Joo Mi Kim on Measuring Security Effectiveness | Qualys QSC23
Joo Mi Kim, CFO of Qualys, discusses the role of CFOs in cybersecurity and addresses topics such as evaluating the cost of cybersecurity, risk management, quantifying the ROI of cybersecurity investments and the challenges of measuring security effectiveness.
Transcript
This is Textron tv. Hello and welcome back to the Qualys Security Conference Americas. And we're with June.
Me, Kim, who's the CFO for Qualys. And we're talking about the role of the CFO in cybersecurity these days because, well, it's expanding and she might have some advice and some things we can learn. Welcome to show.
Thank you. Mike, What are you seeing with CFOs and cybersecurity? There's been a lot more focus on all things related to costs, whether it's IT or cybersecurity.
Um, but at the same time, we're more dependent upon security. We have more processes than ever that are dependent to drive the business. How does CFOs kinda evaluate the cost of cybersecurity?
'cause I think they struggle. Yeah, no, that's absolutely true. And it's been interesting in the role of ACFO because the traditional role of ACFO has always been kind of, if you will, the table stakes are overseeing the finance operations.
And I think more and more we're looking at risk management from the lens of not only the potential monetary laws, but cybersecurity. And especially at Qualys, because we're a cybersecurity company, we're looking at ways in which that, how do we, how do we do it ourselves and how do we leverage that information to help customers to really quantify the risk associated with a potential cyber breach. And how do you anticipate, how do you prepare for that overall?
And I think it's difficult right now because, I mean, there's no standardization, right? And if you were to quantify the risk to the business, you have to really understand all the different elements around the business and, and have that discussion with executives to make the right assumptions that are relevant to your company and there, and then assess what is the risk appetite of your company, and how do, how do we, how do we make sure that we're prepared for that? How do we make sure that when we're purchasing cybersecurity solutions, you know, that you can't a hundred percent insure yourself against all cyber risk?
And so what is the right level? How, how do you justify? And so we're, I'm having a lot of different conversations with our CEO as well as ciso, um, as well as CIO, talking with other executives to understand like what makes the most sense for us?
Is there work to be done either at the business school level or maybe in some association somewhere to help quantify these models in a way that they do become standards? Um, I think that one way to do it is until we come up with a standardization, what I encourage people to do is scenario planning. I know that that's been like existing, everybody's been doing scenario planning, but I'm talking about taking a holistic approach to really understand, prepare for all possibilities.
That's what we say at Qualys, right? Because we've gone through so much in the last few years. Unprecedented times where disruptions from covid and then followed by supply chain inflationary risks, interest rates going up.
And then on top of that we have geopolitical situation bank collapse. And so if you think about it, you have to broaden the scope in which you're looking at things, right? And so if you make certain assumptions under different scenarios, how do you employ, how do you deploy enterprise agility?
How are you making sure that you can run as quickly as possible if certain things come up? And then quantifying the risk associated with it, how do you mitigate that, right? And based on that, you'll be able to run the organization in a way that you don't run into issues where you're just going after profitable growth for an example.
You have to balance that. And finding that perfect balance is what I'm focused on right now. You have to make sure that profitable growth is great, but how do you, how do you also take into consideration some of the risks associated with that?
And are those risks justified? Are you taking calculated risks? How should cybersecurity people engaged with the CFO?
'cause a lot of them look at it as kind of like, it's a trip to the principal's office. So and you kinda have a a real dialogue. Yeah, a great question.
And I think that it's, it's no different from looking at it from a cost savings, which, and people understand when you're coming with a budget, you have to justify that budget and how do you define success, right? And how do you set the targets and how do you check and monitor that? It's the same thing with cyber.
If you're coming, coming to have a discussion with the finance department and saying that you need to spend this much mon money to secure the business, you have to quantify it. What are the underlying assumptions that you're making? And is that based on data?
Like for example, if you're saying that, well, here is a probability of an incident happening and in order to reduce that probability by five 50%, this is how much you would need to spend with this vendor. And then consider what are the other opportunities? What are the other options that are available to you?
Maybe it makes sense for you to like consolidate vendors to reduce that security. But then that might actually, like say you have to have initial upfront calls. So the ROI might not be there in the first year, but you'll have that return over the next three years.
How are you thinking about it? And what are the assumptions that you're making so that we can later in hindsight go back and say, well, I'm sure that we weren't correct in all assumptions, but at least we understand that at the time when we were making those decisions, making those betts, making those investments, we were really thoughtful about how we went about in managing the business. Do we need the cybersecurity people to come up with some more tangible metrics that can be tracked?
'cause well, things might not ever be perfect, but we have to measure something. Absolutely. And I think it goes around to enterprise risk management.
Whenever a company's looking at risk management, you have to really look at it holistically from an enterprise lens. And that when you're doing that, you come out with KPIs, list of KPIs, define it and start tracking it and come up with a baseline. At the end of the day, you're never gonna be perfect in terms of like, there's not market data readily available.
It's not easy to benchmark yourselves to other companies when the, when the like data is not available publicly. So what I always say is, well start with your own historical, are you doing better than last year when you're saying that this is the most critical area of the business where you have to protect your assets in a certain way, right? Then let's measure it how number of incidents that, like how, how often, like how quickly are you able to remediate it?
Let's track the time and then how many resources were did you have to deploy? And then maybe if, if it makes sense for you to hire another person to handle that amount of risk, it would make sense. But after you hire that person, after you increase the number of security professionals or after you purchase another security solution, did that go down?
Is that metric trending in the right direction? We talked a lot today about the challenges security people have with talking not just to the business but to the rest of it. A lot of times the IT folks don't want to patch something.
It may be 'cause they're afraid it's gonna break or for whatever reasons. A lot of times the IT team reports up into the CFO in a lot of organizations. Is there an opportunity for the CFO to kind of facilitate that conversation a little bit?
'cause you're measuring metrics on both ends. Absolutely. And I think that this is, um, part of the reason why all rules are evolving.
If you to think about the new capabilities that are required from all executives, it stems from the fact that, uh, all of us have to really understand each other and how the, the functions work. There's definitely cross-functional synergy that we are required to identify and leverage so that at the end of the day, we, we do have a common goal so that we're not comp compartmentalizing decision making and then working with each other. Do we understand that, what that means for the company holistically versus like your specific kind of like KPIs that you're going after to achieve?
Mm-Hmm. Uh, will a lot of the folks who are on boards today have finance backgrounds. They typically, you know, have some sort of CFO history.
A lot of them are just learning how to spell cybersecurity. Others know more. What's your advice to those people about how to become more literate about cybersecurity and have a meaningful conversation with somebody?
Yeah, great question because I've, I've, I myself have learned a lot since joining quas because if you think about cybersecurity, it's, once you learn more and more about it, it's no different from managing risk. From a financial risk perspective too, you can quantify anything as long as you understand what you're dealing with, understand the situation, you have to first understand all the different elements and inputs that goes into it, right? So come up with a set of assumptions and set a baseline and then start quantifying it.
Don't worry so much about the fact that maybe it's not perfect, like if you say about like, how can you possibly quantify a reputational risk to the company, right? And so this is, I would say that instead of trying to define the monetary value to the reputational risk, because you could say that, well, we might not exist if we have, if we go through this reputation or understand, well, what is the, the, what has the highest probability or the frequencies of happening that would impact your reputation in a meaningful way. And let's start with that.
How often has that happened in the past and what do you think the probability is of it happening in the next year or two? And is there anything that you think that you would prioritize to prevent that from happening? Right?
And so at the, like at the end, it's, it's really has to up at the analytics behind it and the assumption, A lot of times the people on the board will say, well, we spent X so are we more secure than we were before we spend X? And they want to know what the return is. The security people will say, well that's not really a fair question because you know, the bad guys don't have KPIs, they have unlimited resources, right?
And I have no control over those people, right? Right. So how do I have that conversation in a way where somebody in the board feels like there's an ROI, but really understands what that means, right?
This is absolutely the reason why you have to come up with a set of KPIs and it doesn't, I would say start small, start with a set of five or 10 where you can, it's, it's measurable. It has to be objective and measurable, right? And, and so even if, let's say that you have a ransomware attack like next year and you've already doubled your cybersecurity spend, can you really go back and have that discussion with the board?
Did we do everything within our understanding of the, the scope that we looked at, manage the business risk in a, in a proper way, right? And so if you don't even have that, just because there's not a perfect way to measure and you can't possibly think of all different circumstances, you can't say you made a calculated risk, you made a thoughtful judgment in terms of how you were able to manage the business risk. So you have to start somewhere.
And I think measuring it and making that disclosure and having an honest conversation about what does this cover, what are some of the areas that we haven't considered, haven't had a discussion about, like once you have a discussion about it, yeah, there has to be a way for you to objectively measure it. Albeit it might not be perfect. I think everybody out there has opened cybersecurity positions and in theory at least they could invest in automation to eliminate the need for the new hire.
But I didn't hire the person yet, so I didn't spend that money. So can I use that to justify my investment in automation anyway, even though we haven't actually hired that person? You know, that's an interesting question because it's, it's kind of like chicken or the egg and everyone says that look like, you know, you can go around in circles in so many different ways, and this is actually one of the reasons why I encourage people to come to the table.
Let's have an open conversation altogether with all related parties, not have siloed conversation and, and think about the risk that you'd be taking if you didn't do anything versus the risk that you'd be taking by doing something today. Knowing that's not a perfect way to go about, like it might be the least efficient way or it might be like you understand that if you invest in that way, now you might not have the ROI because it's not a perfect setup. I encourage people to first understand all the investment opportunities and risk mitigation opportunities, and you have to prioritize and rank order based on what you think will be the most impactful to the company.
A lot of companies have it in their head that the investment in it will be a percentage of revenue and that the investment in security will be a percentage of it, and yet the business is more dependent upon it than ever. So is that calculation fundamentally flawed because we are living in a whole different era? It is in some ways because it, it companies have gone through this cycle, especially during an economic recession, right?
Like you, you could argue if everyone's looking at it as a percentage of revenue when you're not doing well, then that means that you have limited amount of budget to invest, but then in turn, that makes it so much more difficult for you to re-accelerate that growth momentum, right? And so this is part of the, um, discussions that I think that a lot of my peers are having, our competitors are having is do we lose, do you lose out on that competitive edge? If you say that because of growth is slowing, you're gonna not invest in it, you're not gonna invest in the business.
And so, so then you, you generate the profits. And so like you're looking at making sure that are you taking a balanced bet, right? Balanced approach to growth with profitability and that growth and that revenue.
You have to look at it from a long term lens. And this is why short term will never work out. Because if you think that, you know, in the near term, if you think it's going to result in a long-term value creation, but short-term pain, it might be the right way to manage the business.
And this is part of the reason why a lot of people are looking at unit economics. A long-term return is it's sometimes more beneficial to all stakeholders involved versus a shorter term gain, which might not make sense if you decelerate. And the both, uh, decelerate growth and investments are going up.
Like are you sure that you can justify it? Right? And that, I think that's what it comes down to.
I think part of the issue that security people run into is a, they don't speak the language of business, but the business people, especially at the C level, don't always wanna admit what they don't know. So should the security people just assume that they don't know things and kind of walk them through fundamentally and say, you know, with statements to the effect of say, as you might already know, but repeat the obvious because that's how you kind of bring people along. Absolutely.
I couldn't agree with you more. And um, I think that's probably where we make the most mistakes as like corporations, right? In general, like even with executives, you just, you make too many assumptions.
You just basically say that, look, you're not looking at it from the other person's perspective. You just assume like, well you should have known this and that's why I just made these decisions. This is why, if you think about the interconnectedness, like in order for you to achieve those synergies, you really have to reiterate and even if it means like it, it, even if it seems redundant in in most ways, like step the other person through exactly how you're thinking about it, it's absolutely critical that even if it's obvious to you, step back and think that, think about the fact that the other person probably isn't in it day to day.
So they probably don't understand where you're coming from. And so they're making their own set of assumptions. You might be coming from a very different angle.
And so this is why scenario planning is so important because scenario planning actually forces all parties, um, in like involved to lay out all the different assumptions. 'cause the model has to work. You're looking at like 10 different scenarios.
If if these variables, uh, go in a positive or a negative direction, what is it gonna result in? Are you looking at the flex in terms of budget perspective, in terms of risk, perspective exposure, and then the growth opportunity, the return perspective. All Right.
Um, you've been at this a while now and working for a security company as ACFO. What do you know now that you wish you knew when you first started in this particular role? And what can other CFOs learn from you?
Yeah, I think that I learned a lot about the last point that I made about the importance of taking a holistic view. The enterprise agility is so important because you run into situations like we've run into in the last couple years and you think that you're prepared, but you're really not. 'cause you, I mean, when Covid first came out, everybody was saying that, well, we didn't know this was gonna happen.
It wasn't included in our scenario planning or the poss the realm of possibilities. And so everybody was kind of scrambling and I think a lot of value was lost during that. But after that, we, we came to fruition that look like, given that we just went through it, we can't use this excuse again.
So what are some of the other kind of outside the basis scope of possibilities like class of Silicon Valley, like bank, like, we didn't anticipate that either, but were we able to navigate a little bit better? Absolutely. Because we, we thought about, well, like if these are, we are living in a world of globalization, right?
And people were talking about potential like de deglobalization because so many things have happened and there are puts and takes to it. I think that for, for me, like really being thought, thought through about how it would impact different aspects of the business, not just like from a monetary loss perspective, but from like go to market perspective, from sales and marketing perspective, from the like short term as well as long term risk per long term return perspective. How, how do they, how are they all interconnected?
Like how are they different executives really thinking about it? Because that helps you to prioritize who, who do I have to go to first to discuss it and what are some of the questions that I have to ask to make sure that we're coming up with a potential solution to a problem that before might have not have resulted in the best solutions. Just because not everybody who should have been informed or who should have been consulted were in, in that process.
As Monty Python once said, you need to expect the unexpected. Many of the things you're describing, we used to call 'em black swan events. Do we need to make some assumptions about black swan events?
Yes. Yes, absolutely. All right folks, will you heard it here?
Check your assumptions. 'cause we all know what happens to you and me when they're wrong, but if we think about it, we can get ahead of it. Yes.
Thanks for coming by. Thank you, Mike.





