The Next Era of Cybersecurity Regulation
Esmond Kane explains why the next era of cybersecurity regulation will move beyond point-in-time compliance toward continuous evidence, measurable control effectiveness, executive accountability, and operational resilience. He also explores how AI, supply-chain risk, and faster disclosure requirements are reshaping what organizations will be expected to prove.
Future regulation will increasingly require organizations to prove that controls work continuously, risks are being reduced, leaders understand their accountability, and the business can recover when disruption occurs.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, Security Leaders and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Esmond Kane to discuss the next era of cybersecurity regulation. Esmond, thank you for taking the time to join me today. To get us started, could you introduce yourself and tell us a little bit about your background and your current role?
Sullivan, thank you for the opportunity for the record, and and I hope the audience gets something out of the conversation today. So I'm the Chief Information Security Officer for a company called Advara. Advara is one of the leading research management and clinical trials management services and companies in on the planet. I've been very lucky to be there. CISO for a couple of years now. I've been working in healthcare for a couple of decades. I will state for the record though Sullivan, any comments here today are are my own, not necessarily those of my employer.
Perfect. So cybersecurity regulation is accelerating globally. What do you believe will fundamentally define the next era of regulation compared to the last five to ten years?
Yeah, so we're we're seeing a lot of technology disruption right now. It's it's all AI all the time. And certainly I think there's a lot of innovations that's that's driving some of that change. But I think there's some foundational things that have been pent up over time, irrespective of the technology that will drive some of our future regulations. In the past, the the kind of pace of change was such that a point in time snapshot was was okay. You know, compliance served a purpose. The issue was really it wasn't continuous, it wasn't really adaptive, it really wasn't responding to current circumstances. So a lot of the focus was on things like policies, controls, just control existence, not necessarily control efficacy. So the next kind of phase of regulations are really going to dive into some of that, whether it's third-party or corporate policies, things of that nature. It's gonna ask a much harder question. Can you prove that your controls, that your policies are working all the time? Can you capture that evidence? Can you demonstrate what the risk is right now? Can you demonstrate that you're reducing that risk and that your leadership is investing in making sure that risk reduction is being reflected all the time? So I mean we've seen things like the SEC are pushing things, the the EU there's certainly something starting to happen in the US. You're starting to see things like more kind of senior executive level accountability beyond the cybersecurity and IT leaders. You're seeing requirements for material disclosure. Things like Cercia in the UAS in the US are kind of driving that window even closer. But you know, foundationally you're looking at continuous compliance, you're looking at kind of oversight that that compliance is effective. That those risks are being reduced. And kind of a as a last thing I'll just throw out there. If there's one been one lesson for the last couple of decades, it's been that the bad guys are able to innovate just as much as the good guys. So there's certainly been a renewed focus from a regulatory perspective on on resilience. Kind of the the adage that you know, Mike Tyson says, Can you take a punch? Can you get back up again?
Those hard questions that you are talking about, are there any other hard questions that you think that the next era of cybersecurity regulation will require? Anything that you've seen from, you know, you said mentioned the EU, the US introducing some new regulations. What are you what are you seeing in that regard?
Yeah, it's very similar to what I just described. It's this kind of transition to outcomes. It's this transition to proving. It's kind of show, don't tell.
You know, can you recover quickly? Can you demonstrate that you're able to stop lateral movement? Can you respond to disruptions in your supply chain? The The bad guys, like I said, they're using AI as much as the good guys and the the pace of change, the the kind of threat that this acceleration presents means that you need to be moving faster, you need to be relying on standards, you need to have security by design, you need to be able to demonstrate that discipline, not just on paper, but actually with appropriate measures.
So you had touched on this in your answer to the first question, but as regulations evolve, how do you see responsibility shifting among the CISO, executive leadership, and the board?
So we've been hearing for several decades now that boards are are going to be held a lot more accountable for risk management. And I think we've seen that certainly from a financial perspective. I think we're starting to see that evolve from a cybersecurity perspective. We we've seen it from environmental controls, maybe social controls, diversity, things of that nature. But in most organizations the CISO still owns that that security operating system, as it were, the how the the organization programmatically addresses cybersecurity risk. It's still a cybersecurity discipline. But the adage is that if you think something like ransomware is a security matter, you'll learn pretty quickly if you get hit that actually you can't function without business. So cybersecurity is is a business issue. We also are very fond of the mantra in in healthcare that cybersecurity is a patient safety issue. But you know, when you're looking at this larger focus, certainly an element of this is to start with some level of of shared responsibility or kind of board level visibility. So things that aren't directly control driven, like funding, like risk acceptance, like like prioritization, like alignment with the business initiatives, those are typically things that senior executives and boards are driving. But there's a huge element of those that overlap with cyber security and as a security leader you need to align so that your controls are iterative, that they're introduced pragmatically, that they're not disruptive, that you don't let the bad guys dictate the tool set and the tempo of introducing these things. So when you're look when you're looking at things like the SEC, as I'd mentioned earlier, NIS2, certainly you're starting to see things like boards having to approve and demonstrate the they're getting presentations from the CISO, that their oversight is sufficient to to kind of fund the program, and that if there are risks, whether it's audit or compliance or cybersecurity driven, that they're acknowledging them and indeed they might be held liable for infringements. We'll have to see, but that that's what it looks like from my perspective, certainly.
So you had mentioned that AI is changing how both attackers and defenders operate. How do you believe the next generation of regulations should address AI-related risk without unnecessarily slowing innovation?
Yeah, I mean it's it's such a hard question to ask, Sullivan, 'cause today's AI isn't tomorrow's one and it wasn't yesterday's one. It's it's just such an accelerant. It's just a catalyst for change. We've certainly not seen AI actually demonstrate a large increase from a from a business perspective, an outcome perspective. But certainly we're seeing the bad guys start to use it. The good guys are certainly seeing some productivity impacts. It's it's relatively minor. You know, to go back to an adage we used during the the build-out of the internet era, there's there's no killer app yet. There there isn't really a must. Everybody's kind of feeling their way through it. But certainly when you're feeling your way through that, you should be doing things like establishing governance, establishing oversight for for your your utilization, your requests. whatever case may be, you you should be approving that and and documenting it. You also need to kind of, as I mentioned earlier, with respect to kind of the life cycle, you need to be revisiting some of these decisions because they're they're very time-bound. And you know, as much as we're all enamored with large language models and things like harnesses, there's things like small languages models out there and other kinds of stuff starting to drop and desktop automation beyond kind of the investments we made in corporate automation. So, you know, in summary. You need to be looking at AI from a risk perspective, where it's being used, what data it can access, what decisions it's influencing, and that you demonstrate that those decisions are documented and surfaced. And what guardrails exist around that kind of oversight, that that kind of testing, that potential bias. you know, there's things like AI RMF, there's the EU AI things, these certainly the NIST one is is voluntary. And it's it's a little dated. We we'll start to see what happens as sense or see kind of engage there. But there's some interesting things happening from a critical infrastructure perspective, Sullivan that I think will respond to that pace, that respond to that change. But certainly the foundational controls are or risk assessment, visibility kind of tying it to some kind of life cyclifecle or renewal.
And do you believe that there's an area that regulators may be most likely to overcorrect in the AI space?
Yeah I mean you'd mentioned around regulations earlier and and kind of the move from them being point in time to them being continuous. I worry that that's something that they might repeat in this this instance. It's maybe focused heavily on deployment rather than continuous maintenance. I mean there there's there's a phase change about to happen in US healthcare where HIPAA kind of version two, the December twenty twenty four NPRM was anticipated in May of this year and now we're anticipating it in in July of next year. But you know HIPAA isn't very conscious of things like cloud, right? Or or Software as a Service. So I I'm hoping that they include some AI language in there and that it's not overly burdensome. That it's not gonna just be a gift to Silicon Valley or cybersecurity. So I worry that will be overly prescriptive to answer your question. You know, for for me it's it's less around the the fact that AI exists or you're using it to speed your business. It it's around the fact that it's influencing decisions. And if if if you're gonna trust too much in AI and and if they're not going to dive into that from that continuous establishment of trust, I I worry that that these these frameworks will kind of overreact and kind of do what we can amply demonstrate hasn't been working to defend against ransomware or or third party attacks.
So to touch on third party attacks, how do you expect regulatory expectations around third party and software supply chain risk to change over the next five years, five to ten years?
Yeah, so so I I can hope that that change healthcare was was a wake up call. It's not just enough to do a point in time snapshot that you are assessing for risk when you're onboarding that vendor. You know, you need to kind of do that continuously. You need to know as that vendor changes, as you integrate more with them, as they become more critical to your business, that that's being elevated and maybe you're being reviewed. You might start with secure by design, but do you have secure by operations? Vulnerability management, how are they dealing with the same problems you're dealing with? How are they handling AI? Are they just shoving AI down your throat without kind of giving you an opportunity to review it or and disable it? You know, we're seeing the CRA out of the EU kind of drive some of these things. They're certainly starting to hold manufacturers more accountable. Software manufacturers in particular, it it's not just enough to design. You know, what does your update process look like? Cause the bad guys are going after both of those things. How are you continually kind of investing as a manufacturer but also as a consumer of these products to address some of these vulnerabilities? You know, if you can tighten the blast radius of a potential threat actor exploiting your third party. You know, that's secure by design, secure by operations. That that's kind of continual investment. You know, it it's just an opportunity, I believe, to to invest. I think waiting for regulators to drive that is you're ignoring the headlines with, you know, all the MPM breaches of the day, whether it's change, whether it's these various other ones. The opportunity to act is is now and certainly do it more than just that point in time. Monitor continuously if there's one thing. I advocate for.
So as more countries and industries introduce their own individual regulatory requirements, do you expect greater regulatory alignment or do you in or do you expect it to fragment as an as for global organizations?
I mean, expect the best, prepare for the worst. I think we're gonna see more fragmentation. I think with certainly what's happening from the US perspective, destabilizing the the national vulnerabilities database, kind of you know, defunding CISA, kind of pushing things to happen more at the state level with with kind of the inertia that's happening at the federal level. It certainly it worries me and I I think that's now a global problem. It's it's it's both a geopolitical and a technology issue. You know, if even if I look at from an AI perspective, you've got a certain nation pushing a lot of free and and public models, which is kind of directly impinging on on some of the private models in in in the Western world. But yeah, I I expect fragmentation, both from a governance perspective, from kind of like a a very prescriptive perspective around things like incident reporting and you know your tolerance for risk and and what your board is expected to do. There'll be different laws, there'll be different reporting timelines, there'll be different enforcement models. It's going to create an opportunity for security leaders to create these unified frameworks, I think. Again, something we've been working on for a while. I don't think it'll be necessarily one core compliance model. It'll it'll hopefully be one core cyber risk management model or enterprise risk management model with multiple kind of outcomes. You you'll need to have regional authorities, you'll need to have overlays around reporting and liability and obligations, certainly, and on if you're in the manufacturing space or or the development space. Yeah, what you know you know, I just look at what's happening at the SEC. I look at what's happening with like Dora, NIST, CRA there's things happening in in in India, Japan and in China. The some of them are are all kind of around the same outcome, but kind of the the the flavor will differ and and and how you present that and how you manage it is is certainly going to be fragmented to use your language.
So how should organizations, especially multinational organizations and security leaders that work there approach dealing with these fragmented regulations across the EU, Asia, the US, California, and you know, across the rest of the world?
Yep, Canada, Latin America. There there's certainly an evolving regulatory landscape there. You know, I do think as we described earlier, good governance, aligning your program with your initiatives, being able to demonstrate, not just design. I think that that change around accountability is stark. I encourage people to be investing in that right now. I'd mentioned secure by design earlier. Holding your vendors, or indeed if you are a vendor, holding them accountable for product safety for for outcomes is something I'm not certain where you know the the industry is ready for yet. If you look at kind of like the focus on resilience, if you look at the focus on on AI accelerated vulnerability disclosure, who's accountable there? You know? If you push an update or you consume one, you you have to test that now. And and the testing cycle is is greatly shrunk. You can plan for that, but we don't want another dress exercise like like unfortunately what CrowdStrike* went through last year or the year before. Yeah, you know, how are you consuming some of these offshoots from from vulnerability disclosure or secure by design? I think that's something that we're still trying to adapt to in in a post-mythos world. That moving at machine speed, if all you're gonna do is patch, you're just gonna create a another NPM breach of the day, another CrowdStrike event. It's it's it's a disservice to to your your constituents, your your company. You should be advocating for kind of continuous risk assessment and risk awareness and context and you know, building that zero trust secure by design so that the blast radius is greatly contained.
So what major regulatory developments do you believe security leaders are least prepared for today?
Yeah, I the change in governance as I described earlier. we've been working on things like asset visibility and zero trust for decades and it's continually frustrating. identity now that all of these systems and AIs are gonna have their own identity, that's that's gonna be a continual struggle. Resilience, it's all easy to say things like a cold start recovery or having a hot site, but that's an expensive proposition that's typically unavailable for the more mature and well funded organizations. Being able to demonstrate these controls and providing evidence and kind of assessing for risk, these are all gonna be very difficult. I mean, Sullivan it's so hard. You know, even just responding to the change in in regulatory landscape is huge. You can't govern what you can't see, right? So, you know, if your controls are are point in time and it's historical, it's stateful, that's not reflective of current reality. And the bad guys are gonna jump on that. And when they do, can you recover? Right? How quickly can you recover? Are you testing that recovery? That's an expensive proposition. You know, it's great to prevent that that's always the cure is is isn't as as well valued as prevention if you can do it. You know, but how do you evidence that? How do you demonstrate a regular? How do you demonstrate to your board that you can do these things that you think you can? You know?
So as a security leader, if you were building a security broke program with the next decade of regulation in mind, where would you start and which capabilities would you prioritize now?
So I always start with kind of the threes, which is what needs to start, what needs to stop, what needs to continue. So you need to look at what sources of truth that you have. You need to know you know what you're walking into, what risk assessments exist, what penetration tests exist, what compliance obligations exist, what what attestations you can rely upon, what perhaps need more work. You need to kind of invest energies in that. You also need to figure out from a tactical perspective who are the movers and shakers. You know, it's not necessarily the hierarchy. Some of the go-tos, the people who get things done, may be buried on an org chart. So kind of establish that mind map of who it is that you can partner with. Kind of the other thing I think you need to do in this era is it's no longer acceptable to be a roadblock. You can't be the security team of the past, which was the department of no. You need to be the department of let's have a conversation. How do we help you get to where you need to go? And it might be an iterative process and take several phases. You know prevention, as I mentioned earlier, huge response huge, fast response in this era of AI is huge. How do you scale your program? If if you're working in a startup that's hyper growth, how do you automate? What does policy as code look like? Those are some of my general principles, Sullivan, when I look at things and certainly I don't see that changing over the next decade and beyond.
Okay. So as we wrap up today's episode, how do you believe this next era of regulation will change the CISO s the personal accountability of the CISO role?
Yeah, it's a tough question. So I mean when I think of this, the role of the CISO is just changing so dynamically. When you go back to what Steve Katz is doing, was doing, bless him. You know, it was different from what a lot of thought leaders are doing. But I talk to my peers, and and some of them are doing different things than I am. Some are very governance driven, some of them are very technical. What a CISO is doing is is gonna vary widely by the organization's needs. So there there isn't a a kind of a template really. But you know, I mentioned a lot of of things throughout this conversation. There's things that I think need to improve, demonstrating, not being distracted by the shiny, you know, focusing on regulations as being an enabler, a catalyst, but not the end goal. Focusing on demonstrating that you're reducing risk, that you're containing the blast radius. It's okay to be credible from a technical perspective, but can you speak to the business? Can you change that culture? Can you get a how ahead of kind of like executive education so that they're making informed decisions and they're using you as a trusted advisor? We've been talking about that for a while. In the last five years, we've seen a focus on personal accountability and personal liability as well. I certainly hope a lot of CISOs are on the DNOs. you know, the the the CISOs can't own everything. So you're working through abstraction, you're influencing, but you have a certain amount of key levers that include board visibility, executive visibility, you know, funding and prioritization. These are things that you can align. I think the last thing I I'll throw in there is Incident response is a big one. Both the EU and the SEC and indeed CIRCIA are going to require you to do a lot more there. So that needs to be well exercised muscle. You you need to be doing your tabletops, you need to understand who owns what. There needs to be a RACI when it comes to your response. You know, you can't do this alone. You're leveraging your vendors, you're leveraging your key partners internally and externally. I would certainly advocate you lean on your federal partners. CISA have been a great help to me through the many, many years. The the AHISAC and others have been a great help to me through the man through the many years. So yeah, those are my thoughts, Sullivan. More accountability and certainly more evolution, I think.
Excellent. All right. Well thank everybody thank you everybody for watching. If you enjoyed this conversation, be sure to like, subscribe, and leave a comment with your thoughts or suggestions for future guests and topics. And thank you again to Esmond Kane for joining us today. And we'll see you guys in the next episode.
Thank you very much, Sullivan, and and thank you for the audience. If you want to connect with me on LinkedIn, please do. Thank you.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.