|By Liz McMillan||
|November 15, 2012 12:00 PM EST||
With the common theme in today's security management conversations being "your security will fail" and "expect to be breached," there's no question that there has been increased interest in the area of incident response. The industry is realizing that the addition of regulations, people, or even product features, is not going to cut it - a next generation incident response offering is needed.
To get a view of what the next-generation incident response solution might look like, Web Security Journal sat down with entrepreneur and life-long incident response veteran, Joseph Loomis, a cooperative member with the FBI and DEA's divisions on Cybercrime and founder and CEO of Phoenix-based CyberSponse.
WSJ: Tell us a little bit about yourself - why does incident response interest you enough to start a company that appears to be all IR all the time?
Joseph Loomis: The desire to help people and businesses in need is in my bones. In fact, my experience with incident response goes all the way back to my childhood days when my father and his friends saw a gap in community protection and emergency "incident" response, and in turn created an entirely new fire department for our town. What I saw was that most people aren't aware that nearly every medical emergency - even if not fire related - is responded to by the fire department. My father and his friends came up with their own incident response program - they saw the need and made it a reality. They took the bull by the horns, figured it out, and worked on it until they got it right. Watching them, I repeatedly got to see how people responded during traumatic/chaotic events.
Like my father, I too served six years in the military, an experience that allowed me to help individuals, organizations, and countries alike. Shortly after completing my service with the armed forces and attending the University of Florida for Electrical Engineering, I was working for an electronics manufacturer in California. While working as the director of engineering, I saw the need for businesses to protect their assets in the online world. In response to this need, I founded NetEnforcers, a company chartered with protecting online brands and intellectual property. After successfully growing the company and securing customers like Apple, Microsoft, Cisco, Samsung, LG and Pfizer, I sold NetEnforcers, both debt-free and very profitable. Soon after, I began to look for the next area where I could help the world become a better place.
As a formally licensed Private Investigator and a cooperative member with the FBI & DEA's divisions on Cybercrime, I have been fortunate to connect with other entrepreneurs and security industry experts that share the same goals as I do. In 2011, I looked to Spyro Malaspinas, a proven, trusted, and innovative information security leader and a long time friend, to partner with me as a co-founder for CyberSponse - a Phoenix-based company chartered with helping organizations successfully respond to the inevitable security breach. Together Spyro and I developed the business case that would make CyberSponse a reality.
WSJ: What do you see as the biggest challenge faced by organizations with respect to security incident response?
Loomis: As you can imagine, my exposure to fire response, medical response, and military response presented me with far worse situations than a firewall breach. It's safe to say that these experiences taught me how to remain calm under pressure, to recognize how important planning is, and to appreciate how critical communication is during a crisis. Relating this back to cybersecurity, I find the biggest challenge in IR is having the right information available to the right people on the IR team at the right time, and being able to communicate and collaborate throughout the entire response process.
For example, most IR programs involve the use of panicky conference calls and drawn-out email communications, both of which seem to get in the way when something really serious is happening. If you haven't been through it, it may be hard for you to understand. But think about it for a minute - speed of communication is critical during an incident. Even if the right people are included in an email thread, if the critical person is not looking at their email program when it really matters, something can get missed. Similarly, oftentimes the IR leads don't have a clear view of who's doing what and when, regardless of the communication methods used.
WSJ: If you were to pick one big thing that has to change for IR, what would that be?
Loomis: Collaborative communication. The problem is that most IR personnel only know the email/conference call method to incident response. The improvement of standard IR methods needs to be the focus of organizations. In my mind, this is exactly where IR necessitates transformation. New methods of communication need to be leveraged; we need to move things from an ad-hoc model where organizations are forced to jump the tracks, to a cohesive experience that enables teams to communicate and collaborate. We could look to "The Computer Incident Response Planning Handbook" by Neal K McCarthy as a starting point for how to begin this transformation as it is a great source for what works during IR..
WSJ: What prompted you to tackle these challenges with your founding of CyberSponse?
Loomis: I know from first-hand experience that leadership, coordination, communication, planning, and collaboration are key elements to controlling a chaotic situation. Reaching out to old friends that were familiar with security, Spyro included, we decided to form CyberSponse. After digesting the business model and vetting it and the technology plans with some great contacts in the security world, I elected to personally invest over what will be 2M when we hit the market. Our founding management team has been developed through a close network of experienced and trusted friends and partners. And, rather than building an engineering team from the ground up, we looked to a development genius who already had an experienced and functional team, Paul Janisko. He quickly joined the march, and right from the start, we found ourselves with a solid plan, a solid team, and a solid solution to a problem that is not going away.
We are well positioned to succeed and intend to make CyberSponse a reality very soon, a reality that will change the face of IR forever, a reality that will seen by the world at the upcoming launch at RSA 2013 in San Francisco.
WSJ: How will CyberSponse shape the future of incident response?
Loomis: While our solution is far from simple to develop, simply put, CyberSponse is going to bring the efficiency, economics, transparency, and analytics that IR has needed for a long time. No more relying solely on ticketing systems, no more conference calls lasting 6 hours, no more meetings to have meetings. The CyberSponse solution has been tailored to handle the future of IR, designed specifically to streamline the use of a variety of technologies such as SMS, instant messaging, secure document collaboration, and mobile (to name a few). One example I can share pre-launch is that the CyberSponse system will offer built-in tools and training which will help teams become more prepared for a breach when it occurs. Also, by partnering with cutting edge providers like FireHost, Carbon Black, and Blackhills InfoSec, CyberSponse is going to put the power of IR back in the hands of the IR team in a way they've never experienced before, giving them the ability to respond with confidence from wherever they are.
WSJ: What does the future hold for CyberSponse?
Loomis: Legacy technologies like email and ticketing systems are holding the IR teams back, forcing them to operate outside even the best laid out IR plans. In fact, best practices such as NIST SP800-61 and ISO-27035 call for organizations to stay out of email when an incident occurs - not use it as the main tool for communication. With several patents pending, this is the future for CyberSponse - we will bring the IR teams up to date with a next generation IR solution so they can actually follow industry standards, guidelines, regulations, and more - while becoming more effective and efficient in their IR programs while doing so. CyberSponse will provide the perfect solution for companies small and large, leveraging a cyber-response community we help build where companies help each other fight cyber-crime and respond to cyber-attacks.
One final thought that I would add with respect to standards and regulations is the IR audit trail. CyberSponse, effectively operating as a secure bunker for all IR activities, will keep track of everything IR related and keep it secure within the bunker. Organizations will be able to see and report on what Resource A did and what Resource B forgot to do - even if one of those resources is an external service provider bound to an IR SLA. This will be an auditors dream - and will help the organization improve upon future IR activities.
Cloud computing is unquestionably one of the driving forces of DevOps, as the automation of operations transforms enterprise software development. DevOps, however, is more than a technology trend, as it represents a move toward silo-busting, self-organizing horizontal teams that drive business velocity. At the same time, enterprise Digital Transformation represents an upheaval across the enterprise, as customer preferences and behavior drive enterprise technology decisions. This transformation ...
Dec. 1, 2015 12:35 PM EST
SYS-CON Events announced today that Catchpoint, a global leader in monitoring, and testing the performance of online applications, has been named "Silver Sponsor" of DevOps Summit New York, which will take place on June 7-9, 2016 at the Javits Center in New York City. Catchpoint radically transforms the way businesses manage, monitor, and test the performance of online applications. Truly understand and improve user experience with clear visibility into complex, distributed online systems.Founde...
Dec. 1, 2015 12:15 PM EST
The annual holiday shopping season, which started on Thanksgiving weekend and runs through the end of December, is undoubtedly the most crucial time of the year for many eCommerce websites, with sales from this period having a dramatic effect on the year-end bottom line. Web performance – or, the overall speed and availability of a website or mobile site – is an issue year-round, but it takes on increased importance during the holidays. Ironically, it is at this time of year that networks and i...
Dec. 1, 2015 11:15 AM EST Reads: 164
Most of the IoT Gateway scenarios involve collecting data from machines/processing and pushing data upstream to cloud for further analytics. The gateway hardware varies from Raspberry Pi to Industrial PCs. The document states the process of allowing deploying polyglot data pipelining software with the clear notion of supporting immutability. In his session at @ThingsExpo, Shashank Jain, a development architect for SAP Labs, discussed the objective, which is to automate the IoT deployment proces...
Dec. 1, 2015 11:00 AM EST Reads: 138
Countless business models have spawned from the IaaS industry – resell Web hosting, blogs, public cloud, and on and on. With the overwhelming amount of tools available to us, it's sometimes easy to overlook that many of them are just new skins of resources we've had for a long time. In his general session at 17th Cloud Expo, Harold Hannon, Sr. Software Architect at SoftLayer, an IBM Company, broke down what we have to work with, discussed the benefits and pitfalls and how we can best use them ...
Dec. 1, 2015 10:45 AM EST Reads: 131
Discussions of cloud computing have evolved in recent years from a focus on specific types of cloud, to a world of hybrid cloud, and to a world dominated by the APIs that make today's multi-cloud environments and hybrid clouds possible. In this Power Panel at 17th Cloud Expo, moderated by Conference Chair Roger Strukhoff, panelists addressed the importance of customers being able to use the specific technologies they need, through environments and ecosystems that expose their APIs to make true ...
Dec. 1, 2015 10:00 AM EST Reads: 577
It's been a busy time for tech's ongoing infatuation with containers. Amazon just announced EC2 Container Registry to simply container management. The new Azure container service taps into Microsoft's partnership with Docker and Mesosphere. You know when there's a standard for containers on the table there's money on the table, too. Everyone is talking containers because they reduce a ton of development-related challenges and make it much easier to move across production and testing environm...
Dec. 1, 2015 10:00 AM EST Reads: 658
DevOps is an organizational and cultural rethink of how software-driven organizations can become organizations at velocity – agile enough to innovate and fast enough to deal with any change that comes their way. Information technology is a central enabler of DevOps, but today’s better-faster-cheaper technology is not the whole story, as tools are only as good as the people wielding them. The more fundamental story here is the organizational and cultural transformation necessary to take full adv...
Dec. 1, 2015 10:00 AM EST
ThoughtWorks has issued the latest Technology Radar, an assessment of trends significantly impacting software development and business strategy. The Technology Radar sets out the current changes in software development - things in motion to pay attention to based upon ThoughtWorks' day-to-day work and experience solving their clients' toughest challenges. "With the threat landscape still evolving, our latest edition of Technology Radar continues to focus on security and innovative approaches,...
Dec. 1, 2015 09:45 AM EST
Microservices are a very exciting architectural approach that many organizations are looking to as a way to accelerate innovation. Microservices promise to allow teams to move away from monolithic "ball of mud" systems, but the reality is that, in the vast majority of organizations, different projects and technologies will continue to be developed at different speeds. How to handle the dependencies between these disparate systems with different iteration cycles? Consider the "canoncial problem"...
Dec. 1, 2015 09:00 AM EST Reads: 482
The Internet of Things is clearly many things: data collection and analytics, wearables, Smart Grids and Smart Cities, the Industrial Internet, and more. Cool platforms like Arduino, Raspberry Pi, Intel's Galileo and Edison, and a diverse world of sensors are making the IoT a great toy box for developers in all these areas. In this Power Panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists discussed what things are the most important, which will have the most profound...
Dec. 1, 2015 06:30 AM EST Reads: 515
As organizations shift towards IT-as-a-service models, the need for managing & protecting data residing across physical, virtual, and now cloud environments grows with it. CommVault can ensure protection & E-Discovery of your data - whether in a private cloud, a Service Provider delivered public cloud, or a hybrid cloud environment – across the heterogeneous enterprise.
Dec. 1, 2015 06:00 AM EST Reads: 273
Growth hacking is common for startups to make unheard-of progress in building their business. Career Hacks can help Geek Girls and those who support them (yes, that's you too, Dad!) to excel in this typically male-dominated world. Get ready to learn the facts: Is there a bias against women in the tech / developer communities? Why are women 50% of the workforce, but hold only 24% of the STEM or IT positions? Some beginnings of what to do about it! In her Day 2 Keynote at 17th Cloud Expo, San...
Dec. 1, 2015 05:00 AM EST Reads: 622
PubNub has announced the release of BLOCKS, a set of customizable microservices that give developers a simple way to add code and deploy features for realtime apps.PubNub BLOCKS executes business logic directly on the data streaming through PubNub’s network without splitting it off to an intermediary server controlled by the customer. This revolutionary approach streamlines app development, reduces endpoint-to-endpoint latency, and allows apps to better leverage the enormous scalability of PubNu...
Dec. 1, 2015 05:00 AM EST Reads: 361
In today's enterprise, digital transformation represents organizational change even more so than technology change, as customer preferences and behavior drive end-to-end transformation across lines of business as well as IT. To capitalize on the ubiquitous disruption driving this transformation, companies must be able to innovate at an increasingly rapid pace. Traditional approaches for driving innovation are now woefully inadequate for keeping up with the breadth of disruption and change facin...
Dec. 1, 2015 03:30 AM EST Reads: 533
I recently attended and was a speaker at the 4th International Internet of @ThingsExpo at the Santa Clara Convention Center. I also had the opportunity to attend this event last year and I wrote a blog from that show talking about how the “Enterprise Impact of IoT” was a key theme of last year’s show. I was curious to see if the same theme would still resonate 365 days later and what, if any, changes I would see in the content presented.
Dec. 1, 2015 03:00 AM EST Reads: 470
You may have heard about the pets vs. cattle discussion – a reference to the way application servers are deployed in the cloud native world. If an application server goes down it can simply be dropped from the mix and a new server added in its place. The practice so far has mostly been applied to application deployments. Management software on the other hand is treated in a very special manner. Dedicated resources are set aside to run the management software components and several alerting syst...
Dec. 1, 2015 02:00 AM EST Reads: 254
Culture is the most important ingredient of DevOps. The challenge for most organizations is defining and communicating a vision of beneficial DevOps culture for their organizations, and then facilitating the changes needed to achieve that. Often this comes down to an ability to provide true leadership. As a CIO, are your direct reports IT managers or are they IT leaders? The hard truth is that many IT managers have risen through the ranks based on their technical skills, not their leadership ab...
Dec. 1, 2015 01:00 AM EST Reads: 437
Naturally, new and exciting technologies and trends like software defined networking, the Internet of Things and the cloud tend to get the lion’s share of attention these days, including when it comes to security. However, it’s important to never forget that at the center of it all is still the enterprise network. And as evidenced by the ever-expanding landslide of data breaches that could have been prevented or at least their impact lessened by better practicing network security basics, it’s ...
Dec. 1, 2015 12:45 AM EST Reads: 302
Put the word continuous in front of many things and we help define DevOps: continuous delivery, continuous testing, continuous assessment, and there is more. The next BriefingsDirect DevOps thought leadership discussion explores the concept of continuous processes around the development and deployment of applications and systems. Put the word continuous in front of many things and we help define DevOps: continuous delivery, continuous testing, continuous assessment, and there is more.
Dec. 1, 2015 12:30 AM EST Reads: 195