CISO Lessons Quantifying Risk – Fawaz Rasheed, VMware
With the increasing sophistication and stealth of the threat landscape, today’s C-suites and Boards are constantly struggling with understanding the cyber risks that their organizations are facing. Fawaz Rasheed, field CISO at VMware, discusses how this must start with CISOs and leaders quantifying security risks.
Transcript
This is texturing TV. I have the great pleasure being joined by Fallas who Rashid who is field siso with VMware. Welcome.
Hi, I'm Mitch was here. It's a pleasure to be here. Thanks for having me today.
Great happening for us. Would you tell us a little bit about yourself and what you do at VMware? Yeah, absolutely.
So I'm in the capacity of what's called a field see so having been in the Chief Information Security Officer role since 2015. I've worked for some large size Global manufacturers financials Healthcare organizations. So I have the benefit in the privilege of parlaying a lot of my lessons learned talking about advancing cyber Security Programs meeting with csos cios, ctOS son, and so forth to talk about their directional priorities and how we can help in terms of that risk reduction effort and journey that a lot of organizations are on You know that conversation is one of the great things about role like years being able to talk with multiple customers and specially with your background, you know, you're not only relate but you've experienced those things and understand what some of the challenges are.
I've got to imagine. That's me. That's very valuable both for VMware and also your customers.
Yeah, you're smart. You know when I said on the other side of the table as a C cell that was one of the things that I would perk up about is when I would meet with partners and vendors to hear about what they're hearing in the field from others within my industry outside of my industry. What are others doing that maybe I was in my Blind Side spot about that.
I need to kind of be more attuned to so yes to your point that that is very helpful. Excellent. So we're we're talking about kind of managing the cyber security risk and some of the questions that are maybe quantifying that risk.
It's always you know, how much security do we need? How much how much is too much? What's the risk which what are the risks that are the most things we need to invest in versus those that we need to be aware of Talk about that process of quantifying risk and really putting some some numbers around it or Investments around it or making those kinds of decisions as a see-so from what you're yeah the field.
Yeah, absolutely. So to provide some context to the ask, you know, the two macro approaches to analyzing and Reporting out on Cyber risk our qualitative and quantitative right qualitative primary looks at likelihood and impact without dollar value associations. It also limits itself.
So it's not really coming with clearly defined thresholds what you'll get out of a qualitative assessment is another risk is critical or it's high or it's medium, but you won't get thresholds in terms of what's the sealing of a high versus the floor of a critical and how do we know if our risk has reduced we've been going from a critical to a high or if it's increased right? And so looking at it from a qualitative skill also limits Itself by not having this overlay of what we call a Tolerance or risk appetite? So what is the organization willing to sustain when it comes to risk?
Right? We know that you can never escape from risk completely. You have to have a risk appetite that you can accept a certain amount of risk, but in qualitative skills, those are all pretty much missing, right?
So the importance of kind of going to quantitative is that you get more accuracy, right? You get more directional correctness in defining risk you depart from this non definitive t-shirt sizing if you will type of categories of small medium larger or high medium low, if you will and then unnecessary inclusion that you get is that you embed this notion of risk tolerance or risk appetite right with your risk depiction and then very crucial, you know, a directional view into the cost benefit analysis. And/or the reduction you're really putting dollars of loss as a result of having a critical or a high-risk and that is what really resonates quite a bit.
Imagine too when you're talking especially with board members sea level folks you want to put it into business terms three into customer terms, right, you know be talking about loss of customer data or brand damage or reputation continuity of business things like the business people are going to get immediately to say I can tolerate this much risk in that area. Yeah, you're absolutely right. And that's that's so critical Right.
In fact when you start thinking about what board members and CEOs and executives are usually asking about you know, they're going pretty quickly to the bottom line of asking you know, what are our top risks? Right? What's that dollar value impact to the business, right?
How do we evaluate the effectiveness of our information security program by way of Roi against those risks, right and then kind of akin to that and an offspring to those questions, you know questions like are we investing in the right areas, right? How do we know that? Right are we spending enough on information security and our cyber program or are we investing too much and a lot of those are really what quantitative risk analysis seeks to to address.
You mentioned that all important word right Roi what am I getting for my money? And how much is enough and what should I be investing? How much is too much or two little I would imagine some of those things still get tough to quantify or do you think we were getting better as Quantifying those in dollar terms or impact of the business terms.
Yeah. It's it's a great question and one that is debated often, right, you know, typically when it comes to risk Cyrus specifically it's seen as being a bit esoteric right because you can never really put your finger on it in terms of true quantification. So, you know, when I look at risk quantification, it's really a journey that's more directionally correct than the qualitative or ordinal scales of red yellow green or the watermelon charts right of likelihood versus impact we're saying oh our risk is up here versus down here.
So this really kind of evolves it it advances it and takes it to the next level and rather than just putting it in terms of a DOT on a chart what it does is it actually Associates a potential loss value to that risk? So if we don't do acts then we have a stand we stand a chance to lose why in dollars, right? And and as we invest in things we reduce that Eye level of dollar loss through the investment of those controls.
They all important why question if you can't answer that things usually don't get funded very well. That's right. Well, we'll talk a little bit about you know, we obviously are to have talking with Executives every day about risk management.
And and where we should be investing. What's the right Cadence and part of why I asked this is we're all living in a sea of information about you know, this kind of malware this kind of Ransom event or something happened at this institution. And so executives are informed about that too.
So, you know my ex for some frequent anytime something happens in the news. I know what I'd get asked but I also want to proactively talk about first management and what we're doing, what are your thoughts and kind of that back and forth Cadence? Yeah, you know Cadence is one that I think needs to be determined based upon the organization, right but for the most part you can't say doing it annually is enough because I think that's that's not enough, right?
And then, you know looking at it and doing it weekly is quite onerous. So somewhere in the middle if you say well what's the right sweet spot here if you will, you know, when I think of that basically it's you know quarterly is a minimum in my opinion, right? If you're presenting to the board of directors your elt to do it on a quarterly basis.
I think that's table Stakes but beyond that if it can be done in a monthly basis, I think that actually gets you closer to looking at you know, how things are changing and evolving and gosh, you know, I mean the Cyber landscape is changing Moment by moment, right? So while you have a Cadence that might be monthly or might be quarterly you may have to be proactive and maybe pop up something from a risk assessment view that might happen once every other week or so or maybe every seven to ten days again, that's quite owners and it's a lot to ask but if you have an automated means by which you can get there great, but a lot of what we're talking about actually does take quite a bit of effort and there is a journey involved when it comes to to getting to that notion of simplifying Risk, it takes a lot of input. Yes, not an on/off process.
So that's a journey to get there well, too and you're talking about doing it on a monthly or somewhat in regular Cadence like that. And those Trends are just as important as the details right? It's directionally where things going and are we matching to that curve or there's a flattening out or we need to invest more and that's part of that decision-making point in your education not on your cells, but your fellow Executives on you know, where where things are moving and what we need to do to either get ahead of the puck or you know catch up and yeah absolutely even monthly is actually if you think about it's quite ownerous, you know, in terms of oh, yeah project to implement a cyber control and that may take three to five months and so your risk analysis in terms of the impact of that control that you're implementing over five to six months hasn't really deprecated much within the last month, right?
So you have to kind of consider those Trade Winds if you will and there's time Horizons in terms of the maturity model of the organization and the program You know when I when we're doing programming or conversations around talking with csos, we're always talking about the people who are kind of moving into those roles as well. Right? It's it's a journey to move into that that senior level kind of role in the some big differences in playing that role.
What do you think some of the common mistakes or learnings that everybody we could accelerate our learning by sharing some of those things that people might do around reporting risk, that'll help them kind of hit find that sweet spot. Yeah, you know, I I think looking at risk in terms of you know, it's quantification is one that requires a focused effort, right the downsides of of this is that you don't want to do it in a Half Baked manner, you know for a see so Integrity is everything right and being stewards of the organization in terms of governing and managing risk. It's critical that we measure Thrice before cutting once if you will so the last thing I would want to do is get in front of Elt members CEO CFO or a board member and depict risk in an improper manner or an immature or Half Baked manner, right?
Well, they say figures line Liars figure, right? So you have to be basically look at it from all sides ensure that what you're putting out there and demonstrating an illustrating in terms of the risk posture is sound right and this is all directional correctness again, right? It's not about Precision.
It's about accuracy. So as long as you can get accurate, you don't have to hit the bullseye specifically here, right? But you want to show at least the region so as an example, I don't necessarily need to know that a data breach is going to cost me 12 million 342,560.
I need to know if a data breach is going to have an impact in the organization of one to five million five to ten million 10 to 20 million. So there's Windows of accuracy that you want to get to as a result of doing these informed measurements. And I think that the fall down parts are if you make mistakes and you fall into a window that might be greater or worse less right than what is anticipated that can put you in some hot water.
The question for you, which are what's your experience around? I know businesses even technical organizations always think about benchmarks. Right?
Are we investing compared to others the same amount is compared to others in the insurance industry or financial services or whatever are those benchmarks? First of all, is that information attainable? And if it is is that something that still useful or our business is just unique enough that that's a data point but don't rely solely on benchmarks or primarily on them.
What's your experience? Yeah. I think there's Credence to both sides.
Right? So benchmarks are helpful from an industry perspective to give a gauge and boards and El tease love benchmarks, right they love them. And so they're always gonna look for that.
If you're in the insurance sector, they're gonna want to have a benchmark of the insurance industry and how we are in terms of maturity. But by the same token when you hear about a breach that has happened through the Wall Street Journal or New York Times, whatever it may be and you're saying oh, you know company X got Breeze how Be doing the reality is I don't know how company X's house was in order. I don't know what kind of video cameras they had.
What kind of monitoring for security they had what kind of guards and dogs and Gates and all the good stuff and locks. I know what we have right and I can speak to what where we are at and that's something that I would consider from. That is they look while I'm not intimately aware of where they're at in their maturity model.
Here's where we are within ours. So from a benchmarking perspective if there's a prescription at a level to say look industry wise for insurance. You should have Thou shalt have this this and this and from a maturity for framework of one to five.
75 on these then yes, that could be helpful at a macro level to kind of show where you are from a maturity perspective. So I think that that's that's one. It's pretty common.
I know I've had mappings back to to models like that as well. But by the same token there's other Frameworks out there that I believe might give not so much insight and Clarity into the actual cyber res. So for me when I go in front of leaders and Leadership to be able to show look we've done penetration testing for ransomware, right we've done specific threat hunting for this type of malware, and this is how we fared as a result of it.
You could still be pretty high from a benchmarking perspective, but fall down when it comes to a real world threat hunting exercise, so I think both of those have to be married together if you will that goes into the response too and also being prepared preparedness for that, and this isn't always fit well into a benchmark it's over score if you will, that's right. Well, this has been fantastic for us. I appreciate you joining us.
Today was Rashid with VMware Fields he's so hope we come back again and love to explore some other topics with you. Thank you Mitch. It was great to be here.
Thanks for having me. Really appreciate the conversation you bet. Thanks to you.
Thank you.