20
Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization Fernando Martinez Ph.D. CISSP CISM CISA

Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Hidden Pitfalls: Identify and Manage the Latent

Risk in Your Organization

Fernando Martinez Ph.D. CISSP CISM CISA

Page 2: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Defined: LATENT RISK

Risk that is present and capable of emerging or

developing but not visible, obvious or active

Why speak about it or focus on it?

Page 3: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

[Enter]

Page 4: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D
Page 5: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Collusion and Willful Neglect

“51% of employees said

they would go around any policy that restricted their use of their own devices or

use of cloud storage” Elizabeth Weise, USA Today, August 26th 2014, Money – Cybersecurity for Business, Pg. 3B. Citing data from 2014 Fortinet study.

Page 6: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Approach??

Page 7: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

IoT

Page 8: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Distributed Data

Page 9: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Cloud Storage

Page 10: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

What “Data Breach Fatigue” Could Mean for the Privacy

Profession

June 6, 2014

(https://privacyassociation.org/news/a/what-data-breach-fatigue-could-mean-for-the-privacy-profession/)

Page 11: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Data breach notification fatigue: Do consumers (eventually) tune out? Data breach notifications are flying en masse following the Epsilon Interactive breach, but are they doing customers any good? By George V. Hulme CSO | Apr 12, 2011 8:00 AM http://www.csoonline.com/article/2127999/data-protection/data-breach-notification-fatigue--do-consumers--eventually--tune-out-.html

Page 12: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

• Close to 50% - 110 Million – of all adults • In the last 12 months! • Conservative figure – several large

organizations are not “fully transparent” http://money.cnn.com/2014/05/28/technology/security/hack-data-breach/

Page 13: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

BYOD aka Consumerization

Page 14: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Social Engineering

Page 15: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Identity Management

Two Factor

Page 16: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Identity Management

Multi Factor

Page 17: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Latent Risk - Summarized

1. Internet of Things (IoT) 2. Distributed Data 3. Cloud Storage 4. Consumerization 5. Social Engineering 6. Challenge/Response for identity

management 7. Data breach fatigue

Page 18: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

There is no Silver Bullet

Page 19: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Abstraction

Page 20: Hidden Pitfalls: Identify and Manage the Latent Risk in Your … · 2014-06-06  · Hidden Pitfalls: Identify and Manage the Latent Risk in Your Organization . Fernando Martinez Ph.D

Fernando Martinez, PhD Senior Vice President and CIO

Parkland Health and Hospital System [email protected]