Continuous Improvement in Cyber: Findings Are the Point
57m 11s
The discussion centers on the importance of integrity and transparency in cybersecurity governance, risk, and compliance (GRC). The guest, Peter, highlights that integrity-driven leadership involves openly addressing vulnerabilities and findings, rather than hiding them to avoid difficult conversations or present an overly positive image. He stresses that continuous improvement is key, and findings should be viewed as opportunities, not personal criticisms. The conversation distinguishes between passing audits (like PCI or SOC 2) and running a full security program, noting audits are often limited in scope and depth and should not be the sole focus. Proper audit scoping is crucial to balance thoroughness with boundaries, avoiding both negligence and excessive intrusion. Both sides—executives and security leaders—share responsibility for fostering a culture where risks are openly discussed and addressed. The dialogue underscores the need for coachability, collaboration, and separating ego from work to effectively protect against evolving threats, emphasizing that cybersecurity is as much an art as a science.
[MUSIC] Cyber that actually protects is as much art as it is science or tech. Welcome to the Art of Cybersecurity Podcast, where we say what needs to be said. >> Hello, everyone, super excited for our episode today. I have an amazing guest that I've known for quite some time. Peter, hello, how are you today? >> Hi. Thanks for having me. Good, how are you? >> Of course, yeah, it's been a while since we've talked, but see you on LinkedIn, of course, that's kind of like knowing someone, right? No, not really. >> I think so. >> Yeah. >> Connection or mood, maybe. >> Oh my gosh, such a crazy world. Yeah, we met, gosh, it was probably around 2012, maybe. >> Sounds about right. >> Well, over a decade ago, did some PCI work together? Woo-hoo, so exciting. >> Oh, yeah. >> Because you were, maybe still arc USA, and so definitely got the opportunity to get to know you. So you want to briefly introduce yourself for those listening? >> Sure, my name is Peter Spear, and I'm an integrity-driven GRC leader who has been doing this for about 25 some years. I did PCI for a good decade, leading a practice, and building out its payment application, and all the stuff that goes with PCI. >> I just recently started doing a little bit more work on that, but not with a QSA firm. So it's kind of a nice return to form. I think PCI is a bit of a comfort blanket for me. >> Yeah, that's fantastic. And of course, that's how we met with PCI, but okay, we're going to have such a fun dialogue because you literally said something that I'm like, "Whoa, wait, what?" Integrity-driven GRC leader. "Oh my gosh, you used the I word in the first one minute. What are you thinking? Oh, please unpack that for the audience. That's why I'm super excited to be having this chat with you." And unpack that. What do you mean? >> Well, first off, credit where credits do. I don't believe that AI is an evil that we can never use. It's a tool, and it has evils to it, but I'll credit the integrity of everything to chat GPT. I was telling a little bit about my background, giving a little bit of my experience while I was prepping my LinkedIn profile, and it came up with, "Hey, integrity is pretty important to you." And I'm like, "It sure is." So what does that mean? Well, you know, I think that's a thing in GRC in a risk that it's probably worse than any risk that you actually run into that vulnerability driven, let's say. We can all have vulnerabilities, and they can be exploited, they can be patched, maybe. There's all kinds of stuff that we work collectively in cybersecurity to try to protect. And yeah, a lot of it's about the data, but the real risks that we don't get to see very often, we don't talk about all that much because we're so focused in what sounds cool coming out of the latest hack, is the idea that a lot of the times we know better. And we just chose not to, because it didn't seem risky. And it was no more risky today than it was yesterday. And, hey, you know, wouldn't it showing some red on that board report cause some questions? Yeah. And that's where we start to see leaders make little compromises. And those little compromises are slippery slope. Before you know it, everything's green. It all looks good. We're doing great world class. But the reality when we dig into the details as an auditor or as a GRC assessor is that it's not always all green, it's not always all rosy. And in fact, a lot of the things that should be spoken about with the board or with other leaders is actively discouraged or hidden or downplayed because it would make us look bad and it would make things harder and difficult and uncomfortable conversations. But yeah, in GRC, that's really like the business. We're supposed to be able to have uncomfortable conversations because it's a process of continual improvement. A finding is not a slight on you. A finding is part of the process we need findings because if we don't find them, that's when the hackers do. Yeah, boy, so true. And you know, I fault both sides and a thousand percent agree. And, you know, thank you, Peter, for saying what needs to be said. More people need to say what needs to be said. And that's part of what we do here. This is this is not black and white. It is definitely an art. And, you know, back to the green. I'd like to joke about the green tech mark. We're good, right? Ha ha ha. Okay, well, it's a bad on both sides, honestly, because it's bad on the executive for not having more common sense or the board to go, but are we really green? And what does that really mean? And can I sleep while at night and to really ask the right questions? And then it's a bad on the security leaders who maybe intentionally do that, maybe don't intentionally do it because they're just not monitoring to the level they need to be. Or maybe they've had their handslapped so many times. They're tired of getting their handslapped. And so they just kind of back down. I mean, there's a lot of reasons for it. It's not really one answer. But you're right. I love that you said continuous improvement because that's what we should be driving. It's funny. You know, we have to, I say this all the time, I'm thinking of a particular scenario that I'm not obviously going to say, but somebody got a little sideways because my mindset is we're always lifting the rocks up. We're always looking under the covers. We're always saying, is this really the way it is? That's what we do because that's how we get better and we have to always remain coachable. The minute someone takes that personal like, oh, did you say I didn't do my job? Okay, that's not what this is about at all. Like this is not about any of us. This is about I think I think it was probably with you or back when I was working with you, you know, every day, I remember like in the PCI space, I went to one of the conferences and they were talking about back then the bad actors are like constantly staying ahead of what the latest greatest thing is. If we're right there ahead of them, we've lost the game. And so really just what you said, continuous improvement is what helps us to stay ahead of the game. We should never take that personal nor should we sleep it under the cover nor should we pat ourselves on the back and say, look how great we are. And so because because that's just not what the goal is here, the goal is to stay ahead of the bad actor, the goal is to continually be looking for what needs to be changed. And I love that you brought that up because that is core of what we do. And then I'll just say one more thing and then I'll stop because I can't wait to hear what you say next is coachability. I say the minute all of us and you mentioned 25 years for the record, I would never admit I was a professional for that many years. So props to you Peter. But no, no. But the point is whether you're one year in your career, 10 years, 20 years, more years than you're going to admit, if we don't maintain coachability, if we don't always stay coachable, we're done. We've lost. And so that coachability comes from all sorts of different places. We just need to be in this state to receive it. So wow, I'm blown away. Thank you. You're welcome. And I agree entirely with that perspective. You know, I think to your point about being able to sleep at night and understanding thrust to ego, there's there's this thing where like when we do this, it's important to try to separate ego from the work. If you're a good it auditor, a good risk assessor, you're going to find stuff and you want to find stuff and you want the people who, if you're in charge, you want those people finding stuff and you want to have the difficult conversations to try to get to a point of what to do about it. Because then it's out in the light and we have an opportunity to try to be better and we can be better together. If we discourage those voices, if we try to keep to a storyline that we like to tell where things are great, you know, two things happen. You establish a group thing that makes it very difficult to have friction against and come any way of self-realization, right? It's all, you know, this is what the party line is. It can't be bad. It's always been that way. It's one of my favorite. But oh, that's one of the reasons. Yeah. Right. But the one of the things that always gets me is this idea that if I'm an auditor or an assessor and I look at somebody's report and it shows me no findings, that's a far worse flag to me than if there were a lot of findings. Yeah, totally. If there were a lot of findings, I go, cool, they're working on this. How's it looking? If there's no findings, I immediately suspect that there's something wrong. The depth. Yeah, what really quality was done, the depth. It's it's so interesting because people don't think that way. If we just like think about a sock too, for example, it has all of the section four in a type two. It should have, you know, here's what was tested. Here's what was found. People should read those items. Here's the control. Here's what was tested and here's the exception. And yeah, to your point, if it's a totally clean report, is that realistic? Not really. So yeah, no. And the other thing too, sock two is a really scratch the surface kind of stuff. So you're not you're not really going deep dive with sock two. You don't have the time and scope for that. And a lot of the assessors who do it aren't that deep technically. So being able to write out what they're finding is fine. You know, it's nice that you did that is important for a number of things. But should that be the thing that you really care about? Probably not. Yeah. Okay. So so let's camp here because there's two very different camps. Our mindsets or maybe like rolls. So you're talking about, you know, early on we we want to find stuff like we want to pick up all the rocks and pull up all the covers. But then you just said, audits aren't a deep dive. I think that is such a huge distinction that people need to understand. There is a very real difference between building and implementing and running a program and being responsible for this stuff versus passing an audit. And while they're not mutually exclusive, I mean, they definitely support each other. The mindset is different. Odits are always going to be a point in time. They're always going to be some sort of sample or subset. You know, you said, Sock 2 doesn't go very deep. A real Sock 2 auditor is obviously better than some of the ones that that we're seeing of late here that literally are just clicking the button. Sure. But even PCI, PCI is very prescriptive. It can be very deep in some areas, but it can't be deep in your whole security posture. And so there you go as well. So so talk about that from your perspective because they're I think people commingle passing audits is running a program. They're not even the same thing. They're two entirely different things. Well, you know, I've been an IT auditor and I've been an assessor and I've reviewed Sock 2 reports and I've done PCI and I've done a number of other different types of assessments and looked at third party evidence for what they've done. And yeah, when I see no findings, it concerns me. That's first off. But the other part is I like to be able to see that there's multiple levels of assessment. So Sock 2 is great as a as a primer. But it's not like where I want my entire program hanging its hat because it doesn't go terribly deep. And what we find in this is a matter of what the framework is and what the scope of the assessment was. So we can easily be able to scope our audit to be able to return more favorable results by having it not look at the thing we don't want it to look at. Right? So when we have to do this is great. We came out with all green again. But what did we really accomplish? And who are we communicating the all green status too? I know. Because it's the stuff we didn't look at that also matters. Yeah. That's what I say about AI. Like, I'm a very opponent of the efficiency. But be smart. Don't just jump off the cliff without thinking what that looks like. But it's like all the the busy work that that teams do. If AI can relieve them of that and allows these people with this this expertise to actually be their expertise versus busy work, that is fantastic. What is it? Sure. Exactly. What you just said, Peter, it's what we didn't look at. And you already hear people talking about, oh, we're just going to deploy the AI thing over here and it's going to watch that. And it's just going to let us know if there's an issue. But first of all, there's this little thing called governance. There's monitoring and oversight of the thing. And then you're exactly right. Is it looking at the right things? Are we checking that? Has that been consistent? We see this with the with the low NGRC tools all the time. They just scope that thing down to whatever they put in the tool green check mark, write the sock to report, call it today, move on and scoping is really the critical problem. Talk more about scoping because scoping is in PCI as well. It's in a lot. It's in CMMC. It's in a lot of the frameworks. And I don't think people like really fully wrap their mind around like what scoping really means. Okay. That's a difficult question, but you're absolutely right. So let's think about this. I think if you've been in an audit or an assessment, then you've probably had scope arguments. And they may have been as a customer and they may have been as the third party or they end as the auditor assessor. And why that matters is because when you're writing scope as an auditor or assessor, you have to be concrete about what it is you're trying to go for and where it is that you're going to go up until. And you're going to quickly run into like this little bit of a gray area where like you were testing the hardening of a subset of systems. And part of that required that you looked at the policies that were being applied technically in the policies that were written and that policy that was written also had a reference to an audit policy for like log review. And you went and looked at it and you found that it didn't actually look at anything about whether the hardening was effective. Okay. So do you have scope? Probably. But you've quickly gotten into the spot where you're a little bit removed from where you first started and you have to be able to draw a tangential line to why it matters to the scope that was your intent to be able to go out to. And that's I think where the crux of it is. What's the intent of the scope? What's the intent of the audit or assessment? What are we really trying to get? We're not trying to get everything. I remember sitting in a payment application assessor certification. And there was a hot shot pen tester behind me with all the stickers on the laptop. Very outfited well. And they said, hey, you know, let's say you're testing this payment application. And you know, you see that there's a connection from a from a printer that's outside of your scope. You know, what do you do? Well, the answer is stop. Make make a note of it. Focus where you're going and come back to that one later. Do you have a chance to clarify, you know, with the stakeholders what the rules of engagement might be. But to this guy onward, let's go ahead and take out that printer. Okay. Well, maybe it wasn't a printer. What if it was something a little bit more consequential? Well, if we don't have a place where we end, we tip things over. And we cause a little bit of a bull in a china shop sort of scenario that we don't really want. So, um, I think it's important that we hold to scope as assessors and customers, but we that we have the conversations of what our intent really is behind it because not everything should be sacred. We should be able to talk about the things that we do see, but they might just be an observation. Our scope was this. We worked on this. We also observed this. You might want to look into it. That's that's more helpful than it is harmful. Yeah, I totally agree. And it goes back to the difference between passing an audit, which typically is tied to customer assurance or potentially regulatory. And like in the case of PCI, it's only concerned about card holder data in the case of HIPAA, only concerned about PHI, the case of CMMC, only concerned about CUI. Like there's their level too. Of course, there's all these flavors. And from a customer assurance mechanism or regulatory, it makes total sense that yeah, it's not everything. That's not the notion. But then unfortunately, human nature kicks in and people start playing this scoping game that becomes like a shell game. Oh, you don't notice this. It's like I'm pretty sure the somebody told me the SolarWinds that those servers were out of scope for the SOC2 audit. And so they weren't included. Yeah, well, that's management's problem for having defined it that way. But the reality is there's a lot of scoping latitude for how it's done. And then yes, reliant upon the assessors to maybe figure that out and dig into that. But then also be respectful that yeah, there are appropriate boundaries. That's fine. So you do need to stop there. Don't be the wild cowboy that just goes through everything because it's not everything. But on the flip side, don't play the scoping game either. It's like, you know, it's like if I put my workstations in a tool that's supposed to monitor if they're being managed, and then the SOC2 audit or any auditor comes in and says, yep, it looks like everything's being managed. That's good. But if they fail to ask for an inventory of devices and they fail to make sure that this is an appropriate scoping in this particular case, then the result is incomplete because the auditors fail to do their job. And let's face it, Peter, you're probably seeing this as well. A lot of the audit firms are being highly commoditized and it hurts. And so they're having, you know, they're getting a lot of time pressure to not do right audits. They're getting a lot of financial pressure to do them ridiculously cheap. They're outsourcing a lot. They're using very inexperienced resources that quite frankly just don't know to write, ask the right questions. And it's really an unfortunate scene. But then again, it all goes back to integrity. What you said at the very, very beginning in that AI knows about you, Peter. That's awesome. That you are a man of integrity, which is amazing because ultimately again, it's very different to pass an instrument. We'll call it whatever it is, framework regulatory audit assessment, whatever you want to call it, oh my. And that's for customer assurance, probably on a very particular set of data or subset of your systems or your service offerings versus, hey, I'm responsible for this organization and protect it. The data, the people, the systems, its continuity, all of the above, which should, should look very different than just what my auditor is asking me. I agree with you entirely. I think the audit is often a component of the program, a starting point in the program is a new role for an assurance perspective, but it's not it. They're all that continuous monitoring stuff that you talk about. It also matters and it's not just things to go bump in the night, performance, somebody doing some kind of reconnaissance. It actually also is those other pieces that when you dig down, you find that we willingly accepted because, hey, it's business critical that we get this other thing done so we can't fix that thing right now. It has extended. Okay, fine, but how long are you comfortable kicking the can down the road? I think a lot of programs have it where the SISO is there to be the fall guy that the cybersecurity insurance didn't cover, right? So in turn, they're like this sort of powerless figure head is always looking for budget. They're bleeding expense. They're not really providing anything where they can say we're building to the bottom line. When in reality, when we shift left and integrate it into the designs, we find we're building a better product that has less repercussion on the tail end. So there's ways to be able to do it, but it won't always make it popular at parties. You know, I think about the Judge Mill's Lane who was a boxing ref, who refs Tyson Holyfield, and he used to say I'm firm but fair. And I think if you're an auditor or an assessor, that's probably what you need to be. If you're in cyber security, it's probably fair, too, because we're all products of our environment. We're all trying to be a little bit better. We all care about our families and we need to care about each other too. So that's the less this system and the squeaky voices. Yeah, no, I love that. You mentioned how long you're going to kick the can down the road and feel comfortable. Sadly, because I work with a lot of different companies and have over the years, I won't name how many. And so they, what's sad is a lot of them don't even have the can. They don't even know what the can is. That's true, too. They don't even have the list. They don't even know what they're kicking down the road. Again, they're just scrambling toward some sort of audit and they're being so mindful about, you know, this dollar and that dollar, which I totally understand it's a fixed fixed world. But the bad actors get a hold of you or your customers get a hold of you because you've done something that they can't trust. And there's where it all starts to crumble in an instant. And so I think it's important. You also said something earlier that made me chuckle. You said threats to ego. I think that is a risk register item that needs. I suppose finding threats to ego. Like what is the threat to ego that's going to make people make choices. And I have stories of people who are like, I just don't want to hear anything other than I'm perfect or I'm going to be ugly and think that you just said, I'm not doing my job. And that's precisely not what we do. But that threat to ego, unfortunately, they can make people act just a tad bit erratic and can make them sometimes cover things up that are not or just purposely intentionally not look at things that they should otherwise really be unpacking. I agree entirely. And it doesn't help when as we try to work as an industry, the audit and GRC professionals risk and have a little bit of infighting because we want to be competitive, we want to be an expert too because of ego. But in doing so, we disagree on fundamentals. And in doing that, that conversation in front of stakeholders looks a little disorganized and haphazard. A given example. IT auditors often talk about risks when they really mean threats. And many GRC tools designed audit center, so a threat is a risk, but it's not. The threat times a vulnerability is a risk. So we have to be able to figure out how we do those things. It doesn't help then when you bring in outside experts. I remember being in multiple meetings with a big four partner, who was explaining their risk assessment methodology, they had a lovely grid, five by five. And what they did was something that you saw back in NIST 830, like Rev1. Very high. Well, forget that they didn't have very high then. And let's use the example five by five. Very high times a very low. What is that equal? Well, if we think about it, you know, we go, oh, I remember this, it used to be a medium. But is it really? Yeah. No, it's probably not. It's probably low. But I had to explain this to them and explain that all their expertise and all their industry and all all made it a medium. And then they gave me some analogy about driving a car, which I always have problems with because I'm like, it's like, I have no breaks. But here's where it really comes down to an example. If I walk outside my front door and I'm hit by a meteor, I have a very high impact against a very low probability. That is correct. I walk outside my front door to get packages a couple of times today already. Has it happened? Yeah, that's right. And is it a moderate? Do you take precautions? Just in case it did happen. What am I going to do? Have us if you'll play it above your head. I don't even know what you would do. But yeah, that's exactly. So it's not a moderate when we put it aside, other moderates. But if we misunderstand terms and we go, well, the inherent risk, which we just kind of throw around because we love to say inherent for some reason, it doesn't matter anymore because our message to other people. We agree among ourselves on fundamentals. When are we talking about a risk? When are we talking about a threat? Do we really care about what's inherent? Because in all actuality, the probability and impact matter the most to us. Yeah, no, that's exactly right. And the meteor, yes, it will be catastrophic. But you know, one might argue that the probability is higher because I see stuff pop up on YouTube. But you know, again, aliens can have made the planet. Yeah, but yes, there's all sorts of crazy stuff. You know, it's interesting. So hearing you give those examples and thank you for that. It goes back to the whole tech box mentality versus like this stuff is intended to help us make better choices. And we've lost the latter. And so just to what you said, don't jack with my risk formula because that's my process. That's my check box. I pass my audits with this. Okay, well, whatever. Don't care. But actually mitigating risk in the organization. Is it actually driving the right conversations? Is it actually driving the right decision making? Exactly. Is it guiding where budget goes? Is it forcing those tough conversations that you've said earlier that people don't like? That's risk management at its core. Humans thinking, having dialogue, making decisions. And in some cases, yeah, we have to accept the risk of the meteor because I need my packages. And that's what it is. But at least I'm mindful of how I'm just using that example. But at least I'm mindful about how I'm doing that, not just poking my head in the sand. And oh, I passed my audit. So I don't need to think about risk for another year. And sadly, that's what we see. That's what we see it all the time. So now let's bring it around to AI then. So then you first, when the cloud first became a thing, entire organizations laid off their cybersecurity departments. And they did it because they said, I'm outsourcing the cloud. They take care at all donated anymore. They got my compliance. They got my cybersecurity. I don't need people. Oh, yeah. Right. And people don't remember this because they go, well, I've been using the cloud forever, you know, and they understand what the cloud is today. But when the cloud was new, we lost cybersecurity departments. They are part of layoffs. Does this sound familiar? Well, it sure does because we brought in AI today and we said the same thing. Well, we don't need anybody because we can automate it. Well, you remember AI hallucinations, right? It doesn't always come up with the right answer. And we see this in, I just saw an article recently, of a big four audit report that came out that was clearly used AI as a generative report writer because it was including references and data that didn't exist. But we can't stop all of that if we allow us to automate from pressing the button and not consider what the actual outcome is. We need humans in the loop to be able to use the tool really well because it is a tool. It can be efficient. It can be helpful. But if we allow it to automate everything, we automate empathy and we automate rationality straight out of it in the hopes that it's going to predict a conclusion that we like and it blows smoke up our ass so it fuels good while it's doing it. But you just think if you like a green dashboard and you want to go ahead and make it green once you have the AI automation into that dashboard, you're going to create hallucinations and then you're going to break automations all in the spirit of trying to get yourself to look good. Yeah, I mean, I totally agree. AI is a tool like so many other tools we have. It's a, you know, it's a pretty fancy tool, but I'd love to give the analogy that it's like going to Home Depot and buying a hammer. That's amazing. Buy the fancies hammer you can find. Buy the one that claims that if you line it up on the nail is going to keep doing it. That's awesome. But the minute you turn your back on it, the minute you let it design what you're trying to achieve that that wasn't ever the intent of it to begin with and where AI is right now. I mean, I use it. I use it every day all day and yeah, I fight with it a vast majority of the day as well until it's dumb and other stuff too like completely got this wrong. But it is. It's that human oversight. It's funny. This will make you laugh too. So we hear all this hubbub about AI governance. Ooh, there's this new training on AI governance and on this and all of this different stuff coming out and people like, Oh, AI governance. It's extremely important. But can I tell you just like your cloud analogy, this is not a new concept. This is called governance. Just take the AI off. It's called governance monitoring oversight, defining the rules of the game, implementing those, monitoring those. And so none of that's new. The thing about AI that excites me is how, you know, as humans, we can only do like it take like writing, writing a stupid email beater. Oh my gosh, I can spend 10 minutes doing that dumb thing. And then the AI is I can tell I can spend 20 seconds going, this is what I want to say blah, blah, blah, blah, blah. And then I read it and I'm like, oh, yeah, that's really nice. That's what I wanted to say. And it took less than one minute versus 10 minutes. It's wonderful for that. But I'm not having it send emails for me on my behalf that I'm not reading. I'm just letting it make me more efficient. So those other nine minutes, I can go do something else. And so that's what excites me. It's just exactly. Let's go back to your risk example. Right now, most teams are understaffed, no staffed, whatever staffed, wrongly staffed, they hire junior resources that really don't even know this stuff. So all of the above. So think about it. They spend all their wheels doing risk registers and risk assessments to pass audits. Because that's all the hours they have in a day. Sure. But if you can leverage something like AI to do some of that busy work. So then maybe these people can be actually experts in the space who can now go through and say, okay, AI, I know the media are hitting me. You put it a moderate. But let's really think through what this means for our organization. And now I have physical time, but mental bandwidth to really like dig in and think about this. That is the piece that excites me. Absolutely. Yes. And in that way, if you remember, you know, what now seems a lot less sexy than it used to be, but your SEM, we're seeing whatever you want to call it, right? I call it SEM for this. centralized logging solution. You know, what do you want to sell fancy when you configured an alert? Why did you do it? You did it because you know, it allowed you to be able to find something faster and to pay attention to the thing that mattered. That's the same thing, right? You can use AI in the very same way to be able to work on what matters to be able to help you move the ball more efficiently. But human in the loop matters. And just like every other system we've ever designed, garbage in, garbage out. Right. That's exactly right. Well, and even go back to the alerts. So that's being used in a lot of AI. I mean, AI has been used, being used. You've got millions of of events. Oh, yeah. Nobody can look through that. So yes, that's a great use case for AI. Except how many times, Peter, have you seen companies buy tools, never fully get them implemented, never configure them properly? And even if they did accomplish that, how often do they actually go back and revisit that to mean and tune? And so we don't take that approach to AI. I said, oh, great, look at it. It's looking through my 10 million events. And it's telling me, here's the three I need my attention. But is it right? And if we're not revisiting the, is it right on a regular basis, now we're sitting in complacency that the three that needed my attention were the three that needed my attention. Meanwhile, the bad actors laugh in his rear end off because he's like, you didn't tune your tool, dummy. And so there's six things that you're not even paying attention to. And there's the danger of the laziness of human nature to be like, I'm done. I don't have to think about this thing anymore. It's doing my job. But is it? And we need to always be asking that question. That's right. And have you ever seen an organization that has more than one GRC tool? Oh my gosh, Peter, you're trying to make me laugh. Yeah. So four four is my number. I've seen six. Oh, you've seen six. Okay. You beat me. I routinely see two and three. And they're just convinced that the tools are wrong. There is no perfect tool. Totally agree. However, normally, you know, it's like, you know, anything in life, when there's a pattern, you really kind of need to probably look in the mirror and go, okay, maybe the world is not the pattern. Maybe I'm the pattern. And it's the same thing. You're right. If you're up to your six GRC tool, there might be something else going on than the tool. Now, if we consider that each of the six may have a different risk register. And they may not know about each other. And we may be putting our audit findings over a share point instead of the register. They're going to get fixed. So now when the assessor auditor comes through and they want to look at your governance, you know, what do you show them? That's correct. So back to scoping games, right? We might say, well, this one over here is the one you really want. And then you go find auditors that just smile and shake their head because they're either not getting paid enough or they don't know or they're being told to just smile and nod, you know, what all of the above, whatever. And there you go. There's the recipe for the disaster that quite frankly, we have one of our clients sent me a funny meme about, it was like a breach versus we pass the audit like confusion. And while I was laughing, I was like, I'm going to cry now because sadly, that is such a prevalent attitude. And it was really interesting because most of our clients are very like committed to security, which this one is indeed that. And so I was like, yeah, that's funny, but it's not funny because it's too prevalent. And he was like, why would people waste their time with that? I'm like, I, yeah, I, yeah, it's really, I mean, I'm not a proponent of, you know, let's get rid of risk acceptance is necessary. Yes, I accept the risk all the time of the meteor. That's right. You go to the mailbox. That's right. That's really fine. No fear. Yes, you could send, you could send children and let them get creamed by the meteor. Yeah. And if I got hit, you know, put that on my tombstone, you know, this guy got hit by a meteor because it doesn't happen every day. Well, maybe it does, but it doesn't happen to anybody. I know. That's right. Oh my god. So you'll take the fame and the accolades don't get it. So it's okay that you accept some risks because it's necessary to keep the business going. Yes. G or C shouldn't be dragged. G or C should be for speed. We put it into our process. We integrate it shift left. We put it into the designs because we want you to be able to not to fail with the same team. Yeah. Yeah. In any company that has to, I was just thinking about like people listening, how would they know they fall in that space? So when I hear things like, oh, well, we got to prepare for audit. That shouldn't. Yeah. Other than maybe booking a meeting room for them or clearing off time on schedules, there shouldn't be any preparing for audit. Again, this goes back to you've built, you've run, you're monitoring something. Oh, the auditors are coming. Wait, what do they want this time? Okay, they want this stuff. Got it. We might have to go warn a few people, get a few heads up items, but the reality is we're already doing what we're supposed to be doing because just like you've said so many times, this is risk. And so we should be on top of that all day every day. Right. Here's an example to think about in that point. When you look at a policy or a standard, do you ever see them reference another policy or standard? Sure. That happens all the time, right? And when it does, that's helpful to you as an auditor and it's helpful to you as somebody who needs to follow it. Yeah. You ever see ones that don't? Yes. Sure. Why don't they? Because they're trying to make it so that when the auditor or the assessor comes in and they say, show me your identity and access management standard policy or your standard forever, you can just give it to them. And it doesn't reference the count management standard and it doesn't reference, you know, the provisioning guideline. And you're hoping that this makes it so that you'll have less findings. But why would you hope that? Why wouldn't you just hope that all that documentation was written really well so that it wouldn't or that if they found something, it would help you to fix it because it's just documentation. When you're making those choices, the rest of your program is bound to be a problem because policy and documentation stuff is kind of the bedrock that needs how we get to things. I know. And every time I hear, I can just download that or now it's even better. AI will just write that for us. Wow. Wow. The bedrock of everything. Yeah. Just have AI write a good look with that. Nobody has any clue what it is. It's not driving anything, missing the whole point of it. So we've talked a lot about like what's wrong. But I always try to be positive. So how so this is a this is a mess. Like it is a big mess. It's a mindset shift. It's human nature. So many different things. And there's many reasons for how we kind of got here. How do we get out of this mess? Because what you've also said several times on this call. And I echo exactly the same. We are all in this together at this point. This is not you versus me, that company versus that company. The reality is we have to all it's almost like parenting. We have to all like come together and interlock with each other so that we are stronger together than we are individually and to not be at odds with each other, but be on the same page for ultimately what we're looking to do because we're protecting us at this point. Us, our families, our friends, our data, our livelihoods, us, right. And so, so how do we get out of this mess? Cause it is a big systemic mess. I think you're right. From a philosophical perspective, I'll go back to a chat GPT realization that I just had recently that said, Hey, you're probably a pluralist. And I go, what the hell is that? And then I read the description. And I go, you know, I might be. And what answer is effectively, I say, I don't really care, you know, your race, religion, sex, whatever you've got, you can have three heads. I really just want to give you a chance to get that done and not hold you back and doing it while we work together. Because at the end of the day, I'm going to go home to my family. You're going to go home to yours. We need to feel good about what we've accomplished. But we move the ball together. The thing is, when people do their bias training and their ethics training at their corporation, a lot of the time, they go, yeah, that's great. I passed it and they move on promptly. Forget about it and decide that it didn't apply to them. But we all have bias, right? So we have to be able to find this sort of what's ultimately pluralism way of setting aside difference and identifying through empathy. Instead of saying that the group that I've come into myself and identify with is a silo. And the group thing that comes with that means that you're the enemy really rustically. A little bit of empathy goes a long way because we probably want good things for good reasons. And we might be able to disagree and not decide that each other are the enemy. Yeah, exactly. But it doesn't happen as often as it should. So I think you have to start by finding a way to say when you see organizations that go better together, great. Now actually walk that talk and work together in a way where you're not excluding each other and sliding each other and playing these games to try to be able to produce a biased result because it's counter-intuitive. Next up, maybe consolidate your GRC systems to one and write some decent policy. Right. Stop outsourcing cybersecurity. Oh my god. Bring in the consultants for a reason at least. Yeah, exactly. Yeah. I worked out a place where half of the place was contractors. With sort of skin in the game, do you think they had? Yeah, they don't. That's just it. I mean, we are contractors or not contractors, we're consultants and we definitely hold on with our clients. But yes, there needs to be that deep ownership, that deep vested real partnership, a real partnership. I did a talk. I don't remember what it was about, but it was that exact concept. Like, don't, don't be either side of the spectrum. Like, don't and I see people are notorious about this. Well, I'm smart. I know everything. You don't. You don't. And even if you did, you don't have enough hours in the day to be that good at everything. So goes back to the risk of ego, exactly what you said. There needs to be a little humility and the whole thing to say, okay, you don't know everything. And even if you did, you can't do everything. So go find people and partner with people who are more experts in this particular space. So don't make that end of the spectrum mistake. But then exactly what you just said, don't make the other end of this spectrum mistake, either, where it's like, oh, well, we just hired someone to come and write our policy. So work good. Don't do that either. Like when we work with the company for their policy, we might be like the first line kind of presenting a draft to them. But then we workshop it with them and with the key stakeholders to this defensible. Is this really what you do? Is this the level that you want to hit? And then if there's some sort of framework or regulatory or best practice like, no, you can't really dumb that down because here's the bar. But let's talk through this and let's talk what, you know, really you're going to do. And so there is a way to hit this middle ground to where you leverage the expertise. But you're right. If you just outsource the whole thing, that's what we're seeing with the low-end GRC tools. They're outsourcing to that tool. And like, I'm good. I'm good. I'm doing it. And they're doing it with them to design in mind, right? So I think that's one of those things where like, you know, some of this, I think when I T went into the comm days, it came with a lot of acronyms and a lot of new business-y terms that like, you know, we've carried forward. And as they've aged, you know, we've started to find that people pay lip service to those terms because it's just part of our lingo. So we all say, well, you know, be a good partner. But do you really have good partners? Yeah. And are the partners that won't give you any of the information that helps you a good partner? And that policy you really have to live with. So your partner doesn't care. How are you supposed to? That's exactly correct. Yes. And then if you haven't taken the wherewithal to know what it means to care, that's right. That's a different problem too. So I think the summary of what you say, it's a complex problem and it's one will be we'll be solving for decades. It is definitely a complex problem and it's a mess. I like what you said though, you know, empathy, we do, I heard something of the doctor yesterday, basically a particular device is geared toward one type of skin type, one type of person demographic and then causes health issues because of it. And so there's, you know, we need to think beyond just our self, our one view, our one lens. Yeah. And then the other side of it, you mentioned group thinking, you've mentioned it a few times here. Likewise, don't go find people who are just going to cuddle you in your way of thinking. Like this is serious business. You don't want someone to just, oh, yeah, you're beautiful, you're perfect. There's nothing, you know, hey, I will do that for you. But unfortunately, but the reality is we get better when we find people who have different perspectives and then that goes back to your empathy, like don't look at them in a, you know, I'm going to get personal now and you're calling me names. No, I'm not. It's a different perspective. You can go buy your 3GRC tools, but the reality is, yeah, you really should look at one and you should look at all the use cases and you should make the right choice and you should work to get all of those implemented. Like it's a much larger thing than that. That's right. Again, that also kind of goes back to that coachability as well. And then, oh my gosh, you talked about policy, meaningful policy. So, yeah. I just, I roll my, it's funny. People don't understand. Like as a general rule, people just, they roll their eyes with policy. They think it's just absolutely. It's just what everybody doesn't like. Well, but I always explain it like this. It's like we're playing a game. Well, what game are we playing? I don't know. Oh, I want. There you go. If I like that, I'm going to start using that. Yeah. Oh, right. Because when I go to do an audit or an assessment, the first thing I do is the documentation review because it's like reading the instructions. Yes. Right. We can't know how to play if we don't read what's there. And if you meant me to understand something, but you didn't write it, how am I supposed to know? And if that's a problem for me as an auditor or assessor, how are your people supposed to follow it? They don't. They ignore, it's a stupid exercise. Oh, wait, the auditors are coming. We have to re-review policy. Yeah, that's just not it. Policy literally is an everyday because it defines the rules of the game we're playing. And then audits require policies, risk registers, you know, even vulnerabilities, you can get away with this in some cases a year once a year. Yeah, that's that's laughable because because again, this is stuff we do every day. Just look at AI. AI is changing, you know, what is the technology cycle been like up around 18 months or maybe closer to 12 months that's technology like completely cycles over. So now with AI, it's going to be less than that. We're seeing legacy tools that have been staples of the industry for years. We're seeing AI based tools pop up and take over them within months and then radically things are different now. And so my point is, and exactly what you're saying, your policy should be living and breathing. It really is the rules of the game and how we're engaging with each other. And where it's lacking and doesn't answer our questions, we need to fix that and go fill that in. And then people are people. We, you know, we love them here in Texas. We say, bless their heart. We love them. But people sometimes, I mean, all people self included need to be told like what the boundaries are. And some people need to be told more than other like this will make you laugh because I sure you lost count how many times you you've seen this. You can't write your password on sticking out under your keyboard hardstop. You just can't do it. But sadly, you can't you have to tell people that. And so again, that's the meaningfulness of policy. And when you get an organization that's more robust and complex, the management is not talking one and two and three and four and 10 layers down. So how do you know those people are doing what you're thinking and expecting that they should be doing? Well, let's see, that's where it all starts. It's so meaningful. It does. And, you know, little bits matter a lot like, you know, discretionary and declaratory or mandatory or discretionary kind of language, right? If you say that I made you something or I should do something, it doesn't mean I'm going to. That's correct. Yeah. So you also have to say what you mean, which is probably why I really like it. Yeah, that's a good point. That's true. Yes, because it is you shall you will like this is it. This is not debatable. This is what is going to happen. But you're right. See a lot of policy that's very commingled with procedure and guideline. And you're right. The language is not really clear. And then my personal favorite, the 85-page policy that you make everyone acknowledge and how many how many of those 85 pages do people actually read that would be zero. They just don't read. I'm a big proponent of kind of breaking that up so that you can have subject matter domain area work. So like I can never write an encryption policy as one page. I've never been able to be successful in writing an encryption standard or a policy that is two pages. Yeah. Because there's so much to it because it's so complex that it ends up a really long complex document that's difficult to understand. Yeah. So it's cryptography. Yeah. So it really matters then how much does that policy standard matter to you? And it may be that it doesn't if your job isn't to do anything with key management. Correct. If not, then over in the security policy, you know, your data should be encrypted. Great. Or shall be good. Yeah, that's funny. Good. Well, and that's a very that's a good point. While those policies may be readily available to everyone, you want to may not your standards obviously, but there are people in the organization that they are much more relevant to. So design it in such a way that the people who it needs to be, they need to know it for sure. They will take the time to read the longer document because it's their world. But then when you take, you know, Joe person over here that just comes in and does their job encryption. What? Like why? I don't even know what that means. And so you're right. We write it. We don't write it to the right level. Meanwhile, we need to tell Joe to not write his password down to not share his password. Yes. We need to tell Joe to, you know, don't log in on your home computer. Like there's things we need to tell Joe that we need to make sure he hears. Absolutely. Not picking on all the Joe's in the world, but but then we're just going to create noise with all this other stuff that's not relevant to him. And so again, that's why when you have a I write it or consultants come in and here's your document said and then oh, the auditor said everybody has to acknowledge this. So this is what we're doing. Boy, miss the whole point of the whole exercise. Wow. Well, thank you so much for the conversation. What final topics or thoughts would you like to leave the audience with? Some really, really great stuff here, but but if there's just a few things that you would like for them to know, what would it be? I'd say that when it comes to cybersecurity or risk management, it's more people problem than it is a tool problem. I love it. Tools matter, but tools do what we configure them to do. So we really need to be able to understand what do we really want? What's the requirement? Are stakeholders on board? And as we go to configure them and we look for that desired result, we continually reevaluate, refine and improve because continuous improvement really should exist. Yes. How we use our tools, how we write our policies, how we use AI, and in our personal lives ourselves, always try to be a little bit better every day. Yeah. Because that's an important thing to be able to make everybody better. And then break away from your biases or at least understand them enough, you'll be able to give somebody a fair shake. A little bit of empathy in doing this is a lot less antagonism and it makes the work better. Beyond that, you know, AI is here to stay, so get used to it. It is. We're all hooked now, so it's not going away at this void. So true. You know, dressing our dogs up and, you know, farmers outfit, I'm kidding, I'm just not going anywhere now. No, but you're so right. Yeah. But this is a people game. You're absolutely right. It's a people in process game. The technology is the technology. There's a lot of smart people in the world that are able to buy and implement technology, but we're almost every company that we work with and that we've, you know, I've worked with over the years. It's the people in process that's hard. People are number one asset. They're also our most difficult asset at times. And then I like what you said, like learn, when I left my corporate job, one thing I did was I went and got certified, trained and certified as a coach, because I wanted to learn how to work with people better, not to say that I'm anywhere close to where I need to be because it is it's a daily getting better. But the reality is how we work with people and people change management is so critically important in cyber because you're cons. You need people to be successful. You need to engage people to be successful. You need to learn how to talk to them in a way that you don't turn into just a bully because nobody likes bully and toxic workforce. And we all have our examples of those unfortunately, but to really work to help people understand the why and the what and here's the role. And then you've said empathy several times and that's very important. Well, because everybody's busy and overwhelmed and overworked and underpaid and they have their personal lives. And so here you want, what do you want me to do now? And though it's just all this other stuff and so to have that kind of wherewithal to think at it from their shoes. Thank you so much for bringing up those points. Those are the points that often get ignored. But to me, that is the crux of the success of this thing because the technology only goes so far quite frankly. People are the ones that mess it up. I agree. Well, truly wonderful dialogue. I really appreciate your time today, Peter. Thank you so very much and appreciate it. Thanks audience. Everyone for listening. This is the Art of Cybersecurity Podcast. Thanks for listening and don't forget to subscribe. See you next time.
Podcast Summary
Key Points:
Integrity in GRC (Governance, Risk, and Compliance) is essential, emphasizing the need for honest reporting and uncomfortable conversations to drive continuous improvement, rather than hiding issues to present a falsely positive "green" status.
Audits and compliance frameworks (like PCI, SOC 2) are limited in scope and depth; they should not be conflated with running a comprehensive security program, which requires broader, ongoing monitoring and risk management.
Proper scoping in audits is critical to avoid both negligence and overreach, but it should not be manipulated to exclude relevant risks, and findings (rather than clean reports) are valuable for identifying areas needing attention.
The cybersecurity field requires maintaining coachability and separating ego from work to effectively adapt and improve, staying ahead of threats through collective effort and transparency.
Summary:
The discussion centers on the importance of integrity and transparency in cybersecurity governance, risk, and compliance (GRC). The guest, Peter, highlights that integrity-driven leadership involves openly addressing vulnerabilities and findings, rather than hiding them to avoid difficult conversations or present an overly positive image. He stresses that continuous improvement is key, and findings should be viewed as opportunities, not personal criticisms.
The conversation distinguishes between passing audits (like PCI or SOC 2) and running a full security program, noting audits are often limited in scope and depth and should not be the sole focus. Proper audit scoping is crucial to balance thoroughness with boundaries, avoiding both negligence and excessive intrusion. Both sides—executives and security leaders—share responsibility for fostering a culture where risks are openly discussed and addressed.
The dialogue underscores the need for coachability, collaboration, and separating ego from work to effectively protect against evolving threats, emphasizing that cybersecurity is as much an art as a science.
FAQs
Integrity in GRC leadership is crucial because it involves having uncomfortable conversations and avoiding compromises that hide risks, ensuring continuous improvement and transparency in cybersecurity practices.
Findings should be seen as opportunities for improvement, not personal criticism. They help identify vulnerabilities before attackers do, supporting a process of continuous enhancement.
Passing an audit focuses on meeting specific, often limited, framework requirements for assurance, while running a security program involves broader, ongoing efforts to protect data, systems, and organizational continuity.
A clean audit report can indicate inadequate depth in the assessment, potential scoping issues, or a lack of transparency, suggesting that real risks may have been overlooked or hidden.
Scoping defines what is assessed; improper scoping can exclude critical areas, leading to incomplete results and a false sense of security, while appropriate scoping ensures relevant risks are evaluated.
Coachability is essential for staying effective in cybersecurity, as it allows professionals to learn, adapt, and improve continuously, regardless of their experience level.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.