Перейти к содержанию

Sergey PETRENKO: "The Image of a GR Director in Modern Infosec"

Sergey Petrenko, Director of Government Relations at UserGate, answers questions from the IXBT.pro editorial team.

In the information security industry, a GR director must have a deeper understanding of technologies (DPI, NGFW, EDR) than their counterparts in the FMCG segment. In your opinion, what are the main technological aspects that a GR director of an information security company needs to know?

For an information security product to sell successfully, it must have a set of necessary artifacts: registration in the Ministry of Digital Development/Ministry of Industry and Trade register, an FSTEC/FSB certificate, etc. Obtaining some of these, such as an FSTEC of Russia certificate, requires the product to meet certain requirements, including specific security functions for various classes of information security tools (IST). Based on this, a GR director must know for which IST classes the regulator has information security or protection profile requirements, and for which there are none (however, these classes must meet a certain level of trust); know for which market segments certification to a particular level is necessary and, accordingly, which ISTs are oriented towards which market segments; understand which departments are involved at different stages of certification, i.e., which regulatory requirements relate to architecture, documentation, testing, and plan appropriate resources in a timely manner. This is roughly the level of technological immersion a GR director in the information security field should have.

Given the list of unfriendly countries, active blocking of prohibited content, and expanding FSTEC requirements, which three qualities of a GR manager can help a vendor company's business development, and which, on the contrary, are more likely to hinder it?

As Director of Government Relations, composure helps me. It's important to stay collected and not give in to emotions. To think not about the problem, but about the solution. As a rule, there is one, and the only question is how quickly you find it and how effective it turns out to be. The second quality I would name is pragmatism. As American General George S. Patton Jr. said during World War II: "A good plan violently executed now is better than a perfect plan next week." You should always have a plan B in mind, and preferably a plan C, for all more or less realistic negative scenarios. And then, if they occur, you start acting immediately, already having some outlines and not losing precious time thinking. And the third quality I would name is communicability. Most problems, if not solved immediately, can at least be understood how to solve them, simply by making a "call to a friend." But for this, you need to have enough trusted people from different professional fields in your phone. And what can hinder, in turn, is talkativeness. GR work is inextricably linked with confidential information. The ability to obtain and store it is very valuable. Fidgeting should also be avoided. Excessive, ill-conceived vigorous activity to solve a problem can create even more problems. Rigidity can also hinder. The world changes, whether we like it or not. Sometimes these changes can cause problems for a particular country, industry, company, or individual. This must be accepted a priori, and one must always be ready to adapt.

The state requires code transparency from vendors, while business practice demands the protection of know-how. How should a GR director act to convince a government customer that they are not a "spy" but a partner, without revealing key technological secrets?

It's relatively simple here. During product certification, the code can be shown to inspectors "from our hands," meaning in the office or from an employee's laptop. This is normal practice. What's important there is not the source code itself, but the artifacts resulting from various types of testing (static, fuzzing, functional, etc.). And the regulator's certificate obtained as a result is a necessary and sufficient argument for government customers that the product is secure and meets the requirements for a specific IST class. And the customer is not interested in the know-how itself, but in the cool functional and non-functional characteristics that result from using a particular solution in the product. This, in turn, is confirmed by testing results: internal, independent, or during piloting directly with the client.

Let's say you are at a meeting with a regulator, where competitors' lobbyists have already left a negative impression of your company. How does a GR director in information security demonstrate the difference between "our approach" and theirs?

The golden rule works flawlessly: "Speak well of competitors, or not at all." I personally always say not just "competitors," but "our colleagues-competitors." Because in terms of GR, we are actually more colleagues than competitors. And this immediately changes the tone of the conversation. In addition, one must always operate with facts confirmed by observations or measurements, and not by someone's subjective judgments and conclusions made based on an incorrect interpretation of events.

5-7 years ago, regulators valued the presence of "hardware"; today, it's import independence; tomorrow, it's AI for SOC. How does the GR director's agenda and lexicon change in this regard, and are you keeping up with this technological and linguistic race?

By the nature of my work, I am subscribed to several dozen specialized chats and channels, daily monitoring of which allows me to stay on top of all current trends. The only problem is that now more working time needs to be allocated for this monitoring. That is, it's no longer 5-10 minutes a day, but rather 30-40. And this is just to quickly skim through and put aside voluminous materials for the weekend. Accordingly, about once a week, I spend another couple of hours reading the deferred longreads: articles, reviews, draft regulatory legal acts, etc.

The opinion that "import substitution is over" is increasingly heard. Moreover, it can often be heard not only from analysts but also from officials. In this context, can you describe a scenario where a tough communication style of a GR director of a domestic vendor with clients would yield better results than a soft approach?

Blessed are those who believe. If someone manages to successfully report on the completion of import substitution, one can only be happy for them. Giving such unambiguous assessments to the process under consideration is beyond our competence. As for the choice of communication style, I suggest looking at it from a different, less categorical angle. In communicating with clients, we still try to operate not only, and not so much, with strict regulatory requirements, but with the real benefits brought by our products. In other words, there is always a choice: either implement import substitution requirements (and any other legislative and regulatory requirements) purely for show, still spending time and money and ultimately not getting any tangible benefit, or perhaps even worsening business processes in the organization. This is often how "paper security" works: many regulations, prohibitions, restrictions. In fact, real security has not increased, but it will be more difficult for people to work. Or, implement these requirements by actually strengthening the organization's security through the introduction of modern domestic ISTs, perhaps spending more money and time, but at the same time gaining tangible benefits and not worsening existing processes.

Among specialists in companies using protective software, and even its developers themselves, there is an opinion that the norms of Federal Law 152 or FSTEC orders are sometimes too strict and excessive. In your opinion, how should a GR director convey existing criticism to regulators so that they are not remembered as a perpetually dissatisfied troublemaker?

Through cases, that is, purely with specific examples, and by operating with facts. If requirements or certain norms of regulatory legal acts are excessive, that's half the battle. Times are turbulent now, and you can never have too much security. But if they are fundamentally unrealizable, that's already a problem. Unfortunately, it sometimes happens that a particular regulator, in its undoubtedly good intentions, outpaces the current capabilities of the industry. We collect facts and, as a rule, on behalf of professional associations, convey information to the relevant department, after which a constructive dialogue begins.

If tomorrow a major Telegram channel writes that UserGate is letting attacks through due to raw code after Western architects left, what would be the GR director's first phrase or action for government agencies?

Knowing the advantages of our product well, and especially in combination with our information security expertise, I would start with the famous phrase from the movie "Red Heat": "What are your proofs?" You can write a lot – paper will endure anything. Paraphrasing Gleb Zheglov, one can say that "product quality is measured not by the presence of vulnerabilities, but by the vendor's ability to eliminate them." And thousands of implemented solutions of our production in live IT architecture of clients in this context speak for themselves: we are trusted and chosen often based on the results of a long and painstaking piloting procedure. I can also state that not all architects left with Western vendors – some chose to stay in their homeland and even work in our company, adding trust to us and our products.

Suppose a critical vulnerability was discovered in an information security product. The government customer is panicking. How should a GR director appear at an emergency meeting in the department – as a "repentant sinner" or a "confident engineer with a plan"?

He should appear as an engineer with a plan. CVEs happen and are fixed – that's life, there's no point in being hysterical or panicking. I'll refer back to the quote option above. If the product is truly domestic and the vendor fully owns the source code and the technologies used, then the fix happens very quickly.

In the information security environment, "technical patriarchy" is still strong. Should a GR director conform to the image of a "brutal male technician 40+", or is there a demand for other types today?

You know, I myself am a kind of brutal male technician 40+, so I'll probably support this version. But I honestly admit that women are increasingly appearing in this role. I am generally against any sexism and ageism. Conforming to a particular role lies solely in a set of personal qualities, relevant experience, and the degree of satisfaction with one's work.

Name an effective technique in negotiations with a government agency that an experienced GR director might occasionally resort to in special situations. And why is it better for young specialists not to repeat this?

I'll say right away that I don't like manipulation, as it's a very bad long-term strategy, and I never use it – all my colleagues in government agencies know this. But if we're talking about effective techniques used once every two or three years, there's one. It's called... "asking." Life is structured in such a way that sometimes people ask each other for things. And sometimes these requests are fulfilled. Over a more or less long and meaningful career, an energetic leader can accumulate quite a few people whom they once helped with something. And, again, occasionally, in some difficult, non-standard situation, you can ask one of these people, close to the problem, for a favor in return. People really dislike being indebted, so the scheme usually works. And young people are not given this simply because they lack the necessary life experience – only a long time spent in certain circles works here. And empathy, of course.

Suppose that during a massive attack on the public sector, your product failed due to overload. How should the image of a GR director change for the Investigative Committee, the Ministry of Digital Development, and the internal team?

Regardless of the situation, my image does not change. The GR director's personality must always be integral and strong, especially in a critical situation. The formal side, however, might look like this. Suppose a failure occurs. Since it happens due to hypothetical overload, it means that, overall, it's not a product problem. The fact is that any solution has a stated performance, beyond which it ceases to fully perform its functions. In the case of our products, performance is confirmed by objective results of load tests. Thus, we come to the conclusion that the problem, obviously, lies in a poorly designed IT/IS infrastructure. At the same time, we will always help our clients understand why a particular failure occurred and eliminate its consequences so that their infrastructure, and with it our product, continues to operate normally. And in general, the problem of overload is relatively quickly and easily solved by increasing capacity (installing higher-performance products, combining products into clusters with a load balancer, etc.), that is, all this is regulated by the operating conditions on the client's side. This is exactly what a GR director should convey in the communication process. Talk less, act more, promptly attracting all possible resources within the company to minimize damage to clients in order to increase their trust in us as an information security vendor and network security architect.