Balancing Cybersecurity and Essential Business Operations with Raphael Ferreira | Qualys QSC 2023
At Qualys Security Conference 2023, Raphael Ferreira and Mike Vizard discuss the unique cybersecurity challenges faced by consumer banking. They highlight the constant threat of fraudulent accounts, emphasizing the need for securing exposed APIs and internet-facing systems. They also delve into the difficulty of balancing cybersecurity measures with the essential business operations, particularly when addressing critical vulnerabilities.
Transcript
This is Textron tv. All right, we're back at the Qua Security Conference and we're with Raphael Ferreira, who's cyber risk leader for Kohan, and they're out of Brazil and they specialize in consumer banking. Is that fair?
Yeah, Exactly. And we're gonna talk a little bit about, well, what makes cybersecurity different in consumer banking and some of the challenges that people encounter. Hey, welcome the show.
Okay, welcome. Uh, no, no, not welcome. Thank you.
I'm, I'm just nervous, but sorry. No worries. Let's just start with the easy stuff.
What makes security and consumer banking different? I mean, there's a lot of vertical industries, a lot of folks work in different sectors, but is consumer banking more challenging in your perspective? I mean, where are we right now?
Yeah, we receive like a lot of attacks being a consumer banking, 'cause we have like a lot of people trying to create fraudulent, fraudulent accounts in consumer banking. So we have like API is exposed and all our internet stuff expose. It receives like hundreds of thousands of attacks all days.
So the, that's it. I, I think it's the most difficult part. Are the fraudulent accounts just people trying to commit actual fraud?
Or is there something else going on here where it's, we heard today about some nation state activity that goes along with that. It seems like a lot of the accounts are suddenly fraudulent. Yeah, Yeah.
Most of the accounts open every day at bank. It's, it's frauds. So it's talks of, talks a little bit about what Rachel, Rachel Wilson, uh, in Morgan Stanley told us.
So for us, uh, it's the, it's the same thing. So the fraudulent, the fraud doors is always, uh, trying to hack the banking and open accounts to have like payroll loans and things like that to steal money for us. Of course, the whole purpose of being a bank is to have transactions and the business side thinks online is probably great.
How do you strike a balance in the conversation so they understand the risk, but not to the point where we need to shut the entire business down? Okay. Uh, we focus on the most important vulnerabilities that will impact our car business.
So when we have like APIs, vulnerabilities, and web application vulnerabilities in the most critical of our assets, like one of our main assets are the on credit system, the system to give credit for the customers. So for us, when we have like vulnerabilities in this system, we need to align with our CEO because it's, uh, a high level stuff. So we need to align with him because it's very important it can impact our, uh, revenue.
So let's say we discover a vulnerability is being exploited. What's the process you guys use to go fix that? How does that kinda work?
'cause there's usually an IT team sitting on the other side of this somewhere. Yeah, We need to align with them, uh, our priorities because we have like a lot of vulnerabilities and we are prioritizing, like I said on the stage, uh, the KDS greater than, uh, HG KDS, the quality detection spark. So we need to prioritize, uh, this kind of vulnerabilities with our teams.
So I align with them the, the new needs that we need to, to fix our vulnerability to remediate a threat. So it's kind of difficult to, to make, um, the IT teams to understand the needs. And most of the time it's difficult to them to understand that needs changes like maybe every day.
So we need to correct, uh, vulnerability today and another one in the other day. So we are like always changing the, the priorities. So it's a, a difficult stuff.
Do they need to appreciate the actual level of risk? Because to them it's just one more task to do in a day, right? Exactly.
Exactly. Uh, they need to prioritize the, our vulnerabilities talking with our business team. So the business said, oh no, we cannot stop the, the system right now.
You can stop there like on the next week. So we need to prioritize vulnerability and have like an SLA that was approved by our COA few years ago. I don't think cybersecurity people knew much about APIs, and I don't even think the bad guys knew much about APIs.
Has this become the new endpoint target? I mean, is this where the, the the focal point of the, the fight has shifted to, Yeah. Yeah.
Uh, most of our, um, main, uh, services on BankOn are supported by API. So we need to, to test to our red team to be testing the APIs every week, every time. And the APIs are always changing.
So we need to test the security of APIs in new functionalities almost every single day. Mm-Hmm. Are there regulations getting more, uh, stringent in Brazil these days?
'cause here in the US we're struggling with this concept, so I don't know what you guys are seeing, but is it similar? Yeah. In Brazil, we have the Bain, it's a central bank of Brazil that regulates all the, the banks in Brazil.
So we need to, to give him information about incidents, about, uh, vulnerabilities that were explode, exploited by, uh, a lot of attackers or maybe data that we have and it's on internet. Mm-Hmm. We are talking here this week a lot about risk management.
How do you guys approach that in a way that you can help everybody in the organization understand what they're really looking at or what they're dealing with? Because I think part of the problem is we've all kind of, not just, you know, between countries, but between security, it and the business, we all speak a different language. Yeah.
Um, we have this same challenge in, in, in bang. So we need to take care of what kind of message are we willing to, to, to talk with our directors, CILs and, and leaders in at Bon Cuppa. So for us, it's difficult to, to take like the same message to pass to them.
So we are correlating like financial data with, uh, our CVSS and true risk to give like a, a real answer to the board and to the directors. So when, uh, we have like, um, an availability, an availability of, uh, one application, how much it cost to the bank. So we are like dealing with this kind of thing.
There are a lot of security options out there. And of course we're at a quas conference. But how did you land on Qualis?
What was the process you guys used to evaluate your solutions? Okay. Uh, when I start working at BankOn, uh, they already already used Qualys.
So I used it quass in 2012 at, uh, ECGI productivity is a consultants firm that I worked for. So I used it before and I know it's, uh, a great tool. So when I see Quas at kopa, I, I be happy.
So it's, uh, a great tool for us. It's, it's was our CMDB before servicing now, because at Global Asage view, uh, help us a lot with identifying our assets. So for me, what is is, uh, a, a, a great thing in, in my life every day.
Well, let me ask you about that, because I mean, once you get past salary and benefits and all that stuff, how important is it that the tools that the company has are something you're gonna wanna work with? Okay. Uh, the tools are just, uh, a way to get something.
So qualities is the way that we use to get, uh, a real cybersecurity problem and our real framework for bank of funds. So, uh, I have like, almost everything from, from Alis, I have Total Cloud web application scanning, VMGR, and Search V. So all these tools help us to have like, uh, a real framework implemented in our bank.
We talked a lot today about their new platform for managing risk. Is that something you're gonna add to the portfolio? Is that just come with a, I don't know.
For all I know you've already got a license for it. It's, uh, probably, probably next year because we have like Prisma Cloud, bird Suite, we have SonarCube and a lot of tools that can be integrated with True Risk Manager. So for us it's a, a, a good thing that for sure, I will, uh, let my season know.
All right. So one of the things we do hear a lot about is, you know, security, it's a stressful job. Yeah.
What do you do to cope? Uh, like you say, like the compensation? Yeah.
I mean, how do you relax or how do you not let the job kind of just drive you around the bend? I think when you like what you do, uh, like I, I like working with cybersecurity. It is not, uh, uh, difficult stuff for me.
'cause I really like what I do since I have like 14 years years old, I am starting hacking systems and, and things like that. So when you real, like with what you do, it's um, more easy. So for me, it's okay, but in my free time, I go to go to the, to the mall, watch movies, but in every, every opportunity I am being like a, a cyber nerd because, So yeah.
And hacking into systems was just kind of a hobby to see how things worked. And now you turned it into a profession. Yeah, exactly.
All right. Well you heard it here, folks. You do something you like, you never work a day in your life.
So if you're gonna be in cybersecurity, you might wanna start with playing around with stuff just to see how it works. Yeah. Raphael, thanks for coming by.
Thank you. Thanks a lot.





