00:06
All right. Welcome everybody. Hello, hello. Greetings and welcome to, another edition of Tech Talks. I'm your host, Jason Walker. I'm a director of technical strategy for cyber resilience, here at Pure, and today's episode is going to be know thy enemy.
00:23
A deep topic, threats to cyber resilience. We're gonna go over a lot of cover a lot of ground in cyber resilience. And helping me to do that today, two amazing guests. Five-star co-stars, if you will. First we have, you know, Scott Taylor.
00:38
And there's Scott, welcome aboard. Thank you, JSON file. I'm excited. I don't know how you couldn't be after that really big hyped video that we just watched about data. Kinda hard to, to not be awake after that one. That's right. I thought I heard it say
00:52
gator in the very beginning. I, I, I got really excited, about that. And, and joining Scott today, Chris Brandt. Chris, welcome aboard. Hello, everybody. Well said. Well said, Chris.
01:04
We are gonna get into it today. Well, we're gonna break, break the ice a little bit. All three of us were at RSA, and, I would love to hear kind of your thoughts about, what you, what you saw out there. Well, let's, let's start with Scott first.
01:19
Scott, what were your impressions of RSA this year? What is, what are folks dealing with? Well, it's fir- first of all, it's just a massive conference, right? 43,000 attendees. There are a ton of people out there.
01:32
Really, and global, right? I, I saw a lot of people from all over the world that attended this thing. And I really think there are two things, and I'm not gonna go too deep in this, 'cause I, I have a feeling we're gonna talk a little bit more in depth as we go about this. But identity, obviously, we like to say that people aren't breaking in, they're logging in,
01:48
so identity was a huge thing. But the even bigger thing, as you might imagine, was AI, right? I think there was some kind of contractual obligation that AI had to be the talk track. And most of that, quite frankly, kind of in a negative way for us as defenders, and we'll get into that a little bit more. Yeah.
02:05
But certainly AI was kind of the dominant theme that I saw, whether it was on the expo floor, or keynotes, or during any of the actual breakout sessions. Yeah. Chris, what did, what did you see out there? I, I would agree. I- every single booth had something about AI in it, and AI is certainly representing a really huge threat vector, but it's also an,
02:27
an important tool, and it's an important thing to protect, and I think we'll get into that. But, the other thing I, you know, the overall sense I got from everybody was that, everybody's business models had been completely upended this year, and I think everybody was kind of scrambling to figure out what the new message was, this is a radically different new era we're stepping into, and, and it's gonna require
02:53
really big changes for security platforms. Yeah, absolutely. I mean, I think what, what we saw out there was, you know, obviously a preponderance of that, but it's really just, just another vector of what, what the folks are dealing with out there. So Chris, let's start with it.
03:09
There's, there we are right there if you wanna know our, our titles there. Let's start with it. Let's talk about the threat landscape, of what's, what's happening out there. Chris, what Give us a couple. Give us a couple. And I know we could, we could probably spend a
03:22
whole hour- I- talking about the landscape we, we could spend an hour on this. But yeah, I mean, I think, you know, when we, when we talk about, cyber extortion events, we're really typically talking about, people who are financially motivated for this. And then, you know, we have the other category, which is more the advanced folks, which are tend to be the, the, the nation state actors.
03:42
And, and unfortunately right now we're kind of seeing a, a convergence of all that because, you know, a lot of nation state actors are, are, are actively targeting, companies with more sophisticated attack. But I think what we're seeing is there's a lot of ransomware-as-a-service out there. So these are, services that have, you know, tech support, they have, you know,
04:07
satisfaction surveys. They operate like real businesses, 'cause they are really big businesses, and they have these attack frameworks in there so that less sophisticated attackers, the more financially motivated folks, can get in there and launch these attacks, which is one of the reasons why recovering from these, you know, by getting the keys and things like that oftentimes
04:27
doesn't work out, because these are not particularly sophisticated attackers who can, who can, or are going after you. But one thing I wi- will say is that we're seeing, from an attack perspective, we're seeing, the rise of, data exfiltration is becoming more of a significant threat. So when they get in, within the first minutes they start exfiltrating data.
04:51
They tend to linger, you know, 7 to 14 days before, you know, really doing any kind of deletion or encryption event. But I think that, one thing that we all have to be really sensitive to, that most of these attacks are coming through unpatched vulnerabilities, and a lot of those from a supply chain.
05:11
And I'm not sure if you noticed the Axios, attack that just was announced the other day. 83 million downloads weekly on that one, and that was a, that was a big, big attack vector. So we're seeing a lot of that stuff. We're seeing, ITW attacks, IT worker attacks, and largely, like, Korean, North Korean nationals are getting, applying for jobs, getting hired.
05:36
They're, they're getting laptops, getting access. They're using laptop brokers here in the US to tunnel through to, to get at these organizations. So really folks are getting hit from every single angle possible right now. And it's just getting, getting more and more significant.
05:56
So I'll let Scott jump in on it now. No, I think the You know, you hit a lot of these things, right? And the-The IT workers, right? From, from some of at least our US foreign adversaries. You know, the recent kind of story was they're generating something like $500
06:13
million of revenue for North Korea. So this is not a small thing. You know, we actually saw several vendors at RSA who their whole business is actually being able to detect these deep fakes kind of in real time. Right. So when you're doing these interviews, they
06:31
can figure out, are you inter- actually interviewing a real person? Are they actually the person that they say they are? That was actually a pretty interesting thing out there. So you're, you're getting hit kind of from all angles, even your own employees. Some of these individuals even get promoted inside of these organizations.
06:46
So that's the crazy thing. They're not just coming in looking to, you know, exploit. They're generating revenue, and they're actually doing good work, to the point that some of them are getting promoted. Of course, it's when things go wrong, right, that we have to worry about that. But it's Yeah, I, I think the other thing customers just have to think about is you've
07:02
never seen more variety of threats from more different vectors, if you will. Right. And, you know, I can't remember, Chris, if you just hit on the supply chain or not, 'cause you and I talk about this stuff all the time, but how do you know? Now even your, quote, trusted software might be a backdoor into your environment. How do you, how do you protect against that?
07:23
Yeah, and some of these- That makes really difficult some of these supply chain attacks are, are, you know, components of other software, so they're getting incorporated- Mm-hmm you know, without a lot of review too. So it, it, it's a, it's a complicated issue. And, and that's why you have to focus on, on the recovery side of things,
07:40
w- with your business. E- exactly. We, we talk about things like, third-party risk, right? But really, to your point, you're now having to think about fourth-party, fifth-party, sixth-party risk because other companies are using other companies, whether it's inside the software or even in their own environment, to per- provide these services.
07:58
And so it could be way down the line where you actually become vulnerable, and you wouldn't even know it. Yeah. It's very interesting. Insidious. Insidious. So Scott, what, what are they after? I mean, what, what are these attackers after?
08:10
I mean, is it just a, is it just a joyride like we used to do in college, or just lawn driving through somebody's yard out there, or what, what are these attackers really Well, you know, the first thing, JSON, I didn't realize you were still in college, cause I saw some joyriding last week, when we were together. But- it really depends on who it is.
08:30
Now, the interesting part, we just kind of mentioned the North Korean IT workers, and they are actually generating revenue for their government, right? So sometimes they're after money, but they're not doing it in, you know, the traditional exploit way, holding somebody for ransom. But it kind of does depend on their motivation.
08:45
We see, obviously, and hear a lot about the financially motivated threat actors that are out there. They're after the money. They're going to encrypt your data. They're gonna steal your data, hold it for ransomware, et cetera. We kind of know that drill at this point.
08:57
The other big one, and especially given current geopolitical events, are these nation state actors. And so again, North Korea, they might be after some revenue, but realistically they're in for things like espionage. They're lying in wait. We've seen some recent attacks that, everybody has, has a news reader that
09:15
go read the stories. We won't, we won't name names, but where they had tens of thousands of devices just wiped out. There's, there's no demand for a financial payment. Their motivation was to cause chaos. So you have to be prepared for all of these attacks.
09:30
You have the people that are gonna extort you for money, and you have that are basically siphoning off your data for espionage purposes, as well as kind of laying in wait for a geopolitical kind of event to happen where they do a strike. And they're not, they're not gonna be after your money. They're gonna be kind of going after destroying your environment, right?
09:48
And causing chaos in the world. Chris, anything to add on that? Yeah, you see a lot of that in specific sectors as well. Yeah. Yeah. Well, you know, and Chris, we, we would think about this. You know, WEKA- think about the nation state,
10:01
and you were talking about it a little bit before when you mentioned ransomware as a service. W- these used to be these super criminals that would be tucked away somewhere, and you know, they We always think of them as the black hat and, and de- delivering all these things. You had to be a really good, hacker to be able to leverage that.
10:20
But Chris, you mentioned the ransomware as a service. Really, that's not the case anymore. No. Yeah, no, it, it, it These are not sophisticated attackers who are largely financially motivated. I mean, there are some.
10:31
But if you think about it, they You know, these ransomware-as-a-service offerings can bundle up these nation state actor attacks and give them to people. It's, it's sort of like handing a toddler a handgun, you know? And, and so you, you've got a lot of firepower behind them, but they, they particularly sophisticated.
10:52
I think about those old The movies where the, where the, the cowboy gets transported in time, and he finds a futuristic, type weapon, doesn't know how to fire it. He just pushes a button and something extraordinary happens. But it But these folks are creating, you know, chaos. They're, they're leveraging these big nation state tools, Chris.
11:11
And, and, really can cause even more damage than maybe they're even thinking, so it makes it even more difficult to recover, I would imagine. Yeah, for sure. I mean, there's definitely a lot of, collateral damage when they do this. I mean, you, you see them, they go in, they delete, you know, data.
11:28
They, they erase all the snapshots on devices that are not immutable or indelible. They'll go in and delete the logs. They delete backups. They attack identity access management systems. So, you know, recovery needs to be done at a massive scale.
11:43
Yeah. So, you know- Yeah it, it's a challenge. So the landscape, you know, is, is diverse and is becoming more chaotic every day. And like we talked about at the top, we couldn't turn our head, Scott, without seeing some sort of, you know, AI impact. What i- what is the, What is AI's role in all of this as we're seeing today and moving
12:07
forward?Yeah, it's interesting. And, and of course, when you go to a conference, you kind of expect to walk away being scared, right? Because that's just- Yeah that's just the nature of the beast. Right. It's all doom and gloom. However, I, I think we're facing real here, and there were a lot of examples
12:23
And this is where right now really the adversaries have a little bit of an advantage with AI versus what we have as defenders. And, you know, whether you believe AI is, is helping productivity, you know, lots of studies around, you know, AI projects failing or not delivering an ROI, whatever it's pretty real in this space.
12:43
Agentic AI is being used to, move at a speed that humans could never think of moving. We're, we're seeing them uncover vulnerabilities. Chris talked about vulnerabilities being, you know, one of the top, ways people are getting in. They're uncovering things that have been out there for 10, 20 years that humans have never found.
13:02
Right? And unlike Chris, who loves to take lunch every day, I'm working on that, but he still does it, they don't take lunch. They don't sleep, right? There's, there can be multiples of them, and they're moving at machine speed far faster than any human is actually able to work and operate.
13:18
So they're uncovering these vulnerabilities. Not only are they uncovering them, they're starting to have the ability to really create the exploits kind of on the fly. There was one talk that I listened to where, I think it was a former NSA, you know, red team kinda guy, and he talked about there was a hacking contest.
13:35
There was 125,000 hackers, and there was somebody that entered an AI agent basically into this, and it outperformed 99% of the human attackers. So the best humans in the world still won at the moment, but it beat 99% of the human attackers. And it was putting together, chaining together, if you will, exploits in ways
13:58
never even thought of before. And if you think about how long people have really been doing this whole LLM-based stuff, it's not very long. So we're still kind of early days on some of this technology, and it's already better than almost every hacker that exists. So it's quite, it's quite scary.
14:15
The other thing I, I wanna mention really quick before I let Chris chime in comments, I know he's, he's chomping at the bit over there, is as companies are using AI, and we've seen this recently, like, in people's own personal environments, but we've seen some company names. Again, I'm not gonna call out the guilty, but everybody can look up the news stories, people have let AI have some autonomy, and
14:36
it's actually brought down their environment. Or in the personal world, it's, bought some things that they didn't think it did. It, it deleted emails of a prominent, person at a social media organization, I believe it was. So, you know, AI itself, even when used for good, can have some unintended consequences that you need to be able to account for inside
14:57
of your environment. So Chris, I know you, I know you got some thoughts here. Well, yeah, yeah. What are you thinking? I mean, y- you, you're seeing things, you know, Anthropic uncovered an attack where broken the attack into such small discrete components, it didn't look like an attack. So they're using existing, you know, publicly available AI frameworks to, to,
15:17
launch these attacks. And then, you know, you're also seeing that they're multimodal. Like, you're, you're getting, attacks on multiple fronts, something that we didn't see human attackers- necessarily do, where AI is using social engineering both on humans and agents, and it's build You know, it's launching larger attack frameworks.
15:36
It's, it's, it's getting in, and it's rewriting itself through the use of AI/ML that's publicly available, you know? So i- it's, it's a, it's a very complicated, attack framework. And I think the other thing that, that, you know, is, is challenging is we're seeing that, you know, with the rise of agents, you know, agents security of our agents has
15:59
a really complex issue. Yeah. And you're having agents that are attacking agents or and running around their restrictions to access things by accessing other agents that do have, access to that data and going through, through there. And I And, and the other thing that we're seeing on the other side or the flip side of,
16:19
of that is, you know, we're all relying on AI right now, but there's a lot of attacks against AI itself. So you're seeing things like data poisoning attacks and things like that- Right where they're not necessarily exfiltrating data, but maybe going in and changing weights so that you get, you know, incorrect results out of your, your LLMs, or your, your RAG models are
16:39
getting, you know, corrupted. So AI is having a huge impact in this, in the, the attack side and the defense side and, and the vulnerability side. So it's, it's a really, getting to be a really complex area that's moving so incredibly fast, it's really hard to keep on top of.
16:58
Um- Yeah, and the big thing that was clear, too, out of this conference is human versus AI doesn't work, right? Yeah. We, we heard, a good bit, and I kinda like some of this, th- there's a lot of talk in the world of AI around human in the loop, right? We don't wanna take the human out of the loop.
17:11
And in the security world, what we're really hearing is that's just It's impossible, right? Humans cannot keep up with the pace that, of, of AI, and so we have to think about human on the loop. Maybe AI's advising us. We're setting strategy. We're trying to have governance over it.
17:26
But if we try to go human versus machine, the machine's gonna win pretty much every time, right? It's gotta be AI against AI. Yeah. And- And that, and that's hard because in the past, security has been a very deterministic sort of thing. We've, we've had, you know, polymorphism and things like that where, you know, code is
17:44
changing to avoid detection. But, you know, now it's, now it's, it's, it's way, way more complicated 'cause you have to trust these non-deterministic systems and feel okay about it because w- we as humans can't do this fast enough.Yeah. So basically what I, well obviously what we saw at, at RSA is that AI is an accelerant,
18:06
and I think we're experiencing that. We're, we're watching things, like you said, Scott, accelerating at a, at a high pace. And basically, you know, when we, when we talk about human on the loop or like that, basically what I'm hearing is that Skynet is inevitable. And, we should all, we should all welcome our new ter- terminator overlords as soon as
18:27
possible there. Only- I like to think of them more as Cylons, honestly. Because we're seeing a lot of activity happening in, biological, AI/ML approaches too, and chips and things like that. So we may be, we may be part of Battlestar Galactica soon.
18:44
Oh. Yeah. And also, you know, one, one thing to keep in mind is humans still make mistakes. If you saw some of the, the recent news, one of the prominent AI companies had their, source code accidentally- Right leaked out. Yeah. And, that's not great, right?
18:59
Because now they're, you know, now people are able to more easily go back and figure out how it works, duplicate it. Again, a lot of these threat actors aren't necessarily using the frontier models, right? Mm-hmm. Because some of the frontier models are trained to build in protections to keep people from doing this stuff, so why would you do that, right?
19:14
And we just You know, th- that leak potentially helps, some of these threat actors enhance the models and things that they already have that won't include these safeguards and allow them to do some of the criminal activities. Sorry, JSON, you were gonna add something else, and I just I had to throw that in, cause I think that was actually a pretty big bit of recent news.
19:33
Yeah. Absolutely. You know, it's, it, it We talk about, we talk about And as we move into kinda how we counteract all that, 'cause it sounds, you know, we bring up Skynet, we bring up, you know, the Battlestar Galactica. It seems, like a fait accompli that we're doomed, in this way.
19:52
But, but there, there are countermeasures, Chris, that we've, you know, begun to look at fighting. And Scott mentioned a little bit about, you know, what I would call spy versus spy, the old Mad Magazine, type thing in there. But, what are some of the ways we're countermeasuring, this, this We saw the threat
20:12
landscape, and now we see that AI is accelerating a lot of, a lot of this. What are we doing to counteract it? Well, one thing I, I think you have to have good data hygiene, for one thing. You have to know where things live and where, where the, the, the most dangerous things to get at RTO. But I think, you know, what we're seeing is, a
20:31
lot of agentic, defenses that, that are, are rising up. I think, you know, like we said, you know, having to set policy and then let it kind of do its thing and, and trust that it will, it will do its thing. And, and if you think about it, in a lot of ways it's no different than hiring somebody to do something, and you don't know how they're gonna defend your organization- Right
20:54
necessarily either. And, you know, at least with AI, you know, there, there are a lot of, good, indications that it, it's, it's doing a fairly thorough job. But you know, it is a scary moment we're in, where, you know, we don't know where, what those kind of vulnerabilities are gonna look like.
21:13
So I, I think we saw a lot of agentic kind of things happening. I think identity access management, you know, API, keys are, are gonna because you're gonna have inter-agent communication. You know, what's gonna restrict these agents from accessing certain types of data? Are they going to talk to other agents to get around their blocks to, to get th- that data?
21:35
So, or n- understanding your data, understanding your threat landscape, and then putting in the right kind of access controls is going to be a big part of that. But it's gonna be, it's gonna be a tricky piece right now as the tools are evolving and we're evolving the tools to, to, to meet the threat. Yeah. I, I think there's, like,
21:53
a couple different aspects. One is as companies are doing kind of some of their own training, really making sure that you have good tools in place to kinda classify that data, cleanse that data so you're not accidentally exposing sensitive data, right? Making yourself more vulnerable. The other thing is just like the AI is being used to find vulnerabilities by adversaries,
22:14
really companies should be doing that proactively, right? They should be doing that before the adversaries get a chance to find those loopholes, right? So we could get to a point, we hope this was, like, the little bit of positive spin from the RSA, right? Get to a point where we're actually putting out better hardened software up front, and
22:31
we're not exposing ourselves as much, right? So over the long term, we may have a little bit more advantage as a defender. Right now we're a little bit behind. And, you know, CISOs really have to rethink how they operate- Yeah their organization in general, right? It's gotta be less reliance on humans
22:47
kind of stuff, and the humans have to up-level themselves a little bit and let the AI take over some of that day-to-day, task, right? The other one is we, we've talked about probably for a while now the whole concept of assume breach, and I think that's never been more true. I- if, if there's a motivated attacker with these tool sets out there, again, think about
23:07
this stuff is uncovering things that security researchers haven't uncovered for 10 plus years. It is going to find a way into your environment, whether that's, like, a very sophisticated phishing attack. You know, think about, you know, Jason Walker used to get, emails from Nigerian
23:22
the time, and, like, half the time he'd click on it. It sounded like it was great, how he was gonna get, like, you know, 5% of, of the $200 million bounty or something like that. Only one had to be good, Scott. Only one had to be good. Right.
23:33
And that was set for life. Y- exactly, and then you'd be all right. You wouldn't be hosting this wonderful webinar with us. So I'm glad none of them worked out for you. Sorry that you lost some money in, in the process. But now you don't see that as much. Right.
23:46
These attacks on the phishing side are very, very sophisticated. It takes very little effort to, you know, do a deep fake. It takes very little effort, and we've, we've been nice enough as humans to publish everything about ourselves online, right, on social media. So they can learn our voice, right?
24:03
They can learn things that we say. Especially executive leadership. And they can craft something Especially executive leadership, right? The higher you up-In an organization, the more likely that you, you are a public figure of some sort, and it's very easy to replicate you.
24:16
So an attacker's gonna get through if they wanna get through. So how do you actually protect yourself and ensure recovery, right? And I know that's a lot of what we tend to focus on, but it really is critical, because as we like to say, it's not even, it's not if, it's not even when, it's how soon and how often.
24:34
And again, every day that gets more and more true, that you are more vulnerable to one of these attacks being successful. Yeah, and I, I think it's important to note that, Gartner recently came out and noted that, there's been a shift in, in the focus of the CISO, office of CISO, and it's, it's going f- we've spent a lot of time with, you know, detection sprawl, a lot of tools to detect
24:57
attacks and, and, and things like that. But the reality is the budget needs to start shifting more towards recovery. Yep. And, and, and the CISO's role needs to focus more on the recovery effort, not just all those detection tools. 'Cause a lot of times, you know, one, there's a, an enormous amount of sprawl in that space and, and a lot of those tools
25:16
don't get used effectively. But, you know, a lot of times they're just used after the, after the attack happens to identify what happened, because that's an important piece of it too, because you have to report on what was exposed and what was leaked and things like that. But it's really, a lot of that shift is, is coming onto the recovery side and, and that
25:35
looks like, you know, immutable backups, or immutable snapshots, immutable b- backups, indelible snapshots. So if you look at a lot of these extortion attacks, you know, they of them denial of service attacks. And so the goal is really to get you backup and running in, in as quick as po- quick as
25:56
possible of a time. And, and really the only way to, to do that, recover your environments quickly, is through some sort of indelible, immutable snapshot to recover. And also focusing on what is really your minimum viable business. Cause if everything's a priority, nothing's a priority.
26:16
And so getting things back recovered, you know, from the point of whatever the mass deletion or encryption event was, doing that, the search for i- identifiers of compromise, cleaning up your environment, restoring it back online, and then building out the rest of your environment is really where the focus needs to be right now. Well, one thing I want to add into that is a lot of times CISOs may not get a seat at the
26:43
table from an executive or a board level, right? And this has certainly become more of a board topic, and I think as CISOs are looking at how do I transfer my organization and even themselves, it's how do you talk about you know? Yeah. Most executives do not understand technology, unless you happen to work at a technology company, and even then sometimes
27:02
they don't. But they do understand things like revenue disruption, right? They do. They do understand things like cost of capital, and these are absolutely things that cyber has an impact on. And so the way that we speak to our leadership I think is actually really
27:18
they understand the importance of making these investments. I see, you know, we, we internally get these reports every time we win a deal or when we lose a deal. And so when you read through some of these reports, often you do actually see that, oh, they weren't able to get the budget, right? We, you know, the loss was actually to doing nothing because the board- Yeah or the CEO or
27:39
the CFO didn't understand the importance. So I think it's important that we frame it in a language that they understand so that we're not unintentionally leaving our organizations vulnerable. And- It's, it's the so what, right? The board cares about the so what.
27:54
You're right, the, most of the time at the table you get 15 minutes every six months. So you have to talk about the impact that things are happening out there, and stuff that we're talking about and, and, you know, live, you know, live results of what's going on and what it means to their customers, to the reputation. Chris, you know, there's a lot, a lot of that going on out there and, and, you know, we talk
28:18
a lot about isolated recovery environments as a way to do that. Scott talked about, it's, it's, it's how and, you know, I always say it's not getting attacked isn't the chicken pox. You don't get hit once and it's painful and agonizing, but at least it's over with. In fact, it means you're likely to get hit again.
28:35
So there's this cycle that has to happen for you as an organization, and a lot of times, as you, you know, you're talking about ways to recover, an isolated recovery environment is one of those things. What's important about that? Yeah. Well, if you think about what happens during an attack, right? I mean, it's, it's an extraordinarily
28:54
disruptive event for your business. But, you know, one thing that may happen is you may have, law enforcement coming in confiscating your, your, your storage sys- storage arrays to, to, you know, look through them, identify evidence. Right. And, you know, you have your incident teams and forensics teams that have to go
29:13
through all those arrays, identify what was attacked, what got, what got leaked, you know. And that can be a multiday, multimonth kind of, thing that, that's, that's going on. So, you know, when you want to shorten the recovery time, you have to have something ready to go. And, you know, there's a couple things
29:35
You know, we have our ransomware Evergreen, package that'll ship out an array in, you know, 24 hours. But an isolated recovery environment is, is really your fastest way to, to get backup and running. You have, within an isolated recovery environment, which is isolated, thus the isolated, from your production network.
29:56
You have, you know, copies of your data in, in, immutable snapshots. You have an area where you can do that recovery work, where you can bring it up in a s- in an area that's disconnected from the rest of your network so you know where, where you can, get that up and running. It's gotta have proximity to your production environment because the RTO you have to be able
30:18
to run a production environment out of these isolated recovery environments or, or, or move data into your production environment in a very quick- fashion, and that's data has gravity, and that's why a lot of times you'll see organizations, they have an I- IRE for their on-prem stuff- Mm-hmm and an IRE for their cloud stuff as well, because you need, you need to have that, that kind of proximity.
30:41
But, you know, having the ability to have your minimum viable business inside of that isolated recovery environment so that that can be the point of res- restoration for your environment is really the only way to get your business up and running in hours or days rather than weeks or months. Yeah. One thing I'll add into that, too, you know,
31:02
we talk about the threat sometimes of law enforcement or insurance companies or other people maybe- Yeah making your equipment unavailable. The other thing is when you get attacked, you don't, and especially initially, you don't know what happened. You don't know what they compromised. You don't know what level of access they had, what level they went to.
31:17
Right. So that infrastructure, you should your production to be an unclean environment just period, right? Even at the infrastructure level. You may have to completely rebuild that. And so again, back to that IRE concept or even our Evergreen//One re- Green Square Recovery
31:31
SLA, that gives you an ability to start those recovery efforts, like some of the forensics and the actual recovery efforts right away, not have to wait for other things to complete, and you can get that minimum viable business up and running as quickly And we, we talk sometimes about, like, Zero Move Tiering recovery and things like that, right?
31:51
That's where traditional methods, you're, you're relying on, you know, kind of those traditional backup systems to send out the data. You know, some people will tell you, "Oh, you can boot right off the system." Well, I mean, maybe, but can you and will it really be fast? Could you run your production environment off of your backup system?
32:05
I probably wouldn't want to try that, right? So again, we're not talking do another 100% copy of your environment, unless you want to, right? Our, our sales reps at Everpure would love you to do that. When you think about that minimum viable business, minimum viable company, you want to have infrastructure that
32:20
is ready to rock and roll. Right. The other thing that we tell customers is don't, don't think of this like DR 'cause they're really not the same thing from a traditional DR. Chris mentioned having that proximity to production. That's something you wouldn't want to do in a DR, right, because what if there was a
32:35
physical disaster? It'd wipe- Right everything out. But that's not what we're trying to protect here. The other thing is how often do DR events, traditional DR events happen? It's re- very rare. Lots of IT people go, go through, Sorry, IT people.
32:48
I can't even talk today, JSON file. Lots of IT people go through an entire career and never experience an actual DR event. But I would say, like, especially the current generation, you are going to experience, if you haven't already- That's right you're going to experience some kind of cyber extortion event.
33:04
And so this is a real thing that you actually have to be prepared for. Well, let- Yeah let's, let's talk about Yeah, let's, That's a good point, and I wanna say it's This is kind of a shift in the, in the business, what you talked about, Chris and Scott. The things you just mentioned is that, you know, your storage platform really can't be a
33:21
passive target anymore like it used to be. That's a DR kind of methodology, where it's just kind of a passive repository. You sit, put it, throw it in there and forget about it until maybe, maybe you need it in there. But a cyber, you know, s- you know, cyber recovery and cyber events kind of require more
33:40
of an active, participant in the process. Yeah, I would say, you know, the, the one thing, if you can take two things away from this call today, I would say the, the first thing is that cyber extortion events are fundamentally different types of attacks than- That's right anything else. You know, we've got high availability, we've got backup, we've got DR sites, but this is a
34:03
very different type of attack. This is a different type of a disruption. This is an attack on your, your data, not necessarily your physical infrastructure, right? So you have to be very, very ready to recover from that specific kind of an event.
34:19
And the other thing that I would say is that you have to look at, you know, indelible and immutable snapshots as, a fundamental way to recover this. This is not to say that you don't need backup and you don't need all the data protection, which you absolutely 100% do, and, and, and it's a big part of the whole IRE story and data recovery. But having that ability to get that minimum
34:42
viable business recovered quickly is really important. And in order to do that, you have to work with your systems. You have to make sure your systems are ready to go at any given point. You have to be constantly looking for threats on those, those systems, those recovery environment systems.
34:59
And this is one of the great things about an IRE, is that it, it can function and serve multiple purposes, right? It, it, it can be You can value engineer your isolated recovery not just like we're reproducing infrastructure. This can be, you know, where you're constantly running Deep Threat analysis
35:18
on, on your environment. Right. This is where you can do a lot of that analysis. You can be very proactive. And it, and you need to be proactive about this. You need to have a regular schedule of interacting with this data, making sure your
35:29
environment's in good shape, having that governance wrapped around that environment to make sure that it's ready to go when, when you need it. One small thing I want to point out, it's small, but it's actually really important because we- we've said the words immutable and indelible- Yes in this, right? Immutable snapshots, pretty much every in the world, at least from any
35:49
major vendor, is immutable. I can't change it, right? It, it's almost the write once, read many. Some people can turn them into rewrite copies, but immutability's kind of been But if that's as far as you take it, like, we don't want to give you a
36:02
false sense of security. If that's as far as you take it and you don't take additional steps, these threat actors will come in and delete that. We have seen this in our customers too- Yeah where they don't make those snapshots indelible, which means that you cannot remove them even as an administrator. If you don't take that extra step and you're just taking snapshots, when you get in one of
36:21
these events, you may very well find that you don't have anything to recover from, and that's actually true even when you're taking the backup side of that, right? Chris mentioned backup plays a, a pretty important role in, in this whole thing too.That's actually the first place that they wanted to go after, right? Was your backups. And it's close to 100% of all attacks, that is,
36:39
like, one of the f- first steps is they're going to try to remove your recovery capabilities. So if you don't take that extra step of those things indelible so that even your administrators cannot remove them, you might find yourself in a little bit of a pickle when you actually need to recover your
36:54
Yeah, and remember that all these attacks are gonna be privileged user attacks. These are, these are attacks that are gonna come from people who have the same level of access as all your IT admins and things- Mm-hmm like that. So you have to, you have to have, something that's outside the scope of their privileges, that, that allows those things to be protected.
37:14
We, we talk about TPA now, third-party a- authorization, so that's somebody outside of your organization that, that may have to, to enable, you know, some things on your system so that you have that extra layer of protection from yourself, because these are, these You know, these attacks are coming from inside the house. The call's coming from inside the house.
37:35
That's right. And, you know, it's, it really is, and the one thing, again, around RSA, it's, it is all hands on deck. I mean, I, I don't see any of this without everybody in the organization being on the same page, but also everything that's working in the data center working, kind of working together. And I know that's where a lot of folks are
37:55
looking to, you know, experts like, Scott and Chris to help out with, how do we get everything kind of working together to kind of get to this, you know, this mean time to adjust or I mean, things are happening so fast and AI's accelerating, everything kind of needs to be working together, in the environment. And, you know, so, just a kind of final thought there on it, Scott, you know, is how
38:25
do the, how do companies make this happen? How do things How can you kind of bring that all together? Yeah, that mean time to adapt thing, that's kind of a newer thing, but w- we, we have to be agile as organizations. Yeah. And you're hitting on a big point, which is a
38:38
lot of people think that, well, this is an IT problem, right? It's IT system, so it's an IT problem. It's really an everybody problem. When this happens to your organization, it's not just going to be the IT people that are involved, right? Every aspect of the business will be involved
38:52
in the recovery efforts, or in just how to service the customers while they can't access s- access the systems. So you need to be thinking about that in your planning, in your testing, which hopefully you're planning and testing- Yeah and constantly, right? Because if you don't plan for these scenarios, you don't plan and, and
39:12
built into the entire organization, everybody's not gonna be on the same page, and it's gonna extend your outage. And what does that mean? That means things like additional revenue disruptions. It means, like, longer term increased cost of capital.
39:24
It means, losing potentially top talent, right, who you burn out during these events. So it's really critical to have that plan, involve everybody, and make sure you're testing it. Yeah, and I, I just wanna throw in, double down on that a little bit because I, I think a lot of times this is thrown to IT and they It's like, "IT, this is your problem, fix
39:41
this." But it really requires the whole business because- That's right IT's not gonna know what the minimum viable business, the critical things that need to be running, what, what are, you know, revenue, you know, core revenue, components and things like that. So you really have to pitch a big tent here. Yeah, absolutely. I mean, we talked about it already.
40:01
The board cares about the so what, so the CISO puts the plans in place to, to respond to threats and to set the risk-averse strategies. The CIO has to deliver, and, and if That impacts everybody down line, with all the roles and responsibilities. It is truly, you know, all hands on deck.
40:20
It's an all organization, type thing. All right, let's g- let's get to some questions, in here. We've got one here. Either one of you can take this first. You discussed how AI is shrinking the attack life cycle, from months to minutes, and it's true. You know, once the hackers get in there, it
40:36
used to be maybe they would sit around, and maybe they are to blueprint things. One of the things that attackers are kinda getting after is they just, they don't wanna attack, they just wanna blueprint it and sell that, information off. But attacks can now happen in minutes. In this environment, is it still realistic to rely on traditional manual recovery or, or do
40:57
we need to move to a fully autonomous, use your word here, Chris, agentic recovery system? A magic button, if you will. Just press the button. Well, I, I, I mean, I think it's gonna end up there. I think right now if you're doing it manually, you're, you're, you're probably not doing the right thing at this point.
41:14
I think you have to have orchestration and automation into your process. And whether that's, you know, agentic or not, a- at least having the, the orches- you know, like, the pre-scripted ways to approach recovery is really important at this point. Right. Yeah, I c- completely agree, and I think, you know, that's a little bit why some of the testing and planning is important too, because
41:37
automation doesn't happen at time of incident, right? You have to have a lot of these things set up and ready to go. But I, I honestly don't even know if AI's the reason that that's important. Why it's important is because you wanna get back up and running as fast as and any kind of manual effort disrupts that.
41:55
And you don't know when these attacks will happen. They tend to target on holidays, weekends, right? Things when staffing tends to be light. Times when Jason Walker's on vacation, right? So- you, you don't know who's gonna be around, and you don't wanna rely on a single
42:11
You know, we've all heard of, there's a term for it, but, like, the, the heroic efforts, we'll call it, of IT people where there's an individual who's, like, the rockstar, right? The, quote, "rockstar" of the group. Well, what if that rockstar is on vacation? What if that rockstar happened to just resign the week before kind of thing?
42:28
Won the lottery. The more you can- Won the lottery. Exactly. Won the lottery. They're not coming in tomorrow. Yeah. Yeah. They're done. But the more that you can plan and automate that stuff, the less reliant you are on any single individual when it comes to actually recovering.And the less likely you are to make a bad mistake when, when that's too.
42:44
Because y- you know, these, these events are chaotic, they're exhausting, they can run- Yeah for, you know, all day, all night, and, you know, your, your staff gets really burned out. And without having that, those pre-prepared, approaches to recovery, you're, you're gonna be in for a world of hurt. Okay. That all day, all night is across weeks too,
43:01
by the way, typically, right? Right. Not, not like one day and one night. That's right. All right, transitioning from a passive, passive storage or, you know, sometimes we'll call it a passive citizen, in the in- in the, ecosystem there, to an Active Defender sounds like a major shift in philosophy.
43:20
What's the single most important first step an infrastructure team can take that tra- transition? It's probably not the infrastructure team that's going to make, be making that kind of call. Sounds like that's something that may be coming from the top down. But look, what's the first step on moving from kind of that traditional
43:41
kind of the, the merging of a more of accelerated, automated type of, type of system? Well, I would say, you know, there, there's two things that you need to do right away. One is, is identify what minimum viable business is, and that, that I think is, is- Yeah really a- an important piece of it. Because if you They're gonna take everything down, and you gotta get focus on the things
44:04
that are gonna matter the most first, right? So that's a big step, but I think r- the, the first things that you can do is, immutable, indelible snapshots, right? Because that's, that's gonna be the center for Rapid Restore. And, while there's a lot of other components that go into this, you know,
44:23
is gonna really, really help you i- in, in one of these events. But then, then beyond that, I, I think, you know, you really have to focus on getting executive sponsorship for these types of things, and, and focusing on, on, on convincing them- Yeah you know, about the things about these being capital events and, you know, seeing, you know, sometimes in some businesses, you know, within two days losing
44:44
billion dollar, billions of dollars in cap that, that continues for years, you So I mean- Right there's a lot of reasons for executives to, to get on board with this. Yeah. I think it's also important to evaluate who you're working with, right, and what your ecosystem is. We, we saw What did, what did somebody
45:05
There were, like, 600 vendors at RSA. It's a lot of freaking companies, right? Yeah. You know, we've seen, all seen slides of, like, the hundreds and hundreds of vendors the security space. A- and you talk to a lot of them. One, you don't understand why they're different from the other.
45:19
Two, a lot of them, like, tell you that there's potentially something wrong, but they don't really do anything about it. So that's, that's a little bit being passive, like, "Hey, we're, we're gonna alert you that there's a problem, but don't ask us to, to help you fix it." but- Yeah no single company that I've found, maybe Chris has, but- Mm-hmm I haven't found one that solves this by themselves.
45:39
Right. Right? Yeah. So having companies that work together and have a strong ecosystem that have integrations is something I think you have to have. Otherwise, you know, you just have an individual piece of the component, and that piece by itself might be passive, may not be- Yeah sharing information. I think if you're gonna move to a more active
45:57
posture, you have to have an ecosystem that talks to each other, tries to get ahead of these. We know we're not gonna be able to stop everything, but, like, it's just like at your house. Do you still lock your door when you leave? You still do. You don't wanna make it easy for them, right?
46:08
You wanna try to at least raise the cost- Raise the cost, yeah for them, right? So I think that's a critical thing is, like, evaluate your ecosystem. Who are you partnered with? Are they the right people? And you also don't wanna have a million different tools. Tool sprawl's a real thing, right? Yeah.
46:22
I know it's a big concern for CISOs. Right. Am I partnered with the right people? In addition to all the things that Chris said, I think partnering with the right people is important. For sure. All right. We'll take one more here.
46:34
The, the industry is comfortable with RTO and RPO, of course. Meantime to adapt, this follows up on that, is a newer concept. How can we practically measure, that metric, during a live incident to prove to leadership that our resilience posture is actually improving? Well, I guess the question is, you know, what, what can they do to start measuring how How do
46:57
they know they're getting better out there in adapting? I mean, I think that's- Yeah, I mean that Go ahead, Scott. Go ahead. All right. I think, I think that's where the testing part comes in. Totally. Right? In, in doing exercise.
47:09
And, and by the way, not the same exercise every time. One, one of the things when one of these attacks happens is you don't know what the attack is gonna be. You don't know, are they going to encrypt your data? Are they gonna steal your data? Are they gonna poison your data?
47:22
Are they just gonna, you know, be a wiper ransomware and try to de- destroy absolutely everything and, and there's nothing left? So you need to practice different scenarios, but I think practicing is the only way that you can be confident in your ability to, you know, improve your RTOs and RPOs. And we like to talk about work recovery time, which goes a little farther than just those
47:40
two definitions. But if you, if you don't try it and you don't test it, I'm not sure how you could prove it until you're actually in the is a little late at that point to know what it really is. Yeah, and it's, it's har- it's hard to, to evaluate 'cause, you know, attacks are getting more sophisticated, faster, broader.
47:57
At the same time, you're, you know, you're trying to up your game. So you may be upping your game- Right but, you know, it, it, it's a more challenging environment, too. I think, you know, you, you, you wanna make sure you have good telemetry from your devices. You wanna make sure you, you, you review your incidents after the fact and, and, you know,
48:12
i- identify areas you did well, i- areas you didn't do well. You know, write up, documentation. You g- you've got to, you've got to, take an attack as a, a, a data point and, you know, leverage that to improve your processes going forward and ne- you know, so that next time you'll be even better.
48:33
I, I think, you know, like, analyzing the data of that attack is a, is an important piece of it, too. All right. Well, we talked about the, the threat landscape. We painted the doom and gloom, the, around that, and how AI/ML makes it even more inevitable a- as, as quicker as possible.
48:49
And we also, you know, hit on some of the counter- countermeasures that we can take, and how to kind of d-Plan to attack this new age of, of cyber resilience in there. So let's get your final thoughts. You know, Chris, if you were gonna l- you, you said two things already. You know, this is like the, all I need is this paddle game and this, you
49:10
know, and this glass pitcher. It's all And that's all I need. That's all I need. Nothing else. And, but, uh- That's, that's a DeepReduce what, what, what would you want to leave them with? Yeah. Well, like I said, I, I mean, I think, you know, one, if you haven't already, start engaging your organization to identify what minimum viable business looks like.
49:26
I can't stress that enough, because I see so many organizations trying to approach security from, like, everything needs to be secure. And, when you do that, you make the most important things less secure because, you know, like I said, if, if everything's a priority, nothing's a priority, right? So, like, identifying that minimum viable business and, and engaging the rest of the
49:46
organization to, to identify that is really important. But the, then the, the next thing I, I would say, because it's, it's probably a very low lift for your organization, is enable immutability in your s- in- indelibility in your snapshots. That's, that's, you know, that's a really strong defense against what's happening here.
50:07
And, and it gives you a Rapid Restore. And, and I think, you know, w- I, I hear a lot of folks talking about, well, we're just gonna run backups in the cloud. And, you know, rehydrating all that data, you know, which could be petabytes of data from the cloud into your environment, is not a recipe for a quick recovery.
50:27
It's, it's good to have things like that, so that, you know, you, you may have to restore from, you know, data points that are, that are way in the past. So you need to have, you know, different varia- variable lengths of your recovery options available to you. But that, that immutable and indelible snapshot is, is your first line of defense.
50:49
Yeah, I agree, and we don't have time to get into the whole cloud recovery side of that because, you know, a lot of vendors push that as an easy button. It's really anything but an easy button, right? There's a lot of complexity in- That's right in, in that move. You know- Yeah just look at people that try as full projects to lift and shift
51:03
how does that work out? Not sure why we think it's gonna be a great option when you're in an emergency kind of situation. Yeah. But, Chris has great things, of course, right? He got to go first, so he gets some of the best. Oh, sorry. But- It's all right I think the, You
51:17
talk differently to your executive team is important, right? If you're, if you're a CSO or even an infrastructure leader, go have a different conversation with the business. Use terminology that they care about to help them understand the gravity of this Sure. And then the second one, of course, I've said
51:32
this a lot during this call, but have a plan to test it. Yep. Inject AI into your testing, right? You are going to be defending against agentic attacks. You should have that as part of your testing process to see if you can hold up. So I think those are the two things.
51:46
Think and talk differently internally to your executives, and make sure you have a modern plan that you actually test frequently. Yeah, and, and on that front, I would say there's, you know, like focusing on cyber risk quantification, identifying, like, what the impact is to your business for the executives- Yep I think, is a big one. And annualized loss expectancy calculations
52:07
are, are a big part of that, and that's something that, you know, you might wanna investigate, taking a look at so you can kind of put a quantification to, like, what an outage, what an, what an attack would look like financially for the organization, so. 100%. Good calls, Chris. Yep. It's all hands on deck.
52:25
I think, you know, being an active defender and m- participating in this resilience brings, you know, security, fastest possible recovery, all the things the fellows are saying. And then, you know, bringing, you know, powered by data intelligence in the organization in there too. You're gonna need to understand more about your data than ever to take action faster.
52:48
So definitely, great, great thoughts there. And if, you know, if you wanna hear more from these guys, feel free to come out and visit us in, Las Vegas in June for our, Pure Pure//Accelerate, which is going on out there. We will have a ton of, So I don't know if I can measure that exactly, but we will have a lot of cyber resilience to talk about, our partners and leaders and, and folks
53:13
Scott and Chris out there. But i- if you can't make it there, don't fret. You can join our digital community, and we wish you would do that. Go ahead and fire it away there, purecommunity.purestorage.com. You know, we had Fire off some, strongly worded messages or share your thoughts.
53:32
We love to hear thoughts in there. That's, that's what educates us as a, as a community, and that's the only way we're gonna fight our new digital overlords, that are clearly coming with i- with Skynet. And then we appreciate everybody participating, you know, in this. We, we love the conversation.
53:51
We welcome you every time here. For Scott Taylor and Chris Brandt, I'm Jason Walker saying thank you for joining Tech Talks. Bye, everybody.