CISO Challenges in Cybersecurity Risk Assessment with IANS’s Nick Kakolowski
Nick Kakolowski, research director for IANS Research, discusses the challenges CISO are facing as organizations focus more on evaluating cybersecurity risk.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nick Klowski, who's research director for Ian's Research and we're talking about a new report they have out on the state of the CSO mind as it were.
Hey Nick, welcome to the show. Thanks Michael. It's great to be here.
So this report kind of suggests that uh, the role of the CISO is fundamentally changing. We want them all to have a little more business acumen maybe, but we're also seeing that they're being held more accountable for things that may be outside of their control. So based on the research, what's your sense of the mood of the average CISO these days?
Yeah, it, it's a tricky situation. A lot of CISOs, you know, we've seen this trend gradually building of CISOs getting pulled more into business operations, getting pulled more into board respon board level conversations and executive conversations and really needing to start becoming really business risk owners. Not just, you know, technical folks and CISOs are feeling the pressure now that that's happening much faster than initially.
You know, it was kind of a gradual curve for a while and now it's escalated and CISOs are feeling the pressure. It seems like they have wanted the seat at the table for a very long time. But now that they're there, they're kind of discovering that the folks who sit around that table with them don't speak cybersecurity.
They speak in terms of finance and risk. So do the security folks need to learn a whole new vocabulary? I think they're already doing that.
It's, we've been seeing it over the past few years. CSOs are working a lot to develop that vocabulary and work on speaking finance and risk. The key is finding that common ground, that middle area where they can help the business leaders understand enough of the technology to make governance decisions and contribute to those risk conversations without actually pulling those business leaders all the way into the tech side and being able to kind of translate those tech conversations into the business language.
Do you think they're finding it surprising that a lot of business leaders have a large appetite for risk? And I asked the question 'cause they all went to business school where they were taught to manage risk and they will look at the upside of something such as the revenue potential for and the profit and decide that a lot of times the cybersecurity issues are well worth the risk. So are security people kinda in for maybe a shock to the system?
I don't know if that's so much where the shock is that, you know, the more CISOs I talk to, if they're confident that the business leaders understand the risk adequately and are making an informed choice, they're okay with the business leaders, you know, making those choices. The real problem is CISOs being afraid that the business leaders don't properly understand the situation and are trying to accelerate the conversation and get to a decision that they're not quite ready for. And that eventually something goes sideways and the CISOs are gonna get scapegoated for it.
You know, back like we saw in the early days of breaches where every time there's a breach the CISO is getting fired right away. 'cause the business is like, wait, how did this happen? This should be easy.
But now the business knows it's not easy, but they also don't really know how to actually deal with how complex it is yet And who should be responsible for security. We have seen some court cases involving CISOs that have left people scratching their heads in many cases, and I'm asking this question because when your house burns down, the town doesn't fire the head of the fire department. So why should we be firing the head of security when generally speaking it was somebody else's fault anyway.
Well, and exactly it's gotta be a shared ownership model. The business really has to come together and figure out who owns which risk, who's responsible for determining level of acceptance of that risk, and then what's the plan to resolve and mitigate it so that all the stakeholders involved. 'cause it's never gonna be just security, it's never gonna be just tech, it's never gonna be just the business unit.
It's everyone from the board down's gonna have an influence on those risk decisions. And it's gotta be a documented shared model of this is what we understand the risk to be. This is how we believe we're gonna address it.
This is who's responsible for addressing different parts of it and this is what we're gonna do if something goes wrong. How do we assess risk when it comes to cybersecurity? Because I think a lot of folks are talking about this and almost every vendor I talk to has got some new platform that's aimed at addressing this particular issue.
But um, where does that conversation start in a way that is generates something that's a real assessment, Right? So you're poking at something that folks might not all wanna have poked at here. This is bringing us a little bit back to some of those risk quantification conversations we were having a few years ago where risk quantification got big and then everyone wanted to do it and then we realized, wait a minute, it's way too complex and way too laborious to actually sit here and quantify cyber risk.
There's now another move to kind of revisit risk quantification a little bit, but just to do it differently to kind of figure out how we can more accurately ballpark what cyber risk looks like in terms of financial terms and kind of relate it to comparable business risk so that orgs can figure out what are our materiality thresholds, what kind of dollar amount risk are we willing to take? And while it's never gonna be a direct one for one quantification and translation of risk, figuring out a shorthand that works within your specific organization is becoming really a critical thing for CISOs. I think when I've talked to some of the business folks, there's a sense of, shall we say frustration and the source of this frustration is they're investing in cybersecurity but they don't know if the organization is any more or less secure as a result of those investments.
So, um, what exactly are they looking for from cybersecurity and is this just kind of a, a knee-jerk reaction to increased costs? I don't know if it's so much a knee-jerk reaction to initial costs as it is an initial process of becoming aware that the way the business has looked at cyber is not nearly as mature as the way they look at other forms of risk as speaking with some CFOs. Because one of the things we're realizing coming outta this is what's going on with CISOs right now isn't all that different than what CFOs had to go through when SOX are.
But when SOX came around years ago and talk about how CFOs go through financial audits, they're dealing with lots of fuzzy data, they're doing lots of forecasting. How are CFOs gonna forecast adequately when there's lots of gray area there similar to what we see in cyber. And CFOs have budgets for quarterly audits, they have huge budgets to bring in consulting firms and get third party perspectives on what that financial risk is.
We just don't see, so see CISOs getting the budget and resources to do that yet. And we expect there to be a gradual move toward more ways for CIS for CISOs to get support both within the org and with third parties to help validate and assess where the org is and ensure that what the CISOs are reporting up to the rest of the business can be considered sufficiently accurate and informative to help shareholders understand the state of security in the org and help business leaders and board members figure out how to govern that risk. It also seems to me that business leaders are assuming that the risks are somewhat static as they might be in other aspects of the business, but uh, the trouble with cybersecurity is there are these people called, you know, bad guys and they are adjusting their tactics and techniques all the time.
And the minute we shut one down, they add up another. So, you know, do business people really understand what's involved in the platforms and tools required to combat those threats that are constantly evolving? And I think that's really the critical next step for CISOs.
That's the, the level of informing and educating business leaders that CISOs are starting to explore and are really able to solve is bringing them into understand that, you know, improving maturity is one thing but the attackers are always gonna move the mark. They're always gonna move what good looks like and just 'cause we're good but six months ago doesn't mean we're good now and how we invest and how we grow our programs. It just has to be constantly adaptable.
What's your assessment of the impact that AI might have on this whole process? 'cause I can imagine a world where I am just giving somebody a chat interface and they can say, you know, generate or summarize a report for me on what is our level of risk for this particular application and how it will pop. I mean is that where we're heading Long term?
There's a lot of potential here. We're, we're hearing really good early pilot projects around things like, you know, how are we gonna do architectural assessments and take reports about really deep infrastructure elements and the risk there and compile all of those data sets or third party questionnaires. How can we compile the, does hundreds of third party questionnaires that we're getting and figure out ways to draw conclusions as to what our risk trends are.
But right now the technology is still so early in development and there's still so much to navigate as to how to actually put it in practice that outside of orgs that already have a pretty deep data science function in place, it's a little distance away. We'll we'll see vendors start to compete to get into this space, but the security industry has been burned by vendors claiming big AI capabilities, for example in the SOC for years and not quite being able to deliver. And CISOs are understandably a little dubious and they're waiting to see if folks can actually deliver on some of those promises before they start throwing resources into it.
There seems to have always been, regardless of the field, a natural inclination to kind of just move up the ladder over time. But do you think a lot of security professionals are doing a little bit of a gut check and saying, well I may like security but I definitely don't wanna be a ciso? I don't know if it's a lot but there is definitely an a recognition now that there are folks in the industry who love being a CISO because they really wanted to solve the strategic technical issues that have traditionally fallen under security.
And they look at how the role's evolving into more of a business risk risk executive and they're just realizing that's not really what I want to do. And so that finding a place where that, let's say more old school skillset is able to be valued within the organization and evolving the roles in the overall organizational stack's gonna be really important because that is a super valuable role. It's not diminished, it's just different than what a lot of businesses need in today's environment.
So ultimately, what's your best advice to both CISOs and aspiring CISOs about how to navigate all this? 'cause it is squishy, you know, I mean it's not hard math, it's not like a bunch of metrics that I can look at and say, you know, here are the number of attacks and here's the number that we defeated. This whole business side of the house is kinda, you know, it's more art than science.
Yeah. And so the first thing to do is figure out what you actually want to do. If you really want to lean in more on the science side of technical stuff, you might need to look for an alternate path in your career.
But if you want to really lean in on the business risk management side and business leader, business executive side, start building relationships and partnerships and expanding your network, getting mentors who are outside of tech, strengthening your bond with the CFO and understanding how they're managing a risk and what they're working on and really starting to elevate your skillset and understand that being a CISO is just very different than it was five years ago. Of course, business leaders respond to external stimuli, namely in the form of regulations and then they go ask security people for this. So maybe do we need to have a conversation with the people who are writing those regulations because they're the ones that are kind of creating, uh, potentially untenable situation between the business and cybersecurity people.
So do we need to close that loop? It's kind of a bit of a wait and see. We, you know, all these cases that the SC are, are bringing to bear and initial enforcement action.
We still haven't really seen any actual results. We don't know what's gonna hold up in courts. We don't know how the SEC is gonna adapt once they start getting a flood of eight Ks every time somebody has any kind of breach.
'cause those companies wanna cover their back. The SEC may well quickly learn this lesson and say, wait, this is just not realistic. We can't even process all of this.
You know, participating in draft regulation periods, participating in industry dialogue is gonna be very critical and very important. But we still don't understand the full implications of all of of these rules. So what's your best advice to CISOs these days?
I mean, what should they be doing to prepare for probably more stringent regulations and more challenging inquiries from the board? What, what's the smart move? It's just building up that executive skillset.
Awareness of the legal and liability risks that you're handling as an individual within the org and that you're handling on behalf of the business and getting really good at documentation, getting really good at partnering with other business leaders and figuring out what are our processes, how are we gonna follow them? And having defensible, repeatable processes that you can use to respond in tricky situations so that you are protected in the business, is protected from folks kind of getting panicked and making decisions that take you off of that path. The last minute.
All right folks. Well you heard it here. CISOs need to be diplomats at the end of the day.
I mean these are conversations that go on across the business and maybe external stakeholders and regulators and all kinds of folks and you gotta find a way to talk to them on their own terms, otherwise they just won't understand what you're talking about. Hey Nick, thanks for being on the show. Thanks for having me.
This was great. Alright, And back to you guys in the studio.