Standing up an innovation team

Archive for the ‘Security’ Category

Standing up an innovation team

Posted by

Expect security execs’ remits to include greater risk responsibilities and opportunities to elevate the business as organizations look to accelerate innovation in an increasingly challenging cyber world.

Excerpt from: What the CISO role will look like in 2029

Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more.

“For the future I see growing the role of CISO to be the pacesetter for innovation, to be in the board room and executive conversations advising them on how to take smart, calculated risks with technology, including AI,” says Goerlich, who is now a public sector CISO and a faculty member with IANS Research.

Goerlich sees this as the next step for a role that has continuously evolved since its inception in 1995.

“It’s gone from the ‘department of no’ to ‘let’s slow down’ to ‘let’s take smarter risks based on our understanding of them,’” he adds. “How exciting is this? To be the one to say, ‘You want to take more risk? Let us help you. We can help you make smarter decisions.’”

Goerlich isn’t the only one with such observations. Others similarly believe that the responsibilities assigned to the typical CISO will change in the upcoming years.

Despite a broad consensus on change, predictions vary on how that change will play out in terms of the CISO’s roles and responsibilities. Mirroring the traditional three-year look for strategic planning at many organizations, security leaders see a range of possibilities for the CISO position evolving by 2029. Regardless, all agree that the CISOs of tomorrow will have to work at a faster pace, contend with more threats, and bear more strategic responsibility than they do today.

Research confirms this outlook.

Goerlich is experiencing that shift already, having been tasked with standing up an innovation team that includes architecture and engineering professionals as well as security practitioners.

CEOs and boards increasingly recognize that having security in those leadership roles accelerates — rather than slows — innovation because “security knows how to help them take risks,” he says.

Read the full article: https://www.csoonline.com/article/4208210/what-the-ciso-role-will-look-like-in-2029.html

Wolf’s Additional Thoughts

I’m excited about my new innovations lab. As I shared with CSO, the CISO can be the pace car or the pit stop of innovation. The pace car is more fun. If you’re doing something similar, reach out, let’s compare notes.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Synced passkey security issues could allow account takeover

Posted by

The attacks can misuse trusted workflows to take over passkey-protected accounts, but the attacker must have first breached defenses and planted malware; analysts say the issue is flaws in supporting processes.

Excerpt from: Passkey security issues could allow account takeover

Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.

J. Wolfgang Goerlich, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.

“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”

Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”

Read the full article: https://www.computerworld.com/article/4205809/enterprise-passkey-security-under-threat-from-malware.html

Wolf’s Additional Thoughts

In 2021-2023, in presentations such as Street Cred and Mistaken Identity, I warned of this exact type of attack. Credential theft and re-use is only possible when the authenticator can be copied, cloned, and replayed. That’s exactly what synced passkeys allow. It’s frustrating but entirely unsurprising to see this happen. If you must shared passkeys, use enterprise credential managers like 1Password and others.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Techstrong interview on IANS new MCP

Posted by

The first cybersecurity MCP server is here. Wolfgang Goerlich, IANS faculty member and public sector CISO, joins Alan Shimel on how IANS now surfaces peer research inside Claude and other AI clients. Furthermore, Wolfgang and Alan unpack whether AI is really rotting our brains or quietly sharpening the pros who use it well.

Wolfgang came up in the golden age of security alongside Alan. Consequently, he brings decades of hands-on CISO perspective across healthcare, financial services, tech and public sector engagements. Meanwhile, his IANS faculty seat gives him a front row view of what practitioners are shipping today.

Inside the first cybersecurity MCP server IANS is a practitioner-led research and intelligence network for CISOs. As a result, its new MCP server lets clients pull that research directly into a Claude prompt while they draft a policy or standard. Meanwhile, one of Wolfgang’s own runbooks got refreshed in minutes rather than weeks.

Alan pushes on the details. In addition, the cybersecurity MCP server is scoped to IANS clients and faculty, and it feeds real quotes, insights and polls back into the prompt. Therefore, teams stop guessing what generic AI thinks and start acting on what their peers actually did, whether they are updating a runbook, a policy or a fresh standard.

Why every CISO should watch the cybersecurity MCP server story Alan and Wolfgang widen the lens to the de skilling debate. Meanwhile, the latest studies suggest AI power users sharpen their thinking by interrogating outputs rather than accepting them. Consequently, the gap between passive and active AI users is widening across security teams.

Wolfgang also weighs in on MCP protocol security, comparing today’s posture to the early days of API security. Furthermore, he explains why 170 practitioner-faculty members give the platform an edge as vulnerabilities surface. Learn more at iansresearch.com.

Multi-cloud Security challenges

Posted by

From inadequate visibility to access management complexity, multicloud environments take baseline cloud security issues to another level.

Excerpt from: 5 multicloud security challenges — and how to address them.

Some CISOs opt to have a single security program for their entire cloud environment while others take a cloud-specific approach. Each strategy has pros and cons, says Wolfgang Goerlich, IANS Research faculty and a public sector CISO.

“If you’re treating all clouds the same, if you have a unified security program, then that means you’re not using the native security tools and you’re not driving the value out of each cloud. And not all solutions will pull in data [from each cloud provider] with fidelity, and not all apps will be as granular as the native tools,” he explains. “But if you go native, if you do a deep dive into each cloud, you add more tech and you probably won’t have teams who can work across the different clouds, so you create more challenges with processes, staff, and technology.”

Goerlich doesn’t list one option as better than the other but instead stresses the need to weigh the benefits and drawbacks of each one when devising an enterprise security plan.

“It’s all about the tradeoffs,” he says. “You can organize your team by cloud to drive more value from native capabilities, or have your team know enough about each cloud to effect change, or take it to a high level and not use the native tools.”

Read the full article: https://www.csoonline.com/article/4009247/5-multicloud-security-challenges-and-how-to-address-them.html

Wolf’s Additional Thoughts

It is the tug‑of‑war between unified vs. cloud‑specific security controls. It is a balance between manageability and defensibility. Often the culture of the organization and the design of the InfoSec team makes more of a difference than a specific tool or strategy.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

CISOs in crisis

Posted by

Cybersecurity is an intense race that never lets up, an endless back-and-forth with threat actors looking for a way in. Not surprisingly, CISOs are continually on edge, feeling increased stress and pressure: In fact, 75% are open to change, according to a new report from IANS Research and Artico Search.

Excerpt from: CISOs in crisis – why they feel dissatisfied and neglected by the C-suite and board.

So what can CISOs do to improve their satisfaction levels, standing and influence within a company and broaden their non-technical expertise? For starters, advocate, IANS advises. With traditional characteristics no longer meeting the needs of the new security landscape, CISOs have an “unprecedented opportunity” to argue for their role at the C-suite level and call for enhanced interaction with boards.

Ultimately, says advisory CISO and IANS faculty member Wolfgang Goerlich: “CISOs who manage relationships are more satisfied and successful than CISOs who manage technology.”

Read the full article: https://www.sdxcentral.com/articles/analysis/cisos-in-crisis-why-they-feel-dissatisfied-and-neglected-by-the-c-suite-and-board/2024/01/

Wolf’s Additional Thoughts

Security leadership is a relationship, not a position. I’ve said it before and I’ll say it again. I understand many of us (myself included!) got into this field for our love of technology. Preserve that love, that spark, that joy. But always remember it is our relationship with our peers, the C-Suite, and the board, which enables us to lead and make a difference.

Side note, I’m a fan of coaching. Both being coached, and coaching others. I think it just makes good sense to get an outside opinion on what you’re doing, and what’s possible. The study found it also makes good business sense. “Security leaders who don’t participate in professional development make an average of $369,000 a year, while those with executive coaching take in roughly $550,000 — a difference of nearly $200,000.”


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

 

A pre-mortem on Zero Trust

Posted by

Zero trust offers organizations an approach that can help to significantly improve security posture and help to minimize risk. But what would happen if, let’s say, an organization had fully implemented zero trust and yet at some point several years into the future had a breach? What would be the likely reasons?

Excerpt from: How a pre-mortem can tell you what’s wrong with Zero Trust

“Our out of scope is in scope for adversaries,” Goerlich said.

“Whenever a control reaches critical mass, the control will be bypassed,” he said. “Another way of saying that is all a better mousetrap does is breed better mice.”

He suggests that organizations deploying zero trust today, look at their roadmaps and make sure they have plans to sustain support, interest and engagement for years to come. Goerlich also recommends that zero trust implementers shore up out-of-scope areas to help reduce the attack surface.

Read the full article: https://www.sdxcentral.com/articles/analysis/how-a-pre-mortem-can-tell-you-whats-wrong-with-zero-trust/2023/04/


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Empathy, kindness, and behavior economics on We Hack Purple Podcast

Posted by

Tanya Janca invited me onto her We Hack Purple Podcast to discuss vulnerabilities beyond code. Along the way, we cover behavior economics and the importance of empathy in cybersecurity design. “Kindness is the original security principle” makes an appearance, as we talk about how all this and more applies to building better products.

Our conversation was sponsored by the Diana Initiative, a conference committed to helping all those underrepresented in Information Security.

 


To see listen to other podcast interviews, click to view the Podcasts page or the Podcasts category.

Cisco Rolls Out Duo Passwordless Authentication, Sees WebAuthn Usage Surge

Posted by

Excerpt from: Cisco Rolls Out Duo Passwordless Authentication, Sees WebAuthn Usage Surge

Cisco plans to roll out its Duo Passwordless Authentication globally next Wednesday. This push is in line with the findings from Duo Security’s recent report which showed that passwordless adoption continues to climb.

“We’re starting to reach a tipping point where the hardware is ubiquitous, the standards are in place, and enough services support the standards, and that’s really driving that increase that we see in web authentications. So now … organizations can adopt them with confidence,” Goerlich said.

Read the full article: https://www.sdxcentral.com/articles/news/cisco-rolls-out-duo-passwordless-authentication-sees-webauthn-usage-surge/2022/11/


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Nudge and Sludge: Driving DevOps Security with Design

Posted by

 

Nudge and Sludge: Driving DevOps Security with Design

Security people say users are the weakest link. When security becomes burdensome, users take shortcuts jeopardizing security. Design offers a solution. We will walk through affordances, nudges, sludge and principles to inform and direct our design. Come learn how better usability leads to DevOps security.

This talk was given at DevOpsDay Tel Aviv 2021.

Good security is like a good coffee pot – Design Monday

Posted by

Coffee. Coffee fuels hackers, coders and security wonks alike. For hackers of my generation, we tackled many a problem and brewed many a pot with a Braun. And within its hourglass shape lies a lesson for today’s security professionals.

The chief designer at Braun from 1961-1995 was Dieter Rams. He was behind the ubiquitous Braun coffeemaker from the 1980s. (I had a hand-me-down pot in my workshop in the 1990s.) Now you might think the shape was for decoration. Makes sense. One of Dieter Rams’ ten principles for good design is that good design is aesthetic. You’d be wrong.

Attractiveness for the sake of attractiveness isn’t Dieter Rams point. His design aesthetic was first solving the problem, and then solving the problem in a beautiful way.

The hourglass coffeemaker’s shape stemmed from a problem with the plastic. Plastic casings were still relatively new at the time. The process wasn’t producing plastic that was strong enough. The fluting provided strength and structure. As Dieter Rams wrote, “what was often misunderstood as some kind of post-modern decorative element had in fact a definite structural function.”

Applying this to cyber security: first design to meet the security requirements, then redesign using the same elements to provide a good experience.

Braun KF 157 Coffeemaker, Photography via WorthPoint.

Good Design is Aesthetic

I’m nostalgic about Braun KF 157 coffeemaker. But I’m in love with the Braun KF 20.

The KF 20 was ahead of its time. It looked like science fiction. In the futuristic world of Alien set in 2122, there was the Braun KF 20.

Florian Seiffert designed the coffeemaker in 1972. Following Dieter Rams direction and principles, every stylistic element has a functional purpose. The end result is well-designed, well-intentioned, beauty.

“It is truly unpleasant and tiring to have to put up with products day in and day out that are confusing, that literally get on your nerves, and that you are unable to relate to.” Dieter Rams spoke of products like coffee pots. But he just as easily could have been describing security controls.

Good security has a design aesthetic that is relatable and understandable.

Braun KF 20 Coffeemaker, Image via Dan Gorman

This article is part of a series on designing cyber security capabilities. To see other articles in the series, including a full list of design principles, click here.