Mike Towers | DigiCert Trust Summit 2023
Mike Towers, a former chief information security officer (CISO) and chief digital trust officer, shares insights into the evolving role of a digital trust officer and how it differs from the traditional CISO role. In essence, both roles share a foundation of security and risk management but differ in their focus areas. Mike highlights the increasing need for digital trust in various industries and offered his expertise to help organizations navigate the complexities of this emerging role. He can be reached on LinkedIn for further discussions about digital trust and cybersecurity.
Transcript
This is Textron tv. Hey, everyone. We're back here live at the DigiCert Trust Summit in Las Vegas, covering a, a, wow.
What a great day of interviews. A great day of sessions, a great day of learning and about digital trust. And, and that's kinda what this event's about.
Speaking of digital trust, I want to introduce you to our next guest. His name is Mike Towers. Mike presented here at DigiCert Trust Summit today.
Mike is the former ciso, I believe, right at at at Taketo Pharmaceuticals and over the welfare, at least the last six months or so. Mike has kind of gone off on his own, helping a lot of companies, uh, with their digital trust in cybersecurity. And, uh, Mike is a board member on several companies as well as consulting.
Look, everybody needs a smart guy about this stuff. This might be someone you want to talk to. Mike, welcome to Techstrong tv.
Oh, thank you for having me. It's my pleasure. So, Mike, you know, I, I tried to do a little bit of your background, but who am I?
Why don't you tell them a little bit of your background? Yeah. So interestingly enough, uh, one of the main reasons why I was presenting here is because I was the CISO and had been a CISO at four different global pharmaceutical companies, and then created and was elevated to a new role that we created at Takeda called, uh, chief Digital Trust Officer.
Wow. So it couldn't be a better fit for this, this summit. Absolutely.
And what I spoke about before with was, uh, kinda like transition from CISO to, uh, to digital trust and what that meant and what we were focusing on, uh, et cetera. So, um, by way of background, I've been doing a lot of data, digital technology work mostly for life sciences and healthcare for, heck, almost 28 years. And, uh, up until about 2008, just various different technology roles.
And then in 2008, I was offered, uh, the first information security leadership position at another pharmaceutical company, GSK Mm-Hmm. And then took that role and then, uh, became the CSO at three other companies before, uh, before joining Takeda. Uh, and as you mentioned, I also sit on, uh, a board, uh, three boards, series B level startups, focusing on various different pieces of the digital trust and cybersecurity challenge.
And I'm also proud to say I'm on the board of the Health isac, which is an organization that's deeply focused on improving resiliency security for the healthcare industry overall. Excellent. Man.
You know, back in 2008, it wasn't easy being a ciso. Yeah. You know, the, I I think I had a lot of friends back then who would, you know, burgeoning, burgeoning CISO and a lot of, I, I think the average lifespan of those people were about nine months.
Yeah. Yeah. It was really a security architect role, right.
You'd come in, you'd architect kind of the security, uh, posture and makeup, and then they'd say, thank you. Go back to being a, a security admin. Right.
Or there's the door. Yeah. Yeah.
And, and you know, a lot of 'em took the door, but it, it, the role has evolved. You are the second digital trust officer I've ever spoken with, though. I'm trying to, I, my friend Matt, who's C-I-O-C-I-S-O at, and I forget the name of the company out of Virginia, but he has a, a digital trust officer at his company and spoken to, but our audience probably isn't familiar with what is the difference, what, what is the digital trust officer and contrast it with A-C-I-S-O role.
Yeah. So it's, so why don't you, yeah, it's an interesting dynamic because it's rooted, I believe, quite strongly in, uh, in the principles of being a good ciso. It's important to note that even though the digital trust officer role was pretty new for life sciences, a biopharmaceuticals where I've been working the constant of a digital trust officer, some of them are just called trust officers.
Probably the most prominent industry you'll find somebody with that title is in the tech industry. Sure. And I think the reason why that is and why it was important to create the role within, uh, a life sciences company is that, let's face it, if you don't do data digital and technology well, and you're in a tech company, the trusted reputation of your company is gonna be challenged.
So we created the role, basically, the best way I can explain it succinctly is we created the role because we were recognizing that at some point in the near future, and we could debate whether this was gonna be, uh, six months or two years, that how well we did data digital and technology was gonna be directly linked to the trust and reputation of the company. Um, I think it's safe to say that in the past, many of us are patients we recognize, and we felt how inefficient the healthcare industry is in terms of, uh, you know, God forbid you have to change doctors or you to go to an urgent care if you're traveling the level of data sharing, it's just not something that's been very, very efficient. There's been tremendous innovation in the clinic in, um, in, in coming up with new medical treatments, but the delivery of care and the data behind it has been reported.
Yeah. No, the paperwork still kills you, man. Yeah, It's horrible.
So, digital trust officer is a recognition that, uh, the entire industry needs to rewire itself to do better with data and digital. So how's it different from a ciso? Well, first and foremost is that it's fundamentally, fundamentally based on the same foundation that the foundation of security and risk management's still critically important.
You have to be brilliant, the basics. You have to make sure your third party risk posture is good. You have to make sure your network's protected.
You have to make sure your, uh, your endpoints are protected, your users have the appropriate access to their system. So a lot of the basic and foundational stuff that C'S has been doing for a long time is still critically important. But where I think digital trust, uh, extends the responsibility and where, how we built the role was, it was much more, I would say, of a business focus around what is the business doing to basically make data and digital a key foundation of its business, and therefore, how can you make it more trusted and maintain that trust?
So there was new practice areas for things such as digital engagement. So most CISO, if I contrast most CISO, when they think of their users and they think of their stakeholders, they're all internal. The employees, internal leadership, maybe a few partners.
The digital trust officer role includes that, but also thinks about who outside your company's using your technology. So in a life sciences case, it might be a mobile app for oncology or a, a portal that a physician would use to learn about your drugs. All those external users and the experience that they have using your tech, even social media pages, all of that could impact and would be impacted for the trust reputation of your company if it's not done properly.
So that was, uh, one of the key difference areas. Some companies call this a product security role, but, um, that is one difference. I would say.
One of the other major differences, and this may be a little bit unique to life sciences, is the exploding amount of data that's being generated in healthcare. And it, and it completely different how it's gonna be used. So, uh, it won't be too far where if you're prescribed the medicine by your physician, it's not just gonna be for that medicine.
You're gonna get some sort of medical device, probably a mobile app or maybe a combination that will track how the medicine's doing while you're taking it. That's one piece of, and, and the, the amount of data that's gonna generate, I mean, we all wear Fitbits or Eye Watchers or whatever, this is all started from a consumer perspective. Mm-Hmm.
So that is gonna extend to scale and frankly, many, many governments and many, many insurance companies are gonna require that before they'll pay for the drug. So that's gonna become big, but not only on that side, but think about, you know, how much of the drug discovery process is now deeply data drug, whether it's computational chemistry, gene sequencing, molecular genomics, protein, all of these massive data stores. Yep.
Traditional ciso, data protection practices won't scale to that. So that's another big focus area. Sure.
And then I would say one of the last areas that's a real, real big difference is, um, what we called responsible innovation. So, and everybody's talking about generative ai, what's the right usage of AI for your company? What's the right usage in AI for your customers, for your patients, for your doctors?
I often quote Dr. Ian Malcolm from Jurassic Park when he says, just your scientists were so busy focusing on whether or not they could, they stopped to think about whether or not they should. They should.
And that's, there's certain parts of, uh, reusing AI that could be potentially dangerous and impact the reputation of the company if it's not applied properly. And I think this problem is even more acute, potentially in healthcare. I mean, imagine a world where, I mean, this could be a little bit science fiction issue thinking, but at what point would a patient trust an AI algorithm diagnosing them, or, you know, tho those types of questions, or even I, I don't think that's science fiction.
Yeah, yeah. I tell you the truth. I probably trust that more today than Yeah.
Some of these doctors who went to some dubious medical school. Exactly. You know, and, and a doctor gets that, gets tired, forgets what they learned in medical school.
So many respects AI could be a benefit, but there's all sorts of ethical boundaries, privacy boundaries, bias challenges, all of that has to be factored in as well. So those are some of the areas where the scope is different. It, It, uh, you bring it up and I think you make some great, great, great great examples.
I, I think, you know, listening to you talk and thinking about it, I, I've always said for a long time, this is why we can't have nice things. Mm-Hmm. Right.
Yeah. Because a lot of these technologies, a lot of the, the, the breakthroughs we've made, not just in technology, like, like new faster computer chips. Right.
But in not, I met a, a friend of mine, John Re who used to work at PNC Bank, he works with a company that makes the diabetic the little white thing that goes, yeah. There's Probably a few of them, but he works for one of them. You know, I was talking to him about it and I mean, so I was pre-diabetic.
I wasn't diabetic, but they were making me stick my finger two times a day. Yeah. What a pain in the ass.
Excuse my language, but what a pain that is. Yeah. Literally, what a pain that is.
Right. You're making yourself bleed and it's, it's enough to not want to do it. Mm-Hmm.
Screw it. Right, right, right. What a, what a godsend this is not, and not just to be able to do it two times a day, but to monitor your blood sugar Right.
Continuously and, and act on it continuously. But at the same time, someone could hack that. Right, right.
Yeah, exactly. And I, and it's funny, I always use an example. I mean, many of us traveled here for this summit.
My dad was in the hospitality industry. And I always think about what it would be like to compare what I do to maybe running a hotel chain or being a big Marriott person, or heck one of these giant casinos. And I often say the, the, the responsibility for the data in this area, you ain't booking hotel rooms anymore.
No. It's a whole different level of responsibility when you're dealing. And, and, and when I think about some of the ethical boundaries I'm talking about, there's been so many parts of our personal lives where we almost laughed this off.
We accept it. So we're out with our family and we're talking about this new shirt we saw, and somehow the next day it's in our, on our, it happens. Somehow that happens.
Or, uh, we're traveling with our family in the Caribbean and we get a text when we try to use our credit card. 'cause the fraud thing kicks in kick. 4%.
You're sure you wanna order that? There's something tells me that society wouldn't accept that as much for healthcare, not potentially for a while, or there'd be some, there's a lot more questions that would be asked for that. It's Dubious marketing.
I, I agree. But look, and some people that may be what it takes To. Exactly.
Yeah. So I think it's an interesting, this level of sensitivity and the level, I think the personal connection when doing some of these things in healthcare. But you're the medical enhancements in leveraging technology, we have to continue to No, We can't afford not to.
Right. It's game, it's game changing stuff. It's, it's just Right.
You know, the, the, the, the other side of the edge of that sword is used maliciously. Right. It's as game changing as it is that way.
It's game changing this way too. And, and that's a bad thing. It's so funny sometimes how Hollywood gets in here too, because I remember being in my field and being in my industry, one of the, and most interesting weeks was the homeland episode where the hackers packed into the pacemaker for the vice president.
Right, right, right. But that came right outta black hat. Yeah.
Yep. Exactly. Right.
I mean, that, that's where it was from. Right, right. So the more you technify, the more, uh, vulnerabilities you have and as more of healthcare becomes more data driven, and then obviously the more it can be impacted by this.
I, I agree with you a hundred percent. Hey Mike, we're almost outta time people who may want to learn, who may want understand more, maybe they have uses that you can help them with. What's the be, and I'm not asking you to give you your email here, but what would look you up on LinkedIn Or Yeah.
Uh, I'm, uh, LinkedIn is, I'm heavily accessible on LinkedIn. I'm a, I quite regular presenter at conferences like this, but I'm very, very responsive on LinkedIn. I'm happy to talk to anybody about this.
'cause this is something I'm pretty passionate about. 'cause I believe Bet that, bet most industries have gone through a tech revolution. You know, think about The transformation, uh, The banking industry, the hospitality industry, the travel industry have ordering groceries.
All of that's gone through digital transformation. Healthcare is just starting theirs. Yep.
So I think building trust in from the beginning is be really important. And I think as we start seeing things like generative AI and we're talking post quantum here and everything, even those industries that have been digitally transformed are going to go through yet another cycle of it. Yeah.
Yeah. I agree. And, you know, there'll be no pain, no gain.
Right. And, uh, there'll be some of that, but interesting times indeed, man. Absolutely.
Interesting times. Absolutely. Mike Towers here on, uh, at Digi CER Trust Summit, one of the keynote speakers, and with us here on Text Drunk tv.
We're gonna take a break. We'll be back here, live in Vegas in about five minutes.





