Oct 26, 2017 · 22m · mad

Cybersecurity Data at Scale // Sam Kassoumeh & Bob Sohval, SecurityScorecard (Data Driven)

Dr. Bob Sohval · 13m spoken Sam Kassoumeh · 5m spoken Matt Turck · 33s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this Data Driven NYC presentation and panel discussion, SecurityScorecard co-founder Sam Kassoumeh and Data Science Director Dr. Bob Sohval explain how non-intrusive, internet-scale data collection and machine learning models quantify corporate cybersecurity risk and predict potential security breaches.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Matt holds 3.7% of the talking time here. How this is scored →

Matt as informed peer 0.4 Guest teaching 3.3 Guest disagreement 0.4 Matt pushing back 0.1
05100:0010:0020:001:21–4:07 · Matt as informed peer 0/10 Becoming the Vocabulary of Risk This segment is an uninterrupted presentation monologue by guest Sam Kassoumeh explaining the need for a common vocabulary of cybersecurity risk. The host does not speak, requiring all host-side scores to be zero. Kassoumeh uses accessible analogies like ordering at Chipotle to illustrate communication barriers in security.4:07–6:58 · Matt as informed peer 0/10 Scale of Data Consumption and Storage Dr. Bob Sohval delivers a slides-based presentation covering company scale, IP attribution, and grading methodology. The host is inactive during this presentation segment. Sohval educates the audience on how open ports, honeypots, and sinkholes feed their A-F rating rubric.6:58–9:37 · Matt as informed peer 0/10 Core Data Science Pillars at SecurityScorecard Bob Sohval outlines core data science pillars including distinguishing corporate IPs from leased residential IPs and norm-based scoring. The host does not participate in this monologue. The tone is informative and technical.9:37–14:09 · Matt as informed peer 0/10 Case Study: Organizational Health and Insecure Browsers Sohval presents case studies on insecure browser usage and details structural obstacles in breach prediction like underreporting and reporting time lags. Host is absent from the dialogue. Sohval highlights that industry average breach detection takes five months.14:09–16:29 · Matt as informed peer 0/10 Bayesian Relative Breach Likelihood Model Sohval concludes the formal presentation with a Bayesian relative likelihood ratio model showing poor scores carry a 5x breach risk factor. The host only speaks at the very end to thank the speakers and transition to Q&A. Host scores remain zero due to lack of substantive host commentary.16:29–19:08 · Matt as informed peer 2/10 Panel Q&A: Dark Web Crawling Techniques Host Matt Turck joins the guests on stage and asks a direct question regarding dark web crawling techniques. Sam Kassoumeh lightheartedly jokes before detailing their web crawling methods on hacker forums. Turck synthesizes the core takeaway regarding outside-in data collection.19:08–22:34 · Matt as informed peer 1/10 Panel Q&A: Anticipating Breaches and Equifax Rating The panel takes audience questions on portfolio aggregation and Equifax's pre-breach rating. Bob Sohval and Sam Kassoumeh explain Equifax was in the B/C range and break down patching cadence as a key predictor. Matt Turck moderates the microphone and concludes the session.1:21–4:07 · Guest teaching 2/10 Becoming the Vocabulary of Risk This segment is an uninterrupted presentation monologue by guest Sam Kassoumeh explaining the need for a common vocabulary of cybersecurity risk. The host does not speak, requiring all host-side scores to be zero. Kassoumeh uses accessible analogies like ordering at Chipotle to illustrate communication barriers in security.4:07–6:58 · Guest teaching 3/10 Scale of Data Consumption and Storage Dr. Bob Sohval delivers a slides-based presentation covering company scale, IP attribution, and grading methodology. The host is inactive during this presentation segment. Sohval educates the audience on how open ports, honeypots, and sinkholes feed their A-F rating rubric.6:58–9:37 · Guest teaching 3/10 Core Data Science Pillars at SecurityScorecard Bob Sohval outlines core data science pillars including distinguishing corporate IPs from leased residential IPs and norm-based scoring. The host does not participate in this monologue. The tone is informative and technical.9:37–14:09 · Guest teaching 4/10 Case Study: Organizational Health and Insecure Browsers Sohval presents case studies on insecure browser usage and details structural obstacles in breach prediction like underreporting and reporting time lags. Host is absent from the dialogue. Sohval highlights that industry average breach detection takes five months.14:09–16:29 · Guest teaching 4/10 Bayesian Relative Breach Likelihood Model Sohval concludes the formal presentation with a Bayesian relative likelihood ratio model showing poor scores carry a 5x breach risk factor. The host only speaks at the very end to thank the speakers and transition to Q&A. Host scores remain zero due to lack of substantive host commentary.16:29–19:08 · Guest teaching 3/10 Panel Q&A: Dark Web Crawling Techniques Host Matt Turck joins the guests on stage and asks a direct question regarding dark web crawling techniques. Sam Kassoumeh lightheartedly jokes before detailing their web crawling methods on hacker forums. Turck synthesizes the core takeaway regarding outside-in data collection.19:08–22:34 · Guest teaching 4/10 Panel Q&A: Anticipating Breaches and Equifax Rating The panel takes audience questions on portfolio aggregation and Equifax's pre-breach rating. Bob Sohval and Sam Kassoumeh explain Equifax was in the B/C range and break down patching cadence as a key predictor. Matt Turck moderates the microphone and concludes the session.1:21–4:07 · Guest disagreement 1/10 Becoming the Vocabulary of Risk This segment is an uninterrupted presentation monologue by guest Sam Kassoumeh explaining the need for a common vocabulary of cybersecurity risk. The host does not speak, requiring all host-side scores to be zero. Kassoumeh uses accessible analogies like ordering at Chipotle to illustrate communication barriers in security.4:07–6:58 · Guest disagreement 0/10 Scale of Data Consumption and Storage Dr. Bob Sohval delivers a slides-based presentation covering company scale, IP attribution, and grading methodology. The host is inactive during this presentation segment. Sohval educates the audience on how open ports, honeypots, and sinkholes feed their A-F rating rubric.6:58–9:37 · Guest disagreement 0/10 Core Data Science Pillars at SecurityScorecard Bob Sohval outlines core data science pillars including distinguishing corporate IPs from leased residential IPs and norm-based scoring. The host does not participate in this monologue. The tone is informative and technical.9:37–14:09 · Guest disagreement 0/10 Case Study: Organizational Health and Insecure Browsers Sohval presents case studies on insecure browser usage and details structural obstacles in breach prediction like underreporting and reporting time lags. Host is absent from the dialogue. Sohval highlights that industry average breach detection takes five months.14:09–16:29 · Guest disagreement 0/10 Bayesian Relative Breach Likelihood Model Sohval concludes the formal presentation with a Bayesian relative likelihood ratio model showing poor scores carry a 5x breach risk factor. The host only speaks at the very end to thank the speakers and transition to Q&A. Host scores remain zero due to lack of substantive host commentary.16:29–19:08 · Guest disagreement 1/10 Panel Q&A: Dark Web Crawling Techniques Host Matt Turck joins the guests on stage and asks a direct question regarding dark web crawling techniques. Sam Kassoumeh lightheartedly jokes before detailing their web crawling methods on hacker forums. Turck synthesizes the core takeaway regarding outside-in data collection.19:08–22:34 · Guest disagreement 1/10 Panel Q&A: Anticipating Breaches and Equifax Rating The panel takes audience questions on portfolio aggregation and Equifax's pre-breach rating. Bob Sohval and Sam Kassoumeh explain Equifax was in the B/C range and break down patching cadence as a key predictor. Matt Turck moderates the microphone and concludes the session.1:21–4:07 · Matt pushing back 0/10 Becoming the Vocabulary of Risk This segment is an uninterrupted presentation monologue by guest Sam Kassoumeh explaining the need for a common vocabulary of cybersecurity risk. The host does not speak, requiring all host-side scores to be zero. Kassoumeh uses accessible analogies like ordering at Chipotle to illustrate communication barriers in security.4:07–6:58 · Matt pushing back 0/10 Scale of Data Consumption and Storage Dr. Bob Sohval delivers a slides-based presentation covering company scale, IP attribution, and grading methodology. The host is inactive during this presentation segment. Sohval educates the audience on how open ports, honeypots, and sinkholes feed their A-F rating rubric.6:58–9:37 · Matt pushing back 0/10 Core Data Science Pillars at SecurityScorecard Bob Sohval outlines core data science pillars including distinguishing corporate IPs from leased residential IPs and norm-based scoring. The host does not participate in this monologue. The tone is informative and technical.9:37–14:09 · Matt pushing back 0/10 Case Study: Organizational Health and Insecure Browsers Sohval presents case studies on insecure browser usage and details structural obstacles in breach prediction like underreporting and reporting time lags. Host is absent from the dialogue. Sohval highlights that industry average breach detection takes five months.14:09–16:29 · Matt pushing back 0/10 Bayesian Relative Breach Likelihood Model Sohval concludes the formal presentation with a Bayesian relative likelihood ratio model showing poor scores carry a 5x breach risk factor. The host only speaks at the very end to thank the speakers and transition to Q&A. Host scores remain zero due to lack of substantive host commentary.16:29–19:08 · Matt pushing back 1/10 Panel Q&A: Dark Web Crawling Techniques Host Matt Turck joins the guests on stage and asks a direct question regarding dark web crawling techniques. Sam Kassoumeh lightheartedly jokes before detailing their web crawling methods on hacker forums. Turck synthesizes the core takeaway regarding outside-in data collection.19:08–22:34 · Matt pushing back 0/10 Panel Q&A: Anticipating Breaches and Equifax Rating The panel takes audience questions on portfolio aggregation and Equifax's pre-breach rating. Bob Sohval and Sam Kassoumeh explain Equifax was in the B/C range and break down patching cadence as a key predictor. Matt Turck moderates the microphone and concludes the session.

speaking balance: gold is Matt, purple is the guest (3 minute bins)

0:00 · Matt 0% · guest 100%0:00 · Matt 0% · guest 100%3:00 · Matt 0% · guest 100%3:00 · Matt 0% · guest 100%6:00 · Matt 0% · guest 100%6:00 · Matt 0% · guest 100%9:00 · Matt 0% · guest 100%9:00 · Matt 0% · guest 100%12:00 · Matt 0% · guest 100%12:00 · Matt 0% · guest 100%15:00 · Matt 16.1% · guest 83.9%15:00 · Matt 16.1% · guest 83.9%18:00 · Matt 9.7% · guest 90.3%18:00 · Matt 9.7% · guest 90.3%21:00 · Matt 5.2% · guest 94.8%21:00 · Matt 5.2% · guest 94.8%
Sharpest disagreement ▶ 16:49 Playful initial deflection regarding dark web sources

When host Matt Turck asks how dark web collection works, Sam Kassoumeh playfully deflects with 'Secret. No, I'm just kidding' before answering, marking the single light pushback moment in a very collaborative session.

Hardest push from Matt ▶ 16:31 Host presses on dark web data collection methodology

Host Matt Turck opens the Q&A by directly probing into how SecurityScorecard gathers dark web data without internal company sensors.

Biggest teaching moment ▶ 11:55 Bob Sohval explains detection time lags and breach reporting delays

Dr. Bob Sohval educates the audience on the hidden complexities of breach prediction, pointing out that breaches take an average of five months to detect and even longer to publicly report.

Matt holds his own ▶ 17:30 Host highlights the key takeaway of SecurityScorecard's outside-in model

Matt Turck demonstrates quick grasp of the platform's core architecture by noting that SecurityScorecard operates entirely non-intrusively without inside corporate data.

the scores for every segment, with the reasoning behind each
ChapterTopicMatt as informed peerGuest teachingGuest disagreementMatt pushing backWhy
Becoming the Vocabulary of Risk 0210 This segment is an uninterrupted presentation monologue by guest Sam Kassoumeh explaining the need for a common vocabulary of cybersecurity risk. The host does not speak, requiring all host-side scores to be zero. Kassoumeh uses accessible analogies like ordering at Chipotle to illustrate communication barriers in security.
Scale of Data Consumption and Storage 0300 Dr. Bob Sohval delivers a slides-based presentation covering company scale, IP attribution, and grading methodology. The host is inactive during this presentation segment. Sohval educates the audience on how open ports, honeypots, and sinkholes feed their A-F rating rubric.
Core Data Science Pillars at SecurityScorecard 0300 Bob Sohval outlines core data science pillars including distinguishing corporate IPs from leased residential IPs and norm-based scoring. The host does not participate in this monologue. The tone is informative and technical.
Case Study: Organizational Health and Insecure Browsers 0400 Sohval presents case studies on insecure browser usage and details structural obstacles in breach prediction like underreporting and reporting time lags. Host is absent from the dialogue. Sohval highlights that industry average breach detection takes five months.
Bayesian Relative Breach Likelihood Model 0400 Sohval concludes the formal presentation with a Bayesian relative likelihood ratio model showing poor scores carry a 5x breach risk factor. The host only speaks at the very end to thank the speakers and transition to Q&A. Host scores remain zero due to lack of substantive host commentary.
Panel Q&A: Dark Web Crawling Techniques 2311 Host Matt Turck joins the guests on stage and asks a direct question regarding dark web crawling techniques. Sam Kassoumeh lightheartedly jokes before detailing their web crawling methods on hacker forums. Turck synthesizes the core takeaway regarding outside-in data collection.
Panel Q&A: Anticipating Breaches and Equifax Rating 1410 The panel takes audience questions on portfolio aggregation and Equifax's pre-breach rating. Bob Sohval and Sam Kassoumeh explain Equifax was in the B/C range and break down patching cadence as a key predictor. Matt Turck moderates the microphone and concludes the session.

Statements from this episode (13)

Insight
Applying data science creates a common vocabulary of risk for cybersecurity
“Because it helps us to create this vocabulary of risk. It's a common language that enables us to have practical conversations across entire organization, whether you're a security practitioner or engineer, or you sit on the board or the audit committee to disc…”
Sam Kassoumeh Oct 26, 2017 ▶ 2:25
Disclosure
SecurityScorecard collects terabytes of data monthly across IPv4 and dark web
“We collect data from the public internet, entire IPvFOR space, as well as the deep web and dark, dark web, and we're collecting terabytes and terabytes of this information every month in a very automated fashion and a non-invasive, non-intrusive fashion using …”
Sam Kassoumeh Oct 26, 2017 ▶ 3:07
Assertion Not checkable as stated
SecurityScorecard monitored around 200,000 entities as of October 2017
“Currently we monitor in the vicinity of some 200,000 entities, mostly companies, but also government organizations, government agencies, hospitals, different organizations.”
Dr. Bob Sohval Oct 26, 2017 ▶ 4:18
Prediction Not checkable as stated
SecurityScorecard aimed to monitor one million entities by the end of 2018
“We plan on growing that to about one million by the end of next year.”
Dr. Bob Sohval Oct 26, 2017 ▶ 4:30
Prediction Not checkable as stated
SecurityScorecard predicted data ingestion would reach petabyte scale by late 2018
“That will grow a factor of six at least next year. And by the end of next year we'll be at the petabyte. Level.”
Dr. Bob Sohval Oct 26, 2017 ▶ 4:37
Disclosure
SecurityScorecard operates proprietary honeypots and sinkholes to detect corporate malware
“We are able, we operate our own bank of sinkholes and honeypots to detect malware on, on systems that are at the, on the companies that we monitor.”
Dr. Bob Sohval Oct 26, 2017 ▶ 6:00
Assertion Supported
Sohval: Corporate digital footprints by IP count span over eight orders of magnitude
“In terms of digital footprint, number of IPs, that spans more than eight orders of magnitude.”
Dr. Bob Sohval Oct 26, 2017 ▶ 8:45
Opinion
Experian's outdated browser usage signals poor security hygiene, says Bob Sohval
“Northwestern Mutual on the left is, is doing a pretty reasonable job of keeping their browser browser use up to date. Experian, not so much. And this is a signal that they're not paying enough attention to security hygiene in, in their company.”
Dr. Bob Sohval Oct 26, 2017 ▶ 10:13
Disclosure
SecurityScorecard observes a 1,000-to-1 ratio of non-breached to breached companies
“The number of non-breached companies, the ratio of non-breached to breached is something like, in our system or our platform, something like a thousand to one.”
Dr. Bob Sohval Oct 26, 2017 ▶ 11:45
Assertion Partly supported
Industry-wide cyber breach detection takes an average of five months
“Industry average is five months.”
Dr. Bob Sohval Oct 26, 2017 ▶ 13:27
Insight
Cyber breach prediction is more accurate on portfolios than individual companies
“And I would say that, ah, in general, breach prediction on portfolios is somewhat easier than for individual entities. The law of large numbers does apply here, and it's easier to make statements at a portfolio level.”
Dr. Bob Sohval Oct 26, 2017 ▶ 13:55
Assertion Not checkable as stated
Companies with poor security scores are five times more likely to breach
“Of the probability of a breach given a poor score versus a good score, and we look at our data, and that is a ratio of five, something like that. So poor scores are predictive of breach.”
Dr. Bob Sohval Oct 26, 2017 ▶ 14:44
Disclosure
SecurityScorecard uses homegrown web crawlers to gather risk signals from hacker forums
“We do have various techniques that we've built homegrown that allow us to essentially crawl on things like hacker forums and vacuum in signals of risk.”
Sam Kassoumeh Oct 26, 2017 ▶ 16:58
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 400 conversations transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.