22
In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

Embed Size (px)

Citation preview

Page 1: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

In the age of Continuous

Compromise

EXECUTIVE REPORTING

Trey FordGlobal Security Strategist

Rapid7

Page 2: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

AGENDA

•Boardroom Disciplines

•The Security Executive’s Challenges

•What’s Reported – 90 CISOs Point of View

•Affecting Change – Rapid7 Research Project

Page 3: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

BOARDROOM DISCIPLINES

Page 4: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

ESTABLISHED PROFESSIONS

• Medicine

• Law

• Engineering

• Accounting

Page 5: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

BOARDROOM TECHNOLOGYNCR - 1884 IBM - 1911

Page 6: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

SECURITY EXECUTIVE’S CHALLENGES

Page 7: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

INFORMATION SECURITY

NO REAL ‘HOW TO’ GUIDE

Page 8: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

SECURITY STATUS REPORTS

•Accounting has their GAAP

•Legal and Medicine has theirs

•What about Information Security?

Page 9: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

COMMUNICATION FLOW

Data, Verbose Reports

SUMMARIES

WISDOM

KNOWLEDGE

INFORMATION

DATA

Page 10: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

• Uncertainty at the Top

• Executives are Comfortable

• Engineers are NOT Comfortable

• The Secret

• Helping inform a point of view

• The idea may not be right or wrong

CURSE OF KNOWLEDGE

Summaries

Page 11: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

DELIVERING BADNESS

Vulnerability &

External Audit Reports

BURY THEM!?!

Page 12: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

INCIDENTS HAPPEN

Unsafe to Discuss?

Acknowledge bias:Prevention vs. Response

Page 13: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

ACTIVATING INCIDENT RESPONSE

AdmittingFailure?

Insurance Policy?

Page 14: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

Helping your CISO in the Boardroom

All CISOs have to address 3 questions (with EVERYTHING they say)

•What do I need to know?

•Why does this matter / Why do I care?

•What do you need from me?

Simple… and Hard.

Page 15: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

WHAT’S REPORTED

Page 16: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

WHAT’S REPORTED - TENURE

•20% have been in the CISO role less than 12 months

•New focus by Board in Security

•Last CISO was “too much business, not enough security”

•1/5 CISOs are looking for guidance or program validation

Page 17: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

WHAT’S REPORTED – AREA OF FOCUS

•15% report on specific security project status

•20% are concerned about Compliance Audits

•25% are focused on Incident Response

•49% are reporting on Vulnerability Management

Page 18: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

WHAT’S REPORTED – TANGIBLE

•6% report on Volume of Spam Blocked

•12% report no real metrics to their Board

•Also heard “lost laptops”, “stolen iPads”, “blocked websites”

•Many CISOs grasp for topics to catch their boards attention

Page 19: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

AFFECTING CHANGE

Page 20: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

Affecting Change – Rapid7 Research

•A Quantitative and Qualitative SURVEY

•>100 CISOs & non-Security Executives

•What gets reported? (Routine vs. Special Updates)

•Mapping against common Cybersecurity Frameworks

Agreeing on Simple…HARD TO DO!

Page 21: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7
Page 22: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

QUESTIONS?

Let’s talk!@treyford -or-

[email protected]