Episode 382 ·
David White, Founder of Axio - How the Digital Threat Landscape is Evolving
Today we’re talking to David White, the Founder and President of Axio. And we discuss how David found his way into shaping many of today’s cybersecurity best practices. How the digital threat landscape is evolving today, and the importance of constantly reassessing your security strategy for the future.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Axio, check them out at https://axio.com

About David White:
Accomplished cybersecurity and business continuity strategy and management consultant with expertise in developing and using maturity models, benchmarking diagnostics, and training to support organizational improvement in cybersecurity and resilience. Chief architect of Electricity Subsector Cybersecurity Capability Maturity Model (ES-C2M2) and co-author of the CERT® Resiliency Management Model. Experience in federal, energy, and defense sectors.
About Axio:
Axio is the leader in SaaS-based cyber management software, which empowers security leaders to build and optimize security programs and quantify risk in financial terms. Axio360 is the only cyber risk management platform to align security leaders, business leaders, and Boards of Directors around a single source of truth about their most critical corporate risks. Since 2013, Axio has been a trusted partner to many of the world’s leading critical infrastructure, energy, manufacturing, and financial services companies, helping drive better visibility and decision-making about cybersecurity priorities and investments.
Transcript
(Joel Beasley at 00:00:04) Hello, my friends. Today we're talking to David White, the founder and president at Axio. And we discuss how David found his way into shaping many of today's cybersecurity best practices, how the digital threat landscape is evolving today, and the importance of constantly reassessing your security strategy for the future. All of this right here, right now on the Modern CTO podcast.
(Joel Beasley at 00:00:33) Here we go. This is the Modern CTO podcast.
(David White at 00:00:45) I grew up in North Carolina, in Western North Carolina. First generation college student. Studied civil engineering and engineering and public policy at Carnegie Mellon way back in the day. My first career was in robotics. So I did a master's degree in robotics and worked at a startup that was doing robotic systems for nuclear weapons complex cleanups.
(David White at 00:01:12) So I toured some of the nation's most interesting real estate, and we had some teams and technologies deployed there, which was interesting and fun. And then—
(Joel Beasley at 00:01:25) Did you spend a lot of time in Nevada?
(David White at 00:01:29) Not Nevada because, you know, that's where we want to send all the waste, but it's not where we generated the waste for the most part, right? So there are other, shall we say, hot spots around the country that are where the weapons factories were built.
(Joel Beasley at 00:01:46) That's interesting.
(David White at 00:01:49) That are an interesting legacy for us to clean up. It'll take decades and decades more work to do that. And ultimately, you know, after doing that for about 10 years, I went back to Carnegie Mellon at the Software Engineering Institute and started there in a business development role, serving as the account executive for key commercial clients that they were doing research for. Did a lot of work with the auto industry in Germany, which was fascinating. Did a lot of travel in Germany, so that was a lot of fun.
(David White at 00:02:26) And then ended up working in technology transition, sort of developing strategies for how the research lab at the university, at the institute, could get the methods and techniques that they were building, that we were building, really out into the world. And through that, started working with a team in CERT, the research program for cybersecurity there, on a number of projects, including what ultimately became a book that they were working on called the CERT Resilience Management Model. It wasn't really called that then, but they were like, "Here, we're going to need a transition strategy for this, so you should just read everything we're writing and start learning about this." So I did that, and I started doing my own kind of reading on the side and research and sending them comments and ideas and proposed edits.
(David White at 00:03:23) And they're like, "You're in the wrong job, dude. You should come over here and help us write this because you have a knack for this and clearly have a passion for it." And so, you know, a couple years later, my name was on the cover of that book. And that was the sort of beginning of my career in operational risk and cybersecurity. So that was not expected.
(David White at 00:03:52) It was completely fortuitous, opportunistic, and I'm really glad that I stepped into the opportunity when it was presented because I'm having a blast.
(Joel Beasley at 00:04:03) That's amazing. So writing the book kind of sent you on your trajectory of a career in security.
(David White at 00:04:11) Yeah. Yeah.
(Joel Beasley at 00:04:12) That's crazy.
(David White at 00:04:14) You know, it took us a couple of years to produce—in the end of the day, it was an 1,100-page book. I remember Addison-Wesley complaining about how they had to use special papers so they could get it into their book presses at the factory.
(Joel Beasley at 00:04:28) Like a Bible with really thin pages.
(David White at 00:04:31) Exactly. So, yeah, it was a blast, and I learned so much. And I got to lead the initial work with companies that were piloting that method and then ultimately using that method. And I got to work with some federal agencies on the same thing. And so, you know, it was a lot of fun.
(David White at 00:04:50) And then around 2010, 2011, around 2011 time frame, I started doing a lot of work with the electricity sector through the Department of Energy and some work that we were doing there. And ultimately, they asked me to serve as chief architect for a maturity model that they developed called the Cybersecurity Capability Maturity Model, which was really developed by the industry for the industry back in 2012. It was a fantastic collaborative project. I spent many, many long days and late nights in DC working with stakeholders from a lot of different utilities and the Department of Energy and all of the big trade associations in electricity on developing guidance that was compact and lightweight enough that it could be useful by a wide range of utilities, the largest utilities in the nation and the smallest utilities in the nation. So it was a really challenging project, and it was driven by the White House at the time, who was very concerned about security in the electricity sector, the power grid.
(Joel Beasley at 00:06:01) Oh.
(David White at 00:06:03) Yeah. We got that out in June 2012. And, yeah, hundreds, thousands of utilities have been using it since then to help guide their cybersecurity programs. It was a precursor to the NIST Cybersecurity Framework. So the folks at the Department of Energy who worked on the project went on to the National Security Council and then helped create the project that led to the NIST Cybersecurity Framework.
(David White at 00:06:31) And so that whole trajectory was really interesting for me to watch as part of my career from just being this guy who is like, "Hey, I have some ideas for this book you guys are writing. How about this?" Right? So, yeah, it's been a blast.
(Joel Beasley at 00:06:49) That's crazy. So you've been like a driving force behind a lot of the modern best practices that are being used in security.
(David White at 00:06:58) Yeah. Yeah. Who knew that was going to happen? I sure didn't.
(Joel Beasley at 00:07:05) So when did Axio come into the picture?
(David White at 00:07:09) Wow. So that's another interesting story. The company was founded by myself and Scott Kannry. And, you know, at the time, I was at Carnegie Mellon University still at the Software Engineering Institute. Scott was working for Aon, one of the world's largest commercial insurance brokers.
(David White at 00:07:30) And Scott was a real thought leader in the deployment of cyber insurance and other insurance products to help organizations transfer their exposure associated with cyber risk. And Scott and I met at this really interesting dive bar in New York the very first time we met in person. And at this bar, they serve beer from the tap in 32-ounce cups. It's the only way they serve it.
(Joel Beasley at 00:07:59) Wonderful.
(David White at 00:08:00) Yeah. They call them buckets. So you order beer by the bucket, and the cups are so big that you've got to put both hands around it when it's full, or it just sort of squeezes the beer out over the top. Anyway, Scott and I met over a couple of beers and started talking about cyber risk. And, you know, at the university at the time, we were still teaching people that, look, risk transfer is not really an option for cyber.
(David White at 00:08:28) You've got to mitigate, accept, monitor. Transfer is really nascent. And what I—
(Joel Beasley at 00:08:37) Meaning like cyber insurance?
(David White at 00:08:39) Like cyber insurance. Yeah.
(Joel Beasley at 00:08:41) Got it.
(David White at 00:08:41) And, you know, what I learned from Scott was quite the contrary. It was still a pretty immature form of risk transfer at the time. And it's evolved a lot since 2013, but Scott and I started imagining a future where, you know, security and risk leaders are making decisions about where to spend their limited resources. And so do you buy a technology? Do you invest in process-oriented controls?
(David White at 00:09:11) Do you invest in administrative controls? Do you invest in risk transfer? How, as a security leader, do you make that call? No security leader has unlimited resources. And so how do you make a smart decision about where to put your next dollar as an investment to protect the organization and reduce its risk exposure?
(David White at 00:09:32) And that led to the thesis around which Axio was created. So in 2013, we started this conversation. I left the university, and we started taking on some scrappy projects with clients to sort of bootstrap a set of activities. And then in 2015, we signed our first major contract with a company and also closed on some seed financing, and we were off to the races. And, you know, in that interim, Scott and I had been developing what we now call Axio360 and delivering it really in spreadsheet mode, sort of a couple of experts running around the world, helping people make good decisions about where to invest to protect their organizations from cyber risk.
(David White at 00:10:23) And now we have all of that in a methodology that's, you know, much, much better than it was back in 2013, '14, and '15, and it's in a modern software-as-a-service application and being used by more than a thousand organizations. I think we have close to 5,000 users in our platform now. So it's really been a really exciting journey. And we have so much more to bring to the marketplace in support of that mission that works out.
(Joel Beasley at 00:10:56) That's amazing. Very cool, man. So you guys are kind of giving organizations the information they need to be smart about where they're spending for mitigating cyber risk.
(David White at 00:11:10) Yeah. Yeah. Yeah. And, you know, one of the things that Scott and I have always said is it's really about unlocking and making use of the information that you have inside the organization because almost nobody can come from outside your organization and tell you something that someone inside your organization doesn't already know about the risk that you're facing, right?
(David White at 00:11:35) Because it's people inside your organization that understand how things are wired up. They understand what happens if I take this down or take this away, whether it's a machine or a server or even an endpoint. Like, how does that affect the business? I have no way of knowing that coming in from the outside. The people in your organization know that.
(David White at 00:11:54) And so we really developed a methodology that is for the masses that we can teach any organization to do on their own, or we have a professional services team that can come in and do it with and for them. But that was always our vision, a sort of something for the masses as opposed to a methodology for a select few. And it's working. It's, yeah.
(Joel Beasley at 00:12:23) That's awesome. So can you explain to me, like I'm a five-year-old, what it looks like to—how do you go about estimating the financial strain of cyber risks?
(David White at 00:12:37) Sure. Yeah. So our methodology is really straightforward. And the first part of that methodology is just to think about, you know, what could go wrong. And if the security and risk leaders inside your organization are paying attention to anything, they're probably watching the threat landscape.
(David White at 00:12:58) And so they're seeing what's happening in the news. They're seeing what's happening at other organizations. And almost all of those people—I mean, you know, you probably do it yourself when you read a headline. You're like, "Oh man, what if that happened to us? What would it be like here if that happened to us? Thank goodness that wasn't us." Right? And every security and risk leader goes through that same thing. So you're processing all of this stuff through your head all the time just based on what you see and read and observe in the threat landscape, whether it's open source or news or trade association articles or maybe you're getting some classified briefings if you're in select critical infrastructure sectors. But you have a sense of what's going on in that landscape.
(David White at 00:13:39) And so the first step in our process is just developing a set of scenarios. We call them scenarios of risks unfolding, right? And, you know, our approach for this is to go top-down. Meaning, we focus on affecting the business.
(David White at 00:13:59) So everything we try to do is in the language of the business. And so, look, if you're dependent on this factory, what could happen that could cause that factory to have to go offline? Or what could happen that would cause that factory to have to curtail production or reduce output or something, right? If you have a lot of delivery contracts, we worked with a client where, you know, they were a manufacturer. They had a just-in-time delivery contract with one of their major clients that calculated penalties in minutes. Like every minute they had a shipment that was late, they paid, I forget how much it was, a couple hundred dollars or something. So, you know, you can imagine that for them looking from the top down at business impact, what they really want to know is what could happen here that would have that shipment be late, right? And that's very different than some legacy approaches that look from the bottom up and say, "Okay. Let's go run around to every asset in the organization and figure out what could happen to that asset." And then we sort of build up scenarios from that. That becomes a kind of boil-the-ocean process that very quickly gets divorced from the business impact. We go top-down. There are other methods that go bottom-up.
(David White at 00:15:18) Top-down is much easier, right? Because you're really talking to business leaders about what could affect business. So that's number one. And step two is prioritize those. Look, you're never going to do a thorough analysis on every risk you identify. And so we go through a prioritization technique. We have a couple of techniques that are designed to leverage the expert judgment inside your own organization. We use a multi-voting technique. We also use a force-ranking technique. Those are the two most popular prioritization schemes we have, and we've got both of those built into our software. And so that gives you the sort of critical few that you then want to take the next step on. Now you could work your way through the whole list, but you've got to start with the high-priority item. So identify, prioritize, and then quantify.
(David White at 00:16:10) And we do quantification. We developed, Scott and I, in the early days of the company back when we were slinging spreadsheets, right, we developed a list of all of the common impacts that organizations face from cyber events, and we mapped those into a framework that we still use today.
(David White at 00:16:32) And so now what we've done is for every one of those potential impacts, we have one or more candidate simple math formulas on how you can think about the scale of that impact in your organization, right? And so it's simple things like, are we going to bring in an outside forensics team? Well, if you're going to bring in an outside forensics team, there are two really easy ways to estimate that. One is, like, how big is the team?
(David White at 00:17:00) How long are they going to be here? How many hours are there in a day? And how much do we pay them by the hour, right? That's just simple math.
(David White at 00:17:08) There's another technique that some forensics firms use that says, you know, how many computers do we think we're going to have to do forensics analysis on, and how many hours do we think it's going to take per computer, and what's our hourly rate? So that's just a different way to get at the same basic answer of, let's put a price tag on forensics. And then we have candidate equations for every one of those impacts, and you can estimate the impact of an event by populating those estimated values into those formulas. You pick a formula, pops up on the screen, you put in estimated values. And we also were really careful with our methodology to have people not get bogged down in a quest for precision.
(David White at 00:17:57) And so every one of those estimated values in one of our simple math formulas has a minimum, expected, and maximum amount. So if I said, Adam, what's your negotiated rate at Modern CTO for forensics? And you said, oh, Dave, it's, you know, $317.48 per hour. Well, then we know that value. We can just type it into the expected value box.
(David White at 00:18:22) Right? But if you said, oh, gosh, I don't know. We'd probably end up paying, I don't know, three to $700 an hour. It sort of depends on what else is going on in the world and how fast we can get somebody and the extent to which our hair is on fire and things like that.
(David White at 00:18:38) Then we can just put that in. Okay. Let's just estimate this at three to 700. So that way you can work quickly through this process without getting bogged down in a quest for false precision. These are all estimates. Right? And so that leads us to a bunch of equations that have a bunch of range values. And then on the back end, our software just boils all that up and uses Monte Carlo simulation to give you a range of values for the total event. And that's how we do it. It's really straightforward.
(David White at 00:19:11) And one of the beautiful things that our developers did with our software that I really love is they created this way to edit and actually build custom formulas. So if you said, yeah, we're not going to estimate it that way. Here's how we think about it in our organization. You could just start typing that in plain language, and our system will turn it into an equation. And so what you end up in all cases are equations that you can read.
(David White at 00:19:39) We found that that makes a huge difference for people who have to stand in front of these estimates inside their organization. Because if you can stand in front of something and somebody asks you a question about it and you can just look at it and say, well, yeah, we arrived at that in the following way. Then that's very different than if you're standing in front of a board looking at some black box results that you have no idea how they were calculated. Right?
(David White at 00:20:05) So, yeah. It allows our users to have the confidence to stand in front of those estimates. Right? So sorry. That was probably a really long-winded answer to your question, but that's how we do it.
(Joel Beasley at 00:20:21) No. That was great. That gives me a much clearer picture, not only of how you do it, but more exactly what you're trying to do. So earlier you mentioned that it's a SaaS platform that people can use. What does it look like on the UX side of things? So you have all this methodology built in on the back end. Is it just pretty easy? They can just go down and fill in values and boxes and the number spits out?
(David White at 00:20:48) Absolutely.
(Joel Beasley at 00:20:50) That's awesome. Yeah. And with the explainability built in on top of that too so that they can take it to upper management.
(David White at 00:20:56) Right. Yeah. And so I think that our UX team has done a fantastic job so far. And we have some new folks on the team recently that are going to do an even more incredible job as we continue to evolve the platform. Because they've been working on some new reports that I've seen that we've put in front of some current and candidate clients that are really knocking people's socks off. So we're also committed to creating a method that didn't require users or consumers of the information to have a degree in statistics to understand.
(David White at 00:21:44) So we've come up with some really straightforward ways to communicate complex concepts about impact of events. And we've come up with a proprietary way to aggregate those events and give an annual view of risk exposure that is incredibly novel and founded in some really good academic research. And so our output is also easy to understand.
(Joel Beasley at 00:22:13) That's awesome. So something I've seen on Axio's website and materials kind of pretty often is the four most critical questions for cyber risk. Can you take me through what those questions are? First of all, who should be asking these questions? What is the target audience of this?
(David White at 00:22:35) Yeah. I think, so from my perspective, boards and executives should be asking these questions. Right? And they should be asking it of security and risk leaders. And so security and risk leaders should be asking those questions of their teams. Right? So but I think that it's important for an abstraction of that information to be presented all the way at the highest levels in an organization. It really is the board's fiduciary responsibility to protect the organization's balance sheet and bottom line. And they can't really do that without understanding what's at risk. So question number one is, what's at risk? And we answer that using our quantification methodology.
(David White at 00:23:21) Because we want folks to be able to answer that question using dollars and cents, the same language other people in organizations are using to talk about risk, as opposed to answering it in red, yellow, and green, which is how we've been answering it in the security space for a long time. Right? So we'd like for people to be able to put down the crayons and pick up the calculators. So that's the vision for quantification. The second question is, are we doing the right things to mature our cybersecurity program?
(David White at 00:23:59) And, you know, there are a lot of assessments, including some of the assessments I worked on earlier in my career. There are a lot of great assessment instruments out there. We have many of those instruments loaded into our platform. We also support custom instruments. So if Modern CTO had its own framework that you've developed for managing cybersecurity, you could load that into our platform and use that.
(David White at 00:24:23) But the whole notion there is that assessments of your program or of your controls should not be once and done events. They should be continuous events. Right? And those assessments need to be backwards looking, current looking, and future looking. And the only way to accomplish that is to, when you're conducting an assessment, capture not only where you are today, but also where you intend to be at a specific point in the future.
(David White at 00:24:55) And so by implementing assessments in that way, you get essentially a story arc of where you've been, because you have all of that historical data in the platform, where you are today, and where you're going in the future. It also gives you the ability to evaluate whether you've got enough budget to get where you think you should be at that point in the future. Right? And so we have some planning tools and other advanced techniques in the platform to help you understand where you are on your journey and to plan that journey for your overall cybersecurity program and the deployment of controls to protect the organization. So that's answer two. How are we maturing our program? Right?
(David White at 00:25:35) Question three is, have we protected the balance sheet? So how much of that risk that we're facing, how much of that impact would flow to the organization's financial statements if we had a bad event? And the only way to answer that question, and this question is so important for boards to know the answer to, is to understand how your insurance portfolio would respond. Do we have the right kind of coverage? This is no different than thinking about, look, if you went out and bought a $200,000, $250,000 house, right? But you only bought $100,000 worth of insurance, then chances are, if you lost that house to a fire, you wouldn't have enough coverage.
(Joel Beasley at 00:26:29) Right? Yeah. Pretty straightforward.
(David White at 00:26:32) Unless you paid two and a half times what it's worth or two and a half times what it would cost to replace, then you're underinsured. And you'd better have that money sitting in reserve, or you're probably looking at bankruptcy if you have a really bad thing happen to your house. Right? And it's the same thing with organizations. Look. The resilience of an organization at the end of the day is driven by one thing. Can you afford to continue operating? Can you make it through and afford to continue operating? And the only way to answer that is financially, and the way to answer it financially with respect to cyber risk is to understand what's at risk through quantification and then what's your capacity to transfer that so that you understand how much you've got to cover yourself. Right?
(David White at 00:27:20) So that's question three, you know, what's at stake on the financial statements or balance sheets? And then question four is, what investment should we make? The threat landscape is changing. We all know that. We've seen it. We've seen dramatic shifts over the past, you know, 12 to 24 months in the prominence of ransomware as an event type. You know, a couple years ago, everybody was wringing their hands about PCI theft, credit card information theft. Right? When's the last time you heard people read a bunch of headlines about credit card information theft? It's been a while. Right?
(Joel Beasley at 00:27:59) Probably the Target.
(David White at 00:28:01) Yeah. And that was what? That was 2017, I think? 2016, 2017. Right.
(Joel Beasley at 00:28:06) A while ago.
(David White at 00:28:06) Exactly. Because that led to an enormous investment in deploying end-to-end encryption to better protect credit card data in retailers. Right? And so that investment was pretty clear, not in the earliest days of that trend, but it became pretty clear and a lot of retailers made the right investment. And now we're in a situation where every organization is facing a ransomware threat, and so we're scrambling to figure out what the right investments are for that. And tomorrow, it'll be something else. And ransomware is not the only thing we have to worry about. Right?
(David White at 00:28:45) But I'm using that as a point to say the threat landscape changes, and it's going to continue to change. These are human-motivated, human-perpetrated events, and so they're only ever going to be limited by the imagination and technical capabilities of humans to figure out a way to make money on this. Right? Yeah. And that's forgetting for a second nation states.
(David White at 00:29:09) But so the risk landscape changes. So optimizing your investment over time or figuring out the right next spend, what's my next best move here? Right? Is an important question, and we strongly believe that those first three questions should inform the fourth question.
(Joel Beasley at 00:29:29) Absolutely. Yeah.
(David White at 00:29:29) And so we have ways to model that in our platform too, by either adjusting your insurance portfolio or modeling control changes and how they would affect the quantified scenarios, or building plans for maturing your program and understanding the cost of that. So that fourth question is really about what's my optimal next best spend or next best move.
(Joel Beasley at 00:29:57) That was excellent, man. Let me just try and say them all at once so the listener can remember. So we have, what's at risk? How are we maturing our cybersecurity program? Is that correct as the second one?
(David White at 00:30:08) Nice.
(Joel Beasley at 00:30:08) How are we protecting the balance sheet? And then what investments should we make in security?
(David White at 00:30:16) Yes. Yeah.
(Joel Beasley at 00:30:17) Cool. All right. We got it. So I want to get a little bit more into the ransomware stuff.
(David White at 00:30:24) Okay.
(Joel Beasley at 00:30:24) So are you able to offer your program, the Axio platform, as an option for when a company is in a ransomware attack? Can they use it to see whether or not they should just pay it and be done? Is that a use case?
(David White at 00:30:43) Yeah. You could certainly do that modeling. And I want to be careful because look, I have the same kind of moral and ethical concerns that we all have about paying criminals. And we've also seen recent trends for criminals going back to the well for multiple demands. And so, you know, it turns out there's not a lot of integrity among thieves. But that said, you know, there are some cases where it could be compelling to make that payment. And certainly, modeling an event out as part of that decision-making process is one way to do that.
(Joel Beasley at 00:31:27) Right.
(David White at 00:31:28) And, look, I think that some of the most compelling reasons to pay involve maybe slowing the potential release of data that may have been stolen that could dramatically and negatively affect people if it were disclosed. Right? And so you can think about certain kinds of health records in that category.
(Joel Beasley at 00:31:50) Right.
(David White at 00:31:51) At this point in time, I mean, if the attackers were, if you're running good backups, there's probably not going to be a good reason to pay unless you're convinced it's going to take you longer to recover operations than it will to decrypt the data. And we saw that just this week with Accenture. Accenture made a really good showing. I don't know if you saw that in the news in the last couple of days, but Accenture announced that they had a ransomware attack, and they fully recovered and very swiftly recovered their operations in the part of the business that was affected from backups, and they resumed operation. And it was sort of a blip. It made a couple of headlines, and they're off and running. So good for them. It's great to see somebody of that size demonstrate the kind of resilience that we want organizations to have. But, yes, you could build some financial models to help you make that decision. Absolutely.
(Joel Beasley at 00:32:44) That's really cool. Yeah. So a question I've wanted to ask you in this interview relates to a while ago we had on Tony Cole, the CTO of Attivo Networks. And this dude is an OG cybersecurity guy. He was running cybersecurity in the Pentagon on 9/11, and he also worked on the NIST framework.
(David White at 00:33:06) Yep.
(Joel Beasley at 00:33:06) Did some work with MITRE as well. Anyway, it was a pleasure listening to him talk, but he was talking about how there's $140 billion spent on cybersecurity tools each year. And with all of these resources pouring into cybersecurity, I think it's easy to ask the question, why is it still so hard to stay one step ahead of bad actors?
(David White at 00:33:32) So my answer to that question is that it's not just a technology problem. And as a discipline, we, as in the cybersecurity world, are not yet mature enough as a discipline to recognize universally that it's not simply a technical problem. And so, and it's really easy to be convinced, because it does involve technology, it's really easy to be convinced that, you know, this new whiz-bang technology is part of the solution. The problem is that, you know, I think of the, have you ever been to the RSA conference? I don't know.
(Joel Beasley at 00:34:13) No. I just have not.
(David White at 00:34:13) Yeah. So it's an interesting place. It's an interesting event, really interesting event, and they have a trade show. The trade show has thousands of cybersecurity technology vendors. Thousands. And so I think of it as the silver bullet bazaar. Right?
(David White at 00:34:33) Because you can just look at one silver bullet after another. And look, all of these technologies are critically important as part of an overall strategy, and none of them, or the accumulation of all of them, are not going to solve this on their own. It is a people, process, and technology problem. And so we can't solve it by technology alone. God, I wish I could remember the guy's name.
(David White at 00:34:59) I was reading an interview with somebody recently. It'll come to me maybe in a minute. And he was like, look, it's not a technology problem. If it was a technology problem, we would have solved it fifteen years ago. Right? It takes more than that. And so I think that's the answer, is that there's a lot of money still being spent chasing silver bullets, and they're part of the solution, but they're not the entire solution.
(Joel Beasley at 00:35:25) That makes sense. And so while it does come down to being a people problem, I think aside from education, obviously as a wonderful part of the solution, I think there's still definitely a role for technology to play in terms of making it easier for the people to have good practices. Right?
(David White at 00:35:47) Absolutely. Absolutely. Please don't hear anything I said as saying that it's not a technology problem. All I'm saying is it's not only a technology problem.
(David White at 00:35:55) Right.
(Joel Beasley at 00:35:55) Right. Right.
(David White at 00:35:56) It's not something that we can solve just with technology. It's also something that we can't solve without technology. Right? It's just that we need more than technology. And look, the other part of that dynamic is, according to the Wall Street Journal, there are now more than 65 nation states that are investing in offensive cyber weapons. And you can't have that kind of investment at the top of the pyramid without it trickling down. So all of those investments in offensive cyber weaponry are raising the skill level, the capability level, and the tools that are available across the criminal enterprise because all of those technologies are being built by companies, and the people who work at those companies go and work at other companies. Sometimes they leak out. EternalBlue, which was behind the NotPetya event, that was a nation state built weapon that was stolen and then used against us.
(David White at 00:37:08) And it was built by the US, for those of us following along. But you can't keep that stuff in a bottle. Right? These aren't like bombs that once they explode, you can't really tape them back together and then use them on the other guy. Cyber weapons, once they're out there, they're out there.
(David White at 00:37:24) And so this investment by nation states is raising the water level of skills. I think of it as trickle down capabilities, trickle down attack capabilities. And, you know, that means that this is like treading water. To stay in place requires continuous input of resources. So even to maintain where you are right now from a cyber posture in an organization requires the continuous input of resources. And to move forward, to get better, requires even more resources. So we're going to continue to spend. We just don't have a choice. Right?
(Joel Beasley at 00:38:02) That makes sense. And I mean, as you're saying, these attacks are getting more and more advanced. And just earlier this week, we had on the CTO of Avast. And I don't know if you're familiar with him as a person, but he self-described himself as a hardcore AI scientist guy.
(David White at 00:38:25) Okay.
(Joel Beasley at 00:38:25) That was his introduction. And he's a professor in AI at Czech University. And he was talking about adversarial AI in the cybersecurity space and how the main problem that presents is it increases the scale at which attackers can attack because all they need to do once they have whatever scheme in place is just buy more compute power and give their AI algorithm more room to run with. And as a result of that, the only way to really fight it is by having really good security AI where the same kind of, what's the word, the same process works. You can throw more compute at it and it'll do a better job. And the amount of power creep that's there, thinking about that, it's just insane. I just have an image in my head of giants fighting, you know?
(David White at 00:39:26) Right.
(Joel Beasley at 00:39:27) And just getting bigger and bigger as they go to match each other's strength. And that just sounded so crazy to me. And I was just curious, have you been spending much time thinking about the adversarial AI and the way that's impacting the security landscape?
(David White at 00:39:45) Well, look. I think, yeah, I haven't really thought of it in AI terms. I think of it more generically as the automation of those attack tools. Right? Now intelligence and automation, I think of AI as sort of intelligence crossed with automation, and maybe that's, you know, he might dispute me on that, but that's how I might describe it to a fifth grader. Right? Back to our earlier point.
(Joel Beasley at 00:40:14) But I think that's fair. Yeah.
(David White at 00:40:17) Look, automation is a problem because it's pretty inexpensive in modern attack tools to try out attacks on thousands of different organizations in one day. Right? And so certainly, to the extent that it's happening, the incorporation of artificial intelligence into an evolving automated attack tool is of enormous concern. And do I believe that there's a role for AI on the protect side? Absolutely, there is. Because it's only through algorithms and other massively scalable techniques that we can ingest all of the signals available to start to have better visibility, detection capability, and learning of our environments and the attacks that we're facing. So I'm a big believer in that. I agree that, you know, we've got to deploy that on the protect side as well.
(Joel Beasley at 00:41:28) Another company that we've had on the podcast before, because we've just had a lot of security companies on because as we've covered, it's a huge space. You've been to the Silver Bullet Expo.
(David White at 00:41:39) Yeah.
(Joel Beasley at 00:41:39) Exactly. And that's where I've gotten a lot of my context around security from. And so one of these companies that's come on is called FireMon and they focus on network security. And their VP Tim, who put on the show, was talking about a report they released called the Future of Network Security Report. And it focused a lot on zero trust. And I think zero trust is, it obviously seems like such a great way to conduct your security, but it also seems really hard to implement in some use cases. Like how earlier you were talking about the manufacturing company that had a just-in-time delivery contract.
(David White at 00:42:20) And so...
(Joel Beasley at 00:42:20) I was thinking like, especially in manufacturing automation, the manufacturers and the suppliers and the distributors down the chain, they all have to share their data to an extent in order to get the full efficiency out of their automation. So how do you think about trying to implement zero trust in areas where you implicitly have to trust your partners?
(David White at 00:42:51) Yeah. So this is a challenge, and it's one of those, you know, I think least trust might be a better moniker, but it didn't pass the marketing committee. Right? And so zero trust is the name. And I think it's funny. A year or so ago, I was in a conversation with a couple of folks from the security world who I deeply admire and respect. And they were like, this whole zero trust. There's no such thing as zero trust. It's this mythical asymptotic approach. You can't get to zero trust. There has to be some basis of trust. There's gotta be something you trust at the core. Right? So zero trust is a misnomer. And I was like, yeah, it's a misnomer, but it's a really catchy marketing phrase for a strategy. The way I like to think about it is, look, one of our clients manages a really complex operation, and one of the core premises of their strategy is at any one point in time, at least one endpoint in our environment is being controlled by an adversary. So they take that as a given.
(Joel Beasley at 00:43:53) Wow.
(David White at 00:44:13) And they've built their entire security strategy around that as a given, that at any one point in time, at least one computer on their network is being controlled by an adversary. Right? And so when I think about zero trust, that's the story I think about because then that causes you to question data on the network that you wouldn't normally question, to question identities on the network that you wouldn't normally question. Right? Many organizations have a security strategy that we think about as a hard shell and gooey center where once you're in, you're in and you can do anything. Right? If you're assuming that at least one computer on the network is being controlled by an adversary, you can't have that gooey center. Right? You can't allow anyone to do anything once they're through the castle gate. And for me, that's the sort of core idea behind zero trust, and I really like that. I think it's a sound security strategy. And I think zero trust is a really catchy name, but it's a little bit of a misnomer from my view. Now some zero trust fanatics probably debate me on that. And, you know, they probably know more than I do anyway, so that's okay. But yeah, that's my view.
(Joel Beasley at 00:45:34) Well, I think that's a really smart way to think about it and really brings the phrase zero trust to be even truer when you're assuming that there's already an adversary in the space, because yeah, then you're not trusting anyone. But yeah, I think that's a trend that's definitely coming out more in the security landscape today of not having that gooey center because we're seeing attacks like, that was kind of the detriment of the SolarWinds attack, right? That the attacker was in there and they were able to move laterally and escalate their privileges. And if they had more of a focus on monitoring the data inside and not letting the center be so gooey, then that wouldn't have happened.
(David White at 00:46:19) Yeah. And a lot of those efforts, I'm really a fan of because they are about hardening the center. And, you know, that's also the thing that we're seeing in ransomware to go back to the ransomware conversation. The kinds of things that are necessary in a network to inhibit lateral movement also protect you from the scale of a ransomware attack. Because if a ransomware attacker is unable to get to everything, then it makes it harder for them to take everything down. Right? So you can limit the impact of an attack by limiting the lateral movement, sort of limiting the blast radius, I think of it. And so all of those efforts are really important for our security future.
(Joel Beasley at 00:47:04) That's really important to think about. Yeah. So before we wrap up, I just want to make sure if there's anything that we didn't cover that you want to make sure we hit on, or any plugs you want to give for Axio. Are you guys hiring right now? What are you looking to get out to the world, man?
(David White at 00:47:23) We are hiring. We have a software development team. Look, we're 100% onshore software development. Our software development team is headquartered here in Atlanta where I live, but we're not limiting, you know, the whole job market has become national during the pandemic. So you're not limited to Atlanta, but that's where we're headquartered from a software development perspective. So we are actively seeking developers. We have a professional services group. We're actively hiring professional services folks. We're hiring in the marketing space. We're hiring in the sales space. We have a careers page on our website. So if you're interested in working with us, please visit that careers page because we are always looking for great people. Absolutely.
(David White at 00:48:14) From a plug perspective, oh gosh. We recently released a service, a sort of a deployment or a product really that is designed to help organizations get their heads around ransomware as a risk. And it includes a deep dive on ransomware controls. We built a ransomware assessment in collaboration with a large insurance company, leveraging what they've learned from a couple hundred claims in the past year. So they certainly have a lot of great visibility from that. We also leveraged all of the great guidance that's come out of DHS CISA. So we have a ransomware preparedness assessment that is available for free. You can visit axio.com and find out how to get access to that. We also have a ransomware modeling exercise that we can conduct with an organization to help you understand the potential impact. This is also a really great way to understand some of those and uncover some of those dependencies in different parts of your operation that you might not be mindful of. Things like, you know, Colonial Pipeline discovered during their event where an IT-only event took down the OT side of the network and thereby the pipeline. Right? Because of those dependencies in operation and some potential porosity between those two networks from everything we know. I don't have any inside information on that, but I've read all the same stories that you have, I'm sure.
(David White at 00:49:52) Right? And then we have an improvement planning activity that follows on that. So for any organization that is really trying to follow the guidance that came out of the White House a couple of weeks ago for how organizations and business leaders should be thinking about and responding to ransomware, we have a product available to help you out with that that we're really excited about. And it's also a great way to sample the full Axio methodology that we have in our platform.
(Joel Beasley at 00:50:26) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.