40
© Copyright Fortinet Inc. All rights reserved. GDPR : La protection périmétrique avec Fortinet Security Fabric October 6 th , 2017 Steven VersonnenFortinet Roland de Biolley - Fortinet

GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

© Copyright Fortinet Inc. All rights reserved.

GDPR : La protection périmétrique avec Fortinet Security Fabric

October 6th, 2017

Steven Versonnen– Fortinet

Roland de Biolley - Fortinet

Page 2: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

4

Do I need to care about GDPR?

Do I need to care about GDPR?

Page 3: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

5

Do I need to care about GDPR?

OCTOBER 2017

SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY

1 2 3 4 5 6 7

8 9 10 11 12 13 14

15 16 17 18 19 20 21

22 23 24 25 26 27 28

29 30 31

* M-Trends 2016

25 May 2018

No stress …

Page 4: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

6

GDPR and technology

No silver bullet solution

Legal issue

Not technology

Consists of 99 articles

Only 1 article about technology

There is no “buy this and be compliant” solution

A safe network is an essential foundation

1. Strategy & Policies

2. Employee training

3. Procedures to address complaints

4. Agreements with third parties

5. Privacy by design

6. Data flow audit

7. Data register

8. Privacy impact assessment

9. Consent

10. Incident/Breach Response plan

11. Internal security audits

12. Technical security measures

Page 5: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

7

Looking to the Future - What GDPR Requires

MAI 2018

SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY

1 2 3 4

5 6 7 8 9 10 11

12 13 14 15 16 17 18

19 20 21 22 23 24 25

26 27 28 29 30 31

DATA BREACH

DETECTED!

DATA BREACH

REPORTED!

Page 6: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

8

What Your Network Requires

INITIAL

INTRUSION!

Average time between

intrusion and detection =

200 DAYS*

* M-Trends 2016

* Verizon Breach Report 2016

Page 7: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

9

The Hacker’s Advantage:Window of Opportunity

INITIAL INTRUSION “WINDOW OF OPPORTUNITY” BREACH DETECTION

Page 8: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

10

The Fortinet Objective: Close the Window of Opportunity

INITIAL INTRUSION INTRUSION DETECTION

KNOW SOONER

REACT FASTER

Page 9: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

11

THE ROAD TOAN INTEGRATED SOLUTION

Page 10: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

12

Advanced Threat

Intelligence

Access

Client Cloud

Partner API

NOC/SOC

Network

ApplicationBROAD

POWERFUL

AUTOMATED

The First Step

Exchange security information between Fortinet

and non-Fortinet solutions to increase your

security visibility and enforcement to a higher

level

Page 11: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

13

Today’s Network is Borderless - Network Segmentation Architecture from IoT to the Cloud Essential

IoT

Mobile

Windows

Mac

Private

Public

No Trust

Trusted

5G

100GAccess

Campus

WAN

Core

Orchestration

Page 12: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

14

Branch Office Campus

Data Center

Remote Office

Mobile

PoS

IoT

More Ways to Get In – Even More Way to Get Data Out

Page 13: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

15

Enhanced Protection Across the Entire Attack Surface

WAF

EMAIL

SWITCH

ACCESS

POINTS

Network

MOBILE IoT

WINDOWS MAC

APIs

SECURITY

SANDBOX

MANAGEMENT

ANALYTICS

CASB PRIVATE

PUBLICMETER

Access Apps

CloudEndpoint

Page 14: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

16

WE DON’T KNOWWHAT WEDON’T KNOW.”

DONALD RUMSFELDFORMER US SECRETARY OF DEFENSE

Page 15: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

17

99.5%

Need for Unknown Threat DetectionTarget attacks

Page 16: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

18

Hand off:

High risk items

Hand off :

Provide ratings & results,

automatic signatures

Hand off:

Updating prevention

Prevent

• Act on known threats

and information

• Using NGFW, Web

Filtering and AntiVirus

• Important part of the

first line defenseFortiOS

FortiGate

FortiSandbox

Detect

• Unknown Threats

• Maximize Threat

Protection

Mitigate

• Immediately mitigate new threats

identified by FortiSandbox

Unknown Threat DetectionUsing FortiSandbox (FortiCloud or OnPremise)

Page 17: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

© Copyright Fortinet Inc. All rights reserved.

‘Security Fabric’ real example

Ransomware & Data Breaches

Page 18: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

20

Page 19: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

21

Page 20: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

22

Page 21: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

23

Page 22: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

24

Page 23: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

25

Page 24: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

26

Page 25: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

27

Page 26: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

28

Page 27: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

© Copyright Fortinet Inc. All rights reserved.

Did it have to happen ?

Page 28: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

30

Page 29: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

31

Page 30: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

32

Page 31: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

33

Page 32: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

34

Page 33: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

35

Log, View and Act

Enterprise

Firewall

Secure

Access

Cloud

Security

Advanced

Threat

Protection

Application

Security

Security

Operations

FortiGuard

Page 34: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

36

Log

Page 35: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

37

View

Page 36: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

38

Act

Topology Awareness

Security Fabric Reports

Single Management Plane (of Glass)

4th Dimension (4D)

Page 37: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

39

IOC – Indicators of Compromise

Topology Awareness

Security Fabric Reports

Single Management Plane (of Glass)

4th Dimension (4D)

Page 38: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

40

FortiAuthenticator: Gateway Into the Security Fabric

FortiAuthenticator

Secure Access

Network Entry

Certificate

Server

FSSO

FortiToken Mobile

Page 39: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1

41

CONCLUSION

We can make the life of a hacker difficult

Technology for GDPR is important

Close the hacker Window of Opportunity

Fortinet Security Fabric

» Detect. Mitigate. Prevent. Collaborate.

Page 40: GDPR : La protection périmétrique avec Fortinet Security ... · 7 Looking to the Future - What GDPR Requires MAI 2018 SUNDAY MONDAY TUESDAY WEDNESDAY THURSDAY FRIDAY SATURDAY 1