Martin Hinton (00:01) Hi, welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor of Cyber Insurance News, and your host today, Martin Hinton. And joining us today to discuss micro seg segmentation, that's micro segmentation, is Piotrat Kopashewitz, who is with Elisity. He's the chief technical officer or out of Poland with Elisity. Piotrat, thanks for joining us today. How's your day been so far? Are you dealing with a heat wave? Piotr Kupisiewicz (00:24) Yeah. I am. Thank you for having me, Martin. Martin Hinton (00:32) My pleasure, my pleasure. So let's start with the big the the word I just used and I stumbled over it. Micro segmentation. That's the business that you're in with Elisity. Tell me what that means for the audience. I I suspect a lot of our audience will know, but we like to start with the baseline of information. So micro segmentation. Explain that to me. Piotr Kupisiewicz (00:53) I mean I I I I think majority of the people would be familiar with the concepts like a firewall or a VPN. And when you think about, for instance, a firewall, this is a kind of segmentation. It segments what we are calling a perimeter or a boundary between our infrastructure, our corporate infrastructure, and the rest of the world. When we are talking about the VPN, we are talking mainly about the remote access. But what we are seeing nowadays is that majority of the attacks are actually happening from within the infrastructure. These are compromised laptops, compromised servers, valid credentials, which are basically compromising our network from within one laptop and lateral movement spread of a malware or ransomware. the the infrastructure within the network itself. Martin Hinton (01:52) So you you in the in the past securing the whole house was required and now within the house you need to secure each room individually so a malicious actor can't move from room to room. Is that is is that sort of a simplified way to think about it? Piotr Kupisiewicz (02:08) Hundred percent. Yes, it's a great analogy. Martin Hinton (02:11) So what's really, really interesting and we can't get away from this is Poland is very close to Russia and a lot of the places you work with are in critical infrastructure of some kind. So I wonder whether you might take us into how this impacts the the the work you're doing these days. Piotr Kupisiewicz (02:31) You you mean the the situation here in Poland, right? In in the context of Martin Hinton (02:34) Yes, correct, correct, yes. Piotr Kupisiewicz (02:37) So I think you know from from where I see it from Poland's perspective, you know, the the cyber warfare is not theoretical anymore. It's very much our day-to-day life. we, you know, what we are hearing especially covered in the in the Western media, I mean there are this hypothetical situation of the cyber or hybrid warfare, and what we are seeing is basically this our our our day-to-day life. what the the the way it impacts you know our life and and the society here is you know there's obviously we we had as you mentioned already an attacks on the critical infrastructure the the hospitals were impacted the water facilities were impacted which obviously impacted the life of the regular citizens there is a huge campaign that done by the government as well as just some cyber activists in terms of just an education, you know, similarly to what's happening nowadays in the enterprise in the enterprise environments. it's basically education. Don't open random files, you know, use multi-factor authentication. Back to the basics. so you know, but move from the classical enterprise environment into just day-to-day. life of of people. So, you know, either my e even my grandma and she's eighty five, she has some understanding of, you know, what to open on or what not to open on her on her PC, which is actually you know, amazing to see. Martin Hinton (04:18) It is. And and do you put that down to education that's being driven by the geographical proximity of this threat and how dynamic it is. You know, because we we I did an interview recently and one of the things that the person talked about was water and critical infrastructure. You forget how vital that is. And you could talk about turning the lights off and that sort of thing, but particularly given the heat wave you're going through, access to clean water is vital. These are it's evidence of, you know, attacking Piotr Kupisiewicz (04:40) It's equally fun too. Martin Hinton (04:47) I guess civilian infrastructure, is that the right way to put it? Is that is that one of the reasons it's become something that, you know, allows e everyone from say your grandmother on down age wise to to recognize this concern and then act appropriately and t educate themselves? Piotr Kupisiewicz (05:06) I I think so. I mean, don't get me wrong. I think there's still plenty of work that we that we need to do. I think, you know, there's more and more attention put into what we are classically calling what what's what's typically called the critical infrastructure. We are when we are talking about water facilities, electricity, electric plants, etcetera. But what what I think we are still learning is Like for instance the telecommunication or just the internet providers, some of the local internet providers. Very often here in Poland you will have, you know, frankly speaking, this garage internet service provider, just you know, just a bunch of individuals who are sharing the the the internet with with their neighbors, right? And should you consider it critical infrastructure? Can we imagine nowadays life without an internet and the connectivity, right? so what I think is still I mean there's still obviously plenty to to be done on many fronts, but I think just the realization that critical infrastructure is broader than what typically we used to call critical infrastructure and I'm talking here very much about the to telecommunication and just the internet, right? We cannot live without internet. It's very difficult to, you know, to even travel without you know the the the proper you know connectivity. So yeah there's still plenty plenty of work in front of us. Martin Hinton (06:31) No, mean I I I think you're right. I think it underscores the sort of fragility of our existence digitally, you know, even if you're traveling, say, in the States and you hit an area with poor cell phone coverage or we had a Verizon technical outage recently. And, you know, the joke I made in the wake of that and I've made to this day is if you work at a company and you don't think the internet and technology matters, have everyone put their phone in their desk and they can't use it for twenty four hours and see how things go. You know, it'll it's it's a it's an enormous problem. You know, one of the things that we hear in the States hear a lot about is Russia, but you're in Poland. Is there anything that doesn't get reported as far as you can see out in the sort of meter in media in our our part of the world or west of you, I guess would t to to put it, in geographical terms, that that is important for people to know? Piotr Kupisiewicz (07:17) No. I I think I mean y you know, when when I'm in when I'm traveling to United States, one one thing that I realize is that this the the cyber warfare and for instance Polish hospitals or or water facilities or you know being being impacted by by the threat actors by Russia, it seems remote. And it seems like, hey, these are guys in Poland, you know, maybe they didn't protect their infrastructure well enough, right? And and I and I have this sense of that of you know of of the problem being very much remote because it is geographically it's very far away. There's an ocean in between. But you know the the the IP packets travel through the ocean every day at high volume. and and I think you know the the the this one realization that I do have when when I'm in United States or or in other countries is that you know the the and I know for a fact that actually our infrastructure is for most you know it it's really well protected. I know some of the individuals that are working there, so I know that this is not a you know an amateur team that is that is protecting the the the the infrastructure. so what I'm trying to say is that I do think that you know that that this realization that this problem can also impact countries like United States, you know, that the the issues that we are having with you know with with some of the vulnerabilities or just you know the the the operational elements like a default passwords still being used, these problems might be universal, right? And I'm not trying to threat here or anything like that. This is this is not my point. I'm just trying to to I highlight the fact that you know that that in terms of the cyber warfare, the distance does not really matter. and some of the problems that we are observing here might be very much relevant. you know, to to hopefully not, but you know that that might happen also somewhere else on the planet. Martin Hinton (09:25) No, I mean I think you make two two very good points. That the the speed of internet traffic, if you will, which is what can carry the threat or is speed of light, I suppose. And it doesn't care about the lines on a map, right? It it will travel wherever it's permitted to, and that is something to keep in mind. You y y y you th oceans don't protect you from this hybrid warfare, this cyber warfare. The other point you make is that We make the same mistakes as human beings everywhere, right? You you don't change the default password on some new router, you don't patch properly. The very, very basic things that, you know, you would do to make yourself secure are not happening in the digital space. And the analogies I always use are in the physical world. If you owned a factory with a fence around it and there was a gate with a lock on it, and you noticed that the lock was rusty and the chain looked like it might be, you know, easy to break with your bare hands, you would have that fixed. Piotr Kupisiewicz (10:10) Okay. Martin Hinton (10:23) You would maybe if you were living in a place where the weather was bad or you know, rust came on more quickly because you were near, say, the sea, you would guard against that sort of thing. And we do this in the physical world. We have twenty-four hour monitoring in the ph physical world with security cameras and overnight watchmen and that sort of thing. Those ideas in the digital world are slow to be adopted. And it's not just geographic, it's from the top of a Piotr Kupisiewicz (10:31) Yeah, this team. Martin Hinton (10:50) an economy to the bottom, right? Huge companies are making these mistakes as well as little small businesses. And one of the examples that we discussed when we were preparing for this, and you've touched on it already, is the water treatment facility attack. And it's a striking example because it wasn't a sophisticated attack and it did involve a default password. And I wonder whether you could take me into that example where you think about something that would be obvious to protect with every means necessary. Piotr Kupisiewicz (11:11) Yeah. Martin Hinton (11:19) And I suspect there were probably guards and you have to pass an ID check to get into the building. But that security doesn't didn't reflect in the digital space. Do I have that right? T t take me through that scenario and how it all unfolded and how they were able to gain access. Piotr Kupisiewicz (11:30) It was no more. Yeah, I mean the the the water treatment attack example that that you are mentioning, I mean it's almost difficult to call it an attack, right? Because it was just an exploitation of default passwords or different cr differ default credentials set on the on the firewall that that allowed you know the attackers to to to to go through. yeah, I mean Yeah, it's not even a vulnerability, right? And and to your I I'm trying to find an analogy to to the guards and the physical world, but what I know for the fact and and and unfortunately this is the case, you know, in d this is the case in in in some of the in in some of the systems that we do have the You know, the IT is the shared resource. you will have an individual who is, for instance, responsible for multiple facilities, you know, multiple schools, multiple hospitals. Very often it's one or two individuals who are basically carrying everything related to IT, from connecting the printer to configuring the firewall and you know, managing Active Directory. I know because you know, more than 20 years ago I was one of this, you know, IT specialists, basically a men of multiple talents, right? But and and if you are having so broad you know plethora of I mean if there are so many different tasks that you should do, right? Just forgetting to reset or set the the the password on the on the firewall might happen, right? And it's just the you know again the the the lack of you know enough resources allocated it's it's basically an operational problem not even a technology problem. But I am optimistic actually in this regards. I think this is a fantastic place where actually artificial intelligence can help us, can, you know, do such monitoring for us, you know, and and and find places with default passwords, for instance, you know, before the the attackers do. Martin Hinton (13:37) So th I mean you're talking th routine maintenance, right? One of the one of the things that I'm a huge fan of is the reminder that much of what we do as biological creatures is maintenance, right? We have to sleep every day, eat every day, drink water every day, we have to take care of our personal hygiene every day, brush our teeth. All these things are, you know, what become burdensome. You need to go shopping for groceries, you need to take your car to get the oil changed, all these things. we call chores in America, you know, they're the the the taily daily mundane tasks. But they're the things that make all the things we really want to do go smoothly. And there's not that the problem, as you note, is that there's not a lot of sexy in in changing default passwords and making sure things are patched. You you you you said when we spoke initially that that po and you touched on this sort of the perception of Poland, the the phrase cyber militia and that culture in Poland. And I wonder whether you might tell me a little more about that element of of of the situation there. Piotr Kupisiewicz (14:38) Yeah, I mean so we we we have this concept in Poland which is called cyber religion. it's basically a a a government founded you know project. it's actually I mean I would be careful calling it cyber militia because it's not about you know random people you know hacking into I don't know Russian you know systems. It's actually very well organized. structured, you know, system with processes, etcetera, where just regular citizens who are having an experience and talent in cybersecurity can actually, you know, apply this talent, apply the their skills in a in a structured way, in a way that are benef you know, that that that are maybe a little bit more organized than just, you know, bunch of people trying to, you know, to hack a re remote state. And yeah, I I think it's a great way to, you know, for the regular citizens just to kind of give back and and contribute. because as I mentioned, it's not hypothetical here. we are continuously under an attack. Poland is is one of the i is a NATO member which is under attack continuously. And actually the amount of attacks that we are having on our infrastructure is the largest in in NATO. So yeah, the the Cyber Legion and and you know, the the kind of organized way to contribute by by the government. I think it's yeah, it's it's a way to contribute without entering the full, you know, military service, the the day-to-day service. Martin Hinton (16:14) Well, I mean it you know, in in this new new world where the the future has its pl own plans, what you describe there sounds like civil service, right? Some sort of volunteer service or mandatory service that you hear about and all kinds of things. We often associate that with, you know, putting on a uniform and and serving a year or two in your country's military, South Korea for example. And I I I wonder whether or not you see that as something that could be adopted and absorbed as an idea and a practice. Piotr Kupisiewicz (16:24) Yeah. Martin Hinton (16:44) in other countries because as we've discussed and as you know better than I this is not something that's a unique threat to Poland. We know that for example, Great Britain, the United Kingdom has suffered, for example, attacks on their national health system as well. and they have I you know, in my my estimation, the government there is pretty forward thinking with the Cyber Resilience Act and that sort of thing. And I wonder whether or not there is you know, again it's it's it's weird to say And compare things to warfare when we don't see what people associate with warfare, bullets and bombs and tanks and planes and all that sort of thing. But there is a real economic cost to this, which is again one of the reasons you go to war is to create economic costs to your enemy. There is that is happening. do you think that, you know, across Europe, this idea of taking people who are, you know, tech savvy or motivated or willing to learn or capable of learning and and like you said, organizing them into Piotr Kupisiewicz (17:22) Yeah, it's you know. Yeah. Martin Hinton (17:40) put it in American terms, a well regulated environment and organize their energy and their efforts is is a way to to counter this and to to push back against it. Piotr Kupisiewicz (17:51) I mean a hundred percent and I and I actually think it's I I think it's a phenomenal way for regular people to contribute and I think not only in I don't think it only applies to Europe, I think you know there's a broader applicability to it because it's not only about the I mean it's it's always the and I actually think you know, the countries that are not under you know the the active cyber warfare threat. I mean I think every country is, but you know, there are different dimensions to it. I think it's always better to prepare, you know, before the war than during the war. You know, and I and I do think there's a huge value of just understanding the procedures because you know the the the it's like in the regular, you know, analog military You know, a lot of trainings are about knowing the procedures, knowing the go-to points, knowing what to do, you know, in the cyber context, what if internet goes down? Like, you know, how should we, you know, organize the the the replacements? How should we, you know, help? so I I do think that it's even you know, ideas like this one are even more important for the for the countries that are not in the the active, you know, situations like like what we are having here in Poland. And frankly speaking, it's it's you know for us people in the in the in the cyber world, right? The the you know the nerds is is just a way to give back, right? you know to to you know you you feel that you are you know doing something good for the for the for the community, you know Martin Hinton (19:13) Yeah. Yeah, well you make it you you you touched on a couple of things, it sort of brings me to the next point I wanted to make is we discussed AI and the case you made, if I had it if I have it correctly, is it hasn't really invented a new attack technique sort of dynamic just yet, as much as it's lowered the entry point for someone who wants to be an attacker. And I wonder whether you might t tell me about how AI might fit into this or it how it impacts things as you see them now and what you anticipate going forward. Piotr Kupisiewicz (20:03) Yeah, I I mean it is happening extremely fast, right? Like you know, a few few years ago the attackers, you know, very often they were sophisticated developers, sophisticated coders who who you knew who knew exactly, you know, the techniques, they knew what stack overflow is or the buffer overflow and et cetera, et cetera. I don't think this is needed anymore, right? It you know that in the past there was this this I think we were calling people who didn't really know how to code, but who were using already existing exploits as script kiddies. It was almost like a negative phrase. And it feels like this AI allows everyone kind of to be a script kiddy nowadays, right? Like you don't need to understand, you know, really deeply the system that that that you are looking for the vulnerability in. You don't need to understand the programming language. And once you are in you know, w once you have for instance an access to the database that you didn't know before, it it's still it you know, i it was almost like security by obscurity. You really needed to understand what you are looking at, you know, what data you are looking at to even you know, extract some of the sensitive information. And nowadays you just have this huge force multiplier, you know, in for in in in in in in embodded in the in in the AI, right? Which which can help you in so many different phases from reconnaissance, you know, to install, you know, to through exploit, through ex through exploitation, etc. Right. So yeah, 100% you know, on the on the negative side of the of the things, you know, I I I unfortunately think an AI is a huge force multiplier, but fortunately it works also in a similar symmetric way for us, the defenders, right? Martin Hinton (21:52) W within the AI concern, one of the things that we chatted about was AI identity and identity concerns and agentic AI tools running on an employee's laptop. It's something we've talked a lot about and I just did a big podcast about cyber insurance and agentic AI. Like if the agent makes a mistake, whose fault is it? So I'll tell you my experience with agentic AI for law. I was due to fly to Ireland and my flight was cancelled and I was at the airport already and They said, we're gonna rebook you, and I left. And I got an email saying, hey, we've rebooked you on the same flight. It's 24 hours later. Boom, done. So I'm relaxed the next day. My flight's not till the evening. And then around three o'clock, I thought, you know what? I'll go on the airline app and download my boarding pass and you know, make sure everything's okay. I do that and I see that I'm booked on a much earlier flight. A flight that's so much earlier, I'm not gonna make it to the airport. So I call the airline as I rush out the door and have a panic, and lo and behold, get someone on the phone, and they say, well, you know, AI sends the emails. That's not our fault. And the obvious response was, Well, what do you mean? Whose fault is it? And what can you put me on that flight anyway? So there's a there's a very small and low cost imp impact of AI agents. And I wonder whether you might tell me a little bit about how you see that scaling to bigger things and real issues. Piotr Kupisiewicz (23:21) Yeah, I mean, I hope you made your flight at the end of the day. Martin Hinton (23:26) I did, I did, I did. Piotr Kupisiewicz (23:29) I mean I I I think the we actually had this discussion here at Elisity since we are using we are we are using AI to help us with with the with some of the presentations, right? Like just creating PowerPoints, etc. and I remember James, our CEO, said, look guys, I know we are using AI to help us build the slides, but you still own the content. You still own the every single number that it's under. It's I don't want to hear an excuse you know saying that this was AI generated, right? I think this is the right approach. And yeah, and I think you know when when we are using AI, which and you know, for to do whatever on our behalf, yeah, we sh we still should be responsible for this. and but there is also another kind of side of I mean there is an AI which might act on our behalf in in in kind of not expected way or you know sometimes even malicious way. And I think also because we are talking about cybersecurity here it is important to limit what this agent can do, what the identity that AI is using can actually do, right? This agent probably does not need to have access to you know, all my different, you know, personal files or or very much confidential companies data, right? it should only have access to, you know, the small small amount of data that that I needed to to perform the task. And frankly speaking, I think there's still huge amount of work that we the industry need to do you know to to build this identity systems that will allow us to you know to pin the agents to to do only what what we want them to do. But on the responsible responsibility side, you know, I hundred percent agree that you know, it's not an excuse. It shouldn't be an excuse, you know, that the AI did it. Martin Hinton (25:26) I mean I mean I I I I I I completely agree. I mean, I think that if you were a a builder or you were working on someone's house and you you used a tool and it broke something, you you wouldn't blame the tool, right? Like that that would be that would be no one would take you seriously. You you what do you mean the hammer broke the window? The hammer was in your hand. What what are you talking about? And I I know that's an overly simplified example, but but it is it is one where we meter some of what we expect out of Piotr Kupisiewicz (25:52) Right. Even. Martin Hinton (26:03) our ability to turn work over to something and then be able to point it a finger at it and say, well it's it's it's the thing that's responsible. You you touched on your company's use of AI and one of the things we know is that when we prohibit things, particularly in a competitive sort of free market business competitive business economy or environment, you create problems. And the examples I might use and the phrases shadow AI. Piotr Kupisiewicz (26:12) Increase okay. Yeah, so Martin Hinton (26:27) And the idea that if an employee is told they're not allowed to use AI for this, but they're stressed or they're worried about finishing something, they might go outside of their company or use a personal device to put something in that they're having trouble understanding or completing or finishing or whatever it might be. And that creates a a risk, a liability. I wonder whether you might give me your thoughts about how you govern that situation. You obviously you your CEO created a situation where listen you can use these tools, but you're responsible for the output. The outcome is still something you have to own, I think was a great word for it. But what what advice would you have for a CISO out there who's looking for, you know, there is a real complex trade-off here between taking advantage of these tools. We know that there's a lot of pressure, particularly on publicly traded companies, to seem like they're all, you know, adopting the newest thing for efficiency and maximizing profit and that sort of thing. Piotr Kupisiewicz (27:15) Yeah, public and trade companies would seem like questions. Martin Hinton (27:23) What about the ungoverned tool threat and the A AI shadow threat? The shadow pardon me, the shadow AI threat. What what do you see in that space? Piotr Kupisiewicz (27:32) I mean first of all I want to say that you you I think the life of of the of the CISO has been very difficult for a very long time. And I think you know in the last twenty four hour twenty-four months I think it became even more difficult. and and we all see the you know the burnouts among CISOs and and I completely understand why this is happening. But putting this this aside for a moment, I mean It is a difficult one. I think if there is a real I mean if the job of the employee can be done quicker or just easier, if every day I'm working in an Excel environment and I'm just moving data and I can do it instead of in a couple of hours in just a couple of minutes using an AI tool, probably I will do it. for many reasons, just because it's easier being being one of Right. And and I think it's very difficult, if not impossible, you know, not to allow employees you know, from from doing that. I do believe though that you know there's just no no turning back. I think especially for the employees who are doing like an office work, you know, that the responsible deployment of an AI is is is almost a must. But I do believe there's a You know, there's a huge opportunity for for for training, right? I I do believe that you know people will understand the fact that you should not put there, you know, your critical intellectual property. Obviously, there's a there's place here for technology to to help with this, like a data leakage protection, DLP is solutions for AI. But I I do believe there is you know there is this part of of responsible. deployment of of an ai in the in the in the company and i don't think there's a way back this this is what i'm trying to say i think not allowing it basically means that we are allowing shadow ai people will will find like water will find a way you know will use private devices will start making photos of the of their screens etc etc and and so i i do believe that it's just better to to try to approach it, you know, head on, and and and just build the the process, including the training, you know, and and and help people. Martin Hinton (30:09) No. Well said, well said. We we we touched on critical infrastructure in respect to hospitals and water systems, but there's a lot of other critical infrastructure that exists. And I wonder whether or not you might tell me a little more about the the other elements of critical infrastructure, which I guess power grids. You did touch on telecom and in your reference to sort of the you know smaller internet providers. Tell me about that space and w you know, w what are you seeing in your part of the world in Poland with regard to those other elements of you know, I mean we I guess I should stop here because the phrase critical infrastructure in this realm rolls off people's tongues like they're saying, look at that flower. Right? The the the word critical seems to be lost infrastructure like what it what it actually means. And and I guess the the simplest thing and and I've tried to do this lately is that imagine those things don't exist, right? You can't you can't get fresh water. There's no electricity Piotr Kupisiewicz (31:00) Okay. Martin Hinton (31:07) And you can't call anyone about it, right? Like that's how bad it is. And then when you fall down and break your leg, there's no one to take care of it. Right? That is the these are critical things to our existence. What about that space beyond the hospital and water systems reality we've discussed? Piotr Kupisiewicz (31:24) Yeah, I mean I I I think you know we we we should think about the manufacturing as you know maybe not of everything but especially in the context of hospitals, the then the manufacturing, the manufacturers of drugs, right? Like, you know, starting from from from just the basic needs. you know, the people need their medicine and they might not survive without, you know, the they are basically dependent on manufacturers. producing drugs, then we need to think about the logistics, you know, the the the the stuff moving around. We are start, you know, starting from food, going through, you know, through fruit through drugs, etc. So I think manufacturing is is is one I mean, again, not maybe not of every good, but but there's a the the the big amount of manufacturers that are critical just for our day to day life. And I think there is this priority that you can assign to these different businesses based on how long can you survive without that without their products, right? So I think manufacturers, you know, logistics, the the telecom and energy we've already we've already mentioned, but also the the the financial institutions, right? Like how much cash do we have? right, not everyone has you know gold gold coins in the basement, right? so what if the financial systems basically stop functioning? How are we going to pay for stuff? Right? so I I I think what we are calling the critical infrastructure, you know, I I think you know it's much broader than what we typically used to call the the critical infrastructure. Martin Hinton (33:08) You know, you you you remind me of a an op ed piece that I wrote some time ago now and it raised the possibility or the question, at least in America, is the K through twelve, so five to eighteen year old education system critical infrastructure. You know, in in America at least, a lot of schooling takes place during the day, during the workday, and what it does is it also serves as education, as also as serves as part of me childcare. So People c take their kids to school, then they go to work, and then they come home and that's the day. And if school doesn't exist for that situation, it's very disruptive to the work day, right? 'Cause you don't have someone to watch your kids. We see it with snow days is a great example. So I think the analogy I use was a digital snow day. What what what do you do if they last for a week? 'Cause we know these outages and those sorts of things go on. Piotr Kupisiewicz (33:54) Mm-hmm. Martin Hinton (34:00) If you were in a situation to advise government and they were looking for, you know, the the first thing they should do next or the place that the the next big round of funding should be focused, what what area of that space do you would you encourage them to look at first? Piotr Kupisiewicz (34:01) You can look into the back. I think that something should be I mean sorry, maybe adding one thing to the to the previous question. When when war in Ukraine started, here in Poland, the first thing that happened, we had this ten hour skews to the I'm not sure how you like what are the facilities in in in United States, but basically the places where you can buy gold coins. So people were just okay, you know, we don't know how far it will go. And literally, you know, every place where you could buy gold coins, because this is the best, you know. met of of payments, you can it's portable, etc. and this makes you realize like, you know, the the financial institutions are are among the one, the the critical ones for sure. To your point about the advice I would give to the to the government, I mean I obviously I spend majority of my life in the in securing securing the infrastructure. So I think And frankly speaking, it's a similar advice I would I am giving to enterprises when when when being asked about how to approach cybersecurity. we always should start with the most critical process in our I think in in in our in our system. So if we are i i if there's a if we are looking at the country from a government perspective, like you know, again, which parts of the of the economy might be the most critical, and then going backwards towards you know what should we how should we make sure that this actually work and if we are talking about just the networking infrastructure it's going back to the basics like what assets do we have in our infrastructure which assets are the most critical for delivering the business outcome right maintaining the hospital maintaining the the water supply and etc and then you know again going going back to the segmentation, right? Which devices can talk to to the to the critical controllers in in our infrastructure and do they all need to communicate with it limiting the the the blast radius so just going back to the you know to the basics from from from from from a top process you know this is this is how I approach things. Martin Hinton (36:33) We we we've touched on this and we touched on it with regard to civilians being utilized in defense. You you just used the phrase going back to the basics and we were talking about the people factor. You know, is it is it i or is that fair to say maybe you deserve a little bit of the burden for why you got got broken into? Piotr Kupisiewicz (36:38) Yeah, you can Yeah, you made a great point. Yeah, maybe you could. Is it okay? Martin Hinton (37:02) There is a basic concern here with human error in in the absence of sophisticated attacks. I think there's a perception that a lot of these attacks involve complex computer activity and in fact it's not that way at all. And I wonder whether or not in that context there's, you know, any advice you might have about how what gets classified and we've touched on this is sort of the boring stuff, is still the hardest to get organisations to actually do. Piotr Kupisiewicz (37:14) Yeah, yeah. No. Martin Hinton (37:31) You know, like everyone wants to there's a there's a at least in America, right? There that no one does something by taking things away. Right? You you do more, you don't do less to fix a problem. And that works for business because that means more means you're maybe buying a new service or buying a new piece of technology or buying and adding employees to a staff. So there's there's economic b benefit there broadly. Piotr Kupisiewicz (37:40) I think. Yeah. Martin Hinton (37:59) That unfortunately is only one way to fix things. Sometimes doing less is effective, but it's not in our nature as human beings generally to do that sort of thing. So I wonder in that context with human nature mind and the the vast majority of cyber breaches typically come down to human error or some act the human could have changed without any real technical knowledge. What about that, you know, the human factor, the the basics? And then there's a real burnout associated with this where you get Piotr Kupisiewicz (38:01) Okay. So you can have Martin Hinton (38:29) you know, the teaching training and these seminars and every three months you gotta change your password. There's like an absence of maybe s how important it is that's in the messaging. And I I guess I'm curious whether you might tell me a little more about that from your perspective, Poland. Piotr Kupisiewicz (38:33) If we're gonna change it, or we can use the network. So starting with the with the human nature and and and the security, I think actually when when when you were asking the question I was thinking about the Like what when you want to try and stay healthy, right? it's very difficult to I mean it's impossible to become healthy, you know, in one afternoon buying product, you know, supplement or something like this, right? Usually staying healthy as a human being means it's a routine, right? You need to sleep well, you need to eat well, you need to exercise, right? And it's kind of boring. You don't see an effect after a week or two, you see an effect in the in the long run and I think there is an analog I mean I see a similarity here when when when applying this to to to to cybersecurity you know foundations. It's about you know knowing what's on your network every day. It's about knowing who logged in where every day, continuously. Right? the vulnerability management, you know just the boring yeah the boring work but you know it's similarly it's a to to to to just staying healthy, right? It it is sometimes boring, you know, to run, you know, every day for forty-five minutes, right? But but it is a necessity. And I I I I see a lot of similarities here. and and you know if you stop running or if you stop exercising for a couple of weeks, your, you know, your health will degrade. And I think, you know, it's very much similar with with cybersecurity. If you are not going to continuously, you know, monitor your systems, know what's on your network, what No, you know, if if you're not going to check if your passwords are set, you know, your your security posture will will degrade. And yeah, it's just a continuous routine thing. but I think this is the the only way. I think here though we do have an AI that can help us. I don't think AI can help us, you know, with running or eating well. you know, I think that this is something we still need to do for ourselves. And in in in context of on of a burnout, I think this this it is related, right? Because you know, I I I think there's also an analogy. I I remember when almost 20 years ago I was kind of I I already mentioned it, I was responsible for an IT in a manufacturing company. when everything worked, you know, people were asking, like, what is this guy doing? right. And it felt kind of You didn't feel important, right? Because you know, when when infrastructure was up and running almost for the whole year long, you know, nobody was coming to you and saying, Piotr, thank you. You know, you're doing a great job. It was usually an opposite when things went bad, you know, then everyone suddenly realized who who who who who you were, right? And I think you know, the CISOs out there are having so difficult work because they need to prevent business disruption, they need to enable the business. Everyone is expecting from them that everything will be, you know, secure. and yeah, I I I I just think you know if you don't have a an active breach, people might not appreciate the security teams and and I and there's so much work that you are continuously doing that might not necessarily be rewarded. And I do believe you know, it might lead to to the burnout, you know, because it's not yeah, it's not a fantastic achievements you know, that you are bringing every day to the to the business. You know, it's very much hard to to measure. Martin Hinton (42:28) Yeah. I I I mean the the CISO situation is one that I find fascinating. I mean I you know, I'm a journalist, so my job is people and things and how people interact. And that dynamic on on the s sort of executive C suite level is is fascinating. I mean, do you think that I mean I think the average tenure of a CISO is roughly two and a half years in any given position, something like that, which is very, very brief in the context of that sort of level of Piotr Kupisiewicz (42:44) Yeah. Martin Hinton (42:58) you know, responsibility. Do you think the burnout is a function of how complex the problem is from a technical point of view, or do you think it's born more of the human reality? And we see this where boards are disconnected from the CISO's concerns and when they come to the CFO, it's always they need more money for something and they're viewed as a you know a cost center, not something that's protecting the business and creating stability and resilience in a as we know. threatening dynamic sort of cyber attacks sort of landscape, regardless of the space you're in as a company. W w what what is it? Is it just accumulation of all those things? Piotr Kupisiewicz (43:35) Okay. I I do think it is an accumulation of all those things and I do believe that the the human element and you know just I mean I I think the life of the CISOs and and the way they approach their spending, you know, coming to the board asking for for another, you know, hundreds of thousands of dollars for the firewalls, how do you quantify the risk? how do you explain it? How do you compete for the budget with with the revenue growing, revenue generating projects, right? because as you mentioned, right, this security might be considered a cost, right, a cost center. And Actually we at Elisity and and me as the CTO I I've spent plenty of times with CISO with CISOs who who were frankly speaking just asking me like hey Piotr, you know, we are three years into the project, how should I justify to my board the renewal? right? Like what are you guys bringing? And we've spent I've spent personally just last couple of years thinking about the metric. like how should we, Elisity, justify our existence? I do believe there is a huge value in what we are providing, but how do we quantify it? And I've come up with this thing that we are calling a zero trust score here at L City, where we are basically you know showing a number like you know from zero to one hundred in terms of how well your network is segmented, what's your blast radius, and we are also giving the benchmarks that we think that you know, in this vertical, this is you know. This is a reasonable benchmark. And then the cost of the most pessimistic because I think this is what helps the board understand the risk is once you quantify the worst case scenario. Like if this is your biggest blast radius or a zone in your network, you have 7,000 devices in it. 5,000 of these devices are, you know, critical OT devices. If there is a malware here and it propagates 100% to the whole zone, we think that this, I mean, this is going to impact this and this process of your business, and you might try to quantify it, right? So so then it's you know, it's much easier for the board to make a decision you know, in terms of like, is this worth an investment, yes or no. and so what I'm trying to say is that. You know, I feel it for CISOs, but I also do believe that we, the industry, the vendors in cybersecurity, I think we need to do much better job giving proper data and proper you know ammunition, you know, to to CISOs so they can defend you know what we believe is right, what we know is the the the the right decision, right? But how to show it to the people who are not you know, living and breathing cybersecurity every day. Martin Hinton (46:37) So that's a natural transition into the cyber insurance part of this where, you know, the the business that Elisity is in, despite our broad range of conversation to this point, is the micro segmentation. When you're dealing with companies, where does cyber insurance and the impact from a financial point of view that having it, the controls they can exhibit, whether it's micro segmentation or anything else, impact their policies and their renewals and what they're paying? Piotr Kupisiewicz (46:58) Even second. Martin Hinton (47:05) Tell me about the the cyber insurance element to this from your point of view. Piotr Kupisiewicz (47:09) Yeah, I mean so so obviously the segmentation allows our our customers to have lower premiums, you know, in terms of the the cyber insurance. I myself I I think you you you know there there's sometimes a challenge. I mean some some folks are challenging me saying, Hey, you know, some of I mean what what if the customer wants to use solutions like Alicity that they want to introduce micro segmentation only to reduce their their premiums, right? Is what do you think about it? And Frankie speaking, I think, you know, whatever is the reason for people to just increase their security posture. I think I mean I I I I think this is the you know the the I mean I I I look at this as a positive or you know the the underwriter might might look at this as a you know a risk reduction. The the CFO might call it a it's a business continuity investment. Like, you know, there are different people who are calling you know just the the risk reduction in a different way. but at the end of the day I look at this as a as a positive and and for sure the I mean because because objectively reducing the blast radius reduces your risk to, you know, to to to the business impact by by a threat actor. So I think it's a right way forward. Martin Hinton (48:34) Do you is micro segmentation something that is appropriate for say a mid-sized company? I mean, what where where does the the line draw? One of the phrases I've heard l recently is the cyber poverty line and and it was in the context of American small businesses, and that a lot of small businesses and even medium sized businesses, they they don't have a CISO. They don't have, you know, they're still coalescing the IT and cybersecurity roles into in the mind of say the board. Piotr Kupisiewicz (48:51) Even if I said complete. You can see the bullet. Martin Hinton (49:00) One task, one responsibility, when there's real differentiation between what an IT sort of environment means and what cybersecurity means, where does the sort of micro segmentation realistically fall for maybe a company that's making tougher decisions? Then there's also in that context, at least in the States, we've got companies that have a SEC compliance where mandatory reporting of cyber breaches has to occur. So there's a lot more at stake. So their budgets are maybe Piotr Kupisiewicz (49:03) Any company? The microsegmentation was never fitted in the market or maybe this is behaving. You could have Martin Hinton (49:30) millions and hundreds of even millions of dollars, even potentially at some very large financial institutions. and I guess I'm curious where this solution and the benefits come from it might might hit you know, resistance from a financial point of view that's that's hard to overcome. Piotr Kupisiewicz (49:30) Yeah, maybe. Thank you. I think the the huge advantage of segmentation overall, and this includes micro-segmentation, is that from a technology perspective, it's kinda you can think about it as a passive kind of, you know, you're just building fences or walls in your room to the analogy you gave at the bear at the very beginning. And once you build it, it's kind of there. It's there to protect you. So what I'm trying to say is that, you know, there are lot of cyber solutions that are that do require day-to-day maintenance, that do generate Plenty of locks. And you know, there there are plenty of solutions out there who are just generating more and more, you know, locks that you need to aggregate, you need to monitor. And you know, and I do realize that a lot of these mid market companies they they don't they cannot even afford security operations center. Right. So I do believe that passive solutions like microsegmentations are like micro-segmentation actually a really great place to start, right? To just limit your infrastructure separate your critical resources servers with the intellectual property, you know, from the rest, the IT from OT, manufacturing lines within the OT. I think it is a great start. And actually I think about it the micro-segmentation in opposite way. I actually do believe that you know that the that it's very much appropriate it is very much appropriate solution for the for the mid market and the barrier to entry, the time to value, the time to implement micro segmentation has significantly decreased in in the in the in the last couple of years, thanks to solutions like LCT, but but but there are also other solutions. So I I do I I do encourage you know the mid-market solutions, the you know to sorry companies to to really really look into you know into limiting that brass radius. Martin Hinton (51:36) That that's a really interesting way to think about it. One of the things we we we s sort of hear a lot about in the cybersecurity space is that we've never really made security a huge part of our digital reality, right? It's always been about speed, efficiency, does it work? You know, software in mind in that case. And we are now at a moment where, to your analogy about physical fitness, we've come to middle age and it's like, Ooh, wow, we need to get it we need to get back into shape, you need to Cut out the red meat or drink less or lose a few pounds, whatever it is, walk more, take the stairs, that sort of thing. And if you were starting a company today from scratch, or you you you you start your startup, one of the things that you would advise them to do from the very basic is to s micro-segment from day one. Like treats treat put implement this at the beginning and it and it sets the bedrock or groundrock or foundation, whatever w analogy you want to use for a more secure system. Piotr Kupisiewicz (52:21) Please. Martin Hinton (52:31) as you grow and we know, right? We know that the dilemma with companies when they're growing is that everyone's working on growing the business, not working on the business, and there's a subtle difference there. And one is priority and the other feels like something you can push off till next week. And lo and behold, we've pushed off a lot of this since the nineties when the internet came online. We we've sort of well I guess passwords weren't that secure. Now we'll try MFA with a text. that's not that secure either. What about that? Is that is i i if you were gonna give advice to some organization starting out today or would that be something to to put in the cybersecurity bucket right away from day one? Piotr Kupisiewicz (52:59) Yeah. I mean 100%. It's much easier when you're starting up and when you are starting to build your infrastructure, connecting your assets to the network. When you are connecting the asset to the network, you know, it's much easier to ask yourself a question, what should it communicate with? you know, what is it? Versus 35 years later, when you realize like when you when you look at the asset in the network and you're like, what is it? I mean, what does it do? You know. yeah, it it it is hundred percent much easier to do it, you know, starting up. It is not it doesn't mean that it is not possible to do it later on. It is just you know, a little bit more difficult. Martin Hinton (53:51) No, I'm I again, you know, it i the we can't go back in time and and and the the joke I I I've learned to make is hindsight is the name of a hill from which the view is always perfect. But the best the best the the best time to have started something was yesterday and the next best time is today, right? So so it is i yeah, it like you said, and sometimes things take a process, right? There's a process and there's a way to do things to make sure they implement properly. But it is a fascinating idea. I mean I I use the house analogy. The analogy you used when we first spoke was the submarine for what micro segmentation is. And and I wonder whether you might use your your analogy to help the audience understand how this works, but then also the concept there of how it creates protection for the whole of the enterprise, or in this case submarine. So so tell me that give me that example again. Piotr Kupisiewicz (54:41) Yeah, I mean the the the submarine analogy is you know when you look at the submarine the the constructors just assume there will be a water bridge at some point for various reasons and there are and to limit the the impact to the submarine so it basically does not sink, you know, there are these compartments that you can close you know at will. and it it's basically about the building the submarine that case, you know, and and about the res resiliency. And I think, you know, the analogy here to the businesses, business and the infrastructure is you know, we should try to to build our business in the way that you know, if if if part of our business is, you know, impacted in in in our world by by the Cybersecurity Threat Act or by a malware and ransomware, we still can continue running the business. You know, there might be an impact we might you know manufacturing things a little slower or you know one of our products that we are manufacturing might not be actually manufactured at the at the time but we are still continuing with the with the day-to-day business and I think you know to to the discussion we had earlier I think it is it is easier to you know to design the submarine kind of ground up I mean the company you know when when when you're starting up thinking like about the res resiliency from the day one, but it does not mean that we cannot you know what we are actually doing in in Alicity is kind of you take a regular ship or submarine without these compartments and you know we've spent you know the last six or seven years knowing where to put these compartments on already running and on already running submarine and and it's very difficult but but it is possible nowadays. Martin Hinton (56:34) Yeah, well mean the one of the my y you you the analogy I've used keeping this at at sea, if you will, is you see ships, you know, being painted as they sail across oceans and the sailors hanging over the side, you know, scraping off rust and painting the hull. There is a constant need for maintenance. And and in some ways the the the ship or boat analogy is is one I keep coming back to in this space. There's a joke, at least in the States Piotr Kupisiewicz (56:41) Right. Martin Hinton (57:00) for people who buy boats for recreation that they aren't boats, they're holes in the water you throw money in, right? The the idea is that they're there's constantly something they need to be done because the ocean is relentless. The ocean winds. What you you made the analogy already, water winds, right? We know it erodes stone, it w it takes away coastline. If there's a huge storm, it can totally radically change the geography of a shoreline. And in some respects the cyber threat is this twenty-four hour day can come in the middle of the night. Piotr Kupisiewicz (57:07) Right. Yeah. Martin Hinton (57:29) Come in the middle of the morning, in the middle of the day, relentless pressure that you have to accept the reality of, like Sisyphus, and you just have to keep holding that rock up and moving it up the hill. That that's the situation we're in. you know, it it doesn't mean it's impossible and it doesn't mean it shouldn't be undertaken, but don't underestimate the the threat, because if you do, you're gonna wind up in a potentially very, very difficult situation as a company or an individual. I mean, I I don't know if that's overstating it, but what do you think? Piotr Kupisiewicz (58:01) I mean a hundred percent I I think cyber cyber threat is not something anyone can ignore nowadays. I want to say that, you know, in the maybe not that rosy picture that you have painted. I I need to say that, you know, after spending almost two decades in cybersecurity, I need to say there that there are plenty of positives. You know, there are great people that I've met on the defense side of things, very often, you know, like minded, you know, with with with just fantastic you know, values as as as humans and at the end of the day, yeah, I I think you know just what what I'm trying to say is I do believe that cybersecurity is is a team sport. you know we we are all seeing even the largest company l largest competitors out there who are working collectively in the in the cyber warfare, right? You know, Amazon will work collectively with with eBay or or with Google, even though they are competing on the cloud side of things, they will work collectively against the threat actors out there. So yeah, what I'm just trying to say is that it is a hard job and we cannot ignore the the cyber threat but we should work you know collectively as a team. It's a team sport. and and you know there is also some fun in this yeah. Martin Hinton (59:24) So I I it's a it's a total aside and we're about an hour, so we're gonna wrap it shortly. But I I I've been a journalist for over thirty years, and I've had the p privilege of traveling and working in all kinds of different spaces and sectors and industries. And I've been working on this journalism in this space, cyber insurance and cybersecurity, for about three years now. And there is a real there's a duality, right? There's this awareness of the problem that needs to be solved and the enthusiasm and energy around finding those solutions and working at that problem. And again, it's, you know, people are seeing a problem. They're thinking, I can create a company or a product that'll make money to solve that problem. And there is really, really it's like pleasant to be around. Like the the the the there's optimism, not misguided optimism, not foolish optimism, but like, you know what, we can get this. We we we're we're not alone in this. And then the other thing is when you when you go to these sort of conventions that I attend, there is that sense of camaraderie. Like there's, you know Piotr Kupisiewicz (1:00:08) Yeah. Martin Hinton (1:00:22) we we're trying to sell the same product to the same people but but i i if any of us don't figure this problem out and we're not selling anything to anyone no matter who we are or how good our product is. So so it's it's it's kind of a fascinating and interesting dynamic and as I touched on, people and the way they behave, it it's it's n it's nice to be around, frankly, and and and I just wanted to say that 'cause I I second your take about it. It it it really is. Piotr Kupisiewicz (1:00:24) Yeah, that's okay. Yeah. I guess I'm not a question. You can read it Martin Hinton (1:00:45) So we've been talking about an hour. Is there anything we didn't get to that you'd like to say some more about excuse me, that you you'd like to say more about or anything we didn't get to you'd like to say something about? Piotr Kupisiewicz (1:00:55) No, I I I actually think we we yeah. I I think we we covered everything that I would cover. Thank you. Martin Hinton (1:01:03) Yeah, my my pleasure. So I'm gonna ask one last question. For a non technical executive listening to this, the a CFO or maybe a general counsel who thinks cybersecurity is just an IT thing, what's one idea you want them to walk away with or ask their CISO about or raise with the board? What what's one topic that that you think they should make sure that they understand and have their head around today? Piotr Kupisiewicz (1:01:27) I I think What's the most pessimistic scenario? for you know if we are being attacked, like you know, I think this the conversation that I always encourage people, the boards to have. It's very difficult conversation, but the most, most, most pessimistic one. And you know, how are you? You know, how are you it doesn't need to be technical conversation, but you know, very often you are seeing a company saying, Hey, or or I ask this question, like what's the what's the worst case? That can happen for you. Hey, if we are if we lose this ERP system, we are dead. There's nothing we can do ever. You know, the company's shut. I'm like, okay, so what are you doing now to protect it? And now you can go back, you know, to backups, to disaster recovery, etc. But just you know, just having a conversation. I don't know if this is exactly, you know, what what what what you are asking for, but but yeah, this this is what I'm saying to non technical executives, you know. Martin Hinton (1:02:30) Yeah, no, I I I I listen, I I think that's that's it's a great idea. What what's the worst thing that you could wake up to on a Monday morning and are you ready to deal with that? Is is from a from a cyber or a digital point of view, given that all companies are in the cyber digital space is is a really good one. I mean the the joke you hear is you come in Monday morning and every computer screen's blue and you can't do anything. You can't send any bills, you can't receive any payments, you can't communicate with anyone. How does that day unfold and where do you go from there is is A good question. And then that gets into incident response and all sorts of things that open up the question of are we ready to deal with the worst case scenario? Piotr Kupisiewicz (1:03:05) Yeah, I mean then then you can go backwards, right? You can say, okay, you know, if all of my computers are having a blue screen, you know, even if at least I had one, I can then email my suppliers or something. So maybe start with this one. but I I what I've noticed is just asking the question and then I'm just okay, let's visualize this case. Like what happens? And and and then you can I mean it opens the just the understanding of, you know, how important is digital systems. We talked about critical infrastructure, but then what's critical infrastructure in your company? Like, you know, which server, which device, which application, you know, and and and then I think, you know, this sparks an imagination and you can go backwards to like what what's what's then the, you know, the the defense measure. What's the the control system to address this. Martin Hinton (1:03:55) Well said, well said. Well I I don't have anything else. I just give you one last chance. Is there anything else from you? All right. Piotrit Kopashevitch, the CTO with Elisity. I hope I got that correct. Thank you so much for your time, Piotr. It was really, really interesting and I hope the heat wave breaks soon. And again, thank you for your time. We just discussed a few things. We'll be links in the show notes for the audience. If you've got a question, you can leave a comment and we'll get an answer or we'll get back to Piotr Piotr Kupisiewicz (1:04:00) I'm good. Thank you, Martin. Martin Hinton (1:04:25) and we'll see what he has to say. But thanks very much again. Everyone else, thanks for listening and watching. My name is Martin Hinton, the executive editor of Cyber Insurance News and Information. Again, thank you very much for your time today. Enjoy the rest of it.