Transcript
Yeah, because it will happen. It's not a matter of if, it's a matter of when. And so you just want to make sure that when it does happen, like you said, you've kind of minimized the blast radius, you've locked down everything that you can so that the impact is a lot less significant. Right, and you can recover faster. Yes, exactly. Welcome to Speed Data, quick conversations with cybersecurity leaders. I'm your host, Megan Garzep. My guest today is John Barrow, Chief Information Security Officer for J.B. Poindexter & Co. Thanks for joining me today, John. Sure, I'm glad to be here. John oversees security for the leading motor vehicle manufacturing group, ensuring the cybersecurity program runs like a well-oiled machine. Before joining J.B. Poindexter & Co., John led security teams at Texas Children's Hospital and Caesars Entertainment Corporation and was an intelligence analyst for the United States Army and NSA. In his free time, he somehow learned to speak Portuguese and he has his CISSP and BS in business and IT management. That's quite an impressive resume you've got there, John. What made you want to get into cybersecurity? Well, it was a natural transition from the intelligence community to cybersecurity. Same mindset, just different focus. Yeah. And so it's kind of happened naturally, like organically. Yeah. And what's your favorite aspect of cybersecurity? I would say my favorite aspect is the people. Working with people, communicating, making sure that we're aligned with their business objectives. I think a lot of times in IT and cyber, the focus is always technology. But you can't be successful in any cyber program unless you focus on the people, right? Yeah. So that's your most valuable asset is the people. Yeah. What do you think most organizations misunderstand when it comes to cloud security? What they misunderstand is they assume that the cloud provider provides all the security. Mm-hmm. But there's still – it's a shared responsibility, right? Yes. Like the organization still has to protect their assets and the data and all their applications within that cloud environment. Yeah. I think that shared responsibility model seems to confuse a lot of folks, unfortunately. But you do have your own responsibilities. And what do you think is the number one rule for data loss prevention? You need to work with the business. You need to make sure you minimize the operational impact when you're implementing DLP. I think that's where a lot of people are starting to not shy away but not focus so much on DLP because it's so hard to implement because they try to force it. They don't work with the business. They don't make sure they do proper testing and kind of do it methodically to minimize that operational impact. Yeah. And what type of data breaches or exploits keep you up at night? Like what are you worried about the most? Ransomware, obviously. But any time our business users are sharing sensitive data externally, things like that, that puts me up at night. Yeah. We do have protections in place for that and controls, but I know it's still happening, right? Yeah. So we're trying to minimize that and it's just training and education. Yeah, because a lot of times they'll share it externally or unintentionally. Right. And sometimes it's required as part of their business processes. So just ensuring that it's protected, it's encrypted in transit and things like that. Right. And what do you predict to be the biggest shift in cybersecurity? I think the biggest shift will be from having a cyber prevention mindset to cyber resilience because forever and ever everyone's been focused on preventing an attack. Yeah. Which is important, but it's going to happen. It's going to happen, yes. So I think cyber leaders and programs and organizations, they're going to need to really double down on their resilience. Yes. And I think it's going to be a shift even in investments and budget where it's going to be maybe 50-50 on prevention and resilience. Yeah. But I think that's going to be a huge focus. I mean, every day you read in the news another company has been compromised or whatever. I mean, I know that's what we've been focused on at my organization. Yeah. I mean, we did have an attack, and luckily we had made those investments in resilience for when it would happen rather than just hoping it doesn't happen. Yeah. Yeah, because it will happen. It's not a matter of if. It's a matter of when. And so you just want to make sure that when it does happen, like you said, you've kind of minimized the blast radius. You've locked down everything that you can so that the impact is a lot less significant. Right, and you can recover faster. Yes, exactly. And how do you think the threat landscape has changed since you began your career? It's actually much faster now. For a long time, I think the mean dwell time was like 15 days or months or sometimes even years where they would just sit persistent in your environment and wait for the perfect time to actually enable or execute whatever malware. But now with AI and everything else, that dwell time is a lot less where in personal experience with the tech we had, the second they got in our environment, they were already moving laterally. They were already trying to go to their objective. So it's immediate. So the speed. Yeah, AI has been such a game changer. Right. For both good and bad, really. Right, right. And you and I, you know, we've kind of chatted a little bit about our passions and your passion for running and my reluctance to do so. But if you weren't in cybersecurity, what would you be doing? I would probably be playing music, actually. Oh, yeah, because you said you're a drummer. I play drums and sing, and my dad was a musician in Nashville and all that. Oh, wow. So I'd probably be playing music. That's another one of my passions, yeah. Yeah. What kind of music do you play? Everything more rock and roll, but I've played country and hip-hop and funk. Hip-hop. Yeah. Wow. I did a world tour when I was in the military, actually, for six months where we toured the world playing in a top 40 band. I like to play everything, but rock's kind of my default. But I do love the rock, yeah. Yeah, yeah. Well, thank you so much for joining me today, John. I've loved chatting with you. And for our audience, if you would like to be a guest on Speed Data, please visit varonis.com slash speed hyphen data. Thank you, John. Thank you. Thank you.