


Paul Groisman, senior director of cybersecurity at Fubo, brings over 23 years of expertise in IT, with a steadfast focus on Information Security for the past two decades. Specializing in Enterprise Risk Management, Security Program Management, and PCI-DSS Compliance, Paul has conducted numerous PCI Reports on Compliance audits and gap assessments, aiding stakeholders in navigating compliance requirements effectively. His proficiency extends to Data Privacy assessments, vulnerability management, network penetration testing, application security, and IT Audit reviews. With a deep understanding of IT Risk Assessments and Governance, he is well-versed in leading security frameworks such as ISO 27001/27002, NIST, COBIT, and ITIL, guiding clients in policy development and security best practices.
Please share your career path leading to your Senior Director of Cybersecurity role at Fubo. What are your primary responsibilities and priorities in this position?
With over two decades of experience in cybersecurity, encompassing both consultancy and hands-on practice, I have spent the last 20 years navigating the dynamic intersection between IT and cyberspace. Beginning my career in consulting, I specialized in compliance assessments, vulnerability management, PCI compliance, and ISO 27001. Since 2009, I have been a practitioner, dedicating a decade to manufacturing and diversifying into financial services, tech, e-commerce, and retail.
For the past two and a half years at Fubo, a publicly traded TV streaming platform with a startup ethos, I played a pivotal role in transitioning from Fubo Gaming to focus on TV streaming. As the inaugural dedicated cybersecurity professional, I built the cybersecurity program from the ground up, reporting to the SVP of Engineering. Operating remotely from Chicago for the New York-based company, Fubo maintains a cloud-first approach, recently migrating certain services to an on-premises data center for cost efficiency and quality control.
We have enhanced our cloud security strategy in light of a cybersecurity incident on December 22, which led to an eight-hour outage during the World Cup semi-final. This includes incorporating third-party expertise for penetration testing and application security assessments, complemented by in-house tools. As a Level One merchant with PCI obligations, outsourcing credit card transactions minimizes our scope. Recognizing the evolving threat landscape, I advocate for continuous validation through third-party managed services to stay ahead of potential risks in the fast-paced cybersecurity industry.
What are some of the significant challenges currently facing the cybersecurity market?
When integrating cybersecurity into our DevSecOps methodology and agile development processes, one of the primary challenges we face is the scarcity of expertise in this domain. While many tools are available, finding professionals with specialized knowledge in areas such as application security (AppSec) and cloud security architectures remains a significant hurdle. This scarcity is particularly pronounced given the expense and rarity of such expertise, making it difficult to compete with larger companies in securing resources. Additionally, as we strive for profitability by 2025, resource allocation becomes even more critical, necessitating a careful balance between onshore, offshore, and budget-friendly options. Moreover, integrating remediation activities seamlessly into our processes and timelines is essential for addressing cybersecurity vulnerabilities effectively.
What recent trends have emerged to address the challenges associated with penetration testing in the cybersecurity industry?
One prominent trend in addressing penetration testing challenges is the shift towards adopting a zero-trust architecture or approach to cybersecurity. Historically, organizations relied on external penetration tests, assuming their perimeter defenses were sufficient. However, with the increasing complexity of modern environments and the distributed nature of data and systems, there is a growing recognition that breaches can occur anywhere within the supply chain or ecosystem.
"One prominent trend in addressing penetration testing challenges is the shift towards adopting a zero-trust architecture or approach to cybersecurity.”
With the zero-trust architecture, the focus of penetration testing has shifted towards limiting the attack surface and containing the potential blast radius of an attack. This involves assuming a breach within the environment and conducting more internal or behind-the-firewall penetration testing. By giving testers basic user privileges or assuming they already have access to the network, organizations can better assess how attackers could gain access or elevate privileges within their environment.
This approach minimizes attackers’ ability to move laterally within the environment, which is crucial for detecting, responding to, and containing potential ransomware attacks. Overall, the trend towards internal penetration testing aligns with zero trust principles, emphasizing the importance of continuous assessment and validation of security measures to ensure robust protection against evolving threats.
Can you discuss a recent project where you’ve successfully applied these emerging trends to achieve success?
Ensuring the validation of controls by external parties after a breach or significant changes to the environment is crucial. Our recent projects have focused on updating incident response plans to incorporate necessary business partners and adhere to SEC notification and disclosure requirements. This emphasis on external validation and regulatory compliance underscores the importance of robust incident response measures in today’s cybersecurity landscape.
With all these potential disruptions and transformations happening in the market, how do you envision the future a couple of years down the line?
Anticipating the rise of AI, its integration into cybersecurity processes is seen as a transformative trend. Rather than replacing human controls, AI tools are expected to enhance and supplement human expertise. The essential advantage lies in the efficiency gained by security professionals leveraging AI technologies, enabling them to accomplish more with fewer resources. Automation of inevitable redundancies, analysis of extensive datasets, and anticipation of threats are areas where AI tools excel. While recognizing the potential for high false positives and inaccuracies, the focus remains on humans validating critical aspects. The overarching benefit lies in achieving greater quantity, efficiency, and scalability, making AI an integral part of the future cybersecurity landscape.
Is there any advice for your fellow peers and the upcoming professionals in this field?
It’s crucial to understand that achieving 100% security is elusive; cybersecurity is an ongoing evolution and an enduring journey. It’s not a static destination but a continuous process. As threats evolve, our focus should be on staying ahead of threat actors. They only need to be accurate once, while our responsibility is to be vigilant 100% of the time. This demands a proactive mindset, constant adaptation, and readiness to do more with less. My advice to fellow peers is to recognize that cybersecurity is a dynamic landscape, and our approach should reflect a commitment to perpetual improvement and staying resilient in the face of evolving challenges.