Niloo Howe on Cybersecurity Innovation Trends

501 views
•
February 19, 2021
by
RSAC Cybersecurity
YouTube video player
Niloo Howe on Cybersecurity Innovation Trends

TL;DR

Cloud security, supply chain visibility, asset discovery, automation, self-healing systems, and human resilience are central areas of cybersecurity innovation. Startups can attract funding and stand out by addressing a large problem in a new way, drawing on relevant experience, and building alongside the expanding security capabilities of major infrastructure companies rather than automatically competing with them.

Transcript

Hello RSA Conference community, and welcome. My name is Cecilia Marignier. I am the program director of Innovation and Scholars. Today, I am fortunate enough to have the opportunity to chat with one of the Innovation Sandbox Contest judges, Niloo Howe. She is also senior operating partner at Energy Impact Partners. Today, we're gonna just talk abou... Read More

Key Insights

  • Cloud security is a major innovation priority because enterprises are rapidly migrating infrastructure and consuming applications through the cloud. Emerging solutions aim to defend workloads and data across commercial clouds while addressing containers, migration, web applications, and other elements of cloud adoption.
  • DevSecOps is increasingly important because security must be integrated earlier in the development life cycle. Protecting applications cannot be treated only as a final-stage activity when organizations are changing how they build, deploy, and operate software in cloud environments.
  • Supply chain security requires deeper visibility than traditional third-party risk assessments provide. The next generation of solutions must examine code, firmware, and firmware vulnerabilities so organizations can better understand risks embedded within the technology and suppliers on which they depend.
  • Asset visibility is essential as remote work and accelerated digitization widen the attack surface. Startups are responding with tools that identify managed and unmanaged assets, giving organizations a clearer picture of systems that may otherwise remain unknown, unmonitored, or difficult to protect.
  • Detection and response solutions are combining signals across endpoints, networks, security information systems, and other assets. This convergence is intended to reveal relevant activity across a wider environment and reduce the time required for defenders to understand what is happening.
  • Automation is an operational imperative because security teams face technology sprawl, remote security operations, and growing complexity. Automation and technology-enabled services can help operators work more efficiently while compensating for the reality that chief information security officers are outmanned and outgunned.
  • Self-healing environments are a model for system resilience in which machines understand an optimal end state, recognize when the environment is out of compliance, and determine how to return it to the correct condition while improving management of the attack surface.
  • Strong cybersecurity startups solve large problems through new and interesting approaches. The problem itself does not have to be new, but applicants must articulate its importance, explain how their technology addresses it differently, and show why their prior experience provides relevant understanding.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What cybersecurity innovation trends are most important?

The central trends are security for and from the cloud, DevSecOps, deeper supply chain analysis, visibility into managed and unmanaged assets, converged detection and response, automation, self-healing systems, and human resilience. These areas reflect rapid cloud migration, remote work, accelerated digitization, expanding attack surfaces, technology sprawl, and the need to make security operators more effective.

Q: How is cloud adoption changing cybersecurity?

Cloud adoption is increasing demand for solutions that defend workloads and data across commercial cloud environments. Organizations are migrating infrastructure and consuming more applications through the cloud, creating needs around containers, cloud migration, and web application security. It also makes DevSecOps more important because security must be integrated earlier in the software development life cycle.

Q: Why does supply chain security need code and firmware visibility?

Traditional third-party risk assessments represent only an initial stage of supply chain security. Better risk visibility requires organizations to examine the code and firmware within their technology dependencies, including vulnerabilities at the firmware level. This deeper approach helps reveal risks that conventional assessments may not expose and strengthens protection of the software and technology supply chain.

Q: Why is visibility into managed and unmanaged assets important?

Remote work and accelerated digitization have widened an attack surface that was already difficult to manage. Organizations therefore need visibility into both managed and unmanaged assets so they can understand what exists across their environments. Without that knowledge, systems may remain difficult to monitor and protect, making comprehensive asset visibility an important area for cybersecurity startups.

Q: How can automation improve cybersecurity operations?

Automation can help security teams manage technology sprawl, remote security operations, and increasingly complex environments. Technology-enabled services allow operators to become more efficient and help organizations respond when their security leaders are outmanned and outgunned. Automation also supports resilience by enabling machines to identify deviations from an optimal state and assist with restoring compliance.

Q: What is a self-healing cybersecurity environment?

A self-healing environment is a system that understands what its optimal state should be, detects when it is no longer operating at that level or has moved out of compliance, and determines how to return to the correct end state. This model uses increasingly capable machines to strengthen resilience and improve ongoing management of the attack surface.

Q: How did COVID affect cybersecurity startup funding?

Cybersecurity startup funding remained robust despite COVID, although some deals, especially early-stage transactions, took longer to reach completion. Companies affected because their customers reduced purchases sometimes received insider-led rounds when their underlying fundamentals remained strong. Early-stage investment was described as particularly robust because investors continued seeking innovation and new ideas for addressing cyber risks.

Q: How can an Innovation Sandbox submission stand out?

A strong submission should clearly articulate and contextualize a genuinely large problem, then demonstrate a new and interesting way to solve it. The problem may be longstanding rather than newly discovered, but the technical approach should be distinctive. The founders should also show how their previous experience gives them meaningful insight into the problem they are addressing.

Summary & Key Takeaways

  • Cloud adoption and remote work are reshaping cybersecurity needs. Organizations require protection for workloads and data across commercial clouds, earlier integration of security into development, and stronger visibility into both managed and unmanaged assets as accelerated digitization expands an already difficult attack surface.

  • Supply chain security must move beyond conventional third-party assessments toward examination of code, firmware, and firmware vulnerabilities. Detection and response categories are also converging across endpoints, networks, and security information systems, while automation and technology-enabled services help address tool sprawl, remote security operations, and limited human capacity.

  • Cybersecurity startup funding remains robust, particularly at the early stage, although deals may take longer to close. Strong Innovation Sandbox submissions should clearly contextualize a large problem, present a new and interesting technical approach, and show how the founders' previous experience gives them meaningful insight into that problem.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚