[0:00] okay fantastic so thank you everyone for joining us today my name is Boaz Boaz [0:06] barzel and we’re here to discuss mastering the secure software [0:11] development life cycle and third party risks with a number of Industry experts [0:17] uh including uh Nuno Teodoro Tomer Weinberger David Cross Conor Mancone Luca [0:25] ...
[0:00] okay fantastic so thank you everyone for joining us today my name is Boaz Boaz
[0:06] barzel and we’re here to discuss mastering the secure software
[0:11] development life cycle and third party risks with a number of Industry experts
[0:17] uh including uh Nuno Teodoro Tomer Weinberger David Cross Conor Mancone Luca
[0:25] Lanziani Jag Singh and myself so we’ll start with the webinar with a brief
[0:32] introduction uh and then our panelist will each introduce themselves and
[0:38] afterwards we’ll dig deeper into the discussion on the different
[0:43] topics as usual if you do have any questions throughout the discussion feel
[0:48] free to send them in our Q&A we’ll address those uh during uh uh kind of
[0:54] more onto the end uh of the webinar the end of our discussions and this really
[1:00] impressive lineup that we have here is very exciting I was really excited to uh
[1:06] join forces with these guys and what I would like to do is i’ like to start
[1:11] with a quick introduction to the topic and talk really about what we’re seeing in the market
[1:18] so first of all I want to thank the panelists that joined us today and
[1:23] really it’s a privilege to be one of the people in that kind of discussion and
[1:29] we’re delving into a critical aspect of our modern technology and really to
[1:34] master the security of software development life cycle and to understand
[1:39] third third party risk um it’s a big topic it’s a major topic and I bet it’s
[1:46] going to hear really interesting uh stories uh here but first let’s consider
[1:53] what it means this you know secure software development life cycle and third party risks
[2:00] really in today hyperactive landscape where we have both attackers and
[2:06] organizations speeding their efforts you know we’re constantly evolving that and
[2:12] the attacks becomes more sophisticated the tools that you’re using there are so
[2:17] much that can be said about it but it’s really coming from a place where it’s no
[2:25] longer a methodology when we’re talking about the security
[2:30] uh of the development life cycle it’s really something of a necessity and what we can see is more and more businesses
[2:38] are trying to stay competitive in the market and they understand that if they don’t integrate security into everything
[2:44] that they’re doing they’re creating a heightened risk and really this is
[2:50] because of the transition to you know Cloud uh transformation Cloud security
[2:57] aspect where now we can just connect into a platform and can you know give us
[3:03] all kinds of Wonders so from this aspect we’re seeing
[3:08] Cloud we’re seeing involvement in you know network security and endpoint security and then we’re seeing
[3:15] application security taking a main stage in that sense we all understand that there’s
[3:22] different Frameworks today for software development security and and continuously involve evolving in that
[3:29] sense and and we’ve understood that the methods that we are using today the traditional methods are shifting or
[3:36] changing and we want to understand how we can do it and what’s the Innovation
[3:42] what’s coming into the market what we’re experiencing in that and really I want
[3:47] us to be able to focus the attention on that so before we get onto the
[3:53] discussion and really talk about the common third- party risks we’ll talk about the challenges we talk about
[4:01] what’s really preventing us from sleeping at night or what we’re following and we’ll also probably talk a
[4:08] little bit more about generative Ai and a little bit about Automation in those
[4:14] aspects and trying to understand where is the landscape going to go what is
[4:19] coming for us so without any further Ado I would
[4:25] like to invite our panelists to introduce themselves and Nuno go
[4:32] ahead yeah hello um very nice to be here and thank you for having me my name is Nuno I’m the vice president of cyber
[4:40] security for Solaris group um we like to call ourselves um a tech company with a
[4:46] banking license so we are indeed a bank um from from Germany um with all the
[4:53] regulatory requirements and pressures that Financial entities have around it but we try to uh have a culture of the
[5:00] modern tech uh companies out there of being fast Innovative and trying to
[5:06] challenge the the current status quo to be honest so under my responsibilities I have a set of areas one of them is funny
[5:14] enough you’ve mentioned application security we just recently uh thought about changing it to product security
[5:21] just to resemble more with um with our upper management
[5:27] board that’s very nice that’s very nice thank you very much uh I would like to invite Jag to introduce
[5:36] himself I’m I’m Jag I look after cyber security for Ted Baker been here now two
[5:42] and a half years and U I’ve come from a retail background it’s um I was
[5:48] explaining earlier to to yourself it’s like uh jumping in the pool of sharks
[5:54] and we are surviving it’s changing really fast every day and we have to keep up with all of these uh amazing
[6:01] crazy hackers keep ourself up to date with all of them and uh yeah look after
[6:09] cyber security for um our Global supply chain and other areas behind Supply
[6:16] chains as well which is a part of the risk uh discussion we are going to have here I think
[6:23] later ah that’s great good thank you very much Jag and Tomer on to you
[6:30] hi guys uh I’m Tomer uh working for Microsoft I’m a senior manager at
[6:35] Microsoft uh basically with cyber security uh background but in the last
[6:41] uh five six years focusing on cloud security leading Cloud threat protection
[6:46] products in Microsoft as Microsoft Defender for cloud if you’ve heard of um and kind of building the entire world of
[6:54] uh Cloud detection and response and basically kind of uh trying to navigate
[6:59] in this ever Dynamic um product environment happy to be
[7:06] here thank you very much Tomer and we have Sherny who just joined us and she’ll
[7:12] help us throughout this discussion uh in understanding uh and everything and kind
[7:18] of moderating uh this discussion thank you very much Sherny for joining us uh in that
[7:27] sense a few minutes late I’m glad to hear that everyone introduced um welcome
[7:34] welcome everybody to today’s session so let’s just Dive Right In uh
[7:40] Sherny we’ll continue with the introductions we’re uh now introducing Connor in that sense
[7:47] perfect hello everyone I’m Dr Conor Mancone I’m principal application security at um engineer at Cimpress so
[7:53] we’re kind of the Masters of mass customization um for the you know for the US folk folks are um probably more
[8:00] commonly known brand is Vista formerly Vista Print um and I’ve got a pretty much kind of wandering career path I’m
[8:06] actually trained as a a research scientist I’ve got a PhD in astronomy but I’ve been building e-commerce and business automation solutions for kind
[8:13] of small and medium businesses in the US since the early 2000s um I you know I
[8:18] unfortunately got to see lots of data breaches around me even going all the way back to my PhD days um so Security’s
[8:24] always been kind of at the Forefront of you know what I was doing what I was planning and trying to keep teams moving
[8:29] towards and I I finally made that you know officially my career back in 2020 when I joined Cimpress um and so you
[8:36] know I have a I have a lot of responsibilities there now but one of my key responsibilities is helping to implement the you know SSDLC at Cimpress
[8:44] um so you know third party risk SS DLC is you know the the key focus of my work
[8:49] on a daily basis so so hopefully I’ll have something useful
[8:55] here fantastic thank you very much Connor and now I’d like David to
[9:00] introduce himself thanks Boaz yep David Cross I’m the senior vice president and
[9:06] CISO for the Oracle SAS Cloud right not all of Oracle but the SAS Cloud I’m also a venture partner with Rain Capital VC
[9:13] and I’ve been uh involved with the cloud security for the past 20 years you know building up the Azure security team at
[9:19] Microsoft the Google Cloud security team at Google and now here at Oracle and the SAS Cloud so very excited to uh be uh
[9:26] talking today fantastic thank you very much David and last but not least Luca on to
[9:33] you hello yeah hello everyone nice to be here I’m Luca head of the ops and platform engineer Nearform Nearform is a
[9:39] Service Company remote first service company that is spread across Europe and United States we help our clients with
[9:45] all the devops uh or at least my role is to help our clients on all the devops side of things including security because as
[9:51] we know devops turned into Dev SE Ops lately nice to meet you
[9:57] everyone thank you very much Luca and Sherny yeah
[10:06] so you can introduce yourself already as well
[10:11] okay yes so I’ll be just hi everyone I’m my name is Sherny I’m gonna be hosting
[10:17] today’s discussion um and I wanted to um give Boaz a chance to introduce the topic
[10:24] chance to talk about um sdlc and okay great
[10:30] um just dive into our discussion then today we’re going to be covering three main topics primary topics the first is
[10:38] about um just a market General overview for those who are joining and um need a refresher either for um for for the
[10:45] market itself or don’t have any background the second topic will’ll jump into risks and challenges followed by
[10:51] Solutions and approaches and we have a lot to cover so let’s get started just a
[10:57] quick reminder actually um at the a short Q&A 15 minutes so if you
[11:04] have any questions you can drop in the QA below box really encourage you guys
[11:10] to also just have an open discuss with each other
[11:18] umow okay well just to get started um I I’ll kind of give an open question to
[11:23] the panel um us what is a SSDLC or secure software develop
[11:30] and why is it so important in today’s
[11:36] threat well I I probably can pick that up uh draw myself to the discussion uh
[11:42] to start with I think very pragmatically um everyone already understood that uh
[11:48] everything if not most mostly um all the service that we offer um in our day
[11:54] Society um rely on um digital components and software so for me it’s a fundamental
[12:02] part of my cyber security strategy um we do have uh and put a lot of focus on
[12:07] product security and application security at the bank um and it’s just a matter of very pragmatically making sure
[12:15] that you properly address the risks and the threats that come from having uh
[12:21] software developed in your organization and the services that you offer to your customers we can follow a bunch of
[12:28] Frameworks a bunch of standards all of them help and support for sure inherently um I think this leads more to
[12:35] a cultural shift and the mentality shift in the organizations in order to bring
[12:41] more trustworthy and reliable products to our
[12:47] society you anyone want to add on to that I think I would just add very
[12:54] briefly you know in terms of what is the SSDLC I think you know we stick that s in
[12:59] front of the software development life cycle as kind of a maybe response is not the best word but like I think you know
[13:05] going back 20 years when security was kind of something you would start to think about once your stuff hit production you know once your services
[13:11] were active and you know there’s that growing realization that hey if you only do security at the very end of this
[13:17] process then it’s going to go badly you know so we make it we go from a software development life cycle to a secure
[13:22] software development life cycle just to help kind of teams recognize and understand that hey you know this is something that we need to be thinking
[13:28] about during the entire software development process and and not just at the very
[13:44] end um to that okay I why don’t you start us off
[13:51] what is the current market approach to Cloud
[13:56] security so I think um taking into account uh SSDLC in general you can see a
[14:04] lot of unification with tools kind of the market is going to be uh unifying all solution and kind of inhal into one
[14:12] and in Cloud security it’s very obvious that the current market is focusing on creating a single pane solution like a
[14:19] cloud native application platform um that basically for years we thought that
[14:25] uh you need to kind of have C uh like posture cspm and cwpp for workload uh
[14:31] you have your devop security you have your uh infra entitlement but now everything is looked as a one box where
[14:37] you take security throughout this kind of software development life cycle and you kind of connect with the cicd and
[14:45] your runtime and you need to have a full visibility um of your application rather
[14:51] than resources and I think we’re kind of changing the way that we’re thinking of uh other than just protecting endpoints
[14:58] and devices than protecting scenarios or applications and how we approach that so
[15:04] it’s very obvious that in Cloud security it’s been a huge transformation throughout these
[15:09] years I’d like to add to that an element is and I think it’s also we had a a great question I think uh raised by one
[15:16] of the participant Amir you know talking about this security development life cycle the software development life cycle is but also I think if they raise
[15:22] it’s like you know uh threat modeling is critical as part of that in pen testing and I have to agree especially as a
[15:28] cloud services is that every release it needs to be pen tested right it need to be released and I think that’s part of
[15:34] really the standard of The Benchmark now uh compared and I think it’s very important to call that out thanks for
[15:41] asking Luca what are you know some practices that um that have changed um
[15:48] that have changed over the years which are now showing their limitations so SCA is evolved where are we seeing some of
[15:55] those mutations yeah I think I think we touched up on some of those right we we have seen we have said that the
[16:01] environment has evolved uh we used to develop software very differently we used to deploy the software very
[16:07] differently right the the number of dependencies that we were using the number of tools we were depending on the
[16:13] number of services we we were depending on was very different some years ago and not not so many years ago right if we
[16:18] look back 10 years ago it was completely different right the cloud was just there
[16:23] right we were starting to move to the cloud and with that move we started to rely on more Services external services
[16:30] so the security wasn’t just wasn’t just about ourself and how we would protect our boundaries the boundaries got bigger
[16:37] right we had to rely on external vendors and we had to make sure that those external vendors were caring as much as
[16:43] us about security and we were relying on more dependencies including software dependencies and so the more libraries
[16:50] we imported there is a famous joke about I mean not JS modules being big or other uh software uh modules but the more
[16:57] things you bring into your the more you are increasing or you increasing the let’s say the the the
[17:02] boundaries of your security right the more you have to care about those so with this environment evolving we had
[17:10] to evolve our tools but tools can do just that much right we had to change
[17:16] our mentality we have seen the past few years how supply chain attacks became a reality uh we also touch on the fact the
[17:23] attackers have changed the way they I mean they have evolved they have leveraged those new environments
[17:29] and so yeah the nowadays with all the things that we use with all the things that we depend on the complexity of the
[17:35] software the security approach has to drastically change it’s no more that
[17:41] once a quarter right as that say every release should be pen tested maybe it’s no more a once every now and then it has
[17:49] to be
[17:55] continuous I 100% agree with you Luca there I think uh uh you just stole my
[18:01] words what I wanted to talk about but yeah despite of the fact that technical
[18:07] layer has evolved and cloud and who got the keys to the uh you know servers
[18:12] where these Cloud servers are hosted but also uh C Suite
[18:18] has understood the accountability which has created um you
[18:23] know helped all of us here to not to go and just beg them to add
[18:30] some security or or use good practices but them understanding accountability
[18:37] because of what’s been happening in the industry ransomware and and all these kind of things it has also helped and
[18:45] our life has become little bit more easier to explain that the responsibility sits with the different
[18:51] stakeholders in the business but and of the accountability is with the top layer
[18:57] which has always help me um like a top down approach helping um third party
[19:04] suppliers or internal um software development teams or compliance teams because it’s a big
[19:12] business objective it has also always helped so yeah thank you for covering that yeah I think it’s good that you got
[19:19] kind of that top down approach and that kind of support from the C suite and I think that’s important and a big reason why is because I mean I suppose I’m not
[19:26] really answering that question like what techniques aren’t working as well but you know the reality is there’s always going to be techniques that aren’t
[19:31] working as well because you know when you’re trying to protect your your infrastructure and your organization
[19:36] against outside attack like you’re you’re aiming for a moving Target you know this isn’t something we like hey we’ve made everything secure and now we can just
[19:43] forget about it for the next few years you know it’s it’s a cat and mouse game you know as as more as like we on the
[19:48] defender side change the way we work um to protect our systems you know attackers also are on the other end
[19:54] finding new and more creative ways to break in so it’s it’s just it’s a
[19:59] continual ongoing process and the things that work today you know they’re not going to work in five years um and you
[20:04] know you do have to have that concept of just continuing to evolve and improve yeah and and sorry maybe I
[20:11] forgot to say one thing right of course the environment evolved but with that also the security offerings evolved is
[20:17] today is very easy to add some basic security to your system I’m not saying that you’re going to make it 100% secure
[20:23] but if we think back when we had to generate certificates it was completely a different environment right you can
[20:29] now generate certificate with a few clicks you have let’s say security or basic security boundary security out of
[20:35] box in most of the clouds so I would say that right now there are no excuses to at least apply this base level of
[20:42] security for no one right so easy definitely okay let’s move on to
[20:49] the next question can everybody hear me a bit better yes yes great okay I’m using my
[20:55] phone now um as a mic um so what what Boaz I want to ask you what emerging Trends
[21:00] in application security uh do you find most concerning and or
[21:06] promising thank you Sherny so it’s a good question and I’d like to connect it to
[21:11] uh the previous discussion where we talked about you know adding more security and more security tool and I
[21:18] think that this kind of trend that we’re trying to add more security and
[21:23] everybody saying oh what’s what’s more security so we’re throwing tools at it and we’re I think we’re at some point
[21:30] that another tool and another tool and we can see that it starts to crumble and
[21:36] we’re not sure what’s really the ROI of that and now we’re starting to see and
[21:42] and kind of taking that to the the emerging Trends start see Ai and Automation and everybody’s coming with
[21:49] promises and saying don’t worry we’re gonna hold the tools for you uh but
[21:54] we’re going to do something else for you and that something else can first of all be you know let me analyze all the data
[22:03] from all the tools that you have that you now need to kind of start understanding and produce something
[22:09] that’s meaningful to you um we’re seeing you know the the dev Ops Movement
[22:15] platform engineering movement kind of trying to provide it as a service so
[22:21] we’re seeing that kind of movement because of the increase in soft supply chain attacks and the increase of risks
[22:28] because because again from my point of view and I’d like to hear kind of our uh
[22:34] members of the panel talk about it is we are I would say forced in some point to
[22:41] release more versions and not always we are confident that we understand what we
[22:48] are about to release from a security standpoint uh that all comes in with an
[22:54] additional element of compliance and regulation that now kind of pushing at
[22:59] us and we have to get an SBOM out so what I see is that kind of those kind of
[23:06] Trends makes it really hard to understand what it means to add more
[23:13] security I think uh When taking into account AI co-pilot for security is
[23:19] something that we’re going to see much more of kind of taking all of the recommendations all of the alert so
[23:25] alerts fatigue in general is something that I think everybody’s kind of suffering you see a lot of noise and you
[23:30] know the backlog is not going to end it used to be something that you clear off your table but now you have to have not
[23:37] just context but more of a understanding of the impact analysis of what exactly
[23:43] this is reaching for and you’re not going to fix everything just sorting by
[23:48] severity or uh if it has this and this sbom or whatever you need to have full
[23:54] deep context and I think that’s where co-pilot will have more meaningful um
[24:00] kind of uh ideas working with multiple tools uh and multiple additional
[24:06] security and then you just put another feed another signal um and kind of hope for the co-pilot to summarize it to
[24:12] you yeah we’ll get more into that when we get to solution and approaches um but for now
[24:18] just to wrap up the section what are some recent examples that are maybe worth discussing of companies that have experienced um o security
[24:25] breaches um because of a third
[24:33] party and I sorry David um I can’t help but talk about um OKTA I find that one
[24:40] very interesting you know they they are an identity provider and they they serve as some some fairly large and important
[24:45] you know companies in in just the tech space you know the cloud flare is one of theirs um one of their customers um and
[24:52] they had a data breach caused by U basically you know improperly managed credentials um and as a result you know
[24:58] the attackers got into octa’s um support system and from there they found um
[25:05] credentials that gave them gave the attacker admin access to the customers o
[25:10] uh the customer OKTA tenants which is to say that you know now we have an attacker who has um administrative
[25:16] access to the identity provider for some very critical companies you know by the time you break into somebody’s identity
[25:21] provider you know now you theoretically have the ability to go anywhere in that company so you know you’re potentially looking at complete company compromise
[25:28] so so I find that one to be very interesting and I mean it’s not necessarily the typical thing we talk about when we say third party risk is
[25:33] we’re thinking about like hey I deployed them Bing software and it was exploited but you know like it’s still absolutely
[25:39] like third party I’m using this vendor they got exploited and now the attacker was able to make their way deep into my
[25:45] networks as a result of that third party breach um is probably an example of about about as bad as it gets honestly
[25:53] um so you know just kind of you know seeing that event happen and seeing the companies deal with it was was quite
[25:58] interesting and like for me anyway really kind of brings home the the the risks of third party
[26:04] vulnerabilities sorry I have to make the usual joke those are the breaches that we know about right not the one that we
[26:10] don’t know about so sorry right I mean at the end of the day what what influenced this decision also at the C
[26:16] level are these breaches right seeing the way that they impact other organizations um and the way that um
[26:22] they’re utterly unprepared um so let’s go to our next topic I think that’s a good segue um let’s start off by just
[26:28] giving our guest a brief overview of what some of the common thirdparty um
[26:34] risks are that are faced uh throughout the software developing life
[26:42] cycle I’ll start on on this one for a moment certainly I think for many companies that uh and you know
[26:48] organizations that are build building software right do they really have an understanding of all of their third
[26:53] party their fourth party you know libraries right what are they consuming what are they doing right and and I
[26:58] think certainly some of the smaller uh companies and certainly the normal vertical you know Industries not the
[27:03] Tech Industries this may be a big challenge do they understand what they have and then another element is that uh
[27:09] unlike you know ourselves like what companies can actually build from Source yes we use open source software and many
[27:15] others as well but how many can actually build from The Source right and not just rely upon consuming all these libraries
[27:20] from questionable sources and I think that’s a big challenge for the industry and this is maybe some places where s
[27:25] bombs can help enormously but I’d love to hear everyone else’s thoughts I can jump into that we actually funny
[27:33] enough we we were tackling that issue um not long ago um within the the
[27:39] organization um and that that’s a real problem because not only entails um um a
[27:45] level of risk that probably was unknown to the organization when you start to dig into that uh when you really start
[27:51] to understand what kind of Third Party Source libraries you do have in your source code also uh uh messes with
[27:57] regular in legal requirements on nonpermissive licenses on what you have on your source code what you are
[28:03] integrating uh with your uh inhouse developed code so that that’s really
[28:08] something that probably most people don’t dig enough into it I think it’s super relevant that we understand that
[28:14] and also understand what kind of um potential hazards are you inserting
[28:20] blindly into your sourcecore that then you put in production for your end users to consume um so I would say that that’s
[28:27] a really relevant thing for the organizations to do
[28:34] in anyone else want to add to that I think I would just add you know oh sorry
[28:40] you know we just talked about software dependencies of course but you know that’s it’s funny because it can be so much more than that and I think that’s
[28:46] where one of the challenges is is is identifying all those places where you have those third party risks because it’s more than just hey you know these
[28:52] packages that I’ve installed it’s also like these containers I’m running you know these Amis that I’ve taken from the
[28:57] marketplace you know even my own operating system you know is is a source of third party risk so just finding all
[29:03] of those places and identifying them um and you know where they impact your organization I think can be very
[29:08] challenging the authentication provider you’re using and so on I was going there myself Conor right and it’s it’s yes the
[29:14] tools again are important but it’s very much more important to have a security minded uh team in the in the company
[29:21] that is going to look through the old system holistically and try to find all
[29:27] the possible uh problems that you have there and again um we we’re talking about es bomb that are definitely
[29:33] something new that is coming out well something new it’s not new anymore but we starting to talk about that more and
[29:38] more uh but that is just a list of things right then from there you have to
[29:43] find all the vulnerabilities that those things are so you have to actively look at those and then even there are we sure that we
[29:49] are looking at this all those libraries that are there and we are actually surfacing all the vulnerabilities that are on
[29:54] those libraries so there is a lot work to do after even after having SBOMs and I think go ahead sorry I think
[30:03] in general we’re talking about uh Kind Of You’ mentioned uh Conor uh containers and I think when you’re using or reusing
[30:10] uh base images other than just using uh code but you’re actually using like layers that you’re taking and reusing
[30:18] them you have to take into account a lot of things other than s bomb you have to take if it’s at supply chain attack like
[30:24] the source like where is it from Mal wearing scanning there’s a lot of things
[30:30] that you have to do and we all know how painful and costly it is to find that on
[30:35] production and you want to know that as shift left as possible and I think we currently uh are involving especially
[30:43] with containers to see how we can detect that in a very early stage um that is still a kind of a challenge that we’re
[30:54] risking what are some of the challenges um and this is for Tomer so what are the challenges in responding to just
[31:00] security issues in the cloud versus other environments yeah so I think in general
[31:06] Cloud response is still a not a very evolved area um responding to endpoints
[31:14] is very with edrs um is very straightforward but we’re when we’re thinking about Cloud we see a lot of
[31:20] issues especially when it comes to the access and shared responsibility model so basically you don’t have access to
[31:27] your resarch resources or you have access to some parts of your resources and once you need that there might be in
[31:33] multiple clouds not even one Cloud it could be halfway into AWS and some parts
[31:39] in Asia and you’re trying to take all of the data um but in some other cases they
[31:45] are kind of Imperial or transient resources meaning that by the time you
[31:51] came to investigate that you don’t have the data because the resource is gone so
[31:56] I think we see a lot lot of issues when we’re trying to think about how Cloud pillar is going to be part of xdr and
[32:03] something that we’re working on like what it actually means to remediate or responding uh automatically in auton
[32:10] like in an autonomous way uh to Cloud threats which is kind of different than one we used to with end points or
[32:17] identity for example i’ thought to jump in on that one for a moment is I think is also the
[32:23] cloud is I think Tomer you’re kind of reaching out some things that the shared security model and that sometimes as you
[32:28] go from on premise you know to the cloud some people they say everything’s taken care of especially in the SAS
[32:33] environment but actually you still own things right as a customer or as an organization like the identity you own
[32:38] the identities you own the identity logs are you capturing and monitoring those you know what about the application logs
[32:44] are you capturing and and and uh and monitoring those and I think that’s Sometimes some organizations forget
[32:49] about this is one of the things I talked about RSA and also in my presentation but very very important and thanks for
[32:56] raising as we know also often you know security
[33:03] risks um lie in human blind spots so where are we seeing right now the biggest blind blind spots in the supply
[33:09] chain happening this is an open question so feel free to just jump
[33:16] in I want to raise something about it and and maybe the other panelists can uh
[33:21] uh share their insights um I want to talk about the collaboration between the teams so we
[33:27] are talking about human blind spots and sometimes we’re referencing that because we’re missing information that we’re
[33:34] receiving from the different security tools but the fact is that sometimes the the way that we collaborate the way we
[33:40] share information between teams in order to fix or immediate something gets lost and then
[33:49] there is that kind of sense that I told you you haven’t told me we wrote about
[33:55] it and and so on and so forth and maybe I’ll like to hear the address from other panelist on the kind of collaboration
[34:03] issues so I think uh each environment have its own kind of uh risks when
[34:09] you’re talking about specifically just because I’m uh familiar with Cloud you also have this kind of trade-off with
[34:15] you have the cloud workload owner and you have the devops guy and you have the SEC Ops guy and there’s a lot of personas that are kind of working on the
[34:22] same incident but there is no single kind of uh point to understand
[34:27] everything in terms of how it kind of apply to the application and how you
[34:33] don’t affect production or whatever it makes sense um and I think those as you said there’s a lot of personas and a lot
[34:39] of parts of it are very hard um to kind of scope into one single incident
[34:46] especially the more complex the application
[34:52] is that is something that we often see with clients right be a solution a service company we work with different
[34:58] clients and that is the one thing that we see and we touched on this earlier on when we say that right now we have the
[35:04] Cs uh help there right if the security is a company priority then people are
[35:10] going to start collaborating on there right every if it’s everyone resp responsibility I know that when something is everyone responsibility no
[35:16] one responsibility but you can play with that uh the sock team has been there
[35:21] since forever right but sock team cannot do things by themselves uh they’re going to need
[35:27] help of the overall company uh and I think those are the the the the person the people that should look over the
[35:34] overall system security and then try to trickle down the responsibility on the different teams like the software teams
[35:40] the The Bobs team and so on right um of course tools can help with that tools
[35:45] can still help with that we can have a tool that is going to surface vulnerabilities and then it’s going to send vulnerabilities to different team
[35:51] so it’s not going to be about I told you or I didn’t tell you it’s going to be about it was there and you need to address it um yeah yes then we also say
[35:59] that then there’s going to be alert uh too much noise right so you’re going to be too many no too much noise and you’re
[36:05] going to be and not caring about those anymore it’s a tricky thing to do but
[36:10] again it’s about mentality mostly it’s about sharing their responsibity understanding that is part of your job
[36:16] to take care of the security of the system and not enough the thought yeah prob great points go ahead
[36:23] go ahead Conor I was kind of a long go ahead Nuno go ahead go ahead I I I just
[36:29] going say that I think um yeah you know making sure everybody understands that it’s a part of you know security needs to be a part of their responsibility um
[36:36] and I think that’s kind of a culture that has to be built um you know as long as as long as security is somebody
[36:41] else’s job um then you know it’s going to make it more it’s going to make it easier to have those kind of
[36:47] miscommunications you know and so I I do think again going back to that top down approach you know you have to have that
[36:52] cultural emphasis on hey like you know security is something that we all build together um and and everybody
[36:58] understands that you know hey you can’t just Kick the Can to somebody else you it makes everybody else kind of take the time to understand what’s going on and
[37:04] make sure that they’re communicating properly I think you you touched exactly the point that I wanted to touch which
[37:11] is culture uh culture culture empowerment and accountability so at
[37:16] least my experience what we try to do is we try to create a culture where we as a
[37:23] security team don’t go to the uh developers or products team and we say hey look at this 1,000 vulnerabilities
[37:31] and this U 300 Mis configurations on your environment and applications we we
[37:37] don’t do that we we really try to implement Dev Ops culture we have a very
[37:43] very close collaboration with all the development team the tools that we select for application security or code
[37:50] security pipeline security uh Cloud security we chose them with the other
[37:55] teams jointly so it’s not a one side we choose tools and then we force this to the other tools because we
[38:02] actually try to see what works in our culture with our reality with our development mindset and with the
[38:08] capabilities that we have in house and of course we try to empower them also to be more um autonomous in ter in terms of
[38:16] actioning the mitigations that we need them to to action so it’s not a matter of um hey here are the security
[38:22] Frameworks here are the tools we are checking the code we are checking the dependencies um your containers have 1
[38:27] billion vulnerabilities hey fix it here here are 3,000 Jira tickets to fix the vulnerabilities we completely try to
[38:34] avoid that and we try to embody them into our culture of security and we work
[38:40] collaboratively with them our Dev secops team or product team is completely
[38:45] connected with the development team and with the product team in order to bring from uh left to right a complete
[38:51] Security is it perfect of course not uh but we are in that direction at least
[38:58] these are all really great points thank you guys um how do you bring in the context you need to understand um if an
[39:06] alert from your tooling is actually a vulnerability that needs rapid remediation similarly how do you ensure
[39:13] that the things you are prioritizing are actually
[39:23] prioritized I’m I’m actually really curious to hear what what the rest of the panel has to say so yeah you can
[39:28] start us off Conor and then the others can jump in I mean I don’t I don’t have too much to add that than the fact that I think it is a very critical issue you
[39:34] know like there was that an recent SSH issue cve related to agent forwarding and I saw you know lots of people you
[39:40] know even all across the internet like Hey how do I tell if my server is ownable hey how do I tell my servers vulnerable but for this specific issue it’s
[39:46] it was really an issue that affected workstations not servers and so you know it’s it’s crazy how easy it is to get
[39:51] focused on the wrong area and trying to fix it in a place where it’s not really an issue and as a result you know missing it where it is an issue um I
[39:57] don’t really have a great answer to that other than just you know kind of culture and experience and whatnot um so I
[40:03] mainly look here to see what every else has to say I I think context as security
[40:08] graphs in general we see a lot of uh the agentless movement as you know to see like everything but then connect
[40:15] everything to like a graph and then once you see all the misconfigurations that you have um and then you wanted to add
[40:23] context into that you want to understand how you’re approaching an attack path rather than approaching a single
[40:29] recommendation or single assessment that you have had um because a top forion
[40:35] ability uh in one of your services but that does not have endpoint access to
[40:41] the internet or it does not have a sensitive data is a whole different story than the medium vulnerability that
[40:46] you have in a very critical sensitive area um and the the ability to connect
[40:52] all of your resources while connect them into a graph and kind of prioritize
[40:58] everything based on their context and where are they deploy as an app I think
[41:03] something that we kind of it’s kind of a mandatory tool that we starting to see in a lot of security uh
[41:10] solution that makes sense for sure I agree with you um sorry to jump in David so I think
[41:17] one of the things that uh usually is a good uh choice of action to do is uh
[41:22] following what you said take a risk-based approach where the risk based approach is do you know your environment
[41:28] and you have nowadays a lot of tools that not only give you the CVSs of the vulnerability itself but they have a a
[41:35] predictive path of attack and they have the knowledge of the architecture where is it being scanned the vulnerability
[41:41] and they can say okay this is a 9.8 CVSs but according to your architecture is a
[41:47] 7.2 so you already have like an automatic uh uh let’s
[41:52] say reclassification of the vulnerabilities sometimes that help of course at Le at least what we try to do
[41:59] is to correlate that also with some naming and tagging and classifications of the products where we see um that
[42:06] vulnerability is appearing is it CR is it a critical product for the organization is it in the Bia
[42:12] classification is it a critical infrastructure is it classified as a crown jewel of the organization alongside with that
[42:19] uh let’s say reclassified CVSs that the tool gives to you then that gives us our
[42:25] priorities yeah I think about on that is I think is like some of us technology companies that we have a lot of the full
[42:31] context and the graphs that we can build out right in in in our systems of all the different Scanners from the SAS Das
[42:36] sea other things but the other a lot of other companies especially Enterprises may not have these uh these skills and
[42:42] this is where they use technology from like ox and others or other things I’ve seen a lot of companies use like Simplicity right and helping them bring
[42:49] things together defying their you know kind of prioritization in ordering and that helps them enormously when they
[42:55] don’t have that same level of contextual um uh Frameworks you know inside their environments
[43:01] themselves we didn’t tell David to do a product promotion for us I just wanted be clear so just clarification I want to thank
[43:10] but I do want to address that from you know another standpoint so context is important prioritization is important
[43:17] but I also see a lot of uh companies trying also to understand their culture
[43:24] in relations to their security tool tooling and understanding what do I need right
[43:33] now not just from security perspective because we’re all people and we have a
[43:38] lot of tools and you mentioned you know autonomous and Ai and there are so many things and we’ll probably discuss that
[43:43] but eventually at some point I would like you know to have something that will tell me listen I’ve looked at your
[43:51] business I’ve looked at the threat intelligence out there I’ve looked at your problems I’ve looked at the context
[43:58] of everything and this is what you need to do so I really think that you know
[44:04] this is what we’re trying I think we’re not there yet I think we’re getting close but we’re trying really to see
[44:10] everything and using all the tools and information and and kind of grapping
[44:16] everything together and squeezing out that drop of this is it this is my uh uh
[44:25] the set if if you give me that tool will throw money at you all right let’s move on the the
[44:31] tools are important but given two teams with access to the same tooling what do you think will ult ultimately make the
[44:38] difference between the two and let’s start with Luca let’s try to keep it short so we have some still have some time for the rest of our questions too
[44:45] yeah I don’t think I have to up much because we said it right it’s it’s about enabling those teams it’s about the team that is more enabled to make the change uh
[44:52] the data is there we say there are tools that can give you back the data uh the tool cannot give the understanding of
[44:57] the system so the team that is going to know the system better is going to be the one that is going to advance faster
[45:02] uh and in today’s uh companies we said different teams have autonomy because we
[45:08] want to move fast so give them the autonomy to take care of their own security uh Empower them teach them the
[45:15] importance of security uh so cannot keep everything under control I still remember when before releasing into
[45:21] production we have through had to go through the sock review of the software that doesn’t work anymore right the team
[45:28] has to be um empowered and I would add accountable for security that’s
[45:36] it let’s move to our third topic um Solutions and approaches um and again we
[45:44] can start with Luka anyone can jump in but how how do we ensure our organization security posture really
[45:50] remains up to date we we talked a bit about who remains who is um about accountability excuse me but really who
[45:56] at the end of the day is primarily responsible for remediating um security
[46:01] issues yeah I put it there because I think the answer is everyone uh simply right it’s everyone the we I I find that
[46:10] fascinating that sometime we talk about the systems like if the system don’t evolve right we have 100% coverage but
[46:16] yes but today right what about tomorrow what if something else gets added to the system do we know about something else
[46:22] who added that right who added that dependency added that new system who added that new service other the new
[46:27] provider right so if don’t have everyone responsible for security and everyone
[46:34] accountable and aware of security we’re never going to get there um again I I I used this in another C uh we I used to
[46:42] discuss with people about the fact that we always had vulnerabilities we never were running out of vulnerabilities right no matter how much we patched no
[46:49] matter how fast we patched so this are this is a never ending game you have to keep going keep going keep thinking and
[46:56] I know that some time is exhausting and that’s why we we should all share the
[47:01] responsibility I think coverage as you said is kind of the the main thing here because we see agent based or anything
[47:09] that has to do with manual installation or some manual work that you have to do
[47:14] will keep you just um vulnerable uh to a lot of changes uh as we know most of the
[47:19] or many of the security Bridges is due to misconfiguration um and this is what
[47:25] you’re trying to kind of cover uh with your tools yeah but at the same time as as Boaz
[47:32] say right the platform engineering movement May address some of those misconfigurations right having someone
[47:38] that collaborates and gives the uh the developers a common ground to start from
[47:43] even the the base image that you were talking about before right someone is responsible for that you’re already starting from something that is a little
[47:50] bit more secure than starting from scratch right it’s not going to solve everything but it’s again working together to get there yeah you want to
[47:56] shift left as much as possible I agree with the Luca there
[48:01] having a transparency and teaching everyone with great power comes great
[48:08] responsibility you know I love that yeah and and U we have done something similar
[48:15] given everyone the power when I say everyone all the technical teams and made them
[48:22] responsible and also rewarded them when the transpar has been you know things
[48:28] have been found teeny tiny things but it has a big impact somewhere this person didn’t think it’s
[48:34] a job of security person but this person was sitting in the front desk of the service desk he took an initiative to
[48:42] contact everyone not his job and problem solved big big problem
[48:49] solved before it even happen so yeah having that culture is a very difficult thing to do
[48:56] even in the supply chain we have seen um third parties parties um just by talking
[49:03] to them I’m not saying giving them some Advanced cyber security fishing
[49:09] trainings or something I’m just talking it helps a lot a lot yeah it’s a
[49:16] great approach if you see something say something um I’m from New York sorry um
[49:22] what are some of the emerging Solutions um let’s talk a little bit about the emerging Solutions approaches for cloud
[49:27] native applications um supply chain and development life cycle security um I’d
[49:33] love to hear from you guys before we um we head into Q&A
[49:40] soon yeah so I think when it comes to Cloud native and I think we’ve mentioned that before we have much more risks when
[49:46] it comes to supply chain uh we see in cncf uh which is the cloud native uh
[49:51] Computing Foundation a lot of new projects and that are being embedded through all of the cloud vendors um to
[49:59] provide to each image or kind of attach to each image um artifacts that will give you a lot of security um valuable
[50:07] data um so today you can add image scan for
[50:12] vulnerabilities and S bombs and a signature for notary and everything that
[50:18] you can just give context of what you are trying to deploy in your Cloud native environment and then you can
[50:25] enforce that on deploy time I think this is there’s a lot of solutions that we
[50:31] see in this area um and they are kind of building in throughout the container registry in the market and I think uh
[50:39] it’s a it’s it’s an an important solution to take into account one one thing I’ll jump out is
[50:46] certainly the element is that you know we look at historically of our bare metal you know instances our VMS and
[50:51] things like that we’re moving to the world of microservices and containerized applications and we think about vulner abilities and things in like do we want
[50:58] to go patch all the VMS or do we just want to uh uh update the repository and
[51:04] re uh redeploy the the containers in a rapid fashion right and I think this is the future right of going forward it’s
[51:10] going to take time we’re not going to refactor all of our our applications we say Microsoft Exchange Server it’s all
[51:15] going to be containerized no it may never happen but as we add new things on they are become micro services and
[51:21] containers and I think this is a big part of the security future and how we can address things much more rapidly than ever before
[51:27] David a brief follow-up for you so do companies need um to recommend tools for organizations
[51:34] for organizations that they’re working with Partners to consolidate and prioritize all their disparate uh
[51:41] findings yeah I think this is where a lot of the uh I think for many companies that don’t have this um you know the
[51:48] Deep you know development organizations themselves right is they really need to look at the the some of the tools I
[51:54] mentioned you know uh of here and I won’t make any plugs for anymore but ultimately looking and helping them right of how they consolidate if you
[52:00] have web scanning and Source scanning and composition analysis um uh and Cloud
[52:06] Clash management and you’re pulling in everything and you’re doing sock Audits and PCI audits how can you do that I
[52:12] think you do need help and looking at that and and looking some of those tools because it gets so complex that’s hard
[52:18] to do if you don’t have your own framework that you developed I jumped around anyone want to
[52:24] add anything to to any the last few questions okay what are some of the
[52:31] techniques that um you think companies uh should be investing in which aren’t yet known to be a common approach and we
[52:39] can start with Connor um David yeah you know this is probably like my own
[52:44] personal chip on my shoulder so if there’s anybody here from my company they’re probably groaning but I’m I’m I’m a big proponent of the importance of
[52:50] good Secrets management and and in particular I think that um like changing from thinking of credentials as like
[52:56] static thing to thinking credentials is something that’s very Dynamic and you know like short-lived credentials and using those more exclusively especially for
[53:03] internal applications you know going back to like the OKTA breach you know that kind of approach would have just
[53:08] completely mitigated that entire event um and I think it’s also very important when you start working with third
[53:14] parties because you know like the entire point of using credentials is to connect to a third party so I think it’s an
[53:19] important part of um uh risk management when working with third party systems um you know again just that concept of in
[53:26] that you know credentials shouldn’t be static like thinking of them as a dynamic shortlived thing that are given
[53:31] to you and expire shortly thereafter and it substantially reduces the risk of number of
[53:38] breaches I’m going to just that one word training and I know they seems obvious but I mean help your people and you
[53:46] think that they know everything they don’t right we are shifting left a lot of things so help them help themselves uh
[53:54] give them some training teach them them did good practices get some help that
[54:00] that’s that’s very needed from my perspective third parties
[54:06] is um I mean companies this is speaking out lot about other companies I’ve
[54:11] worked in past we look at our security we fix a lot of our problems and we ignore or we don’t
[54:20] prioritize the connections coming through those companies whether it’s API or or
[54:25] whatever and having the same practice applied
[54:31] everywhere is the key
[54:37] yeah go ahead sorry Jag no it’s fine just the training part need to be broadened to these companies as well and
[54:46] we have found I mean I found uh many times uh
[54:52] things they can mitigate so easily but then um we call it Muppet
[55:00] Factor so something so small and and they learned from our practices
[55:08] obviously we have uh resources we have Consultants working for us you know using nist framework and PCI standards
[55:15] and and other things but they start learning and a lot of times I’ve seen let’s say around 80% of the times I’ve
[55:23] seen third parties will be interested in ask asking for more help how we can
[55:28] improve what we can do and this also raises their profile business value and
[55:34] wherever they go and sell their product to some of definitely um I’d love to hear also from
[55:40] the audience if you guys have you know uncommon approaches feel free to share um exchange yeah enlighten as let’s move
[55:49] on to our I think it’s this our our final question for this category for for our final topic of solutions and
[55:55] approaches and then we’ll head into Q&A um how do you and this kind of open
[56:00] question but we can start maybe with Boaz how do you envision Ai and automation um impacting the future of application
[56:07] security we touched on it briefly um but what are just give us a bit more of an
[56:13] Insight what some of the potential benefits and pitfalls may
[56:18] be and that’s actually a fantastic topic thank you for raising it um so I would
[56:24] like an AI uh to be in everything that we’re doing
[56:29] and just to tell me uh what to do so when I come in the morning let’s say to work it tells me listen this is the two
[56:37] items you have to deal with today this is the elements that you need to take care of and that’s basically this is
[56:43] kind of how you say it autonomous even without me doing anything I’ll just tell him okay go do it so envisioning AI I
[56:51] think that if taking the training aspect of it we can use AI for training we’re
[56:58] using AI for anything else why not use AI for training you know and everybody can do it we have so many tools today by
[57:06] the way I’m uh receiving one AI tool a day I like it I play with it for about
[57:12] few minutes if I enjoy it I start using it if not then I just move to the next one we have so many tools there are
[57:19] tools that can help us with that and not just that you know it can enhance our uh
[57:24] detection it can show us other areas and when we talk about microservices and
[57:30] faster deployments I think we’re all trying to say that we need to scale everything that we’re doing so if so far
[57:37] we’ve done x amount of activities and were mostly manual we want to automate
[57:42] that so most of the activities will not be manual so I can do more of those activities because there’s more
[57:48] vulnerabilities I develop more software I encounter more you know not just that
[57:54] you know new tools for my I bring AI tools those tools require
[58:00] some sort of specialty some sort of skills so I need to invest time in it it takes away the the time that I have so
[58:06] these are kind of the the benefits but then you’ll say okay AI it’s not that
[58:12] great today sometimes it’s hallucinating it might get me chasing those kind of risks that are not really there so can I
[58:20] trust it uh is it biased in some sort of a way and now that I have more tools it
[58:27] create more complexity so how do I control that so I’m bringing more it
[58:33] becomes more complex the promisees was it makes it simpler but how do I know
[58:39] that and this is from that kind of place and the last one that I’ll touch is around
[58:44] regulations of regulations you know it makes
[58:50] everything more complex it’s supposed to be better it’s supposed to help me but then I need to get
[58:56] understand that the more regulations that I have it’s overloading me with more work when I need to buy more tools
[59:03] to compensate for that and to understand that I’m still under compliance so it’s really important but then how do I
[59:12] understand the requirements of the areas from that all that regulation aspect uh
[59:18] I would like you know everything that I do be incorporated into a single place
[59:23] that I can just query so I ask you know like I asked an assistant you know a
[59:29] voice assistant what’s my main problem today and they’ll tell me the main problem
[59:35] what do I need to do to solve it and they’ll tell me what to do so if I imagine it I would imagine you know
[59:40] something like that yeah I’d love to hear from the others but just on that note there’s also a question a Q&A um
[59:47] someone was asking you know the increased layering of more more technology are close to a point where the industry tooling starts to
[59:53] consolidate um I love to hear also your thoughts on this the panel the rest of the panel I’ll would say two things the
[1:00:01] first and going into what Boaz was saying um or maybe challenging a bit I
[1:00:08] think probably a fruitful thought for the audience is before thinking on AI
[1:00:14] first think on Automation and after you have your automation really well fine-tuned then think on AI because
[1:00:22] after the automation if you still find that you need a human to inter interpret some things and to take some decisions
[1:00:28] then you probably can take use of AI putting why everyone wants to throw AI to everything today even to things that
[1:00:35] don’t need AI to be solved uh so I would counter that and say first think on
[1:00:41] automation after automation if you still have some gaps that you need actually AI to solve that in a more efficient way
[1:00:47] for your organization that’s that’s great point the second one is uh coming
[1:00:53] to to your question I think is a matter of you uh as a person has a responsible
[1:00:58] for I don’t know security development organization whatever you need to optimize um the tools that you have so
[1:01:06] of course the vendors especially big vendors try to buy other companies
[1:01:12] integrate the functionalities into their own uh um products and have a more broad
[1:01:17] set of services that they offer or more broader um set of tools into their portfolio and in that sense you
[1:01:24] consolidate and you have a lot of synergies between the the tools and between the Telemetry that you receive
[1:01:29] from most of the tools but it’s also your responsibility to see okay my uh
[1:01:35] organization my profile of people my profile of deployments my profile of services um are not really well suited
[1:01:42] for that kind of technology so I need a different kind of Technology maybe I can integrate three or four into one or I
[1:01:48] need to spread myself uh between three or four Technologies so there’s no Ser
[1:01:54] to that to that question to be honest it’s our job to think what is more efficient for us and then try to find
[1:02:00] probably an abstraction layer where you can uh consolidate everything from multiple tools into one single spot for
[1:02:07] you to assess I can probably draw a parallel there we have seen that in observability
[1:02:13] right we seen the same Movement we started to monitor in one place log in another and then we had different type
[1:02:19] of metrics and then we have frontend Matrix backand metrix and so on and nowaday we see platform that are there
[1:02:24] that consolate all these into one single pain of glass I’m pretty sure they were going to see the same thing for security
[1:02:30] right it some already there but that’s where you get the real value when you can start correlating the data and
[1:02:35] watching how one thing impact the others on the a part instead I actually brought
[1:02:40] a document on the 2024 prediction on my side and I would love to have as you say
[1:02:46] what the assistant AI That’s going to tell me what is the most vulnerable part of my system or the less performant now
[1:02:54] yes automation is important but we also said we need someone that understand the old system and that could be the AI right
[1:03:01] you could actually let the AI understand the old system and keep all that data in mind right something that right now we
[1:03:07] struggle to do we struggle to see if we so right now we have different figures
[1:03:12] right in in general companies we have the The Specialist that look at the very fine green data and then we are the
[1:03:18] generalist that look at the broader picture imagine being capable having all the context in one place now it doesn’t
[1:03:25] have to be necessarily AI but we’ve seen the AI as the power of probably summarizing and consolidate the
[1:03:31] information a different way and create this with Nal language that can be the the next thing that we can do
[1:03:40] there thank you thank you Luka anyone else wanna go ahead add to
[1:03:46] that um I think 100% agree automation Ai and uh we have done
[1:03:54] something similar in my previous couple of roles where we had let’s say Splunk U then we have SOAR use the SOAR
[1:04:03] we also have one like umbrella AI tool and it’s done lot of stuff for us again
[1:04:10] this umbrella tool let’s say machine learning tool
[1:04:15] was whatever we have learned in last five years was pretty much automated and
[1:04:20] something new will come up it will come up as an alert but now bringing AI
[1:04:26] to do rest of the things filter and filter and filter and filter so we have
[1:04:31] more uh we don’t have to repeat ourselves doing the same problem but
[1:04:37] finding something new based again AI need to pick up something based on something so having business
[1:04:45] objectives protecting the crown jewels based on you know where they sit and what kind of vulnerability or or zero
[1:04:52] rate is is the key if AI can do that I think human and AI tools and AI need to find the balance
[1:05:00] right now tools are probably here and everyone has like five or 10 hats to do
[1:05:06] one job so if this balance you know comes in place it will
[1:05:11] be a great
[1:05:17] place okay well that was our final question if there’s anything else that
[1:05:23] anyone would like to add feel free if not thank you everyone for your insights
[1:05:29] and for a really wonderful discussion um let’s jump into some Q&A because we do
[1:05:36] have some questions in our Q&A box um
[1:05:41] that that some of them we’ve touched a little bit on already um but it would be good to um to to discuss
[1:05:52] um discuss um them more in depth with these question questions um so here we have a question
[1:06:00] or I don’t think more of a statement from Amir um I think standards like ssdf
[1:06:05] captures the essence more accurately should be addressed as a development framework which can change from one
[1:06:10] organization to another depending on the cicd pipeline and tools used just my two
[1:06:16] cents okay so it was more of a statement anything to add to that
[1:06:24] statement yeah I would like to say that um the standardizations and there’s a
[1:06:29] few of those especially for software development there’s a few of those out there uh are really
[1:06:35] important um I don’t think they’re the answer but they’re definitely something
[1:06:41] that can give you a a clear assessment I would say on the actual posture that you
[1:06:48] have and it can also show you oh I don’t do this part I haven’t done this part
[1:06:53] yet so what are the next steps that I can take if I’m not pretty sure what
[1:06:59] will provide me so I can choose one framework of another every organization is different the goals are different and
[1:07:05] the important thing from my perspective is to connect it to what the business is
[1:07:10] trying to achieve I cannot just kind of throw a framework into the mix and say okay I’m done so this is kind of my two
[1:07:17] cents on that I think having those Frameworks can
[1:07:24] be a good starting place for a lot of of companies that are really trying to just especially smaller companies that are maybe just trying to really kind of try
[1:07:30] to cohesively address this whole you know software development life cycle thing I think a framework definitely gives you a place to get started helps
[1:07:36] you even if you don’t follow it exactly helps you think through that process um and capture the important parts as you
[1:07:42] develop your own ways of working and and you know adapt it to your own tooling so I think there is a lot of value in those
[1:07:49] um even if it’s not like hey literally everybody should just go follow this thing
[1:07:57] next question is um from nadav and um we have two questions here so any idea on how to put a monetary value on not
[1:08:04] dealing with specific vulnerabilities I think that’s a great
[1:08:11] question would you justify it later yeah well I mean that that goes back to um
[1:08:17] the very old return return on security investment where it’s very difficult to prove a negative right what’s the the
[1:08:24] cost of not doing anything think uh it’s it’s really hard and it’s usually one of the biggest debates that we uh on a as
[1:08:32] a C level on security need to prove and to demonstrate um the best way on doing
[1:08:38] that is try to drill down into if I mean you will not ever be able to do that to
[1:08:44] a single specific vulnerability unless it’s something like a log4j or something uh because I mean I don’t know
[1:08:50] your reality but I have thousands of vulnerabilities
[1:08:56] uh right I’m sure most of you have the same so you cannot do that on a vulnerability per vulnerability uh uh
[1:09:02] case but you can Define scopes of for this kind of critical products or
[1:09:07] services in my organization with this kind of vulnerabilities classification
[1:09:12] um if we don’t mitigate that then the potential impact on the product if these compromises confidentiality Integrity or
[1:09:19] availability then you have like a risk scoring for each one of them and you you see like okay I have X amount of
[1:09:25] customers consuming the service if this is breach in terms of let’s say Integrity this might result in whatever
[1:09:31] Financial impact for the organization and also Financial uh impact due to contract breach or to regulatory breach
[1:09:38] so you make all of these sums and then you present this use case but it needs to be on a broader level not on a
[1:09:44] vulnerability by vulnerability case uh this this is my
[1:09:50] Approach yeah there are some Frameworks that can help you try to estimate the potential like dollar impact of a breach
[1:09:56] a data breach um we’ve kind of played around with some of those in the past um but I think you know I think I mean it
[1:10:02] is like difficult to do that on vulnerability by vulnerability basis you’ve got a lot of them um but you know
[1:10:07] I understand the desire there because I think you know if you’re trying to sell um you know management CEOs whatever
[1:10:14] about like hey no we really need to take this thing seriously you know it’s a lot easier to do that when you can see just a dollar amount next to it like hey you
[1:10:21] know this could potentially cost this x amount of money you know that kind of it’s it’s a helpful way I mean you know
[1:10:27] money is the language of business so so it’s helpful to be able to stick a dollar value next to something so you can help get it the appropriate priority
[1:10:34] and needs but yeah I mean in practice it can be very difficult so I guess I’m not really getting the answer yeah the other
[1:10:41] opportun just to wait for the next vulnerability breach announced by the industry right and then everyone realize that
[1:10:46] oops we have to do it as well so maybe we need more breaches maybe that’s the answer that’s a that leads into another
[1:10:52] question here which is what can be done to explain uh Junior mid-level Engineering Management the importance of
[1:10:57] security for them it is less says your feature to introduce um they have much
[1:11:03] to lose and nothing to gain from
[1:11:09] security there are two ways I would say the first one is um on a more cultural
[1:11:15] base you actually embed them in in a culture where they actually start to
[1:11:21] feel a bit of responsibility and proud in doing things aligned with security
[1:11:27] because in the end of the day is their work that they are producing so their output will be better than the others
[1:11:34] that don’t put security into it so it’s a matter of culture and perception the other one is in a more structured and
[1:11:40] probably more um I would say differently differently defined organization this
[1:11:47] works in some kind of organizations is to have clear secur security kpis per
[1:11:52] team where in they will have to uh to keep the kpis and with a good score and
[1:12:00] eventually they will need to implement some security measures to uh implement the kpis I think a mixture of both is
[1:12:07] probably okay not one or the other um this also depends on the culture of the organization the size of the
[1:12:13] organization the complexity the maturity of the organization there’s no one recipe for all the organizations so I
[1:12:20] would say a balance between making them also feel accountable proud
[1:12:25] responsible for doing things secure by Design um and this takes time I’m not
[1:12:31] saying like one or two months it takes probably years and then also putting some kind of metrics and requirements
[1:12:37] and kpis um from top level into the teams in order to achieve higher
[1:12:45] security and sorry just yeah go on sorry just a short one you mentioned
[1:12:51] everything I wanted to say you know but again having this culture and top down
[1:12:57] approach is the key if if I’m a parent company who consuming these Services
[1:13:05] then you know keeping everyone in that Assurance um framework is good but if
[1:13:12] I’m a software development company and I’m supplying my software then it’s a
[1:13:18] different game and and now you you start to have more and more regulatory requirements
[1:13:24] where even you need to do this so that also supports you so you cannot just develop a lousy software that has a
[1:13:31] bunch of security flaws and then you put it in the market you are liable for that so I think there’s a mix of several
[1:13:37] things that push you into the direction of yeah you actually need to care about security from design from the most early
[1:13:45] stage possible um I understand it’s difficult for some uh uh parts of the
[1:13:50] organization to deal with this and to understand this can give you one example in one my in one of my
[1:13:55] organizations everyone from everyone every business unit had security targets
[1:14:02] imposed by the C marketing HR Commercial Legal everyone oh what do I have to do
[1:14:09] with security you do and then you find the security requirements that they need to fulfill and that’s part of their uh
[1:14:16] uh um evaluation in the end of the year I’m not saying that this is the answer for everything but it’s for sure in some
[1:14:23] kinds of structures a good approach on other companies other organizations probably more flexible more fastpaced
[1:14:30] more let say Tech Innovative space they need to be more embodied of the culture
[1:14:35] of security from from the beginning right yeah and that’s it’s from the top
[1:14:40] down we said right so um go ahead Luca yeah I was going to say I was going to add
[1:14:46] the regulatory part and Nuno added after right and let’s not forget that yes we have to make everyone aware everyone
[1:14:51] responsible but at that point you can also Define security policies so at a point it becomes your responsibility you have
[1:14:57] to do it you don’t have to care but you have to do it right because the minimum has to be there and we have tools for
[1:15:03] that we can Define security policies if your code doesn’t match certain security policies your code doesn’t go to production if you really cannot I mean
[1:15:11] invite everyone or involve everyone or make everyone care then you have to force them to care at the
[1:15:18] point on that not I can add one more thing real quick I think this is really kind of the fundamental issue with
[1:15:24] security which is why I think some companies are like kind of just trying to get on the security bandwagon relatively late into the game is you
[1:15:30] know like security has an upfront cost um but a hidden benefit you know like it
[1:15:36] takes me time away from the work I want to do in order to work on security but I don’t actually see the benefit of it because the benefit is I’m less likely
[1:15:42] to have a risk that may a breach that may not have happened anyway so like all of these things that I think everybody’s talking about like you know even up to
[1:15:49] the regulatory changes you know like the reason we have those regulatory changes is to help teams see those cost UPF
[1:15:55] front um and so I think that’s what it really comes down to you know like culture regulatory changes tooling is
[1:16:02] trying to help team see that um you know kind of uh see that benefit
[1:16:08] um up front still go so they can see the benefit as well as that cost that they have to
[1:16:14] pay I I go ahead go ahead no it’s all
[1:16:19] good go ahead yeah it’s certainly it’s like I think The Upfront is certainly is that yes it’s said well security doing
[1:16:25] these these fixes and things in advance be very costly slow things down a little bit you know that’s the perception but
[1:16:30] if you ever have a major vulnerability or compromise or things like that the cost of a vulnerability is far higher
[1:16:37] than fixing all those bugs you know earlier so more vulnerabilities that that’s what
[1:16:42] we need more more breaches 100% And the rep as well the damage to reputation
[1:16:47] that costs it yeah involved yeah I think in general when you’re doing a postmortem and on any issue and you
[1:16:55] presented to the entire company or the entire org everybody sees that this is not fun you don’t you don’t want to be
[1:17:02] in this position and you’re trying to kind of tell everyone it cost us a lot
[1:17:07] of effort uh to recover from this so that’s why we shouldn’t do it we should
[1:17:13] learn from that from that but we should try to avoid
[1:17:23] that okay my Wi-Fi jumped can can you hear me
[1:17:29] now okay sweet um so on that note um there’s a question here I think is very
[1:17:35] up don’t you think that being a CISO is becoming more and more complex um besides protecting yourself
[1:17:41] you are becoming accountable for tprm for critical providers not only the ones that are digital connected to the
[1:17:47] company question mark yes I I mean um there are different
[1:17:54] definitions of CISOs there are executive CISOs field CISOs blah blah blah so you can uh name quite a few
[1:18:03] um definitions of the CISO but in the end of the day yes um ultimately you
[1:18:10] need to navigate a lot of waters more and more complex the landscape is more complex than a couple
[1:18:18] of years ago you have more regulatory pressure more audits coming your way you
[1:18:23] need to understand more technology you need to be broader in the sense of what you need to scope and there’s only so
[1:18:30] many hours in a day and so many so much time that you can dig into uh certain
[1:18:36] specific topics so for sure yes and specifically if you go to certain reg
[1:18:41] regulated uh Industries you are legally accountable for breaches so that poses
[1:18:47] another thing into your scope of pressure because there are times where you are you are trying to take decisions
[1:18:53] and you need to take them with lawyers by your side to actually make sure that am I doing something that will jeopardize
[1:18:59] me in the future yes or no I need to be cautious with this so yes it’s a tough
[1:19:05] uh um spot to be uh but a very fun one I would say fun
[1:19:13] okay um we have more technical questions as well in the Q&A if anyone would like to um add on to what Nuno said um feel
[1:19:22] free otherwise we’ll move on um for OSS how do you see the role of
[1:19:28] epss for prioritizing remediations is it im mature tool and how should we use
[1:19:36] it um so epss really is the potential of exposure in that sense and we touched
[1:19:44] that a little bit in the beginning and we can iterate that that epss basically
[1:19:49] means that uh I’m looking at more context of vulnerability like we said
[1:19:55] like internet exposure for example if something is not internet exposed it’s less likely to be attacked it’s not
[1:20:02] foolproof but it’s less likely so it is important I think that it’s something that we need to consider so to
[1:20:09] understand if something is reachable if it can be reached if it can be exploited
[1:20:14] because the environment is different sometimes exploits and it requires analysis but sometimes specific exploit
[1:20:21] will work on specific environment and if I’m running on a different environment it’s not nobody can exploit it and the
[1:20:28] last one is kind of the damage so what kind of damage it can do maybe there’s not a lot of damage a critical
[1:20:33] vulnerability but there’s not a lot of damage so if you look at it from different perspective and I think that we’re in going in in a good direction in
[1:20:41] that it can really paint a picture of is it critical to address now or it’s
[1:20:47] something that I can I need to address but I don’t have to do it right now and I think this is kind of part of the
[1:20:54] answer answer that we’re trying to find in that sense and I do want to say that you know if you pick a good framework
[1:21:02] you have good culture and training in place and you adhere to some regulations I think that’s a good start
[1:21:09] uh again it’s not the best but it’s a good start yeah I think I think it can also
[1:21:14] be dangerous without the right culture right because way I been in companies that were like okay this is a medium or is a low so it’s okay you can
[1:21:22] wait it doesn’t really work like there right when when you have thousands of vulnerabilities and I want to say it
[1:21:28] right it’s going to become tough to navigate vulnerabilities and you cannot just I mean this Miss some
[1:21:35] vulnerabilities because it’s low or it’s not exposed to internet assuming that you are okay with that because once the attacker inside your system the system
[1:21:42] is still vulnerable the fact that it’s not exposed it doesn’t mean that your the attacker is not already in right we
[1:21:48] starting from thinking on that as well yeah yeah so again those are nice tools
[1:21:55] that can help you but you have to be cautious of what you’re doing so don’t just trust the tool blindly again a lot
[1:22:02] security training a lot of awareness of what you’re doing and
[1:22:07] understanding yeah for sure I think epss will be um if you can automate that into
[1:22:14] a way where you have the score that takes into consideration the exploitability and your uh your
[1:22:21] environment it’s for sure better than relying in a let’s call it a blind CVSs that comes from yeah an out of the box
[1:22:30] assessment without context but um the trick here is how to produce that
[1:22:35] scoring from epss uh how do you do that because then you need to commit with that uh if you work in a highly
[1:22:42] regulated industry you know that you need to comply with the policies and you know that you have audits coming in uh
[1:22:49] day by day and when Auditors come it’s good that you have a good story on how
[1:22:54] did you classify or reclassified your priority your vulnerabilities according to what system and why did you didn’t
[1:23:01] for instance uh were able to keep the SLA for patching that vulnerability so
[1:23:07] those things need to be really well thought in terms of process and how do you do that because most of the times uh
[1:23:13] uh organizations are regulated or are audited and you need to have a good story to justify
[1:23:19] that yeah we have a question here from AA since false positives are usually the
[1:23:24] source for alert fatigue what schemes do you think can be implemented to mitigate this
[1:23:32] problem well we had that problem and kind of have a bit um there’s no other
[1:23:38] way than going back and forth and fine-tuning the the policies it is what it is uh you need to fine-tune the tools
[1:23:46] you need to of course there are tools and tools yeah I don’t know what kind of false positives but probably because
[1:23:51] we’re referring to uh Code probably something on source code analysis or static code analysis or something
[1:23:58] independent on that even if it’s dast or iast or static code analysis or
[1:24:04] something you need to fine-tune uh the scans you need to fine-tune the policies
[1:24:09] that you are using to scan and it’s a a continuous work on Improvement until you
[1:24:14] reach a good point where okay I’m satisfied with this uh we had that that
[1:24:20] problem and I think we have fairly mitigated it but for sure in the beginning we had like a bunch of
[1:24:26] complaints from the development team like yeah I’m getting like 150 alerts
[1:24:32] every time I go there is a false positive so I don’t trust you anymore I don’t care about security and immediately you lose trust from the
[1:24:38] development team I can I’ll add to what Nuno saying there as element is yep you’re always
[1:24:44] going to have false positive and it’s the tuning right for your environment and your graph and things like that there is the the fine tuning and that’s
[1:24:50] always going to be required but also I think this comes into place as some of the tools I mentioned before is ultimately you find something on a web
[1:24:57] scan you find something on your internal scan with an agent you find something in your source code scan right and saying
[1:25:03] are they all the same well this is where the kind of correlation and lying saying that yes this is appearing to be in the
[1:25:09] web scan this is appearing but actually in the source code there is no path to it right and things like that so in some
[1:25:14] ways you could say that’s a false positive and how you tune it identifying those and having the right Tools in place for
[1:25:22] that thank you David to add to that really high level um Automation and
[1:25:28] machine learning equals Ai and and we used to
[1:25:35] have uh triages done in six hours two years earlier now it’s half an hour just
[1:25:41] because of fine-tuning policies and other things but it’s still there but
[1:25:46] it’s less yeah it’s a lot of effort a
[1:25:51] continuous effort you’re never done you may think they done now and full supp are going to come back in a couple of
[1:25:57] weeks so if someone has to be dedicated to that unfortunately it’s again it’s part of the job like writing documentation
[1:26:02] no one likes to do that yet you have to do it like fixing bugs like avoiding regressions and so on it’s it’s part of
[1:26:09] the job yeah and I’d like to address that in
[1:26:15] a sec and false positive will always be here and I agree with you know fine
[1:26:21] tuning and everything uh today there are also tools that can help with that uh in
[1:26:28] that sense and I think that when you’re start looking for different tools
[1:26:34] especially for uh software security where you have to collaborate with
[1:26:39] developer it’s not like you can solve it by yourself you want to make sure that the tool itself can provide you with
[1:26:47] also the extra level information to basically understand if it’s true or not before you go on ahead and to implement
[1:26:54] that in the tool I think it’s it’s really critical and it’s something that you know we’ve seen in the market and
[1:27:00] the direction we’re going it’s really to help provide that level of accuracy in
[1:27:06] the same place so I think that this is also a good point because we need to
[1:27:12] collaborate we need to work with developers and as you said we need to make sure that trust and confidence is
[1:27:19] in place and I think that first we need to do it with our own tools and the way that we are working
[1:27:24] and then we can kind of externalize that and and have that better collaboration culture uh with the other team so I yes
[1:27:32] this really important and it’s a good point Thank you definitely thank you Boaz and with that we’ve reached our time
[1:27:38] limit this has been fun but we need to wrap up so thank you to everybody for
[1:27:44] joining us today thank you to everyone in our audience um and thank you to our speakers you know to Nuno Teodoro Tomer Weinberger
[1:27:52] David Cross Conor Mancone Luca Lanziani Jag Singh and Boaz Barzel uh we look forward
[1:28:00] to hosting many more discussions like these in the future so please join um and if you’d like to stay up to date
[1:28:06] also on our upcoming webinars um from OX Security you can follow OX Security on LinkedIn and um just be aware that
[1:28:13] you’ll be receiving an followup email with um some contact information from um for also for our panelists if you’d like
[1:28:20] to reach out and be in touch with them follow them um on on LinkedIn or wherever they’re posting um some good
[1:28:27] cyber security Insight um and yeah hope to see you guys all again and uh do this
[1:28:32] another time thank you thank you thank you very


