Into the Abyss: cybersecurity tool selection, rationalization, and decommissioning
Download resourcesAbout this session
Jeff Schmidt, CTO of GoSecure and a former Microsoft kernel developer who ran the company's first malicious-testing program after the Lovebug and Code Red era, argues security tool selection is unscientific and should become an optimization problem grounded in offense-informed defense. He challenges how organisations buy tools (CISO whack-a-mole, best parties, vendor relationships, board panic over ransomware) and how rarely anyone decommissions anything. Two provocations anchor the talk: your controls do not work the way they are written down, proven by offensive testing, and controls and response procedures degrade over time. He reframes security around time, using fire codes, aviation fire containers, UL fire safes and GSA classified containers, all rated to survive an adversary long enough for the cavalry to arrive, and notes the Verizon DBIR dwell-time drop is only because ransomware is self-announcing. Combining MITRE ATT&CK with tightening OODA loops and continuous testing, he proposes assigning every technique a CDTRV profile, controls, detection, timing, response and validation, then overlaying which techniques real threat actors use against your sector to find gaps, redundant tools, and where to spend the incremental dollar. A Q&A covers unknown-unknowns and hygiene, economic versus non-economic threat actors, and justifying spend with a fence-and-holes analogy.
The information security space is awash in point technology solutions. As a defender, how does one choose where to spend a limited security budget when faced with this sea of choices? How can we minimize overlap within the highly dynamic toolset we already own, rationalize vendor relationships, and decommission tools that overlap or no longer justify their operating expense? We are debilitated by too many choices and similarity of products in security where even experienced practitioners find it difficult to understand the rapid technological evolution and the trade-offs in play. When clear objectives, goals, and decision-making criteria are not present, people often make buying decisions based on less scientific considerations: what they perceive “everyone else” is buying, unsubstantiated “gut feelings,” pre-existing relationships with vendors or sales individuals, or even who invites them to the best parties or nominates them for the most coveted industry awards. The practice of information security is maturing rapidly. This transition to more scientific approaches to prioritizing security investments is becoming the standard to justify value. Security practitioners must embrace these mature approaches to strategic defense planning and resource allocation. This presentation will discuss ways to make the best choices to maximize defense coverage with appropriate resource allocation.
Key takeaways
- Treat tool selection as optimization: deciding what to decommission or consolidate matters as much as what to buy, and redundant coverage of the same techniques is budget you can redeploy.
- Assume your controls do not work as documented and degrade over time; use offensive testing to invalidate assumptions about both controls and response procedures.
- Design and measure security in terms of time, time to detect, time to respond, and whether the 'cavalry' arrives before damage is done, rather than a binary secure-or-not posture.
- Map MITRE ATT&CK techniques to a CDTRV profile (controls, detection, timing, response, validation) and overlay which techniques real threat actors use against your sector to find the red gaps.
- Scope offensive tests and justify the incremental security dollar objectively by targeting the techniques adversaries actually use where your coverage or validation is weakest.
Speakers
Mr. Schmidt is a 25-year veteran of the information security industry. With a unique blend of technical expertise and business savvy, he has consistently shown results architecting and delivering security and risk management solutions for a full… Read moreRead less
Mr. Schmidt is a 25-year veteran of the information security industry. With a unique blend of technical expertise and business savvy, he has consistently shown results architecting and delivering security and risk management solutions for a full range of government and private sector firms. Previously, Mr. Schmidt was a Vice President of Covail where he led the cybersecurity business (Covail was acquired by GoSecure). Prior to Covail, Mr. Schmidt founded Authis (acquired by Richemont), served as the Vice President of Product Management for ENDFORCE (acquired by Sophos), and directed the technology planning, budgeting, implementation, and operations for a $65M department at The Ohio State University. He also spent time at The Microsoft Corporation where he spearheaded Microsoft’s first internal malicious testing of Windows 2000. Mr. Schmidt served on the Board of Directors of Delta Risk, A Chertoff Group Company, until its acquisition by Motorola Solutions. Mr. Schmidt received a BS and MBA from The Ohio State University and currently serves on the Board of Directors of DataPulse LLC.