Asheem Chandna | The Long Game in Cybersecurity artwork

Asheem Chandna | The Long Game in Cybersecurity

Greymatter

February 17, 2022

The audio version of Greylock general partner Asheem Chandna's column for Forbes, "The Long Game in Cybersecurity." As the underlying technology of cybersecurity advances, so, too, does the cyber threat.
Speakers: Heather Mack
**Heather Mack** (0:05)
Hi, everyone. Welcome to Greymatter, the podcast from Greylock, where we share stories from company builders and business leaders. I'm Heather Mack, head of editorial at Greylock. This episode is the audio version of Greylock general partner Asheem Chandna's column in Forbes, which is entitled The Long Game in Cybersecurity. You can read this column on Forbes, and we have also republished it on the Greylock website under greylock.com/blog. You can find all of the Greymatter podcasts on SoundCloud, Spotify, YouTube, or wherever you get your podcasts.
The Long Game in Cybersecurity by Asheem Chandna. I have followed the evolution of cybersecurity for almost three decades. The one constant is that as quickly as the underlying technology advances, so too does a cyber threat. To understand how things might play out in the coming years, I spoke with four cybersecurity experts, each of whom breathe a different lens, a national security leader, a pioneer and technologist, a veteran CISO inside one of the most sophisticated technology companies, and a prominent cryptography professor, whose students will invariably shape the course of the field. They are unified on one point. Cybersecurity has never been more central and more complex. No one can afford to fall behind. The national Security Dilemma Richard A. Clark's experience in cybersecurity and counterterrorism stretches across three decades of service at the State Department, the Pentagon, and as a counselor to three US presidents. Today, he remains an indispensable advisor to countries and businesses on cyber risk and is one of the permanent thought leaders in the space. As a national security matter, Clark believes the US government is well organized for cyber defense, but persistently falls short of providing adequate funding. In a recent conversation with me, he suggested that most informal criminal hacking organizations around the world could probably be shut down by a combination of the NSA, CIA, FBI, and Cyber Command. But, he says, if only the US was willing to expand the resources at Nadevoz to counter cyber warfare. nation-state cyber terror is a different issue. He says, Iran, Russia, and China all have cyber vulnerability. But so do we. In the current conflict between Russia and Ukraine, he worries that every non-cyber move by the US., say, shutting down Russian access to the swift messaging system, could trigger a damaging retaliatory strike across US critical infrastructure. Clark says, the problem is that we don't know how to handle the escalation of cyber warfare between countries. New strategies need to be developed. He cites the 1965 seminal work by strategist Herman Kahn on escalation, which addressed how major powers could contain and manage the risk of nuclear conflict. We need a similar roadmap for managing escalation and cyber attacks, Clark says. Clark's concern for businesses is a repetition of the SolarWinds attack that went undetected for months. The biggest threat to most companies is a cyber attack that comes through the software supply chain, Clark says. That's what happened to SolarWinds. Today, every company gets a staggering number of software updates every month. Companies are vulnerable with no clear place to seek help. The US government would likely come to the aid of a major defense contractor hit by a cyber attack, Clark said. Large banks might also expect support, but other companies need more clarity about whether or when US government resources would be deployed to help them recover from an attack. The problem of cybersecurity complexity. Nir Zook, the legendary founder and CTO of Palo Alto Networks, remains frustrated by a fundamental truth of cybersecurity. Customers have no credible way of knowing whether the products they purchased actually work. Failures are only discovered after an attack has breached security. Zook believes this is one reason why cybersecurity conversations have moved up the ladder of the enterprise hierarchy, from engineers to the CISO to the CEO and the board. He sees growing awareness at all levels of business that simply buying the latest vendor solution is no longer a viable strategy. Enterprises must understand why cybersecurity is growing both more sophisticated and more difficult to manage. According to Zook, operationalizing cyber systems is the bottleneck. Customers can't keep up with the volume of information generated by cloud and machine learning technology. An alert about a potential breach might show the whole chain of the attack, stretching back into the architecture of the interconnected components in the cloud. It's very hard for any human to absorb and respond to all that information, Zook says. This dynamic makes automation of security crucial and inevitable. But Zook worries most vendors and companies will get it backwards. Rather than adding one more automated feature to human tools, he advocates thinking about automated security the way Tesla thinks about autonomous driving. First create the autonomous products, then add the human factor. Two threats concern him. First, ransomware continues to spread with impunity. No foolproof system exists against an attacker who only needs to be lucky enough to breach your system once. The best antidote, he argues, is to turn the tables by focusing on how to detect a breach once it has penetrated the system. That's when the attacker must hide 100% of the time. But he quickly concedes that a good backup and data protection plan may still be the best strategy. Supply chain attacks are the second major threat and are hard to prevent because the enterprise that is victimized is not the first target of the attack. Instead, hackers are going after the vendors in the supply chain, exactly what happened in the SolarWinds attack. The problems, Zuck believes, are knowable. The challenge is how companies will respond. The New Corporate Imperative Phil Venables was already an established and highly respected figure in cybersecurity when he joined Alphabet as Google Cloud CSO. He spent over two decades at Goldman Sachs as both CSO and cheap operational risk officer. When he looks at today's risk landscape, he sees many companies still thinking about cybersecurity the wrong way. Companies are rushing to invest in cyber software without modernizing their underlying technologies as Venables. They are effectively trying to build a fortress on sand. Venables argues the cloud should be viewed as a quote, digital immune system. He concedes this may sound self-interested for Google's cloud CSO, but his case is hard to refute. Writing recently in Forbes, he described the cloud's persistent ability to update, adapt and respond to shifting threats as quote, an accelerating feedback loop for enterprise IT leaders. In the coming years, both executives and corporate directors will need to become more sophisticated, Venables believes, not about the technology itself, but about how to build security into products and processes. Venables argues business leaders should be prepared to talk about the digital underpinning and security of a product just as knowledgeably as they would about supply chains or customer relationships. Think about secure products, not security products, he says. Venables proposes an exercise for a board. Instead of quizzing CEOs and their teams about patch updates or the latest security scanners, directors should simply ask how often the organization updates its software. Not long ago, IT teams boasted about quarterly updates. Venables says the leading edge companies are typically updating software multiple times a day or more. That's the reality of an agile approach to cybersecurity. The next frontier. Dan Bona is a leading professor in applied cryptography and the co-director of Stanford's Computer Security Lab. He enjoys a distinct advantage in the world of cybersecurity. He sees what new problems fascinate his students. Not surprisingly, they are gravitating to a set of problems around blockchain security. One involves a scalability of cryptocurrencies such as Bitcoin or Ethereum, which currently are restricted to conducting about 15 transactions a second. Yet as demand goes up, this limitation is causing transaction fees to rise. The research question is how to move far beyond the 15 transaction per second limit without compromising the integrity of the system. The other security issue with blockchain is privacy. While the virtual ledger offers efficiency and accountability for all types of enterprise transactions, the very nature of blockchain requires that the information can be viewed by others. This is a challenge for companies that want to pay suppliers or even employees through a blockchain system. Researchers are exploring how this can be done securely without compromising competitive or personal information. Bonnet and his students are also focused on a threat that he believes remains overlooked by most enterprises. Adversarial machine learning. For some time, engineers have been refining machine learning algorithms so that a robot or a vehicle can reliably recognize patterns, say defects in a progette or the difference between a stop sign and a yield sign. But Bonnet points out that a growing number of results show how to attack these models. Some are breaking into the training data algorithms that make machine learning possible. Others are extracting the model and effectively stealing it so those with malicious intent can query it for the purpose of infiltration.

2 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000551416868