
19 segments available
The paradox of security is we pretty much know what we are supposed to do most of the time -- but we don’t do it. If you examine all the recent high profile attacks, somebody in the organization knew something was wrong before it happened. They just didn’t have the ability to escalate the problem, or the ability to raise a flag that people took seriously. The lack of foundational security hygiene is what makes companies vulnerable to relatively mundane attacks, which are far more likely to hit your company than some sophisticated nation-state mounted attack. “There’s this misconception that we can’t defend against these attacks because we can’t deal with the sophistication of the attackers,” says Tanium CTO Orion Hindawi. “In turns out, we should just be doing the good hygiene we’ve all been trying to do for the last 20 years.” In this segment of the a16z Podcast, Hindawi shares how to get your security hygiene right -- not just from a technical perspective, but from a cultural one as well.
Orion Hindawi discusses the challenges faced by security professionals in 2013, highlighting the increase in detected attacks and the growing volume of accessible data online. He explains how companies are becoming more vulnerable due to the sophistication of attacks and the need for better detection mechanisms.
"welcome to the a 16z podcast i'm michael copeland and i am here at the headquarters of teh neum with Orion and AH we CTO Orion thanks for coming or actually I'm visiting you so thanks for having me pl..."
Hindawi emphasizes the tension between the need for online data accessibility for business and the increased vulnerability it creates. He points out that as companies expose more data to the internet, they become prime targets for attackers who are becoming increasingly sophisticated.
"there are a couple factors there so the first factor really is that we're getting better at detecting that we've been attacked and so I think a lot of customers have invested in detective mechanisms s..."
In this segment, Hindawi discusses the irony that security experts know the basic hygiene practices necessary for protection, yet many organizations fail to implement them. He stresses the importance of fundamental practices like patching, disk encryption, and two-factor authentication to prevent attacks.
"attackers are actually getting a lot better we're definitely seeing the sophistication of the attacks that we're looking at increasing and I think the volume of data that they can go after and the acc..."
Hindawi addresses the misconception that sophisticated attackers are the primary threat. He argues that many attacks exploit known vulnerabilities due to a lack of basic security practices, highlighting the need for organizations to focus on fundamental security hygiene rather than seeking a 'magic bullet' solution.
"so you know the irony of security is we all pretty much know what we're supposed to be doing most of the time if you're a security expert and you've been doing this for a while we all know that they'r..."
Hindawi explores the psychological barriers that lead organizations to resign themselves to security failures. He compares this mindset to the challenges of maintaining a healthy lifestyle, suggesting that many organizations feel overwhelmed and believe they cannot achieve proper security hygiene.
"years and in many cases our customers are just realizing that they've been failing for 20 years and now they're actually realizing the frequency that they're being attacked by relatively mundane attac..."
In this segment, Hindawi critiques the idea that a single solution can solve all security issues. He emphasizes that security requires ongoing effort and commitment to basic practices, rather than relying on quick fixes or new technologies that promise instant results.
"possible to patch all their devices because they don't think that it's possible for them to get all of the antivirus and hips and disk encryption working the way that they were supposed to password po..."
Hindawi discusses the critical need for collaboration between security and operations teams. He highlights that successful organizations foster a partnership between these teams to quickly identify and address security gaps, ensuring a unified approach to protecting the organization.
"there's no way to be a hundred percent secure but the truth of the matter is if you look across the 10 biggest attacks us here all of them tied back to pretty mundane things that the organization knew..."
In this segment, Hindawi explains the natural tension between security and operations teams, where security often prioritizes urgent fixes while operations focuses on stability. He stresses the importance of both teams understanding each other's perspectives to effectively manage security threats without disrupting business operations.
"and really coordinating on finding and then fixing very quickly any gaps that exist in the work is is that relationship you know as operations worried that their ability to function gets hampered by s..."
Hindawi discusses the necessity for organizations to create an environment where security concerns can be escalated effectively. He points out that many attacks could have been prevented if someone had the authority to raise alarms, emphasizing the need for security to have a prominent voice within the organization.
"operational focus of the environment is maintained right and it's urgency not in the sense of like okay let's all freak out now it's urgency like okay we have a plan you know it's DEFCON 5 push the bu..."
This segment highlights a significant cultural shift in how boards perceive cybersecurity threats. Hindawi shares insights on how recent breaches have led to a greater acknowledgment of security as an existential threat, prompting organizations to invest significantly more in security measures than in the past.
"and it gets back to this this notion of like you need an environment where again people understand both sides like I can imagine that you don't want to raise the alarm if that's gonna you are worried ..."
Hindawi reflects on the aftermath of security breaches, noting that organizations often react with panic rather than strategic thinking. He contrasts this with companies like Target, which have successfully built resilient security structures post-breach, emphasizing the need for thoughtful decision-making in the wake of an attack.
"one of which I actually have any control over right and so that change drives behavior across the organization you look at a lot of these big companies they're spending literally ten times more on sec..."
In this concluding segment, Hindawi discusses how Target has evolved its security culture following its breach. He notes that the organization has recognized the importance of ongoing security vigilance, transforming its approach to prioritize security as a permanent and integral part of its operations.
"right and so you know we will often get business out of those situations but it's not the kind of business that I actually prefer my preferences a deliberate decision by the board or the CEO or the ma..."
After a significant breach, Target's leadership recognized the need for a cultural shift towards ongoing security vigilance. Hindawi explains how the organization learned from its past mistakes and now emphasizes the importance of maintaining a proactive security stance rather than reverting to business as usual.
"tremendously during that breach and I think you know there's more public on this then I can repeat here that you know gives context but they hired a great C so he hired a great set of lieutenants all ..."
Hindawi addresses how smaller companies can approach security differently than larger organizations. He discusses the importance of good security hygiene and the need for smaller firms to adopt basic security practices, even if they lack the resources of larger corporations.
"through the spectrum security is scary because it can cause massive damage the same way that you know a lot of things in our lives are scary cars are scary because people die in them every day and mos..."
In this segment, Hindawi emphasizes that good security practices are akin to safe driving. He argues that organizations should adopt basic security measures to prevent vulnerabilities, comparing the need for security hygiene to everyday safety habits that everyone knows they should follow.
"the results so my assertion would be this good hygiene that you should be practicing in security and operations everyone knows what it is let's just do it it turns out that if you do it you feel a lot..."
Hindawi discusses the necessity for organizations, especially those with significant data assets, to prioritize security. He explains that while smaller companies may not have the same capacity as larger ones, they still need to implement fundamental security practices to mitigate risks effectively.
"huge disclosure issue if they actually get attacked and they typically have a security set of personnel in the environment because they can't afford not to right I mean it's again a risk reward the ri..."
In this segment, Hindawi contrasts the threat posed by nation-state attackers with the more immediate risks from unpatched vulnerabilities. He argues that while nation-state attacks are serious, the majority of companies are more vulnerable to everyday threats from less sophisticated attackers. Hindawi stresses the importance of addressing basic security measures before worrying about advanced threats, as many organizations are not equipped to handle even the simplest vulnerabilities.
"haven't dealt with your patches you should be worried about kids that have access to Google not nation-states that want to attack you right that's kind of the point I'm making is that you know there t..."
Hindawi uses the analogy of building a house to explain the importance of understanding an organization's security infrastructure. He points out that many companies lack awareness of their own assets, making it impossible to implement effective security measures. This segment highlights the need for organizations to first establish a clear understanding of their security posture before making changes, ensuring that they can effectively manage security risks.
"vulnerability most of our customers are at the first level of that when we walk in our goal is to ratchet them up a couple levels of less obvious vulnerability and give them the tools to keep going bu..."
Concluding the discussion, Hindawi reassures listeners that improving security is achievable with the right tools and discipline. He addresses the fear surrounding security vulnerabilities, emphasizing that organizations can make progress by focusing on foundational hygiene first. This segment serves as an encouraging message that, despite the challenges, companies can enhance their security posture through consistent effort and the right approach.
"you don't know those things right it's not hard it's impossible so we would assert that you have to solve those problems first get the hygiene in place then let's go worry about everything else arjan ..."