Privacy and Compliance in 2024 with Terry Ray of Imperva
Terry Ray, Imperva SVP, data security GTM and field CTO, shares the common data-related requirements prevalent in many privacy laws and key steps organizations should take to prepare for data privacy regulations in the coming year. Terry explores the California Privacy Rights Act (CPRA), increasing privacy regulations by U.S. states and GDPR. He also discusses early activity in AI guidance coming from governments and considerations for a future with AI regulation.
Transcript
This is techron TV With the great pleasure today being joined by Terry Ray. Terry's been with us many times. Enjoy talking with Terry, with, he's with Imperva, SAP, data security, go to market and failed CTO.
Hey, how you doing? I good, Good, good. You know, we're, we're, we're kind of hitting towards the last part of 2023, which means we're always looking forward, right?
What do we gotta get ready for for next year? We're already doing all that stuff. Security people, we're thinking about other things, right?
There's a, like privacy and new security threats, all that kind of thing. And I know you're, you're well-versed in, in, in what's happening in the privacy space, you know, both us and, and, and globally. So appreciate your thinking about what do we need to be preparing for.
Yeah, absolutely. I mean, it's, it's one of these things that we could have this conversation, and maybe we do have this conversation every year because something changes every year. Uh, but yeah, this, this is a conversation that is a recurring, iterative process, just like every single regulation that's out there.
Mm-Hmm. Uh, there's a lot of things I think that, that we want to be thinking about in terms of, uh, security practitioners, risk practitioners, auditors, compliance, whatever organization or group you find yourself in, where privacy, which in my world fits right under the larger umbrella of just standard, regular, everyday regulatory compliance. Could, could you have to do a lot of the same things.
You have to start thinking about some different things. And I know earlier in the year, we talked a little bit about CCPA, CPRA, whatever we want to call it, but we wanted to have this, I I wanted to have this chat, and I'm, I'm, I'm glad you you're having it as well, because I wanted to be able to bring this up and, and, and remind people that as we move into 2024, these things are still alive and there's more and more regulations that are in fact coming here in the United States. And of course, if you're doing business overseas, if you're doing business in South America, central America, just about every, uh, uh, nation in the world has some kind of a privacy law.
And in fact, I saw a statistic, uh, today as I was doing some other research, that 75% of the world's population fit under some kind of privacy law. So there's a really good chance, if you don't think that you need to adhere to a privacy regulation of some kind, you should review the states you operate in, the countries you operate in, uh, and, uh, and how you, uh, how you fit into the global economy that way, You know, part of the relationships with working with partners and, and customers and things. I have the luxury being the person that fills out all those forms, you know, and fills out the surveys.
It is getting longer and long. I mean, I mean, just looking at that, you can see already what's in place. And of course, you know, there's other things on the horizon.
So pretty soon that's gonna be a full-time job, I think, for somebody. Uh, well, yeah. You know, to, to be fair, right?
You know, so I, I'm, I'm in the process of, of writing some other material, and, you know, looking through that material, it reminded me that, you know, we, we all have a, a chief information security officer. We all have a chief information Officer. If you do business outside the United States, outside of very specific states, you may or may not have somebody who, in fact is dedicated to this, this conversation about privacy.
Mm-Hmm. If you operate in some of these states, and in fact you do operate outside the United States, you probably have a data protection officer or a chief data officer, or whatever it is, somebody who's whose job it is. And I got an interesting thing.
So I, I, I may, I may have even said this on one of one of these discussions before with you, but when I would do CISO round tables, now, I haven't done this with, with, uh, data protection officers before, I suspect they would raise their hand, but with CISOs around the table, I would always routinely ask them, whose job is data security in your organization? Whose job is it? I, in fact, have slides that just delivered to, uh, saka the, uh, auditing organization.
I asked that question in these slides. Interestingly, it was about 50 50 half of the group CISOs would say, it's my job. The other half said, it's my job, but it's other people's job, or it's everybody.
Data security is everybody's job. What I mean in that, and I think what the, the, the, the test here is, is where, whose phone rings, whose actual responsibility job function is it to make certain that the wrong data doesn't go to the wrong place and have that understanding? And to be fair, I don't think all org, I mean, actually, I can tell you most organizations, you get 10 organizations, they do it 10 different ways.
Mm-Hmm. That, and, and, and that's the world that I'm, that, that I, I tend to operate in. I see all the time.
There's not necessarily, I don't think a right way in a wrong way, but you do have to find somebody in the organization who's willing to either raise their hand or at least wear the hat to say, it's me. Come to me and let me do it. Uh, I'd love to hear your thoughts.
You know, the, with the California privacy or whatever you wanna call it, I think the name changes. You know, that, that's an evolving thing too, because, you know, we've, we all became aware of it, but it's been updated and new changes coming. And I, I assume that will continue to, to happen.
So it is isn't a one and done, it's an, even with the regulatory things that are there. And now we have states implementing their own requirements in addition to this. So this is a very complex web of requirements that we're having to meet.
And that's just talking about in a US market. Yeah, absolutely. I mean, yeah, we're here, here.
Let's talk about CCPA. I'm just gonna call it CCPA. Okay.
Here we talk about CCC PA, thanks. Yeah. And so, and CCPA, I'm just gonna call it that, but you know, you've got Utah, Washington, Oregon, Texas, Florida, Montana.
You already had a few others that were already out there. So we're seeing more and more, I don't wanna look to the future and say maybe at some point we have one that just is 50 states altogether. I don't know.
But as it is, they kind of all mostly say the same thing. They exclude a little, add a little here, that sort of thing. But at their core, they're the same.
And we'll get to that, I think. But when we look at CCPA this year, they added, of course, a few different elements in terms of what it means to be personal information, right? I won't go down the whole exhaustive list, but it includes now, race and sexual orientation, genetic data union membership, non-public communications.
These are things that are identifiable. But what they brought to it, what I thought was interesting, and it is helpful, is a lot of that information does not matter unless that information is breached along with your first and last name by itself. It doesn't really mean anything.
It has to be along with your first and last name. And if you look at it, some of the language that in fact they actually use, they say, look, it's gotta have your first and last name, and then it can also be your social security number, your driver's license number, credit card, medical, yada, yada, yada. You get the whole list, right?
So it has to be this toxic combination of information that begins with the most identifi, most identifiable thing, first and last name. Even though I've, I've Googled it, there's at least 50 different Terry rays around the world. I'm sure there's plenty of 'em, but it starts to be identifiable.
What really was the, the, the teeth that got into CCPA this year in 2023, was the fact that you can now be subject to civil litigation. That was the biggest, biggest thing that came, came over. Because before it was a fine and fine, a fine can be finite, it can be a certain number, and I'm done.
As soon as you start to introduce civil litigation into this, oh, now you just lost 9 million records of personal information, and I can have a class action lawsuit, because it was name, first name, last name, address, and some health information. That's $750 per incident, not per breach. That's Terry's incident.
And John's incident and Mitch's incident, that becomes very expensive, very, very fast, best. And I think the one, the one important point, I love the language that they used because it's language that I feel like regulations need to use, but they need to use it more. And I'm, I'm, I've got it here from, I'm gonna read it here.
It says, in addition to the personal information, and in addition, the personal information must have been stolen in a breach as a result of the business's failure to maintain reasonable security procedures and practices to protect it, reasonable security procedures and practices. Now, I've not seen a regulation yet, and I've read an awful lot of 'em. I've not seen one.
This says, you need to go buy a firewall. You need to go buy antivirus. You need, they're not that prescriptive.
They define themselves as reasonable using security frameworks like NIST or sand. Okay? That's best practice.
If you, if you could argue, you meet the standards of that, you probably are, are probably in a pretty good place. I'm no lawyer, please talk to your lawyers if you wanna find that out. But you're, you're probably in a pretty good place if you're not adhering to those, if you don't have some frameworks, some standardized framework, you're just sticking the finger in the air and saying, this is what I have budget for, and I'm just gonna do a little bit, and, and I'm gonna hope, well, then that's okay.
Hope can be a plan. It's just not always, you know, uh, it's not a strategy. It doesn't always work out Well, you know, and it's also, we're well past the days of I'll deal with it when I have one of those things happen.
Right? Well, now, yeah. That, that's some pretty costly when it does.
Uh, I'm curious, you know, you mentioned that, and I can relate as I'm filling out, filling out different surveys and things, you know, the, the language is so similar. It's not always exactly the same, but they may reference what kind of data and it gets into, gets some things about what, what's happening in different states and, and personal information also of their employees information, right? So there's a designation of things that you may be transmitting or storing that's personal, private information.
Then there's also personal private information about employees or health information about a certain group. So it, it isn't just everybody. You have to look in the context of how that data is used in your business, how it's used as part of delivering to customers or to partners as well.
So that's, I think that's a complicating factor in this. I think this, uh, you, you bring up a good point, right? Because, uh, a a yes, you're absolutely right.
I mean, you've, you've, you've done your homework on this too, right? I mean, I think, you know, it's interesting. Some of it applies.
Some of these regulations apply to only in, in the, in the case of California only to California citizens, you know, a citizen of California doesn't matter to you. So you're, you're, you can't, you can't, you can't sue, um, you're not an employee or you are an employee. It also makes it complex in that if you do business in California and in Texas and Oregon and Florida and these other things, you need to go look at each and every one of those other states, because every one's a little bit different.
Texas, for example, chooses to opt out small businesses out of the, out of the regulation altogether. It's too much burden on them, right? So, so look at each individual state, and it can be complex.
And, you know, I, you know, I, I do a lot of work in, in Europe, and I think, you know, even just trying to adhere to GDPR by itself, knowing that in every single country over there, part of the eu, at least the same thing applies here in the states up until we decide, and I'm not advocating one way or the other, but, uh, complexity wise, until we decide to have one answer for everyone and do it across the board, it's gonna get up to 50 times more complicated than it is with just CCPA as it is today. And that's, I think, what organizations are probably going to struggle with. And I think the future is going to be, ultimately they're gonna get tired of it.
The lobbyists are gonna get in, in play, and they're gonna say, look, we, you gotta make this easier for us. We can't be doing this 50 different ways across 50 different slices. And I think that that's probably one of the challenges that, that organizations are, are running into is who does it apply to?
When does it apply? How do I do it? So as an organization, best practices find the most strict one, and that's what you have to adhere to.
And then you're probably fine, and you just need to do that. It's kinda like organizations that even before they go public, if they want to go get on the stock market, they will go ahead and try to adhere to sox anyway. Sarbanes Oxley, make sure they're doing the right control so that when they ready, get ready to do the right po, uh, they've already got a history of doing the right thing.
Well, and I really like your comment earlier about, you know, go to nist, go to sans, go to, well-known organizations that publish a lot of times for free, or at least to get started. That's, it is a great starting point of, you know, you usually have to take it farther than that. I mean, NIST covers a lot of things, of course.
Um, as opposed to kinda rolling your own. I think that's also a pretty fraught, you may be best practices, but now you have to prove that they're best practices by going in and look at the things that you might've actually started with them to begin your process. Yeah, I think, yeah, I, I, I would be surprised if a legal team didn't expect post breach, didn't expect to hear from a security team that the strategy processes and technologies that that security team brought to bear to solve the problem of, I'll say in this case, data security wasn't based on some sort of agreed upon common framework that they can point to and say other organizations solve it this way, and therefore that's why we're doing it this way.
Mm-Hmm. If you come to the table and say, I'm doing it this way because, you know, I, I, I got a degree and I went to college, and gosh, this is the way I've been doing it forever. You know, that may or may not stand the test of, uh, litigation quality.
Once you get into, uh, best practice, especially if your way is not aligned with a, uh, a more common framework. I'm guessing you might spend a little more time testifying in that case to describe your way, your way of doing it. You, you know, you talk to so many different companies and you're talking about who owns the privacy regulatory implementation.
And, uh, my experience is it's also working with, um, legal or compliance groups. 'cause there's usually people there who also have been trained in security, or they've gotten security certifications, you know, as part of their own professional development. And of course, they're gonna look at it from their lens, um, or you're looking at it from the lens of the CISO or whatever role that you're in.
But combining those two also kind of gives you a best practice of, let's look at it from both sides of the business so that we know we would answer this question this way as opposed to in the moment of urgency, I don't know, I didn't, I'm surprised you would say that. Or, you know, whatever kind of getting out of alignment, you realize that you're not in alignment. Yeah, I mean, I I, what you see in, in, in, well, I'd say what you see in the difference between risk legal, which I kind of put them in the same bucket, but risk and legal, and then security, security tends to be, of course, the people that are saying, what can I do about this now?
How can I solve the problem now? What controls can I put in place where your legal and risk really should be looking at? What is my risk?
What, what, what are we doing over time historically to, to reduce risk? What are the impacts on my risk for making certain decisions, acquisitions and sales and, and all of these sorts of things and, and, and growing the business into a new industry, and how does that impact me moving to the cloud and how does that impact my risk? All of that should be part of that same organization.
The collaboration between legal risk compliance, I'll throw privacy in there just to add, add a fourth word in there, and we're talking about it anyway, right? Is it's that group of folks that sit in the other department, usually the nicer building, and then you've got the security department that sits in the old building over here, that they've got all the widgets and all that sort of stuff. And they're the ones that are implementing the technology to answer the questions toward risk compliance and everything else.
It really does have to be that, that collaboration. And we mentioned earlier that yes, you have to have an owner, someone's phone's going to ring. The reality is, is the larger the organization, it's going to be a cross-functional discussion.
And, and I should say it should be a cross-functional discussion before a breach, you should be red teaming and doing different kinds of efforts and making certain that under the scenario of we lost a lot of data, and the regulation that's coming to our front door is CCPA, what answers do we have? Security, how would we answer this? How would we answer this risk, et cetera.
And I think savvy organizations certainly do that. There are a good batch of organizations that don't, or do it a little bit, but really don't have the good, the good quality answers until the rubber does meet the road. And it's not the internal auditors, the internal teams who are actually asking the questions.
It's the, the external teams who do this every single day and have just triaged 15 other breaches, and they're taking all the questions they didn't get answer to answers to from those 15 breaches. And they're asking you those exact same questions. Mm-Hmm.
So it's important, I think that organizations don't ask softball questions of your teams. You need to ask truly hardball, good college tri questions of your teams and hold them accountable if you don't have the answer. We need a timeline and an understanding of when and how you're going to get that answer, because we need to know it before we have a problem.
Right. You need to know the answer and yes. To be, have to be of also demonstrated what attestation do you have that says yes, we do it in addition to saying it.
Yeah. And, And effective, an an effective answer is not, I don't know. Let me get back to you on that.
You know, it's, um, I don't know if we plan to talk about this, but even thinking about regulatory kinds of things, we're early in the days of ai, right? 'cause we have the eu, uh, AI act, this that's under negotiation, the couple presidential orders telling organizations to put certain things together. You know, we're, we're early in those days, and I don't think we're at a regulatory framework close to it.
Well, maybe we are. But that, that seems to be the next front of what we're gonna be dealing with. We're gonna be having the privacy conversation and the ai, you know, safe whatever, whatever words that we apply to it.
And that'll be a whole nother domain about how we're using, uh, AI and the data that goes into it. Yeah, absolutely. I'd say my experience over the last year has been interesting in that you submit an abstract to any conference, and if you don't have AI in your, in your title, you're much less likely to get, get your speaking slot.
Uh, so, but I will say I've gotten plenty of 'em without it. But what, here's what I'll say about AI is it's, it's one of these interesting things. You're right, we don't know a lot about it yet in terms of the impact into security and otherwise, we know that there are already, uh, uh, uh, uh, attack tools and attack efforts going on to leverage it.
We know there's already frameworks for AI that's specifically dig into the dark web and do others. The interesting thing for me about AI that wasn't as interesting when we were talking about machine learning over the last prior three years, right? It was security and it was big data, sorry, it was security, machine learning, and big data.
Mm-Hmm. And what I saw over, over the last three to four years or so was that we would see the, the combination of big data and machine learning tends to allow bad actors to attack one source, another source, and another source, put it all together, dig through the data, and then find commonalities among that data. That's how we expected them to use that data.
And maybe they, maybe they did. I don't know that it, it came well to fruition, but there was a great example of OPM, the Office of Personnel Management and then a healthcare breach and a Lockheed breach. And you put all those three together and you find people who have top secret clearance who work at Lockheed, who have, uh, you know, who have medical conditions, et cetera, and you see some leverage being created there.
As you bring those together with ai, it creates another model, I think, where we say, okay, well now, yes, you can use AI in security controls. We can use AI to, to dig through certain data. The lovely thing about data security is that we have an awful lot of data.
So AI fits well into that model. Let me dig into that data. The same thing is true over on the attacker side of the, the, the house, if you will.
They can dig through all kinds of exploits. They can rapidly look at, okay, this website, here's what it looks like, here's the exploits associated with it, that's the best one. Go hit that one.
Some cool things they can do. But what I think it now introduces is the capacity for rapid exposure of data. It's not about a breach, it's not about an attack, it's about organizations inadvertently exposing data because they don't know what goes into their ai, what's shared with ai.
So I, you know, it may or may not be a prediction. Maybe it is one of my predictions, I don't know. But I think you will actually see a lot of inadvertent exposures.
And I don't know that we necessarily measure, uh, breaches versus exposures, but it would not surprise me at all to see that breaches are a little more common than exposures, but exposures to bounce up a pretty good, significant percentage higher than what they are today. Primarily because you're gonna start to see more people say, oops, uh, that wouldn't supposed to be in there. It shouldn't have grabbed that.
And that's exactly I think what AI is gonna be doing for people. Uh, some, some surprise grabs here and there. Yeah, I think, I think we're still learning about large language models and how to do domain specific and how to protect, you know, IP as well as, you know, we get into personal pri private information.
It, it, there's a lot to learn, at least a lot to learn from me, I'll tell you that. And then I feel like I'm learning a lot, um, you know, as, as field CTO as part of your title. I do, I imagine you get an opportunity not only to speak at conferences and, and conversations like this, you get to customers, ask you in and to ask you questions like what we're talking about and what they should be doing, and where should we look to, or what are you seeing across your customers that might be a common practice.
Um, is that, is that the case in, in your role? Yeah, Yeah, absolutely. Yeah.
I, I would say it's probably 50 to 60% of what I spend my time doing. And, and it is, and to be fair, it's, it's one of the pieces I enjoy the most, right? Because, you know, I can sit in front of a conference and I can present to a lot of people.
And, and while that may be entertaining here or there, really being able to affect security in an organization and be able to see the outcome of that over time, to be able to say, we had the conversation here and now I see you've really matured your program to a place where, you know, I feel comfortable about it. You should feel comfortable about it, and, and, and you're, you're never done. Everything's iterative as, as we already as we began this conversation with everything changes every single day, but you're in a place to do it.
So yeah, I have those conversations all the time. And I think it's, it's, it's, it's common that those, those, those conversations unfortunately tend to focus on highly regulated businesses like healthcare, financial services and insurance, where they should be happening. Those, that's absolutely where they should be happening.
The unfortunate aspect of it is the fact that it should be happening in retail. It should be happening in aviation and, and oil and gas and everywhere else. But the less regulation that exists in organizations, even though I completely accept and, and, and, and, and propose that you should not build your security program around regulation, it is a very effective motivator for organizations to say, yeah, you, you mentioned earlier, right?
Uh, you know, it, you know, hope is, you know, I mentioned hope and you said, look, it, it's, it's what some people will do. And, and, and it, it doesn't always work. But the fact is, is regulation, you're guaranteed to be audited.
It's not an if you're gonna be audited. So if you need to meet PCI, whatever it is, regulations drive a lot of it. So my point is, is these conversations tend to focus on regulatory.
How do I meet CCPA, how do I meet GDPR? How do I do all this? And my more successful organizations that I work with are the ones who've gone beyond that, matured beyond that and said, okay, I know I have regulations that's never gonna end.
I'm gonna get an audit every single day, every month, whatever. Really where I want to be, Terry, is I want my data security practice and strategy program, whatever they want to call it. I want it to be as mature as the network security that I've been dealing with for 30, 35 years.
The endpoint that I've been dealing with as long, I've only been doing data security for 10 years. How do I get my data security program as broad and as accurate and as, as, as effective as all the rest of my security? And that's where a lot of them are beginning to tighten their screws and saying, I can do more, Terry.
Help me understand what do I need to do to get there? Fantastic. Well, I wish we had about an another 55 of these conversations queued up so we could keep talking.
Um, where can folks find out more from Imperva, maybe even reach out to somebody like you that might be able to have these conversations with them? Yeah, there's no place better than Joe's going straight to our website. com.
Certainly I'm on LinkedIn and I'm happy to, to chat with anybody. So you're always welcome to connect with me. And then really anybody at Imperva, we have a very open door policy, so feel free to reach out to us, but imperva dot com's the best place to reach us at.
Okay. All right, Terry Ray, let's, let's do this again soon 'cause things are changing quick. Thanks, Mitch.
I appreciate It. Well, you have a good rest of 23 and we look forward to 24. So we, and, uh, thank you so much for sharing all of your, all that you've learned and are thinking about and sharing with others.
Absolutely. Thank you for having me. You bet.