Mather:ย Iโm thrilled that you all are here. My name is Laura Mather. Some of you saw me last night. Right now Iโm working in the very exciting human resources space, but my background is cybersecurity, so Iโm somewhat relevant to this panel.
But weโre not here to talk about me, which is awesome. Before we get started, I do want to point out that the way I like to run panels is, itโs all about you, right? Youโre here for a reason, and if there are questions you have or comments you want to make, this format is actually fantastic for that. So we really want to encourage lots of interaction. We have microphonesโI will tell you that if you raise your hand, youโre going to need to wait until the microphone gets to you because weโre recording this. But definitely we want to make this as interactive as possible.
So what weโre going to do is weโre going to start and have each of the panelists just do a quick introduction of themselves, start with sort of some overview questions, and then, again, the more this can be a discussion of all of this group, the better.
So, Todd, do you want to get started?
Simpson: Sure. Iโm Todd Simpson with AVG Technologies. You probably remember AVG from 10 or 15 years ago as the free antivirus on PCs. So weโre still a security company, but we actually now offer a lot more security solutions. We have approaching a hundred million users on Android, as well as all of our old PC base, and we offer not only antivirus, but a lot of other malware protection. We talk about doing devices, data, and people, and protecting your device, your data, and you as a human.
Mather: Great. Erin?
Cox: Hi, my name is Erin Nealy Cox, and Iโm an executive managing director with Stroz Friedberg. We are a cybersecurity and investigations consulting firm. Before I was with Stroz, I was a federal prosecutor with the Department of Justice for almost ten years, and that informed my job at Stroz. I was prosecuting economic espionage and cybercrime cases for the Department, and now as part of my responsibilities at Stroz Friedberg, I run the incident response unit, which we have teams of cyberspecialists that go into companies and assist them when theyโve been breached.
Mital: Amit Mital, Iโm the CTO and also the GM of the IOT and mobile businesses at Symantec. Symantec is the largest security company in the world, and we have a very, very interesting and exciting challenge and opportunity in front of us with what is happening with security, and also our enormous assets across the enterprise that we hope to leverage to provide better solutions for our customers.
Grossman: Hi, Iโm Jeremiah Grossman. I am the founder and CEO of WhiteHat Security. But please donโt let the title fool you; I am a hacker. [LAUGHTER] And not like the code hackers you might read about. Iโm the guy that actually breaks into systems. In my career Iโve broken into everything from finding vulnerabilities in Google, Facebook, Microsoft, and banks you probably use. So the company I founded, our mission is to secure the web, and we do that by finding vulnerabilities in the sites and the systems that the bad guys eventually will, and hopefully those issues will get fixed and the web gets to be just a little bit more secure.
Dennedy: Hi, Michelle Dennedy, Iโm going to hopefully have a voice for at least one more hour. I am the chief privacy officer at Intel Security, formerly known as McAfee. I guess I would also characterize myself as a hacker of processes and myths about data privacy. And so I do that during my day job. My team is responsible for compliance as well as product development at Intel Security. In my part-time free time I run a site called The Identity Project to help educate parents and other vulnerable populations about the real impact of identity theft.
Mather: Great. So what weโre going to do is start with just getting a sense of what everyone on the panel thinks is the state of the union with cybersecurity. I donโt like to go in order again, so, Amit, do you want to go first?
Mital: Sure. Thank you. So cybersecurity, and Iโd say the enterprise in particular, is at this perfect storm of need, opportunity, urgency. If you look at all the news that is happening in the last 12 months, with all the major breaches, you know, the number is escalating, the damage is enormous, and obviously, thereโs a bunch more thatโs not public.
If you think about why this is happening, one of the most fascinating things about security for me is that you have an active adversary, and so you have these really smart, really motivated, really creative, really agile guys creating amazing IP to steal your stuff and do damage to you. And we arenโt talking about dozens, we arenโt talking about hundreds, weโre talking about literally tens of thousands of people who are doing this day in and day out, and a breathtaking amount of IP created all the time. And so that by definition creates a huge demand for, quote/unquote, โthe good guysโ to create innovation. And so the opportunity for innovation is absolutely enormous. And because this data and the infrastructure that is being damaged is so important, security has now become the top of the CIOโs priority list. So as an engineer, this is amazingly exciting because itโs such an opportunity for continuous innovation, basically infinite amount of innovation. But also, from a business perspective, I believe itโs probably the most exciting place to be in the enterprise.
Mather: So let me ask something of the audience. When the panel was talking about cybersecurity, we were thinking about it in terms of sort of enterprise, consumer, and then even infrastructure as sort of a third category. How many of you think that the most threats right now are against enterprise or consumer or infrastructure? So how many people think the most threats right now are against the enterprise? A couple.
Washington: Are banks enterprise?
Mather: Yes, banks are enterprise.
Dennedy: Thatโs a good question.
Mather: Well, actually, no. Banks can be enterprise until theyโre starting to infiltrate the consumer accounts, right? So then it would be against the consumer is the way I look at it. So enterprise, a few. Consumer?
Washington: I think your questionโs artificially constrained.
Mather: Can we get a microphone?
Washington: So, sorry to disrupt your survey, butโ
Mather: No, no, no, this is good.
Washington: But, you know, your questionโs artificially constrained because ultimately what matters is how all of those, all three of those pathways eventually touch people. And if the enterprise is not secure, then individuals wonโt be secure, and if infrastructure is not secure, then enterprises canโt be secure. And I think a lot of people are living without a clear understanding that these three ecosystems are all intertwined, and we canโt forget that. And so one of my interests, and my hope is that we have some discussion around how do you thoughtfully address the vulnerabilities when not all of those vulnerabilities come from your domain of influence.
Mather: Ah, so when you donโt have control over it.
Washington: Yes, exactly. Right.
Mather: So thatโs actually a great question. And I want to be clear that, for this panel, weโre very thoughtful aboutโthereโs a lot of really scary stuff we could talk about today. But the good news is thereโs actually a lot of reasons to have opportunity and hope and innovation that is helping to protect, and so weโre going to try very hard to show you both sides of that coin, because it is not our goal for everyone to walk out and like close all their online accounts.
[LAUGHTER]
And is there another question or comment here?
Anderson: Yes, thank you. I agree completely with, I donโt know your name, but with what you just said.
Washington: Ken Washington.
Anderson: Ken. Yes, Iโm Mark Anderson, and I believe that the wisest way to look at the threat landscape today, or portfolio, is through what people are after. And theyโll use any technique, as you describe, to get what they're after. But they do kind of break cleanly into classes if you start thinking of them in terms of their own targets. And so if you do the card or ID thing, thatโs one group of very distinct criminals from a certain number of countries and places. And then if you want to go after people who are taking crown jewel IP out of commercial enterprises, youโd have to use bring your own device to do it, or supply chain to do it. Thatโs a very distinct group of people in different countries. So I think thatโs a very useful way of sorting this all out.
Dennedy: Can I just jump in with a point?
Mather: Please.
Dennedy: To sharpen that, I think weโve spent a lot of time, in the tech industry in particular, looking for magic fairy dust that will fix everything for us, and I think what we havenโt really done in a root cause analysis is to get at where I thought you were going, and I think where your comment goes, which is the reason that people used to rob banks is because thatโs where the money was. The reason people attack consumers, enterprise, and infrastructure is because thatโs where the data is now. And if weโre truly living in a data economy, we need to stop looking at data as (a) being free, (b) not being an asset, and (c) being some sort of an exhaust fume that comes out of the technology. Because thatโs what the hackers are after. Theyโre after personal data that they can leverage, theyโre after enterprise disruption because of information flow stoppages, and then theyโre up to no good in mechanical stoppages too, with mass SCADA system-type nation state attacks. But I think if we start to look at that corpus of what is the thing that we need to protect, I think it changes, and I think illuminates a new path of exploration for solutions.
Cox: And Iโm going to jump in there too. I think itโs good to think about what the hackers are targeting. But in my line of business, and this was true at the Department of Justice, and now at Stroz Friedberg, I have found that hackers are targeting almost anything. I mean the buckets have to consume every piece of data out there, right? And so you can certainly think about it in terms of buckets of information and who the threat actors are. But I also think, if thereโs any silver lining about the last year, 18 months, is the publicity that these high-profile breaches have, if you try and look at the silver lining of it, itโs that some companies that used to think they were never going to be targets are now becoming more aware that they in fact can be targets. You know, when I got out of the Department of Justice six years ago, I had been investigating these cases for years and I would talk to potential clients and they would look at me like I wasโyou know, this is โWar Games,โ this is not going to happen to me. And if thereโs one thing that we can say positively about what's happening, itโs that more and more companies have come to the realization that they in fact can be targets for any of the data in their networks, and hopefully that means progress in terms of awareness and security, because ignorance is not bliss in this area of the world.
Mather: We have a question there?
Westby: Hi, Jody Westby. Itโs kind of an add on, which is, in my work, and I do a lot of assessments of cybersecurity programs for large multinational corporations from top to bottom and that the threat environment is very sophisticated. It involves all the actors Mark talked about, still involves some random actors alone. It involves IP and sensitive, proprietary, confidential data, as well as customer data. And so, to me, I prefer to look at this as an enterprise risk, and you have to look at all of those because I see companies with vulnerable web apps and their website being exploited. They donโt have the right configurations on their firewalls, they donโt have the right network architecture. Thereโs so many different touch points that if you look at it as an enterprise risk and not try to break it apart, then you donโt end up maybe missing something that you should look at. Because you have to look at it overall, because the threatโtheyโre winning. Weโre trying to catch up. But to keep it as that enterprise risk and understanding the whole environment and all the actors and say, now, how do we best prepare for all of that?
Mather: Yes. Todd, did you have a comment?
Simpson: I was just going to comment that maybe architecturally weโre making it easy for people to target data as the asset. You know, we talk about privacy or best practices in collecting data. Weโve evolved into this world where every device you own, every service you subscribe to are these vertical silos that take all of our data and store them all in these nice rich cloud databases, which become very attractive targets. And so thatโs where a lot of the efforts go is to break into those large, large datasets. And so another component about thinking about the whole space is are we designing the systems correctly, and should we actually be stepping back and thinking about more distributed models as opposed to putting all of our data into multiple, multiple services and actually leaving ourselves exposed because of the way everything is architected today.
Mather: Did you have a question?
Audience: I was going to respond and say what about encryption, strong encryption for data at rest, data in motion, data in transit. It seems like we still seem to be walking away from that as being either too expensive, too cumbersome. Is that true, or do you think that we really should be able to move so that we really are living in a world in which strong encryption is everywhere?
Simpson: So Android and IOS have both started to step up to that, as well as on the web, HTTP-S systems are getting better and better. So weโve evolved from almost none to more, and I think itโs an accelerating trend. So I think we will see encryption much more widely deployed. Itโs just one layer though, right? Thereโs obviously attack vectors through the current encryption protocols as well, as weโve seen even fundamental in some of the algorithms, there are still being bugs found that were dormant for 25 years.
Mital: Let me add to that as well. Encryption as you know, thereโs a substantial user experience component to it. As Erin said, most people, they hear about the breaches, they hear about the security vulnerabilities, but few people, at least historically, believe that it applied to them, โIt will never happen to me.โ People were historically reluctant to pay the tax on the experience. Building it in the U.S. really helps because then it hopefully becomes a transparent to the user, but my belief is that, kind of this idea of DRM everywhere, everything being encrypted all the time.
Mather: Can you define DRM
Mital: Oh sorry, Digital Rights Management, as an approachingโ
Audience: How about PRM, Personal Rights Management.
Mital: Right.
Audience: My data.
Mital: PRM, yes, I think will be in the future one of the pillars of solving this security issue.
Mather: Yes. Go ahead Jeremiah.
Grossman: Encryptionโs got to be like table stakes, without a whole lot of crypto-communication. With data at rest, you canโt do much. Itโs necessary, but insufficient. Letโs say Facebook or Google, or any bank, has all of their data encrypted, an outside adversary like me itโs not going to matter a whole lot. Iโm going to use my browser. Iโm going to go to their website. Iโm going to take all the data out. Because the application has all the keys and thatโs the only thing that really matters. Who the adversary is that youโre trying to prevent with using encryption, itโs somebody with physical access to the machine or the ability to sniff the wire, mostly law enforcement.
Westby: One tiny point, which isnโt so tiny actually, which is one of the reasons people are targeting data and itโs so easy for them to target is because they donโt have people like Michelle in their companies.
Dennedy: Thank you Jody.
Westby: She knows how to integrate privacy requirements into the security program. Most people donโt so they have a privacy officer and they approach this as a policy/legal thing and they donโt really interact with IT that much. Theyโre not involved in the controls or any of the other stuff. In fact most companies I walk into donโt have a data inventory. They know they have PII somewhere, PHI somewhere, they have stuff, but they donโt know who all accesses it. Sheโs a big piece of this because sheโs a privacy person and an engineer background and she knows how to take privacy and get it in security programsโ
Dennedy: This was not a plant. [LAUGHTER]
Westby: โand thatโs one of the reasons data is so easily gotten to today. She didnโt pay me to do this.
Dennedy: I didnโt even know Jody was coming. Thank you. Just as a quick response, I wrote a book that is now an international best-seller which for textbooks apparently is a very low threshold [LAUGHTER]. But we open-sourced it because we want people to see our methodologies, itโs in the back of room if you guys would like a copy of the paper version. Itโs called โThe Privacy Engineerโs Manifestoโ and this is a conversation that weโve been having with various people around this room for many, many years taking what we knew from the 1960s in working with my father, whoโs a coauthor, using UML, using data mapping, using the things even the youngest of engineers and code slingers in hacker dens in high school even understand, business activity diagrams looking at the assets systemically, and then figuring out where does encryption really fit. What I found as a privacy person in the security industry isโand this goes to the lack of awareness, as Erin was pointing outโthat people believe if they can just put a little encryption Band-Aid on it and weโre done. โLook, yay! Reasonable security! I met all of the executive orders things.โ And theyโve totally not really looked at systemically at whatโs going on, what does this mean to my customers, what does this mean for ownership of data, and globalization. I thank you for that and I think the person or persons that you need are starting to retire now actually. I think we need the COBOL programmers, I think we need people that trained under Grace Hopper who started and said we have to have a systemic way of coding and not just to make it easy because we forked that way, but now how to make it sustainable. I think thatโs the big trend thatโs really exciting me today.
Mather: So we can take a question here.
Sprague: This is Kara Sprague from McKinsey. Building on the point that you were making and the fact that cloning technology doesnโt work yet, what are we doing in a world where every company is at risk, our critical infrastructures are also at risk, and we just have a severe talent shortage? We can talk about teaching developers how to embed security protocols into their code, but is there an easier way to do this thatโs simply based on hygiene?
Dennedy: Letโs start at the very top and I promise not to monopolize too much, but I have such a passion about this. After the Target breach what happens? We replace the CEO, then we hire a CSO whoโs in charge of your logical security. Weโve got now physical security, logical, and so weโre holding ourselves like this where he can just sucker punch you in the face. Whoโs sitting on that board of directors now? Whereโs the chief privacy officer? Whereโs the data asset and risk and management person? On every board in the U.S. they should have gotten scared. By January 1 we should have had every CEO calling these recruiters for the next board seat saying, โWho knows about data asset management? Who knows aboutโ?โ I mean, PII, personal identifiable information, is a form of IP and we can all agree that IP, intellectual property, needs to be protected. Where are we sitting on our governance? That, I believe, is the one move that will trickle down. It starts with leadership.
Mather: And I have some data on thatโand weโll get to another question. I went to an event by โAgenda Magazine,โ they have the magazine for board members and they polled the Fortune 5000 and of those 126 companies had a risk management board member on themโof Fortune 5000. When asked if that was a priority of the next board seat the overwhelming response was no. Just a little data about how the boards see this. We have a question in the corner?
Anderson: Yes. Iโd like to go back and underline what Jody said a minute ago and I think all three of these comments. If you look at this from the human beings side of things itโs absolutely right the board is the fulcrum for this. I donโt know whether itโs the SEC with a little tougher view forcing disclosure of all kinds of things that will get the board on board, so to speak. Thatโs got to happen somehow. They really have to be afraid for their own personal safety in terms of liability I think before they take action. Theyโve got to understand that they have responsibility, just like a fiduciary responsibility, to the shareholders, to protect those assets. Theyโre not acting like that right now. We see it if you survey of CEOs and CSOs, whatever you want to call them, thereโs this huge distance between what the CEO will say whoโs in denial, saying that, โMy Companyโs is fine. Doesnโt need anything else. Weโre spending enough now.โ And then the chief security officer will say, โAbsolutely not. We definitely need to spend more. Weโre not good.โ These guys know each other, but they donโt agree somehow. The boards job is to fix that. The deeper problem, I think, comes back to what you were saying, Jody, we have to identify the assets, so you said it very well I thought. We work in this all the time and the questions is, If I go to any CEO, Ray Ozzie and say, โWhatโs your crown jewel IP?โ Almost no one can identify what that is. They have not been through the project of talking to their top people and actually physically identifying where is it stored, and how is it accessed, what are the policies about those particular five people, instead of 5,000 who have access to those things. Those things havenโt been done properly. Just understand, if youโre a law firm and youโre going through a merger with someone in China, guess what, youโre going to get hacked. Have you put those documents and those bid numbers into some place thatโs unplugged from the internet? No. Okay. Then your guyโs going to lose. Itโs really important to identify what is the IP for Coke, or Ford. And trust me, Ford doesnโt know. So, no one knows.
Cox: Kenโs going to know. Heโs only been there two months. [LAUGHTER]
Anderson: You and I talked about this before I think. And Ford got hacked after our last conversation. Weโll have that conversation later. So anyway itโs a big deal and I think itโs a human thing and the boards have to apply the pressure, but then the CEOs have to put the pressure on their staff and say, โLetโs identify this important stuff and letโs sequester it, and restrict access to it.โ
Mather: Yes, but letโs be clear. How many direct reports of CEOs would say, โNo, Iโm good. Iโve got plenty of budget.โ I donโt think any of them would, right?
Cox: And just to be clear what CIO is going to go before the board and say, โWeโre in a lousy position.โ What CSO is going to do that? Itโs inherently counterintuitive for those individuals to be there saying, โYes. We have real problems.โ The CEO is not going to do that. Some of it, I wanted to echo a point that you were making which is, it is an enterprise issue, but what I found over the years that Iโve been working for the private sector clients that have these problems is, ultimately theyโre getting better. The CSO position didnโt really exist five or six years ago accept maybe for some financial institutions. Now weโre seeing more CSOs. The chief privacy officer as well. Weโre seeing that companies need to think about it in a multidisciplinary way. Itโs not just an IT problem and itโs not just the boardโs problem, it is actually almost every stakeholder within the company: corporate communications get involved because itโs a crisis, the CFO gets involved because itโs an unbudgeted expense, CEO obviously gets involved, the chief privacy officer gets involved, and all these people, and of course chief legal officers too, because of all the liability implications. So if all these people in a company are echoing the sentiments youโre echoing, which is this a huge important issue for our company and trying to get both the best inside and outside experts to help them with it, theyโre going to be in a far better off position.
Mather: And it sounds like people are moving forward with that. You had a question and then weโre going there.
Washington: Yes, so I had a question Iโd like to ask the panel and address this. My nameโs Ken Washington and Iโm the vice-president of research at Ford. Six years ago I was asked by my company at the time, which was Lockheed Martin, to create a privacy program. I was a former privacy officer. Through that experience I learned the importance of not only doing this from a governance point of view, but the fact that we were creating something from nothing because no one had given it any priority before and the hardest part of protecting the data and the information, and building a system which could be responsive was the fact that we already had a bunch of infrastructure, and a bunch of architectures that were already in place, and so youโre trying to Band-Aid or patch something that was fairly complex, and already had significant amounts of cost sunk into it, and had a lot of momentum into it. This is not unique to the company I used to work for, which is the heart of my question, which is: how do you deal with the fact that youโre dealing with immense amounts of legacy and a huge amount of momentum in a systemโif we had the architect, the governance, and the technology architectures to mitigate the risk today from nothing, it would be a whole lot easier. It wouldnโt be easy, but it would be easier.
Cox: Startups have it easier?
Washington: Startups have it a lot easier. Right. But most of us donโt have that advantage and Iโm asking from the point of view of the challenges I now face at Ford which is, the automobile is about to get more connected than ever before and itโs in a situation where we can get it right the first time because no one had been thinking about cars as nodes on the Internet before, but now thatโs going to be the case. So, weโre going to be architecting our solutions with the knowledge of the fact that we have to do it right the first time, and weโre committed to that, and I have the background from my former privacy officer and security days to do that. But Iโd like to hear the panelโs thoughts, and maybe anyone else in the room regarding how do you deal with the fact that you have all this momentum and built up architecture, because you just canโt rip it out and start over again.
Mather: Go ahead.
Grossman: I had this exact problem idea where every single day no one empathized with this more than the web security expert. Yes itโs all nice to have that conversation about how do we build more secure systems, but itโs devoid of the fact that the webโs already built and so now what? If youโre up against professional hackers, guys who do this for a living, this is how they make their money, I always bring the bad news, the bad news is youโre going to lose. Youโve got two choices, two strategies. One is, how do you increase their costs, because theyโre on an economic scheme too so you have to increase their costs economically through whatever means possible, you know, security with obscurity if you have to. The second thing is fast detection and response. Most of the damage thatโs done after these breaches, pick your favorite Fortune 500 breach, the breaches only causes damage because the bad guys were on the systems for months. If you can detect the breach within a few hours or few days, a compromise, and kick them off the systems, or get them out, itโs almost as if you were never breached because the bad guys couldnโt really profit a whole lot. If you gave me root access on a bank it would take me a long time before I could figure out how to get access to the mainframe system and extract money. Itโs very difficult to do that or to extract a gigabyte worth of information. Its fast detection and response and then the ROI changes.
One other point. One of the things you have to understand is that black hats have economics too. Imagine youโre a CSO and you have a million dollars to spend on defense. What does the bad guy have to spend to beat your million? Right now itโs probably no more than $100 to $1,000 dollars. If we start looking at our defenses, whether the product services or strategies we employ, the more we can bridge that gap and bring that closer the more successful weโll be. Right now itโs just off. You can beat, right now, pick your Fortune 500 Company, a day, no more to break into, thatโs all it really takes.
Mather: Anybody else want to comment?
Mital: A couple of things. I fully agree with you Jeremiah on the ease of entry. Not only do the bad guys have to spend a lot less, but if youโre playing defense, which is what youโre doing when youโre protecting stuff, you have to be right all the time without really compromising the experience youโre customers have. If youโre a bad guy youโve got to be right one out of a hundred, one out of a thousand times, youโre still ahead.
Cox: I like say that bad guys donโt have to do QA. We have to do QA [LAUGHTER]. It sucks.
Mital: Thatโs one. The other thing is that the very thing that makes life easier for developers: a stable, homogenous, consistent operating system also makes it much easier for the bad guy. Because in the end theyโre writing code and writing applications. Thereโs a way to change the targets, constantly change the targets, obfuscation, polymorphism. Maybe thatโs one of the interesting avenues that people are investigating as well. So you level the playing field so that their economic cost is equivalent. Iโm not sure how well that works for state sponsors because they have mostly the deep pockets, at least you begin to dent the conversation.
Dennedy: I have another point thatโsโ
Cox: One quickโIโm not going to reiterate. I agree with everything that has been said. I would challenge a little bit that startups have it easier. In theory they have it easier which is they have new systems and they have new technologies they can deploy. But I would suggest to this group the tech sector is one of the most targeted sectors that we have and thereโs not a lot of people talking about it because itโs not like a retailer or a hospitality where they have mandatory disclosure. But we know thereโs very valuable IP thatโs happening in the tech sector thatโs being targeted by hackers all the time. And they often have bad security programs. Startups have the worst security programs.
Audience: Theyโre not putting any energy into it.
Cox: Thatโs right, because all their energy is into growth and R&D and hardly any of the energy is in security.
Audience: But thatโs by choice.
Mather: This personโs been waiting.
Kvochko: Elena Kvochko, Iโm from the World Economic Forum and Iโm responsible for oiur cyber resilience program. Talking about solutions, I would be interested to know, in your opinion, who do you think should drive the agenda the cyber security agenda? Who do you think should drive security of the online environment? Actually last year we did an executive survey together with McKinsey where we asked about 300 companies what they think, who they think should take the primary responsibility, and the results were quite surprising. We have a such a diverse panel, fast growing companies, we have government perspective, we have industry leaders. So, if you were to pick some leaders who would you choose? Would it be law enforcement, public sector vendors, private sector corporations, and I guess probably youโre tempted to say, โWe should collaborate,โ but if it was sort of a forced ranking who would you pick as sort of the primary driver.
Mather: Iโll make them choose one. You have to choose one. [LAUGHTER]
Simpson: Iโll go and then youโll get some maybe better answers because weโre a consumer security company. We actually think a lot of this starts with having smarter users. Thereโs a lot of tools available to users where they can actually do a lot better jobโ
Mather: I thought you were going to say; weโre a consumer company so we think itโs the government [LAUGHTER].
Simpson: No, I think, obviously thereโs a lot of education that goes on in enterprises around privacy security. Thereโs also a lot of education to go towards the end users. We have a lot of tools and we have a lot of techniques that can actually make end users a lot more secure which makes a lot of data more secure etcetera. A lot of the attacks are still social engineering attacks. So, just password managers, real basic stuff that we have, but users donโt deploy or use properly. Weโre actually starting this initiative called Smart Users as opposed to smart phones, so if the next two billion people come up on their smart phones weโd also like them to be smart users. We started this and would love to have other people help us, launched at the Clinton Global Initiative to start working with the ecosystem to put better tools and smarter users behind the smart phones.
Mather: Does someone elseโYou have to say one. You canโtโ
Cox: Okay. Iโll say one. Iโm not going to pick the government because if weโre relying on the government weโre going to be woefully disappointed [LAUGHTER]. I think it has to be the private sector and doing it on behalf of their clients, and their consumers, and their customers. They have to be the leaders and I think that everyone has to be willing to give up some of the convenience. Security always comes at the price of convenience. Encryption is just one example of that. I think everyone has to be willing to give up some convenience to be more secure.
Mather: Other thoughts?
Grossman: Would you believe it, Iโm a security person, I donโt trust anybody at all to do this. [LAUGHTER]
Mather: We have another question here.
Audience: I love the name of this panel which was โCivil Defenseโ because the first thing that came into my mind was air raid sirens going off and everybody running down into the shelters.
Mather: You donโt hear that. [LAUGHTER].
Audience: No. My question is what makes us hear the siren going off? Running down into the shelters is not the answer and that whether itโs going to be civil defense itโs something that is beyond just the individual corporations because I donโt think the individual companies can do it on their own. But I do believe you can enlist an army, thereโs a lot of developers out there who have a lot of new ideas about how to make secure containers with virtual machines as everything moves to the cloud. I think we were saying, build forward. The legacy problem is just a horrible problem to solve, but building forward we could, I believe, have the technologyโmake some advances in technical solutions to this. If we were to enlist the entire civil defense core for the Internet and for the digital age, and itโs going to take that kind of rallying cry to do it.
Mather: I think I start to hear those sirens going off. Security budgets are going up, is what Iโm hearing. I think some people said that earlier right? Weโre not there, but itโs much better than it was five years ago.
Mital: It was three weeks ago Jimmy Dimon the CEO of JPMorgan says heโs going to double his security budget in two years from a quarter billion to a half a billion dollars.
Dennedy: And meanwhile he busted his CPO down to director from VP. Itโs this teeter totter of when does the siren ring and what is our answer to the call. Are we going into a bunker? Or are weโI like the answer very much that Todd gave and actually AVG had a great book out for digital childrenโs, parent protection which I canโt think of the name of it, but it is good. I liked it. But I think thereโs a couple things. One is, as Barton and I were discussing this morning, one of my feelings about Ed Snowden and his whole activities, I was ticked that it wasnโt me. Iโve been crying and begging for people to care about this for almost two decades now and I was pissed that it wasnโt us that rang the siren. What will be the thing? How much worse does it have to get? I think the answer is we have to do the Randy Pausch head fake. We have to go into schools and we have to talk about STEM. Thereโs a lot of money being spent on STEM and I think one of the most exciting careers, deeply biased myself, is in tech, is in cyberism, is in civil obedience, like massive civil obedience.
Mather: Can I make a point about that? CSI is actually coming out with โCSI Computerโ in the next four months. Patricia Arquette is the lead actress and I think this is amazing.
Dennedy: โScorpionโ has just come out and โHackers.โ
Mather: I think when CSI launched, the increase in people doing forensic science was like 1,000%. This can help. The media supporting this is also helpful.
Dennedy: I think so too and I loved when the โBig Bang Theoryโ came out because they talked about encryption stuff, but of course the portrayal of women is just abysmal. But I do so want to make [LAUGHTER]โI know, weโre not actually all stupid. Itโs shocking. We can walk and talk. Now I know the portrayal is like these [LAUGHTER] I know. I married one of those guys who is just like that guy, so I have a soft spot in my heart.
But I also wanted to respond to the question too of balance and I think we are giving this a very Western perspective because I think having these same conversations last week throughout Europe, which is why I sound like this, I think the answer there would be government, and government and heavy regulation, particularly in the civil law countries over there. I donโt think thatโs necessarily the answer because I donโt think it opens it up to this open self-defensive, self-knowledge, I donโt think thereโs any big daddy thatโs going to come and save us in big data. I think we need to figure out how to make kids smart about ethics, and morality, and legality, and technology, and I think all those are great careers. Talking aboutโunder programs such as the Department of Education and the Entertainment Network weโre launching a huge thing on Thursday, Iโm probably not supposed preannounce, but weโre going to hit 50 million kids this year and teach them how to be safe online. Iโm very passionate about that. Yay!
So, Iโm really passionate about it, but I think. I donโt know to this point, whatโs it going to take for people to care?
Grossman: After you have your first heart attack you buy some running shoes and thatโs pretty much how it works. Information securitiesโit doesnโt have a whole lot of, thereโs no dead bodies yet. Yet. I donโt like to bring this news forward and be doomed, but that will be an eventuality. Weโre going to have pacemakers with Wi-Fi access
Audience: Andthe infrastructure hasnโt been kept up and thatโs where Iโm afraid.
Grossman: Medical devices running Windows XP.
Cox: Imagine if you could get control of the Presidentโs car, right?
Simpson: It comes back also architecturally. I donโt need my thermostat to go to the cloud to control my furnace, but thatโs the way the world is being designed to think.
My thermostat should talk directly to my furnace. Architecturally I think weโre on the wrong foot right now. We back up everything absolutely to the Cloud which means that all of that data is always accessible. Data should be routed appropriately as close as it can to the use case.
Mital: The thing I wonder, the cultural question I wonder from a consumer perspective is; our banking and our credit cards infrastructure in America anyway, is set upโI think the maximum liability is only $50 bucks and not even really that. So you know that even if you get hacked, whatever, as long asโ
Cox: Yes, weโve incented consumers the wrong way.
Mital: Yes exactly. The consumer say, โOkay. Well I might get hacked. Itโs unlikely because thereโs so many other people, but even if I do Iโll be made whole by my bank.โ Thatโs one. Then somebody breaking into my identity and stealing my pictures, thatโs a Paris Hilton problem, thatโs not a โmeโ problem.
Denndy: Now itโs Jennifer Lawrence.
Mital: Jennifer Lawrence, exactly. Thatโs a problem most people wish to have is that theyโre that famous that somebody wants to steal their pictures? For most people that issue, at least culturally, the downside of the liabilities arenโt quite there. Once we get into this IOT world where my car traveling 70 miles per hour down the highway has the same energy as a stick of dynamite, which is true, itโs a megajoule, then suddenly Iโm, once something happens there then the conversation changes, but thatโs a debilitating conversation.
Mather: I want to point out that weโve only got around 10 minutes left so if thereโs any questions you guys really wanted to ask that hasnโt gotten asked, please speak up, but weโre going to go here and then there, and then I think thereโs one over here. So, weโve got a line, butโ
Gellman: Iโm Bart Gellman and I want to be a Johnny One-note, I did want to ask the other panelists about the implications of Michelleโs point on Snowden and how it relates. I know security folks talk a lot about threat models and if youโre representing or if your clients are principally big enterprises worried about their IP, I understand why the U.S. government isnโt a big part of your threat model, but to what extent does the Snowden revelations have any impact on the threat, the mitigation possibilities or your thinking about how to protect what youโre trying to protect?
Simpson: Again,I think we should be deploying a lot more peer-to-peer technologies, less centralized systems. Before AVG I worked at Mozilla on WebRTC, which is a generic peer-to-peer thatโs deployed now by Google and by Firefox, so itโs in a billion web browsers around the world. We should encourage people to use technologies like that, fully encrypted peer-to-peer, when they develop services that should be deployed that way.
Mather: That brings us back to, I think it was Jeremiahโs point, you were just making it more expensive right? Because you have to hit multiple spaces.
Grossman: I can tell you what our customers tell us, WhiteHatโs a cloud provider, we host very important data and our international customers, letโs say in Amea, they want us to host and have entities in Amea and their data doesnโt leave. Rather than having all data in the U.S. where we get economies, efficiencies, thereโs now a lot more data being hosted outside the U.S., thatโs not good, bad, or otherwise that is whatโs going to happen.
Gellman: Probably misguided in terms of trying to defend yourself from theโ
Mather: Can you say it into the microphone? Sorry. What was that?
Gellman: I was going to say thatโs probably a misguided instinct if youโre trying to protect yourself from the NSA.
Grossman: You have to remember many of these Fortune 500s are multinational conglomerates right. They donโt trust the U.S. government. They donโt trust the NSA, so the extent that they can remove the data outside their jurisdiction thatโs what theyโre going to do, right or wrong, thatโs what theyโre doing.
Gellman: Theyโre opening additional legal and technical doors to the NSA by keeping it under the U.S.
Grossman: Known risks verses unknown.
Mather: Well also where the NSA can spy versus canโt.
Mathews: Iโm Dave Mathews, Iโm a reformed hardware hacker. Iโm using my powers for software now [LAUGHTER]. A couple things. The phrase, โWeโre from the government, weโre here to help you,โ was always a favorite of mine. I was with the CIA of Estonia last month and they had a country-wide denial service attack because the whole country uses smart cards for everything, from driver license to payments, etcetera, and they literally killed the switch that brought the Internet to its knees because of the hackers going after this small country. That was interesting to hear. A couple days after that I interviewed the kids from LulzSec, which is a pretty notorious hacker group out of Northern Europe and some U.S. ties too. We did a live hack on stage with a project with the Mayor of London. I gave them access to hack my WordPress site. I said, โIn the past HTML was flat. Now weโre all database-driven.โ And these kidsโthe preview before the hack, we were hanging out at our friendโs flat, and they were like basketball players, one of them would use a laptop for a minute, theyโd volley to the next one, the next one would hammer, and what they came up with was this injection that looked just like my domain name and it wasnโt a phishing scheme, but itโs amazing these vulnerabilities that these kids find and they just go at it with such precision like a highly tuned team would. The reason why I think weโre in dire straits now as we have all this intellectual capability with kids going after vulnerabilities, but right when broadband put every Windows machine on the Internet then those became botnets very quickly from people sending an email out. Weโre about at that point now where the IoT world is going to turn that in with a refrigerator or television thatโs sending SPAM email messages. How about the network detached storage servers that are mining bitcoinโ
Mather: Just to be clear, IoT is the Internet of Things, in case anyone didnโt catch that. Sorry.
Mathews: So, the NEST thermostat doesnโt need to talk to the cloud unless I want to turn my Tahoe house heater up because it takes 12 hours to bring it up to temperature. The problem with the startups is they donโt put money into R&D and security. Thereโs Internet-connected light bulbs that are putting the WPA keys in the clear. I think we need not only a best practices, maybe like a security consultancy that anyone can say, โHereโs an open source set of rules to go by.โ But also I think ultimately this plays into the operators, so the cable providers, the Comcast Xfinity router which gives this extra capacity for someone else to jump on to my Wi-Fi as well as my own protected network, but those guys are the gateways. There the ones keeping the packets either in or out of the house and if my NEST thermostat is going crazy and my network attached storage device is mining bitcoin, and we detect these anomalies, those are going to be the only real ways we can stop this or turn it off because the government is not going to kill Americaโs Internet.
Dennedy: Just a quick comment back. On the kids that can do this kind of hacking, first of all, I think of the cement guy this morning, did you see the cement guy rolling out his thing? How many billions of dollars and fossil fuels have we burned with cement trucks that had liquid in it? All he did was desiccate the cement and water it and thatโs a huge innovation. I think some of these hackers, if we can figure out how to remove the water, the chaff, the waste from some of this data, thatโs a business. How do we get these guys into the business? The other quick point I wanted to make is the investment community throws and we catch as companies doing M&A and I think minimal viable products has to have a basic privacy and security infrastructure. Itโs easily done. We did it with my nephew over a weekend with one pizza and weโre able to take his app and turn it into an architecture that can be shown to a VC. This can be done, this can be taught, and I think thatโs a minimum viable product. I think we shouldnโt be funding things that arenโt and we shouldnโt be buying things that arenโt, and we certainly at Intel are punishing company that come to us with crap.
Mather: Todd did you have a question?
Simpson: I just want to come back to that we as consumers have to choose smarter products otherwise the startupโs incentive is just to move faster and ship garbage. We have to educate people and we ourselves have to actuallyโ
Dennedy: Thereโs always the WhatsApp unicorn thatโs haunting us. โOh, look, itโs garbage.โ
Simpson: We have to make privacy policies readable.
Mather: And when you say consumers youโre saying enterprise is consuming?
Simpson: Enterprise is consuming or end consumers. We just have to make smart choices
Grossman: So, we should recognize we make it the telecomโs or the ISPโs responsibility to secure the pipes then theyโre going to have to terminate SSL. That has a very real consequence. I donโt know if we know what that leads to.
Mather: Yeah, letโs get back to the whole encryption thing.
Audience: Why is that?
Grossman: Because they have to be able to see the data. If itโs all encrypted, every IoT device tunnels through. Fortunately, what IoT gives us is more targets, more things to hack, but fortunately it doesnโt increase the bandwidth utilization. Thereโs lots of more things to hack. But the other thing, the thing no one likes to talk about is the liability aspect, the reason we need minimum secure certified products is because we have this little thing called the EULA that purposely disclaims all liability over crappy software. When that goes away weโll get more secure products. The EULA is killing us.
Mather: Define EULA please.
Grossman: Iโm sorry?
Mather: Whatโs the acronym?
Grossman: Iโm sorry. End User License Agreement.
Simpson: The thing that you click through on software?
Grossman: Yes, that thing.
Cox: I would agree with you. We have to have minimum standards of security. Iโm conflicted about that though because once you impose this minimum standard it becomes a compliance regime as opposed to a security regime. That is the danger in that, is that companies just comply with the compliance regime, they say theyโre secure, and theyโre not actually paying attention.
Mather: But isnโt it better to have that instead of nothing?
Cox: I agree with having nothing, but my concern is then you shift to more of a compliance.
Simpson: Youโre just checking the boxes.
Cox: Youโre just checking the boxes. We see this with PCI/DSS.
Audience: And wonโt spend any more than the level to be compliant.
Anderson: Iโd like to be a bit of a wet blanket at this point.
Mather: No no. Canโt allow that. Sorry. [LAUGHTER].
Anderson: I forgot your name, I think the head of WhiteHat has made a most important statement of the day which is, โHe can hack into any corporation in one day.โ Iโll just tell you a little story that is not classified. Iโm telling you what I said, but I was talking to Sir Iain Lobban, who until recently was the head of MI5 and GCHQ and heโs a pretty smart guy on this subject. He was talking about how Britain was doing really well and itโs true, in working with business, government and businesses together to solve these problems. He said, โWeโre going to solve 80% of the hack problems when we get all done here.โ I said, โThatโs great, but youโre not going to solve any of the APT threats that are going after crown jewels that are important in the global economy. Itโll be 100% failure for that tip of the pyramid that matters the most, so donโt pat yourself on the back yet.โ I think, from what you said today, thereโs nothing wrong, I agree with everything youโve all said, but the big problem this is insolvable. Itโs a radar trap problem and every time you improve the radar detector they improve, you knowโthat game never ends and it keeps all of us getting paychecks. But if the real goal is security for the enterprise or security of some kind, I donโt see it. I think weโre all talking about the wrong things. I donโt think anything that weโve talked about today will provide that. I guess the question Iโd like to raise is: is the whole system, weโre kind of at that moment, is the whole system just not protectable? Then weโve got to start from scratch in some other way. Because this system that I see, even before the IoT happens, no one can protect it. WhatHat can go in there in one day? And thatโs not going to change I donโt think.
Grossman: When it comes to hacking systems if youโreโIโm from Hawaii, so if youโre in the surf lineup and a shark comes, you donโt have to outswim the shark, you have to outswim the other surfers. Same is true in security. So that means you have to be a little bit more secure than the next guy with an opportunistic target. If you are targeted then and the shark just wants to swim and eat you, well then you have a different problem all together. But fortunately we donโt have to make truly impenetrable systems and spend the ungodly sums of time and money to do it. We have to make them time-wise a little more secure. The distance between 10 minutes and 15 minutes matters a great deal and Iโve seen this in personal experience, if you make systems 20 minutes secure the bad guys will go elsewhere. Theyโre in an ROI model as well, thatโs why they cast wide nets across the Internet. But if youโre targeted, thatโs anotherโhopefully youโve made your systems difficult enough where you can actually see the bad guys and watch them win and then kick them off. Thatโs what youโre looking for. Youโre looking to make it expensive and noisy.
Mather: And maybe we just havenโt got to the place where we have the dead body yet that requires the reboot of the system. Maybe just to bring back the conversation that happened early. Do you have a question?
Audience: Yes it was actually two comments. Number one, I agree with you on the dead body. I actually think that as much as we would like to educate and have smarter users, etcetera, itโs going to be the 9/11 equivalent thatโs infrastructure attack that actually wakes people up because people are insulated on their credit cards and they donโt really care a whole lot about their personal information anyway, but if suddenly thereโs a fire or a reactor accident or something that impacts people more dramatically, that will change the conversation, likely. And itโs going to happen. You know itโs going to happen. On the โapp developers are sloppy and thereโs no real encouragement for them to do it,โ I would merely put forth an idea that although I am strongly against government regulation of these things there are a couple of entities that represent really good choke points that if they encouraged developers to go through a specific audit in some way, shape, or form, it would be very effective: Apple App Store, Google Play Store. If they want to insert a certification requirement that one of the following handful of organizations for $1,000 will just do something. I donโt know what. Just donโt rule out the fact that they do have a very powerful position in the ecosystem right now in terms of encouraging developers to do best practices.
Mather: Thatโs a good point.
Audience: We keep talking about the bad guys as if itโs an amorphous mass. Is it bigger than ISIS? Is it a couple million people? How many people are we talking about? How quickly are they recruiting?
Mital: It depends on ways thatโwe know of many organizations that the commercial power of businessโLet me back up. Thereโs basically three general categories: Thereโs state sponsored guys, the numbers vary and I donโt really want to get into those things. There are the people who are commercial hackers, and thereโs leakage between the state sponsored guys and commercial hackers and that number is in the tens of thousands. Then there are people in the general category of activist hackers, sort of weekend hobbyists who want to do it for notoriety or fame or whatever, and that number varies. Is it somebody whoโs testing a system in college? Then it could be in the millions, but really the people that are actually doing it is probably on the order of many tens, maybe hundreds of thousands.
Audience: What would normal law enforcements say about how you counterattack?
Grossman: You mean actually counterattack them?
Audience: I thought when people were talking about dead bodies it was making examples of people who were doingโ
Grossman: No, actualโ
Mital: Somebody getting hurt.
Audience: Iโm being facetious [LAUGHTER]. Iโm just wondering under normal circumstances, we have a government here who will go out and kill a terrorist and say, โThis is what happens to you when you attack American soil.โ Maybe weโre neglecting more extreme methods of dealing with this, not that you can deal with the Chinese government because I think youโre in a mutually assured destruction situation there which is analogous to nuclear war, but I think in the case of hobbyists thereโs going to be more effective counterattack measures than, โGee there are millions of them having fun in their college dorms.โ
Grossman: Itโs an attribution after a cyberattack gets really, really difficult and if youโre using truly extreme measures, be guaranteed Iโm going to use them against you. Iโm going to start targeting other people, weโll make it look like them. So with the attribution itโs really challenging. But the other one, just a different way to count the bad guys, I used to work in Yahoo way back when and at the time we had 120 million active users. Our data says that roughly 1% of our users were malicious in some way, not just hackers. It was a quite a lot. It was spammers and other deviants and things like that. It was a lot. So, attribution is key. We should go after very key bad guys who cause a lot of damage, but weโre not going to be able to catch everybody. It just doesnโt scale with law enforcement, not one at a time. Theyโre going to have to prioritize and they kind of do already.
Mather: We have one more question and then weโll do a little wrap up.
Audience: My question, thank you, it was really in his direction which is unilateral offensive behavior by private parties is impermissible. Is it technically possible and what would it look like in a general way? And should we be talking about that because if weโre talking about critical infrastructure and problems around a perimeter defense strategy Iโm sure firms are deeply thinking about what kinds of things should they be doing that would have a more offensive character. If we could engage that question.
Grossman: Digital self-defense brings up a whole category of issues thatโs really, really tough. Itโs attractive, but itโs also tough. Itโs not like protecting oneโs own life. Usually a lot of times when youโre getting attacked by a system itโs onโWhat happens if one Fortune 500 company sees themselves getting hacked by another Fortune 500 company, what do we do then? So thatโs a challenge. I donโt think thereโs a really good answer. Thereโs plenty of dialogue, but I certainly donโt have any good answers on that one.
Mital: Translating a cyberattack to a kinetic response is a very dicey thing to think about. I mean today the world thinks about kinetic, sort of physical responsesโ
Mather: Military responses
Mital: โmilitary responses. Thatโs very separate from cyber. I donโt think thereโs any document there yet other than within governments on how that maturation โฆ happens.
Mather: Right.
Dennedy: But I saw something where we are doing tactics like so like in Brian Krebs whoโs a journalist really, and weโre constantly monitoring the darknets, weโre embedding with these people, weโre trying to figure out how, why are people in LulzSec, what are they motivated by, how are we dealing with these guys. I think itโs almost like thatโs the jawbone, if you will, of the cyber complex. And to your earlier point why I think that is a scratching, but still something is I think the only industry more pointless than security is healthcare. And yet, itโs pretty good to be here in much better condition than to actually try to maximize what itโs like during our shelf-life of approximately 100 years. Weโre not going to be able to do a total reboot unless weโve had complete Third World War Armageddon with data so we have to get as healthy as we can, we have to educate people, we have to eat our broccoli, weโve got to test out the systems. And then we have to figure out the dicey issues, which is where your question really is going, which is if I as an entity or an individual think that you are attacking me and I attack you back so I shut down your email because I see itโs coming from your IP address, but it turns out it was this guy over here because heโs out there swimming against the sharks trying to get me into a bad position, you get into all sorts of very difficult legal tangles, if you will. But I still think itโs worth it.
Mather: All right. Unfortunately weโre out of time. I want to ask the panelists to quickly say what theirโweโve talked again, a lot of doom and gloom, and I promise we would come back to what is working, so Iโd like to ask the panel to say what theyโre most hopeful about or excited about, or see the most promise in. Todd do you want to start?
Simpson: Sure. Again, from the consumer viewpoint. Quick comment, our houses are becoming like small businesses. We each have some 20 something devices connected and all these solutions. Weโre early enough in that curve in our personal lives that I think thereโs time to adopt solutions that make us as small businesses actually more secure and more private, and appropriately protected.
Mather: It gets to the lack of legacy thing.
Simpson: Yes.
Mather: Erin?
Cox: I think that the battleground has shifted from guarding the perimeter to actually recognizing as soon as possible when you have an attacker in your environment. I think thatโs where the focus needs to be. Iโm not suggesting you shouldnโt guard your perimeter, you should, but I thinkโIโve investigated cases where the attackers have then been in environments for months and months and they just have the opportunity to do more and more damage. So I think if we can shift our focus to making sure we identify them as quickly as possible and kick them out, theyโre going to have lots less opportunities to damage the environment.
Mather: Amit?
Mital: I think privacy and security are a triumvirate of policy, people, and technology. On the policy side, awareness is growing dramatically and people are much more open to the idea of being adherent to good hygiene. On the people side, for most security things we see, people are the biggest problems, either they do sloppy thing, or they have a weak password, they misconfigure stuff, so education can help and I think things are improving there as well. The thing Iโm most optimistic about, being an engineer, is the technology side. I do actually believe if you can solve the first two there are actual technological solutions that are feasible and workable that certainly dramatically improve the situation, maybe not 100%, but dramatically.
Mather: Jeremiah?
Grossman: I started hacking websites 15 years ago and that long ago was pretty easy within minutes. Now most of the major websites it takes you substantively longer. Things are moving in the right direction there. But also just wanted to give a shout out to the Ruby on Rails guys. Youโve heard of this little vulnerability called SQL injection? Itโs the cause of most of the compromises out there. We have yet to find a SQL injection vulnerability in any Ruby on Rail sites weโve ever tested. The sample site is smaller, talking a few hundred here, but thatโs a big deal. That one cause, thatโs getting rooted off the face of the planet in the Ruby on Rails world. Those guys, keep up the good security work.
Mather: Michelle?
Dennedy: I think, although Iโm not an optimist, Iโll completely pander to our moderator. I think one of the things that makes me very optimistic is the diversity question is starting to be addressed. The reason I think thatโs so important is the carbon-based unit is the biggest risk factor, thatโs us. If we donโt address different thinking, if we donโt address context through, if I have to see another dropdown click, weโre going to keep talking about inconvenience for security, but if we find beautiful iconery, we find music, if we find contextual smells where a puff of alcohol comes out of your phone when you go on a health app, I think weโre going to get to a different place. We have to really break this model. I think the other thing that is the most important to me is that weโre starting to see value in information in and of itself. I think value drives markets and marketโs drive behavior, and behavior drives a greater drive to more technology, and better technology. I think itโs a very wholesome cycle that weโre on, even though weโre all going to die, weโre going to live better while weโre on the planet.
Mather: Just to follow up on that I do want to point out that weโve had a lot of women in here and women who are technical security positions and I think Simone did a really good job of making sure weโve got great representation, so thatโs awesome. I think Michelle said it, if anybody wants one of her books theyโre in the back so help yourself. Can we thank our panelists please?
Participants
Michelle Finneran Dennedy
Vice President, Chief Privacy Officer, McAfee, a division of Intel Security