This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Troy Fine. Troy is an industry-recognized thought leader (and meme creator) at the intersection of compliance, auditing, and cybersecurity. His expertise spans a range of frameworks, from SOC 2 and ISO 27001 to HIPAA, HITRUST, PCI, FedRAMP, CMMC, and privacy regulations. Through a holistic approach, Troy helps clients navigate the complexities of compliance and fosters a culture of continuous improvement within organizations.
Chapter Titles:
00:00 Introduction
00:15 Our Guest
01:27 Finding a job during an Economic Crisis
06:26 Auditing is not Sexy
09:50 Learning by experience and teaching others
13:44 Top 3 most common questions
17:02 Does this do anything to improve security?
32:30 Why should I be liable?
39:35 Overbearing controls
44:42 Jumping from SOC2 type 1 to type 2
50:01 Book recommendations from Troy
Audio:
Important Links:
Transcript
Manoj Tandon (00:00.598)
This is your host, Manoj Tandon. Welcome to another episode of Dark Rhino Security, Security Confidential. Today we are honored to be joined by Troy Fine… Troy is an industry recognized leader. He’s been in this business for a long time. He is a compliance expert. And you want to talk about SOC 2, ISO 27001, HIPAA, FedRAMP, CMMC. Troy…really understands these frameworks, his background and understands cybersecurity. He’s worked with continuous improvement in many different organizations, a brilliant guy. We’re honored to have him here today. Troy, thank you so much for joining us on this sunny day in Pittsburgh, Pennsylvania.
Troy Fine (00:48.054)
Yes, it is very sunny. It feels like spring. Thank you. Thank you for that introduction. Brilliant. I like the word brilliant. Let’s go with brilliant. Brilliant.
Manoj Tandon (00:57.106)
Yeah, hey, you know what? Look, I’m in the business and I don’t know all those frameworks. So it takes a degree of understanding to really get into it. And we’re gonna talk about it because I think this is a topic of huge interest where people really need to get their minds wrapped around these.
But before we go there, we always love starting with an origin story, because everybody wants to know where the beginnings are. So what is your origin story if you don’t mind sharing with us?
Troy Fine (01:32.206)
Sure, yeah. Where do I start? When will start? No, I’m just kidding. How far back do I go? But yeah, so graduated from Ohio State. I am a Buckeye. Had an unfortunate football. Yes, yeah, you guys are in Columbus. So that, yes, that’s where I know Dark Rhino from, but they had a, football was a little rough this year. But anyway.
Manoj Tandon (01:46.002)
Oh my, by the way, so good school choice.
Manoj Tandon (01:56.302)
Thanks for watching!
Troy Fine (01:58.434)
Graduated from there, I graduated in 2009, right? That probably wasn’t the best time to graduate college. That was during the economic crisis. So getting a job was not, it was a struggle, I remember, right? It took me about six months, actually, after I graduated to get a job. But when I finally landed a job, I actually just took what I could get, and I became a business intelligence consultant for a local consulting.
data Doing extract transform and load jobs like helping companies build. Yes
Manoj Tandon (02:34.162)
ETL transactions, man, that was like bread and butter for a long time. But yeah.
Troy Fine (02:38.854)
Yes, we were using big data, helping companies use their big data. Big data was like the big buzzword at the time, right? It was a local consulting company out of Columbus, Ohio. You know, I did accounting and IS in college. So they hired me. I knew IT. It was a lot of SQL. I wrote a lot of SQL code for that job, right? That was good though.
I did that for about a year and a half and uh…
Manoj Tandon (03:09.602)
So I take it you were primarily working with Oracle at that time?
Troy Fine (03:13.71)
So we were using a tool called Informatica, if you remember, and DataStage. I think one of the tools might have been an Oracle tool, DataStage. DataStage was an IBM tool, I think. But that’s what we were doing. Yeah, writing a lot of SQL. But I then transferred to Pittsburgh after about a year and a half at Columbus. I ended up moving to Pittsburgh, Pennsylvania.
Manoj Tandon (03:19.058)
Know it well. Yeah.
Troy Fine (03:44.302)
I didn’t want to do a long distance relationship anymore, so I came to Pittsburgh, Pennsylvania and I found this IT auditor job at a CPA firm. I didn’t really know much about IT auditing, but I read the job description and it involved testing IT controls on financial systems. So I figured my business background and my IT background would be a good fit. I did the interview and got the job.
Manoj Tandon (04:12.606)
Okay, I gotta pause you there for one second, because that is like a total orthogonal turn, if you will. Did you know somebody in the firm to get that first interview? Because we have a lot of listeners that are looking to transition into cyber, and some of them really struggle to get that break, that first view, and it sounds like you… How did you tee it up? How did you get it?
Troy Fine (04:19.647)
Yeah.
Troy Fine (04:28.78)
Yeah.
Troy Fine (04:39.682)
So, if I remember correctly, this was about 12, yeah, almost 13 years ago. So, I knew an employee that worked at the firm. Well, I didn’t know them. My wife now, girlfriend at the time, she knew somebody that she used to work with at another CPA firm that worked there. And we found this IT auto role and I just gave my resume to him and he submitted my resume.
for that role. And that’s how I guess I got the interview, because I guess I knew somebody there. But at the time, there also weren’t many people applying to that type of role. Like IT Auditor was a very kind of like, I don’t wanna say new, but it wasn’t like it is now, right? Like cybersecurity wasn’t even really a word yet, probably in the mainstream in 2010, 2011. And I don’t think there were many people applying.
Manoj Tandon (05:29.889)
Yeah.
Troy Fine (05:39.01)
So when they saw a good candidate come through, who understood IT, but also had like a auditing, I did accounting in college, right? So I had that auditing background, plus I already had an IT-like job for about a year and a half, so I had that. So I think they saw a good candidate come through, they gave me a chance, and when they interviewed, I was a personable person, I could.
Manoj Tandon (05:50.253)
Yep.
Troy Fine (06:03.998)
answer questions. I can answer basic questions about IT, basic questions about auditing. And it’s a really tough position to fill. Like throughout my career, finding like auditors is actually a very still tough role to find because it’s just not a sexy job. Right? If that makes sense. Like it’s not a job when you think about cybersecurity and GRC, well GRC yes auditor, but we think of cybersecurity not many people think like entry level.
Manoj Tandon (06:18.827)
Really?
Manoj Tandon (06:23.191)
Hahaha
Troy Fine (06:32.902)
auditor at a public accounting firm doing like auditing work. And nobody really thought that in 2011, right? Like nobody was thinking that. And I wasn’t thinking that either. I was just thinking, I’m young. I don’t, let’s just go. Like I can’t be picky, right? Let’s just get a job and see where it takes me. Um, that’s kind of like the theme of my career. I’ve always just kind of been like, let’s go and not really think about it. I, I.
Manoj Tandon (06:33.964)
You’re right.
Troy Fine (07:00.77)
When I think about something, I tend to talk myself out of it. So I try not to think. And when I was younger, I didn’t think. I didn’t have any responsibilities. I didn’t have kids. I didn’t have a family. So I took my chances when I could, and I wasn’t going to be picky. That was my attitude.
Manoj Tandon (07:04.777)
Yeah.
Troy Fine (07:18.562)
That’s why I do.
Manoj Tandon (07:18.794)
Hey, it’s a strategy and it worked. It paid off for you, obviously.
Troy Fine (07:26.217)
It paid off and you know what I think it’s
You know, it wasn’t as easy, like, this whole idea of remote working wasn’t a thing yet either, like, you couldn’t just go find a job anywhere and apply and have a thousand people applying for the same job. There wasn’t, you know, online, you could apply online to places, but it wasn’t like very prevalent, like LinkedIn, you weren’t just like searching jobs on LinkedIn and applying, like, people weren’t like posting jobs as much on LinkedIn then.
So I didn’t have any information anyways to go off of, right? Like I think nowadays you could get all this information thrown at you and you’re like, oh, but this’ll be bad, but this’ll be this, and you just talk yourself out of it because there’s so much information coming at you all the time and that’s hard to deal with. Like if I was trying to look for a job now, I think it’d be a lot harder, especially in cybersecurity because there’s just so much information out there. How do you know what information is accurate? How do you?
know what path you should go on because there’s, you talk to this person, they’ll tell you one thing, you talk to this person. I was always just trust my gut. But I also didn’t have all this information flow coming at me at the time. Which I think is liberating when you think about that, right? I think we get so much information thrown at us that we don’t know what to do with it. Well, I didn’t have that information, I just did it. I just acted.
Manoj Tandon (08:49.518)
Well, you know what, Troy, it sounds like, and you’re not giving yourself enough credit for it, but you had a stronger sense of intuition than you might realize. Cause that’s something that when you have too much information, that gets disabled. Cause you’re bringing too much, there’s an over abundance of data, which gets you nowhere. Whereas…
Troy Fine (09:13.111)
Right.
Manoj Tandon (09:15.094)
There’s an innate intelligence inside of all of us that if you call upon it, a lot of times it can guide you in the right direction in ways that you don’t necessarily.
Troy Fine (09:25.086)
Yes, can you spot the signal in the noise, so to speak? Yeah, that’s a good book actually by Nate Silver, I think his name is, I don’t know if you ever read it, but he’s a statistician. He’s just like a, he’s the guy who predicted like back in, like he still does all the like election predictions and he has like a website, does all the sports predictions. I can’t remember the name of the website, but he wrote a book called like some,
Manoj Tandon (09:28.206)
That’s right. That’s exactly what that is.
Manoj Tandon (09:36.774)
I have not, but now I’ll put it on my list.
Troy Fine (09:54.246)
signal and the noise like finding the like and understanding what information is signal what information is noise So it’s a good book. I read a long time ago, but yeah, I would recommend it But yeah, that’s how I got to entire tea auditing I guess I should continue with the origin story
Manoj Tandon (10:11.154)
Yeah, so that got you into this. And now, did you have to go through a lot of learnings for SOC 2, ISO 27000, all these different… How? Yeah.
Troy Fine (10:24.13)
So, yeah, good question. So when I was at the CPA firm, I really focused on Sarbanes-Oxley first. So I did Sarbanes-Oxley testing, which we were, basically we were helping companies, public companies that needed Sarbanes-Oxley. As a part of that, you need to do IT control testing around your financial applications. So your main accounting systems, you need to have good access control, good change management, like all the basic IT stuff. That’s what I was doing initially.
Manoj Tandon (10:33.87)
Okay.
Manoj Tandon (10:45.07)
Okay.
Troy Fine (10:54.262)
Fast forward a couple years, the AICPA came out with this new standard called SOC 1 and SOC 2. Formally, it was called SAS 70, but it didn’t really focus on security. It was really focused on financial systems and same thing, like IT controls around those. But then they came out with this SOC 2, which was like a security focused audit on any type of system that has any type of sensitive data. So I guess you could call it intuition again.
But I saw an opportunity and we were starting to get into doing those types of audits and I raised my hand and said Hey, can I start working on these right because I saw that like This is gonna be I guess it was intuition, right? I guess you could call it me Not thinking and taking chances or intuition, but yeah I had an intuition about it and I raised my hand and started doing those types of audits. I Didn’t I just I learned by experience
But I took an opportunity because nobody really knew what they were doing with those audits yet, right? So if you don’t have any baseline to go off of, then you can’t really mess up because you are creating the baseline, so to speak, right? So that’s a challenge in itself, right? Though if you had to be able to like think on your feet and then figure things out and wanna have that personality. But so started doing SOC 2 and we just started growing our SOC 2 audit practice. And I just started auditing.
Manoj Tandon (11:58.785)
Yeah.
Troy Fine (12:21.966)
clients that were SaaS companies, startups that were hosting their applications in AWS, Azure, GCP, and I was just learning on the job what AWS was. I didn’t know what S3 meant when I was auditing AWS. I didn’t know what any of that stuff meant, but I just learned it and figured it out. So that’s really how I learned how to do the actual auditing. Then I started to read like the mid-
Manoj Tandon (12:37.038)
Buckets were, yeah. Yeah.
Troy Fine (12:51.37)
like the standard, so to speak, the material about like the requirements on how you’re supposed to audit, so to speak. But the actual like testing and learning like cloud security and figuring that out a lot was just kind of learned like based on experience. And then I just, from there, I just kept getting more into security. At that time I had my CPA, I had my CISA, and then I ended up, I wanted to learn more about security.
in cyber security, so I thought getting my CISP would be a good idea. So I worked, you know, the firm supported and invested in paying for people to get those types of certifications. So I took advantage of that and then I’ve gained my CISP. And from there, I just started building a brand for myself. You know, I’d gathered all this information over the last 10 years. I was getting so many questions every time I was trying to talk to a prospect.
or a client about SOC 2 or different compliance standards, they were always asking the same question. And I kept answering the same question over and over. So I was just like, why don’t I just proactively put this information out to the world and see what happens and just start educating people like we talked about before we started the podcast. And that’s what I started doing. I started democratizing compliance in SOC 2 on LinkedIn and just started posting information, answering simple questions.
Manoj Tandon (14:05.003)
Yeah.
Manoj Tandon (14:14.542)
That’s.
Troy Fine (14:15.81)
that people were always asking me. And that’s where it started.
Manoj Tandon (14:18.838)
So what would give us like your top three that you get still even today probably get all the time
Troy Fine (14:25.062)
Oh, top three today. Well, the funny thing is people are so much more educated now. I mean, not just because of me, there’s just so much information out there. But what’s the top three? Well, I don’t know if I still get them today, but really just basic, like, what’s the difference between a type one and a type two? Like, people never understood that ever. Whenever you, like, you would ask, like, oh, are you thinking about getting a SOC two type one or a SOC two type two?
and they’d be like, I have no idea, what are those? And then that would just start explaining that and educating them. Another common question would have been what’s involved in a SOC 2, what areas are covered in a SOC 2? So a lot of people think that when you do a SOC 2, like it’s all technical controls, right? Or like access control, risk, you know.
Manoj Tandon (15:20.486)
It’s not, and it cost a fortune because we went through it. And it’s no fun, but I digress. Please keep going.
Troy Fine (15:25.644)
Hahaha
Troy Fine (15:29.87)
Yeah, well, we can talk about that after the podcast. But yeah, so people think it’s all technical controls. Especially a SaaS company, right? So let’s say you’re offering a SaaS solution. A lot of people just think it’s going to be like, oh, you just have to talk to our engineering team and figure out all the technical security controls within the application. But really, that’s like 40% to 50% of an audit is that. A lot of the audit is going to be like,
all your entity level and other departments like policies and procedures, risk assessment, vendor management, communications with your customers and clients, onboarding, offboarding, that’s the other 50%. I wouldn’t even, and that’s not really technical controls, that’s like administrative and controls that have nothing to do with your technology all the time.
Manoj Tandon (16:23.444)
Yeah, they have huge security implications depending on how you execute them.
Troy Fine (16:27.647)
they do have big security implications. And…
Manoj Tandon (16:30.383)
I would argue they have bigger security implications than some of the technical controls, but.
Troy Fine (16:35.09)
You are correct, exactly. But that was a common misconception. There was like, oh, wait, you’re gonna have to understand how we onboard new hires to our systems? Oh, that’s not even on me. That’s like our HR team. I gotta get them involved as part of this audit? Yeah. Oh, okay, this is gonna be a little bit more effort than I thought. So that was a common question. Like, what was the scope of the SOC 2, I guess. That’s really a common question.
You said top three was another one? Um, oh man. There’s so many. I don’t think there’s any dumb questions. But, uh, what’s the dumbest question? I don’t have to think about that one. We might have to come back to that.
Manoj Tandon (17:13.466)
You can substitute it. What’s the dumbest question? I know there’s no such thing.
Manoj Tandon (17:30.734)
Okay, so I’ll ask it, does this do anything to improve security?
Troy Fine (17:36.054)
I don’t think that’s a dumb question. I think that’s a very in-depth question actually. Cause I, that’s a very interesting question. Because at the end of the day, you know, I don’t know if it, I don’t know how to, how we can measure that impact, right? So like, how do you met like, it would mean I’ve been interested in this answer for a long time and I think somebody needs to like actually do like a real study on it. Like organizations that have
you know, Dunsok 2 or the NYSA 27001 certified or have FedRAMP or, you know, high trust certified, whatever the case may be, are they more likely or less likely to, um, to experience an incident and what is the impact of those incidents when they do that, right? So maybe the likelihood of an incident is the same, right? But if you have good controls in place, then
the impact of those incidents should be less, right? So if you have good controls and you have SOC 2 and ISO, you should be able to recover faster and mitigate the impact of an incident.
Manoj Tandon (18:39.398)
You would think! Yeah.
Manoj Tandon (18:46.198)
But this is, I can tell you, and this is pure anecdotal because we have not done a research study on this that’s scientific by any stretch of the imagination, right? So this is kind of like putting your thumb out in the wind which is what I’m about to say is, from what we have seen, whether you get breached or not has not materially impacted on whether you meet compliance standards, okay?
The question about do you recover faster? We haven’t seen that to be materially impacted either. It seems.
Manoj Tandon (19:28.078)
polite way to say it and that is it’s almost like it’s a checklist. People are going through the checklist process without diving into the in-depth. What it’s not sparking and you should, I would love to hear your side of it and say, no, Manoj, you’re wrong. It seems like what it’s not sparking is that conversation like when you’re asking about what is your onboarding process, right?
Okay, I have it documented. I have it listed out and I can show to you that I hired three people last year and this is how they went through it, okay. Well, I would wanna know what was the order in which you provisioned their systems? And…
Did you inadvertently enable an escalation of privileges as you provisioned those systems? When they left, how did you deprovision it? How did you make sure that the deprovisioning was complete and can you certify that, right? Because orphaned accounts, man, we find them all the time, Troy. We run into it all the time. And I’m just giving you an example. I could…
we could spend the next four hours talking about various gaps that arise. But I would hope that when you’re asking those questions, that’s what those conversations are coming to mind and saying, yeah, we’ll meet compliance. But by the way, this looks like it’s an exploitable vulnerability in our process, not in our technology. Big difference, right? It’s an exploitable vulnerability in our process.
Troy Fine (21:12.972)
Yeah.
Manoj Tandon (21:17.746)
should really address it. And I’ll let you counter, and I’d love to get a real auditor’s perspective on this. Ah.
Troy Fine (21:28.302)
Well, hopefully a good auditor would have caught those vulnerabilities as part of the audit. I think, I guess that brings up the point of like an audit is only as good as the auditors performing the audit, right? And that’s a whole other discussion, but the rigor of an audit can, is important, so to speak, right?
And so if an auditor is not necessarily going to that depth, then I think going back to your original question of does do audits, do they mitigate security risk, let’s just call it that, that is the question, then the answer is probably no in that instance, right? I mean, if you’re just checking a box to pass an audit and there’s no…
culture of constantly improving security and someone only does security when an auditor is coming in and they provide their evidence, give them their little, you know, hey, show me how you onboarded this employee, show me how you off-boarded this employee, here’s my checklist, we signed off on it. If that’s the audit, then yeah, we’re doing a disservice to the people relying on these reports for lack of a better way to look at it. And I think you’re right.
I think that the audits are not going far enough. But that brings up the question, most companies don’t want their auditor to find those things. Right?
Manoj Tandon (23:04.885)
Thank you. Okay, keep going. I won’t stop you because there’s a whole laundry list of questions on this one. But go ahead, please.
Troy Fine (23:12.062)
Yeah, well, I mean, yeah, like you’re, I think about this a lot too, right? So in order for me to do a rigorous audit, that’s going to take me more time, right? If it’s going to take me more time, it’s going to cost my client more money, right? So the client then says, wait, if I pay you more money, you’re going to do a more in-depth audit and there’s a better, there’s a higher risk that you’re going to find something we’re doing wrong.
because nobody’s perfect. But then I have these other auditors over here who are charging half your price. Well, that means they must not be doing as in-depth of an audit, but I’m still getting this piece of paper at the end of it that I can show to my customers.
Manoj Tandon (23:58.627)
or my regulator or whoever it is.
Troy Fine (24:00.266)
or whoever, right? And there’s a lot of that going on, I think, in the… I think there’s a lot of that thinking going on, whether it’s conscious or subconsciously from people that are looking for auditors. I think in the back of their mind, they…
Troy Fine (24:23.15)
People want a good auditor, but what they won’t tell you is they also don’t want an auditor that’s going to dig too deep and find things that another auditor wouldn’t find, right? So, if I use a smaller firm and I don’t pay them as much money, then they’re not going to spend as much time on my audit. So they have less chance of finding things.
Manoj Tandon (24:43.066)
It gets better than that, Troy. I, it, and we’ve experienced this firsthand, where there was a company, a former client of ours that was being pushed to get their SOC 2 type one and then get their SOC 2 type two by the industry in which they did business, right?
Troy Fine (24:45.073)
I don’t know.
Manoj Tandon (25:08.794)
And we were putting in a very, a defense in depth approach, which genuinely was geared towards a material reduction in risk. And that takes time. And it also takes a change in employee behavior because there’s things that you have to put in. You already know this procedurally and from a policy perspective that
really alter, it doesn’t complicate, it doesn’t interfere, but it does change the way people are used to doing things. And they’re like, well, no, we don’t want to do any of that. We, we want to meet the minimum to get this done to the point. They’re like, oh, well, yeah, we need
Manoj Tandon (26:05.078)
technology, I really don’t want to, because I don’t want to give away who it is or what happened here, but, and they’re like, well, yeah, well, we have the technology, we’re paying you for it, but it’s not implemented. That’s okay, the question is, do we have this control?
Troy Fine (26:07.767)
Yeah, yeah.
Manoj Tandon (26:22.754)
No, you don’t. Yeah, we do. We’re paying you for it. But it isn’t rolled out. You know, there’s a lot of that. It’s like they’re being driven by the market because the market wants and reassurance that a certain level of due diligence has been done in these processes. But they do the.
Troy Fine (26:27.693)
Right, right, right. Yep.
Manoj Tandon (26:47.83)
the clients looking at it and saying, you know what, I really want the revenue stream to not be disrupted, which is understandable. So I just want to check the box and just move on and who cares about this stuff? You know, this is why we have cyber liability coverage. If things hit the fan, we’ll let them deal with it.
Troy Fine (27:06.282)
Yeah, yeah, yeah. So in your situation, it was more, we don’t need to do this full defense in depth strategy or solution because we can get this SOC 2 type one with.
Manoj Tandon (27:20.45)
without it and it’s okay, you know? Now, they were in the medical healthcare field and forget the fact that if those records are out and PII is out there, all right, you know, we got, that’s why we have AIG.
Troy Fine (27:35.961)
Yeah. That’s why you have insurance. Yeah.
Manoj Tandon (27:39.252)
That’s how we backfill that. We’ve had other clients that, you know, they are required to have, I mean, MFA single sign-on is a basic requirement anymore.
They have the technology, but they haven’t turned it on. It’s like, yeah, we bought multifactor, but nah, you know, our team doesn’t like, that’s too hard, we don’t want that. I’m not making real examples. I wish they were lies and they were just total nonsensical garbage, but it really happens.
Troy Fine (28:06.195)
Yeah.
bright.
Troy Fine (28:16.938)
Yeah, I think that, yeah, and it’s, I guess it’s not just, it’s a big cybersecurity problem across the board, right? It’s people not understanding the risk of implementing controls. And I think, well, I think part of the reason is that, like, all the, obviously all these costs money, all these solutions cost money. It’s not just a procedural change and culture change, sometimes like maybe with MFA and like.
Manoj Tandon (28:40.13)
Sure.
Troy Fine (28:45.538)
I mean with the defense in depth solution, it’s a big cost, right? And so you’re trying to get a budget approved, you’re trying to explain to somebody why we need this solution, why we need to implement it. And the people you’re explaining it to are trying to understand an ROI, right? Well, what’s the ROI, right? Okay, well the ROI is we won’t get breached, but like, how do you, like, okay, what if we don’t implement the solution? What’s, what’s…
Like what’s the risk of getting breached if we don’t have this solution? Well, you need to almost like do like a return on control, so to speak, like a return on investment, return on control, and you need to measure, you need to quantify risk, right? So here’s the risk without the solution, and then when we have that solution, our risk is going to be X. So our return on that risk reduction is this risk minus the risk.
when we implement it. And it’s almost trying to explain it in those terms because they don’t, people making the financial decisions can’t understand risk unless it’s quantified. And they need to understand what’s the risk with it, what’s the risk without it.
Manoj Tandon (29:58.807)
So.
Manoj Tandon (30:03.55)
So this is cost avoidance in many respects, right? So the question is, do you have fire or flood insurance on your house, Troy? I’m sure you do. Did your house burn down last year? No. Are you still paying for it?
Troy Fine (30:18.964)
Right.
Troy Fine (30:22.263)
No, right.
Troy Fine (30:26.902)
Right.
Manoj Tandon (30:27.966)
All right, so what’s your ROI? There’s that, and then there’s the question of, if you look at the stats, and we only service the SMB space really, we do some work in the enterprise on a consultative basis, but most of our work is in SMB, small, medium businesses, those people sub 1500, 2000 employees, that group.
Troy Fine (30:31.934)
Yeah.
Manoj Tandon (30:55.69)
Six months, according to insurance statistics, six months post breach, many of these companies are out of business.
Manoj Tandon (31:07.106)
So what is that? That’s that now that’s a quantifiable statistic because that’s and that’s from an outside measure. If I, if we as a cybersecurity company or you as an auditor presented, it might be a little bit of a self-serving thing. Well, you’re just trying to sell me more hours or I’m trying to sell you whatever, no more security or whatever the case may be. It may be looked at that way, but that’s a genuine thing. And
Troy Fine (31:34.178)
But, you know, going back to the insurance though, those are the car insurance. There are rules that said if you’re gonna go on the road, you need to have car insurance, right? So they almost made laws to force people.
Manoj Tandon (31:50.166)
Yes.
Troy Fine (31:50.722)
to buy that because they could impact other people, right? So we don’t have those types of mandates for cybersecurity, right? Like if you think about it, like, right? Like I give you my data, there’s no really no mandate unless I put it in a contract for you to have, you know, you might put contractual clauses in there, but there’s not like a law that says like, in order for you to do business with the…
Manoj Tandon (32:02.862)
Yet. Yeah.
Troy Fine (32:19.95)
with other customers, you know, CMMC might be that and FedRAMP might be close to that. But if we’re looking at the private sector, you’re not worried with federal government, there’s not like laws that would require you to do certain things like in car insurance, right? I can’t drive a car without car insurance in Pennsylvania, right? Because if I get in an accident, I gotta have money, if it’s my fault, to pay for the damages, right?
Manoj Tandon (32:42.849)
Yep.
Manoj Tandon (32:50.862)
And you know what, Troy, the counter you get is, well, cybersecurity is unique in that the other side is often, this isn’t criminal behavior, in the traditional sense of somebody’s got a gun, they come into your house and they say, get out or give me your money, or as the case may be. These are very sophisticated actors who are constantly piercing the veil of technology and process.
at every moment to try to find a way to infiltrate. And companies are like, we can’t stop that. And there’s a little bit of a truth to that statement. I mean, staying ahead of that is a very impossible task almost. There’s always gonna be a way to breach something. And they’re like, well then why should I be held liable for something that I can’t prevent anyways? I’ve heard that argument and I have a counter to it, but
your thoughts as a pro on this, what? Yeah. There’s 5,000 PhDs who work at the GRU, who wake up every morning, trying to figure out every gap in Microsoft’s.
Troy Fine (33:54.294)
I should have you help lie it while you’re saying for a breach of my customers data in my systems.
Troy Fine (34:12.082)
sec.
Manoj Tandon (34:12.37)
environment or Amazon’s environment and how they’re going to do bad things. I can’t compete with that. You’re telling me my cybersecurity guys or my IT team of four people is going to stop that crew.
Troy Fine (34:30.018)
Yeah.
Manoj Tandon (34:31.586)
Uh…
Troy Fine (34:34.246)
Well then I don’t know if I have a good counter to that these they’re right they’re not gonna be able to stop it I don’t think you can’t I don’t you can prevent it you know there is no silver bullet that’s gonna allow them to prevent it
Manoj Tandon (34:41.856)
Yeah.
Manoj Tandon (34:50.018)
There is no silver bullet, you’re right.
Troy Fine (34:53.155)
But I guess should they be held liable, if it’s negligence, yes. I mean, if it’s something that’s like.
Manoj Tandon (35:03.792)
That’s a brilliant answer. And that’s my counter to the whole thing, right? If it’s negligence, have you done enough?
Troy Fine (35:11.671)
You’re right.
Manoj Tandon (35:12.738)
No one is saying that you’re gonna be breach free. I mean, even any of our customers, we never guarantee that we can stop all breaches. We can’t do that, right? But if we do our job right, we can certainly make sure the ship doesn’t sink or even really suffer major catastrophic losses.
Troy Fine (35:34.786)
Right. Yeah, I mean, I think for companies, it’s something even as simple as like, you know, we all know where our money is, right? If we all can tell you exactly what banks we have our money in, what 401ks are, where’s this, where’s that, where it’s hidden in our house. Like we can all tell you that right away right now. If I asked you, where’s your customers data? Could you answer that question? Most people probably couldn’t answer that question.
Manoj Tandon (36:02.862)
I can, I can actually tell you where it is.
Troy Fine (36:04.874)
You might, yeah, but you’re a cyber-scare, you could. But I guarantee if you went to like, the leader of a comp, well, you know, depending on the size, it’s hard to know where it all is, right, but do they, can they, do they even know what they have to protect and where it is, I guess is my question, right?
Manoj Tandon (36:07.586)
Yeah.
Manoj Tandon (36:20.326)
Oh my God, that topic’s come up on the show a thousand times, but.
Troy Fine (36:23.466)
Yeah, because I think that’s the number one thing. It’s like, don’t start doing anything if you don’t know what you need to protect or where it is. I’m like, what do you, if you don’t know what you’re protecting, what do you build? How are you gonna protect it? It’s like.
Manoj Tandon (36:40.814)
So, Troy, that brings up a question on when you’re, when you go into an organization as a professional auditor, is your interface typically the technical team or do you have the year of the executive team to report back to them and really give them genuine feedback on rather than, you know, because the tech, the exec team doesn’t understand.
Troy Fine (37:02.669)
Uh, it’s-
Manoj Tandon (37:06.626)
Maybe they don’t understand why we need a SIM or how does it work or what. Right.
Troy Fine (37:10.174)
Yeah, right. It probably depends on the size of the company, I would say, right? I mean, I think smaller companies, the exact team is usually at least interested in the results, so to speak, of the audit, right? Edging into bigger organizations, it depends if the person leading the security team is considered part of the executive team.
I mean sometimes they have a direct line to people on the C-suite, sometimes they don’t or they’re a couple layers removed. So it really depends on when you get to the bigger companies but a lot of times we’re not necessarily directly engaging with the executive team at larger companies during the audit. You know they just they have too much going on to worry about me.
You know.
Manoj Tandon (38:10.078)
But do they? Because if you highlight vulnerabilities and gaps in process, I would imagine they have a fiduciary responsibility to correct.
Troy Fine (38:20.822)
Yeah, yeah, that is a good point.
Troy Fine (38:29.422)
But it depends on their governance structure, right? Like who’s responsible for those gaps, I guess
What the people do with our audit report internally is a good question. I don’t always know that answer, right? So if there’s gaps or vulnerabilities identified, and I think it’s different too with the type of audit, if that makes sense, right? If you’re doing a SOC 2 or ISO and it’s an external audit, that’s kind of meant as a report for your customers, that type of audit might not necessarily like.
Well, it won’t be as in depth probably, as like an internal audit, right? So I’m in a large company and there’s an internal audit being done by internal audit on a very, let’s just say, identity access management. So internal audit’s doing an identity access management audit over the entire company and how they manage identities and how they remove, how they onboard, how they do all that. That type of report, if there’s gaps called out in that type of report that’s meant for management or executive teams.
I think yes. I think those types of reports are getting reported to audit committees. They’re getting reported to executive level team members and they’re seeing those results and they then have a responsibility to make sure that those vulnerabilities and those gaps are being remediated. So I think if you’re talking internal audit at a large company, yes, I think they are seeing, I think certain members of the executive team are seeing those results.
Manoj Tandon (40:05.854)
Regarding CMMC, specifically, I think I’ll just call it level two, where you have like, I believe it’s 108 controls you have to meet. Do you think that is overbearing for many of the businesses that have to comply or is that does not go far enough?
Troy Fine (40:16.887)
Yes.
Troy Fine (40:26.523)
Well Nissenher 171 right that’s really what it is.
Manoj Tandon (40:29.563)
Yeah.
Troy Fine (40:32.41)
Oh, that’s a fun question. No, I mean.
Manoj Tandon (40:35.094)
Sorry. Hey, it’s Friday. Let’s.
Troy Fine (40:39.726)
Yeah, does it go far enough? I mean, we can always say something could always be more, I guess, is what I’m saying, right?
Troy Fine (40:51.586)
But I think…
Yeah, if we look through Nissan 171, I’m sure we would say like, why doesn’t it talk about X? We’d be like, where’s this? Why is it not telling you about that? So yes, it can always go do more. But I think if we compare it to what’s going on in the defense industrial base right now, meaning like
the maturity of security at these companies is probably very low. And if they’re not mandated to do something, they’re just gonna continue to have low maturity in terms of security. Then it does go far enough, I guess, if that makes sense, right? Like if we, right? We take that we’re doing now is nothing. And something is better than nothing, as far as I’m concerned, at this point.
Manoj Tandon (41:31.67)
That’s good to hear actually. It makes a difference.
Troy Fine (41:40.642)
Do we need to iterate and constantly improve and get better? Yes, you should always keep doing that. But I think for a lot of companies in the defense industrial base, complying with this standard 171 is gonna be a burden. It’s gonna be hard for them to do, especially for the smaller players, right? The smaller manufacturers might not even have a security person and now all of a sudden they gotta implement 110 controls.
That’s going to be hard for them to do. For the companies like Boeing and all the big crimes, they’ve already been doing this. They’ve had so many regulations. They have to do all this. It probably doesn’t go far enough for them, right? But if you’re talking to smaller players, it goes far enough and they’re probably going to struggle for the smaller players.
Manoj Tandon (42:15.338)
Oh yeah, well…
Troy Fine (42:37.59)
But it’s better than, we need something. They need to start somewhere.
Manoj Tandon (42:43.103)
How much time do you think it would take a firm in that defense industrial base, a small medium business to actually comply with the CMMC requirements? This one’s it. How big is the bread box? What’s the range here?
Troy Fine (43:02.499)
Yeah.
Well, if they’re starting from, if they have no, nothing in place, like today, I guess it’s probably 12 months, if I had to guess, to do it all. Just because it’s going to require solution, solutioning, right? Finding tools, evaluating tools, changing your policies and procedures, you know, implementing, you know, new controls.
that you might get pushback on, right? So it’s not, you know, understanding what you have to do isn’t the problem. It’s getting, it’s implementing, right? And getting people to do what you want them to do and finding the right tools and finding the budget, right? All that takes time. So it’s not necessarily, I think people have a misconception that it’s all implementation, so to speak, right? Like, if 110 controls, it’s gonna take us so long to implement, but the implementation part might not take long.
But if you’re trying to buy three new tools to do something, you don’t have the budget. Getting the budget approved might take six months, right? Depending on the organization, right? Or evaluating the tools. Once you have them, that might take a month to configure them and get them up and running and do what you want them to do. But it’s that initial six months that people don’t understand because they haven’t been involved with it. So I think people need to understand that it’s not just, you know, implementation.
Manoj Tandon (44:25.001)
Yep.
Troy Fine (44:33.47)
it’s really the administrative and red tape and overhead that, depending on the culture of your organization, might slow you down a lot. So you should start thinking about it now so that stuff doesn’t get in the way. Because when sales says, are we CMMC certified yet?
and you’re like, well, I’ve been trying to get this budget approved for six months, that’s not going to be a fun conversation to have, right? So yeah, that’s what people need to start thinking about.
Manoj Tandon (44:57.27)
That might be a late point to start.
Manoj Tandon (45:10.346)
The jump from SOC 2 Type 1 to SOC 2 Type 2.
Manoj Tandon (45:16.866)
How long does that take?
Troy Fine (45:20.066)
That, actually that probably doesn’t take as long as you would think. Because SOC 2 Type 1, really the difference between Type 1 and Type 2, it’s more of from the auditor side, right? So an auditor has to do more testing, has to look at more evidence, has to do more sampling, so to speak, throughout the period. But the controls are, if you’re doing a Type 1 and Type 2, the controls should be the same.
The difference is you’re going to have to give more evidence to your auditor, spend more time with your auditor, they’re going to ask you more questions, they’re going to look at more evidence. That’s the biggest difference. But if you did a type one and your controls are in place and they’re operating, theoretically speaking, you should be good for the type two.
Manoj Tandon (46:08.374)
That’s good to know. Now, and the SOC standard is an accounting standard, if I understand correctly, right? It’s not missed.
Troy Fine (46:16.382)
It is. It is not. The standard is by the AICPA, the Association of International Certified Public Accountants.
Manoj Tandon (46:28.362)
I bet you a lot of people didn’t know that. And that, you know, they’re thinking that’s a security standard. And it’s not, it’s, which is interesting that a bunch of accountants got together and put it in place, so.
Troy Fine (46:31.105)
Hahaha
Troy Fine (46:45.226)
Yes, yeah, that is another fun, fun topic to discuss. But it is true that auditors’ accounts got together. But I would also make the argument that NIST might not have lawyers, I don’t know. I don’t know who’s putting together NIST, but the people putting together NIST are necessarily
practitioners, I guess, either in the security field potentially, right? You know, so I think the standards are good in general, but I think what organizations need to think about is how can I make these standards practical to my situation, right? Nobody’s going to comply with NIST 153 100%. It’s impossible. Like, it’s not even, or CMMC.
But you need to be flexible and you need to be able to interpret what the standard says and make it practical for you. And base it off of risk, right? I mean, again, these standards are written with a certain type of organization in mind. And if you’re a smaller organization, you don’t face the same types of risks necessarily. You don’t necessarily need to implement a very expensive tool. Maybe a spreadsheet is good enough for a smaller organization to start off.
Maybe, right? But I think people need to be practical about security. The standards are great, but you need to be practical about it and understand how do I implement this the way that makes sense for my organization, while also meeting with the spirit of the standard says.
Manoj Tandon (48:14.018)
Why not? Yeah, no.
Manoj Tandon (48:23.81)
So.
Manoj Tandon (48:36.362)
Which is now, is this something that you and your firm do when they hire you is provide them the practical guidance even prior to audit as to how to.
Troy Fine (48:45.194)
I think we do that naturally. I don’t think we’re coming out and saying that we’re doing that. But I think if you have conversations with our team, or there’s a lot of good auditors that are probably doing this out there. But naturally, we’re probably being practical when we’re having our conversations, because we’ve had experience working with these types of organizations. And so when we do consulting engagements, we are taking practical approaches with them, having collaborative conversations, really understanding like,
What is your system like? What is the risk? What type of data do you have? Maybe your data is less, if you don’t have highly sensitive data, long-winded processing control might not be necessary. So I think it just comes down to having collaborative conversations and really understand their systems, asking the right questions, and just being fun, being a fun auditor. We like to be fun.
Manoj Tandon (49:40.878)
God. That’s too fun. And audited are two words that usually do not coexist. But so that’s unique. I’ll give you that. That’s.
Troy Fine (49:51.743)
We want to be a fun auditor. It’s why I post memes is to be fun
Manoj Tandon (49:55.871)
That’s right, you’re a creator of memes, if I’m not mistaken.
Troy Fine (50:00.322)
that’s that I guess sometimes I get good ones out there but you gotta have fun with not even just with auditing right with security in general I think right I think we all get it’s very easy to get burnt out in the security industry it’s dry it’s scary at times especially with some of these things going on with like solar winds it can cause anxiety so you gotta like lighten it up a little bit have fun
Manoj Tandon (50:13.894)
it can be a very dry topic too.
Troy Fine (50:30.083)
So that’s what I try to do.
Manoj Tandon (50:32.414)
And well, we want we’re at the hour here. I want to give you a couple minutes. Is there anything you want to plug or let our audience know about? You know, your floor is yours on anything you want to.
Troy Fine (50:42.43)
Anything you want to put well, you know, if you’re looking for SOC 2, I’m your guy, Gills Norton. Come reach out. But yeah, you know, I don’t really have anything to plug specifically. I would just recommend read good books that have nothing to do with security. Like read good books.
Manoj Tandon (51:02.818)
Do you have one that you would absolutely recommend?
Troy Fine (51:05.994)
What’s one that I would absolutely recommend? Start with Why by Simon Sinek. It’s one of the first, not the first, but one of the best books I’ve ever read in probably 10 years ago I read it. And I would definitely recommend everybody read that book. It’s just, it boils down to anything you’re doing or decisions you’re doing, you need to understand why you’re doing them first before you understand the how.
Most people start with the how first, like how do I do this? But they don’t stop to think why am I doing this? And once you understand why you’re doing something, it drives the how, right? So your decisions become a lot easier when it’s clear why you’re doing something. Which is kind of relatable to security, right? If you’re just implementing controls, to implement controls, what’s the point, right? Like understand why are we implementing this? Oh, we’re trying to…
do this, we’re trying to reduce this type of risk here, and we’re trying to protect this data over here. Oh, all you have to do is do this, right? But if you start just like implementing, and don’t understand why, you can go down the wrong path very quickly. So I recommend everybody read that book. It’s really relatable to anything in life. So it’s a book I would read.
Manoj Tandon (52:26.712)
Awesome advice. Thank you so much for sharing your Friday afternoon with us, Troy. Really appreciate it. It was a great conversation.
Troy Fine (52:34.666)
I appreciate you having me, it was fun. And yeah, we should catch up in Pittsburgh.
Manoj Tandon (52:40.962)
Sounds like a plan to me.
Manoj Tandon (52:45.967)
M, you got it?
Troys’ LinkedIn
Check out the other episodes in Season 13:
Ep. 0 Chris Cazel and Rory Meikle – Streaming Services vs Cable
Ep. 1 Chris Rock – Shelf Babies: Killing and Birthing someone virtually
Ep. 2 Joseph Steinberg – Humans are the Achilles heel in Security
Ep. 3 Dave Sobel – Boring is Perception
Ep. 4 Aaron Painter – Holiday Season Verification Attacks
Ep. 5 Dr. Eric Cole – Where good CISOs become world-class
Ep. 6 Angela Bergsma – Paving the Way for Latina’s in Cyber
Ep. 7 Matt Brown – Why do 99% of Start-ups die
Ep. 8 James Potter – When you’re small, you’re the easiest target
Ep. 9 Chandra Pandey – Will the SIEM ever be Automated by AI?
Ep. 10 Troy Fine – Learning through Experience
About Troy Fine

Troy, is an industry-recognized thought leader (and meme creator) at the intersection of compliance, auditing, and cybersecurity. His expertise spans a range of frameworks, from SOC 2 and ISO 27001 to HIPAA, HITRUST, PCI, FedRAMP, CMMC, and privacy regulations.
Through a holistic approach, Troy helps clients navigate the complexities of compliance and fosters a culture of continuous improvement within organizations. His proficiency in articulating intricate concepts and delivering tailored solutions has made him a trusted advisor, empowering clients to not only meet regulatory requirements but also build resilience against emerging cybersecurity threats. At the core of Troy’s professional philosophy are the values of integrity and trust. These principles underscore his commitment to maintaining the highest ethical standards while fostering relationships built on reliability and accountability.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
