Cooking Up a Better Cybersecurity Model

Can the solution to cybersecurity dysfunction be found in the kitchen? A chef friend and I think it might be possible.

Cooking Up a Better Cybersecurity Model
Photo by Fabrizio Magoni / Unsplash

I've seen Iron Chef America. I've watched Gordon Ramsay scream at cooks and chefs on multiple TV series. (Seriously, check out the original UK "Ramsay's Kitchen Nightmares" and "The F Word," they're both far more realistic and entertaining than what he's done for US networks) I've enjoyed seeing Anthony Bourdain return to Brasserie Les Halles and try to work a shift as a cook - though admittedly I still need to read Kitchen Confidential. I've watched the workers at my local fast-food haunts run around like people possessed to get orders out quickly and correctly. But I've never worked in a professional kitchen in my life. (Before you go telling me I'm soft, I worked retail for years, so let's just let it go at that OK?)

That's OK, because my friend Jamison has. He also has had the opportunity to develop mobile apps on both Android and iOS platforms as he shifts his career focus to cybersecurity. As we started talking about careers and experiences, we came to understand that perhaps we've built the wrong model for our cybersecurity functions within organizations, and by looking around at our experiences both in and out of IT and cybersecurity there are some key architectural changes we can make to better integrate cybersecurity and the needs of our businesses and organizations.

A bit more about Jamison's background in food service. (You can get his technical details on plenty of platforms like LinkedIn if you like) He's worked in just about every level of restaurant from fast-casual to fine-dining, from traditional American fare to sushi, and sushi is where his skill has really blossomed. His experiences here certainly outpace mine - my kitchen experiences are more Alton Brown than Bobby Flay. We came to a few interesting comparisons that concerned us about how we approach cybersecurity as viewed through the lens of commercial food prep.

Each Cook/Chef Is Responsible For Their Food Quality and Safety

As Jamison points out, sushi chefs are particularly focused on things like the proper temperature of the refrigerator, as sushi is both best and safest when stored at a very particular temperature setting. There's no "refrigeration supervisor" monitoring that, the chefs themselves do the work.

Jamison also points out that while there may be a head chef or expediter in the kitchen who does quality control as dishes are prepared, there are some dishes that can be sampled for quality and others that cannot. A soup can certainly be taste and temperature tested, but a freshly seared steak often cannot. By the time the steak is plated and turned over to the head chef or expediter, cooling has occurred, and what self-respecting steakhouse is going to present you a steak that has had a piece cut from it before it got to your table?

So for the most part, the restaurant has to trust it's cooks and chefs to do their jobs safely and well. There just isn't an opportunity to do QA/QC on everything going out the door beyond a visual inspection.

Because of this Responsibility, Kitchen Training Is Heavy On Food Safety

Cooks and chefs are drilled on food safety, proper doneness, and safe handling techniques to prevent cross contamination. Yes, knife skills, the proper way to butterfly a chicken, what spices go with what proteins and plenty of other subjects are interesting and useful, but ask any professional cook or chef and they'll tell you that before any of the rest of that the food safety items come first. (This is often the difference between chef training and a "cooking class," - don't confuse the two)

Professional kitchen life is often less like playing jazz and more like building a car on an assembly line - regimented, precise, and repeatable. Cleanliness is a mantra, and unused food trimmings are not left around to rot, they're immediately removed before they can be mistakenly used as ingredients, or allowed to act as petri dishes for malicious microbes.

Prep Work Makes the Meal Rush Smoother

sliced meat on white ceramic plate
Photo by Rudy Issa / Unsplash

Every cook and chef knows when their busy times of day are. When the rush of customers is overwhelming, and there are people standing in the bar waiting for a table, or even lined up around the block for the drive-thru. So what does the wise kitchen do? They prep ahead of time. Chopping the onions, slicing the tomatoes, mixing the bread dough, simmering the stock, mixing the spices, prepping the herbs, and trimming the proteins. Getting everything in place to speed through the assembly of the dishes to be served once that rush hits full swing. Organizing the chaos that is to come. The routine changes with the daily specials, and with what the kitchen knows about people's tendencies on particular days and events. Sometimes they guess wrong, but usually they get it right.

Inspections Are Regimented and Predictable - Though Their Timetables May Not Be

Every chef and cook knows what they need to do to pass inspections. They know the criteria, they know the concerns, they know the needs. What they may not know is when either corporate (in the case of chains, etc.) or government inspectors are going to show up. A bad inspection can cause the kitchen to close, and in some jurisdictions they are required to share their "grade" publicly, whether they remain open or not.

Changing the Cybersecurity Model

It seems to me that modern commercial kitchens have figured out a lot of things that we're still struggling with in cybersecurity departments, and overall as an industry as we try to secure our environments.

  • We can't continue to pretend cybersecurity is the responsibility of the cybersecurity department. Every role in the company has to accept their involvement. This goes well beyond just yearly policy adoption signoff and some half-hearted anti-phishing training - just as everyone is expected to behave in a fiscally responsible way and a legally responsible way. From the Board of Directors down to the receptionist, we all have to commit to this if we're going to actually make it work.
  • Key roles need to become bastions of cybersecurity outside of the cybersecurity department. Developers, especially, need to be treated like chefs and cooks - we need to drill good cybersecurity practices into them, and make them responsible for their code's fitness. (Sorry to pick on you developers, but we can't continue to bolt-on security after you've developed the functionality, we have to do this hand-in-hand)
  • We need to be looking ahead to the organizations needs, goals, and direction instead of reacting in the moment. Sure, we're expected to be experts on new tech the day it releases, and we're supposed to have the answers before the questions are asked. That's not realistic and we all know it. But that said, we have to stop spending as much time on the day-to-day fire fighting and be able to look at the horizon to partner with the business to build better going forward. In short, we need our mise en place ready to go for the business rush.
  • We need to build clear expectations that we can measure our organizations against for cybersecurity compliance. Let's please face it, every cybersecurity framework from the NIST CSF on down is written for cybersecurity professionals, not for the people who do the work of making business happen. We need a means of communicating our expectations, metrics, and scoring so we can help the people responsible for making our organization run understand their responsibilities and how they'll be held accountable for cybersecurity. And then we need to implement assessments.

So this is just an idea a couple of us put together over beers.

Well, that's not true.

This is an idea that the combined decades of experience of two professionals in our respective fields put together as we enjoyed some time together. It is born out of observation of the world around us, what works and what doesn't. How one high speed, high pressure industry deals (quite successfully on the whole) with life and safety demands that impact their chosen profession, and how another is still in infancy, with a success rate that would cause a carnival fortune teller to despair. So maybe there's something to this.


https://www.linkedin.com/in/jamisonnorwood/

🦣
You can follow Between To Firewalls on Mastodon, Threads, BlueSky and other Fediverse connected solutions. Connect with us on those apps with this handle: @posts@between-two-firewalls.com