Go back

Stories from an Expert Threat Hunter with Taz Wake

43m 33s

Stories from an Expert Threat Hunter with Taz Wake

The transcript introduces the podcast "Cyber Leaders," hosted by Kieran Martin and James Line from the SANS Institute, which aims to equip CISOs and security leaders with knowledge to secure their organizations and combat cyber criminals. The episode features guest Taz, who began his career in the British military in 1993, working in intelligence, electronic warfare, and signals intelligence. He transitioned to cybersecurity in 2010, founding his own company and taking on roles such as leading incident response and CSIRT functions at Unilever. Taz is also a SANS instructor and author of pivotal courses on incident response and threat hunting. He reflects on his journey from military security to civilian cyber defense, noting the evolution of threats from early computer security to modern challenges like Stuxnet. Taz emphasizes his passion for incident response, highlighting its direct human impact—such as stopping a fraudulent bank transfer and saving an individual’s life savings. He outlines key traits for effective incident responders: deep technical adaptability to handle diverse systems, strong communication skills to bridge technical and non-technical stakeholders, and a focus on practical outcomes. The discussion underscores the value of community and trust in cybersecurity, with Taz’s experience illustrating how proactive defense can make cyber criminals' lives difficult.

Transcription

9171 Words, 50605 Characters

English
Welcome to Cyber Leaders With Me, Kieran Martin, and Me, James Line. Now we're both from the Sands Institute who are kindly backing this podcast. I myself, Mateki, a massive geek who spent my life chasing cyber criminals around the internet. Less of a techie, I dealt with cybersecurity operations in policy and government and set up the UK's National Cybersecurity Center. But together, James and I are trying to unpack the weird, wacky, wired, and wireless world of tech security and all the complications it involves. That's right, Kieran. This podcast is a voice for security leaders. We want CISOs, security directors, and frankly everyone beyond to build up their knowledge of what works, what doesn't, and ultimately secure their organisations more comprehensively and quickly. One, frankly, ideally makes some cyber criminals miserable too. Well, first of all, James, good start to an audio podcast, nice haircut. Very aerodynamic. Yes, you look like a thug. In fact, you look like a baddie. You look like a criminal. And I mean, a physical one, not a cyber one. A bit of cyber roleplay. Yes. Now, let's go back to baddies. Let's talk about some baddies. So I'm going to take you back to something you said at the start there. Oh, so you were listing this time, Kieran. That may be a first. I hang off your every word, my friend. All of them. Even the ones I don't understand when you like to talk about computers and hacking and stuff. I listen then, too. And which particular bit, or bite, did you want to haul me up on today, Kieran? I'm getting paranoid. I feel like I've made an error. I have to watch my words, or double words more carefully. There was a lot of data size puns in there. It was. But I want to talk about baddies today. So in that wonderfully spontaneous, yet repetitive introduction that we both do, we all just talk about chasing baddies around the internet. And you've come today in character. You've come looking like one. Well, yes. I would get inside their heads, based on, I've spent the last 20 or 20 years of my career chasing cyber criminals and their exploits and malware and frankly trying to make their lives difficult. Well then, let's go back to data how many baddies have you chased? Well, it's hard to think, but it's a lot. I could probably more easily name the ones we've managed to deal with with law enforcement. But where are you going with this, Kieran? Are you trying to create a chasing baddies league table? That's exactly what I'm trying to do as a matter of fact, James. Yes. Can I ask why? Well, I'm not really trying to create a baddies league table. I'm just trying to work out whether you've spent more time chasing baddies than our guest. Because we've someone today who spent more time in what I would call the front line of cyber defense and pretty much anyone I know except perhaps maybe you're good self. With someone joining us today who's seen it all and done it off of a whole range of different perspectives and jobs. Indeed we do, I frankly would be quite happy to be beaten in the baddies chasing league tables by this individual. We have a guest today, folks, who started his career in the military, who's in intelligence, working on human intelligence operations, counterintelligence and in electronic warfare, obviously very closely related to cyber security and more so every day. Now without getting too much into his age, he was in uniform at the time when the military started to worry about what we now call cyber security and started to specialize in that. Leaving the service in 2010, he found his own company, which he still has, specializing in incident response, risk assessments, compliance and training. But he's done way more than that. He's built socks and threatening teams at various major organizations. He's a sands instructor and a faculty member of the Sands Technology Institute. He led incident response and C-Sert functions at Unilever, a massive organization. I can only imagine the challenges there. And he is the author of two pivotally important sands courses on incident response and threat hunting, which means he's had thousands of students go through his classes learning these key concepts. And while supporting that general theme of trying to make life difficult for the cyber criminals, Karen, we're going to have to figure out if he gets credit for all those students by proxy, because if so, he's definitely got me beaten. I think that might be the case, but let's figure it out. There's some kind of tree there, isn't there? But anyway, look, on the more friendly side, he's got an entire barnyard full of animals, which we'll have to ask him about. So my powers of deduction tell me he basically never sleeps. And he's going to talk to us about a whole lot. And Karen, we're going to struggle to contain our lines of question in the length of the podcast as usual as normal. Yeah. So it is, of course, based on that introduction, you probably have it from the barnyard full of animals, the truly remarkable task wake. Welcome, Taz. Hi, everyone. Hi, James. Hi, Karen. It's absolutely pleasure to be here. And that was an incredible introduction. I am honored. Well, it's fully deserved. And I think fitting with your background and the mystique around everything you've done, James is looking like a thug with a short hair and you're off camera. So this is good because I'm going to start with a question we ask everybody about your journey into cyber, but I'm really looking forward to your answer. There's as many different dancers as there are guests. So you join the military in intelligence work. This is a pretty scary time. The beginnings of a pretty scary time that we're still in. The world starts to go on fire at the start of the century. And you emerged from this period when you come out of service in 2010 and you're ready to take on the world of cyber thugs and thieves in the private sector. So clearly, you didn't go into the military in cyber, but you came out of it ready to go. So I'm guessing you're not going to be able to tell us everything about your early career and what led you to pivot to cyber. Some of that will probably be classified. So here's two options for you. One is you can tell me and James everything. Let's go through all the classified operations, all the really cool stuff. And then we'll edit it out. It'll be like one of those government document releases you see where it's mostly black ink blotched over the words. And our listens can just listen to that or maybe something less hype it's maybe just the sign of silence. So that's option one. Option two is you can tell us whatever you can about your early life from career and height. You ended up fighting digital baddies having started off fighting physical ones in the military. Your choice. I say, I'll absolutely go with option two there. OK, the 35 minutes of silence isn't exactly a selling point. But no, so as you described it, I joined you. I mean, I actually enlisted in 1993. Wow. I started off as what we referred to at the time as an operator, special intelligence. And that meant you go through a variety of different jobs at the end of base of training and I was specialized in electronic warfare, signals intelligence, that kind of thing. Postings to Germany, really, really interesting jobs. There's a whole range of things. The cold was over at this stage, but not quite. We still had occasional threats, Middle East, Africa, places like that. Throughout the 16 years, we changed jobs in the army or certainly my trade in the army. We changed jobs every two years, which meant I had the opportunity to bounce around a whole raft of things, lots of succumbents to other government agencies. I spent a bit of time working in tricevice organizations, a bit of exchange trips with the US, which was quite fascinating. But a lot of it revolved around the terms intelligence and security. So we kind of look at it as a double-crowned effort. We're attempting to, similar as we talk about cybersecurity today, as an intelligence operator, I'm attempting to gather information from the enemy and as a security operator, I'm attempting to prevent the enemy gathering it for more. And that was kind of the big blow. Interestingly enough, in 1993, I was actually sent on a computer security officer's course, which was kind of the first step into what we'd call cybersecurity today. Someone was ahead of the time? Yeah, it was very different to how you'd look at things today. That's probably the easiest way to describe it. It was very much, we probably felt it was auditing today. There was a lot more into just making sure the processes were followed, making sure the passwords were rotated. That kind of thing, there was less focus on the more direct technical cybersecurity we'd expect in the year 2026. Well, that did evolve, absolutely. It evolved quite a bit until my last posting with the enemy I was done as a convent to a government agency. And I've kind of reached the point where I thought I've had enough, I've done some really interesting things. There are many more new interesting things ahead of me and that's the point which I decided to leave. And basically because of a lot of background protecting organisations, that kind of thing. Yeah. Some very interesting investigations. A lot of the way I could talk about sadly. No. But if anyone ever wants to get down and see what I've got, some incredible stories that I can try and declassify a little bit. I will bet you do. Yeah, that was kind of the point which I thought when I left. I was very fortunate. I formed my own company and the biggest advantage I had really was having lots of friends and contacts in the industry. So we've been managed to be successful and here we are 16 years later still doing cybersecurity. Love to see it. And of course, oh, how things have changed as well, Tas. Absolutely. I was thinking back to those days you're describing and of course the roles have changed, but the nature of the problem, the scale and the problem, the use of technology. I mean, it's just been a whirlwind. When you were there during that period towards the end of it, you know, there's still a very unstable world and so forth. How much were the military thinking about cyber and so forth at the point of your departure? And you get any sense that if you're still in touch with people, you know, how much is all this change now given that quite a lot of all the things going on in traditional military circles? Yeah. Where is it all at now? So, certainly by the time I left, the army had very much pivoted. We'd gone from the early 90s of a computer security office, so we had an information security unit in the intelligence call. At a very skill, they do a lot of science training as a prime example around that. So, the head rain, which that kind of happened in the early 2000s, I think when Stuxnet hit the news in 2009, that kind of made everyone really aware of the additional levels. Yeah. And you might remember about like 2007 when we had the fears about supply chain attacks and we could no longer talk about we've strict the information over the telephone network. Yeah. That kind of thing. They were the mindsets that people were very much going into. Yeah. I think it's quite modern. Really, it's a world like James said. It's night and day difference to when I started. Yeah. And the technical details will have enhanced today. I know the army still has a very strong dedicated cybersecurity capability. The technical details will have improved, but I think that real mindset approach probably changed in the early 2000s. Stay with us. We'll be right back. Hi, everyone. James Line here, the CEO of the Sands Institute. A quick thought for you. Cyber criminals have networks, dark web forums where they share what works, what and where they call. constantly sharpening their playbooks against us. So why shouldn't we do the same? That's exactly what the Sands Cyber Leaders Network is about. It's a place where CISOs and security leaders share what's actually working inside their organizations and what isn't while getting access to world class experts sharing insights into latest threats and trends. You'll find me in there surfing around sharing what works. So come join us at go.sands.org/CLN. That's Charlie Lima, November. And if you're enjoying the show, one teeny tiny small favor. Hit subscribe. That's genuinely all we'll ever ask of you. And in return, we'll keep fighting to bring you the guests and conversations that you want to hear. Appreciate it all. Now let's get on with the show. Yeah, nothing like an exploding centrifuge to focus the minds, I guess. Anyway, I'm rudely entrop to James. I'll hand you back to him. That's quite okay. We've got to exploding centrifuges already at a great start to the podcast, which is probably going to make my next line of questioning see mundane, but I actually think it's really important. Taz, I don't normally read out bits of people's official biographies. Well, mostly because it makes people think I've just been lazy and that's all I've looked at. And where would people get that idea from James that maybe somebody else did all the research? I don't know. I mean, an occlusion. Well, I can't even possibly imagine now. Anyway, sorry, I'm interrupting again. Exactly. In a world of AI, we shall assume that perplexity or chat GPT did the way. Excuse me. I'm much cheaper and certainly better. Maybe. But there are a few bits of your official biography, Taz. So good. I wanted to quote them and ask you about them. After all these incredible achievements and experiences, you're described as an incident responder at heart. I love that quote. And then you're quoted kind of talking about seeing individuals fighting the good fight every day and catching an attack, in flight, responding quickly enough to get ahead of the exploitation that have been the environment. It means someone or some organization is better, more secure, and able to return to normal life. I just love that. And it takes me back to the first bit about how your incident responds at heart. So could you give us a sense of some of the buzz around incident response? Why do you love it so much? Why are you so passionate about it? And in Safari to Can, any highlights or cool stories that aren't classified and require beeping? Absolutely. You've hit the bell and I had to James. I think for me, I was definitely into responses is where cybersecurity really gets it for. And I think there's a couple of reasons for it. First of all, as the slightly a historical approach of the fact that it's always quite a nice feeling to do something good for people. I mean, when I joined, I mean, I had lots of reasons for joining. But part of it is around that sort of being part of a bigger picture, protecting things, that kind of idea. There's a little bit of a cynical approach in some cybersecurity areas. And that really what we're doing is protecting shareholder value. But interview response is a little bit different. There's genuine ways that we can actually protect individuals. At most of my work isn't really in like ICS OT environments. But if you look at those as an example, the interview responders there are genuinely saving lives. There's risk for life that their actions are preventing that people dealing with a nation-state attack in Ukraine, for example, are going to save lives. And that's hard to compete with letters and auditors that doesn't have that same kind of feeling for me. Regarding the kind of activities as well, the scope that we can get an IR is phenomenal. One day, we can deal with a nation-state threat to get an access to a critical database system taking the entire NHS down. And then in an next day, we've got an individual who's had their bank account attacked and all their funds stolen. So for me, doing IR is a combination of an incredibly very challenged. There's the same note today is the same. It's absolutely true here. It really is the case of, well, there's a rhyme between events. They're always different enough that we have to use our brains. We have to think. And then there's always that feeling at the end of it. You've actually made someone a little bit better. You've got, for example, I mean, now there's always a little bit challenging. I thought it would get sued out of existence for an end of it all going to prison. Or require bleeping. I actually thought James had to require beating. I thought that was up in the empty pits with his new haircut. But anyway, I was really, both approaches aren't ideal. I'm scared of them both. What can you safely disclose? Well, some of the more common ones then, I've dealt with an incident whereby, and this is kind of almost feels trivial. But there was a user in Singapore. They'd browse to a suspicious website. A fake help desk pop will put come up. They'd clicked on it, they'd rang through. And the attack is socially engineered them to connect in their own personal bank accounts. And they had all of their life savings extracted. Now, as an interview spawned at that heart breaking, that's not just the company impact, because it was while the attacks started and the company device hence, I get involved, the actual individuals felt personal pain. Of course. Now, we were quite lucky with it with the most recent one, although it's rare. We were quite lucky that we were fast enough that we were able to engage with the bank. We could speak to the bank's account of fraud. And again, I'm just going to do it a little bit. And I decided one for Sans here, because the head of their account of fraud team, you move from a Sans class, which absolutely facilitated a lot of this. Well, we were able to stop the fun transfer in flight. Right. And this person managed to save their money. That's the great feeling at the end. I love that. Oh, just seeing the cyber criminals not get money. Oh, so satisfying. And that's an absolutely lovely example. And I do also feel obliged to point out that now that you've plugged Sans twice, that has is not being paid for this podcast. This is not an information. And no, I don't work for Sans. No, I don't work for Sans. No, we will come back actually, because the more serious point is about communities of people who trust each other, which I know is something you're big on. But look, before we leave incident response, you've talked about some great stories and so forth. But give us some things to take away about good incident response. You mentioned there's enough difference, but there may be some patterns to do. So for people listening out there working, what have you seen that makes for good incident response? So there's a hierarchy of skills that an incident response needs at the very base level. There's an absolute technical requirement. As an incident response, there is an expectation that you'll understand technology well enough that it doesn't matter what you're having to deal with. If you're dealing with a compromised Mac device and then you're pivoting into a compromised Cisco firewall, as an incident response, you can't just say that or not my specialization. You've got to be able to understand enough to keep going. This isn't about being the expert. So there's a slight difference when we talk about maybe digital forensics. If I'm going to stand up in quarters and expert witness, I have to have a deep subject matter expertise. I are not quite that bad. Moving up from the technical level, because lots of people manage that where it really becomes different or a couple of key traits that insu-sponders have. You've got to be a good communicator. And insu-sponder absolutely has to be able to toilet the technical people and victims. If you are a very technically focused person and you can't communicate with the victim, it's going to slow things down. Absolutely. If you can't communicate with the board, you're not achieving your recommendations, your remediation actions aren't going to work. We get failing there. And the last, but probably the most important element, you've got to be interested. You've got to look for the challenge. It's like, you'll probably remember this from the olden days. It's like, you've got to be the person who does cross-word puzzles who does logic problems because you're interested in that challenge. And that's kind of what gives people towards being very good incident responders. Excellent. Yeah, it makes a lot of sense to me. Years ago, I heard this line that I think applies to what you were describing that a great incident responder has to be the calm in the storm. They have to be very zen. They have this ability to follow a checklist and be repeatable and evidence-based and methodical and calm, whilst also pursuing all these completely diverse and different scenarios. And that's quite a fascinating intersection of style challenges for people who do this stuff well, isn't it? Absolutely. I mean, James, that's probably the best swimmer I've ever heard. That's exactly it. You can have that one for free. - No, no, no, no, don't that true. - Yeah. - That really does. So I'm gonna make a note of that, and from now on, that's mine, just to be crystal clear. - You can see his head, it's quite big enough. - We could attribute it to you, you could put it on a t-shirt. - Oh, t-shirts, we're back to t-shirts. - Sorry. - Wait, have we had a t-shirt for a while, have we? - We have no t-shirt for a while. - I might be about to make another one. So, you know, hold onto your chair. Taz, let's pivot over here to one of the other things that you're very well known for, very experienced in, and a little related to this, that's threat hunting. Now, one of those areas that's, you know, well understood by some, and at a high level, the term is pretty self-explanatory, but not really, actually, if you don't kind of know the details, it kind of stops at the, I'm hunting threats level. So, get what is it to you, and where and how do you think it works best? - Okay, so a very basic level threat hunting is the proactive approach where defenders are looking in their environment to see, is there a problem that our security tools have missed? It's similar in physical security. We have similarities with security guards doing patrols inside the building. They're looking for someone who might have broken in and not set off any alarms. That's kind of the thought process that drives it. It is critical. I mean, we look at lots of statistics like Mandient and Frouge Strike, they're showing that dwell time, the amount of time and attack a commune of them before they get detected is dropped dramatically from like a year and a half in 2010 to 15 days of theirabouts today. That's nearly all down to threat hunting and as organisations get better at this, that's going to reduce just 15 days, still a long time. As I'm sure you can imagine James, if you're active in a network for 15 days, they're not recovering their rebuilding. - I could cause all manner of chaos to 15 days. - It's absolutely game over at the hot point. There's no hope. - Isn't it just? And it has to your point as well. So wonderful the dwell time is reducing so, That's a huge improvement. One of the things on my mind, though, is of course AI and auto. and agents coming into this space. That's gonna have a very interesting impact on that to all time staff, potentially in both negative positions. - Both sessions. - Ways, right? I kind of struggle to think through the next couple of years and what might happen there. I don't know if you have a profound realization for folks or more of a, it'll be different and hard type summary. - The problem today is this is very much a definition of interesting times. I don't have anything profound. I think it is gonna be a significant change. We are seeing attack or behavior speed up, absolutely. For most organizations that are deploying some form of LLM, within their security boundary, are also speeding up their response. So it could be that we are gonna see them increasing lock step. The main point to our net, there is ultimately, the LLM is just a tool for me, a cyber attack and its defense is still a very traditional, almost like spy V spy, sort of thing. It's a human at one end of the attack chain and a human at the other end of the attack chain. It's just about how we utilize these tools to our best advantage. - Yeah, I really subscribe to that viewpoint too. But I know this is trivializing kind of different technology use cases, but I stand by the statement in macro at the end that said it before, if both sides have AI, then once again, the edges human. But there is a very important, of course, threat hunting thing that I do have to ask you before Keirin follows up with, but we'll know that there'll be a more serious question. Don't bet on it. There is, of course, this trend of the amalgamation or concatenation of threat hunting into thrunting. How do you feel about thrunting? - I have not all to go the show where to go with that. (laughing) - I think that probably describes it in itself. - Yeah. Is this a refinery put in the bleeps? - That's not a term I'm gonna utilize on a regular basis. (laughing) - I think we have a call on it. I'm with Taz. - You're silence, please. - I had no idea where that came from. I think I said earlier in this podcast about James, I even pay attention to the words that I don't even understand and here we go. So that's perfect. But anyway, thank you for taking us to the humans because I want to ask about humans. So this is thrunting, oh my God, I'm doing it. This threat hunting stuff. - Oh, thank you. - I know. - Can't she? - Oh God. - Could be a company. - No. - No, no, no, no, no, that will get blocked. And rightly so, hand breath. - Now look, threat hunting, humans. Ian James have talked before, going back to the human, you've talked a lot about what you learn technically and so forth, what you need to do. What do you learn about the adversarial mindset and even the adversaries themselves? And James accused me of asking more serious questions who are better trivialize that as well as that. I wanted to ask you, what about threat actors? I mean, if you had to make a league table of threat actors as opposed to baddy catchers, any particular groups that you've dealt with or studied over the time, but you think, oh, they're a difficult bunch. So what are you learning about the adversaries and who do you worry about? - Really good question. All of them is the short answer. So there's a whole range of skills and things like that. Some of the ones we refer to as, I mean, we use the term APT quite loosely. But some of the APT's we refer to like shiny hunters. - Yeah. - They are always in the news. They are always doing very high profile, high monetary gain attacks, but they're incredibly low skilled. And now that everything that shiny hunters do is down to a misconfiguration, basically default passwords being exposed to the internet. Shiny Hunters make a few millions. I'm not trivializing that, but as an insurvener, that's not really a threat actor you worry about because investigating them is not really that challenging. The defending against them shouldn't be that challenging. They're the high noise, very, very profitable annoying criminal groups. The ones that create more of a problem are the genuine nation states, the pandas, the bears, that kind of thing. That's where we see more skilled trade craft. And they're also very often difficult to really get to understand what they're happening. Their techniques are a lot stelthier. There's a lot more required for our investigations. That's where the problem really lies. The good news is they don't target that many people. We get a lot of noise, but when they do, it is a very difficult annoying investigation. - Brilliant. - Hi, let's develop this a little bit further. I will get on to the state of our industry, cybersecurity and so forth. Now you've been constructively outspoken, I think, as the way that I would put it, about all sorts of things to do with this industry. And we're gonna ask you about all of them. Well, no, as many as we can fit in. So let's turn a bit to digital infrastructure and some of the myth-busting you've done. So you've become quite famous and a bit controversial sometimes about this. Linux is a secure operating environment myths. And that's just one example of you taking on some of the structural problems about corbits of hard and soft digital infrastructure that seem to be at the root of so many of our difficulties. How are we getting all of this stuff? - We're getting better. - Yay. There is definite trends of improvements. We'd be the easiest way to describe it. But there is a genuine problem. And one of the reasons why, I don't know if I like the tale about spoken, but I'll lean into it. One of the reasons we find that is, we've kind of allowed ourselves to get into a kind of static mindset, a key truth of the security is, tomorrow you need to learn something that you didn't know today. This is a constant thing. The things that I thought were gospel truths in 2003 just aren't correct today. - Absolutely. - And if I'm not able to make that mental leap, I'd be wrong. - Yeah. - The work that I do would be incorrect. And I think we struggle a little bit. So I will use the Linux one as an example. A lot of that came out. I went to a couple of conferences and I had recently seen you people within cybersecurity, making statements to me about Linux and Windows that were probably last year in 1997. - Right. - And I'm like, we've got to have this constant learning mindset where we adapt and evolve relentlessly, really. - Yeah, it's so funny, Tas. I'm emitting some confirmation bias to your position and a lover of a little bit of outspoken as well. So others could argue with us, but we love a story in cybersecurity. We love to introduce a concept or an idea, a quip or a trope, a slogan. And then once it's in the language of security professionals, we hold onto that idea for so damn long, so hard. To your point on this kind of Linux thing, the relatively true position kind of back in the day, that a great deal of the general attack space was malware, focused on Windows and that Linux enjoyed relative immunity to that problem, very fair. But that of course morphed into this, well, it's secure and you don't have to worry about this stuff. - Yep. - Which is hilarious because whilst Linux provides incredible frameworks for security and customization in the right hands, on the out of the box it provides some ludicristically fantastic ways for attackers to hide information and compromise just because they're not necessarily using a traditional piece of malware like on a Windows computer. And I still find people who hold to that idea today and will tell me there's no malware for max and iPhones and so on. We got to slave these stories, we got to be outspoken. - 100% you've hit the exact nails on head there. I mean, there's two kind of angles to this that, I don't know if frustrating right where, but there's two kind of angles that things in industry, we need to be a bit better at. First of all, the concept of secure is kind of meaningless without threat actors, so you could be secure against an asteroid strike or secure against theft. And without trying to go to your tentacle, but if we use like operating systems as an example, the Mac operating system, it's security models based around someone stealing your Mac device. The Windows operating system of securities based around malware, they've got two different threat models, so they implement security differently. If you say one's more secure than the other, you're kind of missing a significant element of a point. - You've got to say against what? - Yeah. - Yeah, exactly. That what is the important bit. And then I just said James, the key point for me is Linux, Linux operating system. I love them. I spend most of my life in Linux. As it can be secured against most things we consider and attack, but they don't come out of the box that way. The exact opposite when you first install it. No auditing, often weak privilege escalation paths. - Yeah. - So it's about understanding and instead of just sitting back on our heels and thinking to ourselves, "Oh, 20 years ago I was taught this, "therefore it must be true." I think it's about that. We need to constantly understand that everything's changing and learn to adapt. - Yeah, constant reevaluation. I think that's exactly right. And be careful with those tropes and stats and challenge yourself against what, against who type questions. One of my examples, I'll share very quickly to kind of support your point, Taz, and then Keirin will no doubt come up with a better question. But there's this often quoted stat that 95% of breaches involve and are caused by humans. And you kind of go, well, that's kind of briefs well at the surface, it's quoted all the time. But it goes back to an IBM report in 2015 where they specifically said that that was true in inside of threat cases. They weren't talking about the whole threat landscape and totality and all the API attacks, malware, web app, et cetera. It's very specific niche. And people never quote that bit since not as catchy. And then in more recent studies that have happened over the last year, the great, you know, Verizon data breach report stuff and similar, they say that the stat is more like 68% the way people think about that with humans clicking something they shouldn't and so on. And much of the rest of the delta is made up from credential theft, misconfiguration of systems and so on. Well, okay, but that's a bit like saying 95% of problems happen in a kitchen because there is a chef. Well, yeah, like of course. Yeah. But you've got to be so careful on these tropes and stories. It can really cause resource allocation issues in security leadership, can't it? Absolutely. That's exactly it. I think we do fall into this mindset. And maybe it is a little bit, but that is a lack of data. I know getting reliable incident on intrusion metrics has always hit miss. No one likes talking about them. For example, I don't think there's more than three cases I've worked in the last year that I could mention, let alone add into some kind of statistics thing. But without that, it's always going to be a little bit more cause and effect challenged. Yeah. Well, let me jump back in here. And I want to take you back to something you said a little while ago. And it was about the Linux environment. But I wanted to ask you about it because it's got wider applicability. So you said you didn't like or you might be completely comfortable with the word I've spoken. And that's fair enough because you're not one of these people who jumps up on a conference stage and says something outrageous and arresting. but it ended. You do challenge myths and you do try to put people right and make changes. But you told a really interesting story to get back to storytelling, but you didn't have time to develop. So I wanted to ask you about it. You were talking about earlier in your career and there are some senior figures in the industry essentially talking nonsense about Linux to your face and you push back. How did you do that? What happened? Was it difficult? Were you nervous and did it change anything? Because these are things have to be done, but they're not easy. Yeah, nervous isn't quite the right word. I was ultimately unsuccessful. I might as well lead with the failure first. So this was a conference. There was vendors talking about it and the vendor had basically taken a stance that the problem that you've got with sub-security is that you always use windows. If you come towards as your managed service provider, we'll migrate you to Linux to secure. In the questions part, I said that's not really the case, tried to ask it. And I did notice that the thing that really stuck with me is almost all of the other attendees agreed with the vendor. I had people telling me that I didn't understand Linux, which I found quite entertaining. Yes. People telling me I was a lulledite. I didn't understand the future. I was just a Windows fanboy. And ultimately, I don't think I convinced a single person in that session. Right. But it did inspire me to try and spread the words to everyone else. Yeah. Yeah. And you did have some success in that respect. And that brings me into another question and I'm going to try and stick with you know, things that are slightly controversial. Now having inadvertently accused you of shilling for sands, having done two plugs, I'd forgotten I was going to ask this question because it's a belter. So last year you write an article on LinkedIn and you know, it's called cybersecurity certifications are they worth it? Well, that's hardly something sounds would have paid you today. Absolutely not. So this is a sands podcast. So cybersecurity certifications are they worth it? Yes or no? All right. You can have the classic cybersecurity answer of it depends. But what does it depend on? And more seriously, how does this whole debate about certifications which has been running for a very long time? Now what does it tell us about the state of our industry and the whole battle to get enough? All the people into the fight that you've been in and inspired so many others to get into? So I'm going to avoid doing a consultant trope and saying it depends on whether that's kind of the answer I want to give you put me on a spot. So I'll, I'll, I'll, I'll go away from that. I'm going to say yes. Okay. I do think they are actually genuinely and this is absolutely nothing to do with any relationship with sands and who I believed in them. The reason why I have a relationship with sands is because I believe training and certifications are essential not the other way around. And why is that? Well, ultimately, so certifications, there's kind of two ways to look at it. There is a certification whereby you can demonstrate that you know something. So if I go and do something like the cloud security certificate, it's just the straightforward exam that shows I understand the cloud. That type of certification allows you to go to other people and create that sort of like selection of trust. So for example, let's say if I want to be an expert witness and I want to present the court that have expert credentials, I can present to the court. Here is a certification by this recognized body that says I know XYZ. What makes my ability to be an expert witness much easier if I'm applying for a job, it makes my ability to demonstrate to the hiring manager that I know something much easier. I'll come back to that because there's a little career there. That's where people get the most frustrated, I think, but the expert witness one is pretty useful. That's one type of certification. They are absolutely worth it. They allow you to demonstrate to people that you can do things, maybe an insurance company, maybe a hiring manager, etc. Yeah. Where it really pays off though, are the ones that teach you something as well at a training class followed by a certification, for example. And I think this is where the biggest advantage can happen for cyber security as an industry really. We've got lots of people and there are a couple of career apps will hold on to that for a second. We have lots of people who need to know more. I said earlier on that we've got an entire industry of people who maybe did a university class in 2004 and think the EXT three file systems, the default file system in the entire world hasn't been true for a decade. Yeah. I do miss it though. It's a nice file system. The easy days by doing training, we can improve, we can be better than that, we can learn what the state is today. And that to me is the essential thing. We've got to learn new skills. Even if you think you've got to set a skill site, the very first, I'll use the air quotes where honestly you can't see them. The very first cyber investigation I did was like 1993. The skills that I use today are completely different. So I have to keep doing training and learning to keep that I'm proving. Yeah. But that's the value. So I have kind of headed away from that leads to a lot of discussions or people start to get a little bit focused on maybe the numbers, which I think is the challenge. We mislead ourselves. There's a couple of perceptions that people tend to have. And a lot of it is that simply having the certification or the training isn't always enough. Yeah. So I could have, let's say, I mean, I've been in the next bit of when it's in the past. I have been eviscerated on cross in the past. Right. Despite having certifications, it didn't save me. Oh, sure. Without the certifications, I wouldn't have had the chance. And I think that that's quite a significant thing. There's also the cost-benefit trade off. And I think without drilling into numbers, the reality is we've got a lot of people who are very well paid industry. They should be willing to invest in making themselves better if they want to continue to be well paid. Yeah. That's the bit that creates the most arguments with people. I think we've got to understand this. And from an employee's point of view, there's the old Henry Ford saying about what if I train my employees and they leave, what if you don't train them and they stay? Yeah. That's the very good point. That's the biggest problem. Yeah. So for me, long winded route about way. They're very good. They absolutely are worth it to me. I'll put your LinkedIn post in the show notes because it's very, very good and very balanced. James, thank you. It is indeed. And as you note in the post, there's no silver bullet, one is in charge of one's own career and there are ways to do this without certifications if you'd like to and you suggest some of that too. But again, I admit confirmation bias in thinking that take is right from my perspective. But let's pivot to a couple of other spots before we run out of time, Taz, which I knew was going to be a problem on this podcast. Just a question here about people and cyber security. One about the community and mentoring. You know, it's very clear from, for example, your last LinkedIn write up that you're passionate about seeing people vicariously succeed in this industry. You've done a lot of this. You've spoken written very proudly and movingly about it. Tell us a bit more about that and what you think could be done to bring more talent through to face these future challenges. We've got to help you to the more ultimately. We've got to understand the fact that there's a little of a perception and a minority of the community for to the perception that if you help people, they're going to take your job. So I see this occasion within some responders. Yeah. They're very reluctant to allow a sock analysts to sit alongside them because they feel if the sock analysts can do it, they'll lose the job. That's not how it works. Everything about cyber security is community driven. Well, nobody ever believes what I say this, but I am an introvert. And even if you don't like being around and talking to people, cyber security, you've got to find a way to make that work. You've got to share information or threat actors are doing it. Fret actors have very active communities. They have active knowledge sharing. As defenders, we've got to get more into this. We've got to be more active. We should attend more conferences. We should go to things like B sides. We should be talking more and I don't get told off of it, talking about sounds too much again, but as an example, pretty much every sans class I teach someone on the class says to me, Oh, here is this great tool I've written. Here's my get top. Here's this thing I've got. And that's then something that everyone may included can take away and utilize in our future work. And just by simply being around people and sharing these ideas, that's where cyber security gets better. It is awkward. I understand that a lot of people we have a senior type within cyber security, not liking to talk to people, but we're amongst friends. This is the ideal opportunity to discuss topics that we've got to share interesting. I think this is really how we can make cyber security better across the board. I love that, Taz. And look, I think the next few years of cyber security are going to be very interesting, whether you're hands-on keyboard, you're kind of in a sock, you're doing malware reversing, you pen testing, you're in security leadership. AI, as well as the eternal pressure of kind of threat actors, will significantly reshape the profession. I don't think it will eliminate roles. I think there will be more of them, but the roles will be different. And working through that disruption, using these technologies so that we come out with more good versus bad just requires that type of community engagement and discussion and togetherness. And I just, I want to unline the thing you said, the bad guys are doing it. So if we don't, we are going to set ourselves up for failure. So a crucial and important point there and lots of opportunities to get engaged in the community. And many of them don't even have to be expensive. They can be free. But Taz, I do have an important last question for you before we go to our close here because I know we're burning through time. We mentioned in the opening your ludicrous collection of animals. We're reliably told at this time of recording that you have two pigs, four goats, two donkeys, the pony or horse, six chickens and five cats. So three questions, one, why? Why? Two, how? How do you have the time? And three, perhaps most importantly, are they named after threat actors, like extra excitable pony, a punitive goat? I mean, we could have great fun with this, but are they named after threat actors? And if not, why not? So I'll go through the three versions. No, they're not named after threat actors. Now you've said it though, that's a fantastic idea. I really like that. I think any new ones will be from now on. Generally, most of them have really boring names, like so for example, the goats. Goats are registered animals, so they have a little tag in their ear with a number that's registered in like the council's list. So I just call them by their number, like 406 and 408 and stuff like that. I haven't actually named them even over 10 years old now. How do I find a time with difficulty? I think the key is what you said early on, I just avoid sleep. Most of my work is actually done outside UK hours as well, which kind of helps a little bit. And now we're getting into summer. It's a bit more day-light. But the big one, why? The interesting question about it is I don't really like being indoors. I find, I mean, let's say you. If you spend 12 hours working in an incident and you need a way to decompress, go outside and trimming the goats who's fighting the goat to let it trim your two's, getting beaten up by the goat, that's a very, very good way to just kind of wash it all off. Yeah, it sounds like a future incident response presentation. That time I fought the goat. Well, and it's also a pretty convincing answer, because I can't imagine there are too many incident responses that you can lead from the outside. So dealing with all these things, but wrestling horses, wrestling horses. A good way of decompressing. I know we're running out of time, but I can't resist this given that. James said, you know, there's endless potential fun in this game. We don't have time for much, but here's one bit. Okay. I'm going to read out four animal-related threat act to names. And you have to tell me which one is a real actual threat actor named by a credible cyber security company? Is it mournful donkey, indifferent pig, charming kitten or resentful chicken? Which one's real? The kid? Yes. It's cry strikes around of England. Lots of work with crowd strikes. So crowd strikes the demon conventions. I know the best. If you said one of Microsoft's done, I thought mournful donkey was almost plausible. I like that, though. That is good. Last season, I suggested erudite badger and no one has made that happen yet. So I'm quite sad about that. Oh, I love it. We've got to stop. We've got to stop. We've got to stop. We've got to stop. We're out of time, Kirill. I'm going to put the brakes on the threat hunter naming for occasion. No doubt we'll have Taz back with a terrified ferret. Stop it. Okay. We'll have him back for an update on his farm yard animals and presumably his new acquisition of several ferrets based on that suggestion. So look, Taz, we are going to have to bring things to a close. But there is a pretty key thing we like to do at the end here, isn't there, Kirin? My favourite bit? Yes. Yes, your favourite, but go on. Tell a model is. So Taz, look, as you know, it's only fair. If we have people listen to us about our naming conventions and so on, we give them something really piffy and useful at the end. So we are asking you for your 30 second takeaway. So Taz, this is a podcast about lessons for cyber security leaders. So if you've got 30 seconds with a cyber security leader, what would you advise them? Something to pay attention to to ignore. Whatever it may be, 30 seconds of brilliant wisdom. For the understanding network, don't rely entirely on things like CMDB's or existing network diagrams, understand the actual data paths, understand where people can access things, understand where the data resides. That's the 99% of every single entry you know ever worked. If you can know your land better than the threat actors, you can respond better, you can defend it better. Oh my God, I think that's the first one that's ever come in under 30 seconds. That's the most Taz thing ever. That's fantastic and very, very useful. Highly efficient. Maybe we'll have to slow it down on the broadcast version to overshoot 30 seconds like everybody else. Thank you Taz, that was incredible. That is it. Sadly, it was brilliant, a tour de force, so much there and one of the best takeaways ever. So thank you Taz, thank you for joining us. Thank you very much. Thank you to everybody for listening and you can leave us feedback at the podcast site or you can email us at [email protected]. Tell us whatever you want. And with that, thank you for listening. Thank you for listening. Keep cybering. So for me, Keir and Martin. And me, James Lyne, it's goodbye and I'm off to buy a ferret. Bye bye. [Music]

Podcast Summary

Key Points:

  1. The podcast "Cyber Leaders" is hosted by Kieran Martin and James Line from the SANS Institute, aiming to educate security leaders on effective cybersecurity.
  2. Guest Taz, a former military intelligence operator (1993-2010), transitioned to cybersecurity, specializing in electronic warfare and security.
  3. Taz founded his own company in 2010, focusing on incident response, risk assessments, and training, and has led IR and CSIRT functions at major organizations like Unilever.
  4. He is a SANS instructor and author of key courses on incident response and threat hunting, emphasizing the importance of hands-on defense.
  5. Taz describes himself as an "incident responder at heart," valuing the direct impact of protecting individuals and organizations from cyber threats.
  6. Effective incident response requires a mix of technical proficiency, adaptability across technologies, and strong communication skills to coordinate with victims and leadership.

Summary:

The transcript introduces the podcast "Cyber Leaders," hosted by Kieran Martin and James Line from the SANS Institute, which aims to equip CISOs and security leaders with knowledge to secure their organizations and combat cyber criminals. The episode features guest Taz, who began his career in the British military in 1993, working in intelligence, electronic warfare, and signals intelligence. He transitioned to cybersecurity in 2010, founding his own company and taking on roles such as leading incident response and CSIRT functions at Unilever.

Taz is also a SANS instructor and author of pivotal courses on incident response and threat hunting. He reflects on his journey from military security to civilian cyber defense, noting the evolution of threats from early computer security to modern challenges like Stuxnet. Taz emphasizes his passion for incident response, highlighting its direct human impact—such as stopping a fraudulent bank transfer and saving an individual’s life savings.

He outlines key traits for effective incident responders: deep technical adaptability to handle diverse systems, strong communication skills to bridge technical and non-technical stakeholders, and a focus on practical outcomes. The discussion underscores the value of community and trust in cybersecurity, with Taz’s experience illustrating how proactive defense can make cyber criminals' lives difficult.

FAQs

The podcast, hosted by Kieran Martin and James Line from the Sands Institute, aims to unpack the world of tech security, helping CISOs, security directors, and others build knowledge to secure their organizations more effectively.

The guest is Taz, who started his career in military intelligence in 1993, specializing in electronic warfare and signals intelligence. He later founded his own incident response company and is a Sands instructor.

Taz notes that his military role involved gathering intelligence from enemies and preventing them from gathering it, which parallels cybersecurity. He attended a computer security officer course in 1993, and by the time he left in 2010, the military had pivoted significantly toward cybersecurity.

Taz loves incident response because it allows him to protect individuals and make a tangible difference, from saving lives in ICS/OT environments to preventing financial loss for individuals. It offers variety and a sense of accomplishment.

He describes a case where a user in Singapore was socially engineered to connect to their bank account, and the team was able to stop the fund transfer in flight, saving the individual's life savings by contacting the bank's fraud team.

He emphasizes strong technical knowledge to handle diverse systems, but also excellent communication skills to explain issues to victims and boards, ensuring effective remediation.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.