Transcript
and information for protecting against today's cyber threat landscape. I'm your host, Rebecca Craddock, and I'm delighted to welcome today's guest. He is an industry veteran who has had an impressive career spanning 25 years in cybersecurity, driving digital transformation and cybersecurity practices across a wide range of sectors, including logistics, retail, FMCG, and finance. He is currently the chief security officer at VetCorps, a US and Canada wide network of nearly a thousand exceptional veterinary hospitals who have built an impressive reputation in medical practice. Andrew Wilder, it's my absolute pleasure to have you on Bad Actors. Thank you for joining me. Thank you, Rebecca. It's been too long for this. We've been talking about doing this for a few years now, I think. We have finally making it happen. So absolutely. Yes. Thank you so much for joining us. You are a busy, busy man. You're hard to track down. So thank you for making the time. So VetCorps, first of all, you know, I'm a massive, massive animal fan. So I actually think you might have my dream job. Tell me a little bit about what VetCorps do. And then we're going to go into the sort of running of what you do on a day to day basis and some of the challenges that you have to deal with in your role. Sure. So VetCorps is what's called a veterinary consolidator. So there's a number of businesses that do these consolidation businesses. They're usually private equity backed. And what we do is we go to a veterinarian and we say, look, you didn't go to veterinary school to do HR, finance, legal, IT, back office. Let us buy your practice at a nice sum. We'll bring you back in as a salaried employee and we'll do all of that stuff for you. And you can spend all of your time taking care of pets, which is what you want to do anyway. And so it's a pretty easy conversation for them to say yes. Yeah, absolutely. And I presume that means everything from a cybersecurity defense posture as well, right? Absolutely. When you buy a single unit mom and pop veterinary hospital, they have done pretty much zero in terms of cybersecurity. So it's a fun amount of job security that I have of continuing to acquire very small businesses. And it's interesting because when you think of it, I guess there's so many different aspects you have to consider. You talk about HR, you talk about the fundamentals of the IT infrastructure. But let's think about this logistically. You've got hospitals that are looking after your nearest and dearest from a pet perspective. And I know my dog's not here today. She's downstairs, but I can't even talk about it when I think about losing her. So you've got people, you're looking after the medical facilities, you're looking after the vet's care of them. You're looking after the building management systems of keeping the lights on, keeping the generators going, but also securing the people that work there and their wellbeing and their personal data as well, right? Yes, absolutely. That's amazing. I'm really excited about this because for those of our listeners who have been following the Armus story for a long time, you are a member, a very longstanding member, maybe one of the originals of our customer advisory board. What has made you keep coming back to Armus all these times that you've been in your different career paths that you've had? Yeah, so I think this holds true for Armus, but this holds true for any vendor. It's really about a long-term relationship. So in each of the different times that I've brought Armus in, it's been for a different use case. So the first one was with Nestle and it was really for looking at OT devices in all of our factories and getting that kind of visibility. A lot of people ask, what keeps a CISO up at night? And the answer for me, at least for me and for many of my peers as well, is the risks that I don't know about. So Armus was there to kind of bring those risks to light. The second time I brought Armus in was at Hill & Brand, and this was an industrial manufacturing company. So we were looking to make sure that the OT security of the devices that we were shipping out to our customers was up to snuff, let alone our own OT environment as well. And then this use case is really around asset management. So asset discovery and asset management and security of those assets, and also some bone prioritizations and really neat stuff there. So it's because we have that long-standing relationship, I know that Armus is able to deliver on each of those different use cases. And when we have specific needs, they're always able to kind of pivot and help us and build things to support out those needs as well. So for me, it's really about that long-term relationship. And as you say, as being part of the customer advisory board, I think you have a unique insight into the development of Armus as a platform, right? So because you have seen different use cases, different parts of our platform, you're able to really help define how we develop our technology, what we put on our roadmap, and some parts of the new innovation for the future, where we're starting to think about early warning threat detection, we're starting to think beyond the scope of our current capabilities. And your insights, I think, especially with the career you've had in different sectors, has really helped guide some of that practice. Yeah, well, I appreciate that. I'm doing my best to bring value to the advisory board and Armus has continued to bring value to me. So that's why I keep coming back for it. Oh, that's good. It's a good partnership. So I want to talk a little bit about the role of the CISO. One of the things we hear the headlines always commenting about, it's just overwhelming level of data, a lot of people leaving the practice at the moment, moving on to other things. We see a negative downturn of the focus of the role and how difficult it is now. What do you think are the challenges that you're faced with now, as opposed to, say, 10 years ago? I will say my current role at my current company is the best role that I've ever had. We're privately held and we're unregulated. So that really allows me to do real cybersecurity. A lot of my peers in heavily regulated industries, who I know you know very well, they really have to do compliance first before they can do security. And compliance definitely does not equal security. Now, in terms of the role and the risks overall, those continue to grow. We see a lot of CISOs in the news. Some people joke it's the chief scapegoat officer. A lot of large businesses, publicly traded businesses, when they have a breach, their action plan, one of the first things is to get rid of the CISO, which is the worst thing I think that you can do in that scenario. So, in fact, when I was at RSA a couple of weeks ago, we talked about this on the stage there. We talked about the whistleblowers and how to protect yourself as a CISO. And I think there's a lot of things that we need to do in terms of D&O insurance, personal legal liability, documentation, negotiating your severance package ahead of time. Those are all things that can help the CISO to act with independence and make those right decisions at the right time. That's really interesting because I've had a number of customers on this podcast, and you're the first person that's really talked about the role in its entirety of, you know, sort of getting ahead of potential problems. Do you think that that role of the CISO has changed at a board level? Do you feel like you have to defend your, not in your current role, but do you feel you have to defend your role? Many people do feel like that. Yeah. You know, if you think about other roles in the C-suite and as they go up into the board, those roles are very well established, right? We've had CEOs for centuries. We've had CFOs for centuries. We've had head of sales and even head of marketing for a very long time. The CISO role is in its infancy. So we have to constantly be advocates for ourselves. And a lot of it depends on the culture of the company. You see certain companies where on the board they will have a cyber committee or a risk committee or a technology committee. And those companies are clearly leading in terms of putting this first. A number of companies still put cybersecurity into what some refer to as the audit committee junk drawer of the board, where it's one of many things that they look at. And so they're not giving it that level of priority. So yeah, we have to constantly be representing ourselves to have a seat at the table, to be seen as someone who understands the business and business priorities, and then is able to put a cyber twist on those things and help move at the speed of business. And I think that's so interesting because what you're describing there is sort of a very now moment role, but also we know within Armisen and working with you and other customers, that there's also an element of the job or maybe 50% of the job, which is focused on the future, digital transformation, getting ahead of problems in advance. So how do you then balance the priorities of everything you've just said, compliance regulation, responding to board requests, all the things that you're trying to defend against, but also planning for the future? That's a very loaded question, Rebecca. There's a slide that I use at the class that I teach at the university, and it says the role of a CISO. And the font is so tiny. It's like one of those mind maps. And the font is so tiny that you can't possibly read all of those things. And I say, here are all of your responsibilities. But in reality, human beings are not good at focusing on a thousand things at once. And if everything's a priority, then nothing's a priority. So what I do is I find the top two or three things that my team needs to focus on, and I make sure we do those things really well. And then I protect my team against all of these different things that you're talking about to make sure that they're not getting bombarded with all these kind of outside requests. Because as much as we want to be helpful and have a good relationship with the business, we also need to say, hey, we need to do what we're here to do first. And then we can help people as well. That's how we do it, is focus. Yeah, I love that. And I think it definitely has evolved, as you say, over time. Is it easier to sell or talk to the board about budget requirements now? Is there more awareness of your role and what is required today to keep the lights on and to keep transforming elements of the business? Yeah, so I would say kind of at the midpoint of my career, about 2012, we saw a real shift in terms of business understanding of cybersecurity. Before that, we were a cost center. I was banging on the door of every CIO in our business to say, please, please do cybersecurity. And after that time, when it started to become something that was known in the news, the CEOs were starting to ask questions like, how are we making sure this doesn't happen to us? Absolutely, it's more forefront than it was in the past. I wonder, though, what keeps you up at night? Because if there's been this evolution, and there has been massive leap forward in understanding and development of the technologies, we're always worried about the next threat. Everyone says, geopolitics is at its all time worst. There's a big threat from cyber warfare, AI, what does that mean? What actually keeps you up at night when you're thinking about what to do with your own environments? Still, for me, the answer is those risks that I don't know about. Now, those could be future risks that I don't know about, or those could be risks within my environment that I don't know about. And again, we try to focus on the three biggest things that we think are going to reduce the material impact of a cyber event in our organization. That's what we're focusing on. Once we get one of those things done, we'll look at what's the next thing and we'll add that to the list. Do you find yourself still spending any time on educating and awareness within your organization, though? Or do you think those times have moved on significantly? So, we do. I'm of the strong belief that the cyber awareness program as it is today is broken. It's a check the box exercise. I don't think people are getting a lot of value out of it. There are some things around human psychology and just-in-time training. You know, if you try and go on a bad website, it pops up on that website and says, hey, don't do this. So, there are some innovations in that area. But I think if we look at kind of the dinosaurs of the awareness industry, they're delivering the same old stuff and it's not really effective anymore. That's interesting because I think people often say, oh, you know, there has been so much more awareness made in the general public as well as within organizations of what cybersecurity is and the risks posed. But someone was on my podcast a few weeks ago and they said people still fall for the text message from the CFO trick. And that's just so basic now that we still, there's so many aspects of what we do that people haven't moved on from. But what you're saying is more of a tick box exercise in your view. Yeah. You know, you and I are part of the industry. So, for us, it's really obvious and it's kind of common knowledge. But, you know, the reason that people are still falling for that is because it works. Like, they keep doing it because it works. So, it's, and a lot of people are of the belief that I'm not important enough. You know, nobody wants my information. You know, every threat actor that's out there, they want your information. They want your financial data. They want to be able to do something, you know, nefarious with you and you need to protect yourself. And it's unfortunate that the awareness that we have today is not really helping people. No, it is true. I think there is that still, well, it won't happen to me, sort of environment. And yeah, nothing could be further from the truth. There's so much data out there now. You probably have already been, you know, you've already lost your data already and you just don't know about it yet. That's probably more of the scenario we see, depressingly. I want to talk to you a little bit about your other role, your teaching role, because I'm interested in this sort of next generation, the next generation of cyber professionals, what they're going to have to be faced with and the impact of AI. Can you talk a little bit about what you see from your lofty view of university teaching? So, the course that I teach at WashU is called Executive Cyber Learning Program. And this is where we take CIOs, CISOs, or maybe CISO minus one roles like VPs or directors in cybersecurity and equip them with the tools to be ready to be a chief information security officer. You know, there's another organization that I work with, Rebecca, called Cyber Up. And Cyber Up does, they do sessions with kindergarten through 12th graders. So, they're inspiring the next generation of cyber leaders. And then at the career level, they take people and give them six months of free training, certify them, and then place them as apprentices. So, I'm able to see kind of all stages of the cybersecurity evolution. And you're all right that I think AI is going to change a lot of that. You know, I think kind of low value tasks are going to start to be automated by AI. So, you need to figure out how you level yourself up to be ready for those higher value tasks. Yeah, I think you're right. There's a lot of worry, I think, in the sort of generation that's coming out of university and looking to that get that foot in the door, that those roles aren't going to be there. But like everything, they evolve and the nature of technology is to be embraced, but also to be wary of in equal measure, I find. One final question before I know we have to finish. What is the one big piece of advice you would give to organizations trying to tackle the current cyber landscape? Wow, that's a loaded question too. I think for me, it would depend on the organization. So, I'm going to give an answer for a small and medium-sized business, and then I'm going to give an answer for a larger business. So, if you're a small and medium-sized business, it behooves you to get an independent cyber leadership opinion on what you need to do. So, find a virtual CISO. You could go through your MSP or your MSSP, but they are probably a little bit biased towards their own services. So, getting that independent opinion, I think, is going to be really valuable for you to focus your finite resources on what you need to do. Now, if you're in a large organization, you probably already have cybersecurity established. I think some of the things we talked about today, like knowing all of your risks, right, that's a huge thing. And then once you understand what all of your risks are, I think prioritizing and blocking out all of that other noise to focus on your top two or three things, I think that's really important. Yeah, no, I think that's really good. And we talked with Nadir a few weeks ago about sort of the foundations of everything is all about visibility. And to your point, really understanding what you have is a first step to pretty much the open door of everything else. Thank you so much for your time today, Andrew. I really appreciate you joining us and look forward to seeing you soon. It's my pleasure, Rebecca. Thank you. Cheers. Thank you.