This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Avoiding the Urgency Trap of Modern Cybersecurity

Download resources

About this session

Greg Young, VP of Cybersecurity at Trend Micro and a former Gartner analyst, argues security teams over-index on urgent work and neglect important, non-urgent infrastructure, using Y2K as a model slow-burn problem fixed only through sustained investment. Post-quantum cryptography is treated as decades away, but the real risk window opens once a nation state can spend about a month of compute to break a high-value target, which he estimates within five to ten years; every year of delay widens how much of today's data is already exposed to future decryption. Supply chain risk has shifted from availability concerns to embedded, unknown components; he pushes software bills of materials as the practical fix, plus awareness of fourth-party risk from vendors' own suppliers. Attack surface visibility is the highest-leverage action: most organizations only see the easy eighty percent of their assets, with shadow IT, unmanaged mobile devices, IoT and recent acquisitions forming blind spots that unpatched systems and lateral movement exploit. The talk closes with audience questions on how SBOMs are produced and how much runway remains before quantum breaks current cryptography.

With an ever-increasing number of threats, cybersecurity teams have become focused on responsiveness. We all want to patch or protect against the latest threat - but has this urgency come at the expense of long term defense? In this presentation, the speaker will consider why the things that are put off till tomorrow to focus on the most recent attack could come back to roost in a year or two. He will use the current industry mindset around quantum safe cryptography, supply chain vulnerabilities and attack surface visibility to illustrate why short-term fixes must be balanced with long term planning. Finally, he will share three actions that attendees can take now to put their teams back on the path towards a more balanced approach.
These include:

  • Creating dashboards or scorecards that record progress on longer term initiatives
  • Building a reward-system around gaining headway on those initiatives
  • Developing goals & tracking milestones on important (but not imminent) cybersecurity concerns
  • Creating dashboards or scorecards that record progress on longer term initiatives
  • Building a reward-system around gaining headway on those initiatives
  • Developing goals & tracking milestones on important (but not imminent) cybersecurity concerns
  • Key takeaways

    • Start budgeting for post-quantum crypto migration now; every year of delay adds a year of today's data to what will be readable once decryption becomes practical.
    • Ask vendors and partners whether they maintain a software bill of materials (SBOM), and start building your own so you can tell what components and dependencies you actually run.
    • Treat attack surface management, not IT asset lists, as the source of truth for what you own; ops inventories are known to be inaccurate.
    • Expect the easy 80% of your asset inventory to come quickly and the last 20% (shadow IT, unsupported mobile devices, IoT, newly acquired subsidiaries) to take disproportionate effort.
    • Frame long-term risk work for the board rather than for fear of attackers; boards now demand assurance and respond better to that framing than to technical urgency.

    Speakers

    Greg Young
    Greg Young
    Vice President for Cybersecurity · Trend Micro
    Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of… Read moreRead less

    Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of Communications, Chief Security Architect for a security product company, headed several large security consulting practices, and as Captain Young served in the military police and counterintelligence branch. Greg received the Confederation Medal from the Governor General of Canada for his work with smart card security. He currently is: Member and former co-chair for the federal government’s Forum on Digital infrastructure Resilience (CFDIR), and a member of the AI Working Group, and the Supply Chain Resilience Working Group, on the federal National Cross Sectoral Forum (NCSF) for Critical Infrastructure, appointed by cabinet of the Government of Barbados as a member of their Cybersecurity Working Group, liaison to the Canadian Security Telecommunications Advisory Committee (CSTAC).

    Resources

    Tags

    More from GoSec 2024

    Also from Greg Young

    On the same topic

    This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.