Transcript
I'm your host, Jason Kikta, the CISO here at AutoMox. Today, we're stripping away the complexity and getting back to basics in ITOps. In a world of ever-evolving threats and technologies, it's easy to lose sight of the foundational principles that truly secure and optimize our environments. So let's dive into three core topics that are absolutely essential to IT operations. Play my jam. Our first topic is asset inventory management. Sounds simple, right? Know what you have. But you'd be surprised how often this fundamental step is overlooked or poorly executed. As a CISO, I can tell you that you cannot protect what you don't know exists. That's not just about hardware. It's about software, cloud instances, virtual machines, even shadow IT. A comprehensive, accurate, and continuously updated asset inventory. It's it's the bedrock of any security program. It informs your patching strategy, your volume management, your incident response, and even your compliance efforts. So if you don't have a clear picture of your assets, then you're operating blind. And that leaves gaping holes for attackers to exploit. Invest in tools and processes that give you real time visibility into your entire IT estate. A little story on this, and this is one thing that that I thought was just really fantastic at the time. I remember when Rob Joyce was running TAO, tailored access operations at NSA, and he went and gave a talk at USENIX back in 2010, 11, 12, 13, somewhere in there. It all runs together. But he said something that was really simple and yet really profound at that conference during his talk. He said, my job and the job of my team is to know your network better than you do. Right. To know the network better than the network owner. And I think that surprised a lot of people at the time. It's pretty obvious in retrospect. But at the time, that was deeply profound because people had an impression that attackers only learned what they needed to in order to get the attack done. But what they didn't realize is that the really top tier cyber actors took the time to learn every aspect of the network that they could and then leveraged it to their advantage. And that was, I think, a bit of a sea change in thinking around these topics. But let's move on to our second basic, patch management and vulnerability remediation. Another one that seems obvious, but the execution often falls short. Unpatched systems are low hanging fruit for attackers. Most successful breaches leverage known vulnerability for which patches have been available for weeks, months, even years. Right. So back to basic here means having a robust, automated and prioritized patch management program. It's not just about applying patches. It's about understanding your attack surface, identifying critical vulnerabilities and remedying them swiftly and automatically. That requires clear policies, consistent execution and a culture that understands the urgency of addressing security flaws. Don't let your organization become another statistic because of a preventable vulnerability. And a little story on this one. I remember when CISA in the U.S. government started putting out binding operational directives and emergency directives a few years back or several years back now, and it made news. And DOD had actually started doing something similar before that. But, you know, I think CISA needed some additional authorities to be able to give it to the civilian agencies in the U.S. government. But the reason those things came about is because we had so many breaches in the federal government, across the federal government, where, you know, vulnerabilities that had a, you know, a different year at the beginning, sometimes several years ago or a few years ago, kept getting leverage for intrusions into federal spaces, into federal networks. And it just became to the point where it was, I mean, it was obviously completely unacceptable, but it became so extreme that, you know, basically the discretion of most network owners was taken away, especially on high threat vulnerabilities. And it got pushed up to these centralized places to make the call for them. So, you know, that's the kind of mindset you need to have. This isn't, you can't delegate all this down to the application owner or down to particular system owners. You know, have an exceptions process if needed, have some mitigating controls if you have something that's mostly internal. But, you know, you have to be really aggressive with your mitigation policies. And, yeah, sometimes that is going to break things. But, you know, usually a brief outage is a lot cheaper than a full blown intrusion. And that brings us to our third basic, perhaps the most critical in a lot of ways when you're talking about cloud infrastructure and its identity and access management, who has access to what and why? That's the core question that IAM seeks to answer. And it means strong authentication, right? Multi-factor authentication, non-negotiable these days. It also means using the principle of least privilege to ensure users only have access, only have the access they absolutely need to perform their job functions, preferably only at the time they need it and nothing more. And it means regular access reviews to ensure that privileges haven't accumulated over time. Compromised credentials are a major vector for breaches. It's very popular these days, both for state actors and criminals. So securing your identities and controlling access is just paramount. Get your identity foundations right and you'll significantly reduce your risk. And again, I think about this not just from the security perspective, but from the IT safety perspective. I remember we had a few instances when I was young and starting out in IT management where we had an over-provisioned user who was able to delete the share drive for the entire organization because we gave them too many privileges and they thought they were deleting something that they owned, deleting their copy of it, and didn't realize that they were so over-provisioned that they could just delete everyone's files. And fortunately, we mostly had backups, not entirely though. And that was a painful learning experience for me as a young IT professional. It's one that I never forgot. But if you have good IT safety guardrails, those will also serve you with security imperatives as well. So, you know, don't underestimate the value. So there you have it, three fundamental pillars of good IT ops, at least from my perspective. Asset inventory management, patch management, and vulnerability mediation, and identity and access management. They're not flashy new technologies, but they are essential building blocks upon which all other operational excellence rests. If you're looking to strengthen your IT posture, start with these basics, master them, and you'll be well on your way to a more secure, reliable, and efficient environment. That's all the time we have today. Thanks for tuning in to the Audemars Piguet CISO IT podcast. Again, I'm Jason Kikta, and we'll catch you next time. Transcribed by https://otter.ai