Cyber Resilience: Making it a Reality | The Six Five Summit
In today’s dynamic threat landscape, cyber resilience is no longer an abstract concept but a critical strategic goal for enterprises. A robust cyber resilience framework is critical to protect your organization from ever-evolving cyber threats. But the challenge lies in translating theory into practice, making it tangible and measurable.
In this session, Cohesity’s Dale “Dr. Z” Zabriskie shares invaluable insights and practical strategies to move your organization beyond theoretical discussions and to implement actionable cyber resilience measures.
Transcript
So we're in day three for the six five summit, and I have the pleasure of speaking with Cohesity. Um, the company's been around for over a decade, and it's focused on data, cyber, and business resiliency. And joining me is Dr.
Z, Dr. Z, you're the America's field CISO for the company. That's great.
Great. So, Dr. Z, how are things going?
Things are going really well. Uh, I'm having, uh, an en enjoyable and, but enlightening time, uh, traveling around, talking with customers and, and seeing, you know, how they're trying to respond to the threats and the challenges out there. Sure.
Uh, it's seems like it's never been so overwhelming for a lot of organizations Mm-Hmm. You know, the fear of ransomware is still out there. Sure.
And a lot of organizations are taking steps, uh, very serious steps within their groups to, to ensure that they're ready to respond accordingly. I mean, how do you make cyber, uh, resilience tangible and measurable in today's new age? Yeah.
The, the, the conversations that I'm having with customers and, and, and groups is helping them understand that, okay, you've got the idea of replication. Mm-Hmm. Okay.
A functional A to BI can do that, I can prove that you have the function of my backups are good. I'm a check sum. Looks good.
Uh, but then on top of that, we start talking about things like disaster recovery, which brings more people in process and things in play. Sure. To the point now with attacks like ransomware Mm-Hmm.
With the concerns around AI and such, the business has to think of it as, how can I respond to different events? You know, we have a lot of attacks. Last year, ransomware was over a billion dollars, uh, you know, paid, uh, the statistics continue to show how rampant that is.
Mm-Hmm. But it could be, you know, a natural disaster. It could be the well-meaning stupid person.
It, it could be, you know, anything that brings a system down that affects the IT organization of keeping the revenue generating clock running. Sure. Right.
Yeah. That's their job. That's their one job.
Right. And so the idea of, uh, replication is, is has to expand to the idea of keeping that business running. And that when is when we pull in not just the infrastructure team Mm-Hmm.
But the security team, the legal team, the finance team, the HR team, these are All critical stakeholders when it comes to Yeah. The notion of data protection. Exactly.
And, and so what I ask customers a lot to say, what is, can you define a minimal viable company? Mm-Hmm. So if you were totally down, what would you bring 'em first?
Sure. What data does that include? What systems does that include?
What people need to be part of that process? Mm-Hmm. Uh, to help the, the technology folks realize they have to get out of maybe their blinders Mm-Hmm.
And what they do, and understand the impacts of what the business needs to continue to operate. What are some practical tips to implement so that you focus on the right policies, processes, controls, and procedures. Historically, you know, the security team has written a policy and basically thrown it over the fence Mm-Hmm.
And said to infrastructure or whatever, here's what you deal with, you have to comply with. Right. Exactly.
You know, they become the department of no. Yeah. And here's what you have to do, and don't, don't bug me about it.
Just, just make it happen. Right. And that's the, the barrier that has to break down so that those plans, those discussions have to be very comprehensive for the organization to understand these are the threats, these are the things, these are the risks that we're looking at that we need to be aware of and, and take into consideration should this occur, how are we gonna make this happen?
So, uh, when, when an event occurs, and again, it could be anything, but especially an attack of some kind, the first thing that breaks down is communication. Mm-Hmm. Okay.
Often because a crisis plan that you've written and you've planned and you've tested, sits on a SharePoint server that you now can't get to and you don't have. So what was Bob's phone number and, and, uh, the out of bounds type of communication process Mm-Hmm. Needs to be somewhere on a piece of paper that somebody Well, I'm just gonna Say, I mean, do you need to print it off?
I mean Yeah, Absolutely. I mean, we, we do need to think about that. Sure.
So that's the first step, is making sure that you can communicate out of bounds with whomever you need to. And that, that will include, uh, it might include law enforcement, it might include, uh, you know, legal or partners. Sure.
Uh, it depends on your business model. It might include your franchisees. It could, you know, it depends on how you're doing business.
Yeah. One of the things I'm spending a lot of time with, uh, this first half of the year is going into organizations and running a ransomware resilience workshop where we put 'em through a scenario. Right.
And we, we bring people in and we say, okay, you're the CEO, you're the CIO, you're the head of, you know, HR or, or, or PR or whatever. Uh, we give them a promotion for a short period of time Sure. And we say, okay, you've been attacked, and it's a very immersive experience.
Okay. And the hacker talks to you and you have to respond. And it's like, choose your own adventure type thing.
And based on your responses, certain things happen. Mm-Hmm. And what people learn, uh, early on is they become very impotent.
They become without ability to do much Sure. Or negotiate or control. Right.
And that really opens their eyes. And then this, the second thing that, that, and probably the biggest thing that they come away with is they say, you know what, when we are talking about this in our groups, we do not have all the people in the room. We need to broaden out that discussion.
Sure. Include all the stakeholders like we were speaking to before. Exactly.
Yeah. And, but that's hard to do because we, we get so tech minded about my process. Right.
And or that it's The responsibility of net ops or SecOps. Exactly. And you're not, You're not thinking about, you know, HR and legal and Yeah.
All the, All the rest of it. And that's what we're trying to do, is to give visibility, you know, and AI is just a component of that. Right.
Visibility into your data, both production and secondary data so that you know exactly what's in your data. So We've really been, you know, talking about the human element, and you mentioned stupid people, like, you know, and you know, when you look at ransomware and you look at how that, that propagates, a lot of times it's socially engineered. Right?
Mm-Hmm. And, um, so I'm just wondering from, from your perspective, how, you know, you, you've mentioned a few things on, you know, what, what Cohesity does to sort of, you know, empower the human element to, to be more defensive. But are there some other considerations that organizations should be thinking about when, when, you know, focusing on the human element of this equation?
Uh, I'll ask organizations say, how many individuals in your group have high level admin access? Mm-Hmm. To your systems, whether it's an authentication system or it's a, uh, the cloud resource.
How many, and I, I, I don't even let 'em answer. I give 'em the answer. Right.
The answer is two. Right. Too many, too many.
Yeah. Because it evolves, our, our organization's evolved to where somebody says, Hey, we need to run this, this new project, and so I need, I need this access to Okta, or whatever. It's Right.
Oh, okay. Okay. That's fine.
And then we forget about the fact that Bob just got that access. Right. And so that really needs a hard look, right.
To say, what's the role? And does that really require that kind of access? Mm-Hmm.
So we become lax often in our, our, um, management of access to tools. Right. And that starts to just spread the attack surface.
Well, what I also see too, in organizations are orphaned applications Yes. And orphan systems that are allowed to remain, be dormant, and then they become weaponized because a bad actor finds a way to get in and infiltrate that. So, I mean, what, what can organizations do?
I mean, you know, to have that, that level of visibility. 'cause it's oftentimes it's very, very difficult, especially a large enterprise that has hundreds of, you know, SaaS applications and systems. And, and some of it is legacy, some of it is modern.
I mean, any recommendations on, you know, how organizations can, can manage that infrastructure. So, You know, it comes back to blocking and tackling it. We talk about this all the time.
Yeah. You know, what's the default password? Mm-Hmm.
You know, change it from admin or password. Right. We Still see that it's not 1, 2, 3, 4, It's not 1, 2, 4.
Uh, you know, it's like I came up, my, my son came up with hot pants movie buffet. I thought that was a great pastor. Number one, you won't forget.
Very creative. And nobody will, nobody can guess it. Right.
And you'll never forget it. Right. Yeah.
So, Uh, you know, to change that type of stuff, there has to be a continuous auditing process in that world to understand, you know, have we done those basic hardening processes, uh, password, you know, organizations are working to go passwordless. Right. Uh, we, well, And a lot of, a lot of companies, like, you know, you've got Cisco Duo that Yeah.
Cisco's a good example. That that's sort of the direction that Yeah. That a lot of infrastructure Companies.
Yeah. And so that now puts, uh, you know, a lot of, uh, another layer of security in there. So we don't have that human element so much.
Mm-Hmm. Uh, capital One just went through this and, uh, with, I listened to them at the, uh, executive Security Action Forum this week Mm-Hmm. Kind of outline their experience of doing it.
It was really fascinating. And, and yeah. They had a lot of humans that were, you know, getting up in arms and everything.
Sure. Um, but when people understand the ramifications of their actions, and, and I'm not saying that they're trying to be bad, it's just that they're, we're kind of lazy. Right.
We're all lazy. We just kind of want, and we get Into line of time. Yeah.
We get desensitized to Yeah. You know, everything. But you look at the, the last year's, uh, Caesars and MGM hack.
Oh my goodness. You, you mentioned the, the social thing. I think the term ransomware, we could even argue is a misnomer, because often there's no wear, there's no malware, there's no software.
Uh, case in point is MGM. Right. We person, someone, uh, impersonated an individual that Yeah.
Gave them high level Okta access, and then that gives them high level, uh, Azure access. Right. So they basically, if you're a gamer, they basically were in God mode Right.
Running around. Yeah. MTMs infrastructure moving, Moving laterally, um, right.
Yeah. Disabling, um, keys to rooms Yeah. Shutting down the casino.
I mean, think about just, you know, the, the opportunity, you know, costs to, to MGM potentially the, um, the patronage they're gonna lose over time, because I mean, I saw some of those pictures. I mean, there were hundreds of people in life that couldn't even get into the room, couldn't get on the elevator. Yeah.
It just, it was madness. It's, it's, yeah. And it just totally goes against our, our normal ex expectations of things.
The impact, uh, is so far beyond, um, you know, what we think of is that, well, I can't log in somewhere, so we have to be diligent in things like, um, how do we manage passwords? Mm-Hmm. Uh, the multifactor authentication, the, uh, the role-based access control.
Right. Yeah. These are the basic building blocks that organizations need to apply.
Yeah. And, uh, is, will also apply in the AI space Sure. In the use of ai Mm-Hmm.
If people are scared to death Right. To open it up to everybody. Sure.
Well then let's take a pragmatic approach to it. Let's apply the rules that we use around access to other tools. Right.
To the use of ai. Right. And that will help, uh, reduce that threat, uh, surface as well.
I agree. You know, and you mentioned MMFA, you know, one of the statistics that I've read is that, you know, 30 per, you know, 30% of organizations don't even employ multifactor authentication. Yeah, yeah.
Which that is like, that's frightening. I mean, that should be like the first thing that an organization consider. We Did a, uh, a ransomware workshop and, uh, they're, they publicly stated a number of months ago that their networks see 45 billion hits a day.
Wow. And that they aren't, that's a, they're on record of saying that. And it's just like, yeah.
So how do you do that? One of the guys in the room when we, uh, went through this exercise, you can just see, you know, kind of the light coming on. And he literally said he, he raised his hand and made a comment, I get it.
Now I get it. To understand why we put these controls in place. Mm-Hmm.
Because even as a security professional who has a, a pretty good high level of responsibility of that organization Mm-Hmm. He was like, you know, I gotta do this again. I, the m FFA and blah, blah, blah.
Everybody, you know, the fatigue. That's The friction. Yeah.
Yeah, yeah. The, and, and he just like, I'm not gonna complain anymore. No.
You know, so unfortunately, fortunately, they didn't have to go through a real exercise, you know, for him to, they went, They went through your workshop. Right. Yeah.
So, well, Dr. Z thank you for, uh, for sitting down with the six five, uh, media. Uh, it's been a really, really insightful, uh, conversation and I just wanna let our viewers know.
Um, keep, continue to tune in. We've got a lot of great content this week. And if you'd like this video, please hit the like button and subscribe.
But thanks again, Dr. Zin. My pleasure.
Thank you.


