Cybersecurity More Challenging in 2023 – Matt Coose, Qmulos
Qmulos CEO Matt Coose explains why the cybersecurity environment is for better or worse going to be more challenging in 2023 thanks in part to increased data privacy regulations.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Matt. Whose is the CEO of cumulus and we're going to be talking about what the security regulations environment is going to look like for 2023 Matt. Welcome the shop.
Thanks so much for having me. Mike's great to be here. Everybody's kind of on pins and needles waiting to see what the SEC comes out, but it looks like maybe we got a taste of that from the state of New York.
So I know you've been following that so why don't you walk us through what you're seeing from those guys. Yeah, I think so. The you know regulations came out a little while ago from near Department of Financial Services, and they're promoting what we're seeing, you know from other states and the federal government as well specifically around just accountability for Security Programs and and compliance reporting.
And it's going everywhere from the board requirements levied on the board to attestations by CEOs and you know reporting of incidents as well. Isn't your sense that this is a step forward or should we all be quaking in our boots? Yeah, I mean, I think it's a step in the right direction.
I think just you know compliance around cyber has been broken for so long and we're seeing more and more, you know incidents occur every day. I mean and and with that has become, you know more enforcement as well. So sec's been enforcing you've seen fines levied you seen some whistle lower cases where folks have you know, wrongly tested their security posture and those are finally being held accountable.
So I think it's a good step the right direction. I think New York's leading the way to set the stage for what's to come. Do you think sea level execs are ready to sit on a board and have some cybersecurity knowledge.
I mean I know enough to be dangerous, but I don't think you could pay me enough to do that. Yeah, I mean it's it's a requirement for for the financial services even broader than that with this new new regulation that came out. So they're gonna have to get those expertise, you know on the board in some fashion to make sure that they're you know monitoring knowing what their cyber posture is at any given time and an accurately reporting that inappropriate channels.
One of the more challenging aspects is the accountability side of this equation for the cybersecurity folks. So there's a breach they have to kind of record it. They have to share that it kind of tears that they're loyalty a little bit sometimes between you know, they're requirements to their company versus their obligation to regulatory body.
We think cyber security folks are prepared to kind of navigate that what could be a bit of a wicked as they say. Yeah, I mean I think it is but at the end I think it's all about, you know, texting of sensitive data, right? And so the requirement is there I think the implication the impact to individuals and an organizations is pretty high and just as we see these breaches happen over and over again, there's a lot of room to improve cyber posture and how we monitor that and and report on it.
So it's a needed I think evolution in just the Cyber, you know ecosystem in general. Do you think they'll also be a greater need to understand how the cybersecurity products and Technologies actually work because when there is a breach you kind of have to explain why and then you're going to have to explain what you're doing to fix that and I don't think it will be enough just to say I deployed a firewall and that's all I needed to do. Yeah, I think that's part of it.
I think definitely software vendors, you know our big part of that supply chain and holding them more accountable to the software. They you know, the code they produce and publish is I think part of the the grand scheme and the federal government's doing a lot in that space with SBOM supplier Bill materials where you got to publish, you know, the libraries your depending it depending on and so forth. So it does go into multiple levels.
I think cyber General's complex already and supply chain is definitely part of it. So, yeah. Do you think as all this gets more complex more organizations are going to say you know, what?
Let's just rely on some external service provider to manage this whole thing for us and they'll have the processes in place to take care of all this stuff because it seems like while it's important. I'm not sure there's a lot of differentiated value for each business to do with themselves. Yeah, it's a good point.
And I mean we have seen a big shift to the cloud and SAS providers and so forth. I don't think that necessarily means you can shift, you know, the risk entirely to the outsourced entity though. So they're still gonna be some accountability there.
Thank you still need to assure that that provider is doing what they're supposed to be doing. And so regardless of where it's done. I think the, you know level of expertise a level of you know, real-time monitoring level of you know, just do diligence on on Cyber defense and the Cyber posture those entities needs to need to be maintained and improve quite a bit.
Do you think we'll see a spike in cybersecurity Investments as a result of all this because people will be we need to get prepared for this and maybe just relying on the old endpoint protection and firewall is going to do it enough anymore. I definitely think that's gonna be one of the outcomes. You know, it's it like I said, it's a cyber is very complex.
But a lot of the tools exist now to do what needs to be done namely around just monitoring, you know security controls in real time. So just folks haven't done them. They've kind of relied on these Legacy largely paper-based or manual based, you know compliance efforts that really don't get to the root issue of improving their posture.
So I think you'll see a shift in kind of the automation around cyber defense and compliance reporting and there's certainly room for some investment and that space But I think just the implementation of the tools that are out there is gonna be a big effort and and companies investing in that space. I think it will be beneficial to them. We also hear a lot about zero trust and of course, it's not something necessarily that you go and buy but you implement but if that becomes my North Star do I get to check all the compliance boxes as a result?
I wouldn't say all of them, but it's definitely a good start. You know, zero trust is an architecture. It can be employed with multiple Technologies.
But the truth is it's made up of numerous security controls, right? So if you if you collect, you know, the 80 controls or so that you can kind of align to zero trust, you know, it's kind of you can you can then report on the compliance requirements that relate to those so I think that's one of the challenges organizations are gonna be faced with here and they kind of already are is you know with this the New York Financial Services compliance requirements. You got other states doing similar efforts, Massachusetts, Nevada, Vermont, California.
All those are around, you know, their residents data. So if you house, you know data from their residents, you have to comply with certain security controls and requirements. The federal federal government is doing the same things their sector specific agencies that issue regulations around compliance for like nuclear and other sectors and more and more coming out.
You've probably sell the f Didn't happen today. I don't know there was a cyber event per se. I mean it was a system outage.
But so as you see these multiple mandates coming out, whether sector specific requirements or state-specific, you know, requirements companies are gonna have to deal with that. They're gonna have to you know, either report against zero trust report against you know, Massachusetts requirements report against you know, the federal requirements if they're in a certain sector so being able to do that very dynamically and manage and monitor all those controls based on technical evidence and then report out on whatever, you know, requirements have to meet is gonna be a big challenge for a lot of folks. So should people be preparing now for the inevitable audit that's come in their way.
A lot of folks are not exactly thrilled with audits, but it seems like it's going to happen whether you like it or not. Yeah, I mean I think you know. I think audits are sort of a byproduct almost like, you know, I think I think what folks need to focus on is, you know, how do we protect the data and nist has a great framework of security controls because the risk management framework.
It's got a you know, probably the largest set of you know catalog security controls out there. So adopting a framework like that will allow them to really Implement those controls monitor those and then report against these Myriad of mandates that are coming out from either locales or the federal government or sector specific agencies. So yeah, I do think that's going to be the the better approach rather than focus on an audit and passing that and then, you know kind of having to revamp again when it comes around next year.
A lot of folks are in a lot of a lot of companies I talk to are in Perpetual audit mode just because of these different mandates. So they're they're constantly being, you know walk through audits from different, you know, organizations something the better approach is mature your security program be able to sort of monitor, you know any control and then, you know reporting in auditing becomes a buy product of of that and having a good good timely security program. So what we change the way we think about compliance going forward because historically it was always one of these, you know, well, we like compliance because it creates a bare minimum level of cybersecurity standard and we hate compliance because of the same reason so, you know will people have a different mindset about compliance going forward.
Yeah, I mean it just depends on the requirements right? So I've always kind of said that you know. If if what you have to comply with doesn't get you any more secure then I would agree with with that, you know, send me just mentioned right?
It's it's terrible right? I hate to spend money on things that don't help me get better or help me, you know secure my environment. However, if the requirements are, you know more technical more focused on the things that matter then compliances, you know perfectly aligned with my security program and kind of the things I'll be doing anyway to protect the data and the networks and the systems that I have.
So and I think there's some flexibility in there in terms of what organizations focus on, you know, certainly you have to kind of Meet the male for the Audits and do some of the the manual things regardless, but if those mandates start focusing a little bit more on the on the things that matter the technical, you know, elements technical controls then I think we'll all be in a better spot. So that's that's the hope that that's you know, kind of where it heads. I think the New York, you know DFS regulations a little bit head in that direction, at least it's kind of top down requiring, you know more timely more accurate at that stations, which I think in turn will require, you know, less and less manual less and less paper-based reporting and assessing of their security posture so indirectly, I think that's going on the right direction.
I think it can be a more explic. With some of these mandates and and really focus organizations on on the right things and and Automation and and Technical controls in my opinion is kind of where where that sweet spot is. So the other day when you put all this together, or we kind of have a tacit recognition that just maybe just maybe that we're all a little complicit in this cybersecurity issue because we didn't do enough to defend against it no matter how bad the bad guys are.
We're making it just too easy. Yeah, I mean that's that's probably true. It is a complex space, you know, so it's I mean a lot of folks say you can never really be 100% sure you're gonna you're not gonna be breach right?
There's there's a thousand things the good guys have to do and there's there's one thing the bad guy can find and exploit right? So it's a it's a difficult challenge, but I do think we can do a much better job, I think for far too long. We've been focused on just the non value added, you know components of of compliance versus they're really relevant security relevant security beneficial, you know, elements of compliance.
So hopefully we can focus on those and really things that protect, you know, our networks and systems and data. We'll be in a much better place. All right, folks, you're hurting here do the right thing for somebody else makes you hey, man.
Thanks being on the show. Thanks so much. I appreciate all right back to you guys in the studio.