Episode 309 ·

Tony Cole - CTO at Attivo Networks

Today we are talking to Tony Cole, the CTO at Attivo Networks.  And we discuss their suite of detection tools that can help to mitigate damaging cyber attacks, risk management concepts that CTOs of all levels should be thinking about, and Advice for how to lead in times of crisis.

All of this, right here, right now, on the Modern CTO Podcast!

Check them out now at AttivoNetworks.com!

About Tony:

Tony Cole is the CTO at Attivo Networks, the leader in the Cyber Deception space working to deceive, detect, and defend enterprises from cyber-attacks.

Prior to joining Attivo Networks, Mr. Cole held executive positions at FireEye, McAfee and Symantec. He’s retired from the U.S. Army, where he worked in intelligence, communications, cryptography, around the world including building out the Network Security Services at the Pentagon.

He previously advised Wall Street on security technology and was on the advisory board for Secure Elements prior to its sale to Fortinet. Mr. Cole has served on the US President’s National Security Telecommunications Advisory Committee’s IoT security subcommittee. He also served on the Federal Communications Commission’s (FCC) Communications Security, Reliability and Interoperability Council (CSRIC-V). Mr. Cole served previously on the Board of Directors for Silent Circle, and today serves on Bayshore Networks Advisory Board. In 2017, he was elected by (ISC)² constituents to serve on their Board of Directors and was also appointed by the NASA Administrator to the NASA Advisory Council (NAC). He is a former president of the Information Systems Security Association -District of Columbia.

Mr. Cole speaks at security conferences across the globe such as the G20, RSA Conference, World Economic Forum, Munich Security Conference, CyberTech, and has been a contributing author to the SANS Institutes’ publications and classes. He’s been featured online and on TV and radio, such as CNN, BBC, Politico, the Hill, Washington Business Journal, ABC, USA Today, and the Washington Times.

In 2014, he received the Government Computer News Industry IT Executive of the Year award, and in 2015 he was inducted into the Wash 100 by Executive Mosaic as one of the most influential executives impacting Government. In 2018 he was awarded the Reboot Leadership Influencer Award by SC Media. Mr. Cole is also a volunteer member of the WhiteHat USA Board, a charity benefiting Children’s National Medical Center. He has a bachelor’s degree in computer networking and is a Certified Information Systems Security Professional (CISSP).

About Attivo Networks:

Attivo Networks®, the leader in lateral movement attack detection and privilege escalation prevention, delivers a superior defense for countering threat activity. Through cyber deception and other tactics, the Attivo ThreatDefend® Platform offers a customer-proven, scalable solution for denying, detecting, and derailing attackers and reducing attack surfaces without relying on signatures. The portfolio provides patented innovative defenses at critical points of attack, including at endpoints, in Active Directory, in the cloud, and across the entire network by preventing and misdirecting attack activity. Forensics, automated attack analysis, and third-party integrations streamline incident response. Deception as a defense strategy continues to grow and is an integral part of NIST Special Publications, MITRE Shield, and its capabilities are tightly aligned to the MITRE ATT&CK Framework. Attivo has won over 130 awards for its technology innovation and leadership.

Links Mentioned In The Podcast:

CyberVet: http://cybervetusa.com/

SANS CyberTalent Immersion Academy: https://www.sans.org/cybertalent/vetsuccess

VetsWhoCode: https://vetswhocode.io

Veteran’s guide to a cybersecurity career: https://cybersecurityguide.org/resources/veterans-guide-to-cybersecurity/

Veterans: Launch a New Cybersecurity Career: https://niccs.cisa.gov/training/veterans

Cyber Veterans Initiative: https://www.cybervets.virginia.gov/

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Tony, the CTO at Attivo Networks, and we discuss their suite of detection tools that can help mitigate damaging cyberattacks, risk management concepts that CTOs of all levels should be thinking about, and advice for how to lead in times of crisis. All of this right here, right now on the Modern CTO Podcast. Here we go. This is the Modern CTO Podcast.

(Tony at 00:00:37) How are you today?

(Joel Beasley at 00:00:38) Fantastic. I heard you're from Bradenton.

(Tony at 00:00:41) I am. I am.

(Joel Beasley at 00:00:43) Did you go to school here, or were you just here as a child?

(Tony at 00:00:47) No, I was there as a child, and my parents moved around. Dad in sales. So I lived in Vermont, New Hampshire, California, Massachusetts, Virginia. But most of my summers, even as a kid though, were back in Florida with cousins.

(Joel Beasley at 00:00:59) So if he was in sales, how'd you end up getting into technology?

(Tony at 00:01:03) I actually—he passed away when I was a teenager, and I was a poli sci major and dropped out of college, joined the military. And once I joined the military, that was my start in cybersecurity, long before it was an industry or fashionable.

(Joel Beasley at 00:01:19) Really?

(Tony at 00:01:20) Yeah. Yeah.

(Joel Beasley at 00:01:21) So you were on, like, some of the original cybersecurity, I guess, government teams?

(Tony at 00:01:27) Yeah. I actually joined as a cryptography repairman, went to school for a year on that, and learned encryption theory based on the Rainbow Series and Orange Book and some of the great work that NSA did long, long ago, along with the predecessor to NIST. And I built and repaired those systems for many years until the internet sprung up and we started connecting stuff, and they dragged me into the full gamut of cybersecurity. And I helped start the Army Computer Emergency Response Team. That's really where I got my start completely in the full gamut of cybersecurity as we know it today.

(Joel Beasley at 00:02:04) That's pretty cool. What did you learn from all of that? From setting up the Army Emergency Response Technology Team?

(Tony at 00:02:12) Yeah, the Army Computer Emergency Response Team, the ACERT. I learned a tremendous amount in the early days. This is in the nineties. It was very, very complicated, very difficult because we were advising. We didn't own all the assets across the Army, which at that point in time was probably close to about 800,000 assets across the Army, and we didn't own it. So, but we would identify things that were going on and try to get them to fix it, send teams out, try to help them fix it. So very problematic the way it was initially structured, along with a lot of fistfights from the seniors, the generals, over who owned that functionality, because at that point in time it was part of an organization called Land Information Warfare Activity. And that was really part of information operations, which really for DOD it still is today. Cybersecurity is a large component of information operations. So it was a lot of fun. But I did that one, and then I built a regional team as well in Korea for the military in Korea. And then I came back and restructured the Pentagon Security Agency and built the PENCER. So founded the PENCER and then retired after 9/11.

(Joel Beasley at 00:03:29) That's unbelievable. That is such an interesting background that you have. And you also spent some time at NASA?

(Tony at 00:03:36) Well, I didn't work at NASA, but I worked for NASA.

(Joel Beasley at 00:03:41) Okay.

(Tony at 00:03:41) Yeah.

(Joel Beasley at 00:03:42) We're going to say you were an astronaut. We're gonna just put that in there.

(Tony at 00:03:45) Hey, if they called me and said, we want you to go up, I'd be there in an instant. Obviously, it would have to be via commercial means because I have no astronaut training whatsoever. But no, they asked me if I would join the NASA Advisory Council, their institutional subcommittee, which is looking at how facilities were being connected in the cybersecurity facets for that, a number of years ago. And I said, you know, hey, NASA wants me to join. And whenever I was active on those committees, I was a special government employee. And then, you know, after a while they sunsetted that committee and asked me to move up to the NASA Advisory Council proper, reporting to Jim Bridenstine at the time, the NASA administrator. And so I did that and just absolutely loved it. So absolute blast. As a geek, Joel, and I've listened to your podcast and I know you are as well, I would sit there listening to the different briefings from all the program managers, the mission directors, and it was fascinating for me. I would have to try to tell myself to focus. Think about the aspects of risk management for this and stop geeking out over this. And I was also for a while—there was a really great guy on the advisory council with me, Ken Bowersox, who is a former shuttle commander in ISS. Spent time with the ISS and did some of the original Hubble repairs in space. So really smart, cool guy. But I would lean over and I'd say, Ken, what are they talking about? Because, you know, I'm learning heliophysics. I'm a cyber guy. I don't know many of the concepts that we're talking about, sometimes at a pretty lengthy depth. But anyway, great fun working at NASA.

(Joel Beasley at 00:05:31) And you focus primarily advisory council and your specialty was software. So you did advisory in the software area there?

(Tony at 00:05:39) Really, it's risk management, but all around the cyber aspects because, you know, for risk, it's a tremendous challenge way back from the Apollo fires where they've got another committee called the ASAP, a congressionally appointed committee, and they look at safety for everything that happens for the missions. And that includes with any mission partners. So SpaceX, Blue Origin, Virgin Galactic, any company that would provide space travel, satellite launch, restocking the ISS as a service, you have to worry about that as well. So the ASAP looks at all those pieces and the safety associated with it. So I would advise the NASA Advisory Council and the chair there, General Lester Lyles, and the ASAP on how I saw cyber risk related to the programs that the CIO and the CISO there, Mike Willett, who's a brilliant guy, were building across our entire platform. And it was a tremendous amount of fun and a great learning experience for me as well. I mean, some brilliant, brilliant people at NASA.

(Joel Beasley at 00:06:39) What are some of the risk?

(Tony at 00:06:42) Oh, well, you know, one of my favorite ones to talk about is I was talking to the CIO long ago there and asking about her patching cadence on systems. And it's very, very interesting and turns very quickly into a controls discussion versus a patching discussion around some legacy systems. Most of the people you talk to, they think about legacy. You know, here's some OT systems that are connected to the internet that we don't want to patch because we want fifteen years out of these things, and it was never designed for a patch. But what about something like Voyager that was launched in 1977 and it's now left our solar system? How do you patch that? Right? So you can't. So it's really, really interesting, some of the challenges that they have in the way they've had to change their control structure to mitigate risk for that environment.

(Joel Beasley at 00:07:34) That's so fascinating. And all of this experience prepared you perfectly for what you're doing at Attivo. Right? Is that how I say it? Is it Attivo?

(Tony at 00:07:42) That's correct. Yeah. It's the first thing I learned when I started talking to this company was to enunciate because people would say, wait, you're going to a DVR company?

(Joel Beasley at 00:07:52) Not TiVo. Attivo. Yeah. That's good. So what do they do? What's their core competency?

(Tony at 00:07:59) Well, their core competency is really around detecting privilege escalation inside an environment and detecting lateral movement. So there's a lot of facets to the technology that can help you prevent. But the most important piece and the driving factor for us has been completely across the board, detecting the adversary inside the wire. Because as we know—I mean, just open a paper today and look at the technology section, and there's gonna be a lot of stories about ongoing breaches, breaches that have been hampering operations for a long period of time and potentially impact that we're not aware of yet from some of the recent source code challenges. So what we're doing is we're shrinking that dwell time inside the IT environment in a very quick fashion by detecting that lateral movement and looking at privilege escalation through a whole bunch of different means, looking at misconfigurations in Active Directory, ensuring that once the adversary is inside the system, we have a structure to alert quickly on it as well as provide deceptive information back to that adversary, which is a tremendous amount of fun. So really, we're giving the cyber defenders home field advantage. We're making them start to understand it's your enterprise, run it like it's your enterprise, and don't let the adversary have an advantage over you because there's no reason to.

(Joel Beasley at 00:09:18) It's a little bit of offense in the defensive strategy. I like it.

(Tony at 00:09:22) Yeah. It really is. It's a large component of active defense. We're not talking about hacking back, so I don't advocate for that at all. We're talking about owning your own enterprise and ensuring that the information that the adversary looks at may or may not be real, but putting hurdles in front of them and then ensuring every time they bump up against a hurdle, you're getting notified.

(Joel Beasley at 00:09:41) Yeah. I remember back—and I'm not a security expert by any stretch of the imagination, but I am a B2B software engineer for seventeen years—and I remember the first couple of times we started, you know, spoofing some of our—I guess that'd be the word to use. We would tell it we were a different server than we were, so they wouldn't really know our build and we would send back different information. And because the first thing you would do—these bots, we were watching what was happening and what started to emerge over a decade ago is people started building these bots that would take known security risk and they would go ping servers, figure out what versions they were running, and then they would execute at scale these mass attacks on these systems. And so when I was seeing that happen, I was like, well, you know, from my software engineer's perspective, I spoof my browser all the time to get it to be mobile or whatever I need it to be. And let's just change the output that it's sending back to them, so it tells them it's a different server or a different build.

(Tony at 00:10:45) That's it. Home field advantage. I mean, you are owning your enterprise. And there's a lot of defenders today that are really back on their heels that aren't doing that. My interest in this started way back in '98 or '99. I think I was at DefCon and there was a really good briefing on honeypots. And somebody introduced me to Lance Spitzner, and I don't know if you know Lance or heard the name before, but he owns SANS Security Awareness now. But he had his own company and sold it to SANS. But he got out of the military and didn't know him in the military. He was a tank commander, but his degree was in IT. And he decided he was moving into cybersecurity. It was an interesting field, and this is, you know, from his own mouth. But he wrote a series called Know Your Enemy, and he did it around building honeypots and putting them out on the internet to discover what some of these adversaries are doing. Keep in mind, lot different environment at that time. I mean, that was late nineties. But I met Lance and I got very interested in honeypots, deception. And that's when I started playing and brought honeypots into the Pentagon in the late nineties and early 2000. So for me, it was a very fascinating space. And although I didn't end up staying in it, I continued to watch that space. And after almost twenty years since I retired now, getting very close, I decided three years ago to jump back into the space after talking to Attivo and seeing what they were doing.

(Joel Beasley at 00:12:07) Yeah. How did you come to meet the team there?

(Tony at 00:12:10) It's really interesting. Alberto Yepez, who is on the board for us, great guy, ForgePoint Capital, has been in the investment space for a very long period of time. I've met him a few times. I think I met him when I was at FireEye was the first time. Great guy. And I started thinking about where I wanted to go and what I wanted to do differently. Quite frankly, five years at FireEye. Loved it. Had a blast. Great respect for everybody there. In fact, Marshall Hausman from FireEye from Mandiant, he's on my advisory board here at Attivo. So good relationships with him. But five years of doing over 300,000 miles almost every single year, and I was done. So didn't have another role that I could move into that was interesting to me, so I decided I was gonna leave. And anyway, I was having a conversation with Alberto and just kind of looking around a little bit. And he sent me to meet the CEO at Attivo and a discussion with Attivo. And next I know, I've signed an agreement and come over. And also, a former VP at FireEye had also joined Attivo, and he made a recommendation to me as well. So Rick Afton, a guy I really respect, who runs our Middle East team. And, you know, it was an easy step for me after talking to some customers already running a much earlier version of the technology that already really liked it, thought it was doing great things for them. It even showed more promise down the line. So easy stuff.

(Joel Beasley at 00:13:36) Now does FireEye—do they have the same—are they the same similar product or different like, how do you play together? Or are you direct competitors? Or you're just in the same industry?

(Tony at 00:13:47) We're in the same industry. We're definitely not competitors. In fact, FireEye is a partner. You'll find us on their page, and they're on our page as well. So we've got interconnections and ways to trigger alerts at about 32 companies now with different product sets that they have. So we've got partnerships with FireEye, Palo Alto, CrowdStrike, Cisco, Oracle, Citrix, VMware, pretty much pick it, and we've got a structure in place to help a security defense team integrate our toolset into their existing processes. So we're not breaking processes. Instead, we're adding more capabilities to shrink the dwell time very quickly.

(Joel Beasley at 00:14:28) I like that. I've never heard dwell time. But is that the time that they're just hanging out doing nothing, like, just waiting? Is that what you're talking about?

(Tony at 00:14:36) So dwell time is a really interesting and really scary statistic. It's the time from when a breach happens and before they're discovered inside the environment. So that is the dwell time. And, unfortunately, when you think about it, there's three different structures for it. There's dwell time. So an adversary has broken in. You're not aware of it. So that can be a very long period of time. In fact, for some countries until very recently was well over a year and a half. And even today, if you look at different datasets from different organizations, they'll say four months or eight months. So it kind of varies. But the next piece is breakout time, which can sit inside the dwell time. And that's the time from when an initial system is compromised until the adversary has figured out a way to move laterally. And that's where we're really good at catching them is that breakout time, which shrinks the dwell time because they want to move laterally and create additional beachheads in the environment. And the other piece that's really important to that is containment time.

(Tony at 00:15:35) So your dwell time could be, say, 35 days on a system. An adversary can do a lot of damage. What's really unfortunate is we often see, you know, a security team now that's aware of it, they go in and they decide they're going to clean this up, of course, because they didn't want an attacker running around inside your enterprise. And it might take them another month, sometimes two months, sometimes a couple years to do a complete cleanup of a large enterprise. So there are a lot of statistics in there that are quite scary.

(Joel Beasley at 00:16:03) Why isn't it like the movies where we can see their IP and we can just send a cop to their house and be done with it? Why isn't it like that?

(Tony at 00:16:16) Well, like you mentioned earlier, you know how to hide your browser. Others go much, much deeper than that, and they'll use many intermediary hopping points from around the globe. They're going to go through countries that are non-cooperative with the United States, you know, and quite frankly, with a lot of our allies as well. So it's going to be very difficult to track them and trace them when we don't have the cyber norms, the standards and structure in place to go in and do an arrest for these folks. And then at the same time, we've got an industry that has spent—I think last year IDG said it was like $124 billion spent across the globe on cybersecurity tools.

(Tony at 00:16:58) And if you look at those, the vast majority of those are preventative-focused. Well, you can't stop a determined and well-resourced attacker. So whether they're nation-state or, you know, nation-state tools have bled over to the underground, or a nation-state is contracting out pieces, or they've given them tools because that financially-motivated actor is feeding the pockets of a nation-state—you know, there's so many intricate pieces to this—but you're not going to keep them out. It's just simply not possible.

(Tony at 00:17:28) So you've got to detect them once they're inside the wire. So everybody's got that hard preventative core, and not enough—some do have it, not enough though still have instrumentation inside to detect them quickly and mitigate the impact by shrinking that dwell time.

(Joel Beasley at 00:17:43) That's interesting. That's fascinating. It's like this crazy city, and everyone's like, "All right, I'm just going to focus on preventing the chaos that comes into my building or detecting it when it comes in," because you can't police the whole city. It seems to be because there's countries that don't cooperate, so you can't go all the way back to the root.

(Tony at 00:18:03) Yeah, that's it exactly. That is a really good analogy, and we're going to continue to have this problem for the foreseeable future. I mean, it's a long way away from correcting this problem set. It takes me back—I was in front of the New York State Senate a number of years ago, and two professors who will go unnamed were up there, and they had done the first joint hearing of all the different committees they had for the New York State Senate.

(Tony at 00:18:30) And I testified right after these two professors. They both stated, "Oh, well, we're working on secure coding, and this problem is going to be resolved in a very short period of time." And I was just sitting there twitching in my seat, you know, waiting to get up there and talk about this. It's like, yeah, that will only work if the entire world teaches secure coding, you know, and we build a structure to ensure that it's mandated and we're looking at these code repositories. So inside every application that comes out—consumer side, the enterprise side, you know, in OT systems, in critical infrastructure.

(Tony at 00:19:08) So we're a long way away from that. And even then, even if we use the best practices for secure coding, you know from your background, we're always going to have zero-days. If humans are coding it, there's always going to be some problem in the code that we're unaware of that someone will find sooner or later.

(Joel Beasley at 00:19:26) That's why the bug bounties are such a big industry.

(Tony at 00:19:30) Yeah, absolutely. But that was my point. I was just sitting there thinking, why are you telling these state senators that you've solved the problem? You've not solved the problem, you know, unless everybody got on board. And then it's still not going to work because there are going to be nation-states that aren't going to want this to happen because they're driving their economy by stealing intellectual property, and you've got others that have taken their very expensive espionage structure and they moved it online because it's significantly cheaper and there's less risk to their people doing it.

(Tony at 00:20:04) So why wouldn't they do that? And why would they fix something that they're utilizing today for a benefit for their nation?

(Joel Beasley at 00:20:12) I had spoken to somebody a few years back who was describing to me—I don't know if it's the same thing as the secure coding—but the premise of the conversation was that, you know, as an architect, there's a certain way to do things, right? As an architect, there's these specific standards, and they were going to be doing this type of thing for programming. And sort of enforcing these types of standards within coding. And then you would go get certified as a programmer.

(Joel Beasley at 00:20:40) You'd have this certification and you would code in this very specific way, and there would be these checks and balances. And I championed them. I was like, "You know, let me know how that turns out." But in the back of my mind as a software developer, I was like, I don't know, man. That sounds pretty difficult because you have to get everyone to agree to play the same game, and the bad people don't want to play the same game.

(Tony at 00:21:04) Yeah, I agree with you 100%, and it's a challenge. I think in critical infrastructure—I've helped contribute to a series of articles that Dr. Ron Ross from NIST has been rolling out. You know, they built the Cybersecurity Framework. He's been the father of a lot of really important information that has helped build frameworks that most large enterprises are running today. And he's a big advocate for secure systems engineering.

(Tony at 00:21:31) And I think in critical infrastructure it can work. Consumer side is going to be problematic for a very long period of time because, as we all know, it's first to market. You've got a new idea, you get a new concept, you've got to get that app created, you've got to get it out the door—you know, or that little piece of hardware—and you've got to do it quick if you're going to win in the space and get your market penetration quick, or somebody else is going to beat you to the punch. So I think that is going to continue to be a problematic force because many of these same systems tie right back to an infrastructure out there, and that can be an avenue then.

(Joel Beasley at 00:22:04) I'm curious, because we're talking so much about data and security and privacy. So there was something new that came up to me. And zero trust as a concept isn't entirely new, but I was talking with Ori, who is the CEO of Upsolver. And they had built something where you could use their tools, but it was a zero trust concept, and you could deploy their systems, but they don't have access to your data. It's like you take their code over and it runs inside of your environment, and there's no connection back.

(Joel Beasley at 00:22:37) Do you think—and I hadn't seen tools like that before. I think they worked in—it was related to data lake providers. So if you had this data lake, you needed to run operations on it, but rather than plugging your data into third-party providers and everyone's seeing it, you can bring these tools over into your environment and they have no connection back. And I hadn't seen anything really like that before. Do you think more tools will be like that, where we have our data and then we bring tools in versus us currently right now?

(Joel Beasley at 00:23:07) Like, I'm always authenticating and giving them complete access to all of my data. How do you think that's going to roll out, like, the zero trust?

(Tony at 00:23:16) Yeah, you know, it's an interesting concept, you know, and I like to remind people that we're in our infancy. You know, we really are. So IT, cybersecurity, it's in its infancy. When you look at where we are in the transportation industry, where we are in the aerospace segment of that, you know, and even space—you know, started way back in the fifties and sixties, right? And that's in its infancy still. So we have a tremendous amount of distance to go. I do think there's merit to that. And quite frankly, I don't have enough data on it because I've not looked at their technology.

(Tony at 00:23:52) But I think a lot of people would love to see where something is delivered and then they own it, and there's no connectivity back. However, I think we're going to see more and more moving to the cloud, you know, where that infrastructure is going to continue to be updated and changed, where there's going to be lots of new code that impacts an enterprise for a very long period of time right now. So, because I see more and more trend where everybody's leaving the on-premises piece and going to the cloud. I think it's important to have both because once you move stuff to the cloud, you know, then you have your shared responsibility for cybersecurity with the provider versus you owning it inside your own enterprise.

(Joel Beasley at 00:24:34) Yeah, that's why I like having these types of conversations, because I can sort of think out things that aren't well-formed thoughts. We can edit out whatever we need to. But if I get really smart people, then I can kind of figure out how to ask these questions better. Specifically, preparing for an interview with Tim Berners-Lee, who's often recognized as one of the creators of the Internet.

(Joel Beasley at 00:24:57) He's got a new project going on, which is this concept of "you have your data, and tools will come in." And I guess, you know, when I go around and have all these conversations with people, these patterns subjectively to me start to emerge. And one of these patterns that was coming about is it's my data, and I will let you in. And that is step one, but I would prefer to let you in and you have no understanding of my data, because right now we can let you in, but they usually have copies of the data.

(Joel Beasley at 00:25:31) First thing they do is suck everything down and then run their operations. I want to let you in, but you don't have access to my data, but I can still use your service. I think that is the ultimate future of security and privacy.

(Tony at 00:25:47) It's going to be really interesting. And I think that, based on just some of the recent major breaches of SolarWinds, Hafnium, you know, Exchange attacks, we're going to see some shifts, but there's kind of a balance there as well. I mean, when you think about it, the Hafnium attacks, you know, the big Exchange problem that we just had—if you had on-premise Exchange, you were vulnerable. If you had Office 365 in no hybrid environment, it was just in the cloud, you were okay. SolarWinds, on the other side of that, you know, when you look at that breach, it was their source code in those customer environments that gave the adversary access via a backdoor in that code.

(Tony at 00:26:27) So it's really, really interesting, and I think what you state there has merit, but I don't think we have the right structure today and the right offerings today to say, "Here's a capability for you. Here's the container that it stays in, and your data is inside that, and nobody else has access to it," because you're going to continue still to get updates on that technology that you're going to need for new capabilities that others have. And, you know, when you do that, there's got to be some connectivity back to pull that code down. I mean, it's been a long time since my Department of Defense days, you know, where we would sneakernet, you know, antivirus updates from unclassified system over to a high-side system. So, you know, but that's really almost really what you would need to do updates as you were just talking about, taking that code off one system to another and ensuring there's no connectivity.

(Tony at 00:27:18) And even then, when you do that, you don't know if there's something new in it. Supply chain is going to be a big area, I think, to bite us in the behind for a while.

(Joel Beasley at 00:27:27) Yeah, it's a crazy world out there. I want to talk about a couple things. We're about halfway through, but I want to talk about leadership in crisis. But I also want to give a shout-out to your company and, like, what your customers look like and why people reach out to you.

(Tony at 00:27:44) Yeah, it's a really interesting environment, and it's one of the reasons, you know, when I retired from the military, I went to a small honeypot company, Recourse Technologies, and we were acquired by Symantec. And technology didn't last. They did away with it there. This is way back in 2002. I stayed there, and I ran their global government consulting business and built that up. And then, after a number of years, went to McAfee, did that, and then got recruited over to FireEye and became their global government and critical infrastructure CTO. And it was very interesting. Most of those pieces across all those companies was all focused on preventative and cleanup, you know?

(Tony at 00:28:21) So try to prevent the adversary from getting in. The adversary gets in, and now you're going to send out incident response teams. You're going to help clean up that environment. So when I decided I wanted to leave FireEye, I was looking for something different. You know, what can we do to put technology in place to automatically identify that adversary inside the enterprise and help shrink and mitigate the impact?

(Tony at 00:28:44) So I liken it to having a burglar alarm on your house that's set middle of the night. Burglar comes in and breaks a window, and you've got a glass break sensor, you know, or a sensor on the window if they pry it open, and it goes off. Burglar runs away, you know? You've got to fix that broken window and get a new sensor, but everything did its job.

(Tony at 00:29:03) So the impact was mitigated. So that's exactly what Attivo does. You know, the adversary may break something and get in, but we quickly set off alerts and provide that information back to the defense team. They very quickly understand they're high-fidelity alerts because our environment shouldn't be touched.

(Tony at 00:29:24) And it helps tremendously shrink the dwell time for that adversary. So they may never get to their target. They may never be able to really do what they wanted to do inside there. The customer base is very interesting because many CISOs out there will tell you, "This is only for a mature organization." Absolutely not true.

(Tony at 00:29:43) We've got a great blog from a single-person security team at a very small company who put it in place and uses it for those detection alerts because she knows it's high fidelity. We've also got 50% of the Fortune 10. So it's pretty wide across the board. We've got a lot of utilities, energy. Retail was a really big one for us because we did decoys early on.

(Tony at 00:30:04) So for point-of-sale terminals. So an adversary that's broken into the system remotely, and they're looking at these different systems and they're installing code on a point of sale—and they would install code on a decoy point-of-sale terminal, which immediately set off alarms, which is great fun. So it's really across the board: government, large corporations, mid-tier.

(Joel Beasley at 00:30:28) How do people get—can they just go on the Attivo site and download or start interacting with the code? Or how do you get introduced to this?

(Tony at 00:30:38) So through partners, from the website, from speaking engagements, hopefully people will see this podcast and go take a look at it. It'll be interesting to them. And we've set up some recent things with relatively newer technology. We're continuing to expand our capabilities. Where the adversary goes, we go as well.

(Tony at 00:30:58) But one of the things that we've done recently that they can get direct access to is our AD Secure technology, which is great fun. So without it impacting the domain controllers, because most CIOs are concerned about that, you know, we sit on the endpoint. And when the adversary goes in, let's just say your boss sent you an email. Looks real, it looks valid.

(Tony at 00:31:19) Spoofed email address. So you open that Excel spreadsheet. You know, "Joel, look at this. I need your input back right away on this." And maybe your boss is like that, right, in the past, so you do it.

(Tony at 00:31:29) And it's a weaponized attachment, and now that system is compromised. Adversary pops up on that system. First thing they do is, "Alright, where am I? What credentials do I have?"

(Tony at 00:31:38) Let's put a few tools down here. Let's scrape memory. And let's do a couple queries to Active Directory. As soon as they do that, they're going to hit our decoy credentials inside memory on that system. We're going to set off alerts as soon as they try to use those. When they do the query to Active Directory using Bloodhound or, you know, whatever they use, we're also going to set off an alert.

(Tony at 00:31:59) So to the cybersecurity team. And, you know, on the other side of that, what's really great fun is, without impacting the domain controllers, we'll provide deceptive results from Active Directory to the adversary on that system. It's going to send them into a decoy environment, and we're going to alert on that as well. That's technology. Somebody can go to the web page right now and just say, "Hey, I want to sign up. I want to do a 90-day trial of that. Let me pull it down and check it out."

(Joel Beasley at 00:32:23) That's pretty cool.

(Tony at 00:32:24) Yeah. And we're doing the same thing for AD Assessor, and that one's really cool as well. And people really like this one because it runs on a single endpoint, you know, just a single endpoint, and it goes in and continuously will query Active Directory and look for misconfigurations and challenges you have in there, and then provide results back on how to clean up Active Directory, you know, before an adversary takes advantage of it. Because that's a huge problem we see: orphan credentials, misconfigurations. I think a recent study showed 90% of successful attacks involve Active Directory.

(Tony at 00:33:00) So it's a reason we really started to focus in that area and really help our customers provide additional capabilities to quickly identify adversaries inside the wire.

(Joel Beasley at 00:33:09) That's pretty neat. I love the fact that you made it so you got the suite of tools people can just go experience. That's how you win: getting it into the hands of people.

(Tony at 00:33:20) Yeah, absolutely. Well, there's too many companies today, in my opinion, that, you know, are out there, and they're important — don't get me wrong — but they're trying to continuously sell services around, you know, always looking inside. "Let me put a bunch of PhDs on continuously searching inside your environment."

(Tony at 00:33:40) But you can put some tools in there that can do the same thing for you and provide that data back to your security team and integrate it, you know, with the architecture and processes that you have. So integrate into, you know, your SOAR structure, the orchestration, you know, the flow, your SIEM, you know, devices that provide alerts. So why are you hunting in there continuously when, potentially, instead you can take this and automate it and then provide real high-fidelity alerts for that same hunt team? And now they can really start to understand your environment much better because they're not chasing the last thing, and they're getting alerted on it right away. And they're starting to look at these vulnerabilities ahead of time and fixing these problems before an adversary gets in.

(Tony at 00:34:21) So they make it in, but they're not going to get anywhere, and they're not going to steal what they wanted to steal.

(Joel Beasley at 00:34:26) Earlier, you mentioned something along the lines of like a point-of-sale type system. For me, in my head, I saw like the small credit card type reader, and I started to think about sort of like IoT type devices, right? So do you ever do custom engagements with a company that might have some unique type of device? Like maybe I'm a company and I've got vending machines. Or have you ever done anything interesting like that?

(Tony at 00:34:52) Yeah, we've done some really cool stuff in that space. We've got solutions on the decoy side for IoT. But, you know, it's really interesting. About a year and a half ago, we did an agreement — and it's public — with the U.S. Department of Energy.

(Tony at 00:35:06) And through them, they had us put a contract in place with Pacific Northwest National Labs, one of their national labs. And they liked what we had done with deception on the deception side, and they asked us if we would work with them to move deception down the stack into the cyber-physical systems. So could we take some of these historians and such, you know, where typically you don't have metadata, so you don't know what's going on in those systems — can you move deception down there so if anyone touches those, you know immediately?

(Tony at 00:35:35) So we've done that and have made that technology available to further protect, you know, our utility customers and others that are using cyber-physical systems, which is a lot of critical infrastructure today. So we do that. We do IoT. We've done VoIP phone systems, a server on the back end. And one of the coolest ones we ever did in working with a company was we created a deceptive medical infusion pump for a healthcare provider.

(Tony at 00:36:02) And caught some really interesting new technology that had just come into their healthcare system that was infected. X-ray machines that, you know, everything else on the preventative perimeter we talked about missed, and this thing started scanning internally. So ransomware. And we picked it right away, you know, and then killed it with a deceptive medical infusion pump. So it's really fun. Again, as you stated early on in the conversation: take the home field advantage. You know, it's your network. Build it to defend it.

(Joel Beasley at 00:36:32) Yeah. And these systems are only limited by the creativity of the engineers. So I heard once that if you have really good software people, which is where my background's better at than networking, right, and you have, like, really good networking person — together, they can do a whole lot. Right? Because I can think like a software engineer. I could say, "Okay, I'm writing this system. Here's the things I would probably think of at first," depending on the quality of developer.

(Joel Beasley at 00:36:46) I know a greener, a newer developer is not going to probably check for these things, all the way up to expert. So I can sort of prioritize the areas I'm going to start exploring and checking. But all of that is fascinating because they can build these systems. And, like, you can get this — and tell me if I'm wrong too, right? Because I want to know.

(Joel Beasley at 00:37:17) I'm kind of like checking here. Let's say that X-ray machine. Like, is it possible that that X-ray machine — it could have been like an autonomous, like a program running that was just seeking through things and ultimately got the malware onto that machine without someone intentionally saying, "I'm going to put malware on this machine"?

(Tony at 00:37:36) Yeah. In this case, we don't know if it was — you know, I don't know if the healthcare provider even knows if it was done through just a sloppy manufacturing process where there was an issue and somebody had loaded it with, you know, code that had been infected. Maybe they had a system that somebody was accessing the Internet that was compromised where the build code was. Don't know. But, nevertheless, you know, when it appeared there and was booted up and turned on, it starts scanning and, you know, looking for systems to infect. So, but we don't know if it was on purpose or somebody compromised them and did it on purpose, or if it was, you know, just a negligent, you know, manufacturing process.

(Tony at 00:38:14) We don't know. But back to your point about the coding, you know, to me, that's really fascinating: tying the software-focused engineers, you know, and coders with, you know, the networking experts. Now I tell you, the team that they had already assembled before I joined here? Rock stars. When I think of them, I see them as a big rock band on a stage, you know, and people throw them stuff at them — good stuff, right — because they're just absolute rock stars. Can ask them to build something. "Yeah, that's a great idea. We could do that in three weeks." You know? Just amazing what they turn out.

(Joel Beasley at 00:38:47) Yeah, it's a lot of fun too. All right, I want to talk about leadership in crisis. Because over the years, I've gotten calls from people, you know, "Your server's down," or this or that or the other. But you're in this at a much larger scale, right? You have entire organizations that can become compromised. They can call up. We're humans, right?

(Joel Beasley at 00:39:11) So we'll get emotional. I've gotten crying phone calls before from people. And, uh, and so I want to know, like, as a leader, how do you handle these high-stress crisis environments?

(Tony at 00:39:26) You know, for me, you know, I grew up in the trenches in the military, and I think that helped me tremendously. You know, and just to shout out very quickly, there's a lot of great organizations out there today providing some really cool programs to turn veterans into cyber warriors. And I highly recommend, if anybody's listening to this podcast and if you haven't looked at hiring veterans that are still in training, you should. Because the topic you bring up — most of them, you know, have been baptized through fire.

(Tony at 00:39:57) Myself as well, and some much more than me. But I think it makes you cooler and calmer in any situation. You know, as my wife likes to joke, you know, it's like, "Hey, I'm going to this country. I'm going to South America." You know? And she's just happy because I'm going somewhere where no one's shooting at me. So, you know, so the point is that, you know, you're a much calmer individual. I would say the biggest crisis I probably faced was, you know, when the Pentagon, you know, was hit 9/11.

(Tony at 00:40:42) And I was running network security at that time in the D.I.A. And, you know, that, you know, had a lasting impact on me and made me, you know, try to really buckle down and see very quickly how we can get systems back up and running and what did we need to do to be operational in a very fast period of time.

(Tony at 00:40:42) I mean, it's the Pentagon. People think of it as, you know, the headquarters of the military. But in reality, you know, it's an office building where a lot of contractors work. You know, a lot of people just think of it as a job, and they do a great job. But nevertheless, it's an office building. And that changes when the building is attacked and you suddenly find out, "All right, this country is going to war more than likely, and we're the headquarters for that activity. How do we, you know, get everything up and operational again?"

(Tony at 00:41:32) So it's a really interesting experience, and even more interesting for me over the years as I look back and discuss with other friends that were in other organizations inside, you know, the Pentagon as well. Rick Howard, who was at the CyberWire — an old friend of mine — so he was a colonel at the Army Operations Center with another colonel over there, Bruce Backus. Great guys. And, you know, they talked about how they kept, you know, the Army Operations Center from flooding and, you know, they're courageous soldiers. But you have so many experiences that, you know, help you understand what you should and shouldn't be doing, you know, that can really make you think differently. I'll give you an example from 9/11.

(Tony at 00:42:01) As soon as the buildings hit and the alerts go off and we found out what happened — and Twin Towers had already been hit — so we knew, you know, more than likely what it was right away. So the building's being evacuated. And I was going out into the North Parking. As you go to North Parking on the right-hand side, it's the DiLorenzo Clinic. And, you know, keep in mind, I'm close to retirement. Most of these people are very young.

(Tony at 00:42:15) You know, they're young adults. And here is — they're evacuating us. I'm military. I'm not a contractor or a civil servant, so I'm used to, you know, some dicey environments is my point, and most military folks are that are, you know, further on in their career. Here's all these young men and women out of the clinic at DiLorenzo, probably many of their first assignment.

(Tony at 00:42:33) And what are they doing? They're trotting information into the burning Pentagon, you know, while we're being evacuated. And that, just to me, that, you know, just shows you the leadership level of so many different people in the military here. You know, these people not thinking about their lives at all. You know, "We've got to go in, and we've got to help people."

(Tony at 00:42:51) And that's just one example, you know, of some of the things that you see that can really help you start to understand some of the challenges you have. And if it sounds like I'm not giving you specific examples, there are still pieces of it that I can't talk about, of course, after 9/11 from some of the recovery systems that we had to do. But it was a fascinating experience and really helped shape my head in the time of crisis, you know, what to do and what not to do.

(Joel Beasley at 00:43:16) Those pieces are the best parts.

(Tony at 00:43:20) I will tell you, it was — just for me alone, my wife and the kids didn't know if I was alive or dead, you know, for about six hours. So about six hours, you know. The anniversary, the 20-year anniversary is coming up here shortly. And that was hard enough on the family. What was harder yet, if you remember, the Pentagon roof burned for a number of days.

(Tony at 00:43:41) So, you know, it did not go out. Tar roof, so burned for a number of days. So here it is at about 3:45 a.m. after 9/11, and I'm in uniform going back into the Pentagon. So they had released us to come in and start rebuilding the systems. And that, of course, really freaked out my family that I was going right back into the burning building at that point in time, you know, that quick after the attack, you know, over about 18 hours. You know, nobody really still knew all of those details yet and wouldn't for quite some period of time.

(Tony at 00:44:11) But going back into a burning building to bring the networks back up, right? So at least the cybersecurity components of it. There were a lot more people involved. It was amazing how many, you know, really brave, wonderful people there were. They worked on so many things in there to try and get things operational again from every aspect in every branch of service.

(Joel Beasley at 00:44:31) Yes. Makes me proud — proud of our ability as humans to rebuild and to gather together and to overcome obstacles. Right?

(Tony at 00:44:41) Yeah. In times of crisis, you know, that's when people typically really stand tall, step up, and do what's needed of them, you know, to do the right thing.

(Joel Beasley at 00:44:49) Yeah. I mean, when I interview people — I often ask them, for when I interview people for jobs, I often ask them, like, what's the most difficult thing that they've experienced in life. And the reason why is because people who've been through very difficult things just tend to manage life better. Like, it's like hardening steel, right?

(Joel Beasley at 00:45:12) It's like, if you have some beautiful, polished, shiny steel object that looks beautiful, everybody wants that beautiful object. But if you saw that raw steel that got heated up, you know, bent, banged on, cooled off, and then polished — like, it was quite the process to get that beautiful object to that point. Everybody wants the shininess. Nobody wants the work.

(Tony at 00:45:35) Yeah, I agree with you. You know, you got to put in the work, right, to get there. But you're right. Sometimes, you know, things do shape us differently. I'm a guy that, when my dad died, I was a teenager and, you know, the youngest of all the kids, and everybody else has grown in and out of the house. And, you know, and I spiraled out. So that's when I dropped out of college and joined the military because I had a — my mom's boyfriend, who was a, you know, retired military. Air Force side — I'll forgive him for that, not Army.

(Tony at 00:45:42) But, you know, he was a great guy, and he recommended, just knowing me, you know, that move me down the path into cybersecurity. But the military helped me get my mind straight, you know, and start to have a, you know, quite frankly, you know, a very fulfilling life, which, you know, I could have easily gone the other way.

(Tony at 00:46:21) So after the things that had happened, but anyway, the point is that I really won't—he's long gone—but I always appreciated the fact that he was the one that said, "Military police, are you kidding me? You've taken apart every single thing anybody's ever given you and put it back together again if it plugs in." So he convinced me to pick the longest school in electronics that I could, and I did: cryptography. And that's how I got into this field.

(Tony at 00:46:46) Oh, I love it. Thanks to that Air Force guy. He was a great guy.

(Joel Beasley at 00:46:50) Yeah, my father's Air Force. Oh, very cool. Yeah, he had a different story.

(Joel Beasley at 00:46:56) He left like '18, came Air Force. He went there, then he learned that he could get education there. So he started electronics design courses in the Air Force. And then, I'd say about every ten years or so, he's got some new piece of something cool he can share that he worked on because things become declassified as time goes on.

(Joel Beasley at 00:47:17) And the coolest one that he shared so far—he shared some laser ones that were pretty cool—but my favorite one is they put the first GPS systems into the B-2 stealth bombers.

(Tony at 00:47:28) Oh, so—

(Joel Beasley at 00:47:29) That was like a project he was on, was integrating these GPS technologies into the stealth bombers.

(Tony at 00:47:36) Yeah, it's really cool, the things that you find out from people that are influential. Obviously, your father, very influential, I'm sure, in your life. I was with a boss of mine. It was just me and him. Our military unit was in Virginia at Fort Belvoir, but him and I were stationed in Kaneohe, Hawaii. And we would work on designs and then go build networks for this agency across Asia and other parts of the world. But anyway, really funny story. We're sitting once—me and my wife and him and his girlfriend—were sitting at a restaurant, just a sports bar, and there's a discussion on the TV about the Hubble Telescope.

(Tony at 00:48:15) And he is the most laid back, great guy—jacked out—and Jack, if you're listening, huge kudos to you. He's a great boss. And this was so funny. He shushes me. He's never shushed me ever. He's like, "Shh, shh, shh." I'm like, "What is it?" And his girlfriend leans over. He's like, "It's Hubble. He worked on the engines for that." I was like, I had no clue. Never even knew he worked at NASA. So, but it was the funniest thing. And of course, then after that, many conversations about the Hubble and NASA. And then years later, I end up working on the advisory council at NASA. Just a small world.

(Joel Beasley at 00:48:48) Have you gotten to go see some rockets in person launch?

(Tony at 00:48:51) Oh yeah. Yeah, I have some very cool photos, some that I'm not allowed to share. SpaceX, we've had tours of all the facilities. So really, really funny. The last time we were at SpaceX with—trying to remember Bob's last name. He runs Kennedy Space Center—but we're going through one and, like, this is the only time I'm ever gonna get to say this. It's like, "Bob, don't hit your head on the rocket." We're talking underneath one of the Falcon 9s inside their facility. Yeah, I've got some very cool pictures, and I have been very lucky and blessed to go in and see many of these systems and, you know, the service providers to NASA. So Blue Origin has a phenomenal facility. SpaceX has a phenomenal facility. Northrop Grumman has a really cool one. Boeing has a really cool one.

(Tony at 00:49:37) So I've, yeah, really enjoyed that time. Lot of fun. Just continuously geeking out in there and picking other people's brains that are sending men and women to Mars.

(Joel Beasley at 00:49:49) It's so neat. I took the kids to go see their first launch, and it got scrubbed four days in a row. So the day we left, it launched. But we did get to go to NASA—I think it's Kennedy Space Center—and tour around. And the interesting thing was, we were sitting there at the light about to turn in and I looked to the right and I see this giant building and Blue Origin built like a large facility across the street from the entrance. I don't—I didn't see the SpaceX facility, although we were there for a SpaceX launch. But do you know, do they have like a large facility down there in Florida?

(Tony at 00:50:26) Yeah, they do. Yeah, they actually have their own launch pad as well that they leased from NASA and then paid to renovate it themselves for their requirements. I've stood within those clamps on the SpaceX—you know, 39A, the Launch Pad 39A. But SpaceX is on Kennedy Space Center, and where you were is actually a commercial center. And Blue Origin—you know, Amazon, it's a subsidiary—decided to build there. Then there's other companies, there's other space companies. In fact, Blue Origin's also building another huge facility just a couple miles from there because they're going to be turning out rockets in a very quick fashion.

(Joel Beasley at 00:51:04) Yeah, it's so cool out there because there's just thousands of acres and it's all like government space land. And I was—I'm an early person, so I get up like 5 a.m. and I go for runs or workout or whatever. And when we were—we were camping out there for a couple days—I was like, oh, I'm just gonna go drive around, see the sunrise, go explore. And you're on these long stretches of road where there's kind of like nothingness.

(Tony at 00:51:29) Yeah, nothing to turn.

(Joel Beasley at 00:51:31) No. Oh, and then I get like these lights pull up and apparently I'd gone into some area where I shouldn't have been. And the guy pulled up, you know, behind me, knocked on my window. And he's like, "Oh, you know, I need—I wanna see your ID and license and why are you here on this." And he was, like, full up, like, not just cop. He was AR-15 across the chest type fatigues. And I was like, "We're all explorers, aren't we? Like, I didn't mean to be here. I was just kind of driving around with my family, you know." And he's like, "All right, cool. Follow me." And then he had me follow him out. And I saw where, like, apparently I accidentally went through the area I shouldn't. And then he gave my license back and he was super nice. He was super, super nice about everything.

(Joel Beasley at 00:52:17) But it's so cool out there because it's just a bunch of nothingness and then some launch pads and a beach.

(Tony at 00:52:26) Yeah. Well, I'm glad you got to go through Kennedy Space Center, the visitor center, because that is one of the coolest ones I've seen anywhere. Houston's is great, and Cape Canaveral's is great. I mean, just the—I've not been through since they've got the new shuttle ride inside there as well. So it's supposed to be pretty awesome, and I haven't been at that virtual reality one yet. So I plan on going back. Pandemic kind of slowed everything down for, heck, everybody with their plans, right?

(Joel Beasley at 00:52:52) Yeah. Yeah, everything kind of slowed down. I wanna—I have a note here because I didn't wanna forget about it because I'm a huge fan of this too. You said there's a group for veterans that will help them become cyber trainers. Can you describe that? Do we have the name of the groups we can put a link in the notes?

(Tony at 00:53:09) I would have to pull it up. I'm happy to—I'll send it over to you. But there's like seven of them now. And a number of different companies are also building their own programs. I helped push McAfee HR, who was very receptive when I was at McAfee, and they set up a veterans program. And there are many others as well. Because today, you know, it's even more viable because now there's career paths for cyber in every branch of service. So now you're getting people who have operational experience coming out of the military that people can hire. But I'll send you the links to a number of them that you can put in the show notes because there's some really great programs. SANS has one, and another friend of mine, Matt Devost, does a great program every year. I'm sure you're familiar with Black Hat DEF CON conference. And he's got a scholarship program set up, and he takes vets, and he gets scholarships for them. And it's really—it's free pass and free travel to Black Hat to attend the conference.

(Joel Beasley at 00:54:04) So somebody's listening, and they just got out of, you know, service or they're about to and they're looking for their next thing and how to transition in. They can search for these programs. But for you as a leader in your experience—and you've done this because, you know, you've made this transition from sector to sector—what's like one core piece of advice that you would give to these people making this transition?

(Tony at 00:54:31) You know, that's a really great question, Joel. And I will tell you that so many people that retire from the military typically only last seven months before they realize, like, "Wow, I picked the wrong role," you know, and they'll change jobs. So, and people that get out of the military—I've not seen as many statistics on that because people can get out at any point in time, you know, through their twenty, thirty, forty year career. But for those who retire, I would say find a mentor. For anybody getting out that wants to go into a field, find a mentor. And quite frankly, you can go on LinkedIn and find somebody that's doing something in that field, tag them in it, put it on LinkedIn, which is typically better than Facebook or Twitter because so much can get lost in Twitter, you know, with all the tweets that come out on a daily basis and so many people trying to follow thousands of different people. But LinkedIn is a great way to utilize that to use a hashtag even related to where you wanna go, what you wanna do, and ask for help. And you'll find that a lot of people are like, "Wow." Get out of the military and you wanna figure out, you know, what's a really good career recommendation for you. Find a mentor and somebody will help you out. And, you know, I'm in a lot of different groups on LinkedIn where I see that stuff posted all the time and make lots of recommendations and myself have helped mentor and had conversations with people retiring. And, you know, what should you do? Where should you go? "I don't wanna go in sales. That's a dirty, dirty world." It's like, not true. Not true. And then you explain really what happens. And a lot of people think that, but on the other side of that—

(Joel Beasley at 00:56:05) That's what I'm saying. Yeah. Like, at first, you think—that's how you can—that's like a maturity scale for me now. The dirtier you think sales is, the less you understand it and how everything is sales. And it's a helpful thing. It's a useful thing. We need each other and we need great salespeople.

(Tony at 00:56:22) Absolutely. I mean, we live in a capitalistic society. I mean, if we don't have sales, then, you know, there's no need to create, you know, anything because it's just gonna sit there and no one's ever gonna consume it. I tend to remind my friends in cybersecurity that aren't at cybersecurity vendors of that. You know, it's like, "Oh man, your inside salesperson called me and was, you know, pestering me and I laughed at him." It's like, "Really? Because your bank's tried to sell me like 10 credit cards in the last week." You know, and they never—many of them don't make that correlation. It's like, "So your companies, even though you're not selling, they're selling." So people forget that. Anyway, the point is that, you know, it can be a lot of fun. The sales side can be fun. I ran business development for a while at Symantec for federal. And there was a lot of fun. I learned a tremendous amount, and I needed to understand the business side more and didn't have that background on that. So as a military guy and a degree in computer network, I didn't understand that piece. So that helped me a lot. So that's a great way to do it. And reach out to your own existing network is my other point. You know, people you know that have already left that have gone into a similar field that can help connect you up with those who can mentor you and help take you down the right path.

(Joel Beasley at 00:57:37) How many people would I need to contact? I wanna give some context to volume here, right? Because people will hear some advice and they'll say, "Oh, they said, you know, go online." I asked three people. Two of them didn't respond. One of them told me no. Like, what's the scale here? Do you think they should reach out to 10, a hundred?

(Tony at 00:57:57) You know, that's a really good question. And I would say, you know, use some hashtags, and anybody that doesn't know what hashtags to use can type a sentence into Google and get great recommendations back, right? So put some hashtags around, you know, CTO. So hashtag CTO, hashtag CISO, hashtag, you know, veterans, you know, and hit some of those up and see if you can get at least two, you know, people that have been in the field for a while to talk to that are veterans. Sorry, there's no former in it. But, you know, maybe even three or four, even if you can just have, you know, a thirty, forty-five minute conversation, you know, because many of them that have been out in the commercial world for five years or more might be able to ask just a few simple questions to try and understand that personality better and what might make you very happy. Introvert, extrovert, you know, do you wanna be, you know, trying to help the company shape its vision, or do you wanna actually be in the trenches, you know, looking at logs or, you know, designing an architecture? So many different things to do in our field that, quite frankly, as you know very well, you dance across that line frequently from the coding side to the architecture side, to defending the enterprise side, and all of that feedback, you know, into what your company, of course, does because that's even the most critical piece. What's the business out there? So, yeah, I would say probably hit three to five people, maybe even as much as 10, and then pick a couple from their profiles and, you know, have those conversations and it's gonna help you make the right first step out of the military into something that, you know, you might hang out at for two, four, ten years.

(Joel Beasley at 00:59:34) People I have found, if you do it correctly, do the ask correctly and you're professional and you're kind, people are very helpful. They wanna see you succeed. They'll either be able to not help you and typically they don't respond, or they can help you and they will respond and have a meeting with you, or they know someone who could help you even though they might not be the exact right person. So I've just found that a little bit of volume, reaching out to a couple different people and just keep going until you get those conversations and not giving up. I mean, I think that's almost like the—tell me, what do you think? That's almost like the first skill you have to learn is persistence.

(Tony at 01:00:14) Yeah, absolutely. But I would tell you, I see too many friends of mine, you know, that get out of the military, and they just become a contractor right where they used to work because it's a comfort level. They go to one of the big system integrators, and they're right back inside that same installation where they used to work, which may be a comfort factor. But, you know, one thing I think that's critically important is if you're somebody who loves to learn, then you go out into the real commercial world and step away from where you used to be. You're gonna learn a lot, and you're gonna have a lot of fun and lead a very fulfilling life. Even if you do it for a few years and decide, "No, I prefer to go back and support, you know, much like I used to, the mission, but this time as a contractor or civil servant." So there's so many pieces you can do there, you know, and do things differently. Go to NIST, go to MITRE, you know, some of these organizations that are working to build frameworks and structure, you know, to make all of this better.

(Joel Beasley at 01:01:04) We're starting to wrap up here, but there's a couple more questions I want to get to. So we'll do them a little bit faster if that's okay, because I just want to make sure that we really bring this value. Alright, so I'm curious to know your experience. What are you learning right now as a leader?

(Tony at 01:01:20) It's a really good question, and I'm learning I can't consume information fast enough. You know, our world continues to—the innovation is accelerating on a continuous basis. So I'm voraciously reading all the time. You know, I used to want to plop down sometimes and get stuff recorded and watch some program, and more often than not now it's pick up another book, read these 10 white papers this weekend, and try to stay up to speed on everything. I think that if you're looking at stuff now and you want to be a leader, it's really important to not only understand the tech, but you also have to understand the business.

(Tony at 01:02:01) And a lot of people miss that part. So understand wherever you're working, whatever you're doing, one way you can help lead is by understanding the business and its associated risk. So if you want to be a chief information security officer down the line or a CTO, you have to understand what's the impact across every one of the business units if something you build or something you're defending goes down. So to me, that's a continuous process, and I will do this a lot. Our team will say, hey, can you go meet with this ministry of defense? Can you go meet with this global oil company? It's like, you know, so I need to buckle down and read a ton of information on them before I go out there so I can understand their challenges and the risks that they have. And are we building the right tools? Are we doing the right things to help them defend themselves?

(Tony at 01:02:48) So there's a lot of pieces to it.

(Joel Beasley at 01:02:50) This is like a dream job for you, isn't it?

(Tony at 01:02:52) It's a lot of fun. It is a lot of fun. And it's a phenomenal team. It's an absolutely phenomenal team here at Attivo. I'm so happy I joined this company.

(Joel Beasley at 01:03:00) I have in the notes to ask you about the Microsoft Exchange server hack. I know you mentioned it briefly earlier, but what's the most interesting point there? Like, what was that hack? How did it happen?

(Tony at 01:03:12) This one is absolutely fascinating. And I think much like SolarWinds, one, every once in a while I'll walk out of my home office here and tell my wife who used to be in IT as well—she's retired from government as a civil servant—but I'll say, you know, thump, another shoe dropped today on SolarWinds and the Exchange hack. So on the Exchange piece, it's really fascinating. Nation state driven. You know, they were compromising these Exchange servers through a number of zero days that they tied together, four different zero days that they hit. And they were compromising on-premise Exchange servers, not in the cloud, on-premise. Although you were impacted if you got a hybrid environment; there's a lot of those organizations. But what was really fascinating was a very small group of companies that it looks like they had targeted, that they had breached using these zero days and creating this backdoor into Exchange and gathering information.

(Tony at 01:04:08) What was fascinating and the most fascinating part of the story is right before the patch dropped, suddenly that same nation state hit everybody potentially that they could that had not patched. So to me, you know, and this is a little bit on the speculation side, any adversary would want to cover their tracks, and that's what it looks like. So that it would take the intelligence agencies and the incident response teams a long time to figure out if this company was a specific target by this nation state, because just overwhelm the system by using that same vulnerability and compromise everybody that was vulnerable. And almost everybody was vulnerable, and you do that and it jumps into the hundreds of thousands of companies, and now you've covered your tracks on who those specific targets were and what data you were looking to extract from those targets. So it's a fascinating hack, and quite frankly, much of this falls right into espionage 101, which just makes it really, really interesting.

(Tony at 01:05:06) I mean, cybersecurity is a fascinating field. And when you see something like this that comes this public as well as SolarWinds this public, you know, it makes it even more interesting to me as you look at what the adversaries were doing, what information they were going after, and how they're trying to cover their tracks.

(Joel Beasley at 01:05:23) Could this have been prevented?

(Tony at 01:05:26) Yeah. Absolutely. SolarWinds could have been prevented more than likely. But I think it's important to caveat that and say that, you know, since we specifically don't know where they got in on SolarWinds and we don't know—we don't have all the details on the Hafnium attack as well, the Exchange attack. It more than likely could have been prevented because if you're running an enterprise and you've got the right instrumentation in place, then you potentially could have caught that adversary even if they were an insider, you know, by detecting their lateral movement, by detecting them doing anomalous things that they should not be doing.

(Tony at 01:06:00) But the adversary will always get in. So if they're well-resourced enough and they've got the right expertise. So I think that's the important thing to think about, although it looks like we probably could have detected both of these if they'd had the instrumentation in place. Doesn't mean the adversary won't find another way in and still compromise them if it's a target that they're well-resourced to go in and break. They're going to break it sooner or later.

(Tony at 01:06:23) The point is, can you detect that attack very quickly and not allow them to have the impact that they did?

(Joel Beasley at 01:06:28) I love it. Alright, so I want to think about real quick with you. I want to brainstorm here about our audience. Right? So we've got a chunk of people that are, you know, first-time leaders and their companies are growing, and they might be like an executive position or a management or VP. So we got the smaller end of the market. We've got the middle part of the market, which is, you know, the growing companies, 100 plus employees. They're scaling. They figured out their product and the market, and they're just in growth mode. Right? And then we have the high end, the Fortune 500, the executives. So those are sort of how we look at our audience in these three different topics. And I'm always interested to leave them with value. So we can either chunk it up by each one if there's specific thoughts for each one, or we can kind of group it all together.

(Joel Beasley at 01:07:22) But, you know, what should they be thinking about right now in terms of security?

(Tony at 01:07:28) They need to realize, first of all, and this, unfortunately, is still true, that they are a target. You know, and there are a lot of your smaller organizations that think I'm not a target. And for them, it's very, very difficult. I mean, you might have, you know, Joe or Betty, and I'm just making up two names here, that are pretty good with computers. So they set up the server. Right? And that's the extent of your IT support team. You know? So it's really important to put together the right team that's got expertise in this area. And if you can't and you want to focus specifically on your own products that you're developing and what you're bringing to market, then take that to the other experts.

(Tony at 01:08:09) So take an MSP that focuses on small businesses, you know, and have them help you ensure they take off your plate as much as possible. Some of the challenge that you have around keeping things secure. For all three organizations, and, you know, on the top end, the vast majority of them know it. You know, take your engineering processes and don't connect them to the internet. Or if you do connect them to the internet, you've got to make sure that you've got all of the requisite instrumentation in place to protect it on the preventative side, because there are a lot of attacks you're going to be able to stop.

(Tony at 01:08:42) And then you've got the instrumentation internally to do the detection when the adversary does get in for those large enterprises that are a target and midsize ones as well. So it's really important to understand, you know, if you are a target and don't build just a preventative piece, you've got to build the instrumentation inside to look for those adversaries moving across the wire as well. And there's a tremendous amount of help out there. SANS Institute has some great structure. Center for Internet Security has some great structure, and many, many others that, you know, if you're a small company, here are the things you should do right off the bat. CISA, you know, DHS Cybersecurity Infrastructure Security Agency has great information on things you should be doing to set up your initial security as you're building a very small company.

(Tony at 01:09:27) I think those are really some of the most important points that people need to think about and understand if they're going to be successful, you know, in encountering this. Because if you're not looking internally, you know, you're definitely falling down and failing in the very near term.

(Joel Beasley at 01:09:41) And if we do have some developers, security experts, people that want to geek out, they can go to your website and down—I thought it was so cool that you can put, like, fake stuff in the memory and then that will trip a detection. For me, I was just like, that's next-level stuff. This guy must have, like, a background in government technology.

(Tony at 01:10:00) Yeah. It's really cool. And as I stated, we have a phenomenal engineering team that built some really cool stuff. And the fact that we're able to do this across pretty much any cloud environment, you know, deceptive Lambda functions, it doesn't matter. We can do decoys across the board.

(Tony at 01:10:17) I think the other piece that I would tell them is, you know, I think that's really important for any size. If you're building a structure, identity is critical. And if you're going to ensure that, you know, when you're breached, it's minimal impact. You need to protect Active Directory, whether it's Azure Active Directory or it's on-premise. Or if you've got a different identity system, look at that carefully, because people are going to steal those credentials 90% of the time and utilize those against you, and then they're going to move laterally and elevate those privileges.

(Tony at 01:10:49) So if you're not looking at those pieces, you know, you're going to get breached, and it's going to hurt.

(Joel Beasley at 01:10:54) Anything else we didn't cover that we want to get out there?

(Tony at 01:10:59) I think that's primarily it. The last thing I'll mention, you know, is, because we didn't really go deep on that, and that's the current security climate. I think that this problem is going to get worse and worse over the years because, again, we talked about, you know, people are trying to get a new product out very quickly, so first to market. And quite often, security is ignored for consumer-facing applications. I think adversaries are going to continue to take advantage of that.

(Tony at 01:11:26) We talked about everybody, you know, should realize that they're a target. And as we see more and more connectivity with more and more sensors on everything, complexity is going to continue to increase, which is also increasing our attack surface. So those are things we need to think about. Simplify where you can. You know, complexity isn't our friend. So, and I think those are some of the most important things. Think differently and be innovative. If you build anything that's completely static, you know, the very innovative and dynamic adversary is going to take advantage of you. So building your security program, it's got to be dynamic.

(Tony at 01:11:59) Keep thinking out of the box.

(Joel Beasley at 01:12:04) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.