Techstrong Gang – June 17, 2024
Mike, Mitch and special guest Chris Blask dive into the breach debacle involving Snowflake and TicketMaster before turning their attention to the role the FBI should be playing in securing IT environments. Finally, in the wake of the Fortinet move to acquire Lacework the distinction between tools and platforms in the land of cybersecurity is starting to blur.
Transcript
Hello everybody. I'm Mike Baard, and welcome to the latest edition of the Techstrong Gang. We're gonna be talking about this ticket Master debacle involving Snowflake, and then we're gonna move on to, well, some insecurity that results from some of the work that the FBI is doing.
And I know that's a little counterintuitive, but we'll get into it. And finally, we're gonna look at, well, Fortinet acquired Lacework. We are gonna see what's going on with Synaps.
We'll be back in a minute. All right, folks, and we're back. This edition of the Gang has Chris Blatt, who is north of the border.
Chris, where are you In? Lovely Brook, Ontario, Canada. Excellent.
And then we have our globe trotting. Mitch Ashley is actually back in Colorado for a change. How you doing, Mitch?
Good, good to be home for two hours before I head out again on, it's a little longer than that, but it's, it's gonna be a short, a short stop. There you go. All right.
Our first topic today is this whole thing that went on with Ticketmaster was the initial breach involving Snowflake. And the, some of that stuff sits up on Amazon Web Services, and then it's researchers at Mandy and seemed to report that. Well, a lot of people are having the same issue, and it's just starting to expand and it's kind of like watching a slow moving traffic accident.
But Chris, what's your take on what's going on here? You know, we're, we're talking about Snowflake now, right? You know, and I, I just have to say, you know, I, I try to give a positive message and a positive outlook.
You know, I think that's true most of the time and worth the, um, uh, PBM Mind. However, you know, we do make the same mistake time to time again. And the first mistake is not taking responsibility.
You know, I a guide, uh, I'm not an expert on this in, uh, individual topic. You know, folks at, at Snowflake may take exception to this, but own it. Own it, you know, even implying that, you know, we're gonna help our customers fix their problems.
Uh, no, you know, don't, don't ever say it that way. Uh, Mitch Mitchell, what do you think? I mean, a lot of this comes down to this shared responsibility model.
And I gotta say, I'm a little skeptical of the whole thing, but what's your take here on, uh, is this working? Well, I'm, I'm kind of a skeptic. I dunno if skeptic's the right word of shareds responsibility model.
It's true. You're, you're depending upon the provider like Snowflake, uh, to a secure environment to secure your data, et cetera. But ultimately, it all comes back to you.
Shared security model means you're still a hundred percent responsible for whatever happens as the end user. Now, to Chris's point, I absolutely agree, is just don't fob it off on the customer. Oh, bad customers.
They just, they, they're not securing their accounts. Well, maybe you ought to help 'em a little bit, you know, best practices. I'll bet there isn't a security professional in the world that wouldn't say, Hey, you know, at least enable multifactor authentication or two factor authentication just as a start.
'cause we all know passwords are free, and, uh, there's many of them available and keys and everything else on the net. And so, uh, you know, at least to do some basic things to kind of save, you know, we know it's a pain, but you should be used to it. 'cause I'll bet you used two factor on just about everything else you use in your environment.
If you don't, we'll help you start. There you go. Yeah.
And that has really well said. You know, the shared responsibility model, you know, the contemporary topic, like right now in the CISA supply chain working groups, we're, we're looking at spinning up tiger chain. So shortlived focus groups work on things.
And what that's really interesting is, is sort of sparked off by an FCC requirement request. Um, don't quote me on exactly how permit it is, but you know, they want, you know, the, the ability for people to scan a QR code on a medical device, on a, on a IOT device and get the SO and the HBO and next. Um, and without going into all the details of that activity, I think that's anything to follow.
I think this year was some guidance to come out to help with that. But you are ultimately always responsible for your own security and the shared responsibility model. We're getting there, you know, really work this out.
Like the reality is that most of you out there is working, your vendors are good, your suppliers are good, your customers are good. You, you manage to figure it out all out. We're all, as we said in the beginning, we're all in this together.
Don't give or take, you know, a, a blame, just, just work it all out. But, you know, we're a long way from being able to actually see through our relationships in an a, uh, uh, in, in a fast enough cycle to use that information. So at the end of the day, yeah, Mitch, you right?
Yeah. You're responsible for your own security. I'm a simple guy.
So help me understand this. If I leased you a car and I knew that you didn't know how to drive it, and now I'm gonna charge you extra to, for services to help you to drive this car, am I not kind of setting up a, a, a, a failure by definition here? If I look at all these cloud service providers, every one of them seems to offer a value added managed security service where they manage all this stuff on your behalf.
I feel like a large percentage of that should just be baked into the actual original service and that there's a, a, a little bit of a game being played. Or am I being too cynical on this, Mitch? Well, I, I do think, you know, service providers should set their customers up for success.
You know, you can't sign up for a Google account without two factor authentication, at least pushed on you if not required. And in this day and age, I think that's the, that is a responsibility that providers have, you know, just can't say it's, they didn't have any responsibility, then there'd be no password formulation requirements. Yeah.
Enter your password. 1, 2, 3. Okay.
No, it's all up to you. You, it's your job to worry about making sure yourself, either you're secure. So what's the difference between, you know, having password standards and, uh, requiring multi-factor authentication?
Really not much in this day and age. I think a consumer might be, you know, a little put out about a, a two factor still, even they're having to do it, they do it on their phones all the time, right? And some code or a biometric.
And, uh, I think that should be a basic element of it. So I think there is a responsibility that is a, as a service provider, especially when it's something as sensitive as your data. I mean, but our data's everyone in the cloud.
So at least that's my position. I dunno, what do you, Chris, am I off base or, uh, seems to me this is pretty basic stuff. No, I, and you said that.
Well, but you know, to Mike, to your question, I think you, you have a healthy, uh, citizenism in that, you know, I, you, you can take that too far, but, you know, as long as you have teams, you know, I, I have a, you know, a healthy optimism, I tend to think that folks are doing things right. You know, when you to keep an eye on, and this is a good example because features get baked in, you know, windshield wipers or seat belts, air conditioning, you know, so you can watch as an industry develops and what are they charging extra for? That's not baked in yet.
And yes, it all gets baked in eventually. So we're where a healthy cynicism, cynicism comes in because, you know, service providers can, can, you know, make a lot on the mar to everybody, you know, selling those add-on services just a little bit longer or a little bit less, or a little bit extra than they really should buy now. Right?
So, you know, I will, I'll save my commentary on any particular cloud providers in this case or anybody else, but you, we should all keep an eye on that. You know, some things should get baked in over time, and we, and we shouldn't let, uh, momentum carry us too far. Ask what, what should be default?
All right, so then my next logical conclusion is, Mitch, do we need Ralph Nader back here to write unsafe at any speed for cloud computing? Is that what's going on with this thing? It feels like, you know, we're giving people access to these services and there's no breaks or seat belts.
Well, then we'd need a Corsair of the cloud, right? For him to write the book about problem is just too many, too many choices to pick from, though none of 'em are safe at any speed. I don't, you know, so I posted something and I'm, and I don't know if I've got flamed yet, but you know, as, as much as we talk about security and especially national security and security of our infras critical infrastructure, um, it's beside me that we don't have a, an equivalent of a Secretary of Defense, but Secretary of Cyber, uh, defense for the nation.
It is equally the battlefield, uh, of everything. And it's the subtle part of war. It's like the, it's the non declared war that we do.
So I think that's the book to write is like, where the heck is our cyber defense? It's there, but it's never above board because our news cycles are only about two hours long. So by the time we talk about, you know, the snowflake breach, as soon as we're done watching, watching Textron Gang, something else has taught happened.
And so we kind of forgot about Snowflake until, unless they pop back into the news. And so it's not, it's not top of mind of, of securing all of this because we're so used to, oh, more data got stolen, more keys got stolen, more passwords got stolen, more personal information got stolen. Okay.
Uh, nine o'clock time for a second cup of coffee. I think we're just numb to it. I think you're right.
I was just having this conversation with some of the folks who write for Security Boulevard for us, and it's starting to turn into like the local crime blotter. I'm like, there's a, there's a breach every day now somebody's involved in something or other to the point now where I was just asking the question, is this news anymore? Does anybody care if there's a breach?
I mean, Chris, what's your sense? Have we just gotten to the point now where, uh, we're just inured to the whole thing? Well, You know, I'll sort of echo my last comments, right?
You know, there's, you know, to be clear, it's all working. It's still running, you know, decades and decades, you know, now. And it generally works all the time.
So it's not as bad as we might think. However, um, it is as creaky as it looks at the same time, right? There are massive risks and we've avoided a lot of them by not doing all the wrong things until it was too late.
Right? And we can't ever forget that. And Anthony, Mitch, your, your, to your point, I agree.
I think there should be a secretary recycle or something of that level. And, and, uh, yeah, with the, you think the defense of, if it needs to be seen that way, we to explain, you know, how we got here, like in the, the US federal government is the biggest slowest entity in all human history. But it gets there usually on, in the end.
And Howard Schmidt, you know, lake grade, Howard Schmidt was, you sort the first cyber are, and we had rules like that, you know, when you get right down to exactly where that seat would be, who gets it and where the authority comes from, and so on and so forth. Yeah. That can take a while to do.
But yeah, I think, you know, I think, you know, we got a space force, which I don't really think it's necessary, but, you know, it is a new, it's a domain. You know, I can understand the argument, you know, a cyber force, you know, focusing our efforts at, you know, at in any nation in the us, uh, at that level on these issues. A hundred percent, yes.
Yeah. Or who knows, maybe the cloud service provider should get together and have a SWAT team put together to help customers go deal with these issues. And maybe it shouldn't be a, something I pay for, it should be a free service in the interest of national security.
Well, and that that's per per perfectly reasonable suggestion. And things like that having happened in the industry, you know, we, I've done that, you know, in various hats. You know, sometimes we just say, look, you know, we're, we're Cisco, right?
You know, the turn of the century. Cisco had a deposition. We did all sorts of things because, you know, they need to be done and nobody else can then do it.
Yep. And ironically, it makes people like you more, so you sell more products, you make more money anyways. So it's not a, not a terrible idea.
The government, again, is big and slow and stupid that God bless their pretty little hearts. But most of this stuff needs to be done by us in the private sector, can just choose to do so. There you go.
But, you know, hopefully it won't be us taxpayers paying for that. 'cause maybe we didn't set this issue up in the first place. I'm Mitch, speaking of making money, it seems to me that, um, lawyers are gonna be making money off of this particular incident for years to come.
I mean, let me get this straight. We can sue Ticketmaster, we can sue all the other customers of Snowflake. We could sue Snowflake itself, and we could sue the cloud service providers.
'cause they all have some sort of quote unquote shared responsibility. So, um, what are the financial implications of shared responsibility? Well, so there's a cynical answer.
Maybe it's cynical for what day is it? This is Monday, cynical Monday. Um, yeah, there, there's a, if if the financial impact were significant enough, this would happen less.
We would see it not grow as fast. The number of breaches, and I've said this for a long time, it's like, you know, until there's really, you know, think about it. If this was like SOC compliance, right?
Where the CEO had to sign off that the financials are accurate, and, uh, you know, it's, it's disclosing the right information. Uh, I don't want, I'm not saying it's the CEO's job to sign off on security, but you had, if you had something like that, I bet you a lot less, um, breaches would occur because it would get a lot less scrutiny. I just came back from, um, AWS reinforced this week.
It was really interesting to hear, uh, Chris Betts talk about their culture of security. They don't call it a security culture. They call it the culture of security.
Not sure the difference, but, um, one of the first, well the first thing he talked about is every Friday, uh, their C-E-O-C-E-O of AWS sits down and works through, talks, through, works through what the escalated security issues be are in the organization. This is, this is across all, and all of AWS not saying he solves all those problems, but they have an escalation process and anyone can escalate it. Security issue.
And, you know, I'm sure sometimes it's budget, it's sometimes it's other factors. Sometimes it's kinda holding people, you know, feet to the fire, whatever it might be. Um, at least that's what they claim.
They do that every Friday. Well, okay, that tells me, okay, it's pretty important then if the CEO's gonna take their time to re review and work through issues. Both they're informed about what's going on.
And people also know that it's an important, so I, I think it's more than just a visual, oh, that looks nice. It must be important there. I think they actually take it seriously like that.
I don't know. Here's the part that makes my head explode. So Let's say that I was leasing you a car and I leased you a car, and I knew perfectly well that you had no idea how to drive that car.
And you, and, and then you went out and caused all kinds of mayhem. So now I have a cloud service and I'm giving that to developers, and I let them provision that stuff and use that knowing perfectly well that they have no idea how to drive that cloud platform securely. And then all these bad things happen.
So, um, I feel like we gotta have a better way, Chris, but am I crazy or what? I you're right. You're, you're talking about the future, right?
You know, and the, uh, quote is always Terry prt. You know, there's an acceptable level of nemesis, you know, that we have to live with. And, and, and it's not only okay, but it's, it's desirable in some way.
You, you, you ask about, you know, is this going to be, you know, lawyer's gonna make a lot of money, not this. Oh, right. And they always will.
And as long as you know enough, but not too many lawyers are making enough, but not too much money on these issues, it'll continue to push those levers that make the CEOs make the choices. You know, you know, not as early as many of us would like, like them to, but more often than not, just barely, not too late. Mitch, last word.
If anybody, if any idiot can buy a chainsaw, then anybody can buy a cloud service. How's that? Al Monday?
That's what happens when you put me on the road too long, Mike. All right. I think we all need to take some responsibility for this and stop passing around to each other.
And to Chris's earliest point, finger pointing may not be the most useful thing here, but it does seem to me at the very least that we're all not stepping up enough here. So that's the last word there. And we'll be back in a minute to talk about our next topic.
All right folks. And we're back and we're gonna talk about a little more insanity that goes out on the land of cybersecurity. But we have this, what sounds like a positive development.
The FBI announced that they have somehow or other discovered 7,000 deen encryption keys that can be from the lock bid service folks, and they're making those available. Um, the problem seems to be that, uh, people are hesitant to call up and say, I would like those keys. 'cause they may not have reported the fact that there was a crime in the first place.
And so now they're kind of like, well, I don't want to get fined for, uh, not reporting the crime. So there's this kind of, you know, damned if I do, damned if I don't feeling out there, Chris, do we need to kind of think about this a little bit? Or is this just the fact of life that if you don't report the crime, you're gonna do the time as it were?
I don't know, honestly. Right? You know, so you, as I, as I understand the story, the FBI has decided not to, you know, they, the, they vote, release those keys, or you have to ask as opposed to just posting on the site, you know, so anybody can ly go and grab them and see if you know they work or not.
Um, I think that would be the better call. You know, so maybe, you know, we're talking about lawyers at the end of the last, uh, section. Maybe this is one of those things inside the FBI, the lawyers are saying, you know, no, we shouldn't do that because of X, Y, z.
You know, they got the information from, as I understand the ally. Uh, so maybe they can't. Uh, but if you're gonna give 'em out to anybody that asks, you know, why don't just post 'em all online, Right?
Speaking of where they got the keys, as I understand it, they got it from our, uh, British friends. So maybe they posted it already. So maybe we just gotta go look for a different website.
I don't know Mitch thoughts. I feel like I'm, uh, as I said earlier, I'm traveling a lot. I feel like I'm at the airport.
Well, the passenger who left their keys at the TSA checkpoint police return, pick up your keys. It kind of seems like that. It, it, I dunno, I I found this story a little really interesting.
Like, come and get your keys. You lost your keys. Well, if they have 'em, who else?
And they got 'em some locked, but, well, who else has 'em too, right? So that's my concern is didn't you have replaced those keys by now? Or maybe this is like ransomware and you're trying to get your stuff back or something.
It didn't quite, it didn't quite connect to me. So I, maybe one of you can explain it, but I wasn't, I don't quite get why you would want your keys back. You should have replaced them by now.
Well, yeah. It's the shared responsibility thing we're talking about in the last segment, right? You know, the, the, this is why at the end of the day, your comment, you know, Mitch, you know, is right?
Yeah. At the end of the day, you're responsible for your own security and, and always moving. And as we start talking about really sharing the responsibility, then you need to be able to, to connect all the dots.
I mean, how can you really take responsibility when you really don't know you? Because, you know, most people won't even hear about this story. You know, there's a lot of news.
This is one, you know, I, you know, for dabble, I may have been somebody who got the ransomware, but I didn't hear about the story. So I don't even know the FBI has, you know, may have the keys. I don't even know that.
And if we're really going to try, you know, on a, you know, serious level, a corporate level, a national security level, to really put together systems that are fast enough, you know, that we get work through this shared responsibility model, uh, it can't be that you hope you may have seen a reel where somebody mentioned a headline and found out that the website that you're gonna ask to be your keys back from the FBI. So again, I'm a simple guy, but it is the Federal Bureau of Investigation. So can they not figure out whose keys these are and give them to 'em?
I, I would, I I would, I I don't know. I mean, so so you think this through, you know, if the UK got them from, you know, the bad guys, then they might have not have gotten the data, you know, to tie those directly back to where they're from, though, of course the bad guys would have that data. That's the whole point.
Most of having the keys, unless, you know, there they go. That so you can, you know, blackmail people to get 'em back. Uh, yeah.
And, and, but you know, to your, to your question, if they did, I think yeah, they should just contact 'em. Why not? I guess you live in this, you live in this space, Chris, so it feels like the public private partnership around cybersecurity is, shall we say, uh, not well-defined.
So what's going on in this conversation out there? I know you talked to these guys in Washington. I mean, what's your sense of where are we and what needs to be done here to make this kind of just take the friction out of it?
I think we need to keep talking and keep trying, right? You know, the, uh, the, the public and private is always different. Now.
We pay taxes, they spend the taxes, you know, that's, you know, it doesn't matter where you start on the, your thought process, ideological spectrum and whatnot. Um, but, you know, the, the government just like companies just made of people who just do things, you know, for a living. And, uh, my experience, you know, they tend to be just like in the private sector, you know, they tend to be decent people doing the best they can.
But there's, you know, we were talking about lawyers and it's lawyers act when they get to extremes bog, but we have lots of actions before those, lots of impact before those extremes. You know, people don't like, you know, getting into situations that may lead to a lawyer someday. And, you know, so whether I'm an employee at the FBI and I say, ah, how do I handle this?
Gotta make a call. Take the safe that, um, so we handle all that friction anyways. And as I've said here, and I say frequently, some of this stuff just takes a long, long time.
You shouldn't be surprised, you know, it literally takes a decade or more to build one in the aircraft carrier. How long does it take to build one in Department of Cyber with a secretary of cyber and everything else, you know, 30, 40, 50 years? You know, these things don't happen overnight.
And, and I, I think, you know, I gave a talk to, uh, uh, on Wednesday of last week to, uh, a group, you know, in the beltway in the intelligence media and so forth, looking at it, patient integrity. And my recommendation there, I think is the, is the answer to your question, is lean into what our strength is. You know, our strength is openness and transparency and democracy of freedom of speech and open source, all these good things.
And I, I encourage in the corporate world all the time, we sort of touched on that in the last se segment, but do the right thing as a corporation, ironically, you'll just make more money, right? Because people like dealing with companies that do the right thing and as government agencies and employees, you know, work towards transparency, right? You know, there's rules.
You can basically back up any action you take in inside the government because you live it inside nothing but a policy environment. You know, just being more every take, every opportunity you can to be extremely transparent builds why you did what, what basis that was on. So there's just less mistrust.
We talked about responsibility last segment, and it does seem to me that we've been dealing with this whole ransomware and encryption stuff for, I don't know, better part of a decade it feels like. And yet we still have these issues and we are not resilient enough. I mean, at this point, are the bad guys doing things that are, you know, changing tactics and evolving in ways that we can't handle?
Or is it just kind of getting to the point where it's simple negligence? Well, I, I think it's more than just kind of security policies and filling out questionnaires, you know, getting information from our suppliers about the security and the certifications or testing that they've had and, and past and past. There's other dynamics that come to play.
So for example, in the healthcare industry where literally lives are on the line, in many cases, if, if they've been attacked ransomware, they're not able to operate. Um, it's one thing is somebody's money's locked up and you might have a financial loss. Yeah, I'm not saying it's not significant.
It's a different, you know, have people laying on the operating table. Not to be too, too dramatic, but you have people's lives. And so there, there is, in, in the, you know, hacking world in the, in the bad guy world, if you will, they know that hospitals will pay the ransom, uh, healthcare entities will pay that because they can't wait.
They can't wait to, to come back and kind of deal with it, have somebody go negotiate with them, they'll just get over it. So there are, there are places where it's not that people are more vulnerable, but they're more susceptible to the financial outcome that the bad guys are looking for. So you kind of have to look at it systemically, Mike.
'cause it's multiple factors, not just, you know, some are better at protecting themselves from ransomware. That's true, but it's more than that. Alright, Chris, you got any thoughts here on what is the definition of, you know, I'm a victim versus I just kind of simply negligent?
Well, I, I think, I think when we're in a happy place, you know, the most of this is simply negligence, right? The same reason, you know, the office, you know, with all these stories we read about, you know, a contractor building contractor negligence happens. Now, if it happens 90% of the time, then no building stand up.
If it happens 0% of the time, your control is probably too tight. Uh, so as long as our problems tend to mostly be negligence, and I think they kind of are, right? You know, as we discussed earlier, as much as we can spread the responsibility and lots of parties, you know, a fair responsibility when anything happens, uh, were you driving the car, you know, oh, I was driving the car.
It's like, yeah, I can understand how this happened. Happens all the time. But you get the ticket, you have the responsibility.
'cause yes, you could have taken the time and, you know, so as long as the incompetence level, you know, a talent for most of these problems, and it's not, you know, stopping everything, then it's not systemic. But to Mitch's point, yeah, there are a lot of systemic issues. And you know, as I concern myself about this stuff, I don't like seeing any of those stuck for a long time.
You, you see 5, 10, 15 years go by and, and a problem is still a problem. It's either acceptable or we're missing something. And we usually are.
And that's when, that's when Mike, you know, your citizenism is really involved, pointed. We need that. Someone saying that's a problem right there and make people think it.
So who's responsible for this mention? And, uh, I'll use that car metaphor. Um, if I take my car and I drive it to a disreputable part of town, and I leave the windows down and the keys in the ignition and the car gets stolen, well, it's still a crime.
It should not have been stolen. But I am, I'd be kind of stupid, wouldn't I? It's kind of back to the snowflake example, right?
Same kind of thing of, yeah, it's, is it the manager that hired somebody that didn't know what they were doing that was supposed to be, you know, performing security function at the, at the organizations we didn't know, you know, or didn't kind of have the, have the influence to be able to say, we, we really need to set up two factor authentication ourselves, or whatever it might be. It, it's a mix, right? And on the other hand, if the manufacturer's handing you a a car and you know, it, it, it basically, it basically has, uh, uh, problems with it that safety issues with it, guess what?
They have to recall it. They have to do something about that, right? When enough people have reported that it is, is an issue.
So it also happens where, you know, the providers are on aren't always gonna get it right either. So they have to be responsible and say, Hey, you know what? It's time we yet to take these measures.
We learn something from this breach, or we discovered something we have to do better in our security, or we're beefing this up, we're changing our APIs. I've had that happen a lot in the last two years of people saying, eh, we're not, not really hand comfortable handing you a key anymore or a token to use the API anymore. We're gonna have you go through this interface and then for each application you get, you know, whatever it is, certificate or maybe a maybe maybe a token or a gateway to go through to have better security.
And that's what we have to do. We all have to upgrade our security. Whether you're in the service provider world or you're in the application development world, or you're in the, uh, security organization, the CISO at, at your company.
Chris, back to the shared responsibility thing, um, I feel like we're trying to blame too much of the security folks for aberrant behavior that really belongs to the end users sometimes and probably more often where it's the end user who didn't do something or didn't follow a policy, and yet we're trying to hold the security people accountable for the end users. I guess, you know, we're entering a political season and I'm kind of like, you know, who should we be locking up here? You know, the, the, you know, I like responsibility.
I think it's liberating, right? You know, it's nice to know, okay, I'm responsible for that, right? And it's, uh, I, I think that's, uh, but, but again, you know, the shared responsibility requires ability to figure out what you're responsible for, right?
And in the, in the case of taking a security job, I mean, let's just, you know, focus in on all us people who work in security, you took the job, right? You know, and, uh, I agree. Mitch, you said a second ago, you know, someone hired you.
Now, did they hire the wrong person? Did they not resource you? Maybe however you took the job, right?
So I'm willing to, you know, and I, and security folks are, are some of the best people in the world, frankly, right? And they can take it. You know, every, every one of us knows you took the job.
I did the thing. I knew they weren't gonna pay me enough. I knew they weren't gonna get me the, the authority.
I could not take any job. Now, maybe you need the money anyway. We all make choices.
You know, responsibility has to start with the individual. And, you know, if the, you know, at the end of the day as the board and the, you know, in a corporate environment, that's it. That's where the responsibility really is.
They didn't empower or instruct or whatnot, the ceo EO and then the CEO from an operations perpe perspective, they're responsible. Period. Done.
However, don't take the bloody job if you can't get the work done. 'cause we all own a slice of it. All right?
You heard it here folks. The other side of responsibility is called accountability. And we all have to answer for it at the end of the day.
We'll be back in a minute to get into our next topic, but it's just gonna be more and more chaos. Here we are. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong research.
All right, welcome back for our third block of insanity. So we have had an acquisition in the security space. Fortinet has acquired Lacework.
Lacework is a provider of what's known as a cloud native application protection platform. A cmap, and maybe I get this wrong, but I'll let Mitch clarify, but it seemed to me the whole point of these synaps was to roll up all these tools so that I could reduce my friction and my cost so that that way I could standardize on a common platform. And we were supposed to roll up everything through the cnap, but now it turns out the CNAP providers are being acquired by other people.
So who's rolling up who here and for what purposes? Mitch, what do you think? Well, I mean, c synaps specifically to support more cloud native architecture, right?
Microservices API first kinds of applications, but they're, you know, using, obviously probably using containers, probably using Kubernetes, but not necessarily have to be. Um, and, and it's really providing you, just speaking generically about CA provid you things like, uh, API discovery, API gateways, um, authentication, ident identity management for machine, machine machine identities, things like that. So you don't want every application going off and inventing its own, you know, machine to machine identity mechanism.
Just like you wouldn't every department go create their own person identity, you know, IAM solution. So it, it, the idea is to pull that together because guess what? Every app needs that.
What's interesting about Fortinet is, you know, Fortinets pretty easy to view them as a traditional security vendor security provider. They've been around a long time. They've, you know, they're in the sim world, um, you know, doing SOAR XDR, things like that thing that traditional security people would, you know?
Yeah, yeah, that's what I know them for. Um, and now this is with this acquisition with Lacework really helps them step into the software architecture of security world. Um, that, so it's, it is, I think it's a smart purchase from that standpoint.
I'm not sure everybody living in the security world yet knows kind of cloud native and what all that means, but I'll bet they're dealing with it somewhere in their organization. They need to kind of help make that transition. I gotta believe Fortinets looking at as we can help you get there, we know how the Synap solution, Chris, I don't know if you have a thought on the actual deal, but it does seem to shine a light on this whole tool sprawl issue within cybersecurity.
And, um, frankly, I sometimes think where all these tools are resulting in us working across purposes, but I don't know, do we, do we have too many tools or not enough tools, or just not the right tools? Well, it, you know, you know, to sound like a broken record in many ways, you know, when if we have too many tools, you can't find them and literally have tools here at the right tools on hand. And there's also the other tools that get built into things.
So I have to deal with the tools myself anymore. But, but I think this one, I think that this one is interesting. It's, I see Fortinet in the role of John Deere, right?
You know, John Deere just very recently suddenly has more software than hardware engineers, right? And they make physical tractors or these sort of things. And I know I gotta get, uh, meaningly named by my Fortinet friends, but you know, coordinate, you know, sells G got, right?
Yeah. Flying us to the firewalls and yes, yes, yes. Other things.
But, you know, I think Ally put it better than I I'm about to. But, uh, they're more that traditional play and cloud native and, you know, the, the ought to use ai, what does it even mean? How we bolt all these things together.
So, you know, whether this individual deal, this merger, you know, works out well, we'll see. But I think this bolting the traditional, you know, network providers, the infrastructure providers, the Harvard providers, the security infrastructure providers, um, into players like laser were, seemed like the direction were going. And, you know, Chris, I was thinking about it some more based on what you said.
Um, and I mean this in a positive way, Ford that is kind of a modern day belt and suspenders, right? This is sassy and web application, firewall and bot protection and uh, cloud native firewalls, all that kind of stuff. So it's, you know, they're in this, they're in the modern world of, of what we think is the security protection.
And I think with, with, uh, Lacework, it kind of gets 'em into the software architecture side of this. And what really happens inside of those applications is 'cause what they look like a network, they just talk to each other over APIs. And it might be on the same cluster.
They may not be, it could be fully distributed. So it's, it, it is a logical step. Um, then I think, you know, we're in the acquisition era, right?
Cisco by Splunk, um, roll up these days. And so I think we'll see more of this kind of activity. Yeah, I think to your point, Mitch, what we're seeing is all these tools are becoming features of a larger platform.
And ultimately, I think, know, there's pressure to reduce the cost of cybersecurity. 'cause otherwise you gotta integrate all these tools and then you're basically giving yourself whiplash as you swivel from tool to tool to tool to try to figure out what's going on in the environment. And each tool is telling you something different at a different point in time.
So, I don't know, Chris, I mean, have we just gotten so tool happy that, you know, we're kind of becoming our own worst enemies? He, yeah, I guess it's probably the risk. You know, I, I literally love tools.
Well, you know, I've got, I'm always sort them and using them and categorizing that I'm in, uh, we were talking before in the green room before this. I've pulled out a bunch of gear and a hardware and associated tools from 25 years ago, you know, but they haven't taken any of my tie to your point, Mike, you know, I haven't messed with 'em, but I keep them outta hand and they're available. Um, but, uh, but you know, so as we do this a lot, and I think, I think again, we continue to build things in, you know, security products and services that were a good idea that, that were structurally significant get, and some go away because we stopped doing things the way that, you know, ended up needing to have that security feature in the first place.
You know, a lot of security is compensating controls. Like, you know, what we should do is a DC, but we're not gonna do that. So instead we'll create this market segment and we'll stick this thing in there.
And, you know, if you're the vendor, then you can make money. Or if you're the consumer, you can solve that, which you, we can tell it fit and then that, you know, so there shouldn't be any, there's not an infinite number two, those are actual screw drivers, right? Some tools are just always tools.
Other tools are fans and fade away over time. Yeah. Vince, we have this notion in the land of DevOps called platform engineering, right?
We're trying to figure out how to run processes at scale. Do we need to have, you know, platform engineering extended out to cybersecurity and do we call it platform security engineering? I don't know, but Well, um, you know, the function of platform engineering versus platforms, right?
Kind of two interconnected topics. Platform engineering can be more about, you know, the setting up of standard environments, whether they be security, right? I mean, yeah, there's security patterns and templates and things that we can do.
And matter of fact, a lot of platform engineering groups are about improving the security of the images, the base images that they're, that they're constructing their templates and their configurations out. It's also about how to keep that up to date. I think the other side of platform though is whether you're one company acquiring the company, bc, D, e, and F, you don't want to be, uh, you know, like this loose collection of we're we're just making it easier to order off one price sheet.
And that's kind of what our integration strategy is. That's not, not so helpful as it is in, in today's world. You have to be able to see data across all of these TA tools and then understand the context of it so you know, action to take.
And there may be workflow that crosses all that. And I think in a security context, that is what a platform is about. So when someone acquires another company, there are integrations that they can make.
That's all good. Well, what about the data layer? Think about, um, thinking about having the data platform across all of those security tools that they're providing you or plugging into other things like, you know, observability platforms and hotel and things like that.
In, in today's world, things happen too fast to do very much manually and at least keep pace with what's happening manually. And we can not only automate, but we can, uh, make our lives easier to get access and understand and then use data across security domains and tools. And by the way, application security, right?
Cloud security provider, all that stuff, I think that's the key to keeping pace, at least Chris, the part of this that as makes my head explode, there's many things that do lately, but we've been saying that, um, there's a shortage of security professionals forever and ever and ever. So who's, who's using all these tools, but we don't have enough people to give the tools to. So who's figuring out how to use all these tools?
Uh, yeah, the, the, the Institute of Shelfware is a thing, right? You know, a lot of things get bought, you know, you know, as a vendor, you, you run into this, I'm really happy someone above my thing, and then you can's say, oh, I to find out what you did with it about nothing. Right?
You know, so that's an actual thing, right? Mean as they, oh, pine the minute ignore. I think we gotta be careful.
You gotta just, you know, we're enthusiastic about the acknowledging we're gonna do the stuff we're, you know, don't acquire more tools and more things you can actually bloody use. Uh, use the ones you have as much as as much, you know, their best effect. And, uh, and, and they think back on, you know, the old tool, you know, a lot, a lot of times, you know, new problems actually work well with existing technique.
So I think it's, yeah, there's certain serious, you know, that's an intrinsic risk of, of free. I don't know. I know.
I, I don't think we're any worse. Well, yes, we are worse now than we have been because we have more choice to, but I don't think the problems me worse. It always been, it's not a matter about how many tools we have or how many people we have.
Is are we doing this effectively for the right reasons with the right authorities? And that has a done what? I don't know, Mitch, I can, I can get a little paranoid sometimes, but have we allowed a cybersecurity industrial complex to evolve here where there's just this massive amount of money and infrastructure all chasing, you know, all these threats without actually maybe solving the problem?
I feel like I just watched a World War post World War ii, Eisen, president Eisenhower, you know, we careful of the, of the industrial military, industrial complex. Um, it, it's easy, lemme say it this way. It, it is easy to, to become, have, have a mindset where we think the tool is the solution.
And, you know, have, how many times do you maybe walk into somebody's garage and they got a wall full of tools and, and you say, let's go work on this. They grab, you know, three things that they take out to go work on something. Start with that.
There's like a quarter of 30 things that I need to do. 80% of the jobs and all the other stuff are sort of those fancy situations. Or maybe they're shelfware, maybe I use them too.
It's kind of the same thing in, in security, right? I mean, you, we removed from a checkbox mentality of network security. Well, okay, I got my firewall, I got my prevention, I got my web application firewall, I got my content, uh, my data protection, whatever it might be.
So I've got every one of those pizza box in the rack, so I'm good, right? And I, and I'm being over simplistic, of course, but you, you can't take that sort of checkbox mentality because what it's all about today is how you as operations, it's all about the soc. It's all about the in security incident, uh, teams and how they respond.
Um, and of course, compliance and having data to verify, say you say you're doing this and how can you demonstrate that you are so, it, it's a complex world. Um, so I think you're, you're better off to use fewer tools really well than a lot of tools. Not very well can be general about it.
I mean, hopefully that that's more than common sense, but sometimes common sense isn't too common. This is true. Chris, what's your take on ai?
And I'm asking this question because is that not an opportunity to kind of flatten this whole infrastructure and maybe we'll have a common data pool that we're running algorithms against and we can have a common view of the events. I mean, are, are we on the cusp of maybe changing this because AI will force the issue, or is that just one more tool added to the pack and it is what it is? You know, the, the fact that you of all people when asked that question right now, uh, makes me think that maybe we kind of are right.
You know, I I I'm very hesitant to, to wax too poetic about all the promises of AI in, in the, in the short term. 'cause it seems everybody's doing that and it kind of seems true, right? You know, all of the, we're talking about, you know, time to visit, you know, time to transparency and sort of each of these segment segments today on the show.
And, you know, the reality is if you have to have a staff of 10, 12, 10,000, 12,000, you know, know people reading things to actually get, you know, far up longing in time to, to achieve with some goal, you're not gonna do that or almost ever gonna do that. That's the kind of stuff this large language model, you know, wave of, of psychology is bringing and just in the security space, yeah, whether I can just look just looking at supply chain, just being able to put all the pieces together in time to do something about it. Not post catastrophe, not, you know, you know, in some catastrophic, you know, year and a half in the, in the courtroom with boxes of records telling.
But like right now, how do we put all of this stuff together? Um, what we are calling a ai, AI right now has amazing potential in that space, right? And on both sides, you know, studies, you know, already on, on the negative, you know, the negative security effect of ai, you know, AI in the same tools, in the, in the hands of people, you know, we're not in favor of.
Um, I, I think this is a demand of defendants because we, we have the ability to put things together, put visibility, uh, together to put situational awareness together so much faster in ways that aren't really revolutionary than we would just do if we just had a lot of people. But you don't need a lot of people. There you go.
Hey folks, we're coming to the end of the show show, but I think the definition of insanity is banging your head against the wall and expecting a different outcome then well, welcome to cybersecurity. So I'm hoping things get better, but um, right now I gotta say it from the outside, it doesn't look too good. Just we're a helmet of it, Mike.
We're out. Anyway, thanks everybody for watching the latest episode. The rest of the tech strong TV lineup is coming up right behind us.
By all means, stay tuned and thanks for watching.