Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
August 30, 2022
Earnings Call Speaker Segments
Jason Spindlow
executiveThank you all for joining today. My name is Jason Spindlow, and so we'll be talking about the endpoint of no return. So reasons why we need to look at upgrading our endpoint protection or your endpoint protection out there in the [indiscernible]world of cybersecurity. I think we've just had a message coming through that it could be a [ sip a cup of coffee get ready ] and sitting for the next half hour or so, and then we'll shift into another part of the discussion. So today, that discussion is going to include a little bit of points around the limitations that we find in our legacy end point, we're also going to look at how you can shift into a modern approach with cybersecurity and securing your endpoints and also, I think, a broader perspective of your environment as well. How that translates into what Palo Alto Networks does with Cortex XDR for endpoints. And then we're going to shift into a bit of an analysis of some of the attacks that we've seen in the world over the last few months or so. And then we've got some Q&A at the very end at that point as well after we've put that Q&A in, we'll actually shift into a discussion with our CTO, [ Lynn ] and one of our incident responders, Vicky to talk about what the current threat landscape and one of the Unit 42 incidence response report that we've released just recently as well. So without further ado, let's get into it. If you have questions as we go along, please write them into the Q&A box. We will answer those when we get to that Q&A section or afterwards. And if we can't get to you in this time, we'll certainly respond back afterwards as well. So a couple of these percentages and numbers here, these are from the Ponemon's State of Endpoint Security Risk Report that was released. And you can see here that -- it's talking about endpoints being an easy target with the frequency of the types, the effectiveness of the attack on an end point. So with the 68% there for frequency, you can see we're talking about the amount of organizations that experienced something in the forms of an endpoint attack, and we're actually talking to what has successfully compromised data within their infrastructure, be it cloud or on-prem or wherever. The types of attacks that we're seeing, 81%, so a lot of the businesses that we're seeing looking at some type of a malware attack, ransomware being a really big part of that. In fact, if we relate this back to the notifiable data breach reports from the office of the Australian Information Commissioner, we actually see that they talk within there that of all the incidents, 464 of those notifications of breaches that occurred between July to December last year, 37% of all the breaches were from a cybersecurity incident, and 23% of that was from ransomware on its own. So there's a lot of different activity that's occurring. And a lot of that is coming up into either ransomware or only 3% was malware in fact. A lot of the rest of it was actually using stolen credentials for accessing environment and moving largely. But there's a lot of different types of attacks that occur there. And the effectiveness, well, we see that 51% of those attacks were pretty effective. The attacks weren't stopped because the security solutions that we're using on the endpoint weren't as effective as they could have been. And they weren't detecting when they couldn't prevent, and that's one of the big things we're going to talk to today. So the problem. We know that legacy endpoint has failed. The way that we look at definition files on an endpoint, just doesn't work anymore. There's more threats coming through on a daily basis that we have never seen -- and so a DAT file or a definition list is only as good as the information that was in it, unfortunately, with the majority of those threats never actually seen again. So it's just hard to keep up on that. And then also the type of effort that sits on to the endpoint scanning for those files that are never seen through what is existing on the endpoint itself, it just hits the resources on those systems as well. We talk about burdening there. And we see the solid endpoint tools, the complexity. This is the enemy of all security people and teams and any team within the IT teams actually. The more tools you have, the more layers you have, the more difficult it is to respond to be able to group all your alerts together and reply on it in an effective way. And that's what we see here. It's just becoming too complex. And speaking of alerts, we hit that alert fatigue. So there's not so much a singular solution for us to be able to respond to with these legacy solutions. There's too many of these alerts. And unfortunately, a lot of those are false positives that come through and we can see here creating distractions and causing our investigations to be slower than what they should be. So that's the bit of the problem. Now, when we look at the solutions that are available today, you can see over on the far left-hand side there, we've got antivirus. This is that legacy AV, we talked about. We've got our database of node signatures, our hash file and our list of hashes, and then we saw that shift into next-generation AV, I like to think of this as Phase 2, where we tried to get a bit stronger. We were looking at those attacks that weren't known. We started to look at machine learning, looking at file attributes to understand where a threat was potentially coming from and then we shifted into the broader EPP platform. So what else can we add in there? Is there a firewall on the endpoint? Are we looking at disk encryption or USB device control, all those types of things. And they're one part, you still need the prevention piece, but you also need to shift into the detection and response side. So we see the modern solutions. And even then we see EDR, where it was and where it was great a couple of years ago, we've really seen that shift into extended detection and response. We need to be performing analytics on things outside of just the endpoint, and attack never just occurs on the endpoint. There is always something else within your environment that is going to help you add to your investigation and analysis of that threat. So this little statement here. We can see from Forrester report, State of SecOps in 2021. So 2/3 of security teams still rely on legacy endpoint security solutions, as scary the ones that we talk to on a daily basis that are still using old antivirus tools and expecting that to be effective for them. It is limiting how they got to that reach endpoint data. And that's going to stop them from doing their detection and response as best as they can with the additional data and information that will come from both the endpoint and the network and sets as well from different security tools. So we go and talk to a couple of these. The limitations of legacy endpoint. We know that, that is hash-based scanning for known virus signatures. There's a lot of false positives, a lot of missed threats within that, performance gets hit, like we talked about. I'm scanning my entire file system with -- from a database of hashes to see what they are. I'm trying to run that at a lunch time. But unfortunately, what we've seen with 1 gig plus size definition files these days for legacy AV solutions, it takes a lot longer than a half hour or hour long lunch break for you to scan a system. They update the software, the definition files, pulling those down. It's got to be a daily thing to try and keep up with it, but we know that's just not the case. And then those security gaps. I've got to fill those with other tools. Again, more panes of glass for me to be looking at to try and respond to an incident when one occurs. And looking at it from a reactive perspective as well instead of more so proactive. And then the deployment and management, a lot of these legacy AVs are very big in size and trying to get those installed out on to endpoint as well is quite difficult as well as the uninstallation of those systems and applications as well. So how can we stop today's advanced threats. Very good question. Glad you asked it. You've got me. -- [indiscernible] endpoint threat prevention that we recommend and look at. We need to look at -- these things are just some of the subset of the threats that you need to look at. But from a prevention perspective, a lot of these will be covered within that bubble of prevention. So you can see malware, malicious files, imminent threats, zero-day attacks, you can see phishing ransomware, fileless attacks and exploits. All these things need to be covered by prevention first. And if missed, then we shift into what we talk about with our extended detection and response side. So what we see today with endpoint protection requirements to be modern and protect against the issues we have, that constantly evolving cybersecurity threat landscape is Next-gen AV, absolutely, we still need that from a prevention perspective. And you can see on this slide here, we've got behavioral protection. What am I seeing from an application doing something, which maybe it's never been seen before, it's not classified as a threat as machine learning hasn't detected a pre-execution phase that this is malicious. But I'm now seeing behavior that is telling me that, that file is doing something malicious. That's where we start talking behavioral protection. Any artificial intelligence, machine learning to understand what it's trying to do and respond or push that back out to one of the analysts to understand what's happening. Plus the traditional side of blocking the malware and exploits, and even fileless attacks sit within that next-gen AV piece. There is always something part of a fileless attack. There never no such thing as a 100% fileless attack. We then shifted that endpoint protection capability. So these components pretty important to we know we need that host firewall and the endpoint to control our network traffic. Disk encryption, if you're not getting or being able to control the encryption for your endpoints from within your platform, you're missing out, and then your device control, what systems are being connected through your buses on to your systems? How can you protect and block those from pushing anything bad into the environment. And then that deployment and management. A lot of organizations we see today are shifting in to cloud management. Yes, there will be some outliers to that. But a lot of what we see is managing it up in the cloud and still having agents sitting on endpoint is the way to go from pushing out in management side without having to have additional resources within your environment. You can see down there, there are no signatures. We don't require scanning or reboots. That's some key requirements for the endpoint side of things from any agent you're sitting on because you don't want to have to sit there and reboot a server through a new agent installation. You don't want to have to wait for signatures to get downloaded to scan the system to star with before you secure -- you want to be secure or as secure as physically or humanly possible by the time you finish installing that package. And so we started talking about a couple of these things with making sure we've got firewalling on the endpoint, but also things like network packet inspection into the endpoint itself as well. And you can see here, we've got this comprehensive endpoint protection. So this is all, we're now talking about Cortex XDR. This is all what is occurring on the agent itself. So understand that we can do reconnaissance protection, looking for exploit kits trying to analyze the system for vulnerabilities. The packet inspection. We're actually using FIDs from the next-generation firewalls to help build out what we do to identify attacks from a network perspective coming from the -- or going through the endpoint and stop up in its tracks. You can see the exploit prevention techniques. So we don't do the old virtual patching where you're having to try and sit there and scan the system for what patches aren't installed. We're actually looking at that through a very smart way and actually using exploit techniques and understanding that there's only about 30 or so of those out there, and we provide the protection modules against those. Where generally, you've got to have 3 or 4 of those exploits hitting a vulnerability to allow you through to the underlying operating system to help spread laterally. So we cover a whole heap of those instead of looking at that virtual patch side of things. And then you can see the threat intelligence piece, WildFire. If you know Palo Alto Networks and the next-generation firewalls, we've got the WildFire component of that, which is our online sandboxing or even on-prem, that allows you to run a file within that sandbox either through -- on a virtualized system or we've got our hyper-virtualized bare metal analysis engines as well that will scan those. So we're not running in a lot of malware, it knows about virtualization and sandboxing now. So we do that as well to provide deeper analysis in. And then you can see -- and all that information gets passed back through to the firewall to the endpoint, which is a really key part, with those things start working in unison in regards to what's being picked up from one and sent to the other to help prevent that from coming through again the next time. And then we've got the local analysis we talked about, file attributes. If I see the majority of these attributes within this file look malicious, I'm going to mark that as malicious and block it. Or I'm going to send it up into the sandbox or cloud-based analysis for deeper analysis. We can see the script-based threats that we're stopping through the malicious process prevention, ransomware protection. So we're blocking ransomware either through decoy files or seeing the steps that are being taken from a behavioral perspective to stop that ransomware in its tracks, as well as things like being able to utilize something like volume shadow copies. If they haven't been deleted, we know the majority of ransomware attackers or users out there tend to delete the volume shadow copies first. We can revert through if they haven't done that through that as well, all through our remediation actions or suggestions within the platform. And I started talking about behavioral threat protection here. You can see this is the key part of. I see suspicious behavior. You've got the old [indiscernible] class is there and the eyebrows and [ we moustache there ] to pretend it is somebody else, but we can see the activity that's going on and start to analyze that and stop the threat in its tracks, break that chain, that link in the chain. Now what we're going to do is break one of those links to break the chain of the attack. We talked about the device control disk encryption firewall. All of these, again, included within XDR Prevent as well as XDR Pro, which is the full extended detection response arm of what we provide. The local analysis, yes, and obviously, all that behavioral threat protection as well. So I think I've said this a couple of times already, but I will reemphasize it because sometimes we need that in our brains. No one can prevent 100% of cyber attacks. And what we have to do is look at the detection and response side because it's so critical to how we look at and respond to cyber attacks, especially the ones that we've never seen before. And that's unfortunately where the majority of them sit these days. So how are we looking at that? So you can see here, we've got how we respond and detect those to those invasive threats. We want to first detect accurately. We want to look at using AI and machine learning. We've got the behavioral analytics. So it's understanding each step in a causality chain, what started within maybe outlook, it's an e-mail that's come through with a link in it. The link is telling you to click out to online somewhere to download a file. We're capturing all that information about the steps within that causality chain to understand the flow of processes to the outcome being it stopped or not stopped because of that, no such thing as 100% prevention, but detecting and being able to respond or remediate based on the information that we're collecting from the end points. And then you can see down the bottom of the custom correlation, [indiscernible] Rules. There's a lot of information within here, but thinking about indicators of compromise or using correlation on other data sources being ingested into the XDR platform and into our data lake to be able to build out correlations within the system. If I see this activity alert me through a custom indicator of compromise. And then we've got the investigation and response side. So outside of just the detection piece, how am I responding, how am I searching through? We collect all the single alerts and combine them into an incident using our analytics in the back end to make sense and put them into -- that casualty chain I was talking about before to understand what's occurred. And we see that then with the root cause analysis, where did this start? And then we're also aligning this back within the platform to the minor attack tactics and techniques, showing you all the different tactics and listening out underneath each of those tactics, what techniques we use within those as well to help understand how the attacker is hitting you and if it matches across or against any existing threat actors out there as well. So you can see this is -- the main aim of this is to help increase your ability to detect and respond. We're getting rid of those blind spots. The accuracy is up because you've got more information included in how you're hunting. The investigations are all within a single area, plus we can dive deeper in using our XDR query language area as well to help build out and dive deeper into the queries. The way you respond is more flexible. You can have different teams involved in this to help do different parts of your threat hunting. And then the manual piece. There's less of that because we're combining it all and building it out to enrich the incident before someone has even looked at it or been alerted. And that's one of the really key differentiators for what you need to do to help detect and respond correctly. So here's a both for and after example of what happens with or without Cortex XDR. So we can see before XDR and this is about the example I talked before about. We've got an e-mail attachment being opened. There's a malicious macro that launches power shell. The power shells requested some -- malware to be downloaded. We then had that malware run. We then had that local endpoint infected and there's exfiltration of data starting to occur. And we see lateral movement that start spreading around and outside of that singular device and the exfiltration occurs, what other systems can I connect to that I can also extract data out of. I found my way in. So again, there's no such thing as that 100% prevention. But what you can see on the right-hand side here is each one of these can be stopped at this particular point. And if it's not stopped, it's stopped by the next piece. And that's what you need to see from your endpoint solution is right, first method of prevention fails, or is bypassed, then we need to step into the next stage and bypass it there. And so that's what we talk to her. Well, I can see that Power Shells are attempting to run a malicious code through a malicious macro. I've got the prevention technique being blocked that stopped. If it's allowed to go through, well, maybe they're downloading the malware. Well, now I can see the malware protection, but trained by WildFire analyzing that file saying, no this doesn't look any good. I'm going to block it all, allowing it to go through, but still analyzing it and alerting an admin afterwards. Then when we've got the agent on the endpoint and it's having a look at this piece of malware attempting to be run at pre-execution we're doing that local analysis of the file on the end point. If it bypasses that and steps through to the next point, we've got where that local endpoint would be infected, we're now seeing behavior. So everything else has occurred from a file level perspective. We're now seeing activity on the endpoint itself, behavioral threat protection, identifying the steps of maybe someone [ living off the land ] or hands on keyboard type attacks that we can pick up and alert the user to. And with all of that, we've got on the back end of that being alerted to the detection piece being able to investigate the threat that's occurring and respond effectively with the information that's being gathered through each of those different phases, stopping it or detecting it. So we know that this also needs to go beyond the endpoint. And I talked a little bit about that before with how Palo Alto Networks coining the term of XDR talks about broader than just endpoint detection and response. I can see a hand raised from, I think, Maria, what I may suggest is if you've got a question, may wait until that Q&A component and kick into that there, if you don't mind waiting for just a moment. So when we talk about extended detection response, it needs to be more than just endpoint. So I can see EPP here, yes, that's great, and EDR. But when I start adding in firewall, firewall data to the discussion and to the detection response phases, I can see network detection and response coming up into play. I can see user behavior and analytics not just from an endpoint, but also from a network traffic perspective. And also then from cloud, anything sitting within a cloud service provider, be a workload or containers or any type of cloud information or a system that's running within that, that we can run an agent on or run it on the host itself, hosting the containers, we can pull that information and use that as part of the way that we hunt and protect your entire infrastructure, be it on-prem or cloud or wherever. We also don't want people to go too far ahead of where they're capable of right now. We know that everybody has a security road map for their organization and where they got coming from and where they're trying to get to. As you can see, within here, we've got the discussion across all of this, where you can start on the left with that endpoint protection side with XDR Prevent looking at the Next-gen AV component, and we can then shift up and build into it with the endpoint detection and response by switching on the pro component of XDR. And then when you're ready and when you've got those other data sources that you want to start combining and hunting through together, that's where XDR comes into play, pulling in all of those other data sets, helping you use those to hunt more effectively within that single area and be smarter with the analytics that occurs around that as well. Conscious of time, we'll go over some of these attacks quickly. So these are some real-world attacks that have occurred out there. Log4Shell was back at the start of the year and noPac as well. So let's have a quick look at -- Log4Shell or Log4j as we know it. A lot of different victims were hit by this. A lot of applications, a lot of servers are seeing they're running something that has Log4j sitting on them. And unfortunately, there was a huge CVE and vulnerability attached to that specific logging utility. With the scale of it, we saw a whole heap of these potentially compromised organizations to the point of tens of thousands of those. And the costing position, unfortunately, we saw that there was a huge cost to remediating, rebuilding those servers. It just unfortunately was the way that it happened. That's the bit that we know about from a cost perspective, but the unknown cost, you can see down the bottom there, it's the PII, it's HIPAA, all those regulations and the information around our identities from a personal perspective, that we don't know who or what got from those systems that were compromised. And the adversaries, it wasn't just one type of a threat actor. It was all sorts using this because it was an easy way to get into systems when it came out and got alerted to. So where Palo Alto Networks help protect against this, we actually have a component part of that exploit prevention that we talked about before, which is all about on Linux looking at the Java to serialization export protection. So we have that as part of our security here. We're blocking the malicious payloads and behaviors on any of the different endpoints that we cover. And then we can also go through and hunt through all that data that's being collected to identify those TTPs, with that behavioral analytics, we talked about within those that XQL, that XDR query language I talked about before. It's really going from, again, that prevention all the way through to the detection and response side of things. So this is 1 example that we had. We can see the serialization attack. We're exploiting those untrusted and unsanitized user inputs, with our specific version of XDR, we're able to block that exploit and also enable the serialization protection to stop it from recurring. And then we can see the hooking into Java here to detect attackers. So there was actually multiple steps and stages that we provided protection for Log4j attacks. So with Kerberos and the noPac, one of the big things was, it actually happened around the same time as Log4j. And so nobody was focusing on that. They were focusing on the big angry-looking bear compared to the little deadly thing that was sitting behind it without anybody realizing. So there were some key CVEs associated with that. It was very easy to compromise. And again, we're sitting in tens of thousands globally for that. And what they got out of that was full domain and in privileges to those organizations systems that were running it. Little scaring. So what we did with the data being collected? Because we can pull active directory logs into Cortex XDR, we're able to pull the next-gen firewall logs from Palo Alto Networks next-gen firewalls as well as combining that with the XDR agent data, we stitch all that together, we talked about cross data analytics. This is where it's not just from the endpoint, but also from things like next-gen firewall or other data sources and use that to hunt through and find those threats that occurred. So look at this point, we've really finished with the main component before we shift into the discussion piece with Lynn and Vicky. But what you'll see pop up within your chat box in a couple of seconds is some links to these industry validation and independent testing. We're going very strong with the independent testing that we do and really showing us as a leader within these different environments and different organizations that they really see that what Palo Alto Networks is doing is incredibly strong and incredibly effective at limiting the threats from those threat actors out there, completely understanding there is no such thing as 100% prevention. So what we'll do next is quickly throw up a poll. And if you can answer this little question here, so you can see the question is asking if you're interested in finding more about XDR and how it can help your organization. Hopefully, what you've seen today is help you get additional information that helps you understand that potentially your system or your organization may need a little bit more from a security perspective, we can help you with that. Excellent. It looks like we're getting some -- we've got everything else, and thank you so much for responding to that. We see a few saying, please contact me, which is always nice. So hopefully, you found something out about this today. I'll end that poll. And our next follow-up from this is the virtual hands on workshop. So you see it's happening on the 11th of October. So there's a link here, that links also going to be thrown into chat, which I think it already is. If you want to click on that, if you want to see XDR in action actually go through a threat hunting process, looking and utilizing the XDR platform as well to understand how it can help you find those bigger threats within your organization and be more proactive in the threat hunting process as well, you can click on that as well. Outside of that, that's me for now. If there are other questions, and I did remember the hand raised, but if you want to type your question down in the Q&A, you can do it honestly, if you want, I can respond back to that or we can respond afterwards. But from here, let me switch across so that the other team can share their side of things.
Leonard Kleinman
executiveGood morning, good afternoon and good day wherever you all are. Thank you for joining us in this episode of Cortex dialogue. I am Leonard Kleinman, Field CTO and evangelist for Cortex for JAPAC. Now it certainly is an interesting time to be a cyber security practitioner these days. In the last couple of years, the definition of a physical office has changed remarkably. Today's work has now operate from a combination of office, remote and hybrid environments and increasingly using their personal devices to work from pretty much anywhere. So hence, my description of the distributed ecosystem in which we work in. And that's probably why we are seeing some rather interesting statistics flow through for instance, according to a Ponemon Institute Study on the State of Endpoint Security Risk, 68% of organizations have experienced 1 or more endpoint attacks. And therefore, they've also seen some successful compromise of their data and/or their IT infrastructure. That very same study also says that 68% of IT professionals saying that the frequency of endpoint attacks have increased significantly over the last year. So securing these endpoints has become an even more critical than ever situation than before because like our workers, your staff as well can work from anywhere. And therefore, threats can also come from pretty much anywhere. Additionally, if you truly know what attackers are after, you stand a chance. You also know then what to protect most. In our newly released 2022 Unit 42 incident response report we have painstakingly conducted in-depth interviews with a dozen incident responders and analyze over 600 instant response cases from the past year. And one of the key findings was that in 44% of cases, organizations did not have an endpoint detection and response or an extended detection response security solution, I find that rather staggering. Or if they did have one, it was not fully deployed on the initially impacted systems to effectively enable fast detection in response to these such malicious activities. So today, for your viewing pleasure, we have with us Vicky Ray, Principal Researcher of Unit 42 Threat Intelligence Unit, Japan to share his insights and put forth his views on the current threat landscape and to hopefully provide you guys with some sage advice on where do you need to start first, as these cyber criminals continue to evolve their attack methods -- welcome to the program, Vicky?
Vicky Ray
executiveLeonard, great to be on the show and thanks for having me.
Leonard Kleinman
executiveAbsolute pleasure. I'm really looking forward to this opportunity to unpack this particular topic here. So without further ado, I'd like to dive into some of the questions I'd like to put to you, starting with how has this highly distributed or a hybrid work environment, coupled with digital transformation at speed impacted the state of endpoint security these days?
Vicky Ray
executiveSure. I think post pandemic, with the growing number of organizations suddenly going to the cloud has definitely changed the threat landscape in several ways. One, as organizations found that people have to now work remotely, they started deploying technologies in a pretty fast manner without a lot of those efforts, which would typically be taken, pre-pandem, right? So with that quick deployment processes, security definitely took a back stage, right, because they wanted to be productive, the operations needed to go on, the business needed to go on. However, in a lot of these instances, we have seen in organizations not prioritizing security. And that definitely has caused a lot of issues where a lot of those infrastructures of businesses have been exposed to the Internet and have been the low-hanging fruits for cyber criminals. So definitely, that is impacted in a big way and I would say that a lot of these cases, which we have kind of worked on and in many cases, which we have observed in the while, was due to exploitation of this infrastructure, which were insecurely deployed.
Leonard Kleinman
executiveYes. Yes. I totally agree with you. There's been a lot of narratives and conversation around what we call this cost, technical debt, the speed to deploy to remain connected and productive but at the expense of security. So I guess what you're really saying is that we're seeing a lot of catch-up now as organizations have settled in this mode and are starting to actually deal with that technical debt around security?
Vicky Ray
executiveYes, absolutely. And the amount of security, which has been technically available for organizations when employees would work from the office has not been the same when they were working from home. So definitely, that has also impacted, and this is one of the reasons a lot of organizations eventually has resulted on a breach where employees didn't have the right set of security technologies either deployed on their computer systems, whether it is a VPN or other tool sets, which are typically needed. When we talk about our capabilities, we have -- we have Prisma Access, which allows us to have the same level of security if they we are working from the office or at home. So I think a lot of these organizations missed that capability.
Leonard Kleinman
executiveOne good point you raised there. I do appreciate that. What I'd like to ask you next then is according to this Unit 42 Incident Response Report, which I find really quite enthralling and comprehensive. In the last year, about 70% of incident response cases were ransomware? Is this email compromise a BEC. I'd love to get your view, your insights into why do you think this is so -- is really all the fault of this is the remote work? Or is there more to this picture?
Vicky Ray
executiveYes, that's a very good question. And right off the bat when anyone reads that report might see that, okay, that's a growing rise of ransomware attacks and -- BEC attacks, probably maybe due to remote work, which you mentioned. But really, when we look at these cases, I want to answer it in 2 different ways; one, looking at BEC, when we are looking at business email compromise, it's been there for a long time. It's not something which started or had an increase during the pandemic. It's been there. It's whenever I'm talking about BEC, we need to see that BEC does not get a lot of media attention like many other threats out there. But BEC does almost the same amount of financial impact or maybe a lot more than others, like ransomware. But because it is not that sophisticated, it sometimes does not get the media highlight. But when we look at our cases, which we have been working on for several years, BEC has always been one of the top threats or impacts which we observe. Now let's look at ransomware. Yes. from Ransomware perspective, again, when we look at the rise in these cases, it started at least from 2019. And again, pre-pandemic, it was basically due to a lot of these ransomware gangs, who were providing the RaaS service, the ransomware as a service to other criminals. And that has become very profitable to other criminals. It's opened up opportunities for other criminals to be ransomware affiliates. And when we look at the 3-year data, you can see the amount of impact and money involved and many other criminals are jumping in the boat to become ransomware affiliates because there's a lot of money, both in BEC and ransomware. So I wanted to say that wherever the money is, this criminals are going to go and exploit. And this is the main reason we are seeing the rise in those cases.
Leonard Kleinman
executiveSo really, it's -- the opportunity has exploded in the last few years because of the way we work in that rush to maintain connectivity and productivity. And these systems, these mechanisms, let's say, they obviously work. So they're able to generate a good return, let's say, through their nefarious activities. I was wondering if I could just take a moment and delve a little bit deeper into the ransomware situation in particular. On my mind that a lot of the conversations I've been involved with, and what I'm seeing is that ransomware these days has somewhat extended into data breach territory, which really means an organization that's hit by ransomware in the first place is really also dealing arguably with 2 types of incidents. What is your take on this? And what does this mean for responders and the like?
Vicky Ray
executiveGreat point there. Yes, absolutely. I mean we talk about breaches as soon as the data or whatever the sensitive crown jewels are of a company has been stolen. And that is exactly the moment where we call it as a breach. So yes, we have ransomware incident, but at the same time, you can say that there are 2 different types of incidents, which -- and the most important part when we are looking at this is how prepared an organization is and understanding these kind of threats, right? So for example, when we are looking at ransomware, if a company is prepared to deal with those incidents. They also should have the right process whenever -- as soon as they realize that, yes, there is a breach. -- yes, we are dealing with a incident, we are dealing with a malware incident the moment it qualifies for breach, yes, there are indicators, which shows that our data has been exfiltrated. We start the process on what should be the -- there are several internal teams involved, for example, legal, other IT teams, HR and many other teams who needs to be part of that cases. But again, yes, I mean, whenever we are looking at such cases, it needs to be handled in a way that people are matured enough, not only from a technology wise, but also from a process wise. This is so important because whether you have the technology, but you don't have the right process, it's going to be a panic situation. And panic has got no place when we are looking at cyber attacks.
Leonard Kleinman
executiveYes. So really what I'm hearing here is there's so many moving parts, so many aspects to these types of double type scenario incidents, that really, it's all about the organization being aware of it and preparing for these types of scenarios through drills and practices. So if I can refer a little bit to my military household prior preparation prevents poor performance is really what we're talking about here.
Vicky Ray
executiveAbsolutely. We have fire drills in the office. These are very -- it may happen once or twice a year. But when we talk about cyber drills, it really has to at least happen every quarter, if not more. so that people are on the ball on this because it is so essential that as people practice, it is also not -- it is actually exciting when we have these cyber drills. But there's a lot of learning which we can achieve from those trials. So it is definitely something which needs to be prioritize.
Leonard Kleinman
executiveGreat advice. We do appreciate that one. So moving on to insider threats. These never ever seem to go out of style here. Again, according to the Unit 42 incident response report, 75% of insider threats caused -- sorry, cases were caused by a disgruntled or vexatious employee where they got enough sensitive data to become a malicious threat actor. With these type scenarios, what should cyber practitioners and cyber leaders be aware of? What can they do to combat this?
Vicky Ray
executiveYes. I mean we have seen so many organizations. It's not a surprise, to be honest, that a lot of these organizations are giving way too much access to their employees, and access to data needs to be on a need to know basis, whether it is just because it's within the organization doesn't mean and somebody can have access to source code if that individual is not a person who is involved in developing code. Even when we look at product managers, we need to classify access in a way that they should be able to access only their part of the project rather than everything else. And a lot of these cases, which has resulted from disgruntled employees stealing or taking away data before they leave an organization is because they had too much access to data, which they did not need to, that is one. And this all goes to things like having the right amount of visibility, having the right amount of policies. The technology needs to enforce the policy set, again, going back to policies, which are created in the organization. But do we have the right set of technology to support that policy. Just having policies on paper is not going to help. So it's hugely important that the technology can support with visibility and enforcing those classifications.
Leonard Kleinman
executiveNice, nice. No. I understand that. Look, I just wanted to have a small segue on this one and delve a little deeper into this insider threat situation. We tend to focus on the malicious actor, but what about the non-malicious actor? You know the one who may have innocently caused an incident through e-mailing data to the wrong recipient or that like. There's clearly no malicious intent. This still is an incident, right? And just interested in your thoughts here. Anything we need to be aware of?
Vicky Ray
executiveYes. That's a great point. And you remind me of my previous day job, which I had. It was on an end-user environment. I've always -- majority of my career have been in security operations. And we have actually found these cases where an employee who wanted to work on the project and finish the project faster would have send some of the code out to his or her email address, personal email address. Just their intention was to go and finish the work over the weekend, but they -- some of them fail to realize that those are intellectual property and they cannot go out of it. So definitely, there has been instances and these things will happen. But if we have the right set of tools, for example, DLP, but at the same time enforcing as soon as something is being attempted that needs to be stopped rather than going out. But these things happen and it should be considered as an incident. And again, the process should support or the process -- there should be processes built for these kind of incidents. But again, these are considered an incident, which needs to be handled in a way where you can contain it and have next steps taken so that it does not get into the hands of wrong people.
Leonard Kleinman
executivewonderful. Thank you for the clarification on that point. And yes, this has some -- again, some sage advice there. So as we start to close things out here, one of my final questions here in that same report, I want to find rather alarming statistic in there, 44% of cases, organization did not have endpoint detection response or any other type of XDR extended detection response solution or it was not fully deployed. From your perspective, just how critical are EDR and XDR solutions these days. What do organizations risk losing if they don't have a solid endpoint solution implemented or for that matter properly configured?
Vicky Ray
executiveYes. Yes. That's a very important point there. properly configured. But yes, just to answer to your point, there is a huge percentage of organizations who just rely on endpoint solutions like AVs to -- for the security on the endpoints. But really looking at the type of threats we are seeing and how things have evolved, not having an EDR or XDR, again, when we are talking about EDRs, it still has certain limitations. And this is why we are talking about why XDR is so much important because that allows the endpoints to talk to other solutions like the network and the cloud, and it is immediately within seconds when you have an XDR solution where the endpoint is able to share intelligence and talk to each other. This is -- this brings in so much power to the capability, where just an AV or even an EDR is not able to help because EDR is another version of an AV with a response capability. But there's no intelligence built on it. Many people may say, okay, the EDR has certain signatures, which can -- that is not intelligence. Intelligence needs to be where any -- there is something malicious seen on the other part of the world and something which can be immediately pushed on to other devices, whether it's an end point in Latin America, being -- having the signature where the malicious indicator was observed in -- maybe in Singapore. So it really needs to -- the technology needs to really be built in a way that the endpoint is able to get this intelligence in a very fast manner. And I think that's a huge differentiator, and that is lacking in a big way in the industry.
Leonard Kleinman
executiveNo, really, really appreciate the narrative and the clarity in terms of the differential between the traditional EDR and XDR. I think that's a question a lot of people do ask they have that. So thank you for that. So finally, I'm closing up here, I'd just like to put out there for yourself here. What is your to today's cyber security practitioners and leaders who are trying to combat these ransomware attacks and other cyberthreats. And they're struggling to defend the endpoint devices -- and also, of course, their business, their organization. I love to get some [indiscernible] thoughts from you?
Vicky Ray
executiveSure. And I think the biggest point I make when I talk to customers or even in general, is to -- is for practitioners to really have a good understanding of the threats, right? Just because if somebody just understands what a ransomware is superficially is not going to help them build capabilities to deter ransomware. Because a lot of times I've heard this narrative that my technology can deal with ransomware because they think that they have signatures, which can deal with that. But we need to understand how these bad guys operate. What is their business model, whether it is -- whether you are an executive, a CISO or whether you are an analyst, you really have to -- I'm not saying that executives need to go and understand how a malware operates, but at least understand how the business model is from the bad guys' perspective, right? So really having a good understanding of how the threat landscape is changing, what the capability is to the bad guys is going to go a long way to -- for the defenders to build their defenses. So of course, we can go in a lot of different directions, but I would say having an understanding -- a good understanding of the tactics of the bad guys will play a big role. So I'll end there, but we can always have a very lengthy discussions on how that can be achieved.
Leonard Kleinman
executiveNo, no, understood. I appreciate that here at loud and clear. Again, appreciation for their methods and for their motivations. Certainly, Look, thank you so much for that, Vicky. I guess that's it. We'll call it. That's the wrap. Thank you for sharing your experience and insights there. This has been tremendously helpful for us to understand the significance of where today's organizations are in terms of endpoint security and where we need to be going headed -- and to you, the audience, I hope that you found this episode of Cortex Dialogue informative and insightful. And I am certainly looking forward to seeing you again in the next episode. Take care.
Jason Spindlow
executiveThank you for that team. Maybe we've just got a couple of minutes left, and there's a couple of questions there. Florence, just in is that okay if we answer a couple of those to try and answer live or...
Operator
operatorPlease go ahead, Jason.
Jason Spindlow
executiveNo worries. So I think I had -- and I'm not sure if you're still on line Maria, did you have your question you wanted to ask? I can unmute you to ask the question or if you want to talk it through you want to ask that, you just want to raise your hand again, if you want to ask that question live. Where is that? I can't find -- where is the hand raised. Can you guys see that hand raise there? No one yet? Okay. I think there's a question there from Shailendra as well. So the question you're asking is which solution is ideal for an organization, EDR, XDR or MDR. I'm going to say something which is probably going to an cliche, but it's whatever best suits you. EDR is just about the endpoint detection and response. So it is an endpoint, the be-all and end-all of your threat hunting needs or is it the start like what we talked about in that path we saw. XDR, I would say the same thing. Are you further down the path of, well, I've got my endpoint information, but I also need to bring in additional information from my network from other security tools, start and combine that into a single spot where I can hunt better and effectively through those data sets, create correlation rules, build out custom indicators of compromise on to those endpoints as well or within those data sets, and create better stitching and cross data analytics between those systems as well. If you have all that or if you're in your part on the path to all that, but you don't have the resources, the question about MDR comes into play. Do I have a team internally that can manage my detection response and protection capabilities and functions. If not, and I can't build that out quick, Then, yes, MDR, that managed detection response having a team managing and responding to those incidents as they occur in your endpoints to stop them from occurring or going any further, is absolutely where you'd want to go. You may then decide to bring that in-house later on once you've got the skill set or depending on the size of your organization, you want to outsource that and allow that to be run by a dedicated team like what we have within our Unit 42 team that Lynn and Vicky were talking about there. So hopefully, that answers the question. If you've got anything else to follow up to that, please let me know. Any other questions around? I'm looking for the hands a little bit better now. So if you've got another question, please feel free to raise. Otherwise, I'm more than happy to give everybody a couple of minutes back. Can't see on the questions in the chat summary. Looks like you don't have a question. That's okay. That's fine. All right, If there's nothing else, look, thank you so much for your time. And hopefully, we'll see you at the next one of these events. And if you've got any other questions, I think that details have been sent through. You can reach out to us that way and more than happy to answer any questions you've got about Palo Alto Networks and Cortex XDR. Thank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.