Barclay Damon Live Presents Cyber Sip™ Season 5, Episode 12 “The Leadership Truth About Compliance: It’s Not Just Technical, It’s Cultural” Speakers: Kevin Szczepanski, Barclay Damon and Bruno Lecoq, BEMO Summary What is the episode’s main message about compliance? • Compliance failures are often leadership and culture failures, not just technical or policy failures. • Effective compliance depends on how people behave under pressure, especially when no one is watching. Where does an organization’s compliance culture need to come from? • The leaders in the C-suite must set clear priorities and show that compliance matters. • Middle managers are critical because they translate leadership’s message into everyday employee behavior. Why is the “checkbox” approach to compliance risky? • Compliance efforts must reflect real operational discipline and ongoing review. • Compliance cannot be treated as a one-time certification goal. It’s ongoing. How and when should organizations test whether compliance culture is working? • One method is the hidden tabletop exercises, to test real-time responses, process gaps, and leadership alignment before an actual incident occurs. Transcript Introduction to Compliance and Leadership Kevin Szczepanski: Well, we're delighted to have Bruno Lecoq, the cofounder, CEO, and CSO at BEMO. And today we're going to talk about the leadership truth about compliance—it's not just technical, it's cultural. But before we get to that, Bruno, tell us a little bit about your background and how you came to found BEMO. Bruno Lecoq: Yeah. So my you know, my background is I worked for 20 years at Microsoft. And, I started BEMO in 2010, and we do again cybersecurity and compliance for SMB across the US. Kevin: So focus on small and midsize companies. Why did you select that focus, Bruno? Bruno: I think, again, for my past experience, Microsoft, you're used to dealing with a bigger enterprise and always felt like, well, you know, the small guys need the same level of security because they cannot afford it. But at the end, you know, they are the one that are easy to hack and easy to make money as a hacker. So I always felt like it, let's find a way to help, those SMBs. And so again, we develop a lot of automation in order to make it happen. The Role of Leadership in Compliance Kevin: No. And I think the SMB community appreciates that as well, because that is an underserved but growing area in the field of cyber compliance. All right. So let's kick things off. And I want to kick it off with the concept that compliance failure is very often a leadership, and not a technical, failure. So let's suppose a situation involving a company that experiences a major compliance breakdown. The immediate reaction is sometimes to blame a policy or a process or a technical control. But in your experience, how often is the real root cause actually a leadership problem rather than a compliance problem? Bruno: Oh, it is for me it all start from the top. Again, it goes back …to the top are setting the culture, you know, the cultural they are setting the direction and you know, employee knows, the what the leadership cares and the employee do what the leadership cares. So if I'm mean again from a governance, from a compliance perspective, you know, the leaders, the C-suite, you know, we said, yes, we care. We manage our business to compliance. People will follow. Kevin: Now, I suppose many executives do believe that they have created a culture of compliance, but employees may be getting a different message. I remember a survey that I used to talk about when I presented on cybersecurity, and it was something like two-thirds of the leadership team surveyed would say they had implemented a policy or procedure, and two-thirds of the employees would respond by saying they had never seen it. So how do you how do you wrestle…what are the warning signs, I suppose, that the leadership’s values are not filtering down into the organization, the culture of the organization itself? Bruno: Yeah. I guess for me, always believe, you know, again, from the compliance perspective, compliance is defining the “what” again, you may have the policy… That is what you should be able to do. But the culture defines how people would behave when no one is watching. Okay. And it's how you see again, we talk about my company is again we do tabletop exercise. We do a lot of exercise again; every quarter all the way to make sure people will be. And how would their reactions. And the goal of it is to find holes. I prefer to again, when I do my tabletop exercise or when I do my exercise with a company. Let's find the issue now, not when we will really have an issue and there's nothing… Kevin: Can you describe briefly how your tabletop exercises work? There are many different ways… Bruno: Sure. We do it, we do it. And so we do a simulation and we do a simulation of, a hacker. A hacker came into the system, and we do a simulation about, you know, hey, how will the team behave? So in a, you know, site, before, you know, we'll do it, we will push a fake correct. And we can see how the organization reacts again from the, from the SoC team to the engineering team to do they contact the leadership team how we you know, how do we take your process okay. So and you don't tell people when you do it. From our perspective we don't tell because of course you people also I want people not to know is it a real one, fake one. It also just oh.. Kevin: So it's a hidden tabletop. Bruno: It's a hidden tabletop exercise. Kevin: Interesting. I have found a lot of times when it's an announced tabletop and everyone's in the room, the vibe sometimes is, ah yes. We're doing everything we should be doing. This is going well, but generally that's not what should be happening in a tabletop, right? You should be progressing to failure. Bruno: Exactly. Yes. Because now my perspective in when is programmed, people come ready or the IT team will two days before will check their you know what other step I should be doing. What I said the goal is what happened that day. A hacker is on your system. Would you know? What are we to panic, not to panic. And I think it's an exercise of, again, we deal with cybersecurity and our customers are always surprised like, whoa, you guys are very calm. And I'm like, oh, we are like the surgeon in the operating room. You want the surgeon to just, you know, case after case, no problem. You know, there is a saying. So we have to test the same thing. All employees have to have the same calm—oh, there is a hacker? I know how to do it. Middle Management's Influence on Compliance Culture Kevin: You know, I like that metaphor of surgery because I think that's what it is. Let me ask you about the middle management challenge, Bruno. I think a lot of times when we talk about leadership coming from the top and compliance is a leadership issue. We're thinking of C-suite executives, but many employees take their cues not from the CEO, but from the manager that’s sitting ten feet away. Or they may… the manager that they may be most commonly communicating with. So in your experience, how important is middle management in shaping that compliance culture and what mistakes do you think leadership makes when they ignore that middle management link in the chain? Bruno: I think from my perspective, the middle management is almost the most important. They take the cue from the top, but they are the one that convert the cue into action with their employees. So, if the C-suite tells you to go right, then the middle manager tells you go left, then you have a huge issue. And all… the opposite of a good management will tell it on all hands meeting. Yeah, we do that. The middle management take it over repeat. And then they get slapped on in their hands. Like what happened? You know people are not stupid they see when there's a misalignment. It's very you know, it's very clear. So it's again, it’s cultural, is how do people manage the message from the top to the bottom? How do they get feedback? It's, for me is the same as, is how do you run your business? Kevin: So everybody's busy. But, you know, and it's relatively easy to audit a firewall, implement a training program, or update a written policy. It seems to me it's much harder to assess whether people will actually do the right thing when they're under pressure. Bruno: Yep. Assessing True Compliance Culture Kevin: And you talked about the hidden tabletop as a means of testing that. But aside from that, how should the leaders of an organization go about determining whether they really have a culture of compliance, as opposed to just a compliance program that might be out there somewhere, but isn't really being brought into the heart of the organization? Bruno: Yeah, I see from, you know, people that to come to us, you know, our potential customers. I can see first, after ten minutes, is the company looking for a checkbox of compliance, or do they really care about security and want to become compliant? So I think it's already, you know, so because for me, from the compliance perspective, the other part is not to do the security. The other part is the operational rigor of the tenants, the disciplines. And again, to be more we are SoC2, ISO seven CE. So we have a cadence of we have to review weekly, monthly, quarterly. And from my whole management has to sign up every month, every quarter. So again, it's just …it's whole. But you know we don't even think it's compliance. It's how we run the business. So a company that want to know do they run it as just a checkbox like compliance. They know it. They know it. They do the… you know they… the amount of work is different. Kevin: And it sounds like the rigor and the regularity that monthly check-in, those updates help to just slowly and gradually… Bruno: I always joke with my IT team, you know, ten years ago, if we.. admin, were pretty much global admin, I mean, all the time. When you make a change, go make a change. Then came PIM, oh, so now you want to be global admin, I mean, you have to request access and you know what I mean. For two hours. I remember in those days when we made the change, oh, the IT team were like, wow, it's [hard to hear]. Now, from a compliance perspective, it's start by a ticket. You want to do something at IT, you open a ticket. What are you going to do? Why you need to do it. And then you do your PIM. You do the process and everything start with the ticket. When we did it before I do, people have to open a ticket each time I want to do something. Yes. And by now people are realizing, whoa, I see the value of being able to trace… of be able to understand what you know. So again, it's a habit. It takes some time to make the change. But, you know… The Checkbox Mentality in Compliance Kevin: Let me rewind for a second and ask you a question because as you were saying that and talking about comparing that culture of compliance to the checkbox format, it occurs to me that checkbox is out there. And one of the places that it still exists, I think is in the cyber insurance application process, is literally a checkbox. And we don't know what happens to those boxes once they're checked. But thought experiment: Is it better to have a checkbox system than no system at all? Or is there something inherently problematic about just checking the boxes and moving on and hoping everything's okay? Bruno: I feel like everything we do in life is almost a checkbox process, so you follow. But there's how there's the meaning behind the checkbox. Do you really care? Or is this just…so again, it's easy for me difference when I talk compliance with the check is someone said I want to be something I'm soc2, I got my soc2. You know my attestation. All great. And then what do you do? Do you check every month or is just you will wait next year on you and you hope so. Even from us with you know the rigor that we do. We have checked, you know checkbox. We have to check. Make sure you do this. Make sure you do that. So there's checkbox and checkbox. Incentives and Compliance Outcomes Kevin: No, that makes sense. All right. Let me shift gears and talk about incentives within an organization. So if I wanted to identify the true values of an organization focusing on cybersecurity, I might ignore the mission statement, which is something some of us spend a ton of time on and focus on what actually gets rewarded, punished or celebrated. Not what we say, but what we actually do. How closely do you think incentives can drive compliance outcomes, and are there any cases you’ve seen over the years where some very well-intentioned incentives actually have a negative effect on the organization? Bruno: I'm sorry compliance, to be honest, I don't think I have seen company doing incentive. So I know and I seen my company we don't, because I feel like you have to be careful about rewarding or not creating the wrong motivation, you know? And so we don't, you know, we don't have a system. And I haven't seen customer doing it. So I again I almost feel like again, it's part of the culture of the company. And if you have to have an incentive to have people behaving correctly, I think is because you have the wrong culture. Compliance as a Leadership Issue Kevin: Oh, that's a great point. No, thank you, Bruno. All right. Bruno, maybe this is a good closing question. Let's suppose a CEO comes to you and seems very sincere about compliance. But says something to the effect that, look, I don't see compliance as a leadership issue. I see it chiefly as an IT issue and a legal issue. So this is for the IT folks, the CISO, and the general counsel of our organization. How do you address that and maybe course correct the CEO’s perspective. Bruno: So I would give an example again that when we think, CMMC you want to be CMMC complaint, we'll take that one. Right. To be CMMC compliant. You have to have your person and they have to do a process ,background check that is, you know, whole process of you first need or the first one get onboarded. They have to follow a training program. You don't give them the admin access or again, they are going to join your IT team. They have to follow a training program before you can get them to this level. So this is again this is a Cha. Then the other process of you know, the operation team. So I could give him two, three or four example of what outfits whales sign up. Not only it not only you know it's a combination. The Ongoing Process of Compliance Kevin: So one final question. Open ended for you, Bruno. This is truly the final question. We've had a nice discussion here, but only about 15 minutes or so. Certainly not as much as we would expect organizations to be thinking and talking about compliance. Is there anything I haven't asked you that you think is really important. When you're thinking about the fact that this is a cultural issue within the organization, what's one thing you would want to leave with our audience that would, really focus this issue for them? Bruno: If I think it's for my perspective? I haven't seen a single organ today. We manage more than single company. I haven't seen a single company being successful, if they came from a perspective of compliance is a checkbox. And it's just what I would just get, you know, they get a certification after a year or two, they fail the next one because they are they don't have the ongoing process. So again, from my perspective that they always said to my customer, if you don't need to go into compliance, don't go there is expensive, right? But if you need to go there, you have to do it correctly and against always use the example. If you go compliance is like having a baby and then you have your baby. But then after we have to handle a baby for the next 18 years, because you have to remain in compliance. Same thing. So don’t start compliance if, you don't need it. But if you need to do it correctly. Kevin: Right. So compliance is an ongoing process. It's not just a check the box. It's something that starts and stays with the leadership of an organization. And the leadership has to work that down through middle managers to the employees on the ground to make sure that compliance is really part of the overall culture. Bruno: Yes, for me, it's part of everyone in an organization, everyone for me should have an objective around compliance. Kevin: Right. So even in my organization, I have to see that as my responsibility too. It's not something that someone else handles and that they just tell me when I need to know something. I have to be proactive every. Bruno: Agreed. Kevin: All right. Well, Bruno Lecoq, thank you so much for joining us. Cofounder, CEO, and CISO of BEMO, one of the great cybersecurity compliance organizations out there that focuses on SMBs, small and mid-sized businesses. And those are really… that's really where the action is when it comes to compliance, when it comes to attack prevention, threat actors. So it's something to be very vigilant about. Bruno, thank you so much for joining Cyber Sip. Bruno: Thank you for having me. Kevin: I really enjoyed having you. And thanks to all of you. We'll be back soon with another episode. Kevin: The Cyber Sip podcast is available on barclaydamon.com, YouTube, LinkedIn, Apple Podcasts, and Spotify. Like, follow, share, and continue to listen. This material is for informational purposes only and does not constitute legal advice or legal opinion. No attorney-client relationship has been established or implied. Barclay Damon Live podcast transcripts and captions are automatically generated through artificial intelligence, and the texts may not have been thoroughly reviewed. The authoritative record of Barclay Damon Live programming is the audio file. Thanks for listening.