
CISO Talk by James Azar · 2023-04-25 · 45 min
Key moments - from our scoring
Substance score
54 / 100
Five dimensions, 20 points each
Patrick Gaul returns to CISO Talk to provide a comprehensive update on federal cybersecurity policy and what Congress is planning in 2023. The National Cybersecurity Strategy dropped on March 2nd with five pillars: critical infrastructure security, threat actor disruption, market forces/software manufacturer accountability, workforce development, and global partnerships. Gaul emphasizes the urgent cyber workforce crisis - over 50% of practitioners are Baby Boomers and Gen X, creating a looming talent cliff with massive experience gaps at the 7-9 year level. The episode digs into the regulatory chaos: CISA's Cyber Incident Reporting for Critical Infrastructure Act rulemaking (proposed rules expected March 2024, implementation September 2025), conflicting SEC incident reporting rules coming April 23-25, plus requirements from the FCC and FTC, creating compliance nightmares for multinational corporations. Gaul advocates for a National Cyber Scholarship for Service program and highlights the Joint Cyber Defense Collaborative (JCDC) as an emerging but limited information-sharing mechanism. He stresses that trust - not just regulation - must underpin public-private collaboration, citing examples from the UK, Israel, Germany, and Switzerland where partnership models outperform regulatory-heavy approaches. Small businesses remain particularly vulnerable and under-resourced.
The five pillars are: (1) Critical Infrastructure Security overseen by CISA, (2) Get After Threat Actors, (3) Shape Market Forces to Drive Security and Resilience (pushing responsibility onto software and hardware creators), (4) Invest in a Resilient Future (including workforce development), and (5) Global Partnership.
Director Easterly expects proposed rules to be released by March 2024, followed by a comment period, with implementation scheduled for September 2025 - a timeline critics argue is too slow given that adversaries attack daily.
CISA, SEC, FCC, and FTC are all creating independent incident reporting rules with different timelines and definitions (24 hours vs. 72 hours), plus 50 states have their own cyber notification requirements, forcing corporations to manage multiple compliance frameworks that drain resources away from actual security work.
The JCDC is an information-sharing organization created by Director Easterly with participating companies like CrowdStrike, Microsoft, and Palo Alto Networks, but access is currently limited to invited participants; most organizations still lack advanced threat intelligence sharing.
Gaul has been promoting this program to Congress for two years as an alternative to the underfunded CyberCorps for Service (which has 118-120 colleges and 7 community colleges), aiming to create a national strategy addressing the cyber workforce shortage and increasing diversity, particularly women (currently 24% of the workforce) and minorities in cybersecurity careers.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a genuine and relatively dense policy update - specific rulemaking timelines, workforce ratio statistics, state privacy law progression - but is diluted by tangents on Ukraine funding, a US Cyber Force sidebar, personal military reminiscing, and a formulaic closing segment. Useful for someone not tracking DC closely, but not rich with non-obvious claims.
over 50% of our cyber workforce, James, are baby boomers in Generation X. So we're headed for a cliff...there's about five jobs or uh, five people for every job. But if you go up the stack, there's only about 0.5 people for every job
Director Easley expects to have the proposed rules out by March of next year. That will go through a commentary period. And then the idea was the implementation will happen in September of 2025
The episode is primarily a news briefing rather than original analysis; most framing - compliance doesn't equal security, public-private trust deficit, regulatory fragmentation - is well-worn in the CISO community. The ESI Thought Lab finding that heavily regulated industries (healthcare, finance) rank below unregulated sectors on security posture is the one genuinely counterintuitive data point, but it's barely developed.
the two most regulated industries I think in the United States are probably health care and financial...and yet this study determined that...financial services only rated one number one in one area. And that was the plan to invest more money and healthcare fell well down
can you regulate your company into security? I don't think so
Patrick Gaul is a genuine practitioner-advocate with real Hill access - he was briefed on the National Cybersecurity Strategy at 5:30 AM the day it dropped, met the same day with Homeland Security staff, and leads a coalition of 53 Fortune 1000 CISOs. He is not a career podcast guest and speaks from direct engagement with named senior officials, giving him legitimate caliber for this topic.
I happened to be in Washington the morning it dropped and had a number on the Hill that day. Um, actually got my copy at 5:30 in the morning. So, uh, had three hours to read it before I went up on the Hill
We had Val Cofield, who's the Chief strategy officer for CISA, spent about 45 minutes with us. Uh, we had Nick Larson, who's the Assistant Deputy Director within the Office of the National Cyber Director
The episode offers a solid density of named officials, specific vote tallies, dollar figures, and legislative timelines for a conversational format; however, several key claims are hedged with uncertainty ('if I remember correctly,' 'I think it has to do with something like'), and the ESI Thought Lab study is referenced without enough methodological grounding to be fully actionable.
that passed out of the subcommittee. I think the vote was 53 to 2. Extremely bipartisan bill
I talked to one CISO, uh, global CISO and a very large bank and they spend $2 million a year just on staying compliant with all of the regulations
The host provides useful clarifying prompts (asking for the JCDC definition, pressing on appetite for federal privacy legislation) but frequently injects personal political opinions rather than probing the guest, allows extended digressions, and closes with formulaic buzzword-graveyard and book-recommendation segments that add no informational value.
I wish to do the same with Ukraine money, um, because I'm less concerned about how Jenny Sterling spends my tax dollars, uh, than I am with Ukraine
Buzzword. Um, you'd love to bury in our buzzword graveyard
Computed from the transcript - who did the talking, and the words that came up most.
CISO Talk Podcast A CyberHub Podcast Production Season 3 Episode 13 Topic: CyberSecurity Policy In DC, 2023 Update Guest: Patrick Gaul Title: Executive Director at NTSC Bio: From an early age, I have been driven by an innate sense of curiosity and a passion for exploration, which helps to explain a career that spans multiple industries across the globe. In my current role, my mission is to make the NTSC a preeminent force in respect to driving the national dialogue on technology security within the United States. We have amassed a prominent group of Chief Information Security Officers from across America who make up the Board of Directors. Through dialogue, education, and government relations, we unite both public and private sector stakeholders around policies that improve national cybersecurity standards and awareness. LInkedIn: SubStack: Apply now to be a featured partner on the show: ****** Listen here: ****** Website: Youtube: Rumble: Facebook: Linkedin: Twitter: Instagram: Thank you for watching and Please Don't forget to Like this video and
Transcribed and scored by The B2B Podcast Index.
Speaker A: Thank you all for tuning in today, and thanks for taking the time to join the show. Please make sure to subscribe to the podcast. Find us on your favorite podcast listening platform or on YouTube at, uh, the CyberHub podcast YouTube channel, where you can find all of our episodes. Short, long, of all sizes and kinds. I've got a very special guest today on the show. If you're a lifelong listener of this podcast, meaning over 150 episodes that we've done at Cisotalk, you know, Mr. Patrick Gall, he's the executive director of the National Technology Security Coalition.
Speaker B: He's.
Speaker A: He's a dear, dear friend of mine, someone who. I definitely admire his work, uh, because he's trying to get the voice of the CISO heard on the federal government level. He's got a board that represents approximately 90 Fortune 100 CISOs that support his efforts on the Hill, and he's a champion for all of us that are security practitioners. So without further ado, let's go bring Pat into the show. But one last thing. I will be in Israel for April live podcast, April 16th over at Intel. Ignite with our friends at intel and so many others. So you can go check that out@cyberhubpodcast.com. make sure to get that there. Without further ado, let's start the show. CyberHubPodcast, uh, dot com. And it's CISO talk time. Let's go, y'.
Speaker B: All.
Speaker C: From the CyberHub bunker in studio, you're listening to the CISO Talk podcast. No sales, no bullshit, just straight talk. Straight talk. And now for your host and ciso, James Az.
Speaker B: Foreign,
Speaker A: Mr. Patrick Gall. Welcome to the show again.
Speaker B: Hello. How are you, sir?
Speaker A: I'm doing well. You're no stranger to the show.
Speaker B: I am not, but it's been far too long.
Speaker A: I think it's. It's been a few years since I've had you on because I took. I took a year off from the show in 2022, and, uh. And. And, you know, with a new baby at home, I decided that I was gonna do just one show instead of three.
Speaker B: You know, is that per day or per week?
Speaker A: No, I do one show five times a day, and I do another two other shows that are each, you know, once a week. So kind of decided to take some time off. It's now back, and this show is exciting, and I'm glad to have you with us for our audience who may not be familiar with the ntsc, and I think you heard my introduction. Is there anything I missed that they should know about
Speaker B: just one small correction. We have 53 chief information security officers on our board, but we have about 90 senior technology security executives associated with the uh, um, coalition. Some of them serve on our advisory committee, some serve on our policy committee, and some are just special advisors. But 53 CISOs, uh, but Fortune 1000 companies from across the nation, all big names.
Speaker A: That's um, I stand corrected. I remember seeing 90 somewhere. And, and it's probably 90 senior executives and not CISOs. But the uh, NTSC has been a force to reckon with as you guys fight for the voice of the ciso. Uh, Pat, I'll kind of kick this off to you. Um, you guys just spent a lot of time, you had your policy meeting in D.C. with some of our elected representatives. I think a lot of people who tune into the show are always wondering what's you know, the mix match of, of government regulation around security and, and kind of their view of cyber to the realities of what we encounter in the trenches daily. You want to give our, our audience a bit of an update on that?
Speaker B: Sure. I mean this is actually a very exciting time. Um, we had the National Cybersecurity strategy drop on March 2nd. I happened to be in Washington the morning it dropped and had a number on the Hill that day. Um, actually got my copy at 5:30 in the morning. So, uh, had three hours to read it before I went up on the Hill to meet with some of the folks in, you know, Homeland Security so I could ask them some questions about it. Um, so there's a lot of interest in terms of, you know, the pillars. There's five pillars critical, uh, infrastructure security is certainly, um, an important one. Pillar one and you, you know, um, that'll be the one that'll be most, you know, overseen by um, the Cybersecurity Infrastructure Security Agency. So cisa. Um, pillar two is get after the threat actors. Pillar three is shape market forces to drive security and resilience, which is really about pushing uh, the responsibility for, you know, security back into the folks that create software who manufacture hardware. That's going to be an interesting one to um, to regulate and create. Um, pillar four is invest in a resilient future. And uh, workforce development is in that pillar. And that's something that the NTSC has certainly been focused on for quite a while. I think it's a problem that we've admired for the last decade. Um, we're coming to a critical point where over 50% of our cyber workforce, James, are baby boomers in Generation X. So we're headed for a cliff. And um, you know, we need a pipeline of young people. But the gap for most companies today is in the seven to nine year experience level. So we've got to figure out a way to keep the young people interested because, you know, for every young person looking for a job just out of university, there's about five jobs or uh, five people for every job. But if you go up the stack, there's only about 0.5 people for every job. So there's a lot of stuff we have to unpack there and work through. And uh, that's going to be handled by the Office of the National Cyber Director. And I learned last week that there's actually a draft circulating, uh, among the federal agencies on a plan to address workforce. Uh, and hopefully the private sector folks like myself will see that plan soon. And then last pillar five is global partnership. So there's a lot to unpack in that 35 page document. And we spent a lot of time, time last week in our legislative day talking about it. We had Val Cofield, who's the Chief strategy officer for CISA, spent about 45 minutes with us. Uh, we had Nick Larson, who's the Assistant Deputy Director within the Office of the National Cyber Director responsible for cybersecurity and programs. And he came in and kind of gave us the perspective from, you know, oncd. Um, so a lot of work there. Meanwhile, uh, there's a ton of stuff going on with privacy. Uh, Iowa passed, um, well, the legislator legislative body passed the House, passed a, uh, privacy bill. I think the vote was 43 to nothing. And um, that had already been passed by the Senate. So that goes back to the Senate for some procedural issues. Then it'll go to the governor, get signed and that'll be the sixth state that has privacy bill. Um, we're headed down the same path we have with data breach notification, James. We're looking at the possibility of having 50 plus privacy bills, which I know, you know, between the chief privacy officers, the chief information security officers and the chief risk and compliance officers, they're all just thrilled with that concept and that idea. Um, meanwhile, uh, you know, we've got the uh, systems working on the data rulemaking part of um, the um, Cyber Incident Reporting for Critical Infrastructure Act. Uh, Director Easley was on the Hill yesterday meeting with the appropriators. There's a lot of money in that bill, $3 billion in going towards CISA in the budget. 98 million of that is earmarked just for managing the amount of information that CISA expects to get under this incident reporting bill and, and there's a ton of stuff they're going to have to be able to do to process that information, discern the intelligence in that information, connect the dots and send it back out to the private sector and near real time. Um, you know, but that's not happening today unless you're in the jcdc. If you're in the jcdc, you're getting some pretty good information. But as we learned last week, if you're not in the jcdc, uh, cyber threat intelligence sharing has not advanced dramatically in the last several years.
Speaker A: In fact, real quick, that for audience members who may not know what the JCDC is, what, what is that?
Speaker B: It's the Joint Cyber Defense Collaborative, and it's an organization that Jen Easterly, Director Eastley, put together in response to solar winds and log 4J. And it was initially, uh, intended to be, I think, um, you know, like a rapid incident reporting on a national level. It has, um, evolved into something a lot more dramatic, focused on incident reporting. A lot of companies like CrowdStrike and Microsoft and Palo Alto, collaborating and sharing information. But you have to be on the inside as a private sector company to get that information. Right now, um, I think Director Easley's idea is to leverage that relationship and, and eventually push that out to more companies. But, um, right now, you know, we did a session last week and, and it was. You, uh, remember when, uh, Ronald Reagan was debating, um, can't remember who it was, but he, you know, he asked, uh, I think it was Jimmy Carter, he said, um, are we better off than we were four years ago? And Jimmy Carter had to say no. So when, you know, cyber threat intelligence, are we better off than we were, you know, four years ago? And we're not. And we've been doing this for seven years and it's constantly been a real problem. Um, so that's going to go through rulemaking. Director, uh, Easley expects to have the proposed rules out by March of next year. That will go through a commentary period. And then the idea was the implementation will happen in September of 2025. So we're a long ways away from
Speaker A: having that bill be our adversaries. Don't wait this long to come after us.
Speaker B: Right?
Speaker A: They're after us every single day. Is there any hope in sight to see government maybe grease their wheels? Maybe some WD40 to get it to move a bit faster?
Speaker B: Well, you know, we're in an interesting political environment. You know, every time I go on the Hill and no matter which side of the aisle. I talk to, uh, when we talk about cyber security, everybody says we're bipartisan, we're bipartisan. And um, but you know, uh, you know, let's see if they walk the talk when it comes time to start appropriating money, investing in, uh, the things we need to invest in, especially workforce, um, and uh, you know, that ought to be a bipartisan issue. But, um, you know, I'm not sure what's going to happen in this session. And then we're going to be entering a presidential race next year and a lot of things aren't going to get done. So I don't. For example, the cybersecurity, um, strategy, I don't see a lot of that getting implemented in the next 18 months.
Speaker A: Uh, so is this document even relevant? Right, because one of the things I was reading, I was reading something in the Washington Post, um, earlier this week. I think it was in the, in the Washington Post two, uh, hundred two kind of their cyber newsletter. And, and they were talking about, um, the, the desire to create a U. S. Cyber force. That's correct. The desire to create. There's calls to. There was an open letter penned by multiple, you know, five four star generals and then a lot of uh, uh, folks over at the Pentagon saying it's time to unify all of the DoD cyber efforts under one and established a seventh branch of the military called US Cyber Force. And there's very little appetite like space force. You and I were, we witnessed the establishment of space Force very, very quickly because it had presidential support. Here they're saying that there isn't some, um. Do you think congress could push potentially a seventh branch? Do you think a US Cyber Force is actually good for.
Speaker B: Well, I, the article and I, I wonder how it bounces against US Cyber command, which is a joint group.
Speaker A: So it's kind of like organizing cyber command, but cyber command, rather than it being almost kind of like a army slash NSA type of tool, it'd rather be a US Cyber force. And then the concept behind that is also, um, recruiting soldiers for cyber force. So you enter the seventh branch of government where if you're in cyber, you know, you and I are military vets, so we went through PT requirements. But if you're in cyber Force, you may not need the same type of PT requirements that you would if you enlisted in the army and wanted to become cyber Command. There's no difference whether you want it to be a cyber officer in the military. A, uh, signet, uh, there's no PT difference between that and let's say an 11 Bravo. You've got to have the same physical condition.
Speaker B: Yeah, no, I don't, I don't see any appetite for that. And right now all of the armed forces is struggling to recruit. They're all missing their recruiting goals on a quarterly basis. And whether you're offering them positions in Cyber or, you know, 0311 grunts, uh, they're just not signing up right now. Kids aren't going into the military. And, um, so now I, personally, I don't see an appetite for that. I, I think, um, they're still trying to figure out, you know, balances between, you know, federal agencies and some of the regulations they're creating around things. And, um, you know, my goal would be to have a national Cyber Scholarship for Service program. James. And I've been promoting this for two years in Congress, and for the first time I'm starting to get some feedback from people that saying, that's an interesting idea. Tell me more about it. We have Cyber Corps for Service, which is an amazing program. It's graduated 4,000 students in 20 years. Um, it's underfunded. There's only about 118, 120 colleges, maybe seven community colleges involved in that. Um, stay in on workforce for a second. Um, there's a lot of, you know, what Microsoft is doing with community colleges is great. There's some wonderful things going on, which HBCUs, um, but they're all disparate efforts. And so. And what the National Cyber Security Strategy document called for, it said, we need a national strategy around fixing the cyber workforce problem. For the past three years, I've been pounding on the doors in Congress saying, well, we need two things. We need a national strategy and we know more diversity in the workforce. You know, the 24% are women. You go into minorities. That drops dramatically. I think 15 fortune, ah, 1,000 CISOs are women. You know, um, it's a big problem. So I don't know that, um, you know, I don't think it's a bad idea. I just don't know that there's an appetite in Congress given the current, um, you know, budget discussions and debt ceiling discussions and oversight and uh, you know, over the fact that, uh, CIS is getting 3 million or $30 billion. You know, there's a lot going to be a lot of oversight from the House on that money. And like I said, Jenny still was with the appropriators yesterday, got asked a lot of hard questions about where that money's going, um, because it is a lot of money. And they want to make sure that the taxpayer is getting their bang for the buck.
Speaker A: You know, I wish to do the same with Ukraine money, um, because I'm less concerned about how Jenny Sterling spends my tax dollars, uh, than I am with Ukraine.
Speaker B: That's, That's. I'm not sure I want to go there. But we're not going there.
Speaker A: That's. That's a personal. James opinion. That's my personal opinion at all.
Speaker B: Ah.
Speaker A: You know, seeing her being grilled for it, um, ah, a bit upsets me because she should be focused on strategy. I mean, not saying she shouldn't be answering to appropriation. Right. But Jen's been a, I thought a unifier and one of the, uh, better leaders that we've had on the CISA side. Granted, we've only had about less than a handful since its establishment.
Speaker B: If you think of mppd, the National Protections and Programs Directorate, which was the predecessor to, uh, cisa, which Chris Krebs took over and initially evolved into cisa. And then, um, you know, he had his situation with President Trump, and, you know, he. He ended up leaving. And then Jen came in and she, she's done an amazing job. Um, you know, we talk a lot about the public private partnership. Um, I, I'm not sure that that's, um, as, um, much of a reality as people think. And we talk a lot about, um, you know, other terms. But when we think about incident reporting, cyber incident reporting, today, the challenge is that, you know, you got to have trust to start out with before you can have collaboration. And then collaboration leads to, you know, beneficial actions. Um, I'm not sure the trust exists today. Most corporations, you know, not necessarily willing to open the kimono and share everything that's going on. Even if the CISO thinks, you know, I got to share this, um, he or she still has to go through legal and, um, you know, there. There's a lot of challenges to getting to the point where we are truly exchanging information the way we need to. So, um, you know, it. Just think about incident reporting for a second. You've got the, the bill that says it's pushing through rulemaking. Meanwhile, the SEC is going to come out, I think it's April 23rd, 25th is going to come out with their proposed rule.
Speaker A: Correct.
Speaker B: And, um, right now, according to everything I'm hearing, incident reporting is still in there, and it doesn't align with cisa. Now, I've talked to Admiral Montgomery, former Executive Director of Cyberspace Valerie Commission. I know he's encouraging, uh, the sec, uh, to remove the incident reporting piece and to resonate on cisa. Let CISA be the centralized point of view. And if we end up 72 hours or 24 hours, we still have to define what is an event, what is an incident, what is material. James, under the sec, what is material. And if you go and read if I think this is, uh, you can fact check me on this, I think it has to do with something like 20 plus percent of pre tax revenue for it to be material. And if that's true, then we've never actually had a material breach Target Equifax, none of those were material. So there's a lot of definitions that need to be refined. Um, and then we all understand what an incident is and when you have to report it and how much you have to report. But the idea is you have to report, you know, tons of information within 24 hours under the SEC rule or 3 hours in India. Um, it's just insane. I mean, you know, the forensics haven't even begun. Um, and um, so, and so you got the sec, the FCC is also looking at incident reporting and so is the ftc. So you have all of these independent federal agencies who have the ability to create their own regulations. So where's the harmonization going to come in? And in the national strategy they talk about harmonization, they talk about, I forget the office cyber, some new group that's going to set up that's going to be pushing for harmonization and Jen talked about that yesterday as well. Um, but we can't have multiple incident reporting bills and regulations. That would be insanity. And um, would just drive the private sector nuts. So uh, hopefully they'll get all of that harmonized. And meanwhile, um, and that's the federal level. We haven't even talked about the fact that we have 50 states plus four territories with their own um, cyber incident notification requirements. So if you have a breach, you have to know, you know, you're, you're, you're a multinational corporation, you're all over the country, you have a breach, you have to deal with the ags in every one of those states. And while a lot of the bills are similar, there are nuances that you have to be aware of. And that requires compliance in compliance, requires money and um, it takes resources away that could be focused on cyber security. And you know, this whole regulatory, you know, can you regulate your company into security? I don't think so.
Speaker A: I, you know, I haven't seen one government regulation globally to stop a cybersecurity breach, incident event or Otherwise, uh, are
Speaker B: we going to regulate. I mean, this is an off the cuff comment. Are, uh, we going to regulate ourselves into stopping school shootings?
Speaker A: Yeah, you're.
Speaker B: I mean, it's, you know, I mean, again, I, I have to go there, but.
Speaker A: No, no, I, I agree with you. I think, you know, there's, there's an effort, um, there, there's an effort that, That I think is, is, is, um, there's an effort being done to, to try, and I want to say, um, add more regulation, because we, we all think that regulation solves problems. Um, but, but regulation is oversight. And you know, one of my challenges, I did a 30 minute podcast alone kind of with my take on the national, uh, cybersecurity strategy after it dropped. And, and, you know, I spent, I think it was 20 minutes on the fact that we're talking about more regulation and rather than talking about the private public collaborative. And there's other countries in the world where you see that being very, very. The, the private public partnership being very, very effective. Um, UK is one of them. Right. Israel's another. Uh, you know, um, I believe Germany is up there as well. Switzerland's up there. There's, there's countries out there that have shown the private public model to be better than regulation. Right. And there's a need for that. You said one key word there, which is trust. And I can tell you that I trust my federal partners. I don't have to agree with the agency as a whole to trust the people that support me in doing my role effectively. Right? Like my partners at the FBI or Secret Service or, or cisa. Uh, they're not political to me. They're. They're my partners. They're. They represent something that's supposed to be helpful. And I think that's something Jen was able to kind of get across her team. And I know there's, you know, depending on what paper you read or what website you look at, you hear a lot of stuff around the FBI. But every person I've ever met in the FBI and the cyber security team has been just been phenomenal in their support of everything we try to do as practitioners.
Speaker B: You know, Director Easterly has been, um, criticized recently in the recent past for, um, being a rock star at being at all of these, you know, defcom, Black Hat, rsa.
Speaker C: Um,
Speaker B: the place Aspen, you know, um, but you think back seven years ago, you know, mppd, before Chris Krebs got in there. You know, they never collaborated, they never interacted with the private sector. And now Jen's got All these regional offices, you know, building relationships with um, you know, the local community, being a resource to the local community. We have one here in Atlanta. You know, I've had met with some folks, we've tried to bring those folks into our regional roundtables so they can talk about the resources they have and what they can do to help.
Speaker A: Um, and the amount of free tools that CISA drops, the amount of free tools that your cyber team is able to use is magnificent.
Speaker B: It is. They need to do a little work around the language. Um, and we had this conversation last week with Val Cofield, uh, the chief strategy officer there. Um, it's good stuff. But if you're a small business, most of these folks don't know what red team, blue team is. So um, they've got to simplify the language, dumb it down a bit so it speaks more directly to the, um, to the small business. But these regional offices, you know, yes, they build relationships with multinational corporations, transnational corporations, but where they really are of value added is, you know, the small businesses are able to come in and, and get some, you know, some indirect, you know, direct conversations and learn a bit more about how they can secure themselves. Because right now small businesses are getting killed. They are resource for and target rich and m, you know, and you know, small hospitals, regional hospitals are getting killed. Health care is getting murdered. Water authorities are, you know, in desperate need of, of, you know, more support. Um, so, you know, most, you know, I don't think JP Morgan Chase, uh, is getting a lot of interaction with the regional office. I don't know that they need it, but um, you know, the local regional hospital does because they don't have the resources. They just, they don't have the money to invest in cyber security. And um, and you know, I told you about a study recently that was done by ESI Thought Lab. And going back to regulation, the two most regulated industries I think in the United States are probably health care and financial, two of the most. Right. And yet this study determined that um, in fact they don't rank very high against some of the unregulated agencies like tech, automotive, manufacturing, which you traditionally wouldn't think were very secure. But across all of the cybersecurity elements that the ESI Thought Lab analyzed, um, financial services only rated one number one in one area. And that was the plan to invest more money and healthcare fell well down. So um, you know, uh, there's ah, goes back to regulation. Um, you know, these are heavily regulated industries. HIPAA has been around a long time. So uh, can we spend a few minutes talking about privacy?
Speaker A: Yes, please. Absolutely.
Speaker B: So, um, six states have passed privacy legislation so far. California, which is really their CCPA 2.0, and it's called the California Privacy Rights Act. That went into effect in 1st of January. And uh, what else? Virginia went into effect the 1st of January. Connecticut and um, Colorado go into effect the 7th, uh, the 1st of July. And then Utah goes into effect December of this year. So those were the first five states. And then Iowa. Once the bill gets finalized, we'll know when it's going to go into effect, but I would think later this year. Um, meanwhile, last year, um, the subcommittee on Consumer Protection and Commerce within the House Committee on Homeland Security, um, or the House Committee on Energy and Commerce produced the adppa, the American Data Privacy and Protection Act. American Data Privacy and Protection Act. And um, that passed out of the subcommittee. I think the vote was 53 to 2. Extremely bipartisan bill and uh, but it never got to the House floor. Um, I think two reasons. Speaker Pelosi is from California and uh, you know, the California caucus is pretty strong in the House on the Democratic side and uh, CCPA and this new bill which was due to come out, there's just no appetite to, to put it forward. And then the other side of that was Senator Catwell, who's the chair of the Senate Committee on Energy and Commerce, said that uh, she would, you know, she would never put it on the floor in the Senate. And she had two primary objections. Uh, she didn't fill the private right to action when far enough. And sorry. And she um, she felt like it didn't go far enough to regulate data brokers. Both valid points I think. But you know, this is where compromise comes in. This bill passed the subcommittee 53 to 2 if I remember correctly. And while it's not perfect, it's the closest thing we've seen to a federal privacy legislation that actually works, um, in, you know, ever. And uh, so we met with the
Speaker C: um,
Speaker B: the chief counsel for the um, on the Republican side for the subcommittee and um, to talk about adppa, and I think you'll see that reemerge. And um, in fact the nts.
Speaker A: Is there an appetite for it in this session or, or this year to, to bring it to the floor floor. And
Speaker B: I think there's an appetite for federal privacy legislation. I think everybody recognizes that it's insanity to go down the same path we went down with data breach. The challenge is going to be okay. I think it'll get on the House floor. I think it could pass the House because it's now controlled by the Republicans. Right.
Speaker A: And, um, Kevin McCarthy is still from California though.
Speaker B: Right. And, um, you know, that's, that's going to be a challenge. But let's say we, we get the compromises we need on private right to action. Um, interestingly enough, CCPA doesn't have private right to action or the privacy, the California Privacy Rights act, but this bill did have private right to action. Now, it wouldn't kick in until two years after the bill went into effect and there were a lot of restrictions around it, so it wasn't perfect, but it was in there. Um, and it didn't go far enough to regulate data brokers, especially in this truly political climate with abortion laws popping up and law enforcement wanting to get access to health records. And I don't think anybody wants that to happen. But, um, that aside, if we get it through the House, you know, then, then, you know, it's going to have the same barrier at the Senate. And that's Senator Cantwell. So I don't know what it's going to take to get Senator Cantwell to accept it. But we're going to be working hard in partnership with our, you know, the members of Congress. We have been working with. Um, we had Congressman Swalwell, um, who
Speaker A: is the Congressman from California, formerly of the House Intelligence Committee. Formerly.
Speaker B: But he's also, um, he's a ranking member on the Subcommittee on Cyber Security and Infrastructure Protection. And we had him in last week and we talked to him about this. And you know, his point was, look, um, I understand why industry wants a federal mandate. I understand the, the angst that all of these bills are going to create. And you know, there's a cascading effect. You know, you got to be compliant. Compliant is costly. I mean, it's just. I talked to one CISO, uh, global CISO and a very large bank and they spend $2 million a year just on staying compliant with all of the regulations that they have to be compliant with. And you know, while compliant firms get act a whole lot less than non compliant firms, the reality is compliance doesn't equal security. And we, we talked about, uh, that issue before. Um, so, you know, his point was we think California is the model and I don't know, maybe what do we do? We, you know, a lot of companies are just resonating on gpr, gpd, gdpr. Um, yeah, gdpr. Global Data Protection.
Speaker A: Yeah. The European Data Protection.
Speaker B: Yeah, yeah. Regulation and um, gdpr, uh, a lot of transnational companies that's, that's their family.
Speaker A: Because that was the first one that came through, right? GDPR was the first one to come through the door. I recall five years ago, you know, I started the podcast around the time GDPR was getting enforced. If m. My. One of my first episodes, you know, I remember I had uh, a guest on the show and we talked about, you know, how useless GDPR really is to prevent data breaches and how much cost it added to, to, to, to companies to comply with it and, and, and increase the cost of doing business, obviously for, for a lot of them. Um, and so, you know, gdpr, while it's, it's a style, it's become fairly standard. It's. I don't think it's the right solution for America. I think it's, Americans are very different from Europeans. You and I know this. Having, uh, spent time on the other side of the pond, we very much well know that privacy there is very different from privacy here. Ask an American what privacy is, he's going to give you something completely different. Ask a European what privacy is. And it depends which European you're asking.
Speaker B: Uh, the other thing about adppa, which we're uncomfortable trouble with is the um, the section in it, in the bill where uh, they um, invest a significant amount of money in additional lawyers into the ftc.
Speaker A: Um, we need less lawyers in the ftc. We need less people in the federal government, period. But that's, that's um. You know, I think, you know, the work the NTSC is doing on the Hill is to get this across so that people can, can at least, at least if it goes to the floor and gets voted, whether it gets passed or not, at least we know where, where our areas of opportunities are. Right? If it fails to pass the Senate for whatever reason, because it doesn't regulate data brokers enough, because it calls for more FTC lawyers. Right? And those are at, uh, least we know where to go back and have the sponsors of the bill go back and make some adjustments, take it through a subcommittee and get it back on the floor. But it'd be disastrous if we went through 50 privacy bills in this country.
Speaker B: It would. And look, it didn't come out of that subcommittee last year without a lot of compromise. And you and I have talked about the lack of compromise, the lack of sitting down and finding out where we agree and working on those issues that we agree on. We don't have to agree on everything and we're never going to agree on everything. And um, I'm this collective. We Right. Republicans, Democrats, independents, we're never going to agree on everything, but you know that we ought to be able to find those nuggets common ground.
Speaker A: Yeah.
Speaker B: Advance things and workforce development. You know, addressing the cyber workforce challenge is something we all ought to agree on because China's not got a problem with workforce. North Korea doesn't, Russia doesn't. They don't have a problem with getting people.
Speaker A: You've named three communist nations where their people have no rights.
Speaker B: Um, that's true, but that's the reality.
Speaker A: I mean, North Dakota just passed the first cyber security bill requiring cyber security education in K through 12 schools, which.
Speaker B: Who did that?
Speaker A: The state of North Dakota. So 17 and a half people and about 30 buffaloes and 100 eagles can now go study cybersecurity. It took him eight years to pass this bill.
Speaker B: There are years, there are pockets of enlightenment. I call it, you know, uh, when Georgia elected this, that you can take a coding class, um, or you know, a class of that nature programming class. Coding class. And that will substitute for a foreign language credit, uh, in high school. That's a good move forward. They're doing some amazing things in Texas, especially around Austin and school districts. Um, you know, we've got some high schools up around Augusta that have, you know, four year cyber high school curriculums and they're doing the same thing in Texas. And that's what we need. Yeah.
Speaker A: Ah, but we need that across the entire nation. We need K through the way we solve our, our workforce development, the way we solve our lack of recruiting in the military, the way we solve. A lot of the challenges we encounter today is by really going to the schools and getting people interested in it early on. Right. You get a, you know, I've got a ton of books around quantum computing that are toddler books for my son and around mechanics and engineering. Why? Because that's what I want him to be interested in. Right. So that's the toys we buy, that's, that's the books we read, that's the stuff we go into because at a very young age I can mold his mind to go towards that type of work, um, and that type of, uh, develop, uh, that passion because no one knows what they're really born to do at 18. None of us know what we want to be either. So, you know, going to college for four years and trying to figure that out is just a challenge all of within itself. And it's, it's unnecessary pressure on a lot of people at the age of 18. Because I guarantee you, when you and I were enlisted at 18 and someone said, what do you want to do when you grow up? And you're like, grow up? I don't know.
Speaker B: I was 17 and uh, I was
Speaker A: 17 when I enlisted.
Speaker B: Yeah, when I went in the Marine Corps. And um, you know, um, when I got to Parris island, it didn't matter what I wanted to be or what I wanted to do. They told me what it'll be and do. And for the next nine years that worked out well for me. But um, you know, I was one of those kids who needed that structure and discipline in order to mature. And uh, not all kids need that, but for some kids it's a pretty good thing. Um, and, and there's some real, you know, opportunity in, in the military for, you know, getting into a cyber curriculum. And you know, kids should be looking at that if they don't know what they want to do. Um, I'm trying to think if there's anything else that we've talked about recently.
Speaker A: Um,
Speaker B: I talked about the cyber threat intelligence, I talked about privacy. Um, you know, the other thing that's going to come out, we touch on this just quickly when it comes, the SEC rule comes out. You know, there's a whole new subcommittee within the cyber, within the Cybersecurity Advisory committee, which is this committee of 35 executives that support Director Easterly. We just named 14 more last week. Um, I think they originally set it up at 21 and then they just added the last 14 last week. And um, there's a subcommittee called uh, Corporate Cyber Responsibility and headed up by Dave DeWalt. And that subcommittee is focused on trying to understand how, you know, we can make corporate boards more cyber aware. Uh, help understand because the SEC rule is going to impose some pretty significant responsibility, judiciary responsibility on corporate board members. And they uh, can't not going to be able to ignore cyber security going forward. They're going to have to be really interested in it. Um, but are they prepared to be interested in it? Um, one of my national, uh, sponsors this company called proofpoint and they're uh, global ciso. Um, global resident CISO is a, ah, woman by the name of Lucia Malika. Just in, brilliant, um, lady. And um, you know, she spends a lot of time working with corporate boards. They have a whole program educating corporate boards. There's a lot of work to be done to get all of our corporate boards up to speed on this. And um, you know, it's um, it's an issue that I think, you know, it's going to be really Important in the next 18 months after the rule comes out.
Speaker A: All right, I know we're almost at time. I'm gonna put you on the hot seat.
Speaker B: Let me say one last thing before.
Speaker A: Yes, sir, absolutely.
Speaker B: I just wanted to note. Mention that today is National Vietnam Veterans Day. And I just wanted to, uh, say to all my brothers who served, simplify, simplify, indeed.
Speaker A: I'm gonna. Now, Mr. Marine, uh, I'm putting you on the. Are you ready?
Speaker B: Yep.
Speaker A: All right. Buzzword. Um, you'd love to bury in our buzzword graveyard.
Speaker B: Hall of a nation I'm so tired of hearing doesn't exist. It's never going to exist.
Speaker A: Okay, we'll take it. Um, what's the last song you listen to for coming on the show, Pat?
Speaker B: I've been listening to. You can see all my albums back here. I'm listening to Linda Ronstadt's Greatest Hits. I was listening to it this morning.
Speaker A: I love it. What's the book you're reading right now or listening to if you're. I think you're a book reader rather
Speaker B: than a audience reading Fixing American Cybersecurity. It's a book that was, um, orchestrated by Larry Clinton. There's a lot of contributors to it, but Larry Clinton's the editor of the book. He's the, um, president of the Internet Security Alliance. This is, um, in some. Some sense a fairly controversial book and talking about regulation, a lot of proposals for change. I highly recommend anybody who's interested in the future of cybersecurity in America to read this book.
Speaker A: I will be ordering it off of Amazon. It'll be my, um, book to read on my flight next week. So Love, uh, that. Mr. PatrickGaul. NTSC.org Correct.
Speaker B: That's the website NTSC.org or PatrickTSC.org if
Speaker A: you're a CISO, um, and you're interested in getting involved or at least learning more about the ntc, you can reach out to Patrick. The, uh, NTSC is an amazing organization, a great collaboration for C. Says, um, and a definite great opportunity to have your voice heard. Patrick, on behalf of myself, continued, uh, and everyone on the show, thank you for coming on and continued success with the NTSC and everything you guys are doing. It's. It's really valuable work for a lot of us in this area.
Speaker B: James, always good to connect with you and looking forward to finding some time. And after you get back from Israel and catching up face to face.
Speaker A: I can't wait. Thanks, y', all for tuning in. Please make sure to subscribe to the latest and catch all the latest talk podcast episode episodes. Season three is just about wrapped up here. We'll be coming back with season four in August of this year. Um, with some really, really awesome guests I can't wait to share, so tune into that. Till then, have a great rest of your day. And most importantly, I'll stay cyber safe.
Speaker C: Make sure to subscribe to our podcast and share it with your friends and colleagues and get all the latest information@cyberhubpodcast.com.