Ira Winkler, CYE | RSA Conference 2023
Ira is CISO at CYE Security and author of 8 books including You Can Stop Stupid, Security Awareness for Dummies and Advanced Persistent Security
Transcript
This is texturung TV. Hey everyone. We're back here live at RSA.
You know, look it's a bit it's two days in and I'm already having a great time here. Why am I having a great time? Well the excitement at RSA this year is palpable but really for me it's about seeing my friends.
You know, I called my wife this morning. I said, you know Bond. I see all my people here.
I'm so excited. I was like crying already and I you know, and I talk about my people I were a Winkler. One of our people here in security if you're familiar with security, you know Ira whether no matter what the company on his shoulder on his Justice Iris been a mainstaying security for many many years probably longer than he wants to oh admit to but anyway, it's a pleasure to have you on texture on TV live at RSA know at RSA coming and awesome to be here.
Absolutely. So the shirt says size security. Yep.
Tell us what's the deal there? So I security is a company that frankly I thought was awesome when I go back to when like I wrote my first book in 1997 you admit it. I admit it was published in 97 wrote it in 96 called corporate Espionage.
Everybody knows that I updated the title and 2005. It's spies Among Us was an update to corporate Espionage and incorporate Espionage. It was essentially a book about applying risk management to Security because everybody's like Oh, we must be secure and I tell people you know, I say, are you security professional?
They're like, yeah I go. Well congratulations. You're a failure.
They're like, what do you mean? I thought there's no such thing as security the definition of security is being free from risk. We're never free from risk.
It's all about risk management. And in the book, I remember I said the biggest problem with cybersecurity is that CISO get the budgets they deserve not the budgets that they need and they need to learn to deserve what they need now going back to why I left Walmart to join sigh what happened was they actually have a program. They it's risk optimization to me technically people would place it in like because everybody has to Pigeon put it into a bucket.
Yeah, they call it risk quantification. But we take risk quantification and really really accurate. We actually use machine learning not as a buzzword, but have real experts implementing it and we're able to quantify risk within 7% of actual what it is based upon studying previous incidents based upon taking the output of like, you know, Big Four consulting firms and applying it to our clients and we get it risk quantification down to seven percent.
We map out attack pass vulnerabilities and figure out the probability of vulnerabilities being exploited and then we're able to take The probability of a vulnerability being exploited with the assets that it touches and coming up with a dollar figure for a vulnerability. And then we also have within the system the capability to know what it costs to mitigate so we can actually do mitigation planning. That's actually true dollar figures not some mythical.
Oh, this is a critical vulnerability. This is low high because you could have a low risk vulnerability that's going to create a bigger loss than a critical vulnerability. Absolutely.
Absolutely so Is this done is a Consulting sort of Engagement, or is it a more of a product service? Well the company it's one of those Israeli companies that started with Israeli. Right?
We say that with all due respect is both of us are members of the tribe here, but I don't want to insult anyone Ira. It's actually a good thing though because you know Israel, they're known for having cybersecurity offensive experts. Absolutely.
This company comes more from the defensive side of doing like red teaming and incident response for the Israeli government and then they applied what they learned from the Israeli government and they did start out more than a decade ago doing You know penetration testing Insurance response, but then they actually said hey what would happen if we take nation state level mathematicians and AI experts and apply them to you know, the fine the problem is like I've always said this most penetration tests are a waste of money. The only value of pen test has and how you take that data to mitigate the problems that you find or else. I describe it as pulling a Nelson.
You know Nelson from The Simpsons. Yeah. Most pen tests are like, haha, right and you need to take that data and figure out how to apply it.
To figure out how to mitigate and that's essentially what they came up with. And that's important, you know because look I had this guy. I was in the Amsterdam last week cubecon and all of a sudden everything Cloud native is about security.
And I'm a big fan. I'm happy to hear that. but we had this discussion about the whole critical vulnerability to medium vulnerability look you were around then I was here then when the whole CBE scoring system was was drawn up and everything and as we sit here now in 2023 I realize just because it's a critical vulnerability according to nist or miter or whoever doesn't necessarily mean.
It's a critical vulnerability to my situation because it doesn't have the context. Yeah and context has to be taken into account when we talk about risk. Exactly and that's one of the problems because when I would do see the thing is I what I mentioned corporate Espionage.
Yeah corporate Espionage was my first attempt in theory at a dissertation. I've been pursuing my doctorate for 30 years now. And what I did was I said, let's microanalyze actual incidents and figure out what were the root causes of incidents and you know, I started developing case studies.
I'm like, wow everybody I would talk to they're like, this would be a good book. So I Had a book essentially of lots of case studies and what enabled it and when you look at what are the enabling functions of like when I stole nuclear reactor designs it wasn't because I compromised a zero day exploit. It was stupid things like somebody leaving a door unlocked something really simple and you would call that.
Oh, that's like a low risk not critical, you know, then I get on a computer system. And yeah, there were one or two maybe that was critical, but if you couldn't get to the critical elements, it's not a critical vulnerability. So anyway, I'm too many people it, you know, like criticality is a way of saying if this is relevant in context then yes, this is a critical vulnerability and we need to account for that.
And at some ways and I do agree that well eventually somebody will get to Any Given system. So maybe a critical vulnerability would be exploited. But if I have mitigating controls, like for example log4j that was a classic example to me where you know, I'm sitting there and I know there's a lot of major organizations that to this day.
I forgot I don't think one two years later. There's still log for Jay instances on their Network. However, that is only there because they put in mitigating controls and a critical vulnerability with a mitigating control is a move point now.
Yeah. So anyway, sorry just being that I Ira that's exactly what we're talking about. It is a move point right now, so My audience out here.
They said that that sounds good. I'd like to engage with with size security. How do you how do you engage here?
Oh, just feel free to reach out to Ira at size you personally. Oh, yeah. I know.
I'm actually horrible at this. No, but yeah, I mean if they went to the first one that don't let me start. Okay, you know, yeah just a few years in security.
I still got a Breadcrumb him here. com. Yeah.
See, I'm not a market. I just love what I do, but we okay. com we see this you know this whole kind of well, you know lay down demo.
I mean because I okay you can't see the problem is I can describe it and when I describe the functionality all of a sudden I'm going way off track. And the reason is it just does so much that a lot of people are like, okay. So cyberists quantification I get a graph it's like no you don't get a graph you get a dollar figure and the dollar figure is broken up into all these different figures and then I'm going on for 15 minutes describing something I like.
Yeah, okay. Bye. Anyway, hey, I got you.
Well, but it all depends on your audience. Yeah. So let me ask you another question.
I'm listening to you and I'm thinking to myself this is something cyber insurance companies would love. Yeah, you need a Biz Dev guy. I I'm not allowed to qualify, but I do believe we need a good business.
Alright, I mean this is I I got to assume you know, this is something cyber insurance companies. Okay. Hey, you want a policy you got to run?
Well part of why is our data is actually so accurate is that we are taking in data from insurance company. Okay, and so the partnership with insurance companies probably can always be improved. I'm going to assume but really if I was a cyber insurance company, we're talking to someone, you know, I can't tell you which are record, but you know, frankly, I'm The other competitors out there.
I'm positive. We are better than or I wouldn't be with the company, but I really do think that there is a good Because at the end of the day insurance is for underwriting and insurances will last resort. I would rather have people start thinking about insurance and they do need that because no matter what and like I started there's no such thing as perfect security.
Yeah, and you need to mitigate your eventual losses, but having this to help quantify where you should go ahead and which are the best vulnerabilities to mitigate. I think that's the way to go. so and again, it's probably a different rabbit hole, but you know, I I think cyber insurance companies have taken on a different role.
than what we see regular insurance companies do in that they are becoming sort of the PCI industry of security or the PCI Council of security and that they're saying hey you want cyber Insurance? You've got to meet this bar. It may be a minimal bar, but you got to meet this far.
I'm actually I have always let me tell you when I became a fan of Regulation. back and give or take 2000 well 2,000 ish somewhere between 2003 maybe in 2007. I remember I was talking to a actually here at RSA.
I was talking to a friend who was a seesaw for a known retailer. Not Walmart. I should say that but a known retailer and I was saying so how's it going we were at the RSA party when they had a big party and she's like, do you know how hard it is to find encryption for a Mainframe?
And I sat there and I thought I was telling her, you know, I know unfortunately I have zero sympathy for you because what you're telling me is they're all those credit cards on your Mainframe. They're not included. And that's where I came up the cons.
There's this there's an expression. I have a few iraisms. One of them is when something's a should and not a must you should all over yourself.
All right. I've never heard it put that way. But okay and what happens is until PCI came out encryption was a should not a must And now with insurance companies when insurance companies are doing because I was talking to Aon and I think they had like 20 criteria for insurability.
And the reason those 20 criteria are there is they've gone through and said okay. These are the criteria that we found when they're not in place leads to actually risk. And so what they are doing and why some people hate it.
I love it. They're making shoulds into musts. And the problem is everybody says they should be secure every you know, there's a whole bunch of shooting going on and all over the place.
They don't get secured till they absolutely positively have to and that's and to that extent we're insurance companies are doing that. Unfortunately. Those are the people who are paying the price now, it's kind of a murky road because there's some conversations going on about if it's a nation state involved attack.
Because then what's a nation state involved attack? Is it a nation-state? Cause Shadow Brokers for example is a Russian entity.
The Russian government takes the nation of that and so on hard to prove. Yeah. And so I think that's gonna be a concern I might have with insurance carriers, but otherwise I'm kind of for them doing it because you know, I remember back in I was talking to Richard Clark former and I came up with what I call the Winkler act and what the Winkler act and I asked Richard I go how about this that you know vulnerabilities have to be patched within a given period of time systems have to be maintained by the appropriate number of Administrators by the vendor recommended like, you know one administrator for like 20 systems or whatever.
It is automated patching enabled multi-factor authentication. Whatever it was I forgot something else and Richard Clark was like, yeah. Absolutely, nothing wrong with that, but it'll never happen and why because everybody will fight.
What should happen being turned into a what must happen? And we need this because we've had Decades of self-regulation that has gone nowhere. But but tell the truth.
I think security is more. A real priority. It's always been a priority but it's a real priority more now than it ever has I think in certain circles because for example, if I were to go to the large Banks out there if I would go to like the Capital One the Wells Fargo US Bank whatever it's a must period they have top rated staff top rated sea so's high value budgets and everything like that.
I start going down to some of the smaller Banks. It's a should. Some of the smaller Banks and again, it's like I was horrified.
I spoke to a seesaw once who was going to bring me in to do an assessment. He's like Ira because he just got the job and he's like Ira did you do you want to know why I never called you back about your proposal which I told you, you know, I'll just get it signed the following day. He's like I was told the only reason I'm here is because the order said they need to have so in place, you know, that was that was very true.
We see so but so it's getting there but still there's a lot, you know from the top people the A-list players you start getting some of the BC and especially Dee security starts becoming a should more than it's a must atop because they don't have the oversight and maturity and I'm not trying to like there's some I shouldn't say all of them, but unfortunately, they're still active. It's selective I think by verticals and other things. I don't want to end on a sour note though, right we've made progress we have and again the A-list players before um, you know, that's something like it was like, I remember I was one of the investigators on the City Bank breaking in 1994 and City Bank top.
Skilled. Hey, let's player A-list players all around but then the other Banks started coming aboard and they started all you know, raising the bar for them and I still think we have got a lot further and the thing is despite everything. We see if you want to high note.
We're kind of making it through I do think we have more loss than we should have. But we have for lack of a better term a really resilient infrastructure. And when we see some major incidents here, we see however that it's We still have an environment in place where we can operate where we're doing trillions of dollars online.
I hate these fake statistics people make up like, you know, we're having a gazillion dollars worth of loss by you know, 2027 or something, but we are having this but somehow we managed to get through and constantly innovate. Yeah, and that's what I would like. Yeah, and that is true.
com. Yeah virus says they're good. They must be man the pleasure.
Good luck in the new role. I appreciate it. I think that may wrap up our days coverage here.
They do it RSA. We will be back in the morning bright and early I think 8:30 Pacific time, which isn't so bright in early back home, but we'll see you then. We got some parties and some RSA sessions to go to right now parties.
But thanks for joining us today. This is Alan Shimel. We're out of here.





