The $20M Coin Flip: Cyber Risk in Real business terms
16m 26s
The discussion emphasizes that the ultimate goal of risk management is to enable sound business decisions, not merely to identify risks. Executives, such as the CFO and CEO, require risks communicated in their language—financial terms like probability and potential monetary loss—rather than vague qualitative ratings. A personal anecdote recounts a SQL injection attack, detailing the chaotic "day zero" response, the cross-functional effort involving technology, security, legal, and PR teams, and the subsequent shift in company culture toward taking cyber risks more seriously. The conversation advocates for proactive measures, including quantitative risk modeling—using frameworks akin to actuarial science and competitor data to estimate likelihood and impact—and rigorous tabletop exercises to build organizational muscle memory. Key advice for practitioners is to focus on decisions executives need to make, quantify risks to facilitate resource allocation and insurance discussions, and maintain composure during incidents through practiced preparedness.
The CFO and the CEO and the CTO, they speak in dollars. They don't speak in colors or high-medium low. So if you go to them and tell them we have a 50% chance of for data breach, 50% chance. That's a coin flip, Mr. CFO. You have a coin flip chance of losing 20 million dollars or more. Does that hurt? We took that back to the executives and it really helped them make a better decision. So it's all about decisions. It's not about risk or trying to scare people. Risk isn't the end goal. Decision is the end goal. You're only so wonderful to have you. You've been a thought leader in our community and somebody who I've been very fortunate in my team and been very closely working with you for many years now. So it's truly an honor to have you on the show. The goal of CFO confidential is to really show the world what goes under the hood. Real war stories. Most people outside don't realize the importance and the consequences of decisions that a lot of security leaders take, but proactively and during the time of an actual incident. So Tony, we'll start with, we'll jump right in and we'll start with an actual day or evening or night that you remember. When you saw an incident first hand, so if you don't mind, kick us out from there. First, thank you for having me. It's such a pleasure and an honor. So thank you. Okay, I remember very vividly because I was driving to work and this was many years ago. This was several jobs ago, but it still leaves an impression with me. So I was driving to work and we got hit. We got hit with a sequel injection that led to the suspected expelation of data because we knew that this database had customer data on it. Though worst case scenario is the bad guys got that customer data. And the reason why I got to calls, I wasn't an incident responder. I wasn't on the first line incident response team, but I was on the technology risk management team. And so I called that day like day zero. It was one of the worst days because we went in and we were just trying to triage, just trying to figure out what happened. And I can reverse about 30 days prior when I felt like we started getting a heads up, you know, early warning signals of this. And that was basically sequel injections. We had a couple people, about three or four people that were on the computers, curiously typing, looking through logs, trying to figure out if the attackers were still in the system because there were a whole bunch of detections that went off, a whole bunch of alarm bells that went off and people got paged. But whether or not the attackers are still in the system or not, is something that needs to be ascertained very quickly and needs to be shut off. One of the very first decisions were whether or not to shut the systems down to try to stop the attackers, stop the attack or stop the exploitation or whether or not to try to keep it going. Because if you shut the systems down, that actually shuts the systems down. Of course, customers can't get in. What happened in the next few days, right? What was the whole sentiment in the organization on one on the security team side and the others outside the security team? What was happening? Did you communicate it to the whole company, customers, regulators, just what was going on? Definitely communicated to the immediate team very immediately within our technology teams and the security teams. That's where tabletop exercises really come in handy and having very good runbooks of what to do when this happens. The trick is you have to follow the runbooks, immediately some people weren't. But I'm glad that some people stepped in and really forced that type of discipline. So the days leading after there was a lot of different notifications that went out as we started to understand the situation. We knew that there wasn't any lateral movement. It wasn't it wasn't ransomware and that there was an attempt to get customer data but it didn't happen. At least that we knew at the time. And we just basically walk through all the steps and just tried to get a handle on the situation. And what about external communication outside the team? Was there anything involved in doubts or customers? Yes, there was customer notification. And that involved a lot of different teams. So the immediate incident response teams were technology teams and security engineers and then as the informed party you keep executives up to date and then there's a switch. Once you get a handle on the incident, the main incident responders I think become other people like the legal team, the communications team, PR, those become the main incident responders. And that's the really important thing that I think I want to emphasize or for people that are viewing this. That incident response isn't just the security team. It's a lot of different people throughout the company. And who's wearing the main incident response hat changes as you move through the chain of response. So a few days later I would say that probably our legal team was the main incident response at about day three and they decided only legal can make the decision of something's a reportable data breach. And that's the decisions that they made, those hard ones. Got it. Okay. And what happened like a month out from there, two months out from there? Was there a change in the way people look at cybersecurity, the way people look at resilience? Like was there a change in behavior of people? Did that have an impact on the culture of the company? Yeah, I think it did. I think that the company at the time, this was the first data breach. Okay. And you know, in our field, you always feel like a data breach is around the corner. But if you've never had one, if enough time passes, you also think it's never going to happen to you, right? Like you're just kind of going to be the one, just kind of in denial. And then statistically speaking, data breaches happen to large companies. It's about once every 10 to 15 years. So statistically speaking, you could go your entire lifetime at one company and never having seen one. And I think that it did change the psychology certainly of the incident response teams, but it also changed how I operate as a technology risk manager prior to the incident. We did model out SQL injection risk. And we modeled out data breaches on those type to databases. But of course, you know, the remediation is deprioritized as most things are. And I think that sometimes it just takes something really bad to happen to get people to prioritize stuff like this to take it seriously about it. I totally agree with you. And it's unfortunate, but reality is that we're more reactive than being proactive in most things, entering health, for example, not very different for cyber health. Right. But definitely not preparation. You spoke about one is the tabletop side of things, Tony. The other side is really talking about letting expectations. You spoke about, say, something which is once in 10 years, you analyze that that translates into 10% likelihood in simple terms, right? What is your view in terms of the importance of setting expectations both in terms of likelihood and then the loss impact or loss magnitude or different kinds of scenarios like the one which we just mentioned. And just, you know, because that in my view goes as a part of the preparation for the teams, especially the non-technical folks to say, look, this kind of risk, are we looking at a 10 million impact or a 100 million dollar impact or a billion dollar impact and what's the likelihood and how do we compare it with our peers in some cases? What are your views on that? How important do you think that becomes in terms of preparing people executives or a scenario like this? It's incredibly important. I think that it's, yeah, it's one of the most important things that a company can do is to manage their risk and to try to understand their risk. I've worked at companies where they articulated risk and regular green or high medium low. And I think that when it comes to data breach risk, if you're going to the sea suite and you're you're communicating risk in colors like high medium low or regular green, it's going to be really hard for them to put that in business terms for them to take that seriously and to try to give you the resources you need to start to remediate that. I think that a big unlock for me in my career is when I moved away from that and started speaking the language of business. And the CFO and the CEO and the CTO, they speak in dollars, they don't speak in colors or high medium low. So if you go to them and tell them, we have a 50% chance of for data breach, 50% chance. CFO. Does that hurt? Or are you okay with that? Yeah. And nine times out of 10, they say, I am not okay with that. What do we need to do? How much are you okay with? I'm okay with five. Okay, let's start the conversation about how to drive that risk down to five million. Because we're never going to get rid of risk. Sure. Because that's the cost of doing business. So the answer to your question, it's just incredibly important and you need to have those conversations in business language. You need to speak exact, I think. Some people will have an argument here and say, is that even possible to go ahead and actually accurately predict whether it's a 50 million dollars, could have five million dollars. You've done this successfully for many years, right? What are your thoughts on that? I hear that objection a lot that it's not possible or the risk landscape is too complex or I don't have an update. And my response to that is, I get it. I get where you're coming from because I used to think that too. And if you think that it's hard, I think that all of your feelings are valid, but just know that you're not alone, that this has been solved for before. Quantitative cyber risk, CRQ, it's not a new thing that us cyber people invented. It's been around for, I would say hundreds of years in the form of actuarial science. Actuaries, people that issue insurance policies invented all the basic math and all the basic frameworks that we use today. And if it wasn't possible and if it was too hard, then you wouldn't be able to buy auto insurance because an auto insurance policy uses the same math as the example I just gave you 50% chance of losing 10 million or more. It's basically the same thing. So not only is it possible, it's doable and it's easier in the last couple of years than it then it ever has been because of software, software like safe. No, certainly. And the good part there is the degree of automation and simulations that you can now do today, which is exponentially so much more than what was possible in the past. Any practical examples that you've seen which comes out to say, look, this is what I was thinking about. And this is what I don't need the exact numbers, of course. But you thought through a particular scenario and then you were able to go ahead and actually talk about that to say, look, this is how I was able to quantify risk and show that, look, this is either the likelihood side or the loss magnitude side. Any example that you can share that only. Yeah, the one that comes to mind is ransomware. So almost every company I've worked at wants us to quantify the risk of ransomware. That's something that's top of mind for everyone. And we had a situation in which the company I was working at at the time never had an incident of ransomware. Never had one. We got lucky. But we use the same techniques that you just described. I had some people come up to me and say, how could you possibly quantify risk if it's never happened here? We did what automobile insurance does as we took a look at our competitors, our peers. And I don't know if I'm lucky or unlucky. Ransomware hits everybody and there's so much data out there of how often it happens, how it happens, why it happens, and how much it hurts. It's just there. Yeah. If you if you know how to use Google, are opening these. Open AI. Yeah. It's easy. You can do deep research and you just get that answer. You just say it'll tell you exactly what the probability. Yeah. So we just use competitor data. So in the sector that we operate in, what's the probability of ransomware? And we got that. We know what an outage looks like and we know what a data breach looks like. So a lot of ransomware is a combination of the two. Though we were able to combine that. Though for likelihood, we figured it out. It's about once every seven years for that company. And it hurts a lot. It's in the multi millions of dollars, especially if it's worst-case scenario. And it helped them with remediation. We bought some extra insurance because of it. Just a lot of extra things that we're able to do to prepare ourselves. Just because you had better visibility. And basically what you did was you made risk-informed business decision rather than being amigurous because somebody might say a high risk or a low risk. But the meaning of highs in lows or red, those are numbers of greens might be so different from every single person. You don't know. You don't know what type of cyber insurance policy, what your policy limit should be if you're ransomware risk is yellow. How much should I buy? But if you're ransomware risk is X million, now you have a starting point to have a conversation with your broker. And on the other side, one is the loss magnitude, which is dollars. Now, if you can quantify on the likelihood side and see look on an average in my industry, a ransomware hits one out of every 10 companies, which is 10%. And then I am at like 6%. I can actually make a case for my broker in my carrier that I am in the best in glass. And therefore I deserve a better price, a better sublimit or a better deductible. So you have those levers if data is by your side and you're able to get things going in the right way. That's fantastic. Only any final thoughts in terms of, you know, when somebody's starting on this journey, when they're in the heat of the moment, before an incident or during an incident, and they're a risk practitioner, because we have a ton of risk practitioners who are listening in any top two or three recommendations that you would have for them on how do you look at risk in the right way and your learning from your journey over the years. And turn on the decision. Don't think about gaps or findings or worries or nightmares or just trying to get distracted. Really focus on the decision that executives are trying to make. So that would be my first device. My second one would be when it happens, and if you stay in this field long enough, it's going to happen to you. Just try to stay cool. Let the cooler heads prevail. And I just can't emphasize enough the importance of gaming this out. Tabletop exercises. Practice this muscle. You practice it enough times. It's going to become muscle memory. And then when your company's relying on you to do the right thing to follow the steps, you'll be able to do it. Fantastic. That's creative rise. And I'm pretty sure the listeners did learn a lot from this episode. Don't you've been amazing and you're very kind to spend this time with me. Thank you so much. Thank you. Thank you for having me. Of course. [BLANK_AUDIO]
Podcast Summary
Key Points:
Effective risk communication to executives requires translating cyber risks into financial terms (e.g., probability and potential dollar loss) rather than using qualitative terms like "high/medium/low" to drive informed business decisions.
Incident response is a cross-functional effort involving security, technology, legal, communications, and PR teams, with leadership shifting as the situation evolves from technical containment to legal and external reporting.
Proactive preparation, including quantitative risk modeling (using industry data and actuarial principles) and regular tabletop exercises, is crucial for building organizational resilience and enabling calm, effective action during a crisis.
A real-world example illustrates how a SQL injection attack highlighted the importance of having clear runbooks, communication plans, and the psychological impact of a first breach, which often shifts company priorities toward stronger cybersecurity investment.
Summary:
The discussion emphasizes that the ultimate goal of risk management is to enable sound business decisions, not merely to identify risks. Executives, such as the CFO and CEO, require risks communicated in their language—financial terms like probability and potential monetary loss—rather than vague qualitative ratings. A personal anecdote recounts a SQL injection attack, detailing the chaotic "day zero" response, the cross-functional effort involving technology, security, legal, and PR teams, and the subsequent shift in company culture toward taking cyber risks more seriously.
The conversation advocates for proactive measures, including quantitative risk modeling—using frameworks akin to actuarial science and competitor data to estimate likelihood and impact—and rigorous tabletop exercises to build organizational muscle memory. Key advice for practitioners is to focus on decisions executives need to make, quantify risks to facilitate resource allocation and insurance discussions, and maintain composure during incidents through practiced preparedness.
FAQs
Executives like CFOs and CEOs think in dollars, so framing risks as potential financial losses (e.g., a 50% chance of losing $20 million) makes the impact tangible and drives better decision-making.
The end goal is not just identifying risks but enabling informed decisions. Cybersecurity efforts should support business decisions, not merely highlight threats.
Conduct tabletop exercises and maintain detailed runbooks to ensure teams know their roles. Practice builds muscle memory, so responses become automatic during real incidents.
Incident response involves multiple departments, including technology teams, legal, communications, and PR. The lead role shifts as the incident progresses, with legal often making key decisions like reporting breaches.
Use industry data from peers and competitors to estimate likelihood and impact. For example, actuarial science and quantitative methods can model risks based on external data, similar to insurance underwriting.
An incident can shift organizational psychology, making teams more proactive. It often prioritizes remediation efforts that were previously deprioritized, fostering a stronger security mindset.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.