Building the Foundations of Cybersecurity
CIOREVIEW >> Data Security >> NEWS

Chief Information Security Officer at Virginia Polytechnic Institute and State University.

Randy Marchany

Building the Foundations of Cybersecurity

Randy Marchany
Randy Marchany, Chief Information Security Officer at Virginia Polytechnic Institute and State University.

Through this article, Randy Marchany reflects on his early journey in cybersecurity and how key innovations and challenges shaped his career. From his involvement in pioneering projects at Virginia Tech, Marchany shares how these experiences prepared him to help shape modern cybersecurity. He also highlights the impact of initiatives like the Virginia Cyber Range in revolutionizing cybersecurity education and emphasizes the importance of learning from mistakes, evolving with threats and actively participating in the cybersecurity community.

A Journey from the Early Days

In a way, I was lucky that I got into cybersecurity when I did (1992). Since it wasn’t a “thing” back then, we had the opportunity to shape it. The most significant break I got was back in 1991-2 when I got an email from a startup called the SANS Institute. Alan Paller, SANS founder, liked our presentation at their second annual conference and invited us to participate in some projects he had in mind. The SANS connection was a small part of a larger group of tool builders, practitioners and some management types. Our connections through Alan were a great resource for sharing and testing ideas. Working at a university was another key factor in my career.  Some of the things at Virginia Tech that I think were cutting edge were:

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

a) Bring Your Own Device (BYOD). The university started requiring students to purchase a personal computer in 1984.

b) Connecting to the “internet” in the late 1980s. Universities, including Virginia Tech, were among the first to connect to networks like Arpanet and Bitnet, setting interoperability standards. The 1988 Morris worm attack was a wake-up call that highlighted the need for cybersecurity, leading us to work with groups like Computer Emergency Response Team (CERT). Virginia Tech was also an early member of the Internet Storm Center, contributing to its initial intrusion detection efforts.

  ​When it comes to incident response, the most critical phase is the follow-up. Reviewing what worked and what didn’t is where real learning happens.

c) The Blacksburg Electronic Village (BEV). In 1991-1993, Virginia Tech, the Town of Blacksburg, VA and Bell Atlantic (now Verizon) partnered to connect the town's residents and businesses to the Internet. It was an experiment to see how the general public would use the Internet. The first e-commerce transaction arguably took place here in the BEV between a customer and a local grocery store. That experiment gave us a preview of how the Internet could be used by the general public.

d) System X Supercomputer (2004). A research team at Virginia Tech created System X, a supercomputer consisting of over 1100 Macintosh computers in a grid. System X was rated as the 3rd fastest supercomputer in the world, built for a fraction of the cost of other supercomputers.

e) The Virginia Cyber Range (2015-16). The Cyber Range platform allows K-12, community colleges and higher education institutions to create an environment for teachers to create free cybersecurity exercises, labs, modules and full courses. Almost every K-12 school, community college and university/colleges use the Cyber Range for cybersecurity courses. Initiatives like these contributed to my overall career growth. All of these perspectives helped me in the cybersecurity world.

Cybersecurity Challenges in Academia

In the late 90s and early 2000s, the biggest challenge was changing the university's culture to embed cybersecurity hygiene into everyday life. It’s gotten better today but some of the root issues from 25 years ago are still present. Fortunately, the university’s executive management understood the challenge and allowed us to continue working. Cybersecurity is becoming an integral part of the university's everyday business functions.

Dealing with security flaws in vendor software is another challenge for us.  Email phishing is another recurring problem that is a great example of how offense affects defense which affects offense. The phishers adapt to new defenses like MFA.

Leveraging Threat Intelligence

Virginia Tech is a member of VASCAN, a consortium of the public universities, colleges and community colleges of Virginia. VASCAN meets on a regular basis and is an excellent source of threat intelligence. We’re also members of the REN-ISAC and MS-ISAC which are great resources for discovering new threats and solutions. The Federal Government cybersecurity resources like CISA are another venue for threat intelligence. Vendor resources are yet another resource. EDUCAUSE is an excellent resource for the EDU community and participating in their various working groups and projects has been a great asset for my staff.

The Impact of the Virginia Cyber Range

I think the Virginia Cyber Range and its twin, the US Cyber Range are the most influential services that allowed the explosion of cybersecurity education at all levels of education. In the K-12 arena, teachers interested in teaching cyber courses typically ran into barriers put up by their local IT staff. Local IT didn’t want “hacking” systems disrupting their daily operations.  When the Range came online, teachers no longer had to create physical labs at their schools. All their students needed was a browser to access the lab environments. The course repository was filled by teachers from all levels who were funded to create the course materials and most importantly, make them available to anyone using the Range.  At any given point, the Range may be hosting 20,000 virtual machines for students all over the state. Dave Raymond, the Cyber Range director, has been the driving force in the Range’s success.

Lessons from the Front Lines

Well, realize that you will make mistakes in the cybersecurity world. Learn from your mistakes. I became a cybersecurity expert because I got hacked a lot in the 1990s. I suppose that was fortunate for me since it wasn’t a big deal back then. I learned from my mistakes.  However, the most important phase of incident response is the last step – follow-up. This is where you review which incident response worked well and which ones didn’t. Know when to say yes, but more importantly, know when to say no. Ask questions and learn from your superiors and peers.

Career Tips for Success

Submit a proposal for a presentation at a local, regional or national event. Talk about things you’re doing at your job. Volunteer as a working group member for some external project or event like the Center for Internet Security projects. Check out free and low-cost training venues like SANS Summits, BlackHillsInfoSec’s pay-what-you-can and free training they provide. Learn one new thing every day, whether it’s a technical thing or a work-related process.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.