معلومات عن هذه الحلقة
On this episode of the IT Matters Podcast, our host is joined by Michael Irwin, CISO for Odyssey Logistics, to discuss the challenges and misconceptions in the cybersecurity industry. Together, the emphasize the importance of understanding one's environment, prioritizing proactive measures over reactive chaos, and addressing legacy infrastructure.
Conversation Highlights:
0:00 Michael Irwin, CISO for Odyssey Logistics
[6:05] Michael's Cybersecurity Journey
[8:54] Challenges in Cybersecurity Investment
[15:22] Proactive Disruption vs. Reactive Chaos
[31:47] Advice for Emerging Cybersecurity Leaders
Notable Quotes:
"Cybersecurity is asymmetrical in general. We have to protect everything, and a bad actor has to find the one thing that we didn't protect." - Michael Irwin [9:10]
"Focusing on positive culture and work-life balance and really supporting the people on your team moves the needle more than anything else." - Michael Irwin [33:40]
Connect with Michael Irwin on LinkedIn.
Read the transcript: Episode 40
The IT Matters Podcast is about IT matters and matters pertaining to IT. It is produced by Opkalla, a technology advisory firm that helps their clients navigate the confusion in the technology marketplace and choose the solution that is right for their business.
في هذه الحلقة
وتظهر الملاحظات 🔗
النص 🔗
00:00:00,900 --> 00:00:03,570
Aaron Bock: Welcome to the IT
Matters podcast, hosted by
2
00:00:03,570 --> 00:00:07,500
Opkalla. We're an IT advisory
firm that makes technology easy
3
00:00:07,500 --> 00:00:10,650
for your business. Our
vendor-neutral technology
4
00:00:10,650 --> 00:00:14,580
advisors work directly with your
team to assess technology needs
5
00:00:14,580 --> 00:00:18,030
and procure the best IT
solutions for your organization.
6
00:00:18,030 --> 00:00:20,790
On this podcast, expect
high-level expertise from our
7
00:00:20,790 --> 00:00:24,675
hosts, plus experience-driven
perspective from the leading
8
00:00:24,675 --> 00:00:28,815
experts on topics like AI,
cybersecurity, industry-focused
9
00:00:28,815 --> 00:00:33,525
IT solutions strategy, and more.
Now let's get into today's
10
00:00:33,525 --> 00:00:35,745
discussion on what matters in
IT.
11
00:00:35,745 --> 00:00:39,045
Keith Hawkey: And welcome back
to the IT Matters podcast,
12
00:00:39,045 --> 00:00:44,325
hosted by Opkalla. At Opkalla,
we help IT teams understand the
13
00:00:44,325 --> 00:00:48,300
busy marketplace of technology
strategy and services with a
14
00:00:48,300 --> 00:00:51,930
data-driven approach. And on
this podcast, we invite
15
00:00:51,930 --> 00:00:55,080
technology leaders to discuss
the challenges facing the modern
16
00:00:55,080 --> 00:01:01,230
IT department. My name is Keith
Hawkey, technology and podcast
17
00:01:01,230 --> 00:01:06,150
host of Opkalla, welcome to the
IT Matters Podcast. Today's
18
00:01:06,150 --> 00:01:09,465
episode is going to be a little
different, in a good way,
19
00:01:09,465 --> 00:01:13,695
because we're going to challenge
some of the assumptions that
20
00:01:13,695 --> 00:01:16,185
have become pretty standard
across the cyber security
21
00:01:16,185 --> 00:01:20,955
industry. We hear all the time,
more spend, more tools, more
22
00:01:20,955 --> 00:01:25,215
complexity, but at the same time
breaches aren't slowing down,
23
00:01:25,215 --> 00:01:28,185
and I think a lot of the
technology leaders are starting
24
00:01:28,185 --> 00:01:33,060
to ask a simple question: Are we
actually getting better or just
25
00:01:33,060 --> 00:01:38,460
getting busier? I'm joined today
by Michael Irwin, CISO for
26
00:01:38,460 --> 00:01:42,630
Odyssey Logistics, who brings a
perspective that I think cuts
27
00:01:42,630 --> 00:01:47,400
through a lot of that noise.
Michael has spent time inside
28
00:01:47,400 --> 00:01:50,640
environments where the stakes
are real and the constraints are
29
00:01:50,640 --> 00:01:54,750
real and the decisions aren't
made in a vacuum, and he's not
30
00:01:54,750 --> 00:01:57,165
afraid to call out where he
thinks the industry might be
31
00:01:57,165 --> 00:02:00,945
getting it wrong. And in this
conversation, we're going to get
32
00:02:00,945 --> 00:02:04,185
into where cybersecurity
investment might be missing the
33
00:02:04,185 --> 00:02:08,985
mark, and how to think about
trade-offs between operational
34
00:02:08,985 --> 00:02:13,845
friction and real risk, and why
it matters when you don't have
35
00:02:13,845 --> 00:02:19,200
enterprise-level budgets or
resources. Michael, welcome to
36
00:02:19,200 --> 00:02:21,120
the IT Matters podcast.
37
00:02:21,680 --> 00:02:22,430
Michael Irwin: Thank you for
having me.
38
00:02:24,590 --> 00:02:28,700
Keith Hawkey: So, there, okay?
Before we begin, there's a
39
00:02:28,850 --> 00:02:35,270
little game that we play here to
prime the session. Have you ever
40
00:02:35,450 --> 00:02:37,220
played Two Truths and a Lie?
41
00:02:39,320 --> 00:02:40,870
Michael Irwin: Two Truths and a
Lie. I have. Yes,
42
00:02:41,830 --> 00:02:44,020
Keith Hawkey: the name is a
little bit self-explanatory, so
43
00:02:44,920 --> 00:02:48,790
I'll.. these are cyber security.
Well, actually, today it's a
44
00:02:48,880 --> 00:02:51,040
little less cyber security
related, but it's tech related.
45
00:02:51,610 --> 00:02:59,020
Okay, and let's see if you can
guess what the lie is out of
46
00:02:59,110 --> 00:03:08,310
these. So the number one AI
powered holographic companions
47
00:03:08,460 --> 00:03:15,510
were introduced that sit on your
desk, talk to you, and help with
48
00:03:15,600 --> 00:03:20,010
task, and even give you personal
advice. This was introduced at
49
00:03:20,100 --> 00:03:26,990
the latest CES consumer
electronics show this year.
50
00:03:28,250 --> 00:03:32,660
Number two, a startup has
created a device that lets you
51
00:03:32,930 --> 00:03:37,340
upload your dreams and share
them like videos with other
52
00:03:37,460 --> 00:03:44,560
people. Number three, robot
vacuums are being designed with
53
00:03:44,800 --> 00:03:49,180
legs, so they can climb stairs
and move between floors without
54
00:03:49,300 --> 00:03:54,670
human help. Let me know if you'd
like me to repeat any of these.
55
00:03:55,180 --> 00:03:57,340
Michael Irwin: Well, I'd say in
this day and age, anything AI
56
00:03:57,580 --> 00:03:59,890
related is perfectly feasible,
that somebody's selling a
57
00:03:59,950 --> 00:04:02,850
product with it, right. So I
don't want to go towards that
58
00:04:04,230 --> 00:04:08,370
one. Let's see, the I think I
had seen something about some
59
00:04:08,460 --> 00:04:12,660
brain scan related imagery for
dreams, or associating that, but
60
00:04:13,050 --> 00:04:15,270
that would normally be where I
jump to. But I think I'll stick
61
00:04:15,330 --> 00:04:18,480
to the simple robot vacuum with
legs. I have one, and it rolls
62
00:04:18,570 --> 00:04:21,050
around the house, and it's
gotten smart, but legs it has
63
00:04:21,140 --> 00:04:22,340
not gotten yet.
64
00:04:24,000 --> 00:04:29,460
Keith Hawkey: Well, I'll have to
say much to your amusement.
65
00:04:29,460 --> 00:04:33,000
Robots do have legs now. Our
robot back of the vacuum
66
00:04:33,000 --> 00:04:41,940
apparently company named let's
see Robo Rock unveiled devices
67
00:04:41,940 --> 00:04:46,440
like the Soros rover, featuring
a wheel leg design that can
68
00:04:46,440 --> 00:04:50,445
actually climb and clean stairs,
something traditional vacuums
69
00:04:50,445 --> 00:04:52,305
have never been able to do.
70
00:04:52,425 --> 00:04:54,525
Michael Irwin: Wheels and legs,
though, that seems different,
71
00:04:54,525 --> 00:04:58,095
though. I wouldn't call wheels
legs, there's a trick,
72
00:04:58,000 --> 00:05:02,650
Keith Hawkey: Maybe it was,
maybe. A trick, and in addition,
73
00:05:03,460 --> 00:05:09,550
the gaming component company
Razor has come out with an
74
00:05:09,610 --> 00:05:17,590
AI-powered holographic companion
that it's actually very strange.
75
00:05:17,620 --> 00:05:21,880
It sits on your desk, and you
can talk to it much like I guess
76
00:05:21,880 --> 00:05:25,930
an Alexa, but there's a visual
component to it. It sits in like
77
00:05:25,930 --> 00:05:31,420
a little box, and you can adjust
the looks, and it speaks to you.
78
00:05:32,380 --> 00:05:34,570
They are calling it Project Ava.
79
00:05:34,930 --> 00:05:35,470
Michael Irwin: Oh,
80
00:05:36,310 --> 00:05:39,070
Keith Hawkey: and to my
knowledge, you might have
81
00:05:39,070 --> 00:05:43,510
knowledge that I don't. I don't
think there's been major news of
82
00:05:43,510 --> 00:05:47,320
a startup that has a device that
captures your dreams quite yet.
83
00:05:47,320 --> 00:05:52,300
However, honestly, I might just
not be read in on that
84
00:05:52,300 --> 00:05:53,440
information yet. Well,
85
00:05:53,440 --> 00:05:56,290
Michael Irwin: no, I think I
read something about like brain
86
00:05:56,290 --> 00:05:59,530
activity during dreaming and
sleeping and tracking that, but
87
00:05:59,560 --> 00:06:01,900
certainly you're not going to
have a video of what that dream
88
00:06:01,900 --> 00:06:04,960
was, I'm sure. So, no, that's
interesting to hear.
89
00:06:05,350 --> 00:06:07,510
Keith Hawkey: Yeah, I'm sure.
I'm sure it's coming, coming
90
00:06:07,510 --> 00:06:13,630
very soon. So, let's, you know,
a lot of what this episode is
91
00:06:13,630 --> 00:06:18,250
about is challenging assumptions
that are industry-wide within
92
00:06:18,250 --> 00:06:21,160
the cybersecurity landscape and
industry, and it's gone through
93
00:06:21,160 --> 00:06:25,030
a tremendous amount of change
over the last five years, last
94
00:06:25,030 --> 00:06:28,930
decade. Before we start, there,
Michael, can you tell us a
95
00:06:28,930 --> 00:06:33,730
little bit about how did you get
into it? How'd you get into
96
00:06:33,730 --> 00:06:36,430
cybersecurity? A little bit
about your journey, and kind of
97
00:06:36,460 --> 00:06:38,680
where you got, how'd you get to
where you are now?
98
00:06:39,430 --> 00:06:41,740
Michael Irwin: Sure, yeah, my
really, my entire career path
99
00:06:41,740 --> 00:06:45,910
has been IT oriented, so I kind
of started my career in managed
100
00:06:45,910 --> 00:06:49,360
service provider space, small,
midsize consulting, or IT
101
00:06:49,360 --> 00:06:53,050
consulting, which I think is
pretty common. Ultimately, at
102
00:06:53,050 --> 00:06:55,270
that time, was looking for an
organization that I could really
103
00:06:55,300 --> 00:06:57,850
establish roots at, and
something that I could see the
104
00:06:57,850 --> 00:07:00,430
long-term value of the work that
I was doing, rather than kind of
105
00:07:00,430 --> 00:07:03,430
jumping into each fire, as I was
kind of going customer to
106
00:07:03,430 --> 00:07:06,460
customer, and so that landed me
at a media company in
107
00:07:06,490 --> 00:07:09,730
Washington, DC. So it's an ABC
Seven affiliate, but also a
108
00:07:09,730 --> 00:07:14,110
media company that focused on
political media, and I started
109
00:07:14,110 --> 00:07:16,210
with them kind of as a
consultant, as somebody that was
110
00:07:16,210 --> 00:07:19,360
helping during the transition of
a previous employee, and just
111
00:07:19,390 --> 00:07:21,640
was able to find an opportunity
there, and that was something
112
00:07:21,640 --> 00:07:24,670
that I kind of grew through the
help desk space, really, and
113
00:07:24,880 --> 00:07:28,450
more IT generalist at the
beginning, but the track of help
114
00:07:28,450 --> 00:07:31,900
desk management leading into IT
director kind of roles, and then
115
00:07:32,020 --> 00:07:34,690
really building a cybersecurity
program at that organization
116
00:07:34,690 --> 00:07:37,630
within kind of the efficiencies
that we found within the IT
117
00:07:37,630 --> 00:07:41,530
budget allowed us to really
align those two things, I was
118
00:07:41,530 --> 00:07:44,980
there for about 12 years, and
then ended up transitioning to
119
00:07:44,980 --> 00:07:47,710
another organization when I
moved down to Charlotte, North
120
00:07:47,710 --> 00:07:49,930
Carolina. So, obviously,
logistics were headquartered
121
00:07:49,930 --> 00:07:53,470
down here. I always, I always
enjoyed the fact that
122
00:07:53,470 --> 00:07:57,010
cybersecurity is really industry
agnostic. I was kind of curious
123
00:07:57,010 --> 00:07:59,140
about the idea of can I
replicate the things that I did
124
00:07:59,140 --> 00:08:01,750
in this organization, and can I
bring value with that to
125
00:08:01,750 --> 00:08:03,880
another, and that was kind of
one of the things that I was
126
00:08:03,880 --> 00:08:06,760
looking for coming here.
Obviously, Odyssey Logistics is
127
00:08:06,760 --> 00:08:09,760
a much larger organization,
we're a global multi-multimodal
128
00:08:09,760 --> 00:08:12,250
logistics provider, and so we
had a lot of presence kind of
129
00:08:12,250 --> 00:08:15,640
around the world, including in
the United States. So, bigger
130
00:08:15,640 --> 00:08:18,700
teams, kind of bigger budget
opportunities, kind of bigger
131
00:08:18,700 --> 00:08:20,980
scope of responsibility, and I
think all of that was an
132
00:08:20,980 --> 00:08:24,340
interesting challenge, and what,
what I found was much of my
133
00:08:24,340 --> 00:08:27,250
roadmap at an organization that
was significantly smaller in a
134
00:08:27,250 --> 00:08:30,130
different industry really
resonated in this one. Also, it
135
00:08:30,130 --> 00:08:33,040
added a lot of value, they had
the similar challenges, they
136
00:08:33,040 --> 00:08:35,200
might have been at different
stages of maturity, kind of in
137
00:08:35,200 --> 00:08:38,200
their technology journey, but
really a lot of close alignment,
138
00:08:38,200 --> 00:08:40,810
and I think that was really eye
opening to me, how a lot of
139
00:08:40,810 --> 00:08:43,990
those kind of simple things were
able to land in such a good way.
140
00:08:43,990 --> 00:08:46,840
So that's kind of how I found
myself here. I was brought in to
141
00:08:46,840 --> 00:08:50,050
build a security program,
primarily, but early on was kind
142
00:08:50,050 --> 00:08:52,810
of given responsibility for the
IT operations function as well.
143
00:08:54,280 --> 00:08:56,470
Keith Hawkey: And you've said
the cybersecurity industry as a
144
00:08:56,470 --> 00:09:02,620
whole has failed, despite record
spend and tooling, what do you
145
00:09:02,620 --> 00:09:06,190
mean by that? What, what are we
measuring wrong exactly?
146
00:09:06,660 --> 00:09:08,730
Michael Irwin: Yes, man, at the
end of the day, it's kind of the
147
00:09:08,730 --> 00:09:12,000
nature of the function, right?
Cybersecurity is asymmetrical in
148
00:09:12,000 --> 00:09:14,730
general. We have to protect
everything, and a bad actor has
149
00:09:14,730 --> 00:09:17,460
to find the one thing that we
didn't protect. So, the odds are
150
00:09:17,460 --> 00:09:20,490
kind of set against you to begin
with, but I think what you look
151
00:09:20,490 --> 00:09:22,530
at is, you have a lot of
conversations around budget
152
00:09:22,530 --> 00:09:27,240
opportunity, team size, resource
challenges, alert fatigue, like
153
00:09:27,240 --> 00:09:29,610
there's all these conversations
about the challenges in the
154
00:09:29,655 --> 00:09:32,475
space where generally, and
everyone would say they don't
155
00:09:32,475 --> 00:09:35,655
quite have enough cybersecurity
budget right now, but generally
156
00:09:35,655 --> 00:09:38,355
speaking, cybersecurity budgets
have grown annually. Most
157
00:09:38,355 --> 00:09:41,445
organizations are spending more
than they ever have. Most
158
00:09:41,445 --> 00:09:43,995
organizations are building
cybersecurity departments or
159
00:09:43,995 --> 00:09:47,625
functions that maybe lived
inside of an IT operation
160
00:09:47,625 --> 00:09:51,495
function historically, and so
the function is growing. There
161
00:09:51,495 --> 00:09:54,540
is no shortage of tools and
services in the space that you
162
00:09:54,540 --> 00:09:57,510
can buy to solve your
challenges, and so you're
163
00:09:57,510 --> 00:09:59,700
spending more, you have access
to more technology, you have
164
00:09:59,700 --> 00:10:02,940
access. More resources, but
breach incidents grow and grow,
165
00:10:02,940 --> 00:10:06,510
right? And the breaches you hear
about aren't at every small mom
166
00:10:06,510 --> 00:10:09,330
and pop shop, but they are
organizations that might be ISO
167
00:10:09,330 --> 00:10:12,750
27,001 compliant. They might
have a SOC two type two. So, if
168
00:10:12,750 --> 00:10:14,850
you have these mature
organizations that are still
169
00:10:14,850 --> 00:10:18,585
experiencing breaches, and you
assume that they likely have
170
00:10:18,585 --> 00:10:21,105
more adequate funding and
resources to monitor what's
171
00:10:21,105 --> 00:10:24,015
going on, like, how does that
reconcile, right? And I think a
172
00:10:24,015 --> 00:10:25,965
lot of it is, we're measuring
effort, we're not measuring
173
00:10:25,965 --> 00:10:30,915
outcomes, we're still looking at
kind of identity, is still that
174
00:10:30,915 --> 00:10:33,015
perimeter that we're dealing
with, we're still looking at
175
00:10:33,015 --> 00:10:35,865
this castle concept in a lot of
ways, we're dealing with a lot
176
00:10:35,865 --> 00:10:38,640
of legacy infrastructure, and I
think a lot of that is that
177
00:10:38,640 --> 00:10:41,250
misalignment between
cybersecurity and technology,
178
00:10:41,250 --> 00:10:44,340
much of the risk we deal with in
this space lives in the legacy
179
00:10:44,340 --> 00:10:46,830
world, and if you have a
technology roadmap that's not
180
00:10:46,830 --> 00:10:49,770
focusing on that, or you're not
focusing on the kind of the
181
00:10:49,770 --> 00:10:53,130
housekeeping basics of stale
accounts, or permissioning
182
00:10:53,130 --> 00:10:56,280
creep, or configuration
problems, if you're not focusing
183
00:10:56,280 --> 00:10:58,890
there, but you're focusing on
that new tool, you're likely
184
00:10:58,890 --> 00:11:01,440
missing the mark of where the
majority of the trouble is.
185
00:11:03,210 --> 00:11:08,805
Keith Hawkey: Yeah, I think
you're exactly right. Just wait
186
00:11:08,805 --> 00:11:10,965
for Gartner to come out with a
new three or four letter
187
00:11:10,965 --> 00:11:17,085
acronym, and to start a buying
cycle for said tooling, and a
188
00:11:17,085 --> 00:11:20,775
lot of that's laying on top of
where the real risk lies, which
189
00:11:20,775 --> 00:11:23,775
is a lot of the maybe
traditionally on on-prem
190
00:11:23,775 --> 00:11:28,440
infrastructure, some of the,
some of the policies, the holy
191
00:11:28,440 --> 00:11:32,550
grails of organizations that new
IT leaders don't really want to
192
00:11:32,550 --> 00:11:39,540
touch, because they're afraid to
break certain things. You, you
193
00:11:39,540 --> 00:11:44,190
shared an experience where
delaying MFA implementation led
194
00:11:44,190 --> 00:11:48,555
to a major incident. Can you
walk us through that decision
195
00:11:48,555 --> 00:11:52,455
process, like what pressures
were at play, and what you would
196
00:11:52,455 --> 00:11:56,085
do differently today? That's a
kind of personal antidote we had
197
00:11:56,085 --> 00:11:58,845
spoken about, but I'm sure that
would resonate with some of
198
00:11:58,845 --> 00:12:00,615
these cyber security leaders out
there.
199
00:12:00,615 --> 00:12:02,565
Michael Irwin: Sure, I mean,
this story is pretty
200
00:12:02,565 --> 00:12:05,385
straightforward, and hopefully
for most people listening now,
201
00:12:05,385 --> 00:12:08,355
like this isn't still an active
problem, because these controls
202
00:12:08,355 --> 00:12:11,190
have been needed for quite a
long time. But earlier on, when
203
00:12:11,190 --> 00:12:14,700
I was dealing with this issue,
what it boils down to is the
204
00:12:14,700 --> 00:12:17,580
usage of multifactor
authentication alongside the
205
00:12:17,580 --> 00:12:20,760
usage of single sign on as a
larger initiative, so getting
206
00:12:20,760 --> 00:12:23,970
away from distinct username and
passwords for each service, more
207
00:12:23,970 --> 00:12:26,760
central identity management,
ensuring that you have the right
208
00:12:26,760 --> 00:12:29,250
password policies, ensuring that
you have multi factor
209
00:12:29,250 --> 00:12:32,370
authentication for everything,
and the expansion of that effort
210
00:12:32,370 --> 00:12:34,815
is something I think a lot of
organizations have are either
211
00:12:34,815 --> 00:12:38,595
actively going through today or
have dealt with in the past, and
212
00:12:38,595 --> 00:12:41,745
during this time we were
expanding on single sign on in
213
00:12:41,745 --> 00:12:44,655
that, in our, in that particular
moment, there was a lot of
214
00:12:44,655 --> 00:12:47,655
friction relating to kind of
user experience challenges, and
215
00:12:47,655 --> 00:12:50,595
so users had a particular
understanding of what they
216
00:12:50,595 --> 00:12:53,025
wanted to do, what they thought
was appropriate, what might
217
00:12:53,025 --> 00:12:56,475
impact their productivity, they
had preferences on what tooling
218
00:12:56,475 --> 00:12:59,010
they got to use, or
collaboration suites, and so it
219
00:12:59,010 --> 00:13:02,610
was a very kind of user
experience oriented culture
220
00:13:02,610 --> 00:13:05,400
there, and they preventing any
interruption to productivity
221
00:13:05,400 --> 00:13:09,000
culture, and so with that, we
rolled out single sign on. We
222
00:13:09,000 --> 00:13:11,850
had documentation and training
around how to enroll your MFA
223
00:13:11,850 --> 00:13:16,080
device, how to log in. That was
all great. As we went to expand
224
00:13:16,080 --> 00:13:19,020
that functionality, we ran into
a particular function, so VPN
225
00:13:19,020 --> 00:13:21,825
connectivity, that is something
that traditionally didn't use
226
00:13:21,825 --> 00:13:24,585
multifactor authentication. You
might be using simple username
227
00:13:24,585 --> 00:13:28,065
and passwords in order to
integrate that functionality
228
00:13:28,065 --> 00:13:30,825
into that same single sign on
system, maintaining the same
229
00:13:30,825 --> 00:13:33,075
ease of use that customer or
that employees were
230
00:13:33,075 --> 00:13:36,915
experiencing. We weren't able to
do that immediately, so it had
231
00:13:36,915 --> 00:13:40,545
some native functionality built
in, some email based time codes,
232
00:13:40,545 --> 00:13:44,610
things like that, but didn't yet
support the integration with our
233
00:13:44,610 --> 00:13:48,090
existing identity provider, and
so what we chose to do was say
234
00:13:48,090 --> 00:13:50,940
rather than teach something
else, rather than teach this new
235
00:13:50,940 --> 00:13:54,810
way of logging in, we're going
to upgrade our firewall, we're
236
00:13:54,810 --> 00:13:56,580
going to upgrade that firmware,
we're going to get that
237
00:13:56,580 --> 00:13:59,520
compatibility, and then we're
going to roll out the way that
238
00:13:59,520 --> 00:14:03,480
we intended to, it's effectively
looking for the perfect solution
239
00:14:03,480 --> 00:14:07,815
instead of progress, and in our
case that decision, which really
240
00:14:07,815 --> 00:14:11,625
was just a delay of a few
months, ultimately resulted in a
241
00:14:11,625 --> 00:14:14,955
large-scale incident that
required quite a lot of kind of
242
00:14:14,955 --> 00:14:18,585
effort and financial resources
to remediate, and ultimately was
243
00:14:18,585 --> 00:14:21,615
handled all right, but it's one
of those things that you have to
244
00:14:21,615 --> 00:14:23,865
kind of go back and think, if I
had prioritized differently,
245
00:14:23,865 --> 00:14:27,345
would this incident have
happened? I'm a big proponent of
246
00:14:27,345 --> 00:14:31,500
not looking back with the same
sort of perspective and saying,
247
00:14:31,500 --> 00:14:34,980
you know, there's something we
did do that didn't allow an
248
00:14:34,980 --> 00:14:37,560
incident to happen. So, when you
flip priorities, you can't just
249
00:14:37,560 --> 00:14:40,680
say that it wouldn't have
happened that way. That benefit
250
00:14:40,680 --> 00:14:43,170
of hindsight, I think, doesn't
favor people in this space very
251
00:14:43,170 --> 00:14:46,110
well, and so I think that's one
that I try to look back at, is
252
00:14:46,110 --> 00:14:48,900
whether I'd make the same
decision, and in my case, I
253
00:14:48,900 --> 00:14:53,145
think what the way I approach
things today is more in a
254
00:14:53,145 --> 00:14:57,045
vacuum, it's more risk-focused,
it's saying if the worst were to
255
00:14:57,045 --> 00:14:59,535
happen, what's the impact of
this thing, this control that
256
00:14:59,535 --> 00:15:02,565
we're trying to. Impact really
taking all of the other factors
257
00:15:02,565 --> 00:15:05,715
out of it and saying what's the
what's the right thing to do
258
00:15:05,715 --> 00:15:08,655
first and then starting to look
at how you can kind of modify
259
00:15:08,655 --> 00:15:11,865
that and fit into a larger
strategy but when when you're
260
00:15:11,865 --> 00:15:15,600
looking at something purely from
the angle of satisfaction I
261
00:15:15,600 --> 00:15:19,470
think you miss some of the the
signs of higher level of urgency
262
00:15:19,470 --> 00:15:23,010
relative to the risk you're
actually dealing with,
263
00:15:23,010 --> 00:15:24,810
Keith Hawkey: And those are
those are great points, Michael.
264
00:15:24,810 --> 00:15:29,220
It actually goes, flows into the
same vein of other points that
265
00:15:29,220 --> 00:15:33,330
you've argued that proactive
disruption is much, much
266
00:15:33,330 --> 00:15:38,385
preferred than reactive chaos. I
actually love that, that way of
267
00:15:38,385 --> 00:15:43,455
phrasing, proactive disruption
is better than reactive chaos,
268
00:15:43,455 --> 00:15:47,595
which is much of what an IT or
cyber security leader is dealing
269
00:15:47,595 --> 00:15:54,795
with today. A lot of them are
reactive in the chaos, and some
270
00:15:54,795 --> 00:15:58,905
are, I think, are a little bit
too slow to engage and make the
271
00:15:58,905 --> 00:16:02,295
case for that proactive
disruption, whether it's
272
00:16:02,775 --> 00:16:07,920
password rotations, whether it's
service accounts or restarting
273
00:16:07,920 --> 00:16:12,510
aging infrastructure. How do you
decide when to accept that
274
00:16:12,510 --> 00:16:16,590
operational pain today versus
the risk to tomorrow? Do you
275
00:16:16,590 --> 00:16:18,690
have a framework that you work
off of?
276
00:16:18,730 --> 00:16:21,077
Michael Irwin: I wouldn't call
it a framework necessarily, but
277
00:16:21,127 --> 00:16:24,175
I think a general principle is
that if we're nervous to touch
278
00:16:24,225 --> 00:16:27,222
it, then we need to touch it,
right? It gets this idea of if
279
00:16:27,272 --> 00:16:30,369
there's uncertainty like that,
need that means we need to act,
280
00:16:30,419 --> 00:16:33,566
and ultimately, if we're going
to take the hit, I'd rather take
281
00:16:33,616 --> 00:16:36,214
it on my own terms. So, if we
have change management
282
00:16:36,264 --> 00:16:39,261
procedures and we're evaluating
what the outcome might be if
283
00:16:39,311 --> 00:16:41,809
something bad happens, we
understand what rollback
284
00:16:41,859 --> 00:16:44,906
procedures we have, or we can
control it. We have the ability
285
00:16:44,956 --> 00:16:47,804
to fill in the gaps on that
uncertainty more proactively,
286
00:16:47,854 --> 00:16:51,001
and so I would say it's less of
a framework, so much as you are
287
00:16:51,051 --> 00:16:54,048
developing policies and program
guidelines that force you to
288
00:16:54,098 --> 00:16:56,696
touch everything. You need to
audit and evaluate the
289
00:16:56,746 --> 00:16:59,493
infrastructure you have. You
need to do proactive patch
290
00:16:59,543 --> 00:17:02,391
management and vulnerability
management on infrastructure
291
00:17:02,441 --> 00:17:05,638
that will require restarts, you
need to be rotating passwords on
292
00:17:05,688 --> 00:17:08,935
service accounts that have maybe
been around for a long time. You
293
00:17:08,985 --> 00:17:12,082
need infrastructure to do that
more automatically. You need to
294
00:17:12,132 --> 00:17:15,329
be able to have those processes
in place that require you to run
295
00:17:15,379 --> 00:17:18,227
into these problems, because
ultimately, when an incident
296
00:17:18,277 --> 00:17:21,524
happens, the first thing they're
going to do is have you restart,
297
00:17:21,574 --> 00:17:24,771
reset everything, every password
in the organization. They might
298
00:17:24,821 --> 00:17:28,018
be accounts you don't know where
they live, right? They're going
299
00:17:28,068 --> 00:17:31,115
to have you segment off areas of
the network to avoid kind of
300
00:17:31,165 --> 00:17:33,863
lateral movement or sprawl. And
if you don't know what
301
00:17:33,913 --> 00:17:36,960
infrastructure exists, you're
going to have a hard time doing
302
00:17:37,010 --> 00:17:39,857
that. You need to install
endpoint protection on anything
303
00:17:39,907 --> 00:17:42,555
you might be missing, or you
need to give an incident
304
00:17:42,605 --> 00:17:45,702
response vendor access to see
logging and material from all of
305
00:17:45,752 --> 00:17:48,799
your assets. If you don't know
where those things are, you're
306
00:17:48,849 --> 00:17:51,497
going to have a hard time,
right? So, this element of
307
00:17:51,547 --> 00:17:54,195
understanding what your entire
environment looks like
308
00:17:54,244 --> 00:17:57,242
proactively, even if it makes
you nervous, it's always going
309
00:17:57,292 --> 00:18:00,239
to be a better solution than
waiting for the reactive event
310
00:18:00,289 --> 00:18:02,937
that then you have to act. I
think most companies are
311
00:18:02,987 --> 00:18:05,934
generally weary of production
impacts. They're weary of any
312
00:18:05,984 --> 00:18:08,632
business outcome that's
negative, and I think part of
313
00:18:08,682 --> 00:18:11,379
this is just it's a messaging
problem, a communication
314
00:18:11,429 --> 00:18:14,427
problem. If you're working with
an executive team or a sales
315
00:18:14,476 --> 00:18:17,224
team or folks that are
responsible for kind of customer
316
00:18:17,274 --> 00:18:20,421
experience, if they understand
what that impact would look like
317
00:18:20,471 --> 00:18:23,618
in the worst of scenarios. It's
better to understand why you're
318
00:18:23,668 --> 00:18:26,566
willing to kind of risk it a
little bit more in the better
319
00:18:26,616 --> 00:18:29,513
ones. And obviously, the more
you do this, the more you do
320
00:18:29,563 --> 00:18:32,361
this over time and track what
you're doing, this problem
321
00:18:32,411 --> 00:18:35,308
starts going away. So, really,
this issue at its core is a
322
00:18:35,358 --> 00:18:38,305
legacy problem, one that comes
out of programs maybe aren't
323
00:18:38,355 --> 00:18:41,303
mature or haven't had that kind
of formal focus, but it's a
324
00:18:41,353 --> 00:18:44,800
solvable one, where you stop
dealing with that same level of concern.
325
00:18:46,000 --> 00:18:49,640
Keith Hawkey: And you've had
exposure working in a multitude
326
00:18:49,719 --> 00:18:54,467
of industries, Michael, and I
can imagine that the, the, you
327
00:18:54,546 --> 00:18:59,057
know, the receptive nature of
making change, particularly
328
00:18:59,136 --> 00:19:03,726
disruptive change, can vary
somewhat industry to industry.
329
00:19:03,805 --> 00:19:08,395
How does referring back to
cybersecurity? You've worked in
330
00:19:08,474 --> 00:19:12,510
both media and logistics
environments. How does the
331
00:19:12,589 --> 00:19:16,862
threat intent change based on
industry, and how should
332
00:19:16,941 --> 00:19:19,870
defensive posture adjust accordingly?
333
00:19:20,590 --> 00:19:22,570
Michael Irwin: Yeah, I mean,
threat intent changes
334
00:19:22,570 --> 00:19:25,270
everything, right? So,
ultimately, your defenses should
335
00:19:25,270 --> 00:19:28,120
mirror what the attacker
actually wants to achieve, and
336
00:19:28,120 --> 00:19:31,810
so you need to look at it. In my
example, media, we generally
337
00:19:31,810 --> 00:19:34,810
focused on persistence and
integrity issues, so we would
338
00:19:34,810 --> 00:19:38,590
deal with sophisticated actors
that are trying to maintain
339
00:19:38,590 --> 00:19:41,410
control in your environment,
perhaps for the purpose of
340
00:19:41,710 --> 00:19:45,760
modifying content that we're
publishing, as an example, that
341
00:19:45,760 --> 00:19:49,000
is, by its nature, very quiet.
It's something that isn't going
342
00:19:49,000 --> 00:19:51,460
to be the big noisy disruption
that's obvious. And so, when
343
00:19:51,460 --> 00:19:53,920
you're looking at that, you need
to protect that content, you
344
00:19:53,920 --> 00:19:56,500
need to detect subtle
manipulations, and things you
345
00:19:56,500 --> 00:19:58,600
need to really focus on
long-term access, things that
346
00:19:58,600 --> 00:20:01,840
are harder to detect, it. It
really requires more visibility
347
00:20:01,840 --> 00:20:04,360
laterally across your
infrastructure. When you look at
348
00:20:04,360 --> 00:20:07,330
logistics, I think it tends to
be more financially motivated or
349
00:20:07,330 --> 00:20:10,150
disruption motivated, and so
it's going to be louder. It's
350
00:20:10,150 --> 00:20:12,370
going to be more obvious. You
might have an employee
351
00:20:12,370 --> 00:20:15,400
compromise of an account that
you see negative effects of that
352
00:20:15,400 --> 00:20:18,790
same day. In media, you might
have an employee compromise of
353
00:20:18,790 --> 00:20:20,980
an account that you see the
effects of six months later,
354
00:20:21,250 --> 00:20:24,490
right, and so that nature of I
can't remember what the exact
355
00:20:24,490 --> 00:20:27,760
statistic is right now, but
there's a very lengthy multiple
356
00:20:27,760 --> 00:20:30,910
months period of time on average
that it takes organizations to
357
00:20:30,910 --> 00:20:33,850
discover breaches, and a lot of
that relates to what they're
358
00:20:33,850 --> 00:20:36,310
trying to actually achieve, and
so when we think about
359
00:20:36,310 --> 00:20:39,340
logistics, ransomware
disruption, the ability to
360
00:20:39,340 --> 00:20:42,370
recover, protect backups becomes
a significantly more important
361
00:20:42,370 --> 00:20:45,340
control. I mean, all of them are
relevant across the board, all
362
00:20:45,340 --> 00:20:47,590
the controls and the areas that
you might deal with, but if
363
00:20:47,590 --> 00:20:49,480
you're dealing with priority, if
you're dealing with budget
364
00:20:49,480 --> 00:20:52,180
limitation, it's important to
understand kind of where the
365
00:20:52,180 --> 00:20:53,830
most important component is.
366
00:20:54,940 --> 00:20:57,220
Keith Hawkey: And you've also
suggested that the majority of
367
00:20:57,220 --> 00:21:02,020
breaches stem from a narrow
identity-driven attack path,
368
00:21:02,230 --> 00:21:06,790
which is the talk of today. If
you walked into a billion-dollar
369
00:21:06,790 --> 00:21:10,930
organization tomorrow, what are
three foundational controls that
370
00:21:10,930 --> 00:21:12,070
you would audit first?
371
00:21:13,840 --> 00:21:16,240
Michael Irwin: So that I would
audit first is generally always
372
00:21:16,240 --> 00:21:19,540
going back to what causes an
incident, what leads to a
373
00:21:19,540 --> 00:21:22,990
breach. So we're thinking about
number one, if I'm going into an
374
00:21:22,990 --> 00:21:24,640
environment, there's an
understanding of how well do
375
00:21:24,640 --> 00:21:27,940
they know their own environment.
I've gone to organizations, or
376
00:21:27,940 --> 00:21:30,430
I've worked with groups before,
that would say, "Oh yeah, we
377
00:21:30,430 --> 00:21:33,520
have our EDR solution deployed
across all of our devices.
378
00:21:33,730 --> 00:21:35,890
Great, that's a great statement
to hear. And you have a modern
379
00:21:35,920 --> 00:21:40,300
next-gen EDR, perfect. Now the
question becomes, where's your
380
00:21:40,300 --> 00:21:43,630
asset inventory? Right, do you
actually.. well, we don't have
381
00:21:43,630 --> 00:21:46,660
that, or there's uncertainty in
that space. So, if you don't
382
00:21:46,660 --> 00:21:48,940
know the assets you're trying to
protect, why are you certain
383
00:21:48,940 --> 00:21:51,280
that you've deployed them
everywhere? That generally leads
384
00:21:51,280 --> 00:21:55,900
to a, at a minimum, 10, 20% gap
in coverage at a lot of these
385
00:21:55,900 --> 00:21:59,080
locations. That ultimately leads
to an incident. So, when you're
386
00:21:59,080 --> 00:22:01,300
thinking about what an
organization might have what I
387
00:22:01,300 --> 00:22:04,090
would be auditing that awareness
of their own environment, and
388
00:22:04,090 --> 00:22:08,740
really proving that awareness
beyond just checking the box is
389
00:22:08,740 --> 00:22:11,560
critical. From there, once you
know what your environment looks
390
00:22:11,560 --> 00:22:13,660
like, you again, you go back to
where your problem is going to
391
00:22:13,660 --> 00:22:16,090
be. You're dealing with employee
training and employee access
392
00:22:16,090 --> 00:22:18,460
issues. So, on training, that's
obvious. You can do phishing
393
00:22:18,460 --> 00:22:20,470
simulations, you can have
employee awareness training, you
394
00:22:20,470 --> 00:22:23,620
can measure how well they're
behaving. That's all one
395
00:22:23,620 --> 00:22:26,860
component, but you can also look
at, are they using single sign
396
00:22:26,860 --> 00:22:28,780
on? What does their password
policy look like? Do they have
397
00:22:28,780 --> 00:22:32,530
MFA enabled for everyone? When
you look at MFA these days, it's
398
00:22:32,530 --> 00:22:34,900
not as straightforward as a
simple code that you need to
399
00:22:34,900 --> 00:22:37,900
present, but rather, are you
protecting sessions? Do you have
400
00:22:37,900 --> 00:22:41,140
proactive awareness of session
behavior that's an anomaly,
401
00:22:41,140 --> 00:22:44,350
something that might signal a
token theft in an environment.
402
00:22:44,620 --> 00:22:46,570
There's a lot of organizations
that are checking all the right
403
00:22:46,570 --> 00:22:50,350
boxes, but they, un, they, they
kind of miss the understanding
404
00:22:50,350 --> 00:22:53,200
of the underlying ways that bad
actors are using these accounts,
405
00:22:53,200 --> 00:22:55,690
and they're bypassing them, and
so it's really a moving target
406
00:22:55,690 --> 00:22:58,300
that we have to hit. But outside
of that, you look at endpoint
407
00:22:58,300 --> 00:23:01,660
protection, right? So, I, I tend
to not be as infrastructure
408
00:23:01,660 --> 00:23:04,930
focused at the beginning. I'm
much more user focused, much
409
00:23:04,930 --> 00:23:07,960
more user device focused. So,
even thinking about things like
410
00:23:07,960 --> 00:23:10,930
segmentation, I think there's a
lot more value in segmenting a
411
00:23:10,930 --> 00:23:14,560
user population from one another
than there is segmenting, say,
412
00:23:14,560 --> 00:23:17,680
resources in the data center.
One might be more important. A
413
00:23:17,680 --> 00:23:20,440
lot of people talk about what
the crown jewels are, the most
414
00:23:20,440 --> 00:23:24,520
important assets, and that's all
true, but access to those things
415
00:23:24,520 --> 00:23:27,400
generally starts with that user
device. It's going to be the
416
00:23:27,400 --> 00:23:30,340
email they click on, the malware
they download on a computer, and
417
00:23:30,340 --> 00:23:33,130
where they can get from that
device laterally is what that
418
00:23:33,130 --> 00:23:36,430
bad actor is going to be
following. So, really sticking
419
00:23:36,430 --> 00:23:38,470
to the common causes of
incidents is what's going to
420
00:23:38,470 --> 00:23:41,830
move that the needle,
particularly in ROI, and is
421
00:23:41,830 --> 00:23:44,260
really achievable with low
investment. I mean, it's a
422
00:23:44,500 --> 00:23:47,500
people and process problem more
than it is a technology problem.
423
00:23:47,500 --> 00:23:50,650
So small, mid-sized businesses
that are trying to kind of keep
424
00:23:50,650 --> 00:23:53,800
up with this changing world in
this space, that's an area that
425
00:23:53,800 --> 00:23:56,800
you can really add a lot of
value for limited budgets.
426
00:23:57,820 --> 00:24:00,910
Keith Hawkey: Yeah, and
following up with some of the
427
00:24:00,910 --> 00:24:04,630
security tooling that you're
referencing between EDR asset
428
00:24:04,630 --> 00:24:09,730
inventory, you also suggested
that much of the industry
429
00:24:09,730 --> 00:24:14,500
messaging is geared toward the
enterprise space, not the mid
430
00:24:14,500 --> 00:24:18,220
market. Like, what's.. I mean,
you've.. I'm sure you've
431
00:24:18,220 --> 00:24:21,970
listened to dozens and dozens,
and maybe even hundreds of
432
00:24:22,000 --> 00:24:26,680
cybersecurity tooling pitches in
your career. What, what
433
00:24:26,680 --> 00:24:30,130
cybersecurity advice sounds
impressive, but it's really
434
00:24:30,160 --> 00:24:33,340
irrelevant for most mid-size
organizations.
435
00:24:34,990 --> 00:24:38,410
Michael Irwin: So, I think
anything that is pitching you at
436
00:24:38,410 --> 00:24:41,500
this kind of re-architecting of
the way your business operates
437
00:24:41,530 --> 00:24:45,610
as this prerequisite is always
always kind of makes your alarm
438
00:24:45,610 --> 00:24:48,370
bells goes up. Obviously, in
this day and age, AI is a big
439
00:24:48,370 --> 00:24:50,830
center of that, right? There's a
lot of assumptions that are
440
00:24:50,830 --> 00:24:53,410
being made with the value that
certain tools in that space
441
00:24:53,410 --> 00:24:56,680
might be able to provide.
Another big one is that there
442
00:24:56,680 --> 00:25:00,760
are a plethora of products that
will say we. Will give you full
443
00:25:00,760 --> 00:25:03,370
visibility into your network.
We'll show you all of the
444
00:25:03,370 --> 00:25:05,650
traffic, we'll inspect all the
packets, we'll show you all the
445
00:25:05,650 --> 00:25:08,560
vulnerabilities, we'll give you
all this information. And that
446
00:25:08,560 --> 00:25:11,230
sounds great if you have a large
team to actually act on those
447
00:25:11,260 --> 00:25:14,350
recommendations, but if you
don't, and you're expected to
448
00:25:14,350 --> 00:25:17,260
provide them, and you have a
PowerPoint presentation with a
449
00:25:17,260 --> 00:25:19,660
bunch of green, yellow, and red
check boxes that you're trying
450
00:25:19,660 --> 00:25:24,340
to kind of show posture to
another group, it's not really
451
00:25:24,340 --> 00:25:27,400
impressive if you can't act on
it, right? And so it's funny,
452
00:25:27,400 --> 00:25:30,520
one of the thoughts I have, and
kind of hard to say where the
453
00:25:30,520 --> 00:25:34,330
right answer is, but if you have
100 vulnerabilities and you
454
00:25:34,330 --> 00:25:37,810
can't solve them all, like, do
you want to even know, right? Is
455
00:25:37,810 --> 00:25:40,090
it valuable to even know a
vulnerability exists if you
456
00:25:40,090 --> 00:25:43,090
can't remediate it. It's kind of
like, did a tree really fall in
457
00:25:43,090 --> 00:25:44,650
the woods if you weren't there
to hear it, right? It's that
458
00:25:44,650 --> 00:25:45,460
kind of idea.
459
00:25:45,490 --> 00:25:45,850
Keith Hawkey: Yeah.
460
00:25:46,540 --> 00:25:49,089
Michael Irwin: And so I think,
because of that, what especially
461
00:25:49,142 --> 00:25:52,276
small or mid-sized companies
need is focus. They need focus
462
00:25:52,329 --> 00:25:55,357
on what is actually being
compromised. They need focus on
463
00:25:55,410 --> 00:25:58,756
things that small changes that
make the most large scale value.
464
00:25:58,810 --> 00:26:01,944
So, if we're talking about
upgrading or patching something,
465
00:26:01,997 --> 00:26:05,343
something that affects multiple
devices, not one. You're really
466
00:26:05,396 --> 00:26:08,743
looking for something that you
can actually act on. So, even in
467
00:26:08,796 --> 00:26:12,036
my own space, an area I always
look for is what organizations
468
00:26:12,089 --> 00:26:15,170
are providing a tool, and they
also have a managed service
469
00:26:15,223 --> 00:26:18,516
component. CrowdStrike, as an
example, as an EDR solution, has
470
00:26:18,569 --> 00:26:21,756
a managed services component to
their licensing that you can
471
00:26:21,809 --> 00:26:25,050
provide that's actually doing
some of the work for you. Other
472
00:26:25,103 --> 00:26:28,449
managed socks service providers
might do the same thing, right.
473
00:26:28,502 --> 00:26:31,742
So, there's different players in
that space that say we won't
474
00:26:31,795 --> 00:26:34,929
only tell you when there's a
problem or there's a risk, but
475
00:26:34,982 --> 00:26:38,223
we will help you solve them, or
we will help you weed out the
476
00:26:38,276 --> 00:26:41,569
noise. Those are things where
you have a lot more value, and I
477
00:26:41,622 --> 00:26:44,862
think oftentimes presentations
or conferences that are geared
478
00:26:44,915 --> 00:26:47,943
towards larger organizations,
generally because they have
479
00:26:47,996 --> 00:26:51,024
larger budgets to pay for the
products that they're being
480
00:26:51,077 --> 00:26:53,892
pitched. Those sort of things
often assume a level of
481
00:26:53,945 --> 00:26:57,345
resource, a level of maturity, a
level of documentation, a level
482
00:26:57,398 --> 00:27:00,372
of things that have already been
achieved in order to be
483
00:27:00,426 --> 00:27:03,666
successful, but they kind of
gloss over that at times, and so
484
00:27:03,719 --> 00:27:06,693
it's, it's difficult to look
back and say, oh yeah, it's
485
00:27:06,747 --> 00:27:09,721
great, you're referencing a
problem that we know exists,
486
00:27:09,774 --> 00:27:13,014
this is a risk we're concerned
about, your tool sounds great,
487
00:27:13,067 --> 00:27:16,308
but I have 10 other things I
need to do before I can even get
488
00:27:16,361 --> 00:27:19,760
there, right? And I think that's
where that message gets lost on
489
00:27:19,813 --> 00:27:20,770
smaller audiences.
490
00:27:22,240 --> 00:27:25,510
Keith Hawkey: Yeah, I couldn't
tell you how many, how many
491
00:27:25,585 --> 00:27:30,193
demos that I'm on. It feels like
weekly that the whatever name
492
00:27:30,268 --> 00:27:34,877
your cybersecurity vendors is
requesting the client completely
493
00:27:34,951 --> 00:27:39,709
re-architect their their network
design and I give kudos to some
494
00:27:39,783 --> 00:27:44,169
of these AI advancements, like,
like you said, that really,
495
00:27:44,243 --> 00:27:48,257
where these cybersecurity
vendors make their money and
496
00:27:48,332 --> 00:27:53,089
differentiate themselves is the
services that they attach to the
497
00:27:53,163 --> 00:27:57,475
tooling, because I have a lot
of, I have a lot of clients,
498
00:27:57,549 --> 00:28:02,158
quite frankly, that they just
can't handle the alerts that the
499
00:28:02,232 --> 00:28:06,470
mid-market IT teams are lean,
and more information really
500
00:28:06,544 --> 00:28:11,004
isn't bliss. Yes, it actually
just causes them more headache
501
00:28:11,078 --> 00:28:15,910
and heartburn because they can't
get to everything. So, you know,
502
00:28:15,985 --> 00:28:19,627
having there are some
innovations in the AI agent
503
00:28:19,701 --> 00:28:24,310
space that we are seeing with
cybersecurity that hopefully can
504
00:28:24,385 --> 00:28:28,696
help remedy some of the log
ingest some of the tasks, some
505
00:28:28,770 --> 00:28:33,156
of the especially the level one,
level two tasks that don't
506
00:28:33,231 --> 00:28:37,914
require network changes, don't
require like fundamental changes
507
00:28:37,988 --> 00:28:42,448
to the existing ecosystem that
can help, hopefully, save the
508
00:28:42,523 --> 00:28:46,240
day to some extent with that
increased visibility.
509
00:28:46,600 --> 00:28:47,890
Michael Irwin: Well, it's
interesting, though, because I
510
00:28:47,890 --> 00:28:49,870
mean, I think one of the
challenges that we have in the
511
00:28:49,870 --> 00:28:52,150
space is cybersecurity.
Obviously, there's stress,
512
00:28:52,150 --> 00:28:54,280
there's burnout. I think what
people don't talk about enough
513
00:28:54,280 --> 00:28:56,320
is there's a lot of imposter
syndrome, right? There's a lot
514
00:28:56,320 --> 00:28:59,020
of people that they're in a
role, they're responsible for
515
00:28:59,020 --> 00:29:01,540
something that they don't know
they don't necessarily have
516
00:29:01,540 --> 00:29:04,330
confidence that they know what
the right answer is, and you
517
00:29:04,390 --> 00:29:09,580
look at that in the example of
AI. Let's say AI as a concept is
518
00:29:09,580 --> 00:29:12,010
now talked about everywhere,
people are trying to bring it
519
00:29:12,010 --> 00:29:14,650
in, your board, your leadership
wants to bring this technology
520
00:29:14,650 --> 00:29:17,200
in, you're tasked with
protecting it, and this is
521
00:29:17,200 --> 00:29:20,440
something that is new within the
last year or two, right,
522
00:29:20,440 --> 00:29:23,470
depending, I mean, not new
conceptually, but new as far as
523
00:29:23,470 --> 00:29:27,490
kind of public favor goes, and
so you're now tasked with not
524
00:29:27,490 --> 00:29:30,130
only understanding this thing
that is new and everybody's
525
00:29:30,130 --> 00:29:33,220
trying to learn opportunities
for, but also understand and
526
00:29:33,220 --> 00:29:36,190
articulate the risks involved
with it, the potential gotchas,
527
00:29:36,190 --> 00:29:39,670
the configuration mismanagement,
the how to do that in a safe
528
00:29:39,670 --> 00:29:42,160
way, and like you need to do all
of that at the same time, and I
529
00:29:42,160 --> 00:29:45,790
think when you look at that
concept, and you say I have
530
00:29:46,210 --> 00:29:48,370
alerts that are generated
problems that are generated from
531
00:29:48,370 --> 00:29:52,120
a tool, I have some AI
integrated function of that,
532
00:29:52,120 --> 00:29:55,300
that is now telling me what to
do, it's maybe translating
533
00:29:55,300 --> 00:29:58,150
something, and that's where I've
seen a lot of success is taking
534
00:29:58,150 --> 00:30:00,340
a technical alert and
translating into. Simpler
535
00:30:00,340 --> 00:30:04,060
language, because many of our
teams are lower or mid-career
536
00:30:04,090 --> 00:30:07,030
people. They may be focused on
their past experiences, they
537
00:30:07,030 --> 00:30:09,130
don't have the technical
knowledge of some of the stuff
538
00:30:09,130 --> 00:30:13,270
they have to learn. And so that
balance of AI is helping you
539
00:30:13,270 --> 00:30:16,060
move faster, maybe it's telling
you how to remediate it. To what
540
00:30:16,060 --> 00:30:18,610
degree, or are we there yet,
that we trust the answer it's
541
00:30:18,610 --> 00:30:20,650
providing, right? Especially
with a team that can't
542
00:30:20,650 --> 00:30:23,170
necessarily vet that, or is
missing some of that, and I
543
00:30:23,170 --> 00:30:26,680
think that leads to hesitancy,
and so I think when you run into
544
00:30:26,680 --> 00:30:28,720
that space, is the idea that
there's certainly opportunity,
545
00:30:28,720 --> 00:30:31,510
without a doubt, there's
certainly value that these sort
546
00:30:31,510 --> 00:30:34,240
of approaches have for
organizations, but when you are
547
00:30:34,570 --> 00:30:38,290
using it as a fix for what is an
underskilled or under-resourced
548
00:30:38,290 --> 00:30:43,000
team, I think there's often this
fork in the road, or this kind
549
00:30:43,000 --> 00:30:46,090
of mid intersection point, where
they come back together, and
550
00:30:46,090 --> 00:30:48,160
you're going to kind of run into
that same problem. And I think
551
00:30:48,160 --> 00:30:50,920
that's the piece that, when we
talk about people, process, and
552
00:30:50,920 --> 00:30:54,490
technology, what I often find
is, in this, at least in the
553
00:30:54,490 --> 00:30:57,250
sense of AI, is that it's
technology in search of a
554
00:30:57,250 --> 00:31:01,330
problem. Traditionally, we've
looked at technology as we have
555
00:31:01,330 --> 00:31:03,880
a problem, we have a process,
and we're looking for technology
556
00:31:03,880 --> 00:31:07,690
to be something that will help
with scale, it'll help with
557
00:31:07,690 --> 00:31:11,200
efficiency, it'll add value that
way, but you're starting from
558
00:31:11,200 --> 00:31:15,040
the focus of a problem. I think
when you go back to that and you
559
00:31:15,040 --> 00:31:18,130
think about in the cybersecurity
space, a focus on people and
560
00:31:18,130 --> 00:31:21,640
process, you focus on
administrative housekeeping, you
561
00:31:21,640 --> 00:31:24,010
focus on best practice and kind
of cleaning up what you have,
562
00:31:24,220 --> 00:31:26,740
and then you identify something
that has too much volume for
563
00:31:26,740 --> 00:31:29,410
your small team to handle, that
becomes a great use case to
564
00:31:29,410 --> 00:31:33,970
leverage that AI or that kind of
optimization technology into the
565
00:31:33,970 --> 00:31:36,820
mix to make you better, but at
that point you're coming from a
566
00:31:36,820 --> 00:31:40,300
point of awareness and strength,
you're not trying to fill a lack
567
00:31:40,300 --> 00:31:42,850
of awareness with it. Right, I
think that's a distinction that
568
00:31:42,850 --> 00:31:46,000
often will drive whether or not
you're successful in using it.
569
00:31:47,680 --> 00:31:50,350
Keith Hawkey: I feel like we
could talk about this for hours,
570
00:31:50,350 --> 00:31:55,420
Michael. I really appreciate the
antidotes and the conversation
571
00:31:56,140 --> 00:31:58,630
that we had today, challenging
some of the assumptions in the,
572
00:31:58,630 --> 00:32:03,610
in the cybersecurity industry.
Just, just leaving here, if you
573
00:32:03,610 --> 00:32:10,510
were going to have a message to
a let's say a green behind the
574
00:32:10,510 --> 00:32:14,770
ears cyber security, formerly it
getting into the cyber security
575
00:32:14,770 --> 00:32:20,140
world leader, what what message,
if it could fit on a billboard,
576
00:32:20,170 --> 00:32:23,260
would would you share with with
this individual?
577
00:32:24,130 --> 00:32:26,950
Michael Irwin: I think the main
story is that you will be tasked
578
00:32:26,950 --> 00:32:29,710
with solving problems that you
didn't create, and that's the
579
00:32:29,710 --> 00:32:32,920
nature of the business. And so,
what that means is there might
580
00:32:32,920 --> 00:32:36,190
be more than you can handle, but
you can continue focusing in a
581
00:32:36,190 --> 00:32:38,740
methodical way, and you can
always make progress, right,
582
00:32:38,740 --> 00:32:41,410
whether it's small budgets or
big budgets. If you have an
583
00:32:41,410 --> 00:32:43,930
understanding of everything that
needs to be done, and you
584
00:32:43,930 --> 00:32:47,200
prioritize and really align with
the business based on where they
585
00:32:47,200 --> 00:32:50,500
are kind of financially or
economically, you'll be able to
586
00:32:50,500 --> 00:32:53,230
continue making progress, and
what you really find is a lot
587
00:32:53,230 --> 00:32:57,370
more success with that same
business seeking funding if you
588
00:32:57,370 --> 00:33:01,330
are understanding of the
financial position they're in,
589
00:33:01,330 --> 00:33:03,730
so if you're in a lean budget
year, that's the time to look
590
00:33:03,730 --> 00:33:07,300
for high ROI people in process
work, right? If you're in a
591
00:33:07,570 --> 00:33:09,460
higher budget year, something
that has a little bit more
592
00:33:09,460 --> 00:33:11,980
capacity for new tooling, maybe
that's a good opportunity to
593
00:33:11,980 --> 00:33:14,950
look for those high value but
higher dollar investments that
594
00:33:14,950 --> 00:33:17,890
you have. So not being able to
do the high dollar investment in
595
00:33:17,890 --> 00:33:20,530
a lean year doesn't mean that
you can't be successful, it
596
00:33:20,530 --> 00:33:22,330
means that you need to be
aligning to what the business
597
00:33:22,330 --> 00:33:24,970
needs in that moment, and
there's always work that can be
598
00:33:24,970 --> 00:33:27,670
done, and I think when you look
here, what really moves the
599
00:33:27,670 --> 00:33:31,720
needle in protecting against
incidents is just that, and the
600
00:33:31,720 --> 00:33:33,550
only other thing, because I
think it's important, is don't
601
00:33:33,550 --> 00:33:36,190
overlook culture, right, because
when you think about people,
602
00:33:36,280 --> 00:33:37,750
when you're talking about AI,
when you're thinking about this
603
00:33:37,750 --> 00:33:41,170
work, the inevitable bad days
that you'll have, focusing on
604
00:33:41,170 --> 00:33:43,390
positive culture and work-life
balance and really supporting
605
00:33:43,390 --> 00:33:45,970
the people on your team moves
the needle more than anything
606
00:33:45,970 --> 00:33:46,360
else.
607
00:33:47,950 --> 00:33:50,673
Keith Hawkey: Yeah, very well
said, Michael. How can you, how
608
00:33:50,731 --> 00:33:53,050
can our listeners get in touch
with you?
609
00:33:54,010 --> 00:33:56,590
Michael Irwin: So I'm available
on LinkedIn, so you can search
610
00:33:56,590 --> 00:33:59,440
and find me there. I generally
accept invites from whoever,
611
00:33:59,710 --> 00:34:02,530
whoever asks, so I'm not, not
particularly limiting on that
612
00:34:02,530 --> 00:34:05,740
front, but I'm pretty active in
the Charlotte CISO community, so
613
00:34:05,740 --> 00:34:09,700
I'm a lot of events in this
space, some of the Gartner Apex
614
00:34:09,700 --> 00:34:12,700
Assembly things, there's various
things that are going on, so I
615
00:34:12,700 --> 00:34:14,800
tend to be in those spaces, but
yeah, always reach out, and I'm
616
00:34:14,800 --> 00:34:18,130
happy to chat, I do a lot of
mentoring for individuals,
617
00:34:18,130 --> 00:34:21,040
particularly coming from kind of
IT backgrounds, or looking to
618
00:34:21,040 --> 00:34:23,890
get into cybersecurity, so I'm
always open to chat if anybody
619
00:34:23,980 --> 00:34:25,000
wanted to speak about anything.
620
00:34:25,900 --> 00:34:27,490
Keith Hawkey: We'll make sure to
include that information in the
621
00:34:27,490 --> 00:34:30,610
show notes. Michael, thank you
immensely for joining the IT
622
00:34:30,610 --> 00:34:34,900
Matters podcast. Thank you. We
will catch you guys next time.
623
00:34:35,170 --> 00:34:36,010
Michael Irwin: All right,
thanks.
624
00:34:37,660 --> 00:34:40,298
Aaron Bock: Thank you for
listening, and we appreciate you
625
00:34:40,356 --> 00:34:43,625
tuning into the IT Matters
Podcast. For support assessing
626
00:34:43,683 --> 00:34:47,182
your technology needs, book a
call with one of our technology
627
00:34:47,239 --> 00:34:50,853
advisors at O P K A L L A.com.
That's opkalla.com. If you found
628
00:34:50,910 --> 00:34:54,295
this episode helpful, please
share the podcast with someone
629
00:34:54,352 --> 00:34:57,737
who would get value from it, and
leave us a review on Apple
630
00:34:57,794 --> 00:35:01,179
Podcasts or on Spotify. Thank
you for listening, and have a
631
00:35:01,236 --> 00:35:01,810
great day.