Measuring the Value of Cybersecurity – Grant Gibson, CIBR
CIBR CISO Grant Gibson explains why organizations need to change the way the value of cybersecurity is measured.`
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Grant Gibson. Who is the siso for cyber? And we're gonna be talking about cybersecurity return on investment and value and how to measure all that good stuff Grant welcome to the show.
Thank you. It's great to be here. A lot of organizations seem to be struggling with this whole concept.
I mean Roi cybersecurities always been elusive because it's like proven and negative. But at the end of the day, we're at a point right now where people a little more sensitive to cost in general. So how should folks go about thinking about measuring the value of their cybersecurity Investments, and maybe what should they be thinking about to get more out of it?
Right. It's a great question. And and I like I like to put it in the framework of sales sometime because businesses have a great idea of how to Value sales, right?
Because it drives Revenue. It drives the business. So we have a lot of metrics in place.
We have metrics that are for the board. We have metrics for this sales leaders. We have metrics for the sales team.
We have all these metrics designed to push sales forward to generate growth and and if we're not seeing growth then to strategize on how to deal with that. We don't always have the same visibility in the cybersecurity because like I said, it's it's a negative right cybersecurity is usually coming to say hey, we've got these things we need to spend money on to deal with right and we're not going to generate Revenue off these ideas. So it's it's a tougher conversation with the board of directors or budgeting committees or or any different way that goes to have and and so but finding ways to do that is what's going to drive more security for your organization.
But why does your organization need security right? That's that's the big thing. Why do we need how much should we invest in it?
And I think you have to start by quantizing like shooting. I think you have to start by looking for something that is positive and your data is positive your data is what runs your business. And being able to put value around your data can help you make business decisions on how to spend money on cybersecurity how to metric out your cybersecurity program so that you can deliver good reports to people about where you are at in that program.
And when you think about that data, you have to look at it in different ways. You have to look at your data how your data is what your data means to your business, right? So there's data that your customers provides you there's data that you collect there's data that's important to you.
There's data that's important to hackers what Dad is important to hackers? And how valuable is that the hackers that that's a part of that equation too, right? What's the value to you?
What's the value to your customers? What's the value to the hackers out there? And then you have to kind of think of it from a risk management standpoint because that's what cybersecurity is at the end of this risk management.
So it's taking the how valuable I think my data is to me right what happens what that kinds of data. Do I have? What happens if that data is compromised or lost right in the case of ransomware attack?
You might lose that or at least have it locked up, but what if that's all your leads and you can't call anybody and do business. How is that valuable to your organization if you can't reach out to your to your contacts into your leads into your customers? That can be pretty damaging right especially it goes on for extent for your time.
If you're talking about a couple hours. Okay, you can recover from that. But if you lost access to your data for a month You can't contact your customers because you don't know who they are.
You can't contact your new leads because you don't know who they are. That's a very valuable proposition to a business and you have to be able to put it in line in perspective to understand how you're going to protect that right? That's the worst case scenario and that's where the risk management comes and you take that Dad a point you say?
Okay. I've got this data point. What's the likelihood that I could lose access to this data versus what the damage?
if I lost access to this down to this data point To this data and then you have to be able to say okay. This is a really big concern. We should really be spending some resources making sure that this particular thing doesn't happen.
It's also important to look at it from the hackers perspective when you're looking at that right because a lot of times today we talk about social security numbers is being like penultimate of getting of a hacker getting into our system and get Social Security numbers for for our customers, right and that that's a big data breach because now we have to go to our customers say we lost our social security numbers. A big deal to your customers, but not nearly as big a deal as if you're in businesses that collect other type of data like healthcare, right your medical records. If you're in the banking industry and you're dealing with loans, you're collecting pay stubs and identification and tax transcripts and in some cases maybe even medical records because you need to prove something happened at some point that this is a way something is for a loan.
If hackers get a hold of that, you know, that's the kind of data that gets you a mortgage. Not just not just $100 Quick Loan off the internet, which is social security numbers gonna get you right and so looking at the data you have and saying well, how valuable is this to a hacker? How valuable is this to my organization to run how valuable is this to my customer if it gets leaked and then you can start making those risk-based decisions you've Quantified what you have that you're trying to protect and now you can quantify metrics around how you're going to protect it and there's a lot of ways out there to do that.
But you have to start there you first you gotta what am I protecting? Why is it important? So a long time ago there was this German Emperor Frederick the great said, you know, if you try to defend everything you wind up defending nothing.
So is this kind of the same conversation but we need to figure out what data matters most and kind of work our way out right now. It seems like historically we just kind of fortifying the perimeter, but you know that became just in defense Right and that and that that's kind of the truth, you know, it's a lot of the other problem with metrics inside of the system and why is you negatively is because what is the board want to hear the board once here? We're not going to get hacked.
Well, that's impossible. Right? Nobody can guarantee you you're not going to get hacked.
There's no company out there with security so good that they can guarantee. They won't be hacked. And and that's challenging because that's what the board wants to hear.
When you go and present metric to them. When you report on your cybersecurity program here. Hey, we're in good shape.
Nobody's gonna hack us and and that's what they want to hear. But that's not something you can necessarily give them right? You can't tell them we're not going to be hacked you're gonna talk about the things you've done to prevent that hack which is what we should be doing.
Um, it's it's a challenging thing and it's not just the perimeter, right? You have to look at the different pieces of the puzzle that get you there. Technically we have very good reactive ways to measure security.
We can say hey to the board. We have the five nine. So you many many cios out there gonna be familiar with five nines.
99% of time, right? And can we look back at last year and say we had that up time and it wasn't because and we didn't lose it because of a hack we can say hey we're doing our job. That's not a good predictor, right?
And that's why we have metrics. We don't necessarily just have metrics to see how we performed. 99% up time last year.
You didn't have a major hack that doesn't mean that you won't have one the next year. So it's really drilling down into those risks and start looking for what that is important to me. And how am I going to protect that particular data, right if somebody does get in can they get to this really important data?
Right who's protecting that kind of data and those are really important conversations that I teach teams need to have with their different departments because it might not know right it might not know what's important to a different department accounting may have a different idea of what's important data then sales does or compliance does or the various other opportunities that they're out there for the hackers to get into right? They need to really dig down into other departments and say, okay, where's our important data what's important to business operations and then start risk managing that and saying okay, we're gonna start here and set up a program for these and we're gonna work our way back and there's the general stuff too. Right?
You got to have good firewalls in place. You got to have limits on what can come in and out of your network, but you also have focus on specific segments. The tough part about being in the security space.
Of course, is that the bad guys only got to be right once and you got to be right a hundred percent of the time but how shared organizations think about evaluating cybersecurity people. I mean because there are going to be breaches. So how do I kind of take an assessment of this into your point come up with some metrics that are fair and reasonable?
Right. I think I think you literally have to stop looking at it as a fact that we're going to prevent all the attacks, right? We've got to change the board mindset that we're going to prevent it.
It's got to become about mitigation. To prevent the attack or if there is an attack prevent the this the breadth of the attack. So how much data do they get where they get?
What were they able to do? At the same time you have to have the conversation that we also need to focus on. Detecting these attacks.
We also need to focus on responding and recovering from these attacks because attacks are going to happen. There's not a lot of companies out there that have had no type of reach whatsoever. Maybe it was spam.
Maybe it was fishing. Maybe it was a small malware incident. Maybe it wasn't a major cyber security attack.
But you've probably experienced an attack at any size organization at some point. You certainly had somebody attempt to get into the organization. Right?
If you've got phishing emails from somebody in a foreign country trying to get you transfer them funds that's a type of attack. Right? So we've all experienced that low level attack some of us experience higher level of tax and sometimes those are attacks are successful.
We can't look at it as we've got to get over this because we are being attacked you're being attacked. I'm being attacked. Some of them are successful many of them are very small but that's happened.
So part of it is just understanding. What's our attack. What are what is our attack surface look like and that's not just from the perspective of how can people attack us.
That's how are we being attacked? Right and start having metrics around that how are we being attacked? What are we seeing and then we can go into whether they were minor or major and start having that conversations because that will help that will help organization change their perspective from we're trying to prevent this attack.
And if you didn't prevent this attack, your job should be at risk to this is how many attacks Mitigating every day every week every month. This is how many are getting through. This is the severity of those attacks.
This is what we're worried about next in those attacks. And this is where we need to shift our focus and that's where people need to be. We talk a lot about the shortage and cybersecurity Personnel, of course, and I guess the question that comes to mind is.
Does this level of attention to the metrics though, and to the stress which then burns more people out and then we wind up with you know, a lot of good people even the space and you know, is this becomes something of a vicious cycle? Well, we're not gonna get over that hump anytime soon. It does.
So listen, we can't not have metrics in this industry. It's not it's not gonna work. We're a data driven Society.
We're a data driven Society for a good reason. It works. It's effective.
It needs to be a part of the industry, but it is going to increase stress because we're really going in with good data to say hey attacks are down this year as a whole 20% right? If anything a tax go up every year right that's never gonna be there's never gonna be a time anytime soon that I know of we're attempts or not made right and it's gonna be tough to continue to have those conversations gonna be stressful, but we have to do it the problem. I think what we need to do is we need to be realistic as the cyber security Community with our counterparts in accounting and Leadership and compliance and all these other departments that we may work with that that we're going to go through a tough period and these numbers are not going to look good.
And we have got to get our hands. We've got to get our hands around them though so that we can get to a place where we do feel more comfortable and we do feel more confident and I would say that if you are a cyber security person that's in an organization where you're very confident in your cybersecurity. That's probably not a good thing because you're probably overconfident in your cybersecurity.
And if you're bored once if you're bored wants to be confident about their cybersecurity, they might be overconfident in their cyber security and that's not necessarily a good thing because now you're not preparing for what's going to come and something is gonna come in some form and hopefully you're able to mitigate it but it is and and there's just no quick solution for this right? It's it's a stressful field. You know, how different are you from a police environment?
Well, your life may not be in danger every day, but crimes not going away police have to deal with these stressful environments every day that they're going out to stop crying and and it's not going away and the metrics aren't going to get great and there's always going to be crime. Cyber Securities in the same place, right? It's a tough job.
We've got to deal with it though. Because if we don't it's not just our organization's data. That's it's our data, right the organization has my data.
Because I work for them and no matter what organization I go to that's gonna be the case. The economy depends on all organizations to do. Well, right if all the organizations are struggling because we're walking away from cybersecurity that's not going to help us individually as well.
Right because we're gonna find stress from other player places is our data gets released and and different things like that and and it can hurt the economy unless other things so, you know, it's just a tough place to be and I feel for you in the cybersecurity world. I understand it's a tough place to be it's tough to present these numbers. It's tough to try to put up metrics.
It's tough to try to work with the budgets that we've got in today's environment, but we've got to make the best of what we have because it's important and the attackers are not going away. They're gonna continue to try we've just got to do our best to get everybody on board to create a good cybersecurity culture. And that's an important part of this.
Do you think we can win this battle? I mean is the playing field? So uneven that we're just fundamentally disadvantaged or you know, I know are the bad guys getting better and smarter or you know, what's your assessment of the current state of things?
I I you know, can we can we win this battle and that's trick question. You can't you you can't stop cyber security depends your definition of win right cybersecurity tax no longer exists. Never gonna happen.
You can't win that battle. Um for me it comes back to this idea of culture culturally. Do you have an organizations that cyber resilient right do they mitigate?
Well, do they reuse detect they respond they recover. When and a lot of that's not just in your policies or your technical compliance or things a lot of that's in the culture. 95% of cyber attacks are generally caused by human error.
Now this is a broad term human error, right this can mean we didn't patch things on time. This could mean we didn't see a vulnerability. This could be in someone in a department that has nothing to do with security clicked on an email link or gave information out over the phone or recently.
We've seen hacking groups tend to bribe employees that are struggling to get paid gas money $250 to get their password and their multi-factor authentication how security team stop that how scary team stop and employee who struggling for gas is being an opportunity dollars to offer the username their password and then give them the multi-factor authentication code. They got on their phone. There's no way that the security team can be a hack like that.
but When we start measuring the culture of cybersecurity within our organization do people recognize fishing and tax. Are they trained? Well, do they know they need to protect their password do they know that they're potentially compromising themselves when they share this information right that they could then in turn be hacked do they understand the risks and their responsibilities and the impacts on them personally if these things happen and and as we get that better cultural awareness, we will reduce a lot of tax because again, it's not because our firewalls are failing necessarily.
It's not because our scene tool didn't tell us it's not because we didn't have access to the patches necessarily doing is it's human error that's creating them opportunity most of the time and so as we do things like that we can start to get to a place where we feel better about cybersecurity where We do mitigate a lot of attacks and we do make it much harder for the hackers to get in is it gonna go away and stop? No, we're not gonna win that battle, but we can reduce it a lot as as we organizationally as we culturally adopt better cybersecurity with on organizations. We hear a lot about all things AI these days is AI gonna save us from ourselves.
Is this some sort of maybe not a silver bullet, but certainly something that will level the playing field. There is a more hype than reality. AI Is going to be an amazing tool.
How powerful it's going to be and when it's going to be that powerful is hard to understand right because we're in the infancy of AI I I watched last year and somebody was telling it was somebody's talking in an election not too long ago about how mature cybersecurity was getting and it is the type of security is mature at this point. It's been around since the 80s. We still got a long way to go, but it's mature AI is not mature.
It is in its infancy and it's going to do a lot for us and it's going to catch a lot of things but how and when we get to a point a pinnacle point where it's good enough? That we don't need humans. Nobody can predict that is that going to be in 10 years 50 years 100 years.
We don't know. But it is going to get to a point where it certainly very helpful in the near future right? It's going to do a lot for us in the new future.
But again, how does AI detect That someone's been bribed to give up their credentials and log somebody in with their MFA. It's gonna be a long time before AI can detect that we do talk a lot about identity management and bringing AI into identity management to see that you are who you say you are is gonna do a lot for us, right because they've got AI now that can notate that you are who you are based off the way you type on a keyboard. Right.
So if you're not the one typing and we can tell that you're not the one typing. Well, you're not the identity, right? You're not the person we thought you were and we can lock you out and do different things like that.
So there there are so it's gonna it's gonna make significant advances for us in the short term. But is it going to get rid of? Our need for humans to be involved not anytime soon.
You know, I think we're still pretty far away from that. But I think I think it's gonna help. I think we're gonna get good at it and just a matter of one.
All right. Hey Grant. Thanks for reminding us to have a little empathy for our friends in cybersecurity.
Absolutely. All right, and once again, we hope to have you back in the show one of these days soon. Hey guys.
Once again, thanks for the time and back to you guys in the studio.