Empowering Tomorrow’s CISOs – Graeme Payne, Kudelski Security
Graeme Payne of Kudelski Security discusses how we can better train and empower tomorrow’s CISOs to bridge the gap between business risk and cybersecurity, and further, to re-define the position to provide meaningful support across the business, from top to bottom.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Graeme Payne, who's head of US advisory services for KOLSKY Security, and we're talking about how the role of the CISO's gonna evolve.
Graham, welcome the show. Thank you, Michael. Good to be here.
I feel like this has been an ongoing conversation, and maybe different CISO have different functions and roles these days, but what is your sense of how close is the CISO getting to the business versus the security team versus the IT operations team versus the application development team? It seems like there's just a lot of handshakes that need to be happening. This is true, and in fact, you know, the roles evolved a lot over the, um, I guess the last 30 years or so.
I mean, when I, I started my career, we didn't, we had no CISO. Um, I started my career in the, in the eighties. Um, I think, you know, the first sort of CISO was probably acknowledged as Steve Katz from Citibank in 1995.
And really, if you think about the modern business organization, the CISO roles still, you know, real relatively new. So I think it's kind of, it's evolved quickly. Um, early CISO roles were really focused on, we're more technology focused, uh, you know, really implementing security controls, antivirus, firewalls, those types of things.
But as more businesses have digitized their, um, their systems and their, their ecosystems, that more reliance on, you know, cloud providers, um, et cetera, that role has really evolved. And, and today I think, you know, the modern CISO is, um, is one that is really, I'd say much more focused on, on risk and managing risk, and that facilitating the discussion around risk. And because, and to take that on, they, as you say, they have to have relationships throughout the organization.
So they're working with, you know, people in the, in application development and product development, operational security, industrial control systems, physical security, as well as the traditional kind of IT security, uh, the IT teams. So it's a, uh, the skillset, um, needed to kind of take on that, that expanded role was, is definitely different than it was, you know, say 30 years ago. As that continues to happen, how are the security teams themselves adjusting?
'cause they're all trained to kinda like, let's not lose and yet risk and has some assumption in it that, you know, we are possibly gonna lose. So, uh, is there a kind of a cultural, psychological issue that goes with shifting over to a risk-based mentality? Absolutely.
I mean, um, you know, the whole concept of risk is that you're, you know, you're prepared to suffer some sort of a loss, right? I mean, that's, uh, um, and where that, where you draw that line is, is a really interesting, you know, discussion point. And I think where what we've seen is that, uh, that that discussion has, it, it never should have been really the CISO's responsibility to determine that.
'cause it's not a, it's, you know, it's really a business decision about how much risk you accept in the organization, you know, in any area, whether it be, you know, credit risk or market risk, or, you know, liquidity risk or cyber risk. And so that, um, but what the CISO can do is to help, um, illuminate those risk areas and then let the business make those informed decisions. So, um, and you know, if you look at the latest SS e c rules, for example, on cyber risk disclosures, you know, there's certainly, uh, and, and also the national association corporate directors, uh, guidance and over cybersecurity oversight.
I mean, the, this really goes all the way to the board. The board and the senior management team have to be working together to, to help define what the organization's, you know, risk appetite is, and then pushing that down through the organization. And, and the CISO can help, um, educate and form, uh, advise.
Uh, but the decision about how much risk the organization should accept, um, how much they should try and transfer, how, how much they should mitigate is really a, a, it's a trade off that involves a, uh, the business folk Are the business leaders getting a little more, um, sanguine about cybersecurity. And I'm asking the question because most of the ones that I know are, have a huge appetite for risk because, you know, they're in veteran gamblers to a certain degree. And, um, is the board kind of reigning that in?
'cause every business exec will say, well, you know, there's risk, but we'll make more money on revenue if we go build this app and deploy, then, you know, hopefully cross your fingers and things will work out. Yeah, I mean, um, uh, I I think that's, that's where, uh, so yes, I think that's a, that's, uh, I, I mean, I think most business leaders I talk to, uh, you know, I recognize that there is, there's, you know, it's not always upside, right? There's, there's a downside to a lot of business decisions.
So considering you, you know, making that, that trade off is really why we have people, you know, leading lines of business, you know, leading companies, um, and providing that, having that board, having the oversight to kind of, uh, guide management and, and provide the appropriate governance over it. So, um, now you can, you can certainly, um, you know, there are lots of different techniques you can use to, to, you know, mitigate or manage or, um, transfer that risk. You know, I'm thinking things like cyber insurance here, but the reality is most organizations are really self-insuring a significant par portion of their cyber risk, even if they have cyber insurance, uh, you know, it's probably only gonna cover a small amount of losses.
I know from my personal experience, you know, working, say for example, in during the, in the, at Equifax, during the breach, you know, we had, we had cyber insurance, but it, it, you know, covered about $120 million of, of the initial costs. And, you know, the company ended up spending billions of dollars. And so, um, so, you know, cyber insurance is, is a risk mitigation technique, but it's not the, um, it's not, the reality is that most organizations are, are self-insuring, um, uh, a significant part of that risk.
What's your sense of, is the risk increasing because we are seeing all these new AI tools and the bad guys are probably gonna get to 'em a little bit faster than the good guys. So, um, what's your sense of what is our level of risk gonna be like in the months ahead? Yeah.
Well, I mean, you know, it's constantly changing, right? So as, uh, the threat, so as, as organizations have gone to continue to push and digitize and adopt new technologies, obviously that increases their, um, their threat landscape, their threat profile. Um, and AI is just another example of a, of a technology that's, you know, created creating changes in that, um, threat landscape.
I mean, there's still a lot of an unanswered questions related to ai. Attackers are gonna use ai, you know, how are we gonna use AI to defend our organizations? And then, um, you know, what does AI do to kind of cr change the threat landscape of our, of our organization?
So what, probably more questions at the moment than answers, but, um, but AI is just the, just the next thing you know, there's always gonna be another thing coming down the pipeline that changes at risk profile. And that, and that's kind of what makes, I think, what makes the CISO's job both interesting but also challenging because you have to be thinking about those things. And then advising and, and in that risk facilitator role, talking to your senior leadership and talking to your board about what those things coming down the, the pike like ai, AI do to your risk profile and, and what should you, how should you be res responding?
We've seen some new regulations that require board members to at least one or two of them have some sort of cybersecurity expertise. Not quite clear how much, but, um, I guess the question is, is will that make the life of the CISO easier? Because there is somebody on the board asking these questions.
Yeah, yeah. So that particular piece of the SS e c, uh, proposals didn't get adopted. So, um, so what they ended up doing, which is unfortunate, I was hoping that they would include that requirement.
So there is no requirement that you have cybersecurity expertise on the board. However, it's definitely a best practice, and I think, um, we've seen, you know, we're gonna see more and more organizations, um, bringing, uh, people with that expertise onto the board. But what is clear in the s e C guidelines is that, um, there should be some management committee, uh, someone in the senior leadership, either a role or a committee that's responsible for evaluating, uh, these, uh, you know, cyber risk.
And one of the things that the you've required public companies are required to do under the s e C rules is to actually disclose, uh, the who, the, where that expertise sits, um, and, and what exactly that expertise is. So, um, I do think that it's going to be very helpful for CISO that, um, don't have the right visibility today in their organization. Um, I do think it's, it is gonna elevate the discussion.
And I think, as I said, I think, um, having, uh, people with cybersecurity expertise on boards is definitely a, a leading practice. And there are companies like, for example, um, general Motors out there that have, you know, a, a risk and technology committee that, um, focus specifically on, on sort of o oversight of cyber risk. There are other laws running through the system too, that seem to be saying to folks that you're gonna be held more accountable for how you manage data and the security of your applications.
What does that do for CISO in terms of either raising their profile or increasing their headaches? And are these laws are reasonable because, well, I mean, I have control over everything that runs through my IT environment. Yeah.
Well, I mean, I think, uh, you know, in most cases the law tends to, and the regulations tend to follow the technology, not, you know, get in front of it. Um, so that's generally the, um, the, the CISO kind of having to react to changes in risks and changes in threats before any, you know, um, re re regulation or, or, uh, legislation comes along. But, um, what that do, what the, what that does do is it does bring, um, some focus and, uh, you know, like for example, one of the, uh, uh, you know, the, the idea that, uh, we need, that we need to kind of move up in the product lifecycle to embed security, um, uh, you know, to manufacturers and suppliers of technology need to do a better job of embedding security controls into their technology before they release it and before it kind of gets deployed out.
So, you know, we saw the, the challenges of, um, widely deployed technology and things like SolarWinds attack that, you know, had impacts for over thousands of different organizations because there were, you know, uh, problems in the technology. So the push to and regulation to get that, um, sort of up, uh, further up in the, in the, in the development lifecycle and to really put the emphasis on manufacturers and suppliers of software and technology to embed the security controls by default, I think is a, is a good move. It, it should actually make the, um, CISO's job a little easier in that respect.
Um, but, you know, the other, uh, chat, but then it's a question of how then the organizations use that technology and how they integrate it with everything else they're doing. And there's still gonna be, um, you know, there's still gonna be challenges in other areas that they're gonna have to look at as, as those technologies get deployed into their organizations. What's your sense of how stressful is that CSO job gonna be going forward?
I mean, there's been a lot of turnover in these roles historically, and, um, and a lot of it just comes down to that level of stress. But if we're running on a risk-based methodology, will it become less stressful, more stressful? There are just different kinds of stress?
Um, yeah, I mean, I think it is a stressful job and I mean, there's lots of different studies out there that will tell you that, you know, this is, uh, um, you know, as you said, there's a lot of turnover in these roles. Um, there's a, there's, um, burnout in these roles, that type of thing. Um, I think, uh, um, I, I, I, I think that the ciso, um, role is, uh, it's been somewhat of a, as I said, it's still relatively new in modern business, so it's kind of evolved a lot.
And so, um, the, there's been, I I think the in more, in more recent times with some of the things that, uh, like the c c rules and things like that are now providing a little more air cover, I think, to CISO. And I think they're getting more ingrained into, um, kind of these risk management processes that what organizations, organizations are implementing, you know, enterprise risk, that type of thing. So I think that does provide a little bit of ear cover and a little bit of relief, but, um, I can tell you from personal experience that, you know, there's nothing worse than getting a call, um, you know, that some, your organization under attacked and potentially being breached, and, you know, it's, uh, that that's the thing that most people worry about on a daily basis.
And, and, you know, that's, that's, that's when, um, that's when the job gets really, uh, stressful. I think. So is that fair?
I mean, you're a CISO and you've told everybody about the proverbial risks that are at hand, but when the crisis comes, you still gotta go clean it up. Yeah, that's true. And, um, uh, you know, and I, I do do think there's been a little bit of, I mean, if, if you go back, uh, again, you know, I would say last 10, 20 years, I mean, I think, uh, earlier on there was kind of a tendency to blame the CISO for those problems.
But I think, um, I think more recently there's been kind of acknowledgement that no, this was not, you know, the ciso, this is not necessarily the CISO, this is a, um, a problem with the, the way that we manage the risk in the organization. So, um, less of a tendency to blame the CISO and more of a tendency to sort of say, well, okay, we, um, you know, we made the incorrect inappropriate risk decisions here. Um, because it's not the, you know, just going back to what I said before, it's not the CISO's job to protect the organization.
They're there to advise and, um, and, and, uh, uh, and let the business make decisions as to where they want to draw, draw that line of, um, you know, how much, how much protection and, and, uh, response capability should we build versus how much money do we wanna invest in this? And that kind of balancing, and how much risk do we wanna accept that, that we could be attacked and we could have suffer loss Folks, you heard it here. You shouldn't blame the security team for a breach any more than you would blame the fire department for a fire, right?
It's the same thing at the end of the day. Hey Graham, thanks for being on the show. Thank you.
Appreciate it. Enjoyed it. Thank you.
Back to you guys in the studio.