Transcript
with Marco Marchiardo, Lead Security Architect at Zscaler. Marco, a question for you. A Zscaler report shows that 60% of companies expect a computerization in the next 12 months. What are the main criticisms that emerge from this data? Yes, Antonio, it is a very interesting report. In fact, reports of this type have always existed. Years ago, if you remember, there was the FBI that said every year the top percentage of companies have been attacked and the remaining top percentage will be attacked again. So nothing new. It is certain that today, compared to the past, there are huge differences. I talk to companies when they tell me I have 2,000 applications, partly in my internal datacenter, partly in Google Cloud, partly in AWS, I have to manage the management of the applications, I have a problem with NIST 2, so I also have to deal with the supply chain, and it becomes a more important problem. It becomes a much more important problem because, as we said, Google, AWS, Cloud, etc., I no longer have a real perimeter that I can defend or have to defend. Before, I closed the barriers. What was inside, was inside. What was outside, I scrutinized it so that I could decide whether to let it in, how to manage it. Today it is no longer like that. Today there is no longer a perimeter, albeit logical, let's call it physical, which delimits what I have to control and what I don't have to control. So, we have to change the paradigm today and say, look, today, the perimeter, the only perimeter that I can actually control is the user, is the authentication. And this is obviously one of the founding principles of Zero Trust, and it completely changes my paradigm. Just think of one thing, let's call it a traditional scenario. In a traditional scenario, the user with his computer reaches the application that he has to reach, Oracle, SQL, SAP, whatever it is, it is authentic and automatically has access. Let's forget about side movements, lateral movement and similar things. Let's imagine that there is only that application for which it connects, it connects, it is authentic and it works. Today, if it is true that the only possible perimeter is the user, I have to manage the authorization in a completely different way and therefore I must first say, tell me who you are, when I know who you are, I release you a set of authorizations that enables you to connect to that application. So, let's call it, the authentication phenomenon is shifted to the left, a shift left, a bit like you say when you do secure DevOps and DevOps development. We are talking exactly about this. We are talking about the fact that I have to authorize the user, my perimeter is him. It connects remotely, it connects with applications that I may not know, it connects with computers that could be managed, therefore corporate, or unmanaged, therefore personal, and maybe it is not authentic within my company, but it is authentic from home to an application that I have in the cloud. In this scenario, actually, the only and the first way I have to control security is to define that my user is my perimeter, so he is the main part that I have to face. So we can say that many resilience strategies are obsolete or underfunded? Of course, many resilience strategies are obsolete or underfunded. Here too, we have always talked, in fact, about disaster recovery, about business continuity. In fact, if you look at the NIST, be it the Cyber Security Framework, be it the 853, they are moving in this direction. But an organization within a GRC system, therefore Risk Governance and Compliance, has never been done. Just think, the NIST Cyber Security Framework came out two or three months ago, I think, the Framework 2.0, which adds the part of governance on top of this. As you can see from the slide, a resilient architecture must be integrated. So the Cyber Resilience, which includes and embraces business continuity and disaster recovery, as well as many other elements, maybe we will see them later in the conversation, are decisive, they are absolutely decisive. NIST is talking about it now. Now, speaking of Cyber Resilience, so having an integrated resilience strategy moves the topic from disaster recovery and business continuity to something a little wider, which is a Risk Management strategy that embraces these things. If you think of the Cyber Security Framework, the part of Identify and Protect, as highlighted in this slide, is the part of Risk Management. Respond and Recover is the part that talks more about Cyber Resilience, and then there is Detect, which obviously bridges the two factors. At this point, it is important, given the type of network architecture that exists today, I have to be aware of two phenomena. My resilience towards the cloud, so how I can manage the Cyber Resilience towards the cloud, certainly doing disaster recovery and managing optimal paths in order to be resilient and always have access to the cloud application. But not only that, it is probably a factor that not many think about. The resilience to the cloud, but also, and this is essential, the resilience of the cloud. I have to rely on providers that are able to manage a cloud architecture, possibly native to the cloud, and not a legacy structure that is brought to the cloud to follow the evolution of networks. But not only that, at the operational level, it is resilient itself. So, if I am resilient in the way I access the cloud and I know how to access an automatically resilient cloud, I get something different, I get something much more complete and pervasive. Just think of NIST, MITRE, certainly important, but not many think of the fact that there is a standard, which is an engineering framework, it is the NIST 800-160, which is really an engineering framework of Cyber Resilience, which embraces the whole Zero Trust part. So, being compliant, or following the guidelines, the modes, the Cyber Resilience framework automatically allows to integrate a Zero Trust strategy within the company. Marco, excuse me, let's talk for a moment about the need for constant update to face new threats such as artificial intelligence. Sure, Antonio. Of course, the problem remains to face the most recent thing, which is to face threats deriving from artificial intelligence. In reality, as with artificial intelligence, there are two main categories of threats from which we must defend ourselves. The classic deepfakes, so techniques that use artificial intelligence to filter information, and techniques that are used to create new malware. Today, as you know, the use of artificial intelligence helps to build the Python script that is used to perform that particular attack, so to bring tailored attacks intended for a particular company. Given, of course, the speed of the vehicle, we must take precautions. We are talking about it, we are talking about it, we are talking about, therefore, Fight AI with AI, which means that we must fight artificial intelligence with artificial intelligence. With Zscaler, we already do it, actually. Because with Zscaler, if you think that we have the possibility to block or enable access to certain... One can block access to chat GPT and leave access to others free, or vice versa. It can block file filtering, because, as artificial intelligence, we have also connected it to the DLP part. So, maybe leave access to artificial intelligence, so to chat GPT, but avoid certain files being uploaded, or files with certain information, using our DLP solution. In addition, it is possible to have a registration, let's call it registration, of course, everything in terms of privacy regulation, respected, but doing so that what is asked of artificial intelligence is also logged, anonymously, but you can, for example, say, if in the request these certain characters appear, this certain word, this sequence of words, well, we avoid sending them out, so we block access, even leaving access to artificial intelligence, but we block the fact that it can actually be used in some way. Marco, now I want to face for a moment a bit a transition from the traditional approach to the Resilient by Design strategy. You know, one of the critical aspects is that many companies give priority to prevention over response and recrystallization. Why does this represent a problem and what changes with a Resilient by Design approach? Actually, it changes a lot, it changes substantially. Resilience, or cyber resilience, has always been seen as the part, let's say, of disaster recovery and continued business together. Actually, cyber resilience, organized in a way, among other things, complies with the standards of cyber security that exist today, it takes the moves from the integration with a company risk management strategy. So, you have to deal with the management part of business risks. How do you win from this slide? In the end, any method is used to do risk management, whether it is an analysis, qualitative, quantitative, that uses FAIR, that uses the Cyber Resilience Framework, whatever it is. In the end, you fall back to a high level within this model. A risk is still a probability for an impact, the probability is a vulnerability for a threat and the threat obviously depends on the capabilities, the opportunity and the will of the attackers to effectively attack the company. And this, if you look at it, matches perfectly with the organizational structure of risk management that many companies have given themselves, if not almost all. You start from the bottom, when we talk about understanding the ability of an attacker, we are talking about threat hunters, we are talking about threat intelligence, we are talking about forensic analysis, of SOC activity, if you prefer. At a higher level, vulnerability for threat, any company today has a vulnerability management program or a threat management program on the field. All this information naturally comes from the SOC, which comes from the internal or external threat intelligence, maybe both, and from vulnerability management systems must be taken into account by the enterprise risk management function, which, as you well know, uses specific tools made specifically for them, Excel. Reconciling all this information is necessary because then it must be passed to the CISO, to the GRC team and therefore also to the board, so that they can evaluate and calculate the company's capital risk, therefore the residual risk, which budget to associate with any evolution of the security strategy and, of course, also their prioritization. Always remaining on the subject, this, as a risk management system, fits well with the four fundamental principles, called goals, of the Cyber Resilience framework, the one I was talking about before, the NIST Engineering Framework, 800-160 version 2, which, if you look at the four goals from the bottom up, they speak of anticipate, withstand, recover and the second of the versions. And looking at the definitions, it is clear that we are still talking about business risks, we are never talking about technological risks or vulnerabilities in themselves, we are talking about continuing the corporate mission, continuing the corporate business function, in any case or any event that then is the same definition of resilience. What is interesting about this framework? This framework is a very interesting thing, as you can see from the two red circles I made, it was written by NIST and MITRE at the same time, so it is an engineering framework that includes a strategic part coming from NIST and an operational part. You know, many frameworks today can be either strategic, or operational, so it collects, as they say, the best of breed of technology and is absolutely aligned, among other things, with the implementation of Zero Trust architecture, so following a framework, the NIST Cyber Resilience framework, NIST is marked anyway, this document allows the implementation of this framework. Naturally, the difference lies in the fact that this can be integrated into the risk management strategy, as we said before, and therefore be part of the long-term business strategy. An implementation, let's talk about six months, a year, maybe even two years. Yes, a single strategy, therefore a Cyber Resilience strategy, which, however, is integrated with a risk management system, therefore governed by a GRC structure and which follows a framework or possibly more framework to also guarantee compliance, possibly compared to other standards, which, of course, automatically also implies the adequacy of a Zero Trust architecture and vice versa, so the part of transformation, as you said, integrating prevention and integrating the strategy is absolutely present. But in addition to this, compliance is also possible compared to NIST 2, for automation, the OT, there is the ESI standard 62443, which can be integrated and mapped within a single strategy, as you said, and therefore have the completeness of the solution. How can we talk about the advantage of being, therefore, of proactivity, therefore the advantage of being proactive in facing threats? The first task, in fact, of a company that wants to have an effective cybersecurity system is to generate and develop two phases. If we remember before, at least, from the risk management side, the fact that there is a constant flow depends on the fact that there are two phases, the phase of anticipation and the phase of evolution. So the first and the last. The first automatically implies proactivity. If I have to be able to anticipate attacks, and therefore it is the phase that allows me to understand the opportunity, the ability and the will of an attacker to attack. The Zero Trust, as Zscaler sees it, for example, works on three phases. So, I want to connect to a resource, whether it is a private resource, whether it is a public resource, it does not matter. The paradigm remains the same. First thing, authentication, we said. So, who are you? Where do you go? So, the resource you are trying to access, is it actually a legal resource or is it a URL that I already have to block, rather than an application on which you do not have permission to access it? So, the first thing is to know where you are going, it is important to close the door before you reach the resource and be authentic on the resource itself. And the third thing, what do you bring? So, deep inspection of the sessions to understand if there are any exceptions. So, for example, we have a very important deception architecture that works very, very well and that naturally does its job. So, it allows to distribute onipods, both internal and external, to the company, at the end of the session. So, the first thing is to know where you are going, it is important to know where you are going, it is important to know where you are going, it is important how you are going, it is important to know where you are going, it is important how you are going, it is important how you are going, it is important how you are going where you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important how you are going, it is important you are going for how you are going, it is important how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you are going for how you re going for how you are going for how you are going for how you are going for how you are going for why you are going for what you are going for where you are going for what you are going for why you are going for when you have been good for six years ago tell me what you are doing now what are you doing now so tell me what you are doing now tell me what you are doing now so tell me what you are doing now so tell me what you are doing now so tell me what you are doing now so tell me what you are doing so so those who are seeking answers from us tell me what you are doing now so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what are your goals I figured out that I don't have to tell you what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what are you doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what you are doing so tell me what doing so tell me what you are doing so tell me what you are doing so you are doing so tell me what you are doing so so tell me what you are doing so you are doing so tell me what you are doing so you are doing so I am doing so entertain so I love you so I have two questions for you tell me what you are doing so I love you so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you are doing so I have two questions for you tell me what you