In the same way that new security measures can help organizations better enable Big Data, utilizing Big Data can help improve and transform enterprise security practices on the whole. If we think about security in the context of Big Data, the proper utilization of data can help organizations achieve better insights and become more predictive and proactive in their security measures overall. So what are the steps to making this security transformation possible?
Contributor
Transcript (Stronger Security with Big Data)
Speaker A [00:00:00]:
CIO Talk Radio is brought to you by HP and Siemens Smart Grid. Welcome to CIO Talk Radio with your host, Sanjog Aul. All all comments, views and opinions expressed on this show are strictly those of the host, guests and callers. Now here’s Sanjog Aul.
Sanjog Aul [00:00:24]:
Very welcome to CIO Talk Radio. To learn more about this show, please visit www.ciotalkradio. do. And as always, we invite you to join the discussion on Twitter, #Ctrlive and look for this show as Big Data and Security. Today’s topic is Stronger Security with #Big Data and our guest for today’s show is Derek Brink, who’s a Vice President and Research Fellow of IT Security with the Aberdeen Group. Good morning Derek. How are you?
Derek Brink [00:00:53]:
Hey Sanjog, I’m well and thanks for having me on the show.
Sanjog Aul [00:00:58]:
Great to have you as a guest on our show. And now today’s show is actually the second part of a two part series we are doing on big data and security. So last week we touched on how the introduction of big data into the enterprise has made us more vulnerable in surprising ways. But the interesting idea that came out of that was what if we could get the same insights out of Big Data that have helped make organizations find new value and apply them to make the enterprise even more secure. That said Derek, the first question would be is that what specific enterprise level security practices that we are looking at which can be fine tuned or which are being fine tuned over the years and how can Big Data further add incremental value to it?
Derek Brink [00:01:44]:
Yeah, it’s a great question and it is a great topic. I look forward to our conversation today. I think I should really start out by mentioning that there are some things that will change for sure and there are also many things that stay the same. So let me start with the latter first talk about a couple things that are going to stay the same as they always have been. There are some fundamental things that will never change I think with respect to security. So for example, confidentiality is one, it’s also called privacy.
Derek Brink [00:02:13]:
But making sure that sensitive data is accessible and intelligible only to the people that are authorized to see it or the systems that are authorized to see it. That’s one thing that will never change. Integrity is another thing. Integrity refers to making sure that the data is not altered, right? You don’t want to have transactions altered in terms of the quantities or values or that kind of thing and the third one is availability so to make sure that the data that we are talking about here is accessible to the authorized persons or systems at the right time and from the desired location and from the desired device. So those three things, confidentiality, integrity and availability, they often are referred to by an acronym, CIA and it’s probably worth saying that these days the availability aspect is often getting the highest priority.
Derek Brink [00:03:04]:
People want to have access to data from the device they want and where they want, and so on but in the context of big data, these things aren’t going to change at all but there are some things that will change so let me just mention those. One of the biggest challenges for Big Data, and by the way, I’m sure you defined it last week, but I’ll just mention that what it implies is a growing number of sources and a wide variety of data types and just a faster flow of information. This makes that any time, anyplace, in any device dynamic even more challenging. So, for example, most of your listeners, I’m sure can appreciate that when we think about back end systems, that no longer refers necessarily to the networks and hosts and storage and applications that are within the enterprise server rooms or the data centers. It also means the virtualized infrastructure in the cloud and that kind of thing
Derek Brink [00:03:51]:
and the networks, by the same token, no longer means just connections and protocols between systems. It also refers to social connections and collaboration between people. I’m sure you talked about that last week and finally, the endpoints that we have to deal with no longer refer just to devices that are centrally purchased and provisioned and managed by the enterprise IT function. It also refers now of course, to the distributing highly mobile devices that we all use and these are ones that we buy and provision and essentially manage by ourselves, the so called bring your own device or BYOD phenomena. So all this confidential information and intellectual property that lives among the Big Data is just likely to be flowing from systems that the organization doesn’t control, through networks that it doesn’t control, to endpoints and end users that it doesn’t control. So that’s why I was saying that these privacy and security issues are the same as they’ve always been
Derek Brink [00:04:45]:
But these changes in the underlying infrastructure is really a lot more complex and that’s what makes the challenge of security a lot more difficult.
Sanjog Aul [00:04:52]:
Now you did mention that, okay, the security could further get. Or let me pull back. The way we are approaching this is we are saying that Big Data could be a problem and Big Data can also be used for a solution But we are not as an enterprise looking for a zero sum game, right? So we are saying, okay, big data, we could create value, and that may be the case for some organizations. So that’s why they will adopt it and they’ll try to use it and which may introduce security vulnerabilities, which is what we discussed last week. Now comes the point here where we say, okay, perhaps we may not go on the jump on the Big Data bandwagon for creating business value, but perhaps we can just tell the security folks to say, hey, you got this new tool, can we use that to make our fort more secure so that we are creating more confidence in the eyes of our consumers or customers? So are people only touching Big Data as a way to improve security when they’ve already adopted big data for revenue generation and other positive top line growth initiatives or you are allowed.
Derek Brink [00:05:56]:
But they definitely are taking advantage of that more and more and let me give you an example of how that works. I think it’s a metaphor really, but I guess I wrote about this in a blog, but I don’t know if you or any of your listeners enjoyed the show on the History Channel. It’s a series called the Vikings and I really enjoyed it and you might have noticed there’s a frequent appearance of ravens in the fabric of those stories and I looked into that. It turns out that the chief of the Norse gods is called Odin and he rules from his high throne and he can see everything that’s happening on the nine worlds of Viking mythology. So every day these ravens fly all over the human world and they bring Odin information.
Derek Brink [00:06:41]:
His two ravens are called Memory and Thought, those are their names. So essentially think about this as a metaphor. He’s established complete situational awareness, which is the language that we use in public safety, or if you prefer homeland security language, we’d call that total domain awareness. Or in security we would call that actionable intelligence. So he’s got these ravens called Memory and Thought that bring him this information and really that’s the cue that we’ve taken from mythology of 1500 years ago. So leading companies today are in fact seeking this ability to transform these massive volumes of security related data into useful and quote, actionable end quote information and intelligence.
Derek Brink [00:07:19]:
So there’s lots of use cases for that. One leading example would be insecurity and of course others could be in the area of fighting fraud or waste and abuse. You could find it in the area of public safety and so on and there’s a reason why I just mentioned this too. As we talked about the community and infrastructure getting more complex and at the same time it’s more mission critical. So companies are realizing that their traditional strategy of trying to prevent things from happening cannot be successful 100% of the time and so they’re looking to augment that approach, not replace it, but augment it.
Derek Brink [00:07:53]:
And so the use of data, even so today has been primarily reactive and forensic. So we’re trying to investigate what’s happened and why but what we’re talking about today, I think is this movement towards a more real time and predictive type of capability. So we’re talking here about the ability to identify and contain and respond more quickly to things that aren’t normal. So again, back to that silly analogy, I guess, but just the way that ODIN was using memory and thought to generate the visibility and insight for the purposes of taking action on Middle Earth, the leading enterprises today are in fact already starting to capture and integrate this kind of data and then analyzing it and getting insights from it and ultimately to take action. So I think that’s exactly the point of the arrow in terms of how this data can be used and we do see many examples of it right now.
Sanjog Aul [00:08:41]:
Now, you referred to quite a few progressive organizations who first of all may have adopted Big Data and subsequently used that as an opportunity to also improve security. So if you were to inventory specific areas in which Big Data could be utilized to improve security, and not just because you got more data, you got more insight that doesn’t improve security just by itself. There has to be some more interpretations of manifestation, some specific changes in the way people policy, pocketbooks, etc have to be tweaked in order for security to really be seen incrementally improved. What are those?
Derek Brink [00:09:19]:
Well, again, I just want to make sure we underscore the foundational point here, which is that this traditional approach to security, which is largely oriented around the idea of prevention, is really slowly but very perceptibly in the research that I do, being augmented with this increasing focus on detection and response and we have to keep in mind that attackers have the advantage here of asymmetry, and that is the preventive measures that we put in place, the defenders that, you know, we put these preventive measures in place, they can’t succeed 100% of the time, and attackers only have to succeed once. So what we see in companies and solution providers, both, they’re strongly promoting this notion of operating under an assumption that you’re already compromised and that’s another way to express how many enterprises are evolving their traditional approach. So what I’ve seen, I think I alluded to it a little bit already, is that what’s changing quite a bit right now is the nature of the detection and response capabilities. The shift that’s underway is more from this reactive approach, meaning mostly, okay, we had a break in, let’s go in and investigate log files and see if we can figure out what happened that’s responding to and recovering from things that have already taken place. Moving towards this more proactive approach, which is the ideal, which is to monitor and detect and contain attacks earlier in their life cycle so it’s about this idea of moving from this backwards looking forensic mode to establish a baseline for what’s normal and then detecting and responding to what’s not normal in this more forward looking and proactive way.
Sanjog Aul [00:10:52]:
So the different tactics that you just explained in or different places where there’s an opportunity to what degree have these been, are being tried and what kind of results are we getting? You know, by and there’s some data which can be utilized to say yes, by deploying this mechanism, we reduced our threats and our vulnerabilities by X percentage.
Derek Brink [00:11:16]:
Yeah. So you’re asking for some examples. I think that the best examples can actually be the opportunities that present. I’ll give you some facts. Just for example, let me make sure we establish a definition of what a typical attacker’s life cycle might look like. So attackers, the first thing they tend to do this is very general and high level, but attackers are looking to identify vulnerabilities in the infrastructure. They’re doing reconnaissance on the target organization’s networks and systems. Once they find those vulnerabilities, they’re looking to implement and execute those exploits to the vulnerabilities.
Derek Brink [00:11:49]:
They can use a variety of forms, it could be, you know, drive by download on a website that’s infected, it could be social engineering through phishing and attachments, it could be a number of things and sometimes the attackers are able to automate the exploits to run at scale so and additionally they also have the ability through their command and control communications to modify the exploits over time so even as the organization happens to identify and eliminate some of the underlying vulnerabilities, they can maybe stay one step ahead so this is, you know, just think about the so called era that we’re in now of advanced persistent threats
Derek Brink [00:12:23]:
and we have to keep in mind that these lifecycles are being designed to be imperceptible and they might be carried out over a period of weeks or months or even years. So I’ll give you some examples. There’s a report by the association of Certified Fraud Examiners they actually looked at cases, actual cases, and sort of dissected those cases of actual fraud. This is 2012 and the median time to detection was about 18 months and the range was between one and three years so this is how long fraud was being carried out before it was detected. So imagine the opportunity to reduce the time to detect from an average of 18 months to less than that obviously it has a significant impact on dollars.
Derek Brink [00:13:02]:
There’s a high tech company called Mandiant who specializes in monitoring and so on and advanced persisting threats and they had a report earlier this year on one of China’s cyber espionage units and what they found was that this particular espionage unit, they call it APT1, had access to the victim networks for an average of nearly a year. I think it was just under 365 days and for as long as 4 years and 10 months. So that’s how long the presence on the victim networks was there without being detected and Verizon Business is another annual study that comes out and they also analyze actual case files globally from actual data breaches and what they find that was that the time to an initial compromise is 84% was within just hours. The time from compromise to beginning to exfiltrate data was also within hours, 69% was within hours
Derek Brink [00:13:54]:
but then from compromise to being discovered it was 68% of all the cases they analyzed was months or longer and from discovery to containment it was 77% there was days to longer. So I hope you get the idea that being able to find and detect and contain and remediate these things much earlier in that lifecycle has some serious potential in terms of reducing the monetary impact of this kind of attacks, these kind of data losses and this kind of fraud.
Sanjog Aul [00:14:22]:
Let’s take a quick break listeners, we’ll be right back. And Derek, as you mentioned that thieves are head of the copsthat is hackers always have an edge and that’s what they’re able to hack and create problems. You got Big Data and enterprises can leverage them to perhaps say, okay, I have been able to identify much earlier. But then it’s a level playing field where the hackers for the most part look like they’re well funded and they can also deploy Big data to again get an edge over you, or is that not going to be the case? Are we going to for once come at the same level as that expertise and intelligence those hackers demonstrate in terms of getting into our network and creating problems? What is the horizon looking like with introduction of Big Data into enterprises and what is the opportunity here? Please stay tuned. We’ll be right back and explore.
Sanjog Aul [00:17:37]:
Welcome back. So the question is, Big Data going to help create a level playing field between the hackers and enterprises or they will still have an edge because they’re also well funded? I’m referring to the hackers.
Derek Brink [00:17:51]:
Well, I think that one advantage that we have with our own access to Big Data is we have clear access to all of it. We have to implement proper policies for access and so on. But, but you know, the hackers and attackers have to find it when they can get it and so we do have that advantage. The other advantage we have of course is the operational knowledge of our enterprise and how it works so of course that can be studied and learned and gained to some extent by attackers but we have the advantage on what is normal and what’s not normal. I keep using those words, but that’s a big part of what it means to leverage Big Data and so that’s an advantage that we have should we choose to use it in that way.
Sanjog Aul [00:18:40]:
So would you say that the people who are getting at least they are seeing what the value Big Data can bring to an enterprise? Are they now required to make a very solid business case, as with any other investment? Or people are already seeing, or the executive management and other people who hold the pocketbooks are already seeing the value and they’re readily doling out cash in order for it to be implemented and to make this fort more secure.
Derek Brink [00:19:11]:
I say this almost tongue in cheek, but there’s actually a lot of truth in it that a lot of times when the checks are being written and the cash is being doled out is actually just the day after there’s been some kind of incident and that’s a sad thing that we as security people really should learn and I think we’re trying hard to learn how to make a better case and align our views on risk and how to mitigate risk with the business but the fact is, let’s be honest here, the fact is that whether or not these tools should be applied to security or other areas of business is not the question. I believe it should, and I do believe it can and is helping in many existing examples but it really is a question of what are the priorities of the business for leveraging the data and the tools and so to illustrate, I’ll give you an example, I can look at the titles of topics that some of my colleagues here at Aberdeen Group have written and I picked some just almost at random
Derek Brink [00:20:06]:
but in the retail research practice, right? So they’re focused on research and if you just look at the last dozen or so publications, here’s the words and the phrases that are in the titles, which tells you what they’re writing about, which tells you what those folks are interested in, reductions in inventory holding costs, enhancements to business intelligence, customer intelligence and engagement, store level workforce management, revenue growth through early insight, increasing traffic and volume and profits, reaching new customers, driving responsiveness to customers, collaborating in the supply chain, social media marketing and return on investment, customer loyalty, visibility of inventory, lowering the cost to serve, these are the titles and the topics, therefore, that are of interest to folks in the retail area. Just for one example, and I don’t think one of them really talks so much about security so they do care about security, they care about shrinkage, they care about protecting information, they care about all those other things but what’s really top of mind is revenue and cost and I think that’s one of our challenges here.
Derek Brink [00:21:07]:
It’s just simply not compliance and security, it’s just not as high on the list of priorities as these other topics so it is one of the challenges that we have to deal with. I think it’s a tool that can be used, but it’s not necessarily being used first for these things because those other things are perhaps viewed as more strategic and rewarded types of uses for Big Data.
Sanjog Aul [00:21:30]:
Do you think CIO and the CISOs within an organization could partner and squeeze some funds out of the other revenue generating opportunities and funnel that into the security? Because frankly, both will be dinged in case you create great value for the business. But at the same time also show that there have been instances where there was a leakage of revenue as well.
Derek Brink [00:21:58]:
Well, I think you’re back to the very important point, which is how do we make a case as security professor knows, that there’s some threats and there’s vulnerabilities that we are exposed to. We have to talk about how those vulnerabilities could lead to better outcomes, we need to do a better job of talking about the probability of those exploits being carried out successfully and we need to do a much better job of trying to quantify the magnitude of what those impacts could be. So I’ll just give you a quick example. It’s simple. Anybody could do this math. It’s really just back of the envelope.
Derek Brink [00:22:33]:
But if you had some process or let’s say it’s a website or a process and let’s say to make the numbers easy, that it generates $10 million in a year and that that’s continuous. Now what if that website or process was down? You can calculate just on the simple assumption that it’s a continuous generation of revenue throughout that year and that if you lose a revenue because of some kind of outage that it’s lost, you can’t regain it. Well, that works out to be about $1,100 per hour so $1,100 per hour is for every 10 million in revenue. It’s kind of a, you know, back of the envelope. Now it doesn’t matter why the website or the process is down. It could be a power outage or it could be a security breach. But if it’s down, you’re not generating revenue,
Derek Brink [00:23:19]:
you’re not serving your customers, you’re not carrying out the objectives of the business. So being able to relate just simply to things like that, that’s what matters more to the financial aspects and the strategic aspects of making the case for security. It’s not if we focus too much on the bogeyman. I think we lose eyes glaze over when we do that and those are vulnerabilities and threats. We need to start talking about the risks and the magnitudes and the probabilities.
Sanjog Aul [00:23:47]:
So coming back to the question, and thank you for this great answer, the question is to say if we are going to keep living that stepchild syndrome, then we will never get to show the value. Do you think there are ways by which us not try to even create a business case for introducing Big Data into security and thus get more money, instead bundle it in other initiatives so that this actually gets done and we are not because if you try to go and explain this to people above and the executive management, they would really not care one way or the other but you will really get penalized if there is a security hole and you know that you have an opportunity to plug it. So why even bother?
Derek Brink [00:24:30]:
Well, I think to try to answer what I think is your question, the platforms and the tools that may be brought into the company from the solution providers, the vendors are providing tools that can be used in that flexible way. So the same tools, the same business intelligence, the same analytical capabilities, all those tools can be applied to analyzing customer data to improve the cost to serve and things that we discussed before, it can also be used, the same tools could be used with different data to understand what’s normal and what looks like it’s abnormal in the context of security and potential threats and vulnerabilities being exploited. So absolutely, I think the leverage of those same tools, however they come into the tent, so to speak, is fantastic and it’s up to the security teams to make the case to get some access to those tools and also to integrate the data that’s relevant to them to help with that and that’s an important question. By the way, the integration of data is interesting, what I found in my own research is that companies have very naturally, and I think dovetails with the previous point, they’ve integrated a wide number of data sources. I have a colleague who specializes in business intelligence.
Derek Brink [00:25:43]:
He says the average is about 15 different sources, but that’s growing very fast but what I’ve seen in terms of the percentage which data sources are most likely to be integrated, it tends to be internal sources and also customer focused sources so things like actual transactions, customer records, the product records, customer interactions, maybe notes from call centers and things like that. Those are the things that tend to be most first to be implemented and most commonly implemented by most companies over time. You see a lot of intent to integrate other things, external sources, customer behavior, unstructured data, customer sentiment, feelings, survey results, social media data, click stream data. All those other things are integrated to a lower extent right now, but plan to be integrated to a much higher extent so integrating the security related data, I think is definitely possible in these same tools, which I think was your original question, but it needs to be planned and the case needs to be made for that
Derek Brink [00:26:45]:
but the tools are the same and once they’re in, they should be able to be used a lot easier than making the case from a blank sheet of paper.
Sanjog Aul [00:26:52]:
So, CISO, as a leader, a security leader, what is it that they would or should be changing within their organization? What kind of benchmarks and standards that they should reestablish for their team and perhaps for the rest of the organization, given that they have this newfound insight or an ability to get the newfound insight available through the spic data?
Derek Brink [00:27:17]:
Well, you mentioned the team, and maybe I’ll just pick up on that part of it for my response. I think that traditional security people might not have the background that they need to communicate properly. Or maybe I should say it this way they have tended historically to focus on the, I guess the negative aspects of these are the things that could go wrong. These are the threats and vulnerabilities and it’s almost, here’s another analogy, you might get tired of these by the end of our discussion today
Derek Brink [00:27:48]:
but if you’ve seen the movie A Few Good Men and you remember Jack Nicholson when he’s on the stand at the very end as the general from Guantanamo Bay, and right after he says, you can’t handle the truth, he gives a little soliloquy and if you remember, he says things like, you know, deep down in places you don’t like to talk about at parties, you want me on that wall, you need me on that wall, and so on and what he’s expressing is, I think, very similar to what a lot of security people think they feel that they’re passionate about protecting the organization that they work for they feel that they might be misunderstood and underappreciated, but they need to do a better job of communicating the value that they bring and that might mean that the folks need to change we might need to mix in some other aspects to the team. If you’re going to talk about responding quickly to incidents as you see them unfolding in real time and being more proactive, as we were talking about, you need not only the technical skills but you need to have that operational knowledge that we talked about.
Derek Brink [00:28:43]:
How does a business work? How does it run? What does normal look like? We need to be able to communicate effectively both verbally and in writing, you need to command respect across the organization, you need to remain calm under pressure because some of these incidents can be again unfolding in real time so that composition of security teams is maybe where you know, as opposed it’s probably more relevant to a larger company where, where this is really happening first as opposed to a smaller company that has just some guy named Mike who handles everything from administration to security and so on so this final point is that responding to these types of changing needs with changing skill sets I think is what some of the leading companies are doing right now.
Sanjog Aul [00:29:28]:
Let’s take a quick break listeners. We’ll be right back and we’ll continue this conversation around leadership and people. So Derek just mentioned about these people have to become better understanding the business and correspondingly show that they really can create value. How? I mean forever we have always seen security as a cost. Do you think if big data was infused with security, can this become cost of doing business? Is that at all a possibility? And if yes, then how? Please stay tuned. We’ll be right back.
Sanjog Aul [00:32:26]:
Welcome back. So in short, do you think security can ever be shown as a cost of doing business and morphing it from just be seen always as a cost?
Derek Brink [00:32:38]:
Yes. So this is a question that has kept me busy thinking for 15 years. I would say literally I started thinking about this as a product manager. I worked for RSA Security way back in those days and it’s been on my mind ever since and what I found is there’s only when you talk about business value of security, I’ve only found four major buckets at a super high level that you can assert business value for security. I’ll just list them real quickly here. The first one would be in the area of risk so for example, if you say we’ve assessed our systems and the vulnerabilities and threats and what we believe is that there’s an X percent probability that there could be some exploit that costs us greater than Y millions of dollars
Derek Brink [00:33:31]:
and so that’s a way to phrase it so it’s phrased in a risk sort of format so business decision makers can decide what’s their appetite for risk and you can say, and I recommend that if we use the following controls, we can reduce that probability or reduce that impact and, so that’s, you know, a classical way, but that’s seen as a cost. As you were saying, another thing and very closely related to that is compliance. It’s sort of we’re required to do this by law.
Derek Brink [00:33:56]:
There’s regulatory from the government, there’s regulatory requirements from industry, there’s other types of compliance as well. But you know, compliance and security are kind of both sides of the same coin, kind of that unrewarded sort of investment area. On the other side of the coin, there’s what business people are more prone to listen to, which has to do with either cost or revenue. On the cost side, you can certainly do currently the things that you’re doing currently and spending dollars on already if you can make them more efficient by maybe automating some of these aspects of security so that counts, I mean, you can say we’ve decided, we’ve made the case already to do such and such a thing in our security and compliance, but now we’re going to do it at higher scale and lower cost well, that’s a win. So you can save money for the organization that way.
Derek Brink [00:34:43]:
There’s also this notion of cost avoided, which is a little tough. So if you have 5% fraud and through better security and invisibility and trying to detect things sooner, you can, let’s say cut that in half. Then I think that gets to the credit of the investment as well so that cost avoidance versus cost savings, maybe that’s a nuance, but I think it’s legitimate and ultimately, if you can get to the revenue side, if you can say, look, we want to implement these new capabilities and these are rewarded risks that business leaders take all the time. We want to gain new customers, we want to enter new markets, we want to capture new revenue streams, but there’s some risk to that and by implementing these security capabilities we can reduce that risk and have us feel better about moving ahead with those initiatives to generate revenue. Then I think aligning and kind of getting grouped in with those, maybe that’s what you were alluding to before.
Derek Brink [00:35:37]:
That’s not a trick, but it’s the right thing to do for the security capabilities because they’re part of enabling those positive business benefits, the rewarded risk that the company wants to take.
Sanjog Aul [00:35:51]:
So if you were to look at the way security all along has been handled and now the big data has been introduced, has that at all or would you say fundamentally changed the way even the security leaders are looking at security? Or they are saying that okay, this is just a tool or this is more of a. But it doesn’t fundamentally change how I diagnose. How do I proactively find out what’s going on and how do I plug the holes?
Derek Brink [00:36:18]:
Well, I do think it changes a lot of things and I’ll just say again, I’m not saying no one should take away that. I’m saying that there’s a reduction in the amount of prevention oriented controls because those are still in place, but those controls are being augmented by these detection and response sort of capabilities. So what’s different between putting things in place to prevent versus being able to detect and evaluate threats with greater speed and acting on them? There are some fundamental practices that have to change. I’ll just list a few of them. So you need to keep current. The team has to keep current that is about the latest attacks and techniques,
Derek Brink [00:36:55]:
they can do that on their own, they can do that through subscribing to external threat intelligence. There’s a number of ways to do that. They need to have strategies for response in advance, maybe for a range of scenarios. If something happens, we would do this, maybe we would segment the network immediately to reduce the scope of the threat and so on. You need to have a way to classify incidents and handle them. So there’s triage effectively that can go on to speed the process of getting the right resources in place to deal with the problem. Probably have to have an incident tracking system.
Derek Brink [00:37:26]:
Maybe you use the tracking system that you already have in your customer support team. Maybe it’s different. You have to assess severity so how urgent is this? You have to assess, scope what kind of resources are affected and how valuable are those, you have to be able to communicate so there’s dissemination of information. Is there a need to know kind of a situation that needs to be followed, especially in these time sensitive scenarios. All those skills need to be put in place.
Derek Brink [00:37:50]:
Probably three or four others if you want, need to coordinate like crazy with other business functions so the executives, the legal team, the operations team, maybe physical security, maybe human resources, press an analyst in case you need to, you know, it goes public and you need to communicate publicly. You might have outsourced experts that you bring in you might need to work with your vendors. There might be third party response teams that are also involved and on and on law enforcement, by the way, do you have an escalation plan based on the severity of the incident and so on and so on. So all those things are skills that might not be so much in place under this new augmented detect and respond strategy, but they certainly need to be in place if you’re going to be effective.
Sanjog Aul [00:38:32]:
You brought up a very important point about the skill mix that was originally not present and now it is required for you to be able to leverage big data and make it happen. Number one, we have a budget constraint and that would prevent that from happening immediately. That means you might be required to go to those existing resources who might have been identified and deployed for value creation or top line growth related initiative. And if at all we go that route, number one, you got diluted attention, number two, you are now making security and its effectiveness dependent on external people who then are not being monitored and are controlled by the CISOs, they are at most being influenced by this security division. Where does this take us?
Derek Brink [00:39:18]:
Well, there’s a couple ways to think about it. You sort of painted a bleak picture of it, but I would say there’s the alternative view, which is that if you involve other people in sort of a virtual response team because of their expertise and because of their operational knowledge, because of their access to certain information or what have you, I think if done right, you can actually widen the buy in and widen the support and get more parts of the company kind of rowing in the same direction as you’d like to get them to row because frankly the planning and upfront preparation is one thing, but in time of crisis, if you already have the relationships in place and sort of have worked out some of these things and I think the company as a whole will be much better off. Now that’s just assessing the internal side of things. But if you’re talking about involving external expertise and at some point you escalate and maybe you have on retainers some kind of expertise from a third party, all the better because those folks are specialized and focused on these precise things, whereas inside the company you may not be. So that might be a good case where the, the outsourcing strategy to supplement the team in the time of crisis is exactly what’s needed. So I think personally I take the more positive view than what you painted but I suppose like anything in any project, not just security, companies can implement it badly or they can implement it well and I guess I’d rather focus on the idea of implementing it well.
Sanjog Aul [00:40:42]:
So I agree with you that there would be a possibility of us looking at a positive view. I’m more concerned and that’s why I voice that concern. Is in reality, when somebody is being measured and evaluated for creating insights for top line growth and they truly are not primarily known or identified as someone who’s going to work as part of the threat response and the timeliness of that is not truly a benchmark or a measure that they are supposed to adhere to, then effectiveness of your security is not known and, or you cannot really control it. Would you agree?
Derek Brink [00:41:20]:
You make a point that is just a point that’s valid for all projects, for all humans and every company everywhere. If you’re not directly measured on it, then maybe you might deprioritize that. I think that’s the point that you’re making and I can’t argue with that. Those things can happen. I’ve seen them happen. We can all, probably you and I both and every listener can think of our own experiences and our organizations and say yeah, I can give you four examples of where that took place. But the leadership that needs to happen is what overcomes that. And I don’t know what else to say except that’s the transition that the Colonel Jessups like I was mentioning in A Few Good Men, the movie played by Jack Nicholson.
Derek Brink [00:41:59]:
Colonel Jessups need to change their way of doing business they can’t just order the code red and have things happen, they need to work more collaboratively with other functions and those are different skills for the leadership as well as for the lower level hands on people. So that transition has to happen. I hope it happens by, by self selection and people who have those skills can mold and move into these roles. In some cases it might be that the old guard has to move on and the new guard has to come in in order for change to really occur.
Sanjog Aul [00:42:30]:
So if you were to look across the board and see different organization who may have partially applied a Big Data towards improving security and or some people are on the fence and others have tried and they are already deep down with it and basically are using it full throttle, what are the true results? What is it that what empirical data has been generated for it to create a strong or a bleaker case?
Derek Brink [00:42:59]:
Well, I’ve given you some example. When we do the benchmarking style of research that we use here at Aberdeen. I hate to make this about my own research, but since you asked, we’re asking questions of organizations and instead of just reporting because a lot of people do surveys, right, Instead of just giving an answer, this is such and such a percent said this. We actually have a technique where we kind of separate the respondents into those who had relatively better results than the others and those who had relatively worse results than the others. It’s kind of a bell shaped curve almost. We create a leaders class and a laggards class and in between there’s kind of an average and then we can compare those classes. So all that by way of just telling you how we do it. So the difference between the leaders and the laggards as found through my own work is that the leaders are in fact able to detect and contain attacks, let’s call them attacks earlier in the attack lifecycle.
Derek Brink [00:44:00]:
So they’re quantitatively showing that they’re able to detect and respond, contain and shut down these attacks earlier in that cycle. That I was telling you about, from reconnaissance to exploit to exfiltration and so on that’s a big benefit. If you’re able to close that window of vulnerability sooner, you not only of course are less exposed for a shorter period of time, but you also have the benefit of shutting down whatever data loss or data exposure there was of eliminating the downtime that might be a result of these kind of attacks, and so on. So that’s where the quantitative difference between best performance and sort of beginners or worst performance would come in.
Sanjog Aul [00:44:50]:
Let’s take a quick break, listeners. We’ll be right back. And then let’s look at actual solutions that are being offered from the different providers. And we don’t really necessarily have to name the providers, but what are the different flavors that are being offered, how effective do they look like, and to what degree there is a reliance on external vendor solutions? Or are organizations finding their own homegrown solutions to be a better fit for their unique needs? Please stay tuned. We’ll be right back and explore.
Sanjog Aul [00:47:43]:
Welcome back. So of course, you know, provider community, which is the vendors, they always look at an opportunity which will help them make a ton of money and of course they would like to put out solutions which would promise the moon in many cases. In other cases they are more realistic or they are point solutions. So if you were to evaluate or give a synopsis of what do you see is the state of vendor solutions that are available and to what degree are they are true to the claim that they are making in terms of helping actually security with infusion of Big Data?
Derek Brink [00:48:17]:
Yeah, I’m glad to respond to that. I will say as a disclaimer that at Aberdeen we don’t really rank vendors or any kind of magic quadrants or things like you might see from other analyst firms. But I will say that just in terms of general categories that remember I was telling the audience before about the leaders versus the laggards, kind of that differentiation that we’re able to do in our style of research where there are certain technologies that are very clearly correlated with the leaders as opposed to the laggards. The leaders are much more likely to have deployed these than the laggards. So they include things like, well, we’re talking about proactive and detection oriented products and service so that would include things like network vulnerability scanning or application vulnerability scanning, just periodically scanning for vulnerabilities, external threat intelligence, and subscribing to that kind of information so you’re smarter about what the threats and vulnerabilities could be around the clock security monitoring. So you have in that real time sense of what’s normal and what’s not normal and then we’ve talked of course about the platforms that can integrate intelligence from multiple sources and basically integrate create that Big Data repository, but then also give you the analytical platform that you can use to try to find the information and communicate and share the information.
Derek Brink [00:49:33]:
And also by the way, the use of third party incident response teams when there is trouble is an example of vendor solutions that are more correlated with the top performers. So that’s kind of a quick answer. I would also want to say one other thing and that is in more general terms, if you, if you were to just think about, maybe as a listener you could kind of do this exercise in your own mind. If you think about all the security controls that you have in place at your organization and remember that security controls doesn’t only mean technology controls, it also means administrative controls, it might mean physical controls, but if you think about those, you kind of make a catalog of those and maybe list those along the rows of the list that you’re making along the columns you could also split it into two simple column A would be the controls that are more oriented to prevent or deter things from happening, you know, to prevent an incident from taking place. And the other ones would be on the other side, which would be to, after an incident has taken place, to detect it, contain it and respond and sort of remediate and reestablish things back to the way they should be. I think what you’d find is that most of the implementations currently are on the prevent side of the ledger and that the growth in things on the detect and respond side of the ledger is nascent,
Derek Brink [00:50:56]:
it is growing. There’s many examples of doing it, but it’s by no means yet mainstream and I think really that’s what we’re talking about here is the augmenting of those traditional prevent oriented controls to the more detect and respond, analytics, intelligence, Big Data side of controls and so that’s what we see in the research.
Sanjog Aul [00:51:15]:
Do you think there is a better opportunity for a Big Data tool provider or solution provider to latch on the security related insights as part of a bigger tool set? Or is it better that a security provider basically infuses or finds a way to put an adapter to a Big Data source and that way you can make just enhance the existing tool which would in your view would best serve the end goal?
Derek Brink [00:51:43]:
Well, I think most security companies, I don’t mean to speak for them, but I did work in that space for many, many years prior to having this role as an analyst. And I think most vendors would take the approach of making their solution as applicable to as wide a market as they could. At the same time, they want to have focus so I’ve seen examples in both ways. I’ve seen examples of vendors who, who have a generic platform and market it as such and I have seen others who have taken an approach where they maybe started out focusing on security and they’ve subsequently said, you know what, we need to broaden our focus to include other things. So take that retail example, you can use things like video surveillance and video analytics to do things like protect the store or you can use the analytics to do things like say, hey, I can see that there’s a queue forming here and the lines are too long
Derek Brink [00:52:37]:
we better open up some new registers to improve our level of service. So there are some examples where it’s been used in a traditional security application and it’s being moved towards more of a revenue oriented application and there’s other examples where it’s maybe started out being more used for where people want to use it, which we talked about, which is probably more oriented towards revenue and yet vendors identify this wonderful opportunity to say, hey, you can also apply this to security and so they develop their campaigns and partnerships and so on and go to market around that. So I’ve actually seen both take place I don’t think one’s right or wrong, I think both are proper from the vendor perspective.
Sanjog Aul [00:53:17]:
Now, finally, what advice do you have for organizations and their respective leaders, both I would say CIOs and CISOs to push Big Data enabled security. And what do you think is going to be the future? I mean, of course you don’t have a crystal ball, but what do you expect the future to be in terms of of the level of threats that we are going to experience and to what degree this Big Data related solution or infused Big Data infused security solutions will be able to handle well.
Derek Brink [00:53:48]:
Almost hate to end this way, but it’s who I am. So I guess I’ll expose myself for the cynic that I can be sometimes, and I’ll mention a recurring topic that I like to blog about it’s this concept of a devil’s dictionary or a cynic’s dictionary. A guy first wrote it in the 1890s, I think, and I sometimes give examples in security so the definition that I’ve given and written in a blog already about Big Data is the shorthand term that solution providers use to hype an infrastructure that’s designed to help enterprises to ingest and store and search and analyze and visualize vast amounts of data, ignoring the fact that most organizations are still struggling to manage the small amounts of data in an effective way, that’s my cynical view, but if you set aside any jokes, the point is that I do think it will come, but it’s going to take time and you might say that awareness about security and awareness about Big Data is at a high, I think I would say that
Derek Brink [00:54:44]:
but the funny thing is we all know about awareness is that doesn’t necessarily bring about changes in behavior so we need awareness it’s necessary to bring out change, but it’s not sufficient so any 12 step recovery program would say this is kind of step number one. So it’s a simple point really but awareness by management and business leaders about Big Data doesn’t necessarily mean a greater understanding of what you can do with the data and it doesn’t mean more thoughtful and deliberate decisions and allocation of resources and greater awareness by end users and the training and exposure that we might get doesn’t necessarily mean any change at all in our behavior. So it’s a first step.
Derek Brink [00:55:20]:
My sense is that the heightened level of awareness is a great thing, we should celebrate that, we should take advantage of it but if we’re going to be real here, we should recognize that this, you know, we’re conscious but we’re not yet competent is an important step. It’s, you know, some of the earliest steps on the journey towards this ultimate goal. It’s like anything, it’s one step at a time. So that would be my view on.
Sanjog Aul [00:55:43]:
Behalf of the show and our listeners. I’d really like to thank you, Derek, for sharing your thoughts on how organizations can build a better security, better and stronger security leveraging Big Data.
Derek Brink [00:55:56]:
Well, thank you for having me, I really enjoyed it and I’m glad to contribute something to your discussion. Thanks so much.
Sanjog Aul [00:56:01]:
Thanks again! And listeners hope you got something out of this conversation. Hope you’ll be able to further secure your fort leveraging Big Data and get some tips from this discussion here. Please like us on Facebook, search for CIO Talk Radio and please be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul your talk show host till next week. Take care and God bless.
Speaker A [00:56:26]:
Thank you for tuning in to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. please join Sun Joke all next Wednesday at 7am Pacific Time, 9am Central Time and 10am Eastern Time for another hour of CIO Talk Radio on the Voice America Business Channel. CIO Talk Radio is brought to you by HP and Siemens Smart Grid.
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
-
- Big Data, Bigger Security Challenges
- Enabling ‘Big Intelligence’ Against APTs
- Cyber Espionage, APTs and Enterprises
- Data Security for the Digital Business
- Cloud Security Wish List
- Cloud Enabled Security
- Roundup: Cyber Security Month
- Cloud, Mobility, Social Networking, and Inter/National Security
- Utility Resilience And Security
- Security Challenges in Education Today


