THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Security today has evolved so much in terms of the technologies, frameworks, and risks. Cybersecurity can impact our businesses and daily lives in many ways. We often have to carry multiple devices to tend to personal business on the road, go through rigorous cybersecurity training every year, and yet we are still just as vulnerable as we were before. Security is a continued game of Cops and Robbers, with one side creating new security measures and the other constantly (and eventually) cracking it to gain access to sensitive information. Keeping up a modern security network is a major operational overhead for companies as well as a source of inefficiency and dissatisfaction to resources, both of which can be invested in other areas to improve the core business. One would ask “Is there a way to break this wheel and make this never-ending game a bit more efficient?” I want to suggest exploring the adoption of my passion: blockchain. Perhaps this won’t be your typical security technology conversation, but I hope this can inspire some ideas that can make security less of a cost center and influence positive experiences for employees operating a business.
I’ve had the pleasure of working with dozens of clients on blockchain use cases around supply chain, identity, and credentials management, and ecosystem development with my former employer IBM. Blockchain is still in its nascency, and while recent developments in cryptocurrency takes much of the attention, it is a powerful tool to drive security and resilience to a company and its partners if they can find the right team – or “network” – to work with. I’ve often been asked how blockchain is supposed to help cybersecurity. I can understand the confusion, but to address this, I consider calling blockchain more of a deterrence mechanism that complements cybersecurity. If cybersecurity focuses on addressing the vulnerabilities of day-to-day cyber-attacks, then blockchain creates a governance that disincentivizes a malicious player to even attempt to disrupt the network. To borrow the military term, cybersecurity would be the active battle fought to protect ourselves, while blockchain would be protective missile wall that would scare any belligerent to even fly into our airspace to start a battle. I believe the latter can help eventually reduce the ongoing costs of security while providing additional assurance that a company is operating in a business network where data exchange is trusted and can generate value even outside of the security conversation. Please accept that the term “network” here does not refer to connectivity and IT infrastructure, but to a group of participants with a common stake in the ecosystem they operate in.
“If cybersecurity focuses on addressing the vulnerabilities of day-to-day cyber-attacks, then blockchain creates governance that disincentivizes a malicious player to even attempt to disrupt the network.”
Going into the fundamentals of blockchain would be a long story, but I would argue that its biggest benefit is the ability to create a business network where its participants can agree to share selective information, either openly or privately, that can be useful in enhancing the efficiency of security operations of each participant. This selective information can be anything from the version number of their operating systems, security test results of a supplier, or customer credentials. These participants, who ultimately serve as nodes of this data collection and sharing, can be anyone on a network, even competitors or unknown parties, as long as they have established goals and guidelines to exchange information on this network. The design of each business network can define its constituents and their comfort level of privacy; there are too many permutations of how creative this can be, based on the blockchain protocol or the industry, but the impact here is that instead of each individual partner investing in and managing their own security, participants can team up and work together to build resiliency into the system thus deterring external threats from impacting one or more participants in the network. Of course, this assumes that the typical data access controls are managed through a well organized and up to date security framework within the company and its network (again, blockchain does not solve for cyber-attacks directly). I’d like to share one example use case I worked on where blockchain can be useful to make life easier for security teams.
Use Case: Supplier credential management and security clearance
When I was working at IBM, I learned that a typical company spends an average of six months or more to onboard a supplier; for government or defense industries, this takes even longer. A significant amount of time is used on background checks and security clearances of the supplier. Probably a lot of these actions are also delivered via third parties since it is a heavy burden for procurement to fund and operate this workload regularly. The CISO department will likely ask for documents such as security certificates, penetration test reports, certificate of insurances, and an ever-growing checklist of questions to verify what technologies they use, if they operate out of trusted locations, and follow the right policies and GxP to reduce the risk to the buyer. Taking a deeper look at this, we can learn a few things. First, much of this information is requested of the supplier repeatedly from almost every buyer, perhaps with few variances in formatting. Second, these data points are generally expected as good practice for a supplier serving multiple Fortune 500 customers– would you ever want to work with a supplier who doesn’t use a secure cloud platform or does not have a COI? Third, much supplier information may be collected from third parties, which means there is always room for error, thus trusting that third party’s work is still a risk. Last, this is a repeatable cost for every individual buyer for the one supplier, one which any CISO would love to subsidize or outright reduce. In summary, it is slow, costly, and carries risk of inaccurate information – can you really trust that all the data you collected are verified and trustworthy?
Imagine if these buyer companies across the industry can form a trusted digital network based on blockchain where they can share relevant information freely amongst themselves to reduce the complexity of verifying the same supplier. In a nutshell, here’s how it can work: Suppliers would simply upload their credentials, test results, and certifications onto the blockchain. There is a clear publisher of this information (the supplier self-reports all this information), and that information can be verified by a trusted set of partners across the network. Again, the selection of these partners can vary based on industry need or trustworthiness: for example, it can be the first five buyers of this supplier, or the largest revenue generator from three different industries, or a random sample set of buyers who have recently done business with them over the past two years – this can be decided by the network governance itself. The partners need not identify themselves to anyone, they just need to know that there is a “proof of verification” on blockchain where someone actually did the verification and recorded the result. Once verified, the supplier can choose who they want to share this data with (this is similar to the popular “Know your customer” use case on blockchain). This information can help accelerate the onboarding of a supplier for any interested party, since it can be trusted through a group of peer buyers. Whenever there is an updated report by the supplier, all subscribed buyers can receive these updates instantaneously; any security breach events or malpractices captured about this supplier can also be recorded by any relevant party and then shared with the network to first verify but then review for their own purposes.
One would ask, what’s the security angle here, and what are the benefits of this approach? First, the supplier is incentivized to keep all of this credentials and security compliances up to date and accessible for everyone in the network. No more challenges around outdated security documents or having the supplier make these updates manually for every buyer. The information will come directly from the supplier, so there is less risk of erroneous data collection through a third party. Second, it reduces the cost to each buyer to collect manage this information. What an army of analysts would do for each company is now reduced to an automated platform that is co-funded by the network. Last but not least, it disincentivizes the supplier from any potential malpractices. Every bad action is recorded permanently on the blockchain, for every buyer to review and respond to, thus it is in the supplier’s best interest to keep its practices secure and its data accurate. This last part doesn’t cost the buyer at all, it is the network’s resilience built upon self-regulation amongst its participants, one of the core fabrics of the blockchain-based network. Solutions like Trust Your Supplier–who I had the pleasure working with–can help bring this offering to reality and reduce supplier onboarding time for all companies, and that’s a value for the ecosystem.
We can apply these attributes of blockchain to other use cases, including infrastructure management, heavy (or military) machinery operations, and banking systems. All of these industries and services have experienced hacks because a malicious entrant was able to penetrate the cybersecurity services and apply their damages. By applying verification points across a network with blockchain, these systems would have a secondary opportunity to check if this malicious entrant was indeed a certified and validated user before it was able to proliferate the damages. That’s how I believe blockchain can make organizations and networks resilient, thus more secure.
As I mentioned in the beginning, blockchain will not be a substitute for general cybersecurity. However, weaving together cybersecurity (the day-to-day monitoring of security vulnerabilities) with blockchain (deterrence of bad practices and endorsement of self-governance across participants), I am confident there is a path for each company to remove the complexities, risks and costs of the traditional wheel of Cops and Robbers game in cybersecurity and drive more value to its core business, employees, and ultimately customers.