Welcome!

Microservices Expo Authors: Ruxit Blog, Liz McMillan, Sematext Blog, Elizabeth White, Lori MacVittie

Related Topics: Cloud Security, Java IoT, Industrial IoT, Microservices Expo, Agile Computing, Release Management

Cloud Security: Article

What Is the Future of Security Incident Response?

An interview with CyberSponse CEO Joseph Loomis

With the common theme in today's security management conversations being "your security will fail" and "expect to be breached," there's no question that there has been increased interest in the area of incident response. The industry is realizing that the addition of regulations, people, or even product features, is not going to cut it - a next generation incident response offering is needed.

To get a view of what the next-generation incident response solution might look like, Web Security Journal sat down with entrepreneur and life-long incident response veteran, Joseph Loomis, a cooperative member with the FBI and DEA's divisions on Cybercrime and founder and CEO of Phoenix-based CyberSponse.

WSJ: Tell us a little bit about yourself - why does incident response interest you enough to start a company that appears to be all IR all the time?

Joseph Loomis: The desire to help people and businesses in need is in my bones. In fact, my experience with incident response goes all the way back to my childhood days when my father and his friends saw a gap in community protection and emergency "incident" response, and in turn created an entirely new fire department for our town. What I saw was that most people aren't aware that nearly every medical emergency - even if not fire related - is responded to by the fire department. My father and his friends came up with their own incident response program - they saw the need and made it a reality. They took the bull by the horns, figured it out, and worked on it until they got it right. Watching them, I repeatedly got to see how people responded during traumatic/chaotic events.

Like my father, I too served six years in the military, an experience that allowed me to help individuals, organizations, and countries alike. Shortly after completing my service with the armed forces and attending the University of Florida for Electrical Engineering, I was working for an electronics manufacturer in California. While working as the director of engineering, I saw the need for businesses to protect their assets in the online world. In response to this need, I founded NetEnforcers, a company chartered with protecting online brands and intellectual property. After successfully growing the company and securing customers like Apple, Microsoft, Cisco, Samsung, LG and Pfizer, I sold NetEnforcers, both debt-free and very profitable. Soon after, I began to look for the next area where I could help the world become a better place.

As a formally licensed Private Investigator and a cooperative member with the FBI & DEA's divisions on Cybercrime, I have been fortunate to connect with other entrepreneurs and security industry experts that share the same goals as I do. In 2011, I looked to Spyro Malaspinas, a proven, trusted, and innovative information security leader and a long time friend, to partner with me as a co-founder for CyberSponse - a Phoenix-based company chartered with helping organizations successfully respond to the inevitable security breach. Together Spyro and I developed the business case that would make CyberSponse a reality.

WSJ: What do you see as the biggest challenge faced by organizations with respect to security incident response?

Loomis: As you can imagine, my exposure to fire response, medical response, and military response presented me with far worse situations than a firewall breach. It's safe to say that these experiences taught me how to remain calm under pressure, to recognize how important planning is, and to appreciate how critical communication is during a crisis. Relating this back to cybersecurity, I find the biggest challenge in IR is having the right information available to the right people on the IR team at the right time, and being able to communicate and collaborate throughout the entire response process.

For example, most IR programs involve the use of panicky conference calls and drawn-out email communications, both of which seem to get in the way when something really serious is happening. If you haven't been through it, it may be hard for you to understand. But think about it for a minute - speed of communication is critical during an incident. Even if the right people are included in an email thread, if the critical person is not looking at their email program when it really matters, something can get missed. Similarly, oftentimes the IR leads don't have a clear view of who's doing what and when, regardless of the communication methods used.

WSJ: If you were to pick one big thing that has to change for IR, what would that be?

Loomis: Collaborative communication. The problem is that most IR personnel only know the email/conference call method to incident response. The improvement of standard IR methods needs to be the focus of organizations. In my mind, this is exactly where IR necessitates transformation. New methods of communication need to be leveraged; we need to move things from an ad-hoc model where organizations are forced to jump the tracks, to a cohesive experience that enables teams to communicate and collaborate. We could look to "The Computer Incident Response Planning Handbook" by Neal K McCarthy as a starting point for how to begin this transformation as it is a great source for what works during IR..

WSJ: What prompted you to tackle these challenges with your founding of CyberSponse?

Loomis: I know from first-hand experience that leadership, coordination, communication, planning, and collaboration are key elements to controlling a chaotic situation. Reaching out to old friends that were familiar with security, Spyro included, we decided to form CyberSponse. After digesting the business model and vetting it and the technology plans with some great contacts in the security world, I elected to personally invest over what will be 2M when we hit the market. Our founding management team has been developed through a close network of experienced and trusted friends and partners. And, rather than building an engineering team from the ground up, we looked to a development genius who already had an experienced and functional team, Paul Janisko. He quickly joined the march, and right from the start, we found ourselves with a solid plan, a solid team, and a solid solution to a problem that is not going away.

We are well positioned to succeed and intend to make CyberSponse a reality very soon, a reality that will change the face of IR forever, a reality that will seen by the world at the upcoming launch at RSA 2013 in San Francisco.

WSJ: How will CyberSponse shape the future of incident response?

Loomis: While our solution is far from simple to develop, simply put, CyberSponse is going to bring the efficiency, economics, transparency, and analytics that IR has needed for a long time. No more relying solely on ticketing systems, no more conference calls lasting 6 hours, no more meetings to have meetings. The CyberSponse solution has been tailored to handle the future of IR, designed specifically to streamline the use of a variety of technologies such as SMS, instant messaging, secure document collaboration, and mobile (to name a few). One example I can share pre-launch is that the CyberSponse system will offer built-in tools and training which will help teams become more prepared for a breach when it occurs. Also, by partnering with cutting edge providers like FireHost, Carbon Black, and Blackhills InfoSec, CyberSponse is going to put the power of IR back in the hands of the IR team in a way they've never experienced before, giving them the ability to respond with confidence from wherever they are.

WSJ: What does the future hold for CyberSponse?

Loomis: Legacy technologies like email and ticketing systems are holding the IR teams back, forcing them to operate outside even the best laid out IR plans. In fact, best practices such as NIST SP800-61 and ISO-27035 call for organizations to stay out of email when an incident occurs - not use it as the main tool for communication. With several patents pending, this is the future for CyberSponse - we will bring the IR teams up to date with a next generation IR solution so they can actually follow industry standards, guidelines, regulations, and more - while becoming more effective and efficient in their IR programs while doing so. CyberSponse will provide the perfect solution for companies small and large, leveraging a cyber-response community we help build where companies help each other fight cyber-crime and respond to cyber-attacks.

One final thought that I would add with respect to standards and regulations is the IR audit trail. CyberSponse, effectively operating as a secure bunker for all IR activities, will keep track of everything IR related and keep it secure within the bunker. Organizations will be able to see and report on what Resource A did and what Resource B forgot to do - even if one of those resources is an external service provider bound to an IR SLA. This will be an auditors dream - and will help the organization improve upon future IR activities.

More Stories By Liz McMillan

News Desk compiles and publishes breaking news stories, press releases and latest news articles as they happen.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@MicroservicesExpo Stories
This is a no-hype, pragmatic post about why I think you should consider architecting your next project the way SOA and/or microservices suggest. No matter if it’s a greenfield approach or if you’re in dire need of refactoring. Please note: considering still keeps open the option of not taking that approach. After reading this, you will have a better idea about whether building multiple small components instead of a single, large component makes sense for your project. This post assumes that you...
This complete kit provides a proven process and customizable documents that will help you evaluate rapid application delivery platforms and select the ideal partner for building mobile and web apps for your organization.
Monitoring of Docker environments is challenging. Why? Because each container typically runs a single process, has its own environment, utilizes virtual networks, or has various methods of managing storage. Traditional monitoring solutions take metrics from each server and applications they run. These servers and applications running on them are typically very static, with very long uptimes. Docker deployments are different: a set of containers may run many applications, all sharing the resource...
With so much going on in this space you could be forgiven for thinking you were always working with yesterday’s technologies. So much change, so quickly. What do you do if you have to build a solution from the ground up that is expected to live in the field for at least 5-10 years? This is the challenge we faced when we looked to refresh our existing 10-year-old custom hardware stack to measure the fullness of trash cans and compactors.
The emerging Internet of Everything creates tremendous new opportunities for customer engagement and business model innovation. However, enterprises must overcome a number of critical challenges to bring these new solutions to market. In his session at @ThingsExpo, Michael Martin, CTO/CIO at nfrastructure, outlined these key challenges and recommended approaches for overcoming them to achieve speed and agility in the design, development and implementation of Internet of Everything solutions wi...
Node.js and io.js are increasingly being used to run JavaScript on the server side for many types of applications, such as websites, real-time messaging and controllers for small devices with limited resources. For DevOps it is crucial to monitor the whole application stack and Node.js is rapidly becoming an important part of the stack in many organizations. Sematext has historically had a strong support for monitoring big data applications such as Elastic (aka Elasticsearch), Cassandra, Solr, S...
There's a lot of things we do to improve the performance of web and mobile applications. We use caching. We use compression. We offload security (SSL and TLS) to a proxy with greater compute capacity. We apply image optimization and minification to content. We do all that because performance is king. Failure to perform can be, for many businesses, equivalent to an outage with increased abandonment rates and angry customers taking to the Internet to express their extreme displeasure.
SYS-CON Events announced today that 910Telecom will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Housed in the classic Denver Gas & Electric Building, 910 15th St., 910Telecom is a carrier-neutral telecom hotel located in the heart of Denver. Adjacent to CenturyLink, AT&T, and Denver Main, 910Telecom offers connectivity to all major carriers, Internet service providers, Internet backbones and ...
Before becoming a developer, I was in the high school band. I played several brass instruments - including French horn and cornet - as well as keyboards in the jazz stage band. A musician and a nerd, what can I say? I even dabbled in writing music for the band. Okay, mostly I wrote arrangements of pop music, so the band could keep the crowd entertained during Friday night football games. What struck me then was that, to write parts for all the instruments - brass, woodwind, percussion, even k...
Right off the bat, Newman advises that we should "think of microservices as a specific approach for SOA in the same way that XP or Scrum are specific approaches for Agile Software development". These analogies are very interesting because my expectation was that microservices is a pattern. So I might infer that microservices is a set of process techniques as opposed to an architectural approach. Yet in the book, Newman clearly includes some elements of concept model and architecture as well as p...
DevOps at Cloud Expo – being held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real results. Am...

Modern organizations face great challenges as they embrace innovation and integrate new tools and services. They begin to mature and move away from the complacency of maintaining traditional technologies and systems that only solve individual, siloed problems and work “well enough.” In order to build...

The post Gearing up for Digital Transformation appeared first on Aug. 30, 2016 05:45 PM EDT  Reads: 1,720

Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 19th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devices - comp...
Thomas Bitman of Gartner wrote a blog post last year about why OpenStack projects fail. In that article, he outlined three particular metrics which together cause 60% of OpenStack projects to fall short of expectations: Wrong people (31% of failures): a successful cloud needs commitment both from the operations team as well as from "anchor" tenants. Wrong processes (19% of failures): a successful cloud automates across silos in the software development lifecycle, not just within silos.
19th Cloud Expo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterpri...
As the world moves toward more DevOps and Microservices, application deployment to the cloud ought to become a lot simpler. The Microservices architecture, which is the basis of many new age distributed systems such as OpenStack, NetFlix and so on, is at the heart of Cloud Foundry - a complete developer-oriented Platform as a Service (PaaS) that is IaaS agnostic and supports vCloud, OpenStack and AWS. Serverless computing is revolutionizing computing. In his session at 19th Cloud Expo, Raghav...
SYS-CON Events announced today that eCube Systems, a leading provider of middleware modernization, integration, and management solutions, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. eCube Systems offers a family of middleware evolution products and services that maximize return on technology investment by leveraging existing technical equity to meet evolving business needs. ...

Let's just nip the conflation of these terms in the bud, shall we?

"MIcro" is big these days. Both microservices and microsegmentation are having and will continue to have an impact on data center architecture, but not necessarily for the same reasons. There's a growing trend in which folks - particularly those with a network background - conflate the two and use them to mean the same thing.

They are not.

One is about the application. The other, the network. T...

The following fictional case study is a composite of actual horror stories I’ve heard over the years. Unfortunately, this scenario often occurs when in-house integration teams take on the complexities of DevOps and ALM integration with an enterprise service bus (ESB) or custom integration. It is written from the perspective of an enterprise architect tasked with leading an organization’s effort to adopt Agile to become more competitive. The company has turned to Scaled Agile Framework (SAFe) as ...
If you are within a stones throw of the DevOps marketplace you have undoubtably noticed the growing trend in Microservices. Whether you have been staying up to date with the latest articles and blogs or you just read the definition for the first time, these 5 Microservices Resources You Need In Your Life will guide you through the ins and outs of Microservices in today’s world.