About Heidi Roth
Heidi Roth, Executive Vice President, Chief Administrative Officer & Secretary at Kilroy Realty, has spoken about her participation in the REITWise conference, which she described as an opportunity to connect with peers and discuss the regulatory environment, SEC financial reporting, and day-to-day challenges. She noted that she had attended the conference multiple times.
In a 2015 interview, Roth discussed cybersecurity risks for real estate investment trusts (REITs). She stated that cybersecurity threats "know no boundaries," citing attacks on companies such as Target, Home Depot, and Sony. Roth said that cybersecurity risks should be part of corporate governance and risk management, and recommended that companies conduct comprehensive risk assessments and develop incident response plans. She also emphasized the importance of internal education, stating that awareness campaigns should cover secure passwords, email and mobile device risks, and that protocols should be communicated consistently throughout an organization.
Source: AI-verified profile updated from Heidi Roth's recent appearances.
Browse all interviews →
Transcript (10 segments)
M
Matt Bishow0:02
I'm Matt Bishow with NAREITsreit.com, here in Phoenix, Arizona for REIwise 2015. Joining me is Heidi Roth, Executive Vice President, Chief Accounting Officer and Controller with Kilroy Realty Corporation. Heidi, thanks so much for joining us.
M
Matt Bishow0:15
Now here at REIwise, you were on a panel that looked at cyber security. What's been the biggest change in the past year or so that's elevated this to such a critical issue?
H
Heidi Roth0:24
Well, Matt, I think that SEC Chair Mary Jo White summed it up nicely in some recent comments where she said the cyber security threat now knows no boundaries. And I think over the past year, we've really seen that evident as household names such as Target, Home Depot, and Sony have all come under attack. And I think month by month, we see companies small and large are falling into that as well.
M
Matt Bishow0:48
And what are the most critical steps that a REIT should take to protect itself from a cyber attack?
H
Heidi Roth0:53
I think it's recognizing that cyber security risks should really be part of the overall corporate governance, risk management, and planning framework. And that companies should really do a very comprehensive risk assessment to look at what their specific risk factors are and come up with a plan to mitigate those risks. With that said, I think it's also important that people have a very well-vetted cyber incident response plan, because in the event that an attack happens, it's important to be prepared.
M
Matt Bishow1:24
And how important is internal education to protecting a company?
H
Heidi Roth1:26
Internal education is critically important. I think throughout the organization, from the boardroom to the mailroom, it's critically important for everyone to understand the sensitivity of the information that they're responsible for and to protect that information. With that said, companies should be very mindful of having an effective awareness campaign within their organizations, involving things as simple as people understanding the importance of secure passwords, the risks with incoming and outgoing email, the risk of mobile devices, and really coming up with a protocol to try to mitigate those risks and communicate that throughout the organization consistently.
M
Matt Bishow2:03
Heidi, thank you so much for joining us today.
H
Heidi Roth2:06
Thank you.