From MSSP to MCOP: How SLTTs Are Redefining Cybersecurity Partnership
A three-part conversation · with Michael Pegues, former CIO, City of Aurora
Why the traditional managed-security model leaves the burden of running an actual security operation with the organization least equipped to carry it, and what changes when the customer governs and the provider operates. Recorded across three parts.
TF
Cyber Resilient Report powered by Data Defenders. I'm Tracy Francis, digital strategist for Data Defenders we recognize cybersecurity awareness month. This episode builds on the foundation, laid in our first two installments from vulnerability to resilience and the 60 minute brief expose threats built solutions. Together, those episodes reveal how MS-ISAC transitions and recent 60 minutes revelation exposes the growing gap between policy awareness and operational resilience. Today we're taking the next step showing how the MCOP model Regional SOC Utility Cybersecurity Operations 2.0 Paradigm Shift powered by DataShield. Cybersecurity 360 and data shared analytics closes the gap by transforming
Cyrus Walker
Okay.
TF
continuous
Cyrus Walker
Well,
TF
defenses
Cyrus Walker
um, obviously the,
TF
leaves
Cyrus Walker
uh, there's an impact there, uh, of a loss of services or potential loss of services, uh, for municipalities and, uh, units of government that
TF
different
Cyrus Walker
come to rely on those services, uh, to
TF
defenders
Cyrus Walker
stand up.
TF
of the
Cyrus Walker
Yeah, I'm here. Can you hear.
TF
A managed operations. First approach to cybersecurity with him is Michael Pegas, president of Aurora Dynamic Solutions and former CIO of the city
Cyrus Walker
I did. What am I supposed to do there?
TF
I'm sorry, uh, city of
Cyrus Walker
Uh.
TF
who's led municipal transformation firsthand. Their parenting terms, their complex news hook into practical operating choices, showing how MCOP run state executions, compliments municipal governments and constraints. Together, Cyrus and Michael will speak directly to the leadership questions top of mind for SLTT decision makers, mayors and executives to CIOs and CTOs to CFOs, balancing costs with risk. Alright. Let's dive into pillar one, setting the stakes to round this into reality. We recently surveyed SLTT leaders across the country.
Here's what we heard most often. CIO ask when those free services end, what's the biggest operational hit My team will feel on Monday morning, mayor asks, what's the single leadership action I could take right now to protect critical services like 9 1 1 and the CFO? If we start paying for these capabilities, what's our real cost exposure, especially when we factor in cost of inaction. These are questions driven driving this segment, and they're always, they're also the foundation of our companion resource, the mi sac dependency mapper. It's a quick visual tool that helps leaders see where their defenses depend on mi sac, where new gaps may emerge.
how to plan the continuity available in the show notes. So Cyrus and Michael speaking to these questions, what operational realities start to surface in the weeks after pre mi SAG services? Go away.
Michael
I do give you the honors there.
TF
Our, yeah, I, I have a message on mine saying that recording failed to start, uh, for you. Did you, do you see that on your side? Are you able to refresh your screen? Looks like
Michael
Think you just lost some.
Cyrus Walker
Okay. You guys there?
TF
Yeah. I'm here. see. Is that message reappearing on your sir?
Cyrus Walker
Uh, no. I don't see anything.
TF
Alright. Um,
Cyrus Walker
I.
TF
what I'll do is I'll stop the recording and it just to make sure that everything is sent.
Cyrus Walker
Are consenting to be recorded. Okay.
TF
Okay, so Cyrus and Michael speaking to these questions, what operational realities start surfacing in the weeks after those free mi SAG services go away.
Cyrus Walker
So the, um, potential reality is that, um, there's a loss of critical services that municipalities and other units of government have come to rely on. Uh, as they have attempted to stand up, uh, some semblance of a cybersecurity, uh, uh, operation. Um, and depending on, uh, those services, it could some significant holes in their visibility, uh, in their, ability to detect, um, uh, uh, uh, malicious activity. Uh, and in some cases their ability to.
Uh, respond to that activity from a technology perspective, when I say respond to it, meaning able to kill threats, kill signals, block ports, you know, do things that are, uh, important to keeping the bad guys out so loss of services can, um, be impactful. That way, those loss of services can also be impactful, uh, in of, uh, limiting their proactive capabilities. Um, for instance, for vulnerability. of being able to, uh, identify vulnerabilities that exist um, devices in their infrastructure. Uh, being able to provide, uh, some proactive capabilities like EDR on the, um, endpoint.
Um, I know that particularly here in Illinois, was being offered, uh, as part of a, a free service to municipalities. Uh, and CrowdStrike is an EDR application that allows for. Security teams to be able to monitor, uh, activity happening on the endpoint device, laptop, server, or the endpoints that CrowdStrike was installed on. So it gives, it did, could potentially take away that capability from being able to, they monitor activity, but also keep, uh, level of security, um, on, on each of those endpoints as well. So it makes, basically, makes them vulnerable to the bad guys again.
Michael
Yeah, absolutely. Uh, absolutely. Sorry about that. And I think if we kinda look at it from a different perspective, so I'm gonna put my, my former CIO hat back on here. Um, if you look at, I'd say kind of statewide, we take the state of Illinois in terms of local governments and those municipalities that actually have a, a. This type of capability, it's probably less. Th then more of those municipalities that have a capability. I would say, you know, just based on my recent research, that although you know, more of the 98% of the, you know, local governments, CIOs or CISOs say that that cybersecurity capability is a top priority.
I would say probably about a third of those local governments really have the capabilities. Um, to basically to manage off compromise or threats and things of that nature. Um, especially when you start to look at the smaller municipalities, they tend to rely more on like generalists or like shared services rather than kind of like a formal, uh, SOC or MSSP. Um, but you know, those tend to, um, exist within the larger cities or the counties. Right where they have the dedicated resource capabilities to kind of manage that. You know?
So I think just like in short, you know, nearly all the local governments say that, you know, the cybersecurity is a priority in that space, but only really one in three have dedicated cybersecurity functions.
Cyrus Walker
Mm-hmm. Right.
TF
Is there any additional comments to Michael's comment?
Cyrus Walker
No, I think that pretty, that pretty much covers what, what, uh, the reality of losing. Uh, this, this, this services, the, the, the, well, there's one thing that, that, um, uh, can uh, negatively impactful to the, um, municipality or unit of government. And that is, uh, the fact that they now have to spend this money in order to potentially replace these services. that they might not have had earmarked for cybersecurity services, you know, had earmarked for something else. But particularly for those units of government, uh, that, uh, hosts critical infrastructure like water treatment or power distribution or, um, traffic management in some way, shape or form, um, uh, or, or even healthcare.
You know, like for Cook County for instance, you know, with their Cook County Health system, um, uh, losing those services. Can potentially put, uh, the protection of those, of the critical infrastructure, uh, in jeopardy, um, and may require them to have to replace those services with costly, uh, services that, um, they might not have allocated budget for. So it's a, it's a, it's a reverberating impact throughout the entire organization. You know, at the end of the day, uh, no politician or, or, uh, elected official, you know, wants to. up in the news.
And so this has to be a serious consideration that they make, uh, in order to ensure that they can keep the, the residents of their communities or constituents, uh, safe. Um, we've seen, you know, where that can be very detrimental. Um, you know, when you look at cities like Atlanta or Baltimore that have, experienced severe cybersecurity, uh, breaches in the past, um, you know how that can. Result in millions and millions of dollars in losses and expenditures to recover the incident. Uh, so this is a serious consideration, uh, that, uh, municipalities have to make, uh, in order to ensure that they can continue to maintain some level of security, uh, in their environment.
TF
So now that the stakes are settled, this brings us to pillar two, the MCOP model, proactive operations, and financial Reality. Our follow-up survey with SLTT leaders, told us that their biggest challenge is in understanding the difference between reactive and proactive cybersecurity. It's knowing how to make the transition. Before we get into those questions, Cyrus, you mind giving us a 62nd breakdown about what's the real difference between an MSSP an MCOP provider?
Cyrus Walker
So it starts with the nature of, uh, the MSSP the MCOP. And the big difference there is one is naturally reactive, the other one is naturally proactive. Uh, and what that means is the, the MSSP model a 20 plus year old model that was designed to provide some assistance. Two, um, companies, customers, um, municipalities, units of government to give them some eyes on what's going on underneath the covers of the infrastructure. Um, and that's primarily done by, uh, an alerting function. So there's some kind of function that's set up um, for the vendor to capture, uh, and identify threat activity.
That then results in an alert being sent out to the customer, which then requires the customer to to that alert, um, either by making some adjustments to the infrastructure or countering that, that that threat that's been identified by that alert. at the end of the day, it's re it's requiring the, the customer to take that next step, uh, MCOP side from a proactive side. Um, uh, not only do you have the proactive threat hunting and threat killing, uh, but you also have the proactive operations management as well. So of relying on the relationship between the, uh, vendor to provide an alert and the customer to respond to the alert, now you have an MCOP base spender who is doing all of that.
They are identifying. The threat, they are responding to the threat. and they're also managing operations to mitigate any, uh, vulnerable state of vulnerability or vulnerabilities that exist in that environment that makes that threat viable. you have this act of 24 hour, uh, 24 by seven by 365 happening, integrated directly into the customer's environment designed to manage the three. Uh, components of the cybersecurity lifecycle, the, um, aspect of it related to strategy and risk management and compliance and so forth and so on. Policy development.
Um, then you have the, uh, process and procedure design around vulnerability management, assessment, um, incident response, you know, all those things that are required to activate the. Operation. And then you have the, uh, technical infrastructure management piece, is designed to, uh, provide the, the, the people, the expertise necessary run the operations on a daily basis. also the infrastructure, the technical infrastructure necessary to, uh, stand up, uh, the technical component of the infrastructure. What I mean by that, I mean your point solutions like your MDR, your EDR.
Your vulnerability assessment, your, uh, identity management, your cloud security, you know, all those things that, are necessary in today's, uh, tech, uh, technical environment. So, an MCOP is a much more comprehensive, uh, delivery of cybersecurity operations to the, uh, customer. Uh, that allow basically frees up the customer to do what they do best, and that's deliver services to. uh, and constituents of the communities that they serve, instead of them having to focus on doing that and building a cybersecurity operation to then encounter this active persistent threat. Uh, OGs and municipalities are not designed to, provide cybersecurity services.
They're, they're designed to provide, um, traffic management. They're designed to provide. You know, um, um, government related services that constituents rely on. You know, they're designed to provide law
Michael
Shovel snow,
Cyrus Walker
um,
Michael
you know.
Cyrus Walker
Right, right, right. Yep. Yep. They're designed to do those things. They're not designed to hunt trying to mitigate threats. So, um, it frees 'em up to do what they do best uh, the, the vendor, the MCOP vendor. It what it it does best, which is threats, kill threats, build operations, manage those operations on a 24 by seven basis.
TF
Yeah. And also there's a 77% savings compared to an in-house, so right.
Cyrus Walker
Yeah, so there is definitely a cost savings that's gained as a result of relying on a vendor that delivers this kind of service. You know, for, for an entity who's trying to build it on their own, um, they're gonna spend a lot of money doing that. Um, they're gonna spend money in hiring the people. They're gonna spend money in building the technology or, or, or, or procuring the technology. And they're gonna spend money in operating the technology. Um. Why, why go down that road when you can bring in a vendor who can spin up a, a cybersecurity operation very quickly at a fraction of the cost, uh, that it would take to do that?
Uh, so again, there's, there's better economies of scale and working with a vendor who could spin that up as opposed to going to do it on their own. Now, one of the things we've encountered in doing this is the. The control syndrome. Um, it, it makes sense. You know, most organizations wanna control what they do. I get that. Um, it's in that mindset of control where the challenges happen. Uh, the mindset of control, and particularly for tech, for technical people. You know, we, we naturally have a desire to control, you know, we wanna build, we wanna see the flashing lights, you know, we wanna see. Things working.
You know, we wanna ourselves on the back that we got this sexy technology solution up and going. That's now enabling services for everybody. You know, we wanna wear that cape, but for most organizations who are not designed to do that, that's not their charter, that's not their purpose. it, it's very hard and very costly to do that. So that's one of the major benefits of working with an MCOP. vendor, uh, as opposed to an MSS vendor, MSS vendor is just delivering a point solution and the MCOP vendor is delivering entire comprehensive operations.
TF
Mike, you've worked with an MCO providers with the City of Aurora. You speak about, what was the operational lift with working
Michael
Well, I mean, that was one of the benefits as well, that that lift, it didn't go away in terms of accountability. Um. That the city maintained, but it took the heavy lift off the staff trying to develop something. From scratch. Right. I know SARS talked about the key difference. I totally agree that that MSSP is more like bringing in an outsourced security operation team in a proactive manner to monitor, detect, and respond. Where that MOC is more of that broader cybersecurity partner that helped us to build frameworks. Governance compliance and operational maturity. I always like to think of it as that MSSP is like hiring a security guard service to watch the city of Aurora 24 by seven.
The OC with data defenders provided is like hiring a chief security officer and their team to help design the security program, help train staff to set policies also to basically to run the guards to make sure that. That threat vector is minimized as much as possible. Right. So those benefits actually ended up showing in terms of stronger cyber resilience, um, reducing that risk around ransomware or phishing or any type of data breaches or compromise. You know, you talked a little bit about the cost effectiveness piece and that was huge because even.
At the time, and I might even get this number wrong, when we implemented that capability at City Aurora, I could say at a minimum yearly we saved about $5 million. Was probably that, uh, total cost of savings, at least in the first year. It probably was more than that. Not probably. It definitely was more than that. Through year 1, 2, 3, and on as we move forward. Because obviously the cost goes up when you start to look at enterprise grade capabilities and that's it. Not the capabilities, that's the talent, that's the tools, right. Um, so you know, you kind of remove in a sense that cost of hiring, and especially in government, it's almost next to impossible to hire.
Industry wide cybersecurity talent in a government because the budgets are not there within government to pay for those. Right. So, you know, bringing that model in that subscription based model, um, helped us do a lot of like budget planning, but at the same time. Reduce the risk and protect our critical assets and services in the city, whether it's 9 1 1 dispatch, whether it was utilities, the water treatment plan, whether it's our permitting, payroll, public safety systems, right? It helped to ensure that continuity of services and also, and, and, and also more importantly,
Cyrus Walker
And, and
Michael
it helped us to gain public trust and maintain a solid reputation within the city of Aurora.
Cyrus Walker
yeah. One, I think one, one thing to note when you talk about the, the staffing aspect of it, just in this country alone, there's a shortage of about 500,000 skilled cybersecurity professionals around the world. That's in the millions. And imagine a, so a highly sought after cybersecurity professional, or even an entry level person, , uh, looking for a job. They, they in some cases look to the government for that initial opportunity, but once they get that training, they didn't leave for higher paying roles in the private sector, or at the federal level. Uh, and, and so what that did was it created a.
A revolving door of talent, out of, in and out of, uh, the, the government sector, which, which totally destroyed any potential for continuity, uh, any potential for maintaining and growing a cybersecurity operation. Uh, but basically when you had that talent leave, you had to start back at square one trying to find, uh, the, the talent to replace what you lost. And so what an MCOP, uh, model does or vendor does is. They bring all that staff and they create that stability, uh, right, right off the bat, so you don't have to worry about the instability in, in and the staffing in the workforce.
And, and depending on of N-C-O-M-C-O-P that's brought in, like for instance, US Data Defenders, uh, a lot of that information is captured in our data show analytics tool, which allows for that continuity of knowledge and information, that. Anybody can then plug into, in order to get a sense of the, the historical context to get a sense of where the organization is, uh, at the, at the current moment in time. and to help to get their arms around, uh, how the organization is functioning from a cybersecurity perspective. So there, there is a, a great benefit from working with, an MCOP vendor like Data Defenders because we, we, we address those seven challenges that we've identified.
in the, uh, municipal space, you know, related to costs, related to workforce, related to, um, um, uh, relying on the human element to, to deal with all that information that's being generated on a daily basis. Uh, there's, there's major benefits there that, any MSSP or build it on your own kind of scenario.
TF
Yeah, and the, the results they speak for themselves that I'm pulling these numbers from the Aurora case study, which Mike, at the time you were the current CIO, um, 35,331 threats detected 351, high severity attacks blocked and zero. Major incident. So quite an accomplishment. from looking at the survey from our SLTT leaders, most are within small municipalities. They're not as large as the city of Aurora, the second largest municipality city, uh, in the city of, or rather in the, in the state of Illinois. Mike as President of Aurora Dynamics Solution, can you speak to how effectively the MCOP model will work for all sizes of municipalities, especially the the smaller
Michael
Well, absolutely. Um, because you're talking about scale and also as I mentioned earlier, it's typically the midsize or the metropolitan. Size cities that have, uh, I'd say more robust or mature cybersecurity capability. Now, if the impact capability is already built and it's already scaled to manage a city like the city of Chicago, or you know, a county like Cook County to bring in. A smaller village, right? That's under, say maybe 200,000 or 150,000 or even a hundred thousand population is simple, right? The capabilities are there. The impact to the impact is, I would say. Smaller or more minute than trying to just set it up from scratch.
So, you know, this particular framework or motto is basically built that way to actually, what's the word I'm looking for? It's basically to look at it as almost like a shared service model where if you set something up more in a, you set it up like City of Aurora in a regional framework. If you have the surrounding suburbs or villages or townships, it's easy to get them on board. It's typically not a challenge to onboard those from an impact perspective. The challenge is more around budget and bureaucracy at the government level, right? I think that's the challenge in terms of the procurement aspect, uh, and budget.
Uh, bringing those, uh, smaller villages or townships or cities on, um, because you know, it's a scalable partnership, right. You know, that adapts to, you know, city sizes or needs, whether it's a small municipality or a large metro. So, you know, and it basically, the impact provides that flexibility to expand those services as the city adopts new technology. 'cause that's what we did at the city of Aurora. First it was really focused just on the enterprise, but then we also. Expanded that to focus on the water treatment plant. We started looking at the I OT space, that segmented network, right? Um, and infrastructure or cloud or whatever it may be.
Cyrus Walker
Yeah, that's an important distinction there. Um, that, that shared services. Model, which makes adopting a comprehensive solution much more easier and palatable for those smaller municipalities. One of the unspoken benefits of a shared services model also the shared intelligence that comes along with that. for instance, if something is happening at a city like Aurora, that intelligence can be automatically shared across various tenants. Uh, for surrounding like Naperville or, uh, Woodridge or, um, uh, Palatine or Lyle or, or any of those surrounding communities to Naperville, uh, to help them strengthen their, their defenses immediately, uh, to the, to the threat that's been identified.
and, in that MCOP model, it, uh, allows for that seamless transfer of information. Uh, uh, immediately, again, unlike A-M-S-S-P is siloed because point solution is only, uh, um, allocated to that particular And so you only have that information that, can be used for that customer the MCOP model, particularly in the data show Cybersecurity 360 model that we There's a back plane of intelligence that happens and intelligence sharing that happens allows for our security operators to be able to immediately scale up and, and intensify, uh, services when it's needed, and then scale it down when it's not
Michael
Right. And also, yeah, go ahead. Sorry.
TF
X
Michael
Yeah, and I was gonna add to that, and that's just one of the specific benefits when you actually look at it from trying to leverage the impact in that shared service model. Right. Also, you got regional cost savings opportunities, or not cost savings, but sorry, you got regional cost sharing opportunities where you the, you know, the larger municipalities may pick up the bulk of the cost. Right where the smaller villages don't have to pay, they're just paying a much smaller percentage and they join into that joint contract. Um, you know, um, so again, those sh you know, those.
Those costs are shared proportionately, you know, based on, and they can be shared proportionately based on the population, the budget, you know, the system size. And then those smaller cities gain access to more advanced cybersecurity capabilities without having to bury that full, you know, financial cost as well. That's where that, you know, that shared service model is very, very beneficial. In regional areas or where you have large municipalities, um, like something like the city of Chicago, and then you have, you know, uh, thousands of cities and villages that can, you know, piggyback, for lack of a better word, off of that particular model.
You know, that's that whole kind of regional soc as a service approach, um, to, you know, being smart about your cybersecurity.
Cyrus Walker
Yeah, that's, that's a, a excellent point. There is a, a, a, a, uh, uh, a weighted cost that, can be applied to the municipality based on, various, uh, parameters, like number of residents, size of the technology, infrastructure, number of endpoints. Um, that, uh, so it's not a one size fits all kind of scenario. it's, it's, it's very be bespoke to the municipality, uh, or to the, the, the unit of government. but, uh, and which allows for that waiting delivery of services and, and, and resulting cost that comes along with that.
TF
Okay. I think we thoroughly covered the MCOP model. Um, we've built a resource that's available in the show notes titled the MSSP to MCOP explainer. So for our listeners, take a look at that to get a comprehensive understanding on the differences between an MSSP and the benefits of an MCOP. So let's take a, a look at. Our third pillar. Um, now let's talk about our, our leaders. Well, lemme, lemme start this over. Um, now let's talk about how our leaders sustain, uh, this, this level of resiliency with the MCOP model. Um, turning strategy into daily discipline. This brings us to pillar number three. resilience, the cybersecurity lifecycle and 90 day action plan.
So far, we've covered the operational and financial realities of moving from reactive alerts to proactive continuance, continuous operation with the MCOP model. But real resilience isn't just a model, the mindset. It's built through consistent, measurable practices that repeat and improve over time. Before we dig into the leadership questions from our SL SLTT, survey, uh, Cyrus, can you give us a quick breakdown of what cybersecurity lifecycle actually is and why it matters?
Cyrus Walker
So, yeah, so the cybersecurity lifecycle, uh, is a, um, uh. Method methodology. It's a, it's a method methodology, sorry, uh, that identifies the important aspects of a cybersecurity operation, uh, and the, the important considerations made about the daily operations. So the lifecycle itself basically means that, you know, you go through this process, you come back to, uh, the starting point, and you start all over again. The whole point of that is evolution. Hopefully as you've gone through that process, once you've learned a lot, you can then add that information back into the stream of operation, uh, which should translate into an evolution of the operation.
So it's getting better and, and that operates and, and either a generalistic perspective or in a, a very in, in time, real time perspective. So, for instance, with threat hunting, you know, as you are, are. Learning more about new threats or persistent threats, you are adding that information back into your operation to a stronger defense, a stronger response to that threat. But the lifecycle itself, uh, we've identified that there are three major components of any cybersecurity operation. Uh, and as I mentioned earlier, there's the governance aspect, uh, which is the strategy, the planning. Then there's the process and procedure aspect.
Which is the, um, um, action, uh, part of the operation. then there's the, uh, technical infrastructure management piece, which is the response. what I mean by that is, you know, as you identify the risks in your environment, you're responding to those risks by building a cybersecurity operation or cybersecurity infrastructure that can help you to mitigate or counter those risks. And as you are operating your op, as you're running your operations on a daily basis, those three components should be evolving and getting better over time. But they should also be informing each of the other components.
For instance, your governance component is going to inform process and procedure, meaning you're gonna identify a strategy or risk management, uh, program or policy or compliance program. That's gonna dictate the other two components are gonna look like. But it's gonna initially directly the process and procedure piece, that dictates how you go about operating and acting in your environment. That is going to dictate what technology you need in order to support your action. that's the technical infrastructure management piece. Not, and not just technology, but what, what people do you need in order to run this on a daily basis. And so as you are going through that process, it becomes cyclical.
It should never become Anytime a cybersecurity operation becomes stagnant, you are as vulnerable, as, as if you didn't do anything in the first place. Why? Because that threat is always evolving, and particularly now that we're dealing with ai, is accelerating the evolution of those threats and, and, and, and bad guy capabilities. And so that means that this lifecycle has, the operation has to continue to evolve. As well.
Um, there's a, there's a ancillary component to all of this and that each of those components should be directly informing and indirectly informing the other components of the lifecycle that you have what's called balance 'cause if you think about a circle, if you will, or, or, or just a will, you know, in order for a will to properly service, uh. Or provide that service. It's gotta be in balance, otherwise it's gonna be a bumpy ride. Um, find that most cybersecurity operations are out of balance, meaning they've done well with the governance, not, uh, done well in implementing the process of procedures or the technical infrastructure management to match what the government said.
Or they've grown their, their architecture in an ad hoc way in response to industry threats or stuff that they've heard on the street. They go out and get the next, uh, and great next latest and greatest point solution to address that threat. it, it's not correctly reflected in their governance strategy, uh, or their process and procedure. Uh, as an anecdote, we had a customer, a municipal customer that uh, basically was a one man shop. They were a pretty large city. Um. And every time we had a meeting, we always marveled at all the monitors that were behind the CIO's, uh, desk. He had 10 monitors behind his desk, one of those monitors was a point solution that he himself had eyes on.
None of those point solutions were integrated with each other. Uh, they were, they were there because he had, responding to what he was hearing in the industry about. Threats and experiences that other people had. And um, he just went on and purchased the latest and greatest point solution to help mitigate that threat. But they still had an incident because of the lack of integration technical infrastructure management and alignment with the governance and process and procedure piece. So that's some, that's basically the life cycle, how that life cycle works. It has to be. Balance. There has to be alignment and there has to be comprehension across each of those three components.
TF
And Michael, from your, your perspective, your experience, um, how does tabletop exercises specifically an IARP tabletop exercise, how does that fit into adapting this cybersecurity
Michael
Yeah. Um, just let me say before I get into the response for that for a minute, I thought Cyrus was talking about me with all those monitors behind him, but then as he went on and, and his explanation, I said, nah, that's not me, because I didn't go and buy anything. So I. All right. I have one big monitor. Exactly. Yeah.
Cyrus Walker
big monitor on your desk.
Michael
All right. So in terms of lifecycle management and, uh, the, um, the incident, can you repeat that question again? Uh, Tracy, with regards to the incident response plan?
TF
Well, it's about the right tabletop exercises. How does that fit into the cybersecurity
Michael
exercise. I mean, absolutely. I mean, that's a function in terms of, um, I like to think of, okay, so the incident response and also the tabletop exercise is really readiness, right? You're. Staying consistent and you're staying updated and trained, and not just you, your entire team, and also those, you know, your stakeholders in terms of if there is a outage, how do we respond to that? Actually, how do we identify, how do we detect, how do we, you know, protect ourself and we respond to that. As part of the overall, uh, lifecycle management, when we had, you know, that impact model that directly integrate into what we called our continuity of operations plan.
We called it our coop, COOP, continuity of operations, right? The incident response plan. Was an artifact within the city's continuity of operations plan. Now, keep in mind the city's the coup plan is basically a plan that they use. Or it's designed to say, how do we respond when critical services are out? Whether it's 9 1 1 dispatch, whether it's the water treatment, whether it's the financial system is down, or public safety is actually hit in some, uh, fashion, right? And how do we basically, um, remain operational during that disruption and how we recover. Those services. Right.
So that incident respond plan to that particular artifact is how we respond in terms of, you know, the staff within, you know, the IT department within the other city departments to a particular incident, right? And how we, um, you know, basically, uh, get services back up and running, but the actual, um. Where am I going with this? The actual, um, um, lifecycle management piece is, I think it's all kind of. Integrated together because, you know, we have to, you know, um, you know, the city has to depend on those services, uh, to function, to provide to our citizens. But you know, the impact is there to make sure that that incident response is actually integrated. So.
Requiring, you know, that, you know, that that coop plan actually requires clear procedures for responding to those emergencies. And that's where this, you know, the impact brings that structured incident response playbook that, you know, that's aligned to the NIST standards and probably the, you know, the FEMA from Department of Homeland Security Guidance as well, to ensure that the incident is handled, you know. With the same rigor as any other natural disaster or physical emergency that might happen.
So again, as you talked about before, that resiliency piece is actually built in, you know, to the, to the coup plan to ensure that redundancy, you know, to, you know, make sure that those controls are there. So we know how to fail over, cut back, and recover. In those times of needs when there's that disaster and a cyber threat. In the city of Aurora, we actually had it updated within our city ordinance. It is a considered, you know, an incident that requires the utmost importance. Just like a flood, just like a tornado, just like any other natural disaster. Um, you know, um, so.
We, you know, the whole ideal is to make sure that you know, that, you know, that resiliency is there, that redundancy is there, you know, and we continue to improve those services. Right. And again, it all goes back to the public trust piece, right? And transparency, making sure that the public, it's pro, that we are actually proactively safeguarding those, you know, our citizen data and services. And basically we're strengthening that trust during, uh, during, uh, during crisis.
TF
And for anyone who wants to start mapping those steps immediately, uh, we've created a companion resource. Title, the IRP Tabletop Checklist and Executive Oversight Dashboard. It's in the show notes. Um, it'll walk you through a simple 90 day action plan surrounding how to run your first dependency sprints, how to track tabletop exercises, and how to report issues or results clearly to leadership and council members. Before we finish off with our last segment, and Mike, do you guys have any additional comments?
Cyrus Walker
Um, yeah. So, you know, the, the, the thing that is most important, uh, about the MCOP model, is the initial consideration of trust. You I talked about the idea of control, but the, the consideration of trust. Allows for the municipality or, or customer to, uh, be able to relinquish that control in a, in, in a controlled way. Um, you know, to use that word, uh, uh, for double meaning, and trust the, the, that the vendor's gonna do what the vendor's going to do, which is to, to manage and, and deliver operations while the customer. the governance and strategy aspect of it with input from the, from the vendor, from the MCOP vendor.
And so what that does is it rightly places both the customer and the vendor in the right places in the cybersecurity operation, which allows it to move forward in a very fluid and, um, cohesive and, and, and, uh, um, uh, expedited way, uh, without that trust. Uh, you're gonna have, you're gonna naturally have conflict, and when you have conflict, things don't work. I remember, I, I had a customer back in the day, they had rolled out a $10 million network upgrade using this vendor called Bay Networks. And, um, network wasn't performing. It was, it was a New England based, uh, uh, provider. They didn't have any, um.
Had zero trust from the vendor because the network kept shutting down a, across New England area from Maine all the way down to New York. They were ready to throw out the vendor and spend another $10 million to bring in Cisco. Um, but it was, it wasn't until I came in and identified that there was an issue of trust between the two, the customer and the vendor, and we began to work on reestablishing that trust. That we were able to actually find out what the problem was, why the network was shutting down the way that it was, and we were able to fix the problem and save the account for both the, the vendor and the customer.
So that's an example of how trust can bring right alignment in the relationship to allow for people to do what they're meant to do in, in, in the, uh, structure of the relationship.
Michael
Yep. And I would've just like to add, just lemme go back because you talked a lot about the tabletop exercise, and I think in my, in my last, uh, um, conversation, I talked a lot about, you know, um, why the tabletop exercise, you know, helps the continuity of operations by ensuring you know that those cyber disruption are treated with the same rigor as any particular natural disaster, but. I think more importantly, why does it matter for municipalities? You know, with regards to the tabletop exercise, I think.
Embedding that tabletop exercise into that OC life cycle makes the cybersecurity more of a living, breathing, operational aspect and not just a, let me check the box type of compliance. Right. So I think that tabletop exercise becomes kind of like that validation engine of that cpac, not the PO, the impact, um, lifecycle. So it's almost like a, it's, yeah, it is basically that kind of like a pressure test for each phase. It. Tries to identify those different blind spots and drive that continuous service improvement, you know, making that whole process very sustainable, you know, and operational, viable for municipality as it actually moves forward. Right?
Cyrus Walker
Mm-hmm.
Michael
And again, that's what we did in the city of Aurora, right? I mean, everything we're talking about is, is practical and it's real.
Cyrus Walker
Right.
TF
Wonderful. Well, Cyrus and Michael, that wraps up our last pillar. Thank you very much
Michael
Thank you.
TF
your time and insight and your contribution to the cybersecurity awareness mug.
Cyrus Walker
Yeah. Thank you, Tracy. Thank you for, for having us and we'll, we'll look forward
Michael
Thank you both. Thank you.
Cyrus Walker
in the future. All right
TF
So I'll stop the recording there. I have a few, uh, outros that I need to do on my end. So. And Michael, that was an incredible productive final segment. We've shown the read. We've shown the resiliency isn't built on tools or technology alone, but on continuous loop, the cybersecurity lifecycle where governance, procedure and technology infrastructure work in sync. That frame empowers a defender's MCOP model and operations first approach that transforms cybersecurity from reactive monitoring to proactive 24 by seven defense. And though the regional Security Operations center or r.
Protects the scale and through the Regional Security Operations Center or O that protects and through the Regional Security Operations Center or O, that Protection Scales, empowering cities and SOTT networks to share intelligence pool resources. Maintain continuous coverage. If your organization or consortium is ready to move from alerts to operations, start by mapping your cybersecurity lifecycle and explore how the MCOP and RSAC models make resiliency rsac models make resilience for both practical and affordable. Before we close any final thoughts from both of you? Okay, great.
Hey, cybersecurity Awareness Month reminds us Staying Secure is not longer, and Cybersecurity Awareness Month reminds us. Staying Secure is no longer about reacting to threats. It's about building operations that never stop Across the Cyber Resilience Report series, from vulnerability to resilience to the 60 minute brief, one message stands out. MCP model extended through the regional SOC turned cybersecurity from an IT expense into a mission critical capability. If you miss those episodes, you can listen anytime at data dash defenders. If you miss those episodes, you can listen at any time at data-defenders.com/resources or wherever you get your podcasts.
Together, they trace the full story from national headlines to local solutions. Together. They trace the full story from national headlines to local solutions. Together they together they together, they trace the full story from national headlines to local solutions, and show how SLTT leaders can achieve budget realistic 24 by seven resilience to explore deeper, download the companion resources mentioned in the episode, and engage at your own pace. With our Rone AI enabled expert powered by Google Notebook, lm an intelligent companion that dynamically summarizes and responds with actual insights rooted in data defender verified content. I'm Tracy Francis.
Thank you for joining us for our cybersecurity Awareness Math edition of the Cyber Resilience Report. Protect and Secure What Matters as the outro. Uh, this is the intro. Welcome to the Cyber Resilience Report by Data Defenders. I'm Tracy Francis, digital strategist for Data Defenders as we recognize Cybersecurity Awareness Month. This episode builds on the foundation leading in our first two episodes as we recognize Cybersecurity Awareness Month. This episode builds on the foundation leading in our two as a as we recognize Cybersecurity Awareness Month. This episode builds on the foundation, laid in our first two installments.
Vulnerability to resilience and a 60 minute brief exposed threats built solutions Together, those episodes reveal how the mc ISAC transitions and the 60 minute revelation exposes the growth. Together, those episodes revealed how the mc ISAC transition and recent 60 minutes revelation exposed the growing gaps between policy awareness and operational resilience. Today we're taking the next step showing how the MCOP model Regional SAC Utility Cybersecurity Operations 2.0 Paradigm Shift powered by Data Defenders Cybersecurity 360 and DataShield.
Today we're taking the next steps showing how the MCOP model regional SOC Utility Cybersecurity operations with I know Paradigm Shift powered by DataShield Cybersecurity 360. Data analytics closes the gap by transforming awareness into continuous AI driven defenses. Two. Today we're taking the next steps showing how the MCOP model Regional SOC Utility Cybersecurity Lifecycle powered by DataShield Cybersecurity 360 and Data Show Analytics closes the gap by transforming awareness into continuous AI driven defenses. Because awareness without action leaves communities exposed, and this month is all about turning awareness into resilience. Joining me are two people who live in these challenges.
Joining me are two leaders who live these challenges from different angles. Joining me are two leaders who live this challenge from different angles. Joining me today are two leaders who live. Joining me today are two leaders, leaders. Joining me today are two leaders who live this challenge from different angles, cyber Walker, Cyrus Walker, CEO of data defenders and architect of the MCOP model, A managed operations first approach to cybersecurity. Joining him is Michael Pegas, president of Aurora Dynamics Solution and former CIO from cyber. Cyrus Walker, CEO of data defenders and architect of the MCOP model, a managed operations first approach to cybersecurity.
Joining him is Michael Pegas, president of Aurora Dynamic Solutions and former CIO for the city of Aurora, who led the municipal transformation for and former CIO for the city of Aurora, Illinois, who led municipal transformation for sand. A complex news hook into practical operation choices, showing how MCOP run state execution compliments municipal governance and constraints. Together, Cyrus and Michael will speak directly to the leadership questions top of mind for SLTT decision makers, from mayors and executives to CIOs and CTOs and CFOs, balancing costs with risk.
Together, Cyrus and Michael will speak directly to the leadership questions top of mind for SLTT decision makers, from mayors and executives to board members to CIOs and CTOs to CFOs, balancing costs with risk. These topic points are designed around your real world and concerns and decisions you face every day. By the end of the episode, you'll learn. By the end of the episode, you'll leave informed, confident, and ready to execute. Actionable next steps this quarter. Let's dive into pillar number one, setting the stakes to ground us into reality. We recently surveyed SOTT leaders across the country. Here's what we heard most from, often from us across the no. Here's what we heard most often.
ECO asks. When those free services end, what's the biggest operational hit? My team will feel on Monday morning and Mayer asks, what the single leadership action I need to take right now to protect critical, like what is the single leadership action I need to take right now to protect critical services like 9 1 1 1 and water, A CFO if we're starting to play? If we started paying for these capabilities, what's our real cost exposure, especially when we factor in cost of inaction. These are questions driven. The these are questions driving this segment, and they're also the foundation of our companion, and they're also the foundation of our companion resource, the mi sac dependency mapper.
It's a quick visual tool that helps leaders see where their defenses depend on mi sac. It's a quick visual tool that helps leader C, whether the, it's a quick visual tool that helps leader C, whether defenses depend on MI sac. It's a quick visual tool that helps leader C, whether defenses depend on mi sac, where new gaps may emerge, and how to plan for continuity available in the show notes. These are the questions driving this segment, and they're also the foundation of our companion resource, and it's also, and they're also the foundation of our companion resource, the MS. ISAC dependency mapper available in the show notes. It's a quick.
It's a quick visual tool that helps leaders see where their defense is, depending on mi sac and where new gaps may emerge, and how to plan for continuity. So Cyrus and Michael, speaking to these questions, what operational realities start to surface in the weeks after those free mi sac serves? Go away. Pillar two, transition. So now that the stakes are settled, this brings us to pillar two, the MCOP model, proactive operations, and financial Reality. So not the stakes are settled. This brings us to pillar two, the M, the MCOP model, proactive operations and Reality, and the. Our follow up survey.
SOTC leaders told us their biggest challenge is in understanding the difference between reactive and proactive cybersecurity. It's knowing how to make the transition. Before we get to, before we get into these questions, Cyrus, give us a quick 62nd before we get into this question. Cyrus, give us a quick, before we get into these questions, Cyrus, give us a quick understanding of the, before we get into these questions, Cyrus, can you. We into these questions. Cyrus, can you explain to us the difference between an MSSP and an MCOP now that, so that sets the scale perfectly and those servers responses from SLTT leaders build on exactly what difference. Okay.
That sets the scene, you know, that sets the scene perfectly. You know, that sets the scene perfectly. And the survey response that we got from SLTT leaders built on exactly the differences, here's what they told us. You know, that's interesting. And that a, you know, that interesting. That sets the scene perfectly. And those survey responses that we got from SLTT leaders. They speak to those differences. For example, A COX, if we try implementing these best practices on our own, what's the real lift for a small IT team? Mayor, ask, what should a city council be asking each month to make sure governance is actually working and a C and A CFO ask, what does a 77% and a CFO ask?
What does that 77% savings really look like in dollars when compared? Comparing an SS. What does that seven in A-C-F-O-X, what does that 77% savings really look like in dollars when comparing an M in A-C-F-O-X? What does the 77% savings really look like in dollars when comparing an MSSP to an MCOP? Those are the perspective. We'll export. Those are the perspective we'll explore next. And for listeners who want to visualize these differences in real time, we build a companion resource. The MCCP. I got that. So we've defined the MCP. So we define the MCOP model. We built a companion resource, the MCC, so, so we define the MCOP model. We've also, so we define the MCOP model.
We built a companion resource, the MCCP, to MCCP. Now that we define MCOP model. Okay, so we define MCP model. So with greater understanding of the MCOP model, we've built a companion resource, the MCCP, to MCOP explainer, which is also available in the show notes. Now let's take a look at the leaders. Now let's talk about how leaders sustain it, turning strategy into daily discipline. Now let's talk about how leaders sustain it by turning strategy into daily discipline. This brings us to our third pillar, building resilience to cybersecurity lifecycle and 90 day action Plan.
So far, we've covered the operational financial realities of moving from reactive alerts to proactive continued operations. Real resilience is a just a model. It's a mindset and built. It's built through consistent, measurable practices that repeat and improve over time. Before we dig into the leaders' questions we heard on this topic, Cyrus, before we dig into the leaders' questions we heard on this topic, Cyrus, can you give us a quick breakdown of what the cybersecurity lifecycle actually is and why it matters? So with that said, so with that said, our recent survey of the S Ltt leaders confirmed it's top of mind.
So with that said, our recent survey of the SLTT leaders confirms it's top of mind, and here are the three questions we heard most often. You see I ask. CIO ask, how do quarterly tabletop exercises actually strengthen resilience? And how should we measure success? And Mayor acts, how do we connect these practices to outcomes? Civilians notice in Mayor Acts, how do we connect these practices to outcomes? Civilians, notice not just internal compliance metrics. And the CFO asks, how do we justify investments in readiness? When the ro I isn't clear until after an incident. Are the perspectives we'll explore next for anyone who wants to start mapping those steps immediately.
We created a companion resource and IRTP, tabletop Checklist and Execution oversight dashboard. Walk you through a simple 90 day action plan. How do you run? First dependency sprint, blah, blah, blah, blah, blah, blah, blah. Alright, that's it.