It is not a matter of “if” but “when” we will get hacked and detection may not be the best prevention strategy. This is the premise used by multiple security intelligence and analytics solution providers as a way to get smarter and proactive about Security. To what degree are these helping? Are these solutions and services any match for resource rich cyber attackers?
Contributors
Transcript
Sanjog Aul [00:00:00]:
Hello and welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com and as always, we invite you to join the discussion on Twitter #Ctrlive and look for the show also as #Security. Today’s topic is Evaluating Security Intelligence And Analytics Solutions and our guests for today’s show are Gary Eppinger, who’s a Global Vice President, Chief Information Security Officer and Privacy Officer for Carnival Corporation. Hi, Gary, how are you?
Gary Eppinger [00:00:29]:
Hey, good morning, how are you?
Sanjog Aul [00:00:31]:
Very good, sir, thank you and we also have Jonathan Klein who is Chief Information Security Officer with Broadridge Financial Solutions. So how are you John here?
Jonathan Klein [00:00:40]:
Good friends and thanks for having me on.
Sanjog Aul [00:00:42]:
Very good. Thank you for. It’s an honor to have both of you on the show. Now we are looking at the newer age of business and the way we are living our lives and security is becoming very important for us. In fact, we are keeping that as top of our mind and trying to find strategies. Challenges are there and we also find that it is not a matter of if but when we will get hacked. So do we have to always working on the prevention strategies better than or more than becoming better at responding to the incidents that happen? If that’s the case, or in either case, should we be relying or banking on security intelligence and analytics solutions that are being proposed? So goal here is to challenge in a healthy way, as a healthy skeptic, that what would it take for us to be feeling secure and how much the tools, technologies, policies and processes will help us and where do we go with this security intelligence and analytics solutions? So that’s as a background.
Sanjog Aul [00:01:44]:
So as a first question, I’ll start with you, Gary. We are looking at lot of incidents happening over the years and media is doing a fantastic job of exposing but also sometimes in a way creating paranoia. What do you think is truly the state of vulnerability we have today?
Gary Eppinger [00:02:03]:
So when I think about vulnerability today, it’s absolutely very critical and changing.
Gary Eppinger [00:02:09]:
We’ve had security incidents, we have security exposures for the last 30 plus years. Where I’ve been in this space, however, there’s a lot more visibility from the C suite all the way down to the guy that’s pushing a broom in the lobby.
Gary Eppinger [00:02:24]:
So it’s not that the issues have got, have grown and got bigger, but they surely have more highlights for those particular incidents as well. As you think about the bad guys today, they are way more organized than they’ve been in the past. They more and more focused on the commerce side of the equation. We started off where it was just taking a heel, and so how can I take a company’s system down now? They’re highly motivated to get revenue from that transaction and or get market share potentially from impacting individual companies. So we shouldn’t be paranoid, but we absolutely need to be concerned.
Sanjog Aul [00:03:04]:
So, John, when you look at this as the state of security that is reported by Gary, where do you think our investment should be because I have spoken to quite a few CISOs and there is always two schools of thought. A percentage of them say we should focus more on prevention. Another is to say, okay, I do not know if there’s a way for us to prevent this at all or completely, so might as well focus on responding to threats effectively. Where do you think the balance is?
Jonathan Klein [00:03:33]:
I think it’s going to have to be a blended approach. I agree with the comments that we’re not going to prevent everything and I don’t think it’s economically feasible. To Gary’s point, there’s a lot of vulnerabilities out there and while we used to deal with what we called scripted kiddies in the past, these guys are smart, they’re well funded, and they have a lot of vulnerabilities to choose from. So blending our approach with both a prevent and not only just detect, but detect and quickly contain is really the approach that we’re going to have to take going forward.
Sanjog Aul [00:04:06]:
Now, if you are to look at Gary set of solutions that we may have tried or maybe beyond solutions to strategies, what is it that you would say would be a plausible and a practical strategy in today’s day and age to prevent such incidents from happening and if they do happen, then respond to them. What’s your overarching mantra, if you will?
Gary Eppinger [00:04:29]:
So overarching. I kind of look at it absolutely from that balanced approach. So you need to be able to detect early and we’ll talk a little more about analytic, but the more, excuse me, that you’re able to use, it helps. It gives you an opportunity to focus in on areas that you may be invisible to you. The tough part of this job and the thing that we’ve seen explode over time, if you think about the number of connections that we have into our environments today, right.
Gary Eppinger [00:05:00]:
There was a time when you could. You could count on a couple hundred connections coming in. Either from vendors or
Gary Eppinger [00:05:08]:
and or from customers now with millions or billions of connections coming in. So how do I determine where do I need to focus from leveraging analytics to fit within that balanced approach? We will Never be able to prevent everything but how do I zero in on the most important highest risk items that I need to be able to react appropriately to?
Sanjog Aul [00:05:30]:
Now if you are to look at John once again, if you had to take the top deployments of solutions that you may have made and where do you see hindsight 2020 which has given you the best bang for the buck?
Jonathan Klein [00:05:45]:
It’s an interesting question. I don’t think there’s been any one tool that was an absolute game changer. It’s really been a blending of a number of different tools because you’re just not going to find that one solution that’s going to fix everything or even fix a bulk of things. I’d say one that would probably stand out would be data loss prevention where not necessarily that it was softening everything but the tool raised awareness for the need to detect information and to make sure certain kinds of information didn’t leave the firm. So the tool was in itself the game changer but the awareness could management was the game changing aspect.
Sanjog Aul [00:06:30]:
So Gary, if you are looking at and based on John’s response that there is not one tool or one strategy, but if you do not have a clear mapping between the strategy that you had, the tactics that you thought of deploying and corresponding solution set, it would be a shotgun approach to say what do you kill or throw spaghetti on the wall to see what sticks. How do you go about handling it better?
Gary Eppinger [00:06:53]:
I think you absolutely have to go after it with a strategy based on a risk based approach. So instead of using the shotgun approach, how do you leverage data to align to your strategy that they will you focus on. As we alluded to earlier, you it’s not about the biggest walls. So it’s no longer who can, who can build the biggest walls that the bad guys can’t get over. If there’s a focus, if there’s a targeted, if there’s a highly motivated organization, country and or individual they may and will find a way over. We’ve started a conversation in our conf in our company and you’re talking to a guy that used to talk about keeping the bad guys out and now it’s about. It’s not if you get compromised, it’s when you get compromised now what are you going to do once you get compromised and more importantly or as importantly, how do you know you’ve been compromised and then so you can react to it as quick as possible. Unfortunately, today so many companies are getting compromised.
Gary Eppinger [00:07:58]:
Don’t find out until a Week or a month or six months down the road and they usually find out by a customer or a federal agency that calls them on the phone and they you’ve been compromised. So it’s a tough scenario.
Sanjog Aul [00:08:13]:
So we have discussed these challenges that you’re talking about which is advanced persistent threat. So, we are looking at those challenges. People may be either directly impacted with these APTs or they could be the source because they could be an HVAC provider or another supplier to a large financial services firm and they could become the source through which or a conduit through which one may get impacted cacked. So John, if you were to look at this whole scenario, this ecosystem, would you think that the security intelligence that we need to garner it has to only be the responsibility of the final impacted entity or this has to be a value chain driven security intelligence because they may not directly intrude through your door, they may come through another supplier store.
Jonathan Klein [00:09:02]:
It’s got to follow the entire chain. It can’t be just the endpoints. It has a security intelligence. There has to be information sharing amongst the suppliers, because if one of my suppliers is seeing something I certainly want them to tell me so that I am making sure I have the proper defenses in place to defend against it. Without it we get caught off guard like a target got caught off guard where, they were hacked through their HVAC provider. Information sharing is going to be very important and it’s not going to just be out of tools. It’s got to be conversations that CSOs have with one another.
Jonathan Klein [00:09:38]:
Conversations CSOs have with law enforcement. Sometimes it’s just good old fashioned legworks. Give you an example of a threat our company faced a couple of years ago and we didn’t use fancy intelligence tool with good old legwork of searching social media, YouTube and Twitter and Facebook to find the threats and then to be able to mitigate the threat.
Sanjog Aul [00:10:00]:
Now where would you call yourself lucky that when you went about looking through social media it could have been seen as a wild goose chase by someone if you had not found anything. So would you call yourself lucky because not every time things will be as explicitly stated out in open which you can just do a google search.
Jonathan Klein [00:10:17]:
I wouldn’t say lucky is the right term. I think is we looked at other channels outside of looking at a security intelligence act for because those tools they do have limitations. They look at things that are already out there. They don’t look at people talking and so you’re looking at multiple sources and you’re sharing that information with your vendors, with your clients so that they’re well aware of the threats that are coming and have a chance to defend those against them.
Sanjog Aul [00:10:46]:
So the key phrase and we’ll take a quick break and we’ll be coming back, but I wanted to lay the groundwork. So the key here is security intelligence. Now that’s the intelligence you want to get through some source. It could be a set of tools or other form of organizational changes or organizational strengths that you may be able to harness. What is the source of security intelligence and where do we stand with respect to that today? What’s the current state of security intelligence that you’re able to get with before the event, proactively and even after the fact so that you can basically track the problem or respond to a problem? Please stay tuned listeners. We’ll be right back and explore.
Sanjog Aul [00:12:53]:
Welcome back. So Gary, I’ll start with you. So whether it is about preventing a security breach or responding to one, perhaps some sort of security intelligence and analytics has to be performed. It may come from a set of tools or a duct tape and shoestring based processes or Excel spreadsheets that you may create yourself but what’s your fundamental vision of a set of solution or a solution for an organization that will work effectively?
Jonathan Klein [00:13:22]:
Yeah.
Gary Eppinger [00:13:22]:
So when I think about solutions, it’s three different paths that I consider and which aligns with our strategy. It’s all about people, process and technology. So if you think about the cyberspace today and how all of the mechanisms and tools and processes and things that we put in place to help prevent incidents from happening and then when it happens, give us visibility so we can react. It’s how do we balance it from a people? So people is how do we educate our employees? How do we educate our consumers that are using our tools and products and services, the processes that our employees use to leverage the system that deliver services for our customers and then the technology. So the technology could be the specific analytical tool or that analytics can come from conversations with other CIOs, the conversations with our vendor community, but it’s for the federal government. So it’s a combination of all of those that give you rich data that can be leveraged and it doesn’t necessarily come from one, it could come from any one of those three.
Sanjog Aul [00:14:31]:
So, John, when you have tried to deploy or you’ve even envisioned security intelligence and analytics type of solutions, the culture, the people processing technology that Gary mentioned, what were the lessons learned along the way? And do you think you are at a point where you say, okay, I’ve got already a good mix which I could use in a most predictable manner to tame this beast?
Jonathan Klein [00:14:55]:
I think it’s still in the learning phase. Security intelligence analytic tools are still very new. They’re very limited. They focus very heavily on things that are out there. So they look for malware that’s running around on the Internet. They look for web pages that are serving up still content. They look for spammers. They do very little in talking to folks on the dark web.
Jonathan Klein [00:15:21]:
They don’t do a lot of putting in that human intelligence. But I think the biggest shortfall is that they don’t understand your business. So you could be getting a lot of data, but unless it’s actually meaningful data that impacts your business, it’s not really actionable data and I think that’s where the shortcomings are with security intelligence analytics solutions. So I haven’t gone in with Boatfeet yet to purchase an analytics solution. I’m looking at various ones. I’m looking at outsourced services as well as in source services.
Jonathan Klein [00:15:55]:
I still rely very heavily on members of my team actually going out and looking for threat. I do work very closely with our users and make sure they understand their responsibilities on security so that they are not creating additional vulnerabilities, but to really jump in full force of any good security intelligence solution. I just don’t really see the value yet until we’re able to come up with a solution that really can understand my business and give me quick actionable intelligence without having to invest heavily in people.
Sanjog Aul [00:16:29]:
It’s interesting you bring up this point about actionable intelligence. So, Gary, if I have a good data crunching tool or even my own people are somewhat churning out data using whatever primitive methods they may have or the modern methods but then it’s a last mile challenge. It’s basically coming down to what do I do with that data, how do I interpret it into something actionable, which is also an intelligent and a creative way to approach a problem. Do you think suddenly we are expecting our own people, the security leaders who have a different set of competencies and skills to develop over the years to convert into a data scientist?
Gary Eppinger [00:17:10]:
What a great question. I would have thought I would probably answer that question very differently 10 years ago than I will today. I would say absolutely. I don’t believe our security engineers will be data analysts and data scientists. However, there’s skill sets, there’s tools, there’s techniques that give them more valuable data that they can leverage, as John just alluded to do their job better so they can focus in on a specific area because they know the business way better than anybody else and they know what’s important. They know the risk tolerance of the business and they know the data flows. We’ve started down this path of using data analytics in our environment from a marketing and from a consumer perspective and when we jumped into that space, it allowed us visibility into places that we hadn’t thought about in the past
Gary Eppinger [00:18:04]:
and so I think of it very similarly from a security perspective. It will give us visibility into things that we may not have visibility to today. So, we put in tools in our environment that allowed us to start to focus on things that we didn’t know was actually going on as part of normal day to day process that was, beneath the sheets, but allowed us to now have greater conversations with our business partners around business practices that may been okay in the past, but no longer okay as we think about increasing the level of security, increasing the level of control in our environment. So let us drive business processes in a more secure manner.
Sanjog Aul [00:18:47]:
John, do you think we have the necessary academy, if you will, which will churn out better security leaders who can think beyond not security leaders per se, but security workers who would have that overarching business insight coupled with understanding of what security works which and further flavored with the data science so that they can really produce something which the whole organization can react to, invest towards and get the benefits from.
Jonathan Klein [00:19:17]:
I think we’re churning out some, but I don’t think we’re churning out enough. I’m finding it, man. Sure, Gary’s probably having the same problems just finding good qualified security people I think we keep just feeling from each other, I think that it’s really not a matter of having good security people within data scientists, but reducing the footprint of the data that we’re actually looking at. I’ll go back to the history of it all. In the late 90s, intrusion detection system came out and I remember was at a client and gung ho. I installed it, got it, I got everything configured and I started looking at the data and I was, wow, I was seeing like all these incidents popping up and I was contacting people, hey, I’m seeing unusual activity from you. What is this? Or can you please stop it? And what I found after a couple of weeks was that was all I was doing, was spending eight hours a day going through intrusion detection logs and tracking down incidents and not getting any of my other work done. Then we tried to come out, the next evolution was security incidents, event management, and we shrunk it down a little bit, but then the amount of data grew, we ran into the same problem and now we have big data security analytics and we have data scientists and we try to squeeze it down further
Jonathan Klein [00:20:28]:
but the data has grown so large that it’s become an unmanageable problem again, and I think until we’re able to break that cycle and find ways to reduce the footprint of the data that we have to actually look at. So if it’s by the time people like Gary and I get this information, it’s true actionable items that we need to be worried about and go execute on as opposed to the myriad of false positives that keep popping up and I think that’s when the game finally changes and I haven’t seen it arrive yet. I don’t think any of the vendors get it yet. I’ve been looking for it for a couple of years. Until they do and until they’re able to help us, I think we’ll all continue to struggle with this problem.
Gary Eppinger [00:21:10]:
I absolutely agree with that comment and you’re seeing more and more convergent from vendors. So on the software side, where they’ve been acquiring each other, you also seen hardware companies just started to get into the software space from a security side but as far as that enterprise solution that’s truly going to solve this problem, we’re moving in the right direction, but we’re still far away from having the right solutions out there.
Sanjog Aul [00:21:36]:
If I were to go and go ahead and evaluate what’s available today in terms of solutions and how does it match back to what, what we are attempting to do is that like a one size fit all type of solutions available or is there some customization possible? Gary?
Gary Eppinger [00:21:53]:
Yeah, no there’s absolutely a necessity for optimization and customization right there will, there won’t be a one size fits all because you think about the mere differences between a bank, the banking industry and insurance industry and the cruise space as an example, dramatically different business processes which drives a different configuration that’s going to be need needed from company to company. So what’s important for us will be dramatically different than a bank. So you think about some of the things that we’ve seen some success and I would say some early success in the banking space. So if I go to use my credit card in three different states, within 15 minutes of apartment my phone ring and they say geez Mr. Eppinger, we’ve seen some transactions on your account that doesn’t meet your profile and in fact there, it’s impossible for you to be using it three different states at a time. So if we stopped them. So that’s an example where they’ve taken a lot of data to be able to focus into some activity reactive mode, but focus into some activities that just didn’t make sense and they could stop it and prohibit it from going through 5 years ago, 10 years ago, because everything was done batch and everything was done after the fact that would have, those transactions would have been through before somebody knows them as being an issue.
Sanjog Aul [00:23:15]:
So let’s look at security intelligence and analytics solutions which are being offered and we will not take names so that we make sure we are objective in our evaluation. What do you think is the level at which they are being operated? Is it like a one science? They somehow sniff through all the different traffic on your network and perhaps match it up to some heuristics engine where they are collecting data of the type of breaches and signatures and sending it back. It’s like, would you call this like an antivirus on steroids? Is that what is John?
Jonathan Klein [00:23:50]:
I don’t think I’d call it an antivirus on steroids. Look, there’s vendors out there that have solutions that focus very heavily on data collection from various intrusion devices, various firewalls that are out there so that they’re seeing traffic that’s already out there and then the rest of the world, hey, we’re seeing this traffic. You have other companies that are going out and going through the dark web and they’re actually gathering human intelligence by talking or infiltrating these underground groups to get a sense of what’s going on and providing intelligence that way. What we haven’t done is taken those two different kinds of solutions and married them together. How do we take what’s out there and tie it to a particular group’s campaign and understand what their focus is so that we can actually look at, okay, what industry are they targeting? How are they trying to target that industry so that we’re not just chasing everything? And that’s the problem is we’re getting so much data, we’re chasing everything.
Sanjog Aul [00:24:47]:
When you say that you’re getting so much here, go ahead.
Jonathan Klein [00:24:50]:
The vendors are trying to do everything for everybody because they can’t just build a box for a particular industry. So the struggle that you face as a customer when you get one of these solutions is how do I tailor it down and configure it? And what’s my strategy around that? To be able to get reasonable data out of it so that I’m not just getting in and dated with a lot of unnecessary events, but at the same time I’m getting some value and that falls down back to the I don’t have the human capital to be able to do that effectively and we all struggle with.
Sanjog Aul [00:25:21]:
So let’s take a quick break when we come back. John, I’ll come back to you on this one because you interestingly mentioned that the domain knowledge is very important for a security solution to be effective. Typically for the rest of the world, security has mostly been what does this mean as a technology or even in terms of risk and at risk level? Yes, you’d have to understand the domain, but when you are trying to use a tool or a service, would they necessarily be able to find the level of domain knowledge or be able to utilize when they are not embedded in the organization? Is it asking for too much from a third party provider and instead take the responsibility ourselves? Please stay tuned listeners. We’ll be right back.
Sanjog Aul [00:27:35]:
Welcome back. So we are talking about domain knowledge here or someone who really lives the business. Now we know practically every CISO and their team has expressed this challenge where the business doesn’t really open up and tells them what do they really want, what their crown jewels are and the security workers are not truly as embedded in the business. And so how do we get this whole domain knowledge be offered to a third party provider, even to our own people for them to be effective?
Jonathan Klein [00:28:06]:
I think that the barriers providing that freak out of the barriers between the business and security in the last several years so definitely been dropping and we’re getting that domain knowledge. The challenge we have is a lot of our organizations aren’t big enough to be able to properly staff up a group with those people with the domain knowledge to be able to effectively use these analytics solutions. There’s 24 by 7 solutions. Hackers don’t wait till business hours to try to break in. They typically try to break in in your overnight hours. So for anything to be effective, got to be 24 by 7, which means somebody’s looking at a 24 by 7 last I checked. I know companies are trying to get us to work 24 hours a day, seven days a week, but it’s not really realistic. So we have to hire enough people to be able to get that adequate coverage.
Jonathan Klein [00:28:52]:
It’s said to a large organization they can probably do it. Medium sized companies, smaller companies, there’s no way it fails and so when you have out there the opportunity for these managed security service providers, they’ve been out there for years. I used to years ago, Shell Managed Security Services. It’s a very good play in the monitoring space. So the MSSPS can build up those analytic functions and then you get them to provide you three or four analysts who are assigned to your account but sit down with you, learn your business, at least learn enough of your business so that when they’re shifting through data, they’re not giving you things that are just completely immaterial to you. They’re giving you things that yes, you’re concerned about.
Jonathan Klein [00:29:38]:
This particular threat pertains to you and that’s where this whole industry needs to go for security intelligence and analytics to be effective for everyone. I don’t have the deep pockets of the big banks out there to go and build all that myself. It’s just not very cost effective. So I want an MHSC to do that for me and I think it’s realistic for them to have those kind of solutions with that domain knowledge.
Sanjog Aul [00:30:03]:
So, Gary, interestingly, when you invite procurement to get an MSP or MSSP here to deliver services, they should get sharp with their knives and they basically, the vendor wants to get sharp with the knives and the procurement wants to get sharp with their pencils to bring the cost down and now on the other hand, you want these people to really embed themselves in the business, learn all the business knowledge and then become much better than you could ever be yourself. What are we? Do you think this is, first of all, the way we are structured to acquire services of any third party and the way we incent them. Is there a model that would realistically work based on what John is promoting? It’s amazing. If that can be done, it will be awesome if it can be done but what do you do with the costs and other challenges with respect to us controlling the cost and how any services like this is procured?
Gary Eppinger [00:30:56]:
Yeah, it was great question. I think it’s a tough dilemm. So if you think of it from a company perspective, they want the most service at the cheapest price and the vendor wants to provide great service, but also they have to be in a position to be able to make revenue and make their profits also. So as you bring sourcing and you bring the legal team into the equation, it gets way more complicated and you start looking at the benefits and costs and the risk and those equation but at the end of the day, I like to pull back the onion and say, what are we trying to accomplish and what’s the best mechanism for us to be able to do that? How do we improve our level of security and then allow it to be done in a most effective way, cost effective way, for both not only the vendor, but also the company. Because what you don’t want to do is have a price so cheap that the vendor can’t put their top performers on that particular client engagement, that they can’t spend the time, as John just alluded to understand my business because if they can’t, then they’re just giving me, going back to that shotgun effect. They’re giving me so many false positives that I can’t be successful. So when that event that I need to be focusing on comes through, it’s mirrored with all of the other events that I don’t need to be spending time on
Gary Eppinger [00:32:13]:
and so I miss something. So you end up missing the thing that you want So I think it always becomes a dollars and cents game but you got to continue to pull back the onion to figure out what’s important and how do I kind of get there, what I like to leverage and not only external from a vendor perspective, but also internal business engagement. We throw that term around pretty loosely. Phil, but how do you drive business engagement and what’s the value proposition around it? The value proposition allows you to truly put better solutions in place because you understand your business better. So how do I give that knowledge and data and value to my vendor if I’m going down that path and outsourcing that component of it, or if I have internal resources that’s focused on it, how do I ensure that they have that capability? And we try to spend more time with our business partners. So if you.
Gary Eppinger [00:33:08]:
Supporting the marketing team, and from an IT perspective or an IT security perspective, how do I carve out time? So I’m spending time with my vendor, sorry, with my business partners. One of my best lessons learned from my life back in the GE days was if you really, if you think you’re really good from a security perspective or you think you’re really good from an IT perspective, go spend time with your business partner. He’ll tell you everything that you did wrong when you delivered that particular tool. They’ll tell you how to use it today versus how you built it. They’ll tell you all of the great capability, the features that you built, the time to build into that particular tool that they don’t even use. So all of that means to me is we’re not spending from an IT and IT security and a risk management perspective.
Gary Eppinger [00:33:59]:
We’re not spending the appropriate amount of time to understand what the true needs are from a business perspective and building that capability and only that capability into our tool.
Sanjog Aul [00:34:12]:
What a great response. So John, when you look at Gary’s response here, what comes to mind as the next set of steps which you would take, besides getting the actionable intelligence to really make sense of this whole intervention in terms of security prevention or security breach prevention as well as response.
Jonathan Klein [00:34:31]:
What’s going to be that continued engagement with the business? To Gary’s point, businesses understand business risk. They understand operational risk. Security risks is still fairly new. Yes, you’ve been facing breaches for the last 15, 20 years, but CSOs have only been at that soft level for maybe the last eight to ten years. Security risk is still very new and so it’s going to be that constant education of your business focus on understanding security risks and how these tools help reduce security risk, which is inevitably helping them reduce their business risk and we’re just going to have to keep having those conversations and keep educating them until it becomes very much ingrained in everything they do for their perspective. The ingrained operation through every aspect of their business.
Jonathan Klein [00:35:22]:
Security now has to be ingrained in every aspect of their business.
Sanjog Aul [00:35:27]:
So Gary, given the solutions available and whatever the current state may be, do you think as a leader, have you been able to get your team to use the security intelligence and analytics solutions and processes and then also been able to harness the intelligence that it is producing or the actionable intelligence that it’s producing? Where do you think we may be missing the mark or where you feel I wish we could. What’s your wish list, if you will, in that context?
Gary Eppinger [00:35:57]:
In that context, I got a huge wish list. I would say we are, we’re in that. If you think about from a maturity perspective, we are not at the optimal level. We’re not at that set five level from a maturity perspective, we’re in that three and a half to four level. That being said, if you have to determine what is adequate for your company, for your industry, for your maturity of your business, for what’s going on from a business process perspective, are you in an acquisition mode? Are you divesting of different companies, are you looking at new markets, are you growing or is it contrasting? All of those factor into what may be important at that particular time from a tools and the capability for the business and for the security organization to fit. I would say we are leveraging the data.
Gary Eppinger [00:36:47]:
There’s way more data than we can get to every day to look at but we’re looking at the most important things today and I think the other component is it’s a model that’s changing, right? So our business model is changing demands on them from a customer perspective is changing. The things that we’re doing today we weren’t thinking about necessarily a year ago, two years ago. So the closer we get to a higher level of maturity, we end up taking three steps back because now we learn more that we didn’t know before and our business change. So three months, six months from now, we’ll be doing dramatically different things than we are doing today. So therefore we get better and we get worse all at the same time.
Sanjog Aul [00:37:34]:
So John, if I had to offer you an option to go out and pick the best of breed solutions which will provide you and that solutions could be built internally or you go outside to a solution provider or you go to MSSP. What would be a healthy portfolio you will develop in order for you to achieve that desired end state?
Jonathan Klein [00:37:59]:
Well, I tend to lean forward for my company. Not all companies are the same. For my company, I tend to lean towards a managed security service provider to provide the basic tools, the basic analytics, provide them some domain knowledge and then build some of the extra teams in house to be able to really leverage the tools but at the same time, I’d also want to look at somebody who has a human interaction, engages with some of these groups on the dark web to infiltrate, understand where they’re coming from, what their campaigns are so that I can take that human capital and apply it to this technical capital that I just got and really get a better risk picture and then it’s engagement with the business leaders so that they understand the data that I’m providing them, say these are the threats to the business. You may have to look at changes to some of the business processes you have. You may have to rethink some of the business opportunities you’re getting into or at the very least just make sure you’re factoring in those threats into whatever strategies you’re moving forward.
Sanjog Aul [00:39:09]:
So John, your response is basically assuming that let’s see who can do the best they can versus marching everyone towards a desired state which is set in stone. Do we have to continue to live with this fact as if we were weather meant to say we will predict weather in a certain fashion? If it doesn’t happen, we still don’t lose our job.
Jonathan Klein [00:39:33]:
Risk management is all about prediction, It’s probably not much better of a science than weather forecasting is. We try to make the best guesses we can. The more data, the better data. Shift into the more data, the better data we have. I think the better guesses we will make and you look at a hurricane prediction when it’s days away from you, they have no idea where it’s really going to go. A couple days out, they have much better data that’s telling them pretty much where they think the storm is going to go. It’s going to be the same way in our business.
Jonathan Klein [00:40:00]:
As we get better data, we’ll make better predictions. It’s never going to be perfect and we’re still going to be on the hot feed for them but at least we have the comfort of knowing we had better data to provide our business leaders better information on how to make decisions.
Sanjog Aul [00:40:16]:
Well said. So let’s take a quick break, listeners. We’ll be right back so Gary, when we come back, we should actually see if security intelligence and analytics solutions are primarily to prematurely or proactively, not prematurely proactively detect what may be going on versus making you even more responsive. So is that only contributing towards being proactive or is there is a possibility for it to make us better at responding to the threat so that you’re looking at the whole security activity portfolio and then apply this whole security intelligence and analytics set of solutions? Please stay tuned listeners. We’ll be right back.
Sanjog Aul [00:42:25]:
Welcome back. So Gary, we can buy or develop solutions related to security, intelligence and analytics. Is that primarily for prevention or also for reaction to those threats, the breaches, when they happen?
Gary Eppinger [00:42:38]:
If you listen to some of the vendors, they’ll talk a little bit about it being a preventive tool. These are the things that it can stop. These are the things we can help you stop before it happens. I contend that it’s just opposite. Again, we won’t be able to stop everything. Things will come through our environments and through our protections that we put in place. I look at it as a tool that gives me a capability to focus and react more appropriately. So as we talked about is, is how do I know something happened and then be able to react to it appropriately with the right speed and intensity to recover our environment and, but I think it’s a balance that we’ve had over the last several years of looking for that perfect solution, that perfect tool that’s going to prevent everything from ever getting into our environment.
Gary Eppinger [00:43:29]:
And I contend there is no perfect security and there’s no perfect tool out there that’s going to do everything.
Sanjog Aul [00:43:35]:
So if I were to go back to you, John, and ask you this question about whether you are using other tools, of course and you may even deploy MSP, MSSP and these other security intelligence analytics solutions. What type of readiness do you need or preparatory work that you need at an organizational level before you can take them on and really make best use of them?
Jonathan Klein [00:43:57]:
So actually, if I’d like to add on to Gary’s comment. I think the tools can be used both for react and it prevents but in this way, if I have similar services running within my company and I have something happen with one of the services. So to Gary’s point, I’m reacting to an incident that occurred. I can still take that data and say, wait a minute, I have two other services in my company, citizens, same kind of services. Let me go look at those and make sure I’ve got the right defenses in place before something does happen. So potentially I am using that as a prevention but Gary’s absolutely right.
Jonathan Klein [00:44:32]:
You can’t just market these tools as it’s a pure prevention. It’s mostly a react.
Jonathan Klein [00:44:36]:
It’s some preventions but then how you use the data right can help you determine how much am I reacting to and how much can I try to prevent and then your question to me directly, how do I get ready for all of it? You have to come up with the right strategy. I have to understand what are the most important assets I have in the company. What are the say, hey, I hate to reuse the term, but it’s a term used all over the place. What are the crown dual? Those are the things I need to focus on. Those are the things that I need data on. Those are the things that I need the better controls over
Jonathan Klein [00:45:08]:
and that’s where I’m going to focus my attention. To be prepared for an MSSP, I have to have the strategy. What am I going to send them? What am I going to have them look for in the event? How are they going to understand my business? So they’re giving me the right event. How are they engaging me when I actually do have events that I have to action on? What other information will they be able to provide me as I’m doing my investigation? How do they fare within the industry? Are they in the top corner or are they an up and cover? So you have to feel, at the end of the day, you have to feel that you have comfort and trust in the organization that you pick to be your managed security service provider because you are at the end of the day giving them a lot of sensitive information about yourself and you have to feel comfortable that they are going to provide you that real actionable data that you can move on and that they will be your partner in investigating anything that happened to the organization.
Sanjog Aul [00:46:03]:
That’s a great point. So Gary, one is of course John’s view of using MSSP and using them to their maximum capabilities so that we get the value. Now we would also have quite a few companies who would not want to get that outsourced approach to security embedded within their organizations. They want to build a talent within and talent is one of the bigger challenges with most CISOs face. So now you’re talking about helping these individuals come up to speed where they can interpret data, make sense of it and convert that into some actionable steps and even refine the strategy related to security. Do you think such animals exist today? And what are the challenges in terms of attracting them, retaining them and even training them? Because what you’re trying to train them on that science is literally unknown because that’s ahead of the curve.
Gary Eppinger [00:46:51]:
Sanjog, I think it’s a huge value in developing either from your outsourced vendor as well as internals that that type of resource when they’re truly understand your business can leverage specific tools. They have you focus in on where the true problems are and it didn’t help you drive those right solutions and I think one of the issues that you run into as you develop those folks is how do you continuously challenge them and how do you retain them because there are so few of them. They’re highly thought after. Those are the guys that you have sitting in a corner in dark room that does a lot of analytical stuff that you don’t let anybody else know, that you you have working for your organization because you don’t want anybody to steal them. You don’t let them go out to vendor shows and talk to anybody because you fear that they can be detached away from you but on the other hand they have to be able to have those dialogues with their peers as well as with the business partners to be successful. So I think it’s a tough dilemma of figuring out how do you develop them, how do you continue to engage them, challenge them, give them meeting assignments, but also keep them in that special place that only their delivering that value for your company.
Sanjog Aul [00:48:08]:
When it comes to the type of leaders that we have to develop, which is like people at your level, not everyone thinks like you don’t have all the clarity. What do you think needs to be done so that other organizations, maybe your organizations are lucky to have you as your respective leaders. In those organizations, but there are many who are struggling. So what’s your message to the rest of the community out there who would essentially will be able to, as a result, benefit from what was discussed today, the security intelligence and analytics solutions, build the right type of team and be seen as winners, starting with you, John.
Jonathan Klein [00:48:47]:
So I think the key thing is not to just jump out and buy gold or as you could, I think earlier, shiny toys, that you have a person in house who has a good understanding of the business level of security. They have a good understanding of the technical side of security and that you build a good, solid plan on. What are you trying to protect? How are you going to protect it? And what kind of tools do you need? What kind of people do you need? What kind of services might you purchase? It’s very important to have a good plan. It’s very important to have a knowledgeable executive who understand the nuances of security and that they can help guide the company into executing on that plan. Because it’s very easy to just go out there and spend a lot of money on a variety of tools and then end up with getting no value out of it. It becomes what we call euphemistically in the industry of shelfware. We don’t want to be purchasing shelfware.
Jonathan Klein [00:49:47]:
We get way too much of that on our shelves. So, but a punchline have a good security person in place and have a good plan in place.
Sanjog Aul [00:49:57]:
All right, A short answer, Gary, from you to top it all up.
Gary Eppinger [00:50:00]:
Yeah, so short answer. I don’t know if I have a short answer, but I would say we’ve done a pretty good job from a technical perspective of developing security practitioners.
Gary Eppinger [00:50:09]:
We need to pick up some of those really good ones and move them out of security, put them into the business, put them into other areas of it so they can learn the business even further and then be able to leverage their skills from a security perspective in places that you need them throughout the business.
Sanjog Aul [00:50:25]:
What a fantastic discussion today. On behalf of the show and our listeners, I’d really like to thank you both, Gary and John, for sharing your thoughts on how organizations can perhaps leverage the security intelligence and analytics solutions, develop their team and their leadership to get to the end goal, which is to make an organization grow, innovate, but while all along manage risk. Thank you so much.
Jonathan Klein [00:50:50]:
Thank you for having him.
Gary Eppinger [00:50:51]:
Thank you. Absolutely enjoyed it.
Sanjog Aul [00:50:54]:
And listeners hope you enjoyed it. Please like us on Facebook, search for CIO talk radio and be sure to follow us on Twitter thank you again for listening to CIO Talk radio. This is Sanjog Aul your talk show host till next week. Take care and God bless you.
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
- How to make IT security everyone’s business?
- How to Build an IT Security Team
- IT Security: Future Perfect?
- IT Security: How much is enough?
- Securing Business Growth with Cybersecurity
- Cloud security, cost, and culture: Technologies Concern
- Ensuring Digital and Virtual Healthcare Security
- Embedding Security in Technology Capabilities
- Security and Agility – Tips for Getting the Best of Both Worlds


