This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Bob Carver CISM, CISSP, M.S. Bob began his security career working in the financial industry. Later, Bob became the first full-time security employee hired to start the dedicated security monitoring and incident response team for Verizon Wireless. He has been involved in cyber risk management, policy, threat intelligence, and analytics. He was recognized by LinkedIn as one of the Top 5 Influencers in the World to follow in Cybersecurity. Most recently, he was on the expert panel for CES (Consumer Electronics Show) in Las Vegas discussing “Focusing on Security in Product Innovation”. Bob joins host Manoj Tandon on this weeks episode of Dark Rhino Security’s Security Confidential
Chapter Titles:
00:00 Introduction
00:18 Our Guest
01:47 Bobs Beginning
05:02 How did Bob land his position at Verizon?
08:00 Budget issues
11:02 Why are companies so ineffective with Cybersecurity?
13:38 Cyber professionals not addressing business security implications
18:40 Malvertising
21:31 Not downloading everything off the internet
26:15 Curing your problems with a tool
28:26 Budgeting: Where should you prioritize?
32:22 ChatGPT
33:47 Cyber Insurance
37:29 Multifactor Authentication
43:06 File Storing System
45:48 Modern-day Bonnie and Clyde
47:43 Connecting with Bob
Audio:
Important Links:
Transcript
Manoj Tandon: Welcome to another episode of Dark Rhino Security Confidential. This is Manoj Tandon, your host. Today we are honored to have Bob Carver join us, and he is of no relation to the speaker guy. I wish he was, but…
Bob Carver: Me too.
Manoj Tandon: But he’s awesome. You know, he actually started his career off in the financial sector and then got into cybersecurity. We’re going to talk a little bit about that here in the future, but he has worked for—I think he was one of the first employees at Verizon in their incident response business.
Bob Carver: In the wireless.
Manoj Tandon: Wireless, yeah. Right. So we’ll get that background. And you, Bob, were also voted by LinkedIn as one of the top five influencers in the world to follow for cybersecurity. What an honor there. And you were recently at CES on a panel discussing cybersecurity in product development. So thank you for being here. Welcome to the show.
Bob Carver: Well, thank you for having me here, Manoj. I appreciate it.
Manoj Tandon: You know, we’re grateful for many of the insights that you’re going to bring to us. You know our audience is pretty eclectic and they love these topics. And they—you know, our mission is to educate them, and hopefully, knowing what you do, you’re going to be able to give a couple of nuggets on some practical things that some of them might be able to implement in their businesses and their daily lives as cybersecurity professionals.
But we’ve got to start with: How did you get into this? You were in finance.
Bob Carver: Yeah, I was an IT guy that was working in the financial industry, and then I volunteered for all the security projects at the financial institution, Fidelity Investments. You’ve probably heard of that.
Manoj Tandon: I’ve heard of them. They don’t like your job. You wanted to take more punishment, was that the—?
Bob Carver: Well, I thought it was… You know, I sort of… I think I knew instinctively that security was going to be an up-and-coming thing. So I did; I volunteered for a lot of projects. Like, my first project was building a Key Management Center that basically keeps track of security keys for encrypted systems. And we had these financial institutions that transfer millions of dollars back and forth, and you’d have private circuits and you wanted them encrypted and that sort of thing. So I built an encryption system called a Key Management System out of embedded Unix back in 1999 so it would be Y2K compliant.
Manoj Tandon: That’s fantastic. And Unix. So what was the platform at that time? Was that—?
Bob Carver: Yeah, it was in embedded Unix. I actually called it QNX, I think. And what was wild is that only ran on five-and-a-quarter-inch floppies. And I had to source a five-and-a-quarter floppy drive because they weren’t using them anymore. They still had the disk at three—you know, I think it’s three-and-a-half. Anyway, the normal size disc, the smaller diskette, but the floppies? They just didn’t have them. So I had to find somebody that was selling some old new-old-stock on five-and-a-quarter.
Manoj Tandon: You know, I still might have some new-old-stock lying around. I kept it around for nostalgia. Just so that people walk into my office and say, “What’s that for?”
Bob Carver: Yeah.
Manoj Tandon: That’s good. That’s nice. That’s a talking point. But Key Management is huge. I mean, even today that’s a very relevant topic.
Bob Carver: Sure. And there’s a bit of a science to it and a process to it. It’s not something you just do haphazardly. I think back then AES-256 was considered DOD-type encryption. So, although AES-256 is getting less and less as the “top banana,” they’re getting bigger and better. Look, as our compute power goes up and you know, that world is going to continue to evolve and change. When we look at quantum computing, what’s going to happen with that? It’s anyone’s guess. I mean, there are a lot of theories out there, but chances are years from now maybe AES can be cracked in microseconds.
Manoj Tandon: You know.
Bob Carver: Oh yeah, unfortunately.
Manoj Tandon: Right. And that throws a real damper on the entire internet. But we’ll get to that in a second. I wanted to get to: How did you start on the Verizon team then? Two questions there, actually.
Bob Carver: Go ahead, go ahead. Two questions there. So, first of all, we think of Verizon—I know everybody knows of Verizon Security now, but typically if you ask the layperson about Verizon, they’re thinking about that guy that walks around saying, “Hey, can you hear me now? Can you hear me now?” So explain a little bit about how a company like that even gets into the security business, and then how the heck did you become the first guy in this thing?
Bob Carver: Yeah. You know, they did have some full-time people on the Verizon wireline—the older wired lines. But wireless? They were part-time people and contractors. Okay. And what happened… I’d say I owe my job at Verizon Wireless to Paris Hilton. I don’t actually remember…
Manoj Tandon: Who doesn’t know Paris Hilton?
Bob Carver: Paris Hilton. Anyway, if I ever see her I have to thank her, but I haven’t seen her recently.
Manoj Tandon: Oh well, one of these days. Hey, maybe you’re in better social circles than I am, because I can’t get into those parties.
Bob Carver: No, I haven’t been to any of her parties either. But what happened: She was… I think the device was called a Sidekick back then, and anyway, her account got hacked at T-Mobile. And the Verizon Wireless folks, which was a totally separate entity back then from Verizon, they said, “Oh, I think we better start hiring some full-time guys.” So anyway, as a result, I went to an interview—long, long interview process back and forth and back and forth with multiple candidates—and they ended up hiring me as employee number one for Verizon Wireless back in 2005.
Manoj Tandon: You don’t… What? I bet you Paris Hilton doesn’t listen to this podcast, but also she probably has no clue that she inadvertently kicked off one of the largest security arms in the world.
Bob Carver: There you go. You’re probably right on that.
Manoj Tandon: Right. And from this bad story that you’re telling… So, that’s just amazing how she has that much power even when she’s not…
Bob Carver: Sure.
Manoj Tandon: Directly—she didn’t have social media back then, she just had the normal press.
Bob Carver: Yeah, she had the normal press.
Manoj Tandon: So when Verizon got into this, was it just about incident response or were they actually going to get into full SOC operations and things?
Bob Carver: Oh, well, eventually we did get into full SOC operations. It started out just with me for quite some time, dealing with millions and millions of events. And then finally I said, “Well, when am I going to hire somebody?” And they finally let me hire one guy, and then over time we were hiring more and now, you know, we have dozens of people working 24/7.
Manoj Tandon: I guess there’s a question in there that… I can’t think of anybody who listens to this who hasn’t faced a budget problem. So just looking at the Verizon example you gave, it sounds like… What caused the executive team to actually give you a budget to say, “All right Bob, maybe we’ll let you have a guy and a slice of pizza too”?
Bob Carver: Oh yeah. Well, I mean, one of the big expenses we started out with, besides personnel, was being able to… Because there are so many security events when you’re talking about a nationwide wireless network. You know, we had well over 100 million customers.
Manoj Tandon: That’s incredible.
Bob Carver: Even at the beginning, you have tens of millions of security events. And how do you make sense of those? You know, I tried to… As a matter of fact, I was hired before a director and the CISO and all those people. I was “the guy.” But I was dealing with people at the beginning that didn’t have a full understanding of what was going on. I said, “You’re going to have to have something to make sense of all these events.” I showed them—I showed the events zooming by. It’s like… “Can you make sense of any of those? Can you write a report on anything that’s going on there?”
And they said, “No.” Anyway, I couldn’t get them to come up with a decent answer. I said, “You’re going to have to come up with a security event management system to be able to slice and dice those events so you can see them better. And if you want to do some reporting down the road, you’re going to have to have something like that.” So, I got a budget for that and of course you gradually grew that. That was before things had gone into virtual machines on a regular basis, or the cloud. And so we built that system from one or two servers up to like 20 or 25 servers. So it was a pretty large, sizable infrastructure back then.
Manoj Tandon: That would have been expensive back then.
Bob Carver: Oh yeah, and very expensive. And of course, it takes people to manage that infrastructure. You can’t just do that in a few seconds a day.
Manoj Tandon: No, you can’t. You need a team of people, right. And that equipment back then was very expensive. Storage was expensive. Memory was expensive. I mean, 25 servers—that was probably a healthy seven-figure investment into that.
Bob Carver: Yeah. Oh, it was a lot. It was a lot. But anyway, we were able to start getting some reporting and able to see events more strategically, to be able to see when things were going wrong. So it helped a lot.
Manoj Tandon: So, you have seen and built cybersecurity programs at some very large organizations from their infancy. So I have to ask you the question: Why are companies, given the large number of breaches that happen today, why are they so ineffective with cybersecurity? What gives? What’s going on?
Bob Carver: A lot of times I don’t think they understand the amount of risk until it happens to them or somebody very close to them. You know, if all of a sudden one of your key competitors goes out of business, it’s like, “Oh, maybe this is something I need to look at and figure out.”
Manoj Tandon: So why is that? Is that “out of sight, out of mind”? They genuinely don’t care?
Bob Carver: Well, I think there’s still—especially the smaller the organization is—a mindset that the number one most important thing is to remain profitable, so there’s cash flow so you can pay your employees and so you can pay yourself.
And they just sort of… I think it’s more of a “head in the sand” or you’re playing Russian Roulette.
They just don’t think…
“Well, there’s only one bullet in that revolver.”
Manoj Tandon: Yeah.
Bob Carver: “It’s not going to happen to me.” I mean, I had… At one time, my parents were sort of that way, too. And they didn’t run a business or anything, but I said, “You’re going to have to do some things to protect yourself.” And then my parents were involved in a situation where all their information was exposed in a major breach. And they said, “Oh, we’re good Christians, nothing bad’s happened to us.” And then, like I said, all their stuff was exposed and then all of a sudden they called me in a panic like, “What do I do? What do I do?”
Manoj Tandon: Yeah. You know, it’s unfortunate. What you’re describing… We primarily at Dark Rhino serve small-medium businesses, and we usually don’t get a call from someone until the horse leaves the barn. And now it becomes a lightning priority.
Bob Carver: Right. Yes.
Manoj Tandon: And then there’s a little bit of a sticker shock as to what cybersecurity is like if you’re really going to do it. And we’ll talk about… I want to get into more detail on that. But is there also, do you think, how much of that—and I’ll just put it in air quotes—”ineffectivity” of cybersecurity is due to cybersecurity professionals not being able to articulate to the business owners what the real business implications are? Is there a failure on that side that’s not able to daylight the magnitude of the problem? I know I’ve been there before many times.
Bob Carver: I think until it gets really close up in people’s faces, sometimes they just don’t want to deal with it. A lot of times because they’re dealing with all the things… I mean, just think of the things we have to deal with on a regular basis. I mean, inflation alone, the cost of borrowing money. Look at the price of bread, eggs, and cars right now.
Manoj Tandon: Oh, it’s ridiculous, just gone through the roof.
Bob Carver: So I think people just have a limit on how much they can process and deal with. So I think that’s a lot of it.
Again, until it’s close and up in their face, it’s difficult for people to deal with. And I think it’s again more of a “head in the sand” mentality. But they’re just overwhelmed with the amount of risk out there and what they’re dealing with. It’s difficult. It’s not easy.
Manoj Tandon: Oh, it’s absolutely not easy. I’ll give you that.
It is difficult, and for people whose core businesses are not in the cybersecurity business, for them to even put the right level of resources or get the right advice is a very difficult task if they were genuinely interested in it to begin with. So we can absolutely appreciate it, but it’s unfortunately not going towards solving the problem.
Bob Carver: Yeah, understood. One of the things I know that helps me is that I have seen so many things over the last 23, almost 24 years now, that I know what can go wrong and what can go bad. And there are times where I had better security in the early days than some corporations. So, you know, I probably have better security than most small-to-medium-sized businesses.
Manoj Tandon: I can absolutely believe that. And I don’t think I have everything covered. I’m sure I don’t have things covered that I might should, but I’m better than the average bear, probably.
Manoj Tandon: Well, Bob, there’s no such thing as 100% cybersecurity. I don’t think you can get there.
There will always be an attack surface. There will always be vulnerabilities. I don’t care what you throw at it. Sure, it’s just never going to be zero. The question is: Can you get it down to a place where you know what likely losses may occur, and that becomes acceptable to you? If you can do that, then you have better cybersecurity than anybody else at that point.
Bob Carver: Sure. Yeah, one of the things… I sort of look at it this way: You’re trying to block all the bad things out there. And of course, like security fences… Think about it.
A lot of times there are these big chain-link fences and they have the razor wire on the top and that sort of thing. But you still have little holes in those fences. And then you have to sort of gradually… I mean, that cuts out some of the big things, but then you have smaller and smaller things that get through the hole. Then what? Then you have to layer your security. Then you have chicken fencing, then you might have some sort of screen—the screens in your windows—to filter out even more things. But then what happens if what you’re dealing with is a threat that’s not even physical, that you can’t see and feel? What if they all of a sudden use carbon monoxide or something like that? Carbon monoxide is a gas, and it just goes right through all those screens and it can’t be stopped. So I think people have to think that there are other things besides what they might know that could be a threat. Unknown unknowns.
Manoj Tandon: Yes. Right. And what you just described is defense-in-depth, Bob.
Bob Carver: Yes, absolutely.
Manoj Tandon: And even that has limitations to it.
Bob Carver: Sure.
Manoj Tandon: Right. And the carbon monoxide analogy… Look at SolarWinds. I would put that right in that category. I mean, that was carbon monoxide poisoning. They would have never detected it. Brilliantly engineered.
Bob Carver: Oh yeah. And unfortunately, I think we’re seeing more things like that. One of the concerns—and this has sort of come and gone a few times—is malvertising, where advertising is carrying malicious payloads.
Manoj Tandon: Please describe that in more detail. That’s fascinating.
Bob Carver: Sure. Well, one of the things, if you’ve looked into online advertising, Google’s one of the big ones, and then of course Facebook. And then you have overseas—you have the Baidus and the Yandexes and on and on. But people can buy advertising and almost pinpoint exactly who they want to target, which is really sort of scary. You can probably pinpoint it down to an IP or even a company, a specific ad. Anyway, there’s a big science behind this, but the thing is, from what I’ve heard, I think that the NSA and the CIA actually block advertising from their networks. If you can block most of the advertising from your networks, then you lower your risk of having that type of situation where malware’s dropped on your system.
Manoj Tandon: That’s very good advice. Now, the question is: Are there effective techniques by which you can block that?
Bob Carver: Yeah, there are multiple layers. On a simple, easy, cheap way that individuals and small businesses can do it: They can install some plugins. There are several. There are a lot of plugins that you can do that block advertising. I could probably find some for you if you need the names, but there are a lot of them out there. Some are better than others, no doubt, just like anything else. But a lot of them are free. There’s a few that are paid, but a lot of them are free, and they block a large portion of advertising. But you can also block advertising in DNS.
You can block advertising with some layer 7 firewalls. But for simple consumers and small businesses, get some good security plugins in your browsers and keep them on most of the time, unless there’s a site that says you must remove your ad blocker to see the site. Then you can temporarily turn it off, and then when you’re off that site, you turn it back on again and you keep on going.
Manoj Tandon: That’s really good advice. And there are more and more sites that are relying on those advertising dollars.
Bob Carver: Sure. Again, there’s probably, like with anything else, a balance to be achieved.
Manoj Tandon: Oh yeah, exactly. You’ve seen so many exploits. Is there anything that is memorable, that’s like your favorite that you could tell us a story about? And protect the innocent.
Bob Carver: Yeah, yeah. I think one of the things that comes to mind—and I was actually one of the key people to help push this into place—was not being able to download whatever app you want off of the internet. There are a lot of apps that are open source and free on the internet, but the problem is that a lot of the cyber-criminals and other negative entities take that and modify the code and put malware in it. For example, one that’s used for admins to take care of servers and that sort of thing is an app called Putty. Yeah, P-U-T-T-Y. You’ve probably heard of that.
Manoj Tandon: Very, very familiar with it.
Bob Carver: Yeah, there are a lot of versions of Putty out there that are malicious on the internet. And if you don’t know where you’re getting it from, you may be downloading some malware. But there are others: FileZilla—I mean, I can…
Manoj Tandon: Yeah, it’s out there too.
Bob Carver: Yeah. A lot of the apps that sysadmins used. And so I started seeing people download… I would a lot of times grab the same thing and start analyzing it myself, and I’d say, “Oh, this is not the good version. This is the bad version.” And so, basically there were several of us that got together and we pushed for it so they could only download apps from an internal website to be able to get the tools that they needed, because we had people verify them. And actually, I had some people go to the actual person that wrote the original code and say, “Hey, can you give me a good version so that’s not malicious?”
Manoj Tandon: Now there’s a novel idea. If it’s open source, why not just go to the author themselves?
Bob Carver: Yeah. And ideally what you should do if it’s a company is give them some money. Give them some money and say, “Hey, thank you very much for your app here.” It’s going to be cheaper, probably, than a commercial version, and you could verify that it was a good version.
Manoj Tandon: That is a cheap insurance policy.
Bob Carver: Oh yeah. I used to be, many years ago in my early days of PCs, saying, “Oh, I want to be able to download whatever I want, whenever I want.” But the problem is, when I started seeing more and more people getting compromised, I thought, “Oh, maybe Apple, when they had the closed system and they were trying to only allow apps from their store… Maybe that’s a good idea.” Now, I at first thought, “No, why should we be throttled from downloading the apps that we want?” But now I’m sort of thinking that the average consumer, the average person, doesn’t have the capability to be able to analyze a piece of software and know whether it’s malicious or not.
Manoj Tandon: 100% agree. And you know, you’re also cutting out Shadow IT by doing that.
Bob Carver: Sure. But I can tell you, even though antivirus and endpoint securities are generally getting better and better all the time, I’ve had dozens of pieces of open-source software that were malicious. And I knew they were malicious, sometimes a week or two before all the antivirus and endpoint security companies did.
Manoj Tandon: Look, I’m not going to get in trouble because we actually did a paper on this topic and it became a little controversial. But all these endpoints… All the antivirus systems out there are pretty darn good, but they’re going to miss about 10%. And I’m going to generalize: They will always miss about 10% of what’s floating around out there.
Bob Carver: Yeah.
Manoj Tandon: And if you happen to download or come across that 10% that’s in the wild, well… And you don’t have the skills of a Bob Carver, then you’re going to succumb to some bad things, potentially.
Bob Carver: Exactly. Nothing is free. When you download something for free, it’s not free. There’s a reason for it. It may be the gift that keeps on giving. It compromises your system and then will probably go out and try to compromise other systems.
Manoj Tandon: So, Bob, talking about downloading technology… Just switching this a little bit, it seems like a lot of Infosec programs are really focused on acquiring new technologies versus addressing the people/process/awareness side of the equation. Why is that? Why is everyone thinking that I can cure my problems with just another tool? How about looking at your people as one of your largest and most valuable tools in the organization?
Bob Carver: Sure. That can evolve. I agree. I think larger corporations have been working on that quite a bit. It’s a little tougher with smaller corporations or smaller companies. They just may not have the resources, or if a person is the owner of the company, he’s busy trying to make business happen to have sales, to have income, that sort of thing. And to get to the point where they can have somebody to focus on security, or even possibly train people to have a security awareness program of sorts… Maybe not a full program, but where they have some sort of quick course every quarter, or even once a month. You’re going to do a five or ten-minute thing once a month just for awareness. A lot of times they’re just like, “I’m already working 80 hours a week,” and they just don’t have it. The other thing I think with small-medium businesses is that a lot of times they have an IT guy and they think that the IT guy is going to do all the security too. And there’s a ton of that going on.
Manoj Tandon: Too much. Too much.
Bob Carver: And the poor IT guy at the small company is already… He needs three or four hands already just to manage the systems and keep them up and running properly, let alone trying to investigate security incidents. So unless something really goes bad, it may not even be seen for a long time.
Manoj Tandon: Yeah, I couldn’t agree with you more.
We’ve also even in larger companies seen where, because of budgeting cycles, they get caught up with what was budgeted but what may not necessarily be the most effective for the present day.
Because when the budget was built, there was a different set of conditions, and the world in six months changes rapidly.
Bob Carver: It does, especially in Infosec or cybersecurity.
Manoj Tandon: And we’ve seen this quite often even in larger companies where they say, “Well, we budgeted for firewalls and now we’ve got to spend the money there.”But maybe that’s not the best place to go spend it, given what their threat surface is and how things have changed.
Bob Carver: No, I understand.
Manoj Tandon: Right. So is there something that can be done about that? Even in the larger companies, is there a realization that maybe there needs to be more flexibility brought into the procurement cycles or budgeting cycles? Because it seems like—at least as an outsider and we work occasionally with the enterprises—it seems like there’s a very solid line there that says, “Well, this is the money and this is what it’s going to be.”
Bob Carver: Yeah, well, that’s… I think part of it depends on the CFO or the person in charge of the money, how flexible they are. A lot of large companies that have been in existence a long time do have a somewhat rigid way that they finance things, and they want you to sort of “stay the course” most of the time. Occasionally there’s some flexibility and some money can be moved into something that could be considered more important. But part of it depends on your person that controls the purse strings and how flexible they are, and just their awareness of how fast things change in cybersecurity.
Manoj Tandon: Oh, I think… You know the mindset. I spent a lifetime in manufacturing before I was in tech, and it comes from manufacturing. In manufacturing, you do want to stay the course, and typically when you were ordering things, it wasn’t things that were available in two microseconds. You had to place orders, and they were built and then they were delivered. You couldn’t just change, right? I get that. But applying that same mentality to something like cyber or technology in general… Maybe there’s a rethinking that CFOs should have on this topic.
Bob Carver: Yeah, they… I think a lot of CFOs or people that charge the purse strings would benefit if they could have a refresh, maybe every quarter, of all the changes in technology that are happening. Just to help them out and to help them best understand how fast things are moving. It’s moving fast. Of course we know that in AI and ChatGPT and machine learning, it’s all happening very fast right now.
Manoj Tandon: ChatGPT, by the way… I have an account. That thing is amazing.
Bob Carver: I had put a video on LinkedIn and on YouTube just recently. I had it write a haiku—a haiku being a Japanese-style poem. Did you see that?
Manoj Tandon: No, I didn’t see yours. I will go and look it up after this. Anyway, I saw a demonstration. I had a junior associate at a law firm recently give me a demonstration of ChatGPT and how they could use it, and I was like, “If I was Google, I would be worried.”I would be worried.
Bob Carver: Well, Google’s on it big time. Baidu, the Chinese search engine, is on it big time. And of course Bing and Microsoft are on it. I think they’ve been hiring to be able to… obviously, catching up is a tough thing.
Manoj Tandon: Oh yeah, but I think Google’s been working on it in the background. They’re just not quite as… they didn’t go out there as big from a marketing standpoint. I think they are now. They actually… I actually signed up for the Google version. I can’t remember the name now, but hopefully I’ll hear something soon. Well, back to the CFO conversation: This is something they’ll understand—the rapid changes happening in the world of cyber insurance. They’ll certainly understand that. From what we’ve been reading, cyber insurance providers are typically today paying out 30 cents on the dollar of the contracted value because they are really looking at the fine points of exceptions and looking at how they’re going to minimize their payout. So, what’s happening in that world? I mean, we know what’s driving such a massive clampdown.
Bob Carver: I wrote an article on 2023 cybersecurity predictions and a wishlist, and this is one of the key points that I brought up. I said cybersecurity insurance is big time in flux right now. I think right now all the pieces are sort of thrown up in the air and we’re going to see where everything lands. One of the things that was the big indicator of what was going on: Lloyd’s of London, as you probably know, is one of the largest reinsurers of cyber insurance in the world, and they’re partners with a lot of the other large companies in the cyber insurance space.
Manoj Tandon: Yes they are.
Bob Carver: And they made an announcement a few months back. They said, “Oh, we’re not going to insure any nation-state-related breaches anymore.” And of course that’s a lot—it’s Russia, China, North Korea, Iran, and on and on. You can name it, and if it’s considered a nation-state-sponsored breach, they just won’t cover it. Quite interesting: Within about a week after they announced that, they were breached by some nation-state, which was really ironic. And then—
Manoj Tandon: Go ahead, go ahead please.
Bob Carver: Oh, and after that, Zurich Insurance basically said, “I don’t think we’re going to be able to continue on this course of cyber insurance as we know it. It’s going to have to change drastically.” And there are going to be a bunch of changes, and it’s already started. So what did you want to say?
Manoj Tandon: Well, I can tell you, when you were talking about Lloyd’s, we know them intimately—well, not that we work with them directly, but we had some mutual clients in the energy sector. I won’t name names, but they got dropped.
Their coverage got dropped. They just said, “You know what? In this space we just don’t care. We don’t care what controls you have. We’re out. We’re just not going to insure it. You’re not insurable.” Which for Lloyd’s is a big thing, because remember, I think they insured Marilyn Monroe’s finger or Cary Grant’s eyes. They insured anything you could get your hands on, right? For a company like that to say for cyber, in this sector, “We’re washing our hands of it. So long, farewell, it’s time to say goodbye”… that’s a really big thing.
Bob Carver: I think the key thing we have to look at is the exclusions in the fine print. There are going to be more and more and more exclusions in the fine print. So you better have your attorney and probably an insurance expert with you when you go to sign the next version of insurance. And of course the other thing is the cost of insurance has gone sky-high. I’ve heard a lot of people whose insurance went up 40%, 60%, and for some of them, even several hundred percent.
Manoj Tandon: Yep.
Bob Carver: So that’s a key thing. And then of course, you may have heard this, but they’re going to start requiring multi-factor authentication on a lot of things, especially anything that has to do with admin privileges—any privileged account at all.
Manoj Tandon: Two questions on that. Sure. You’re absolutely right, they are requiring it. Unless you’re a donut shop, then maybe you don’t have anything to MFA. But barring something like that, they’re requiring MFA. Why MFA only? Or why is everyone keen on MFA? And is it because the attack surface is so large? MFA is a key piece of it. But then you also mentioned admin accounts. How the heck do I know what admin accounts I have? I mean, that’s a whole bees’ nest of a problem. So please, I’d like you to comment on those things.
Bob Carver: Well, when it’s a real small business, they may not know. I mean, if they have a part-time PC guy that comes in and looks at their system maybe once a quarter or something just to see if everything’s working okay… The PC guy hopefully knows, but the small business owner a lot of times he’s not going to know.
Manoj Tandon: But even a 500-person company is a small business, right? Look at the number of cloud-based services that they’re consuming, whether that be Salesforce, Jira… pick something… QuickBooks, Office 365.
Bob Carver: Yeah.
Manoj Tandon: They have a huge cloud-based infrastructure. They might have stuff in AWS, and they might have a lot of various admins and various service-level accounts that are accessing those things.
Bob Carver: Right. I’m telling people more and more to try to stay away from two-factor authentication that’s text-based or SMS-based.
It’s better than nothing, but it is the bottom of the barrel of MFA. You need to have one of the apps that can do two-factor authentication, or even better yet, use security keys like Yubikey. Of course, the issue is getting concerned that somebody might lose their security key somewhere and then they’d have difficulty getting back into the system. But the key thing I think here is that I don’t think you’re going to see as many checkbox-type questionnaires, especially the larger you get. They’re going to want verification somehow or another. And boy, I tell you, if you try to put MFA on a system after it’s been breached, they’re going to have a forensics expert that’s going to tell them that, and they’re going to say, “Sorry, game over.” “You have no money coming to you. Thanks for playing.”
Manoj Tandon: You say that and I believe it’s probably happened quite a bit.
Bob Carver: Yeah, it’s already starting. It’s happened quite a bit because…
Manoj Tandon: Can we get away from service-level accounts?
Bob Carver: Yeah, it’s awfully hard. You’ve got to have… People have to be able to do their work. Simple as that.
Manoj Tandon: So is this a place for PAM?
Bob Carver: Sure.
I think we’re going to go beyond that.
You have your access management and you’ve got to verify the user, verify the user account, verify what computer it’s coming from—all the players involved.
Manoj Tandon: Yes.
Bob Carver: And then as far as Zero Trust, eventually you’ll have more micro-segmentation where the permissions are very small.
You might be able to only have, say, read-only access to a certain part of a database, not even the whole database, if the database is designed for that kind of granularity.
I mean, that’s another problem, right?
Manoj Tandon: Absolutely. Absolutely.
If it’s a mom-and-pop database, it’s probably one big happy family where anybody can go in there and do everything.
Well, I’ll tell you that there is a major production shop that makes motion pictures.
And we encountered a situation where the final prints were on a database server that wasn’t… that needed some security. I’m going to leave it at that.
Bob Carver: Right, right. It’s been corrected since then, but good.
Manoj Tandon: That could have been a catastrophic financial loss.
You know, it’s interesting:
A friend of mine… their friend designed a storage system just for the movie industry.
Bob Carver: And he spent a lot of money developing it and making it secure and having it encrypted and on and on.
I can’t remember the exact dollar figure, but compared to what movie studios generally spend on their movies, it was relatively minor.
And they had a chance to try it out for at least six months, and it worked perfectly as designed.
And they just didn’t want to come up with the money for that.
It was interesting.
Manoj Tandon: Believe me, I believe that story in its entirety given our experience with it.
This person had relatives in the industry and had key contacts, and they just didn’t… it wasn’t on their radar.
And you know what’s amazing to me is that they’ll spend a hundred million dollars in the shooting, filming, and production of a major motion picture.
It might cost them 600 grand to get the right boundary layers in place, which is nothing.
What’s the interest on a hundred million dollars?
Bob Carver: Yeah.
Oh yeah.
I think one studio wanted to buy it outright—the ownership, the patent and everything.
I think they wanted to offer like two hundred thousand dollars, and he said, “No, that’s the cost for you to be able to use it, but not to own it outright.”
Manoj Tandon: Yeah.
And my counter is: In this case, the final cut was actually available to anyone with the right skills.
They could release the movie before the movie house could and make it available globally for free.
Now, what is the financial loss with that?
And is 600 grand really any amount of money to even talk about in the guarding of that?
Bob Carver: Understood.
Sometimes it just doesn’t make sense.
I always visualize that rush into Russian Roulette like a pistol with one bullet in it.
It’s like, “Do you feel lucky today or not?”
Manoj Tandon: Is this the way you run your cybersecurity program?
Bob Carver: Exactly.
Manoj Tandon: So, you talked a little bit about MFA in the insurance world.
What about social engineering and routers and endpoints and all that?
Are requirements around those things going to get toughened up?
Bob Carver: I’m sure they are. I’m sure they are.
I think they’re still trying to figure out a lot of things like that.
I think there’s a lot of talk about how they may not pay the ransomware anymore.
It was a big time where they just pay it and they may or may not get the data back even though they pay the ransomware.
Manoj Tandon: Oh, the data part is a farce.
I would never believe you even got it back, because…
Bob Carver: Yeah, sure.
And you’ve probably heard the statistics: A lot fewer people were paying the ransom last year.
Manoj Tandon: Yes, a lot fewer.
So what’s happening now?
Bob Carver: The trend now, as you may know, is that they’re just exfiltrating all the data.
They’re holding that for ransom.
They say, “We’re going to start selling it on the market in 48 hours if you don’t come up with X amount of dollars,” in cryptocurrency.
Manoj Tandon: How is this different from Bonnie and Clyde?
If kidnapping didn’t work, let’s resort to extortion.
Bob Carver: Absolutely, it’s the modern-day Bonnie and Clyde or famous mobsters.
Why do you rob banks? Because that’s where the money is.
Manoj Tandon: That’s where the money is.
I don’t know who said that; it was one of the big mobsters. We’d have to look it up.
Now it’s like, “Okay, why are you doing these cybercrimes?”
Well, that’s where the Bitcoin is, or Monero, or whatever.
I mean, that’s a whole other topic which we don’t have time to talk about.
But I’d love to have you back to talk about that whole Bitcoin thing.
Bob Carver: Sure.
Manoj Tandon: So, Bob, we didn’t get through this list because I want to give you some time to go ahead and plug things that you want to bring to our audience’s attention.
Are there any appearances, books, talks, or anything that you’re up to that you’d like to plug out there?
Bob Carver: You know, I’ve not been as active lately as a result of COVID, but I’m hoping to be at Black Hat and Defcon this summer if everything—the COVID and all the other viruses that are running around—has slowed down a little bit.
But one of the things I’d like to tell people is to look into doing some ad blocking.
I’ll have a video here very soon, maybe if I have time, I’ll get it out by tomorrow, on ad blocking.
Because that is the thing that’s happening right now.
And also, everybody should be doing MFA on all the accounts that you can.
If possible, look into doing security keys like Yubikey.
Those will improve your ability to protect your accounts better than most things right now.
Manoj Tandon: That’s wonderful advice, Bob.
And we need to get you back and get into more topics.
We’ve only scratched the surface.
Bob Carver: Yeah, if I remember, I was interviewing for a board job on a small startup, and we got talking.
It was supposed to be like 45 minutes to an hour at the most; we ended up talking for four hours straight.
So it can happen.
Manoj Tandon: It absolutely…
There’s a wealth of knowledge that you have, and we’re grateful that you’re willing to share it with our entire audience and the planet.
Make us all a little bit safer.
Bob Carver: Absolutely.
Manoj Tandon: Well, Bob, thank you so much for being on the show.
We look forward to having you back at some point.
Bob Carver: You bet. Take care of yourself.
Manoj Tandon: Everybody stay safe and secure until next time.
Bob Carver: Until next time.
Bobs video on Malvertising
Bob’s Twitter: @cybersecboardrm
To learn more about Bob visit LinkedIn
Check out the other episodes in Season 9:
Ep. 1 Justin Daniels – Where does our Data go?
Ep. 2 Kenneth Ellington – Bagging Groceries to A Career in Cyber
Ep. 3 Brian Davis – Credentials: What is important?
Ep. 4 John Shegerian – Responsible Recycling of Electronics and Data
Ep. 5 Philippe Humeau – The Captain America Approach
Ep. 6 Dallas Baker – Human Behaviors that cause breaches
Ep. 7 Eric Allard – Everybody has a Boss
Ep. 8 Peter Warmka – Confessions from a CIA Spy
Ep. 9 Bob Carver – How Paris Hilton Helped My Carrer
Ep. 10 Dr. Wendy Ng – Biological Viruses vs Computer Viruses
About Bob Carver

Bob Carver CISM, CISSP, M.S. began his security career working in the financial industry.
Later, Bob became the first full-time security employee hired to start the dedicated security monitoring and incident response team for Verizon Wireless.
He has been involved in cyber risk management, policy, threat intelligence, and analytics.
He was Recognized by LinkedIn as one of the Top 5 Influencers in the World to follow in Cybersecurity.
Most recently, he was on an expert panel for CES (Consumer Electronics Show) in Las Vegas discussing “Focusing on Security in Product Innovation.”
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
