YouSaid · the spoken record

John McCumber

lines on the record
27
first
2021-11-10
most recent
2021-11-10
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. When mistakes do happen, they can't be immediately exploited by attackers. So I think the race continues. The requirement for defense in depth continues. The management of complexity, the management of supply chain risk and actually making sure that everyone is operating at a really high standard. It is essential. Otherwise, a weakness in one area can actually then have ripples that impact other organizations that thought they were on a firmer footing. But I do subscribe that this is something we're getting better at. And, you know, it's not the sort of thing that you ever can declare you've won, but we're getting better at it. And I think we and the governments of the world need to help support businesses and the supply chain generally to get better at it together so that there aren't weaker links that allow attackers in.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  2. In terms of future state, I mean, one of the things that I don't actually subscribe to we're losing the battle, as it were, because yes, we're seeing more instances, we're seeing more mega breaches and greater impact, but that's actually from a much more secure baseline than we had a few years ago, certainly a few decades ago. And actual fact, it's really an example that the prevalence of attackers and attempted data breaches and the development of business models around that has driven up the amount of people trying to attack and trying to find vulnerabilities. But the actual number of the quality of software is getting better from a security point of view and the quality of infrastructure is getting better. To Matt's point with regards to the pristine cloud environment, giving you a fresh baseline, a fresh capability. Now, the key thing, of course, is to make sure that

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  3. Yeah, I think I definitely agree with all that. I think we're all going to be employed for a long time in this space. But honestly, I think vigilance is key. So I do think being attacked and target is going to continue to be a way of life, right? We've talked about there is more connectedness, right? There's further digitization of everything, money, et cetera. So it makes for a larger tax service and targeted opportunity for bad actors. We touched on things like automation. We're looking at things like capabilities that can basically automate a SOC analyst, all the decisioning that a SOC analyst might go through when they see a case from a particular sensor. There's companies that have a vision to try and automate that. So I think capabilities like that will be key for us. It'll free up our analysts to focus on more high order things like some of the machine learning and the data analysis that Matt referenced. And I'm also optimistic that things like the Biden administration, executive orders, but also the committed investment from various companies and government entities to improve cybersecurity. We'll keep raising that baseline.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  4. Some of these new technologies like homomorphic encryption or quantum key distribution. These are technologies geared specifically to meet that threat. I think also one thing I would say moving to the cloud, I mean, a lot of companies have a lot of legacy technologies or tech debt. So moving to the cloud in more of a cyber pristine environment, I think is also a great leap. And so I think we're going to see a very technology driven defense, a very data-driven defense philosophy over the next five, ten years.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  5. Yeah, I think first I'd have to say it has to evolve. You know, just not too long ago, a bad actor group called the Shadow Brokers stole quite a bit of nation-state level tools. So all that sophisticated tooling is now in the marketplace. They sold it on the dark web. So clearly, I think the way we defend has to change. I think some of the emerging technologies like deep learning, artificial intelligence, machine learning, I think think about a malicious software, a piece of malicious software that has AI built into it that is built to evade defenders. I mean, that's pretty scary stuff. Obviously, the new emerging technologies like blockchain and quantum computing really will impact the way firms think about cyber defense. So I think leveraging technology is super important. And it's a bit of a cat and mouse game between the bad folks and the good folks. And I think we've got to be able to use these technologies to defend before the bad folks use them to attack. And I think there's been a lot of progress in that space.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  6. As mentioned earlier, fishing is typically the front door to the beginnings of a cyberbreach. And so I think we use that to great effect. And I think other firms in the sector have used that to great effect.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  7. Think awareness now is much different than it was maybe five years ago. I think the media has played a big role in that. And I think every one of us has gotten that email or that letter that says your information has been breached. And I think makes our job a lot easier as cyber practitioners around making sure that folks are aware of what to do and what not to do. I do think, however, that keeping the topic in the forefront is really important. And that starts at the board with senior leadership and of course all of our employees. I think one of the best sort of methods that I've seen is really things like phishing testing, right? So obviously computer-based training, these aren't good October cyber month, having the discussions around cyber awareness. I think those are good. But I think testing provides somewhat of a unique learning moment, right? So where the firm will send out a phishing test and when you click on it, you get a pop-up that says, hey, this was a phishing email, if this was a true phishing email, then a bad thing could have happened. So I think that's one of the most effective that I...

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  8. The other aspect of this is, of course, the rise of cybercrime makes consumers more reluctant to hand over their data. Obviously, we're living this increasingly digitized world, and there's a lot of concerns around that. What are companies doing to protect their data while assuaging consumers' concerns around these issues?

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  9. Stop running a vulnerability scanner that's looking to see if there is any vulnerable systems or libraries within that environment and then going after those and patching those. You want to be running both of those things in order to make sure that you've got that defense in depth with regards to your assurance activities. And so we really apply that sort of mindset across the design build and operate lifecycle of our products, make sure that we have more than one mechanism in place to stop any given type of attack or make sure any given activity is working as we'd expect.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  10. In depth aspect. One of the things now is that we've now effectively globalized the tax. So many attackers all over the world that can try and attack and compromise systems. And that means that if you have a vulnerability, it's not a question of, you know, if it will be exploited sooner or later, someone is going to come across that and they're going to try and exploit it. And that makes it vitally important to have defense in depth. And that's not just defence in depth in one aspect. That's defense in depth with regards to your processes and practices as well as with regards to your controls and also your assurance activities. The example Wes gave around the importance of patching and maintenance. Well, you can do that by rebuild and repaves environments where you just sort of continually replacing the infrastructure with fresh up-to-date infrastructure to make sure that it stays well maintained. And that's one way of keeping on top of patches. But equally you don't

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  11. Certainly. So, I mean, it obviously mirrors the way we've seen threats develop more generally, but as the famous bank proper once said when asked by Rob Banks, it's because that's where the money is. And often, you know, these sorts of cyber crimes are financially motivated. So the banks are clearly a target. And I think that's challenging because we can't put huge walls and moats and obstructions around people's interactions with our sites and with our digital services. Or it would impede the user experience too much and the relationship with the customers. So what we need to do is we need to find a way of balancing that user experience with the customer with maintaining the security posture to prevent fraud, prevent account takeovers. And that's always a bit of a balancing act to just get that right and make sure that we aren't making it too difficult for our actual customers to access their accounts by making it difficult for attackers to. And the other thing is, you know, that's been mentioned previously is around that.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  12. Andy, let's bring you into the conversation. As I said, you're the chief information security officer for the firm's consumer banking business compared to other industries that consumer and retail sectors seem more vulnerable to cyber attacks due to the nature of its online traffic and the design, of course, of its e-commerce websites. Can you talk about how cyber attacks and security efforts in the consumer space have evolved?

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  13. Crisis. On the partnership side, so there's the ARC, the analysis and resilience center. There's lots and lots of engagement with US government on the risk and intel side with members of the ARC, and then also the FSI SAC, so the Financial Services Info Sharing and Analysis Center. They have some subgroups that also focus on improving ways to collaborate with federal partners and also just help identify other ways to engage with the government.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  14. Yeah, for sure. I think they're definitely always opportunities to kind of increase this collaboration in the space. I think they can be done in a couple ways, either direct engagement also via partnerships. So some of the direct engagement, you can organizations can become members of the cyber information sharing collaboration program. So the CISCP. And it's a part of DHS CISA. So the cybersecurity infrastructure and security agency. And when you engage there, you're able to share, receive information about cyber threats and also just attend just various technical exchanges. There's also a routine just engagement with the FBI through an organization called the NCFTA, so the National Cyber Forensics Training Alliance. That includes one daily information sharing, but also weekly threat calls. And I would also encourage organizations just to think about direct engagement with the FBI. There are just really good relationships to form well ahead of the time that you might be dealing with a

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  15. You get into legislation, a couple of them that we are watching and they're making their way through Congress is the Cyber Incident Reporting Act and the Ransomware Disclosure Act. And I think these are worth watching for us and the sector. I think the biggest area that we're going to have to come to an agreement on between public and private sector is what constitutes a cyber incident, right? Because a lot of the basis of these bills are quick, very quick, almost real-time reporting of incidents, but we have to define what that means. within the bills that use terminology like substantial cyber incident or substantial attempt what does that mean i think the focus again on incident reporting i think that's a good thing but we just need to make sure we know what we're signing up for and that it's absolutely crystal clear what our responsibilities are

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  16. I think the other thing that's come out in ransomware is really just having a strong handle on your asset inventory. Several of the victims of ransomware, parts of the network that were impacted, they didn't have a good understanding that this was connected to their network or this was on their network. So I think those are some key things that were lessons. The last piece I would suggest is organizations should consider participating in a bug bounty program. See, these bug bounty programs basically incentivize software researchers or security researchers to report and disclose vulnerabilities in a responsible way on things that are on your internet facing properties. So very, very talented researchers focused specifically on certain software packages, and then they can let you know that you might have a vulnerability. And I think that also helps in the face of these kind of ransomware attacks.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  17. Profile attacks, ransomware attacks certainly that occurred against colonial pipeline. We've also heard most recently about Kaseya. They underscore the importance of what we talk about a lot as just having this sort of layered approach to cybersecurity where this defense in depth approach to cybersecurity. And in some ways what that means is just employing some good practices around hygiene. So we've got practices called

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  18. I mean, clearly, there's been some very high profile ransomware attacks, colonial pipeline hack, there was the solar winds attack, just to name a couple. So are there any lessons learned from some of those examples that you've been able to apply or in general people in the space have been able to apply

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  19. Can deal with dozens, right? Sometimes there's dozens, and phishing attacks, a campaign could definitely come in in the hundreds, sometimes in thousands, but we'll see between someone trying to do some sort of business email compromise attack to someone doing something with our brand.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  20. Touched on this a little bit around fishing is we're starting to see an uptick in fishing campaigns and just the volumes of other security events. So it's led us to think about investing significantly in automation to help us and other vendor solutions just to help us manage and kind of triage these events. Matt touched on some that's really, really important around just being Intel-led. So the CERT team is Intel-led is very key and having some of those trusted sharing relationships with other organizations, it helps you kind of build that margin, right? A margin of safety to get ahead of various threats that might be a risk to the sector. So those are several ways that we've evolved. I'd say the last one is we focused a lot more on drilling and preparedness, right? And I think that's extraordinarily important for us and not just tabletop exercise sitting around the table talking about, but actually validating that your capabilities work as you expect. So if you think you have a capability to isolate hosts, let's validate that. If you think you have

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  21. Yeah, for sure. And I think it's clear there's been so many different types of attacks to consider, right? That so many different dimensions, whether it be our cloud assets, containers, on-premises assets, we're now having to think about brand, reputation, website attacks, supply chain attacks where you're seeing folks try to introduce malicious software libraries into your code, business email compromised now where folks are trying to manipulate you into sending funds to an unintended destination. DDoS attacks regularly make the news, trying to inhibit sites availability, and then ransomware. I think that's probably very topical as well. So I think the combination of all these things has kind of led us to converge on a virtual fusion center, sort of multidisciplinary approach, really to make sure that the right stakeholders are brought in to manage the events and the incidents and not just engineering, but legal compliance, the risk division, privacy, et cetera. I think the other thing that we've started to see, and I think

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  22. Is that typically folks that are working from home or maybe they're working Into Starbucks, those networks tend to be less secure, right? That's number one. Number Think the devices that folks are using, and I'm talking broad.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  23. In a sense, we were throwing a curveball, of course, with the pandemic and the hybrid work environment. employees constantly shifting positions did that change the cybersecurity landscape for security chiefs

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  24. In the right direction, I think more information sharing is necessary. I think now Sharing sort of threats, but we're now starting to share. Start Analytics. So, I think this is the future of cyber defense

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  25. Procedures, what we call TTPs have gotten quite sophisticated, they've become quite destructive, and no one company can defend the whole field. So we rely on our peers to share information and we rely on governments, whether it's the US, UK, et cetera, to provide us with threat intelligence and give us some help when necessary. And so. Think that's been the biggest change in terms of the cyber defense posture. I think it's that willingness to share. And there are a couple of forms within the financial services sector that are dedicated to the sector that I think are quite effective. Which is the Financial Services Information Sharing and Analysis Center Now it's just Which is the analysis and resilience center

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  26. Think it's changed considerably over the years. I remember just 10 years ago, I was working in the UK as a global CISO for a large financial institution, and we were called by the UK government down to 10 Downing Street to talk to Baroness Neville Jones, who was the newly appointed UK Cyber Czar. And the government had invited 10 or 12 of the top high street banks. We were there to specifically talk about the increasing threat of cyber and how the public and private sectors could work together and to meet that threat. And I remember being in 10 Downing Street around this big office, a big oak table, and the Baroness opens up saying, well, let's talk about the state of where we all are in the banking sector around cyber defense. And nobody wanted to talk. Nobody wanted to share information. We actually considered cyber defense as a competitive edge. And so it was one of the shortest meetings I've ever been in on the topic of cyber. When you fast forward now, information sharing is an absolute must, right? The cyber threat, now the tactics and tools.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT

  27. Matt, let's start with you. You have more than 30 years of experience in technology, operations, and really cybersecurity across Wall Street. Cyber attacks are increasingly getting more sophisticated and destructive. Start by setting the stage on how you've seen companies evolve their approach to cybersecurity.

    2021-11-10 · Goldman Sachs Exchanges · An Evolution in the Cybersecurity Landscape · IDENTIFIED FROM THE TRANSCRIPT