Ep 15: Navigating Cybersecurity in OT: Challenges, Tools, and AI Integration with Joseph Perry | PrOTect IT All
HomeEpisodes › Episode 15
Episode 15
Episode 15 Interview

Navigating Cybersecurity in OT: Challenges, Tools, and AI Integration with Joseph Perry

Jul 8, 2024 01:03:13 with Joseph Perry
OT SecurityCritical InfrastructureAIIncident ResponseRansomware

Watch This Episode

In this episode, Aaron Crow and special guest Joseph Perry dive deeply into the evolving landscape of cybersecurity. The episode explores the integration of commercial off-the-shelf systems into OT environments, highlighting how this transition brings similar security challenges from the IT sector into play. Throughout their discussion, Aaron and Joseph tackle the complex vulnerabilities, the resistance to adopting new technologies, and the critical necessity of tailored security measures. They also examine the pervasive buzzwords like "AI" in modern cybersecurity products.

Listeners will gain insights into the growing regulatory scrutiny from the SEC, the heightened responsibility of Chief Security Officers, and the anticipated evolution of cybersecurity professions into more rigorous, skilled trades. The conversation further touches on the chaotic state of threat intelligence, the impact of technological advancements such as AI on cyber-attacks, and the increasing industrialization of fraud. From understanding the hype cycles of AI to the practical challenges of explaining complex security solutions to non-technical stakeholders, this episode is packed with valuable information.

Aaron and Joseph also discuss the importance of learning from past IT mistakes when adopting new technologies and the unique challenges of protecting both cutting-edge and legacy systems within OT environments. As they address topics like social engineering attacks, ransomware, and the use of AI tools in cybersecurity, listeners will come away better equipped to navigate the intricate cybersecurity landscape. Tune in for a comprehensive exploration of these critical issues.

Key Moments: 

05:36 Library catalog conversion led to career in cybersecurity.

15:02 AI useful in cybersecurity for structured data.

18:07 Questions remain about AI, and human intervention need.

25:39 Advanced fraud detection surpasses current AI capabilities.

28:37 AI contributes significantly to medicine, finance, and cybersecurity.

34:57 Powerful means test and audience testing revolutionized fraud.

37:58 Attacks getting shorter, focused on initial access.

47:52 Focus shifts to CPE, vulnerability, and attack.

48:53 Russian threat actors reassert, causing chaos. No rules.

54:43 IT challenges in dealing with construction clients.

59:56 Evolution of cyber security concerns and measures.

 

About the guest : 

Joseph Perry is a seasoned cybersecurity expert currently leading incident response, threat intelligence, and purple teaming at MorganFranklin Cyber. With a background spanning the US Navy and the National Security Agency, Perry has built a robust expertise in emerging technology and cybersecurity. He specializes in critical infrastructure protection, threat intelligence, and the adoption of new technologies.

Perry is a prominent figure in the cybersecurity community, contributing his insights at major conferences like Black Hat and Defcon. He focuses on the practical applications of AI in cybersecurity, fraud detection, and the evolving threat landscape. Committed to advancing the field, Perry emphasizes continuous learning and domain expertise to help organizations combat cyber threats effectively

How to connect Joseph : https://www.linkedin.com/in/lousyhacker/

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:


To be a guest or suggest a guest/episode, please email us at [email protected]

Chapters

05:36Library catalog conversion led to career in cybersecurity.
15:02AI useful in cybersecurity for structured data.
18:07Questions remain about AI, and human intervention need.
25:39Advanced fraud detection surpasses current AI capabilities.
28:37AI contributes significantly to medicine, finance, and cybersecurity.
34:57Powerful means test and audience testing revolutionized fraud.
37:58Attacks getting shorter, focused on initial access.
47:52Focus shifts to CPE, vulnerability, and attack.
48:53Russian threat actors reassert, causing chaos. No rules.
54:43IT challenges in dealing with construction clients.
59:56Evolution of cyber security concerns and measures.
Read the full transcript

Aaron Crow (0:0.000): It's, it's, it's just, it's weird. Like my, I use my iPhone as the camera because it's got a 4k or higher quality camera than this 10 ADP one. And it just has better lighting, all that kind of stuff. And I use it all the time and I've never had this problem. It just like lost its mind and then it wouldn't go back. And I wasn't sure if it was recording or not. So anyways, I think it was, but this way we can make sure that we don't lose anything.

Joseph Perry (0:20.334): no, no worries at all.

Joseph Perry (0:24.178): I say a lot, like a lot of people get into cybersecurity because they were super technical and they were really into it and they grew up watching hacker movies. I got into cybersecurity because every computer I've ever touched has broken to pieces and I figured I might as well weaponize that. There's nothing, and a lot of it's just because I have a suffix in my name, but every database I've ever been entered into has just erred out and failed. So yeah, I am sure that somehow I broke something plugging into this and it's totally.

Aaron Crow (0:46.606): That's awesome. I actually want to use that in the podcast because honestly, it's important to understand. Same thing with me. I didn't start out, I didn't drive towards getting into cybersecurity. I graduated high school in 96. I'm old. But I took our library when I was in high school, I was very computer savvy. I had a computer from a very young age, Tandy or Trash 80, IBM or the RadioShack version.

Joseph Perry (0:49.490): Absolutely.

Aaron Crow (1:16.174): Tape player is as the program would fast forward and hit play. Yeah, that Mac over there is one of my first computers that actually still works. But yeah, you know, I was just the technology guy. Like it just came naturally to me. It worked really well. I never really did much programming. It was more around the infrastructure side and kind of connecting them all together and kind of using them. I took the library, our high school library from the old school catalog, you know,

Joseph Perry (1:21.618): Love that.

Joseph Perry (1:26.098): That's awesome.

Aaron Crow (1:45.294): index cards and, and took that to a computerized barcode system, right? While I was there, that was my, as my senior year, I worked in the library and converted us all over. And I, I'm the one that set it all up and all the users and all that kind of stuff. And then that kind of transitioned. I went into, I went into college as an electrical engineer and then I was working in, it was really, you know, the internet and the technology boom was really happening and there was so much going on. And then through that working in infrastructure and networking and systems integration, all that kind of stuff.

Joseph Perry (1:52.114): That's really cool.

Aaron Crow (2:15.086): the configuration piece again, we didn't call it cyber security, but you know, I was a domain exchange admin for AT &T and these different places. So I was doing security, but again, we didn't really call it cyber security. It was just, you were making sure that, you know, Bob didn't have, Bob and accounting didn't have access to the, you know, the, the non -accounting environments and vice versa and, and all that kind of stuff. And then that just kind of grew and grew and grew. And then it became this whole other thing that

Aaron Crow (2:41.774): you know, online and hackers and all this different stuff, especially from a public facing perspective. But a lot of that time I was working in manufacturing and critical infrastructure and all that stuff was just air gapped and it was, you know, security by obscurity. It was these one -off systems and they weren't the same things. But as we started bringing those things into the, into these environments, commercial off the shelf and stuff into these OT environments, we started having the same problems that they were having in the IT space. And we unintentionally brought those things into the OT world and we're like,

Aaron Crow (3:11.870): crap, we need to fix this. This is a problem. I remember doing a control system and the vendor actually gave us a proposal. And it's when I was an asset owner and he gave us a proposal and it was the secure version or the insecure version. And that was the proposal titles. Do you want the secure version or the insecure version? And the insecure version was obviously like $100 ,000 cheaper. And the plant wanted the insecure version because it was cheaper. And I'm like, you can't choose the insecure version. Like that's not an option.

Joseph Perry (3:27.794): Yep. The insecure version, yep.

Joseph Perry (3:40.338): Yeah, absolutely. It's one of the things I joke a lot. Like I have a unique insight because I came up as a programmer. I have a unique insight insight into how exploits become possible and how vulnerabilities happen. And pretty consistently a vulnerability doesn't happen because it's some new, incredibly advanced technique that no one's ever heard of. We get a vulnerability because somebody refuses to change the tech stack they've been using for 30 years and God help them. You're not going to make them change their library either. I mean, it's, it's, it's sort of the joke that there are still people out there who are trying to upgrade from Python two to Python three.

Joseph Perry (4:10.226): But it's as technology gets adopted into a new area, that area kind of starts on the back foot and has to, I joke, like speed run, learning all of the hard lessons that we learned the first time we did it. So when we brought IT into the OT world, they had to speed run learning all the problems that we learned in IT. I mean, kind of the same thing when we actually built cybersecurity up as an industry, it went through all the same problems that IT went through, where nobody took it seriously, nobody who was involved in it, who understood it technically, was able to talk to business leaders.

Joseph Perry (4:35.026): All of those same growing pains kind of happen. And it's, it's that, that sense of technological adoption is powerful and useful. And it's sort of inevitable in most industries, but it also carries with it kind of those same problems that had the first time it got adopted, wherever it was first innovated into.

Aaron Crow (4:49.646): Well, and the irony is, and I know some of the things that I want to get into with you is talking about AI and IR and threat and all those different categories. But the irony is specifically in a lot of these areas and it's IT and OT, I think it's just maybe a little bit more extreme on the OT side, but you've got folks that are 40 year old technology, the stuff that was installed 40 years ago, it hasn't been patched, it hasn't been changed. It's exactly the way that it was when it was installed 40 years ago.

Joseph Perry (4:53.682): Yeah, absolutely.

Aaron Crow (5:18.638): all the way up to people talking about how do I use AI in my, you know, to enhance my, my manufacturing line, right? And everything in between. So you've got this vast difference of cutting edge, bleeding edge capabilities and looking to, you know, enhance and update and all that type of stuff to people that are just continuing. If it ain't broke, don't fix it. Like they're running their old pickup truck that they've been around. It's got a million miles and they're not going to get a new carburetor, you know, a fuel injected engine, right? It's that far difference between them and

Aaron Crow (5:47.918): as cybersecurity professionals and in this vast world, and obviously hackers as well, we have to be able to look at and protect all. Like we can't just expect everybody in the world, OT environments, IT environments to just upgrade to the latest and greatest across their entire organization, because it'd be super expensive, hard, all of those things. So we have to be able to protect where we're at. And the answer is not always, especially in OT, it's not always just patch.

Aaron Crow (6:16.110): It's not always just upgrade the control system or the Windows machine or the network switch or whatever the thing is that's old and archaic. Sometimes it's like, okay, I can't do that. So how else can I protect this thing?

Joseph Perry (6:27.570): mitigating controls can I put in place? Yeah, and I think that point that you hit on there is such a critical one and it gets into what we'll talk about with AI. I have clients that I go to and I'm talking to them about using LAPs and removing local admin privilege for most of their users. And then I have clients that if I go to and if I brought that to them, they'd be like, you're not a serious security professional. You're talking to me about security measures from 15, 20 years ago. Why are you bringing this up to me? Like I need you talking to me about Cribble and how I can minimize my Splunk input and how I can reduce costs and how I can improve my analytics and my dashboard. Like that's what I'm here to talk to you about.

Joseph Perry (6:56.402): But if I go back to that first client, I was like, so here's the Cripple implementation that I think makes sense for you. They're going to lose that. They're going to start screaming at, cause like they're not even, they're not even in the cloud yet, let alone needing to worry about data input and managing that the volume. And so it's, it's not only do you need to be able to, to change that context within your own kind of mind and understand these are the solutions best suited to this problem state. But you also within the industry, we have this kind of constant push where there's a chunk of the industry and I love them. They're very near and dear to my heart who are just interested in the most advanced research.

Joseph Perry (7:25.234): We're just doing the hardest red teams. We're just doing, and that's great stuff. But when I talk to this, I'm like, I can't take that to any of my clients. They're not going to understand a word. I'm so, I love this. I love your results. I'm so glad you did this, but like, I can barely explain it to my junior analysts, let alone a sizzle who's going to have to make purchasing decisions based on it. And so, so much of our challenge is changing context and sort of this, this matrix sense of not only is it how mature the organization is, but it's also based on what kind of needs they have. Are there needs extremely technical? Are there needs extremely procedural? Are they about?

Joseph Perry (7:53.266): you know, we don't really have that many data assets that we need to have this complex attack chain for. We really need our people to stop paying out fake invoices and stuff like that. So there's just all of these different sort of ideas there. I think of the mentally sort of tags, but these different things that you need to associate with a given client or a given environment that is, this is the way that I have to approach this. These are the problems that I need to solve for them. And it's just a wild constellation of potential problems that you might get from space to space.

Aaron Crow (8:18.094): Yeah, absolutely. You know, and you talked about something really important there and it ties right into the AI, you know, talking about Cripple and how much data I'm sending in and adjusting. And I think that's the bigger piece is, is you talk to these CISOs and they hear these buzzwords on LinkedIn or in the newspaper or, or their, their vendors are telling them, you know, it's like, every, every product you have has an AI label on it. Right. I've got AI. Like, what does it do? I don't know, but I've got AI in it.

Joseph Perry (8:43.890): Yes.

Aaron Crow (8:48.258): is it actually something I need? Is it enhancing something? Not really sure. but as we, as we look through this, it's no different than any other product. It's like, I actually did a podcast and a post the other day and it was around, you know, there's an OT, Forester, OT product that Forester put out and, you know, there was top right quadrant and all the different things, but it was such a generic view of it. It was like you had, you know,

Aaron Crow (9:15.342): networking products, firewalls, and with, you know, compliance tools. And they were writing them against each other. And it's not really a fair rating. It's like, it's like rating a, an 18 Wheeler with an apple. Like, yeah, the 18 Wheeler is better at hauling equipment, but it's not going to taste good. I mean, it's, they're just not the same product. They're not even the same category. Like, yes, they're both in the OT industry, but they're not, they're not really a fair comparison between. Yeah.

Joseph Perry (9:31.090): But yeah, if you take a bite out of it, you're gonna hurt yourself, yeah.

Joseph Perry (9:40.274): They're solving different kinds of problems coming from different spaces. Yeah, absolutely.

Aaron Crow (9:43.790): Yeah. So, so AI I see as a huge one. so let's, let's dive into that. Like what, where do you see AI being an impact in cyber security? And I know there's a lot of different ways and obviously we can't hit them all, but you know, what are some of the bigger ones that you see being a benefit to folks no matter where they are in that tech stack? Are they the guy that doesn't have the admin, you know, they're still logging in as admin or people that are more advanced down the road in their cyber jerk.

Joseph Perry (9:49.170): Yeah, by all means.

Joseph Perry (10:9.074): Yeah, that's a great question. So, without getting into the whole technical history of AI, which I love talking about and would happily do for hours and hours, one fact that really needs to be known when we're talking, and for the purposes of this conversation, when I'm talking about AI, I mostly mean generative AI, and I mostly mean things that look like or behave like chat GPT. So in that context of AI, one thing that's really important to know is that kind of AI was mostly created for language -based tasks.

Joseph Perry (10:38.290): So specifically translation, but just in general for things that are conversational, that sound like a person talking to you. And so that's important to note as we start looking at how can AI impact cybersecurity? Because there are a lot of problems in cybersecurity that we hear AI like, haha, this is going to solve that problem. We can hand it our data lake and it's going to tell us every security problem. That's not really something that this kind of AI is suited for. And in fact, that's something that big data and data science have been doing for 20 years. That's where data lakes came from is to solve exactly that problem. So.

Joseph Perry (11:4.370): There are a lot of problems in cybersecurity that people want AI to be a solution for, and they really just want it to be a solution for that because that would make them a lot of money. That being said, there are places that it is a really useful solution. And I was alluding to that when I first made the point of they're really good at conversational tasks. So one of the things that I've already seen it implemented in is in various Sims and SOAR products where they are using it as basically the final analytic layer before an alert gets to the analyst. So if I'm an analyst and I'm looking at a Sim, I'm looking at

Joseph Perry (11:32.754): dozens, maybe hundreds of alerts a day, but I'm also not seeing thousands more alerts that are below a certain threshold that don't actually meet incident qualifications, whatever the case may be. There are thousands and thousands of data points that are coming into this tool that I'm not necessarily going to want to read through all of those and look at all of those. And what AI tools are really, really effective for doing is taking all of that information that's already structured and formatted. It's not unstructured, a big blob of data somewhere. It's a very clearly structured and metadata type and sort of data.

Joseph Perry (12:2.226): But the AI can look at all of that, use what's called retrieval augmented generation, RAG, and basically use those documents to print out, basically use only the context of those documents to give you its result. Which means that it's going to give you a very human, very conversational analysis of a very limited data space. And that's great because it removes, it doesn't remove the possibility of AI being wrong, but it dramatically reduces the risk of it. And it also means that what it's having that analysis of is something that you can just look at yourself. If you're like, this doesn't make sense to me, you can look at the alerts and see if there's a mistake.

Joseph Perry (12:31.058): So it's a very tightly focused use. You know, it's just taking a big pile of alerts and putting them in a paragraph that a human being can read. But it's what that analyst would have had to spend an hour or more doing of just manually reading all of those alerts and putting it in a paragraph. So that's the biggest impact I've seen for it. And you see that same basic use sort of spread across all forms of cyber. So threat intelligence has a similar thing where reports are not being generated based on the data being put in. Threat hunt reports being generated in the same way, purple team, red team, all of that. A lot of it comes in that we have the data. Now let's put it out into a formatted.

Joseph Perry (13:0.914): form for users. And for a lot of folks, when they first hear that, that's kind of a disappointing use case of AI. They're like, so it's like it's a secretary. And my response is like, well, yes, now you have someone writing your report. You have a secretary. That's such an expensive thing and hard to get. I would fight tooth and nail to get a secretary in my current role. It would save me hundreds of hours a month. So yeah, AI is just a secretary in that case. But that's a really powerful use if you're using it effectively.

Joseph Perry (13:30.962): A bit more technical use case that I've started to see, and I'm not, I'm not convinced it's going to work long -term yet, but I'm also not convinced it won't. I just haven't been kind of convinced in either direction. And that's where a lot of organizations, you know, the miters of the world or folks who are associated with the miters of the world who have really large data sets where they have this, this, you know, the MITRE ATT &CK and the MITRE DEFEND and the MITRE DAO. And they use AI to basically take a given attack or a given event and map it across that.

Joseph Perry (13:56.786): to quickly give you information about what next steps to take and what process to take. And that gets a little bit more tightly into what a lot of people imagine AI being used for, which is automating that whole operational process from start to finish. There are a lot of questions yet to be answered about that. I mentioned earlier in the reporting creation, if AI makes a mistake in generating its report, I as an analyst read that report and say, that doesn't look right based on what I found, I can go check that data. If this AI is following the MITRE process and they're following the kill chain and...

Joseph Perry (14:25.618): making changes to my environment and making changes and cutting the attacker out, mitigating all this, a mistake is much more potentially catastrophic and requires much more human intervention. And so that's where the question I think still exists of will there be too much human intervention required that it's not really worth the expense of implementing AI or will we find a balance where, okay, we go from, you know, a team of 10 people monitoring this to one person who monitors it. And so it's worth the investment. I'm not really at all convinced that the second case is going to happen yet.

Joseph Perry (14:53.170): But there are a lot of very smart people working on it, and I'm willing to give them the benefit of the doubt there. Those are probably the two biggest kind of general use cases I would see for AI. Beyond that, when you get into the very like, AI is going to hack your environment with a brand new ODE, that's nonsense. It comes from a fundamental misunderstanding of how AI works. Anybody with enough money to do that can just tell the NSA to hack you. They already have government. They already have a spy agency working for them. They don't need to build an AI to do it.

Aaron Crow (15:18.670): Well, and I think people get confused around some of those topics, like a lot of the quantum computing and all that, that really is not AI, right? That's a difference in the processor and how things are, how quickly and fast and how many records it can do at a time and all that kind of stuff versus AI. I think we have this, many of us have this vision from, whether it's Terminator or whatever, like you're gonna have this thing that can...

Aaron Crow (15:45.038): that can out crunch and is smarter, et cetera. But our current version of AI is not that, right? Now, next version, if you go from three to 3 .5 to four, obviously there were giant leaps in all of those. Five is potentially exponentially better than where it is now. And sure, maybe at some point we'll get to that place, but.

Aaron Crow (16:9.102): You know, you even, I've read books and articles around, you know, even on the, on the defense side, you know, using AI and just make it faster, right? The whole point is to narrow down, but I still want to have a human making sure that, Hey, this is the right decision. And I, I'm hesitant to take out a defense, put it into a power utility, put it into a critical infrastructure. Am I willing to just give the business, the, the, the automation or the computer?

Aaron Crow (16:37.582): the right to make all decisions without humor and intervention ever. Like in the whole thing of OT is automating. Like we are automating and we're building, if this happens, then do this. If this happens, then do this. If this happens, then do this. But all those things, an operator is watching screens and they're seeing those indications come up and they're able to hear, look, feel, taste, smell, all the things that are going on around them and take action accordingly, right? They know they're trained. They understand what good looks like.

Aaron Crow (17:6.734): They understand when to take action, what to do in these scenarios. You know, you go back to your, whether it's an IR, DR, whatever, you know, my response plan of how do I operate this thing? These are my normal conditions and know what to do. I don't think, I don't see a time anywhere in the near future where I'm going to just remove a human person from at all. Now to your point, maybe I'm going to reduce it from needing 10 to needing two. Can I do that? I can absolutely see that.

Aaron Crow (17:34.638): But I don't see any in the near term future where we're going to have, we're just going to completely automate that thing. And then, you know, I'm done. We're going to walk off, do the next one and AI will take care of that just like a human would like. Yeah, we're not there yet. I don't, I don't feel it.

Joseph Perry (17:48.850): Well, and it's one of my favorite quotes in the whole world comes from Marvin Minsky and it was in 1967. And Marvin Minsky said, I am convinced that within a decade, we will have substantially solved the problem of creating human -like intelligence. In other words, what he was saying was we will have Terminator level AI no later than 1975. He was a little off. So I don't think anybody who makes the claim today of like, we're X years away, we're X year, we're Y years away.

Joseph Perry (18:15.474): they're just as wrong. And quantum computing is a great parallel here because quantum computing and AI and in its slightly different but related way, like things like the metaverse or Bitcoin all have a similar problem at the heart of them. And I love AI. I have been obsessed with AI for basically my entire professional career. So this isn't just me being like, AI is stupid. We shouldn't do it. But they have a fundamental problem at the core of them, which is that they require such a massive investment and such a massive public adoption to make sense that they really have to reshape the world.

Joseph Perry (18:44.818): Otherwise they're not worth talking about. And so every time someone who sells AI is talking to you about AI, they're always going to be pitching you the future of what AI will be one day. And the fact that we're not there yet is kind of incidental to the current conversation. The fact that like, but one day you'll be able to give chat GPT 55 total control of your environment. It's like, okay, but today I'm on chat GPT four. And if I try and do that, it's going to sell my company for a peanut. Like, what are you, and like promise that it's a legally binding deal. What are you talking about?

Joseph Perry (19:13.042): And so so much of what we have to do as security professionals, and this is why I love talking about AI and hype cycles and security is our job is not to be true believers, but it's also not to be obsessive skeptics. It's not to say AI is stupid and it's useless. Cause I just talked about two use cases where a sock that uses AI to do that first pass analysis is going to work hilariously faster than a sock that does. I've seen it on our own practice. I've seen it with my own analysts. I've seen it with my own work. Having access to those summaries is much faster and much more, even in the times that I've had to be like, that's not right. And I have to go back and check it.

Joseph Perry (19:42.642): That's one thing that I had to go back and fix as opposed to all of the little bits and pieces that I had to arrange and get just so and all. It's so much faster. So the thing that I love about AI and the thing that we as security professionals have to do is picking the parts of it that are actually useful and figuring out through all the hype, through all the magical thought and the mythical language about what AI is going to do and the dark AI God that's going to turn us all into paper clips. The reality of it is like, well, mostly what it's good at is taking this very technical data and turning it into conversational data.

Joseph Perry (20:11.314): And that's very useful. That's a very useful thing for it to do, but that's a bit different from solving cold fusion and taking over the world. That's a very different problem set. And it's, you know, your point about, you know, chat GPT -5 might be worlds better than GPT -4. And it very likely is. One of the interesting things about this kind of technology is basically the more money you dump into it, the better it gets in a pretty predictable way, which is not true of most technology. If you dump $10 million into making a car,

Joseph Perry (20:38.642): There's not really any reason to think you're going to get a better car than if you dump $5 billion into making it. Ask the Air Force about their jets. That was mean. But with AI, there is kind of that promise of if you dump more money into it, this model will get more powerful. Now, we don't know how long that's going to be true. And that's one of the things that's really interesting, because basically with each form of AI we've seen in the past, where the first version of AI is what we now think of as the internet. It was the idea of web pages and distributed metadata type information that's accessible from across the world.

Aaron Crow (20:45.994): You

Joseph Perry (21:7.506): And then AI matured into human level reason, human level thinking. There's never really been one accepted definition of AI. And so then in the 80s and 90s, it kind of got dialed back to basically what we now think of as cell, the ability to transform data at large scales and turn it into useful human knowledge. That's AI in the 80s and 90s. Then in the 2000s, AI was big data. It was the ability to draw conclusions, to make market decisions based on this massive unstructured data.

Joseph Perry (21:34.834): And that is, by the way, when you asked me like the, when we talk about like the most advanced AI, that's still the most advanced AI. The stuff that folks like Goldman and Sachs are using for fraud detection is hilariously more powerful and advanced than anything we're using to give us a recipe in the form of Shakespeare. It's so much more effective and technologically impressive to me. But that being said, so what I think is really likely is we're going to get to in the next few years, we're going to get to the end of this current version of AI's ability to keep getting better. They're going to dump another billion dollars into it and it's only going to get

Joseph Perry (22:3.410): a 10th of a billion dollars better, and that's not going to be worth it for the investors. But it always leads the seed of the useful thing, and it also always leads to the next version of AI technology. So the paper that popularized chat GPT that made this current version of AI popular came out in 2016. It's not a very, very old paper. There were a lot of other papers coming out at the same time, trying to solve those same problems that may spark the next AI revolution. And so we as security professionals have to look at this AI, this current AI revolution, this current hype cycle and say, okay,

Joseph Perry (22:31.890): What can we take out of it? What's going to be useful? What is a risk that we need to avoid? What is the thing that we need to mitigate, manage, control? What is the third party risk, et cetera? But also, what lessons can we take from this so that the next AI hype cycle we see, we come into it more prepared and we don't make bad investments. We don't make bad decisions. It's really, it's one of those kind of, in my opinion, really cool things about the cyclical nature of AI and security is that if you pay attention, you get to learn from the cycles and do better on the next one. So that's my soapbox about AI and the past and future thereof.

Aaron Crow (23:0.302): I love it. So I also want to dive into what you just said there. I love the term and again, it aligns with a lot of things I'm talking about this week as well. And it's that hype cycle and that may have a negative connotation to some folks and it's not intended that way, right? It's about the things that we're seeing in the zeitgeist in the current, you know, cybersecurity tools or processes or capabilities or whatever. Obviously AI being one of those.

Aaron Crow (23:28.430): What are those things that you're seeing today in the current hype cycle that are really impacting us, whether positively or negatively or neutral even, overblown, underblown, whatever it may be?

Joseph Perry (23:36.530): that are really useful, yeah.

Joseph Perry (23:43.154): Yeah, that's a great question. So I think one of the really interesting things about hype cycles in this context and the reason why we want to talk about it is that hype cycles have been a known and studied thing in AI for a very long time, for decades and decades now. And a hype cycle really only refers to AI's relationship with the public, not actually with the growth of the technology itself. Basically, the idea here is the public catches wind of some new innovation in AI, chat GPT, which actually before chat GPT was deep fakes that caught everyone's attention and then chat GPT kind of...

Aaron Crow (24:10.830): And now they're just like, my God, this thing is crazy, which it's been around, right?

Joseph Perry (24:13.298): Right, right, exactly. And so it gives everybody gets really hyped up. We start hearing the predictions of, the global economy is going to grow by 5 % because of this, which is a wild and goofy prediction to make about any technology except for like harvesting wheat. But anyway, so then we move into the phase where it doesn't manifest those those predictions. It doesn't give us those things. And everybody says, this technology was actually always stupid and useless and we don't need it. We're going to throw it all away. And then we move into sort of the stasis period before the next type cycle. So in this current type cycle,

Joseph Perry (24:42.034): We're right getting into that third stage now where a lot of folks are starting to say, well, we're spending all this money on AI. Where are all the promises? Why isn't it materialized? And why aren't we getting anything out of this? But folks are kind of missing that we have actually gotten a ton of stuff out of it, like a huge amount. For example, one of my favorite things about this is medicine. In the COVID pandemic, one of the main, I don't want to say the only thing that cured COVID or helps solve the pandemic. One of the biggest influences in the pandemic being

Joseph Perry (25:10.194): solved as fast as it was and the cure being developed as fast as it was is AI, is basically a machine learning model that is similar but not identical to the way chat GPT is designed with all of the different pharmaceutical research organizations across the world that were doing research into COVID, pooling their research in one of the greatest acts of humanitarian medical technol technol technolagism in human history. It's a hard word to say technolagism. But the idea is, you know, that we are seeing in medicine, we are seeing in finance, we are seeing in cybersecurity.

Joseph Perry (25:39.634): these really complex analytic tasks being made not trivial. You know, it's not, I could not develop a drug with the help of AI. It doesn't matter how good the AI is. I'm an idiot when it comes to drugs. I'm not going to be, I don't know anything about chemistry, but somebody who has a bachelor's degree today now has a much more, a much more effective ability to contribute to their team than they would, you know, five, 10 years ago where they had to manually look up each thing they had to go through this process.

Aaron Crow (25:56.258): Hehehehe

Joseph Perry (26:6.386): And that's not using chat GPT, that's just using tools that are built on similar designs, where they have these data sets that it's trained on. So we're finding in all of these really niche areas that AI that's not necessarily identical to chat GPT, but is very similar in the concept and in the design of neural nets that are trained on data sets that are curated and that generate new information as a result of those data sets. So those are the areas where in really niche fields where we already have deep domain knowledge, where we already have this corpus of information for the AI to be trained on.

Joseph Perry (26:35.154): That's where it's really, really impactful. Most of those places have already been using big data or data science in that direction for a while. So to them, it feels a lot more like kind of a one step up rather than the dramatic revolution that it actually is. But under the hood, it's a really significant change. So that's the biggest area. The other area that I think it's worth calling out is AI is really good for criminals and fraudsters. Like it's so, so easy to do a fraud right now. I don't want to advise anyone to do it, but I like, I have seen more

Joseph Perry (27:3.570): fraudulent emails, more fraudulent letters, more convincing frauds in the last 18 months than in my entire career before that. And I saw a lot of fraud before that in my career. It was not a rare thing before that, but it's such a powerful tool. And not just for overtly fraudulent, but even for the kind of like shady, two -person basement consultancy that we see a lot of in cybersecurity, it's very easy for them to all of a sudden have a professional or semi -professional looking presence.

Joseph Perry (27:30.226): statement of work and all of this that can give a client a really, really positive impression of what they can do. And then, you know, they actually work with them and they find out that it's a bargain basement consultancy. So I don't want to say that that's all AI is good for, but it is really, really good for fraud.

Aaron Crow (27:45.038): Yeah, you know, I've seen some of that talked about and really diving into it though, right? Is the emails you got from the Nigerian prince, right? You know, the language was bad. It was obvious if you were, if you really paid attention, you know, it was obvious it wasn't right, right? But now they can take those same scammers, can take that copy, put it into chat GPT, say this is designed for a United States, you know, they can get specific. This, I want to focus on people in Texas.

Aaron Crow (28:14.126): So I want to talk like a Texan would talk or a Californian would talk or whatever. So that language barrier and noticing the... Exactly, right? So it's harder to notice the differences in language and it's very easy to take a tool like this and copy and paste, right? And get out this really a lot better looking, easier to...

Joseph Perry (28:20.498): please write this email in the style of a 60 year old from Houston. Yeah.

Aaron Crow (28:43.374): assume is good, especially with somebody that doesn't do like you and I will probably notice a lot more likely than others that don't do this for a living. Exactly, we get them all the time. We're seeing it from we've seen really good ones and we've seen really poor ones. I mean, it kind of everything in between. But we're also trained to look for those things. Whereas, you know, my grandmother that is, you know, in her 90s, she's just assuming that well, she got my wife has even got, you know, the text, you know,

Joseph Perry (28:51.858): Yeah, we see hundreds of examples a year.

Joseph Perry (28:59.442): Yes, absolutely.

Aaron Crow (29:12.986): you want a Walmart gift card for a hundred dollars? Just click on this link and sign up, right? Those things are getting better and better. And chat GPT is definitely a, a, a tool, just like anything. And I think that's the good point to really focus on here is it is a tool. It's like a hammer or a pry bar or whatever. You can't just expect the tool to do all the work. Like you still have to wield it. You still have to do something with it and you have to instruct it and guide it.

Aaron Crow (29:39.534): and you're gonna get different results depending on how good you are with that tool. So an expert, you know, I can take the same tools that, you know, a 30 year expert craftsman that builds cabinets, I'm not gonna get the same quality. I can buy all of his tools, materials and everything. And I'm not gonna build the same quality of cabinets that he has, cause I've never, I haven't been doing it for the past 40 years. I can't expect to take that tool and get the same results that he does.

Joseph Perry (30:3.250): Absolutely. And that alludes to kind of the thing that's important to understand here about the way scammers use generative AI. And chat -chipity is probably the biggest, but they are also using things like mid -gen where they're creating images, where they're using video generation. I can't actually remember the name. There is actually like one GitHub project that's responsible for 95 % of all deepfakes, and I can't remember the name of the project off the top of my head right now, which is for the best, because I don't want to advertise for them. But yeah, so it's...

Aaron Crow (30:27.086): Exactly.

Joseph Perry (30:31.250): The thing that you need to know about attackers is they're not just attacking you. They are sending millions of messages, tens of thousands at least of messages out. And it used to be that wasn't that big a deal because they still had to have somebody on their side writing those emails. And so yeah, they can A -B test against 10 ,000 people, but they're looking at a click rate of 0 .001 % versus 0 .0015%. It's really just not a big deal. Whereas when they now have Chat GPT, they can give them hundreds of examples of potential uses right out of the gate. Well, now I can A -B test. Now I can do, you know,

Joseph Perry (31:1.298): really good audience testing across all of those different examples and figure out, this one has a click rate of 5%, thousands of times better than anything we've ever seen before. And so that's where fraud has always had this industrial, not always, fraud in the last 50 years has developed this incredibly powerful industrialization to it, but it always lacked inputs because there was never anybody willing to, there wasn't really anybody willing to sell their good exploits to those folks. There wasn't anybody really willing to do the hard copy work for them.

Joseph Perry (31:29.842): All the stuff that we see in the more advanced, like the Russian threat actors who are really, really advanced, who have assets in country who will write emails and do things for them. A lot of these scams fronts, a lot of these really large industrialized fraudulent organizations, they didn't have access to that before. They were kind of considered the lower rung, the lower class of criminals. And now that doesn't matter as much. Now they have access to that input. And so that's the way in which you call it a tool and you're exactly right. The most powerful tools are force multipliers. And that's all this is, is a force multiplication.

Joseph Perry (31:59.858): Now that's not to say it's not a tool that we need to consider carefully. As the Hong Kong case, last year somebody sold out $25 million given to a fraudster as a result of a video call where the fraudster used a deepfake to create an entire room full of people who were like, we need this right now, we've got to get it done, it's a secret, it's such a big deal. But if you're a finance person who's never really dealt with this kind of fraud before and you get on a conference call with 10 people,

Joseph Perry (32:28.178): Of course you're going to believe it. Of course you're going to think that's real. So it's that area where fraudsters are now, they get to take this industrial engine they've been building for 50 years and all of a sudden they have really, really high quality gasoline to put into it. And it used to be they were working with basically just mud and whatever little bit of fumes they could get out of that mud, that's all they could get out of their engine. But now they have what that engine was designed to run on. And that's a very, very scary.

Aaron Crow (32:51.054): So how does all of this adjust and change and shift as these new emerging technologies are coming in the instant response world, right? So we have all these things and capabilities driving how we have to respond. And we don't wanna be too far behind the eight ball, but obviously we are, incident response implies, right of boom, right? The thing has happened and now we're responding to it.

Joseph Perry (33:12.722): Yeah. Yeah. And that's so, I think the biggest change is that, you know, it's always been true that in incident response, we're always, there's always going to be some social engineering element to the attack. Whether it's a phishing link that got clicked, whether it's an actual phone call that happened, whether an email went back and forth. There's in almost every incident I've worked across my entire career. And it's been way too many incidents. There's been some element of it that we would classify as social engineering.

Joseph Perry (33:38.930): No, that's not really an innovative or exciting thing to say if you work in IR or you work in red teaming, you already know social engineering has been key to the process for 15 or more years. The big thing that we're seeing now, however, is that between ransomware and AI, social engineering is often the whole incident now. It used to be the attacker would get into your environment and then they would need to get privilege escalation. They need to establish persistence. They need to move through the environment. They need to get all of these different systems. Now, a lot of the cases I see are the attacker got a click by 10 people in the organization.

Joseph Perry (34:7.794): figured out which of those 10 people had access to reasonably important data and hit with ransomware, whatever systems they could get access to. There's very, very little process inside the environment. You know, when I started in incident response, we would talk about dwell times of 140 plus days where the attacker really carefully mapped out the environment and understood everything, got to know everything. Attackers are now much more figure out what part of your infrastructure is critical, find a way to touch that part of your infrastructure, shut that thing down, move on.

Joseph Perry (34:33.810): There is data exfiltration that still absolutely happens. There's still that theft and that extra ransom, but it is more and more those attacks are getting shorter in their cycle and they're getting much more tightly focused on just getting that initial access through social engineering. That's not to say there's no technical aspect to it, but I've definitely seen a lot fewer really technical incidents in the last few years. I would also say, you know, from the incident response perspective, one of the things that's the biggest difference is most of the time the attacker that you're investigating

Joseph Perry (35:1.746): is obviously trying to avoid getting caught. They're obviously trying to avoid the security tools, trying to act in whatever way is going to be most stealthy. But I should say, obviously, that used to be the case because the case was that the attacker had some ODA, they had access to this environment and they didn't want to burn their access. Now in this age of industrialized processes where they have AI doing most of the first pass stuff for them, they've got a scanning tool finding the low hanging fruit and the AI is doing it and they're deploying the AI script automatically. They're not touching anything manually.

Joseph Perry (35:30.258): A lot of that has gone away. So a lot of attacks are getting kind of noisier and clumsier. We're seeing a lot more of those, those script kiddies who before would be able to hit like five companies a month are not hitting a hundred or 500 companies a month. And so as a result of that, the average attack is getting a lot louder. That's a good thing from the incident response perspective in that it's a lot easier for me to find and be like, yeah, this person's using a 10 year old exploit. Like you should have patched that, but it is also very easy to catch using a modern SIP. So it's, it's, we're seeing a lot of those kind of low hanging fruits.

Aaron Crow (35:41.102): Right.

Joseph Perry (35:59.954): that used to go by the wayside, used to kind of escape notice are now being hit because the ocean, so to speak, is sort of drying up as everybody is targeting on an industrial scale every possible target.

Aaron Crow (36:11.950): To put it in sales terms, it's almost like the cost of acquisition has reduced to a point where they're willing to spray and pray more often. And yeah, right. So is it also that they're less worried about maintaining that access because they're more confident that if you clicked on it once, I can probably get you to click on, I'll just change the attack and get maybe not the same person, but somebody in your organization. I'll get access through another way again, if you find me today.

Joseph Perry (36:19.698): It's exactly it.

Joseph Perry (36:39.314): There is definitely quite a bit of that. And I think one of the things that's really helpful in understanding this is that it's not so much that old attackers have changed their process as that new attackers who use a process that didn't used to work, now that process works. And so exactly what you're talking about where the attacker, the sort of attacker that we used to be worried about is somebody who's really focused, really subtle, really attentive. They get one point of access and they don't want to get caught because if that gets burned, their whole attack chain might get burned. Whereas now when we're dealing with somebody who's willing to be loud.

Joseph Perry (37:5.682): they'll send the same phishing email to 15, 20 people in the organization. And if they get a click through on all of them, they'll start exploiting all of those people at the same time. They'll start hitting all of those at the same time. So it is absolutely what you're seeing. I don't necessarily think it's necessarily because AI has caused a change in practice so much as AI has enabled what we in this field would consider very bad practice.

Aaron Crow (37:25.582): Sure. Yeah. And it just allows bad, you know, again, that tool is leveling up people that don't have that skill set. Maybe they're, they're not at, you know, the script kiddies is a great example. And if, if, why don't you explain what that is for some may know what that is and some may not.

Joseph Perry (37:37.382): Yeah, yeah, that's a great question. This is kind of a parallel. So if you're using marketing and sales as the example, if you work in marketing sales, you're probably aware of this huge influx of people who have absolutely no idea what they're doing, but have decided that because they have access to chat GPT and it can spit out their sales script for them, now they're a salesperson. Same thing's happening to us. So script kiddies are folks who we would think of as being not just not very good at what they do, but all they're capable of doing is

Joseph Perry (38:5.874): running a script, in other words, using a tool that someone else created for them. That term got popularized with the low orbit ion cannon incident of like 2005 or something like that, like a very long time ago, where a tool was created, a DDoS tool, a distributed denial of service tool was published that leaked to the user's email address. Anybody who used the tool, it was a cracked version, anybody who used that version of the tool, their email was essentially just sent straight to the FBI and hundreds of people got arrested as a result of it. It was a huge take down.

Joseph Perry (38:35.122): And so that kind of cemented this contempt in the environment because the cracked version of the tool wasn't introduced by law enforcement. It was a hacker who did it to like screw with people. And so there's the folks who just use tools without understanding them have often been held in contempt by the industry because they just get their hands on a tool and just spray and pray it, which is exactly what we're seeing with AI.

Aaron Crow (38:55.054): Well, and now we even see, you know, chat GPT able to take those existing tools that may exist and maybe I can put it into chat GPT. Maybe I don't have the programming chops to really create something on myself, but I can say, Hey, adjust this to fit into this environment. So it's adjusting in to fit a certain type of environment, a vulnerability or whatever. So you're using again, tools. I don't necessarily have the capability to do that just in coding myself.

Aaron Crow (39:22.734): but I can use tools like chat to PD to kind of help me. And we've seen a lot of that happening too, where chat to PD is just helping them adjust, take a tool and, and modify it to fit a certain scenario.

Joseph Perry (39:34.066): Yeah. And that's, and you talked earlier about, you know, a tool, a chat GPT is just a tool and that is kind of what's happening here is people are getting really, really good at using chat GPT in and of itself, just using this tool. And so now they're able to adopt it to lots of scenarios. And one of those scenarios is this kind of attacking. So I, for example, we use chat GPT when I'm researching a new topic, I don't use chat GPT to give me the answers. I use it to develop my reading list, to develop my like study guide, to develop my syllabi, to help quiz me, stuff like that. I use it for processes like that.

Joseph Perry (40:2.514): to help me develop knowledge really, really fast. Attackers do essentially the exact same thing to develop new exploits or to get access to your environment. So if I'm a script kitty and I see, you've got a login page, well, I remember reading a blog that said SQL injection attacks work against login pages. So I'm going to go to chat GPT and say, please give me a SQL injection attack to use against this URL. And it's going to spit out. Probably it'll tell me, no, it's not allowed to do that. And I'll need to massage my request a little bit. But if I'm really good at using chat GPT, that's not a struggle at all.

Joseph Perry (40:31.602): And so I can, even though I, all I know is that's a login page. And I remember reading somewhere that SQL injection is a good way to defeat login. Chat GPT can do all of the other work for me. And so because I'm good at using this tool, I'm now again, not really like a high quality, because if I, as an, you know, as a security professional who has more than a blog level understanding of security, I'm probably not just going to hit a login page with a SQL injection out of the gate. Cause I'm aware that that stopped being useful on most organizations like 10 years ago, but there are, as I said before,

Joseph Perry (41:0.274): all those low hanging fruits who kind of got away from notice, avoided being caught before, now folks are trying attacks against them that would have been disregarded as non -viable. But yeah, it's that script kitty, that sense of, it's not about knowing everything. It's not even necessarily about being good at everything. It's just figuring out how to use one tool to solve as many problems as you possibly can.

Aaron Crow (41:22.382): Right. Well, let's dive a little bit into threat intelligence and what we're seeing in the space. And it's not that the space has changed all that much, right? I think we've seen, we've always had nation state actors. We've always had people that are just bad actors that are, whether doing it for financial purpose or because they're a disgruntled employee or they don't like the company or social activists or whatever the hacktivist type folks, the same categories have always existed.

Aaron Crow (41:52.174): I think the tools have adjusted and maybe made some of the others more having more access or success even, even more attempts at that, right? Even just swinging more often because they have access to this. So dive in a little bit around that threat intelligence that we're seeing in the space.

Joseph Perry (42:10.642): Yeah, absolutely. So, you know, in general, when we're talking about threat intelligence, there are a lot of approaches to it. And I always try to take the approach of for a given organization, this is the thing that's most likely to be your problem in the next X time. So 30 days, 60 days, 90 days, one year, whatever the case may be. And it used to be for most organizations, I would talk to them about your biggest fear. Most organizations, biggest fear is just getting in the news is just being on the front page. That's what's going to draw them. Right. Not just bad press, any press.

Aaron Crow (42:33.998): Sure. Bad press.

Joseph Perry (42:38.546): because that's what's gonna draw a lot of eyes to you. That's when most attackers are gonna take their kind of first pass at you with a scan to see what they can hit. And so that's what you need to be prepared for is those moments of notoriety. And so you need to have more attention around those, more preparation around those. That's not really as true anymore because what I've been talking about a lot with this industrialization, this kind of grinding process that's been brought up by a lot of these kind of script kitty level actors is that...

Joseph Perry (43:3.378): The thing that makes you most likely to be hit now is just being under a certain threshold of ease of access. And so threat intelligence, you're absolutely right. Like the categorization of the process of discovering threat intelligence hasn't really changed. But the way I prioritize the way a lot of my peers in the field prioritize, this is the intelligence that we need to approach first. We need to care about first has changed. We're not really, we're still spending time on APTs. I'm still paying attention. I have clients that have been specifically targeted by Russian actors because of their response to sanctions, stuff like that.

Joseph Perry (43:32.594): I'm still being attentive to that and I still keep track of that, but a lot more time now is spent on, okay, this is the exploit that's being hit by 60 % of threat hackers in this space, or whatever the case may be. Even though it's not necessarily one that leads, it's not one that has access to the entire environment, only accesses one bit of data, we found that attackers aren't necessarily as concerned with that. They'll go in through this one open door, hit the low hanging fruit, and bet that they can get something out of the deal.

Joseph Perry (43:59.058): So a lot of what we're doing now is really shifting from an attacker model of let's deep dive this attacker and know everything there is to know about them. Because even the APT, even the really advanced ransomware gangs, they break up and reform and break up and reform all the time. And so it's not necessarily easy to keep track. So a lot more focus has now been given to sort of that technological side, the CPE tracking, the vulnerability tracking, the attack surface management, stuff like that. That's where threat intelligence is really tightly focused now. In terms of concrete kind of findings and things that I find really interesting in threat intelligence right now, my...

Joseph Perry (44:28.082): favorite kind of fact about threat intel is just that Russian hackers really don't know what to do and haven't known what to do for like two years now. I've worked with a lot of companies to do like ransomware negotiation and stuff like that. And ransomware negotiators went through a really bad period like a year or so ago now because nobody was doing ransomware because nobody in or around Russia really knew whether they were going to get called up to war or whether they were going to get blown up or like what was going to happen with their whole lives. So they just weren't hacking.

Joseph Perry (44:56.274): And so that's in terms of interesting things happening in the world of threat intelligence right now, we're starting to see Russian threat actors start to reassert, but it's kind of it's lawless, I would say in a way that it wasn't where there's a lot more vote, you know, where before we'd see like maze that would say like we don't attack hospitals or whatever. Nobody has those kind of rules anymore. There's none of that like honor among thieves mentality. It's really chaotic threat actors are taking work from one another. Threat actors are I won't give too much away here because this is something negotiators are really actively using in a lot of ways, but

Joseph Perry (45:25.586): One technique that is viable now that was not viable, say, 10 years ago is playing threat actors against one another and getting access to information, getting access to data, or getting access to systems simply because, as I mentioned, groups break up, groups reform, groups break up, groups reform. Finding disgruntled hackers who are willing to sell out their comrades is a lot easier now, but they're not part of this really big hierarchy that is eventually leading up to the FSB. So it's a really fun place to be, especially if you're a ransomware negotiator right now.

Aaron Crow (45:54.510): Yeah, that's interesting to see. Obviously all these world events happen and they impact and we don't always understand the downstream effects that are going to happen from, you know, something, you know, a butterfly effect that happened over there and what impact it's going to have to us here. So it's obviously for entities out there, like you can't expect to know all of this, right? So no more than I go out and fix my car. Like I'm a shade tree mechanic. I used to work on cars and things like that, but

Aaron Crow (46:23.182): My car today has more computers in it than anything. It's not the computers that you and I work on. It's a different thing. Doesn't mean I couldn't figure it out, but you know, if something's happening there, I'm not the expert in that. So I'm going to call an expert for it, right? So that I think we're seeing more and more in that today. You know, with all the focus on CISO now with their personal responsibility for impacts in their organization. And it's crazy.

Joseph Perry (46:27.858): Very different, yeah.

Joseph Perry (46:48.914): Since I was going to jail, yep.

Aaron Crow (46:53.070): Unfortunately, I think it's going to force it. And I think it's probably a good thing, not that CISOs are going to jail, but I think there's been a long time of CISOs that see in their name, really by name only. They didn't have the authority that a normal C -suite executive would have. They're not in the board meetings. They're not directly reporting to the board. They're sometimes two and three levels below the rest of the C -suite.

Aaron Crow (47:20.366): they're being held responsible for something yet they don't have the authority to take action. They don't have the budget, they don't have the authority, they're having to get those things pushed through others. So Bob told them no, and now I'm hold responsible because he wouldn't approve the budget, right? So there's all that's kind of flushing out and forcing organizations to put the responsibility and the authority into the right place so that because they know if something happens,

Aaron Crow (47:47.630): then we're all held responsible for this. We can't just, we can't choose the insecure option anymore because it's cheaper.

Joseph Perry (47:54.258): Absolutely. And the SEC has made it really clear they're not willing to play ball on that anymore either. They have become much more strict about, you know, whether it's reporting material incidents, they've given very strict timelines on that, whether it's yearly disclosures discussing the board's experience with cybersecurity, whether it's whenever a new board member joins, they need to detail their experience and knowledge of cybersecurity. It is very clearly a matter that is getting scrutiny right now.

Joseph Perry (48:17.650): And not just scrutiny in the sense of, you need to be secure or you're going to get in trouble. That's not what happened. The scissors who are getting, who are drawing legal attention. I'm not going to say whether or not they deserve to draw legal attention. I'm not a legal scholar. It's not my area. But the facts of those cases are legally interesting facts and are things that I would prefer a judge handle than you or me schmucks off the street. And so there is definitely an element, I think, where we are seeing those very serious, whether it's the legal process, whether it's auditing, whatever the case is, we're seeing what I might call very serious people.

Aaron Crow (48:37.230): Correct.

Joseph Perry (48:46.994): taking an interest in cybersecurity in a way that before we'd go to the board and say, hey, you need to care about cyber because if you don't, you might, and they're like, yeah, we need to care about cyber because if we don't, the SEC is gonna come after us. It's just a very different perspective for sure.

Aaron Crow (48:59.534): Yeah, it's the club, the stick instead of the carrot. And we see this in, you know, switching over real quick to OT cybersecurity, it's the reason why critical like power utility is so kind of further down the road than other, you know, of the 17 critical infrastructures. And part of that is from the compliance requirement to do so, right? So they have this, they don't, it's not optional. They have to do it or there's huge fines that we've seen implemented. So those fines impact, so it's not a,

Aaron Crow (49:29.134): We can, well, we're not gonna worry about that. Like $10 million fines I've seen given out. I mean, they're huge. So of course we're gonna do it. Yeah. So.

Joseph Perry (49:35.250): genuinely crippling for an organization. Yeah. Yeah. And that's because that's yeah, but it was just the last note on that because in critical infrastructure is a perfect example of that area where AI cybersecurity a lot of these tech fields they come from a kind of Silicon Valley move fast and break things you can promise it in marketing and then eventually we'll build it in prod. It's not a big deal critical infrastructure. Something goes down something goes down and that's a that's a real fact about the world that has changed and so it's got a much smaller tolerance for

Aaron Crow (49:57.838): Correct.

Aaron Crow (50:3.022): Well, and that's why the lead time on emerging technologies and all of this, we're 10 to 20 years behind some of the things in IT. Like we don't use cloud. We just recently in the last 10 years started really adopting virtualization. Like all of these technologies have been in the IT space for decades and we're just now getting comfortable with them in some of these critical infrastructure environments for the right reasons. Like from outside in, it's like, wow, you still have Windows XP running? Yes.

Joseph Perry (50:25.810): For good reasons, yeah.

Aaron Crow (50:31.406): It's not perfect, but it runs and it's harder. It would cause more problems than solve by just replacing that thing that you think is bad. So I'm going to, and we talked about this earlier, right? I'm going to put other mitigating controls around that instead of just replacing it. So.

Joseph Perry (50:44.466): Yeah. And that's exactly it. It's that, and it's something that a lot of computer folks, I struggled with it a lot in my early career. Every time I go to, I deal with the, I don't want to talk too much back, but construction clients were the ones that I fought with by far the hardest. Cause I would say, well, you can't give all your users look lab, but you can't do this with users. And they're like, okay, if we don't do that, tens of millions of dollars are lost on this building project because of this process has to change and this thing has to change and we have to go to this thing for I, we have to do all this. And it forced me to realize like, I can't just come in here as this.

Joseph Perry (51:12.818): on high security genius and be like, do all of these things and now you're secure. They're like, well, we do those if we could, but we have contracts that say that box is gonna stay a Windows XP box forever. Like we have agreements that say for safety reasons, we won't make changes in this environment. And that can seem genuinely ludicrous coming from the outside in, but once you've been in that space and you've moved in the OT in the critical infrastructure space, you start to understand that it's just a completely different value set and it's a completely different set of problems that need to be solved.

Aaron Crow (51:40.526): Absolutely. Absolutely. So we talked a lot today. Next five to 10 years, what are maybe one thing that you're excited about coming up over the horizon and maybe one thing that you're a little concerned about that you see that could be coming up over the horizon.

Joseph Perry (51:54.866): Yeah, I would say the thing I'm most excited about is probably the thing that has most people the most afraid, which is what we were just talking about, which is the fact that cybersecurity is starting to tighten down and get a lot more serious. I think in the next five to 10 years, it's going to get a lot harder to break into this field. I think most of the boot camps are going to evaporate. I think a handful of the online training programs will still exist. I think some of the certifying bodies will still exist. And I don't think it's going to get smaller because it's less necessary. I think exactly the opposite.

Joseph Perry (52:21.362): I think it's going to get smaller because it's more necessary. There's more scrutiny. There's more attention. You have to really be able to perform. And these shops that are charging $100 ,000 for a Nessus scan, they're not going to be able to stand up because people are going to start asking them hard questions. So I'm excited to see our industry start to really move towards more of sort of how we view the electric, the electrician. I said it wrong both ways. The electrical industry as electricians or plumbers, more of those skilled trades that have.

Joseph Perry (52:48.850): There is a very rigorous understanding of what a good electrician or a bad electrician looks like. There isn't really yet an accepted definition of good sock analysts versus bad sock analysts, but I think that's what we're moving towards and we're getting closer and closer by every day. So that's the thing I'm excited about. The thing I'm really nervous about is we, and by we I mostly mean cybersecurity leaders and business leaders. We've solved almost all of the easy problems and we've also solved most of the hard problems.

Joseph Perry (53:17.618): which means now we have this terrible habit of inventing new problems to solve. And we keep coming up with like, this is going to be your new, I don't want to say a specific technology because somebody will get really mad at me about it, but this is your new 15 word long cloud -based technology that maybe, maybe one in 100 technical employees will understand. And at most one in 50 ,000 people in the world understands. And that's not a good place to be as an industry. That's not, you know, that's

Joseph Perry (53:44.274): There are always going to, you're going to need that niche of specialization, that niche of, of deep experience. But if the technology you're selling is not something that you can explain to a normal human person off the street, it's probably not solving a real problem. because encryption, you know, one of the hardest things in cybersecurity, trivial to explain. Sometimes we need to keep data secure. That's pretty hard. So we have people who do it for a living. Done. Solved. I, whether it's RSA, whether it's Black Hat, whether it's DEF CON, I walk around these vendor floors and I ask people, so what does your technology do?

Joseph Perry (54:14.163): and three paragraphs later, I have no idea what their technology does. And like, I don't want to be jerk. I'm really good at, I know a lot about this industry. I can't begin to parse what that person is saying to me. So yeah, I think that's the thing I'm most nervous about is we have a really bad habit of just inventing goofy problems to solve. And I think that comes because of the thing that I'm excited about, which is we're moving into a much more mature state as an industry.

Aaron Crow (54:35.374): Yeah, and I see that too. Part of it's because it's the gold rush and there's a lot of money being dumped into cybersecurity. So you see a lot of people put, they've got a widget, they've got a as seen on TV, they've got a whatever, right? And they sell it and then you put it in there and then there's limited to no value, right? But they already got their money and they're gone, right? So there is a lot of that. I think there's...

Joseph Perry (54:41.394): lot of shovel salesmen out there, yeah.

Aaron Crow (55:1.870): There's a lot of big companies buying smaller companies. There's a lot of commoditization in product space here. I think we're gonna see that narrowing in people as well as products as we start doing this. That Forester thing I was talking about before, having things like that, I'm not trying to beat up on Forester. I think it's a great thing to have. I want to have some understanding of these things, but we need to be really specific in what we're looking at so that I know that I needed a firewall, but I also need an asset management tool.

Joseph Perry (55:6.006): yeah.

Aaron Crow (55:31.598): I also need something that does change detection and also need this other thing. Like it's not a, there is no silver bullet in any of these things. I'm going to have to have an ecosystem of capabilities, whether it be product driven people, it's people process and technology, right? It's, I need all those things. We're not there yet where we can just put in a tool and then I don't have to hire people and I don't have to have all the process in the backend to just do it all for me, right? We're just not quite there yet.

Joseph Perry (55:57.010): Yeah, in 2010, all we were talking about was how to get cybersecurity taken seriously and looked at as a serious problem. In 2015, all anybody was talking about was how do we standardize this? How do we have frameworks? How do we all agree on the language for it? In 2020, all anybody wanted to talk about is like, what's the future of the technology? How do we go from here? How do we get the next big thing? And where we're at now, and I think where we're going to be for the next few years is just, okay, what are our actual goals for this program? And how do we measure them? Not just in the sense of what we're doing 10 years ago, how do we measure success or failure in a basic way?

Joseph Perry (56:25.842): How do we measure progress toward a specific kind of nebulous security goal? How do we know whether or not a given technology should be adopted? And the answer to that, you know, the trite answer is just domain expertise. You have to have the right, whether it's in -house or consultants, the right folks who have the right deep level knowledge, but there's also a certain level of the right institutional mentality because it's really easy to have somebody come in here and tell you like the metaverse is the future. You've got to move your company into the metaverse. You're going to get hacked. And that's, that's obviously nonsense.

Joseph Perry (56:54.962): But why is that nonsense and somebody saying the same thing about AI isn't nonsense? And there is a difference between those two things, but you as an organization need to have the right kind of rational skepticism to be able to dig in and understand the difference between the two.

Aaron Crow (57:5.998): Yeah, absolutely. Awesome, man. I really appreciate you being here today. Anything you want people to know, come find you, all that kind of stuff. this is your, your call to action.

Joseph Perry (57:16.722): Yeah, absolutely. Well, I, you know, as I mentioned at the beginning, I work with Morgan Franklin cyber specifically in the cyber fusion center. you can find us doing all sorts of stuff, but especially you can get ahold of me, Joseph Perry at Morgan Franklin .com. I do, I think our next big event that we're doing is going to be black hat and Defcon where I think we've got our cyber lounge there. it's, I can't remember the name of the place that it's at. I'm terrible at doing blogs. The house of blues. You're so much more prepared than me. Yes. We're going to be doing an event to the house blues. It's going to be awesome. We did an event, you know, in San Francisco.

Aaron Crow (57:37.390): It's the House of Blues. House of Blues. Yep.

Joseph Perry (57:45.842): during RSA convention, it was awesome. They're really excited to do, yeah, just see folks and to have folks out. We'll probably be talking a lot about AI there and I'll probably be saying a lot of things that make people mad at me because everybody at that convention loved AI, the last one loved AI and didn't like what I had to say about it. But yeah, it's gonna be a great time. We love the conversation, we love meeting folks. And of course, you know, on a more business -y level, if you have a cybersecurity problem, whether that's an active incident, whether you're looking for a SOC provider, whether you need somebody to help you understand AI, please do get ahold of me. That's what I'm here to help.

Aaron Crow (58:15.182): Awesome. Yeah. Thank you. Thank you so much, Joseph. Definitely excited about other than the heat and all the things in Vegas during that time. But yeah, Black Hat and Def Con is always, always a lot of fun and, and, and getting in and diving in with all the, the, the users, as well as the other vendors that, that are in the space and looking at all the emerging technology and, and, you know, sometimes making them upset with us because we're like, yeah, I don't get it. I feel like in big, like, you know, when Tom, Tom Hanks raises his hands, like, I don't get it.

Joseph Perry (58:36.114): I don't think this does what you think this does.

Joseph Perry (58:42.034): Yeah, yes, I feel that so often. All right, well, thank you very much, Aaron. It's been an absolute pleasure to talk to you.

Aaron Crow (58:45.454): Exactly.

Aaron Crow (58:48.750): Thanks, sir.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.