logo

NJP

Tightening Cyber Security - Workflow Wednesday 8 June 2022

Import · Jun 08, 2022 · video

june 8th in another workflow wednesday on now with troy and i'm now with try to talk about two things what's happening on the servicenow platform now and what's happening right now in the business world well this week it's a cyber security focus and i'm super excited to have my guest let me unpin my camera and mike ellerhorst from imaginext mike thanks for jumping on with me absolutely thanks troy always a pleasure to spend some time and and share some knowledge indeed um you know we've been talking for a while that as we look at cyber security you know obviously servicenow has so many different capabilities to add into that but that's often the technology piece and with imaginext being a partner of third era you can bring in so much of that great wisdom that helps the people in process um but this week in fact yesterday i got to catch part of your session you had an opportunity to be on stage at quallas's security conference 2022. uh tell me about that so excited for you to get on stage and really be recognized as an expert in the people in process around cyber yeah yeah thanks it was it was a it's been a bit of a whirlwind of a week uh denver on monday san francisco tuesday back to denver last late last night um so i need might be my coffee cup with me but uh right yeah it was you know real real exciting so qualis this year has done this um roadshow where they've had these qsc qual security conference in about 10 different cities so far across the us and um this week being the the rsa conference in san francisco which brings a lot of cyber security practitioners and vendors and you know that ecosystem into san francisco qualis has has always had a uh a conference across the street to capture some of that energy and tap into the ecosystem and so you know with with this being a really big week um the session that i actually got to participate in was the announcement of the rollout of the next iteration of of qualis called flagship product vmdr so vulnerability management detection and response so um there's a big announcement vmdr 2.0 um some additional features that have been in beta for the last couple months are now generally available and um you know and it was really exciting to talk with uh with nagi who's the chief product officer at qualis about the this shift in narrative that qualis is really trying to support from vulnerability management and looking at it as you know a bit of a technical challenge to um risk management and it being you know just a piece of broader business and technology risk and running a business and so you know it was it was fun to talk about my experience standing up patch management programs helping customers design vulnerability management teams and um you know and one of the one of the pieces of the announcement was this native connector and and marketplace application on the servicenow platform so so really con continuing to strengthen that partnership i see between quality and servicenow right right and we talked a little bit about that before and the so many things in servicenow i mean i've got several clients right now that we're kind of walking through that journey of cmdb to csdm and all the things that go with that and i think in the cyberspace there's also journeys whether it's grc to irm to esg right there's there's so many acronyms so many different journeys that we go through um but one of the things that i wanted your thoughts on is you know as we look at vmdr in qualis that we have many clients that that might have qualis they might have servicenow but they're not connected we have others that they are connected in and are kind of growing that people in process let's spend some time to walk through that evolution kind of starting with a customer that that maybe perhaps you know has servicenow but they're they're looking at implementing koalas to get some more information and what's that journey look like as they build out particularly from imaginext's perspective the people in process around tightening their cyber security yeah absolutely and i think you know i'm we're a little biased but to me i think that's where partners and implementation partners like third era and imaginex um are so important in companies journeys of figuring out their their i.t transformation so so quality and servicenow and you know some of the some of the folks out there may be saying wait qualis has already had this integration with servicenow for a number of years like what's what's new about what's different right yeah and so so so at a high level i think there's kind of three different um ways that servicenow and qualis are can connect and can kind of play together so there's a there's a cmdb sync which is has been in place has um has gone through a number of iterations and and it's a way to to true up and and try and you know continue to validate the asset repository within servicenow and align it to the scanning targets and what's being managed within qualis bi-directional sync really asset driven number a couple of years ago service now introduced and has been investing in the the secops module which includes a vulnerability response piece of it um there's a lot of great workflow there's some um prioritization engines and rules that that can that are built in there and there's some native connections to automatically pull qualis data into that piece of service now right the third now is this um itsm uh vmdr excuse me for itsm which is uh it's a marketplace app uh on the servicenow marketplace that qualis has developed and is another connection to be able to actually pull back more vulnerability data into the itsm module so so you don't have to purchase the secops module to be able to get some of the capability and some of the functionality um that that other connection enabled so you know this is this is a little bit of you know hot off the presses and so i think um it was it was interesting you know the the demo was great and who provided you know some really good visuals of what the uh what the functionality looks like it can look like but some of the dialogue that happened at lunch and and you know in the hallways after the congress after the or during the conference was so what about this and what about that and started you know talking about these different all the boundary conditions right exactly and all these different scenarios that existing customers are thinking about um you know one of the other women that i i spoke with they've just spent three years working with servicenow and qualis to build their integration and optimize this their vulnerability response module in servicenow right so she's like scratching your head saying well now was all that money well spent or you know did you guys just go ahead and release this for free and this is what this is one of the value propositions um of this newest connector is that if you are an existing servicenow customer this connection this marketplace app comes with your subscription to vmdr qualis so so it's um yeah it's it's definitely been an evolution and i would say it's not um the evolution isn't done and yeah the evolution isn't done in and when i looked at it again when i i was able to catch the first half of that session yeah and and when i saw the capabilities where i really seem like it fit is is those customers that are starting to stand up just kind of base level oh i need a vulnerability response process what's that right that kind of base zero ground zero you now you could stand up vmdr and start getting that into itsm change to be able to resolve those prioritized vetted you know vulnerabilities that qualis is finding um but it it really only starts the foundation right it only gets them started and that's where i think search what's now is secops piece to bring in vulnerability response yeah because now qualis can feed right into it have that true risk coming in have that information so you can prioritize it but also very likely particularly as clients get larger they're going to have more than one source qualis is great but you know very often and i won't name the names but you know there's very often multiple sources that are in in the platform for different technologies different environments you know as enterprises grow you know that happens um that there's multiple sources and i think that's where you know when you think down that journey you can start with quality mdr into change then qualis into secops into change but also you know then then you can grow into saying well vulnerabilities at some point either can become security incidents where we are breached or they become security incidents where i need to look at i need to fire up my security team to really do security incident response to be able to look at is this going to become something that is the front page that we need to avoid yeah yeah absolutely no and and i think um that's my initial take kind of that that journey that you talked about so we've we've been part of the beta we've we've been able to deploy um this in our servicenow sandbox and so so we've been able to poke around a little bit but again you know we're our sandbox doesn't have all those fringe cases doesn't have all the diff you know we only have a few hundred assets in our sandbox we don't have a hundred thousand assets it's gonna change and it's gonna be different but um one of the things i talked about with with nagi yesterday is exactly what you were saying i think this is a great it reduces the barrier for entry to up the game of companies vulnerability management programs it's a way to actually start to introduce this concept of business risk and prioritizing what do you fix first right the number of vulnerabilities and and there's some some very interesting stats that they had put up i wish i took a picture of one of their slides or got one of their slides um they showed this kind of funnel of there's like a hundred and eighty thousand defined vulnerabilities yeah i remember that's like right 180 000 then you know then they chopped it down into the ones with known you know with known exploits then ones with weaponized exploits right there's some that are just you know security researchers trying to figure out what is you know if all the stars align and you're somehow on the box already you can do xyz yeah and it gets down to the like there's then there's only a couple hundred named kind of front page vulnerabilities and so for organizations and smaller security teams less mature you know it teams or companies that you know it is is not is a is an important piece of the business but it's not the core piece of the business right how do you make sense how do you how do you get from that hunt you know 180 000 known vulnerabilities time you know multiply that out based on the number of assets you have down to the ones that actually may sink the ship you know and so so i think this this is it's a great enabler for it teams who may be used to working and interacting in the servicenow platform to start talking the same language with the security teams who are spending time in qualis and understanding and talking vulnerabilities because it's really starting to connect that dot those dots and build this common lexicon of risk which then the i.t and security team can lock arms and go talk to their business stakeholders and say this is why we need to patch your system this is why we need to have these uh you know maintenance windows this is this is the business risk so so that's what i'm really excited about you know it's it's like the technology is now enabling and at a point where um it's making some of that people and process change a little bit easier right a little bit easier indeed um because you know as as you look at the stats too again you know kind of the from the industry side of things the cyber attack surface the way i keep saying is the attack surface continues to multiply in and you know grow at compounding rates um and more organizations are really having a tough time keeping a handle on even what is my cyber attack service forget managing the vulnerabilities on it um and then face that with the opposition you know the we face a very predatory set of hackers it's it's really frightening with the tools that they have um that tightening cyber security is so critical in that out of those stats in the industry there are many many organizations that know it's a problem but have struggled because like you said the technology hasn't been there there hasn't been a good kind of segue in to start and it sounds like you know from your perspective and and i'd agree from what i saw that this is is kind of a good way into it that you can start with vmdr get that in get that started the other thing you talked about is is having the security teams that that might be living in qualis starting to talk to the it teams the itsm teams tell me a little bit more about some of the people in process that you've seen in between that wall if you say how have you helped organizations build those relationships so that that moves more quickly because is king in tightening cyber security too absolutely yeah and one of the things i talked about with nagi also yesterday where you know unfortunately this is this is something that we we've we help you know almost all of our our our clients our organizations that are implementing or trying to mature their vulnerability management programs this is a challenge that's faced where the security team has one remit they have a certain set of objectives they have a certain set of kpis and metrics that they're trying to achieve the it operations teams have a different set of metrics a different set of kpis different incentives and they're often misaligned and so um unfortunately we get into this kind of no-win situation where security is trying to provide visibility identify all the vulnerabilities they don't want to be the ones to miss the the in the armor where the arrow comes through right from a security practitioner and and this is a bit of the reactive frame of mind but a security practitioner is saying well if i pointed it out then it's not my fault that it got compromised yeah okay right and that's where you get these giant spreadsheets and millions of vulnerabilities that get get exported and tossed over the fence to the to the it teams with a you got to fix it and you know there's processes that make it overwhelm right a 7-day sla for criticals and a 30-day sla for highs and okay is that realistic you know and then the i.t teams receive this volley of you know this mountain of vulnerabilities and oh by the way they also have a day job of running your it operations partnering with you know their application owners their business owners and so how do they fit that in right and so um you know so so for me even before you know even before this announcement and this connection like what this is enabling is something that we've been talking about for the last 10 years you want to get it and security aligned on what are the business outcomes and what is the what are the true risks what are the crown jewels what are your most important assets what are your mitigating controls that actually may bump a you know qualis critical vulnerability down to a you know company abc medium or low vulnerability because you've got all these other you know mitigating controls or you've got processes in place right so um so it's it's connecting those different dots of what is the vulnerability what is the asset who's using that asset what's your control environment around those assets that may be you know reducing the likelihood of that exploit being being uh exploited you know that or that everybody being exploited i agree completely and and it kind of extends that journey that that we talked about a little bit that you know you're all you're really getting to the point where i inside a service now i now have you know vulnerability response security incident response i have that common services data model so i have that if this ci goes down what business services business capabilities or impact so i see the business impact but then you also alluded to you know really because i get further down this journey i'm bringing in policy compliance and integrated risk so now based on that common services data model i i truly have a framework of controls and a framework of risks now you know like you said on the top of this panacea that we've talked about for a decade yeah right and it's all then built upon this foundation of assets partner assets software assets business processes that is in many ways of service now that is the foundation of running that platform and so yeah it's um you know it it can create this perfect ecosystem of all these different data points being presented in a single pane of glass in a single tool set that will enable companies to make better decisions faster with more confidence you know and and and manage their risk yeah in indeed now getting there is the is is the fun part getting there is is indeed the fun part and that's where i wanted to spend our last couple of minutes mike um you know if if someone's watching this and they they want to learn some more um what steps would you have and then i've got some from a third era standpoint but always like to get your perspective first if someone's wrestling with the oh my gosh i need to tighten cyber security uh we've been looking at quality looking at service now um but my people in process might be struggling what's a good next step with imaginext yeah absolutely so we you know imaginex we we try we say we we try to make sense of cyber security and and we want to bring a pragmatic and practical lens to helping our customers helping our clients establish mature and operate their security programs so for me and if you're in the audience and you're saying oh my gosh you're talking like a way past where we are right that's okay we you know we we meet our customers where they are and wherever you are you know is the one 0.1 on the maturity scale or a 3.9 on the maturity scale there's always improvement opportunities and we meet our customers where they are so you know from a call to action perspective if you've hear if you heard something that's interesting reach out to me my email is is very easy mike.ellerhorst imaginextconsulting.com connect with me on linkedin if you're an existing qualis customer and you're really interested in you know that angle you can reach out to qualis imaginext.com that'll get into my team into the right group and and we can uh we can help talk through next steps um you know it's in some ways vulnerability management feels a little bit like uh motherhood and apple pie every company needs to be doing it and and in concept it's not that hard you find it you you know you you find a hole in your armor you fix the hole in the armor but it is pretty complex yeah well that's the thing is in in my experience it can feel overwhelming like you said you know i've got this million entry spreadsheet that i tossed over the wall on either side either i tossed it or i received it right um so many of the organizations i've spoken to and worked with in the past have felt that overwhelm and with their day job keeping them busy it's like well that's overwhelming and it gets set aside and so i think that's where as clients reach out to yourselves and as they reach out to myself or the others at third era um you know we can help walk through that one of the things i wanted to share is our security and risk team just recent released a no-cost assessment called a security hardening assessment so let me share this screen it's just a one page view but in this security hardening assessment what they get is a chance for our experts to come in and really look at two primary areas if i could talk about it from a service now from a now perspective is looking at vulnerability response as well as configuration compliance configuration appliances as you're standing up your assets as you're standing up your servers are you following all the different rules that we've put in place to configure them properly and those two tools from a servicenow perspective are fundamental to really tighten cyber security and so this free you know security hardening assessment is a way for clients to reach out and say hey can i can i get a quick glimpse you can see it's a way for us to come in very very quickly in about two weeks time frame give you some recommendations of where you're at as well as kind of a what would the next steps be to implement you know those things on your environment and like you said let's meet our clients where they're at yeah and and you hit on something that's really really great there troy and i and i forgot to mention but one of the the things that we talked about a lot yesterday you know a number of the folks on the stage was how do we continue to fix the vulnerabilities before they get into the environment and so one of the stats that kind of blew my mind was of all of the hundreds of millions of data points that that qualis has collected and their threat intelligence and their research team has evaluated about half of the assets that had log 4j the log for shell vulnerability on them right about half of the assets were end of life or end of service and so from a from a basic it hygiene perspective if you're keeping up with you know software updates if you're maintaining that configuration compliance you've eliminated half of your attack surface for one of the most you know widespread vulnerabilities in the last decade so you know this this configuration evaluation and making sure that what's being deployed into your production environment is hard and is safe and is good is is an incredibly valuable uh process and and capability to have yeah from maintaining a good cyber security posture you know just that that data statement is just reeling in my head that if if i heard you right that half of the vulnerabilities were on systems that were already end of life that that you know for a number of different reasons we knew we we should have been standing this thing down um you know we're not releasing that's good config lifestyle life cycle management um to it that can address half of the vulnerabilities that's huge yeah it reduces that million line spreadsheet by half or more right it makes that prioritization exercise easier it makes the you know the actual conversation and it and it strengthens that partnership between security and i.t because you're no longer you know fighting over you know this this debt that that you're carrying as an organization right indeed yeah well again awesome to hear that you know third era has got that that uh that uh offering out there so yeah our our security team is is pretty stellar and if you have not met third era and you're watching this third era is a servicenow elite partner and one of the things that we strive to stand out as and we do is really being able to span the platform because servicenow is ridiculously large wonderfully large but before joining tordeira i used to say if you ever meet someone that says they know all of servicenow run the other way at thirdera i've been able to really be supported by practice teams that really do know this platform and our security team is no exception and so it's it's been great to you know have some time to talk about you know this area of the platform and spend time with you mike so thank you for jumping on a workflow wednesday with me um and i look forward to having some conversation with clients together thanks again troy i always appreciate the time yeah thanks so much

View original source

https://www.youtube.com/watch?v=eX4FtkV1Z80