THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Brett Davis, Co-Founder and General Partner, New North VenturesBrett Davis is the Co-Founder and General Partner in New North Ventures, a venture capital firm focused on technologies that both provide solutions to national security threats and help commercial interests create enterprise value. Davis retired as a Senior Executive in the Central Intelligence Agency and Special Operations Officer in the US Navy. His combined 34 years of government experience included leading complex operations and enterprise-wide programs across the Central Intelligence Agency, National Reconnaissance Office, US Military, and other government agencies.
What are Some of The Major Challenges that Have Been Impacting The Enterprise Security Space Lately?
Companies that sell software to government agencies are being forced to comply with certain cyber security criteria in order to secure the software supply chain as a result of recent executive orders and memorandums. These requirements are quickly making their way down to the defense contractors, who are pushing the same requirements onto their subcontractors. As a result, these trends are forcing numerous businesses to incorporate software supply chain risk mitigation and cybersecurity risk mitigation plans into their development processes.
Cybersecurity is not Anymore, An Afterthought; Everyone is Realizing The Importance of Cybersecurity to Maintain Business Reputation and Avoid Any Risk.
Another risk factor that is emerging is deep fake risk. In such cases, someone pretends to be the CEO during a phone call and instructs the CFO to send a sizable sum of money by wire transfer. The accounting department or the CFO go and transmit the money since they believe this is coming directly from the CEO. Identity detection, as a result, becomes essential for businesses.
What are Some of The Trends Helping to Mitigate Those Challenges?
Today there are many companies stepping up who are helping alleviate business challenges. For instance, Reality Defender is one such company that is addressing the serious problem of fake news and is making headway in a number of really important use cases that are in the best interests of the general public. Dark Sky Technology is a company that does an excellent job of reducing some of the risks associated with the software bill of materials when it comes to open-source software. They are delving deeply into the source code to identify any known malicious actors that may be present in some of that open-source software. Using machine learning, they are able to examine the open-source code used by developers and see whether there are any flaws.
“Cybersecurity is Not Anymore, An Afterthought; Everyone is Realizing The Importance of Cybersecurity to Maintain Business Reputation and Avoid Any Risk”
What Keeps You Up at Night When it Comes to Some of The Major Predicaments in The Enterprise Security Space?
There are a couple of challenges that we see in the enterprise security space today, however, the most popular among them is the reliance on open-source code. Today 98 percent of all the companies who develop software use open-source code to save an enormous amount of time and money. However, with benefits, it also introduces numerous risk factors. It’s important for companies to examine the software bill materials and be able to really dig into and understand where that code is coming from.
What Would Be Your Piece of Advice for fhe Budding Professional in The Field?
My advice is not to accept the status quo. Even though there are a lot of problems, they can be solved. We need to work diligently on finding solutions and figuring out how to measure the risks of deep fakes. Also, we need to look for real solutions that can be put into place as part of their regular business. As we move forward, more and more things like power grid infrastructure and financial infrastructure are becoming software enabled. So one should continue digging deeper into the supply chain and make sure that we really understand where the code is coming from.