WEBVTT

NOTE This file was exported by MacCaption version 7.0.06 to comply with the WebVTT specification dated March 27, 2017.

00:00:05.714 --> 00:00:09.801 align:center line:-1 position:50% size:47%
It's really interesting when you look
at the security space.

00:00:09.801 --> 00:00:18.268 align:center line:-1 position:50% size:54%
We spend about $150 billion a year now
on IT security tools and services.

00:00:18.268 --> 00:00:21.063 align:center line:-1 position:50% size:48%
Mostly on tools that are pretty good.

00:00:21.063 --> 00:00:24.191 align:center line:-1 position:50% size:47%
Most of the EDR [endpoint detection and response] software out there
and the firewalls

00:00:24.191 --> 00:00:29.238 align:center line:-1 position:50% size:63%
and intrusion detection and prevention systems
and WAFs [web application firewall], SIMs, all that stuff,

00:00:29.238 --> 00:00:33.283 align:center line:-1 position:50% size:36%
they're actually pretty good
and everyone has them.

00:00:33.283 --> 00:00:36.954 align:center line:-1 position:50% size:42%
No one hooks up to the internet
without a firewall.

00:00:36.954 --> 00:00:42.417 align:center line:-1 position:50% size:54%
Yet, the global cybercrime market
is about $6 trillion.

00:00:42.417 --> 00:00:47.506 align:center line:-1 position:50% size:54%
If cybercrime were a country,
it would be the world's third largest GDP [gross domestic product].

00:00:47.506 --> 00:00:48.548 align:center line:-1 position:50% size:32%
Why does this happen?

00:00:48.548 --> 00:00:53.595 align:center line:-1 position:50% size:66%
Why did people deploy all these really good tools
and then still get breached every day?

00:00:53.595 --> 00:01:00.018 align:center line:-1 position:50% size:35%
A lot of it is a combination
of unfamiliarity with tools

00:01:00.018 --> 00:01:06.358 align:center line:-1 position:50% size:48%
meaning you aren't able to
get the most out of your investment.

00:01:06.358 --> 00:01:10.904 align:center line:-1 position:50% size:51%
You set up something wrong
or you have something misconfigured.

00:01:10.904 --> 00:01:16.368 align:center line:-1 position:50% size:59%
I know I've certainly seen analyst reports
that something like 99% of firewall breaches

00:01:16.368 --> 00:01:20.372 align:center line:-1 position:50% size:52%
are caused by simple misconfiguration,
not technology problems.

00:01:20.372 --> 00:01:24.710 align:center line:-1 position:50% size:47%
When we say "misconfiguration,"
this doesn't just mean human error.

00:01:24.710 --> 00:01:30.465 align:center line:-1 position:50% size:51%
It can, but it can also mean things like,
"I had to make a network change."

00:01:30.465 --> 00:01:34.177 align:center line:-1 position:50% size:47%
Your network, your application,
things like that change all the time.

00:01:34.177 --> 00:01:39.266 align:center line:-1 position:50% size:65%
That may require a change in your security stack
to accommodate it

00:01:39.266 --> 00:01:40.434 align:center line:-1 position:50% size:35%
that just doesn't get made.

00:01:40.434 --> 00:01:43.729 align:center line:-1 position:50% size:61%
Or a change is made
but then it's rolled back for some other reason

00:01:43.729 --> 00:01:46.148 align:center line:-1 position:50% size:52%
or something isn't implemented in time.

00:01:46.148 --> 00:01:48.608 align:center line:-1 position:50% size:69%
Of course, the threat landscape changes every day.

00:01:48.608 --> 00:01:51.611 align:center line:-1 position:50% size:36%
Every minute there's some
additional threat out there

00:01:51.611 --> 00:01:58.076 align:center line:-1 position:50% size:59%
and that also may require a change in some
of your security stack configurations.

00:01:58.076 --> 00:02:02.456 align:center line:-1 position:50% size:49%
If you are susceptible to some attack
because of drift,

00:02:02.456 --> 00:02:06.168 align:center line:-1 position:50% size:51%
either in your environment
or in the threat landscape around you,

00:02:06.168 --> 00:02:09.504 align:center line:-1 position:50% size:57%
that is indeed because of misconfiguration.

00:02:09.504 --> 00:02:13.133 align:center line:-1 position:50% size:63%
That doesn't mean you necessarily made a mistake.

00:02:13.133 --> 00:02:15.635 align:center line:-1 position:50% size:46%
It could be that, but it could just be
the landscape changed

00:02:15.635 --> 00:02:17.721 align:center line:-1 position:50% size:38%
and you didn't catch up to it.

00:02:17.721 --> 00:02:23.143 align:center line:-1 position:50% size:54%
It turns out, there's a very, very common
cause of breaches

00:02:23.143 --> 00:02:27.814 align:center line:-1 position:50% size:37%
because you have the tools
to either stop something

00:02:27.814 --> 00:02:30.233 align:center line:-1 position:50% size:49%
or, in more cases, detect something.

00:02:30.233 --> 00:02:35.238 align:center line:-1 position:50% size:55%
We spoke earlier about the dwell time,
how long malware is active on a network.

00:02:35.238 --> 00:02:38.617 align:center line:-1 position:50% size:48%
If something gets into your network,
it's not silent.

00:02:38.617 --> 00:02:42.287 align:center line:-1 position:50% size:51%
There were probably logs on your SIM
that you could have seen

00:02:42.287 --> 00:02:47.167 align:center line:-1 position:50% size:56%
and that could have alerted you to,
"I've got this active attack on my network"

00:02:47.167 --> 00:02:49.127 align:center line:-1 position:50% size:44%
but it didn't set off the right flags.

00:02:49.127 --> 00:02:53.340 align:center line:-1 position:50% size:57%
In many cases, this is a lack of SIM tuning.

00:02:53.340 --> 00:02:58.345 align:center line:-1 position:50% size:59%
The SIM is the thing that collects all the logs
from all the security tools in your networks

00:02:58.345 --> 00:03:01.890 align:center line:-1 position:50% size:59%
and then you write rules to tie them together
and say, "If this happens, this happens.

00:03:01.890 --> 00:03:05.685 align:center line:-1 position:50% size:67%
This doesn't happen, this happens in five minutes,
that's bad so send up a flare

00:03:05.685 --> 00:03:07.396 align:center line:-1 position:50% size:45%
because I need to know about it."

00:03:07.396 --> 00:03:12.234 align:center line:-1 position:50% size:55%
If you don't have that tuned appropriately
and on a frequently updated basis,

00:03:12.234 --> 00:03:14.277 align:center line:-1 position:50% size:43%
along with the threat landscape,

00:03:14.277 --> 00:03:16.530 align:center line:-1 position:50% size:57%
you could consider that a misconfiguration

00:03:16.530 --> 00:03:21.827 align:center line:-1 position:50% size:60%
and that means that you're going to miss
the telltale signs of a breach in your network.

00:03:21.827 --> 00:03:26.206 align:center line:-1 position:50% size:54%
Rather than maybe detecting something
five minutes or five hours

00:03:26.206 --> 00:03:30.043 align:center line:-1 position:50% size:42%
or even five days into a breach,
it's five months.

00:03:30.043 --> 00:03:34.464 align:center line:-1 position:50% size:45%
The attacker had much more time
to extract data from your network

00:03:34.464 --> 00:03:36.341 align:center line:-1 position:50% size:32%
and do a lot of damage.

00:03:36.341 --> 00:03:41.763 align:center line:-1 position:50% size:49%
When we think about the actual risks
that people face on their networks,

00:03:41.763 --> 00:03:43.682 align:center line:-1 position:50% size:47%
and the impact of misconfiguration,

00:03:43.682 --> 00:03:50.230 align:center line:-1 position:50% size:54%
that is indeed the source
of the majority of breaches in a network.

00:03:50.230 --> 00:03:56.361 align:center line:-1 position:50% size:61%
Making sure that everything is tuned correctly
and configured correctly all the time

00:03:56.361 --> 00:04:01.575 align:center line:-1 position:50% size:62%
turns out to be much more important
than making additional investments in security,

00:04:01.575 --> 00:04:05.579 align:center line:-1 position:50% size:48%
just making sure that what you have
is actually working correctly.

00:04:05.579 --> 00:04:10.125 align:center line:-1 position:50% size:40%
That's step number one
in keeping your network safe.

00:04:10.125 --> 00:04:16.965 align:center line:-1 position:50% size:50%
Breach and attack simulation tools
let you realistically simulate an attack

00:04:16.965 --> 00:04:22.846 align:center line:-1 position:50% size:56%
on your own network using your own tools
but doing it in a safe manner.

00:04:22.846 --> 00:04:25.015 align:center line:-1 position:50% size:59%
This isn't something you do in a lab typically.

00:04:25.015 --> 00:04:27.559 align:center line:-1 position:50% size:54%
It's not something that you do in a class.

00:04:27.559 --> 00:04:33.565 align:center line:-1 position:50% size:65%
You have software in your network
which is emulating the behavior of real attackers.

00:04:33.565 --> 00:04:35.400 align:center line:-1 position:50% size:42%
The way that something moves
through the network,

00:04:35.400 --> 00:04:37.277 align:center line:-1 position:50% size:41%
the initial transmission vectors,

00:04:37.277 --> 00:04:41.406 align:center line:-1 position:50% size:56%
actual emails with malicious attachments,
things like that.

00:04:41.406 --> 00:04:50.665 align:center line:-1 position:50% size:66%
You're really testing your security stack against
the actual tactics and techniques and procedures

00:04:50.665 --> 00:04:53.710 align:center line:-1 position:50% size:41%
that bad guys are going to use
to break into your network.

00:04:53.710 --> 00:04:59.299 align:center line:-1 position:50% size:52%
We spoke earlier about how
the traditional IT security best practices

00:04:59.299 --> 00:05:01.676 align:center line:-1 position:50% size:57%
are now very, very relevant for automakers

00:05:01.676 --> 00:05:04.763 align:center line:-1 position:50% size:63%
because their threats to their backend systems,

00:05:04.763 --> 00:05:10.185 align:center line:-1 position:50% size:62%
the things that do billing and firmware updates
and safety and all that stuff,

00:05:10.185 --> 00:05:15.398 align:center line:-1 position:50% size:62%
now look very much like other IT deployments.

00:05:15.398 --> 00:05:22.405 align:center line:-1 position:50% size:65%
It's now very important for automakers to run the
same kind of real-world security assessments

00:05:22.405 --> 00:05:26.826 align:center line:-1 position:50% size:63%
on a continuous basis
against their networks and their security stacks

00:05:26.826 --> 00:05:32.457 align:center line:-1 position:50% size:62%
so that they know, "If I'm hit by this new attack,
this threat, maybe this old attack,

00:05:32.457 --> 00:05:33.750 align:center line:-1 position:50% size:24%
am I susceptible?

00:05:33.750 --> 00:05:35.627 align:center line:-1 position:50% size:58%
Is it going to make it through my defenses?

00:05:35.627 --> 00:05:40.215 align:center line:-1 position:50% size:51%
Or if it does, if something just appears
on the inside of my network somehow,

00:05:40.215 --> 00:05:45.470 align:center line:-1 position:50% size:35%
am I able to quickly detect
and put out that fire?"

00:05:45.470 --> 00:05:46.888 align:center line:-1 position:50% size:40%
Breach and attack simulation,

00:05:46.888 --> 00:05:51.935 align:center line:-1 position:50% size:59%
which has certainly been gaining
a lot of ground in more traditional IT spaces,

00:05:51.935 --> 00:05:57.691 align:center line:-1 position:50% size:64%
is extremely relevant for automakers as well
to protect all those backend services.

00:05:57.691 --> 00:06:02.654 align:center line:-1 position:50% size:58%
With a breach and attack simulation system
such as Keysight's Threat Simulator,

00:06:02.654 --> 00:06:06.575 align:center line:-1 position:50% size:54%
what you're really doing is you're putting
software agents in your network

00:06:06.575 --> 00:06:09.494 align:center line:-1 position:50% size:66%
and then there are some typically out in the cloud

00:06:09.494 --> 00:06:12.956 align:center line:-1 position:50% size:50%
and they talk to each other in the way

00:06:12.956 --> 00:06:19.421 align:center line:-1 position:50% size:53%
that a real attack would sort of go from
an attacking system to a victim system.

00:06:19.421 --> 00:06:24.676 align:center line:-1 position:50% size:66%
The same communication protocols,
the same ports, the same data is sent over them.

00:06:24.676 --> 00:06:29.764 align:center line:-1 position:50% size:60%
The difference is what makes it safe
is rather than talking to an actual application,

00:06:29.764 --> 00:06:35.353 align:center line:-1 position:50% size:44%
or actually running malware live
on some end user's work station,

00:06:35.353 --> 00:06:37.856 align:center line:-1 position:50% size:63%
you're talking only to your own software agents,

00:06:37.856 --> 00:06:43.236 align:center line:-1 position:50% size:56%
or you're simulating the way that a piece
of malware would behave on an endpoint.

00:06:43.236 --> 00:06:47.574 align:center line:-1 position:50% size:47%
So if you can accurately reproduce
the registry mods and system calls

00:06:47.574 --> 00:06:49.993 align:center line:-1 position:50% size:32%
and file system touches
and things like that,

00:06:49.993 --> 00:06:51.953 align:center line:-1 position:50% size:51%
that a real piece of malware would do,

00:06:51.953 --> 00:06:55.332 align:center line:-1 position:50% size:45%
you can see if your EDR software
can detect that.

00:06:55.332 --> 00:06:59.753 align:center line:-1 position:50% size:51%
Similarly, if you're making all the same
network connections and behavior

00:06:59.753 --> 00:07:03.298 align:center line:-1 position:50% size:55%
and you take the same amount of time
and send the same data in the same way

00:07:03.298 --> 00:07:05.967 align:center line:-1 position:50% size:42%
and do the same sort of probes
that real malware does,

00:07:05.967 --> 00:07:08.261 align:center line:-1 position:50% size:44%
you can test your NDR [network detection and response] software.

00:07:08.261 --> 00:07:12.307 align:center line:-1 position:50% size:49%
And all of those alerts and things like that
bubble up to a SIM.

00:07:12.307 --> 00:07:15.894 align:center line:-1 position:50% size:59%
You can see,
"If this happens, this happens, this happens,

00:07:15.894 --> 00:07:18.938 align:center line:-1 position:50% size:48%
which is exactly what would happen
in a real attack,

00:07:18.938 --> 00:07:21.107 align:center line:-1 position:50% size:49%
is that going to set off the right alerts
on my SIM

00:07:21.107 --> 00:07:23.693 align:center line:-1 position:50% size:45%
or do I need to go back
and tune something to make sure

00:07:23.693 --> 00:07:27.656 align:center line:-1 position:50% size:42%
that when a real attacker runs
the same attack on my network,

00:07:27.656 --> 00:07:31.326 align:center line:-1 position:50% size:52%
that I can detect it and flag it or block it
or take remedial action?"

00:07:31.326 --> 00:07:35.080 align:center line:-1 position:50% size:45%
Let's talk about the way
that breach and attack simulation

00:07:35.080 --> 00:07:41.628 align:center line:-1 position:50% size:63%
is different from some of the other, maybe more
widely known security testing mechanisms,

00:07:41.628 --> 00:07:44.005 align:center line:-1 position:50% size:46%
penetration testing or red teaming.

00:07:44.005 --> 00:07:48.468 align:center line:-1 position:50% size:61%
When I say pen testing or penetration testing,
there are different kinds of that.

00:07:48.468 --> 00:07:51.888 align:center line:-1 position:50% size:48%
You can think about like pen testing
against a particular device,

00:07:51.888 --> 00:07:54.391 align:center line:-1 position:50% size:59%
like a car where you're trying to break into it,

00:07:54.391 --> 00:07:56.935 align:center line:-1 position:50% size:46%
or in the more traditional IT space,

00:07:56.935 --> 00:08:02.315 align:center line:-1 position:50% size:57%
penetration test means, "I'm on the outside
of the network and I'm trying to get in."

00:08:02.315 --> 00:08:04.943 align:center line:-1 position:50% size:53%
The overall concept is obviously similar

00:08:04.943 --> 00:08:08.321 align:center line:-1 position:50% size:56%
but maybe different scope, different goals,
things like that.

00:08:08.321 --> 00:08:13.284 align:center line:-1 position:50% size:46%
When you hire a pen test team
to maybe break into your network,

00:08:13.284 --> 00:08:15.328 align:center line:-1 position:50% size:52%
you're really hiring a bunch of hackers,

00:08:15.328 --> 00:08:16.913 align:center line:-1 position:50% size:34%
typically fairly expensive.

00:08:16.913 --> 00:08:18.456 align:center line:-1 position:50% size:51%
They will almost certainly find a way in

00:08:18.456 --> 00:08:23.545 align:center line:-1 position:50% size:61%
so what you're really getting is, "Here's a way
that someone can get into your network."

00:08:23.545 --> 00:08:29.134 align:center line:-1 position:50% size:60%
Modern pen testers tend to be more focused
on things like social engineering attacks

00:08:29.134 --> 00:08:31.302 align:center line:-1 position:50% size:28%
and physical attacks.

00:08:31.302 --> 00:08:34.305 align:center line:-1 position:50% size:38%
When I say physical attacks,
not kicking a door down,

00:08:34.305 --> 00:08:37.934 align:center line:-1 position:50% size:51%
but they might try to tailgate someone
and get into an office

00:08:37.934 --> 00:08:41.938 align:center line:-1 position:50% size:53%
or they may sit in your office parking lot
in a van

00:08:41.938 --> 00:08:44.399 align:center line:-1 position:50% size:65%
and try to hack their way onto the WiFi network.

00:08:44.399 --> 00:08:46.943 align:center line:-1 position:50% size:55%
They may try a social engineering attack:

00:08:46.943 --> 00:08:50.155 align:center line:-1 position:50% size:41%
find out that the CFO has kids
who play soccer

00:08:50.155 --> 00:08:53.158 align:center line:-1 position:50% size:43%
and then they find out the name
of the soccer team

00:08:53.158 --> 00:08:56.661 align:center line:-1 position:50% size:54%
and the name of the coach
and they spoof an email from the coach,

00:08:56.661 --> 00:08:58.204 align:center line:-1 position:50% size:48%
which the person is likely to answer,

00:08:58.204 --> 00:09:00.790 align:center line:-1 position:50% size:37%
that says, "Here's the donut
and orange juice schedule

00:09:00.790 --> 00:09:02.333 align:center line:-1 position:50% size:66%
when everybody's supposed to bring something."

00:09:02.333 --> 00:09:06.546 align:center line:-1 position:50% size:45%
The CFO answers it and that gets
their malware onto the network.

00:09:06.546 --> 00:09:09.632 align:center line:-1 position:50% size:47%
That's all perfectly appropriate stuff

00:09:09.632 --> 00:09:15.346 align:center line:-1 position:50% size:42%
but penetration testers tend to
not conduct exhaustive attacks.

00:09:15.346 --> 00:09:18.600 align:center line:-1 position:50% size:48%
They're not going to try every single
security control in your network.

00:09:18.600 --> 00:09:22.353 align:center line:-1 position:50% size:58%
They're going to keep trying something until
they find their way in and then they're done.

00:09:22.353 --> 00:09:25.565 align:center line:-1 position:50% size:38%
They checked that box
and they've done their thing.

00:09:25.565 --> 00:09:30.320 align:center line:-1 position:50% size:59%
Penetration testing also obviously gives you
information about your security

00:09:30.320 --> 00:09:32.197 align:center line:-1 position:50% size:23%
at a point in time.

00:09:32.197 --> 00:09:34.157 align:center line:-1 position:50% size:42%
Typically you're going to do this
once or twice a year

00:09:34.157 --> 00:09:37.202 align:center line:-1 position:50% size:45%
so you'll know something about
your security in January and July.

00:09:37.202 --> 00:09:39.996 align:center line:-1 position:50% size:52%
What the team in July finds is probably
going to be very, very different

00:09:39.996 --> 00:09:42.415 align:center line:-1 position:50% size:50%
from what the team in January found.

00:09:42.415 --> 00:09:45.168 align:center line:-1 position:50% size:57%
It's certainly not a continuous assessment.

00:09:45.168 --> 00:09:46.920 align:center line:-1 position:50% size:13%
It's good.

00:09:46.920 --> 00:09:51.090 align:center line:-1 position:50% size:60%
We never say don't do pen testing,
but you're going to learn very different things.

00:09:51.090 --> 00:09:54.844 align:center line:-1 position:50% size:43%
Red teaming is typically more of
like a gray box approach

00:09:54.844 --> 00:09:58.515 align:center line:-1 position:50% size:49%
where the attackers know something
about your network.

00:09:58.515 --> 00:10:02.519 align:center line:-1 position:50% size:42%
Typically, red teams
have a more restricted tool box

00:10:02.519 --> 00:10:08.399 align:center line:-1 position:50% size:53%
because you're often asking a red team
to emulate a particular attacker:

00:10:08.399 --> 00:10:12.362 align:center line:-1 position:50% size:47%
"I want you to use the kind of TTPs
that ABT29 is currently using

00:10:12.362 --> 00:10:15.240 align:center line:-1 position:50% size:36%
to get into networks
and steal this kind of data."

00:10:15.240 --> 00:10:18.952 align:center line:-1 position:50% size:56%
So you're really emulating a particular attack.

00:10:18.952 --> 00:10:21.579 align:center line:-1 position:50% size:44%
Again, it's not a bad thing to do
and you can certainly learn a lot.

00:10:21.579 --> 00:10:27.168 align:center line:-1 position:50% size:63%
It's not going to be exhaustive
because if the tactics and procedures and tools

00:10:27.168 --> 00:10:32.423 align:center line:-1 position:50% size:57%
that are used by a particular attacker
are outside the scope of their current work,

00:10:32.423 --> 00:10:33.967 align:center line:-1 position:50% size:47%
they're not going to exercise those.

00:10:33.967 --> 00:10:38.555 align:center line:-1 position:50% size:61%
You're not going to know if your security stack
is tuned to stand up to those.

00:10:38.555 --> 00:10:40.849 align:center line:-1 position:50% size:37%
It's more limited in that way.

00:10:40.849 --> 00:10:46.813 align:center line:-1 position:50% size:66%
It also is very expensive because you're still
hiring a pretty expensive team of security experts

00:10:46.813 --> 00:10:49.691 align:center line:-1 position:50% size:40%
to try to conduct these attacks
against your network.

00:10:49.691 --> 00:10:52.193 align:center line:-1 position:50% size:52%
Now you're paying two security teams.

00:10:52.193 --> 00:10:54.654 align:center line:-1 position:50% size:51%
One that's your actual defensive team

00:10:54.654 --> 00:10:56.948 align:center line:-1 position:50% size:45%
and then another team
that's running around attacking it.

00:10:56.948 --> 00:11:00.285 align:center line:-1 position:50% size:43%
It's great to do and if you're
a very well-funded organization,

00:11:00.285 --> 00:11:03.371 align:center line:-1 position:50% size:30%
go for it, absolutely,
it's a good thing to do.

00:11:03.371 --> 00:11:08.209 align:center line:-1 position:50% size:44%
Unfortunately, that's out of reach
of a lot of IT shops

00:11:08.209 --> 00:11:11.963 align:center line:-1 position:50% size:41%
just because it is so expensive
and not everyone can do it.

00:11:11.963 --> 00:11:13.756 align:center line:-1 position:50% size:46%
With breach and attack simulation,

00:11:13.756 --> 00:11:16.801 align:center line:-1 position:50% size:42%
you're really deploying software
that's doing all this for you.

00:11:16.801 --> 00:11:18.261 align:center line:-1 position:50% size:34%
It can be very automated.

00:11:18.261 --> 00:11:22.599 align:center line:-1 position:50% size:51%
You can literally run tens of thousands
of assessments every day

00:11:22.599 --> 00:11:25.393 align:center line:-1 position:50% size:52%
and exercise your entire security stack,

00:11:25.393 --> 00:11:29.105 align:center line:-1 position:50% size:46%
even bubbling up through the SIM 
to your security team.

00:11:29.105 --> 00:11:31.608 align:center line:-1 position:50% size:41%
"Here's today's latest malware.

00:11:31.608 --> 00:11:35.528 align:center line:-1 position:50% size:42%
Am I able to respond
to that malware appropriately?"

00:11:35.528 --> 00:11:38.197 align:center line:-1 position:50% size:35%
You can do this every day.

00:11:38.197 --> 00:11:42.994 align:center line:-1 position:50% size:45%
You can look at the change
in your security posture over time

00:11:42.994 --> 00:11:46.289 align:center line:-1 position:50% size:51%
and answer the question,
"Am I safer today than I was last week,

00:11:46.289 --> 00:11:47.832 align:center line:-1 position:50% size:35%
or last month, or last year?

00:11:47.832 --> 00:11:51.669 align:center line:-1 position:50% size:51%
What's the return I got on
all my security investment, etc.?"

00:11:51.669 --> 00:11:55.381 align:center line:-1 position:50% size:37%
The fact that it's exhaustive
and automated,

00:11:55.381 --> 00:11:58.968 align:center line:-1 position:50% size:51%
and certainly less manpower-intensive,

00:11:58.968 --> 00:12:05.350 align:center line:-1 position:50% size:57%
makes it a much more cost-effective option
for many more organizations.

00:12:05.350 --> 00:12:09.228 align:center line:-1 position:50% size:51%
It makes breach and attack simulation
a much more realistic option

00:12:09.228 --> 00:12:13.316 align:center line:-1 position:50% size:44%
for ongoing security assessment
than some of the other tools.

00:12:13.316 --> 00:12:20.990 align:center line:-1 position:50% size:40%
The exposure, the risk profile
that auto manufacturers have

00:12:20.990 --> 00:12:26.329 align:center line:-1 position:50% size:55%
now that cars are connected
to the cloud, to the greater infrastructure,

00:12:26.329 --> 00:12:28.790 align:center line:-1 position:50% size:32%
to 5G networks, all that,

00:12:28.790 --> 00:12:31.918 align:center line:-1 position:50% size:47%
is really something unprecedented.

00:12:31.918 --> 00:12:38.675 align:center line:-1 position:50% size:70%
We haven't had to deal with heavy deadly machinery
being effectively computer-controlled

00:12:38.675 --> 00:12:40.843 align:center line:-1 position:50% size:32%
on a large scale before.

00:12:40.843 --> 00:12:47.350 align:center line:-1 position:50% size:61%
Payment information, personal safety, threats
to national security, these are not exaggerations.

00:12:47.350 --> 00:12:50.937 align:center line:-1 position:50% size:38%
These are all very real risks.

00:12:50.937 --> 00:12:57.694 align:center line:-1 position:50% size:58%
We discussed earlier how an attack against
a traditional IT system, a phishing attack,

00:12:57.694 --> 00:13:01.280 align:center line:-1 position:50% size:42%
can have a downstream impact
that sends a car off the road,

00:13:01.280 --> 00:13:06.244 align:center line:-1 position:50% size:40%
or steals payment information
from tens of millions of users.

00:13:06.244 --> 00:13:11.666 align:center line:-1 position:50% size:61%
It's very important now for auto manufacturers
and those operating the networks

00:13:11.666 --> 00:13:17.964 align:center line:-1 position:50% size:62%
that maintain the connectivity between
the backend services and the cars themselves,

00:13:17.964 --> 00:13:20.717 align:center line:-1 position:50% size:40%
to have very, very good security.

00:13:20.717 --> 00:13:22.885 align:center line:-1 position:50% size:57%
The threat landscape changes all the time,

00:13:22.885 --> 00:13:26.931 align:center line:-1 position:50% size:62%
their application deployment profile and things
like that are going to change all the time

00:13:26.931 --> 00:13:33.187 align:center line:-1 position:50% size:50%
so it's very, very important for them
to now continue security assessment,

00:13:33.187 --> 00:13:35.106 align:center line:-1 position:50% size:39%
to continue probing and attacks

00:13:35.106 --> 00:13:38.651 align:center line:-1 position:50% size:54%
using real techniques that real bad guys
would use against their networks

00:13:38.651 --> 00:13:43.448 align:center line:-1 position:50% size:59%
to make sure they they are as well-protected
as they can possibly be

00:13:43.448 --> 00:13:46.617 align:center line:-1 position:50% size:65%
against those attacks that you know will happen.

00:13:46.617 --> 00:13:48.661 align:center line:-1 position:50% size:42%
People will absolutely try them.

00:13:48.661 --> 00:13:52.582 align:center line:-1 position:50% size:46%
If you put anything on the internet,
someone's going to try to attack it.

00:13:52.582 --> 00:13:56.669 align:center line:-1 position:50% size:59%
It's certainly in the automakers' best interest
to stay ahead of that curve

00:13:56.669 --> 00:13:58.880 align:center line:-1 position:50% size:58%
by first launching those attacks themselves.

00:13:58.880 --> 00:14:02.550 align:center line:-1 position:50% size:54%
That's why breach and attack simulation
is such an important tool

00:14:02.550 --> 00:14:07.597 align:center line:-1 position:50% size:55%
for auto manufacturers in maintaining
the security of their extended ecosystem.

