Interview with MNIT Cybersecurity Experts
10/27/2020 3:40:18 PM
On October 1, 2020, the Minnesota National Guard announced that Stefanie Horvath, Chief Business Technology Officer at Minnesota IT Services (MNIT) for Minnesota Boards, Councils, and Commissions was selected for a duty position at U.S. Cyber Command. U.S. Army Brigadier General Horvath will serve as the Mobilization Assistant to the Director of Operations.
We know that there are many, like Brig. Gen. Horvath, across our agency who ensure that the data on our networks – whether it be local, state, or federal information – is protected and secure. Women, in particular, comprise a growing part of the cybersecurity field. In 2020, 27% of cybersecurity professionals are women, compared to 11% in 2017, according to the (ISC)² Cybersecurity Workforce Study. To wrap up our Cybersecurity Awareness Month in 2020, Horvath led an interview with some of the women in cybersecurity at MNIT.
Horvath spoke with Catherine Scott, Enterprise Governance, Risk, and Compliance Supervisor, Nancy Skuta, Senior Information Security Analyst, Deb Stafford, IAM Security Manager, and Vidya Vadlamani, Access Control Services, who represent a cross-section of security professionals at MNIT. The below is edited and condensed for clarity.
Skuta: I am a senior security analyst on the threat management and vulnerability management team, which is responsible for scanning all of the devices across the state including workstations, servers, and any other devices that touch our networks. We are scanning them for vulnerabilities, but also compliance. Our compliance work checks against federal requirements and the standard for how we build our applications, devices, and services in the State of Minnesota. If we spot a vulnerability, we work with our enterprise and agency partners to deploy fixes.
While we sometimes feel like the bearer of bad news when we bring up those fixes that need to be addressed, we’re working to ensure that all of these systems are fully secure. It’s such great work that we are able to do with our partners because we know there are hundreds and hundreds of vulnerabilities that come out on a daily basis.
Vadlamani: I am the Minnesota Enterprise Identity and Access Management (MNEIAM) lead and a part-time architect for that service. I joined the State of Minnesota in September 2016, and I’ve been working on this product since that time. We manage the identities of end users over their lifecycle, managing their authorization and authentication to systems. We have to make sure that citizens who log into any external-facing applications are able to do so successfully and securely. It’s a 24/7 job to make sure the sites, log ins, and systems are working in good shape.
Identity and access management is so important to making sure that the right people (identities) can access a system. We push people to adopt a good identity and access system and provide MNEIAM as a solution. One system that is incredibly important for MNEIAM is MNsure, which has about 1.5 million people registered, and it’s important that all users can create and keep their accounts safe.
Stefanie Horvath during a cybersecurity exercise at MNIT's Security Operations Center in 2016.
Scott: My path to cybersecurity has not been conventional. I have a liberal arts college degree, went to law school for a couple of years, and do not have an IT background. I started in the policy and legislative area, and moved over to the area of security policy. In my current job, I am the manager of the Governance, Risk, and Compliance (GRC) team.
The thing that I’m most interested in is protecting people’s data and making sure that we’re using it for the purposes we say we’ll be using it. Before, we could collect a lot of information, but you couldn’t necessarily compile it in a meaningful way. New technology gives us better capabilities to understand what the information means. While we know that collecting sensitive information is necessary for certain programs/processes, maintaining it creates risk unless it is secured properly. We want to make sure that we’re clear on why we are collecting that information and make sure that we are maintaining it as securely as possible.
Stafford: When I graduated college as a marketing major, I started at a company where my role focused on consulting for business continuity. That business continuity work led me to cybersecurity. When I fell into the technology-side, I went back and got my master’s degree in Information Technology. I’ve moved around and worked at a lot of the different areas within security at MNIT and ended up in the identity and access area. I’ve been given a lot of opportunities to try different disciplines.
Now, as manager of the identity and access management area, I am responsible for securing the access to state services, applications, and more. We are responsible for understanding who has access to what.
Scott: Some of the ways we can get other women involved is just increasing awareness at the high school and college levels. We know that this is a growing field with a lot of opportunities, and there should be more understanding that depending on the role, a person may not need to have a deep IT background. I know that the state is increasing the recruiting they’re doing around cybersecurity, to help bring awareness to these opportunities.
Within the state, I’ve participated in MNIT’s mentorship program for a number of years. I see that as a way to bring more awareness to the security work. We can encourage those that have taken a more standard path into state government, or work in conventional IT, and may want to branch out, that security is an option. Some of this kind of feeds on itself, the more women that people see at conferences, or presenting as experts on the topic that look like themselves, it becomes more of a norm.
When thinking of skills that women can bring to the table, one thing that is incredibly important is communication and problem-solving skills.
Stafford: I agree that the mentoring program is good for the ability for women, and others looking for new career opportunities, to understand that security is out there as an option. There are all kinds of roles in security like business continuity and GRC, that need someone with analytical skills. Those skills are hard to teach, and can be something that people just naturally have, which I think women in particular are very good at. We want to understand why things are happening, and their cause.
Vadlamani: In my experience, there can still be a mindset that women should be in a supporting role in IT. To get more women excited for this field, we need to work to combat and erase that mindset. We need to know that it’s okay for us to be strong and to be in these powerful roles where we can make a difference. If we can say we can do it, we’ll make it happen.
Nancy Skuta speaking to the Boys & Girls Club during Cybersecurity Awareness Month in 2019.
Skuta: Security is pretty invisible, and people don’t see the number of vulnerabilities that are resolved and never cause us an issue. We need to be behind the scenes, that quiet investigator that is learning what we need to do and sharing it with the teams that need to make those resolutions. What inspired me is that the work is so interesting. Every day is a new day. It’s exciting to see how many groups come together to do this work, to keep our end users up and running safely and securely.
Stafford: I get inspired because I want to make sure that access to state services is easy for the citizen. I love the idea of a One Minnesota, one identity, single sign on, and I keep trying to expand that area. I also try from the employee standpoint to make access as easy as possible to get into your systems. All that to say – process and process-design is what drives me.
I’m a behind the scenes person so it doesn’t really bother me that our work is more invisible. I would much rather have others shine than me. I would much rather have people experience an easy sign on and access to state services than to understand how much goes into cybersecurity.
Vadlamani: It’s a race every day, and the technology is changing at a rapid pace. You have to keep up your skills set to support or improve the systems. It is challenging work that can go unnoticed, but it is necessary to keep these systems up and running. There are so many interdependencies between the access, security, and changing technology, that another challenge we face is making sure we understand how our areas interact with each other. That is the exciting work, learning how all these systems work together and keep up with new technology. We are keeping up with anything happening in the private sector.
Scott: Over the past year, our team has been involved in making significant improvements to improve our ability to communicate security risk to our agency partners and help them prioritize addressing those security risks. The tool gives a comprehensive look at our systems. We need to be able to be able to assess our security risks and communicate exactly where we need to make change to do better. We’re starting a rolling onboard of the tool and it means we’re on a better road.
Skuta: One of the things that our team needed to do when the pandemic hit was to figure out how to scan the desktops, laptops, and other devices while people were working from home. When those systems are no longer on the state’s network, we needed to quickly get our scanning software deployed to all those devices, regardless of whether it’s in St. Paul or Biwabik. Working from home sets up greater challenges for us, for example protecting against phishing campaigns that increased in that time period, so we want to make sure that we have systems that are hardened and it’s difficult for these hacks to occur.
While this interview highlighted a selection of voices and opinions, MNIT would also like to call out and share the names of all the women at MNIT who contribute to securing the State of Minnesota.
Cybersecurity
Cybersecurity
Cybersecurity Month