68
"Cyber" security - all good, no need to worry? Ian Amit Director of Services, IO Active

"Cyber" security - all good, no need to worry?

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: "Cyber" security - all good, no need to worry?

"Cyber" security - all good, no need to worry?

Ian Amit Director of Services, IOActive

Page 2: "Cyber" security - all good, no need to worry?

¡Hola

Page 3: "Cyber" security - all good, no need to worry?
Page 4: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Page 5: "Cyber" security - all good, no need to worry?

Incidents by Business Type - All Time

Biz Gov Med Edu

Source: datalossdb.org

Page 6: "Cyber" security - all good, no need to worry?

Incidents by Business Type - All Time

Biz Gov Med Edu

52%

Source: datalossdb.org

Page 7: "Cyber" security - all good, no need to worry?

Incidents by Business Type - All Time

Biz Gov Med Edu

18%

52%

Source: datalossdb.org

Page 8: "Cyber" security - all good, no need to worry?

Incidents by Business Type - All Time

Biz Gov Med Edu

16%

18%

52%

Source: datalossdb.org

Page 9: "Cyber" security - all good, no need to worry?

Incidents by Business Type - All Time

Biz Gov Med Edu

14%

16%

18%

52%

Source: datalossdb.org

Page 10: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Page 11: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

Page 12: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

57%

Page 13: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

20%

57%

Page 14: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

10%

20%

57%

Page 15: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

7%

10%

20%

57%

Page 16: "Cyber" security - all good, no need to worry?

Source: datalossdb.org

Incidents by Vector - All Time

Outside Inside - Accidental Inside - Malicious UnknownInside

6%7%

10%

20%

57%

Page 17: "Cyber" security - all good, no need to worry?
Page 18: "Cyber" security - all good, no need to worry?

DataLossDB.org Incidents Over Time

0

450

900

1350

1800

2004 2005 2006 2007 2008 2009 2010 2011 2012 2013

695

1621

1091

829728

1048

775

644

157

43

Page 19: "Cyber" security - all good, no need to worry?
Page 20: "Cyber" security - all good, no need to worry?
Page 21: "Cyber" security - all good, no need to worry?
Page 22: "Cyber" security - all good, no need to worry?
Page 23: "Cyber" security - all good, no need to worry?
Page 24: "Cyber" security - all good, no need to worry?
Page 25: "Cyber" security - all good, no need to worry?
Page 26: "Cyber" security - all good, no need to worry?

Problem ✓

Page 27: "Cyber" security - all good, no need to worry?

Problem ✓

Solution?

Page 28: "Cyber" security - all good, no need to worry?
Page 29: "Cyber" security - all good, no need to worry?
Page 30: "Cyber" security - all good, no need to worry?
Page 31: "Cyber" security - all good, no need to worry?
Page 32: "Cyber" security - all good, no need to worry?
Page 33: "Cyber" security - all good, no need to worry?
Page 34: "Cyber" security - all good, no need to worry?
Page 35: "Cyber" security - all good, no need to worry?
Page 36: "Cyber" security - all good, no need to worry?
Page 37: "Cyber" security - all good, no need to worry?
Page 38: "Cyber" security - all good, no need to worry?
Page 39: "Cyber" security - all good, no need to worry?
Page 40: "Cyber" security - all good, no need to worry?
Page 41: "Cyber" security - all good, no need to worry?
Page 42: "Cyber" security - all good, no need to worry?
Page 43: "Cyber" security - all good, no need to worry?

What would CISO do?

Page 44: "Cyber" security - all good, no need to worry?

What would CISO do?

Page 45: "Cyber" security - all good, no need to worry?
Page 46: "Cyber" security - all good, no need to worry?
Page 47: "Cyber" security - all good, no need to worry?

WTF?

Page 48: "Cyber" security - all good, no need to worry?
Page 49: "Cyber" security - all good, no need to worry?

RISK MANAGEMENT

Page 50: "Cyber" security - all good, no need to worry?
Page 51: "Cyber" security - all good, no need to worry?
Page 52: "Cyber" security - all good, no need to worry?
Page 53: "Cyber" security - all good, no need to worry?
Page 54: "Cyber" security - all good, no need to worry?
Page 55: "Cyber" security - all good, no need to worry?
Page 56: "Cyber" security - all good, no need to worry?
Page 57: "Cyber" security - all good, no need to worry?

We need to get back to BASICS

Page 58: "Cyber" security - all good, no need to worry?
Page 59: "Cyber" security - all good, no need to worry?

insert crowd pic here

Page 60: "Cyber" security - all good, no need to worry?
Page 61: "Cyber" security - all good, no need to worry?

Prioritize !

Based on risk, impact,

potential cost, and cost of remediation

Page 62: "Cyber" security - all good, no need to worry?
Page 63: "Cyber" security - all good, no need to worry?
Page 64: "Cyber" security - all good, no need to worry?
Page 65: "Cyber" security - all good, no need to worry?
Page 66: "Cyber" security - all good, no need to worry?

Summary1. Stop throwing money on products

2. Identify assets, processes, technology, threats.

3. Assess your current posture. Identify gaps.

4. Address gaps based on priority and relevance. Consider cost (of impact, of fixing).

5. Test effectiveness.

6. Back to 2.

Page 67: "Cyber" security - all good, no need to worry?

REMEMBER!

• You are not fighting off pentesters. You are fighting off actual adversaries.

• You are not fighting off auditors. You keep your organization working.

• You are not fighting off regulators. You are trying to keep yourself out of jail.

Page 68: "Cyber" security - all good, no need to worry?

Thank You! ¡gracias

Ian Amit Director of Services, IOActive

[email protected] Twitter: @iiamit