Herbert Smith Freehills Kramer Podcasts
Herbert Smith Freehills Kramer Podcasts
Cross Examining Cyber EP25: Cross Examining Anne Templeman-Jones
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
After our brief hiatus, we are back with our Cross-Examining Cyber Director Series. In this series, we sit down with some of Australia's leading directors to discuss the challenges and opportunities facing boards in an increasingly complex cyber landscape.
In this episode, we cross-examine Anne Templeman-Jones, one of Australia's most accomplished business leaders and non-executive directors. Anne has served on the boards of Commonwealth Bank, GUD Holdings Limited, Worley Limited, and Blackmores (as Chair). She has also held board and leadership roles with Cuscal Limited, HT&E Limited, Pioneer Credit Limited, TAL Superannuation Fund… the list goes on. Anne is also passionate about technology and cyber security – what a combination!
In this conversation, Anne shares insights from her boardroom experience, including how directors can navigate emerging technology risks, approach cyber resilience, and balance governance with growth and innovation. Drawing on a career that has spanned multiple industries, Anne reflects on what makes an effective director and the lessons that boards can apply in an increasingly uncertain digital environment.
Thanks again for listening. This is Cross-Examining Anne Templeman-Jones. Here we go…
Welcome
Welcome And Series Return
SPEAKER_00to Cross Examining Cyber, a podcast brought to you by Herbert Smith Free Hills Kramer. In this podcast series, we speak to our business leaders about all things cyber, including the legal, governance, technical, regulatory, and policy developments that impact corporates around the world. We look at the evolving risk landscape by speaking to those people who are on the front line. After a brief hiatus, we are back with our cross-examining cyber directors series. Today we cross-examine Anne Templeman-Jones. Anne is one of the country's most accomplished non-executive directors, holding NED roles at CBA, GUD Holdings, Wally. She was the chair of Blackmores, worked with Cuskell Limited, HTNE, Pioneer Credit, Tel Superannuation, the list goes on. Anne is also passionate about technology and cybersecurity. What a combination. This is Cross Examining Ann Templeman Jones as part of our director series. Here we go.
SPEAKER_01Anne, welcome to Cross-Examining Cyber. Thank you. We like to start these discussions helping our audience understand a little bit about your background. Obviously, your career is quite a remarkable one. Do you mind taking us through your journey, how we got to the point where you started to take up these roles as NEDs, and then a little bit about your NED journey?
Anne’s Path To Leadership
SPEAKER_06Okay, it's very happy to. So I was actually born in Country Western Australia. So this is some of the stuff that you won't see in my resume. Grew up on a farm, wheat sheep and cattle, went to the local primary school, went away to boarding school in Perth, and then went to UWA. I did I did commerce. I was always, I think part of it was from a country, you sort of got involved in everything, everybody played sport, and you were part of a community, so that continued on sort of during life. I couldn't wait to travel. I just wanted to see the world. So commerce for me was just a stepping stone. And when I was at UWA, I discovered an organisation called ISEC International, which is ISEC is a French acronym for economics and commerce students. It was started in in Belgium after the Second World War, and it involved university economics and commerce students raising what are internships but with external companies. And for example, Telstra was one of the biggest providers. PWC, what was Price Waterhouse then, was still a global sponsor. And we would approach companies to where they had short-term six-month or often in Australia it was 12 to 18 month roles or specific projects. Mining companies were great for it as well, where they could bring in, they would create an internship for an incoming student, and that allowed us in this exchange programme that happened twice a year by paper. You filled in an application form, that allowed us as our members to be able to go on an internship overseas. Most Australians would go once they'd finished their degree because travelling out of Australia was just such a long way. A lot of the internships in Europe were quite short term, three or six months. But the ones in the US, Canada, so I saw that as my that was my ticket out of there. I was very involved. We in WA we used to raise between 17 and 20 internships over in Sydney in the late 80s, particularly active over here in New South Wales and also in Victoria. Many of my professional and close friends were all in ISEC. We all travelled and did inter internships. It gave me a thirst to be able to stay, sort of travel. So I went to Winnipeg for three months. And then I had applied for the general manager of finance at ISEC International in Brussels before I left. And a lot of it was the administration around the exchange programmes. And that was at a time pre-Burlin War falling. So we had member organisations in those countries where we would have to facilitate trying to get money to them because they found it difficult to raise money themselves. But it didn't exclude them from sending some of their members on trainerships into Europe in particular. And when I had left uni, I didn't want to do audit. I thought that was probably the most boring of the subjects that I had done, I do admit to that. But I was prepared to forgo my stubbornness to stay in Europe for another two years, and so I applied for the internship that Price Waterhouse offered at the time in Zurich. So I went into the audit profession and did that for a couple of years, eventually came back to Australia and went into banking. The audit at that time was not industry-specific. You weren't a sector-led expert. So you got to audit all sorts of companies in different sectors. And so when I eventually decided, once I qualified after I was back in Australia, I wanted to stay in a type of role that I would still see that cross-industry experience and be responsible for it. So I joined part of OCBC Bank, which in Australia operated as the Bank of Singapore. But I was in Perth and we only did syndicated facilities for mining companies and for properties. So that's how I got into the banking sector. And then the CEO of Westpac at the time, who was WA based for WA and Challenge Bank, convinced me that I needed trading bank experience. So I thought, well, I'll go into banking, but I'll go into corporate institution because then I can still have that cross cross-industry sector experience, which I loved. And I think it's driven by natural curiosity, love a challenge, and a lot of different industry sectors offer that.
SPEAKER_01And that obviously ignited your passion in banking.
SPEAKER_06Yes.
SPEAKER_01And probably arguably tech, really, because banking was becoming more and more technology focused.
SPEAKER_06It was. And even before that, one of the things that I did while I was in I was in a relationship manager role, we were having to pitch for deals, new clients, apart from the ones that we were managing. So I went and did the AI C D, the company director's course. Not because I wanted to be a director, but I I figured if I could figure out what they were doing, how they make the decision, what's important to them, I could kind of get in the head, so to speak, it would make me more effective in what I was doing. And at the time, Henry Bosch, who at one point he was the chair of ASIC, if I recall, he had said to me, You're very young to be doing this, because I would have been in my early 30s. And I told him why. And he said, Oh, well, one day if you decide this is a profession you want, this is a good starting point. But stay in your operating roles absolutely as long as you can. And I always remembered that as being good advice for me.
SPEAKER_01You clearly at some point in your career decided you're going to take on a sort of more broader governance role.
SPEAKER_06There was no aha moment, oh, I'm going to go from being an executive to board roles. When I was still in Western Australia, I was actually working for ANZ at the time, I was running their private bank over there. I'd had an approach from one of the search firms to say that the HBF Health Insurance were thinking about going into financial services because, as a health fund, as a mutual, they couldn't distribute any dividends to their members. And it wasn't like a listed company where you could pay dividends. And they wanted to give greater benefits to their members. And so they had a strategy around getting a financial services license and being a bank because they would be able to offer cheaper loans but better deposit rates. So they they put three new directors onto their board. I was one of them. And I think really within six months we'd convinced them all it was a really not very good idea because banks are complex to run, they're expensive, the regulatory capital burden, and you'd be taking on four really well-established banks at the time. And that was when technology was it wasn't like it is today, where you've got a lot of challenger banks. So I actually did that role for ten years, still while I was in my executive career, and it gave me a really good exposure to a whole of an organization in terms of.
SPEAKER_01So you were at ANZ at that time?
SPEAKER_06I was at ANZ, yeah. And that was in Western Australia, and I eventually I transferred, I took another role back in Westpac when I came over here. And I still had HBF while I was here, and then there came a point in my time where I figured um and I had always I had chosen a path where I decided I didn't want to go down the CEO route. I had two children, was married, I wanted to be an at-home parent. I didn't want to be working till 11 o'clock at night. You know, I wanted to be able to go to sport with them on Saturdays, you know, I wanted to be the mum, you know, the best mum I could. And for me that was having it all. I could have a career, but I could be a mother, still involved with my children, so that was the path I took. But at a point in time when I think, you know, I was I was past the CEO opportunity, but there were becoming more and more opportunities for women to take on board roles, and I'd had the experience with HBF and I actually really enjoyed it. So that for me was a pathway. So after I was offered two ASX listed board roles, which was APN News and Media, actually, and Cuskirl, which was in payments, they weren't listed, I decided that was the time.
SPEAKER_01You weren't responsible for the Quokka advertisement campaign at HBF Wii?
SPEAKER_06No, I'd left voluntarily after that.
SPEAKER_01I love that campaign. And
Traits Of A Strong Director
SPEAKER_01so when you stop and think about your director journey and what it takes to be a good director, w what are the attributes that you would provide, say the top three attributes for a good director?
SPEAKER_06Uh I think you have to be incredibly curious. I think you have to be calm and not afraid to ask questions. And I think not arrogant, because it's very much around you're going into another environment that a lot of other people are familiar with and you're not. That doesn't mean to say you have nothing to add. But it's about you, you finding a way to fit in and find the balance. But you also do need to come with a mindset and skill set that you have a responsibility. You have to like and accept governance at a certain level. And particularly now, I think then you add on all the other complexities, cyber security, now we have AI, it's here. Quantum computing's coming down the pathway very quickly, and and a lot of those new things, within two or three years, they'll be redundant in a way. They'll still be part of the system, but they'll be redundant. So it's that ability to be flexible. I think it's really important at a board level, whether you're in crisis mode or not, is to really be able to, yes, you need to be prepared and come focused on the discussion, but you have to really be able to sit back and actually widen your aperture a little bit and say, okay, what actually does this really mean? I'm reading what I have in front of me, but what else have I read in other papers? What am I hearing with other industries? What am I what am I hearing is happening in other companies? Could it apply to us?
SPEAKER_01Yes. As a director though, you've been in the business long enough to have seen incidents occur, and you don't have to talk about any of these in particular, but just the way in which you have seen these unfold. From
What Good Incident Response Looks Like
SPEAKER_01an incident response perspective, what what have you seen done well in these sort of incidents? I think what works Both from a board perspective and just more generally.
SPEAKER_06Generally speaking, if you have a plan where you've considered at least you know who who's the leadership to start off with. Who's going to be the one person who at the end of the day might have to make a decision? You do need to put your trust in them. And if you give them the right support around that, if it does come to that, from what I know from others I've spoken to, it's generally never just one person deciding. I do think you have to be, in terms of having that leadership, the team around you, then actually working who's the team that's outside the organization. So whether it be whether it be lawyer, advisor, investor relations, and sometimes it's not the people that are necessarily you would think of in their daytime job.
SPEAKER_03Yep.
SPEAKER_06You also need people that are incredibly calm and thoughtful, can think outside the box, and you need to be in that position where you can actually try and join the dots. You might not join all of them, but you can be in that conversation. And I think you have to have a plan about which of the regulators you have to contact straight away, even if you don't have all the information. And we've got some government organizations that are really important to notify as well. And often they have as much information, they just didn't know who was going to get attacked.
SPEAKER_02Yes.
SPEAKER_06So it's you have to leverage every relationship that you possibly have and test them before these things happen.
SPEAKER_01And in terms of things that went well at a board level, though, because we're all human, right? And boards are made up of a diverse range of individuals, some that come from operational backgrounds and love to get into the detail, arguably would like to be part of the crisis management team at times. And we certainly test that with boards. I don't want to say we play with their minds at all, but we tempt them to the edge a little bit to see whether or not they'll take that step beyond governance into crisis management. Have you learnt any lessons along your journey about the role of the board and the delineation between the board and management with a cyber crisis?
SPEAKER_06Yes. I do think dealing with a cyber crisis in one way, any crisis is a crisis. Any crisis is a failure of more than one control. It's easy to try and go to what's the problem first between actually what's the damage I've got to deal with right now and be forward thinking about it rather than backward thinking.
SPEAKER_02Yeah.
SPEAKER_06And being and that means there's a degree of preparation that's required. Any ransomware attack for me in my mind would be think of the worst. The worst could be someone dies or this company's going to be insolvent within two weeks because we can't pay our creditors, we have no access to our bank account. We can't pay people for six weeks. You've got employees who've got commitments. Thinking of what could be the existential crisis we've got to plan for. And if you sit down with your checklist and you go, well, okay, given the circumstances, these three things probably don't apply. But this is where we absolutely need to focus. Having a roadmap is a lot better than having no compass.
SPEAKER_01Yeah, it's amazing, isn't it? Because things move at pace, very little information. And if you don't have some sort of framework in that environment, it becomes very challenging because you're reacting to different noises as they arise and to keep it sort of steady. And we find that, I wonder if this is your experience, that whether it's a strong chair or a strong letter of a crisis management team, you spoke about that person being just they could just be a smart generalist, to be honest. Has to have at least some sort of structure in the way in which they run these things. And with that little bit of structure, brings time. Or at least it feels like it brings time because things become a little bit more orderly in that environment. Is that a is that consistent with your experience?
SPEAKER_06It does. The framework helps stay focused, but in any crisis, it's very easy for people to either panic or they rush at doing things or they rush at making a decision because they think that's helping it's doing something right now is better than doing nothing. You need the thinker in the room as well, someone who's actually really thinking, well, okay, what else, what what else might there be? What else do I need to think about? In terms of something like cybersecurity, yes, you need your technical people, but you need to be able to ask, have someone who's just going to calmly ask the right questions. Yes. Do we know what data has been taken? Do we know which customers does it impact? Is it, you know, where are our employees? How soon can we get back online if we can't? Did we have a digital twin? Do we have a digital twin? So some of those things you might already know, but you might have known them six months ago, but you haven't asked the question since then. So it's yeah, it's all about relevance, taking stock, you know, seeing seeing what you've got in the kit bag right now to deal with the emergency, what you had six months ago might not help you.
SPEAKER_01I
Cyber As Multiple Control Failure
SPEAKER_01loved your comment before about the crisis being a failure of multiple controls, essentially. And that kind of goes to this heart of this problem with cybersecurity where we've got a crisis that unfolds quite quite slowly, really. When I say slowly, it's quick. There are lots of quick things that happen, but it's like a car accident that lasts for three months. You know? It's it's it's not like a normal sort of health and safety crisis or anything like that. And and your point about uh having uh a failure across a number of control areas goes back to that the old adage that this is a whole of business uh sort of risk. It's as much a people and issue as it is a tech issue, as it is a sort of a governance, legal, etc. And how have you found that as SISO roles have developed that we're really looking for people now who are in the center of this or at least helping us manage these crises and informing the board who are adequately and well-rounded enough to understand that we're not just dealing with technical issues, we're dealing with potentially multiple failures. And I'll give you an example. Many incidents that we're dealing with at the moment are as a result of initial social engineering, which is very much a people issue. Then it becomes a technical issue, then it becomes a people and culture issue, for example. So it's a fascinating point that you make about that multiple control failure. Is that what you meant when you said that?
SPEAKER_06Yes, it is, because that your control environment is actually a construct. It's a bit like building a house or building a big-story building. The engineers design the format, the what the plan together, and then there's the specs are put together in terms of what materials you need. In the process of building whether you're building a building or whether you're doing some sort of transformation program with technology, at various stages along the way, for various reasons, either budget cuts, something's not available, you don't have the expertise, you think at that point in time we don't need that particular application, so we'll descope it.
SPEAKER_05Yes.
SPEAKER_06The decisions made in the time without necessarily thinking, ah, but could that be important if this other thing happened? So you can't plan for everything. This is where the documentation comes in about what you do what you do and don't keep.
SPEAKER_05Yes.
SPEAKER_06But in in terms of how things operate, what you do in the time is actually then becomes the building stone for what might happen, which windows were left open, which door hinge wasn't stuck on properly. Was there supposed to be a fire door on the ground floor, for example? And if there wasn't, would that mean that someone could or couldn't escape the building house because of a fire? We think about a technology environment with lots of different platforms and switches and same thing could happen. And to the point where you've said that it you they it could turn out to be someone who was an employee who deliberately made some choices in that technology process with the view that at some point in time, you know, the typical sleeper. Yeah, yes, that does it does happen. And so it's only and it's often only on reflection through the passage of time you realise, oh, that thing was missing, or that piece of technology was de-scoped because it wasn't important. But in the bigger scheme of things, in terms of the way that the platform was put together, the mindset that the particular vendor had, it was important. So those type of things where the weakness is in the system, I do think it's important, absolutely understand that you have at least the discipline of a NIST framework.
SPEAKER_05Yes.
SPEAKER_06And for any companies that are either involved or at the periphery of what's designated critical infrastructure, whether it be here or whether it be connectivity to some of your customers who might happen to be in the US.
SPEAKER_03Yeah.
SPEAKER_06Thinking about from that perspective, Essential 8 is basically the Essential8 that were put together by, you know, it's essentially in Australia, but it's not just applicable to Australia. That's the minimum you need.
SPEAKER_01But it's it's about those are more technical controls, too.
SPEAKER_06They're technical controls. Once you have them in place, though, it's a desktop review will only tell you that you've you've put them on a piece of paper. Are they really effective? And monitoring the the effectiveness of what you're measuring over time, those things all become indicators. They're incredibly important. They do give you a degree of comfort, but it doesn't mean to say it's 100%. And as you change, particularly now that organisations are connecting with more than one vendor, we've got different cloud providers, some people have hybrid arrangements, it just makes it far more complex. And I do find that the regulated financial services sector, particularly banking in Australia, has done a great job, for example, putting together the Prudential Standard 230, which really combines third-party cyber outsourcing in supply chain. So you're really thinking about the business as a you are connected to a massive amount of supply chains, thinking about it from that way. So it's all about resilience and recovery.
SPEAKER_01Yeah, operational resilience. Yeah. You mentioned before about someone sort of challenging about the what could go wrong.
Fighting Optimism Bias In Boards
SPEAKER_01Yeah. And it it's such an important role to play, the individual that for whatever reason plays a bit of a role in the room that says, hang on a second, this is my I'm gonna take on this role to sort of press what could go wrong. Do you find in a board environment that that just happens naturally? Because we worry about optimism bias when we deal with these sort of incidents. What's the best way, do you think, to make sure that we don't lose control and fall into this optimism bias?
SPEAKER_06I think there's two ways you could do it. You can and I've seen it happen in both ways, where there's been deliberately each board meeting someone's been designated to be the black hat person. And sometimes it's during the meeting, sometimes it's at the end, do a summary of what we could have done better or Or where we missed opportunity to challenge management. I think really that ends up being the dynamic that's created between the chair, the directors, and also management. In a perfect world, that all sounds great.
SPEAKER_05Yes.
SPEAKER_06The reality is though, when you're in a when you're in a board environment with executives, there's a lot of people who have different expectations. There are people that have a certain amount of stakeholder claim, if you can put it that way, or responsibility. And you know, I've I have heard of boards, and we see it sometimes that it comes in, flows over into the public domain where there's been differences of opinion that evolve through a company. It's not just a board thing, but it happens with executive teams. It's about making sure that the dynamic at the time is absolutely managed. I do think it is good to have a challenging person.
SPEAKER_05Yes.
SPEAKER_06The idea of spreading it around, giving it each person a different responsibility for each different meeting is so that one person just doesn't become the nager all the time. I do think though it would take a bit of practice in terms of to get that right. But you do getting to a point where as a director you help others feel comfortable when they might say something that's or challenge something that might seem not mainstream. I take on the responsibility myself to actually say, well, it might seem like a dumb idea, or was it a good idea? Maybe I don't know. Yes. But it's and the way to approach that is just ask a few more questions.
SPEAKER_01And as part of that sort of role as a board member, whether it's fighting that optimism bias or not, we do have a role that the board plays, which is unique from the role that the crisis management team might play, and which is unique from the role that the executive team and there are often three different components. There might be cross-membership and the like amongst the exec and the crisis management team. How do you define the role of the board when we go through these sort of incidents? How do you see a good board playing its best role in these sort of circumstances?
SPEAKER_06I think uh the best boards feel comfortable to challenge.
SPEAKER_05Yes.
SPEAKER_06They they will consider the counterfactual, you know, asking a question. So this all seems great, but what if it isn't? Like what what else is there what here would be one of the largest things we could miss, even though we accept that it's 90% perfect. But what what would cause it to fail? So it's almost like you're asking management to challenge you to say, well, because often they've already sort of these things anyway when they've done the pros and the cons. Sometimes they have it both. If it looks too good to be true, sometimes it usually is. Yeah. So it's it's but it's trying to understand why it might not be the right way, but leave yourself some optionality that if these other things happen, how could we diversify? How could we retract from that particular decision? Maybe not, what would be the consequences?
SPEAKER_01It's interesting, isn't
Ransom Decisions And Stakeholder Duty
SPEAKER_01it? I find that in many circumstances, the decisions that bubble together, bubble to the board level are actually not many. And it's often a the efficacy of the proactive supervision. You touched on the counterfactual, and in one word, you described probably one of the most important manifestations of director duties, which is, and this goes to things like pay or don't pay. But it's it's not it's not pay or nothing, it's pa pay or don't pay. So you've got to ask the counterfactual, um, you know, what would happen if we paid and what happened if we don't. Four or five years ago, and we would come up against boards that would say we will not negotiate, we will never pay. We will and we will not even engage. That we do not see that anymore. It is just simply not part of the way the board functions because ultimately you're acting in the best interest, you're looking to act in the best interest of the company. Surely you have to lean into the decision of what happens if you pay and what happens if you don't pay, irrespective of your moral compass or whether you'd like to be in that position or not. Is that is that fair?
SPEAKER_06It is. I think it's some might call it moral compass. I have a I have a bit more of a broad perspective in what's the right thing to do. So if you start with what's the right thing to do, you go on a path of saying, well, yes, the moral thing might seem the right thing to do, which means don't pay because it's illegal. But the other situation that I have been in, which was where it was actually imagine it's kidnap and ransom of a person or family as opposed to a system or some data, and then then you're down that path, it's still illegal. But is there a ch is there a chance that yes, we might get the person back? A chance is better than no chance. And yes, paying a ransomware, similar to cyber security, is is it a leverage for other companies to see that's happening and we have opened the door to other people, you know, we might be safe for a period of time if we've got the deep pockets to pay. Yeah, it becomes very much around, I think, it's more than moral, it's about what's the right thing to do. So that then you're thinking about you're thinking about the company, what's the chances of survival? We've got regulators, employees, we've got customers, we've got community around us. There's a whole lot of stakeholders that actually are part of the consideration, in addition to whether or not should you pay or not actually should be the last question you asked.
SPEAKER_01Yes, of course, yeah.
SPEAKER_06Consider all the other things. Yeah.
SPEAKER_01I mean, yeah, that's a good way to put it. And this is where practical legal advice comes in too, because you lean into a decision which at least on its face might be a technical criminal offence. Yes. But it's also an offence which has significant defenses, and enforcement risk which is negligible, incredibly low and negligible. And you're dealing with the health and safety of individuals, or it might be an existential threat to a company, where does that leave a director?
SPEAKER_06I think the qu the the director needs to be able to be in a position where, and this is where the good it's not just about good legal advice, but you actually want a legal advisor who can tell you what you must do or you mustn't do, but also then what you should do.
SPEAKER_02Yes.
SPEAKER_06It's the can can we do it versus should we? Can we is more of a legal, strictly legal interpretation. You can or you can't, it's binary. Should you puts you into that position where you you should be thinking about all the other things that you've got to take into consideration. At the end of the day, whatever your decision you make, you will come to having done a certain amount of reasoning, but actually making no decision is a decision in itself, which can be worse than making one of the two choices that you had.
SPEAKER_01Yeah. Yeah, it's interesting actually, because we there wouldn't be a scenario that I've been involved with where a board hasn't come to me and said, let's talk me through the risk profile, we have a discussion, and then they turn to me and say, Cam, what would you do? It takes courage, actually, to be in that environment to say, on balance, this is what I think. But that's the expectation. That's what it is to be a strategic advisor in this sort of space.
SPEAKER_02Yeah.
SPEAKER_01It's an uncomfortable position for some lawyers, but it's the expectation.
SPEAKER_06And it's it's expectation, but it's also for directors to be thinking about the last thing they should be thinking about is are they going to get sued? Yeah. That wouldn't it wouldn't even come into my mind at the time, although there are some that if you were to follow the strict letter of the law by fiduciary duties obligations, if you put your ruler straight through a whole lot of facts and said, well, on the left hand side it says this and on the right hand side it says no, and by virtue of the law says no, we shouldn't do it. That's where you get the distinction between having a mindset that's open-minded. There is never going to be a perfect solution to anything.
SPEAKER_03No.
SPEAKER_06So it's about trying to find what's the best for the situation you've got. You know, there are there are companies that have faced this twice in in a relatively short period of time when it's happened to them a second time.
SPEAKER_04Yeah.
SPEAKER_06So, you know, and and by virtue of that, in that particular case, one I'm thinking of, it did have really serious consequences in terms of what then ended up being the economic viability of the company.
SPEAKER_03Yeah.
SPEAKER_06So, but at the time when the decision was first made, they probably thought they were making the right decision.
Making Cyber Reports Board Ready
SPEAKER_01Hey, just in terms of uh as a board member, when you receive reports from the CISO, from other sort of members of the management team reporting in relation to cyber, we often hear concerns raised at a board level that there might be a sort of a language problem or a translation problem where some of the reports are coming through and they're they're full of jargon, there's you know acronyms. Even the nature of those individuals that are drawn to those roles may have challenges in relation to communication at a board level. Is that consistent with your experience? And then how how do we break down those? I'm gonna assume you're gonna say yes to this. Um but if you're assuming your answer is yes, how do we kind of break down those translation issues? And it probably happens the other way around where those individuals may not fully understand the messaging that's coming through the other way around.
SPEAKER_06It it definitely happens, and you get there, I'd sort of put them into.
SPEAKER_01But yes.
SPEAKER_06Yeah, so it depends on you do get some tech individuals for who are experts in the field, they're very good at what they're doing, their technical ability in terms of how they explain things, not everybody has that ability to translate it into the same type of language that perhaps we're used to hearing around the boardroom. And it doesn't matter how many lists of acronyms that you've got, that doesn't necessarily mean anything if you actually don't know what the thing does. And so it's being able to tell the story, get them to tell the story, and some people can't do that. By the same token, I do think often it's we as directors ask questions because, and this is where you get the the value of when you chair of or you're on an audit and risk committee, is you do get to see a lot more detail and ask a lot more questions. That said, though, it still is an uncomfortable place to be asked in sometimes an audit and risk committee, some of the the reasons why is that important, or what does it mean, or explain to me when they're used to dealing with tech people who know the jargon all the time. I think it does work both ways, how to break that down. I do think it depends on the individual. I do think it is a common, there's a bit of a common observation now by particularly around cyber, is where, and this again comes back to, you know, is is an environment punitive or not, where people are not prepared to say, I have found something, this is wrong, our budget's been cut, we we've only put in two-thirds of the system that we had because we ran out of dollars and we had to de-scope different things. It's being able to have the open, honest, and frank discussions without feeling that that they're going to be reined down upon because they haven't delivered something either on time or on budget. And the biggest risk is getting to if you're in a place where the technical teams are making the decisions, even though the executive team or the board have agreed on a certain strategy. And it's understanding what falls through the cracks in the middle is often where this tension comes because the board's asking the questions because they thought it was going to look like a zebra, and it's looking looking like a giraffe.
SPEAKER_01Yeah, is it it it's interesting, isn't it? Because uh I suspect as a as a board you might get this traffic light sort of style, you know, this is how we're going in relation to project X and Y, and this is it, we're on target. But where's the bit that says this is what we haven't done, or this was the decision that was made to do less of this and more of that? Like, how does that bubble up to the board?
SPEAKER_06I think it's important to ask the question that the board needs to ask, or someone from the board needs to ask, is tell me what you descoped. Yes. And was it why was that important to descope it? And what does it mean? Yes. Like what could it mean in six or nine months' time? I'd think that question often is not answered because often, especially when you get to the end of a project or not even a big transformation, it might be a specific piece of work delivering on a it could be something to do with your retail customers, is that everyone talks about what we've delivered. But the the decisions that are made along the way in those discussions that are had with the decision makers, often doesn't bubble to the surface. It's only when something's gone wrong, and when you do the post-mortem review type, you find out, oh, is that what happened? Or that part of the capability was taken out. It's a bit like, you know, if you if you talk to mechanics, they have a process where they they will say, we can't fix a car. It might be in one isolated place. I think technology is really no different from a lot of other machinery that's in the rest of the world. You you need to document and know what choices you made, not thinking about what you did or didn't do, what choices you made, because that has actually set you on the direction of the outcome where you've suddenly found yourself.
SPEAKER_01Yeah. And maybe the role would it be fair to say that one of the things that a board might bring to an organization when it's setting risk profile and governance is that it helps set culture as well. No blame culture, speak up if you need to speak up, that type of stuff. And that's not just before, but during an incident as well. Correct. We find that there is a tendency, a human tendency to find fault. And like how did this happen and who was responsible, that sort of stuff. And it's the most unconstructive way to manage yourself through. Now, those conversations may happen in due course. But you know, there may be that sort of thing in due course.
SPEAKER_06But I think you're thinking look at it in two ways. So if you're sitting there as a board member, having heard some feedback or you've read a particular paper, I always think of things, if it's a particular issue I'm I've got a question about, I try and think about what else did I read in this set of papers or of what I've been learning from management before, that is this related or not related, for example. So it's that widening the lens and thinking, sort of bringing yourself up out of the issue at hand and saying, well, what's really important here? What really matters? The other part of it is sometimes you go, you know, my experience is, you know, I know that I've been criticized sometimes, or not criticized, but I've been challenged because people feel I asked too much detail. But part of that doesn't come from trying to find fault with you, I'm actually just trying to understand what's happening. So I think it's it would be helpful for boards to do more of that in terms, and part of it comes to the education. And actually, not all education happens outside the boardroom, going off and doing courses. The education about how the business operates and what makes it tick, what's its what I call its ecosystem look like, instead of thinking of businesses as a supply chain. Supply chain by nature, because it's often depicted in an end-to-end, that's the end-to-end process. But if you actually think about along the way, there's many processes that sit around it. It's far more dynamic than that.
SPEAKER_01Like a spiderweb. Correct. Yeah, yeah. You'll probably find that the questions you're asking, there's probably a number of directors around the table going, that's a pretty good question. I don't know the answer to that either.
SPEAKER_06So it's it should be a you want to try and be in a room where there's a non-threatening environment where you can feel comfortable. But that's that would really be the optimum environment that you want that you want to work in.
SPEAKER_01I'm gonna go out on a limb here. Sure. Throw myself in harm's way.
What Great Cyber Lawyers Do
SPEAKER_01I think I've got a fair idea about what this looks like, but what do you think a good lawyer looks like in the cyberspace? And we're dealing with both before, during, and after, but let's just say during an incident where we find that lawyers are playing a disproportional role, perhaps more than they used to, probably because of the long tail and the risks and the sticky decisions that have legal consequences early in the piece. But I've seen good lawyering and I've seen poor lawyering. I'd be interested to know what your view of what a good lawyer looks like.
SPEAKER_06So what a good lawyer feels like for me is someone who will actually tell me what it is. And and yes, is if there's been failings on the part of company or, you know, whether it be people or without trying to lay the blame at this point in time. But actually it's really frank with you that tells you what this means or what it could mean. Because there are some things you actually can't fix, they're already done.
SPEAKER_02Yeah.
SPEAKER_06It's no different from a particular something that might have not might be nothing to do with cyber, but even the same principle applies where what's been said has been said. You can't unsay it. And it could be one of your employees, it could be one of the directors that said something publicly. You want someone who can help you in that situation to say, this is what it is.
SPEAKER_02Yep.
SPEAKER_06And because it gives you the right sort of guidance around what are the things that you shouldn't say, not only because it could further damage the situation, but it's actually help firstly help to understand what are the options. And even if someone wants to say, Well, what would you do? It still becomes a personal question and it's a matter of judgment. You want a lawyer who's prepared to show some judgment, but give you some optionality. Yep.
SPEAKER_01Yeah, I think that's fair. Look, I I I come out of these. I mean, I I think we pride ourselves at HSF Kramer on providing a legal framework or at least legal support, which is which is pragmatic, which understands that these things move at pace, we are gonna have wrinkles, we are gonna trip and stumble from time to time as we work through an incredibly ridiculous crisis unfolding with uncertain facts. They will always change. But the ability for us to come in and say we're gonna provide advice, but not in a way which is gonna prevent the smooth or the effective response to this. And that's that's a big challenge, and we see lawyers from time to time who just come in and with binary answers around no or yes around stuff like this, maybe often no. And it's the most unhelpful contribution you can make.
SPEAKER_06Again, it comes back to can you do it? Which is probably more the legal, and then there's the should you, and the should you actually, the bit that comes before that, okay, these are the things you could do. If one of these can, you could do this. Now, whether or not you choose to or should choose either one of those, or if there's some optionality, sometimes there's limited optionality.
SPEAKER_02Yes.
SPEAKER_06At the end of the day, the directors have to make that that call in terms of what they feel comfortable with. But it's it's then why. Yeah. Even if you get to the should, still ask that last thing, well, why should we do it?
SPEAKER_02Yeah.
SPEAKER_06Because that then should bring you hopefully to the close closer to the answer that probably is the right one for the time. Six months' time you look back and you might say, That was the worst thing we ever did. Hopefully not. But you know, people are faced in that situation every day.
SPEAKER_01Yeah. And one of the one of the other things that I think a a good lawyer can bring to a crisis of this nature is a sort of a calmness. There are many people, and I've seen people break, I've seen tears, some some people don't enjoy or manage these scenarios. But I think because we've done so many of them, we've gone through that process. There's something to be said about the ability to help a board or help an executive team know what's going to happen even if it's not good.
SPEAKER_02Yeah.
SPEAKER_01You know, and get and forewarn. And that sort of strategic advice is not necessarily legal advice. That's just based on the fact that we've done a couple of hundred extortion demands in the last 18 months or two years, you know.
SPEAKER_06So it's very similar to practising fire drills, evacuation processes, even though the the cyber side of it is can be far more complex. The more you practice, the more you get used to being comfortable with being out of control.
SPEAKER_01Yeah. A plan is nothing without planning. That's right.
Closing Thanks And Next Guests
SPEAKER_01Hey Ann, thank you very much. Can I just say congratulations on a remarkable career? I hope we see a lot more of you in the director's space. I'm sure we will. Thank you. But also thank you for your continual interest in sort of engaging with us as a firm and the conversations that we have in this space. Like I said, there's not many directors out there that have that sort of passion both for governance and what's happening in the space and awareness of quantum and what that's going to have, three, four, five years before it's arri going to arrive. So we need more lucky in this sort of space. But I'm very grateful. I know you're incredibly busy, but can I say thank you? Thank you very much.
SPEAKER_06Thank you for having me.
SPEAKER_01All right.
SPEAKER_06Thanks. Cheers.
SPEAKER_00Thanks again for tuning into cross-examining cyber. Our director series continues next time with the cross-examination of John Mullen and Catherine Brenner, two incredible leaders for the price of one. Thank you again for your time today, Anne, and thank you all for listening.