Convergence of Compliance and Cybersecurity Management – Stacy Hughes, Voya Financial
Voya Financial CISO Stacy Hughes explains why compliance and cybersecurity management are finally starting to converge, thanks in part to new rules being imposed by the SEC.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Stacy Hughes, who's CSO for Voya Financials, and we're talking about compliance and security and how all this is converging 'cause well, the rules are getting tougher.
Stacey, welcome to the show. Thank you very much for having me For so long security and that whole GRC space were, you know, loosely coupled I would say, but it feels more and more, it's about to be more tightly coupled. So what's your perspective as to what's driving that and what's going on?
Well, I think there's always been a continued increase in the regulatory and compliance landscape that I think security professionals are needing to address in their cybersecurity programs. And, and the new SEC rule is, is no different in, in that regard. Tying and coupling in very closely what we're doing from our instant response plan, but also making sure we're meeting all those requirements in an event that does need to be disclosed, that we have the right procedures and that we are communicating timely with all of the regulatory bodies as well.
For so long, security people had a mixed feelings about compliance, shall we say, because they were better than nothing, but they weren't nearly good enough. So are the compliance mandates getting better or are they still just pretty much a baseline? Well, I would say any program really needs to look at what their unique risk is to their organization and make sure they've got the security controls that mitigate that risk from each different organization.
From that perspective then it does line tie in very closely with compliance. And in my opinion, if you're meeting the security requirements, you're mitigating your risk, then you are meeting the compliance requirements. I do think more and more over time the compliance requirements are being more prescriptive as well.
And I think that's also in alignment to the continuous evolving, you know, threat landscape that we're facing as security professionals. And how is that threat landscape evolving? Because it seems like on the one hand there's a lot more attacks, but they're not that much more complicated than they used to be.
But then again, there are these kinda little nuance attacks that are very sophisticated. So how do you see things moving forward? Well, I think there are a couple of different aspects that I see moving forward.
One is always new technology. You know, we've faced that over years as we've evolved even from on-prem technology to cloud. And now even looking at, you know, over the past year, uh, I'll call it language learning models, now going into artificial intelligence and how that technology and any new technology, I say it's very exciting because it does provide a lot of other opportunities on how we can continue to really, uh, I would say identify and detect things quicker from a security perspective and, you know, help defend our organizations.
But I also see it on the other side that the threat actors are also leveraging that technology to potentially come up with different, uh, attack vectors, different schemes, different, having their phishing emails be, you know, very compelling and upping their game with being able to leverage new technology. So I do see that, you know, as a continued evolving trend that, you know, is exciting in multiple aspects. And of course that applies somewhat to the crime syndicate folks, but there's also nation states at work and um, we hear for example, the Russians are pretty keen the stymie any capital outflow from Ukraine.
So they're creating a lot of false accounts in various banks just to keep everybody busy. But, um, what is your sense of, um, how sophisticated are those guys and how big a threat are they? Because for example, you could argue, you know, the entire North Korea economy is funded by crime.
I think it's something that we always have to keep in front of and, and keep looking at from the, the landscape. I do know over time, you know, there's been changes in what we're doing with sanctions over the past few years, but the threat actors will continue to find ways to fund their activities and it's just continuing to make sure that, you know, we as an organization, as an industry, you know, continue to put all the right defenses in place to, to mitigate that risk from, from potential nation state and other threat actors. So clearly there's a lot of stress in the equation.
So what's your advice to your fellow CISOs about how to deal with all this? Because, you know, if you let it get to you, you could be up pretty much all night. You could, you definitely could.
That is a true statement. I think the, the, some of the biggest points that I would recommend is just, you know, making sure you're relying on your team and you've got a good team. I think that is very important.
You know, I've got a great team at Voya that helps us, you know, keep defending and protecting our data and our customer's data. 365 days, you know, 24 by seven, uh, throughout the, throughout the year. So that's very important is having the right team.
I also think the other area is just really continuing to network with other CISOs and other peers. There's a lot of great information that's shared as we come together, you know, informally and formally and in various groups. And also being very involved in information sharing groups.
I think that's another area where you get, you know, more of of the technical detail, ransomware, hashes, those parts and pieces, the tactics, techniques and procedures that indicators of compromise that bad actors are using that then you are able to take that information and go threat hunt, you know, within your own environments and continuously, you know, make sure, make that you're in that constant evaluation of your environments. How do you communicate that risk to the business folks? 'cause you know, the truth of the matter is they, on the one hand, they understand risk fundamentally, but they have a big appetite for it because they're generally trying to drive some revenue and they think there's a huge opportunity.
Do you think that when it comes to cybersecurity, they understand the level of risk and what it means to the business? Or is that more still a work in proverbial progress? It's always, uh, I would say continuous work in progress because we need to as security professionals tie back what the cyber risk is in business terms.
And my philosophy is you really need to understand the business and how the business grows and works. It makes money to be able to support that business from a cyber threat perspective. So for anything that needs to be done on a cybersecurity improvement perspective or other initiatives, those types of things, it's really important to be able to work it into their language and also be able to be a good storyteller on how to explain the importance of a certain cyber threat or cyber initiative, uh, within a company.
It seems to me if I look at some of the regulations and where they're going is the expectation is that auditors think that the security people are actually gonna understand the business workflows and what the impact of that is. So, uh, to your point about knowing more about the business, do the security folks need to, I don't know, get an MBA or some equivalent or how does this kind of work out? Well, one of the things that we do, and I've been very, uh, important with throughout my career is having key business leaders come and talk to our information security team and understand where they're going from a business strategy and philosophy and also tie in how can we help with what they're doing to execute on the strategy.
Uh, it's a real feather in my cap when we have our business partners reach out to us proactively continuing as they're looking at new initiatives, having security embedded into the process. So that is something that's been embedded in our culture at Voya is to be very proactive and engage, uh, information security and really see us as Aval valued business partner. There's a lot of issues these days involving, uh, legal jeopardy and CISOs these days.
And I guess, you know, without commenting on the specific instances, but what is your sense of how should CISOs proceed if they're in a public company? Is there things they should be thinking about or doing that kind of protect themselves? Well, I think it goes back to talking with the organizations and making sure you've got good roles and responsibilities defined.
Uh, also going into specifically with the incident response plan with how procedures would be documented, how they are communicated. I think those are things for any, uh, CSO just to continue to look at as part of their overall day-to-day activities. Uh, from that perspective, Do you think we're asking too much of the ciso and I asked this question in this regard, if I live in my town and suddenly there's a fire and there's a, you know, and there's damage and it's unfortunate, but we don't go out and fire the head of the fire department because there was a fire.
So how come we're, you know, putting security folks in the crosshairs for these issues when ultimately wasn't necessarily your responsibility to patch that system or make sure that the policies for that particular individual were granted? So how do we kinda strike some reasonable balance here? I think the tide is changing to where the ciso and that's the intention of the SEC rules, to have a bigger seat at the table and be involved in a lot more strategic decisions and what we're doing and really talking more frequently about cyber risk in an organization.
So I do see, you know, the CISO role has changed. It's changed since I became a CISO years ago and is continuing to evolve. And I think that is, you know, one of the results of that is the SEC rule, being able to provide that additional information that, you know, typically the CISO wasn't always at the table before.
Okay. Um, we've been dealing with a shortage of cybersecurity expertise for more years than any of us care to counter admit, but, um, A, is that getting better? And b um, I guess, you know, back in the old days the Marshall would deputize everybody in town and put a posse together.
So are we deputizing the IT operations teams and the developers to help with all this? Well, there is still a shortage of cybersecurity professionals, uh, in the industry. However, I do see things changing in what we're doing to bring in more cybersecurity professionals.
And this is one area I'm, I'm very passionate about, is really helping develop and, and have the next generation get excited about cybersecurity. Um, so in a few different ways. One is being able to provide that mentorship program with, you know, either I would say college students as well as, as there could be team members that have been in other areas, as you said, deputizing, you know, it, or somebody that maybe has come back with a different experience and wants to pivot over into cyber.
The unique experiences and backgrounds I think really help us to defend an organization with all the diverse background and thinking. Uh, also with the college programs, it's really important to get involved with a, uh, internship program at Voya. We do have a internship program and that kind of helps fuel our future pipeline as well.
And not only with that internship program, we do have a rotational program as well too, so they can come in and not just try and be a part of our cybersecurity team, but they may learn about data, they may learn about other areas and infrastructure and really get that well-rounded perspective. And I think that also helps provide, you know, entry level cybersecurity professionals, the need for their skills and, and that overall background to do some great things. So I see there's a lot of potential going forward with, you know, all the various programs, whether it's college programs, one year, very technical programs that are upskilling professionals to get them out into the cybersecurity world.
And then it's now up to us as I would say, as as CISOs and leaders in organizations to really embrace all of those programs and really execute and, and help fill those cyber jobs with those, you know, there's a lot of great individuals out there that have the right skill sets and are hungry to learn and very curious and that's what makes great cybersecurity professionals. Right. And they don't all need to be in a four year program either.
No, they don't. Okay. Um, you've been at this a little while now.
What do you know now that you wish you knew when you first started out? I think one of the biggest areas is continuing to always be centered. As you said, you know, earlier that CISOs can be very under a lot of stress at times and just making sure that, you know, if there is anything, I keep it very internal and I don't show anything outwardly because if I am concerned there is a reaction with everybody else.
So just being able to make sure staying calm under pressure is always something of, of an importance, uh, that I've learned looking back over my years to now. All right, folks. You heard it here.
If you're not calm, you can't expect everybody else to be calm, so it's just kind of a reasonable expectation. Stacy, thanks for being on the show. Thank you very much.
All right, back to you guys in the studio.