Change Management Cybersecurity

Preparing for major cyber events

Preparing for major cyber events

With our world disrupted by COVID, how are you preparing for major cyber events that could most likely follow? What level of crisis preparedness, escalation processes, and communication strategies would allow your organization to handle major cyber events effectively?

Contributor

    • Don Cox, Chief Information Security Officer, MEDNAX

Download Podcast
Apple PodcastGoogle PodcastSpotifyPandoraiHeartRadioSoundCloudTuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript

Sanjog Aul [00:00:21]:

Hello, and, welcome to CTN. To learn more about the show, please visit ciotalknetwork.com, and today’s topic is Preparing For Major Cyber Events. So our world, we already know and living it in this interesting world of COVID, and we also can feel that while it has been a health crisis and a financial crisis, it could very quickly become a security crisis, which is a major cyber event could very well follow. So when we look at organizations, while they’re dealing with the decentralization of their workforce or the way they do business, even their business models, but what are they doing with the level of crisis preparedness, the escalation processes, and related communication and business strategies that will allow the organizations to handle such cyber events in the event they occur. So to discuss this, I have with me Don Cox. Don is the Chief Information Security Officer with MedNax. Hey, Don. How are you?

 

Don Cox [00:01:24]:

I’m great. How are you?

 

Sanjog Aul [00:01:25]:

Good. Good, sir. So, let’s first set the context. So major cyber event. If I was in my company, anything which could have a material disruption to my business, I would call it major, but if you were to set, say, a common ground or a common denominator, what would you call as a major cyber event?

 

Don Cox [00:01:46]:

One would be, the inability to access the data that your organization needs. So, if it’s health care, it would be patient information. If it’s financial, it would be your financial information. If it’s the airlines, it would be their ticketing system. So it’s the data. That would be, number one, and then, two, it would be the, when you talk about ecommerce, the applications, that people use in order to purchase products. So in an ecommerce environment, if they weren’t able to get to the data which displays the products that they’re trying to sell or availability, shipping information, that would to me be catastrophic for those businesses.

 

Sanjog Aul [00:02:36]:

So, essentially, anything which is in the critical path to them creating value for their customers, whether it’s internal or external, is that a good way to generalize it across the industries?

 

Don Cox [00:02:47]:

Yeah. Perfectly summed up. Yes.

 

Sanjog Aul [00:02:49]:

Okay. So now do you think there should be a threshold which one crossed? And across industries, across companies, that’s when we should call it major cyber event, and that’s where your different set of strategies should kick in, or any event which comes close to it, we should flip and start going in that major, you know, cyber event mode. What would be a threshold that you will take?

 

Don Cox [00:03:14]:

Yeah. I’m hesitant to say a standard across everything. Different companies can withstand different activities or different intrusions and still function and continue their business. So I would be kinda hesitant to say across the board. I think each industry, each group needs to be looked at differently. The size of the organization takes into consideration, the data that they have.

 

Sanjog Aul [00:03:49]:

So suppose we take your organization. Right? So let’s let’s not grossly generalize anything. So in your organization, I’m sure you handle security issues day in day out. So life as usual, you have some or the other thing happening which could cause disruption or it looks like it’s impending, so you want to kill it before it happens. So all of that is business as usual for you, but then what would you consider as something which has gone beyond a certain threshold for you to pull out your SWAT team approach to handling something that major?

 

Don Cox [00:04:24]:

Sure. So if it was a denial of service attack where, in health care, the physicians and clinicians can’t get access to the patient information. If you found out that your patient data, your financial records were being exfiltrated from the organization. To me, that would be a major incident that you would have to deal with.

 

Sanjog Aul [00:04:49]:

And could such a disruption be caused by something outside of cyber? Because we are very carefully and very exclusively qualifying this topic around a cyber event. Because a data center could go down, but not necessarily due to a cyber attack.

 

Don Cox [00:05:06]:

Yeah. Absolutely.

 

Sanjog Aul [00:05:07]:

Yes. So, how would you isolate? So you cannot we cannot jump to a conclusion that anything that gets disrupted is because someone has a malintent.

 

Don Cox [00:05:16]:

Correct. So are we using the word cyber event to include hardware failures, or are we just talking security related events?

 

Sanjog Aul [00:05:33]:

So when we say cyber, essentially, you’re talking about anything which is caused due to any online disruption.

 

Sanjog Aul [00:05:43]:

If you were to go and make it like an cybersecurity event. Or a cyber event in the context of a security related intrusion. What would that be? Since you’re the chief information security officer, you would be looked at as someone who’s going to reveal or rather go investigate and say, why did this even happen? And in the cyber world, we could have lot of things happen, something goes down, which could be an infrastructure and operations issue, but then many times, it comes down because of a potential security issue, but for that, you have to go do some digging.

 

Don Cox [00:06:21]:

Understood. Yeah. It’s from the onset of what is it that can’t be done? And then from there, start the troubleshooting. Right? Is it, to your point, is it a hardware failure? Is there a network outage that you can’t control, a piece of equipment, and the network that went down? Back to is it a denial of service attack that’s either being done on purpose or on accident? And then flip to the other side with the cybersecurity event that somebody’s credentials get compromised. Is there an insider that’s exfiltrating data from the environment? Is there an insider that’s causing, or deleting servers or doing something inside the environment that’s causing resources not to be available?

 

Sanjog Aul [00:07:14]:

Given the way we have been creating our technology infrastructure, our authorization, etcetera, I think if you were to look a couple of decades ago, we may not have a clue, but nowadays, we have a lot of safeguards in place, hopefully, for an organization as mature as yours that if something happens, it at least immediately gives us, first of all, a warning that something like this has started to happen. So you can plug a hole before the damage goes too big, more out of control. Or even otherwise, you will invariably come to know that this was done and trace it back to people who ended up either responsible or were used as a channel. Right. So do you think no, this is me sitting outside from the cybersecurity world.

 

Don Cox [00:07:58]:

Yes.

 

Sanjog Aul [00:07:58]:

So What’s the what’s the scoop, really? Can you really always claim that you will know and trace it back to the one who had the malintent or whatever the reason why this happened?

 

Don Cox [00:08:09]:

The answer is no, and this is not just the organization. I’m speaking specifically now. I can draw from many other experiences in past companies. Organizations don’t know enough about their environment. They don’t know what’s in their environment. The term that was used in the past was shadow IT. That can have an impact on your network. You didn’t know about it, and it’s causing a problem. There could have been a Microsoft patch that was pushed and took something down. You could actually have in-house development that caused something to go down, and if a user calls in and says they’re having a problem, one of the 1st things you do is, okay, what changed for that particular application? Let’s go and see if there is a change control process. Does your organization even have a change control process? Do they know what changes were made? So no. It’s not every organization that you’re able to trace it back to what could have caused it.

 

Sanjog Aul [00:09:11]:

If you took a look at the IT persona, right, that whole chain of command, they are, of course, paid to keep things humming, keep things going on a regular basis, but they typically are not trained over the years to go do big-time investigation like security. So would you go and do that job for them if it turns out that it’s an infrastructure and operations issue? Because it’s a cyber event. We don’t know yet, but somebody has to figure out where this thing went.

 

Don Cox [00:09:49]:

So in an organization, it’s going to be, depending on the size of the organization, depending upon what you’re seeing happening, and it could be the security engineers, because in organizations, typically, people start out at the service desk. They go over to network operations. They may go to infrastructure, and then they’ll bounce over to security because they really like that. So they’ll have some knowledge, but, really, in an organization, it’s going to be kind of a combined, open up a collaboration method. So either open up a Teams channel or open up a conference line, and everybody gets on and starts talking about what they’re seeing and what’s happening, and then kind of walking towards the resolution from there.

 

Sanjog Aul [00:10:42]:

Would you say that we have come at least a little farther than what it used to be the earlier days when we were like you said, we get on a team’s channel, and we start talking. Yeah? Which is having a discussion to see where to start. Have you gone beyond the Wild West approach to digging into and converted ourselves into a more systemized approach to looking at the challenges, have a very quick process of elimination of removing things which should not be looked at and start very quickly getting into the areas where we should focus, and as a result, the time to value of uncovering what could have happened is reduced. Are we there yet?

 

Don Cox [00:11:26]:

Yes. There are products out there. Splunk is a very good example, pulling in data from multiple sources and its ability to help detect anomalies based upon questions answered and kinda get you right to the point of failure and or alert you on a failure or if a failure is gonna happen. So, yeah, there’s technologies out there that could do that.

 

Sanjog Aul [00:11:49]:

So is this still a problem left to be solved in this domain? Because we still get people fired. We still see websites or any other online mechanisms they have to serve or reach out to their customers down, and somebody’s getting fired.

 

Don Cox [00:12:04]:

Yeah. It’s still a problem we have to deal with and for the reason you just said, it’s still happening. Right? So companies either don’t have the money or the decisions made not to invest the money into that technology. They don’t see a return on investment. I’d rather spend $1,000,000 on a product that is customer facing and can generate revenue than on a product that would tell me my system’s about to go down because I know it’ll take 10 minutes for the system to come back up again. So, it’s that risk versus reward conversation that happens a lot.

 

Sanjog Aul [00:12:38]:

Let’s take a quick break, listeners. When we come back, let’s talk about the different areas in which in typical disaster recovery scenario, right, when we are looking at disaster recovery, we have a way to test something, and and we know it’s gonna be down, so, this is what we will do, and we could literally pull the plug, but if it’s a cyber event, we are always on, and I’m not sure the CEO would like the idea that I’m gonna bring down my ecommerce site or my health care data availability for two hours to see how the different stakeholders, the users will react. How do you handle it? And if that’s not available as a way to test that pull the plug test in this cyber event context, how could ever we be fully prepared? And if this is not possible, what’s a happy medium? Please stay tuned. We’ll be right back.

 

Speaker 0 [00:13:38]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Sanjog Aul [00:14:33]:

Welcome back. So, Don, disaster recovery in our regular business and business continuity plans we build, we do disaster recovery, and we can do a pull the plug test and maybe build some sort of, you know, capability in our non technology, non security users to be able to deal with things when they happen, but frankly, in cyber events, we do not seem to have a recourse unless otherwise you can enlighten us on that, and if we don’t have them, then how do we be fully prepared? Can we be fully prepared? And if none of those are options, then what is?

 

Don Cox [00:15:12]:

So I’d say, can we be fully prepared? The answer is no, and I think this was, like, either, a Mike Tyson statement or a Norman Schwarzkopf statement. Once the first punch is thrown, the plan’s out the window or, once the first bullet’s shot. So I don’t think you can ever be fully prepared because I don’t think two events are the same, but in saying that, yes, you can plan for an event to happen. You can train for an event to happen and then build some kind of muscle memory. There are also a number of capabilities out there today that are actually very good at simulating events; they call some of them cyber ranges, where you can actually mimic an outage or a DDoS attack and then watch how your employees can navigate, can troubleshoot, can identify where the problems are coming from and then rectify them.

 

Sanjog Aul [00:16:20]:

So if you just have the tools, like you mentioned, it’s a tool, but frankly, in many of these situations, people are the ones who could become the bottleneck. People who have, first of all, they don’t have the intent of messing up with their day. They’re not getting paid to do this either, but, yeah, they understand the boss said so, so I’m gonna do it. Would they really when you’re doing such pull the plug tests or the tool-driven simulations, it’s the people who lose it when the real thing happens because they feel either their job is at stake or something else similar, which will create that anxiety, which will make them not do the things they would do when they were sane. How do you deal with that?

 

Don Cox [00:17:03]:

Yeah. That’s very true. So how do you deal with it? It’s culture. As a leader, the onus has to be on your back. You have to say that if we fail, if we’re breached, something’s accessed, it’s on me. Because I either didn’t give you the tools, I didn’t give you the training, I didn’t give you the staff you need in order to be successful. So you tell everybody, as long as you’re doing your best, you’re gonna be protected, covered, and we just need you to focus and remediate the event, and get us back to being protected again. So it really comes down to developing that culture. Now having dry run exercises, simulations, those are all necessary. Sending people to training for different things, having people that are certified in certain areas to help, those are all exceptional as well. There might be some simulation tests you can run. Right? You have a development environment, so why not use your development environment and simulate some activities? Hire an outside 3rd party to come in and set up some simulations and run your people across those in a development environment, or maybe hire a company that has an environment that you can play in, like I was talking about the cyber ranges.

 

Sanjog Aul [00:18:27]:

So one is to, of course, get people on board and as you mentioned, the culture, and assuming that the culture at least looks good and people are willing to do that. We still have to come up with rather exhaustive checklist, which has the obvious things which most people talk about in the disaster recovery world or things you got to kind of check in that checklist, but then there are certain things which come from experience which you may know which are not as obvious. The to-dos or the things to look for, some gotchas or the pitfalls that you have to watch out for when you’re preparing for a major cyber event? What would those be?

 

Don Cox [00:19:08]:

Yeah. I’ll give you a great example. Right? And here’s a story. So, I was working with a federal government agency, and we started to receive phone calls from our customers saying that they couldn’t access their file shares, couldn’t access their email. So we began to investigate, and at the time, we had one of the $2,500,000 SandShark that were supposed to never go down and always work in our data center, and we found out that the SAN wasn’t functioning, and we bought the 3rd-party help instead of the company that sold it to us, but luckily, we got a person that had worked with the SandShark organization before. He had joined on the 3rd party. So he comes in and realizes limitations, and he says, yeah. I don’t know how to fix this. When I finally came in to fix it, they found out that it was a patch that we didn’t apply, and there was a heat sink that fell off, but one of the things we learned from that entire event was, one, maybe don’t pay for the cheap services that come with it, but two, the thing that we learned was we lost all communications. We couldn’t email each other anymore. Our phones didn’t work. So we were just dead in the water trying to communicate until somebody realized that our BlackBerry devices had PIN numbers in them, and you can actually call somebody with their PIN number. So we had to run around and get everybody’s PIN, and create a list instead of trying to create a list of phone numbers. So it’s things like that where we looked at the book, we exercised, we researched everything, but the event happened, and, yeah, we had no idea we were gonna lose the ability to communicate with each other.

 

Sanjog Aul [00:21:04]:

So that means improvisation is going to always be required because you never know what’s gonna surface.

 

Don Cox [00:21:10]:

Absolutely. You have to think outside the box. Not settling for, you know, it can either be a, b, or c. Well, what about d, e, f, g, h, i? And I just keep thinking of ways to be successful.

 

Sanjog Aul [00:21:28]:

And when such a major event happens, and not everything can be solved within days or even hours. Right? Something could be long-tail. We hope not, but that could happen. What’s the management’s benchmark that if we are to be prepared, we got to be able to prepare ourselves with some sort of an internal SLA that if we have a major cyber event, we should be able to get to the status before the event within these many days or at least the minimum viable product type of level, like that minimum level of viability, we should restore within, say, 4 hours. Is there something which is very company specific, or is this a benchmark or a standard even established for something which is a major, which could come in different shapes and sizes? We do not know if we can even put our name on the line to say, oh, I’ll get it done to the minimum viable level in four hours and fully restore in two days. Otherwise, you fire me.

 

Don Cox [00:22:35]:

Yeah. So this is where organizations fail. There’s terms out there these days, RPO and RTO times. Right? Recovery point objective and recovery time objective. So, organizations are gonna have to sit down and they’re gonna have to look at what are their high value assets. What are the things that the organization must have in order to continue business? Then you’re gonna have to sit down and evaluate how they’re protected and how they’re backed up and what are their redundancy plans. Right? Do we need high availability? So the old 5 nines, 6 nines, 7 nines capabilities. Or, do we have the ability to have a hot site and a warm site, or can we have a hot site and a cold site? Another example that I have is I was with an organization where we were billing $500,000 every 15 minutes. So that was our benchmark that the moment we hit if we couldn’t get it fixed within 15 minutes, we had to switch over to our off-site and start operating out of there because we would start losing $500,000 every 15 minutes. So I think you have to look at what’s the brand impact to the organization? What’s the revenue impact to the organization? How long can you stay down? Some companies can stay down longer, and then from there, you go back and you build those tables with the recovery point and the recovery time objectives, and then you invest in technologies that help you maintain those levels. Now, there’s always the event that’s unplanned for and natural disasters and a truck drives through your door or those things you can’t plan for, but it’s something that you should consider. What do we do if something happens and we can’t continue to work in this building?

 

Sanjog Aul [00:24:32]:

So you mentioned about, if such an event happens, then you wait for 15 minutes or less or move to off-site, which is assuming that you could totally keep a parallel warm site or a hot site running, which is totally isolated with this current one and whatever caused this main primary site to go down has not at all impacted that parallel run that you were having. Are we that clean in our systems and processes and the way we run our shops that you could do this?

 

Don Cox [00:25:07]:

I would say no. I mean, it’s from organization to organization, it’s gonna differ. Some are gonna be more mature. They’ve hired the right people, whether they brought them in house or outsourced, and they’ve created capabilities that will protect them. Specifically, ransomware is a good example. I used to be a detective, and I investigated fraud and computer crimes events years ago, and we would get called in all the time, for events where they didn’t call them ransomware back when I was doing it, but where viruses would shut down computers and take things hostage, but we would come in and we’d say, okay. So we’re not gonna be able to resolve this for you. You’re gonna have to go back to your tapes or whatever you have and restore and get back up and running again. So companies need to think about it. They need to have plans in place, but across the board, I don’t think everybody’s doing it effectively.

 

Sanjog Aul [00:26:09]:

Now now let’s look at the aspect of cybersecurity. As I mentioned, that most of the times when any of these things happen, which you cannot easily explain, first, hunch is that, hey, it has to be a hack attack or something where someone has malintent and they came through the cyber and they wanted to take it down, which means, your organization, the CISO’s organization, is the one on the spotlight, but at the same time, I’ve spoken and interviewed and facilitated discussions with quite a few CISOs, and frankly, when budget comes and resources come, that’s actually a sore issue with them. When you have this much riding, and you’re supposed to, and your organization’s supposed to deliver on something whereas in you said, like in 15 minutes, you can start losing 50, whatever, dollars 500,000, then why this tug of war for resources? And if you needed the support and resources, how would you define that resource set or support mechanism which will allow you to front end these crisis and deliver successfully?

 

Don Cox [00:27:29]:

So there’s always the give and take between needs and wants. I think for one, organizations are now starting to see the importance of cybersecurity to their longevity and success. So they’re removing the budget for security from the CIO’s budget, and they’re creating independence, and justifying budget needs based upon what the organization needs to be successful. Absent that, it’s really a conversation about probability. Right? So back to risk, the probability of events occurring, and if that event occurs, what’s the damages? And then because you only have a finite bucket of money, organizations have to assume some risks somewhere. Either deal with the risk with insurance or transfer the risk to somebody else by buying their capability. So once you’ve identified where the risk is in your organization and then you go down that process of trying to put compensating controls in to mitigate it, eventually, you’re gonna get to a point where the money’s gonna run out, your staff’s knowledge is gonna run out, and then a decision has to be made how do we go forward with doing this?

 

Sanjog Aul [00:28:54]:

Let’s take a quick break, listeners. We’ll be right back, and and talk about the set of things which you would still need. So granted, if the executive management is understanding and appreciative of what cybersecurity group does, gives them the right budget, but at an organization level, the whole organizational level, what kind of support and resources should be offered? Who should be front ending? Or who should take the main ownership and responsibility of dealing with a major event and seeing it to resolution. Please stay tuned. We’ll be right back.

 

Speaker 0 [00:29:32]:

Today, enterprise technology is both strategic and global. Each week on CTN, CIO Talk more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the

 

Sanjog Aul [00:30:26]:

show. Welcome back. So, Don, besides budget, if you were to build a repository or I would say longer checklist and or request sheet where you would say, this is the things you give me, mister business executive management. I’ll be able to see it through, and with that, I’m assuming that you are taking the lead as a cyber sec, like, a CSO or a security leader within the organization, but if it’s a cyber event, who should truly take ownership? Shouldn’t that be you anyway, or would you say let’s CIO front end and you come beside them? What kind of structure would you make, and then what resources and support would you like to have, like a charter? If I had to build a major, major cyber event intervention charter, what should that look like?

 

Don Cox [00:31:16]:

Yeah. So it’s really gonna depend upon the size of your organization and resources available, but let’s just take a large organization. Yes. The CISO should own the event if it’s determined that it is cybersecurity related. If it’s cyber related, then the CIO should own it, or the CTO, whichever is designated. So in a cybersecurity event, you’re gonna follow NIST. The National Institute of Standards and Technology (NIST) has a very good incident response plan. I’ve been in the federal government working for a number of years and so very familiar with it, and it lays out step by step criteria for declaring an event and whether the event is high or critical, and then it goes down into who should be notified and when that person should be notified. So all these things need to be documented and trained on ahead of time, and then print it out and put in paper and store it someplace just in case your SandShark goes down and you need to refer to it, so you can get to it, and so even within the CISO owning it, the CISO needs to remove themselves from the actual incident response. So they need to create and then I’ve created in past organizations what’s called a CERT team. Right? So it’d be a computer incident response team, and that team is made up of individuals from each one of the different specialties within an IT organization so that you can actually almost like a SWAT team or some special forces team. They have the knowledge, skills, and abilities to go and deal with this event, whether it’s a cybersecurity breach, and how do we block the IPs, the firewalls, if the person’s inside, you’ll get rid of their access, and then that person then communicates back up through the CISO on details what’s going on. The CISO then reports to the executive staff. So you’re gonna need to have media involved. You’re gonna need to have legal involved. You’re gonna need to have a representative from the CEO’s office involved. You might have to have HR involved because it may deal larger. So you have to have all that planned, documented, mapped out, and trained on, or at least people read it, for you to be successful when you move forward.

 

Sanjog Aul [00:33:43]:

Now with that said, would you say anything that could create a confusion? So one is that you laid out a playbook. This is what we should do, but where can the confusions occur? What are those dark areas or blind spots which where most people, lose their focus and or get frustrated or there’s a lot of leakage or things don’t get done?

 

Don Cox [00:34:10]:

Yeah. So the organizations I’ve been in the past, it’s become almost a fist fight. People become very protective over their environments, and they don’t wanna be known as the reason why something failed, and whenever I go in organizations, either as a CIO role or a CISO role, I sit all of my leadership team down and I tell them, there can’t be any finger pointing in this organization. Today, it’s gonna be you. Tomorrow, it’s gonna be you. The next day, it’s gonna be you. So go into each one of these events knowing that you’re gonna get the support from each other. No one’s gonna be criticized or chastised. We just need to come to a resolution on it as quickly as we can for the best interest of the company. So that’s how I approach it, and that said, you still have individuals that say, not mine. Not mine. Not mine. I didn’t cause it. I didn’t do it. It’s this product over here. Famously, there’s an awesome product called Carbon Black. I’m just so used to saying the other word. It was referred to as carbon block for a long time because it was always stopping processes, but really, it came down to people didn’t know what it was supposed to do. So every time something went wrong in the environment, they would just automatically point to security, say they did it, and then security would have to go troubleshoot it and say, not on any of our tools, but we think it’s this one over here. So sometimes you lose that troubleshooting when you start finger pointing at individuals, and you really have to get the teams to work through all of that.

 

Sanjog Aul [00:35:47]:

So if you were to go in as a consultant, yes, you will tell them no finger pointing, but frankly, because you tell them, they’re not gonna listen.

 

Don Cox [00:35:55]:

True. So that’s where the team training comes in. You have to get these individuals that work together kind of on a personal basis. Give them something more than that’s just Johnny or Sally that works over in network operations. They need to cross train together. You need to do some team building together. You need to have exercises where they’re given a problem and how do you resolve it to kinda give them some examples and knowledge. You might as well also get your senior people to talk to the junior people and give them some lessons, or some knowledge about past experiences, some things that failed, and some things that were successful, and, hopefully, you can use that peer mentality to make the organization better.

 

Sanjog Aul [00:36:41]:

So just because it’s such a major event, right, that’s why we are qualifying this to be a major cyber event, does that have any influence on the gravity that is felt by all people? And the people who otherwise would say, yeah. It’s not my thing, so you deal with it. They know now their job, their ability to deliver value, all of that is at stake, and they better come on board in all hands on deck.

 

Don Cox [00:37:09]:

Yeah. That’s definitely true, and I honestly did miss the first part of your question there, but I hope I’m answering this one correctly. There needs to be a conversation on we can’t have this behavior. We can’t act this way. If the organization fails because we didn’t come together as a team and we’re unable to rectify this, then we’ve let the rest of the organization down. People don’t have jobs, go out of business, whatever it may be.

 

Sanjog Aul [00:37:41]:

Yeah. So I was referring to maybe since you didn’t hear the first part, what I was trying to differentiate is one is a major cyber event. Right? You get a lot of cyber events happening all the time. Right? In different degrees. Yes. So when it’s a major one, do you change your approach to how do you deal with it? Because at that time, if anyone is finger pointing, frankly, the person knows they are on their way out because the company is hurting

 

Don Cox [00:38:05]:

No. I think you deal with the little ones just in the same manner that you deal with the big ones. Right? Employees like consistency. They like the fact that if it’s a minimal cyber event, whether it’s a minimal cybersecurity event, that their leadership is going to be even keeled. They’re gonna be openly communicative. They’re not gonna be yelling and screaming at people, and they’re gonna be helpful and trying to give the team the things that they need to be successful. So that’s gonna build that trust between the two. If there’s a serious cybersecurity event, which could lead to loss of money, and you’re gonna start yelling, screaming, people are gonna get defensive, and they’re gonna be like, I don’t wanna go out on a limb and try to help out because it could be me that loses my job if I point out what caused the problem or if it was me that caused the problem. So I think as leaders, you need to be very consistent in how you handle situations. For me, it’s always handling them with a leader being calm, cool, collected, and very careful about how they communicate with their team.

 

Sanjog Aul [00:39:33]:

Now you did mention about the muscle memory that you send people for training, let them come and do the things that they’re supposed to, maybe simulate scenarios so that they are able to behave the way you expect, but people don’t do what you expect. People do what you inspect. Is there a way to test them? And I know we spoke about pull the plug test is not that easy. What have you seen in your experience? The people, the way they behave, the way this whole thing was carried out or restoring to normalcy, if a major cyber event was simulated versus an actual happening, I hope you have not had to deal with this major cyber event, but if you did, what was the gap that you found?

 

Don Cox [00:40:21]:

Yeah. So I have. Back to my days as a law enforcement detective investigating computer crimes, I’ve been inside of Fortune 100 and Fortune 500 companies that are losing millions of dollars a day in revenue, and they’re just trying to get it down to, like, under $200,000 before they kick everybody out and go from there. So, I’ve been involved in a lot of those activities. For me, it’s really gonna come down to the people that you have on your team, both people internal to the organization and people external. That’s one thing I didn’t talk about when we’ve been having this conversation: not relying just on the resources that you have in house. You’re gonna have to create relationships, partnerships with your vendors for the different products, and you’re gonna have to get them involved in your process of troubleshooting recovery along the way.

 

Sanjog Aul [00:41:22]:

Let’s take a quick break. Let’s first, we’ll be right back, and we spoke about the people side a little bit, how an individual who did not sign up when they joined the company that I’ll have to deal with all this, and I’ll have to be part of it. So, yeah, leadership level, you get it, that it’s a responsibility, and you come with that mindset, but if that administrative assistant who just came to help schedule stuff, and you’re saying you have to be custodian of the data that you create. You are supposed to make sure that you are behaving in a responsible manner where it does not hurt, our organization, and if there is a cyber event, this is how you’re gonna change your behavior or the way you used to do, the things when the business was normal. They may say, yes. I’m gonna do it, but there will be a delta. How do you minimize that delta? How do you get them to become alert or rather stay alert? And if something like this happens, they immediately switch to the desired state of how they operate. Just because training you do, that doesn’t motivate people. Training doesn’t motivate people. What will?

 

Don Cox [00:42:40]:

So, I guess, you can go to the one extreme and say that your supervisor HR will be involved, and there’ll be some kind of retraining. There’ll be some kind of remedial action and or you’ll be disciplined and which can include up to being terminated from the organization. Right? That’s the one side. The other side is to sit down with the individual and maybe some one-on-one training. Do you understand what’s being asked of you? Have you ever had any experience with what’s being asked of you? Can we create some opportunity for you to practice what we’re asking or expecting of you? And then it’s also sitting with that individual and explaining to them why we need their participation, why we need their help. I mean, if you push it back to your job is to do this and protect this data. If you don’t and the data is compromised, then the organization loses revenue, so it’s gonna impact our stock price if you’re publicly traded. Or it’s gonna impact our brand, and people are gonna stop wanting to come here, and then, unfortunately, when we start looking to reduce staff, there are just positions in the organization that we’ll have to remove first. So, it’s that fine line or balance into trying to get that individual to understand the importance of their role in the cyber and cybersecurity posture.

 

Sanjog Aul [00:44:13]:

Alright. So since this was a question we were supposed to answer, you anyway thank you so much, Don. You answered partially, but I’d like to dig deeper into it. So let’s take a quick break, listeners. We’ll be right back, and let’s see who else besides the CISO should join hands in getting these people across the board to step up and play a responsible employee of the company and help in case of a major cyber event. Please stay tuned. We’ll be right back.

 

Speaker 0 [00:44:40]:

Today, enterprise technology is both strategic and global. Each week on CTN, CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, You are listening to CTN, CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Sanjog Aul [00:45:34]:

So, Don, you mentioned about motivating people by giving them a bigger picture, perhaps tell what’s at stake, etcetera, but then, what other tangible on the ground things we can do, whether from hiring practices to policies to governance structure to something which works versus saying we tried. We, like, predicted weather. Guess what? It did not work. That was not gonna fly in this case.

 

Don Cox [00:46:03]:

Yeah. Just thinking about this over the break. There really needs to be a top-down approach to the seriousness of what it is that you’re trying to get accomplished. So, if you’re a company with a board, there maybe there needs to be memos or emails from the board saying that we’re invested in this and we need this to happen. CEO has to be out in front of the cheering saying, we need everybody to be part of this, and then follow on down your proverbial chain of command from there, but you’re absolutely right. Policies, procedures, all of those things need to be in place, combined with training, in order for the organization to be successful.

 

Sanjog Aul [00:46:58]:

So let’s talk technology. So you did mention a few technologies, that are there which will help you in major cyber events. If you were to keep the specific brands aside for the technology tools, what would you say would be a good core stack that an organization must have and have their people be ready to use them to best handle the major cyber events that could happen?

 

Don Cox [00:47:25]:

Right. So in the middle of that, and I’ve done this in a number of organizations. This is kinda how I build out the cybersecurity architecture. You start in the middle with a SIEM tool. Right? So you need something that can aggregate all of the log files, all of the events that are happening in your environment, and one particular capability to say that, if these events happen, then I need to know about it so that I can then alert either the network team or the security team or the database team or somebody. So SIEM tool has to be number 1. Then as you move out from there, you start looking at the different components of your infrastructure. So how do I protect my servers both from not letting malicious files run on it or applications run on it to what kind of antivirus and malware on there, all the way to the laptop or the mobile device or what have you. How am I going to make sure that that mobile device is patched properly, has the antivirus on it, has all the things that the organization needs in order to protect it. Then you start moving out to your cloud environment and how are we communicating the cloud? What security do we have in place in the cloud? You start looking at your identity access management stack and, do you have the differentiations between privileged access and just regular access, and do you have multifactor authentication in there in order to challenge people? Move on around. You definitely have to have some next generation firewall equipment in there to help you with some of the DDoS attacks you might see or stopping things from the perimeter. You need to look at technologies like geofencing. This application can only run from this one particular location, no place else, or these people outside this IP address can’t talk to us. So there’s a whole host of technologies, and then on your development side is how do you put cybersecurity inside of the development process? So, you know, you’re starting to hear terms like DevOps and DevSecOps and shifting left from where security is typically applied and putting it in the build process, automating a lot of provisioning of servers and tools that developers will need or infrastructure will need so that you can take the human mistakes out of creating infrastructure that’s needed for applications to sit on.

 

Sanjog Aul [00:50:14]:

Once again, thank you so much, Don, for sharing your insights and how organizations can prepare for major cyber events.

 

Don Cox [00:50:23]:

Thank you.

 

Sanjog Aul [00:50:25]:

And listeners, hope you enjoyed, got some nuggets. Maybe you’ll be better prepared for the major cyber events, which we hope will not happen, but if they do, you’ll know what to do now. Please connect us on Facebook, LinkedIn, Twitter, and Pinterest, and subscribe to our podcast on Apple and Google Podcasts as well as wherever all major channels are available where you can go and listen to the podcast. Once again, thank you for listening to CTN. This is Sanjog Aul, your host. Till next week, take care, and God bless.

Contributors

Don Cox

Don Cox, Chief Information Security Officer, MEDNAX

Don Cox has over 25 years of experience in technology. Don started his career as a Special Agent with the US Secret Service Electronic Crimes Task Force in Washington DC, investigating high-tech crimes and conducting computer forensic inves... More   View all posts

Advertisement

Grande 1 MPU 300X250
Don Cox