Exploring Cybersecurity with Theo Bowman at QSC24
Theo Bowman, Information Security Engineer at NCR Atleos, shares his journey in security and coaching. He discusses vulnerability management and the impact of open source software on enterprise security. Theo highlights the importance of software composition analysis and the challenges of third-party vulnerabilities. He praises Qualys for its efficiency and offers advice for aspiring cybersecurity professionals, stressing persistence and networking.
Transcript
This is Textron tv. Hey, everyone. We're back here in San Diego.
I'm really happy to have this gentleman right here next to me. We just spent 10 minutes talking about fish, not fish that you eat. I guess you could eat 'em if they, you know, but, you know, fish, tropical fish and salt water.
Fish and fish tanks and aquariums and stuff like that. And it's a, it's a, a subject i, i, I love and I talk about all day. I wanna introduce you to Theo Bowman.
Theo, first of all, welcome to Techstrong tv. Thank you for coming on here with us. Thank you.
Thank you for having me. Um, yeah, I'm gonna let you, if you don't mind, share with our audience a little bit about your journey and how you came here today. Uh, my journey is, uh, it's a interesting one.
I've been in security. They're all interesting in security. We attract interesting stories.
So I've been in security, uh, about five years now. Uh, hit the ground running with my, this is actually my first job, actually. Insecurity.
Good For you. Uh, basically, so, uh, before that I was coaching basketball, really high school. Training, training, training.
I, I have a background, we'll talk offline, but I, I coached for a long time myself. Yeah. Football more, but Yeah.
Uh, yeah. So, uh, joined on with a company, Cartronics World's largest ATM provider, servicer. Uh, they, they passed over the vulnerability management program to me, like here at Theo.
Uh, had a good, had a very good cso, uh, leader. Mm-Hmm. Uh, my direct management and the, and the whole team was good at, uh, mentoring me and bringing me through the ropes.
And now, and now I'm, I guess you can say I'm the guy when it comes to vulnerability. You're the guy. You're the guy.
All right. And, um, you work for NCR Adios at LIOs. Yes.
At lyos. Now, you were at Tronix. Tronix got acquired By NCR National Cash.
By NCR? Yes. Alright, take, take me from there to here.
Well, so, uh, as you say, we got acquired by NCR, uh, which, uh, it's National Cash Register, all the POS systems. Sure. Uh, ATMs, you go to Walmart, it's a big one, and you use the self-serve.
You see NCR that, so Mm-Hmm. That's us. And so, uh, we got acquired by them and during the integration process, um, they decided, Hey, we can make two companies.
And so, uh, so they decided to make two companies. So They forked off. Forked off.
We still kind of together, but we, we actually two different companies. Uh, so you have the inside, uh, NCR VO side, and you have the NCR Allo side. And I'm on the atal side, which the, we, uh, deal mostly, primarily with all the hms One was more hardware and one's more software related.
Yes. So you're on the software side. Yes.
Okay. Um, now, you know, one of the, I've been in, as I mentioned to you, security for 30 years. And one of the biggest things I found in one of the biggest developments over these past 30 years is when I first got in no self-respecting enterprise would admit to having open source software in their product or in their shop.
Because open source software was a no-no, there was no one, there was no throat to choke. If something went bad, they didn't know, you know, the source code was available to anyone so they could be hacked. And, and so the rule of thumb was enterprises didn't use open source software.
Open source software was for hobby people. Crazy nerdy people who want to experiment, but, you know, enterprises don't use it. Well, that, that's changed, right.
Today, virtually every enterprise uses open source software. Right. And most of the applications we use are predominantly open source components, right.
That are kind of stitched together 70, 80% of the code, but open source software, and I'm not saying it's less secure than non open source software, but it has security issues. Right? Right.
And, and the way, the way the market and the industry has responded is like they, they treat it set different. Like we, we have a, we have a, we have, we, Qualys has had a vulnerability scanner for 25 years, and it's a good vulnerable, it was good 25 years ago. It's better today.
But we have special vulnerability scanners for open source software. Right. Ass.
I call 'em software composition analysis. S ca. Right.
You call 'em sw ca ca But it's the same thing. It is speaking the same language. And it's not just Qualys.
It's not like Qualys is an outlier. Every one of the vulnerability companies have SCA Right. Scanners.
Let me start there with you, Theo. Do you think we need a separate scanner for open source, or should it be part of just the regular scanner we use? Uh, I think it should be part of the regular scanner that we use.
Me too. Right. The, the less you gotta put your hands on something or to activate something, the, the, the better.
Well, the less tools you have, the simpler things are, you would think. Right. Right.
But that being said, there are specific, uh, challenges with open source, especially when we talk about software supply chains. You know, everybody talks about SBOs. Now, talk to me about, and again, without, I know you're gonna present, so Right.
Whatever you're presenting is out there. I don't want you to get in trouble saying anything proprietary, but talk to me about some of your challenges with this. Uh, so before, uh, we, we had a big challenge on, uh, remediating third party vulnerabilities.
Right. And so with, uh, the implementation of, you know, SWCA mm-hmm. SCA, so we we're cutting that on.
We, we found that it was a lot of stuff that we didn't know about. Right. So we, and so that, that helped us a lot.
And then it helped us, uh, really assess our risks Mm-Hmm. For the company knowing those, uh, vulnerabilities that was out there. Yeah, Absolutely.
You know, when we talk about third party vulnerabilities like that, right? Like the, so the SolarWinds case a couple years ago that was actually out in Dallas, wasn't Yeah. Solar Winds On there.
Winds case law four jks. Yeah. You know, um, and it's given rise to this whole SBO M thing, right.
Where software bill of material, so we know what components are in the, our software had had, has that kind of impacted you guys yet? Are you starting to look at SBOs to look at your stuff or? We we're starting to look at it.
We're starting to look into it, but so with some of those vulnerabilities, for us anyway, they're not, uh, as easily fixable as, as you know, just as applying a patch. No. Right.
Well, the problem is 'cause it's not your software. Exactly. Right.
So we had an issue with, uh, with a company, with some software we was using. Uh, it actually had log four J in it. And, uh, but it wasn't us.
It was them. It was, uh, and so, which we had to get them to update they stuff. So we can not be vulnerable on, on, on that end.
So what kinda leverage did you use to get them to update it? Nah, we just told 'em we're not gonna use it anymore. Yeah.
That, that'll do it for you. Right. Yeah.
Because that, that's kinda what it takes. Right, right. And, and that, you know, because a lesson I learned very early on in security is when that customer's yelling at you because you got a vulnerability and you telling them, well, it really isn't my vulnerability with some third party vulnerability that got into my software that don't make them feel any better.
And Right. Right. So it it's on, you know, the buck stops with who they paid money to.
Right. And, and that's I think, a lesson that all of our audiences probably learned the hard way. Right.
Uh, the, the thing about security is you are responsible for the product you put out into market in terms of security. Right. And they don't want to hear that it was someone else's fault down, you know, down in the supply chain.
Um, how's Qualis helped you with this? Oh wow. I mean, Qualis has done, uh, has done great things for us because, uh, originally during the integration process when we was all a part of NCR, we was going to be, uh, rapid seven.
Yeah. Mm-hmm. Familiar with 'em, Familiar with that.
Yeah. Yeah. I was glad when we said we wasn't going to do that anymore.
But that's Another story. You said it, not me. Hey, I might be at DARE conference next week.
You don't know, but go ahead. Don't wanna get you in trouble. I'm probably kidding.
I'm not gonna be at DARE conference, but it's okay. But, um, uh, yeah. So it's to, to have everything in one console, in, in one space is, is, is big, right?
Yeah. And, and then with all the, the flexibility and the integrations that it has, uh, with a lot of the tooling that we use, it's, it's, it's great. So it, it is done big things for us.
Good For you, man. Um, how much time do you spend, do you think, on, on, just on the SEA part of it on this software composition analysis, scanning, remediation? 'cause it's not patching, as you said, A lot of times it's third party stuff, but how much time is that?
Uh, we spend a little time on it, uh, not as much as, uh, that, that we would like to. Right. Uh, just because we need to assess it.
And then, uh, so it's, it's a lot of risks out there, but our teams, they need to figure out how to, to remediate some of that stuff. Right. Right.
And so it's, uh, I mean, it could be, it could be difficult at times, but far as like doing the scanning and all that kind of stuff, it's on autopilot really. Yeah. Well, that's the nice thing about Qualys is it is, let me ask you about the remediation.
Who does the remediation? Is that your team or does that get kicked over the fence to like DevOps or ops or developers? Yeah, it gets kicked over to the fence to our either DBA team networking teams, this admin team.
Uh, we have, uh, we have the integration with ServiceNow. Okay. We usually Call Sure.
BMDR, uh, plugin and ServiceNow, the Okay. BMDR plugin and core. So that tracks your whole ITSM kind of mm-Hmm.
Yep. And so we, we, we, we pretty much do a data ingesting to the ServiceNow daily. Right.
And so those, so it's not real time. So we like 24 hours behind on when the, the vulnerabilities discovered and when it's ticketed and put out for, for the teams to go fix it. That's fantastic.
That's good stuff. So ServiceNow, the ServiceNow Qualys integration's an important piece of the puzzle for you? Yes.
Very cool, man. Yeah. It was manual before we had that.
That's tough. So let me ask you, 'cause I I the most often question question, you know, I got kids, my, my boys are 25 and 23, they're just graduating college law school and stuff. A lot of their friends have gone to school for cybersecurity.
Mm-Hmm. And they, I, the question they ask me all the time is, how do I break in? How, how do you get that first job in cybersecurity, man?
What advice can you give them? Uh, keep trying, you know, just keep trying and keep applying. Uh, and just that's big.
And, and ask questions like, uh, if you know somebody that's in the, in the industry, ask them if they can get you on, even if it's at, you know, if it's, uh, doing help desk, whatever. Yep. Uh, if you're already working with a company, but you, you want to go into cybersecurity, see if they can move you around to, to be on, on the security team.
Right. So it, and that honestly, just don't quit. Just keep trying.
I love it. Theo, congratulations man. I appreciate you coming on here today.
Knock 'em dead on your presentation. Oh, okay. We did that.
We are live in San Diego. Theo Bowman. All right.
Here on, uh, text Drunk tv. We're gonna take a break. We got more people coming on.
Stay tuned.