THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


What are your roles and responsibilities in the organization that you are working for?
Dr. Srinivas Bhattiprolu
My name is Srinivas, and I have worked in the communication service provider industry for over 23 years and have been with Nokia for the past five years. I hold a Doctorate in Business Administration and oversee pre-sales and advanced consulting services for Nokia's cloud and network services. Our primary objective is to develop multi-vendor networks and infrastructure agnostic software solutions to help our communication service provider and enterprise clients derive maximum benefits from their network.
Our recent focus has been on assisting customers in better monetizing 5G technology. Previously, I worked with various product vendors and have had a 16-year-long security journey across several organizations, including security product vendors, security services with system integrators, and Nokia, where we developed security products to safeguard our customers' critical infrastructure. In addition to driving our security products and managed security services business, I am responsible for growing the security consulting business at Nokia, where we develop blueprints for communication service providers (CSPs) to secure their 5G critical infrastructure while leveraging our proprietary IP and tools. As a certified security professional, I hold internationally recognized security certifications and have worked on several security engagements. I have spoken at multiple public events on security-related topics, trying to raise awareness regarding the importance of cybersecurity.
What are the challenges you see in the current security and cyberspace environment?
Professionals in the security industry face two significant challenges. Firstly, the industry is rapidly evolving, and it is challenging for practitioners to keep up with the latest developments. The curriculum taught today can quickly become outdated and staying up-to-date with industry advancements is imperative to add value to the field. Secondly, unlike other industries where there are vendor ecosystems providing tools to solve problems, the security industry has an overwhelming number of vendors. Across sixteen domains ranging from endpoint detection to XDR, security operations, firewalls, DLP, DRM, and GRC, there are approximately 1800 vendors. Therefore, it is challenging to follow a particular vendor due to the extensive vendor landscape.
“There is a need for more basic cyber hygiene among individuals, including even the most knowledgeable security professionals. People need to regularly change their passwords or subscribe to multi-factor authentication, or else it can leave them vulnerable to attacks.”
The security market is highly fragmented, with numerous start-ups and existing vendors competing for market share. This poses a significant challenge for professionals in the industry, as it is difficult to keep track of all the available options. Furthermore, the threat surface is constantly expanding, with new techniques and technologies being utilized by attackers. The regulatory landscape is also becoming increasingly stringent, with severe punitive measures being imposed for security incidents. As a result, there is a shortage of security professionals, with predictions indicating that the industry will need more than 1.6 million professionals by 2025. This scarcity is compounded by a need for more interest from new graduates and entrants, making it difficult to attract fresh talent to the industry.
What new trends are prevailing in the market when it comes to cybersecurity?
One of the most significant cybersecurity trends emerged is the evolution of malware and ransomware. This malicious software constantly evolves and takes on new forms, making it a formidable threat to which no network is immune. Attackers are utilizing this software to drive extortion, which has become a significant concern.
There is a need for more basic cyber hygiene among individuals, including even the most knowledgeable security professionals. People need to regularly change their passwords or subscribe to multi-factor authentication, and if not done can leave them vulnerable to attacks.
Another trend is the rise of social engineering attacks, which are becoming more sophisticated and pervasive. Whether targeting businesses or individual consumers, attackers are utilizing persuasive techniques to trick innocent people into divulging critical information, which can then be used to compromise applications and systems.
Finally, the pressure from regulators on communication service providers, banks, and other organizations to ensure that their systems are secure is another major trend. This pressure forces these organizations to take cybersecurity more seriously and implement measures to protect themselves and their customers from cyber threats.
Do you have any recent cybersecurity projects you have worked on or are working on in your organization?
At Nokia Cloud and Network Services, we are committed to ensuring the security of the critical infrastructure. As a network-agnostic software organization with extensive experience in the field, we have helped numerous customers and enterprises secure their critical infrastructure. We use extended detection and response principles to prevent multilateral attacks on 5G infrastructure. Existing tools, technologies, processes, and people's knowledge are insufficient for communication service providers (CSPs) to protect their 5G network infrastructure against various threat vectors.
To address this issue, we developed a product called NetGuard Cybersecurity Dome, which utilizes advanced machine learning technologies and analytics to build indices like the threat index. NetGuard Cybersecurity Dome is designed to detect and respond to wide range of attacks across radio, transport, and code, with a level of automation that allows customers to respond to issues in a semi-automatic and automatic manner. As a result, CSPs can better protect their 5G infrastructure. It also provides a single pane of glass view that is essential to monitor different layers of 5G infrastructure.
Additionally, we are building assets as part of our security consulting team to help customers develop a threat inventory specific to 5G and provide best practices and recommendations for securing their 5G infrastructure. We derive these insights from our experience securing networks and distill them into a capsule format to share with customers.
Finally, we work with regulators to understand evolving regulatory requirements and ensure that our products are designed with security in mind, following appropriate processes and guidelines like DFSEC (Design for Security). Overall, we are committed to delivering products and solutions that are resilient, secure, and adaptable to changing regulatory requirements to meet the needs of our customers.
What are your expectations about the future of cybersecurity in the next 12 to 18 months?
There are three key trends that will shape the future of cybersecurity. The role of new and advanced technologies such as blockchain, machine learning, artificial intelligence, and multi-dimensional analytics in securing critical infrastructure is gaining prominence. There is also a need to attract more talented professionals to the cybersecurity industry through government and educational institutions. The current shortage of cybersecurity professionals is a critical issue that needs to be addressed to secure our networks effectively.
The importance of automation in security operations to reduce human intervention is also gaining traction to address the shortage of cybersecurity professionals. With billions of mobile devices and online systems, scaling security operations through the workforce alone is not feasible, and therefore automation will play a vital role in securing our networks. The concept of extended detection and response (XDR) is a prime example of how automation can help address these challenges. These trends must be considered to develop effective cybersecurity strategies for the future.
What is your advice for budding professionals in the field?
The security field is a highly engaging and challenging profession that requires a substantial amount of effort and dedication to keep up with the constantly evolving landscape. It offers monetary and non-monetary rewards and is open to individuals from various backgrounds, not just those with an engineering background. There are around 17-18 areas of specialization within the security field, and individuals can focus on one area and strive to become an expert in it. Relevant certifications such as CISSP, CISM, and CCSP can add significant value to one's professional profile. With the increasing adoption of microservices and containerization, security is becoming more critical than ever. Everyone involved in software development, networking, business analysis, leadership, and sales must have at least a basic understanding of security. As a result, this is a challenging yet exciting time for security professionals. Those aspiring to enter the field should continuously update and upgrade their knowledge and skills to avoid becoming obsolete.