{"id":49083,"date":"2022-05-04T05:58:19","date_gmt":"2022-05-03T21:58:19","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=49083"},"modified":"2022-05-04T05:58:21","modified_gmt":"2022-05-03T21:58:21","slug":"is-todays-cyber-security-meeting-ciso-demands","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/05\/04\/is-todays-cyber-security-meeting-ciso-demands\/","title":{"rendered":"Is today\u2019s cyber security meeting CISO demands?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Guy Matthews<br>Editor, NetReporter<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The world of cybersecurity is akin to a giant iceberg \u2013 vast, complex, ever-changing, multi-faceted. Of its various facets, one in particular has the power to keep enterprise security professionals awake at night, and that\u2019s the critical intersection that straddles the networking world and the cybersecurity world.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This nexus is not only a major pressure point for the hard-pressed CISO, it is the object of much effort and investment in the security vendor community. It has also been the subject of much scrutiny on the part of Mauricio Sanchez, Research Director, Network Security &amp; SASE\/SDWAN with independent research firm Dell\u2019Oro Group.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He visualises the market for network security as divided between product types that have been around for a while, and newer technologies designed to address more contemporary challenges: \u201cIn the former category we have things like firewalls, email security and secure web gateways,\u201d he says. \u201cSome of these are now delivered as platforms in the cloud. And on the application and delivery and security side, closer to the data center, are things like web application firewalls and application delivery controllers. Then bringing together enterprise networking and security we have SD-WAN and what I call the great convergence of SASE.\u201d<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1.jpg\" alt=\"\" class=\"wp-image-49084\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech1-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><figcaption>Figure 1: Network security trends<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sanchez sees a number of market forces and trends influencing developments in these areas, perhaps the most glaring being the pandemic: \u201cWe&#8217;ve seen a huge increase in incidents, whether that be ransomware or denial of service attacks,\u201d he notes. \u201cIt seems that the hacker community is taking advantage of the current situation. I think hybrid work is a second market force that has resulted in an upheaval of enterprise IT and the rise of the remote workforce. Then there\u2019s the shift to everything being online. The need to reach out to your customer with a digital experience has really motivated enterprises to up their game and invest, but in doing so they also open themselves up to a new set of security implications.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cybersecurity landscape of last 20 years has, argues Sanchez, been a story of fragmentation. Now he sees evidence of some consolidation with large vendors getting larger and looking to grab the entire CISO cybersecurity spend.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2.jpg\" alt=\"\" class=\"wp-image-49085\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/05\/tech2-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><figcaption>Figure 2: Cloud-delivered security<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAnother phenomenon we have noted is a shift from hardware to cloud-delivered network security,\u201d he says. \u201cMoving on from an age of hub and spoke and hardware deployed at each physical point, we now have a new breed of security vendors delivering their value exclusively through the cloud. There is no hardware to buy, just a contract to sign and you&#8217;re off to the races.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CR Srinivasan is Executive Vice President, Cloud &amp; Security Business with global carrier brand Tata Communications, and has additional responsibility as the company\u2019s Chief Information Security Officer and the Chief Information Officer. He has noted a number of large trends that are influencing the shape of the cybersecurity market: \u201cThere\u2019s remote work, and virtual \u2018work from anywhere\u2019,\u201d he notes. \u201cA distributed workforce is now the norm. We\u2019ve also seen many enterprises pushing for their processes to become digital, a trend that accelerated during the pandemic. There was demand to increase the number of processes that were part of the digital transformation drive. Then of course there\u2019s the move to cloud, which has also been accelerated with more and more workloads moving in that direction. All of this is putting pressure on network security.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He additionally sees enterprises being challenged more and more by their customers: \u201cThose customers are looking for new capabilities, and at a faster pace than before. Businesses must keep up with market expectations, and compete effectively. This means becoming a lot more dynamic and composable, more flexible in what they do. And along with all of this, digital trust is becoming more important.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dr Ronald Layton, Vice President, Converged Security Operations with Sallie Mae Bank, knows a thing or two about digital trust. Prior to Sallie Mae, he was acting assistant director in the United States Secret Service with a variety of responsibilities, including an assignment to President Obama which saw him put in charge of the day to day operations and long term strategy of presidential information systems. He\u2019s also a former Deputy Director of the National Cybersecurity Division, and Program Director of the Electronic Crimes Task Force. He describes himself as \u2018the guy with a geek hat and a pistol\u2019.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAs cyber risk professionals, we continue to embrace human behavior and try to wrap security blankets around it,\u201d he says. \u201cI see security as being about three Cs. Human beings are curious, we want convenience and we want to be comfortable, and so all of these things provide challenges in the security environment. As risk professionals, we have to continue to evolve and respond to these things.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given the current climate of raised risk, what should a CISO or a risk executive be doing? Dr Layton\u2019s advice is foremost to push towards a SASE environment, and towards the notion of Zero Trust: \u201cIt\u2019s about how do we, as risk professionals, adjust to these human behaviors, to make sure that we&#8217;re still operating in a secure environment,\u201d he concludes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So just what is the nature of all this risk? Ryan Hammer, Chief Information Security Officer with vendor Ciena, is responsible for the overall strategy and execution of the company\u2019s enterprise and product security functions. He points to statistics that indicate that an unpatched machine with Internet connectivity can now measure its survival in minutes, perhaps hours, but certainly not weeks or months.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWith some of the kinetic warfare activity that&#8217;s occurring, we\u2019ve seen governance loosened,\u201d he believes. \u201cThe Internet is starting to feel more like a free fire warzone than just a rough neighborhood. Certain sectors are being hit much harder than others. But with a pervasive and porous perimeter, with machines and people all over the world working at various different hours connecting to a wide range of infrastructure, that makes it much more difficult for us to manage without some of these additional technologies. It&#8217;s a very rapidly changing landscape for sure, and the deck is often stacked against us as CISOs. It&#8217;s the old adage that the threat actor only has to be successful once and we have to be successful every time.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With Zero Trust one of the best answers to all this increased risk, it\u2019s useful to hear from John Kindervag, SVP, Cybersecurity Strategy with managed security services player ON2IT. He formerly spent eight years at analyst firm Forrester where he invented the concept of Zero Trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He pinpoints the ransomware trend as one of the great modern cybersecurity evils: \u201cWhen people started to insure for ransomware, that ended up increasing the number of ransomware attacks,\u201d he says. \u201cIt\u2019s just like when life insurance was invented, there was a rash of murders. The invention of cyber insurance has created a surge of attacks which at the end of the day means that when CISOs want to innovate, they need to think what that really means.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Given current conditions, Ben de Bont, Chief Information Security Officer, ServiceNow, sees his role as a threefold one: \u201cIt\u2019s about protecting our company and our customers on the one hand, second it is to provide trust, transparency and assurance to our customers, many of whom represent the most regulated or critical infrastructure globally. The third part is using our own security products, testing them out, providing feedback to our product division.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So with the cyber climate as it is, what are vendors of security solutions doing to help? How can they better come to the aid of the CISO?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIf you look at the vendor landscape there are probably 50 to 100 vendors who are all doing different things,\u201d believes Srinivasan of Tata Communications. \u201cSome of them are specializing in a very small area, and some claim to do many things under a framework but may not have equal capability or equal depth in each one of those areas. I think there&#8217;s a lot of help that&#8217;s needed in the areas we\u2019ve discussed.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hammer of Ciena is in agreement: \u201cI&#8217;ll add that there&#8217;s lots of acronyms in security, but to me that\u2019s just a reminder that it&#8217;s important to have a focus on the basics,\u201d he observes. \u201cIt\u2019s one thing to be focussing on your AI DevSecOps strategy, but really we need to focus on the fundamentals and make sure that those are rock solid.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kindervag of ON2IT steps in to remind those who are suffering from terminology confusion and tech overload that Zero Trust should be regarded as a strategy and not a technology: \u201cWhen you take a strategic approach, you can change the whole game,\u201d he notes. \u201cWhen I joined Forrester in 2008, I wanted to bring strategy to cybersecurity because most people get confused between strategy and tactics. They say they&#8217;re being strategic, but they&#8217;re actually being tactical. Zero Trust is about protecting things, and if we don&#8217;t understand what we&#8217;re protecting then we&#8217;re going to be completely unsuccessful.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cA rule of thumb that I use is to tell security vendors what our requirements are for driving down risk, and not have them tell us what solutions they say we should be using,\u201d interjects de Bont of ServiceNow. \u201cWe like to take a risk-based approach and look at what we actually want to achieve. And then we&#8217;ll consider some products, rather than the other way around. It&#8217;s a little surprising to me how many times it happens in reverse.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When talking to the vendor community, CISOs might wonder exactly what gaps they need to address and where priorities truly lie.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rarely is anything straight forward in the information security world, and seldom do easy answers present themselves reminds Hammer, of Ciena: \u201cIt all moves so fast and changes so continually,\u201d he comments. \u201cWe&#8217;re constantly planning and checking to make sure that everything is in place. One important thing is being able to demonstrate that you have a commercially reasonable security program in place. It is also important that we remember that we are stewards of the security program for our company, and we&#8217;re responsible for making sure that all the pieces are in place, and that we can comfortably demonstrate traceability between the things that we should be doing and the things that we are doing. Sometimes it\u2019s about protecting the business, other times about protecting customer data, or access our partners, or intellectual property and securing our products.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a complex landscape, Srinivasan of TATA advocates a practical and pragmatic approach: \u201cLook for a commercially viable security program and not something that you would ideally like to have,\u201d he suggests. \u201cBecause there\u2019s always a trade-off between what risk you&#8217;re trying to protect against, and cost.\u201d Dr Layton of Sallie Mae Bank, the geek with the gun, concludes by advising the CISO to do what they can to take the element of human error out of risk: \u201cJust make it hard for humans to do something that is just screwy. As a risk executive, what you&#8217;re really trying to do is eliminate surprise, and to control your environment. You should never be ambushed by some exogenous factor that you did not make an account for. It\u2019s about putting in all these trip wires so at least you have a better idea of what&#8217;s coming.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The world of cybersecurity is akin to a giant iceberg \u2013 vast, complex, ever-changing, multi-faceted. Of its various facets, one in particular has the power to keep enterprise security professionals awake at night, and that\u2019s the critical intersection that straddles the networking world and the cybersecurity world.<\/p>\n","protected":false},"author":7,"featured_media":48152,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[54,2103],"class_list":["post-49083","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=49083"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/49083\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/48152"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=49083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=49083"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=49083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}