Changing World of CISOs – Mike Scott, Immuta
Mike Scott, CISO at Immuta, explores the changing landscape of challenges CISOs are facing increasing risk management, privacy, data security and regulatory-related workload. At the same time, CISOs are being held more accountable for the security actions or inactions taken by the business.
Transcript
This is techstrong tv. Well, I have the great pleasure of being joined by Mike Scott. Mike is ciso, chief Information Security Officer with Immuda.
Welcome Mike. Thank you. I'm glad to be here.
Really excited about our conversation today. You too. Great to have you here.
Uh, before we get going, tell us a little bit about yourself and tell us a little bit about auDA. Sure. Um, so I've been in the information technology and security space for over 25 years now.
So I'm dating myself a little bit, but, uh, primarily focused on security for about 18 of those. I've been the CISO at auDA for two years now. Um, it's been great to join a cloud native company.
Kind of a transition for me, uh, throughout my career. I've worked for some large hamburger companies, uh, technology companies, and really kind of started my career, uh, in the intelligence field in the military, uh, muta here, we, we really help customers unlock data. We're a data security platform.
Um, and probably the biggest thing that really I'm excited about is that, um, enabling our customers use a lot of the data that traditionally they have not been able to use to run their business. You know, my favorite use case here is unlocking HR data with a customer so they can start monitoring for attrition and look for trends, you know, and that data historically has been unavailable to them. Uh, so leveraging our platform and, and really being able to monitor and restrict access, um, down to a finite level where they can have the data they need at the time they need it, um, is really important.
It's been really exciting for me to be with an organization that's, you know, clearly in our space and serving our customers, but also working with data professionals over the last couple of years has been new for me and really had a chance to hear their problems. And it's funny, the exact same problems we face as CISOs, just a little different spin on, on how to solve them and why they need to solve them. Mm-hmm.
And security's such an important part of data, right? Absolutely. Understatement.
Well, let, let's talk a little bit and it's great that you've been, uh, you've been in security for, you know, for the time that you had cuz you've, yeah. Things have changed a lot in the security world. I was just doing a panel recently where someone says, you know, I, I remember when we couldn't even get attention of an executive and now every day our, our c e o security pops out of their mouth that it, it's security is on mind, is on the topic.
And we, we have access to, you know, business leaders all the way up, you know, on board levels, people sometimes too. Um, so we, we, we have a little bit more than a seat at the table. We really have some access we didn't have before, but our jobs change too.
It, it's not just the best technical person wins and rises to the top cuz it's not a, just a technical job anymore. I, I'd love to hear your perspective on that. Yeah, I, you know, I started my career as an engineer and, you know, found myself in the CISO role because I had a great understanding of a broad range of technologies and, and how to secure things within an organization.
But, you know, over the last 10 years I've really seen that evolution increase where, you know, now you really have to have a strong business acumen, uh, privacy compliance. And it's a, it's a much harder balance than it was even 10 years ago to secure an organization. I think really privacy and and regulations around that have really changed everything.
Um, and increased, like my day now is a lot of paperwork, a lot of contracts, um, a lot of interpretation of various international rules and regulations. Um, quite a big change from, from where I was at before. Yeah, it is, you think of the regulatory front.
We used to talk US regulatory regime, if you will. Now it's international, it's global, it's, you know, different and it, but it's also dnce between California and the rest of the country. Or, or, or, or, and I imagine, um, you work with customers probably US and North America, maybe beyond, right?
So you have to people location of data right. Is also an issue and local regulations. Yeah, absolutely.
I mean I, we do have the pleasure of working with a lot of international firms as well as us. And I think interesting is, you know, GDPR kind of got everyone excited years ago, but now to me looking at, you know, a lot of our state laws are really evolving to a point where, like you look at California where now there's gonna be rule making authority, you know, within that regulatory branch. And I think that is, is a really scary but um, interesting development.
You know, where before G P R came out and that's the way it is. You know, you look at C C P A and, and their new, uh, laws, now they're gonna be able to create new requirements on the fly and the same thing, um, and some of the other states. And that's really now making my role a lot more of having to interpret like how we use data.
Do we use data in the right way? Can we meet these state requirements, these international requirements? Um, and even federal requirements.
You know, I've been doing a lot of work recently with executive order 14 0 28. And when you look at how that's gonna roll downhill, it rolls into almost anyone because most of us have a public sector customer or you know, or a supported public sector customer. Um, and the complexity there, you know, it's almost this, this whole matrix type evaluation of data now, um, has definitely made the job, I would say more challenging because it's not, you know, just because you have an identity, you don't get access anymore.
Now we have to think about, you know, what's the proper usage of data and how do we stay in sync with all of these? And even more seeing how customers are really ramped up their, um, risk and security assessments of organizations like amu. You know, the, the, the phrase we used to say a lot, you know, six steps from Kevin Bacon we're, we're all maybe one or two steps away from someone in our customer chain who's supplying technology software to the federal government.
So if it's not on your doorstep, those requirements, it's only a step or two way or a contract two or away. Cuz they have to have it from you too, right? Yeah, I mean, you know, to me it is funny to see, you know, um, I think last year, uh, I might have spent two hours on average on customer risk assessments.
Um, and they were typically, you know, ca IQs from the Cloud Security Alliance or SIG Lights. Um, now we're getting much more in depth. I think the most complex one I did this year was about 32 hours of man hours.
Uh, it was, it was almost, it was almost intensive as our SOC two audit was. And that was for one customer. I think also we're seeing, uh, like we just completed our ISO 27,001 and 27 7 0 1 certifications because we saw that increase of, of, you know, scrutiny from those customers.
And what they're really looking for and what they need to, to enable their business is really starting to drive, you know, compliance to be an enabler. Which is kind of kind of funny. Most organizations I've been at, compliance has been a mandated requirement cause we processed credit cards or we did various things in the financial industry.
But now almost every industry is seeing that, you know, to be competitive, you've gotta be able to demonstrate that you have the ability to secure the data you work with. Yeah. I think it's almost like security.
We, we used to think of those things as cost of doing business. Now it's not only required to to do business, but your ability to respond with that information demonstrated, attest ATS to it, et cetera. I mean, the next guy might be, you know, a week away from doing it and you've got, you've got it locked and loaded to give it to customers, you know, you're not too far away.
Yeah, absolutely. It's funny, we did some, uh, research recently and saw that about, um, 58% of data is used when an organization makes a decision. So when you think they have a hundred percent of their data on site or in the cloud and only having access to a little over half of it in the decision making process, you know, that's a real problem.
You know, when you think the money and the time we've invested in building these really, um, massive data structures and really making sure we had great quality data. You know, 10 years ago that was our problem, right? With, with BI and big data was we had terrible data.
Now we have great data, but we're struggling on how can we use it ethically and legally to make better business decisions. So it's absolutely, um, security and privacy is about agility and about being able to quickly get that trust and, and get the customer moving in the right direction. And think about the, I mean, I have to tell you, but the, uh, proliferation of where data lives and how it is created, whether it's sensor data that's, you know, maybe part of a, uh, some kind of a IOT solution or, or you know, could be sim we have sensors on everything, right?
Could be your charging station in people's homes or whatever it might be that your business is. But it's also, um, you know, we're almost in the kind of pop-up restaurant era of data, right? I have an app, I do a serverless app on this cloud provider and it's there, and then maybe the app goes away, maybe the data doesn't.
So, so understanding that changing environment and where it is, how long it lives and what you need to do to, to manage it, secure it, it's, it's, it's not, it's more than moving target. It's kind of an evolving system. Yeah.
It it, it makes our reliance on our end users and our, our data professionals, uh, to understand security and privacy even higher. Cuz you're absolutely right. You know, it's, um, I think interesting for me when I talk to some of the data, um, officers at some Fortune 500 companies to hear that, you know, moving a terabyte of data by an individual user is, is just very common to them.
You know, and you think about you and I, if, if, if you moved to terabyte of data 10 years ago, you know, security would've been at your door going, what are you doing? What are you, what's going on here? And now this is part of a business process and you know, cloud solutions have absolutely made it so easy for people to stand up and instance copy data in and then, you know, we didn't even bring up chat G P T and, and those type things.
Uh, the user and data community, we really have to get better in sync with, you know, what are the rules of the road and how do we do this and do it in a safe way has definitely made the challenge. Um, it feels insurmountable at sometimes, but mm-hmm. Luckily, I think we'll get there with the right tools and stuff, but absolutely a higher risk, you know, for me the cloud has been a great enabler as a ciso, but it's also what keeps me up at night.
Mm-hmm. I remember the days of moving to a hosting or even early cloud, sending 'em drives of data, right? Because you couldn't ship that much data over a connection, not in the time it took to do your migration.
That obviously has changed. Um, I'd love to get your perspective, um, on the kind of business part of the role of the CISO and maybe even for you personally, how that's been in the translation where transformation of your job over time. It could be communicating with senior executives and business leaders across the company and now you need to kind of understand the business, right?
And be able to speak in terms that you're not gonna make, you know, nobody likes to feel stupid, especially your boss or leaders in the company, right? So you have to be able to talk about security in ways that are, are helpful in informing them not driving a, a wedge between that connection. You've got to 'em now.
Yeah. You know, the, the worst thing you wanna be is the department of no. Right.
Um, I think there's been a lot of CISOs in the past that were guilty of that and I think we've kind of evolved past that. But, you know, there's, there's no zero risk decision. And I think as CISOs, a lot of times we had the luxury in the past, he made him to say no because there wasn't demonstrated value to doing something versus now I spend a lot of time working with either, you know, our executives or our customers talking through what's the right risk decision.
And there's a lot of stress and anxiety that can come with that for security leaders when you're, you know, you're going, okay, you know, the, the perfect answer is X, but we really need to do y for the business and we need to take a little bit of risk and look at, you know, how's our insurance gonna cover this? Um, how are we going to react if there's a negative outcome? But also knowing that, um, especially in a muted space, you know, we're a, we're a startup and, and a data security world that's rapidly evolving.
We have to deliver solutions quickly and we have to deliver features quickly. And it, it's a balancing act and it's definitely something that is a lot harder for, for the technical, technical side of our profession to really understand, you know, we can't just say no, we have to really work with the business and make the best educated decision we can make. Now is your company a hundred percent cloud based to be in a kind of newer company or Yes.
Do you still live in a hybrid world? Uh, a hundred percent cloud native, which has honestly been an amazing, it's a, it is a godsend really. You know, I spent years on stages talking about the need to switch to the cloud and what the cloud was gonna do for us.
But the agility and the ability to be able to modernize a system and do something quickly is, is really been refreshing. And especially when you're at a company that has security culture. And I think that is the challenge there is if you're moving to the cloud or cloud native security has to be ingrained in the rest of the business.
Cuz to your point earlier, when I have a discussion with an executive, I need them to have at least some sense of accountability for the decision we're making. And luckily I have seen that evolution on the business side pick up as well. But, um, yeah, it's, it's a never ending challenge, which I guess is what keeps our job interesting.
Yeah. If it wasn't, yeah, we'd be doing the same old stuff. Um, I'm curious for you, and I've talked with other CISOs about this, th this transition to living in a software world, right?
Where it's a software driven, you know, it's more than just the strategy the company's built on, you know, the software capabilities, uh, that are provided through your technology and your services. Um, how do you see that's changed for data people, for people that are in data roles or securing data? Now we talk about things like DevOps and pipelines and continuous integration and deployment and DevSecOps and, you know, terms that we wouldn't have necessarily talked about with, with CISOs or security people 10, 15 years ago.
Yeah, I, you know, it's funny as you know, all of those things really drive the need for agility and that can be difficult sometimes. You know, we've historically would love to do a full risk assessment and really spend some time researching, you know, what the possible impacts could be. And, and that's just not possible, you know?
And so we have to apply agile security just like we do in development. Um, some of the things that I've really seen work well is enabling the rest of the team. You know, it's something we have here.
I have a small team at auDA, but the rest of the engineering team, including development's very bought in. And so as we've been able to shift security into that DevSecOps, you know, where we're actually continually hardening our containers, we're always patching and we're always doing things, um, it's been a great benefit, but that's really a cultural requirement. You know, I've been in organizations before where we tried this and it failed miserably because, you know, I can't make the software more secure.
I need the engineer to make it more secure and I need that person's manager or supervisor to also give that time up. Um, but what we have seen is, you know, because we do apply, you know, all of our security in an environment here is those small incremental changes add up quickly. And the more you get into practice of it, uh, what I love seeing now is I see my teams coming to me with, Hey, we've made, we're gonna make this change or we're gonna change the product in a way where we don't get that data anymore.
And that's really exciting. But it is, it's, it's been two years in the making here and I've done it other places, but it requires the entire company really to understand or at least trust my judgment. Mm-hmm.
And I think the other important part there is as business professionals, we have to earn that trust and it's best done when the business actually believes that I understand their problem and that I care about their problem more than mine. It's like, we need to solve a business problem, I'm gonna help you do it securely, but the business problem is really the most important thing. So, kinda last, I'd love to talk with you more.
Matter of fact, we have some events that come up you would be perfect for. Um, so the la last thought, I'm curious for you in your career, uh, in security and as a ciso, how much if you had to, to take on in learning about how software is created in, in like DevOps world, how cloud native microservices and Kubernetes and containers and all those things we gotta secure now that are a part of the, the threat landscape. How much about those technologies have you had to come up to speed on or have you been able to kind of cross the chasm if, if you will, um, maybe it's not a big chasm at at at this company, uh, through working together with people Or do you feel like you've had to kind of really become somewhat ex of an expert in that side of the business?
A absolutely. Um, you know, when I came here we're, we use Kubernetes heavily in our product and it's, it's unlike any other, you know, virtual operating system or you know, our old, you know, rack 'em and stack Steinham hardware. The concepts are quite a bit different.
And not only did I have to understand it from my role just to make good security decisions, but I needed to develop some level of mastery so that my customers trust when we're having this conversation. Uh, Kubernetes is, is an interesting animal where you can have a vulnerability that's not exploitable versus in a traditional virtualized operating system that doesn't exist. And even for me, it took some time to get that confidence that I believed it, right?
I've got my engineers saying, this is how it works, I'll trust but verify. Um, so it is been a learning curve for me, but it's been, it's been an exciting one and the more I've really understood it and and developed that trust with the team, the more I've understood what we could do. But yeah, the cloud is, is a entirely different journey and I think CISOs have to spend some time understanding, especially Kubernetes, cuz it's not going away.
Oh, no, no. It's seems to be accelerating. It's on the, the end of the hockey, hockey step, at least curve.
Well, it's been fascinating to talk with you, Mike. I really appreciate it. Um, and it's great to, uh, you know, it's always fun to talk with people about wherever they are in their career and if they're now living in sort of cloud native land or they're trying to, you know, wrestle with some of both.
And I think those, sharing those experiences helps everybody with how to tackle, you know, a very changing, uh, very changing landscape of security and challenges and regulatory and all the things we've talked about. So, wish you the best and hope you'll come back. We'd love to talk to you again.
Absolutely. Anytime. I really appreciate it.
Thank you. Have a great day. Absolutely.
com who is the data security company. Um, have a lot of great offerings for you to, to look into. Thanks for joining and come back soon.
Thank you.