RegisterEnterprise AI Summit — Oct 7–8 · Charlotte, NC
Video Library

Log in to watch

Log in or create a free account to watch this video.

Log in
Las Vegas 2023
Share

Lightning Talk: How to Rob a Bank?

SA
Vice President - Strategic Solutions, DivIHN Integration Inc

Cybercrime has evolved from physical bank heists, forgery, and employee theft into digital equivalents—data breaches, phishing, zero-day exploits, and insider threats—while the underlying modes of attack have remained remarkably consistent. Shantanoo Govilkar argues that DevOps teams can no longer treat security as an afterthought, especially as attackers increasingly target software development pipelines through business email compromise and zero-day payloads. He presents a cyber resilience framework built by blending major standards and regulations into a layered model grounded in ISO 15288, covering governance, shift-left security practices, identity and access management, SecOps, and automated compliance evidence collection.


In this talk, you'll learn how to apply a structured, automation-driven cyber resilience framework across the full software development lifecycle—from threat modeling at requirements through regulatory audit readiness—so your team can reduce security risk without creating methodology conflict.

Chapters

Full transcript

The complete talk, organized by section.

Shantanoo A Govilkar

00:07

All right, let's start here. So, talk about cybercrime and where it all started. Start with this disclaimer: don't try this at home.

00:19

The robbers have been doing this in four different ways. Bank heists, you know that very much. Forgery, right? Signing for someone else, the check, the hidden drawer, the tunnels and everything, or the employee theft. So those were the ways people were robbing banks.

00:39

With the technology, now they can rob any business. So the modes have remained the same. Now you can see the names are different. It's called a data breach, or phishing, or zero-day, or insider threats. And all these new names are part of my job security.

01:02

So why should we care? I don't know. It's something... Anyway, I'll go with this. Sorry. Yeah, yeah. I think I can hit the reset. Yeah. Okay.

01:19

So why should DevOps care about cyberattacks? As you know, the perimeters are getting stronger, and I'm part of FBI InfraGard industry community, and we inform, especially software development houses, that the new modus operandi is go through phishing, business email compromise, and get into the zero-day exploit, and then deliver the payload. And that's the way cyberattacks are happening. And that becomes imperative for the DevOps community to worry about this.

02:06

What do lawmakers and standards do? They put a barrage of standards. You can count; there are like six of them at least. So how do you handle this?

02:19

That's where you shift left. So what we did, don't want to start methodology war, so we referred to ISO 15288 as a standard lifecycle model, and we put all the standards and regulations, executive orders, in a blender and created a framework.

02:30

The framework has two layers. There's the security layer, and with all the plethora of tools available, there are a lot of automation availability. So the framework has governance as the overarching layer. Then it has the lifecycle, and that's where you shift left. You start off straight from requirements, and then you have the operations layer, including identity access management, data security, SecOps, security operations, and recovery preparedness in case of ransomware attack.

03:04

And then from an audit point of view, putting automation for standards, regulatory compliance, evidence collection, and exit criteria enforcement become...

03:19

So this is an example. It's a busy slide. So what I would like to at least present to the audience here is what all can go in the cyber resilience framework. And this is for robotic process automation deployment.

03:38

So as you can see, the coding standards, resilience policy, and whatnot, even right from the left requirement side. So this is not only about doing a static scanning, penetration testing, SBOM. That comes way at the right side of cybersecurity. You have to start right from your standards and your threat objectives, threat modeling, et cetera.

04:00

So with that, I would like to leave you with that thought: leave security as a forethought, not as an afterthought. You don't want to end up like SolarWinds. And automation-driven will actually ease the pressure on the software development teams overall.

04:24

So having said that, I will conclude. I think I have some time right here.