Agnostic Advisory – Mathieu Gorge, VigiTrust
VigiTrust CEO Mathieu Gorge explains why the company has created an agnostic advisory board to wrestle with the major cybersecurity issues of the day.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Matthew gorging who is CEO for vigitrust? And they have put together as massive Advisory board. And the idea here is to tackle some of the more pressing issues in cybersecurity Matthew welcome.
Thank you very much delighted to be here. There are a lot of advisory Boards out there addressing cyber security. So what makes this one different and what are the goals and ambitions?
Yeah, so the reason why this one is different is because it's aimed at addressing one key topic, which is that if you do your job as a ceto or as a risk manager the right way. Nobody knows your name, whereas if something goes wrong, you become Public Enemy Number One within minutes. And so, you know about 10 12 years ago.
I started thinking about getting cisos together and getting people that were in charge of risk together in a judgment free area where in an environment where we could talk about what works but also what doesn't work. So you're right. There are a lot of very good platforms out there and some of which we work with like I I see Square I say AP another platforms most of them though focusing on best practices.
Writing you with guidance that's been written by experts and so on the vijitrust global Advisory Board doesn't actually do that. It's more like an experience sharing an opinion sharing a platform where we bring together generally speaking a board of directors sea level folks. So cisos Chiefs Chief risk officers Chief legal offices Chief learning officers and law enforcement FBI Interpol French police Irish police UK police NYPD and a few others as well as Academia.
So we like to think that we bring all of the stakeholders together as opposed to other platforms that are very good in their own right but focus on assessors or Auditors or technical people. And what exactly is busy trust? I don't think people are familiar with you guys.
So where do you fit in this role? Yes. So VG trust from a commercial entity perspective is an organization that's been in that's been going for nearly 20 years and the first 15 years of the business.
We were essentially security assessors and trainers in and around 2012. We started productizing our training into a new learning offering and then 2017 2018. We we pivoted the business into what it is today, which is a provider of SAS based governance race compliance solution.
So we've got an award-winning tool called Beijing one which allows our clients to prepare for validate and manage continuous compliance with about a hundred security Frameworks. The The Advisory Board is part of the group of companies are under the VG trust umbrella, but it's It's an independent think tank in that there's no commercial agenda with it with nothing to sell. And in fact membership of The Advisory Board is completely free and so far we've managed to remain Vander agnostic.
Now that said, we we have some Innovation Chief Innovation people research people from vendors that come in and talk about what we do research on but it's not a commercial platform to sell firewalls GRC training or anything like that. So what's your sense so far as and there are a lot of issues out there. But what is the one or two things that are keeping cybersecurity people up at night.
What's the primary thing that they're really focused on versus all the long list of things that they can be focused on. Yeah, I mean if they start looking at everything they'll never sleep. But the reality is that right now there's five or six key topics that I matter to to our members and I would say to the security people generally speaking.
So the first one is the evolution of standards and regulation. So 2022 is very busy year for that with PCI for good zero the update to the Indian data protection bill with the UK going. It's on Direction and and completely changing the UK gdpr and which is moving away from mainstream gdpr and and I asked to for instance and then in in the US a number of executive orders and build that is about to be discussed around Federal privacy.
So there's a very busy environment the second thing that keeps people awake. I think is run somewhere because of what's Happening. And over the last the last few years and because of the fact that ransomware attacks, unfortunately still come through.
Very standard vectors, like fishing social engineering and so on and and result in in attacks becoming much more personal in terms of the impact. So yes, you know, you look at Colonial pipeline where they're not hacking private citizens, but there is an impact on access to energy you look at the health service executive in Ireland. They are not hacking your local GP, but they your local medical practitioner, but they they are hacking the hospitals meaning that you can't actually get access to care.
So the impact is is very much personal the other thing that obviously we have to talk about the elephant in the room here and and it's the geopolitical changes that are being started because of Russia invading Ukraine. So, you know if you look at data made Public by companies like crowdstrike, we can see that there was a lot of cyber attacks against Ukraine from Russia in the months leading up to the physical attack and to some extent. You know having that information it was quite clear that there was an extreme likelihood of a physical attack.
What's now very clear is that any country or organization that publicly makes it clear that they're against Russia is opening itself to a lot more attacks for the second half of 2022 and 2023 and primarily with with ransomware. So we also have that you know that complex geopolitical ecosystem. That's affecting everybody worldwide.
And that's that's one thing that we discussed it. The next topic I think is the talents skills Gap and the shortage in talent in cyber. Which kind of goes together with diversity and inclusion in cyber, so, you know according to different surveys we went from having 11% women in cyber three to four years ago to about 24 percent and in the last studies published at the end of last year, which is good progress, but it's still not enough.
I know so from a cultural diversity. We're seeing that the cyber security groups tend to don't mix cultures. And so if we are not mixing cultures, we're not mixing experience.
We're not mixing ways to deal with stress and to deal with crisis. And again, we're missing out on on opportunity. So, you know, we talk about all of us topics another couple of topics that are very big at the moment would be collaboration between low enforcement and the private sector which of course you need to Foster those relationships before you have.
Students because once you have the incident, it's a little bit too late. And again, you're missing out on opportunities to understand how they work and they are missing out an opportunities to understand how your business works and then finally visit protection of the most vulnerable on the on the internet and generally speaking we talk about young people but one one area within the demographics where we need to do a lot more East for the much older generation that are being targeted and that are trying their best to stay in touch with technology, but yet don't understand the risks. Do you guys think that this is a battle that can ultimately be one or is a matter of endurance and perseverance, but we'll never actually win it.
It's just about minimizing our losses. So, you know, there's a saying in the industry that says that there's only two types of companies those that have been hacked and those that don't know that they've been hot. There's also a lot of talk about the fact that security from from industry and government perspective.
We need to get it right all the time. Whereas the the bad guys only need to get it right once and one of the things that we need to understand is that the skills level of attackers is actually going down. They don't actually need to be computer gurus in order to launch around somewhere attack.
They can actually buy it as a service on the dark web. And so what that means is that somebody with with bad intentions doesn't need to be a computer geek in order to attack you on the other hand from the other side the large organization has a huge risk surface and Need the best technology the best people and the best processes in order to to minimize that risk. Can you minimize the risk 100% absolutely not.
There's no silver bullets. If you want to do business with the outside world, you have to open up. The question is how much do you open up and to what level and so you'll always end up with a residual risk?
There's only a few things you can do with risk generally speaking. You can ignore risk which you should never do. You can try and transfer risk, which you can do to an extent operationally and potentially by getting cyber Insurance.
Although that's another topic. It's getting harder to get it what you can't do is offload the legal responsibility of that risk. So the only solution you have is really to mitigate the risk to your level that's acceptable to your organization and that depends really on the boards appetite for risk with regards to cyber.
Do you think as we go forward that AI will help level the playing field a little bit for these folks or is there just too much hype around it, but it doesn't really deliver on the promise. So today it's it's embryonic. So it's not exactly delivering on on the promise just yet.
There are some very interesting proofs of concept going out there going on out there one one thing that's for sure is that if you use AI to try and second-guess or to try and and preempt the attacks, you can do it faster than you do today. The challenge though is that AI is also being used by attackers to try and map out the vulnerabilities a little bit quicker. So it's kind of a cast and my skin and for now, I think the jury is out the other issue.
Is that AI? Is not regulated well generally speaking not regulated. There are a few standards out there.
There's some again some initial regulation in in various parts of the world, but it's all based on ethical use of AI and it's based on data privacy and data concerns. It's not actually based on the value out of AI for the cyber security industry to to stop attacks. And that's one thing that as Security Professionals.
We need to push to government. Do you think that we need to collectively ban together more than we do. It seems like the bad guys share a lot more knowledge than we do in the good guy side of the equation, but it's part of this issue here that we need to find a way to combine or Investments because otherwise we're involved in this.
cybersecurity arms race and no individual company on its own can sustain Yeah, and and you're right. There's a feeling out there that the bad guy is collaborate a lot better than we do and you know, there's also a name and shame culture or this company got hacked. The Cecil wasn't doing their job correctly.
They didn't take security seriously, but but at the end of the day, I think that we need to collaborate like for instance the the VG trust Global Advisory board has Partnerships with various chapters Issa chapters, and so on the what we need to do is we we need to remove the stigma of being hacked is a failure. Of course. It's a failure something failed somewhere whether it was a process whether it was a technical solution not in place or not configured the right way human or human error, but it call it could also be zero day attack.
Seriously could not have been stopped because it was brand new and so where I think that we also need to make an effort is in how we deal with crisis. There's always going to be a new type of attack because we keep augmenting the risk surface. Right?
So the Internet of Things is a great example of that right now on you you probably have two to three connected devices when you go home, you'll probably have 15 to 20 and so you you've built your own infrastructure and it has its own critical components. So now as a as a bad actor I can hack into your home if it's not protected and use that piggyback on your on your company laptop and then go back into the company, whereas before I would have had to literally know where that laptop was or where where to send the the attack. So we're making it.
We're making it easier right for bad guys. And so we all need to work together. I think that there's also a Response a collective responsibility right from businesses and governments to provide job public that's working for them or that's a citizen in their City to to be more security aware, you know, you can't drive without a driver's license.
Why should you use the free connectivity in my city? if you're not gonna take it seriously and you're not going to behave properly and you're not gonna protect the devices, you know that there's a there's a school of thought that says that We need to empower the citizens to make the right decisions from a business perspective. You know, we see that a year after year on two occasions in October for cyber awareness month and in January for Global privacy day where companies really try to push out their security message to very employees and that's great and that's very commendable and it should be done.
However, it should also be done with the what's in it for me for the employee because if you say to them, I'm gonna Empower you to protect your own infrastructure at home your own connected infrastructure. Then when we're when we're home and we use their connected devices, they're going to be more secure and therefore when we go back to the office, we'll be more secure and it kind of snowballs into that kind of responsibility or where awareness around security and I think we have secured as Security Professionals have to impart that knowledge to the board and the Board needs to sponsor those initiatives so that we can all work together. hmm ultimately in almost sounds like it's not so much that we're losing because of the tools and advances in technology, but rather just the attack surface has gotten too big to defend and so maybe we need to look at how we're applying it as much as how we're securing.
Are you right? I mean, I often talk about ecosystem diagrams and people ask me Matthew. What's it what's an ecosystem diagram what's difference with a network diagram and I say to them.
Well a network diagram is a diagram technical diagram that shows you your your logical and your hardware and network assets within your your environment an ecosystem diagram is showing you where you do business. And with whom now, once you map besides you can say I'm exchanging data from that area to that area. It's encrypted.
It's not I'm using multi-factor authentication. I'm using ideas IPS or whatever, but I can't protect something. I'm not aware of so I need to map my ecosystem at home at work in a city at a state level at a national level and also International level and and as we we keep extending that risk surface.
We also need to extend the process to to secure it. And so what I mean by that is that you you really need to ensure that you use technology the right way. I often offend technical people by saying that the technical parts of of security is the easiest thing to sort out because the technology is here.
We just need to configure it the right way and very often it's a human problem or it's a policy problem. But I I also think we need to recognize that as population grows more and more people are on the internet. And as we have less and less on banked people more and more people do online banking.
So all of that risk surface is going to continue to grow where we can win the race. I believe is by continuing to educate people and in really needs to start from the board level. You need the board to invite to see souls and the compliance people to the broad meetings on a regular basis.
You need them to allow security people to translate cybersecurity risks into business risks because boards they deal with risks every day Financial Risk HR growth tax legal cyber is just an additional risk. It's not that we don't want to deal with it. It's mostly that.
We don't translate it into business discussion. I guess in some cases we are still our own worst enemies. Hey Matthew.
Thank you for being on the show. Thank you very much for having me really appreciate it. All right back to you guys in the studio.