ESAF Report – Laura Robinson, RSA Conference
Laura and Alan discuss RSA Conference’s ESAF Report. This unique report is the work of the RSA Conference Executive Security Action Forum (ESAF), a community of Fortune 1000 CISOs. The research was steered by the ESAF Program Committee, a group of 15 CISOs from global companies. For the first time, ESAF is sharing the knowledge of its members with the wider community.
Transcript
This is Textron TV. Hey everyone, welcome to another segment on techstrong TV. I'm really happy to introduce you to Laura Robinson who is affiliated with as you can see in her background the RSA conference esaf, and that's where we're going to explain what this esaf is about and some news around them.
But first, let me welcome Laura Laura. Welcome to Tech strong TV. It's great to have you on thank you.
It's great to be here. Yes, it is Laura. I guess we should start with maybe who is Laura Robinson and maybe a little of your background to share with our audience.
Sure, so, I'm Laura Robinson. I'm the E staff program director, and I've been eat that program director now for Almost 18 years. So a long history with this group and has been a fascinating ride, and I'm still very much enjoying it.
Absolutely outside of esaf the Laura a little a little bit about sure turning your so I've actually had a consulting company for the last again almost 18 years it RSA conference is one of my clients and we do industry analysis as well as strategic Communications. So my background is varied mostly marketing Communications in analysis that sort of thing. Got it.
Okay. So let's talk about Esa. You know, look I've been going to RSA conference.
Probably longer than I want to admit 20 plus years. But I've never I wasn't aware of esaf. I'm not sure why I was unaware if that was on purpose or not.
Well, tell us what's he yeah. So the executive security action form which is what the acronym stands for is an association of Chief information security officers or cyber security Executives, basically from the 14000 companies. And we have been meeting at RC conference and also throughout the year.
It's basically a trusted form for information sharing confidential information sharing. And the reason why you haven't heard about it is because it is just that it's a closed door Invitation Only confidential information sharing forum. Now we actually have as you mentioned earlier.
We have taken on a more public profile just really very recently. We've decided to start branching out into research reports. And so our first one is just coming out now, so you'll hear more about us in the future.
Absolutely. That's great. We're going to jump into this report in a second, but I have to tell, you know, I recorded a piece last week.
Of course in the news the news was full of. Fellow Joe Sullivan, the former CSO an Uber. Yes, of course was convicted of a couple accounts of holding or lying withholding information not telling the truth.
Yeah, and and you know, that was a shock to many in the industries. So it's a bit of wake up call. um, but to me, it was one side of a coin the other side me of the coin being I think it was the month before much that much zako over at Twitter, you know, the Twitter whistleblower who testified to Congress Because I mean to me it was sort of a Jerry Maguire moment right where he just said.
Hey, they're not they're not doing what needs to be done. This is a real problem here, right? So rather than waiting for the other shoe to drop and having to lie about it.
He would try to be more proactive and kind of go public right with with what he was seeing there and a lot of people in the industry, you know, it was it was a bit of a lightning rod as well in the industry where people were like, yeah should he have not done that what was motivation but to me these represents kind of two extremes. Of what to see so to do does he does he do what I call the Nuremberg defense, which is what Sullivan said. Well, he's just following orders the legal team told them not to say anything.
What do you go become a quote unquote whistleblower and go public and but look at the matter is I bet you most folks in our in our audience or in the community would walk with their feet. They just very quietly head to the exit and find another job which may or may not be the right thing to do either. So I'm pleased to see of an organization, especially when it's been around 20 years such as esaf, which gives Cisos in exact security Executives a closed door if you will confidential forum.
to to explore What to do what are the responsibilities how to communicate to the board and these kinds of things so really really happy to hear about this and I'm really happy to hear that you guys are coming going public with it. It's good stuff. Well, I think what you're pointing out is how important it.
Is that companies. have some sort of formal processes in place to manage and oversee cybersecurity risks And the management of the cybersecurity risk, it's I think in a lot of cases the cases that you're pointing out. It's because companies haven't focused on it enough throughout the entire organization up to an including the executive leadership in the board.
Yeah, but at some level. You know, you make the big bucks or I hope they do as this information security officer Chief security officer. the responsibility lies with them right when they went to go to the board what to go to the board with what to do with what the board or others in the order at senior level, you know management tells you Don't talk about this dude disclose that right.
These are these are decisions that can affect one's career far beyond the immediate instance. Well, what is freedom? Yeah, absolutely.
What what security officers in our community really emphasize? Is that you have to be working with your the other peers executive Management in your organization? You have to be working with other organizations.
It's it's not just a one person show up. It's it's it really isn't and the responsibility for managing the risks within a company. Is everybody's responsibility the what this what the SEO is tasked with?
It's helping people understand those risks and how to best manage them. They're not responsible themselves for managing those risks their responsible for making sure people understand how to manage them. Excellent.
Let's let's jump into this first public report from the essay if you if we got Well, it's you. It's your report. I'm gonna let you start it off.
What okay. So this is the first report that the executive security action forum is has done it said it's a new Endeavor for us. The community wanted to go beyond information showing at sessions as we mentioned earlier.
Typically, we have confidential information sharing sessions throughout the year, and we will continue that but we decided to also Branch out into research so that we could do a deeper dive on topics and also We decided it was time to share the wealth of information that we have within this community with the larger security community. So this is one way that we're going to be doing that. So this first report is on reporting to the board.
And why do we choose this topic one is because it's a super important part of a csos job. and also it's Hard to get information on how to do it effectively really the best information on how to do it effectively is to speak to your peers about it to share how they're doing it. So that's why we tackle this particular topic and also as you pointed out there's lots of stuff going on in the news.
There's also increased regulation around reporting at the board level. So it's become a real focus in the board or with the board. and therefore we wanted to make sure that we could Help organizations do this well.
By all means, you know Laura I'm thinking back. It had to be. Eight to ten years ago.
I was actually on a panel at RSA conference and it was it was the I don't remember the exact title, but the gist of it was What metrics? Do you provide to the board? Oh, yeah versus the metrics you work with.
Right with your security team. and it was almost and it was almost like you got a dumb down the metrics for the board because they're not gonna get into it and I disagreed with that. I don't think dumbing down was the right thing.
I think. Yeah, it's not translation. Yeah, right.
Well you you choose the ones to share. Yeah. Yeah, well, but the board and this is something I've learned in 25 plus years in the security growth board level language dialogue.
It's a different language than the language of the security professional. Yes, right. Yeah it they're both, you know, they could both be talking about risk, but at the board level it's business risk.
Yes, right. Yeah not it's it. It's a different dialogue and and I think a lot I think that's a big hurdle for a lot of especially younger Seasons kind of learning.
You're not talking to the guy who's Manning the vulnerability reports or doing the pen testing or or these kinds of things you're talking to a business? Board who's interested in business metrics. Anyway, if you wouldn't mind share a little bit about the report, you know Finding what we maybe that our team would like to yeah for sure.
So we actually do cover metrics. That's bang on what you what you've just described is it's a very big challenge what metrics you share with the board what will be meaningful to the board because like you're describing you can't give them all sorts of operational metrics. They in a lot of ways are not going to understand them because they'll just be too technical.
and they won't be meaningful to them because you want to describe things that are happening that will impact the business and so this the Report has a whole section on metrics and it goes through how to choose meaningful metrics and how to formulate and present them in a way that will be meaningful. So for example, if you're going to provide metrics to the board You always have to show targets you want to show trending you want to consider what message you're trying to get across. What are you trying to tell them when you share a metric with them?
Are you trying to help them understand a risk or help them understand some progress that's being made. So there's a lot to formulating and presenting metrics for the board. And in terms of what metrics are being shared in the report that we have done we looked at.
we had materials actually contributed to to our research team So several csos actually gave us recent board updates Anonymous. They were all Anonymous and we were able to go through that and analyze them and in the ones that we analyze we found that there were two common metrics there were many many metrics and there were very different. There's a lot of variety in it depends on the company in the board Etc.
But the two that we're very common were a maturity score of some kind So based on an assessment like the nist cyber security framework and also the number of incidents, obviously the board wants to track how many and how many incidents that companies having and the C so wants to report on that. That's a very important metric. So those are two of the common metrics Got it.
Beyond metrics though Well, I don't want to minimize the metrics are important. Yeah, that's right. But what else?
Yeah. Yeah, what else is in the report? Yeah, so the report lays out.
How challenging it is to share information on cyber security risk was the board like, where do you start? So it lays out? Well, what are the boards objectives in understanding cyber security risk?
What are some of the challenges in describing those risks to the board you you want to provide them with the right level of information you want to give them assurances? You want to have a balance between this is what we're doing to. Manage the risks here are the areas that have gaps and here's where we're making progress.
So one of the quotes in the in the report. talks about you don't always want to report a Rose Garden because that's gonna seem kind of funny to the board that everything is always perfect. So you really have to balance it to help them understand be as transparent as possible about What the gaps are and filling them?
So the report gives them advice in those areas. I guess it's not necessarily advice, but it shares how people are doing it so that you can get some ideas from that. and look I think that's the most important part of this whole thing is this isn't set to be the Bible person, but it's supposed to oh, absolutely.
Yes. It can't be appears. Yeah it there really is no standard and the report at the very beginning kind of as a as a section that says, you know how to use this report.
It's it's not intended as a set of best practices or a standard because the really can't be it really depends on your board. It depends on their expectations. It depends on the regulatory environment on your company.
Depends on the cease of themselves and how they want to structure their report. So what it provides you with is just a bunch of great ideas on how to do it effectively. Great Laura, we're running a low on time.
But for people who maybe want to take a look at the reporters, it's publicly available. And if so, where? Yeah, just go to the RSA conference website.
It will be available. within the next few days Absolutely, I think people by the time they're watching that. Okay.
Sorry, it's available now. Yeah available. If you go to the RSA site, yeah, I think yeah.
You know, what a long overdue. Thank you for 18 years of shepherding the esaf. I'm glad to see it, you know coming out from behind the closed doors to help the community at large.
Yeah and kind of an expansion of this of the of your mission. Well, and after 20 years, we we have a lot of we have a lot of really great information to share with the community. So we're excited about our next report.
We're going to be tackling supply chain security. So that will be something people are very interested. Yeah.
Yes. Right gets into the whole s bombs and all that good stuff. And I would be remiss if I didn't mention the RSA rsac call for speakers.
I think it might have just closed by the time people see this or might still be open. But also the the event itself this year the US is in April. I think it's the week of April 24th.
Yes, people can go register now, I assume yet. Yes AF we're already planning our meeting yet. That's right.
We'll be doing our devsecops event there Monday of oh nice week as well. So excited about that. Hey Laura.
Thanks for coming on. okay, thank you for having me we're doing as I said, yep, so go to the RSA site RSA conference site folks and download this report. I think you don't have to be a seesaw to get good value and no there's lots of great information in there managing risk and how to report on it.
Okay. Thank you. Thanks, Laura be right that might take a break here on Tech strong TV.
We'll be right back with our next guest.