mnemonic security podcast

Risk Hunting

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:07

In this episode of the mnemonic security podcast, Robby is joined by Tony Fergusson, CISO EMEA at Zscaler. They start with a market update on Zero Trust and discuss the challenges relating to adoption that he has observed (ever heard of the Popcorn Theory?). 

Fergusson then introduces the concept of risk hunting – a proactive strategy to identify and mitigate risks before they escalate into breaches – and explains how it relates to threat hunting. He emphasizes the importance of least privilege, continuous evaluation, and what Zero Trust looks like for users and workloads.

Send us Fan Mail

Evolution of Zero Trust in Security

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

By now you've probably heard of the concept of threat hunting. Now, whether you feel that's relevant for your organization or not is one thing, but keeping the concept of threat hunting in memory, replace the word threat with risk. My brain at least led me to think of some GRC resource wearing a Patagonia vest, stressfully reading through all of your policies and procedures and trying to identify gaps. And apparently, I wasn't that far off. What I didn't immediately connect with the thought of risk hunting, however, was the concept of zero trust. What does zero trust look like for users and workloads? And what does it mean to hunt for risk relating to them? So stay tuned for that as I have a very well-suited guest to guide us through that conversation. But before that, I just wanted to take the opportunity to say thank you for tuning in to the mnemonic security podcast this year. After recording this intro, I will be taking a vacation from podcasts until 2025. But don't fret, I have plenty of episodes in the pipeline for next year. So happy holidays, everyone, and Merry Chrysler, as someone on the internet once said. Over to you now, Mr. Tony Fergusson . Welcome back to the podcast.

Tony Fergusson

Yeah, likewise

Robby Peralta

So uh I'll let you introduce yourself. Who's uh Tony Tony Fergusso n in 2024?

Tony Fergusson

Yeah, so um yeah, so I'm the uh the CISO in residence for Zscaler. And uh yeah, I I spend most of my days talking with uh other CISOs and other customers and really being that sort of trusted advisor and helping them along their zero trust journey.

Robby Peralta

I want to say you taught me what zero trust is, but I feel like that'd be really rude to you because I feel like I don't really understand it yet. Uh you have all these new terms like SASE and SSE, and I'm not sure if those are the same things. There's a lot to unpack in this uh zero trust journey.

Tony Fergusson

Yeah, it is. And uh, you know, sometimes when I look at the number of vendors out there and all these acronyms that Gartner loved to create, then I'm like, no wonder we're all a little bit sometimes confused on what is zero trust, what is SASE, what is SSE? Um yeah, so that's uh yeah, that's something I'm also spending a lot of time on trying to educate and make sure people understand what is zero trust.

Robby Peralta

Well, you're in the right spot, I would say. A little biased there. But hey, so uh we're gonna get around to zero trust. I want to know like what's the lay of the land look like for that space in uh in our point in time. Uh you also, last time we had a chat at the ICS conference in Denmark. You actually taught me the history of zero trust, which I thought was a fun story that which I didn't know about. So I think we should uh like the term zero trust. So if you don't remind repeating that, that'd be awesome.

Tony Fergusson

Yeah.

Robby Peralta

And you also touched upon something I've never really heard before. I'm not sure if it's something you made up, but it sounded really smart, and it was the concept of risk hunting.

Tony Fergusson

Yes.

Robby Peralta

So let's uh let's start with the the the history of the term zero trust, and then wiggle figure it out and we'll end on risk hunting. Yeah.

Tony Fergusson

So look, the actual term zero trust. So so so you might not be aware, but John Kindervack, he was a practitioner like I was, um, and worked on the very first firewall, right? The firewall, like the Pix Cisco firewall. And these firewalls, the way they were built and designed, um, they had like a trust model. So put it very simply, when you would take this uh firewall out of the box and you know, you'd plug in your RJ45 and plug it into your computer, and you would start getting it on the console, right? And you'd configure it. The first thing you really had to configure was, hey, um, this interface was outside the internet. So you would give it a name, outside, and you have another interface on the inside, which is your corporate network. You would say, hey, the name is inside. And then the next command you would actually do is you you would set a trust level. Yeah. Also known as like a security level, so a trust level. And what you would do is you would say, hey, the the inside interface that would be 100 trusted. The outside would be zero. Don't trust anyone on the big bad internet, right? And then if you had other interfaces, that would be somewhere between one and 99. So if you had a DMZ, that might be 50, right? And when you set up it in this way, the trust model on the firewall would say all traffic from 100 to zero is allowed by default. So all traffic is allowed from the trusted network inside the network towards the internet. All traffic from the internet towards the internal network is not allowed. So that's that's the the basic rules you would have as the firewall. And I I actually do remember when I started actually. Um now this is you know going back probably around 2008 when I started. I remember looking at the firewall configuration and going, why are we allowing everything outbound from our data center? Right? And you know what? The funny thing is I still see even this today. Companies actually say, Well, you know, it's just easier for me to have an outbound rule that says allow everything out. Yeah. Because everything in my data center is good. Right? And and you probably remember, but you remember the solar winds, right? That was on some infrastructure that was in the data center. For those people that had a zero trust model that said, hey, my SolarWind server can only access these resources on the internet for updates. Sure, you would have got the bad update, but that's it, right? It wouldn't have then communicated to these other areas. So yeah, those companies that have really adopted the zero trust mindset of saying the server only needs to communicate to these things on the internet and spend the time doing this, right? They were saved by some of these sorts of attacks, right? And that was a hard one, right? That was a very difficult one to stop. Hmm.

Robby Peralta

Okay, but the the the term zero trust comes from a Cisco Pix firewall from back in the 90s or something like that, basically.

Tony Fergusson

Yeah, because because what he what he asked was shouldn't all the interfaces be zero? Shouldn't we just configure the firewall with zero, zero, zero? That means no traffic is allowed in any direction. And then you would specifically have to put in policy, least privileged policy, to say this resource is access to this resource. So that was really the idea, and that's where the zero came from. Zero on the PEX firewall. So probably not many people know that, but it gives you a little bit of an idea of yeah, a little bit of the history and where where where it actually came from.

Robby Peralta

I always learn more when there's a story involved. That's why you're that's why you're here, Tony. But okay, but you said in uh 2016 you were at Man, right? Uh huge, I don't even know what to call them, and bus company, but they just make big machines company.

Tony Fergusson

Exactly.

Robby Peralta

Uh you said zero trust, yeah, manufacturer, yeah, that's a word for it. You said zero, I just ZTNA. What does that stand for again?

Tony Fergusson

Zero trust network access.

Robby Peralta

Yes. Was that your first encounter with zero trust as an idea or like

Tony Fergusson

so look, I uh as I said, like about five years prior to that, I had been introduced to the idea by John Kindervåg So I sort of knew of the concept and knew of the idea, and I thought it was a great idea, and I was trying to at least in places where I could. For example, the data center, I could apply zero trust principles on my outbound traffic from my data center. And I managed to do that, right? Um, and that's probably one of the first sort of things that I did, but it wasn't until you know that 2015 where where then I had some technology that was able to do very granular policies, you know, not just for workloads, but for users, right? I could apply it to my users, I could apply it to contractors, I could apply it to my OT environments. And then when I started to go down this, then I think that's where it really it sort of set in my head, okay, now I'm getting an understanding like how this can impact the security and the posture of the company.

Robby Peralta

If I should just stop real quick, like uh why do you why do you want to? I'm thinking of the use cases for why you want to block you know uh traffic from inside your walls outside, right? I'm thinking like call back to cobalt strike, or I'm thinking of you know stopping of data leakage. How many other use cases are there? I know it's a dumb question. I should probably know the answer to this, but

Tony Fergusson

so you know, it's sort of interesting, right? Because, you know, I actually always thought I had a plan. I I drew up a plan, like a 10-year roadmap of implementing zero trust. And I actually remember having like, you know, zero trust completed, right? Like, like it's done. But I just laugh at myself now at thinking that they would ever be done, right? Because the actual concept itself says you as a user, you should have access to maybe this application. But you can even take it further. You should have access to this application, but only this data set. Yeah. So how far do you want to go with that sort of lease privilege, right? And of course, the idea is like if you only have access to some systems and some data, then if you're breached, then of course that reduces the risk of uh what I could leak from your company. Yeah. So and one of the biggest uh problems we have today, and we still see it with many companies, is obviously VPN, right? Because what a VPN does is it just gives you complete network access. That means I have access to the entire network. I may not use all the applications in the network, but I still have access. And I suppose that was the fundamental change in 2015, where we s switched these around the other way. So think about it. A VPN gives you access, then I would connect to the application and say, Hey, it would say, Who are you? Authenticate. Who are you? And you would say who you were. But now we flipped the model and said, no, no, no. We are going to find out who you are first. We're gonna say, Who are you? What device are you on? I'm gonna check all the things I need to check first, and then and only then will I connect you to where you need to go. And that was a complete fundamental change from where we had been and giving network level access to then actually giving access to an application based on context, based on who you are, what device you're on.

Robby Peralta

Hmm. And I'm just thinking, uh, is that why people are never done with the zero trust journey? Because, you know, I've all of a sudden I moved to London and I work there and have access to different stuff. And so then I have to keep that process going. Or is there more than just the fact that people move around in a company that makes it so that the journey's never done?

Tony Fergusson

Yeah. I mean that, I mean, that is still a problem today, right? And there's a lot of technology out there trying to solve some of those problems that, you know, yeah, you and your role, you get access based on your role. But yeah, often what happens in companies, you move, and we don't revoke those accesses for the role you used to have, right? And probably you just get more and more access. But I suppose that's why, you know, NIST, NIST did a pretty good paper, 80207, if you want to look it up. It's called the NIST Zero Trust Architecture. And actually, in that paper, there's some really good references of you know what you need to do architecturally to be able to build a zero trust environment. And they talk about continuous evaluation. So it's not okay just saying, hey, Robbie, you have access to the application and it's all good, and then leave it like that, right? We need to continuously evaluate has your security posture changed? Has something changed that I may need to revoke your act your access? Yeah. And if you think about the very first implementations of zero trust in the network was network access control, right? I mean, this came, you know, yeah, many, many years ago. And there's still companies that are still trying to go this way, but network access control is fundamentally I do some checks, you are then allowed onto the network and away you go. Right? We don't continuously validate who you are and validate your device and validate everything every time you connect to an application. No, no, we just inherently trust you always until you come in maybe the next day, right? So that is not, yeah. So that's why we are always continuing to continuing to improve and try to get more granular, get more context, because context matters. Um, if you don't have good context, how do I know what policy to enforce? Hmm.

Robby Peralta

I'll say it like this. So if network access is getting into the, I don't want to use the castle because we're going away from the castle with the there's no more castle remote with zero trust. I know that, but just just an analogy. Uh listeners can think of something else themselves, but like getting in the castle, getting to that front door is like the network's assessment and then getting into the room you want to go to the further you go in, you the the more controls you want to have. And that's the kind of the journey that you want to do, right? Uh what where is that is that it is just always that's it?

Tony Fergusson

Yeah, so so look if you want to think of an analogy of like how does you know because you talked about the castle, right? So the castle is the old way, right? You just open the doors, you let everyone in the castle, and you know, even better, VPN, what is that? But if you want to think about it, it's just like underground tunnels from everyone's houses, right? Yeah, yeah. I I mean, you know, everyone is allowed in the castle, right? And if you're uh that user's compromise and they're at home, well, guess what? They have access to everything in the castle, right? So so that's a great analogy. But if you think about zero trust in this way, um, think about it when you come to to the office, yeah, and you're going to visit somebody. Um, so let's say I come to your office, yeah, and I come to the reception. Then there's I'm just not gonna walk in and walk around your building, right? I'm gonna come to the reception and she's gonna say, Hey, who are you here to meet? Um Robby, okay, who are you? Can you show us ID? I'm turning, right? So I'll show my ID and she would go, Okay, yeah, yeah. Check, yes. Policy says, yes, you're allowed to go and meet you. Yeah? So rather than just letting me go and walk around your building and pop in all the different rooms, she would escort me to your room. And I would have a meeting with you, and then you would call her to come back, or him, come back, and then I would be escorted back out again. Yeah. So what I what did I get access to? I only got access to your room and you. You could think about your room and you being the application, right? But I wasn't able to roam around the whole building. I couldn't go into every room and see what's there or you know, or steal anything, right? She will also check that, you know, I didn't, I the nothing was stolen, yeah. So I think that's a good analogy if you think of zero trust. It's really just allowing people to what they need access to. Yeah.

Robby Peralta

So, and that's like a constant thing since everything's changing all the time and you know, new things get added. Where uh so does is it like just I've never seen on LinkedIn that somebody has like a well, I have seen people call themselves zero trust soldiers, uh, but I didn't know that was like a job role. So who I mean, what is like a typical what does it look like today to operationalize zero trust

Operationalizing Zero Trust Security Strategies

Robby Peralta

from a people perspective? The the ones that you're most impressed over, the the clients you meet today that just have their shit together when it comes to zero trust and are have just done the they get an A plus from you, what does that even look like? Yeah.

Tony Fergusson

So I get to see so many companies in so many different ways of doing this, right? The biggest problem I see is that because zero trust is not something that sits in your network department, it doesn't sit in your security department. It's it's it doesn't sit in your identity, right? It sits across all of this, right? So if you think about all the teams that need to be involved in a strategy of driving a zero trust architecture and concept, you need lots of people in your organization across from your identity teams, your network, your security teams. And they need to all work together. And often we've built companies in the past being very siloed, right? So we have the network department that's doing one thing, we have the security department trying to secure everything. The network department, they have a goal to make sure you know packets are moving as fast and reliable as possible. Yeah. And then the security are trying to secure them, yeah. And they're quite different goals. And so what we often see is that there's a misalignment with these two, yeah. And that can really, really slow you down. Yeah. So that's that's one thing we see out there. The other thing that, you know, I I've talked a little bit about this before, but you know, zero cost is a journey, and I think that complexity is also the enemy. I think complexity is the enemy of security. Right. We ended up now, you know, many companies have, I think, on average, is it like 50 security products? So you have a lot of complexity, and that also slows you down. Yeah, it doesn't mean they're secure. I can tell you that now. I can I look at the many companies that have lots of products, it doesn't mean they're secure. It means that they've invested a lot into a lot of products, but you know, are they configured? Well, do they have good policy? Often not. Um, you know, legacy, that's also really hard in organizations. You've got an old system or something, and you know, you need this in the corner and no one knows how it works, and that that's holding us back. And then probably the last part is the the mindset, yeah. This people don't like change. Yeah, I actually quite actually call it the the popcorn theory. Yeah, so even made it have you ever made popcorn? Have you made popcorn before? Like in the the way in the pot, in the old pot. Have you done that before?

Robby Peralta

Yeah, you well, wow, yeah. You put some butter in the pot, throw the little whatever those bead things in there, and they pop eventually. Yeah, yeah.

Tony Fergusson

Yeah, and and you notice that when you do this, right, there's always a few of the popcorn that pop first. That don't pop. Yeah, yeah. Yeah, there's also no, yes, I'll get to that, but there's a few that pop, right? They don't like your people like me, right? I pop early and poop, I'm on this journey. I like change. Yeah. And I think, you know, 20% of the people in your organization love change and they will lead and they're change agents. They want to, you know, be the person to stand up and go, we're going this direction, come along with me. And then you have the 60%. They're all the other popcorns that pop along during that time, and they will come along with you. But the the disappointing part is there's always, you know, people resistant to change, right? Then there's those corns left in the bottom, the ones that don't pop. Yeah. And I always say, don't underestimate how they can hold you back. Yeah. Especially if they're in in certain positions, because they will, you know, try to say, no, we've but we've done it, we've always done it this way. We need to continue to do it this way. And there we just really need to make sure we, you know, the majority wins, right? You want the 80%, make sure you get them and empower them, right? Empower the the 20% that want to do change and empower them to uh drive change.

Robby Peralta

The word is inertia, right? So I guess the ones that you're never done with it because it's an ongoing thing, but most a lot just don't get started because they're don't fix it if it's not broken, they think, in their minds, and they don't want to change it.

Tony Fergusson

Yeah, exactly. And you know, like you just said, don't fix what not was not broken. And actually, I think, and I've been in this position, we are sometimes scared to make change because you know, if you make change, there's always risk. You gotta break something. You know, that's just that's how you know technology is complicated. You can have the best plan and you can go into the migration, and we see it all the time. And oh, things don't go the way you planned. And they take a lot of effort, and they so you know, sometimes we're not wanting to do change because we're scared of breaking something. But then the problem is, yeah, the company gets broken in another way, right?

Robby Peralta

Yeah, right.

Tony Fergusson

By by an adversary that's by a ransomware attack, yeah. But so it's like and you know, being able to to to balance that risk of change, but the risk of the unknown. I think that's been difficult for many companies. Yeah. And you know, I think there's two types of companies, right? The ones that are, you know, almost breached and then maybe accelerate their change, or the others that are are too just too far behind and yeah. Well end up in the wrong place.

Robby Peralta

I feel like everything you just said kind of sums up to the uh the companies that are doing zero trust correctly they're they're like the most aligned. Like they they've understood that yeah identity network they have their their goals I have to understand their goals and try we have to come together to make this work and operationalize it. And we have to understand that this is actually this is a what we're doing today is not ideal so we have to go towards this new path even though it's going to be hard and we have to figure out a lot of things we have to do it. Those are the ones that have come the farthest in your eye in your mind. Okay interesting.

Tony Fergusson

Yeah. Yeah and and you talked about inertia right the adversary they don't have a lot of this right they don't have much inertia but we do right we do many especially large organizations have a lot of inertia and and and that's difficult here.

Robby Peralta

Elephant elephants can't dance you said when you started using zero ZTNA I never remember there but Zero Trust Network Access when you start there what like what's the evolution of products look like from a because I assume that is a product. I think that's what Z scalar causes ZTNA right but what about all the other acronyms that you guys have like where do where do those fall in along that journey and are all those you know SASE SSE are they all relevant do you have to have all of them to be like zero trust compliance

Tony Fergusson

actually this probably a really important point right like I I always call it a journey because it is something that is never ending it is more of a concept and a change a mindset change and you have to get started right I I I quite often have companies and they go hey oh we're just not ready. I'm like ready for what like we're like oh but we don't have our identity uh you know we don't have our identity we need to do a lot of work on that before we can do the zero I'm like one thing is clear that there's never ever a good time to start right there's never a good time to start and the longer you wait the further behind you're going to be yeah and I always sort of try to look at this from a risk point of view. So for most organizations what is your biggest risk yeah and find out what that is right now you could go to the business and try to work out what do we do and you know what processes and technologies are there. But you can also look at it from the other point of view and go, okay, what brings the most risk to my organization and if you look at it you will say my users do. It's the people so it's the user that gets the phishing email that clicks on it that downloads the malware. Right? And then that device ends up being the risk because the adversary's now got command and control and they're going to now laterally move into micro and drills. So if you just take that as one example and go, okay let's forget about OT, IoT workloads and all that let's just focus on doing zero trusts for the people in the corporation the users and just start at that point and just go yeah let's deploy and you know you don't even have to do a big bang you can slowly deploy you know thousands at a time or hundreds at a time right you don't have to do a big bang you can slowly move them away from VPN and you can slowly move them towards zero trust. So it doesn't have to be a big bang it can be overtime and then once you've done that then you can think about oh okay now what about my workloads? Oh okay what about OT? What about IoT and manufacturing if you're in manufacturing what about my factories my warehouses but you need to start somewhere yeah and picking where that is is uh yeah you just need to find an area and say okay yes this is end of life or like I like for me when I started this actually I had a file that was a third party access file right so actually the very first people to actually get this stuff was consultants and third parties. Because I had a problem I had something that has end of life and I was like well let's just yeah that would be a great place. I want to reduce third party risk yeah um so I think yeah just just finding that area and then just putting a plan in place and you know biting you talked about the elephant right don't eat the whole elephant just you know you need to take small pieces right and and then you'll

Embracing Change in Cybersecurity

Tony Fergusson

you'll get there in the end. Yeah.

Robby Peralta

But by the way I really liked your analogy there like okay if users they you know they're the I have a device it's that device that becomes a risk that starts you know doing lateral allows for lateral movement blah blah blah. What does zero trust look like so that was zero trust for like a user what does zero trust look like for the you said workloads you said IoT you said OT. Just give me a quick example for those other ones because uh I really like the one that you gave for users. So I want people to remember what you're gonna say now for the other ones.

Tony Fergusson

Yeah so look look you know workloads that's I suppose that's an easy one in the sense that we've always been trying to do this. Your your public attack surface on your data center whether that's cloud or on-prem right your attack surface is is always always a target right you're public on the internet any vulnerability whether that's in your VPN or an application that's going to be found pretty fast. So that is of course when you think of data center that's your for your first you know your first area of biggest risk yeah attack surface yeah and of course in the zero trust model you should really reduce that to what actually Gone Kinder calls protect surface so only the things you need to post right and you have a protect surface. And then you're the rest of it you can maybe hide behind the technology. And then of course in workload you want to stop that if one workload gets compromised they're able to move actually to other workloads. Yeah so then that's all about segmenting segmenting workloads and that's part of the zero trust principle least privilege within workloads this workload should only talk to these workloads right same as these users can only talk to these applications. So that's of course a great area to to improve on and there's lots of products and other things out there to do this. And then I suppose the OT and you know we we met at the conference and this this area is still yeah still evolving I feel there's not enough talk about zero trust and and OT I feel and look it's a difficult area. We know that OT is a lot of legacy it's you know critical infrastructure it's a lot of areas that are difficult to maintain um difficult to even change anything in these environments right you think IT had an inertia yeah yeah yeah exactly the the OT inertia is like massive right and yeah so that one we need to be obviously careful going into that and you know we need to make small steps again but again we've seen now new innovative technologies like uh like air gap and so you know putting everything in a network of one that's you know that's that's fascinating right so there are technologies out there to start to segment out the OT network. We will get there and and OT will come along with the journey but as always I think some of that is always lagging the corporate technologies.

Robby Peralta

Yeah just really quick I know it's a product pitch for you but I thought it was interesting you said that you bought a company Zscaler bought a company that just put like a 30 slash 32 and made it its own network or whatever. Can you just explain that really quick just because I thought

Speaker

Speaker

that was that

Tony Fergusson

the telcos have done this for years, right? They always put you in your own network. So if you look at the IP on your mobile you'll see that it's an IP address or over 32. So it's in its own network in its own subnet yeah so that was segmented that means my telephone can't talk with your telephone even though we're on the same mobile network and that's good that's good for security right I don't you should I shouldn't my phone shouldn't be able to directly talk with your phone yeah

Robby Peralta

unless I call you right now I'm confused

Tony Fergusson

because when you call me you will call Apple or whoever or your telco and then they will call then the call comes back right so there's actually an exchange right that you connect to you connect to the exchange and the exchange will call you back. So called the other authentication yes exactly like you well like like our zero cost exchange right like a switchboard. We we especially call it like that because we are like a switchboard connecting the right user to the right app but yeah if if you think about this idea of just putting everything in the network of one um then you prevent laxal movement but the advantages are that you haven't you haven't re-invented the whole network you haven't restructured the network right you still had the same IPs you still have the same VLANs you still have the same infrastructure so you haven't changed a lot you've only changed the subnet yeah and then of course if we can become the default gateway and that's one obviously migration point you need to do then we need we can now see all the East West traffic and now we can use machine learning to tag it and make policy a zero trust policy yeah so a very simple approach but I think we need simple approaches because we're not going to make it if we just say we're gonna have to rebuild all our networks and upgrade all our switches and redesign everything while the while you're in the middle of manufacturing. I love the conversation we're having so far what does it have to do with risk hunting yeah risk hunting so oh yeah so this one this one's a bit of a team effort actually and a lot of my colleagues and us we obviously get to talk to lots of customers and we also get to talk internally with each other. And one of the things we've always sort of talk about man you know like oh I went to this big customer and I you know we did that we we do this thing that's called a pause review where we actually look for areas that are maybe not configured properly or areas of our platform they're not leveraging, right? So basically what I'm doing is trying to get our customers to leverage our platform as good as possible right so that corporation is protected as much as possible with what they've got. And when I go in sometimes I see like oh my god like you know the the the firewall rule the last yeah they've got firewall rules but the last one is allow any any one rule the rule of them all the last rule yeah yeah yeah exactly I'm like so what so what are all these rules for when the the default is you know allow and you know I take think back and I just think oh like what why is this why are you know these are big companies that have a lot of resources a lot of people a lot smarter than me I'm like so why are we sort of stuck with companies that have great technology but the actual adoption and the the way they've operationalized it and implemented it is not right. So then we started talking about what do we actually what are we doing when we're talking to the customers and we came up with this term risk hunting because what we're actually doing is we're looking for risk. So I'm going to a customer and saying hey where is there risk? Oh look here I found a policy that is way over permissive it's it's not growing the policy it's allowing everyone to the internet one I really like to often talk a little bit about is you know many customers are connecting to Microsoft and that's becoming a threat. You need to see what traffic are within Microsoft threat actors are now leveraging Microsoft Google AWS platforms to do their attacks. So just abusing their trust it's Microsoft you have to trust it right yeah exactly you know and the zero trust principle is look look sure these company companies you can trust but you can't trust all the consumers that are on those platforms I can go and buy a credit card and buy my Microsoft tenant. Yeah so that is that and that is a problem so if we just say hey I just allow a big rule that says allow everything to Microsoft yeah but that's not that's not how we should think we should be thinking okay my tenant that's okay because it's my tenant my data allow that but for all other tenants my users are connecting to yeah then we should think do browser isolation or or at least inspect the traffic or or do something else to make sure that nothing bad comes down to the user and what none of your data leaves.

Robby Peralta

Interesting concept because I like obviously my mind went to threat hunting right like uh I think the question I asked you at the conference I think we were drinking a beer at this point maybe but uh I think I said like yeah you're a mature client you know you're doing you're doing threat hunting at that point because you have you know you have your other basics of security monitoring sort of you know in place and you're doing risk or uh threat hunting is risk hunting kind of like a mature function for grc or like where should I where should I put that in my head you know

Tony Fergusson

so I my other colleague same carry he would say like it's um you know GRC is big G, little r, big C, right? Yeah and it's the it's the R the risk part that we need to work on, right? Because we do we often do a lot of the a lot of the other two right where trying to be compliant and yeah and we're trying to do all that but then if we look at the risk part and say how well are we actually evaluating risk then if you think of I would say like threat hunting is good if you're trying to find a threat actor that's already compromised a device or your systems. Yeah for example nation state they will come in they want to stay undercover they want to sneak around collect uh intellectual property so for those threat hunting makes perfect sense yeah but for ransomware attack these happen fast right I mean you know crowdstrike gave some good figures around this I think uh what is it two minutes or something now yeah two minutes between yeah the breakout time they call it from when you compromise for when the threat actor then actually moves so that amount of time is coming down down I think it was like nine hours about five years ago right and we've got down to literally minutes so if that's coming down then to prevent a ransomware attack I can't react I can't have my security operations center save the day so then we need to look for risk yeah and that's a proactive measure it's been proactive in the way we look for risk and find risk and if I find risk then of course I have to mitigate it right mitigate the risk before it happens. So I sort of look at threat hunting being more of a reactive type of way of doing security and I look at risk hunting being a lot more proactive and I really feel we can do a huge amount out there on this we can do a lot more and let's hope that AI and ML will also play a part in helping us find risk right

Robby Peralta

yeah I just had an episode on have you heard of the term CNAPP?

Tony Fergusson

Yes yeah

Robby Peralta

yeah CNAPP so I just what I learned about the CNAPP thing because I was asking uh the guest like uh can you do this as a human without having the tool and he's like yeah well you can you can read those API calls and try to map it all out in your head but good luck you're gonna be sitting there forever right so like it's not like it's impossible but it's just machine learning and AI if I can call it that that will just understand and be able to point out hey this isn't good this is good this is good. So you kind of need AI or ML to help you with risk hunting too because you just don't have manpower or you you won't have an employee very long if you make them do that like with their own eyes, right?

Tony Fergusson

Yeah, yeah yeah that if you yeah like if you think of it it's like you know when you talk about tech surface management but it's also attack path management right yeah so if I compromise this then what does that lead to right and that's also around CNAPP that's very much involved but yeah understanding if I compromise this server, what business process is that going to affect I mean going down to that level right and mapping all of that out is going to be really important. Yeah breach attack simulation could we even you know use MITRE which has a great framework could we use that to uh simulate attacks and and make sure we find out where is the risk for my organization and my vertical where can I close the gaps right? I think that's gonna be a an area that we need to do a lot better at

Robby Peralta

that's interesting I I think you with the way you just described that right now you would help sell a lot more breach and attack simulation than anybody else has ever sold because nobody I feel like that's like a in my mind I thought that was like advanced pen testing like you have to be really have your shit in order to do that. But it's almost something you should be like starting with because it's proactive right I don't know I think that is a different way of looking at it's interesting. I haven't heard it before

Tony Fergusson

yeah yeah I think that we're starting to see some of this right we're starting to see breach attack simulation picking up and look it's not it's not easy right to do that type of simulations and but I sort of feel that's that's where we need to move we need to move in that direction right because technology is complex and attack paths infinite to some extent right and as you said we're we're we're not gonna a human's not going to be able to look at the systems and go ah yeah look look there there's the problem right yeah

Robby Peralta

yeah yeah so you actually can't use humans for exactly that risk I mean the way that you and your colleagues are doing it by the way I w I wish every vendor would actually look at what their customer has bought and like hey by the way you guys should be doing this this this uh but so but in your in the Zscaler context you were literally looking like hey here's their portfolio what they have from us at least we think they would get value or this is a risk for them. So that's like the risk hunting where it came from but the for a a client the the risk

Proactive Risk Hunting Strategies in Cybersecurity

Robby Peralta

hunting approach is that have I understood it correctly that it's kind of like a a combination of breach and attack simulation with you know crown jewel protection or like how what do you want people to walk away with risk hunting as the uh

Tony Fergusson

yeah so I look I think um I think I think what what our idea around risk hunting is is that you know I I wrote I I wrote an article a while ago I a fool with a tool is still a fool. Right? Um and that was my frustration right my frustration of hey sometimes we have great technology and we often do but often we lack to operationalize it and actually have people that understand least privilege understand how to write policies in the right way and that's always going to be uh you know we we lack a lot of resource in in in that area that's always gonna be a problem and I think risk hunting I would hope would be a a service or an idea of making sure it's call it SecOps or AIOps whatever you want but to help the humans do a better job right in combination if we think of AI and us creating policies together you know and getting some feedback oh maybe this policy could be done in this way yeah it's a pretty bright future when I think of that on our side of the fence we can start to leverage some of these technologies to make sure we're actually you know are gonna take the fight with the adversaries and we're gonna keep up with them, right?

Robby Peralta

And one more last thing on this topic risk hunting how does that relate to zero trust to just to bring it full circle.

Tony Fergusson

So zero trust is least privilege and we often see that is best practice I share least privileged policies but often risk is there and we need to find the risk and do some risk hunting to find out where where are my policies do I have misconfigurations? Where are my policies do I have risk how do I how do I get that zero trust concept to be that really least privileged access very granular and I don't have gaps in my policies. Yeah? Because that's always hard right it's really hard to get to that place where you say look I've finished I've got every user in every application I've got every policy in place and it's perfect right there is no perfect so we want to just be able to get as close as possible as and I think risk only can help us at least get closer towards the zero trust concept

Robby Peralta

uh and uh I want to let you go on that but I can't is there a product for this today somewhere or is it is it like is it just an idea that you have to put different strategy/ products together to accomplish that goal

Tony Fergusson

look look we never lack products and innovation and other things there's certainly products out there and certainly we have some of them right and we don't have all of them right but not a believer in you know you know don't come to us and say hey Zscaler can I please buy zero cost right I hope everyone's takeaway today is that zero cost is a is a is a is a mindset and it's a a concept that involves many products and many moving parts yeah and don't go away and also think that you can just do zero cost with one vendor. Don't think you can go away and do it with 50 either because that probably won't work either because you end up not having the integration but then pick pick if pick an identity provider that you want pick somebody that's going to be your policy enforcement point right like Zscaler. Pick somebody that's gonna be on your endpoint to do another layer of protection like CrowdStrike or whatever. And then together make sure they work together to give you that zero trust concept yeah

Robby Peralta

it's the best vendor neutral answer I've ever received from a vendor Tony

Tony Fergusson

I try I try.

Robby Peralta

10 out of 10 A plus any closing thoughts anything that you're gonna use your your brain on moving forward

Tony Fergusson

I'm just look I I I get up in the morning and I talk with lots of customers and it's it's also great to be on your show and and uh get to be heard a little bit and make sure that I can add some value out there right to make the world a a a more secure place. If I can just help even somebody that's listening out there say oh actually maybe we should start there maybe we should just get rid of our VPN right and that would prevent that ransomware or that me reading in the headlines then I'll think okay so yeah my my job is done right uh it's never done but at least I'm making a slight impact right so uh yeah so I appreciate the time

Robby Peralta

I I really appreciate the time I'm looking forward to having on you next time Tony take care in the meantime thanks peace out well that's all for today folks thank you for tuning in to the mnemonic security podcast if you have any concepts or ideas that you'd like us to discuss on future episodes please feel free to hit me up on LinkedIn or to send us a mail to podcast @ mnemonic.no. Thank you for listening and we'll see you next time