Security Confidential S12 E4 Ryan Leirvik

This week on Dark Rhiino Security’s Security Confidential podcast, host Manoj Tandon speaks with Ryan Leirvik. Ryan is the CEO of Neuvik and the author of the book “Understand, Manage, and Measure Cyber Risk”. His past adventures include growing a cyber research and development company, formerly serving as Chief of Staff and Associate Director of Cyber for the U.S. Department of Defense, a cybersecurity strategist for McKinsey, and a technologist at IBM.

00:00 Introduction

00:17 Our Guest

01:08 Behind the name Neuvik

02:20 What does Neuvik do?

03:29 Imperfect Technology layered on Imperfect Technology

05:35 Is the next gadget worth it?

07:54 Guiding a newbie CXO

10:50 What is it that you’re protecting?

22:54 Which framework has worked the best?

25:56 Understand, Manage, and Measure Cyber Risk

35:39 Leveraging vulnerabilities for offensive purposes

40:35 Connecting with Ryan

Transcript

MANOJ (00:00.731)
Hello everyone, welcome to another episode of Dark Rhino Securitys, Security Confidential. Today we are honored to have Ryan Leirvik join us. Ryan is the CEO of Nuvik. And Ryan’s last name is Lirvik. And there’s a story there. And we’re gonna connect the dots here in a second, but you should look up on him. He is an author. He has written the book, Understand, Manage, and Measure Cyber Risk. And we’re gonna talk a little bit about that today.

but he’s a awesomely qualified person. He has been in cyber research and development. He has served as the chief of staff and associate director of cyber for the USDOD. He has been a cyber strategist with McKinsey and Company and a technologist with IBM. We’re honored to have you here. Ryan, thank you for spending a couple of minutes with us.

Ryan Leirvik (00:52.078)
My nose, thanks for having me. It’s my honor, really, I appreciate it.

MANOJ (00:56.651)
Yeah, so for our audience, you know, your company’s name is Newvik and your last name is Lirvik. There’s a limerick in there somewhere. Connect the dots for us, please. I’m sure this is a great origin story.

Ryan Leirvik (01:04.494)
coincidence?

Ryan Leirvik (01:11.622)
Oh, sure. Yeah, happy to. And it’s funny, it kind of maybe goes back a little bit to sort of what you’re reading from the bio there. So back when I was at the D.O.D., we were doing offensive cyber warfare. Right. And so I was also trained in incident response. And I got discussions from some clients or soon to be clients about, hey, can you help sort of frame out some incident response stuff? It’s way back, like 20 years ago. So I needed a name right for an organization to sort of spin up.

And I just won a Garmin Nuvi from a Sands hacking course right back in like 2003 or 2004, yeah. And just won one, I thought, oh, this is great, right? Like I love the Nuvi because, you know, it gave you directionally accurate, well, directions to where you were going. And I needed a top level domain, so I figured, well, why not a relic of my first hacking win with my last name and Nuviq won out. So there you have it.

MANOJ (02:09.513)
That’s a great story. What do you guys do at NuVic?

Ryan Leirvik (02:09.686)
Yeah.

So we do three things, right? So what we think of sort of the cornerstones of service, right, we’re a peer-play cybersecurity services company. What does that mean is we provide sort of the White Club Service on incident, sorry, we don’t do any incident response, we do. White Club Service on red teaming, so that’s our sort of advanced assessments. So we’ll do anything from like very, very advanced sort of pen testing to actual red team emulations inside the environment to find vulnerabilities, to training.

So we run a training division that teaches individuals and you know, say SDLC trying to shift left in security. Right? And then of course, the third piece is risk management because that’s where it all sits. Right? We’re able to communicate this to executives and managers to understand what’s the actual risk of the vulnerabilities we find, or what’s the actual risk of, you know, that we’re reducing through the training of SDLC. So that’s, we do those three things from a services standpoint.

MANOJ (03:10.1)
That’s fantastic and I gotta take it that business is probably doing very good given the current environment.

Ryan Leirvik (03:16.106)
Yeah, it’s one of those businesses you kind of want to work yourself out of, given the business environment. Yes, absolutely. There’s a significant amount. In our world, Minoj, it’s interesting. We just keep seeing sort of imperfect technology layered on imperfect technology and us expecting it to interoperate perfectly, right? It doesn’t work that way. So, we have to, us and other services organizations come in and say, all right, here’s where the holes are, right? Here’s why they’re important.

Here’s how to fix them. Now, fix them so that you don’t have some sort of material impact, you know, from the risk manager’s side on your business.

MANOJ (03:53.115)
There is a lot to unpack in that last statement that you just made. And it’s true. I think often, almost 99.999% of the time, when if I’m at a social event and someone out of the cybersecurity, who’s not in the world, comes up and talks to me, they’re thinking cybersecurity, black hoodie, back room, high tech.

Ryan Leirvik (03:54.934)
Hehehehehehe

MANOJ (04:21.591)
uh, you know, people that are just coding or hacking or doing it’s the typical stereotype in the lay person’s mind.

But it’s really not, I mean, a good chunk of this problem is not a tech problem, it’s a human behavioral issue. It’s a business problem in many respects, right?

Ryan Leirvik (04:42.854)
Yeah, 100% in ocean fact, I would say it starts with the business decision of getting into information technology. Like that’s where the problem begins. And then the decision on whether or not to layer in a significant investment or priority of security, which is to say, we know where this IT is, information technology is connected to, what it’s doing.

how it’s working the way we expect it to work, right? That’s where the problem actually begins, right? Versus the opposite of that is chasing the shiny object and buying cool things and just asking your IT folks to plug them into the network without really understanding sort of how they interoperate, right? Which just creates massive amounts of holes. Well, could potentially create, yeah.

MANOJ (05:29.635)
It can, yeah, but why is it so prevalent then that exactly what you said in the latter piece of this is exactly what’s happening? Everyone is out there looking for the next gadget. As soon as the next best word comes up, XDR, Zero Trust, ZTNA, whatever the heck it is, and I’m sure there’s more, God knows how many acronyms, we have more than the US military, but everybody goes to that.

But how about, why not look at process people what’s worth protecting first and then kind of work backwards as to what really needs to be layered in. You were at McKinsey, I was never that smart. So what’s the story?

Ryan Leirvik (06:00.066)
Mm-hmm.

Ryan Leirvik (06:12.302)
It’s way too logical of a notion.

Ryan Leirvik (06:16.638)
Oh, don’t conflate me being there and being smart by any stretch. Sometimes we get lucky in our careers. So yeah, look, it’s interesting because businesses are all organized differently. They’re organized to be in business for something. Or let’s just say even organizations are organized differently. It might not be in business, you might be a government entity or just providing a service not for profit. So maybe a…

MANOJ (06:20.902)
Hahaha

Ryan Leirvik (06:44.134)
not quite a business per se, a for-profit business, but in business. And the organization side of it isn’t always thought through right off the bat, right? Sometimes it’s more about trying to do whatever it is we’re trying to do without thinking through the underlying information technology pieces that we may need, right? How they’re actually gonna interoperate, and oh, by the way, what’s really important to protect that’s critical to the business or the organization so that we need to be mindful of putting proper controls around that.

And you laid it out nicely because that systems that nice, I can tell you’re an engineer, right? That systems thinking behind what you just laid out isn’t always there when business decisions are made. And sometimes they’re made without understanding, in our case, impact to what critical systems may create some sort of material impact to business, right? But you can tell that systems thinking that you just laid out not always is there. And so the argument is it starts with the business process.

MANOJ (07:16.551)
It…

Ryan Leirvik (07:41.678)
business decision of purchasing some tool or capability that may or may not fit in the ecosystem that we currently have.

MANOJ (07:50.259)
Is there anything in your experience that would guide a newbie CXO, right? In getting their arms around the world of cyber without getting mired in technology, which is what their IT or CISO is gonna do to them. What can they do to actually get a baseline understanding of what they’re dealing with here?

Ryan Leirvik (08:03.949)
Mm-hmm.

Ryan Leirvik (08:15.53)
Yeah, that’s a great question. So I like breaking it down into the classic threes, right? First, like understand what problem it is you’re actually solving for, right? Two, get that problem under management. And then three, we all love measures, right? Get some sort of measure, like a performance measure or a risk measure, if you will, that measures that performance. And that’s the system’s thinking. I noticed that you laid out that in a security point of view, if you’re just getting started, right? Can be wickedly helpful because

Look, in a world where we have multiple layers from a CXO perspective, right? We have multiple layers of individuals who have some sort of either say in what you’re doing, demand on what you’re doing, or expectation or some combination of the three. You know, you’ve got the executive team above you that you have to report to on what, you know, what may or may not be a well-defined definition of like, hey, what’s our cyber risk, right? You got your peers.

MANOJ (09:03.111)
Sure.

Ryan Leirvik (09:12.898)
at the executive level to say, hey, I need to invite the legal team in, or the procurement team, which may or may not be illegal, and maybe the IT side isn’t necessarily in the CXO side. So you’ve got to bring in the risk team or the technologist side or the IT side. So you’ve got to work across all your peers, and then you’ve got to lead teams to success. And that’s the management side all at once.

For me, as these patterns start to unfold themselves in all organizations, to me, the three pieces really are, understand what the problem is you’re actually solving for from a cyber standpoint, right? And have a clear definition of risk, if you will, right? Define that in a way, define sort of material impact. This sounds all easy as we’re going through it, right? But these are the fundamentals, right? And then have that under management, like choose a way of managing that covers, you know.

MANOJ (09:58.831)
Oh yeah.

Ryan Leirvik (10:07.946)
what you’re actually trying to manage, and then have performance measures that actually speak to your ability to manage that. Those are sort of the three things that, you know, it seems like are the fundamental pieces. And if you take care of those and have that sort of through line through everything, it has this interesting impact of, or, you know, intended impact to get focused on what problem is we’re solving for so that when these things get thrown at you, you at least have a place to put them over time.

MANOJ (10:34.075)
So one of the things that, and I’m gonna speak just for my personal self here that I have seen at least historically in this industry is that companies, believe it or not, Ryan, have a very difficult time when it comes to the risk conversation, first defining what is it that they’re protecting? And I kid you not, and I’ll give our listeners a little bit more color on this so I’m not gonna leave everybody hanging. Because people will be like, what the hell do you mean? You don’t know what the hell you’re guarding. So.

Ryan Leirvik (10:53.406)
Yes. Yeah.

MANOJ (11:05.34)
I’ve used this example on the air a couple times without naming the company, but there’s a major motion picture house that absolutely, I will not mention it, but I guarantee you that whoever’s listening to this has definitely seen movies from them. 1000%, it’s impossible they did not. Now, they don’t have a sizzle, they have sizzles, multiple sizzles across different groups. Now,

Ryan Leirvik (11:12.474)
Hmm.

Ryan Leirvik (11:25.026)
Hehehe

MANOJ (11:33.187)
If you know something about movie production, it is a layered process that goes from team to team. There’s a team doing the shoot, a team doing the editing, and then there’s people compiling and putting it all together. Well, in the very end, what used to be the cutting room floor, which is all digital now, that cutting room floor, which contains the final product, the final product ended up on a server that was open to the world.

Right? So you think a company spends $110 million in the production of a major motion picture and it ends up on a server that is unguarded because it’s being used by a small group of people that are editing it and putting together and they got their own little setup going. Right? That’s not figuring in anyone’s risk equation, right? So…

Ryan Leirvik (12:21.198)
Mm-hmm.

MANOJ (12:28.247)
what is it that you’re guarding? And in that case, their mission should have been, guard our IP, which is movies, that’s what we make, and find that wherever it is. But we, I mean, this is a major company with an infinite budget. It didn’t work. So how?

Ryan Leirvik (12:36.339)
Mm-hmm.

Ryan Leirvik (12:46.45)
Mm-hmm.

Yeah, especially if you’re gonna publish something that might upset somebody else. It might make you a target for something, right? That you otherwise wouldn’t want. So yes, there’s all of that, right? And that’s the challenge. And I think you strike to the core of what the problem is, which is, do we understand what’s actually critical inside the business? Like what…

MANOJ (12:55.939)
Ha! Yeah!

Ryan Leirvik (13:14.75)
what do we need to protect, what’s worthwhile protecting? And then how do we put controls around those? So in this case, whether or not, just happens to be, hypothetically speaking, a movie that upset a large, let’s just call it area, to be as obscure as we possibly can, that would then turn their attention to you to heighten their adversarial response, let’s just say.

MANOJ (13:29.658)
Yeah.

Ryan Leirvik (13:42.07)
Absent that, right, because that’s just the threat side of it, right? If we kind of really break down the security of the landscape, like that’s a threat, right? That probably didn’t exist before the publication of this hypothetical movie that you’re talking about, right? But the interesting thing is from the threat is actually less relevant in this as to your point is the critical information, which is the intellectual property of the movie, especially prior to release.

MANOJ (14:07.149)
Exactly.

Ryan Leirvik (14:07.214)
before it gets out there and it’s distributed and you start to lose ownership control and things like that because of the supply chain that is or the distribution chain that is movie production. The issue here is do we know what’s important and if released prior, if let’s take the CIA, the confidentiality of it, the integrity of the availability of said item is disturbed in any way prior to…

MANOJ (14:29.339)
Yep.

Ryan Leirvik (14:34.59)
us not owning that timeline, what’s the material impact, you know, to the business itself? And without understanding that in front, you don’t know what, one, what problem you’re solving for, right, and two, what controls to put in place, and like you say, like, you know, production server with access to the final product, right, may or may not have solved the problem, we’re not gonna get into that piece of it, but at least you know what’s important, right? And that’s where I think,

Manoj, to your point, this is where we start to lose the essence of why we’re actually in, that why we’re even having this cybersecurity discussion in the first place. There’s all this, there used to be, there still is, but back in 10 years or more, it was all about FUD, fear, uncertainty, and doubt. It’s like, oh my gosh, what happens if somebody hacks my phone? It’s like, well, what if somebody hacks your phone? Like, does it matter?

MANOJ (15:19.557)
Yep.

Ryan Leirvik (15:27.538)
There’s a lot of uncertainty in there and fear in that, and so we sort of see the problem bigger than it is. And so, if we react to a problem where we don’t fully understand what it is, well, we’re gonna wind up with a lot of inefficiencies in decision-making, right? But the way to do this is, as you say, let’s sort of flip it to like, all right, what’s really important? Is it the intellectual property of this particular piece? Okay, great, what are we doing to protect that? Who’s authorized to have access to either the editing content, right,

the final product once made. Great, how do we know that those people are acting in the right way? Okay, great, we have compensating controls over that. Okay, so I mean, look, nation states do this quite well, and most, like Department of Defense does this quite well. You know very clearly what’s confidential, what’s secret, what’s top secret, right? And then the components above that. But most organizations don’t necessarily have that problem unless you’re in legal…

MANOJ (15:56.93)
Yep.

Ryan Leirvik (16:25.842)
entities, right? You know, law firms and others or banks for that matter. And so I think that’s really it. And you know, from back to your sort of root question on this CXO side, getting back to defining what it is we’re actually protecting and why it matters, helps to one, protect it, right? And put compensating controls around it. But two, which is the big piece, it helps to define the problem that we’re actually solving for. So when we start talking about resources, we started talking about, you know, time, people.

actual cash budgets to put towards things, we know what it is that we’re actually dealing with.

MANOJ (17:02.723)
And you described it really well when you said, you need to know what you’re protecting. Then you need to know if the people around it are behaving appropriately. And then you’re talking about compensating controls. So technology doesn’t really come in until step three, right? There’s so much that can really happen with…

Ryan Leirvik (17:15.757)
Mm-hmm.

MANOJ (17:27.471)
I’m gonna say, you know, probably the most underutilized cybersecurity asset in the company is the people themselves is bringing that awareness level of that group up can probably do better than any firewall is gonna ever do for you. Not saying firewalls aren’t important guys, I’m not beating on those. It just came out, but it’s really about if you can affect

Ryan Leirvik (17:43.076)
Mm-hmm. Yeah, if

MANOJ (17:54.415)
the human behavior with an A, then you can effect cybersecurity risk in a positive fashion.

Ryan Leirvik (18:01.126)
hands down, Manoj. And here’s a perfect example of how, remember, we probably shouldn’t say, when the defenses are so high, right, and there’s a critical asset somewhere that somebody wants, they’re gonna impact the individual. They’re gonna go for the human, right? I think Stuxnet taught us that, right? You know, with the centrifuges. So like the issue there is, you can protect the heck out of everything, but like it’s the, it all starts with us, the humans. Like we create, you know,

MANOJ (18:16.962)
Yes.

Ryan Leirvik (18:31.338)
for some reason, or we either create bad code, right? Or insecure applications, we push them into some cloud instance somewhere, which is even more insecure, depending on who actually architects it and pushes it out, right? And then we expect it all to work perfectly without saying, hey, what’s actually critical in here? Like, who’s the person that actually does this? And do they have the right training? Do they actually know what they’re doing? Because a lot of these times, it’s just a simple mistake. We see this in cloud infrastructure all the time. It’s like, hey, let’s push the cloud. OK, great, why?

Well, because we’re going to gain all these efficiencies in not having on-prem systems. OK, terrific. Well, as you push your architecture there, your infrastructure there, like those that are architecting the cloud infrastructure, buckets, blobs, whatever you wind up choosing from a provider standpoint, are they trained well enough to know simple things like not to market?

public so it gets pushed all entirely, so the entire internet can scrape it and identify without the internet itself, but those actually doing that. But on the other side of it, it’s like, do they know what the sensitivity of the data is and what protections do you have in place? And it’s just like bringing it down to the core set of like, this is what’s important and what’s not, is the start of the conversation. And look, the reality here is like, it’s hard, right? Let me say this another way. It’s simple, but it’s not easy.

MANOJ (19:31.326)
Right here.

Ryan Leirvik (19:54.462)
And it’s simple, there’s enough guidance out there right now for any organization, like especially a new CXO type, to try to find out like, all right, what do we mean by impact? Like, well, how do we know it’s important? I mean, heck, you just saw the SEC come out with new laws, right, and the rules are, anything that’s gonna be a material impact within a certain amount of time needs to be reported and it better be on the quarter four filing.

or the next quarter filing, that’s a big deal. Now, industries are scrambling, we’re like, oh, what do we mean by impact? Well, there’s plenty of materials out there that can very quickly identify what we mean by material. And usually in some sort of set of categories that make sense to the business, so such as lost access, lost work, lost penalties, or fines and penalties.

legal activities. We always forget about how much lawyers are going to cost when we actually get into a big breach like the one you mentioned with the entertainment company, right? Lost business or impact or even IR. I mean, we forget, you know, on a huge breach with a lot of customer data, especially if you have PHI or a lot of PII from the healthcare standpoint. I mean, your incident recovery is going to be huge because legal activities and your incident recoveries are going to go sky high. And understanding within an order of magnitude.

MANOJ (20:53.354)
Yeah.

MANOJ (21:03.541)
Oh yeah.

Ryan Leirvik (21:14.538)
is the important part to say, all right, is it a million dollars or is it 10 million? Or is it 100 million? Like, where are we? And just understanding sort of that from a critical asset standpoint can help any new CXO sort of jump in like, okay, I now know what, if breached in some way, is gonna create the highest level of impact to the business, so why don’t we start there? And now all of a sudden you got a priority list. It was that easy. Yeah.

MANOJ (21:39.387)
That sounds amazingly simple, but what typically happens is that CXO is going to say, all right, CIO or CISO, this is what I pay you for. Come back and give me the program. Right?

Ryan Leirvik (21:54.602)
Mm-hmm. Yeah. And in the meantime, answer these questions for the board. Answer these questions for the team. Oh, by the way, hire new people or give me your budget. And so this is the problem where we’re pulled in so many different directions. But I’ll tell you, I was like, in my experience and what I’ve seen from a lot of individuals and clients, this is where the industry frameworks come in. I know we love to push and pull on them all the time. And it’s fun. And look, we hear about them all the time. And not one.

MANOJ (22:02.004)
Right.

Ryan Leirvik (22:23.982)
framework is perfect for any one organization. It’s just, they’re just not, right? But they can act as a really good guide to say categorically, these are the things I need to pay attention to. And now that I’m paying attention to those, now I can sort of build the bespoke and more customized pieces inside of those categories that fit the way my business operates in what I think is critical. And that’s where, you know, that’s where frameworks might come in, but those are not easy.

MANOJ (22:49.639)
Well, so are you partial to NIST? Are you partial to FAIR? Are you partial to ISO? Like, what’s your personal experience been in this area? Or what’s the difference between these frameworks?

Ryan Leirvik (23:02.162)
Okay, here’s where we get the Rotten Tomatoes score, right? Like how many of you are gonna throw tomatoes at the screen? All right, so here’s where I stand professionally. We do a lot of work in North America, right? Most specifically in America, right? So the NIST CSF is great at the first, first of all, it’s a great piece of work that sort of when released, you know, is very thoughtful about the future and not to be a, hey, here’s a regulated standard, right? It was…

MANOJ (23:06.416)
Yeah.

Ryan Leirvik (23:30.038)
the way NIST operates is very specific to like, hey, let’s think through where the problem’s gonna be and for whatever, 10 years maybe, and put out sort of guidance there. And then, that’s it, like let industry or everybody else adopt it. Now, if you’re in the US federal government, it’s a different story, right? That’s a regulated environment. Well, you can actually set the standards there, but in the private sector, right? In the commercial sector, even more specifically, like in the US, you don’t really have the regulatory bodies forcing a type of framework, right?

So I like the NSCSF from the first three levels, which is first, right now five, soon to be six, foundational categories, because they push what we should be thinking about. Identify what the issue is, identify what’s most critical, protect that, detect any weird things that might be happening on what your protections are. Oh, and by the way, when those break down, because they will, be able to respond and be able to recover.

It forces you into that categorical thinking. You’re like, okay, do I have things covered in that way? So I see it that way. Now it’s not as strong on the control side, where like an ISO 27001 might be, largely because that’s where the authors have mentioned, they don’t mean to go that deep because they’re not forcing individuals into those controls.

And I think from a North American or US standpoint, then this CSF is a great starting point to just get your brain wrapped around what the problem really looks like.

MANOJ (25:04.987)
So no, that’s great. Great answer. I mean, these are practical things because, oftentimes, and I’ll pick on FAIR for just a second. When you look at FAIR consulting, it’s not cheap. So if you’re GE, you probably have a group inside your company that can do this. But if you are, you know.

a small business with 200 employees, for you to afford that kind of an exercise may not, might have practical limitations to it. So the NIST, if you follow the guidelines and the framework, there’s a lot of things you could do in-house if you walk through it. Now you wrote, you actually wrote the book on this, you know, Understand, Manage and Measure Cyber Risk.

Ryan Leirvik (25:41.634)
Mm-hmm.

Ryan Leirvik (25:52.042)
Exactly.

Hahaha.

MANOJ (25:59.867)
Tell us a little bit about that. Does the book act as a guide on how to go through a proper assessment?

Ryan Leirvik (26:07.474)
It can, yes. More specifically, actually, the book is helpful for even the new CXO or board member or anybody. It’s just trying to understand why are we having this conversation about cyber, what’s important, and how do I actually measure it. Like sort of the three things that are sort of top of mind for everybody these days. And here’s why. You asked why I wrote it. The reality is, you know.

Manoj, we had conversations before and for the audience, Manoj and I talked about when you’re around long enough, you start to see this pattern start to unfold. And look, the one thing that I started to realize is like, because in the earlier, I’m just gonna say earlier, I’d say 10 years ago, it was really unclear what problem most were solving for. And granted, look, for those rolling out of the Department of Defense with offensive cyber, it’s pretty clear with the problem, it was us. Right?

MANOJ (26:57.807)
Yeah.

Ryan Leirvik (26:58.286)
So you flip that and you’re like, all right, well, how would I defend against that? So that’s one area. And what I was surprised at, but having conversations with a significant amount of those in the hot seat that had to actually do this, or even at the board level, who had to properly oversee this, there were these, the same conversation kept coming up, but like, of, okay, what do we do about this risk? It’s like, all right, we’ll define the risk. Like, all right, what do we do about, let’s say North Korea? Like, well, that’s not a risk, that’s a threat, right? The threat is them, right? And whatever piece of, you know.

but we won’t get into the details of how they actually organize. But like, okay, let’s say it’s them. What vulnerabilities do you have in your organization that they could take advantage of given these type of TTPs that would lead to something critical that would then have material impact on the business? So North Korea is not a risk. North Korea is a threat, right? Log 4J, we just went through it, right? Well, a little while ago, right? So what’s the risk of log 4J? Well, what’s the risk of what? That’s a vulnerability. Now it’s huge.

MANOJ (27:51.577)
Yeah.

Ryan Leirvik (27:58.014)
it is wildly difficult to do one, identify where it is in the supply chain and identify where it is in your environment, right? And try to figure out what to do. It’s a huge problem, but in and of itself, it’s not a risk until it’s applied to material impact of the business. And I started to realize like, this isn’t really well understood. So I’d kind of look around for, as I’m sort of helping organizations do this, looking for a guideline to say, I’m gonna always like, hey,

read this, this seems to do it. The CISO handbook’s really good, and one of them, but I couldn’t find something that’s really spelled it out. So if you’re a board member, you’re in a CXO shop, right? You’re a manager, or you’re just an individual trying to figure this out. There wasn’t something out there that said, here’s what the problem is, here’s a handful of ways to solve it, right? And here’s ways you know if you’re solving it well. So I literally wrote this down, and was having conversations with us, and figured, all right, well, might as well just publish it. And so…

just put it out there as a book. And so it’s a guide to help answer any part of that problem that you’re trying to solve for in a practical way.

MANOJ (29:06.387)
You should have tried to get it under the Four Dummies title because, you know, not saying that doesn’t imply anything about you, but it’s such a foundational topic. And those books have been so good at addressing foundational things that if you’re going to. Yeah.

Ryan Leirvik (29:22.666)
You know, it’s really, that’s a really valid point in sort of the, so a new version just came out a handful of days ago, actually. And so the feedback I’ve gotten is, wow, there’s a lot of humor in here. And so there is a little bit of like, hey, I try to make it so simple that it’s actually funny that we’re having the conversation. And I love that idea, because maybe we could write a book on like cybersecurity for, I think one exists, you know, forgive me for not knowing that.

But yeah, that’s the essence. If you can… Yeah.

MANOJ (29:53.639)
There’s a lot of technical rendition to it. It’s not about a… What you’re talking about is a practical use guide. And that is something that’s actionable. And we get this in our world with threat intelligence. Are you subscribed to a threat intelligence platform? What does that do if it’s not actionable?

Ryan Leirvik (30:02.636)
Yes.

Ryan Leirvik (30:14.158)
100%, yeah, I’ll tell you, in briefing a lot of boards, what I find is really interesting, and forgive me for those that find this wildly valuable, but when you start with the threat, because here’s what we’re seeing from the threat intelligence and we’re having this conversation, it’s like, okay, why are we giving them the advantage? Right, why don’t we flip that and say, hey, here’s what’s important to us, here’s what’s gonna, from a material impact standpoint, here’s what’s gonna hurt our business.

by the way, here are the vulnerabilities associated with it and here are the threats that are looking for those vulnerabilities that are associated and now you’ve got contacts for the threat. Because if we start there, we’re just, you know, great, it’s fun, I love it. Like threat intelligence is amazing and it’s a lot of fun to see what people are up to and what they’re doing, you know, and the TTPs they’re using and what tactics, you know, wow, I never really would have bounced from here to there, you know, to do that or I didn’t know that exploit existed, like, and they’re exploiting it, right? Or this, you know, you could build a proof of concept that quickly, but it’s really fascinating. But the problem is, as you say,

it’s not actionable right away, right? And so you gotta bring it back to like, why is the business and business in the first place, right? What if that vulnerability and that threat came together to impact some sort of part of the business, why would this actually matter? Okay, great, and now when you’re in that practical space, what’s really interesting, and this is Minoj where I’ve seen the flip happen, now when those conversations about newsworthy pieces show up,

now you have context for it. Like, oh yeah, that’s really interesting. Well, this is what happened to a peer, right? Or a competitor in this space and da-da-da. But we’re not running on those systems. We don’t have those vulnerabilities. So fortunately for that particular threat, it’s a low priority for us because we don’t see it impacting us.

MANOJ (31:58.823)
that should be part of your baselining before you start any kind of a program. In fact, what you’re describing, if I was to paraphrase this another way for the audience, would it be good to go to MITRE? First, go to and understand in your industry what kinds of breaches have taken place. Go to the MITRE ATT&CK framework, look at what TTPs are being used to execute that.

then look at who the major players are that are actually using those TTPs. So now you know who’s actually likely, because risk is likely. It’s the probability and magnitude of loss. So if you know who’s likely to come after you, now you go look for those vulnerabilities and see, can you eliminate the likely? So you make it hard enough where people are like, you know what, there’s other fish to go fry right now. We’ll come back to these guys later. That…

Ryan Leirvik (32:32.137)
Mm-hmm.

Ryan Leirvik (32:56.85)
And that’s the essence of cybersecurity at large right there. It’s can we spend just enough to make, to just spend, you know, spend enough resources and time, right? Just enough resources. So time, energy, people, right? Money. Just enough so that the attacker goes away. Right? Slightly more than what the attacker is willing to put in if we could do this, right? And then, you know, at that point, you’re doing okay. Yeah.

MANOJ (33:20.811)
Yeah, at that point you want to live another day. And the story keeps changing, but foundationally that’s not a bad approach because we can’t guard against 100% of everything. It’s just not, and you reach a point of diminishing returns as well at some point where it’s like, well, like you said, this isn’t even a vulnerability here. Why are we putting in compensating controls for it? So.

Ryan Leirvik (33:25.166)
That’s right.

Ryan Leirvik (33:44.39)
Mm-hmm. Yeah.

Ryan Leirvik (33:49.134)
That’s right, yeah. In Minoji, we see a lot of this with measures, right? Measures have been an issue for a while. Like, do we have the right measures? And we see operational measures, you know, that aren’t actionable or informative, which just sort of, you know, aren’t really helpful to have a conversation with, but they’re certainly fun, right? To ones that are actionable and are informative. But here’s the interesting, here’s the unintended issue with spending a lot of time on getting the perfect, you know, measure down with the right amount.

Chances are pretty good, like you say, when that risk is actually realized, it’s not gonna be anywhere, it’s not gonna hit that exact number you’re hitting with your risk assessment. It’s just not. Because there are gonna be things that you don’t know have dependencies on whatever the actual breach or incident was that’s gonna either drive up or drive down costs that you either did or did not assume. So the trick with measures is put in just enough time

You should invest just enough time in identifying the right measures that give you the right indicators of risk holistically for the environment that then allow you to spend more time mitigating those risks. If we spend too much time figuring out to the perfect point of how much… Yeah, it won’t even be true when the risk actually is realized in the first place. It’s like…

MANOJ (35:09.112)
We’ll never have it.

Ryan Leirvik (35:14.546)
It’s a fun exercise. Don’t get me wrong. Insurance companies love it and it’s actually a ton of fun for quants, but in the reality of cyberspace, maybe those resources could be applied mitigating it versus… And then once you strike a balance of like, we’ve got all these people mitigating the issue, so let’s really get down to like what the perfect answer is. Okay, great. That’s a resource allocation decision.

MANOJ (35:36.091)
So, you know, you, your organization, and you have been involved with threat teaming and threat hunting and doing that at a world-class level. So I want to take a little bit of a different tact here and ask you the question of what about leveraging vulnerabilities for offensive purposes? So let me give you an example. So if we…

If we know that in whatever industry we’re in, this is a traditional approach, threat vector, and it gets exploited, and there’s a vulnerability that comes up over. Why not leverage that vulnerability to give the bad guys a whole bunch of shitty information? You know, and screw with them a little bit, you know? So now, yeah, you did steal data, didn’t you? And you’re gonna sell it? Please sell it, because the people buying it are gonna be kind of.

Ryan Leirvik (36:21.877)
Yeah.

Ryan Leirvik (36:26.858)
Yeah, yeah. Yeah.

MANOJ (36:32.299)
because they got a whole bunch of crap from you, right? So turning the tables into, we could open the whole conversation on offensive capabilities here then in a way. Is there, does anybody do that? Have you seen?

Ryan Leirvik (36:34.927)
Mm-hmm. Yeah.

Ryan Leirvik (36:43.18)
Mm-hmm.

Ryan Leirvik (36:49.727)
Well, let’s say it this way. I’m going to break it down this way first, not a lawyer. But number one, the idea of sort of hacking back and taking the offense from the US commercial point of view is not legal. So let’s just start with that. As much as we would love to do it inside of the US, let’s say the boundaries of the US and the laws, it’s not necessarily legal. So that’s, yeah.

MANOJ (36:55.004)
Yeah

MANOJ (37:13.703)
Absolutely, but here I’m intentionally putting out bad stuff.

Ryan Leirvik (37:18.162)
Exactly, so now we’re in the world of like, you know, we’re like sort of honeypots and honeypits and tarpits and things like, well, tarpits just slow them down. But that was, so like the idea of, you know, putting information out there at false flags, if you will, right, so that those bite on it and take it is a wonderful idea. The challenge we’ve run into these days is that you’ve got to keep it so real and so active because the sophistication level of the threats has increased to the point where

they can identify are these people who are accessing these documents real people in the organization? Are these documents or this data, or I’m just gonna assume data, right? It’s kind of a narrow scope, you get the idea, right? It’s sort of like are they real individuals? Is this real data? And especially given sort of the ML pieces that have been thrown out lately, you can tell pretty quickly whether it exists somewhere else in the organization or it doesn’t. So that would be a great discussion.

with a real expert in that area because to see from a defensive standpoint how the false flag obfuscated data world is playing itself out is a lot of fun. Because from the red teaming side, yeah, because from the red teaming side, when we see it, we’re like, oh yeah, like this is like three IT people that are in the security space like managing these documents every few months, making them look like they’re real. Okay, we’re just going to blow right past that. Right. But the way to actually make it look real over time, you know.

MANOJ (38:28.125)
Oh yeah.

Ryan Leirvik (38:44.278)
That could be an interesting ML play, right? Where you actually point the machines to learn how what good looks like and then flip it from there. And I think we just came up with a business idea if somebody isn’t already doing it. I’m not sure they are.

MANOJ (38:54.903)
Well, yeah, I mean, look, in the day of chat, chat GPT, man, I can use natural language processing, say, here, this is good. Now you scramble this and turn this into bad. And you can start, we can create thousands of fake identities that look totally legit and start.

Ryan Leirvik (38:59.766)
Hehehe

Ryan Leirvik (39:12.822)
Yeah, I know that’s not a bad idea, right? I’m certain like right now it’s coming to us and maybe somebody else had thought about this, but yeah, the generative side of just like generating real documents that, right. Yeah, as long as you can obfuscate the metadata or actually assign a real user to it, right? So it actually looks legit, you know, and tag it to all the pieces that you’ll need to tag it to from an active, depending if you’re an active directory shop or not. But, you know, make it look as real as possible. Yeah, you know, then you get into the, you know,

MANOJ (39:22.647)
Real not.

Ryan Leirvik (39:43.584)
You know security through obscurity right there’s so much stuff out there that they got to figure out what’s real what’s not

MANOJ (39:49.043)
Yeah, well, and you know, again, if your objective is that they’re like, you know what? Let’s just go over to these guys over here because it’s just easier. Which is what you want them to do, because they’re a business too, right? I mean, they want a ransom to where somebody that’s going to pay them money for the data, if you stole a bunch of dog poop, no one’s going to pay you for it. So.

Ryan Leirvik (40:01.186)
Which is what you want them to do, right? You want to be like, oh, throw their hands, I’m like, you know what, forget it. That’s right.

Ryan Leirvik (40:12.822)
No, yeah, unless somebody really needs that dog poop. You know, like there’s some fertilizers, some organizations out there going, no, don’t mess with the dog poop because like I need that fertilizer. Like that’s certain ingredients in it. Right?

MANOJ (40:16.75)
Hahaha!

Yeah!

MANOJ (40:28.361)
Hey, listen, Ryan, we’ve got the two minute mark here. I want to give you some time to talk about anything, you know, plug anything you’d like to, whatever. You got so much stuff going on, but the floor is yours. Let people know whatever is coming up in your world and what you’d like to share.

Ryan Leirvik (40:31.308)
Okay.

Ryan Leirvik (40:35.712)
Oh boy.

Ryan Leirvik (40:41.25)
Oh, wow. Yeah, happy to. So, you know, at Nuvik, we’re doing, you know, security assessments and training. So feel free to reach out if there’s anything we can do. It’s, you know, any UVIK, pretty easy to find. But the more important piece here as well is sort of, you know, there’s a book out there now called Understand, Manage, and Measure Cybersecurity. So like, if you’re worried about any piece of this, you know, of like, hey, how do I actually get my brain around open source material that’s out there, right? There’s nothing really proprietary in it.

other than the publisher will say it and the way it was put together. But there’s a book out there to understand, manage and measure cybersecurity. Give it a look, use it as a reference guide and that’s probably the best plug I could give right now.

MANOJ (41:24.155)
Is there any way they can get a signed copy?

Ryan Leirvik (41:27.274)
Yeah, that’s great. So we’ll be in, you know, we call it Week in Vegas now because we’re out there for a whole week for sort of, well, Black Hat, Def Con, B-Sides, and the Diana Initiative. So it is actually a Monday through the following Sunday, Week in Vegas, which is a long time to be out there, but we’ll be out there. So hit us up, nuvic.com. I’m on LinkedIn, Ryan Liervick. You know, feel free to hit me up. Yeah, and then I can give you a signed copy. I’ll have plenty of them out there.

MANOJ (41:33.199)
Black hat?

MANOJ (41:44.132)
Wow.

MANOJ (41:57.039)
That’s fantastic. Well, Ryan, it’s been a pleasure having you here. Hope to have you back sometime and continue the conversation. We’ve barely scratched the surface of this thing. I really wanna get into the offensive side of this and I don’t wanna put all the ideas out there, but would really, I think it’d be a lot of fun. That’s the fun part of cyber.

Ryan Leirvik (42:20.522)
That would be great. Yeah, happy to. So thanks so much for having me. Like happy to come back and have a deep discussion on that. That’d be great. But Minosha was great. I really, really appreciate the time. Thanks for having me.

MANOJ (42:31.311)
Thank you for being here.

Ryans’ Linkedin

Learn about Neuvik

Link to Ryan’s Book “Understand, Manage, and Measure Cyber Risk”

Check out the other episodes in Season 12:

Ep. 0 Dark Rhino Security – The IT Security Money Pit

Ep. 1 Marius Poskus – Tech talk overwhelms the nontechnical

Ep. 2 Robert Black – Who is responsible for Cybersecurity?

Ep. 3 Eric Allard – Your Guide to SBOMs

Ep. 4 Ryan Leirvik – Understand, Measure, and Manage Cyber Risk

Ep. 5 Dan Wachtler – Building Awareness About Your Startup

Ep. 6 Peter Warmka – A Seniors Survival Guide

Ep. 7 Susan Bennett – More than the Voice of SIRI

Ep. 8 Frank Riccardi – The Human Factor is the Weakest Link

Ep. 9 Dmytro Bielievtsov – What is Vishing?

Ep. 10 Chris and Rory – Bourbon Breakdown

Ryan Leirvik is a cybersecurity professional who has spent the better part of two decades enhancing information security programs at the world’s largest institutions.

With considerable US government and commercial sector experience, Ryan has employed his professional passion for cybersecurity at almost every level within an organization. A frequent speaker on the topic of information security, Ryan fields several questions on “How do I make sure I have a sustainable cyber program?” This book was written to help answer that question.

Ryan has been the CEO of a cybersecurity research and development company, Chief of Staff and Associate Director of Cyber for the US Department of Defense, and a cybersecurity strategy consultant with McKinsey & Company. Ryan’s technology career started at IBM, and he has a master of IT degree from Virginia Tech, an MBA from Case Western Reserve University, as well as a bachelor of science from Purdue University. Ryan is also on the faculty at IANS.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

1 thought on “Security Confidential S12 E4 Ryan Leirvik”

  1. Pingback: Security Confidential S12 E6 Peter Warmka – Dark Rhino Security

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top