The world is on fire. Geopolitical tensions, hybrid workforce, and of course the rise of AI is requiring that we innovate cyber security. Welcome to the CISO Perspective, our webcast to share with you how leading CISOs think, decide, and lead. This episode, we'll talk about obviously cyber innovation and I'm very glad to have Roberto De Perales with us. Thank you. From Leonardo and I'm very happy to have you here. Thank you very much.
Roberto, perhaps not all of our audience will know who Leonardo is. Perhaps you say a couple of words about this interesting company and then of course also people would like to understand who are you. Leonardo is a global player in aerospace, defense, cyber, electronic, and it has a worldwide footprint. In Leonardo, I'm head of digital security and security operations. It means the managing of almost all technology platforms to protect the enterprise from the perimeter to the endpoint.
If we neglect the years when I was a teenager and practicing with Commodore and basic programming, after the degree, I worked for many companies, telecommunication, banking, and from 2018, I'm in Leonardo. When you look back, I think cybersecurity always has been a battlefield, of course, right? But I think everyone feels that in the last two or three years, things have even worsened.
So, what's your view on that? So, yes, the last year has changed the landscape of attacks. I think we can simplify as we have four mainstream.
One, it's the malware at the browser level that try to steal cookie token session in order to bypass multi-factor authentication. Then we have more sophisticated phishing. The third stream is the attack on supply chain software. And the fourth one is maybe less interesting at the enterprise level, but it's interesting because it's a customer level, society level. Since everyone has kids, daughters, and we want to know what is happening at their side.
So, for the phishing, there is the using of AI to make more sophisticated with the cloning of voice, making fake videos. And also, traditional one that are rising, it's the so-called WhatsApp takeover account.
So, the attackers want to send messages from the legitimate number of the victim. So, what they do? They try to log in to figure on the victim's side. They raise an OTP that is sent to the victim. Then they contact him and tell, oh, I'm Roberto, I'm your friend. I changed my number. For mistake, I sent an OTP code to activate the services. Or send malicious link in order to force the victim to put this OTP code. And finally, they take over.
Oh, WhatsApp is done and they start the mess. Then we have the attack on the supply chain software.
So, the attackers create a GitHub project. They try to boost the ranking in the GitHub search. The developers download, the malware is executed, and almost all job is done. And the fourth one is interesting.
Bertolo, I have a question. You're not prepared, but I don't think it's difficult. What almost all the teenagers do, or even they do in airplane when they are bored, that is not Netflix, TikTok, Instagram, or watching videos. What they do usually with the smartphone? Kids. They play. They play. Absolutely, they play. And the biggest platform for playing, for entertainment, it's Roblox. They have more than 1 billion users in the world.
Yes, millions of them can be fake account, duplicated bot, etc. But they have 140 active users per day and 400 million per month.
So, it's crazy numbers. And what is the frictionless on these games? You have to buy something, you have to collect, you have to involve friends, to have these tools to bypass the level, etc. And millions doesn't want to do this.
So, they try to cheat, to jailbreak the game. And there are a lot of, several ways to do this. The most common is the Delta Executor. It's something that is able to inject and run custom code, Lua code, it's programming language for Roblox, to automate and escape something. When they download the Delta Executor, there is the malware. The malware collects the information and that's why a lot of players have their crypto wallet empty. This is the most common attack.
So, let's come to some defense approaches, technologies, etc. As a chairman of the NATO study group 294, you are working on Zero Trust architectures.
So, Zero Trust has been around now for many years. Is this still sufficient or do we need to do more? Or did we still not yet completely implement it? Zero Trust is a journey, not a technology. It takes a lot of years to arrive to enforce the principle.
So, I think it's enough if we apply Zero Trust even in AI. And in the study group, we didn't invent the wheel again.
So, we propose a model of federation based on identity providers that are federated each other, hosted in the single countries, that has to comply a set of minimum requirements, very high, minimal but very high, in order to federate. And we applied the literature of a policy decision point, a policy enforcement point that speaks with another component that has other capability of data analytics, data security, etc. With a bus of interoperability layer.
So, I think Zero Trust is enough if we apply this also in AI and identities, human and not human. Yeah, that's the buzzword also here all over the place here at the conference EIC in Berlin, where we are at the moment.
So, we cannot avoid not talking about AI. So, how has AI accelerated the threats we are seeing? But of course, we can also use it as a defender.
Yes, as defender, AI currently is used almost for malware detection in sandbox, for triage, SOC automation. And I think that the vendors are introducing AI capability slowly compared to what they can do. And they give us with drops. And in many cases, they are introducing an agent in their platform that helps a lot, but is subjected to some problems and limitations. A question made in a different way has a different answer. That is a problem in a single platform that should instead be very, very, very stable and give you the right solution.
So, the attackers instead, as we can say, more freedom, they go fastly. Also, the asymmetric is the cost. They can use tools that are much cheaper, but it's not comparison. Instead to defend, you need even millions to defend properly.
And if we, for example, we think that attackers as a platform like Xanthorox, that is a modular platform that has five specialized AI models to attack, able to write code, to interact with voice, with the phishing toolkit, and also offering other capability of internet browsing, although it's just marketing, bad marketing from the attackers. And the cost from 300 per month to maximum 1,000 per month, you see the cost are different. And these are unfiltered AI that are used by attackers. But it's really so powerful, so and so. I have something to tell about this.
For example, Xanthorox, three researchers demonstrated a few months ago that it is not the capability of browsing in darknet and search engine. Why? Because they discovered that Xanthorox relies to Google Germany. It means it's subjected to external conditions, so Google can detect and stop. And that's why it's, we can say, limited.
But, I don't know, this is six months ago. Maybe now they are building their own infrastructure. They have the potential computational power to do this to be 100% unfiltered. At the same time, AI can be used to attack, to automate the attack, a reconnaissance phase, but also exploiting. But we can try to fool AI, so to put it on the defender side, because AI, in my opinion, reacts to signals, not to the entire object.
It's more, we could say, like animals. They react to stimulus, to single signals, not to make the full analysis of everything.
So, we can try to use prompt injection against the attacker, to defend. And the injection is the attack, the prompt injection, is the attack on systems that are based on LLM to inject code that is interpreted by the machine, the chatbot, and he goes out from his intent, who is trained to do.
And so, we can be offensive on this chatbot. But, or give them valid, but not real, API keys, thousands of directories, millions of directories, routed to each other, linked, chained. Or a password that AI will try to decrypt, and it will lose time, cost, and tokens. It's money. But when we speak, I come back to the injection, and I think we have to speak about ethics. Because we have no rules, there is no transparency, scope, and proportionality.
So, the proportionality, maybe we have to use these offensive capabilities to fingerprinting and detecting. And scope in a platform of deception, of honeypot, of decoy, not in live production environment, where there is an agent, a chat, that will go out from his intent. This is a problem.
And then, rules. We have to decide what we can do, and what we cannot do.
So, ethics is underestimated, maybe in security environment. So, I think bottom line is we have to accept that the attackers use AI, and we have to make use of AI as much as we can, without forgetting the ethics.
Yes, absolutely. I think that's perhaps even a special focus here in Europe.
Also, talking from a European perspective, I'd like to touch on another topic, which is serenity. So, we all were happily moving to the global hyperscalers, of course, to benefit from cost and productivity efficiencies, etc. On the other hand, of course, we need to keep sensitive data and our capabilities under national control.
So, what's your view on this problem? Bertold, let's speak frankly. Some software as a service has become a commodity, and vendors begin to discontinue the support on-prem, or they give you on-prem, but with features very far from what they offer in the cloud.
So, this is a problem for the companies. I'll make a practical example.
In 2020, Leonardo decided to use a specific software as a service platform for a business need with not a high level of confidentiality of data, so it's impossible to go in the cloud. We asked this vendor that we selected, by the way, used by 40-50% of Fortune 500 companies, that we want to encrypt our data.
They said, yes, of course, we can. We have the capability to generate a key in our HSM we want to give you.
No, we don't support this. We encrypt with other keys.
So, yes, it was six years ago, we signed the contract, but when we go live, we must have this feature on, at least as a private preview, beta preview, just for us. And they did, otherwise we don't go in production, so we give our key generator with our own HSM.
And so, our role as Leonardo, we try to influence vendors in order they can implement security features that they can offer to other clients. And now, that was 2020, we are moving to other concepts, to managing directly HSM on-prem, we did already, but even the cloud, and other concepts like all your own key concepts.
So, it is important because US cloud in Europe became part of critical infrastructure. So, we have to take as much as possible precautions on this. Thank you for these insights. Another different topic, operational technology security.
So, SCADA systems, industrial control environments, long life cycle assets is a growing concern across sectors, especially in defense and aerospace. So, how do you deal with that challenge? This is a big challenge, like AI, because the IoT world, everyone knows, was born with the technology that they thought that it was secure because it was completely segregated.
Now, it's not like this. And at that time, when it was born, IT told, no, but it's not our stuff. It's not our stuff. In all the companies, business, manufacturing owner, director of plant, yes, it's a machine, it's ours.
So, now, it started a process of onboarding of this operation area to the digital world. And that's why it takes a lot of time. It's not easy to go there in a machine that costs millions of euros, that has specific certification, and begin to put sensors that is able to capture, sniff the traffic, make a baseline of the machine, alert the SOC.
So, and sometimes there are facility constraints, problem on power supply, there is no Ethernet because it was a segregated area. So, there are other stakeholders to be involved in this.
So, it's just a matter of time to take back this environment in digital world, managed by digital security teams or by digital solutions, digital infrastructure team that traditionally are in IT world. So, I think at the beginning, we mentioned that the world is under fire and we need more innovation. I think there is also a broad agreement in Europe that we touched on that already, that we need more serenity and that we have to work together much more closely with the Italian community, the German, Spanish, France, and so on, right?
So, across Europe, of course. So, and we have somehow also lost confidence in technologies coming from other places.
So, will this, in your opinion, whole development lead to more innovation coming out of Europe and what needs to happen that this takes place? This is difficult. It's like why we don't have a European army. I don't know. I don't have the answer to this question. I see that many countries make big steps and investment in cyber security.
France, with a company acquired, interesting company, they invest a lot on startup and that's good. Italy is making a very good job with the agency of cyber security. Leonardo acquired two very cool, interesting vendors in access management to implement Zero Trust in attribute-based access control. And there are other countries that has interesting technology. Italy has interesting startups.
Sometimes, some of them are bought by US. And Europe has the capability to cover, we can say, 90% at least of technology stack that is needed to protect the company. But we are dispersed. I don't know the solution. Maybe a consortium owned by different states. I don't know. But we have to put together technology and begin to use more common technologies. I totally agree. I think we have to work closer together and be more self-confident. And give these startups also the possibilities to sell their products in scale in Europe. So we have to buy our own products. Yes. Thank you so far.
Thank you so far. And as usual, before we close, I'd like to fire some questions to you. Please be fast in your answers, but very brief.
So, first question I think is very easy for you. Zero Trust, real architecture or marketing buzzword?
No, it's real architecture and long journey. Compliance frameworks, keeping you safe or keeping you busy? This is tricky. If we use regulations to implement innovative technologies to make the real security, not the paper security, what I call the paper security, I think it's a big chance to enhance the level of maturity of the organization. AI in your sock. Trusted teammate or trusted shiny distraction? Automation using AI in a modern security operation center has to be taken seriously into consideration. So it will evolve and will be used more and more. Greatest cyber threat to Europe.
Is it Russia, China or something else? I think this is the two, also Korea, biggest country that has offensive capability and most probably they don't use ethical barriers. Five years from now, more regulation or less? I want less. We don't need other regulations. We don't need update of regulation issued two or three years ago. Consolidation, I think, is difficult because there are regulations that are different markets.
Banking, telco, defense, national laws. So we don't need to use new laws. Sensitive workloads, on-prem or full cloud?
On-prem, at least for our business. If a company sells biscuits, I think 100% full cloud. If you could dream, what type of innovation would you want to use? It's not a real innovation. But I would like to have a platform to make red teaming on chatbot, on agent, before the developers put in production an application that uses AI to be sure that it's not possible prompt injection or the attack on an LLM. Thank you for these spontaneous answers. Thank you for being with us for this little talk. I enjoyed it very much. Thank you very much for coming.
Everyone else, thank you for watching this episode of the CISO Perspectives. To share with you how leading CISOs think, decide and lead. You can watch these episodes on our website and also all other episodes, the ones we already produced and the others which are still to come. We'll be back soon, so stay safe. Thank you.
Thank you, Berthold. Thank you.