Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2023 Q&A: Fortra Will Showcase Its Breadth of Solutions and Services – Data Protection and Infrastructure Protection All Under One Portfolio

Share: 

David Marshall | Published: July 27, 2023

 

Are you getting ready for the upcoming Black Hat USA 2023 event, an internationally recognized cybersecurity event providing the most technical and relevant information security research, now in its 26th year.  The event is quickly approaching, taking place August 5-10, 2023, returning to the Mandalay Bay Convention Center in Las Vegas, NV with a 6-day program. 

Ahead of the show, VMblog received an exclusive interview with Antonio Sanchez, Principal Evangelist, Fortra, a global cybersecurity software and services provider.  Make sure to get them on your MUST SEE list.

Fortra Logo 

VMblog: Before we get into it, can you give us a quick overview of the company?  What should folks know?

Antonio Sanchez: Fortra is a global cybersecurity software and services business, and many of your readers will be familiar with us as HelpSystems. The company rebranded last year because we wanted to be more synonymous with security. We’ve grown from an organization with heritage in IBM i and supporting IT teams with automation software, to a security company with a unique and comprehensive suite of industry leading solutions and services. Readers might recognize names such as Core Security, Digital Defence, Cobalt Strike, Outflank and Terranova Security. These are just some of the solutions and services we’ll be showcasing at Black Hat.

VMblog: You are sponsoring the upcoming Black Hat USA event.  How can attendees find you at the show?  Does your booth have a theme?  How many folks are you sending? 

Sanchez: Visitors to Black Hat can find us on booth #1340, where they can see our offensive security tools and how they can be layered to achieve a more mature security posture. Organizations need to be proactive in their defense against today’s cybersecurity threats and using these tools helps them “think like a threat actor” to “expose and close” security gaps before it’s too late. We’ll have solutions engineers on the booth who can talk through the benefits of this layered approach.

Several members of our senior leadership team will be joining us; our President, Matthew Schoenfeld, and our Associate VP of Research & Development, Bob Erdman. They’ll be talking about our recent collaboration and efforts alongside Microsoft’s Digital Crimes Unit (DCU) and Health-ISAC in preventing cybercriminals from abusing security tools. We encourage people to visit the booth to find out more.

VMblog: Is this your first time sponsoring Black Hat?  If not, how many times have you sponsored before?  And, what keeps you coming back?

Sanchez: This year is the first time we’ve sponsored Black Hat as Fortra. Last year, visitors would have seen Digital Guardian’s booth showcasing our data protection solutions for data loss prevention, data classification, and secure collaboration. This year, as Fortra, visitors will get a real sense of the breadth and depth of our solutions by seeing our data protection solutions and those for infrastructure protection all under one portfolio.

It’s hard to believe that Black Hat as an event is over 25-years old. It’s grown into one of the most well respected, “must-attend” events on the security community’s calendar and what keeps us coming back each year as sponsors is the quality of visitors it attracts. This is due in part to the fact that the event’s review board is made up of over 100 industry professionals, which keeps the briefings and trainings technically relevant for practitioners to hone their skills and stay abreast of industry trends. It also provides a great forum for networking and collaboration.

VMblog: What is your message to Black Hat attendees coming out to the show this year?

Sanchez: To answer this, I’ll go back to my earlier point about the breadth and depth of our portfolio. As a single vendor, we can help organizations address multiple parts of your security infrastructure. You may not recognize us yet as Fortra, but we’re likely already working with you from a point product solution. Come and see how we’re integrating our solutions to unlock new use cases and solve complex problems. Ask us about how we’re developing a platform to simplify operational management.

VMblog:  The show is focused on cybersecurity.  What specific problems is your company and technology addressing?

Sanchez: Organizations today are facing an unprecedented level of threats, and often they simply do not know which ones pose the highest risk and therefore which ones they should address first. The goal is operational resilience, but what’s the best approach? We’re helping customers adopt a proactive approach to security by using the same techniques as the threat actors who target them. This helps organizations expose where they are most vulnerable and prioritize their remediation efforts.

VMblog:  What are some of the key takeaways of your solution that Black Hat attendees should be aware of?

Sanchez: I would echo what I said earlier, mirroring the techniques used by threat actors is a very proactive way to evolve your security. Let me share this example, we recently tested the defenses of a large multi-national manufacturing company by performing pen testing (using Fortra’s Core Impact) alongside attack simulation in a controlled environment (using Fortra’s Cobalt Strike). This exercise harvested 900 user credentials, including multiple Domain Admins. An attack of this nature would allow a threat actor to take over the organization’s entire domain. “Exposing and closing” this risk makes a significant impact on that organization’s operational resilience.

VMblog:  The market is a crowded space.  What is it about your company and technology that sets you apart from the competition?  What are your differentiators?

Sanchez: Having the right security tools in place is one piece of the puzzle, the other is having the necessary resources to optimize their configuration and management. When organizations work with Fortra, we offer more than just the tools to get the job done, we also offer a range of managed security services. This helps organizations alleviate the skills gaps that’s so keenly felt in the industry right now as well as improving their security maturity.

Through Fortra’s Alert Logic managed detection and response service, we can help reduce the likelihood and impact of a cyberattack. Through Fortra’s Digital Guardian managed data loss prevention, organizations can leave data protection to the experts so they can focus on their core business.

That’s from a solutions perspective. We also work with various enforcement agencies to disrupt and takedown infrastructure being used by threat actors. We can do this because of significant investments in R&D that allow us to do things beyond building great products.

VMblog:  Is your company launching anything new at the show?  Can you give us a sneak peek?

Sanchez: Yes, we’re officially launching new integrations of our offensive security tools. The integrations allow customers to benefit from automation, and shared functions and resources. There are five different configurations available:

  • Essentials – Combines Fortra’s Frontline Vulnerability Manager (Frontline VM), the industry’s most comprehensive SaaS vulnerability management solution, with Fortra’s powerful penetration testing platform, Core Impact, to scan, evaluate and prioritize security vulnerabilities throughout a customer’s network.
  • Advanced – Combining Fortra’s penetration testing and threat emulation software solutions, Core Impact and Cobalt Strike, provides a robust view of vulnerabilities through advanced ransomware and phishing simulations and comprehensive reporting, while also giving teams the ability to collaborate in real time.
  • Elite – combines Frontlines VM, Core Impact and Cobalt Strike allowing customers to evaluate security, identify vulnerabilities and proactively reduce risk. These combined vulnerability management, penetration testing and threat emulation tools run at the same time and are interoperable, streamlining the process to identify, remediate and simulate vulnerabilities.
  • Red Team – Built to integrate seamlessly into Cobalt Strike’s flexible command and control framework, Outflank’s Offensive Security Tooling extends a company’s red teaming capabilities. Together, these tools can deploy more sophisticated adversary simulation and assess overall security posture and vulnerability.
  • Advanced Red Team – combines Core Impact, Cobalt Strike and Outflank’s Offensive Security Tooling to safely evaluate security gaps, defenses and security strategies using the same strategies as today’s threat actors. Together, these solutions provide a holistic security testing methodology for advanced red teamers.

Visit the booth to find out more!

VMblog:  What will you be showing off at the show this year?

Sanchez: At Black Hat, we’re delighted to have our colleague, Max Grim, join us from Fortra’s Outflank. Based in Amsterdam, Outflank’s team of experts employ ethical hacking methods that closely mimic those of cyber criminals. Outflank Security Tooling (OST) is their cloud-based software offering for red teams and in a speaking session on Wednesday Aug 9 at 2:25pm (in business hall theater C), Max will take a deep dive into the capabilities of the OST toolkit.

VMblog:  What are some of the top priorities you believe attendees at Black Hat should be considering for 2023/2024?

Sanchez: Identifying and keeping up with the next new attack vector is challenging. There’s always something on the horizon. How do organizations prepare for these attacks? How do they ensure their defenses are strong enough to thwart them? How can they limit the impact the attack would have? Fortra can help organizations address these priorities and take their vulnerability management programs to the next level as we regularly update our offensive security solutions with the latest tactics, techniques, and procedures (TTPs) used by malicious actors so organizations can test their defenses against them.

VMblog:  What are some of the security best practices you would deem critical?

Sanchez: Employees play a key role in reducing the likelihood of a cyber-attack. It only takes one click on a malicious link for a phishing attack to be successful. That’s why it’s essential to implement security awareness training, to monitor employee behavior, test their willingness to comply with best practices, and ultimately help build a culture of security awareness. This will significantly reduce an organization’s risk. We invite organizations to benchmark their phishing resilience and sign up for Fortra’s Gone Phishing Tournament. It takes place in October during Cybersecurity Awareness Month and provides insightful data to help organizations enhance their programs. Registrations remain open until the end of September.  

As well as reducing the likelihood of an attack, organizations need to think about how quickly and how well they’d recover from one if it was successful. Another important best practice is to test, evaluate and refine business continuity plans on a regular basis.

VMblog:  If you were presenting on the keynote stage, what trends do you see that companies should be paying special attention to in 2023 and beyond?

Sanchez: There’s definitely a trend towards more industry collaboration. We’re all fighting the same adversaries so let’s come together as a community and work on these challenges together. Earlier I mentioned our collaboration with Microsoft DCU and Health-ISAC, we welcome more of this type of partnership. It’s only by coming together that we can overcome the scale of the threats we face.

VMblog:  Is your company giving away any interesting tchotchke at your booth?  What is it?

Sanchez: Our swag at this year’s event is both functional and good for the planet. The coveted Fortra water bottle will be on the booth as a giveaway. It’s great quality and something I use every day. Working booths and walking around exhibition halls is thirsty work, so come by and grab one.

VMblog:  Is your company involved in any parties during the event?

Sanchez: As an organization that offers remote working, events like these provide the ideal opportunity to meet with colleagues, some of whom we’ve not met face to face with before. Diaries get busy with customer meetings but we always have a team night, where we go out for a meal together. In Vegas, it’s never too hard to find somewhere to have a fun evening. Fremont Street is a short cab ride away. It’s a different experience to the strip, with a good selection of restaurants, outdoor stages offering live music, and outdoor light shows in the evening – there’s even a zipline several stories high for the brave.

VMblog:  As a show sponsor, do you have any tips for attendees to better prepare for the conference?

Sanchez: It’ll be the height of summer, so my advice would be to get your fresh air in the morning before it’s too hot and drink plenty of water (from your new Fortra water bottle) to stay hydrated.

##