Transcription
Identity is foundational for private and
secure computing, but it's filled with
challenges. Today on CXO Talk number
892, we explore AI
identity and board level cyber security
with the CEO of RSA security, Rohit Guy.
I'm your host, Michael Cricggsman. So,
let's get into it.
>> We are an identity security platform
company. We serve the world's most
security sensitive organizations. We
provide solutions in the area of
identity and access management and
identity governance and administration.
Balancing trust and business agility.
That's that's what we do. Michael,
>> when we talk about identity, tell us
what that actually means. identity.
Think of it as a digital representation
of a person, a device or a system. So
the actors on the network could be any
of those and and a digital
representation of that is needed to
again control the the the who, the what,
the when, and the why um questions
around identity. So the who or what it
is is look um can I prove
deterministically that it is indeed
Michael that is trying to access you
know this this uh this IT resource so
establishing that trust in terms of uh
you know who you are is what is referred
to as authentication right are you who
you're claiming to be and we have
several solutions over the years you
know passwords was the most basic one
and you know we have a bunch of other
technology now that is at way to provide
this layer of authentication.
The next piece is around authorization
which is the you know what and what can
you access what systems applications
data are you allowed to access what
rights do you have what credentials do
you have what privileges do you have and
then finally uh the idea of um kind of
managing the why like why should Michael
have access to these resources because
he has a certain role in the
organization he has a certain job
responsibility you know so so that's
sort of the the who, the what, and the
why. And you know, touching on the when
a little bit, what has happened over the
years, Michael, is that, you know, the
the the typical pattern of the cyber
threat actor is that they find a way to
get in. We have to resign ourselves to
the fact that we cannot keep them
outside. They're going to find a way to
get in. So our job really is twofold
which is to make sure even despite the
fact that they get in to make sure they
can't move literally inside the network.
So we we have to have this idea of
continuous trust even if when they're
inside the door inside the gate we still
have to monitor the behavior of the
actor to make sure the right things are
happening and everything is legit over
time and and and no nefarious activity
takes place. So that's that's really the
overlay on top of the who the you know
the what and the and and the why right
that that traditionally has been the
problem of identity. So that's what we
do in the in the area of identity. It's
all about the digital representation you
know ensuring these uh these questions
and making sure the right things are
happening and and by the way it's it's
you know I might remind everybody that
most cyber incidents happen on the back
of credential compromise. So identity
the line I like to use is is identity is
the most attacked part of the attack
surface. That's how the bad guys are
getting in. So it's super super critical
in today's world to improve your cyber
posture.
>> What does that mean that identity is
this core piece? That's how people are
getting in. There's this report Michael
in the industry that uh you know all the
cyber professionals pay attention to
which is the Verizon databach
investigation report and year after year
it it it does a great job of reporting
on uh you know what was the what is
called the initial access vector what uh
techniques did the threat actor use to
uh to get in and u you know I'll I'll
cite the latest one and then this has
been true for the last decade that
credential compromise meaning stolen
credentials either your password got or
stolen or your uh multiffactor
authentication got compromised or
somebody uh impersonated your biometric
maybe your voice etc to uh uh to
basically get in through the door
pretending to be you right a legitimate
actor in the network so this this idea
that um you know identity is the new
security pyramid and the and the initial
access vector it's the number one
initial access vector for the datab
bridge investigation report. Uh the
other thing I I want to say is that you
know this doesn't just mean you know
technical means it doesn't mean the
threat actor is using very sophisticated
engineering or technology to break in.
uh you know they're often using social
engineering attacks to actually um you
know kind of manipulate the human that
they're trying to impersonate or exploit
uh you know to to um to get in. So um
it's been consistent for the last decade
that this is the number one initial
access vector. So it's obvious things
staring at us in terms of what we ought
to do to improve our security posture
which is to improve our identity
security posture. Kathleen Mitchell on
LinkedIn asks this question which is
fundamental, simple and basic and I
think is a little more complicated which
is how is identity breached in the first
place.
>> If you think about how we are
manifesting identity, how are we trying
to manifest identity? It's through a
credential
which is um uh you know in the past and
even now painfully so is a password.
It's it's based on what you know right?
So the way you log into a computer or
the way you log into your bank account
or any other IT resource or or or
control resource let's call it you know
you have to um you have to um share
something that only you are supposed to
know a password or a passphrase that's
one type of credentials um you know so a
lot of compromise actually happens
u just by u you know the password
getting compromised ized and the way
that is happening is either through a
brute force attack that the threat
actors are basically just running
through a dictionary attack what is
called it brute force just apply a lot
of different passwords to guess what the
password might be but increasingly what
they're doing is using sophisticated AI
technology to scour your digital
universe to figure out your dog's name
your children's name your address your
date of birth etc from your digital
shadow on the internet and then make a
very educated guess in terms of what
what that credential might have been. So
password compromise is one of the ways
that identity compromise might occur.
But that's not all, right? There are
other credentials that we offer like
multiffactor authentication which is hey
it's not just what you know but maybe
what you have or who you are in terms of
a biometric uh authentication, right? So
let's talk about what you have. So a lot
of times and RSA has been in this
business of offering what is called MFA
multiffactor authentication where we
provide either a physical hardware token
or a mobile phone based application that
so if Kathleen is trying to log in and
if Kathleen is in possession of her
phone we can send a message to her phone
with a one-time password animeal
password that nobody knows about right
and then Kathleen can provide that
information to log in but in this
pattern what has happened is a lot of
times the bad bad actors can uh uh you
know execute what is called a
man-in-the-middle attack the resource
and then there is Kathleen and her phone
they can intercept the communication
between those two uh whenever there is
vulnerable type of communications as an
example SMS messages are very insecure
so if if the the onetime password is
being sent over SMS they can actually
exploit that and steal that over like uh
you know these unprotected channels.
They can actually um you know do as you
know kind of um um you know steal your
you steal your um uh you know the phone
uh credentials to actually pretend that
this is your phone. So there are
technologies to compromise the
cryptography and the encryption or
attack this you know the middle
communication the man-in-the-middle
attack to defeat that type of credential
and then finally the type of um uh you
know identity that is based on
biometrics in terms of who you are you
know and the perfect example here is a
lot of banks even today painfully they
might use your voice to authenticate you
on your bank account and guess what
today with the AI technology that is
available, you know, an AI can have
access to maybe one of the videos you
posted on the internet and they can
mimic your voice perfectly. So, they
will in their way in your voice talk to
your, you know, bank and basically fool
them into thinking that it's Kathleen on
the other side and thereby defeat their,
you know, biometricbased
identity strategy. So there are multiple
techniques that the threat actor is now
wielding to defeat uh and compromise
credentials and identity and thereby um
you know get get in in um uh in a you
know in an unexpected way and and cause
harm. So that's just an explanation of
what what might happen there.
>> Subscribe to the CXOT talk newsletter.
Go to cxot talk.com. Check it out. read
tremendous we have tremendous shows that
are coming up. Really just extraordinary
shows. So subscribe to our newsletter,
join in, ask your questions. So Kathleen
follows up and we have a bunch of
questions now stacking up. So we're
going to have to get to those. But
Kathleen follows up. So you know what do
we do with MFA is not enough. So what do
we do?
>> I'm not saying MFA is not enough. MFA is
a is an amazing solution to harden your
harden your attack surface. But the
issue is all MFA is not created equal.
MFA codes if they're sent over SMS
networks over mobile networks, they are
vulnerable. That's not a good secure
type of MFA that is susceptible to SIM
swaps, account takeovers, or you know,
phone, you know, hijack uh uh hijacking
of your phone number. All attacks that
are uh relatively easy to um uh to uh
execute and exploit.
a fishing resistant MFA,
an MFA solution that has uh strong
cryptographic roots like an RSA um
physical token or an RSA um soft token
we call it a mobile based application.
They are not sending these one-time
passwords, these FML credentials if you
will over vulnerable networks. they're
sending them over highly secure sessions
that are established between the
resource and and your um and your MFA
device or your or or your MFA uh token
if you will. So MFA is uh is a a highly
recommended and highly effective
solution frankly to defeat many many
credential compromise attacks.
So one recommendation absolutely adopt
fishing resistant MFA that is not
relying on mobile based OTP onetime
passwords. Having said that I also want
to add now getting to the fact that even
with MFA
the thread actor is super smart. They
know that RSA and a bunch of other
companies have designed technology that
is not vulnerable and it's strong MFA,
fishing resistant MFA.
Guess what? When you can't beat it, you
bypass it. So that's what the threat
actor is doing. And how are they doing
that? Well, they are doing that by using
attacks like the help desk exploit
attack. So about 3 years ago, uh you
know, we had an incident u at at MGM,
one of the and and and another casino in
in in Vegas where um you know, the way
the threat actor got in is they called
the help desk for that organization
pretending to be an employee and they
said, "I have lost my MFA uh device and
I urgently need to log in to my IT
device because I have a deadline and
this is a project that is very important
to our CEO and therefore I need your
help to provision new credentials for me
and help me access my my device and my
IT resources and thereby they use social
engineering via help desk scenario to
bypass MFA. they actually did have MFA
uh you know provided to all their
employees and all their users but it was
bypassed through social engineering
techniques by fooling the help desk
agent into issuing an alternate
credentials by creating this fake sense
of urgency. So this is a very very um a
common attack now and it is even more
and more sophisticated because now it's
maybe not a human calling the help desk
it's maybe an AI impersonating the
employees voice literally. So the help
desk you know is is is is uh you know
can be very easily fooled because it
sounds exactly like maybe somebody very
important in the organization. It might
be the CFO's voice calling the help desk
and the help desk you know will
recognize the authority and be fearful
and therefore you know sometimes make
the wrong decisions. So that's how uh
you know uh things get exploited. So my
recommendation back to what can we do
use MFA strong fishing resistant MFA
100% for 100% of your users.
Recommendation number two, do not just
obsess about authentication and strong
credentials.
Think about managing the identity
throughout its life cycle. Uh you know
and and and preventing against these
help desk type of attacks by uh finding
other identity security solutions that
uh protect identities even during these
types of like credential what we call
the joiner mover lever process. A new
employee joined, an employee called the
help desk, they got promoted, they're
leaving the organization. We need to pay
attention to managing those events in
the life cycle of an identity to assure
security in today's digital world. I
want to just tell everybody that you can
ask your questions.
when else will you have the chance to
ask the CEO of RSA security pretty much
whatever you want. So take advantage of
it folks. So let's jump over to Twitter
to X and Arcelon Khan is a regular
listener and he says this I think this
is related to what you were just
speaking about Roi. He says as a
consumer we share our identity
information credentials multiple times
to various IT systems the library
grocery stores banks and so on. We are
only as safe as the least safest system
and these are not in our control. So
what can what can we what should we do?
Any information that is potentially
identifying
you as an individual,
we need to uh share it on a need to-
know basis. We have been as individuals
especially as professionals in a
workforce setting, we have been perhaps
been too lax in terms of sharing our
information. uh because you know as you
said you know there is a legit reason
many a times for actually you know banks
or uh or or libraries or others to kind
of you know get get access to that
information. I think we need to pay
attention to what is that organization
or individual doing with the information
you're providing are they storing that
in a in a safe way. So uh the the the
sec you know when we share uh let's say
our information with a bank our mother's
maid name our uh you know date of birth
etc. We need to pay attention to the
cyber security posture of that bank
their data privacy statements that we
often you know kind of glance very
quickly and and agree to in in in sort
of agreements that we sign etc. I think
we need to pay attention to are they
doing the right things to keep your
information as private as it needs to be
to assure security in today's
environment. So a share on a need to-
know basis b pay attention to what the
organization that you provided the
information to is doing to protect your
information and how are they how good of
a job are they doing handling that
information. So those are two two
recommendation and I have a third which
is look if you are an IT professional
do not rely simply on an
informationbased
identity system. This is the whole
concept behind multiffactor
authentication. Don't rely on one
factor. That's what literally
multiffactor means, right? Do not rely
on the knowledgebased proofs of who you
are. your date of birth, your address,
etc., etc., ask for your, you know, ask
for other things like are you in
possession of the phone that is supposed
to be yours? Can we send
a FML password or code that you can
provide us? Uh, you know, biometrics
uh in terms of like uh scanning your you
know, face ID or or things like that.
So, always as an IT professional, you
have to use multitude of factors to
assure identity. do not rely on just
knowledge based information. Those are
three things that we can do to harden
our environments despite the need to
share information like like you asked.
So great question. Thank you for that.
>> Let's jump to a question from uh Pretine
Orion on LinkedIn who's asking about
CISO roles and she says this CISO roles
are among the most in demand globally.
Does this reflect a shift in how
organizations prioritize identity and AI
risk at the executive level and will
CISO demand rise further? What I will
say is the stature of the Cecil like you
said
uh is elevated now in today's um today's
world of AI powered threats and the
reason is um
cyber risk
um is now one of the top risks in the
what is called the risk register for
most organizations.
uh you know most public companies but
also um a lot of private companies
uh have a practice around risk
management
uh which is to make sure that the
organization can deal with the risks
that it faces and has uh sufficient
mitigation for those risks.
Cyber risk is now a very very prominent
part of that risk register and therefore
the SISO's stature in terms of advising
the board and the management teams on
cyber risk and its implications as well
as the mitigating controls that the SISO
is recommending is one of the most
consequential business decisions that a
private or a public uh company today
needs to make. So what I would say is
there is uh the there is a huge demand
for these strategic sysos that can
translate the technology of cyber
security to the business uh implications
of cyber security for the board and
management teams to act upon. So I I
think that uh you know that we are we
are going to find uh find sysos
um you know finding uh even more and
more uh stature in organizations a a
larger voice a more prominent voice uh a
and what I would say is that um you know
even at the board level you'll see a lot
of demand for cyber security expertise
because not only do you need a strategic
SISO, you need a board and a management
team that can understand what the SISO
is telling them. So, you need a a level
of expertise in order to govern uh the
cyber risk that most organizations face
uh in today's climate.
>> So, should the CISO be a technologist
or a business person? We are entering
the era of sysos that maybe have a
strong business background
with enough technology
uh sort of capability to drive teams
that might be operational and technology
oriented and therefore I would frankly
ask for a syso to be more sort of you
know 5149 you know more business than
technology in today's climate because
cyber security is now a squarely a
business problem more so than it is a
technology problem. Right? It's social
engineering. It's in the world of AI,
right? So, so, so thinking about uh
robust risk management uh approach to
cyber is uh is consequential to the
efficacy of a SISO.
>> What kind of communication skills a SISO
has and when they communicate? And the
reason I asked this is not too long ago
I approached two CISOs, one each from
two of the largest, most well-known
brands in the US independently.
And CISO number one said she wants to do
it. And then I started saying, well,
it's live and we take questions. And
she's like, no, no, no. I can't can't do
that. CISO number two said in my role
and I I've known CISO number two for a
long time. In my role, no way. So,
what's the job of the CISO in terms of
communication? And is it too scary for a
CISO to join something like this that's
live that we take questions?
>> CISOs have a dual role as does every
cyber security professional.
If you think about cyber security as a
business area, it's unique. In other
business areas, when we talk about
competition, you're often thinking about
other vendors that might offer a similar
solution that is competing for the love
of the customer with you. In cyber
security, when we say competition,
it's the threat actor on the other side.
So, the SISO has a dual role. One is to
defeat the competition on the other side
and and and make sure you know your
security posture is robust that you have
all the uh you know the right technology
and the processes to make sure your
cyber security is is assured.
But in addition the syso has another
role. The threat actors are
collaborating. They are sharing
information. They're sharing malware.
they're sharing uh ransomware tools that
are that they're using. We on the good
side need to do the same thing. We need
to do a better job of collaborating on
the good side. So if one syso in the
financial services industry is noting
that a certain type of malware
is is u is prevalent or is trying to you
know get access to their environment.
that information sharing that
information with other companies and
other peer SISOs and other cyber
professionals is highly highly valuable.
So my point is that I think there is a
certain level of transparency that the
SISO um needs to have with peers and we
need to lift all boats not just protect
our respective organizations but share
our knowledge with peers and peer
organizations so we can lift all boats
and defeat the threat actor on the other
side because that's who we are really
competing with in cyber not not other
peer companies. Arcelon Khan comes back
on Twitter and he says, "Our identity is
spread across so many different systems
and
companies. There's not just one single
place. It's the entire ecosystem of as
we were talking earlier pretty much
everybody that we do business with.
But most companies are not transparent
in how they deal with consumer data. In
fact, consumers have no clue until after
a data breach happens. And I'll just add
and sometimes a long time after that
data breach has happened.
>> It is getting better. And the reason
it's getting better is that the
regulator is stepping in, right? The
regulator is mandating responsible
disclosures that if you get breached
that as a public company for example
especially public companies there is
real teeth in in in in some of these
regulations in terms of responsible
disclosure that you must any material
breach or cyber incident you must report
right and and there thereby protect your
consumers and customers before their um
you know information gets compromised
perhaps. So the regulators stepping in,
things are getting better. In addition,
there is, you know, you know, it started
with GDPR in EU and then CCPA here in uh
California and there's more regulations
around data privacy as well. So yes,
there is it still remains a challenge
more broadly, but it is it is
dramatically better than what it used to
be. And again, I go back to the same
recommendation.
Let's not solely rely on the privacy and
the successful privacy of the
information we've shared because despite
best conduct on part of organizations
that have that information, the bad guys
can still get in. We must reconcile with
the reality that the bad guys will
always find a way to get in because
sometimes they're actually insiders.
Sometimes they're actually inside the
company. It's not somebody bad on the
outside that's trying to get in. It's
just somebody on the inside. It's an
inside a threat issue. Therefore, do not
rely on the the privacy of your
information as the only mechanism that
you're going to uh uh use for cyber
security. So that's that's sort of my my
headline summary uh on that question.
>> Sounds kind of hopeless.
[Laughter]
Let let me let me let me swivel then to
a more optimistic uh picture. Uh Michael
and and and all the all the audience.
Look the way to approach this problem is
framing our goal properly. Okay. And I
I've often use a medical analogy to talk
about the goal is you know if you think
about medicine you can frame the goal in
terms of like we're going to eradicate
disease. That could be one goal or you
could say the goal is actually wellness
and health despite the existence of
disease. So in cyber we need to take a
similar approach. It's not about making
sure that uh you know cyber incidents
don't happen because they will. It's
about resilience. I think we ought to
actually redefine our industry not as a
cyber security industry to but to be a
cyber resilience industry because the
goal is digital wellness. It's not to
make sure the threat actors are kept at
bay, but the fact that even if they get
in,
there is limited risk or damage to the
business that they can perpetrate.
That's the goal. It's wellness despite
the existence of the threat actor. And
if you frame the problem like that, it's
not a hopeless situation at all. In
fact, it's it's it's very tenable. And
you approach cyber security as a risk
problem. And I would love to talk about
sort of you know the the the you know
how CEOs and boards ought to pay
attention to cyber cyber as a risk
problem right it's about reducing risk
it's not about eradicating it because
that's untenable goal right and and and
and that's that's the hopeful uh
narrative for cyber uh that it is
absolutely possible and absolutely
attainable to have cyber health and
digital health despite all these threat
actors especially in a world of AI. I
think AI will be a massive massive force
that will help the good good actors uh
keep up with the threat actors. So I'm
I'm actually an optimist as it pertains
to the cyber u you know cyber landscape
if you will. Let's take very quickly uh
Kathleen Mitchell comes back with
another really good question and then we
need to talk about AI and we need to
talk about uh these board issues both
very very important. Kathleen says, "For
smaller and midsized businesses, how can
leaders move beyond just meeting
compliance requirements to make cyber
security a real competitive advantage,
one that they'll prioritize and invest
in?"
>> The reality is traditionally smaller
organizations have struggled to actually
um make headway with cyber security. The
reason being they simply don't have the
technical expertise or the teams to
actually deploy solutions.
Having said that, I think there is um uh
you know there is uh
uh a couple of trends in the industry
that are really helpful to smaller
organizations which is managed service
providers. So you actually now have uh
solution providers that are uh uh you
know that are providing full end-to-end
service in terms of helping smaller
organizations that don't have the human
capital to manage cyber to do it on
their behalf and do it treat it as a
business problem. The second thing is
the advent of AI will uh will I think
hopefully foster the creation of more
autonomous cyber solutions where you
don't need as many humans with hands on
the wheel to drive the cyber security uh
truck if you will right so so the the
the promise of AI as I alluded to
earlier we've always suffered on the
good side of the fight with the lack of
cyber talent we don't have even enough
good humans to fight the good fight and
the bad guys only need to be right once.
We need to be right all the time.
With AI, we can now
wield these agentic digital workers on
our behalf, on our side to tip the
balance in our favor so that we can do
the things that we never could do
because we didn't have enough good
humans on our side. You can automate
that, right? That's a massive massive
tailwind for us on the uh in the cyber
security world that will help especially
smaller organizations
and u and and and I think um you know I
I you know the other thing is I want to
commend some of the organizations
um you know here in the here in the US
like CISA uh critical infrastructure
security agency. So the government has
done a great job of elevating the
knowledge, the knowhow and the
sensitivity to cyber security for
smaller organizations. They have recipe
books. They have great resources on sit
cisar.gov evolve that smaller
organizations can uh peruse and and and
consume to get smarter on the issues
around cyber security as well as tools
and techniques and prioritize
recommendations on what they can do to
protect themselves. So, so I think it's
an emerging uh you know it's a um it's a
world that is getting much better in
terms of cyber for smaller organizations
than it used to be let's say 5 years ago
>> for smaller companies it's tough you
know CXO talk we're a small company and
because of CXO talk we're attacked all
the time I'm mean I get attacks fishing
like very targeted and our
infrastructure was attacked and I was at
a loss like what to do and and actually
I asked a couple of former CXO talk
guests who are like you know top
security experts and we had a call and
they gave me advice and we were able to
ultimately sort it out some you know a a
AWS configuration issues and a bunch of
other stuff but it's tough if you're a
small company
>> it is tough and I would say this these
social engineering type of attacks are
especially tough fishing as you alluded
to, Michael, they are like, you know,
relentless attacks and now more
sophisticated because they can
impersonate, you know, your loved ones
or or people in your company, etc. So, I
have a couple of recommendations in
terms of like what can you do to protect
yourself against fishing attacks, right,
for um you know, so I I I have three
macro recommendations.
number one
multi- fishing resistant multiffactor
authentication
deployed for all users. I think that can
help. So anytime uh you know that that
is a baseline table stakes
recommendation. Number two is we have to
realize that these threat actors
try to manipulate you emotionally and
create a sense of urgency. Act now you
must do this now otherwise bad things
are going to happen. So anytime you
sense any communication that tries to
ignite the sense of urgency, treat it
with a lot of suspicion.
That's recommendation number two.
Recommendation number three is that
realize that deep fakes is the era of
defakes and what is called synthetic
media. You might get a video of your son
or daughter in harm's way that looks
completely real asking for help and you
might kind of act on it.
Do not act on u on uh on media alone,
voice, video, things that uh things that
might appear very real
with your loved ones or within your
company. Have a out ofband mechanism to
assure identity. So if you have your
children as an example or a family, you
might have a family password that if I
ever call you asking for help if I have
a flat tire, if your daughter says,
"Hey, if I, you know, I have a flat
tire, I need 50 bucks to, you know, pay
the towing company." Do not send that 50
bucks right away. Ask your daughter for
the family password. So verify the other
person outside of you know what might be
very realistic voice or synthetic media
that you know might sound or look
exactly like the the individual that you
trust. So do not establish trust based
on uh you know media because they are
they can be compromised in the world of
AI. Have an outbound channel to assure.
So those are three quick recommendations
and what you can do uh to I guess avoid
getting fished if you will. And Michael
you know you I'm sure you're a big
target. I am. I'm famous in my company
for sending text messages asking for
gift cards as a CEO. So, they get CEO
text messages all the time. My my
colleagues in the company that asking
for gift cards.
>> We have an AI question from Elizabeth
Shaw on Twitter and I'm glad she is
jumping in because we need to talk about
AI and she says AI brings its own
issues. There's AI versus AI. AI run a
muk. How should companies consider AI
for cyber security and place their trust
in it? So the role of AI in all of this,
>> there are three dimensions to AI. One is
AI as a
sword,
right? It's a it's the attacker's tool.
So they're the threat actors are going
to use AI to attack at scale or
hyperpersonal personalize, impersonate,
bypass traditional defenses, create
malware because you can do wipe coding.
So even tech technically inferior threat
actors can now code because AI can code
on their behalf. So it's it's a it's a
sword. Second thing is it's a shield on
the threat actor side which is we have
not had enough humans to look at all the
incidents all the threats that are
playing out we can do that you know
we'll have digital workers software
robots that can do that job for us we
can monitor synthetic media to look for
signs for synthetic media right is this
deep fake right there are technologies
that can do that AI technologies we can
u you know monitor patterns for what is
normal versus what is normal. Do
predictive risk modeling do incident
simulation and playbooks automation
because of AI. So that's the shield
dimension. So sword dimensions, shield
dimension, but there is a third
dimension which is what you were
touching on Elizabeth which is AI as a
it's an act it's an part of the attack
surface
right the threat actor might actually
compromise the AI that you're using uh
by poisoning AI or or uh doing you know
you know doing nefarious prompt
engineering
uh or u you know by actually ensuring
ing that um you know that you're um
denial of service attack. So if AI is in
a decision loop, let's say it's it's um
you know approving uh I don't know loan
applications for a bank, you know, they
can actually u you know bombard and do a
denial of service type attack to to
confuse the AI, right? And and and cause
that. So AI can be attacked and
therefore we as cyber professionals
need to do two things. One is we have to
embrace AI as a shield because we know
that the bad guys are using it as a
sword. So we better pick it up, get more
educated and proficient on using AI
otherwise we'll be left behind. We
cannot wait. But then also adopt AI
responsibly, right? And and uh and don't
trust AI blindly. uh you have to have AI
inside of guard rails meaning
u you know any agentic AI you deploy in
your environment make sure it has the
guardrails of human defined workflows a
human in the loop
second second is you must have nonhuman
identity solutions to make sure just
like you're protecting human identities
and making sure the human is has the
privilege to act on your digital estate
Don't allow AI agents to work
autonomously without verifying their
identity. So you have to have nonhuman
identity solutions that assure the
identity of these AI agents that are
acting on your behalf. So that's that's
what I would say in terms of AI. Those
are kind of the three dimensions that we
must pay attention to. It is not just
you know as a proverbly a double-edged
sword. There is a you know it's also
it's also um it's also the thing that is
actually being attacked by the sword.
>> Can you talk a little about the
economics of AI or how does AI affect
the economics of cyber attacks?
>> Cyber security is an economic problem.
At the end of the day the cyber threat
actor is economically motivated and
constrained just like we are on this
side. They don't have infinite budgets.
they don't have infinite resources
either. So the economics of
AI based you know or cyber in the in the
era of AI is that the cost of
perpetrating a cyber attack is going to
go remarkably lower right so we have to
recognize that reality in the past we
would say oh you know what it takes a
lot of cost lot of expense to actually
exploit
uh you know zero day attacks because it
requires a lot of technical expertise
and hiring technical expert experts is
is costly and so forth. So we we we
could make those assumptions. Now we
cannot do that because you know there is
AI on the other side and the cost of
launching an attack is a lot lower. So
we cannot use economics or cost as a
deterrent. What we have to do is we have
to be smart about our crown jewels. What
the what the threat actor doesn't know
is once they get in, they're trying to
get to our crown jewels. We know where
our crown jewels are. They don't. So if
we pay if you know, so don't have a
peanut butter cyber security strategy of
protecting everything. have a
differentiated strategy where you have a
robust enterprise riskmanagement
framework where you have what are the
likelihood of cyber threats happening.
What is the impact of those cyber
threats have have this kind of matrix
and the cyber threats that have a high
likelihood of happening and have a high
impact are the ones you look to mitigate
and address, right? and have this
differentiated economical strategy of
not spending your money, if you will, to
cover all bases, but to cover the right
bases and spend smartly because the e
the economics as a deterrent strategy no
longer holds true in the in the AI era.
>> Let's talk about board issues.
What is the role of a board versus the
executive management when it comes to
dealing with these cyber security
issues?
>> Let me frame it at a high level first. I
think the board sets the what and the
why, which is what is the acceptable
level of risk, what are the strategic
priorities and how much are we going to
fund to mitigate those risks.
The management teams own the how, the
tools, the processes and the execution
to actually achieve those outcomes. So
board, the what and the why, management,
the how. And the way the way this needs
to play out is,
you know, and I'm on the risk committee
of of of a few uh public board and I've
I've I've held those roles. I've I've
kind of advised them on cyber security
as a part of that enterprise risk
register. Like I said, the erm strategy
for an organization is you take your
risks and you place them on this matrix
of likelihood and the and the magnitude
of impact. You start with what is called
inherent risk which is if you do nothing
what is the level of risk and you create
this matrix. Then you say I am going to
apply some controls. I'm going to uh
adopt MFA for everybody. I'm going to do
patch management and I'm going to use u
uh you know a a zero trust micro
segmentation tool that will uh protect
um my uh my users from thread actors.
Those are mitigating controls and then
what you're left with is what is called
residual risk. Right? So inherent risk
apply mitigating controls remaining risk
is residual risk and then the board has
to make a call on what is that
acceptable level of risk what's your
risk appetite what's your risk tolerance
if you have a if you're a software
vendor that provides a SAS solution how
much downtime can you accept right and
maybe the downtime that you can accept
is 4 hours in which case you're spending
you know instead of making sure you're
available all the time what you want to
make sure is that if you do get
compromised, you can bring things back
up in 4 hours. The idea of resilience.
So, it's this fine balance between
managing risk, deciding what to avoid,
what to reduce,
sometimes you transfer risk by buying
cyber insurance and what risk are you
going to accept. That's a board level
topic, right? That's what the risk
committee of a board needs to think
about, needs to uh planfully execute on
and then and then um uh kind of task the
management team to say this is what we
want in terms of u you know the
mitigating controls and this is the
acceptable level of risk. you now go
forth and execute on deploying the tools
and the processes to make sure we remain
within that kind of realm of risk that
is acceptable to us as a company. That's
kind of the division of labor if you
will between the board and the
management that you were touching on.
Michael,
>> you just described a very sensible uh
and general risk management framework
that's applicable of course in many
kinds of circumstances. However, when it
comes to cyber security, there's also
this technology element. And so, how can
board members make intelligent decisions
about that residual risk when they don't
necessarily understand the underlying
technology that's driving the whole
thing?
>> I don't think the board needs to be
steeped in the technology of cyber. They
need to be uh steeped in the risk of
cyber. They need to understand that a
ransomware attack you know what's a
typical ransomware attack and you know
what's the what's you know for my ilk of
company my size of company what are the
kind of you know if if if something like
that were to happen in our environment
do we have the playbooks to kind of
restore our services and and what's the
type of ransom demand we might hear etc.
So they have to think about the business
aspect of cyber not the technical aspect
of cyber but they do need to be aware of
the types of technical threats that
exist but they don't need to worry about
the how.
>> In one minute can you briefly describe
the life cycle of a ransomware attack I
pointed out because the consequences can
be so d companies have gone out of
business because of this. Ransomware is
a very nefarious type of attack because
it's changed the game on us, right? It
in the past the bad guys would get in,
they would steal stuff and take it out,
data,
you know, uh, information, things of
that nature. In this case, what they do
is they get in, they disrupt your
environment and pause, you know, they
might encrypt your data. They don't
steal it. It's still there, but it's now
encrypted, so you can't access it. Or
they might u you know kind of disrupt
your operations as in you can't run your
trains because they have kind of you
know the you know they've kind of locked
the lock the go button for the train
and then demand ransom. So the the the
the life cycle you what you need to
think about from a um ransomware thing
is what can you do before during and
after a ransomware attack. The board
needs to think about that framework and
there are things you can do in terms of
the before which is uh you know the the
the policy the the the you know the BIS
BC business continity plan that says
even if they get in and if they let's
say encrypt the data how quickly can we
restore it from a backup copy is
everything protected so before invest in
identity backups segmentation response
planning during you have to focus on
containing fast communic communicating
clearly, restoring quickly and then
after a ransomware attack to learn,
adapt and harden. That's sort of the
framework that you should be thinking
about. Uh if you do happen to, you know,
face a ransomware situation, but do not
pay ransom right off the bat because it
only encourages the bad guys to do more.
think about um you know unless unless
your hands are tied and you you know the
the the damage is so um consequential
and and and and that that you have to
that's should be a matter of last
resort.
>> Where is RSA security investing over the
next 12 to 18 months?
>> We are focused on what we call the three
Ps of of cyber in FY in in 2025. We
think that that's the most important
things to focus on for organization. The
three Ps of identity security,
passwordless,
posture management, and platformization.
Passwords, we've talked about the cost,
complexity, and the vulnerability aspect
of passwords. Passwords need to die. You
need to adopt to a passwordless world to
um uh and and all passwordless solutions
aren't created equal. So you know uh
embrace enterprise ready passwordless
solution because passwords are not um
you know not the right tool for an AI
powered cyber threat landscape. Number
two posture management. Like I said
that's how the bad guys are getting in.
So best way to improve your security
posture is to improve your identity
security posture. Do the users have more
entitlement than they do? Do you have
orphaned accounts that people have left
the company? there's still there's still
accounts. So, cleaning up the digital
debris and the sort of you know
tightening up your identity posture uh
using AI is investment area number two
and platformization. The bad guys are
exploiting the the gaps between our
tools. Best of breed strategy in
identity isn't working anymore. you need
solutions that have shared context that
can defeat uh you know this modern
threat attacks that the that the you
know the bad bad guys are throwing at
us. So those are the three areas of
focus for RSA and um and that's how we
believe we can make a difference in
terms of keeping the most secure
companies around the world secure. Okay,
Rohit Guy, CEO of RSA Security, thank
you so much for taking your time to be
with us. This was great.
>> Thank you, Michael.
>> Everybody, thank you for watching.
Before you go,
subscribe to the CXO Talk newsletter. Go
to cxot talk.com, check it out, read
tremendous, we have tremendous shows
that are coming up, really just
extraordinary shows. So, subscribe to
our newsletter, join in, ask your
questions, and we'll see you again next
time. Take care, everybody.
[Music]