Good day, and thanks for joining. I'm Bob Bragan, Senior Vice President and Worldwide Managing Director of CSO. Organizations of all shapes and sizes have unique stories of resilience to tell about their experiences responding to the pandemic. Lessons have reached beyond just pandemic response and speak to the resiliency of their organizations. Today, we're speaking with Tim Callahan, the Senior Vice President and Chief Information Security Officer of Aflac. Aflac, a Fortune 500 company which operates in the U.S. and Japan, provides financial protection to more than 50 million people worldwide. Tim is a major force in the CISO community, and I'm pleased to be speaking with him today. Tim, welcome, and thanks for sitting down with us.
Thank you, Bob. Glad to be here.
Tell us about your role at Aflac and a little bit about the organization itself.
In 2016, we established a global security organization. Prior to that, we had security embedded in each of the business lines. Through various industry studies and internal studies, we determined that we needed to take a more global approach to securing our environment. While you think of Aflac in Japan and Aflac in the U.S., we still have several subsidiaries as well. We wanted to bring that together in a common framework. I've got kind of the expanse of traditional information security, but as well as things like information governance. We certainly have BC and business resiliency and recovery as part of our organization. We have a cybercrime prevention team. We have the traditional security ops, but really have put a lot of emphasis in our threat intelligence program, which comes under our director for security operations, and then identity access management.
We have also run a PMO, a global security PMO. We have recently, in fact, in January, actually announced an information security service that we offer to our independent agents. We've got a director for that. We've established a separate legal entity to be able to offer that. We've recently also opened up a cybersecurity innovation center in Belfast, and that's operating. That's kind of the expanse of the organization.
No small task.
Yeah.
What was Aflac's COVID-19 experience?
Yeah. There was several things that kind of influenced that. One thing, back in 2017, we restructured our whole crisis management program, crisis management team. We lead that primarily through our business resiliency program. We adopted a model, the Work Anywhere model, which we didn't coin the phrase, we use it a lot. Prior to that, again, we were very kind of focused within our different business lines with our program. As we globalized the program, we adopted, like I said, the all-hazards planning approach. It's interesting. I don't know if you maybe recall in circa 2012, 2011, around in there, the CDC came out with the zombie apocalypse plan.
Right.
That caught a lot of attention. What they were trying to emphasize is, well, if you can plan for the zombie apocalypse, you can kind of plan for anything.
Yeah.
They were using that as an education point for an all-hazards approach. We adopted that, certainly had a pandemic plan. We had a program where we exercised our global crisis management program, a couple of times a year, but definitely once a year with the executive team, where we all got together as the executives across the whole company and then went through tabletop exercises. The combination of those things, also the fact that we did have a presence in Japan and got some pretty early warnings from that. Our executive team, even before it was a pandemic or a crisis, we actually established a pandemic task force to start refreshing the plan, walking through it, talking about it, having conversations. When we had walked through a stage-down approach, if we needed to Work Anywhere, work from home.
As we kind of walked through that, we were very well prepared when the different states where we operate started declaring the shelter-in-place models. We were able to get our employees out the door pretty rapidly. We made the decision, as part of our 2017 plan, to divorce ourselves somewhat from a traditional disaster recovery trailer kind of thing too.
Yeah.
Like I said, the Work Anywhere model. We invested in the security technology and the remote work technology to be able to do that.
It wasn't a model like some businesses have had where they go, "If we had to take a fifth of our workforce and put them in another office because we had to evacuate a building." Yours was all in.
It was. As we canceled our contingency trailers, we did go through a step of saying, "Okay, what facilities could we double up on?" Just that all part of the plan.
Yeah.
The key to it was we were not bound by a facility. We had the connectivity, even to the point we've gone through scenarios. Well, if we had to, we'll go contract a hotel or-
Sure
a conference center or whatever. It gave us a lot more flexibility in that model, and that proved to be very beneficial in this case.
That's great. What have been some of the challenges you've encountered as a result of the pandemic?
Yeah. We've not had major challenges. We've been very fortunate on that. In the early days, getting people out the door, getting them comfortable. Some of them had never worked from home.
The kind of the calls to the help center, getting them set up and helping them work through that. We do use a multi-factor for all of our remote access. In some cases, people had not exercised that yet.
Most cases they had, they hadn't in some cases. Walking through those kind of things. I think the biggest challenge is the HR challenge, I think of helping people understand, to start achieving a little bit more balance.
probably you experienced the same thing.
Yeah
at 6:00 in the morning you still wake up at 6:00 in the morning.
Right.
You get in, instead of having an hour and a half commute, you're on the computer, then especially in our case, many of my team especially because we do have the global program, we're doing calls with Japan at night very early in the morning, then through the day, our traditional calls. You can sustain 12-hour days for a while. At some point, your body starts reacting to that. A lot of that has been those kinds of things, getting people comfortable, making sure that we're paying very much attention to the human aspect. We do have kind of a all-hazards but people first approach to everything we do.
We want to do that. We got early intel on some of the activity of the criminal. I thought it was very humorous. In fact, I put a post on LinkedIn that one of the famous ransomware groups had early came out said that, during the pandemic, they weren't going to attack anybody. Right? Of course, we didn't believe that, we got some early intel that certainly some of the people are going to take advantage of this. We've seen tremendous increase in activity. We've also seen that it seems like a lot more of the criminal element is shoving at third parties, going after third parties.
I think, if you got a bunch of CISOs around a table like you often do, Bob, we would have that conversation about how our third parties are becoming a sharper attack surface.
Yeah. Not too surprising. Have your priorities changed compared to what they were maybe at the beginning of the year before this whole thing started? Your security priorities, I should say.
Yeah. The priorities haven't changed. We're a strong 4-year, almost 5-year into our long-range remediation plan. We had deployed most of our capabilities. Some we found that we've had to redeploy. We have a roadmap, a global program roadmap, and we're staying pretty focused on that. What I will say is some of the business priorities have changed, and so we've obviously changed our focus. For instance, we were on a pretty aggressive digitization transformation anyway as a company. We found in this that we needed to accelerate some of that. Especially some of the security engineers, security solutions architects, have really had to take a little bit of focus away from what we were doing and move over there just to make sure that we're supporting the business and our technology partners.
Yeah. We're hearing a lot of that.
Yeah
All industries, just that acceleration of digital transformation has just exploded.
Yeah.
Has your perception of resiliency changed at all because of the pandemic?
That's an interesting question because we always talk about resiliency in theory.
When I do presentations, I'll often talk about the evolution of security. You can remember way back when we were primarily, especially in financial service, primary compliance-focused.
As the threat increased, we said, "Compliance is good. You have to do that, but it's not always security." We became security-focused. We looked at, well, how do you measure that? We started talking about maturity models and how that integrates in the program. We started talking about defensibility, right? It's.
do we talk about the program when something happens and thinking through that. Now it's resiliency. Not the others have gone away, right? They're still there.
Right.
You overlay resiliency in there. In theory, we've talked a lot about it. Then, this I see as an object lesson in resiliency. It kind of brings that home.
Yeah.
It kind of says, okay, all this conversation we've been having, this is part of resiliency. How do we continue business in less than optimal conditions? That's really the definition of resiliency.
Well, I see that as we have the conversations, it's no longer abstract.
Yeah.
We can really use this as one example of what we mean by resiliency, and that's been very beneficial.
Yeah. I think that's something that's going to play out over the years, too, right?
Yeah.
I hope that this sticks with businesses for a long time, this experience that they've gone through. Of course, the fear in the back of my head is that we'll forget about it in five years and go back to the way we did it before. God forbid, it ever happens again, we have to start all over again.
Yeah.
Tim, how do you think security is going to be most challenged in the months ahead? For a lot of businesses, they're starting to head back to the office. They may already be doing that. We may have to pull people back out. The whole dynamic seems to be changing, that raises a lot of challenges for security.
Yeah. At Aflac, we've adopted a fairly conservative model. We're going to really take a slow approach to returning to office, so to speak.
We're really avoiding use the word return to work because people are working.
Yeah, right.
Working very hard. We're taking a go slow approach. I think one of the reasons you just brought up is, let's all pile back in just to leave again if there's a second-
Yeah
wave or whatever. We've seen a little bit of friction in our field force, in our sales model. We're really trying to support them through increased digitization and getting more of a digital experience.
I think our security team is really focused on making sure that we do that in a way that preserves the security, privacy, all the aspects of our customer experience, and make sure that we have the confidence of our customers that they can transact business in this in a secure fashion. I'm not sure that's a challenge, but that's definitely a focus.
Right.
From, again, a human resources standpoint, we really want to make sure that we're taking care of our teams.
Right.
one of the things I talk, we were doing weekly town halls. We've gone to biweekly. We talk a lot about taking care of themselves.
Taking the PTO. We're in here for the long call. You need to make sure that you find ways to find release and relaxation. I do think, that's not necessarily a security challenge, but it can affect our security posture.
Yeah
if our people are crumbling. We just got to keep focused on that, I think.
Yeah, you mentioned, digital experience, that's something I've seen or heard about so much during this, is the focus on IT delivering the same digital experience to their end users, whether they're at home, whether they're.
Yeah
in the office, wherever they might be, because people get used to that from a productivity standpoint. They're used to working. They want security to be invisible. They want everything to just work.
Yeah.
A lot of companies have a challenge with that, but that's sounds like you guys have a good handle on it.
I think so. We had been going through a program where we were de-emphasizing printing anyway.
Yeah.
We went to secure printers. It gave us the opportunity when someone wants to print, someone in the office, they print it, then they have to go badge to pick it up.
things like that. Some would argue, well, that's not really necessary in an enclosed, secure building. It was more about the discipline of.
Yeah
Consciously thinking through, do I really need to print this, right?
Through that, we've been able to do a whole lot more online type of work that's not paper-dependent. That's helped us tremendously in keeping our productivity up.
Yeah. That's great. What's the biggest lesson you learned from this whole experience so far?
We are actually going through a lessons learned. We made a decision to, instead of doing our annual crisis management exercise, which incidentally, our plan was due a pandemic this year.
Oh, was it?
It was. We've made the decision that we probably exercised that enough. We're doing a lessons learned, what went well and what could we improve on kind of thing. Then we preserve the executive tabletop exercise in September, that date, so that we can all come together and talk through that, right?
What we're finding is that it's been more experimental things. How can we enhance the employee experience? How can we do more of those kinds of things? The company has been fantastic on that. We have a wonderful Chief Human Resources Officer that's very conscious. In my team, we have employee engagement committees that's been very active in coming up with ways to keep people engaged even through this. I think, some of the events that we've been so used to having on-site.
we've learned, hey, there's other ways to do that. Let's find different ways now.
Right.
Let's not depart from those when we go on-site. Another, I think tremendous lessons learned is the productivity. Our Chief Operations Officer for the U.S. program has kind of made this statement, "I think I'm going to probably keep 60, 65% of our workforce remote.
We've made a decision that my business resiliency team, we're probably never going to bring them back on site.
Yeah.
They were geographically dispersed anyway. Maybe not intentionally, but just because how we had to recruit people.
Yeah.
That's a good opportunity. These are the kinds of neat learnings. I call them the kind of the silver lining, so to speak, that we're discovering. We've also, again, some of the things that myself, as well as many of my security colleagues in other businesses, have found when we hire, because of the cyber talent shortage, you kind of hire where people are-
Right
You figure out how to leave them there if that's where they want to stay, rather than relocation. What we're finding is the rest of the company is kind of saying, "Hey, this is working. Maybe we can be a little more flexible in how we hire." I think that's another good learning.
Yeah. Makes recruiting a little easier when you can recruit from anywhere, but now everybody else-
Yep
is recruiting from everywhere.
Yeah. It is.
Final question for you. What's your number one rule for crisis management coming out of this?
Gosh. I think all-hazards approach. It really is.
I think being prepared for any scenario, understanding the commonality in scenarios, whether it's a physical, whether it's a cyber.
even a financial crisis or a pandemic. There's commonality in making sure that we exercise ourself in that commonality so that we're flexible in how we actually respond to a particular incident. It is interesting that there's kind of three major things that can affect a company globally. Certainly, a financial-
liquidity crisis, certainly a cyber event-
will, and then a pandemic. When you kind of walk through those scenarios, we're encompassing all three of those things come about at the same time.
Yeah.
Certainly the increase in attacks and responding.
We've been very blessed, very fortunate that we have not had anything in our core get through.
Responding to our third parties that have been affected. Certainly, when business is down, you have to respond to the financial issues, right? Certainly we're not in a liquidity crisis or a financial crisis per se, but there is that aspect. Every-
global crisis management meeting, we talk about that. Certainly responding to the pandemic. The one thing that's key in all of that is good, strong communication and making sure that we're talking to our employees, make sure that they're hearing from their leadership on a good, strong cadence, to be reassuring and be very transparent on any challenge we're facing and bring the team together. I think those are the key.
That's great. Tim, very much appreciate your insights. Thanks for speaking with us, and stay well.
Thank you, Bob. You too.