When you think of cybersecurity, we normally only think of technology, but cybersecurity is much bigger. And today, I speak with someone who has been thinking harder than anybody else about the bigger dimensions of cybersecurity. Welcome to another episode of the CISO Perspective. I'm Berthold Kerl from KuppingerCole, and in that series, I sit down with security leaders who actually are responsible to lead cybersecurity in the world's most demanding organizations.
And today, I'm actually invited by my guest. So he hosts me, if you want. And here we are in Bonn at Deutsche Telekom, and I'm sitting down with Thomas Tschersich, CISO of Deutsche Telekom, and also part of the executive committee of Deutsche Telekom Security. Thank you for giving me the chance to interview you. And at the very beginning, I'm sure the audience is interested to hear more about you. Usually I had to say, thanks for having me, but in this case, thanks for coming over, Berthold.
Yeah, so I'm Thomas Tschersich, so being responsible for the couple of decades here at Deutsche Telekom for security. I started with cyber, so that's coming from heart. But meanwhile, I'm also responsible for personal and physical security, and it all comes a bit together when we talk about threat landscapes today. And in my other role, we're serving meanwhile more than 700 customers in mainly cybersecurity. Thank you. So when we prepped for this interview, you suggested to talk about the 360 degree view of cybersecurity. What actually did you mean with that?
Yeah, if we focused just on cyber, I believe it's not enough today. So we do have workforces which can cause harm on cyber, and I'm sure we will get there. We do have geopolitics, we have supply chain, we have technology, we have organized crime, threat actors and the like, and we have regulation. All of these areas influencing the job of CISOs today, and all of them kind of influencing the exposure level of my cybersurface and the company today. So that's very complex undertaking. So let's perhaps start with one of the first dimensions. So let's start with the human, with the people basically.
So the narrative often is humans are the weakest link. And I know that from your public talks, you have a slightly nuanced opinion about that. So I'm curious to hear that.
Yeah, when we talk about that, often people in my role are stating that the biggest source of problems is the employees. And I'm not convinced that this is true. So if we build shinny systems, people have to use, so they can't do their job. So who is guilty then? The one who built the system or the one who has to live with the system and to act with the system. So that's the reason why I have different perspective. So in principle, if we can't trust our employees, for instance, then who can you trust then?
We need to trust our employees and we need to enable them and we need to help them to act in a secure manner. We need to design systems in a way that they can act with them in a secure way. And if we overwhelm them with too complex passwords, they have to change very frequently, once a week, then it's no surprise they're noting it down. And what is then better, the downloaded password or the less complex one, which is not noted down.
Yeah, so that's what I mean with that. But if we talk about the people dimension, especially in cyber, there's also a different view on that and different perspective we need to consider. So we're facing in middle Europe, a demographic challenge. In the next couple of years, we will lose a lot of the labor forces here, the workforces as resources, not being replaced by younger generations. So what is the answer on that? So one potentially answer is to solve that with technology and automation. Another example is we can go to different markets where we don't have this problem.
For instance, we can do offshoring to India. But if you do, you might enter in the next problem in the geopolitical issue here. So that suggests that there's an interlink between those dimension I mentioned before. So in that case, between people and technology, between people and geopolitics, and this needs to be balanced out.
Yeah, so you mentioned already, but the regulation, of course, is also a dimension of the 360 degree view. So NIS2, DORA, you name it, right? So in Europe, we have an unprecedented density of regulation. Is this the right level? Is it already too much or still too little? What's your view here?
Yeah, this is one we can be proud of. Yeah, so we're a work model leader in regulation. So actually, everybody is kidding on us around the globe, and this is giving us a weak position in the market. So don't get me wrong. Regulation is sometimes needed. Every time industry fails, regulation is needed. So politics has to regulate and has to correct. But what we achieve right now is kind of an over-regulation. And I give you an example.
If we would have a cyber incident at Deutsche Telekom, as a telecommunication operator, think about that, and think about customers being affected by that, and think about customers from financial sector being affected by that. We have to notify to five different authorities in five different sheets, five different channels, five different contents. But the content is overlapping by more than 90%.
Yeah, and here starts a problem. I use five people to do all the notification, and I have eventually only one left to solve the problem. Is that right? So in an ideal world, in my view, we would focus that more and say, okay, there's one notification, and everybody in the back is grabbing then the information out of this single entry gate, yeah? So that would create more efficiency for us and also for the authorities here. And I respect the need for notifications, but the way we implement those things are totally over-regulated.
And if you talk to Deutsche Telekom, we do have the resources to solve it. But what is with the classical German Mittelstand, the SMBs, they don't have, they don't have, and that's a problem. And of course, given that many of these smaller companies do big deal export in many other countries, they are faced with that problem today, right?
Yeah, and they have also to be compliant with other regulations in other markets, right? And here, there's again an interlink between people and regulation. So if I would need six people to do the notification, and if I run in a skill shortage because of an over-aging population, you see the problem, right?
Yes, absolutely, yeah. Now, you mentioned geopolitics as another dimension.
Of course, I think there was, I can't think of a year in my life, and I'm 60 plus years old, where I've seen more wars, more problems with trade and other crisis across the world. So how has the threat landscape changed because of this new dimension? I think it's very, very new and very, let's say, focus, in a focus of- Is it really new, or did we just close the eyes for a couple of years? So I believe that the later is the thing here. So here's the problem with geopolitics. And we're talking these days a lot about sovereignty.
And if we talk about full sovereignty, we gave that up 20 years ago, where we decided to build global supply chains. And I'm giving you an example here on chipsets. Chipsets and regulation around that is being used as a trade weapon already. So there are sanctions from the U.S. on China. There's sanctions from China to the U.S. and the like. So everybody's trying to get an advantage by not providing the latest capabilities to its competitors or enemies or whoever you would call them. And here's the problem.
We then start talking about, we need to bring back capabilities to build our own chipsets in Europe. But if you want to build a computer, you need resistors, you need capacitors, you need current regulators and the like. So very cheap stuff. When this is coming 100% from a single source in Asia, so then you're in the same problem. So we don't oversee today our supply chain. And a single resistor for the cost of a quarter of a cent can cause a big harm on you when you need to build a computer and not get access to those parts. And we saw that also by different incidents.
And think about the Ever Given was stuck in a Suez Channel. There were containers on the Ever Given, this container ship. And in this containers, there were filter inlets. Filter inlets being used by Cisco to avoid dust in the routers. So they weren't able to sell the routers to the market because they didn't get access to the filter inlets.
So again, this couple of cent article, which was then creating harm. And now think about nation states using that as a weapon and trying to shorten the supply on such cheap components. It's very much under the radar, but it will cause big harm. And therefore it's clearly a security issue because then we're not able to renew our firewalls or renew all cyber defense capabilities because we were relying on those components. But this is indeed a complex and I think widely unsolved problem for many reasons, right? We are dependent on so many parts which we have no impact on.
So in theory, CISOs or companies would need to check whether everything is okay. But in practice, this is close to impossible.
Yeah, and here's the problem exactly. So if as a CISO, you just look on whether a cyber attack is killing your firewall or not, that's unfortunately not enough anymore. You also need to look whether there is sufficient supply. Do you have dependency on the supply chain? Are you able to rebuild stuff once it's out of support, for instance? Are you able to get access to new components and the like? So you need to get a much broader view in my perspective.
Now, Serenity, if I recall, at the Munich Cyber Security Conference back in February was one of the most used words ever. So I don't remember that that word was used so often any time before. In most cases, it was in the context of being dependent of the hyperscalers, et cetera, et cetera. So Deutsche Telekom has now launched together with Palo Alto, the Sovereign Cortex project or offering. So what's the background here and what are your targets and what are the advantages?
Look, as I said before, the full sovereignty is kind of a fairy tale. Nobody will be full sovereign on this planet anymore. So what else then can be achieved? And the thing is, in my view, you can achieve still operational sovereignty and data sovereignty. And if you would shield the entire market, take the example, you would shield Europe against US security products. We would just shoot us from the best technical product. Does that make sense? Not at all, in my view.
So what we do together with Palo Alto, we bring the best technology available and we operate the technology in a way that we achieve data sovereignty and operational sovereignty. So we can guarantee who had access to those datas from the customers here. And this is exactly what we're building. So we bring that into operation with our teams in the German data center, operation out of Europe to provide this level of sovereignty. But at the same time, we can make use out of the best technology available on this planet.
But when you think of latest technologies, like obviously AI, but also NHI, crypto, quantum, what do you think are the trends or which kind of technology will influence our security situation in the next two, three years most? Let me clean up with one fairy tale regarding quantum, but first talk about AI a bit. All right. When we talk about AI, the big challenge here is we can't trust our eyes and our ears anymore. And by the way, for the first time in humankind, you can fake everything. I just need a five second snippet out of this podcast to fake your voice and even to fake your video.
Well, I'm draconian. So that's the problem, it's so easy. So question here is what can we do about this? At the same time, this is technology which can create great benefit for us. So if we just ban it, that's most probably not the answer. So we need to learn how to use this technology without falling into the traps here. So in that space, I believe we need something like an HR department for agents in future. And by the way, agents are also behaving like real people.
If you just compare from the pricing perspective, for instance, for these high developed models, you pay a high token price, for the lower ones, you pay a lower price. And it's the same with employees. For high skills, you pay more than for less skilled people. And every agent needs an identity. Every agent needs an identity and every agent needs also kind of restriction what he's allowed to do and what not. So there's many similarities we can learn from the classical world and we just need to transfer to them.
If we do that right, we can overcome the harm and we can create the benefit out of it. But of course, we would need to implement in future new kind of technologies, new digital identities to ensure that the ones talking to each other over video conference are really the ones intended to be. So this can be ensured with digital certificates, for instance. So that's the AI part. And many people underestimating and at the same time, overestimating the capabilities of AI. We also need to come to that point and really figure out what is AI really able to do and what not.
At the moment, it feels a bit like the Rosamunde Pilcher movie of AI. Everything is corn world, green, nice environment, cozy place to live in, but it's actually not. And we need to figure out where is the traps and where is the benefits, much better than we do today. But we will, I'm pretty sure. So when we talk about quantum, so everybody talking about quantum these days, I believe there's around 20 people who really understand quantum physics on this planet.
But everybody's talking about, it's a bit like in the soccer world championship when we have 70 million soccer coaches, national coaches immediately here. It feels a bit the same in the discussion about quantum. So there's a lot of debates. Every crypto is broken in the future. Everything can be hacked and the like. And this is simply not true. We do have the mass available, providing algorithms which are quantum safe. The real problem is we don't have transparency in which devices or which areas we do have weak algorithms needs to be replaced. And where do we have sufficient already?
So it's not a technical challenge itself. It's more transparency challenge we are facing. So sometimes people arguing, yes, but there is this store now, decrypt later.
Okay, that might be a threat for companies investing a lot of money in R&D like pharmaceutical companies who wanna earn their- Protect their intellectual property. Protect that and wanna earn for the next 20 years out of that. That might be a challenge. But in most of the use cases, there is the information of yesterday is outdated and tomorrow already. So therefore I see that more relaxed and more calm here. We need to work on the transparency here, but that's more or less the issue.
And when I talk to the people really working on inventing quantum computers, what they're telling me roadmap wise, eventually in 32 to 35, we will get there that we have quantum computers who eventually can run Shor algorithm. It's not proven yet.
Yeah, so everybody is thinking that will be possible, but the proof is still missing. Once we will have the proof, that might be done a breakthrough, but again, it's no rocket science in my view.
Yeah, I've seen probably same amount of people who underestimate quantum as the ones who overestimate the quantum. Yeah, I would say you need to take it serious, but you need to focus on the real problem, which will be caused by quantum computers. And I've dedicated a session, an episode on quantum together with one of our council members, Connie McIntosh. So everyone is invited obviously to watch that one as well. So 360 degrees view of security.
I think we only touched the surface, but I think people got an idea of how complex the topic is if you have to look at all these dimensions with the real focus and importance. What I'd like to do now, so stop, sorry. Maybe one advice at the very end. Okay. Open your view on the risk perspective. And just one idea, you can attack a data center by a cyber attack. You can attack a data center by a power outage, or you can attack it just dropping Gibbs power, this is called in English, I don't know. So powder in front of the air condition and then the air conditioner will most likely fail.
So that's a different vector, but the result of those three attacks is always the same. An outage in a data center. So therefore we need to broaden the focus in the view we're thinking about a problem.
Yeah, yeah, absolutely. Now, what I normally do in these episodes, I like to do what I call quick fire session. So short questions and equally short and spontaneous answers would be appreciated. So we touched on some of the topics already, but let's get it to the point.
Humans, weakest link or first line of defense? First line of defense, if we do it right. One regulation you'd cut tomorrow if you could. Reporting channels.
All right, that was easy. Biggest threat right now, state sponsored actors or organized crime? Organized crime cause this is responsible for 90% of the attacks. European cloud or hyperscaler with sovereignty add-on? That's a tough question because cloud is on-prem in somebody else's premises, right? And it's a question of trust at the very end. Trust your partners or verify every single one. Where do you actually sense it's quite a big spectrum? Trust is good. Verification is always better. If you could. If you could.
I think we touched on that already, but just to make the point, post-quantum, the genetic AI or non-human identity, which one keeps you awake at night? None of them keeps me awake, but all of them have serious impacts on security. We have one sentence for young people who'd like, who consider to go for a career in cybersecurity. What would that sentence be? Look always for the mission impossible because it's much harder to fail in the mission impossible than you'd think. Everybody believes you will fail. So if you fail, you just fulfilled expectation.
But if you succeed and only a bit, you overachieve expectation. So you can win much more in a mission impossible than you can lose.
Yeah, all right. So that's interesting advice probably true also for other professions.
Yeah, thank you, Thomas, for this very first, for this first part of our talk. We will soon follow with the second part and I'm looking forward to see you there. Thank you for watching this episode. And if you liked it, tell your peers, tell your contacts or also visit Thomas or myself on LinkedIn where you'll find more information. If you don't like it, just tell us. Exactly. Thank you very much.
Thank you, Bertrand. Thank you.