Cloud Cybersecurity Data Analytics Infrastructure & Operations

Taming the data security beast

Taming the data security beast

Data security requires rethinking people, processes, and tools to protect data throughout its lifecycle across public cloud, on-premises, and hybrid cloud deployments no matter the size and scale. Marred with explosive data growth, privacy regulations, operational complexities, and acute talent shortage, enterprises are scrambling at best. What are some of the most progressive and creative security leaders doing to tame this beast?

Contributor

    • Leon Ravenna, Chief Information Security Officer, KAR Global

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Transcript 

Sanjog Aul [00:00:22]:

Hello, everyone, and welcome to this segment on CTN. To learn more, please visit ciotalknetwork.com. And the topic for today is Taming The Data Security Beast, and we have Leon Ravenna, Chief Information Security Officer with Car Auctions Services. Hey, Leon. How are you?

Leon Ravenna [00:00:39]:

I’m doing well. Thank you. 

Sanjog Aul [00:00:41]:

Very good. So we are talking data security here. And as you and I both have seen that we are trying to manage this data as it flows through the organization, and now we’ve introduced cloud in different flavors, whether it’s on premise, hybrid cloud, public cloud, you name it. So data when it is there in different places, first is how do you find where they are because there are some nooks and corners which are not even visible sometimes. And then secondly, as it goes through its life cycle, we want to keep it secured. How do we make that all happen and with the complexity of digital, which means even more data is pouring in at velocity and volume and variety? This is not becoming any easier. So if I were to request you to please inventory the top challenges that are preventing us from tackling it, because I know it is morphing, but we still have to do something about it. What would those be? What would be those most pressing challenges? 

Leon Ravenna [00:01:41]:

Sure. So when people think about data, they tend to think about it in the context of a data center. So I have all my stuff in a data center, and it hasn’t been that way for years and years. One of the first things people need to understand is that whether or not they believe they have data in the cloud, they probably do. They may have data in multiple clouds. So you’ll see organizations that didn’t think they had anything. They have data in Amazon. They have data in Azure, maybe a little bit in Google. And then the second piece of that is the services. The thing that people don’t think about a lot is the free services. So I can sign up for a Box account or a Dropbox account or Slack and I can use it, except you’re not really abiding by the terms and conditions if you are a corporation. And so you need to license those. And so one of the things that I’ve worked with people on in the past is understanding and, quite frankly, making sure that you are square with the provider. So going out to the Boxes and the Dropbox of the world to make sure you have a list of accounts that belong to your organization, and then paying for those as you’re supposed to and pulling them in so they can be accessed in a right and proper way. This may be bringing them behind single sign-on, so you can make sure you know that you’re going to the correct, quote, unquote, vanity URL for one of those companies and that you can’t get to those things outside the organization. 

Sanjog Aul [00:03:24]:

Now when you do see those places where you’re going and you’re finding that there are certain, these things that you talk about, the long terms and conditions, which I do not know if I’ve ever read or I can read and make sense of. Are we expecting people to suddenly become so cautious that they’ll have an attorney or someone from their general counsel’s office to sit next to them every time when they sign up for a public cloud? Is that in the works, or is that even in place as we see it today? Otherwise, if it’s not, that’s more work for you. 

Leon Ravenna [00:04:01]:

Yeah. And realistically, you can’t guard against the fact that people can sign up for services. I mean, it’s easy enough to use your web content filtering to block out file sharing. But what you end up finding is that typically, you’re going to have your legal folks that need to share large files with outside counsel. You’re going to find that there is a definite business use case. You can use CASB tools. You can use things like Palo Alto looking for what’s flowing through my system to start to get a handle on what accounts I have, and then go and say to those companies, someone will come to you and say, I see that your company has signed up for x number of accounts. Do you want us to go ahead and do that for everybody as a first start? But to your original question, people are not going to sit with a lawyer every time they do anything on the Internet. It is a process of being vigilant and understanding how your process and workflow actually happens within the organization.

Sanjog Aul [00:05:23]:

So if you build, they don’t usually come. If you tell them, please watch for terms and conditions or watch for the gotchas, people don’t because they are so excited and so consumed with the outcome they are looking for using that tool that they just want to get through it quickly. And if we try to create stumbling blocks or obstacles in their way, you are seen as a no person or someone who’s causing more nuisance versus helping.

Leon Ravenna [00:05:55]:

How absolutely.

Sanjog Aul [00:05:56]:

Do you think anyone can get over that hump?

Leon Ravenna [00:06:01]:

So the way that I have seen that work in the past is that we pull those groups in. So we’ll use Box as an example. Get a list of accounts, go to those people and say, look. We’re going to license this appropriately, and then we will make it easy via things like single sign-on. You don’t have to log in. We will take care of those things, and we’ll take care of that as a service, not necessarily as you have to manage this on your own. Because quite frankly, what I have to be concerned about is where the data is and what that data is and how you handle that sprawl. In most cases, organizations haven’t thought about where all of their data is. They still think it’s kind of constrained to these couple places that we know it is. But in reality, it’s all over. So to your point about not being the no guy, it’s the here’s how we can help you make it easier. There’s always going to be some level of constraint. You can only use certain services. But at the far end, once you have turned the services on that are right and proper for your organization, you can then turn around and block the rest of them if you choose. So there’s a way to be kind of that know security person, not necessarily the guy that always says no.

Sanjog Aul [00:07:43]:

Now in this response that you gave, the premise is that if we come to know that somebody’s using a tool, right, a Box or whatever other tool that we talk about, that means we are going to discover the wrongdoing and then take corrective measures. Means we will play catch up, which is okay. It’s better than nothing. But then do you think there is a way for us to get a little more proactive and get people to feel obligated to inform you that I am interested in this service. Please see how it can be done without me creating more problems or creating more risk for the organization.

Leon Ravenna [00:08:29]:

Sure. You’re always going to have some legacy pieces. You’re always going to have some things that we found out about and then go correct. Not in a punitive way, but in a here’s we understand that there is a business process that needs to be addressed. So let’s help you provide that function that’s necessary. Part of it ends up being organizationally, when you are looking at new tools, you need to go through the right and proper procurement channels. There is the case for, on the punitive side, examining T&E charges, examining things like procurement cards for are there things being procured outside of the procurement organization? And then pulling those back in, again, not in a punitive way, but let’s make sure that we’re doing things properly. And then making sure that when you go to buy things, you’re running those past your legal folks, past your security folks. We end up reviewing a huge number of contracts for vendors and for customers just to make sure that we understand the security and the privacy provisions that are in there and make sure that we’re not signing up for something in error. Most people don’t bother reading the many pages of a license agreement or most anything; they just press the accept button. There’s some interesting stuff buried inside of those, but it’s more about us helping people to get their job done as opposed to standing like the roadblock in the way. 

Sanjog Aul [00:10:23]:

What would you say is a good benchmark for good or adequate data security? Because as you mentioned that there will be always something that we are patching or plugging the holes. Mhmm. For the most part, that could be part of daily life of CISO and the troop. But then what would you do to make sure that we create a holy grail or a blueprint of this is what data security should be? These are the threshold values above which we should play in terms of risk prevention or detection and later intervention. What does that blueprint look like? 

Leon Ravenna [00:11:02]:

Realistically, the things are always changing, and you can’t say here is the benchmark and it’s never going to change. There will always be things that come up. There’s monthly things that come out from Adobe and Microsoft, and there’s always something that happens. You can’t really say I can accommodate for everything. I don’t know anybody that’s perfect, no matter how much money they’ve spent. But I think the focus when you start to look at what are the things that we have to do to make sure that we are providing a secure environment. Number one, it’s the basics. At your house, if you ignore your furnace, you’re going to end up on the coldest day of the winter with no heat. And so you have to be doing normal maintenance, and those normal maintenance and due diligence things are your patching, are making sure that your things like SSL certificates are up to date. There’s the due diligence stuff that is the ongoing not very sexy part of security. It’s just diligence and getting those things done. You can add any number of tools. I end up seeing probably 30 to 40 emails and voicemails a day on here’s the best new product ever, and trying to sort through those. You’re basically looking at what is right for my organization? What are the threats that we’re actually trying to guard against? If you as an organization say you make shoelaces and you are trying to guard against nation state attacks, that’s probably the wrong thing to try and guard against. The first is understanding what your threats are. Typically, an actor is going to do an action to an asset because of their motivation for a result. It’s I’m going to do something, and it’s typically I want to harm somebody or I want to make money, and it’s understanding what those threats are. Once you have an understanding of what the threats are, then crafting the things that start to make sense for your organization. There are some basics that people will always need. You’re always going to need some type of antivirus. You’re always going to need the ability to encrypt machines. You’re always going to need the ability to look for and block bad content and things like spam. A typical organization is going to see 80 to 90% of the mail that actually comes into their organization should be dropped because it’s junk, and it’s just not appropriate. Then you start to get into how am I looking for threats? What are the threats I anticipate? Do I anticipate corporate espionage? Do I anticipate somebody trying to steal intellectual property? And building those defenses around what the threats are.

Sanjog Aul [00:14:37]:

Let’s take a quick break, listeners. We’ll be right back. And Leon, when we come back, there would be a good conversation to be had on balancing the cost versus the value or rather risk mitigation because there is nothing like a 100% secured environment. And organizations, of course, would like to have that, but then they’ll have to spend $1,000,000 a day. Mhmm. How does an organization decide on data security? Let’s take this as the scope since that’s what we’re talking about today, that this is the level at which we have to stay because this is gonna cost me less than $900,000, and that is acceptable to me. Where does the security level and the cost equation how do you go about even creating that equation for an organization? Because you cannot always have 100% security, and then you cannot spend all your revenue on just making the organization secure. That’s being practical. So how do you go about it? Please stay tuned, listeners. We’ll be right back.

 

Sanjog Aul [00:17:35]:

Welcome back. So, beyond when we look at balancing the cost versus risk, you know, it’s an age old problem, no perfect solution, but there has to be some form of equation building approach, which will allow you to eventually get to a point where you say, okay. If I’m gonna spend x number of dollars, this is just gonna get me enough risk prevention or mitigation that it will make business sense. What are the tenets of this? And how do you how does one approach it?

Leon Ravenna [00:18:08]:

As you look at how much do you spend, how big is the organization, you start to ask yourself again, what are the threats that I worry about? Again, if I make shoelaces, there’s not a lot of people who are going to come to me and try and steal my intellectual property. But what you’re looking at is understanding the data that you have, and you may have regulatory concerns, you may be in the health care space or the education space and have laws that you have to abide by. If you’re taking credit cards, you’re going to be in the PCI space. So there’s a certain level of things that you’re going to have to hit no matter what, to be able to accommodate those regulatory pieces, those compliance pieces. Then it gets to the threat that you’re trying to protect. A lot of people end up tying things to customer contracts. So a customer says I have to do x, y, z. If you’re in the banking space, those are going to be stiffer requirements than if you’re in some of the more manufacturing spaces that don’t have as much personal data. With the advent of GDPR and CCPA, states and countries are starting to tell you here’s how things have to work. There’s also other compliance things that are starting to roll out. There’s things like modern slavery. There’s things around sustainability that people are going to start to have to answer as to how does my organization actually get stuff done, and those all get essentially tossed in a blender to say, okay, to accommodate a wide range of things that an organization has to deal with. Here are the things that we have to set out as our core tenets. We’re going to protect our individuals. We’re going to protect the machines they use. We’re going to protect the outer perimeter and the soft edges, be it AWS, Azure, or Google. And those things all have a cost. Some companies will say, well, I can deal with whatever the fine may be. However, in the last two days, you’ve had British Airways fined $230,000,000 for GDPR issues. You’ve had Marriott fined $99,000,000 for GDPR issues dating back to 2014 when they bought Starwood, and it’s around due diligence of the acquisition. So you start to look and say, well, can I pay the fine? That’s pretty stiff. So you start to set up a threshold that says, here are the things that are important to my organization. In this pathway that we’re going to get them, the most important things first, protect my individuals, protect my company’s data, then getting into some of the more esoteric things. Do you want to probe the dark net? Do you want to see if there are threats that are coming out that way? Or how well are you getting back to some of the basics again? You can’t overstate: are you doing your routine due diligence? Are you getting the basics done? Those are the maintenance things that tend to break. 

Sanjog Aul [00:21:47]:

Now when you look at the data, which, of course, we know the data is everywhere, and I did mention as part of the introduction it’s just invisible and not so visible crevices in the organization. Do you think organizations, before they try to secure it, have started working towards pulling all of that out, putting it on a single pane of glass, see how it is flowing so that they can invite you and say, folks, help us secure it.

Leon Ravenna [00:22:17]:

And so that would be ideal, but ideal is not the world that most of us live in. Most organizations don’t understand the data they hold, and so what you end up finding out is that you may have thought you hold some of the basics, name, address, email, phone number. But you also happen to hold Social Security number for some reason. Historically, what I’ve seen in the US is that people will try and gather as much data as possible with the notion that we can monetize this later, but then you’ve got years and years of personally identifiable data that puts your organization at risk. Some of the tenets of the new privacy laws are around data minimization. What do I actually need to hold, and how do I manage that? So if you have a system that is 30 plus years old, and you’ve got 30 years of data, if you have an issue with that system, how are you going to go tell 30 years worth of people that you had an issue? Understanding the data and building that data map for your organization, guaranteed it will look like a cracked windshield. Essentially, you’re going to have data moving from system to system, and you will see, if you do the diligence on this, you will see data moving from System A to System B internally, to System B externally, and then you have to ask yourself the question, do I sell that data? Do I share that data? Building that logical data map is difficult, because in a lot of cases, people don’t know. But guaranteed, if it doesn’t look like a badly cracked windshield, you probably haven’t done the due diligence necessary. Ideally, the first step is to start with what data do I have, what data do I protect, because you can start adding controls to those systems that hold your most sensitive data.

Sanjog Aul [00:24:38]:

So would you say you’ll have to sit, wait, and watch for, say, the CIO’s group or the chief data officer, whosoever is as a data guardian or custodian to give you a blueprint, and then you can get started. Because, otherwise, why would you be left or you should be holding the bag if there is a data breach because you were not even able to get all the data or the snapshot of where it is at least today and how it’s being run. Why would you own it? You shouldn’t.

Leon Ravenna [00:25:05]:

Right. It has to be a relationship between CISOs, CIOs, chief data officers to make sure that you understand what’s actually happening. The location I work today, I have a phenomenal relationship with the CIO and his management team. So we work hand in hand on a number of things. Most organizations don’t have that luxury, but you can’t wait for that to be handed to you. If it doesn’t exist today, it’s critical that you know where that data is and what sensitive data you have, and quite frankly, what sensitive data you send. Depending on the organization, if you’re in the health care space, you have to know you’re dealing with people’s health care information, or with their lives. You have to protect that. Based on the organization that you’re in and the threats you have, it will help you decide what to do, but without having an understanding of the data that you hold, you’re fighting blind. You don’t have the ability to know that if for some reason a system is being attacked, and it doesn’t have sensitive data, doesn’t have personal data, maybe it has vehicle data. Is that valuable? It’s not nearly as valuable as something that would hold Social Security, credit cards, and things like that.

Sanjog Aul [00:26:48]:

Let’s take a quick break, listeners. We’ll be right back. And let’s talk about the common benchmark. So, as you mentioned, Leon, there should be relationship between the data leaders, the CIO, and the CISO. Now even though you have relationships, but at the same time, if there was not a common understanding of what that data quality be, then there should be no responsibility attributed to the CISO to be able to secure it. So is this fuzzy? Is there some more clarity needed? Are the way these things being handled, could that be improved in terms of common benchmarks and standards and level of visibility into the data? So that before we say let’s go and secure something, we have that in place. And I know if there even if there is a shift in the environment and the data, well, volume and variety and velocity keeps changing, but it is it should be first be the baton should be first, first held by the data and the CIO leaders or the information leaders before it is handed over to the security leaders because you are more at the tail end. But is that the right way? What kind of common benchmarks? How do you make it happen? Let’s discuss all that. When we come back, please stay tuned listeners.

 

Sanjog Aul [00:30:11]:

Welcome back. So there are relationships among the different information data and security leaders, but that’s not enough. You got to have common standards and benchmarks, and data security should be everyone’s responsibility. But what’s happening in that regard? Are we just discussing challenges or we are thinking solutions? Leon?

Leon Ravenna [00:30:31]:

From a solution standpoint, you’re going to look at things like ISO 27001. You’re going to look at NIST CSF. If you don’t have something that you are benchmarking against today, I strongly recommend that you go do it. Realistically, the NIST CSF framework is probably one of the easier ones to align to, and it’s not as stringent as some of the other NIST standards. Going back to your original question on relationships, it is a shared relationship. There’s too many times where something happened and it’s, well, it’s the CISO’s fault because he didn’t anticipate or didn’t think about it. One of the things that I have today is a great relationship with CIO and with IT, working with them to help make them better because what we’re trying to do is make sure that we are building trust for our customers. A lot of the tech companies have done very well: if you look at Amazon, you look at Microsoft, they have all of the appropriate standards and guidelines in place. You can get a SOC 2, you can get ISO 27001, you get all those things from them. If you don’t have something in place today, it is critical to think about what do I benchmark against? Because I can’t really tell am I weak in how I respond to an incident, or am I weak in detecting an incident? If you don’t have something, I would probably look at the NIST CSF just to be able to start thinking about how you start to paint the picture. NIST CSF ends up building you a spider graph, and it will show you, hey, I’m weak in this area. That’s where you want to be able to translate this to: I need to do these five things to increase our diligence there, and I may have to go buy a system. That’s where you start to use those things to measure. I need to go spend this much money because I need to raise that score from, you know, from 3 to 5. There are a number of companies today that will rate the outside of your network. There’s BitSight, RiskRecon, the security scorecards that are passively looking at people’s networks and then providing a score. What you may end up seeing in the next 6 to 9 months—it’s already started happening—is people using those scores from a third party vendor management standpoint. So people are rating you on the outside of your network to how you do due diligence. If you don’t have a way to say I am starting to rate myself, somebody’s going to do it for you and you’re not going to be very happy with the outcome.

Sanjog Aul [00:33:52]:

Now you mentioned about relationship, and you explained about these different standards and frameworks. But on the ground as a reality, do you think the data officers, the information officers, and the security officers are so thick when it comes down to the real stuff that the other two, other than the security officer, will take the bullet for the security officer. Or are they saying, yes. We have a great relationship, but we are struggling ourselves, so we are not able to give you what you want, so you cannot secure the fort. So you’re on your own when it comes to you getting fired.

Leon Ravenna [00:34:27]:

Yeah. And realistically, from a very cynical approach, there’s somewhere between 3,000,000 open jobs right now in the security space, so there’s somewhere to go. Again, that’s very cynical. I spend a lot of time working with the CIOs and with folks that control data for businesses to understand that it is a shared responsibility. Building that relationship is as hard as it may be, particularly if you report to the CIO, that can be more difficult. In my case, I’ve always reported to the CFO. So there’s a separate budget, separate way of doing things. But it really comes back to how much this goes back to the CISO reaching out. It can’t be here’s what you will do, and here’s how you do it. There has to be an understanding of relative risk. When the CIO says, look, I need to deliver future functionality, that’s fine. Let’s build security into your process so it becomes part of everyday life, not necessarily something that gets tacked on the end. For example, if you take the approach of encrypting everything in a database whether you have sensitive data or not, you may at some point in time have sensitive data. I don’t want to come back two years in because now you’re collecting something that is sensitive. I would much rather say those systems are encrypted. We have that level of protection. I’m okay if you do new things. It’s working more towards the front end as opposed to the back end, and that’s where driving the relationship hard really has benefit. If you’re just the last rung of the ladder that people have to get by, people will find a way to go around you as opposed to come to you and say, I have a question. How can you help me? So it’s a lot about relationships. I put it squarely in two camps. One is you have to build a relationship. I’ll put this on CISOs: if the CIO is not working to maintain that relationship, but quite frankly, it’s shared. So everybody gets blamed.

Sanjog Aul [00:37:24]:

But do you think the data security related challenges or breaches when they happen, is it attributed to the CIO not doing their job or are you left holding the bag as a seesaw?

Leon Ravenna [00:37:37]:

If you look back to Equifax, there’s a Senate report that came out on that, and everybody got in trouble there. There were too many things that didn’t happen. I’ve done infrastructure and security. When I’ve done the infrastructure side, I knew that I have to take care of uptime. I have to take care of making sure that my systems are available and reliable. If you’re not managing those basics, then you’re going away anyway. I really look at it more as it ends up being a shared responsibility. At the end of the day, if there is an issue, somebody’s going to be left holding the bag. Quite frankly, it’s moving more towards not necessarily security, but it’s moving higher up the ladder, and so it makes my job even more important to make sure that I’m protecting my organization but my senior executives. 

Sanjog Aul [00:38:51]:

So you mentioned about the job and number of jobs open and the talent shortage. Right? And then totally understand that you cannot just suddenly produce 1,000,000 people. With that said, even organizations which have large teams and they have MSSPs, managed security services providers, even they are scrambling. Even they don’t have their act together. I would never say it’ll ever be 100%, but close to being together. So what are we missing?

Leon Ravenna [00:39:27]:

What’s interesting: I have 3 kids; my youngest is a sophomore in college, and I’ve tried to convince them to go into the security space. They look at my schedule over the last 30 years and say, well, dad didn’t come home last night because he was working on a problem. I don’t really want that. What you have is a lot of people in school today that are not choosing those paths. When it gets right down to it, security is a lot of time looking at spreadsheets, looking for anomalies in data, and looking for things and thinking outside of what would be traditional for how you might be attacked. One of the things that I’m starting to see is some of the immersion training. You have organizations like Google and Apple saying they’re okay with not having a college degree. That can help. Going back to some of the immersion training, there’s an organization in Annapolis that does immersion training and development. They will take 12 to 14 weeks and teach you Java or languages, and then they are taking entry level positions. Those organizations are starting to do the same thing in the cybersecurity space. They’re building cyber ranges. They’re building things where you can get trained so you have an adequate level of skills to start. I think that’s going to be more of what we see in the longer term, because it ends up being more of a trade as opposed to having been classically trained. My background was liberal arts college and studied computer science and business. People aren’t willing to wait the four years to get through school to start a job. I think some of the immersion programs are really going to help. One of the things we’re looking for in security is a different way of thinking. It’s not necessarily that you’ve been classically trained, but it’s more you think outside the box and look for things that are not normal. It’s here’s how I would go break something, and start looking that way as opposed to always following a defined path. Some of your best folks are not in what you would think is the classic path. I have a couple of guys working for me that have high school degrees and didn’t go to college, and they’re really good at what they do. I’ve had folks in the past; one guy was mid fifties, had been in the army for a long time and ran a warehouse. He called me and said, I want to understand security. I told him some classes to go to. He did that. He got his first job. He’s making over 6 figures now working for a company doing PCI stuff. There are all kinds of ways for people to break in and get trained up. So it’s not going to be the classic way; it’s going to be taking people and building them.

Sanjog Aul [00:43:10]:

So one is that we play catch up. And the reason I say that is because we have our infrastructure and our computing paradigms, the way we want to handle data, all that is shifting. And that is even disruptively shifting, not incrementally. And that’s gonna continue to happen. If we are to look at that as a given, what are the possibilities of rethinking data security so that we could insulate to the maximum extent from such fundamental shifts? Is that a possibility? I’m not expecting the CISOs to go to a two week vacation to Hawaii and nothing will happen behind their back because there will be. But could there be a fundamental rethinking that can happen by the security leaders versus always playing catch up so that they can handle this ongoing madness? Please stay tuned, listeners. We’ll be right back and explore.

Sanjog Aul [00:46:06]:

Welcome back. So we have spoken about challenges at people level, relationship level, processes level, and the data security, the beast it is. With so much changing fundamentally and incrementally, could the security leadership and the folks who are at the forefront of handling or reimagining security start rethinking this whole thing a little bit? And so we can get ahead of this versus always feeling like tired warriors. Is there something being done in that regard? And if yes, what?

Leon Ravenna [00:46:39]:

Yeah. If I were to offer one piece of advice, take a step back from your day to day job. It may be worthwhile taking a day and just thinking about how do we make things better? How do we move security forward in the design process? If you had the ability as a CSO to say I have three things that I want to start with at the very beginning that my development teams were doing—are they encrypting things? Are they using certificates? How are they protecting it, and how are they building it into the design? I think that’s a day or two of off-site thinking that’s very valuable, to take that step back and say I have this legacy stuff that I have to deal with. Got it. But for anything new, here’s the path we’re going to go down and making it as low overhead as possible, giving your development teams and business the ability to run on anything new that they’re building. Does that fix the problem? No. But it starts to take away things that you’re worried about 9 months, 12 months, 18 months from now, so you can focus on those legacy things where 10 years ago people didn’t think about adding in security. So really, it’s taking a step back and reimagining what’s best for your organization, and what are the threats you’re fighting? It’s not 10 things, maybe it’s 3 things that you want to get accomplished over the next 12 months.

Sanjog Aul [00:48:47]:

Let’s talk about the solutions. I hear two types of problems. One is there are too many. It is tough to choose from. And secondly, everyone promises the moon, but it doesn’t land that way when you try to look at the demos or even start using it. So if you look at data security, I’m sure there are different types of security domains somebody has to manage. In the data security domain, if you look at the solutions that are available, we don’t necessarily need to take names here. But are they keeping up? Are they truly understanding and bringing solutions to the table which will solve your problem? And are they even alongside with you as leaders, envision what’s coming ahead and getting up for that?

Leon Ravenna [00:49:37]:

The tool piece is interesting. I get 30 to 40 pings a day on here’s the best product ever. Quite frankly, most of the products that people have bought, they use 15% of what’s there. I think the average on things like Microsoft Office is you use 10 to 15% of its capabilities. If you’re using 10 to 15% of your security products, you’re buying an awful lot of things. If I had one piece of advice, go exploit the tools you have. Several years ago at a different company, the CEO changed strategy at the beginning of the year. The products that were selling well weren’t cloud based, so he wanted to change that. I knew right away that we weren’t going to go buy a bunch of stuff. The conversation I had with my engineers was, we’re going to fully exploit the tools we have, and we’re going to find that at the end of the year we will have gotten more accomplished than if we went and bought a whole new set of tools. In a lot of ways, that actually worked out. There weren’t things that we didn’t need, but we used what we had and made it more valuable. I think that conversation with your senior leadership and with your board when you say, look, I have been able to—I’m not at 100% utilization, but I’m using 65% of the tools I have, and there are specific things I need to go get—that’s a much easier conversation than saying here’s the new cool shiny thing I need to go get and then it’s going to go sit on the shelf. I’ve bought a bunch of products, but I’m not really using them. I guess the question I would ask people who say they’re fully utilizing their tools is, can you be a reference for that company based on the depth to which you use those tools? There’s no shortage of new tools that solve something. A lot of times you end up hearing artificial intelligence and machine learning and blockchain—kind of a bingo on who’s going to say what. At the end of the day, most solutions end up trying to fix a problem that you may not have, as opposed to understanding what you really need to get done and here’s how I go attack those things that are of particular issue.

Sanjog Aul [00:52:33]:

On behalf of our show and the listeners, thanks so much, Leon, for sharing your insights about how we can rethink our people, the processes, and the tools. And I’d say also rethink how we are being security leaders and how our counterparts in data and information leadership should work together to tame this data security beast. Thanks so much.

Leon Ravenna [00:52:56]:

Sure thing. Thanks for having me.

Sanjog Aul [00:52:59]:

And listeners, hope you enjoyed, got a few nuggets out of this. Please like us on Facebook, search for CTN, that’s CIO Talk Network, and be sure to follow us on Twitter and join our LinkedIn group. Thank you again for listening to this segment on CTN. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.

Contributors

Leon Ravenna

Leon Ravenna, Chief Information Security Officer, KAR Global

Leon Ravenna is Chief Information Security Officer at KAR Global. He leads KAR’s efforts in global security strategy, execution, and privacy and compliance services for the company’s more than 17,500 employees. A seasoned CISO, Leon has... More   View all posts
Add Comment
Click here to post a comment

Advertisement

TECHM - GENAI - MPU02 - 300x300
Leon Ravenna