Episode 463 ·

From FBI Raids to CTO with Marc Maiffret, CTO of BeyondTrust

Today we’re talking to Marc Maiffret, CTO of BeyondTrust; and we discuss how Marc’s career in cybersecurity started after getting raided by the FBI, Marc’s co-discovery of the infamous Microsoft vulnerability Code Red, and how the culture of a company has to change fundamentally in order to make meaningful changes to security. 

All of this right here, right now, on the ModernCTO Podcast! 

Check out BeyondTrust at https://www.beyondtrust.com

About Marc Maiffret:

Marc Maiffret is a well-known entrepreneur and executive with over 20 years of experience in security leadership at organizations such as eEye Digital Security, FireEye, SpaceX, and BeyondTrust. Marc founded his first company shortly after being raided by the FBI at the age of 17. As a security researcher Marc was an early pioneer in Microsoft vulnerability research, including co-discovering and naming Code Red, the first Microsoft computer worm. Marc has presented at numerous security conferences and has testified before Congress on matters of national security. As an entrepreneur, Marc helped design and build some of the first products for Vulnerability Management, Web Application Firewalling, Endpoint Security, and Malware Detonation. Marc has written for numerous publications and is regularly sought after by media organizations to break down complex security topics.

About BeyondTrust:

BeyondTrust is the worldwide leader in Privileged Access Management (PAM), empowering organizations to secure and manage their entire universe of privileges. Our integrated products and platform offer the industry's most advanced PAM solution, enabling organizations to quickly shrink their attack surface across traditional, cloud and hybrid environments.

The BeyondTrust Universal Privilege Management approach secures and protects privileges across passwords, endpoints, and access, giving organizations the visibility and control they need to reduce risk, achieve compliance, and boost operational performance. We are trusted by 20,000 customers, including 78 of the Fortune 100, and a global partner network.

Transcript

(Intro Narrator at 00:00:03) Hello, my friends. Today, Joel is talking to Marc, CTO of BeyondTrust, and they discuss how Marc's career in cybersecurity started after he got raided by the FBI, Marc's co-discovery of the infamous Microsoft vulnerability Code Red, and how the culture of the company has to fundamentally change in order to make meaningful changes to security. Podcast.

(Joel Beasley at 00:00:35) Here we go. This is the Modern CTO podcast. So do you see yourself as more of an entrepreneur or a technologist? How do you sort of view yourself?

(Marc at 00:00:54) It depends on the day. I mean, probably both in a sense, right? I mean, I kind of oscillate between, you know, everything from hacking around on code and getting in the weeds on things to, you know, doing the kind of chief technology officer business role and everything in between. So I think definitely the moniker a friend gave me when I was very young, he coined the term chief hacking officer. So I think that's pretty representative.

(Joel Beasley at 00:01:23) Have you been hacking a while?

(Marc at 00:01:25) Yeah. I mean, since I was about 13.

(Joel Beasley at 00:01:29) How'd you get into that?

(Marc at 00:01:31) For me, it was really just kind of an escape from a crazy home life and a crazy upbringing. And so getting my first computer and kind of access to it, it was just this entire world of learning to program, learning how things work. I mean, there was definitely that aspect where you had control over it, right? So I think anybody who's kind of grown up as a child in a chaotic household, if you will, you know, it turns into something where having your escape—sometimes the escapes end up being bad ones that are detrimental. Luckily, mine was nerding out with computers and getting into hacking and things of that nature. So it was a world I could kind of control in the sense that I could control that virtual space in a way that, you know, the real world was uncontrollable for me at that point.

(Joel Beasley at 00:02:18) Yeah. I connected with that a lot. So, like, around age 11, 12, my parents got divorced. And it was more so they were just focusing on other things. So I had a ridiculous amount of free time. I was self-governing. I was completely autonomous, and that's not what you see for most 13-year-olds, right? And so I look back on it now. I'm 34 now and I have two kids and a third on the way, and I look back at it and I say, man, I was so lucky that, like, some of the worst stuff I was doing was just, like, you know, things on the computer. And I wasn't out there, like, smoking meth and, like, all this other stuff.

(Marc at 00:02:55) No. It's like you're saying at the start, that kind of overcoming things. I mean, it definitely can make you stronger. But, you know, I consider myself kind of lucky in a lot of ways, right? Because I think it also, this planet people end up broken and you might not ever get out of it, right? So I was lucky that, like, my escape and kind of addiction, if you will, was, you know, computers and hacking and learning about that sort of thing versus, sure, it could have gone a lot of other ways for me.

(Joel Beasley at 00:03:24) Yeah. I remember one day I went to Best Buy, and then I went to, like, Books-A-Million, and I found this book my dad let me buy, and it was called Hack This Site. It was a book about Hack This Site. And I went home, and I started playing around with it. And I, you know, performed a couple of the hacks, went through, like, the courses. And then almost immediately, I figured out that I could make money, like, writing code on ScriptLance. And then my focus completely shifted and I barely had, like, maybe six months of my life where I spent it interested in the security and the hacking before I realized that businesses would pay me money to write business logic code. And I was like, I'll go do that.

(Marc at 00:04:02) Yeah. No, it's an interesting thing. I think everybody's got the, like, what was that first book or exposure? And I don't remember what store we're at. We were at some sort of a used computer store, and I think I was, like, 12 or something like that. And the only programming book that they had was a language that's not very popular anymore called Visual Basic. And so that was, like, the first thing I got exposed to, was not, like, the prime language that I would have wanted, you know, to be learning at the time and stuff like that as far as the kind of value to using it in the kind of hacking space and security and stuff like that. But it was definitely a fun exposure and jumping-off point just to learn programming in general. My friends will tease me, of course, on Visual Basic being the first language, so it's out there now.

(Joel Beasley at 00:04:49) Yeah. I think it was Visual Basic Studio was the, like, IDE for that, right?

(Marc at 00:04:53) There you go. Yeah. Yeah. Drawing all your interfaces first and then figure out what's the code actually gonna do, versus pretty much everything doesn't work that way anymore.

(Joel Beasley at 00:05:03) Yeah. The closest thing I found to that was when I got into a little bit of the Apple development. That's how they do a lot of their interface work, right?

(Marc at 00:05:11) Right.

(Joel Beasley at 00:05:11) Yeah.

(Marc at 00:05:12) I still prefer it as a thing. Get the, as real as possible, you know, UX, UI prototype, so you kind of get that full experience and then fill in the blanks. I don't know if that's just a preference or, you know, been poisoned by Visual Basic early on.

(Joel Beasley at 00:05:30) I think it's because it's the way you develop the best products. Like, that's what I have found to be true. Yeah. So how did you go from, you know, hacking, raided by the FBI? How did you not go to jail, and how did you end up making a career out of it?

(Marc at 00:05:44) It's funny you asked that. A lot of people don't ask the, like, you were raided. Did you get in trouble or go to jail or any of that? Yeah. So at the point that I was raided, I'd been hacking all sorts of, you know, companies, government sites, you know, things of that nature. And different—you know, I should clarify—different than a lot of things you hear about hacking today where it's like ransomware, cybercrime kind of driven. You know, this is hacking at a time when it was much more about the ability to just go explore systems and the way that you would go learn about new computer environments and things of that nature would be to go break into the companies that had those sort of computer systems because you couldn't—all the magical stuff you can do these days of setting up your own home hacking lab just wasn't quite a thing, right? So your lab was other companies, universities, stuff like that. And so that hacking eventually caught up with me. But, yeah, I was never actually charged or, you know, arrested or, no record or anything of that nature. The wake-up call was very real, though, I'd say, as far as, you know, what do I do at that point? I was definitely scared enough into doing the right things, and I think I'd been trying to find the path of how do I take this, like, passion that I had? I was writing a lot of, like, security hacking tools at the time. And, you know, I very much knew as best as a 17-year-old could know what they want to do with a career. I knew I wanted to do something in my life with that. But this was at a time that the security industry was kind of more in its infancy, right? There was a couple of big, you know, consumer antivirus companies, but the modern security market that we kind of know today really didn't exist. So there wasn't as clear a path as there would be right now.

(Joel Beasley at 00:07:22) And did you have an influence in your life that was entrepreneurial that caused you to not just go work for another security company, but actually start eEye, I think, was your first company?

(Marc at 00:07:32) Yeah. Yeah. So it was an interesting path when I—at the time that I got raided, I was working for a kind of a website development type of firm, and the founder of it, Firas Bushnaq, friend of mine, he—I basically told him, you know, hey. I got raided by the FBI. Didn't end up spooking him. And so I told him, hey. I have all these ideas of, like, you know, security technology and stuff that I actually, you know, want to try to productize, basically. And that was kind of the initial seed, and we started the first company together, eEye Digital Security. And, really, the first product that we built was to take all the different kind of automated hacking tools that I had been building and turn that into what, you know, we now call vulnerability management, where you can essentially scan a company's environment, figure out all the weaknesses and ways that a hacker could break in and how to fix those things.

(Joel Beasley at 00:08:26) Oh, nice. Is that when you got involved with the whole Code Red Microsoft thing?

(Marc at 00:08:30) Yeah. Yeah. So in parallel to, you know, building a lot of security tools and starting my first company, eEye, I was also heavily involved in some of the early Microsoft security research. So in the kind of, like, late nineties, early 2000 time frame, helped, you know, pioneer a lot of the kind of early vulnerabilities of Microsoft software. And so in doing that, we were also trying to figure out, you know, software that could be defensive and trying to, you know, prevent attacks against Microsoft systems. And throughout that work, we eventually found the essentially the first Microsoft computer worm called Code Red, which is an interesting story in itself.

(Joel Beasley at 00:09:08) Yeah. We were doing the prep meeting, and I made a joke. I was like, oh, yeah. He's sponsored by Mountain Dew. And then Adam stood up and he's like, hey. There's actually something there. Ask him about it. So I wasn't sure.

(Marc at 00:09:19) No. That's a true thing. So the start of Code Red was essentially it was a Friday afternoon, and I was hanging out with a good friend of mine, Ryan Permeh, who went on to go co-found a company called Cylance. And we got an email from a customer that was seeing something kind of weird happening with their web server. We started to do some kind of research and started to unravel and figure out that there was this, you know, worm code that existed. But that's probably, like, less interesting than the, like, jump to two days later on the Monday morning we were putting out our research. We got a call from somebody who claimed to be in the Situation Room in the White House. And the worm itself was supposed to eventually flood and kind of attack one of the White House web servers. And so we thought it was probably a crank call or something and called a friend at the FBI to find out, you know, it was actually somebody at the White House that was trying to figure out what was going on. And so that jumped to a couple days after that. It's all over the news. There hadn't been this sort of worm for Microsoft, you know, up until that point. And so I got a call from the head of marketing for Pepsi, which was making Code Red Mountain Dew at the time. And it was supposed to just be a soft drink that was, like, out for a limited offering. But I guess because of the worm and all the press surrounding it, like, I don't know. A lot of IT people or whatever were buying Code Red. And so we got this awkward call from, like, the head of marketing saying, hey. It's weird to be associated with something bad, but, like, you know, pretty cool what you guys found. And, like, we just want to send you, you know, free Mountain Dew, basically. And so the distribution plant down by our old office, just up until we finally told them after, you know, probably, like, a year or two, we're so sick of getting shipments of Code Red and stuff like that. We were, like, stop sending it. So that's always the fun joke at conferences when people try to hand me a bottle of that. I'm not quite the fan as I was back then.

(Joel Beasley at 00:11:15) Man, I have been drinking way too much Code Red and Surge. And I think people underestimate how popular those drinks were. They were, like, incredibly popular.

(Marc at 00:11:24) Absolutely. Absolutely. That was kind of our joke in naming that. We were like, we kind of appreciate this soft drink as a couple of, you know, hacker programmers at the time, and we ended up naming it after it. And it was like a tongue-in-cheek, like, maybe they'll stay around and, you know, very much did. And that's essentially why there's Code Red on shelves still.

(Joel Beasley at 00:11:45) I would have, like, named the second virus, like, Cool Ranch.

(Marc at 00:11:49) Yeah. We were like, why didn't we call it, like, the BMW worm? Or, there you go, something better, you know, something with better sponsorship.

(Joel Beasley at 00:11:58) There you go. Yeah. Just a steady stream of Beamers showing up year after year. That'd be great. Yep. Yeah. So I definitely had a ton of fun in the prep meeting. I do a lot of these, but there was one thing in there, a bullet point in there, that a Microsoft—somebody at Microsoft, like, in the security team—I guess, I'll back up. One of my producers explained it to me like this. They said, Marc's really brilliant at security. He sort of bullied Microsoft into being better at security, and then one of their heads of security called him up and cursed him out. I don't know if we can talk about that.

(Marc at 00:12:30) No. Yeah. I love it. You guys have gone deep. That's fantastic. No, it was—yeah. So totally nice guy, put that disclaimer up front, the person from Microsoft. I won't name them. But, yeah, we had this kind of interesting aspect of that. We were both a security software company. And so at the time that this kind of incident that you're describing happened, from a security vulnerability management software, we had the two largest deployments in the world. So we were deployed across the entire Department of Defense and then across the largest—I won't name the company, but largest commercial deployment. And so we were both trying to navigate as a startup selling software and all the kind of normal business trajectory there, but we were also very active in security research and very passionate about doing something larger than just the products we were selling, right? So we were trying to improve the security of Microsoft. And Microsoft back in that kind of early 2000 time frame very much treated security as more of a marketing problem to be solved for than a technical one. And so there's things that people take for granted today. For example, Patch Tuesday is the, every once a month patch release cycle for Microsoft, and it's changed over the years. But the reason that came about and also this phone call where I got cursed out is we were trying to make it painful enough from a vulnerability research perspective for Microsoft for them to start fundamentally changing how they approach things. And so we had a couple months period where we would find a very critical Microsoft vulnerability. We would report it to them. You know, a few weeks later, they would come out with a patch. We would send them another one. And so we would keep doing that over and over. As soon as they would fix one, we would send another. Obviously, we could have sent them all at once, but what we were trying to do is optimize for constant hits in the headlines of these issues to draw awareness to fundamentally get them to change. And so jumping ahead from that, not just because of us, there was plenty of other security researchers active at the time that were doing their own version of what I'm describing. Bill Gates eventually sent out his trustworthy computing memo to basically refocus the company as security as a number one priority.

(Mark at 00:14:40) But in the process of that, I think it was on one of those fourth iterations of back-to-back vulnerabilities, and they clearly understood we're holding on to these things and using it as kind of a pressure campaign. And so that led to the cursing out. And we also started at the time to publicly list, not the details of the vulnerabilities, but we're one of the first companies to list here's all the vulnerabilities that we've reported to Microsoft that they're working on, so that we could make public, you know, a vulnerability had been sitting there for eight months to get fixed and is unpatched by Microsoft, and essentially draw more awareness to get them to change. And since then, they've changed dramatically and for the better.

(Joel Beasley at 00:15:21) No, that's great. I mean, it was coming either way. If it wasn't you, it's other people.

(Mark at 00:15:25) Yeah. And like I said, in some ways I hate describing it because I don't want to make it sound too much about me and my team at the time, right? Because there were so many other people working hard from a security research perspective to try to make change happen there. And plenty of people within Microsoft themselves that were trying to fight the good fight and change the culture, and eventually it changed.

(Joel Beasley at 00:15:47) Yeah. And so you stayed with the hacking. I would just did a brief detour there. So you've gotten to see the whole evolution of the past twenty years. Like, has hacking changed over time? Is it similar?

(Mark at 00:15:59) Yeah. I mean, I always probably boil down hacking, or kind of the personality of a hacker. Like, I've met everybody from, you know, myself that's a high school dropout, self-taught in everything I do, to somebody who's a PhD, you know, other end of the spectrum as one might think. But the common thread is just the kind of insatiable curiosity, right? Just wanting to understand how things work. And then also that ability to kind of maybe think about systems and try to get them to work in a way that maybe the people that created them didn't intend, right? And that to me is more of the core to hacking, is like that curiosity, not hacking in the sense of the person behind doing cybercrime ransomware. You know, that's the nefarious movie hacker, is not how I would classify. It's more of that curiosity and kind of creator. So yeah, it's definitely changed a lot over the twenty years of going from that exploration culture to just, you know, a major source of revenue in crime and everything else.

(Joel Beasley at 00:17:05) You gotta love that cinematic command line thing that happens. Every, I cringe. Like, the first movie I ever saw got it right or was doing something legitimate was The Facebook, The Social Network movie, where they use the commands. I was like, oh, he's actually typing something. It's not...

(Mark at 00:17:22) Yeah. No. Well, and then you had, you know, you had like Mr. Robot did a great job. They showed that you could show the real thing and it could be compelling and interesting. And, you know, there's a million and one bad versions, of course, of, you know, flying through magical 3D worlds and everything else, that is not quite it. But yeah.

(Joel Beasley at 00:17:42) So you could be doing anything. Super bright. You've been in this industry forever. What are you doing right now? How are you spending your time?

(Mark at 00:17:49) Spend my time at, I'd say two ways. So, you know, you mentioned having kids. I have my daughter, so when I'm not working, I spend the time with her. But yeah, from a professional perspective, I'm the Chief Technology Officer of BeyondTrust. And really, my primary interest is that, as you see the headlines every day coming out about different hacking events, right? There's always different hacker techniques or malware or attack campaigns that exist. But everything's usually centered around having the right level of identities that you've compromised and the right level of access between systems. So I spend a lot of time researching what are those threats, what are those kind of themes, how does that work, and then what can we do from a product perspective to try to fix some of that and give our customers the visibility and control needed.

(Joel Beasley at 00:18:35) Nice. And so how long have you been doing that?

(Mark at 00:18:38) So I'm actually back to BeyondTrust about six months now. So I was previously also CTO at BeyondTrust five-ish years ago. I'm horrible with timelines, so don't quote me on that.

(Joel Beasley at 00:18:50) And so what was that? How did you get involved with them originally?

(Mark at 00:18:54) BeyondTrust actually acquired my first company, eEye Digital Security, years back. So that's how I ended up there originally, and it was, yeah, great team. And I think one of the things in security, right, is that there's a lot of security companies that are always chasing the kind of surface level threats, and there's always something kind of new and different there. But I like to think about a lot of what we try to focus on, and my appeal to the company is that we try to focus on the kind of core physics of, I'd say, probably one of the most important security concepts: limiting and lessening your attack surface, right? Versus, you know, a lot of security threat prevention type of products are much more about, you have this sprawling attack surface, and we're gonna hopefully see the right kind of attacker behavior, versus removing things in the first place that don't need to be there.

(Joel Beasley at 00:19:44) So entrepreneur, I want to talk a little bit about leadership. A large part of our audience is, you know, leaders, people that want to become leaders in technology growing. You've done the difficult thing. You're a leader as a CTO. You've gone through, Elon Musk calls it, you know, staring into the abyss and eating glass, the difficulty of starting a company. What are your thoughts? Like, when you hear the word leadership, I know it's super broad, but what pops into your mind when you hear that?

(Mark at 00:20:10) I think the main thing when I hear leadership is that there's a million and one recipes out there on what the right way to lead is, but it's really about finding yourself, knowing yourself, and your own style of leadership, right? There's not like a set template that works. It really is much more about understanding what works for you. And I think one of the struggles that's common, you know, for folks, I know I certainly deal with it myself and I've dealt with it myself, is trying to transition into leadership type of roles. You know, it could be hard, I think, sometimes for people to make that jump and kind of having that belief in themselves, those first kind of knowing yourself enough. But then there's, you know, maybe the voices in your head, right, that are trying to tell you, you know, maybe you're not capable or you're not deserving in some sense, you know, those things of that nature, that sort of imposter syndrome that I think some people go through. And again, it varies case by case.

(Joel Beasley at 00:21:08) How do you deal with that? I call imposter syndrome, I say it's a synonym for self-doubt. But like, how do you deal with it? Do you listen to, like, Tony Robbins? Do you surround yourself with people? How do you actually deal with it yourself?

(Mark at 00:21:18) That's a good question. I don't think I have kind of one way. I mean, I think having a good network of friends, not just in a way that, you know, your friends just tell you, oh, you're great, you know, everything's good, right? They challenge you when you should be challenged. They say, you know, yes, maybe you did do the wrong thing there when they should say that. So I think definitely having the right peers. And that's always what I kind of talk to people, especially when they're earlier in their career. You know, you definitely want to be paid well and those sort of things, but it's much more about, like, what sort of growth are you having? And it's not just growth in the titles that you're collecting or the kind of ladder climbing in that sense, but the growth in character that you're having and the growth in skills that you're having. And I think the worst thing is if you find yourself in a job where you could be making great money, but you're not actually growing in those sort of ways. To me, that's a death trap that I don't want to find myself in.

(Joel Beasley at 00:22:16) Yes. I have found increasingly as I've gotten older, the people I get to spend my time with have a premium. Like, if I'm on a project and I'm with really, really great people, that to me is more important than money. Obviously, money is incredibly important, and I never want to devalue that.

(Mark at 00:22:35) Yeah, exactly. Because there's equally that where I've had people that I've known where because of maybe some of that self-doubt and stuff, they allow themselves to not maybe speak up and kind of get everything that they deserve, right? So, you know, from a money perspective, it's the given of kind of some level of baseline there, right? But I think revolving around it is a horrible thing to do, not just in business, just in life in general.

(Joel Beasley at 00:23:03) Oh, 100%. It's important, though. I think you sparked an interesting thought. So as you're progressing through your career, you typically start pretty narrow, right? Like, let's say software engineer on a team, become team lead. But as you expand out, your compensation, I would argue, is correlated to your understanding of the business as a whole.

(Mark at 00:23:28) Yeah. No, that's exactly it. I mean, a lot of, you know, you asked me earlier, what's some of my kind of maybe day in the life entail, and it's really being able to translate. I think if I have my core value, it's translating, you know, deeply technical things, hopefully, at a level that others can understand. And I think there's kind of another aspect to that where I got advice earlier in my career after I had left my first company, eEye, for a little bit. And I was debating taking a job as the Chief Security Architect for a company called FireEye. And at the time, I had been mostly focused on vulnerabilities, vulnerability research, vulnerability management, and FireEye was an early stage at the time startup doing kind of malware zero-day threat detection. And I got great advice from somebody I have a ton of respect for named Dan Geer. And I was talking to him about, you know, how do I make this kind of switch between these two worlds? Like, I haven't really done anything with malware. And he was super encouraging in a sense of, like, you know, that's actually a great thing that you haven't done it. He's like, you have the intelligence to think through the problems, and you're gonna bring a totally different mindset. So I think the other thing, career-wise, you know, that you just made me think of it talking about that exposure and learning is, part of the way that you kind of broaden your horizon is just in some of the different roles that you take. And that doesn't have to be dramatic where you, like, start development and you go do something totally like sales, you know, something totally different. But even within development, you know, maybe switching between front end and back end or something just to have a broader perspective so that you can think, you know, for that larger picture as you're eventually getting in the position of leading and trying to steer a ship, if you will.

(Joel Beasley at 00:25:15) You've mentioned a couple people like Dan just now, and I think somebody Freud or, I can't remember his name. Frost.

(Mark at 00:25:21) Yeah. Yeah.

(Joel Beasley at 00:25:21) Frost. Yeah. How have relationships played into your progression in your career, in your life?

(Mark at 00:25:30) Yeah, it's, I mean, it's interesting. Lately, definitely with having kids, relationships are just harder because time is harder. So, but no, I mean, I think the main thing is life's limited. We hopefully have, you know, some level of awesome memories at the end of it, even that's not, you know, guaranteed, given the different things in the world. But so it's really about, to me, the memories you're creating, and that all comes down to what people you're surrounding yourself with. And I think you need to be extremely picky and extremely thoughtful in who you're spending time with, you know? But everybody's got different versions of that for themselves. That's more what works for me.

(Joel Beasley at 00:26:15) Yeah. Well, there's a thousand ways to cook a steak, right?

(Mark at 00:26:19) Right.

(Joel Beasley at 00:26:20) Yeah. So when you're, do you ever put in your calendar time for relationship building or networking at all?

(Mark at 00:26:27) No. Not specifically. I mean, I probably could do a better job if I'm speaking honestly on networking and stuff like that. I kind of oscillate between that sort of aspect of business and then the, you know, staying up till 4 a.m., you know, mad scientist in the lab. And those two things are kind of counter to each other in some sense. And so I definitely select much more for the mad scientist in the lab because I find some of the other network building and other things, it kind of takes care of itself if you're working on stuff that you're passionate about and if you're creating some, you know, impact in the world, right? That's not to say you're just trying to, you know, do awesome things so everybody kind of comes to you or something like that, right? But I think there's a balance of how much time do you spend, you know, talking about all the things that you want to be doing in life and you're aspiring to, versus can you name what are the three things you did in the last week to kind of get to your goal, right? And so I think on the balance of that, I try to stay in the lab, try to work on the next record, and then get out there, tell everybody what the new record is, play it a few times, and then try to quickly get back into the lab until I have something worthwhile to say or do again, you know?

(Joel Beasley at 00:27:45) My brother-in-law is a music producer, so that's exactly how he operates. He goes away, does a bunch of music, comes out for the premiers and the shows, and then goes back away for a year. And...

(Mark at 00:27:55) Yeah. The reason I use that example is I was kind of explaining to a friend once, and he's in music also. He's like, oh, yeah. It's like you're working on your next record. Do you want to go tour on it? And then you want to, but you don't want to tour on the same record for twenty years or whatever, right? And that's where, you know, even for me when I'm, and I really appreciate the thoughtfulness of questions because, you know, the getting raided part. I love telling that story because I love any chance that if I can inspire some other young person that's maybe going through a trying time in their life, you know, to give an example of, you know, that there is, you know, maybe hope or path or, like, you know, go fight the fight and try to get out the other end. But yeah, it's always good that progress.

(Joel Beasley at 00:28:42) Yeah. We try to do deeper prep when people have more well-known stories simply because, like, I've traveled the world and given the same talk 50 times. You know, in interviews, people will often fixate that I got hit by a car when I was a kid, and I was in a wheelchair, and that taught me discipline. It's like, you know, I just sort of go on autopilot. And so I was like, you know, we can maybe lightly touch on the FBI thing, but let's try to find some better questions around that. And...

(Mark at 00:29:05) No, it's cool, man.

(Joel Beasley at 00:29:07) So you mentioned translating deeply technical things, a large part of your job. At BeyondTrust, do you get to do anything that's really geeky cool, like run a team of people that are searching for vulnerabilities? Or what's the geekiest, coolest thing that you can talk about publicly?

(Mark at 00:29:24) Yeah. No, I mean, we do plenty of that. Just this morning, actually, a few hours before getting on here, I was hands-on working with three of the people on my team, and we're essentially doing a simulated attack of, essentially, compromising a Kubernetes environment, getting code execution within one of the containers, and then gaming out different versions of what lateral movement look like. You know, plenty of known techniques and things in that space.

(Mark at 00:29:54) But yeah, that stuff's cool of, you know, you start with a vulnerable web app, and now all of a sudden you have account access to AWS. Right? Like, what does that look like from the attacker's perspective of how that actually plays out very hands-on, what that actually is? And then the important translation part for me is that it's easy for me to go describe that attack and kind of give that sort of an example or something. Right? There's plenty of people doing that. But how do I go take the complexity of trying to defend against something like that? The tailored nature of security where security needs to be is kind of tailored from company to company as possible. And how do you try to put that into something that's productized where so many companies don't have the people and expertise or the time, frankly, even if they do have the expertise to really go learn all this nuance. Right?

(Mark at 00:30:46) So how do you try to understand that threat to a deep enough level, understand what the solution might look like that you could try to, you know, give something out there to help out.

(Joel Beasley at 00:30:55) No, it's definitely hard. So I've programmed for the past, you know, seventeen years pretty much until the show got really popular. So it's been about three years since I was doing it full time. But everything got so deep so quick. Right? And to be able to keep up with all the different ways you can get in trouble with security, even just being a developer. Right? You have to accomplish the business goal, but you also have to make sure that it's secure. But it's like, how deep can you go?

(Joel Beasley at 00:31:27) Because you could build out a whole security team for your—

(Mark at 00:31:29) Oh, absolutely. No, it's a great point that you brought up and maybe another way to answer the question you asked of how things have changed in the last twenty years. So, you know, security twenty years ago, you could be a domain expert in everything to do with malware, everything to do with vulnerabilities, everything to do with web attacks, SQL injection, etcetera. Right? Like, you could really be across multiple disciplines in that way. You still can today to an extent, but you're, for example, take something I just mentioned, like, you know, security revolving Kubernetes and those sort of environments. There's people that that's all they do, and they go super deep, do some super, super amazing work, and it's hard to think that you're both gonna be excellent at that level of focus that somebody has on that and, you know, for other domain areas in security. Right? So I think, you know, in security, kind of going back to from a professional perspective, getting exposure to these different types of environments, working on both offense and defense, and getting the different perspectives becomes very, very helpful when you start thinking about, you know, how you're gonna improve things, and especially as you start thinking about leadership and kind of what are the physics and kind of core principles of what matter from a security perspective.

(Joel Beasley at 00:32:48) Yeah. And one of the beautiful things about that is, and tell me if you've seen this, but I saw the sort of egotistical, I can do everything gatekeeper nerd persona become really unpopular really fast because we all have to rely on each other, and it has to be a team thing now.

(Mark at 00:33:04) It's all community driven. Yeah. I mean, it's just, a lot of fucking curse, but just be a good person. You know? That should be the default for any professional thing. But, you know, particularly in security, I mean, it's a complete community-driven effort. There's plenty of security companies that try to do the right things, but there's so many independent security researchers. There's so many amazingly hardworking, you know, people at different companies working on the individual security teams. Those are some of the, you know, people that I think of most often. Right? Like, the human impact of what it is to be on the IT security team of a company that's responding to ransomware. Right? That's a heavy load. And you could kind of characterize, I think, for most people working in security depending on the role, there's just kind of this sense of looming. Right? Like, the sense that, you know, that's not the if but when you're gonna get breached. And so you always just have this uncertainty and sense of looming of something's around the corner and something's about to happen, and you hope you're doing everything right. You have a million and one people trying to tell you what the next right thing is, a lot of noise out there. And so I have, yeah, just like a lot of empathy for people that, you know, work at different companies that are trying to get security to where it needs to be and especially in the context of, you know, security is this race without a finish line. Right?

(Mark at 00:34:33) Like, you're never gonna be done. Like, software, you're in some sense, you're also never done. Right? You're always iterating new version, but there's at least a little bit clearer milestones. And so we think of that in terms of security of, you know, milestones of maybe different projects or improvements we're doing. But again, with that sense of looming, you know, disaster of who's out there that's potentially starting to target you or what's going on in that sense.

(Joel Beasley at 00:34:59) And earlier, you gave sort of a brief overview of BeyondTrust and what they do. But I'm gonna ask you, can you make it more concrete? Like, let's say I'm gonna give you a hypothetical. Let's say we're a company. We have a hundred employees. We're a technology company. We make a SaaS application. And we just got some funding, and we're expanding, and security is becoming a bigger and bigger topic as we grow and bring on more important customers and larger accounts. How could I interface or what's the problem you solve for them? How would you interact with that company? Or are they too small? Or—

(Mark at 00:35:32) No, I mean, we have companies of all size from the largest enterprise to small. And so, really, for us, the central focus is around, you know, what you just described. Right? You're gonna have a variety of different users and identities, you know, from a cloud perspective. You have a lot of, you know, machine-based identities where there is no kind of human attached, if you will. And so one of the most important things to do is to understand, you know, what are all the, what are those different identities? What are the different privileges of who has access to what, and how, what are the different points of how you're controlling access into systems? And so we really try to put a lot of the guardrails and safeguards around identity access controls. Right? And there's other types of, you know, security products and technology out there. But, you know, I think our core focus around identity and access is really one that is, again, central to every breach. It gets back to what I was kind of talking about with first principles of you typically need to compromise someone's identity at a company to then try to move laterally to the systems and the information that you care about. So we're really focused on that kind of problem space.

(Joel Beasley at 00:36:42) And so one thing that I remember about seven years or so-ish ago, GitHub, people were writing code to scan GitHub for AWS keys and things like that. And then they would just be fully privileged AWS keys because you saw Amazon's, I'm the whole thing. That whole rollout became so much more granular. It started out with, like, here's a key, and it can do everything. And you could either check, like, admin key or just other key, and then it became incredibly granular. Are you actually a system that you'll have, like, I'll put my employee into it, and then I'll manage what access they have. And does it, like, API into Amazon? I can create keys. Does it do all of that, or am I missing it?

(Mark at 00:37:27) No. Yeah. That's, it's across a few things. So it's everything from, you know, say you are, you know, a company. You have your thousand employees with, you know, laptops working remote, you know, especially in this kind of post-COVID world where that's much more common. So there's both being able to control, you know, kind of what level of access do people have on their systems, you know, do they have full-blown administrator access, which makes, you know, the kind of impact of if they were hit with malware. Right? The ability for malware to spread and have more impact is greatly reduced by removing administrative rights, better controlling those rights. So there's both that from kind of the workstation servers perspective, but the same concepts of things like least privilege, making sure people only have access to exactly what they need to. We have solutions that work with that from a cloud perspective to try and rate it in. So it's really from the, you know, client server all the way to cloud and everything in between.

(Joel Beasley at 00:38:26) Are people, like, writing BeyondTrust policies that work with your system, or is it mostly just all done through an interface?

(Mark at 00:38:32) Yeah. There's definitely policy driven. I'd say in the balance of things is especially for large enterprises, they typically have, you know, people and resources where they really, if it's a, you know, Fortune 100 bank. Right? They have teams dedicated to writing, you know, very tailored policies on who could do what and how. What's the request and authorization mechanism. And, uh, we, yeah. We just do some awesome stuff there. Nice. Try not to curse, but that's what gets me excited. And so there's also the, when you look at, you know, for maybe a smaller company that's more kind of, you know, cloud native in the sense where they're not trying to run on-prem or traditional servers in that sense. It's more like SaaS cloud infrastructure. There's definitely how do we help do, you know, least privilege and things of that nature that we focus on also. And then, of course, just the ability for people to be able to have secure remote access to systems and managing the different privileged accounts. And it's not always just the company and, you know, your kind of own employees at the company.

(Mark at 00:39:32) It could be I need a vendor to be able to get third-party remote access to some critical infrastructure type of system that is, like, a, you know, I don't know, water filtration pump management. You know, there's weird scenarios like that that come up. And so how do you provide them secure access that's audited, recorded, you know, exactly what's happening. It's limited to only what they're allowed to do. So there's a variety of scenarios that we help with.

(Joel Beasley at 00:39:58) Yeah. There was an interesting issue in Florida where I think somebody left some sort of TeamViewer up at a utility company, and they got in through that. And I was like, oh, man.

(Mark at 00:40:08) So there, yeah. There was, I'm bad with dates and timelines, but I think it was the first or second time that I testified before Congress. It was about critical infrastructure. And one of the things I was specifically calling out when I testified was about the fact that a lot of water filtration, other utility companies, they were starting to, you know, switch and just use everyday off-the-shelf software, like you mentioned, as a way to kind of control and manage. And so there was an example where I was able to, I was doing a penetration test of a large utility company in California, and I was able to get control of the water filtration system. And so, of course, I'm not a water filtration expert, so I was asking, you know, one of the employees there, hey. This system that I have control to the filtering process, like, what could you do? And you could obviously, at that point, you know, do all sorts of nefarious things that would cause people to have to boil water for a period of time and stuff of that nature. And so jumping now, I think that was, like, ten, fifteen years ago or something when I was both testifying about that before Congress. You know, pretty much what I was explaining was the, you know, that sort of scenario that you just described that, like, happened in the real way in Florida.

(Mark at 00:41:25) And I think that, like, highlights one of the challenges is it's easy to point a lot of these things out. But, again, like, how do you not just give the right technological solutions. Right? But, you know, especially from a leadership perspective. Right? The hardest thing in security is not so much the technical security controls. It's changing culture. Right? It's changing business culture. It's changing, you know, how businesses operate, how people think about it. I, you know, one of the things I always highlight is, if you are looking to move into a position of security leadership, you know, you really wanna focus on your, you know, kind of storytelling abilities and how do you make the technical controls that, you know, you know in your heart is the absolute thing you need to protect the business, but, like, how do you translate that in a way that the business understands, cares, and most importantly, that you're not just being some, you know, giant, you know, security team of no roadblock, right, that you're actually figuring out, you know, what's the business trying to accomplish, and then how do we give them the right safeguards to do what they need to do as a business securely, right, versus just saying, can't do that, can't do this, take this away, take that away. Right?

(Joel Beasley at 00:42:30) Well, it's hard when, at first, you fall in love with the technology, and then you wanna protect it. And then you realize that you—

(Mark at 00:42:38) It's the question I ask so many people when they're aspiring to different security leadership roles. I'm like, alright. You might be stepping beyond the bounds of some of the technology leadership and into some of the culture people change agent type stuff. And, you know, that's one of those again, you gotta know yourself first of, like, is that the sort of thing you wanna be doing? And not to say that you can't be doing both. Right? But there is a level of, you know, you get to a point, it becomes much more about how do you, you know, change culture and behavior, less than figuring out some technical security controls.

(Joel Beasley at 00:43:13) Oh, yeah. I had an interesting conversation a few years ago with Bryson. He's the CTO at Equifax, and he came in after the whole breach thing. And his responsibility was to change everything. And he explained to me. He told me all of this. He had to just completely, I think my video cut out for a second. But Bryson had to completely change the entire culture in engineering because it's a large company and, you know, switch it from just being vendor-led and don't, each department buying their own thing and bolting it on to it being built into the culture at the lowest level.

(Mark at 00:43:48) That's absolutely it. And I mean, the way that it was just, that you just described it is the way to go about it. Right? There is no magic five things that you, like, kind of bolt on and you get security. Right?

(Mark at 00:44:01) Even if somebody had a security product company, right, I mean, we're offering a great series of different tools and technologies that you could use as part of your process and what you're doing. But you still have to have the right processes, the right ideas around how you're going to tailor these things to your business in specific ways. So absolutely.

(Joel Beasley at 00:44:21) Yeah. I don't envy him at all having to make that change. I'm just going to find a company that was good at it.

(Mark at 00:44:27) Some people live for it. Right? Some people are like, oh, the culture's this and it needs to be that. They live for that sort of change. And again, that's where you just got to know yourself and know at what stage of your career and what your interests are.

(Mark at 00:44:40) Right? Because I think some of those people will get caught up in wanting maybe the next title, or they just feel that they have to grow up into some different leadership role. And I had a good friend of mine that he was a SOC manager on the security operations team and wasn't really looking to do other stuff and moving into CSO type work and some of the policy aspects and everything else. He just loved threat hunting and getting into that. And I was just like, yeah, you should feel zero pressure on trying to go make that your own. That's the thing you love doing. Keep doing it.

(Joel Beasley at 00:45:14) That was a mistake I made many times. I would think that people were like me, like anthropomorphism. Right? And I would excite them with the things I thought would be exciting, but to them it was stressful. It's like, oh, you're going to have your own team and the company's going to grow, and then they'd resign. And I'm like, oh, man. I just stressed this person out who has a kid at home who's trying, right at that point in time, that's where their focus is.

(Mark at 00:45:40) It's a funny thing with leadership, right, where sometimes it's just like, well, it's a given. I've given this person new growth, this, it. But is that actually what they want? Right? I mean, it seems obvious because everybody always wants to grow in this way or that. There's the stereotypes to it all. But yeah, I think always asking the first question of, is that actually their interest, and where are they trying to go? And trying to be, I think, also the sort of leader that's a good mirror in the sense that you can hold up a mirror and hopefully reflect back to people. I mean, I can count numerous people that I've hired and gave them their first job in security, and they've gone on to do amazing things. That's not because of me and because I hired them. Most of the time, it was because I saw something awesome in them, and I just needed to hold up enough of a mirror so that they could see it in themselves and believe in themselves and go down that path. Right?

(Joel Beasley at 00:46:31) A hundred percent. We have to identify the next generation, those sparks in people, and then help fuel that fire.

(Mark at 00:46:38) Yeah. Absolutely.

(Joel Beasley at 00:46:40) How did you get the opportunities to testify in front of Congress?

(Mark at 00:46:44) Good question. So the first time I testified, I think it was in relation to Code Red. And so it was very much, you know, computer worms, particularly in the Microsoft sense. There had been previously the Robert Morris worm, many years prior. So I believe that was the first time. And then at the same time, I mentioned from a vulnerability research, vulnerability management perspective, we had at the time the largest deployment in the world. Every DOD system was essentially mandated to use my company's software. So if it was a Humvee driving through the desert somewhere with a server rack on it, it was running our software, you know, maybe a ship out at sea, and so on and so forth. And some of the vulnerability research we were doing led to some of the conversations, and I believe the second time I testified, specifically on critical infrastructure itself and the kind of risk to the country from that perspective.

(Joel Beasley at 00:47:42) That's pretty cool.

(Mark at 00:47:43) Yeah. It was a lot of fun. I was actually talking, a friend, awesome author, journalist, et cetera, extraordinaire, Kim Zetter. And she did a write-up about some of the previous pen test I had done on the water filtration plant. I was catching up with her at one point. She's like, when the Florida hack happened, she's like, hey, didn't you say something about something like this? And it was pretty on-the-point to description. And yeah, I think we can always do more to educate and kind of get the word out.

(Joel Beasley at 00:48:20) Yes. Man, this is great. I want to make sure, do you have a book we can plug? I mean, I know we can say go to beyondtrust.com. That's the website, right? Hopefully.

(Mark at 00:48:29) Yeah. beyondtrust.com.

(Joel Beasley at 00:48:31) For your identity management needs. Is that how we describe it?

(Mark at 00:48:35) Yeah. Identity and access security. Yeah.

(Joel Beasley at 00:48:38) Okay.

(Mark at 00:48:38) That's cool. That's what we do.

(Joel Beasley at 00:48:41) Thank you so much for listening. And if you found this episode useful, please share it with a friend or a colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.