Andy Ellis: Navigating Boardroom Realities and Liability – CISO Talk EP 40 (Part 1/2)
Transcript
Well, hi, you've joined CISO talk. I just wanna tell you a little bit about what's happening. This is part one of a two-part series that, uh, JJ Manila and I interviewed Andy Ellis.
If you don't know Andy, very prominent figure in the industry and security industry. Uh, he was 22 years at Akamai with CISO there in his last role for quite a number of years. And today he's a operating partner at IL Ventures.
He's written some books, a lot of great things that Andy's done, I think you'll find fascinating. This first part we're, one of the things we're gonna focus on is the role of the ciso, but the question of does the CISO belong in the boardroom? Is it really that level of a position?
If so or not, why So can we join, uh, our interview with Andy? Well, welcome. You've joined us and another episode of CISO Talk.
I'm here co-hosting with my friend and colleague, Jennifer JJ Manila. Welcome, Jennifer. Hey everybody.
Hey Mitch. Andy, Speaking of Andy. We have a great guest, Andy Ellis.
If you don't know who Andy Ellis is, you'll quickly find out really quick here. Um, and there's a lot of things I think we want to run by Andy May, maybe Andy if, if you would, to give a little bit of your background, you, your very prominent roles in some companies who would love to hear about it. Yeah, sure.
Thanks for having me here. First of all, I always appreciate that opportunity. Um, so Andy Ellis, I'm operating partner at Weil Ventures right now, but I retired from being Akamai ciso.
I was there for, uh, 21 years before that I was in the United States Air Force doing information warfare. I always love to joke around when I'm interacting with folks in Israel who are coming outta the I D F in 8,200. And I'm like, I was doing that in the last millennia.
Like, let's move forward a little bit. Um, I'm Hall of Fame CISO and the author of 1% Leadership. Amazing.
Fantastic. J jj any thoughts on kind of topics we wanna start off with Andy? Yeah, and you know, Andy and I have had other conversations kind of o off other threads and stuff, so it's fun to bring this for all of the listeners and with you, Mitch, because we've had all of the, all, all of the top news we've been covering, um, the s e c disclosure guidelines, which are still being discussed because I think there's still a lot of confusion around what that means for the security professional in an organization.
Um, and then of course we've had a lot of talk around AI and what that means for cybersecurity, both in offense and defense, so I'm curious about that. Um, I'm also, you know, I've met Andy so many years ago and, and followed him and consider him a, a, a voluntold mentor of mine. And, uh, he did just publish a book.
That's awesome. Um, so, so many wonderful tidbits in here about really, you know, leading, um, through example and building teams. So Andy's just a great person to bring all of these fun topics together and, um, I know Andy, and no matter what we throw at him, he's uh, gonna, gonna hit it outta the park.
I'm kinda like Chad, G p t t, I can make up an answer to almost anything. There you go. That's true.
We'll just feed this directly in and it'll have our responses as we talk. Well, let's start out with the s E C filing. You know, I think we all love those, uh, statements of you shall disclose in four of material breach in, in four days, and we're all going like, okay, what's material four days really, from what you know, how does this work, uh, interested in your perspective on it, Andy?
Yeah, so this one's what's interesting, it's part of a larger conversation that I think people aren't really having, which is, is the CISO actually an executive of the company? And by executive, I don't just mean like you have a title, it's are you truly a decision maker? Are you part of the c e O staff meeting?
Because the people who decide if it's material is that meeting, it's the general counsel and the C E O and maybe the C F O are ultimately, like that's the group that decides if something's material. So I see a lot of people are like stressed about, well, how do I decide if something's material? The ultimate answer is you don't, like, you might say it's material, but if the general counsel says, no, I don't think this is material, that's what the company's going to go with.
So in a sense, we're off that hook, but we're gonna have a lot of stress because stress is the feeling you get when the world does not match your expectations. And so You expect that you get to say, oh, this is material, we're gonna go disclose this. And the the other executives are like, yeah, no, have a nice day.
You're gonna feel a lot of stress. Now that said, I do have a definition for materiality that people should think about, which is in the wake of a breach or a vulnerability, like are you going to dramatically reconfigure your business? Like it's not about business ending, but about business altering.
Like if this gets disclosed, are you like SolarWinds that will all of a sudden say that CISO has a blank checkbook, if so, well, that was a material event that creates a blank checkbook if you're going to, you know, fire a bunch of executives and replace them and reorg, you know, dramatic restructurings. But if it's gonna be business as usual on the other side of it, it probably wasn't material Sort of a normal it cost of doing business sort of last. Yeah, we're not gonna worry about it.
Well, I have a question about that actually, then maybe to, to clarify. So I, I mean, I think for over 10 years, maybe almost 20 years now, we've joked about ciso like the little C versus a, a big C as we think about them in a corporate environment. But when it comes, so materiality when you're saying if it's something that's business altering.
Yep. So some of the other definitions I've heard from, um, you know, people managing publicly traded companies is, um, that that may be predefined based on the share or stockholders' expectations of what that means for them. So I'm kind of curious, like if it, if it's something that doesn't necessarily alter business, but it's a huge reputational hit that might, you know, break, uh, you know, consumer confidence and brand confidence, where do you, where do you see that line shifting between those two?
So I think they're really closely coupled. Like if you have an event that is going to damage shareholder confidence, then you're going to alter your business to regain shareholder confidence, which means that that event was business altering, even if it wasn't directly. Like you might say, well, I think this should be a cost of doing business, but clearly the street doesn't agree with me.
Well, that's material. And it's important to recognize that there is no regulatory definition for materiality. We define materiality in hindsight after lawsuits.
Like at the end of the day, a judge and a jury decides if something was material. And so we're really are, that's why the general counsel's the one who gets to decide because they're the one with the legal experience to say, what is the thing that we will get sued for and lose? And what are we willing to risk?
Like maybe it is ma would be material if people found out the whole details, but we don't think they will. So we're gonna say it's not material. Yeah, there's a lot of that going around too.
Yeah. I, I wanna come back to the, to the, the thing you talked about with the, the, and I said the, the big scene, the little c Yeah. What, why are we still at the position where we don't have CISOs proper as part of the leadership team?
So I think that there's a lot of reasons. One is nobody wants that leadership team to grow too big, right? You can't have more than 10 people in that room.
And even that is problematic, right? So you really look at, it's the c e o, it's the C F O, it's the general counsel, usually the C R O. Um, the CMOs have broken their way into that room over the last 10 to 15 years.
Um, you know, usually the, the head of hr, so that's six people already. And I haven't even gotten into, do you have a C o O? Do you have a president?
And so we're already pushing and the C I o I didn't list. 'cause in a lot of companies they're getting pushed out of that room because this, because as you move to cloud, like why do you have a C I O doing tons of things? Um, and I think, so part of it is that part of it is we're a very immature career field.
Um, you know, I think, you know, without, you know, giving, naming our ages, you know, there were no CISOs when I was basically doing that job. Like, we had to point and say, oh, there was the first, who was the first ciso, but realistically this title didn't exist. And in fact, my title was C S O because nobody knew what to give the title.
And I got to pick and I said, well, I, I want, I think three letters is better than four. So that was the title I went with. Like, this wasn't a norm, it wasn't a standard.
There's so many people who do not have a diversity of experience. They've always been back of the house. They're breakers who turned into makers, but they're not people who understand finance, who understand sales.
Um, in many cases, you know, grew up very, um, strong-willed, right? You had to argue a lot to get your point across. That's not gonna be welcome in that room of you coming in and being like, well this is like an ethical de decision.
Like we can only make one possible choice if you're not willing to compromise. Nobody's gonna open the door and let you in the room. So I think some of it is that some of it is reputational, but at the end of the day, like I, I do question like, should it be, should that person be in the room?
What I worry about is organizations and really humans make decisions before they realize they've made them. And when you have that room of seven people that are running a company, the moment a topic comes up, the decision is made within minutes. Even if they don't acknowledge it right?
Then they say, okay, we'll have to go to a study group, whatever. But the CEO's first impression is probably what they're gonna go with at this point. And if you didn't have somebody in the room who could just say, Hey, wait a second, here's the risk that we've got.
Bringing that risk up three weeks later is not the same as bringing it up within the first three minutes. And if nobody in the room is really looking at systemic complex system safety, that's really the, the downside of not having the CISO in the room. What's, What's the compensating measure for that then if you don't have a CISO or security person or, or even c i o for that matter in the, in the executive team level?
Well, I think we, how teams are compensating is you, you know, spend a lot of money on a security team and as soon as the ciso, you know, gets a, a little too much gumption and starts arguing with you, with you replace them with the next one. I don't like your answer. Somebody that agrees with me.
Right? Yeah. Just a lot Of truth to that.
And I see a lot of CISOs that that's their career arc, which is they work at a company, they're doing a great job, they uncover a lot of risk, they start to bring that risk forward. And, and here's another challenge, which is who do people report to? And if you ask CISOs, they'll say, well, I report to the board.
You don't report to the board. You give a report to the board. That's a very different thing.
But they think that they're like independent internal audit who is an independent agency that really does report to the board and they want to come in and say like, here's all of the problems. And boards do not want to hear that. What a board wants to hear is, here's a problem and here's how we are fixing it.
And if we're not fixing it, we don't want to hear about it. 'cause we don't want it in the board minutes that we knew about a problem that isn't being fixed and It better be something worthwhile to discuss with The board. Right?
And in fact, I, I discovered this working with an internal audit team who came in and said, you know, here's our findings about your organization. Like here's the, these top three things that we wanna brief the board on and we would like your response on what you're doing to fix them. And two of them, I was like, yeah, I'll go fix this.
And the third one, I'm like, I'm not fixing this. I don't think this is a problem. I'm willing to accept that risk.
And they said, great, we'll take it off the list the moment I said I wasn't fixing it. They're like, well it's not reportable to the board then. Like, we're not gonna tell them it's a problem if you're, you would argue with us.
And it like, it opened my eyes to like, how many risks had I brought in front of the board without stakeholder buy-in that they were going to fix it. Mm-hmm. And how many other CISOs do the same thing?
Interesting. I think it's just some really clear thinking about that. And uh, you know, if you're not a business person or been at that level, you haven't been in a lot of boardrooms right there, there's a whole dynamic and a process and, and how they operate and how, how, uh, CEOs or presidents or whoever chairmans lead a board, right?
It's a very different dynamic. Like I worked with one person who's, you never surprised the board. You already know what the answer is to all the things you want to get approved because it's already been socialized la la la and we don't live in a world necessarily Like that.
Yeah. Like, how many CISOs have you heard make some comment like, well I need to get budget for this, so I'm gonna brief the board. And you're like, that is, that is like, that's a threat you can do.
And I have used that threat before, like of the, I think there's a risk we have to fix and if we're not going to fix it, I'm gonna brief the board and all of a sudden everybody gets on in line and says, okay, let's go fix it. But I didn't just go brief the board, I just threatened it every once in a while. And it's dangerous to do that.
But that's a, that's like a careful nuance that you have to learn those skills to operate at that level. So then what's the, go ahead, what's the path? Um, 'cause I think one of the things that comes up a lot, um, talking to friends and colleagues and professionals to some of the clients, you know, I work with directly and with ions, you know, a lot of the question is in a lot of the conversation is when you're, when you are the person who is responsible for security, whatever the title is, yep.
What are we, what do we need to be doing to level up to be respected and invited into that room as a business partner instead of the little c that's tucked down in the corner somewhere? So I think a big piece of it is, one is do pairwise relationships. Like everybody in that room, you should have the relationship with where they want you in the room.
Where if a meeting happens, like I once had this, that there was gonna be a laugh and it was the first laugh that I wasn't in the room for the planning. Like this was amazing. Like some, there was new person in HR and they're like, oh, we've got this handled.
We don't need to talk to InfoSec. And they walk out of the room and, you know, one of the, uh, heads of product or product division calls me and says, do you know about Operation X? 'cause we always had code names.
I said, haven't heard about it. And he's like, okay, we have a problem. You need to be involved.
Here's what's going on. And he brought me over the wall 'cause he thought I should have been in the room. And that's what you do, is you build these relationships where people know the value you bring and would value a conversation with you.
And one of the, the phrases someone said to me, a boss who, you know, I didn't like for a lot of reasons, but gave me some great advice. He said, know what you're trying to achieve before you open your mouth. And too many security professionals, all they, all they really want to achieve is to be right.
Mm-hmm. Like, I found a thing. Let me show you how smart I am.
Let me show you how right I am. Well what that will demonstrate to the other person is that you are wasting their time and they don't wanna talk to you. If instead you say, here's what I'm trying to achieve is I want this person to fix this thing, to make this change, here's how they would do it.
I think they would do it. And so I come to them with this vision of us getting better together, then they value my input and they wanna come back and talk to me. So it's why, like I had a rule, which is if we found a bug in our own developed software and our own developers found the bug, it was not something brought to us by a third party that they got to specify when we would fix it.
I did not pressure them. So they could come in and it could be a really bad vulnerability. Like what we, you know, we call, how do we call the requests of death, which is here's a single H TT P request that could take down a server.
And sometimes we would find them ourselves and they'd come in and they'd say, here's what it is. When can we fi when, when do we need to fix it by? And I said, you tell me like what works for you.
Like, you know how bad this is. I'm not gonna tell you, you have to disrupt your release cycle to do it. If you think that like this one's hard to trigger and you want to take two months to get it right, go for it.
Because otherwise you won't tell me about the next one. If I tell you you have to disrupt everything and fix it right now. Well, you're the reporter and the fixer.
I've just disincentivized reporting. You're speaking the two language right now, now may not like it. Yeah.
How, how about the, um, so we're kind of back to the SS e c thing, the four day requirement, um, to, to report a material, you know, the, the devil's in the details well, like what, what do you have to prepare and disclose and how does all that work? What are your thoughts on that? 'cause Yeah, I really worried you send an email and we're good.
Yeah. Well, so first of all, there, I think there are some specific ways you have to do disclosures, but fortunately you have a legal and finance team that knows how to report things to the s e c. So like make sure you have that partnership.
The four days is really a trap. Like I look at it like there's language in P C I that we all know about that we know is just the trap, so that after a breach visa can come in and say, you really weren't compliant because you were not auditing system level objects. Like if anybody you know, has done p c I recently, there's one of the these lines in there and they never define what a system level object is.
So you're always gonna be screwed on that one. Or on reading all of your log files. Like those are the two traps in P C I that make sure you cannot be compliant.
And I think this four day rule is basically another one because it's four days from when you believe it's material. So if you start to have evidence of an incident but you haven't yet decided it's material, I think in retrospect the s e C is gonna start the clock there and they're gonna say, well, you didn't tell us for eight days. You're gonna say, well, I didn't realize that we had lost access to this data for five days.
And I suspect this is where companies are gonna, in hindsight be like, oh, I guess we did the wrong thing and we'll have nice legal battles about it. But at the end of the day, remember materiality is your general counsel. So your job as a CISO is provide the evidence that enables your company to make a wise risk choice and then make sure it is all documented.
Do not let yourself be thrown under the bus because you only had verbal conversations. I, having worked with general counsels, I could imagine there was a relationship where the general counsel, it's not in their interest to say it's material until we're ready to say it's material. Right.
And not that you're, you, you obviously can't go into the territory that you're hiding things, but you may not want an answer right away from your general counsel, this is material, here's what we have to do to be prepared to say it's material that we know it and we can show why it's material and here's how we disclose it. Mm-hmm. But it seems like one of those, don't say it until you're ready.
Don't take forever, you know? Right. I think that's where it's gonna come down to.
And I think a, a skill that CISOs will need to practice in communicating is communicating the difference between evidence of absence and absence of evidence. Like, we don't know that a bad thing has happened because we have no ability to look is very different from, we have no evidence, a bad thing has happened, but we knew where to look and there was no evidence. Right.
And being able to communicate that clearly so that your peers are saying, oh, we're, we know this one's not material versus we have no idea if it's material or not because we had a security weakness, we weren't logging, whatever it is. What are gonna be the, the consequences of missing the deadlines? Well, so I think that's what's gonna be interesting.
I I am really looking, looking forward in a grim way to seeing the s e c action against Tim Brown. Like I really wanna understand what are they going after Tim Brown for when they do this investigation? Like, is this for, uh, statements that he made publicly, statements made to the s e c?
Like what is, is there really gonna be personal liability for CISOs? Because I honestly think there should not be because they're not actually C-level executives. Mm-hmm.
Like we have the title, but do not have that position in the company so that corporate liability should not extend down. You don't have requisite insurance. Right.
If you're a publicly traded company. Like you have to sign a disclosure as a CISO that you have briefed on relevant security risks. So that creates an opportunity for you to have some liability.
You know, at the end of the day, what does the s e C do? They find companies, if they think the company's doing something wrong, you take a, you know, share price devaluation for a little while. You, you know, say you're doing something new to, you know, make everybody happy and you move on.
So I don't actually think like these disclosure rules are the end of the world for companies. Interesting. I know we have definitions for things, but it's, it still feels a little bit, uh, qualitative versus quanti.
Like there, there's some Oh absolutely. There's some, there's a lot of discretionary judgment calls throughout this process. And, um, it sounds like that, you know, the feedback loop, if we don't have the right security professional in the room offering that guidance and input throughout, or at least hearing top down what's happening and participating in the conversation early, then that may delay things in an, in an awkward way for people.
Absolutely. I think you're, you're right on the head with the qualitative versus quantitative. 'cause a lot of materiality rules that we understand are quantitative.
Like we know if you miss your numbers by a certain amount, you know, that's material you have to disclose. If you have a customer that is more than 10% of your revenue because that's material, like there's these standard accepted quantitative materiality thresholds around your revenue and your costs, but around risks, there are none. And you're absolutely right.
It's qualitative. So you need the ciso, you need the general counsel, you need them to have a good relationship so that together they can, you know, make that, and look, we're all gonna be guessing until there's case law on this. Oh, and I did wanna ask you this too while we're on this topic before we, we hop off to something else.
And, uh, so one of the things that it, it, I guess, common threads or concerns is that, you know, a lot of directors, board directors and executives have insurance within the company that that covers them against certain liability. And it sounds like, what I've heard from a lot of professionals is that that doesn't extend down to the CISO because they aren't, like you've just said, they're not actually the big C cso, they're not Directors of the company as Director. Right.
'cause d o insurance for directors and officers. And if you're not one of them, you know, getting yourself on that insurance can be hard. So, you know, I think if you're the CISO of a large public company and you're not on that, you should be talking to your own personal insurance carrier and making sure you have some coverage so that when you get sued, you have insurance that will at least cover your legal defense.
Mm-hmm. Yeah. And talk through scenarios.
Because many people get an umbrella policy and then they discover that there were writers that they were not covered for, you know, public statements they made. And it's like, oops, you know, that can be a problem.



