Overhauling Third-Party Risk Management – Laura Robinson, RSA Conference
The consensus within the Executive Security Action Forum (ESAF) community of chief information security officers (CISOs) is that traditional third-party risk management in information security is ineffective. The need for change is growing more urgent as attackers increasingly target third parties.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
You know, it's starting to sound a lot like Christmas. Well, starting to sound a lot like it's r s a season. And this year actually, r s a season's a little later than last year.
A little later than maybe, I always knew it was r s A conference 'cause they used to do it during my anniversary, which is February 25th. And so the end of February was r s a season This year. It's actually May though.
So good news for my wife. I'll be home for my anniversary. Um, good news for the rest of us though.
This is gonna be a bang up year, I think for r s A conference. It may be maybe, maybe their biggest one ever from if other in-person events are any indication. Right.
We could be, well look, last year, Laura, I think there were 40,000 plus people at R S A. I know. Yeah.
Yep. So no reason it shouldn't be bigger this year. Anyway, let me intro.
Speaking of R S A conference, let me introduce you to Laura Robinson. Laura is the program director for the R S A Conference, executive Security Action Forum. E S A F.
She's gonna tell us all about it. Laura, welcome back to our show. It's great to have you on.
Thank you so much, Ellen. It's great to be back. Absolutely.
So, Laura, before we get into the E S A F and we talk more R s A, let's hear a little, I, I remember you, you kind of invented this E SS A F for you were there, you know, pretty much in the beginning. From The beginning, yeah. Almost from the beginning.
That's right. I've been doing this for almost 20 years. Geez.
So, E S I F stands for the Executive Security Action Forum, and I'm the program director of this group. And I'm, I've been in information security actually for more than 20 years, so obviously love it. And, um, I work with CISOs.
That's pretty much what I've done through most of, uh, my career and information security. I help them address their common challenges, and that's what ESEF is all about. We have our annual meeting at the R s A conference every year.
We have virtual sessions throughout the year, and it's really a place where CISOs can come and share information candidly, because as you know, Ellen CISOs have incredible challenges and they really appreciate peer-to-peer conversations to figure out how they can address threats and digital transformation and new regulations and that sort of thing. So we also, besides that, we have recently decided to start doing reports as well. This is our second report that we're here to talk about with you today.
Absolutely. Typically, our sessions are confidential, but the, the CISOs in the community really wanted to start to get out the information that they have to the larger security community. So we've been offering that knowledge through these reports.
Absolutely. And you know, it, it, it's almost two different missions there, but both of them are equally as important. Yeah, right.
CISOs need a place to network with their peers in a, in a safe environment. Exactly. Right.
Because so many of the issues they deal with, we, you just can't talk about publicly. I mean, no, a it violates all kinds of things. Bs b it can make you susceptible to, you know mm-hmm.
Kinds of attacks and so forth. And CISOs need those safe places to communicate. Yep.
On the other hand, the world at large needs to understand the knowledge these people are gathering and the experiences they're having and their advice to the rest of us. Exactly. And, you know, so that's equally as important and that, that has become the, the reason, you know, the reason for being of this report.
I remember we had you on last year, it was the first, uh, report. Yep. It was a great report.
I'm glad to see it, you know, continuing through this year. Mm-hmm. Um, give us a little background.
Is the report available at this point or? Oh yeah. Yes it is.
We released it last week and mm-hmm. Um, it's all about transforming third party risk management. And this is a pretty hot topic right now because so many organizations are getting hit with cyber attacks.
And from these CISOs perspectives, they're CISOs at very large enterprises, fortune 1000 enterprises. And as their suppliers and business partners are getting hit with cyber attacks, it affects them because they're connected to these companies. They share information with these companies.
So it's all about transforming the way those risks are being managed because it's not, um, effective the way that companies have been doing third party risk management for years is really not effective and they're trying new things and they wanna share that with, with others, You know, and Laura, the whole third party risk space has kind of been turned upside down for many of us old timers. Me, yeah. You know, third party risks sort of, uh, personified was the, the target.
I don't know if you, you probably remember the target breach years ago. Oh, absolutely does. Yes.
Where it was hvac, remember it was an HF factor contractor. Yep. It was HVAC system mm-hmm.
Who had access to this flat network. So when he got hacked, bang, the hackers had the entire target network at at their mercy. Exactly.
But today, you know, when we talk about third party risk management, we talk about things like software supply chains and SBOs and a p i security because our code today, our technology is so interconnected. Yeah. No one sort of owns the whole stack anymore.
We all it, there's dependencies in everything we do. Mm-hmm. Physical Exactly.
Code everything. And, And these companies are connected to thousands of, of suppliers and business partners, and many of them are SMBs, typically. They don't have really sophisticated cyber defenses, and they're, they're struggling with security.
So part of this report, um, talks about helping those companies actually develop better security. Absolutely. So give us, I mean we only have 15 or so minutes, Laura.
Sure. But if you can give us the highlights of this year's report Yeah. And what people, you know, might wanna latch onto here.
Sure. So the report is based on discussions amongst the CISOs in the SEF community over a period of a few years actually. So what's been happening is CISOs have been coming to esaf and talking about really innovative approaches in third party risk management.
And they're, and some of them, these initiatives are at very early stages. So they're getting feedback from their peers. What we did is we, we documented all of those conversations and we built out these six case studies.
So these are very large enterprises, some of the world's largest enterprises, and they're doing new innovative things in third party risk management that, um, we also have summarized within the report. So you get the six case studies. And then we summarize what we found from those case studies is there's this pattern of new approaches kind of emerging.
So we've laid out seven types of new approaches, and so people can really understand how companies are moving. These leading companies are moving from the old approaches, which really focus on assessment to new approaches, which focus on broader risk management strategies. So, fantastic.
I could get into a couple examples of the new approaches. Go ahead. We got time.
Okay. Alright. So for example, um, I'm, I'm actually gonna just talk about how the new approaches kind of differ from the old approaches.
So, as you are probably very familiar, Alan, and I'm sure people listening realize is typically the way that companies manage third party risk is through self-assessment. So they send off a self-assessment questionnaire to their third party, and often it's hundreds and hundreds of questions long. They also use the cybersecurity rating services and they get some sort of score for the security posture of that company.
And then sometimes they ask them for a compliance framework report like a SOC two report. Very common. But the, the seasonals in our community don't think that those things are managing the risks.
So instead of focusing kind of on the assessment, they're moving into their giving their, their, um, third parties, very specific security requirements, sometimes boiling it down to like 10 or 20 Look, focus on these. And then they actually validate that those companies have put in place those requirements. And then instead of chasing them around the questionnaire, Hey, did you get those things remediated?
They actually help them get technologies services. Some of these companies have actually extended their security program and are, are delivering security services to their supply chain because they're so concerned about their supply chain being secure. They're actually offering them services to help them be secure.
Excellent. So that's the sort of thing that the, that they're, they're just doing very different approaches to the assessment focus. Yeah.
And, and, And I, I, I will tell you, Laura, you were talking and I was sighing because I, you know, look, partner, partner well, because we partner with a lot of tool vendors. They're our primary sponsors, right? Yeah.
We have people who consume our content, and then we have tool vendors who sponsor a lot of the content. And, you know, many of them send us those third party reports and they are voluminous The long questionnaires. Yes.
Oh, spreadsheets. I, you know, it, it keeps, and it's, it's like busy time work for, you know, some of our people here, I, I hate giving them the assignment, but it needs to get done. 'cause they won't pay you without them.
Right, right. Um, but it got to the point, Laura, where it became like boilerplate template kind of stuff. Exactly.
And yeah, we weren't even paying attention. We're just filling in the boiler plates. That's what's happening.
Yeah. Because you're getting doesn't work so many of them. Right.
You Can't actually answer them really meticulously. No, You gly what I still got last time. Yep.
It's just, it's too much and Right. You're just checking the box. We need a better way of doing it.
Yes, exactly. So that's what these CISOs are finding better ways to assess their third parties, better ways to validate that those third parties have security in place. And then also they're putting more specific requirements and incentives and enforcements in the contract.
So you, you know, speaking of boilerplates, the contracts used to be very generic, very generic security requirements. You have to comply with regulations and standards. Companies are now getting more specific, even tailoring the requirements to the type of third party.
Mm-hmm. That's interesting. We've seen some of that in contracts more around data collection.
Oh yeah. Right. Companies are very concerned about their data collection techniques and, uh, notices to individuals and stuff like that.
And, and look, we try to be transparent. Mm-hmm. Uh, that's kind of my philosophy on these things.
Right. Don't, don't hide stuff. Don't, if that information is gonna be moved on to a third party, make sure you say it.
Exactly. No surprises. Um, Yeah.
And um, actually part of, uh, another new approach that they, or not really new approach, but something that they're really focusing on is protecting their own organization from these third party incidents, because you kind of assume they're gonna happen. Companies are gonna get hit with cyber attacks. So as you know, in terms of data protection, as you're talking about, um, part of protecting your own company from third party incidents is to make sure that you don't share too much information with third parties.
So they're really reining it in, reigning it in in terms of what they share with third parties. And then they're putting in place incident response plans that will be able to do things like swap out a supplier. If one supplier is down, they can quickly swap out to have another supplier in place so they don't have business disruption.
Sure. So that's the kind of things they're putting in place. Yeah, no, I, I could see that happening.
You know, over the past year or so, we've seen several different kinds of, of, uh, third party events that have had impact a lot. Yes. Yeah.
Well, there's been a lot. But like for instance, one involves sort of, uh, Okta, which is a huge company Oh, right. Big in, uh, in uh, uh, identity.
I a m identity access management, you know, they were the victims of a hack. Others in the space were as well. And look, it's gonna happen.
I don't blame a company for getting hacked unless they're, you know, but it's gonna happen. But what happens is companies who use those products now find they're vulnerable. And what we've seen is that the hackers are using these companies like an Okta Exactly.
As a, as a, as a means into a larger target that they're really targeting. Exactly. Solar Winds is, I think, I guess another example of that.
Yep. Um, and that's definitely A tactic on their part for sure. Yeah, no, that's a fact.
Go after that's an factor Because they could be, it could be a big jackpot if you get in there, you're gonna have access to a lot of companies through their products. You know what, you go to those third party webpages and they say, these are our customers. And you say, Hey, that, that's someone I want.
That's right. So if I get into this guy, I'll get to that guy. Yeah.
Unfortunately, yeah. That's, that's kind of the world we live in. Mm-hmm.
Now, you know, mitigating that risk again, you, you, you do the best you can by limiting the amount of information, you know, zero, zero access and, and all of these things. But you know, it, it's the world we live in. We, we live in such an interconnected world that, that we, we, we, we have to do it.
That Laura, the report you said came out last week. Yep. Where can people go get a copy of it, study it.
Yep. Download it maybe Is on the RSA Conference homepage. Actually, if you just scroll down, there's a banner if you want to access it through the essaf website, it might be good 'cause you'll learn a little bit more about us.
com/esaf. That's another way to get to the report. And I also wanted to mention that the call for speakers is out for R S I conference and it's going to be available, um, until October 6th.
So if you wanna submit something, get it in by October 6th. At least October 6th. They've been known till extend it, but don't count on it out there.
That's right. That's true. But you know what, so many, so many friends of mine and people I know in the industry, I got their start really becoming, you know, kind of known in the security industry from submitting and speaking at R say.
So I, I, I do highly, highly recommend that. Um, you could, you could submit as a single speaker, you can submit panels, dual, you know, multiple kind of people speaking. It's a great, great thing to do.
I did it years and years ago. I'm hoping this year we'll be doing our DevSecOps event on Monday of r ss a week again this year. Yeah.
We'll have a, a speaker submissions for that shortly as well. Laura, what about those CSOs watching this out here and who say, Hmm, I'd, I'd like to be involved with E S A F. How, how would, what's their best path for that?
Members Of the forum are, um, strictly CISOs a Fortune 1000 organization. com or sorry. Absolutely.
I forgot my last name. com. There is only one Laura there.
That's right. I'm kidding. Yeah, of course.
Yeah. Excuse me. com.
If you are, and again, you must be a Fortune 1000 cso, but if you are, there's a great forum. It's a great Yeah. Uh, group to be part of.
You guys do have meetings during r s a week, but then you also have sort of virtual and other meetings throughout the year. We just have one last year as well last week. Yep.
Yep. Other just kind of housekeeping stuff. You mentioned the call for speakers is open.
Yep. Registration opens I think in October. In October.
That's right. And the, For the event in May this year. Right.
It's, uh, the week of May 6th. Yep. Uh, sixth to the ninth I believe it is.
And uh, and also I guess sponsorships are still available for any vendors out here who want to sponsor or, you know, service providers who want to be seen at R S A. You can also do that on the R S A conference website. Yeah.
You Could go through the R ss a conference website if you're interested in that for sure. Yep. Fantastic.
Laura, thanks for all you do all year round Yeah. To making the E S A F what it is. A a great organization.
Thank you also for, and, and the members for this report, I'm sure a lot of people out here will, will gather a lot of good intel and a lot of good advice from it. Yeah. Forward to feedback you.
Absolutely. Hey, we will again, hopefully be streaming May at r s A conference from broadcast Alley. Stop by say hello and, and maybe we can get an update.
Okay. Great. That sounds fantastic.
Thank you so much, Alan. It's always a pleasure to have you on. Laura Laura Robinson, program director r s a Conference Executive Security Action Forum.
E SAF f Their second annual Executive Security Action forum report is now available. You can get it right on the R S A conference website, scroll down or go to the E S A F site. Um, and call for speakers is open.
If you want to talk at r s a, get on it. It's only till October 6th. That's right.
All righty. Hey, we're gonna take a break here on Text Drunk tv. We'll be back in just a minute.