SAN FRANCISCO — Before moving on to the “real” questions, there’s Wendy Nather’s title: head of advisory CISOs at Duo Security, which Cisco now owns. What does that mean?
Nather laughs. “I knew that was going to be the first question — what exactly do you do here? We kind of made this up when I came over to Duo as a former CISO,” she explained. “What I do is I bring the perspective of the CISO to the benefit of people both inside and outside the company.”
When Cisco acquired Duo, Nather’s was the only such CISO advisory team. But the larger company quickly saw the value and has since created a Cisco-wide CISO advisory program.
After working as a chief information security officer (CISO) in the private and public sector — Nather led the IT security for Europe, the Middle East, and Africa in the investment banking division of Swiss Bank Corporation (now UBS), and served as CISO of the Texas Education Agency — Nather brings a unique perspective to the vendor.
Internally, she and the rest of her five-person team help Cisco design security products and develop roadmaps. “This is what a CISO would expect to see from this product, or this is how we would react to this marketing message, or these are some of the issues that CISOs are interested in,” she said. She also advises the sales teams: “Never say this to a CISO.”
What’s one of those things?
“One of the things that I used to find so annoying is when a salesperson would come in and assume that I needed to be educated about what threats there are,” Nather said. “Like, dude, you come over here and try doing my job, OK? Don’t assume that I need to be educated.”
Also in this role she can voice concerns that current CISOs can’t. “Nobody can get up on a stage as a current CISO and say, hey, patching is hard, because that’s asking for trouble, isn’t it? But somebody has to say it,” Nather said. “So that’s another thing that we try to do is surface the important issues that CISOs can’t say for themselves.”
CISO’s Job: Trying to Make Something Float in the Open OceanThe biggest challenge facing CISOs is not understanding security. “They know what they need to do,” she said. But rather, figuring out how to apply security to the business.
“Most security solutions are designed to fit just one generic type of enterprise,” she explained. “It’s kind of like they are designed assuming everybody has an Olympic-sized swimming pool. But the reality is that every CISO is out on the open ocean. And they’re all different oceans. The Caribbean is very different from the Indian Ocean, and the circumstances are all different. So the biggest challenge that the CISO has is trying to take these theoretical, thought-out solutions and actually apply them in a real and messy environment with culture differences, technological constraints, all sorts of things that make it difficult for them to just put something in.”
Security researchers prefer to talk about new attack methods and the hot new technologies that can stop these attacks. But CISOs are the ones “trying to make something float in the open ocean,” Nather said. “Researchers who have never tried this are going, ‘Are they still working on that floaty?’ But they don’t understand how hard it is.”
Nather detailed another challenge facing the security industry in her RSA Conference keynote “We the People: Democratizing Security.” It’s definitely worth watching the video, but the basic idea is that vendors are building security based on an outdated model. Instead of thinking of the end users as the weakest link, security should be designed with users in mind.
Rethinking Security DesignRethinking how we design security can also help address the high levels of CISO burnout, she said in an interview after her keynote. In fact, another key practice that Duo brought over to Cisco security in the acquisition is hiring one designer for every five security engineers, which Nather said is a really high ratio for the industry.
“Maybe the reason we are so stressed is that we are asking the wrong questions, or making the wrong assumptions,” she said. “If we are expecting the wrong things of our users, if we are saying look, these rocks are just not flying. We’ve been yelling at them and educating them for 20 years. We’re tried kicking them, we’ve tried throwing them, and they are not flying. I’m so burned out trying to get these rocks to fly. Then maybe there’s something wrong with us, and we need to change. If security is hard, maybe it’s because we made it hard. And we need to rethink and reinvent how we do security.”
This means models like touch ID instead of passcode security on phones, and even passwordless authentication, which is something Duo demoed at the Cisco RSA booth.
A few years ago Nather predicted a security-user revolution in which company employees revolt against the security gods blaming the users for breaches and mistakes. “And I think we’re now really seeing that, particularly with the passwordless movement,” she said. “Everybody is calling for the death of the password. And the enthusiasm with which enterprises are embracing that indicates to me that yes, users are tired. They want something different. And passwordless is probably just the beginning.”
Comments