John Pescatore mulls how security has changed since his early IT days with the U.S. Secret Service.
Like many industry analysts, Gartner’s John Pescatore got his start working hands-on with technology. He began his career at government agencies, including the U.S. Secret Service.
Like many industry analysts, Gartner’s John Pescatore got his start working hands-on with technology. He began his career at government agencies, including the U.S. Secret Service, then spent 11 years at GTE. Now a vice president and Gartner fellow, covering security and privacy, Pescatore recently discussed his beginnings in IT with Network World Senior Editor Denise Dubie and revealed how he has watched the hot market evolve over more than 25 years.
Tell me about your start in IT security.
I came right out of college in 1978 and went to work for the government at the National Security Agency. That was before network security and computer security; it was all about information security and communications security. From there, I stayed in the government for about another four years and went to work for the U.S. Secret Service, where I still worked building secure systems. Nobody back then called it an IT department, but we were building IT systems for specific uses in law enforcement in that case.
Then I left the government and went to private industry, working at GTE for 11 years. I worked there mostly as a defense contractor building secure computing systems for the intelligence community. That job had a lot of worries about secure computing systems before the Internet, such as things called the Orange Book and NSA requirements for multilevel security. That was in the 1985-to-1990 time frame.
What made you decide to move from working with technology to doing market analysis and advising others?
Working in that world, I realized even back then that security people were making this way too complex. And back then the world of computers was basically [Digital Equipment Corp.] VAXes and dumb terminals, which was beyond the mainframe but was still only DEC VAXes and dumb terminals, and the PC was just starting to come onto the scene. That is what influenced me to say, wait a minute, if security can only keep saying no to the business, then it is going to fail. That is what we saw happening in the government world of multilevel security. It just failed and went away. So after working at GTE for 11 years, both on government projects and working with the commercial side of GTE on projects, I realized it was time for a change for me. But I did some work with vendors that opened my eyes too.
What did you do on the vendor side of the business?
I worked for security-product vendors for three years, in the firewall and industries, running consulting groups, helping companies set up security policies, architecture and organizations. And once again it reinforced for me that people in security were saying no and trying to stop things from happening, instead of saying, here’s how we can do what the business needs to do securely.
The second thing I learned was the security-vendor industry was taking this approach called defense in depth. What that means to security vendors is a message to customers saying, keep spending on everything you were spending on and buy me, too. And I thought, this is crazy. Most of the times when you’re doing consulting you’re telling people, wait a minute, in the name of defense in depth you have three products doing basically the exact same thing. That’s why in 1999, I went to Gartner.
How did you make the transition?
It was somewhat by accident, like most of my career has been. If you stay in one place long enough, like I was at GTE for 11 years, you take over a lot of responsibility. I managed all our research-and-development funds, and with all our capital equipment and technology investment, I owned the budgets basically. In order to do that job, you really had to be an analyst to decide, OK, I have this amount of money for R&D, capital equipment and software, and we have these business units making these requests, how do I analyze the requests against the business, against our company’s needs, against are these projects sufficient and complete. Toward the end of 11 years there, I realized I was not doing engineering. My degree is in electrical engineering, but I was not building anything. I was analyzing what other people want to do, where they saw their own little piece, and I was comparing that against the needs of the big picture. That is how I started making recommendations to the head of our business unit about where we should spend money and how we should think it through. I was writing a lot of reports and researching technologies, so when the opportunity came to become an analyst, I realized they do the same thing, but instead of for one company, they do it for lots of companies.
What experience from working with security technologies do you think helps you now as an industry analyst?
There are a couple key things you need to do as analyst. It’s easy to say see the big picture, but you have to also realize the big picture isn’t the same for everyone. The easy thing for an analyst is to say, this is what should be done. But you also have to look at what can be done realistically and what has to be done. Again, defense in depth in theory is great, and we can all say, security is not a destination, it’s a journey. But if you are on a journey, you have to know where you are going, and you have to decide which road to take, and you can’t just decide to do everything. Dealing with constrained R&D budgets and 50 people wanting to spend five times more than what you have, you have to make trade-offs.
How do you advise clients to compromise when it comes to security? It seems that might be a difficult area to justify scrimping on budget dollars.
Security is all about prioritization, risks and trade-offs. You can’t just buy everything the vendors want to throw at you and you can’t just say yes to every project the business units want. Security is all about reaching the compromise point of doing all you can do and ending up as safe as you can be at that moment.
What does working at Gartner help you understand about the issues in network security today?
Half the week at Gartner, I am on the phone with enterprise clients. I think that has actually opened my eyes. I have had my experience working in IT over the years, but 11 years with GTE — that is one company in one industry. In one week at Gartner, I am talking to 20 clients from 20 different companies and five different industries. That is the part that helps.
How does talking with multiple enterprise organizations compare to your own hands-on experience with technology?
A lot of those systems built for the NSA are built for what they call analysts, but they mean intelligence analysts. What intelligence analysts do is examine little pieces of data to determine if there are weapons of mass destruction there or not. Of course, it’s very publicly visible when they are right or when they are wrong. But they always have an incomplete picture, and they are getting input from a lot of sources. Analysts have to spot the pattern, identify the trend.
It’s the same thing. My experience in IT working in one place for such a long time, I know the pattern of how GTE operated. But at Gartner, talking to so many clients, I can spot patterns of what our clients really need. And when vendors come along talking about building something that fits the bill, we tag it as a vision, because where they are heading lines up with where we see end-user organization going.
What about when the trend-setters are wrong? How do you deal with overhyped technologies?
On the flip side, vendors and people like you in the press will call up and ask us to comment on, say, the integration of physical and information security, wanting to know why that is the hot new trend. And I have to say no, there is not a trend. There are a couple clients maybe buying badge systems, but there is not a widespread trend. There is a lot of talk that isn’t happening in practice, and working in IT helps you realize the real world constraints that IT security people operate in vs. anybody studying a security book and making recommendations about defense in depth. Analyst companies that talk with enterprise companies is where the reality is. To be honest, that is why I have stayed with Gartner so long. Without the enterprise client interaction, your recommendations are hopeless.
In what ways have you seen security evolve over the years?
Security today really has almost no power to say no. It is by far the biggest change, which started in the early 1980s with the emergence of PCs and the Internet. If a new technology or even just business process comes along and the business can make money with it, then the business is going to do it. Instead of saying, no we don’t do wireless. Now security has to say, OK we have to do wireless, so how can we do it securely.
It seems there are a lot more malicious threats to deal with as well. What are your thoughts on managing risk?
Another big change has been with the threats. They have gotten so much more motivated. This has been since 2003 really. Everything prior to 2003 in terms of threats was worms and viruses and sort of an annoyance. And sometimes the annoyance would impact the business, but it was more like a power outage in that it affected everybody equally. Since then, there is financial motivation with these attacks, and there is a real and big business impact when it happens. That has put the pressure on security to do more than just say after the fact, see I told you not to do that.
How does the security industry today compare to the field you entered into after college?
There has been a gold rush toward security, because it has become so visible, it gets so much press and money is being thrown at it by venture capitalists. Ten years ago security was like a little club, with a handful of people doing it. It was almost like open source in the old days; everyone worked together, and it was all for the good of being more secure. As the money started exploding, a lot of snake oil started to creep in. It’s sort of just like any other market these days. That’s been a big change. It’s no longer the religion or cause that it once was. It’s just another market.




