Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern cybersecurity world. Good day, everyone. This is Steve King.
I'm the Managing Director at CyberEd.io. And on today's podcast, we're delighted to have Ted Gutierrez, who is the CEO and co-founder of Security Gate. They are a provider of market-leading SaaS platform for OT cyber improvement. And he is committed to protecting what matters across operational sectors by helping to align industrial cyber teams on their improvement journey.
Ted's background is extensive in compliance and risk audit and management for critical infrastructure. And he knows well the pain associated with effectively maturing organizational resilience in a decentralized ecosystem. Ted's a graduate of the U.S. Military Academy at West Point, battle-hardened veteran of the U.S.
Army, and a seasoned recon and surveillance expert. So welcome, Ted. I'm glad you could join us today. I appreciate it, Steve.
You didn't have to tell the whole background, but it's a pleasure to be here. Pleasure to be part of this podcast, and I appreciate the opportunity. Yeah, sure. So why don't we start with the SEC and the most recent regulations and the impact that you see that they may well have on the critical infrastructure space?
Yeah, it's a big topic right now. You know, I actually, on my business, the Cyber Podcast talked about what we anticipated as the SEC's ruling on having some level of cyber component. And what was funny is that, I think we did like a LinkedIn audio event, and almost a week later, they had come out with the actual guidance. So, you know, from my perspective, Security Gate talks with CISOs, CIOs, P&L leaders, really the strategic folks that set budgets, they set direction.
And I think these folks are only going to get more resources long-term. I just don't know how it's all going to fade out or play out. It's definitely giving more teeth, if you will, to the idea that cybersecurity is a business problem. It's a business challenge.
It's giving more. It's making the CISO and the CIO role even more important. And I think it's bringing an element of cybersecurity to the boardroom. And so it'll be interesting to see how it's implemented, how it rolls out.
But for right now, you know, I think a lot of CISOs and CIOs are taking positive action to get ahead of this, at least in the publicly owned companies. Yeah, well, there's an opinion on both sides of this regulation. You know, four days for a reporting of a, quote, material, end quote, incident is aggressive. A lot of folks think it's very hard to determine, make that kind of determination within that period of time.
And so, you know, from an IT versus OT kind of point of view, what are your thoughts? I mean, does one side or the other have an easier task in determining materiality? Or is that requirement even reasonable from, you know, from the get-go? It's a good question.
A good couple questions. So as far as timeline, right, I think there's going to be a lot of, I wouldn't say the word litigation, but I do think there will be some collective collaboration over the next couple of years of, you know, when did we find out and when did we make the decision to communicate? I don't have an issue with four days. I have an issue probably with companies having the infrastructure set up to be able to really confirm within that first 24, 48, 72 hours whether this is a real material, you know, let's not use the word breach, but does it really materially affect?
So I think that what that type of requirement or bullet point does to a given organization is it forces the security leadership to beg the question, hey, guys, can we please define so that I can be the watchdog of this what a real material impact is to the business? And so the one positive that I see from this guidance and this guideline that's being pushed with this mandate, rather, is that it forces the conversation about cybersecurity to incorporate a business side. I've been saying that all year long, that there aren't enough resources within the critical infrastructure sector, so we've got to use them more wisely. And the way to do that is you've got to correlate your cyber investments specifically to business outcomes.
This SEC ruling does that in a lot of ways, and it helps push because it forces the business leaders to start telling the cyber leaders, these are all the top 15 business impacts that would be, you know, adversely affect our stock price, adversely affect our operations, adversely affect our P&L. And once they know that, I think that helps cyber leaders a lot because what it does is it says, okay, well, those are the 15 business outcomes we're trying to avoid. What are the myriad of compensating controls and defenses that we layer up to make sure that that doesn't happen? So I think in that side of the equation, I think it really helps.
To answer your other part of your question, you know, is IT more involved than OT? Unsure. It really depends on the organizational structure. I see a lot of companies that still don't have a lot of resources on the OT side, so in those cases, I think it's going to follow an IT person and probably operational or an automations expert to say, look, this screen is down.
We're going to have to shut something down. And so it'll be a little confusing, the data transfer between those two parties. For some organizations that do have OT and IT security roles really defined, I think it'll be volleying the question back and forth of whose responsibility starts and ends where and then the reporting from there. So I think it is as much of a question about the organizational hierarchy as it is kind of OT and IT, at least at this point, Steve.
But overall, I think with the right organizational push from the top, I don't think there's any reason that a given organization, given the right resources, should be able to say, hey, there's a material impact within four days, regardless of the size that comes from. Yeah, well, certainly if you're MGM Grand or Caesars, you knew immediately that you had a material impact. But if you're a SolarWinds victim, for example, you know, when do you decide that that's filtration of data that's been going on for a month? I mean, when does that become reportable as a material impact?
Yeah, it's a big question. I think it you have to, it begs, hey, what's the impact of this long-term? What are the potential impacts? And I think that's where we're going to start to see some element of refinement to the overall definitions.
I think the definitions are generally nebulous in version 1 by design. And I think that you're going to see some real strong leadership come out from various companies that make a filing and say, look, this happened. And whether or not it affects stock prices over the course of the next day, week, quarter, I think that's going to be the real tell. It'll be interesting to see if people use this almost in a transactional capacity that says, hey, this happened, here's the impact, and here's the report.
Or if they do it somewhat in a kind of transitional capacity to say, hey, look, we don't really know what's happening, but we know this happened. Here's all the actions that we're taking to protect it. And the hope would be that industries choose the latter. They look at this as a mechanism for being transparent.
They look at cyberattacks as in an offensive mentality that says everybody was subject to being hit at some point in their future. So how we manage it and how will we start articulating, you know, cyberattacks in the news rather than clickbait, it's more so just like any other incident would be viewed. So not to take the show away from safety, but if you think about an auto shop or auto plant or a manufacturing plant being shut down from a fire, you think about it from a potential safety hazard, but they decided to shut the plant down because of a safety hazard. They had to shut down the plant because of a fire.
They chose to shut down the plant because of a cyberattack. The real question that I offer in the industry is these are all very realistic scenarios. How are they going to be viewed by the investor world? How are they going to be viewed by how are they going to affect the P&L?
And I think that we owe it to the cyber leaders of the world out there to enable them to make change to operations if necessary as a precautionary issue. And right now, I'm not sure that the media, I'm not sure that the world is ready to accept that. I think you still have kind of that clickbait fear that says so-and-so company was hacked. What are we going to do if stock price goes down?
So it's a really dynamic situation that I think public companies are in right now. And I think the real underlying question that leadership has on their shoulders is, are we going to treat cybersecurity as its own body of risk, or are we going to kind of put it together with safety? Are we going to put it together with environmental? Are we going to put it together with even weather?
You know, people shut down facilities all the time for weather, and somehow the P&L still makes it work. So it'll be interesting to see how much negative press the first 10 to 15 of these disclosures create in the industry. And I think that's going to be pretty much a leading indicator of how people view this SEC ruling. Yeah, sure.
And if I'm a shareholder, I'm going to be disinclined probably to hang on to stock of a company that tells me that something's going on. They're not sure what it is, but they're Any kind of calculus around how to evaluate that risk? Yeah, I mean, you bring up a good point. There's a lot of companies out there that are working on products and intellectual property that will calculate the true cost of a cyber attack.
And I think that's really tough to do. It's really tough to do because the data sets that they're using very rarely incorporate real true blue business data. I think it's really easy to do on the fines side. So in Europe, we see with a new directive that's coming down and active in October, you could actually be fined a certain percentage of your P&L.
Okay, that's pretty fair. Pretty easy to understand. If you're in the banking or the retail or in the healthcare side, you know, there's fines associated with privacy and regulatory standards that have been out for a long time. I think it becomes increasingly difficult to calculate the cost of a cyber attack when what your company does is generally difficult, right?
In the critical sectors, moving clean water, moving natural gas safely, transporting a vessel from here to the other side of the world, it becomes increasingly challenging because what you see is you see a lot of supply chain elements, a lot of trading of hands, a lot of varied operations. And so it becomes a more challenging, the more diverse your company is. So in a lot of ways, the more different types of revenue models that you have, so too increases in a positive rate, the level of complexity it takes for cyber. On the flip side of that, Steve, is I think that cyber is overcomplicated.
I really do. I think that people maybe don't understand cybersecurity because they've never really tried to or had the opportunity to look at it. And as a result, there's a lot of negative assumptions and belief systems that cyber is this black box and I don't understand it. One of the number one ways that people experience a negative outcome is related to cyber.
generally starts with a people challenge. So let's call it phishing. I would tell you that somebody with HR experience, somebody with customer-facing experience, is probably as well qualified to prevent a spear phishing or social engineering campaign as somebody who's in the cyber world, who has traditionally dealt with firewalls and encryption. So I think we owe it to ourselves as a collective sector to change the mindset about cybersecurity is too technical.
And as a result, I just, I don't know how to quantify anything and attack it from a different angle and says cybersecurity is the outcome. The negative outcome of cybersecurity is the same negative outcome as safety or as a plant shutting down or as, you know, something being robbed. And if you approach it like that and you try to simplify it, I think that, I think this SEC guideline may force companies to start thinking of cybersecurity more as a business problem rather than some technical problem. But we're a long way from that.
Yeah, no, I, your point is spot on. And I agree. You had said when we started this conversation that you hoped, I think, or expected that boards of directors would incorporate a, you know, structure that includes senior stakeholders in cyber risk management that you do. And I agree that the, you know, this has been going on for way too long.
Do you think it'll make a difference? Do you think that we'll actually see people in board positions who can provide some influence from a background in understanding cyber risk? I hope so. I hope so.
I mean, I think, you know, it's funny. I'm giving, I have a lot of opinions on investment in the space. I have a lot of opinions on training and available skill sets in the space. I think we overthink it too much in cybersecurity and we drastically overshoot it.
You know, where somebody may say, I can reduce our risk by XML percentage because I'm going to implement all 10 of these controls in one year. I haven't met a single cyber leader who's been able to implement their project roadmap effectively year over year. They usually overbite and it'll be interesting to see over the course of the next decade, over the course of the next two decades, how cybersecurity becomes a little bit more, less of an alert button and a little bit more of a marathon mentality for, for resource allocation. You know, when people think about how they pay taxes, you know, and they think about the consultants that they use in their business to, to pay taxes or to run through the financials.
When they think about lawyers and the risk of being sued or the risk of litigation, you know, there's just not as many alarm buttons and fire buttons that you push. Cybersecurity is still in that, in that, in that phase where non-technical people don't really understand it. And it'll take a couple cycles for them to recognize that cybersecurity is just another business, just another business enabler. You know, in a lot of ways, automation, digitization, moving to the cloud, scale and efficiency.
There's a ton of things that technology brings us. I think a very few people 10 years ago were correlating digitization and automation and all the things it could do along with the additional entry points for some sort of hack. Okay. I think 10 years from now, people are going to start asking themselves, you know, do I have the foundation of cybersecurity established so that I can bring in new applications so that I can bring in new, new people to my organization.
So I think we're, I think it's a step in the right direction. I think the people who have the largest responsibility right now, really the, the big miss or the big three-pointer, right, is going to be how do the security and risk management leaders that are actually telling the story to their non-technical leaders, those are the people we've got to wrap our arms around right now. Those are the people we have to empower. Those are the people that we've got to watch because I think that how a CISO or a CIO is reporting to the board forever paints a picture in that non-technical leader's mind of what maybe cyber risk should look like.
And I don't think there's a product on the market, nor will there be, that, you know, you click this button and it's all okay. I don't think there's a positive correlation with the amount of money you spend and how secure you are. I do think that leaders have to be very thoughtful about the resource allocation. And yes, there probably is an argument that resources are going to increase maybe a little bit, but it's just going to come from somewhere else.
And so I think that the global macroeconomic picture that we see right now, the uncertainty that's out there, the interest rates that are really high, there's not enough dollars circulating presses just create endless amounts of resources for cybersecurity. So what I think the best CISOs right now are the ones that recognize this is a moment in time where I can really get the board and I can get all the resources I need. But I've got to connect these cyber risk to business outcomes. And that takes us back to the very first topic that we talked about, Steve.
It's like, is this, you know, who's going to determine what a material impact is to the company? Well, that's the job. I think that the CIO and the CISOs job is going to become far more business oriented and it will outsource or decentralize more of the technical side of the house than it has been in the past. And that's because non-technical people need a layer of translation.
And I believe it falls on the experienced security leaders of today to teach them. I agree 100%. We're part of our challenge there is that, you know, we're just not very good at this stuff. And so we, some people pay some lip service to the idea that, yeah, we should be doing all of that.
But at the end of the day, I know very few CISOs who are board capable. And by that, I mean, can have a business conversation with a board of directors that places them at the same level in terms of considerations for the elements of the discussion that the rest of those people around that board are, have as their, you know, their day-to-day job. And the boards spend their lives making risk decisions. And, you know, that's part of the job, but cybersecurity folks do not.
And so it's always been curious to me how, where enterprise risk management kind of get lost, kind of got lost over the years. It feels like to me in that, in that equation. You've been at this a long time. What are your thoughts about whether that occurred?
I mean, maybe you have a different view, but if it did, how did that happen? Well, I tend to agree with your perspective that the majority of security and risk management leaders are probably not ready tomorrow to go present to a board. I think there's a lot of new products on the market that are saying, we'll make you board ready, which, which I think there's some elements of that, right? So, and I'm one of them, right?
I believe in the simplification of visualization of cyber controls, cyber risk, cyber impacts. And so the more simple you can make it, the bigger, the bigger impact you can have by talking to people that maybe you're not technically qualified. I think that we've asked our security leaders for many, many years, decades to lock things down, to make sure that they don't change, to keep the things always running, to make sure a hundred percent uptime. And so their whole world has been about connectivity and security and architecture.
When you start asking highly technical or usually data-oriented personnel, generally early adopters that like to try technology and try new things. I mean, I'm putting a very big circle over what is probably a diverse persona. But if we just said, Hey, look, the mass majority of security leaders in the last 20 years have been very data-oriented. They've been very process-oriented and there's zeros and ones kind of people.
Does this work? Does this not? Is it patched to scale their assessment and the decisions they make based on what the assessments tell them. And they haven't been able to do that themselves.
So they're looking to move away from consultants or move to their own native system. And security is an option for that to help scale out. So connecting those business outcomes to your cyber investments, whether it's on the people, process, or technology side, it requires a couple different layers of data. We figured out some really proprietary ways to do that.
So the folks that are looking to change their views and alongside the maturity, those are the folks that tend to enjoy collaborating with us the most. Yeah, that sounds great. Thank you, Chad. It's been an absolute pleasure.
And I hope that our audience has enjoyed it as much as we did. It's been a real pleasure. Thanks, Steve. Have a wonderful day.
Yep, you too. And until next time, this is Steve King, your host, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook, or send us an email at social at cybered.io.
For more information about the podcast, visit cybered.io forward slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.