Using the New Toys to Solve the Legacy Issues - An Interview with Scott Laliberte of Protiviti
Interview with Scott Laliberte of Protiviti:
Cyber Security Dispatch: Season 2, Episode 09
Show Notes: Today on the show we speak with Scott Laliberte, the former Information Security Systems Officer for the US Coastguard and Managing Director and Global Leader of the Cyber Security and Privacy Practice at the global consulting firm, Protiviti. In this episode, we discuss the necessary mindset shift that CISOs need to make and why we need to be using new technological toys, like AI and machine learning, to solve legacy issues. Scott shares his findings on how CISOs need to and are starting to talk the business language and how the changing narrative of what security does for business can lead to a more cohesive enterprise. We find out why acknowledging weaknesses, foregrounding transparency and “talking the talk” can lead to a CISO’s longevity and success. In addition, we discuss the tech skills shortage and how the industry is working to create a balance between the experienced workforce and the new kids on the block.
Key Points From This Episode:
- Find out more about Scott and his background in the industry.
- Using newer technologies to mitigate risk issues.
- The importance of measuring vulnerability and patch programs.
- Speaking in business terms versus technical terms.
- Addressing patching and hardening caused performance issues.
- Resolving a CISO’s mandate versus the line of business mandate.
- What are the guiding principles of organization collaboration?
- Getting the business to realize that they are the brakes on the car.
- How do we define world class security?
- Why the best security is secure but transparent to the end user.
- Why CISOs have to start explaining problems in business terms.
- How a CISO can still stay relevant knowing that a threat is out there.
- Find out why CISOs need to start acknowledging their weaknesses.
- How CISOs can make the shift from tech heads to business leaders.
- Companies are realizing they need a more business-minded CISO.
- Managing CISO fear and how to ensure a long-term position.
- The common trait that Scott sees in successful CISOs.
- Why unsuccessful CISOs don’t want to be the bearer of bad news.
- Are we really facing a cyber skills shortage?
- And much more!
Links Mentioned in Today’s Episode: Scott Laliberte – https://www.linkedin.com/in/scott-laliberte-1629551/
US Coastguard – https://www.uscg.mil/
Protiviti – https://www.protiviti.com/US-en/
Protiviti on LinkedIn – https://www.linkedin.com/company/protiviti/
Spectre/Meltdown – https://meltdownattack.com/
Coleman Group – http://www.colemangrpinc.com/portfolio/cyber-security/
The Evolution Of The CISO Role And Organizational Readiness – https://www.csoonline.com/article/2838371/security-leadership/the-evolution-of-the-ciso-role-and-organizational-readiness.html
The New CISO: How The Role Has Changed In 5 Years – https://www.csoonline.com/article/2126087/it-strategy/strategic-planning-erm-the-new-ciso-how-the-role-has-changed-in-5-years.html
Facebook CSO Alex Stamos To Leave The Company – https://www.cyberscoop.com/alex-stamos-facebook-ciso-resigns-steps-down/
RSA Conference – https://www.rsaconference.com/
Introduction: Welcome to another edition of Cyber Security Dispatch, this is your host Ashwin Krishnan. In this episode, Using the New Toys to Solve the Legacy Issues, we speak with Scott Laliberte, the former Information Security Systems Officer for the US Coastguard and Managing Director and Global Leader of the Cyber Security and Privacy Practice at the global consulting firm, Protiviti.
Scott shares his findings on how CISOs need to and are starting to talk the business language and how the changing narrative of what security does for the business can lead to a more cohesive enterprise.
TRANSCRIPT
[0:00:41.1] AK: Welcome everybody to the Cyber Security Dispatch, this is a series of podcasts that we’re doing, bringing in COD leaders both from the vendor space as well as the practitioner space, talking about security and privacy but more so from a real life perspective, rather than just pontificating about what should happen.
In that context, I have today with me, Scott Laliberte and I will have him introduce himself because it’s too much for me to talk about. So go ahead Scott.
[0:01:07.1] SL: Thanks. I’m Scott Laliberte, I’m a Managing Director of Protiviti. I’m the global leader of our cyber security practice, been in that role for a little over a year now but I’ve been with the firm since the start. I’ve come up through those ranks leading our technical security services arm and prior to that, I ran IT for the US coastguard many years ago.
Right now I’m kind of helping clients manage all the challenges in cyber, trying to keep up with the latest threats and do that while balancing that with the need to do business quickly and in a cost-effective manner.
[0:01:36.2] AK: Wow, okay, you just said something that if you can do that then there will be lots of followers who would say “Hey Scott, how will you do that?” Let’s talk a little bit about the report that just came out, I believe recently, as recently as Monday. Okay.
Can you talk about like what are some of the ‘Aha moments that were new but also a reinforcement of things that we knew all along but just saying “Hey, this thing continues to plague us.”
[0:01:57.7] SL: Sure, yeah. The report covers nine years of scanned data that we have accumulated so it’s all the deidentified data, of course. But we wanted to look at that historical trending to see, have things gotten better, have things gotten worse?
What we saw is that, it’s pretty much stayed the same, there’s been some ups and downs from years to years but there’s still a lot of high-risk vulnerabilities that exist in environments. Many of them are very old, still a lot of outdated operating systems that are out there and it just doesn’t seem like we’re making a whole lot of headway with that problem which is compounding a problem with all the new threat actors that are out there, the constant bombarding.
These just present numerous avenues by which attackers go in. We’re not winning the battle on that front. Until we do, it’s going to be very hard to make strides forward.