SEC Rule Changes and Cybersecurity – Nick Lantuh, Interpres Security
Interpres Security CEO Nick Lantuh dives into the impact latest SEC rule changes are having on both cybersecurity teams and the cybercriminal syndicates looking to weaponize them.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nick Lanta, who, CEO of Interprise security, and we're talking about the SEC and some of the new rules and how some of that stuff may be coming around a bite us all in the proverbial behind.
Nick, welcome to show. Thanks, Mike. Thanks for having me.
What is your take on the effort that the SEC has put together? I mean, I think we're all aware that these are new rules and they are definitely trying to, um, as we've seen with the case involving SolarWinds enforce them. But what's your take on, how realistic are they?
Because a lot of times I feel like they're asking people to do things that are outside of their ability and control. Yeah, I think, look, I think it's all well intentioned, right? I think that the SEC, what they're trying to do is they're trying to, uh, you know, enforce cybersecurity and, and make sure that everybody understands from a public company standpoint that they're serious about this.
Um, and certainly the, uh, breach disclosure and materiality, uh, guidelines that they're providing, uh, coming this December, uh, state that, and, you know, there's a precursor, obviously this, uh, lawsuit that they filed against SolarWinds and their ciso, uh, is kind of reinforcing that. I think they're really serious about this. And is the CISO really the right person to be trying to ascend to prison?
Because it seems to me most of the security people I know, they advise, but they don't really have the ability to enforce the controls that usually is in somebody else's hands, whether it's the IT person or someone even more senior than them. But aren't we kinda like indicting the fire chief because there was a fire and it wasn't his fault, he didn't light the blaze. So who's really responsible here?
Well, look, I think, I think that the issue here is, uh, for the ciso, um, you know, I think that they have to be, uh, cognizant of the fact that they're in a hot seat to a certain degree right now. And so the reporting that comes out of this, uh, they have to make sure that they are, uh, documenting it very well. So if it's whether it's a breach, um, or whether it's filings, um, for disclosure that they need to present, um, right now I think that, you know, the focus is on the CISOs trying to determine, you know, what they need to do in order to make sure that they're doing everything right to keep lawsuits away.
And, you know, the SEC is, is, uh, doing this for shareholders. Uh, they're trying to make sure that, you know, what companies are disclosing is accurate. Uh, but there's a fine line there, uh, in terms of, uh, you know, of materiality, which I don't think they've really defined yet, and what, how this is gonna play out in the long term.
Do you think we might be seeing a scenario where a lot of CISOs just decide, Hey, this is too much trouble for what it's worth, and they move on and do something else because it has a lot of stress in the job to begin with, and now suddenly I'm looking at potential liability that I hadn't signed up for. Right. I think that that's exactly right.
I I, I'm not sure how this all plays out. It certainly feels as though, um, you know, they may need, uh, DNO type insurance coverage on this. Uh, you know, I think that they're going to, you know, certainly focus in, if you look at the way that the SEC wrote their document, um, you know, they, they mentioned threat and threat actor as much as they mentioned risk.
So I think that the SEC is clearly stating that threats are integral to the risk and that CISOs need to focus on a real defined set of threats versus kind of nebulous risk risk scores. Um, and so I think that this paradigm shift that's happening that needs to happen is towards really, you know, prioritizing threats and implementing plans that defend against the, you know, who really wants to come after us, and then a program that's really based on, you know, threat intelligence and being able to morph that in to enable the CISO to define who is trying to, you know, to attack their specific industry type of company dataset systems that they have. Um, but I do think that from a CISO perspective, they need to obviously document, uh, and report those security incidents and be very specific and focused on the threats for public disclosures, because, as you had said, ACFO or a general counsel or the CEO or maybe the board can change their recommendation, and I think they are still in line to potentially be liable.
We have also seen the bad guys. AKA cyber criminal syndicates essentially turned this whole thing into a circus already. They have, uh, identified a victim that they then reported to the SEC for being outta compliance because the victim didn't, you know, cough up the appropriate amount of reward for their troubles.
So, um, I don't know what the SE C's gonna do with that information, or theoretically, I guess they have to hold somebody accountable, but is this thing spinning outta control already? Yeah, it's, you know, certainly the, uh, the Black Cat ransomware gang tried to weaponize, right? The SEC's soon to come, you know, regulatory requirements, which are in December, so a little bit premature.
Uh, but, you know, certainly MeridianLink, they, they were breached and, and the, uh, the threat actor, uh, then filed a complaint with the SEC. Um, so it's a bit of a, you know, a bit of a catch 22. I think that there are, uh, you know, some motions in play.
If you look at, uh, what the White House has just come out with, um, you know, on October 31, right? Ann Neuberger announced that the international counter ransomware initiative was, uh, you know, was started up with 40 countries, right? A US led alliance, and they plan to, you know, sign this pledge where they're not gonna pay ransomware to cyber criminals, right?
And so, um, yeah, it's gonna be interesting how all these regulations kind of, you know, overlap and, and what at the end of the day is gonna happen here. But I think that's just a, you know, a, a ploy, uh, that they, you know, tried to obviously throw out there to say, look, we're gonna, not only are we gonna release your data, uh, but we're also gonna report you to the SEC for, you know, not be not, not disclosing in a timely manner, which they did jump the gun Beyond that obvious ploy, it seems like their whole methodology is becoming much more sophisticated. You hear now that they will, uh, for a monthly fee, they'll not only tell you what's wrong with your systems and leave you alone, they'll defend you against other attacks.
It's becoming very much a protection racket. Yeah. It, it's been the case for quite some time.
You know, when, uh, when somebody gains a foothold in an organization, they certainly wanna defend that foothold. Uh, but now they're trying to monetize every which way that they can. So, uh, it's a, it's a, you know, it's an ever evolving threat landscape and how they monetize that is certainly evolving along at the same pace.
Meanwhile, we're all looking at this AI thing that's coming down the pike, and there's no doubt the bad guys will be using it, but will AI help level the playing field for the defenders? You know, it's another technology that's being used. Um, you know, certainly, um, you know, AI is hot right now.
Um, you know, it, uh, it does have some, you know, accuracy issues on the generative side of things. I think that from the standpoint of being able to optimize and speed up, uh, you know, and scale, right? For more, more mundane tasks and doing data science techniques to kind of strip out the noise, I think there's absolutely use for that.
Uh, but you know, when you ask AI to reason, right? And that generative ai, you know, there are issues there, uh, but you know, the adversaries have been using machine learning and data sciences for, for quite some time to pivot on their attacks. And I think the vendors need to keep pace.
Um, but I think that, you know, one of the things that they really need to do is they need to automate kind of this continuous readiness capabilities of know, of the known threats that are out there, and proactively being able to understand that their tooling is always optimized to counter those types of threats so that, you know, the landscape becomes easier to manage. If you're, if you're addressing the known threats out there and you're, and you're defended against them, well then, you know, you're not trying to boil the ocean when you defend yourself. You have a, you know, more of a finite set of things that need to be done.
And I think, you know, those are all just good hygiene and good practices that, that defenders need to, to take on. And, you know, AI is gonna be part of the landscape going forward. Um, it's just a matter of, you know, using it judiciously so that, uh, it actually works versus, you know, provides providing, you know, inadequate, uh, answers or maybe wrong answers.
There is no doubt that other federal agencies will look at what the SEC has done and copy and paste some of that into other regulations. What do we learn here? What should we think about more deeply than we have had a chance to thus far based on what we've seen?
I mean, 'cause if these are the regulations that people are gonna use everywhere, well then it's gonna be a challenging times going forward. Yeah, look, I I think that the, that the regulations that are, you know, that are, you know, have been passed that are being discussed, are all done, uh, with good intentions in mind. Uh, I do think that, um, you know, sometimes, and we've seen this before where, you know, regulations get passed and then they're used from a compliance standpoint, and then compliance becomes the proxy for security, and it doesn't quite work.
Um, you know, it becomes more of a checkbox and spreadsheet exercise versus a true operational security, you know, foundational, you know, exercise. Um, but I do think that, you know, this is certainly going to open up, uh, you know, the eyes of the security teams I think has become, you know, definitely personal, uh, and, you know, these publicly traded company CISOs now, you know, have, you know, personal liability attached to this. So, you know, I think that this is a departure from what I think is gonna happen is there's gonna be somewhat of a departure from risk modeling and a shift towards more threat modeling.
Um, and I think that, you know, being proactive and, you know, installing and, and automating that continuous defensive readiness capability, I think is gonna be something that is, is going to be really sought after here in the coming months. Because you know, you're gonna need something that provides you with a threat model to be able to assess and identify and manage those, you know, defensive capabilities you've got against the known threats and the SEC called out, you know, those known threats in that legal, uh, you know, document. So I think that being able to defend against those known threats and have in true defensive readiness capabilities, you know, that are automated, are gonna be paramount for the CISOs to be successful In a lot of organizations, the security and compliance have been managed somewhat separately.
Is all that gonna be forced to converge now because the people being held accountable for the compliance or the security people? Uh, yeah. I don't, I don't know if it's gonna, I mean, it, it's been, they've been working hand in hand, right?
They are closely related. Uh, but I do think that, you know, certainly there's a, there's a focus now on understanding the threat, you know, truly understanding the threat and really try, try and understand what the tooling in your organization is in relation to that threat and how to optimize that tooling. So, you know, I do think that there's gonna be more of a collaborative, um, you know, exercise going forward between the two sides.
So looking at this now, you know, I don't know if you have children or not, but you have children, cousins, nephews, nieces, best friends, whatever. Would you tell 'em to get into the security space and move up the ranks? Or is it just a lot easier to kind of sit in the middle because there's too much pressure at the top?
I mean, I look, I think that the security space is a very rewarding, uh, space. I, I think that there's a lot of tremendous folks in the, in the area already. I think there's a lot of tremendous folks that will be entering it.
I think that the, the CSO seat right now for the publicly traded companies is a hot seat. Um, it's gonna be, you know, still to be determined on how this plays out and, and what the real ramifications of this are. But I think that, uh, you know, certainly the SEC has gotten the attention of, you know, of every security professional that's, you know, executive leadership.
Um, and I don't know how it plays out, honestly, Mike. It's, uh, it's, there's still some issues that I think need to be addressed, um, that aren't very clearly defined. Um, but you know, how aggressively they pursue.
And, and how many of these lawsuits actually, you know, are brought to surface, you know, brought to bear, you know, still TBD. How closely do you think the bad guys are watching all of this? Are they slightly amused or are they watching with the level of intent?
'cause they're concerned? Uh, I mean, I, like, I think that, I think that the bad guys do what the bad guys do. I think that, you know, nation state actors have their priorities.
I think that the, uh, you know, the ransomware gangs have their priorities and they're gonna continue doing what they do. Um, this is, I think this is a non-event for them. So what ultimately is your best advice for folks?
What should they be doing? Well, look, I think, as I said before, you know, I think that it's very important, uh, you know, for CISOs to rigorously go in and document their cybersecurity strategies, right, based on the prioritized threats. I think that there is a definite need, uh, for understanding, um, the targeted threats that are coming after the organizations, the vulnerabilities that are being leveraged, you know, understanding the tooling, right, to defend against those threats.
Uh, but I think that it's very important at the end of the day to be proactive and to really be able to understand your defensive capabilities against the targeted threats that are really driving towards, you know, your types of organizations. Uh, and I think that that's a, you know, a, a a critical component of this to be able to threat model, uh, to be able to assess and identify and manages, manage the kind of the defensive capabilities against those known threats, uh, so that you can really be certain that you're decreasing that likelihood of a breach. Um, and I think that is really where we're, we're heading towards is organizations now are going to be forced to really understand their threats and really understand, you know, what they need to do from a defensive standpoint to, uh, address those, those specific threats targeting them.
One other outcome could be with increased responsibility, maybe everybody's paycheck is gonna go up. So will it become just that much more expensive to hire a cybersecurity expertise because the re risk level is just too high? Yeah, look, I I, I, I mean, you would have to, you would have to pay me quite a bit to be in that CISO role right now.
That's a, uh, you know, it's, it's a very, um, uh, you know, thankless job. I think. Anyhow, they, they do a tremendous job of trying to secure these organizations.
And now they have, you know, a lot of personal risk and, and liability associated with it. If even if they do their job, you know, very, very, very well, um, you know, it may be that what is reported out isn't they're doing, and yet they're gonna be liable for something that maybe somebody else had said on an earnings call or in a disclosure, um, that now is gonna by, by the way of, of looks of this, you know, specific SolarWinds, uh, motion that they might be responsible for this now. All right, folks.
Well, you heard it here. You gotta be a very courageous person indeed. But just remember, there are places where angels fear to tread.
Hey, Nick, thanks for being on the show. Yeah, Mike, thanks very much. Appreciate it.
All right. Thanks to you guys in the studio.