28
From awareness to culture: Building an effecve security program Chester Wisniewski Principal Research Scienst October 2016

From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

From awareness to culture:Building an effective security program

Chester WisniewskiPrincipal Research Scientist

October 2016

Page 2: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Who am I?

2

Page 3: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

The problem

Page 4: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Which is easier to circumvent?

4

Page 5: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

The keys to social engineering

5

Page 6: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

I’m here to help

6

Page 7: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Criminal tactics

Page 8: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

We’re good at detecting this

8

Page 9: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Not so good at this

9

Page 10: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Not so good at this

10

Page 11: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

High definition phishing

11

Page 12: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Open Source Intelligence

12

Page 13: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Education only goes so far

13

Page 14: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

What to do about it

Page 15: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

The number is 3.

15

Page 16: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

People

Page 17: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Creating a security culture

17

Page 18: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

The great phish debate

18

Page 19: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Use the force

19

Source: Verizon Data Breach Investigation Report 2016

AlwaysClick

SuspiciousReport to IT

Page 20: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Process

Page 21: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Assess risk

21

Page 22: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Focus where it matters most

22

Page 23: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Continuous improvement

23

Page 24: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Tools

Page 25: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Continuous improvement

25

Page 26: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Compatible → cooperating

26

Page 27: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS

Here to help

27

https://www.sophos.com/free-tools.aspx

Page 28: From awareness to culture - Office of the CISO · SOPHOS BACKUP-TOOLS PASSWORD- MANAGER FIRE WALL URL-FILTER SPAM DEFENSE SECURITY X TROJAN X PHIsHING X MALWARE ENCODING SOPHOS SOPHOS