Large Data Breaches, Attack Surfaces and Security Marketing Guru – Security Boulevard Chats EP13
Alan and Mitch discuss data leaks and Bank of America’ recent data loss and, Alan’s interview with security marketing guru and colleague Jennifer Leggio, defending the expanding attack surface.
Transcript
Hey everyone. Thanks for joining us today. My name is Mitch Ashley and I'm joined by Alan Hummel and you are listening to Security Security Boulevard.
Chats. Chats. Yay.
We're working on our synchronization. We'll get it. Yeah, we'll get it where we, uh, look, the East German judge is gonna give us a seven five for that one.
And we made a little bit of a splash. 5 and then We did really well. Yeah, we did.
Yeah. Would Nadia change Khi? Maru, change the game, change the rules?
Absolutely. Absolutely. You know, I got a new Star Trek shirt I gotta show you, Mitchell.
Ooh. It's the alternate universe. One with spark, with a beard, and not with the beard.
Yeah. I, I'll, I'll, I'll wear it one of these days. I'll show it to you.
Little Spark that turns out to be nice, evil Spock, you know. Well, he's still Spock no matter what universe he's in. Yes, he is.
Yeah. Helps turn the message back to the right universe or multiverse, whatever it is. Yeah.
Affected with that tool. I'm sorry. Ahead.
I I you take me on Star Trek Mitchell, and boom, I'm at War Speed. Yeah, I know, know what's gone before. So many great shows.
We could like do a, we should do a Star Trek podcast. But anyway, another topic, you know, kind of thinking, 'cause we're going back, thinking about, you know, star Trek. We've been interested in that and for so long.
Yeah. I was thinking about an interview that you did with Jennifer Legio. Jennifer is someone that we've both known, I think you've known her a little bit longer than I have for a long time.
And when I saw your interview, 'cause I've had her on, on, uh, caw talk and we've talked with her at different times on interviews and stuff. You know, it, it's a small universe. It's a small community of friends, you know, security is massive.
But you and I have known dozens of people for at least 20 plus years through our career in security. And Jennifer's a perfect example of that. Who somebody you keep reconnecting, you might work with her, you know, she might work as part of the security bloggers network, you know, that they're doing interesting things in security, see each other at RSA all the time.
And, and, you know, in between it just reminded me of how important is the relationships you build can be career long relationships. And she's one of the great people to have, you know, I'm purpose to have that relationship with, you know, what else Mitchell, and, and I'm sure you feel this way too, as we get older, some of us, some of us don't get older. Um, you recognize that without even trying, sometimes you have at least some small influence on others and their career and their career trajectories.
Mm-Hmm. You know, when I, I had Jennifer on, as you said, on Text Trunk tv, and it's available at text trunk TV if you want. And it's posted on LinkedIn and Facebook and everything.
First of all, looking at Jennifer, you know, and I still see that girl that I knew 20 years ago. Mm-Hmm. Right.
She was just a pr not, there's nothing around with being a PR person, but Jeff, that was how she started Better Talk. But that's how she started. She, she was a PR person moving and then, you know, and she was a tremendous help on the security bloggers network meeting and awards.
Yeah. And tremendous help. She ran it for us.
Who are we kidding? Right? We all sat back, let's, let's, let's put it out.
Let me, Martin McKay you and, and, you know, and, but watching her career trajectory as she's climbed the ladder Mm-Hmm. Just so damn proud of her. Mm-Hmm.
Right. Um, you know, because look, 20 years ago the security industry was a little different too, and as it relates to women, quite frankly. Oh, absolutely.
Yeah. And, um, you know, watching the progress, steady progress she made, she's made, and even even her physical appearance, she looks like a leader, right? Mm-Hmm.
She was on here and, and that was the, the gist of, or the title of, of this TV interview, tech Drunk TV interview we did. Right. How to Lead.
Um, so, you know, Jennifer recently left her last gig and she started her new company. It's a, it's a consulting company right now. It's just her and a couple of friends.
Uh, it's called Movable Feast. And she told me what Movable Feast is, and I forgot what the reference is now. Apologize to watch the video.
Yeah. You'll have to watch the video, but, you know, she has big plans for this. And, and look, Jennifer Succeeds wherever she goes.
Mm-Hmm. And so there's no doubt in my mind she'll succeed in this. And, and maybe we'll have her on here on a Security Boulevard chat at some point in the future.
That would be fun. But she's here to help people with their go to market to here, help people with their career counseling and, you know, especially people in, and people, you know, diversity women. Mm-Hmm.
Um, so just really, really proud of her, Mitch. And it, and it, it gives you a feel good to know that, you know, this is one of your friends who you came up with. We, we were, we are blessed Mitchell.
Right. When you look at the people we came up in the ranks with insecurity and Mm-Hmm. You know, many of 'em, not many of 'em, but some are already retired, unfortunately.
Some we've lost. Yeah. But, you know, some are retired, but many of them are still active, really have very senior positions in the industry now.
And, um, God bless 'em. And it's great, it's great to be part of that. It's great to be part of something.
I really, I, I spoke to Jennifer about it. I really would like to do something this year at RSA around the Security Bloggers network, rename it, security Creators network. 'cause not everyone blogs anymore, but they create content and, and kind of pass that baton on to some younger people Absolutely.
Who let them build their own up and coming story. Mm-Hmm. So if you're listening or watching this, and you'd like to be involved in the next incarnation of Security bloggers meetup, security Creators Meetup, and potential award someday, and help build this community that's already 20 something years old, we'd love to hear from you.
com and love to get you involved. We'd like to do something around RSA this year. Again, we usually do a Wednesday, uh, like five to seven, uh, security bloggers thing.
So if you're interested in that Right. To us. And, but in the meantime, happy, happy, proud, proud of Jennifer Legio and, and what she's doing with Move Movable Feast.
Definitely check her, check out her, her company. If there's anybody that can be a mentor, advisor, consultant, you know, help you. She's got a wealth of experience to share.
Absolutely. So, absolutely. Um, Mitch, I think the big story in security this week is just starting to break as we were, uh, recording that, recording this Mm-Hmm.
And that is, uh, could be a big breach over a Bank of America. Mm-Hmm. Um, you know, I'm trying to think.
We had a lot of friends at Bank of America security at one point, right? Hoff was there. Yeah, I bet.
Um, oh, who came over from Zion's Bank? Um, Alex Hutton. Alex, yes.
Yeah. And, uh, there was a bunch, I think Dave Lewis might have been there for a while, a while. But anyway, they, we haven't heard them in the news in years, frankly, in terms of security breaches.
But this is the nature of this beast. Sooner or later, it's not if it's when Yeah, absolutely. And, and so it looks like there was a breach there.
They're starting to notify people exactly how big it is. We don't know, but from what I'm kind of reading between the lines, it's a big one. Yeah.
We haven't heard the numbers yet, but it's information, you know, it's personal information, but including social security numbers and government IDs and financial account information you're talking about, you know, financial institutions. So there's potentially some pretty damaging information that, uh, it's been, uh, let's say stolen. That's what it really is.
It's not just a leak. Right. Yeah.
Someone stolen. And, and also, you know, we were talking in our DevOps chats, uh, podcast Mitchell about software supply chain security. Mm-Hmm.
And, and this again, was a case they believe of a third party who, um, you know, that a third party vendor was how the people accessed the, uh, bank of America info. Mm-Hmm. Same old story, right.
From Target, the, the HVAC vendor and, and all of that stuff. So again, dependencies, dependencies, dependencies, dependencies becoming the most popular attack vector as we have these bigger attack surfaces. That's kind of the, uh, a modified version of the, you know, I don't have to outrun the bear, I just have to outrun you.
Well, the bear catches you, but then they're still gonna catch me. Right. So Right.
Because if they so much for that, they're gonna get to you. Yeah. And, and so we're all in it together.
And, and something to think about. Um, speaking of, uh, attack surfaces though, Mm-Hmm. I wanted to bring up an interview that our friend Mike Ard did, um, on Textron tv.
And it's with, uh, another person who I know pretty well. Uh, mark Gaffin, the, uh, CEO founder of Ioni. It's I-O-N-I-X.
Right. And, and Ionix Israeli startup, you know, cybersecurity startup. They just raised a bunch more money, um, on why defending attack services has become more challenging than ever for understaffed security tapes.
Uh, you know, this is a common theme we hear a lot, security, Mitch. Mm-Hmm. Right.
The attack surfaces are growing. It's not that the budgets aren't growing and we hear about the security gaps, but this goes back to when we were still secure. There's, there's a handful of companies that have the resources to do security Well, and they're big.
Right. And the companies have large security teams. They 50 Fortune 10 companies.
Yeah. It's the mid-sized, even small, but mids, you know, even small enterprise are working on a, you know, handful of people in their security teams, maybe five or six and under-resourced. And, you know, I think we just gotta realize that's, that's the nature of the beast.
Well, and I think that the challenge is, you know, what's, what's changed since we got into security Allen is, you know, we've, we're, we're at, we're way past the days of, you know, um, sort of build that exterior and that protects the things on the interior and now and does to, um, you know, zero kind of frameworks, if you will. But, uh, the thing that's really substantially changed for me is what you're protecting has changed. It's not just network resources, it's just not where data is located.
It's application security. It's API security. Um, it's suppliers and supply chain security, all the stuff we were just talking about around supply, you know, so it's security engineers, at least in our day, didn't grow up as software engineers, at least not most of the time.
So, and, and I know that's, that's been a challenge for some people to get their head around this whole DevOps things and the deployment, continuous deployment and what's all that jazz. But as part of the job today, um, at least to have people on your team that, that have some expertise in that can talk to developers, can talk to cloud architect, can talk to all the folks that are delivering or putting together, you know, your delivery platforms and partners and interfaces. It's, it's a big attack surface.
Not just 'cause there's a lot of software out there. There's a lot of different kinds of surfaces. Agreed.
Matt agreed. You know, uh, there's an article on Security Boulevard also in the same vein. And what the Bank of America thing is, it's called What is a data leak or data leak.
Right. Causes examples and prevention. It, it's a pretty remedial article for a beginner.
A newbie. I highly, highly recommend it. Mm-Hmm.
Because we talk about data leaks and you know, and I say the big breach over at, uh, bank, bank, bank of America, and you said, yeah, there was some PII including social security numbers. You know, there, there's data breaches and there's data breaches. Mm-Hmm.
Right. And depending how many, how much information, what kind of information really determines its criticality and what you have to do and, and reasonableness and all of that. And, and for those of you maybe listening to this who are new or, you know, newbies in, in cyber, or not really cyber people, but interested in it, or they're just fans of you and I Mitchell and they like listening to our voice, God help you, um, should find something better to do, but okay.
Yeah. But if you have nothing better to do, go read this article on Security Boulevard. It's a security Bloggers network article, by the way.
Mm-Hmm. And it, and it's a good, it's a good primer on what do we, you know, sometimes we toss around words and acronyms thinking everyone has the level of detail we do, and they don't. And, and so highly, highly recommend that article to go have a look.
And one of the things that didn't talk about, I don't believe, is the SEC reporting requirements. Now, we now live in age of, you've got five days from whatever you define as knowing there's been a breach to reporting it and, and public disclosure, disclosure and, you know, AK forms and all kinds of fund government, things like that. So it isn't any longer just, you know, controlling the message and what do you, what do you release publicly or not?
It's, you have to disclose things now. Absolutely. It's a different, or if you're CISO and you don't follow the rules, you can find yourself criminally charged, civilly liable, all kinds of craziness.
Sign me up. Yeah. You know, I, I did a, uh, did an interview this week or last week with a, a, I think his name's Max Schein.
He's a ciso, former Air Force guy, and now CISO at a, a vendor, and I don't remember, it's on Textron tv and we spoke a lot about this, right. About you with the liabilities that CISO's face now Mm-Hmm. What does that mean?
Right. Uh, can you afford to be kind of an in the weeds security guy, or do you have to be a business suit, or you have to be both and then hope for the best. Right.
What, you know, what's the standard for negligence here? Mm-Hmm. Um, it's, it's a fine line.
They're walking right now, I think. I'm hoping it'll evolve and get a little better. It was a really good, um, we had an interview with Andy Ellis, you know, CSO friend from Awa Mm-Hmm.
Was there what? Oh, of cso, Andy Ellis. Yes.
I mean, renowned author, you know, done it all, been there and, and Patriots fan and Patriot. Well, you had to bring that up, which is that Pata. Yeah.
But how'd you like that Super Bowl, Andy? Just in case he's watching Mitch. I'm sorry.
How did the Patriots doing the even Super Bowl? I don't remember. Yeah, I don't, I don't remember seeing him there.
Brady was there to, Brady was in a lot of commercials. Yeah, he was. They seemed to be all over the place.
Him and Taylor Swift. I'm not sure what the deal was, but anyway, well, one of them kisses a guy with a beard and I don't think the other one does. I hope it wasn't.
Um, yeah. Okay. Anyway, um, well, reason why I bring it up is he has some really interesting views of, the CISO job is not a board level job.
It's not a senior, senior, senior executive team job. And also, and, and I won't explain all if you want to hear it, it's up on text run TV under CISO talk. Um, but also we talked with them about, so what do you do when you don't have, uh, the support of the company, whether it's executives or legal or the board or whatever, to do the, to do what you need to do, and they force you to, you know, no, don't disclose that or do something you shouldn't do.
Maybe do something illegal and, you know, what do you do in that situation? Well, the first thing is not to get yourself in that situation. If you think you're in that kind of a business climate or culture, you know, do yourself a favor before you do get arrested and charged with something, go somewhere else.
It's not worth it. Absolutely. Absolutely.
Um, you know, we, that, my interview with this fellow Max Schein, we spoke just about that too. What to do. Right?
You, you, you know, you don't want to be the whistleblower, but you know, you gotta extract yourself from those situations. Mm-Hmm. Anyway, Mitchell, the next, uh, the last article I wanted to bring up for this week's show is another Security Boulevard article, but with a DevOps Bend, and it comes from Security Bloggers Network, and it's how DevOps evolved into DevSecOps.
Ooh. This is a topic. We, we've been around a lot.
Yeah. I mean, it's a topic we live, we see it with the leading DevOps platform providers. They don't call themselves DevOps companies.
They call themselves DevSecOps companies. Mm-Hmm mm-Hmm. And, um, you know, we do our show at RSA, this will be the eighth or ninth year, Monday of RSA week in Moscone DevOps Connect DevSecOps this year, of course, it's DevSecOps and generative ai.
Yeah. Got an amazing lineup. Yeah.
We got such a, I mean, leading AI company security guy. So really definitely wanna check that out. Mm-Hmm.
Actually I think it, the whole lineup and everything is available, uh, February 15th on, on the RSA on the RSA site. Yep. Yep.
And, uh, if you'd like to go to that, we also have, uh, codes for free Expo Pass, which will be enough to get you in on Monday to our event. So definitely have that for people who are interested. Um, but Mitch, that's a good article and it kind of explains the whole evolution of DevOps to DevSecOps, which is I'm sure something we'll be covering in this DevOps next report you're doing.
Mm-Hmm. Absolutely. Big part of it.
So cool on that. Um, I think that's all I got this week for Security Boulevard. Mitch, you got anything?
You know, there, there's some, uh, I really do wanna highlight that article again on DevSecOps because, you know, we, we often apply the shift left moniker to that, and that can mean anything from just being ridiculous. Like, the developers will do it all. They, you know, they, they don't want to do it all to, you know, what do you really do to embrace and embed security into, throughout the, the DevOps process and the workflow pipelines and designing it into software and testing it and all the things that you could do.
And how do you do that as a security person? As I was talking before, you, you may know a lot about software. Now maybe you came up with that kind of a degree or you have that experience.
If you don't, how do you embrace this? How do you get involved in it? There's some good things in that I think in that article that will help around understanding, put a little more reality to DevSecOps.
So, and I'd definitely please join us at RSA. Um, we have, it's gonna be a killer lineup. I think we're gonna have great attendance at it too.
So it'll be a great networking event. Yeah. Yeah.
But it's all day. So you come in and grab a seat, grab a T-shirt of some great sponsors. Mitch, you are gonna do a panel that day there too, right?
I am, yeah. I've got a great panel talking about AI and DevOps, uh, dev DevSecOps, excuse me. So, uh, with some real great folks and, uh, just putting that together now, that'll go up as part of the agenda, uh, up on the RSAC site.
I think we even have a talk, right? I'm doing a talk, um, an RSAC talk. Don't we have the after dev sec ops?
Yeah. After DevSecOps. So I'm gonna talk to you about that.
So I'm not gonna be at the Monday event. I'm, I'm thinking if I maybe wanna grab that talk and I'll do that panel. Well, that'd be great.
You should totally do that. But I'd like to do it from DevOps next with a DevSecOps Ben to it. Mm-Hmm.
I think that's a great, um, I got some speakers in my too. We'll talk. Okay.
You'll have your people call my people. Yeah. Don't My AI companion Dr.
AI copilot. Okay. We'll see how that works.
Um, hey, Mitch, I think that's gonna wrap up our Security Boulevard chat, uh, episode three of the relaunch. Yeah. We'll be back next week, right.
With more, we will, we al we'll have, always have great topics and, and again, if you, there's something you'd like us to talk about or you wanna interject and be part of the conversation, send us an email. com. We're happy to, uh, chat with you that way and, you know, incorporate ideas.
We appreciate your feedback. You know, if you like some things, tell us if some things sucked and we need to do it better, I'm sure we can work on it and make it better. So wouldn't be the first time I was told, wouldn't be the first time and it won't be the last.
Right. Absolutely. All right, well thanks everybody.
Thanks so much, man. Yeah, thanks everybody. Listen for joining us and it's been a pleasure as always, Alan doing this with you.
So Yep. Thank everybody for joining us Shiel. Yeah.
I'm sorry. Okay. You do it, Mitch.
Yep. I'll start. This is Mitchell Ashley and, and Alan Shiel.
And you've been listening to Security Boulevard.