Episode 441 ·
Defending the Antivirus Authority with Jaya Baloo, CISO at Avast
Today we’re talking to Jaya Baloo, the CISO at Avast. And we discuss how Jaya and the Avast team successfully defended a notable cyber attack in her first week on the job. The impact quantum computers will have on encryption, and why it’s important to prioritize time for mentorship.
All of this right here, right now, on the ModernCTO Podcast!
To learn more about Avast, check them out at https://www.avast.com/
In case you missed it: check out our previous episodes with Avast's CTO Michal Pěchouček, and SVP & GM of Identity Charles Walton!

About Jaya Baloo:
Jaya Baloo is a cybersecurity expert who is currently the Chief Information Security Officer (CISO) at Avast Software. Baloo was named as one of the top 100 CISO's in 2017, and one of Forbes 100 Women Founders in Europe To Follow in 2018.
About Avast:
At Avast, we strive to give everyone the power to explore our shared digital world freely and safely. Our team is working to help shape the digital world to be a freer, fairer and safer place through the application of science, technology and human ingenuity, and we are looking for people who share our passion to contribute to a better online world. Avast promotes a rich diversity of cultures, debates, and out-of-the-box thinking. Today, Avast is a FTSE 100 company that safeguards more than 435 million people worldwide, protecting their digital data, identity, and privacy.
Transcript
(Joel Beasley at 00:00:03)
Hello, my friends. Today we're talking to Jaya, the Chief Information Security Officer at Avast. And we discuss how Jaya and the Avast team successfully defended a notable cyberattack during her first week on the job, the impact that quantum computers will have on encryption, and why it's important to prioritize time for mentorship. All of this right here, right now on the Modern CTO Podcast.
(Jaya at 00:00:36)
Here we go.
(Joel Beasley at 00:00:37)
This is the Modern CTO Podcast.
(Joel Beasley at 00:00:49)
So how did you first get interested in technology? What was your start?
(Jaya at 00:00:53)
Wow. Wow. That was a really long time ago. I don't think that we had very dissimilar backgrounds. I was really young. I grew up in the States, in New York. I live in the Netherlands, but I think I started when I was younger than ten. I think it must have been, I don't know, eight or nine. And on TV—we're talking eighties—there were already shows. And I remember there was a show called Whiz Kids, and it was about this group of—there was this guy who reminds me of Matthew Broderick, but nothing like him. You know, no conflation with Sneakers. But he was hacking into the California traffic boards, like over the highway. You know, you have the traffic information boards. So already then, I was just super inspired by hackers and security and stuff from when I was a kid. I had a public school teacher that sorted it out that we could get Basic programming classes when we were still in public school. So I think I was nine when I had introduction to Basic. And I got a computer that Christmas because I was so completely in love and a little bit obsessive, I think. So, yeah. And then later, I don't know if you've ever heard of CompuServe.
(Joel Beasley at 00:02:09)
I have not.
(Jaya at 00:02:10)
No. Dude, I'm so old. Okay, well, there's this Internet service provider called CompuServe, and I had a conversation before and a CompuServe account is all I ever really needed, I think. So I wound up doing a whole bunch of stuff with that until my parents cut off the account because I spent too much money and too much time on it and I racked up our bills. And so they were like, "Okay, that's it. You're done. No more of this anymore." And then, before, you know, you had like a grace period where you still had to kind of pay. And so during that grace period, I learned all about bulletin board systems and dialing. And so I wrote a dialer program in Basic to go find other BBSs in the local area because I remember local calls were free. Like, within your own little vicinity, you could have free local calls. So I just dialed all the numbers and waited for other BBSs. And it's like the premise pretty much for War Games when he tries to do the same thing for a game. I don't know if you've ever seen that movie.
(Joel Beasley at 00:03:08)
A while ago, but yeah.
(Jaya at 00:03:09)
Yeah. Okay. So it's so sad, but those were, at the time when I was a kid, those were, you know, my favorite movies. And later, Sneakers. Have you seen Sneakers?
(Joel Beasley at 00:03:20)
Not Sneakers.
(Jaya at 00:03:22)
So good. So old, but so good.
(Joel Beasley at 00:03:24)
Yeah. Alright. Alright. I'll add to the list. That's great.
(Jaya at 00:03:28)
Yeah.
(Joel Beasley at 00:03:29)
So what was your first major job in tech?
(Jaya at 00:03:32)
Well, major job. I don't know. I mean, I think there's different types of jobs that give you different things. There are jobs that pay your bills. So I worked in the computer science department, you know, fixing printers and VAX VMS systems and stuff. And I learned a lot. And I did this while I was studying something completely different. So it was good. But I also had jobs that were super inspiring. I worked in Boston, in Harvard Square, in a place—this was a side job in university—where I worked at this place called Cybersmith, and they had VR games. And they had—which is really cool because it opened my eyes at a time where there wasn't sort of mass market for this stuff, but clearly people were interested. And I was teaching people how to use the Internet, you know, how to use FTP and Gopher and Archie and Veronica. I mean, again, this was Wayback Machine kind of long time ago stuff. But still, already then, the appeal and the potential and the inspirational quality of being able to play and touch and, you know, do that stuff was just so immense that every job—so, major is defined by what it provides you. It doesn't necessarily only provide you income. If it provides you inspiration, it might be much more valuable. So my first major job, I think, was actually probably the place where I got the most inspiration and where I learned the most, which were the jobs I had in university.
(Joel Beasley at 00:04:53)
That's awesome. Have you done any VR stuff since then?
(Jaya at 00:04:57)
No. I mean, no. But afterwards I got real job jobs where, you know, I worked for bank and then I worked for telco and, you know. But I think nowadays, of course, I do cool stuff at work, but there are so many cooler things out there. There's so many cool things to work on. I think that's my biggest thing these days, is to find time and ability to seek those things out.
(Joel Beasley at 00:05:23)
So I saw that one job title on your LinkedIn was Lead of Lawful Interception at Verizon. What does that mean? It sounds—
(Jaya at 00:05:32)
It was practice lead. Yeah. No. So I was working at Verizon. It was actually in Netherlands, and I was working in—it was a consultancy services unit, and I was good at designing safe infrastructures. It's basically network architecture. But lawful intercept is when you have a warrant and you're allowed to do network interception. Things can go horribly pear-shaped because you gotta make sure that you can actually conduct the intercept on the basis of the warrant. You gotta also make sure that you don't do it on the same network where you would have production problems, right? It's from a pure preserve the initial network perspective. But also, you'd have to do it in such a way that the person who you're tapping doesn't know that you're tapping them. So, on a really small network, if you start making a copy of all of the production traffic, if you can see on MRTG over the routers that you're monitoring—if you can see that there's a traffic spike—then you may say, "Oh, here's my normal traffic levels, and by the way, this is what it looks like when I'm also capturing traffic." And if you can do it at a granular enough level, you let the person who you're tapping know that you're tapping them. And so that's not really the idea. So there's a lot of things that can go wrong. I'm not even beginning to talk about all of the craziness that can happen with the built-in tapping modules that are there in network equipment because that's a whole other level of pain that can go wrong. And also, all of this stuff is legally mandated things that you must do if you want to provide a public service. That means that there is stuff you must do, but there's also stuff you absolutely cannot do, which is ever misuse this ridiculous capability. So that means you have to have super strong audit logs that you can vet and verify that no one just ever wanted to tap their ex-girlfriend or, you know, boyfriend or stuff. So you really have to have it under very tight scrutiny and control because this is an awesome power, you know, in terms of just how crazy powerful it is to actually be able to—what's the word—invade someone's privacy on the basis of some, hopefully, legitimate security concern. So you don't want it being used willy-nilly, but you also don't want it to be used by an attacker.
(Joel Beasley at 00:07:52)
That's really crazy. I mean, I guess it totally makes sense that the law enforcement agencies have to work with the private telecom providers, but I hadn't actually thought about, like, that's someone's job. And to work on that and make sure it's implemented properly and everything. And so that's what you were doing? Your job was mainly focused on interfacing with law enforcement, doing the wiretaps and—
(Jaya at 00:08:19)
Yes, this particular job at Verizon was much more in consultancy and professional services and trying to do more security architecture work. And I was also doing identity work, et cetera. But that was kind of the capability set that I came with for doing secure architecture. And I had done that in other jobs before. Actually, you know, helped build lawful interception environments.
(Joel Beasley at 00:08:41)
That's really cool. So how did you meet the team at Avast and decide to join there?
(Jaya at 00:08:48)
Honestly, I had Avast running on my kids' computers. So when, you know, at parties you always get asked, "Okay, so what should I use for blah blah blah? What should I use for this?" So if people ever ask me, "What should I use?"—people who really aren't, you know, able to afford necessarily the top-end enterprise products, and they just wanna be safe at home or for their church or for their whatever. They wanna be safe when they go online. I used to recommend AVG Avast because, well, it's a freemium product. And if you're okay with the alerts and the reminders and "Hey, maybe you should switch to this" kind of thing—if you're okay with that kind of stuff—then yeah. The cool thing about Avast and AVG is that the layer of protection that you get—and by the way, this is not an infomercial, I'm just telling you why I used to recommend it, and that's still the case—the layer of security protection you get is the same as some paid product. It just comes for free in the free product. I love this. I love this idea that everybody has access to good security. And this is why I put it on my kids' laptops. Otherwise, I never would have done that. So when someone approached me about, "Hey, there's a CISO job available at Avast," and I've worked at KPN for seven years—you know, there's just kind of rule of thumb that I've followed, which is the minimum place time that you ever stay at any one place is two years. The best average time is around four to five, but usually not longer than seven. So that's pretty much been my ethos through my entire career, is kind of minimum of two, but kind of maximum around seven. And that's a long time. And I had done that seven-year stint at KPN, and I thought, "Okay, well, I can do this job." You know, there's always gonna be new challenges, but I can do this job pretty well. I know what I've done, and I had to build something up from scratch, and it's there now. So I really needed something else. So I was actively looking, and this came by, and I thought, "Oh, this is great because it's a brand I know, and it's something that I thought huge potential for doing cooler things because they have a lot of different people that they protect." So the opportunity to be able to protect all those people meant something to me. It still does. You know, I quite like this idea of having an impact to improve stuff for other folks, and the possibility to do that for 500 million people is awesome.
(Joel Beasley at 00:11:08)
As CISO of Avast—so, you're CISO of a cybersecurity company—is there extra pressure on the CISO role, given that it's a security company?
(Jaya at 00:11:20)
Yeah. And the thing is, you know, you would assume that—this is what I had assumed incorrectly very early on—that, "Okay, well, it's security for a security company, so probably they have everything already. And probably I don't need to convince anyone of anything." So they're probably all gonna be like, "Oh yeah, sure. You wanna do that? Or you wanna limit the—you wanna limit the permissions here and then do that? Oh, sure. Go for it." You know? I just assumed that it'd be a lot easier to convince people to do the stuff that I wanted them to do. It's not so much easier. No.
(Joel Beasley at 00:11:57)
Yeah. I mean, that's—we've had a couple CISOs on the show during my time here, and that's always been a big chunk of the interview, is how do you get buy-in from the other executives at the company to do security? And the answer that I've gotten has always been vaguely around using security to enable the business rather than to throttle the business and trying to present it in a way that you're adding value rather than just putting up costs or slowing things down with more security measures. And so—
(Jaya at 00:12:37)
So I don't lie about that stuff. So I actually think that the best way to take the bitter pill is to do it straight up because sometimes you are gonna throttle and you are gonna slow down. And if my pen test has results that says that, you know, "You can't go live with the product unless you fix all this stuff," and for you to fix all this stuff it means a two-week delay or your time-to-market thing is—then, yeah, that's a delay. But you are gonna have to fix it because this is what we agreed in advance. And so there is gonna be that. But then I always think, what do you have to do that's better than this? If you work—if you work at a security company and we are tasked with making sure that our products and services are secure for that end user or for this intrinsic entity that is holding all this customer data—tell me what you've got to do that's more important than this. You know? And then we can have an honest discussion because there is gonna be a delay. There is gonna be a little bit of throttling. Ultimately, we're all doing it for the same reason. Everybody showed up to work today to do the best job they possibly can with the best interest of the company at hand. So it's not a thing of someone has a bigger stake in the game. We all have the same skin in the game. But I do think that when it comes to priorities, it's pretty clear, for me anyway, that we gotta do the security thing right, period.
(Joel Beasley at 00:13:57)
Yeah. I mean, that makes sense. You gotta lead by example if you're selling security. But one thing I'm really interested to hear from you about is I know that right around when you were starting as CISO, there was the—is it Abiss attack? Is that how you—
(Jaya at 00:14:15)
Yeah.
(Joel Beasley at 00:14:15)
Yeah. So can you tell me a little bit about the Abiss attack? How did you detect them? What were they after? What was going on?
(Jaya at 00:14:24)
So the week before I started Avast—and it was literally the week before—I had a call from some of my new colleagues, and they told me they had seen something that was concerning. And they wanted to call an external forensics firm. And so first, I thought this was an overreaction. So I called them back and said, "Well, we're not calling anyone. I first wanna understand what the heck we're dealing with before we overreact." And then we had a good long chat, and it was clear, definitely needed to call. So we moved forward with calling, and then, you know, I started, and it was pretty much diving head first into the new job because of the attack. And we worked with internal teams, external teams, with agencies that supported us—intelligence agencies and law enforcement, multiple of those—in order to really assess what the heck happened. And it was really clear we had a state-sponsored attacker who was after, not necessarily us, but definitely our customers. And in order to get to them, wanted probably to steal our code signing keys to then push code out as us because of that very awesome user base. And we observed the attacker go through the network and made a choice to let the attack continue to understand the extent of which the compromise was actually happening. It's a pretty crazy step initially, but I think it's—I still think it's the right thing to do. Otherwise, you're just shutting stuff off. You cut yourself off and you have no idea about how far they've gotten. So this was, yeah, in that—I think we stopped the actual acting on objectives, and I think the objective was those codes. I think we stopped that in time. We had another bit of collateral damage, but that was stuff that we could remediate, thankfully. Knock on wood. And then we informed the security community first.
(Jaya at 00:16:20) So folks like us who would also have a similar threat vector, we told them first to make sure that they could all fix their stuff, and then we went public. And I wrote a blog for the Avast website with the help of our communications team. And we were as open and transparent as possible as we could to everyone. At the time of this attack, we had no evidence of any kind of customer compromise. So their actual ability to do what they came to do could not be affected through us because they weren't able to push that code out.
(Jaya at 00:16:51) And we really, you know, we don't do attribution, but the agencies that we worked with were fairly confident that the attribution was at the doorstep of China.
(Joel Beasley at 00:17:03) That's insane. So is that kind of standard practice to, if the attacker isn't actually achieving their goal yet, leave them in the system to see so that you do have that visibility and can track them as they're moving around?
(Jaya at 00:17:19) That is not standard. And I would say that every situation is different, and it depends on how good your visibility is on your network. So what you can actually see. Because frankly, every network I've ever gone to, there is always stuff that's missing. You know, the first and foremost thing, the biggest thing that we always tell everyone to do is know thyself.
(Jaya at 00:17:40) So understand your own network, understand your own threats, understand your own data flows. So it goes back to Bruce Schneier saying, you know, know what you have to protect against whom. And this is the most foundational thing that is always missing in every company I've seen. Properly understanding regular operations, crown jewels, you know, knowing where everything is, knowing how stuff interconnects to each other, also potentially third parties, and then trying to figure out what could possibly go wrong. And then having a proper enumeration of those threats and saying, alright, well, if this and this and this goes wrong, I've got this and this to protect me or I don't because whatever. And that overview is usually not present. And I don't think Avast was any different initially, and this is exactly what we've been trying to make better all this time. And it's really kind of a much more diligent, proactive, more strategic view on what you're doing instead of just, like, amoeba, you know, stimuli response kind of behavior.
(Joel Beasley at 00:18:41) Right. Yeah. I mean, if you're being reactive, then the attacker is always a step ahead.
(Jaya at 00:18:48) They're a step ahead even when you're proactive. It's just about, you know. Yeah. It is. I mean, to be honest, the benefit of being reactive is you're highly adaptive in that mode, you know? And sometimes if you're too proactive and unable to be reactive, that's also not so great because then you're inflexible to adapt to new threats. So there is a balance here. It's not about being all gung ho one way or the other. It's really hard to get wrong and very difficult to get it just Goldilocks right.
(Joel Beasley at 00:19:18) So after, since the attack, what have been some procedures that you've implemented or changes you've made to prevent it from happening again?
(Jaya at 00:19:29) So I don't know that you can ever completely prevent every single kind of attack. I mean, maybe you could if you had unlimited budgets and tons of, you know, wonderful personnel. But I think you're always making bets. It's a gamble. And what you're trying to figure out is, how do I increase the difficulty and the cost of every single attack that is possible?
(Jaya at 00:19:50) Because there's always going to be a possible vector of attack just because, you know, do you know the XKCD comic? It was totally, like, brilliantly in use this past December when we had Log4Shell, where you have all of our modern infrastructure and it's on this sort of Lego blocky structure of dependency of one piece of code maintained by some random guy in Ohio who's unpaid to maintain it. Do you know this XKCD?
(Joel Beasley at 00:20:18) I'm not familiar. No.
(Jaya at 00:20:19) Okay. I'll show it to you after the podcast. But the point is, it's a brilliant comic, which illustrates our foundational interdependency for everything we run on a lot of open source libraries that we know absolutely nothing about. So it's a crucial piece of the entire puzzle. But again, it's maintained by some random guy for free on a best effort basis.
(Jaya at 00:20:42) And everyone on the planet uses it. That's what happened this December with Log4j. And I genuinely believe that our ability to protect only goes so far as our ability to truly understand all of those dependencies. So right now, we don't have such a great view.
(Joel Beasley at 00:21:00) Well, so looking forward into the future, what are some things that could be really good for security or and some things that could be really scary? Specifically, I've been, we've had a couple people in the crypto space on the show and we've also had a couple people in the quantum space on the show in the past. And I know that there's a lot of talk about how quantum computers could possibly break the blockchain and—
(Jaya at 00:21:31) Oh, that, like, all encryptions. Crypto.
(Joel Beasley at 00:21:34) Oh, no. Yeah. Yeah. Like, currencies. Yeah.
(Jaya at 00:21:36) Currencies. Yeah. So first of all, I got to tell you that every time I hear crypto, it's just maybe again my age, but I always think cryptography. Yeah. So anyway, the reason that quantum computers will have an impact on cryptography as well as things like the blockchain is really because a lot of the mechanisms, the mathematical problems that we based our current cryptography on, they are reversible with a quantum computer.
(Jaya at 00:22:04) So you imagine that pretty much everything we use to encrypt secure transactions like those between your bank or those between you and your favorite web shop, that all of that cryptography has very hard math problems baked in. The very hardness of the math problem is the thing that makes them secure because they are using something called one-way functions, which means they are easy to do in one way and difficult to reverse in the other. So these one-way functions, they are solvable but with a lot of time and effort baked in. However, with a quantum computer, we can drastically reduce the time and effort, and that's the whole deal. So it's not that, you know, we're solving the unsolvable.
(Jaya at 00:22:53) No. They are solvable, except initially, they were solvable with the lifetime of the universe. And now with a quantum computer, they'll be solvable potentially within a couple of minutes or seconds. That's scary.
(Joel Beasley at 00:23:05) We had on the CTO of Ripple who kind of dismissed quantum as a threat because he was like, ah, we got this quantum-resistant algorithms that are slower right now, but those will probably get faster when they need to. So quantum-resistant algorithms, I assume, just use a different type of hard-to-solve math problems that quantum computers aren't necessarily as good at solving.
(Jaya at 00:23:34) That's right.
(Joel Beasley at 00:23:35) Are quantum-resistant algorithms viable today? Or if not, what do you think is the time horizon on them being viable for practical use?
(Jaya at 00:23:47) So let me be clear. We already have quantum-resistant algorithms. We have McEliece, which has been around since 1976. Oh, wow. But yeah.
(Jaya at 00:23:55) But there is a cost. There's a computation cost to running such an algorithm. So it's about making these algorithms efficient to use in a smartphone. You know? It's about making them efficient to use across all of the places across the Internet where we actually currently deploy cryptography.
(Jaya at 00:24:14) And the fact of the matter is you probably will have a higher likelihood of adoption of these quantum-resistant algorithms than you will of other potential solutions to deal with the quantum threat, which are things like having, you know, secure quantum communications at a transmission fiber optic link. Those are hard to set up across the whole Internet. And this whole idea about ready in time, in time for what? You know, this is not true. So the whole problem right now with a lot of our secrets is the fact that if they've already been captured and are waiting to be decrypted by a scalable enough quantum computing architecture, then maybe we've already got a problem right now.
(Jaya at 00:24:57) And I'm again, I'm not referring specifically to coins, but more to secrets. So all of the encrypted communication we have running all over the Internet, if it's just being captured somewhere, storing it, and then decrypting it later, it could still be a problem. So this whole timing issue is quite finagly. We could discuss this till the, yeah. Because I don't think that we have a lot of time to waste.
(Jaya at 00:25:25) I think we need to actually already think now about implementing some of these quantum-resistant algorithms, and we should already be embedding them into every place where we have current standard cryptography, which we know will eventually be at risk. There's other things we can do now with the current crypto we use, which is, for example, like I told you, you know, it's about making an attack more costly and more difficult. That's the initial thing. So we can also do that here. We can just increase our key length of every bit of cryptography we already know we use.
(Jaya at 00:25:58) That's the first thing we can all do. And then the next thing we can do is look for things, places, opportunity areas where we can do this transmission layer, either quantum key distribution or quantum secure communication on the transmission layer on the secure links. And again, this is not scalable across the entire Internet. We're going to change all the infrastructure, although maybe that will be something we do in the future with a quantum Internet. We might actually do that.
(Jaya at 00:26:27) I just think that we need to buy ourselves some time in order to do that kind of technical revolution because we will need to do that. And then finally, post-quantum crypto is really the thing that is the most scalable across all of this distributed architecture, but will also take some time. And if you listen to some of the physicists, they'll tell you that it still doesn't always, you know, what's the word? Pass the NP hardness test in order for it to be really considered secure enough to be provably secure and resistant to a quantum attack. So that whole question is a continuous disagreement between physicists and cryptographers.
(Jaya at 00:27:07) And for practitioners who are very often caught just in the middle, like, what do I do? Let's be pragmatic. I think the biggest thing is to start now. Understand what you use. Understand how you're going to do this transition.
(Jaya at 00:27:21) And then already assume that stuff is going to break. Because, like, let's be honest. Every time we try to implement anything new, stuff breaks. And it's usually because we screwed up the implementation. There's this beautiful protocol, which we then when we tried to build the actual thing, we broke it.
(Jaya at 00:27:39) We broke the protocol because, oops, there's a side channel attack because I didn't mean to do that, but I did. You know? And so we need to get smarter about, the balance between proactive and reactive. We need to have a good set of ideas going forward. But if they wound up to be broken, for whatever reason, we need to be super agile to shift to some other cryptographic standard.
(Jaya at 00:28:05) So having this flexibility in mind when we think about our future planning is really important.
(Joel Beasley at 00:28:12) And, yeah, there's also the issue of whenever you create anything on a small scale or like in a lab, there's going to be phenomenon that show up that you can only observe at scale. So problems are going to arise that you couldn't have foreseen when you deploy at scale. And yeah, like you said, just have to be reactive at that point. But another thing I wanted to ask you about was, since we just had your colleague at Avast, Charles Walton, on talking about how Avast is moving into digital identity in the next year or couple years. And I'm just curious, like, are you at all involved in the identity stuff that's happening at Avast? Because I imagine that has to be highly, highly secure.
(Jaya at 00:29:06) Yes. I think, you know, we already have quite a target painted on our back in the sense of being able to protect all these folks. So it's an awesome responsibility. But I think that identity will make that target even more highlighted because look at what you have to do. It is the foundation for any kind of trust relationship you have online.
(Jaya at 00:29:26) It all starts with identity. It's able to verify in a mutual way who you are against the service you're trying to access. So trying to turn yourself into an identity provider means a whole new host of risks and precautions you'd need to take as a provider of these kinds of services.
(Joel Beasley at 00:29:45) So what are some of the biggest challenges from a security perspective of developing identity services?
(Jaya at 00:29:54) So I think there's quite a few things, actually. Like, let's start from the basis of if you have to provide identities, you know, you have this idea of the storage of the initial identity and the identity relationships you'd need to kind of keep intact. There's always some point where you need to have some derivation back to the identity or if you're like an intermediary identity party, the identities that you'd need to kind of capture and forward or the repudiation you need to capture and forward. Either way, either a positive affirmation or repudiation, you know, you'd need to have transactions that you then collect that would essentially allow access or not. So I think this already the potential for misuse of this is already something that I'm worried about.
(Jaya at 00:30:39) But then also, like, all of the potentially privacy-related information that you'd need to hold and not just the transaction succession because you could probably do that pretty well with some sort of fully homomorphic encrypted system. You could probably. But I'd still think that there's a differential privacy challenge with the user identification and then processing that and being able to do things like risk scoring. You'd have to have multiple identity attributes collected for that. And again, I'm hypothesizing here because I haven't seen our service.
(Jaya at 00:31:13) No one has. This is an area that we want to enter with all these cool things, but I've yet to pen test a whole service of here's our product, and this is what we're doing. So bam, bam, bam. And then we know all the weak points, and we know how to make them better. We haven't gotten there yet.
(Jaya at 00:31:29) We want to do it, you know, but it's really at the conception phase. So it's the starting point. What Charlie is doing is building. So we're helping now with getting the requirements for how to build securely. Yeah.
(Jaya at 00:31:40) That's really where we're at.
(Joel Beasley at 00:31:42) So looking forward into the future, like, I know right now the biggest thing that people, that individuals can do for their security is multifactor authentication. Alright. Well, I want to hear what else is good for individuals to do.
(Jaya at 00:32:05) We mean regular humans. Right? Yes. Okay.
(Joel Beasley at 00:32:08) Yeah.
(Jaya at 00:32:08) I think it's kind of, to be very honest, it's so simple because I hear this all the time. The most vulnerable amongst us are the ones that have old devices that they don't know how to update, and they don't do the basic stuff. You know, they don't have an antivirus. They don't have any kind of VPN use. They don't, you know, they've got an Android phone or iPhone.
(Jaya at 00:32:32) It's got, like, 10,000 "update me's," and none of them have been done. And they're just leaving in the background. There's no auto-update turned on. You know? So kind of I would always say the first things first is just keep your stuff up to date.
(Jaya at 00:32:46) Just keep your stuff up to date. And it sounds so trivial, but it's actually not. I've also seen the consumer space. Everybody is incredibly, you know, there's a lot of consumption of all different types of devices, and we love having IoT of everything, blenders, toasters, you name it. We'll hang it on the Internet.
(Jaya at 00:33:07) But we rarely think about update mechanisms. We rarely think about how they're connected to other devices in the home. You know, we just hook them up and let's go. And in terms of personal devices, you know, what are they saying about us? Like, I'm sure you've heard about the Strava analysis from the Fitbit.
(Jaya at 00:33:25) So I thought that was brilliant, you know, the researcher in Australia who finds out how much information you can get by analyzing outliers on Strava data. And he finds, like, extraordinary rendition bases in Somalia by looking for, "This is weird. There's a whole bunch of users jogging across a beach in Somalia. Why is that?" And then he figures out this is a U.S. Marine base or Special Forces base or whatever it is.
(Jaya at 00:33:51) And, you know, I think that we forget the power of that kind of data analysis. We put all of our data in all these different gigantic haystacks, and if there's someone that's able to look at it carefully enough, they can find out all kinds of stuff about it. So I think it starts, first and foremost, with making sure we have all of our updates. And there is an inherent caveat emptor, you know, buyer beware, for all of this stuff all across the board.
(Jaya at 00:34:18) But if we can do all of our updates and we can upgrade our stuff when we need to so they're not using devices from the Stone Age, I think we're already in pretty good shape, just that. And then, of course, it's deploying from all of the platforms we use the security features that are inherent to the platform. And one of those things is indeed multifactor authentication or two-factor authentication when it's available from Google, Facebook, Instagram, whatever. Just turning it on. And most folks don't even do that.
(Joel Beasley at 00:34:45) But so where I was going to go with the multifactor authentication is that most people don't do it because it slows them down, and it's a slight inconvenience.
(Jaya at 00:34:57) Yeah. Yeah. That's the dream. The dream is frictionless security and frictionless, yeah. Yeah.
(Jaya at 00:35:04) But, like, even now with privacy, right? How do you ever go to a website? Well, I live in Europe, so I cannot visit a website without being barraged by cookie screens where I have to first, you know, turn everything off and then the legitimate interest off and blah blah blah, then proceed.
(Jaya at 00:35:17) But everyone, all of my girlfriends who see me do this, they think I'm mad. They're like, "Oh, why do you do that? What?" And so I tell them why I do that, and they're like, "Oh, I guess I should do that too." But they don't.
(Jaya at 00:35:29) It shouldn't have to be so hard to get our security and privacy, but it is. It's made difficult. So I think that for now, it's updates, upgrades, using the services that are available that provide different types of better authentication, but also thinking about using a good VPN and a good AV and really trying to hone in on having some basic stuff, really basic hygiene stuff that takes care of all of those advanced threats, because that's exactly what happens.
(Joel Beasley at 00:35:58) So I guess just to start, what is, like, a piece of advice that you got early in your career that was super helpful, or something that you wish someone told you early in your career?
(Jaya at 00:36:12) Yeah. So I think the best piece of advice that I got was to kind of keep consuming training and to just never have this idea that you were, for whatever reason, trained out. I had a manager that was super hungry and kept doing that, and I thought that was really good advice. I also think that that's what is a sort of USP, as long as you can hold on to that kind of foundational basic of being able to learn and being able to admit that there's stuff you don't know that you need to know, so you need to learn.
(Jaya at 00:36:46) I think that's really a good starting point. And what I wish I had figured out or been told is probably not to underestimate myself. I think the biggest person who thinks, "Oh, I can't do that. Oh, no. No. I shouldn't even try for that because I'll never get that." That's always you. And I think if we don't place those bars up on our own abilities, then other people won't either. But it begins with you. So I wish I had driven a little bit harder and been more vocal and just kind of dared and jumped more.
(Joel Beasley at 00:37:22) So how do you encourage, like, the next generation of leaders or the people at your company, your direct reports, to be daring and take those risks?
(Jaya at 00:37:33) I have to be honest, I'm still trying to do it myself, so it's one of the news learning things too. But I have a couple of mentees, and yeah, also my direct reports. I think it's just about trusting them. I'm not a really big fan of management layers. I really like flat structures with little hierarchy, or as little hierarchy as possible, while still being very sensitive to giving everyone individual attention. So there's a balance there as well, because, you know, you make it too flat and no one, you don't have time for anyone, which is also not really in their best interest. So you need to have a little bit so that people know where to go. But I really trust my people.
(Jaya at 00:38:13) I trust them, and I give them lots of space to tell me what we need to be doing. And I think that is probably the biggest thing that they can afford to their colleagues. I think everyone has something to teach each other. So you just need to be able to give them the room to do it, you know, to show someone else what you're really good at or what you're really passionate about or what you just learned. We just need to give ourselves the space to explore that talent.
(Joel Beasley at 00:38:39) You mentioned that you have a couple of mentees. Is that, like, a formalized program, a mentorship program?
(Jaya at 00:38:46) There is a formalized program at Avast, but these were also just people who emailed me and said, "Can you please?" You know, because I think officially we're supposed to have one or two mentees, and I have, like, six. So, yeah, these are just people that are like, "Oh, please." And so I asked my secretary and she just organizes once a month regular calls with them, and then we chat about everything.
(Joel Beasley at 00:39:08) That's awesome. Yeah. I was just curious because I hear a lot of executives talk about, like, mentees and mentorship. But, like, personally in my career, I've certainly had some mentors, but it was never, like, a formal thing where I was like, "You are..." We never, like, admitted it, I guess. Like, "You are my mentor. You are mentoring me." It's just like a professor I kept in touch with and asked for advice and...
(Jaya at 00:39:38) Yeah. Yeah. That's wonderful. And that's actually how it should be. Unfortunately, because of other priorities, work priorities, we don't make time for it. So what I think is good about formal mentor programs is that it forces you to have a structure, put it in your agenda, and make time for it and prioritize. I mean, that's it. That's all you really need is you need to take time and prioritize. And so I think that's the benefit. And I, again, like my assistant, I have to actually ask her because it's really good you're saying this. I have to ask her because I haven't seen who's on, but it used to be that every week I would have someone else. So we just go week by week, you know? And so then I have someone else, and then we just run through it. And, yeah.
(Joel Beasley at 00:40:20) That's really cool.
(Jaya at 00:40:21) Yeah.
(Joel Beasley at 00:40:22) So before we wrap up, is there anything that we didn't get to touch on or any extra shout-out you want to make at the end of the interview here?
(Jaya at 00:40:30) You know, I think the most important thing that we need to do today is to try to find our inspiration and what it is that we want to achieve, because I get, I don't know about you, but I get sometimes overdosed with Twitter. And I get a little bit depressed about some of the stuff that we see. So I try to find the bright side. I still get inspired by, you know, everything happening at SpaceX and Tesla. And it's still super cool to think about all of the advancements that we could be making, from everything from biotech to artificial intelligence.
(Jaya at 00:41:08) I mean, there's just so much cool stuff to be able to work on and make even a little bit better that I just hope that everybody takes the time to think about where we could be using our creative energy better, because we tend to use a lot of energy, a lot of mental and emotional energy, on the super negative stuff. But I think we need to find more of the positive stuff. And also, like, working on things that truly matter, like the environment and climate. I think we all need to find a way to prioritize that and make sure that we just create a future for ourselves that we want to have.
(Joel Beasley at 00:41:45) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.