Data Breaches and Cyber Risks
|
|
|
- Preston Foster
- 10 years ago
- Views:
Transcription
1 Data Breaches and Cyber Risks MD/DC Credit Union Association 2015 Volunteer Leadership Conference Presented by: Ken Otsuka Business Protection Risk Management CUNA Mutual Group CUNA Mutual Group Proprietary Reproduction, Adaptation or Distribution Prohibited 2014 CUNA Mutual Group, All Rights Reserved.
2 Data Breaches How do they Happen? Network hackers and malware Employee negligence / theft Lost / stolen laptops, backup tapes / disks and other data-bearing mobile devices Vendor leaks/mistakes 2
3 Data Breaches Financial risk Compliance / Legal risk Reputation risk A data breach can result in more than lost data. It can damage the credit union s reputation, shake member trust, and cost tens of thousands to repair. 3
4 Agenda Board s role in data security Data breach studies by the Ponemon Institute, Verizon, Mandiant and PricewaterhouseCoopers (PwC) Data breach insurance claims study NetDiligence Best practices for securing members confidential data Mobile devices Assessment tools National Institute of Standards and Technology s (NIST) Cybersecurity Framework Federal Financial Institutions Examination Council s (FFIEC) Cybersecurity Framework Tool 4
5 Boards Have a Duty to Protect Member Data NCUA Rules & Regulations 748 and its Appendices A and B spell out the credit union s responsibilities for protecting sensitive member data Appendix A implements the Gramm-Leach-Bliley (GLB) Act s safeguards rule and requires credit unions to develop a written information security program (ISP) Ensure the security and confidentiality of member information; Protect against anticipated threats to the security and integrity of such information; and Protect against unauthorized access to, or use of, such information that could result in substantial harm to members The board is responsible for overseeing the development, implementation, maintenance and approving the ISP ISP must contain an incident response plan (IRP) Addressed in Appendix B Board is responsible for the IRP Management must report to the board at least annually on the overall status of the written information security program 5
6 Ponemon Institute Is Your Company Ready for a Big Data Breach? Cybersecurity Preparedness: The Good, The Bad and The Ugly The Good 73% of the organizations have an incident response plan in place compared to 61% in last year s study The Bad 78% of the organizations say they either don t review and update their incident response plan or have no set timeframe for doing so Only 30% of the respondents say their organizations are effective or very effective in developing and executing their incident response plan 56% of the organizations do not perform a risk assessment on their information systems to identify vulnerabilities Only 54% of the organizations have training and security awareness programs Only 34% of the organizations train customer service representatives on how to respond to questions in the event a breach occurs Source: Ponemon Institute s 2014 study, Is Your Company Ready for a Big Data Breach? 6
7 Ponemon Institute Is Your Company Ready for a Big Data Breach? The Ugly 43% of the organizations experienced a data breach involving a theft of more than 1,000 records 60% of the organizations experienced more than one data breach during the last two years Only 41% provide for either continuous monitoring (20%) or daily monitoring (21%) of their information systems for suspicious/anomalous traffic 44% say they either never monitor their information systems (28%) or are unsure if monitoring takes place (16%) 7
8 Verizon 2015 Data Breach Investigations Report External threats far exceed internal threats and partner threats. Source: Verizon 2015 Data Breach Investigations Report 8
9 Verizon 2015 Data Breach Investigations Report Malware distributed in spear phishing attacks In a controlled study 150,000 s were sent 50% of the recipients opened the and clicked on the link within the first hour Source: Verizon 2015 Data Breach Investigations Report 9
10 Mandiant s 2015 M-Trends Report Early Detection is Critical Source: Mandiant 2015 M-Trends Report 10
11 PwC s Global State of Information Security Survey 2015 Total number of security incidents reported by respondents climbed to 42.8 million. The equivalent to 117,339 incoming attacks per day Security incident: The National Institute of Standards and Technology (NIST) defines security incident as a violation of computer security policies, acceptable use policies, or standard practices. These include, but are not limited to: Attempts (failed or successful) to gain unauthorized access to a system or its data Unwanted disruption or denial of service Unauthorized use of a system for the processing or storage of data Unauthorized changes to system hardware or software million million million Source: PwC Global State of Information Security Survey
12 Malware s Role in Data Breaches Data breaches are frequently the result of credential-stealing malware Distributed in spear phishing attacks Tool of choice in Advance Persistent Threat (APT) attacks What s an Advanced Persistent Threat (APT) attack? Malware planted on network via spear phishing attack Establishes communication with command & control server Moves slowly about the network searching for sensitive data to steal and the credentials necessary to access that data Sensitive data is extracted using encryption and other techniques to disguise it Intelligence Gathering Point of Entry Establish Communication with C&C Lateral Movement through Network Data Discovery Data Exfiltration 12
13 NetDiligence 2015 Cyber Liability & Data Breach Insurance Claims Per breach costs Average payout: $673,767 Median payout: $76,984 Per record costs Average cost per record: $ Median cost per record: $13.00 Average records lost: 3.16 million Median records lost: 2,300 Crisis service costs Average cost of crisis services: $499,710 Median cost of crisis services: $60,563 Crisis services include the cost of forensics, legal counsel guidance, notification and credit monitoring Legal costs Average cost of legal defense: $434,354 Median cost of legal defense: $73,600 Average cost of settlement: $880,839 Median cost of settlement: $50,000 Source: NetDiligence 2015 Cyber Liability & Data Breach Claims Study 13
14 Why the Problem? Intrusion detection and network monitoring is weak Malware Lack of encryption Websites are porous and need constant care Hardening and patching Cyber thieves take advantage of human error Unchanged default settings Failing to install patches Failing to protect laptops Improper disposal of paper records Weak passwords 14
15 Best Practices Protect data wherever it is located At rest In motion In use Encryption Data residing on the network (servers, workstation hard drives and laptops) Data residing on mobile devices Backup tapes/disks Data transmitted over the Internet and in s Endpoint security Protects the endpoints (devices) connected to credit union network Includes typical protections such as a firewall and antivirus/antimalware Block access to personal accounts Spam and web filters Intrusion detection system (IDS)/intrusion prevention system (IPS) Install operating system patches when made available 15
16 Best Practices Protect data wherever it is located At rest In motion In use Vulnerability assessments Penetration testing Monitor system logs Disable / lockdown workstation USB ports and CD Rom drives Helps prevent insider theft of confidential member data Data loss prevention (DLP) solution Identifies, monitors, and protects data at rest, in motion, and in use DLP tools allow credit unions to see which databases, file servers, desktops and laptops hold sensitive data Identifies when someone is transmitting data via or downloading to external storage devices Third-party reviews of network security Secure paper records 16
17 Best Practices Protect data wherever it is located At rest In motion In use Accessing network/systems remotely Telecommuters working from home Third-party vendors Remote Access Best Practices Prohibit remote employees from using home computers to access network Establish a virtual private network (VPN) A VPN is a network that uses the Internet to provide remote employees with secure access to the credit union s network Prohibit employees from using unsecure wireless networks (public Wi-Fi) Require multifactor authentication not just usernames and passwords One-time-password tokens Plug-in tokens 17
18 Mobile Devices: Tablets / Smartphones Credit union issued versus employee use of personal devices (BYOD) Both should be secured Secure the business side of the device (sandboxing) Good Technology MaaS360 Adopt acceptable use policy Mobile Devices Used for Business Purposes Antivirus software Password protect the device/time-out feature to lock the device Remote wipe capability Prohibit employees from storing confidential member data to the device If it is necessary to store such data on the device, the data should be encrypted Encrypt confidential member data transmitted in s Does your credit union issue tablets or laptops to directors to receive board meeting packets? 18
19 Data Breaches Employee Negligence Credit union discovered malware on least 24 workstation pc s Malware captures screen shots Social Security numbers, account information and transaction records for 115,000 accountholders (members) may have been compromised Credit union employee accidentally published a file on the credit union s public-facing website File contained member names, addresses, Social Security numbers, account numbers and account passwords Credit union employee accidently ed a spreadsheet to a member Spreadsheet contained member names and account numbers Credit union employee s laptop stolen from vehicle Contained unencrypted sensitive data (names, addresses, SSN s and account numbers) on 45,000 members Source: CUMIS Insurance Society, Inc.. 19
20 Data Breaches Vendor Negligence Credit union uses third-party vendor to mail monthly account statements Members received their correct statements plus a portion of statements belonging to other members Credit union downloaded confidential member data to a thumb drive for their outside auditor - Auditor lost the thumb drive in a public park while watching son s football game - 14,500 members impacted Source: CUMIS Insurance Society, Inc.. 20
21 Security Awareness Training Must be addressed in the credit union s information security program All employees should receive training on at least an annual basis The goal is to change employee behavior to reinforce good data security practices 21
22 Malware Beyond Theft of Data Carbanak Malware Targeted 100 financial institutions in 30 countries, including U.S. Losses per institution ranged from $2.5M to $10M Funds stolen from institutions not from depositor accounts Distributed via phishing attacks Sought out employees with administrative rights Performed reconnaissance (video) to learn details of the 3 rd party EFT systems used Logged into 3 rd party EFT systems to transfer funds to other institutions Source: Kaspersky Lab, The Great Bank Robbery: The Carbanak APT 22
23 The National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity (Cybersecurity Framework) 23
24 NIST s Cybersecurity Framework Background President Obama issued Executive Order (Improving Critical Infrastructure Cybersecurity) in 2013 Directed the National Institute of Standards and Technology (NIST) to spearhead the development of a framework to reduce cyber risks to critical infrastructure NIST published the Framework for Improving Critical Infrastructure Cybersecurity (Cybersecurity Framework) in 2014 Critical Infrastructure is defined in Presidential Policy Directive 21 (Critical Infrastructure Security and Resilience) to include the following sectors: Chemical Commercial facilities Communications Critical manufacturing Dams Defense industrial base Emergency services Energy Industry Sectors Financial services Food and agriculture Government facilities Healthcare and public health Information technology Nuclear reactors, materials and waste Transportation systems Water and wastewater system 24
25 NIST s Cybersecurity Framework What is it? Collection of best practices, procedures and guidelines developed in partnership by the government and private sector to manage cyber risk Relies on industry standards and best practices (e.g., ISO and COBIT) Intended to be used by organizations of all sizes to evaluate, maintain and improve security over information systems Not a one-size-fits-all approach Enables credit unions to understand how their cybersecurity risk management processes stack up against the ideal standards addressed in the Cybersecurity Framework Promotes participation in information sharing groups, such as FS-ISAC Participation is voluntary 25
26 Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool 26
27 Cybersecurity Assessment Tool Launched by the FFIEC on June 30, Assists credit unions in identifying their risks and determining their cybersecurity preparedness Developed specifically for financial institutions based on the results of the cybersecurity assessments conducted by FFIEC member agencies piloted in 2014 A better option for credit unions than NIST s Cybersecurity Framework Designed to provide a measurable and repeatable process to assess a credit union s level of cybersecurity risk and preparedness CUNA Mutual Group highly recommends using the Cybersecurity Assessment Tool 27
28 Cybersecurity Assessment Tool Completing the Cybersecurity Assessment Tool is a three-step process Step 1: Determine Inherent Risk Profile Step 2: Determine Cybersecurity Maturity Level Step 3: Analyze Results 28
29 Step 1: Inherent Risk Profile The Inherent Risk Profile (IRP) identifies a credit union s inherent risk before implementing controls IRP identifies the amount of risk posed to a credit union based on the types of products, services and activities; and the volume and complexity of the credit union s operations in five categories: Technologies and connections Delivery channels Online/mobile products/services Organizational characteristics External threats Includes five risk levels Least Inherent Risk Minimal Inherent Risk Moderate Inherent Risk Significant Inherent Risk Most Inherent Risk 29
30 Step 2: Cybersecurity Maturity Determine the credit union s Cybersecurity Maturity level across five domains Cyber Risk Management and Oversight Threat Intelligence and Collaboration Cybersecurity Controls External Dependency Management Cyber Incident Management and Resilience Five levels of Cybersecurity Maturity Baseline (lowest level) Evolving Intermediate Advanced Innovative (highest level) Source: FFIEC 30
31 Step 2: Cybersecurity Maturity Components and Declarative Statements Within each component are declarative statements Declarative statements are the minimum regulatory guidelines that must be attained and sustained for that level of maturity Credit unions must satisfy all declarative statements for each maturity level, and previous levels, to achieve that domain s maturity level Indicate whether credit union satisfies each declarative statement Source: FFIEC 31
32 Step 2: Cybersecurity Maturity (Baseline) Some credit unions may have trouble qualifying for the Baseline Cybersecurity Maturity Level The controls needed to achieve the Baseline maturity level are consistent with the minimum guidelines contained in the FFIEC s IT Examination Handbook Credit unions must meet the minimum guidelines to be placed in the Baseline maturity level The effects are cumulative in that all declarative statements in each maturity level, and previous maturity levels, must be attained and sustained to achieve that domain s maturity level. 32
33 Step 3: Analyzing Results As inherent risk rises, so too should maturity levels If a credit union s maturity levels are not aligned with the inherent risk profile: Management should consider reducing inherent risk, or Develop a strategy to improve the maturity levels by adopting controls needed to meet the declarative statements required to achieve a higher maturity level Over-investment in cybersecurity preparedness Be in the blue Danger zone policies, procedures and controls are not sufficient given the Inherent Risk Profile Source: FFIEC 33
34 Additional Thoughts and Comments Piggybacking on FFIEC joint statements: Cyber Attacks Compromising Credentials and Destructive Malware (March 30, 2015) Cybersecurity Assessment General Observations and Cybersecurity Threat and Vulnerability Monitoring and Sharing Statement (November 3, 2014) Domain 3, Cybersecurity Controls, could be the most important domain and the most difficult for many credit unions to achieve even the Baseline maturity level Domain 3 is the largest part of the Assessment Examples (declarative statements for Baseline maturity level): Mobile devices (e.g., laptops, tablets, and removable media) are encrypted if used to store confidential data. (*N/A if mobile devices are not used.) (FFIEC Information Security Booklet, page 51) Remote access to critical systems by employees, contractors, and third parties uses encrypted connections and multifactor authentication. (FFIEC Information Security Booklet, page 45) Domain 2, Threat Intelligence and Collaboration, is a short but major part of the Assessment Organizations participating in FS-ISAC are in a much better position to defend against cyber attacks 34
35 CUNA Mutual Group s Collaboration with FS-ISAC Credit unions that have or purchase a cyber liability insurance policy through CUNA Mutual Group may be eligible for a discount on the basic membership (new memberships and renewals) Visit CUNA Mutual Group s dedicated web page to learn more 35
36 Session Summary Information theft is one of today s most common forms of fraud Given the financial, legal, and reputational risks of a data breach -- failing to prepare can be disaster Take proactive steps to prevent incidents from occurring in the first place Protection Resource 36
37 Questions & Answers Ken Otsuka, CPA Senior Consultant - Risk Management CUNA Mutual Group [email protected] 37
38 Disclaimer This presentation was created by the CUNA Mutual Group based on our experience in the credit union and insurance market. It is intended to be used only as a guide, not as legal advice. Any examples provided have been simplified to give you an overview of the importance of selecting appropriate coverage limits, insuring-to-value and implementing loss prevention techniques. No coverage is provided by this publication, nor does it replace any provisions of any insurance policy or bond. Credit Union Loss Scenarios Case Studies The credit union loss scenario claim study examples do not make any representations that coverage does or does not exist for any particular claim or loss, or type of claim or loss, under any policy. Whether or not coverage exists for any particular claim or loss under any policy depends on the facts and circumstances involved in the claim or loss and all applicable policy language. CUNA Mutual Group is the marketing name for CUNA Mutual Holding Company, a mutual insurance holding company, its subsidiaries and affiliates. Insurance products offered to financial institutions and their affiliates are underwritten by CUMIS Insurance Society, Inc. or CUMIS Specialty Insurance Company, members of the CUNA Mutual Group. Some coverages may not be available in all states. If a coverage is not available from one of our member companies, CUNA Mutual Insurance Agency, Inc., our insurance producer affiliate, may assist us in placing coverage with other insurance carriers in order to serve our customers needs. For example, the Workers Compensation Policy is underwritten by non-affiliated admitted carriers. CUMIS Specialty Insurance Company, our excess and surplus lines carrier, underwrites coverages that are not available in the admitted market. Data breach services are offered by Kroll, a member of the Altegrity family of businesses. Cyber liability may be underwritten by Beazley Insurance Group. This summary is not a contract and no coverage is provided by this publication, nor does it replace any provisions of any insurance policy or bond. Please read the actual policy for specific coverage, terms, conditions, and exclusions. CUP CUNA Mutual Group, 2015 All Rights Reserved 38
39 39
Data Breaches and Cyber Risks
Data Breaches and Cyber Risks Carolinas Credit Union League Leadership Conference Presented by: Ken Otsuka Business Protection Risk Management CUNA Mutual Group CUNA Mutual Group Proprietary Reproduction,
Ed McMurray, CISA, CISSP, CTGA CoNetrix
Ed McMurray, CISA, CISSP, CTGA CoNetrix AGENDA Introduction Cybersecurity Recent News Regulatory Statements NIST Cybersecurity Framework FFIEC Cybersecurity Assessment Questions Information Security Stats
Click to edit Master title style
EVOLUTION OF CYBERSECURITY Click to edit Master title style IDENTIFYING BEST PRACTICES PHILIP DIEKHOFF, IT RISK SERVICES TECHNOLOGY THE DARK SIDE AGENDA Defining cybersecurity Assessing your cybersecurity
Data Breach Response Planning: Laying the Right Foundation
Data Breach Response Planning: Laying the Right Foundation September 16, 2015 Presented by Paige M. Boshell and Amy S. Leopard babc.com ALABAMA I DISTRICT OF COLUMBIA I FLORIDA I MISSISSIPPI I NORTH CAROLINA
Cybersecurity. Are you prepared?
Cybersecurity Are you prepared? First Cash, then your customer, now YOU! What is Cybersecurity? The body of technologies, processes, practices designed to protect networks, computers, programs, and data
FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors
Overview for Chief Executive Officers and Boards of Directors In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed
Internet threats: steps to security for your small business
Internet threats: 7 steps to security for your small business Proactive solutions for small businesses A restaurant offers free WiFi to its patrons. The controller of an accounting firm receives a confidential
Cybersecurity Workshop
Cybersecurity Workshop February 10, 2015 E. Andrew Keeney, Esq. Kaufman & Canoles, P.C. E. Andrew Keeney, Esq. Kaufman & Canoles, P.C. 150 West Main Street, Suite 2100 Norfolk, VA 23510 (757) 624-3153
2 0 1 4 F G F O A A N N U A L C O N F E R E N C E
I T G OV E R NANCE 2 0 1 4 F G F O A A N N U A L C O N F E R E N C E RAJ PATEL Plante Moran 248.223.3428 [email protected] This presentation will discuss current threats faced by public institutions,
Defending Against Data Beaches: Internal Controls for Cybersecurity
Defending Against Data Beaches: Internal Controls for Cybersecurity Presented by: Michael Walter, Managing Director and Chris Manning, Associate Director Protiviti Atlanta Office Agenda Defining Cybersecurity
By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015
Community Bank Auditors Group Cybersecurity What you need to do now June 9, 2015 By: Gerald Gagne MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C. Cybersecurity
Belmont Savings Bank. Are there Hackers at the gate? 2013 Wolf & Company, P.C.
Belmont Savings Bank Are there Hackers at the gate? 2013 Wolf & Company, P.C. MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2013 Wolf & Company, P.C. About Wolf & Company, P.C.
ICBA Summary of FFIEC Cybersecurity Assessment Tool
ICBA Summary of FFIEC Cybersecurity Assessment Tool July 2015 Contact: Jeremy Dalpiaz Assistant Vice President Cyber Security and Data Security Policy [email protected] www.icba.org ICBA Summary
10 Smart Ideas for. Keeping Data Safe. From Hackers
0100101001001010010001010010101001010101001000000100101001010101010010101010010100 0100101001001010010001010010101001010101001000000100101001010101010010101010010100000 0100101001001010010001010010101001010101001000000100101001010101010010101010010100000
Online Banking Risks efraud: Hands off my Account!
Online Banking Risks efraud: Hands off my Account! 1 Assault on Authentication Online Banking Fraud Significant increase in account compromises via online banking systems Business accounts are primary
Ten Questions Your Board Should be asking about Cyber Security. Eric M. Wright, Shareholder
Ten Questions Your Board Should be asking about Cyber Security Eric M. Wright, Shareholder Eric Wright, CPA, CITP Started my career with Schneider Downs in 1983. Responsible for all IT audit and system
FFIEC Cybersecurity Assessment Tool
Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,
Logging In: Auditing Cybersecurity in an Unsecure World
About This Course Logging In: Auditing Cybersecurity in an Unsecure World Course Description $5.4 million that s the average cost of a data breach to a U.S.-based company. It s no surprise, then, that
Cyber Self Assessment
Cyber Self Assessment According to Protecting Personal Information A Guide for Business 1 a sound data security plan is built on five key principles: 1. Take stock. Know what personal information you have
SECURING YOUR SMALL BUSINESS. Principles of information security and risk management
SECURING YOUR SMALL BUSINESS Principles of information security and risk management The challenge Information is one of the most valuable assets of any organization public or private, large or small and
Cybersecurity: What CFO s Need to Know
Cybersecurity: What CFO s Need to Know William J. Nowik, CISA, CISSP, QSA PCIP MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2014 Wolf & Company, P.C. Today s Agenda Introduction
Cyber Security. John Leek Chief Strategist
Cyber Security John Leek Chief Strategist AGENDA The Changing Business Landscape Acknowledge cybersecurity as an enterprise-wide risk management issue not just an IT issue How to develop a cybersecurity
Information Security and Risk Management
Information Security and Risk Management COSO and COBIT Standards and Requirements Page 1 Topics Information Security Industry Standards and COBIT Framework Relation to COSO Internal Control Risk Management
Presented by: Mike Morris and Jim Rumph
Presented by: Mike Morris and Jim Rumph Introduction MICHAEL MORRIS, CISA Systems Partner JIM RUMPH, CISA Systems Manager Objectives To understand how layered security assists in securing your network
Supplier Information Security Addendum for GE Restricted Data
Supplier Information Security Addendum for GE Restricted Data This Supplier Information Security Addendum lists the security controls that GE Suppliers are required to adopt when accessing, processing,
ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES
ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES Leonard Levy PricewaterhouseCoopers LLP Session ID: SEC-W03 Session Classification: Intermediate Agenda The opportunity Assuming
Online Account Takeover. Roger Nettie
Online Account Takeover Roger Nettie CUNA Mutual Group Proprietary Reproduction, Adaptation or Distribution Prohibited CUNA Mutual Group 2013 Session Outline Types of attacks Movement of funds Consumer
Small Firm Focus: A Practical Approach to Cybersecurity Friday, May 29 9:00 a.m. 10:15 a.m.
Small Firm Focus: A Practical Approach to Cybersecurity Friday, May 29 9:00 a.m. 10:15 a.m. Topics: Explain why it is important for firms of all sizes to address cybersecurity risk. Demonstrate awareness
Into the cybersecurity breach
Into the cybersecurity breach Tim Sanouvong State Sector Cyber Risk Services Deloitte & Touche LLP April 3, 2015 Agenda Setting the stage Cyber risks in state governments Cyber attack vectors Preparing
Network Security & Privacy Landscape
Network Security & Privacy Landscape Presented By: Greg Garijanian Senior Underwriter Professional Liability 1 Agenda Network Security Overview -Latest Threats - Exposure Trends - Regulations Case Studies
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT S OF PUBLIC WELFARE, INSURANCE AND AGING INFORMATION TECHNOLOGY STANDARD Name Of Standard: Mobile Device Standard Domain: Security Date Issued: 09/07/2012 Date Revised:
Cybersecurity Awareness
Awareness Objectives Discuss the Evolution of Data Security Define Review Threat Environment Discuss Information Security Program Enhancements for Cyber Risk Threat Intelligence Third-Party Management
TODAY S AGENDA. Trends/Victimology. Incident Response. Remediation. Disclosures
TODAY S AGENDA Trends/Victimology Incident Response Remediation Disclosures Trends/Victimology ADVERSARY CLASSIFICATIONS SOCIAL ENGINEERING DATA SOURCES COVERT INDICATORS - METADATA METADATA data providing
What Data? I m A Trucking Company!
What Data? I m A Trucking Company! Presented by: Marc C. Tucker 434 Fayetteville Street, Suite 2800 Raleigh, NC, 27601 919.755.8713 [email protected] Presented by: Rob D. Moseley, Jr. 2 West
How To Protect Yourself From A Hacker Attack
Cybersecurity Demystified: Information Technology Security Trends Joe Oleksak, Plante Moran Agenda Data Security Trends Example Attacks Industry Examples An Answer 1 Who Are The Victims? Targets - victims
Presented by Evan Sylvester, CISSP
Presented by Evan Sylvester, CISSP Who Am I? Evan Sylvester FAST Information Security Officer MBA, Texas State University BBA in Management Information Systems at the University of Texas Certified Information
Information Security It s Everyone s Responsibility
Information Security It s Everyone s Responsibility Developed By The University of Texas at Dallas (ISO) Purpose of Training As an employee, you are often the first line of defense protecting valuable
ITAR Compliance Best Practices Guide
ITAR Compliance Best Practices Guide 1 Table of Contents Executive Summary & Overview 3 Data Security Best Practices 4 About Aurora 10 2 Executive Summary & Overview: International Traffic in Arms Regulations
CYBERSECURITY HOT TOPICS
1 CYBERSECURITY HOT TOPICS Secure Banking Solutions 2 Presenter Chad Knutson VP SBS Institute Senior Information Security Consultant Masters in Information Assurance CISSP, CISA, CRISC www.protectmybank.com
Preparing for a Cyber Attack PROTECT YOUR PEOPLE AND INFORMATION WITH SYMANTEC SECURITY SOLUTIONS
Preparing for a Cyber Attack PROTECT YOUR PEOPLE AND INFORMATION WITH SYMANTEC SECURITY SOLUTIONS CONTENTS PAGE RECONNAISSANCE STAGE 4 INCURSION STAGE 5 DISCOVERY STAGE 6 CAPTURE STAGE 7 EXFILTRATION STAGE
Data Security Incident Response Plan. [Insert Organization Name]
Data Security Incident Response Plan Dated: [Month] & [Year] [Insert Organization Name] 1 Introduction Purpose This data security incident response plan provides the framework to respond to a security
What Directors need to know about Cybersecurity?
What Directors need to know about Cybersecurity? W HAT I S C YBERSECURITY? PRESENTED BY: UTAH BANKERS ASSOCIATION AND JON WALDMAN PARTNER, SENIOR IS CONSULTANT - SBS 1 Contact Information Jon Waldman Partner,
Data Breach and Senior Living Communities May 29, 2015
Data Breach and Senior Living Communities May 29, 2015 Todays Objectives: 1. Discuss Current Data Breach Trends & Issues 2. Understanding Why The Senior Living Industry May Be A Target 3. Data Breach Costs
Security Management. Keeping the IT Security Administrator Busy
Security Management Keeping the IT Security Administrator Busy Dr. Jane LeClair Chief Operating Officer National Cybersecurity Institute, Excelsior College James L. Antonakos SUNY Distinguished Teaching
Cyber Security, Fraud and Corporate Account Takeovers LBA Bank Counsel Conference December 2014
Cyber Security, Fraud and Corporate Account Takeovers LBA Bank Counsel Conference December 2014 Lisa D. Traina, CPA, CITP, CGMA Lisa Traina utilizes her 30+ years of experience as a CPA, CITP and CGMA
Advanced Threats: The New World Order
Advanced Threats: The New World Order Gary Lau Technology Consulting Manager Greater China [email protected] 1 Agenda Change of Threat Landscape and Business Impact Case Sharing Korean Incidents EMC CIRC
Cybersecurity Issues for Community Banks
Eastern Massachusetts Compliance Network Cybersecurity Issues for Community Banks Copyright 2014 by K&L Gates LLP. All rights reserved. Sean P. Mahoney [email protected] K&L Gates LLP State Street
Honeywell Industrial Cyber Security Overview and Managed Industrial Cyber Security Services Honeywell Process Solutions (HPS) June 4, 2014
Industrial Cyber Security Overview and Managed Industrial Cyber Security Services Process Solutions (HPS) June 4, Industrial Cyber Security Industrial Cyber Security is the leading provider of cyber security
IBM Security Strategy
IBM Security Strategy Intelligence, Integration and Expertise Kate Scarcella CISSP Security Tiger Team Executive M.S. Information Security IBM Security Systems IBM Security: Delivering intelligence, integration
CYBER SECURITY SPECIALREPORT
CYBER SECURITY SPECIALREPORT 32 The RMA Journal February 2015 Copyright 2015 by RMA INSURANCE IS AN IMPORTANT TOOL IN CYBER RISK MITIGATION Shutterstock, Inc. The time to prepare for a potential cyber
Privacy Rights Clearing House
10/13/15 Cybersecurity in Education What you face as educational organizations How to Identify, Monitor and Protect Presented by Jamie Gershon Sr. Vice President Education Practice Group 1 Privacy Rights
IT Security Risks & Trends
IT Security Risks & Trends Key Threats to All Businesses 1 1 What do the following have in common? Catholic church parish Hospice Collection agency Main Street newspaper stand Electrical contractor Health
Perspectives on Cybersecurity in Healthcare June 2015
SPONSORED BY Perspectives on Cybersecurity in Healthcare June 2015 Workgroup for Electronic Data Interchange 1984 Isaac Newton Square, Suite 304, Reston, VA. 20190 T: 202-618-8792/F: 202-684-7794 Copyright
Information Security It s Everyone s Responsibility
Information Security It s Everyone s Responsibility The University of Texas at Dallas Information Security Office (ISO) Purpose of Training Information generated, used, and/or owned by UTD has value. Because
Cybersecurity Awareness. Part 1
Part 1 Objectives Discuss the Evolution of Data Security Define and Discuss Cybersecurity Review Threat Environment Part 1 Discuss Information Security Programs s Enhancements for Cybersecurity Risks Threat
AB 1149 Compliance: Data Security Best Practices
AB 1149 Compliance: Data Security Best Practices 1 Table of Contents Executive Summary & Overview 3 Data Security Best Practices 4 About Aurora 10 2 Executive Summary & Overview: AB 1149 is a new California
AIRDEFENSE SOLUTIONS PROTECT YOUR WIRELESS NETWORK AND YOUR CRITICAL DATA SECURITY AND COMPLIANCE
AIRDEFENSE SOLUTIONS PROTECT YOUR WIRELESS NETWORK AND YOUR CRITICAL DATA SECURITY AND COMPLIANCE THE CHALLENGE: SECURE THE OPEN AIR Wirelesss communication lets you take your business wherever your customers,
IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including:
IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including: 1. IT Cost Containment 84 topics 2. Cloud Computing Readiness 225
Practice Good Enterprise Security Management. Presented by Laurence CHAN, MTR Corporation Limited
Practice Good Enterprise Security Management Presented by Laurence CHAN, MTR Corporation Limited About Me Manager Information Security o o o o Policy formulation and governance Incident response Incident
Information Security Awareness Training Gramm-Leach-Bliley Act (GLB Act)
Information Security Awareness Training Gramm-Leach-Bliley Act (GLB Act) The GLB Act training packet is part of the Information Security Awareness Training that must be completed by employees. Please visit
Cybersecurity The role of Internal Audit
Cybersecurity The role of Internal Audit Cyber risk High on the agenda Audit committees and board members are seeing cybersecurity as a top risk, underscored by recent headlines and increased government
Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information.
Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information. Mobile Devices: Risks to Health Information Risks vary based on the mobile device and its use. Some risks include:
MIT s Information Security Program for Protecting Personal Information Requiring Notification. (Revision date: 2/26/10)
MIT s Information Security Program for Protecting Personal Information Requiring Notification (Revision date: 2/26/10) Table of Contents 1. Program Summary... 3 2. Definitions... 4 2.1 Identity Theft...
The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance
Date: 07/19/2011 The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance PCI and HIPAA Compliance Defined Understand
Information Technology Security Review April 16, 2012
Information Technology Security Review April 16, 2012 The Office of the City Auditor conducted this project in accordance with the International Standards for the Professional Practice of Internal Auditing
Jort Kollerie SonicWALL
Jort Kollerie Cloud 85% of businesses said their organizations will use cloud tools moderately to extensively in the next 3 years. 68% of spend in private cloud solutions. - Bain and Dell 3 Confidential
CNA NetProtect Essential SM. 1. Do you implement virus controls and filtering on all systems? Background:
1. Do you implement virus controls and filtering on all systems? Anti-Virus anti-virus software packages look for patterns in files or memory that indicate the possible presence of a known virus. Anti-virus
Top 10 Baseline Cybersecurity Controls Banks Aren't Doing
Top 10 Baseline Cybersecurity Controls Banks Aren't Doing SECURE BANKING SOLUTIONS 1 Contact Information Chad Knutson President, SBS Institute Senior Information Security Consultant Masters in Information
Data breach, cyber and privacy risks. Brian Wright Lloyd Wright Consultants Ltd
Data breach, cyber and privacy risks Brian Wright Lloyd Wright Consultants Ltd Contents Data definitions and facts Understanding how a breach occurs How insurance can help to manage potential exposures
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 123. Cybersecurity: A Growing Concern for Small Businesses
RLI PROFESSIONAL SERVICES GROUP PROFESSIONAL LEARNING EVENT PSGLE 123 Cybersecurity: A Growing Concern for Small Businesses Copyright Materials This presentation is protected by US and International Copyright
INFORMATION SECURITY PROGRAM
Approved 1/30/15 by Dr. MaryLou Apple, President MSCC Policy No. 1:08:00:02 MSCC Gramm-Leach-Bliley INFORMATION SECURITY PROGRAM January, 2015 Version 1 Table of Contents A. Introduction Page 1 B. Security
Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information.
Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information. Mobile Devices: Risks to to Health Mobile Information Devices: Risks to Health Information Risks vary based on the
AIRDEFENSE SOLUTIONS PROTECT YOUR WIRELESS NETWORK AND YOUR CRITICAL DATA SECURITY AND COMPLIANCE
AIRDEFENSE SOLUTIONS PROTECT YOUR WIRELESS NETWORK AND YOUR CRITICAL DATA SECURITY AND COMPLIANCE THE CHALLENGE: SECURE THE OPEN AIR Wirelesss communication lets you take your business wherever your customers,
Agenda. Cyber Security: Potential Threats Impacting Organizations 1/6/2015. January 10, 2015 Scott Petree
Cyber Security: Potential Threats Impacting Organizations January 10, 2015 Scott Petree Agenda 2 Data Security Trends Root Causes of Cyber Attacks How Can We Fix This? Secure Infrastructure User Awareness
1. For each of the 25 questions, multiply each question response risk value (1-5) by the number of times it was chosen by the survey takers.
Employee Security Awareness Survey Trenton Bond [email protected] Admin - Version 1.3 Security Awareness One of the most significant security risks that organizations and corporations face today is
KEY STEPS FOLLOWING A DATA BREACH
KEY STEPS FOLLOWING A DATA BREACH Introduction This document provides key recommended steps to be taken following the discovery of a data breach. The document does not constitute an exhaustive guideline,
Security Overview. BlackBerry Corporate Infrastructure
Security Overview BlackBerry Corporate Infrastructure Published: 2015-04-23 SWD-20150423095908892 Contents Introduction... 5 History... 6 BlackBerry policies...7 Security organizations...8 Corporate Security
A practical guide to IT security
Data protection A practical guide to IT security Ideal for the small business The Data Protection Act states that appropriate technical and organisational measures shall be taken against unauthorised or
Nationwide Review of CMS s HIPAA Oversight. Brian C. Johnson, CPA, CISA. Wednesday, January 19, 2011
Nationwide Review of CMS s HIPAA Oversight Brian C. Johnson, CPA, CISA Wednesday, January 19, 2011 1 WHAT I DO Manage Region IV IT Audit and Advance Audit Technique Staff (AATS) IT Audit consists of 8
whitepaper 4 Best Practices for Building PCI DSS Compliant Networks
4 Best Practices for Building PCI DSS Compliant Networks Cardholder data is a lucrative and tempting target for cyber criminals. Recent highly publicized accounts of hackers breaching trusted retailers
Security and Privacy
Security and Privacy Matthew McCormack, CISSP, CSSLP CTO, Global Public Sector, RSA The Security Division of EMC 1 BILLIONS OF USERS MILLIONS/BILLIONS OF APPS 2010 Cloud Big Data Social Mobile Devices
