Palo Alto Acquires CyberArk for $25B, Identity, Risk & Accountability | TSG Ep. 893
Palo Alto Networks acquires CyberArk for $25B, signaling a major cybersecurity shift. As data breaches surge, identity management becomes central to modern security strategies. We also dive into the challenges of tech integration, vendor risk, and the scrutiny facing Cognizant after recent failures. Transparency and third-party accountability take center stage.
Transcript
Hey, did Vibe coating know what you did this summer? And in What's 25 billion amongst friends? We're gonna talk about a couple of those topics here on the Textron Gang.
We'll be back in a minute. Hey, thanks for joining us again on The Gang Today. We've got a number of, uh, great members that we're gonna be talking about.
Some really cool topics, you know, 25 billion. If that didn't get your attention, I'm not sure what will, but of course, we probably know a lot about that already. Joined by John Schwartz and Lisa Martin, Fred Wilcott, and, uh, the very own, uh, IRO Winkler.
Good to have all of you here, regular gang members talking about this stuff today. Let's, let's take the teaser, the 25 billion. You'll, we'll, we'll, we'll take the hook and talk about that with, uh, Palo Alto, uh, snatching up cyber arc.
Uh, John, why don't you kick that off for us? Sure, yeah, I'll make this really brief so I can get everybody's comments, because I'm really interested in what you all think. I mean, it's just another big cybersecurity acquisition.
So, as you mentioned, Mitch Palo Alto Networks is, uh, announced on Wednesday. They're gonna acquire CyberArk software for 25 billion. It's the biggest deal yet for Palo Alto Networks, and they've done a lot of deals.
Um, this deals, uh, expected to close in fiscal 2026, and it comes on the heels, as it, we mentioned Google's $32 billion acquisition of Wiz, and in 2023, Cisco scooped up Splunk for 28 billion. And there is a rumor that Okta is in play, and there might be something happening with them very soon. I, I spoke, uh, briefly with, uh, Krista case, who's the research director of Cybersecurity and Resilience at the Futurum Group yesterday.
And she talked to me about the importance of, uh, identity in today's critical attack vector, which was a major reason behind this deal. Um, and I'm sure we're gonna be seeing even more consolidation. And, uh, Alan, who is now with us, wrote an interesting analysis on, on the market.
But what I wanted to do is go to Fred first and get his impressions. And then after Fred talks, I'd like to share what Lisa has to say from the marketing perspective. So we'll kick it off with you, Fred.
Uh, it's pretty amazing. I think one of the things over time that we've watched, uh, with, with Palo Alto, uh, Palo Alto, no longer Palo Alto Networks, right? Much bigger, uh, thought and vision for the company, uh, Nikesh, uh, or is basically crazy like a fox, I think, uh, super talented.
Uh, I've had the privilege of being in a couple of meetings with him in specifics, uh, but super talented operator at the helm. And I think what, uh, where he sees the, the future, you know, he skates to the puck, uh, in this particular case identity, everyone knows is a fundamental, uh, requirement for, uh, netting altogether. All of the resources you have.
I think there's inherently, it's a good decision from a product, uh, affiliation perspective and making no bones about exactly how to go out and do that. Um, they've demonstrated a bunch of success with some of their acquisitions already. Uh, you know, I'm not sure what we'll see out of this, but it's an incredibly powerful statement that also helps unlock, I think, a lot of the motions in the market about, uh, you know, where small, medium and larger companies in the acquisition climate can, uh, can start to move in this economy.
You know, I think, um, I've sat down with Nikesh before as well to interview him. And I, I've never been more nervous. He's so stoic.
I was trying to crack him. And how about, you know, just a where are you from? Kind of, you know, late night talk show conversation.
And he was outstanding, uh, as a guest, which was a nice, pleasant surprise. But I think from Palo Alto's perspective, I was taking a look at CyberArk from a customer perspective. They've got, they've got some great enterprise customer appeal.
They've got customers like Aflac, I think also Coca-Cola, Cisco, um, what we've seen in the cybersecurity market, we were just talking about this. Alan and I, and Mitch, you were there as well, and John too at, at RSAC just a couple of months ago. And this huge surge in data breaches and ransomware that's been really propelled by AI tools.
And that's increased this urgency, I think. And we're hearing a response to that urgency and with increased interest in firms like CyberArk and consolidation. So I think it's showing that what Alan talked about in his article was that the industry, the cybersecurity industry is at an inflection point.
And Palo was responding to really strength strengthen its position in the cybersecurity market. We're seeing more consolidation, which is another theme that came out of R-S-A-C-E. And from a a, a messaging perspective, I think what they're saying is, you know, managing identity is simply not enough.
It has to be secure from the forefront. Because today's world, every identity, whether it's human or machine or coming now, AI agents is a potential target. And I think that what they're demonstrating and saying from a marketing perspective is that this is security for the AI era that we have to address head on.
Yeah. Um, oh, sorry. Um, let me just jump in 'cause I have two observations.
One, I think that more important than identity, all of a sudden being out there, I mean, to me, this is a sign of where Palo Alto intends to go as a company. 'cause I think specifically, you know, I've heard from people who know Nikesh, I don't know him. He would ha, unlike the other two, I have not been, well, I have been in a room with him, but he would not know who I am.
But basically, Palo Alto is trying to be Symantec 2005, where Symantec was buying up every possible thing to fit every possible security need. And I think this is the direction Palo Alto is going. So yes, identity's important, let's not downplay it.
And attacks are there, and everybody likes to think it's some sort of strategic move. But really it's a move for Palo Alto that they are filling in every block in a matrix. You know, they acquired a lot of companies for a lot more money than I think they should have.
But, you know, they acquired like Dig, they acquired Talen, they acquired like, you know, now them and a bunch of other ones, and they're basically filling in a hole. And in this case, I'm almost impressed because I don't think Palo Alto is spending way too much money. I don't think this is akin to the, I'll say this is different than Wiz.
'cause Wiz was a private company and a private company with random valuation with a company that had an incredible amount of excess cash, which is essentially what, you know, Google is, you know, and they could pay more money than theoretically it's worth. Um, cyber Rock, on the other hand, is a well established public company with a well-established valuation. They're probably giving a fair premium.
I haven't looked at the stock price 'cause I think it is 25, the valuation. Yeah, it's, it's a little bit more than the valuation. I, uh, it's, um, and CyberArk's been, uh, public for about 10 years.
And just one other thing I wanna just mention really quickly, IRA, I'm sorry to interrupt, is that, I'm glad you mentioned this, this idea of, of more of a, of kind of a comprehensive solution because the word comprehensive keeps coming up in terms of cybersecurity solutions and filling gaps and filling holes. So back to you. Yeah, I think that's probably a key concept.
I mean, because the power, there's pa like for example, in the cybersecurity industry, people like the Guidepoint and Optives of the world. 'cause they can have a master contract and then buy anything they want through them, where they're, they act as the reseller. And it makes it easy.
Palo Alto, by acquiring all these different types of technologies, means you can have vendor consolidation and a buy from one person instead of going through legal contracts with lots and lots of people, which in a large company does matter. It takes time, it takes effort. Smaller companies even more important.
But I think one of the things that is gonna be a, a critical success factor at the end of the day is how well are they gonna integrate this? So it could all be managed through a single platform. Because, for example, you look at some people like ca and they just buy everything, or I dunno, ca around still, but they just buy everything, throw it together, and try to get people to migrate to their preferred platform at the end of the day without integrating what's there.
Microsoft, for example, when they acquire a company, they do a lot of work to make sure it fits well within the ecosystem. And it's gonna be a trick whether or not Palo Alto is acquiring all these different things and allows you for, for lack of a better term, manage it through a single pane of glass. And as opposed to just being a simple contract vehicle, be a true platform.
'cause there's a difference between being a platform and just being a source for a lot of different tools that don't fit together. Kind of a product catalog versus really a platform. You know, to your point, IRA, you, in addition to, are they filling out the, the, the seats at the table, right?
The blocks with identity. Um, I I, I've seen numbers like over 10,000 customers for CyberArk that Palo Alto now gets access to. And since they weren't in the same markets, uh, they're in security, but not an identity with Palo.
That gives them access to a whole new set of customers as well as the ones that they do overlap with. And to your point about easier to do business with, 'cause we now have one contract and one, uh, one way of dealing business makes it a lot easier for them to both assume cu current customers, but go after a lot of others. Mm-hmm.
Yeah, I agree. Um, people don't realize large companies do have a serious problem in managing lots and lots of vendors. However, as important, when you're managing lots and lots of vendors, you also want ease of integration.
And if you're just gonna have a CyberArk out there functioning as CyberArk, and then you're gonna have your firewalls functioning as firewalls, you're gonna have your web browsers functioning as web browsers, it's gonna be a mess. But then there's also the implication. I haven't got to, uh, I just, I'll just pass the concept of zero trust.
A full zero trust platform requires identity. I was just gonna say, IRA, to your point about integration, they did the right thing from a marketing messaging perspective. 'cause they talked about, oh, you know, we're gonna be combining CyberArk strengths with Palo strengths, and we're gonna deliver these integrated security solutions to our customers that they need to secure their digital future.
So the messaging, they talked about it, but to your point, whether that is delivered is a different story. You could also argue, Lisa, that ai, AI agents identity of AI agents and things like that are also critical to a future. And how disadvantages Palo without That?
That's a good point. Ms. Beach is, this morning I got a, uh, an email from the former chair of CyberArk's board, this guy named, uh, Errol Maritz, I sorry if I butchered his name, but he, he refers to this as a complete end-to-end agentic AI cybersecurity automated platform.
That was his, that was his takeaway. So it's hyperly, what do you expect? Yes, I love it.
It's all about, it Always is. Well, We'll talk, well, I mean, big companies. Yeah.
Big companies do acquire innovations. In this case, I think it's innovation market customers, all of the above. Right?
And how well it's integrated, that's, uh, in the eye of the holder to be seen. Alright, good. Well, you know, we'll, uh, we'll see how that, uh, 25 billion gets spent, I guess, in a lot of stockholders.
Um, I think it was a four, I forget what the numbers were. It was part cash and, and stock deal as well. Ca Yeah, cash and stock.
Yeah. $45 a share. Yeah.
Et cetera. They typically are. So.
Well good. Hey, there's, and more to come, right? We, I think we all probably expect more.
Oh, we're just getting started. Acquisitions and consolidation seems, uh, pretty, pretty common in the cyber security market. Alright, well we're gonna take a break here and we'll be back, uh, come back and talk about, um, are we generating secure code or are we just generating code with ai?
There've been some incidents to talking about security with, uh, AI generated code. We'll be back in a minute. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way.
With Techron Group. Hi, welcome back. We're talking about security and AI generated code, vibe, coding.
Now, Alan, who's now with us today, he's on the road, uh, moving his son from one city to another. Um, he had, he had lunch with, uh, Eric Cab Battis, who's the founder of, uh, include security. And one of the things Eric said to him that caught his attention, I think probably caught all of ours, is, uh, you know, that, uh, s stands, SS in Vibe, coding stands for security.
Okay. Hmm. Yeah.
Well, does it really interesting, you know, I I there have been links to, uh, links to, you know, NY and other, uh, software security, vulnerability scanning, those kinds of things. But I, I'm really fascinated or kind of frustrated that the industry hasn't really stepped up with secure code generation through the LMS themselves. Yes, we need it checked, but let's start with more secure code than what people can generate.
And it doesn't seem, we've made that many advancements. So we've already seen some incidents where, you know, databases get dele deleted, configs are left open on the cloud, et cetera. We'll see a lot more.
I think, Brett, I'd love to hear your perspective on, uh, you know, we're generating more code, but probably more unsecure code. Yeah, no, it's, uh, I, I think when you look at the amount of models out there and the data they've been used to, to train on and the code they've been used to train on, so Veracode would say 45% of the code for more than a hundred AI models, uh, contains known vulnerabilities like, you know, SQL injection, cross site scripting, you know, all the various things that we know. We root out with the O os top 10, you know, with static dynamic analysis tools that do that as a usual, uh, way of operating.
What's interesting to think about is like the, the suggestions both on the language type, the volume of these vulnerabilities or problems that we know, we sort of put in the automated checks and behaviors for or guardrails, right? For us to, to do that with younger developers. We're seeing some other interesting parts of this where that software development lifecycle doesn't include these tools, uh, and arguably might start less secure given the fact they were a trade on insecure code to begin with.
So it's interesting, right? We had, you know, this, uh, this, this set of occurrences, the the rep conversation that you're referring to around the sql, you know, production SQL database getting dumped. But you also have, you know, the Amazon Q extension issues around the, the version compromise where there was a GitHub PR that was submitted here that had malicious, uh, effect due to, you know, insufficient code review.
Uh, it's just sort of fraught with peril everywhere. I don't know that vibe coating's the problem here, uh, I would say this is, uh, you know, if I were channeling my inner IRA Winkler, I would say this is the problem we've had for 20 years, uh, maybe longer, but uh, now we have another permutation of it with not following any of the same rules. We already know.
Ira, you can stop stupid, right? This is your, is your domain. So well Technically you can stop stupid and that's our job.
But I would argue it wasn't the first time I heard the joke. The s in vibe coding is not well vibe coding that, I mean, the S in IOT stands for security. The s in worldwide web stands for security because what I see is a consistent problem through the history of technology where security is an afterthought.
Like there was no security in the mosaic web browser, web servers, whatever, when they first came out. There was no security in IOT when they first came out. Now, the problem is people always want the benefits of saving money and speed to market without actually investing in any forethought, especially with regard to security like the coding alone.
Because really security vulnerabilities are essentially coding bucks, for lack of a better term. I'm oversimplifying. And if there are security vulnerabilities, there are coding bugs.
And that leads to fundamental issues where people are generating massive amounts of code that are gonna experience problems and fail both in functionality, um, resilience and security. And so I see this more as an overall problem where companies are just trying to rush out there. I mean, I remember this was a story I maybe you spoke on in another tech strong gang.
I wasn't on it, but there was an Indian company which said they had a, a, an agent AI that wrote software, and it turned out they were just hiring lots of people. I don't understand what's wrong with that. You know, you're essentially paying a company to write software.
Do you care how it gets written? As long as it solves your requirements? There seems to be this focus like, oh gee, you didn't do it with just an ai.
I am like, does it matter? And we need to understand that if you take out the ai, the AI only does what you tell it to. And if you're taking this out and you're not, including, if you're taking people out and you don't include security in the programming of the vibe coding tools, you're gonna be screwed.
And this is a problem where people need to say there are security requirements. This happened with Microsoft, it happens with every software technology out there. And sorry, I can go on a rant about this, but this is nothing more than everything else.
Like another mistake you just see that's gonna snowball unless people stop it and say, where's the security? Yeah, the, the, the three points that I would just make real quick, Mitch, if you look at, uh, repla AI wipe, okay, no environment gating, we know that to be a problem For anybody that writes code, the Amazon Q hack, that's a poor PR review. Okay?
We just automated that process and didn't participate. And then, you know, a lot of the things around the vulnerabilities, well that's just, you know, the absence of A-C-I-C-D security, uh, pipeline for that process, right? So none of this is a new problem.
We just took all the governors off and decided we're gonna write a bunch of code and push it. You know, Lee, all good points. Lisa, I, I wonder if we're exacerbating the problem with AI because we are in such a rush to move into AI to capture mind share, to, you know, move beyond just kind of saying we're doing ai, but, but bringing things to market and with that accelerated pace, the security problems could be even worse.
Oh, absolutely. I I think we, we hear that constantly the speed, time to market, time to value. And whereas what Ira was saying, I totally agree, security shouldn't be a, a feature that you tack on when something goes wrong.
And companies talk about this all the time. This is a message that is consistently relayed. It shouldn't be an afterthought, but it is.
And by the time customers are asking, it's usually because something's already broken. But I think the problem is, and, and some CMOs I talk to, argue that we've gotta slow things down. This accelerated pace, which I think is only poised to get faster, is causing a lot of problems that we could be preventing if we weren't trying to be the first to market every time and infuse AI into everything.
I think that that rush mentality has got to slow down and it's gonna take some strong companies willing to do that and not be first, uh, for I think that, uh, problem to start to be reduced. I don't say mitigated, I think reduced. It reminds me of, uh, the exuberance about going to the cloud when that was like, oh, let's get everything to the cloud.
And then that got sort of quelled by Yeah, but it's not secure. I know, Fred, I, you, you vibe with that too. I wonder if we're gonna hit that kind of an a moment with AI generated code.
I would say, here's the issue that the cloud is actually an interesting example because in many cases what's happening now is moving to the cloud gets you more secure these days than if you did it yourself. Because an organization, let's just say an organization that's using like Google apps or whatever the case is, those organizations are fundamentally being managed more secure now because Google has better internal security than I would say 99% of companies can implement on their own. Same, whether, you know, same thing with my, you know, office 365.
Salesforce, again would manage the CRM programs better than people would themselves and so on. And it would be nice if these, you know, vibe companies are actually writing software that has better security implemented into them in the first place. The problem is, I don't think these people know these are people who themselves, you know, it's like Google has a lot of security engineers.
These are startups that have no concept of their people have no security background, they just know how to code generative ai. And frankly, I doubt they even know how to do that. They're just figuring out as they go along.
And then trying to tack on security is almost the opposite of what's happening with cloud security because you're getting a whole bunch of people who don't have native security ability, who are then not investing in security trying to get these applications up and running quickly to sell. And I think that's where we're gonna have more problems if I, if I'm not doing an endorsement here, but if you tell me Google, Oracle or somebody else like that is developing these vibe coding tools, I would have a lot more faith in them than just these generic startups developing them. Interesting.
John, do you, do you hear much in the market? Is anybody talking about this in terms of, I mean, one scenario would be pick your company open AI or Anthropic or whoever that's building foundational models. Say you go get the Freds and I Winkler and other people of the world and, and software engineers who know about secure coding and build the next model that's really good at, at creating secure software.
I mean, that's just one possibility. Is anybody besides just integrating with, uh, code security products, is anybody talking about solving this problem that you've Seen? Um, not really.
It was just like full bo full throttle ahead. I mean, when you mention open ai, it's like, I can't even keep track of all the new product announcements or releases there. I mean, it's just like, it's dizzying, you know, they're, they're leapfrogging themselves, you know, uh, so I, I wonder we again, and I, I'm not gonna be a alarmist, but I'll, I'll throw this out.
It's eventually it's gonna ha be some sort of incident. I thought it was CloudFlare. I, for instance, I I I thought it was about that a year ago that where there's gonna be some sort of caution around, uh, the lack of guardrails.
I remember we talked about this yesterday, this, this idea of getting, getting full speed ahead, damn, the consequences. And I, I just, I don't see it changing unless people are, are, are forced into some sort of public relations or cybersecurity disaster to address it. Um, I think right now the obsession is just to, is to get out there as fast as possible and, and especially if you're larger companies and overspend as Ira had pointed out, which I agree with and gobble up as much as you can.
But I think it's also, we're also tilting the direction with the larger companies are just, are, are at a huge advantage versus the startup community. You know, I've done a, a fair amount of my own kind of working with these vibe coding, if you wanna call 'em that tools. And, and I think it makes the case for a more experience developer because it doesn't generate code that's that's more secure.
You have to ask it or tell it what you want it to do. You can ask it to exam and examine my code. Find where you think there are security flaws in the design as well as scan it and may find something, may say, Hey, here's a constant that you've defined probably shouldn't be in your code.
Let's pull that out. But you, you have to ask it or tell it to go do things. It's not gonna naturally, oh, I need logging for that.
I need to know when something happened. I need, I need to, uh, apply this approach as opposed to, you know, leaving something, something open where I'm gonna violate an O os top 10, I guess you could say, make sure my code doesn't, but then who's gonna verify that, right Fred? Just to verify, I think the, the easy steps are the ones we know already for guardrails, right?
It's not hard to separate environments. It's not hard to implement A-C-I-C-D pipeline with approvals, right? It's not hard to, you know, put branch protection on things.
Like, there's just a lot of things that we know that aren't hard. So those are easy things we can do. The fixing vulnerabilities, I mean, okay.
I don't know. Yeah. But I would also have to add that you can take away, you know, it's like easy to put the blame on the companies writing these vibe tools or whatever.
You really have to blame the customers at the end of the day because just 'cause you get code from a tool, it doesn't mean you take away the ver verification of this code. You know, it's almost like, oh, well it's the developer's fault. It's like, no, it's kind of your fault because you're taking stuff, you want it cheap and you're not investing in quality assurance in any way, shape, or form.
'cause again, if security vulnerabilities are slipping through, that is a specialty, I admit. But functional quality problems are also gonna be slipping through as well. I think the interesting thing we're gonna have to wrestle with here is a, a company may get around their environment pretty well and understand the guardrails, but, um, third party risk.
Uh, we don't know whether or not your code is secure. We don't know whether or not all of these other, uh, processes have been followed appropriately. I mean, it's hard enough to figure that out within ours, but if you look at sort of the Amazon problem and, you know, some of the provider problems, these are significant that customers had no action on.
I think it's a, I mean, it's a, it's a good segue into one of our other things we're gonna talk about. Yeah, it's a good point. Especially with the innovation cycles being so short with these tools, you know, coming out with the new plugins, new models, new everything.
You know, i i is the proper security testing happening in the, in the product end of things. And then back to your point, it, it, IRA, it's kind of what were you thinking when you left all those good security practices on the table to try this new coding tool? You know, was that really a good decision?
Probably not. Well, all good points. Yeah, I would say there's an issue though.
The question is in the first place, and this goes back to one of my other comments, did they have good sec coding, coding practices, coding, especially coding security practices in the first place, which is number one, and then at some point, much like all these other, you know, rush to the cloud and everything else, do they have contractual, um, obligations built into the contracts with the providers to ensure that these good security practices are then embedded in the acqui, the acquisition of software that they're essentially making? Frankly, I think I don't, most of the companies who are being hit, I doubt had good security practices in the first place, or they would have verification of any of these things going into production, but that maybe have the look on, on case by case basis. All righty, well we're gonna get into some more security issues around AI on our next segment.
So we're gonna take a BA break right here and we'll be right back. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. We're back at, um, Textron Gang and this segment is called Passwords, please. And I cannot wait to hear what Ira and Fred think about this one.
Uh, Clorox is accusing it services firm cog cognizant of letting hackers into their corporate systems simply by giving them the passwords when asked multinational. Uh, Clorox is suing Cognizant and Superior Court in California for $380 million for its role in a cyber attack by the scattered Spider threat group nearly three years ago. It's also seeking punitive damages.
I'm just gonna tee it up and say, what do you think Ira, about this one? Alright, so I've been in security like so long, like nothing has come to surprise me. I have however, developed what I call a church lady scale.
You know, the church lady scale is hopefully people get this is isn't that special and then could it be Satan, you know? And oh my God, you make a good data car, by the way, you know, Harry, I live, yeah, God, that's it. That's old school.
And then for this one I almost, I had to add like the Deadpool scale where Deadpool has like his, um, uh, what's the name? Home alone face, like, you know, a hopeful maybe you saw like, you know, like that because I'm like sitting there thinking one of the major providers has, and and they, they claim to have audio of this, you know, one of the major providers has no identity verification, you know, going back to the first block discussion of like, you know, multifactor authentication and they're even saying where there was multifactor authentication, they could just change the phone number by calling up and asking for the change. And, uh, I mean, when you look at fundamentals of a help desk, this is like one of, I, like, literally more than a decade ago, I was writing help desks, actually two decades ago.
I'll, I'll mention this because there was a case where Microsoft, hopefully Microsoft's not mad for something that happened more than two decades ago where I was like paid to go through Microsoft's authentication procedures to verify like a decision tree. Like if somebody calls up and says, I want my password changed, how do you go ahead and, you know, do this? So I went through a decision tree.
Okay, well what if they say this? What if they say that? What if they say this?
And so the people know, like from a security perspective, how do you do that? And that's without the technology in place like caller ID and everything that we have now. And so we would, and the reason I did this was there were account takeovers where people were calling up the Microsoft help desk on their gaming systems and saying, oh, I forgot my password.
And the agents would change it and then people would like sell off all their like magic unicorn hammers or whatever it was. So there was a lot of money to compromising this. And Microsoft decades ago realized there was a problem and took proactive steps to putting in like this whole protection mechanism from an operational security perspective.
And that doesn't include, for example, you know, like the technology caller id, multifactor, authentication, everything, you know, to the extent we have now. And so when I look at this, and this happened, what, 2, 2, 3 years ago, I guess, you know, this was kind of like horrifying because people, you know, I do social engineering simulations where I call up a help desk and get them to try to do things and people are like, gee, that's not nice, that's unfair and all that stuff. And you know, somebody should have, honestly, it's not a standard practice, but this is beginning to an incident like this says all large companies should implement it as a standard practice to try to see how hard is it to get their help desk providers to change things like this.
Because if any of this is halfway true, this is horrifying where you are, you are paying somebody to implement processes, which supposedly there were that were just not followed appropriately. And to the extent they say, look, I am no doubt Cognizant is strong in security in many, many ways, but there has to be an acknowledgement if, if this is true, if as alleged, you know, people could call up and just say, Hey, please change my password or gimme a new one or change the cell phone. That's a problem.
And that's an operational problem because a lot of people are relying on technology and they need to make sure they have the appropriate operational procedures. Like I said, I helped Microsoft with decades ago of step by step by step, what's the right way if you don't have the technology? There was supposedly, if the articles were correct, a process to at least verify with the manager or at least inform the manager that this was done.
And so, yes, a CyberArk is critical, but you can't ignore the operational procedures you need to build in. And a, I'm sorry, I like, this is just like I said, Deadpool level, you know, horrifying, you know, like, you know, like that. And so hopefully, um, anyway, I will leave it at that.
My rent temporarily over. Yeah. Hey, you know, Lisa, you, you, we've talked before about sort of the incident management from a brand company perspective in these kind of situations and you know, sometimes you think something fatal has happened, you know, maybe it's a CrowdStrike, but you know, CrowdStrike had a great reputation before that, I'm sure Cognizant did too.
What, what do they, what do companies have to do to to fall back and recover from this? And is there any really big financial impact when something like this happens or we kind of desensitized to it now and we just don't wanna be Clorox? I think, well we don't wanna be Clorox, but, uh, it's funny, IRA got a, um, an OG church lady vibe.
I got a Lloyd Christmas vibe with these folks on the set of Cognizant just go, sure. Because he was, you know, Lloyd Christmas, he just could do anything. I'm so happy.
But I think one you mentioned CrowdStrike and I praised them recently on Schwab about being a company to watch, but also one that was completely transparent last year when this huge breach occurred, not breach, um, uh, issue happened, security incident happened. Their CEO came out, I think same day, acknowledged what was going on, took the blame, and they've come out really well. I think they've really done a great job because they were so honest with customers and transparent about being able to preserve their, their brand reputation.
Nobody wants to be the next, in this case, cognizant. But what Cogni what what I read in this article was, it's a, he said, she said, Clorox is saying this. Cognizant is saying, no, we did this instead.
But what what they need to do is acknowledge where they had missteps on both sides to be able to salvage the trust that com customers of all types have in both brands. I think that transparency, um, is not, it, it's a, it's an imperative to be able to maintain that customer trust and then to continue earning trust from perspective customer. So that he said, she said, mentality is not gonna help in this case.
Well, I think also you have to look at how other companies did. There was an incident, JP Morgan Chase lost 80 million records. And the 80 million records was due to the fact that one system did not have multifactor authentication on it.
That was like a failing, it might not have been the only failing, but you know, people were saying, Hey, there's this issue. And they were, and there were some other major incidents happened that were on a smaller scope at about the same time. J at the time JP Morgan basically came out and said, yeah, we screwed up.
There should have been multifactor authentication on the system. There was not, we will deal with it. And everybody just said, I have nothing to yell at them for.
Everybody was just like, there's nothing to dig in. They put out information, they said they were wrong, they said they're gonna fix it, and the story was over. But then you have all the other stories where people are pointing fingers and that creates more of a story.
It's always the co it's so, I mean, I hate to say that it's always the co not the, I'm not saying that there's a coverup, but when you're transparent and up upfront say, look, we made a mistake in the case of CrowdStrike or JP Morgan. The what this issue about cognizant this interesting to me is you wonder if there were other similar problems with other customers. I don't know if this is a one-off.
So therefore, I mean with Iram a little bit, um, aware, I'm not wary of what what was written, but it says again, if it's a he said she said story that's difficult to weed through. Yeah, I mean if they would just frankly say, look, we, there are deficiencies in the thing that might have gone ahead and cr you know, added to this. We're investigating this.
If there are deficiencies found, we will address them. That would make it more of a non-issue. Because frankly the more Clorox has to drag it out the way these cases are gonna work, they're gonna go ahead.
They're gonna dig into all of cognizant security to find every possible flaw that Cognizant has in there that could theoretically come out in court. They will almost a hundred percent settle out of court where, you know, cognizant admits nothing wrong, but gives them money. The reality though is if they would just say there seems to be a deficiency that we're looking into and have addressed since that time, it would make people feel so much better.
Because I don't think anybody expects perfect security from any vendor out there. And yeah, but Let me interrupt you 'cause I think, let me put the, you put your CISO hat back on, I'm gonna put my former identity provider CISO hat on and say two things. There's this notion of implied security and around third party relationships, right?
So as a identity provider, right, I might outsource to another organization or health or hope desk function or support function. That organization may also, uh, be sourced for five other organizations, right? So if we go back to the Okta breach, this is what happened there, uh, at the same time, right?
I called Dave at that time, was like, Hey, exactly what happened. Why? Because some of those same environments at that time, we also used some of the same people.
So one of the challenges with this particular exercise is transparency is one thing, but accountability is another. And so if you've outsourced your third party risk to an organization that is a industry known Titan for doing this kind of work and it becomes a problem, there has to be some accountability there. The cyber resiliency part, Clorox has to own that too.
It's a shared responsibility problem. But the, the bottom line here is like if you trusted Cognizant to do your endpoint and identity management and this particular thing happens, happens, is that not akin right to a violation of your third party trust agreement? And are they not accountable for it?
Well, I'm not disagreeing at all with any of this responsibility. I'm saying from Cognizant's perspective, they need to just say something clearly happened. We're looking into it.
Even if they would just say, yes, there was a problem. It appears to be an isolated attack from what they could tell, we haven't heard others. If there are others, the more they fight this, the more public, the more it will come out.
But I'm just saying from a response, a PR response capability, they should do what JP Morgan or Tylenol did. And I don't, sorry, I saw the Tylenol. Yeah, I was thinking back to a year ago with CrowdStrike.
CrowdStrike was pretty transparent, I think about the way Delta reacted. They threatened to sue and they, they, they spoke way too loudly. 'cause I know Ed Baskin and his, his whole idea was we are gonna be as advanced technology as technologically as anybody else.
And they immediately pushed that. And you know, in a sense they, I think they had some sort of reputational damage and then Microsoft just put his head in the standard in the sand and pretended like nothing had happened. So I think about that and, and, and the, there are consequences, right in the public forum.
There, there are, um, I mean at the end of the day, it depends who's out there telling a better story. But I think when you look at this story, 'cause is Clorox, see, the thing is that, you know, it goes back to my church lady scale, you know, isn't that special? And now adding Deadpool in this case, the fact Deadpool is involved in the identity portion, does it alleviate the problem in theory of the internal resiliency?
I would have to say I don't think so. That's one issue, you know, but the issue here, I mean, as we're addressing, you know, you know, if you are outsourcing your help desk, support your technology infrastructure for Somebo to somebody who allegedly changed passwords negligently and let the bad people in. The question is, is there liability there?
That's the answer should be probably yes because there's an expectation of what they're doing. There were clearly s standard operating procedures that were not followed. You know, does that alleviate Clorox not having more resilient infrastructure?
You know, at one level, I have to find out more, and I I will say this and caveat this. At one level, I have to find out how much was the identity access management tied into this? In other words, like what in the resiliency, how much revolved around, for example, access to tool sets that were given out that allow, for example, manipulation of log data that allow for overriding of operating procedures and stuff or, or sorry, permissions and things like that.
And that's potentially a mitigating factor for Clorox. Is it to say the whole thing should have crumbled to the point where it did impact cause outside of, you know, cause $300 million worth of damage. You know, I don't know enough about the internal incident.
I would have to think, yeah, it could have been a bit more resilient, but the whole thing changes things and I'll leave it at that. Well, I guess the, can I close this topic? One thing I would also add to this is when you aren't transparent and you just point fingers at the customer, guess how your other customers feel about working with you?
That there's, there's some consequences to getting into the he that you said without that transparency. So I'm sure we'll have another conversation about another breach or some, uh, some fault in a security incident to, uh, to examine and maybe you'll learn from. I mean, that's what this is all about.
So, well thank you to all of our gang members, IRA, Fred, Lisa, John, it's been, uh, wonderful. We had a great conversation today. Kinda hit a lot of areas and, uh, there's some ties in between 'em as well.
We thank everybody for joining us here on The Gang today. Please stay tuned for some great content. It's coming up on Textron tv.
com, security Boulevard, cloud native, now, tech Strong, ai, et cetera, et cetera. com, another new one that we have. So thanks to you all for joining us.
We'll see you on the next game.