📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

RSA Security CEO: Dangers of Weak Identity Security | CXOTalk #892

CXOTalk53:39

Transcription

Identity is foundational for private and

secure computing, but it's filled with

challenges. Today on CXO Talk number

892, we explore AI

identity and board level cyber security

with the CEO of RSA security, Rohit Guy.

I'm your host, Michael Cricggsman. So,

let's get into it.

>> We are an identity security platform

company. We serve the world's most

security sensitive organizations. We

provide solutions in the area of

identity and access management and

identity governance and administration.

Balancing trust and business agility.

That's that's what we do. Michael,

>> when we talk about identity, tell us

what that actually means. identity.

Think of it as a digital representation

of a person, a device or a system. So

the actors on the network could be any

of those and and a digital

representation of that is needed to

again control the the the who, the what,

the when, and the why um questions

around identity. So the who or what it

is is look um can I prove

deterministically that it is indeed

Michael that is trying to access you

know this this uh this IT resource so

establishing that trust in terms of uh

you know who you are is what is referred

to as authentication right are you who

you're claiming to be and we have

several solutions over the years you

know passwords was the most basic one

and you know we have a bunch of other

technology now that is at way to provide

this layer of authentication.

The next piece is around authorization

which is the you know what and what can

you access what systems applications

data are you allowed to access what

rights do you have what credentials do

you have what privileges do you have and

then finally uh the idea of um kind of

managing the why like why should Michael

have access to these resources because

he has a certain role in the

organization he has a certain job

responsibility you know so so that's

sort of the the who, the what, and the

why. And you know, touching on the when

a little bit, what has happened over the

years, Michael, is that, you know, the

the the typical pattern of the cyber

threat actor is that they find a way to

get in. We have to resign ourselves to

the fact that we cannot keep them

outside. They're going to find a way to

get in. So our job really is twofold

which is to make sure even despite the

fact that they get in to make sure they

can't move literally inside the network.

So we we have to have this idea of

continuous trust even if when they're

inside the door inside the gate we still

have to monitor the behavior of the

actor to make sure the right things are

happening and everything is legit over

time and and and no nefarious activity

takes place. So that's that's really the

overlay on top of the who the you know

the what and the and and the why right

that that traditionally has been the

problem of identity. So that's what we

do in the in the area of identity. It's

all about the digital representation you

know ensuring these uh these questions

and making sure the right things are

happening and and by the way it's it's

you know I might remind everybody that

most cyber incidents happen on the back

of credential compromise. So identity

the line I like to use is is identity is

the most attacked part of the attack

surface. That's how the bad guys are

getting in. So it's super super critical

in today's world to improve your cyber

posture.

>> What does that mean that identity is

this core piece? That's how people are

getting in. There's this report Michael

in the industry that uh you know all the

cyber professionals pay attention to

which is the Verizon databach

investigation report and year after year

it it it does a great job of reporting

on uh you know what was the what is

called the initial access vector what uh

techniques did the threat actor use to

uh to get in and u you know I'll I'll

cite the latest one and then this has

been true for the last decade that

credential compromise meaning stolen

credentials either your password got or

stolen or your uh multiffactor

authentication got compromised or

somebody uh impersonated your biometric

maybe your voice etc to uh uh to

basically get in through the door

pretending to be you right a legitimate

actor in the network so this this idea

that um you know identity is the new

security pyramid and the and the initial

access vector it's the number one

initial access vector for the datab

bridge investigation report. Uh the

other thing I I want to say is that you

know this doesn't just mean you know

technical means it doesn't mean the

threat actor is using very sophisticated

engineering or technology to break in.

uh you know they're often using social

engineering attacks to actually um you

know kind of manipulate the human that

they're trying to impersonate or exploit

uh you know to to um to get in. So um

it's been consistent for the last decade

that this is the number one initial

access vector. So it's obvious things

staring at us in terms of what we ought

to do to improve our security posture

which is to improve our identity

security posture. Kathleen Mitchell on

LinkedIn asks this question which is

fundamental, simple and basic and I

think is a little more complicated which

is how is identity breached in the first

place.

>> If you think about how we are

manifesting identity, how are we trying

to manifest identity? It's through a

credential

which is um uh you know in the past and

even now painfully so is a password.

It's it's based on what you know right?

So the way you log into a computer or

the way you log into your bank account

or any other IT resource or or or

control resource let's call it you know

you have to um you have to um share

something that only you are supposed to

know a password or a passphrase that's

one type of credentials um you know so a

lot of compromise actually happens

u just by u you know the password

getting compromised ized and the way

that is happening is either through a

brute force attack that the threat

actors are basically just running

through a dictionary attack what is

called it brute force just apply a lot

of different passwords to guess what the

password might be but increasingly what

they're doing is using sophisticated AI

technology to scour your digital

universe to figure out your dog's name

your children's name your address your

date of birth etc from your digital

shadow on the internet and then make a

very educated guess in terms of what

what that credential might have been. So

password compromise is one of the ways

that identity compromise might occur.

But that's not all, right? There are

other credentials that we offer like

multiffactor authentication which is hey

it's not just what you know but maybe

what you have or who you are in terms of

a biometric uh authentication, right? So

let's talk about what you have. So a lot

of times and RSA has been in this

business of offering what is called MFA

multiffactor authentication where we

provide either a physical hardware token

or a mobile phone based application that

so if Kathleen is trying to log in and

if Kathleen is in possession of her

phone we can send a message to her phone

with a one-time password animeal

password that nobody knows about right

and then Kathleen can provide that

information to log in but in this

pattern what has happened is a lot of

times the bad bad actors can uh uh you

know execute what is called a

man-in-the-middle attack the resource

and then there is Kathleen and her phone

they can intercept the communication

between those two uh whenever there is

vulnerable type of communications as an

example SMS messages are very insecure

so if if the the onetime password is

being sent over SMS they can actually

exploit that and steal that over like uh

you know these unprotected channels.

They can actually um you know do as you

know kind of um um you know steal your

you steal your um uh you know the phone

uh credentials to actually pretend that

this is your phone. So there are

technologies to compromise the

cryptography and the encryption or

attack this you know the middle

communication the man-in-the-middle

attack to defeat that type of credential

and then finally the type of um uh you

know identity that is based on

biometrics in terms of who you are you

know and the perfect example here is a

lot of banks even today painfully they

might use your voice to authenticate you

on your bank account and guess what

today with the AI technology that is

available, you know, an AI can have

access to maybe one of the videos you

posted on the internet and they can

mimic your voice perfectly. So, they

will in their way in your voice talk to

your, you know, bank and basically fool

them into thinking that it's Kathleen on

the other side and thereby defeat their,

you know, biometricbased

identity strategy. So there are multiple

techniques that the threat actor is now

wielding to defeat uh and compromise

credentials and identity and thereby um

you know get get in in um uh in a you

know in an unexpected way and and cause

harm. So that's just an explanation of

what what might happen there.

>> Subscribe to the CXOT talk newsletter.

Go to cxot talk.com. Check it out. read

tremendous we have tremendous shows that

are coming up. Really just extraordinary

shows. So subscribe to our newsletter,

join in, ask your questions. So Kathleen

follows up and we have a bunch of

questions now stacking up. So we're

going to have to get to those. But

Kathleen follows up. So you know what do

we do with MFA is not enough. So what do

we do?

>> I'm not saying MFA is not enough. MFA is

a is an amazing solution to harden your

harden your attack surface. But the

issue is all MFA is not created equal.

MFA codes if they're sent over SMS

networks over mobile networks, they are

vulnerable. That's not a good secure

type of MFA that is susceptible to SIM

swaps, account takeovers, or you know,

phone, you know, hijack uh uh hijacking

of your phone number. All attacks that

are uh relatively easy to um uh to uh

execute and exploit.

a fishing resistant MFA,

an MFA solution that has uh strong

cryptographic roots like an RSA um

physical token or an RSA um soft token

we call it a mobile based application.

They are not sending these one-time

passwords, these FML credentials if you

will over vulnerable networks. they're

sending them over highly secure sessions

that are established between the

resource and and your um and your MFA

device or your or or your MFA uh token

if you will. So MFA is uh is a a highly

recommended and highly effective

solution frankly to defeat many many

credential compromise attacks.

So one recommendation absolutely adopt

fishing resistant MFA that is not

relying on mobile based OTP onetime

passwords. Having said that I also want

to add now getting to the fact that even

with MFA

the thread actor is super smart. They

know that RSA and a bunch of other

companies have designed technology that

is not vulnerable and it's strong MFA,

fishing resistant MFA.

Guess what? When you can't beat it, you

bypass it. So that's what the threat

actor is doing. And how are they doing

that? Well, they are doing that by using

attacks like the help desk exploit

attack. So about 3 years ago, uh you

know, we had an incident u at at MGM,

one of the and and and another casino in

in in Vegas where um you know, the way

the threat actor got in is they called

the help desk for that organization

pretending to be an employee and they

said, "I have lost my MFA uh device and

I urgently need to log in to my IT

device because I have a deadline and

this is a project that is very important

to our CEO and therefore I need your

help to provision new credentials for me

and help me access my my device and my

IT resources and thereby they use social

engineering via help desk scenario to

bypass MFA. they actually did have MFA

uh you know provided to all their

employees and all their users but it was

bypassed through social engineering

techniques by fooling the help desk

agent into issuing an alternate

credentials by creating this fake sense

of urgency. So this is a very very um a

common attack now and it is even more

and more sophisticated because now it's

maybe not a human calling the help desk

it's maybe an AI impersonating the

employees voice literally. So the help

desk you know is is is is uh you know

can be very easily fooled because it

sounds exactly like maybe somebody very

important in the organization. It might

be the CFO's voice calling the help desk

and the help desk you know will

recognize the authority and be fearful

and therefore you know sometimes make

the wrong decisions. So that's how uh

you know uh things get exploited. So my

recommendation back to what can we do

use MFA strong fishing resistant MFA

100% for 100% of your users.

Recommendation number two, do not just

obsess about authentication and strong

credentials.

Think about managing the identity

throughout its life cycle. Uh you know

and and and preventing against these

help desk type of attacks by uh finding

other identity security solutions that

uh protect identities even during these

types of like credential what we call

the joiner mover lever process. A new

employee joined, an employee called the

help desk, they got promoted, they're

leaving the organization. We need to pay

attention to managing those events in

the life cycle of an identity to assure

security in today's digital world. I

want to just tell everybody that you can

ask your questions.

when else will you have the chance to

ask the CEO of RSA security pretty much

whatever you want. So take advantage of

it folks. So let's jump over to Twitter

to X and Arcelon Khan is a regular

listener and he says this I think this

is related to what you were just

speaking about Roi. He says as a

consumer we share our identity

information credentials multiple times

to various IT systems the library

grocery stores banks and so on. We are

only as safe as the least safest system

and these are not in our control. So

what can what can we what should we do?

Any information that is potentially

identifying

you as an individual,

we need to uh share it on a need to-

know basis. We have been as individuals

especially as professionals in a

workforce setting, we have been perhaps

been too lax in terms of sharing our

information. uh because you know as you

said you know there is a legit reason

many a times for actually you know banks

or uh or or libraries or others to kind

of you know get get access to that

information. I think we need to pay

attention to what is that organization

or individual doing with the information

you're providing are they storing that

in a in a safe way. So uh the the the

sec you know when we share uh let's say

our information with a bank our mother's

maid name our uh you know date of birth

etc. We need to pay attention to the

cyber security posture of that bank

their data privacy statements that we

often you know kind of glance very

quickly and and agree to in in in sort

of agreements that we sign etc. I think

we need to pay attention to are they

doing the right things to keep your

information as private as it needs to be

to assure security in today's

environment. So a share on a need to-

know basis b pay attention to what the

organization that you provided the

information to is doing to protect your

information and how are they how good of

a job are they doing handling that

information. So those are two two

recommendation and I have a third which

is look if you are an IT professional

do not rely simply on an

informationbased

identity system. This is the whole

concept behind multiffactor

authentication. Don't rely on one

factor. That's what literally

multiffactor means, right? Do not rely

on the knowledgebased proofs of who you

are. your date of birth, your address,

etc., etc., ask for your, you know, ask

for other things like are you in

possession of the phone that is supposed

to be yours? Can we send

a FML password or code that you can

provide us? Uh, you know, biometrics

uh in terms of like uh scanning your you

know, face ID or or things like that.

So, always as an IT professional, you

have to use multitude of factors to

assure identity. do not rely on just

knowledge based information. Those are

three things that we can do to harden

our environments despite the need to

share information like like you asked.

So great question. Thank you for that.

>> Let's jump to a question from uh Pretine

Orion on LinkedIn who's asking about

CISO roles and she says this CISO roles

are among the most in demand globally.

Does this reflect a shift in how

organizations prioritize identity and AI

risk at the executive level and will

CISO demand rise further? What I will

say is the stature of the Cecil like you

said

uh is elevated now in today's um today's

world of AI powered threats and the

reason is um

cyber risk

um is now one of the top risks in the

what is called the risk register for

most organizations.

uh you know most public companies but

also um a lot of private companies

uh have a practice around risk

management

uh which is to make sure that the

organization can deal with the risks

that it faces and has uh sufficient

mitigation for those risks.

Cyber risk is now a very very prominent

part of that risk register and therefore

the SISO's stature in terms of advising

the board and the management teams on

cyber risk and its implications as well

as the mitigating controls that the SISO

is recommending is one of the most

consequential business decisions that a

private or a public uh company today

needs to make. So what I would say is

there is uh the there is a huge demand

for these strategic sysos that can

translate the technology of cyber

security to the business uh implications

of cyber security for the board and

management teams to act upon. So I I

think that uh you know that we are we

are going to find uh find sysos

um you know finding uh even more and

more uh stature in organizations a a

larger voice a more prominent voice uh a

and what I would say is that um you know

even at the board level you'll see a lot

of demand for cyber security expertise

because not only do you need a strategic

SISO, you need a board and a management

team that can understand what the SISO

is telling them. So, you need a a level

of expertise in order to govern uh the

cyber risk that most organizations face

uh in today's climate.

>> So, should the CISO be a technologist

or a business person? We are entering

the era of sysos that maybe have a

strong business background

with enough technology

uh sort of capability to drive teams

that might be operational and technology

oriented and therefore I would frankly

ask for a syso to be more sort of you

know 5149 you know more business than

technology in today's climate because

cyber security is now a squarely a

business problem more so than it is a

technology problem. Right? It's social

engineering. It's in the world of AI,

right? So, so, so thinking about uh

robust risk management uh approach to

cyber is uh is consequential to the

efficacy of a SISO.

>> What kind of communication skills a SISO

has and when they communicate? And the

reason I asked this is not too long ago

I approached two CISOs, one each from

two of the largest, most well-known

brands in the US independently.

And CISO number one said she wants to do

it. And then I started saying, well,

it's live and we take questions. And

she's like, no, no, no. I can't can't do

that. CISO number two said in my role

and I I've known CISO number two for a

long time. In my role, no way. So,

what's the job of the CISO in terms of

communication? And is it too scary for a

CISO to join something like this that's

live that we take questions?

>> CISOs have a dual role as does every

cyber security professional.

If you think about cyber security as a

business area, it's unique. In other

business areas, when we talk about

competition, you're often thinking about

other vendors that might offer a similar

solution that is competing for the love

of the customer with you. In cyber

security, when we say competition,

it's the threat actor on the other side.

So, the SISO has a dual role. One is to

defeat the competition on the other side

and and and make sure you know your

security posture is robust that you have

all the uh you know the right technology

and the processes to make sure your

cyber security is is assured.

But in addition the syso has another

role. The threat actors are

collaborating. They are sharing

information. They're sharing malware.

they're sharing uh ransomware tools that

are that they're using. We on the good

side need to do the same thing. We need

to do a better job of collaborating on

the good side. So if one syso in the

financial services industry is noting

that a certain type of malware

is is u is prevalent or is trying to you

know get access to their environment.

that information sharing that

information with other companies and

other peer SISOs and other cyber

professionals is highly highly valuable.

So my point is that I think there is a

certain level of transparency that the

SISO um needs to have with peers and we

need to lift all boats not just protect

our respective organizations but share

our knowledge with peers and peer

organizations so we can lift all boats

and defeat the threat actor on the other

side because that's who we are really

competing with in cyber not not other

peer companies. Arcelon Khan comes back

on Twitter and he says, "Our identity is

spread across so many different systems

and

companies. There's not just one single

place. It's the entire ecosystem of as

we were talking earlier pretty much

everybody that we do business with.

But most companies are not transparent

in how they deal with consumer data. In

fact, consumers have no clue until after

a data breach happens. And I'll just add

and sometimes a long time after that

data breach has happened.

>> It is getting better. And the reason

it's getting better is that the

regulator is stepping in, right? The

regulator is mandating responsible

disclosures that if you get breached

that as a public company for example

especially public companies there is

real teeth in in in in some of these

regulations in terms of responsible

disclosure that you must any material

breach or cyber incident you must report

right and and there thereby protect your

consumers and customers before their um

you know information gets compromised

perhaps. So the regulators stepping in,

things are getting better. In addition,

there is, you know, you know, it started

with GDPR in EU and then CCPA here in uh

California and there's more regulations

around data privacy as well. So yes,

there is it still remains a challenge

more broadly, but it is it is

dramatically better than what it used to

be. And again, I go back to the same

recommendation.

Let's not solely rely on the privacy and

the successful privacy of the

information we've shared because despite

best conduct on part of organizations

that have that information, the bad guys

can still get in. We must reconcile with

the reality that the bad guys will

always find a way to get in because

sometimes they're actually insiders.

Sometimes they're actually inside the

company. It's not somebody bad on the

outside that's trying to get in. It's

just somebody on the inside. It's an

inside a threat issue. Therefore, do not

rely on the the privacy of your

information as the only mechanism that

you're going to uh uh use for cyber

security. So that's that's sort of my my

headline summary uh on that question.

>> Sounds kind of hopeless.

[Laughter]

Let let me let me let me swivel then to

a more optimistic uh picture. Uh Michael

and and and all the all the audience.

Look the way to approach this problem is

framing our goal properly. Okay. And I

I've often use a medical analogy to talk

about the goal is you know if you think

about medicine you can frame the goal in

terms of like we're going to eradicate

disease. That could be one goal or you

could say the goal is actually wellness

and health despite the existence of

disease. So in cyber we need to take a

similar approach. It's not about making

sure that uh you know cyber incidents

don't happen because they will. It's

about resilience. I think we ought to

actually redefine our industry not as a

cyber security industry to but to be a

cyber resilience industry because the

goal is digital wellness. It's not to

make sure the threat actors are kept at

bay, but the fact that even if they get

in,

there is limited risk or damage to the

business that they can perpetrate.

That's the goal. It's wellness despite

the existence of the threat actor. And

if you frame the problem like that, it's

not a hopeless situation at all. In

fact, it's it's it's very tenable. And

you approach cyber security as a risk

problem. And I would love to talk about

sort of you know the the the you know

how CEOs and boards ought to pay

attention to cyber cyber as a risk

problem right it's about reducing risk

it's not about eradicating it because

that's untenable goal right and and and

and that's that's the hopeful uh

narrative for cyber uh that it is

absolutely possible and absolutely

attainable to have cyber health and

digital health despite all these threat

actors especially in a world of AI. I

think AI will be a massive massive force

that will help the good good actors uh

keep up with the threat actors. So I'm

I'm actually an optimist as it pertains

to the cyber u you know cyber landscape

if you will. Let's take very quickly uh

Kathleen Mitchell comes back with

another really good question and then we

need to talk about AI and we need to

talk about uh these board issues both

very very important. Kathleen says, "For

smaller and midsized businesses, how can

leaders move beyond just meeting

compliance requirements to make cyber

security a real competitive advantage,

one that they'll prioritize and invest

in?"

>> The reality is traditionally smaller

organizations have struggled to actually

um make headway with cyber security. The

reason being they simply don't have the

technical expertise or the teams to

actually deploy solutions.

Having said that, I think there is um uh

you know there is uh

uh a couple of trends in the industry

that are really helpful to smaller

organizations which is managed service

providers. So you actually now have uh

solution providers that are uh uh you

know that are providing full end-to-end

service in terms of helping smaller

organizations that don't have the human

capital to manage cyber to do it on

their behalf and do it treat it as a

business problem. The second thing is

the advent of AI will uh will I think

hopefully foster the creation of more

autonomous cyber solutions where you

don't need as many humans with hands on

the wheel to drive the cyber security uh

truck if you will right so so the the

the promise of AI as I alluded to

earlier we've always suffered on the

good side of the fight with the lack of

cyber talent we don't have even enough

good humans to fight the good fight and

the bad guys only need to be right once.

We need to be right all the time.

With AI, we can now

wield these agentic digital workers on

our behalf, on our side to tip the

balance in our favor so that we can do

the things that we never could do

because we didn't have enough good

humans on our side. You can automate

that, right? That's a massive massive

tailwind for us on the uh in the cyber

security world that will help especially

smaller organizations

and u and and and I think um you know I

I you know the other thing is I want to

commend some of the organizations

um you know here in the here in the US

like CISA uh critical infrastructure

security agency. So the government has

done a great job of elevating the

knowledge, the knowhow and the

sensitivity to cyber security for

smaller organizations. They have recipe

books. They have great resources on sit

cisar.gov evolve that smaller

organizations can uh peruse and and and

consume to get smarter on the issues

around cyber security as well as tools

and techniques and prioritize

recommendations on what they can do to

protect themselves. So, so I think it's

an emerging uh you know it's a um it's a

world that is getting much better in

terms of cyber for smaller organizations

than it used to be let's say 5 years ago

>> for smaller companies it's tough you

know CXO talk we're a small company and

because of CXO talk we're attacked all

the time I'm mean I get attacks fishing

like very targeted and our

infrastructure was attacked and I was at

a loss like what to do and and actually

I asked a couple of former CXO talk

guests who are like you know top

security experts and we had a call and

they gave me advice and we were able to

ultimately sort it out some you know a a

AWS configuration issues and a bunch of

other stuff but it's tough if you're a

small company

>> it is tough and I would say this these

social engineering type of attacks are

especially tough fishing as you alluded

to, Michael, they are like, you know,

relentless attacks and now more

sophisticated because they can

impersonate, you know, your loved ones

or or people in your company, etc. So, I

have a couple of recommendations in

terms of like what can you do to protect

yourself against fishing attacks, right,

for um you know, so I I I have three

macro recommendations.

number one

multi- fishing resistant multiffactor

authentication

deployed for all users. I think that can

help. So anytime uh you know that that

is a baseline table stakes

recommendation. Number two is we have to

realize that these threat actors

try to manipulate you emotionally and

create a sense of urgency. Act now you

must do this now otherwise bad things

are going to happen. So anytime you

sense any communication that tries to

ignite the sense of urgency, treat it

with a lot of suspicion.

That's recommendation number two.

Recommendation number three is that

realize that deep fakes is the era of

defakes and what is called synthetic

media. You might get a video of your son

or daughter in harm's way that looks

completely real asking for help and you

might kind of act on it.

Do not act on u on uh on media alone,

voice, video, things that uh things that

might appear very real

with your loved ones or within your

company. Have a out ofband mechanism to

assure identity. So if you have your

children as an example or a family, you

might have a family password that if I

ever call you asking for help if I have

a flat tire, if your daughter says,

"Hey, if I, you know, I have a flat

tire, I need 50 bucks to, you know, pay

the towing company." Do not send that 50

bucks right away. Ask your daughter for

the family password. So verify the other

person outside of you know what might be

very realistic voice or synthetic media

that you know might sound or look

exactly like the the individual that you

trust. So do not establish trust based

on uh you know media because they are

they can be compromised in the world of

AI. Have an outbound channel to assure.

So those are three quick recommendations

and what you can do uh to I guess avoid

getting fished if you will. And Michael

you know you I'm sure you're a big

target. I am. I'm famous in my company

for sending text messages asking for

gift cards as a CEO. So, they get CEO

text messages all the time. My my

colleagues in the company that asking

for gift cards.

>> We have an AI question from Elizabeth

Shaw on Twitter and I'm glad she is

jumping in because we need to talk about

AI and she says AI brings its own

issues. There's AI versus AI. AI run a

muk. How should companies consider AI

for cyber security and place their trust

in it? So the role of AI in all of this,

>> there are three dimensions to AI. One is

AI as a

sword,

right? It's a it's the attacker's tool.

So they're the threat actors are going

to use AI to attack at scale or

hyperpersonal personalize, impersonate,

bypass traditional defenses, create

malware because you can do wipe coding.

So even tech technically inferior threat

actors can now code because AI can code

on their behalf. So it's it's a it's a

sword. Second thing is it's a shield on

the threat actor side which is we have

not had enough humans to look at all the

incidents all the threats that are

playing out we can do that you know

we'll have digital workers software

robots that can do that job for us we

can monitor synthetic media to look for

signs for synthetic media right is this

deep fake right there are technologies

that can do that AI technologies we can

u you know monitor patterns for what is

normal versus what is normal. Do

predictive risk modeling do incident

simulation and playbooks automation

because of AI. So that's the shield

dimension. So sword dimensions, shield

dimension, but there is a third

dimension which is what you were

touching on Elizabeth which is AI as a

it's an act it's an part of the attack

surface

right the threat actor might actually

compromise the AI that you're using uh

by poisoning AI or or uh doing you know

you know doing nefarious prompt

engineering

uh or u you know by actually ensuring

ing that um you know that you're um

denial of service attack. So if AI is in

a decision loop, let's say it's it's um

you know approving uh I don't know loan

applications for a bank, you know, they

can actually u you know bombard and do a

denial of service type attack to to

confuse the AI, right? And and and cause

that. So AI can be attacked and

therefore we as cyber professionals

need to do two things. One is we have to

embrace AI as a shield because we know

that the bad guys are using it as a

sword. So we better pick it up, get more

educated and proficient on using AI

otherwise we'll be left behind. We

cannot wait. But then also adopt AI

responsibly, right? And and uh and don't

trust AI blindly. uh you have to have AI

inside of guard rails meaning

u you know any agentic AI you deploy in

your environment make sure it has the

guardrails of human defined workflows a

human in the loop

second second is you must have nonhuman

identity solutions to make sure just

like you're protecting human identities

and making sure the human is has the

privilege to act on your digital estate

Don't allow AI agents to work

autonomously without verifying their

identity. So you have to have nonhuman

identity solutions that assure the

identity of these AI agents that are

acting on your behalf. So that's that's

what I would say in terms of AI. Those

are kind of the three dimensions that we

must pay attention to. It is not just

you know as a proverbly a double-edged

sword. There is a you know it's also

it's also um it's also the thing that is

actually being attacked by the sword.

>> Can you talk a little about the

economics of AI or how does AI affect

the economics of cyber attacks?

>> Cyber security is an economic problem.

At the end of the day the cyber threat

actor is economically motivated and

constrained just like we are on this

side. They don't have infinite budgets.

they don't have infinite resources

either. So the economics of

AI based you know or cyber in the in the

era of AI is that the cost of

perpetrating a cyber attack is going to

go remarkably lower right so we have to

recognize that reality in the past we

would say oh you know what it takes a

lot of cost lot of expense to actually

exploit

uh you know zero day attacks because it

requires a lot of technical expertise

and hiring technical expert experts is

is costly and so forth. So we we we

could make those assumptions. Now we

cannot do that because you know there is

AI on the other side and the cost of

launching an attack is a lot lower. So

we cannot use economics or cost as a

deterrent. What we have to do is we have

to be smart about our crown jewels. What

the what the threat actor doesn't know

is once they get in, they're trying to

get to our crown jewels. We know where

our crown jewels are. They don't. So if

we pay if you know, so don't have a

peanut butter cyber security strategy of

protecting everything. have a

differentiated strategy where you have a

robust enterprise riskmanagement

framework where you have what are the

likelihood of cyber threats happening.

What is the impact of those cyber

threats have have this kind of matrix

and the cyber threats that have a high

likelihood of happening and have a high

impact are the ones you look to mitigate

and address, right? and have this

differentiated economical strategy of

not spending your money, if you will, to

cover all bases, but to cover the right

bases and spend smartly because the e

the economics as a deterrent strategy no

longer holds true in the in the AI era.

>> Let's talk about board issues.

What is the role of a board versus the

executive management when it comes to

dealing with these cyber security

issues?

>> Let me frame it at a high level first. I

think the board sets the what and the

why, which is what is the acceptable

level of risk, what are the strategic

priorities and how much are we going to

fund to mitigate those risks.

The management teams own the how, the

tools, the processes and the execution

to actually achieve those outcomes. So

board, the what and the why, management,

the how. And the way the way this needs

to play out is,

you know, and I'm on the risk committee

of of of a few uh public board and I've

I've I've held those roles. I've I've

kind of advised them on cyber security

as a part of that enterprise risk

register. Like I said, the erm strategy

for an organization is you take your

risks and you place them on this matrix

of likelihood and the and the magnitude

of impact. You start with what is called

inherent risk which is if you do nothing

what is the level of risk and you create

this matrix. Then you say I am going to

apply some controls. I'm going to uh

adopt MFA for everybody. I'm going to do

patch management and I'm going to use u

uh you know a a zero trust micro

segmentation tool that will uh protect

um my uh my users from thread actors.

Those are mitigating controls and then

what you're left with is what is called

residual risk. Right? So inherent risk

apply mitigating controls remaining risk

is residual risk and then the board has

to make a call on what is that

acceptable level of risk what's your

risk appetite what's your risk tolerance

if you have a if you're a software

vendor that provides a SAS solution how

much downtime can you accept right and

maybe the downtime that you can accept

is 4 hours in which case you're spending

you know instead of making sure you're

available all the time what you want to

make sure is that if you do get

compromised, you can bring things back

up in 4 hours. The idea of resilience.

So, it's this fine balance between

managing risk, deciding what to avoid,

what to reduce,

sometimes you transfer risk by buying

cyber insurance and what risk are you

going to accept. That's a board level

topic, right? That's what the risk

committee of a board needs to think

about, needs to uh planfully execute on

and then and then um uh kind of task the

management team to say this is what we

want in terms of u you know the

mitigating controls and this is the

acceptable level of risk. you now go

forth and execute on deploying the tools

and the processes to make sure we remain

within that kind of realm of risk that

is acceptable to us as a company. That's

kind of the division of labor if you

will between the board and the

management that you were touching on.

Michael,

>> you just described a very sensible uh

and general risk management framework

that's applicable of course in many

kinds of circumstances. However, when it

comes to cyber security, there's also

this technology element. And so, how can

board members make intelligent decisions

about that residual risk when they don't

necessarily understand the underlying

technology that's driving the whole

thing?

>> I don't think the board needs to be

steeped in the technology of cyber. They

need to be uh steeped in the risk of

cyber. They need to understand that a

ransomware attack you know what's a

typical ransomware attack and you know

what's the what's you know for my ilk of

company my size of company what are the

kind of you know if if if something like

that were to happen in our environment

do we have the playbooks to kind of

restore our services and and what's the

type of ransom demand we might hear etc.

So they have to think about the business

aspect of cyber not the technical aspect

of cyber but they do need to be aware of

the types of technical threats that

exist but they don't need to worry about

the how.

>> In one minute can you briefly describe

the life cycle of a ransomware attack I

pointed out because the consequences can

be so d companies have gone out of

business because of this. Ransomware is

a very nefarious type of attack because

it's changed the game on us, right? It

in the past the bad guys would get in,

they would steal stuff and take it out,

data,

you know, uh, information, things of

that nature. In this case, what they do

is they get in, they disrupt your

environment and pause, you know, they

might encrypt your data. They don't

steal it. It's still there, but it's now

encrypted, so you can't access it. Or

they might u you know kind of disrupt

your operations as in you can't run your

trains because they have kind of you

know the you know they've kind of locked

the lock the go button for the train

and then demand ransom. So the the the

the life cycle you what you need to

think about from a um ransomware thing

is what can you do before during and

after a ransomware attack. The board

needs to think about that framework and

there are things you can do in terms of

the before which is uh you know the the

the policy the the the you know the BIS

BC business continity plan that says

even if they get in and if they let's

say encrypt the data how quickly can we

restore it from a backup copy is

everything protected so before invest in

identity backups segmentation response

planning during you have to focus on

containing fast communic communicating

clearly, restoring quickly and then

after a ransomware attack to learn,

adapt and harden. That's sort of the

framework that you should be thinking

about. Uh if you do happen to, you know,

face a ransomware situation, but do not

pay ransom right off the bat because it

only encourages the bad guys to do more.

think about um you know unless unless

your hands are tied and you you know the

the the damage is so um consequential

and and and and that that you have to

that's should be a matter of last

resort.

>> Where is RSA security investing over the

next 12 to 18 months?

>> We are focused on what we call the three

Ps of of cyber in FY in in 2025. We

think that that's the most important

things to focus on for organization. The

three Ps of identity security,

passwordless,

posture management, and platformization.

Passwords, we've talked about the cost,

complexity, and the vulnerability aspect

of passwords. Passwords need to die. You

need to adopt to a passwordless world to

um uh and and all passwordless solutions

aren't created equal. So you know uh

embrace enterprise ready passwordless

solution because passwords are not um

you know not the right tool for an AI

powered cyber threat landscape. Number

two posture management. Like I said

that's how the bad guys are getting in.

So best way to improve your security

posture is to improve your identity

security posture. Do the users have more

entitlement than they do? Do you have

orphaned accounts that people have left

the company? there's still there's still

accounts. So, cleaning up the digital

debris and the sort of you know

tightening up your identity posture uh

using AI is investment area number two

and platformization. The bad guys are

exploiting the the gaps between our

tools. Best of breed strategy in

identity isn't working anymore. you need

solutions that have shared context that

can defeat uh you know this modern

threat attacks that the that the you

know the bad bad guys are throwing at

us. So those are the three areas of

focus for RSA and um and that's how we

believe we can make a difference in

terms of keeping the most secure

companies around the world secure. Okay,

Rohit Guy, CEO of RSA Security, thank

you so much for taking your time to be

with us. This was great.

>> Thank you, Michael.

>> Everybody, thank you for watching.

Before you go,

subscribe to the CXO Talk newsletter. Go

to cxot talk.com, check it out, read

tremendous, we have tremendous shows

that are coming up, really just

extraordinary shows. So, subscribe to

our newsletter, join in, ask your

questions, and we'll see you again next

time. Take care, everybody.

[Music]