{"id":31705,"date":"2019-07-10T11:10:29","date_gmt":"2019-07-10T10:10:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=31705"},"modified":"2019-07-10T11:10:52","modified_gmt":"2019-07-10T10:10:52","slug":"we-go-phish-with-andy-harris-cto-osirium","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/07\/10\/we-go-phish-with-andy-harris-cto-osirium\/","title":{"rendered":"We &#8216;Go Phish&#8217; with Andy Harris, CTO, Osirium"},"content":{"rendered":"<p><strong>We \u2018Go Phish\u2019 with\u00a0<\/strong><strong>Andy Harris, CTO, Osirium<\/strong><strong>,<\/strong>\u00a0<strong>who tells us about life inside and outside the office.<\/strong><\/p>\n<p><strong>What would you describe as your most memorable achievement in the cybersecurity industry?<\/strong><\/p>\n<p>The industry will remember the invention of the MIMESweeper series of products \u2013 MAILSweeper, WEBSweeper etc.\u00a0Personally, there were more challenging inventions and solutions, some of the principles of the Osirium PxM platform are particularly elegant.<\/p>\n<p><strong>What first made you think of a career in cybersecurity?<\/strong><\/p>\n<p>It was 1987 \u2013 the experience of a war dialler looking for modems at the CEGB. \u00a0War diallers used to call numbers in sequence to see if they were auto-answered.<\/p>\n<p>If they were answered, the software would check for open sessions and if no session was found they would send an &lt;enter&gt; to see if the login prompt was recognised and from there test well known passwords.<\/p>\n<p>At the time, I worked in a R&amp;D department that developed power station software.\u00a0The consequences of a breach were clearly unthinkable.<\/p>\n<p><strong>What style of management philosophy do you employ with your current position?<\/strong><\/p>\n<p>We have a very good team of developers.\u00a0It often transpires that more than one person holds what they believe to be the correct solution.\u00a0I see these moments as vital, since one is making a grey decision where there are multiple routes forward.<\/p>\n<p>In these instances, it is the people with the ideas and views that are in the best position to choose the best route.\u00a0I\u2019m in a privileged position to be around these arguments. My contribution is to ensure that people are arguing about the ideas and not the personalities. I sometime think of it as herding lions \u2013 particularly with good people.<\/p>\n<p>Management philosophy changes with conditions and situations. I hold a belief that teams need to change their practices as the number of customers increases.<\/p>\n<p>For example, your development team has a lot of freedom before the first customer but once the first customer starts using a product, the team has a responsibility. This changes again with the second customer because they will be different to the first.<\/p>\n<p>Once a product has five customers, common issues start to emerge.\u00a0At 10 customers one of the developers will gravitate towards support. At 20, a dedicated support person is needed and at 50 a small team.<\/p>\n<p>Ideas are very easy, implementations are difficult.\u00a0I wince inside when I\u2019m introduced to an \u2018ideas person\u2019. I\u2019d prefer to be meeting the doing person.<\/p>\n<p>There\u2019s also friction to adding features as\u00a0the customer numbers grow.\u00a0A good team will try to see into the future in order to deliver an architecture that can adapt.<\/p>\n<p>There will always be features that fight each other and features that you\u2019d like to lose but the customer base won\u2019t allow it.<\/p>\n<p>Most of my experience is in the 0 to 1,000 customer range for significant security software.\u00a0The MIMESweeper range exceeded 20,000 customers before I moved on.\u00a0Things will be different for those developing consumer apps.<\/p>\n<p><strong>What do you think is the current hot cybersecurity talking point?<\/strong><\/p>\n<p>My biggest concern is the view that things are a case of \u2018when\u2019 and not \u2018if\u2019.<\/p>\n<p>It represents a state of despair amongst the security professionals in the customer base.<\/p>\n<p>IT is growing in complexity and the Internet provides too many public interfaces. This trend is increasing with an ever-growing shortage of security professionals.\u00a0Thirty years ago, there was a deep respect for credentials \u2013 not that we had that many to worry about.<\/p>\n<p>Today the human cognitive load of too many credentials is driving breaches, even in the DevOps community. Witness the recent ransoms for accounts on GitHub, GitLab and BitBucket.<\/p>\n<p><strong>How do you deal with stress and unwind outside the office?<\/strong><\/p>\n<p>Make stuff, code stuff, laser cutting, CNC and 3D printing. There is always something to learn.<\/p>\n<p><strong>What do you currently identify as the major areas of investment in the cybersecurity industry?<\/strong><\/p>\n<p>It seems that people have bought into the idea that monitoring is a priority.\u00a0It is easier to make a monitoring product than a prevention product. Forewarned is forearmed is a useful philosophy, but I believe this comes after defence in depth.<\/p>\n<p><strong>Are there any differences in the way cybersecurity challenges need to be tackled in the different regions? (Middle East, Africa, Europe, Americas.)<\/strong><\/p>\n<p>The main difference is the degree of trust in staff, which in turn affects the degree in which organisations are worried about insider attacks. There is also a difference where organisations have outsourced much of their IT.\u00a0In these cases, the security posture is dictated by the outsourcers.\u00a0This can be good, since experience counts, or bad in that any change is a significant cost \u2013 more than the cost of the solution.<\/p>\n<p><strong>What changes to your job role have you seen in the last year and how do you see these developing in the next 12 months?<\/strong><\/p>\n<p>Recruitment and remote working are closely tied.\u00a0In order to get the best people, we need to offer remote working.\u00a0But this means we need the network bandwidth and tools like Zoom and Owl to get as close as possible to the nuances of being part of a face to face meeting.\u00a0We pay more attention to the onboarding process.\u00a0Working on Slack is good and getting better.<\/p>\n<p><strong>What advice would you offer somebody aspiring to obtain C-level position in the security industry?<\/strong><\/p>\n<p>The quickest way is to start your own company. It could cost you a lot if you fail, but that experience will teach you about how managers feel about sales\/marketing and all the non-tech sides of the business.<\/p>\n<p>A safer route is to start at a large company and switch to a senior position in a smaller company and be prepared for the culture shock.\u00a0Never engage in office politics \u2013 learn how to spot it happening and how to put the brakes on.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We \u2018Go Phish\u2019 with\u00a0Andy Harris, CTO, Osirium,\u00a0who tells us about life inside and outside the office. What would you describe as your most memorable achievement in the cybersecurity industry? The industry will remember the invention of the MIMESweeper series of products \u2013 MAILSweeper, WEBSweeper etc.\u00a0Personally, there were more challenging inventions and solutions, some of the [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":31709,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6652,14],"tags":[12802,7242,564,12803,12804,12805],"class_list":["post-31705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-get-to-know","category-more-news","tag-andy-harris","tag-cto","tag-cybersecurity","tag-mailsweeper","tag-osirium","tag-websweeper"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/31705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=31705"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/31705\/revisions"}],"predecessor-version":[{"id":31707,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/31705\/revisions\/31707"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/31709"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=31705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=31705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=31705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}