Sublime Security’s Josh Kamdjou: The state of today’s email threat landscape and how to defend without reinventing the wheel
Aug 1, 2023
auto_awesome
Josh Kamdjou, CEO of Sublime Security, discusses the evolving email threat landscape and the need for better tools. He shares his journey in security, highlights the types of business email compromise fraud, and explains Sublime's approach to product development. The podcast also explores successful defense strategies, future trends in security operations, and Sublime Security's plans for the next year.
Sublime Security allows security teams to have more control over their email security by building custom detection rules and closing gaps in traditional approaches.
Top security teams prioritize the fundamentals, such as setting up MFA, deploying EDR tools, and implementing email security solutions, before moving on to advanced security measures.
Deep dives
Sublime Security: Empowering Security Teams
Sublime Security is an open and adaptable email security platform that aims to give security teams control over their email security. Traditional approaches to email security rely on black box solutions, leaving security teams reliant on vendors. Sublime Security allows teams to build custom detection rules and have more control over their email environments. By closing gaps and implementing tried and true concepts, teams can better protect against phishing attacks, malware, and business email compromise. Sublime Security also emphasizes collaboration with the security community, offering their platform for free and encouraging the sharing of detection rules. The ultimate goal is to enable security teams to do more with less, automating manual tasks and focusing on higher-value work.
The Importance of Focusing on Security Basics
Top security teams understand the importance of focusing on the fundamentals before diving into more advanced security measures. This involves having MFA set up on all systems, deploying endpoint detection and response (EDR) tools, and implementing email security solutions like Sublime Security. By prioritizing the basics, teams can mitigate a significant amount of risk and create a solid foundation for advanced security operations. It is essential to have a hierarchy of needs in place and ensure that the fundamentals are in place before moving on to more advanced security measures.
The Future of Security Operations
In the next five years, security teams will continue to do more with less, leveraging automation tools to enhance their operations. Tools like Tines and Sublime Security play a crucial role in this future by providing teams with the means to automate manual tasks, detect and prevent common security issues, and gain control over their environments. Additionally, the use of generative AI and chat GPT-like tools can greatly enhance security operations, providing robust memory and recall capabilities for investigations. The future of security operations will focus on empowering teams, enabling collaboration, and leveraging advanced technologies to strengthen defenses.
The Future Plans of Sublime Security
Sublime Security has an exciting roadmap ahead, with a focus on improving detection efficacy and prevention capabilities. They are working on enhancing credential phishing detection, making malware and ransomware detection more robust, and integrating with other best-in-class tools for enriched context and detection capabilities. Sublime Security aims to continuously improve their platform and provide security teams with the tools they need to effectively protect against emerging threats. They believe they are just getting started and have many exciting updates and features planned for the future.
In the first episode of this season of The Future of Security Operations podcast, Thomas speaks to Josh Kamdjou, founder and CEO of Sublime Security, the world's first open and adaptable email security platform, preventing email attacks using Detection-as-Code and behavioral AI.
Josh has more than 13 years of experience in the security industry, doing a mix of government work and private consulting before founding Sublime Security in 2019. Josh holds a B.Sc. in Computer Science from the University of Maryland and is a regular speaker at security conferences and workshops.
Topics include:
Josh’s interesting path into security started with his career working with the government.
How the approach to email security has changed over the last 10 years.
The gap and lack of tooling that Josh discovered in email security led to the founding of Sublime Security.
The types of business email compromise fraud that are still working today and how the threat landscape has changed.
Moving from consultancy to creating a product and securing Sublime’s first customers.
Putting yourself in your customers’ shoes to aid discovery and build a better product.
How Josh’s experience working in government and industry shaped his approach to how he builds Sublime’s product.
What companies are doing to successfully defend against email threats.
Where security operations might be in five years and how teams will be doing more with less.