SecurityMetrics Podcast | 9
Cloud Security: Management Versus Implementation
As a former US Air Force Cyber-Warfare Technician, Vince Romney (CISSP) has been able to leverage his unique military experience in the private sector–most recently as CTO of SK2 Technology, developing high-security encryption applications.
Vince Romney joins Host Jen Stone (Principal Security Analyst, CISSP, CISA, QSA) to explore cloud security challenges in the corporate world, but also to share the valuable insights about risk analysis and mitigation which he gained during his military service.
Listen in to learn:
- Common misconceptions about the security, implementation, and risk management required for cloud solutions.
- How decision makers in the corporate world can apply specific risk assessment principles and methods used in the military.
- Lessons learned in military operations that will help you increase the discipline, honesty, and problem-solving ability within your organization’s security program.
“You can live a much calmer life if you accept that your work is never done. Readjust your mindset to see that if you want to succeed in cybersecurity, you should be constantly engaged in learning new concepts and trying new tactics.” –Vince Romney
Resources:
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
Cloud Security: Management Versus Implementation Transcript
Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst at Security Metrics. Today on the podcast, we have Vince Romney with us. Vince, I am so excited to have you here with us today. Will you please introduce yourself to everyone so they know who you are and where you come from?
Sure. And I'm excited to be here too, Jen. It's good to catch up with you after several years of not working with you.
So Absolutely.
Absolutely.
Yeah. I come from a, a military background as far as, my cybersecurity environment goes. And, but prior to that, I have been involved in technology since, nineteen ninety six. So I I've been in technology most of my working life. And, as such, I've been able to see a lot of different viewpoints and a lot of different domains of security, including banking and fintech, general retail, you know, and then through the military, both DOD and then DOD contracting. So So I had a lot of good opportunities in that. But in the military, I was one of the first guys to stand up in a cyber warfare cell.
Back in two thousand five, cyber warfare was not really a discipline. It was something that information operation flights in the air force or, you know, Essex groups in the army. Those guys all have some kind of interaction with the, opposing nation states, shall we say, on on that network domain, but we didn't have truly what was called a cyber warfare environment.
And so for us, we got tasked in our information operations flight to stand up the cyber work ourselves. And it turns out we were the first in the National Guard to do that, as, AGR group, active guard in Zurich. But, also among the first few in the military in general. And so we had a lot of unique opportunities as a result of that to work side by side with, different agencies, three other agencies in their operations to kind of learn from them and teach them what we you know, what little we knew and, and evolve that whole program through its formative years into where it, when I finally retired in twenty thirteen, you know, it was a professionalized, environment.
We had full doctrine. We had training, funnels feeding us to twenty fourth Air Force, and it was a whole different environment. It was great to go through that that formative and very, nascent environment and now, you know, take that experience and apply it in the, in the retail, or, you know, general enterprise world has been really entertaining.
That's super interesting. It's and that's a particular interest of mine. I'd love to learn more about that, at some point, maybe have you back on and talk specifically about those experiences.
Today, I asked you to come on and talk about cloud security because that's something that you're applying now in in your in your civilian life.
And there's a lot of people, our listeners who care a lot about cloud security and would like to kind of hear how other people are doing it.
Yeah. Cloud security is one of those things that I think people look at the cloud as a solution, which it's a platform, obviously, and as such, has some things that help you build solutions. But in and of itself is not a solution. And one of the things that, I get asked often is what's the difference between cloud security and an on prem security environment? And I always bring up the old, twenty fourteen, Codespaces attack, if you remember that.
Codespaces was a, you know, basically, an online code repo, similar to Git, and that type of thing. But they they also hosted, you know, full websites and and and all of that as well. And what turned out happening was somebody hacked in to Codespaces back end, gained root privilege and ended up after a little bit of, you know, network warfare, so to speak, as they tried to, eliminate the threat. They found out they've been breached, and they tried to shut things down and switch passwords out. Well, this guy had set up a new account, and so he just deleted the entire account. So, you know, that company went away in one click. Literally.
They they just disappeared because the entire cloud account, the AWS account, was gone. It had been deleted.
And so if you think of that comparison with an on prem environment, you can't delete a whole bunch of, you know, hardware. You can't take the company out in one fell swoop. It takes more work to shut down an entire on prem system.
So from from that perspective, cloud is different simply in that the threat surface is potentially more volatile. You can do more damage in the cloud than you can on prem in many cases.
That said, now you look at cloud security from the perspective of what's available to me as a security professional to use in a way of tool sets and systems to secure my environment. And now I have an entire group like AWS or Azure helping support me with great tools. So I have more at my disposal in the cloud, you know, literally at my fingertips to help secure my environment. But I also have an environment that if I do the wrong things, can disappear with a single click.
And and, you know, you brought up a good point about a lot of people are kind of confused about what cloud actually is. You know, how why why people choose the cloud? So why do you think, for example, you've got security people, you've got, implementation people, you've got people who have to maintain that environment, versus an on prem, and then you've got management who who ultimately makes the decisions on how the money is made. How, or how how the money is spent? How do you, how do you see differences in in how they view it and how those those decisions are made to eventually go to a a cloud based environment?
Well, I think I've I've got some interesting stories to kind of tell through that.
One of my friends is the, cloud security architect for Liberty Mutual.
And, they are largely cloud now. Several years ago, an edict was given from their c staff.
We're going to the cloud.
And, as as, Craig Olsen is his name. He's a great guy. I should introduce you and have him come on the podcast as well at some point. But Craig said, oh, okay.
What? You know, what is this? Why are we doing this? What's going on? But he was tasked with securing the cloud.
And, you know, this is a forty six billion dollar insurance company. And so he, you know, he looked at that and that adopting task, and he became a cloud expert as a result.
Excuse me. And I think a lot of us become steeped in cloud simply because we get an email.
You know, I I joined my current position with Nu Skin as their enterprise security architect as a result of them making the decision to go cloud. And at the time, I was working with a company who was cloud native. So they had started their company when I'm in the cloud. So you have two different perspectives.
One, they saw the opportunity of the cloud. And again, the the leadership said, we need to be nimble. We need to be able to scale. We need to be able to, you know, grow and and and be elastic in our infrastructure capability because we have admin flow in our sales cycle.
And we need to be able to accommodate that flow when it happens, but then not pay for it when it's not happening. So that company, started from ground zero as a cloud company. So all of their systems were coordinated.
In the case of both, Liberty Mutual and Nu Skin, it was a lift and shift. It was we're gonna take our stuff that we have on prem, and we're gonna plug all of that into a cloud environment.
Uh-huh.
And that comes with a whole different set of challenges Yes.
As I might imagine.
And, you know, as anyone that has worked through a lift and shift will tell you, it's probably not the best way to do it, but it's the way some people do it.
Yeah.
And I think it comes from that perspective difference of management.
Management sees they view another company. They've got friends say at another company in the management staff that says, hey. We're cloud native, and it's awesome. You know, we do all these things, and and we can we can hit, you know, a ten x or a twenty x or a hundred x on our sales and not even feel, in in a in a just a quick, you know, like a a promotion.
And you can't do that on prem. It's it'll just it'll destroy your systems.
Yeah.
It's pressure because you can't put new you can't rack up a whole bunch of new boxes Sure.
In five seconds. You know? But you can start spinning up new c tunes in that kind of time frame.
Sure.
And, so the the management sees that potential, and they wanna go there. What they so they're looking at end state.
Mhmm.
Implementers have to look at what actually gets you to the end state.
Right.
And as implementers, we have to look at it and say, alright. End state is everything cloud native, everything functioning, you know, in in serverless state So that we're not even using the kind of archaic architecture of an EC2 with an RDS and all the the system set up so it's kind of traditional stack. Mhmm. If you want to be cloud native, you wanna be running off Lambdas, you know, or you have to run off containerized environments. And you wanna do that so that you're literally able to be essentially fully ephemeral across your entire stack. Yeah.
And that means you're taking advantage of what the cloud has to offer.
Mhmm.
But again, the management never sees it that way from day one unless they're actually technical people.
Right.
And that's pretty rare. Yeah.
So I I see that as well.
So I one of the best parts of my job is I get to go evaluate people's environments for security, and they could be anything from a single server in a in their closet to up to, fully cloud native where, as you said, using Lambda or using, the Google Cloud platform, a services only, environment. But where I see people really struggle with implementation and, leveraging what's what's available there and security is when they try to take what they have on prem and imitate that in the cloud.
So all of the Right.
All of the security challenges that they have on prem are maintained again in the cloud rather than eliminating, a massive, like, layer of those security vulnerabilities, the potential security issues there by going to a services based architecture in the cloud. But but as you say, if you're not familiar with that, if you're uncomfortable and so I always, now I have to time out because I always promise the listeners that we're not gonna take it too technical and too geeky. So here's here's some basics. It's and it's and it's super, I mean, it's not super easy, and I'm not gonna lie to you. It is not super easy, but the concepts are you can get this.
You have servers and you have workstations that you use in your environment, and you you say, okay. Now I wanna go to the cloud to leverage all of the things that you were talking about, being able to to quickly adapt to changing situations.
There's ways to do it so that what looks like your your server client architecture in in your, office environment looks exactly the same in the cloud environment, and you'll be comfortable with that. But it's the wrong way to do it. And so if you can kind of let go of the old architecture that you're familiar with and really take advantage of the way the new architecture works in AWS or in Azure or in GCP, then you're going to to to event you're going to it's gonna take you less time. It's going to be less maintenance overall, and you're going to have less security issues. But it does take training, and it's exhausting training at first because your brain's like, oh, this is a different if it's a different way of looking at how architecture works.
Right? I mean, are you seeing that as well?
Yeah. Absolutely.
I liken it to when when you get that tasking that you're going to move to the cloud, basically plan on having to keep up with a full time college load in study while you actually apply that same information you're studying in real time when you're working on it.
Absolutely.
And it's it's that kind of workload from a, an ingestion of knowledge standpoint.
And it's important for managers to know that because if they give somebody a task and they don't know, oh, also you're going to school full time to learn how to do this, and then you wonder how come you're not getting this done, or how come you're slow, or how come you're grumpy because you're getting no sleep.
Yeah. And there's that's a huge difference, in management perspective versus implementers perspective. Right. Again, you know, the management goes, well, hey. It's it's in the crop. It should be done. And and I think the other part that happens from an assumptive basis with, with management is they hear the promise of things like, you know, security as code, infrastructure as code, automation, you know, security automation, all of that stuff that is certainly there in the cloud for you to use and implement, but it is not automatically there.
Right.
That's the part that gets your your, conflict between management and implementers is the management thinks, oh, it's already there. No. Capacity to implement it is there.
Right.
But doing it is not there.
And a lot of people don't know yeah.
They don't even know where to look to if you don't know some basics about security at all levels of technology, you don't even know that there's a module you should be looking for or a configuration that you should check.
Yeah. I mean, there's, what about I think in in, in AWS, at least, I think there's a hundred and fifty pages of configurations.
Yeah.
So, you know, you to say you should know all of those automatically is incredibly assumptive and impossible. Yeah. And, you know, even for someone who's been working in it, the concept of I'm going to do task a and something as simple as, say, stand up an e c two instance. Mhmm. Well, yes. You can just go in and stand one up, but there are several pages of configuration that go with that process.
And best practices are one thing, but you can also just get it done.
Right.
And best practices are obviously the things we wanna be following.
Mhmm.
But when you've got, you know, management or, you know, project managers standing over your head saying get it done, get it done, get it done. Sometimes that doesn't happen.
So it's that concept that in the cloud, we have these cool capabilities, and we can build controls around them, but you have to build the control Right.
That tells you, oh, that EC2 deployed in a open to the public status. And you don't want that, therefore, you're gonna back that out or at least the word to you.
Right. Because it it's easy to, it's easy to skip the steps and leave yourself wide open.
Right. And, you know, we see that in the news a lot. You know? Another s three bucket left open to the world.
And and it's it's very consistent. And, you know, it's not that a a public s three bucket is a bad thing. It just depends on what's inside it. Right?
Exactly.
And what capabilities exist within that, you know, content if there's, you know, the capacity to take that content and use it in a fairly sleek way or if that's got an application in it. You're using a static app inside an s three bucket.
Okay. If that application has no functionality and it's just there for viewing, that's one thing. But if that has a form field in it or it has, you know, it's it serves up data, now it's a different thing. You can start manipulating that code because it's public. You can start gaining access to that and looking at it.
So so how, as you've gone along that path, how have you been able to basically bake security into the process of implementation?
So one of the things that we we learned is that as a security team, you pretty much have to assume you're always behind because you are. Developers are gonna work way faster on building than you can keep up with controlling.
Yes.
And so you have to start looking at that automation concept. And initially, there's, you know, configuration alerts and things like that through some of the incumbent, you know, you've got GuardDuty and and CloudTrail and CloudWatch that you can aggregate in and start, actually firing off, building landers that fire off based on conditions that are met and send an alert out and say, hey. You now have something that's public that may or may not need to be public. Or Right.
You have a configuration that, is, somebody set something to, you know, zero dot zero dot zero dot u you know, size zero. Okay. Yeah. Yeah.
It works, but that's unfortunate.
So when you see those kind of things show up, you go, oh, okay. We need to build this controller app that says, if I see that, not only alert me, but actually stop it from happening.
Mhmm.
Actually block that from going to production. And as we start going down that road, we recognize that, there's probably not, enough manpower to be constantly reacting to these things and, you know, and and, let me say, every time I build a Lambda, I've gotta build another one or change configurations every time a new situation comes up. And I wanna push that workload out to the actual developers.
Uh-huh.
I want them to be able to write their own rules Right.
And and then so that it fits them. You know, I can check those to make sure they're not riding crazy. But if they're actually creating their own, security, and then the guardrail just sits there and they can bounce off that guardrail all the way down through the, the completion to production, then they're good. And and security no longer has to work with it.
So, one of the guys that I work with, is named Taylor Wilson. He's a sharp a a, security engineer as I've ever met. Just really, really sharp guy. So he looked at, an open source tool that, he's called Cloud Custodian and said, okay.
How can I take this concept, take this open source code, and work with our team and manipulate this into something that is much easier for a developer to go in and just write a rule Uh-huh? That says, okay. I need this rule to say, you know, if a happens, stop it. But if a plus b happens, it's okay.
Those type of things. So conditional sets and the rules can just be written and none of the underpinnings that, you know because you can't just write a rule and expect it to happen. You have to have all of the code that supports that rule. All of the interaction that grabs something off the EventBridge and says, oh, here's this event.
Now validate it against the white list. Okay. Is it in the white list? No. If it's not in the white list, then kill it.
But then notify, you know, you have to write all the tools. This way, there's a single rule set and all of the other supporting stuff comes in. And so taking that that concept, Taylor built this whole project with our team, and we now have what we call security bots. Oh, nice.
Security bot just allows, anyone to write the rule. The rule gets applied using that same set of, validations and and, you know, consumes it up with EventBridge. And then EventBridge is where we capture everything that happens from GuardDuty and Quadro itself.
Okay. Great. And so so, so was it easy buy in from the developers then?
It's it's getting there. Especially once we really had it working and we had a full kind of, hey. Everyone come see our demo. We had a lunch and learn and said, everybody come look at this. It was really kind of fascinating to see that shift of, wow. That is cool.
Yeah.
That that makes my job as a developer much easier.
Nice.
And when you when you can, you know, buy in like that and we learned that arguably from Craig and his experience at Liberty Mutual. Mhmm.
I think that's why it's so important to share information as security professionals is, you know, you can't you raise the tide, all boats raise with it.
Right.
And, you know, so we we're trying to elevate that in that process.
And I've seen more sharing of information and and sharing of of, knowledge, during COVID, which we're all experiencing right now, than I have before. One of the, but but old attitudes, you know, carry on. I have found in the security world, people are very, hesitant to to share information and even more hesitant to ask questions. Almost like, oh, I'm expected to know everything. If I ask a question, maybe it'll it'll reveal me as as not capable or something.
Have you seen that?
You are hitting on a real strong nail there that we all have this because we have a background in security, people call us experts.
Uh-huh.
And I was shattered at that because, you know, even back when I was just in technology, someone go, oh, you're an IT expert. And they go, no. I have certain sires that I know a lot about.
Mhmm.
You know, don't know that I understand a lot about who are asking about this over there. I I have my brother, as an example, called me the other day and says, hey. I've got a question about, this this, process in Adobe Photoshop.
I think she said, Stan, I have no No idea.
You know, that is the most complicated application on the planet, and I've never even tried to use it. Yeah. So yeah. No clue. But people make that assumption. Yeah. And I think the same thing happens in security and maybe even more so because it's a domain that's, even now, still relatively new Mhmm.
In in a in a standpoint of a focused profession.
Right.
And it two thousand five, we stood up in the military.
Right. And it it's it's difficult because, in order to be a security professional and say and, basically, what we're doing is looking at other people's work and telling them where it sucks.
Right?
And so in order to do that, you have to have a level of of ego or self confidence that allows you to step up and say those things out loud. Right? So first of all, you have to have kind of that personality. But then to be really good at it, you have to be able to drop that ego and accept that you don't know oh, let me give you an example. This was really hard for me because I had to stop in the middle of an assessment.
I was working with a group that was doing a services based AWS architecture. It was different from anything I had seen before. Right? So so red flag number one to me is shut up and listen. Right? And the guy that was talking to me was arguing with me about something I was asking to do in terms of of, monitoring and alerting, and he said, you don't understand.
That's not how it works. And I said, I did not blow up because that's what I wanted to do, but I went, can you tell me more? And he said, well, you know, I used to be the guy that helped AWS customers with their security questions. He was an SA in that field, and he and he had done that for four or five years and then decided to move to, a single company and work there for he just wanted a little change. Right? So he knew his stuff.
And so when I was able to go, alright. I'm gonna listen to what you have to tell me. And he spent a day and a half educating me on not just what they were doing and why, but how it how it worked in the larger scheme of things in the AWS, architectural concepts. So I was able to to learn so much about how does security work in something that I was unfamiliar with, but it was hard.
I'm not gonna lie. I'm accepting that and and breathing and go letting it go and saying, yep. You're right. I don't know your stuff.
Tell me more. And I think a lot of security professionals feel like that.
Yeah. I I think it's one of those things that, again, going back to that comment that you're basically a college student for the rest of your life if you choose to get into security. Yes. Because there's always more to learn, and we need to be learning.
But you'll get left hand vectors. Yesterday, I was in a meeting reviewing the app a mobile app for security. We were going through the code review, and, they were using some data points that potentially had some HIPAA compliance.
Oh, okay.
You know, we got it with and and I have to admit, you guys, I don't know enough about HIPAA to know if this is a concern, but I know enough to know I should go look it up.
Yeah.
Yeah. I need I need to go research this and find out what the answer is.
HIPAA is not an easy research topic.
Yeah. And so, you know, my and I I never wanna become a HIPAA expert, but I wanna be able to know that that's a concern. And I think that's you know, when you look at all the certifications and stuff out there in in, in security and they're, you know, they're proliferating, certainly.
Mhmm.
I think the value that something like a CISSP has is merely in providing you enough information to know what you need to research and what you need to look up.
Hundred percent agree with you.
Yeah. You don't come out of there as security expert. I'm sorry. The CISSP is nothing but a number, assigned to you since you passed the test. But if you take it for what it is, you know how to ask questions now.
Yeah. I mean, I'm proud of mine because it was a hard test.
But That's a hard test.
Do I apply it? Only as you said, you know, understanding it gives you a basis to know where to look for to to do additional research.
Looking deeper. Yeah.
Yeah. Every every day learning a new thing. So, so you spoke a little bit about some of the tools that you're familiar with.
As you said, there are the cloud incumbent tools are there because they work in certain situations, but there's also open source tools that have that bring some value. Where where do you find a balance in those different tools?
It's really interesting because I look at our current stack, and and I talk to friends that have their stuff going in. And it's very interesting because, first off, depending on the size of company, they they find value in if we've got the budget, just buy something that already works. Mhmm. So if you have a use case that doesn't really fit within, the the incumbent services Mhmm. Similar to, like, our automation platform that we build.
Right.
Okay. That doesn't really exist.
You have to build it. Uh-huh. But are there, you know, opportunities to buy something? Well, as we move towards a more serverless foundation, so breaking down monolithic gaps that we're lifting and shifting Yep. Turning into serverless containerized workloads, etcetera.
Well, you know, yeah, we could go out and, for our service mesh, get STO and take that in and start building that out. We could use open open policy agent and, you know, and and put, Envoys on all our containers and and and start filling it out that way. But that takes a lot of development time. Mhmm.
Or you can go out and buy something that already exists. You know, you can go buy, the Prisma Cloud stack, which is like PureSec and RedLock and, Twist TwistLock and all that. How you go get, Aqua and you know, there's all these toolsets out there for Kubernetes, orchestration layer management and and great. You know, see where's your budget.
But I think there's two things that come down to where are your resources.
Right.
And what is your use case? So if your resources are cash and your use case requires something that's not incumbent with the dynamic in the in in the cloud, great. Then just buy it.
Sure.
You know? But understand, you still have to have a human for many depending on the on the tool to actually manage that.
Right.
I mean, I I love when people go out and buy solutions and then find out that they're gonna have Sharplore for the next three years on that contract because they don't have the manpower to actually get the tool functioning.
Right.
I often, try and take those things into account. People ask me all the time, what tool should I use? I don't know.
But, I mean, we can figure it out a lot of times. So like you said, if they don't have there was a a great little, well, you know, it's so little. They're pretty pretty massive fast food franchisee that that I, worked with, and they had a a couple of guys who were really sharp. For some reason, they had hired a couple of really sharp, hungry, young, fairly inexperienced IT guys who wanted to learn more. They wanted to and one of them was especially interested in in security. But they they didn't have enough work to really keep them busy, but they didn't have the budget to buy any tools for what they needed.
They they were going through a I believe it was a PCI assessment. And so, the one guy said, well, what should we do for for monitoring and alerting? And I said, well, your guy here wants to learn more about security. Why don't you give Mosec, and and let him go?
I would never say that to someone who had no time and a lot of money. Right? And so so looking at what is the tool, yeah, what's your budget? What's your manpower?
What's your internal appetite for learning and figuring out something new?
For sure. And and that's a, you know, I think most of us that went into technology and profession in one way or another are there because we like to learn new stuff.
Yeah.
Yeah. And there's there's a reason you get drawn into that because it's not something that you're gonna learn once and then just rehash over and over and over again. Yeah. It evolves way too quickly. So you're always learning, and that's a great thing.
But like you said, some companies, they've got the pockets, and they keep a lean staff. Right. And you just say, great. Plug the tool.
Mhmm. And if we need to hire a human to manage it, great. We'll hire a human. Mhmm.
But but we're good on that. And it's just kind of an interesting, thing because I've seen many different approaches. And you and your position have probably seen, you know, dozens more than I have of every you every company has a unique kind of resource, to risk profile. Mhmm.
And so they look at their risk, and then they look at their resources, and they wanna apply resources to risk, but it's very unique to each company how they do that and what kind of relationship ratio that has.
Right. Right. Yeah.
And talking about risk, I don't think anyone in security, can really do their job well if they don't understand how how risk works.
And because you can end up applying all of the security to all of the problems because you want zero risk, which makes no sense. And then, also, all of a sudden, your bottom line is just out that you can't make any money because all you're doing is chasing risk. But, and and, you know, getting back to your military military training, which I'd really do wanna do, like, a whole podcast on that. But, going from military to the security domain to understanding risk, how does that give you some different insight into, how to evaluate security security solutions and and based on risk?
Well, I I think the military and and again, I speak the military is a very broad thing. It's like IT. Right? Yeah.
You know, You know, you can be a a cook. You can be a a special operations operator and and everything in between. You know, there's just so much, differential in any one person's military experience. And and I had a great and very diverse military crew.
I enjoyed the heck out of it. And and I probably had way more fun than I should have. It's evident in, you know, my my career progression. But, you know, I I took advantage of a lot of cool, fun opportunities, and and I'm glad I did.
But when it when you look at how we are trained just fundamentally, the whole training process, starts with your plan. What is your training plan? And there's this model of what are the risks in what we're about to do. And whether that's a training plan or an actual operational exercise where you're going out into the field and doing, you know, x, one of the first things you do is evaluate risks.
What are those things, and can they can they be controlled?
So the mindset is one of, hey. You know, suspect everything, assume there is risk everywhere, and then pair it down by validating that. Mhmm.
And, you know, it it's, I had the opportunity to, work alongside, some operators and provide, you know, some some feedback to those guys. And it was interesting to hear their perspectives of what we do in cyber versus what they do on the ground.
Right.
And so that was kind of fun to have those conversations and and talk about, you know, what shaping the battlefield meant to them Mhmm. Versus what it means to us, but how those two actually have a corresponding location in that if I'm shaping the battlefield from a cyber standpoint in support of a ground operation Mhmm. That those two things have to dovetail perfectly.
Oh, interesting.
So that so that the cyber side or the, you know, the information technology side of that battle space is prepared in a way that fully supports what the ground operator needs to do.
Well and I think in in that situation, you know, you're looking at, people could die risks. Right? Yeah. And so so how how did like you said, you look at all the risks and then you pair them down. How do you pair them down, in a way that that I I'm not sure how to ask the question that feels acceptable based on on potential death.
And you you actually you know, you hit on the head when you said potential death. You know, you you start ranking your risks based on impact if realized. And we do the same thing in business. Right?
Mhmm. You know? If if this risk was realized, what would that actually mean to the company? And so the same thing happens in the military.
We're just looking at it through the lenses of, you know, potentially, injury or death can occur if you screw this up. Mhmm. And, you know, when I when I was, at a stint with PAE Systems working on, as the the software security analyst for, the ground based strategic deterrent, which is the replacement for the Minuteman missile. And, so that was about as critical, set of software you could be looking at.
At. Right?
You know, from from the standpoint of what that represents Mhmm.
It's a nuclear defense of the nation.
Right.
So it has to have a risk profile around what you can call acceptable that's very different than the risk profile around a retail application that sells a product online.
Right. Right?
And and, you know, so when when you're looking at that, you take very seriously any risk that has the potential to degrade the security around a nuclear surety program. Mhmm. And, you know, we had one situation where we, we identified something that was actually a mandate from the congressional committee in charge of this and said that cannot happen.
It simply can't happen. If if that mandate is real is built into our system, we're screwed. And we had to go back through and push that back up the chain through the o seven to the actual congressional committee. We had to pick up the congressional committee and say, we can't do that, and here's why. And it was interesting to see that process because you think you you would kind of assume that a congressional committee in charge of the upgrade of a nuclear surety program like that would have a clue. But they didn't. Yeah.
Well and I wonder if it's if it's because of of training. From what I've seen in my in my work, most people are not trained in risk management. They're they're not training trained in risk analysis, and they don't understand, how risk mitigation works. And so and it's not something that we teach in school. Right? And Right. And so I wonder if maybe, people in charge of making decisions, if they don't have the right kind of training in risk management, are maybe hampered in in that rulemaking.
I absolutely can agree with that. Because if if you're looking at things through purely a functionality standpoint and not trying to apply risk to those functionalities, you're you're just making decisions completely blind to their impact.
Right.
And, you know, we I see that on a fairly regular basis in corporate. But the upside is my background in the military, again, I think this is where military people are are uniquely positioned if they wish to jump into security to do so Mhmm. Is because you push back up chain your risk.
You say, alright.
Mhmm.
Are we willing to accept this risk?
And and, you know, we we used to and I've actually moved this into our corporate world. We used to have a thing called quad, and you know the military probably familiar with it. But it basically has four sections. It's a standard sheet of paper, four sections, turns into a PowerPoint slide when you're actually presenting it.
But, and it it nearly says, what is the decision to be made? What's the background on that decision? What are the risks associated with that decision? What are the artifacts associated with that?
And and it's made for delivery to, you know, like, o seven or an o six, who's looking at this to make a decision for their environment. And you're basically telling them, if you make this decision, this is what it means.
So if you accept this, then here's the risk that goes with it.
So it makes it very clear for them to make a a decision on it?
Yeah. Yeah. Because you're you're you're outlining that whole environment. Here's the scope. Here's what this is.
Here's the risk associated with with saying, yes. I accept this. And, and then, you know, let's take it to the retail world. At that point, I'm willing to say, you know, asset up chain, and the person accountable to the company says, yes.
We will accept that risk. Great. I just apply compensating controls and move on.
Right.
Right? You know, I because my job is now defined.
Sure.
As a stability practitioner. And that that's one of those things that the military taught me is, hey. When when you get orders and you provide the risk assessment, when they say, yep. There you go. Run with it. I mean, now it's just up to me to provide compensating details.
Right. And this is something that so, depending on the, compliance that a company is trying to meet, PCI is very checkboxy. You have to do certain things. If you wanna do a compensating control, it's hard.
Right? HIPAA is different from that. HIPAA is very risky. You start with the risks, and then you you form your program around that.
So it's harder because you have to think more about it, that you have to take more into account, and there has to be more communication. But one of the things that that I sometimes run into in security professionals are people who who want to eliminate all of the risks.
And Right. And they and they get frustrated because they're like, well, they don't understand the risks. And I'll say, well, did you explain it to them? Yes. And what did they say? They decided to accept it. I said, okay.
So they did understand the risks, and they got to set the risk appetite for your organization.
So you need to understand what that risk appetite is and then do your work based on that. If you are still freaked out about some of these risks, keep bringing them up or find a way to to to resolve them based on what you your your current mandate. Right?
But, understanding who makes the decisions about what and how to communicate, that's not an easy thing.
Yeah. And and I think it's anyone that assumes they're going to remove all risk is in the wrong profession. Right. Security is, you know security in its foundational piece is risk management.
Right.
That's what we do is we determine what level of risk, we're going to, you know, provide to a given environment.
And, you know, zero risk? Great. I know how to do that. Turn the systems off.
Right.
Yeah. There is zero security risk for your data.
The fourth side to it is is that you also can't conduct business. Yeah. So there's, you know, there's that balance. And in in military operations, risk is inherent. There's you cannot, you know, go engage an enemy without risk.
It simply isn't there.
How that risk gets mitigated is the art of war, you know, legitimately.
If you've ever read, you know, that, you know, some scenes Art of War I have. It's a great yeah.
See, you know, there's a lot of great principles about how to engage your enemy Mhmm. Which, you know, we all have, some common, cyber enemies out there that we are all fighting Right. In one way or another. And, you know, yes, we are all in defensive roles. Mhmm.
You know, there's there's no offensive role in civilian side right now. Right. And I I don't know who it's up to get there. But No.
That doesn't, yeah, it doesn't seem like the right direction to take it.
Yeah.
And and, again, the nature of cyber is that it's a continual arms race. So even if there was offense, it would, you know, just continue to scale back and forth.
Sure. Yeah. We and and we we hear we hear that all over and over again, that they they only need to get things right once, and we have to get things right a hundred percent of the time. And and so fighting that defensive battle, is it's it's exhausting, but, there's some good people out there doing it.
Yeah. And and part of that exhausting part, I think, is mindset. If you go into security with the understanding that your job is never done and that you are constantly going to be engaged in the process, to me, that's what makes it fun.
You know, I need to be more like you, Vince. That's that is such a great attitude. I'm gonna I'm gonna take that as a takeaway, readjust my mindset and and have more fun with it.
Yeah. I, you know, it's I find I can live a much more calm life, you know, with our current environment with all the crazy going on, as a result of the pandemic.
You know, I view it through those same eyes. I view it through the eyes of someone who says, I'm a little bit cynical about pretty much everything. Uh-huh.
Oh, I view it through a a scope of motivations and understanding that I am not going to be able to apply my sensibilities to everyone else, but I should also not assume that everyone has, shall we say, altruistic or best for everyone intentions.
Sure.
Have a a couple of different courses that you're taking at any one time and be able to just work through those courses because that process is what makes this job fun.
Yeah.
There's always cool stuff to learn, always new stuff to apply. And, you know, and you get surrounded by those same people. Right. So then the people you're working with are all of that same kind of mindset.
And and that's where it gets kinda cool. You know? Like, some of the best people I've worked with in my life have been since I've jumped into cybersecurity as a full time gig. I see. So, you know, two thousand five forward, I can I can identify a dozen people that I just think are the best guys out there?
So Best people to work with.
So as a veteran, what do you think makes security a good job for someone who served in the military?
Well, certainly, all of the perspectives that you learned in the military are applicable here. You know, assuming you learned them. There's obviously people who go in the military don't learn good things, but, you know, most come out that they've spent time in the military with a unique perspective on how to view the world. And with that, I think it's very applicable to security. The discipline required to be successful in the military is exactly the same discipline you'll use in security to continue to learn, to continue to, you know, move forward. And, and then in the military, you're taught to state it as it is.
Don't try to quote things. Don't you know, you screw up. You screwed up, sir. I screwed up.
This is what I did. You know? Here it is. You take full responsibility. And in security, that's, you know, yeah, I screwed up.
This is what I did wrong. Here's how we're gonna fix it. That is the statement that makes, you know, everyone comfortable. And that's something that we learn in the military as a standard part of life.
Yes. Excellent. I really really appreciate that that insight. And, again, thank you so much for for joining me today. I look forward to talking to you again in the real near future.
Absolutely, Jen. Thank you for having me. It's been fun to reconnect.
Thanks. Bye Bye bye. Thanks for joining us. I hope to see you again here on the Security Metrics podcast.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
