Disclosure or Consequences – Techstrong Research Review EP 26
In this week’s Techstrong Research Review, Mitch and Mike discuss the Wells Notice served to SolarWinds‘ CISO and CFO and the longer-term ramifications for breach disclosure. To be clear, there is limited information, and speculation abounds, but anyone in a leadership position must now make sure they have proper disclosure and reporting processes in place.
Transcript
Hey everybody, Mike Rothman here, general manager of Textron Research for another episode of the Textron Research Review. I'm joined by my typical partner in crime, Mitch Ashley. Mitch, how are you?
What's going on? Good, good to be here. I'm not traveling this week.
Yay. I'm not traveling this week. That's right.
We are heading into a holiday weekend, so by the time you see this, we will already be past the holiday, but we are recording right before the holidays. So as we like to say, it is the last shopping day of the quarter. So buy whatever it is you're supposed to buy out there and, and make, uh, make some reps happy and so that they can afford their car payments and their mortgage payments and, uh, all sorts of, of things like that.
Um, but getting to our kind of knitting, right. You know, at least my knitting, right. You know, back into the security world, you know, since I've been with Techstrong, I've had to open my aperture a little bit to this DevOps stuff and cloud native infrastructure and, and ai, although everybody's had to open up their aperture ai, uh, on that front.
But, but this, this week I really want to talk, uh, about, you know, CSO level issues, right? Chief information security offer is officer issues, because I think we all kind of felt the reverberations when SolarWinds denounced that two of their, at least two of their executives, uh, were served with Wells notices. Uh, and that wells notice is when the s e C notifies, uh, an individual that they are under investigation for possible criminal uh, issues, right?
Criminal indictments and the like. And again, I'm not a lawyer, so I don't know the exact terminology. Uh, but suffice it to say it is not a great thing when you get served with a Wells notice.
And it turns out the CISO was one of the individuals served with the Wells notice, and he actually wasn't the CISO at the time, but he was a, a major player in the security team for SolarWinds when the supply chain attack hit, which of course reverberated, and that was about two years ago now, um, really reverberated and forced everybody to start thinking about what their software supply chains look like resulted in the requirements for SBOs. But I don't even want to talk about that. Right?
What I want to talk about is, you know, really understanding disclosure and consequence, right? You, you know, there's the expectation that you'll disclose any kinds of issues that happen, uh, in a timely fashion. I think it's within 28 or, you know, 24, 48 hours or, or something along those lines.
And SolarWinds did that, right? They disclosed that they had an issue within the, the, the, the appropriate timeframe. So you start speculating, right?
And that's all this is at this point. It's speculation about why they would be found criminally culpable, uh, in some type of, uh, you know, issue relating to that disclosure. So, but even besides what they ended up doing, what does that mean for CISO, right?
Makes you, you know, you spend a lot of time, you know, you do CISO talk, you know, you're kind of immersed as, as much as I am in, uh, this kind of space. I mean, where, where, where's your head in terms of, you know, the impact to CISO of, you know, potential legal liability for, for what you think is doing the job. Yeah.
I've been, I've been through a couple breaches as a C I O when we didn't have a ciso, so kind became the defacto all of a sudden ciso. Um, yeah, it, it, it's, it's, we don't, what's curious is we don't really know why, to your point, was it something in the process and procedure of how things were done there or the response was done there? Or was it in the disclosure?
And, and to your point, you think the suspicions about the disclosure, interestingly enough, it's the CISO and the C F O were the two executives that were named. And there was also a Wells notice, I think a couple months ago, or last year, uh, to the company to, so the wind. So this is the second notice, but this time to them individually, what I've read about is the consequences.
Cuz it's some, they have lingo for it, but it's civil or criminal or whatever. But there, there's of course monetary fines. There can also be, you can't hold a, uh, an executive position or board member position at a public company, blah, blah, blah, blah.
So there, there are career consequences, not as well as potential monetary. So I, I think it's really important, whatever the S C C does is just to be really clear and why now we'll see, you know, now usually things aren't very clear coming outta the government because the game of security is we don't all know all the right things to do. And even if we do, we can't do 'em.
So you follow frameworks, you know, you follow this framework for the n you follow these guidelines for disclosure. And a lot of audit auditing is all about, not, not necessarily just what are the things you are gonna do and what Kate's circumstances, but do you follow it? And you know, it's that getting third party validation.
So curious to see, of course this is Russian actor too, that that's a whole nother level of we're gonna expect every company to, uh, be able to fort uh, Russian actor getting into your DevOps pipeline. Tough, Right? So there's, there's, there's nation state stuff and obviously because the federal government was so impacted by the SolarWinds issue, cuz so many agencies used the Orion, you know, network monitoring technology that was compromised.
But again, you know, to your point, Mitch, about, you know, communicating and then being consistent about that kind of enforcement, again, if there's bad behavior, and, and as you always know, it's, it's typically not the issue or the, the initial action. It's the, you know, kind of explanation, the disclosure, the coverup, the obstruction that tends to result in some of the more specific criminal, uh, types of, of, uh, uh, prosecutions that, that are out there. Um, so again, I just think that as a ciso, we, we just need some guidance in terms of y you know, we know what we should be doing from a disclosure timeframe.
Is it y you know, is that enough? And are there things that really haven't been disclosed, uh, about what happened with SolarWinds that y you know, again, would be, you know, kind of the, uh, the, the issue here and, and we don't know, right? And, and you know, you've got certainly one group, uh, certainly a fairly sizable number of folks that, you know, play chicken little, we are security folks after all right?
Our job is to figure out how we're gonna get killed every day. So this is just another thing on the list, right? Oh, federal action.
Uh, You, you, threat vector, attack vector, you Threat. That's right. No attack vector, um, uh, on, on that front.
But, you know, I mean, I think that there are folks that are justifiably concerned that y you know, this makes the CISO job a lot less interesting. But I also remember when Sarbanes Oxley first hit you, you know, again, 15, 17 years ago, however long that was, and everybody's like, oh, nobody's gonna wanna be a C E O, right? Nobody's gonna want to be a C F O if they have to, you know, sign an attestation to the, uh, you know, to the reliability of the, you know, kind of results that are, that are published, uh, and posted.
And, and guess what? I don't think anybody, you know, that's gotten a call from the board saying, Hey, we want you to step up. Said, well, I'm really worried about Sarbanes Oxley, so I'm not gonna do that.
Thanks, but I'm, I'm just gonna stay right where I am. Right. Violations Are pretty egregious.
It's not a mistake. And, you know, accounting, Right? Well, right.
So, and, and, and I think, you know, that's a again, the point, which is when given proper guidance, right, when given, you know, constructs for what we should be doing, doing it shouldn't be that big of a deal. Right? And, and again, if you're sitting there covering stuff up or if you're not, you know, kind of coming clean when you need to come clean, yeah.
You, you know, you've done something wrong and there should be consequences to that. Uh, What about, what about Uber and Joe Sullivan, there's a case, right? Yeah.
You're familiar with we, we've all read about that. I mean That's right. And, and he ended up with three years of probation, you know, for felony obstruction.
Um, you, you know, and, and again, I, I don't know Joe personally, um, but from what I know, you, you know, competent guy, you know, everybody said he was, he was a pretty good guy. Um, but, you know, did some stuff that, you know, potentially impacted the not potentially Right. Impacted, you know, the ability for, uh, Uber to you, you know, be truthful about, you know, kind of what happened, uh, during the breach, right?
And that's a problem. And, and, and that's an issue. And that is something that is not within the boundaries of acceptable behavior for, um, CISO.
Right? So a again, I mean, I think that what we are, we're constantly, and, and this again for somebody who's been doing this for 30 years, right? Y y you know, for 20 of them and lemme let's say 15 to 17, you know, we all sat in a room and bitched, you know, with each other about the fact that nobody gives a s**t about what it is that we do.
Right? Nobody cares. And no, we can't get visibility and no, the board doesn't care.
And ah, you know, they don't take us seriously and well, guess what, folks, we're in the room now and, and when you do bad stuff, you're in the room. That means you're the one that's gonna be held culpable. You know, you can look around and go, oh, oh, oh crap, that's me.
Yeah. Right. You know, so it's one of these things where be careful what you wish for cuz we've been trying to become, you know, more high profile in the organization, you know, get, uh, a bigger ability to sit at the table.
Well, we're at the table now, and, and that comes with, you know, the positives. But it is a double-edged sword. And if you don't do the right stuff, it is, you know, again, there's just a, a, a much higher bar that, that we're expected to, uh, uphold.
Yeah, I think it, it just goes back to now we, instead of just the CISO trying to struggle of how do I get others to be involved in this, it's, you do need to run kind of red flag scenario testing, right? Of your process and procedures, of course, having that as well and just so when it's not right, we've talked how many times it's not if it's when it will happen. Yeah.
Right? And some point you might have a serious one. I mean, hopefully not as much as serious, uh, as solar winds, but could happen and you're gonna have to respond to it.
And you don't want to that to be the first time you've run the, the lets down and out to the end zone and see what happens. You know, we, we want to practice that, you know, so when we do run it, you know, we have better chance of success. I'm curious your reaction to this, cuz in my reading about it, you, you check out sort of the, I used to call 'em the chat rooms, but now the Reddits of the world and all these places and the responses people have with all due respect to them are like, yes, nothing's ever gonna be fixed until we can pierce the corporate veil and hold companies responsible and, you know, pull their charters.
And I'm just like, God, people, what are you, you know? Well, you know, you're, you always had What you're talking about, first of all, you corporate mail, Right? I mean, you, you know, you, you've always got the very vociferous, you know, significant minority of folks that would opt for anarchy, right?
Yeah. Until they get anarchy and they're like, well, come help me. But, You know, so I I, you know, there, there are always gonna be those folks that are on the, on the polar sides of you, you know, just extremists, uh, on that from piercing the corporate veil.
Now again, a lot of corporations practice bad behavior. You, you know, a lot of folks do the wrong stuff in order to enrich themselves and, and there's no question about that, but to treat this as a systemic thing, I don't think so. Right?
And, and I think, you know, kind of the s e c kind of stepping up and saying, you know, we are going to be much more aggressive about looking for this kind of bad behavior given the high profile nature of, um, cybersecurity issues, given the fact that it is a lot of private data that tends to be stolen in these specific situations that puts, uh, other consumers at risk, uh, you know, for identity theft and, and things like that. I don't think over time these are bad things, right? I do think that the government can be a little bit clunky in terms of how these things get rolled out.
I do think, uh, there are a, a little bit, um, you know, ob obscure or obfuscating, you know, kind of what the real issues are. Obtuse Of obtuse, right? Uh, um, you know, under the auspices of, you know, this is an ongoing investigation and we can't really talk about, you know, what's happening.
Um, so we are all in the dark until we're not. Right? And, and also understand that a lot of the legal constructs tend to be years behind where the technology is, right?
Well, That's what a lot of these notices are typically about Ponzi schemes, right? And corruption and, you know, heading down a RICO path or whatever, you know, something criminally. But in regard to federal laws, so that's what was so curious about this.
So what is it, what are you saying? Yeah, we Don't know. We don't know.
But, but you know, as security folks will do, we're gonna talk about the roof fall in here, right? And we're gonna, you know, we're gonna put our chicken little suits on and, and, and go talk about how nobody's gonna become a CSO anymore. Uh, and again, I don't think that's the case.
I think that I've seen a whole bunch of people quitting. No. And, and I, I think the folks, you know, again, we, what we need is guidance and, and always, always, always, always talk more, talk sooner about what happened, right?
And I know the legal folks don't like that because it sets you up for, you know, class action stuff. But here's your choice. Fight you with your GC about, you know, kind of potentially you, you know, putting the corporation up for liability because you did the wrong thing or suffer criminal liability.
Mm-hmm. Right? Criminal culpability y you know, for covering stuff up and, and hiding information.
Hey folks, choice is yours. You get to make that choice every day. And I've dealt with enough lawyers who have been like, no, no, we can't say that, that puts the company at risk.
Well, guess what I'm gonna think about, number one, because I know you are not thinking about number one, I am not your number one. Mm-hmm. Right?
I gotta be my number one. And that means, uh, again, you know, sometimes they're whistleblower types of, uh, protection in order to do that. But man, do not go down with the ship cuz the corporation will sell your ass up the river every day of the week.
And that's just a fact. There, there is also the fear of whatever the ripple effects of this could be could decrease security. And I'm not sure all the threads of that logic of why that is.
Maybe it's cuz good people leave, maybe it's because people pull back and, and, uh, don't disclose as much as they should kind. I'm not sure what exactly people are saying about this, why this would, but I, I guess it depends on what the ruling is. We're kind of going down the, you know, how many, which chicken little do you want to talk about?
That's right. I'm not sure. Well, we dunno.
We, we dunno. But, but, but again, I mean, and, and, and I think as, as we wanna, you know, kind of start wrapping up on this part, we don't know what we don't know yet. Y you know, there are certainly, there's certainly a scenario where this is pretty concerning, you know, to security practitioners.
Um, but overall I think that, you know, kind of having more of a spotlight and more specific guidance on disclosure practices is not going to be a bad thing. And again, I'll just make the point again, disclose early, disclose fully, and understand that you are, it's okay if you change the story once you learn more, right? Mm-hmm.
You know, you just say, listen, this is what happened. We think this is the issue. As you dig into it, as you forensic and do all that, you will learn more.
And that's to be expected, right? But you know, again, the idea, it, it's been made very clear, right? Very clear that if you obstruct in any way, if you are not telling, you know, kind of the truth as you know it at that given time, and man, there's just so much paper trail now, you know, a digital exhaust, uh, that that's out there.
You, you're not gonna be able to hide the stuff. You're just not gonna be able to hide it. So man, just come clean, right?
You, you know, you'll get another gig, you'll do that. It's just, just come clean because I'll tell you, having to deal with criminal lawyers and fighting the government, man, that will make your ass old real fast. Hey, speaking of come clean, we, you and I are talking at cloud native, uh, now event on, what is it?
June, July 11th. Sorry, it's almost July. Yeah, July 11th.
And we're doing an update on our predictions from 2023. Yeah. Hamilton, we're Cloud native Specifically.
We're cloud native. Yes. Don't get Into the security stuff, but the cloud native predictions.
Yes, that's Right. We're kind of checking in how we doing, where we off course, do we need to course correct and what, what didn't we expect? So that's happening.
I'm excited for that and, and a lot of other great content. And then also I wanted to mention on August 16th we're doing, um, data ops day, which is of course focused on data. And given the role of security and privacy and protection of data, there's lots of opportunities if folks wanna speak, I think we're still open for, uh, call for speakers.
That's right. Uh, sponsors, things like that. com and register to go or, you know, submit to speak or sponsorships, all that good kind of stuff.
But a lot of good content over the summer. You know, we're not backing off. We're, we're, we're keep keeping the pedal of the metal.
That's right. Hit the gas, Hit the gas over the summer. Right.
And, and I don't know, you, you know, actually Mitch, you're, you're at most at, at risk, right? Cuz it's actually beautiful in Colorado, you know, over the summer, uh, in Atlanta it's kind of hot as, as all get out, right? And down in Boca, I mean it's like 105, it'll be 105 this weekend, y you know, in Boca.
So that's not too interesting, uh, on that front. So it's Gotta stop raining. We're gonna sit in the, we're just gonna work.
Yeah. We had so much rain in Colorado, so it's not your typical buddy. Yeah, it's still beautiful to a toy.
You say, I get what you mean. And it's not, you know. Yes.
Sweltering can't go outside hot For sure. Exactly. So, so I'm gonna stay inside in the AC and just work because I work in no play is, you know, that's Mike's existence.
That's what Mike does. I hear, I hear it. I hear all playing on your little violin.
I know. I think, I think it's even smaller, but yes. Alright, with that another episode of the Techstrong Research Review.
Mitch Ashley, thank you as always for being my partner in crime on this. Of course. We will be back next, uh, maybe.
Yeah, I guess we'll we will record next week after the, after the holidays. We'll record next week. Uh, we'll be back right with you for the next interesting topic that we'll cover on Techstrong Research Review.
See y'all then. Thank for joining us.





