Navigating the Journey of Cybersecurity Risk Management with Rich Seiersen at QSC24
Transcript
This is Textron tv. Hi everyone. We're back here in San Diego for continuing coverage of of QSC, quality Security Conference 24.
Um, I'm really happy to introduce you to our next guest. His name is Rich Sson. Rich.
Rich is the, uh, chief Risk Technology Officer. CRTO. Yes.
Got it. Hey, rich, first of all, welcome to Techstrong tv. It's great to have you on here.
Um, you know, you have a bit of an interesting background. You, your history with Qualis goes back almost 20 years. That's right.
But you haven't been here in 20 years. That's also right. Fill us in, give us, give us a little bit of the rich story.
So, yeah, 20 2004, I was here at Qualys, um, as an engineer doing security things. And I got an opportunity actually through Qualys to go to Kaiser Permanente. And, um, that led me to this, uh, role.
I called, uh, serial recovering ciso. So I ended up going from Kaiser to GE to Twilio and others. Um, along the way I became an author.
So I co-authored a book called How to Measure Anything in Cybersecurity Risk, despite the long gangly title and P Green cover. It's the book's done. Great.
So it's the, it's the, uh, main curriculum for the Department of Defense, really c still program outta Carnegie Mellon. It's graduate school curriculum in Harvard, brown, bunch of couple hundred other universities. It's got the unique distinction of being the only security book that has been required reading for the Society of Actuaries Exam.
Really? So the Actuaries Society, they're kind Crazy. Fantastic.
They're kind of crazy people. So it's the Book, I imagine it's gotta be a multiple editions at this point. Second Edition.
Second Edition. Fantastic. Available on Amazon, Barnes Noble.
All your favorite book vendors. That's Right. It's, it's the first of two books I've written.
The second one is far less popular. Well, this is your chance to plug it. Oh, well, If you are interested in applying, uh, you know, Bayesian Mathematics to Security Metrics, if you're the one person who wants to do that, this is the book for you.
We got an army of one on that one. What's the name of the book? Uh, the Metrics Manifesto.
Confronting Security with Data. Actually, it's done pretty well. Not as great as the Green Book, but I'm happy to have What Color is this one?
This one's Red. The one with red More popular than P Green. Yeah.
Yeah. Maybe a shorter title. Yeah, maybe.
Well, it's the Metrics Manifesto subtitle, confronting Security with Data. Love it. So you left in 2006?
Six, yeah. Yeah. When Didd You come back?
Uh, about nine months ago. Oh, really? So relatively recently.
And what brought you back? Well, uh, ed, he, he, uh, he was stalking me. Really?
No, not really. Uh, he, you know, he reached out and said, Hey, you know, um, I have this vision for the future for Qualys. I'd like to meet and talk to you about that.
Um, we met at a Starbucks close to his home and hung out and he shared with me the vision, which was, which is live now today. And it was, uh, pretty compelling. Um, and he wanted someone who had, you know, had been there, done that as a cso, right?
Mm-Hmm. Um, but also had a strong, you know, interest on risk management, particularly from a quantification perspective. Um, I seemed he decided that was me and Uhhuh said, Hey, why don't you come and not only help us with the strategy, but really become a, a voice to the industry on this topic.
And so, yeah. That's, And here you are. Here I Am.
We're gonna dive into this, into the whole risk thing in one second. Sure. Before we drive.
One other first question. Sure. Qua circa 2006 to qua circa 2024.
Obviously Philippe is not here. Yeah. And, and Philippe breathed life into this company Absolutely.
For many years back then. Right? Right.
But beyond that, differences, similarities, what's changed? Not changed. You know, I, I don't know if this is a fair analogy, but it's like, you know, pre Satya, Microsoft, here's, here's a hardcore engineer takes over as the CEO, uh, that's summed as well.
I mean, hardcore engineer is taking over as CEO now. He rose to the ranks. Um, but what we got 22, 23 products when I was there.
There was like one product. It was a great product. It was great.
Mm-Hmm. But, uh, you know, 200 people back then sh shy of, I think now we're at like 2000. So it's just vastly different.
But, uh, you know, in what three years the, the revenue is and doubled. I mean, it's just really increased. And I think that's a testament to really leaning into, you know, bringing, you know, serious kinda an engineering ethos and vision to the company, which I think is critical.
But also, you know, summed brings a business savvy, hence the, you know, the vision of bringing in risk from a, both a, not just from a, you know, a technical perspective, but from a financial perspective as well. So I think it's a vastly different company, but I loved Qualys back then and I love it more now. Absolutely.
So I, as we were talking off, look, I've been friends with the folks at Qualys for going on 25 years now. 24 years, something like that. And, uh, it is, it's an interesting, uh, evolution Yeah.
That we've seen here. The theme for this QSC is certainly risk and, and, and somewhat rich, like you, I've been in security a long time. 0 first came out and we were blogging risk does not equal equals sign with the strike through IT security.
Right? Right. And a lot of people had a hard time with that, but it's true.
Risk doesn't equal security. Risk is risk security. Cybersecurity.
Cybersecurity. They are connected. They are, you know, tangential and one helps the other or, or not, but it's not the same for too many of us.
Risk was Good. Here's my take on it. Okay.
You can call me out and think if I'm wrong. Security, when I first got involved in security, had a image problem in that it wasn't really part of it. Right.
It was kind of bound up with risk non-IT. Right. And we fought like heck to make security.
The whole DevOps and DevSecOps thing that I, I've helped with was to bring security into mainstream it. And we've done a decent job of that. Security is part of it, but risk didn't come along.
Risk stayed over there. Not part of it, necessarily. CFO risk management, you know, that traditional kind of pipeline and that created a wider gulf between security and risk.
They certainly don't, one doesn't equal the other, but they weren't even in some ways talking to each other. True. Now I see a wrap approach, man.
A, a, a, trying to bring security and risk. Again, they're not necessarily equal. They're never gonna be equal, but together closer, if you will.
Right? Is that how you see it? Or how would, what would your critique be there?
Well, Security is not a noun. Security is a verb. You secure things, you secure all the things you're going to, you know, it's an activity.
But what is risk? You know, risk is a state of uncertainty where some of the possibilities could lead to loss catastrophe or some other undesirable outcome, right? So they're not, I mean, they're not, I don't think they're things to be compared at all.
Right? They're, you know, again, security is a thing that you do. And risk is, again, a state of uncertainty and they work together.
So I don't think they're, um, exclusive. I actually think security is an activity that's a subset of a risk function. Okay.
Um, right. So I, that's my, my thoughts on it. Uh, what, so then what is risk management?
Right? So risk management is where you're going to mitigate or remediate the most plausible of those losses that impact business objectives, right? So that's where the security activity comes in, mitigation or mediation, particularly for those digi digi digital plausible losses.
So again, what is risk? Risk is a state of uncertainty where some of the possibilities could lead to loss catastrophe or some other negative outcome. What's risk management?
Risk management is the remediation or mitigation of the most plausible, plausible of those losses that impact business objectives, right? So that's where security fits in. So I think security ends up being a kind of a subset of that.
Um, you know, I'm gonna be honest, it's been 10 years since I've worked for a company that had a CIO. Really? Yeah.
Cloud native companies don't really, I mean, they might have a CIO there, they're somewhere, it's a ct. They're CTO driven organizations. More And more we, we see, you know, we, we started a site, it's called CXO, uh, digital CXO.
Yeah. Because we found the same thing. Yeah.
In, in not just cloud native, but cloud like modern tech companies. Yeah. Or heavy tech reliant companies.
You're right. The CTO often wears two hats too. He's the CPO sometimes too.
Chief Product officer. Yep. Yep.
Absolutely. Could be a sheik. Yeah.
But, but the chief technology can be the chief te, uh, product officer. But certainly the CTO drives what used to be the CIO. And we've seen another interesting thing, the cso, the, the chief Security Information Security officer takes over some of that CIO role Too, because the, the, the scope of the CIO role has really shrunk significantly.
So like, they look at the cso, they go, you've got a pulse, you got that I word here, you know, here, you're not stuck of this, of this function. CTO has all, all the budget. Um, so the, then the question is, you know, should security be a subset as a role?
Should it be a subset of CTO? I don't know. Listen, the, the function is to identify and try to reduce plausible future loss.
I mean, that's really the idea. And that gets into the function of, again, the risk operations center. What it, what it the risk operations center is really just almost like an epiphany of the obvious is that, you know, average csaw, I'm gonna have 70 plus solutions, you know, for a fortune level, ciso, A fortune, I think it's over a hundred Now.
No, over a hundred. You're gonna have a lot of solutions. How do I bring all that to, again, telemetry is not measurement.
How do I bring all that telemetry together in such a way where I can measure what matters most and then hopefully take automated low impact when I say low impact disruption, low disruption actions that eliminate risk, right? That's, that's the hypothesis behind the risk operations center. It's just, you gotta say epiphany the obvious.
It makes you hear it. You go like, okay, that makes sense, right? Yep.
And so that's what we're trying to do. And so where the CISO fits in in terms of responsibilities, I, it's more about what's the function? What are you trying to get done?
How do you do it cap in a capital and operationally efficient manner? Where does the rock fit in next to the sock? So I think the, Is it like this or is it like that?
So the risk operations center, and remember I said risk security is kind of a subset of that. Um, I don't think you can sock well if you don't understand what your value at risk is and what matters most. So if you think about a, a, so like a, so, you know, angry packets sopping against a firewall, right?
You, you're getting all this noise. You have your, uh, you know, your first line, which may be with your SSBs going, oh, light blinky, red scary call. Second line person.
They're look, and then they're gonna triage, throw away 99% of that, then have something that that's, oh, this is very difficult. It's real. Go to the third line, right?
The SMEs. So you have this whole process. Our view is, well, maybe, you know, if you understood the context, what's the value at risk from an asset perspective, right?
You can de-dupe that signal, then deliver to the SOC what matters most, right? So the so becomes a subset of this, uh, broader function. Um, that's kind of my, That's your take on it.
Oh, Yeah. Yeah. I think so.
I think it's as good as anything else I've heard today. So that's a good thing. Um, what about QSC?
This is, this is your first one since you're back. Well, the first Americas One. Yeah.
I was at the, uh, one in the UK before. Right. I think it's fantastic.
I think people are really leaning in on the risk topic. You know, I was at the, uh, product advisory, uh, board, and, uh, you know, I was, I was watching these CISOs and sub CISOs all working while other people are talking. And I, it's not all about me, but I got up there and started talking about risk, and They put it down every single One.
Yeah. Well, they knew you wrote the P Green book. No, I, well, yes, but I think the reality is we're talking about a subject that really matters to them.
They are concerned about risk. They want to be able to speak the language that the money people speak, they want to be able to drive decisions, right? They, you know, I imagine this like, here's, here you are, you're in your board meeting, you know, CFO, GC investors, whatnot, and they look out the glass wall and they see this person, you know, pushing your room.
And they say, well, who's, who's that guy? That's the ciso. Should we invite him in?
No, no, don't do that. You know, He's just, and We don't understand a word That person saying, right? He's gonna it and bites.
So how do we, you know, but I think that needs to change, right? They need to be able to speak the language of business. Right?
Well, That's what good CISOs do, right? Otherwise, they're just security architects who do their architecture and get the hell out, right? Right.
They have a lifespan of nine to 18 months, basically. Yep. Yep.
Um, but is there a place where chief risk officer or Chief Risk Technology Officer, supplants, the CISO at the board level, or the CISO maybe is not a ciso, not a 'cause that's always been, you know, CISOs always have a, uh, a Rodney Dangerfield issue. They get no respect. Right.
Right. Right. They don't really earn their seat at the table.
Right. Maybe the future is they don't have a seat at that table. The chief risk, the CRTO does, I dunno about CRTO, but Chief Risk Officer, what's a Chief Risk Officer do?
I mean, uh, since we talked about insurance earlier today, they, you know, typically they're gonna be one who's buying your tech know subset cyber, your DNO property casualty, all that. But that's just representative of the things that they're, they're, they're supposed to ensure that the business is sustainable, right. Financially and otherwise.
Um, they don't have a, you know, they don't have a digital expertise. Right. That's not their domain.
I mean, what the CTO does is about ensuring that they're, you know, that you're exposing and you're exposing more value to more people through more channels at higher velocities to increase revenue. So CTO is gonna be producing product and platforms to increase revenue. You could say, well, that's risk too.
Does that end up CRO end up replacing that person? No, not at all. So again, I don't think the CRO supplants, could I see a CSO report reporting A CRO?
Sure they do. Can they report to the CTO? Sure, they do.
Could they report to the gc? They do. Could they report to CEO?
They do, but I don't think the roles are supplanted. That's, that's my opinion. I'll go with that too.
It's better than anything else I've heard today. Yeah. Hey, we're about outta time, man.
I want to thank you for coming. Likewise. I know you're busy as heck here.
Welcome back to qualis. Thank you. Congratulations.
It's gonna be an exciting ride, I think. I hope so. So far, so good.
All righty. All right. Hey, we're taking a break.
We're live in San Diego today. We'll be back in just a moment with our next guest. We have some other content to play for you.
Stay with us. We still have, oh, I don't know, five or six more guests to come today. This is Techstrong tv.