as much as we as much as we want to hate the security industry cyber Insurance might be the tool that fuels us to mature our our conversations from talking about security talk about risk. It's every good friend Alex Hutton. I know of you've ever met Alex he was at Zion bank.
Then I think he was a B of A. And I forget where Alex is now. What's the big risk group?
So now Prophet. Oh, you know who I'm talking? Yeah.
Remember their name this right? But look, this is something we've been preaching insecurity we have for a really long time right? It's about security cyber or infosec.
Whatever you want to call. It was about managing risk. It wasn't about Making us that we never have an attack or that we never you know, I mean, yeah, we can unplug everything from the internet not be connected and hopefully don't you know, we're at fault.
We are at fault, right we talk about it's all about reducing risk. Okay, great, but we don't manage to that. We don't what do we do we go to our board of directors.
We buy shiny new we buy shiny toys and we go. Hey Mr. CEO, we addressed 4,000 alerts last month.
Pretty damn good pretty good. Yeah and see you goes. Am I safe?
No, no, no. No, you don't understand. I don't know.
I patched 4,000 vulnerabilities. What does it mean deadly? What does it mean?
What does it mean right risk is about a condition risk is about the about an outcome, right? It's about it's about am I safe like it allows the board to make the decision. So we need to start evolving our it's our fall.
Until we look I I hear you preaching to the choir. It's why I said on this side instead of that I had enough time on that side there but you know That's a really hard question answer because I've been at you know, there was a time where we saw the business. I started 60% of our business was DOD and fed.
Yep and stuff and I got asked that question a lot. Are we safe? Right and I can't tell you if you're safe.
All I could tell you is how we've managed the risk and your percentages are but that's like asking who's the guy Nate silver from the from the polling thing who's gonna win the election? All he could tell you is going on. I take all the polls and run them together.
These are the chances 65 times out of a hundred that one wins. To a certain extent I think that's where we will that's the best we can hope for with security is give you sort of that sort of odds if you will or percentages. I don't think I will ever be able to guarantee someone no safe.
I think we're getting better though. I think we've ironed the corner. Hey, we've gotten a lot better.
Yeah. I look back to where we were, you know, as I said over the last 25 30 years. I've been involved in security.
it was Child's Play Back Then I mean it was really Really I think about I mean you've been at this a long time think about the 2014-25 2015 time frame post-target breach. What do we do? We threw we threw crap at the wall.
Let's see what sticks see what stuck like we are vastly better than we were and and it seems like we're starting to get a little bit ahead of the attacker and I I apologize. I realize what I'm saying is sacriley grandmother would be upset that you even letting that out of your life. I know but but yes, but yeah.
No, I think I think we're starting there's a maturation happening or definitely a mattress and we see I'll bring it home to this QSC thing. Yeah. We see it here.
Yes. Yes. Okay.
I was I remember when Philippe started. Koalas because that's true. I was a competitor.
I used to think he was crazy. and but they were strictly a vulnerability management, right and you come here now and you see all the things they're involved in and how It's not that they're bringing it all together making a more holistic of a better view into your security posture so that you could better manage their elevating the conversation no doubt patching stuff to creating outcomes and part of that by the way part of that is just making things easier right security people are expensive right holding on to them is hard. Like let's make it easy for like like there's so that like I say, there's the you know, the messages that you hear companies like this this week, you know, it kind of elevates the conversation to outcome Centric.
God bless it. It's about time. It's about time.
Yeah, I you know, I always thought in my career time we wouldn't see it, but maybe we will maybe yeah if I stick around a little bit so for us anyway, hey Frank for people want to get more information on IDC. And yeah, you work. Where can they go?
com like I'm easy to find. All right. You so much appreciate I share also mentioned Frank is doing a keynote was I am tomorrow tomorrow?
Well, you probably not if you're not here in Vegas already, you won't see it because it's not virtual this year, but you should check it out and usually the quality people put it on after anyway, but they should but if you are here come check it out this QSC show. By the way is free. If you if you're in the Vegas area, come on down.
Anyway, we're gonna take a break. We'll be back in a bit here. We're live in Vegas and quality QSC 2022.





