In short
Episode Summary: The Tech Leaders Podcast - Episode #112 with Darren Desmond
Overview In this episode of *The Tech Leaders Podcast*, host Gareth Davies interviews Darren Desmond, Chief Information Security Officer (CISO) at the AA (Automobile Association). The conversation delves into Desmond's unique journey from military service to cybersecurity, the challenges facing CISOs today, and the implications of AI on the cybersecurity landscape.
Key Themes
Effective Leadership in Technology
- Active Listening: Desmond emphasizes the importance of active listening as a crucial leadership skill. Engaging with team members and understanding their perspectives fosters trust and facilitates better communication.
- Team Development: He shares his experience in building a cybersecurity team from scratch at the AA, highlighting the joy of nurturing talent and seeing team members grow.
Transition from Military to Cybersecurity
- Military Background: Desmond discusses his experience in the military police, where he conducted covert operations, and how those experiences have influenced his approach to cybersecurity.
- Career Shift: After years of military service, he transitioned into cybersecurity, starting with the Atomic Weapons Establishment, which sparked his interest in IT forensics.
Cybersecurity Challenges
- Ransomware Threats: Desmond notes that ransomware remains one of the top concerns for organizations, emphasizing the need for robust cybersecurity measures.
- Asset Management: He advocates for the importance of maintaining an accurate inventory of IT assets to strengthen security postures and combat threats effectively.
The Impact of AI on Cybersecurity
- AI in Cyberattacks: Desmond warns that AI could accelerate the speed and sophistication of cyberattacks, creating an arms race between attackers and defenders.
- Defensive Strategies: He argues that organizations must invest in defensive technologies to match the evolving threats posed by AI-driven attacks.
The Future of Cybersecurity Roles
- Evolving CISO Role: The role of the CISO is changing, with responsibilities increasingly overlapping with those of CIOs, especially in organizations looking to cut costs.
- Cultural Shift: Desmond emphasizes the need for a cultural change within organizations regarding security, recognizing that it is a collective responsibility rather than a standalone function.
The AA's Adaptation in a Changing Landscape
- Electric Vehicles (EVs): As the AA adapts to the rise of electric vehicles, Desmond discusses new services being developed, including remote assistance and diagnostic capabilities.
- Future Directions: The AA is looking to evolve its services to encompass a complete journey for drivers, integrating training, maintenance, and roadside assistance.
Important Takeaways
- Cybersecurity as a Team Effort: Security should be a collective priority across all levels of an organization, involving all employees, not just the IT department.
- Investment in Training: Organizations need to prioritize employee training beyond basic compliance to create a security-aware culture.
- Asset Management is Critical: Proper IT asset management forms the foundation of an effective security posture.
- AI and Cybersecurity: While AI presents challenges in terms of security risks, it can also provide opportunities for enhancing efficiency and user experience within organizations.
Conclusion Darren Desmond's insights provide a valuable perspective on the intersection of leadership, cybersecurity, and technology. His experiences highlight the ongoing evolution of the CISO role and the critical need for organizations to proactively address cybersecurity challenges in an increasingly complex digital landscape.
Additional Resources
- For more information about the AA and their services, visit [AA Official Website](https://www.bedigitaluk.com/).
- For insights on technology investments and AI readiness strategies, check out Be Digital.
---
This episode serves as a reminder that effective cybersecurity is not just about technology; it's about culture, people, and a proactive approach to evolving threats.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00It's like an arms race. We put a mitigation in or a new piece of technology that stops a certain kind of attack. And then the attacker works out a way to go around it within six months to a year, typically, if they're really good. That's just going to get faster with the advent of AI-based technologies for the attacker. They're going to be able to do more and they're going to be able to do it faster.
0:22The AA is one of the UK's most recognizable and iconic brands. Founded in 1905, it's most recognized for roadside assistance, but has grown into so much more, providing services ranging from driving lessons with the British School of Motoring, through to insurance, secondhand cars, and much, much more. Our guest today is the CISO of the AA, Darren Desmond. His career journey is nothing short of fascinating. After a bold but unsuccessful attempt to scale the family business, Darren decided to join the military where he actually worked undercover for the military police, tracking down the likes of drug dealers and other high-risk targets.
1:07After 16 years of high-octane service, Darren decided to change careers in his mid-40s, going into cybersecurity in the private sector, culminating with him being made CISO of the AA back in 2018. In this episode, we dive into the increasing complexity of securing an enterprise organization, covering everything from ransomware, software asset management, through to building a security conscious culture through the organization. We also discuss the impact of AI on attack velocity, amongst other things, the rise of EVs and the implications of that on the AA, and also how the role of the CISO continues to rapidly evolve and where that's going.
1:52This one is a real treat. Darren is a brilliant speaker and quite clearly someone who is passionate about his craft. This is the CISO of the AA, Darren Desmond.
2:07Darren Desmond, thank you so much for coming on the Tech Leaders Podcast. How are you today in sunny Basingstoke? Fantastic, thank you. It's not so sunny today, but yeah, it's not a bad day for mid-March at all. Look, I've been really excited to talk to you. The AA is just such an institution in the UK, such a well-known brand. Security is such a big topic these days. So it's a pleasure to get you on. Thank you so much for accepting our invitation. So let's start with this one then. What does good leadership mean to you, Darren? Yeah, so it's one I was pondering on. It's an odd one. So I never aspired to be a leader.
2:40I just wanted to be a duo when I was a younger person. I joined the army fairly late in my life. And early on, I just wanted to do stuff like you do when you're a younger person. I had no real qualifications to speak of. Not that the army was a last resort, because I don't think it was. And it shouldn't be either. It's a great career. You know, that's where I ended up. And I never really had aspirations to become a leader in any way, shape or form. And I just, I wanted to enjoy myself. But as I moved through my career, I started to realize that there's lots of benefit and personal reward in teaching and leading other people.
3:08And that really became apparent once I left, actually. It wasn't so much whilst I was serving, although I used to have student investigators. I was in the special investigation branch and as a staff sergeant, which was my last rank, you tend to look after the student investigators. So nurturing and coaching those individuals sparked something for me. When I left, then I moved into a number of other roles in the cybersecurity arena. Everything from, again, doing cybersecurity investigations, threat intelligence work, and then on to managing teams, or managing an ISO 27001 environment first and certification there.
3:39But again, that involved quite a bit of matrix management. As I moved through my commercial career, I started to do more and more people management. And one of the most fun roles I've had since I left the military was in Ernst & Young, EY as it's known now, because we had quite a young dynamic team working with it. So we had quite a diverse team, actually. It was younger people and people older than me in the team. And they were great fun to be around. They're just great fun to work with, to understand their perspectives on a particular task or problem and how they would solve it. Different age groups would attack things slightly differently.
4:10And it's quite interesting to see that dynamic. Neither the younger people or the older people are right or wrong, but it's just an interesting perspective to see them solve these problems. Then when I moved on from EY, I came to the AA. When I came to the AA, I had a team of me and that was it. Just so you were the only security person in the AA. Wow, okay. Yeah, the previous team had imploded a little bit for various reasons. And we'd got a couple of contractors in, but in terms of full-time employees, it was just me. So I thought, I need to build a team here. So I went and built a team. And the more people I managed to, the more funding I managed to get more people in, it made me realize that's what I wanted to do.
4:44I wanted to take a step back from the doing and watch people grow into the roles. And I delegate like mad, right? Even now, I delegate as much work as I can to my team because you can see them flourish when they're given a task that they're not necessarily used to solving, but they're able to go and attack and solve and own it end to end that's really important for me for somebody to own an issue end to end but it's also about developing these active listening skills I never really had prior to joining the military but when I was in the special investigation branch when you're interviewing a witness or a suspect or you're investigating a serious crime now you do have to pay attention to what's being said around the room and whether it's actually a formal interview scenario or just a conversation that's taking place as part of an investigation you have to really actively listen so those skills came into their own and I think that's probably one of the most important skills for a good leader is to have active listening skills and to understand what your what your team members perspectives are on solving problems as I mentioned a moment ago.
5:37Yeah absolutely I love that obviously we ask every guest that question and a lot of the answers are great but they're very high level and they're very ideological or philosophical but that just you need you pinned it on something tangible there active listening which I think is a bit of a underrated skill shall we say active listening is so important to emotionally engage with your team, isn't it? You have to engage with your team. And active listening is a great way of doing that because they feel like they can trust you because you're listening to them and you're responding to what they're telling you, responding to what their needs are essentially, which I think is just a critical part of leadership.
6:13That's a great answer. Cheers for that, Darren. So I want to rewind you back to the beginning. I'm really keen to dig into your army experience. Can you tell us about that day you decided to go into the army. What was the stimulus for making that decision? What did you learn? What were the top sort of three lessons you learned from your time in the British military? Gosh, no, this is a bit of a long and sad story. We used to have fish and chip shops. My family business was fish and chip shops. My dad was quite an interested individual. He was into all sorts of different businesses. He had a green grocers.
6:44He's an entrepreneur. That's how we describe him these days. Yeah, but he was quite a character. But he died when he was 44 and I was 16 years old. I was thrust into running these businesses. I think we had two at this point in time. And at 16 years old, trying to run two businesses, my mother and my brother. My brother was still only 14, so he was still school age. And my mother wasn't really that interested in running them, although she did the book work and this sort of accounting stuff, all that end of it. So that's what I did until I was 23. And I tried to buy them both out. I had these grand visions of becoming a millionaire by the time I was 40 and having a chain of fish and chip shops and all this sort of stuff.
7:18That didn't really pan out for one reason or another. We didn't get on particularly well. My mum and I didn't really, I was just at an awkward age, I think. And I was, because I had these big ideas and she wanted to be a bit more cautious. We just didn't really have a great relationship at that time. It's much better now, thankfully. So anyway, I got to the point where I tried to buy them out of the business and they didn't want to do that either because I don't think they thought I'd leave. So that's when I thought I've got to go, otherwise I'm going to be stuck here forever. In what transpires is the best stone town in England, which is Stanford and Lincolnshire.
7:45But it's a beautiful place. But when you live there, you don't appreciate it. Of course. That's when I made my decision. I applied to the Army, the RAF and the Navy, actually, all at the same time. So I knew I wanted to be in the forces. And when I was a child, I wanted to be a younger person. I wanted to be a fighter pilot. My educational qualifications didn't support that. I was never going to go to university in a month of Sundays. It wouldn't have suited me. And I don't think I had the academic brain required to get the qualifications, then go on to do fighter pilot training. And looking back on it, it was the right choice.
8:11I would never have passed that training anyway. And it would have really upset me. So I applied to Army, Air Force and Navy all at the same time. and the army accepted me first. It was 1993. They were going through a big recruitment drive at the time. And they steered me towards the military police. And I had a really varied and interesting career. I worked on covert operations, running surveillance teams, running surveillance operations. We used to do test purchase, I undercover work, where we'd be buying drugs off criminals, mostly soldiers, sometimes civilians, working for the civil police.
8:39Really? Good God. Yeah, we'd get aviation assets up, so helicopters up to assist us in surveillance. We'd have motorcyclists on the surveillance team. And we do mobile and foot surveillance as well, and static surveillance and observation posts on target houses. It was really exciting stuff. Yeah, that's so great. Exactly the sort of thing I wanted to do when I was a kid. I grew up on Warlord, the comic, and the Commando comic. So it was exactly the sort of thing I wanted to do as far as I was concerned. I loved it. So then I did a couple of tours of Iraq. I'd done a couple of tours of Bosnia prior to that.
9:08Did a couple of tours in Iraq. Because I joined a bit later, I was nearing 40 years of age, and I had to make a decision really about whether I wanted to stay and do a full career. Yeah. By which point I'd have been 46 years old. at the time, certainly getting on a bit to try and start a second career. In my view, then it was anyway. My wife was serving as well, actually. We're trying to start a family, trying to make a decision about whether the stay or go. And quite a few of my friends have had children whilst serving in the military, and then they've gone on to do operational tours away for six months plus.
9:33I didn't feel I wanted to do that. And in fact, one of my friends, I rang my wife up when I was in Iraq in 2003, managed to get a satellite phone, rang her up, and one of her friend's children answered the phone, just little landlines back then. And I was so choked up because I was talking to this child. I thought there's no way I could do that if that was my child. I just missed home so much and I missed my wife. So I thought I can't do that going forward. So I decided to leave. I was trying to find something that was really fulfilling and I wasn't really getting it. As you get more progressive in rank, you do a lot more desk work, basically, in the military.
10:04It's the same as any job. I wasn't really getting what I wanted from it at that point. And yeah, I made the decision to leave. Obviously, so that shaped you, which pushed you, I'm guessing, into the security world. Tell us a little bit about the atomic weapons establishment position that you had then, and then how that ultimately ended up kickstarting a career within cybersecurity. Yeah, sure. My last few years in the special investigation branch were centred really around IT forensics. I wasn't in the IT forensics department, but almost every investigation, search and seizure we did involved technology of some kind, whether it's a PlayStation, one of those old Sony phones with a hard drive in that were on the market at the time, or indeed desktop computers, which were prolific in soldiers' accommodation, but also in the offices.
10:47So again, without going into too much detail, often we get involved in investigations where a service person, or in fact, even some MOD staff attached to service units would be doing something on their IT systems they shouldn't be doing, and we'd get involved in the investigation there. So we'd seize the device, do the forensics on it. And that's what sparked my interest in it, really. I'd had a computer for a few years, so I knew how to work a computer. but the forensic aspect really fascinated me because for me it's pure detective work literally quite binary right is the evidence is either there or it's not and if you're asking the right questions of it and it can show you what you need to know or it can't there's no in between yeah so when i left the military i applied to the atomic weapons establishment there's quite a few ex or at the time there's quite a few ex-service personnel working there largely from the RAF actually RAF police and security branch and ended up getting the job as a principal cybersecurity investigator, did some really interesting work there.
11:40But it's quite slow paced. It's government-owned, contractor-operated operation, or it certainly was at the time. And there are lots of, there's a bit of a civil service culture around it where everything's very well structured and processes are very fine-grained detailed. So therefore, it was quite slow to get things done. I don't want to say bureaucratic, because it's all there for a very good reason. But it's quite slow to get things done. So the pace of life wasn't quite what I wanted. I had a great year there. Some great people I worked with. Do you know, in terms of like military security operations, is there anything specific that you've learned from that world that you can apply to cybersecurity today?
12:13Is it just the mindset that you take over or are there tangible actions and ways of working that you've kept through your career? They're silly things, right? What I consider to be silly things and anybody else that served in the roles I serve, they consider to be obvious things. So surely you do that anyway, don't you? So it's, I was just starting to see it recently at the AIA in particular. We've got a good process in place now for dealing with incidents. And they're very good at dealing with incidents anyway. A few years ago, seven years ago, our IT systems were in need of some serious attention.
12:42And we're having lots of service outages over that period. I don't think that's a sensitive thing. It would be obvious to anybody who was a member at the time. And we've gone through a major transformation program since then. So they're in a much better spot. It's things like maintaining a log of your activities. If you're running an incident, certainly when you're doing a forensic investigation, it might go to a legal proceeding. You have to log every action you take and the decisions for taking that action. So that to me comes naturally. If I'm involved in a security incident which may result in a data breach, then I maintain my own log, my own decision log, and the reasons for making the decisions I've made.
13:14When I direct an investigation, which is what I like to do, it's my favorite thing in fact, I record the reasons for turning left or right on a particular investigation because you may end up in a court of law having to justify why you chose to take that particular action, And particularly if you're looking at volatile evidence, perhaps, without getting too techie, volatile evidence in a RAM, in RAM in a desktop computer. If you've had to take the decision to shut the computer down to preserve the evidence on the hard drive, you'll lose the evidence or any evidence in the RAM if you've not managed to recover it live.
13:41So not cutting corners, you're saying, Darren, basically, I think. If there's a process and there's a good reason for that process to exist, then follow the process. I completely understand. Yeah, that makes total sense. So you obviously moved into the corporate world then. How was that culture shift for you? Was that an eye-opener for you? Moving into Virgin Media, I think, was probably your first, or maybe you had a role before that, didn't you? Betfair, was it? But what was that culture shift like for you personally? So I'll just explain a bit more about my work in the military. And I use this term with a heavy dose of love, right?
14:14I wasn't indoctrinated in the military. One of my instructors in basic training said he's the most un-military recruit I've ever seen. Right. Why is that? I think I was a bit older. I was nearly 24 when I joined. Ah, right. And my squad was all a bit older, actually. There was only a couple of sort of 18-year-olds in my squad. You had a taste of running a business as well before going in. And, you know, a lot of squaddies haven't done that, have they? Yeah, exactly. So there's a bit of life experience there. And I wasn't as phased by some of the things as perhaps some of the younger guys and girls were.
14:40But for a large part of my career, probably three quarters of it, I didn't wear a uniform because of the roles I undertook. So I worked with civilian organizations, all sorts of different organizations, mostly law enforcement, some intelligence agencies. So I never really worked in the hardcore military, if you like. only when I was on operations in Iraq and Bosnia, as I mentioned earlier. And a little bit of time in Germany, I was in uniform. The rest of the time, I was long hair, scruffy, unshaved, all that sort of stuff. So I never really got that sort of indoctrinated, as I mentioned. So my shift to the commercial world, again, was really fortuitous.
15:09I was really lucky, and I met really great people along the way. My time at AWE was a good stepping stone into the commercial world, because I say it was government-owned, but contractor-operated. So we had a bit of both sides of the house there, a bit of commercialism, a commercial way of doing work, but also very structured and very process-driven. Yeah. For good reason, as I mentioned. And then when I moved to Betfair, that was quite a shock still, that was, even though I'd had a gentle sort of transition from the military and I was fairly civilianized anyway. So that was quite a shock to the culture because there was only about 2 ,500 people at Betfair.
15:40I think our security function as a whole was about 30 people. That was quite a large security team. But everything was so fast-paced and decisions were made on the hoof all the time. There was almost a lack of control that I was used to. I was used to being in a very rigid environment. and all of a sudden everything feels a bit fast and loose. It was a bit of a culture shock, to be honest with you. But again, I was blessed because I had a lot of really good people around me. I had two bosses at the time, which wasn't ideal, but one of my bosses was an ex-inspector from the Metropolitan Police and then he'd worked for the Serious Organised Crime Agency for a while.
16:07So we're kind of on the same mindset. We had a really good working relationship. And the people that worked, I was the lone cybersecurity investigator in the organisation, but the team, the security team worked with me and for me occasionally. So I was really fortunate. And it's, again, all down to the people. I worked with some really great people, and I was very lucky, I think. Yeah, I think, I've got to say, moving from the military to a sports betting company, that is a proper juxtaposition. It's like hardcore capitalism. You've jumped right at the deep end there, didn't you? But let's talk about the AA then.
16:37Iconic, well-known, institutional UK brand. What cybersecurity threats do you need to be mindful of when you're running security for an organization like the AA? So the key threat remains ransomware. Yeah, there's no doubt about that. You see it in all of the threat intelligence reports. Whilst that is the key threat, and I don't think that's going to change any time soon, the risks really are around people. Again, I mean that with a heavy dose of love because that's not to say the people are bad or they're doing the wrong thing. It's just that we haven't historically, and it's been the same in many other organizations I've worked in, we haven't historically invested enough in training our people.
17:15Now, that's not to say they need to be trained to be cyber ninjas, but they do need to be trained beyond basic annual training that just goes click test you've passed because that is inadequate i think i almost think that's irresponsible in fact and we've been growing that capability over the last few years to a point where this year we're hiring a security awareness and cultural change lead to actually deliver that cultural change across the organization we've built some fairly robust security technologies and we test them and configure them regularly if you're not testing your configurations on a regular basis in whatever technologies you've put in if you're not testing they do what they're supposed to do, then you're going to fail.
17:50So that's where we focus a lot of our efforts. And again, we're not perfect. We've still got a bit of a journey to go on. We're on the right track and we have that externally validated every year as well. But for the AA, really, the biggest risk is around ransomware. And that's typically allied with a significant data loss as well, a breach. Can you talk us through a specific scenario? What does ransomware mean in today's cybersecurity environment? What type of in specific situations have you seen recently, Darren? So typically, it's initiated via phishing email, but not always. Quite often, if a company hasn't nurtured, looked after and nurtured its technology from end to end, everything from front-end applications to back-end databases to the infrastructure to the network systems, everything in between, even down to firmware, if you haven't got a handle on where you are in terms of your patching cadence and your vulnerability management, then that is a real issue.
18:41And just to be really boring, a lot of that starts with an asset management approach. So if you don't know what your assets are, how on earth do you know how to protect them? So what many organizations do, and this was the case for us some years ago, you have a big spreadsheet with all of the assets listed on them, but it's really manual to update and nobody really maintains it. It's not really accurate. There'll be stuff on there that's wildly out of date. You'll have some systems that perhaps haven't been rebooted for 15 years for whatever reason. They're in a basement somewhere, unloved, forgotten about because they're not on a list.
19:10So many organizations are in that position, especially large older insurance organizations for some reason and they don't necessarily want to touch the old technology because it's still working why would you touch it you know you can't build security into a 15 year old system you have to wrap it around it and it's always a compromise yeah so there's the sort of scenarios that unfold other than the phishing ones or i'll talk through the phishing one first typically what happens is a user will receive a phish or an email with a link in it sometimes an attachment but that's less common these days it does still happen quite often a link that looks like a legitimate link and it might take you to your internal payroll portal right or what that's what it looks like it's doing so when you click on it you think you're going to the internal payroll portal what you're actually doing is going out to a server that's under the attacker's control now in the background and you won't see any of this on the screen but that server that's under the attacker's control will start communicating with your laptop and once the attacker reverses access to your laptop which is fairly rudimentary to do in a lot of cases yeah depending on what your security technologies are they take control of your laptop and they perform activities in the background that you will never see.
20:13So it could be while you're working on your device, you'll never see it. Yeah, it's crazy, isn't it? Their goal at this point is to obtain privilege, so a higher level of privilege so they can access other systems. Yeah. And what is their goal? They're stealing data, essentially, I suppose. That's the ultimate goal. But the initial goal is to steal identity and gain persistence in the organization. And this is long-tailed work, right? So this might happen over a period of six months or more yeah wow really yeah so it's that drawn out so it's not a hit it's not a hit and grab and run sort of piece it's very much embedding them and not getting detected for six months that's crazy traditionally this is what happens but i think with the advent of the dreaded ai i think we'll see this accelerating we already see a level of automation that's far and above what it was five years ago and there's attacks and we call them hands-on keyboard or hands-off keyboard attacks.
21:01And it's quite not easy. You can determine the difference between the two. Of course. This episode was brought to you by Be Digital. Be Digital support leadership teams to optimize cost and get more out of technology investments. Be Digital and the team have unrivaled expertise with technology license management and data remediation and are therefore perfectly positioned to help prepare organizations for AI technology capability. And on the last point, BDigital have just developed a cutting edge AI readiness assessment, which provides tech leaders with a platform they need to make well-informed decisions about AI adoption strategy in 2024 and beyond.
21:46Go to BDigitalUK.com to find out more and get in touch.
21:54I'm keen to talk about visibility of software assets and mitigating security risks within your estate essentially or software product estate so we are an asset management consultancy firm and we see a lot of organizations who have shadow IT and unmanaged assets and it really impacts this, a security posture, essentially. So what can CISOs do to address that? How can CISOs get full control over their software estate? What advice would you give to CISOs basically on this matter? Yeah, first of all, have that aspiration to gain full control over everything, because I think it is an aspiration for many organizations, unless you're in a particularly sensitive sector like tier one finance sector, bank or something like that, or obviously the MOD or defense in general so have that aspiration to gain visibility over everything and be confident what's on your network and what is there and then it's about observability so the first part really is asset management gain visibility of what you've got and the second part is observability over what is that stuff you've got doing and what's it talking to i'll give you some examples i won't talk about specific technologies but we have a micro segmentation platform at the aa and it's designed to stop or limit lateral movement and it makes it much harder for the attacker to move around undetected.
Read the full transcript
23:08And again, it's not foolproof. We're not perfect, but it's a good bit of kit. We've been trying to get better asset management since I joined. When we started, it was on a spreadsheet. It was partially true. We've invested quite heavily in specific technologies to get better asset management. And what we found is you have to pull data from multiple sources. Running a discovery scan on your network isn't necessarily going to give you everything. It might give you most of it. It won't tell you what this stuff's talking to though. so the micro segmentation platform we brought in once we started running that discovery tool it was very different technology but started filling in a lot of gaps in terms of what our assets were and what they were doing so what they were talking to and you know this is when you start seeing communications are a bit odd you start seeing communications that are talking to the Tor network the onion router network which is typically used for dark web file sharing or nefarious activities yeah or dark web yeah people refer to as dark web you start seeing occasionally that where an agent's been installed something years ago by an employer that employee rather they really didn't know what they were doing perhaps might be malicious who knows so you can start to take that down and prevent that from egressing the organization obviously you can do this at the firewall as well but it's there's multiple places you can do it you also start seeing communications you don't expect with that servers in universities in all over the world and you can start limiting your attack surface effectively in terms of what your systems are talking to and limit them to the business systems they should be talking to and isolating them much more effectively.
24:30So obviously that's all great. And on top of that, we do vulnerability scanning every month. We do penetration testing. We do red teaming. We do purple team. We do lots of stuff. But you need a way to aggregate that view. And if you haven't got a good asset management approach, you're not going to be able to centralize all of that data and then make informed decisions. So getting across asset management is absolutely vital and underpinning. It's central to everything, isn't it? You can't get secure without asset management being in place and being effective. Yeah. No, very well said. How does AI change this, Darren?
24:59I don't think it changes it vastly. I think it changes the velocity of an attack. But equally, if we as an industry get on the front foot with this, we can change the velocity of the defense as well to match it. And that's always been the case, right? It's like an arms race. We put a mitigation in or a new piece of technology that stops a certain kind of attack. And then the attacker works out a way to go around it within six months to a year, typically, if they're really good. That's just going to get faster with the advent of AI-based technologies for the attacker. They're going to be able to do more and they're going to be able to do it faster.
25:27So similarly, as an organization, you're going to have to be able to do more and do it faster. So really, it's about investing in the right types of defensive technology to match the threat. So if you've done a decent threat assessment on your organization and against your assets, because you now know your assets because you've got good asset management, you do a threat assessment against those crown jewels, as it were, and then you move your defensive posture accordingly. You orient it towards a threat. I think trying to put the castle and moat model up from years ago, I think that idea is long gone now.
25:56I don't know how that would work in a modern environment. Yeah, absolutely. So what's the biggest challenge you faced at AA, Darren, since you've been there from a cybersecurity standpoint? So there's a number, but the biggest one is people. Can you just unpack that? When you say people, do you mean the skills shortage, not having people suitably trained and qualified? Okay. People generally. Oh, right. Okay. And again, this is the dollop of love. So historically, the AA had been under-invested in, and our share price wasn't doing very well. for various reasons, the IT function as a whole have been cut to the quick.
26:27And that included the security function, as I mentioned, that it was tiny when I first joined. And the tooling was badly thought out, badly deployed, wasn't really doing much, apart from consuming power. So the biggest challenge was articulating that security is not a standalone activity to my colleagues, my peers, the board, the exec, and everybody in between. Security is not a standalone activity. You don't just get a security guy and they come and fix all the stuff. It's a team effort across the board. whether it's the lady on the front desk looking after reception we've had a couple of ladies that have been with us for decades looking after front reception in basingstoke for example and they're literally the gatekeepers of the building whether it's somebody on the front desk or whether it's somebody who's an administrator on a really sensitive system it's a team effort so it's about having policies and standards that reflect reality so they're not just downloaded off the internet replace this company with that company and push your policies out get certification you're off to the races it's not about that it's about ensuring that the policies and standards you create or articulate in a way that your end users can understand and if they're not reading them and don't understand them then you failed from the outset you're not going to get secure in any way shape or form so it's about communicating those standards engaging with the stakeholders at all levels in the business so that this is a security standard these are mandatory and this is what i expect of you and then testing that so this is where frameworks really come into play so we were iso 27001 certified it doesn't necessarily mean we're secure okay because compliance does not equal security as anybody who works in this field will tell you what it's about though it's about getting people used to producing evidence that they are doing the right thing on a regular basis that's where the real value comes in and probably even the iso people tell you that so we run a number of different standards for very good business reasons across different parts of the company and that's helped change the security culture as much as anything but we've almost and this is why i say the biggest challenge is people it's not because they're bad at what they do or they're doing the wrong thing necessarily or with the wrong intent, should I say.
28:17They've just not been told what's right. And it's very difficult to do that when you've got a project that's finite in terms of resources and time. And then you've got to add security into the mix as well. And they just, I think, users expect security to be built in regardless of any effort they put into it. And that's the sort of culture we're trying to change. And we're a good way down the road there with certain parts of the business. Some parts got a bit catching up to do. But the people element is critical. And I think organizations pay lip service, to be honest. Yeah, I see what you mean.
28:45Do you know what? The biggest culture shifting instances will be when it's happened to them personally, when their identity has been stolen, when they've been involved in a security attack. And I think, unfortunately, people often don't shift their behavior until they have to. We've had quite a few going on, like whenever we had a new starter the other day working for us, within a day of them being here, they had an email from someone impersonating RMD from a totally different email address. They didn't try to, it was a hotmail account or something, but the name said the MD's name. And we've been having this for years.
29:19A couple of people have fallen for it in the past. So it's little ones like that, obviously through to the big ones that like what you're talking about. So look, AA, when you ask anyone in the street, what are the AA famous for? Most people will say, picking me up on the side of the road when I got a flat tire or when I got a problem with the engine. Obviously, the proliferation of EVs, they're increasingly becoming more ubiquitous, aren't they? They're sort of all over the place. How is AA going to evolve and change? Because there's going to be less roadside assistance inevitably. It's all software now.
29:51The roadside assistance can be done remotely a lot of the time, can't it? But how has the AA shifted in terms of its services and products? So we've made quite a shift over the last few years, actually. As the EV proposal has become more of a realistic prospect, A significant number of our patrol vans are now electric. We've got a flatbed recovery vehicle that's electric, fully electric. It's a beautiful piece of kit as well if you're into your HTVs, but it's a gorgeous piece of machinery. Most of our technicians, if not all of them, are trained on how to deal with EV issues now as part of their standard training for roadside recovery.
30:22So all this sort of frontline stuff is already in flight. We've adapted our vehicles and also our systems to deal specifically with EV issues, so we can tow an EV if needed. Battery run out, I bet that's a big one. it's getting less though it's getting less and less common i think in the early days when we first started adopting as a nation perhaps four or five years ago we saw a lot of that but it's almost matching fuel run out pickups now how do they deal with that by the way do they have like a little sort of generator in the back to plug it in to give it a mile or two some of the vehicles i've built in battery packs which can you know give you a surge into your electric vehicle to get you to the next charging station yeah okay because i've got an ev and it's not quite happened to me yet, but I've been pretty close.
31:03We've got dedicated systems in the vehicles now for dealing specifically with EVs. So we made the move quite early. It's not the first time we've looked at electric vehicles as an option for our patrols either. We had electric scooters in around London for a few years in the 90s, late 90s it was. So it's not a new proposition to the AA and we've just adapted our previous experiences to suit the modern EV landscape. And it's evolving at pace but we've also built a product now that covers end the driver's journey end to end so if you look at we've got driving school we run bsm and aa driving schools right we've got the driving schools pick up users right at the very start of the driving journey we have a company called prestige that we own that we do service maintenance repair for fleet vehicles yeah which nowadays includes a lot of evs so we've had to make that adaptation quite quickly we run a company called drive tech as well which does a lot of driver training so including the speed awareness courses that you may be familiar with.
31:54I've done a few. Unfortunately, yes. Yeah, I think we've all been there. Well, in Wales, it's 20 mile an hour. So yeah, it's particularly bad. Yeah, I ride a motorcycle and I've ridden through Wales since that has been put in. So yeah, so we've got a number of different diverse businesses and I hope I haven't missed any. AA Cars, we sell second-hand cars via the AA Cars website. So our business runs really, what we're trying to do is we cover the end-to-end journey from the cradle to the grave for driver's experience, obviously the roadside recovery built in there. And also smart breakdowns another initiative we launched a couple of years ago.
32:25And that's really to help diagnose modern vehicles over the phone, as you mentioned a moment ago, remotely. So we can do a fix over the phone rather than the driver and the wait for a patrol to come out to fix the problem. I think as we're able to ingest more data from the vehicles, then we're going to be able to do those sort of remote fixes more and more frequently. So as you say, the battery dying or running out of juice is still a problem, but it's less of a problem than it was a few years ago. And it almost equals the amount of fuel, traditional fuel run-out calls we have. What is your thoughts on maybe we can get the crystal ball out at this point and sort of say what what do you think about evs is it going to kill combustion engine cars in the medium term do you think we're on that trajectory or do you think there's going to be a split for quite a quite some time to come what's your thoughts i don't think evs are the answer and this is controversial because i think our organization i've heard a lot of people say that pushing ev as there is this sort of the nirvana of motoring but the thing is a lot of these companies now looking at hydrogen based engines other hybrid engines I know there was a biofuel engine that Porsche were looking at some time ago they were developing the biofuel specifically and they were going to scale the factories if it worked so I don't know where that got to because I've touched the story but so I think hybrid is the future without a doubt I have a traditional combustion engine car right and my wife and I have a car each I've got a motorcycle as well so I'm a big fan of internal combustion engines despite the sort of the impact of the environment I appreciate it's not great for that but I love the sound of an engine like I say I'm a lifelong motorcyclist so I'm probably never going to give that up And I've tried electric bikes.
33:51They don't quite do it for me. It's not the same, is it? No, it's not the same. But I genuinely think hybrid is the way forward. And I think that's probably where government should be averting their gaze instead of trying to force everybody in. I don't think that's practical for a lot of people. If you live in a block of flats, how are you going to plug your vehicle and all that sort of stuff? I don't think it's been fully thought through. And this is just a personal opinion. We're not that other company, obviously. But so I think that for me, that's where it will go. And if I were to invest in a new vehicle, I would probably buy a hybrid rather than a pure EV.
34:17No, that makes sense. I've got to ask you about just in that crossroads between EVs and cybersecurity. I've read some dystopian article before about the prospect of bad actors hacking into EVs and causing cars to drive off the side of a bridge or whatever, unbeknown to the driver. Obviously, we're potentially moving into an era now of driverless cars. Do you have security concerns about EV, the software-run cars at all? Have you got any thoughts on that? Every new technology we adopt, right, and going back to AI, it's the same there. We have rapid adoption and uptake of a new technology and the security controls and the data privacy controls in some respects often left as an afterthought.
35:00We saw the same with blockchain and cryptocurrencies, which is why you still see big cryptocurrency heists. We saw the same with cloud adoption some sort of 15, 20 years ago. They rushed into deploying the new technology with little thought for data privacy or security. I think it's been the same with modern connected vehicles. and I don't just limit that to EVs, but my Mini is eight years old and I can still connect to the internet via the in-vehicle system. So I think we've probably rushed into it without really considering the longer-term impacts, as I say. I say longer-term impacts specifically mean around security.
35:32So I think it's a reality, that could come to reality of somebody taking control of a vehicle remotely. If it's not already happened, I haven't seen a report of that. It wouldn't surprise me if it's not already happened in a lab somewhere. Yeah, it was more someone writing about the prospect of it happening than reporting on a specific incident. But if software is hackable everywhere, isn't it? It's possible, I suppose. I did a presentation a few years ago at the Space Center in Harwell, and we were talking about hacking satellites then. Now, if you think, everything's connected right these days.
36:01So a satellite's only 200 miles above Earth orbit. It's only 200 miles away. But hackers can hack systems all the way around the world. You can be anywhere in the world. If you're connected, you can get to anything. The concept of hacking a satellite is pretty simple, really. When I played that scenario back to the audience, they were aghast. They were shocked at the prospect of it. They hadn't really thought about security being built into the communications of the satellite. Yeah, absolutely. So the same is true of modern connected vehicles. It's a bit of an afterthought. I suspect it's catching up now.
36:29I'm not too close to it. I suspect it's catching up. But again, when you look back over the last 10, 15 years, and you can see we've not really resolved the issue of security on traditional IT systems, let alone a system that might appear in a modern connected car. it's entirely possible that will become a reality. How has it evolved in the last couple of years since you've become the CISO of AA? And how do you see it evolving over the next five years as the security landscape obviously becomes more complex? Yeah, so it's a strange one because I've been talking to quite a few different people about this recently because the job market for CISOs seems to have dried up over the last 18 months.
37:04And it's almost as though the technology that enables security in many organizations has got to the point where organizations don't necessarily feel they need a CISO to deploy the security strategy, to look after the team, to help with testing and configuration, as I mentioned before, to drive the security strategy. And a lot of CIOs have picked that up as a second hat in their role. So the job market for CISOs seems to have dried up over the last, say, 18 months. And I think the reality is it's commercially driven. So you might have a CISO who's got a head of, say, a head of InfoSec and a head of SecOps with him, and maybe even a head of physical security reporting into him.
37:38And in order to cut costs, what a lot of organizations are doing, get rid of the CISO role, pass responsibilities directly to the next level down. And that seems to be the norm at the moment. So there are a lot of really good CISOs who are currently between roles because of that. Yeah. Which is quite interesting because, you know, a few years ago we had this huge challenge of ransomware knocking companies over left, right and center. That's not gone away. In fact, it's still getting worse. Yeah. We've not solved that problem. But the minute the financial crisis bites, the first people they seem to get rid of are the security leaders and organizations.
38:06So it's a difficult one to predict where it's going to go. And I think it will come full circle. I think we'll see an evolution of ransomware and it probably will be driven by AI. These technology leaders will need specialists to look at implementing a strategy. Now, for me, employing good basic cyber hygiene is the starting point of controlling any technology, whether it's, as I said before, blockchain, whether it's AI, whether it's cloud security. You have to have a good level of basic hygiene across the board. We talked about zero trust in the security industry for some years. We still haven't really achieved it.
38:36I think it's a nice concept. It's very difficult to implement. Until we get to a point where that is genuinely implemented, we're always going to have gaps in our security attack surface. So I don't think the role of the CISO will go away anytime soon. But again, we've seen it evolve from a technology leader to more of a business leader in the last few years. And I think a lot of forward-thinking businesses get that. They understand that security needs to be part of their strategy to win new contracts, to maintain existing contracts, to demonstrate due diligence to a financial regulator, for example.
39:03And I think as we see the next few years unravel, I suspect a lot of these regulators will mandate the role of CISO in many organizations, much in the same way the Information Commissioner mandated the role of a data privacy officer in organizations, even though they're sometimes double or triple-hatted. I suspect that's the way it'll go, because a lot of companies are going to end up in court because they haven't taken the appropriate due diligence on the security front, and that has resulted in a big data breach and loss of revenue for the organization, particularly enlisted companies. So I think that's the way it's going to go.
39:32It's a bit of a strange time at the moment, for CISOs. Yeah, I just assumed that CISOs had become, it used to be like in addition to the CTO type thing, you'd have a CISO as almost like a periphery job title. But now the CISO has almost become the CTO, if that makes sense. Security is so central. So I hadn't looked at it the way you framed it there. But yeah, I thought security has just become mainstream. Therefore, CISOs are CTOs nowadays, or the CIO. But yeah, it's an interesting one. And to add to that, I think we'll probably see, because of this, it's almost drying up of the market a little bit at the moment.
40:06I think you'll see a lot of CISOs move to CIO roles because they tend to be quite technology-focused, technically competent. I think you'll start to see a lot of CISOs move into those CIO roles where they have those skills. Yeah, absolutely. No, I agree. Let's talk about AI very quickly then. It's a double question. What are you most fearful of, okay? And what are you most excited about in relation to AI? It doesn't have to be about cyber, just in general societal and business impact of artificial intelligence, large language models, generative AI, whatever. But what are you most fearful of? What are you most excited about?
40:38I don't know if I'm fearful of it, really, because it's been around since 1954 in one aspect, one format or another. So it's been around a long time, and it's not. We haven't seen the rise of the Terminators yet. Skynet is coming, Darren, but not quite yet. It possibly is, yeah. So I think, what am I fearful? I think my biggest fear is around the poisoning of data. So there's a number of different specific AI controls you can apply to control your AI and large language model environment. One of the key aspects of that is protecting the data source that the AI relies on. If you put incorrect data in a large language model, the AI will spit that data out as though it's the truth, regardless of how good the AI is.
41:16So unless you have human intervention or some level of checking in there, you're not really going to know if that's right or not. So protecting the data source, I think, is probably the priority action we need to take if we're deploying LLMs anywhere. And again, that comes down to basic cyber hygiene, right? So it's security in the software development lifecycle for the AA and the LLM. It's protecting the infrastructure, so it's vulnerability management for the infrastructure. It's knowing what talks to that infrastructure. So again, it's your asset management piece. It's all of those basic cyber hygiene activities I mentioned earlier.
41:44And if you look at a fairly typical model to adopt is NIST's cybersecurity framework. If you apply all of those controls consistently to a mature level across all of your organization, then you're going to be in a pretty good spot. you're going to reduce the risk of data exfiltration. You're going to reduce the risk of a vulnerability being exploited on your LLM infrastructure. You're going to reduce the risk of that data being poisoned. And having observability, going back to detection response capabilities, which again is part of the NIST model, if you have that capability in place, then again you're going to minimize the risk of an event becoming a data breach or a significant security incident.
42:16So whilst I am concerned about data poisoning, I think if you apply the controls consistently across your organization and test them regularly, ensure the configurations remain consistent. I think the fear factor is fairly low, let's say. Yeah, that's really good. What are you most excited about then? So I'm most excited about the opportunities it brings for users, really. I'll give you an example. These are fairly low-level activities, right, or use cases that I'm talking about here. I mentioned earlier about people being somewhat of a challenge for security folk because most of them find security quite dull.
42:47And again, it can be quite a dry topic, but I love it. I find it fascinating, but I've worked in some fascinating parts of security such as forensics and threat intelligence. I love that side of it. But the reality is we need to build a tool that enables our colleagues to be able to get access to the information they need really quickly in the context that they need it as well. And that's not always possible from a PDF standard or a database or a, God forbid, an Excel spreadsheet. But you can do it from an AI chatbot. You can ask the chatbot the question, given this system serves this customer, this data, and it's under this regulatory regime, what control should I apply for identity access management?
43:21and it will tell you in simple language, you know, you're able to go, okay, I get that now. Whereas at the moment, we have a set of security standards that are quite technical. You know, they're appropriate, but they're quite technical. They're not very user-friendly. So for me, creating that user-friendly face of different aspects of the business, not just security, but any aspect, contact centers, people call in whether they're vulnerable customers perhaps and they've got specific needs, but some of the information they need can be generated by an AI chatbot. Again, you've got to protect that data, make sure it's appropriate, have a level of human checking, between the data and the customer.
43:53And I think that's where it'll add the most value. And obviously automation is slightly different. Robotic process automation has been around for some time as well. We use it to great effect in the AA. The level of automation that I think we can achieve using AI is very exciting. I think that will come with cost efficiencies and possibly replacing some roles, which I think is inevitable. But again, as we say at the AA, we can move people onto more interesting tasks. And again, that's true. Nobody wants to be moving spreadsheets around all day. I think if we can replace that boring activity with something a bit better, then that's better for everybody.
44:19Yeah. Do you have fears with jobs displacement, Darren? Do you think, I know every technology innovation in the past, the roles have just been upgraded to more sophisticated roles and the machines have done the legwork. But now, is this different? I think it will be in the future. I think we're a little way away from that though, because as I mentioned a moment ago, you're still going to need a human intervention to check the data's correct. I think what it will do, it'll increase efficiencies in people's days. Yeah, of course. So they could probably do more of the same type of work. But like I say, make it a bit more interesting for them because nobody wants to be pushing data around.
44:51So I don't think that's an immediate concern, certainly not for us. I think it is inevitable, though, in the long term, there will be some displacement of roles. But I think it will be those very manual, tedious tasks that people probably aren't getting that much satisfaction from anyway. Yeah, sure. So let's finish on this one then, Darren. You're in your armchair with your cigar. I know you ain't done yet, but you've got a while to go in your career. But looking back now on your career, that 24-year-old who joined the Army, me, I think you said you were, what would you say to that guy? What advice would you give to your 24-year-old self?
45:24Gosh, so I was quite an excitable young man, and I was always chasing the bigger, better prize, not necessarily from a financial perspective, but I always wanted to be the guy jumping out of the helicopter with a dagger between his teeth all the time. I didn't do that, by the way. That's what I wanted to do. Darren Rambo Desmond. Exactly. When you're a young man, I think that's fairly natural, right, to go after that. Oh, absolutely it is, yeah. But it's about focusing on the goal not necessarily how you get there i think and this is probably counter to what a lot of people say because i was never clear on what my goal was ever i was just enjoying the ride and i did enjoy the ride very much so but that has caused compromises later on in life so i guess it's pick a goal and try and work towards it and if it doesn't work out but don't fear that just pick another yeah sure but at least have one goal to steer towards and i think that's probably the best advice i could give my younger self because i was like a dog with a bone a lot of the time and I'd just be running around enjoying life, which is great.
46:16It's a great thing to, I'm very happy with what I've done and where I am now, but I just wish I'd been a bit more structured and perhaps a bit mature in my thinking. I was quite a mature young man, so that's perhaps the best advice I could give myself. You're definitely not the only one, Darren. And don't give up on that dream of owning multiple chippies either. It's never too late, okay? Well, look, it's been a pleasure, Darren. I've learned a lot in this conversation. I'm sure the listeners have too, and it's been a real, it's been great fun. So yeah, thanks for coming on the Tech Leaders Podcast.
46:45No problem. Thanks for having me. I really appreciate it.
46:51That was a fantastic conversation. I really enjoyed that. We've had plenty of CISOs and security experts on the podcast over the years, but few speak about cyber with as much passion and clarity as Darren. There were so many takeaways, but I think the key takeaway for me was the critical role of understanding your software estate and maintaining strong IT asset management practices, it's surprising how many organizations still overlook this. As Darren said, if you get your ITAM right, it forms the backbone of a solid security posture, turning security from a constant firefight into a foundation for innovation, growth, and just more progressive endeavors, which I completely agree with.
47:38I hope you enjoyed this episode. If you did, please subscribe, leave a review, and don't forget to connect with us on social media. It really helps us reach more people and bring you more amazing guests like Darren. Thank you so much for listening.
47:58This episode was brought to you by Be Digital. Be Digital support leadership teams to optimize cost and get more out of technology investments. BDigital and the team have unrivaled expertise with technology license management and data remediation and are therefore perfectly positioned to help prepare organizations for AI technology capability. And on the last point, BDigital have developed a cutting-edge AI readiness assessment, which provides tech leaders with a platform they need to make well-informed decisions about AI adoption strategy in 2024 and beyond. Go to Be Digital UK to find out more and get in touch.
From the publisher
“I had a team of me…and that was it!”
Join us this week on The Tech Leaders Podcast, where Gareth Davies sits down with Darren Desmond, CISO at the AA, to discuss how AI will change the Cyber Security arms race, why it’s a strange time for CISOs, and how he was the most un-military recruit his training Sergeant had ever seen…
Time stamps:
- What makes effective leadership in tech? (2:32)
- Starting from scratch: "I had a team of me... and that was it!" (4:20)
- Lessons from the Army and Atomic Weapons Establishment (6:20)
- The Betfair culture shock: "Decisions made on the hoof" (15:20)
- The key cybersecurity threat: Why ransomware remains a top concern (16:50)
- How asset management strengthens cybersecurity (18:10)
- CISO advice: Why asset management is critical for security (22:17)
- The CyberSec arms race: How AI will change the game (24:58)
- Why security is a team effort, not a standalone activity (26:00)
- Ransomware evolution: "The risk of AI-driven attacks" (36:45)
- AI in cybersecurity: The future, risks, and opportunities (40:20)
- Career advice: "Pick a goal and work towards it" (45:06)
