Securing Your Digital Transformation – Techstrong Con 2023
Digital transformation promises to introduce new ways to serve customers better, faster and cheaper. But these new business processes typically involve new ways of communicating with parties up and down the value chain. Unfortunately, security tends to be an afterthought to these transformation projects, forcing organizations to bolt on security after the fact. But it doesn’t have to be that way! Mike Rothman, GM of Techstrong Research, will lay out a process to get ahead of the inevitable security issues involving digital transformation. You’ll learn how to:
* Position security as a benefit to the digital transformation process
* Build processes that integrate security from the design phase
* Design secure, repeatable patterns to accelerate technology implementation
Transcript
Hi everybody, Mike Rothman here general manager of text wrong research and we're here for another. Session for Textron Conn but this one is is actually pretty pretty exciting very interesting. Right and we're not gonna necessarily deal with you know, entirely it oriented issues, which I like since it is broader than just this little Echo chamber that we live in um, but we're gonna talk about how to secure your digital transformation and again that can mean a lot of things to a lot of people so I'm excited to have Jason Bloomberg who is a principal.
I think that your title Jason principle and managing partner managing partner. All right sounds even better than the man on that for intellects and they are an independent research Boutique. I really focus on digital transformation and a lot of the other aspects.
So he's a great addition to the discussion. Um, so before we kind of jump into a Jason, why don't you just introduce yourself a little bit till tell the audience a little bit about what you're doing and where you spend a lot of your time and then we can get going on the discussion. Well sure.
Well, as you said I'm managing partner at intellix. We are a boutique industry analyst firm focused broadly on Enterprise digital transformation topics, which in practice means that we talk about many different disruptive Trends and Enterprise it including cybersecurity, but also Cloud native Computing big data and AI logo tools Mainframe modernization devops range of other topics. So if a topic is interesting in the Enterprise it space we gravitate toward it the more confusion the better we love confusion gives us something to write about and talk about as a as an area gets sort of more settled and people figure it out.
Then there's less less reason for us to focus on it. So as we end up moving around depending upon how topics evolve and so recent topics cybersecurity is always us all the topic getting more into VR and metaverse topics. That's a an area that we keep hoping we'll take off and it hasn't yet.
It's all a bunch of hand waving at this point, but we keeping our eyes on it and looking looking for you know. Progress in that space as well as many other areas that are up and coming. Yeah, you you bet and and I think that kind of brings up the whole thing.
And and you know, listen I'm as guilty as anybody of getting kind of caught up in you know, again the echo chamber in our you know, kind of little it world when I was putting some talking points together for the discussion, you know, I did I did hone in on you know, it related issues which again that's kind of where I live. That's what I've been doing. You know for a long time.
That's most of the folks that I talk to but Jason you are both, you know kind yet firm in that, you know, we're we're missing a big part of the discussion because really digital transformation kind of relates to not just you know, kind of hey, we're gonna update our systems we're gonna Embrace microservices and you know, collaborate better with our partners and that creates all sorts of security issues, but we really have to revisit the organizational models and we kind of talked about that in our digital transformation trends that we talk Out at the predict show a couple months ago back in early January again organizational change was front and center in terms of you know, kind of our digital transformation. So I just kind of forgot about that for a second but I'd love to kind of start the discussion with you know, kind of when we start thinking about how these changes are gonna be happen in the organization where we start to see some of the risks right where this additional collaboration could create some problems where you know, some of the siloed business operations that have really stymied a lot of organizations for a while. You know, how does this start to create real security issues if folks have to start thinking about yeah, you're right when you say that digital transformation is more about organizational change then technology change.
We like to say that is customer driven, but software empowered. So helping organizations provide more focus on the customer understanding how to organize themselves to better Meet customer. Needs is core to what it means to digitally transform an organization.
So technology is a supporting player here that you know leveraging digital Technologies end-to-end across an organization to better Meet customer needs as customers as well as employees and other stakeholders and organization leverage digital interfaces Endeavor digital Technologies at the front end to better interact with a particular large organizations, but also midsize organizations as well. So when you get to this question of risk, there's really two sides of the story on the one hand digital transformation requires organizational change. So a question might be can that organizational change help an organization manage risk cyber security risk in particular that is to we have to change the way that people work and interact with each other and collaborate in order to provide better management of cybersecurity risk.
And the other question is well once we have this technology in place, how can it better support the overall? Security needs as organizations digitally transform themselves and there's many different parts of that story, right? It could be more customer self-service and what are the cybersecurity concerns there or could be greater collaboration across different departments and that opens up potential security risk.
So, how are we going to deal with those issues? So there's two sides of the story, right? We want to both leverage security to help with our cybersecurity risk as well as understand the digital transformation requires organizational change that can impact our security effort directly.
Yeah, you bad and and you again I just thought let's dig into that a little bit and and we can certainly take the use case of you know, kind of customer support or let's broaden it a little bit more into Outsourcing right? Because that's something that we certainly see a lot of folks embracing, you know different service providers up and down the value chain really to allow them to focus on the things that they're most affected at right most profitable at doing yet that creates all sorts of potential problems. You have external parties that are accessing Key Systems, right?
You've got you know kind of developers that are in, you know with access to you know, the proverbial King keys to the kingdom. I've seen a lot of different technology answers to try to deal with that but you know, I haven't really engaged on the discussion of you know, the senior folks going. What is my risk tolerance for that?
Is that some discussion that we should be having right? You know, how do you start to frame those discussions, you know within the chief business off. That are driving these things so that they understand hey that may make sense from an efficiency standpoint.
It may make sense from a profitability standpoint yet. We have to consider these, you know potential issues on the security side. Yeah, that's this.
This story is broader than digital transformation and and predates really the digital transformation movement. I mean, it's really a question of the expanding attack service in an organization back in the old days. We could Rely Upon Our firewall-based perimeters.
Everything inside was trusted. Everything outside was untrusted in the world was a very simple place. Right?
Well now everything is untrusted and there's no such thing as a perimeter, right? So this is partly due to the third party problem right where there could be contractors. It could be Consultants.
It could be an extended communities, you know of contributors of various sorts, right? So there's a whole range of different kinds of individuals now that are interacting with organizations and it's also the explosion of the different kinds of devices technical touch points right with with the internet of things and sensors and actuators and with increasing dependence on our you know, mobile phones and other types of Smart Technologies at the at the edge at the edge so and Edge Computing broadly. Being built out and leveraging new technologies like Ai and cloud computing to better flesh out what we can do with with the edge.
So all of these expand the organizations threat footprint, right the the overall, you know risks facing the organization. So the organizations whether they're you know, companies or governmental organizations. You can't be reactive.
You can't say, oh we're surprised by this expanding threat surface. What do we do? Let's scramble, right?
You have to be proactive. You have to say well we're going to come up with a strategy for managing risks across the board that's going to include our cybersecurity risk as well other kinds of risk risks essentially operational risk, right the risk things are going to break, you know risk of downtime very important part of the story as well as other kinds of risks compliance risk, very important to consider, right we want to make sure we're complying with regulations the more regulated and Industry the more that and more important that is but really every organization public and private sector has compliance risk that they have to manage. There are other kinds of risk as well.
I recently wrote about technical debt risk, right this way became hot news item with the Southwest Fiasco in December. And then the FAA Fiasco in January right to is separate but Airlines related Fiasco's that are both fundamentally technical debt issues. So the question is now we're in a an economic one, maybe downturn or any attentive time slow down larger say but but in any case Many organizations are saying well I got to put my modernization on the back burner technical debt is a long term thing.
I have to worry about but short-term. I have more urgent things maybe cybersecurity ransomware protection other things are more urgent but then Southwest comes along and goes down for the holiday week and leads people stranded around the around the country and and obviously they didn't properly manage their risk. So what does this mean for an organization?
All you have to be proactive you have to consider all the different kinds of risk and you have to place them into that appropriate context or what are the relative risks to the business of a breach of you know, a crash of an old Legacy system or compliance issue or whatever the the risk the threat in, you know in discussion is and then take our limited budgets because nobody has enough money to address all these risks. So how what is our strategy for saying? This is how we're going to spend the money we have to address the risk.
We're facing given that we Can't address all of them, right? We can't be perfect. There's no way to reduce risk to zero because it's just what cost far more money than we have.
So how do we do that? And we have to place any cyber security risk into that overall context? Yeah, and so let's kind of dig into that a little bit more too.
Right because you know in a lot of cases I have discussions with senior security folks and you know, yes, they're starting to get more comfortable in the boardroom. But that's a little bit different than starting to engage within a digital transformation context going. No.
No, we've got to fix some stuff before we're ready to do this in a way that protects the organization and ensures that our data is ultimately secure and and not overly available to potential adversaries, right? So, how do we start framing out that discussion? Right and we can pivot and talk about you know, how the marketing person has to talk about their stuff or you know, how the business persons but It ultimately it comes back to making business case for the fact that you know, again, these are the potential dance studies, but with security it's a little bit different right because in a lot of cases, we're not saying hey you invest in this get you know that out of the back end of it.
We're saying invest in this and and at some percentage a Bad Thing may not happen. Well what percentage um, I don't know right? Well, how do you know?
It's Happen anyway. Mmm can't tell you that one either right? So it just becomes a very difficult discussion to have which means usually you see the security folks, you know in the security projects as part of these things, you know, my grade down the list of stuff that is just, you know, ultimately pushed back again that technical debt, you know type of thing.
But again, you know having those discussions tends to be the hardest thing that folks can do because we haven't figured out a way and not just relative to security but any business function of really nailing down, you know, kind of what that Roi is maybe a bad term, but you know some type of payback that we can get for, you know, kind of staging out that transformational effort. Yeah, so there's a few parts of the story here. I mean one is the and inherently siled aspect of risk management in today's organizations, right?
You have this cybersecurity team. They're dealing with cyber security risks right dealing with threat cybersecurity threats and the risks of breaches and they're focused on that and they have budgets for that and they have tools they can deal with that and then you have other people to site reliability Engineers. For example that are focused on reliability Risk by keeping systems up and running risk of downtime and they have tools for that and they're looking at data that that help them with that and they're focused on that and then you have other other parts of the organization focused on their respective risks.
And this is a siled organizational model right because each each of these different teams has different tools has different priorities and is leveraging day data in different ways and has their own budget, right? So they're if any time the question comes up as to who gets more money than they would have to fight over it right and they end up with this adversarial context. Is one of the big challenges with siloid organizations as you end up there's a problem that everybody's finger pointing and you end up with these War rooms for everybody's yelling.
Right? And that's counterproductive for for everybody. Right?
So, how would you ever been around to those? I don't know what you thought how so how would you address this? Right?
Well, there are some commonalities and you have to look at these right? It's not just a question of executive leadership saying Thou shalt collaborate because those sorts of you know, executive proclamations never work or never work for long, right? And there's there's all these organizational movements like, you know secops and netops and netset Ops and devsec officer, you know, just sort of you know blanches of different words that are trying to indicate the different teams are supposed to work together, but just because somebody says they're supposed to work together and comes up with a cute little name for that collaborative team doesn't mean that it's actually going to happen.
Right? So so the challenge here is how do we align the priorities and for all of these groups? They have a common priority and that is managing risk.
The problem is They think of risk in different ways right risk of a ransomware attack is very different from the risk of a server becoming overloaded and the website going down, right but they're both risked to the organizations and now challenges. Well, how do we quantify that risk in order to manage it from in a data-driven way so site reliability engineering tells us how to do this right because site with within the SRE reliability engineering practice. They have this notion of error budgets.
They realize that they can't keep systems up 100% right 100% is never a realistic way. 9% whatever and there's some sort of gap between what is realistic to achieve and Perfection and that Gap is the error budget and it's not just necessarily having to do with the inability to address some problems. It's also has to do with the cost of addressing problems and how much time it would take given that this organization is digitally transforming.
Is that's leveraging it's software infrastructure to provide Dynamic capabilities, right? So how long it takes to address a problem impacts the ability for the organization to respond in an agile way to customer demands. So time cost and the ability to resolve issues.
Now our balanced in this notion of an error budget where you say we can't be perfect. So we'll manage to this number that is shorter Perfection. And that's what we'll go.
Our goal is right. Well, can we take the same idea and translate it to cybersecurity cyber security is never perfect either right? There's always the chance of breaches.
So you want to manage to that you don't want to assume that you can be perfect and then just pull your hair out when something happens because that that doesn't help right you want to be able to say well we can't be perfect. So here's how we're going to address what we can Address given the budget and time constraints. Well, once everybody's thinking that way now you can align the teams right because they have the same prior.
Is namely risk mitigation and the same data-driven approach to measuring and managing those risks, right? So they need a common set of tooling that supports their respective efforts. So they still have different things they need to do so somewhat different tooling but all shares a common set of data that supports all of these different risk management capabilities.
So now I want to come time to say well now let's come up with some sort of organizational change that helps these teams collaborate. Well, they're already collaborating because they're already managing risks in a quantitative way and leveraging the same source of data the same source of truth and that's what we see we call that risk engineering and we see that as being essentially the digital transformation approach to dealing with these different kinds of risks in a way that now is quantitative. It's rational.
It doesn't it reduces the dependence on emotional reaction. Oh ransomware is scary. Let's spend a lot of money on ransomware and then, you know Short change something else that may not be getting the Should but is every bit of an important risk to the organization.
That's like technical debt risk who thinks about that. Right when ransomware is a problem. Well, it's could be equally important because the the risks once you measure them could be equally dangerous to the organization, you know, it would funny that that old, you know, Reagan adage, you know, I'm the the most dangerous nine words are you know, I'm here from the government or I'm from the government and I'm here to help right, you know again a lot of security folks feel that way when they show up and say, hey, let's talk about the risk issues right whether we're architecting, you know a new system whether we're, you know, trying to really kind of visualize what a new business process is gonna be that's gonna you know, kind of stake out these digital transformation, you know types of of efforts and and part of what I've been espousing for years with, you know, kind of the folks that are responsible for cloud Security is to get into those devops teams get into those business organizations as early as poss.
Supposed to you can start to influence right what that architecture looks like. So yeah, you are collaborating. Maybe it's a little bit subversive right?
You're not having to go in there and say, oh we're thinking about security you're saying no, let's kind of look at the architecture and you know kind of point it's stuff and fix things as early in the process as you can so that you're not, you know, again retrofitting and again back to that whole technical debt issue of you know, kind of building something that is very difficult to secure when you could have made a couple of different architectural decisions up front and and made that and and I think that's really a key thing here is that you know, the digital transformation is going to force and become the Catalyst for a number of different organizational changes. If you don't think about risk within the context of all of those different changes again, we're in the same Groundhog Day we've been in for the last you know for me, it's almost 30 years right where you know, same same crap. Per day, right, you know kind of always trying to put the genie back in the bottle and you know, that's a difficult one to do.
So, can we use these opportunities as a way to you know, get out ahead of it and really start to help folks understand what architectural decisions what process decisions really what transformational decision is, you know can both achieve the business need as well. As you know, not put a lot of that data, you know at risk, right? And I think that that that's that ongoing challenge is giving a lot of these folks that understand this risk mentality the vernacular to talk to the business right to really kind of see be part of the you know, kind of front end right spearhead this organizational change what a lot of folks are sitting there going.
Yeah, I understand, you know kind of far more rules. I understand ransomware. I understand adversaries, right?
I may not understand the business to a degree to make the case as to why this is important again, this kind of seems to be the continued Gap. Had for many years is that you know folks that do security want to do security right folks who want to do business want to do business and the twain, you know have not met often enough for it to really make a difference. Yeah, well, you mentioned, you know bringing security earlier in the development life cycle, right architecting security into software and that's a part of the shift left movement and shift left, you know is a is a term actually I remember it from the 1990s.
It shows how old I am. Right and in 1990s is before the agile movement. There's a book called code complete that talked about shift left quality.
It was about quality where the later in a life cycle you deal with quality the more expensive in time consuming it is right. So traditional waterfall does testing at the end of development to turn out that was Impractical because there's too expensive too long and didn't really give you good quality code. So you shifted to the left you plan the test plan the test ahead of time and this is it became part of the agile movement, but it actually predates agile where you shift quality to the left and plan plan for Quality code at the beginning and you end up with better quality code and you spend less time testing and and you know, so you deliver more quickly as well.
So this is been of established software development best practice now for 30 years, right? It's nothing new and a lot of the developers who are currently developing. It's been part of their life since before they were born right music people are less than 30 years old, right?
It's just been the way to build good software forever right before, you know, if you're if you're too young to remember the 1990s, right, so That's nothing new. So having a context where you build quality into software. It's something that developers are expecting to do right?
So the taking the leap to building security into software is not a big leap because you know in a way from the developers perspective. It's just another kind of quality right having a security breach in software is essentially a bug right? Oh, you know, I allowed for you know SQL injection.
Well, that's yeah that is a threat from the security person's perspective from the developers perspective. It's a bug right they should have fixed that they should have planned ahead for that. So that those kinds of bugs don't creep into the code in the first place and that's what it means to build quality code from the beginning right in a shift live so flat fashion, so we just want to make sure we don't forget this why they don't forget that shift left is still important even in the context of modern software development where we're doing so much more in production than we used to do right in a modern Cloud native environment.
We're likely to do a lot of testing and production. Go to Rolling Out software all the time, right multiple teams are doing it. So you roll it into Canary or a/b testing and we do testing in production because we simply don't have the time or the appropriate environmental context.
Right? If you don't have a an adequate test environment to do any testing anywhere else well, so that's shift right right is shift in moving testing into production is shift right shift, right and shift left in spite of the names are not opposites. You can do them both at once right?
If you do them properly, you still need to shift security and quality to the left, even though you're shifting a lot of activities to the right. It's part of the gitops mentality where we're leveraging the power of get to manage our software deployments in a best practice way that enables us to manage shift, right even though we're still shifting left. So this takes the discussion a bit away from digital transformation, but in reality these kinds of software practices that are supporting Cloud native Computing and shift right Computing and and a very Dynamic scalable software at speed is Central to many organizations digital transformation efforts.
So we have to manage security. We have to manage compliance and other risks in this context of dynamic software at scale and or we're never going to be able to leverage Dynamics software and scale and that will put the organization at a competitive disadvantage. So one hand you have to manage risks on the other hand.
You want to deliver Dynamic software scale. You have to figure out a way to do both at once and this this threat engineering approach I was talking about is is essential part of that because we will need to make it collaborative. We need to make it data-driven.
We have to do it across the board. We can't just have it siled or we're never get to the point that we can deliver Dynamic software at scale without just introducing tons more risk, and and the organization would never want to do that. Right which is counter to the point that we're trying.
Right exactly, you know where digital transformation is gonna happen, right? That's really what tech strong cons all about and you're you're all sorts of, you know, different aspects of that from you know, the dev side from the op side obviously from the security side from the business side funny. We were just ideating today about, you know, kind of our digital cxo Summit which is gonna be in the fall which really talks about, you know, kind of the strategy of all this stuff but that's a long winded way of saying this stuff is gonna happen, right?
What are the things that we've seen to that whole shift left shift? Right, you know type of an under them is you know, again, it's really fostered and requires collaboration because we've seen developers push back on I'm responsible for the entirety of securing this thing you security folks what the hell are you doing again? Right?
So, you know, we have to have shared interest. We have to have shared accountability. We have to have shared responsibility to make sure that anything that is related to these.
Will transformation efforts doesn't put data at risk doesn't put you know, the organization at risk and it's hard, right? So it's not you know, again digital transformation was hard enough, right? Just getting everybody on the same page you're trying to get them to you know, kind of build new systems and think creatively and innovate and and you know kind of kill the the the children and the like so to speak right because you know, you got to eat your unborn to use terrible Andy grow wisdoms.
And again, you know, Jason your old enough to remember those as well as as I am, but you know, you have to think about who is my competitor. Oh, it may actually be me, right, you know how we do things currently, but you also have to think we're in a much different risk environment than we were in the, you know late 80s when I came out right, you know school, you know, and the mid 90s when we kind of went through the initial Mainframe the client server, you know kind of transition in the early 2000s when you know internet Three tier type applications really started to hit and now, you know again in the 2015 to 2020 range when we have these modern architectures that are driven on, you know, kind of cloud native infrastructure. So as that risk profile continues to increase it becomes that much more important that Security is part of the discussion right that risk management from a perspective standpoint really starts to influence how a lot of these digital transformation efforts and really the implementation of those within the technology Stacks really start to come to fruition.
So I mean tons of stuff we could probably talk for three or four hours on this if not more. Unfortunately. We don't have three or four hours.
We're almost at time but just if there's one thing that you could tell our audience here about things that you really have to think about relative to securing your digital transformation, what would that one thing be? Well, I mean tells you as you mentioned digital transformation is difficult. It means different things for different organizations depending upon their their current state and where they want to go.
So it's not like everybody has to do the same things but it is an ongoing challenge where you don't finish your digital transformation, you become better able to deal with change. So it's an ongoing thing. So within the contest of risk management our comments about shifting to the left, right you have to be proactive with all of the risks facing the organization and digital transformation involves breaking down silos and that includes silos across these different areas of risk.
So that's essentially because it has to be done in a shift left. It's a prerequisite where you have to get started on that as your early as the early part of your digital transformation because you don't want to be in a situation where you're down the road with digital transformation you find that your siled risk approach is now adversely impacting your ability to manage risk. That's a recipe for disaster.
Right? So you need to be Active with regard to potential disasters including these kinds of risks whether they're cybersecurity risk operational risk, great risk of downtime technical debt risk, great risk of Southwest type of failure or other compliance risk, which can lead to you know, lead to your Executives going to jail. They clearly don't want that.
They probably don't want that but for sure and and again, so the thing that I kind of take out of this again is organizational change is going to drive a lot of you know, kind of what is gonna work and what isn't gonna work relative to digital transformation breaking down those silos and really collaborating which means if you do happen to be a security professional you've got to start to add a lot more business lingo to the discussions you have and you can't just stay in the little corner of our world where you're just talking to security folks all the time right gotta get out. You got to experience business. You got to understand and learn how to you know, really kind of frame the issues of any initiative within the the context of business risk.
So with that thank you Jason Bloomberg in Alex. I think this was a great discussion give a lot of people a lot of food for thought as they're either headlong in a digital transformation effort or trying to you know, kind of figure out what it means to them as Organization kicks out one of these things off. So your Insight was really invaluable Jason can't thank you enough for that.
And with that, let's head back and headed to the the next session.





