Mike Orosz, Vertiz | Qualys QSC22
Mike Orosz, VP of information & product security at Vertiz, joins Alan Shimel at Qualys Security Conference 2022 to discuss how security teams can get an attacker’s view of their environments.
Transcript
This is texturong TV. Hi everyone. We're back here live at the Venetian.
We're at the qualis QSC 2022 event. We're live in person. It's good to be an in-person events because I don't know what you guys see behind us, but there's there's real life people talking here.
And that's the kind of stuff that happens in events that you don't get on the virtual stuff. Let me introduce you to my next guest. His name is Mike oroz.
He's the VP of information of information security. Excuse me at Verdes. Is that right?
It's very difficult. You bet. Okay and hey Mike.
Well, we were talking I got a little bit of your life story. But yeah sure some with you know, your background professional background with our absolutely, you know, I started out in the military a long time ago. That's about 20 something years ago.
And I didn't really know what I wanted to do and I ended up kind of migrating towards threat intelligence and like, you know higher level cyber security stuff at the national level then I transition out of the government in a city Group which I called city government because it was his autocratic as the government much maybe even more we're good. It's just an interesting transition because people like well, how did you transition out of the military and the government and the private sector and I was like it was so easy to do because Citigroup was just like the government in the military. So from there, I got a phone call from Citrix.
He said, you know, we don't know why exactly we need you but we need you to come here and do some stuff. So I ended up bleeding some security functions there and then I ended up, you know coming over to vertive where I work right now and vertiv is a company that produces Data Center and other critical infrastructure. I was gonna ask that next.
So that was my next. There you go. So when you say produces critical infrastructure for data centers It's not not servers, but other equipment everything those servers are bolted to including the power distribution.
Oh, okay, and the remote and everything. Yeah remote switching like switch from one device to another so you can control it and configure it remotely as we I saw we call power ping and pipe. Yeah back in my I I need to use yeah that sort of stuff.
That's what we do. com. I had helped the company we were what they called an asp the application service provider.
Okay. So before there was Cloud. Oh, that's where I serve architecture.
Right you just at scale. Well, we would trying here trying we would try the pre-cloud. Yeah, we would do a Lotus which I don't like myself notice notes Lotus Notes people soft.
Oracle a little bit of that loss in yeah. I read a book about that where they talked about Dallas called crossing the chasm. Yeah.
Everybody's read that one. Yeah, they talk about that. I'm like, oh my God.
This is like a history lesson. Well in my lawn it it's just a good refresher it what it was an experience. Right?
But we also operated data centers right in the glanter and Virginia and we had one in London not ask her and we're you know another girl three letter. No, neither expert because the later life I actually sold over there but no we had taken over an old AOL data center in Tysons Corner. Oh, wow, okay.
Everything's Corner. We were Dell house. Yeah at the time too.
We were in OEM of Dell. But we're also a son some my binder and I am very load. It's not yeah, so depending which team companies executive is in town.
We would move we would move the service. Why not, you know to make sure yeah exactly but you're trying to scale. Hey you had to meet demand and we had it, you know, you had there was no concept about time at the mom.
Yeah. Well we did we had a cut, you know, we didn't have five nights. Okay.
It was a very different world. It was solid. Yeah.
Yeah. Anyway. Hey, I wanted to talk to you a little bit actually before we get into it.
Is this your first QSC? Have you been here? I've never been to a QSC before but I've been a quality customer probably dating back.
I don't know six years now two different roles. so after I left that ASP, I started a security company in Colorado and we were in early quality competitor. Oh, wow, okay and back then I could not I thought I thought they were crazy.
Because they were scanning and keeping stuff. It wasn't the cloud but expert externally, excuse me. One of the things that Wallace was always known for was sort of that attackers I view.
Of your network. That's right, right. What do you look like to an outsider to an attacker?
Now today that's kind of you know, that's bread and butter. You need to know that but I want you to ask you what you know, is it still like that? What do you is it still relevant and important?
What's new in this kind in that kind of view of things tell us which if you know my share with the audience. Yeah, absolutely. So what's really interesting about like the external attacker or birds eye view is the fact that many people should be conducting pen tests.
Anyways, right fear a large Enterprise you need to conduct depends us an annually at least externally internally, you need to have that attackers point of view. And the first step of attack is the enumeration scan to enumerate what assets are facing externally and then you do a vulnerability scan then you detect what is there to exploit and then you go from there. So it's moving kind of from like a once a year thing now until like a phase where people now have the tools even the, you know, entry level people in cyber security.
It's a little more I guess democratize. So to speak from a perspective of being able to if I can pick up the tool and have no training they try to say Mike you need training first before you use balls. I don't just give me access to it make me an admin and let me go and I'll tell you what I can I don't need no, I don't want to use it's intuitive.
It's easy to use what quality is always better, right? They did have a great intuitive thing. I think one of the problems though with this attackers.
I view that we didn't have when I was more involved in the you know at that level. is today our networks our attack surface if you will is so much greater. I mean back then I just worried what was in my data.
That's right. Right. That was all I had two data centers and they were big.
Yeah Hub and spot Network. Right? Right.
They weren't these little, you know dense things and Today, I think organizations struggle with an accurate picture of their assets. You can't protect what you don't know is there. they do you know, and that's a really great Point you're making and it's largely because People have many different levels of in abstractions of cloud services.
You have you have IAS, you have passed you got SAS products, you know, you can't go you can't go scanning all those things because you know, you have to look at your terms of service and what you get from your provider and what you don't get and you have to acutely know the difference because you could be in a situation where you can figure a server in a public Cloud environment that you're gonna expose to the internet certain circumstances you at hairpin that back to a data center that you control and egress through your own firewall. That's again that back like an extension of your corporate Network. So if you have extension of your corporate Network where your hair pinning back through your Hub?
Yeah, you can treat it as I can extension. You're on premise environment. Now, if you have devices hosted in the internet, you know servers exposed to the internet.
We're attacker can see it and the cloud service providers and providing that security or patching it. You're accountable to do that. Now, if you move up the abstraction layers to the point where you're at, you know ephemeral containers or something like that or you're you're dealing with SAS applications.
That's the beauty of SAS. You're not accountable to that because you're transferring that responsibility off to a third party and they're handling that old client server application now, they're serving it to you as a service. Yeah.
Absolutely. That's the benefit. I well.
It you know as much as things change some things don't that things don't yeah, that's the benefit not off the hook just because you're in the cloud absolutely and in some ways it's more complicated because it's not right in your face the way it is in a data center. Right? Let's talk a little bit about how you use koalas for this Wallace.
You know what we started with the MDR which is vulnerability management sure and I when I began talking with quality, I'm like wait you make an asset like cyber security Asset Management tool? That's great bring it all together. So then I was like you make a web application Scanner.
I can use one of those Absolutely. I'll give it a try. You know, what we have multiple different types of applications and I do buy some other vulnerability scanning tools, but there's no greater value than having one pain of glass.
Where you can optimize the resource utilization and that's I'm going to kind of be talking about that a little later today and my session but the bottom line is we use koalas to scan all those environments and scan all those hosts. We use a scan virtual machines. I used to scan and detect like the versioning of the security tools.
I've deployed like zscaler, you know, but you know, we have we have clients that we run and we want to make sure those are in support. We have our VPN clients. I want to make sure those are the correct version they're not and a life and a support.
So who would have thought you can use a vulnerability management tool where everybody thought was vulnerability management I can use it to patch so I can do I can scan I can find issues with components within apps. I can use it to detect vulnerable apps and a life and a support apps and now I can push a button and Patch it last week. I was patching that's my thought.
Took something but it turns out it was two other applications fighting for control with one another security apps. No less right? I'm glad you're brought that up though, because that my own private little survey.
Right? Look this whole issue avoidimation as the economy. It's crappy.
Right companies want to make me do more with less the more you're right less people less headcount people are expensive and so maybe because we've had automation available. For patching for a long time. Oh granted.
It wasn't perfect. There were. Yeah there issues, but we've had automation around and it hasn't.
Gone mainstream as much as we would like. Maybe this is the kind, you know, this economic situation is what we need to give it that push right and see there's a secret sauce to it, though. So I'm happy to share that.
It's because it's not just with me though. Go ahead. No, I'm sorry couple of times.
Yeah, exactly. Yeah, very happy to talk talk to that right there. So it's the proverbial challenge of asset management and assigning ownership to those applications.
So you oftentimes you run in a complex hybrid environment. You got some applications that hey We bought it 15 20 years ago. It was working great.
Then it works great now but you know, let's face it some of the parts of that thing where maybe open source maybe they're vulnerable maybe something can be exploited just because it works great doesn't mean it is in fact secure. So it's like anything you have to basically have a thorough understanding of your environment. What are the interdependencies for those applications and brought?
Let's say browsers great example, you know, what if you have an application that uses a legacy browser you go patching everything you just break broke manufacturing. I just affected order with 15 million bucks and I got a plant manager who's angry who can't you know deliver. So, you know, it's really critical to have your assets identified enumerated and then broken down into buckets because if you do go down that path of automated patching you want to do it in a responsible way that doesn't break the business.
Absolutely. That's the best definition in advice. We've not thinking about it for a while because I've broken the business.
Yeah you all have you talk about City. I remember going to talk to City 15 years ago about vulnerability management and patching they had three different cios. Oh, yeah, right.
There was like three there there average patch like time to patch was 90 days. That doesn't sound bad to me though organization outside. Well, it was Employee if they were lucky and And they just but they couldn't see where they'd ever get beyond that.
That was as good as a God for them. They just they limitations of the technology at the time. Well the time too you're right.
Anyway. Hey Mike. Thanks for joining us.
Thanks for speaking. Thank you. Yes, he as well man.
That's yeah, but there's a pleasure. Um, hey if you want to see people like Mike and get a chance to talk to him. That's what the QSC program here is all about.
Maybe you want to check it out when it comes to a town near you. We're gonna take a break here at Tech strong TV. We'll be back in just a moment.





