Adapting Security Practices to Meet Emerging Cyber Threats
CIOREVIEW >> Cyber Security >> NEWS

Virginia Tech

Randy Marchany, Chief Information Security Officer

Adapting Security Practices to Meet Emerging Cyber Threats

Randy Marchany, Chief Information Security Officer
Randy Marchany, Chief Information Security Officer, Virginia Tech

Randy Marchany, Virginia Tech’s IT Security Officer and Director of its IT Security Lab, has worked in computing since 1972. A US Cyber Challenge founder, he shaped cybersecurity education, standards, and policy through CIS, EDUCAUSE, REN-ISAC, and national initiatives, authoring over 40 publications and advancing workforce development.

In an exclusive interview with CIOReview, Marchany discussed about the nuances of the evolving landscape of cybersecurity including the challenges and opportunities it presents.

How has your background in cybersecurity shaped your approach to safeguarding digital assets and ensuring robust security practices at Virginia Tech?

a) Over the past 33 years, I’ve been in cybersecurity, and my approach has evolved over time in the technical aspects (How things are done) but stayed constant in the strategic aspects (What needs to be done). For example, when there’s an incident, you need to be able to answer these questions quickly: What is the asset? Where is it located? Who’s responsible for its care? What data is stored/processed by the asset? How was the asset attacked? Where did its data go? How that information is gathered, processed and analyzed has changed because of technological advancements. The basic questions remained the same over the years. Use your tabletops to determine how long it takes to gather that material. Winn Schwartau’s “Time-Based Security” book has 1 equation, E=D+R, where E= the amount of time you’re exposed, D=the amount of time it takes to detect an attack and R= the amount of time it takes to react to an attack. Measure those times in months, weeks, days, hours, minutes, and seconds. That exercise alone is an eye-opener.

b) There’s a lot of effort that goes on (“pay no attention to the man behind the curtain”) to collect the answers to those questions and ensure their accuracy. For example, identifying a hardware asset isn’t easy. The diagram below shows some of the questions you need to answer before you can accurately identify the IP address of an asset. You certainly want to verify that the DNS record is accurate. You need to check with your networking group to determine how they assign addresses. DHCP addresses may change dynamically after a certain period of time. Are you using proxies such as Network Address Translation (NAT) or Port Address Translation (PAT)? Are you requiring critical assets to have static IP addresses? Certainly, vendor asset management products can provide information, but they depend on your network addressing procedures.

  ​A good place to start is simply making your user community aware of the digital threats out there 

a) Building a high-risk data inventory is difficult as well. Knowing what type of sensitive data is on a compromised asset is paramount. Why? Apart from the usual PR image issues, your organization may have to meet certain disclosure deadlines to regulatory agencies. These deadlines can range from 24 to 72 hours from the time an incident or suspected incident occurred.

b) My experience has shifted my focus from hardware/ software inventory to high-risk data inventory. There are data breach notification laws, not device breach notification laws.

What are the primary challenges you face in managing information security at an academic institution and how do you tackle them to ensure campus-wide security?

EDUs face the same challenges as any other sector in managing information security. Budget constraints, bureaucratic inertia and resistance, staffing issues are the main challenges everyone faces. You approach it a piece at a time. A good place to start is simply making your user community aware of the digital threats out there. Tell them who to contact if they suspect they’re a victim of a cybercrime. Creating short refresher training options keeps everyone in the loop. For the first time in my career, security awareness training (onboard, refresher) is mandatory for all employees.

How are you leveraging emerging technologies, such as AI-driven security solutions or advanced threat detection systems to strengthen Virginia Tech’s cybersecurity framework?

a) I’ve seen too many movies like 2001: A Space Odyssey, Colossus: The Forbin Project, the Terminator series. I’m not that concerned about AI for defense at the moment. What really scares me is how AI is used for offense. We’ve seen an increase in credential stealing attempts where “secret question” or PII information that is used for account change verification is being provided by the attackers. For example, we had a user who was notified that their PII was included in a data breach of a major telecom last year. Shortly after that, someone attempted to change their user credentials. They supplied the correct verification info and almost succeeded. One of the data elements requested by us was something that would have been in the person’s record that was part of that data breach. An AI tool could have assembled all of the information needed to launch a successful “bypass credential updating” attack. We’re using a vendor pentest tool that automates their pen testing tools using “AI” based methods.

b) AI for defense has to get access to your IDS data somehow, and the easiest way to do that is to have you send copies of your logs to a 3rd party vendor for analysis. Some vendors have a huge presence in agent-based IDS/IPS, so they’re getting excellent data for training their AI engines. The tradeoff is sacrificing the confidentiality of your data vs. the threat hunting benefits.

With the increasing threat landscape in the digital world, how do you ensure that Virginia Tech’s cybersecurity strategies evolve in alignment with emerging cyber risks and regulatory changes?

We’re using the NIST CSF and the Center for Internet Security (CIS) security controls as the framework for our cybersecurity strategy. The CIS maps to a number of frameworks (NIST800- 171, PCI, CSF, CMMC, international), so we can at least comply with the major points of those frameworks. Our minimum security standard is the CIS IG2 version of the controls. Tony Sager once said that there are only 3-5 unique cybersecurity frameworks, and the rest are cut-and-paste versions of those original ones. If a particular business unit is required to adhere to a stricter standard, then we can segment their network and apply the stricter requirements on those assets.

What advice would you offer to other cybersecurity leaders in educational institutions seeking resilient and adaptive security systems in this rapidly changing digital environment?

My advice to all CISOs in the EDU, commercial and government worlds is threefold.

1. Learn to anticipate potential attack venues by taking advantage of information shared on various platforms and your own organization’s data. Never waste a breach, which means have some potential solutions to anticipated attacks.

2. Know what you don’t know and find out who knows it so they can teach you. Cybersecurity arrogance (“I know it all” syndrome) is a serious threat to an organization.

3. Identify the most critical business processes in your organization, find out what assets (hardware, software, data, people) they need and how to protect them. Recognize that all of this takes time to do.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.