Regulatory Trends for Critical Infrastructure – Dan Lorhmann, Presidio
Dan Lohrmann, field CISO for Presidio, takes a victory lap for his correctly predicted view of increasing regulation for incident reporting. He then chats with Mike about other markets where we can expect tighter regulation and what organizations should do to prepare.
Transcript
This is Textron TV. Hi, this is Mike Rothman. Welcome back to another tech strong TV interview.
I am very pleased to be joined by Dan lorman of Presidio. We'll have Dan introduce himself in in a sec. But you know, we're gonna do one of these things.
It's a little bit interesting on text growing TV. Today. We're gonna revisit some predictions that somebody came on to the show and made a couple of months ago and we're actually gonna come back and revisit them in terms of what what was right on, you know, kind of Target.
What was maybe a little bit off Target, you know, and and where do we see things moving forward now that we're kind of in this whole 20 23 planning cycle that a lot of folks are trying to get their arms around, you know, what's gonna happen? So before we jump into that Dan, why don't you introduce yourself give us a sense of what procedio is and and what they do and and by the way, I was a little bit rude welcome to Tech strong TV. Thanks for being here today.
Hey, Mike. Thanks so much for having me. It's great to be with you.
I'm Dan. Lorman. I am the field Chief Information Security.
Officer field see so for Presidio and Presidio is a global digital Solutions provider. We provide services that help companies make the transformation by using technology and and really modernizing their infrastructure making the journey to the cloud and secure ways and and we help companies all over the world in a wide variety of areas, but certainly I focus on cyber security and and how to do you know really enable a digital transformation insecure manners and and a lot of different forms. We we get involved but happy to be with you today.
Yeah you bet and that's obviously a topic that's near and dear to our heart at Tech strong. Right? We've got digital cxo which is our digital transformation editorial site.
We're really working with a lot of the you know, large organizations help them understand, you know how and and why and and really, you know, when they should be thinking about embracing a lot of these Technologies, obviously your Security Boulevard, you know focused on on the security side of things. Something that's near and dear to my heart right as a 30 plus year security professional obviously yours as well Dan, but you know really a lot of what the discussion surrounded last time was, you know, you focused on banking a little bit but it's really about you know, kind of how a lot of the regulations are evolving. What does that mean to different organizations and when you break it down into a number of other Industries, right?
How do we have to start thinking about these overarching, you know and evolving mandates as a way to start planning what we're gonna do over the next year, right? So I know we want to revisit, you know, kind of what you said a little bit before but I also want to make sure we have sufficient time to ensure that we give folks say I'll view forward in terms of how they have to start thinking about this problem. Absolutely what I think the challenge Mike is, you know, we thought thinking why why is this happening?
I did CNBC came out with a report. Um just earlier this month. 2 billion dollars in ransomware payments were processed by a congress.
I'll report that came out just recently and and so, you know clearly this is a huge issue facing all the industries. And yeah, so what we talked about with with Charlene back in back in the spring was um, the banks have reporting requirements, there's different regulations out there. But um, basically that they have to report within 72 hours, um of a substantial incident security incident, which is like a ransomware an outage something that causes their business to be disrupted.
There's also regulatory, um processes and say within 36 hours where payments need to be reported within 24 hours. And so these different Reg Relations that are out there and we'll be talked about was how their impacting other Industries. And so what the change that came out that you know, we wanted this mention is that on September 12 of this year 2022 the cyber security infrastructure Security Agency, you're basically came out with a number of our fives that say that they want input on this, um, you know from from the industry across the board on you know, what what the definitions are what you know, what they want input from us across the industry, but then last month they announced seasa announced that transportation and Communications water which you know EPA and then health and hospitals and Health and Human Services, um in the federal government are going to start, you know, basically coming out with rules around reporting in those critical sectors, so they would be required that if you have an incident you're gonna have to report it.
And you know and and also ransomware payments and those kinds of things and really tracking that because those big numbers are based on what we know right? But the question always is what do we not know? What's the exact word?
I mean clearly we have an iceberg situation here, right? You know that what we what we see is what you know kind of is above the waterline, but clearly there's a lot going on, you know kind of below the water line from that standpoint that we want to you know, focus on and I think that's an interesting, you know thing to start digging into one. I'm such a huge fan of what cisa is doing here the United States.
I mean, you know just in terms of making security policy and and a lot of the controls that we have to think about, you know much more accessible to both large and small organizations. I think, you know secretary and easterly is a great, you know, kind of spokesperson right for the security business or I guess she's the head of it. I don't know but You know, I think really that's fantastic.
And again, this is just another example of them getting out ahead of what is, you know, really an issue that's very again controversial to people right? You know, they don't necessarily want to talk about, you know, the fact that they got popped. They don't want to talk about whether you know, they ended up paying the ransom or not.
They don't want, you know, folks to know that they're not perfect and in some cases your data, you know has been breached if if not inaccessible, you know, really impacting, you know the availability of services. So I think that's you know, that's great. So, you know, she's just come out with a couple of guidance things.
So you were right, you know from that standpoint relative to where things are going or where things were right. I want to really talk about, you know, some of the other Industries right, you know Finance Health Care, you know, some of these other, you know, kind of I would say higher profile really, you know, kind of more sensitive data at risk in in these envirus did we think we're gonna start to see guidance on you know, kind of waiting for some of these organizations when you have any idea what that's going to look like and really most importantly how that's going to change how an organization should be thinking about their security Investments as we you know, kind of get into the 23 planning cycle. Yeah, the answer just simply answer is yes.
I mean, you know, we're going to see across all the sectors and you know that we talked about the critical infrastructure sectors. I'll just read them quickly here by this, you know chemical sector communicate commercial facilities sector communication sector critical manufacturing sector dams defense industrial base Emergency Services sector energy sector Financial Services, which already has okay the banking that they're already in place food and AG will culture government facilities Healthcare Information Technology nuclear reactors and materials transportation sector Water and Wastewater systems. So I think what they've announced is it before um sectors and they sent out, you know requests for input.
So, you know part of the challenge we talked about with Charlene the last time Mike was you know, that the supply chain, you know, like who's impacted if you say okay, you know, we would say nuclear reactor sure. I mean obviously people what that would be imported, but you know, what if It's a water system. It's a lot of private water systems on a small water systems.
What about Their suppliers. So who does this actually impact is it like tier one tier two, tier three suppliers to these organizations to the definitions are really key. And that's what ceases asking for right now.
You go out to the Cecil website and have input into that. But you know, we're going to see rules coming out from regulated agencies in transportation Communications under the FCC water. It's gonna be the EPA if I remember Protection Agency and then health will be healthy human services.
I think you're gonna see regulations in those areas and they're going up, you know, they're gonna start by the, you know small but it's it's gonna grow up now not all of these sectors are regulated. And so there is debate. You said the debate About you know, how much should regulation you know that slow down industry.
Um, when do you need to report? What's the definition of an incident? You know what you know, what is I mean clearly if you have a major ransomware in your your whole system is down and you're you know, we know we know that's a big incident.
Yeah pipeline. We have experience with pipeline. Let me know that I mean, right and we know you know, JBS meets was down.
I mean, it was all over the papers. So we're not really I think those are clear but but every organization is attack each and every day and so really clarifying what are the rules what what constitutes and outage what constitutes a Cyber attack an incident of significant reporting of reportable incident. Um, Those are the things they're working through now and I think it will be could be slightly different in different different.
I suspect they will be right, you know, when once you know, yeah. No, I'm not a military guy in any way shape or form but I do I do know the term, you know, no plan survives first contact with the Enemy, right? So I know that you know things will be shifting, you know once folks get their hands on but I want to talk a little bit about enforcement right because you know again being an older guy and and kind of you know, having been through, you know, HIPAA and sorbachs and and you know, a lot of these really high profile regulations that you know, everybody's like, oh, you know insecurity and and we kind of ran around with our you know heads cut off or a couple of years trying to figure it out and it turned out to you know, largely be nothing burger, right, you know, a lot of organizations made a business decision that said the if I kind of evaluate likelihood of getting caught versus penalties if I am caught it's an Decision to not you know kind of worry about protecting, you know, my customer data because there's just not enough in it for you know, not enough downside for me to you know, make the millions of dollars of Investments that I would have to be to fix the problem.
I mean, are we in a citro? Obviously the the downside of getting popped by ransomware, there's problematic enough, but you know from an enforcement standpoint. Yeah.
I mean are we gonna see something that has enough teeth to get folks to really play ball with this? I mean I it's hard to say exactly how this is gonna roll out. I mean my by, you know, if you look at Banks as a model, you know, obviously a bank Regulators.
They have a lot of audits. Um, they go through that and it's not surprising. It's also where all the money is, right?
So that's you know, kind of them leading the pack, um, you know, and they have penalties associated with that and and you know certifications and things that are on a regular I mean, obviously there's starting with the more regulated industry, you know, the hospitals, um, you know, the rules around that you know, the you know, like I said water, you know, a chemical plants, um, you know, the the kinds of things where they're used to having regular audience. I think you're gonna see fines number of these industries. How do you know, how do you enforce in the it sector as a whole?
I mean, it's gonna be challenging to talk about enforcement wider enforcement in a number of these sectors. I do think it's gonna be gradual. It's gonna they're gonna ramp it up.
They'll start slow, um, you know in Cases there may be overreach where there's too much regulation. And and I just you know, what we're seeing here is um The Challenge I think that's really going to be interesting. Mike is is what if and when you know the domino effect from a number of these and so, you know clearly we lose our power.
We lose energy set. We lose, you know, electricity and like as we had the black out of the Northeast the impact the society the impact is huge. Um, so, you know, they're trying to prevent obviously that trickle down supply chain challenge, but these sectors feed each other as well, right?
They've rely on each other. So, um, I think you know, will there be an embarrassing um, you know situation that comes out that it gets a lot of attention that all of a sudden lights of fire under this and we see more sooner. Um, we'll the Evolve, you know, the events of the election of fact, you know Congress, you know, will you know generally tends to be a bipartisan issue.
Cybersecurity but you know regulation is something that obviously Republicans like less than the Democrats and so the question of how all that plays out. Um, well, you know time will tell but I there's no doubt in my mind. You're gonna start seeing more reporting mandates, um around incidents because we don't even you can't protect what you don't know about and so the criminal justice Community the law enforcement Community really wants to get a better handle one.
Is that one point two billion dollar ransomware number for last year even the right number? I mean, it might be a lot larger than that well and and you know, we'll never know what the real number is because you know, some folks are gonna obfuscate and that's always, you know, kind of part of the game, you know to me a lot of the benefit of you know, kind of a mandated reporting is to learn about tactics, right, you know, listen guys like you, you know, you've got teams of people who you know kind of spend time, you know, basically Excavating what's publicly known and in threat Intel communities and and reversing There and understanding what the attacks look like. Right most of the organizations don't have those capabilities.
So they're relying on their security vendors to give them some researches some maybe they pay for threat third party threat Intel to give them some you know view of that. So anything that's going to get out into the public sphere that helps folks understand what the tactics are. Right what you can do to remediate those tactics and more importantly.
What can you do to protect yourself from that kind of attack I think is a net positive for everybody. So I'm excited, you know for those kind of things. I'm skeptical in terms of enforcement so we can put that into my predictions.
Okay, you know for the next year, I think that's just brutal but I do think that you know, especially the highly regulated organizations are going to have to start to come clean and we're gonna learn a lot. I think that's a net positive for everybody. I would agree and I think that you're going to see if you said, you know more and more help.
There's a lot of talk about how the public and private sector can work together how We can have Partnerships and and the law enforce Community, you know, and and you know can help especially with nation state attacks when you're talking about tax coming from from you know, foreign adversaries and and that kind of a thing. I think there's a lot of benefits that can come from it. I do think it's gonna be an ongoing, you know kind of back and forth as to what is the right level of Regulation versus what is what is overreach?
That's right. That's right. So with that Dan, I can't really appreciate the time what I appreciate you coming back, you know, most things and I'll say front brilliant cortex not working as good as it used to so I was gonna remember to say, oh, I better call Dan and find out, you know, how we did on those predictions.
So so I appreciate you coming back onto the show and giving us and an idea and it never hurts when you're right, you know, if you were wrong, I'm not sure how excited you to come back on the show and talk about that. But you were clearly right in this aspect. I think it's an interesting area because we do need to share information better and not just, you know, kind of between It and and public but also amongst all of the the private organizations so that we can again benefit from The Misfortune of others, which is a term.
I like to use relative to threat Intel and just sharing a lot of that perspective. So Dan thank you for for showing up on text on TV many parting words or thoughts that you want to leave us with pleasure. Thank you Mike for having me.
com is our company website, but I have a Blog for you mentioned in number different blogs mind but government technology magazine is actually a also syndicated and Security Boulevard. So it actually comes out to the one you mentioned so but yeah Norman on cyber security Comm feel free to reach out or LinkedIn as well Dan Mormon and thanks so much for having me. It's great appreciate that day.
And with that we will send it back to the studio for next interview