Episode 417 ·

Quantifying Cyber Risk with Rich Caralli, Cybersecurity Advisor at Axio

Today we’re talking to Rich Caralli, the Cybersecurity Advisor at Axio. And we discuss how risk quantification is the missing link between business decision makers and cybersecurity professionals. Recognizing that cybersecurity and business resilience are two sides of the same coin, and why companies need to get back to basics with their security practices.

All of this, right here, right now, on the Modern CTO Podcast!

To learn more about Axio, check them out at https://axio.com

In case you missed it: check out our episode with David White, Axio's Founder and President

About Rich Caralli:

Richard Caralli is a cybersecurity professional with nearly 40 years of experience in accounting, auditing, risk and resilience management, and process improvement.  He is currently helping organizations implement and institutionalize GRC programs as a member of the consulting team at Seiso LLC, a solution-focused cybersecurity firm based in Pittsburgh.  Prior to joining the Seiso team, Caralli held various senior level positions in information technology and cybersecurity in the oil and gas industry where he was responsible for developing and operating information and operational technology cybersecurity programs.  Prior to returning to industry, Caralli was the Technical Director of CERT’s Risk and Resilience Directorate at Carnegie Mellon’s Software Engineering Institute where he was the lead architect of the CERT® Resilience Management Model (CERT-RMM), a process improvement-focused maturity model for managing operational resilience, much of which has been incorporated into various models including the Cybersecurity Maturity Model Certification (CMMC). Caralli’s research agenda was influential in developing and delivering coursework in information security to graduate and executive education students at Carnegie Mellon’s Heinz College. Prior to joining CERT in 2001, Caralli led accounting and IT audit teams in the banking, manufacturing and oil and gas industries.

About Axio:

Axio is the leader in SaaS-based cyber management software, which empowers security leaders to build and optimize security programs and quantify risk in financial terms. Axio360 is the only cyber risk management platform to align security leaders, business leaders, and Boards of Directors around a single source of truth about their most critical corporate risks. Since 2013, Axio has been a trusted partner to many of the world’s leading critical infrastructure, energy, manufacturing, and financial services companies, helping drive better visibility and decision-making about cybersecurity priorities and investments.

Transcript

(Joel Beasley at 00:00:03) Hello, my friends. Today we're talking to Rich, cybersecurity advisor at Axio. And we discuss how risk quantification is the missing link between business decision makers and cybersecurity professionals, recognizing that cybersecurity and business resilience are two sides of the same coin, and why companies need to get back to basics with their security practices. All of this right here, right now on the Modern CTO Podcast.

(Joel Beasley at 00:00:36) Here we go. This is the Modern CTO Podcast.

(Rich at 00:00:48) Yeah, so I actually started with the accounting, and I went into cost accounting, which got me into a manufacturing environment so I could see the production line and then into IT audit. And from there, I ended up running a large Y2K project.

(Joel Beasley at 00:01:07) Oh, crazy.

(Rich at 00:01:08) Probably not by choice. More like I was the only guy that was left with his hand up. And it turned out to be a fascinating experience because it's where I learned a lot about resiliency and the ability to not be able to control everything in your environment and have to be ready to deal with operational disruption. And I found myself in Australia because I was working for a large oil and gas company that was building a pipeline from Perth to Darwin, and they needed help with somebody doing their Y2K projects. I found myself there four times. Beautiful experience.

(Rich at 00:01:44) That's when I think all the cybersecurity and the technology and all those things sort of clicked for me.

(Joel Beasley at 00:01:51) So when you say Y2K project, do you mean like a reliability engineering project for Y2K?

(Rich at 00:01:58) I mean, we had hundreds of thousands of lines of code that were written in COBOL. We had a lot of legacy systems that were like 30 and 40 years old, which you often see in an oil and gas legacy organization. And so I led the effort to not only renovate all that code and renovate those systems, but also to work with business owners to understand their contingency plans should things go wrong at Y2K. And it was a bit of a non-event, but it was planned to be a non-event, right? I mean, if we did our jobs, it should be a non-event.

(Rich at 00:02:35) So that's kind of how I made a little bit of the transition to understanding and really liking the whole resilience side and realizing that was the partner to cybersecurity because you got to be able to do both.

(Joel Beasley at 00:02:48) What's like one piece of advice you got early on in your career that has helped you throughout?

(Rich at 00:02:55) You know, I've gotten a lot and I would have to say it's hard to pick one. But one thing I learned, I think, about leadership early on, as I was transitioning to more of a leadership role—people always said, look, leadership is about leading by example and investing in people and giving them the tools they need to thrive and encouraging strategic thinking, being accountable, all those things. And we know those are all really true. But I think leadership comes down to two fundamental things that are hard to master and vital to survival. And one is the ability to make tough decisions because decisions by nature are not clear and there's always a downside to the selection, the choice you don't make.

(Rich at 00:03:46) And in tandem with that, having the courage to lead. I think if you're going to be in cybersecurity, you're in a very interesting position in the organization. You have a group of people who are telling you you need to make sure we're secure. And every day, the ground level truth is that you're fighting to stay relevant and to stay engaged and to stay at least contributing to the business. But sometimes it just takes courage to stand up and say, this is the wrong way to do it, or there's a better way to do this, or we need to think about this problem more critically, and we need to put resources at it.

(Rich at 00:04:33) And I think if you know that, but you don't have the courage to say it, you don't have the courage to engage people in lively discussion about it because you don't like conflict, you're really doing the organization a disservice. And as a leader, you're really doing yourself a disservice. So early in my career, I probably took that too far and was very outspoken. As I got older, I learned how to manage the message, right? And to deliver it in a way where there was win-win coming out of it.

(Rich at 00:05:11) I think one of the lost skills in organizations is the ability to negotiate. Everybody thinks negotiation means you come to the table with your position and you don't move off of it, right? And we see this at every level of our lives—in government and in our work lives and whatever. But negotiation means you sort of have the things that are important to you and you have the things you're willing to compromise on.

(Rich at 00:05:38) And you know you're not coming out with your good list. There's gonna be some bad list stuff too. And it takes courage to sort of stand up for the good stuff if you really think it's the things that the organization needs to do. And if you're trying to advise them in your best risk management or risk reduction way, then you need to tell them the truth. And sometimes it's hard to tell them the truth.

(Rich at 00:06:05) So that's kind of what I learned. And even to this day where I'm not in a leadership position, I try to have the courage to be honest and to have the hard conversations when they're needed because there's an easy way to do it and there's a respectable way to do it. So I think if you're a cybersecurity leader, to me, those are two skills you can't be without.

(Joel Beasley at 00:06:33) Yeah. And something that I've found really useful for trying to be outspoken without being too outspoken and also being reasonable at negotiations is just if I feel too strongly in either direction about basically any situation, I try to just not reply and just get up, walk around. Then you can think about it and say the better thing, which you're absolutely enabled to do that more if you work remotely. It's like a cheat code because you can just close your laptop instead of being in a face-to-face conversation with somebody over there looking at you.

(Rich at 00:07:18) Yeah, you know, it really is. That's really true. And I think that stepping back—like it's been a theme we've been talking about today—that need to just sort of step back and take stock, it applies to a lot of levels of decisions we make. And sometimes, you know, I remember there'd be times in the organization where somebody did something that was just so objectively wrong, right? And it was not in the best interest of the organization. And your first reaction is to go at them.

(Rich at 00:07:49) But the best reaction is to sit down and channel that into, you know, here's five things that I think would be productive to discuss. And if you're a cybersecurity leader, I think you're faced with that every day because you have a really dynamic user community that's working all around you. So it's like keeping a lot of balls in the air and not letting any of them hit the ground.

(Joel Beasley at 00:08:12) Yeah.

(Rich at 00:08:13) You know, you're on your toes all day, 24 hours a day.

(Joel Beasley at 00:08:18) Right. So when did cybersecurity become like your main focus?

(Rich at 00:08:23) So in the year 2000, a large company, Dominion Resources, bought the gas company that I worked for. And I had some opportunities to continue in that space, but I really wanted to do something different. So I went to Carnegie Mellon on the invitation of a former colleague and went to a startup company there focused on cybersecurity, and I found myself at CERT. The startup company didn't make it and was not well defined, and I found myself at CERT and really got interested in not only the research side of cybersecurity, but also CERT and the Software Engineering Institute at Carnegie Mellon where CERT is located is really famous for the Capability Maturity Model for software development. And I found myself really interested in that.

(Rich at 00:09:13) And I started to see that those two worlds weren't necessarily divergent, that there was a lot of lessons from the process improvement community and the software community that the cybersecurity community needed to learn. So I started basically—I worked in a system network management sort of group, and then that emerged into a risk and resilience management group that I ended up leading for probably about 10 years, leaving there in 2015. That's where I met David White, who was on my team, who you've podcasted with before.

(Joel Beasley at 00:09:49) Yeah, dude. David was a fantastic episode, fantastic guest. Really enjoyed speaking with him. So did he pull you along with Axio from the start, or were you just kind of like talking for a while and then eventually came over?

(Rich at 00:10:03) We kind of diverged though. When he left the Software Engineering Institute, I had an opportunity to go back into oil and gas, which I had spent 14 years in previously, and that was to become the leader of the cybersecurity program at a large natural gas company. In fact, it's, I believe, still the largest natural gas producer in the country. It's EQT, which is headquartered here in Pittsburgh. And it was a way for me to take—just like you said—I had cybersecurity experience, I had business experience, I had manufacturing experience, I had oil and gas experience, and I was going to be able to converge all of them. So I reluctantly left Carnegie Mellon, which was a wonderful place to work, and went back into industry and led the cybersecurity program at EQT and then a spinoff, which was Equitrans Midstream, until 2020 when I really came to a point where I thought retiring was the next phase of life. And I did some consulting after I left in 2020, but I really still wanted to have some impact.

(Rich at 00:11:08) And so I was talking to David and he's like, look, we can really use some help and work as a senior advisor with us. And so that's how I joined back up with David. I was following his journey all along, and I knew he would be successful and Axio would be. But I'm having a great time working with those guys and helping them get on the map even more than they already are.

(Joel Beasley at 00:11:30) That's awesome. So for those that may not have listened to David's episode, could you give the overview of what Axio does?

(Rich at 00:11:38) Yeah. I think my best description of Axio is from a former customer. So while I was in the oil and gas industry, I used their product, Axio360, which is their assessment product. And so from my perspective, what they really do best is that they are a full-scale cyber risk management organization. So they really help organizations use risk management to advance their cybersecurity programs.

(Rich at 00:12:05) They provide tools and consulting that align to all the phases of risk management like diagnosis and planning and measuring and metrics. And recently they've gone full scale into risk quantification, which I really wish I had had the opportunity to implement a lot of what they're doing in that space when I was in industry because cybersecurity risk quantification is that missing link between the cybersecurity profession and discipline and the business makers in the organization. I mean, it really links the two together. And it's because business decision makers use quantification as a universal language. So it's a way to align to the way they think.

(Rich at 00:12:51) And I think what they're doing in risk quantification at Axio is very impressive.

(Joel Beasley at 00:12:55) Yeah. It is really cool stuff. And yeah, giving people the ability to look at their cyber risk as like a dollar amount and make decisions, like financial decisions based off of cyber risk versus just like trying to prevent everything. Like you're not gonna prevent everything. Some stuff is gonna get over the wall. So just prepare for that.

(Joel Beasley at 00:13:15) Budget for it. So one thing I wanted to ask you is the job title of advisor—I feel like that can mean such a broad idea level of involvement. Like you can be driving the organizational strategy in full time or more than full time, or you can be at the golf course meeting with the CEO on Sunday and be called an advisor.

(Joel Beasley at 00:13:45) So what do you do day to day at Axio?

(Rich at 00:13:47) You know, I'm more of a sounding board in a lot of ways as they are thinking about strategy and what's needed in the community. And I give them back a lot of the experience that I had, firsthand experience using their tools and products and services and how they worked and didn't work possibly in my environment. And what I find myself really doing with them a lot is writing. It's a lot of codifying and really putting their approach and their strategy on paper for them, helping them make these really good business cases for what they do. So, for example, I got involved in a document that they recently published—a ransomware state preparedness for ransomware.

(Rich at 00:14:33) And basically they gave me a pile of data and I sort of took it and really went in and analyzed it and looked to see if there were trends in there and then wrote the report with David White. And so, David and I wrote a book together, the CERT Resilience Management Model. So we're really used to collaborating in a technical way and also in codifying things. And so I think a lot of what Axio does is they go out into the community and try to advance the state of practice. So I help them do that.

(Rich at 00:15:08) And that could be very different things on different days. It could be helping them prepare content for a legislative hearing that they might do, or it could be writing a report for them. So what I do know about my advisor role, and I use that in air quotes, is it's some of the most fun I've had in a really long time. So I just say throw at me whatever you want and I'll figure it out with you. So it's been a great time.

(Joel Beasley at 00:15:39) That's awesome. So I'm curious. What is like the driver of doing all the education and community outreach from a business standpoint at Axio? Like what return do you guys get from publishing like all these materials that people can use to better their cybersecurity practices?

(Rich at 00:15:58) You know, I think the most benefit that you get from it is you're stimulating people to think. So we are now at that point in the cybersecurity discipline where it's becoming a little routine. You know, everybody does these things and uses these tools and they do it in this way and they use this framework. But that can lead organizations to stop thinking critically about what you really should be doing. And it's almost that the cybersecurity community understands that compliance as a mindset can be very limiting.

(Rich at 00:16:36) It can take your focus away from doing the right things and investing in the right places. And so I think they're conscious of that. But what I think they're not really conscious of is taking a step back. You know, and again, I'm an old guy, right? I'm a retired, semi-retired guy, and I always think we did things better in the beginning than I would see people doing them today. But my bias is that we had to think about it more critically. We had to explore it more critically. We didn't just have the opportunity to push a button and have something happen. It's like writing code when you're a COBOL programmer and you have to understand how the machine reacts to that code.

(Rich at 00:17:18) And you have to build divisions in those programs to instruct that machine to do things. But with languages like the modern languages, you don't have to do any of that, right? All of that's being managed by the software. So it's really helping, I think, organizations think critically and get back to basics.

(Joel Beasley at 00:17:39) So what are some issues that you notice organizations committing pretty often?

(Rich at 00:17:46) Yeah. So I came away from my initial work with the Axio folks with three sort of fundamental truths. One is that organizations have to understand that cybersecurity is just one of many risk management challenges. So from an organizational perspective, they look at cybersecurity as another pillar in their risk management program. They might have market risk and credit risk and strategic risk and HR risk.

(Rich at 00:18:16) And cybersecurity is one of those things. Now it might be shouting the loudest right now, but at the end of the day, if you're a decision maker, if you're senior management, if you're a board of directors, they're being presented with all kinds of risks all day. And so to the extent that you see cybersecurity through a risk lens and you are heavily adopting a technology, especially internet-focused tech or anything as a service, looking at the risk management aspect of it is really number one, I think, in my book. And I think that's something that Axio does really well because they keep that risk management thread alive when they're consulting with you, when they're talking with you, when you use their tools. Their tools start with a risk perspective.

(Rich at 00:19:07) So it's not simply a, you know, how well do I compare against X framework? It's how well are the actual risks that are unique to my organization driving me through that framework? That's a whole different approach. And that's to me the best approach. So that's the first fundamental truth, I think.

(Joel Beasley at 00:19:30) Well, I mean, you got me on the edge of my seat. What are the two other fundamental truths?

(Rich at 00:19:36) So we talked about one of them early on, and that's to recognize that cybersecurity and business resiliency are two sides of the same coin. You can't do one without the other. And because uncertainty is at the core of risk, you have to realize that any approach that pretends to address all risk as a known known, it's flawed from the start. So if you go into it with the bravado of, you know, we're going to build a cybersecurity program that's impenetrable, and we're never going to have to deal with an incident, and we're going to have this fortress, you're probably going to spend a lot of money and be disappointed.

(Rich at 00:20:15) And then you're going to have to explain to your board of directors why you spent a lot of money, made a lot of guarantees, and somebody still got through. It's the Red Rover conundrum. I don't know if you've ever played that game. You lock arms and you dare somebody over. Well, every day as a cybersecurity professional, you are really daring the next attacker over.

(Rich at 00:20:38) So if you don't look at it from the perspective of let's control what we can control, let's understand risk from a scenario perspective, let's plan for those scenarios, but also let's plan for the fact that there will be organizational and operational disruption. We're going to have to do something about that to get back to normal operating condition. And when you do both of those things, I think from a risk management perspective, you have the best potential coverage because you're thinking about it from the perspective of what could get through and you're thinking about when it gets through, here's what I'm going to do about it. So you're covering all the bases. So that's fundamental truth number two.

(Joel Beasley at 00:21:23) What is truth number three?

(Rich at 00:21:25) Number three: cybersecurity requires excellence in the foundational practices. So when we did this work on the state of preparedness for ransomware, we had a pile of data from organizations that took Axio's ransomware preparedness assessment. And understand that the reason somebody would take that assessment is not really to answer a survey. It's because they want to know what their gaps are, and they want to know how to fix them.

(Rich at 00:21:57) So they have vested interest in the data. So I find that kind of data much more compelling and much more valid. And as we went through that data, there were some truths emerging. And, you know, we kind of all sat back and looking at the conclusions and said, this seems to indicate that organizations are failing at the basics. Like, they're just not doing the old school basic stuff that we did back in the day, and they've taken their eye off of that toward, you know, the shiny metal object and the advancements and all these things.

(Rich at 00:22:35) And I'm not saying those aren't important because, you know, as we were moving into a cloud environment in my past jobs, your mindset has to shift. The tools change. The controls are the same, but they're implemented differently. So these things happen that you have to really account for. But at the end of the day, it's all still basic stuff.

(Rich at 00:22:56) And so, you know, when we looked at the data that came out, I think initially we were shocked. But then we were like, this makes a lot of sense because if the foundation is weak, the house will fall. And what we think we're seeing, at least anecdotally, is that a failure to attend to the basics is causing an overexposure to things like ransomware and other threat vectors. And we identified seven areas where those basics we thought were failing, and we published that in a report.

(Joel Beasley at 00:23:32) Nice. So what are some ways that companies—because I think it's easy to be blind to that kind of thing when you're operating on a day-to-day and you're doing what you think you should be doing—how can companies take a step back and evaluate whether or not they are adhering to the basics?

(Rich at 00:23:50) Well, I mean, certainly you can use a lot of the framework instruments that Axio has in Axio 360. It will point out the gaps, and it's going to help you because the questions and the controls that you're addressing in that framework, in that tool, are written at a level that it really gives you the opportunity to think critically about it and answer honestly. Because that's the problem here, right? If you don't answer these questions honestly, you're fooling yourself.

(Rich at 00:24:19) So I think that's one way to do it. I think also, you know, the reason we wrote the report was to give people seven areas to focus on that came up repeatedly in the data. Simple things like basic cyber hygiene, right? When you spin up a server, you should have a security footprint that you are implementing in that server, which means you're closing ports that you don't need and you're turning services off you don't need and you're cutting off the internet connection if you don't need it.

(Rich at 00:24:51) All of those sort of basics that when you spin up a server, you shouldn't have to think about it. It should be the footprint you use when you do that. I used to think about the fact that giving users local admin privileges, for example, was one of the, you know, the biggest cybersecurity threats in my organization because first of all, they're not going to use it responsibly. Second of all, they're going to download and install their own software, software they haven't vetted and they haven't looked at the controls on it.

(Rich at 00:25:23) And that creation of that shadow IT, I understand it from a business perspective, but from a cybersecurity perspective, your user base is expanding your threat environment and you don't even know it, right? So it's those simple sort of things, you know, like cyber hygiene. And supply chain is another one. If you don't realize yet the world that you control as a cybersecurity professional is not just within the boundaries of your organization.

(Rich at 00:25:58) If you do anything as a service, if you do cloud anything, if you have customers, if you have regulators, you exist in an ecosystem sometimes that is bigger outside of your walls than it is inside your walls. So not having a basic supply chain risk management program is a massive failure in my view, because you need to at least know what that exposure is to do something about it.

(Joel Beasley at 00:26:30) Yeah. And so Axio is the tools for noticing these failures, right? And then it gives you recommendations of what you can do about it, or is there also tools offered by Axio to do something about it?

(Rich at 00:26:44) Well, what I love about the Axio 360 tool, and I used it in this way, was after you get through sort of the assessment activity, it helps you prioritize your gaps based on risk. It helps you build plans and start to engage people in the organization to help you close those gaps. So it gives you—and this was always one of the hardest things to do as a senior leader in cybersecurity—it gives you that roadmap that you can start to use to have a systematic and structured way through your risk, your highest risk, and closing those gaps. And of course, the consultants at Axio will absolutely help you build those plans and implement those plans and measure their effectiveness.

(Rich at 00:27:37) But just being able to come out of four or five hours of investment with people around the table having a conversation about the organization's cybersecurity and its risk with a roadmap is just brilliant. I mean, it used to take us months to do work like that. And we would rely on internal auditors to help us. And, you know, they have kind of a different objective in the organization. You're not always really aligned with them as an independent body.

(Rich at 00:28:06) So just being able to produce that so quickly is, you know, it's 50% of the battle in my opinion.

(Joel Beasley at 00:28:14) For sure. So one thing that's been on my mind when you're talking about the increased threat landscape of giving more people access to your servers and your employees access to everything that they need to have access to—recently we talked to this company called Cradlepoint on a couple episodes. They do a lot with private cellular networks. And it's pretty cool hearing about how you can have a Wi-Fi-like connection and experience to your enterprise network through a cellular signal through the tech that they have, and that offers all sorts of security advantages going forward with remote work. And I'm curious, with remote work, you know, obviously a lot more than it used to be, what are some ways that security strategies are going to have to change going forward, forever?

(Rich at 00:29:10) Yeah. I love that you brought that up because I think that on March 13, 2020, the cybersecurity world changed dramatically. That was the beginning of the lockdown for most of us, right? And everybody went remote whether the organizations were ready for it or not.

(Rich at 00:29:32) And what lagged, in my opinion, was any of the gaps that you had in remote work to begin with. So most of these organizations had some remote capability, right? Whether it was through a VPN or something like that. But I think it forced them to look critically at not only what happens when the person leaves the physical organization, but now they connect to their own ISP. And they might be connecting on a computer that's shared in the household, shared with teenagers, shared with kids who might not be best at, you know, keeping it nice and clean and secure.

(Rich at 00:30:16) And beyond all that, we started to learn that what really started to lag was any policy around remote work. Like, what is acceptable, or how does your machine have to be configured? And, you know, do I—if I'm using my home computer at home, do I have to download the organization's EDR solution so that I, as a cybersecurity professional, can make sure that that home environment is at least 90% as secure as it would have been if it was inside my walls? I think it forced a major conversation in organizations. In fact, before I left my position, we were really sitting down and thinking about, did we have the capacity?

(Rich at 00:31:05) How would our networks handle all of this? What kind of traffic would be coming across, and where would it be coming from now that we're not used to? How would we monitor for it? How would we rebaseline for anomalous events? And then how would we get the message out that we expect you to behave at home the exact same way we were training you to behave in the office.

(Rich at 00:31:29) And I think that meant for a lot of companies pushing out new policy, getting sign-offs, doing those sort of things, and auditing that that was actually happening. And of course, you know, remotely monitoring, you know, giving up some of your maybe some of your freedom at home when you're plugging in that—you're at least being monitored to make sure that—because, you know, somebody's router could be wide open and somebody's driving down the street, and they're on that router and they're into, you know, whatever you're doing at work or, God forbid, you know, they're into your network. So I think that just changed everything. And by the way, I don't think we're going back.

(Rich at 00:32:09) This is too productive for a lot of people, and it's too balanced against their lives. So I think if companies have not already confronted this maybe majority remote workforce, it's well past time to do that.

(Joel Beasley at 00:32:30) Absolutely. I know me personally, I would never want to do full-time work in an office again. I mean, just because of the loss of sleep, because that's the thing that's going to go if I have to add in a commute.

(Joel Beasley at 00:32:46) Like you said, people have found this balance that works and are not really willing to give up the extra time and effort that it takes to get to an office. But that being said, there's also—I think it's not wise to gloss over the large amount of people that like working in an office. Like, there's a study—actually, not a study, an article I read by the Wall Street Journal recently talking about how people coming out of college right now are actually a large percentage of them looking for in-office work because—

(Rich at 00:33:24) Absolutely. Yeah. Yeah.

(Joel Beasley at 00:33:25) That's how you—when you graduate college and start that new step in your life in a new city or whatever, a lot of times you make all your friends at work.

(Rich at 00:33:35) And I will tell you, one of the things I learned—the most valuable lesson I learned at Carnegie Mellon—was collaboration. Carnegie Mellon is a highly collaborative environment, and I learned there how a thought or idea gets made better by the diversity of opinion at the table. It wasn't always pretty, and it didn't always feel good, but it made everything we did better. So for example, when David White joined my team, when we were looking at the Resilience Management Model, he came at it from the perspective of somebody who had experience in transitioning work to a community. So he was in a part of the Software Engineering Institute that would translate research ideas into actual codified products that, you know, the Department of Defense or federal civilian agencies could use.

(Rich at 00:34:30) So his perspective at the table was, you know, Rich, that's really great, but people won't use it that way. They'll use it like this. So maybe we should write it that way. And so that whole collaboration, I can't imagine if I was at Carnegie Mellon now how this might be harder because that collaboration is so dynamic. And the thing I miss in the room I'm talking to you in is if I was allowed, I'd be writing all over these walls.

(Rich at 00:35:02) Carnegie Mellon, you have floor-to-ceiling whiteboards. And boy, we really made use of those things. And that is harder, I think, in this respect. And it is harder for cybersecurity people too. Heads-down analysts, maybe not, but the strategic folks, I think this has probably been harder for them.

(Joel Beasley at 00:35:22) Yeah. We actually just had a guy on the podcast that had clearly a really nice camera setup and he was in this cool room where he was free to walk around and he's still in focus and everything. And halfway through the interview, when he's describing something, he just picks up a marker and starts writing on the glass in front of him between him and the camera that I didn't know was there until he did that.

(Rich at 00:35:49) That's awesome. I need that. I need that.

(Joel Beasley at 00:35:52) Yeah. I know a lot of online instructors are using tools like that. It's definitely a bigger setup and a bit of a production. But I know that's one solid tool. I know for a while, right at the beginning of the pandemic, we were always asking people, what are some digital whiteboarding solutions you've come up with? Because there didn't seem to be really any good ones.

(Rich at 00:36:18) Yeah. I mean, the ones you see in the traditional, you know, collaboration platforms like Teams, I mean, they work. But it's not like having a whole bunch of people in a room and, you know, everybody at the board with a different colored marker and really looking at all the aspects of a problem. And I think, you know, I'm actually kind of glad you went here because I do think that is going to have an impact on cybersecurity. The inability to sort of on-demand kind of get in a room and solve a problem.

(Rich at 00:36:52) Because a lot of times that's what we were doing in the real world is something blipped. And on a spare notice, I got a conference room, brought the operations folks in, brought our external collaborators in, brought our management team in, and we solved it in a room. And I think this is going to be much harder, frankly.

(Joel Beasley at 00:37:11) What do you think about the prospects of doing that in VR in the metaverse as—

(Rich at 00:37:16) Oh, I think it's coming. Yeah. I don't have a good experience with VR because I don't know if you remember, there was a movie called The Wire about the—I believe it's a Frenchman who strung a wire between the two Twin Towers, the World Trade Center before they opened, and he walked that wire. So there was a movie made about it. And when you went to the theater, you could put the VR equipment on and walk the wire.

(Rich at 00:37:49) And it was terrifying. In fact, people—they had to bring in medics and so forth. So, you know, VR in the cybersecurity world, I wonder, will somebody be running head first into a wall or, you know, on YouTube when people have VR set on. So, yeah, I mean, that's a very interesting concept. I mean, you know, we are living in a virtual world and the fact that things are made more virtual is a new problem set for cybersecurity professionals.

(Rich at 00:38:23) So if you want to understand the problem from the perspective of where it lives, you got to be in it. You got to be in head first and have your sleeves rolled up.

(Joel Beasley at 00:38:34) Yeah, absolutely. So before we get closer to the end, I want to ask you a couple leadership questions if that's cool with you.

(Rich at 00:38:43) Absolutely.

(Joel Beasley at 00:38:44) So recently we were talking to this guy at ITProTV. His name was Don. And he was a fantastic speaker because he's a professional educator for ITProTV. It's what they do. They provide these videos in a talk show format for upskilling and getting good at tech, and people use it to get certifications.

(Joel Beasley at 00:39:08) And companies use it to upskill their workforce. And I know you guys do a lot of education outreach in terms of cybersecurity. And I'm curious what you've seen other companies do to upskill their workforce and bring everybody up to speed on their cybersecurity practices and what's worked in that regard?

(Rich at 00:39:32) Yeah. I was a big fan and I still am of learning through applying. So when I was back in industry starting in 2015, we were putting in learning management systems and those sort of things. And that kind of, you know, watch a video and absorb and answer some questions, some things get through, but they don't get through in a great way, right?

(Rich at 00:40:01) The two ways that I found to be really helpful—and I wish I just started to do this when I was right before I left industry—but one is simulation. So to the extent possible that you can put people in real situations and see how they behave and give them the ability to learn from the behavior, to me is the number one way. So, you know, everybody goes to the classic example of phishing. So, you know, we used to fish the living devil out of people in the organization, and we fished different tiers of people.

(Rich at 00:40:35) We fished engineers differently than we did accountants, and we fished senior management. And we used to play a game with them and say, well, I'll bet you seven drinks on Friday that I'm going to get you this week. And, you know, it was engaging. People wanted to—okay, try. Try to get me. Fish me, you know, or scrape a website that I use all the time and see if I'll give my credentials up. They wanted to do it. It was a game for them. And I think it was really that sort of experiential learning that they loved.

(Rich at 00:41:08) The other thing that I was wanting to do and I never got to was a cybersecurity—not internship, but fellowship, if you will. So bring people from the organization into the cybersecurity team for a two week stint, for a four week stint. Live the experience through our eyes. See what we see on a daily basis from an operational perspective. See what you're doing in the field that's causing us grief and why we come at you with rules and understand it from our side, because we take all of our time trying to understand it from the business perspective to make sure we don't get in your way, to make sure that we don't make your experience less than.

(Rich at 00:41:56) But sometimes you need to understand it from our perspective. And the best way is an immersion. Immersion is the word I was looking for. An immersion program. Put key people in the organization through the team. That's how I learned to be an internal auditor.

(Rich at 00:42:12) So I went into a bank, a big bank management program, and everybody did a two week turn in internal audit and went on an audit to understand the rigor of internal audit and why you do it and what comes out of an internal audit. So that when you were an auditee at some point, you would understand why the auditor was asking questions in the order and why they were asking for documentation and those sort of things. So to me, those are, you know, immersion and learning by doing, I think those are really the two best ways to get the culture of cybersecurity to emerge. Learning management systems are great, but I think in my case, I feel like they're supplemental to those things.

(Joel Beasley at 00:42:54) Yeah, absolutely. That reminds me of—I've heard a lot at the time developer teams will do a thing where they put the developers on sales calls with the sales team and on demos to watch that happen. And it really helps to build not just the empathy for what they're going through, but also it breaks down the walls of the silos and opens up communication between the different teams. And I can totally see how that's also beneficial for cybersecurity. I just haven't heard of the two week thing specifically in cybersecurity before, and that's really cool.

(Rich at 00:43:35) You know, Atlassian, the Confluence folks, they have a video out on YouTube about co-programming, co-coding, right, where two people sit together and write the same program and the advantages of all that. And it's hilarious. I mean, so, you know, try to find it and watch it because they put it in the sense of this partnership you're creating. But, you know, we always knew that even back in the day when I was writing code, not very well, by the way, you know, a code review with people in the room and walking through your logic and the way you did something, knowing that programming is really more of an art than a science. There's twelve ways to get to the same answer.

(Rich at 00:44:18) It just builds a better product. So this whole notion of people working together and doing things in tandem and learning from one another, and you see something I'm not seeing and vice versa, I think, I mean, if that's not the wave of the future, it should be. Certainly the DevOps community, I think, embraces that. I'd love to see the cybersecurity community embrace that as well.

(Joel Beasley at 00:44:43) Yeah. And I like that you brought up that co-programming concept because I think that also ties into earlier when you were talking about thinking critically about your cybersecurity practices and not just doing things out of habit. Because I still do some audio engineering projects after work because I really enjoy doing that. And I like sitting with the person who I'm mixing their project for and having them there because it forces me to have a solid reason for every decision I make and not just do things because that's what I always do.

(Rich at 00:45:21) Right. Right. So there's an epidemic of that, I think, in cybersecurity. I mean, instead of chasing the next tool, which you do need to do, thinking about the process that the tool is going to help. So again, back to the ransomware report, the most startling finding in there, which I have to say made me sweat a little bit, was the very low level of privileged access management that was being done in organizations.

(Rich at 00:45:54) So statistically, I think it was like 80% of organizations have not implemented or only partially implemented a privileged access management tool. And only 36% of organizations that were in the data actually even audited their privileged access. I mean, these are the keys to the kingdom. These are the pot of gold an attacker wants. If an attacker can get in and get those privileged IDs, it's going to give them the ability to stay inside your organization long enough to craft a really good strategy.

(Rich at 00:46:34) Yeah. I mean, think about the Target hack that I think happened, what, in 2015? You know, that was a set of credentials that an HVAC operator had that, you know, gave up in a phishing expedition. And then, you know, the attackers went in, and they found their way to the point of sale terminals. So, I mean, the fact that—that is a basic notion, which is that you need to have people in the organization who can do more than other people in your technical environment, and they need to be controlled in some way.

(Rich at 00:47:12) It's a fundamental notion. To find statistically, at least in our data, that that wasn't top of mind is very concerning. And, you know, you can extrapolate that to the use of service accounts, for example. Service accounts are typically accounts that one computer uses to talk to another computer that's embedded in code, and it's not really supposed to be used by humans to do things. But all the time, humans get that user ID and password and use it in a pinch to do something that they normally would have to go through some hoops to get those privileges.

(Rich at 00:47:47) And it's very dangerous, especially if they leave, and they know those credentials. So, I mean, it's—I can't state it enough, but it's the sense of really just stepping back for a minute and thinking critically about there's these foundational things, vulnerability management, incident management, privileged account management, supply chain risk management, that you really just need to do from a foundational perspective and build on. And if you're missing any of those or you're not doing them well, it's likely contributing to a lesser state of cybersecurity in the organization.

(Joel Beasley at 00:48:28) Well, I think that example that you brought up of people using service accounts when they probably shouldn't be using them for that specific thing is demonstrative of a trend that I've been seeing a lot talking to cybersecurity people, and it's that removing friction in the security process is the best way to get people to be secure. Because if there weren't those hoops to jump through to get access to the other machine, then that person wouldn't use the service account. They would just do it in the secure way.

(Rich at 00:49:04) Sure. Sure. And, you know, implemented well, a privileged access management tool can be a very elegant, simple solution, right? You log into the tool. You know where you need to go. You take a couple of keystrokes. It sends you there. You never see the user ID or password. It logs what you're doing.

(Rich at 00:49:26) It takes the burden off of you as the privileged user to even have to remember that user ID and password and protect it and do all those things. And in some cases, if the tool is really good, it changes that password immediately after it's been used. So these are beautiful solutions that, you know, they can be challenging to implement, particularly if you have a very diverse technical environment and you have to communicate with all this different—you know, we had an AS/400 environment. It isn't particularly happy with some of those tools, you know? But into a server farm or a Nutanix box or something like that, they're made for that.

(Rich at 00:50:07) And taking the time to sort of step back and look at how you do that process in the organization and what tools would work for you, I think, is worth your investment of time. You know? It's just a fundamental thing.

(Joel Beasley at 00:50:21) Yeah. Absolutely. Well, before we wrap up, is there anything that we didn't get to touch on that we want to make sure we hit on? What do you want to be the ending call to action here?

(Rich at 00:50:32) You know, I think that it's interesting how much cybersecurity has advanced, but it's also interesting how much it's still based on the foundations, right? It's still confidentiality, integrity, and availability. It's still looking at where data is stored and transmitted and processed. And it's still a layered approach of administrative, technical, and physical controls.

(Rich at 00:50:53) Those things have not changed in thirty years. It's the world that we apply them to that changed and the controls we use and the tools we use. I think people need to understand that the best approach is to stick with the fundamentals, and it will lead you to the right solutions every time.

(Joel Beasley at 00:51:15) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn, or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.