SEC Cyber Incident Disclosure and Cyber Risk Mandate: How to futureproof your cybersecurity program
all right thank you everyone for joining us um this beautiful Wednesday no matter where you are in the world morning afternoon or evening or even on demand um we're very excited to be here um to talk about the SEC cyber incident disclosure and what you should be thinking about doing with it because it's coming up fast at the end of December many of you are going to have to comply I've got a few housekeeping tips before I jump into to uh or might turn it over so our so our hosts can jump into the subject um we will be recording this so um just know that you'll be able to share it with your co-workers that aren't able to make it today there is a Q&A button at the very bottom please use that to ask questions um we will be checking it throughout the webinar and we'll make sure we get as many questions answered as possible if we don't get to your question we'll be sure to follow up um after the event you'll be prompted to fill out a short survey um we really do appreciate your feedback if you we want this to be interactive so please do ask questions we um we want to hear from you and with that I am going to turn it over to our illustrious panelists um Angie Redfern and Melissa coo can you please uh go ahead and introduce you guys yourself yes hi everyone thank you so much for joining us my name is Angie Redfern I'm the director of Enterprise risk and issue management for service now and I've been with service now for about N9 years um when I started we had 2,000 employees and now we've grown to be almost 23,000 so we've had a lot of growth um we have uh started our Enterprise risk management program about four years ago and so I helped create that and I'm fully maturing it and so we're excited to talk to you today about all the different things about this um cyber risk mandate hi everybody Melissa thank you Angie my name is Melissa caho um I'm the global practice strategist for security risk and resilience at new rocket which is really a long title that means that I am responsible for helping organizations stay at The Cutting Edge of where risk and security is going within the industry helping build out the correct Solutions creating the cultural change necessary to support those Solutions and really being successful in both your cyber risk programs and your cyber Security Programs as well as risk management as a whole um um I've been at new rocket for almost nine years and prior to that I spent quite a bit of time working for the banks so um I've worked in it risk management cyber um working in it Disaster Recovery Etc so I'm really happy to be here today and to talk about um the Cyber RIS mandate so first of all we do have a poll question um and we're all curious to hear from you about how prepared are you for the SEC cyber incident disclosure and cyber risk mandate totally prepared somewhat prepared not prepared at all um so we're just going to kick off a poll here we'd love to hear your feedback and get some um information about kind of where you stand and how comfortable you are all right we've got some people filling it out I like the polls because you can really get a sense of you know who's listening and and honestly you know you guys can tailor some of your comments to you know Le the folks yeah absolutely okay well it looks like in the poll here we've got um about half the people are somewhat prepared and about half the people are not prepared at all and then slightly less are are totally prepared okay it's not I'm sure everybody is a little better in an uncomfortable place but it's kind of a good thing because that's what this webinar is for if everybody had answered they were totally prepared we probably would have I probably would have asked that everybody to get off camera so we can hear how you're totally prepared so it's good to know that this webinar is going to be incredibly helpful before um we really dig into it we do want to talk a bit about how incident disclosures have been mandated earlier and earlier so we have everything from 60 days to six hours a variety of mandates as to if you have data exposed to whom you must notify and by when and it's not getting easier it's just getting harder and more important that organizations are very clear as to what is um when do they have to actually disclose it and doing so as quickly as they possibly can to avoid the negative impact and the new SEC rule does require that um public companies and we're going to deal with it go into this more a bit more in the next slide but it needs to be done within four business days there are three key elements to um the Mandate the first one is the disclosure of material cyber incidents and applicable incident trends within 4 days so if you've had if a cyber incident occurs which is defined as material and we're going to go into that a little bit more into the further into the deck or if you're identifying a trend of incidents which become material it must be notified within four days you also must have an annual disclosure of your cyber risk program and describe the board of directors oversight um of of risks from cyber security threats and this one I think is really important I actually think that the the last two are really the critical foundational elements that really lead to the overall goals that the SEC is trying to accomplish um the other thing I would add is that what I'm starting to see and I think Angie you've been sort of in a similar position is that as these mandates are coming in it's just becoming more and more important for organizations to not just check the boxes within the Mandate but actually look behind the Mandate and say well what is the the genuine problem they're trying to solve what is the result they're looking to achieve and how do we accomplish that so that we can we can not only handle this mandate but any potential future mandates as well let's start with the disclosure of material cyber incidents couple things your organization can be doing first one Define materiality and provide training to your cyber security incident response teams and and impacted teams yeah and you know Melissa this is super important because if you if you the legal description of materiality is very vague and so it's really important that each organization really looks at theirselves and say what is it that makes something material to us because it may not be just a number right may not just be some number of financial dollars it could be the amount of offices affected or it could be any variety of different components that they want to include that defines materiality and without having the definition of materiality what happens is then everything becomes noise and you don't know what needs to be reported and what doesn't so that is really the most critical thing to do at the very beginning is get with your other teams get with your cyber team your security team your legal team your risk team and really sit down as a cross functional collaboration group and make that definition um so that everybody agrees you know run it by Finance the all the different departments that you may have to make sure that everybody understands what material means so that the minute that that happens we can start talking about some of the other processes that need to be defined as well and I think the important thing to mention is that material for one organization may not be material for the other organization this is not a one-trick pony that you're going to be able to implement and apply across the board every organization really needs to look at what material means to them looking at the size and scope of your organization and also what's important to you what's important to your customers what's important to your investors and making sure you define materiality um and Angie when you and I were talking about like preparing for this piece before you had mentioned it's difficult and you should not have somebody come in and just say okay this is what materiality is so for everybody who's on the call who is really hoping that we would tell you okay this is what materiality means I'm sorry we're not going to be able to give you that information and nobody should because it should be unique exactly it really has to be accustomed to that particular company and that and what's important to that company um the other thing that goes with this is as you're defining materiality right it's important to realize that you're going to have things that are going to fall outside of that scope and so really you need to make sure to refer to your one trick pony comment Melissa is that you need to have multiple playbooks available so that you know when a m um you know security incident arises that you know exactly what needs to occur versus a different kind of cyber incident or a different kind of exploitation that needs to be um you know followed up on as well and I think you actually you just teed up our second Point perfectly it's almost like we planned this um and it's starting to build up a companywide cyber incident plan and performing a tabletop exercise so you have playbooks usually in cyber security how do you handle malware how do you handle fishing this is more of a broader umbrella cyber incident plan that allows your organization to say okay here are all of the steps if I have a material cyber incident or a significant cyber incident here is how once it's once it's been defined and here's the definition once it's been defined who tells whom what by when who talks to the board how frequently um who talks to the media if it's applicable how frequently Etc excuse me exactly and the thing that goes with this too is that as you're performing your tabletop exercises make sure that everything that you do is auditable because you can use all of that information in any kind of audit that comes or if any of your customers want to audit you and you can use it in any kind of certification so you can actually use those tests for multiple purposes so that you can get as much functionality out of them as you can and when you're doing the test you will see if you haven't defined roles and responsibilities very well that's going to come out when you actually perform the test so having a plan is one thing testing your plan is a whole different ball game and it's super important because you think people understand what they need to do but when you actually run the test it really does show if those rules and responsibilities are fully defined exactly this is very much like business continuity and it Disaster Recovery where you do have a series of plans on what is defined um like what will happen when something significant goes wrong and given the technical footprint of the majority of organizations I think that's critical third create a culture of early notification and responsiveness from the board down um what this really is is this is making sure that um everybody feels comfortable and are not concerned with speaking up and bringing up I um incidents that may be material or that may have a significant negative impact it's not but it's not simply about speaking up it's also about being heard and that information being taken in and reacted to so this is really creating a culture where it's like it's everybody's responsibility to speak up and then who acts is clearly defined what their expectations of them are clearly defined and making sure that there isn't a culture of sweeping things under the rug because what has happened and what will continue to happen is organizations are being held responsible if they are not acting quickly enough and some of this is starting to to set set it up so that if there are holes in your program or if there are holes in the way that you're setting things up you will when you are exposed when the incident happens hindsight's 2020 and organ like your your regulatory bodies are going to look back and say well why didn't you fix that hole so making sure you doing you're doing everything you possibly can to to communicate clearly is incredibly important yeah I totally agree with that if the other thing is if you aren't keeping your board notified and you aren't keeping your board educated then they may not understand some of the importance of the different cyber risks that can occur so again it goes back to not only do you have your materiality defined for yourselves but you need to make sure the board also understands that definition and that there's a clear communication path so that anytime that that happens you can get to the board or to the level of executive management that you need to very timely because you only have four days to actually do the reporting exactly Yeah we actually have a um I think a good comment and and a question um in the chat um so this is one of listeners once we Define and strategize what is material what material means for my organization what is the next step how do I know I comply with sa99 is this something I can work with the SEC on and sync with them upfront does the SEC encourage this upfront engagement the really good question and I'm actually see both Angie and I thinking through I have not personally seen organizations working with the SEC UPF front um now and and I don't work directly with the SEC I usually help organizations become compliant by helping them build out the overall program I'm not sure if Angie because I know that service now has worked on making sure that they're compliant and responding if you Andie have any insight in into that so I haven't worked with the SEC either but I do know that in our scenario we have consulted with third with outside councel and so you probably will have better results if you can actually talk to outside counsel um I know that I have you know spoken to different government officials and they're going to turn it right back around and say what do you think is you know material for your own using the the legal definition of materiality so I think outside Council would be a better option for you because they'll have more experience in terms of really getting into the details of different levels of companies different sizes different markets um than the SEC would but like I said we personally haven't tried that ourselves so I don't know maybe try it and come back and let know how it works if you want or yeah I wouldn't say no 100% but I I would personally lean towards outside Council as well um where you have outside council with experience with the SEC that's probably the fastest way because if you think about the entire breadth of scope of the SEC possibly trying to get that get it from them directly might be more time consuming than valuable but I do think it points to the fact that once you have materiality defined right you have to have the Buy in from your your legal department to make sure that they agree that that is a good definition but once it's defined your next steps are going to be starting to create the communication paths the um your incident plan and then make sure you have a test for your tabletop exercises you know you can use a platform like service now which helps put all of that information into your your tool or your platform to spin up your Bridge or to send out notifications or different things like that so whichever GRC tools or incident response tools you happen to be using um and if you don't have a tool then I would say make sure that you at least have like templates created and you've identified roles and responsibilities and those are fully documented somewhere so that you at least have something to fall back on and that you can show your Auditors yeah no I completely agree and um so both Angie and I work with service now extensively and we're both proponents of service now but I will say for some organizations Excel is okay hey so long as it's your your volume isn't so big and your needs aren't so big that it can it it's over like it's it's making it too difficult to work um really the most important part is the process that it's auditable that you have Buy in from the outside Council and that you have it controlled enough to be successful and it meets the needs of your organization where it is today yeah I just want to add reportable to that as well absolutely because now if you have the tangential incidents right so two months later you have another incident maybe it's not Material material by itself but in relation to the one that's already been reported it could end up falling in that category so what they're doing is they're trying to say anything that's relational to that material incident needs to be reported as well and if you can't do the reporting to see prior and past and all that stuff then you're you're you could miss some and then you know you could be in for some SEC findings completely agree really good point I actually want to go back because I I can see the question in the chat as well where you were asking about sort of like the next step I will I will say Obviously like defining materiality in the reporting is a very important part of the SEC mandate but it's not the only part and I would say like once you've defined materiality the next step is to take a look at what is your cyber risk program looking like look like so there is the annual disclosure of the Cyber risk program and I would say that the meaning behind this isn't simply filling out the form on the annual basis and and indicating okay I have a program and this is the program or actually saying I have no program um I I I do believe that this is going to it's important that organizations take a look at their cyber risk program and make sure that you are really focused on predicting and preventing annual or pardon me um material events as well as making sure that you're prepared for them and you're able to respond and move on from them as quickly as possible and that's really your cyber risk program so it's important that you have an organizational understanding of your attack surface and threats number one thing if you don't have this you can't really move forward I think this too um actually you can use your BCM plans for this because within your BCM plan right you should have identified your most critical business uh processes your most critical systems and services and apps and so that's going to help you lend into this number one because that's going to you know that's going to um go into what you define as material as well so this kind of will help support if you're having a hard time getting some you know buying into your BCM or your BCP plan trying to get management this is going to be one thing that you can use to help with that is to say hey we have to have this defined so that we know what's material so that can help that might be able to help get you know give you a little bit more um bigger stick to to swing so to speak so that you can get some more Buy in into your BCP plan because it all feeds into this absolutely it's also um a statement for having a really good asset management database and having automatic discovery of your assets so that because organizations you're bringing up assets you're bringing them down all the time there's things that are temporary there are things that are brought into your network they may actually have importance at that time so it's really important that you have a flexing and changing um asset database that is tracking what's going on so when an incident happens you wen't trying to figure out what is the criticality of this asset what does it contain what like does it have personally identifiable information um does it have like financial information does it have anything that's confidential that information um having it at your fingertips results in a lot less turn and makes your makes it a lot less friction to define whether an asset whether an incident is material pardon me material or not exactly and the thing that goes with that as well is that once you'' have that defined and you figured out what system services and apps are important to you and you can map them to actually your business and the different lines of business or the different functions that you perform in your business now what you've actually done is you've Associated those different you know assets to an actual piece of your business so then you can go on and form your risk universe and with that being done now you've been able to associate you know all those different systems to a specific risk and all you have to do is fold in your controls and now you're full 360 exactly you also need to be identifying your potential exposures to cre and create a plan to correct so if something's wrong you have a vulnerability in your environment or perhaps you have a failed control or a misconfigured asset you need to identify them so that you can close those as quickly as possible and make an incident less likely yes I totally agree with this sometimes you know when we're actually fixing things we have a tendency to take the oh let's get the Quick Fix in and then the long-term fix May did get deprioritized and so this is one thing that because you have to report those tangential incidents need to make sure that that long-term fix gets prioritized appropriately so that you don't have those repeats or those things that are relative to it repeats so it also is a is another you know thing that you can use to help really get some of those things prioritized some of those things that maybe need to have been done for a while but just couldn't quite get enough priority to them this is this is going to be another way to be able to do that exactly it's another method of being able to prioritize what the work um your it teams and your cyber teams need to do to help make sure your assets are appropriately protected and again this is all about trying to stop that incident from happening so that once an incident does occur and unfortunately it's inevitable that it will occur you can at least look back and say we did everything we possibly C could to keep that from happening yes and you know the thing that goes with this that we forget about sometimes is the the Cyber forensics that should occur so if you do have an incident that happens making sure that you do fully look at your logs look at all of your you know different monitoring and and threat vectors and make sure that you are noting some of those different types of details so that um once again if the C comes back to you and says what did you do about it and how did it affect it you've done all the Cyber forensics already when all the logs are available to you versus six months a year down the road and you're like oh my gosh we that's in some tape backup somewhere it's going to take us however long to get that up exactly last but not least and this has been a bit of an undercurrent of what Angie and I have been talking about which is connect your exposures to business risks and potential loss so that you can prioritize it and really what this is is it's starting to align your business context to your cyber risks so that you can you can actually qualify or quantify how bad could this be if this exposure was exploited you have a vulnerability on an asset that's sitting under somebody's desk that one person uses and has no confidential information that's a low priority even if it's a high severity vulnerability you have a medium severity vulnerability on an asset that contains your pii information and you have um and you're in scope for gdpr p something along those lines and of course obviously the SEC mandate that's a higher priority that should be fixed yeah the thing I love about this one is that this really starts highlighting that cyber risks are no longer just cyber right right they actually can affect every aspect of your business and all of your business owners need to understand how their data plays into the Cyber risks that occur and so you know in service now we use our own modules and so what we've doing is we are actually um we actually do associate some of the different risks that we have with the different incidents that occur um because using the platform you know you can you can pull in incidents defects stories demands all kinds of different pieces of data that you need to and we um Can associate them to our risk universe and that way we can do reporting across the board so we can see the impact on the likelihood of the different level of risks the impact and likelihood of which ones rise to the top and then you know be able to do a heat map so we can we actually have data to underscore where we have um plotted some of our different risks exactly and the thing is is technology does not exist in a vacuum and even though our organizations are built on silos simply because of the history of culture and the world um silos don't mean anything when everything is interconnected even if you're organizationally built in silos you're in a cyber team or a technology team your business is using your technology your business owns the data that's in it your business in a lot of cases are the ones that have the money so being able to connect things to the business risks is critical um I have a colleague who always talks about how no one actually wants the technology you want what the technology can do that's really good point actually yeah yeah and they you start talking about your potential loss yeah this one can be really hard because it's hard to get that level of data um but at least this way once you start looking at your asset management and you start figuring out which assets are important you can at least start tagging some even just some simple dollars to it even if it's just the cost of the server and bringing it back online right so it at least starts giving you some ways to get to some level of data and dollars um because that's something that's very difficult to do is associate the actual dollar amount with the Cyber risk agreed and I think that a lot of people are worried when they put um a monetary value to a risk or to an asset that because they worry about being wrong the reality is though is that if it's right until you have something better and then you just move on to something better and as long as you've kind of got everything out at an even so long as everything is like equally incorrect you're still going to have a directional piece of information that you can use until you do get something better and unless you start to add monetary value you're never going to find that better answer you're never going to realize boy I really like that it's right until something else comes along better to prove it wrong that's a great point because I think we you're right we do we're we're afraid that we're going to misrepresent or we're not being detailed enough and I think sometimes we overanalyze it and over engineer it so much that we make it so complicated whereas just start with the basics yeah just just start with what you've got so now that we've ident we have an organizational understanding of our attack surface we've identified the potential exposures and we have a plan to correct we've also blunk all of our exposures to business risks so we can actually accurately prioritize the next thing we need to be looking at doing is having a defined Security Council so to be looking at the overall picture and this actually if anybody has the ISO certification is requires you to have a security Council and to have official minutes and to actually go over all of your um issues and risks certain number of times a year whatever you define in your sop but what this is going to do this is going to give you a clear communication path that's been established right so once you have the security Council you can comprise that of people from the business or your ceso or people within cyber risk but at least you have a group of people people who are going through and looking at all of your cyber risks they can start taking into account the past they can take into account you know start looking for Trends start looking for some commonalities so that you're proactive and you're ahead of any breach that might come along you know you've already pre-identified all the things that that might be susceptible to um you know Insider threat or a malicious hacker or whatever uh but you can start you can start with that it's at least your like we said going back to the basics of having a set group of people who are definitely looking out for this specific thing because you only have four days once materiality is determined right right so they give you some Grace in terms of if materiality is there because you have to do some forensics and some research and stuff but once you figure it out you have four days and that's four days to actually file the paperwork so you not only have to know what happened you have to be able to explain it document it and get get it filed in 4 days on an yeah easy you like you have to make things easy and frictionless as possible so that you are like everything moves without um like any problems and any roadblocks of um sorry my sentence just completely fell apart there you need to be roadblock free is essentially yes exactly and this also will help you because now you have security personnel and maybe members of the business who have who have looked all these things before they go to your board so that's another good thing right is because you have an opportunity to look at what's going on you know you could do it quarterly you can do it by annually you can do it monthly whatever your frequency is but just knowing that you have that counsel that that's their that's one of the things that they've taken into their purview and their responsibility and that way when you do go to the board you will have people who have been working on that throughout and not just thrown in the middle of a cyber incident because those major security incidents they happen fast they happen intensely and they are super upsetting to everybody so exactly super stressful um we also need to be creating and this does relate to the security Council but create a regular review Cadence of business and cyber risk with the appropriate levels of management yeah this also helps with ISO as well um because this is another ISO requirement but just from a pure Common Sense perspective once you have that regular Cadence established you start looking at things through a new lens right now you're becoming familiar with the different things that are going on within your or and it also allows you to see what some of the just the regular noise is and really helps you be able to distinguish you know the wheat from the chaff so to speak which is the things that need to rise to the top gives you an opportunity to look for trends for commonalities I I just can't stress that enough because once you start being able to do that whether it's through reporting in Excel or service now or some other JC tool that really helps you being able to understand your general what's happening generally in your business and that way you can start really separating out what's important versus all the other stuff because there's always stuff there's yeah we do have another question this is um probably start with Angie on this you mentioned that you you know you use service now yeah um do you think that service now BCM cmdb combo and I know this is probably not the thing you use the most but um can be used to quantify at least qualitatively or connect the business risks with the potential loss so that you can prioritize better I do and that's because once you get into the cmdb right that's where you can identify first off your business owners for the different things but you can also link the asset assets to a business application on the different tables within the cmdb and then once you do that you can start you can start giving those business applications you can give them priority and severity rankings um now once you've done that and you've got that pulled into the cmdb you can pull those business applications in as entities into risk and compliance and then you can actually start doing your risk universe and your controls and all that stuff going all the way around so that you've actually mapped the controls you can do your testing and control Health that now maps from your cmdb and your business apps into your risks and your issues which is all your remediations so you can use that if you decide to use a cmdb to autocreate your entities I'm just going to encourage you to think about that carefully because you could end up with a lot more entities than what you actually need but you can totally do that if you have a clean cmdb you gosh man the world is your oyster you you can do everything out of that cmdb absolutely um and there's a lot of there's a lot of connectivity within the ecosystem of service now that can start to create that for you um and I do um I know you had mentioned in the question about BCM one of the ways that I've seen organizations do this if you don't have a fully functioning cyber risk program where you're you're you're assessing the criticality if you can actually connect your assets to the recovery time objective that your your business needs from it this can be a quick and dirty way to start to Define your critic of your assets if an asset needs to be recovered within 5 Seconds that's a pretty important asset if it can wait three weeks that's probably not an important asset and that's just a way to without going into a full bore business risk program or like operational risk or Enterprise risk program using the criticality is a good starting point yeah and I would even add to that you can do that on your assets but don't forget your processes and your people the human capital piece of the BCM right is where that whole BCM plan really helps you because you know if you are relying on offshore and then those offshore Personnel are not available due to a flood due to a covid pandemic or whatever right that can throw you into more of a problem than if an asset goes down so um cmdb can help you on the asset portion but then that BCP module can also help you with some of those other aspects of that plan absolutely great advice great advice okay I'll let you guys continue what I was going to say so Angie and I were joking there's no way that we will have to worry about like filling the time because we can talk about this for hours I actually have to keep moving us along because we're running out of time oh all right so the last piece of advice that we we have for you today is describe the board of directors oversight of risks from cyber security threats so the first thing you need to be looking at is increasing the Cyber lit literacy of your board of directors they need to understand the context of what you're talking about so that they can actually prioritize it appropriately and in order to do that you have to make sure that your taxonomy of cyber literacy is the same across your organization and this is something particularly in the risk world that can be very difficult and complex just take the for example the word risk everybody the word risk and everybody means it in a totally different way right yes so um so making sure that your taxonomy uh is pretty much standardized everybody's agreed to it before you present something to the board of directors I highly highly advise because when you go to the board of directors less is more yes be what is it be quick be bright be gone be brief yeah be brief be Bri gone there we go um the other thing I'll mention is that using a tool like service now can actually help you uh cement your taxonomy um and the reason is is that when you talk about risk management risk is a philosophy it's a it's an art um we use English words to describe what we're doing and English words can be interpreted in a variety of ways service now or other technology it doesn't have to be service now um other technology is a science so what you say for the word risk in service now has to be very clear and very well understood and that can be really helpful for cementing what words you use to communicate and then your taxonomy has to come because everybody has to come together to get to to get that resolved yeah the and the thing to remember too is we forget in the IT world right I've been in it for more years than I'm going to tell and um we get into this this this you know language like we have our own language and it right and we forget that not everybody understands the difference between a risk or an issue or even what a remediation is or means and an asset to them is their house and their bank account it's not servers and routers and switches right so it just be very aware that when you're when you're at the level of the board of directors obviously those people are they're not I mean they're there for a reason right they they definitely are there for a reason but they may not have that background and it's very intimidating to get just this whole list that has all these it terms on it it doesn't hurt to put things in layman's terms right and to make sure that they can understand that and that also helps your taxonomy because you're going to have to take the word and Define it anyway so you know that that should just help all the way around agreed cyber security leadership needs to have a voice to the board level and it needs to be accurately heard and understood yes and we as service now our um cyber leadership team they actually present to our board quarterly um and the reason for that is because we have raised it to such a high level in our risk world and it's gotten so much well you know I mean everybody knows about all the Cyber breaches and all the different things that are happening but it's important that the board gets briefed on those Trends because the trends change right for a while it was all about you know individual hackers well then it moved to nation state hacking and then it moved to ransomware and malware like all of those things have their own different nuances and it's important that your board understands the differences between that because like recovery at scale is different than recovery at scale for ransomware because when it comes to ransomware now you have things that need to be isolated and you need to make sure that they can't be you know duplicated whereas recovery scale is more just about bringing up the different assets and the different systems and processes and the orders so there are definite differences and actions that need to be taken based off that and so with your leadership cyber security leadership being able to get to the board it helps keep them AB breast of some of those terms it'll help with your cyber literacy and it definitely will help if there's a material incident exactly and then Define where the board should be this should be informed on business risks and cyber risks which I think does relate to the both one and two well yeah the first time you go to your bored about cyber doesn't you don't want it to be on a material incident no that would not that makes it a very hard trip to the to the board meeting so um you know the sooner you can get in front of them and and just start talking about some of your different business risks and how they're connected to cyber risks and how you've identified you know like I said less is more but definitely like here's our top risks this also will give you an opportunity to um tell the board and to tell executive management hey we want to do a risk assessment right we want to go in and we want to assess all of our even if you don't go down to the asset level we at least want to assess our different functions and determine what we think is the most business critical function so you don't have to approach it purely from an IT perspective you approach it from your overall business perspective because that's what you're supporting and that's what needs to be prioritized the most right and I would say this has nothing to do with the SEC mandate or but really important that you actually show you you you talk to the board about good things as well as bad because what you want to do is you don't want them to only see you like to Angie's point they don't you don't want them to only see you when something has gone wrong because then the perception will make the relationship with the board that much harder um so show the good work and show what's being done before the emergencies happen so that you already have like that Social Capital to be successful and to be able to work work effectively with the board yeah and also you don't want the board to find out something when they read your 10K because when you have to submit your your material incident to the SEC right that's going to be on your 8K well your 8K can be filed all the time but then that can affect your 10q which is your quarterly reporting and then you need to go back and look at your 10K to see if the risk factors in the 10K need to be updated so you don't want the board to see you know to be paying attention to your 10K and then all of a sudden you have a bunch of different risk factors in there because of all the things that had to be filed so obviously you want them to be aware of things before you have to file it with the sa SEC emergency board meetings probably don't go over that great so the sooner that you can get in front of them the sooner you can get them um understanding the different cyber risks that your company faces I then you're just going to be better off completely agreed so we have another question um you've provided a lot of um insight and recommendations um we're talking about the board of directors here but what if someone is not a ciso or a board of directors can you summarize what people should be doing succinctly um to ensure they're meeting the SEC mandates so it's important that every person and every company they have the right and they should self-identify risks and issues right you can call and I know it seems stupid but you could call your whistleblower program and just say hey by the way too many people have access to a server right and and that's what the Whistleblower program is for it's not necessarily for you know you're going to take down the whole company because somebody committed fraud it's all about these little things that can affect your company and you work there and you take pride in that company so I highly advise self-identifying if you are comfortable with going to your ciso or you're you know you have some kind of relationship there with somebody in security you can always do it that way but there is nothing wrong and I highly encourage people to self-identify and if the Whistleblower program is the only way you have to do it do it that way go to your management chain they can go up the chain and over that's another way to do it but if you've noticed something um you know even if it's something like you notice that people are leaving printouts on the printers for days on end and that has pii on it that needs to be changed that is really a high violation of security it seems so simple and silly but it really is I mean any contractor could walk by there or anybody in the building CO walk buy and pick it up so um so yeah that's one of the things I would say Melissa you have another idea the only thing I would add is um that if you are a leader in your cyber team but you're not necessarily in the SE Suite take a look at your your scope of control and your scope of um um sort of influence and try and make that scope of influence as compliant as possible and as resilient as possible the SEC mandate so if you have a team and you know that there are things that you could do that could be better just do it just get started and then what you can do in a lot of cases is you can actually make um be agents of change for your organization because other people will see how your organization your part of the organization is functioning and see how successful it is and how much more resilient it is and you can actually create a Grassroots movement to be successful visit us at our um risk page visit new rocket thank you so much Melissa for all of your great Insight um at their page you know join us on the community there's lots of activities going on you can you can interact in a lot of discussions ask questions questions um provide points of view it's it's wonderful I put the um the link to the YouTube playlist in the chat for all of our community webinars which will include this one in a day or so and then um you know check out the SEC company disclosure sheet that's here and and please register for more webinars I I truly appreciate you know all of your time your insights um the wonderful conversation Angie and Melissa that you had I think it's insanely insanely valuable to everybody um and thank you for for being here and thank you all for joining us that are viewing this now and that that you know are going to be viewing on the man later so again thank you so much we appreciate it than you everybody thank you thank you everybody bye bye
https://www.youtube.com/watch?v=nlc_d-A0Ed4