17
Dennis Birchard Principal Enterprise Security Architect

PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

Embed Size (px)

Citation preview

Page 1: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

Dennis Birchard – Principal Enterprise Security Architect

Page 2: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

THIS IS NOT FUD – THIS IS JUST ME

Fear, uncertainty and doubt (FUD) is a tactic used in sales,

marketing, public relations, politics and propaganda.

FUD is generally a strategic attempt to influence perception by

disseminating negative and dubious or false information.

PERCEIVED RISK

REALITY OF RISK

Page 3: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

WHAT IS THE FIRST WORD YOU SEE?

Page 4: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

How Do I Know When I’m Doing Enough?

Page 5: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

Page 6: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

OR

Page 7: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

Security Strategies

Page 8: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

Security ToolsPhishing Social Engineering Endpoint Security DNS Poisoning

DDOS WebApp Vuls Critical Vuls Identity and Access

Page 9: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

Good Security Hygiene

Page 10: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

1) Patch / Update – Firmware, Software, All

2) Limit Access – Admin vs Production & Non-Production

3) Monitor Admin Usage CLOSELY

4) Employee Recon

5) Policy Segmentation

6) Automation vs Manual Ad-Hoc

7) SIEM/Visualization

8) Documentation and Escalation Repositories

9) Escalation Training (Readiness - Red-Team Drills)

10) Evaluate / Optimize / Adherence

10 Easy Steps “Back to the Basics”

Page 11: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

PATCH PATCH PATCH and LIMIT ACCESS

Page 12: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

EMPLOYEE RECON and POLICY SEGMENTATION

VPN Concentrator wwwwww

ISP xcons

Public Internet

Relational Database

wwwwww

Users (good/bad)

DMZ

IPS/IDS

Remote Offices

LB

Name Servers

=

Page 13: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

AUTOMATE and VISUALIZE EVENT DATA

Page 14: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

DOCUMENTATION and ATTACK DRILLS

Page 15: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

TRAINING and ADHERENCE / OPTIMIZATION

Page 16: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM

Page 17: PA DGS 16 Presentation - Cybersecurity How Do I Know When I'm Doing Enough - Dennis Birchard

©2016 AKAMAI | FASTER FORWARDTM