Your digital assets and networks are growing, and so are the related threats. Executive leadership now views cybersecurity as a strategic business issue. The reputational, regulatory, and financial risks are mounting. How are you transforming your security operating model to make cybersecurity an enabler, not a barrier to exploiting digital capabilities?
Contributor
Transcript
Sanjog Aul [00:00:00]:
Hello and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com and the topic today, Transforming Security Operating Model. So what we are dealing with today is we have a lot of digital going on and then the COVID hit and many other things which are happening coming from the left field. We don’t know what’s going to come next. Now, with that said, we also are seeing security becoming important because there are a lot of vulnerabilities, so we are seeing a lot of holes being drilled into the fort that we otherwise built and then accordingly, we also have many other ways we can lose our reputation. We could be in compliance risk, and there’s of course, financial risk in all of this.
Sanjog Aul [00:00:48]:
So the goal is that while we do business as usual and while we see security as a function within the organization which somehow helps you keep the fort secure but how can we prevent security to be seen as something which slows us down, but instead it becomes an enabler or seen as an enabler? Is it utopia we’re talking about or is there something that we can get to realistically, if there was a recipe, if there was a specific operating model for security that we can envision and put in place. So to discuss this, I have Richard Kaufmann. Richard is the Vice President and Chief Information Security Officer with Amedisys. Hey, Richard, how are you?
Richard Kaufmann [00:01:36]:
Doing great. Thank you for having me on today.
Sanjog Aul [00:01:38]:
Great to have you. So, as I have laid down the foundation of this discussion, so we are going at a warp speed, a lot of things are changing, our life got disrupted and the world got disrupted in 2020. There are a lot of things that are happening here, but then security, yes, it is top of our mind but then still see the business leadership not changing their perception about security. They’re seeing it as a necessary evil. What do you see from your vantage point that has to be changed or has changed, which is moving security function or your security group in the positive direction?
Richard Kaufmann [00:02:19]:
Absolutely and I just, I have to take a good step back when you describe security as a necessary evil because I joined Amedisys about two years ago and I don’t think that they saw security as a necessary evil, but I think they had a lot of the questions of is this investment truly bearing the fruit that we want it to and at the end of the day, Amedisys is one of our nation’s largest hospice, home, health and personal care providers. They want to ensure that through security as well as all the other functions within IT that we’re ultimately providing a higher level of patient care. So the executives were thinking, do we have the right leadership and do we have the right tools, processes, people, to really impact the way that we provide patient care to all of those who are in need and so when I came into the organization two years ago, that was one of the first things that I knew that I was going to need to be able to show value on because it was going to be an area of increased investment and because of that, some of these initial conversations that I had with the leadership team were really understanding from them, what does a successful security program look like to you and when you have that skin in the game and that buy in from executive leadership from jump street, it gets you out of the conversations of is security going to slow us down or are we truly secure or is for every dollar spent, am I getting a $5 of value out of the organization and so that’s where I started those conversations two years ago
Richard Kaufmann [00:04:00]:
and I guess for all the listeners out there today, I think that’s a very key takeaway if you’re establishing a security program, is to get that buy in early on, what success looks like, so as you are successful, we’re two years down range now, I can show through metrics how the needle has been moved.
Sanjog Aul [00:04:20]:
So when you talk about you talking to business and say, hey, what does a good security program look like, frankly, knowing how business thinks, for the most part, I don’t want to do a gross generalization. It could very well be like deer in headlights and they would say, you know what, good question but I don’t know and frankly, isn’t that your job to figure out? What do you do? So you, when you came in, you asked the question, you must be very lucky for you to get a straight, clear answer and if you do, you did get an answer, I would not say rest of the life is going to be easy for straight. It would be better for you but what do you tell to people who get such a response? That I do not know and I do not care.
Richard Kaufmann [00:05:07]:
That’s right and so that’s the interesting thing is I was very fortunate into the position that I came into because and a little bit of it starts with the genesis of the company understanding that security has to be part of a business plan in 2020, risk management has to be part of your business plan in this day and age. Covid is a great example of this. The recent ransomware attacks within healthcare are a great example of this. If your company is not investing in security, the amount of money that they are going to spend in response is tenfold what it would take to establish a security program and again, going back to those original conversations was, hey, I want to show that we are stopping attacks in their tracks. I don’t want data leaving, I don’t want malicious software being installed
Richard Kaufmann [00:05:57]:
and so a lot of that conversation up front was educating executives on things that are a little bit technical in nature. Here’s what a cyber kill chain is, here’s how we want to stop it in this stage versus the execution stage of the kill chain and so it going back to educating them and again, I had a very engaged audience. If other people aren’t as fortunate to have that engagement at the executive level, it’s up to you to say real life events are occurring here and I need to move us from whatever that measure is into a better measure down the street and that might be number of phishing messages landing in your inbox. It might be total amount of events that your SIM is picking up.
Richard Kaufmann [00:06:43]:
There’s a number of ways to start speaking volumetrically about security events so that over the course of time you can say we were here and now we’re here. Therefore I believe that we’re more secure.
Sanjog Aul [00:06:58]:
Now, when you mentioned that your description to them was this is what you want, or what’s what that you want in the businesses, I do not want data to be leaving, I want the place to be secure. Now, you and I both know you cannot promise 100% foolproof security when it is less than that. How do you have them spend money for something which does not come with a guarantee?
Richard Kaufmann [00:07:26]:
That’s a great question and I think it goes a little bit into things like risk appetite and items like that but I think most importantly, you have to put it in terms of real world examples. You have to take things out of the nebulous and out of the potentiality of occurring and into the realm of here are other businesses our size and here are the threats and the vulnerabilities that they are faced with and when you do that and when you can show good examples of for us, for health care, here’s what happens when health care systems are hit with ransomware. Here’s what happens when data is exfiltrated by a threat actor and it’s for sale on the dark web, that it’s almost like that understanding of those things actually taking place. It makes your arguments a lot more stronger. It brings it out of the this could happen and into the real world.
Sanjog Aul [00:08:24]:
Now what we have learned altogether is a good security model is where if it is implemented, besides the blessing from business, they should actually be owning it. Otherwise you will be always in a chasing game. So starting from you coming and giving them a 1-o-1 on what security is to what the shape of security can be, what it can realistically deliver to them, getting all the way to owning it. All right, so Richard, one is to get them to understand the security 1-o-1, the basics of it, what security program could look like, what it could potentially deliver, maybe set expectations that how far we can go with whatever investments that are allowed in terms of the security quality and the effectiveness but then a good security program is one where the business owns it versus you chasing them to get the next blessing for the next initiative. What kind of hoops you have to jump through to get to that state, the coveted state?
Richard Kaufmann [00:09:39]:
That’s another really good question and I think the way that we approach it at Amedisys is a little bit different than I’ve seen a lot of security programs approach it in other organizations and again, it starts for us with a difference in expectations of what our business partners are bringing to the table with regards to security. I’m often quoted to saying I want my clinicians to be the best clinicians in the nation. I don’t necessarily need them to be the best security experts in the company. The burden of information security to me lands on the CISO and it lands on the information security team. We shouldn’t necessarily have an expectation that the business owners are going to own any of the security things but I think if you start off with that expectation and that dialogue up front of I need this from you in order to be secure,
Richard Kaufmann [00:10:33]:
can you provide me a better asset listing or more robust context in how you’re using these services. That’s how you start taking those initial steps to getting your program off of the ground. I like to joke around quite a bit. I grew up playing basketball and by my junior year in high school, I knew that I wasn’t getting ready to be an NBA player but that’s the expectations that I see a lot of security leaders have is that they want their business partners to be the NBA players of information security within the organization and so that’s one of those things for us is that again, going back to dialogue and communication and just both entities, security as well as the business partners understanding what ins and outs are needed in order to secure the organization.
Sanjog Aul [00:11:24]:
So security leaders, I mean many of them, including yourself, like you, are sounding strategic and they are thinking strategic. How come we still have a very geeky, very technical perception of the whole security function, which essentially pushes away business and say, I don’t want to put my hands into this. What are they holding? Why are they holding back? The business talk, which talks about risk and not security, not the virus or anything. It’s basically a business risk and then why there is always an outcry that, hey, I do not get enough money. You cannot get all the money in the world, which the whole budget cannot be allocated to security. There will be resource constraints. You will have to figure out how to get creative
Sanjog Aul [00:12:12]:
and then if you cannot deliver perfection, you at least have to be able to demonstrate progress. So if something is not going right, is it a good idea to always say the business folks are the ones who are messing things up? How about looking at ourselves? How would you fix ourselves, the security leaders and the people within the team?
Richard Kaufmann [00:12:36]:
Yes, absolutely and so I think it starts with exactly that, the accountability of the security leaders. First, my experience with many of my peer group is that security leaders have typically the reputation of being very rigid and being very set in their ways and I think that is doing a disservice to all of the security functions across organizations, because it is that’s helping propagate that geeky thinking. If we’re not there meeting business partners and really speaking the language that they speak, we have to change our syntax within security in order to get that partnership that we’re looking for there and that’s one of the things that really drew me to the position at Amedisys and continues. My investment in the company is we at Amedisys have a culture of care giving that starts with our CEO, Paul Kucero, and flows down all the way to our most junior information security analyst. We are here to help first and secure second
Richard Kaufmann [00:13:44]:
and just that little bit of a shift in approach makes all the difference in the world. So that when we are engaging with our business partners, they understand we’re not just the place to go to get the no answer. We’re going to give you the yes answer and here’s how we’re going to do it securely.
Sanjog Aul [00:14:04]:
Let’s take a quick break, listeners. We’ll be right back and let’s talk about the specific steps as if this was a recipe for this or any other organization which is trying to put a security operating model and where we spoke about business taking ownership, which means that model itself should be simple. It should allow you the visibility so you have priorities very clearly understood. You can oversee all the risks that are available are there and how you could put in the efforts to address them and actually watch that effort put in and the things getting addressed. How far are we from that perfect portal, if you will, which will allow a business to feel comfortable, feel that they are in the know at all times and they understand what’s going on, so they say, yes, I am willing to take ownership.
Sanjog Aul [00:14:55]:
Let’s talk about this more when we come back. Please stay tuned listeners.
Sanjog Aul [00:15:54]:
Welcome back. So Richard, when we are trying to get the business to take ownership of the security risks and how the security function works, we got to give them some sort of a model, an operating model which will give them the visibility of what is being done, what are the priorities and expectations and what’s going on as an effort to address it and what’s going on at any given time, so that’s a beautiful looking security management portal we are referring to or what would that look like so that business can understand and because of that comfort of being in the know, they will be willing to take ownership.
Richard Kaufmann [00:16:35]:
I think a great example of how we’ve accomplished this at Amedisys is a project that we took on in 2019 where we had to update and overhaul our web proxy and our content gateway and it’s interesting because I think a lot of security practitioners while faced with that project, they would do things like come to the table to speak with the business partners about risks, about controls, about maybe some other events that were topical related to maybe content filtering that have come up lately and we didn’t start there at all. Where we started was a conversation with our operational teams and we said what do you want your experience with the internet to look like? Do you use social media? Do you use websites that you don’t know? What are you googling throughout the day and it started with nothing about security whatsoever and getting that feedback from our operational team, from our finance team, from HR. We were able to correlate all that data into a single message and come back to them and say, here’s what we heard on how you use this technology. Here are the things that we can do to enable you and make your life a little bit easier with a new piece of tech and then here’s the security side of the house that we absolutely have to have
Richard Kaufmann [00:18:01]:
and I think one of my favorite things about this was we actually reduced our policy, which sometimes is the only gateway people have into information security is by reading a policy document. The documentation itself went from a page and a half document to one sentence and our acceptable usage policy is now when you are connected to an amenetic network, please use your time wisely and productively and browse content that’s safe for work and that’s it and that goes back to again, a little bit of the expectation on both sides is that we want our business partners to be, I joke around and say, fully formed adults and being part of a fully formed adult is understanding that there are security risks on the internet and that you shouldn’t do things like browse Facebook for four hours a day, correct and so again, but we gather all of those requirements up front and now we implemented the technology, there were no surprises when some websites were being blocked and others were not
Richard Kaufmann [00:19:11]:
and there was buy in at the operational level from all of our clinicians on the technology change that took place.
Sanjog Aul [00:19:18]:
Now, based on what you went about doing this, have they really taken ownership or that’s a work in progress. What are you learning in the process?
Richard Kaufmann [00:19:27]:
No, they’ve absolutely taken ownership of it and what we have found is we unblocked a lot of websites that had been blocked before because part of it, especially as we interact with functions like HR, we want to see activity taking place and social media is a great example of this. A lot of organizations will block social media outright because they look at it as a non productive way to use your time and generally speaking, I agree with that but when you block something, you don’t have an opportunity to change behavior and what that has done is it sure, your corporate device might block a social media page, but then what people are doing is they’re just pulling their computers out of their pockets and they’re using their phones to do the behavior
Richard Kaufmann [00:20:17]:
and so what we’re seeing is we’re using security and the tools that we have to modify the way that we engage from an employee relations standpoint to say, hey, it looks like you’re spending too much time doing this, do you not have enough on your plate, are you disengaged from your job and it’s empowering the business partners to get more value out of a tool that’s historically just been used for security and so this kind of goes back to that original question, right? Is this is how security is starting to prove itself as a value add to the business and not just a blocking mechanism.
Sanjog Aul [00:20:52]:
Yes. So as you are, as you’ve lived through this journey, what do you think is the vision you can paint for the fellow CISOs who, if they went through this, is what would change for you? What does it look like with business owning security?
Richard Kaufmann [00:21:12]:
So again, it goes back to helping first,
Richard Kaufmann [00:21:18]:
help, that’s as simple as that, help the business complete its objectives. Through that, you can still secure things and you can still have all of the control that you need in an environment but if you don’t approach problems with the perspective of how can I help , you’re immediately wrong and I see in the organizations that I work in where I see a lack of engagement with security, it’s because oftentimes the CISOs head security leader are the most stringent in their rules and approach and I think that’s the thing is I wake up every single morning and the first thing that I do is check my email to make sure that there wasn’t a breach overnight. It is a worst case scenario, but it’s a very real possibility of my life. One day of waking up and being faced with that event.
Richard Kaufmann [00:22:06]:
That’s the burden of being a CISO, If you don’t want that, if you don’t want that heat, stay out of the kitchen and at the same time, you cannot just bring everything in an organization within your area of control to gain comfort that you aren’t going to experience a breach, so unless you’re going to show up to help, I would say don’t show up at all.
Sanjog Aul [00:22:32]:
Now what we have also traditionally seen, when you try to get people to work on the security related efforts, you go to the business and say, tell me, what do you feel are your crown jewels and keep that or help us keep that list update but then most of the time, people either are not aware in business or they would not volunteer their information. They would not on a regular basis come and say, here is my updated sheet of things. Not sure if that’s even a practical expectation, but how do you achieve it, because you could be securing the wrong things. As the boat is currently moving in choppy waters or it could be a speedboat which could be going 100 miles an hour and you are trying to secure it and it would change direction in a heartbeat so you got to stay on top of it. Business doesn’t want to do it. It’s not that they, even if they want to own it, but do you think they’re going to step up and drop everything they do and come to security leader and say here is my updated list,
Sanjog Aul [00:23:39]:
perhaps not. How do you crack this problem?
Richard Kaufmann [00:23:43]:
So the way that I would approach that, it gets into a little bit of how you set up a security organization under you as a leader. The way that I’ve approached this is I have find it, fix it mentality where I’ve got an engineering team. Think of it as a blue team that is constantly updating defenses. They’re fixing problems like these are the guys that defend the company and then at the same time I’ve got an operational team that is a little bit of like a red team and I would say again, stepping into any organization, having an understanding of where those crown jewels actually are, that’s a great start but every security team should, either by hiring it themselves or engaging with firms like pen testers or third party teams, if the budget allows to show, to demonstrate, here’s how we can get to those crown jewels and here’s what we can do with them and again, that goes back echoing the comment that I made earlier about anything that we can do to bring things out of the potential of occurring and into the very real know this is occurring,
Richard Kaufmann [00:24:50]:
it makes all of those arguments much more persuasive in my opinion and so I would say whether, if you’re a security leader and you’re allowed to hire two people, hire one person for defense, hire one person with an offensive mindset who’s going to come into your environment and say, hey, I know how to get to those crown jewels. I can communicate that to the business and I can work with the defensive side of security to start building the controls in place to make that a little bit harder.
Sanjog Aul [00:25:20]:
So with the chasing, we are not able to prevent the chasing match. You just split the team into two.
Richard Kaufmann [00:25:26]:
That’s right and I think that’s the right approach. I think because security is, it’s ever evolving and just like to the business, the business’s perspective on this problem is, hey, I know I gave you a list and I’m doing other things and all of a sudden that list is outdated. The business is constantly evolving and so when you have two functions that are constantly evolving. There should be this reconciliation function that’s out there that it’s not. You don’t need to push the information. They don’t need to pull the information from you.
Richard Kaufmann [00:25:58]:
If you’ve got a function out there that can find what the current state looks like. That’s why I think an internal red team is such a valuable asset to any security team.
Sanjog Aul [00:26:08]:
So think about a scenario you’re working with, say a list that business gave you and your team continues to try to update it but as they continue to update the status keep changing from green to yellow to red . Nobody wants to see red or yellow when especially they say I’m giving you a million dollars. What do you do during the transition time that hey, you just told me that this is a problem, but it is red and the other thing that you kept me on green for me to continue to invest on it, so it stays green, but it’s no longer your priority today it could become a priority tomorrow again. I’ll have to stop investing in that so I can work on this new thing that you give me but then because I’m not investing in that other thing, the green could turn to yellow, which could turn to red when you put your focus on it.
Richard Kaufmann [00:26:53]:
That’s right.
Sanjog Aul [00:26:54]:
And you don’t have unlimited budget either. So how do you tackle this?
Richard Kaufmann [00:26:58]:
That’s right, so to me that goes back into how the enterprise itself takes on work and prioritizes risk and operational activities. A good example and we are at the genesis of this atometicist where we use our GRC function to help prioritize and categorize those risks and then that output goes into our annual budgeting cycle as well as the annual ideation process for what work the organization is going to take on and that way it doesn’t become like a security versus the business conversation. It comes into a here is a list of items that we have found. Some of them yellow, some of them red.
Richard Kaufmann [00:27:44]:
Is the organization going to invest in bringing these items all up to green next year and is a conscious decision and so at least that way again, breaking down those barriers between just security and the business, there’s multiple other functions that are involved in that conversation and it’s not just a binary decision between one group or the other. It’s holistically the enterprise is going to address this next year or it’s not.
Sanjog Aul [00:28:14]:
So let’s talk about the oversight mechanisms. So we spoke about a good operating model for security would be one you provide a way for business to feel they are in the know, what do you think a good oversight mechanism in that portal that we could offer them and how different or how much more new or different is the business expecting from it?
Richard Kaufmann [00:28:45]:
And again, I think this is something that we’re doing very well at Amedisys. I think many practitioners listening in today are familiar with NIST as a control framework. We also marry NIST on the risk management side of our business with the Mitre attack framework on the security operational side of our business and using those two frameworks it gives us here’s a list of controls and the status of those controls. They’re either operating effectively, perhaps there’s design gaps, but it gives us a baseline of what we should be doing, NIST is great at that. Then we take Mitre attack and we see what’s going on in our environment. How does that line up with the attack framework and then we also have a very robust threat intelligence capability out of Metasys
Richard Kaufmann [00:29:35]:
and so we’re constantly getting seeds of here’s what adversaries are doing and so we map the adversaries to Mitre. We use Mitre to cross reference what our defensive controls look like from an implementation standpoint and then we cross reference Mitre and our NIST managed NIST control framework and that gives us a very clear operating picture of where our gaps are, where investment should come into play and if an attack were to take place, this is the most likely path that it would take. So I think getting that clear picture, again providing that back to a CFO, a COO, even a CEO of this is what security looks like today. It is a great oversight feature into the effectiveness of any security program.
Sanjog Aul [00:30:29]:
So let’s take a quick break listeners, but when we come back let’s talk about the three constituents. So yes you spoke about the business folks then we also spoke about the enterprise risk folks who are not business truly, but they are like the third party with independence, if will not third party truly, but independent body which is supposed to make sure all types of risks are looked at and managed and reported on and then the security people, just like a three way relationship. If the enterprise risk people were to look at what you mentioned as your oversight mechanisms and if they were to come and poke holes into it where all are they likely to poke holes because they business is more likely to listen to the enterprise risk leaders versus directly security leaders because that’s where the affinity lies truly, so what would you do in that regard? How would you make it tight that you get thumbs up from the enterprise risk people. Please stay tuned, listeners. We’ll be right back and discuss.
Sanjog Aul [00:32:25]:
Welcome back. So Richard, we all know that enterprise risk people take pride in making sure everything is airtight because that’s how they earn their paycheck and you’re trying to present something to the business, you’ll say, okay, I’m giving an oversight. This is a good security model and yet there are other elements, but these people are the ones who are going to come and be looking to poke holes in it. What would be the typical way of for a security leader to fortify their plan, their oversight mechanisms and other elements so that they get blessing from enterprise risk team?
Richard Kaufmann [00:33:03]:
So it all starts with the syntax that’s being used and how security leaders start communicating risk back into the organization. I am a very strong believer that security risk in and of itself doesn’t truly exist. IT risk doesn’t truly exist. What does exist is business risk and the way that business risk can present itself is through financial implications, through technology, through human resources, through operational, through reputational, through all of those different avenues, that’s business risk and so I make sure when I’m engaging with our ERM function that I’m speaking about risk not just through these security links, because when you do that, it is going to quickly open up that position to lots of poking and prodding and the ERM folks are quick to say, did you think about this, did you think about that and so we’re again, when we communicate those models that we create based on some Mitre and also on mist, we can say, hey, this is what a risk looks like to security.
Richard Kaufmann [00:34:11]:
These are the financial implications of that risk. Here’s what could happen from a human resources perspective. Here’s the reputational impact that we think about and again, it becomes less about, ERM, poking and prodding into that feedback and they have experience where they’re a lot more receptive because that language, that syntax is so similar to the way that they, they explain things, is that you’re already on this common operating picture and so anytime you can get someone speaking the same language as you, instantly that relationship is going to become more collaborative and that’s what we see out of medicines, is that our risk function as it reports up into ERM, is really just small, like filter, a subset of the overall ERM universe and they’re very, I would say, willing to work with us as we’re trying to communicate what security risks are.
Sanjog Aul [00:35:07]:
So what you tried to do, and I’m sure you’ve been successful in whatever you’ve tried to do in terms of building and adopting or implementing a security operating model, I’m sure it wasn’t a straightforward journey either, right, so best is to learn or get to learn about what your learnings and what your revelations were as part of you going ahead and adopting or getting the organization to adopt this security operating model and what would you have done differently if you had to do it all over again? Anything like that would definitely be very valuable for the listeners.
Richard Kaufmann [00:35:44]:
Absolutely and so again, when I came into the organization, I had an enormous opportunity to rewrite how security was being done and we basically retooled pretty much every single piece of fundamental technology that makes up an information security program. We did that first by replacing our sim, and we spent probably the first six months of the year that I was there getting data into this sim because if you don’t have visibility into events that are taking place on your network, you are truly blind into any attack that’s taking place or any malicious activity that’s going on in the network and so that, to me, like, that’s the first thing is establishing visibility. The next investment that we made that, again, I know a lot of people I don’t think would invest in this right off the bat, and maybe they even view it as nice to have, but I think it’s critical, and that’s quality threat intelligence because gaining visibility into your network is only half of the conversation,
Richard Kaufmann [00:36:49]:
the other half is what are adversaries doing, what malware are they developing, what tools, techniques and processes are they using to run exploits, because again, especially if you’re establishing a security program, you are going to be in firefighting mode, so don’t go patch things that don’t need to be patched if a bad guy isn’t using them. That’s how we prioritize our vulnerability management. Practice out of medicines is we patch the things that are being actively used by bad guys first and we know what they’re using because we spend a lot of resources on threat intelligence and so those are the two big takeaways for me is get visibility into your network as much as possible and then find out what the bad guys are doing with relation to your organization.
Sanjog Aul [00:37:39]:
We could build a good security operating model like you did for your organization and many others could do for their own respective ones. Just because you build one doesn’t mean it’ll get adopted. Maybe the people at the top will give you a blessing, maybe they will come and try to be an owner but then security is as good as the people adopting it at the very junior, most field staff level if required. How do you get them to adopt something what you put together as a security operating model because you will need their inputs and their adoption and to that end, what should first shift or on a regular basis keep shifting in terms of their mindset and the culture of the organization as a whole so that they are paving the way for this security operating model to become the basis of how you handle security.
Richard Kaufmann [00:38:33]:
I think one of my favorite experiences when I changed jobs from my previous employer and stepped into the security leadership position at Amedisys was a big portion of any CISO’s job is gender management and kind of always keeping their pulse on what’s taking place within the technology space and it’s interesting because when I landed in the new position, I reached out to a lot of vendors who weren’t a good fit for the previous organization and it happened on more on one occasion where they said, hey Richard, I didn’t think you like me and it was, it wasn’t, it was never a personal thing. It was just that the technology didn’t fit that organization and it can fit a different organization and so I think your note there about different security operating models for different businesses is absolutely spot on and so as a security leader, the first thing that you should do is again, understand the objectives of the business in the face of COVID 19 and the pandemic that’s facing the world right now. A big conversation that is taking place within healthcare right now, especially in home health and hospice and personal care, is telehealth.
Richard Kaufmann [00:39:41]:
The idea of providing care not necessarily in person, but through the use of technology. As a security person, that is an incredibly interesting problem to help solve because now maybe we’re looking at a BYOD model, but for patients, how is connectivity going to be provided is that going to be on someone’s home wireless network that’s typically not secure. How do we give that person an identity to securely transmit data? All of these things. It’s a fascinating problem to start focusing on, but I have to have a good understanding of what our COO is trying to accomplish operationally. I have to have a good understanding of what our clinicians are going to do in that model before I can start securing that environment
Richard Kaufmann [00:40:29]:
and so again, I feel like a kind of broken record at times, but it really does going back to as a security leader, you have to understand what your company is trying to do and if you don’t, you’re going to quickly find yourself in a position of risk managing your company out of business and that’s the thing is I want to help amedisys drive innovation and care and the way that I do that is not by showing up and saying no or not by showing up and saying okay, you can do this, but here are your walls you have to operate in. Oftentimes I show up and I say, tell me what you’re thinking about doing and just that emphasis on learning is the first step, I think of any good security leader.
Sanjog Aul [00:41:15]:
A data entry clerk in your company is also important because they could turn out to be a weakest link so while you’re managing up and doing everything with respect to you trying to be a good leader, expecting them to be good leaders, but that person could create havoc not because they want to unintentionally so that means they are also part of the equation so as my question was that what do you do with the fundamental fabric of a company, so each person takes responsibility for helping security become a reality in the organization in real sense versus just you chasing everyone, creating a pool effect.
Sanjog Aul [00:41:57]:
What do you think they could do in this regard?
Richard Kaufmann [00:41:59]:
So that’s a really interesting problem as well because we think about end user training almost exclusively in my experience as phishing messages and I get it, phishing is going to remain the number one attack vector for bad guys for a long time coming but we’ve evolved our end user training at Amedisys to be more than just hey, don’t click on that link when you get an email from someone you don’t know and it has become more of a here is your role within the company and here are the expectations for you to help us be more secure, so for your example that you’re right, an entry level data clerk may open up an enormous security hole if we’re engaging with that person early in Austin and communicating with them what the secure, what the security expectations are for their position as well as just what the security expectations are for the entire organization. That’s one of the things that I think is missed when we talk about end user trading because again it’s very heavily focused on phishing these days.
Sanjog Aul [00:43:05]:
The one final question will be essentially if you want to bring the change, you got to change yourself. Let’s talk about the CISOs. What are they supposed to do to fix in themselves? What are some of the shortcomings? You could start with yours or tell some of your friends and buddies, CISOs or anyone in general in this profession the traps that they may have or self inflicted limitations or limiting beliefs they have which hold them back from being able to putting a good security operating model in place and doing justice to the business needs.
Richard Kaufmann [00:43:46]:
I think it really does start with a lot of self reflection and I think the good comment in that is that I don’t think there’s any shortage of ego in the CISO space, especially people who I’ve interacted with, but I think that’s exactly it is. Again, understanding that may that while you are the security leader, I don’t ever have an expectation of meeting with another CISO that they know everything and so just approaching the position with a little bit of humbleness and a little bit of flexibility I think would do a lot in advancing those conversations and making sure that security are seen as a business enabler, as person who can find the answer to yes. All of these things I think missing in the CISO world right now.
Sanjog Aul [00:44:35]:
Once again, thank you so much Richard for sharing your views and insights about how organizations can implement a robust security operating model to make cybersecurity as an enabler and not a barrier to exploit all the digital capabilities and all the good things that we can do together.
Richard Kaufmann [00:44:56]:
Thank you for having me. I appreciate it.
Sanjog Aul [00:44:59]:
Thanks so much. So listeners, please connect with us on Facebook, LinkedIn, Twitter, Pinterest and subscribe to our podcasts on Apple and Google Podcasts as well as any other major channel where you can get access to them. Once again, thank you for listening to CTN. This is Sanjog Aul, your host. Till next week take care and god bless you.
Download podcast
Apple Podcast, Google Podcast, Spotify, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More


