Conference Presentation, Panel, Fireside Chat
Hacked and Back: Cybersecurity Lessons From the C-suite
Milken InstituteDmitri Alperovitch, Sanford (Sandy) Climan, Christopher Krebs, Thomas Pritzker, Tom Pritzker, Sandy Kleiman, David Batts, Jr., Jeffrey Brown, David Brooks, Eric Schmidt, Alan Seales, Tom Ginsburg, Chris Collins, John McWhorter
Threat Landscape and Evolution
- Cyber threats are categorized into three primary actor types: financial-motivated criminal groups, hacktivists driven by vendettas, and nation-state actors.
- The top four nation-state adversaries of concern in the West are China, Russia, Iran, and North Korea.
- Cyber conflict has evolved through three distinct phases:
- Phase 1 (1980s–1990s): Primarily state-sponsored espionage between the US and Soviet Union targeting government networks.
- Phase 2 (Mid-1990s to ~2010s): Proliferation of actors including criminal groups monetizing cybercrime and nations targeting private sector intellectual property (e.g., China's theft of trade secrets).
- Phase 3 (Last 7–8 years): Shift from information theft to disruptive and destructive attacks, exemplified by the 2014 Sony Pictures hack and the 2017 NotPetya attack.
- The NotPetya attack, attributed to the Russian government, initially targeted Ukraine before spreading globally; it damaged Hyatt's Kiev hotel infrastructure, though the corporate network was contained.
Hyatt's Strategic Governance and Response
- Hyatt integrated cybersecurity into its core corporate purpose of "caring for people," making the protection of guest and colleague data a strategic priority.
- Cybersecurity is classified as one of Hyatt's top six enterprise risks, reviewed quarterly by the risk, disclosure, and audit committees, with an annual deep-dive at the board level.
- The organization allocates approximately 6% of its IT budget specifically to cybersecurity initiatives.
- Hyatt established a layered governance structure involving a CISO, general counsel, and C-suite leadership to ensure rapid decision-making.
- During the NotPetya incident, Hyatt's CISO exercised autonomy to share threat intelligence with the FBI, DHS, and industry peers within 10–20 minutes of detection, without waiting for CEO approval.
- This transparency decision was enabled by a culture where the C-suite empowers the CISO to act decisively against shared threats.
Government Perspective: DHS and Collective Security
- The Department of Homeland Security (DHS) promotes a "collective security mindset" to shift from reactive containment to proactive, shared risk management.
- DHS faces a "information gap" where imperfect data leads to imperfect national security decisions; they aim to aggregate private sector threat data to build a holistic national risk picture.
- Collaboration with the government offers legal risk transfer; companies that can demonstrate due diligence and active partnership with DHS may face reduced liability from regulators like the FTC.
- DHS lacks broad regulatory authority over the private sector (outside the chemical industry) and must rely on value proposition and relationship-building to encourage participation.
- The "National Protection and Programs Directorate" is undergoing rebranding efforts (to Cybersecurity and Infrastructure Security Agency) to improve stakeholder trust and communication.
- Current legislative hurdles, such as the Cybersecurity Information Sharing Act of 2015, force agencies to implement tools quickly without beta testing, sometimes reducing effectiveness.
- DHS utilizes "Binding Operational Directives" to compel civilian agencies to patch critical vulnerabilities, reducing average patch times from over 45 days to under 30 days (sometimes 8–9 days).
Entertainment Industry Challenges and Evolution
- The entertainment industry historically lacked cybersecurity discipline, often cutting security budgets to meet short-term financial targets.
- The 2014 Sony Pictures attack by North Korea served as a wake-up call, resulting in the destruction of data, the leak of employee personal information, and severe workforce trauma.
- Unique industry risks include a distributed workforce, reliance on personal devices, and a culture resistant to "conditional access" protocols that might disrupt creative workflows.
- Entertainment is now a high-value target for nation-states due to its influence on public opinion, access to VIP guest data, and its role as a proxy for national government interests.
- The industry is transitioning from a product-focused model to a data-aggregation model (competitors with Amazon, Apple, Netflix), significantly increasing its exposure to cyber threats.
- Future threats involve the "Internet of Things" and "ambient computing," requiring new security disciplines for a constantly expanding digital ecosystem.
Metrics and Performance Indicators
- Hyatt reports 163 technical metrics to IT, which are rolled up into a simple "pie chart" for the board showing the distribution of high, medium, and low-risk areas.
- Board-level reporting focuses on major strategic initiatives and the ratio of risk reduction progress rather than granular technical data.
- DHS measures success through network health metrics, specifically focusing on "dwell time" (time to detect, investigate, and remediate).
- CrowdStrike tracks "breakout time," the average duration (1 hour 58 minutes) for an attacker to move from an initial compromise to a wider network invasion.
- Best practice benchmarks suggest organizations should aim to detect breaches in under one minute, investigate in 10 minutes, and eject attackers within one hour.
Recommendations for Executives
- Tone at the Top: C-suite leaders must prioritize cybersecurity as a strategic business imperative, not just an IT function.
- Empowerment: Organizations should empower the CISO and security teams with the authority to make rapid decisions without excessive hierarchical bottlenecks.
- Budget Allocation: While not requiring massive capital, cybersecurity funding (e.g., 6% of IT budget) must be consistent and sufficient to support layered defense.
- Collaboration: Companies must proactively collaborate with government agencies to share threat indicators and align on national security goals.
- Industry Cross-Pollination: Entities in the entertainment sector are advised to adopt best practices and security disciplines from more mature industries like hospitality and finance.
- Workforce Education: Companies must re-educate their workforce to view cybersecurity as a continuous process rather than a solvable product issue.