Video: Emerging Compliance Risks and How to Navigate Them with Confidence | Duration: 1864s | Summary: Emerging Compliance Risks and How to Navigate Them with Confidence
Transcript for "Emerging Compliance Risks and How to Navigate Them with Confidence": Alright. And hello, and welcome to this AppTiva webinar. I am your host, Robert Hilson, and I am pleased to be joined today by experts from our partner, Fullsite Cybersecurity. Today, we're going to be sharing an overview of emerging risk and compliance hurdles, particularly faced by small and medium sized businesses, and importantly, how to partner with the right security and technology provider, to address those risks. Before we get into the conversation, let me quickly introduce our speakers. First, we have Richard Mormon. He's a senior cybersecurity advisor at Foresight Cybersecurity, where he provides guidance and technology solutions to organizations seeking to up level their security posture and meet compliance obligations. Richard, thanks a lot for being here. My pleasure. Joining Richard is Jody Madsen. She's a regional director at Foresight. Jody is a solution specialist who's worked with organizations to help them identify ways to improve their security. Wines Foster, she has more than 8 years of experience in managed security sales and consulting. And, Jody, we're we're really happy to have you here. Thanks for being here. Thanks, Robbie, and good morning to everybody. And last but not least, we have my colleague, Brock Gulich is here. Brock is one of our solutions specialists and has been working with some of our biggest managed security partners, Aptica, for 3 years, helping them build streamlined managed compliance practices that, importantly drive revenue, margins, and customer retention. He's gonna be our demo guy at the end of this program. Brock, thanks a lot for being here. Yeah. Happy to be here. Thanks. Alright. So, this is a 30 minute program, which means we're going to boot, but we do encourage questions. If you have them, you can ask them in the little chat box that you see on the right of your screen. And if they are relevant to the conversation, we'll try to answer as many as we can. With that, let's get started. And and, Richard, I'll start with you. Just to kinda kick these things off, let's let's try to paint a picture of the landscape facing many of the types of organizations that that you're working with on a daily basis. What would you say, from a security perspective are the biggest emerging risks, particularly facing small and medium sized companies? That's a great question. So my forte is small and medium businesses. I mean, that's just our sweet spot. And I had worked in larger organizations where security was kinda more common in the culture. And what we're seeing is the small businesses, they just don't have that yet. Right? So it's a general lack of awareness of the risks that they're exposed to, but they don't know they're exposed to. Right? Again, with a bigger corp company, people start talking about this a lot more. Smaller companies, they're just busy nugging it out day to day, trying to keep the lights on, keep the IT equipment running so they can make money. And they're just not aware of the risks that are actually out there that could spill out spill gloom and doom any day. And and and, specifically, like, what do you see as the most common risk that they are they're facing? Like, what what's the stuff that they kind of, you know, it's not on the radar but should but should be? Well, besides the overall lack of awareness, there are some companies that, believe it or not, are just doing business in the IT context the way we did it 20 years ago or 15 years ago. I mean, for example, Microsoft Active Directory, I have a client who doesn't use that, and that just is a mind blower for me. And there's a lot of these, again, small shops, they're just doing things the way we did things historically in in a legacy mindset, and so they're just unaware and unprepared for what's gonna hit them. Got it. And and from a a compliance perspective, like, how would you rate kind of the the ability of these organizations to meet compliance obligations, whether they be, you know, something like maybe more complex like a like a CMMC certification or something that kind of everybody needs to, be aligned with like a like a PCI, for instance? Right. And I'll throw, the NIST Cybersecurity framework in that mix. So the CSF is one of my favorite frameworks because it's one I can walk in the door with somebody who's totally unfamiliar with security. And the language we use, the vocabulary, we can bring them up to speed quickly and say, hey, look, basics. Do you have an inventory of all your assets? I mean, almost every compliance framework requires you to know where all your assets are. And obviously, that leads to the next step, which is are you managing those assets? Are you keeping things patched? You know, are you monitoring? And so on. So that's why my favorite is the cybersecurity framework. And every small business can do this. Right? If you just start with a basic look, walking through the framework, you'll have a real quick understanding of your security posture. Mhmm. So you just answered my first question, Richard, was what do you think about the overlap between compliance and security? I think you kind of answered that a little bit. Well, actually, there is a distinction, And it's important that people understand those. So if you're 100% compliant, right, you have a regulatory requirement to conform to a standard or a framework, and you do that 100%, and you've got a perfect score, that does not necessarily make you secure. Right? Compliance does not equate to security. There is, some misbeliefs out there, believe it or not, that if I do everything that the checklist tells me to do, I'm secure. And that's just not true. And I think most practitioners agree with that. It that security requires kind of more of an ongoing programmatic approach. It's not a one and done. Let's check what we're doing, turn everything on, walk away. It does not work that way. We have to maintain it continuously. Richard, on the I mean, to to your point, when you have a compliance obligation, and obviously, it it this the kind of answer to this question will depend on what compliance framework you're aligning with, but where do you often see, gaps from a security perspective? Like, if you did go through the exercise of checking all of the compliance boxes, where are you most likely to still be gapped from a from a security perspective? Yeah. That's a great question too. The let me start with the positives. What I do see is usually an IT department has some security apparatus in place. Right? They've got the antivirus that we've had for 20 years. Maybe they've got the firewall lit up. Maybe they've got an email filter. Maybe they've got, a web filter, web proxy, right, and so they're watching what traffic is moving. Those are good things, okay? So they've implemented the technical piece. Now what we end up doing is backtracking it a little bit. We're looking at policy and procedure. Right? Why did they put those things in place? Well, from a compliance context, you should have a policy that dictates that you're going to have a practice. Right? Because any auditor in any field of audit will say, tell me what your policies are, and I'm gonna assess you against how well you do what you claim to do. Right? That's just audit 101. And so we'll end up backtracking and saying, okay, it's good that you did that. Now let's write the policy that tells you you should do that. And then specifically, if they don't have certain things in place, the things that are likely to be missing are kinda more formal things. Right? So for example, incident response plans. Mhmm. You either have one or you don't. It's kinda binary. And if I talk to like a IT director or a senior system administrator and I say, okay. If you have a ransomware incident, do you know what to do? And they do. They they do just because they've been around. They're like, oh, yeah. Maybe I'll isolate the machine, or I'll go to my backups and do a restore. Okay. Great. But wouldn't it be better if we had more of a procedure, maybe a checklist to start with? And everybody knows that you don't rely on your incident response plan to make everything whole again. But it's a great place to start. Right? We're starting with a plan. And, you know, in the military, they say a plan doesn't survive first contact with the enemy. And that's true. But it's a place that we can start. You know? You'd be surprised how many people have an incident response plan, and they didn't print a hard copy of it. I'm like, really? So we're talking about technology here. It does fail. I mean, I had to reboot my system just 20 minutes ago. And let's say you got ransomware, and your drive, where the procedure is, is all crypted up. What are we gonna do? You're gonna pull the binder off the shelf, old school. Yeah. You need to have your plan printed. And I swear, 90% of my customers do not have a printed incident response plan. And so it's it's those simple things. It's like, just you didn't think about that. Again, this goes to maturity of the organization in their thinking and planning. Nobody wants to go through an incident response exercise, but you need to. That's the other thing. So we got a plan, then we practice it. And that's another thing almost every framework requires. Practice exercise your incident response plan. Why? Because you can find what things you didn't account for. Or maybe a system changed, or a role changed, or the people left the organization. Right? Hey, we gotta update the phone numbers in the response plan. Well, it's a hard copy. Yep. We're gonna have to print it again. You know, things like that. And so it's it sounds basic, and for me it is, but if you haven't been exposed, you haven't been exposed. And so that's where we start. Yeah. Great points. And and, Richard, I was gonna ask you too. Like, so you're you're talking a lot about the plans. You you mentioned the policy piece of this as well. A lot of a lot of kind of the security aspect is contingent on getting people to actually, like, follow through on the policies. Right? So when you're, you know, when you're talking to your your clients and they might be having challenges around this, like, what what's kind of the guidance you give them to to not only, like, get people to follow the things that they should be doing, but to really, like, start to develop an internal, like, culture of security? Right. And that is the biggest hurdle is the culture of security. I'm glad you brought that up. It's like, if a the question is like, really, when did suddenly the, organization become aware that they need to start looking at this security stuff more seriously? Right? And that usually happens one of 2 ways. You know, whether somebody's getting bombarded with these, you know, marketing messages about security things, security products, security services, and they're like, maybe I should look into that. And then they come to a webinar like this, and they learn something. But most often what happens is there'll be a change in leadership, like a board member comes in, looks around and says, what are we doing about cybersecurity? Because guess what? I mean, if you have any investors, the SEC is all over this these days. Right? This is a risk. You have to have a designated person who's competent in cybersecurity now. It's a requirement. So it's usually a change in leadership, and the second one would be regulatory. So if you're, for example, in government, a government contractor or you support government work, that stuff is flowing down now big time. They want everybody in the supply chain to be cybersecurity aware and more cognizant. Right? They want that culture of security to come up from the bottom all the way to the top. And so that's where we see a lot of people calling us. It's like, oh, by the way, our main customer, like, say a prime contractor, for the government, just told us we had to get aligned with CMMC, and we don't know where to begin. Okay. Well, it's it's been in regulatory law for a while now that you need to comply with the NIST 80171, but let's get started. So we walk them through, you know, baby steps. Let's just start at the beginning. Tell me where you are, what you know, and then let's figure out how to get you up to the next step, because you're not gonna conquer it overnight, but you need to begin. Yeah. So that that gets into well, go go ahead, Jenny. You jump in. I that basically was a great segue because I was gonna ask you if, you know, a customer wanted to get an engagement started with foresight. What does that process look like, and what could they expect at the onset of that engagement? Yeah. I mean, even even in our, scoping calls, you know, before we've sealed the deal, I walk people through exactly my process, which starts with a lot of question asking. Right? I'm gonna read through all your policies and procedures that you have and identify where you need to improve or create. Right? That's where we start. We start with policy and procedure. And then we'll talk about your technology. We will go through whatever framework. Again, my favorite is the CSF. And you'll just tell me how you do what this thing is asking. How do you track inventory? How do you manage your patch updates? How do you whatever. How do you do security awareness training, for example? A lot of organizations are still not doing security awareness training. There was a a rub a few years back where people were saying it was a waste of time. And I totally disagree with that. I've always offered security awareness training to the staff that I work with. And I find it it helps cultivate that culture of security. You know, remember 20 years ago before we had computers on every desk, or maybe it was 30 years ago, And, on every position description, it would say I don't remember. You don't remember. You're too young. I'm too young. Every position description would ask if you had experience with Microsoft Office products. They would ask that. And to me, that should be replaced with, what is your understanding of information security? Right? Because I want every employee to have a basic understanding of information security. I shouldn't have to train you every time to not click on bad links, but I will. You know? Even in my own company, I get I get the training. And every time, once in a while, I'll click on the link. And it's like, how can I be so stupid? I've been doing this for over 10 years. Because it's well done. It's well crafted. It's what the bad guys are doing. So everybody needs to be doing training, you know? And it's just you're always trying to raise the level of the organization's security understanding. Through awareness and through this compliance effort, it gets us there. Richard, let me ask you this. Like, when you're on the front end of an engagement with, you know, a client or a potential client, Like, what are the things that you typically look for in terms of kind of buy in, like access to people within the organization, like resource allocation that that kinda indicates to you that that they're serious about this and that, you're gonna be able to kinda work with them to to see the improvement in posture and and and achievement towards compliance goals that that you're looking to see? Yeah. That that's a fun one. So I actually enjoy doing this kind of work because I spend a lot of my time educating. Right? So if I get somebody who's just totally unaware of all these risks that we've been talking about on let's say they've got a few technical things, you know, they got some good stuff going on, but they just they're unfamiliar. I had had had to explain a lot of interesting things, such as hard disk encryption, MFA, just things that, again, that are easy to do, that they didn't know they had at their fingertips, that they could turn on. So that willingness to learn and just take on board from me, and and it's a narrative. It's a conversation that we have ongoing. You know, sometimes we cover 5 controls in 1 hour. Sometimes we only cover one control because there's so much to to get into the weeds on there. And so I take the time to make sure they understand what I'm saying, not just are you doing it? I have no idea what you're talking about. No. No. No. No. You might know what I'm talking about. Let me explain it again. So that's my approach. It's a very consultive approach on purpose. Because we want them to achieve their security goals, not just say, oh, you're doing it wrong. I don't do that. I want you to have a plan to get there. Yeah. Excellent. And and well put. And I'm I'm gonna bring in Brock here in a second, and we're gonna kinda hit on the technology piece of this. Richard, maybe one last quest question for you, and we'll try to go 2 or 3 minutes here. But but when you're when you're consulting with these organizations and helping them kinda think about the return on investment and and the services you're delivering and just kind of security and compliance in general, a lot of times these are kind of, you know, soft costs. It's it's hard to quantify. But but what are the things that you're kind of, you're you're educating them on so that they can understand kinda where their dollars are going? Sure. And you're right. It's very hard to quantify an investment in security, and that's across the globe. Right? It's physical security, IT security, it doesn't really matter. What the the way you scope that or get a value assigned to that is you look at the cost of not doing it. Mhmm. So for us we would look at the cost of a data breach, the cost of a lawsuit because a bunch of data was spilled. Right? So, yeah, you're gonna call your cyber insurance company, but guess what? They have limitations. Oh, you don't have cyber insurance? We need to talk to your legal counsel and see how they wanna manage this risk. And so we put it in terms of risk. And so the cost of, like, working with us, working with you is minimal compared to the cost of dealing with a breach or an incident. And there's an incident every single day. And then there's the whole regulatory side where they're assigning penalties now. I just saw that, was it Georgia Tech Research just got slapped with a huge penalty by the US government for failure to follow all these cybersecurity guidelines that we've been talking about. So there's there's a financial risk for not complying, and that's usually how we talk about the investment. Yeah. And and there are in addition to those things, there are some hard cost savings that that that can be attained as well, specifically around, cyber insurance coverage. And and we've seen, you know, consistent premium reductions with organizations that are following either security best practices frameworks or or compliance frameworks as as it might be. One of the things we also, you know, look at, and, I mean, we're we're doing it here as a business, is is, you know, acceleration of of revenue. So to the extent that you need to get certifications to either be more competitive against, you know, your competitors in in selling to a certain industry or you need to be compliant to actually, you know, sell to, for instance, a a DOD contractor. Right? There's a lot of upside there, and and a lot of times there's obviously an obligation too. So so so good stuff. Good discussion. Let's segue into the technology piece of this, and, you know, we didn't touch so much on it, but given the complexity of having to track and attest to and report out on how you're meeting security and compliance obligations, not to mention all of the evidence collection, the policy drafting, Richard, that you were talking about. The the process is typically pretty tedious and can take up a lot of time and resources. So we'd like to share an approach here, and this is certainly one that the Foresight uses. We we use it here at Aptiga, which which can both create internal efficiencies and speed and also a lot more visibility around how secure and compliant you are at any given time, which, you know, at at the end of the day is is the name of the game. So, Brock, I'll I'll turn it over to you. I see you got your demo, ready to go, and you'll you'll walk us through this. Yeah. Awesome. Thanks a lot, Robert. Yeah. Yeah. So my name is Brock Bullock. I'm a channel account manager. I work directly with the foresight team. And so, you know, I I got 10 minutes here and really I just want to take you through a high level overview of the Abtega platform. And so feel free if you have any questions, drop them in the chat box, and I'll try and answer them the best I can before we kinda, run out of time here. And then if you'd like to see a deeper demo, feel free to reach out to us and we can work through that. And so, yeah, really, you know, Aptiga, we've been around since 2017, and the focus was to make cyber compliance easy for any sort of organization. And so, you know, we're we're we're finding today that 70% of organizations are managing their cyber compliance either on spreadsheets or they're kind of starting from scratch, kind of like what Richard mentioned. And so, you know, what we're gonna do, so if you were to use the AppTika platform for your cyber compliance, so you'd start off here, we'd kind of white label on your your branding, color scheme, logos here. But first off, we just want to understand, you know, what are your cyber compliance goals? And then if you don't really have anything specific today, that's where you work with the foresight team to really build out that program and and and get that work done in here. And so just to show you here, we have 30 plus frameworks today that are all mappable to each other. So if you are organization that follows multiple frameworks, you you can manage that in here. So we have CCPA, GDPR, the privacy standards, HIPAA, ISO, all the different flavors of NIST here, you know, PCI, SEC, SOC 1, SOC 2. And so all these frameworks are mappable to each other. So we have CCPA, GDPR, the privacy standards, HIPAA, ISO, all the different flavors of NIST here, you know, PCI, SEC, SOC 1, SOC 2. And so all these frameworks are mappable to each other, which which is really helpful. But, you know, the the main thing and and Richard kinda talked to this is, you know, if we start out an engagement with Foresight, what happens? Well, we have to go through the scoping process and we gotta gather this information. A lot of it's question based. So, you know, the Foresight team likes to work with NIST CSF. We would say that's probably our most popular framework in here. And so the process would be in the platform, It's pretty straightforward where we ask specific questions that relate to sub controls, and then it's just an exercise of kind of self auditing yourself. What are we doing today? Well, we we we've met this control. Here's our documentation on on our implementation detail, and then the foresight team can come in and actually give their recommendations, if you haven't met something. And so then, you know, we have the ability to start to gather evidence and and bring in, you know, SharePoint, screenshots, PDFs if you are gonna go through a cyber compliance audit today. And so, really, the idea of the assessment is to get this information in here so we then can figure out where your gaps are and then put the playbook together to go remediate the gap. So what's really cool about Optiva, you get the information in in the assessment, then it's like, okay. Boom. Now we've scored this assessment. So let's say company x, y, z, you know, they've went through this initial assessment. They're sitting at 64% compliant with NCSF. Not too bad. Not the greatest. You know, there's some gaps in here. So if we look at asset management, for example, here's the first control. You know, device and system management, in that initial assessment, you said, yep. We're doing this today. Well, you still need to go prove and verify that you're compliant with the control and have the appropriate documentation and evidence in here. And so this is where we give you the playbook. We give you the guidance of the control, the action items, you know, some of the different related documents here. So we do have a 150 policy templates in our knowledge base that you're allowed to access if you become an AppTeegia customer, foresight customer. And then, you know, from here, it's all about best practice of collaborating with Foresight or with your internal kind of GRC infosec team. So you have start and end dates to track those audit deadlines. You can track vendors, you know, collaborate amongst each other. And just for the sake of time, I'm gonna kinda go through this quickly, but 2 really powerful areas for organizations that are doing things manual today, like managing their compliance in Excel, having a central document repository where you can store all that information and really see where those artifacts are being linked out to at the control level is really important is what we hear. And then the big thing is just, you know, you're gonna have gaps in your program. You have to go remediate those. So how do you build out a well functioning collaborative way of remediating those those tasks? We like to call them. So tasking is our most used module because it pretty much relates to everything. So that's the high level overview of being inside a specific control. And then to really get into the the deeper area of, you know, AppTIGA as a whole, we are what we like to call the full GRC capability. So we we talked a little bit about, you know, the document repository. So all your documents will be stored here if you are preparing for that cyber compliance audit. You can download everything into a zip file pretty easily to give to a third party, And then we did mention tasking here. So, you know, this is where we have this nice Kanban view where you can filter between who own who owns what task, what stage is it in. But then also another big thing that we hear from a lot of our customers, especially if you're focusing on the CMMC and the NIST side of things, is vendor management. How are you managing your vendors? Are you sending out cybersecurity questionnaires to those vendor contacts? So we have an entire module here where you can create a vendor, and you can use some of our templates to send out cybersecurity questionnaires, whether it's the sig light, you know, NIST, or your own custom questionnaire that you wanna bring in here. You can send that out, and and track all that information. You can ask follow-up questions, and it's just a good way to to document that information. And then based on some of those vendor responses, you can actually document the risk of of of those responses. And then, you know, really getting to the next area, you know, we find it you know, you're working through these cyber compliance frameworks in Aptica, and that's definitely where we're very strong, because we have the 30 plus frameworks. But we do find that running in parallel and building out your risk program is is very, very important. So this is where we have this risk module where you can bring in your risk register. You know, you'll be able to document, you know, here's our inherent risks, you know, before the controls in place versus our residual risk. And so, you know, to present, you know, the CSOs, the info sec posts, they they really care about, okay, where am I at with the 300 controls? But, you know, maybe a board or an executive team, they wanna kinda know your risk maturity and and where you're at on that front. So so you can document that all in here. And then really the last two areas to kinda round this out is, you know, you put all this information in Aptiga, you know, you should be able to get some sort of valuable output. So, you know, when you're talking to vendors, customers, prospects, whoever, and they ask about your cybersecurity compliance posture, you know, we have a great deal of, you know, reporting capability to pull. You know, I'm not gonna go through all the reports. If you if you come on a demo, we can get deeper into a lot of these areas, but we have an executive summary report, really clean, 15 slides that you could show to a CFO, you know, an assessment report, full program board reports, based on this this cybersecurity best practices information that you brought in here. And then the last area would be if you do have to go through a cyber compliance audit, then you could actually track that here in Aptiga, where you're working with the 3rd party auditor. They import the you know, you import the audit request list, the items they wanna test, and all your information's already here. So the evidence is ready to go for the auditor, and it just saves you a ton of time as you work through an audit. But, yeah, that's that's the quick high level overview. The goal is just to make cyber compliance easy for really any organization, and I'd say the big thing to really think about if you are managing compliance on spreadsheets or starting from scratch is, you know, these regulations change all the time. You know, Richard could definitely tell you that. You know, there's the new version of NIST CSF. You know, the new version of PCI came out. Aptiga, internally, we make those updates to the requirements, you know, usually 2 weeks after they're released, so you don't have to worry about that. Oh, I gotta go work in another spreadsheet now that there's these these new sets of controls. So, yeah, I really appreciate the time today. And, yeah, if you have any questions, feel free to add it in the chat. Yeah, Brock. That's a really helpful overview. And and typically what we see, in particular for, organizations that are that might be, you know, smaller is that, they have the best experience. They're able to achieve their compliance objectives a little bit faster with fewer resources if they're partnering, with an organization, like Foresight. So, we'd encourage everyone to, if you're interested, check out Foresight, check out Aptiga. We are gonna be incentivizing follow-up conversations. So, please feel free to reach out to us afterwards. I believe we're giving out Jodie $100 gift cards on us. So so, don't be shy, and, we appreciate everybody's attention here today and time. Jody, Richard, thanks a lot for being here. Brock, way to stay on time. We appreciate it. Thanks, everybody. And thanks, Robbie and Brock and Richard for all of your time as well. Yeah. We'll see you all next time. Thanks a lot. Thanks. See you all. Bye.