How Security Starts With Infrastructure
Konrad Fellman explains why lasting security improvement starts with understanding infrastructure, architecture, and the systems an organization is trying to protect. He shares how aligning security and IT around shared goals, common metrics, and business priorities can reduce friction, accelerate remediation, and strengthen the overall security posture.
Security and infrastructure teams make faster, more meaningful progress when they share accountability, prioritize business risk, and measure improvements in security posture rather than isolated technical activity.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, security leaders and technology executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Konrad Fellman to discuss how security starts with infrastructure. Konrad, thank you for joining me today. To get us started, could you introduce yourself and tell us a little bit about your background and your current role?
Sure. Hi, I'm Konrad Fellman. I'm the CISO and VP of Global IT infrastructure for Modine Manufacturing. I've been in this space, I don't know, for longer than I want to think about since around 2000 I've been doing stuff like this. My background, I started in consulting, security consulting, IT consulting. After that I made my way to Cubic in 2012 where I took one of my first roles as just a normal person working for a single company instead of consulting to try and leverage all those things that I learned as a consultant. And from there made my way to the CISO role there and then I spent some time at a company called Encore Capital and then now here I am at Modine.
All right. So when you're assessing an organization's security posture, what do you look for within its infrastructure and its architecture before examining individual vulnerabilities?
Really looking at kind of what we have, what are the platforms we're using, you know, how's it architected, how much segmentation do we have, what kind of security stack exists, just to get a feel for what's there, because I think you know important piece is understanding and having that visibility of what you're trying to protect before you can really get started on reducing vulnerabilities and maintaining a good risk posture.
Having led both IT infrastructure and cybersecurity, where have you most often seen infrastructure and security teams become misaligned and what does that misalignment cost the organization?
Yeah, I think where I've seen that is when they operate in their own silos, right? And they don't coordinate a lot and there you get a lot of finger pointing, well, we said to do this and they chose to do this. Why l which is why I kinda love the role that I'm in, where I get to manage both IT infrastructure and security. So no arguments because everybody gets to be on the same sheet of music with what we're doing. But I think the other times it there are ways to alleviate that. I think, no, you look at security guys, they're focused on security. So when they don't get kind of the understanding of what they're trying to do and how they want to move forward, they become that department of no. And IT is always focused on, well, we gotta keep this stuff up and running or we're gonna get in trouble with our SLAs and when you guys tell me to do and fix all this stuff, cause downtime. So you just gotta get everybody on the same page to understand we're all working for the same goal and the only reason either of us exist is because a business is trying to go out there and do something and sell our products or drive revenue and growth and everything else. So it's you know, getting the teams aligned with what's important, why they exist, and that we're all part of the business and we need to all be there to help the business move forward.
So speaking of that alignment, at Cubic, you helped bring IT infrastructure and cybersecurity into closer alignment, which reduced vulnerability mitigation time and achieved a point where 95% of systems had no critical vulnerabilities that were more than 30 days old. What operational changes did you make that made that improvement possible?
Yeah, I think a big one was I started as the CISO and then I was given IT infrastructure a little bit after that. So I got to do both, and that's where we got to really get that alignment. So really pulling both sides of the house into the same meetings, like the same stand-up calls every week to talk about what we're doing, help prioritize what needed to be done. So I think when you get people collaborating more closely and giving that why. it helps you drive progress a lot faster.
So what was creating the biggest delays before the changes that you implemented were made?
Again, it goes back to those silos, right? Security always, hey, they don't wanna do this, they don't wanna do that. And you see it in a lot of organizations where, you know, I'm every place I go and I try and pull security out of that mindset of saying no to everything, right? Everything's a risk, everything's a critical priority, we're gonna have a massive breach if we don't do this or that, right? That's not the case. You gotta be a bit pragmatic about it and understand why you exist and what you're trying to do, right? We're we're not there just to stop every bad thing from happening. We're there to allow the business to innovate and move forward and do what they need to do. And we need to be cognizant of that as we do our jobs so that we understand and could better talk about things from a risk perspective and say, that's cool if you want to do that, but understand this is what the potential risks are. I'm not gonna stop you, but let's do this with everybody having the right understanding of what the possibilities and potential consequences are.
And how do you maintain accountability between infrastructure and security teams without creating additional friction?
Yeah, I think it's having common metrics that we can all work towards together, right? So not metrics that help shift blame or put different people under the gun or highlight this guy's not doing his job, but just metrics that make sense, right? Outcome driven metrics that you could look at. We're trying to achieve this goal of improving our security posture as a whole. So here's what it takes for everyone to do that, and this is a shared goal, not just securities goal or not just IT's goal, but say this goes with to everybody's performance review, right? Everyone's gonna be measured on that. So when you can get everyone working towards that same goal and working towards those same metrics and driving those numbers that right way, I think you get a lot more cooperation and buy-in from everybody that's involved.
So some what are some of your favorite outcome metrics to use when trying to align security and infrastructure?
Yeah, I think a lot of times, you know, a lot of these metrics, when they get created, they're focused on just things that maybe IT or security understands, right? Just the technical side of the house. Let's figure out this percentage of critical vulnerabilities on each system or something like that. So I think looking at outcome, right, it's how do we where our goal is to improve our security posture overall. So we want to focus on the most critical threats to the our organization and try and where you can put them in business terms, right? Something that if a board member is looking at it or executive management, they understand what it means, right? So I think when you look at kind of the outcome driven metrics, It's not about, well, we got our patching percentage in SLA right, right? It's no, we made this improvement to our posture that's going to prevent threat actors from causing a huge breach on these critical systems that we have. So it's kind of the phrasing a little bit, but what I what I do see is a lot of organizations also just look at the numbers and just look at the metric. How do I improve that metric? Right? If you just say percentage of systems with critical vulnerabilities, all you get is people trying to get that number down. So not really evaluating what the actual vulnerabilities are and looking at the ones that have a critical exploit that's available in the wild, right? So You really want to shift that focus to we're improving posture, protecting against threats versus some arbitrary number that you just wanna hit. So it's it's really trying to move people to let's focus on the most critical vulnerabilities, the ones that leave us the most exposed, and how does that reduce our risk posture or you know, reduce our risk overall with the infrastructure, not just some number.
Right. So when shifting to focus on the most critical vulnerabilities, what information about assets, systems, dependencies do security teams need to make those effective risk decisions?
I think it's a lot of times bringing in the right tools. You don't want to do that manually.
Right, of course. That would be a nightmare.
I think every organization has thousands, hundreds of thousands, potentially millions of vulnerabilities that exist out there. So I think you could use various tools that exist and there's a lot of great ones out there. We use CrowdStrike's exposure management and it and their expert score, which takes into a lot of different content related to the asset and other risks it sees related to asset and external exposure and if there's critical exploitable vulnerabilities that exist. So you can kind of pull all that together and use its score, right? Everything out there is using AI and things to figure that stuff out. There's really no reason to go try and manually figure that out on your own.
So shifting a little bit to more of the architectural decisions that affect security. What type of architectural decisions, such as segmentation, identity design, cloud configuration, et cetera, how did they determine the impact that a vulnerability could have?
Yeah, I think with all of that, you really need to look at how you've architected your defense in depth, right? I think everything comes down to a lot of those basics, right? Are you properly segmenting networks and your critical things from your non-critical stuff? Right? Are you putting IoT devices on a separate VLAN from all of your workstations and everything else? You know, what does need to have internet access versus not needing internet access, right? So that least privilege type concept. You know, managing your identities, seeing how many layers you could put between your critical things and what the threat actors are doing, right? Trying to minimize your attack surface as much as possible. So looking at all those different layers of controls, like for me, the way I like to look at vulnerability management is breaking things down into external facing assets, end user compute, and then the rest of the infrastructure. And then my highest focus is always gonna be on that external facing stuff because if it's out there on the internet, everyone could see it. And as soon as there's vulnerability, everyone's gonna try and exploit it. And then just moving down that stack. So looking at end-user compute where you have all of your people, right? Probably not adequate training or they're trying to do the right thing, but likely make some poor choices on clicking certain links and typing credentials into places they probably shouldn't. So and then
Getting their lunch gift card.
Yeah, things like that, right? So that helps you kind of do that risk-based prioritization as well, right? Focus on where threat actors are gonna get in. Right. They're typically never gonna have direct access right back into your back office and data center. Right. There's multiple layers in there, but it's also about how well you do those other controls, how well you're managing identities, right? Are you using single sign-on? Are you tying as much as you can in the SAML policies, conditional and risk based access policies, right? Do you have the visibility when something weird is happening or somebody's account is used in a way that it's not normally used, right? Did you deploy your EDR to everything that you possibly can? So making sure you have that visibility and those layers of defense really helps.
So, how should security teams become involved in infrastructure and architectural decisions before new risks are introduced?
Yeah, I think it's where you can and it's not always possible, but having the security team involved in when decisions are being made up front, whether it's about the network infrastructure, the architecture, new applications different groups wanna bring in and giving them the chance to evaluate, whether it's vendor risk management, looking at all the new vendors people want to use, SaaS services, whatever it is, make sure they get a chance to kind of review and see how that works. into what our security stack is and what our security architecture is overall.
Okay. So in environments that have legacy systems or operational technology where strict patching or immediate patching may not always be available, how can they manage risk more effectively in that scenario?
I think goes back to that layers of defense, the defense in depth, right? Segment things off that are more critical. You know, minimize your attack surface. everybody, every organization I know has some obsolescence, has some older systems, has some applications they can't live without. That support ran out a decade ago for, right? There's lots of those things, but you have to be really pragmatic about your controls and what you're looking at and really, really follow right, those principles of defense in depth, least privilege, you know, looking at your access controls, your ACLs, right, the access you give individuals to things and make sure you understand what exactly you have out there and where it is. So visibility is key as well, making sure you know what all your assets are and where they are.
So with defense in depth, how do you determine which additional layer of defense will meaningfully reduce risk rather than simply add complexity?
Yeah, I'm a big fan of simplifying things as much as possible. Yeah, I think security should have a very low amount of friction to the business. The harder you make things, the more complex you make them, the more people are going to try and find a way around them. Right. If somebody's gotta go through three layers of MFA and go into five different portals to go get to one application, they're gonna find a workaround, right? They're gonna see And look for a different way or they're gonna write everything down and keep it in some plain text file on their desktop or do goofy things like that. So it's I think when you look at defense in depth, it's more about right, are you managing identity properly? Are you managing your vulnerabilities properly? Have you managed your infrastructure properly and your ingress-egress rules? Are they adequate enough? Are you looking at zero trust? And a lot of these things when you do them. They also make life easier for the end user, right? Moving from, say, traditional VPNs to a SaaSy solution, right? It's almost frictionless for the end user. Going from traditional passwords where people gotta use three or four different character types and it's gotta be you know twelve, fourteen characters long and you gotta change it every 90 days. That's a lot of friction that causes people to do weird things with their passwords. That causes a lot of reuse, writing down. Putting them in places they shouldn't be. So when you start shifting and tying more into SSO, looking at NIST 800-63B, being more proactive about looking for compromise credentials and things like that, not giving people, you have to use all these character types, but make them have a little bit longer character and they could use whatever characters they want in their password. But as long as you're monitoring them for potential compromise, weakness being found on a dark web, and then you could trigger a change. It just makes life easier. Also things like going a passwordless, you know, using capabilities like Windows Hello. I think people freak out about it, but just because something's easier doesn't mean it's less secure. A lot of times it's more secure because we're getting out of the bad behaviors and habits.
All right, so as we wrap up, if a security leader wants to strengthen the foundation beneath their vulnerability management program, where do you recommend that they should begin?
Create some metrics that make sense for you and your organization. I don't think they're the same for everybody. Everyone's got a unique scenario. Everyone's got a different infrastructure or at different phases of their own life cycle and maturity. But think about what you want to do. Think about in a pragmatic matter, take into account what the business goals are, and then figure out how we can isolate all of our old stuff, how can we make it harder to get to things that are more critical that people don't really need to log into all the time. Just look for those small opportunities and look for things. I think there's a lot of capability and solutions that people already have that aren't taken advantage of. Right. If you look at a lot of environments, a lot of organizations are using O365 a lot of capability in Entra related to say password management. So if you can kind of tighten up some of those controls. That also makes things a little bit easier for end users, take a more risk-based approach. You could probably start reducing how much you have to tackle. So if you're just focusing on the top five most critical remediations in your environment, you know, that take in a context of what they are, what kind of data they have, how exposed they are, versus just looking at the numbers like we talked about, just percentage of all of our systems that have critical vulnerabilities, right? Focus on the things that are the most important and try and make your metrics work that way instead of and it's some of the common ones that you see that way. You'll start reducing your posture, you start having more of those layers that exist and you'll get into a better place with a little less stress probably too.
Alright, excellent. Well thank you everybody for watching. If you enjoyed this conversation, be sure to like and subscribe and leave a comment with your thoughts or suggestions for future guests and topics. And thank you again to Konrad Fellman for joining us. We'll see you guys in the next episode.
Thanks.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.