Grayson Milbourne, OpenText Cybersecurity | RSA Conference 2023
Grayson Milbourne discusses the latest from OpenText Cybersecurity, its channel-focused strategy, and how tool simplification in this data deluge is the way forward for SMBs to remain more cyber resilient, secure and move their business forward.
Transcript
This is texturung TV. All right. Hey, we're live back here at RSA.
It is a day three well day two but sorted day three, it's Wednesday. How about that? And we are in Moscone West people going up and down the escalators to their sessions.
I'm really happy to be joined by Grayson Milbourne. Grayson is with open tech security. We're gonna tell you all about that in a second but Grayson welcome and thanks for joining us here.
Yeah. So Grayson, let's start off a little bit about you. Well, thank you.
I'm so I'm the Cyber. I'm the security intelligence director at open Tech cyber security. I've worked in cyber security since 2004.
So I'm approaching 20 years. So it's as you can imagine in those 20 years A lot has changed in this landscape. And so my primary role is focusing on efficacy.
So I work within the product team. I used to be a threat analyst for about a decade and now I work to align throughout researchers efforts with product life life lion and efficacy improvements to basically ensure that our products stay effective against the ever-changing threat landscape. Excellent, man.
So Grace and look open text is a company name that I think a lot of our audience is heard when we started saying open Tech cyber security. It might be a lot of blank stares. Understandable, give us give her a share with our audience.
What is open tech security? Yeah. Yeah.
So open text cybersecurity is a newer division of open text and it really began in 2018 when open text acquired guidance, which is encase and pretty well known brand and then in 2019, they acquired carbonite and Webroot and I actually came from the web route side of things and that's where most of my career has resided but open text really saw cyber security as a really opportunistic environment to be within and so after they acquired carbonite and Webroot, they acquired another company called zix that does email security a company called bracada that does Network detection and response and then the biggest news really is this this past February open text acquired a company called microfocus and in microfocus has a pretty significant cyber security portfolio as well. Formerly. It was like cyber ress, but they had products like Ark site net IQ for five.
And so really the idea is to bring all these Brands together and Have a portfolio that really can go from end to end from consumer SMB Enterprise ndr xdr all under one brand. Absolutely and just in way of History, right the the microfocus security portfolio came microfocus had I don't know if you want to call it a merger or divestment but the old HP, right? That's right portfolio came into microphocus, which is now part of open text.
Correct, correct, right? Yep. And so there's a lot of very very well known security brands that our audience probably uses on the daily basis that now come under this microfocus cyber security.
Yeah. It's really exciting for us because there's so much threat intelligence that we're now able to combine and it's that stronger together message really for us when we saw rsa's brand of that. We were like, hey, that's exactly what we've got us that worked out really.
Well this year fantastic and for people who want to explore the whole Micro Focus cyber portfolio. Is there a particular website you'd send them to? com and there's a link to the cybersecurity area and you can then learn more about all these products and in our vision for how we're going to integrate excellent.
All right, I think we've done our job laying out who open text cyberries. Right? Right.
Let's turn now you guys recently released a new Intelligent threat report. Yeah. Yeah, so I'll tell you a little bit more right?
So this is actually our eighth year in releasing this report. And for me. It's like I'm very proud of it because I'm the guy who puts the data together who looks at the data and says Ah, this is what's interesting.
This is what has changed year over year. And so this year again, it's it's a another fantastic report. But you know, there's a lot of different threat reports out in the market and so it's important to understand how we generate ours and one of the core components and how our efficacy works is that we put data collection and Telemetry at the endpoint.
And so really we're just consuming what our customers encounter and there's really no better fish trap in the world for encountering threats then tens of millions of real world users being users making mistakes sometimes and and so we capture that data and our report is basically a reflection of the threats the malicious URLs, the fishing sites IP addresses malware and ransomware, of course, but through the lens of our customer experiences. is absolutely so given I mean you have all of this data. Let's hear some of the findings.
Yeah. Yeah the key absolutely. So um, there's a lot of there's a lot of data in there, but I think the things that really resonated with me was really looking at the impacts of layered security and so because we again, it's our reflection of what our customers see we have customers who use different combinations of cybersecurity products and what we found was that customers who layer their security together see very significant reduction in overall malware encounters.
So for example, we have a DNS protection product that privatizes DNS and then we have customers who use our endpoint and those who use both of those Solutions together see 30% fewer malware Encounters in their environments. And so that's like a product these kind of cool metric that shows that hey as we advocate for this approach to layered defenses that it actually works like we have data to prove it. I think what's also interesting is really within like the ransomware landscape and and sort of like the the perception of is this problem getting worse or is it getting better?
Herb, and I think we have some conflicting data. For example, the FBI at the beginning of the year released their 2022 update on ransomware and they reported a 33% decline. But that's a decline in people who wanted to contact the FBI and say I need your help, but the reality is is the majority of people are paying these ransoms, especially in the SMB space because well, let's face it right here.
It's easier right? It's less disruptive. There's no shame that is exposed publicly and it just, you know can be sometimes the easier thing to do and that's not the right solution because all that really does is continue enablement.
Well look a year and a half ago, right? That was this whole debate should you pay the terrorist? Right?
Right and the government's attitude at that point was absolutely not right, but that's changed and we see it even changing with we see it even changing with cyber insurance companies. Who who Look, we're gonna pay in some cases. It's yeah, we know who the The ransomware gang is this right particularly gang versus that gang and we do our thing with it.
So that is you know, that's the reality of the world. We're in today challenge with that. I find though is it's really important for the forces that are able to disrupt these organizations to have proper awareness of who's most active and who's causing the biggest problem and you know in the last couple of years, it's been great to see some offensive attacks against these organized cybercrime groups in the beginning of this year.
We saw Hive was taking offline. That's a multinational 12 Nations participated in there. You know, that's enabled because people do come forward and I would love to see the cyber security industry or just in general like we need to be shameify the fact that you are breached because it happens.
It's not it's an if Or so yeah. Exact courage is companies to be more forthcoming and to provide information that ultimately does help disrupt these organizations. I mean the fact that the matter is in cybersecurity when nothing happens we win right and you know that you couldn't have said it better and I think that's a challenge with cyber security spending if you have to justify spending money, so that nothing happens.
Yeah, the CFO always looks at I know nothing happened because you're right. I get it. You got it.
The other thing I just want on the ransomware issue, you know, we're seeing ransomware not just by encrypting would see like DDOS ran somewhere. Oh, yeah. Oh absolutely.
So that's one of the other things we report on is, you know, initially the first layer of extortion was hey, I've encrypted your data. Okay, release it right? Well so now right they like 84% of the time they also steal your data and we're even seeing some ransomware groups that used to do encryption.
Now forgo the process of encryption because it's an additional step. There's some complexities decryption doesn't always work even though they claim it, you know, you're gonna get all your data back that's not a guaranteed thing and so stealing the data and then leveraging like gdpr is a fine and most of their league sites post. Like hey, here's the you know the section that's going to find you up to 4% of your revenue.
And so that's a very significant motivator for people to pay and then yeah last year. We saw lockbit lock bitty attack somebody like they had a smart. Team who figured out where they were launched their own DDOS attack against lockbit Lakme was like Wow.
Hey, that's Brazen of you, you know and they're like, you know what we're adding this to our Arsenal now, and so now they you know, they Candidas, it can be more disruptive. But ultimately, right I mean I think extortion is is not going away and so how do we combat this problem and I think that's something that the cyber security industry is really still struggling to solve absolutely What else from the report? Yeah, so some some other cool things are around fishing.
And one of the cool things about how our product works is. Again. We know that these are real-world users who clicked on a malicious URL that took him to a fake login page.
And so this is different from from email based fishing. This is really more credential based capture. And so we can track the brands and it's really interesting to see we track over 300 different brands to see who's who's targeted the most and and not that surprising.
You see the Google the Apple the Facebook primarily trying to get into your primary email account because hey, let's face it if I can get into your email. I know all the other accounts you have if I need to reset their passwords. Well, they send me an email.
I've already there but one of the interesting things is we saw Instagram break into the top five this year. They were the number for most impersonated brand we saw last year and that was sort of interesting because you know, we track Facebook, even though you know, they're related. We look really to see like who's the focus of the the credential capture tax and Instagram to me sort of felt like This is it was surprising and I think what it shows is there's a continued focus on younger and younger people and also Millennials are getting a little older and you know, they're getting jobs and they still have their Instagram accounts and you know with password reuse as common as it still is you know, that was someone interesting.
The other thing on fishing is that now more than half of fishing sites are hosted using https. And if you go back 10 years when fishing was still a massive problem Almost 100% of them were HTTP, exclusive, but we've taught people. Oh look for the padlock, you know, make sure you have in the bed guys aren't stupid.
No and you know what? It shouldn't be this easy because certificate authorities the people who issue you issue those SSL certificates so you can have an https website. They're not doing their due diligence in that vetting these companies and you know for very small amount of money what the problem and it's funny because the interview before you was the CEO of did you sir?
Oh, yeah. Well, I'm sure they're doing a good job, but you know The problem is they don't sell the certificate directly, right? You most a lot of these people get their certificates right from their hosting provider.
Yeah. Yep. And and so the whoever you're hosting provider is and whoever they uses certificate provider.
It's a it's a blank, you know, a web based kind of things that they don't do that you diligence now a few things are happening though, right? They're making certificates expirable. Right?
Right right in a much short. They're talking about 90 Day certificates 30 days different. It's even like one day or by hours.
Yeah ever good. Well that makes sense for fishing because most times we see fishing URLs last for about 12 hours. Yeah, and the other challenge with fishing and why are our Solutions really Poise for this is that a lot of times those those links to that fake login page do arrive via email, but it's a unique URL per email and so they're very difficult to crawl organically and you have to have you have to sit like where the user is.
You know what? They're not done these bad guys. No, right and they get smarter all the time.
Yeah, and now of course empowered by Ai and it's gonna be a whole different world where I was actually just talking to the digit circuit guy about this. I mean, is there gonna come a point a time where you know this texture on TV interview with Grace and has a certificate on it to prove that it's really Allen and Grayson, you know, I mean the amount of voice that is recorded in this conversation is way more than enough more than enough, you know. Yes about it.
Yeah. It's a great world. It's great.
You know, all technology has been seemed to be used for for good and/or bad. And so I just hope that the the good far outweighs the bad here but it's gonna or something, you know, I'm doing this really long time. Yeah for all of the bad that you know on the horizon and we think you know Dooms Day right?
We're a heck of a lot better now than we were 20 years ago when you started. Oh, absolutely. Oh, absolutely.
I mean no question. No question. Well, I did on a positive right there Grayson for people want to get more information on this report from open text cybersecurity.
Where can they go? You can go to open text? Calm slash threatreport.
I believe that's the URL. com look up cyber security and threat we'll get to find it there. You got it.
Excellent, man. Hey, thank you for coming on tech strug TV, you know these all year round that just did RSA keep us posted on what you guys good morning. All right.
Open Tech cybersecurity here. We're live at RSA. We'll be back in a moment.





