Security as a Business Enabler: From Cyber Risk to Action | Interview with Matthew Webster
Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello. I'm Dejan Kosutic, the CEO at Advisera and the host of Secure and Simple podcast. Today, guest is Matthew Webster, he's the founder and the CEO at Cyvergence.
Dejan Kosutic:This is a New York City based cybersecurity firm that is specialized in advanced business focused cybersecurity consultation and leadership. And in his work, he's focused on bridging business and executive decision making. So in today's podcast, you'll learn how to introduce this concept of security as a business enabler in your company. So welcome to the show, Matthew.
Matthew Webster:Thank you so much. Happy to be here.
Dejan Kosutic:Great to have you here. So tell me, you know, this, let's say phrase, Secure Security as a Business Enabler, it's becoming, you know, quite, let's say popular lately. But what does this really mean? I mean, what do people or companies really should do about or how does this actually reflect in reality?
Matthew Webster:So I think there's a lot of different challenges, and I'll kind of talk about the story behind it first before I jump into it. And this is a problem. I've even done this in my past, too. I've learned from my mistakes. And a lot of companies do this.
Matthew Webster:And a lot of cybersecurity experts, what they do is they start by learning the discipline of cybersecurity, which makes perfect sense. But the challenge is a lot of the disciplines within cybersecurity are are invitations to be a silo, and you aren't communicating with the rest of the business in a way that makes sense from a business standpoint. Our language, everything we talk about creates silos. So for example, let's take a look at a vulnerability. You know, we could get into the, quote, unquote, geekier side of CVSS scores.
Matthew Webster:And I know there's exploit prediction scoring system as well. But, you know, you talk about, oh, it's high risk. Well, the business, you know, has a little bit of doubt in their head when they hear high risk. What does high risk actually mean? And you've got to look at the context.
Matthew Webster:You've to take a look at the details. And some of that can be baked into the process. But let's take something like, are you looking on the systems level? How is that actually going to impact the business? Like, I'm a big fan of doing things like the business impact analysis.
Matthew Webster:And part of the reason is that's going to give you greater business clarity if the business is involved in the BIA. And I've seen some cases where the BIA business is not involved, and that's a different story. But if it's done right, you have a very clear understanding of where the business is at. And then when you get into things like the disaster recovery plan, you have your prioritizations. Here's our P0, and you go from there.
Matthew Webster:And so when you start to marry those two concepts between, like, vulnerability and the business impact analysis, you grant gain a lot of clarity for what's important to the business, and that helps you learn how to communicate with other people. That's just one tiny example, but it gives you an idea of one possible starting point of getting aligned with the business.
Dejan Kosutic:Okay. But beyond this, let's say communication, which can obviously be improved, How actually exactly can security help a business?
Matthew Webster:Well, just by, I mean, A, getting the prioritization right. Because if you're helping the business by doing what the business wants and what the business thinks is important. Now, a lot of businesses don't sit down and define what's important to them. They think they know. And then the IT or the security team, they think they know what's going on.
Matthew Webster:But trying to find out what's important, try to bring in the risk and communicate with them in a way that makes sense from their standpoint, that's what's important. So if we're aligned with that BIA and then you start to talk about things like, here's the real risks based on what the business impact is going to be, you start to get into a quantified approach, you help them make decisions. That's where decision science comes in. And you can start to get the right level of governance by having the right communication structures for your organization. And to me, that's absolutely critical.
Matthew Webster:And so once you start doing that, then you're going to start having the right levels of communication. And there's a lot more to it. But you start to get in the realm of having the right levels of communication that other business leaders can understand. Does that help?
Dejan Kosutic:Yeah, definitely. So if I understood well, okay, so this kind of business aligned cybersecurity helps communicate better and helps the business actually make these decisions, which are also relevant for cyber. But all of these things are actually related to, I would say, managing risk, right? Cybersecurity risk or operational risk, if you want to use a wider word. Now, is there any other, let's say, aspect on how cyber can help a business beyond managing risks?
Matthew Webster:I mean, the managing risk is important. But if you don't mind, I'd like to unpack a little bit of what you were saying there. Because there is a massive difference between operational risk and cyber risk. And you have to be very careful about the approach. Now, I'm of the ilk that on a certain level, we should start to get rid of the concept of cyber risk.
Matthew Webster:That might seem a little strange. That doesn't mean ignore vulnerabilities, don't do the pen test, all that kind of stuff. But the reality is, what's going to resonate with executives? When you talk about what's resonating, it's usually what you talked about is operational risk. This is the risk to the business operations.
Matthew Webster:Don't think about it. It operations, think about it as business operations. So when you start to do that, it helps the communication. And when you start to take that, tie that into BIA, all of a sudden, you've got a little bit better conversation about what does that risk actually mean. And it's a way that business executives can identify with.
Matthew Webster:I mean, yes, there's a lot of sources you can go. But if you're doing the defining and you're imposing that on the business and, one, you come off a little bit arrogant, even if you're taking it from a known data source. And I've made these mistakes over the years too. And sometimes I've used some of these techniques very successfully. Like, let's take, cyber insurance, and then you can find out what those risks are and say, hey.
Matthew Webster:So here's where we're at, the fiftieth percentile versus the ninety fifth percentile. So what is the likelihood? You you get a better sense of that. But businesses, usually, the first thing you do because they doubt the data, I don't believe you. And I've had those conversations multiple times.
Matthew Webster:So when you start to get into the decisions, when you start to understand how the business actually looks at things like, I'm very big on quantified BIAs and getting the feedback from others that's going to help you to communicate because you're not telling them what to think. They're already invested. And so when you talk about risk analysis, I'm very big on scenario analysis. Ask what if. And like, for example, there's a company just recently.
Matthew Webster:I had done a business impact analysis, but I didn't do it from a cyber perspective, purely a business perspective. I looked at some angles that were IT slash cyber related and starting putting that bigger picture in. But it turned out, the reality is, their biggest risks had nothing to do with cybersecurity. And I was working with them. That's very helpful.
Matthew Webster:So it's not taking a look just on the pure cyber level. It's taking a look at on the business level so people can understand it. And the business team and this is a small company. I'm building them enterprise risk management. That's how you can make a much bigger impact on the organization by bringing people around.
Matthew Webster:So there's a lot of emotional intelligence that starts to go on for how are you going to bring people along from a risk standpoint. And those questions yeah. But anyway, you get the idea.
Dejan Kosutic:Yeah, no, we'll definitely I mean, you definitely started to speak about something very interesting. And this is about how actually security should understand what business is about. And we'll come to that in a couple of minutes. But first, I wanted to kind of finish this thought about how can actually security contribute to business. Okay.
Dejan Kosutic:Risk management is obviously one aspect. Now but from my experience, cyber can also increase revenues in in some examples. So for example, it can I don't know? On very simplistic level, it can you know, if you have a certificate security certificate, it will give you entry into certain markets like CMMC, right, or or twenty seven thousand and one. On the other hand, it might actually help you bring or decide some or make some really important decisions, you know, in a better way.
Dejan Kosutic:So what's your thought on that? Is there really something there?
Matthew Webster:I am a big believer in that because you can figure out what that sort of cost benefit analysis is for where you're at, and Cyber does that. And also, it's going to depend a little bit on the type of company you have and things like that. So take this with a grain of salt. But for a lot of companies, what's getting bigger and bigger, especially in the more regulated space, the tougher this is, they're diving into third party risk management. I know a lot of people are liking the term, you know, supply chain risk management, as is the approach that they use today.
Matthew Webster:But you start to bring that in, you're going to get business. A lot of businesses will not do business with you unless your security meets a certain level. Or they're going to develop their own internal compensating controls to protect against whatever deficiencies you may have in your organization. So for example, I know organizations that have and I've helped contribute to this in more than one organization where I help you build your own internal controls on a system because their systems are simply insufficient. So then you start to build those types of things.
Matthew Webster:That's where you save the company money. And so when you start to look at, hey, here's the operational risk of doing what we're doing, we can do that. A, we've got no control of the data, the data is going outbound. Now we've got control by bringing it in, You can start to consider what those risks are over time and consider what I like to look at is the p 90 risk. You know, what's the ninetieth percentile?
Matthew Webster:The the 90% chance this isn't gonna happen and what the risks are there, can ignore. Everything below, you can start to ignore. And that should be a curve that you're looking at. Yeah. Depend on, you know, is what kind of curve and you can talk about that.
Matthew Webster:But when you do that, you help the company make better decisions. When you start to bring the scenarios in, you start to talk about the context. That's how cybersecurity can really be a business enabler. Now, I am painfully aware that, for example, the Institute of Internal Auditors actually has a perspective where you've got what's called the three lines model. It used to be referred to as a three lines defense.
Matthew Webster:Now in some cases, cyber doesn't get that detailed in those discussions. And that's okay. Sometimes it does. It depends on the organization, even if you're following this three lines model. Now, a lot of the financial organizations, and I know others that have as well, have followed that and definitely, breathe that as part of their disciplinary process.
Matthew Webster:But once you start doing that, you really see yourself as a helper of the business that these cybersecurity controls give you business. And that's what's very powerful from my perspective.
Dejan Kosutic:Great. You mentioned these, let's say scenarios, can actually help business make better decisions. So can you give some examples on what kind of scenarios actually cyber can contribute to the business for this decision making?
Matthew Webster:Oh, sure. I mean, what happens if this data center goes down? So an example I was just talking about on a meeting the other day, this is many years ago. There's a requirement in this sector where the data centers need to be at least I think it was 200 or 300 miles away. I forget which.
Matthew Webster:So they built two different data centers, the main data center and the backup. And the first data center got hit. Happen to be on a river, and a river hit that. Now, they built their backup data center. And that got hit on the river, too, is sort of a backup perspective.
Matthew Webster:That's just like a tiny example there. But when you look at controls, especially if you're dealing with federal controls, they do care about these types of things. And they get very detailed in this sort of analysis to say, hey, how much is this going to cost you? Now, in some cases, the business just flat out doesn't understand. So this is where, as CISOs, we need to be very good at storytelling.
Matthew Webster:Need to find the stories in the news, have a communication process, talk to them, say, hey, here's what I saw happen to somebody else. And when you start to bring I'm very big on getting alignment across different parts of the organization. So bring in legal. What do they care about? How do I bolster a lot of what I'm doing?
Matthew Webster:So cybersecurity should be part of a bigger picture within organizations. It's helping to contribute to the data related to risk, but also receiving data from a business standpoint. So I look at CISOs in the best of possible worlds where they're really communicating with one another to help the business create the best possible decision as a team. And that's part of the thing that I see as a challenge with a lot of CISOs. So, you know, they're pulling in the data.
Matthew Webster:You know, you look at every company under the sun. We've got the data. We show you the data. Then you show the data off to them. They've got, cost benefit analysis.
Matthew Webster:They've got all these other things. But they're not really communicating with the business, and you're imposing it. And there's not a lot of emotional intelligence, and the business sort of rejects that. And some of it has to do with the language and other things.
Dejan Kosutic:Okay. So do you think it's only the language? But it's also or is is it also that the CISOs don't really understand the business good enough?
Matthew Webster:In many so this is I know the CISOs who really understand the business. So putting them aside for a minute, there are a lot of them that don't fully understand the business. They don't understand they understand, like, what's going on from a technology standpoint. They might understand some systems, but they don't understand how the business is looking at things. They aren't looking at them from an operational perspective.
Matthew Webster:They don't understand what that business impact is going to be, what the politics are. Trying to get that sort of executive orientation sometimes is very difficult. And for example, some CISOs are buried deep within the technology frameworks. You might have the CIO, then the CTO, then a director of IT. And then underneath that, you find the CISO.
Matthew Webster:I've seen some strange things like that. They don't even have some visibility to have a conversation with other people because they're not and I've been stuck in this situation before where you're not allowed to even speak to the executives. So I
Dejan Kosutic:think Okay. But how can the security officers overcome this problem of that they are actually not educated enough or that they do not know enough about the business side?
Matthew Webster:So I think there's a lot of things that they can do. One, I think learning the language of business, learning how do you communicate with people. So for example, we talk about critical high, medium, low, etcetera, a dollar value hits. But like, for example, one of the tools, say, the financial services, chief financial officer is going to work with is value at risk. Learning those sorts of tools and learning how to be engaged in the discussion when they occur and making people want to talk to you because you're helping with the business, it shows, A, you respected the business.
Matthew Webster:You respect where other people are at. It starts to show like, hey, this is somebody I want to talk to you because they're really helping me out because you're a translator in a language that I understand. And of course, you have to look at the context. I've worked with a CIO, who a CEO who used to be a CIO, for example. I could use more technical language with that person.
Matthew Webster:But, you know, when you start to look at a lot of, CEOs, they don't know how to communicate that way. So learning some of that language and learning how to communicate is a really critical part of that whole process.
Dejan Kosutic:Okay. But the problem obviously is also on the business side, right? The business executives very often do not know what to expect from cyber, nor do they know how cyber can help them from the business point of view. So how can actually CISOs overcome this problem where, you know, the business doesn't simply know, you know, anything or or, you know, basically in which direction to to go with cyber?
Matthew Webster:Yeah. I mean, this is a huge problem. It's one of the that area I kind of deal with with people too. But like, for example, one of the things that I do is I just have a risk communication workshop. You know, how do we communicate?
Matthew Webster:Because you can't just use CVSS score 10.0 and expect people to understand. You can call critical risk, but there are so many different risk tools you can use. So for example, you have to define what is critical risk mean. One of the other financial terms that's very common is materiality. And a lot of CISOs, and I didn't, first time I was a CISO, understand the term materiality, and that's how they look at things.
Matthew Webster:So you can choose there's so many different methods you can use, but you could use just materiality as a threshold. What does materiality What does
Dejan Kosutic:this really mean? I'm sorry to interrupt, but what does this materiality really mean?
Matthew Webster:Well, that's the thing. So you take a look at the Security Exchange Commission. They avoided trying to define it, and they having the companies define what materiality is. You could throw in something like, for example, a lot of companies are going to use a threshold of 1% to 2%, their gross profit. And so that's one metric you can use.
Matthew Webster:But most companies, they want a lot more detail in it because it's not just about money. Like Krispy Kreme, when they had their breech, they couldn't make donuts. That's really big challenge here because if you can't make your main product, your store is gonna be shutting down very quickly. That's a material risk. So you can start to be very specific about that.
Matthew Webster:You could say, well, let's say, 30% of our stores can't produce donuts in this example for I'm just making this up, you know, for a period of more than a week. That's, could start to say that's a material risk. So it depends on the size of the company, it depends on the context, it depends on all these different things. You know, if you're a SaaS company, and you have 99% uptime, and all of a sudden, you're down because both the combination DDoS attack and ransomware going on at the same time, or maybe they're doing them, you know, in link, that could be a material risk too. So you really have to sit down and look at those scenarios, look at the context, understand the business to really define what does material mean.
Matthew Webster:And my opinion, it should not be defined just by the CISOs. But you can start the conversation. Because a lot of CEOs, I've run run into a lot of CEOs, they'll understand the concept of materiality. And we have to distinguish it from like the AICPA, which defines the SOC two criteria. They have their own definition of materiality.
Matthew Webster:But here, I'm talking about what is the financial materiality that the CFO is typically going to have. So when you start to do that, you can start to get those conversations going. You instigate it, but you can't tell everybody, here's what your material risk is. You bring it in, you're going be alienating the people that you're around. So I think that's one of the powerful tools is, hey, let's have a discussion around this.
Matthew Webster:I'd like to find out about x, y, and z, and let them come to the table with their viewpoints. Now we could should bring in legal, HR. If there's a chief risk officer, revenue officer, chief financial officer. But you start bringing in these other disciplines into it to help define what this means. That's the approach that you should be using to start changing the perspective of the people around you.
Dejan Kosutic:Yeah. What I found, I mean, from experience is that very often, obviously, businesses are not relying on on security to give them inputs for their strategy, which means that usually the the security part of the company doesn't know what the business strategy is, and, of course, it doesn't know how to help. But if actually security professionals, especially CISOs are are actually involved in strategy making of the company, then they can basically they suggest what kind of improvements or what kind of contribution cybersecurity can do for, I don't know, let's say new product development or marketing or these kind of things.
Matthew Webster:Yeah, I totally agree. And that's part of the problem right there. When you're buried well below IT and you're not even permitted, that's a big problem. There's a lot of different challenges with how businesses approach things. And sometimes it's organizational and structural.
Matthew Webster:And you have to go in there and push yourself into the area. So you can go have those conversations. And that's, that's one of the problems of being at the lower echelons of it. And then there's always a conflict of interest, know, because we're here to point out the bad things, you know, hey, we've got a weakness. Hey, we've got a vulnerability.
Matthew Webster:Hey, somebody could do this. You know, when we're doing that, we're a little bit of annoyance. Because I think a lot of times, organizations are structured specifically not to bring up the truth, not to bring in the security element. And there's a lot of different reasons for that. But that's where some of those challenges are at for organizations, for sure.
Dejan Kosutic:Now, what do you think when you speak about this connection between cyber and business? So what kind of, let's say, business objectives should cybersecurity support? So is this more around, I don't know, protection of revenue or, I don't know, uptime or customer trust or, I don't know, compliance? What is your impression here? So where should cyber really focus when supporting the business?
Matthew Webster:All of it. Because a company if nobody trusts your company, are you going to buy from that company? And there's always exceptions. Like, so for example, with the TJ Maxx breach, they had a slight dip in their stock, but they barely hit them Because they're so cheap and people are going go buy the stuff anyway. So there's some element of that.
Matthew Webster:But when you sit down and talk about what does reputation actually mean for our company, what is that reputation based on? Is cyber part of that? And figure out what's going to be appropriate for how much you want to go down that path. And a lot of companies haven't sat down and thought about it, haven't thought about where the risk comes from, and how do you identify that. So to me, customer trust is gonna be part of that.
Matthew Webster:But really, the big thing I like to look at is mission critical objectives, you know, that and tying things into a BIA. And the thing is, you talk about things from a leadership standpoint, here's the mission critical objectives. That is powerful. That gives you the why for the organization. Why is this important?
Matthew Webster:And when you start to get into the why, you can take that as a cybersecurity leader to your team and say, hey, here's where we need to focus. This is why it's important.
Dejan Kosutic:But are you saying that basically for every security objective needs to be related to a particular business objective?
Matthew Webster:I think so. I mean, there's gonna be certain exceptions. You can't just say always. And anytime you say always or never, you're gonna end up with problems. And I'd agree with you on criticisms along that route.
Matthew Webster:But take something like revenue. Let's say you don't have a firewall, you don't have antivirus, and you've got all these web servers that are out there collecting data and doing all those types of things. Well, you know what? You are there to help protect the revenue. You put the firewall in place.
Matthew Webster:You put the intrusion detection, the antivirus, and so on. All of those things are part of revenue protection. So when you look at the basic controls, you can do a cost benefit analysis on it. And if you don't have those controls, what kind of impact is that going to be? You just need to extend it because everybody today is going to accept you need next generation antivirus.
Matthew Webster:And I know EDR and MDR for those who like to go down that route too. But you need to have some basic controls in place. What are you doing from an identity standpoint? How is this going to impact the organization? So all of these things have to be part of that.
Matthew Webster:And it can go far up the food chain. For example, the BIA to me is like the start of the conversation. Then you can get into business impact analysis, sorry, BIA, then you get the DRP, the IRP, you know, business continuity planning, all of those types of things that should be brought in, you know, like, for example, I'm in some GRC circles, I'll speak occasionally, How many companies are bringing in all these AI agents that they're putting on so many different machines? How many are bringing into their business continuity plan? And what is that going to mean?
Matthew Webster:Most companies are not going down that particular route. I kind of say it sarcastically sometimes, ask the question because I know the answer. Nobody's got a good answer for that. So that's where I kind of come in and say, let's point out some of this stuff. And is this going to be an impact from a business standpoint?
Matthew Webster:How much do we care? And so looking at these things, because you start to take a look at a scenario, let's say ransomware, how long is that going to take for the ransomware to go away in order for you to get up to business properly? And it's gonna take you're probably gonna have to reinvent the wheel that you may have spent two years developing the agents for. And do you have two years to spend on getting you think everything up to speed to get all those agents set up the way they need to be set up? Most companies are going say, no, we're not there yet.
Matthew Webster:That's going to going to it's going take us an additional six months. That's going to change that business impact analysis based on this scenario. And this is where you have to be connected with IT to get their input too.
Dejan Kosutic:Okay. But how do you actually balance this, let's say, need for speed from the business side and actually acceptable cybersecurity risks? So how do we actually reach this balance?
Matthew Webster:I mean, you kind of were hitting it because it's all about risk. You know, security has to come in there. Like, for example, take multifactor authentication. There was a time like, oh, have to do MFA. Now it's like, no, we accept that.
Matthew Webster:And I think because there's been so many breaches, because there's been so many stories along these lines, and you're looking at a lot of the regulatory bodies, and of course, I'm in The United States, so I look at it from a US perspective, they're coming down and hitting companies hard for not having things like multifactor authentication in place. You know, there's just a ruling out on a company called twenty three and me. Part of the issue from reading the news sources was that multifactor authentication was not fully in place and would have saved them from some of the damage that had occurred. And when you start to consider those types of things, that's what I would do is start to say, hey, let's take a look at this. Is this something you really want to go down?
Matthew Webster:Here's that scenario. So you've got to balance that. And when they start understanding, hey, there's a cost benefit, you're now in the business language now. What's that cost benefit? What is the impact going to be?
Matthew Webster:Like, take single sign on. Sometimes that's an IT initiative. Sometimes that's a security initiative, I know. But what's the productivity gonna be impact? Because everybody's like, oh, here, let me get my multifactor authentication.
Matthew Webster:Let me go type this in 15 times a day. You get a little bit of friction from a business standpoint. It's a little bit of dissatisfaction. And if you go through and find out what is the source of the dissatisfaction and you solve it, that could be the business case for doing the cost benefit analysis for that. Because you're saving everybody, making everybody a little bit happier, and you're making the work that they have to do so much easier, that's a good business case.
Matthew Webster:So you bring in that cost benefit analysis, you're going to be in a better place. Now, those don't get into the larger business trade offs, because they might see opportunity. They invest, you know, 20,000,000 over here where you don't have to spend 20,000,000 back here. You know what? They they that's a different discussion.
Matthew Webster:So just making sure that you're at the table. You're not gonna win all the time. But if you make those logical cases and saying, here's the impact, you don't they don't have to understand all the details. But if they build you start to build trust over a long period of time where you're saying, hey. This is my understanding of the risk based on what other people are saying.
Matthew Webster:So you're not arguing with 10 people in the room. You're already having discussions with them on a fairly regular basis or understand their viewpoint after working with them for years, where you don't have to build that trust. That's where that conversation takes place.
Dejan Kosutic:Okay. But I feel also that, you know, the security part in this, CISOs also need to have a very good feeling for the business and they also need to have a feeling of what is acceptable and what is not acceptable, because sometimes they also raise the bar too high, which is then of course not acceptable for the business, right?
Matthew Webster:Oh, to me, I mean, when you get to risk management, where you're doing it properly, you've got to take a look what's the cost and the benefit. And it might go down, it might go up depending on what you're talking about. When you start to look at that risk, and you bring it in, that's going to make you a business player and it's going to be acceptable from a business standpoint. This is where you have to have conversations and get people around your way of thinking. And sometimes these conversations take years for people to change their viewpoint on.
Matthew Webster:But it's such an important conversation to have. But that's what CISOs can do.
Dejan Kosutic:There is also this kind of, I would say, tension between business and security when it comes to innovation. Right? Because innovation is something that obviously pushes the company forward, whereas cybersecurity is very often seen as something that slows the innovation. So how to achieve really this balance between innovating quick enough and not being too risky?
Matthew Webster:So this is where I go back to the scenario analysis and figure out what is that risk. As long as you can agree on it, then you can start to look at innovation versus cybersecurity. Because that's part of the problem too. I think security needs to be part of those very early discussions when you're doing the innovation. And some of it has to do with reputation.
Matthew Webster:If you're like, no, people are like, oh, let me work around security because they're clearly not very helpful. So I think that you have to like, one of the phrases that I heard years ago, and I still kind of hold on to it, is work towards yes. We can do it. Let's figure out how to do it. We're here to support you.
Matthew Webster:Because that language changes everything. And so when you start to develop that reputation where you're blocking everything, people start to get a little pissed off with the approach. And so you want to make sure that you're connecting with them and saying, hey, here's where I think this innovation can bring some value. Can you give us a couple weeks to look into that? I'll have my team focus on that and get that done.
Matthew Webster:And that's where I think when you start to look at what that cost benefit analysis is important and why you have to have these regular discussions, especially with AI. When I was sitting and working with the teams, what are the potential impacts? So let's say you want to get a customer service chatbot in place. What happens? What are the potential impacts?
Matthew Webster:Now, in some cases, they've done things where the customer service is like, hey, you what? You can buy this island for $5 when really it's a lot more expensive than that, And companies have lost millions as a result. So you have to understand what access are you giving it? Is it appropriate access? What kind of protections do you have in place with all the problems we have?
Matthew Webster:What's that cost benefit analysis that we have? And what's the worst that could go wrong? And then there's the likelihood, which that's kind of difficult to tell, especially with new technologies. But when you start having these discussions, business people are smart. They understand the trade offs.
Matthew Webster:And if you speak the trade off language and you say, hey. All these people, we have these concerns because AI is a nondeterministic technology. Oh, okay. They start to develop respect. And it takes time to earn the trust.
Matthew Webster:It takes time to earn that respect. And that's where a lot of those challenges come in. Once you do that, though, they're going listen. Can we take some time to look into this? Because I don't have the answers right now.
Dejan Kosutic:Yeah. But you mentioned AI. Obviously, it's it's now very popular and and most businesses are using AI really to be to become, I would say, even quicker with innovation. So how do you actually I mean, do you have some concrete examples on how AI can be used in a safer way in a way that it doesn't compromise the confidentiality, integrity or availability of the data?
Matthew Webster:Oh, absolutely. I mean, there's a ton of different ways. And I've seen this in many organizations. I've helped build that. I mean, I use AI all the time.
Matthew Webster:I also, when I'm using AI, A, I never put any customer information up in AI. I don't put any sensitive data in AI. I might put scenarios or concepts or talk about a custom, which is a customer name, which has its own pseudonym I work with. But those are additional controls that you put in place to use it safer. When you talk about AI, hey, let's take a look at the potential business impact of using AI.
Matthew Webster:Do you have AI versus AI to reduce the problems? Now, one AI can convince the other AI that they need to move forward even though it's a really bad idea. And so these things aren't perfect, but you have to accept imperfection as part of that model and understand what the potential risks are. Because if it's a low risk, it's really not that big of a deal. But like, for example, I'm going to there's one story I was reading on a professor who had Gmail had access to everything.
Matthew Webster:It just decided, let's delete everything. Or what happens if AI decides to delete the entire database? Oh, you know what? Let's not give AI access to our database then. Yeah.
Matthew Webster:Yeah. Because those are the impact. And I think that's what I see with a lot of companies is they're being responsible in their approach and saying, look, some things people can do better than AI. Sometimes AI can do better than people. And we have to figure out how do we balance those two.
Matthew Webster:And I think that's an important approach, say, how do we innovate and how do we at least put the guardrails on? And this is where the storytelling comes back in. I forgot the name of the company, but the company that had AI just wipe out the whole database. They took a lot of time. It was like a car service company.
Matthew Webster:But they took a lot of time to rechange it. They didn't know who paid, who did this, who did that. They've got all these other methods that they've got to use to make up for the fact that things had gotten screwed up. And so that's what I would do. I'd bring it back to risk.
Dejan Kosutic:Mhmm. Mhmm. Okay. But also the question here is how basically you can develop all these guardrails, all these rules, I mean, whether or not related to AI, but related to cybersecurity. So how do you actually build all these rules so that they are, I would say, that they are not really stopping the business?
Dejan Kosutic:Does this really come down to only to, I don't know, business impact analysis or cost analysis? Well, it's under trust.
Matthew Webster:I mean, trust is part of it. But then when you bring in these other tools, they start to get that. And you bring in their logic, their reasoning. And when you really start to get to know people, that can have a tremendous impact on the approach. They see that you're trying to do something good.
Matthew Webster:You're not the department of no, but you're also learning all the time. You're growing. You're changing with the role that you're in. And that, to me, is an important part of that. So you have to look at the human element, too.
Matthew Webster:The human element is not, hey, follow BIA. We're going to solve this and get that. It's how do I communicate with you? Hey, let's go out to lunch occasionally, those types of things. And so you get to know them.
Matthew Webster:You get to know what their concerns are. You understand what their biases are. What are the structural biases in the organization? All of those types of things. And that changes your whole attitude, your whole outlook, how you look at them.
Matthew Webster:You're mindful of what their impact is. Are they going to lose $50,000 with their bonuses if they don't make such and such goal? They're going to care about stuff like that. So you've got to figure out how to navigate properly within an organization. So yeah, a lot of these tools are good, but then you start to bring in the logic part of it.
Matthew Webster:But the reality is stories have more impact on people sometimes than logic, even if you're 100% right. That's why getting that alignment at the human level first is more important than sometimes that risk analysis. And so when you tell the stories, hey, did you read this? You make sure the board is, if that's appropriate for your organization, if some places don't have boards. But when you get all of this type of stuff, it changes the dynamics pretty drastically.
Dejan Kosutic:Yeah. Okay. Great point. So to wrap up the discussion for today, so what do you think are, let's say, some top things that CISOs should do so that cybersecurity can actually help their business?
Matthew Webster:I think get out of cybersecurity risk and get into enterprise risk. Even even with my background being a CISO multiple times, I have built enterprise risk for companies, and they love it, you know, and they really relate to it, they get on board with it, they're excited about it, because you're not geeking out on a CVSS score and taking a look at the details of ENTRE, and maybe we should have done this, that, or the other thing in order to protect it properly. They get it. And so sometimes working with things a little bit higher level, that's going to resonate with them a little bit more. And as long as you've done that analysis, let's say you're working out with your CFO ahead of time to say, hey, here's what I think the risks are.
Matthew Webster:Maybe it's your chief revenue officer, but we're thinking we've got a big risk over here with the one of revenue generating tools. How is that going to impact the business? Because here's some couple scenarios. But you have that worked out ahead of time, people are going to have a lot more respect for you. So I think that's probably one of the most powerful things that CISOs can do is step across the aisle, learn to speak their language, understand their concerns and their viewpoints.
Matthew Webster:And then when you do that, you get to that larger discussion as a team. Okay, here's here's the challenges that I've been talking with people about in the background, and here's why it's important.
Dejan Kosutic:Great. Thank you for these insights, Matthew. It's been a pleasure talking to you.
Matthew Webster:And you. Thank you for having me.
Dejan Kosutic:Yep. Thanks again, and thanks everyone for listening or watching this podcast and see you again in two weeks time in our new episode of Secure and Simple podcast. Thanks for making it this far in today's episode of Secure and Simple Podcast. Here's some useful info for consultants and other professionals who do cybersecurity governance and compliance for a living. On Advisera website you can check out various tools that can help your business.
Dejan Kosutic:For example, Conformio software enables you to streamline and scale ISO 27,001 implementation and maintenance for your clients. White label documentation toolkits for NIS2, DORA, ISO 27,001 and other ISO standards enable you to create all the required documents for your clients. Accredited Lead auditor and Lead implementer courses for various standards and frameworks enable you to show your expertise to potential clients. And a learning management system called Company Training Academy with numerous videos for NIS2, DORA, ISO 27001 and other frameworks enable you to organize training and awareness programs for your clients workforce. Check out the links in the description below for more information.
Dejan Kosutic:If you like this podcast please give it a thumbs up, it helps us with better ranking and I would also appreciate if you share it with your colleagues. That's it for today, stay safe!
Creators and Guests
