Andrew Rose (US)

speaker
103 appearances 1 recordings 1 series first heard Jun 2024 last heard Jun 2024

Andrew Rose (US)’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
If you call the FBI in, they're going to get it in and out as quickly as possible with full permission from you to access whatever it is they need. And then they're going to go catch the criminal, but they're not going to fix your systems. So I did talk to a large pork producer who was upset the FBI didn't fix his computers. I said, that's not their job. And he was,
I couldn't placate him, but I at least stated that as a whole.
Make a friend before you need it. Yeah, make a friend before you need a friend. That's usually my first bulleted point. But in the ag community, there is a little bit of trepidation about the FBI. There are certain sympathies for what happened on January 6th.
And the FBI will be the first to tell you everyone in this country has a First Amendment right to wave a flag, to have a bullhorn, to ring a cowbell. But once you take an action, that's when risk and consequence occurs. So sympathies are fine, you know, and they're not there to judge you on anything like that. They're there to catch criminals. That's
I do want to give an amen to that. I've been preaching the secure by design principles to robotics and ag tech companies, and it's not a resistance. Oh, didn't think about that. So it's not a... It's worse. Well, I mean, they're concerned with interoperability, exchanging information, flow of data. So security is obviously an afterthought, if it's thought at all.
But by putting that in the top five on their list, now it's there. I'm also coming from the investor standpoint. So an investor is not going to want to put money into a company that's going to have a lifetime of patches and upgrades required because they weren't thinking about security on the front end. That's just going to degrade their investment dollars, too. So there is no pushback from that.
It's just a lack of awareness, which is the first step in anything. Another piece that I mean, this is more of a global piece, but as a species, we rarely will fix something until it's been broken. So we didn't even understand how significant this was until the JBS attack.
So Andrew, I'm just hoping that somebody someday will come back to this podcast and say, oh, all those things Andrew said, yeah, we're going to implement them now that something has occurred, you know, rather than getting ahead of the attack. So I'm not, I mean, I don't want to be overly cynical, but it appears that's typically the way that we operate.
The thing that we haven't talked about here, and Chris, maybe you'll cover this in another podcast, was the Microsoft hack of all the executives. And there's a lot of speculation that the source code is gone and that the Russians now know every zero day vulnerability before Microsoft does.
I don't know if you've been watching your Microsoft updates lately, but every day now there's another patch coming in. And again, Microsoft, I'm just speculating. No one's admitted anything yet, but I have a high suspicion that some of that could have been compromised. And then going back to the secure by design is the liability piece.
Let's say that there is that one little thing that everyone's using that isn't secured. What happens if that's a conduit from a tax? Then who is going to hold the liability? Is it the end user? Is it the farmer or the agribusiness? Is it the manufacturer? Who knows? Are they still in business? There's a lot more questions there than there are answers.
And as I mentioned before, we need to understand we're in pre-war footing here. Our enemies are already pre-positioned into our critical infrastructure. If we're not aware of that, if we're not mitigating and responding to that, shame on us.
And with the, and again, this is Andrew just speculating out there, with the number of onslaught of attacks and the increase in velocity of these attacks, we still are playing the nice guy. You know, we're still putting the fires out, fixing things, and whatever offense we're taking is shrouded in opaque for certain reasons.
Yeah, but we're going to reach a day when this crescendo is so great that we're just going to take the gloves off and start hitting back. And, you know, I'm kind of looking forward to that. I mean, just... They said that a cyber attack could constitute an act of war. And I know that's been said, but I haven't seen it acted on yet.
But it breaks my heart because for every ag hack that you see, there's probably another 90 that I hear about that aren't seen. And it breaks my heart what's going on right now. And I really would love to punch back a little bit.
Or Kristen, I mean, the easy answer there, at least the normal reaction is let's just fire the CISO, you know? Absolutely.
So Kristen, are you setting up the next podcast? Because we ran a field exercise recently in Pennsylvania that is pretty much word for word what you described. There were two identical companies, agribusinesses. They both got hit almost on the same day, the same ransomware, same actors. One paid ransom, one didn't. And we were able to do 18 months later postmortem on what that was.
And it is amazing. We haven't released a white paper yet, but that was part of the volunteer work I do for the Bio-ISAC.
Well, it echoes what you said. The CEO, they didn't even think that this was anything other than why us. It was emotional. It was tears. It was employee tears. So they felt personally attacked. They didn't even think about law enforcement or anything. They just wanted to get everything cleaned up and get their systems online. It was a significant financial hit, a significant timeout.
time hit and they are a major player in the country for the sector they serve, as was their competitor. So yeah, affirmation to what you just said.
Showing 81–100 of 103 · page 5 of 6 ← Previous Next →