Building Small Company Security Programs – Frank Kim, YL Ventures
Frank Kim and Mike discuss when and how smaller companies should build a security program and hire dedicated security people. They also talk about how to decide the appropriate level of security tooling for a company.
Transcript
This is Textron TV. Hi, welcome to another episode on our Tech strong TV interview. I'm Mike Rothman general manager of texturung research and chief strategy officer of tech storm group.
I am very pleased to be joined here by Frank Kim who is ciso or one of the field csos or you know partial to you. You can explain what your exact title is for why El Ventures while Ventures if you haven't heard of them is a very exciting, you know, seed stage Venture fund funds I guess we should say plural and they find very cool technology security technology in Israel and help to productize that and make it into a thriving company. They've had a number of different outcomes thus far.
So again, very exciting Tech very exciting partnership and and Company and I'm pleased to have Frank here. So Frank, why don't you just introduce yourself if I miss characterized anything about why IL don't be bashful. Just correct me as they might doesn't know what the hell he's talking about.
So, you know, feel free. Correct me on that front. Well, hey Mike.
First of all, thanks a lot for having me. And as you maybe immadently mentioned, you know titles, you know, don't really matter. But you know, hey, I guess we'll get that out of the way.
I am to see so in Residence at yl ventures helping entrepreneurs and Founders get from idea to eventually company to eventually product to eventually seed stage investment and Beyond and I'm also a fellow at the Sands Institute where I lead the cybersecurity see so leadership curriculum and the cloud security curriculum as well. So helping both Founders and students in their Journeys to securing their organizations. Yeah, that's great.
And and really what I think makes sense given your background Frank and a lot of what you're doing today is really to kind of hone in on this concept of you know, what is a security program for a smaller company, right? When do you started and whether it's one of the startups that you're working with, you know kind of within yl whether it's you know, some of the folks that you're advising and working with on the you know, Sands Institute side, you know, that's one of the questions I get a lot right from practition. Nurse who maybe aren't full-time security and they're like, when do I start?
What kind of tooling do I need? What kind of policies do I have to put in place? Do I have compliance, you know issues that I've got to deal with.
So I love to just get you know to kind of start with a pretty broad one, right, you know your perspective about you know, what what where and when right from a security program standpoint for you know, whether they're startups or smaller companies and maybe have an invested in that thus far. Yeah. Yeah sure thing, you know and you know, it's you raise to keep point there because you know as a SEO as a security leader going in and we might have some of these preconceived notions sometimes of how we want to build out the program but it really is stage dependent.
It depends on the stage at which the organization is at. And therefore where the business is that I had a engagement with a company a billion dollar plus valuation company that a little while ago and they had a they had a see so but long story short that see so wasn't lasting very long and I was talking to the CEO and she said, you know, hey, I kind of feel like the sea still kind. Pulled the word kind of change the script a little bit on me.
Once they came on board. And even though we've gotten a lot of funding the stage of our business is not one where we can invest hundreds of thousands of dollars in an EVR solution hundreds of thousand dollars in other solution. And the problem was well in that particular case the ciso didn't realize what stage the business was.
That was kind of taking that. Traditional if you will Enterprise Playbook and trying to adapt it apply it to a business where it didn't really make sense and you know, they didn't realize at that stage that ciso's job was probably more 80% sales enablement marketing enablement customer support things like that and whatever it might be 20 30 percent on actually building out the capabilities themselves. Now the problem is that can quickly shift right from six months 12 months within a year as the company changes as the company grows, but that's the challenge that you know, we as csos have is adapting to this changing market dynamics.
That's right. And you know, I do have a little bit of experience in this having started up a number of my own, you know, kind of companies I go back and forth between research and you know corporate things because I'm professional add right? I just get bored and I got to go do something else and and build things on that front.
But but really, you know kind of to me the Catalyst for a lot of small companies to really start investing in the program is when customers start asking you about it, and it makes no What business you're in if you're you know fintech or you know kind of a smaller Financial type organization, you're going to have Regulators that may be asked those questions. But somebody's asking a question about how do you store data? Right?
How do you protect it? You know, if you're doing business with one of the big, you know, kind of global technology companies, they've got you know, whether it's on online questionnaire or some for, you know, 30 tab spreadsheet that you gotta work through on that front. But to me that is usually an indication once it starts getting in the way of your deals.
That's the time where you really have to start thinking about. All right, not only do I have to start, you know, kind of implementing a bunch of these controls actually have to start documenting them as well. Yeah, exactly.
You know you mentioned that thousand question questionnaire, right the Thousand tab questionnaire and that's certainly one of those things is and really going back to kind of the stage of the company. We see this from both sides. Is that might mean that the company needs to get a sock 2 type 2 that might mean you might need to think about in the future ISO 27001 depending on the client base your targeting it could be something like a Fed ramp certification but on the flip side for our portfolio companies, for example as they're growing as they're scaling to series a and Beyond and eventually hopefully bigger things.
Well the question then becomes well, when do you bring in a full-time see so and when does that actually make sense and it's usually exactly what you said time to exactly this in terms of not just the marketing story in the sales enablement and so on but hey, well, what's the work that needs to be put in place to be ready for that sock to the type 2 what's the work that needs to be ready to? Oh Downstream further along get ready to actually go public in terms of the SEC filing requirements and things like that. So there are some of those hard and Rules but it requires.
Yeah the ciso to be adaptable to figure out. Well what what is needed at that particular time? Yeah, and and I mean having been through that process, you know, and it was a long time ago to be clear.
So we have much different reporting kind of requirements, you know, then then when I was doing it, but you know kind of the scrutiny that's on public companies is just not that interesting to me, right? So, you know, you also have to be prepared for the fact that you know, the the individual you have leading the program initially is you're starting to build it out may not be, you know, kind of the same person as you, you know, continue to grow it's not not unlike what you see with entrepreneurs right at some point. They may, you know, kind of yield to you know, more professional management on that front.
I think we have a similar type of you know situation insecurity that there are folks that are well suited to yeah, I think is you said your first story right, you know kind of that see so they came in with an Enterprise mindset to you know, roughly a startup company that Prize mindset is absolutely critical when you get there, right and and if you're a mismatch, right you either have a startup see so who's much more about you know, kind of the show, right the external, you know piece of it rather than the policy and the team and and all of that, you know, if you put them in a situation where the companies ramping up to go public that doesn't end very well either right? So it really is making sure that you've got, you know kind of the right folks in the right chairs at the right time. I think Jim Collins said that many hey, I mean, hey, I've read good to great too many times.
So yeah that resonates with me. But yeah exactly, right, you know, some ceases are what post-reach Specialists some Caesars are sustaining sisters. And as you said some csos are startups that have more of that entrepreneurial bent and really understand.
Hey, well what it takes in terms of the being that business enabler in terms of solving problems for both today and tomorrow for sure. Let's talk about some of the challenges that these folks have right. Let's kind of start with I don't know one that may be a little timely and and somewhat high profile, right but ransomware.
All right. So what do you know when you're getting in and starting to work and engaging with customers or a client? Right or a company?
I mean, however, you want to phrase it. How do you start to build that out? Right, you know and to what degree, you know, you mentioned well Ed.
All right with maybe too early for EDR but there's got to be some base defenses that are in there to protect, you know the devices but what I found with with ransomware is, you know, it's it's a process thing right when and how do I start to figure out you know, what the proliferation is, right? When and how do I understand? How much of my data is actually a risk?
What Provisions do I make the possibly pay the ransom and I love to you know, get your perspective on whether that's or really, you know, bad idea or necessary evil, you know in this, you know kind of environment but if we take that as kind of the stalking horse, you know, how do you start to take this? You know, we have this You know kind of squishy mythical program and make it into something that becomes pretty tangible for, you know, kind of companies that are trying to figure out how to behave in those situations. Yeah, you know, well kind of let's take it into kind of two prongs here first is maybe a little bit more Technical and then we'll focus a little bit more on the business on the technical side.
It depends on the organization. If it's a cloud first company that's doing things from scratch relatively new organization. The good news in my opinion is that there's a lot of cloud capabilities that help us help make it easier to get some of these processes in place in terms of recovery resiliency availability and so on but from a business perspective.
Yeah, that's the bigger question. We see all of those headlines all the time of company X Healthcare Company why other company Z they've gone ahead and paid the ransom and that is an indication that well one. They didn't have the processes in place.
They didn't have the backups in place. They didn't have the data anyplace else and the cost of not having that data of course was much greater than the cost of paying the ransom so it became just really, you know, just a business Direction right and that's the the risk trade-off is a lot of times for better for worse Security leaders. We don't realize necessarily that our job is not to implement technical controls.
Our job is to manage information risk and that's helped to manage and mitigate the Cyber risk that the organization might be facing sure. Ideally we'd have those preventative controls in place and processes in place ahead of time, but it really to get a seat at the table. We need to understand.
Hey, well, when do we pay the ransom? What do we advise or not? A truth be told we're not going to be the one making the decision on paying the ransom but we've got to be giving the good advice that gives the accurate description of what the trade-offs actually are.
Yeah, that's right. And and the other thing I would add, you know kind of fleshed out a little bit more Frank is um, you don't want to be having that discussion with your board of directors. Well, it's happening.
Well it's time. So those are when you're a new season when you're you know, first starting to build the program, you know, those are the kind of questions or scenarios or table tops or whatever. Technique you're going to use in order to make sure that you've got that Playbook, you know, at least discuss.
I mean you're going to deal with it on a situation by situation basis, right that's obvious. But the reality is if you haven't even brought that up, right and then you've got somebody saying it's going to be, you know, X number of Bitcoin, you know, in order to free up your data again, that's not when you want to be having that discussion, you know with folks. So we've got a couple minutes left.
So I mean just real quick bring up the top of your head and I love to do these, you know, kind of just stream a Consciousness type thing. Right? If you're an early security practice or security practitioner in a company that you know really doesn't have as built out of security program as you know, you'd love to see what are the first three things that you do.
You know, I'm really looking at identity right looking at what who has access to what what are the various systems and especially in this newer smaller company a lot of it is the the cloud-based footprint the SAS Services the public cloud services that are largely being used getting an understanding of the footprint. It really all boils down to the basics. But in a different context, what's the inventory right?
Where do we actually have exposure and a lot of times we get we know security people we ask the question. Well what you know, ask the executives, what's what what keeps you up at night? That's not a horrible question, but I don't think that's the best question.
I'd much prefer to go in and say well, what are your most important processes? What do you think are the most important assets honing in a little bit on it a little bit better so that I can then decipher. Where is the Cyber risk for the orc and does that match up?
Is that what you see as well and having more of that business conversation around things. I love the business conversation. The question I usually ask is um, if you were to get fired, what is the what is the scenario that kind of got you there right because to me that's Pretty indicative of stuff that's important to those folks.
So it's just a different, you know kind of flavor on that question. It's just when you're talking to somebody it's a lot more tactile and they think about oh, I'm gonna get canned if this, you know kind of situation happens, but I love you know kind of the idea of focusing on visibility because again, you know, especially when you're new or you haven't thought about it this way understanding data sprawl, especially in this, you know age of SAS is critical and I'll also put you know, a hundred percent behind I am right and as folks move to the cloud, they don't realize kind of the foundational aspect that you know, kind of not just the identities but the entitlements that go along with those, you know, how that plays in terms of how your resources in the cloud are used. So I think that is really a great list of things to do when you're getting started.
I think again the idea of thinking about the program, you know within the Construct of you know kind of whatever, you know matching up the maturity of the company, you know with the type of security program that you need and then ultimately being able to think and have discussions proactively about things like ransomware to make sure that you know, you don't get surprised if you do get hit at any given time. So I think those are you know, really just fantastic ideas and and guidance for all of you that are out there. Thank you Frank that I miss anything, you know in that little summary or that kind of you know, that's a great summary.
I will just kind of try to put a headline on it and say Hey, you know to me it's all about being a security business leader not just a technical security leader and that's exactly what we're talking about. So yeah, appreciate the conversation Mike. Yeah, you bet.
So Frank came I see so in Residence at yl Adventures, I really appreciate the time and thank everybody for listening to another episode of tech strong TV. So now we'll send it back to the studio.