Transcript
Speaker: Welcome to The Market That Moves America, a podcast from the National Center for the Middle Market, which will educate you about the challenges facing mid -sized companies and help you take advantage of new opportunities.
Speaker: Today's podcast in the market that moves America is about risk. In particular, it's about the threats middle market companies face from attacks on their computer systems or the systems of companies they do business with. I'm Tom Stewart, the executive director of the National Center for the Middle Market at the Ohio State University Fisher College of Business.
Speaker: We're the nation's leading research outfit studying mid -sized companies, which account for a third of private sector employment and GDP, and the lion's share of economic growth. It is the market that moves America. The National Center for the Middle Market is a partnership between Ohio State and SunTrust Banks, Grant Thornton LLP, and Cisco Systems.
Speaker: And with me today to talk about cybersecurity and its implications for mid -sized companies are two special guests. Dmitry Kaczynski is a security principal in Global Security Advisory Services at Cisco Systems. Welcome, Dmitry.
Speaker: Thank you for having me. And also here is Vishal Chawla, the managing principal in the cyber risk advisory services practice at Grant Thornton, the audit and advisory firm. Vishal, thank you also for being here. Thank you for having me. Look forward to the discussion.
Speaker: So let me begin with just a couple of points and maybe a little data to set the stage. The first point is that just about everybody agrees that cybersecurity is important. We asked middle market executives about that and just 14 % shrugged their shoulders and said, yeah, cybersecurity is no big deal. The others all said it was a big deal and more than a quarter said that it was an extremely important issue for them. So it's a concern for more than seven out of eight.
Speaker: But when we then asked the same executives what they were doing about this concern and what they were doing about protecting their information assets and their networks, fewer than half, just 45%, told us that they have a cybersecurity strategy that is in place and has been reviewed and updated within the last year.
Speaker: So there's a disconnection between what companies say is important and what they're actually doing about it. I'm going to guess that that gap exists for a couple of reasons. One, some people aren't really convinced about how important it is. They're not going to worry about it until they are actually hacked or actually know that they've been hacked. And so they're not convinced about what their level of risk is. And so they're giving lip service figuring they can deal with it tomorrow.
Speaker: The second possibility is that they don't know where to start so that they're paralyzed into inaction. And maybe there's a third group that falls in between that underestimates the issue and figures that half measures are enough or just doesn't have the resources to bring to bear. So I guess I want to start with that first topic. How big is the risk? And Dimitri, maybe we can
Speaker: start with you first. I mean, we read about attacks on Target and Chase or Sony or Yahoo. How much do middle market companies have to fear from cyber attacks? It's a great question, Tom. So in our work with our customers from our commercial practice walls, the mid -market size,
Speaker: In my view, the companies don't need to fear, but they need to be very highly concerned, right? When you have large companies from retail, financial, entertainment, as well as technology verticals, getting compromised, there is definitely science for concern for companies on a much smaller scale. I'm also seeing a large progression a few years ago when I talked to several CFOs as well as the CIOs from
Speaker: from several of the manufacturing and healthcare companies. There was very little concern about the breaches, basically. The notion was, well, I don't have something that bad guys have, right? Or I have enough protection that the company around me would be a lot more further compromised than I will be.
Speaker: So today, this notion is changing. So a lot of boards are actually asking this question, well, how we prepared and what is our level of exposure around whether it's medical devices or manufacturing side or basic level of protection around customer records. Boards are getting a lot more engaged into those type of discussions which actually scales to the financials and technology executives within the companies.
Speaker: So are there any industries, Vishal, in your experience, are there industries that are particularly at risk or is the risk across all industries? I mean, Dimitri just mentioned that medical companies and manufacturers sort of thought they were a third or fourth in line. But in your experience now, are we seeing that basically everybody's on the front line in cyber? That's a great question, Tom.
Speaker: based on our experience and based on what you see in the market. I think everyone is going to get exposed to thought. You need to step back and ask the question. If you are a business and you have some kind of asset which can be turned into a financial asset, then someone is going to come after it. We are not talking just about nation states or
Speaker: terrorists, we are talking about criminals looking for money. We have found that actually in the middle market companies, because they don't have too much investment into their cyber program, they are actually the most easy targets. Based on most of the research, industry research, you will find any time the middle market company
Speaker: It has happened so many times. They will get access to their credit card machines. They will load malware. And the biggest threat they run into is putting someone on a ransomware and asking them to either pay the bill or they're going to take over all their assets and steal the money.
Speaker: So I remember ransomware from an episode of The Good Wife, which some people might have seen where this little law firm gets, they come to work in the morning and they get this notice saying, guess, ha ha, we have your computers and unless you send us X thousand dollars, is that how your network is down? Is that what happens? You're absolutely right, pretty much in the same fashion.
Speaker: I was working with a small company, a middle -sized company. Someone clicked it. Sum it up, I think, if you are finishing with an obvious answer. There was a hospital just yesterday which got hacked. Obvious answer.
Speaker: But because there is something critical for you to have assets, understand your risk, understand your risk profile, and see where the movement of cash or other assets happens. So that puts every industry in the bank. So, Dimitri, what happens?
Speaker: when you're attacked. I mean, in the case of ransomware, you know about it because your computers are blocked and somebody's saying, send us a lot of money. But there's an old proverb around cybersecurity, or I guess it can't be old since it's not that old an issue, but there's a proverb that says, there are two kinds of companies, companies that have been hacked and companies that don't know it yet.
Speaker: What am I looking for? How do I recognize that my network has been compromised? It's a very challenging task. Our executive chairman, John Chambers, likes to say, as you mentioned, there are two types of companies that have been hacked to know it and have been hacked and they just don't know it. Because on average,
Speaker: It's somewhere between 200 and 250 days that the company realizes that they've been compromised, right? And it's usually more than half a year, more than half a year, I'm sitting there compromised and don't know it. On average, exactly. And they get a fax or the message or call from a local FBI office saying, Hey, we found some sprinkles of your data.
Speaker: on some server in a different foreign country because they seized control of the server and they found 10, 15 companies' data, so they contacted this company. When the company starts digging into their records, they discover, well, this data left the company 200, 300 days ago. That's how wide of the scale is from the compromise.
Speaker: When companies don't usually realize that a lot of times it starts with a very small, very inconspicuous email, ran from a phishing, targeting executives, targeting, if you're on the medical side, targeting chief nursing officers, if you're on the financial side, targeting tellers. People that have enough responsibility to get a hold of their accounts, of the credentials, and further start digging. In one of the cases we discovered,
Speaker: a hacker basically, when they compromise one of the accounts, they spent additional two, three months reading different emails and PDF documents within the company, trying to identify how the company segmented, where is the most important data lives and which particular service, right? And only then they started crafting different types of methods of attacks. I mean, you have a full blown project management expertise on that side.
Speaker: And it's very, very commercialized, right? Well, you mentioned ransomware. It's a very lucrative business. When you deploy two, three hundred malware pieces at multiple hospitals or manufacturing plants that can just cannot function without them, they would definitely pay their
Speaker: they're 10, 15 bitcoins or 100 bitcoins, because companies don't usually realize that it's not just about the reputational damage. There are different productivity losses that you cannot function without on a regular basis. At the same time, there is also response costs. And the response cost, what we actually studied when we started discovering and responding to a lot of the breaches and advising,
Speaker: a lot of the executives around their response procedures, what we determined, well, they don't have enough connections with the law enforcement. Or when they signed an insurance provider, they have not signed anything a response provider that will work together with this insurance.
Speaker: And at the same time, their legal counsel is not prepared for a wide -scale attack as well as the communication. So they don't have how to actually handle a wide -scale breach. So they would need to have a predetermined relationship with an external legal firm to start those known conversations. So there's a lot of preparation where it goes.
Speaker: in the front, right, before you are able to successfully mitigate the breach response efforts. So I heard you say something very interesting. And Vishal, I'd love you to add to it, which is that one of the one of an important part of responding of cybersecurity is creating defense. We'll come back to that in a minute, because I'd like to talk to talk about that. But a second important thing is so that's prevention, right? I do want my best to prevent. The second thing is I realize I'm going to get hacked.
Speaker: So I need to have a response plan in place. No matter how good my prevention is, I need a response plan. And you mentioned some elements. Number one, I need to know
Speaker: the people I should be in touch with at the FBI or local law enforcement. I need to know my law enforcement. Number two, I should have insurance and I should make sure that I should have insurance in place before I need it, right? Just as you would have insurance in place before you take your car on the road. So I should have insurance. Number three, I should have an internal response plan, a playbook.
Speaker: right, all lined up. I should have my legal defenses, my insurance defenses, my law enforcement defenses, and my processes, and I guess my communication plan all lined up. Vishal, is that a comprehensive checklist? What else do you need to think about so that you have it? You want this thing written down before the panic strikes, right, so that you can turn to this playbook when you have it. What are the other elements of my response playbook?
Speaker: I think that's a great point. I think what Dimitry covered is quite saying. I would say of that couple of things. One, you need to have what I call basic hygiene. You've got to have policies. You've got to do all the confidential records. You want to make backups and stuff like that. But coming to your
Speaker: And then second is, like you mentioned, the plan. The key part of the plan, though, I also see putting incident response plan is understanding how your business really runs. What are things which can bring your business deeply deep and carefully? Turning those items into real use cases and then testing them.
Speaker: So for example, if you are running a restaurant chain, then you've got to figure out what will shut me down. You can have all the clients in the office, but
Speaker: in the restaurant, but if someone loads up the malware and all the point of sale system stops working, you cannot cut the bills. Now someone can put you on ransom. So do you have an incident plan which handles that particular use case? And do you know how to deal with it? So what we are recommending is exactly what the taking from the victory, take it one step further is just to add to it is come out with your use cases.
Speaker: So I think that's a great point that in this as everything has become
Speaker: information technology and all information technology has become connected, you may have vulnerabilities that you're not even aware of and you just sort of have to rethink what are the locks? What are the systems that I'm dependent upon?
Speaker: Or what are my assets? I mean, your restaurant, for example, has all kinds of credit card records that go through its point of sale system. And losing that credit card information could be a very expensive covering. If that information or patient records or other things for a medical practice are lost, those are really serious liabilities for the company and also really serious damage to your customers, which you don't want to have.
Speaker: You're right, Tom. And I would say also, as you are thinking about it, I know sometime it looks easy. Let me go pick up the phone and we'll call the FBI. One of the things we are seeing with some of the clients that they're nervous about is, remember, once you call one of these three left agencies, like FBI, for them, there is confusion in the crime scene. You lose control of everything until they are done with their investigation of the crime scene.
Speaker: Some of the businesses feel, especially in mid -size companies, think about if your business has to stop for just through the process. So you gotta be smart about it, how you're gonna, what's your real risk or how to manage it, when you should call FBI, when you just deal it yourself. Right, so you have to remember to put your business in a really important position. Dimitri, yes, were you gonna add?
Speaker: Yeah, I was going to add something that, you know, a lot of companies fear that the involvement of the law enforcement's right or fear getting engaged within outside companies, research firms or anybody else who kind of oversees different level intelligence around.
Speaker: certain industries. That's the connotation that historically, during the breach, law enforcement comes in, takes all your devices that have been compromised for that investigation if you have nationwide attack and everything else. That is an old way of thinking and overprotective way of thinking. The law enforcement went a long way.
Speaker: With our work around our clients, as well as working with law enforcement, it's a lot more sharing that's going on within the industries, right? With financial services, right, and FSI sec, and law enforcement participates a lot with FSI sec and sharing a lot of the information associated with threat actors, with the risks associated with the business applications, right? They provide a lot more educational aspect versus purely investigative aspect around the notions.
Speaker: as they really are your friend here in a minute yeah and they really are your friend in your experience
Speaker: Obviously, before the breach, you want to make sure that you participate with law enforcement. You get to know the folks who are actually supporting localities around this, which is usually a local FBI office, state police involved. At the same time, there are pockets of different companies who are always sharing this data through the industry associations, as well as the approaches that they share common practices around the protections.
Speaker: share different indicators that they received through third party or commercial sources that they want to make sure that other companies are not compromised. Because as an industry specifically, we are stronger together than individualized providers in this case. It's kind of like an old way of saying, if I'm spending a dollar more than a neighbor next to me, I'm in good hands. That's not the case today.
Speaker: So I hear a couple of things here, and I think this is really useful. One is get to know the relevant law enforcement people early. And if you're a CEO, you should ask your whoever's in charge of cybersecurity, do you know who those people are? Do you know who you're going to call? And do you already have a relationship with them? And second of all, be actively engaged with your peers.
Speaker: which I imagine could be peers in industry or your community peers. I mean, local CEO groups and companies of your size. What about cloud service? I'm a mid -sized company. I've got an IT department of six, 12. I haven't got the deep expertise in this that I'm afraid that I need. Can I just, should I just,
Speaker: work with a cloud services provider, and I know, Demetri, you provide this, so I think your answer's gonna be yes, but I'd love to hear the dos and don'ts about that from both of you, but Demetri, why don't you start and say, what's the case for and maybe the case against outsourcing your cybersecurity?
Speaker: When you look at it, it should be always looked at in connotation to your business, whether you can outsource some functions or outsource functions over cybersecurity or not. If I just take a step back and think about how Cisco is structured, we have four chief executives that are tasked with protecting the business.
Speaker: There is a John Stewart who is focusing on security and trust organization. Steve Mortinos who is focusing on the information security function. Edna Conway on the supply chain. And we recently hired an individual to protect our privacy and reputational aspects. So those are four executives for four aspects of information security.
Speaker: Right. Wow. Exactly. Exactly. And that doesn't mean every company has to follow it. But what I'm trying to say, every company has to understand their exposure and the business exposure around their supply chain. Right. And how they interconnect with other businesses or their customers, which leads
Speaker: to that cloud question specifically. Cloud is an extension of your business and it should be treated as that. That means there are a lot of third -party risks associated with the data sharing, depending where you conduct your business. Is it specifically in the United States or also includes with companies around the world? But that should be specifically considered.
Speaker: And cloud providers are also different, right? Because if, as the CEO, you started thinking today about using cloud, you're probably already too late to the game. There's a term called shadow IT, where an employee can purchase cloud level storage for less than $50, right? And fit the entire database in the cloud without IT department even knowing it. Because that's how easy it is to acquire cloud -based storage. So that's already in here in the game.
Speaker: So sort of private cloud could actually create a new vulnerability for you. Vishal, what's your advice for companies? How should they investigate or think about outsourcing some of their cybersecurity capabilities? I think it's a great question. I'm going to take off my consultant head and my wife runs a medical practice and we are a small business head.
Speaker: The cloud is there to stay, and only where it is going to go is it, like Domenica said, is going to keep going more and more. I think my take is, some of the risks are, yes, introducing new risks, but there's an infrastructure which is hopefully a little behind your company. But again, on the other hand, you can also say you may have a server hosting all the data sitting at someone's desktop,
Speaker: which is probably more vulnerable. Someone's talking to you, then they're sitting in the top. Why would they help you? Getting your crowds, the cloud services from, that's what I did for my wife. Figure out what security they do, what kind of backups they're going to keep. Then you're actually in a much better hand that way. Also, you got to think about
Speaker: cloud, even if the data goes into cloud, some of the issues are very similar to the data that was sitting in cloud. A hijack of the cloud is part of the big one, like Target, other things. It was hijack of someone's account, which brought those companies to the knees. That's the most common phenomenon. It is not necessarily people breaking and getting their hijack counter, so generally,
Speaker: I think as cloud is here to stay, you just need to do more due diligence. And also you need to start thinking how much value cloud is providing you. So spending some extra into security is actually a good thing because that increases, helps you grow faster in your business. You don't have to take stand -up big infrastructures. You don't have to create payments.
Speaker: You can take Venmo payment, you can do all the FinTech stuff. But the way the world is growing more digital, you are actually better off spending. Spending on security should be part of cost of doing business so you can grow faster and participate.
Speaker: You know, we have a datum that I was quite happy to see which is that companies that told us that they were growing more than 10 % a year were also companies that were more likely to say that they had an up -to -date cybersecurity policy. In other words,
Speaker: A good defense was not contradictory to a good offense. It seemed to be enabling a good offense, and I think that's a point to make. I know we don't have too much more time. One of the themes that has been running through this is that
Speaker: there's a whole opportunity to map your risks, or a requirement to map your risks. And I can almost imagine a big piece of paper or a whiteboard that was literally a map of my cyber risks. And you're probably not gonna be capable of covering all of them. You can't ever be 100 % safe, so you're gonna have to manage
Speaker: risk versus how much risk you're willing to take and how much risk you're not willing to take and how much defense you want to put up. But I think another theme that runs through everything I've read about cybersecurity and learned about cybersecurity is that
Speaker: Technology can help you a lot, but your vulnerabilities are mostly human. And they're in processes and having good processes and having aware people. And I'm wondering if each of you can talk for a minute about how you audit processes and how you train people so that you don't make the careless mistakes that open your network. Vishal, let's start with you on that.
Speaker: Sure, Tom, this is one of my favorite topic. I almost call it, it's like a good hygiene enhances the wellbeing. We do that in our personal life, but you don't have a good hygiene, we all end up with a dentist. So in my part, when I look at from a cyber perspective, there are certain things companies should be doing, should be part of the hygiene.
Speaker: like you mentioned, having a security policy, encrypting all records which have confidential data, performing frequent backup. The big part is carefully screening your potential employees because the insider threat is much higher than the threat we see from outsiders. Someone coming in, putting a thumb drive on one of your internal system and collecting all the data
Speaker: selling it on dark web is more complex than you think. Training your employees, this is the big part in key areas like acceptable use, password policy. Finally, what we also recommended, what I'm seeing is, have a good policy on your, bring your own device and
Speaker: In terms of training, the best way to train is not necessarily sitting in a room and going to PowerPoint site. The best way to train is really doing some real -time social engineering on your employees to show what happens. I recently did with one company where we actually had a couple of people, trusting example, stand outside the office and they just looked legit and were not wearing any
Speaker: needs to address something and they just said, hey, you are entering in, we are just checking whether your badges are working. We are from the badge company. Ninety percent people handed us their badges. We just scanned the badge on our machine in the hand and handed it back to them and they checked in into the company. By evening, we have badge access data for 90 percent of the people. It's so easy to do because
Speaker: As a human beings, we like to trust system, we like to trust people, but we are forgetting there are cyber criminals, and I stress word on criminal, who are after this model, and you gotta be doing a lot of those case -based social engineering kind of models, and that will, that starts changing behavior so fast. And that's the key for security is driving risk culture within your organization,
Speaker: The more you spend on it, the more stronger your company is going to get and be able to defend themselves. Dimitri, let me give you a chance to pile on to that or add on to that about the human and process side of cyber defense so that the technology can do its job.
Speaker: Absolutely. Michelle has a lot of good points associated with that nature, right? There is actually a saying, the best network to protect is the network that's down, meaning nobody has access to. And obviously, fortunately, in our reality,
Speaker: that we're all interconnected when we actually communicate information to our partners, supply chain, cloud level providers, employees or users will always exchange different bits and pieces of information. And this information could contain private data, employee information, health care record, payment record, that a lot of the users don't even realize this.
Speaker: So one of the steps that we see where companies started focusing on is just little steps. How to recognize what efficient email looks like, right? And how to create strong passwords, how to avoid using different dangerous applications that could be not just social media applications, but applications at work specifically.
Speaker: and avoid taking information out of the company on different types of devices. So one of the companies that we work with is a health care, a smaller health care company. When one of the executives received a phishing email and followed the link and became a victim of the phishing, that started a wild -scale education around the entire company.
Speaker: And the company even started going deeper into how they operate security within their enterprise, right? If the executive falls into that level of fishing trap, then everybody else could. And then same thing goes for an employee or subcontractor that works for that company.
Speaker: Another part is also kind of outlining the clear use policies for new employees and vendors, right? Because we bring other folks into our environments to use our devices or bring their own devices. So what can be done, what cannot be done, right? How do you escalate what you see within your environment to your IT and security staff, as well as maintain compliance? Because a lot of mid -size companies don't realize that frameworks that large companies use
Speaker: also can be applied to a mid -size company. And I'm referring to HIPAA as well as the payment card industry standards and NIST, National Institute of Science and Technology, that provide the ready -to -go frameworks that allow you to assess how your internal security department is doing in terms of the readiness to protect against the large -scale breaches. Do you know, it's interesting, and so the human side of this is so important. And I think one of the things that we learn is that
Speaker: When processes become inconvenient, they become dangerous, that people will take shortcuts if there are shortcuts to be seen. And so ideally, you want to devise secure processes that are convenient. I once worked for a company where we suddenly, we used to let visitors come up
Speaker: You know, I was working on the third floor. Somebody would come in downstairs. We'd just send them up, come up the stairs. Turned out we were taking credit card information in another part of the building and we really could no longer do that. We were supposed to go downstairs and physically escort that person upstairs as part of a standard about taking credit card information. Well, that was an inconvenience to us. It was just not what we were used to and it didn't sort of match our ethos.
Speaker: So we sort of complied, but we didn't comply as well as we ought to have, and that was actually a vulnerability and a breach. I'm afraid we're out of time for what could have been a discussion if you go on for an awful lot longer. A couple of key themes that I heard are it's important to understand your readiness.
Speaker: I'd like to call your attention to a website that we've put up, a cybersecurity resource center specifically focused for mid -sized companies. The URL is cybersecuritycenter .middlemarketcenter .org. And there you will actually find an assessment tool, a PDF that you can download that just asks 40 questions to help you gauge your preparedness across people, processes, technology, and across prevention.
Speaker: before, during, and after a cyber attack. Heard some important themes about recognizing the human element of cybersecurity and recognizing its importance. And that regardless of industry and regardless of company size, you and your critical assets can be and probably are in danger. And also the importance of
Speaker: preparation of not only creating a good firewall and good technological prevention, but having a playbook so that 200 days after you've been attacked, when you discover that you've been attacked, you know what to do and don't have to invent a response right then and there when you're sort of in panic mode.
Speaker: So with those thoughts in mind and that advice to you, I want to reiterate the URL, cybersecuritycenter .middlemarketcenter .org. I want to thank very much, Dimitri Kaczynski and Vishal Chawla for joining us. Dimitri from Cisco Systems and Vishal from Grant Thornton for joining us with their expertise. Gentlemen, thank you very much. And thank you all for listening to The Market That Moves America.
Speaker: Never miss a new episode. You can subscribe to the podcast on iTunes, Stitcher, Google Play, or wherever fine podcasts can be found. Or you can also subscribe and visit us at middlemarketcenter .org. Thanks very much.


