All episodes

CISO Debate Webinar: Will increased regulation improve security outcomes?

Apple Podcasts Spotify SoundCloud

This is a special episode. On November 9th Robb moderated a CISO Debate Webinar with Christine Vanderpool (CTO of Florida Crystals) and Adam Glick (CISO for PSG), on the topic of “Will increased regulation improve security outcomes?” This session was recorded and is being shared here, for you to enjoy, share and mock. Have fun!

You can check out a version with video as well as audio on Youtube here: https://youtu.be/5URZ_ufdKCM

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript3636 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a special episode, episode 255. We're releasing this just to show a webinar that I just did last week, um, CISO debate webinar focusing on whether increased government regulation will help drive better security outcomes.

I hope you enjoy this special content and look for our December episode coming in just a few weeks. Hi, this is Chris Ard, CISO with Newmont Corporation. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

All right, well, let's go ahead and get started here. Thank you so much for joining us here for this debate about— well, let me pull up my slide here— around more government regulation and whether that can help drive better security outcomes. So starting off here, introduce myself. My name is Robb Reck. I am the co-founder of Colorado Equal Security.

Previously, I worked as the Chief Trust Officer for Red Canary and the Chief Information Security Officer for Ping Identity. Before that, worked in various financial services and software companies. Super excited to get to do this. The debate series is something that I got a chance to start in a previous job and really enjoyed the ability to debate a controversial topic within security, really think these things through and try and help other people think this through. You know, we live in a world where sometimes disagreements can be difficult to have in a good way, and I think we're trying to model that here through how these debates go.

So as I mentioned, the topic today is around answering this question: does more government regulation help drive better security? And the statement is our pro person will be arguing that more government regulation will help drive better security, and our con will be opposed to that. As introductions, we have Adam Glick. He is the CISO for PSG located in Boston. Adam is going to be arguing the pro and talking about how government regulation can drive better security outcomes.

Previously, he was the CISO for SimpliSafe, at Rocket Software, and VP of Cyber Risk at Brown Brothers Harriman. He has undergrad and MBA from Providence College, and he's a big car and technology enthusiast. He likes to read and he's a hiker and a cyclist. Thank you for joining us, Adam. All right, our con panelist is going to be Christine Vanderpool.

Christine is the CTO at Florida Crystals. Previous to her role as CTO, she was the CISO there, and I've known Christine for quite a while as she was a CISO for Molson Coors Brewing in Colorado and the Deputy CISO for Kaiser Permanente. She's on the Florida Cyber Advisory Council and a member of the Tech Hub in South Florida. She's also a pretty prodigious author of blogs and magazines and speaks at all kinds of different stuff all over the place. Well, with our introductions out of the way, let's just really quickly talk about our format.

We are going to— there's going to be 4 different sessions. First, we have Adam making the case why government regulation will improve security. He'll have 5 minutes for that. Christine will get 2 minutes to rebut Adam's case. Then following that, Christine gets 5 minutes for the con case, and we finish up with Adam rebutting Christine's case.

And then finally, you guys at the end of this are going to get a chance to vote. We're looking forward to seeing who's more compelling in their arguments here. All right. With that, I think it's time to get started. Let me get over here and stop my sharing and turn off my camera.

I'm going to hand it over to you, Adam. Take it away.

Uh, you are on mute right now, my friend. Okay, there it is. I just heard the thing. Uh, thanks everyone, appreciate it. Uh, ladies and gentlemen, esteemed judge, my fellow debater, today I stand before you as an advocate for the proposition that more government regulation can indeed pave the way for improved cybersecurity.

In an age where digital threats loom large and data breaches have become all too common, it's imperative that we recognize the critical role that government intervention can play in enhancing our security posture. Allow me to present a few arguments and substantiate them with concrete examples while addressing some of the counterarguments you may hear from my other end of the debate panel here. One of the primary benefits of government regulation is the establishment of a unified framework for cybersecurity. Regulations can provide clear guidelines, standards, best practices that organizations must adhere to, fostering a common understanding of security expectations. The European GDPR sets stringent data protection standards, ensuring that personal information is handled responsibly and securely.

You might hear my opponent here make arguments that regulation is going to stifle innovation and burden businesses with compliance costs. While initial compliance may entail some cost, the long-term benefit of a more secure digital environment outweighs these concerns. We can all complain about GDPR and the work it's done, but we cannot deny it's an excellent step in the right direction. Is there anyone out there who isn't or hasn't used the NIST framework? Government regulation can provide the necessary incentives for organizations to invest in cybersecurity.

HIPAA, SOX, they compel financial organizations, healthcare organizations to invest in robust security measures to safeguard sensitive data. You may hear my opponents suggest that businesses should be left to determine their own cybersecurity investment strategy. History has shown that without regulatory pressures, some organizations may prioritize cost-cutting over cybersecurity, putting consumer data at risk. It is the rule, not the exception, that companies will misbehave, sometimes with grave results, when given the freedom. Government regulation can facilitate information sharing and collaboration among different entities, a crucial component in the fight against cyber threats.

CISA is a prime example, encouraging public and private sectors to exchange threat intelligence and coordinate responses. My opponent might contend that the private sector is better equipped to handle cybersecurity and government involvement could lead to inefficiencies. However, without a centralized body, responding to nation-state attacks or large-scale cybercriminals can be chaotic and uncontrolled and uncoordinated. If you're facing a major breach, I bet you're calling your local FBI office at some point. I bet their number is in your IR plan, and if it isn't, it should be.

Government regulations establish a framework and accountability and legal recourses when breaches occur. For instance, CCPA empowers individuals to take legal action against companies that fail to to protect their data. You can thank California for forcing companies to delete your information or ban them from selling it. Some may argue that legal aspects of regulation are burdensome and open the door to frivolous lawsuits. These regulations strike a balance by promoting accountability without hindering legitimate business activities.

Government regulation can facilitate international collaboration and cyber diplomacy. In our interconnected world, cyber threats often transcend borders, requiring a global effort to combat them. Regulations can serve as a basis for international arguments and standards. Gotta move my camera so I can see when Robb yells at me for coming up on time. Fostering cooperation between nations to address common cybersecurity challenges.

You may hear skeptics may even say that international agreements are difficult to enforce and nations have varying levels of commitment to cybersecurity. However, regulations provide a strong starting point for diplomatic discussions and can pave the way for development of norms, expectations in the international community. Government regulations are crucial for safeguarding critical infrastructure such as energy grids, transportation systems, and healthcare networks. These sectors are prime targets for cyberattacks due to their strategic importance. Regulation can mandate specific security measures, ensuring that critical infrastructure operators prioritize cybersecurity to prevent disruptions.

Critics may argue imposing regulations on critical infrastructure may lead to vulnerabilities being disclosed publicly. Regulations can balance transparency with the need to protect sensitive information. In conclusion, while some may argue that government regulation stifles innovation and burdens businesses with compliance costs, those arguments are shallow and anecdotal at best. It is vital to recognize the substantial benefit that regulation brings to the realm of cybersecurity. Regulations provide a unified framework incentivizing cybersecurity investments.

They facilitate information sharing and establish accountability. And legal recourse. These measures are essential for protecting our digital assets and maintaining the trust of consumers and citizens. In the face of growing— growing— oh, I see Robb. I'll get close.

Robb, my last paragraph. In the face of growing cyber threats, the government must play a significant role in shaping a secure digital landscape. We should not shy away from the responsible use of regulation to ensure a safer, more resilient cyber environment for all. Simply, if the private sector could agree on any comprehensive minimum standard, they would have. Thank you.

Well done, Adam. I was that good to speak to us. You were within just a few seconds. You had like 3 seconds left or something like that. Perfectly done.

Thank you, Adam. All right, Christine, you get 2 minutes for your rebuttal here. I'll follow up with another 5, but for now I'm going to give you 2 and I'll come back in a couple minutes. Okay, so a lot of the points that were made, I will be countering those in my reasons why IT security should not be mainly driven by government regulation, but particularly to Adam's arguments, I would just point to existing government regulations, at least here in the United States. So for example, if you look at taxes, yes, taxes, we have laws around taxes, people have to pay taxes, there's a lot of regulation around taxes, but as we've seen, the US government at least is not very good at really enforcing things and ensuring that people are following them properly.

We know there's a lot of cases of tax evasion and tax fraud and tax manipulation, right? And I believe it just gives our government, you know, an inlet to penalize and enforce fines and fees on actually those that are not in the best position to pay those fines and fees, right? They're not going after the larger organizations that could handle that. And I think we would see that very similarly in the IT security realm as far as companies. It's great to have a framework that people can follow, sure, but to enforce following a framework might not be realistic for a lot of organizations out there in the world, especially smaller organizations that can't afford to have large cybersecurity teams and comply with everything down to the letter of the law.

And you're gonna stifle businesses from existing.

My sister-in-law owns a small air conditioning shop in California, and they're now considering not using text message notifications because of the compliance burden with California's data privacy laws. So it's getting so expensive, they're thinking they can't even do it. So that's just my quick rebuttal, but should I move into my actual arguments now? Yeah, I'm going to give you 5 minutes now to launch into your con case. Go ahead.

Okay, so as we know, IT security is a vital aspect of our modern society. We rely on it for our digital systems for communication, commerce, education, and entertainment. However, IT security is also complex and dynamic, where threats and vulnerabilities constantly evolve and require adaptive solutions. The question is, how can we ensure that IT security is effective and efficient, and who should be responsible for setting and enforcing those standards? Some argue that the government should play a more active role in regulating IT security, as it has the authority and resources to protect the public interest and national security.

Others would say that that is counterproductive, and that is my argument, and I will present that today as to why I believe that government regulation does not drive better IT security based on 3 main arguments. The first being government regulation stifles innovation and competition. Government regulation creates compliance costs and burdens. And lastly, government regulation undermines trust and cooperation. So for the first argument, that government regulation stifles innovation and competition, One of the main reasons why government regulation does not drive better IT security is that it stifles innovation and competition in the IT sector.

Innovation and competition are essential for improving IT security as it fosters creativity, diversity, and responsiveness to the changing needs and challenges of the market and the society. However, government regulation often imposes a one-size-fits-all type of rule set and standards that are based on outdated and narrow assumptions that do not reflect the diversity and dynamics of the IT sector. For example, GDPR in Europe, which aims to protect the privacy and security of personal data, has been criticized for being too prescriptive and rigid and for creating barriers for new entrants and small businesses into the IT sector. Moreover, government regulation often discourages innovation and competition by creating monopolies or obligatories— I didn't say that right— that dominate the IT sector and have very little incentive to invest in IT security. For example, the FCC in the United States, the Federal Communications Commission, regulates telecommunications.

They have been accused of favoring large and established companies over smaller and newer ones and allowing them to exploit their market power and neglect their IT security obligations. Secondly, government regulation creates compliance costs and burdens. Another reason why government regulation does not drive better IT security is that it creates compliance costs and burdens for the IT sector and for IT consumers, you know, companies that use IT systems and services, which is everyone these days. Compliance costs and burdens is an effort that are required to meet government regulation requirements, such as reporting, auditing, testing, and certification. Compliance costs and burdens can be significant and can divert resources and attention away from core activities and objectives, such as developing, deploying, and maintaining IT systems and services.

Compliance costs and burdens can be disproportionate and unfair as they affect different stakeholders depending on their size, scope, and capabilities. For example, a survey by the Information Technology and Innovation Foundation found that small and medium-sized enterprises face higher compliance costs and burdens than larger enterprises, as they have fewer resources and less expertise to cope with the government regulations and requirements. Lastly, government regulation undermines trust and cooperation. A third reason why government regulation does not drive better IT security is that it undermines trust and cooperation among us in the industry. Trust and collaboration are crucial for improving our IT security posture, as they enable sharing, collaboration, and coordination amongst IT practitioners and stakeholders such as customers, suppliers, partners, and regulators.

However, government regulation often erodes trust and cooperation by creating conflicts of interest, mistrust, resistance among those in the industry.

Damage— when there's no trust and no cooperation can damage relationships and it can jeopardize the IT security for both the government and the, the users such as companies, right? The IT sector, for non-compliance and breaches, for example, GDPR imposes fines up to 4% of global turnover or $20 million, whichever is higher. Can you imagine smaller companies having to face these fines? In conclusion, government regulation does not drive better IT security. It stifles innovation, competition, creates burdens undermines trust in, in the private sector.

Therefore, relying on government regulation should, should not be what is required. We should allow us in the private sector to drive what is right. Thank you so much, Christine. Adam, you get 2 minutes for your rebuttal, and then we'll be turning it over.

Can you hear me? Yep. Great. My opponent brought up 3 anecdotal and shallow arguments I'd be happy to dismantle. While it's true that overregulation will be counterproductive, well-crafted cybersecurity regulations can serve as a catalyst for innovation.

By setting up minimum security standards, regulations create a baseline that encourages organizations to explore innovative solutions within defined parameters, fostering a more secure and dynamic landscape. It is the road well-traveled, as we've seen time and time again. And while it's understandable that some may view government regulation— second point, excuse me— while it's understandable that some may view government regulation as burdensome, the cost of inadequate cybersecurity far outweighs the investment required for compliance. The expenses associated with a data breach, both in terms of financial repercussions, damage to reputation, can be significantly higher than the resources spent on implementing and maintaining effective security measures. In essence, the initial burden of regulation is an investment in safeguarding not only business, but the trust of its customers and the integrity of our digital secure ecosystem.

While it's true that excessive regulation, third point, can pose challenges to trust and cooperation, a well-balanced regulatory framework fosters a sense of security and transparency. By establishing clear cybersecurity standards, regulations actually enhance trust among stakeholders. Customers, partners, and the public can have confidence that organizations are held to a minimum standard of security, promoting a collaborative environment where the exchange of information and cooperation in tackling cyber threats becomes more reliable and more effective. In the face of growing cyber threats, the government must play a significant role in shaping the secure digital landscape. We should not shy away from the responsibility responsible use of regulation to ensure a safer, more resilient cyber environment for all.

Again, if the private sector could agree on a comprehensive standard, they would have already. Thank you, Robb. And thank you, Christine.

And thank you, Adam. And thank you, Robb. Thank you, Adam and Christine. That was so much fun. We're going to open up the poll here.

Hayden, if you want to If you want to open that up, and while we do, while people are voting, I get to share some fun facts about our panelists today. You know, not only are they IT and security leaders with a lot of experience, they're also normal people. So Adam, he has his undergrad degree in special education, and he was a middle school special education teacher prior to coming into information security. Adam, that's awesome. Thank you for, for doing that service.

Before that, before we had kids, he was also a big woodworker and he built his son's crib by hand from rough sawn white oak, which is awesome. I also have done a little bit of furniture making in my life and I know how time-consuming and fun it is and how hard it is to find time to do that after you have kids. Christine, This is not hard for those of us who know you to believe, but Christine used to perform stand-up comedy as a hobby, and she is hilarious and makes perfect sense. And other interesting fact, when she was in college, she gave tours of a nuclear waste dump 2,150 feet underground. Not a thing that a lot of folks can say, huh?

Hayden, are we about ready to close up the poll? Well, if we're waiting on anybody else— ready? All right, when you're ready, go for it. Okay. All right, then I'm gonna go ahead and get my screen shared again and show you guys the results of our, of our LinkedIn poll.

So, oops. So before we did this, this debate, we, we ran— I ran a poll on LinkedIn to see what folks thought thoughts, excuse me, and you can see it was actually super close to 50/50, you know, a slight edge toward that government regulation would help drive better security, but I think we— it shows that we picked a pretty good topic that's worth thinking about since it was so close to 50/50. And with that, let me go ahead and do this last slide and then we'll go over to the results. Big thank you to CyberSanac, you know, Hayden, that's where you work and you guys did a ton of work helping us put this webinar on. Also, a big thanks to Shannon Lund, who kind of partnered with me putting this thing on.

We had a lot of fun. We hope that you will put suggestions for potential next debate topics in the chat so we can, we can use those to keep driving things forward. And with that, to close things up, would you, would you please share the results of the poll with us?

If I can unshare, maybe I have to unshare.

Yep. Wow, super close again. Fantastic. Looks like Adam just edged ahead here, 54 to 46, but once again shows really, really well-crafted arguments on both sides, and appreciate— I just want to personally thank you. This is not just a go spend 20 minutes working on this with us, you know, hours over the last couple of months to get prepared for this, to put together those arguments, and, you know, it takes some courage to to choose to come up here and get voted on.

You guys both did a fantastic job, um, and we really appreciate it. With that, I think we're good to go. Um, we, we're gonna go ahead and let you guys, uh, let you guys get back to your days, and we'll talk to you soon.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes