Achieving and Maintaining Compliance – Igor Volovich, Qmulos
Igor Volovich, vice president of compliance strategy for Qmulos, explains why existing approaches toward achieving and maintaining compliance are fundamentally broken in way that adversely impacts everything from cybersecurity to business risk management.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with eager bulovich who is vice president of compliance assessment for cumulus, and we're going to be talking about honesty. And what is the current state of honesty in the land of cyber security is we kind of look at this Brave New World where nations are attacking each other and there's just tons of collateral damage everywhere. You look Igor.
Welcome the shop. Appreciate it Mike. Thanks for having me.
So to the point, we have invested tons in cybersecurity over the years and everybody has this kind of some sense that they may or may not be secure. They're not entirely sure but do you feel like we're actually being honest with ourselves given the not only the increased volume and the attacks, but what appears to be a ratcheting up with the sophistication of the attacks? Well, so multipart answer for that multipart question, right?
The short answer is no I don't think we're being honest with ourselves about this the security posture either at the national level at the organizational level at the level of individual departments within companies and individually as as people who participate in these ecosystems, I think as Citizens as digital citizens as workers who work within these companies and I think we don't do enough to ask the question of exactly the question that yes. I want to start with being how how much credibility is in the information that we have about our security posture and really people interested in knowing how credible this information is. You know, can you handle the truth?
I think is the question that I would ask right and there's this idea plausible deniability, right? If we know about a thing we have to do something about right. So, you know, if you have done ability, you can avoid it accountability.
At least that's the model that used to exist. You know, people rely on compliance. Well compliance has some built-in limitations, right?
You know, we always looking in the reviewing your rear view mirror. Not looking at the current state truly and compliance is really the closest thing. We've had to anything any kind of a consistent model for measuring security posture.
You know, that's sort of been the proxy for it except. You know, you're looking at that report. It's as good as that by the time it's printed right by the time it lands in your desk.
It's it's worthless. Right? So you're trying to do risk management.
You're trying to understand your compliance posture you trying to stay security posture really by using compliance. But traditional kind of Legacy compliance has not really been effective at that. I think that's one of the reasons we haven't really had a good model for understanding what the resposter is.
So we've defaulted we've relied on this kind of insufficient model of of compliance and that leaves us in this kind of fog of War. That's basically what we're operating under. I'm having visions now of Jack Nicholson as a seesaw where he's basically telling everybody you can't handle the truth.
But are things getting better in this regard. We're seeing more people apply for cybersecurity insurance and the carriers are getting tougher. So maybe the bar of compliance will get higher as we go along and is there something to be hopeful and all that?
Well, I think everybody's getting a little more serious about it. I think a lot more serious that a couple of things that you set up front was, you know, we see more sophisticated attacks and certainly nation state attackers are getting a lot more sophisticated but you know kind of the around the mill the things that you read about every day, it's basic stuff. I mean it's fishing right?
They're exploiting basic social engineering techniques. You've got business email compromise. I mean, that's really it's just conning right?
It's cunning people into doing things for you know, transferring and wire transfer, you know, a billion dollars like that. There's no sophistication there at all. It's a basic understanding of human psychology, right?
And that's what social engineering really is. But to your other point, you know, if the attackers are getting more sophisticated certainly, I mean, there's a lot more a lot better. I exploitable vulnerabilities that are getting discovered right?
There's better trait craft out there for the bad guys. It's this constant arms race. I don't think there's been a real true leap out of that.
You know, nobody's really taking a Leap Forward on either the defense side or the attack side. I think the volume is grown. I think also from a criminal perspective a lot more people.
Are able to enter that Marketplace and the threshold that kept them out, you know, the barrier to entry used to be the sophistication of the skill set. And now it's just all available. You know, you can do ransomware as a service, right?
You know, I got a couple hundred bucks. You got a credit card. You stole somewhere probably but you can jump in you can rent somebody's botnet.
You can rent somebody's ransomware so that that's increased the volume. So and I think that's challenged the defender certainly, but you know volume alone is I mean quantity alone is not gonna it's that's not the biggest concern for me. The biggest concern is the fact that we don't have a decisive model for measuring risk going to continuous basis and and managing managing.
I mean discovering it and I'm doing something about it in a truly effective way. We seem to throw a lot of Technology at the problem. We spend the most money every year on technology and yet we get the most regions.
So something is broken fundamentally in that and not Oman, right? We keep throwing spaghetti at the wall hoping it sticks and you know at best it becomes an abstract painting in a couple of days, but but it's not really doing anything for us. Right and I think that the problem is that we're not exposing the reality of where our environment stand and I mean at nation state level orientation level down to level of a single user single system single asset.
Do you think the Cyber criminals are kind of laughing at us at this point? All the way to the bank. Absolutely.
I mean look you you I don't know. If you saw a couple years ago, maybe within the last year and a half then a story out of I think Belarus were like a grandma which in Russia is like 55 and over but a grandma Babushka I was running an operation like she was not herself a hacker. She was not technically sophisticated at all, but she kind of became a den mother to this band of cyber criminals and she was doing their accounting.
She was managing their finances. She was doing some basic attacks, but I mean, you don't need a lot of sophistication you just press a few buttons and you pay a few bucks and there you are and she was uncovered and arrested I believe and got prosecuted but which is a rare occurrence in that space by the way, so it just shows you that you know, it's not It doesn't take a lot. Right?
You know, are they and and you're laughing absolutely, of course they are you know, and because we have we continue to have this arms race, right and we always chasing them around the block they come up with something we come up with some defense they come up with a way to circumvented. But the one thing that we haven't come up with a great way to defend against is human element in cybersecurity. Why this fishing work was it continued to work because it involves humans right as long as the humans in the loop, which will never go away.
It's just going to continue to happen. Right so we've got you know security awareness training. It's I think we've reached what I've come to call pic awareness.
Like there's only so much training. You can give to somebody before they start turning turning off and tuning out right we can do these kinds of calls we can we can do webinars we can do training we can do interactive gamified training, right which is kind of the next level but people actually put their hands on something and really try to experience it. So for experiential learning that's really geared towards towards adults.
We've done all that right and yet still attacks continue to grow and grow so I think there has to be something better. Right? I think we have to talk about things like cultural change right where it's not just a training you go to and you check a box and you fill it in your compliance report.
And you say okay with train x amount of people out or organization, you know, we all get those emails. We only have 80 80% penetration. We need 95% minimum to be trained on the latest security awareness training, right and we check the box and we feel better, but it's really not doing anything.
It's just kind of a cover you're behind exercise. To say that in in the eventuality of the breach which will happen. Of course, right?
Once that happens. Then we get to say say well but we've done everything possible Right what you haven't really done is actually try to truly credibly influence those outcomes in a long run. And the only way to do that is cultural change, right?
You actually have to embed security into every function security cannot be its own Standalone function compliance can be its own function right risk management can be it's own function. It really needs to be a dimension of every business function. So you need to understand your value chain building you have to understand your your mission.
You have to understand what are the critical activities where the critical assets are right all the basic stuff that we talk about but once you've done that Don't wrap security around it. Right and don't try to use compliance kind of traditional Legacy compliance just to get some insights which are all I mean, they're out of date by the time you've collected them. Right?
So the real idea is to make all those functions ban together you bind them together, you embed them from the start and this whole idea of you know shift left that we've been in Def psycops that needs to happen across the entire business. That's not just for security. That's not just for your development Community you shift left with your risk, you shift left with the understanding of your risk how threat models apply to your business how you build value in your business with a customers you look inside and you look outside, right?
So it has to be this complex holistic model and I've said a lot right? That's a lot because it is a lot right? It's tough to do it's hard to do but to your point if I'm a supply chain executive and I'm building out my digital supply chain.
I need to think about the security of that supply chain as I'm building it versus building it and then coming to somebody like you and say hey, could you maybe secure this thing for me that I constructed with that your input? Well, I mean that's it's a great conversational like to have so we do we would like to do Discovery sessions. We'd like to have conversations where there is no PO at the online, right?
You know, we're not trying to sell you anything. We tried to sell you on the idea that there was a better way to to do this, right? There's a better way to manage risk when you actually using the Investments that you already made and leveraging them to to about a value right?
You can create these volume multiplayer Effects by applying the right kind of mindset first and then the right kind of technology and look I'm not here to tell people in technology, right? We all know about technology. We all love technology will technologists.
That's the reason we probably all got into this business in the first place. I mean certainly is a story of my life, right? You know, I like to hack I like to play with things and and that's how I end up doing what I do, but eventually you you come to realize there was a purpose to all of this right?
We're not here just to Tinker with toys. We're not here to get the latest greatest shiniest new thing and play with it. Right the idea is to manage business Brazil and resilience and to ensure Better Business outcomes secure business outcomes and really churning as we said before security into a dimension of everything you do, right?
So when somebody and says look, I I need to understand my supply chain risk. It's good that they're saying the word risk, right? They're already thinking about the right thing, right?
So the idea is how do you how do you understand how risk translates to you as either supplier or sub supplier or as a consumer of these things right now something I heard recently at conference. And actually forced our out of the Senate and I love the way they put it I used to say Securus your value chain and then things like supply chain immediately come into it forcer said secure what you sell. It's a very easy catchy little way to say.
It's a great slogan. It's a great tagline secure it yourself. If you can understand how things move through your environment from a value perspective.
It starts to make a lot more sense, right then your threat model kind of builds itself. So instead of saying let's go bottom up from the tech. Let's figure out you know, what does that software come from where every component comes from?
These are very important activities, right? But overall, how does that map to a business activity right? So can I get out of you know, the way we used to say what I Mentor in an accelerator get out of the building, right?
You got to get out of your little bubble. You gotta go out and talk to people who are in a different functions. You're gonna learn something else.
You're gonna learn something new you're gonna figure out how what you do applies to them. So basically you have to collaborate constantly have to have this empathic true engagement where you are actually learning and not just coming out and imposing, you know compliance security risk management. Security awareness training and so right you what we're trying to really drive towards is a better experience whether it's a security experience compliance experience Works management experience, and I don't mean just for the people who are doing the work.
I mean for anybody that the function touches across the Enterprise from every person who gets to fill out those little reports and the questionnaires that come out every, you know, three months or four months or six months or whatever, right? Really anybody that engages with this function should have a positive experience that is not the reality today. And I think when you extend that even beyond the Enterprise you start looking at supply chain or somebody who you are a member of their supply chain, you have to keep that in mind, right and and I think that again talking about the human element and how important it is.
And also how much of the attack surface that are presents today. I think we pay insufficient attention to the importance of creating that good positive experience whenever somebody engages with so we engage with them right a security professional risk professionals compliance professionals. So I think focusing back on that kind of and it sounds fuzzy, right it sounds hokey.
Sounds like we're sitting around a fire, you know singing Kumbaya and holding hands, but we actually do have to hold hands and we do have to sing Kumbaya. We have to bring everybody together. It has to be a truly culturally engaging experience.
Right and and that's something that we have an I feel we haven't done a great job of as an industry, right? We've sort of been this department of no problem enforcement. It's always been all these deterrence based models, you know, we catch you A bad thing when I punish you and let the other people want you you get punished and then hopefully you won't do it again hasn't worked.
It hasn't worked. We've had the first building code since the days of Hammurabi building still fall down. Right?
So it's an imperfect model and security is too complex technology is too complex to be able to do that at scale. Right? You know, how many CEOs can we fire?
How many systems can we fire? You know, we keep doing it. It hasn't had an effect.
Right? So it really has to be more of a cultural change. And if you're operating in a secure environment, you know, if you remember of like a defense industrial base, right which we have somewhere between 80,300,000 players in that field.
The responsibilities aren't higher right they accountability level is they don't hire you're talking about National Security talking about defense of the industry data. So you have to think about kind of you know beyond just I need to cover myself. I need to make sure that I show it, you know good compliance.
I demonstrate good posture and then, you know get to that next snapshot that will take a year from now two years from now three years from now, you have to think about it from an ecosystem perspective. I'm a member of a tribe. I'm a member of an ecosystem and what I do as a knock on effect another things right up and down the chain so somebody comes to being asked that question.
I would say let's look at how everything connects within your world. How are you a member of that ecosystem? And when you engage with those other parties what kind of experience do they have?
Right it starts with that it starts with culture and now we start building we kind of start going down from there. So it's not bottom up. It's never bottom up for me.
So the best cop in the world is the one that knows their neighborhood really well, right because they know where all that weaknesses are and they can have some advice with shop owners and where else might become a victim some days similar idea. Do you think we're in danger of? Cybersecurity fatigue to the point where business executives are tired of funding it because they just see all these reaches and so they're just gonna say, you know what?
Let's hope for the best. We'll get a cyber security insurance policy and see how it all turns out, but we're not going to be able to change it because there's no Roi that they can see So a couple of things there. Yeah, I think I think first of all the point is well taken right.
I think there's a general fatigue about security. We keep hearing about it. We keep hearing about it's like, okay, how much can we hear about so it's like pic awareness Peak security.
I think it's peaked security. I think it's I mean security is infinite just like Risk is infinite, right so you can you can apply security infinitely but it's how much can you hear about it? That's the problem.
It's about security awareness Peak security awareness, right? So, yeah, I think there's fatigue. I think there is a reluctance to continue to fund these things because frankly we keep spending more and we keep getting contiency worsen worse outcomes.
Well at least no real impact on that. Okay, let's right. So what's the point like we have to do this right thing.
So let's just do the bare minimum. Let's just do bear level compliance will get away with that. Right, you know next time we have a breach.
Somebody gets cold in front of the Congress. They'll just wave that compliance report and say look we've done our bare minimum, right? That's been the monster that sort of been the operative idea.
Right? I think that's getting less and less plausible what we're seeing right now from the regulars. I mean, we've got mandates coming out of the White House FTC FCC if you remember back, I mean, of course you will but you know some of the audience might not but you know, 20 years ago once Ibanez Oxley came on the it came out.
Every focused on Section 404 right that was the technical controls that went within a general controls. And and that's where it'll fit. Right that was supposed to create a level of governance and assuredness within the the it General controls now.
Fewer people pay attention to section 302 which is the accountability section, right? That's where it says the CEO and the CFO have to sign off on these controls. Right?
So the 10K the annual and the thank you the quarterly. You have to state that you have no awareness of material deficiencies in your controls. Right and you used to be able to just get away with that one line.
You know, we are not aware any material deficiencies, right? The problem is The regular is not one transparency. They want to actually understand exactly what's going on.
Right? They want to know how a program is working. They want to see the control State.
They want to see how you getting to that control state. So we talked about confidence honesty, right? So things like compliance confidence that's coming to a Forefront.
You know, I've been saying it for years now a lot of people asking to say too. How do I know what I know? Right and it sounds a little, you know philosophical and we're getting into epistemology here, but the reality is how do we know what we know about the compliance state which means the secure state of our environment where that they data come from.
On on balance. Most of the data is actually not data. It's actually opinion.
So what I call my, you know, kind of the common traditional compliance model, it's opinion farming at scale. You're asking a lot of people about their opinion you codifying you're putting some spreadsheet and you have a dashboard and you say look here's where we are. It just represents opinion, right?
It's a poll. You're just pulling your audience. That's not a true state of of the world.
And I think that inconsistency in fact, by the way that every audit every SMS assessment is a basically a negotiation, right? We look at this control. We think it's this way and and it looks at and they challenge us on it and back and forth we go to the world happy or equally unhappy and then we call it done right and then we'll come back and do it again next year, you know mountains evidence a lot of billable hours.
I mean this entire model is just so broken and I've been saying compliance has broken for years and and well I will keep saying it until it's fixed right? I just talk to somebody really this week. Actually I prominent industry analyst and she said I want to hear the word compliance anymore.
I'm sick and tired of compliance. It's not doing anything all it's doing is making Consulting companies Rich. It's making budgets poor and it's not creating real positive outcomes.
Like it's not doing it. And and that's the truth. Right the reason it's not doing it.
It's because compliance is broken now when we talk about Transparency, right, you know the data is just not there. It's mostly opinion. The insurance companies are very keenly aware if they know anything they know risk, right?
So when they look at this idea, well we'll just do a bearing minimum and then we'll offload the rest of the risk of insurance policy. Insurance companies don't want any part of that. Like they actually want to know how much to risk they're taking on and what we saw early when as our insurance started to come out.
Folks were trying to get those policies and insurance companies are very happy to get those checks, but there were a lot of exclusions in there and people didn't read far enough into it. And the other writing process was not all that sophisticated, you know, they'd look and say well how far down to a question here. Could you get if you get about half of it, you're fine.
We'll write the policy and they relied on those exclusions because they knew ultimately they were in the hook for very little risk, right? So people kind of had this perception. I'm covered.
I'm good to go. It's not binary you gotta read the fine print and so when the breaches start to happen Especial answer wherever the last two years with the pandemic, People come to find out it barely covers maybe the response services and not really from a tier one firm either like you're not getting managed. You're getting you're getting somebody right but you're not getting manual.
And so there's a million dollars in there. What's that gonna cover, you know basic forensics, maybe, you know, you get a few hours of of into response. Maybe you'll get some support and maybe you know, you got somebody to talk to that behind you'll be half.
That's about it. Right? Nobody's actually coming the loss.
That's the thing that you thought you were offloading. You're just you're just covering Support Services, right? So A lot of people woke up to that right at the same time.
The insurance company is saying look we're kind of exposed here to things that we don't necessarily understand so they started relying on those exclusions and some of them got crafty. So a case out of France where AXA major carrier right worldwide area denied coverage because they said these were acts of War. They actually said this was cyber conflict.
These were acts of War not. And I did not coverage based on that so they went to court. I think they actually the case is being settled.
I believe in the plaintiff's favor, but we'll see about that and we were talking about hundreds of millions of dollars. I mean there were real business losses and and the insurance company got sued for that and I said, they claimed inclusion as acts of War. It was interesting because they unilaterally declared it the state department or the Foreign Service of friends did not declare it.
There was no formal declaration by by un or NATO anybody else but yet the company will add on that. So it shows you there's still some instability in that market, but the trend is towards transparency and accountability insurance companies really want to know where you stand and they're not going by your compliance report. Like they pay no attention to that.
I mean, it's it's a starting point, but they really want to dig in and understand what's going on. Right? So unless you have continuous monitoring unless you're able to demonstrate your compliance or your security risk posture.
Or the continuous basis, you know wake me up at three three in the morning on Saturday and tell me and ask me. What do we stand, you know kind of like classic commercial, you know, it's 10 pm. Do you know where your kids are?
Well, it's any time of the day 24/7 doing way of controls are most people don't know the the instinct is to go back to the compliance report that could have been written six months ago with data from maybe two years before that. Right? So you have these kind of continue like these nesting dolls of uncertainty and at the core of it is well the broken model right will always look in there with you here, right?
So the idea is to really converge on the timeline. We don't accept that retractic timescale in security operations. We've never would right.
We need to know what's going on right now. Plus we got thread Intel. We're trying to be predictive about things.
We actually trying to look into the future again. Our company's actually named for that. Right but traditional compliance to operate on that on that historic time scale.
So if we can converge on that point we say look when you need to be real time. We demand that from everyone from Ours from our program from our leadership from everybody who plays in the compliance ecosystem and from Vendors to supply these Solutions. That's the binary thing.
I want this to be real time. Can I get compliance real time? Because data becomes a true tool of risk management and that's what we haven't had traditionally in this industry.
So I think that's a different way to think about things. I think it enables you to actually go out and become more insurable. I think it increases your trust for your brand.
I think increases your reputation. I think it protects it and ultimately everybody wants to answer transparency. I mean, you've got regulars like FTC who are swinging that enforcement have a pretty pretty heavily and what we seeing most recently the xco of drizzly.
Alcohol delivery company right that required by Uber. They had a breach before they got acquired. She's long gone from Grizzly.
They got bought out. He's gone. He now has an FTC consent decree in his own name.
The last time they tried to do that was against Mark Zuckerberg when he tried to buy a VR company in his own name and they said they had it anti-cantative, you know Monopoly issues. So they said you can buy it but you go on there to create he said no, we'll buy it through matter. This poor guy now has to live probably for the next five years with a personal consent order from the FTC meaning any work.
He goes by the way, not a ciso a CEO anywhere he goes he has to create a program that's up to the snap to Snuff according to the FTC. So they're always in in that boardroom with him creating a security program and managing basically hand-to-hand with him. So that's that's what we're moving towards I think and again the the question is well, how do you demonstrate that?
You are credibly reporting things that are truly happening like where's the ground truth? How do you define it and it can be opinion and I think people are coming more and more become more and more aware of the fact that most of this stuff. It's just opinions, you know, maybe they're expert opinions but opinions nonetheless.
So yeah, I think insurability is a big concern and if companies continue to treat risk as something they can just offload. It can be just as nebulous thing. You can just throw it out the window and go well just deal with that, right, you know, which is upload that risk.
It has to be Quantified and there was no way to do it unless you have true transparency and true understanding of your security and responsure. All right. Thanks.
Well, you're in here compliance is a little bit of a racket and you may have suspected that all along but hey, there's hope right someday things will get better Igor. Thanks for being on the show. Thank you for having me.
Thanks Mike. All right back to you guys in the studio.