Hi everyone, I'm Mirella Ciobanu, lead editor with The Papers, a global financial publication, and we are live at cyberevolution. Happy to speak with Sergej Epp, CISO at CISDEG, and we are going to delve into trends and developments into cybersecurity.
Sergej, happy to have you here with us. Thank you for the invitation. Thank you. It's an honor to speak with you because you have so many results, achievements, and I'm curious to know how you became an expert in security. What attracted you to this? So it's a very simple story. When I was a kid, still going to school, I started to code a bit and just developed a couple of software projects, and one of the software projects was a web server. And this was a very simple one-click web server.
And when I published that, literally within two days, somebody found a vulnerability, a directory traversal vulnerability back in that. And that sort of made me very angry, right? Because there was a lot of, there was a first CVE assigned, and I started to spend more time trying to understand what is it all about.
And, you know, was sucking really into the security and then had a lot of time doing and studying something completely differently. But then I just simply came back because this topic just never, yeah, never went away. And I was more and more attracted by working in the industry as well, trying to understand how can you really, yeah, protect the enterprises. And what's really special about cybersecurity in general, I guess, is that whenever there's a new tech, blockchain, container, cloud, as a cybersecurity professionals, we have always to be up to date.
So this is one of potentially the most dynamic industries out there. And that's what makes so much fun there, because you're always at the forefront of the technological innovations. And since you mentioned here being up to date, yeah, what are the main threats that are, what could be the dark horse, the dark nights that are plaguing systems like financial, healthcare, education in terms of cybersecurity?
Yeah, I think, you know, I would start this more from a business perspective, I'm not deriving technical stress, because I think still the biggest threat is, as we had this already 10 or 20 years ago, is not really understanding your own risks. That's number one. Number two is oversimplification of cybersecurity, because cybersecurity in general is very, very difficult to measure. So whenever we feel secure, but don't really understand the risks and don't understand the effectiveness of certain security controls or programs, that's a trap, right?
Because we can make so many different wrong choices in how to invest in cybersecurity, what to secure and whatnot, that it can be a dark horse in the end, you know, once a hacker or somebody knocks on the door. So I think the real importance is to understand what are the biggest risks for your organization, and try to simulate these risks, understand, okay, what is going to happen, and if these risks are going to materialize, right? And in the financial service industry, for instance, we have got this red teaming exercise being enforced by regulators, cyber exercises.
And I think this is a very good way to really understand how would the hackers, how would the criminals, how would the nation state attackers trying to get in and based on that, then derive the right security priorities for your program, the processes, and also the controls, it's always a combination of both. Where can you mitigate with technical controls?
Where can you mitigate with processes, but the most important decision from our point of view is to really have this understanding, when do you need more security versus when do you need more secure software as well, right and secure processes. So whenever you have a choice to modernize your t stack, you go first for that part of investments rather than trying to add on more and more security. So going back to your question, the risks are, there's a lot of like, more or less tactical risks right now what we observe.
But I think the biggest challenge is really, how do you understand if those risks are currently present to you, right? And then you understand a supply chain risk, which we still currently see as a big one of the biggest issues right now happening is potentially relevant for information or not. And other risks around open source, open source security, also nailing into supply chain could be another problem. Ransomware is still a big, big challenge, because the groups, you know, who made a lot of money in the past years with ransomware are still out there, and they're still being successful.
So they're continuing with a big playbook, right? They're continuing to earn money. And I think, as long as we are not able to sustainably solve this problem, and really find this threat actors behind that, and get him in jail, this problem is going to persist for everybody. And they will always find new ways.
But, yeah, I think in general, the question is, what's really important for your organization for your specific organization, and based on that to write them the security programs and controls. And until we go to Yeah, how we can address this, because you are going to speak about supply chains, and you mentioned about the supply chain risk and source, using open source solutions risk. Maybe can you delve into this topic?
Yeah, presenting it more in detail. Yeah, absolutely.
I mean, I think, because, you know, sorry, for financial institutions, this involves lots of transaction payments, and for them, it's a hot topic. Yeah, of course. And I think, you know, the entire financial service industry is built on trust, right? So we understand if one entity fails, it could really impact the entire ecosystem. And that's why we have financial institutions, but potentially is the most important.
Yeah, organizational type, which has to be protected, because it has this, first of all, you know, industry impact on other financial institutions, but then also macroeconomical impact, because if one bank fails, we found this 2008, it could be a very bad shockwave for the entire, you know, economic of a country or the world. So, yes, supply chain is a big problem. And I think this was not so much in focus during the last years by cyber criminals and by nation state attackers.
And since the last two, three years, we see a more systematic approach being driven very heavily by specifically nation state attackers, considering that some of the big targets they have identified as victims were properly secured, invested more in security, they found a good way just to sneak in through the supply chain, through some small providers, with some small organizations, through open source, and get their foot into the door through this way, because it was much more easier, right, for them to do that.
And I think since then, we also started to see more and more criminal groups like ransomware groups applying the same type of approaches. So instead of now compromising, you know, 10 companies, they would compromise a small MSSP company, you know, small vendor, and then really try to use this as a as initial broker to compromise other companies, right, and then to demand money for that from them. But I think this trend is going to continue.
And I feel with cyber criminals, sort of a bit under control, because it's typically very visible if there are certain breaches happening, because their motivation is to earn money. If you now bring this back to nation state attackers, who are more focused on espionage, and just staying silent in an organization, that's where it's becoming very dangerous, because we don't know what we don't know, right. And we need to assume simply that supply chains are breached today, we just don't know about that, right.
And I think that's where the fun for us as CISOs is starting, really trying to, what we call in cybersecurity, assume breach mentality. So trying to understand what would the hacker do if he would be now an organization, if he would own these assets or these identities, and trying to play through what the scenarios might be, because we all know there's no 100% security. So the biggest challenge is really to understand this tech vector, this blast radius of potential attacks as well, internally in the company, but then also obviously trying to reflect this back to different suppliers.
And then they're not just direct suppliers, they're suppliers of suppliers. And that's where it's becoming very tricky and difficult, because you can still control somehow your suppliers by asking them questionnaires, by spending time with them, by doing audits, by trying to do, you know, inspection of their security controls. But then there's some other suppliers, all those suppliers.
And we saw already a lot of attacks where threat actors, nation threat actors, were motivated, for instance, to hack a cybersecurity vendor who is an identity provider, for instance, and then try to hack through this identity provider other security companies, who then have a lot of very, very critical government entities or other entities. So it was like an attack from one supplier to another supplier to the real targets as well. And therefore, I think there's just one conclusion to draw. We are all in the same boat, and we need to get more transparency, more clearance on the risks.
And on the other hand, try to understand as well, how can we decouple those risks, right? And that's also something perhaps we can talk about, but there's obviously this zero trust architecture, zero trust strategy. But actually, I was about to ask, because we scared our audience, you know, with everything bad that might happen, this ripplets of bad influence from provider to provider. So now we need to give them also something positive to look upon. So you mentioned zero trust, blockchain, I don't know what technological solutions.
And also, I think that the human expertise is important. So what final say do we have for all you have presented?
Yeah, I mean, as I said, I think from a solution point of view, it starts, first of all, with the business risks itself, right? So trying to understand, if you just look specifically on supply chain problem, who are your core suppliers, and what could be the impact to your organisation if those suppliers are getting breached? That's step number one. And then the second step is to understand their risk.
And very often in security, we start with the second step, trying to assess all the suppliers and just put the stamps on them, hey, you have to be secure, instead of first understanding, like from a risk based point of view, which suppliers are really critical to me and which are potentially not so much critical. So I think that's important to make this assessment and the study, potentially for 99% of suppliers, I don't even need to care because it would be just a minor impact on the organisation. But for this particular suppliers, it's going to be really, really difficult.
So I need to prepare. I need to either try to increase the security of the supply, which is always very difficult, obviously, but then also trying to understand how I can cope with the potential breach. And there is a very extreme solution to say, if the supplier is not fulfilling my security requirements, I could just say I'm going to contractually make him liable for this potential problems and then throw him out or just exchange him. This doesn't really work in practice because cybersecurity professionals typically don't have this instrumentation.
So the better way is just trying to understand how do you build security around those critical suppliers. Let me give you an example. If this is, for instance, I don't know, a specific application like SolarWinds, right, which is running in the organisation by a team and it has certain access to your critical assets in the organisation. So if it's getting breached, it can spread laterally within the organisation.
What you can do is just to set guardrails around that to ensure, first of all, that the assets, the workloads you're running this application are secured with proper runtime security controls or proper XDR controls to ensure if this device is breached, we are sort of reducing trust to this device and implementing the security controls to still be able to cope with this, providing then another guardrail around network protection.
So we call it segmentation, right, the micro segmentation around this specific asset or this group of assets, ensuring that the identities being used on this specific assets are only having access to this assets and cannot be misused in any other parts of the organisation, which is also very often forgotten. And if you just look at big compromises, even with large tech companies, this is how the lateral movement happened, right? Identity is a big attack.
So I think this is where we need to spend more time, because I feel supply chain security topic is often very much focused on, hey, the suppliers have now to do all the security. That's not going to happen. That's not going to happen simply because suppliers are always having multiple customer groups, so they need as well to drive a risk based approach. How much security do I need to do now to be successful in the market?
So I think what's more important is also to understand how do you encapsulate, right, or what we call zero trust again, strategy, like how do we really decrease the trust from the supplier or from this installation of the supplier if they're getting breached? So the blast radius stays very small. It seems a bit complex to have this concept encapsulating things, but on the other hand, things they need to communicate so well for things to work well so that you have, I don't know, your bananas on the supermarket.
And yeah, as we are a cyber revolution, what are your event takes so far? I think it's great to, first of all, meet so many diverse security experts from several fields around, you know, cloud detection, response, identity management, CEOs from large banks, from industry companies, startups. I think that's a very great conference to bring all this audience together in a very sizable manner and have great conversations, discussions. So I've enjoyed it so far. So thanks for having me here. Great. Thank you so much for today's discussion. And we look forward to continue. Absolutely.
Very happy to be here. Thank you.