James Hadley, Immersive Labs | RSA Conference 2023
Cyber teams face mounting pressure to build and prove cyber resilience; however, many teams are ill-equipped to protect their companies or even diffuse the impact of cyber incidents. By tapping into the capabilities of the people rather than just the technology, organizations are able to strengthen their workforce’s cyber resilience. While this process of proving cyber resilience can be difficult, there are ways for leaders to organize their practice to better benchmark their progress.
This interview will also cover the disconnect between confidence in cyber resilience and proven capabilities as well as the link between psychology and effective cyber training.
Transcript
This is texturung TV. Welcome back to rsac here in San Francisco 2023 have more great conversations, but not only about technology but also about people and our skills and are what we need to do in the case of an incident, which we're having that conversation right here with James Hadley. Welcome James James the CEO and founder of immersive Labs.
Thank you for having me you bet. Well tell us a little bit about yourself and tell us a little bit about the company. Yeah, sure some James Hadley founder and CEO of immersive my background is it geek growing up?
I played with computers because I didn't have any friends and then went on to join UK intelligence agencies working in cyber security before having a career change to sort of teach cybersecurity and help upscure the Next Generation coming into the field and it was during that time. I identified that you can't really measure prove the capabilities of people that have sat in a classroom watched your video completed it multiple choice exam to get certificate because really when something happens inside, but you want to know that person's got underlying cyber traits like analytical thinking problem solving troubleshooting perseverance self-research and curiosity. So by seven years ago started immersive labs, and the concept is helping large Enterprise organizations, prove the capability of their teams.
It's my strong belief that cyber security is no longer the sole responsibility of Geeks in the basement. And actually it's across business issue wide from executive teams to developers Cloud engineers. To the Cyber team and including non-technical individuals.
It's really hard today for organizations to be able to prove that those different teams have the knowledge skills and judgments to keep organizations safe. So we are all about helping to exercise organizations. So they can prove their capability not only internally but to their regulators and the board or investors so they can start to feel a bit more confident about their posture going forward.
The analogy to make for folks is if you're going to do a product line, you wouldn't just go to class about product launch and take a test about how you do a private large for all the parts of the organization you instrument you outline you even rehearse some of it right for doing a press interview or the review the collateral same thing on an incident because it involves all parts of the organization and the organs during that moment, you know, we're all at our best at 4am on the weekend on the holiday and of course and you know, you need to fall back on what you've been train. Not just educated what you should do. Yeah, what we what we find is many organizations have a written incident Response Guide and written policies as part of their ISO 27,1 certification.
But when a real instant happens, they tend to turn to the person the room. That's what the most experience that's done it before that's got that muscle memory and that's what we do. We help organizations build that muscle memory.
So when it does happen at four clock in the morning on Friday or else I say they can be a confident. We've got this we've drilled for this we know where our capabilities are. Let's just go ahead and carry on go talk about how you do that in lab kind of scenarios workshops.
How do you actually Implement that for people? Yeah, we better experience. Question, we bring that to life through Dynamic Hands-On exercises and simulations, but you need a different approach depending on the audience.
So what will work for developer isn't quite the same that you put in front of an executive or board member. So for example for the red and the blue team we spin up these Dynamic virtual cyber ranges spin up in the cloud on demand and then we run that team to an exercise be an instant response or red team exercise and then we can give the customer back data around where their team was strong where they might have gaps and critically how they benchmarking. It's their peers in the industry anonymized.
So not every organization wants to be the best in industry, but they certainly we don't want to be particularly like lag Goods at the bottom. So it's helping to prove capability up skill those teams so that when we exercise them again in a quarter we can show improvement over time. You've mentioned Geeks in the basement like you like yourself in your past developers Security Professionals.
We talk about comms teams Executives. It's quite an orchestration that happens in an incident. How do you imagine the training you give to a CEO or to comms team legal team is very different than what you might give to a security team or software engineering team looking at that, you know in the code find out what happened.
Yeah, so I think it's all about putting people in environment the most comfortable in and then sort of seeing the decisions that they make but also not only what decisions they make but how much how much confidence they have in those decisions. So what we're going to identify through board level exercising for example is rather than a traditional tabletop, which is kind of the market with disrupting of PowerPoint and going or what would we do in this scenario and imagining it but then just moving on in a linear path, we're able to put each individual board member or executive through the tabletop exercise and then they have to make a decision and then based on that decision to crisis dynamically changes and we record things like rational and confidence so we can see how an entire board goes through an event. Where they end up in that exercise and then unsung their confidence levels so that we can help our customers write their playbooks and then go hang on we had these particular members of the team who made what we consider terrible decisions with high levels of confidence and that's a bad combination.
So we would bring that up to the organization as a potential risk. I know there's a Forester report I've seen in your website the talks a little bit about this and the kind of thinking about holistically across the organization. Tell us about that.
Yes. It's commission study across 316 Security leaders may see from the US UK and Western Europe and what's it identified is whilst we know about the Cyber skill shortage. There's a distinct lack of Readiness even within the teams that people have got so for example 82% of the Seas.
They said that they had they been more operationally exercise but head of the incident. They think they could have mitigated some all of the impact of previous instance. So it's always catching them off the back foot and statistic that came out is 80% of these days and felt that their team were ill prepared for the next day.
They had no confidence in their team's ability to respond to the next attack and that's a big numbers. That's mildly terrifying. So some of the things that you want to know is also what not to do right the decisions you make for example, simple one.
Well, maybe not so simple as like Don't Unplug servers that are in the middle of encrypting your data in a ransomware because you may end up with you know, unrecoverable data, but sometimes it's just as important things you don't do is what you also what you do that's proactive. Yes. So we see that especially where you have technical teams, maybe butting heads with business teams.
So we helped a large Bank Financial Services run an exercise where the the team that the side of the decision that the Cyber team. We're putting forward as part of the excise was to disconnect like systems and then for surpassed reset say that they could kind of try and get the actor at the network but they didn't realize that that's during trading hours of like where there's billions of dollars at risk of Any Given trading organization, which would have been completely unacceptable to the business and then had that day in time to the actual financial services and the underlying Market Equity. So uncovering those differences between what people in the technical Thinks is the right course faction against business impacts.
I think it's key and it's hard to do that especially now a post-covid remote working. We don't all happen to be in a room for the four hours going through an instant every week. So coming up with more intelligent ways to exercise teams, maybe even asynchronously, but then still getting all that data back to uncovering risks.
That's where we think the market is headed. How much is the cloud and just you know distributed application Services globally operating company? How much is that changed kind of post pandemic and aft approach this?
Yeah, I think traditionally people that's infrastructure. Clay's networks or architectures that have been recommended but now there might be some on-prem stuff but there's also going to be multiple clouds. We see across our Enterprise customers.
So for example, immersive how we do this is we actually create a cloud within a cloud within the environments where we then simulate these exercises where the cloud team have to go in and identify and fix configurations or triage incident or do forensics because it's quite simple take your traditional Playbook of forensics on a PC or server, but then moving that into Cloud it's completely different. And again, we're seeing customers unsure about the capabilities of their Cloud security team and that's probably why they're looking more tooling to help triage and raise up vulnerabilities. What do you think is one of the biggest misconceptions or maybe don't know what you don't know.
How to respond to an incident what you need to train for and I think it's the the cross team effort. So what we what we see is when we run team exercises within our customers, even though there's a team of responsible one person will often take the lead and kind of charge ahead and that person might be most experienced technical person but a lot of the other team are kind of a bit but why did we do that? And there's never enough time during the instance really explain the rationale of a why we go a certain way and it's like I will tell you later or tell you later.
So we think that what we see is teams have really responsible and short a few number of people rather than having the skills sort of Federated across the team. So for me, that would be the thing that we keep me up awake at night is if my single point of success is not around who's my go-to person are the actual team the rest of the team going to be able to recover. Are there any company sizes that tend to benefit more obviously more complex environments You need you need more coordination, but is there certain size if your medium or small business not so much but if you're entering in, you know, the size of employees, they're kind of a sweet spot and above to take the types of offerings you have.
Yeah, but we see different maturity even in large Enterprises say some of our large Enterprises, they're running exercises and crisis simulations and operational resilience at very senior levels both internally and with their customers multiple times a month. So they have this High exercising frequency. Whereas lower maturity customers might just run their first tabletop using a consultancy and some PowerPoint and therefore they're moving for the first time to technical platform where we see the mace value is when an organization has a number of different audiences like I talked about so they might have developers and they're seeing vulnerabilities being checked into code.
They might be unsure about their Cloud security team. They might be unable to identify talent to help, you know surge onto the blue team. They might not have the latest skills in the red team doing penetration testing.
So it's trying to find an Enterprise that has multiple team. Generally our platform sits but it does go all the way down to smaller size companies where they might only have a team of five in the cybersecurity team and they're trying to do the best with the resources. They have and the budgets that they have.
We typically brings you in is that the compliance officers see so someone in that part of the organization it's typically seize because they're looking for that top down measurement and proof of the efficacy of their capability that often have to work in tandem with maybe heads of operational resilience. If it doesn't sit with the sea, for example business continuity Disaster Recovery also General Council and legal for the instrument response and notification kind of policy things and then VP of engineering for anything in the app sex side. So application security while it's the outcomes the responsibility of the Seas a the people that it affects the developers often don't see in the security organization.
Very good. Well anything you're seeing at the show this year with with RSA. I mean certainly it's bigger Vibe more energy more people that certainly happening.
But how about how people are thinking about tackling this kind of challenge? And we're not saying so much in our space RSA. We typically have three to four competitors that sometimes you know might seem to replicate what we have but that's a we take that as a form of flattery, but we don't haven't seen too much here at RSA.
What we struggle with is as immersive is awareness in the market. So typically if I was to approach a season say hey we've heard about immersive Labs. We specialize in cyber Workforce resilience.
They'll say Workforce must be training must be fishing. I've already got a fishing provider and user dreaming and user training and then we say no we do this and they go that's amazing. And then we take the conversation forward so sort of a lack of that category awareness, but we're seeing more and more players come into this space.
So I think we'll start to see the themes Around The Wider Workforce come out in years to come very good. So folks can get the Forester report find out more about immersive Labs the website. com where there's a whole host of resources, including the ability to download that Commission report by Forester which helps not only talk about the problem.
And what can be done about it would imagine it'll be a good Aid to have that conversation over about bringing you in too. So, yeah, great. Well, thank you James.
Wish you the best of the show. Thank you for stopping by a Textron TV at rsac 2023 pleasure. Great dreams Hadley CEO with immersive labs.





