logo

NJP

Covestic Podcast E01- Lets Talk NOW - SecOps

Import · Nov 10, 2022 · video

hello and welcome to this episode of let's talk now my name is Dana Nori and I'm the director of servicenow alliances here at povestic and today we are joined by our director of security Barry Stewart Hey Barry how's it going hey how are you Don nice to see you good thanks for being with us so Barry's been in the cyber security space for about 20 years I believe Barry yeah too long too long so yep about 20 years of cyber security in total and the last 10 of that has been predominantly within the servicenow space looking at how do we take these Advanced cyber security tools and make the most out of them for our customers leveraging that A Better Together methodology that servicenow is really successful with great great so so we want to dive into that today but I think we want to start with a few articles about what is going on in cyber security today so if we could just pull those articles up and talk through a few of them that was great absolutely a this is this is my favorite part of the podcast when we do cyber security in the news because I think that really that makes it topical it makes it relevant to all of us here at cafestik we really do focus on providing the best cyber security integration points for servicenow and servicenow solutions but I think it's really important to have that good context when you're looking at things what's going on in the industry why should we bother in the first place sure it's it's not a it's not a big shock to anything that there's a shortage in a cyber Security Professionals in the market there's always there's constantly press out there saying hey a there's a shortage we can't find the skills I think the most recent a Department of Labor statistic was somewhere around a 3.5 million job deficit that's just an ongoing thing and they're not expecting that to change anytime soon what we're actually seeing now is is a new risk is people actually rethinking their choice of why did they get anti-cyber security because a it's becoming an arduous task you know a in this recent survey half of the respondents came back and said look a ransomware has changed the game things are getting harder you stay on top of it's it's harder to maintain that threat landscape a and it's just a recording theme one of the things I like to do when we're when we're holding these sessions is we just pick the top five articles what we're looking at right now are the top two articles that were on Google today really just speaking to this ongoing crisis that we're reaching that a cyber security itself is becoming a bit of an untenable task how do we how do we maintain our landscape and we have all these millions of vulnerabilities these things we need to patch or maintain or take care of a and it's it's there's a lot of analogies I've heard over the years are we boiling the ocean how do we identify the right things to look after every day there is a new and again this is just the next article down on Google today every day there's a new patch every day there's a new zero day a new part of that that internet of things the integrated landscape that we all live in today uh how do we get our arms around that how how does a cyber security professional a a seesaw with a huge investment in tools and policy how do we become successful in driving down the rascular environments you know it's it's an interesting conversation sure it certainly is so how about this one we have up here uh this may uh get close to home for some folks that this is I think this is a recurring thing and this speaks to a couple of areas for me won a supply chain you know a lot of the time when people so that the key headline here is yet again a a point of sale malware has released tens of thousands of credit cards I think the the most recent analysis is the the group that did this and it's profitable work there's a reason this keeps happening that the group that actually achieved his acts probably gonna net of a 3.4 billion sorry 3.4 million round and up there a little bit further sound on a Tuesday a but the key takeaway is this is not a new thing a student's arrest that you might remember there was a huge a Target which a almost a seminal text and how you manage your cyber security environment because it was not Target that were actually a effect and Target themselves so they're pretty okay cyber security platform the the the providers of their point of sale equipment in the other hand were pretty lacks and that created the Ingress point for Bad actors to then go on and have the negative impact and the brand and everything that kind of happened subsequent to that event this to me really highlights that this is an ongoing thing it's not going away it's still very much a case of how do we make sure the devices that are critical that are holding important data for our business how do we protect those how do we get arms around them and do that in a timely fashion there's no such thing there's absolute with no such thing as being able to remove vulnerabilities a and perpetuity short of just unplugging them that that was what a colleague of mine was a really big fan of that as a as a security measure air gapping is a valid technology but in in remediating this it's not always the right solution though it might not fit your business need so when we look at these things it's about reducing the the life cycle of these vulnerabilities have the longer the career they have a there's an old analogy about the longer a vulnerability is exists that the lesser the skill set that's needed to exploit it because a kits become available it falls more into the script kiddy domain and as a result you know the severity of it is not changing at all the accessibility is so the real crap the real thing is trying to deal with them in a timely fashion that when you're dealing with millions of vulnerabilities a day how do we identify the right ones how do we prioritize the correct things and how do we avoid wasting our time with things that maybe are of lesser criticality it may seem severe but it's actually on a pretty benign business device that even if it was to breach uh it's low risk for us as an organization that that's a an ongoing topic and I think a lot of organizations are at the very early stage of that conversation these are for me these articles really do serve as a reminder that this is on you know it's never mind ongoing in a lot of cases the analysis points that that they're actually trending up this is another good example um where we had another data breach this time it's in the HIPAA area we're dealing with Keystone Health and what we're dealing with is a wide variety of their brands a actually suffered a major data breach again in terms of reputation in terms of repeat custom that is a major implication a lot a lot of people if they find out hey my healthcare provider is not taking care of my information they may be a little bit more pragmatic about the healthcare provider they choose in the future and there's obviously a media you know kind of recoil events that occur impact and share price if you're publicly traded there's a lot of different things going on there absolutely absolutely I think we may have one more article here to uh take a look at yes so I think that's that's I think that speaks to the other side of the equation where cyber Security Professionals are are maybe you know get into that Breaking Point we've got all of these things going on business is still booming organizations still need a valid security measures be it a cloud security governance Cloud security posture management data loss prevention these are clear imperatives but the the utilization of those tools I think as we go forward then what I'd like to talk about a little bit is is as we move away from the news articles is that's really what convestites specialize in is how do we enable you to get the the benefit of your spend hey I I have a global environment I I I've invested in Palo Alto Prisma I have a qualis in place for my environment how do I prevent bar note from a team so how do I make sure that when we are focusing on a particular asset application or cyber security remediation activity that that effect is not in itself but you know we're not using a swear Equity we're not burning through our people to remediate that risk we're working efficiently we're working effectively we're talking about really unheard of Concepts like user experience a something that I found it drives security a lot of the time is simply user experience a you can show the most compelling graphs and pie charts known to to human civilization but F if it becomes cumbersome to actually affect that progress or you've built extra Gates into that a you're not going to get success and that is one of the things that's been a trend across every organization that I've worked with in my career is that that we we at confessed it we call it the last mile where okay we have the Telemetry we have our threat intelligence we have everything in one place so forth a how do we and vulnerability in in the the conversation we're having today is a wonderful example of this where if we find something in an environment a particular vulnerability a confistic specializing three things in in improving that for our customers a intelligent prioritization or as we like to call it back in back in the UK knowing where the crown jewels are if we can identify what's important on your company Network well perhaps these are the things we need to remediate in minutes and in hours they need to be dealt with with a white glove service without very aggressive remediation but perhaps the rest of the environment can take a more LAX approach or not necessarily lacks but doesn't need to be so aggressive that we burn out our teams the other piece of the buyer found is the efficiency and I really like a vulnerability as an example of this because it's a great example of where a burnout occurs like I've witnessed it firsthand in some environments where it often the systems of measurement can be different a an in the Red Corner we have our cyber security team who are using tenable and qualis to report on the vulnerabilities and your environment but and the blue Corner we have our unsung heroes we have the I.T Department the people that are actually doing these remediations screaming hey SCCM says these are patched you said you found this vulnerability Microsoft said the fix is this why are you still why is my graph not trending down why are we not seeing that progress well one of the Fantastic things that's baked into the conversic methodology is what we call first pass second pass vulnerability management where we work with our clients they identify hey automate first pass let's use let's use scorn let's use secm let's use your traditional patch and methodologies that you're using in order to do what we call that first pass a vulnerability management second pass is what we like to call the residue or the residuals and it's exactly as it sounds there is exceptions to this I I can deploy a Microsoft Patch to a thousand servers and it works perfectly for 950 or 999 but there's one server that the particular file that's actually vulnerable in this case let's say it's a dll file it was locked or there's a group policy that wouldn't let that file get deleted so the patch is going to end successfully that the new files are there everything's good secm believes all as well and this is where a bit of that I wouldn't call it conflict but this static the the kind of the turbulence that occurs during the last mile is we say hey I told you to patch that what are you talking about I did and so the cycle goes by adopting the cavistic methodology and having those it you know kind of baked in processes to your vulnerability life cycle it tends to close that out for our clients and they spend more of their time focused on prioritization what are the the assets in our environment that we can maybe afford to go more aggressively with a or or perhaps they've achieved a new high water mark and what we're looking at is seeing uh okay we've we've now eliminated all of the uh severity fives from our design environment now we want to start looking at severity for we can start trending down uh so these are key takeaways for me and when I when I and I really want a call back to what we talked about at the for the start of our meeting that there is a lot of burnout in the industry it's incredibly difficult to find cyber Security Professionals uh at the best of times with this added Dimension a it's more and more important to make sure that we're not just empowering our end users to be successful for remediation and providing them with a good user experience but given the right tools to cyber security teams because at the end of the day that's going to drive retention it's going to make you more successful and it's going to allow you to take more ownership and and take a better control of the environment where everybody's working towards the same goal well thank you Barry for that deep Insight really appreciate it so for the customers out there listening to the podcast and from your perspective what are three recommendations that you would give when they're considering deploying this area for any customers looking at vulnerability response that are three a golden rules for the golden rules number one don't eat the elephant uh what that means is never work on vulnerability management using spreadsheets or lists uh work using tasks worked using groups use intelligence use the way you see your assets are aligned within your environment and focus what's important number two a have a partner that you can trust it's really important to find a service new partner with an element of pedigree and the the servicenow security arena there are no a large number of servicenow partners that have done a security implementations across the platform or Integrated Security Integrations where they leverage heavily on cmdp data so be very a Discerning when it comes to selecting the right partner so that you can be successful the the last point would be to educate your internal team for the Persona they are going to have what one of the things that I've I've experienced quite a lot is that some organizations will just bundle in an application use it and expect everything to go great it's really worthwhile there's phenomenal training on the servicenow uh website to really help your end from all the way from your end users your fulfillers the people that are just requesting things from the service portal all the way up to your administrative level staff I really can't recommend that enough so the three golden rules don't eat the elephant pick a good partner and educate your people because it will make it sustainable there you have it folks from Barry uh well Barry listen this has been great and look we love having Barry on board and one of the reasons why is for what I like to call Barry so we heard it don't eat the elephant and find the crown jewels uh so great takeaways but so Barry's been great having you today on this episode of uh uh let's talk now domestic podcast we're going to wrap it up and I just wanted to thank everyone for tuning in uh stay tuned if you want to reach out and have a call with Barry talk about uh VR secops irm please get in touch with us and uh thanks for joining thanks Barry thanks again appreciate it you're welcome bye now

View original source

https://www.youtube.com/watch?v=XFiNcsiCxhk