Techstrong Gang – March 5, 2024
Alan, Mike, Mitch, Amanda and Chris Blask unravel the cybersecurity challenges GitHub is encountering as malicious forks of codebases continue to proliferate across its open repository. At the same, the gang dives into the challenges organizations are facing as they look to secure artificial intelligence (AI) models. Finally, the economics of cybersecurity are becoming more complex as costs increase in an era where business leaders are asking harder questions about justifying return on investments.
Transcript
Hey, everyone. Welcome with Cybersecurity Tuesday here on Textron Gang. We've got a lot of cyber news to talk to you about today.
What's going on at GitHub? What's happening with AI security? How are we going to get more security budget, maybe by moving security ops, combining it with, uh, it ops that and more here, live on Textron Gang.
Okay. Welcome back here to Text Junk Gang. Thanks for joining us today.
As usual, we have a, a great gang of, uh, folks who are going to weigh in on the topics of the day here at, as I said earlier, cybersecurity Tuesday. Let me introduce you to who we have, first of all, as always, joining us from Colorado Techstrong CTO and Principal Techstrong Research, uh, analyst, Mitch Ashley. Mitch, welcome.
Good day security. Tuesday is always a good day. Yep.
And, uh, joining Mitch is our editor for Techstrong ai, as well as digital CXO and all around coverage. Uh, Amanda Rini. Amanda, welcome.
Hello. And then we have a very special guest gang member today. It's the first time he's been on the gang, but it won't be the last we hope coming to you live from his twains.
He'll tell you about that. Chris Blast. Hey, Chris, welcome.
Thanks for having me. Good to see you guys. Nice to have you.
And then last but not least I, because I'm kicking it over to him, uh, our Chief Content Officer here at Techstrong. Hey, Everybody, Mike Ard. Mike, what do we got for today?
All right, well, Let's just jump in. And since you know, it's Chris's first time, we're just gonna kick it right to him from the get go. Um, there's just a massive amount of noise on the cybersecurity front related to this GitHub issue where I guess the bad guys are cloning and forking different repositories, injecting malware type of squatting, and doing all the things that bad guys do.
But is this spinning outta control? Chris, what's your thought? Well, in short, no.
Right. You know, as, as Alan knows, you know, I have this sort of inevitability curve as a term I have for a view of things, and things happen at a certain time for reasons. Right?
And the, the, uh, uh, article that, uh, Richie Jennings broke on Security Boulevard about this on February 29th, and the fasting, the timing of this, the csa, the DHS, uh, uh, I dunno if I'm need to spell out all the acronyms. Most of our viewers know who CISA is had on Feb on the same day on February 29th. And sbo, Orama and Ian.
So Ra and I have been co-chairing one of the working groups. So we're all presenting out and having conversations on that same day about these issues. So when you peer into the details of this, we have now some provenance and, you know, inventory information with software bill materials that over the last five years has been enacted, developed, you know, companies are using and moving around.
And the space that, uh, ish and I and our working group has been focusing on is bound sharing. And this forks, forks, forks all the way down, right? You know, turtles all the way down.
You know, we're at the stage now where we can say one-to-one, here's what's in my software. And we're doing that pretty good. Big companies are doing it, governments are doing it.
But in something like GitHub, where, you know, to this point, there's lots of little pieces. How do we tie them all together? And we're at the same time on February 29th, you know, last week at the point of having serious conversations with serious components of how we actually do that.
So I think this is just yet another example of, you know, the, the adversaries, you know, attackers from a security perspective, taking advantage of something just slightly before the defenders have geared up the components to fix it. So Are these, and they're forcing us to do it because we have to, you know, 10 years ago we didn't have to do this, but 10 years from now, we're going to be doing this. So you're not saying that this is your fault 'cause you had a meeting and now all this stuff is happening because of you guys.
Mere coincidence. Mere coincidence. I'm coincide.
I'm, I'm in the bad in the back of a lot of weird pictures over the, the industry, but no, but it's just time. Mm-Hmm. It's time for these issues.
You know, like, you know, in the ICS world, in the OT world, right? You know, in critical infrastructure, we all think about, uh, uh, you know, the stucks nut attack and the tan and everything else. And a the same sort of question from a, the press journalist at the time, you know, it's like, this is just time.
Is someone going to be using cyber means to attack critical infrastructures? At some point you have a geopolitical event, you know, have some actors play that out. Someone's going to be used using these vulnerabilities have been latent, but too hard to use to date.
But if you can start using 'em, you get an advantage. So, and it's always around the same time, the defenders and the, you know, the people building the systems have been chewing on these things and start coming up with solutions. So it's just a forcing function to make us implement the real end, end supply chain and threat intelligence, visibility.
All this intelligence sharing stuff over the next decade is gonna weave together. I, what I thought was in, I'm sorry, go ahead, Mitch. No, I was just gonna say it, it seems like the, there's two sides of this coin, or the story is, the part you're talking about is how we secure the repositories and we know, you know, what are valid, uh, repositories for project, but there's also sort of human element.
It's kinda like phishing for code, right? And it's like, I, if you just get enough people to pick the wrong thing and you missed, missed something, it's that 1% rule or one time rule. But it seems like that that whole, through the obscurity of so many things, this is up now, it's gone.
And which one do I pick? It really brings into question, how would you know? Well, you know, it's, it's, it's easy to predict things.
We all do that and say, Hey, I thought of that first. But it's all about timing. You know, that's when it really matters.
You know, are we in the window that matters in the next 1236 months over the next, you know, 3, 5, 7 years, I'm gonna have to deal with something. And if not, don't start. And if so, then look around and see if it's happening everywhere.
And one of the supply chain use cases, I love the best with working with the, the, uh, Scottish National manufacturing, uh, uh, institute at a use case where you basically have a, an airframe, uh, manufacturer, you know, Boeing, you know, was working with them, uh, public information, Boeing, Boeing, and Rolls Royce. And you say that I'm a flight engineer in some Air Force somewhere, and I wanna know what software was running on the radio plasma forged and made this one blade. And I wanna know right now, you know, we know how you can do that.
And it's the same sort of systems and literally the same things that we're building in the SBO world right now. So it's not just because of security, you know, to the points later in, in the episode, it's when you know it's better, faster, cheaper, right? You know, if you don't get on the internet and get a firewall in 99, your competitors will, and they'll lower their costs and put you outta business.
That's what drives security adoption. So to me though, specifically on this GitHub issue, here's something unique. The bad guys use the very model that's made GitHub successful to their advantage, which is the openness of GitHub.
Anybody could open an account. Anybody could fork open source software. Anybody can put stuff up there.
Anybody can pick a name that sounds a little similar to a name of a legitimate repo or a legitimate, uh, code component or what have you. It remind, and, and if you speak to GitHub, they're, I mean, obviously they don't want this to happen, but they don't want to close off that openness either. Mitchell, I'm reminded when you and I went to go meet with US geological survey, remember back in the day, it's still secure.
These people have, you know, earthquake sensors all over the bottom of the ocean to the top of Mount Himalaya, right? And everything in between. And we said, Hey, you gotta secure these things.
They said, oh, no, we can't. We're scientists. These things have to be open because the world needs to be able to monitor seismic activity, but someone's going to use it for a bad intent, so be it.
But we need to keep these things open, right? The problem I think we're gonna have here with GitHub is can they put in some automated check to verify the, the identity of the people putting this up, which goes kind of against their kind of principles anyway, and to verify that in fact, it's not malware. It, it's a hard, thorny issue.
I would go another step. I mean, there are other places to put code repositories together. So maybe you don't put everything in GitHub because it's just too big a target maybe.
And especially if it's critical IP to you, maybe you find somewhere else to put that, Mitch, I don't know what you think, You know, it, it all goes to don't trust anything and don't pull things directly from MPM or, or whatever, uh, you know, pipe I or or GitHub directly is. Pull those down, validate that it's what you think it is, and then distribute it into your workflow, into your pipeline. So it, it goes right to that kind of zero trust approach where we just have to assume anything could have gotten compromised right now until there's a better way to, to know what's authentic and what's not.
Just another reason why we can't have nice things. There you go. So, so, so Chris, to that point of that, Mitch is making about distrust and verify.
Why don't we distrust and verify more? Well, you know, time to transparency end ends up being key, right? You know, and the example I, I gave a second ago about the, you know, uh, turbine blades that information's, uh, around, we can find that out, you know, if there was a crash investigation, we'd all watch on, on over periods of months and quarters and years as that information is found in display.
But it just takes too long to get and, you know, to to this issue. You know, Alan, you're exactly right. You know, there's very old standing issues that we've been able to get around, you know, and I think the, uh, the, what's going on in supply chain security, you know, my main interest in it is we're enunciating existing relationships so that we can say, not that everybody needs to get this information, but everyone appropriate needs to get this information.
And what does that mean? Well look at how we live our daily lives. You know, intellectual property control, you know, in threat intelligence and supply chain intelligence.
Same concerns come up and you look at corporations, your, or governments. And how are you controlling your intellectual property today? Mostly hope.
Mm-Hmm. Right? You've got some contracts and policies, and you hope your employees kind of know what they mean and don't say the wrong thing.
So we're, it's not that we need to get perfect, but we're at the point now, and this GitHub thing is a perfect example where we need the appropriate time to transparency. So all these questions could be answered by somebody actually doing something and not in some forensic investigation. 'cause the information's there.
Yeah. I just wanna say one last thing before we close out on this. And that is, look, it is not to shoot arrows at GitHub.
They didn't do anything particularly wrong. Yeah. We said we had a similar situation on a smaller scale on Docker hub a couple years ago where people were putting up docker, you know, pre-configured dock or pre-populated docker containers, very similar names to legitimate containers, you know, for like building block kind of code stuff.
And people didn't know, and they don't look and they don't see where the period is, or the apostrophe or, you know, it's a one letter off, especially if it's English as a second language. And boom, you, you download some malicious container into your infrastructure. So this is, this is not just a GitHub thing.
I think it goes to all repos. I think if it's shared, it's suspicious. Right?
There you go. Fair. That is that the bizarre doctrine.
There you go. If it's shared, it's suspicious. Okay.
Caveat, right? Yep. Hey, um, you know what, maybe we'll take, we, we're gonna come back and we're gonna switch gears into AI security, if that's all right.
We'll be back here in just a second. All right. And we're back.
And we're gonna start talking about AI and security and the lack thereof. And I guess I'm gonna jump this right over to Amanda who hasn't had a chance to jump in just yet. But since you're covering Techron AI for us, are we taking security seriously enough in the land of ai?
Or is this just another instance where we're playing catchup? Well, I think as more and more AI is being utilized and, uh, large language models, uh, there's just more that has to be addressed and more, um, opportunity for threat actors to attack. So we have to be ever vigilant.
Um, which brings us, uh, to a recent story I posted about, um, uh, hugging face and some attacks that they've endured. There was a, um, some research done with Jfr that found there was a hundred issues of malicious, um, uh, models in hugging face platform. So, um, that's, that's concerning because, um, you know, in one way you think, well, they have over 300,000, um, large language models that they catalog.
So a hundred, but a hundred is a very, I mean, when you think about the attacks that can come from, um, executing malicious code just through those a hundred attacks, it could be severe. So, Chris timing, huh? Right.
Yeah. So, you know, I I I tend to look at the opportunities for, you know, we're, you know, we're security folks. We can look at a new tech, like, you know, what we call AI these days and how can you, you know, use that to cause problems.
But in, in just the supply chain folk, uh, space that I've been spending all my time in, I look at this, again, time to transparency. Like I was saying earlier, if you can see the policies across a supply chain, for example, you know, then you could make choices about what information you're sharing and, you know, uh, yeah. To point made earlier, you know, is, is shared suspicious today kind of Yes.
You know, why are you doing it? 'cause I can't see, so I see AI as a huge part of this. You know, again, 3, 5, 7 years out, we get a little, little more maturity in understanding your policy position.
So, you know, whether it's the previous topic, you know, with, with supply chain tax, and be able to see down on that. Without that, it just takes too much time. So we don't implement it in our, in our processes.
We can't use it for security purposes. Um, will security get hacked and, you know, steal our kidneys? Yeah, probably that Too.
That's scary. It seems to what you were saying before too about, um, you know, we, we haven't had to deal with it until now, right? I mean, this is sort of the moth to the flame story.
ai, generative ai, poof. Everybody needs to be doing it. Let's rush and go and figure out how we can leverage this and exploit it.
Well, good. Well, while they're doing that, all those things we haven't done yet. All, you know, there's been some things, but maybe not all the things that we need to do.
It just, it's, it's an opportunity right now given how much prevalence people are, uh, adopting it and using it. I think there's three things to this, and we're only focused on the one. The first one is the one we know and have always dealt with, which is we are have software components that have malware injected into them, and then they wind up being used to build the AI model.
And it's not much different than what we see with other software artifacts. The two aspects we're not thinking through enough is a, the bad guys wanna poison the data model itself by putting bad data into it so that it comes up with a hallucination. And then the third is, the model itself is probably among the most important intellectual property any company has.
And the bad guys want to steal the entire model. They, so we haven't sat down to figure out how we're going to secure the model itself. So, I don't know, Chris, if you, um, how much of that is the cybersecurity responsibility?
How much of that is the responsibility of the ML ops people who are building the models? And are we just having the same DevSecOps conversation we had for with ML SecOps? Is that what we're calling it?
Well, yeah. A couple slices on that, you know, working backwards, yes. It's the same argument we've always been having.
And, uh, you know, and we are the responsible parties 'cause nobody else is actually tasked with, you know, worrying about cybersecurity. And, you know, if you job is to run the network, you know, then you'll get fired if you don't run the network and if you spend too much, you know, so, so we're, we're in the hot seat on this one, and it's the, but I, but I see multiple things coming together. Again, you know, we're, we're not just trying to convince people to get a firewall and close the door and so forth.
We're three, four generations iteration into this whole cybersecurity thing. Right. You know, we have CISOs that are actually CISOs these days.
I was a little skeptical they ever would be. Right. They were a fusible link for a decade or two there.
Right. You know, just somebody the board could, you know, throw under, under a bus. Um, but we're getting to the points and, you know, the, the, the, you know, again, I think, you know, each of these things has risk.
There's no guaranteed positive outcome of all this. Um, but I can't see us now even with, I think ai, what we're calling AI right now is still very, very immature. But the things you can do with it that just took too much bloody time before, give us so much opportunity to clean up so many messes, you know, you know, uh, attestations, right?
You know, so much of what we're talking about right now is because we don't really have any real reason to believe anything we see. You know? And we mostly trust it 'cause we kind of know where it's coming from and maybe we, you know, in some cases can put, you know, cryptographic key exchange to really, you know, have a pretty decent idea that it really is you saying it.
Um, but we're getting to the state where we have to be able to say very, very clearly, and we have the tools to do this. We just haven't had the time. So all this AI stuff, you know, if it doesn't go Skynet on us, allows us to actually, as Pollyanna as this sounds, do a lot of the stuff we all have been complaining about for 30, in some cases, 40 and 50 years.
Yep. Actually, you know, A it seems like it's, uh, the who, you know, new boss, same as the old boss. Mm-Hmm.
We're talking about repositories and Little Pete Town said A little windmill going on. Mm-Hmm. Hey, Well, Amanda, let me ask you something here.
To the people who build these AI models, the data scientists and the folks that you kind of engage with are, do they think about cybersecurity? Can they spell cybersecurity? 'cause it seems like they're even worse off than developers used to be in terms of how much attention they're paying to this.
Yeah, I think there's, um, there's so much going on, um, that they really need to slow down and try to collaborate a little bit more. There's a lot of work needed in breaking down the silos and communicating across departments with a lot more focus on cyber issues. I think if we wait for them to slow down, we're gonna be waiting a long time.
Mm-Hmm. Because they're not slowing down. We gotta keep up.
And, and that fundamentally is, I think one of the lessons I've learned in 25 years plus of security, which is they ain't slowing down. You gotta get on that moving train. Right?
And that's our job is to keep, keep that train moving. But we gotta hop on. I I, I will tell you though, you know, I'm reminded of a, an interview I did maybe 15, 17 years ago at the time I had the CEO of MongoDB and the CEO of Couchbased db, right?
These are no SQL databases. And I asked them a very similar que you said that it triggered my thought. I said, there's no sql Stanford, no security, because it doesn't seem like you guys have any security built into this stuff.
And they both agreed, and they said, Alan, when our customers demand security, we'll give them security right now. They're not demanding security. They want to be able to just take in data in an unstructured NoSQL manner.
When AI consumers demand security, the AI providers will build in security. You know, as Chris said at the beginning of the show, it's full circle. It's all about timing.
It's all about, you know, you can't make wine before. It's time when, when people demand security in AI will have security in ai. Not, not a moment before.
Mitch. What happens though, when we've seen this with DevSecOps, right? Theoretically, we're shifting left, we're shifting, right?
We're all gonna have a kumbaya moment here and fix all this stuff. It seems like what really happens is because nobody's in charge, nothing happens, right? Well, and it's not an issue till it's an issue.
Right? And, and then people will do something about it. Right?
Now we, we need to do it because we need to not 'cause we have to. So there's sort of that burning platform, change management paradigm, right? Until your, your platform's on fire, you've gotta jump.
There's certainly a bit of that. And that ties to what Alan's saying about, you know, when, when the customer, or when the market, when money is on the line, that's when it makes a difference. Uh, I think the one thing I would say that, um, I kind of hope for optimism is hopefully we can take all of our DevSecOps learning of security, working with software folks and figuring out that the motion have of how we break down silos and, and, and get more effective software security working on software, supply chain, et cetera.
We need, we take those same lessons and apply it to ai. It's, it's, it's a different technology, but it's the same problem. So there's many things I think that are applicable to that.
So let's be smart and leverage what we've already learned. Chris, you got are, are you sharing that hope, that optimism here? Where are you?
Yeah, I, I am, I am, you know, notoriously optimistic and so far I've been right. You know, you know, I'm, you know, pushing 60 years old. I've lived through the end of the world all over, you know, over and over again.
Right. And we keep solving problems by the time we need to. And this is, this is one of these things, you know, we look at, you know, everything we've said in all of our careers, however long been been at this is true, but it's now the time.
You know, Alan mentioned these boats, right? You know, I've been building, you know, boats on the water, solar powered for the last two years. And I'll tell you if things get done when they need to get done, not before, right.
And the yeah. As we'll talk about it in the next segment, you know, the economics of things, you know, hacking means, hacking is not engineering. Hacking is looking at some system and saying, how does that work?
How can I change that? You know, engineering is starting with some premise and, and developing something. So when you look at all of this from a hacking perspective, I continue to see throughout my career the opportunities to fix problems just about the time they sink the boat.
Mm-Hmm. Because we don't like boats sinking, and it's expensive. So we tend to feel that by them.
I have noticed that security people are perhaps over optimistic. And despite all The really, I always think they're pessimists. I, you know, most security people are just there.
You haven't been in sales, have you? Every, every one of them seems to say, yes, we can. It's bob the builder moment until it happens.
And then we can't, You know what, there was a captain on a, a cruise ship who said we could get around that iceberg. Not to worry. Every once in a while the iceberg wins.
Well, the the, yeah, the difference though is whether you're talking shipping or one boat, you know, boats, wills, sink, you know, you know, hackers will, you know, the attackers will sometimes wing things will get compromised even when we do everything right. You know? Mm-Hmm.
So that's one of the wonderful things about, you know, being a professional in a, in an area as opposed to going out on a boat once and, and having a sink on you Right. You, you can look at what you do next time, right? And that's that iterative process.
And we get forced in these situations, you know, where a lot of people get to say, you know, I was telling you all along and now's your time. You know, so raise that flag. I actually think the most security people are cynical and pessimistic, but yeah, you can discuss that more.
Yep. So, so He's been hanging around the people who give do interviews with you. There you go.
Amanda. Amanda, last word on this here, because, you know, we're having a debate. Is this, you know, a Titanic kind of issue?
Or is this like, you know, the skipper and Gilligan and a three hour cruise and we lost a boat and nobody knows they're gone. It's funny you say that. I'm rewatching that whole, um, that whole show right now, but no, I, I don't think it's, no, it's not a titanic situation.
Um, they, they've just gotta hustle and keep up as the, I mean, this is such a, a fast evolving technology, so just being ever vigilant and doing just enough to keep, you know, that value stream flowing, um, efficiently and effectively and dealing with situations as the customer says, as Alan mentioned. So can we call this lean AI security? I, I think once again, we're at just in time.
We're at that point once again where the price of freedom is internal vigilance. So there you go. Yeah.
Internal vigilance. I love when you bring a little history in there, Mike. All right.
Hey, let's take a break. We're gonna move into block three. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. All right, welcome back.
Continuing our cybersecurity conversation. We're gonna talk about economics and the cost thereof, because well, everybody's getting beat up about the cost of cybersecurity these days. We had a post on Security Boulevard talking about where the initial ransom demand is now exceeded $600,000.
Barracuda Networks had a report out talking about the cost of cybersecurity is surprise, surprise keeps going up, and we don't know how to get our arms and how to control that. You've been having this conversation for years. What's your take?
So my take is, is something, you know, we were talking about in the previous block. Most every cybersecurity person I ever know is always woe is me. How come I can't get more budget?
Right? Because there's never enough budget for the next shiny trinket to stop the ransomware, pay the ransomware, get the new dude dad, train the people on the old dude, dad, or what, what have you. But here's an interesting thing I've learned about cybersecurity or security.
We didn't call it cyber the whole darn time. I've been doing this for some reason, every little leprechaun in the cybersecurity world is always looking to steal someone else's pot of G, right? It used to be we're doing network security because, you know, those network guys, they have like unlimited budget.
They're buying all these boxes and switches and routers and juniper devices, and we wanted to be more on network security so we could break into that network bid budget when DevSecOps started coming, you know, I remember security people telling me, you know, the best thing about DevSecOps, we get to approve the security, but it comes outta the developer's budgets. Those guys have unlimited budgets. Here's the, here's the message.
No one has unlimited budgets. Security has a damn good budget. And even in, you know, I know there was an article, or last week or so, there were a bunch of stories about, you know, I think it was Palo Alto said, well, you know, spending cycles and security are slowing down.
People want to know, should we keep spending the money when we don't seem to be thwarting the bad guys? Well, the nature of securities, you don't know. It's hard to measure what didn't happen, right?
I didn't get attacked today, or I wasn't the victim of a breach today, right? How do you put a dollar on that? But that's the, that's always been, that's the truth of cybersecurity budgets, Chris.
I think he's saying that cybersecurity people are the folks who come to dinner and never pick up the check. So what's up with that? Honestly, you know, anybody that knows me knows this.
You know, this is one of my biggest beefs, you know, I pick on our friends and our peers all the time, you know, security people, you know, have a, have this hard time with economics. And look, if you, if you're an engineer, you're an engineer and sit down and you, maybe you don't like people in a and economics, but if you're a hacker and you can look at a system, it may be electronic, it may be financial, it may be human, right? And if you can't look at that system and say, how does this work?
And I, and if I want, for example, to get security installed, then someone's gotta pay someone something for it. Where does the money come from? What's their motivation?
What are they doing? It's the same exact thing as figuring out how to get through a password protected, yada yada gadget, right? So this should be in our space.
I really, you know, if you're out there in the world, you consider yourself a hacker, stop complaining about the economics, hack it and figure out who's gonna, you know, be more comfortable in their job. Who's gonna get a raise because they made the right choice to spend the money on you or your friend, or your pet project or whatever it is. And stop just complaining about it, you know, hack the bloody system.
All Right. I wanna run a clip here though, where we did an interview with the CSO for HubSpot, and he was talking about how he justified something. In this case, it was, um, name tag has a thing where you can take your driver's license and it runs your image and your face scan and correlates who you are.
And he said he bought this thing to increase security, but he justified it because it was reducing, um, calls to the help desk, which was on the IT operations side of the house. And so he had a reasonable, shall we say, finance team that would look at the total cost of that and do an analysis based on that. So Mitch, how often are we kinda stuck in a situation where, um, we're trying to cost justify something solely on the cybersecurity merits and not the merits to the whole organization?
Well, I, one things you said in that lead up to that question was working with finance people who can put together kind of the whole picture. To, to Chris's point earlier, most security people are not great financial wizards. Maybe you don't know how to put a total cost to ownership or return on investment beyond outside of the scope of what they work.
So I think that that's an extremely good idea. Um, one of the dirty little secret about corporate budgets in big company is, is nobody has enough budget. It's not just security people.
I've never been to a meeting where somebody said, we have way too much money in our budget. Would you guys take some of this and do do something better with it than we can? Never happens?
Yeah. What you do is you get on board with what the current, uh, corporate, uh, activity or project or mantra is. If it's modernization, well great, that's some modernized security, and then do this and try to go, you know, opium other people's money, right?
You go, go get some budget from other things. So there are ways that you can add to what you're doing, but it's, I'm also always suspicious of it. It's not just the next tool and the next technology that solves all your problems.
It's never that, right? That's just one element of what you've got to do. Maybe, maybe your response is what's gotta be beefed up?
Maybe you're, um, working with, uh, the people, people who are making decisions about what we invest in for technology. Maybe that's what needs help. So it's not a singular, let's go buy more stuff.
All right, let's Run as much as I like stuff, Ask Allen, let's run, let's run that clip right now for a minute. We see people are more sensitive the cost than ever when it comes to cybersecurity. And a lot of business execs are asking questions like, we've been investing in this for years, and are we any more secure?
But how do I make the financial case? Great, great question. The primary reason we implemented Nametag was actually to offset the existing support costs that we had either in our support organization or in our IT organization.
Your support organization is already fielding these requests, whether it's a password for, you know, password reset or a MFA reset, they're already feeling those. And this actually decreases the cost of it. So I actually think one of the great pieces here is you can actually really look at this as a cost savings mechanism, not a cost expansion.
All right, Chris, what's your sense? Do we need new technologies like the one that's just described where we're kinda using, uh, facial recognition and multifactor authentication? Or is this just another example of what Alan started out talking about where, hey, we got more toys and we need to buy 'em.
Yeah, and the, the short answer, I hate to be Pat is maybe right? Mm-Hmm. It depends who are you, what are your, what's your risks?
What are your goals and everything else, right? You know, and and again, the topic of this, of this thread, those answers fall inside. Look, you know, maybe you can be successful selling something like that and have a business 'cause there's enough people who will buy it.
Or maybe it's time for that technology to be broadly adopted. And those are the things that interest me, you know, because that's when the economics line up when it makes sense. It's not just, there may be some business advantage to spending that or some security advantage or whatever, but, you know, I have 20, almost 25-year-old slides on every device I've had, you know, written by the great Stuart Phillips back when we, I met him.
We were both at Cisco and we took a end of life product that picks firewall and, and turn it into 3 billion, you know, plus, uh, in revenue by saying, if you don't get a firewall and get on the internet, your competitors will and they'll lower their CR costs and increase their productivity and, you know, put you outta business. So you need to buy our firewall because, you know, in our case we were Cisco and it's a good, you know, decent firewall and completely stopped at that point, what the company had been doing, which is our features, our security features are so much better than somebody else's security features. Now we took security really seriously.
I'm proud of that team, proud to be part of it. We did great work, but we understood why people bought firewalls and it was firewall buying time at that point. So as professionals, you know, beyond what company we, or vendor or whatnot we may be working with or technology we're concerned with at a time over the long term, we need to be able to recognize those economic drivers.
Now is the opportunity to get a lot of security in because it lowers your costs. It, you know, increases your customer satisfaction or whatever it is that takes two companies and makes one that adopted your, whatever it is, be more profitable and outcompete and buy off the other one and change the one who wouldn't do the right thing in the first place because they can't afford to anymore. So you alluded to this and I'd like to get Mitch's opinion, but how much of this is a problem too, because we don't have enough cybersecurity people that I don't have anybody to run these tools.
So even if I knew what they did and how cool they are, I might not have the personnel to go actually implement these things. And maybe that's why everybody just keeps spending money on firewalls. 'cause that's what they know how to run.
Mitch, what do you think? Well, I heard the, uh, former CISO at, uh, no longer at TWI at Twitter no longer called Twitter. Say, I don't, I don't buy any technology that's will require me to hire more people if I already have more things to do than I've got people to do them.
So adding more tools or technology that send more alerts that more people have to respond to or whatever the issue is. So that's part of that holistic picture of it isn't just about the technology. How do you operationalize it?
Um, uh, is existing staff, what do you do to train them and what do they need to in their hands to be able to be effective at using it? So you can't look at it as just a shiny object if somebody's gotta fly that shiny object and somebody's gotta maintain it. So I think that's, you know, the, the leaders look at that full picture.
You'll never gonna have enough security people, there'll never be enough security people to hire just to sort of a truism at least as far as our, our outlook can see. So what do you do when you can't hire enough security to people? You take the things that are take consuming time and you figure out either can you not do that anymore or can you automate it or can you do something else?
And then maybe that's what one of these new tools or technologies can do. So I think you have to, you're just pretty pragmatic about it, not, and let the enthusiasm be there, but don't know overwhelm some good logic. I'm, I'm a history re logic there.
That One's gonna disagree with No, I don't, don't necessarily disagree. What do you, but I love a good history reference. Go ahead.
Is The, is the cybersecurity industrial complex outta control? Yeah. Yeah, it's, it.
Okay. Does anyone know the movie for what, what was It's, it's Eisenhower's, uh, speech. Yeah.
When he remember it, I, I know, but there was also a movie. What movie was it? Where he met with the guy who was, you know, a mole within the, the, in the military industrial complex that was driving the Cold War.
Um, but you, you know, to your point, Mitch, I, I'm reminded, you know, again, what Chris said earlier and, and, um, you know, I lost my train of thought with your historic Gold Knot, Mitch B***h, you, you were saying about It's not just the tool, it's like, look at where you're Spending resources, people not gonna hiring With. Yeah. Um, you know, it, it's very funny, but I think that's a real decision that CISOs are, are dealing with today.
And that, that was the point, which is, where do I put my money? Do I, do I, you know, automate the heck out of everything and you do with less people? Or do I bring on more people who can, you know, I can maybe better quantify the bang for buck I get, but it, it comes back to what Chris was saying earlier about you gotta hack these things.
And I'm reminded of the movie, uh, the Martian with, uh, with Matt Damon. Remember science the s**t out of it. It's the same thing with, with this stuff.
You gotta hack the crap out of it and figure out whether it is a little bit of people and a lot more technology or a lot more people and not a lot more technology or whatever you, you gotta hack, you gotta hack it and make it work if you're gonna make it till the, the, the rescue ship arrives. All right, Amanda, you wanna jump in here with like parting words? Yeah, I think it all comes down to understanding the level of risk you're willing to take and, um, you know, adjusting your dollars to cover the risk you're most concerned about The managing risk thing.
Alright, Hey Mike, this is a great, this is a great Cyber Tuesday. Um, guys, I think we're about outta time though. We've got another full couple hours of of TechOne TV here ahead of you for today, so check that out.
We'll be back on with that right after this. But before we go, first of all, two hour gang member Chris Blas, who came and joined us today from the, from his boat, from a location unknown, and, uh, thanks for joining us, Chris, it's great to have you on. And then thanks for having me.
It's been a lot of fun. Always look forward to doing tomorrow. We'll have you back soon.
And then Mitchell, Amanda, as always, great job and thanks for joining us on The Gang Today. Love it. Thank you part of the gang, Mike.
Uh, you know, for those who don't know, Mike drives the editorial of, of these shows and, and another great, great lineup of, of information today, Mike. Thanks. It's fun.
Yep. All right. We will be back, I think on Thursday with Is is our next, uh, fresh Content Day here on Text Drunk Gang.
Stay tuned for the rest of Text Drunk tv, everyone. Until next time, this is Alan Shimmel for the Gang, we're out. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery and more. com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more. com to learn more.
com where the world meets DevOps.