Bob West, Palo Alto Networks | RSA Conference 2023
Today’s cybersecurity professionals are being challenged with doing more with less, thanks to tightening budgets and an increasingly narrow talent pipeline. Consolidation not only provides a solution for this, but it also offers operational benefits. Enterprises today are confronted with massive tool sprawl, resulting in inefficiency, ineffectiveness, and additional risk that comes from failing to prevent, detect, and respond to attacks quickly. Bob West discusses more about how consolidation is the key to solving some of today’s greatest cyber challenges.
Transcript
This is texturung TV. Hey everyone. We're back here live at RSA conference at the Moscone Center West and we are thrilled to have a good friend of my Bob West Bob.
Well, first of all Bob welcome and thank you for coming here. Thank you for the invitation. I don't want to embarrass you but Bob sort of a seesaw extraordinaire.
He's so numerous see so rolls, but more than just the roles. He's held his stature in the community is such that he's a go-to resource whether it be as a mentorship type of thing and I don't mean to embarrass you. I'm sorry.
Yeah for sure thing or advice or or just as you know, an overuse term thought leader, but man's truly a thought leader Bob. Thank you for coming here. Absolutely.
So I I did I do you justice when I leave anything out. I think I think it's a good starting point and just to build on that so I'm very fortunate that. I've had a number of different experiences.
So I started out working in technology infrastructure with city in New York and Chicago back in the day and I started working in Security in 95 and and most people have And it's they typically stay in Enterprise roles or on the product side or Consulting. I've had the opportunity to do all three things. Yep.
And you know, one of the benefits of that is that I can look at things from different lenses and you know, I have this unusual path. So I was a German major in undergrad. Okay, and I took the logical path from being a German major to working in technology.
Okay, so very logical absolutely. Absolutely. And but but one of the benefits of that when I compare myself to other people that have had technology and security leadership roles as I'm a better Communicator or at least I claim to be a better Communicator than average and it has some incredible benefits when you're talking to leadership teams and boards and customers.
So, you know, just talking our first guys this morning was Andy Andy Ellis. Yeah. Sorry this new book at the 1% leadership kind of thing.
And we had a very similar conversation about how important communication is. Yeah, and and there's this crazy thing called listening. you know when it when I think of I've worked with some brilliant people in my career and a really large percentage of them.
Will not listen to business requirements or their customers or whatever. Yeah, exactly. Exactly.
I'm yet think of the smartest guy in the room mentality, right? So I guilty yeah, I I will tell you it took me, you know, I'm 62 years old it took me a long time. To number one not aspire to be the smartest guy in the room.
Especially when you're leading a company, you don't want to be the smartest guy now not at all and number two. Just being a listener. Because I'm from New York.
I I think it's in New York thing. We tend to jump in. Just kind of lit you learn more of listening and I'll tell you one other thing.
You know, my just if you can get it no, no go for it. I've spent a lot of time the last few years watching the Dynamics of groups, especially when I do like panels and stuff Bob and there's women in the group. Oh, I think unfortunately, And I've heard this from women, but I saw it in real life because I didn't believe it when I heard it.
Women are decent listeners for the most part but men are terrible and and then they Jump Right In they jump right in and they don't give the and the women they don't like to do that because their listeners and they'll say something. Given the chance to say something. Absolutely.
I had it on a panel. I hosted yesterday. I had four men three men and a woman and I finally said time out.
She wants to say something and that concept of mansplaining. So you're talking about mentorship. So I I've been participating in a group called the Hispanic technology executive Council since 2008.
And this is my seventh year as a mentor. Okay, and I've had I've mentored three women and four men. and one of the things that I've found interesting is that And this plays out in a broader context and get validation of Statistics, but the women in general are not as assertive as men.
They are not comfortable taking the next position. if they truly don't have the background where I've had number of roles where I was so over my skis. But I had the opportunity to learn I had the right mentorship and sponsorship and it's just not natural to take a risk like that for a good percentage of women.
Yeah. And maybe that's part of what it is too. It's probably yeah for sure.
I want to turn back to you a little bit. So what what do you what are you up to these days? Yeah, so I joined Palo Alto networks Prisma Cloud division about a year ago.
So that might my title is Chief Security office, but it's not reflective of what I do. So think of an evangelist customer advocacy role slash strategist. So speaking a lot of events like this sure I partner with our sales team.
So I'm in a lot of customer meetings and having been a CS several times. It's easy to communicate in terms they understand and and the other thing is I sit in the product organization. I report to Uncle Shah who runs the personal cloud Division and I don't have a sales quote so I can have some really objective conversations there.
I share the Prisma Cloud customer Advisory Board, and then I am the executive sponsor for half a dozen of our largest. Customers that's great. So that's what I'm up to.
Absolutely and look. You know, what I remember before Prisma Cloud was Prisma Cloud, right? Yep, Palo Alto was moving into Cloud.
They did a number of Acquisitions. They will they did a masterful job of putting them together into one coherent. Cloud security offering probably one of the leaders right in the future.
Yeah. Yeah God security. So that's great.
I mean from from your point of view though. It also gets you to really listen to right back to what we say some of the big companies in the world who are using this put you in a great kind of A cat bird seed I'm very fortunate. You know, I number one I'm doing something I thoroughly enjoy but but I also have just the lens of really understanding what's happening with n number of customers.
I was on a call early this morning with the global Pharma company. and one of the missions was to listen to our our threat report that President cloud and unit 42 are threatened. Yes division put together and Probably spent half an hour on that and then the rest of it is was the so what so what does this mean to us as a company?
And and how can I communicate what we just talked about to our leadership team so we can tell a really good story, you know. That is such an a Missing Link in the security life cycle blue it you're in security a long time. I'm in security a long time.
We're very good at putting out a threat research report or saying there's a new There's some new you know. Mark 4J kind of thing replace your stuff right away. Yep, we're terrible.
I Translating that to business talk about what does it mean to you? Right? You're the customer I'm not talking abstract.
I don't give me bits and bites and don't you know what I mean? Business talk why why do I care? So you well, absolutely and I mean, I'll give you a really good example of that.
So right before I joined Palo Alto as Consulting with a fortune 1000 company that had a significant ransomware attack much a lot of detail behind that but going back to the communication theme, so I was I was in front of the board on day two of this engagement no pressure, right and One of the reasons I was brought in in addition to cleaning things up was to Mentor the the ciso. Smartest guy in the room mentality, right? And and so one of the things I asked him in the first week was you know, show me the he was he was reporting to the board of directors on a quarterly basis.
And so I asked to see his his presentation 19 Pages full of technical mumbo jumbo and after a page and a half. Well, yeah, and and the thing is there were two people on the board that were Technical and then there was everyone else so they were looking at him with the deer and a headlights. Look and and when I present to boards, I typically have three pages I have absolutely.
My first page is typically a matrix of iso 27000 or the nest cyber security framework. So red yellow green. Where are we healthy?
Where are we not? Then the next page is so here's what we're working on. And it's going well or it's not going well.
And then the final one is here's where I need your help as a member while as the board. and you know It's it's just something that you know, going back to the earlier part of the conversation. They're not a whole lot of people that understand.
What why you know, you can you can tell people what stop you really guys pay attention to what he just said because if you're presenting and I don't care whether it's to a board of directors or Your Business Leaders, that's what you need. It's three pages. It's three pages anything more surprise.
Yeah, absolutely. Whatever attach it. Yeah something from people you want to dig deep.
Go ahead. but that I mean can that sell it rinse and repeat and that's exactly do what we'll see you next quarter next month and I'll give you an update. Absolutely.
I'm sorry. No, no, that's okay. That's okay.
And you know, I think the other thing that I see, you know, when when you look at the cyber security industry historically, I mean, I remember 1995 was when internet security systems was launched by Chris Klaus and Atlanta. You got it. I remember you got it and and a couple years after that they brought out their intrusion detection products.
Yes you get and you know firewalls evolved, you know, checkpoint and tis and you know that they were the major vendors and then and then in the early 2000s there were identity tools DLP tools, etc. Etc. Etc.
The the long winded message for this is that it's very easy to have Your security tool portfolio is a company continue to grow and grow and grow and if you don't manage it. It's an overgrown far as that's exactly it. You know, people aren't cutting the limbs off of the trees, right and You know when when I was sea, so we managed to buy hold cell list.
So what's working right now? Let's maintain it. What are the tools that are no longer relevant?
And then what's coming and and the other thing is As the security industry has matured, you know, so prismacloud. For example, we have a platform that has a number of tools that protect information and multi-cloud environments. If you're doing if you have workloads and containers Etc at Amazon at Google at Microsoft, you have one set of tools that allows you to protect that entire ecosystem where that becomes really important is You know, you could and all those vendors have good security tools.
But if you went with their native tools and think of the number of cloud environments that a typical Enterprise have absolutely most most companies think they have 25 to 30 Cloud instances order of magnitude larger than that typically so you could go down the path of using native tools which creates complexity you have to have a much larger staff. It costs more money or you can rationalize and say I'm gonna consolidate as much as I can and from an operational perspective. It just makes life much easier and I I always think about things from an architectural perspective right simpler is better.
And and if you think in the physical world when you build a structure you have to have the right level of integrity and the more complex the structure Than the probability of it having the right level of Integrity goes way down. Yeah. Let me look.
This is you talk about ISS and back and I'm thinking back. Yeah, you know, I co-founded still secured 2001 but this is a battle that we have fought in Security even back. Then we were fighting it, you know one throughout the show best of breed.
How many tools can I effectively manage in my organization and quite frankly, it's not even just security. It's it's the amount of language is we have to exactly and yeah environments were using and how many different Cloud providers but you know, I I, you know as if we look at the Timeline as time moves forward. I think the tendency is to get more complex not less complex, but someone has to fight the good fight I'm saying, okay, but we got to manage this.
Yeah, it has to be manageable. So anyway, what else is new here at the show for for prisoner and Palo? Yeah.
So one of the things that we did this last year is we acquired a company called Cider security. Yes. I was excited.
I thought that was a great pickup. We well we think so too and one of the things that's really important to organizations is protecting the software supply chain. Yep.
So if you think of most developers don't write code line by line anymore. They take blocks of code from existing applications exactly from Repose. It could be something they wrote.
It could be open source. So the challenges so what do those blocks of code contain? Right and and especially with open source, you know, one of the benefits is it allows you to build applications much quicker, but you don't know what's in there and who wrote it so it might have some added surprises that you really don't want.
And and so it becomes really important to understand that in a very detailed level. And then the other thing is you know, we have the buzzword Bingo shift left term which It makes sense. translates into build quality in from Step One and you know, I'm sure you know from from your experiences.
com. Yeah, we're really crazy. Exactly.
Exactly. So retrofitting security into code is very very hard. If not impossible.
It's like quality and Manufacturing. Yeah, so when a car rolls off the assembly line, you don't say let's add quality now, right? It's a function of the manufacturing process and building code especially in in devops environments is really important because people are doing sprints all the time.
We did a survey and the vast majority of companies are implementing code once a day and so that yeah. Yeah that times are more exactly exactly so you have to balance speed with quality, right and and developers in general are not incented to inject quality and that that needs to change the devops, right? That's right.
You do more faster and higher quality substitute security for Quality. Yep do more faster. With better quality that was what the promise of devops is.
I'm gonna tell you something I was in we were talking I was in Amsterdam last week. Yeah a cube car and you know what I did to a lot of cute concerts kubecon used to be focused almost solely on developers who right we are gonna do micro Services, we're gonna do kubernetes and we're gonna make these developers shift left. We're gonna make the developers responsible for security.
We're gonna make the developers responsible for testing. We're gonna put more the developers responsible for the cicd software supply chain, who The developers on the highest paid people and that scarce his resource in many cases in an organization. I for one think we've played shift left out.
What did I see a cubecon? Pull developers, right? But let's stop putting more straws on the developer camels back blue security people.
Have to make it easy for the developer not to be a security person but to be a security Champion. Yep. But it's still inherent on the security teams who you're selling to yeah, right because they're the ones buying security tools is even if the developers use them.
And so we need it and it was good. I saw an emphasis on What I Call Plumbing who? At kubecon right operators are back whether they be SEC Ops whether they be srees or platform Engineers or what have you.
We can't put the oil on the developer that you've got to give them a secure environment right that someone has thought through and put into place. So so building on that. So in traditional development environments, you have your tools like a varicode or contrast or the artist formerly known as four to five and they known as they're now known as HP HP 980 that was another one alien.
Well, but okay. Yeah the right. Yeah after a while.
Yeah, I'll have to tell you side story about farmer after who founded early. Yeah actually founded fortify as well. That's where yes, but yeah.
Yeah and why I confused them again, no worries. No worries at all. So what's happened?
Historically is developers have this one screen for security testing. They have one screen for their development environment and developers hate that yeah, right, you know, it's like I want to do everything in one place. So so when we acquired Bridge Crew That's our yes, ICD great conversation.
No, it was wonderful and great great Evolution. Yeah. Yeah, so Our our ci/cd pipeline solution integrates into the screen for GitHub gitlab Etc.
So as a developer, I've got my code. There'll be a little message that appears on their on GitHub or gitlab. They're development screen say you've got a security problem.
Do you want to fix it? And and that makes life so much easier for developers. And so that's what I'm talking.
Yeah. Exactly. Exactly.
Yeah, we can't we can expect our developers to become Security Professionals. but if we power them they need to understand good security hygiene, you know, the security team is there to coach and you know, periodically check the the security health of applications, but at the end of the day, it's the developer that needs to do the work. And we've got to empower them.
Anyway, hey, I'm sure we're way over 15 minutes, but that's okay was a good catch up, right? But Alan simmel Standard Time. Yeah, I run on well it gets worse as I get older.
I'm afraid anyway, Bob. Thank you for so much. Great to see you.
It's good. Thank you. Bob West Christmas security here.
We're live at RSA. We'll take a break. We'll get our next guest Mike up and we'll be back in a moment.





