Cybersecurity Leadership

From Peanut Butter to Surgery for Better Security

From Peanut Butter to Surgery for Better Security

Spreading the same controls across all business areas hasn’t proven to be effective for security management. Neither has planting people, whether your own or a managed service provider, and passively waiting for the alarm to go off. How can you as a CISO be surgical in your approach to security operations to proactively safeguard the crown jewels?
Contributors

    • Jerich Beason, Chief Information Security Officer, Epiq
    • Leon Ravenna, Chief Information Security Officer, KAR Global
    • Jake Margolis, Chief Information Security Officer, Metropolitan Water District of Southern California

Download Podcast
Apple Podcast, Google Podcast, Spotify, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript

Sanjog Aul [00:00:23]:

Hello, and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com, and the topic for today, from peanut butter to surgery for better security. So what do I mean by that? Like peanut butter that you would apply on a slice of bread, would spreading the same controls, security controls across all business areas, would that be really effective for security management? When you are trying to plant people in your security group or you are getting a managed service provider, could you just wait and passively do that too, and wait for the alarm to go off? Would that really help you with security management? So all of that has to be discussed. So what the point that we are trying to make is move from a peanut butter approach to a surgical approach for better security. So easier said than done. That’s why we want to have a discussion among the 3 stalwarts in the security field. Jeric Beason, chief information security officer with EPIC, Leon Ravenna, chief information security officer with CAR Global, and Jake Margolis, chief information security officer with Metropolitan Water District of Southern California. Hey, Jeric. How are you?

 

Jeric Beason [00:01:44]:

I’m well. Thanks for having me.

 

Sanjog Aul [00:01:46]:

Great to have you, and hey, Leon. How’s life there?

 

Leon Ravenna [00:01:49]:

It’s doing great here in Indiana.

 

Sanjog Aul [00:01:52]:

Awesome. Awesome, and Jake, how’s things?

 

Jake Margolis [00:01:56]:

Things are good. Busy, but good.

 

Sanjog Aul [00:01:59]:

Alright. I like that. I like the sound of that. Good. Busy. Yeah? So okay. So let’s, Jeric Beason, why don’t we start with you? So we always traditionally built security as a shared function, a shared service almost, but then when we have different business units and they have their own sets of crown jewels and all their own sets of, I’d say, the intricacies of their business, which could create different levels of risk. With all of that changing day by day because of the volatility we have in the business environment, do you think we would be good in going ahead and broad stroking security in any way?

 

Jeric Beason [00:02:46]:

No. I think there can definitely be a case made for going from a centralized to a decentralized way of doing security. I don’t know if we can do it 100% decentralized, but for example, things like the security operations center or maybe security engineering, that needs to stay at the center because it is going to be homogenous in many ways across the environment, but something like vulnerability management or application security, it could be a case made because the applications are tied to the business. They’re tied to those operations, and in the world of DevOps, the lines are blurred even further. We want the developers to be empowered to self gather within those guardrails. So in a case like that, it would make sense to go with a more surgical approach.

 

Sanjog Aul [00:03:30]:

So, Leon, when you have tried to apply at your organization, how are you approached by the top people, like the CEO, etc., to say, okay, help me with security, but they would not care how you approach the people at the business unit level. They would say, give me good security, and they will say, I’ll give you 1 budget, and I will ask you to give me 1 metric, but then when you come to your business unit level, do you just also broadstroke the same way that I’ve got 1 budget, so I’m gonna treat you all the same?

 

Leon Ravenna [00:04:04]:

Yeah. It’s interesting. I have 17 lines of business, and the smallest is 15, the largest one is several thousand people. We do a lot of the same security controls. So for instance, cloud security posture, I use the same tool and tell everybody the same things. We have 4 main development lines for about 500 developers, and so I build for them a very targeted security posture every month that gives them all of the data that we can, whether it’s individual or it’s kind of homogenized across the organization. So we end up doing a little bit of both, and more looking at some of the tools that we’re doing to be very targeted. So one of the things we’re looking at right now, kind of cutting edge stuff, is application reverse engineering. So building out a graphical view of the team’s applications, really pretty cool stuff. Things that the dev teams may not have seen. So we start with everything kind of from 1 central and then bring it down into very targeted tool aspects of what they can best use.

 

Sanjog Aul [00:05:17]:

So, Jake, when you look at your world, little different because Jeric and Leon come from different walks of life, if you will, on how they’re handling things. The whole security mandate which comes from the top to, hey. You secure my whole fort, but there are a bunch of different rooms which have their own sets of complexity at the business unit levels. When you look at your organization, can you realistically broad-stroke your security and still be effective?

 

Jake Margolis [00:05:50]:

Well, the short answer is no. For anything, I think we kind of all agree on that, but sometimes there are some broad brush stroke initiatives that are universal security controls, and I think we’ve all been kind of saying that in different ways. For example, one of the things that we look at in our environment is we implemented smart card authentication across the board, and that was a broad brush stroke kind of initiative. There are applications that we had to figure some things out that are workarounds for them, or how we would apply some compensating controls to work around that, because not everything supports that level of authentication, but given what we’re trying to safeguard, and how we wanted our systems configured, we took that; it was a surgical requirement, but we took a broad brush stroke approach to applying it, and so I think, strategically, you can’t have broad brush strokes. I mean, you have to kind of know what it is you want to protect, and some of that really kind of comes down to understanding your risk profile as an organization. A lot of it is there are threats out there every day from all kinds of organizations to different lines of business. Then your organizations may have different risk profiles matched to a particular threat, but you also can’t go down every rabbit hole to defend against every possible threat, every possible risk. So you have to do some canvassing of, okay, what’s going to give me the most bang for my buck? But there’s still a strategic way to look at that, and so that’s why I don’t like using the term broad brush strokes for things that are wide sweeping, but sometimes you do kind of have to take a step back and say, well, I know that this threat actor, this particular type of threat, watering holes, for example, represent a way into the networks if not properly managed — at least the endpoint not being properly managed, or other compensating controls not being properly managed — could represent a massive compromise on the system from something that may have been relatively benign, possibly, depending on how you’re looking at it. Or dealing with phishing campaigns and those kinds of things, and so I think it really does come down to what it is that you’re trying to do from a strategic perspective, and that should always be a surgical approach as far as I want these particular things because they will help me reduce that risk profile as I work towards my security roadmap completion.

 

Sanjog Aul [00:08:44]:

So, Jeric, if it was you and you had a carte blanche, how would you handle security? Would you go surgical all the way?

 

Jeric Beason [00:08:52]:

Short answer is no. We as CISOs, we’re managing scarcity. We have a limited number of resources and an exponential threat. Dividing an already insufficient number of resources could result in an even lower quality outcome across the board. That being said, this is really an organization dependent conversation, and it really depends on the business model, the size of the team, funding available, applicable regulations, and so on, or even the uniqueness of the products that are out there. In most organizations, you can easily make the argument that a portion of security should be surgical, but how much of that is gonna depend on some of those other factors?

 

Jake Margolis [00:09:34]:

Yeah. Definitely. First of all, there are a couple reasons why politically, internally, somebody’s gonna open up the checkbook. You want to be a good steward of that money. That’s just being a good human, but if I had that kind of carte blanche, I think that I would take a very specific approach to what’s my risk profile, and what is it I’m trying to protect against from my particular sector, or for the lines of business I’m protecting? What are the threats to those lines of business? What’s their exposure? And can I reduce that exposure and still have some strategic banks in my book across the entire enterprise? Because then you can get a little bit more surgical if you need to, but the more risk you can reduce, the better off you are.

 

Sanjog Aul [00:10:26]:

So, totally take your point, Jeric. So Leon, if you were to propose a formula, and I’m sure it’s not easy to put a formula to something like this, but a way an information security officer comes in or just does reevaluation, and comes up with a way to figure out how much surgical can I go? What would be those parameters? And let’s talk specifics. I know it depends on a lot of factors, but what would you have produced if you could?

 

Leon Ravenna [00:11:01]:

Sure. Yeah. I mean, if you’re talking on unlimited budget and stuff like that, first, I’d have to pick my jaw off the floor, but really, what I would look to do is tailor for each business unit. What more money and more resources allows you to do is tailor the program within the same set of constructs, but tailor it to the individual development team. For instance, I said I had 17 business units. Some of them are very small, and so how can I help them get to the same things? The targets that we’re looking at are the same. We’re still looking at OWASP. We’re looking at CIS. Those things don’t change, so you can’t really get out too far on those, but what I would look to do is take the program and tailor it very specifically to the dev teams and the persona and the culture of those dev teams. That’s what more resources allows you to do. It allows you to be more surgical on how you do it, but it’s delivering the same set of services, very much tailored to those teams, those businesses.

 

Sanjog Aul [00:12:18]:

Now when we are looking at, so I’ll come back to you, Jake here. Which ones would you feel you would customize or tailor your program for overall? Which departments, because at the end of the day there are only so many departments you can have, right? We come down to HR, finance, etc. If you were to do a quick rundown on these departments, and if you had to say, I would design a security program for this department this way, would you find a pattern, or have you found a pattern which you could share that, okay, this particular department will handle that, and this kind of security approach serves it best?

 

Jake Margolis [00:13:02]:

That’s actually a really good question because you do kind of have to, as Leon kind of stated, if you had the budget, you would want to have a tailored approach, and you have to take a tailored approach whether you have the budget or not. We live in two different worlds where I’m at. We have this massive industrial control system that we use to move, store, treat water, and a lot of people depend on the service that we provide. The considerations around something like an operational technology system are going to be vastly different than what you would put around, say, an HR system or a payroll system within HR, more specifically. So you have to understand what your overall desired end state is as far as a common set of controls. Again, I like that we don’t get too far from CIS Top 20, or we don’t get too far from OWASP. Typically when I take that approach I look at it and say, well, do you have an understanding of the threat or the risk to the organization? Most of us have an appreciation for that, but on the other side of that I always look at how am I going to respond to threats? What’s my resiliency? Instead of doing precise cookie cutter controls for every organization, I start with my security controls around: do they give me an ability to detect, identify, and respond? Do they give me those abilities to contain threats when they hit the enterprise? I kind of go into it with a little bit of a gloomy approach; I like to be cautiously optimistic, but I’m always a little bit gloomy because I look at it and say the bad thing is going to happen and that’s unavoidable. So why don’t we start understanding how we’re going to do that. With my tailored approach to organizations I’d like to understand what’s the best way to communicate incident response type activities and mitigation through those organizations, and understand what their high profile targets are within those organizations. That’s how we focus our resiliency efforts around those high profile targets for business continuity, disaster recovery, and general operational isolation, because sometimes you can contain systems and still give them some level of operability, depending on how critical the system is and what that risk is to the enterprise. So I think that’s how I look at that. That’s my tailoring, my tailor’s toolkit, always kind of built around cutting the pattern out for the organization, but there is no one approach. Every department is a little bit different and they have different concerns, but you can also have common tools that can meet multiple concerns. You have to have a more robust toolset, and maybe a more robust administrative control approach to allow for customization for the organization. I don’t want to oversimplify and say you’d have a firewall for finance and something different for HR, but the fact is you would have different technical controls, and you could do it through the same platform solution. It again comes down to resiliency and your ability to detect, identify, respond, and contain threats when they occur.

 

Sanjog Aul [00:16:48]:

Let’s take a quick break, listeners. We’ll be right back, and Jeric, when we come back, I’d like to pose this question about one is that you want to do it, like the intent is there, maybe there is even budget for you to play a little bit and do some customization, but what are the constraints and the challenges which you anticipate when you want to go surgical? Please stay tuned listeners, we’ll be right back.

 

Speaker 0 [00:17:26]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Jake Margolis [00:18:23]:

Welcome back.

 

Sanjog Aul [00:18:24]:

So, Jeric, we all have good intentions, and when we are lucky, we also have the funds to play with or to use them to implement good security programs, but since we are talking about moving from the broad stroke or peanut butter approach to surgical, and if you have the resources, there could be other systemic challenges or other challenges which could hold you back. What would you say those are as you live this?

 

Jeric Beason [00:18:52]:

Yeah. So if you’re going the approach of going surgical, you are being much more methodical within each individual business unit or division that you’re going surgical in, and the risk of doing so is you lose some of the benefits of having that central function. So I’ll give you a good example. I can define a cybersecurity strategy for my organization, and it can be business aligned, but if those divisions have their own individual unique strategies, then my strategy may not completely align. So there’s a possibility that the things that I put in place, the things that I prioritize as an organization may not be priorities within those individual business units. I’ve worked for an organization where, overall, confidentiality and integrity is what mattered most, but a piece of our business was tied to the education sector and was tied to the health care sector where availability is more important. So if I put all of my controls from a confidentiality or integrity perspective and I prioritize those and I compromise availability, it may be good for the majority of the organization, but not the parts that I may need to go surgical on. So that’s one thing to keep in mind. Another thing to keep in mind is if I do completely operate from the outside and not from the center, I may not have consistency in the quality of the resources. If I train, if I develop, and so forth, and these are my people, then I can develop them the way that I would want them to be developed, but when you move to the outside, then there’s a possibility that those people may not develop the same way. They may not have the same nurturing and growth opportunities as you may have in the center. So I’d want to make sure that we find ways for them to still feed from the center even though they’re supporting the outside, and then the last thing I would say is sometimes the cost gets a little hairy when it’s not necessarily coming from security. In fact, that budget and that funding may come purely from that business unit, which is not a problem, but it just depends on those shared resources and from a cost perspective how you budget and how you talk about ROI. You’re now no longer just reporting on the health of the whole organization. You’re reporting on those individual surgical components, and that doesn’t necessarily jive with people that aren’t really related to that business unit. They want to know how their business unit is doing, and if you have a hybrid approach, it gets really difficult to tell a singular story.

 

Sanjog Aul [00:21:36]:

So, Leon, what have you seen happening? Love to get your thoughts on this.

 

Leon Ravenna [00:21:40]:

Sure. So with multiple lines of business, I have multiple dev teams, and we’ve bought 3 companies in the last 12 months, and we’re buying them for their intellectual property. So we’re not going to say you have to use this development language. We’re in AWS. We’re in Azure. We’re on-prem, Windows, various Linux, various databases. To bring this together, we have a set of controls that we work to. We use the same cloud security posture system. We use the same vulnerability system, but we tailor what we’re doing a lot to those dev teams because we’re building applications. For the guys that are doing DevOps and infrastructure as code, we come at them differently than the guys who are doing, say, a Windows system in Azure. The things that we mandate — the very first statement as soon as we buy a company is, as soon as we sign, I own your problems. That is a very telling message that says most of the companies we’re buying are pretty small and may not have those controls in place. Their problems become mine. We deal with incidents exactly the same way. There is no flexibility on how we do that because we have to, but as we’re working with those teams on what they’re developing and how they get better, that is very surgical and very tailored to the persona and the culture of those teams.

 

Sanjog Aul [00:23:27]:

So, Jake, when you hear both Jeric and Leon on this topic of the challenges, would you say can there be any sort of proactive preparation to get over it? Because at the end of the day, you are paid to deliver results, and if you know these challenges are there, you may have some countermeasures, if you will. Right?

 

Jake Margolis [00:23:53]:

Yeah. Absolutely. I think first of all, planning to respond, or building a reactionary posture is a proactive measure in and of itself. Sometimes that gets taken a little out of context when you let people know that you’re going to assume that something bad is going to happen. So you have a standardized response to handle incidents. That’s actually very proactive. Most people who have those kinds of plans also spend a lot of time testing them and making sure that they’re tried and true, and their communications are in place when an incident occurs, and they know how to communicate with stakeholders up and downstream lines of business. I think that’s a very proactive thing to do. I also think you can proactively lean forward in understanding the culture of those lines of business. We have multiple lines of business or organizational silos at the Metropolitan. Understanding the culture of these internal businesses or business units helps you to have expectations set on how well a set of cybersecurity controls is going to be taken — how easily it’s going to be adopted. Not how people feel about it, but more the adoption rate. Are people going to work to circumvent it, or are they going to work to support the effort? In organizations where there’s a culture of compliance, you may have a high acceptance of any cybersecurity changes that you want to put in, whether it’s technological or administrative. In more free-spirited business units, sometimes you may run into different problems. Every organization is a little different, but if you understand what it is they’re trying to accomplish and you are intimately familiar with their goals and objectives, then you can absolutely be proactive in planning the best application of defensive measures.

 

Sanjog Aul [00:26:08]:

So, Jeric, let’s talk money. I know I almost assumed that money is available, and I’ve yet to see a CISO who says I have all the play money I want and all the budget I want. When you want to go surgical, you may want to plan a little ahead and also keep some contingency buffer if you go. What kind of a funding model would you work with? Because if it’s 1 bucket of money given by management, go do whatever you have to do, that’s one thing, but if they’re watching it closely, you will have to figure out a way to justify why am I spending more budget in this division versus that division. How would you approach budgeting in a surgical approach to handling security?

 

Jeric Beason [00:26:56]:

So if you are going from peanut butter to surgical, that’s not the sole decision of the CSO. That’s a decision that is made collectively with other parts of the business, because they are now anticipating that there’s a little bit more ownership on their part because you are giving them some levels of autonomy and abilities to govern themselves in some cases. If that is the case, security would be much more deeply embedded in the business, and then it becomes a cost of doing business for that individual division or part of the business or subsidiary, however you’re structured. So the resources, the tooling, and all the spend flows up to the business P&L, and we work on that together. It’s not uncommon for the business to have developers. It’s not uncommon for the business to have IT, desktop support people, and so forth. If we’re going surgical, security becomes one of those additional line items or multiple line items potentially. So that spend is really made collectively at the beginning of the fiscal year, a couple months before, however you go about your budget. You talk about their strategies. You talk about the things that they want to do. If they want to do an M&A, then you say, hey, we’re going to have to spend this money on due diligence. There’s going to be keep-the-lights-on type costs for operations and people, but effectively, all the other spend is aligned with the things they’re trying to do. They’re trying to roll out a product. You need some money to get your SOC 2 or your ISO or to do your pen testing. The list goes on and on. That’s not security dictating the spend. That’s the business dictating the spend based on the activities they want to do.

 

Sanjog Aul [00:28:34]:

So, Leon, when you look at your 17 business lines, if I remember correctly, and if you have those many, and 1 is that you think they need security at a certain level, another is their own perception about what they need, and that could become a tug of war, and then secondly, when you try to get funding and you want to make a case, they will go and cross check with the business leaders, and there might be, again, a tug of war or difference of opinion. Is that how it happens, or you guys are one village singing Kumbaya?

 

Leon Ravenna [00:29:11]:

Well I don’t know that we’re one village singing Kumbaya, but the security budget covers the organization, and that’s by design. I report to the CFO, not to the CIO. We do that for a variety of reasons, and that’s driven by the board of directors. We end up doing security this way because there are things that we will have to mandate and people don’t get a choice on. For instance, you don’t get a choice on the EDR tool that we use. You don’t get a choice on the firewalls that we use, and we work with IT to do that. There are some things that will be non-negotiables. As one particular business unit — and a lot of mine are — we’re building applications in the auto auction/repossessions/financial space, but we’re building applications. We have a big developer community and they may look at application performance management in a different way. We will look at the contracts for that to make sure that we’re all doing the same thing, or that they’re meeting the same security controls, but we’re flexible and saying, yeah, if there’s things that you want to do, as long as they align to the security controls that we need, we’re good with that for your particular business unit because some of them are really far ahead and some of them are still on-prem. I’ve got a bunch of accounts in AWS and Azure and those guys want to move fast, so we accommodate that. It ends up being, again, there are things that are non-negotiables that you don’t get, but then we tailor to every other business line for what they need and how to help them move fast.

 

Sanjog Aul [00:31:09]:

So, Jake, when you are doing what you are doing and you mentioned that you would neither do purely surgical nor purely broad-stroke, what is your approach to making sure the people, the resources, etc., are aligned while at the same time flexible? Because sometimes what you anticipate the need of a given division could change midyear after your budgeting and planning, and here you got to move people around, but now you put individual divisions in the spotlight and they may put you in the spotlight because you said you’re going to go surgical on them. How do you juggle this? Because now somebody’s watching you.

 

Jake Margolis [00:31:58]:

I never actually go to the business unit and tell them that I’m going to get more precise with their security controls. When we apply a tailored set of security controls, it’s because they’re bringing something to the table that doesn’t fit the current software suite or the current network profile. We have network extensions all the time that we do for different services. I don’t think I would have a situation where somebody holds my feet to the fire saying, hey, you promised me a more tailored approach but this isn’t working. When we often work with the units, we do have exception lists where we say, hey, we’re going to require that, and I’m just making something up, service desk people will have X level of permissions to do something moving forward, and they come back and say, well, that’s not really working for us and you said this would be more precise and easier, or this would be a more secure solution and we’re always having to do X, Y, and Z to reduce the posture of the enterprise to fix this problem. We always look at that and say, what is it you feel that you need, what are you recommending would be better suited for what you’re trying to accomplish? And then we analyze that against what everybody else is doing, but we do have, much like Leon said, some pretty standardized approaches to things that we have for privileged access management. We have a tiered administrative process for that. Not everybody gets the same type of privileged account and they’re managed in different mechanisms or privileged-level access, starting at something in the PAM system going all the way up to somebody getting a specific smart card token for their dedicated admin account. We look at what is needed to get the job done and we may tailor and make an exception even though a particular organization is slotted for a certain level of control. None of that can be fully uniform because there’s always going to be something that comes up that we didn’t think of when we were writing the control. So at that level, we do work with them and they do call us to the carpet on that stuff. When it comes to the money that we spend on that stuff, we need to be able to show that we have a high rate of adoption of the security controls and that the security controls are being effective. When we do a more precise or tactical type of security approach to the enterprise — something really specific, like a particular licensing on a set of firewalls, or we’re adding enhancements to our EDR — I frequently have to come back and state what the value gain was. Did it make us safer? Did it improve our productivity as an organization? Did it enable us to do things that we couldn’t do as easily before? That may be something as simple as putting an application on a machine that allows you to either have split tunneling on a VPN or eliminate the need for a VPN altogether. Leon has multiple lines of business and some people are further ahead in the cloud and others are on-prem. That’s where you’re really tailoring a solution and saying, if you’re one of these high-speed organizations that is much more progressive and you can adopt these cloud controls, then maybe we don’t even need to talk VPN. We can talk more security options that are better and more centric around zero trust, as opposed to trying to make a better mousetrap around the VPN connection. In either case, we have to make sure that when we go back and review the effectiveness of those controls, the solution is meeting the expectations of our leadership.

 

Sanjog Aul [00:36:13]:

So, when we are looking at all the situations we spoke about, Jeric, people become important, whether people from your security organization or the people on the other side who have to interact with you. What would you say would be the specific changes you would have to make if you went more surgical in your approach to security management?

 

Jeric Beason [00:36:39]:

People-specific changes that I would have to make? Yes. First, I would create dotted lines instead of hard lines back to my organization. I don’t want them to be completely off on an island. At the same time, they need to be at the direction of the business unit that they’re under if I was going to move into this approach. Number 2: we would change the way we do training. There will be certain technologies that they’ll need to know and certain technologies that they won’t need to know depending on what it is that we’ve put in place from a surgical strategy. I would also expect the people to be far more business savvy. It’s pretty common to expect the CISO to be business savvy, but now when we move out into the perimeter of the organization, you need people with that BISO-like skill set as well, which is very similar to a CISO, except their sole focus is on the business unit that they’re dealing with. There’s a good possibility that that person is a divisional CSO. So we would have to revisit the overall structure of the organization.

 

Sanjog Aul [00:37:55]:

So when we are looking, Leon, at all of this, right, there are different areas in security management. Which other area should we look at differently if you’re going surgical? So I’ve been asking questions. I’ve been directing to say, okay. What are the people? What’s the budget, etc.? What do you think would be an area which would be our biggest concern for a CISO when something like this is being tried or tackled?

 

Leon Ravenna [00:38:27]:

Sure. So actually 2 points there. The first is, to riff off of what Jeric said, I would be looking at tailoring my AppSec. My hard controls — my ADR, my firewalls, my WAFs — those aren’t really negotiables. How we deal with AppSec and how we help them get stuff done is an area where you can get pretty surgical, and that’s going to be more line-of-business specific to the point around the BISO role making sure that people understand more of what the business is trying to do. That’s where I would look at being very surgical in how I approach things, but one of the things we have to remember is next Tuesday I have my quarterly risk meeting with the board, and they’re concerned about 4 or 5 things in total. They want to know what’s good and what’s bad. You have to think about how you are rolling up your metrics and how you’re rolling up what you’re doing. If you get very surgical, it gives you the potential to be scattered or chaotic. In order to maintain consistency and roll those things up, you’re going

 

Jake Margolis [00:39:56]:

to have a

 

Leon Ravenna [00:39:57]:

potentially a blend of both, and so just something for the board to keep in mind there.

 

Sanjog Aul [00:40:04]:

So we look at leadership or governance. There are multiple other areas. This is for you, Jake Margolis. Right? I am clear.

 

Jake Margolis [00:40:14]:

Yeah.

 

Sanjog Aul [00:40:15]:

Yeah.

 

Jake Margolis [00:40:15]:

Okay.

 

Sanjog Aul [00:40:16]:

So when you’re talking about the areas, anytime you want this to be consistent, your security landscape is not going to remain stagnant. It’s going to continually change. So that means you have to have some sort of governance structure with performance metrics and benchmarks that you first establish and then measure by. Would you suggest any changes to your standard approach to measuring and having performance metrics and benchmarks as you do, which is a combination of going surgical and, not broad stroking, but more pervasive across the organization? What would you change in this area specifically?

 

Jake Margolis [00:41:06]:

Well, metrics are good because they can come back and tell you the effectiveness of your current pervasive controls. Pervasive tends to mean threat to me when I think of the cybersecurity world. Your deployed controls across the enterprise are the ones that are adopted. What’s the effectiveness of those? That’s a number you can look in your systems and say this is working because we’ve had this many detections, we’ve blocked this many things. Those don’t really mean a lot to the board. It might make them feel good that you’ve blocked a few things and your investment and your security stack is doing what it’s supposed to do, but I don’t really look at that when I’m trying to look at something more tailored, because I want to understand. I don’t have a lot of detailed tailored solutions typically; I have some. Like I said earlier, I will tailor some because there are specific systems that need it. Even when I was the CFO for the County of Orange, I looked at it a little bit differently. There’s some customization, but I would want to know at what level the existing controls are not adequate to what we’re trying to do. Usually when somebody wants a tailored approach, or we need a more tailored approach, it’s because the current controls are either breaking the functionality of an implemented application, or they want restrictions lightened and there needs to be more compensating controls and risk mitigation. I don’t know if you’re going to have a lot of good metrics that point to that and say if we do this then we know this is going to work. I’ll qualify that because sometimes people disagree with me when I say some of those metrics are telling. We have to get it right 100% of the time in cybersecurity. We have to make sure every control we put in place, every incident response plan, every mechanism to detect threats and respond to them has to work perfectly for our organizations to feel good about what we do, or at least work well enough to protect the organization. They call it zero-day for a reason, because a bad guy only has to get it right once. There are literally millions of threats and only one has to be successful. So the way I would measure and communicate the effectiveness of our governance model is: are we reviewing these controls frequently enough with substantial measurable value? How do I know that phishing campaigns are working? The answer is you probably don’t. You know that your users have learned how to identify phishing emails and they’re not failing tests, but that doesn’t mean the bad guy hasn’t built a better mousetrap and figured out how to create a better crafted phishing email that’s going to get through training or defenses. So when we review those controls from a governance point, are they adequate? Are we documenting them in a way that is deployable and understandable by the people that have to use them? When events happen, do we go back and review the controls that were violated against the incident so we can see were the controls still effective, or do we need to improve those controls to avoid this incident from happening again? I like to take that approach because it’s not always enough to open the checkbook and buy more tools or more staff. Sometimes those sound great, but you may not have the result you want if you’re buying a lot and you don’t have the resources to support it. You may find yourself in a slightly worse situation. I 100% agree with that. I don’t like using fear, uncertainty, and doubt to motivate leadership. I’d like to take a methodical approach and say, we had this bad thing happen — was it our control? When security incidents occur, are you looking and talking about whether your controls were affected in the first place? Just because something bad happens doesn’t mean your security controls weren’t affected; it might mean the adversary was clever in their approach.

 

Sanjog Aul [00:45:50]:

Leadership. Everything else — people, process, politics, pocketbook, policies — all that works. Jeric, leadership. What would you change in your style when it comes to leadership if you had to make a surgical approach most effective?

 

Jeric Beason [00:46:10]:

That is a tough question, my style. I am used to having my hands deeply embedded within the business, and I will have to find a way to take a step back, designate a leader to have that role, trust that person, equip that person, and oversee the individual BISOs in a way that is a little bit different than what I do today. I don’t have BISOs in my organization now. I would delegate that responsibility and take a step back and manage the forest instead of getting too involved with the trees.

 

Sanjog Aul [00:46:59]:

Leon, you’ve been playing with this and juggling the 17 business lines. Would you shift something?

 

Leon Ravenna [00:47:06]:

Sure. I mean, we have a relatively small security team, so there’s a lot of things that I end up doing. I’m one of those odd birds that really wants my hands in the details. So I spent a lot of time in cloud posture stuff and to Jeric’s point you’d have to take it up a level and have people that are managing those things, and then kind of turn loose of that deep technical piece and work more on people management and things like that.

 

Sanjog Aul [00:47:44]:

Alright. One minute or less. Jake, what would you change in terms of your style?

 

Jake Margolis [00:47:52]:

I’d probably echo Jeric and Leon. I tend to have my trade analysts talk to me all the time, and they always want a second set of eyes on what they’re looking at. I’ll get in there and look up hashes and do the work with them sometimes because 1, it’s fascinating. We all got into this business for a reason. Many hands make light work in a lot of things. Most security teams are a fraction of the size of IT teams, but with a massive responsibility. So if I needed to change something, I’d probably learn to back off a little bit more from that and ingest the information provided to me by those analysts or my security engineers and get a little less involved in the architecting discussions and the actual building of the picture when we’re dealing with threat analysis.

 

Sanjog Aul [00:49:02]:

Once again, thank you so much, Jeric, Leon, and Jake for sharing your insights about this interesting topic about moving from peanut butter to surgery and making it better security. Thanks so much.

 

Leon Ravenna [00:49:18]:

Appreciate it. Thank you.

 

Sanjog Aul [00:49:20]:

And let’s just please connect with us on social media, subscribe to our podcast. Hope you enjoyed, got some good nuggets. Don’t use peanut butter as much. Go for the surgery. That’s the lesson and that’s the recipe for great security. Once again, thank you for listening to CTN. This is your host Sanjog Aul signing off. Till next week, take care, and God bless.

Contributors

Jerich Beason

Jerich Beason, Chief Information Security Officer, Epiq

As the Chief Information Security Officer, Jerich Beason is responsible for ensuring the security of the company’s digital assets as well as transforming the Epiq cybersecurity program into a world-class industry leader. Jerich has spent ... More   View all posts
Leon Ravenna

Leon Ravenna, Chief Information Security Officer, KAR Global

Leon Ravenna is Chief Information Security Officer at KAR Global. He leads KAR’s efforts in global security strategy, execution, and privacy and compliance services for the company’s more than 17,500 employees. A seasoned CISO, Leon has... More   View all posts
Jake Margolis

Jake Margolis, Chief Information Security Officer, Metropolitan Water District of Southern California

Jake Margolis is the Chief Information Security Officer for the Metropolitan Water District of Southern California (MWD). MWD provides water to over 19 million people in Southern California through 26 member agencies. Jake holds a Master’... More   View all posts

Advertisement

E-Con Systems MPU 300X250
Jerich Beason