1 00:00:00,080 --> 00:00:03,320 Speaker 1: You're listening to Bloomberg Business Week with Carol Messer and 2 00:00:03,400 --> 00:00:07,560 Speaker 1: Tim Stenebec on Bloomberg Radio. You might recall on Monday, 3 00:00:07,600 --> 00:00:11,320 Speaker 1: Bloomberg reported on an episode that underscores the vulnerability of 4 00:00:11,320 --> 00:00:15,160 Speaker 1: global computer networks when hackers got hold of logging credentials 5 00:00:15,160 --> 00:00:16,880 Speaker 1: for data centers in Asia use by some of the 6 00:00:16,920 --> 00:00:19,800 Speaker 1: world's biggest businesses. The move scene is a potential bonanza 7 00:00:20,160 --> 00:00:23,960 Speaker 1: for spying or sabotage, according to a cybersecurity research firm. 8 00:00:24,040 --> 00:00:26,680 Speaker 1: So we thought, let's get an update if you will 9 00:00:26,840 --> 00:00:30,120 Speaker 1: when it comes to cyber attacks. Yeah, really important story 10 00:00:30,200 --> 00:00:33,479 Speaker 1: that we definitely need to keep monitoring, monitoring, and I 11 00:00:33,520 --> 00:00:35,280 Speaker 1: think our next guest is going to help us be 12 00:00:35,520 --> 00:00:38,600 Speaker 1: smarter on it. This is Charles Henderson, Global Managing Partner 13 00:00:38,600 --> 00:00:41,760 Speaker 1: and head of IBMS X Force, joining us via zoom 14 00:00:41,880 --> 00:00:45,080 Speaker 1: from Austin, Texas. Charles, thank you so much for being 15 00:00:45,159 --> 00:00:48,000 Speaker 1: here with us. Give us just the lowdown on IBM 16 00:00:48,159 --> 00:00:53,840 Speaker 1: State of Security Report. What are your big takeaways? So 17 00:00:54,000 --> 00:00:57,360 Speaker 1: you know, you think about every company that you just 18 00:00:57,400 --> 00:00:59,400 Speaker 1: dealt with A closing Belle, and the name of the 19 00:00:59,440 --> 00:01:02,960 Speaker 1: game is agency and return on investment and criminal organizations 20 00:01:02,960 --> 00:01:06,039 Speaker 1: are no different. What you're seeing is organized crime step 21 00:01:06,120 --> 00:01:08,000 Speaker 1: up to the plate and look at how do we 22 00:01:08,040 --> 00:01:11,639 Speaker 1: gain efficiencies, how do we improve our gross profit margin, 23 00:01:12,160 --> 00:01:15,120 Speaker 1: and how do we do that with automation. All the 24 00:01:15,240 --> 00:01:18,160 Speaker 1: same things that you want to see companies doing, and 25 00:01:18,800 --> 00:01:23,640 Speaker 1: right now they're doing it exceedingly well. Go ahead, no, no, 26 00:01:23,640 --> 00:01:26,000 Speaker 1: go ahead no. Really really interesting to hear you talk 27 00:01:26,040 --> 00:01:29,520 Speaker 1: about them doing well, because we don't always get good 28 00:01:29,640 --> 00:01:32,000 Speaker 1: good news on this topic. What are some of the 29 00:01:32,000 --> 00:01:35,240 Speaker 1: other major findings when it comes to sort of where 30 00:01:35,280 --> 00:01:41,160 Speaker 1: you're seeing energy attacks at X Force specifically, so you know, 31 00:01:41,400 --> 00:01:44,039 Speaker 1: one of the key things the attackers are looking for. 32 00:01:44,160 --> 00:01:48,800 Speaker 1: The criminals are looking for is leverage. They are looking 33 00:01:49,080 --> 00:01:53,200 Speaker 1: for real world output of their labors. So you know, 34 00:01:53,200 --> 00:01:57,840 Speaker 1: if you think about like energy or manufacturing or industry 35 00:01:58,920 --> 00:02:02,480 Speaker 1: a little tolerance for downtime, they are a key target 36 00:02:02,480 --> 00:02:06,520 Speaker 1: of attackers because those sectors tend to know what the 37 00:02:06,600 --> 00:02:09,000 Speaker 1: cost of downtime is going to be down to the 38 00:02:09,040 --> 00:02:12,120 Speaker 1: dollars and cents. So if you have ransomware against an 39 00:02:12,560 --> 00:02:15,600 Speaker 1: energy provider and the lights go out or a manufacturing 40 00:02:15,639 --> 00:02:20,160 Speaker 1: facility and the assembluny line star stops working, criminals are 41 00:02:20,160 --> 00:02:21,880 Speaker 1: relying on the fact that they're likely to pay a 42 00:02:21,960 --> 00:02:25,519 Speaker 1: ransom or extortion because they know how much it's costing 43 00:02:25,520 --> 00:02:29,400 Speaker 1: them in the real world dollars. Hey, listen, what I'm 44 00:02:29,440 --> 00:02:31,320 Speaker 1: always curious about it, and and I feel like at this point, Charles, 45 00:02:31,320 --> 00:02:33,560 Speaker 1: we know that this is happening, right, It's happening around 46 00:02:33,560 --> 00:02:36,120 Speaker 1: the world. It's kind of a part of normal operations 47 00:02:36,120 --> 00:02:38,839 Speaker 1: when it comes to business. What are we learning year 48 00:02:38,880 --> 00:02:41,680 Speaker 1: by year? What's different about what happened last year versus 49 00:02:41,680 --> 00:02:44,160 Speaker 1: the year before. Is it just the frequency, is it 50 00:02:44,200 --> 00:02:46,880 Speaker 1: the type of cyber attacks that are happening? What is 51 00:02:46,919 --> 00:02:48,519 Speaker 1: it or is it all kind of the same. It's 52 00:02:48,560 --> 00:02:54,040 Speaker 1: just more perhaps, So you know, one of the biggest things, 53 00:02:54,040 --> 00:02:55,880 Speaker 1: and I already talked about efficiency, but let's put that 54 00:02:55,919 --> 00:03:01,040 Speaker 1: into numbers. A ransomware activity on the part of a 55 00:03:01,080 --> 00:03:05,320 Speaker 1: criminal enterprise takes ninety five percent less time than it 56 00:03:05,360 --> 00:03:07,959 Speaker 1: did three years ago. So three years ago, we'd say 57 00:03:07,960 --> 00:03:09,880 Speaker 1: two two and a half months soup denuts from the 58 00:03:09,880 --> 00:03:11,360 Speaker 1: point at which they got in to the point at 59 00:03:11,360 --> 00:03:14,760 Speaker 1: which they accomplished their goals. Now that's closer to four days. 60 00:03:14,800 --> 00:03:17,720 Speaker 1: That is huge efficiency gains. That means that we as 61 00:03:17,720 --> 00:03:20,360 Speaker 1: an industry have way less time to detect and respond 62 00:03:20,400 --> 00:03:22,920 Speaker 1: to an active attack. That means we need to get better. 63 00:03:23,280 --> 00:03:27,360 Speaker 1: We need to gain those efficiencies as well. Where are 64 00:03:27,400 --> 00:03:30,920 Speaker 1: we at now with those efficiencies? How what like letter 65 00:03:31,080 --> 00:03:34,120 Speaker 1: grade would you give us in our ability to respond 66 00:03:34,200 --> 00:03:38,920 Speaker 1: to these four day attacks? Not great? And I'll tell 67 00:03:38,960 --> 00:03:44,560 Speaker 1: you why. We have a vulnerability debt that is going 68 00:03:44,600 --> 00:03:47,480 Speaker 1: to be difficult to overcome. Most organizations cannot keep up 69 00:03:47,480 --> 00:03:53,120 Speaker 1: with patching anymore, and so it's no longer a wise 70 00:03:53,160 --> 00:03:55,920 Speaker 1: strategy to just try and keep everybody out and count 71 00:03:55,960 --> 00:03:58,480 Speaker 1: on that as working. So what we need to do 72 00:03:58,720 --> 00:04:02,760 Speaker 1: is focus on assuming that you've been breached and what 73 00:04:02,800 --> 00:04:05,240 Speaker 1: can you do to detect and respond to an attacker 74 00:04:05,280 --> 00:04:08,320 Speaker 1: that's moving laterally through your environment. That pivot is going 75 00:04:08,360 --> 00:04:11,680 Speaker 1: to be key as we go forward. Organizations are starting 76 00:04:11,680 --> 00:04:13,880 Speaker 1: to do it. You see, you saw an executive order 77 00:04:15,560 --> 00:04:19,839 Speaker 1: two years ago that has really changed the way a 78 00:04:19,880 --> 00:04:23,960 Speaker 1: lot of organizations approach working from a sooon breach a strategy, 79 00:04:24,320 --> 00:04:28,839 Speaker 1: implementing zero trust strategies. All these things come together to 80 00:04:29,000 --> 00:04:32,640 Speaker 1: modernize our approach to security. But the final piece of 81 00:04:32,640 --> 00:04:35,279 Speaker 1: this is giving up on the perimeter and starting to 82 00:04:35,320 --> 00:04:39,159 Speaker 1: focus on the interior. Hey, listen, one thing I was wondering, Charles, 83 00:04:39,200 --> 00:04:43,440 Speaker 1: how much of an impact of a global war, the 84 00:04:43,480 --> 00:04:46,200 Speaker 1: war in Ukraine. How is that impact in the frequency 85 00:04:46,200 --> 00:04:51,080 Speaker 1: and severity of cyber attacks? You know, it certainly didn't 86 00:04:51,200 --> 00:04:55,920 Speaker 1: help in any time that you have conflict, you have 87 00:04:57,400 --> 00:05:02,920 Speaker 1: folks that are straying, they're under stress, and that's exactly 88 00:05:02,960 --> 00:05:07,919 Speaker 1: what criminals are looking for. They're looking for either supply 89 00:05:08,000 --> 00:05:11,359 Speaker 1: chain stress, real world stress that they can pile onto 90 00:05:11,440 --> 00:05:14,760 Speaker 1: with cyber attacks and gain leverage. Because at the end 91 00:05:14,760 --> 00:05:18,279 Speaker 1: of the day, extortion is all about leverage. It's knowing 92 00:05:18,680 --> 00:05:21,279 Speaker 1: that your victim has no choice but to pay you. 93 00:05:22,640 --> 00:05:27,880 Speaker 1: And this is also getting worse because of like activist groups. Right, 94 00:05:28,240 --> 00:05:32,040 Speaker 1: I don't necessarily have the best understanding of those groups, 95 00:05:32,040 --> 00:05:34,039 Speaker 1: but I know that it's not good and that they're 96 00:05:34,040 --> 00:05:38,200 Speaker 1: getting better. Are you more concerned about them or about 97 00:05:38,720 --> 00:05:43,520 Speaker 1: um more? I guess institutional hackers that we've already known 98 00:05:43,560 --> 00:05:48,800 Speaker 1: about for some time. You know, Look, activism is a 99 00:05:49,480 --> 00:05:51,560 Speaker 1: real problem for organizations. But at the end of the day, 100 00:05:51,600 --> 00:05:55,440 Speaker 1: I'm most concerned with the evolution of attacks. We've gone 101 00:05:55,560 --> 00:06:02,800 Speaker 1: from the advanced technical attacker to organized crime employing business 102 00:06:02,839 --> 00:06:06,480 Speaker 1: tactics that they've tested long and true in street crime 103 00:06:06,560 --> 00:06:09,440 Speaker 1: and applying them to digital crime. And what that means 104 00:06:09,560 --> 00:06:13,640 Speaker 1: is they're gaining efficiencies, they're working smarter, not harder, and 105 00:06:13,680 --> 00:06:17,440 Speaker 1: they're using a fail fast mentality that quite frankly, it's 106 00:06:17,440 --> 00:06:19,719 Speaker 1: going to be difficult to keep up with. If the 107 00:06:19,800 --> 00:06:22,680 Speaker 1: defenders don't adapt as well, we're gonna need to start 108 00:06:22,680 --> 00:06:25,320 Speaker 1: thinking like attackers. Hey listen, but I wonder too, Charles, 109 00:06:25,320 --> 00:06:26,680 Speaker 1: and I feel like this is just like I said, 110 00:06:26,760 --> 00:06:29,080 Speaker 1: you know, cyber attacks, unfortunately, are just a way of 111 00:06:29,520 --> 00:06:33,280 Speaker 1: life for us increasingly. So having said that, I mean, 112 00:06:33,320 --> 00:06:36,000 Speaker 1: you guys certainly play into the space and provide, you know, 113 00:06:36,040 --> 00:06:38,880 Speaker 1: ways for companies to protect themselves. What's the uptick that 114 00:06:38,920 --> 00:06:42,600 Speaker 1: you've seen in demand for your products? So you know, 115 00:06:43,200 --> 00:06:47,280 Speaker 1: I would say that the biggest demand we are seeing 116 00:06:47,360 --> 00:06:52,960 Speaker 1: now is for you know, threat hunting, adversary stimulation, things 117 00:06:53,000 --> 00:06:57,000 Speaker 1: that help organizations think like an attacker. So they're concerned 118 00:06:57,000 --> 00:07:00,080 Speaker 1: with their attack surface monitor and they're they're concerned with 119 00:07:00,680 --> 00:07:04,240 Speaker 1: red teaming that will help them understand where they may 120 00:07:04,279 --> 00:07:07,440 Speaker 1: have gaps in detection. So it's not enough just to 121 00:07:07,600 --> 00:07:11,520 Speaker 1: defend anymore. Now you need to understand do your defenses 122 00:07:11,640 --> 00:07:16,440 Speaker 1: work and how are they working? Whereas in the past 123 00:07:16,480 --> 00:07:18,960 Speaker 1: it was more of a bioproduct, set it and forget it. 124 00:07:19,080 --> 00:07:23,080 Speaker 1: Now it's more of an interrogation of those products. I 125 00:07:23,160 --> 00:07:27,560 Speaker 1: wonder too, if you've seen any sort of interest from 126 00:07:27,600 --> 00:07:31,360 Speaker 1: consumers about wanting to protect ourselves as well, and if 127 00:07:31,360 --> 00:07:34,040 Speaker 1: you have any advice for the average listener out there 128 00:07:34,080 --> 00:07:36,520 Speaker 1: who might be hearing this and thinking, yes, this is 129 00:07:36,520 --> 00:07:40,200 Speaker 1: obviously bad for big companies and governments, but also we 130 00:07:40,240 --> 00:07:42,560 Speaker 1: want to make sure we're protecting ourselves on an individual 131 00:07:42,680 --> 00:07:48,000 Speaker 1: level from any cybersecurity threats. You know, everyone needs to 132 00:07:48,040 --> 00:07:51,240 Speaker 1: worry about cybersecurity now. It's no longer just big companies, 133 00:07:51,280 --> 00:07:53,200 Speaker 1: and you know, you only need to look at the 134 00:07:53,240 --> 00:07:57,160 Speaker 1: real world repercussions of cyber attack, whether it's colonial pipeline 135 00:07:57,160 --> 00:08:01,320 Speaker 1: a year ago or any number things. But consumers can 136 00:08:01,360 --> 00:08:04,080 Speaker 1: do some things just to protect themselves on a personal level. 137 00:08:05,760 --> 00:08:09,120 Speaker 1: Multi factor authentication is huge, you know that's been in 138 00:08:09,160 --> 00:08:12,720 Speaker 1: the news a lot lately. But a lot of organizations, 139 00:08:12,760 --> 00:08:16,800 Speaker 1: a lot of the businesses that you work with already 140 00:08:16,840 --> 00:08:19,720 Speaker 1: offer multi factor authentication, but it doesn't come enabled by 141 00:08:19,720 --> 00:08:23,440 Speaker 1: default necessarily, So go into your settings, look for multi 142 00:08:23,440 --> 00:08:26,760 Speaker 1: factor authentication. They may call it two factor Authentication or 143 00:08:27,240 --> 00:08:31,600 Speaker 1: other names similarly and enable it. Also, make sure that 144 00:08:31,920 --> 00:08:34,880 Speaker 1: your passwords are are not easily guessed. Make sure that 145 00:08:34,920 --> 00:08:39,400 Speaker 1: you're not sharing passwords between multiple platforms because remember, if 146 00:08:39,960 --> 00:08:42,440 Speaker 1: one password is compromised, you don't want it to affect 147 00:08:42,440 --> 00:08:49,679 Speaker 1: you multiple times. Okay. And then finally, be aware of 148 00:08:49,720 --> 00:08:53,240 Speaker 1: your surroundings into the digital realm. Understand that you're scammer 149 00:08:53,240 --> 00:08:54,960 Speaker 1: on us out there and they're looking to take advantage 150 00:08:54,960 --> 00:08:57,040 Speaker 1: of you. All right, Charles Henderson, thank you so much. 151 00:08:57,040 --> 00:08:59,640 Speaker 1: Global Managing Partner, head of x Force at IBM, joining 152 00:08:59,679 --> 00:09:01,439 Speaker 1: us Vias Zoom from Austin, Texas,