Cybersecurity in Tolling Operations with Lavish Jhamb & Simon Gaiser at QSC24
Lavish Jhamb, senior product manager, compliance solutions at Qualys, and Simon Gaiser, cyber threat and vulnerability specialist at Transurban, discuss compliance solutions, particularly file integrity monitoring and remediation. Simon shares insights on cybersecurity in tolling operations. They emphasize the importance of security in tolling and discuss PCI compliance.
Transcript
This is Textron tv. Hey, everyone. We're back here in San Diego.
It has been an amazing two days. We, I think we've done, I don't know, 30 something interviews in two days. We've brought you this QSC conference from every angle.
I think we can, I've got our last two guests here with you. Let me introduce you to lavish ham. Simon Gazer.
Well Done. Yours was, I'll be honest, was a little easier for me, but I got it. Simon.
Um, guys, let me have you introduce yourselves. Lavish, tell us first about you. Okay, So I'm lavish charm and, uh, I'm senior product manager for Quas Compliance Solutions.
I handle the products, uh, compliance products mostly like file integrity monitoring, policy compliance. And there's one more, uh, remediation product that I work on that is customer assessment and remediation that allows you to create, uh, custom scripts in any scripting language you want and create custom Q IDs out of it. Since it's linked with the complete Quas platform, you can create the custom Q id, the detection, Q IDs, et cetera, and take your mitigation and custom mitigation and response actions as well.
Excellent. Simon, how about you? Yes, uh, I'm Simon Gaza, as you said before.
I'm cyber threat vulnerability management specialist, which sounds a bit long, but yeah. But that's what it's, uh, um, I work for Transurban, uh, in Australia or Melbourne? Australia.
I love Melbourne. Oh, Good. I've been there two years, but I've been about eight years in cybersecurity, uh, in total.
Um, I trained originally as an engineer, um, and worked in schools looking after computers for a bit, and then banking and then some utilities and the education and ended up in, in Transurban, um, you know, a couple, a couple years ago. So For our audience maybe who's not familiar with Transurban, what kind of business is it? And So, so we are in roads tolling, um, and you may know us in Virginia as Express Lanes or in Canada.
Oh, like, uh, as a 25. Okay. Or in Australia as Link T.
Yeah. So in, in Florida we, it's SunPass. I don't know if that's Yours.
No, I don't, don't think that's us. No, no. We probably like it To be, it doesn't, it doesn't work good anyway.
Oh, oh, okay. Okay. Well, it's probably not us then.
No, definitely. Yeah, yeah, Yeah. In New York there's easy pass though.
Oh, okay. That's a good one. You, you'd want to be though, right?
Well, thank you. They get a lot. They, they get a lot of money in New York.
It's crazy. It's like 20, $25 to go over a bridge there. It's, it's, it's a lucrative business.
Um, so being where you are though, I can obviously see that security might be a little bit important to you guys. Absolutely, absolutely. And ever increasingly important in this day and age, right?
So Sure is. Yeah. Um, you guys literally, we just dragged you in off the stage.
You just finished presenting here. Yeah. Tell us what you presented on.
So I presented, uh, file integrity monitoring and how it helps you to achieve your compliance. Especially, I mean, the, the compliance measures are changing day by day. 1.
0 reports will be considered. So, uh, the customers are really worried, like the who those use Swim solutions are worried that what are new changes are there, what are restructure requirements are there, and do we, uh, do we comply to those or not? So today I just gave them a talk on a solution, our call, a swim solution that they, that keeps you audit ready for any requirement that, uh, that comes up new because we keep on updating the solution.
Every release We actually spoke to, I think it's Annu Yeah. Who was also, yeah, She's policy compliance. Yeah.
Yeah. Configuration management. We, we, we spoke about this with her.
Simon, what about you? What'd you, So I also spoke on file already monitoring, which is close to Ish's heart, of course, right? Mm-Hmm.
Um, so he Gets passionate about it. He's very passionate about it. Absolutely.
Yeah. Yeah. 0, uh, with its noise reduction, as you talked about, you know, and, and other things as well.
Uh, we've been using it for two years or so, have you, but, but we also needed to replace, um, some older software from another vendor that had vulnerabilities was end of life. Um, and then by replacing that, we were able to utilize our existing Qualys agents that we already had on servers and just turn on file integrity monitoring and strengthen our relationship with Qualys. So they're, they're good guys and girls.
So, yeah. So, so it's a win win win. It's a win win, win win.
So that, that's one thing I talked about and, and, um, our, the success journey there, but also, um, re-rating our vulnerabilities using the Quas detection score, uh, where, um, um, it, we've been using CVSS for a very long time. You And everyone else Since. Yeah.
So it's, it's been available since 2012. I know. Uh, QDS since 2022.
Um, the beauty of about QDS is everything from like 90 to a hundred is CSA exploitable. Um, so we can pretty much use, um, the QDS ratings, um, with some business criticality to, to prioritize the QDS score and then further prioritize it. If it's PCI.
Great. And then if it's internal rate it lower, otherwise, um, leave it slight, leave it rated slightly higher for external. Um, and then reduced, we reduced our high criticals from 65 to 23%.
Wow. So that, And that's something security people. Yeah.
We've had this discussion here the last two days, so I've been in security 30 years. Oh, sure. Right.
And You know, I remember be, I remember when CVSS came out, you know, and that was a big improvement over what came before it, but at the end of the day, it's hard to rate vulnerabilities across the board because it really depends on your, what's your network Mm-Hmm. What's important to you and what's, how, what kind of controls do you have in place? So we've known for a long time that CVSS scores are kind of a bogus way of, of, and, and then, you know, the, the flip side of it also is, you know, the poor CISO before he got shot would go up to the board and say, well, you know, we've got 65,000 high critical, 32,000 critical and 22,000 medium, you know, that meant nothing meant nothing.
No, That's right. Because you Well, what does that mean money wise? Yeah, that's right.
What's my risk, really? What's my risk? And, and so the, the, the, the new QV came out in 2020 QQDS, QD, QDSQ, yeah.
2022. It tried to give a little bit more Yeah. Reality based Absolutely.
Risk. I love the true risk stuff that Yeah. You know, takes it, I think to the next Yeah.
It's, it's, it's, it's the same. Yeah. It's exactly the same.
Yeah. Yeah. But now he's starting to put dollars and cents.
Yeah. Well That's the business language. Exactly.
Execs understand. Yeah. Mm-Hmm.
And you would've heard this weekend that if everything's critical, then in reality Nothing's critical. Mm-Hmm. Right.
That's always the way it's, Yeah. And so that was the way, that was another problem. That was the way it was at Transurban, right.
Um, and, uh, remediation teams were, would be losing faith in security teams constantly cry, crying out, saying, you must do this, you must do this with only 23%. Now it's much more achievable. Um, and we focus on what's Important, making progress.
Right? Yeah. You know?
Yeah. Look, when I first started doing vulnerability management in, uh, 2003, it was job security, right? Because back then you didn't even scan pre, pre-deployment.
You only scan once a year after, and then they would deliver a telephone book to you. Mm. And you, if you started on your vulnerability, it was impossible to, to prioritize.
They were all, like you said, all critical. You started your vulnerabilities January 2nd, you came, you know, they gave you off in New Year's, so you'd come in January 2nd and Right. The day before Christmas you would finish, or you, you wouldn't even finish.
But you'd be a whole year's cycle just in time. Yeah. For next year's book.
Yeah. It's not really just in time, is it? No, It isn't Really agile, right?
No, it's, it's, It's, but it was job security. Job security. I always got more vulnerabilities to work on, right?
Yeah. Yeah. That's right.
It didn't really make you secure. It didn't really stop, make vulnerabilities better. Mm-Hmm.
It was this game we played, right? Yeah. Yeah.
And, and, um, so I'm, you know, we've come a long way. We have, we have, we've come a really long way talk about file integrity management for a second, right? Mm-Hmm.
I remember doing my PCI years, right? Mm-Hmm. Scanning file integrity di diffs in files from day to day.
Oh, crazy. And did that really make a difference? Oh, Now it's totally different.
It's totally different now. So earlier as you mentioned, it was just taking the diffs right? And, uh, showing You wrote a diff report.
Yeah. And it was scan based. So let's say you take it weekly, right?
You take a diff weekly. But what happens between those seven days is unknown to everyone. Now, with the, now with the, with the advancement in f solutions, like, like we have with cosm, it's more of a real timeframe solutions.
Any time the change is made, you get the diff on this, uh, on the console stating that which user made it, what process was responsible, what was a timestamp, and it runs 24 7, right? Yeah. So, so that, and, and that is the, so that was always the concept behind PCI, right?
That you would have this continuous, continuous monitoring, not point in time. Mm-Hmm. And that, and that, it's not just PCI, it's a good way to think about security in general.
You need continuous security. Mm-Hmm. Not point in time security reports or checks.
Um, so Simon, your Qualys customer using the continuous, uh, compliance. Yeah. It's file integrity monitoring.
And we also use the PCI portal for our external attestation. Yeah. Quarterly.
Quarterly. Uh, Yeah. Well, you considered a level two, level one.
Oh, I'm level, I'm not sure. And That is what, uh, level one, level two is for configuration management. But, uh, he's talking about the external, uh, vulnerability scanning Look like from an external piece.
I'm sorry. Yeah, yeah, Yeah. Wrong product.
Well, well, I thought they were helping you fill out your Oh, We, we, we do, we do. We have to do everything. We do have to do everything, right?
We do the external absolute, the voluntary monitoring. Yeah. Yeah.
What do you think about the announcements this week around the risk piece? True risk game changer, or no? Um, well, the things that I'm most, um, loving and excited about is the enhanced integration of the Qualys Cloud platform with third party providers.
Mm-Hmm. Like, uh, windows Defender Rapid seven. Um, basically, uh, I feel like it's a game changer for quais.
Um, you know, Well, I think it's a game changer for the industry. It makes your life better, easier. Well, like, people have been trying to do it all themselves, like with a threat intelligence tip, uh, for a long, long time.
Right. Um, I will be able to go back to, um, Australia and share this, um, this, this good good news story with, with my manager, um, because, 'cause we, we, we were actually been considering for the last two years trying to do a threat intelligence tip ourselves. This It's a big job.
Yeah. And so this, this is, uh, this is a reasonable, um, option to us now. Um, and, um, yeah.
And the other thing too is, um, for our, uh, our desktops where, um, where architecture teams, um, aren't so keen for us to deploy Quas agents, we were looking at ways to integrate defender vulnerabilities into service now. So now we can turn on integration between winner vendor cloud, uh, we can en enhance it with the And have ServiceNow integration built in. Yeah.
But the, but the thing is, we were gonna insist that we enhance the C-C-V-S-S scores with the QDS score as part of the custom integration within ServiceNow. Now we can do it in Qualys. Mm-Hmm.
And, and we can use the existing integration between Qualys and ServiceNow to bring it in. Huge. So, so that's, that's making our lives so A lot, it's a game changer for you.
It's making your life easier. I agree with you, man. Absolutely.
Huge. I Agree with You. Yeah.
Yeah. Yeah. Guys, the suns of my eyes here, that means it's time to get outta here.
Sure. Um, Simon, I, I know both of you came right off the stage. Thank you.
Sure. Thank you. Thank you so much.
No worries. Um, that's gonna wrap up our Qualys 24 Quas Security Conference, QSC here. A little sad about that.
We've had a good two days, but you know what, if you missed any of our coverage, we're gonna be replaying it next week on Techstrong tv. So you could check it out there. It's all, it'll also be available on demand.
Give us a few days to get all these edited in up there if you caught this live. Hope you enjoyed it. But for now, that's a wrap on QSC 2024.
I'm Alan Hummel for Tech Drunk tv. Have a great day.