newsfilter.io
Conference Presentation, Keynote, Fireside Chat

Security Markets: The Lay of the Land

  • Core Philosophy and Industry Critique

    • The speaker asserts that "software is eating the world," transforming formerly hardware-only objects (e.g., refrigerators, TVs) into code-driven devices, creating new security challenges.
    • The current security industry is described as fundamentally flawed, operating with misaligned incentives where some entities profit from insecurity.
    • Analogy: The industry is compared to buying a new Toyota Corolla and being charged an extra 10% to ensure it doesn't catch fire, highlighting the absurdity of paying for basic security features.
    • Cottage Industries: Sub-markets within security actively benefit when security models fail, and "hackers" have monetized breaking products and stealing data.
    • Layering Problem: Many security solutions involve bolting software security onto products that are insecure by design, creating a cycle of purchasing incremental "bell and whistle" products.
  • Positive Industry Shifts

    • Built-in Security: Major technology trends now prioritize native security, exemplified by Apple's "walled garden" iOS devices and Google's Chromebooks, which integrate security capabilities previously absent in operating systems.
    • Ransomware Evolution:
      • No current ransomware variants modify data directly within the cloud; "cloud-aware ransomware" is expected to be the future trajectory.
      • Attacks are shifting toward highly targeted, custom-designed ransomware with bespoke payment schemes.
    • Cryptocurrency-Driven Crime: E-crime syndicates are leveraging cryptocurrency for:
      • Mining operations on compromised cloud platforms.
      • Enabling the entire ransomware market economy.
      • Specific Incident: A company accidentally committed AWS credentials to a GitHub repository, resulting in approximately $500,000 in unauthorized compute charges within hours of Bitcoin mining attempts.
  • Root Causes and Operational Challenges

    • Cloud Configuration: Misconfiguration remains a critical vulnerability, illustrated by a recent breach at a hosting provider caused by an AWS salesperson misconfiguring S3 bucket permissions.
    • Change Management: Issues such as removing firewall configurations and checking credentials into public repositories are primary drivers of breaches.
    • Human Factor Statistics (Verizon Data):
      • 93% of breaches are caused by phishing and pretexting.
      • 80% of those breaches involve individuals voluntarily disclosing usernames and passwords.
      • 60–70 days: The average time a security patch sits unapplied before a breach occurs, indicating failures in patch hygiene rather than zero-day exploits.
    • Investment vs. Reality: Despite $7.6 billion in cybersecurity VC investment last year, CISOs report that 93% of breaches are caused by "silly" human errors (e.g., spear phishing) rather than sophisticated nation-state malware.
  • Market Gaps and Spending Misalignment

    • Spending Inefficiency: The majority of security spending is directed toward authentication/authorization and malware detection/antivirus, which do not effectively address root causes like patch management or change management.
    • CISO Sentiment: There is low satisfaction with current security tools, with CISOs describing the environment as "fine on the outside but on fire."
    • The "Next Generation" Trap: Every product wave is marketed as "next generation," yet these tools often solve problems created by previous security products rather than resolving core infrastructure issues.
    • Talent Shortage: Hiring security talent is the top challenge for CISOs, with junior roles in the Bay Area taking up to six months to fill and CISO searches often exceeding one year.
  • Forward-Looking Trends (1–10 Years)

    • Standards-Based Compliance:
      • Government mandates (NIST 800-53, FedRAMP) are forcing cloud providers to internalize security and increase transparency.
      • Audits (e.g., PCI) are becoming more rigorous post-Equifax, moving from compliance exercises to deep infrastructure inspections.
    • Cyber Insurance:
      • Emerging ability to categorize vulnerabilities and calculate unmanageable risk will drive the standardization of cyber insurance terms.
      • Current policies often void coverage for nation-state attacks due to specific exclusions, necessitating better risk transfer mechanisms.
    • Blockchain Applications:
      • The speaker views blockchain primarily as a tool for building "communities of interest" and threat intelligence sharing.
      • The technology can incentivize data sharing by compensating contributors, addressing the current dynamic where organizations feel they give more than they receive in intelligence exchanges.
    • Zero Trust and "Beyond Corp":
      • The industry is moving toward eliminating implicit trust relationships within corporate networks.
      • Google's "Beyond Corp" model aims to dissolve the traditional corporate network, treating all access (even from public networks like Starbucks) as untrusted.
    • The "All Cloud" Future (10-Year Horizon):
      • Corporate data centers will shrink to serve primarily as secrets management infrastructure.
      • Purpose-built, secure devices (like iOS and Chromebooks) will obviate the need for traditional "bolt-on" security solutions like antivirus.