


This article is based on an interview with Richard Balducci, director of information security and CISO at Integer.
Major Challenges and Trends Impacting the Enterprise Security Industry
In my experience, the cybersecurity community is relatively tight-knit – we’re willing to help each other to keep our respective companies safe. In recent years, one challenge we are seeing is a shift in adversaries also starting to work together, which makes it a lot tougher on us. In looking at RaaS (ransomware as a service), phishing as a service, and the dark web selling of credentials and data, adversaries are sharing increasingly more with each other while bringing down the barriers to entry for other cyber-criminals. With fewer resources needed, cyber-criminals can now leverage “as a service” resources and functions at the same level as bigger players. While these types of criminal gangs don’t typically breach the same company twice, they do share credentials and methods with other cyber-criminals, potentially resulting in companies experiencing a second or third attack as a result, but not from the same group.
In addition, I would be remiss not to mention generative artificial intelligence (AI). It is a game changer, and we are barely scratching the surface of its capabilities, which, of course, means cyber-criminals are already experimenting with it. We are seeing it used to create phishing emails, polymorphic malware and more. And, while cybersecurity vendors have already begun to incorporate AI into their tools to help thwart attacks, in the future, I believe each company will leverage its own internally generative AI platform for more intelligent alerting and response.
Major Predicaments in the Enterprise Security Industry
Balancing staff and budget is, of course, always a challenge, as is making difficult decisions. Shadow IT is another area that remains a challenge. Cybersecurity and IT must do a better job at communicating processes and clearing roadblocks so we can support the business at the necessary speed.
Latest Project You Have Been Working On, and the Technological and Process Elements Leveraged
We have many projects in the works, but one that is unique and has positively impacted the business is badge authentication. We use service accounts on many of the computers that directly support manufacturing, so our manufacturing associates don’t tend to have named identities in the active directory, as is typical in the industry. This is changing as we roll out a manufacturing execution system (MES), a digital way to track and document manufacturing. The MES requires named users to track who performs each step.
On the manufacturing floor, all systems are touchscreens. Since manufacturing associates would be logging on and off these systems multiple times per hour, it became a burden to type in their user IDs and passwords. To remedy this, we implemented a system to allow for scanning their employee ID badges in conjunction with a PIN. It's the same idea as two-factor authentication, and time studies showed this solution would result in significant cost avoidance. There are not too many times an information security organization gets to impact the business positively in such a way while simultaneously providing a positive end-user experience.
Exciting Technological Trends for the Future of the Enterprise Security Industry
The first thing that comes to mind is AI. It has been around for a while, but with it now hitting the mainstream, it is very exciting to see the evolution. I believe this will potentially be as revolutionary as when the Internet was formed. Cybersecurity vendors are evolving and incorporating AI into their platforms. I also see startups having a bit of an advantage by designing new platforms that are AI native. I am excited to see the newcomers in this space bring transformational creative ideas that present a true paradigm shift in the industry.
I am additionally eager to witness the continued evolution of operational technology (OT) and the Internet of Things (IoT). Over the past two decades, we have had many devices being network-attached without the security controls embedded to secure them properly. Adversaries have taken note of this and recently pivoted to aggressive attacks on these devices. Why? It’s simple; they don't have good security, and they know they can hide undetected for a very long time. There is now a range of tools available to shift the security stack and controls from the device to the network layer. This means you can have nearly the same level of security defenses on traditional computing devices as on OT/IoT devices.
I am also excited about the increased incorporation of anomaly detection capabilities into our tools. The adversaries live off the land, meaning they use capabilities, tools, commands and more to carry out malicious deeds. This makes it extremely difficult to detect because of the question of how to differentiate legitimate usage from nefarious usage. The answer is anomaly detection, which will alert to types of usage not seen before in a specific environment. It is these nuggets that will help us decrease dwell time and find adversaries earlier.
Adapting to the Rapidly Evolving Industry
I learned quickly that I needed to pursue the next big thing. After my time in the Air Force, I jumped on the Internet bandwagon, quickly discovering this extra connectivity required security. In turn, I immediately focused my efforts on running IT infrastructure and securing it. I remember in the 90s running "Cyber Cop" as my vulnerability scanning platform, collecting the results, presenting them to management, and remediating them. It was not easy back then, but it was just as fulfilling. Cybersecurity has been one of those areas that has really taken off in the last two decades, and it is not going to slow down. However, you need to stay agile and continue to evolve as the trends and technologies evolve.
I also fell in love with leading people. I have taken a lot of leadership training throughout my career and have even taught leadership training. I take so much pride in helping people grow in their careers. The biggest compliment I can get is when people under me have grown to the point of becoming a CISO. I want to grow as many new CISOs as possible.