Navigating the Complex Landscape: Cybersecurity Insights and Discussions for Security Leaders – CISO Talk EP 38
Transcript
Hello everybody and welcome to another episode of CISO Talk. I'm Mitch Ashley, c t o with Textron Group and Principal with Textron Research. My co-host Jennifer Manila.
Jennifer, how are you doing today? Hi, Mitch. Hi everybody.
I'm doing great Author Whisper to ci CCOs, all kinds of great projects and work that you do and speaking and number of things. The CISO whisper that, that's a great, I'm gonna, I'm gonna put that on my byline now. I Think you put that at your business card CISO whisper.
Very much so. Well, that's the truth. Well, well we're, we're gonna take a little different approach on this episode of CISO talk 'cause there's a lot of things that popped up in the news here recently, and I know are on the minds of CISOs and people that we're talking to.
And I said, well, let's, let's do an episode where you and I kind pursue some of those, uh, topics. One of the first ones we wanted to talk about is the new s e C requirements around cybersecurity reporting. Do you wanna say a little bit about what that is?
'cause I know we're expecting one thing to happen and it kind of took a little bit of a different turn. It did. Yep.
So last week, the SS e c came out and long story short, for any publicly traded company, um, and that's companies of all sizes, we think of 'em as large, but there's also smaller VC backed public traded companies. Um, they now have new cybersecurity reporting requirements. Um, and the kind of the few bullet points taken away from that are that they need to report a breach within four days of determining that it's MA material.
Uh, and, and, and I dove dove into what that meant, uh, with one of my friends last week to understand what does that mean for the rest of us here? Uh, so we can dive into that. But doing the, the reporting four days after you've determined it's, you know, something, materials are substantive.
Um, there was also a requirement for, um, I don't wanna call it disclosing, but reporting on the organization's processes for how it handles cybersecurity incidents. Um, and d different response, um, both at the executive and the board level. So explaining sort of what the organization does, what capabilities it does, what are those escalation points, what's the board's oversight and involvement in cybersecurity.
Um, so that's another piece of it as well. And it was kind of interesting because the, uh, in the draft language earlier this year, we all got excited, well, not me, um, because the last thing I wanna do is, is have to sit on a board as a cybersecurity expert. Not, not a happy place to be unusually anyway, but in the draft requirements, they said that, you know, one of the things they were toying with was, are we gonna require cybersecurity expertise on the board?
Meaning you need to go fill your board, open a seat and have a, a professional or two, uh, to meet the requirements under these new regulations that actually got dropped. So that's not part of the requirements, but we are definitely gonna be seeing, you know, Mitch, this, this thing kicks in in December, it's the end of July. Mm-hmm.
So we're talking about less than two quarters for some of these, you know, larger organizations to kind of turn the ship here, get all of their ducks in a row, get their paperwork ready, and have a completely different workflow for incident response, which is gonna be totally new. Yeah. It was, I think at December 18th, if I remember right.
And did you have to have your material incident disclosure? But that would be in effect, I mean, it's, it's for some organization it's hard to get the internal communications, you know, together in, in a matter of weeks and months. But that's a pretty well, and you don't know what the consequences are.
Right? Well, so what, you know, what's material, right? And then the definition of that, and what if you don't fully adequately disclose, you know, what you should disclose.
It's all kind of new ground. That's one of the things that I think Al always drives us crazy with new regulation is that's regulation, but what does it mean? Yeah.
And nobody wants to be that first Guinea pig that steps out of line. And I think it was interesting because it's actually the organization itself, like the company who's, who's publicly traded, that determines whether something is ma material or materialistic. Uh mm-hmm.
So is, is it, you know, some of the examples are there might be a threshold of potential revenue impact as a percentage of this particular breach or incident is going to cost us X number of dollars. If that is some percentage, five, 10, 15% of total annual revenue, then that's something that would have to be disclosed. But it's the organization that gets to determine that, not even the s e c that has set a specific threshold.
So that's kind of one thing that I think is very much up in the air because, you know, does that mean an organization might reclassify where that threshold is for them looking, you know, and I think there's gonna be some lookback time to mm-hmm. Say, okay, what's happened in the past five years that would've fallen under this? And is that gonna drive us to categorize this differently if that's even an option?
Um, and then my curiosity here is it doesn't really discuss at this point any consequences for not reporting or consequences for not reporting on time. You know, other regulations we have, there's, there's like a daily fee, um, and sometimes that's just a line item in somebody's budget. We know we're gonna screw this up, or we're gonna do this intentionally, and we're gonna pay these fines or fees for it.
But, you know, I'm kind of curious because I'm sure whether deliberately or not, somebody's going to miss the mark on that reporting requirement or some of the other requirements. Um, and we don't really know what that's gonna look like. I mean, we've seen everything from, you know, a letter to possible jail time for CISOs and executives that have been deliberate Well, and it, uh, until it isn't, it's a moving target, right?
Nobody not knows quite for sure. So you do what you think makes sense. Really what really means is you go hire the consultant that's gonna tell you, here's what we think makes sense or people are doing.
And that's sort of your safety net as what we hired a third party to help us figure this out. And sometimes that's the best you can do. Uh, and also the reporting requirements around, uh, cybersecurity governance and your policies and your cybersecurity program.
You know, I would imagine that's just a disclosure, right? That is, I mean, it goes into the AK filing. So it's, it's for your investors to know what you're doing, and again, how much do you disclose how much is adequate?
Maybe you're not ready to disclose it, but it certainly is a forcing function. It's, it's interesting. It's now an s e c action to get us to do this or requiring us to do that.
I think that's what I guess puts a little bit of a fear in us about, okay, how do we do this and do it right? Yeah. And I think as, as consumers in the world of those of us that are just out interacting and, you know, putting money places and, and, and buying and selling things, um, you know, I think it, it has the potential for give us, giving us some more confidence and the companies that we're doing business with or investing in.
Um, but, uh, yeah, it definitely sounds a little messy still. Um, but for, for some parts of it, aside from the actual incident and disclosure piece of it, you know, the other parts with, you know, describing the risk management and third party risk really was, it's just a say what you're doing and do what you say, which is mm-hmm. Very similar to, you know, like iso um, uh, certification when you're going through that, which is, you know, if you have processes that fall under this, sometimes it's gotta meet a certain framework.
Um, but, but then it's a little loosey goosey, and as long as you're documenting what you're doing and you're doing what you're saying and you say what you do, you're good for that piece of it. So I think it's, um, you know, one of the things we were joking about last week is it's, it's definitely gonna be, you know, I think at the end of this, after the first filing, which is again in December, N Q one of next year, you're gonna get like everybody peeping over to see, you know, they're gonna be reading everybody else's reports and go, Ooh, you know, theirs is a lot better. Let's try to use that as our framework next time.
Mm-hmm. Um, so it's, it's gonna be interesting. But I, gosh, I mean, it's so much work to do in the next five months with everything else happening in the world.
It is a very short timeframe and, and, uh, not much guidance. So I think there'll be a lot of phone calls and emails that already gone out to your compatriots, your peers in the field say, what's your take? What are you gonna do?
You know, unofficial communications is probably well as official, right? Yeah, Yeah. Absolutely.
Well, let's, let's set on term topic to, um, one of the things in the news also, uh, this might go under the, I kind of of figured they were doing this, but the, uh, Chinese, uh, putting malware, hacking malware into government systems and the federal defense systems, uh, around the ability to thwart all kinds of things. Communications, power, you know, water, you know, infrastructure, things like that, I guess maybe directed at it if something were to happen with Taiwan, right? And some kind of action were taken there and a US response, it could be for a lot of other things too, I suppose.
But that's what certainly got, I think, our attention about it. We've talked about critical infrastructure and people hacking in. Now we've got evidence if we didn't before, the Chinese are doing it.
Yeah. And I, I feel very personally passionate about protecting our critical infrastructure. I've worked in and with those, um, types of organizations for my entire career, starting with a lot of telecom and then getting into a lot of utilities with specifically power generation and distribution, wastewater treatment, financial healthcare.
I'm sure there's one or two sectors I haven't directly worked with. But, um, yeah, it's a little unsettling because we do have, in a lot of these, we do have very fragile systems. So I'm gonna take maybe financial out of that for a minute, since a lot of that is, is data driven.
Um, but anytime we have cyber physical assets, the things that are like Colonial pipeline where we have gas that's being pumped around, or we have power that's being generated, or we have water that's being cleaned. And I think for a lot of years there's been stuff happening, and there's definitely been direct attacks on OT systems, operational technology, but a lot of the attacks like Colonial were on the IT side, and it was, they couldn't bill, so therefore they stopped pumping oil, um, or gas. But some of these attacks recently, specifically aimed at the federal government here are a little concerning because they're so outside of what, at least those of us that aren't, you know, in the inner circle of that, it's so far outside of what we've seen before, and it's so far outside of, I think what we would have expected.
So we have everything from, you know, the, the manipulation of the Microsoft Keys, switching from kind of one tenant zone to another, uh, and, and a very, you know, surgical attack against a handful of accounts there, um, specifically to, you know, some of the, the liaisons to specific countries coming out of the, uh, US embassy offices. Um, and then we had a, you know, a similar, um, attack against JumpCloud. Mm-hmm.
Mm-hmm. Again, very surgical, a very small handful, uh, of accounts. You know, I think that one was targeted at, um, cryptocurrency companies.
But when we look at some of this latest stuff coming out in the past 24 hours where we're talking about, you know, potential sup, supposedly Chinese malware being used specifically to impact our military bases and water communications and power. I mean, I don't know what happened to you guys during the Colonial pipeline thing. Um, we still had, you know, most of our normal, uh, things we need for daily life, but we, we didn't have enough gas here, like, you know, to power the vehicles.
And our schools shut down right after they had just opened back in person from covid, uh, and the buses couldn't get gas, so we had to stop. So it was really disruptive, but, but when you look at things like power and water, it's concerning. Um, this is concerning to me that they've been hiding.
Now, the question then becomes, so obviously, you know, the US has had a, a long relationship with Taiwan. We get a lot of stuff from there. Um, China just tends to not like anybody doing business with anybody that they don't have control over.
So, you know, Hong Kong, Taiwan, whatever's in their cross hairs is always a little bit dangerous. Um, so then the question is, are they gonna sit there and collect intelligence and use that somehow later? Or is the intent for it to be disruptive?
Um, and it, it's an either or at least it's a, if it's gonna be, it's not both at the same time. So they might collect for a little bit and then, and then do something that's disruptive. Um, but some of the, you know, the, the tactics with this are different.
So I'm a little, I'm frightened about this. It definitely is, it definitely gives our attention, you know, it kind of reminds me of like a, is this a stucks virus sort of scenario, right? Where this is, get in there, get control of things, we can start now doing things we shouldn't or the Chinese could in our systems, in our military communications, telecom, power, water, et cetera.
Is it a listening post, you know, to find out what we're doing? Um, but I think the thing that got my attention the most was around Taiwan and the disruption that this could occur. I mean, you can imagine, yes, there is cutting us off from Taiwan or cutting Taiwan off from the rest of the world, but the, when you talk about power and telecommunications and water, now you're talking about disrupting our society, right?
You want, you want riots in the streets cut off people's power water, and they can't communicate, right? That that's what's gonna, that's what totally upends, you know, societies, right? So it could be extreme.
I mean, not to, not to overstate it, but, Well, and I mean, with, with China, you just never know what their intentions are. And so, you know, right now, if the target is military bases and maybe a lot of those are outside the US and it's, and they're targeting the bases that might be responding, should China invade Taiwan, then that's one thing, and that, that's its own really bad problem. But the way I'm looking at it, at it is, if they're able to do that, that at those targeted areas, there's very little stopping them probably from doing something similar.
Here. Again, these systems are just so fragile. Um, they're old, they're not always, um, I don't wanna say maintained well, but you know, just, just like they've been sort of isolated enough that all of the, the progression of technology and security that we've had in the rest of it, and the rest of cloud that has not moved its way down into these legacy OT systems.
And some of them were just very, very vulnerable. So I, I wouldn't make the assumption that just because they were attacking something in Guam and that was successful, that that doesn't translate to some of the systems here. I think, I think in layman's terms, one of the ways I describe it is think of our infrastructure in terms of roads and things that you visibly use every day.
And we all know parts of our road systems are not in the best shape, right? There's some good new stuff we've created, but there's a lot of things that are under maintained. Think of our infrastructure and the systems and security of it are a lot like that, right?
There is not a lot of difference. There are a lot of systems that have been out there for, you know, 30, 40, 50 years in some case, some of it's pretty old stuff and hasn't been replaced. So, yeah, it, I mean, I think as a, as a ciso, you look at that and say, well, I can't do anything about the infrastructure, the government side of it, unless I'm a CISO in the government myself.
But also, you know, if you've been around a while, you know, if you've got systems that are 10 or 20 years old, they're probably also, you know, have a few, uh, worn spots on 'em that need addressing maybe a lot. Yeah. Yeah.
And I mean, right now, you know, Mitch, we're in this big conversation around, it's almost a tug of war with, um, so I'm just making a broader ot, you know, um, I c s comment here with, you know, the reality that a lot of enterprise IT security professionals, so CISOs and, and CIOs who have security, uh, responsibilities, they are now being tasked with figuring out how to properly secure the OT environment. Because in a lot of these places, it's been one of two things. Um, and, and sometimes both of these two things manifest.
So it's either OT is over there and we're not gonna really worry about it over here, or they've just sort of put OT stuff on an enterprise IT network and not put a lot of thought around the segmentation. And so, you know, looking at the difference between IT and ot, and this is one of the reasons I've been working in that, in that weird niche, um, recently, is because there is such a, a challenge here, we can't treat OT systems the same as we do it. The same tools that we might use to scan and see what's happening.
We can't use the same, the same methods we might use for segmentation are not appropriate on an OT network. The same way that we monitor and the fidelity of the learning that we get for incident response is not quite the same now. I mean, there's, there, there underlying currents of things that translate from, from a conceptual standpoint for protection, but the, the tools operationally are different and the workflows are different.
And we have to remember that OT systems above all else, we're usually favoring availability. Keep that system up, keep the water flowing, keep the power on, keep, keep the cast flowing. And in IT systems we're way, we're way more nimble.
So, you know, there's, and, and you know, part of my work right now with the Cloud security alliance is helping, um, lead the group that's doing the guidance for critical infrastructure, including, but not limited to OT and I C s. So this is, you know, timely and, and near and dear to my heart right now. Um, but there is, there's a lot of work we have to do.
And I think, you know, maybe the upside of this, the silver lining is that it does give us a, a better opportunity, um, more education. There's a lot of us out there trying to educate the IT side about what to do and not to do an ot, but this tug of war we have is that if you talk to an OT professional, somebody that works in operational technology systems day in and day out, 'cause there's not a lot of overlap here. Mm-hmm.
They're gonna tell you to segment it from OT as much as you can. Mm-hmm. Like physically, logically, don't use the same networking equipment, don't even share a firewall, don't, uh, you know, um, don't use the same active directory structure, may or may not use the same, you know, log management and alerting system.
But the problem is, is the OT side doesn't have the, it, the maturity and the IT systems that we have that we're half the time barely able to do right on the IT side. So we're definitely not gonna be able to run parallel systems. So we have, you know, the OT professionals saying, we have to protect the systems, keep everything separate.
And then we have a lot of the vendors coming out with their combination ot, iot, single silver bullet product and pushing towards converging these two. And I'm all for converging these two, these two, I hope that we get to the point we can do that safely, but we're not there yet and it's not a safe thing to do. So maybe the silver lining is education here Sounds like a segmentation strategy, which we're very familiar with in, in security.
Right. Well, and one is one could affect the other. There's also just as you're talking about sort of generations of technologies and exposure of risk.
Um, so the last thing I wanted to turn our attention to is, you know, ai, you can't turn the front page of whatever digital magazine you're reading or newsletter scroll, you're scroll down halfway down in a newsletter in your email without bumping into AI or generative ai. And it's definitely on the minds of everybody. And a lot of it is about how are we using it and, and, uh, late vendor's latest things that they've added to the product.
But there's also a lot of concern around data that gets fed into long, large language models. And that being proprietary data, uh, hipaa, personal identifiable information, medical information, um, you know, even discussions about if you've used data of something of mine that I helped create, then you owe me money. If you use it in your model, there's sort of the financial replications.
I'm curious your, your thoughts on the privacy aspect of this, because it's very easy for someone innocently to say, let me load this into some public large language model, and poof, now everybody has access to it, yet it isn't domain controlled unless you make it domain controlled. Yeah. This is something that I think, you know, the, I think everybody wants to leverage ai, whether it's, um, for, uh, personal, for like vacation planning or professionally in some way.
And, you know, this is a conversation we have with CISOs a lot. And a lot of the requests we get in, you know, even in my customers and then through ions is, um, security professionals and executives that are asking, Hey, what do we need to do about ai? Do we block it?
Do we, do we do this? Do we do that? Because, you know, things that might seem innocuous, like some of some of these platforms are really good at generating code.
And now people like me who are terrible at coding might go, oh, hey, yes, I don't really know how to write a Python script. Let me just feed some stuff in here, tell this this engine what I wanna do and let it spit the code back at me. Um, and I've actually heard from, from several people, some of those are, they're pretty good.
Um, but it's, what are, what are the developers or what are the people putting into that? Is it proprietary information? Is it intellectual property?
Is it even, because there are some people that are just dabbling in a lot of these technologies, they don't understand that an a p i key is kind of like having a root password to part of your infrastructure. Um, and so there's what within the organization might be fed into this system or this platform. And then there's all of the other stuff, healthcare information, financial information, socio genomic information that might be a little too specific.
So, you know, I, I'm really interested to see, you know, I think we've, we've been hearing these, these cycles of discussion around we need some type of regulation for ai, how it's used, who, how it's used, who it's used by, what it's used for, and to what degree. Um, but in the meantime, it is really just a wild, wild west and it's gonna be hard to put the genie back in the bottle. I think with this, uh, in the meantime, we're all trying to use AI and we're all pushing, pushing pieces and morsels of information into it.
What do you think you've, you've lived in this space for a while now, what's happening? Yeah, it's, it's interesting 'cause my AI experience goes lot, a lot longer before generative ai. And it sure has come a long ways, but, you know, I think there's the, how, how do we leverage this either for competitive advantages or just business operationally, you're like, what should we, what's okay for folks to do at our companies?
Those are two very valid questions and, you know, areas to pursue. I think from a data standpoint, um, I think, I think we do need to give our organizations some guidance on what kind of data we should be feeding into what kind of AI systems. You know, if it's our own data that we're pulling out of our, you know, it's anonymized or whatever we might have from our own systems to put into machine learning algorithms or to put into a generative ai, you know, if it's done thoughtfully, it can be a huge advantage if it's, it could also be just a huge escape valve to go onto some public SaaS service that your data's now living up there.
You didn't realize it was gonna be answering questions for other people. So I think that's one, you know, just as much as we say, don't click on stuff, it's, here's when you should use our data in, in, in an AI system. Here's when you should ask if you should use our data in an AI system.
So it isn't a don't, it's a ask. 'cause we don't always know the use cases and the scenarios that people are pursuing. I mean, yeah, we know some of them, but that's, that's a lot of the wild west is we don't know all the use cases by any stretch, so we can have to learn with our organization.
Yeah, and I think it's something just popped into my head while you were talking here, which is, it's one thing I think to, to talk about it within your organization, and I think user education plays a big role in that. I've talked to CISOs about what they're doing to educate their user population around ai, but it's something else to think about. What is someone else doing with your information that you don't know they have?
And at least in Europe, G D P R helps a little bit with that because there's a lot of specificity around use of, and, and sharing and retaining other people's information. But in the US we're just kind, we're ss o l over here. We don't really have a lot of help when it comes to that.
And our pieces of our lives are just scattered a around the world in, in the marketing world here, and they're all selling the information to each other. And so there are large pieces of ourselves in our world floating in these pockets and buckets that are not under our control. Whether it's a business to business relationship or a business to consumer relationship.
I just think about the freewheeling, oh, I'm ha I'm okay sharing my, my personal stuff on social media. This could be the okay I wish I wouldn't have, because now all that's Yeah. Being harvested and leveraged in some way, you never, you didn't have control over at the time and you don't have control over it now.
So Yeah. But there, There's a lot more questions to be answered or asked. Yeah.
And it's, it's so invasive now. 'cause there's, you know, I feel like every day I wake up, or at least once a week, there's someone else that has an app that's on a phone, uh, or I guess it could be an app that you're running, you know, on a laptop or tablet, but there's an app that is collecting and or sharing information in a way that it shouldn't be that is in vi it is in violation of its own data privacy rules. Mm-hmm.
Mm-hmm. Now, Mitch, on the other hand, I am, in my prior life I did graphic design. Um, and one thing I am very excited about is one of the platforms I use for graphics.
Uh, there's, there's Canva and then there's vis me that I've been using for one, one for graphics and one for, for slides and presentations that's not PowerPoint. Um, and one of those has like a little, um, AI generated image. And so I can make up something very specific because I don't know about you guys, but, um, and I think this is invis me because when I've done presentations, I like my slides to be pretty, you know, I, I feel like for two reasons, graphic design, you know, like I really wanted to be a designer in life, and my parents basically said, we're not paying for you to go to college to be an interior decorator, so you can do computer engineering, or we're not paying for college.
And so I did pretty Definitive guide. Yeah. So if, if the, if this it security thing doesn't work out, I, I do have a plan, but, um, you know, also just from a readability and an interactive standpoint, it's visually you can communicate much better that way.
So they have this little thing that says generate an, you know, AI image. So you can be very specific. And I, I put some, like, I got very specific because sometimes when I'm putting a presentation together, I spend more time sifting through images mm-hmm.
And finding one that I can, that has a, um, what do you call it? Like a, a, the common, you know, the copyright C C L Yeah, yeah. The copyright, so you can use it.
So I, I waste so much time. So, you know, I was writing one on, on mobile device stuff, and, um, you know, I said, okay, make a, make a photo, specifically a photo of, uh, business men and women standing in, uh, a specific desert on mobile devices. And then I got more specific from there.
And then, and then finally I just said, um, create me a photo of rainbow colored horses running down the highway. And that was obviously my favorite, my favorite photos. So there is, there is good stuff happening in the world of ai.
And I don't know that ai, I'm, I'm still, you know, I still get a little heartburn about the whole phrase, the overuse of ai because we, we do have, you know, these lms, we have systems, but so much of in our space and information security, so much of what vendors are doing is really just like machine learning and algorithms. It's just pattern recognition. Um, so I hate that we, we throw a, that's another kind of regulation I would love to see is, is put some definitions, you know, like gluten-free, you know, AI powered.
I, I feel like there needs to be some expectation from the consumer and that then that needs to be regulated to a greater degree than we are right now. Yeah. AI is a mile wide and two miles deep, right?
It is big. It's like security. It's like massive.
There are so many aspects of it. And you're referring to sort of the cognitive, you know, learning and intelligence and consciousness, et cetera, all that kind of interesting fun sci-fi stuff today. Maybe it won't be someday.
What's interesting, I think, I mean, it's definitely a conversation I think everyone's having, and we'll continue to have, I don't think we're gonna have it all, some, some really good answers in the next six months, and then we'll kind of know what we're supposed to do. I think it's, I think we're in a, uh, pretty, um, the pendulum's not swinging. It's, it's kind of circling all around.
We'd be there for two, three, I don't know, five years, who knows how long it's gonna be. But I guess pay attention is the main, main thing we have to do and keep asking questions. Yeah, absolutely.
I'd love to see what Europe is doing because I think they've, they've set precedents we can follow for a lot of privacy rules. So that's, that's, that's exciting because it is nice for those of us that want to have that here. We can point and go look, they're doing it.
Yeah. There is, I, I remember I was on a webinar and they were talking about, um, the eu, EU did have same some AI ML legislation. Um, yeah, they do that.
They had announced a regulation framework kind of thing. I'd have to go Google it again and find it, but sounded like they were starting down that path. There they are.
Yeah. Well, jj, Jennifer, it's a lot of fun as always. Um, we got to talk with the each other this time as well, and, you know, we enjoy talking with our guests when they're as well, but it's nice just for you and I to get to kind of share our thoughts and pursue a couple ideas and lots of questions.
Yeah, this is fun. Yeah, I love, I love the topical stuff because these are, you know, I think there's a lot of resources people are always asking for, and then sometimes it's, they just want to kind of get perspectives on what, what's happening in the past, uh, few weeks and what are the rest of us concerned about? And it's a great way to do it here.
Great way to do it. Uh, Jennifer, great to, uh, talk with you again. And thanks to everybody in our audience for joining us with, uh, this, uh, edition of CISO Talk.
We'll be back with some more great topics and guests. And uh, Jennifer, thank you again. It's always fun.
Bye everybody. Bye Mitch.



