Mike Delaney
speaker
219 appearances
1 recordings
1 series
first heard Nov 2024
last heard Nov 2024
Mike Delaney’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
People live in their own experiences and whatnot. And if you segregate IT knowledge by generation too, you know, you compared me to my children. My children were much more savvy. When my kids first wanted cell phones, I would tell them they can get it the same age I got my first phone. It is well after college because they weren't invented yet.
But you look at my parents and while I find them quite savvy for their age, they certainly have more trust than I would give the Internet. And I think that, you know, that's another aspect of it, that people don't quite understand how easy it is to behave badly through the Internet and information technology and how quick you can be bad.
I have to say, I'm grateful that my parents actually text me or send me a screenshot of something they get and ask me if it's legit. And I'm always like, no, delete it. This is my whole thing. If it's really important, they will get back to you. If you delete something, they will get back to you. It does.
I've said this, I think my whole career, I even probably said it to you four or five times, Mike, just delete it. If you don't know what it is, they'll get back to you or they'll call you, you know? I just wanted to quickly give you a moment to talk about your role as a corporate lawyer in a food company. A lot of people don't know what that means.
They think lawyer and they picture maybe a courtroom or they picture paperwork or something like that, but sort of like a day-to-day in a food company that you would deal with as much as you could probably disclose. Just a quick snapshot of what that looks like.
Yeah. So I'm certainly not a law talking guy. I don't go to court. That's not what I did. Sometimes the day was mundane. Sometimes it's negotiating a supply agreement with your flower distributor. That's going to be a multi-year agreement for millions of dollars and it would take months and months to negotiate. Sometimes it was dealing with an unfortunate accident or incident in a facility.
We're dealing with one, the safety and health of our employees. One two, dealing with what happened, why and Is this an OSHA issue? Do we need to report it? Those sorts of things. When it came down to the cybersecurity side, you know, it ranged from the early days of, you know, when we learned of an incident forming that task force to get in the room and figure out what's going on.
I think food in general is advancing because now we're looking at more robust recovery plans. I think cybersecurity is now finding its way into there. You know, but we would focus on that, you know, Sometimes it was, you know, I had the board of directors coming and I had to go deal with them. And they played a role in cybersecurity because, you know, again, it's an issue that popped up.
It was front of mind for our last company because we were doing such a large revision to the IT infrastructure. So the board was very much involved in that and listening and learning and watching it. When we did enterprise risk management assessments, IT was always top of mind and usually one of the higher risks we had. Yeah.
As we implemented our system and eventually worked through the bumps and issues that we had, especially it ran fine. Our risk assessment moved. And that was one of my roles was a risk manager. I worked with our risk manager. We would do this assessment every year with the board. It moved from. the system itself running to worrying about the issues that could come in and it haunts.
And the board often look towards insurance and you and I and past have talked about whether or not insurance is a good way to go. I have a lot of faith in the insurance business. I think they're usually ahead of the game in terms of pricing risk, seeing risk. IT, I think they struggle with. Cyber is even worse. It is an area, again, it's a new issue.
It's not that it's been around that long, at least in its form. And so I think they're trying to create products that aren't necessarily caught up to the issues yet.
Yeah, and they don't know how to underwrite for it just yet either. There's not enough cybersecurity expertise or IT expertise in the industry. It's getting better, but it's not quite there yet.
No. And again, before we got on, we were talking about a lot of Western world IT cybersecurity management is reactionary. We've seen incidents occur. And one of the bigger ones in the recent years was when JBS had its ransomware attack. And that one really rippled through the industry and raised awareness to this problem. But it certainly wasn't the only incident.
160 food companies last year alone that had some sort of attack. That we know of. Let's actually, and I want to segue into that because one of the things about cybersecurity and the risks that go along with it is if an event happens, if it's material enough, it can really, really hurt your reputation.
It can hurt your bottom line, which usually if your reputation's hurt your bottom line, it's going to follow quickly. So getting information out to the marketplace is important. However, when you're dealing with private management team, they might not want to get that out.
And if they can contain, control it, they'll prefer not to let anybody other than their board know what they just went through. That's changed in the public company world. Starting in December of last year,
The SEC added another reporting requirement to companies that are publicly traded, and this applies to a lot of food companies, that if they have a cyber incident happen, they have a responsibility to report that to the investment community in a prompt manner. There's all kinds of nuances to it. It's called a Form 8K, and the Form 8K is really just a current report.
And there's a list of many different activities that happen that companies have to routinely report out to shareholders. And the rationale is it's information that should be out on the street so they can make an assessment of their investment. And the SEC is, you know, share it with everybody. It's fair. Yeah. When it comes to cyber, they decided to add it as one of the disclosure item 105.
It's if you have a cyber incident that you determine is material to your company, you are required to report it to the shareholders and to the investment community at large. The problem is, when do you know that it's material? And there have been incidents, and the example would be my prior law firm, when they had the infiltration and this large food manufacturer had its issue.
Showing 101–120 of 219 · page 6 of 11
← Previous
Next →