Security Confidential S14 E0 Cyber Basics: Network Security

This week on Dark Rhiino Security’s Security Confidential podcast, Tyler Smith breaks down what Network Security is and answers basic questions. We have all the answers on this week’s episode of Security Confidential. 

Transcript

Tyler Smith: Welcome to Security Confidential by Dark Rhino Security, where we get together and talk about all things information security. I’m Tyler Smith, an information security practitioner at Dark Rhino Security.

Nathan: Hi, my name is Nathan. I am a security engineer with Dark Rhino Security.

Tyler Smith: Today we’re going to talk about cybersecurity basics.

So, let’s talk about network security for a minute. Network security is something that I’ve had a lot of experience with just because it is a large part of any enterprise security. I would say it is my swim lane.

Nathan: It’s mine. [Laughter]

Tyler Smith: But yeah, there’s a lot of security work to be done on the infrastructure side, and I think one of the key elements is network security. There are so many different things that bolt on to that: there are security proxies, load balancers, and application firewalls. I mean, it’s just huge. But with network security, again, security needs to enable the business side of things. With any security undertaking—any IT undertaking for that matter—if you don’t start with what the business needs first, you run the risk of moving in the wrong direction entirely.

Nathan: It’s very easy to let an IT crew saturate your budget.

“You need this.” “Why is that?” “Because of all the bad guys.”

Tyler Smith: “Yeah”

Nathan: “Okay. Well, we were going to get accounting software, but I guess that appliance is more important.” “Yes, it is.”

“We need more bandwidth.” “Why?” “Because…” “Okay.”

“All right.”

“If you say so.”

“Okay.”

Tyler Smith: But the network security issue is one that is central to all of IT and security.

Nathan: Well, it’s because it’s central to everything.

Tyler Smith: It’s the roads upon which all your data travel. Network security is something that a lot of companies haven’t looked at in a long time.

Nathan: People set it up, you forget it, and there it sits.

Tyler Smith: And then the guy who set it up leaves the company.

Nathan: Well, unfortunately, it’s true. Some of those old switches were set up 10 or 15 years ago. Some of that equipment will run forever. I know of a 20-some-year-old VPN concentrator. I know of it; I can’t say who owns it, but it’s out there and the only way to repair it is with parts from eBay, but they run forever. That’s where everything needs to go when we jump outside of training and outside of patch management. Your network and your network security are important.

There are lots of tools—tons and tons of resources out there that’ll help you get started on that. Oftentimes now, with the newer next-generation firewalls, those can even pick up the load when it comes to segmenting your network properly. So your infrastructure teams don’t have to worry about that. Hear that, switching guys? You don’t have to worry about it. You can hand it off to your firewall teams, and they can oftentimes do it.

Tyler Smith: And yeah, I mean, it’s legit.

Nathan: So, ideally, your Layer 143 switching guys do what they need to do. Your routing guys have set it up and they’ve gone away. Routers—I wouldn’t touch routers as they are. If they’re working, you really do need to just leave those.

Tyler Smith: Yeah. But even routers—most of the next-gen solutions out there have the capability to run as your router.

Nathan: Yeah. So, I’ve experienced a couple of scenarios where equipment has just been installed and set to pass traffic.

And some of these were medical companies. If HIPAA decided to walk into some of these companies, they wouldn’t have been companies much longer. I’ve seen that a few times where you get there and, literally, all it’s doing is just passing traffic.

Tyler Smith: You could take it out of line and you would notice no appreciable difference.

Nathan: Honestly, find a vendor you can trust and be honest about your expectations and your own personal capabilities. If you tell your vendor that you can go in and make those changes after they leave, that’s going to be the project expectation. There’s nothing wrong with admitting that you need help.

Tyler Smith: And again, if you’re working with someone and they don’t ask you about it, make a point to ask them about it and say,

“How can we collect information on the business process that this is supporting? So that when you guys do what you’re coming here to do, every effort you make works towards that, instead of shutting down an entire factory line for a week.”

Sunaina: Well, thank you for coming today.

Tyler Smith: Absolutely.

Sunaina: Yeah. And thank you guys for listening. We will include some resources in the show notes, so check those out. Also, please subscribe to our podcast and we will see you guys next time.

Tyler Smith: Bye, everyone.

Check out the other episodes in Season 14:

Ep. 0 Dark Rhino Security – Cyber Basics: Network Security

Ep. 1 Adam Levin – Lie like a Superhero

Ep. 2 Christian Espinosa – The Correlation of Extreme Sports and Cyber Security

Ep. 3 Scott Augenbaum – The Four Truths About Cybersecurity

Ep. 4 Dorota Wrobel – Level up your online safety

Ep. 5 Tom Eston – Debunking Misconceptions in Cybersecurity

Ep. 6 Richard Hollis – Either it works or it doesn’t

Ep. 7 Troy Hunt – Cracking the code: Password Manager Insights

Ep. 8 Daryl Donley – Throwing more technology at a problem doesn’t solve it

Ep. 9 Max Hillebrand – Insights into the Cryptocurrency Fueling Cybercrime (Part 1)

Ep. 10 Brian Vallelunga – Unf*ck your secrets

Tyler Smith Promo image for Dark Rhiino Security's Security Confidential podcast

Tyler Smith, co-founder, CTO, and President of Dark Rhiino Security Inc., a leader in the computer security industry. Tyler shares insights from his journey building three successful companies, including valuable lessons from his experience leading Dark Rhiino.

He is a veteran of the US Marine Corps, where he served as an Infantry Rifleman and deployed to multiple countries in support of the Global War on Terror. He studied Political Science and International Studies, Security and Intelligence at The Ohio State University. He has worked in security and technology since 2011 and has worked in technical roles for Apple Inc., Ohio Health, Reid Elsevier Technology Services/Lexis Nexis, Toyota, Federated Investors, Honda of America Mfg, to name a few.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

 

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top