Curiosity kills the cybercriminals

 

Summary

newsmaker Trend Micro co-founder Steve Chang notes importance of inquisitive mind to not only defeat malware writers, but also understand customer pains.

Events

IT Priorities 2010

Sydney, Australia - 27 Jul 2010
Melbourne, Australia - 28 Jul 2010
Mumbai, India - 4 Aug 2010
Delhi, India - 6 Aug 2010

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

Steve Chang, Trend Micro

newsmaker Every business Steve Chang started, he hated. But things took a different turn the third time around.

Co-founder and chairman of Trend Micro, Chang's first two startups--offering mini-UPS (uninterruptible power supply) for computers and Chinese database--failed. Undaunted, he established Trend Micro with his wife Jenny Chang and her sister Eva Chen in Silicon Valley in 1988, unleashing what was to become a giant of an Internet security player. The company's net income clocked in at US$213.6 million last year, with net sales totaling US$1.1 billion.

Growing up in a small city in southern Taiwan, the youngest in a family of two daughters and a son was a "pinboy" in his parents' bowling alley, which at that time required manual hands to lay the bowling pins. His entrepreneurial streak, Chang admitted, was born not only out of family influence but also from the desire to prove himself to his father.

Chang helmed Trend Micro as CEO until end-2004, then passed the baton to Chen, who had been the CTO for many years.

In town recently to accept the Lifetime Achievement Award at CNBC's 2009 Asia Business Leader Awards, the 55-year-old shared with ZDNet Asia in a wide-ranging interview his thoughts on IT security innovation, his one regret in his career at Trend Micro, and why the Taiwanese player had its head in the clouds as early as the 1990s.

Q: In persuading your sister-in-law Eva to succeed you as CEO, you mentioned that innovation ought to be the core competency of the company. What would you say are key ingredients to sustaining a culture of innovation in IT security?
Chang: The definition of innovation is solving the problem by using new ways. First of all, you need curiosity and intelligence to define the problem, and then you need courage in a fearless environment to try to derive a new way. It's become Trend Micro's culture. We happen to be in this software business, which requires a lot of innovation, and we happen to make a living by defeating hackers who are extremely innovative.

Eva and I have these characteristics. When the founder has certain characteristics, eventually they get into a part of the corporate culture. Because of this corporate culture, we attract those people who have this kind of core competency to join Trend Micro.

Given the fast pace of malware development, would you say that innovation is no longer an option?
It's the only way, right? Innovation has always been important because the technology has changed, the platform has changed and the way the user is being attacked has changed. With all these changes, it's inevitable that the nature of our business has changed. The Internet, e-mail and cloud computing accelerate the need for innovation. If innovation is not part of your DNA and your product, it's very difficult to fake. You are not really solving customers' problems.

Where do you draw inspiration to innovate?
Once innovation becomes part of the corporate and individual DNA, it becomes intuitive. If you really analyze it, you will see that it comes from observing how IT managers in the enterprise handle their internal network security problems.

What is their No. 1 concern? They worry about where these viruses and malware come from, and who in the organization is allowing such things to come into the company network. This is probably one key advantage that Trend Micro has over other companies, which are very technology-focused. We understand how IT managers think, feel and are concerned about.

What is still lacking in IT security innovation today? What areas within IT security can be improved in terms of innovation?
So many things! In IT security, we still have so many things that cannot be predicted. After the IT manager buys all kinds of products from the vendor, they still find their most valuable data is leaking out. If you cannot solve the customer's concern, then you still have a lot of room for innovation.

Hackers are no longer like before, where they just code malware for fun to satisfy their ego or to show off to their friends. Nowadays, they use botnets, spyware, and all kinds of malware technology to try to make as much money as possible. Last year, their revenues were about US$10 billion--much higher than the collective revenues of the antivirus industry! They have become organized criminals. We have to defeat them by coming up with much better, faster and easier ways for users to defend themselves.

Your career in Trend Micro spans over 20 years. If there's one thing you could go back and do differently, what would it be?
One thing I would want to correct is that I was too focused on enterprise software, and therefore, we missed the big opportunity back in the mid 1990s and beginning of 2000s, when the consumers started to become aware and wanted to spend money to buy antivirus software. So, our consumer sector has been behind as we've been very focused on the enterprise market.

For the last nine years, there has been a lot of money spent by individuals. And, end-users spend on the product based on the brand rather than the technology. Due to my background and focus on technology, and my engineers' personality, I missed out on this marketing opportunity. If I were to do it again, I would focus on this.

In 1999, you said in an interview that Trend Micro is the "e-doctor". How has the role of the company changed since?
It's still the same. E-doctor refers to a service. Put in the context of a cloud computing world, it means software-as-a-service (SaaS). Instead of selling the product, we host the service that customers pay for rather than have them buy a product.

It has taken longer to take off compared to what I thought because IT managers' are still thinking in terms of software, yearly maintenance costs and special support costs. The budget is still developed this way, and we tried to say forget it, you pay what you use, like electricity. It was a little bit early--10 years too early, I think. Now, everyone talks about Salesforce.com and SaaS.

But, that path gave us a lot of experience on how to run a services business. Today, our Worry-Free service for small businesses is doing very well. E-doctor transformed into a lot of services that we now have. Now, these services are our major source of income.

Do you see that eventually there'll be no security products, just services?
Yes, eventually, but I don't know how long it will take to reach there.

For Trend Micro, the mix is now 30 percent services, 70 percent products. Definitely, this ratio will change over the years. Cloud computing will accelerate this trend. Eventually people don't really buy a product where you have to install a server, update virus patterns and the virus scans might cause your system to hang--that scenario is not sustainable. Service in the cloud, I think, is definitely the way to go.

Trend Micro announced malware analysis in the cloud, offering the dual approach of tapping as well as securing the cloud. How well has that strategy worked for you?
This strategy had been cooking for almost four years. At that time, Eva had been thinking of a way to solve the ultimate fundamental antivirus problem: products that are not able to adequately protect customers because new viruses develop all the time and hackers use mixed attacks.

The scan update may look fine but every year there are more than 5 million viruses, so the challenge lies in detecting new malware. So Eva came up with the idea of offering a service based on technology like Hadoop, which can parallel-compute huge amounts of unstructured data. We try to fight the hackers and viruses in the cloud, rather than trying to remove it in the customer environment.

What do you see for Internet security in 2010?
Global 2000 companies will start to realize that one way or the other, they have to try to virtualize their servers to become more efficient. And they will then start to worry about how to protect their virtual environment as they don't know where exactly their applications are running on. Virtualization security is probably going to be the No. 1 concern.

The other concern is preventing mixed attacks in the cloud rather than handling them within the network perimeter.

So in 2010, there is going to be a huge growth I think. After so many years, I think this is going to be the best year we will see.

Talkback

Curiosity kills the cybercriminals

Read the chapter regarding security in the book "I.T. WARS: Managing the Business-Technology Weave in the New Millennium." Where I work, all new hires are assigned specific reading in the book (both "business" and "IT" folks). Do a little reading, and never look back...

John Franks December 8th, 2009 Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Access data anywhere in the private cloud & enable entirely new efficiencies with EMC VPLEX.
Tech Vendor: EMC

ZDNet Asia Live

US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4

great! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!

Shocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

Non-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4

Asian firms aware of IT snoops. http://bit.ly/9eGRxG

sg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD

Non-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4

1 hour 8 minutes ago by greentreats on topsy

Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com

RT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY

2 hours 5 minutes ago by phyllis777loves on topsy

RT @HazelHassan: Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

RT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...

RT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa

Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

2 hours 21 minutes ago by hazelhassan on topsy

S'pore marketeers not chirping to Twitter's tune: Marketing via Twitter has not picked up in Singapore, where it s... http://bit.ly/9GEDJS

great! S'pore marketeers not chirping to Twitter's tune http://bit.ly/dotZES Good day!

http://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs

4 hours 13 minutes ago by easytweeting on topsy

in the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/

4 hours 44 minutes ago by findpdf on Researchers find workaround for Adobe PDF fix

Just want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...

4 hours 52 minutes ago by winsource on Making the case for Filipino IT entrepreneurship

Hi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks

1 day 45 minutes ago by Pacific Time Pte Ltd on Recycle your HP print cartridges and get rewards

Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...

2 days 50 minutes ago by yedwin on iPhone 4 shows prudence in procrastination

While I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...

2 days 2 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastination

The online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)

2 days 255616 seconds ago by mingnow on iPhone 4 to ring in Singapore on Friday

After an awful silence, finally the prices are out..

2 days 55 minutes ago by melvinchia on iPhone 4 to ring in Singapore on Friday

Glad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...

3 days 2 minutes ago by gnome_refugee on Smitten with Xfce 4

yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...

3 days 273621 seconds ago by ggolemg on Smitten with Xfce 4

@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...

3 days 6 minutes ago by fredericmuller on Taobao initiates Chinese open source revolution

Geez. I would think giving free books and getting kids to school would be a better place to start.

3 days 14 minutes ago by mingnow on India's US$35 tablet--how low can it go?

I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...

4 days 349244 seconds ago by mingnow on Taobao initiates Chinese open source revolution

hey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...

4 days 31 minutes ago by wendy on iPhone 4 shows prudence in procrastination

It could be done without all these. Just use the opacity addon of Compiz.

4 days 54 minutes ago by hariks0 on How to get RGBA support in Ubuntu