Jonathan Trull, Qualys | Qualys QSC22
Qualys CISO Jonathan Trull joins Alan Shimel at Qualys Security Conference 2022 to discuss the priorities of security teams heading into 2023.
Transcript
This is texturong TV. Hey everyone. We're back here at the koalas QSC conference 2022.
We're at the Venetian in Las Vegas. And our next guest. I'm really happy to it's first time every interviewer interviewed him.
Jonathan told Jonathan is the ciso of koalas and hey Jonathan, welcome to text drunk TV. Yeah. Thanks for having me excited to be here.
Absolutely. So Jonathan you've been see so about a year over. Koalas.
That's right. If you know my share with the audience a little bit of your background sure. Yeah.
I am, you know, I've been in I guess information technology and intelligence for quite a long time. I was a lieutenant commander in the Navy did Intel work there. So there's a lot of application from like physical, you know National Intelligence to cyber security from there.
I was with the state of Colorado is the ciso and worked in the security department for 12 years spend a good run at Microsoft where I ran the global Incident response team, so 300 incidents around the globe, you know visited 18 countries with with teams of reverse malware reverse Engineers incident responders infrastructure Specialists. A lot of ransomware attacks that we would go and and help large Enterprises recover from and then I've landed at qualis as as cisa. This is my actual second stance as see so it qualis so I had a brief stint about six years ago.
funny as I told you I was in the security space a long time, but security company, I co-founded called still secure which based out of Boulder and we had state of Colorado as a customer back then at the time. It's going back 20 2005 to 2007 time frame. Yeah, they were winning a lot of awards there because they really stated the state of Colorado had a great.
Yeah, but we call that info SEC not yet, right? Yeah. I had a great info sec.
Department and program there. Yeah. Yeah.
I ran a program there called secure Colorado really to Centralized security ended up working a lot at the time with the gentleman named John strufert who was there with the Department of Homeland Security around the continuous Diagnostic and monitoring program, and we really wanted to take what was really what I thought of best practice at the federal level and adopts kind of our state version. And then also I mean at the time we were Maybe even before I guess all of the election kind of issues popped up. We were very focused even back then on, you know, helping our secretary of state and our counties secure our election systems, you know before it was I guess fashionable and I I really is we're here the day after election day, right?
So we didn't well we haven't heard yet of any kind of craziness, but You know it farther for another conversation. Yeah, well text drug TV, but unfortunately the drop off a lot of times from the federal level. Of like vulnerability management and cyber in general to State and local sometimes can be drastic.
Right? It's very choppy state to state. But I wanted to talk to you more about going on here at the QSC, you know our audience sitting at home saying well, it sounds like a quality user conference.
I know it is it is not going to say it's not But I've been going to qsc's I think since Philippe started them years and years ago. And I've always found them a great industry event a great a great Forum to speak with peers to talk about. Relevant topics.
It's not just all quality product all the time. No interested in your take on that. Yeah, I would agree.
I mean I think well it is, you know, obviously branded as a quality conference. I mean, there's cisos here from you know, government agencies Health Care manufacturing Financial Services, you know, there's security Engineers that are actually implementing and working in different programs. And you know, if you look at the the new products that that we've introduced over the last couple of years, it's not just vulnerable management anymore.
Right? It's web app security web app pin testing. It's patching and Patch management.
It's cyber asset inventory. And so, you know, all of these the industry's been struggling with, you know for forever right since the beginning and so, you know, I think it's a lot more about the dialogue and and learning best practices from peers. And you know, how do we do this?
Well, how do we move more efficiently certain extent, you know? All constrained with budgets and the macroeconomic conditions. So there's a lot of talk about, you know Automation and how do we optimize the resources and help us focus on the most important things and I think that's where a lot of the value comes from this conference.
Yep, and you know, well obviously over the last well last year was in person but it was hybrid, you know virtual end in person. I believe the year before was virtual lonely this year. It's not virtual at all.
It's all in person and one of the nice things I don't know if our audience can see because it's not like we have it's not a big backdrop. It's real right. There are people here and they're talking to each other right and we don't get that in the virtual space.
So to me, this is Plus why you want to come down meet with people and really talk some of these topics, okay? Jonathan 2022 like most years in security has had its challenges. Yeah, it has right we have had.
We've had some duties ransomware is crazy. Everyone talks about software supply chain, and that's bomb that's bomb this and that. For you, what are the big stories for this year around cyber?
Yeah, and I I think obviously open source software has has gotten a harder look right. We've had some vulnerabilities that have come out and it doesn't mean anyone's not using open source software. It just means we're now having to really consider.
How is it supported? How do we keep track of it? You know, it goes back to inventory but again inventory has been hard, you know for a lot of companies and I I think you know with the presidential executive order and you know s-bomb and a bill of materials is a big topic it's in it's hard to get into it, but it is a very critical aspect for our industry and for me as a Cecil of a software supply chain company, you know, there is a there's a lot of emphasis from our customers that I do have full control over my supply chain, and that's a very Allocated task and we're working very hard on it.
I know a lot of my other peers are working very diligently on what does it mean to truly Implement, you know a supply chain security program and to deliver an s-bomb that people can rely on it, right that makes sense to them. So that's been a really big topic and unfortunately like you said from the internet response standpoint, you know still eighty ninety percent of the attacks and I see a ransomware related, you know, unfortunately, it's causing a lot of pain. I'm not sure I have anything more to share.
I mean, it's the same tradition. I I don't think it's you know, good. I think yeah what we're seeing out there is become almost just common.
Meat and potatoes kind of things quickly on the issue of the open source. I think there's certain extent open sources almost been a victim of its own success. You know, I remember and I'm sure you do too.
I'm usually say mac was so much more secure than Windows, right? Well when Windows had 95% of the market and Mac had five percent. It wasn't as big at Target now.
I don't know what it is now 75 25 or whatever Max certainly is more market share than he used to and you see attacks on Max now, maybe not. Windows isn't what it was either. They're both I think much more secure than they were in the nineties.
Yeah, really 2000. Yeah, but open source is everywhere something like I forget if it's 98 or 99% of Enterprises are using open source software within there really I'd be shocked. If anyone in the world of any size didn't have some component of Open Source, you know, either a small library that the dependency of some code, you know, some Docker instance, it was pulled down because it seemed to easy to use it was, you know, put up in some repo and share it out.
And I think that's why the the challenge of securing the supply chain is so difficult, right? Yes code that's openly shared and a lot of developers share openly right and freely and and even whether they license it is open source or not. I mean, they're sharing their code and sometimes the attackers know that and they have time squatting, you know, that will trick developers into downloading the malicious about the wrong containers.
Yeah. You know what, I think that goes to fundamentally. com in 2013-2014.
And one of the trends I was seeing then was the change in the way software was built. It wasn't just an engineer sitting and writing code from scratch right in many ways. They were assembling.
like a supply okay exactly, right, you know building an application and and so when you have that all of a sudden that software supply chain becomes a big deal. So that's certainly a huge Vector you mentioned the ransomware. you know as much as I hated and I Marvel at the Organization of the bad guys, you know, I don't know how you solve that.
Right? Right. Yeah.
I mean, I don't think we're gonna solve that like policy related or through criminal sanctions. I mean it it's just too complicated. I mean, I think you know, we're I I like applaud the people that are trying to bring you know, those actors to justice but it there's a lot of political complications and people that are Out Of Reach depending on what country they're operating from and I think what we have to do is we have to and a lot of companies are doing this now saying I'm gonna have a ransomware threat Reduction Program, right?
You know, I think if you don't Focus your energy right controls can slip and so if we know ransomware is, you know, probably the leading risk factor for a lot of us we have to have a ransomware response program. We have to evaluate all of our controls against what ransomware would normally get in our Environment move laterally and I think we just really have to focus on it and you're starting to see a lot of programs that say listen. I'm going to have a ransomware Reduction Program and that we're going to focus on all of the ransomware families how they get in how they spread we're going to design controls around that and I think it just takes that level of emphasis now Enterprises can do it.
I think it's much harder for a small business. Right and that's where a lot of the attacks are happening. Yeah, and they're hit and run.
They make their money go. I realize you're to see so equal. It's not the product guy.
But what what you know you haven't xdr and and you know, what is qualis doing anything to help maybe the mid Market with rent somewhere. Yeah, absolutely. So, you know, we've released our new EDR products and xcr I think are the top of really helping prevent ransomware attacks executing on an end point or detecting them quickly and then on the vmdr side, which is I mean been a Mainstay, but I think the thing is now using threat intelligence, you know, we say these are the ransomware families.
These are the specific vulnerabilities that they're leveraging patch those first and foremost, right? Let's make it easier. Don't try to I mean most failures of vulnerability programs in my opinion are treating everything equal, you know, and you get 500,000 vulnerab.
And you send a report over to the IT team and they're like, oh my gosh. I hate you guys in security right like stop sending me this. When in reality like let's focus, right?
There's five vulnerabilities that if we fix those it'll reduce our risk of ransomware. So I think it's you know, helping people prioritize and so I think that's really push to and that's always been. Yeah Pig just one more area.
I want to cover with you if it's okay 2020 for you Siri with two months out from the new year. I'm sure rent as we said ransomware is not going away software supply chain. it's gonna continue being a big thing, but security is As big a priority as it's ever been.
Yeah and everyone I speak to. What do you think for 2023 are other areas that we maybe haven't mentioned yet that we should be looking into or be cognizant enough. Yeah.
I'll be honest with you. I don't think the industry has fully matured with the Automation and the automated responses as much as we had hoped. You know, I think there was great promise and sore and yeah, this is gonna limit the need and you know, we won't have to hire as many people and and honestly, I just don't see that that's played out for the industry.
So I think we are experiencing some macroeconomic conditions. Maybe not in cyber, but there's some pressure to say, how do we do more with fewer resources? Yeah, and usually that leads to Innovations and automation.
I would I would hope and then I I think on the attack side. Well, we have the continued to tax that we have. You know, I I am nervous about the just enormous growth of non-traditional Computing devices and and how we handle those and and I think you know, luckily we haven't seen a tremendous.
We've had a few Colonial pipeline a few others where we've had like OT system impacts, but you know, the more that we have embedded Computing and like very physic physical oriented devices that have true life safety risk. I think there's going to be an emphasis, you know, there's gonna be some issue that's going to transpire that's going to really call attention to a need to better regulate, you know, look for some Solutions in that space. Other than what we have right now, which is unfortunately kind of isolate and let's hope nothing happens is well right as an industry.
You know, we talked about iot devices and there's gonna be 55 billion of the next couple years. It's funny. We have a virtual event next week called devops experience and one of the areas.
One of the tracks is called devops of things. Okay, because I think from a security point of view. We were in stage one of well, what the heck's out there, right?
Yeah, right that's discover. What's connected? Oh those devices.
They don't have a lot of Headroom. They can't be patch, you know, they're they're simple on off but the nature of those devices are changing as you mentioned their pacemakers rights Hearts. There are other medical devices that are implanted.
They're they're sensitive manufacturing but they're sophisticated devices. They're not the old skater on off on off switch. Yeah, exactly and and they have real software on there and they're upgradable.
Yeah, they've got to be secure too. And I I think that's a challenge. And it's not just the security industry's challenge the maker of those the right factors right now another putting a lot of work into it.
I mean listen, I applaud, you know, like the honeywells and many of these yeah corporations and well let's yeah, they're putting a lot of effort and I think that's absolutely you know, kind of the right direction, you know, and unfortunately so easy to get into software development and manufacture devices and and you know, Microsoft and AWS provide SD case get easy for developers to create these smart devices. But with that ubiquitous nature, you know are you know, my concern is are we back to the point where oh my gosh, like every sea code has buffer overflows all over right? They thank goodness.
You know, we've moved to some more secure languages. Yeah garbage collection and and do a better job on that. But watch out there man.
There's so much out there, right like exactly exactly November 16th devops experience. We actually the few tracks right on that point well, and we can do that again in predict in January. Anyway.
Hey, first of all, thank you, you know, the first time we've interviewed you is see so here Carlos, but hopefully it's not the last yeah, right. We do tech struct TV three days a week, right we have you on here. Thank you for talking with us.
It's a great show here at USC 2022 and good luck. Thank you. All right time.
Thank you. Hey, we're gonna take a break here in Vegas and we'll be back with QSC and just a minute. Just a minute.





