Exploring Cybersecurity with Morey Haber | RSAC Conference 2025
Morey Haber covers BeyondTrust’s history and its role in vulnerability management. His new book, “Privileged Attack Vectors: Building Effective Cyber-Defense Strategies to Protect Organizations,” highlights 50 years of cybersecurity evolution. The conversation also addresses AI’s impact on identity security and the importance of foundational security practices for the future.
Transcript
Hey everyone. We're back here at RSA, wrapping up our day three coverage. I think we have one more interview after this, though.
This gentleman next to me, I've known him probably 15 more years. Uh, he is a unicorn in this industry. I don't remember the last time I spoke to someone who's been with their company for 20 plus years.
That's Correct. 21 years this year. Uh, and I've gone through almost every role from CTO to CSO now to Chief Security Advisor, uh, being forward facing, helping clients strategize.
Really kind of a jack of all trades. Yep. It's my friend Maury Haber.
Maury works for a company called Beyond Security. You know, Maury, normally I'll ask someone to say, tell me what you did before you joined this company. Mm-hmm.
We could ask that, but I don't know if you know, some of the people watching out here may not even have been alive, but you were with a company called ei. Yeah. I originally came to EI in the early two thousands, and, uh, BeyondTrust purchased EI in 2012, and it's been BeyondTrust ever since.
Yeah. 2018 we had, uh, an acquisition as well. Baum Gar actually purchased BeyondTrust, took the BeyondTrust name as well as Avec and Lieberman, and it's been a fun 20 year, one year ride through all of it.
Absolutely. You know, for those who may not know the history of vulnerability management companies, I, I had started or co-founded a company called Still Secure back in the day. And when we came in, we, in 2003, we came out with a vulnerability management system, van and back then the players, and you'll remember these, Maury was Found Stone.
Yep. Which was bought by mc McAfee, uh, tenable, which is still here. Yeah.
And everybody knew it by then. Nessus at that name, right? Well, people knew it by Nessus.
Exactly. Yeah. Tenable, Reno and Ron.
And then we had, uh, Qualis, which is still here, Still running hot, But really one of the hot ones was EI. And you know, a guy named Mark Re He's actually here at the show. Izzy Mark's.
Here He is here. And look, this is a very different time. We didn't call it cyber, we called it InfoSec, but EI was the, was the s***s, right?
I mean, that was the sizzle there. And, and vulnerability magic discovered, was it code red or the x It, They, we, um, mark Maray identified code red and uh, part of the blaster worm. Yes.
The one got his name at that time. And Retina was the network, retina Network Screen scanner. It was the staple for about 15 plus years.
And the Discovery engine in many of the capabilities or concepts are still even a part of BeyondTrust today because crazy, doing really good discovery is hard and that technology still survives today. So there's your cybersecurity history lesson, courtesy of Beyond Trust and Techstrong with M Allen. I'll give you one piece of that.
So Alan, I I, I've written seven cybersecurity books, Uhhuh all over the Attack vector series from Press Media. Um, my new book coming out in Q3 is just labeled Attack Vectors. It's actually a history of cybersecurity.
Is it? I love It. It covers the last 50 years.
It's a textbook format really highlighting why tools exist today, how they were developed and why do we have firewalls. It's designed to teach new security professionals how we got to where we are today. That's a great book.
When's it coming out? Q3 and it's called Attack Vectors, A History of Cybersecurity. It'll be the eighth book in my collection.
We'll, we'll be lucky for that. It'll be a good one, Morry, when it comes out. You'll reach out to me.
We'll do a I'd Be happy to an interview on it. Happy to. Excellent.
Now Maury, I don't know, not everyone out here's gonna know BeyondTrust. Yeah, either. So why don't we go there a little bit, tell 'em the BeyondTrust.
Sure. BeyondTrust is a leader in identity security and privileged access management. Privileged access management has been around, oh my gosh, since 1985, well before you and I even sure that, but it has evolved is originally started with password storage, then it expanded to lease privilege and endpoint and remote access and bridging.
And there's a lot of concepts that the analysts now call Pam. But now we have this threat of identity security. The Verizon data breach report sites, 80% of Vulner, um, attacks have an identity component.
The BeyondTrust Microsoft, uh, Microsoft vulnerability report, which came out last week in two of 2024, 40% of vulnerabilities have privilege escalation components. So identities, new perimeter, we've heard that buzzword, but really is key to all modern attacks. So BeyondTrust solutions not only protect against privileged attacks, but identity security, the hygiene, the wellbeing, the identity detection, threat response, the cloud infrastructure, entitlements management, a lot of those acronyms like Kim ITDR that we hear about, that's where our solutions play.
Love it. Love it. com.
One word. Good. Alright.
Let's talk about what's news. What's news. So news about two years ago, we introduced a product called Identity Security Insights.
And what this tool does is it allows you to connect to your IDP, your BeyondTrust products, even some of our competing products and get a state of what your identity hygiene is. Okay. Sounds like a lot of other stuff, but there's a lot of unique tech in here.
The first is what we call paths to privilege. What this does is it analyzes anybody's account and the identity relationship and shows you how you could leverage even from a red team perspective, one account versus another to get administrative rights. You may not even be aware of those paths, but it shows you graphically, if I did this, ran this command went here, I could actually compromise an environment.
This leads to what's called a true privilege. What is your true privilege? Do you even know that you have privileges to do something?
Now this tool's been around for two years. It's been fantastically uh, reviewed. It's got good acceptance in the industry.
But what we have found is most people don't understand what the account's relationship is as an attack vector. So we made an announcement earlier this week, uh, as a part of RSA to basically say we're giving a free or complimentary risk assessment to anybody that wants It takes two hours. The tool plugs in full tilt.
It's not a limited tool. Read only access to certain, uh, data sources in your environment. And you get a concrete report of everything.
That's a problem in terms of joiner mover, lever dormant accounts, privileged accounts that have sta uh, stale passwords, hundreds and hundreds of detections. On top of that for a limited time you get the full analysis. We saw PowerShell run as an admin without MFA.
We saw a token hijacking. We saw all of these crazy detections in real time. So people can get good, a good measure of the identity hygiene of their environment.
This goes far beyond an IGA certification report. It's real time analysis of behavior and the past privilege. I love it.
That's great. How could people do this now? How do they get started?
How do they get started? com website on the main page you'll see sign up for an identity security risk assessment. Fill out the form within about 15 minutes.
Someone should call you during normal business hours. Great. Alright.
Let me bring up the next thing. Sure. Look, you can't walk from the light tile to the dark tile here without tripping over ai.
Yeah. How is AI impacting your business yet? Good, bad, indifferent or AI is huge and we're seeing it not only as an attack vector, but we're also seeing it in the solution sets.
So you just walk the shore floor, you'll see every type of ai. You saw the announcement with protect AI in Palo Alto. Okay.
How does identity security use AI Embedded in our products is AI that can tell you the behavior of an account's usage. And this is kind of cool, is a machine account that's been identified as a machine account behaving like a human because it's been compromised. Or is a human operating like a bot because there's some machine or automation behind the scenes leveraging it that you don't know about.
So our tool sets have incorporated AI for a behavioral analysis and we'll be expanding that even further with some generative AI technology that you'll hear about later. I love it. Um, you didn't mention agen AI just to complete the bingo card.
Sure. I know there's buzzwords here and it's bingo. It is a bingo.
Yeah, go ahead. Nothing yet for us on that one or, Um, when you look at identity security, you have to think of what would you want to generate that would be too volumous or too problematic. If you think about what Pam does with session recording and session monitoring, there are organizations that hire dozens of people just to review privileged sessions.
Yeah. What could generative ai AI do to make that simpler to consume a little bit of tidbit that you're seeing in the future? Alright.
You heard it here. Um, Lori, you've become RSA almost as long as I have. Yeah.
20 years almost. Yeah. Yeah.
I'm 2002. Yep. Was my first RSA.
Um, we've seen a lot of changes in these building. There was that movie that came out, what was it here with Tom Hanks? This I saw that but go ahead.
It was a single camera, very unique kind of film by Robert Za Meki single camera of a room. A living room, yeah. Over a course of about a hundred years.
A house, I guess up in like Pennsylvania or somewhere in Northeast. And was the story of the people who lived in that house and what went on in that room, you know, snapshots over the a hundred years. I'll have to look for that.
Go ahead. Called Here. Here.
Okay, great. Based on a very well regarded book. But anyway, if we did that here, right.
If you and I were sitting here and we said, oh, the last 20 years what we've seen change, what the messaging is, what the companies are, the amount of people, everything else Jillian used to be right there. Now it's the Falcon And it used to have the Mexican restaurants and a Starbucks, A lawful place. Here is a Oh.
Gone. Oh, gone. We've seen a lot of change water under the bridge.
Yeah. As you look back and then use that to kind of as a lens to look forward, what do you think we'll see here 10 years from now, even five years from Now? Five.
Well, you know what the movie analogy you gave me was quite applicable. 'cause the first thing that comes to mind is the movie Inception Uhhuh. I keep on thinking I'm living in a dream.
I just had lunch with the same people that I had last year and the year before at fang's. Uh, so I, you know, it's just like, man, I did have that s**t. That's a movie.
Same time now next year. So when I think about, okay, I am in a dream. I'm having the same food, same thing.
I see the same booths and I see a lot of new booths. I think that the evolution of the city is not necessarily the impact on RSA. I don't believe that this area looks the same outside of RSA come here three weeks.
It'll look different. No doubt about hear when it's not RSA And it San Francisco. San Francisco.
So there is a bubble that exists here. Yes. A lot of the stuff I see on the show floor, I have no idea how these vendors can deliver.
I think there's so much marketing hype in the creativity of the booths that what is being promised or shown is not really what's in code and being delivered. And most of the people there can talk the marketing talk, No understanding, no formulation Less than an inch deep. So if take politics aside, economy aside, I think there is going to be some form of level set in the next five years.
Startups are not going to be able to promise the world. You're not gonna see the big vendors with a lot of fancy stuff. We have to come back to the basics of what you really do.
What's really important, what I call foundational security. Everybody needs antivirus. Everybody needs sim.
In my opinion. Everybody needs privileged access management, whether you solve it with a tool or you do it natively, A lot of the peripheral stuff, it's gonna fall off the wayside or just be consumed, You know, nice to haves, not must have, I think in the direction that what everything is going. Like I said, no politics or economy aside the nice to haves or, you know, that would be a great bolt-on to solve that problem.
I'm not gonna get funding for that. Nice to have, I have to keep my core components. Right.
I think the next five years you'll see some shake out, maybe some shrinkage, but going back to basics or as many people who will call it Secure by design, give me the tools to enforce Secure by Design. I love itm. It's a pleasure having you always.
What a great discussion, huh? Thank you. Um, the name of the book series again, the Name of the book series is Attack Vectors.
Mm-hmm. Uh, you can find it on Amazon or through Springer Natural and uh, you'll see Cloud Privileged Asset and Identity four books, several of them with two editions. And the new one will just be Attack Vectors in Q3.
I love it. com. Yes sir.
Laurie Bert. Hey man, God willing. We're here next year.
We'll do, We will be here. You'll eat at fangs before order the same food and we'll go from there. It's the Chinese food.
Chinese last night. Hey, we're live here. We still got I think one more interview coming your way here at uh, RSA for today.
And of course tomorrow we'll be added. Again, you're watching Text Drunk TV V.