RSA Conference ESAF Report – Brad Arkin, Cisco
Brad and Alan discuss RSA Conference’s ESAF Report. This unique report is the work of the RSA Conference Executive Security Action Forum (ESAF), a community of Fortune 1000 CISOs. The research was steered by the ESAF Program Committee, a group of 15 CISOs from global companies. For the first time, ESAF is sharing the knowledge of its members with the wider community.
Transcript
This is Textron TV. Hey everyone, Alan Schimmel here for another text on TV segment. I'm happy to be joined for this segment by Brad Arkin and and Brad's kind of wearing two hats on today's.
Show I'm gonna ask him to well Brad. First of all, welcome to techstroke TV. Thank you.
So by day Brad you work with the good Folks at Cisco, correct? That's right and the chief security trust officer Cisco. Why don't we why don't we start there?
What so what exactly? Does that entail? Yeah, so I'm the security leader responsible for everything that happens within the company.
And so that's the security of the products that we're building for our customers the services that we operate and then also all the back office work that's happening and So within my team, I've got a chief information security officer Chief privacy officer. We have a trust office product security engineering lots of other odds, but those are big pieces. Absolutely, and that's a big job, right?
You know, it always used to surprise me. When you know and an event or something, I mean security Cisco probably from a revenue perspective was the biggest security company in the world. for a very long time we've got a security business group.
Oh, sorry, but no. No, I was easy. Go ahead.
I mean, you know better than I just security business group is just a huge piece of the business, but but to be clear That's not what you're doing. Right? You're not making security products that we're selling to the whole world.
Yo, you're in charge of Cisco security. Yeah, so the joke I make is the security business group makes the money and then I spend it and so I am cost center. So I don't have any any Revenue making so for me the security business group is just one of our business entities.
And so we have lots of other businesses that are out there making money doing Enterprise networking or whatever it is that solves customer problems and my job just make sure that everything we're doing whether it's security products or Enterprise networking or collaboration that these products are gonna be the security requirements of the environments in which they deployed and operated and then also all the back office infrastructure now because we are a bunch of Security Experts within the security and trust or we work closely with SVG and what we call customer zero and so often we're using things that aren't yet out for customers that we're giving lots of feedback on features that we think would help make the products more practical for us as users and that does will forward and what the customers do but I don't run the security business group. That's a different team. They roll up to a Leader in our executive leadership team, so so definitely back office.
Got it. All right, so that's the day job. At night or at least once a year, you know, you used to be around February this year.
It's April. You're also very Closely involved with a group coming out of the RSA conference. That's kind of gone public now or you know come out of stuff.
Why don't you tell us about that a little bit? Yeah, so, you know the old days we would do this every Monday the week of our state conference the esa so Executive Security action form and this is roughly a hundred of the Security leaders. So see so csos that kind of crowd would get together and for us it was a wonderful chance to kind of get away from the sales reps and all the chaos that happens on the Expo floor at RSA and just get together in a room and we'd have an agenda we go through and it was really leaders sharing information getting on stage talking about topics and usually, you know, the hallway chat what we talk about at lunch and after work that was like the big highlight each year and so with covid we've been meeting throughout the years not just in person on that one Monday and so we've been doing more work together to figure out how we can get more value out of this group.
It's finally, you know covid looked covid was no joke and there was a lot of people died. It's changed. changed the way we do things I mean even You know, we it's on Jewish Jewish holidays last week or we before and you know, the hour our synagogue live stream services and even though you know people could still go now with covid and everything more people.
are watching The live stream than they are going a person. It's not just where I go. But other churches in synagogues are experiencing the same thing covid's definitely changed in this case.
facilitated a group that was meeting once a year into doing virtual meetings, but doing them much more often and and that probably I I am assuming had a big influence in the in the decision to kind of go public with this very first report from esaf. Yeah, so I think the You know, there's no way I could meet six times a year in person with this group of folks. You know, I've got too much else going on and so being able to figure out what do we have happening that we can do together when we're meeting together so frequently and what are the increased ways we can add value for the membership.
So that's something that it's really raised our ambition of what's possible now. Excellent. I love it.
You know it's good to see something good happen from all that suffering. So let's talk a little bit about Esa F. And this kind of you guys agree or decided to do a full-blown report.
the first public report from esaf and it deals on Communications with the board. Correct. That's right.
Give us a little more. That's that's as far as I can. Take a brad.
Why don't you take it? Yeah, I'll give you. So basically, yeah, I've got my day job and I lead a big team and we've got a lot of deliverables and things that we care about and then for me it's quarterly but for pretty much everyone who's in my job at big companies, maybe regularly with the board.
It might be every other meeting. It might be quarterly. But when you sit down to talk with the board and give an update, you're trying to compress the activities of hundreds or thousands of people that have been working for months and try to get that down into a 15 30 45 60 Minute updated and it is so difficult to try to figure out how can you use a subject matter expert that works on this, you know 70s a week all day long and how can you give an update to a bunch of folks who might be coming from backgrounds and finance or governance that's gonna be meaningful for them.
It's still that value in particularly like someone like me coming from a deep Tech background. I've never been a CFO. I have a hard time talking to see it those and so how do we bridge that?
Yeah and make it really meaningful and what does success look like within that corporate governance structure. So figure out how to drive good conversations with the board is a continuing challenge for every security leader that I know and so historically whenever we get together, we're always gossiping about how's that conversation going? Like have you come up with any?
Tricks in order to make that a more fruitful discussion and Laura Robinson at eastaff the heard about how this was a constant topic of interest within the Security leaders community. And so the idea that we could take our actual real world board reports redact them scrub out all the sensitive stuff, but keep the format in the structure and then share that within the community and what Laura and the team did is go through and look at all of these different reports and they start to do research against it and draw out. What are the themes to compare and contrast from one to the other and it's been a really interesting exercise because what we find is that there's some things that are Universal that everyone is trying to provide increased transparency.
They're trying to give it update to the board. That'll convey where we are. What is going well where we need help but the way in which we do it is so different across the industry.
And so I'm more of a narrative guy and so when I sit down and comp My materials to the board it's more like a letter and so it's a couple Pages. It's Pros. You could read it in paragraphs some other folks when they put together materials for the board.
It might be in a PowerPoint format, but it's lots and lots of numbers and the data is there the metrics are there and they're surface in it all directly for the board to consume whereas my style is to digest all of that information that exists but then try to convey in prose narrative style. What does it mean? And so some people want to see the data some boards?
Just want to know what is it tell you you're the expert you explain it to me. So being able to compare each of those different formats and understand what are some of the things that are Universal across each of these is really useful for me because then I can go and use that to double check in my league in something out. Is there a clever idea that I can borrow and put it into work in my environment to make that conversation more fruitful.
A great excellent, excellent, you know. I mean Brad, I spoke to Laura earlier. To go.
I think I did a panel at rsac. about metrics for the board Right from security point of view and you know, it was interesting a few people on the panel said, well, you have to dumb them down and I don't know if dumbing down was the right word or the right phrase or even the right idea. It was more.
I felt you had a translate you had to translate security talk to business talk because business talk is the language of the board and you're right it is it's a different language in some folks are comfortable with it. Some aren't right, but it's important for someone in your position to be able to talk both languages right? You need them.
I mean we were talking off camera looked over the last couple of weeks months. We've had you know some interesting developments in the role of the sea. So, you know, I think we were all a little sad and to hear that Joe Sullivan from was, you know an Uber but before he was an Uber Joe had a distinguished career in cyber was convicted of crimes for not telling the truth and withholding the truth.
Around a breach at Uber and look I I think with not telling the truth is always wrong. Can't go wrong telling the truth ever. But I'm not making excuses for him.
But you know to his defense he said he was following orders right from the legal team there and everything. I think you can trust that with the months before we had much at Twitter kind of yeah, The Whistleblower. Yeah, he's Jerry Maguire moment about why?
Twitter was was a wreck. Waiting to happen from a security point of view and to me these are two extremes. Of what to see so to do but both of those guys could have used an esaf.
To kind of before it went public before the stuff hit the fan. kind of Verbalize hey, what what am I to do here? What what's all right thing.
What should I do? I'm wondering what you think about that. Yeah, so one thing that I think is a theme that came out in the report is talking about incidents.
And so whenever you have a security event, so something goes wrong and it might be a small issue. It might be a massive issue and trying to figure out what is the right level of detail to get into to convey these incidents to the board. And this is one of the things that came out as universal is just about every single board report no matter who the author was what the company was there was some element within the outline that convey this is where we're going to talk about incidents and so for me personally, this is something that I've been working to figure out.
What's the right level of detail to get into what is the threshold and cut off for an incident that we would talk to the board about and then there's other topics we talk with the lawyers about cyber materiality and so from a sec Security and Exchange Commission reporting perspective. You have things that are material like if you know your factory Down and you're gonna miss your Revenue numbers. That's the materially that and you have ways you have to report that and so in the security world, if you had an incident it might trigger certain materiality thresholds, and then you go and communicate that and there's like fine lines that you can make in order to communicate that and so the thresholds within the community over what exactly represents cyber materiality is very much unclear and evolving.
And so whatever we think it is today my threshold for talking about something to the board is vastly lower than that because I don't want the board a year later to say like hey you about this all along like you tell us, you know, that's something I really worry about and so I bring to them anything that's remotely interesting within that incident realm because I want to make sure that I'm over reporting and disclosing at the board level. And so these are things we don't have to talk about publicly. There's no notification obligations that we have already regulatory regime and frequently, they might be more of what we call.
This than a real incident. So it's like something that could have happened but it didn't you know, but still like we've got shook up a little bit and so we want to talk about it and what I really like about this approach is that The more sunshine you bring to these incidents the more people that know about it the more that you can learn from and figure out what are you going to do different next time to make this less likely to occur or if something like this were to happen again, how do we limit the blast radius or the impact of what it could have and so that's something that we spent a lot of time thinking about within my team here at Cisco and then it turns out that this is a hot topic for just about every security team out there. So it came across in the report in terms of the information that people share of the board is really focused on those incidents.
And so when I just read the headlines, I'm not a lawyer but when I read about what happened at Uber the one of the key problems there was such a small number of people who are in the know and it seems like if you had a broader set of folks involved that you could have driven that towards a better outcome. And so that's what we're hoping for is you bring the right people in the room and you can't have a hundred people, you know, you have to have a good conversation, but the right people in the room that have the right information and then hopefully Group, you can then drive the right analysis that will lead to the best outcomes for the organization and for any other stakeholders that are involved. Excellent, you know what?
We're almost at a time. But I I well Laura had mentioned for folks who want to get their hands on the report and you and by the way, you don't have to be a sea. So to get value out of this report.
I'd recommend it for anyone in the Cyber realm or anyone who has to deal with cyber folks. You know, it's part of their jobs. You can get it off of the main RSA site.
I believe right just look up for esaf. And it's available there. I should also I guess mention or I should ask you, you know, rsac is coming up in April this year.
Will Esa F. I'm gonna assume you still gonna have your regular meetings there in person. But will there be a public presence as well?
I don't know. So I'm on the program committee. So, you know, we're looking through a bunch of different options.
Usually what we do is it's like the Cool Kids Club. So people that are in acting roles today. So we don't have a lot of Emeritus folks floating around so you've got to be in the job right now and the group that joke is it's like group therapy for cisos.
And so we all get together. It's a safe space we can hang out together this year coming up in April. It's gonna be on Tuesday.
And so we all get together and some of the ideas that we're figuring out is with public reports like this. What are the other opportunities that we have in order to help get more information out more folks that can benefit and then the idea that this coming hour say there might be some ideas that we can do things with a broader audience. So these are things we're working through the program committee, but nothing scheduled yet.
So we're still working through the different options. Got it. You know what as long as you're doing it Tuesday, we're doing our deaf SEC Ops Dev psychops event Monday.
We've been told for RSA musconi this year. So stop by Brad. We'd love to have yeah.
I'll be free a real a real talk about it. Hey, man, thank you for all the work you're doing with esaf and the programming committee. Appreciate it.
Looking forward to what else comes out of esaf. Great. Thank you.
This is fun talking. Alrighty, Brad Orkin from Cisco and the esaf here on techstrom TV. We're going to take a break.
We'll be right back.