While the times demand making our cities smart leveraging innovation in water, waste, and infrastructure management using IoT (Internet of Things), what security risks are getting introduced? How vulnerable are these smart cities to cyberattacks and what are we doing to secure them?
Contributors
-
- Mark P. McDonald, Chief Information Officer, City of Vancouver
Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
- How to make IT security everyone’s business?
- How to Build an IT Security Team
- IT Security: Future Perfect?
- IT Security: How much is enough?
- Securing Business Growth with Cybersecurity
- Cloud security, cost, and culture: Technologies Concern
- Ensuring Digital and Virtual Healthcare Security
- Embedding Security in Technology Capabilities
- Security and Agility – Tips for Getting the Best of Both Worlds
Transcript
Sanjog Aul [00:00:24]:
Hello, and, welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. As always, we invite you to join the discussion on Twitter, #CTR live, and look for this show as #IoT and hashtag smart city. Today’s topic is securing a smart city, and our guests for today’s show are Gary Hayslip, who’s the deputy director, chief information security officer for the City of San Diego, California. How are you, Gary? Good morning. How are you doing? Oh, could not be better. It’s beautiful out here in Chicago. How about you?
Gary Hayslip [00:01:00]:
Well, I said the sun’s coming up here, but it’s gonna be a beautiful day here in San Diego.
Sanjog Aul [00:01:05]:
Oh, great, and we also have Mark McDonald, who’s the chief information officer at the City of Vancouver. How are you, Mark?
Mark McDonald [00:01:12]:
Wonderful. I am glad to be here.
Sanjog Aul [00:01:15]:
That’s great. Now we’re gonna talk about, the smart city. We have been seeing that as a dream in the past few years, and now many of the cities have really worked hard to make it a smart city, which in a way means that you are going to be able to use technology to make the different resources available and also make them scalable and extensible in order to meet the demands of inflow of citizens or whosoever is living there. The cities are primarily growing. So that was the very basis of this whole initiative. Now if you were to compare to what you thought as when we were dreaming about it versus where we are now. So Gary, starting with you, what do you see we have accomplished and what is still to happen?
Gary Hayslip [00:02:03]:
I can tell you from like the city of San Diego, we have a very robust startup community and tech community here. So there’s always companies that are volunteering to help the city out with new projects. I’ve only been with the city 2.5 years, but I have to admit over that 2.5 years, it’s been fascinating to watch the 40+ different departments. They want to offer new services. They want to go ahead and work with the citizens and provide new services to them, and a lot of these new services are new technologies, new interconnected technologies, and anybody that’s worked with cities understands that the cities have large disparate type networks. So it’s quite interesting to bring these new technologies in, but to do them securely.
Sanjog Aul [00:02:52]:
So, Mark, when you look in your organization or rather the city that you represent, what was the dream that you had laid out? And to what extent have you been able to bring it to fruition?
Mark McDonald [00:03:05]:
Well, when I look at the City of Vancouver, what we’ve done is we really wanted to drive, citizen engagement and access to citizens, in the format that they would like to engage the city in, and that’s really been realized over the past four years of my tenure here, as a Chief Information Officer. I think the big emergence here has really been the entire ecosystem of the city. So now we’ve got transit, healthcare, utilities, logistics, education, all collaboratively engaging on making Vancouver a smart city and a world class city.
Sanjog Aul [00:03:39]:
Now when you say, Mark, about your city, so people said or citizens said, this is what we want. Can you inventory a little bit about what exactly did they say? Did they suddenly say that we want a cool, more progressive and more technology centric, or they were sticking to the same infrastructure and safety and availability of resources at all times as citizens so that they go about living their lives?
Mark McDonald [00:04:10]:
No. It’s just the complete opposite. Really a shift in the paradigm is that the citizens and businesses have really demanded the ability to transact everything from a mobile perspective. So they want to be able to pay their property taxes, pay for parking fines, register for swim lessons, all in a mobile capability here. So that’s really driven out our ability to expand and to a large degree from a security standpoint, it’s really created a different exposure surface for us in terms of security with technology.
Sanjog Aul [00:04:47]:
Now Gary, when Mark talks about, the smartness or the new things that citizens want and that is to have mobile get incorporated in the way transactions happen, that’s like a natural, progression in terms of people using mobile phones, so they want to have that as a transaction. That’s the evolution on the technology front, but for the sake of technology, and, yes, of course, it’s gonna deliver services. When we talk about smart city, in a way, it is tied at the hip with the Internet of Things paradigm or the computing method. To what degree do you think citizens have asked for it versus we saying, okay. We ought to do it?
Gary Hayslip [00:05:28]:
Well, it’s quite interesting because I came from DOD where we just did what we thought we needed to go ahead and protect the country, and we had very little input from the citizens. We’re here. Everything really is directed. A lot of the projects, a lot of the stuff that we do is directed by the citizens. They definitely interact with you, and we’re doing a lot of the same things. Citizens here in Sydney and San Diego, they do want the same thing with mobile and with apps. They wanna be able to sit on their couch at home, pull out their iPad, and be able to pay their water bill. They want a lot of the same features that they see other cities have. The mayor’s updating the website and everything updated, the city website to be more interactive for the citizens. We’re already looking at developing apps and moving into the mobility phase because more of the citizens want that ability. What I find interesting is cities don’t really have to be innovative in some ways because they don’t have any competition. It isn’t like you have another city coming to steal your citizens. So it isn’t like a business where you have to compete against competitors. What drives innovation, I think, in a lot of cities is the citizens themselves who are looking for updated services. If they can do things with their phone at work, why can’t they do things with their phone when they interact with their city? And they demand it.
Sanjog Aul [00:07:06]:
So if we go beyond the mobile related innovation or automation, so, Mark, what all have you envisioned and then executed with respect to Internet of Things so that you’re behind the scenes? One is to interface with the citizens to make their life easy. Another is to become scalable as an organization, and for that, Internet of Things was introduced, and that’s what was the genesis of us calling a regular city as a smart city once you have that in place. What all has been envisioned and to what degree have you executed on that vision with respect to Internet of Things?
Mark McDonald [00:07:43]:
Well, I think one of the big things that we’ve done is with the integration of our CCTV camera systems across the city that monitor everything from traffic to our real estate and facilities buildings. So we’ve really integrated systems there to assist the citizens in terms of not only identifying where problem areas may be within the city via traffic congestion, be it areas where there’s some emerging events, right on down to managing security behind the scenes here across the city, at our 600 or 700+ facilities that we have. So these are systems that we integrated. They were disparate when I arrived at the city, completely uncoordinated and we’ve undertaken to really integrate those and make it smart in terms of some decision making and data and analytics that we’re using to really manage citizen lifestyle and the workflow there.
Sanjog Aul [00:08:38]:
So, Gary, when we talk about security, because that’s, of course, close to your heart given your role, would you say that there is a certain benchmark that a citizen has which may be implied or explicit in terms of how city makes them feel vulnerable versus secure?
Gary Hayslip [00:08:58]:
I present at a lot of different events and for a lot of different organizations here in the city. I talk to a lot of citizens. At times, I get really appalled at small businesses and their lack of knowledge in dealing with cybersecurity. What I do find talking with citizens is that they expect whatever data the City of San Diego has to be secure, and they expect us to do our due diligence with whatever technologies, whatever services they’re providing us that we will protect that information, that we will provide them secured services, and they just expect it. It isn’t something that they’re asking us to. They’re expecting that we have already thought about it and already have it built in. The cybersecurity plumbing per se is already in place before we were to go ahead and even offer a service to them. So the security life cycle that we’re putting in place, the security operations center that we’re standing up, a lot of the cybersecurity program that I’m building out for the City of San Diego is all built on operational resilience. It’s all built on allowing us to be flexible and be innovative, but at the same time to provide that inherent security behind the scenes so the city can go ahead and give the citizens the smart services that they want, and the security is there for them.
Sanjog Aul [00:10:42]:
So, Mark, if you look at the security levels that you could enjoy or at least you were confident that you are offering a secured and safe environment to the citizens pre IoT or pre the smart city endeavor versus now? How much more work or how much more complexity has gotten introduced because of us trying to, of course, give them more and get smarter and get more automated?
Mark McDonald [00:11:09]:
I would say if I do a pre versus post, our efforts here at the City of Vancouver to really become more automated and offer citizens more access to technology has just exponentially increased the level of security risk, and it’s really a trade off. It’s really the trade off between offering citizens the ability to have access to new technologies and automate the city as a whole versus managing the risks that we have through exposure to things such as our CCTV networks, our water wastewater infrastructure networks, our mobility. So as we progress, once again, we’re exponentially opening up the threat opportunities and vectors there, which we have to manage from a risk management perspective.
Sanjog Aul [00:12:02]:
So given that there is an increased risk, Gary, have you have you kind of rethought what security should be in the new age, which is post or not post, I would say, with inclusion of IoT, the smartness that we’ve introduced within the city.
Gary Hayslip [00:12:20]:
Oh, yeah. IoT brings a whole different layer, a whole different texture of security because a lot of it is relatively new. Some of these newer technologies, when they come through our tech review and we’re helping the departments plan out their projects and we’re looking at is it within my CIO’s technology roadmap or where we’re going over the next five years. Some of these things are our best guess. They’re so relatively new, you don’t know what threats, and so I’m already trying to plan, okay, what security controls do we have in place? What do I think is our baseline risk for some of these projects? Is it acceptable? What happens if we do have a breach with it? I find a lot of times what I end up doing is I talk with my peers. I reach out with other CISOs here in the region whether it’s over at Qualcomm or Illumina or Petco or other companies here. I ask them, you guys are using something relatively similar to this. What issues have you had? Because sometimes you don’t know. I honestly find a lot of the IoT technologies that you put in play, they provide newer services to the citizens or make it easier, but there’s a lot of additional planning. There’s a lot of extra things that you have to take a look at, especially if it’s cloud based. Are you ready for that? Are you ready to extend your perimeter to somebody else’s data center? And some cities aren’t ready for that. Some cities are used to keeping everything on premise, but in today’s day and age, where you’ve got a shrinking amount of funds, but you still have to be able to provide security for your IT infrastructure, you start looking at other new technologies that you can leverage and there’s new risk. There is a different level that you have to now really focus and do a lot of research on and figure out, am I doing enough? Do I need to change my workflows and my policies to reflect these new risks that we’re taking? I spend a lot of my time making it visible to the mayoral staff, making it visible to the IT leadership team here so we can plan for it. So we can take a look at it and see, do we have what we need? Do we need to ask for more funding or do we need to put other controls in? Sometimes we’ve even had, for a technology project, we’ll say, hey, we don’t know enough about this, but here’s some other alternatives. Could we look at one of these? You basically don’t want to say no. You want to be able to say maybe.
Sanjog Aul [00:15:06]:
Imagine me riding in a car, and its car is moving, and we come to know that somebody is attempting to change the wheels in the car, but the rubber that is being used in the wheel is of a new material which has not been tested before. How comfortable will I feel? The reason I draw this parallel is of a citizen who says that, okay. You’re gonna try to make the city a smart city. You’re gonna give me more features, but you’re going to try to secure it where you do not know if that very material that you use, which is IoT in this case, is itself evolving, so you do not know everything about it. So if you don’t know enough about it, how could you ever secure it? What’s the level of visibility that has been offered to citizens in that regard, and how much confidence internally that is there within the departments and within the city departments that they can pull it off and they will still be able to maintain the security and safety of the citizens while they deploy IoT. Let’s talk more about it when we come back. Please stay tuned.
Speaker 0 [00:16:27]:
When it comes to business, you’ll find the experts here. Voice America Business Network. HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner.
Speaker 0 [00:17:05]:
We hear it and read about it every day in the news. America is heading over a fiscal cliff. Home prices are still receding and unemployment growing. How can you preserve and increase your wealth in this kind of economy? Tune in to turning hard times into good times with host Jay Taylor. Jay will explain the decline of our monetary system and the economy, and we’ll give you winning investment ideas and the tools to protect and increase your wealth. Turning hard times into good times with Jay Taylor can be heard Tuesdays at 3PM eastern time, 12 noon Pacific time on the Voice America business channel.
Speaker 0 [00:17:39]:
If you currently or aspire to serve on a board or work in a leadership capacity for or with a public or nonprofit organization, where can you turn to get the best advice and practices? How about leadership matters with doctor Cheryl White, Linda Shub, Gerald McFadden, Andre Howard, Tom Wall, and Rianna Absar. Our program discusses challenges facing both public and nonprofit leaders. Don’t miss these practical solutions and tips to enhance your leadership style and effectiveness. Practical solutions and tips to enhance your leadership style and effectiveness. Leadership matters airs live Wednesdays at 2PM Pacific, 5PM Eastern on the Voice America business channel.
Speaker 0 [00:18:17]:
When it comes to business, you’ll find the experts here. Voice America Business Network.
Speaker 0 [00:18:32]:
You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.
Sanjog Aul [00:18:58]:
Welcome back. So, Mark, when we, I gave an analogy before we got into the break, about a car where somebody’s sitting in there and you’re having, a wheel being changed and the new wheel that you’re putting in, its component or the rubber that you’re using is of an unknown material or something which is which is relatively new and you do not know, how well it’s gonna work. I would not feel good as a passenger. So what are you doing, drawing that as a parallel to the IoT and making it smart and also making it secure?
Mark McDonald [00:19:29]:
Well, I think, part of your question also was what type of visibility do we give to citizens and what level of internal confidence do we have? And I think the approach we’ve taken is that when we look at IoT and the emerging technologies that are here, some uncertainty is really going to be the new normal for us, and so what we’ve done internally within our organization here at the City of Vancouver is we’ve given ourselves some relatively safe space to experiment and fail through our budgets, through our pilot projects, through some of our internal innovation labs here. Now in terms of visibility to the citizens, what we’ve done is we’ve really managed visibility very, very carefully. I think citizens are very much interested in end result, and net benefit to them, as citizens. So one of the things that we’ve clearly done is really try to communicate with the citizen in terms of the benefit to them and how we arrive at that is really going to be pretty much up to us as long as we’re within our capital budgets, we’re not raising taxes and other things that are negative to citizens. So one clear example here is with our real estate and facilities organization. We’ve been piloting very heavily smart buildings, so sensors that are involved in managing everything from elevators to HVAC, but even more importantly, we trialed sensors in one of our assisted living facilities that actually sensed if someone actually fell and there was no movement, and they were able to track and sense the body temperature, the room temperature, whether or not there was a medical emergency. We met with some moderate and early success on that. Some of our citizens felt it was a complete waste of citizens’ and taxpayer dollars. However, one of the things we did do was really advance the collaboration with our health care organization through Vancouver General Hospital and other areas. They latched onto this project, and actually, now we’re expanding it further than we ever imagined it would be. So that’s kind of the trade off that you have to have when you look at Internet of Things, you’re dealing with citizen sentiment and citizen budget. You have to really weigh out how far do we push the envelope to really make progress and give citizens the type of usability they’d like and still manage expectations.
Sanjog Aul [00:21:47]:
Gary, what sections of your departments, Oh, how many sections for that matter you’ll have to create in order to effectively deal with this? Because you cannot be looking at just an overarching way to secure it because each department may have their own needs, the way they will deploy the existing technology, or they may have deployed the existing technology and at the same time trying to experiment with IoT. So how are you even kind of unraveling this complex maze, if you will?
Gary Hayslip [00:22:16]:
Our departments aren’t independent. If you’re doing technology, IT related, it’s going to come through our tech review. It’s going to come through the IT business leadership group. We’re going to review the technology. So you’re not going to have departments that are going to be funding, building and deploying technology that we don’t know about. With that said, we do have room to go ahead and experiment. I have several startups, several cybersecurity startups that are in the city that are deployed within my cybersecurity suite. My team is being trained on some of the different tools that we use to protect the city. So we’re being kind of innovative and bringing in newer technologies from a security perspective to protect the city and protect its infrastructure, but as Mark was saying, unknown risk is going to be the new norm. IoT to me is relatively new. Even though it has probably been out there for a long time, I’m seeing the technologies pick up steam. You’re seeing it everywhere now. Everybody wants to connect everything. Which may not actually be a good thing because once you’re connected, you can hack it. That’s one of my biggest concerns is that a lot of times when we look at these new technologies, one of the first things running through my head is, do we really need to have that connected or not? Are we ready for the data that that technology is going to generate? We have an open data officer. We have an open data initiative. We’re already building data sets and putting out on the portal. We’re already having discussion about doing open data around social media here with the city. A lot of our citizens are actively engaged with the different types of technology projects and services we’re doing, which is the reason why I’m reaching out and looking at startups and looking at new types of security technologies, because I’m expecting we’re going to have these risks. I don’t know everything especially around some of these new technologies. So I’m reaching out to companies and asking them, okay. You deal with this stuff like IOActive who specializes in penetration testing and hacking a lot of these new types of technology. I’m reading their reports and asking them their opinion. Then I talk with Gartner all the time, and I’m asking them for some of the newer stuff, what are you hearing? What are issues that other clients of yours are having with these things? What are the things that we need to be aware of?
Sanjog Aul [00:25:09]:
You mentioned about IT and related security, and, of course, with your role, information security officer, I totally see cybersecurity becomes the main focus, but I also have sewer system. I’ve got waste and water management system. I’ve got city infrastructure. They all, in a way, are trying to get to this IoT based monitoring or preventive maintenance and many other areas in which they can actually benefit, and they want to go ahead and either experiment with it or perhaps in some cases, they’ve already put that in. That also is connected to your overarching network, which is pervasive throughout the city, which makes every point of entry vulnerable or something worthy of securing, but that in your view or the way you explained does not seem to be within the scope of an information security officer. So then who handles the security for those areas? I do. Okay.
Gary Hayslip [00:26:07]:
I cover the whole city. Once you’re talking about SCADA and control systems, they fall under our public utilities department, but from a governance, from a strategic standpoint, I do look at those. Because those systems are very unique and they’re different from your typical cybersecurity systems. You keep them separated, but I also reach out to the Department of Homeland Security who has teams that specialize in that type of stuff, and they’re more than happy to step in and help us and provide training and provide the overview of how to protect those types of critical control systems. They do fall underneath my purview for cyber for the city.
Sanjog Aul [00:26:50]:
So Mark, in your world, when you’re looking at this waste management and water management and infrastructure, etcetera, would you look at that as inclusion into your portfolio and then identify the resources who have the knowledge and are able to effectively make it secure and also make the full use of them? Or are you relying on outside services because overnight, you would not build that capability anyways within the city?
Mark McDonald [00:27:19]:
Absolutely. One of the things I’ve undertaken to do over the past couple of years is to really bring those types of technologies into the discipline of the information technology group. Once I arrived at the City of Vancouver, they were completely separate, but as we’ve mentioned, these types of data and supervisory control systems are becoming IP based, highly vulnerable. The City of Vancouver, as most cities, do have an expansive landscape of these. We also own an energy utility as well. So we are bringing those in. We are working right now in the short term with external companies to help us in terms of managing the security landscape around those, but we’re also building the internal capacity, so that these will consistently be a part of the information technology portfolio.
Sanjog Aul [00:28:12]:
Now, Mark, the way we secure anything is limited to how far do we imagine or how much do we imagine in terms of where all things can break. What’s your horizon for that? How are you even scoping out that if I you know, there there was a first one of the first shows I did when I started this show was how much security is enough? So I wanna ask you that question yet again. When it comes to city, how much is enough at which point you’ll maintain that level, but you’ll not go crazy?
Mark McDonald [00:28:44]:
One of the things I’ve done is to work very closely with our chief risk officer and take a holistic view of the City, and really do an inventory of where our points of vulnerability, where our areas of absolute priority in terms of running the city and even more importantly, where are the areas of points of vulnerability, and then beyond that, one of the things we’ve been doing is using predictive analytics to really assist us in determining the level of security that we should have holistically and with each of these key areas here. So it’s certainly a process. It’s definitely a strategic view that you have to have and it is extremely time consuming, but the effort is really worthwhile and it certainly yielded some early results for us here at the City of Vancouver.
Sanjog Aul [00:29:35]:
Let’s take a quick break. Let’s just still be right back, and, Gary, when we come back, I’d like to talk about things beyond technology. Because, you know, in order to make, any place secure, it is requiring some cooperation from the citizens as well as the different departments, their workers, and their leadership. What is, like, in any organization, like, in a private organization, we would request the same, and there will be some policies and guidance, etcetera. Let’s talk about the maturity of security, the way a city needs to be kept secure. How’s that policy morphing, and to what degree are you able to put that or get that to be embraced by everyone involved in order for you to do your job in that is to keep the city secure. Please take a quick I will take a quick break. We’ll be right back after these messages, so please stay tuned.
Speaker 0 [00:30:41]:
From the boardroom to you, Voice America Business Network.
Speaker 0 [00:30:46]:
What is the serve hour? Well, to start, it’s a different kind of listening experience. It’s one that involves you. Host Jim Blackburn and his engaging guests in some very provocative and opinion shaping conversations you’ll hear and be invited to participate in that will challenge traditional beliefs about management and today’s workplace. Also, these conversations will help you look at yourself and your work differently. Make it your business to tune into Voice America Business for the serve hour, live every Wednesday at 9AM eastern time and 6AM Pacific time. It will shake you awake.
Speaker 0 [00:31:25]:
HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. What does a visual workplace mean to you? How does it contribute to operational excellence? And what steps do you take to put it powerfully in place? Listen to the visual workplace, work that makes sense to find out. Each week, Dr. Gwendolyn Galsworth, visual workplace expert and award winning author, shares tools and strategies to help you make the workplace speak at a glance without saying a word. Learn to work safer, faster, better, and at far less cost no matter what business you’re in. Tune in to the visual workplace every Thursday at 10AM Pacific, 1PM eastern on Voice America Business.
Speaker 0 [00:32:34]:
Voice America business network, the bottom line in business.
Speaker 0 [00:32:49]:
You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.
Sanjog Aul [00:33:16]:
Welcome back. So basically, for any large initiative, it takes a village, and that means not only you, Gary, but your bosses, the reportees, the congressional folks, the citizens, everybody has to come together to some degree and cooperate for you to be able to do your job. What’s the scene there?
Gary Hayslip [00:33:39]:
It’s actually quite interesting. I had actually written an article recently where I said cyber, it’s a team sport. I laid out this whole plan and I basically explained that cyber is a life cycle. The way we do it here in the city is it’s a continuous life cycle, and the biggest piece is visibility. When I came here to the city, they really have never had a professional CISO, and they’ve had people that have kind of filled the role. When I stepped in, I realized I needed to build my security program. I’ve learned that you can’t do cybersecurity in a vacuum. You have to get people involved. The biggest piece I started doing was I started walking, doing the whole walkabout. I started wandering through the departments. I was introducing myself. I needed to find out what issues they were having. I started talking with my team members, many of them who had been here for the city for decades and understand the culture. I started reaching out to all the other organizations that are connected to the city, the district attorney’s office, the sheriff’s department, the county of San Diego. I started reaching out to all of them to find out how it was going with them, the issues that they were having. As I proceeded to build a cybersecurity program here, I’m looking at all of our partners. I’m already involved with the civilian cyber community out here. I’ve been doing it for almost 20 years here in San Diego. My biggest thing is I collaborate. I share information. When I get notifications from the Department of Homeland Security or the FBI about specific attacks or things I need to be aware of, I don’t keep it in house. I share it with my team. I share it with mayoral staff. We recently did a presentation to city council, a cyber security presentation where we gave them an update. The City of San Diego were averaging about 60,000 attacks per day that we’re blocking. We wanted to make sure that they were aware of the threat. We wanted to make sure that they were aware of projects that we had in play and things that we were doing future state wise or what we were trying to put in cybersecurity wise to protect the networks and train city employees on cyber awareness. I do believe it’s a team sport. If you’re a CISO, you’re not going to do it yourself. You have to reach out to your stakeholders within your organization. I found talking with leadership that you don’t talk threat vulnerability consequence. You talk enterprise risk. You talk it’s all about risk. It’s all about loss of services. You really need to help them understand because a lot of the people I deal with, the departments I deal with, they’re non IT people. They’re non technology people. They don’t have the decades of experience that I have in IT and in cyber security, but they’ve got big projects that they’re doing because they really want to provide services to the citizens and they have these big technology projects in play that they want to do. They may not understand the risk because it’s really not their job. It’s my job to help them see the risks that are involved and help them stay within that technology roadmap that my CIO is putting out for our department.
Sanjog Aul [00:37:26]:
It’s interesting, Gary, the way you explained that. You of course, there’s a lot of effort going on from your side in terms of outreach and education and imparting the insights on why they should be secure. So, Mark, think about us trying to train these constituents and even business users who are in their respective departments doing their job, and we’re saying, okay. Change the way you put your password or the way you share information because you are vulnerable. All along, intruders are using all possible means to find the weakest link through which they can penetrate. How are you safeguarding a city’s infrastructure or any of its information and other data assets while you got so many weakest weak links, if you will? Because we are utmost trying to be able to educate them, but nothing beyond that.
Mark McDonald [00:38:19]:
Well, I think it’s through a multi tiered approach that we have here. One speaks to what Gary just mentioned is that here at City Vancouver, what we’ve done is we’ve really elevated the level of knowledge around cybersecurity and potential threats here with the leadership of the city. So city council, city manager and one of the outcomes of that has really been increased funding for security here at the city. At the business unit level, what we’ve done is we began with the actual general managers who run the business unit operations, and their standard security training program that we have that are mandatory for all employees at least once a year as refreshers and for all new employees coming into the City of Vancouver. That’s been a secondary approach we’ve taken. I think the third piece has really been, in terms of making sure that the business users have the respective tools they need to manage security at the desktop level, encryption at the data level, at the device level for their mobile devices, as well as their ability to leverage the standard security protocols that we have at the city through our corporate enterprise wide procedures. So it’s a multi tiered approach, and as Gary mentioned, it is definitely a collaborative effort. We have to work with the business units to be successful and to get them to understand the importance of potential enterprise loss.
Gary Hayslip [00:39:49]:
One of the first things I explained to my team was that we don’t make the decisions on this stuff. The business unit is going to make the decisions. If we run scans, if we’re doing a lot of the cybersecurity plumbing, and we find vulnerabilities, we can’t rank them and go ahead and say, well, this is a priority. We have to fix it now. What happens if we fix that and we break a major business process for the city? Instead, you have to do the whole visibility piece where you get your security committee together. You’re looking at the different vulnerabilities and the businesses, the departments, they go ahead and they have a say. You bring your stakeholders to the table and they’re helping you decide which ones need to be fixed first. Getting them involved, now all of a sudden it’s theirs. They’re very interested in what we’re doing. Now cybersecurity is not in the closet. Cybersecurity is pretty cool and they’re always asking what is my team doing. They’re really interested in the different projects and the stuff that we’re doing.
Sanjog Aul [00:41:02]:
So when both of you go about putting in this particular knowledge based or education that you’re imparting to everyone, what is the corresponding responsibility, and how do you measure whether they are doing their job in order for you to say, okay. I am not having those weakest links anymore, and I’m making progress. What’s your way of measuring it? Well, Gary, take that.
Mark McDonald [00:41:28]:
Go ahead, Mark. Oh, I’m sorry. Go ahead.
Sanjog Aul [00:41:30]:
No. No. Mark, please go ahead.
Mark McDonald [00:41:31]:
I think one of the things that I’ve seen is that there has been an increased level of maturity across the city around security. If I compare 2 years ago, to where there was almost absolute ignorance of the need for security, now what we have is business units starting to come to us and starting to say, we’re thinking about purchasing a business solution, and by the way, it’s cloud-based, very low cost, but looks like it may have large business benefit. What’s our risk around that? What should we be looking for in terms of security? So we’ve seen kind of a 360-degree turn in terms of the level of maturity from the business unit. That’s one of the key indicators for me that some of our approaches are working here and there’s a level of ownership and responsibility from the business.
Gary Hayslip [00:42:23]:
Yes. I echo the same thing. We’re seeing that where they want us to be actively engaged. If we’re late to a meeting, they’re texting me, hey, where are you guys at? We want you here, because they want our input. When I came to the city, we were averaging about 160 machines a month that were breached, whether it was phishing attacks or infection with viruses. Right now, we’re down to 32 a month. A lot of that is because our users are educated and they’re not clicking on those things anymore. A lot of that is different security projects we’ve put in play, changes to the architecture we’ve made. It’s become a team effort and it’s definitely unique. Coming from a DOD environment where it was just kind of assumed, here it’s not. I’m thoroughly enjoying the environment because once they’ve figured out what you’re doing and they like what’s going on, everybody wants to play. Everybody wants to help out, and you see the impact. You definitely see the difference.
Sanjog Aul [00:43:32]:
Let’s take a quick break, listeners. We’ll be right back, and let’s talk money and let’s talk politics. Because, of course, you’re part of the city, so there will be shifts whether it is the budgets from one, you know, leader to another or one regime to another based on what all happens in any of the government environments, and on the other hand, you got city the citizens’ security and safety at stake. How do you manage? How do you balance both? And how do you get enough funding and get enough timely approvals for you to be able to go about go and do what you’re supposed to do to keep us safe. Please stay tuned listeners. We’ll be right back.
Speaker 0 [00:44:19]:
The business community’s first choice in Internet talk radio, Voice America Business Network.
Speaker 0 [00:44:29]:
Are you feeling slammed and suckered in today’s stock market? If so, then you need to tune in to Profitable Investing with Jordan Kimmell. Every Thursday at 8AM Pacific time, Jordan Kimmell will train you in what you can do to beat up the big boys on Wall Street, as well as share his secrets to success so that you can buy and sell like a profit pumping pro. Grab the bull market by the horns and listen to profitable investing with Jordan Kimmell every Thursday at 8AM Pacific time right here on the bottom line in business talk, Voice America Business.
Speaker 0 [00:45:02]:
HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. When it comes to business,
Speaker 0 [00:45:33]:
you’ll find the experts here. Voice America Business Network. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.
Sanjog Aul [00:46:14]:
Welcome back. So, Gary, let’s talk about our favorite topic, which is for first is the budget. So let’s talk about budget, and then connected to it is also politics because both shift. Okay. So I’m not gonna leave you there hanging. I’ll ask you a specific question. When you see cybersecurity or any other type of smart city related security initiatives that have to be brought to we have to execute them and get your dreams be realized, you create a plan, and then you, based on that, come up with some budgets, and then you need some timely approvals. Those approvals have to come from people above you who may or may not remain by the time you get to that milestone, and at the same time, the budgets may not be available the way you proposed because somebody accepted it, but the other person who may come replace them may not see it the same way, and it could start all over again, and all along, we are rendering our citizens and our city vulnerable. How do you deal with this?
Gary Hayslip [00:47:23]:
Budget is something no matter what organization you are, especially from a cyber perspective, you’re always wanting it. You’re always looking. What I’ve done is the mayor told me to be innovative, to look at new ways to help protect our networks and our data. So I reached out to our startup community. We do a lot of proof of concepts with the startups where they come in, it’s free. They’re up and running in the city for 1 year. They get a chance to actually build out and test their solutions on the city’s extensive networks, and I get a chance to use their product for 1 year and to help protect the network. I’m constantly talking with a lot of my federal partners and peers, looking for grant funding. I’m always looking for other different modes of funding, and I have no problem using open source, anything that I can get my hands on that we can effectively employ and maintain to protect our networks and our data. There is politics involved in everything. I’m part of the mayoral staff and we answer to city council and the ethics commission and the city auditor. There’s all kinds of other groups that have questions and want answers. Part of that is being visible. Putting the information out there, what we’re doing so that even if there’s a change, even if there’s a new mayor or new staff that come in, because you’re not operating in a vacuum and they see the specific reasons why you’re doing projects, how you’re reducing risk, the new services that you’re offering, it helps you keep your funding and it helps pretty much sell itself that they understand there are specific reasons why these projects are in play. I haven’t had any of them take more than 6 months to get all the paperwork and funding lined up so we could go ahead and get them up and running. When I was in DOD, it could take us two years to get things going. I was actually kind of surprised coming to a city, you can be innovative and the paperwork gets done sooner. I do find that to keep the core money and everything you need, you have to get people involved and put out there these are the benefits. This is what we’re going to get for these things to help us put these projects in play. That really helps when politics come to play and you have people changing out who may have different priorities.
Sanjog Aul [00:50:25]:
So, Mark, how have you handled the budget and the politics related, fluid challenge, if you will, especially when the city’s safety is at stake? What has worked for you?
Mark McDonald [00:50:39]:
From a budgetary standpoint, many of the techniques Gary just mentioned certainly apply and resonate. One of the things I’ve done most recently is undertaken to really take a look at my capital budget, my 4 year capital budget. I’ve actually taken a step back and realigned a lot of the funding in that capital budget with a greater emphasis on funding security. In the past, it really has been just a very small line item across capital, but I’ve since shifted that and really enhanced the capital budget significantly. With the politics and shifting roles and responsibilities, one of my biggest challenges is obviously anytime a city councillor or a mayor is in front of the camera or a microphone, many times they may make commitments to citizens that have huge technology implications. We’re in a position where we have to try to be reactive in terms of making sure that we can help that agenda and that commitment along. I think we’re getting better at that, but once again, I think it goes back to our ability to raise the visibility of the importance of security. I’ve really socialized that very heavily across the organization. Here in Canada, it’s a bit different in terms of the funding model. We’re not as prone to obtain grants. However, I work with my provincial counterparts as well as the federal government here to look at unique types of funding to move us forward and keep us sustained.
Sanjog Aul [00:52:17]:
If you were to look at internally in terms of the people that you may have hired, Gary, the team that you had originally versus now, what changes are you making in that team so that those deputies are able to make you proud and also keep the city secure?
Gary Hayslip [00:52:35]:
The team I have, I’m truly blessed with the people that I have working for me. I’ve been amazed at their dedication and how well they work together. I have two teams. One is more focused towards cyber and security architecture, and then I have a team that’s more focused towards the daily operations and handling trouble tickets and doing basic Active Directory and maintenance stuff that the users need. What I find is I’m doing a lot of cross training because I want them both to be aware of what each other is doing. For the last two years, I’ve gotten full funding for training programs. I’m sending all of them to work on professional certifications to attend different events and keep them educated and trained on what’s going on in the community and the different types of threats that we’re dealing with. As we bring new technologies on board, making sure that when we bring something new on board like Splunk that we incorporate a piece of the bill per se as training. I don’t want my guys to have to figure it out as we go. I want to make sure that we have training involved so that we can employ it quickly to protect our data and our networks. Over the last 2 years, that’s one of the big things that I’ve really tried to do with my team is the cross training piece and making sure that they are very well aware that we provide a service, that we’re not just protecting the networks, that we actually provide a service to our customers, the 11,000 users in the City of San Diego, but also to the citizens for what we do. Part of my responsibility is to make sure that they’re properly trained and that they are properly aware of the issues that are going on with the technology we have employed.
Sanjog Aul [00:54:45]:
All right. I’ve got only 5 seconds. Gary, give me three words or rather, Mark, I’ll come to you. Give me three words, Mark, which you feel should be top of mind of any city CIO or CISO if they were to keep a smart city secure?
Mark McDonald [00:55:01]:
I would certainly say risk management as well as being proactive.
Sanjog Aul [00:55:10]:
On behalf of the show and our listeners, I’d really like to thank you both, Mark and Gary, for sharing your thoughts on how we can work together with the congressional folks, the CISO, CIOs and the team and business users to make and maintain a smart city secure, and listeners, if you, I’m sure you enjoyed the discussion and got some golden nuggets out of it, please like us on Facebook, search for CIO Talk Radio, and be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your host. Till next week, take care, and God bless.


