Episode 298 ·

Jason Taule - CISO at HITRUST

Today we are talking to Jason Taule, the CISO at HITRUST.  And we discuss the way a CISO should operate within the C-Suite, why we should be thinking about risk instead of security, and how to create a culture that is mindful of risk management.

All of this, right here, right now, on the Modern CTO Podcast!

Check them out at HITRUSTAlliance.net!

About Jason:

Jason Taule is a 30+ year information assurance and cybersecurity veteran who has worked in both the intelligence community and commercial sectors, first consulting to federal agencies and then serving as inside CISO and CPO both within the government and at-large systems integrators like General Dynamics and CSC.

Mr. Taule helped build the original DARPA CERT, helped develop the first computer security programs at the VA and NASA, and revised the Risk Assessment Methodology still used throughout DHHS. Mr. Taule helped author the Maryland Data Privacy Law, led a multi-million dollar global cybersecurity practice for a large international consulting firm, ran the team responsible for HIPAA complaint investigations for OCR for three years, and for the last 20 years has been a luminary in the U.S. Health IT sector helping hundreds of systems earn their accreditations and avoid compromise.

Mr. Taule currently serves as HITRUST Vice President of Standards and Chief Information Security Officer (CISO). In this capacity, he oversees the ongoing development and evolution of the HITRUST CSF security and privacy controls framework to ensure its continued relevancy and sufficiency. This includes abroad range of HITRUST risk management framework support functions such as requirements integration, control specification, and the development of standards that organizations can use to develop their own information protection and compliance programs and provide assurances to customers, trading partners, and other third parties. Additionally, Mr. Taule oversees HITRUST’s internal information assurance efforts to ensure that the organization continues to earn and keep the confidence of customers and third parties who have entrusted HITRUST with the safekeeping of their data.

Mr. Taule holds a Master of Science in Information Technology Management from Johns Hopkins University and a Bachelor of Business Administration from the College of William and Mary. Mr. Taule has earned numerous industry and professional certifications, is a graduate of the FBI Citizen’sAcademy, is member of the Homeland Security Preparation and ResponseTeam, serves on the Board of the Loyola Sellinger School of Business and theHoward County Economic Development Authority Technology Council, and isa founding member of and National Advisor to the CISO Executive Network.Mr. Taule sits on the DHHS/CMS Information Security and Privacy Workgroup, the FBI Cyber Health Work Group, the U.S. Health IT Standards Committee’s Transport and Security Workgroup and is a White House invitee to theSecurity Policy Roundtable for the President’s Precision Medicine Initiative.

About HITRUST:

Since it was founded in 2007, HITRUST has championed programs that safeguard sensitive information and manage information risk for global organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security and risk management leaders from the public and private sectors, HITRUST develops, maintains and provides broad access to its widely-adopted common risk and compliance management frameworks, related assessment and assurance methodologies.

HITRUST understands the challenges of assembling and maintaining the many and varied programs needed to manage information risk and compliance. The HITRUST Approach provides organizations a comprehensive information risk management and compliance program to provide an integrated approach that ensures all programs are aligned, maintained and comprehensive to support an organization’s information risk management and compliance objectives.

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Jason, the CISO at HITRUST, and we discuss the way a CISO should operate within the C-suite, why we should be thinking about risk instead of security, and how to create a culture that is mindful of risk management. All of this right here, right now on the Modern CTO Podcast. Here we go. This is the Modern CTO Podcast.

(Joel Beasley at 00:00:33) So you're not in Texas, but what's the energy like in Texas right now?

(Jason (CISO at HITRUST) at 00:00:38) Pun intended or the energy level?

(Joel Beasley at 00:00:42) The energy level, not the freeze, but like the space and everything that's happening.

(Jason (CISO at HITRUST) at 00:00:46) It's a great space. HITRUST is headquartered in Frisco, which is about twenty minutes north of Dallas, and a couple years ago was voted as the best place to live in America. The quality of life, the things to do, it's fantastic. Great schools. I think COVID is dampening the spirit everywhere. So much to do outside, sports activities, restaurants, culture, you name it. Well, COVID's gonna dampen that. But otherwise, it's good. We've got, I think my team, depending on who you talk to, what methodology you might call it technical debt. I think if the world didn't change and we had no more new customer requests, I think I've got more than six years of a backlog to keep us all busy in terms of job security. So our spirit at HITRUST, we feel very much, even though we're large, we feel like a skunk works. We feel like a startup. It's that kind of energy.

(Joel Beasley at 00:01:41) That sounds very attractive. Are you getting top talent coming to work for you?

(Jason (CISO at HITRUST) at 00:01:45) We are. It's an amazing group of people, and when I'm able to articulate what it is that we're doing, so there's lots of folks that have been in different parts of the cyber industry who have different pain points, we're here to help solve for those pain points. I'm not trying to plug HITRUST, but that's the biggest reason that I came here. I never realized how the career arc of the last thirty, thirty-five years that I've spent prepared me for this job that I didn't know I was preparing for. And actually, I want to take that moment before we get deeper into this to kind of give a shout out to everybody who is working in cyber. And I know that term's a little bit strange, and we'll talk more about that in a minute. But the people that do that, that help their companies manage their risk, manage their data, protect their customers' data, are literally, and I'm not just saying this because I'm in this space, but literally nothing short of heroes. Regardless of what your title, the men and women that do this have an impossible job. Right? They've gotta find and plug every single hole. The bad guys only have to find and exploit one. You're doing this in an environment that has unbelievable time pressures. The tools at best can give you near real time. It's not backward looking data. You've got to do this in a way that doesn't have an undue impact on your operations or on your customers or on your bottom line. You gotta change culture, and we know how hard that is. And the landscape that you're doing in the city is continuing to evolve. So the fact that anybody does this at all and takes this job, let alone typically does so with some passion and some good results, there's nothing short of extraordinary. So I just want to give a shout out to everybody that's in this space. And anything that I personally or the company can do to help them is what we're all about.

(Joel Beasley at 00:03:31) And you've been in this space for a long time, right?

(Jason (CISO at HITRUST) at 00:03:34) Probably generation two. The folks before me were the folks that created encryption and wrote RACF and did all of this. But those were the grandfathers of the industry. I came in just after that in the mid to late eighties. The Robert Morris worm and the Computer Security Act that happened in '86, and then the Morris worm a couple years later when this kid from Potomac, Maryland accidentally took down the Internet and woke everybody up. And you can imagine what that impact would be today. In those days, we didn't depend on it for everything like we do today. So that kind of was a wake-up call for a lot of organizations. And I went to work. I was at Booz Allen. I helped build a couple of the federal agencies' programs and went to school on what those experiences were. You know, one of the programs that we helped develop was for NASA. And if you think companies have to, everybody talks about patching computers. If you've got something that has taken twelve years to reach the edge of our solar system and it's got a flaw in it, you think you're gonna patch and reboot that thing? You're not gonna touch it for risk that it might not come back up. So every experience I had kind of sensitized me to something else that helped me, because the job of the CISO is gotta be culturally attuned to your organization. It's also all about constantly dialing it in and getting it right.

(Joel Beasley at 00:05:00) I'm curious. Those satellites out there that are not being updated or that are old, are they prone to being attacked?

(Jason (CISO at HITRUST) at 00:05:07) Not by humans. You know, at some point, maybe there's other forms of intelligence that might be attacking. No, I don't. And I think that's why it's okay that you can say, unlike something that performs a different mission with a different kind of data and has different impacts of getting it wrong. You know, if it's a medical device and somebody's health is at stake, that's very different from we don't get the pictures that we're hoping to get or we're not able to perform the research that we want.

(Joel Beasley at 00:05:36) I am curious. I don't know who I would talk to about that to see if like one country's ever tried to operate a rover, like a Mars rover of another country's. I'll look into that. But you did some security stuff, or at least you were back on the early Internet. Can you tell me about the ARPANET, about that experience, and then the phone books? Because I laughed when I heard the phone book thing.

(Jason (CISO at HITRUST) at 00:05:59) Yeah. So I have accumulated a small museum of artifacts of my own, mostly because I don't trust the devices to the dump or the recycling bin or wherever you would put them. So I guess you could smash it with a hammer and physically destroy it. So I have every cell phone, every computer, every laptop, every device I've ever had. And along with that, I've got copies of artifacts. So when I went to work in the eighties, I got a copy of the Rainbow Series, thus called because each was a different color book. And it essentially was how in the defense sector, they prescribed how you built and addressed these same questions that we're dealing with today. The internet didn't yet exist in the manner that we know it. There was an internet before the web, of course, and before the internet that, you know, when everybody gives Vice President Al Gore grief about taking credit for inventing, you know what he does. He helped with the legislation that made it available for commercial use, but its predecessor, ARPANET, there were a variety of folks that were on that network and all of those folks had their addresses published in a booklet. I have copies of other stuff. I have copies going back to the mid eighties of other documents. I don't have a copy of this one, and it just would be a great artifact because when you want to give people the perspective of the growth and our dependency on the internet, this in a sense it was an address book. It listed everyone who had an address on the internet, on ARPANET, and it listed everybody twice, actually, once by your email and then once by your company. And it was only about this thick. You know, were you to do that today? I don't even know what the calculations would be. It would be miles high, right? And it listed everybody twice. Now there's more internet addresses than there are people. So if anybody's got a copy out there, I would love to grab a hold of one. You know, send me a copy, something like it. I actually have another similar artifact. It's a map of all of the nodes of the Internet. And it's large. It was on a plotter, but maybe it was two or three feet wide by two feet tall. That was it, and listed every node on the Internet. To do that today would probably take more real estate than the Earth. You know? So it's really fortunate that I was able to cut my teeth in this space at the dawn of all of the environment that we rely on to do so many things today.

(Joel Beasley at 00:08:25) Yeah. And what are you gonna do with all those artifacts? Like, are you just collecting them for fun, or are you gonna open a museum later in life?

(Jason (CISO at HITRUST) at 00:08:32) Just actually, we have a pretty interesting museum here in town, and maybe I'll donate some of those things to them. I've got an old Apple Lisa, pretty rare, and the proprietor of that museum is constantly after me to leave it to him. He offers me different prices, and maybe I'll leave it to you as a gift when I pass. But mostly it's out of curiosity that I keep it. Sometimes when, my children are both out of college now, but at the time when they would lament and give me grief because they weren't able to download a multi-gig sized movie on their mobile device over the wireless network in two seconds, and I would try to impress upon the fact that any of this works half as well as it does is miraculous. You know, when you think about everything that we had to do, it sometimes helps to put it into perspective, gives people a little bit more patience to just wait a little bit, be, you know, appreciate what you've got instead of lamenting that you don't have faster speed and it's, you know, more, more, more.

(Joel Beasley at 00:09:33) Yeah. My dad had one of my earliest memories of the Internet is like a Friday night. And my dad's a software engineer and hardware engineer. And we took two 56k cards and had one up and one down. And we uploaded and downloaded something at the same time with two different phone connections. And that was just us being nerdy.

(Jason (CISO at HITRUST) at 00:09:57) Yeah. Yeah. Yeah. The experiences that I had, what it would take to get a file. Right? You didn't know where to go. There were no search engines. You couldn't find a destination node if you didn't have the specific address. Once you reached it, you didn't know how to talk to it. First of all, how are you gonna talk to it? A lot of times before the Internet, you would act as the in-between. You dialed directly. We had to literally call somebody on the phone to set up all the communication protocols that you were gonna use for the data connection, using a stop bit, what protocol, all of those kinds of things for it to work. Then you would get the file, and it would take hours for it to download. There was no guarantee that you had an application that could open the file. And then even if you got the file, eventually, there was no guarantee the file you needed or wanted. Right? You know? And now when kids do their research projects using Google and everything they want is there immediately and it's cataloged and they can filter. Again, I'm talking Stone Age.

(Joel Beasley at 00:10:55) It happens.

(Jason (CISO at HITRUST) at 00:10:55) But the benefit is that if you're trying to understand how these technologies can be misappropriated and taken apart and used differently, it helps if you understand how they're built. Right? So I don't know that if you were an electrical engineer going to school, you're not gonna go out and fly a kite with a key on it in a thunderstorm. Right? But you do need to understand the principles of electricity before you can use that to build on it. Right? So the question is, how far back do you go? So I think, to a certain degree, some of those artifacts have some value.

(Joel Beasley at 00:11:29) Yeah. For example, we can sit here and build software all day and have no idea how the computer actually boots up.

(Jason (CISO at HITRUST) at 00:11:37) Right. Right.

(Joel Beasley at 00:11:38) It's like we don't really need to know to build business logic web applications. What's going on deep down inside the computer? You just build with the layers that you have.

(Jason (CISO at HITRUST) at 00:11:48) So I know this is probably a little bit off topic, but there are a variety of soapbox issues that I have. And one of the things that frustrates me is when people make conclusions that are invalid. We all use these devices. Right? And now most of us have some sort of container. So we separate our work life from our personal life. That strikes the right balance from privacy as it should be, but it also gives our corporations the ability to control this so that they can show respect for customers' data who may be here. If they need to, they can revoke this or they can properly control it. But that's a container sitting on top of essentially an untrusted host. Does it manage the risk? Absolutely. But if somebody were to own this device in a lower level of the stack, right, then anything on top of that stack is potentially compromised. Right? But I don't know that a lot of people appreciate that, and that really gets to the, I think, part of what we should talk about today. One of the conversations that we had prior was, you know, what does it even mean to be secure? I don't like that word. I don't think it serves anybody well. That conversation about the phones is about risk, and the CISO's job is to inform that conversation. Today's companies are run, all companies have always been run by men and women who make risk decisions every single day. That's absolutely what they should be doing. What we don't want them to do is make those decisions without an accurate understanding of what risk they might be accepting by default because they're not aware of them. So the CISO's job is to inform that conversation, not necessarily to be Doctor No, to say no to things. I mean, if they're empowered to do their share of enforcement as an executive, that's different. But otherwise, that's what they should be doing. So the term is not security. I don't even know what security means. For something to be secure, you'd have to take this computer, turn it off, shut it down, disconnect it from the Internet, lock it up, put it in a box, put the box in a closet, and put a guard on that closet. Is it secure? I have no idea. What I can tell you is it's perfectly useless in that state. Right? And that's the point. We have to use these things to support our business missions. That means, by definition, we're going to expose ourselves to some level of risk. And the question then is, how do you balance that? That's really what this is all about. You also avoid the trap that many people get in. If you are security versus risk management, then you better keep that thing from happening. Now, to a certain degree, breach is inevitable. To some degree, something's gonna happen. Remember, we gotta find and plug all the holes. They only have to find one. If perfect security is your objective, if keeping the bad thing from happening is an objective, you're setting yourself up for failure. I don't think you can possibly achieve those ends, and I'm not saying that, and certainly the cost to achieve that would not be ever warranted. If you think about what the C-suite is, all of the men and women who have C in front of their title, they are essentially dividing up the company's risk pool. Right? CFO, you're looking at financial risk. Maybe you've got a Chief Compliance Officer and you're looking at insurance risk, or the Chief Counsel's legal risk.

(Jason (CISO at HITRUST) at 00:14:58) Certainly, CTO and CIO are looking at technology risk and what if we get our stack wrong, and then there's the information and the data risk that's borne by security and privacy, obviously with privacy risk. So that's essentially what that all is. Those are terms, when you express it that way, that all of those people understand. They don't have to be security experts, nor should you try to make them. Each of us probably has enough of an understanding about the other's discipline, but we rely on counsel to be the expert in legal. I didn't go to law school. I didn't have to.

(Jason (CISO at HITRUST) at 00:15:30) We get together in a room, have a conversation. Business should be saying, "Here's what it wants to do. This is the business objective." And then at some point, somebody's going to convert that into a strategy for how to do that. Then relative to your primary audits of CTOs and CIOs, they typically are going to create an IT strategy for how to support that business strategy.

(Jason (CISO at HITRUST) at 00:15:51) Great. That's as it should be. Then the security person should come in and put an overlay on top of that to say, "Okay, based on that, here's where I see areas for risk. Here's what I see that we can already address."

(Jason (CISO at HITRUST) at 00:16:04) "We're already addressing. Here's where we've got some gaps. Maybe we should look at doing some additional things, or maybe we should do a little bit of a course correction in terms of how we're going to go about achieving that strategy to avoid that issue altogether." Right? That's the conversation that the companies need to be having.

(Jason (CISO at HITRUST) at 00:16:19) And if they're doing that, then it's perfectly okay to accept certain risks. There's nothing that says you can't accept risk. The business judgment rule says as long as you did it in due diligence and did an appropriate analysis, if there's some risk, you can accept it. We all do that crossing the street.

(Jason (CISO at HITRUST) at 00:16:37) Right? Everybody does that. That's a risk decision. We don't think about it that way, but that's a risk decision. Think about it.

(Jason (CISO at HITRUST) at 00:16:44) You look both ways. Is there a car coming? Okay. How far away is the car? What kind of car and how fast does the car move?

(Jason (CISO at HITRUST) at 00:16:48) How fast do I walk? How wide is the street? What kind of shoes do I have on? What am I carrying? Right?

(Jason (CISO at HITRUST) at 00:16:52) And you make a decision like that without even thinking about whether it's okay to cross the street. You know? Is it a bicycle and I'm carrying a bag of groceries? That's one calculus. Is it a fast-moving semi tractor-trailer and I'm carrying a baby?

(Jason (CISO at HITRUST) at 00:17:07) You know, and that thing's bearing down on me? Yeah. You know, I'm going to let it pass, and I'll go after it. Those are risk decisions. Right?

(Jason (CISO at HITRUST) at 00:17:13) So this is natural. We're doing this all the time, and this is no different. So that's why I prefer the term risk to security.

(Joel Beasley at 00:17:23) So how do we mess it up? As people, you get to see this all day. What are some of the common misconceptions?

(Jason (CISO at HITRUST) at 00:17:30) Well, I'm not a Negative Nancy. I don't think we mess it up. I think that what happens is it's not always top of mind. People have jobs to do. I think more often than not, let's—there are clearly advanced persistent threats. There are nation-state actions taken against targets, and we're not necessarily talking about that.

(Jason (CISO at HITRUST) at 00:17:54) That's very—I don't know what the—there's research that describes what percentage of the breaches that scenario counts for. But most of the time, it's usually somebody trying to get their job done that either forgot for a moment to be diligent and took their eye off the ball and allowed something to happen, or was just careless. Right? You know, over time, and we've all done it, you get pop-up messages. You don't read that message.

(Jason (CISO at HITRUST) at 00:18:16) You just click it. But what did you just click on? Right? If I create a pop-up message, it looks like the one you always click on without any problem. You just got to click on it once.

(Jason (CISO at HITRUST) at 00:18:23) Now you got malware on your machine. Right? So to me, that's what it's about. And again, that's another part of the CISO's job. I think you have to create this culture of security-mindedness.

(Jason (CISO at HITRUST) at 00:18:35) It's not about Chicken Little. It's not about the sky is falling. It's helping people do their jobs. There's a couple of ways that I think you need to do that. Number one, tone from the top.

(Jason (CISO at HITRUST) at 00:18:46) Right? This is probably the only thing that I can think of where there is a board responsibility. Back in the day, a board seat as a board of director, that was something that you and your country club buddies gave to one another. You came, you met a couple times a year. You had a nice steak dinner.

(Jason (CISO at HITRUST) at 00:19:03) You collected a nice fat check. Right? You didn't think about security. There was no expectation that boards were looking at security. There was no fiduciary responsibility to ask those kinds of questions.

(Jason (CISO at HITRUST) at 00:19:15) Now this stuff flows uphill. Right? You know, there are plenty of examples where a CISO or somebody like me, the vice president, is going to get fired, but they're really the scapegoat. This rests with the board. They've got to be looking at this.

(Jason (CISO at HITRUST) at 00:19:27) That is an expectation. The NACD, the National Association of Corporate Directors, and other governance bodies have clearly established that. Okay. Well, if that's their responsibility, why don't you go to them instead of it being perceived that you're going to them begging for money? Why don't you go and say, "Hey, how can I help you fulfill your responsibility?

(Jason (CISO at HITRUST) at 00:19:47) Here's the issues that we're dealing with. Which ones of these would you like to address in which order? Now let me go help." Now you're being seen as a help, as a partner. Remember, it's about "Tell me what you want to do.

(Jason (CISO at HITRUST) at 00:19:57) I'll find a way to enable the business." You're being seen as a partner. So that's first of all. Then you get that trust, then they're going to come and have those conversations. And the second is getting everybody else in the company to act in a way that's consistent with whatever that appetite is. And I think that's really simple.

(Jason (CISO at HITRUST) at 00:20:12) A lot of times, the security officer is perceived as the stumbling block that somebody's got to get past. "I want to get this done. I want to release this piece of software. I'm going to scan it for vulnerabilities. Oh, God.

(Jason (CISO at HITRUST) at 00:20:24) What's it going to find? If the numbers are bad, I'm not going to be allowed to release this thing. But that means I'm not going to get time to market, and I'm not going to be able to make revenue." Okay. Well, why did you wait till the last minute to scan it?

(Jason (CISO at HITRUST) at 00:20:35) Why didn't we partner together upfront to help figure out how to build decent code to begin with? Totally different way. So if you're not reaching out to them saying, "How can I help you?" wherever possible, in terms of daily activities, what are you doing to remove human error from the equation? Right? If people are working with sensitive data and they're emailing it back and forth, and if somebody simply forgets to encrypt it, now you've got something that went across the public network in the clear, might have been exposed, maybe it didn't.

(Jason (CISO at HITRUST) at 00:21:00) But depending on what kind of data and what industry you're in, you may have a reporting obligation. You may have to notify those data subjects. If you can use technology to encrypt every one of those transmissions by default, or more often than not, you can rely on that and say, "I took human error out of the equation. If you forgot, we were okay because I did it for you anyway." So you should be investing in those kinds of things.

(Jason (CISO at HITRUST) at 00:21:23) And then mostly you need to talk to people and let them know you got their back. We used to call them con men. They're called social engineers now. If I'm yelling and screaming at you and you're worried that you're going to get in trouble, I'm counting on that as the bad guy. I'm preying on those fears that people have of getting in trouble, which actually may be the reason you do the thing that gets you in trouble.

(Jason (CISO at HITRUST) at 00:21:45) Instead, you've got to have this culture that says, no matter what, 25 hours a day, eight days a week, you can call me. You can reach out to the support desk. There's a way. When in doubt, check it out. There's a way to get that answer.

(Jason (CISO at HITRUST) at 00:21:57) You will not get in trouble for getting the clarification that you need. Right? So again, those are some of the things that you can do to create that culture so that you don't get people that are messing it up, because I don't think that they're trying to mess it up. Now, not to single anybody out, we had a water treatment company in the news last week. I don't have any insight into what happened there. I'm operating based on what has been reported about what led them to that event.

(Joel Beasley at 00:22:27) Is this the Florida one?

(Jason (CISO at HITRUST) at 00:22:29) This is the Florida one. Yeah.

(Joel Beasley at 00:22:30) Because I live in Florida. That's—

(Jason (CISO at HITRUST) at 00:22:31) Oh, do you?

(Joel Beasley at 00:22:32) I live—my parents live in that area. So—

(Jason (CISO at HITRUST) at 00:22:36) Well, I could riff on this all day. First of all, I think it's ironic. We have this product called water, which we cannot live without after a few days, and yet we don't protect it like it's a life-dependent resource. You know? Nothing against my data that I have in this system that I use to make revenue, this company says.

(Jason (CISO at HITRUST) at 00:23:03) I can live without that. I can't live without water, yet we go to great lengths to protect this and not that. So that's kind of—no, I'm not blaming this one company, by the way, at least not for that. So let's unpack this a little bit.

(Jason (CISO at HITRUST) at 00:23:18) My understanding is that they're running end-of-support, out-of-support Windows 7. In some industries, that is such an egregious mistake that it is considered a violation of regulation or a law.

(Joel Beasley at 00:23:32) Can you back up and tell what the problem was? Like, what actually happened?

(Jason (CISO at HITRUST) at 00:23:38) So my understanding is their systems were attacked, hacked, compromised. They were able to take advantage of certain exploits, which are weaknesses in anything. There's weaknesses in software. There's weakness in hardware. There's weaknesses in firmware.

(Jason (CISO at HITRUST) at 00:23:52) I don't know which exact weaknesses were taken advantage of. But when you have these weaknesses, what we do to address them is we run scans. There are companies who have products that constantly are updated with information about what to look for to help people identify these weaknesses. In the HITRUST security framework, for example, there's a whole host of things in vulnerability management where we are telling organizations to achieve reasonable levels of security, you need to do these things. Right?

(Jason (CISO at HITRUST) at 00:24:18) So you find them and you should patch them or address them in a reasonable timeframe. If you're running software that is no longer supported by the vendor, that means they're no longer patching it. It's still out there, which means bad guys are still looking for ways to compromise it. And if those holes get made public and we know that the party that originally created it says, "I'm not supporting it anymore," and you're still running it, it's on you. It's different if I have a product that's still being supported where I can count on that vendor to issue patches for their flaws.

(Jason (CISO at HITRUST) at 00:24:50) Right? Or I can issue workarounds. That's not happening. You are failing to protect yourself against a reasonably anticipated threat. So that is a substantial issue.

(Jason (CISO at HITRUST) at 00:25:01) Number two, they put their company network on the public network, on the internet without a firewall. Right? I'm at a bit of a loss for an analogy to explain how insane this is. This is not driving a car without wearing a seatbelt. This is driving a car without brakes.

(Jason (CISO at HITRUST) at 00:25:23) Okay? Years ago in the late nineties, there was an experiment known as the San Diego experiment where researchers put a server on the internet without any protection. And the purpose was, "Let's see how long it will take for this to be discovered and attacked and compromised," and it was measured in months. People have repeated this experiment since. It's now measured in minutes, if not less than a minute, for a similar server to be put on the internet, not behind a firewall, for it to be found, attacked, and compromised.

(Jason (CISO at HITRUST) at 00:25:58) Less than a minute. Right? It's inevitable that this will happen, and you put this equipment—now, again, I'm not blaming this organization if you're a municipal utility that's not got a lot of funding. Are they to blame?

(Jason (CISO at HITRUST) at 00:26:13) Well, I don't know what happened on the inside. Oh, by the way, the third thing that they also did is that they needed to gain remote access to this network, and everybody was doing so using the same account with shared passwords. You know what they say about a secret. Right? As soon as the second person knows, you can't keep a secret anymore.

(Jason (CISO at HITRUST) at 00:26:30) So this is a lot of people. So all things that led to the compromise. Now if I'm a municipal CISO, whoever it is that has that responsibility, and I go, "I've got no budget. I've got to deal with this, and I've got to take the money I have to get clean water that's more important than the systems." Right?

(Jason (CISO at HITRUST) at 00:26:47) Maybe. What I should be doing is I should be calling it out. I should be making a public issue of it. I should be going to leadership. And whoever is the top of the elected set of officials, they should be having a conversation with the public whose taxes form the revenue and funding mechanisms for this municipality.

(Jason (CISO at HITRUST) at 00:27:03) "Okay, guys. How do we collectively—I don't want to get blamed for this. I don't want to be in this situation. But what do we do? We have limited resources.

(Jason (CISO at HITRUST) at 00:27:10) How do we allocate?" And again, that's a risk decision, and that's another part of the CISO's job is to compel those conversations. If they're not happening, shame on them. Right? As long as you have the conversation, then it's not on you, and we collectively make that decision.

(Joel Beasley at 00:27:25) So I'm connected with my local government. It's surprising. You can get involved with your local government and have more of an impact than you think. Like, it's not very competitive. It's not something everybody wants to do.

(Jason (CISO at HITRUST) at 00:27:37) Right.

(Joel Beasley at 00:27:37) But I'm connected with our commissioner. I think that's what it is. There's four or five of them, but he's been a good friend of mine for about 10 years. And so we were talking the other day, and I don't know how much of this is public.

(Joel Beasley at 00:27:53) So I'll ask him before we air it. But he sent our CTO—so we live in Sarasota County, which is about an hour south of one of the counties that the water attack happened to. And so he sent our CTO, who's a really great guy, up there to learn details about the attack and exactly what happened because we're all local. We're the nearest big county. And then come back and report back to him.

(Joel Beasley at 00:28:18) So our commissioner said, "That just happened in our backyard. You go over there, learn this." Right? "And come back and tell us what we need to change or what threats we have or whatever we need to do to take action." And from what I learned was it was actually a TeamViewer from someone doing support on the computer, and they just used a generic username and password, and it was just open, like, completely open.

(Joel Beasley at 00:28:44) And somebody just came in through the TeamViewer and just changed the levels right in the water. And then what happened was a worker at the utility went over and just looked at the screen and was like, "Oh, that number is wrong," and just adjusted it and then filed something. And then the whole thing became known. But if it wasn't for that, the person who's walking by the screen and being like, "Oh, that number's off, and that's going to poison people," then it would have gone through and happened.

(Jason (CISO at HITRUST) at 00:29:13) So let's talk about that in terms of how we can all learn from this. Number one, somehow this notion that our government is something other than us is absurd. Our government is we. Right? It's other humans that said I want to go into public service.

(Jason (CISO at HITRUST) at 00:29:28) We should be holding one another accountable. Right? And if we don't, who's to blame? Two, if you were the first one to experience something in any sector or industry or municipality, it's not as bad. But as a lesson to every other municipal wastewater treatment plant in United States, if you are operating in a similar fashion to this and you don't take this as a wake-up call and change your infrastructure to avoid these problems or have the conversation if you don't have the funds to address these problems, shame on you.

(Jason (CISO at HITRUST) at 00:30:03) Right? You know, this is envelope one. Going to the risk equation, I've spent time designing and doing security in some of our more heavily regulated sectors, including one of the critical infrastructures where we've got nuclear energy. If you've seen the images that everybody has of warheads in a silo, Cold War era, with two people at physically distanced panels to turn a key at the same time, right, so that you couldn't have one person. That's very much how the control panels work.

(Jason (CISO at HITRUST) at 00:30:39) There is a partnership where for any little change to happen, what are we going to do? Here's what I'm going to do. How are you going to do it? I'm going to turn this dial. Which direction are you going to turn that dial?

(Jason (CISO at HITRUST) at 00:30:49) I'm going to turn that dial clockwise. How far? Two clicks. What do you expect to happen when you turn that? I expect this to happen.

(Jason (CISO at HITRUST) at 00:30:55) How are you going to know if that happened? I'm going to look at this gauge. What do you expect that gauge? All before doing this. Right?

(Jason (CISO at HITRUST) at 00:31:00) And it's two people doing that. So now a lot of that's also automated. But that level of controls is appropriate because somehow that is perceived. Well, it's not perceived. For a nuclear power plant to go sideways, that would be catastrophic. Right? Somehow, we don't consider water as important.

(Jason (CISO at HITRUST) at 00:31:19) You know, we've got to decide what our priorities are. If this had gotten out and if there was a poisoned water supply, there would have been, you know, far more people who were called on the carpet than, you know, something that thankfully got averted. Maybe, you know, there's an adage that many folks in security say, which is you never let a good disaster go to waste. And I'm not showing disrespect for the people that were subject to that and whatever the cause is. I'm simply saying if you are not using that as a learning experience, right, don't wait for it to happen to you.

(Jason (CISO at HITRUST) at 00:31:52) If I don't have to touch the burner and burn my hand, if I see you do it, I'm going to learn. Don't touch the burner. It's hot. Right? Same kind of thing.

(Joel Beasley at 00:31:59) I mean, we're adaptive as people. Right? We should not be embarrassed or shy about that. It should be something we can talk about. We see one, you know, this isn't the first time we've seen, you know, a small government municipality or utility attacked.

(Joel Beasley at 00:32:17) Right? And I get it too because I've gotten to go tour these facilities, and they have such a broad range of responsibilities. They're responsible for making sure the hospital's data systems are up and running, the firefight and emergency response 911. And it's a large, you know, as businesses, we'll have different business units and lots of money to put really bright, intelligent people in each business unit because it generates revenue. But when it comes to, you know, our government, we've got one group of bright people that have to make sure all of these services are running and operational.

(Joel Beasley at 00:32:55) And, yeah, like, things happen, and that should be a wake-up call to everybody to, you know, be secure.

(Jason (CISO at HITRUST) at 00:33:03) So we kind of made this a lot larger a conversation than just how organizations, how CISOs and CTOs should be governing their operations. This is more about how we operate at large. I like to paint it this way. I don't care what business you're in. You need two things to succeed: access to capital and access to customers.

(Jason (CISO at HITRUST) at 00:33:28) And in 2021, both of those are about confidence and trust. Right? I'm not going to invest in you as an angel investor, as a stockholder, as whatever if I don't believe I'm going to get return on investment. That's a question of confidence. I have to believe that this is a well-run company.

(Jason (CISO at HITRUST) at 00:33:43) And I'm including cyber in that. Right? That's now a question in mergers and acquisitions and all sorts of things because that's risk, and I don't want to buy risk. As a customer, and this often comes under the questions, it's not security. It's a question of privacy, but that's another element of information risk. HITRUST has two completely separate certifications with different sets of controls, and you can do one or the other or both. But they're all part of this risk picture. This is where individuals are beginning to vote with their feet. So I've been very fortunate to avoid most major compromises.

(Jason (CISO at HITRUST) at 00:34:18) I haven't had identity theft. I haven't had, with the exception of the OPM background investigation, a lot of these problems. But there are many that haven't been so lucky. Now I would likely say it's partly because of the diligence with which I operate. I have professional awareness, so I know when I do something, if it's a free app, there's no such thing as a free app.

(Jason (CISO at HITRUST) at 00:34:40) What that means is I'm probably paying with my privacy. Right? The company that's behind that has to have some policy to monetize that somehow. They're dealing with advertisements. They're selling my data.

(Jason (CISO at HITRUST) at 00:34:52) They're collecting information. Well, therefore, I'm going to either not engage or I'm going to inquire what data of mine are you capturing, what are you doing with it, who are you sharing it with. I'm having, and people are beginning to ask those kinds of questions now. If you're not, then you are making a decision about the acceptability of something not aware of what those risks are that you might be putting yourself or your data to. And I think that's really what's going to be coming next or what's already starting to happen.

(Jason (CISO at HITRUST) at 00:35:20) People are increasingly aware of the Facebooks, of the other organizations that are collecting all of this data. You know, a couple of years ago, we all acted so surprised when that ad popped up that was related to the thing we were just talking about because they're listening. Right? That's a question of privacy. You can get devices and you can put controls on them or you can have settings that will keep that from happening.

(Jason (CISO at HITRUST) at 00:35:46) Probably also going to have less rich an experience. You have to make that trade-off. And it's okay if you choose, if you say, I don't care. Who knows that I'm interested in buying a new TV, and here's an ad for a TV. If I'm talking about maybe some sort of sensitive medical health or circumstance that I'm under, maybe I don't want people knowing that.

(Jason (CISO at HITRUST) at 00:36:06) So I think it's about giving people that choice. And a lot of this role is increasingly becoming about how do we do that? How do we communicate to people in a way that shows respect but still allows us do what we need to do?

(Joel Beasley at 00:36:19) Yeah. The first time that I learned about the microphone monitoring for the ads, I was like, no. And then I looked it up, and there it was on my phone, a checkbox default checked to allow, not Microsoft, to allow microphone access. I think it was to Facebook. And I then went and started telling people throughout, you know, family birthday parties and things like that.

(Joel Beasley at 00:36:45) And they were saying, oh, Joel, you're a little bit out there, my friend. And I was like, let's pull up your app right now. I'll go into your settings and show you. And they were just blown away by the reality that they listen to the microphone by default. If you just install it and accept everything, they're going to be listening, and then they'll show you ads based off of what they hear.

(Joel Beasley at 00:37:06) It's just the way it is. And this was a year ago. This isn't something new. But I did want to touch on something because we're talking about voting with your feet. And I did that the other day, and I felt kind of proud because it was frustrating, and it took a lot of effort for me.

(Joel Beasley at 00:37:20) So what I did was I bought a Samsung TV. We hadn't bought a new TV in like ten years in our house, and the kids want the Amazon Fire stuff, and it's so slow. So I was like, alright. We're going to go get a TV. My work TVs are better than this.

(Joel Beasley at 00:37:34) I'm going to go get a Samsung TV. They're only like four or five hundred bucks. Right? And so I go get this one and install it, get it all set up, you know, hang it, had to go to the hardware store because we didn't, we need a difference. Went through all of this work to get this thing hung up.

(Joel Beasley at 00:37:48) And I go to turn it on, and it's requiring me to download an app on my phone. And I was like, alright. Whatever. I have to download the SmartThings app. But then for me to complete the setup process of the TV, Jason, it made me give them location access 24/7.

(Joel Beasley at 00:38:06) I just, at first, I said no, then it wouldn't let me progress. Then I clicked only while using the app, and it wouldn't let me progress. And then I had to give it all, and I was like, I'll just give it all, finish the setup, and then delete it. But that was completely unacceptable to me as far as user experience. So then I'm like, alright.

(Joel Beasley at 00:38:22) Whatever. I'm over that. So then the Samsung loads. And I have another Samsung here that doesn't do this. It's an older model.

(Joel Beasley at 00:38:30) But they got into the TV in the streaming space called like Samsung TV. And so now what happens is when you turn it on, it's like, you turn on a TV versus like you turn on a desktop, and it starts playing their channel. Right? Their advertisements and their whatever they're playing and displaying. So every time you turn on their TV, you have to be listening to whatever.

(Joel Beasley at 00:38:54) I'm very anti-ad. I pay for premium for everything. I just, I don't like people injecting stuff into my mind that I'm not consciously choosing to do. And so I just said, I'm taking it back off the wall. I'm putting it back in that box.

(Joel Beasley at 00:39:10) I spent like two hours on Saturday, like, put it, and I put it back in my truck, drove it back down to Best Buy, and I said, I'm returning this thing. And I've got this other TCL or some other type of model of TV that I know doesn't have a Roku in it. So I know how the Rokus boot up, and you just get to pick what you want. But that whole experience from giving them my full location, and then I looked it up too. Like, can I disable this?

(Joel Beasley at 00:39:37) And people on Reddit were furious, and they were, the Reddit threads were ridiculous because this is apparently something new Samsung started doing to push their TV stuff.

(Jason (CISO at HITRUST) at 00:39:47) So I think this, again, has to be very much market-driven. California has a privacy law that a lot of people think is somewhat draconian. I think they got a lot of it right. It doesn't tell businesses what they can and can't do. It says if you're going to collect data from people when you engage them as part of your products, as part of your service, you have to tell them what data you're going to collect, what you do with it so you can make that decision.

(Jason (CISO at HITRUST) at 00:40:14) Now, ideally, you're making that decision when you're evaluating products in the store or online before you mount it on your wall. The problem is enough of us have to say, I want choice. I'm frustrated oftentimes where I know about issues, and I can't find a product that will show the appropriate level of respect that I'm looking for. When we went to buy a refrigerator, refrigerators are all online now. Right?

(Jason (CISO at HITRUST) at 00:40:37) Internet of Things. I don't need a refrigerator to be online. The guy at the store, because we did actually go into to physically touch them and to ask because I couldn't find anything online. He said, well, this is the one you want because most of that's for diagnostics and repair. I'm not talking about the capabilities where you can, you know, know whether you're low on milk or something.

(Jason (CISO at HITRUST) at 00:40:57) This one has the same functionality, but you have to hit a button, physically hold a button, and then dial a number and hold your phone up so that this machine can talk to that machine by this way. So I had some control over it. Same thing with, we bought a gas range. Most of the models that we were looking at had Wi-Fi. Do I need Wi-Fi in a gas range?

(Jason (CISO at HITRUST) at 00:41:18) Hey. I mean, I go crazy if, do we leave the toaster on? Right? I guess that's what it's about is if you left home, you could dial in and make sure you turn it off. Okay.

(Jason (CISO at HITRUST) at 00:41:27) But doesn't that mean somebody else could hack into my house and turn it on? Yep. So I don't, it's hard. For me, it's harder to find these non-risky devices. So I think what we have to do as a consumer base is enough of us have to express that we care because if there's a market for choice, some people will say, I don't care.

(Jason (CISO at HITRUST) at 00:41:47) Give me fully immersed experience, and I don't care who knows it. I've gone out of my way. I have alternate identification in emails. I have other personalities online that I use when I do things like, you know, doing research on the deep web. I can use those parts.

(Jason (CISO at HITRUST) at 00:42:03) So you want my email? Okay. But it's not me. It's a completely fictitious personality. Now location, that's tough to get around.

(Jason (CISO at HITRUST) at 00:42:09) I guess you could find something that could make it, you could spoof your location, so that it didn't know exactly where you were. But I shouldn't have to work that hard. I don't know if we're going to get there, but, yeah, this is the conversation people should be having. And if they're not, then they're unknowingly putting themselves or their data at risk. And that's really, and that's one of the, I think you asked me one of the questions was, you know, what kind of keeps me up at night?

(Jason (CISO at HITRUST) at 00:42:36) A couple ways to answer that question. First of all, personally, I'm very fortunate. I work for a company that's very security-minded. I've got the support of my board and my leadership, and we've put in a program. So I'm not really concerned.

(Jason (CISO at HITRUST) at 00:42:48) I'm not trying to put a target on my back. What I'm saying is that we have appropriate structure. We've invested in segmentation and the right tools, and we have really strong detection and practiced response. Right? You want to get good at something?

(Jason (CISO at HITRUST) at 00:43:07) Do it until it becomes muscle memory. I don't care whether it's your golf swing or your incident response program. Right? You've got to just do it, so it's practice and practice. Do it by rote.

(Jason (CISO at HITRUST) at 00:43:15) So I'm not concerned about that. I think the question was really meant to say, what are the things that other people should be concerned about that they're probably not? I think the first thing is third party. So most companies are fully now awakening or already awake to this issue. Their data has value.

(Jason (CISO at HITRUST) at 00:43:33) People are trying to get to it. They need to protect it. If they don't, their company as an ongoing concern can be affected. We have to manage that risk. We make risk decisions about what we deem as an acceptable level or not.

(Jason (CISO at HITRUST) at 00:43:48) But nobody operates, almost nobody operates as a complete island. Right? We all do business in the cloud with downstream trading partners, with customers. We're all part of some sort of ecosystem. We are, in many cases, loosely coupled or tightly interconnected.

(Jason (CISO at HITRUST) at 00:44:04) The decision that you made that was right for you, now we have to have a conversation because I need to know that that decision is not only right for you, but it's also right for me. And that's becoming a challenge, and that's becoming a matter of cost. One of the big pain points that HITRUST is designed to address is I don't want to have to audit you and you audit me. And then if there's a third person, you've got to audit them and I've got to audit them. We're all auditing each other.

(Jason (CISO at HITRUST) at 00:44:27) That doesn't scale, right? One yardstick, one assessment, and now I can share that with you, and you can go, "Yep, this is good. I'm able to do business with you."

(Jason (CISO at HITRUST) at 00:44:37) You're giving me the assurances I need. Somebody else asks you, you don't do another assessment. You just give me a copy of that same certification. Yep. It's like Underwriter's Lab.

(Jason (CISO at HITRUST) at 00:44:45) On the bottom of the hairdryer, it's got that thing that says, when I plug this in, it's not going to explode or catch on fire, right? Good. And then, of course, if you said, "Well, wait a minute, I've had this conversation. What you got is good, but I need more because there's something special about our use cases." Great. Then we can focus our attention on that. We didn't have to focus all these resources inappropriately. The last thing is kind of where do I see this going?

(Jason (CISO at HITRUST) at 00:45:08) One of the things that we're constantly challenged to do on behalf of our customers is keep our framework up to date for new and emerging threats. I think that there's probably two or three that we need to worry about. One is the realization that, I don't know what you want to call it, if there was the Internet 2.0, I'm talking about Earth 3.0. We are now in a world that is global. We are running out of resources, and it is an economic battle for supremacy. So when people talk about Russia and China and think of them as these adversaries somehow different from us, from their perspective, we're the adversary. We're all competing for the same limited set of human resources, of natural resources, for money in a global economy. And before the Internet, we took advantage of a variety of different things to get that competitive advantage. Some cases, there was espionage.

(Jason (CISO at HITRUST) at 00:46:07) Right? Corporate espionage. I'm not going to talk about the other stuff. We have to understand that they're doing that. And in some countries, the government is cooperating with their commercial entities to get a competitive advantage. And if I can find out your plans, if we both make widgets and you're looking to make a better widget, and instead of having to invest in the R&D to take years to get that better widget, I just get your plans for it, is that good or bad? I don't want to get into that political debate. I'm simply saying you better recognize it and protect those plans for that widget.

(Joel Beasley at 00:46:43) That's legit because I was just talking with this black ops type security guy, and he was telling me about some of the craziest attacks he had seen. And one of them was on a CNC machine, an aerospace supplier, because they figured, rather than investing in all this R&D, let's just go target this downline supplier and their machine that they're going to use to cut this stuff, and we can just get the plans right from there.

(Jason (CISO at HITRUST) at 00:47:06) Right. So if that's the case, then what do you do? So here's the things that worry me: artificial intelligence and quantum computing. We have entire catalogs of things that corporations are supposed to do to protect themselves. And if you do them today, you can effectively manage that risk. But that whole risk calculus is based on a notion that may change, a notion that the amount of time and energy it takes for that adversary to compromise my system to get to the thing that they want that has value, it will take them so long that it's not worth their time. Quantum computing, it's not technically accurate to say that it will compute faster because it's not about a speedier drive or clock speed. It's about allowing for new algorithms, new approaches to solve older problems. And the biggest math problem we all need to worry about is encryption.

(Jason (CISO at HITRUST) at 00:48:07) Everything that we do to secure our life today is based on encryption: big math problems that are hard to solve, not impossible, but hard. It's not about doing a brute force approach, trying a bunch of keys sequentially till you get the right one. That you could do faster with a faster computer. This isn't about that. With quantum computing, you should be able to come up with new approaches to solve that problem in orders of magnitude less time. Well, what does that mean I have to do? If that computer using quantum computing can crack my encryption, everything I've done that's based on—does that mean I'm going to have to have a 500-character password? People can't remember eight-character passwords, right? Those are the kinds of things that worry me. And then the use of artificial intelligence, it's already in play, right? We already have the famous Turing test where there's games where you can play, where you try to tell whether the person on the other end of the online conversation is a machine or a person.

(Jason (CISO at HITRUST) at 00:49:03) It used to be scripts, right? I'm a wily hacker, I wrote a script. Some kid can run the script. Yeah, it found a hole, but it also notified me. I've basically got a grassroots organization doing work for me, and now I'm programming all of this myself. And on the good side, we're investing in SOAR, right? Security orchestration and response, all this massive coordination. Because when something happens, we've got playbooks. We're running the same stuff. Well, the bad guys know this. So I mean, it's just a war game that's automated where if I do this, I know that you're going to respond with this. Now the speed with which humans can keep up with that is limited. So if I'm fighting a machine-based adversary that can work faster than me, and if I haven't invested in machine-based defense that can keep up with the attacks from the adversary, I'm going to be left behind.

(Jason (CISO at HITRUST) at 00:49:57) So I don't know where we are in that. I'm sure there are existence of many small pockets. I don't think we're dealing with a huge footprint of artificial intelligence that's on the attack side yet. But if you're on the defense side and you don't have like-for-like technology, that first generation is going to get compromised. Because the footprint and the speed, we just can't keep up with it. That's what's concerning.

(Joel Beasley at 00:50:22) Yeah. There's new tools coming out all the time too, right? One of the tools I was talking to recently was Authenticate. They make it so that there's a tab, another browser tab. And if you want to access something that you might think is insecure, they have another browser tab and you open that up, but it's actually running on a virtual machine. But to you, it's kind of seamless. And I was curious because you're like the security guy, what you thought of, like, where does that tool set sit in the stack? Like, when is that useful?

(Jason (CISO at HITRUST) at 00:50:57) So the risk calculus is often very—we know what to do, but we can't do it. So in this case, I have something that I want, usually software, piece of code. I believe it's legit. I don't know. So how do we evaluate the risk?

(Jason (CISO at HITRUST) at 00:51:17) Well, most of us look at who it's from. It's from Microsoft. It's from Apple. I trust it. No problem. Install it. Maybe it is, maybe it isn't. Did I actually go to Microsoft and say, "Can you give me the checksum for this software package so that I can do a comparison and make sure it's actually yours and I'm not doing something else?" We don't do that. And even if it is, how do I know that they weren't compromised? Remember, it's about third party. So if that Apple store gets compromised with code, that application that's been compromised—I can write a software file that's nothing but malware, and I can call it PowerPoint, and you can find it online and download a PowerPoint. It's going to look like PowerPoint. It's not PowerPoint.

(Jason (CISO at HITRUST) at 00:51:57) Right? So this is where something like that environment runs. So the notion of sandboxes is not new. I don't want to get in the way of my business. We have to do a security impact analysis. We have to evaluate for risk before we let somebody install that software. Sometimes they know what product they want, but sometimes they're like, "I don't know. I'm looking at 18, like you. I'm picking between all these different TVs. Which is the one I want?" You know what? Here's a sandbox. And by that, I mean, it is separate from the company domain. It doesn't have company data.

(Jason (CISO at HITRUST) at 00:52:29) Go download whatever you want. It can compromise that environment. We're fully prepared for that to be completely owned, and we don't care. You make your decision that way. Now here's the problem. That technology is a step forward. It provides an additional capability. It's useful if the wily hackers aren't patient. If I know that you are going to examine what I'm sending you to determine whether it's legitimate or not and you're looking for certain indicators of risk, I'm not going to show my cards, right?

(Jason (CISO at HITRUST) at 00:53:05) So it's going to do everything that this software package purports to do, buried within it something that I won't do for six weeks after it's installed, or six months, or later. Right? Because you remember when we talk about advanced persistent threat, it's that persistence. I'm willing to wait. Dwell time. How long was that thing sitting there? Sometimes people hear that as "I was negligent, and I failed to uncover it for so many months." Well, maybe it's because it didn't do anything for so many months. There was nothing to uncover. And then all of a sudden, it morphed and did its bad thing. So I don't know enough about that particular offering to see whether they're doing anything for that threat.

(Jason (CISO at HITRUST) at 00:53:49) But, you know, there's very little that you're going to be able to do if you're not able to get to the source code and have people that can look at it and see what it's actually doing.

(Joel Beasley at 00:53:57) No, that was really helpful. You made me also think about, like, I'm assuming you don't own a Tesla because the over-the-air updates, that's the thing I'm curious about. I want to get an automotive expert on these over-the-air updates because these cars can be driven. They're self-driving.

(Jason (CISO at HITRUST) at 00:54:15) I do not. Although, I have security colleagues who I would trust with my life who do, one of whom, in fact, did an over-the-air update full system reset while driving because it supposedly can do that. And I'm like, that is—I just, I'm going the other way. I want a 1979 Toyota FJ that doesn't have a single ECU. An electromagnetic pulse can go off, and that car is still going to run.

(Jason (CISO at HITRUST) at 00:54:49) Right? People like, "Well, if you're worried about that, where are you going to get the gas?" Plenty of gas. It'll be in all the other cars that are on the road that aren't running.

(Joel Beasley at 00:54:58) That's right. Now you sound like my brother-in-law. He's really into those FJs.

(Jason (CISO at HITRUST) at 00:55:04) They're a great vehicle. And I'm not saying you should shun technology. Just go in eyes open. Luck also favors the prepared. I have go bags. You know, things go sideways. I'm full in on technology. I use it all the time. You know, I live my life with it. But if things go sideways, I'll do all right.

(Joel Beasley at 00:55:24) Yeah. No, my wife and I, we do what we call mild family preparedness, like, within our available budget, right? We do it. We don't do it to the point where, you know, we're younger in our careers and things like that. So we go shooting every three months, and so we train that way. I mean, I grew up shooting, so it's just second nature to me. But we go three months because that's typically when you start to forget how to oil the bolts and, you know, muscle memory.

(Jason (CISO at HITRUST) at 00:55:56) Yeah. You camp?

(Joel Beasley at 00:55:58) Oh, yeah.

(Jason (CISO at HITRUST) at 00:55:58) I mean RV. I mean tent camping.

(Joel Beasley at 00:56:00) No, we RV, but we did tent camp before. Yeah.

(Jason (CISO at HITRUST) at 00:56:04) Okay. So you can still do this in the RV. We tent camp. And mind you, it's more glamping. You know, I've got a 16-foot regatta bell tent.

(Joel Beasley at 00:56:12) There you go. Come on.

(Jason (CISO at HITRUST) at 00:56:14) I know. I know. But when we go out day one, you take the go bag. If it's not in the go bag, even if it's in the car, even if it's in the RV, it's as though it's not here. We're going to—and first of all, it gives you an opportunity to use up your perishables or your things that you have to replace if you've got food rations or water sanitation tablets, you know, the cleaning tablets, whatever it is.

(Jason (CISO at HITRUST) at 00:56:36) But that way, it's practiced. You know? When I wanted my kids to consider it a game, I didn't want them to be freaked out or, you know, the time to have these skills is not when you need them.

(Joel Beasley at 00:56:48) No, that's exactly—we, I have go bags for all of us, and the interesting thing was when we started putting them together, because we have two kids that are under the age of five, right? But when we started putting them together, the conversation came up. It's like, if we put these together and we don't go actually use them, they're completely useless because we're going to find out which products are good, which products aren't good. Like, for example, we went through a number of different water filtration systems. We tried tablets. We tried the LifeStraw type of thing.

(Joel Beasley at 00:57:15) LifeStraw? Yeah. And we ended up—I forget the name of it. But we just found one that was similar to LifeStraw. It had a bag and it was like a gravity filter. But, you know, we tried them all out though because you don't want to—the other thing is you don't want to learn how to use it. Forget about if it's going to work or not. You don't want to learn how to use it the moment you need it.

(Jason (CISO at HITRUST) at 00:57:39) Yes. Yeah. I'm with you.

(Joel Beasley at 00:57:41) Firestarters? Those were hard to learn how to use, man. That took me a good three months to get it where I could really throw a spark. Yeah.

(Jason (CISO at HITRUST) at 00:57:49) Well, I love the conversation so far. It seems like we are very much aligned. Be happy to—I've done presentations on what's in a go bag and why you need it, and people think it's because I'm worried about Armageddon. People on my team in Texas were without power for more than 72 hours. That's not Armageddon.

(Joel Beasley at 00:58:09) I live in Florida. There's hurricanes. Like, we learned about this stuff because growing up, it's 100 degrees outside, and you have no air conditioning. You have to know what you're doing. Water, power lines can go down. The hurricanes will ruin the water supplies. Like, it's—natural disasters are probably the first reason I would think of because they're the things I encounter the most.

(Jason (CISO at HITRUST) at 00:58:33) Right. And what's interesting is when the Internet goes down, as it did in the power outage, you can't rely on the encyclopedia of knowledge, right, that is Google and other search engines that you count on every day for everything. There's so many things that people—I don't need to know this. You know? Einstein said he didn't need to learn his phone number because he could look it up. Well, if the phone book's not available, right? So as an alternative to boiling water, one of the ways that you can clean it is with, you know, it's six drops of bleach in a gallon of water. But if you don't know that ratio, you know, it doesn't do its job. You know, if the Internet's not there, it's so many of these things that you need to know in advance.

(Joel Beasley at 00:59:18) So what I did was I call it a fallout drive. I built a couple of them for myself and my brother and stuff. So I bought a cell phone and put a 64 gig chip in it, right?

(Joel Beasley at 00:59:32) It was just an Android operating system one. And then I downloaded a ton of the survival Amazon books onto it. And then I found this other, it was a searchable version of Wikipedia that you could download and install into it and search it like a browser offline, essentially. And then I put—I mean, it took me an afternoon, a weekend to do this, right?

(Joel Beasley at 00:59:54) And then I just put it inside of a Faraday bag, not like it would, you know, with a solar power charger. That way, no matter what, I've got something in a waterproof, electromagnetic proof bag. It's got all the searchable information in it with a solar power charger. So I can at least figure some stuff out if things, you know, and not again, not like we're getting attacked by another country. Like, what if we had a solar flare from the sun? Like, you know, there's a lot of different reasons. But for most of all, it's just kind of fun. It's just kind of fun to feel safe and be prepared.

(Jason (CISO at HITRUST) at 01:00:29) I agree.

(Joel Beasley at 01:00:30) Yeah. We got way off topic. This is great, but I like you a lot. Alright. So we want to drive—

(Jason (CISO at HITRUST) at 01:00:36) Going down a rabbit hole.

(Joel Beasley at 01:00:36) We want to drive some traffic to HITRUST. So why should people reach out to HITRUST?

(Jason (CISO at HITRUST) at 01:00:41) Well, for all of the issues that we just talked about with the exception of go bags, if you think about the CISO as someone who is responsible for answering a series of questions that occur to him or her, that are put to him or her by his board or her board or by their customers, right? Where are we? Where do we need to be? You know, what kinds of risks are we dealing with?

(Jason (CISO at HITRUST) at 01:01:05) What do we do about it? And then when I'm in an ecosystem, how do I provide assurances to my third parties, and how do I do that in a way that is the most efficient, effective way possible? And how do I do all that and keep it current? That's where HITRUST comes in. We have a framework of controls.

(Jason (CISO at HITRUST) at 01:01:22) It's one of the most comprehensive of any of them. You can go—there are others. You can go to NIST, and they have 800-53 and a set of controls, and you can go to ISO. But none of them have everything that we have. So we also have a platform so that you can build a repository of answers to these controls to keep your monitoring continuous and to be able to provide assurances to other people.

(Jason (CISO at HITRUST) at 01:01:43) We also provide an independent certification. There is nothing else like that. You know, Underwriters Lab puts their brand at risk when they put it on the bottom of that hairdryer, regardless of who makes the hairdryer. We do, and we QA 100% of our reports. So when you rely on that company and they've got that HITRUST certification, you have a level of confidence that means they are doing the right things.

(Jason (CISO at HITRUST) at 01:02:05) They don't have a high level of risk. I can reasonably entrust them with my data. I can do business with these folks. And then lastly—well, two more things. If you want to do any of this in the cloud, that means you've got to inherit the controls that your cloud provider is providing for you.

(Jason (CISO at HITRUST) at 01:02:24) How do I do that? How do I define which are theirs, which are mine, and which we share? And if we share them, how so? We've gone to the top cloud providers, and we have shared responsibility matrices that tell you there's mine, there's ours. And when you go into the platform, it will actually—you can automatically inherit all of that, lessening the work that you have to do.

(Jason (CISO at HITRUST) at 01:02:45) And then if you are a company and you say, I've got 3,000 vendors. One of our customers has 3,000 vendors. They said, we don't want to spend all this money maintaining a vendor management program to get these assurances that we need from all these companies. We'd like to do is tell them, why don't you just go get HITRUST certified? But then we need to track all of those requests and do all that.

(Jason (CISO at HITRUST) at 01:03:04) We've got a third party system for making those requests and tracking it. And I want to point out that we're not one size fits all, nor should we be. Some of the other models are one size fits all. Here's the framework. You gotta do this.

(Jason (CISO at HITRUST) at 01:03:16) You gotta do 100% of it. If you don't do 100%, you don't meet. That's crazy. Where is that ever the case? Again, perfect security, not the thing.

(Jason (CISO at HITRUST) at 01:03:25) So ours is customizable and tailorable. You go in—there's a core set of controls that everybody should do, lean, good, basic hygiene. Beyond that, you can say, I'm in this industry. I'm in this geography. I work with this kind of data.

(Jason (CISO at HITRUST) at 01:03:40) I'm subject to these kinds of—this is what my technical environment looks like, or I'm subject to these regulations. And our platform will help you determine everything that you need to do to make good on all of those asks. So every one of the pain points I've had for the last 20 years as a CISO, I'm helping solve here, and we're bringing those things to market every single day. And this is not—like I said, this is we're changing a wheel on a moving car. This target keeps moving further away.

(Jason (CISO at HITRUST) at 01:04:08) In fact, sometimes I'm worried that the desired end state is moving away from us faster than the progress that we can make towards it. So if there are folks listening to this podcast who say, that's great. I love all of that, but I have these additional things that I would like to see, and I'm having trouble finding a solution for. Send them our way. Let us know which regulatory factors.

(Jason (CISO at HITRUST) at 01:04:29) There's something like 90 new ones that have just been passed in the past couple of years around the world. We can't do them all. Which one should we do in what order? Well, that's going to be very much market driven. So we're hearing from people like that to say, you know what?

(Jason (CISO at HITRUST) at 01:04:41) I'm doing a ton of business all of a sudden in Latin America. I want that Brazil LGPD in. I'm doing business in India. I want theirs brought in. Those are the kinds of things that we need.

(Joel Beasley at 01:04:51) Excellent. And the website, hitrust.com?

(Jason (CISO at HITRUST) at 01:04:54) Uh, HITRUST Alliance. It's actually hitrustalliance.net.

(Joel Beasley at 01:04:58) Hitrustalliance.net. Alright.

(Jason (CISO at HITRUST) at 01:05:00) Yes, sir. So we have a nonprofit, and we also have a different business that maintains the framework. So the framework itself is available for free. You have to be a qualified organization, but it's available for free for download.

(Joel Beasley at 01:05:11) Alright. We'll put links in the show notes so that people can access it quickly. And by the way, I saw—I don't have the list in front of me for some reason. They're not in my notes. But over the—I saw you coming up on the podcast.

(Joel Beasley at 01:05:23) And then over the course of these past couple months, I've seen other websites, other people that are coming on the podcast that actually have the HITRUST logo on the bottom of their website. So people are taking your logo, and they put it on the bottom of their website when they're customers of you. Things like some insurance or health care companies. But it was really cool to see that and to connect those dots. I was like, oh, I'm looking forward to this.

(Jason (CISO at HITRUST) at 01:05:44) We've actually done quite a bit of research, and we've actually been able to get companies a reduction in their insurance premiums, their cyber insurance premiums, if they're HITRUST certified.

(Joel Beasley at 01:05:54) Oh, wow. There you go. There's a benefit. I love it. I honestly, I loved hearing your story.

(Joel Beasley at 01:05:59) You are made for this position that you're in right now. It's like your whole life was leading up to this. And so I'm just so grateful you took the time to hang out with me for a little bit, man.

(Jason (CISO at HITRUST) at 01:06:07) Oh, it was my pleasure. Again, anything that I can do to help out the heroes that are addressing these risks on a daily basis is my passion and my pleasure.

(Joel Beasley at 01:06:19) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn, or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.