fechar
fechar
Sua Rede do Amanhã
Sua Rede do Amanhã
Planeje seu caminho rumo a uma rede mais rápida, segura e resiliente projetada para os aplicativos e usuários aos quais você oferece suporte.
Experimente a Netskope
Coloque a mão na massa com a plataforma Netskope
Esta é a sua chance de experimentar a plataforma de nuvem única do Netskope One em primeira mão. Inscreva-se em laboratórios práticos e individualizados, junte-se a nós para demonstrações mensais de produtos ao vivo, faça um test drive gratuito do Netskope Private Access ou participe de workshops ao vivo conduzidos por instrutores.
Líder em SSE. Agora é líder em SASE de fornecedor único.
A Netskope é reconhecida como a líder mais avançada em visão para as plataformas SSE e SASE
2X é líder no Quadrante Mágico do Gartner® para plataformas SASE
Uma plataforma unificada criada para sua jornada
Protegendo a IA generativa para leigos
Protegendo a IA generativa para leigos
Saiba como sua organização pode equilibrar o potencial inovador da IA generativa com práticas robustas de segurança de dados.
E-book moderno sobre prevenção de perda de dados (DLP) para leigos
Prevenção Contra Perda de Dados (DLP) Moderna para Leigos
Obtenha dicas e truques para fazer a transição para um DLP fornecido na nuvem.
Livro SD-WAN moderno para SASE Dummies
SD-WAN moderno para leigos em SASE
Pare de brincar com sua arquitetura de rede
Compreendendo onde estão os riscos
O Advanced Analytics transforma a maneira como as equipes de operações de segurança aplicam insights orientados por dados para implementar políticas melhores. Com o Advanced Analytics, o senhor pode identificar tendências, concentrar-se em áreas de preocupação e usar os dados para tomar medidas.
Suporte Técnico Netskope
Suporte Técnico Netskope
Nossos engenheiros de suporte qualificados estão localizados em todo o mundo e têm diversas experiências em segurança de nuvem, rede, virtualização, fornecimento de conteúdo e desenvolvimento de software, garantindo assistência técnica de qualidade e em tempo hábil.
Vídeo da Netskope
Treinamento Netskope
Os treinamentos da Netskope vão ajudar você a ser um especialista em segurança na nuvem. Conte conosco para ajudá-lo a proteger a sua jornada de transformação digital e aproveitar ao máximo as suas aplicações na nuvem, na web e privadas.

Este episódio apresenta uma entrevista com Emily Heath. Emily é vice-presidente sênior e diretora de confiança e segurança da DocuSign. Antes de seu mandato como Chief Trust & Security Officer da DocuSign, Emily atuou como CISO para a United Airlines e AECOM, ocupou vários outros cargos de liderança em tecnologia e estratégia e começou sua carreira como detetive de esquadrão de fraudes na força policial do Reino Unido.

Neste episódio, Emily explica por que o ransomware é o risco de crescimento mais rápido na segurança cibernética atualmente, como a pandemia afetou a DocuSign e a função de Emily e por que ela prevê que os CSOs serão alguns dos profissionais mais bem pagos no futuro.

Esse cenário está mudando e chega a um ponto em que acredito honestamente que as OSCs serão alguns dos profissionais mais bem pagos no futuro.

Emily Heath, vice-presidente sênior e diretora de segurança da Trust & na DocuSign
Emily Heath

 

Carimbos de data/hora

*(2:40) - Como Emily e Jason se conheceram
*(3:10) - Primeiro trabalho de segurança de Emily
*(4:10) - Função atual de Emily na DocuSign
*(5:15) - Segmento: Tópicos Tabu
*(6:35) - Pagar resgate ou não pagar resgate
*(8:00) - Outros riscos de crescimento rápido dos quais as pessoas não estão cientes
*(10:35) - Segmento: Mergulho Profundo
*(12:15) - Carreiras são quebra-cabeças
*(15:05) - Diferenças e semelhanças entre United Airlines e DocuSign
*(17:35) - A parte “Trust” do título DocuSign de Emily explicada
*(21:25) - Como a pandemia afetou o papel de Docusign e Emily
*(26:50) - Segmento: Sentindo-se vulnerável
*(27:55) - Os pensamentos de Emily sobre decisões instintivas vs. dados/decisões tendenciosas
*(31:25) - Por que as OSCs estão deixando seus empregos
*(37:40) - Como é a aposentadoria de Emily
*(39:30) - Segmento: No Futuro
*(42:40) - Segmento: Golpes Rápidos

 

Outras formas de ouvir:

Neste episódio

Emily Heath
Vice-presidente sênior e diretor de confiança e segurança da Docusign

divisa

Emily Heath

Antes de ingressar na DocuSign, Emily Heath atuou como CISO da United Airlines em Chicago por quase três anos. Antes dessa função, ela foi CISO na AECOM em San Francisco, ocupou vários cargos de liderança em tecnologia e estratégia em empresas no sul da Califórnia e começou sua carreira como detetive de esquadrão de fraudes na força policial do Reino Unido. Heath também é membro do conselho da LogicGate, da National Technology Security Coalition e da Security Advisors Alliance. Ela também é membro do Conselho Consultivo do Cyberstarts Venture Capital Fund.

Jason Clark
Diretor de Estratégia e Marketing da Netskope

divisa

Jason Clark

Jason traz para a Netskope décadas de experiência na construção e execução de programas estratégicos de segurança bem-sucedidos.

Anteriormente, ele foi diretor de segurança e estratégia da Optiv, desenvolvendo um conjunto abrangente de soluções para ajudar os executivos de CXO a aprimorar suas estratégias de segurança e acelerar o alinhamento dessas estratégias com os negócios. Antes da Optiv, Clark ocupou um cargo de liderança na Websense, onde foi a força motriz por trás da transformação da empresa em fornecedora de tecnologia crítica para diretores de segurança da informação (CISOs). Em uma função anterior como CISO e vice-presidente de infraestrutura da Emerson Electric, Clark reduziu significativamente o risco da empresa ao desenvolver e executar um programa de segurança bem-sucedido para 140.000 funcionários em 1.500 locais. Anteriormente, ele foi CISO do The New York Times e ocupou cargos técnicos e de liderança em segurança no EverBank, BB&T e no Exército dos EUA.

Emily Heath

Antes de ingressar na DocuSign, Emily Heath atuou como CISO da United Airlines em Chicago por quase três anos. Antes dessa função, ela foi CISO na AECOM em San Francisco, ocupou vários cargos de liderança em tecnologia e estratégia em empresas no sul da Califórnia e começou sua carreira como detetive de esquadrão de fraudes na força policial do Reino Unido. Heath também é membro do conselho da LogicGate, da National Technology Security Coalition e da Security Advisors Alliance. Ela também é membro do Conselho Consultivo do Cyberstarts Venture Capital Fund.

Jason Clark

Jason traz para a Netskope décadas de experiência na construção e execução de programas estratégicos de segurança bem-sucedidos.

Anteriormente, ele foi diretor de segurança e estratégia da Optiv, desenvolvendo um conjunto abrangente de soluções para ajudar os executivos de CXO a aprimorar suas estratégias de segurança e acelerar o alinhamento dessas estratégias com os negócios. Antes da Optiv, Clark ocupou um cargo de liderança na Websense, onde foi a força motriz por trás da transformação da empresa em fornecedora de tecnologia crítica para diretores de segurança da informação (CISOs). Em uma função anterior como CISO e vice-presidente de infraestrutura da Emerson Electric, Clark reduziu significativamente o risco da empresa ao desenvolver e executar um programa de segurança bem-sucedido para 140.000 funcionários em 1.500 locais. Anteriormente, ele foi CISO do The New York Times e ocupou cargos técnicos e de liderança em segurança no EverBank, BB&T e no Exército dos EUA.

Transcrição do episódio

Aberto para transcrição

Emily Heath (00:00): This landscape is changing and it comes to a point where I honestly believe CSOs are going to be some of the highest paid professionals in the future, and it's already heading in that direction over the last few years. We've seen a lot of change already, but this is going to be one of the most highest paid jobs in business because it will get to a point that you're not going to be able to pay people enough money to take on this amount of risk.

Producer (00:25): Hello and welcome to Security Visionaries, hosted by Jason Clark, chief security officer and chief strategy officer at Netskope. You just heard from today's guest Emily Heath, senior vice president and chief trust and security officer at DocuSign. It's been said that you don't get paid for how much you work, but for how much responsibility you have. And in today's modern business world managing risk is a massive responsibility. As cybersecurity threats dominate the headlines the role of security leads, whether they're chief security officers or chief information security officer, becomes one of the most important functions in the C-suite.

Producer (01:06): They're responsible for safeguarding the data, money, and everything else vital to the business. The role is anything but easy, and as Emily points out, individuals capable of shouldering this burden are going to become some of the most sought after executives in the world. And Emily isn't backing down from the challenge. In fact, she's encouraging her fellow CSOs not to either. Before her tenure as DocuSign's chief trust and security officer, Emily served as CSO for United Airlines and AECOM, held various other technology and strategy leadership roles, and began her career as a fraud squad detective in the UK police force. But before we dive in and hear more from Emily, here's a word from our sponsor.

Sponsor (01:50): The Security Visionaries Podcast is powered by the team at Netskope. Netskope is the sassy leader offering everything you need to provide a fast, data centric, and cloud smart user experience at the speed of business today. Learn more at netskope.com.

Producer (02:08): Without further ado, please enjoy episode three of Security Visionaries with your host Jason Clark and Emily Heath, senior vice president and chief trust and security officer at DocuSign.

Jason Clark (02:21): So welcome to Security Visionaries, I am your CSO at Netskope. Today I am joined by a very special guest and good friend, Emily Heath. Emily, how are you?

Emily Heath (02:31): Jason, always a pleasure to see you. Doing well, thanks.

Jason Clark (02:34): I was thinking about this conversation. I'm thinking, when did I meet Emily? Do you remember when the first time we ever met was?

Emily Heath (02:42): God, now you're going by a few years, buddy. Probably, I don't know was it Security Advisors Alliance in Dallas?

Jason Clark (02:51): Right.

Emily Heath (02:51): Right? Yeah, it was.

Jason Clark (02:53): Yes, the Advisor Alliance in Dallas and I remember you, I remember it was actually at the bar and we both were ordering I think it was

. Emily Heath (03:02): That would be a good choice.

Jason Clark (03:05): And then we were like, hey, and we just kind of started talking. I think that was probably six or seven years ago.

Emily Heath (03:09): Yeah.

Jason Clark (03:10): So getting started what was your first, tell us about your first security job.

Emily Heath (03:14): Oh my gosh. Well my very first security job goes way back 25, 30 years or so. I used to be a police officer in England, I was a detective for many years. And this is kind of about the era when cyber wasn't really a thing back then but computer crime was starting to be a thing. And so I worked in the financial crimes unit in what we called the fraud squad, and that was the unit that was responsible for computer crime. And it was completely foreign to me at the time, I mean going back in those days you used to go do a raid on a business or a home, and you'd come out with hundreds of bankers boxes full of contracts and documents. And it's just such a turn to see how that now is all translated to cyber. But I like to think that from a cyber perspective that was probably the very first job trying to dissect computers.

Jason Clark (04:09): And tell us a little bit about your job today and your current role at DocuSign.

Emily Heath (04:12): Yeah, so my job at DocuSign now is a little varied actually. So I'm the chief trust and security officer, so there's a couple of sides to that. There's the usual cyber security related stuff that you would imagine, security architecture, engineering, security operations, and all of those things. I also have the governance risk and compliance group. I have fraud, physical security, health and safety as well. And then the trust side of the job is actually a very customer facing side of the job. So DocuSign as many people know is a really trusted platform because we're a part of our customer's ecosystem, security and trust is super important. So I spent a ton of time with customers now, which I love.

Jason Clark (04:53): I think that's something that's going to continue to evolve for every company that is a [inaudible 00:05:00] technology organization. [inaudible 00:05:02] economy that is, the chief trust and security officer being very engaged with the customers will come, I think, the norm.

Emily Heath (05:11): Yeah, exactly.

Jason Clark (05:12): So getting, our first kind of segment here is taboo topics.

Jason Clark (05:26): Well this segment's about security taboos, misconceptions, controversy. And by the way, you can ask me anything, bring up anything you want to bring up. But the first question for you on this is what do you believe is the fastest growing risk in cyber security today, right? That effects most companies?

Emily Heath (05:43): Yeah. God, there's so many of them it's hard to choose one. I think ransomware is the one that just brings to mind just because you think about the monetization of crime when it comes to cyber, these attacks are no longer just to inconvenience organizations or bragging rights, there's a lot of money in this crime. Long gone are the days where somebody walks into a bank with a [inaudible 00:06:07] shotgun and walks away with $20,000 at best. I mean you're talking millions and tens of millions for these types of crimes. So I think ransom is, we're just seeing the beginning of it. And the more and more you see that companies are paying ransoms, it's just going to proliferate the problem. So it's a trend unfortunately I don't think is going anywhere anytime soon.

Jason Clark (06:30): So it's the new bank robber basically, right?

Emily Heath (06:34): Yeah.

Jason Clark (06:34): So what's your thoughts around, kind of this feeling like this taboo topic, what do you feel around should companies be paying the ransom or not be paying the ransom? What should legislation be around that?

Emily Heath (06:45): God, it's such a tough one. I don't even know where the legislation can be involved in that. It's a really slippery slope because there's a cost of doing business, and if this becomes a new cost of doing business, I mean I'm not advocating for it in any way shape or form, but every organization is different and until it hits you and until your operations are the ones that are crippled, it's really difficult to say whether or not you should or shouldn't pay a ransom. I mean we all know that there's never any guarantee that you're going to get out the other side of it anyway. But if you look at some of the companies recently that have paid ransoms, we are not in the room, we don't know the impact to their actual business function. And I just, I'm not sure whether this is going to end up being a legislation issue, it's a business issue.

Jason Clark (07:34): Yeah. I mean sometimes it can mean lives, right? I mean getting electricity turned back on or getting the medical systems you need turned back on, that shouldn't be a choice that is made because of a law, right? And when you look at it, ransom is obviously a very, very hard problem and we just need to obviously get better at everything. I think, curious like if you think about ransoms, okay that's one, but what's one that you think people are not aware of? What's the fastest growing risk as a CSO? What do you think is growing that a lot of IT organizations, a lot of boards are unaware of? So ransoms in the news every single day, but is there anything else that you can think of that is a rapid growing risk that you think those leaders should be aware of?

Emily Heath (08:24): Yeah, there is a little bit of a theme right now where you're seeing a lot of experienced security professionals leaving the industry. And my fear is that there's going to be a big hole, right? This business has been around for a while but certainly not to the magnitude that it has been over the last four or five years or so. And a lot of the security professionals are leaving the industry to go vendor side, or they're leaving to go to a VC side. The talent and expertise that is leaving the security jobs is frightening. Don't know how you solve that necessarily apart from, as a leader it's our job to make sure that we are investing in the leaders of tomorrow. And I think as an organization I'm not sure there's this great organizational awareness to the big talent gap for senior leaders in the security business and really super talented folks, who honestly are moving to the vendor side and moving to the VC side because quite frankly there's more money in it.

Jason Clark (09:25): Let's talk about this a little later because we talk about the future but I think it's, there's more money but also the CSO job is extremely hard, very, very hard and very taxing.

Emily Heath (09:37): Super stressful.

Jason Clark (09:37): I mean there's many, many friends where they've been like, look Jason, I've given up my last vacation, or I was the best, Dave Fairman at RBC, he said, Jason, I was the best man at a wedding and I was told either go to the wedding or stay here, but if you go to the wedding you won't have a job. And that is emotionally taxing. So I think we're ending up in this where the threats are getting worse, the problem's getting harder, there's more data than ever, we have 57 zettabytes of data in the world and by 2025 there'll be 175 zettabytes. So I think as you think about that attack surface growing, and to your point the people are getting harder to find, that is, so I love that you pointed that out. I think that's a great unknown risk as you just said. So kind of going into a little bit of a deep dive.

Jason Clark (10:46): Maybe walk us through how you pivoted from in the Cheshire police to cyber, talk us through that transition.

Emily Heath (10:55): When I was a detective I took a career break for a while, and you can take a career break up to three years. And I did and the punchline is I taught myself how to code, don't tell anyone. But I taught myself how to code and I actually started my own web design business during the career break. By the time I went back to the police I realized that there was a big world out there and a world that I really wanted to explore. And so one of my former web clients actually called me one day and said, hey, are you interested in this opportunity at MGM studios in London? And it was working for a startup back in the days when DVDs were a thing, it was a startup that managed all of the DVD distribution and supply chain and inventory management for the movie studios. So I left the force, I left law enforcement and did that job. It was not a security job. I did many different areas of IT and technology before I kind of did full circle all the way back to security.

Emily Heath (11:48): But I was the lead program manager on a software implementation for the studios, that's how I ended up in the US maybe, almost 20 years ago now, working with MGM who got acquired by Sony Pictures, so I worked with Sony for many years. And then ultimately when that little thing called PCI came along, and I'd been running infrastructure teams, PMOs, web design teams, and engineers, my boss at the time said, hey, Emily, you were a cop. You were a cop, weren't you? You understand the law, can you figure out this encryption thing and this PCI thing, these laws that are coming in? So it was really purely by accident that I ended getting into more of a legal, compliance, security type role. But it's funny how you look back on your career and your life and you realize that it's all one big jigsaw puzzle. You don't realize at the time how one thing leads to the next. And then when you look back you realize, my gosh, I would not be set up for success in this job had I not done that job.

Emily Heath (12:50): And so it felt like coming home to me, my experience in technology coupled with experience in law enforcement. And they're two very different things, but the skill sets that you bring with you from law enforcement, the skill sets were a lot about people. It was, you're dealing with people from all walks of life. And I translate that to the constituents within an organization, right? I mean we deal with so many different stakeholders from so many different business units, and managing to navigate the corporate world is very much like law enforcement, you're just managing different characters. So it really did feel like coming home to me and I took a very deliberate path to choose the CSO route and not the CIO route. I had opportunities a few years ago to go one way or the other and I chose this route, and I chose the right one for me personally.

Jason Clark (13:44): I'm constantly asked by CSO's, I coach about 15 different CSOs and I'm asked, hey, I've got this opportunity to become the CIO or the interim CIO. And I actually generally coach them no. Focus on CSO, focus on security as a specialty that is going to grow increasing importance. And I basically tell them that financially I believe they'll make more or the same. You talked about kind of a little bit of your experience with PCI, I thank PCI to the start of my career as well. I was out of the army and the New York Times got compromised, and I got the CSO job at the New York Times when I was 27 years old because they needed to have a CSO title and it was driven by loss of credit cards and for one of their business units and I was asked to step in. And when else can a 27 year old with cybersecurity experience and the fact that I had management experience because I was military, I mean it's insane. That would not happen today, a 27 year old being a CSO that quickly. So I thank PCI as well.

Emily Heath (14:53): Yeah, I know. It's like the people ask why did you choose cyber as a career? And I said, I didn't choose it, it chose me. Definitely twists and turns.

Jason Clark (15:04): It's been amazing. So you were the CSO, we met when you were the CSO for United Airlines, and you had tremendous responsibilities there. What are the differences and the similarities between that and your current role at DocuSign?

Emily Heath (15:22): Yeah. So, I mean United Airlines I don't think it gets much more complicated than a huge, big, global airline. Just the sheer scale and complexity of an organization like that is incredible. And obviously it's a much bigger company than coming to DocuSign, so the differences of scale and complexity are very, very different, however the types of issues that we deal with are very much the same. And no matter where I go, or any company, or advice I give to other CSO friends who are joining new companies, I ask myself five fundamental questions, which really doesn't matter which organization that you're in. And it really comes down to what's most important to you first and foremost? A company like United, what's most important is human life. You're flying people, safety is number one. A company like DocuSign, we're a very data driven company so the agreements that people trust us with are what matter to us the most.

Emily Heath (16:19): So what matters most? Where is it? How are you securing it? Where are you most vulnerable and at risk? And how resilient are you when it hits the fan and you need to bounce back? And I think if you go into any new job and ask yourself those five questions, doesn't matter what company it is, doesn't matter what entity it is, those five questions are still very relevant. Because if you understand what matters to you the most you've got a framework to prioritize the task that's undoubtedly ahead of you. So the challenges are the same, it's the same kind of people, same kind of adversaries, scale and complexity is very different, but how you run a security program is fundamentally the same thing.

Jason Clark (17:06): Yeah, 100%. It's just different complexities. Scale is one but then when you're a company you have a different set, and it isn't harder or easier. When you said, when it hits the fan, I love how you said when it hits the fan, I quickly imagined the scene in Airplane, the movie Airplane, right? Where the shit literally did hit the fan, that's what I picture [inaudible 00:17:35]. So look, I love your title, chief trust and security officer. So talk to us a little bit about what additional responsibilities you have and how this changes the way either your company or your customers perceive you with the word trust in there?

Emily Heath (17:53): Yeah. So trust to me is, the security side is what we all understand. It's securing the nuts and bolts and securing the technology and all those things. When you start layering in this concept of trust it's about that intangible. It's the relationships that you're building with people. So when we are building relationships with customers, you cannot trust people that you don't know. So therefore the time I spend with customers is to build relationships with them because I see it as my duty and my obligation to be completely transparent about what we're doing. I think the foundations of how you build trust are truly embedded in that. So I'm not talking about just zero trust as a framework or trust as in what we traditionally have called trust within the security realms, it goes way beyond that to me. It really is a lot about the, you've got to walk your walk. You've got to show up. You've got to be transparent. You've got to be upfront and be honest.

Emily Heath (18:54): And it's actually more than just security. So for example, I also help run our ESG program, the environmental, social, and governance program. Because as part of the chief trust officer role it's not just security, what are the other element of trust and what does that mean to your organization? So I get heavily involved in topics like DNI, I'm a huge advocate of diversity and inclusion and belonging, as you know. The ESG type programs that any organization runs, that all falls under a trust umbrella. So it's really broader than just the traditional security, physical security, cybersecurity type realms because it's about your organization's trust and what that means to your customers, your partners, and your employees.

Emily Heath (19:40): So it's something that we are evolving like every other company. I feel very strongly that we shouldn't be using words like trust unless we know what that actually means to us and that we actually do something about that. This is not just a word, it's a way of being, it's the not just what you do, it's the who you are while you're doing it piece to me. So lot to do with the relationships and that spirit of transparency. And like I said, you can't trust people that you don't know.

Jason Clark (20:08): So how are you, this is a lot around the purpose of the company, right? And you're trying to purposely evoke an emotion from your customers and your employees, right? How are you partnering with marketing to make that happen?

Emily Heath (20:23): Yeah, so we're actually going through some branding and marketing right now and trust is one of our central pillars. DocuSign's been around for 18 or so years, and most people know us for the e-signature. And we've evolved way beyond that into what we call the agreement cloud and now the smart agreement cloud, trust is a fundamental part of that. And if you think about what people actually trust us with, all of their sensitive agreements, I mean their signatures for goodness sake. We're like if you can't trust us who can you trust? There's such an embedded element of that within who we are as an organization that it's been there from the very beginning of time for DocuSign, but we see now just how important that is in the fact that we are a part of our customer's ecosystem and we have to take that really seriously. So yeah, it's a lot about the culture and it's a lot about what matters to your organization. But like I said, it's the who you are while you're doing it piece as well.

Jason Clark (21:25): So as this unfortunate pandemic has happened for the last 18 months how has this changed and affected your role, and just obviously your employees at DocuSign as they try to engage and perform their duty?

Emily Heath (21:45): Yeah. So from the very beginning of COVID when that happened we already had a pretty large remote workforce, so thankfully we already had the technologies like the Slacks and the Zooms to support us so we were ahead of some companies in that respect. However, as we all know it's a definite shift when you've now got a full workforce who's all working remote on home computers and all of those kinds of things. I let the COVID, what we called the COVID 19 Task Force at the time, which was essentially classic crisis response, which is you get cross-functional teams together. At the very outset we were meeting multiple times a day, then we went to daily, and then we went to weekly meetings.

Emily Heath (22:27): But it was a way to bring the whole organization together from every department so that we could consider all the moving pieces across our employees and customers, because much like you and, and many other companies, we had lots of live events that we had to then transition to virtual. We had all of the employees to make sure that they've got all the equipment that they need, onboarding thousands of people since COVID. We've grown so much, we've onboarded thousands of people as new employees, and all that comes with a lot of logistics. So I think this is where CSOs and people who are used to dealing with crisis response are really best suited for these types of these types of initiatives. Because we kind of have that crisis response muscle where we are used to bringing cross-functional teams together to organize it. And it was just a, nobody asked me to do it I just kind of assumed the role and pulled the company together and played my part. And my team did and exceptional job as did the rest of the organization.

Emily Heath (23:32): But it's been tough I think for a lot of employees, just the same as every other company. Everyone's got a little COVID burnout fatigue and Zoom fatigue and all those things. We are taking this opportunity to really listen to our employees and see what they want. So we're highly likely to have a much more distributed workforce and a more remote workforce moving forward. We're going to be pretty much completely hoteling, so no dedicated desks or offices anymore. And that's what our employees want, they want the flexibility so we're taking that opportunity to give them just that.

Jason Clark (24:08): So there's no doubt it's been challenging. I've heard a lot of CSOs, and even using us an example myself and Lamont our CSO, it was a moment for him to step up. He has helped to lead and has been part of leading our COVID community, he also leads DNI as well. Just to say that this is our moment to make sure we're embracing and engaging our employees to the max we can. So I do think you're right, we have this muscle already. And so it's been really good for, I think in the end you think about just IT, forget security, being able to work from home would not have been really possible without IT, without digital, without technology, without VPN, without cloud. How would we have done this? We would've had to either made the decision of lose business or people will potentially have more vulnerability and more deaths. And so I think IT has been an interesting kind of quiet hero in this.

Emily Heath (25:19): And it's almost like as a society we've been forced to think differently. Many companies would never have taken the steps that they'd taken if we weren't all forced to be in this situation. And for us from a business perspective it's been incredible, of course. It's been great for our company's growth, but what really struck me at the very beginning of the pandemic was we were literally in the trenches with the state departments and the federal governments to try and move PPE around, you still need to do that with a signature. And there's this kind of common misconception I guess that the government agencies move so slow. Well sometimes yeah, but when they're forced into to a crisis in this way, the work that they did, and we had a front row seat to that, our customer support folks were working morning, noon, and night in the trenches with them to get them set up so that they could digitize and transform their own businesses and kind of these situations where we had to move equipment around. And it forced us all to pivot really quickly. And I think in some ways many companies have leapfrogged that digital transformation because now they see that they can do it.

Jason Clark (26:39): I've seen a lot of my own customer adoption to actual DocuSign. That's been a big part of their transformation. Especially healthcare, very, very big in healthcare. So transitioning to our next segment, which is called feeling vulnerable.

Jason Clark (27:04): And so in this segment we're going to kind of walk through kind of what are we trying to avoid? What are our vulnerabilities? And just again, just feeling vulnerable. Being very open, which we both already are in this conversation. So lot of times people measure risk differently. Like an example, sharks in the water. I was on vacation just two weeks go with a bunch of friends and there was a shark in the water. And one of the people I was with swam as fast as possible to the lifeguards like, there's a shark, there's a shark, there's a shark, yelling there's a shark to everybody. And everybody's just looking at this person and the lifeguard goes, yeah, we have sharks. They don't bite anybody. And it's like, what are you doing? Like, oh my gosh, we have to react to this. And I'm like, shark deaths are not a whole lot per year out of six or seven billion people.

Jason Clark (27:56): How much do you think that we are kind of maybe in security or IT making decision off of gut instinct versus really looking at the mathematics of the risk? Or just trying to drive check boxes? What's your thoughts on just maybe this issue amongst security in not really, like we buy product because everybody else is buying product, or were doing this because everybody else is doing this versus saying, was that the real issue? Is that the real risk? By the way, I just was the phone with somebody in a financial who said, we're doing segmentation because the auditors and the regulars say we have to, and I think it's the dumbest thing ever. Because I'm already segmented in the end, at the end point, and at the network layer, and I should be doing these other five projects but instead this is my biggest project of my year because the auditor and the regulators say I have to.

Emily Heath (28:42): Yeah, I can absolutely understand that. I think as much as we want to be science and data driven all the time, that's the ideal, right? You always want to have the data and the fact in front of you, but the truth of the matter is it's not always that tangible. And I think there are times when CSOs use their best judgment, and their experience, and their expertise in order to make decisions. Sometimes I think that's appropriate because otherwise, I mean at some point you've got to make a decision and move on. And those are the things sometimes you end up looking in the rear view mirror and go, did I make the right decision on this one or could I have done that differently? But at the time you don't always have the benefit I guess of weeks, or days, or months ahead of you to go collect all that data. And even if you wanted to it probably doesn't all exist.

Emily Heath (29:39): So there's a reality to the job that we do that's a little bit of art and a little bit of science that you have to use your best judgment in order to make those calls. I'm always an advocate for using data because a lot of the times what we try and do is explain situations to people who are not technical or explaining situations and translating them into operational or business risk, because ultimately that is our job. It's not always that straightforward to get data that will point you directly to a decision A, decision B, or decision C. So there's a little bit of an art and a science in what we do. And let's face it, if there was a book that you could pick off the shelf that showed a blueprint and how to do this job we would all love that. But the reality is that that just doesn't exist, we're facing new threats, and new adversaries, and new ways of operating every single day that you have to use your best judgment.

Emily Heath (30:38): And that comes from experience. Sometimes early in our careers we've made some decisions that perhaps weren't the best ones but we learn from it. And the big thing for me is this is why the security community is really special because we share things with each other when our lawyers tell us not to. We share things with each other because we care about one another and nobody wants to see anyone else in the headlines. I have never experienced, or seen, or heard of a community like this one. And it really is special, it's something else.

Jason Clark (31:10): That's amazing. I agree, there is nothing. We are one because, probably because we have a common enemy. And it is tremendous and it's in the end and why I think a lot of our us love this industry and have not changed industries. So it kind of, as we think through this a little bit to your point earlier, we're talking about this industry. We talked about part of the risks are security leaders leaving the industry, why do you think that is? Why do you think that they're saying, okay, you know what? I'm going to go do something different, I've done this three times now. We do love this industry but why are they leaving the operational CSO gig? Because it pays well, there's no doubt they can make seven figures. They're working at the top of their game so why are we seeing people leave these jobs to go, most of the time honestly take less money doing something else?

Emily Heath (32:11): Yeah, and I think it's a combination of what we were talking about earlier. Look, this job has gotten more visibility over the last few years without doubt, and that's something that you've heard CSO's beg for in the past and now I think that's all coming to fruition. And there's good sides and bad sides to that. You want all the visibility, you want the company to take it seriously, well guess what, they're taking it seriously. The flip side of that is the pressure that comes with it. This is a very high risk job. And it's a high risk job because we are managing programs that have so many facets and components that are not in our control. We rely on many, many different constituents to do things in certain ways in order for every body to succeed. I mean if you think about a lot of companies that have thousands of applications but let's say that the access controls were not up to snuff on 10 or 20 or 100 of those. It can't just be the CSO's fault, it's impossible. The CSO's one person, the security teams can only do so much.

Emily Heath (33:22): E como resultado disso, sim, é um trabalho de alto perfil, mas os riscos são enormes. Acho que agora você está começando a ouvir sobre o processo de CSO. O jogo está mudando, esse cenário está mudando e chega a um ponto em que acredito honestamente que os CSOs serão alguns dos profissionais mais bem pagos no futuro. E já está indo nessa direção nos últimos anos, já vimos muitas mudanças. Mas este será um dos empregos mais bem pagos nos negócios, porque chegará a um ponto em que você não poderá pagar às pessoas dinheiro suficiente para assumir esse risco, porque os processos que podem vir com isto. E você começa a pensar sobre o que isso significa para o papel, é um jogo muito, muito diferente.

Emily Heath (34:12): Você está falando agora sobre o que o conselho de administração geralmente é responsável e os riscos que acompanham isso, ou CEOs são responsáveis e o risco que acompanha isso, ou CFOs para esse assunto . Então, acho que o risco e a pura responsabilidade continuam aumentando e as pessoas estão sofrendo de esgotamento. E nem tudo é financeiro, definitivamente há um componente financeiro nisso, mas nem tudo é financeiro. Chega um ponto que é qualidade de vida e é difícil, né? Não é um caminho fácil, não é um papel fácil. Como você bem sabe, você conseguiu.

Jason Clark (34:52): Não vale a pena. Sim, chega um ponto em que é como, ok, já fiz isso várias vezes, mas está ficando mais difícil. E tudo bem, economizei o suficiente, como você acabou de dizer. E eu acho que as preocupações legais são preocupantes. E não é como os CSO's, uma coisa que me surpreende é que eles não estão conseguindo necessariamente o paraquedas nos meus contratos. Posso estar ficando ótimo [inaudível 00:35:20], mas eles também devem ser protegidos. Eu tenho muitas conversas com CSOs onde eles estão sendo pressionados a decidir algo ou assinar algo com o qual eles não concordam, mas eles estão olhando para isso dizendo, bem, eu tenho esta casa cara e eu tenho particular escola ou o que quer que seja, e não posso me dar ao luxo de dizer não ao meu chefe porque vou embora.

Jason Clark (35:41): E isso não é bom. Todos eles devem ser protegidos de que, se você discordar da sua organização, quiser desafiá-los e dizer: não vou assinar esse risco, eles podem ser protegidos, talvez seja um padrão de seis meses de renda? Mas agora são dois ou três meses. E já vi isso acontecer com muita frequência. Mas, no geral, acho que estava conversando com Jason Witty e é público que ele acabou de deixar o JP Morgan. É apenas uma questão de, podemos fazer muito mais com nossa experiência que podemos fazer com menos estresse potencialmente, ou mesmo maior renda quando você começa a falar sobre o que você mencionou, Emily, capital de risco. Mas o que fazemos, façamos o que fizermos, precisamos garantir que a próxima geração esteja pronta.

Emily Heath (36:44): Estou protegida, certo. Quero dizer, está chegando ao ponto de questões de responsabilidade, que diretores e executivos têm cobertura de responsabilidade para isso, OSCs não. Portanto, uma conversa diferente precisa ser feita em algum momento, caso contrário, chegará a um ponto em que você não poderá pagar às pessoas dinheiro suficiente para fazer esse trabalho. Porque se o resultado final ou a consequência potencial para uma ação que uma OSC tomou de boa fé ou uma ação que outra pessoa não tomou, se a consequência pode resultar na perda de tudo ou na prisão, Deus me livre, você não vai conseguir que as pessoas no trabalho façam mais isso.

Jason Clark (37:20): Exatamente. Como se você fosse instruído a pagar um resgate ou uma recompensa por sua liderança. Então, sim, é assustador. Mas vamos trabalhar com isso e, no final, acho que você, eu e muitos outros apenas temos que estar lá para os outros. Quando eles precisarem de conselhos, nós os treinaremos, nós os apoiaremos. Continuando, fiquei curioso sobre esse assunto, como é a vida de aposentadoria para você?

Emily Heath (37:51): Ainda não cheguei lá, mas ainda tenho muito no tanque. Mas a vida de aposentadoria para mim é, não sei se algum dia vou realmente me desconectar desta comunidade. Quer dizer, eu faço parte de um conselho público e de um conselho privado hoje, faço parte do conselho da Norton LifeLock como uma empresa de capital aberto e de um Logic Gate que é uma empresa privada de plataforma GRC. Há muito valor para os CSOs na vida do conselho por causa da experiência e profundidade que eles têm, e ainda é uma área onde há falta de compreensão, há muito valor a agregar. Então tenho certeza que isso continuará fazendo parte do meu futuro. Eu dou muitos conselhos como você, sem nenhum benefício, sem nenhum benefício financeiro, apenas porque é uma parte importante de, como você disse, temos que ajudar a próxima geração. E acho que isso nunca vai desaparecer. Haverá partes disso. Um dia farei a transição para fora da vida operacional, mas ainda não cheguei lá. Como eu disse, ainda tenho mais no tanque para mim. Mas eu imagino que a semi-aposentadoria pode parecer como servir em alguns conselhos que eu imaginaria e fazer algum trabalho sem fins lucrativos e de consultoria.

Jason Clark (39:07): Conselhos, coaching, consultoria, ajudando a indústria.

Emily Heath (39:10): Sim, exatamente.

Jason Clark (39:12): Sentado em uma praia ou nas montanhas por um tempo.

Emily Heath (39:15): Sim. Viajar pela Europa talvez, talvez na Provença ou algo assim. Atender algumas chamadas de Zoom da Provence pode ser bom.

Jason Clark (39:21): Um pouco. Sim, eu gostaria, meu sonho é fazer isso todo verão e trabalhar a partir daí todos os verões.

Emily Heath (39:29): Pronto.

Jason Clark (39:31): Tudo bem, então meio que pensando no futuro. Como estamos falando sobre isso, se pudermos avançar no tempo, no que você acha que as OSCs gostariam de ter investido para compensar no futuro? Como o que você sugeriria a todos, como pensar em cinco e 10 anos a partir de agora, quais são os investimentos mais importantes que eles poderiam estar fazendo além das pessoas?

Emily Heath (40:04): Além de pessoas, seguros. Provavelmente o seguro é um deles muito a sério. Mas se você está falando de mais tecnologia, ainda há muitas empresas que não estão investindo adequadamente em segurança na nuvem. Existem alguns pedaços de segurança na nuvem que eles têm e as pessoas confiam na capacidade nativa do tipo AWS e Azure, o que é bom até certo ponto, mas quando o mundo está ficando completamente na nuvem e todos estão se afastando do bare metal, você não pode confiar apenas no provedores de nuvem existentes, a pilha de segurança em torno da configuração, segredos, gerenciamento e todas as coisas que vêm com isso. Temo que muitas empresas estejam apenas falando honestamente sobre a segurança da nuvem.

Jason Clark (40:54): Acho que, quero dizer, minha resposta à minha própria pergunta seria: acho que segurança de dados. Como se fosse sobre os dados, é isso que estamos protegendo. DocuSign, são essas assinaturas, esses contratos, é sobre os dados e sinto que em minhas conversas somos muito imaturos no pensamento de proteção de dados porque estamos acostumados com os dados armazenados em nosso data center e temos esse grande perímetro. E acho que é uma área muito pouco investida para entender onde estão meus dados, como eles são protegidos? Qual é o risco aí? Qual é o impacto? Quão sensível é? Tudo isso porque prolifera.

Emily Heath (41:31): São aquelas cinco perguntas de novo, certo? São essas cinco perguntas, o que mais importa para mim? Cadê? Como estou protegendo isso? Quão vulnerável e em risco estou? E como estou preparado para quando atingir o ventilador? Parece tão simples quando você analisa isso, mas esses são os fundamentos do programa de segurança. E é diferente para cada empresa. E é difícil fazer isso, é difícil descobrir tudo isso. Porque essas perguntas estão totalmente carregadas de suposições de que, ei, você entende onde estão todos os seus dados e entende os ativos que os suportam e, a propósito, todos eles estão sendo provisionados da maneira certa? Eles têm toda a segurança ou todos os controles de acesso como deveriam? É soa tão simples, mas eu não poderia concordar. Eu acho, e muito disso para nós eu traduzo para nuvem porque obviamente é para onde os ambientes estão indo.

Jason Clark (42:19): Quero dizer, acho que a nuvem de certa forma torna as coisas mais difíceis no começo porque não é onde estão suas soluções, mas no final acho que facilita para nós. Como nós temos [inaudível 00:42:30], quero dizer, há muitas coisas que você pode fazer. Então é um lugar estranho temporariamente, mas no final e no futuro, acho que seremos muito bons. Então, último segmento, acessos rápidos. Perguntas rápidas para você e apenas respostas rápidas. Então você está pronto?

Emily Heath (42:54): Estou pronta, traga.

Jason Clark (42:57): Tudo bem. Qual talento ou habilidade você tem que não está em seu currículo?

Emily Heath (43:02): Sou curadora de Reiki, uma curadora de Reiki treinada.

Jason Clark (43:05): Uau, isso é muito legal.

Emily Heath (43:08): Algo completamente diferente.

Jason Clark (43:10): Eu nem sei o que é isso. O que é isso, Emilly?

Emily Heath (43:13): É uma técnica de cura com as mãos.

Jason Clark (43:15): Ah, legal. Eu vou pesquisá-lo. Então, em segundo lugar, se você não estivesse em redes e segurança, o que estaria fazendo?

Emily Heath (43:23): Eu seria uma chef. Eu absolutamente amo cozinhar. Eu apenas, é minha geléia, é como eu relaxo. Eu simplesmente adoro fazer as pessoas felizes com comida.

Jason Clark (43:34): E eu sei que esta é uma pergunta difícil porque também sou chef e é muito, mas qual é o seu tipo de cozinha favorito?

Emily Heath (43:43): Oh, isso é difícil. Venho aperfeiçoando minha receita à bolonhesa há uns 15 anos porque a comida italiana é simplesmente a melhor. Quer dizer, eu sou amante de carboidratos um pouco demais às vezes, mas a comida italiana é onde está para mim.

Jason Clark (44:01): Cara, o meu provavelmente é asiático. Apenas asiáticos, muitos sabores asiáticos. Mas precisamos nos encontrar em algum lugar na Costa Amalfitana, sair e nos divertir.

Emily Heath (44:15): Vamos fazer isso.

Jason Clark (44:18): E última pergunta, qual seria o seu principal conselho para um CSO pela primeira vez?

Emily Heath (44:23): Oh, eu diria para pedir ajuda. Como falamos anteriormente, esta comunidade é incrível e há tantas pessoas dispostas e capazes de ajudá-lo em sua jornada. Queria ter pedido mais ajuda no começo e ter um pouco mais de humildade em saber que não tenho tudo resolvido. E esse é um grande erro que as pessoas que entram nesta carreira pensam é que precisam saber tudo, conhecer todas essas peças em movimento. É impossível fazer isso. Quero dizer, se precisarmos fazer engenharia reversa de malware, sou a pior pessoa do mundo para fazer isso, tenho pessoas muito inteligentes em minha equipe que podem fazer isso. Não tem como eu saber tudo. Então você pede ajuda, pede orientação. Há tantos líderes incríveis e dispostos nesta comunidade de CSO que se esforçarão para ajudá-lo em seu caminho, então não tenha medo de pedir ajuda.

Jason Clark (45:17): Adorei, é incrível. Então olhe, isso é todo o tempo que temos. Emily, isso tem sido incrível. E eu amo todas as conversas que temos e sinto que poderíamos ter passado quatro horas facilmente. Antes de deixar você ir, se as pessoas quiserem pedir ajuda, se quiserem se envolver com você para alguma orientação ou o que quer que seja, qual é a melhor maneira de se envolver com você?

Emily Heath (45:44): Sim, me mande um ping no LinkedIn é a maneira mais fácil. É a maneira mais rápida e fácil. Já estou envolvido em muitas redes e sou mentor e treinador de muitas pessoas, como sei que você também, Jason. Você dedica muito do seu tempo a esta comunidade também. E embora não possamos receber 100 pessoas, o que eu amo é que se você tem uma avenida e um lugar onde pode ir e perguntar, ei, estou lutando com isso, o que você fez em essa situação? A propósito, faço isso o tempo todo com as OSCs. Se há algo com o qual estou lutando, faço a mesma coisa, estendo a mão para os amigos e digo, olha, isso é algo com o qual estou realmente lutando, como você fez isso? Então, eu diria para entrar em contato comigo no LinkedIn, me enviar um ping no Twitter. Muitos de vocês já têm meu endereço de e-mail e meu número de celular. Mas sim, estou aqui pela comunidade e também quero agradecer a comunidade por estar lá por mim também.

Jason Clark (46:36): Perfeito. Bem, obrigado e obrigado a todos por se juntarem a nós.

Emily Heath (46:40): Obrigada, Jason.

Patrocinador (46:43): O podcast Security Visionaries é desenvolvido pela equipe da Netskope. Procurando a plataforma de segurança em nuvem certa para permitir sua jornada de transformação digital? O Netskope Security Cloud ajuda você a conectar usuários com segurança e rapidez diretamente à Internet de qualquer dispositivo para qualquer aplicativo. Saiba mais em Netskope.com.

Produtor (47:04): Obrigado por ouvir Security Visionaries, reserve um momento para avaliar e avaliar o programa e compartilhá-lo com alguém que você conhece. Fique atento aos novos episódios lançados a cada duas semanas e nos vemos no próximo episódio.

Assine o futuro da transformação da segurança

Ao enviar este formulário, você concorda com nossos Termos de Uso e reconhece a nossa Declaração de Privacidade.