9
Ransomware I Know What You Did Last Summer Stan Banash Jr. CISM, CISSP, C|CISO, CIPP Chief Information Security Officer (CISO) Children’s Hospital of Orange County January 25, 2018

I Know What You Did Last Summersocal.himsschapter.org/sites/himsschapter/files/ChapterContent/socal/PS18_Stan_Banash.pdfIncident Response • Build a Plan – NIST SP800-61 • Prepare

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 3: I Know What You Did Last Summersocal.himsschapter.org/sites/himsschapter/files/ChapterContent/socal/PS18_Stan_Banash.pdfIncident Response • Build a Plan – NIST SP800-61 • Prepare

Threat Landscape

• Hackers• Cyber Crime Syndicates

• Malware Mercenaries

• Insiders• Clinical Staff

• Physicians

• Administrative/Support Staff

Page 4: I Know What You Did Last Summersocal.himsschapter.org/sites/himsschapter/files/ChapterContent/socal/PS18_Stan_Banash.pdfIncident Response • Build a Plan – NIST SP800-61 • Prepare

Attack Vectors

• External• Social Engineering

• Phishing

• Impersonation

• Vulnerable Systems

• Internal• Web Browsing

• Downloads

• External Media

Page 5: I Know What You Did Last Summersocal.himsschapter.org/sites/himsschapter/files/ChapterContent/socal/PS18_Stan_Banash.pdfIncident Response • Build a Plan – NIST SP800-61 • Prepare

Mitigation: Threat Intel

• Infragard

• US-CERT

• National Health • Information Sharing Analysis Center (NH-ISAC)

• Anti-Malware/ Security Vendors

Page 8: I Know What You Did Last Summersocal.himsschapter.org/sites/himsschapter/files/ChapterContent/socal/PS18_Stan_Banash.pdfIncident Response • Build a Plan – NIST SP800-61 • Prepare

Mitigation: Vulnerability Management

• Vulnerability Management Program• Routine Scans• Risk Assessment• Segregation

• Patch Management Program• Applicability• Understand Risk• Metrics

• Time to remediate• Remediation Percentage