Dan Jones, Senior Security Advisor EMEA at Tanium: “If you do cybersecurity on the cheap, you’re just making your life harder”

Taniumโ€™s Senior Security Advisor EMEA, Dan Jones, speaks with the velocity of a man on a mission. Thatโ€™s not far from the truth, given that he spent nearly three decades at the Ministry of Defence (MoD). Today, the mission is more metaphor than reality, but no less important for him.ย  As AI threatens a once-in-a-generation upending of cybersecurity norms, his take is refreshingly honest. This isnโ€™t a technology issue. Itโ€™s a people problem.

TechFinitive caught up with Dan at the Tanium Converge event in London, where he shared his views on everything from Mythos (not hype but not new either), Tanium’s conversations with NATO (they have the same problems as all of us!) and what the company means by “Autonomous IT”.

Which leads us to our first question: with the rise of automation, what role do security ops teams have?

Weโ€™re seeing more and more AI and automation in cyber. Do people still matter?

Absolutely. You can have amazing technology like Tanium โ€“ and I speak as a former customer. But it becomes greater than the sum of its parts when you pair that technology with brilliant people. It’s the people that are your most critical success factor that you can invest your time into. But they’re also probably the single biggest threat that you have in your organisation, because they’ll do things you didn’t quite expect. Humans are unpredictable.

Cybersecurityโ€™s a people problem thatโ€™s always dressed up in technology. That piece of technology does very little unless you can pair it up with brilliant people that know what they’re doing.

Is Mythos hype or will it actually change the way cybersecurity works in organisations?

Mythos is not something that is new if you’re in cybersecurity. It’s always been understood and going on in the background. It’s just that on April 7, it became mainstream. And I think that is only a good thing. It would definitely have been a challenge to help people do their day jobs if we didn’t have something like that become more understood by a broader audience.

It’s definitely cutting through to the board. This is an opportunity that’s not to be missed. Youโ€™ve now got a board that is asking direct questions, and wanting to know what we are doing about it. It isn’t adding anything to the to-do list that wasn’t already there, but it is changing fundamentally what the priority of that to-do list looks like. And it’s probably elevating something to the top of it that has only been given lip service before.

But even if you have the ear of the board, if thereโ€™s no more money, what do you ask for?

The truth is, if you always do what you’ve always done, you’ll always get what you’ve always got. So you need to put people around the table and say, โ€˜this is the problem; we will come up with a way around itโ€™. That’s not to say that it’s easy, and I’m definitely not trivialising budgeting. But there are ways to do creative accounting. Defence, because it was spending megabucks of public money, had an entire cottage industry that would look at cost assurance and analysis, and whether you had enough budget to do everything.

You can also do simple things like, look at the amount of tools in your environment. Do you need all of those tools? Budgetary pressure is not a new thing as a result of Mythos, but it does change the priority. Humans now need to make a call. Where’s your biggest bang for buck going to come from?

Youโ€™ve just been speaking to NATO. What challenges does that organisation have?

It’s exactly the same for the conversations that we have with every customer. There are no exceptions, NATO included. They’ve haven’t got an infinite pot of money, as big as they are. They need to be able to deliver on that investment for the best impact for a multitude of nations that are invested in it. And if anything, their job is probably harder because you’ve got a coalition coming together so everybody’s got to agree. And just when you think you’ve solved one problem, along comes the next challenge.

Tanium is going big on โ€œAutonomous ITโ€. What does it mean?

Autonomous IT is an outcome; it’s a vision. Every organisation needs to do what it thinks it should look like for its own purposes. But it will be a people-based decision. How much heavy lifting do you want the computers to do? Because if youโ€™re patching every month or three months and exploits are coming out after a day, are you still going to do things the same way you’ve always done them?

Itโ€™s down to the culture of the organisation to judge how much of that digital estate you want to run autonomously: self-healing, self-maintaining. Tanium can let you do [cyber hygiene] significantly faster and more cost effectively. And it will give you access to a load more technology and operationalised defensive cyber functions. But you’ve got to have the confidence to take it on.

Where should cyber hygiene start?

Take patching. Itโ€™s one of the most boring topics around. But it’s the kind of thing that you can automate. And if you can do it in a way thatโ€™s cheaper, you can reinvest all of those people that you’ve got currently focusing on that into other cyber jobs where you need that human-in-the-loop decision making. Because not everything can be automated and put on an autonomous footing. 

So can autonomous IT be something of a saviour for a cybersecurity sector short on skills?

Yes, absolutely. If youโ€™ve got, say, Tanium sat behind Security Copilot doing all the work for you, itโ€™s allowing you to be a fairly effective analyst or cyber operator from day one. You don’t need to have 3- 5 yearsโ€™ worth of experience in different disciplines within IT in order to then become a cybersecurity operator or analyst. So it’s lowering that bar to entry.

So you can not only bring on new personnel that maybe aren’t as expensive as some of your existing personnel. You can also start to have a blend of people. You don’t need to have a team of five uber-experts with 150 years of experience between them. You can mix and match. And that also has secondary benefits of potentially offsetting as people move around and look for different roles. Although behind the scenes, you still need those people that have a fundamental deeper knowledge.

The MoD strikes me as a unique organisation in many ways. Did it teach you anything about cyber?

I’ve been quite relieved coming into doing the job I’m doing with Tanium to learn that, actually, the cybersecurity challenges I faced when I was in the MoD are ubiquitous. The priorities are different. The drivers for doing it, and the challenges that you face overcoming them are  different, and that’s the unique aspect to it. But actually, fundamentally, the root cause of problems is the same. You hear about IT, and particularly cybersecurity, being a cost driver. But no, the ones that are succeeding are making it a differentiator. 

If you do cyber on the cheap, you’re just making your life harder. If you make it an enabler, that means you can attract talent in and grow your customer base. That’s what autonomous IT means in this space. But it requires leadership. It requires people to have that vision in the first place.

More on cybersecurity

Phll Muncaster
Phil Muncaster

Phil is an experienced technology writer covering everything from hard drives to botnets, CRM to smartphones and processors to digital piracy. He has delivered news, interviews, analysis and opinion for print and online titles including The Register, MIT Technology Review, IDG, SC Magazine, Computing, V3, the INQUIRER - and TechFinitive.