WEBVTT
00:00:02.114 --> 00:00:04.874
We are ready to rock and roll.
00:00:06.594 --> 00:00:10.434
Hi and hello to the latest episode of Zero Downtime.
00:00:10.434 --> 00:00:14.674
My name is Shelly Calhoun-Jones and I'm a Technical Marketing Director here at Cohesity.
00:00:14.674 --> 00:00:16.934
Today we're joined by Doug Rivers.
00:00:17.034 --> 00:00:18.994
Doug, would you like to do an introduction?
00:00:19.672 --> 00:00:23.393
Sure, I am not here in my company capacity.
00:00:23.393 --> 00:00:30.746
I have a colleague, a past colleague of Shelley, but I guess she had brought me on as a security professional.
00:00:30.746 --> 00:00:32.666
I guess I better earn up to that.
00:00:32.666 --> 00:00:36.908
I've been well over 25 years in security.
00:00:36.908 --> 00:00:44.386
I've worked for different companies like Symantec and Cylance and Zimperium.
00:00:44.386 --> 00:00:56.312
Mainly I started off as a systems engineer and then I got into technical education and training, but my core has always been security.
00:00:56.412 --> 00:00:59.934
I recently retired from the military as a reservist.
00:00:59.934 --> 00:01:03.535
I was deployed to Afghanistan in an information operations capacity.
00:01:03.535 --> 00:01:13.370
I also serve as a reserve deputy sheriff for the Macomb County Sheriff's Office.
00:01:13.370 --> 00:01:19.903
where I serve on the cyber crime team and the bicycle team to try to keep myself fit, the mountain bike team.
00:01:20.183 --> 00:01:27.736
And I also do, I'm on the board of our local community college, Macomb Community College for IT advisory board.
00:01:27.736 --> 00:01:31.408
So I live and breathe all this stuff.
00:01:31.408 --> 00:01:37.070
I know that sounds like a lot of, love me and it's not, I just get bored easily and I like doing a lot of things.
00:01:38.006 --> 00:01:43.829
Doug is a rock star when it comes to security and we're very happy to have him on our show this week.
00:01:43.829 --> 00:01:51.664
And that was one of the reasons why we brought you on Doug is that we wanted to talk more about cyber resilience from a data perspective.
00:01:51.664 --> 00:01:56.216
And I can't think of anyone better than you to be on our episode today.
00:01:56.256 --> 00:02:03.520
So that really leads us into our topic because for a lot of us, we know that cyber resilience is more than just stopping attacks.
00:02:03.520 --> 00:02:06.622
It's about keeping control when things go wrong.
00:02:06.622 --> 00:02:19.777
And also, knowing your data, knowing what you have, where it is, who can access it, because it really does change how security teams detect, respond to, and recover from a security incident.
00:02:19.957 --> 00:02:26.789
When data access and management is handled well, the incident stays contained instead of spreading across the entire organization.
00:02:26.789 --> 00:02:36.872
And I know that's something that both you and I have had experience with in working in previous roles is that it's really a matter of time.
00:02:36.872 --> 00:02:44.316
you know, to really get the incident contained and really understand how the threat got into the environment.
00:02:46.201 --> 00:02:47.211
Definitely.
00:02:47.211 --> 00:02:50.953
It's speed. It's the time to containment, but it's also the preparation.
00:02:50.953 --> 00:03:02.169
I'm sure we're going to be talking about that too, because, you know, we've gotten to that mindset and it's a correct mindset that is not necessarily if something's going to happen,
00:03:02.169 --> 00:03:09.173
it's when, and are you prepared for that when, but I think that's made us a little bit more complacent in preparation.
00:03:09.173 --> 00:03:12.225
It's like, well, hey, if it's going to happen, there's really nothing I can do.
00:03:12.225 --> 00:03:14.536
And that's just not the attitude to have.
00:03:14.600 --> 00:03:28.611
Yeah, a lot of security people have a glass half empty type of mindset where, you have to really try to be the optimist, but think of how you can try to also minimize the
00:03:28.611 --> 00:03:31.582
incident from occurring again.
00:03:33.604 --> 00:03:41.450
So when you hear the term cyber resilience, I know this has been bounced a lot within the security community over the last couple of years.
00:03:41.554 --> 00:03:45.326
What does it mean to you in relation to security operations?
00:03:45.326 --> 00:03:48.373
Not just in theory, but in real practice.
00:03:49.015 --> 00:03:51.096
You know, here's what I think about it.
00:03:51.096 --> 00:03:58.027
And this might not be everybody's cup of tea, but when I think of cyber resilience, I think of what kind of a spectrum process, right?
00:03:58.027 --> 00:04:04.739
I don't think of, okay, we have this software, we have this tool, we have this person or this group.
00:04:04.739 --> 00:04:07.660
We have a cyber resilience group.
00:04:07.660 --> 00:04:10.121
No, it has to be almost a religion.
00:04:10.121 --> 00:04:11.451
You actually have to live it.
00:04:11.451 --> 00:04:13.101
It has to be a process.
00:04:13.101 --> 00:04:15.742
And it goes from what I call
00:04:15.754 --> 00:04:24.438
information management, identifying your information, what information is it there, almost taking a government slash military view of it.
00:04:24.798 --> 00:04:34.472
This information, if it was compromised or what kind of damage could that cause, it actually forms some kind of data classification around that.
00:04:34.592 --> 00:04:43.427
And then you have the, okay, then we have the protection mechanisms, the teams that are responsible for securing that data.
00:04:43.427 --> 00:04:47.729
And then we have the incident response teams all through that though.
00:04:47.729 --> 00:04:53.992
And this is something I would like to talk about during this podcast too, is communication.
00:04:57.004 --> 00:05:00.106
You know, a lot of people think that communication is a soft skill.
00:05:00.106 --> 00:05:03.960
A lot of people are just kind of dazzled by the tech and everything like that.
00:05:03.960 --> 00:05:13.517
But one thing that I see now that I'm getting old and I'm starting to mentor people and I'm starting to serve on, like I said, on this IT advisory board and talk to a lot of
00:05:13.517 --> 00:05:16.930
different people in the industry from different walks of life.
00:05:17.811 --> 00:05:22.294
Communicate, being able to communicate what's going on.
00:05:23.343 --> 00:05:33.698
What needs to be protected, what an incident occurs, what happened without a lot of hyperbole, being able to talk to different types of audiences and be able to scale that
00:05:33.698 --> 00:05:36.890
back and being able to focus on what needs to be done.
00:05:36.890 --> 00:05:42.652
That's the overarching thing to me in that whole cyber resilience process.
00:05:43.061 --> 00:05:47.753
Yeah, no, I like that because you're not getting caught up in all the acronyms and the buzzwords.
00:05:47.753 --> 00:05:55.845
You're just explaining it succinctly, you know, what's happening because a lot of times if you're dealing with an outbreak, you could be working with stakeholders that are not
00:05:55.845 --> 00:06:03.878
technical, but they still need to understand the issue so they can communicate it to the appropriate groups on their end as well.
00:06:04.038 --> 00:06:04.680
That's great.
00:06:04.680 --> 00:06:07.321
I mean, and here's the thing.
00:06:07.321 --> 00:06:16.234
There's a lot of boogeyman type things out there and there's definitely reasons to be cautious.
00:06:16.234 --> 00:06:20.275
I think that, you know, the term, I've never liked the term hacker.
00:06:20.275 --> 00:06:29.890
I use the term adversary because hacker can, hacker denotes somebody, you know, it notes a lot of stuff from pop culture and
00:06:29.890 --> 00:06:33.753
Mr. Robot and war games and all that kind of stuff.
00:06:33.753 --> 00:06:36.336
And that's cool for entertainment value.
00:06:36.336 --> 00:06:39.538
But there's, to me, there's no such thing as hackers.
00:06:39.538 --> 00:06:44.862
There's people with agendas, there's adversaries who are just resourceful.
00:06:44.863 --> 00:06:57.353
And I've always asserted that right now it is a lot easier for anybody to actually engage with free and open tools, free and open
00:06:58.146 --> 00:07:00.567
procedures, concepts, websites.
00:07:00.587 --> 00:07:14.035
I was playing with a Flipper Zero just recently and I was amazed how easy it was to clone a card, a door access card. I mean I didn't, you really did not have to, I did not
00:07:14.035 --> 00:07:16.726
have to have any extensive training to do this.
00:07:16.726 --> 00:07:18.957
I did it in five minutes, right?
00:07:18.957 --> 00:07:27.670
So that's the environment that we're dealing with, we're dealing with an adversarial environment not a hacker environment.
00:07:27.670 --> 00:07:37.073
So to bring all that back, when you're talking to people and you're talking to executives or you're talking to people who might not have that technical grounding that you might
00:07:37.073 --> 00:07:47.365
have, and all they know is the pop culture stuff out there, you have to be able to let them know about the threat, let them know about the danger, but kind of grounded in
00:07:47.365 --> 00:07:51.677
reality and kind of grounded in the fact that this is what people are trying to accomplish.
00:07:51.677 --> 00:07:57.358
This is how accessible, I'm not going to say easy, accessible it is.
00:07:57.444 --> 00:08:01.618
for people to attack us and these are some of things we can do about it.
00:08:02.420 --> 00:08:03.731
No, absolutely.
00:08:03.731 --> 00:08:08.195
You have to assume that your defenses will eventually be bypassed at some point.
00:08:08.195 --> 00:08:11.798
And not just that, but think about the business itself.
00:08:12.039 --> 00:08:22.047
Need to make sure that you're able to continue to make money as an organization, but also ensure that your customers stay safe or their data stays safe within your organization.
00:08:22.047 --> 00:08:23.309
So that's great.
00:08:23.309 --> 00:08:25.327
Those are all some really, really good points.
00:08:25.327 --> 00:08:26.547
And continuity too.
00:08:26.547 --> 00:08:33.049
I mean, I should have mentioned as part of that whole resilience process continuity, how do you get the business back online?
00:08:33.049 --> 00:08:34.409
I always tell stories.
00:08:34.409 --> 00:08:39.951
And it's always about me because that's the subject I know best.
00:08:39.951 --> 00:08:46.693
Just a couple of days ago, my main Windows creative machine went down.
00:08:46.693 --> 00:08:50.964
The latest Windows update Friday.
00:08:50.964 --> 00:08:57.420
And it said, hey, it came up with one of those Windows 11 black screens that says, hey, there's nothing we can do.
00:09:05.066 --> 00:09:07.228
And I'm not saying I'm a genius or anything.
00:09:07.228 --> 00:09:11.001
I mean, this is just a small example, but I had planned a long time ago.
00:09:11.001 --> 00:09:19.574
I'd learned about this disposable C drive, which means if your drive goes down, your operating system goes down.
00:09:19.574 --> 00:09:23.096
I want to make it so that I can bring that drive back up.
00:09:23.257 --> 00:09:29.261
If I have a backup or if I don't have a backup in this particular case, I didn't have a backup without losing data.
00:09:29.261 --> 00:09:33.764
A lot of my other data was on my home NAS or on another drive or anything like that.
00:09:33.764 --> 00:09:39.949
My C drive is just used for a lot of applications that you just download.
00:09:39.949 --> 00:09:41.710
Now most stuff is cloud based.
00:09:41.710 --> 00:09:47.075
So I was back up and running after that massive crash in
00:09:47.075 --> 00:09:50.721
a couple hours just reloading applications and everything.
00:09:50.721 --> 00:10:00.285
Now, yeah, that's an individual versus a company, but that just tells you that that's part of that whole resilience is what do you do when you get
00:10:00.285 --> 00:10:00.996
knocked down?
00:10:00.996 --> 00:10:02.578
You have to get back up.
00:10:02.932 --> 00:10:05.985
Also, there's different workloads could live in different places.
00:10:05.985 --> 00:10:08.747
You could have some workloads that are still on prem.
00:10:08.747 --> 00:10:13.982
Maybe you're working with a legacy application that you really don't have the ability to move into the cloud.
00:10:13.982 --> 00:10:17.535
You might have to refactor or rebuild or pick a different solution.
00:10:17.535 --> 00:10:20.257
You could have cloud-based applications.
00:10:20.257 --> 00:10:22.379
You could be working with Edge.
00:10:22.379 --> 00:10:30.556
So all of these different components, can be really stressful if you are dealing with an active security situation, having the ability to back up and recover.
00:10:30.612 --> 00:10:33.491
from a centralized platform is gonna make it a lot easier.
00:10:33.526 --> 00:10:47.438
And to that point, because I have a little bit of an auditing background too, unfortunately, a lot of people don't see the cracks or the things that they should have
00:10:47.438 --> 00:10:55.284
updated or they should have moved on to or they should have done the application, the thorns in the application until something goes wrong.
00:10:59.626 --> 00:11:02.526
And it sounds like there's so much to do.
00:11:02.526 --> 00:11:06.266
I mean, it's like, oh man, you want me to classify information?
00:11:06.266 --> 00:11:06.906
You want me to audit our applications and everything?
00:11:08.146 --> 00:11:08.546
Yeah, unfortunately.
00:11:08.546 --> 00:11:20.786
Because, you know, you got to say, okay, that sounds like a lot of effort, but you know, if something goes wrong, financial, reputational impact, all kinds of other stuff.
00:11:20.786 --> 00:11:23.246
This is a valuable thing.
00:11:23.246 --> 00:11:24.686
So you have to put in the work.
00:11:24.686 --> 00:11:26.186
It's like going to the gym.
00:11:26.284 --> 00:11:28.416
You know, you have to put in the work.
00:11:28.577 --> 00:11:29.668
There's no easy way.
00:11:29.668 --> 00:11:31.159
There's no easy button.
00:11:34.224 --> 00:11:35.604
I wish there was.
00:11:36.466 --> 00:11:41.231
If you know where that easy button is, please tell me because I want to buy it.
00:11:44.914 --> 00:11:48.799
Well, that actually leads me into my next question.
00:11:48.799 --> 00:11:58.410
How does understanding what data you have, where it lives, and who can access it change the way that a security team can respond to incidents?
00:12:00.191 --> 00:12:03.912
I think you have to have a realistic approach to it.
00:12:03.912 --> 00:12:14.695
I think that it would be great if we could go back to the old days, and I don't want to show how old I am, when you had the mainframes and everything and everything was
00:12:14.695 --> 00:12:15.485
centralized.
00:12:15.485 --> 00:12:20.537
And you could say, OK, we can respond to it because everything's in this container.
00:12:20.537 --> 00:12:25.878
The reality of the situation is you're going to have cloud, you're going to have on-prem.
00:12:26.254 --> 00:12:30.354
Even drilling down, you're going to have applications within your environment.
00:12:30.354 --> 00:12:38.094
You might have something in, you might be a Google shop or a Microsoft shop, and you might have things in Google Drive.
00:12:38.094 --> 00:12:40.814
You might have things stored on servers.
00:12:40.814 --> 00:12:42.094
You might have on-prem.
00:12:42.094 --> 00:12:44.874
I don't even know if Microsoft has on-prem exchange servers anymore.
00:12:44.874 --> 00:12:45.854
They might.
00:12:46.174 --> 00:12:48.934
So, you're going to have Confluence.
00:12:48.934 --> 00:12:54.434
You're going to have your, something I'm very familiar with, your learning management systems.
00:12:55.064 --> 00:12:56.995
There's data everywhere.
00:12:56.995 --> 00:13:10.574
So, and it is in my experience, it is unreasonable and almost unattainable to say, okay, we're just going to double down and put everything in one
00:13:10.574 --> 00:13:11.214
place.
00:13:11.214 --> 00:13:18.290
And maybe you shouldn't because that's a single point of failure, but you have different stakeholders.
00:13:18.290 --> 00:13:23.533
All those different things I mentioned, you have different stakeholders there, right?
00:13:24.770 --> 00:13:36.757
The information management, in my opinion, the information management process is not just knowing where the information is, managing that information and classifying it, but
00:13:36.757 --> 00:13:47.383
opening up that dialogue with those stakeholders and getting, and making sure from a security perspective, you know what type of information is there, you know, what the
00:13:47.383 --> 00:13:51.846
platform is, just getting a little bit more insight.
00:13:53.039 --> 00:13:59.739
That will give you a lot more information when you can design or you can actually implement your security plan.
00:14:00.319 --> 00:14:02.559
Once again, it's communication, that overarching thing.
00:14:02.559 --> 00:14:17.619
If you're not talking to the stakeholders, if there's some kind of weird marketing system out there that they have a lot of information in and you don't know about it, there's a
00:14:17.619 --> 00:14:18.559
gap there.
00:14:18.999 --> 00:14:24.735
I personally know in my current employment, I know the CSO.
00:14:25.456 --> 00:14:26.397
I've talked to him.
00:14:26.397 --> 00:14:36.842
I've actually approached him proactively about different products, different things I'm trying.
00:14:36.842 --> 00:14:42.565
When I chose the LMS, our learning management system, it was another information repository.
00:14:42.565 --> 00:14:47.588
I worked with him on the security review of that learning management system.
00:14:47.588 --> 00:14:49.119
So it's that whole thing.
00:14:49.119 --> 00:14:51.450
So in case something happens,
00:14:51.510 --> 00:14:53.381
and hopefully I'm not jinxing myself.
00:14:53.381 --> 00:14:55.131
He's familiar with it.
00:14:55.402 --> 00:14:58.363
It's not bulletproof.
00:14:58.363 --> 00:15:04.195
It's not 99% but 80% is better than being 0%.
00:15:06.476 --> 00:15:16.550
It's better to know something or at least have an effort into actually knowing where all the information is, having a process, knowing who the people are, establishing that
00:15:16.550 --> 00:15:20.672
communication than actually having to do it
00:15:21.090 --> 00:15:25.289
when something happens because there's all kinds of things going on.
00:15:25.478 --> 00:15:29.160
That drives home the point that security is a shared responsibility.
00:15:29.160 --> 00:15:41.613
And it's good to educate yourself as a security practitioner, understanding what the other stakeholders do and factoring in that at the same time we want to make sure our
00:15:41.613 --> 00:15:48.105
environment is secure, we also want to make sure that the data is accessible so that we can continue doing our day jobs.
00:15:48.105 --> 00:15:52.191
That's great that you already have that ongoing relationship
00:15:52.191 --> 00:16:04.683
with your CISO to make sure that from an application perspective that the applications and the workloads that you're using are secure and that you're checking off all of your boxes
00:16:04.784 --> 00:16:07.046
from a security perspective.
00:16:07.380 --> 00:16:10.881
Yeah, and you know this and that's not because I'm a smart guy or anything like that.
00:16:10.881 --> 00:16:16.834
That's because I've either seen or experienced things where I did it wrong or I've seen it done wrong.
00:16:19.775 --> 00:16:24.856
I am only smart because I know a lot of smart people or I've made a lot of dumb mistakes.
00:16:24.856 --> 00:16:29.009
That's the way I look at it.
00:16:29.009 --> 00:16:31.372
Stay humble and enlightened.
00:16:31.806 --> 00:16:34.127
Exactly, exactly.
00:16:34.127 --> 00:16:37.238
So communication, like I said, I can't emphasize that enough.
00:16:37.238 --> 00:16:38.508
It's not a soft skill.
00:16:38.508 --> 00:16:41.019
It's great to know all the techie stuff.
00:16:41.019 --> 00:16:42.649
I love my tech.
00:16:42.689 --> 00:16:49.451
But at the end of the day, there's a human element behind everything that we do.
00:16:50.271 --> 00:16:53.612
And we can't get those technical goals done.
00:16:53.612 --> 00:16:57.603
We can't get those security goals done unless we have that human element in there.
00:16:57.603 --> 00:17:00.584
And that human element is based on communication.
00:17:03.093 --> 00:17:14.974
So in your experience, what points or situations do organizations frequently lose control of their data, regardless of the security measures that you may have in place?
00:17:15.702 --> 00:17:23.145
I think one of the things that we do is there's a couple things.
00:17:23.486 --> 00:17:31.069
One is the dependency on technology alone to protect you or dependency on technology period.
00:17:31.069 --> 00:17:41.914
We're seeing a really interesting case with AI right now where we're letting AI do a lot of things, but we're
00:17:42.059 --> 00:17:44.260
seeing that it has to be supervised.
00:17:44.260 --> 00:17:57.786
I use the example of if you have a teenager and you're giving your 12 year old or 13 year old the responsibility to cut your grass, cut your lawn for the first time, right?
00:17:58.466 --> 00:18:04.089
They can go out there and they can do it, but I'm sure you have a certain way that you want it done.
00:18:04.089 --> 00:18:09.871
And if you just let them go out there and do it, there's a lot of chances that things can go wrong.
00:18:09.871 --> 00:18:11.982
So it has to be supervised, right?
00:18:11.982 --> 00:18:27.017
So I think that one of the issues out there is not depending on the tech so much and actually being involved, being engaged in any type of
00:18:27.017 --> 00:18:28.346
technology you implement.
00:18:28.346 --> 00:18:30.138
That could really
00:18:30.400 --> 00:18:34.837
impact your security posture.
00:18:34.837 --> 00:18:40.665
The other thing that I see is a necessary evil is information sharing.
00:18:41.568 --> 00:18:45.553
We have an ability or we have a
00:18:46.579 --> 00:18:59.200
thing out there, we have to share information with our partners, with customers, between us, we have to share information or make information available.
00:18:59.200 --> 00:19:06.317
Sharing and availability, to employees who have their own phones.
00:19:06.317 --> 00:19:09.360
They're walking all over the place and everything like that.
00:19:09.360 --> 00:19:11.922
That data is everywhere.
00:19:12.747 --> 00:19:18.350
And it's very hard to control that data in the business that I'm in right now.
00:19:18.730 --> 00:19:21.972
If you look at it, if you really think about it, a lot of people don't realize this.
00:19:21.972 --> 00:19:29.317
Everybody has their phone and most organizations don't issue you a phone, right?
00:19:29.317 --> 00:19:34.319
They might put some MDM or they might put something on your phone.
00:19:34.600 --> 00:19:38.679
If you let them, or if they have that policy, but it's a bring your own device type of thing.
00:19:39.239 --> 00:19:41.301
And the same thing with laptops.
00:19:41.301 --> 00:19:46.954
Everybody, if you're working at home or not, a lot of people have laptops or tablets or something.
00:19:46.954 --> 00:19:48.845
So you're accessing that information.
00:19:48.845 --> 00:19:50.976
That information has little legs.
00:19:50.976 --> 00:19:53.408
It's going all over the place with all those people.
00:19:54.148 --> 00:20:01.132
So actually that's another issue of the sharing of information and the availability of information.
00:20:01.132 --> 00:20:02.733
That box has been open.
00:20:02.733 --> 00:20:04.584
We can't close that anymore.
00:20:04.672 --> 00:20:13.769
So being able to provide protections around that to try to lower the risk, you're not going to eliminate the risk, but you can lower the risk, by implementing
00:20:13.769 --> 00:20:16.911
controls, implementing policies, processes, things like that.
00:20:16.911 --> 00:20:29.061
Those are the things that I see are the biggest issues, the biggest things that you have to really get your arms around if you want to lower the risk of having a
00:20:29.061 --> 00:20:30.501
security incident.
00:20:31.050 --> 00:20:32.310
Yeah, I'm just thinking about that.
00:20:32.310 --> 00:20:43.910
It's been almost 10 years since COVID and I don't think I've had an actual corporate issued phone for a long time, longer than 10 years.
00:20:43.910 --> 00:20:52.930
I've always had just a personal phone that I have my email on and my Slack, but yeah, I could see that being very challenging
00:20:52.930 --> 00:20:56.090
from an IT or a security perspective.
00:20:57.646 --> 00:21:06.926
And even your laptops, even you have a laptop here still for the most part, even though there's certain endpoint stuff on traditional
00:21:06.926 --> 00:21:09.986
endpoints, they might have a little bit more control on it.
00:21:09.986 --> 00:21:13.866
But at the end of the day, most people are still the administrator of their own devices.
00:21:15.206 --> 00:21:21.146
And you know, if you look at your phone, how many apps do you have on your phone?
00:21:21.146 --> 00:21:21.946
Do you know?
00:21:21.946 --> 00:21:23.746
I can't tell you right now.
00:21:25.091 --> 00:21:27.253
But how many apps do you have on your phone?
00:21:27.253 --> 00:21:28.334
And here's the thing.
00:21:28.334 --> 00:21:30.176
And here's another thing you have to consider.
00:21:30.176 --> 00:21:32.559
How many apps do you have on your phone?
00:21:32.559 --> 00:21:43.830
And then how many of those apps are related to what you do for your organization and how many of those apps are like things that you
00:21:44.695 --> 00:21:47.939
do you upgrade your phone to get a new phone?
00:21:47.972 --> 00:21:48.622
Exactly.
00:21:48.622 --> 00:21:51.534
Yeah, or upgrade the apps.
00:21:51.534 --> 00:22:00.681
So and this all gets back to the information. I could access information, in the military
00:22:00.681 --> 00:22:11.878
we saw a really sea change because before everything was tightly controlled. Before I retired, everything was tightly controlled and you had to be in certain areas to access
00:22:11.878 --> 00:22:15.210
certain information and everything like that.
00:22:15.656 --> 00:22:27.180
And classified information is still like that, but even on our own intranet, so to speak, you couldn't get military
00:22:27.180 --> 00:22:30.111
email on your bring your own device phone, right?
00:22:30.111 --> 00:22:33.312
That's changed because the world has changed.
00:22:33.312 --> 00:22:39.634
In the Navy where I came from, when I left, we do virtual desktops now.
00:22:39.822 --> 00:22:48.378
Where you could actually get into your NMCI system and you could actually be like you were actually at the Reserve Center or you were actually on a military site.
00:22:48.378 --> 00:22:55.633
That's the way that the world has forced us to go because you have to have that information availability.
00:22:55.633 --> 00:23:07.711
If you can't have that information availability or that information sharing, you're going to suffer in productivity, in engagement, in all kinds of areas.
00:23:07.711 --> 00:23:09.632
So that presents another
00:23:09.652 --> 00:23:17.581
issue that you have to think about. Not doom and gloom, you just have to think about things you can do to minimize
00:23:17.581 --> 00:23:18.592
those risks.
00:23:20.539 --> 00:23:22.999
That actually leads me into my next question.
00:23:23.660 --> 00:23:30.992
In your experience, at what points do organizations most frequently lose control of their data?
00:23:30.992 --> 00:23:41.906
I feel like we've already touched on this, but do you have any personal examples of organizations that may have lost control of their data regardless of the security measures
00:23:41.906 --> 00:23:43.106
that are in place?
00:23:43.883 --> 00:23:49.908
I'm going to mention something from a long time ago and I'm not going to mention the who or the what.
00:23:51.649 --> 00:24:00.276
There was an organization that I'm aware of, I won't say if I worked for this organization or not, or if I was on the security team for this organization.
00:24:00.276 --> 00:24:04.770
Once again, it was about a communication thing.
00:24:04.770 --> 00:24:08.262
There was a server that
00:24:08.354 --> 00:24:11.894
got compromised or went down, there was a problem with the server.
00:24:11.894 --> 00:24:19.757
The server was used for some kind of marketing effort with a little bit of a financial flair to it.
00:24:19.777 --> 00:24:36.091
And so when we investigated where the server was, we found out that it was a server that was run by an executive's nephew out of his dorm room at
00:24:36.091 --> 00:24:37.482
Michigan State.
00:24:43.886 --> 00:24:48.146
And it was, this was a long time ago.
00:24:48.146 --> 00:24:50.126
This was a very long time ago.
00:24:50.446 --> 00:24:56.666
But I would venture to guess that there are things happening like that right now.
00:24:56.666 --> 00:24:58.806
So think about what I just told you, Shelley.
00:24:58.986 --> 00:25:03.226
There was a server that was somewhere else.
00:25:03.226 --> 00:25:09.506
Was it controlled? An incident happened and we didn't find out about all this stuff until this incident happened.
00:25:10.446 --> 00:25:13.466
We didn't know the capabilities of the server.
00:25:13.702 --> 00:25:21.407
We had no communication with the stakeholders who were using the server. We didn't know what kind of software was on the server.
00:25:21.407 --> 00:25:22.258
He's a smart guy.
00:25:22.258 --> 00:25:26.171
He knows what he's doing. He's a computer science major, right?
00:25:26.171 --> 00:25:36.818
Visibility. It's that all visibility thing something I should have mentioned earlier. Visibility is equally as important as communication.
00:25:36.818 --> 00:25:42.912
So all those things that I talked about, that actually happened. I'm not making that up.
00:25:42.955 --> 00:25:50.579
And the scary thing is, I would suspect that things like that are happening right now.
00:25:50.699 --> 00:26:02.905
Maybe not in that much in your face, but using some kind of application that somebody found searching some open source repositories that all of a sudden without any
00:26:02.905 --> 00:26:03.886
type of
00:26:04.262 --> 00:26:18.790
security review or anything like that you're using and it becomes an instrumental part of your application or your operational motion. Things like that.
00:26:18.790 --> 00:26:21.851
I mean, that's happening right now.
00:26:21.992 --> 00:26:29.735
And I know that the whole security has an inverse relationship of productivity, but you got to put some common sense in there too.
00:26:30.556 --> 00:26:33.718
There are a lot of things that
00:26:34.290 --> 00:26:44.636
in my adventures, especially doing technical training and everything like that, it would just be easy just to do this, or it just appears to be easy just to start using this
00:26:44.636 --> 00:26:56.163
program, or just to start doing this, or start doing that, or just share this using some kind of unauthorized sharing platform and everything, but it wouldn't be right.
00:26:56.163 --> 00:26:59.745
And if something happens and it comes back on you, what are you gonna say?
00:27:01.486 --> 00:27:04.298
Well, it seemed like a good idea at the time.
00:27:04.298 --> 00:27:05.928
It's not a good excuse.
00:27:07.909 --> 00:27:19.634
So those are, I'm sure I could if I really thought about it, I could think of some other stupid security tricks, anti security tricks, but I don't want to
00:27:19.634 --> 00:27:21.635
embarrass anybody out there.
00:27:21.635 --> 00:27:24.826
Somebody might see this podcast and say, wait a minute, you shouldn't have said that.
00:27:24.826 --> 00:27:28.357
So, yeah, there's a lot of stuff out there.
00:27:28.375 --> 00:27:33.678
Yeah, it reminds me of people who create a cloud account and they don't properly harden it.
00:27:33.678 --> 00:27:38.600
And then suddenly you have EC2 instances that are running Bitcoin mining applications.
00:27:40.901 --> 00:27:42.222
It happens.
00:27:44.219 --> 00:27:55.259
Or the person who is on LinkedIn or is on social media and they're responsible for some kind of platform and they love like the Detroit Tigers or something.
00:27:55.259 --> 00:27:57.219
They got Tiger stuff all over the place.
00:27:57.219 --> 00:28:00.859
And then all of a sudden it's like, hmm, what's your password, dude?
00:28:01.699 --> 00:28:03.079
Tiger's 84.
00:28:03.079 --> 00:28:04.779
Yeah, let's try that.
00:28:05.644 --> 00:28:08.755
You know, it's that kind of thing.
00:28:09.376 --> 00:28:12.237
People are listening.
00:28:13.118 --> 00:28:17.640
Once again, not trying to sound paranoid, but I come from an information operations background.
00:28:17.940 --> 00:28:25.264
Part of this, I look at this in a different perspective in the whole field of intelligence, Shelley.
00:28:25.904 --> 00:28:27.295
It's not the big thing.
00:28:27.295 --> 00:28:29.666
You're not actually going after
00:28:29.914 --> 00:28:38.557
the big thing that you want to compromise or this is the big thing to get a lot of money. No, it's the little elements.
00:28:38.557 --> 00:28:50.691
It's doing a little reconnaissance, doing a little surveillance, seeing what's out there, putting in the work, going out there and then saying hey I can
00:28:50.691 --> 00:28:54.618
get in here, going in low and slow and saying okay, I'm gonna look around here.
00:28:54.618 --> 00:28:55.650
Why not
00:28:55.650 --> 00:28:58.140
put a big coin miner on a couple of these machines.
00:28:58.140 --> 00:29:00.733
I might as well make some money off of it while I'm in here.
00:29:01.594 --> 00:29:05.136
And it's that nefarious.
00:29:05.136 --> 00:29:15.162
I'm not saying all this to do doom and gloom or anything like that.
00:29:15.162 --> 00:29:22.368
I'm saying all this to hopefully if somebody sees this and listening to all my nonsense here, they get a
00:29:22.368 --> 00:29:28.012
it makes them think and it gets them encouraged or it gets them riled up to say, yeah, maybe I need to do something about this.
00:29:28.012 --> 00:29:30.184
Maybe I haven't considered this, right?
00:29:30.184 --> 00:29:33.866
So I'm actually trying to provoke an action, trying to provoke behavior.
00:29:34.247 --> 00:29:34.817
Exactly.
00:29:34.817 --> 00:29:42.033
Yeah, because for a lot of folks, they could be looking at a checklist of things they need to do within the environment.
00:29:42.033 --> 00:29:49.729
Maybe it's from a compliance perspective, but also thinking that this could help harden the environment from a security perspective.
00:29:49.729 --> 00:29:52.961
And that actually leads me into my next question.
00:29:52.961 --> 00:30:00.907
How should security leaders approach data management when planning for security, not just for compliance?
00:30:01.794 --> 00:30:07.458
I think that in my mind, we talked about communication.
00:30:07.458 --> 00:30:12.201
We talked about, I think one of the goals should be visibility.
00:30:13.898 --> 00:30:23.284
If you don't know what's going on and the adversaries are counting on you not knowing what's going on, that should be a key goal in there.
00:30:23.284 --> 00:30:26.465
But you have to actually be realistic, right?
00:30:26.465 --> 00:30:33.389
And this is where it gets a lot more challenging than
00:30:34.422 --> 00:30:36.923
getting the visibility aspects of it.
00:30:36.923 --> 00:30:44.106
Because there's some technical things that you can do for visibility and all this other kind of stuff.
00:30:44.106 --> 00:30:47.268
But realistic, what do I mean by realistic?
00:30:47.268 --> 00:30:58.502
There are certain things that a security professional is going to say we need to do that they're going to get pushback from an executive or a C level person, maybe their own CISO
00:30:58.502 --> 00:31:00.233
saying, hey, we can't do that.
00:31:00.233 --> 00:31:02.434
We have to come up with something else.
00:31:02.634 --> 00:31:11.878
So, having that flexibility and knowing that you can't just say, okay, I want to protect this machine, just unplug it and put it in the closet.
00:31:11.878 --> 00:31:13.168
Well, that's not going to help us.
00:31:13.168 --> 00:31:14.639
You can't do that.
00:31:14.639 --> 00:31:17.260
That machine has to be plugged in.
00:31:17.260 --> 00:31:21.682
What can we do with knowing that it has to be plugged in?
00:31:21.682 --> 00:31:31.294
Unfortunately, we're in a business where there's a lot of egos and there are a lot of people who, my way is right and everything like that.
00:31:31.294 --> 00:31:35.217
And as a society, I think we've lost the ability to compromise.
00:31:35.217 --> 00:31:44.336
And the realities of business is if you're going to be successful, you're going to have to realize that there are some things that you want to do.
00:31:44.336 --> 00:31:47.809
There's some things that you're going to be told that you have to do.
00:31:47.809 --> 00:31:50.931
And you're going to have to try to figure out a way to marry those things together.
00:31:50.931 --> 00:31:58.097
I know that probably you were expecting a little bit more of a technical answer, but I really think that these are
00:31:58.403 --> 00:32:02.765
some fundamental things that a lot of people kind of miss nowadays.
00:32:02.765 --> 00:32:10.709
You got to kind of really think about the hills that you want to die on and the fights that you want to do.
00:32:10.709 --> 00:32:15.971
And then you have to look at it in a realistic manner say, okay, if we can't do that, what can we do?
00:32:15.971 --> 00:32:23.554
And that's that next step that a lot of people just are either afraid to take, don't want to take because it just
00:32:27.050 --> 00:32:30.590
sometimes, you know, you have to do what you have to do.
00:32:30.590 --> 00:32:33.190
Now, I'm not saying do anything unethical.
00:32:33.190 --> 00:32:37.690
I'm not saying do anything blatantly open like, okay, we're just not going to have any passwords anymore.
00:32:37.690 --> 00:32:39.410
I'm not talking about that.
00:32:39.410 --> 00:32:40.870
I'm not talking about things like that.
00:32:40.870 --> 00:32:45.766
But I'm thinking that if somebody's really looking at this realistically, they know what I'm talking about.
00:32:45.932 --> 00:32:47.482
We need this system here.
00:32:47.482 --> 00:32:49.433
We need to deal with this particular vendor.
00:32:49.433 --> 00:32:51.863
We need this, how can we do that?
00:32:51.863 --> 00:33:00.275
I know there's some problems there, but we need to deal with this customer who is in this region of the country that's a little bit
00:33:00.275 --> 00:33:03.225
shaky or had some issues.
00:33:03.225 --> 00:33:07.806
Or from a part of the world rather.
00:33:07.826 --> 00:33:16.068
So yeah, you have to have that flexibility and you have to be able to really look at this stuff objectively.
00:33:16.068 --> 00:33:16.779
We're all humans.
00:33:16.779 --> 00:33:17.869
We all got emotions.
00:33:17.869 --> 00:33:22.194
We're all gonna, I've done it myself and we'll do it, right?
00:33:22.194 --> 00:33:31.982
But if you're gonna be successful, you're gonna have to be able to take a couple steps back and say, okay, what is the actual outcome that we want to accomplish?
00:33:31.982 --> 00:33:37.006
The outcome isn't to feed you or your security team's ego.
00:33:37.047 --> 00:33:40.929
The outcome is to protect the organization, right?
00:33:42.363 --> 00:33:48.803
So your career and everything like that, I love my career and I'll build up my career and everything like that.
00:33:48.803 --> 00:33:58.183
But when somebody is paying you or when you're a part of an organization, that means you have to protect the organization doing what you're supposed to be doing, right?
00:33:58.183 --> 00:34:04.910
Which is, if it's security, if it's some kind of marketing or productivity or desktop or
00:34:04.910 --> 00:34:10.130
storage or anything like that, there's a kind of a responsibility.
00:34:10.130 --> 00:34:17.070
I've been using the term malpractice recently outside of the medical field, right?
00:34:17.070 --> 00:34:21.610
There are certain things that people can do that is malpractice.
00:34:21.610 --> 00:34:32.590
Not following security controls, not really having those communications, not really going out for it being visible, putting rogue AI, rogue
00:34:32.730 --> 00:34:36.003
networks into an environment, all kinds of stuff.
00:34:36.003 --> 00:34:37.575
That's detrimental.
00:34:37.575 --> 00:34:39.176
Man, did I get a little soap box there?
00:34:39.176 --> 00:34:40.376
Sorry about that.
00:34:41.384 --> 00:34:43.886
Yeah, you actually answered my last question.
00:34:43.886 --> 00:34:48.361
I was going to ask you if you had any advice that you wanted to give for security practitioners and leaders.
00:34:48.361 --> 00:34:58.480
It sounds really like choosing your own battles and making sure that you're focusing on protecting the business as a whole.
00:34:58.531 --> 00:35:01.794
Yeah, choosing your own battles, focusing on the outcomes.
00:35:01.794 --> 00:35:07.519
This is something I still have challenges with.
00:35:07.519 --> 00:35:13.744
Being able to step outside and say, am I being the jerk here?
00:35:14.305 --> 00:35:21.931
Or being able to really look at it objectively, what is actually trying to be accomplished here.
00:35:21.931 --> 00:35:25.524
And I think that if you have that particular mindset,
00:35:25.556 --> 00:35:26.808
it's infectious.
00:35:26.808 --> 00:35:28.861
It'll infect your team, right?
00:35:28.861 --> 00:35:32.197
You can go out and your team will say, yeah, what is our outcome here?
00:35:32.197 --> 00:35:38.226
It sounds really kind of after school special, dating myself again, but that's the way it actually will happen.
00:35:38.226 --> 00:35:41.460
If you really have a team that's focused on
00:35:41.587 --> 00:35:47.049
the outcomes and doing the right thing, you will have a successful team.
00:35:47.049 --> 00:36:03.554
Something I live by definitely is that teams are responsible for an organization's success, but organization's failure is always due to leadership.
00:36:04.622 --> 00:36:13.222
And there, even as an individual contributor, there is some degree of leadership that you have to do in doing your job.
00:36:13.222 --> 00:36:23.422
So even if you're a security analyst or something like that, you have to show those leadership qualities and be able to, because that will support your security
00:36:23.422 --> 00:36:33.502
manager, your security director, your CISO, and then the people outside the security organizations, your storage folks, your desktop folks, marketing folks, all that kind of
00:36:33.502 --> 00:36:34.222
stuff.
00:36:35.442 --> 00:36:38.325
This is all great information, Doug.
00:36:38.325 --> 00:36:46.451
And I really am so happy that we were able to get you on today to talk more about your experiences with cyber resilience.
00:36:46.451 --> 00:36:50.474
Before we wrap up, did you have anything else that you wanted to share with the audience?
00:36:51.104 --> 00:36:58.741
No, what I would like to once again emphasize that there's a lot of bad stuff out there.
00:36:58.741 --> 00:37:08.390
There's a lot of bad things that you hear, but you really have to say, okay, what can I do?
00:37:08.686 --> 00:37:09.166
Right?
00:37:09.166 --> 00:37:14.686
Kind of focus on what can I do and not focus on a lot of gloom and doom and everything.
00:37:14.686 --> 00:37:23.626
Like I said, I brought up a lot of things that, it's like, oh man, AI and information management and information classification and everything.
00:37:23.826 --> 00:37:25.046
It's overwhelming.
00:37:25.046 --> 00:37:27.626
It's like, no, this is a blank sheet of paper.
00:37:27.626 --> 00:37:28.006
Right?
00:37:28.006 --> 00:37:29.326
Here's a pencil.
00:37:29.486 --> 00:37:30.866
Where do you start?
00:37:30.866 --> 00:37:31.946
You start in the corner.
00:37:31.946 --> 00:37:33.026
How do you eat an elephant?
00:37:33.026 --> 00:37:34.246
One bite at a time.
00:37:35.046 --> 00:37:37.006
This, you could do this.
00:37:37.006 --> 00:37:38.800
So I guess my thing
00:37:38.800 --> 00:37:41.801
is don't be overwhelmed, right?
00:37:41.801 --> 00:37:43.982
It's very easy to be overwhelmed.
00:37:43.982 --> 00:37:46.762
Concentrate on the goal, concentrate on the outcome.
00:37:46.762 --> 00:37:53.744
It sounds like really, I know some people say, well, that's easy to say.
00:37:53.744 --> 00:37:57.105
Well, it's easy just to throw up your hands too.
00:37:57.125 --> 00:37:59.366
So I'd rather go with the other.
00:38:01.642 --> 00:38:10.162
Well, just for the audience, if you want to learn more about how to strengthen your cyber resilience strategy, we have a lot of great resources out on Cohesity.com.
00:38:10.162 --> 00:38:11.810
I recommend checking it out.
00:38:11.810 --> 00:38:22.338
Also, if you found this discussion useful, please follow us for more episodes of Zero Downtime, where we'll take a look at some of the trends that are shaping data security in
00:38:22.338 --> 00:38:23.859
2026 and beyond.
00:38:23.879 --> 00:38:26.301
That wraps up another episode of Zero Downtime.
00:38:26.301 --> 00:38:27.972
Thanks for watching, everyone.
00:38:28.738 --> 00:38:29.250
Thank you.
00:38:29.250 --> 00:38:30.451
Thank you, Shelly.
00:00:02.114 --> 00:00:04.874
We are ready to rock and roll.
00:00:06.594 --> 00:00:10.434
Hi and hello to the latest episode of Zero Downtime.
00:00:10.434 --> 00:00:14.674
My name is Shelly Calhoun-Jones and I'm a Technical Marketing Director here at Cohesity.
00:00:14.674 --> 00:00:16.934
Today we're joined by Doug Rivers.
00:00:17.034 --> 00:00:18.994
Doug, would you like to do an introduction?
00:00:19.672 --> 00:00:23.393
Sure, I am not here in my company capacity.
00:00:23.393 --> 00:00:30.746
I have a colleague, a past colleague of Shelley, but I guess she had brought me on as a security professional.
00:00:30.746 --> 00:00:32.666
I guess I better earn up to that.
00:00:32.666 --> 00:00:36.908
I've been well over 25 years in security.
00:00:36.908 --> 00:00:44.386
I've worked for different companies like Symantec and Cylance and Zimperium.
00:00:44.386 --> 00:00:56.312
Mainly I started off as a systems engineer and then I got into technical education and training, but my core has always been security.
00:00:56.412 --> 00:00:59.934
I recently retired from the military as a reservist.
00:00:59.934 --> 00:01:03.535
I was deployed to Afghanistan in an information operations capacity.
00:01:03.535 --> 00:01:13.370
I also serve as a reserve deputy sheriff for the Macomb County Sheriff's Office.
00:01:13.370 --> 00:01:19.903
where I serve on the cyber crime team and the bicycle team to try to keep myself fit, the mountain bike team.
00:01:20.183 --> 00:01:27.736
And I also do, I'm on the board of our local community college, Macomb Community College for IT advisory board.
00:01:27.736 --> 00:01:31.408
So I live and breathe all this stuff.
00:01:31.408 --> 00:01:37.070
I know that sounds like a lot of, love me and it's not, I just get bored easily and I like doing a lot of things.
00:01:38.006 --> 00:01:43.829
Doug is a rock star when it comes to security and we're very happy to have him on our show this week.
00:01:43.829 --> 00:01:51.664
And that was one of the reasons why we brought you on Doug is that we wanted to talk more about cyber resilience from a data perspective.
00:01:51.664 --> 00:01:56.216
And I can't think of anyone better than you to be on our episode today.
00:01:56.256 --> 00:02:03.520
So that really leads us into our topic because for a lot of us, we know that cyber resilience is more than just stopping attacks.
00:02:03.520 --> 00:02:06.622
It's about keeping control when things go wrong.
00:02:06.622 --> 00:02:19.777
And also, knowing your data, knowing what you have, where it is, who can access it, because it really does change how security teams detect, respond to, and recover from a security incident.
00:02:19.957 --> 00:02:26.789
When data access and management is handled well, the incident stays contained instead of spreading across the entire organization.
00:02:26.789 --> 00:02:36.872
And I know that's something that both you and I have had experience with in working in previous roles is that it's really a matter of time.
00:02:36.872 --> 00:02:44.316
you know, to really get the incident contained and really understand how the threat got into the environment.
00:02:46.201 --> 00:02:47.211
Definitely.
00:02:47.211 --> 00:02:50.953
It's speed. It's the time to containment, but it's also the preparation.
00:02:50.953 --> 00:03:02.169
I'm sure we're going to be talking about that too, because, you know, we've gotten to that mindset and it's a correct mindset that is not necessarily if something's going to happen,
00:03:02.169 --> 00:03:09.173
it's when, and are you prepared for that when, but I think that's made us a little bit more complacent in preparation.
00:03:09.173 --> 00:03:12.225
It's like, well, hey, if it's going to happen, there's really nothing I can do.
00:03:12.225 --> 00:03:14.536
And that's just not the attitude to have.
00:03:14.600 --> 00:03:28.611
Yeah, a lot of security people have a glass half empty type of mindset where, you have to really try to be the optimist, but think of how you can try to also minimize the
00:03:28.611 --> 00:03:31.582
incident from occurring again.
00:03:33.604 --> 00:03:41.450
So when you hear the term cyber resilience, I know this has been bounced a lot within the security community over the last couple of years.
00:03:41.554 --> 00:03:45.326
What does it mean to you in relation to security operations?
00:03:45.326 --> 00:03:48.373
Not just in theory, but in real practice.
00:03:49.015 --> 00:03:51.096
You know, here's what I think about it.
00:03:51.096 --> 00:03:58.027
And this might not be everybody's cup of tea, but when I think of cyber resilience, I think of what kind of a spectrum process, right?
00:03:58.027 --> 00:04:04.739
I don't think of, okay, we have this software, we have this tool, we have this person or this group.
00:04:04.739 --> 00:04:07.660
We have a cyber resilience group.
00:04:07.660 --> 00:04:10.121
No, it has to be almost a religion.
00:04:10.121 --> 00:04:11.451
You actually have to live it.
00:04:11.451 --> 00:04:13.101
It has to be a process.
00:04:13.101 --> 00:04:15.742
And it goes from what I call
00:04:15.754 --> 00:04:24.438
information management, identifying your information, what information is it there, almost taking a government slash military view of it.
00:04:24.798 --> 00:04:34.472
This information, if it was compromised or what kind of damage could that cause, it actually forms some kind of data classification around that.
00:04:34.592 --> 00:04:43.427
And then you have the, okay, then we have the protection mechanisms, the teams that are responsible for securing that data.
00:04:43.427 --> 00:04:47.729
And then we have the incident response teams all through that though.
00:04:47.729 --> 00:04:53.992
And this is something I would like to talk about during this podcast too, is communication.
00:04:57.004 --> 00:05:00.106
You know, a lot of people think that communication is a soft skill.
00:05:00.106 --> 00:05:03.960
A lot of people are just kind of dazzled by the tech and everything like that.
00:05:03.960 --> 00:05:13.517
But one thing that I see now that I'm getting old and I'm starting to mentor people and I'm starting to serve on, like I said, on this IT advisory board and talk to a lot of
00:05:13.517 --> 00:05:16.930
different people in the industry from different walks of life.
00:05:17.811 --> 00:05:22.294
Communicate, being able to communicate what's going on.
00:05:23.343 --> 00:05:33.698
What needs to be protected, what an incident occurs, what happened without a lot of hyperbole, being able to talk to different types of audiences and be able to scale that
00:05:33.698 --> 00:05:36.890
back and being able to focus on what needs to be done.
00:05:36.890 --> 00:05:42.652
That's the overarching thing to me in that whole cyber resilience process.
00:05:43.061 --> 00:05:47.753
Yeah, no, I like that because you're not getting caught up in all the acronyms and the buzzwords.
00:05:47.753 --> 00:05:55.845
You're just explaining it succinctly, you know, what's happening because a lot of times if you're dealing with an outbreak, you could be working with stakeholders that are not
00:05:55.845 --> 00:06:03.878
technical, but they still need to understand the issue so they can communicate it to the appropriate groups on their end as well.
00:06:04.038 --> 00:06:04.680
That's great.
00:06:04.680 --> 00:06:07.321
I mean, and here's the thing.
00:06:07.321 --> 00:06:16.234
There's a lot of boogeyman type things out there and there's definitely reasons to be cautious.
00:06:16.234 --> 00:06:20.275
I think that, you know, the term, I've never liked the term hacker.
00:06:20.275 --> 00:06:29.890
I use the term adversary because hacker can, hacker denotes somebody, you know, it notes a lot of stuff from pop culture and
00:06:29.890 --> 00:06:33.753
Mr. Robot and war games and all that kind of stuff.
00:06:33.753 --> 00:06:36.336
And that's cool for entertainment value.
00:06:36.336 --> 00:06:39.538
But there's, to me, there's no such thing as hackers.
00:06:39.538 --> 00:06:44.862
There's people with agendas, there's adversaries who are just resourceful.
00:06:44.863 --> 00:06:57.353
And I've always asserted that right now it is a lot easier for anybody to actually engage with free and open tools, free and open
00:06:58.146 --> 00:07:00.567
procedures, concepts, websites.
00:07:00.587 --> 00:07:14.035
I was playing with a Flipper Zero just recently and I was amazed how easy it was to clone a card, a door access card. I mean I didn't, you really did not have to, I did not
00:07:14.035 --> 00:07:16.726
have to have any extensive training to do this.
00:07:16.726 --> 00:07:18.957
I did it in five minutes, right?
00:07:18.957 --> 00:07:27.670
So that's the environment that we're dealing with, we're dealing with an adversarial environment not a hacker environment.
00:07:27.670 --> 00:07:37.073
So to bring all that back, when you're talking to people and you're talking to executives or you're talking to people who might not have that technical grounding that you might
00:07:37.073 --> 00:07:47.365
have, and all they know is the pop culture stuff out there, you have to be able to let them know about the threat, let them know about the danger, but kind of grounded in
00:07:47.365 --> 00:07:51.677
reality and kind of grounded in the fact that this is what people are trying to accomplish.
00:07:51.677 --> 00:07:57.358
This is how accessible, I'm not going to say easy, accessible it is.
00:07:57.444 --> 00:08:01.618
for people to attack us and these are some of things we can do about it.
00:08:02.420 --> 00:08:03.731
No, absolutely.
00:08:03.731 --> 00:08:08.195
You have to assume that your defenses will eventually be bypassed at some point.
00:08:08.195 --> 00:08:11.798
And not just that, but think about the business itself.
00:08:12.039 --> 00:08:22.047
Need to make sure that you're able to continue to make money as an organization, but also ensure that your customers stay safe or their data stays safe within your organization.
00:08:22.047 --> 00:08:23.309
So that's great.
00:08:23.309 --> 00:08:25.327
Those are all some really, really good points.
00:08:25.327 --> 00:08:26.547
And continuity too.
00:08:26.547 --> 00:08:33.049
I mean, I should have mentioned as part of that whole resilience process continuity, how do you get the business back online?
00:08:33.049 --> 00:08:34.409
I always tell stories.
00:08:34.409 --> 00:08:39.951
And it's always about me because that's the subject I know best.
00:08:39.951 --> 00:08:46.693
Just a couple of days ago, my main Windows creative machine went down.
00:08:46.693 --> 00:08:50.964
The latest Windows update Friday.
00:08:50.964 --> 00:08:57.420
And it said, hey, it came up with one of those Windows 11 black screens that says, hey, there's nothing we can do.
00:09:05.066 --> 00:09:07.228
And I'm not saying I'm a genius or anything.
00:09:07.228 --> 00:09:11.001
I mean, this is just a small example, but I had planned a long time ago.
00:09:11.001 --> 00:09:19.574
I'd learned about this disposable C drive, which means if your drive goes down, your operating system goes down.
00:09:19.574 --> 00:09:23.096
I want to make it so that I can bring that drive back up.
00:09:23.257 --> 00:09:29.261
If I have a backup or if I don't have a backup in this particular case, I didn't have a backup without losing data.
00:09:29.261 --> 00:09:33.764
A lot of my other data was on my home NAS or on another drive or anything like that.
00:09:33.764 --> 00:09:39.949
My C drive is just used for a lot of applications that you just download.
00:09:39.949 --> 00:09:41.710
Now most stuff is cloud based.
00:09:41.710 --> 00:09:47.075
So I was back up and running after that massive crash in
00:09:47.075 --> 00:09:50.721
a couple hours just reloading applications and everything.
00:09:50.721 --> 00:10:00.285
Now, yeah, that's an individual versus a company, but that just tells you that that's part of that whole resilience is what do you do when you get
00:10:00.285 --> 00:10:00.996
knocked down?
00:10:00.996 --> 00:10:02.578
You have to get back up.
00:10:02.932 --> 00:10:05.985
Also, there's different workloads could live in different places.
00:10:05.985 --> 00:10:08.747
You could have some workloads that are still on prem.
00:10:08.747 --> 00:10:13.982
Maybe you're working with a legacy application that you really don't have the ability to move into the cloud.
00:10:13.982 --> 00:10:17.535
You might have to refactor or rebuild or pick a different solution.
00:10:17.535 --> 00:10:20.257
You could have cloud-based applications.
00:10:20.257 --> 00:10:22.379
You could be working with Edge.
00:10:22.379 --> 00:10:30.556
So all of these different components, can be really stressful if you are dealing with an active security situation, having the ability to back up and recover.
00:10:30.612 --> 00:10:33.491
from a centralized platform is gonna make it a lot easier.
00:10:33.526 --> 00:10:47.438
And to that point, because I have a little bit of an auditing background too, unfortunately, a lot of people don't see the cracks or the things that they should have
00:10:47.438 --> 00:10:55.284
updated or they should have moved on to or they should have done the application, the thorns in the application until something goes wrong.
00:10:59.626 --> 00:11:02.526
And it sounds like there's so much to do.
00:11:02.526 --> 00:11:06.266
I mean, it's like, oh man, you want me to classify information?
00:11:06.266 --> 00:11:06.906
You want me to audit our applications and everything?
00:11:08.146 --> 00:11:08.546
Yeah, unfortunately.
00:11:08.546 --> 00:11:20.786
Because, you know, you got to say, okay, that sounds like a lot of effort, but you know, if something goes wrong, financial, reputational impact, all kinds of other stuff.
00:11:20.786 --> 00:11:23.246
This is a valuable thing.
00:11:23.246 --> 00:11:24.686
So you have to put in the work.
00:11:24.686 --> 00:11:26.186
It's like going to the gym.
00:11:26.284 --> 00:11:28.416
You know, you have to put in the work.
00:11:28.577 --> 00:11:29.668
There's no easy way.
00:11:29.668 --> 00:11:31.159
There's no easy button.
00:11:34.224 --> 00:11:35.604
I wish there was.
00:11:36.466 --> 00:11:41.231
If you know where that easy button is, please tell me because I want to buy it.
00:11:44.914 --> 00:11:48.799
Well, that actually leads me into my next question.
00:11:48.799 --> 00:11:58.410
How does understanding what data you have, where it lives, and who can access it change the way that a security team can respond to incidents?
00:12:00.191 --> 00:12:03.912
I think you have to have a realistic approach to it.
00:12:03.912 --> 00:12:14.695
I think that it would be great if we could go back to the old days, and I don't want to show how old I am, when you had the mainframes and everything and everything was
00:12:14.695 --> 00:12:15.485
centralized.
00:12:15.485 --> 00:12:20.537
And you could say, OK, we can respond to it because everything's in this container.
00:12:20.537 --> 00:12:25.878
The reality of the situation is you're going to have cloud, you're going to have on-prem.
00:12:26.254 --> 00:12:30.354
Even drilling down, you're going to have applications within your environment.
00:12:30.354 --> 00:12:38.094
You might have something in, you might be a Google shop or a Microsoft shop, and you might have things in Google Drive.
00:12:38.094 --> 00:12:40.814
You might have things stored on servers.
00:12:40.814 --> 00:12:42.094
You might have on-prem.
00:12:42.094 --> 00:12:44.874
I don't even know if Microsoft has on-prem exchange servers anymore.
00:12:44.874 --> 00:12:45.854
They might.
00:12:46.174 --> 00:12:48.934
So, you're going to have Confluence.
00:12:48.934 --> 00:12:54.434
You're going to have your, something I'm very familiar with, your learning management systems.
00:12:55.064 --> 00:12:56.995
There's data everywhere.
00:12:56.995 --> 00:13:10.574
So, and it is in my experience, it is unreasonable and almost unattainable to say, okay, we're just going to double down and put everything in one
00:13:10.574 --> 00:13:11.214
place.
00:13:11.214 --> 00:13:18.290
And maybe you shouldn't because that's a single point of failure, but you have different stakeholders.
00:13:18.290 --> 00:13:23.533
All those different things I mentioned, you have different stakeholders there, right?
00:13:24.770 --> 00:13:36.757
The information management, in my opinion, the information management process is not just knowing where the information is, managing that information and classifying it, but
00:13:36.757 --> 00:13:47.383
opening up that dialogue with those stakeholders and getting, and making sure from a security perspective, you know what type of information is there, you know, what the
00:13:47.383 --> 00:13:51.846
platform is, just getting a little bit more insight.
00:13:53.039 --> 00:13:59.739
That will give you a lot more information when you can design or you can actually implement your security plan.
00:14:00.319 --> 00:14:02.559
Once again, it's communication, that overarching thing.
00:14:02.559 --> 00:14:17.619
If you're not talking to the stakeholders, if there's some kind of weird marketing system out there that they have a lot of information in and you don't know about it, there's a
00:14:17.619 --> 00:14:18.559
gap there.
00:14:18.999 --> 00:14:24.735
I personally know in my current employment, I know the CSO.
00:14:25.456 --> 00:14:26.397
I've talked to him.
00:14:26.397 --> 00:14:36.842
I've actually approached him proactively about different products, different things I'm trying.
00:14:36.842 --> 00:14:42.565
When I chose the LMS, our learning management system, it was another information repository.
00:14:42.565 --> 00:14:47.588
I worked with him on the security review of that learning management system.
00:14:47.588 --> 00:14:49.119
So it's that whole thing.
00:14:49.119 --> 00:14:51.450
So in case something happens,
00:14:51.510 --> 00:14:53.381
and hopefully I'm not jinxing myself.
00:14:53.381 --> 00:14:55.131
He's familiar with it.
00:14:55.402 --> 00:14:58.363
It's not bulletproof.
00:14:58.363 --> 00:15:04.195
It's not 99% but 80% is better than being 0%.
00:15:06.476 --> 00:15:16.550
It's better to know something or at least have an effort into actually knowing where all the information is, having a process, knowing who the people are, establishing that
00:15:16.550 --> 00:15:20.672
communication than actually having to do it
00:15:21.090 --> 00:15:25.289
when something happens because there's all kinds of things going on.
00:15:25.478 --> 00:15:29.160
That drives home the point that security is a shared responsibility.
00:15:29.160 --> 00:15:41.613
And it's good to educate yourself as a security practitioner, understanding what the other stakeholders do and factoring in that at the same time we want to make sure our
00:15:41.613 --> 00:15:48.105
environment is secure, we also want to make sure that the data is accessible so that we can continue doing our day jobs.
00:15:48.105 --> 00:15:52.191
That's great that you already have that ongoing relationship
00:15:52.191 --> 00:16:04.683
with your CISO to make sure that from an application perspective that the applications and the workloads that you're using are secure and that you're checking off all of your boxes
00:16:04.784 --> 00:16:07.046
from a security perspective.
00:16:07.380 --> 00:16:10.881
Yeah, and you know this and that's not because I'm a smart guy or anything like that.
00:16:10.881 --> 00:16:16.834
That's because I've either seen or experienced things where I did it wrong or I've seen it done wrong.
00:16:19.775 --> 00:16:24.856
I am only smart because I know a lot of smart people or I've made a lot of dumb mistakes.
00:16:24.856 --> 00:16:29.009
That's the way I look at it.
00:16:29.009 --> 00:16:31.372
Stay humble and enlightened.
00:16:31.806 --> 00:16:34.127
Exactly, exactly.
00:16:34.127 --> 00:16:37.238
So communication, like I said, I can't emphasize that enough.
00:16:37.238 --> 00:16:38.508
It's not a soft skill.
00:16:38.508 --> 00:16:41.019
It's great to know all the techie stuff.
00:16:41.019 --> 00:16:42.649
I love my tech.
00:16:42.689 --> 00:16:49.451
But at the end of the day, there's a human element behind everything that we do.
00:16:50.271 --> 00:16:53.612
And we can't get those technical goals done.
00:16:53.612 --> 00:16:57.603
We can't get those security goals done unless we have that human element in there.
00:16:57.603 --> 00:17:00.584
And that human element is based on communication.
00:17:03.093 --> 00:17:14.974
So in your experience, what points or situations do organizations frequently lose control of their data, regardless of the security measures that you may have in place?
00:17:15.702 --> 00:17:23.145
I think one of the things that we do is there's a couple things.
00:17:23.486 --> 00:17:31.069
One is the dependency on technology alone to protect you or dependency on technology period.
00:17:31.069 --> 00:17:41.914
We're seeing a really interesting case with AI right now where we're letting AI do a lot of things, but we're
00:17:42.059 --> 00:17:44.260
seeing that it has to be supervised.
00:17:44.260 --> 00:17:57.786
I use the example of if you have a teenager and you're giving your 12 year old or 13 year old the responsibility to cut your grass, cut your lawn for the first time, right?
00:17:58.466 --> 00:18:04.089
They can go out there and they can do it, but I'm sure you have a certain way that you want it done.
00:18:04.089 --> 00:18:09.871
And if you just let them go out there and do it, there's a lot of chances that things can go wrong.
00:18:09.871 --> 00:18:11.982
So it has to be supervised, right?
00:18:11.982 --> 00:18:27.017
So I think that one of the issues out there is not depending on the tech so much and actually being involved, being engaged in any type of
00:18:27.017 --> 00:18:28.346
technology you implement.
00:18:28.346 --> 00:18:30.138
That could really
00:18:30.400 --> 00:18:34.837
impact your security posture.
00:18:34.837 --> 00:18:40.665
The other thing that I see is a necessary evil is information sharing.
00:18:41.568 --> 00:18:45.553
We have an ability or we have a
00:18:46.579 --> 00:18:59.200
thing out there, we have to share information with our partners, with customers, between us, we have to share information or make information available.
00:18:59.200 --> 00:19:06.317
Sharing and availability, to employees who have their own phones.
00:19:06.317 --> 00:19:09.360
They're walking all over the place and everything like that.
00:19:09.360 --> 00:19:11.922
That data is everywhere.
00:19:12.747 --> 00:19:18.350
And it's very hard to control that data in the business that I'm in right now.
00:19:18.730 --> 00:19:21.972
If you look at it, if you really think about it, a lot of people don't realize this.
00:19:21.972 --> 00:19:29.317
Everybody has their phone and most organizations don't issue you a phone, right?
00:19:29.317 --> 00:19:34.319
They might put some MDM or they might put something on your phone.
00:19:34.600 --> 00:19:38.679
If you let them, or if they have that policy, but it's a bring your own device type of thing.
00:19:39.239 --> 00:19:41.301
And the same thing with laptops.
00:19:41.301 --> 00:19:46.954
Everybody, if you're working at home or not, a lot of people have laptops or tablets or something.
00:19:46.954 --> 00:19:48.845
So you're accessing that information.
00:19:48.845 --> 00:19:50.976
That information has little legs.
00:19:50.976 --> 00:19:53.408
It's going all over the place with all those people.
00:19:54.148 --> 00:20:01.132
So actually that's another issue of the sharing of information and the availability of information.
00:20:01.132 --> 00:20:02.733
That box has been open.
00:20:02.733 --> 00:20:04.584
We can't close that anymore.
00:20:04.672 --> 00:20:13.769
So being able to provide protections around that to try to lower the risk, you're not going to eliminate the risk, but you can lower the risk, by implementing
00:20:13.769 --> 00:20:16.911
controls, implementing policies, processes, things like that.
00:20:16.911 --> 00:20:29.061
Those are the things that I see are the biggest issues, the biggest things that you have to really get your arms around if you want to lower the risk of having a
00:20:29.061 --> 00:20:30.501
security incident.
00:20:31.050 --> 00:20:32.310
Yeah, I'm just thinking about that.
00:20:32.310 --> 00:20:43.910
It's been almost 10 years since COVID and I don't think I've had an actual corporate issued phone for a long time, longer than 10 years.
00:20:43.910 --> 00:20:52.930
I've always had just a personal phone that I have my email on and my Slack, but yeah, I could see that being very challenging
00:20:52.930 --> 00:20:56.090
from an IT or a security perspective.
00:20:57.646 --> 00:21:06.926
And even your laptops, even you have a laptop here still for the most part, even though there's certain endpoint stuff on traditional
00:21:06.926 --> 00:21:09.986
endpoints, they might have a little bit more control on it.
00:21:09.986 --> 00:21:13.866
But at the end of the day, most people are still the administrator of their own devices.
00:21:15.206 --> 00:21:21.146
And you know, if you look at your phone, how many apps do you have on your phone?
00:21:21.146 --> 00:21:21.946
Do you know?
00:21:21.946 --> 00:21:23.746
I can't tell you right now.
00:21:25.091 --> 00:21:27.253
But how many apps do you have on your phone?
00:21:27.253 --> 00:21:28.334
And here's the thing.
00:21:28.334 --> 00:21:30.176
And here's another thing you have to consider.
00:21:30.176 --> 00:21:32.559
How many apps do you have on your phone?
00:21:32.559 --> 00:21:43.830
And then how many of those apps are related to what you do for your organization and how many of those apps are like things that you
00:21:44.695 --> 00:21:47.939
do you upgrade your phone to get a new phone?
00:21:47.972 --> 00:21:48.622
Exactly.
00:21:48.622 --> 00:21:51.534
Yeah, or upgrade the apps.
00:21:51.534 --> 00:22:00.681
So and this all gets back to the information. I could access information, in the military
00:22:00.681 --> 00:22:11.878
we saw a really sea change because before everything was tightly controlled. Before I retired, everything was tightly controlled and you had to be in certain areas to access
00:22:11.878 --> 00:22:15.210
certain information and everything like that.
00:22:15.656 --> 00:22:27.180
And classified information is still like that, but even on our own intranet, so to speak, you couldn't get military
00:22:27.180 --> 00:22:30.111
email on your bring your own device phone, right?
00:22:30.111 --> 00:22:33.312
That's changed because the world has changed.
00:22:33.312 --> 00:22:39.634
In the Navy where I came from, when I left, we do virtual desktops now.
00:22:39.822 --> 00:22:48.378
Where you could actually get into your NMCI system and you could actually be like you were actually at the Reserve Center or you were actually on a military site.
00:22:48.378 --> 00:22:55.633
That's the way that the world has forced us to go because you have to have that information availability.
00:22:55.633 --> 00:23:07.711
If you can't have that information availability or that information sharing, you're going to suffer in productivity, in engagement, in all kinds of areas.
00:23:07.711 --> 00:23:09.632
So that presents another
00:23:09.652 --> 00:23:17.581
issue that you have to think about. Not doom and gloom, you just have to think about things you can do to minimize
00:23:17.581 --> 00:23:18.592
those risks.
00:23:20.539 --> 00:23:22.999
That actually leads me into my next question.
00:23:23.660 --> 00:23:30.992
In your experience, at what points do organizations most frequently lose control of their data?
00:23:30.992 --> 00:23:41.906
I feel like we've already touched on this, but do you have any personal examples of organizations that may have lost control of their data regardless of the security measures
00:23:41.906 --> 00:23:43.106
that are in place?
00:23:43.883 --> 00:23:49.908
I'm going to mention something from a long time ago and I'm not going to mention the who or the what.
00:23:51.649 --> 00:24:00.276
There was an organization that I'm aware of, I won't say if I worked for this organization or not, or if I was on the security team for this organization.
00:24:00.276 --> 00:24:04.770
Once again, it was about a communication thing.
00:24:04.770 --> 00:24:08.262
There was a server that
00:24:08.354 --> 00:24:11.894
got compromised or went down, there was a problem with the server.
00:24:11.894 --> 00:24:19.757
The server was used for some kind of marketing effort with a little bit of a financial flair to it.
00:24:19.777 --> 00:24:36.091
And so when we investigated where the server was, we found out that it was a server that was run by an executive's nephew out of his dorm room at
00:24:36.091 --> 00:24:37.482
Michigan State.
00:24:43.886 --> 00:24:48.146
And it was, this was a long time ago.
00:24:48.146 --> 00:24:50.126
This was a very long time ago.
00:24:50.446 --> 00:24:56.666
But I would venture to guess that there are things happening like that right now.
00:24:56.666 --> 00:24:58.806
So think about what I just told you, Shelley.
00:24:58.986 --> 00:25:03.226
There was a server that was somewhere else.
00:25:03.226 --> 00:25:09.506
Was it controlled? An incident happened and we didn't find out about all this stuff until this incident happened.
00:25:10.446 --> 00:25:13.466
We didn't know the capabilities of the server.
00:25:13.702 --> 00:25:21.407
We had no communication with the stakeholders who were using the server. We didn't know what kind of software was on the server.
00:25:21.407 --> 00:25:22.258
He's a smart guy.
00:25:22.258 --> 00:25:26.171
He knows what he's doing. He's a computer science major, right?
00:25:26.171 --> 00:25:36.818
Visibility. It's that all visibility thing something I should have mentioned earlier. Visibility is equally as important as communication.
00:25:36.818 --> 00:25:42.912
So all those things that I talked about, that actually happened. I'm not making that up.
00:25:42.955 --> 00:25:50.579
And the scary thing is, I would suspect that things like that are happening right now.
00:25:50.699 --> 00:26:02.905
Maybe not in that much in your face, but using some kind of application that somebody found searching some open source repositories that all of a sudden without any
00:26:02.905 --> 00:26:03.886
type of
00:26:04.262 --> 00:26:18.790
security review or anything like that you're using and it becomes an instrumental part of your application or your operational motion. Things like that.
00:26:18.790 --> 00:26:21.851
I mean, that's happening right now.
00:26:21.992 --> 00:26:29.735
And I know that the whole security has an inverse relationship of productivity, but you got to put some common sense in there too.
00:26:30.556 --> 00:26:33.718
There are a lot of things that
00:26:34.290 --> 00:26:44.636
in my adventures, especially doing technical training and everything like that, it would just be easy just to do this, or it just appears to be easy just to start using this
00:26:44.636 --> 00:26:56.163
program, or just to start doing this, or start doing that, or just share this using some kind of unauthorized sharing platform and everything, but it wouldn't be right.
00:26:56.163 --> 00:26:59.745
And if something happens and it comes back on you, what are you gonna say?
00:27:01.486 --> 00:27:04.298
Well, it seemed like a good idea at the time.
00:27:04.298 --> 00:27:05.928
It's not a good excuse.
00:27:07.909 --> 00:27:19.634
So those are, I'm sure I could if I really thought about it, I could think of some other stupid security tricks, anti security tricks, but I don't want to
00:27:19.634 --> 00:27:21.635
embarrass anybody out there.
00:27:21.635 --> 00:27:24.826
Somebody might see this podcast and say, wait a minute, you shouldn't have said that.
00:27:24.826 --> 00:27:28.357
So, yeah, there's a lot of stuff out there.
00:27:28.375 --> 00:27:33.678
Yeah, it reminds me of people who create a cloud account and they don't properly harden it.
00:27:33.678 --> 00:27:38.600
And then suddenly you have EC2 instances that are running Bitcoin mining applications.
00:27:40.901 --> 00:27:42.222
It happens.
00:27:44.219 --> 00:27:55.259
Or the person who is on LinkedIn or is on social media and they're responsible for some kind of platform and they love like the Detroit Tigers or something.
00:27:55.259 --> 00:27:57.219
They got Tiger stuff all over the place.
00:27:57.219 --> 00:28:00.859
And then all of a sudden it's like, hmm, what's your password, dude?
00:28:01.699 --> 00:28:03.079
Tiger's 84.
00:28:03.079 --> 00:28:04.779
Yeah, let's try that.
00:28:05.644 --> 00:28:08.755
You know, it's that kind of thing.
00:28:09.376 --> 00:28:12.237
People are listening.
00:28:13.118 --> 00:28:17.640
Once again, not trying to sound paranoid, but I come from an information operations background.
00:28:17.940 --> 00:28:25.264
Part of this, I look at this in a different perspective in the whole field of intelligence, Shelley.
00:28:25.904 --> 00:28:27.295
It's not the big thing.
00:28:27.295 --> 00:28:29.666
You're not actually going after
00:28:29.914 --> 00:28:38.557
the big thing that you want to compromise or this is the big thing to get a lot of money. No, it's the little elements.
00:28:38.557 --> 00:28:50.691
It's doing a little reconnaissance, doing a little surveillance, seeing what's out there, putting in the work, going out there and then saying hey I can
00:28:50.691 --> 00:28:54.618
get in here, going in low and slow and saying okay, I'm gonna look around here.
00:28:54.618 --> 00:28:55.650
Why not
00:28:55.650 --> 00:28:58.140
put a big coin miner on a couple of these machines.
00:28:58.140 --> 00:29:00.733
I might as well make some money off of it while I'm in here.
00:29:01.594 --> 00:29:05.136
And it's that nefarious.
00:29:05.136 --> 00:29:15.162
I'm not saying all this to do doom and gloom or anything like that.
00:29:15.162 --> 00:29:22.368
I'm saying all this to hopefully if somebody sees this and listening to all my nonsense here, they get a
00:29:22.368 --> 00:29:28.012
it makes them think and it gets them encouraged or it gets them riled up to say, yeah, maybe I need to do something about this.
00:29:28.012 --> 00:29:30.184
Maybe I haven't considered this, right?
00:29:30.184 --> 00:29:33.866
So I'm actually trying to provoke an action, trying to provoke behavior.
00:29:34.247 --> 00:29:34.817
Exactly.
00:29:34.817 --> 00:29:42.033
Yeah, because for a lot of folks, they could be looking at a checklist of things they need to do within the environment.
00:29:42.033 --> 00:29:49.729
Maybe it's from a compliance perspective, but also thinking that this could help harden the environment from a security perspective.
00:29:49.729 --> 00:29:52.961
And that actually leads me into my next question.
00:29:52.961 --> 00:30:00.907
How should security leaders approach data management when planning for security, not just for compliance?
00:30:01.794 --> 00:30:07.458
I think that in my mind, we talked about communication.
00:30:07.458 --> 00:30:12.201
We talked about, I think one of the goals should be visibility.
00:30:13.898 --> 00:30:23.284
If you don't know what's going on and the adversaries are counting on you not knowing what's going on, that should be a key goal in there.
00:30:23.284 --> 00:30:26.465
But you have to actually be realistic, right?
00:30:26.465 --> 00:30:33.389
And this is where it gets a lot more challenging than
00:30:34.422 --> 00:30:36.923
getting the visibility aspects of it.
00:30:36.923 --> 00:30:44.106
Because there's some technical things that you can do for visibility and all this other kind of stuff.
00:30:44.106 --> 00:30:47.268
But realistic, what do I mean by realistic?
00:30:47.268 --> 00:30:58.502
There are certain things that a security professional is going to say we need to do that they're going to get pushback from an executive or a C level person, maybe their own CISO
00:30:58.502 --> 00:31:00.233
saying, hey, we can't do that.
00:31:00.233 --> 00:31:02.434
We have to come up with something else.
00:31:02.634 --> 00:31:11.878
So, having that flexibility and knowing that you can't just say, okay, I want to protect this machine, just unplug it and put it in the closet.
00:31:11.878 --> 00:31:13.168
Well, that's not going to help us.
00:31:13.168 --> 00:31:14.639
You can't do that.
00:31:14.639 --> 00:31:17.260
That machine has to be plugged in.
00:31:17.260 --> 00:31:21.682
What can we do with knowing that it has to be plugged in?
00:31:21.682 --> 00:31:31.294
Unfortunately, we're in a business where there's a lot of egos and there are a lot of people who, my way is right and everything like that.
00:31:31.294 --> 00:31:35.217
And as a society, I think we've lost the ability to compromise.
00:31:35.217 --> 00:31:44.336
And the realities of business is if you're going to be successful, you're going to have to realize that there are some things that you want to do.
00:31:44.336 --> 00:31:47.809
There's some things that you're going to be told that you have to do.
00:31:47.809 --> 00:31:50.931
And you're going to have to try to figure out a way to marry those things together.
00:31:50.931 --> 00:31:58.097
I know that probably you were expecting a little bit more of a technical answer, but I really think that these are
00:31:58.403 --> 00:32:02.765
some fundamental things that a lot of people kind of miss nowadays.
00:32:02.765 --> 00:32:10.709
You got to kind of really think about the hills that you want to die on and the fights that you want to do.
00:32:10.709 --> 00:32:15.971
And then you have to look at it in a realistic manner say, okay, if we can't do that, what can we do?
00:32:15.971 --> 00:32:23.554
And that's that next step that a lot of people just are either afraid to take, don't want to take because it just
00:32:27.050 --> 00:32:30.590
sometimes, you know, you have to do what you have to do.
00:32:30.590 --> 00:32:33.190
Now, I'm not saying do anything unethical.
00:32:33.190 --> 00:32:37.690
I'm not saying do anything blatantly open like, okay, we're just not going to have any passwords anymore.
00:32:37.690 --> 00:32:39.410
I'm not talking about that.
00:32:39.410 --> 00:32:40.870
I'm not talking about things like that.
00:32:40.870 --> 00:32:45.766
But I'm thinking that if somebody's really looking at this realistically, they know what I'm talking about.
00:32:45.932 --> 00:32:47.482
We need this system here.
00:32:47.482 --> 00:32:49.433
We need to deal with this particular vendor.
00:32:49.433 --> 00:32:51.863
We need this, how can we do that?
00:32:51.863 --> 00:33:00.275
I know there's some problems there, but we need to deal with this customer who is in this region of the country that's a little bit
00:33:00.275 --> 00:33:03.225
shaky or had some issues.
00:33:03.225 --> 00:33:07.806
Or from a part of the world rather.
00:33:07.826 --> 00:33:16.068
So yeah, you have to have that flexibility and you have to be able to really look at this stuff objectively.
00:33:16.068 --> 00:33:16.779
We're all humans.
00:33:16.779 --> 00:33:17.869
We all got emotions.
00:33:17.869 --> 00:33:22.194
We're all gonna, I've done it myself and we'll do it, right?
00:33:22.194 --> 00:33:31.982
But if you're gonna be successful, you're gonna have to be able to take a couple steps back and say, okay, what is the actual outcome that we want to accomplish?
00:33:31.982 --> 00:33:37.006
The outcome isn't to feed you or your security team's ego.
00:33:37.047 --> 00:33:40.929
The outcome is to protect the organization, right?
00:33:42.363 --> 00:33:48.803
So your career and everything like that, I love my career and I'll build up my career and everything like that.
00:33:48.803 --> 00:33:58.183
But when somebody is paying you or when you're a part of an organization, that means you have to protect the organization doing what you're supposed to be doing, right?
00:33:58.183 --> 00:34:04.910
Which is, if it's security, if it's some kind of marketing or productivity or desktop or
00:34:04.910 --> 00:34:10.130
storage or anything like that, there's a kind of a responsibility.
00:34:10.130 --> 00:34:17.070
I've been using the term malpractice recently outside of the medical field, right?
00:34:17.070 --> 00:34:21.610
There are certain things that people can do that is malpractice.
00:34:21.610 --> 00:34:32.590
Not following security controls, not really having those communications, not really going out for it being visible, putting rogue AI, rogue
00:34:32.730 --> 00:34:36.003
networks into an environment, all kinds of stuff.
00:34:36.003 --> 00:34:37.575
That's detrimental.
00:34:37.575 --> 00:34:39.176
Man, did I get a little soap box there?
00:34:39.176 --> 00:34:40.376
Sorry about that.
00:34:41.384 --> 00:34:43.886
Yeah, you actually answered my last question.
00:34:43.886 --> 00:34:48.361
I was going to ask you if you had any advice that you wanted to give for security practitioners and leaders.
00:34:48.361 --> 00:34:58.480
It sounds really like choosing your own battles and making sure that you're focusing on protecting the business as a whole.
00:34:58.531 --> 00:35:01.794
Yeah, choosing your own battles, focusing on the outcomes.
00:35:01.794 --> 00:35:07.519
This is something I still have challenges with.
00:35:07.519 --> 00:35:13.744
Being able to step outside and say, am I being the jerk here?
00:35:14.305 --> 00:35:21.931
Or being able to really look at it objectively, what is actually trying to be accomplished here.
00:35:21.931 --> 00:35:25.524
And I think that if you have that particular mindset,
00:35:25.556 --> 00:35:26.808
it's infectious.
00:35:26.808 --> 00:35:28.861
It'll infect your team, right?
00:35:28.861 --> 00:35:32.197
You can go out and your team will say, yeah, what is our outcome here?
00:35:32.197 --> 00:35:38.226
It sounds really kind of after school special, dating myself again, but that's the way it actually will happen.
00:35:38.226 --> 00:35:41.460
If you really have a team that's focused on
00:35:41.587 --> 00:35:47.049
the outcomes and doing the right thing, you will have a successful team.
00:35:47.049 --> 00:36:03.554
Something I live by definitely is that teams are responsible for an organization's success, but organization's failure is always due to leadership.
00:36:04.622 --> 00:36:13.222
And there, even as an individual contributor, there is some degree of leadership that you have to do in doing your job.
00:36:13.222 --> 00:36:23.422
So even if you're a security analyst or something like that, you have to show those leadership qualities and be able to, because that will support your security
00:36:23.422 --> 00:36:33.502
manager, your security director, your CISO, and then the people outside the security organizations, your storage folks, your desktop folks, marketing folks, all that kind of
00:36:33.502 --> 00:36:34.222
stuff.
00:36:35.442 --> 00:36:38.325
This is all great information, Doug.
00:36:38.325 --> 00:36:46.451
And I really am so happy that we were able to get you on today to talk more about your experiences with cyber resilience.
00:36:46.451 --> 00:36:50.474
Before we wrap up, did you have anything else that you wanted to share with the audience?
00:36:51.104 --> 00:36:58.741
No, what I would like to once again emphasize that there's a lot of bad stuff out there.
00:36:58.741 --> 00:37:08.390
There's a lot of bad things that you hear, but you really have to say, okay, what can I do?
00:37:08.686 --> 00:37:09.166
Right?
00:37:09.166 --> 00:37:14.686
Kind of focus on what can I do and not focus on a lot of gloom and doom and everything.
00:37:14.686 --> 00:37:23.626
Like I said, I brought up a lot of things that, it's like, oh man, AI and information management and information classification and everything.
00:37:23.826 --> 00:37:25.046
It's overwhelming.
00:37:25.046 --> 00:37:27.626
It's like, no, this is a blank sheet of paper.
00:37:27.626 --> 00:37:28.006
Right?
00:37:28.006 --> 00:37:29.326
Here's a pencil.
00:37:29.486 --> 00:37:30.866
Where do you start?
00:37:30.866 --> 00:37:31.946
You start in the corner.
00:37:31.946 --> 00:37:33.026
How do you eat an elephant?
00:37:33.026 --> 00:37:34.246
One bite at a time.
00:37:35.046 --> 00:37:37.006
This, you could do this.
00:37:37.006 --> 00:37:38.800
So I guess my thing
00:37:38.800 --> 00:37:41.801
is don't be overwhelmed, right?
00:37:41.801 --> 00:37:43.982
It's very easy to be overwhelmed.
00:37:43.982 --> 00:37:46.762
Concentrate on the goal, concentrate on the outcome.
00:37:46.762 --> 00:37:53.744
It sounds like really, I know some people say, well, that's easy to say.
00:37:53.744 --> 00:37:57.105
Well, it's easy just to throw up your hands too.
00:37:57.125 --> 00:37:59.366
So I'd rather go with the other.
00:38:01.642 --> 00:38:10.162
Well, just for the audience, if you want to learn more about how to strengthen your cyber resilience strategy, we have a lot of great resources out on Cohesity.com.
00:38:10.162 --> 00:38:11.810
I recommend checking it out.
00:38:11.810 --> 00:38:22.338
Also, if you found this discussion useful, please follow us for more episodes of Zero Downtime, where we'll take a look at some of the trends that are shaping data security in
00:38:22.338 --> 00:38:23.859
2026 and beyond.
00:38:23.879 --> 00:38:26.301
That wraps up another episode of Zero Downtime.
00:38:26.301 --> 00:38:27.972
Thanks for watching, everyone.
00:38:28.738 --> 00:38:29.250
Thank you.
00:38:29.250 --> 00:38:30.451
Thank you, Shelly.