Insider Threats, $25M Deepfakes – Security Boulevard Chats EP12
Return to the office mandates are on the rise, and Mitch and Alan discuss whether security concerns over working remote is a substantial driver. Mitch and Alan also explore the realization of deepfake fears covered in Richi Jennings’ “CFO Deepfake Fools Staff — Fakers Steal $26M via Video,” should HR’s role expand in “Why an HR-IT Partnership is Critical for Managing Cybersecurity Risk” by Guarav Belani, and who should bring the security mindset in Olga Lagunova’s “Innovation With a Security-First Mindset.” They wrap with Alan’s video interview with Cloudflare’s Grant Bourzikas on “API Security and Management in 2024”
Transcript
Hey, welcome everybody. You joined another, uh, episode of Security Boulevard Chats. I'm Mitch Ashley.
And I'm Alan Shimel. We're here to talk with you about security, you know, and our first kinda re re relaunching of the podcast. Yes.
Reorg. Reorg. There we go.
That's every book. Reorg. Good day, everybody.
In reorg, we talked about the origin story of how we got into podcasting and really you started it with some inspiration from Brad Feld and others, and we've been doing this for a while, 20 years. Uh, but, but you know, we haven't been doing it for the last couple years. Yeah.
And, and so it's good to be back. And, you know, we, Mitchell you and I are doing the DevOps chat and Security Boulevard Chats, but also as part of our Techstrong team, we have the Cloud native podcast. Mm-Hmm.
Going live tech strong AI digital CXO podcast, as well as, uh, CSO talks, which you do. And the DevOps Unbound Tech strong women show and tech strong women. So then Techstrong 55.
So we have, we have a whole slew of podcasts that are out there. Depending on what your interest is, we realize very few people are into all of these things that we're into. Exactly.
But pick which ones are good for you. Subscribe to them, follow them, whether it's on Apple or Spotify or any other of your favorite podcasting, uh, channels. Or you can always catch 'em on Techstrong TV as well Absolutely.
To check 'em out. But of all of that, Mitchell, I like doing security 'cause that's where we started and that's kind of Right. And that's kind of where we're coming from home base for us.
Yep. So let's, uh, let's talk security a little bit. Okay.
Well, you know, uh, we're hearing, and we've been hearing this for a while now. Yeah. The return to the office mandates.
Now, it's kind of back in the news of companies are saying three days a week or five days a week, or you can't get promoted unless you're working out of an office. And, you know, it's kind of gone from the work at home. We just need people to work anywhere, anytime.
Yeah. Right. Now companies are pulling back control and a lot of it's about relationship building and well, that's what they say and that's the, well, well, here's the thing.
Why are we talking about this on Security Boulevard? Mm-Hmm. Because I think they've come up with a new angle, and the new angle is, well, you know, it's a security risk having these people remote Yeah, yeah.
Using their own computers and their, and the orders, computers. Yeah. Who knows who's overhearing it and, and you know, everything else.
And, and you know, that sounds, I mean, this is like something outta Castle Blanca let's, you know, round up the usual suspects. Mm-Hmm. Um, and I'm not saying that there, there's some, you know, probably ker the truth there.
Yeah. But really, look, and, and I am saying this as a CEO, when you've got everybody remote, you can't help but think, oh yeah, that one's out with their child doing this. This one's taking the pet to the vet.
This one has this going on. It just seems like, am I getting at my money's worth? Mm-Hmm.
Right. I mean, we, we all try to hire adults. We all try to act as adults, but we've also all seen the, the stories of people with two full-time jobs or more.
Yeah, exactly. Yeah. Or, you know, the average at home person is working maybe four hours a day and, and stuff like that.
And then the productivity losses extend to, you know, the collaboration and people who zoomed out and, and you know, even they're on Zoom and they're, but they're not paying attention. So, you know, yes. Security might be a motivation here, but I don't think that's the primary driver.
If it truly was, we'd see data, we'd see Yeah. Reports. And, you know, this happened there.
We've seen this for the 10th time this week. I don't buy it. Yeah.
I don't buy it. I don't, well, whatever. It's a good excuse.
Look, that's what I, I've been saying for a long time. 'cause I see it here at Techron, like, you're in Colorado, it's hard, but for, for the rest of our team, especially those based in Florida Mm-Hmm. We function much better as a company with the people in the office.
Yeah, for sure. Mm-Hmm. It And, and you miss something by, by not being there.
Yeah. Absolutely. Which is one of the reasons why I'm in the office Yeah.
When I, as much as I can. So Absolutely. So we'll see about the security, but Yeah.
But nevertheless, the, the, the push is on. Right. We, we've seen it.
There were rumors of, uh, Dell releasing something just this past week. Microsoft, Google, apple, and many, many other companies have all, you know, put in return to office mandates. So Yep.
It's, it's rt it's the pendulum. Yeah. Coming back the other way.
Right. rt o Well, hey, let's talk, talk about deep fakes. We were talking at dinner last night.
Yeah. We were in Boston on the road, by the way. Mm-Hmm.
Um, meeting with customers and partners and, and spots. Yeah. It was funny because people brought this article up.
I didn't realize it was one of ours. Yeah. I, I didn't know until I was preparing for the podcast.
Mm-Hmm. Like, Hey, we got an article about this. Yeah.
And it was about a company, a financial institution in Hong Kong that lost $25 million in a scam where I think there was a, a remote branch office that ended up having a video conference call. There were three or four people on that call with the branch office. All of the other people remotely from where they were, were, were DeepFakes.
They weren't really people. And it convinced them, the CFO said the fake CFO said, uh, transfer this money here, and they did it, you know? Yep.
Thinking that's what they're being legit request. And, and so, but this is the brave new world we march into. Right.
Normally look a bank's there to serve its customers. Mm-Hmm. In this case, they didn't ask for, uh, ID to send ID or something like that because they actually had a true video conference with the C or they thought it was the CFO of the, of the multinational company.
Mm-Hmm. And it was clearly, I mean, it, it, for all intents and purposes, it looked like the CFO who knew it was a deep fake AI of the CFO, and it was good enough to fool these people. And, and look, my heart goes out to them 25 million bucks.
A lot of money. It's a lot of money. But you know, what happened here that was interesting was the CFO asked them to the bank branch people to do something that was out of the ordinary, kind of pretty irregular, I think they don't do many calls like that any, and he said, yeah, I know it's a regular, but I need you to do this anyway.
And I think that is always where you got to Mm-Hmm. Put on your common sense that it's like the, I've gotten a text that says, Alan says, go buy cards at Target. Right.
We, we got a text junk all the time. Right. No.
Hey, Mitchell, he doesn't do that. You do me a favor. Go get some Apple cards or something.
Yeah. And read me the numbers. You gotta, if even if everything smells right and tastes right, if they're asking you to do something that just, is that in the ordinary, take your time to verify it.
Yeah. Just, just ask. Yeah.
Hey, call up the assistant for the CFO. Yeah. Double check in.
Like ask some sort of, you know, verification. Something that we, but we are going to need to build those verifications in here. Yeah.
Right. What is it? Is it watermarking?
What is it? Some kind of identity management? Well, no, I, I actually, yeah, I don't actually interviewed a company a while ago.
I'm trying to think of the name of the company that it was just that it wasn't a water digital watermark per se, but it was, it was to weed out deep fakes. Right? Mm-Hmm.
That it clearly is not the person who purports to be smells like opportunity to me. Yeah. Look, there's gonna be a lot of opportunity.
I think this is like anything else, right? When new technology comes out, there's that period where you're trying to figure out like, how do you do these? Right.
And we're in that period. Well, we're, we're in, I say entering, but really in an area era where if you have video of people, like publicly available, have a public persona, uh, there are tools that you can say, here's my script. Take this and turn it into video.
Now that's saying this. Right. Right.
They could do it on, on video. They, and they can easily do it with audio. Yep.
Absolutely. So, you know, it, that's not gonna be enough anymore to verify people's identity. Yeah.
I think we're in for a lot of people getting scammed. Yeah. Well, this gets figured out when you lose 20 million at a shot, you start coming up with solutions pretty quickly gets your attention.
Yeah, for sure. Okay. Um, so, and that, that was a great article by the way, Richie Jennings.
Richie Jennings, our friend Richie. That's a reaction about that. So.
Yep. Uh, I also wanna mention there was a good article, uh, intriguing article, lemme put it that way, about, uh, why an HR IT partnership is critical for managing cyber risk. Mm-Hmm.
And I didn't note the author's name, apologies to the author. Um, but the, the, the premise of it was Kisky saying that over half of companies, 52% believe they face major risk from their staff. Some of it was due to remote work, some of it was just like in general.
Well, some of, you know, it's all kind of that insider threat. Exactly. But some of it's intentional, like, you know, with malice or what have you.
And some of it is unintentional. Sure. Absolutely.
Yeah. It doesn't mean at all. Well get 'em both up.
It's, it's over 90% according to Kaspersky and, uh, unnamed author, author. I hear, I, you know, I I'm always suspect of, when we talk about HR adding a new responsibility or role to HR or elevating the level of importance of it, et cetera, not that it's a valuable function, it's necessary extremely valuable. But it, I mean, asking HR people to understand governances and cyber risk, and yes, they're part of the process when you have an issue, but they're, they're not subject matter experts at that.
No. Nor do they wanna be, it's kinda like saying developers are gonna do all their security for Yeah. For software.
Right. They're not security people. They're developers.
Yeah. So, so I have a little bit of a different opinion than the article states, but you recommended some areas of, of alignment around regulatory compliance, controlling employee data access, managing data disclosures, uh, championing cyber risk culture. Now that might be, 'cause it's a training thing that, that totally fits the others I'm not so sure about.
I I don't know either. To tell you the truth. I look, I it doesn't hurt to try them.
And then I, I think what, what's, what's not carpet dm, bio beware. Hmm. There's the Latin term for bio beware.
Uh, I don't remember. Yeah, I'll look it up. But, you know, your mileage may vary is the bottom line.
And, and you'll see what works for you. But it certainly, um, you know, you need to have HR policies that strengthen and help enforce your cybersecurity policies. Mm-Hmm.
And I think that's it certainly need to be aligned. Absolutely. Yeah.
You know, it's kind of that cyber first mindset, which actually leads us to this next article. Yeah. I mean, and to that, to the prior article, I, I took a different AP opposing view doesn't mean this guy's wrong or Guy or Joe.
No, no. I mean, again, your mileage may vary. You gotta see what works for you.
Yeah. Um, this, this next article go though by Olga la Lagu Nova. If I mispronounce it, Olga, I apologize.
She's, uh, CTO with the go, the go-to teams. Right? Mm-Hmm.
You know, and she says, when you're doing innovation, you always gotta have a security first mindset from your mouth to God's ears. Like, oh. I mean, you know, we've been preaching that for a really, and I, I'm sorry I didn't even flip it, but yeah, we'd love for them to have a security first mindset.
My problem is I just don't think the world necessarily folk, you know, works that way. It doesn't. It it doesn't.
It's, you know, it, it's one of those ands and it must be secure. Right. Right.
So I think as I read the article, I was thinking about, well, what it's about is you have to bring that into the conversation, not just expect that everybody's security's everybody's job. So it's nobody's job. Right.
Exactly. That's not gonna happen. There, there is that if you're expecting, you know, the board on down or the product management team on down or everybody to take securities, and as, as important as we do in our roles, that ain't gonna happen.
That's not, not their. And, and I think it's also, again, somewhat naive in terms of what does the creative process look like, the creative process. You, the, the, in my experience, it's always built around an aha or eureka moment where, man, this would be great.
Right? Mm-Hmm. This would be something people really want.
This is something we, we need to do. And I don't sit there and say, Hmm, I wonder how great this would be if I had security. Yeah, I agree.
Right. And what do I gotta do to make my security, you know, security first mindset. Um, now we, Mitch you've led teams where, you know, as part of the development cycle, you know, security might might've taken, uh, not a backseat, but you know, some, some security shortcuts had to be cut corners to order to get it down on side.
It's like quality. It's like, you know, it's, it's, it's like insurance. How much do you need and when do you managing can't solve all the, it's exactly.
Managing the risk. It's managing risk. So, uh, you know, we've all been there, done that.
It would be great to live in a world where, you know, security could, you know, put its foot down and say stop anything. Right. It's kind of world we're coming from.
Yeah. But we already, and we already have that wrap. Right.
Of the people who say no. Well, and I think that's Olga's really premise here is that, you know, take a security first approach when you're talking about how do we achieve our business goals. Well, you're gonna have to bring that to the table.
Yeah. Well, but she does, to be fair to her, she mentions that, right? Yeah.
'cause you gotta have, she calls it collaboration. You gotta have cooperation among your product, your security, and your IT teams. Right?
Right. And they all have to function, but I don't think security necessarily leads the, the pack, if you will. But to that point, and this is to me always an issue when you're introducing something new, you know, you, you, you'd like to have everything there present from a security standpoint.
You can't always have all the security capabilities you want on the first release, or a beta or alpha release or whatever. Even, you know, it is something you're, you're enhancing as should go in, in the maturity of the product. I'm not saying it comes later.
0 to start introducing it, but you know, you know, there's more things you need to do Yeah. That you can't always do upfront. Um, but you know, you've got, you know, you know, to introduce that into the process, into the plan, and in the releases.
So Absolutely. It's just part of the process that to me, that's what the leaders have to do. So, you know, kudos to Olga for kind of bringing this up to the forefront.
Mm-Hmm. Helping us think about it. It's a really good article.
Definitely recommend reading it. Yeah. And on, and that's on Security Boulevard.
Now you did an interesting interview, um, with Cloud Flares. Is it cso, right? Grant?
Um, I, I forgot what, chief security officer. Something like that. Yeah.
So this guy, grant, first of all, he's a gem, right? He's a treasury guy. Z is that Yeah, BKI.
He's, he's been, you know, he's old school like us, Mitchell. He didn't necessarily, well, you went with a computer science degree grant, grant security. Yeah.
Well, grant didn't start in computers. He has an accounting degree. Okay.
Um, but, you know, he's been CSO for about 20 years. He's headed up security at some of the, you know, top five banks in the world. Um, government stuff.
I mean, he has an, an amazing resume and amazing path and, and you know, heading up security at CloudFlare is a big job. Right? 25% of the internet traffic it goes through, it's responsible for a lot of people's security.
And, you know, they just did a, a little, uh, survey or report on API security and management specifically that really we, you know, we've been talking about API security now for a couple years, but grads, uh, according to the Cloudflare's intelligence, about 57% of all internet traffic right now is API generated. Yeah. Right.
Going to api, Akamai would validate the same thing, I'm sure, and it's got its own numbers, but it's, it's definitely majority of the, it's, it's, it's, you know, so that's how important API is. And, um, and it's also something that's fairly new for most organizations, right? Mm-Hmm.
As they move, you know, they're say, well, don't I have a waf? Right? I have web app firewall.
I got the discovered. Well, no, you don't. And you know, when Cloudflare's taking it on as, Hey man, that's part of their job.
Mm-Hmm. To help do better with this and manage this. Well, that's is increasing.
Guess what? Right? Yeah.
And that's where they are. And, and Grant's, Grant's going for it. This this, this was a video interview.
It's on Text Drunk tv. You could look it up there. I mean, we, yes, we spoke a lot about API security management.
We've talked a lot about security, about breaking in. Grant is on the, uh, I forget what board it is, uh, a big board, uh, to help people get into security. Right.
How do we get more people in the, so-called Security Gap, right? The skills gap. To that point, you told me a little, tell us a little bit more about sort of how did Grant become the security expert he is.
It wasn't just, I'm sure he is a good leader and intelligent person, but he didn't magically No, as I said, acquire this knowledge about accounting degree. Um, boy, you put me on the spot. Wasn't he like reading a lot of No, he, oh, yeah.
So he believes in reading books, right? Like Consumed Graham would read books like of one a day or three a week. As soon as he finished one, he'd pick up the other one.
And he totally self-taught from reading books, like Real Books by the way, this is before was Kindle and all of that. Yeah. No, he'd go to the bookstore and buy books and read technical books on these things.
And he's very self-taught with that and, and Rose up through the ranks, you know, the hard way. Mm-Hmm. And, but knows his stuff.
I mean, as I said, he's a treasure. I can't wait to have him back on. I told the cloud folks, uh, we'd love to do something around this with Grant.
Mm-Hmm. So, um, looking forward to it. If you get a chance, go on Text Drunk TV and check out the interview.
It's a great interview. Very cool. Yeah.
But before we wrap up, I, I didn't plan this in the kind of schedule of conversation. Okay. We're going off script.
We're going off script wrote, we're, we're hitting the dirt here. Mm-Hmm. Um, you know, RSAC is coming up.
We have our In May. In May, um, we have our one day event that we have. Right.
Our DevSecOps is I think the eighth or ninth year for DevOps Connect DevSecOps. Yeah. On the Monday of RSA week.
Once again, we're doing it. This year's theme is DevOps Connect DevSecOps with the generative AI has generative ai, you know, uh, influencing or affecting Mm-Hmm. DevSecOps.
Mark Miller, our friend Mark, who's been working with us on this for all these years, he's, he's helping assemble the, uh, speakers. We have an amazing lineup. It's it's a killer lineup.
It is. Yeah. We have, I think the chief Security officer at, uh, at OpenAI.
Mm-Hmm. We have a top guy from, um, I always mispronounce the name Anthropic. Mm-Hmm.
Anthropic Anthropic. We have, uh, who else? We have Meta, it's Chief Researchers from Meta, couple people from Meta Meta, um, Google Deep Mind.
Yeah. Deep Mind as well as Google's office of the CIO, our friend Dr. Anton Akian.
Mm-Hmm. He'll be presenting. Um, AWS we mentioned open some sci-fi dude.
Right. Oh, and then the keynote is right, David Britt, who's a pretty well known. You're you're a fan boy.
Yeah. Well, I've read almost all of David's books. Yeah.
I've read some of them. Not all of them, but, and, uh, yeah. But he's also a PhD from nasa, JPL, where he is worked for years, and he's probably one of the leading futurists for the last, I don't know, 35, 40 years talking about AI and stuff like that.
Mm-Hmm. Writing about it before it was cool. And before we ever heard of chat, GPT, um, so yeah, that's gonna be a great event.
It's Monday, May 6th. I'm not sure if RS a's website has all of the information that you can, you don't have to register to attend it. I think you just, what do they call it?
Designate a, an interest in it or something like that as part of your regular registration. You do need an RSA badge to get in, but even an expo only pass will get you in. And if you go to our page on Techstrong Events and go to the RSAC DevSecOps event, I believe we have the, uh, code there for a free expo pass.
Yeah. We'll get you in. So get you in there.
It won't cost you anything. It's a great, this is gonna be a great day. Don't miss that one.
I'm excited. Excited. So I, I'll be, uh, I'll have a lot of fun.
I'll be doing a panel there. Right? You're doing a panel?
I, I actually, my, well, fortunately I was gonna say unfortunately, but no, my youngest son's college graduation is that day, so I, I'll be in that in the evening, but not there during the day. I'll miss you there, but I'll have fun stepping in and Yeah. Yeah.
Helping out thing it, uh, I think we're, we're, we're expecting a big attendance. Yeah. No, this should be between, actually David Brin will also be doing a book signing with, uh, one of his recent books.
I don't remember which one off the top of my head. And, uh, it'll be a fun night, fun day. There'll be more book signings there as well.
Fantastic. It's exciting. Yep.
I should mention, we, we have sponsorships available for that too, if, oh, we do interest and there are a limited number of them. Yeah. com.
Yep. E every security vendor is adding AI to their products. And we all have an AI story, you know, for more and some getting started.
So, yep. Potentially relevant to you. So we'd love to see you there.
Love to, to see you sponsor, if that's of interest to you. So, cool. Well, good.
You, I think we're ready to wrap it up. Let's wrap it up. So this episode two of the Security Boulevard chat relaunch Mitchell, thanks for having me on here with you.
It's been fun. Pleasure. It's, we had a, a road version of our podcasting equipment here, right?
We're, we're mobile going, moved from Boston, but yes, we're in Boston. We'll be back in the offices next week for our next episode. But until then, is Alan Shimel and Mitch Ashley.
And you've joined us for another episode of Security Boulevard. Take care. Bye-Bye.