Voice of the CISO with Proofpoint’s Patrick Joyce
Proofpoint launched their annual “Voice of the CISO Report,” which reveals that 70% of CISOs feel at risk of a material cyber attack in the next year (note: less than half reported feeling at risk back in 2022). Patrick Joyce, global resident CISO at Proofpoint, discusses how this report explores key challenges, expectations, and priorities of 1.6K CISOs worldwide in 2024.
Transcript
This is Textron tv. Hey everyone, welcome back here to techron tv. I'm happy to have, it's actually his first time on techron TV here, so, well, let's welcome, um, Patrick Joyce.
Uh, Patrick is the Global Residency, so over at Proofpoint. Hey, Patrick, welcome to Text Drunk tv. It's nice to have you on.
Hey, Janis, happy to, happy to be here. Thanks for the invitation. My pleasure.
So, Patrick, you know, we, the way we do things here is I always like to kind of let our audience get an idea of who it is that they're talking to or who's talking to them more accurately. Um, why don't you give kind of folks a, a bit of your journey and, and how you got here today? Oh, one of those convoluted journey stories.
Well, great. Yeah. I've been with Proofpoint, uh, actually less than a year.
I joined the last fall, um, in this role. Um, I've just spent, uh, the last 18 years at Medtronic, uh, world, uh, world's largest med tech company. Um, I was the CSO and the cso, uh, for the company for the past 10 years.
So I had a combined role of physical security, cybersecurity, did some stints in their product security and privacy and audit and other things like that as well. So, uh, spent a long time there in that role. Built a great team and, and worked for a great organization.
Um, happy now though, to be with Proofpoint as the resident global residency. So, and what that really means is I, I, I describe it as I'm Switzerland. I live between the customer, uh, CISOs and IT pro provide advisory services and support and assistance and mentoring in some cases to them, um, and listen to what their needs are.
And then I help translate that back to our product and marketing and communications teams, um, so they understand what a CISO needs. So I bring perspective to Proofpoint from the, from the field of being a CISO and having lived in that role. So it's really a, it's really a fun role.
I get to do interesting stuff every day. Sounds like and good. You know what, I always tell people, if you gotta get up to work every day you're in, you got the wrong job.
Right. You gotta kind of be excited and love what you're doing. Exactly.
Patrick, proof point's been around a bit. I mean, I've been in, I've been in s cyber for a long time in the industry here as an entrepreneur and, and now media person the last 10 years. Um, but not everyone out here knows Proofpoint.
I mean, there's so many security companies who can blame them, uh, for people maybe who have heard the name or haven't heard the name. But, you know, in any event, not sure what Proofpoint does. How would you describe Proofpoint to folks?
Yeah, well, it's actually, it's a great organization and I was fortunate to be a customer of Proofpoint and then also serve on their customer advisory board for the, the last five years. So I got to know them pretty well. Uh, Proofpoint is, is one of the largest security companies out there.
Been around for a lot of years, um, has grown significantly. Um, a couple stats that you might find interesting. So for those that don't know who we are, we, we protect, frankly, the world's email.
We, our focus is on being very human-centric, uh, protecting people and, and the vulnerabilities to people through email and other, other activities. And then defending the other side of the house, which is the data and da data being data centric and focusing heavily on, uh, making sure that the sensitive data stays within organizations and all, all the other activities in between that. So just an interesting stat, uh, Proofpoint protects, uh, I think the number right now is 86 or 88% of the Fortune 100 email.
Um, and I think somewhere in the area of 68 to 70% of the Fortune 1000 email. So that's a significant volume of very sensitive data flowing through our, our platforms, literally every second of every day. Sure is sure is.
Um, I mean, look, e an email. It, it's funny, they've been predicting the demise of email forever, and it's still the best communication. You know, I, I, I use Slack, I use other, you know, WhatsApps and WhatsApp use what and messaging, but I'm still an email person as I think many, many folks are.
Yeah, we're showing our age a little bit, Alan, in that regard. And, and sure you're right. There's a lot of other platforms out there.
Uh, but those other platforms have vulnerabilities too, right? Sure. So trying to find the right method by which to communicate in the right context and sequence.
Um, you know, I use things like teams. I use things obviously email, I use other types of messaging, but when you think about it, different messaging platforms serve different needs. So yeah, email's gonna always be there.
Absolutely. com? Is the URL?
It is. All right. So if people want to go find out more about Proofpoint There, there, there you go.
Um, all right. Topic of discussion is proof point's 2024 voice of the CSO report. And, uh, if it's the 2024 report, I imagine this has been a, an ongoing annual type of report.
Uh, I guess we should start there. Patrick, how many years has Proofpoint been doing this, if you know? Well, I'm gonna have to think for a second, but I know all the way back at least to 2022, if not 2021.
Um, okay. I think is when, when it started. It's A good couple years.
It's been a, it's been a good few years all during the pandemic as well. The numbers have grown significantly though, in terms of the survey. I mean, this year we surveyed 1600 CISOs Wow.
Across 16 countries. So we really got a good, a good spread of per uh, perspectives and, and, uh, and, and beliefs around what CISOs are really dealing with every day. Excellent.
So, you know, I, when we deal with reports and surveys and so forth like this, I always like to ask, you know, what are the, what are the three key takeaways here? Yeah. It's pretty interesting when you look at, and it's, it's kind of fun to go back to and do some comparisons of year over year of how perception and beliefs and concerns are changing.
I'd say the number one is still that that human error still tops the, I guess, the vulnerabilities and threats that most CISOs are concerned about. And they're turning to things like ai, I'm sorry to use that buzzword, but they're turning to think, Well, no, look, you, you want a good seven, eight minutes without using Yeah, well, okay, today's World, that's pretty damn good. So, but they're returning the technology to help protect the human right.
It makes perfect sense because the, the, the technology if, if deployed the right way can keep people from making mistakes. So human error is still the big one. Whether it be phishing, whether it be clicking on the wrong thing, whether it be downloading data that they shouldn't be downloading or moving it, or sending an email by mistake that sends a lot of sensitive information out there.
AI can help solve a lot of that. Um, so, you know, gen AI is a big concern, I think for most organizations. Trying to, to balance that double-edged sword of the positive strengths that you can get from generative, as well as how do you control that?
The genie wants the genie's out of the bottle, so to speak, right? And being able to manage that from a risk standpoint. Um, data loss is probably the third largest issue.
And data loss comes in lots of different forms, right? I mean, data doesn't walk away on its own. It's usually purposely sent or erroneously sent.
Um, employee turnover is a big part of that. And the CISOs have, have, uh, have again, looked at, look at AI as a way to try to protect that from A DLP perspective. Um, and then there's always the board relationships.
There's always the concern about liability. Right now, that's a big one for just the pressures on CISOs. There's so many angles coming at them in their role.
Um, it's hard to imagine another c-level officer with, with the number of pressures that are coming at 'em, other than maybe being a CEO yourself. Yeah, I, I agree with you. It, it, look, I saw before doing this interview, I was taping our Textron gang segment, and, and we, we spoke about, you know, AI and cybersecurity for it.
And, and here's the good news. The good news is helps on the way it seems like every, every vendor from large vendors like Palo Alto and IBM and Cisco and so forth to, to startups are harnessing AI to try to force multiply, if you will. Yep.
Our protection profiles and so forth. On the other hand, Yeah. Right.
You know, on the other hand, the bad guys ain't stupid. And, and they don't, they don't sit around waiting for their board of director's budgets to come through and, and and so forth. Right.
And they just do, and, and they're using this maybe faster, better, quicker it than our security vendors are. It's Not, yeah. We talked a lot about that at RSA just a few weeks ago.
Right? Sure. It that it's, it's not going away.
It's gonna do nothing but increase. Um, but, you know, the reality is proof point's been using machine learning, excuse me, generative ai, but machine learning and AI for years, it's been the core of our business. And you have to use machine learning to protect the algorithms, to protect the email, and hence why we're able to protect the, the large volumes and percentages that we do.
But yeah, it's, it's a big concern. And kind of back to the CSO report, when you look at it, there's, there's a lot of things they have to be concerned about, and it's all simultaneous, right? It is the bad guys and what actions they're taking.
It, it is the, you mentioned, you know, either reduced budgets or maybe frozen headcounts. If you look at the resources that they're under, it's not like the CISOs, and we certainly learned this in the report this year, are feeling that they're getting more resources or more help in reality. They're having to kind of trade in and trade out what they're doing to try to protect the environment that's constantly changing.
Mm-Hmm. I, you know, and, and, and I I will say it, that's kind of across the board in it, right? We want 25% more with 25% less.
Yeah, True. And that's a hard, that's a hard equation. You know, the math doesn't always work like that.
No. And, and I think we're running into that, but look, let me play devil's advocate for a little bit. When did you ever see a report where CISOs didn't feel at risk when CISOs didn't say, oh, I've got enough budget, I got too many, I've got too many security tools.
They may say, I have too many security vendors that we're certainly seeing that. Right? Right.
But you know this, and, and take it. I, I've been in the security industry a long time, so I don't mean to be throwing rocks, but aren't it CSOs kind of the boys who cried wolf? Maybe.
Hard to say. I think it, I think to some degree it depends on the industry is I think there's been a lot of that maybe have been more resources than others. And I don't know.
It's hard to say because the reality is you're, you're only as good as the last incident. You're only as good as the last thing that occurred or Was the last. But here's the problem.
Being a ciso, yes, you're only as good as the last incident, but you're not only as good as the last incident that you prevented. 'cause no one knows you prevented it. It's the crime that ever, but that's always been the problem in security, right?
No news is good news, but no news is no news. Well, one thing actually we're trying to do from a, and I, I always refer to it as the, the crime that never occurs. We working really hard, hard at proof point to put technology in place to, to your point, to prevent the things, but then be able to give the CISO the ability to be able to, to be able to quantify and communicate what their technologies and teams have been able to avoid.
Right. And try to put some, put some quantification around it. So you're right, you're only as good as the last one that never happened.
Um, but that's the nature of the beast. That's the nature of the business. It's gotta get used to it.
Yep. There's always something in a report that surprises you, Patrick, that hey, it seems counterintuitive. Didn't see that coming.
Anything here that kind of jumps out at you that way? It did a little bit. One of the, one of the takeaways we had, I gotta look at my notes here.
It, it said that most CISOs are, are more fearful, um, of cyber attacks. Um, 70% felt at risk of, uh, experiencing a material cyber attack in the next 12 months. So that, that's a big number.
That's up a little bit from last year. It was 68 the year before and 48 the year before that. So it's, it's still rising a little bit.
But with that concern or fear is maybe the word, um, they feel, um, more prepared. They feel like they're in a, in a position to deal with, respond to address mitigate those attacks. Um, I'll take that as a ray of a ray of hope, right?
So yes, the, the risk is increasing, but they're also feeling more prepared to deal with them and respond to them. So I was a bit surprised to see that. So kind of flies in the face of the cry wolf thing a little bit.
Um, but maybe it means that some of the work that they've been doing over the last few years and the partnerships we've all had across the industry are paying off. Well, you know, I, so here's my take on that. For what it's worth, I think, I think we take both of those metrics, right, the 70%, but yet they feel more prepared.
I think a part of this is the realization that we've come to in this industry that no matter what we do short of unplugging from the internet or something, and even then we'd probably'd find a way. No matter what we do, we are not gonna totally prevent material cyber attacks. It never, right?
No. We could try and we could thwart, but we're probably not going to just totally prevent material cyber attacks. And as a result of that, the, the balance, the pendulum has swung more to the response rather than prevention aspect of, of cyber defense.
And I think we're starting to see that really kind of in spades now where organizations feel better prepared to respond because they know it's not if it's when. Oh, absolutely. And, and that's been a, that's been a term for a long time.
So they're, you know, they're spending more money on things like DLP to prevent stuff from going out the door. Yep. They're spending more time on education and training because they always feel that if you can protect the human, it'll protect some of the risk on the front end.
What's the weakest link? Exactly. But they're also relying more, they want to rely more on ai, like I said, and they also want to rely more, frankly, on ransomware to cover risks and mi and mitigate risks on the backend.
So it, it is a, it is of a before and after kind of thing. It's a front door and back door. But you're right, you have to, you have to, you have to focus as a CISO on that full spectrum.
Yep. I, I, I don't disagree. Um, here, here's the bottom line for me.
It's still hard being a ciso and, and one of the things we saw last year is, you know, CISOs with criminal, uh, charges CISOs with, uh, SEC kind of, uh, charges and, you know, it's a hot seat and it's always been a hot seat, Patrick, you know, that, I mean, the fact that you were at one place for 10 years is probably kind of up near a longitudal longevity, you know, record or, or It shows a lack of intelligence maybe. But, uh, either way. Well, water could be that too.
Yeah. But, you know, the average CISO is an 18 month lifespan, something like that, I think is what the, the numbers show. Um, so it's not an easy job.
And it, and quite frankly, in today's, you know, AI jacked up environments, it's not necessarily getting easy either. It'll be interesting to see the, the 2025 voice of the CSO report, what's changed as a result of this. Because the other thing is things are happening so quickly.
I, we, we saw, I was at RSA two, we was sending our broadcast alley all week. We, we did our DevSecOps event there on Monday. Um, things are moving faster and we used to talk about the internet time and crunch time.
Well, now AI seems to have crunch that even more and things are really happening. So, you know, uh, buckle in, strap on and, and get ready, I guess is the mantra. Yeah, I would, I would agree with you.
And the expectations of a CISO are not gonna go down. They're just gonna go up. Um, one of the stats that came outta the report, which did not surprise me at all, was that 68% are concerned about personal liability.
Well, you've talked about that, right? But 72%, this is a great number. 72% would not join an organization that does not offer d and o coverage.
It seems common sense in today's world. Well, you, so that jumps out to me, Patrick, is what the hell are the other 28% thinking? You know, I, I've asked myself the same thing, Alan.
I have, I have, You know, I don't know if I'd want that job without it. That's, anyway. Hey, Patrick, we're about outta time.
I want to thank you for coming up on here. com is the, is the url, is there any specific URL that they can get a hold of this report? Or is it just off a front page?
Just go to the Proofpoint? com, um, address and click on, click on. There's a, there's a couple tabs on top.
You click on ciso. Um, there's some, you'll be able to get the links there. It's probably even on the front page right now.
So. Excellent man. Patrick, thanks for joining us on Text Drug tv.
I hope this won't be the last time. We'll see you back on here soon. All I will, welcome to the invite again, Alan, thank you so much.
Appreciate anytime you taking the time. We appreciate you and all you guys are doing. Good luck.
Thanks, Patrick Joyce, global resident CISO at Proofpoint here on Tech Trunk tv. We're gonna take a break. We're gonna be back with our next guest in just a little bit.