Organizations have traditionally relied heavily on firewalls and perimeter defenses, assuming that safeguarding network boundaries equates to overall security. However, today’s evolving digital landscape demonstrates that these traditional defenses are no longer sufficient. Persistent threats, increasingly sophisticated cyberattacks, and insider risks continually challenge organizations, emphasizing that complete immunity is unattainable. Forward-thinking cybersecurity leaders are now shifting their focus from purely defensive measures to strategic threat acceptance, adaptive risk management, and organizational resilience.
As cyber threats become a constant, organizations must proactively adapt, implementing frameworks and cultural shifts that enable continuous monitoring, rapid response, and resilience against ongoing threats. Rather than viewing constant exposure as merely vulnerability, visionary organizations leverage this reality as an opportunity for innovation and competitive differentiation.
But are organizations truly ready to shift their mindset from prevention to strategic acceptance? What innovative strategies and cultural changes are required to transform constant cybersecurity threats into organizational strengths?
Contributors
- Leon Ravenna, Chief Information Security Officer, KAR Global
- Steve Lodin, Vice President of Information Security in Corporate Security, Sallie Mae Bank
- Dr. Jagannath Sahoo, Chief Information Security Officer, Gujarat Fluorochemicals Limited
Transcript
Sanjog Aul [00:00:00]:
Hello, everyone. Welcome to CTN. To learn more about the show, please visit ciotalknetwork.com and today’s topic is Accepting Constant Threat Exposure In Cybersecurity Beyond Firewalls. So we all know that there’s a lot happening and there is a constant change that happens in the IT world, the business world, and now you’ve got AI throwing in the wrench. Now we always wanted to get control that is our dream. As cyber security leaders and IT leaders, that we always control it, but somehow it has never happened or for that matter, we might have the reasons why it has not happened because it moves way too fast and intruders and perpetrators, they have got lot more on their mind and they always going ahead of the people who are trying to solve the problems or bring some control. So should we shed that dream of ever getting fully in control and instead work on the resilience? Should we try to become innovative in the way we use our technology, use our workflows, the processes, and also build a culture where we are not almost getting panicky when something happens with respect to cybersecurity breaches, but instead we become better in terms of handling it mentally, emotionally and on the ground solving the problem or at least minimizing the damage.
Sanjog Aul [00:01:22]:
So what should we be doing? How should we tackle it? So to discuss this, we have Leon Ravenna, who is the CISO and CIO for Openlane, formerly known as KAR Global and we also have Steve Loden, Vice President, Information Security with Sallie Mae. Hey, Leon, how are you doing? Well, very good, sir. And Steve, how’s life with you?
Steve Lodin [00:01:45]:
Busy as usual.
Sanjog Aul [00:01:47]:
Busy as usual. Okay, I like that. So, Leon, let’s start with you. Simply said, we have always had this, you know, the sense that we feel warm and fuzzy when we feel we are in control. But are we still carrying that illusion that we would get there ever?
Leon Ravenna [00:02:08]:
You know, I think that the vision is great, but realistically, I think the place where we have to be is really understanding what truly impacts us. It’s understanding taking the wheat from the chaff and being able to say, here’s what we’re going to focus on because these are the things that matter. Steve uses a tool today to, you know, drill down into what’s actually important and where. I use a different set of, of technologies, so I can’t do that yet, but looking to get to the same place because the place where we need to be is having credibility. it’s too easy to say, you know, there’s, I think last year there was 70,000 vulnerabilities. You know, they’re, they’re all sevens or higher. You can’t address those, so you have to understand what’s actually impactful and then go address those and kind of take the ones that are not impactful and put those to the side.
Sanjog Aul [00:03:15]:
So, Steve, what have you seen? Because you know, you have your own path and of course, Leon, and you might have intersected your paths, but frankly, everyone brings their own sense. Have you seen the leadership always hoping for that control or they slowly started realizing that that’s not going to happen? And let’s figure out another way to deal with this. A monster.
Steve Lodin [00:03:36]:
That’s a really good question because I think it depends on your environment. Sallie Mae is financial services. So we have a really strong regulatory environment with lots of guardrails, security controls that we have to meet, and regulatory bodies that audit us quite frequently and have high expectations. So getting control is really one of those questions they ask us all the time. A prime example for us there was prior to this last year where Snowflake had issues. We moved all of our enterprise data warehouse as part of our move of everything into the cloud, we moved our data enterprise warehouse into Snowflake. A couple of years ago, the regulators asked us, do you feel comfortable with the configuration and control you have in Snowflake? And that was largely one of those shadow it kind of in it, but not really managed throughout the entire environment. And while we might not have said this, we weren’t comfortable.
Steve Lodin [00:04:42]:
So we have since added two tools to sit on top of Snowflake to feel more comfortable and control the identity and access piece to control the configuration and setup piece. So that last year when Snowflake customers got breached by attackers because they didn’t have the right configuration bars was fine. We had the configuration set up so that attackers couldn’t get at us. So that control piece in our environment is really the journey to get there and we’re always on it. We’re always looking for tools and technologies to take us to that next but maturity level.
Sanjog Aul [00:05:23]:
Now with that said, Leon, one quick question for you. When you are looking at this whole idea of us trying to become the type of people who would look at zero Trust and we almost are a tongue in cheek because we feel it is more like a marketing slogan. Have we embraced it yet because no one says Zero Trust is a tool. They all say it is a mindset and have you embraced that mindset?
Leon Ravenna [00:05:51]:
Yeah, we’re working on it. There’s very few people that have gotten there. If your company’s, say, more than 15 years old, what you were told for a long time is you use active directory. You threw everything in one data center and to make sure that it was easy, everything was open anyway and so now you’re moving to the cloud and people don’t know what talks to what you know. So you’re so trying to figure out ways to manage that appropriately so you’re not turning off communications to other tools. You know, I think there are, there are things that you can do from a zero trust standpoint to gain that
Leon Ravenna [00:06:33]:
but it’s really going to be a very careful process to be able to say, okay, I know that system A never ever, ever talks system B, we can cut that off. And when you’re, in the cloud, it’s a little bit easier, but you know, you’re still gonna, you’re still gonna run into, you know, oh, we didn’t know that. At the end of the month, this system talks to finance and, and stuff, stuff breaks, you know. But really, I think to your point, it’s, it’s a mindset. First to understand you have to segregate everything out that you can and then work to start doing it.
Sanjog Aul [00:07:14]:
So we have Jagannath Sahoo. Hi, Jagannath. How are you, sir?
Jagannath Sahoo [00:07:20]:
Hi. I’m doing good.
Sanjog Aul [00:07:23]:
Very good. Thank you so much for joining us. So as you might be hearing a little bit about the mindset. So you come from a different part of the world, but very, you know, I’d say it’s growing leaps and bounds. You’re coming from India.
Sanjog Aul [00:07:40]:
And let’s take a geographic and also a cultural approach to. Is the zero trust mindset being embraced wholeheartedly or we are ways before it happens.
Jagannath Sahoo [00:07:52]:
It is way wired. Actually, before flatting, actually let me cover the topic. The topic, I guess beyond security or something topic is right. So after the COVID era, there is a lot of change actually now perimeter is different. Actually after Covid era, the cloud become the new data center and Internet is the new network. Now home is the new office
Jagannath Sahoo [00:08:18]:
and application everything move to containerize and coding becomes zero code. No code. Zero trust. Finally, zero trust is the only trust in the site security. Zero trust is the framework. Everybody should adapt it.
Jagannath Sahoo [00:08:29]:
A couple of principles are there for zero trust. Whether you do micro segmentation, whether to iim, whether it is continuous monitoring, whether the MFA encryption policy enforcements. So it is a completely different framework actually how people are adapting. How much they’re adapting, it is most critical.
Sanjog Aul [00:08:46]:
So you are the CISO of Gujarat Fluorochemicals, which is not like financial services like Steve is dealing with right. For example, or E commerce and retail of sorts where Leon is. So different industries.
Jagannath Sahoo [00:09:03]:
How we are into manufacturing industry and we are into renewable source of energy also. We are based out of India but our 80 to 90% business across the globe. So we manufacture chemicals and sell it across the globe.
Sanjog Aul [00:09:19]:
All right, so with that said, so Steve, let’s, come to you when you are looking at this whole idea about zero trust. We spoke about that briefly right now, but then let’s look at what all other things that people should be looking at to not waiting for control or the utopic state to be achieved and can basically do something about and I’m referring to resilience building and it is an always on effort. But is there a true north that we are pursuing?
Steve Lodin [00:09:53]:
Okay, I’m going to get there. But to start with, zero trust is a journey. I think Leon kind of mentioned that you can’t go buy one tool and call it zero trust. You have to consider all of the different pillars and what zero trust is. To get to that resilience stage, you need the basic hygiene. You need strong IAM with a single IDP that manages your identities for your environment. Role based access control, least privileges. Moving into the network side, you need to have strong segmentation between your workloads, between your servers.
Steve Lodin [00:10:35]:
You know, a server sitting in China shouldn’t need to access your HR server sitting in the US as an example. So micro segmentation between networks, between AWS accounts, between whatever is all just that basic hygiene. Making sure that your devices that access your network are limited to what they can get to, to only what they need. And doing, you know, device management is all basic hygiene. Once you get beyond that in that journey, then you can start to talk about resilient infrastructure. Here at Sallie Mae we’ve moved everything to the cloud. We’re doing the cloud CSPs as our infrastructure and then we’re in a ton of different cloud SaaS services. We rely on SOC2 and the SaaS services to provide that resiliency.
Steve Lodin [00:11:29]:
Are there hiccups? Absolutely. Even on the CSP side, there’s been hiccups over the past five years. With Amazon, they lose a region. How do you work with that? You start to think about resiliency within the resilient environment. So we spent time having US East 1 and US East 2 assets. In case one of those regional data center infrastructure pieces goes down, we’ve got something nearby rather than spinning up a whole backup data center in the west region as an example. So starting to think about resiliency is really critical. And the other thing that you start to then scale up is how can we have multi cloud providers? That’s still a really tough challenge.
Steve Lodin [00:12:21]:
Ahead of us is having the same workloads in multiple different aws, Azure, GCP type environments. How do you triage those? How do you make sure that they’re functioning? How do you get the logs and the data synchronized? That’s still a little above where we are in a maturity level, but I think is the next challenge that the regulators and the US government for critical infrastructure is going to start pushing for.
Leon Ravenna [00:12:51]:
You know, I think you follow and see that, you know, he mentioned, I am if, if you were looking one place to start, I would probably start with identity. Make sure that, that you have that right. So you’re, you’re protecting where you can first. It’s going to be A, a little bit easier and B, quite frankly end up helping you because that’s going to be always the first step to worry.
Steve Lodin [00:13:17]:
About where are the attackers going right now? Identities, they’re not trying to break into end systems as much. They’re going for the identity which gets them access to all the data.
Sanjog Aul [00:13:27]:
So Jagannath, what have you seen in your ecosystem? You know, where are you seeing identity for that matter is being looked at and how much it is important and what are you doing to kind of. It’s not a crown jewel but that’s a point of entry, right? So you got to rethink everything. So what is being done? How are you even looking at it? What are you doing to make sure that you are resilient towards such attacks?
Jagannath Sahoo [00:13:53]:
Yeah, see now question is you cannot tell, you will not get attacked but question is when you are getting attacked or how much attacker is putting effort to get you attacks and somebody was talking about the pillars of zero trust. I think there are almost seven pillars. One is user, device, application and data network, devices, automation, visibility. These are the pillars of the device and zero trust should start everywhere actually. Whether it is endpoint, whether it is API, network, cloud, everywhere, follow zero trust, whether it is data security, IOT security.
Jagannath Sahoo [00:14:26]:
Being a manufacturing company, we are using lot of IOT device ot device there also we should enforce zero trust things.
Sanjog Aul [00:14:35]:
But is it a pipe dream or is this actually happening to the degree you would like to see happen? I know it’s A journey.
Jagannath Sahoo [00:14:42]:
It is happening. Yes, I understand in OT security, lot of legacy system is there where we are not able to enforce OT, IOT, legal system is there but rest everywhere we have started putting robust thought process, particularly endpoint, API, network, security, cloud, every web started, except particularly in manufacturing where IOT and IOT and OT devices, there we are facing some challenge due to legal system otherwise rest everywhere we started putting.
Sanjog Aul [00:15:13]:
So, Leon, do you think we still carry resilience as a fallback or has it become or has it become a frontline strategy, if you will?
Leon Ravenna [00:15:26]:
No, it’s become a frontline strategy. You have to. I mean, Steve mentioned that Amazon went down. Amazon should not go down. Data centers should not lose power. But they do, you know, so you have to plan for that. Now, do you plan for that in huge ways on every application? Maybe not in Steve’s world, yes. But there are some applications that you may not look and say, well, I need duka copies or I need a way to bring this back up quickly.
Leon Ravenna [00:16:04]:
So I think there are measurements of resilience that you’ll want to look at that you can actually kind of, kind of, kind of bite off and chew. The one thing that I would disagree with is doing everything at once because if you do everything at once, you’re going to fail unless you’re a lot better than most of the people that I know in the security space and actually I want to drop back to a little bit on the identity stuff. You know, Steve effectively alluded to. People are logging in, they’re not breaking in. You can go buy credential lists off the Internet that have here’s username, here’s, password, clear text password, here’s where they’ve logged in and we buy some of those to be able to understand, you know, and help for our employees and our customers.
Leon Ravenna [00:17:01]:
And if you’re not doing some of that, you’re open to potential fraud and things like that. But I think that’s. Those are some. That’s why I say identity is first. Agreed. Everything should happen but if you don’t start with one thing, you’re going to fail at all of them.
Sanjog Aul [00:17:22]:
So, Steve, no conversation today is ever complete until you don’t bring the buzzword AI, right?
Sanjog Aul [00:17:30]:
So AI is the weapon and AI is also the shield, if you think about it now. So we thought that, okay, we bring AI, we go after these guys and they’ll be caught in no time and guess what? They again are outsmarting. And you got the same thing could come and sabotage our efforts. So what mindset and strategy and approaches would any organization take now given that CAT is out of the bag?
Steve Lodin [00:17:58]:
Couple of different approaches. You know, if you have a strong third party vendor management process in place today, then making sure that you’ve got your guardrails around AI on top of any business application that you’re trying to buy or contract of services. So making sure that your third party vendor management is at frontline in understanding what’s coming in that says AI, understanding the impact of that, the data flow, whether that data is being merged into global LLMs or whether you have your own tenant that keeps your data separate. Those are all really good questions on the incoming side. From the security side, we haven’t really seen the impact that everybody expects on AI. Every vendor has it in their marketing terms that they’re doing AI and they may have some pieces that help us on essentially a co pilot type approach giving us more context, more information that would take more time to manually go find that on our own. Really appreciate that side of things. But in terms of agentic that you replace people, still not happening
Steve Lodin [00:19:14]:
there’s still a lot of knowledge that is in people’s brains that helps in investigations that you can’t really replace. In terms of AI on the investigation side, there’s 45 different ways that AI could be involved in this process. Leon, over to you. What are you seeing on AI and the impact in your teams and your security environment?
Leon Ravenna [00:19:38]:
Yeah, I think the mantra that I follow is you got to use AI to fight AI and if you’re giving an example, if you’re still using say an iron port to filter mail, you’re in trouble. You have to use things that are smarter to look for what’s there and I think to your point Steve, the biggest thing we’re seeing right now from an AI standpoint is more, hey, we can cut down the number of alerts that you have. So the product that you’re using wasn’t very smart. Now they added AI to give you more meaningful alerts but I’ve seen some pretty wicked new really early stage startups that are doing that will stack vulnerabilities on top of each other. Those are the things that scare me.
Leon Ravenna [00:20:37]:
Those are the things where you know, you’re seeing what’s coming from,companies, but the bad guys are doing the same thing and there is no, there is no real guardrails on what they’re doing, as there there is for you to particular domains.
Sanjog Aul [00:20:55]:
So Jagannath, would you say for us to tackle this whole AI related threats and prepare ourselves. Step one is let’s do a status check. Are we moving fast enough in terms of leveraging AI, using AI and deploying AI so that we are not just stuck defending and instead are able to take an offensive stance and be able to attack so that you nip it in the bud.
Jagannath Sahoo [00:21:23]:
See particularly in cybersecurity space, if you see a lot of AI is getting used, every company, every OEM is coming. They have AI solutions, they have ML solutions, AI ML, both are giving as a combined, every solution started coming. Now even if SOC, the pyramid has changed. Earlier what I was L1 was very number of people was very high, L2 then L3, L3 was very nominal, just like a triangular set but now it got changed putting AIML. Lot of things is getting automated. All the mundan tasks or irregular task is getting automated through AIML. Now there are a lot of optimization is happening and people are talking agentic.
Jagannath Sahoo [00:22:06]:
AI, but I think genetic AI very soon it will go to the history. Now agentic, we’re talking lot of things on agentic AI. There is a lot of things happening in agentic, but AI is helping ultimately for predictive analysis, automations, process optimizations, personalizations, fraud detection, everything where AI is getting used nowadays.
Sanjog Aul [00:22:25]:
So Steve, I’d like to build on what Jagannath said. So while people are looking at tools and frankly tools will catch up. I mean what you don’t have today, tomorrow you will have it. But it eventually comes down to our mindset. So would you say as a security leader, would you rather if given a chance to take an offensive stance and kill the damn thing, or would you say no matter how offensive I get, I still have to not lose my shirt and or not get my company in trouble. So what kind of mindset should prevail among security leaders and how do they convince their business leaders and IT leaders so that you do not win this war, but don’t let it destroy you? Especially with this AI, everything is moving at a pace we do not even know how to tackle.
Steve Lodin [00:23:18]:
I think that’s a company culture perspective. So our culture allows my security team to quarantine or remove access first, ask questions later on certain events so we can automate those using AI as an easy example, and rather than wait for some person to take a look at that case and click a button that says quarantine, we can have that happen automatically. I think in those cases we’ve got cultural support in the business to be able to do that and take advantage of that And that shrinkage of time between a person doing it and an AI doing it really doesn’t impact us that much. So they’re going to be fine with that. It’s the case, oh, you’ve got AI, can it turn off Internet connection? Can it affect the business? That’s where they’ve got their concerns, rightfully so. And where we’re definitely cautious about moving into AI assisted or AI executed activities, we’ll be fine with context, we’ll be fine with some small number of use cases to tip access off right there, but not at a higher level and I think that’s just because of the business risk and the discussion with the business owners on the outcome of those actions.
Leon Ravenna [00:24:46]:
You know, the one thing you mentioned though is let’s be real specific about what offensive means. so are, are we using that to go after people? I don’t know many, many companies that will, even the, the U.S. from what I can see, you know, they will kind of let stuff play out but you know, in my mind we should be blocking things that undersea cables, but we don’t and I don’t know that any company has the resources to go pick a fight, so I think the place that most people are going to stay, even though you’d like to go offensive, you’re going to be defensive because that’s the nature of what you do and if you go pick a fight with the wrong people, what are the impacts? So the, I think they’re, the things that, that Steve is talking about is, is using your resources better but still in, in defensive mode and when we talk offensive, you know, the, I have a, one of my guys is in the Army Reserves and there are people that he knows that that’s what their job is, is to be offensive. You have to be very careful and understand what you’re doing because you’re putting your company’s resources at risk when you do that.
Steve Lodin [00:26:23]:
And you have to weigh that against the fact that if a nation state finds you offensive and they target you’ve lost. You can’t prevent nation states if they’re focused on you from getting in. They have way too many ways to social engineer or logically engineer access into you. So stay below the radar, don’t push them is kind of our goal as well.
Sanjog Aul [00:26:49]:
So Leon, question for you. How do you distinguish between a real time threat intelligence and noise because frankly both are being generated by AI right now.
Leon Ravenna [00:27:02]:
So we like most will buy threat intelligence for what’s coming and some of our tools will do correlation for us. You know, hey, I see something in Cloudtrail, I see something in EDR some over here. Here’s, kind of what it means. It’s taking, people out of, process. I just think using those is beneficial But I don’t want to go right now a lot beyond that.
Sanjog Aul [00:27:39]:
Sure. So Jagannath, when you look at your organization and you mentioned they’re global, 80 to 90% of your business is global and everybody’s working and everyone is also exposed to the potential AI based threats. So have you come up with some sort of a calibrated way by which you say I’m going to put this much human power and this much AI power to do the threat intelligence, do the remediation which has turned out to be a sweet spot or a magic formula that’s worked for you so far.
Jagannath Sahoo [00:28:13]:
See I’ll tell you one thing that is new terminology started that is called Cobotics. So AI and robot getting used in plants nowadays that is Cobotics where human and robot working together. So we are trying to see it should be top down approach until unless the leadership asks in every meeting how much AI is getting used, it will be top down approach. So we have started giving training to all senior leadership whether it is Copilot and others. We are enforcing them to start using Copilot so that they would day in day out they will think how AI will get used by every employee. So we are focusing more on the team.
Sanjog Aul [00:28:52]:
What you’re talking about is them embracing the fact that you have to use human and AI both when coming down to not getting into the weeds. But if there is a problem or you’re trying to secure an environment and you’ve got certain SLAs or certain levels of security you have to maintain, then you got to do something so that you are not fully relying on AI and not totally going back in the ages to say I’m going to only do human because AI is not working out. What are you finding as a good balance here so far as of now.
Jagannath Sahoo [00:29:26]:
We have started using a couple of RPA. So we have decided to put 100 RPA cases for this year where many things we are doing automatic through AI only where through AI deals we want to automate many process through AI through different, different rba nobody process automations.
Sanjog Aul [00:29:43]:
Okay, so Steve when you’re working in financial services, everything moves at a warp speed. Yeah. And then we actually recently covered a topic which is almost like metabolism of AI knowledge. So like our body that somehow knows what to keep, what to reject and what not to get out of hand.
Sanjog Aul [00:30:03]:
Similarly, when you’re putting something in the hands of AI internally, a lot of things it is doing which is not available or it’s not fully explainable, but you’re loving the outcome. Now here, when you’re going to put the AI and the human and you’re trying to get a certain outcome, you also want to make sure that you’re not rolling the dice. You’re doing something which is going to be effective, yet not give you unpredictable results or it’s not going to get out of control or put you in a lot more danger than you started. Have you done anything in your field because you guys must be the most advanced when it comes to industries, right?
Steve Lodin [00:30:40]:
Okay, yes, advanced in financial services, but the business rules there. So putting AI in charge of things. No, as Jegannath said, we’re also doing soar security orchestration type events. He’s using RPA, we have RPA. So specific events, yes, but we’re definitely not, as an industry willing to put AI in charge such that it may have an impact to the business and continuous operations.
Sanjog Aul [00:31:15]:
So do you have a playbook to say, okay, these are the use cases where this percentage or this, there has to be some determination. It cannot be fuzzy logic. So there must be something that you may be doing to make sure by trial and error and ABC testing or whatever else that you do to come up with that sweet spot which so far has brought you reasonably good results with enough risk management, if you will, because financial services stakes are high.
Steve Lodin [00:31:43]:
Yes, I agree. That takes people. We’re definitely not size of an organization like Citibank or Bank of America or something like that, where you could devote an entire team to do that evaluation. So we’re relying on a lot more manual effort in running tests, seeing the impact and then choosing those to be able to be automated rather than, you know, a whole suite and a whole playbook of all these different use cases or definitely not that far yet.
Sanjog Aul [00:32:17]:
Leon, what have you heard because you’re also active in the community, talk to a bunch of people. And including your own environment, how is the CISO community, the security community, trying to tackle this? The mix human and digital worker working together to help get security the best it can be?
Leon Ravenna [00:32:37]:
The short answer to your question is validation. Here’s what we’re seeing. One of my tools we added in the AI component and it takes alerts from a couple thousand to ten a day. Okay, so let’s, let’s go validate that it’s doing the right thing over and over. You know, I think the place where we’re going is this is out of a lot of conversation is having it help make us smarter in what we do, being more efficient in how we look at. Here’s the outcomes that we’re looking for, but I don’t know that anybody is going to rely on it in we as workspace. So we have Gemini in place, but I still review everything that I ask Gemini to do and that’s standard foundational LLMs.
Leon Ravenna [00:33:36]:
It’s not security stuff. So you really have to apply your smart people to looking and saying yes, this is what I expect. Now let’s check that every so often because things can drift but I would rather do that and know that I’m being more efficient with what I’m doing. I’m able to potentially add tools instead of adding people. And then, you know, I don’t know about Steve or Johnny Mouse environment, but it takes, six, eight, nine months to get somebody up to speed, and if you can do that faster and more efficient with a tool and make your existing people smarter, it’s a win win.
Sanjog Aul [00:34:20]:
So Jagannath, would you say pre AI era, the acceptable exposure or the definition of what is acceptable exposure because there is no zero exposure environment, right? The definition of that has just because AI came, so everybody started thinking now I have a utopic state so I can come more to the zero exposure. Has that definition changed or you still maintaining the same and now just trying to become more efficient in getting to that or maintaining that state.
Jagannath Sahoo [00:34:55]:
See, A was there earlier, now A is also there and in future AI will be there also there will be no changes. But use case we are putting more use case to get the couple of tasks getting done through AI. For example, on SOAR you step method about SOAR support where we are trying to automate everything. Automatic IP blocking in firewalls, all the things we are using AI in IAM where we can find out who are the risky users, who are the different things they are doing through AI tools. Scoring of employees, scoring of devices, scoring of assets through AI. We have started using in DLP also where automatically it is doing analysis and monitors the sensitive data protection policies, chatbots. So many places we have started doing AI network traffic analysis, user behavior analysis, email filtering we have started using in all the fields, Yuba ,EBRC , everywhere we started automatically using AI.
Sanjog Aul [00:35:55]:
So Jagannath, I mean that is beautiful that you’ve shown so many use cases. Now eventually it comes down to management pays you the big bucks to make sure you keep the environment secure and that also is measured as you got some KRAs for yourself. Your performance appraisal will be did you keep me below that red line which shows the acceptable exposure level. So because AI came because they invested in the tools and other things, did you move or raise or lower the bar? What happened to that bar and what should happen to that bar? Just because on one end you got more tools but on the other hand AI also is a source of risk.
Jagannath Sahoo [00:36:38]:
See AI is also source of risk. To answer your question actually we have to give value realization to business otherwise until unless you give the viral after putting this AI, after putting this RPA how much cost you are saving, how much businesses you are doing. So that also we have to give business to before adopting any AI solutions. And coming to next point AI can be hacked also for couple of places AI will get hacked where we’ll lose the trust of the user. Where will the user lose the trust of the business. Couple of places sensitive data can be exposed also business critical reparation risk also it will be risk. So AI is the both side, whether positive side or negative side both. But to answer your questions we have to give justification to business why you want to put this AI, what is the business, what is the value ration, what is the revenue we’ll get it from how we are saving money.
Jagannath Sahoo [00:37:30]:
All these things that also we have to give it to business for the business case project for getting the money for the CapEx and OpEx.
Sanjog Aul [00:37:37]:
So Steve, in your organization, right I’m sure they would have defined some sort of acceptable exposure levels and maybe the risk folks, not necessarily the security people may have defined that right now comes AI where earlier they were using the risk parameters strictly based on the business outcomes but now AI is being also entrenched in into all the business areas and the risk measuring approaches will need to somehow be rethought and therefore the risk managers or leaders themselves might have to relook at how am I putting my paycheck on the line to claim that this much exposure is enough or not enough. So is this line getting shifted? So there are two part question one is is that acceptable risk exposure shifting or whatever it is being picked up now is the decision maker of what that should be? Is that also changing because a risk manager cannot do that in isolation anymore, or a CEO cannot do that in isolation anymore.
Steve Lodin [00:38:43]:
Yeah. So your original question was what as a CISO, what are you measured against? For us, it’s not really threat exposure, it’s more, are our regulators happy that we’re securing our environment according to their expectations and have we had any or have we minimized the breaches we’ve had and if those are your criteria, AI doesn’t really fit in the measurement pieces but if you take a look at the metrics that are reported to our operational risk committee or to our enterprise risk management or to our board, we have not seen any AI based applications or functions affecting those metrics. Stepping aside a piece, we also have a governance committee around our generational AI efforts in the company. It starts right at the third party vendor management all the way through. What’s the impact? What’s the data share? What’s the, the knowledge that’s gained that can be used to help us set metrics because we have our second line of defense involved in that as well. It’s really strong on our risk management and metrics. So the closer we get, the more our governance committee will help us define what those metrics may be as they’re influenced by AI, but we’re not there yet.
Sanjog Aul [00:40:15]:
So, Leon, when you look at your organization and the folks that you’re talking to, is the rule book of the past being still used for risk assessment and adhering to the acceptable risk, or is that being rethought, given what I had said earlier and based on even Steve’s response, that they are saying whether those people are okay, that we are meeting that acceptable level of risk. But even the regulators and whosoever else was measuring you, even I’m sure their expectation might be changing because they see the landscape is changing fundamentally. What are you seeing in that regard?
Leon Ravenna [00:40:50]:
Yeah, I think to go back and try and answer the question that you asked first is that no matter what you’re doing, the bar is rising. So you make a step, bad guys make step. You make step, bad guys make step. That bar is never static and so the original question you’re asking at the beginning is essentially, are you doing good enough? Are you ahead? And you’re always going to fight that fight because there are always new and novel ways. I mean, in the last month there have probably been between breaches, high trending vulnerabilities, things to worry about, something almost every day that people have to focus on to say, yeah, we are part of that, okay, but that bar is always rising as to, what am I doing today to protect my organization and that’s, fundamentally, that’s the question that your listeners are going to have to ask themselves. At the end of the day, what did I do to make us better or am I staying the same? So if you’re staying the same, you’re losing, and when you look at it from a risk standpoint, there.
Leon Ravenna [00:42:05]:
There are going to be, you know, call it acceptable risk, but those risks are changing so fast that it’s not. It’s not something you can keep up with on a quarterly basis. You know, one of the things I’m working on right now is understanding what is changing at a federal level in the US that’s going to impact states and impact me. You know, CISA may get cut. They are new. Executive Order 14239, I think, is moving cyber and critical infrastructure out to the states.
Leon Ravenna [00:42:43]:
What impact does that have on my company? That’s not something I would have thought about two weeks ago, but now, now we have to think about it. So when I say that, you know, the bar is changing, it’s. It’s multiple forces coming at us in multiple ways to think about, critical infrastructure. That was always kind of a yeah, we had infragard. We understood what was happening. Is that changing dramatically? Don’t know.
Leon Ravenna [00:43:11]:
It’s how those risks, and particularly if the government is going to, take out part of CISA, is that in any way helping me today and how do I think about it going tomorrow? So the risks are constantly changing, and it’s our job to inform senior management, because those aren’t things they’re looking at. It’s how do. One of the things that I’m building right now is how should we be thinking about changes that are happening at the federal government from regulatory or, executive order standpoint that could ultimately impact us and so it’s a kind of a deeper level of thought than, you know, what we would normally think about risk. It’s added a new wrinkle for us to be worried about.
Sanjog Aul [00:44:04]:
So, Jagannath, I know most CISOs don’t sleep as much anyways, right? I mean, that’s the life that you signed up for. But what’s keeping you up at night? And what’s the biggest heartburn for you right now given the environment that you’re in?
Jagannath Sahoo [00:44:17]:
See, when I was working in Telkona, I asked I was asking my CEO what is giving you? What is not giving sleepless night. He was telling the cyber security.
Sanjog Aul [00:44:30]:
Okay, he is getting sleepless nights because of cyber security. So God, what is happening with you then?
Jagannath Sahoo [00:44:39]:
So see, if you have proper resilience place, then you will also have sleepless night. If you not have resilience place, then you will not have sleepless nights. If you have not tool implemented, if you have not implemented all the solution also you’ll have that issues.
Sanjog Aul [00:44:56]:
So you’re essentially saying that if you put good resilience in place, then you know that you will never be 100% foolproof. So you could take peace in that. Is that what you’re saying and get working on getting the right pieces in place to enable a certain level of resilience based on certain benchmark. As long as that’s there, a CISO should be able to sleep. That’s what your claim is.
Jagannath Sahoo [00:45:17]:
I was telling. My telling is different. When you go to Dr. tells you are 90% safe, 10% God knows, okay, similarly, CISO cannot tell 10%, 90% safe, 10% I cannot touch. So you all be not there. So you should have proper planning for the 10% because 90% you are putting EDR, you are putting SOG, you are putting PAM solution, PIM solution, all the solutions, everything putting 90% you are safe still 10% you should have your visibility, you should have proper CSPM in place, DSPM in place until that 10% is more critical than anything now because 90% you are doing. We are putting all the tools 90% is getting done. Now
Jagannath Sahoo [00:45:57]:
CISO should focus the remaining 10%.
Sanjog Aul [00:45:59]:
So Steve, in your case, what again, I could ask you exactly the same question. What’s your biggest heartburn of sorts. But is this more the way we are with security right now and since we have kind of figured out, okay, have the zero trust mindset, yes, we will build your resilience and you look at how AI evolves and just react to it or respond to it, not react. Is that what is the life going forward or would you say that something better has to have come for you to feel a little more warm and fuzzy than you feel right now?
Steve Lodin [00:46:31]:
So why do we exist in security because there’s attackers that want to take money or data away from our company. So until you’re able to tell me that all of those attackers that are out there have something else to do and they’re not going to focus on us, our job will continue to be here. We’ll continue until there’s nobody that needs to attack us. So in other words, never. Now having said that, it like Jagannath has said, you’ve got a ton of tools in place, you feel comfortable about your environment. My next fear is all of those third parties that we’ve attached to, either they have software in our environment, they become the SolarWinds equivalent break into that software and you’re in all these different customers, CLIO, Progress Software, Moovit, all of those types of things. I’m worried about not us, but our partners and losing our partners ability to keep our data safe and secure.
Sanjog Aul [00:47:41]:
Leon, you know, I’ve been doing this.
Leon Ravenna [00:47:44]:
For almost 40 years. I know I look like I’ve been doing it for five, but you know, there is that. You know, 30 years ago I woke up at 3:00 in the morning wondering if my backups kicked off. You know, and maybe it’s a personal thing, but I still wake up every morning between 3 and 4:30 wondering, you know, are things good? And the first thing I do is check my phone, you know, is there any, you know, any text message, anything that I missed and it’s always less than a foot from my head. So you know, I kind of disagree that yes, you should be able to be in a position where you can, you know, have, you know, sleep, build nights. But in, in this job there are too many things that can go wrong that, that we’re trying to anticipate for, you know and I think you can build as, as well as you can make sure that everybody understands, you know, what is there, what is it, what are the risk points and then, and then move on. But I, I don’t, I know, at least personally I haven’t gotten a, you know, a straight, you know, eight, nine hours sleep and since I was probably in high school, so.
Sanjog Aul [00:49:06]:
Interesting. So we’ll wrap this up with the first question for you Jagannath, that if you were to look at all CISOs, they have always been leaders and now they’ve been recognized and respected for being who they are and what they are doing right. If you had to give your advice to the upcoming or even current leaders who are in security and they are supposed to support business given the changing environment and the disruptive environment we are in, what would be one nugget of advice based on your experience, which is actionable and which they can use?
Jagannath Sahoo [00:49:42]:
Not only one, I’ll tell four. Always use advanced rate intel model because intelligence is more critical of anything. Do a strong collaborations. Second point is strong collaborations. When you do collaborations what other CISO is doing? What other challenges facing we should learn from them so because this is on job training, you should learn from others fellow, not your failures.
Jagannath Sahoo [00:50:07]:
So first thing is first is third intel. Second is collaboration. Third is proactively work on the IOC. IOCs indicator compromise. Proactively work on the IOS. Different IOC. IOCs used to come from our SOC from different different time through different different intel that is. And last thing I’ll tell you if there is an issue report it.
Jagannath Sahoo [00:50:27]:
Don’t hide it till the time you are hiding it. You are suppressing the issues again and again. So report if you have any issues. So four five things I told one is intel threat Intel strong collaboration with the CISO community and use all the IOCs, IOS and start reporting.
Steve Lodin [00:50:46]:
Steve, I’m just going to agree with what Jagannath said. Participate in your industry ISAC. Make sure that you’re working with your peers. Understand the attack environment and what you need to prepare for in terms of threat intelligence and bidirectionally share that with your peers. That will get you the most protective foundation for your company.
Jagannath Sahoo [00:51:16]:
I just want to add one more thing actually we should know what is the 8020 rule in cyber security. Okay, 8020 rules and 80% vulnerability due to 20% of the systems. 80% attack due to 20% of attack vectors. Similarly 80% alert due to 20% of the system crown jewels. Similarly 80% user security breaches due to 20% of user behavior. So these 8020 rule is very critical that also we use today in day out you should practice 80% incidents happen due to 20% of the negligence also. So we need to strong we should strongly collaborate with other team member peer review. I just collaborate with my manufacturing peer partners.
Jagannath Sahoo [00:52:00]:
And sometime one more thing also I want to add. You should do drill different different drills. Just like you have breach happened. You should do tabletop drill so that your management also will get trained in case of any breach. How they will prepare because what happened now some incident is happening. They don’t know what to do. Who’s supposed to do what. If you’re doing cyber drill regularly, tabletop access and cyber drill.
Jagannath Sahoo [00:52:23]:
It will also help the entire company to know what to do and when.
Sanjog Aul [00:52:27]:
Great points.
Leon Ravenna [00:52:28]:
So Leon, I would close with kind of three things. What are you doing to understand your business and help your business succeed? Number two, what are you doing to help yourself succeed? I just went through a AI governance certification. So I understood what’s happening there. What are you doing to make yourself better and then three what are you doing for your community of cyber folks? Are you there to listen when someone needs to vet because quite frankly nobody knows what we do inside your company and you can’t really talk to your spouse about it. So what are you doing to be there when somebody’s struggling? Are you available to someone to call you and bet for 10-15 minutes? I leave you with those three things.
Sanjog Aul [00:53:18]:
Great. So thank you so much again Leon, Steve and Jagannath for sharing your insights. This is a very important topic and the world is changing so all your points are well taken and I’m sure our listeners would love what you shared as nuggets. So thank you so much again and the folks who watch us follow us, please subscribe to our podcast, subscribe to our YouTube and connect with us. We are here to help you get enlightened and perhaps get some actionable insight. So thank you again. This is Sanjog Aul your host.
You might also find these helpful:


