Importance Of Integrating Cybersecurity In Every Nook And Corner Of The IT Infrastructure
CIOREVIEW >> Cloud >> NEWS

Huntington National Bank

Mark Gordon, Vice President - Senior Cybersecurity Operations Manager

Importance Of Integrating Cybersecurity In Every Nook And Corner Of The IT Infrastructure

Mark Gordon, Vice President - Senior Cybersecurity Operations Manager
Mark Gordon, Vice President - Senior Cybersecurity Operations Manager, Huntington National Bank

Could You Give Me A Brief Overview Ofthe Journey That You Have Had In The Industry Before You Became The Senior Cybersecurity And Risk Management Expert At Huntington National Bank?

My expertise started at Computer Land of Sante Fe, NM where I went from a setup tech to a Certified Novell Engineer over the 5 years I was there. That lead me to MicroAge where I achieved the very first certification from Microsoft (Microsoft Certified System Engineer) on Windows NT 3.5. That eventually led me into the semiconductor industry working 19 years at Intel Corporation in their RootCertificate Key Generation facility testing and securing their cryptographic services. After leaving Intel, I built my risk and program management experience through combining the flight systems between US Airways & American Airlines. After a year of working for Cisco Systems selling their security services, I hopped into the automotive sector at Fiat Chrysler Automobiles (FCA) as an enterprise security architect, working side-by-side with Google. My job was to aid FCA in understanding the best way to protect the customer’s intellectual property, while preventing the connected vehicles from being compromised. That is when the banking industry came calling.

What Are Some Of The Trends That You Are Noticing In Terms Of Cloud Adoption, And How Are Organizations Handling Their Migration Processes?

The adoption of cloud computing solutions has accelerated as enterprises attempt to realize the improved cloud-based benefits when compared to on-premise solutions, but lack critical experience and education to make some of the key fundamental decisions around security architecture, IAM, secrets management, DLP and other core services contentious – causing frustration from delays and re-work. From what I have seen across the various sectors, teams earnestly want to try and shift over to the cloud solutions while attempting to embracecloud-native services that have baked security earlier into their processes. On the surface, it seems easy for them to fulfill their desire to reduce the number of misconfigurations due to human interactions, especially when the cloud vendors attempt to make things seem easy. But, it is not as easy as flipping a switch or just enabling a service, even IF you already have the robust skills in coding with Terra form and Python, for example. You need expertise around understanding& choosing the industry standard security control benchmarks, to make adjustments and implement with quality.

 Don’t try and change the whole corporation at once; pick a couple of projects that have some visibility, employ some creative & determined problems solvers - and continuously-improve every day to roll-model the behaviors while shifting security LEFT. 

It also comes down to the management of the cloud. We will see a better adoption and acceptance once fundamental knowledge of what security services can do for all the areas is better understood. In particular, we will need to better educate executives and managers with approach rather than the technical details of how the DevSecOps model works in respect to their existing enterprise silos. It is a shared responsibility between the cloud provider and the enterprise to accommodate and implement the model. Do not try and change the whole corporation at once; pick a couple of projects that have some visibility, employ some creative and determined problem solvers - and continuously improve every day to roll-model the behaviors of shift left security.

Can You Shed Light On Some Of The Reasons Why Cloud Adoption Has Increased After Covid-19?

There are several reasons and aspects surrounding the rise of cloud adoption, thanks to the hardships and change in reality from the pandemic.

For one, executives had to rethink how their resources could accomplish their tasks remotely, which the cloud solves natively. And customers shifted their expectations, some to their dismay when companies could not meet their demands. And then held onto the brighter expectations, from those companies that were nimble enough to pivot on the fly into the cloud. But those companies could not have been successful, without a dramatic change in their mindset, their approach, and their culture. As they began investigating cloud technologies, their concern for how their goals for cybersecurity also increased. But as the “shared-trust model”was demonstrated to be as-secure, or even MORE secure than their existing ecosystem - organizations began investing in the cloud, and it snowballed from there.

However, the effectiveness of their people using the new platform(s) was a gap, where they still needed to learn how to properly design, test, implement and operate within the new “shared-trust model”. But with great partnership from the platform vendors, including hands-on training where resources could learn at their speed (Think: FAST and OFTEN), cloud computing acceptance gained momentum. Senior management began to become familiar with the risk/ reward of moving into the cloud and chartered the teams to build comprehensive programs to grow out hybrid, cross-platform interoperability. As enterprises matured, so did their understanding of the evolving cyber threats, so they could implement their defense-in-depth strategy, ensure that their threat detection & response is optimized and continuously-improving, while meeting their appetite for risk.

Having said that,the cloud providers have been continuous improving their security policies for compliance, and for monitoring/managing customer data to help with GLBA, CCPA, HIPAA, PCI and other notoriously stringent regulations. Another silver-lining of the accelerated cloud adoption after COVID-19.

What Would Be Your Piece Of Advice To Your Peers Or The Leaders In The Cloud Security Space Today?

Take the time for research the best practices of related technologies ahead of jumping into the deep-end. Take the time to evaluate proof-of-concept/proof-of-value projects. Most vendors will openly partner with you to try their services for FREE, if you can show a favorable need. Allow multiple avenues of training. THINK: self-study with hands-on training, remote workshops, time for networking & peer-sharing events both in-person and remote anything atop of the traditional instructor-led classroom (Bueller, – anyone?) to incorporate the basic and advanced concepts into different areas of your business. This reduces the problem of getting answers and managing teams that need solutions faster than waiting for the teach to show up and hope to gain wisdom. If you are hiring a consultant, understand that they will not have all the answers. I would recommend that the resource, and especially leadership, attend at least one virtual conference a month, if not more, in multi-domain and in multi-sector conferences to get their perspective, which will help shift policies and standards into current best-known practices. It’s nothing new to you that ransom ware, phishing, and malware incidents are increasing the rate of security breaches at a mind-numbing rate. Cloud computing + A.I. is a requirement for large corporations to reduce the risk and elevate the correct anomalies that are true risks. Even more troublesome, the hacking successes are, in a sense, the large result of human error. Education and awareness are essential to combat cybercriminal activity and prevent security breaches. And since the bad actors are always evolving, using cloud technologies will help you shift security LEFT, and continuously improve your security posture (if done right) easier than on-premise solutions.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.