Navigating Compliance and Automation with Tom Copeland | Qualys QSC23
Transcript
This is Techron tv. Hello and welcome back to the Qua Security Conference for the Americas. I'm here with Tom Copeland, who's head of GRC for AB, F, and they operate in 55 countries, is it correct?
Yep. Which is a rather significant amount of effort. It is in terms of what GR C's gonna be all about.
Welcome to the show. Thank You very much. 55 countries, each of those countries has its own set of regulations and there's probably multiple regulations within each country that you gotta deal with.
Correct. How do you cope with that? Um, it's, it is a challenge.
Um, so we're quite fortunate that in each of the different territories we've got localized kind of security managers. So, um, we have a central function which kind of has our guidelines and policy and standards, and then each of the different business units will, um, attest to those and make sure they're compliant. Um, and then obviously they're the subject matter experts, again with the regulations that are required for their, um, their regions.
So for, for me, it's obviously based in the uk, GDPR is one of our kind of really major, um, compliance and legislation, um, things that we have to comply to. How much overlap is there in the controls from one country to another, or are they all so uniquely different that you can't really leverage? Um, so since GDPR came in in 2018, we're seeing a lot more overlap between the different, um, legislations.
So especially in the eu, a lot of the similarities. There are some nuances with like Germany where they have work councils, so they have to get, um, which are built up with their own employees that have to kind of look at approving any kind of changes or anything along those lines. Um, but certainly with the sort of like transfer mechanism, datas, et cetera, that the controls are relatively similar, How automated can the process get?
Because it seems to me at the level of scale that you're currently at, there's gotta be a lot of automation, but what, how far? Yeah, so we're, we're starting to look at automation, so we're relatively early on in it. Um, there are some things that we can do, especially it comes to like access reviews, those kind of controls.
Um, but we are still quite junior in it, so there are, there is a lot of manual processes that we're still going through to measure our levels of compliance and on a regular basis and those kind of things. Third party assurance as well. So we've got some process in there from third parties to help us kind of understand the risk of some third parties.
But again, it's still a manual process for us to go to the third party, understand what controls they have in place. Um, so yeah, so we can get some assurance on whether we want to sign up and use 'em or not. And then we aggregate all this stuff and we present it to some auditor or who comes around and how often do they come around?
Yeah, so um, we have some internal audit functions, um, but then we also obviously have external audits that come in as well. Um, we are ISO accredited, so we obviously have those kind of audits that we have to, um, comply to obviously keep that um, uh, certification. Um, so yeah, there's lots of different external bodies that do that.
We also have, obviously within our compliance team, we'll do their own kind of audits against um, our application system, third parties as well. You seem pretty calm, A lot of people get stressed out about audits, so what's your secret? Um, it's a good question.
I don't know, I, I've always been told that I'm a relatively relaxed person, so whether that's just 'cause of my nature, but um, uh, yeah, I dunno. I dunno, I'm very calm head. So what does worry you, you know, what keeps you up at night or makes you go, Hmm, I'm a little concerned?
Yeah, so I'd probably say the most recent thing is the third party aspect. Um, for me at the moment when you kind of assure against a third party, it's a point in time. So they may be, I have a gold star rating at that point, but two weeks down the line it might be very different or they've made themselves susceptible to something else, which then obviously is a risk to us that if they're holding some of our data or something along those lines.
Um, so yeah, that's probably one of my main concerns at the moment. Has this whole thing become a continuous process? Because it used to be the audit was an event, but now it seems like it's a 24 7 thing.
Yeah, so we, it's obviously an event right at the beginning when we're onboarding and we try to do it on an annual basis. Um, but I think we're at the moment trying to work out how we can improve that to make it more up to date, more regular. So we, we know the details as soon as possible, but um, yeah, it's, we haven't got there yet.
We don't know what the fix is. Alright, We're here at a Koalas conference, so clearly you're a customer. What brought you to them and you know, what was the appeal?
Yeah, so we've been with Koalas since 2014, so we've been with them for a very long time. Um, I think we've got, we've got a really good relationship with them, especially in their sort of like support area. So, um, and we've just gone from strength to strength with them, especially seeing our vulnerabilities drop and, and the new, uh, material that's come, especially with true risk, getting a much better picture as to where our risks are, um, is, yeah, it's um, what's the word?
I can't think of the word, but it, it would be lost without it kind of thing. Now Do the business folks understand the function and appreciate it or is, 'cause we've been hearing a lot about there's a disconnect between the security folks, the compliance folks, the IT folks and the business folks. So how do you guys manage that?
Um, so we do work very closely with the different departments and so I'm very keen on making sure that, um, making myself aware, known to them, um, engaging with projects really early on. So, um, that security's kind of security's done by design during the project and all of those kind of things. I'm also trying not to be a blocker.
I think that's a big thing for me. So being, being very collaborative with the business. So, um, they, it might be that they can't do something one way, but I then work with them to get to the same kind of outcome but doing it a different way rather than being that that blocker, which then obviously puts a negative image on me and then they, I might not be as approachable or they'll try and divert me to do something else.
Right. Or they'll just go ahead and do something and then you'll be surprised later. Exactly.
Yeah. Ask for forgiveness. Alright.
Um, is GRC, you know, you don't see the word security in GRC but is the GRC function and security converging coming more tightly coupled? Yeah, I would say so. So I report into security so, um, oh yeah, we, we are arm in arm really to be honest.
Um, we, we abide by the information security policies and guidelines and we help enforce them and then if we are looking at the operations side of things as well, we obviously support them in any investigations, um, if we detect any kind of gaps or anything along those lines, informing them to obviously help us to close it if necessary or additional monitoring and those kind of things as well. A lot of focus on cost these days. Anywhere you go, what do you guys do to kind of maybe have a best practice for trying to keep some control of those costs?
Um, so I must admit that's probably a bit out of my kind of remit. Um, but I know when we look at, we do risk assessments and all those kind of things so we can kind of see if there's a major risk, we can look at what the cost impact might be to resolve it or if we don't resolve it, what that kind of impact might be as well. Um, and I think it's definitely kind of looking at what's on our risk register as well, saying actually these things are really important.
We need to focus on putting these controls in place and whether that's another, a system solution that comes in, then it's all kind of that kind of assessment as well. Are the auditors getting smarter and tougher? Uh, I would say so, yeah, they're um, they definitely dig a lot deeper than they used to I think.
And they've definitely got a real focus on information security, um, than before like 10 years ago. Um, so yeah, no, I think they are. Alright.
What, um, brought you into this role in the first place? Is there something about GRC that, you know, you were like, wow, this is for me here? So I've been in ABF for 10 years now, so I've held varying different security roles.
Um, so I was a security manager within one of the businesses and then I was in the corporate center for a few years. Um, I think for me the risk aspect is the real kind of bit that I enjoy the most actually the assessment, understanding, um, what the gaps are and uh, and kind of following it through, um, IGRC, I think it's, again, I kind of do feel as if I fell into this role a little bit to be honest. Um, but I am enjoying it.
Um, I do like seeing things end to end. Um, which obviously you do get with that kind of the, the, the governance piece of saying how things need to be done and then the compliance bit to check against that. You've done it with the risk in the middle.
There's always a lot of consternation about, some people think, well, we're compliant so we must be secure. But maybe it turns out that that's just the baseline and we need to be better at security. How do you kind of navigate that conversation?
Um, that's a good question. Again, I think, again, I always take it back to risk. We can, we can put as many controls in as possible, but if the, if those controls aren't gonna dampen the risk enough for us, then obviously then that feeds into the conversation around um, what additional things do we need to do to to reduce that.
Yeah. How do you quantify that risk? 'cause we've been talking here about some of the methods that these guys have come up with.
Um, how do you guys approach that conversation? Um, so yeah, so at the moment we do it very much on kind of, uh, impact and likelihood. Um, and it's more, doesn't really look at a, um, a cost basis at the moment.
It's very much on sort of like the impact to the business and whether it's gonna be disruptive and those kind of things. But we are looking to see if we can put more of a cost against a risk to see what the material impact, um, to the business will be. Um, so yeah, that's what we're doing at the moment.
Alright. There are other folks who are just starting their GRC journeys, you know, what do you know now that you can wish you knew when you started out? Um, I think for me one of the big things is it's just, it's every day is different.
It's ever evolving. Um, uh, I think big thing for me is, uh, seeing things with your own eyes, not necessarily taking something at face value. Do your own digging to get your own confidence.
Um, and yeah, I think deep down I quite enjoy it as well. So it's a bit of fun. Lot of talk about AI and it's still early days.
What are you expecting? What do you think you're gonna see? You know, does this, is this good news or a little scary?
Um, I think it's a little scary, but I think, uh, if you know how to utilize it in the right way and make sure it's being used in the right way, um, I think it can be a real benefit in helping do automation piece that we were talking about. Um, so I think yeah, it's just harnessing it correctly. Um, I think it'll be a benefit.
So. So how big is the GRC environment and what goes into that? What, I mean is it all just Qualys?
Are there other components? How do they interact with each other? Yeah, So we've got a lot, we've got a lot of tooling that, um, supports us, whether it's third party tooling to help with risk assessments or um, monitoring of, um, various different things.
But there is a lot of manual processes in it as well, um, that we're obviously hoping to onboard in maybe some other platforms to help us with risk register building and all of those kind of things. So it's, it is a bit of a hybrid, hybrid model at the moment. Alright.
Um, what is your sense of the, we, there's clearly more regulations being considered all over the world when they're getting tougher. Um, do you guys actively monitor that? I mean, how far in advance do you plan when you see this kind of stuff?
Yeah, so we do monitor these kind of things. It might not necessarily be my function, but they certainly feed into us so we can then have good visibility of it. We can, um, plan for the changes that are coming.
Um, uh, but again, it's obviously dependent on uh, the, the feeds that we're getting, how, how up to date and how accurate there are. Mm-Hmm. We've got good feeds in at the moment.
And how trustworthy is the data that you're getting, right? Because you're collecting a lot of data from places but the all the time and they're highly dynamic. Mm-Hmm.
So how do you know that, that it environment your own, nevermind the third party one is, you know, still compliant? Yeah, so we obviously do a lot of third party testing, like penetration testing to obviously get some comfort in the environment. Um, obviously encourage our third parties to share results with us of their kind of compliance checks.
But again, it's one of those things, it's a point in time, how, how often can we do those kind of checks. At the moment it's all, sometimes it's a yearly exercise, so you'd hope that you're in the same kind of gold standard one time to the following year. But again, it's, so it's having the resource or tooling to help us kind of close that gap.
It's a little fluid as they say. Yeah. Where does the, the reports that you generate, they go to some sort of government agency that looks at all this stuff or where does this all, where does that outcome all wind up?
So the outcome mainly kind of stays in our business actually, to be honest. And it helps us kind of deliver our roadmaps of the things that we're gonna address. Or it might be to our stakeholders saying we've got these particular risks that we might need some support in addressing or them accepting the risk and we're sort of like progressing or, um, but yeah, no, we don't really, we don't share anything with the external parties.
Maybe if we had like a security incident or something along those lines, it might go to a government body so they can um, obviously do some investigation and see if that information can be shared with any other entities. Um, but the majority of it is in-house. You're not seeing, uh, regulators and people from, uh, the governments showing up saying, you know, we wanna see this as part of your financial statements yet.
Um, no, we do publicize sort of like our, uh, uh, risk statements, et cetera. But no, not nothing from any kind of regulators Mm-hmm, that I'm aware of anyway. You talk to your peers a lot, what do you hear from them in terms of what they're experiencing in terms of challenges?
Are they similar? Are they different in different countries? Um, I guess there are some similarities.
Some, some of, uh, my peers kind of deal with sort of some customer service kind of impacts, so how it security impacts their users. Um, definitely phishing is one of the things that we have a lot of similarities with. Um, and definitely third party, the management of those third parties and the assurance around those is definitely something that we're all seeing.
Are the attacks changing in ways that are novel or interesting? Um, I guess so we're seeing more stuff around, um, sort of like messaging services I guess, rather than just email, um, uh, wishing so QR codes, um, things, we're seeing a lot of those as well at the moment. Um, they seem to be similar, similar outcome.
It's a type of phishing, but just different mechanism that, that it's being started by. Are they after money, are they after data or both or? So luckily we haven't had any of, um, the output of someone doing something like that, but from what we can see, it seems to be more kind of, I guess disruption and ransomware, those kind of things.
Alright. So if somebody gave you a magic wand and said, here's your one wish, what would that be? What would be the thing you'd wanna change about the way GRC functions?
Um, I definitely think, um, more automation, the only, and then it frees up the, our own resource to them, focus on the other map, things that really matter and we can definitely plan for the future and, um, put the tools in place to help with things like third party assurance and all of those kind of things. There is a chronic shortage of security professionals. I don't know if there's a similar chronic shortage of GRC professionals.
Yeah, so there's a, there is a shortage of security professionals, I think. Um, yeah, we're not, we're not immune to that unfortunately, so, um, so yeah, we need more of them. All right.
Well, you got a few right here, or why come to work for you guys? Um, oh, why would you come work for ABF? I think it's just, it's because of the, the global size of the business.
Um, every, like I said, every day's different. You've got different contexts of different businesses delivering different things. Um, there definitely a lot of development opportunities, so I definitely recommend it.
All right folks, if you're looking for a gig that they looking to hire. So now's the time. All right.
Thanks for coming back. Thank You very much. All right.





