Challenges of New SEC Cybersecurity Rules with Nozomi Networks’ Edgard Capdevielle
The SEC cybersecurity rules went into effect on Dec. 15, and those most involved in the disclosure process – CFOs, boards and even many CISOs – don’t know enough about their organizations’ operational technology networks powering the connected machinery that play a critical role in the health and safety of the general public. Public organizations with these types of networks (airports, manufacturing, healthcare, utilities, oil & gas, etc) face a nearly impossible task when it’s time to accurately disclose material business risk or properly report an incident once it happens, especially as the SEC suit against SolarWinds sends a strong message that they intend to hold companies accountable.
Transcript
This is Textron tv. Hi everyone. Welcome back here to the Textron TV desk.
Um, I'm happy to be joined. Well, it's another first time person on our show here today. His name is Edgar Capel.
Cap. Cap, the vl. I do my Best.
It You got it. All right. Uh, Edgard is the CEO of Niomi Networks, and he's gonna tell us about that in a second.
But let's first welcome him Edgard. Welcome, and thanks for joining us here. It's a pleasure to be here, Alan.
Thank you for the invite. My pleasure. So, Edgard, before we even get into the zomi and what we want to talk about, let's hear a little bit about you, right?
I mean, we know you're the CEO here, but kind of give us your journey. Absolutely. I've been, I, I grew up, I guess, in technology through the product management ranks.
I've done a little bit of everything, uh, from Wayne optimization to storage, deduplication with data domain, uh, storage networking with Macata and brocade Cloud storage. I've done a little bit of everything. I transitioned into security with my last gig.
I was the VP of products at Imperva a while back. Mm-Hmm. And I've been the CEO at ZO Networks dealing with industrial cybersecurity and protecting our critical infrastructure for the last seven years.
It's been a, it's been a great journey and, uh, I am happy to say that this is the best job I've ever had. Excellent man. And that's the way it should be.
'cause if you gotta go to work every day, it sucks. Right? If, if you love what you're doing, life's a pleasure.
You know, you mentioned mcd and some of the ADE and some of the old storage stuff back. Uh, I, I had started, helped start some companies in Boulder, Colorado back in the early two thousands. And that was kind of the tail end of that whole storage industry out there, like near Interlochen, right.
Uh, there was mc, Datar and, and, uh, storage tech and, you know, and then poof, one day they all seemed to got bought or, you know, consolidated and it was gone. Um, cra crazy times back then. Actually, that's an very interesting theme.
Uh, I think, uh, in all networking, there is a movie that is playing all the time, and that movie is called Convergence. Yeah. And that movie is the biggest destruction and value generation engine that we have.
You may go back all the way to telephony when we had switch networks and Avaya, Ericsson and Nortel the World, and then we converged, and you saw the same thing that happened in, in Broomfield, Colorado, where you had the storage unit of HP Sun Microsystem Storage Unit, SDK MAG Data, everybody was there. And then convergence happened. We stock topic about, you know, frames and, and fiber channel, and all of a sudden we converge into ip.
And guess what? Cisco one, and no, there is no standalone company in storage networking. Similarly in the world of industrials.
We used to have something called industrial networking. And that, that, that part of the convergence already happened. Our world is converging, and that's one of the big themes that Nazomi networks.
Excellent. I love it. Let's, let's talk a little bit about nazomi.
Seven years. You are there. Um, you know, some of our audiences has have heard of it, some may have heard of it, but let's set the record straight at guard.
What, what is nazomi and what do you guys do? Yeah. From a network point of view, we, we see the world as, as, as you know, separated by the different kinds of networks.
Most folks in their lifetimes. And that includes me prior to noomi, have only dealt with IT networks, everything that, you know, is an IT network. And, and now we are addressing, uh, this market called ot.
Uh, OT networks are very, very specific. They are the networks that are, that are created with a single purpose of supporting the automation of a physical process. And, and, you know, IT networks deal with bits and bytes and transactions and applications and browsing and Netflix watching OT networks deal with, again, supporting a physical process where atoms get moved or transform.
So I'm talking about the generation of electricity, the refining of oil, the movement of people, the movement of machinery, um, conveyor belts, manufacturing. Um, so the endpoints are, are PLC or dcss. Again, endpoints that support automation with these are types of networks are, are everywhere.
I mean, until you get into this market, you, you, you know, they're invisible to you. But then once you take the red pill and join the, the industrial world, then you start seeing electrical substations and gas substations and water substations all over the place. And then you realize that when you go into manufacturing sites or an oil refinery or an airport or your local metro, everything is automated.
And, and industrial control networks really protect critical infrastructure. One of the key things is that IT solutions and IT security cannot come in and be applied to the world of ot. Again, because of that technical reason, and a lot of solutions are now OT centric, we are, um, a pioneer and a leader in industrial cybersecurity, protecting critical infrastructure and the networks that support it.
Love it. Thank you for that. So, you know, Edgar, I, I've been in security myself 20, 25 years.
Um, and, and I, I, what, what's the word? I've evolved my position on the government being involved in, you know, being the rule setter, the, for in cybersecurity. I used to think that we were much better off as if industries would create their own kind of cybersecurity standards to keep the government out of it, right?
Because I just felt like the government could never really understand. They never got it right. The government isn't gonna do cybersecurity.
Right? They're not gonna, you know, you're gonna have some people who don't know anything about cyber making rules around cyber, and there's no way it could possibly work. But over the years, I've, I've come to the realization that it's such a big issue.
It's such a big problem. It's so critical, mission critical, especially when we talk at an industrial level that it takes the government to, to get, you know, have that big a hammer, to have that big a scope. You know, back when I was in security, I remember like FERC and nerc, I'm sure you're familiar with FERC and nerc, right?
And though that's not officially government, it is government, right? The government saying there, and that's regulating, uh, you know, uh, utility, electrical utilities, nuclear plants, stuff like that. Um, but in, so, but in spite of me recognizing that, yeah, we probably do need the government to get involved here, at least in the us you know, we've had a very much a patchwork approach.
California did their thing, this state did their thing. New York did their thing, but we haven't had a federal kind of presence on it, whereas opposed in Europe, right? The EU seems to have their act a little bit better together in, in tating some real rules around cybersecurity, around personal information, PII and stuff like that.
However, the SEC right has now come out, and I don't know if any of us saw it coming, has come out with some cybersecurity rules and just to drive that point home, right? We got a ciso, uh, a CISO in trouble, right? A CISO named, specifically named the CISO in the suit, called him out, which, you know, for many of my CISO friends are scared to death over this.
Who the heck wants that job anymore? But you know, you, you know more about it than me. What do you think?
I I think you, you touched on a very broad topic. So listen, I think you and I are, are births birds of a feather. Uh, from that perspective, I am a huge Adam Smith follower.
I believe the invisible hand is very powerful. Uh, but I think sometimes the invisible hand takes a while to get to an optimal place. So we can start with a very simple model, you know, cars and seat belts.
Eventually the invisible hand would've gotten there. But we needed the government to put seat belts everywhere and keep us safe. Nobody can argue seat belts are a undue harm by the government.
Um, a little bit of a closer model where it's the same SEC applying Sarbanes Oxley, the invisible hand would've probably gotten to an optimal place eventually. But Sarbanes Oxley really advanced the protection of con of investors when it comes to financial oversight and financial fraud. We haven't had an Exxon Mobile since surveying Oxley, and it's been fantastic.
I think the government has had a good, um, fast forwarding of, of what the invisible hand was eventually going to do. And I think that same thing needs to apply with cyber securities. The SEC role is to protect investors.
And, and, and not everybody is aware. Investor retail investors specifically are not aware of this cybersecurity sophistication that is sometimes needed. Uh, and when you have, you know, I, I don't know that I can speak, um, on an educated way about specifics about the CISO at SolarWinds, but apparently, um, there was a lot of, um, there was a lack of, of sophistication, thoroughness, implementation.
Uh, it was a little bit of the wild West over there. And as a public company, if you are not careful about your cyber stance, you are affecting retail investors that are not able to, um, synthesize your cybersecurity stance and make a decision based on it. So I actually, I'm a big fan of what, um, the SEC is doing.
Um, I think it is going to accelerate what the invisible hand would've eventually done. Um, but again, I'm, I'm a Adam Smith fan. You've talked about the, the state of our electrical, um, fabric and compared to Europe.
I think on that side, I don't think we're doing the great things. I think, I think our electrical grids are unable to do investment pricing decisions by themselves. I think they're completely overregulated.
And I think the, you know, as a, the most developed nation in the world, uh, I don't think it's, we should be proud of the state of our electrical utility at all. No, I, I agree with you. And, and, and certainly there are some states that are worse than others when it comes to that.
Not naming names on Texas, but, you know, it's a whole, it's a mess there. You, I was at a, uh, you know, I was at a, a conference actually in Austin, Texas of all places this week, earlier this week, and there was A-A-C-M-O level discussion about, you know, when reporting to the board or reporting to regulatory agencies, when does, when does the C-level person have an obligation to sort of break with the CEO or break, you know, with, with the, with the rest of his C-level or their c your c-level peers, right? So, and it's, and this is directly to the cso, right?
So the CSO knows there's a problem and hey, we gotta disclose this, we gotta do, and the CEO and the CFO says, oh, no, wait, let's wait till after earnings, right? Or something like that. It's, it's a bad time to do it now.
And look, the CEO hired the ciso, right? There's a, there's a certain fieldy there, right? In terms of the pecking order.
At what point does the CISO say, no, I don't want to be the next SolarWind CISO named in this SECI wanna be able to work again at another public company, and I'm going to, I'm going to go public with this, whether you let me or not, or fire, and even if you fire me, do I still have a duty to go public with it? Right. It, it, it's a, it's a tough, It, it is, it is tough for CISOs.
I think, I think CISO is a role that, for the longest time has not been EE elevated to, to the right level. Um, it is sometimes two, three layers under the CEO and, uh, and again, as, as a, when you become a public company and then, and then the SEC has the responsibility to protect retail investors, um, you know, you need to create frameworks and, and, you know, in the case of the finance world, where, which again, against Sarbanes Oxley is really a good framework for what worked. Um, and then again, we need to think about how apply it to cyber and, and, you know, the s SEC is making its own decisions.
Um, in the case of, of finance, the CFO has specific duties. And, and those duties are to the board, not just to the CEO. They become fiduciary duties.
Uh, the CFO becomes an executive position, and, and the board specifically has a audit committee that has specific responsibilities. Um, they also have to pick a external firm to evaluate the work being done on the finance side. So, so you create a system of check and balances that is, is really, really good.
Um, in this first iteration of SEC cybersecurity rules, we haven't gotten to that extent. I think we're, we're just getting started, I think, I think notification and, and, you know, tell me what your cyber stance is, which are the two components of the current? Um, the current framework are, are I think the beginning, uh, today, boards don't have a cyber committee.
Um, there is no clear responsibility or competency level required at the board for discussing cyber. Um, but we may get there. And, um, and I think, um, I think the role of the CSSO needs to get, I don't know if elevated is the right word, but, but it needs to, from time to time, have a seat at the table.
I, I don't think we've gotten to the place of, you know, financial statements, but we need to understand, um, and, and be able to answer questions around the cyber stance of a company and specifically cyber incidents, uh, as soon as they are. Um, I think you talked a little bit about the point of materiality. When do we know if something happened becomes material?
And I think in the world of it, we have a lot of experience there. Um, and I think the best thing a CISO can do is get that documented ahead of time. The best everything that you can do about a cyber incident happens before the cyber incident.
If you're doing it because a cyber incident happened, you're playing decent in a bad way. Yeah. So for example, define materiality ahead of a cyber incident is what every smart CISO should be doing.
And when it applies to my world, I think it's actually a little easier. Critical systems, ot, the OT world is so critical, it's so fundamental for industrial companies that it's really hard to see how an OT incident wouldn't be material. So I think in the world of ot, just easier.
But in the world of it, the more work you do ahead of an incident, the better. Absolutely. Um, so what, look, people out here now, maybe working in public companies, what can they do to prepare Edgar, right?
Because as you said, I think in the, in the, in these situations, what is it? Uh, announce of preparation is worth a pound to cure, I think is the, the old, you know, saying, what can we do to prepare regarding these upcoming rules? I, uh, we have a little bit of a framework that is easy to digest.
We call it the pre breach mindset versus the post breach mindset. And, and you can see the pre pre-B breach mindset is what everybody has when they're having this conversation. And, you know, cybersecurity budgets are tight.
I don't know how much cybersecurity do I really need? Where is that ciso? And, and who does he report into, or he or she reports into?
Um, and then you can see the post breach mindset in the news, right? What happens when you have a breach and how important is cybersecurity that point, and, and how much budget do we have for cybersecurity? And who is the ciso and where is he or she, right?
The, the whole thing changes. So, listen, like anything in the world, the best thing from a mental preparation perspective would be if you can switch from a pre-B breach mindset to a post breach mindset without the breach, that would be fantastic. Humans have a hard time doing that.
But, but that would be fantastic. In terms of preparation, listen, there's a ton of systems. Understanding the criticality of your systems, for example, uh, resiliency becomes really, really important.
If something bad goes, you know, happens, um, can you come back? How quickly can you come back? And how much will you have forgotten?
Um, which are very traditional metrics in the world of disaster recovery, RPO and RTO, um, people e everybody in the world backed backs up their systems. 0%, almost 0% of the people practices a recovery. So why are you backing up if you've never practiced a recovery?
So practice a recovery. What happens if you get hit by a bus today? How quickly in what order can you recover your systems?
When was the last time you tested that? I don't wanna know how many backups you do daily, because doing backups without the ability to recovery is silly. Uh, similarly, do you have visibility across all your networks?
A lot of folks, um, a lot of CSOs and, and this is more applicable to the world of OT security. A lot of CSOs are inheriting this new responsibility of ot. They hardly understand it.
Um, and they don't have the proper visibility. They don't have the proper instrumentation. So be making sure that among all your children, from a CISO perspective, um, you understand all of them.
You have a good accountability of all of them. Uh, you have good visibility. Sorry, that's Alexa.
And, uh, and, uh, yeah. And you have a really good operational visibility, um, and cybersecurity mechanisms, multi-layered a across your entire infrastructure. Excellent.
Edgar, we're about outta time. For people maybe who want to follow along, find out more about Noomi Networks, what's the website? com.
com. com. Edgar, thank you for coming on to our show today.
I hope this won't, you know, this won't be the first and last time. We expect to hear you back here again and keep us posted and, and we're all gonna be watching, especially, look, we have a lot of friends out here who are CISOs or want to be CISOs. This is something that I, I think has to get on everybody's radar.
I hope to a second one. Thank you so much. Alrighty.
Ed Edgar Capal, uh, CEO Zomi Networks here on Tech Drunk tv. We're gonna take a break. We'll be back in a minute.