Cybersecurity Stress Levels – Dave Stapleton, CyberGRX
CyberGRX CISO Dave Stapleton discusses the level of stress cybersecurity teams are under and what should be done to alleviate it as cyberattacks increase in volume and sophistication.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Dave Stapleton who's seesaw for cyber grx, and we're talking about the current emotional state of CISO and the security Personnel in general Dave. Welcome to the show. Thanks for having me.
I'm happy to be here. In some ways it's kind of the best and worst of times, right? The best of times is the fact that more people are paying attention to cyber security than ever.
The worst of times is well, you might wind up going to jail if you make one wrong move. So the question is Dave, you know, what is the current? Emotional toll that's being taken on the cybersecurity folks.
And is it getting too heavy? well Too heavy that's interesting question. It is heavy.
I'll tell you that and for the I think the reasons that you've just highlighted and I have this little mental model where I use my mom as an example. She is not a cyber security professional nor has a whole lot of experience in it. So if she asked me about a cyber security threat or news item, I know it really must have gone mainstream and and let's just say we had a lot of conversations about cyber security lately and it is absolutely in the mainstream the attacks seem to be getting more sophisticated and the volume attacks seems to be going up the impact of these attacks seem to be more widespread and getting to real humans where they're starting to feel it a little bit in ways that perhaps we're a little bit theoretical to them in the past.
I was just talking with some students and we're talking about, you know, how to cyber security play into everyday life and started going down a list of examples one of the examples I gave was Warfare. I mean, this is crazy. We're getting to where you know, Ukrainian cyber security.
Teams joined up with ESET to block a major attack against their electrical grid. So it's it's just pervasive and I think the stakes feel very very high which creates a lot of weight for cybersecurity teams. But particularly, I think ciso is another cyber leaders who are really responsible and accountable.
Are we starting to see something that looks like a brain drain because people are leaving the feel. I mean, we're recruiting people all the time. But and you may not be a great thing.
If we wind up losing as many people as we wind up bring it in or maybe even if we bring in twice as many people The Brain Drain will be heavy. So what is the impact of all this? Yeah, it's a it's it's definitely something to be aware of and I think I don't know that I would get go quite as far as to say that I'm concerned at this point that we have such a mass Exodus from the industry that we're experiences significant brain training.
I think conversely the more acute challenge right now is encouraging in this and Advising young people and others who are trying to make shifts in their careers to move into cybersecurity. org. I think it was something like 770,000 unfilled cyber security positions in the United States alone.
So we have a problem even just getting people in the door in the first place and and then certainly as folks find the stresses to be overwhelming or maybe the rewards to not I'm kind of match up and balance that out and they leave the workforce that just compounds the problem of how do we have, you know fill these roles that are really necessary in order for us to do our jobs as cyber Security Professionals around Nation when we have shortages almost kind of coming from both ends as far as the initial Recruitment and then the retention of qualified folks later on in their careers. Is the expectation just too high? I mean you got this many attacks and the guys are getting smarter and we only have so many resources are we expect things cybersecurity professionals to pull up a daily miracle and maybe some days they already do but we just don't appreciate it because you don't see it.
But the question I would have is you know, do we need to level set our own expectations of what feasible here? Yeah. I mean, I don't mind sometimes thinking to myself as a miracle worker Michael, you know a kid, you know, there is this kind of common refrain so something along the lines of hey that you know, the bad guys only have to get it right once security teams have to be right 100% of the time and I think that kind of sentiment and mentality is part of what's adding undue pressure and setting the wrong expectations and if we are as you know cyber leaders are going to our leadership and boards and saying, you know, my job is to prevent any type of cyber incident from ever occurring in this organization.
You've you've automatically said an expectation, that's not very realistic. I think a more realistic and perhaps somewhat Center of cooler pessimistic, but again realistic and ideas. It's not so much a matter of if but when and so you can't set the bar so high that it's realistically unachievable.
It just doesn't make make any sense. So I think one of the the major things we have to do in order to prevent this kind of complete burnout and the stress from becoming too overwhelming is be clear with our leadership as cyber Security Professionals about what we can and cannot do and make sure that we understand what their expectations are for us as well and evaluate those and there are some organizations where the leadership is going to say something like yeah, your job is to bring prevent their from ever being a Cyber attack and that's accessible and our organization. If I hear that from, you know leadership CEO or a board member I'm gonna have a lot more conversation with them to try to maybe course correct a little bit there expectations and their thinking on on how this full cyber thing works because unfortunately, you know, we can't get it right 100% of the time and it's a time constant cat and mouse and it's why I think folks are trying I think more about things like resiliency and not always prevention and as the way to handle cyber security Are we getting better and making this more of a team sport and by that?
I mean we seem the beginning more of the it operations folks involved to run security operations. We see more of the developers getting involved in application security and things like SecOps. So will that reduce the stress on the cyber security team?
We kind of think about this more as a group effort. Yeah. I think it reduces sometimes the level of effort right because we're spreading these tasks out to you know broader set of hands.
We're getting some support and some assistance from those organizations and departments. I don't know that it reduces the stress significantly because at the end of the day ultimately comes back to the security team and they are ultimately responsible for the outcomes related to cybersecurity and oftentimes privacy as well. So and I think in so much as folks might be feeling rightfully burned out just because there's so much to do and you know, it's a serious problem.
I've got plenty people on my team for example who I have to coach like you can't keep working 12-hour days. I know there's an unending list of things you can do and my expectation is not that you're gonna do everything. So from that perspective as far as like I need to step away from the keyboard from time to time.
It's really helpful to be able to spread out some of the responsibility and the individual tasks, but when it comes down to it if Is a successful Cyber attack some kind of an incident. It's the ciso who has to go talk to the board and potentially the press and you know, go to court and in some cases as we're starting to see now potentially even go to jail. So I don't know that it reduces the stress associated with that kind of liability and responsibility very much.
Are we seeing advances in automation? We hear a lot about all things AI these days. Well that help reduce some of the stress as well or is that kind of and more on The Wishful Thinking side of things?
Well marketing teams certainly seem to think that slapping AI or machine learning onto their marketing materials is definitely the answer and that they that Security Professionals must believe that that's the answer to everything. It is absolutely a an additional tool in our toolbox and it speeds our time to identification time to response those types of things. It gives us analytical insights.
That would be all been impossible if we tried to fuel those by just human intervention and and Analysis. So there's plenty of upside I think to using AI unfortunately anytime a tool like that comes out it can be good use for good or evil and so our adversaries are using AI against us. So I'm you know, it's unbalance.
Are we better off in totality? I think probably we are and however, we just have to keep in mind the fact that when we create a weapon that maybe we're gonna use for good and that weapon then does exist for people to use for for ill intent as well. How realistic is it for an organization to maintain cybersecurity themselves these days versus relying more on a services provider?
Because you know to you are earlier Point you're never going to find enough people and you're not going to be able to retain them anyway, because there's always somebody wants to hire them. So at some point does should this just be a flat-out service that is a shared resource for a lot of different companies. Well, I think many companies are treating it that way absolutely right now and they've decided there's too much overhead and trying to you know, develop higher, you know, continue to train and retain your own security team develop these specialty areas that you can hire an MSP to do for you and the beauty of I think the MSC in a few model is that they can specialize in specific areas where they can dig deep and leverage Decades of experience in particular areas and be really excellent in those areas.
The challenge comes when you're trying to produce that for your own organization your own team, you find a lot more Jack of trade jack of all trades a type of opportunities as far as you know bringing in recruiting and retaining that Talent. And the problem with MSP is one there can be a lack of accountability and clear Direction on prioritization in that type of thing. So you might find that they've been kind of going down a path that that was not necessarily what you wanted can also be quite expensive and if you're talking about really Outsourcing your entire security program that is that is financially going to require a lot of investment from from your CFO.
And I wonder how often organizations are finding they can get that kind of investment versus potentially saying look we might and I had the same. Level of excellence and expertise but if this organization based on our threat profile and our acceptance of risk and sort of our risk tolerance, and we believe that we can get by with a B+ security team that we can create in internally rather than having to Fork out, you know, however much for more of an A+ MSP driven security team. So there's a factor of just individual risk tolerance and needs that comes into that as well.
Risk versus resources, of course have always been an issue. But as the economy gets a little tougher is that becoming harder to balance if you're an organization because you know, you may not get the additional funding that you're looking for in 2023, even though there's a lot of people who would say cybersecurity is recession resistant, but reality is funds are funds and everybody's might inform. So what's your sense of how much more stress does the current economic climate add to the equation?
I don't know if you've got mics in our conference rooms here at cyberger extra night, but we're having this very conversation yesterday. And I think that adds significant stress. I think personally, I believe the next year is going to be a bit of a roller coaster ride for a lot of Security Professionals as organizations feel the macroeconomic uncertainty and want to tighten the belt be more conservative with their spending.
They're gonna start looking at prioritization and it's interesting when times are great everyone seems to get a little bit of love and and it's not too hard to eke out the resources that you need and when times get tight and that inspection happens you really start to understand what the true priorities of your organization are and my concern or my fear is that a lot of CISO for example might get a bit of a rude awakening when they realize where cyber security really does rank as far as the priorities of their organization. I mean if you work for a for-profit organization You know the security can't be the top priority and it just can't be you have to continue to make profits. So where do those cuts start to come in where you start to feel the pinch?
I think a lot of security teams are going to be asked to basically do more or do the same with same or less. So probably budgets are going to stall or in some cases even go go down and we're already seeing, you know, a lot of large companies. Participating in a lot of layoffs right now.
And I don't know how many of those organizations absolutely needed to do. Those layoffs. Maybe they were thinking it would be great if they had a good opportunity and then you start to see Twitter and Amazon and others do it.
Like okay. Well, let's just jump in now. We don't make a splash or how many of them actually needed to to make those changes.
But that is the situation that I certainly hope. I'm most security teams don't find themselves in big because as we mentioned already the talent pool doesn't exist for the current work that needs to be done in cyber security much less if you start to take those folks away. So what's your best advice to folks to reduce the stress other than the fact that maybe they should go to the gym or some might indulge in some libation or another but you know, what's what's the Practical thing to do here?
Yeah, you know, unfortunately you I think you joke a little bit there, but unfortunately a lot of CISO have turned to various devices to to try to I guess take the edge off of the stress and it's it's very tempting and you know see those have higher rates of things like alcoholism and even suicide so it's it's pretty serious. I'm I think one that I mentioned before is making sure you have those hard decisions with your leadership and establish the expectations up front and don't get surprised by that later or don't have that hanging over your head. Wondering well, what would happen if we actually didn't have an incident like do I get immediately stacked or is there some conversation?
How's that work? What are people expecting to me? I'm Now's the Time to to go and have those really Frank really direct conversations.
And and come ready to set your own expectations. I would say, you know too often csos but I think maybe we're still growing into this executive role and we're a little timid or shy we don't want to you know, come and say hey this is kind of what I demand this what I want to come from you and so just come ready to to say this is how I think it should be and have this conversations and be clear with the expectations up front and then yes. Pay attention to your mental and physical well-being and take the time off.
You got to set boundaries. It is very difficult to do that every single day. When I finish up my work day.
There are you know, 10 to 20 more things that I really wanted to get done that day. Absolutely 100% every single day that's gonna happen, but I can't allow that to make me modify the way that I live my life outside of work first up working if I just you know had to get everything done. I'm here in check every box before I called it.
You just got to set some some guardrails and to protect yourself and then listen to yourself and don't be afraid to talk to somebody if you need to, you know meet with a professional and just kind of go through. Hey my head's and a weird space right now and I need to talk it out I think and we got to get over the stigma that somehow therapy and other kind of professional and mental health services are there's you know, some kind of a stigma around them. We got to get past that and and really think about what's best for our own, you know, physical and mental health Arguably therapy should be required for all Security Professionals because I love it is you know, it is a high stress job.
And there's a lot of other jobs that probably need the same level of therapy. Hey Dave. Thanks for being on the show.
Absolutely. Thanks so much. All right back to you guys in the studio.