Time To Turn The Tables On Attackers

As a security industry, we need to arm business with innovative technologies that provide visibility, analysis, and action to prevent inevitable breaches from causing irreparable damage.

Amit Yoran, Chairman & CEO, Tenable Network Security

November 13, 2014

5 Min Read

Last week, Amit Yoran was named the President of RSA. Amit joined RSA after the company's acquisition of NetWitness, a market leading network forensic vendor which he co-founded and served as CEO. Since the acquisition he has been the driving force behind expanding and transforming RSA's product strategy and portfolio. Amit previously co-founded and served as the CEO of Riptech, which was acquired by Symantec in 2002. He has also served as the founding director of the US Computer Emergency Response Team and as a founding member of the US Department of Defense's CERT program.

Dark Reading asked Amit to reflect on the changes he has seen in the threat and defensive landscape in his career, the future of the security industry and how he hopes to affect that in his role at RSA.

I've been fortunate enough to work in a field that I am very passionate about, and to work alongside so many extraordinary people. I started my career in information security doing incident response work in the Department of Defense over 20 years ago and was exposed to some of the most aggressive adversaries. Those early years made a profound and lasting impression on me. I saw firsthand how well-designed systems can fail, how mature security programs can be circumvented and how focused adversaries orchestrate strategic campaigns.

In the years since we've been faced with the reality that as an industry we've reached a point of catastrophic failure. Networks have become more complex, perimeters have become more porous, mobile and BYOD have become widely adopted and SaaS platforms more prevalent. Cyber criminals have taken advantage of our shortcomings and are winning the war.

How has the industry responded? Unfortunately the response is not enough, offering up more of the same old solutions with only modest improvements in firewalls and signature-based approaches to antivirus and intrusion detection systems. Solutions that by their very definition can't address sophisticated threats and lack the context to adequately scope what is going on in the network. Organizations weren't getting the visibility they so desperately needed to stand a chance going up against increasingly sophisticated adversaries. An adversary with technical acumen, focus, intent, and enough time can make compromises an inevitable reality for any network.

It all sounds very ominous, so how do we turn the tables on our attackers? Where do we go from here?

As an industry we're positioned to incite change in how organizations are securing their notably more modern and complex corporate environments. It's our obligation to arm businesses with the most innovative technologies fit to combat these advanced threats. I believe in an intelligence-driven security -- a strategy that provides the visibility, analysis and action needed to help prevent inevitable breaches from causing irreparable damage or loss. This strategy empowers organizations to effectively address the challenges they can see today and those still beyond the horizon.

The first steps toward stronger security are aligning and integrating our capabilities to better enable organizations to embrace modern computing, and also deliver the most effective security possible. Security has evolved beyond just simply seeing an exploit attempt, and now requires pervasive visibility that identifies an entire sequence of activities, or an orchestrated, strategic campaign. Technology needs to keep pace with this need and facilitate organizations' migration to next-generation computing platforms.

So how exactly do we achieve this? What are the tools we need?

With perimeters on their way out the door, identity matters now more than ever. For RSA, that means creating flexible multifactor authentication that the end user won't find burdensome and moving identity and access management (IAM) and governance from theoretical or a paper-based model to an operational, living, breathing organism that organizations can rely on. Security technologies should leverage the wealth of information offered by identity that offers critical context for a much broader understanding of what's happening in traditional environments, as well as mobile and cloud-based applications and services.

Equally crucial as managing identity is forming comprehensive visibility into network operations and a deep understanding of the digital environment. By establishing pervasive and true visibility we enable organizations to see not only what is occurring across their networks, but give them the analytics to understand what they're seeing. This paired with a mature GRC practice gives the business context and insight necessary to prioritize security efforts where they can make the greatest difference.

In my new role I'll be working across the business to deliver a simpler, seamless, and more unified customer experience alongside an industry poised to drive awareness about threats enterprises face, and the most advanced technologies they will need to combat those threats. As compromise has become inevitable, so must change. Hoping our current defensive technologies will keep us safe is ignoring the attacker already in the room. Historical attack patterns only tell us what has already been attempted, while the adversary has likely already changed their approach.

Intelligence-driven security isn't a marketing term. It requires businesses to know everything they can about their environment, their activity, their risk and their vulnerability. Only then can a business truly adopt a more agile stance, one in which it can confidently say, "I am ready for anything that comes at me, even if I've never seen it before." Today's advanced adversaries, in many cases, know businesses better than the businesses know themselves. As an industry and as individual organizations, it's time to take a hard look in the mirror, and use what we see to reflect, deflect, and fight the enemy on a level playing field.

About the Author(s)

Amit Yoran

Chairman & CEO, Tenable Network Security

Amit Yoran is chairman and CEO of Tenable, overseeing the company's strategic vision and direction. As the threat landscape expands, Amit is leading Tenable into a new era of security solutions, empowering organizations to meet the challenges of evolving threats with innovative technologies and a vision of transformative vulnerability management. Prior to joining Tenable, Amit was president of RSA where he led their growth and strategy since 2014. Amit came to RSA through the acquisition of his high-growth company, NetWitness, where he was founder and CEO for the market-leading network forensic product provider. Previously, he served as founding director of the United States Computer Emergency Readiness Team (US-CERT) program in the U.S. Department of Homeland Security. Amit also founded Riptech in Virginia, one of the first managed security service providers (MSSP), which was acquired by Symantec in 2002. Amit currently serves as a board member and adviser to several security startups.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights