42
It’s Not Sexy Being Over-Exposed Tim Burnett

Tim Burnett - It’s not sexy being over exposed

Embed Size (px)

Citation preview

Page 1: Tim Burnett - It’s not sexy being over exposed

It’s Not Sexy Being Over-Exposed

Tim Burnett

Page 2: Tim Burnett - It’s not sexy being over exposed

Tim BurnettCyber Security Architecture & Design Manager

Atos Big Data & Security

It’s Not Sexy Being Over-Exposed

www.linkedin.com/tpburnett

@tritim

Page 3: Tim Burnett - It’s not sexy being over exposed
Page 4: Tim Burnett - It’s not sexy being over exposed

UK Cybercrime Soars 20% in Two Years

Information Security Magazine, 25 Feb 2016

Hackers behind Ukraine power cuts,

says US reportBBC News, 26 Feb 2016

Cybercrime in the News

Baidu apps found to be 'leaking' personal

dataBBC News, 26 Feb 2016Cybercrime Looms As

Biggest ‘Disruptive Threat’ To Finance

MarketsForbes, 25 Feb 2016

Los Angeles hospital returns to faxes and paper charts after

cyberattackGuardian, 16 Feb 2016

Nissan suspends Leaf app after electric car

hackedTelegraph, 25 Feb 2016

UK businesses battling huge rise

in cybercrimeGuardian, 25 Feb 2016

Page 5: Tim Burnett - It’s not sexy being over exposed

Some stat’s…

98%of tested web

app’s are vulnerable to

attack

93%of DPA breaches

are caused by human error

144%increase in successful

cyber attacks on businesses

Source: ITGovernance.co.uk, June 2015

90%of large

organisations reported suffering a

security breach

Page 6: Tim Burnett - It’s not sexy being over exposed

61%of organisations say

data theft and cybercrime

are the greatest threatsto their reputation

70%of security execs

are concerned about cloud and mobile

security

16Mmobile devices are

now affected bymobile malware

A few more…

Source: NTT Com Security, Feb 2016

65%of businesses

expect to suffer an Information

Security Breach

75%of directors are not

involved in the review of cyber security risks

and yet…

Page 7: Tim Burnett - It’s not sexy being over exposed

Script Kiddie

Cyber Threat Landscape

Malicious Insider

Hacktivism

Organised Cybercrime

Cyber Terrorism State Sponsored

Page 8: Tim Burnett - It’s not sexy being over exposed

Office Hours?

Page 9: Tim Burnett - It’s not sexy being over exposed

…extremely large data sets that may be analysed computationally to reveal patterns,

trends, and associations, especially relating to human behaviour and interactions

…data sets with sizes beyond the ability of commonly used software tools to capture, curate, manage, and process data within a

tolerable elapsed time

…any voluminous amount of structured, semi-structured and unstructured data that has the

potential to be mined for information

BI / Analytics – “Big Data”Definition

:

Page 10: Tim Burnett - It’s not sexy being over exposed

Today’s corporate network

Page 11: Tim Burnett - It’s not sexy being over exposed

Today’s corporate network

Page 12: Tim Burnett - It’s not sexy being over exposed

What to do with all this data?

Image: Google

Page 13: Tim Burnett - It’s not sexy being over exposed

Privacy

Page 14: Tim Burnett - It’s not sexy being over exposed

Insight Systems• Billions of connected

“things”• Exabytes (1018 bytes) of

data• Prescriptive analysis• Autonomous systems

Determine the future• Artificial

intelligence?

Beyond Big Data?

Big Data •millions of customers•petabytes (1015 bytes) of data•predictive analytics

Predict the future• based on what we

know now

Page 15: Tim Burnett - It’s not sexy being over exposed

Automated trading…

Page 16: Tim Burnett - It’s not sexy being over exposed

Haven’t we seen this before,

somewhere?

Page 17: Tim Burnett - It’s not sexy being over exposed

Cloud

“Somebody else’s computer”– Graham Cluley, 2013

Page 18: Tim Burnett - It’s not sexy being over exposed

Cloud

Page 19: Tim Burnett - It’s not sexy being over exposed

Mobile businessMobile workforce

Mobile

Page 20: Tim Burnett - It’s not sexy being over exposed

Easy to change cloud providers Data cleanse?

Mobile business

Page 21: Tim Burnett - It’s not sexy being over exposed

Mobile users

Page 22: Tim Burnett - It’s not sexy being over exposed

Mobile users

“FREE”

Page 23: Tim Burnett - It’s not sexy being over exposed

Is it a tablet or a ‘phone?

Source: bbc.co.uk/news, 22 Feb 2016

…or is it a PC?

Page 24: Tim Burnett - It’s not sexy being over exposed

Digital is much more than just technology and software.

For any organization, becoming truly digital requires a different mindset and increased flexibility.

It requires a redefinition of corporate structures, bodies and roles and use of new technologies to make innovation happen in the 4 core domains.

Customer Experience

Trust & Compliance

Operational Excellence

Business Reinvention

Digital Transformation

Every new aspect of ‘connectivity’ or

‘integration’ widens the Attack Surface

Page 25: Tim Burnett - It’s not sexy being over exposed

Challenges

Your data

Page 26: Tim Burnett - It’s not sexy being over exposed

Challenges

Your data Your Customers’ data

Page 27: Tim Burnett - It’s not sexy being over exposed

Infrastructure & Data Centre

Page 28: Tim Burnett - It’s not sexy being over exposed

“Re-perimeterisation”

Page 29: Tim Burnett - It’s not sexy being over exposed

Enterprise Resource Planning / Customer Relationship Management

Page 30: Tim Burnett - It’s not sexy being over exposed

Supply Chain Vulnerabilities

Page 31: Tim Burnett - It’s not sexy being over exposed

Industry Specific Applications

Page 32: Tim Burnett - It’s not sexy being over exposed

Networking / Voice / Data Communications

Page 33: Tim Burnett - It’s not sexy being over exposed

CryptoLocker

Page 34: Tim Burnett - It’s not sexy being over exposed

CryptoLocker

Page 35: Tim Burnett - It’s not sexy being over exposed

Solutions?

Page 36: Tim Burnett - It’s not sexy being over exposed

“First, I do not think there is any silver bullet to solving the technology side of the security equation.”

John W. Thompson

Page 37: Tim Burnett - It’s not sexy being over exposed

Risk

Page 38: Tim Burnett - It’s not sexy being over exposed

Questions to ask…

Page 39: Tim Burnett - It’s not sexy being over exposed

Do the basics well

Understand the RISK know where your “crown jewels” really are

Use up-to-date software; patch regularly Know where your perimeters are Educate users Secure the Information

Page 40: Tim Burnett - It’s not sexy being over exposed

Emerging Approaches to Security

Page 41: Tim Burnett - It’s not sexy being over exposed

Evolution of Security

Today Tomorrow Perimeter is now porous Simple monitoring is insufficient Can’t afford to watch business burn

Protect the data Faster, broader monitoring & analysis Threat intelligence Cyber skills and automation

Page 42: Tim Burnett - It’s not sexy being over exposed

www.linkedin.com/tpburnett @tritim

Do the Basics

Understand the Risk

Protect your Data