Zero Trusts Given

The Missing Piece of Zero Trust: System Integrity

Episode Summary

In this episode of Zero Trust Given, Cimcor CEO Robert Johnson joins the conversation to discuss how system integrity and continuous monitoring strengthen Zero Trust security. The discussion examines why detecting unauthorized changes to servers, applications, cloud infrastructure, and critical assets is essential for reducing cyber risk, improving resiliency, and meeting compliance requirements. They also explore how Cimcor's CimTrak platform integrates with Zero Trust architectures to enable dynamic policy enforcement, endpoint integrity validation, ransomware defense, automated system hardening. CimTrak also gives organizations real-time visibility into configuration drift, helping organizations move beyond trust and toward continuous verification.

Episode Transcription

[Tom Tittermary]

Hey, everybody. Welcome to another episode of Zero Trust Given. My name is Tom Tittermary.

 

As always, I'm here with my incredible, illustrious host, Tom Gianelos. Say hi, Tom. Hello, everybody.

 

And today, we are here to have another conversation with everybody about Zero Trust relative to the military, the defense industrial base, which now... I mean, is it the war industrial base now that we have the Department of War? I think it has to be.

 

Is it the WIB instead of the DIP? It has to be. In any case, we're going to talk about it.

 

We're also going to talk a little bit about effects upon civilian government and Zero Trust and different technology that's relevant to this space. We're very lucky to have with us today one Robert Johnson from SimCorp. Robert, would you be happy to introduce yourself?

 

[Robert Johnson]

Yes. Thank you, Tom and Tom. So, yes, my name is Robert Johnson, President and CEO of SimCorp, and I really appreciate the opportunity to be on your show.

 

[Tom Tittermary]

Yeah, we're super excited to have you here. We've done a ton of conversations with SimCorp and different angles and plays about how we can try to make that one plus one equal three with Zscaler relative to some of the conversations we're having. For the audience out there, could you do your best 10,000-foot view of SimCorp, what you guys are looking to do for industry, and how it plays into the Zero Trust conversation writ large, and then we can kind of dive in from there.

 

[Robert Johnson]

Sure. Sure. So let's first start by talking about what SimCorp does with our product, SimTrack.

 

It's actually called the SimTrack Integrity Suite. So it helps in three core areas, security, compliance, resiliency, and then the bonus is it helps in terms of Zero Trust. So I'll cover all three of those.

 

From a security perspective, it makes it possible for you to identify drift from within your network, whether we're talking about servers or network devices, cloud infrastructures. Basically, we can identify when unexpected, unwanted, undesired changes occur on any of those types of infrastructure. So let me give you an example.

 

If a new user is added to Active Directory, what would you know about it? Or if your Kubernetes configuration has somehow been altered in some unexpected way, what would you know about it? Or here's a really simple question.

 

If, think about the most important server that you're responsible for, TOMS. Can I call you the TOMS? Yes. Think about the most important system that you're responsible for.

 

And if someone went two directories down and modified something on those systems, something that didn't change blatantly the behavior in some way, something more subtle, something more nefarious, what would you know about it? Yeah. The answer is probably never.

 

Or very, you know, it would be a long time. That's the problem. That's the problem we're trying to solve.

 

In fact, IBM identified that the average amount of time before an organization realizes they've been breached is over 180 days. So you're not alone. So that's what we're trying to solve is provide that visibility into unexpected changes on almost every type of system that drives a modern-day infrastructure.

 

So yes, that means files, changes to your registry, new applications being loaded, even changes to your own Zero Trust Zscaler platform, ZI and ZPI. We're really focused on going deep and wide to monitor as much as possible. So what do we do when we do detect that something has happened?

 

Well, A, we strive to detect these changes in real time. So if a file was added to that critical system of yours, we would have detected it right away in real time, let you know about it in our console, also sent off information to your SEM or log banishment solution. And then what's really unique and really the center of our patent is the ability to automatically fix things and change things right back to what it was as well.

 

Now that's optional, but that provides a layer of resilience, resiliency on top of existing infrastructures. Some other things that we do in terms of drift is identify if your system has drifted away from a secure configuration baseline. So for instance, say you've decided that your company has standardized on CIS benchmarks or DISA STIGs, as in the terms of the whip or in the Department of War.

 

SEMtrak can assess all the endpoints in the infrastructure to see if they're configured properly according to DISA STIGs or CIS benchmarks and then provide you with detailed information on exactly what you need to do to fix it and also map that information back to a variety of compliance standards so you can see how am I doing in terms of 853 FISMA? How am I doing in terms of PCI? We use it all as evidence to drive that.

 

[Tom Tittermary]

Yeah, I think just from my perspective, right, we've all been doing security for a very long time. I think that the two main categories of what I would call security events or meaningful security events, you know, in the red, yellow, greens, these are the reds, they fall into exactly two categories, and one is the malicious insider or outsider that is actively making a change to a system with the intent to do something malicious, escalate privilege, destroy or exfiltrate data. Those are...

 

those sound like things that, you know, CENCOR specifically is looking for very specifically from a change perspective that they can highlight and say, hey, a change was made to the system. The other one that I think all security professionals know about and we talk about less often because it's not like, ooh, hackers, and, you know, it's not the sexiest one, but are well-meaning insiders that are about the mission of the agency that are making changes in time with the intent of moving the mission forward that are not necessarily security compliant, right? But it sounds like from what you're talking about across a wide variety of, you know, just enterprise IT in general, you're gonna be able to see both sides of those and provide meaningful impact or immediate remediation against both of those types of changes.

 

Is that... am I tracking that correctly?

 

[Robert Johnson]

You're tracking that, and you're 100% correct. You know, everything is not malicious that impacts your organization. You know, there are estimates that 80% to 90% of all network outages are due to human error.

 

Somebody made a change.

 

[Tom Gianelos]

With no malice of intent, right?

 

[Robert Johnson]

With no malice of intent at all. It just may not have been documented 60% of the time. It didn't follow the change management process that was defined in our organization.

 

Right.

 

[Tom Tittermary]

Just this once, just this one time, it's really critical. Right.

 

[Robert Johnson]

Nobody will know.

 

[Tom Tittermary]

Nobody's ever gonna find out. But it's... I think that, like, the classic 101, like, if I'm having an issue with my, you know, my internet service at home and I call Verizon, they say, turn it off and turn it on.

 

So that's always help desk number one. Number two, when you get into the weeds, right, the 201, 301 is always like, well, what changed? That's always the next question relative to any level of troubleshooting or outage that I have run into in most of these cases.

 

And the hard part is when I'm troubleshooting as the CIO of my home network is I will ask my family, one, my daughter will say, well, the internet's broken. And I promise you, honey, the internet's doing just fine. Like, there's something going on in the house that's the problem and I'm trying to get the root cause and I'll ask, well, what did you do?

 

I didn't do anything. That's the other question is when you're trying to go through these troubleshooting matters, I could imagine just like from my perspective, either in professional life or personal life, having an audit log of everything that changed on every individual device would be a very, that probably would be the first place I went to if I had that in my organization.

 

[Robert Johnson]

Yeah, that's absolutely correct. It is the right strategy. When you really think about it, in some respects, many of the tools and many of the methodologies that we use in the security industry are really kind of backwards.

 

We're always chasing the bad things, trying to figure out what bad thing happened. Can I give it a name? What exactly does this virus do or piece of malware do?

 

Has it been fingerprinted? We think that's the wrong approach at Simcor. Instead of trying to chase all these bad things out there, instead, let's identify and categorize what you have in your infrastructure.

 

Because from there, we can identify with 100% precision when something is deviated from that authoritative state. I mean, the bottom line is, you both are security experts, how do you hack a system without changing it?

 

[Tom Gianelos]

So it's a known good versus unknown bad approach. Exactly. That makes sense.

 

[Tom Tittermary]

It's a good and bad or value judgment. The fundamental objective truth is there was change. And then you get to the root cause of what was the source of that.

 

And then, by the way, the intent and the effect might also, one might be good and one might be bad on the other side. But the fundamental truth of the whole thing is there was change relative to the environment.

 

[Robert Johnson]

And having that visibility gives you the ability to start making some decisions related to that change. Now let's review those changes.

 

[Tom Gianelos]

So I guess I was more so saying you at least can understand a baseline of what you have. And Tom's right, it's not a good, bad or indifferent, it's just this is what you have. And this adheres to whatever company requirements and compliance requirements that are there versus trying to understand what's going on in the wild, wild west and trying to make that good, bad, again in air quotes, determination as it's coming in and how it will affect the systems in play.

 

So that makes perfect sense.

 

[Robert Johnson]

With over a million variants of malware being created a day, really, how do you? It's impossible.

 

[Tom Gianelos]

Even, I remember the CEO of Norton many, many years ago said, we've lost. We've lost the virus game. We cannot put out signature remediation in time for all the variants that are coming out at us.

 

So that's not a good way to work.

 

[Robert Johnson]

Even when you tie in AI into it, you know, it's based on previous things that have occurred. When a bad actor is targeting your system or as Tom mentioned, someone was not trying to be malicious, just making unexpected changes. Both of those slip through the radar of your current EDRs, TDRs and AI driven tools.

 

At some point with all the great tools out there, at some point you need something in your infrastructure that will let you answer one simple question. Is this system in the same state it was yesterday? Yes or no?

 

That's it. We're going to get more complex than that. Is it exactly how I expect?

 

And I think that's the intent with the say 853 FISMA. It has a section there, SI for system integrity, that really says that you must have this baseline, this authoritative baseline and measure the integrity of your systems.

 

[Tom Gianelos]

And I wonder how many companies actually make that assumption? Well of course everything is the same. Because they may do a cursory evaluation or something.

 

It looks, smells, behaves the same. So no changes on this. But those changes as you pointed out could have been so subtle and so buried the tiny needle in a massive haystack change that is affecting it in a way that's beneficial to your bad guy.

 

But you have no idea. No way to actually see that.

 

[Robert Johnson]

Not at all. And we provide that visibility.

 

[Tom Tittermary]

So getting into, not so far into the weeds right? So let's go from about 10,000 feet maybe down to about 7,500 or 6,000 feet. How is Simcorp doing this?

 

Relative to Enterprise IT in general, there's a wide variety of different devices in there. How are you guys effectively doing that? To be able to pull from such a wide variety of sources in the environment?

 

And then how are you figuring out signal from noise on the back end? Relative to normative behavior versus deviation from standard?

 

[Robert Johnson]

Sure. Well, we have for things that have an operating system, like Windows, Linux, Solaris, Mac OS X, HP UX, AIX, FreeBSD. We have an agent.

 

You load an agent on the machines running those operating systems and from there we can identify changes with a high level of precision and detail. We prefer the agent based method because it allows us to gather forensic data related to whatever event has occurred. That's critical.

 

And allows us to do it in real time. You can't load an agent on everything. Think about cloud infrastructures.

 

Think about network devices. So in those cases we have alternate ways of getting the configurations. Perhaps it's over SSH.

 

Perhaps it's over some API, REST API. So we will find the optimal method of gathering the information from whatever target device and attempt to grab all the relevant configuration data for that machine and store it into something that we call the master repository. Now this master repository does two things.

 

It maintains the authoritative baseline for each one of those devices. It also holds the policies the instructions for how we respond to different events for the respective machines when there's drift from those authoritative baselines.

 

[Tom Tittermary]

So are you guys doing that kind of in association with whatever the standard CMDB configuration management database lives inside the organization? Or is there any give and take relative to that? From what I'm hearing is I see you guys as the audit log around any of the individual changes to the environment.

 

Are you then going back around to the CMDB to update change? Are you reading from the CMDB to pull some of your baseline? What's the interaction that happens there?

 

[Robert Johnson]

Yes, that's a very good question. The baseline is maintained in an immutable state within our product. However, the other half of your question is do we connect to CMDBs?

 

And the answer is yes. We connect to ITSM systems such as ServiceNow, BMC Remedy, JIRA, and others. And in that case, we established a two-way communications with that ITSM system.

 

So that lets us do things such as as changes are being made, if they're unexpected changes, you can have them automatically open up a ticket saying this needs future investigation.

 

[Tom Tittermary]

As opposed to automatic remediation at the code level, option B would be immediately, the policy is immediately fire a ticket over to ServiceNow with a high priority. Or remedy, or not to pick one.

 

[Robert Johnson]

And then your ops team can respond to it. Another way that some people are using our tool is that going from your ITSM system such as ServiceNow into SimTrack. So you create a ticket saying that I'd like to update these 50 systems between 3am and 4am.

 

We're going to install Microsoft Office. Well, if it's synced, SimTrack will identify that there is a change window for these 50 targets in the ticket. And any changes that occur on those 50 systems during that 2 hour change window will automatically be associated back with the ticket.

 

So now you've created this audit trail of exactly what was done, and right within ServiceNow or whichever tool you're using, you can see what was done. Now that's a first. If you think about it, how it typically works, I'm going to install Office on 50 machines, you create a ticket and you assign it to Joe saying, Joe, you need to install Microsoft Office on 50 machines.

 

And when he's done, he simply closes the ticket. The entire change management process the entire ITSM system process is based on the honor system.

 

[Tom Tittermary]

You could say there's a level of trust there.

 

[Robert Johnson]

There's a serious level of trust. Now we're adding a level of accountability to it because we're taking that audit trail now for the first time ever and associating it back with the original ticket.

 

[Tom Tittermary]

I could trust Joe. I don't know why we keep talking about Joe. Everybody in my family is named Joe but me is the funny thing.

 

So anytime we're like, oh Joe I'm like, hey. We could trust Joe, but we'd rather have the data. We would rather trust but verify.

 

We're not going to try to have faith in Joe. Joe. It's always Joe.

 

Let's just use Joe as the standard now. Sure you filled that ticket Joe. I'm not trusting you.

 

You were doing something over there. It's an interesting point because now relative to that you've got a clean audit trail almost like a chain of custody between the person who instantiated the ticket the person that blessed the ticket. It exists in a system of record.

 

The changes happen. I have a very granular view of exactly those changes happening and then I report back not Joe that those changes were accepted in that system and it all relates back to that ticket. Versus the chain of custody ends and begins with our faith in Joe and the fact that he actually did what he was supposed to do in the environment.

 

That's absolutely correct.

 

[Robert Johnson]

So now we're starting to see a gradual intersection with zero trust and integrity.

 

[Tom Tittermary]

Yeah. Well it's interesting. When we talk about zero trust and we were talking about this.

 

We always have a conversation before the conversation. We were talking about the standard definition of zero trust is making sure that the right person or thing gets access to the right DAS, data application asset or service from the right location in the right context off the right machine with the right posture and that's zero trust. And we think about it from the aspect of the consumer but we don't typically have the conversation from the aspect of the DAS and the state of the DAS.

 

And is it in a good state? Is it not in a good state? What's the compliance of that individual server or asset or data component on the far side?

 

But that's really what you guys are bringing to the picture here.

 

[Robert Johnson]

Yes. That's exactly what we're bringing to the picture. What difference does it make if a person has access to the right resource at the right time?

 

If that resource, that endpoint is not in a state of integrity. So we have some great integrations with Zscaler that allow you to do some amazing things. Imagine that you have some critical endpoint.

 

Perhaps it's a HR system and it's been compromised in some way. Currently, you would maintain and allow a very secure connection directly to that endpoint. But if it's compromised, what have you accomplished?

 

SimTrack would detect it's been compromised and then dynamically update your Zero Trust rules in ZPA to say okay, anyone now accessing this HR server, since we're suspecting something's incorrect with it, is going to be put into browser isolation mode or some other mode of operation or even isolated off the network. So now we're taking static, instead of having a bunch of static Zero Trust rules, we're making them dynamic based on the health security posture of your infrastructure.

 

[Tom Gianelos]

Could you reverse that and so if a user's machine that was accessing one of those applications, so Tom talked about the levels of checking that we can do from a device posture standpoint, but can SimCore evaluate that user's device that he's using and say, you know what, this doesn't pass muster, something happened to this device now instead of not even allowing browser isolation, can you write the command to say you're going off into a nothing VLAN or something like that?

 

[Robert Johnson]

Yes, we can do that. We can do that based on integrity, if that device has been compromised in some way and we can ensure that certain files in a Windows directory have been altered, it's likely not safe anymore, now let's put that into that VLAN, no man's land that you've mentioned. Another use case for that is for defense networks, every system that connects to the network should be stigged, correct?

 

How do you actually enforce that? So with SimTrack because we can assess and see if those systems are stigged or not and the level for which they're stigged you can set rules saying if a system drops below 90% of all the controls for a stig being implemented, now isolate them off and put them into that VLAN, no man's land. Otherwise allow them to have access as expected using ZIA.

 

So we're once again, we're dynamically updating and updating ZIA and Zero Trust rules based on the status of that endpoint.

 

[Tom Gianelos]

Is that per connection? So every single time that user goes out to try to access something somewhere that evaluation is always being done?

 

[Robert Johnson]

Yes. That is on a per connection basis. So true comply to connect.

 

It is true comply to connect. And in fact, those are just two scenarios. All of those actions that you can take when setting up your ZPA rules every one of them you can take advantage of in SimTrack and create possibilities we haven't thought of before.

 

Perhaps it's a Cisco device that had new ACLs added to it. Perhaps at that point we should control access to that section of the network. We can do that in ZPA.

 

You can implement those rules dynamically.

 

[Tom Gianelos]

I know a lot of firewall engineers that would not enjoy working under this regime. Yeah, the regime. I can't tell you the number of ACLs.

 

I'll just write this for a second. No, that doesn't fly anymore. No.

 

[Tom Tittermary]

Everyone is very diligent about cleaning up their firewall rules. There's never been a firewall out there that has 10,000 rules that got written for five minutes once that have lived on a system for seven years.

 

[Tom Gianelos]

That's never happened. People scratch their heads and go what does this rule do again?

 

[Tom Tittermary]

They wouldn't do that in the DOW or the WIB. That would never happen. WIB is a tricky one.

 

WIB is a tricky one. DIB sounds strong, but we're going to have to go with WIB. That's kind of where we need to go from here.

 

One of the other things, so from a logging perspective, SimCore is providing data over to, I'm sure that you guys are shooting logs to different SIM infrastructures, right? Relative to a change perspective. Are you having interactions with folks that are running the SIMs and those SOC type operations where you guys are accelerating the root cause and how is that happening?

 

Because I imagine that the folks in the SIM the moment that something flashes up as yellow or red in their environment the two things they're looking for in that environment are access to the system that's potentially a risk or change against that system. Are you guys see yourselves getting used in that way relative to the SOC operations?

 

[Robert Johnson]

Yes, that's a very astute question and we really are. I always attempt to be astute.

 

[Tom Tittermary]

Thank you for that.

 

[Robert Johnson]

The WIB appreciates it. The WIB always appreciates astuteness, but moving on. Yes, so regarding SIMs there's a lot of data that's going to SIMs at this point and we're one more of those data points going to the SIM.

 

It's getting to a point right now for SIM vendors especially for the analysts that have to actually look at all that data. This promise of having the single pane of glass for everything that's happening to the infrastructure has turned into this single glass of paint that has become very difficult.

 

[Tom Tittermary]

My favorite rap band from the 90s Glass of Paint.

 

[Robert Johnson]

Yes, and it's become almost impossible to sort through it. It's becoming a little bit better with AI to help with that manual evaluation process but that's a tough job.

 

[Tom Tittermary]

There's a lot of really interesting stuff going on. I'm not going to name vendors or stuff that I've seen. There's a lot of agentic AI SOC operations stuff going on right now that I've seen out there.

 

Which is, by the way, that's one of those, how many times have we used the acronym like we need to separate the hay from the needles or burn the hay to find the needles or it's these needles, right? That's a key AI task I can imagine. There's one identifying to provide hey, here's the linkage that I see relative to that needle and where it came from.

 

[Robert Johnson]

Here's an important piece. When you have all that data in your sim and you really don't have a starting point for where to look. Now imagine this world where when SimTrack tells you that something has happened it actually happened.

 

There are no false positives. When something has changed, it's changed. Instead of looking at all these items if you look at your sim data, you have a bunch of things that happen in your firewall that actually don't mean a thing.

 

[Tom Gianelos]

They don't really matter.

 

[Robert Johnson]

None of it matters. All these informational messages. You can use SimTrack as that most significant variable when doing your correlation analysis or as a starting point for investigations because the sim core says something happened on system X.

 

You can use that as a point of building context. Instead of just looking at this whole big massive wall of events, you can say okay, if something happened at 3am because SimTrack says something happened, now let's start looking from 2.30 to 3.30. There's the needle. We have a starting point.

 

Now people can wrap their minds around the problem. It's difficult to see a pattern when it all looks the same.

 

[Tom Tittermary]

We could toss it over to our friends over at Vector AI and have them run the math against the pack of captures after the change stamp relative to the time. It's funny to watch. I love working on security because it's funny.

 

We figure out how to block things and they come up with new aspects. The tooling on the back end changes so much so quickly too. I remember when a bunch of my friends started going over to Splunk and there was these massive amounts of data.

 

I started having conversations around there's no way to get actionable intelligence out of a terabyte of data. I remember those words coming out of my mouth like that's too much. Now we've got literally AI energetic AI popping up out of the sock where it's like no no no.

 

As long as you can move that data fast enough, as long as you've got the data in the right media on the back end, more data is better. It's going to help out in that aspect. Having these types of pivot points in the data processes where it's like I don't want to just look at all of the data in the petabyte the same.

 

I want to start somewhere meaningful. The change data I think would have to be relative to any red, yellow, or green where I have a notion of where the problem of the environment might come from. That's the data I would probably go to first is the change data relative to the environment.

 

[Robert Johnson]

That's right. When you think about any type of correlation analysis you have significant variables and least significant variables. You would have some track in the category of data points that are weighted in a more significant fashion.

 

I think that it adds a lot of value and helps wean through that terabyte of data and pick out the important items. Even when using AI because it's not going to ignore SimTrack data AI on its own will determine this. These are significant variables that need to be used as part of the analysis process.

 

SimTrack is the one piece that when it says something has changed there's a 100% probability that it changed. Unlike every other tool out there that uses AI because AI by nature is just a series of probabilities. You're never quite sure if the answer is derived or not.

 

Right, the answer is derived. As much as I love AI and I really do but I really think we need something definitive in our toolbox and that's what SimTrack provides.

 

[Tom Tittermary]

It's interesting, right? It's not to get corny but it's one of the truest things ever we just talked about the industry changing but the only constant is change to any of these environments, right? And then to put corny on top of corny, I'll quote Robert Frost, nothing gold can stay, right?

 

So a golden image is a golden image for a time and then the world changes, environments change and then change happens. I can imagine, so could we get a story or two relative to some of the environments you're working in? Because I think for most environments the way that it's been for a long time is we pick a point, we draw a line in the sand and we say this is good from a security perspective and then we've got a level of trust that we haven't changed from that point in time and there's just this one time, this one thing just needed to change and it was really required for the business, for the mission or and then we drift and then we wind up somewhere else and then we come up with a new line in the sand right? Like what do environments under SimCore look like instead?

 

Because it sounds like there's active consideration around what security posture looks like, there's a clean definition of granularly what that looks like on an asset and then there's a much cleaner audit log of how that's implemented and tracked.

 

[Robert Johnson]

Right, I think most of our customers are moving toward a more formalized change management process and we enable that. One of the very interesting components of our product is we have, we call it our change reconciliation screen. It's almost like balancing a checkbook if you ever remember doing that.

 

Where you can sit. Yeah, right. I'd ring a bell way back.

 

So, for all the changes that are unexpected, we allow you to also document the change. So now you can go through and prove that you've assessed every single change that was unexpected in your environment. And in some areas such as utilities, it's a requirement as part of NERC SIP to actually triage every change that has occurred in a certain period of time and either have justification for it or do something about it.

 

[Tom Tittermary]

Gotcha. Okay, we are I'm going to make a note that we're at 31 minutes because I'm going to have to edit here. So we are at 31 minutes and I've kind of hit the points that we talked about.

 

Do we want to come up with new interesting topics or do we want to just say it's a shorter one and wrap it up in a half hour? Because I think all the conversations we've had has been really solid conversations so far.

 

[Tom Gianelos]

I'm looking at the website right now.

 

[Robert Johnson]

So we haven't talked about zero trust and the seven tenets.

 

[Tom Tittermary]

Oh, I wanted to come back to zero trust and application security.

 

[Robert Johnson]

Absolutely, yeah. And let's talk about the seven tenets and how to number five.

 

[Tom Gianelos]

Can we also talk about I was going to bring up, you have the ability to not just record changes but you have system hardening as well so you can actually bring by your system hardening you can actually bring systems to where they're compliant. Is that correct? That is correct.

 

Yeah, let's talk about that. That's actually a pretty cool feature as well. We just wrote that out like a month ago so yes, we're excited about it.

 

I'll ask how it works. But yeah, that's a good I'm looking at it and going, I think we hit kind of, yeah, zero trust system integrity, file integrity haven't really gone over ransomware but that's sort of in the same and we kind of hit on zero day attacks.

 

[Robert Johnson]

I think we can go back into zero day attacks if you want and kind of define the steps for that.

 

[Tom Tittermary]

Tell you what, how about you kick it back off and go through hardening.

 

[Tom Gianelos]

Okay.

 

[Tom Tittermary]

So just start asking the question about hardening and I'll make a time stamp and we'll pick it up there and then I'll pivot from hardening over to application security as a, I'll just bring up zero trust and I'll let you tee it off and then we'll run down that rabbit hole and then if we want to we can grab ransomware over at the end. Does that make sense?

 

[Tom Gianelos]

Sure.

 

[Tom Tittermary]

Okay. Yep, whenever you're ready, buddy.

 

[Tom Gianelos]

Yeah, that's perfect. Okay, so we'll fire it off at 3220. Okay, so Robert also, I do I'm cheating a little bit and I have your website open here and I saw we've talked about like from a remediation standpoint, the customers or your users getting help with known changes that have occurred on their environment but what about coaching them along and bringing them in a hardening process for their machines themselves?

 

[Robert Johnson]

Yes, that is something we can help with. System hardening via STIGs or benchmarks, it's actually a very difficult process. As we spoke about earlier we can assess and let you know if your system is configured properly and actually tell you exactly what needs to be done for it but here's the problem.

 

There are about 400 tests 400 settings in a STIG or benchmark that you have to manually apply and we timed it out we had an engineer actually do it manually and it took for a couple operating systems and it took from 16 to 32 hours and then manually make all 400 settings and get it right. Now imagine if you had to do that for 500 systems or 1000 especially if they're all different. Not possible.

 

Not possible, it's very difficult to do. You ever seen that TV show Dirty Jobs? Yeah.

 

I always thought the guy that had to sit there and harden all the systems and change all those settings, he's probably a perfect candidate for an episode of Dirty Jobs.

 

[Tom Tittermary]

It's like painting the Golden Gate Bridge too by the time you get to the end you start over at the beginning again, right?

 

[Robert Johnson]

You're never not painting the Golden Gate Bridge. Yeah, you're never done. So, we recently added the capability for SimTrack to not only assess if you're configured properly according to CIS benchmarks or just the STIGs, but also automatically configure these systems in a way that they are compliant to STIGs and benchmarks.

 

So instead of making that 32 hour investment for a system, we're asking you to make a 2 minute investment and it will literally configure everything and we don't do it like a hammer and basically apply the same policies to everything using GPO because that's kind of the technique that folks will try to take is maybe I can create some GPO rules and apply it to everything in my network, but everything in your network is not the same.

 

That's just asking for trouble. So instead, we assess each system individually on its own merit and make the customizations for that system and when doing that, we also make a rollback plan because you may have a set of standards defined in STIGs or benchmarks that sound great in practice to apply but you may have some system from 10 years ago that's running some specialized application that if you apply these security settings, it's broken. Now for your engineer that just spent 32 hours applying settings and now the system's broken, which one of the settings broke it? Now they'll spend another 32 hours or more trying to figure out which of the 400 settings was the problem.

 

That's terrible and you're down for another week. So we have a rollback button where we'll simply rollback and undo all the changes that we made related to getting something in a hardened state so you can get back up and going right away and then you can take a breath and in your own time, you can figure out what's setting.

 

[Tom Gianelos]

You can roll these out iteratively right? It's not an all or nothing.

 

[Robert Johnson]

You can pick a subset of machines or all of them or groups or do it by tag. You have complete control over the rollout of it and the time. Yeah, it's a really cool feature actually.

 

We're excited about it. It just got launched last month but we think it's going to save folks literally thousands of hours and I'm not exaggerating.

 

[Tom Gianelos]

Your math is unassailable there.

 

[Tom Tittermary]

That tracks and makes sense. Just to bring it all the way back home, we started kind of talking about Zero Trust. I'd like to bring it back around because that's why I think a lot of people are here.

 

I don't think it's good for my voice or for Tom's voice. I'd like to think some of the content around some of the Zero Trust stuff is why folks are here. To bring it all the way back around SimCore and kind of where you guys fit relative to Zero Trust.

 

I'll let you take first swipe at this and then I'll probably have a couple of comments, I would imagine.

 

[Robert Johnson]

Sure. I think the easiest way to see how we fit in is to think about NIST 800207 which is really that original definition of Zero Trust. In 800207 they have seven tenets that define the different characteristics of Zero Trust.

 

Two and three are micro-segmentation related and those are where you fit in. There's identity and access management. Tenet number seven is a simp.

 

Tenet number five states that the organization must monitor and measure the integrity and security posture of all owned and associated assets. Well Jim that sounds like a description of our product SimTrack. That's exactly what we do.

 

But we don't want to do this in a silo. And that's why our partnership with Zscaler is so important because I think that we can do things that no one else on the planet can do when we connect to a platform like Zscaler and can automatically activate new capabilities based on the information in Zscaler or based on information in SimTrack. So that's why it's a great example of why integrations are critical because it defines the synergy that's possible.

 

[Tom Tittermary]

Yeah I think it's so one you're dead on right there. I think one of the biggest things that we run into is I run into the notion especially in the Department of War or the WIB I can't stop saying that. Very specifically around the notion of application security stacks and protecting server based applications or cloud based resources from in a security perspective and that's interesting like everybody knows vendors that are in that space.

 

I am not tracking and I haven't had a lot of access and exposure to folks that are tracking the changes that would occur on a system if one of those, if something slipped through one of those security systems. Those security systems are good as they are because they have a notion of known bad or deviation from standard but at the end of the day if something slips past one of those standards it's going to generate a change on the server side. And then the other thing is if I'm a malicious insider or even a well meaning insider and I'm going to cause some level of havoc in an environment I'm going to be working behind the security stack.

 

But it sounds to me like from very specifically like right in that area that you just mentioned Zero Trust, the Simscore is well positioned to spot changes that would happen on systems that would be a result of both of those routes.

 

[Robert Johnson]

That is absolutely correct. And another key component is that in the web for our supply chain and in the Department of War we're also moving towards a stance where resiliency is of greater importance. We're hearing that conversation all the time.

 

You cannot achieve a state of resiliency if you don't understand exactly what's happened so you can respond. And then the mere fact that we have information on what was actually done because just to clarify we don't simply tell you this file has changed or that this network device has changed we would tell you this network device has changed and here are the 12 ACLs that were altered and here's exactly what the ACLs were before. So you can change it you can download the config and change that device right back to how it was.

 

So that is the actionable information and intelligence that you need to actually create, implement a resilient infrastructure.

 

[Tom Tittermary]

Yeah, it's interesting so I'll go back to the whole I find the Department of War formerly the Department of Defense DOD the rules and operations tend to be different in Base Camp Poster Station than they are out towards the forward edge. We had a great conversation with Jared a while back around IPORI and some of this but I could totally see in a data center there being a human in the loop relative to I'm going to manage and maintain every change relative to this environment but if something was closer to something being kinetic I would 100% say I want to track the change and I want to know if I need to revert in another stage but there's going to be decisions and changes that get made in a mission context where I hate to say it, sometimes mission trumps compliance policy in some of those cases.

 

So the flexibility you guys have in the policy structure to be able to account for that is a big deal because I could see it being binary will automatically reflect back I could see that being a mission negative in some cases if you didn't have the opportunity to allow that for a moment.

 

[Robert Johnson]

Absolutely. You have to pick the right settings and policy for the right application. So we give you complete flexibility.

 

If it's an election website perhaps that's a perfect case or ATMs those are great cases where you I think the resilient capability to automatically restore and change things right back to how it was is critical. Other applications maybe not and you simply don't set it to restore but provide you with all the actual information. You can always go into our tool download how something was say it was some critical business logic.

 

You just log into our tool and download it and then manually update it or manually make the fix. So you have complete control. Or you can simply go into our tool, right click and say rollback and it will go to that machine, to that directory and change it right back to how it was on your command.

 

So you can add that inflection point that you're looking for but still keep it very simple. And I think that still fits the bill for resiliency.

 

[Tom Tittermary]

Yeah. Things got wild there for a minute in the mission context but we need to flip back to a steady state. Let me go from the rollback relative to these individual changes.

 

And you're going to have a time stamp from when those changes started occurring as being necessary from the mission context the ability to not have to crawl through those changes that happened and then crawl them back to be able to say no I want to roll back That sounds really effective too. Because nobody wants to be out there patching and out towards the front you want to be able to get back to the business of whatever the mission might be.

 

[Tom Gianelos]

How chatty so you talked about a repository where all the data is being held, right? How often are these machines communicating back to the repository? Do they ever just say no change, no change, no change, just keep reporting back?

 

Or there's no comms until something happens and then it reports just that change itself.

 

[Robert Johnson]

There are it does not simply say no change, no change, no change that's not the way it works. It only reports back changes when there are actual changes but it does send a heartbeat on a regular basis. You can specify what's required there but having that heartbeat saying SimTrack is still active, involved in monitoring is critical because if someone stopped our agent or stopped something on the endpoint you're protecting, the heartbeat allows our master repository to know that this critical asset out there is not responding anymore and that you should take action.

 

[Tom Tittermary]

That completes the audit log because the heartbeat says I guarantee there were no changes on this system in the last minute. That's right. And if it misses a heartbeat then there were potentially changes on that system in the last 59 seconds.

 

[Tom Gianelos]

So can the system come with the paddles and restore the heartbeat on anywhere?

 

[Robert Johnson]

The restore is there. If it was offline and came back online, it double checks everything. So it doesn't at that point simply look.

 

And this is why a baseline is so important. So many antivirus tools will try to say now that they do integrity monitoring. They're not.

 

They're simply saying file changes. That's useless. You need to know exactly what it should look like first so then when you reconnect you can say okay does this match the expected authoritative baseline.

 

You don't have that authoritative baseline. You're just getting garbage because you don't know exactly how it should be. Makes sense.

 

[Tom Tittermary]

In the world of infrastructure as code, I could see tiny little changes deep in the weeds of a Kubernetes statement like having potentially massive impact.

 

[Robert Johnson]

And it saddens me because this message about change monitoring and now mapping that to somehow mean integrity because major vendors are actually starting to do this. Major EDR vendors and XDR vendors are doing that. It's really confusing the industry and it's hurting the industry because I hate it's terrible that people are checking the box for PCI integrity monitoring or SI section of 853.

 

I'm doing integrity monitoring but they've never read what is defined as the capabilities required to achieve system integrity. They're just listening to the vendor saying we do that because the sales guy said it. It's a real problem and it puts us all at risk.

 

I tell you what, those sales guys are the worst.

 

[Tom Tittermary]

So one more, I'm going to make a hard right pivot here. Let's talk about one of the other things I had an opportunity to look at the website earlier. We haven't talked about ransomware at all.

 

If we can talk a little bit about ransomware in the context of SimCore, what you guys can do relative to that fight, I think that would probably be really beneficial to folks out there as well.

 

[Robert Johnson]

Sure. Well for ransomware, most of the time when people think about ransomware you think about it in the context of all my files being encrypted.

 

[Tom Gianelos]

Right?

 

[Robert Johnson]

Well in reality that's like step two or step three. Step one is that you receive that malicious payload. Step two is they got downloaded and added to your system.

 

The change occurred. Step three is once it's detonated in some way then that's when your files get encrypted. We focus on step two.

 

The moment that ransomware is added to your system, that's the change. That's the point where SimTrack can do something like automatically remove that ransomware executable at that time and remove it right away or notify you and hopefully your team, if they want to be in manual mode, will pay attention to the ticket and make the modification to remove that payload that was delivered to your system. So it's the encryption piece is really the final phase in a ransomware process and we're focused on much earlier in the process.

 

[Tom Tittermary]

It's always interesting to me with these ransomware attacks too it's the local encryption of file content. There has to be, so one there's a, you gotta be able to spot the payload as it lands. Two, you have to allow for local execution of EXEs on the system to start the encryption process.

 

The other piece of that is I have to imagine I'm not deep enough in the space I might be telegraphing my ignorance here, but the CPU and memory requirements of the encryption, I don't know if they could slow it down to have it happen over a longer period of time, so it's not flagging CPU and memory resources too, but another one of those things you could watch for against the system. But, the way to get around all that is to notice the file change against the system about a net new .exe getting brought in to be able to kick that whole process off.

 

[Robert Johnson]

And that's the ideal space to catch it. If for some reason we decide I want manual processes I'm not going to have it automatically stop and take that file away. And because of that everything gets encrypted on this curricular system.

 

Fine. You go to the SimTrack Management Console and remember that button I told you rollback? You simply go to the rollback button for that system in that directory and roll it back to how it was.

 

Basically undoing all of the encrypted file changes that were made.

 

[Tom Tittermary]

Are you able in that scenario to not a level of like attestation right, but like a file was loaded on can you roll that back to a user or an identity that put that file on that system?

 

[Robert Johnson]

Yes, we know exactly who made the change when they made the change what process was used to make the change for instance they went into Notepad and made a change to a file we're going to tell you Notepad was used here was the thread ID, the process ID the user they made to change and sometimes even an IP address for which they came.

 

[Tom Tittermary]

And if you've got SimCore on the asset that dropped that got the payload delivered and you have the identity of the user that probably got pwned that now is delivering the .exe now you can basically there's an audit trail back to the individual user too. SimCore is there as well. Did a change happen to that?

 

What ended up happening to that host right? Did this host get pwned or rather the change process or is this a malicious insider or? I got to think that that's super valuable in one of those cases.

 

[Robert Johnson]

Right, absolutely and even on Linux when you might log in as one user and pseudo to another in that case many tools don't recognize who was actually logged in we actually traverse back and we actually know the actual user that made the change. Not necessarily the user that you pseudo to.

 

[Tom Tittermary]

Very good. Guys, so Robert thank you so much for coming in today. I think the conversation has been really really good today.

 

I thank everybody out there for tuning in to another episode of Zero Trust Given. Reminder to everybody out there, one, thanks for listening two, if you could like and share I would greatly appreciate it three, if you have a question that you think would be a good question for us to address on the show zerotrustgiven at gmail dot com is the email address we use for the show if we read your question on the show and we respond to it we'll get you a nice little Zero Trust Given care package.

 

We'll figure that out. But again, for myself for Tom, for Robert, thank you so much everybody for listening. Have a great week.