Transcript
And joining me today is the Chief Information Security Officer, Nitin Raina, from ThoughtWorks. Welcome, Nitin. Thank you very much, Allison. Of course. We're so excited to have you today. Likewise. Now, you and I have been spending a lot of time together because you're a member of the Okta CISO Forum. And one of the best parts about my job is I get to sit down with customers like you in our community and learn about what's top of mind. And one of the topics that's recently come up is sophisticated deception and this rise of social engineering attacks. So I was wondering if you could just share your thoughts just on this really broad topic before we kind of dive into some of our questions. Yeah, I think this area is changing very, very swiftly, right? So, you know, we're seeing a lot of, you know, very intelligent, smart attacks happen. A lot of deception, you know, you know, fake deception, fake attempts happening. It has become so sophisticated. AI has played a very crucial role in assisting both the attackers and the folks on defending it. But yes, it has become really, really sophisticated. It's odd, I would say. You know, it's funny because we talk about AI, the rise of AI, and how bad actors are using and leveraging this technology. Now, when I started a job, I had a text message from an executive asking me to buy Starbucks gift cards and mail it to them. But now with the rise of AI, we're actually seeing how bad actors are using AI to create deep fakes to mimic these CEOs or executives and ask for employees to send money. So it's really evolved. And AI is playing a big role behind that. So have you seen kind of some of these AI attacks or what are you seeing in that broader landscape? Yeah, so lots, right? So we are seeing a deep fake from a CEO impersonation. We are also seeing a lot of fake interviews. We are seeing a lot of these happen through multiple channels. So you could see it from an email, you could see it from, you know, non-official collaboration channels like WhatsApp, SMS. So multi-channel, you know, a lot of these are very sophisticated and, you know, yeah, voice cloning, you name it, it's all over. I know even in interviews, we're seeing that come up and we were laughing. We were saying that, you know, nowadays people are using their hands to maybe see if it's a deep fake or there's just so many different tools available out there that being a CEO, it must be really challenging. It is very scary. And I think we are just enabling our, you know, there are some controls that we will sort of deploy using the standard tooling that we use. Plus, you know, we have to train and get people ready to face this. Totally. Well, you recently wrote a blog around top threats for CISOs in 2025. And in that, you talk about the importance of training employees and making sure they know how to look out for these deep fakes or threats and attacks. So can you talk a little bit more about how that's going? It's going well. I think people, employees, they are the first line of defense. So you have to spend time and effort to train them. So we are running our regular training. We are modifying training for some of the functional power users. And we are also trying to do the regular phishing simulation so that they get trained to spot that, hey, this doesn't look right. So I should maybe alert somebody or maybe I should mark it as phishing. So I think it's crucial. Yeah, that's awesome. Employees are really important. And I love that you're building this culture of security. What else are you guys doing to train and look out for social engineering attacks? So what we are doing today is obviously making sure, you know, we talked about the administrative controls like, you know, and then, you know, the training controls, but that's not enough. So we have to make sure we have phishing resistant MFA in place. We have, you know, tools and techniques on our email security, where our email security is ready to handle, you know, situations where, let's say, a business email compromise is happening. So we are, you know, investigating, we're trying tools in that area. And then, you know, kickstarting journey around Zero Trust. I know everybody talks about Zero Trust, but if you're able to, you know, do something around the Zero Trust architecture, Zero Trust journey through your tooling, I think that will help you to get much more secure and much more ready to prevent some of these social engineering attacks to even happen. Yeah, it's a challenge, I'm sure, because you're trying to keep everyone safe and create some friction, but not too much, right? That it gets in the way of someone doing their job. Absolutely. Detection and response, if I want to expand on monitoring. So you can put a lot of preventive controls, right, in an organization, but it's never enough, right? The attacker is getting advanced, they are, as I've said, in my previous, they're leveraging AI, and other automation and other tech to actually penetrate some of the controls that the organizations are putting. So can you detect things sooner? Can you flag things sooner? And say, hey, this looks suspicious, this looks risky, and can we sort of block it right at that level? So detection, response, monitoring, all of these are super crucial. So one of the challenges that we're hearing in the CISO community is how these sophisticated cybercrime groups like Scattered Spider, they're actually now able to bypass multi-factor authentication. So what do you do now? How are you preparing for that? Yeah, I think they've really gone sophisticated by SIM swapping, bypassing MFA, MFA fatigue, man-in-the-middle attacks. There's lots that they are doing, right? So we need to get better in making sure phishing-resistant MFA is in place. We are securing our organization with tokens and keys, deploying passwordless, fastpass kind of solutions, and then continue to make sure you have a very strong threat detection and response capability. I think, as I have reiterated, you cannot fix everything. You will find things, you need to find it quickly, triage it, and then respond. Yeah. It's challenging because you're trying to bring in technology, you're looking out for new threats, you're training employees, you're changing the culture. So as a CISO, you're wearing a lot of hats. And we actually ask guests what their advice is. And we've heard different things. We've heard some CISO share, be a good communicator, work on collaboration and think about your users and keep them at the center of everything you do. So whether you're a CISO, a year one or year 20, what advice or last thoughts would you have for the CISO community? Yeah, I would say, I think all of the points that you mentioned are applicable and relevant. But what I would highlight is, are you clearly a business team player? So when you are working with your business, do they understand what security initiatives that you are trying to do? Yes, you're there for reducing risk and securing the organization. But are there things that if you do well, you can actually enable the organization to go fast. So partnering with the business, partnering with your functional leaders is so crucial, in my opinion. So I think I would advise CISOs to strengthen that area and then they will see, hopefully they'll see good results. Yeah, I love it. It's a tough job for sure. Well, thank you so much for joining us and sharing your insights. It was really helpful. And thank you guys so much for joining us and we will see you next time. Thank you very much. I thoroughly enjoyed it, guys. It was so nice. I love it. Thank you.