Threats to your enterprise have as much chance to come from around the globe as they do across the hall. This much is obvious to the savvy CISO. Your organization may have governance policies in place along with proper education on privacy and security within your organization, but is it possible that investment dollars are not entirely going where they belong? To what extent are organizations overlooking internal security threats? What kind of internal threats are most concerning, be they malicious or unintentional? And where should CISOs be refocusing their efforts? Kevin Novak will be speaking today at the SC Congress in Chicago on the topic “Security, Privacy and Whistleblowing”.
Contributor
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
- A Digital Operating Model that delivers Results
- Transforming Security Operating Model
- Should There be an IT Leadership Maturity Model?
- New Delivery Models & The Economics of IT
- Cloud Maturity Model Conundrum
- Re/Designing An Effective IT Governance Model
- Digital-Enabled Wealth Management
- CISO as a Digital Business Leader
Transcript
Sanjog Aul:
Good morning and welcome to CIO Talk Radio. To learn more about the show, please visit CIOtalkradio.com. As always, we invite you to join the discussion on Twitter, #CTRlive, and look for this show as #security. Today’s topic is Managing Security from The Inside Out and our guest for today’s show is Kevin Novak, who is the Chief Information Security Officer and IT Risk Manager with Northern Trust Corporation. Good morning, Kevin. How are you?
Kevin Novak:
I’m Great Sanjog. Thanks for having me on.
Sanjog Aul:
Oh, thanks for joining us here today. Now, the topic for today involves internal security risks. We’ve been focusing on other security challenges like APTs and cyber espionage, but we didn’t want to forget about the challenges that exist across the hall in the form of your own employees. So let’s look at where some of the weak links are on this side of the fence. So we are talking about internal security risks because people may be there and they could be the weakest link, yes, we have worked on taking care of the technology side, maybe for define our network and everything else. Now, where do you think, if you were to truly inventory the different areas in which not exactly only people cause it, but what all form of internal security threats that always loom, which you have to handle and be careful of?
Kevin Novak:
That’s a good question. I think the internal threats, especially from internal individuals, I think come in kind of 3 different tiers, if you will. In my experience, the majority of internal risks are really the result of legitimate, well-intended users simply trying to do their job, but maybe doing so in an insecure way. So that’s through gaps in controls, such as, , trying to use new technology and new advancements that we really haven’t accounted for from an information security perspective, or through actually known violations of security controls because they don’t realize it’s as dangerous as they might have thought to violate those controls, or they may just be discussing confidential information in an elevator or leaving confidential information playing around and it being picked up by someone, and maybe even sharing information with individuals they, with whom they shouldn’t share, and then you have legitimate users accidentally causing undue risk, and this is, I think, a bigger risk for enterprises than most companies recognize? So sending the right information to the wrong people. Trying to send a report to client A and accidentally sending it to client B, or sending the wrong information to the right people, Creating a report and accidentally including all your clients and sending it to client A, if you will, and then you have administrators accidentally assigning improper access. The next tier, in my opinion, is really the threats that are those malicious users, but they’re kind of event-based. They’re a result of either voluntary or involuntary termination, They are fear of termination from federal discontentment with peers and others,
Kevin Novak:
and then there are those finally, then the last year really is those malicious individuals that are involved in fraudulent or disruptive activities or activities meant to bring light to something they disagree with internally, socially, politically, or ethically, and I think that the one that the government recently felt was snowballed. These events, those, those kind of smallest peer actually can cause the most harm, can go undetected for longer periods of time because the people are still on staff. They’re in most cases acting as if they’re just normal employees, and they require the strongest controls to prevent, detect, and respond to.
Sanjog Aul:
So we did say that, people could be from different walks of life, They could either have an ethical issue or they just feel differently about certain rules and boundary lines that have been created by an organization. Those are people who are going out and doing it with a malicious intent or what whatever way they want to express. It’s a form of self-expression perhaps. Now comes the process, cause you could have people from all shapes and size and forms and mindsets. That’s something you can realistically cannot control, but what you can do is your process could govern it. You can say that I’ve created a policy, but people, if they don’t agree, then that’s not gonna fly. So what can you do to make sure that the internal threats are minimized, and are you seeing that trend where you are trying to fortify your organization, you do it, but then it turns around and it becomes even more vulnerable.
Kevin Novak:
I think that you need to be cognizant of, all sorts of different reasons why you might have a threat internally. You know, different economic pressures, different corporate events, and different types of just opportunities may present themselves that become something you have to be aware of. Difficult economic times alter an individual’s perception of their risk-reward ratio relative to committing fraud, Top corporate decisions can even impact and increase risk of malicious internal events, and layoffs, a choice for a corporation to with hold raises and bonuses, poor working conditions of an enterprise, and unfortunately I don’t have that type of problem, and failure to keep check on core management practices. All these things contribute to more opportunity to have internal threats and something that companies really have to be conscious of.
Sanjog Aul:
Would you say that this is one of the biggest problems you face, or when you try to compare, you’re battling all the outside-in threats, but this is the inside threat that people may have, but does this take a backseat when you’re looking at something coming from outside? Is this something which you are realistically able to handle now and it is under control, or would you say, we are having a tough time, but since it is an internal threat, we don’t publicize a whole lot about it?
Kevin Novak:
I’m fortunate to work for a company with strong ethical values and a strong commitment to its employees, and we place a high priority on prevention, detection, and response to all threats, regardless of where it originates. So I wouldn’t say it’s a biggest problem we have. I wouldn’t say it’s the smallest. It’s something that is just part of our program. We have an objective of helping ensure that our clients, our shareholders, and company have the highest degree of confidence in protecting the information and systems that they use on a daily basis. So, I think it’s something that we just build as part of our program and not something we really consider bigger or smaller.
Sanjog Aul:
So let’s think outside of Northern Trust as an organization. The trend? I mean, while just wear an analyst hat for a second and you talk to your peers and counterparts and other people who are grappling with situations related to security, if you were to do a math and draw a percentage out, would you say we are equally concerned and grappling with insider, like inside weaknesses or vulnerabilities with respect to security as compared to outside, or it is tilted scale where it’s more coming from outside versus from inside?
Kevin Novak:
I think the inherent problem with it is a lot of people start with the perception internal. You start by trusting your internal and you start by not trusting your external, and while there’s some merit to captive versus non-captive individuals, and you actually have to consider both with scrutiny and apply threat logic to both. Do I think that generically the industry is of the ilk that they need to consider both internal and external threats? I think it really depends on who you’re talking to. I think in the financial industry and my peers, I think absolutely consider both of equal weight and something we consider. I think other industries may not. Be of same belief,
Kevin Novak:
and I know there are absolutely companies out there who believe their internal employees, quote unquote, would never really do anything wrong, and hopefully they’re right but certainly I do know that there are a lot of companies out there that aren’t considering the threats of internal as much as they do external.
Sanjog Aul:
So like in your team, I’m sure when there are certain APT-related threats are there or other main threats, you might create a task force and you might create funds. You will create funds or carve out funds to make sure that you’re handling those threats which look very obvious and you are supposed to handle them and it is a public knowledge, if you will. What do you do to make sure that you have something carved out to make sure there is somebody watching, there is a task force or something to that effect for taking care of inside threats? Cause you could be whole making a great fort from outside and then create a secure fort, but then your inside is crumbling.
Kevin Novak:
Absolutely.
Sanjog Aul:
And it’s not you as an individual. I’m saying this is more for your role as a CISO or anyone in your role.
Kevin Novak:
Certainly, and it’s divided up differently depending on what company you’re in. Some companies manage that through their fraud team. Some companies manage it through their HR teams. Regardless of how it’s managed, it absolutely has to be considered part of the program. Again, we don’t, we don’t necessarily consider it separately, consider that it all integrated into a strong program that helps protect the information of our client and company and protects our shareholders and clients. So, we at Northern, and I know my peers consider it the same way, and there are absolutely programs in place to look at behavior of internals and look at making sure we have appropriate screening and background checking and the appropriate measures to ensure that both internal and external threats being appended to.
Sanjog Aul:
Let’s take a quick break. Listeners, we’ll be back, and when we then let’s, let’s look at the trends that you’ve seen over the last decade or so, because we have changed to some extent the way we communicate, the way our employees base is working. What are they using when they are working inside the four walls of an organization, when they are remotely working, and we’ve given them toys or things to be able to become more productive, but is that creating more problem for the CISO and the crew? Please stay tuned. We’ll be back and explore.
Sanjog Aul:
Welcome back. So, Kevin, when we look 10 years back, 10 years ago, we, we had certain fabric in our society. We had organizations running differently. The pace of business was a little different. There was not there is nothing called as new normal that existed at that time, and now you look back and now traverse that path all the way to today. What do you see the change in the insider, inside security-related breaches or trends where people were less of a problem and you were able to sleep at night and did not have this as big of an agenda as it is today?
Kevin Novak:
I think 10 years ago, the problem was obviously not as much of an electronic problem as it was, as much as it was a more of a physical problem. I think throughout history, there’s always been a consideration for internal threats. Whether that is writing fraudulent checks or that was stealing corporate plans. I think that today there are just more opportunities to make it more pervasive, to spread it outside the bank. So when you look at the ability for individuals to access information anywhere in the world, for individuals to send information, to broadcast across the world, I think it just makes it easier to, I guess, perpetrate certain types of activities that may not have been possible 10 to even 20 years ago. So I think it’s really more about different ways of doing certain activities and less about whether it’s happening or not.
Sanjog Aul:
So you’re saying that there were more obvious ways. Now people are getting smarter, even people who are within, or maybe just because you’ve given them new ways to connect to the organization and get access to the information electronically. They’re getting creative and that is anyways, a thief is ahead of the cop. So, you got more challenges with more creative people trying to create more damage and you come to know much later than what you used to earlier.
Kevin Novak:
It’s certainly a matter of having the tools. So, to your point, we’re certainly giving more tools to do more with the information that’s available. The amount of information that’s available to individuals within an organization is far greater than it had been in the past where you were dealing with paper files or where you were dealing with small amounts of information within an accounting system, for instance. Now there are tools available not only in the enterprise, but remotely from home or from mobile devices that give individuals more freedom to access greater amounts of information and be able to do more with what they have. So again, I think it’s more about having more and having tools to do different things with it.
Sanjog Aul:
So if you were to look at the internal risks and you had to come up with a way as a checklist to say, I’m going to do this, and this to make sure that I’ve done everything I can as the CISO and also helped my team to understand what the landscape is, then I’m done, and it is more of a governance and monitoring versus taking proactive steps. Is that where you sit, where you would just put a checklist and be done, or there is some proactive effort that may be required on your behalf or from your side or from your team’s side to make sure that your inside threats are not magnifying or are they getting to the next level?
Kevin Novak:
Certainly, threats will never become stagnant to the point where you can build checklists. You always have to analyze your threats. You always have to look at different ways of doing things. I think the biggest key to understand is humans are really smart, adaptive individuals, and internal threats adapt when you build controls. So you can never really stop looking at the controls to mitigate the weaknesses in your controls. So you have to be diligent. You have to absolutely be looking for weaknesses and constantly be analyzing changes in threat, changes in technology, changes in how people perceive whether or not you’re going to catch them, but I would say you can absolutely have great mobility.
Kevin Novak:
You can absolutely have bring your own device if you want. You can use the cloud. These are all things are all possible, but to your point, you can’t simply build a checklist. You have to be engaged. You have to be working with your business and you have to be understanding the risks that are out there and how you can mitigate those through controls, whether those are procedural controls or technical controls.
Sanjog Aul:
Now, since you’re dealing with mostly people as the inside threat, you would require a psychiatrist to talk to someone and figure out how to read between the lines. I’m sure you’re not offered that. As a resource. So how can you determine, especially when you are so people dependent in being able to figure out what’s going to happen next, what is your way to actually monitor anything? You’re telling your team member to go talk to other people, or you’re just reading the logs to see what somebody’s trying to do. What is your way?
Kevin Novak:
There are a lot of different things that companies use to help. Mitigate the types of concerns. Some companies have very thorough screening processes. So background checks that hit local, regional, national, and international. The international sometimes a little harder because not every region of the world has the same level of diligence in recording backgrounds, but there are different ways of getting that information too. Some companies utilize multi-vector analytic environments for doing internal fraud detection.
Kevin Novak:
So doing strong anomaly detection, other types of activities individuals are engaging. In some companies, for instance, ensure employees, ensure that employees aren’t servicing their own and their family members credit accounts when they’re responsible for managing credit accounts, So different things to make sure that employees aren’t doing things they shouldn’t be doing and helping them make the right decision. There are absolutely technologies and methodologies out there for monitoring your network, monitoring through data lookss prevention, database net application anomaly detection, using Honeyword and Trapfile programs to catch things going out, and if they’ve gotten out, using external intelligence programs to identify any of these types of things that have already leaked out to the internet. I think one of the biggest challenges that needs to be overcome though, you can implement all the tools you want, you can suggest all the things you want, but one of the biggest challenges you have to overcome is management has to recognize that threats do originate from both external and internal, and then it’s possible to still treat your employees with dignity and respect while still protecting the interests of your company, clients, and shareholders.
Sanjog Aul:
Would you say that you could unknowingly get into the privacy concern of an employees when you’re trying to handle inside threats and or maybe monitor certain things?
Kevin Novak:
It’s certainly something we discuss actively as we’re talking about different methodologies of monitoring. Our employees activities. It’s something that, we certainly engage our legal teams with, our HR teams, because we always have to concern ourselves with getting access to information that really isn’t something the company wants. I would say that most enterprises look at the confidentiality of information as something that if an employees is using company resources, then there is a right to monitor that information that they’re using company resources to transmit, and so we absolutely have processes in place to monitor and watch what people are doing, and I know most of my peers do too, but we also have processes in place to get rid of information that’s not relevant and manage that information in a secure fashion so it’s not something that compromises our teams.
Sanjog Aul:
So if you had to go back and say, I’m going to try to do things differently just because you’re seeing these problems coming up and you’re using whatever methodologies that you’ve been using so far, What’s new and different that you anticipated doing in the future as you see the landscape morphing, whether how people access information or what kind of policies are we changing in order to look like that we are offering work-life balance and/or other perks in order for us to retain and attract good talent? What do you do to make sure that you do not keep doing the same due diligence that you were doing, say, a year ago? What is your way to evolve your security measures in order to make sure that you are current with the times?
Sanjog Aul:
So Kevin, we were discussing about the different issues that we have seen over the years. Now, we also know the world is not going to stop. It’s going to continue to evolve. What is it that you’re doing to make sure that you’re current versus trying to use old techniques with the new docs?
Kevin Novak:
So certainly, we’re always looking to evolve our programs and always looking at different ways of making sure that we’re considering changing in threat. So looking at things like, requiring secondary approvals on certain tasks, shifting job responsibilities at certain intervals. So, noting that this can also be an operational, a sound operational model as well. Requiring comms away from the office, making sure that you’re very conscious of segregation or separation of duties. So for instance, a developer should not be the same person that’s also pushing their code into production, and causing conflicts that may cause either fraud and/or just operational interruption, and then enforcement of policies is really important. So making sure that there is fair and consistent treatment of the types of enforcement that you use to follow up on policy and standard violations when they do happen.
Kevin Novak:
I think it’s certainly recognized that if an individual knows that there is a consequence to actions, they do wait that when they’re trying to make a decision as to whether to do something inappropriate or not.
Sanjog Aul:
So when you’re looking at this where you mentioned that we will be able to employee these different technologies and try to go to the next level, do you see the changes actually, whatever changes that you are making are really making a big enough difference in the way you’re able to secure the fort? Because you got to somewhere, somehow show the ROI on what you’re investing, and secondly, there are certain areas that you mentioned about separation of duties, and other areas, these are not something that you can really control or enforce. This is something which is maybe with an application development organization or any other department where you can at most request the individual leader who is supposed to be making those changes to make that happen. What is it that you can do?
Kevin Novak:
You can certainly impose things in particular, such as segregation of duty through access controls and other technological controls that would prevent an individual from being able to do certain functions. So no, you can certainly deploye methodologies and technologies to enforce the controls that you want to put in place. You can ensure that if a job function requires a certain level of diligence, that that’s monitored. So we do look at how well our strategies are kind of impacting in a particular operation. So, we can see if we allow changes to happen, if we don’t mitigate those changes, more failures happen. We see more events occurring if somebody’s able to arbitrarily go and make changes in a production environment. You see more downtime trends. So, we certainly can watch trends.
Kevin Novak:
You can pay attention to what happens when you implement programs or when you do certain awareness campaigns and the impact you have in the residual month. Is it real easy to determine a direct correlation? No, really not always, and in particular, in information security and IT risk, sometimes it’s real difficult to show an absolute direct correlation. However, as you watch over a longer span of time, you can definitely tell that your programs are becoming effective as you see narrower windows within that time as you see smaller incidents and less frequent incidents, and you can certainly tell when you start becoming more contacted by your internal staff. I’d say one of the things that is the biggest measure of our success when it comes to awareness campaigns within Northern Trust is that we start hearing from people more often. We start seeing more people reporting incidents and reporting, I guess, aberration of responsibilities to the groups that are responsible for looking at those types of deviation from policy. So there are definitely ways to monitor it.
Kevin Novak:
It isn’t always a one for one, but we certainly try to evidence that these programs are being effective at what we’re proposing that it is.
Sanjog Aul:
You know that business is always looking for new ways to create revenue and growth and profitability, and traditionally, CISOs and their team is seen as someone who’s paid to almost say no or sell insurance, and this is not something that you did, but just the very role is basically to make sure that you maintain stability versus your job is not to take care of the profitability and the growth and innovation. You’re there to make sure the fort is secure. That means you are also trying to make sure that the growth is not stifled. It is supported with a stable ground. What do you think could be done where we change that perception in an organization that if I’m going to go to CISO and the team, then I’m going to get a damper effect on all the initiatives that we have going?
Kevin Novak:
I’m not sure I’d agree with the statement that my job is only to secure, and it isn’t. A part of supporting the revenue lifecycle of the enterprise. I absolutely agree, and I communicate this and socialize it throughout my department. We have an absolute job to help ensure that what we’re trying to do is keep the company running and keep our clients protected. So we are part of the revenue cycle in that we support the protection of the confidentiality, integrity, and availability of the information and systems that our clients and shareholders and company have come to expect. So we are part of it, and I think that any CISO who is paying attention to kind of where we are in this day and age, there is no longer a CISO that can just be the no person.
Kevin Novak:
It absolutely has to be the information security person that’s integrated into the risk fabric of the company and working with the business to understand how best to not only prevent failures, not only prevent attacks, but also empower the business to do business the way that clients want to do business. So it’s about finding the win-win solution, if you will, making sure that the solutions are out there, but are also secure. It’s about supporting the organization, not just being a security entity.
Sanjog Aul:
And do you think that trend, the one which you mentioned, is that something which is you are able to put out there and make a good business case and make you then are seen as someone when there is a, say, strategic initiative in place or it is just about to be planned or kicked off? Are you brought at the seat upfront or you’re said, this is what we have come up with. Now you see and see if you can poke holes into it so we go in a secure fashion. At what time do you think a CISO’s organization gets involved, and I’m trying to connect it back to the insider issues as well, specifically because that’s the scope of this discussion, is that there are a lot of things which we want to do with the outside world, and we’ve got a lot of people and process and technology changes that we are making within the organization. How do you make sure that the insider threats are not going to get magnified just because we are trying to do something with the outside world?
Kevin Novak:
Interestingly enough, it isn’t even me that has to sell this. It’s really the business. The business wants to come to us because part of what differentiates us is our ability to protect information, our ability to offer services in a secure fashion. So we are brought to the table at the beginning, absolute planning phases of new product development and new innovation, and whenever new technology wants to deploy, we are involved. Information security in entities of this modern culture are integrated into the fabric of decisions. Absolutely, because it has to simply be considered a part of development. There’s no afterthought anymore.
Kevin Novak:
Afterthought costs money and costs risk. So, so we are integrated into the fabric of the decisions that are made at the enterprise level.
Sanjog Aul:
Now, while it may not be a reality today, but if you were given an unlimited budget, what would you have done differently in terms of securing the fort, especially from the inside threat perspective?
Kevin Novak:
I’m fortunate to have a really supportive management organization and, and a company that focuses heavily on client trust. So I have the resources that I need and when I need more, I’m able to bring those forward provided I can justify that I need more. Unlimited budget, unfortunately, I think would hit diminishing returns. I think at some point you’re not addressing risk, you’re simply addressing security, and for enterprises today, you really have to focus on what’s the most important, and for us, it’s focusing on the protection of our clients, shareholders, and the company itself. So I’m not sure I can address what would I do if I had unlimited resources. I’m sure I’d have a few more staff.
Kevin Novak:
I’m sure everyone would say that, and I’m sure we’d look at different tools, but unfortunately those come with their own risks and you really have to approach it from a risk-based perspective. I do think that a lot of companies out there don’t have the same level of diligence with respect to giving the resources and understanding the right threats, and it’s the information security organization’s responsibility to make sure that the risks that are inherent to doing so are understood in terms that the business can understand. I think that’s one area that has historically been lacking in the information security field, and in particular at the executive CISO level, is the ability to translate information security security and IT risk into business terms. So if we do not do this type of activity, then we will have this type of regulatory risk or this type of legal risk, and so until you translate that into terms the company can understand, it’s hard for executive management to focus on what’s really important, and to be quite honest, if the CISO can’t put it in terms that are in that type of language, then it’s hard for them to really justify that they even need it.
Sanjog Aul:
Now, coming back to those individuals or people side of inside threats. Now, we definitely could have people, and we spoke about people with malicious intent who could cause a problem, but then there are many others who do not feel and they do not have that mindset, but they could be more vulnerable than the rest. They may have that DNA, that psychology or whatever else that could make them vulnerable, and people kind of do profiling on them and then try to figure out how they can create trust trust with them outside of the organization or while they’re even within the four walls and then make them a target, and then that way they are able to find their way through. So what is it that you could do realistically with those people who could become weakest link without they themselves knowing that they are?
Kevin Novak:
This is a really important topic in today’s time. We’re seeing a whole lot more social engineering, kind of interestingly enough, coming back to kind of the roots of information security from 10, 15, 20, 30 years ago. Where there was a lot more social engineering. We’re seeing a lot more phone calls. We’re seeing a lot more just inbound emails and faxes coming in trying to, as you said, coerce unwitting individuals to be duped into becoming accomplices. So absolutely, awareness and testing. Lots of awareness to look for the types of signs that might be indicative of someone trying to coerce them into becoming an accomplice, and actually kept it.
Kevin Novak:
Doing live testing, but with non retribution. So if you find someone that fell for something, don’t write them up and put it on their record. Use it as an opportunity to educate. This is something we do throughout the year. So it’s a constant activity. We, for instance, we do phishing attacks on a regular basis, and when we find somebody who falls for a phishing attack, we use it as an opportunity to train them in how they should have caught those types of things, but our client service representatives, our sales folks, anyone who might have the opportunity to be involved in this type of activity, we certainly train them and we’re in to make them aware of the types of things they should be looking for.
Kevin Novak:
Unfortunately, you can’t prevent everything with education, and some people unfortunately don’t need to be duped. They’re very willing accomplices. For those, you need down controls, to help them, quote, make the choice, end quote. So as we noted before, make sure you have secondary approvals, that you’re changing job responsibilities, that people are forced to take time off without being able to communicate with the office, and engaging in different segregation of activities controls.
Sanjog Aul:
Let’s take a quick break, Lister, and we’ll be back. So there are a couple of strategies that were discussed to make sure, like you mentioned, taking time off and not being able to connect. There are many people who are outside of the security group who are to involved here, and everybody’s very busy doing their own job. How is that overall organization need to be morphed in terms of their roles and responsibility where it becomes their duty as individuals and as people who may have an impact on overall security of the organization to make sure that it is not something which is a request sent by the security group, but it becomes part of their role, part of their performance evaluation, etc so that this is actually carried out on a regular basis. We can create a lot of policies, procedures, requests. How they are followed through, how they are executed is another thing. Please stay tuned.
Sanjog Aul:
We’ll be back and explore how do we make this a more predictable approach to not only just setting a process, but also having people, , execute the tasks that are assigned to them, and they’re measured based on that. We’ll be back
Sanjog Aul:
Welcome back. So Kevin, you did mention about different people who may be at a stakeholder level or as individual managers. They are expected to be carrying out tasks which are behind the scenes, not in a stealth way, but they are as part of you creating a secure port. One is to put a policy in place, which could be in a big handbook or part of their roles and responsibility that was just explained to them in their orientation. Another is to make sure that there is some sort of an enforced, predictable way to enforce those. Is that something that is realistically possible for your organization or anybody else out there, and if yes, then how somebody could accomplish when everyone is busy with doing their core jobs? How do you make security part of everybody’s job? Who’s responsible?
Kevin Novak:
I think the most important thing to actually recognize is that there isn’t a differentiation between their core job and their job of protecting information. So at Northern Trust, and I can’t speak to other organizations how they handle this, but certainly that we bake the requirements for managing risk and information security as part of that into every single employees’s goals and responsibilities for their annual review cycle. So it becomes part of their review. It becomes part of how they are compensated, and so that becomes part of their job. It isn’t something we consider separate. Every single organizational business unit within Northern Trust has risk managers whose focus is all of the different risk areas, one of which is information security, and all the business units have representation at the table when we talk about information security threats and how we protect them and what decisions we make to develop our standards and controls.
Kevin Novak:
So it isn’t a matter of keeping it separate. It’s baked into the fabric of every employees’s goals and objectives.
Sanjog Aul:
So if you were to go out and tell the rest of the crew, so maybe they are reporting to you or the ones who you influence, how would you suggest that they prepare for the future when it specifically comes for the security to be managed within the organization?
Kevin Novak:
Certainly, and you can’t count on every employees keeping up with the latest trend that are out there and the latest methods attackers are using to get at you. There are those interested parties that certainly try to keep up with it, and they’re certainly very helpful liaisons into my organization, but certainly to make sure that you’re socializing what’s going on. I have an awareness program that really focuses on these things, not only for clients, but also for, I mean, not only for partners, within the organization, but also for clients. You know, we socialize the different types of phishing attacks that are prevalent. We host webinars with law enforcement agencies and we bring in different individuals to talk at internal summits so that we can help raise awareness, and we have a very large, and I know I can certainly speak on behalf of most of the peers within the same kind of size and shape of my organization, We have a very large ambassador program.
Kevin Novak:
So we have privacy and security champions throughout the world. So some 200 champions that are people who have a larger part of their goals and responsibilities to support the message that we can send. So we have regular meetings and we convey the different things they need to be aware of, and they then, through a grassroots effort, socialize that with their business units. It’s absolutely something that needs to be trickle-down effect that you can socialize these types of things throughout your entire organization. So everyone has an understanding.
Sanjog Aul:
So if you had a crystal ball, or assume that you have a crystal ball, what do you think is going to be how it’s going to be morphing this whole inside security related issues, how people would be made vulnerable, how the people who would have malintent will try to become smarter and try to outsmart the security folks like yourself in order for you to be, more vigilant and more cautious on what’s going to come ahead?
Kevin Novak:
I don’t see it as a particular big change in methodologies. I think it’s just more of the same. Different tools, certainly there are going to be different ways of doing it. There are always going to be things you have. I as I was trying to convey, it’s less about a single event or a different way of doing things. It’s just going to be more of being conscious of your surroundings, being conscious of different tools that individuals are using and constantly looking for the change. So I think as lookng as you’ve built a program that recognizes that there’s an ever evolving nature and ever evolving culture of ways of perpetrating different activities, it’s less about something new you have to do and more about just continuing a program that recognizes change.
Sanjog Aul:
Now, last but not the least, what do you think you are expecting for now you do not just talk about Northern Trust, but what do you think the stakeholders, the executive management, and other leaders who you’re working side by side to make an organization successful, what can what is your appeal to them so that you want to say, help me help you?
Kevin Novak:
Certainly.
Sanjog Aul:
In your role as a CISO.
Kevin Novak:
The one thing that needs to be understood is that one size doesn’t fit all. That you have to have collaboration between all the different stakeholders within the business legal, HR, fraud, security, technology, IT. In the business unit, there has to be collaboration and recognition that you can’t always have everything you want, that solutions to most problems can be worked out so that there is, agreement on both sides, but that you can’t always have openness without certain controls, and you need to establish standards of conduct and hold people accountable for those standards in a fair and consistent manner, and I certainly encourage people to come to events like I’m at today, the F Secure Computing Congress in Chicago. You know, come to events and meet with your peers and hear some really talented people talking about these types of topics. I think that that’s the most important is to recognize that threats exist and that you need to adapt to them as they change.
Sanjog Aul:
On behalf of the show and our listeners, I’d really like to thank you, Kevin, for sharing your thoughts on how to manage security from the inside out. Appreciate it. Thank you so much again. Now, listeners, please like us on Facebook, search for CIO Talk Radio, and be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.


