Welcome to Cybersecurity Insights, the podcast for the CyberEd.io learning community. Our goal is to bring Cybersecurity practitioners the latest and most relevant education and training to upskill and dive deeper into topics that matter in today's modern Cybersecurity world. Good day, everyone. It's Steve King.
I'm the Managing Director at CyberEd.io. And with me today, I have the pleasure of chatting with Jenny Ederman, who is the Massachusetts Statewide Risk Council from the Office of the Comptroller. Jenny's been doing this for 30 years or so, and she'll practice focuses primarily on state finance compliance. And there are like 152 state departments that she works with and is responsible for in that regard.
And the Comptroller's office, including, you know, Cybersecurity and Internal Control. So thanks for taking the time today, Jenny. I look forward to chatting with you. Absolutely.
Thank you so much. I'm really thrilled to be here today. Great. We were before we got on the air.
We were talking about the Joe Sullivan case. And I know that you had some strong opinions about that. And I'd love for you to share them with our audience. Sure.
I think it's such an unusual case. They were looking for somebody to pin the blame on. This has been a trend that's been happening over the past couple of years. There's a frustration with all the cyber security events that are happening and why enough is not being done to prevent it.
So I think they were trying to pin it on somebody and they picked Mr. Sullivan. So again, one of the sacrificial CISOs that the government is trying to identify. So there's some responsibility for cyber security controls.
Yeah, sure. And I understand that. However, the problem here, in my mind, being a recovering CISO myself, is that they picked the wrong target. The guys, the people that have control, actual control, and the liability and fiduciary duty of care for the company are not the CISOs.
They're the C-suite officers of the company, all the people that carry D&O insurance. And to help them offset the cost of being the appropriate target of these kinds of cases are the right people. Because if you, now the message, two bad messages got sent in my mind. One is, if you're the CEO of a company, don't worry about it, we'll take out your CISO.
And two, to the CISOs, hey, if you want to take this job, be prepared to spend time in jail if you, by doing your job, violate what someone perceives as a regulatory or statutory law. And I don't think that moves our agenda in cyber security forward here. It feels to me like it moves it backwards. What are your thoughts about that?
No, I agree with that. I think it's always a leadership issue. You know, internal control in an organization always start with the tones from the top and the people who are actually in control of the decisions. But I think what you make is that when you're dealing with technology, people get overwhelmed trying to understand the technology, which is a distraction.
And then they think that only the IT people really understand it and have a role in those decisions, which really isn't true. So I think they wanted to focus on the CISO as a way of making it make sense to everybody else, that it logically relies in the IT department. And that's really not true, because ultimately, many of the CISOs and many of the IT decisions are not made by the CISOs or the IT folks. It's the leadership that's making decisions, and then they send it out and they say make this happen.
And then the IT departments and the CISOs have to do the best they can with the funding that they're getting. Right, which is always insufficient and driven by the wrong business priorities in my humble opinion. And then the folks who are doing all of that sort of stand back and say, well, gosh, you didn't do a very good job protecting this. So I said, you know, I'm not complaining, right?
I mean, it's a tough job. Everybody knows that who's in it. They didn't sign up for, you know, for soft duty in any way. But on the other hand, you know, if we want to do a better job of protecting ourselves and organizations and companies, we're going to have to do a better job of understanding as you point out the issues that are prevalent in this puzzle.
And it's the duty in my mind, at least of the, as you say, the leadership to take that off. So you, you, you, I know that you feel and, you know, technology is a distraction. And I agree with you or we've over, we're so complex now that it's kind of like there's no way to turn back. And it's gotten to the point where no one, I believe that the CISO community at large isn't frankly capable of managing this any longer.
And now we have generative AI in the mix. What are your thoughts about AI? I think, you know, there's so much information in the news. I think that AI and especially generative AI has the hope of doing amazing things and I've seen it do amazing things.
I think the danger that I see is more of the open AI and the unregulated AI. I think it went out to market, especially the open AI chat, because there was a war in the internet with the providers and not really understanding how it would be used. I think one of the percentages, I think it was one of your speakers, said that 80% of individuals in offices have not reported that they've been playing around with these tools with work information, which is dangerous because everything that you put into those chat bots or those tools go out into these large LLN, the large language models, and it's out kind of in the public domain. So there are actors that are now doing searches on companies.
They want every search related to this company and they're gathering all this information about a company and being able to have targeted cyber attacks. So I think that open AI is the most dangerous now for the public who are putting their personal information in and businesses who have employees or staff that really are trying to do good work but don't understand the danger. And the other part of the AI is that it is still, even though it's been around for a while, some of it's in its infancy. And because of that, there are a lot of mistakes.
A lot of the data out there is not good data. So the responses that come back are not really good responses. So I think that's what we're dealing with is another emerging technology, which is out in the market before a lot of these security controls are put in place. So I think people just have to be very cautious whether they're at home or at work, not to put in any kind of personal information into those chats because it's going to be tracked and it may come back to harm you or your companies.
And I think for companies, I can hear a lot of pressure that companies need to get to implement a generative AI or they're going to get behind. So now there's this enormous pressure to get on the bandwagon and be part of the group and not be left behind. And sometimes when you have that rush, you're not necessarily going to put these security controls in place. Because security is not sexy.
It's not fun. It seems like a luxury add-on. People want the efficiency and they want the fancy result and they don't necessarily see that security is really meant to enable you to do what you do well in a secure way. It's not meant to be an impediment.
And there's still is that kind of banging between the efficiency and doing things well and doing it securely. So I think AI has great possibilities, but it should, like any other technology, then be done in a thoughtful way. So it's not rushed. Yeah.
So, well, you're in the governance business essentially, if I might. How do you, what regulation could possibly make sense? I mean, how do you regulate AI? I think it's like regulating Jell-O.
It's really impossible to regulate something that is amortous. It's always changing. And everybody has a different vision about what's good about AI and what's not good about AI. I think the areas that would be helpful to start are the ways in which AI can harm people, such as having biases or excluding people from certain benefits or opportunities that they might otherwise have because of the way the algorithms are set up.
Not intentionally, but there's always an inherent bias in artificial intelligence. And then really thinking about when you're automating something, you have to understand that there's no human thought process. It's all done by how well you breathe algorithms. So you have to make sure when you're automating something that needs some sort of review that you still have that review process in.
So you're not just making it faster and more efficient and then creating problems for your organization later on. Faster's not always better. You still want to have, you know, internal controls and evaluations and on it through that process so that whatever you're automating with AI is done better and not just faster. Yeah, and I don't disagree with anything you've said, but given that people are behind everything you just talked about, how do we make sure, how do we do this?
How do we get people to do the things you were talking about? For example, you know, when the natural inclination of most folks is to try to act in their own best interests, but frequently they do just the opposite of that as well. And then the rest of that question I think is if we figure out a way to regulate it somehow here that doesn't kill innovation while we're doing it, what does that mean for the rest of the world? I can name four or five countries that, you know, couldn't care less about what we think about regulating AI.
Right. You know, the reality about any type of laws is they're always behind fast developing areas. So any laws that are there for technology are three, four, five years behind. By the time you get it through the legislative process, which is the way you have to go and you get into the regulations, it does take several years.
And I think the federal government is working on this and there are a lot of states that are working on it. But I think the self regulation in industries and in companies, that's where the most gains will be made. And that's really just having a thoughtful approach to AI. Right now it's competing because of what you can generate monetarily.
And there are a lot of companies that are struggling. So they're looking for AI to be able to generate revenue or give them more efficiencies. And I think that's where the problems come up because it's such a new area. But in regulation, I think states are looking to identify the biggest areas of harm to their big constituents or their federal constituents and focusing on that as opposed to trying to regulate the industry as a whole, which I'm not sure is possible.
So it's more the do-no harm in identifying those areas, similar to the privacy regulations. So I think they're trying to look at it from that perspective. Yeah, well, we have a lot of regulation in place about privacy. We humans continue to sort of violate it and always against our best interests.
And I completely agree with you and it can be frustrating. A lot of that is the technology because if you want to use certain technology and it's free, you have to give something up so they can monetize it and pay for it. And most individuals don't realize when you give up some of your privacy in order to get an app or some sort of benefit. They don't understand the implications of doing that.
Because it's so ingrained in the industry now, it's like the click through agreements a decade ago. If you want to use the software, you have to click through and reach every 20 pages of requirements. It's very similar. And when you have that kind of idea out there, that's really hard to change because people don't value their own privacy until it comes back and their identity is stolen or all their information is posted or somebody is farmed by it.
Until they have a personal impact, their privacy really doesn't matter to them. So it really is up to us as government and us as people who care about this to promote that in the work that we're doing. Yeah, no kidding. You're absolutely right.
What is state of Massachusetts doing about trying to get your arms around this? Well, I'm proud of you, Massachusetts, because the legislature for decades has always kind of been ahead in thinking about their citizens and all of these issues. There's a lot of legislation being drafted, a lot of collaboration across the organizations, public and private organizations trying to figure this out, and a lot talking about AI and business and how to protect Massachusetts citizens. So nothing has come out yet, but there's a lot of work being done, and that's very encouraging to state.
Have there been departmental sort of eX or localized die-shout, not do the following things kind of thing? Or are people just allowed to kind of use chat GPT however they wish? I think our office, the office of control, we deal with fiscal internal controls, and we have given out a recommendation that before you use any of these open AI tools to touch base with your IT staff, just because you don't know the risks of doing so and you want to make sure that even if it's public information, you're not putting information out there that can be used to launch a phishing campaign against your department. So we made that recommendation out to our agencies just from an internal control point of view.
It's not an edict, it's just a recommendation, and individual agencies have determined whether their staff can use these tools or not. I think there's some, a lot of agencies really want to try to use them and see what they can do, but I think the risk is putting information into these open AI forums that gets out into the wild. I think when some of these tools actually have a protected platform where you can put information in and you can pull information from the outside, but nothing that you create or you put in there goes out, then there'll be a lot more progress as far as what these tools can do. But for now, I think there's just recommendations out there to be cautious.
Right. Okay. You've talked about in the past year, you've talked about the lack of control over devices by users with dependence on email for business. What terms of best practices, what do you think needs to be done there?
I think for governance of IT, the two areas I see meeting the biggest attention are, number one, really knowing what your remuner is. There are some agencies that don't necessarily know every single piece of equipment that they're using or how their employees are using it. And it's just because it's a huge job and they need to do risk assessments in order to figure out where their biggest weak points are. I also think for anyone, this is kind of a global issue, is the reliance on email for business because that's the one vector where most of your phishing emails and your attachments come in.
Is it get through your security layers? And sometimes they do. Then you really are relying on your employees to be your last defense. And that's a big burden to put on employees and sometimes they're so rushed doing their work, they may not recognize something that looks like a sophisticated normal email.
So I think really thinking about are there alternatives to just having the regular email that would prevent a lot of these phishing attacks from getting into agencies? On the second part, I think really is our growing dependence on third party vendors. I mean, we've seen it with move it and some of the other cloud providers that have had breaches. If you rely on a third party and your security is strong, but theirs isn't.
They're either not updating it or they haven't put a focus on it or they have something that's not discovered, then you really are at their mercy. And unless your contract really allows you to get coverage for that and get compensation for that, a lot of the customers are just out and they have to deal with the consequences. So I think the move it I think is a shot across the bow to a lot of people that if you're relying on these platforms to run your operations, you really need to make sure your third parties are doing the work that they're supposed to do. So those two areas I think really need the most attention.
Yeah, and then third party risk is very tricky. And I think you had indicated earlier that you you thought that we need to go beyond that sort of SOC one, SOC two kind of enforcement, if you will. But that requires does it not that we're congressional action at the national level in order to create the additional more granular regulations around that. Am I misreading that or is that your thing?
I think for the federal government, it might or I can only speak for Massachusetts. When we have vendors, you know, we go through a pretty significant security review of the vendors and we ask them a lot of questions and we'll get copies of their SOC one or their SOC two to review it and see what they're doing. But the SOC one and SOC two are only valid for that year. And you don't know all the decisions and all the vendors that are part of their process unless you ask that information and you really can't get in and audit what they're doing to make sure that they're actually doing everything that they're saying in their procurement.
Yeah, that's what that's what I meant by requiring, requiring deeper. Yeah, that's such a hard area. It's such a hard area because vendors don't want to open the doors and let you see what they're doing. But then how are you going to validate that they really are keeping things secure?
I mean, one area that helped in construction is that there had to be mandatory insurance with the Commonwealth as a beneficiary. And that required, you know, that's an investment that construction companies have to make, but it also increased the quality of the work that was being done. So something like that might work in this area. I know there's cyber insurance and that's a whole other discussion.
But if there was some way to pin more responsibility on these companies, then there might be more attention paid to making sure that they're keeping what they're doing safe. Yeah, and that mandatory insurance coverage names the state of Massachusetts as the beneficiary. Exactly. Well, that would get their attention.
The unpopular and the IT vendors seem to be the most vociferous as far as burdensome day contracts. There has to be a way to ensure that third parties are not focused on providing the services and making their money, but also making sure that they are protecting their customers. Yeah, but see, you know, in my mind that the reason they don't like it is because we've been, the whole world around this topic is so sloppy, I think, or easy going from a vendor point of view. Yeah, yeah, yeah.
Well, you know, we kind of sure I'm like 80% sure we do this or not, you know, whatever, right? And there's too much whatever here, right? I mean, we're either serious about cybersecurity or we aren't, you know, and as best as I can tell, it looks like we aren't. And that goes to the poll privacy issue.
It goes to what people are willing to do and, you know, to get through a TOU and get their hands on that app, you know, I mean, come on. It's crazy, I think. Cybersecurity and privacy are viewed as being more parental. It's like telling us 16 year olds you just got their license to drive slow.
Yeah. So listen to what you say, but until they have the brain development and maturity to understand the consequences of their actions, they're not necessarily going to pay attention. And I think that, you know, I run into this all the time being in the risk area. You know, I'm an attorney and I'm also going to rest.
So people want to run whenever I walk into a room because I know I'm going to be identifying issues that they need to think about. And it's not that they're not good issues. It just means that they're going to have to maybe not do something that they really want to do because it's risky. So I think, I think this is the discussion that we need to really focus on, which is what we're really trying to do in our office is to repack its cybersecurity, not is this overwhelmingly burdensome thing, but really pick out the things that are important and put them in simple terms that they're going to help you and protect you and enable you to do what you want to do.
So they're enablers, not preventters, guardrails, as opposed to walls or speed bumps. And I think we are getting some traction with changing the messaging and the marketing is, I really think it's a PR and marketing campaign when you're talking about it, getting people passionate about it because it helps them do what they want to do. Yeah. Well, I bet everything's a PR marketing campaign.
You know, I mean, perception is reality, right? There are copyright issues, obviously, with generative AI. And so, following upon your deep legal background, how do you think that's going to get resolved or is it? I'm not sure.
It's going to take a while to get resolved just as all the copyright issues years ago with paintings and photographs. You know, that took a while to be resolved. I think the most troubling is that there are a lot of individuals, especially very creative individuals who create front thing, and that's being used by other companies or other places where they posted their content and they're making money. And they're making money off of it.
In some cases, the original artists aren't making anything, and these other distributors are making all the money. So I think that is troubling. And you've heard certainly at the actors' scale where the extras are being asked to find where they're right to the use of whatever they've done, its virtual, that could be used forever, and they don't get any royalties for that. And that makes it really hard for a lot of struggling actors who are in the industry who are not getting the benefit of the work they've done.
And I think the lawyers, there's good lawyers on both sides. But I think when you're doing things that are going to harm creative individuals who are already struggling to make ends meet, I just don't think that's fair. So I think it's going to get worse before it gets better, but I'm hoping eventually it's going to come out with a balance that the creative people will have some copyright control, and distributors will have to pay for use after. But I don't see that happening right away.
I agree with everything you just said. The creative side is likely, and unfortunate and fair is going to have to bite the bullet and compromise quite a bit on this, because right now they have no power anyway. So musicians get paid nothing. The music industry gets all of the profit from their labor, if you will.
So I think it feels to me like if you go on offense and say, okay, I accept the inevitable right there. We can create music without me now, and it'll be great music and it'll be whatever we want it to be. But just give me a couple of pennies per whatever rotation. And even though that isn't seem like much, it's better than nothing.
And as you point out, greed is sort of the overarching word here in terms of how this is all being managed and it's going to play out. Industry has evolved in this direction, data in general, data now is monetized. And so there are full marketing and financial and other companies that all they do is identify ways to monetize data. And that's being used as your income generation as opposed to the services that you're providing.
So part of it is just inherent in the industry. But I think it's unfortunate that the creative industries that we've known are slowly being pushed out. And that's just disappointing. Yeah, of course, the artists could also decide to sort of take this on themselves and kind of create through a reverse and create their own studios.
And because given the technologies that are required, you can do it for almost nothing. That certainly happened with the independent film industry. If that happens here, then you'll see that model coming up again. Yeah.
Speaking, so we've solved four or five major issues here. The last one is the legal profession and AI. I think if you equate AI to any tool, it's going to be as good or as bad as the person wielding the tool. You see it in Manhattan, you see it in any industry.
You either use tools well or you don't. And I think that in the legal profession, this will be absolutely apparent. And it's already being apparent with some attorneys who have used AI to their credit. So I think what's going to happen is again, it's going to get worse before it gets better because a lot of attorneys believe, unfortunately, that they don't understand technology.
And I think it's kind of a learned of helplessness. That technology is just something outside of their profession and they're really not responsible for it. I'm going to be opposite of you. I think that everything that we do has some basis in technology.
So as attorneys, we have a responsibility to understand the tools that we're using and their technology. We have a responsibility to understand this tool, especially when we're representing clients or representing the citizen of a state like I am. You can't go in and just try to make legal decisions in a vacuum. You really have to understand the environment that you're operating in.
So I think that AI is going to make it so much better to find information for lawyers. And I think just like Lexus next says, and West Long, when it came out, when I was in law school, I used books for years. But Lexus next to the West Long were fantastic at being able to bring a lot of information that I never would have been able to find. It also came up with thousands of searches.
So it makes your search time sometimes longer because you're sorting through. So what? But definitely those tools improve the legal profession because you have more access to information. But also, I think you can become lazy just like you can in any other profession and rely on AI to do your work or you're thinking for you.
And that's what it becomes dangerous because AI can write a great brief. But when you actually have to argue it, that's where the scales really come in. And I think we're going to see that in cases where the briefs are really good, but when they actually have to get up and argue, that's where the weaknesses will come in. So one of the recommendations I think for all law schools is they should have courses in technology.
So their students and the lawyers who are coming out really understand the foundations of what they're doing and understand technology because they're going to be using it. They're going to be using it to create documents. Their client files are all automated. They have medical files that are coming in for some of the cases.
They need to protect those. And I think if you have courses that teach that, we're going to have better lawyers in the future. Well, yeah. And given the confidentiality and privacy issues that lawyers have to understand, it's surprising to many I think that your point about the law profession pretending that they don't understand technology or they don't need to somehow is really startling.
I mean, we live in a digital world. And if you don't have, I don't care what you're doing, especially lawyers, if you don't have digital literacy, you can't be effective doing your job. I mean, as you point out, all of these records over which you have custodial duty are all digital. And if you don't understand how to store them, protect them, retain them, et cetera, et cetera, then you have a new liability problem.
So I'm always shocked that the industry that is so otherwise concerned about lawyer-client relationships and the privacy issues would not reflex well to what's going on here. And I completely agree. I think most industries have this problem too. You see it in medicine where doctors say, well, I don't deal with that.
I just deal with doing the surgery or the reviews. You see it in accounting. You see it in every major industry has the same issue. It's not unique to lawyers.
You would think that lawyers would pay attention to it because it deals with law. But I think that at least for the last couple of decades, people have grown up with technology has been being just kind of this cool that you use and it's okay in the Internet of State. And I don't have to worry about it as long as I have a password. They don't really dig into the details.
And I think lawyers now are kind of getting bitten by that. And I see it in government when you're dealing with technology issues and you ask them lawyers about it, they'll say, well, that's not a legal issue. When, ultimately, it is part of the legal issue, but they just don't understand it. So some of it is just like anything else, education and exposing professionals to this and really expecting that they're going to look into the technology you're using.
Yeah. And I was amused by that case that where they use chat GPT to the lawyers who chat GPT to generate their briefs and the judge noticed that half the references didn't even exist. Exactly. That's pretty embarrassing.
Right. And, you know, they didn't know that a lot of the information and chat GPT and I'm not singling them out because it's, you know, in Bard and all the other ones that are out there. They run the same issue. If the information that's going in and feeding the large language models is tainted or it's not good information and the result comes back is not going to be good.
And they've tested it by putting the same question in multiple times over a period of weeks and different answers come back. But they're not better answers. They're actually worse answers. So again, it's all in the programming and how could the algorithm is and how well it learned and just like in any educational system, some students learn faster than others.
It's going to be a process. I think I see in the education industry, they've really stepped up about using chat GPT for student work because the whole purpose of education is learning how to think and how to write and not relying on these easy tools. So that's an area that I think they've really stepped up and are good example to companies and other industries. Yeah.
And you're absolutely right. And we're doing it in our cyber ed initiative here at ISMG. And we're using avatars who can also, by the way, be multi linguistic. And I can update an avatar's script in under an hour to reflect a current threat that wasn't there two weeks ago and re render it and have a feedback online again.
So, you know, by the way, he or she or it delivers that in about half the time of the live instructor model because the live instructor model is full of folks that think that this is a platform for them to be clever and funny and they're never clever and nor are they ever funny. That's fantastic. I love to hear that. I think that I do see AI being able to get information in a meaningful way out to more people and really enhancing people's lives on encouraging them to educate themselves and learn.
So, I do think that that I love seeing all the work that you're doing there. Well, yeah, thank you. But you're right. I mean, this is transformative.
There's no other way to say that. And we, if we can just get through this part where, you know, we can, we can figure out the path that we can allow innovation to continue, allow that productivity to be reaped by the folks that are investing. And at the same time, protect against the stupid application of, you know, really dumb ideas or dumb use cases, I guess, then, you know, then it'll be an incredible world that we're fortunate enough to still be living inside. On that note, I'm conscious of the time, Jenny, and I didn't want to take more than you've already given me.
I appreciate you, you taking it and joining us today. It was, I'm glad we solved all these problems there. That's another huge thing. So, thank you again, Jenny Hederman.
What is your actual title? You're the Statewide Statewide Risk Council for the Office of the Controller, is that correct? Yes, the Risk Council for the Statewide Office Management Team. Yeah, okay.
All right, that's right. Well, it was fun talking with you. I plan to do it again in a few months. If you don't mind, there's a lot more to, we're going to, you know, the speed of which is happening.
We'll have a entirely new world six months from now. So I look forward to it. Absolutely. Thank you so much.
I love talking about these issues. And I look forward to talking to you again. Thank you. Thanks to our listeners for spending some time with us today.
And hopefully you enjoyed Jenny and our dialogue as much as I did. And until next time, this is your host, Steve King, signing off. Thank you for joining us for another episode of Cybersecurity Insights. You can connect with us on LinkedIn or Facebook or send us an email at social at cybered.io.
For more information about the podcast, visit cybered.io forward slash podcast. Until next week, stay safe and secure, and we'll see you on the next episode of Cybersecurity Insights.