John Hernandez and Matthew Vinton, Quest Software | RSA Conference 2023
Software supply-chain attacks are rising. Because of this, supply-chain risk management is top of mind for many CISOs and other IT decision-makers this year. In this segment, John Hernandez, president and general manager at Quest Software and a former executive at Salesforce and IBM, shares insights from Quest’s thousands of customers on the top five questions that all CISOs should be asking their security vendors to secure their software supply chains in 2023.
Transcript
This is texturung TV. Hey everyone. We're back here live at RSA.
I want to see day two the used to be Monday wasn't a real day. But Monday was a real day here. So we're day two of RSA happy to have from Quest.
Is it still Quest software? It's just yeah from Quest software Matthew Vinton John Hernandez. Who said my memory isn't what it was I just did.
All right. Oh, yeah. Just wanted to just wait once you said that I said God damn it.
I'll show. Anyway, gentlemen, welcome. Thank you for joining us here on Tech strong TV.
So, you know what before we jump into Quest because I I want to bring it for the audience. Why don't we talk a little bit about each of you tell us kind of your own story and who you are John, let's start with you up into it. Yes, so I I'm in general management.
So I manage the businesses of Corporations and many of which over the last decade plus has been around Cloud management. You know, whether it's a CEO for service Cloud at Salesforce or the general manager at Genesis contact center class. So real deep understanding of cloud management and devops and all the security that goes into make sure customers stay up with their applications actually and Matthew.
Well, I'm kind of a junior here at Quest actually. I just just passed my 10 year anniversary and I'm in presale. So I talk to you and work with some of our largest and most complex customers here in North America.
Love it. Ten years at one company. Today is good Runa.
That's a run. So going strong too. Yeah good for you good for you.
So gentlemen, look, I know Quest software. I'll be honest with you. The reason when I first became aware of Christ software and co-founded a company out in Boulder, Colorado and we were at a incubator from Moby Adventure capital.
Okay, and the guys who shared the incubated space with us? I hated them they're paying the ass. and I can tell you story off camera about it.
They're CEO. His wife invented that remember the what is the clogs the plastic Crocs Crocs? No, the things that go in the whole Crocs.
Yeah, his wife and daughter invented that by accident and they sold it for millions and he was so busy doing that. He paid no attention. Yeah to the company that was taking our sharing space with us.
And that was good by us because we wanted this face, you know Crocs are back. I know yeah angels are all absolutely they're like, what's an oldies new? Yeah.
But anyway, they the company that he neglected quests wound up buying and that's what I said who's by these people well because Quest had so many even back then. Yes 2004 2005 maybe six. What a portfolio of companies.
Yes. so that was you know, tell us about Quest. Yeah.
So what we represent is the Microsoft platform management business. Okay. So it's everything around security compliance on active directory M365.
That's really our focus and why we're here at the show. This week is telling that story, you know, it's interesting last week a few of us were in Europe where we had about 300 customers across London Paris Frankford many Security Experts in there coming to share knowledge. So it's very timely as we're heading into RSA here and some very big top of Mind topics around risk mitigation.
How do they follow the nist framework in the US or Miss to in Europe? And how do they take a look at not only their perimeter and network and other security aspects but really protecting the crown jewels, which is authentication through active directory and that's really what we're here about really. Okay.
Yeah. Absolutely, Matt. He's right.
But yeah, you know, just Echo what you said earlier though, like that was a huge challenge for me. I was a customer before I could work request. It's like just understanding what the portfolio was all about.
But yeah, just to you know, okay John said It's easiest to think of it as just aspects of the nist framework, you know, we will assess your active directory to see indications of potential exposure will detect changes to you know, cross many Microsoft platforms that might indicate that there's compromiser or just problems in general. I'd protective controls and some really unique and very powerful ways. And then finally we'll respond and allow you to recover and you know, in case the worst does happen you need to put things back the way they were agreed man.
Hey, so, you know, it's funny active directory. Yeah, everyone in our audience knows active directory. This was one of you talk about the windows m-word, right?
Yeah Antichrist people get involved and yeah Windows had a good market share but active directory was the power that was the lock-in. Yeah now with the move to the cloud and non Windows machines and machine identity and all of these things. You know active directory has had some changes.
It's available as a service now, of course not sure idea. Yeah. What are some of the challenges here from a security perspective that Quest helps with?
Well, the big one really starts around the vulnerabilities of having multiple instances. Most every government most every corporation is gonna have multiple instance, especially if you're acquiring companies like you're talking about so the first thing is how do you consolidate that remove old employees out of that? How do you how do you modernize that and move to Azure ad when you're ready to do so that's step one that that is otherwise, you're gonna have so many possible entries into your active directory stack.
It's vulnerable, you know Microsoft just published a study on this for 2022. Over 1200 password attacks a second are happening around the world. I mean, this is the crown jewels that all the hackers are going after so defending and protecting it is so important after you modernize and migrate those into a single stack.
Which takes a long time for many companies. It's how do you protect it identify vulnerabilities defend it if you're getting attacked and ultimately if you ultimately get attacked on this is how do you recover from it? So you don't get held for ransom, right?
I love it, you know just kind of tell on to that, you know moving to Azure ad is a little bit of a misnomer for most organizations. It's really an additional identity. System that's linked to your old identity system Give an example like really recently information came out on the so called Mercury attack for instance.
And if you look into what actually went into that that was a pathway that attacked the cloud but it attacked it through active directory. So, you know, we still think it's critical because actor just simply something that organizations aren't able to to get rid of most organizations in the way. It's always five years out and Five Years.
It'll be five years out. Five years well an internet dog time, baby, right? So here at RSA Right, you guys haven't sponsorship here.
I'm gonna assume there's forty thousand people back at RSA this year. Yeah, it's great plus more. Maybe there might be more.
How is that you know, how is this playing because you know, the security game is we're all interested in the next shiny. Yeah object. Yeah garbs our attention.
I'm wondering how this is playing out here in the show floor. Yeah. Yeah.
It's it's been very receptive by the folks coming by the booth and it's been pretty busy coming by to understand. Yeah, I think the active directory hang on everybody knows about the endpoints and the network and you know, all that good stuff identity and things but active directory is a Hot Topic right now just because how vulnerable it is and if you get hacked into active directory your employees can't use any application like everything comes to a halt in that organization because I am is still tied into it, right but this brings up a trend I've seen You know we and we talked to some companies that have like active directory Alternatives right like a jumpcloud or these folks. Yeah.
separating eye from a right where maybe I use active identity active directory. to help with identification with identity Authorization, but not access. Right right so that we're not all our eggs in one basket.
Now. It may make life a little harder using one thing for identity another for access. But maybe we I don't know from a security Matthew you you're the sales engineer here, you know, that's an interesting philosophical point.
It's something I've actually thought about quite a bit because there's this sort of tension between consolidation and breath so You put all your eggs in one basket. That's one thing that gets broken, but it makes it easier but it makes it easier. That's exactly right.
And when you have many baskets, you're also kind of can be ironically increasing your attack surface because of the tools that you're using. Thank you balance there that you need to take around like all right, well gosh, you know for a really practical example, it's like an organizations get hit by ransomware after she's down. They're losing Millions per hour, but at least their emails still up because that's a separate liathenticated system because it's in you know, exchange online or Google Cloud.
So yeah, I fully believe there's a middle ground there. That's appropriate and and we're seeing in the customers like he's kicked off with I mean, it's it's prevalent everywhere in the world active directory. And so if you're not gonna go down that path you need to make sure you can protect and defend and ultimately recover if you get hit and that's really what we're all about is just giving assurances and protecting those customers with their crown.
Jewels. Yeah. So we're all well, maybe you look a little younger Matt.
You're only saying about me not right? I would never say nothing about you. I'm of an age believe it that.
Where you know working with Microsoft sometimes wasn't always the easiest. Yeah now it's a different Microsoft. Yeah, we all know that.
No, it's still a active directories Microsoft's. I mean, it's one of their crown jewels, right and How's you know, that would have to make question. You got to be pretty tight Microsoft partner.
Yeah, the technical level were very tight because we don't duplicate what they do or additive on top of it. So they see value in that from a technology perspective. We're all so in their marketplace with Azure, so that helps with the shield integration and customer, you know, reducing of the Mac.
So there's a lot of those things that really bodes well for the relationship with those guys they were with that that customer event I was talking about in Europe last week. They traveled with us. They were part of the session.
They LED information flows on all that stuff, you know there there. I mean, it's a pleasure to deal with them now. Yeah good to win.
Yeah. Yeah. In certainly I could tell you stories, you know, I was the hosting business in 1997.
Yeah, and maybe 96 Windows NT had just trying to get me to move off of Solaris. Oh, yeah, it was like Sun's pretty good. 5.
I remember you remember you remember remember? Yeah. I said I don't wraps on top of that there.
I said, I I don't I I'm sorry, but I just don't think it's his solid is Solaris. And the guy from Microsoft said look we're Microsoft, right and it may not be right now, but by four or four point two, yeah, we'll have more market share than them and be better. Yeah and God damn he was right.
Yeah, he was right around they don't. Yeah, don't when they wanted. They wanted that would make some such a good partner for us.
Absolutely. Absolutely. Guys, I want to bring up another topic because you can't walk three feet without tripping over it here this year.
That's what's up. What effect is AI gonna have on all day? Oh, it's huge.
Yeah and the ability to find the needle in the haystack raise the things that need focus on I mean the number of events and alerts happening in the sock these days. It's hard to weed through all that with the basic tools and the ability to play AI over that and have the ability to bring that to the Forefront. It's just simplifying the sock of identifying the problems and you know, another thing in that Microsoft report I was talking about they identify a gap about three and a half million employees short in the security space.
So, how are you gonna supplement that it's through tools like we're talking about an AI to supplement. Yeah, and that's the general security space to say nothing of the kind of like the vertical knowledge that you know those of us with a little gray and our beards have around you know active directly. I don't have hair.
Yeah. Yeah, so I I do it on I think it's quite a big deal. I think we're still in.
We're not even at the end of the beginning. I think we're at the beginning of the beginning. Yeah this one and well, we'll have to see how that plays out as well.
Yeah, the relationship with Microsoft's really help with that as well because it's kind of moved us up the priority into open Ai and yeah, that's generated. Yeah, I understand there with that. Guys before we hang up.
I want you to look into this camera tell people if they are specifically with ad issues and that kind of a identity and access. Where on quests should they be going to get information on this? Yeah, so they definitely should go to the quest calm website and search for mpm or what is known as Microsoft platform management talks all about the security migration of modernization of AD.
com and PM Microsoft product management platform management. Thank you. Who said you didn't have a memory.
I got the names right now just shut it down in that point. Hey, we're live at RSA. We're gonna be back in just a minute stay tuned.





