I had the opportunity to attend this year’s RSA Conference in San Francisco and I was impressed with the hundreds of cybersecurity exhibitors on display there. If you ever have the chance to go and haven’t been already, do yourself a favor and take the trip. It’s absolutely worth the investment.
If you do go, be prepared for a crowd. This year’s event boasted over 40,000 attendees. I walked the floor and was amazed at the questions being asked, the issues various organizations are facing, and how vendors they are all attempting to solve the cybersecurity threat as they each perceive it. That’s not to mention the amount ofresources they collectively are spending trying to find answers.
According to Cybersecurity Ventures’ Cybersecurity Market Report for Q4 2015, “Market research firm Gartner says global spending on IT security is set to increase 4.7 percent in 2015 to $75.4 billion, and the world will spend $101 billion on information security in 2018.” After attending the 2016 RSA conference, it is obvious that attendance at the show reflects these numbers. The money and time being spent in this area are simply mind-numbing.
What hit me the most was how many vendors and companies were offering standalone cybersecurity tools without offering a complete solution. I couldn’t shake the feeling of being at a car show full of parts vendors but seeing very few cars for sale. If your main goal is to get to one place from another, just buying a steering wheel and some brake pads isn’t going to do the trick. Why should cybersecurity be any different?
It also reminded me of a story I’d heard about a customer who enters a hardware store and makes a beeline for a sales clerk:
Customer: “I need to buy a tool.”
Clerk: “What kind of tool are you looking for?”
Customer: “I want to work in my yard and I need a tool to make it easier.”
Clerk: “Why don’t we talk about what you want to accomplish in your yard and then I can help you select the best tool for the job.”
This little story has so many applications in the cybersecurity realm. At RSA Conference, vendors are selling tools and they aren’t lacking for customers, but to what end? The majority of people I asked this question of replied simply that they wanted a tool to counter cyber threats or something to identify and counter the potential of an insider threat.
Very few of the people I spoke with, however, could answer the basic and integral questions they should have been asking themselves all along:
- What do you intend on doing with the tool?
- What is the overall threat?
- What is the critical value data you are trying to protect?
- Do you have the infrastructure in place to support the tools you think you need?
- Do you have a plan for operations?
Better answers = better results
Before shopping for tools and spending their organizations’ money, they should be asking these questions and preparing themselves to find the right tools, use the tools they select, and build a program around these tools. They can do this by following some basic rules.
First and foremost, threats to critical value data (cyber threats and insider threats) are not an IT problem that can be fixed just by installing a piece of software or hardware. Consider how much money is being spent on tools and infrastructure, yet hackers and insiders continue to successfully attack, manipulate, steal from, hold captive or destroy target organizations. This is a solid indication that we are spending resources in the wrong way. The situation needs to be addressed as a risk management problem.
Second, countering cybersecurity, insider threats, counterintelligence, advanced persistent threats, etc., must be recognized as
a
human problems, not merely a machine or tool problem. Humans are behind these attacks; intelligent humans who, if they don’t understand a new technology or defense, will quickly learn about it and find a way around it. Whatever the motivations of these threat actors may be, we know they are determined to accomplish their goals.
Finally, successfully countering these threats relies on what I call the
“
three A
‘
s
“
: authority, advocacy, and agility. Senior management must understand that to successfully answer threats to their organization, they must grant an internal team the authority and power to plan, counter
,
and continually chase
the
threats across the organization. Senior management must also advocate for the program, recognize the importance of the effort, and place it at the C-level within the organization. The internal organization must be agile. Today’s threats are dynamic; if the organization does not understand the environment, then it will continue to attempt to protect itself solely using tools, applying a static solution to a dynamic problem.
Tools are a means, not an end
Those who begin conversations in their search for better security by asking “What tool should we purchase?” have a long, uphill and difficult road ahead of them. Successful organizations will think strategically by defining, planning, organizing and prioritizing programs before seeking tools. Included in the planning and organizational efforts are evaluating what currently exists internally and honestly answering the question: “Does that infrastructure assist in countering the threat?”
Only when we begin to understand that successfully countering threats is not merely an IT or tool problem, can we begin to feel comfortable that resources and efforts are being spent appropriately. This is a risk mitigation problem — think dynamically, not statically, and spend your money and time wisely.
Keith Lowry is Nuix’s senior vice president for business threat intelligence and analysis. He served as chief of staff to the deputy undersecretary of Defense for human intelligence, counterintelligence and security at the Pentagon, and as an information security consultant in the private sector.




