THANK YOU FOR SUBSCRIBING
Marc Ashworth, Senior VP and Chief Information Security Officer, First BankIn an interview with Enterprise Networking Magazine, Marc Ashworth, Chief Information Security Officer, First Bank, shares his insights on the current and future challenges and trends in the networking and cybersecurity space.
Could you explain your day-to-day responsibilities at First Bank? How has your experience over the years prepped you for this role?
I started my professional journey as a programmer. Over time, I transitioned from full-time programming to server and networking support. This shift allowed me to consult for numerous companies, providing services spanning networking, programming, server and desktop support, architecture, and security. This diverse experience served as a valuable foundation for my later roles.
In the last 20 years, my roles have primarily been high-level management, mostly within smaller companies. In these roles, I worked alongside my team to perform tasks like system updates, hardware installations, and switch configurations. This hands-on experience, combined with years of security oversight, solidified my understanding of the intersection between information technology and security.
About six years ago, I joined First Bank as the head of security, which included oversight of the security and networking teams. The synergy between these two teams has been instrumental in managing our network infrastructure and data monitoring. On the one hand, the networking team focuses on maintaining the network’s performance, quickly spotting and resolving technical issues. On the other hand, the security team monitors the network for any anomalies or potential malicious traffic to ensure proper governance and safety of our systems. The introduction of Software Defined Networking (SDN) and the subsequent architectural improvements have enabled rapid network setups for new branches, reducing the deployment time from 90 days or more to just a day or two.
“Supplementing micro-segmentation with other security controls like identity management with multifactor authentication and the principle of least privilege access enhances its effectiveness.”
In my current role at First Bank, I supervise four distinct groups: network services, the security team, physical security, and the financial crimes unit. Although these groups operate in similar domains, their responsibilities vary considerably, contributing to a robust internal infrastructure.
What are some of the challenges facing contemporary networking space?
Navigating the modern networking landscape presents a variety of challenges. Some of the most prominent ones include data transportation and security. The key challenge is the swift, reliable, and secure transportation of the vast amount of data generated today. Finding suitable carriers that align with your business needs and goals is an essential part of this process.
Alongside the need for rapid and efficient data transportation, the cybersecurity threats have escalated significantly. Networks are facing dozens of potential threats per second, demanding continuous vigilance and robust security measures. It is crucial to ensure that the perimeter equipment is not just secure but consistently updated with the latest patches.
Maintaining the health and efficiency of the network’s infrastructure is another ongoing challenge. This includes monitoring the network for any possible issues, ensuring the effective operation of failover systems, and checking for any problems related to the Border Gateway Protocol (BGP).
The contemporary networking landscape demands a delicate balance of quick and secure data transportation, constant vigilance against cybersecurity threats, and maintaining a reliable, well-functioning network infrastructure.
Considering emerging technologies, what would you identify as the key industry trends to watch for in the next 12 to 18 months?
With emerging technologies continually reshaping the landscape, several industry trends are worth noting in the near future. Remote work, a significant development spurred on by the COVID pandemic, appears to be a permanent fixture for many organizations. Consequently, ensuring secure remote capabilities has become paramount. Applying principles of least privilege access—providing individuals access to only what they absolutely need—will be crucial to network security in this remote era.
Further, the Software-as-a-Service (SaaS) market is expected to continue its growth trajectory. Alongside this, we anticipate a rise in next-generation virtual VPN solutions offering more granular access control. These developments align with the increasingly adopted principles of ‘Zero Trust’ security models, which essentially mean never implicitly trusting any individual or system, even those already inside the network’s perimeter. The focus will increasingly shift towards limiting access strictly to necessary systems, applications, and data, controlled at the network level. Such granular control is expected to become integral to SaaS and various VPN solutions.
Multifactor authentication will also remain a crucial security measure. Simultaneously, there’s a push towards a passwordless environment, making access both more secure and user-friendly. This move towards passwordless authentication, coupled with secure remote access and the continuing rise of SaaS, will shape industry trends in the near future.
Could you recommend some of the practices you’ve implemented for network and data protection that have yielded positive outcomes?
One of the best practices I strongly advocate for is micro-segmentation. Implementing micro-segmentation is advantageous for all sizes of organizations, from small firms to multinational corporations. Essentially, this process involves partitioning your network based on different parameters such as application type or device. Then, within these segments, only allow the protocols, ports, and users required for that particular system or application.
Micro-segmentation serves a crucial role in preventing lateral movement within your network. This is a common tactic used by adversaries or malicious software like ransomware, where they try to spread within your network, either to exfiltrate data or cause further harm. By segmenting your network, you can effectively halt such lateral movements. Supplementing micro-segmentation with other security controls like identity management with multifactor authentication and the principle of least privilege access enhances its effectiveness. When combined, these practices significantly mitigate risks, enhancing the overall security posture of the organization.
What advice would you give to your peers and aspiring professionals in the field to help them navigate current challenges while keeping pace with upcoming trends?
My advice would be to always focus on future-proofing your network and your environment, rather than merely addressing present needs. The adoption of SDN, including technologies like SD-WAN, and automation, will be critical in shaping future-ready networks.
It’s important to understand that enhancing your network’s security posture is a journey, not an overnight process, especially in a large, well-established environment. It may take a year or more to fully implement changes, but patience is vital. The resulting benefits and the significant risk reduction will be well worth the effort. So, it is always better to maintain a future-oriented perspective, prioritize network security, and embrace the gradual process of improvement.
Bio
Marc Ashworth, Senior Vice President and Chief Information Security Officer at First Bank, is a respected IT executive with over 30 years of experience in cyber and physical security, IT/security architecture, project management, author, and a public speaker. He is a member of the Webster University Cyber Advisory board, Co-Founded the State of Cyber annual security conference, and is a Lifetime member of the FBI Citizens Academy, and has security certifications in CISSP, CISM, CRISC, and Security+. Mr. Ashworth currently oversees First Bank’s information security, fraud, physical security, and network services departments. You may reach him at Marc.Ashworth@fbol.com, Marc@AshworthCorp.com, or via LinkedIn at https://www.linkedin.com/in/marcashworth/ .
Read Also