Cybercrime spans international boundaries and poses a formidable challenge which we can only address through collaborative efforts between governments and commercial enterprises globally. While this area is attracting a lot of press, attention, and even investment, what progress are we making? What measures are we deploying to deal with this menace effectively?
Contributor
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
- How to make IT security everyone’s business?
- How to Build an IT Security Team
- IT Security: Future Perfect?
- IT Security: How much is enough?
- Securing Business Growth with Cybersecurity
- Cloud security, cost, and culture: Technologies Concern
- Ensuring Digital and Virtual Healthcare Security
- Embedding Security in Technology Capabilities
- Security and Agility – Tips for Getting the Best of Both Worlds
Transcript
Sanjog Aul [00:00:24]:
Hello, and, welcome to this segment on CTN. To learn more, please visit ciotalknetwork.com, and the topic for today is How Is The Government Preparing To Defeat Global Cybercrime? Cybercrime, as we all know, is international in nature. It spans the international boundaries and it’s not been an easy thing for people to tackle. The governments are trying, private entities are trying to figure out how do they collaborate perhaps to fend off these intruders or people who have a malintent. We are trying things. There is an attention given by the press. See, we are even putting investments in, but are we really making progress? And if yes, in what areas and what else is left to be desired? So to that end, would like to talk about what else we could be doing so we do not have to continue to feel that the people with malintent are the ones who are winning. So to discuss that, I have Jake Margolis, who’s the CISO at Metropolitan Water District of Southern California. Hey, Jake. How are you?
Jake Margolis [00:01:32]:
I’m doing well. Thank you.
Sanjog Aul [00:01:34]:
Great, Jake. So, yeah. Very good. Thanks, and then this is an interesting time that you’re talking with the other type of crisis, which is around COVID 19. However, cybercrime is its own animal which needs to be spoken about because that could also be seen, as I would say, an excuse for an intruder to try to penetrate because we’re busy with this other pandemic type crisis. So we have to become even more watchful in today’s day and age. So that said, the first question I have is let’s set the stage. So let’s see your view on what do you feel is the current state of the global cybercrime and compare that to the level of preparedness and readiness that we have as government and commercial entities.
Jake Margolis [00:02:26]:
Well, I would first say that you’re in a state where there’s nothing to deincentivize cybercrime so it’s just getting worse, right, because there’s not enough deterrent in place that would make it not profitable. The risk is really low for a cyber criminal and I’m not a law enforcement agent. I’m just talking about somebody who’s a former military and looking at how we would look at insurgencies and if you think about it, if you wanted to deal with an invading nation state or somebody that would be viewed as an interloper, it’s a lot more cost effective to deal with an insurgency than it is to try to stand up a formal, professional force, and in the same way cybercrime is similar to that and I compare them to insurgencies a lot because it’s low risk. There’s not a lot that they have to engage to get a big payoff, and so that’s one of the biggest problems that you’re dealing with is because it doesn’t matter what we do at that level until you can start deincentivizing that’s going to be an issue, but I would say the government is improving. We’re becoming more aware and we’re responding more quickly than government may have responded in the past, and we’re being realistic and talking more about resilience and focusing on our efforts and our ability to recover rather than constantly chasing our tails. There’s a lot more discussion about business continuity planning, disaster recovery, improving your runbooks and your SOCs and building relationships with partner agencies and services, and I think I’m even hearing that in some of the commercial folks that I talk to and some of the, I’m part of a COPCISO group and we talk about a lot of these same issues and I’m hearing a lot of the same rumblings whether it’s public sector or private sector. A lot of people are starting to look at more of how I’m going to bounce back after I have this cyber attack, and they’re making more risk-based decisions around that, and so I think that’s good. I think it’s good that we’re looking at it that way because you don’t want to be paying people large ransoms. You don’t want to be putting yourself in a position where you’re making it easy for them but you also don’t want to be put in a position where you’re crippled by it, because then that’s going to incentivize the cyber criminal more because if they know you’re crippled then they’re going to continue with the tactics that they’re using because it works. They get a big payoff and there’s not a lot that you can do to stop them from doing it. So to that end, the more resilient you are in a way that’s deincentivizing the crime because somebody says, hey, I’ve encrypted your data. I want X number of dollars. You say, yeah, that’s fine. I’ve already recovered from that. Just move on. That in and of itself will start to deincentivize that practice.
Sanjog Aul [00:05:11]:
Yes. So, Jake, based on what we have been doing in media for last many years in terms of following how the cybercrime is changing and what’s the mindset of the CISOs, we initially saw when the cybercrime really started gaining momentum. The CISOs were very confident. They said, we’re gonna race faster than the folks who are perpetrators and we are gonna nail them, and in couple of years, they said, perhaps that would not be that was a tall claim. We might have to make sure that we can bounce back quickly, and then a few years again after the AI came in as a technology, they said maybe we should not just be waiting for attack to happen and try to become, to to basically do damage control. Let’s go, go back and become proactive again. So do you think we really have a straightforward strategy or are we on this pendulum which will keep going back and forth?
Jake Margolis [00:06:24]:
I think it depends on who you’re talking to, but realistically, you have to kind of accept a couple of truisms. There’s more of them than there are of you at the end of the day. You have way more cyber attackers and way more people that are trying to get into your network than you’re just one team. You have your partner agencies and whatever, and that’s fine. So you really have to accept that the bad guy does get a bigger float in how your day is going to go than you do when you get up in the morning, and once you kind of accept that reality, you can start developing plans about how you deal with things, and again, something that I used to say when I was leading missions, back when I was wearing a uniform is we would rehearse everything. So I could ask every person on my mission what’s going to happen if we have a vehicle rollover? What’s going to happen if we have a small arms ambush or whatever the case may be and everybody on that mission would know how to respond. Now a lot of times none of those things ever happened but everybody knew how to respond if it did, and so a lot of that is making sure that you’re exercising your cyber incident response plan, that you’re exercising your business continuity plans, that you’re exercising your disaster recovery plan and that is being proactive. Because then when an event happens, you’re not going to run around and through the chaos come up with a way to remediate what’s going on, and you were in some cases, you may be successful in spite of yourself, but you’re still going to find yourself not having something that’s repeatable or well understood led by the organization, which is gonna cause problems. I think technology has helped a lot. I think having AI does help you to have a better understanding of what you’re up against. It helps you develop threat intelligence models because you can see if you’re getting more hits from certain geolocations, if you’re getting certain types of attacks. One of the indicators that we look at, incidentally, is email, because it’s a primary form of communication and it is also the primary attack vector usually because people want to do phishing to get their hooks into your network. We look at where our email gateway statistics are. If we look at if something’s shifting from things that are being blocked because of a particular type of malware or are we getting an excessive amount of spam from certain domains? Are there certain types of subject lines that are starting to increase? And we run a lot of analysis on that. So a lot of machine learning has helped us in those areas to be proactive and better understand what the attacker is doing, but as far as being able to say that you can get proactive to the point where you can stop a criminal from attacking your network, I wouldn’t be able to agree or get behind that just because they’re innovating as fast as we are and they’re also using machine learning just like we are, and so that adds a level of complexity and you won’t win that arms race necessarily. So you have to be more professional, you have to be more focused, you have to be more disciplined than the attacker, and that’s really if you can focus down at that level, and which focuses towards organizational cultures and a lot of other things, I think then you can be proactive in defending against cybercriminals.
Sanjog Aul [00:09:46]:
Now what we have to look at is the collaboration that you mentioned, which is happening among your CISO groups and between government and the commercial entities, but that collaboration is primarily an ID exchange. However, on the other hand, you might have a whole nation state coming after you or a bunch of people with many more resources coming after you and when it comes to you defending your fort, you are left by yourself. So besides just having those discussions over pizza and coke or dinner or lunches, are we truly joining hands in true sense, allowing resource sharing, allowing intelligence sharing and truly build that one bigger or rather stronger fort which these intruders would have tough time penetrating versus they’re actually having a party. The intruders are having a party because they are far they always have an advantage over us who are trying to defend our position. So has anything even been taught in this direction?
Jake Margolis [00:10:56]:
I would say yes, but I would say it still has a long way to go too. We do you’re right. We do have the partnerships and in public sector, your government, at least in California, we, municipalities and government agencies are part of things like the Municipal Information Systems Association of California, known as MESAC, or the California County Information Services Directors Association known as VISTA, and a good chunk of public sector in The United States are joining or eventually it’ll be most is the Multi-State Information Sharing and Analysis Center, the MS-ISAC, and then, you know, even within our offices, I coordinate with the California Office of Emergency Services, Cyber Integration Center for information and to work with them as frequently as they can. Now there’s a lot of information sharing that goes on with that and we’re sharing what we would call tactics, techniques, and procedures. We also share things like, you know, what did you do for your secure web gateway? Or what are you using for your firewalls? Or anything. What did you do for your enhanced detection and response? Hey, I wrote an RFP, do you guys have an example of RFP language for endpoint protection or any number of those things? Those are all helpful collaborations, but as far as building the fort goes, I think, we’re a long way from that for a couple of reasons, partly because there’s political boundary concerns, but there’s also the idea of actually understanding what it is you’re trying to do and that that goes to having the cybersecurity expertise to cut through the noise and figure out what it is that you actually need for your enterprise to secure what it is you’re trying to do. There’s a lot of tools out there and people are putting a lot of time and effort into that, for example, and I’ve seen some enterprises that are pretty well built as far as their actual security tools and the software they’re using, but end users still are undereducated, and so if you spend a billion dollars on security but an end user just absolutely has to have that wallpaper of those cute kitties saying, hang in there or something crazy like that, you’re gonna be done because they’re gonna bypass all your security by social engineering the end user. Or if you spend a billion dollars on security and you’ve locked down you have the most sophisticated tools on the planet, but you can’t convince your end users to take their badges off when they go to Starbucks, you’re still getting your security defeated. So there’s a lot that has to go towards it. It’s not just the technology part for sharing that information. Sharing ideas of how we can change culture and how does government weigh in now to create awareness campaigns like we used to do to say keep kids off a drug. There needs to be more of a cybersecurity awareness culture change initiative, I think, that will start to make the fort stronger. Because if you have a really strong fort but undertrained troops, your fort’s not very well defended at the end of the day.
Sanjog Aul [00:14:04]:
You’re right about it. Now one is the fact that okay, we want the whole village to come together like a utopia, and yes, I know even before asking the question, it’s gonna be something which is a tall order if you will. Even now let’s go to a corporation or an organization in one, as a unit. When you are looking at that and you’re trying to figure out what is the cost of us having a breach, it’s huge, but then whether we will have a breach, no one can commit to it or claim that, and when you go with that type of a case, a use case or a business case, not every time you get the resources you need, and when that happens, an individual organization, maybe they’re armed with collective intelligence from wherever, but you don’t have the resources, that creates a major issue in an organization or the leader to say, yes, I had everything that I needed to prevent the breach from happening, yet they could get fired if the breach does happen. Is there something and this is not there’s something not something new that’s happening today, but is there something we are doing as CISA community, as executive management, and all peers within the company at least, and maybe at the government level, to allow an organization to get some support from a policy, from government, from wherever so that resource constraint is a nonissue when somebody’s thinking security, but hold your thought. Before we get into this, let’s take a quick break listeners. We’ll be right back.
Speaker 0 [00:15:53]:
Today, enterprise technology is both strategic and global. Each week on CTN, CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul @ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the
Sanjog Aul [00:16:46]:
show. Welcome back. So, Jake, I asked you a loaded rather a tough question, and it’s a loaded question too, is a company needs resources. They may or may not have resources or the resources are not made available to the security leader because they are not able to claim that a breach is going to happen even though they can show a formula that how much they would lose, the company would lose or an organization would lose if the breach does happen. So when a company or a government organization is left to to deal with all of this themselves, they are forced to create constraints, and those constraints is where we lose our advantage or at least have lose the possibility of having a level playing field with the intruders. So is something being done between, like, a commercial and government partnership so that this resource is remote?
Jake Margolis [00:17:47]:
Well, it is kind of an interesting issue, on a couple levels and there’s a couple of things going on there in your question. One is the resourcing one and this is something that I’ve often get into disagreements with other security professionals. Sometimes a lot of us say it this way, a lot of us don’t. It just depends on what camp you’re in. I think fear, uncertainty, and doubt, which is what is typically used to get that first pot of money, is really a dangerous tool to use to get funding. Because if you do scare the board into cutting you a check and then nothing happens, where’s the ROI? So that’s a big thing, and then you’re going to go back and ask for more money, of course, because the threat’s always evolving and you have to keep pace with the threat. So a little bit is you have a responsibility to develop governance that you can convince them that we’re going to improve what we currently have. So it’s a little bit like coming to the fight with what you already have and convincing them that you can make that work, but you still need more money for the things to do the improvement because you are always gonna need more money to get these things done, but you’re showing them some stewardship too, and you’re also going to demonstrate how the security controls can make their life a little bit better and I think a lot of times that’s not spent. Whereas in my world, for example, where we’re looking at some things, in what I’ve done in the past. We’ve taken this idea of the user has to have their own, portable, enterprise with you, if you will, with them wherever they go, and it’s this idea that if you had all the security while you were on the premises in the company, the power of the cloud is gonna make you more productive but the power of the cloud can also give you better security if you know how to leverage it, and so by allowing a user to have their identity checked in a zero trust model no matter where they are, and then if that user once is validated and has access, then you’ve done a lot. That’s simple things like 2-factor authentication, pushing certificates to their devices, giving them, let’s just say, smart card authentication. There’s a number of ways you could do that, and you don’t even have to necessarily issue them devices. You can start separating their devices from the domain proper. So you’re doing all these things that are costly because these technologies I’m referencing, I’ve only just barely scratched the tip of the iceberg for the family of technology that are out there that could make this work for people, and they’re costly but at the same time you’re greatly improving their lives and you’re making it so that they can work remote more easily, and even in this current crisis organizations that I know of, ours included have had an ability to respond quickly with remote access without negatively impacting the employee or the operation with more than adequate security controls around the remote connectivity. So there’s a win for the organization that they are now seeing that there’s a value in that investment. They can see it. They can touch it. It makes sense to them, but you’re also getting better security in the process too, but you have to be willing to compromise with them on what you think is the tightest controls you can put into place versus what they want for usability, and so, again, you’re getting to this risk-based decision making, and you’re sharing that risk with the business holders and making them understand what it is you’re trying to do, and because you’ve let them know you understand what it is they’re trying to accomplish, you understand the risk, but you need them to give you the security concessions in order to make that happen more securely, but you can make it happen for them. Then you’re gonna have a partnership with executive management that’s going to allow you to get into a situation that now they’re intimately familiar with everything that you’re trying to do, and it’s not just a quarterly briefing that says, hey. These are the security issues and these are the technologies that we can do to stop it and this is what we have to do, and you’re not having them walk away with the sense that they’re impervious to a cyber attack, but instead they’re walking away that they’re sharing in that with you, and everybody has kind of a shared responsibility in order to have those conveniences, and then that really comes down to communicating strategy, cybersecurity strategy, and then how each initiative is a mission objective for your security strategy for the various technical groups and business units and that they’re all part of that.
Sanjog Aul [00:22:51]:
So if I were to make a comment on your response that this is looking inward in an organization. Within the organization, you’ll build a strategy, you’ll work with with people. Now let’s look at a little macro. We are to some extent still a village. We are still connected. We could still form, become or rather, serve the purpose of a weakest link in a chain which an intruder could use to get into another organization through you because you were weaker.
Jake Margolis [00:23:23]:
Yes.
Sanjog Aul [00:23:24]:
That’s one. So if that’s the case, that means the village has to protect itself. Now with that said, insurance and compliance mandates, executives, same executive management doesn’t question, doesn’t debate that a whole lot and writes the check, and here, we are going through strategy and nothing wrong with it though, but we are fighting a whole much bigger battle and based on what we could do because of resource constraint, you’re not gonna go and try to get a $5,000,000 which you actually need when you’re struggling to get a million. So you will compromise even in the request, but what did that do to secure the village? Because the topic here is global cybercrime and not cybercrime in my company where we are even spanning boundaries. So it could be intergovernmental, It could be interstate. It could be between commercial and state where we say security is a cost and a risk. We can bear the cost by playing the coop. So we share the risk, but by sharing the cost, we minimize the risk. Is has this approach been used you mentioned to some extent it has been used in the state departments. Different states, and maybe federal and state might be doing something of that sort, but frankly, now federal and state and and commercial entities are also to some extent working with each other, especially in this day and age. So is there something being tried in this regard where the money is produced whether as form of a mandate or as as part of an insurance, whatever that it takes so that we are not bugging ourselves in trying to convince our executive management that they need it, and if they don’t agree, we render the whole ecosystem vulnerable.
Jake Margolis [00:25:32]:
I think it’s interesting to use the word compliance because, I think that’s a big part of what drives a lot of stuff, but sometimes, compliance doesn’t come with money, unfortunately, right? And there’s a lot of, and then sometimes it does. If you look at the HIPAA community, there’s, you know, the health care community, they get Meaningful Use money from the federal government that they can use to help improve their security architecture or to do other improvements that meet HIPAA compliance requirements, not necessarily just security, but they get this money, and I don’t know how much it is, but something’s better than nothing. And so there is some of that that does go on depending on the compliance body that you’re talking about, but if you look at in the business world a little bit, retail, let’s just say PCI DSS compliance, that’s not a law. That’s a compliance body that most banks adhere to or you’re not gonna go to process credit card payment, but it’s not the law, and so where are you gonna get the money that meets your PCI DSS compliance? You’re probably gonna have to take that out of pocket at some point, but you can make your vendors or your partners that you work with that have to leverage those same systems or have access to those systems or however you’re making that work. You can require compliance within your procurement language. Things simple statements like we reserve the right to audit your security policy, in as much as that they talk to our networks kind of discussion. You can look at requiring artifacts in the contractual part of it as wanting to see their security policy if it’s appropriate because you’re doing some sort of connection with them. You could do, depending on the sensitivity of what it is, requiring background checks. There’s even security scorecard vendors out there now that will give you at least the IT or cybersecurity score of a vendor, but those services cost money. So now you’re shouldering that cost, but you can then share that with your partner’s supply chain. So there’s at least one company out there that’ll allow you to do a scorecard on your vendors, but then because of that license, you can share that information with your vendors about themselves. So you’re helping them improve themselves for what you know from the outside looking in what an outside audit might see, or vulnerability look at that organization might see. So it’s helpful at that level, but there’s no sharing of dollars that’s going to make that happen, and what I’d say is just in my last statement where I said sometimes coming to the table with what you have, sometimes you know we used to say that when I was in the army, you fight with what you got. We used to say that kind of very informally because sometimes you don’t have everything that you need at that particular moment, but you can’t avoid that fight. That’s true in cyber in that when you come to the table, you’re saying you want money because you wanna buy a really great, cloud based identity as a service engine, and the board says no. Well, does that mean you just don’t do 2-factor authentication? Of course not. It just means that you have to figure out how else you’re going to do it, and so sometimes it’s better to figure out how you’re going to do it first so that you have that, and then when you do remote connectivity or when you’re working with your members of your supply chain, you can enforce some of those standards on them. For me, what I have done in the past is, when vendors need to get connected to my enterprise, I require them to 2-factor authenticate with accounts I provide. So, yeah, it cost me a little bit extra in licensing, but I gain a lot of peace of mind because I know that however they’re connecting to me, I’m not sharing with them directly anymore. I’m making them validate who they are before they connect to my enterprise, and the cost that it cost me for a headcount for, say, Office 365 or something like that is way cheaper than what it would cost me to risk letting some sort of open file transfer with their organization in the broader picture. So it just depends on how you wanna look at tackling that, from the takes a village perspective. To a certain degree, it takes a village that you have to communicate with everybody, what your standards are, what you think standards should be, and the government, again, should be publishing best practices, and they do. The Center for Internet Security is, I think, heavily involved with the Department of Homeland Security and they’re kind of the organization behind MS-ISAC, but they offer CIS benchmarks and the CIS Top 20 Controls. These are things that are out there that people can grab and take a look at. The Department of Defense published the Security Technical Implementation Guides, which anybody can download. They’re free. You can go out there and download the Security Technical Implementation Guides, which have been good enough for the DOD for a long time and apply them to your system. It just takes some determination and wherewithal of the IT staff or the security staff within the company that’s downloading them to make that happen. I think that the tools that you use to validate that are free as well. So there’s a lot of that that’s out there, but I think there could be better information campaigns about free resources like Quad9 DNS or things like that that actually help with security, and as you know, you don’t get much out of it, it does provide you a level of security when you don’t have the money to invest in it. So there are some things that are out there that the government could make people aware of. I know that there’s some legislation in the works at the federal and the state level, for different reporting requirements and vulnerability reporting or remediation activity requirements, but I think it’s gonna go a long way towards securing government. I don’t know what it’s gonna do for the private sector because I know that there’s been certain legislation that while the intent is good to protect individual consumer data, it’s really a herculean lift for a lot of the companies to shift their compliance for those directives. So, in the one hand, if you get government involved and says, hey. This is what you have to do to be cybersecure, companies are gonna turn around and say, well, I can’t afford that. So how am I supposed to do that? And then again, it comes back to we should be looking at things like getting back to basics. We should be communicating with small business, medium sized businesses, even large companies, but I think large companies to a certain degree really do have it figured out a little more just because they have the density and the staffing and the ability to attract the talent to work within the organization. So they have their problems to be sure, but we’re looking at things like vulnerability and patch management. Make sure you’re doing that. User education, multi-factor authentication, web application firewalls, just real basic stuff that you can put into place, and there are basics that if people are handling that network segmentation, those kind of things, that if people understand that and they’re applying it, the basics are well communicated as part of an education campaign. Then I think that people overall might be in a better place, but you’d be astonished at how many people don’t do the basics. It’s staggering how many organizations do not do the basics, and I think that, if we could just get into a place where people understand those and have a road map to get those implemented, then we would probably be in a better place to stand up globally, if you will, as a village.
Sanjog Aul [00:33:30]:
Let’s take a quick break, listeners. We’ll be right back, and Jake, when I come back, let’s talk about this interesting issue of security leaders and their team. They, in many cases, are reported to be fired because they could not secure the fort or keep the fort secured. Was it truly their fault? Was it something beyond them? Did the organization recognize it’s beyond them and they did not give them the resources? Or no matter how many resources did they give them, could they have actually protected when we have a nation state or some other bigger entity working against? So should there be something which would allow security leaders to not necessarily get an immunity along with their team, but at least have some sort of an intervention so that it does not further disincent security professionals to continue to take jobs which are equally important here at today’s day and age where they know they’re gonna work their best, but then they could also be fired for no fault of their own. Okay. Please stay tuned listeners. We’ll be right back.
Speaker 0 [00:34:50]:
Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.
Sanjog Aul [00:35:46]:
Welcome back. So Jake, I don’t want to get fired for what I cannot control, and it’s not that I don’t have the right intentions. Maybe that’s what most of the security leaders and professionals are thinking today, but many of them also have received the pink slip because things did not go well and in some cases, either were they were made responsible or shown as responsible or as a scapegoat, but does it not create a disincentive for the security leaders and professionals to continue in that profession? Or even if they do so, they would like to jump ship and leaving that organization much less secure than it ever was. Isn’t this a problem which is pervasive and isn’t this something which is going to cause a lot of problem or increase vulnerability if we allow this to happen, where at will an organization says I’m gonna let a security leader go because a breach happened? Can government intervene? Can there be policies against this?
Jake Margolis [00:36:55]:
Yeah. I don’t know that the government can. It would be like saying, can government stop somebody from firing a police officer for something unless it’s negligence? And in the cases of law enforcement or other entities where people get fired from what we would consider protective services type jobs, there’s generally clear negligence or somebody violated the law, and what you’re bringing up, it’s not like that. You’re right. For security professionals, you didn’t break a law. You did the best you could do and you’re still probably having to take the fall. The thing that I can liken a CISO position to the most in the environment of time zones, if you look at some of the events that have happened, in the press, with the military in the last couple of decades. Every once in a while you’ll hear a story about a commanding officer that’s released for cause because of something somebody else does in their command, and, when I was in the army that was something that was impressed upon us is that you’re responsible for everything your command does or fails to do. So in that level there’s a level of accountability that you expect when you take that job. So to a certain degree I think senior security leaders accept that accountability when they take the role of CISO on that they’re responsible for everything that happens or that fails to happen with respect to security, and ideally, you’re taking that on. It’s kind of a leadership thing. You’re shouldering that, and because you have that accountability for leadership, you’re expressing that you know that you’re sharing in that risk and that you have that, but at the same time, organizations are starting to learn. I’ve seen it with a few that you don’t gain anything by firing your CISO if they didn’t do anything wrong, but there needs to be some clear understanding. So I think again the government could go to the point of, seminars, education campaigns, talking to corporations. There’s certainly enough events that we’re all at together, to make sure that they understand that, you know, if a nation state wants to go after your network, there’s probably not a lot your security team can do to stop the attack from happening. So what I would look at is that’s where you have to look at resilience. If you got hacked and you were able to recover quickly and your losses were somewhat minimal relative to the scale of the attack, or even if they weren’t, but because the attack was something that was completely out of control, let the forensic analysis kind of paint the picture for did you do everything you could have done, and then you can make a better decision about whether or not you wanna let that CISO go or not. I’m always telling people not to do it when in the conversations that I’ve had with people because you’re asking somebody to have a crystal ball and to foresee every possible thing that an attacker is going to do, and I tell them it’s called zero-day for a reason. So when that zero-day attack or vulnerability is leveraged, it’s kinda hard to hold somebody accountable for something that they just didn’t have the psychic wherewithal to know that that was going to happen. So I think you want somebody who’s intimately familiar with your enterprise to help you get back up and running, and that message I at least in the circles that I’ve been in, has resonated well with decision makers, and I think that’s the message that’s coming out from the federal government and the state government, and again, I can’t speak for them. I’m not a representative of federal or state, but from what I’ve seen, at different events and what I’ve seen going around in other circles is that mantra of let’s fire the CISO because they had a breach is starting to slowly trickle off because I think people are realizing you are better off with the person that knows your enterprise if you’re to remediate the cyber attack, or to remedy the situation so that it doesn’t happen again so that you can take those lessons learned and have some continuity. Now when there’s negligence, I think that can be a valid business decision. When people knowingly not touch vulnerabilities or they haven’t wanted to communicate it because they don’t like to give bad news to their board or their CEO or their CIO or what have you. You know, that’s kind of on you when you’re the CISO. You’re part of your job is delivering bad news and if you’re not prepared to do that, then you probably should look at another career field, because that’s part of what you’re paid to do, and when you’re doing that, there’s a right way and a wrong way to do that, but you definitely want to be in a position where you are making people informed and if you’ve informed them and you’ve made it a risk-based decision and said, hey, here’s what we need to do and here’s the risk if you don’t do it. Here’s what it’s gonna cost you if you do it, and this is what we can do and this is what it’s gonna cost to do these compensating controls to have, you know, something in between. If you’ve done that homework, then there shouldn’t be any reason why you should lose your job except the fact that, you know, sometimes that’s just the way it goes down and it shouldn’t, but that’s just the way it happens, but I think it’s getting better in that sense is that if you are doing those things, you are communicating risks and you are communicating what the issues are and you’re not keeping bad news because you don’t want to tell people bad news, then I think, you’re seeing that less and less, CISOs are actually getting fired because they are doing the right things, but again, I think all of this can be summed up in what leadership quality the organization expects from the CISO and is the CISO accepting the fact that their job is primarily a leadership role and not a technical role anymore, and that they’re supposed to have a certain level of accountability on their shoulders for things that are going on within the organization, and I think that’s where the partnership is, but as far as having the government legislate that, I don’t know that that’s a good way to go because once something’s in black and white, that can equally be used to protect somebody who actually has no business being in the job, and so I think to a certain degree, providing all of the guidance and telling people that maybe you probably shouldn’t fire the person just because something bad happened can be a powerful message, but at the end of the day, corporations are still gonna do what they’re gonna do. I think medium and small businesses are still gonna do what they’re gonna do, and, actually, let’s be real. Small businesses probably don’t have a CISO. Even medium sized businesses probably don’t have a CISO, and so, when you’re looking at that level, though, some of that stuff even falls within the CIO’s world, or the IT manager or whatever it is within that side, depending on the size of the organization, but whoever is accountable for that cybersecurity function regardless of what their job title is, they’re sharing that responsibility to the people that run the organization, and again, it’s on them from a leadership perspective to communicate that to the organization, to the board, or managing stakeholders so that they understand that this is a shared responsibility, but I wish I had a better answer for if there was a way to protect them. I think that from a negotiating perspective, you know, when you get into your various job functions, I think that’s probably where they may or may not have some room to work with the corporation, but, again, you know, I think that’s part of the risk that you accept when you step into the position. So it’s really hard to, you know, I would say, how I would judge the effectiveness of CISOs is if something unfortunate did happen in the company and they decided that you had to step down, but you were willing to help them remediate their problem, and because part of it is you’re the public face for that failure, so to speak, because accountability does rest with you at that level, then how gracefully are you going to step down from that position and do the right thing by the company because you knew that was part of the job when you took it? And I think that’s kind of where the understanding is, but I agree with you that it’s a problem because you mentioned that earlier, and I’ll say why I agree with you is because I see that that scares a lot of CISOs that I’ve met into not making decisive action or taking decisive action. Because they’re afraid that if they do something and it doesn’t remediate the problem or they still get a breach even though they took that action, they’re thinking that as long as they still saved money or whatever the case could be, it makes it harder for them to move, and so I think that it is definitely something that’s unique in that world, but it’s not an easy problem to solve.
Sanjog Aul [00:46:29]:
On behalf of our listeners and everyone who is at the CTN organization, I’d like to thank you, Jake, for sharing your insights and thoughts about how stakeholders and security leaders at government and commercial entities can join hands to prepare and effectively defend against global cybercrime. Thanks so much. This was very insightful.
Jake Margolis [00:46:57]:
Thank you.
Sanjog Aul [00:46:58]:
And listeners, please like us on Facebook. Search for CTN, that is CIO Talk Network, and be sure to follow us on Twitter and join our LinkedIn group. Thank you again for listening to this segment on CIO Talk Network. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.


