SecurityMetrics Podcast | 25
Cybersecurity Innovation from Military to Enterprise
Dr. Oren Eytan joins Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss his experiences as a cybersecurity leader in both the military and civilian realms.
After serving in the Israeli defense forces, two degrees in Electrical Engineering, and time at Motorola, Dr. Oren Eytan continues the fight against malware as the CEO of Odix. Today he helps protect businesses in all sectors, including utilities and technology.
Listen to Learn:
- Why creative thinking is crucial to cyber security
- Lessons learned from protecting critical infrastructure
- The relationship between connectivity and vulnerability
Resources:
Connect with Dr. Eytan on LinkedIn
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
Cybersecurity Innovation from Military to Enterprise Transcript
Hello, and welcome back to the Security Metrics podcast. My name is Jen Stone. I'm a principal security analyst here at Security Metrics. Very excited today to talk to you about our guest, Oren Itan.
I'm gonna read to you a little bit about his bio because it's very cool. He's the former head of the Israeli Defense Forces information security unit, specialized in infrastructure protection, encryption, network security, and mobile device security. And that's one of the key reasons that I was excited to talk to him today. Infrastructure is a really big talk topic, on securing it. So, we're gonna cover that a little bit. He graduated from the University of Texas at Arlington with a PhD in electrical engineering. And prior to ODIX, where he is now, he is he was a business development manager at Motorola and VP business development at GEDA Technologies.
Welcome, Oren. First of all, did I pronounce your name correctly?
Yeah.
Hello.
What did I miss in your bio? What else would you like people to know about you?
Well, I'm, I'm married. I have three children and, already three grandchildren.
So Oh my goodness.
Congratulations.
Yeah. That's there's nothing like family, especially when you're in these difficult times.
So our topic today is the journey from an innovative military cyber environment to the enterprise ecosystem, applying knowledge and leadership to different touchpoints of success. And I think you've demonstrated that in your career. That means let's start with your experience at the Israeli Defense Forces, cyber environment. Can you tell me about a little bit about that work and how that paved the way for your current success?
Yeah. Definitely. So, thanks again for the opportunity.
And, I I joined the Israel Defense Forces, you know, as every Israeli.
I graduated my bachelor degree in electrical engineering, and I joined the army, served as an engineer, a lot of, in the r and d. You know, in the Israeli army, you know, our neighborhood. Our neighborhood is kind of tough. And, we have a lot of, neighbors that looking at us, and, you know, we are not in a in a peaceful agreement with all of them.
So, all over the years since Israel was established, we are kind of a a war situation or, let's say, emergency situation. And, we can never, you know, sit down and, you know, have fun, but we need to to be prepared as, you know and in the military, we used to say that our military has only two states. One of them is being in a war, and the second one is preparing to a war. So there's only two states for for the military, and and we feel it.
And when I serving, at the IDF, all the cybersecurity and all the cyberspace has emerged.
And you know that Israeli is a startup nation and, the IDF relies a lot of, on a lot of technology, a lot of the the weapons, a lot of the the tools that you're using. Actually, we're utilizing a lot of technology. Therefore, we're also vulnerable.
So it's a paradox that, you know, if you don't use technology, you're you're not vulnerable. And as much as you use more and more technology and more and more connectivity and so on, you're more vulnerable.
So my task was to protect all this infrastructure and make sure that all the processes and all the units can, you know, communicate safely, can transfer data safely, and, and in fact, make sure that the continuity of all the all the processes and the moves and the maneuvers that the military needs to do.
I'm glad you said that about continuity. A lot of times in cyber it isn't everyone's focus because it isn't necessary in all environments but it certainly, would be in a war situation or in a military.
And what you said about, technology, I heard someone speaking, earlier today about technology, and they're not sure, well, is technology hurting us or is it helping us? Well, I don't think that's the right question. I think I think the right thing is we have technology.
In what way do we leverage it to to help us with our situation?
Yeah. I I definitely think that technology is helping us. Technology is there, and we are doing great things with technology, you know, all all all over the world. You know, technology is there. If you look at the starting from the smartphone for the personal, usage and going all the way for data systems and the communications and, you know, technology is great.
So I think, also in the in the military, you know, people shouldn't be afraid of using technology because they make them vulnerable. They need to know how to use the technology and make all the benefits from this technology, but make sure that they do it in a secure way and and, you know, protect their, you know, infrastructure and protect themselves. But I I wouldn't give up the technology because of, you know, the chance that I might be vulnerable. And I think it's only good things about technology.
Excellent.
So, a lot of times, people don't think about, the military as a place where innovation happens. But you were in research and development and it sounds like what you're saying is that innovation was, was essential to what you were doing. Is is that how you see that?
Oh, yeah. Absolutely.
You know, if we go back to the eighties, the last century.
Also, the military led the market in in communication.
The most sophisticated, communication system were military systems.
And then when, the cellular systems emerged, then what that was the point where the civilian market was ahead of the of the, defense and military market because they they saw the potential.
And then they got the lead in communications over over the military. The military is still, you know, ahead with, let's say, secured and immune communication and so on.
But as as communication percent, bandwidth, and personal communication, the civilian market made, a significant, advancement over the the military market. However, there are still spaces that are unique for the military, and, the military is still ahead. For example, security.
Because the heart of the of the military and the defense is is, you know, have having a good security.
And it goes all the way to cyber and cybersecurity.
So if, cyber emerges as as, additional frontier for for militaries, then me, these militaries have the lead over the civilian market.
Maybe it's temporary, but Right now that's where it's at.
You're right. But because we see that, a lot of, hackers, a lot of, cyberattacks and a lot of events are actually part of, you know, the, civilian market as well. So it become also very common and become also obvious that the civilian market will adopt, a lot of the, advanced technologies of cybersecurity and then advanced doctrines of cybersecurity, as you know, militaries and, and defense forces are, are using.
And, so, at this point, I think still, you know, the, the military is, it's not only Israel. I think the advanced advanced forces all over the world, they're they're struggling with the cybersecurity and they need to be two steps ahead of the hackers.
And in their case, hackers, you know, are are are state, level or nation level. So they have, a lot of budget, a lot of resources. So they're obviously more, you know, sophisticated, more complex attacks. And then you must have and you must be very creative in order to protect yourself.
And I think that has, as specifically applicability to critical infrastructure.
When we think of critical infrastructure, so, recently in the US, there was a, people are downplaying the attack because nothing bad happened.
But there were, people who were able to, get into the Tampa, Florida water treatment and put in unsafe amounts of chemicals.
And then the person who was watching it reversed it immediately and said, Oh, nothing happened. It's fine. But I think that that's probably the wrong way to look at it. Probably the right way to look at it was somebody was able to breach that system and make something happen that should not have been able to. So so first of all, maybe people don't even know what would be classified as critical infrastructure. How would you characterize critical infrastructure?
I think, the the the right way to characterize critical infrastructure is by defining the potential damage that can be, caused by, you know, hurting this critical infrastructure.
So if, for example, if you hit the one of the US grids and, New York is going to be in dark, So, I think that makes the the grid critical infrastructure because you definitely don't want, you know, millions of people to live in in the dark and in the hospitals that don't have electricity, so it may cause a lot of, casualties. So, it seems and now you need to do an assessment of what is the potential damage. When I'm saying this is a a substantial potential damage or significant potential damage, you can say, oh, okay.
Is it, is the damage is in, in lives or is the damages in, in money and resources and and so on. So I think this is the only way to to do the right assessment of critical infrastructure. When you decide over threshold, you said, okay. Above the threshold, you know, if, if I hit the the water and I poison the water and thousands of people die, then it's obviously critical infrastructure.
Right.
And so, in working with critical infrastructure, I have not personally worked with organizations that are focused on critical infrastructure. Mine is more on, like you said, the monetary side. A lot of us are we care about, well, did your payment go through without causing fraud to your card?
Or in the hospitals, you know, that's more along the HIPAA lines of things. You're getting towards, I think, critical infrastructure when you're talking about health. But I think that the critical infrastructure, as you're talking about, you know, what is the what's happening at our power stations? What's happening at our water treatments? What is happening with them? With those types of things.
How is the thinking different with that type of organization then, say, when speaking with a small or medium business?
Well, this is a big difference.
First of all, in the size.
I mean, when you're talking about critical infrastructure, you usually talk about enterprises and large enterprises.
And obviously, when you're talking about SMBs, obviously, they're not that big. So I say there are there are few or, two major, differences.
One of them is, you know, the critical infrastructure, need to protect, himself against, a specific set of threats.
So and these threats are much more severe than, you know, SMBs need to, deal with because, usually critical infrastructure are targets of, you know, nations and states and, you know, really, heavy resource and, very talented hackers and and attackers.
So first of all, I think the level of the threat is different, and that's the reason, a lot of, you know, the critical infrastructure, what they're trying to do is to do an assessment regarding the risk that they have because they have so many of them. And, so they they do some risk analysis and then they see, okay, where are we vulnerable?
And at this point, we need to protect ourself, in a better way.
Where SMBs, you know, they're they are less aware.
Usually the the attacks over there, you know, are more, let's say, common or or that you know, because hackers also not going to invest a lot of, you know, efforts in attacking an SMB.
So this is, this is one big difference about the threats landscape.
The other big difference is the way that, and the behavior of, critical infrastructure and SMBs. Critical infrastructure usually have their own on prem solutions, on prem systems.
They barely use, you know, cloud infrastructure or doing some other stuff. They're trying to be very secure, very isolated.
While the SMBs, they are, you know, they're consuming their IT services and their cybersecurity services from from the cloud. Sometimes they don't have IT guys. Sometimes they don't have cybersecurity.
For sure, they don't have the awareness.
They don't have, the capabilities.
So they consume the, their solution from from the cloud or software as a service, SaaS, and so on.
And for example, in Nordics, we provide both sectors. So for example, for the, critical infrastructures, we have our on prem solution and we protect the major utilities companies in the United States, the electricity companies, and, we provide them with our on prem solution and this solution protect, their power plants and their grid.
And on the other hand, for SMBs, we got a firewall, and the firewall is a pure SaaS solution that it's, currently provide a security layer for the Microsoft three sixty five, email users. So we provide it as a pure SaaS. So we identified, of course, that, you know, we first do the threat analysis dimension, but then it's a different, way of solving the issues and solving the problems.
So it sounds like what you're saying is that the the threats might be slightly different, but some of them are certainly, some of them are certainly the same and the risk appetites are different. And so the way you need to address the threats might be a different solution for similar problems depending on how an organization's, systems are set up, where they exist, whether it's in the cloud, whether it's on prem, and understanding those things.
You know what? We I I know what your company does, but I don't, a lot of people may not. Can you tell us a little bit about what Odix does?
Because you went there were you one of the founders of this organization?
Yeah.
Tell me a little bit about what you do and and and how you do it.
Okay. So, what we do, and not moving too much into the technical area, We're we're looking at the at the files because files are, one of the major, payloads that hackers like to hide the malware within the files. Mhmm. And now files, you know, are very common, you know, as attachment for emails, there's downloadable in the Internet, the files that are uploaded to, organizational website and so on. So we find out that the file are still a major attack vectors for hackers, both for critical infrastructures and also for SMBs and, in fact, for any size of enterprise.
And we developed our own unique solution that is able to, sanitize files, is able to disarm the file from the malware regardless of the malware type. And this is make us so special because we're completely agnostic to the malware type.
We do, what I call deep file analysis.
We break the file to the smallest component, and then we do analysis on each part of it. And then we reconstruct this file again only from the good portion.
So we completely agnostic if there was a malware, and and we may even don't know that the malware was there. We simply ignore it. And we provide you a fully functional file that, you know, you can, use it. You can, do whatever you want with it, and and the and the and the malware is is behind you.
So this is very unique.
Gartner gave it the name CDR, content disarm and reconstruction.
And but we are doing much more than CDR. We are doing all the deep file inspection, and we're doing a lot of stuff inside in order to make sure that the file that you get at the end of the day is is clean and ready to go. And based on this technology and, of course, we have patents on it in the United States, issued patents and across Europe. Based on the this technology, we develop our products both for the on prem and for the SaaS, software as a service.
That so that's really interesting to me because, our last, guest talked about social engineering and how, clicking on things in email, clicking on files, and and downloading malware is such, an easy way in for attackers.
And so, I was wondering earlier when you were talking about, you know, some people in the cloud and you get all this email, but then these the infrastructure around, these the critical infrastructure where where they try to isolate their systems and they try to isolate, the the traffic that comes in. But even those even in critical infrastructure, you still have email, right? There's still the people who work there are still receiving email. And so there is that potential vector, for negative impact to our critical infrastructure.
That's correct. But in critical infrastructure, you need to distinguish between, let's say, the OT, the operational network, and the IT, the, the IT that obviously, the emails are going in in the IT. Usually, critical infrastructure would like to isolate between the OT and the IT. The OT is responsible if you look at electricity company, the OT is responsible for generating the the the power with with all, in water company. They're responsible for all the pumps. And, really, this is the operational network that's responsible for the core business of of this utility company or critical infrastructure.
And this usually, they try to isolate this OT network from the IT network. And the IT is a regular IT network that you can have, you know, you can browse in the Internet, you can have emails, and so on. Now we allow since we we we are able to sanitize files and make sure that files are clean, we are able to make this gateway between the IT and the OT. So if you want, for example, to transfer file from the IT or from the external world into the OT, please use, our Audix in order to first sanitize this file and make sure that only clean files moving into the sensitive area of the OT, network. And this is also applicable.
It's called the all segment is called ICS, industrial control system. So for example, a lot of manufacturing, if you have, like, manufacturing floor and it does matter whether it's, you know, semiconductors or cars or any others, but the the manufacturing floor and the network that is responsible for the manufacturing floor, which is sometimes secret because of business secrets and is very sensitive and should be full business continuity and so on. You want to have a very, very good protection for this network because this is your core of all your business.
Right. So communication, even though we would like to, completely segment the operational network from the the IT network, the, you know, where the corporate things happen.
Communication still has to happen. Files still have to flow. Right. And I hear sometimes people be very critical, very almost disdainful of of the user, the the person who is, you know, receiving email, sending email, who potentially can bring, threats into the organization, who that person being, not always fully aware of everything, all of the activities they're doing. But I I believe that that is, well, at least unsympathetic, but but also it's unrealistic to be critical of the user that makes the mistake.
And although we can train, having technology in place to back up and support that user's actions, I think, is is a more, productive way to look at the problem.
Yeah. Absolutely. What we're we're all the time looking for finding the ways that the technology will be responsible for, you know, transferring the data, and not rely on the people. Because sometimes, you know, people do mistakes and sometime, you know, without, any malicious intention, they may do some, you know, things and maybe they're not aware, maybe they don't know and so on.
So we have, for example, when our technology we have our product called a NetFolder. The NetFolder sanitizes files in transit. So whenever you connect, you know, two networks, two libraries, two folders, whenever you move files between them, you can make sure that it first goes to our net folder. We sanitize these files, make sure they are clean, and then we transfer them to the, the other network.
Another very important issue that you mentioned, and this is relates to our, firewall, our solution for the three sixty five.
Because we know that over, you know, one third of the cyberattacks and cyber events are initiated from the internal threat.
That means, you know, people sometimes, you know, you get an email, you forward it to the organization, and it is is malicious.
Sometimes, you know, you you just generate, with intention.
It's over one third of the threats coming from the internal, threat.
And by the way, in in recent years, we always used to say that it was above fifty percent. It it went a it it I think it went a little bit down, but still it's very significant. Now the beauty about firewall that is it's a solution for three sixty five, and it's it was built and designed to be native solution to three sixty five. Therefore, we are part of the of the business process of the three sixty five. Therefore, we also handling all the internal traffic of the organization where some other solutions that, like, secured email gateways that going in front of the Microsoft three sixty five cannot handle because we design and build this solution, we are able to sanitize and actually handling all the internal traffic and make sure that all this internal traffic is clean and significantly reduce the risk for the internal threat.
So it sounds like that that you have an innovative solution, that you've been able to bring something new to the market. And I was wondering, did did your background did the time you spend innovating, for military purposes help you as both an innovator and a and as a leader of others to to create innovative thinking in your organization? How How do you think that all kind of fits together?
I think there are, two aspects to look at it.
The first aspect is I think what I learned during the many years in the military is, thinking, out of the box.
I mean, we always see that, you know, you shouldn't be aligned with all the thinking. You always need to think differently. You already need to be very creative. You always need to think out of the box in order, you know, to make sure that, you know, at least two steps ahead of your opponents.
And and this is the way we we are thinking, and this is the way we are we are also educating our young officers and soldiers and so on.
The other thing is the leadership.
That means that, okay.
I'm now the leader. Look at me, and I'm an example for you because I want to, I'll show you the way and at least, of course, you know, everyone has its own ideas and so on, but I, the leadership and the k the capability to lead is also the the the second most important thing that I got from the military service.
Well, so a lot of, business leaders and also cybersecurity professionals, they want to know more about infrastructure. They want to know more about infrastructure attacks.
How what's the best way for people to kind of elevate their knowledge in these areas?
First of all, they can reach us, and I can with my team, I have a wonderful team that are all experts.
We we love to assist, you know, customer and critical infrastructure in order to assess, you know, their threats and help them, you know, solve their their their problems.
So first of all, there's a lot of information in our website.
And I'm also reachable in all the social media and LinkedIn and so on. And I I will be more than happy to forward everyone, you know, to the right solution and to the right to get some, provide some background and advice and, you know, help help people because we are we are a security company.
Of course, we want to be to do business, but we would like to provide security.
And this is my my personal pride is that none of our customers none of our customer was compromised from cyberattack. A lot of them suffered cyberattacks, but none of them was compromised.
And this is my pride as a security regardless, you know, of the business and so on. But this is my pride, and I think that we we we love to provide, security. We would like to provide protection for, you know, critical infrastructure and organization wherever they are. And, yeah, we like it.
That's one of the things that struck me about your organization when I first started learning about your company and and speaking with you is that willingness to to talk about security. The the passion behind the security and making that the front and center thing rather than, you know, focusing on the business side of things. And that's how I look at security as well. LinkedIn has been, surprisingly, a hotbed of conversation about security for me. And I truly enjoy it when people reach out. Well, thank you so much for joining me today. I really enjoyed talking to you, learning about you, learning about, you know, your background and how you built your organization.
Is there anything else you wanted to to tell us before we wrapped up?
No. First of all, thank you very much, Jen. It was my pleasure as well.
And as I said, if anyone needs, you know, more information, like to reach me in person or, you know, I'm I'm always available, in our website, in LinkedIn, in social media, and I'm, we are willing to to assist, you know, everyone.
Great. Thank you so much, and I hope to meet you one day in person.
Oh, sure.
Alright.
Thank you very much.
Take care. You too. Bye bye.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the left. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
