Exploring Risk Management with Scott Frederick at QSC24
Scott Fredericks from Ameritas Life Insurance shares his insights on the evolving relationship between security and risk management. He discusses collaboration between security and IT teams, resource allocation challenges, and the role of cyber insurance in quantifying risk. Community engagement is highlighted as essential for developing future security solutions
Transcript
This is techron tv. Hey everyone. Welcome back.
We're here at day two of Qua Security Conference, QSC. You know, if you didn't get it from yesterday, the, the main theme of this year's QSC Americas is risk. How to mitigate risk, how to measure risk, how to defend and lower your risk.
Our next, uh, guest is Scott Fredericks from America Life Insurance Emeritus. Yeah. Emeritus Life Insurance Company.
com. com. It's like a spelling bee.
Yeah. Alright, Scott, first of all, thanks for coming on board here with, uh, with us at Tech Drunk tv. As I said, we've been talking about risk and measuring risk and quantifying risk, and, um, what brings you here today?
Well, it, my very first QSC, um, we've been invested in, uh, the partnership with Qualys since 2016, and none of, nobody from my organization has ever been to one of these. We've watched them virtually and, and, uh, my CISO's sitting right behind you and he said, we'll be back. So, um, but it really was about understanding the platform, understanding the community, um, and bouncing ideas.
Um, I was lucky enough to be selected to give a, a keynote address. Um, so I just finished up from that. Um, and that was all about how we're managing risk, uh, using the true risk score, um, and how we're just leveraging everything we can outta Quas.
You. I didn't ask you, what's your position with ameritus? I am a director of enterprise security.
Okay. Uh, and I manage the vulnerability management team, so, Excellent. So I, I've been in security.
I wasn't always on this side of the camera. I've been in security about 30 years. Mm-Hmm.
And, and knowing those 30 years, so when I first started, security and risk were closely adjoin. Right, right. And I, I helped found a company that was a, that had a vulnerability management solution, scanner and all that workflow over the years, risk and security sort of parted ways, a little bit.
Security moved closer to it. Vulnerability management became, you know, kinda like just a tailor making a suit. You did your scans, here are your, yep.
Heres the findings, go fix 'em. Right. Right here it throw it over the wall.
And it really almost became divorced from risk. We did vulnerability remediation, because that's what we do in security. Right, right, right.
But now, certainly at qualis, at QSA this year, we're A QSC this year we're seeing Yeah. Security and risk coming back together. Yep.
Um, how do you guys see it in terms of tying risk to, you know, vulnerability scanning and remediation? So, so we, the, the enterprise security team, or the info, uh, sec as they sometimes call it, was part of it until 2019. In 2019, the, the whole InfoSec or enterprise security team went under the risk compliance.
Really? Yeah. So we are, we, we, we share a common senior vice president, but we're completely separate.
We've got a ciso, we've got, uh, senior VP of risk and compliance, and then it has their own organization. So, you know, we really are more partners now than we are any kind of reporting structure. So the dynamics of this three-way, you know Yeah.
It it gets a little dicey there. Right. Yeah.
So how, how, and no one's listening, but a couple of thousand people out here, but how would you say that's affected the relationship between the security team and the IT team? It has improved. It actually, honestly.
Really? Yeah. Good.
The, uh, I, I think the, there was always a lot of headbutting between the security team and the delivery teams, so the server support team, the infrastructure teams. Um, and it was because there was, you know, there a finite bucket of, of money, there was a finite bucket of resources. They felt like you were taking theirs, we were taking, you felt they were taking yours.
They're trying to deliver, you know, they're trying to deliver business enhancements and changes to the website, and we're trying to protect it. This is not bottom line. Yep.
No. So it, I think it's vastly improved now. Okay.
We really do have a partnership. We have, um, we're, I think we're doing biweekly, uh, I call 'em it stakeholder meetings. So my team is meeting with the key representatives from the infrastructure, the delivery teams as I call them.
Yep. Uh, the people responsible for the mitigation and the remediation of vulnerabilities. So, So I mean, there's also been changes on the IT side of the house, right.
We've had the rise of DevOps Mm-Hmm. DevOps teams. We've had SREs mm-hmm.
We've had platform engineering. com and Security Boulevard and Cloud native. So we, we see all of these trends, if you will, and frameworks and, you know, ways of doing it.
And look, it brings more stakeholders to the table. It does. And the more you have, the more, the harder it is to find harmony, right?
Yep. Um, however, the flip side of that is you work more closely now with your chief risk officer. Mm-Hmm.
And, and the risk folks, my issue as a longtime cyber guy is I can't quantify everything to dollars and cents. Right. And no matter how good my risk modeling is, when, when, when stuff happens, stuff happens.
It does. And it may not even be because I did anything wrong. Right.
It's just stuff happens. It does. Uh, how, how do you guys kind of, you know, dance around that pinhead?
Well, I mean, it's a classic thing, right? So, you know, what we've, what we've got is we've got, within the IT organization, we have the enterprise architecture team, and they manage the application portfolio for us, for instance. So right within that application portfolio, there's the sense for, uh, what's the technical debt associated with the particular application, what is the, uh, financial criticality of that?
Um, and it's not dollars. It's, we need to get there based on what I heard yesterday, but it, it's really just, uh, a simple number. This is very critical.
It's not very critical. And then the, we have all the assets or servers that support those business applications. So we're able to look at it from a very focused on the vulnerabilities around that server to, hey, line of business vice president, this application, which you think is super important, has got these vulnerabilities and are using these end of life softwares.
And, and so it's really that application portfolio has really been the way for us to facilitate conversation with the business areas and and our risk team. Sure. You know, one of the things we've heard here over the last two days is for the ciso, the risk officer, it's one thing for him to talk to the cyber team or the IT team, you know, about lowering risk or doing this, but at the board level and at the C level table, they do want dollars.
Yep. Right? They want to quantify down to the dollar.
Right. I've got a billion dollar line of business, I've got 20% risk, and I could mod, you know, minimize that risk, moderate that risk, mitigate the risk by 10%. Right.
So, billion dollar line of business, I, you know, mitigate it by 10%, that's a hundred million dollars I saved. Yep. Now whether you believe I saved you the a hundred, it's like when my wife tells me she saves me money when she bought stuff on sale.
Right, exactly. I hear that too. Yeah.
Um, but nevertheless, it is at least a hard number you can Right. Put your thumb on. Yeah.
Um, are you guys moving towards that? You're thinking, we, with the qualis true risk, does it help you get there? That A lot of, a lot of lights went off in my head.
Um, it sounded like a whole bunch of mousetraps. You hear the click, click, click, because there was a lot of good stuff in the, in the keynote yesterday. Mm-Hmm.
And most throughout the day. Um, one of the things that, and, and we need to, we need to move to that. Um, and I think the true risk, um, the enterprise true risk model is going to be very good.
Um, one of the ways that today we're not there, one of the ways we are able to measure and report to the board is in cyber insurance cost a premium reduction. Yeah. Um, you know, we come in here, we've got these good scores, we've got this, and the premium comes down.
It's a lot of money. Cyber insurance is a lot of money. And, And, and it's, that's very easy to quantify.
I mean, it's like our premium was gonna be here, we did this, we got it down by, There's no Right. There's no log Viewing 800 k, whatever. Yeah.
And you know what the flip side of that though is it gives the cyber, I I was interviewing the guy who spoke yesterday, Mahesh. Yep. From, uh, Mulberry, I think it's called.
Right? Yep. Yep.
Um, it gives them an awful big stick To You guys or to any of their clients to say, Hey, you want this cyber insurance, you want a better rate, better policy premium, I need you to do this, this. And all of a sudden they've carrying the big stick Right. On what you have to do from a cyber perspective.
And, and that, I, I don't know if people are realizing that yet. Right. No, I mean, the government tries to put in regulations, you know, I'm here from, I'm from the government and I'm here to help.
Right. Never. But, um, but when the cyber insurance companies tell you this, and they, and they dangle that carrot too.
The stick and the carrot, it's a 30% reduction in policy premium. Yep. Reminds me of why I got that little thing that I plug into my car to make sure I'm a safe driver, so I Exactly get better rate.
Right? Yep. Is that, I mean, that does it for you, right?
That moves the needle, That that moves the needle and it's, you know, it, it becomes there stick, but it also becomes our way of measure. Yeah. And it becomes a, a, a key risk indicator for us.
So, you know, whatever they're measuring, we can adopt and use. Um, I don't know exactly what we're using for that, but, um, I'm guessing our CISO knows 'cause he would put I'm sure. Yeah, I'm sure.
So he's always in, I mean, the important, at some level, it almost doesn't make a difference what the tool is. Right. As long as you have something that Right.
Because, and, and as long as that's stable. Right. Right.
It's like going on a scale is that scale off two pounds. All right. If it's off the same two pounds every day, what difference does it really make?
Right. It's just I'm measuring the diffs. Yep.
So, um, that, that's a great thing. So this is your first QSC. Yes, Sir.
Beyond what we spoke about. And you were lucky enough to present and congratulations. What else have you gotten out of this?
I mean, peer to peer kind of thing? Yeah, it's been, um, uh, a lot of very smart people are here, both from Qualys and from a customer basis. And it's been interesting to compare notes with other people that are managing vulnerability management teams.
Um, but like I said, the, some of the subject matter experts I've talked with, with Qualys, who have just been out of this world, I mean Yeah. No, they isn't really smart people. Yeah.
We've, we've been lucky enough to interview him too. Yeah. And I, I had dinner with a fellow last night and I was like, Hey, you know what, uh, you've got your Cs a product.
If you did this, it would make my life a lot easier. And he's like, that's a great idea. Send me an email or send me a ticket.
So we're gonna do that. And so it's just that, that, um, it's great to be Part of the community. Well, that community Yeah.
Peer group. Yeah. The Peer group and the community.
And, Uh, I'll tell you dirty little secret, we do a lot of user conferences for a lot of companies. Security, DevOps, cloud native. A lot of people think they put on a vendor, not just Qualys.
Right. Puts on these shows to kind of whine and dine you and sell your product and tell you about what they're doing. But the dirty secret is they put on these shows to hear from you about what you want.
Yep. Because what you tell them you want today is what you'll see in next year's. It goes on roadmap.
Yep. And that's, that's what makes this a double win for these vendors. Sure.
Absolutely. Right. Is hearing from people like you, so.
Yep. No, it's, it's a, it's a win-win all around. Yeah.
And you can't complain about San Diego for a location either, right? No. We're in, we're in Florida.
We're real lucky we're here. We're very lucky. Yeah.
We're, we're here. I've called my wife's. Okay.
Thank God. Everything's, we're on the southeast coast. Oh, okay.
Yeah. It could have been a lot worse. Oh sure.
Yeah. I'd rather be in San Diego. Absolutely.
Yep. So anyway, Scott, thank you for coming on. I appreciate it was a great conversation.
We're live at QSC. We're gonna be back in a moment with our next guest.