Gutsy’s John Morello on SEC Disclosure Rule Changes
Gutsy CTO John Morello explains how recent changes to SEC disclosure rules will impact cybersecurity teams working for public companies.
Transcript
This is Techron tv. Hey guys, thanks Ro. We're here with John Marillo, who's CTO for gutsy, and we're talking about what these new disclosure rules from the SEC are gonna mean on a practical level to all the cybersecurity folks out there because, well, we all have been obsessing about what it means to the board, but when it comes right down, there's some serious brass tack issues that need to be addressed.
John, welcome to show. Thanks for having me, Mike. So if you're in the trenches, what should I be paying attention to here as far as these rules are concerned?
Because a lot of times, as we all know, the proverbial thing rolls downhill, and at the bottom of that is everybody we know and love. That's right. Well, I, I mean, I think the, the biggest, uh, change, the thing that that really impacts security practitioners and security leaders at organizations is this, you know, the, the fact that now there is a legally mandated requirement to disclose material breaches within a pretty short and finite amount of time, you know, historically had been considered a best practice for organizations to do that.
And, you know, many times they may have been obligated to do so by their license agreements or maybe some other regulations that they fell under. But now for the first time, there's a, there's a real kind of blanket level, um, requirement from the SEC that if you're a publicly traded company, you've got a pretty short window to disclose disclosures or to disclose, uh, breaches. And because of that, there's now this, this real, uh, urgency, I think for organizations to create a plan that allows them, not just to detect problems, but to quickly triage them and make a decision on whether or not they meet the bar for disclosure and if so, to do so in a coordinated way.
And, and that's really something that's new in the industry, uh, and I think organizations are struggling to figure out, like, how do they actually adapt to that and make sure that they're gonna be able to meet those requirements? Does that create something of a divided loyalty? Because if I'm the cybersecurity person, I have an obligation to the SCC, and then there's the obligation to the folks who hired me who in turn have obligations to the investors.
So yeah, where do I align on this whole thing? It's a really good question. And, uh, you know, I think you've seen some of the, the early court cases without getting involved in the details of the case.
But, you know, you recently probably saw in the news, uh, with the, uh, issues with, uh, Uber CISO and SolarWind ciso, that that really revolves around almost the exact question you're asking there. Um, and I think the challenge is that rarely in an organization is the CISO themselves, the sole decision maker in how an organization discloses some kind of breach and what actions they take and how much information maybe they share about that. You know, usually that's something that carries a great deal of, of legal and reputational risk for the organization, and is really managed at the, you know, if not the board level, certainly at the C level for the organization beyond just the ciso.
Now you're talking about the, you know, the COO and the CFO and the CEO and so forth as well. Uh, and so there's, there's definitely a, a potential there, I think for, you know, for a ciso, even if they've done their job technically and found a problem and notify their colleagues about it to, you know, still have some risk there if, if the organization ultimately chooses to be, um, you know, to, to not meet the requirements that the SEC has put in place. Um, and I think for CISOs and, and security organizations in general, one of the things that this is gonna drive a behavior that this is likely to drive is probably going to be more official documented, recommended recommendations internally when an issue is encountered about what to do with that.
You know, historically, I think that was always something that would be shared by a, you know, security team and a leader like, Hey, we think this is an important problem, or, you know, maybe this meets some kind of criteria that we've established internally that we'd wanna disclose to our users. Um, but now I think there's gonna be a, a real personal, um, you know, incentive or, or, or at least like disincentive not to get into trouble for CISOs to be really clear and transparent about that with their colleagues. You know, if, if we encounter some kind of breach at an organization, you know, me as the ciso, I probably gonna wanna be especially careful that not only do I understand it technically, but that I make guidance to my colleagues very clear that I think that this meets the, you know, the SEC threshold, I think we should disclose this, here's the information about it so that ultimately I have some personal protection in the situation if, you know, the organization ultimately chooses to do something different.
So I mean, we've, we've already, you know, talked to a number of customers and people that have thought about that and are aware of that concern. And I think those will probably continue to, you know, to be concerns and, and things that drive different behaviors from, from security leaders. All right.
Ultimately, no matter how much you love your company, you're not doing time for 'em. So there you have, Most people would not. That's right.
Alright. Do you think that most cybersecurity teams have the tools they need to make those kinds of reports that quickly? Or is there gonna be a certain amount of, uh, uh, shall we say, shopping that needs to occur to kinda actually be able to meet this mandate?
Yeah, I, it's a, it's, it's a fair question. I think that it's, the answer is a little bit nuanced. Um, I think most organizations have invested, at least ones that have, have done even sort of just basic best practices around security have invested in the kinds of, you know, um, endpoint detection, incident response kind of tooling capabilities to at least let them know that problems could potentially exist in the organization.
You know, you, you talked to lots of security leaders. I know in your role, and I'm sure you, you know, you, you don't hear people saying that they don't get enough alerts or that they don't know, you know, there, there's enough potential problems in their organization. I think the failure and the struggle that most people have is taking the, the next step in that process after they get that initial alert or alarm, you know, how do I actually go from getting all these alerts to putting 'em into some sort of process that allows me to be able to triage them in a timely manner to make accurate decisions on their materiality and whether or not I could take an action with it.
And if so, like what those actions should be and to make sure that all those steps along the route are actually being done within whatever SLAs I'm required to, and that all the various stakeholders, 'cause you know, it's probably not just gonna be the security team now, it's gonna be people in legal and corporate communications and so forth. They may be involved in one of these disclosures that everybody is playing the part that they're supposed to, and, you know, meeting whatever kind of internal, you know, business agreements they've made in terms of responsiveness and roles and responsibilities and so forth. And so I think it's really, it's, it's not so much about the technical tooling and being able to make the initial, you know, detection, but really more so what do you do after that occurs so that you can again, meet this very tight timeline.
I mean, we're talking about days, not months, and you know, for a lot of organizations, they're not really well set up for that. Uh, and I think that that's, that challenge from a procedural standpoint is ultimately the thing that's going to make or break a lot of organization's ability to be able to be compliant with this mandate. Do you think gen AI has a role in all this?
Because in theory, I can imagine maybe using it to create summarizations of incidents and, you know, just generally process and accelerate the whole thing. I mean, it certainly possibly could. I mean, you know, AI and, and specifically generative AI has lots of promise and there's, you know, lots of people that, uh, lots of organizations that are trying to build that into various capabilities and software that they've already got.
Um, you know, I kind of think about it al almost like, um, you know, you did, uh, think about the cloud over, you know, during the 2010s in the sense that it's less a of a feature and more just something that is a fundamental part of the way that all software and, you know, IT technologies are evolving to include those capabilities. Um, you know, you could imagine that there's, there's definitely potential for generative AI to be part of an incident response process, as you said, maybe to summarize an incident or to be able to, you know, to look at all these different alerts and make decisions upon which ones appear to be more material than, you know, than the general background noise of, you know, account lockout attempts and things of that nature. So there's definitely that possibility there, and I think a lot of vendors are already doing work to try to embed that into their products.
Um, but at the same time, you know, ultimately there is a, uh, a human risk management element to this that I don't think any corporation is likely to be, you know, uh, outsourcing to software anytime soon, which is to say, okay, if, if if something, maybe an AI or, you know, maybe just my own sock has told me that there's been an incident and that they feel that it has met whatever, uh, threshold of materiality that they're responsible for, what do I do after that point? You know, how do I message that? What do I disclose?
You know, do I try to be as open as possible about that? Or maybe, you know, do I try to conceal some of the information because of I'm concerned about the brand reputational risk and so forth? Those are all kinds of questions that, you know, have a very important human element to it.
And while JI considerably be a, a helpful aspect there, uh, ultimately it's still gonna be a complex, you know, combination of people, process and technology for organizations to be able to meet this bar. Is the stress level gonna go up for everybody? 'cause it seems like to me that the attacks are increasing in volume and sophistication, and now my time for which I need to respond to has narrowed considerably.
And to add a little insult injury, I gotta fill out the paperwork faster too. Yeah, well, I mean, like, you know, think about it in your own personal life, if, if, uh, if, uh, a police officer shows up and you know, potentially could arrest you and you could potentially go to jail with that, increase your stress level at any, you know, at any kind of interaction probably. So, um, you know, and not to, you know, not to overplay it, but I mean, there have been, you know, pretty publicized incidents that where, where that kind of thing is exactly occurring.
Um, and like I said at the, uh, to an earlier question, I think one of the big challenges here is that sometimes the people that might be held accountable, or at least partly held accountable for an organization not meeting that bar, ultimately are not the people that have the final decision making authority on whether or not to, to, to do some kind of disclosure. Right? And that's one of the reasons why I think it's, it's gonna be so important for organizations to be able to, you know, clearly establish a process for how do you triage these incidents?
What are the thresholds internally, what roles do individuals within the organization? Again, it's not just security or it, it's, you know, everything from HR to corporate communications to, you know, risk management and so forth. All these different parties need to work together.
And if you're trying to figure that out the first time that an incident occurs, it's almost certainly gonna be too late for you to be able to meet that requirement. So organizations need to chart out what that looks like ahead of time. They need to design a process for that.
They need to have ways to measure the effectiveness of that process. They need to know like, are we actually following that? Or all the different parties that play these different roles in it or they meeting where whatever their requirements are.
Um, and another aspect that we haven't really spoken about a lot is think about today how much reliance there is on outsource providers as part of your tech stack. You know, lots of organizations have outsourced their SOC to some kind of, uh, you know, managed detection and response provider or maybe outsource their security operations and, you know, in whole or in part to, to a security services provider in those cases, it's not just you internally what your own staff is doing, but it's also like, are all those other stakeholders that you're paying as vendors to do this work? Are they meeting whatever requirements that they have with it?
And so it's gonna be really important for organizations not just to have a plan, but to have a way to measure the effectiveness of that plan when it's put under stress by an incident actually occurring. Um, you know, and organizations in security have always had these challenges around, you know, process adherence and making sure that you're actually following through with, you know, with the requirements and the policy that you've got in place for kinda all aspects of your operations. But it's particularly important now around incident response, because again, there is that aspect of personal liability that's involved.
Now, Are we holding the wrong people accountable here? Because the cybersecurity people, to your point, weren't the ones that created the chaos in the first place. They got exploited, and they've been telling people for as long as they can remember to not allow that to be the case.
And when it is the case, they get blamed for it. So it seems like it's a lot of accountability without much authority. Yeah, I think that's one of the challenges with, with any kind of, uh, you know, regulatory policy is, is, you know, are you holding the right parties accountable for actions?
And are those parties actually empowered to take the actions that they need to, to be able to meet whatever that regulatory PO policy is? And you know, that's not unique to security, but I think something that exists in, you know, many areas of, you know, of corporate, uh, operations and, and legal, uh, responsibility and so forth. I think for, um, you know, for security, the question you ask is really, uh, a, a very appropriate one, which is, you know, if you're the person who's responsibility is security operations leading the security organization and, and you know that these things are deficient within the organization and could lead to a potential problem, you know, I think now it's gonna be increasingly important again for you to clearly document that, to make those statements in an unambiguous way, to have some way to record that, you know, that you have communicated that and you know, stated the need for improvement or investment in those areas.
And that when there is an incident, that you have a clear way of, again, communicating your opinion on the materiality of that incident, the necessary, you know, steps that the organization should take, potentially even including disclosure about it if it meets that materiality threshold. And, and that, again, that kind of procedural aspect of security is something that oftentimes has not been part of the culture of security organizations that tended to be a lot more, you know, technical focused on like the, you know, the, the bits and bytes aspects of doing it, incident response and forensics and so forth, which is still important, but may not have had as strong of a role in the larger risk management and compliance activities of the organization. I think that role in risk management compliance is becoming increasingly important for security leaders.
And, and I suspect that we will see security leaders maybe have some of those staff internal to their organization, or maybe even you'll see more of a selection of people with more of a risk management and compliance background being put into security leadership roles because of these kinds of requirements. But I think your, your question is, is a very good one, and it's, uh, you know, it's very, uh, appropriate because you, you do have a dynamic here where the person who, who might be most responsible, or at least most central to that investigation, potential disclosure, is ultimately not the one that makes the decision on what actually is disclosed or whether or not there even is a disclosure in the first place. Do you think we'll see something of a cybersecurity professional flight to the privately held companies because, well, the noise level is just too high in the public companies.
I think that's, I think it's possible that you will, I think it's also possible that you'll start to see CISOs have compensation packages that are reflective of this degree of risk and that, that have some way to kind of compartmentalize the risk. You know, if, if there is some breach and you know, you as the leader warned about this or you know, warned about this being a potential problem, um, and the organization didn't heed your advice, that maybe that's, you know, somehow factored into some severance that that might occur in the future. I think this definitely opens up a lot of different, uh, scenarios and questions because the, the nature of the role is changing fundamentally.
I think once you start asking people to take on that personal legal responsibility, you know, their view of that job is gonna change significantly. 'cause it's no longer about like, you know, I'm, I'm trying to do my best to install updates and, you know, have the right firewall rules and so forth. But if there's a problem like, you know, ultimately I'm gonna try to respond to that to the best of my abilities, but I'm not worried about, you know, potentially going to jail for that, you know, whereas now in the future, it could be something where even if you do all the things that you can personally control, right?
If your organization ultimately doesn't choose to, to do what, what it's supposed to do from a corporate standpoint, you know, you might hold some of that legal responsibility. Whether that's right or wrong, it's, you know, you still might do. And because of that, it's, it's, I think, even more important for, for you as a leader to structure like, you know, again, your compensation package, but also like, as you were mentioning maybe even the industries and the companies that you work for.
I think a, an organization that has a history maybe of, uh, being less than forthcoming about disclosure and may seem something that that's more likely to be risky for you as a CISO to work at, may become less desirable and must have to pay higher than market rates to attract the right people. Um, so, you know, I think what you see this occur across lots of different industries and lots of different kinds of regulations that, you know, probably that'll eventually, you know, kind of get washed out in the market as organizations figure out what is the right equilibrium for pay and to attract the right people and so forth. But there'll definitely be some uncertainty and probably some, some churn and change in the near term as that gets sorted out.
All right. So what's your best advice to folks? 'cause clearly, um, the rules of the game are changing, so how do I kinda adjust in a way that makes it reasonable for me to succeed?
Yeah, I think, I think the first thing again is to have a clear understanding of what the thresholds are in your organization, a clear plan, and that includes all the different stakeholders that are involved in that plan. So you know everybody to know what their responsibilities are, and for that to be something that you have tested through, you know, tabletop exercises or you know, other kinds of simulations before you actually experience an incident that might meet that materiality threshold. And then to have a way that you can really measure the effectiveness of that process over time.
Not just the tabletop exercises, but actual incidents, whether or not they result in disclosure or not, to be able to make sure that all the different parts of that process are working together. I mean, ultimately, as it's always been, security is about people, process and technology. And I think with these kinds of regulatory burdens on security leaders, it's even more important to make sure that your organization is working effectively.
Again, not just the technology that might find the problems and help you contain them, but all the people that are involved in that, that response, how do that all work together as part of a process? Can you identify where the problems are? Can you measure their performance of it?
And can you make sure that ultimately your organization is able to effectively meet the requirements to detect and triage and disclose incidents within that timeframe. All right, folks. You heard it here?
Yes, indeed. The goal posts have moved and you need to respond accordingly. John, thanks for being on the show.
Thanks for having me. And back to you guys in the studio.