Transcript
Megan Garza. This afternoon, I'm joined by Dr. Dalal Alharthi, Assistant Professor of Cybersecurity at the University of Arizona. Welcome to the show, Dalal. Thank you for having me. Dalal earned her PhD in computer science from the University of California, Irvine, and has a diverse background that spans both industry and academia. She previously held positions as a cloud security engineer at Farmers Insurance, a resident engineer at Palo Alto Networks, and as a Prisma cloud consultant at Dell. Currently, she serves as an assistant professor in the Cyber Intelligence and Information Operations Department at the University of Arizona. Dalal holds two master's degrees, one in management and one in computer science, and she has earned professional certification, including AWS Cloud Solutions Dalal, you studied programming in Saudi Arabia before moving to the States in 2015. What was the biggest difference in information technology between the two countries? Working and studying in the field of computer science or information technology or cybersecurity in Saudi Arabia and then moving to study and work in the field in the United States allowed me to understand the global landscape of the field. And one of the most notable differences that I may share is, for example, in Saudi Arabia, there is a strong emphasis on digital transformation through government initiative and enhancement of government services to align with our Vision 2030 plan that we have in Saudi Arabia, while in the United States, it's a much larger, much diverse tech industry, and it's more dynamic, with an emphasis more maybe on businesses and private sector innovation. And what do you foresee as the biggest threat or risk to cybersecurity on the horizon? I would say AI-powered cyber attacks can pose the biggest cyber threat in the near future. So AI-powered cyber attacks, they are very sophisticated, very hard to detect or to defend against. And in addition to that, we always say that humans are the weakest link in the cybersecurity chain. That's why it's really significant to have a continuous education or continuous awareness programs on an individual level and on organizational levels against phishing or social engineering attacks. And when I say social engineering attacks, this means psychologically manipulating the target to either click on a link or to download an attachment or to reveal some sensitive information that they probably shouldn't, or to interact somehow with the sender to make things easier for the cyber attacker in an easier, cheaper, more effective way to gain unauthorized access to systems and to infrastructures. And what made you want to go into cybersecurity? The field of cybersecurity is in the intersection between several fields or domains that are really close to my interest and to my academic background, including management, computer science, software engineering, and also some other fields like psychology. But in addition to that, I would say the constant evolution and challenges of the field makes it really captivating field to be part of. And also, of course, in addition to that, the promising future of the field makes it an impactful career choice as well. There's so many opportunities in cybersecurity. Absolutely. And what is the most important thing to remember when working in cybersecurity? So in working in the field, it's really important to keep in mind that there is nothing that is 100 percent secure. So there are vulnerabilities or vulnerable system that we know that it's vulnerable. And there are other systems that have some vulnerabilities, but yet we haven't discovered that yet or we haven't identified that yet. So it's really important to keep that in mind and to have a goal of reducing the time between having the vulnerability and remediating or mitigating this vulnerability, which is one of the key goals that we have in cybersecurity. Also, we always say that key in cybersecurity stands for keep educating yourself. So ongoing education is really important. And I mentioned earlier that AI has significant impact on the field of cybersecurity, both positively and negatively, of course. But there's always new things. There's always new tools, new techniques. So continuous education is something really significant when you are in the field of cybersecurity. Also, one of the things that I share here is when you work in the field of cybersecurity, you work with some tools or techniques that might be used for good or for evil. So, of course, keeping in mind legal and ethical consideration is vital. Like AI, as you mentioned earlier. Absolutely. And I like what you said about key, keep educating yourself. I feel like that can apply to any career path that you're in. Absolutely. In your opinion, what is the best way to defend against a cyber attack? Being proactive is really important. Expecting that you might be targeted by a cyber attack and then act accordingly and build your own incident response accordingly is really important. That's why in most of the organizations, they have what they call the incident response runbook, where we have this written document of several scenarios of incidents that might happen, like being targeted by a ransomware or some other cyber attacks. And then what can we do to contain, to eradicate the threat? How can we respond effectively to that threat? And then maybe try to translate that into technical steps into our systems or in our infrastructure and automate what can be automated is something really important. But being proactive is the key here, of course. And again, I'd say enabling the human firewall is the best defense strategy, of course, through ongoing training and continuous education as well. Comes back to that. Keep educating yourself. Exactly. Because you helped shape the future minds of tech, can you share one thing that you wish future cybersecurity professionals knew? To build your defense strategy effectively, you might need to think from a cyber attacker's perspective or mindset. So that's why in the field of cybersecurity, we learn and we always teach something like cyber kill chain or MITRE ATT&CK or some other frameworks that helps us to understand the steps of cyber attacks. And then our goal as cybersecurity professionals is to either disrupt this chain as early as possible or to build our defense strategy also based on that. So thinking from the cyber attacker's perspective is one significant thing. And also, I would recommend reviewing the job ads in the field. And by reviewing that, they might have a better understanding of what the current market needs in terms of the skills that they might need to have, the certificates, the day to day job duties and so on. And lastly, if you weren't in cybersecurity, what would you be doing? I've always had a strong interest in forensic science. So if I'm not in the cybersecurity field, I think I would do something in the forensic science field. But also, I'm trying to currently apply my interest or my knowledge and experience in the cybersecurity field on digital forensics and more specifically on cloud forensics, which is something I work on from an industry perspective. But I'm trying now to tackle it from a researcher perspective to see what's the open issues in the field of cloud forensics and address that from a researcher perspective. You can tell that education is your passion. It's very important to you. Thank you. Thank you for your time today, Dalal. It was greatly appreciated. And as always, if our audience has any questions they'd like asked during a future Speed Data episode, please email me at pr at Varonis dot com. Thank you, Dalal. Thank you so much.