Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Three Foundational Pillars of Secure IT Operations

Automox
09/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm your host, Jason Kikta, the CISO here at AutoMox. Today, we're stripping away the complexity and getting back to basics in ITOps. In a world of ever-evolving threats and technologies, it's easy to lose sight of the foundational principles that truly secure and optimize our environments. So let's dive into three core topics that are absolutely essential to IT operations. Play my jam. Our first topic is asset inventory management. Sounds simple, right? Know what you have. But you'd be surprised how often this fundamental step is overlooked or poorly executed. As a CISO, I can tell you that you cannot protect what you don't know exists. That's not just about hardware. It's about software, cloud instances, virtual machines, even shadow IT. A comprehensive, accurate, and continuously updated asset inventory. It's it's the bedrock of any security program. It informs your patching strategy, your volume management, your incident response, and even your compliance efforts. So if you don't have a clear picture of your assets, then you're operating blind. And that leaves gaping holes for attackers to exploit. Invest in tools and processes that give you real time visibility into your entire IT estate. A little story on this, and this is one thing that that I thought was just really fantastic at the time. I remember when Rob Joyce was running TAO, tailored access operations at NSA, and he went and gave a talk at USENIX back in 2010, 11, 12, 13, somewhere in there. It all runs together. But he said something that was really simple and yet really profound at that conference during his talk. He said, my job and the job of my team is to know your network better than you do. Right. To know the network better than the network owner. And I think that surprised a lot of people at the time. It's pretty obvious in retrospect. But at the time, that was deeply profound because people had an impression that attackers only learned what they needed to in order to get the attack done. But what they didn't realize is that the really top tier cyber actors took the time to learn every aspect of the network that they could and then leveraged it to their advantage. And that was, I think, a bit of a sea change in thinking around these topics. But let's move on to our second basic, patch management and vulnerability remediation. Another one that seems obvious, but the execution often falls short. Unpatched systems are low hanging fruit for attackers. Most successful breaches leverage known vulnerability for which patches have been available for weeks, months, even years. Right. So back to basic here means having a robust, automated and prioritized patch management program. It's not just about applying patches. It's about understanding your attack surface, identifying critical vulnerabilities and remedying them swiftly and automatically. That requires clear policies, consistent execution and a culture that understands the urgency of addressing security flaws. Don't let your organization become another statistic because of a preventable vulnerability. And a little story on this one. I remember when CISA in the U.S. government started putting out binding operational directives and emergency directives a few years back or several years back now, and it made news. And DOD had actually started doing something similar before that. But, you know, I think CISA needed some additional authorities to be able to give it to the civilian agencies in the U.S. government. But the reason those things came about is because we had so many breaches in the federal government, across the federal government, where, you know, vulnerabilities that had a, you know, a different year at the beginning, sometimes several years ago or a few years ago, kept getting leverage for intrusions into federal spaces, into federal networks. And it just became to the point where it was, I mean, it was obviously completely unacceptable, but it became so extreme that, you know, basically the discretion of most network owners was taken away, especially on high threat vulnerabilities. And it got pushed up to these centralized places to make the call for them. So, you know, that's the kind of mindset you need to have. This isn't, you can't delegate all this down to the application owner or down to particular system owners. You know, have an exceptions process if needed, have some mitigating controls if you have something that's mostly internal. But, you know, you have to be really aggressive with your mitigation policies. And, yeah, sometimes that is going to break things. But, you know, usually a brief outage is a lot cheaper than a full blown intrusion. And that brings us to our third basic, perhaps the most critical in a lot of ways when you're talking about cloud infrastructure and its identity and access management, who has access to what and why? That's the core question that IAM seeks to answer. And it means strong authentication, right? Multi-factor authentication, non-negotiable these days. It also means using the principle of least privilege to ensure users only have access, only have the access they absolutely need to perform their job functions, preferably only at the time they need it and nothing more. And it means regular access reviews to ensure that privileges haven't accumulated over time. Compromised credentials are a major vector for breaches. It's very popular these days, both for state actors and criminals. So securing your identities and controlling access is just paramount. Get your identity foundations right and you'll significantly reduce your risk. And again, I think about this not just from the security perspective, but from the IT safety perspective. I remember we had a few instances when I was young and starting out in IT management where we had an over-provisioned user who was able to delete the share drive for the entire organization because we gave them too many privileges and they thought they were deleting something that they owned, deleting their copy of it, and didn't realize that they were so over-provisioned that they could just delete everyone's files. And fortunately, we mostly had backups, not entirely though. And that was a painful learning experience for me as a young IT professional. It's one that I never forgot. But if you have good IT safety guardrails, those will also serve you with security imperatives as well. So, you know, don't underestimate the value. So there you have it, three fundamental pillars of good IT ops, at least from my perspective. Asset inventory management, patch management, and vulnerability mediation, and identity and access management. They're not flashy new technologies, but they are essential building blocks upon which all other operational excellence rests. If you're looking to strengthen your IT posture, start with these basics, master them, and you'll be well on your way to a more secure, reliable, and efficient environment. That's all the time we have today. Thanks for tuning in to the Audemars Piguet CISO IT podcast. Again, I'm Jason Kikta, and we'll catch you next time. Transcribed by https://otter.ai

TL;DR

  • Asset inventory management provides the foundational visibility needed for security programs, covering hardware, software, cloud instances, and shadow IT to prevent operating blind against attackers.
  • Patch management must be automated and prioritized with aggressive remediation policies, as most breaches exploit known vulnerabilities that have had patches available for weeks, months, or even years.
  • Identity and access management requires multi-factor authentication, least privilege principles, and regular access reviews to prevent credential compromise, which has become a major attack vector for both state actors and criminals.
  • The three pillars—asset inventory, patch management, and IAM—are not flashy technologies but essential building blocks upon which all operational excellence and security posture rest.

Asset Inventory as Security Foundation

Jason Kikta opens by emphasizing that comprehensive asset inventory management is the bedrock of any security program. Organizations cannot protect what they don't know exists, and this extends beyond hardware to include software, cloud instances, virtual machines, and shadow IT. A continuously updated asset inventory informs patching strategy, vulnerability management, incident response, and compliance efforts. Kikta references Rob Joyce's insight from NSA's Tailored Access Operations that elite attackers aim to know target networks better than the network owners themselves, underscoring why real-time visibility into the entire IT estate is mission-critical.

Patch Management and Vulnerability Remediation

The episode addresses how unpatched systems remain low-hanging fruit for attackers, with most successful breaches leveraging known vulnerabilities for which patches have been available for extended periods. Kikta draws from his government experience to explain how CISA's binding operational directives emerged from repeated federal breaches exploiting years-old vulnerabilities. He advocates for robust, automated, and prioritized patch management programs that understand attack surfaces and remediate critical vulnerabilities swiftly. The discussion emphasizes that brief outages from aggressive patching are far cheaper than full-blown intrusions, and that discretion cannot be delegated entirely to individual application or system owners.

Chapters

0:00 - Introduction and Episode Overview
0:30 - Asset Inventory Management
2:48 - Patch Management and Vulnerability Remediation
5:25 - Identity and Access Management
7:20 - Recap and Closing

Key Quotes

0:54 "As a CISO, I can tell you that you cannot protect what you don't know exists."
2:08 "My job and the job of my team is to know your network better than you do."
2:52 "Unpatched systems are low hanging fruit for attackers. Most successful breaches leverage known vulnerability for which patches have been available for weeks, months, even years."
5:18 "Usually a brief outage is a lot cheaper than a full blown intrusion."

FAQ

Why is asset inventory considered more important than just knowing what hardware you have?

Asset inventory must extend beyond physical hardware to include software, cloud instances, virtual machines, and shadow IT. Without comprehensive visibility across all these dimensions, organizations cannot effectively patch systems, manage vulnerabilities, respond to incidents, or maintain compliance. As the episode emphasizes, you cannot protect what you don't know exists.

How aggressive should organizations be with patch management policies?

Organizations should implement automated, prioritized patch management with minimal discretion delegated to individual system owners. While exceptions processes and mitigating controls may be necessary for some internal systems, the default posture should favor aggressive remediation even if it risks brief outages, as these are far less costly than full-blown intrusions from unpatched vulnerabilities.


Categories:
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Best Practices
  • Identity & Access
  • Endpoint Management
  • Compliance & Governance
  • Technical Deep Dive
  • Asset Inventory Management
  • Patch Management
  • Vulnerability Remediation
  • Identity and Access Management
  • Multi-Factor Authentication
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Three Foundational Pillars of Secure IT Operations

              Industry Events (Sponsor Hosted)

              • Oct
                01

                Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?

                10/01/202601:00 PM ET
                • Oct
                  13

                  Interactive Q&A Session on DatasecAI 2026 Insights and Innovations

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: A Comprehensive Approach to Visibility and Control
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-a-comprehensive-approach-to-visibility-and-control/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-arrival-of-the-agentic-internet-whats-next/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Interactive Q&A Session on DatasecAI 2026 Insights and Innovations
                      https://www.truthinit.com/index.php/channel/2141/interactive-q-a-session-on-datasecai-2026-insights-and-innovations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version