
Sign up to save your podcasts
Or


Episode Summary
Implementing an effective security program has become a necessity over the past decade. And without a doubt, all businesses need to level up their security game to mitigate risks and protect their information.
But small- and mid-market companies are somehow left behind when it comes to security guidance and realistic capabilities.
In this episode of the Cloud Security Reinvented podcast, our host Andy Ellis introduces Brian Haugli, the Managing Partner at SideChannel. They talk about the increasing demand for cybersecurity for all organizations, why the black-and-white view won't get us far in security, and the future of technology.
##
Guest-at-a-Glance
💡 Name: Brian Haugli
💡 What he does: He's the Managing Partner at SideChannel.
💡 Company: SideChannel
💡 Noteworthy: Brian is the co-author of "Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework."
💡 Where to find Brian: LinkedIn
##
Key Insights
⚡ There's an increasing need for security programs in the middle market. We often forget about small businesses and mid-market companies when discussing cybersecurity, risk management, and privacy. But Brian believes that all organizations deserve to have adequate security programs and that these programs are equally as important as other business segments. He explains, "There are a lot of companies — hundreds of thousands of companies — outside the Fortune 2000, and most, if not all of them, require some diligence on what their security program looks like. And the question is, 'Who's going to lead that? Who can lead that? And can they afford it?' The market is actually very hot when it comes to this space. We've grown tremendously over the last two-plus years, and it's an area that people are genuinely looking at. It's not just because of what's in the news but also because people are realizing, 'Hey, we should be doing our own diligence and security practices the same way we put wrappers and guidelines and posts around financials and sales and marketing.'"
⚡ Even when you move to the cloud, you still have responsibilities as the owner. Contrary to what many organizations think, you still have responsibilities even after you move to the cloud. Brian says this is one of the most common misconceptions in the field. "People are just thinking, 'Oh, all of this is done by the cloud or the provider or the SaaS platform.' And that's just not true. It seems to happen across just about every sector we touch. And again, especially with the middle market, which is traditionally both underserved and doesn’t have the expertise — it's an area where they're a bit naive about who's responsible for what."
⚡ We need to forget about the black-and-white mindset because it's not helping anyone. If you want to make progress in your organization regarding security, you need to let go of the "gotcha" mentality, as Brian calls it. "Black-and-white" thinking won't get you far. "Honestly, as security practitioners and as an industry, we really need to not just bury, but we need to completely kill this 'gotcha' mentality that stems out of old-school audit thinking or GRC analyst policy wonks or whoever's managing a system where their entire thing is, 'Well, I need these things managed. And if it's not exactly as this says, you don't get credit.' We need to move to risk management, where there is gray. There is the ability to accept risk as long as it's appropriate, but this pure black-and-white view and this 'gotcha' mentality that exists within security professionals — we just need to get rid of that. It's not helping anyone at all."
##
Episode Highlights
You need to test what you're training on in security training.
"I've always truly believed that you have to test what you're training on; it's like school. You study material, you then take a test. Are people actually understanding the material? Great. Move on to the next thing. We need to do that with security training as well. Maybe phishing tests are not part of that, but something else, maybe it's surveys. Maybe it's just more granular testing, not ‘gotchas.’ So, I don't know if we need to bury the whole thing, but we need to bury the aspects of this that don't seem to be really working but still seem to be getting much more play."
Learn what is going on within policy.
"That was the biggest change for me going from a real technical guy to somebody who could actually shape an information security program as a whole. So, the advice really is that even if you're a SOC analyst, even if you are a pen tester or you're in a hunt team or whatever, learn what is going on within policy because it'll help you a lot more than [others]. Conversely, if you've always been an auditor or a policy person, really try to understand what the actual technical components of those policies mean to the folks who are reading them, using them, and have to abide by them."
Ease of use is the future of technology.
"These seem like simple things, but you know how people interact with apps and everything. That is how people are operating and interacting with technology. We need to move those types of technologies to look and feel like that because that's what people are comfortable with, and the more people are comfortable with it, the less they're questioning the technicalities. So it's just ease of use."
This podcast is hosted by Orca Security
Episode Summary
Implementing an effective security program has become a necessity over the past decade. And without a doubt, all businesses need to level up their security game to mitigate risks and protect their information.
But small- and mid-market companies are somehow left behind when it comes to security guidance and realistic capabilities.
In this episode of the Cloud Security Reinvented podcast, our host Andy Ellis introduces Brian Haugli, the Managing Partner at SideChannel. They talk about the increasing demand for cybersecurity for all organizations, why the black-and-white view won't get us far in security, and the future of technology.
##
Guest-at-a-Glance
💡 Name: Brian Haugli
💡 What he does: He's the Managing Partner at SideChannel.
💡 Company: SideChannel
💡 Noteworthy: Brain is the co-author of "Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework."
💡 Where to find Brian: LinkedIn
##
Key Insights
⚡ There's an increasing need for security programs in the middle market. We often forget about small businesses and mid-market companies when discussing cybersecurity, risk management, and privacy. But Brian believes that all organizations deserve to have adequate security programs and that these programs are equally as important as other business segments. He explains, "There are a lot of companies — hundreds of thousands of companies — outside the Fortune 2000, and most, if not all of them, require some diligence on what their security program looks like. And the question is, 'Who's going to lead that? Who can lead that? And can they afford it?' The market is actually very hot when it comes to this space. We've grown tremendously over the last two-plus years, and it's an area that people are genuinely looking at. It's not just because of what's in the news but also because people are realizing, 'Hey, we should be doing our own diligence and security practices the same way we put wrappers and guidelines and posts around financials and sales and marketing.'"
⚡ Even when you move to the cloud, you still have responsibilities as the owner. Contrary to what many organizations think, you still have responsibilities even after you move to the cloud. Brian says this is one of the most common misconceptions in the field. "People are just thinking, 'Oh, all of this is done by the cloud or the provider or the SaaS platform.' And that's just not true. It seems to happen across just about every sector we touch. And again, especially with the middle market, which is traditionally both underserved and doesn’t have the expertise — it's an area where they're a bit naive about who's responsible for what."
⚡ We need to forget about the black-and-white mindset because it's not helping anyone. If you want to make progress in your organization regarding security, you need to let go of the "gotcha" mentality, as Brian calls it. "Black-and-white" thinking won't get you far. "Honestly, as security practitioners and as an industry, we really need to not just bury, but we need to completely kill this 'gotcha' mentality that stems out of old-school audit thinking or GRC analyst policy wonks or whoever's managing a system where their entire thing is, 'Well, I need these things managed. And if it's not exactly as this says, you don't get credit.' We need to move to risk management, where there is gray. There is the ability to accept risk as long as it's appropriate, but this pure black-and-white view and this 'gotcha' mentality that exists within security professionals — we just need to get rid of that. It's not helping anyone at all."
##
Episode Highlights
You need to test what you're training on in security training.
"I've always truly believed that you have to test what you're training on; it's like school. You study material, you then take a test. Are people actually understanding the material? Great. Move on to the next thing. We need to do that with security training as well. Maybe phishing tests are not part of that, but something else, maybe it's surveys. Maybe it's just more granular testing, not ‘gotchas.’ So, I don't know if we need to bury the whole thing, but we need to bury the aspects of this that don't seem to be really working but still seem to be getting much more play."
Learn what is going on within policy.
"That was the biggest change for me going from a real technical guy to somebody who could actually shape an information security program as a whole. So, the advice really is that even if you're a SOC analyst, even if you are a pen tester or you're in a hunt team or whatever, learn what is going on within policy because it'll help you a lot more than [others]. Conversely, if you've always been an auditor or a policy person, really try to understand what the actual technical components of those policies mean to the folks who are reading them, using them, and have to abide by them."
Ease of use is the future of technology.
"These seem like simple things, but you know how people interact with apps and everything. That is how people are operating and interacting with technology. We need to move those types of technologies to look and feel like that because that's what people are comfortable with, and the more people are comfortable with it, the less they're questioning the technicalities. So it's just ease of use."
Episode Summary
The cloud is the future for a reason. Besides its massive impact on security and more convenient file storage options, the cloud has fostered the creation of an environment where you can have all the information in the palm of your hand. And speaking of the cloud and technology, the best is yet to come.
However, its ability to deliver tons of information to users worldwide is a double-edged sword. The cloud has a blend of both true and false information, which makes you doubt the credibility of any source you read, whether it's Wikipedia or a random webpage.
In the new episode of Cloud Security Reinvented, Andy Ellis chats with Morey Haber, the Chief Security Officer at BeyondTrust. They get into the significance of the cloud compared to on-premise solutions, the most significant tech opportunities in the future, and the security loopholes that should have been eliminated a long time ago.
##
Guest-at-a-Glance
💡 Name: Morey Haber
💡 What he does: Morey is the Chief Security Officer at BeyondTrust.
💡 Company: BeyondTrust
💡 Noteworthy: Besides his role as a CSO, Morey is also a prolific writer. So far, he's published three books — Identity Attack Vectors, Privileged Attack Vectors, and Asset Attack Vectors.
💡 Where to find Morey: LinkedIn
##
Key Insights
⚡ Reliability is the core of the business. For Morey, reliability represents one of the most significant aspects of how he does business. "My parents had a jewelry store in Brooklyn, New York, and its name was Haber's Reliable Jewelry. The word 'reliable' was in the name, and reliability is a personal trait that I hold dear today. I believe in being reliable all the way through. The fact that my career started as a reliability engineer, and I ended up as a CSO, I still hold that word very dear."
⚡ You don't need agents to do things in the cloud. Morey believes that the cloud is superior to on-premise solutions in many ways, which is why he prefers it when doing his business. "I did not want traditional scanning technologies and agent technologies to do it. I wanted a modern approach to getting there, and that's how I've seen the evolution of the cloud. Because you don't need agents in the cloud to do the things that you used to have to do on-premise."
⚡The power of the cloud lies in the information it brings. According to Morey, one of the most significant advantages of the cloud is its ability to bring a ton of information to the user and allow them to access it at any time. However, it has its disadvantages as well. "What the power of the cloud has brought to me is that information, regardless of my job, my role, my location, my vacation, etc. I would never have thought that the cloud could bring so many different types of information together to you in a mobile fashion. And I think the key to protecting all that information is to make sure it's accurate. Fake news has been one of the biggest challenges of the cloud."
##
Episode Highlights
The Cloud Has Brought More Security
"Why would you put your data in someone else's data center that potentially could leak to a hacker that knows how to breach your environment? That lasted for a little while, and then we realized it's safe enough to do that. Then we started storing PII, etc. And in the privileged world, why would you store your passwords in the cloud? If that got leaked, it would be game over. But we've got the security good enough, so it's not a concern to do things like that. As the cloud has matured, the security of the cloud has matured. People are willing to put more PII and sensitive information there and operate their businesses."
Morey Haber: One Baseball Cap, Two Essential Roles
"It's a baseball cap. One direction on the CSO is that I'm overseeing internal resources and cloud resources. Flip my baseball cap around, and I'm the vendor. I use my own products. We use every product we make internally. But I am still a CSO, and I have the same challenges with patching, vulnerability management, ransomware and digital transformation and cyber insurance that everybody else does.
So, I try very hard to make sure that people know which hat I'm wearing. And when I am excluded from going to a conference or something because I'm a vendor, I let them know that they're not going to hear me talk about my products. I'm just trying to solve the same problems, and that doesn't always come across the way I would hope. [...] As a vendor, I have to protect what I'm selling. Let me wear my CSO hat, and I promise that I will not talk about my products unless someone specifically asks me to."
The Transition from the Pre-Cloud World
"What most resonate today are the two primary attack vectors — vulnerability and exploits and privileged accounts. It doesn't matter where the software is running; you still have to be able to identify a mistake, flaw, or vulnerability, if it is exploitable, and how you are going to correct it. Secondly, any type of privileges that can allow authentication — how are those being managed, governed, and monitored are the biggest disciplines. On the other hand, the one that I wish would go away is patch management. Vendors that have solutions where you have to use third parties to deploy patches drive me nuts. Every solution that's out there, either cloud or on-premise, should be able to auto-update itself. [...] Almost all infiltration happens because an account was compromised or something wasn't patched. Why can't vendors just patch themselves?"
The Cloud Does Bring Information. But Google Tree Octopus and John Titor
"Fake news has been one of the biggest challenges of the cloud. [...] I use two examples. One is the Tree Octopus. If you've never heard of it, google it. Google John Titor. It is a rat hole. You will go on for endless hours. That's where the cloud becomes a problem. [...] It's lore. There's no better way to state it. But if anybody wants to go down a rat hole, just google it, and you'll understand. That's the negative side of the cloud — conspiracy theories, problems, and bad information that shouldn't be there in the first place.
Unfortunately, it's just a part of the day and age that we live in, where a single statement can become fact and is supported by the internet with all that data in the cloud. You have to trust yourself to state whether that's true or not."
A Piece of Advice: Listen and Shut Up
"Listen, or just shut up. You're in a conversation to process information and formulate an opinion, but your opinion right up front is not necessarily the right answer. It is so important to be able to not talk but listen and not respond, just so you can respond.
Your voice is very important in a security aspect, but your answers have got to be reliable. They've got to be accurate. They've got to be to the point. [...] Try to speak about once every 15 to 20 minutes in a large room setting because people are more apt to listen to you when you talk less frequently with concise answers and affirm opinions."
Words of Wisdom for Future Authors
"If you have all of these ideas built in your head, start with a basic outline, something that you learned in high school. Take an outline and start writing it out. Take each bullet and break it out even further. Then start writing sentences for each bullet. Sooner or later, you're going to have 30, 40, 50, 100 pages, and you've written a book. Break it down into manageable chunks, and I think anybody could be an author."
This podcast is hosted by Orca Security
Episode Summary
The cloud is the future for a reason. Besides its massive impact on security and more convenient file storage options, the cloud has fostered the creation of an environment where you can have all the information in the palm of your hand. And speaking of the cloud and technology, the best is yet to come.
However, its ability to deliver tons of information to users worldwide is a double-edged sword. The cloud has a blend of both true and false information, which makes you doubt the credibility of any source you read, whether it's Wikipedia or a random webpage.
In the new episode of Cloud Security Reinvented, Andy Ellis chats with Morey Haber, the Chief Security Officer at BeyondTrust. They get into the significance of the cloud compared to on-premise solutions, the most significant tech opportunities in the future, and the security loopholes that should have been eliminated a long time ago.
##
Guest-at-a-Glance
💡 Name: Morey Haber
💡 What he does: Morey is the Chief Security Officer at BeyondTrust.
💡 Company: BeyondTrust
💡 Noteworthy: Besides his role as a CSO, Morey is also a prolific writer. So far, he's published three books — Identity Attack Vectors, Privileged Attack Vectors, and Asset Attack Vectors.
💡 Where to find Morey: LinkedIn
##
Key Insights
⚡ Reliability is the core of the business. For Morey, reliability represents one of the most significant aspects of how he does business. "My parents had a jewelry store in Brooklyn, New York, and its name was Haber's Reliable Jewelry. The word 'reliable' was in the name, and reliability is a personal trait that I hold dear today. I believe in being reliable all the way through. The fact that my career started as a reliability engineer, and I ended up as a CSO, I still hold that word very dear."
⚡ You don't need agents to do things in the cloud. Morey believes that the cloud is superior to on-premise solutions in many ways, which is why he prefers it when doing his business. "I did not want traditional scanning technologies and agent technologies to do it. I wanted a modern approach to getting there, and that's how I've seen the evolution of the cloud. Because you don't need agents in the cloud to do the things that you used to have to do on-premise."
⚡The power of the cloud lies in the information it brings. According to Morey, one of the most significant advantages of the cloud is its ability to bring a ton of information to the user and allow them to access it at any time. However, it has its disadvantages as well. "What the power of the cloud has brought to me is that information, regardless of my job, my role, my location, my vacation, etc. I would never have thought that the cloud could bring so many different types of information together to you in a mobile fashion. And I think the key to protecting all that information is to make sure it's accurate. Fake news has been one of the biggest challenges of the cloud."
##
Episode Highlights
The Cloud Has Brought More Security
"Why would you put your data in someone else's data center that potentially could leak to a hacker that knows how to breach your environment? That lasted for a little while, and then we realized it's safe enough to do that. Then we started storing PII, etc. And in the privileged world, why would you store your passwords in the cloud? If that got leaked, it would be game over. But we've got the security good enough, so it's not a concern to do things like that. As the cloud has matured, the security of the cloud has matured. People are willing to put more PII and sensitive information there and operate their businesses."
Morey Haber: One Baseball Cap, Two Essential Roles
"It's a baseball cap. One direction on the CSO is that I'm overseeing internal resources and cloud resources. Flip my baseball cap around, and I'm the vendor. I use my own products. We use every product we make internally. But I am still a CSO, and I have the same challenges with patching, vulnerability management, ransomware and digital transformation and cyber insurance that everybody else does.
So, I try very hard to make sure that people know which hat I'm wearing. And when I am excluded from going to a conference or something because I'm a vendor, I let them know that they're not going to hear me talk about my products. I'm just trying to solve the same problems, and that doesn't always come across the way I would hope. [...] As a vendor, I have to protect what I'm selling. Let me wear my CSO hat, and I promise that I will not talk about my products unless someone specifically asks me to."
The Transition from the Pre-Cloud World
"What most resonate today are the two primary attack vectors — vulnerability and exploits and privileged accounts. It doesn't matter where the software is running; you still have to be able to identify a mistake, flaw, or vulnerability, if it is exploitable, and how you are going to correct it. Secondly, any type of privileges that can allow authentication — how are those being managed, governed, and monitored are the biggest disciplines. On the other hand, the one that I wish would go away is patch management. Vendors that have solutions where you have to use third parties to deploy patches drive me nuts. Every solution that's out there, either cloud or on-premise, should be able to auto-update itself. [...] Almost all infiltration happens because an account was compromised or something wasn't patched. Why can't vendors just patch themselves?"
The Cloud Does Bring Information. But Google Tree Octopus and John Titor
"Fake news has been one of the biggest challenges of the cloud. [...] I use two examples. One is the Tree Octopus. If you've never heard of it, google it. Google John Titor. It is a rat hole. You will go on for endless hours. That's where the cloud becomes a problem. [...] It's lore. There's no better way to state it. But if anybody wants to go down a rat hole, just google it, and you'll understand. That's the negative side of the cloud — conspiracy theories, problems, and bad information that shouldn't be there in the first place.
Unfortunately, it's just a part of the day and age that we live in, where a single statement can become fact and is supported by the internet with all that data in the cloud. You have to trust yourself to state whether that's true or not."
A Piece of Advice: Listen and Shut Up
"Listen, or just shut up. You're in a conversation to process information and formulate an opinion, but your opinion right up front is not necessarily the right answer. It is so important to be able to not talk but listen and not respond, just so you can respond.
Your voice is very important in a security aspect, but your answers have got to be reliable. They've got to be accurate. They've got to be to the point. [...] Try to speak about once every 15 to 20 minutes in a large room setting because people are more apt to listen to you when you talk less frequently with concise answers and affirm opinions."
Words of Wisdom for Future Authors
"If you have all of these ideas built in your head, start with a basic outline, something that you learned in high school. Take an outline and start writing it out. Take each bullet and break it out even further. Then start writing sentences for each bullet. Sooner or later, you're going to have 30, 40, 50, 100 pages, and you've written a book. Break it down into manageable chunks, and I think anybody could be an author."
Episode Summary
Cloud-based solutions are the future of technological advancement. The cloud has gone through various phases, and these changes have made it one of the most potent inventions of today.
Thanks to a broad range of cloud-based tools, even founders without a development background can start a company and release a product. But that's not the only advantage of the cloud. Technological development, alongside the cloud, could significantly reduce one of the most critical issues faced by the world — poverty.
In this episode of Cloud Security Reinvented, Andy Ellis welcomes Ryan Gurney, the CISO-in-Residence at YL Ventures. They have an interesting chat about the cloud, its benefits, the exhausting role of the CISOs, and the tech practices that no longer work.
Guest-at-a-Glance
💡 Name: Ryan Gurney
💡 What he does: Ryan is the CISO-in-Residence at YL Ventures.
💡 Company: YL Ventures
💡 Noteworthy: Before joining YL Ventures, Ryan held security leadership positions at Looker, Google, eBay, and Zendesk.
💡 Where to find Ryan: LinkedIn
##
Key Insights
⚡ Your cloud provider’s weaknesses can become your problem. Since the cloud has become more prevalent, many companies have switched to it. However, Ryan believes that users must be careful when choosing their third-party cloud provider since their weaknesses may become the user's problem. "I've seen us go from attempts to keep all the data inside the borders of the company to utilizing private clouds, public clouds, and the explosion of right third-party SaaS apps and mobile apps. [...] It means that there are more environments where customer company data is being housed. Accessing that and understanding your assets is supercritical."
⚡ Security training needs to be short and to the point. According to Ryan, long-winded security training for employees is highly ineffective. Instead, it should be more precise and company-centered. "Security training needs to be short, to the point, frequent, contextual, and specific to the company and its culture. And that includes how you sign up for SaaS applications and how you manage your cloud environment. You should discuss only the areas that are important to the security company, security in their culture, and give people tips on how they can do things in their personal lives and help their family and friends. So, the old stuff around these long-winded four-hour-long training needs to go away."
⚡ I'm excited about technology being able to reduce poverty. Ryan strongly believes that we can do a lot with technology, including solving the world's most critical issues. "I'm excited about technology being able to reduce poverty and bring conveniences to people around the world. We've seen examples of it — easier access to water, bringing the Internet to everyone, and helping with sanitization. These are massive gaps in people's living conditions around the world."
##
Episode Highlights
Ryan Gurney's Career Path as a CISO in a Nutshell
"Currently, I'm the CISO-in-Residence at YL Ventures, a position that has been held by two predecessors. Prior to my current role, I held security leadership positions at Google, Looker, Zendesk, and eBay. So, I spent a lot of time in the cloud. Today, my role is really interesting. I'm not as much an operational CISO as a strict, strategic person who's helping founders and portfolios figure out their product and security story.
[...]
My industry is now investing in helping founders understand the security landscape horizontally and not just vertically. As I'm a CISO-in-Residence, it's a little bit of a broader picture, but speaking about ideation, founders need to consider the completeness of what they're doing. It's not good enough to say, 'Hey, we cover AWS.' They need to cover all the major public clouds and ideally the hybrid clouds, as well. That is where the world is."
Basic Practices Always Matter in Security
"What [security practices] should we have kept? Well, I think the basics still matter. Whether you're in a cloud environment, in the private cloud, or an on-premise deployment, being able to establish policies, identify vulnerabilities, and patch still matter, and they're always going to matter. And in some cases, with our cloud providers, we have to hold them accountable and work closely with them to do those things."
Technology Gives Us a Lot of Opportunities to Make the World a Better Place
"I think we have opportunities to do a lot with technology. We've seen examples of it for easier access to water, bringing the internet to everyone, and helping with sanitization. These are massive gaps in people's living conditions around the world. I'm interested in the security space specifically. I'm fascinated about abstraction at the cloud layer around security controls, how we can make things quicker and easier for the CISO and bang them over the head about things that need their attention, especially when we consider the challenges we have with hiring security professionals today."
Quick Takeaway: Security is Non-Binary
"CISO is a tough career, and there are a couple of things I've learned that I like to pass on. One of them is that security is non-binary. I would often have CEOs come to me in passing, and they would say, 'Hey, are we secure?' Perhaps that was just small talk, but I took it seriously. I feel an effective CISO should be able to say, 'Hey, listen, I'm aware of our key assets. I know how they're protected, and I know our key risks. We actively monitor it, and we're managing it.'
The term CISO is a bit of a misnomer. Perhaps Chief Cyber Risk Officer would be the better term. Secondly, it's important that CISOs understand their strengths and weaknesses, surround themselves with the right team, and empower others in the organization to take security responsibly and seriously for themselves. They need to be transparent, approachable, and business-focused. You need to demonstrate empathy for others because if you're coming to them, you're likely asking them to do something. So, you've got to be able to demonstrate that empathy."
Episode Summary
Cloud-based solutions are the future of technological advancement. The cloud has gone through various phases, and these changes have made it one of the most potent inventions of today.
Thanks to a broad range of cloud-based tools, even founders without a development background can start a company and release a product. But that's not the only advantage of the cloud. Technological development, alongside the cloud, could significantly reduce one of the most critical issues faced by the world — poverty.
In this episode of Cloud Security Reinvented, Andy Ellis welcomes Ryan Gurney, the CISO-in-Residence at YL Ventures. They have an interesting chat about the cloud, its benefits, the exhausting role of the CISOs, and the tech practices that no longer work.
Guest-at-a-Glance
💡 Name: Ryan Gurney
💡 What he does: Ryan is the CISO-in-Residence at YL Ventures.
💡 Company: YL Ventures
💡 Noteworthy: Before joining YL Ventures, Ryan held security leadership positions at Looker, Google, eBay, and Zendesk.
💡 Where to find Ryan: LinkedIn
##
Key Insights
⚡ Your cloud provider’s weaknesses can become your problem. Since the cloud has become more prevalent, many companies have switched to it. However, Ryan believes that users must be careful when choosing their third-party cloud provider since their weaknesses may become the user's problem. "I've seen us go from attempts to keep all the data inside the borders of the company to utilizing private clouds, public clouds, and the explosion of right third-party SaaS apps and mobile apps. [...] It means that there are more environments where customer company data is being housed. Accessing that and understanding your assets is supercritical."
⚡ Security training needs to be short and to the point. According to Ryan, long-winded security training for employees is highly ineffective. Instead, it should be more precise and company-centered. "Security training needs to be short, to the point, frequent, contextual, and specific to the company and its culture. And that includes how you sign up for SaaS applications and how you manage your cloud environment. You should discuss only the areas that are important to the security company, security in their culture, and give people tips on how they can do things in their personal lives and help their family and friends. So, the old stuff around these long-winded four-hour-long training needs to go away."
⚡ I'm excited about technology being able to reduce poverty. Ryan strongly believes that we can do a lot with technology, including solving the world's most critical issues. "I'm excited about technology being able to reduce poverty and bring conveniences to people around the world. We've seen examples of it — easier access to water, bringing the Internet to everyone, and helping with sanitization. These are massive gaps in people's living conditions around the world."
##
Episode Highlights
Ryan Gurney's Career Path as a CISO in a Nutshell
"Currently, I'm the CISO-in-Residence at YL Ventures, a position that has been held by two predecessors. Prior to my current role, I held security leadership positions at Google, Looker, Zendesk, and eBay. So, I spent a lot of time in the cloud. Today, my role is really interesting. I'm not as much an operational CISO as a strict, strategic person who's helping founders and portfolios figure out their product and security story.
[...]
My industry is now investing in helping founders understand the security landscape horizontally and not just vertically. As I'm a CISO-in-Residence, it's a little bit of a broader picture, but speaking about ideation, founders need to consider the completeness of what they're doing. It's not good enough to say, 'Hey, we cover AWS.' They need to cover all the major public clouds and ideally the hybrid clouds, as well. That is where the world is."
Basic Practices Always Matter in Security
"What [security practices] should we have kept? Well, I think the basics still matter. Whether you're in a cloud environment, in the private cloud, or an on-premise deployment, being able to establish policies, identify vulnerabilities, and patch still matter, and they're always going to matter. And in some cases, with our cloud providers, we have to hold them accountable and work closely with them to do those things."
Technology Gives Us a Lot of Opportunities to Make the World a Better Place
"I think we have opportunities to do a lot with technology. We've seen examples of it for easier access to water, bringing the internet to everyone, and helping with sanitization. These are massive gaps in people's living conditions around the world. I'm interested in the security space specifically. I'm fascinated about abstraction at the cloud layer around security controls, how we can make things quicker and easier for the CISO and bang them over the head about things that need their attention, especially when we consider the challenges we have with hiring security professionals today."
Quick Takeaway: Security is Non-Binary
"CISO is a tough career, and there are a couple of things I've learned that I like to pass on. One of them is that security is non-binary. I would often have CEOs come to me in passing, and they would say, 'Hey, are we secure?' Perhaps that was just small talk, but I took it seriously. I feel an effective CISO should be able to say, 'Hey, listen, I'm aware of our key assets. I know how they're protected, and I know our key risks. We actively monitor it, and we're managing it.'
The term CISO is a bit of a misnomer. Perhaps Chief Cyber Risk Officer would be the better term. Secondly, it's important that CISOs understand their strengths and weaknesses, surround themselves with the right team, and empower others in the organization to take security responsibly and seriously for themselves. They need to be transparent, approachable, and business-focused. You need to demonstrate empathy for others because if you're coming to them, you're likely asking them to do something. So, you've got to be able to demonstrate that empathy."
This podcast is hosted by Orca Security
Episode Summary
The information security field is changing as fast as the rest of the world, and it’s safe to assume that it will grow rapidly in the years to come.
If we look at the last decade, and particularly after the emergence of the cloud, we can't help but notice how much the security field has evolved.
In this episode of the Cloud Security Reinvented podcast, our host Andy Ellis welcomes Dan Walsh, the Chief Information Security Officer at VillageMD. They get into the best and worst practices in information security, the importance of building trust, and share their predictions for the future.
##
Guest-at-a-Glance
💡 Name: Dan Walsh
💡 What he does: He's the Chief Information Security Officer at VillageMD.
💡 Company: VillageMD
💡 Noteworthy: Dan used to work at Vanguard in business operations, but then he made both a career and industry transition and moved into information security at UnitedHealth Group.
💡 Where to find Dan: LinkedIn | Twitter
##
Key Insights
⚡ Bring good security people on to your team to improve your capabilities. Dan talks about his career transition from business operations to security. "I was always very passionate about making sure that the applications we developed were secure, which caught the attention of our security team, and then, I transitioned into working on the security team at UnitedHealth Group, which kicked off my security career."
He shares his point of view on pulling good security people into your team. Rather than pushing security people inside the organization, we should think about bringing people in to improve our capabilities. "If I can find an engineering team that scans their source code for open source vulnerabilities and that makes sure that their cloud infrastructure access and vulnerabilities are managed very well, I'm going to pull those people into my [team]; I want them."
⚡ The healthcare industry has come a long way with its security investments, but there's still room to grow and improve. We often look at healthcare as a slow adopter regarding the newest developments in information security. Having spent some time in healthcare, Dan gets our hopes up that the field is open to improvements. "I would also say that healthcare has been a bit of a low or slow adopter to the cloud as compared to some of the other industries, but I do think that because of the focus on rising costs and trying to keep them down, it's inevitable, and it is happening. In my opinion — not scientifically — we're easily over halfway there. I would say that in order to run a large health care company at scale, these days, you have to start in the cloud. You can't start on-premise. Just financially, that doesn't make any sense."
⚡ Security is all about trust. You have to build relationships with people. They have to trust you, so be excellent but also trustworthy.
"A lot of people complained, 'How do I get into security? They just hired their friend, and I really wish they would have hired me, because I think I might be more qualified.' And I think what people miss is that trust. You don't trust in them. And since we're in the business of trust, that's why it might sometimes feel like it's a club when, in reality, it's not."
##
Episode Highlights
As we move into the cloud, we shouldn't forget about access control and asset inventory
"For me, access control and asset inventory are the top two. I know that, obviously, vulnerability management is important as well. In my experience, I've seen more problems with cloud incidents, with knowing what is in my cloud infrastructure and knowing who has access to it than because something wasn't patched in the cloud."
What long-time security practice should we have gotten rid of by now?
"One thing that we still see pop up from companies in the healthcare system is, 'We want the right to inspect or the right to be notified when you're moving to the cloud infrastructure.' Well, it's like, 'You're not going to inspect GCP’s or Azure AWS’s server building, wherever that's located.' I also don't think that it's really necessary to notify them when they're making a change like that. Because I just don't know what value that adds other than creating overhead for the team. So that's definitely one, even if it's a very specific one."
The importance of trust in the security field
"Cecelia, my first manager at UnitedHealth Group, taught me how to be direct, how to get to the brass tacks and the bottom line. I remember when I first started with her, she would say, 'You have to have coins in the bank with me,' meaning, 'You have to earn my trust.' And so that was a huge lesson — to build trust with people. Because that's what security is all about. […]
It's important to build relationships prior to there being a problem. The one thing that I've just done as good practice, which has benefited me tremendously and that I would advise people to do is, 'You don't have to be the expert in the domain that you're managing, but I would say that you need to get more than an inch deep in it in order to make sure you hire the right person for it.'"
This podcast is hosted by Orca Security
Episode Summary
The information security field is changing as fast as the rest of the world, and it’s safe to assume that it will grow rapidly in the years to come.
If we look at the last decade, and particularly after the emergence of the cloud, we can't help but notice how much the security field has evolved.
In this episode of the Cloud Security Reinvented podcast, our host Andy Ellis welcomes Dan Walsh, the Chief Information Security Officer at VillageMD. They get into the best and worst practices in information security, the importance of building trust, and share their predictions for the future.
##
Guest-at-a-Glance
💡 Name: Dan Walsh
💡 What he does: He's the Chief Information Security Officer at VillageMD.
💡 Company: VillageMD
💡 Noteworthy: Dan used to work at Vanguard in business operations, but then he made both a career and industry transition and moved into information security at UnitedHealth Group.
💡 Where to find Dan: LinkedIn | Twitter
##
Key Insights
⚡ Bring good security people on to your team to improve your capabilities. Dan talks about his career transition from business operations to security. "I was always very passionate about making sure that the applications we developed were secure, which caught the attention of our security team, and then, I transitioned into working on the security team at UnitedHealth Group, which kicked off my security career."
He shares his point of view on pulling good security people into your team. Rather than pushing security people inside the organization, we should think about bringing people in to improve our capabilities. "If I can find an engineering team that scans their source code for open source vulnerabilities and that makes sure that their cloud infrastructure access and vulnerabilities are managed very well, I'm going to pull those people into my [team]; I want them."
⚡ The healthcare industry has come a long way with its security investments, but there's still room to grow and improve. We often look at healthcare as a slow adopter regarding the newest developments in information security. Having spent some time in healthcare, Dan gets our hopes up that the field is open to improvements. "I would also say that healthcare has been a bit of a low or slow adopter to the cloud as compared to some of the other industries, but I do think that because of the focus on rising costs and trying to keep them down, it's inevitable, and it is happening. In my opinion — not scientifically — we're easily over halfway there. I would say that in order to run a large health care company at scale, these days, you have to start in the cloud. You can't start on-premise. Just financially, that doesn't make any sense."
⚡ Security is all about trust. You have to build relationships with people. They have to trust you, so be excellent but also trustworthy.
"A lot of people complained, 'How do I get into security? They just hired their friend, and I really wish they would have hired me, because I think I might be more qualified.' And I think what people miss is that trust. You don't trust in them. And since we're in the business of trust, that's why it might sometimes feel like it's a club when, in reality, it's not."
##
Episode Highlights
As we move into the cloud, we shouldn't forget about access control and asset inventory
"For me, access control and asset inventory are the top two. I know that, obviously, vulnerability management is important as well. In my experience, I've seen more problems with cloud incidents, with knowing what is in my cloud infrastructure and knowing who has access to it than because something wasn't patched in the cloud."
What long-time security practice should we have gotten rid of by now?
"One thing that we still see pop up from companies in the healthcare system is, 'We want the right to inspect or the right to be notified when you're moving to the cloud infrastructure.' Well, it's like, 'You're not going to inspect GCP’s or Azure AWS’s server building, wherever that's located.' I also don't think that it's really necessary to notify them when they're making a change like that. Because I just don't know what value that adds other than creating overhead for the team. So that's definitely one, even if it's a very specific one."
The importance of trust in the security field
"Cecelia, my first manager at UnitedHealth Group, taught me how to be direct, how to get to the brass tacks and the bottom line. I remember when I first started with her, she would say, 'You have to have coins in the bank with me,' meaning, 'You have to earn my trust.' And so that was a huge lesson — to build trust with people. Because that's what security is all about. […]
It's important to build relationships prior to there being a problem. The one thing that I've just done as good practice, which has benefited me tremendously and that I would advise people to do is, 'You don't have to be the expert in the domain that you're managing, but I would say that you need to get more than an inch deep in it in order to make sure you hire the right person for it.'"
Episode Summary
If you've ever thought of pursuing a career in cybersecurity, we have an episode for you! Today's guest is a career coach and a podcast co-host, and he's here to talk to us about cybersecurity in the post-cloud era.
Chris Foulon is the co-host of Breaking Into CyberSecurity, a Cybersecurity Strategist, and a noted career coach. He says his goal is to give back by producing a podcast focused on helping people who are trying to get into cybersecurity. In addition, Chris helps professionals looking to level up their cybersecurity careers, achieve amazing results, and complete their larger goals.
In this episode of the Cloud Security Reinvented, Chris and our host Andy touch upon some interesting topics. From learning about the impact of the cloud on security to understanding a lack of diversity in the industry, you'll have a lot of information to sink in after this episode.
##
Guest-at-a-Glance
💡 Name: Chris Foulon
💡 What he does: He's the co-host of Breaking Into CyberSecurity, a Cybersecurity Strategist, and a noted career coach.
💡 Noteworthy: After 15+ years as an experienced Information Security Manager, Adjunct Professor, Author, and Cybersecurity Strategist, Chris realized he wanted to help others start their career in cybersecurity. Now he's a coach and a podcast show with a mission to mentor future cybersecurity generations.
💡 Where to find Chris: LinkedIn | Podcast
##
Key Insights
⚡ You don't have to be a programmer to understand cybersecurity. Chris is debunking some common myths of cybersecurity in this episode. Despite popular belief, you don't have to know how to code or necessarily be a programmer to understand the security implications. "I think there's still that expectation that everything is coding, programming. I would say today there are so many different verticals within security that you don't have to be that programmer. You don't have to be a coder. You can understand how to design an architect or a well-architected cloud framework without being in the YAML file for that infrastructure as code."
⚡ Be careful what you automate. Chris is excited to see how the future of automation unravels, but at the same time, he has his doubts. People will certainly be able to focus more on the creative side of things thanks to automation, but there are certain risks to it. "The flip side to that is if you automate without thinking through the process, you end up adding more complexity and more risk to your business."
He shares another interesting point of view. "I was in a recent talk with Sounil Yu, and one of the things that he mentions is that the more you automate, the more people you tend to have to maintain that automation. So be careful what you're automating and make sure you do it."
⚡ Let's increase diversity in cybersecurity. As a reputable coach in the industry, Chris concludes that diversity is one of the challenges that we are yet to overcome. He says that anyone can get into security even if they don't have a degree in it. "We need to increase the diversity of thought, diversity of background, diversity of people included in this industry. And part of that is driving that awareness younger in the education cycle so that people are both aware of the pros and cons of technology, and then that they can see themselves in the technology role as they grow up."
##
Episode Highlights
The world of security has improved due to the growth of cloud
"Traditionally in the past, you had to be almost an expert in networking, in infrastructure, in OS in order to get to those high levels where you're working, you're architecting a data center. Now with cloud service providers, all looking to drive on adaptation of their framework, they're putting out free resources, they're providing free content, and to drive that adaptation of their cloud, that now someone who's really interested in it could go access all of these three resources and become very knowledgeable in cloud without having to understand a legacy infrastructure."
What is the pre-cloud practice we should get rid of?
"I think that the biggest thing is when you think of digital transformations and driving to the cloud, this idea that you can just pick up and drop your old infrastructure and your old designs that you had on-premise, even if you had them virtualized and bring them into the cloud. Because A) you're not taking advantage of the design architecture in the cloud and B) you're just really moving your risk from on-premise to cloud. And in some ways, because people. I have a set of false expectations because they don't properly understand the shared responsibility model. They increase their risk by going to the cloud. They increase their costs by going to the cloud with these simple lift and shift transformations that you're doing and then realize, 'Wow, we're spending too much money.'"
Don't choose money over passion
I think for me it is really finding what you're passionate about and driving towards that. Your passions will change throughout your career, but don't go chasing a paycheck. I think all too often, especially when you're younger, you might go, 'Oh, Wow. They're getting six-figure salaries in cybersecurity. Let me go do that.' But if you pick a role and it doesn't align with your skill sets or your passion, and you feel like you're always pushing a stone uphill, you're going to burn yourself out, and then you're going to end up regretting that decision."
This podcast is hosted by Orca Security
Episode Summary
If you've ever thought of pursuing a career in cybersecurity, we have an episode for you! Today's guest is a career coach and a podcast co-host, and he's here to talk to us about cybersecurity in the post-cloud era.
Chris Foulon is the co-host of Breaking Into CyberSecurity, a Cybersecurity Strategist, and a noted career coach. He says his goal is to give back by producing a podcast focused on helping people who are trying to get into cybersecurity. In addition, Chris helps professionals looking to level up their cybersecurity careers, achieve amazing results, and complete their larger goals.
In this episode of the Cloud Security Reinvented, Chris and our host Andy touch upon some interesting topics. From learning about the impact of the cloud on security to understanding a lack of diversity in the industry, you'll have a lot of information to sink in after this episode.
##
Guest-at-a-Glance
💡 Name: Chris Foulon
💡 What he does: He's the co-host of Breaking Into CyberSecurity, a Cybersecurity Strategist, and a noted career coach.
💡 Noteworthy: After 15+ years as an experienced Information Security Manager, Adjunct Professor, Author, and Cybersecurity Strategist, Chris realized he wanted to help others start their career in cybersecurity. Now he's a coach and a podcast show with a mission to mentor future cybersecurity generations.
💡 Where to find Chris: LinkedIn | Podcast
##
Key Insights
⚡ You don't have to be a programmer to understand cybersecurity. Chris is debunking some common myths of cybersecurity in this episode. Despite popular belief, you don't have to know how to code or necessarily be a programmer to understand the security implications. "I think there's still that expectation that everything is coding, programming. I would say today there are so many different verticals within security that you don't have to be that programmer. You don't have to be a coder. You can understand how to design an architect or a well-architected cloud framework without being in the YAML file for that infrastructure as code."
⚡ Be careful what you automate. Chris is excited to see how the future of automation unravels, but at the same time, he has his doubts. People will certainly be able to focus more on the creative side of things thanks to automation, but there are certain risks to it. "The flip side to that is if you automate without thinking through the process, you end up adding more complexity and more risk to your business."
He shares another interesting point of view. "I was in a recent talk with Sounil Yu, and one of the things that he mentions is that the more you automate, the more people you tend to have to maintain that automation. So be careful what you're automating and make sure you do it."
⚡ Let's increase diversity in cybersecurity. As a reputable coach in the industry, Chris concludes that diversity is one of the challenges that we are yet to overcome. He says that anyone can get into security even if they don't have a degree in it. "We need to increase the diversity of thought, diversity of background, diversity of people included in this industry. And part of that is driving that awareness younger in the education cycle so that people are both aware of the pros and cons of technology, and then that they can see themselves in the technology role as they grow up."
##
Episode Highlights
The world of security has improved due to the growth of cloud
"Traditionally in the past, you had to be almost an expert in networking, in infrastructure, in OS in order to get to those high levels where you're working, you're architecting a data center. Now with cloud service providers, all looking to drive on adaptation of their framework, they're putting out free resources, they're providing free content, and to drive that adaptation of their cloud, that now someone who's really interested in it could go access all of these three resources and become very knowledgeable in cloud without having to understand a legacy infrastructure."
What is the pre-cloud practice we should get rid of?
"I think that the biggest thing is when you think of digital transformations and driving to the cloud, this idea that you can just pick up and drop your old infrastructure and your old designs that you had on-premise, even if you had them virtualized and bring them into the cloud. Because A) you're not taking advantage of the design architecture in the cloud and B) you're just really moving your risk from on-premise to cloud. And in some ways, because people. I have a set of false expectations because they don't properly understand the shared responsibility model. They increase their risk by going to the cloud. They increase their costs by going to the cloud with these simple lift and shift transformations that you're doing and then realize, 'Wow, we're spending too much money.'"
Don't choose money over passion
I think for me it is really finding what you're passionate about and driving towards that. Your passions will change throughout your career, but don't go chasing a paycheck. I think all too often, especially when you're younger, you might go, 'Oh, Wow. They're getting six-figure salaries in cybersecurity. Let me go do that.' But if you pick a role and it doesn't align with your skill sets or your passion, and you feel like you're always pushing a stone uphill, you're going to burn yourself out, and then you're going to end up regretting that decision."
From the publisher's feed