Security deficits in an interconnected world Key findings from The Global State of Information Security Survey 2015

Size: px
Start display at page:

Download "Security deficits in an interconnected world Key findings from The Global State of Information Security Survey 2015"

Transcription

1 Security deficits in an interconnected world Key findings from The Global State of Information Security Survey 2015 It will come as no surprise to most financial services executives that information security incidents are continuing to rise, as are the costs of these intrusions. Others disregard essential governance, operational processes, and people capabilities that enable rapid detection and response to compromises. As regulators around the world move to tighten compliance requirements for financial services organizations, improvements in these security practices will become increasingly essential to safeguard data as well as ensure compliance with global regulatory bodies. International financial services firms are at greater risk than ever, and by all estimates those threats will only increase, says Joe Nocera, a Principal in PwC s Cybersecurity Practice. That s why global organizations should prioritize their investments based upon risk focusing on the most critical business assets. Then they can strategically invest in the right combination of security processes, technologies, and awareness and training programs. In today s world, it s not a matter of if an incident will happen but rather when, and firms must be prepared to respond. In the past two years, sophisticated cyber adversaries around the world have launched powerful distributed denial of service (DDoS) attacks against banks, siphoned off billions of dollars from deposit accounts, stolen millions of payment card records, and infiltrated many national stock exchanges. Despite these attacks, many global financial services companies have not implemented the right processes and technologies to ent, detect, and respond to security risks. In particular, many do not adequately address threats from third parties and insiders like employees and partners with trusted access. In other words, it s no longer possible to protect all data, networks, and applications at the highest level, but a proactive cybersecurity program will enable financial services firms to prioritize protection and more quickly react to incidents that are all but inevitable. // 1

2 Yet security spending has not kept pace, particularly among smaller businesses. Detected incidents have maintained a steady upward momentum. The Global State of Information Security Survey 2015 (GSISS) shows that, among 758 global financial services respondents, the number of detected incidents we define a security incident as any adverse incident that threatens some aspect of computer security increased 8% this year over. GSISS 2015: results at a glance Click or tap each title to view data 5K 4,628 4,978 Incidents Sources of incidents Security spending The costs of security incidents jumped 24%, with big losses leading the way 4K $ 3.4M The number of financial firms reporting losses of $10 million to $19.9 million increased by a head-turning 141% over last year. 3K $ 2.7M 3M 2M 1M Average number of detected incidents Estimated total financial losses // 2

3 Yet security spending has not kept pace, particularly among smaller businesses. Detected incidents have maintained a steady upward momentum. The Global State of Information Security Survey 2015 (GSISS) shows that, among 758 global financial services respondents, the number of detected incidents we define a security incident as any adverse incident that threatens some aspect of computer security increased 8% this year over. GSISS 2015: results at a glance Click or tap each title to view data 50% 44% Incidents Sources of incidents Security spending The costs of security incidents jumped 24%, with big losses leading the way The number of financial firms reporting losses of $10 million to $19.9 million increased by a head-turning 141% over last year. 40% 30% 33% 25% 28% 36% 26% 20% 11% Current employees Former employees Hackers Competitors // 3

4 Yet security spending has not kept pace, particularly among smaller businesses. Detected incidents have maintained a steady upward momentum. The Global State of Information Security Survey 2015 (GSISS) shows that, among 758 global financial services respondents, the number of detected incidents we define a security incident as any adverse incident that threatens some aspect of computer security increased 8% this year over. GSISS 2015: results at a glance Click or tap each title to view data Large organizations Revenues more than $1B Small organizations Revenues less than $100M 15.4% 14.7% Incidents Sources of incidents Security spending 15 % $ 11.3M The costs of security incidents jumped 24%, with big losses leading the way $ 10.7M 12% The number of financial firms reporting losses of $10 million to $19.9 million increased by a head-turning 141% over last year. 9M 6M Small organizations Revenues less than $100M Medium organizations Revenues $100M $1B $ $ 2.6M 2.2M Medium organizations Revenues $100M $1B 3.6% 3.3% Large organizations Revenues more than $1B 3.3% 3.7% 9% 3M $ 1.0M $ 0.6M Average annual IS budget IS spend as percentage of IT budget // 4

5 While security events and costs continue to escalate, security spending has not kept pace, particularly among smaller businesses. Globally, investments in information security inched up 3% over the year before. And while financial firms invested more heavily in recent years, security spending has been stalled at less than 4% of the total IT budget for the past seven years. Security breaches not only impact a financial institution s bottom line, but also its reputation, brand, and intellectual property. Executive teams and boards can no longer afford to view cyber security as merely a technology problem, says Stephen Russell, Managing Director at PwC. The cost of defending against cyber threats has risen sharply and regulators are focusing on how well financial institutions are defending themselves against these threats. Due to a lack of investment, many financial firms are falling behind in implementing up-to-date processes and tools to detect and respond to today s evolving security threats. Year-over-year, we saw a lack of progress and in many cases, significant attrition in the use of secure access controls, risk and vulnerability assessments, threat monitoring and analysis, thirdparty security safeguards, and employee awareness and training programs, to name a few. 1 2 In analyzing this year s GSISS responses, we identified five critical areas that financial services firms should consider. Addressing these issues can help financial firms better detect and defend against threats and increase their cyber resiliency. Executive and Board support for security New regulatory requirements 3 Third-party risks 4 Insider incidents 5 Over-reliance on technology // 5

6 Falling behind in security safeguards 66% 73% 61% 64% 59% 74% 59% 67% Secure access-control measures Threat assessments Active monitoring/analysis of information security intelligence Require third parties to comply with our privacy policies 59% 63% 58% 65% 58% 67% 58% 71% Penetration testing Vulnerability assessments Risk assessments on internal systems Intrusion-detection tools 57% 66% 57% 71% 57% 63% 56% 60% Employee awareness and training program Security audits Incident response-process to report and handle breaches to third parties that handle data Risk assessments on thirdparty vendors // 6

7 Cybersecurity is no longer simply an IT concern. Today, it is a critical business issue that demands the attention and the active stewardship of the Chief Executive Officer and the Board of Directors. To be effective, cybersecurity should be integrated into the firm s overall enterprise risk-management framework, and the CEO and Board should own the responsibility for managing cyber resiliency. We consider institutions to be cyber-resilient when they have a comprehensive, well-crafted, cyber-risk management program in place with management held accountable for the program s performance and results, says Stephen Russell, Managing Director at PwC. Senior executives should establish a strong culture of security and cyber resilience by setting an affirmative tone at the top. Doing so will demand that executives proactively communicate the importance of security across the enterprise, a practice that 71% of financial services respondents say they have implemented. Beyond that, executive leaders should engage the Board in the discussion and management of cybersecurity risks. Board participation is essential to reaching an appropriate decision on the level of cyber risk an organization will accept and to building responses around those parameters. It also can be a key factor in ensuring that security practices are adequately funded an approach that most financial firms do not pursue. Only 44% of respondents say their Boards are involved in setting security budgets. Beyond the Board, risk-based cybersecurity will require crossfunctional cooperation between leaders from IT, security, legal counsel, risk management, finance, and human resources. This team should meet regularly to coordinate and communicate information security issues, a practice that 56% of financial services respondents say they have implemented. How Boards participate in security Overall security strategy Security budget Security policies Review of security and privacy risks Security technologies 26% 33% 37% 44% 50% Most firms have not done so. We know because we asked survey respondents to detail how their Boards participate in cybersecurity initiatives. The responses are telling Only one-third (33%) of respondents say their Board is involved in the review of security and privacy risks, a number that is particularly low given the criticality of enterprise-wide cyber-risk awareness. 20% 23% Review roles and responsibilities of security organization Review of security and privacy testing // 7

8 Recent actions by industry regulators in the US and Europe have signaled they may require proof that financial services firms have implemented a robust security program. These types of regulatory guidance and requirements will very likely intensify in the future. What it may take to pass a security exam 100% Consider, for instance, the European Union General Data Protection Regulation, which is on track to be finalized in The regulation is expected to add new requirements for breach notification to individuals, require organizations that handle personal data to conduct risk assessments and audits, and increase fines for compromised businesses. 1 Other regulatory bodies have announced intentions to assess financial institutions for risk vulnerability and riskmitigation policies and procedures. 2 71% 66% 66% 61% 60% 58% 57% 57% 57% 51% 80% 60% 40% 1 Vormetric Data Security, Security measures to go under spotlight as new Data Protection Directive approaches, July 8, 2 PwC, Understanding and preparing for OCIE cybersecurity exams, May Incidentmanagement response process Business continuity/ disaster recovery plans Secure access-control measures Threat assessments Privileged user access Patchmanagement tools Employee Encryption of security smartphones awareness training program Security-event correlation tools Have cyber insurance // 8

9 Guidance from the US Securities and Exchange Commission (SEC) suggests that US financial services firms should seriously consider investing in cyber insurance. In fact, the Commission included cyber insurance on its list of possible factors that may be used in examinations. What s more, the SEC goes so far as to indicate that financial services firms should be prepared to undergo examinations to actually prove their preparedness. In other words, traditional checkthe-box regulatory compliance is no longer sufficient. Firms must become more strategic because, in the near future, regulators may dictate a robust framework for cybersecurity. Regulators may also expect financial services organizations to share threat intelligence and response tactics across the organization as well as with private and public-sector partners. Many financial firms around the world already participate in the Financial Services Information Sharing and Analysis Center (FS ISAC), a global forum that was formed in Among survey respondents, 62% say they collaborate with others to improve security, a considerable gain over last year (55%). Using leading industry frameworks such as ISO or the NIST Cybersecurity Framework as a guide, many survey respondents do not appear capable of passing security examinations. Doing so will require that financial firms build a thorough risk-based cybersecurity practice that includes the following capabilities:»» A culture of security led by the C-suite and Board»» An incident response plan that is regularly tested»» Assessment and monitoring of third-party partners for security risks Such collaborations have indirectly led to new types of security preparedness, including industry-wide exercises that simulate cyber attacks on financial institutions and enable participants to work together and share response tactics. Reaching beyond enterprise boundaries to share threat intelligence and response insights is an effective way to advance security. It s also an initiative that financial firms may be judged on in future security exams.»» Advanced threat intelligence and analysis to understand business-specific threats»» Assessment of the role of cyber insurance»» Basic security fundamentals such as strong organizational governance processes and ongoing employee awareness programs // 9

10 Financial institutions are increasingly worried about their ability to combat threats that can arise from sharing networks and data with business partners, service providers, contractors, and suppliers. As recent high-profile breaches so unequivocally proved, third-party partners with access to networks and data can generate serious negative publicity and reputational harm, not to mention crippling financial losses. Key gaps in third-party security 62% 59% 57% 57% 55% 55% 100% 80% For threat actors, partners and supply chains represent a weak link through which they can gain access to a financial firm s network and data for quick monetary payoff. More farsighted adversaries may infiltrate an organization s third-party partners as a means to gain a foothold on the financial services firm s ecosystem for long-term exfiltration of business plans, financial documents, and trade secrets. 60% 40% Established security/ baselines/standards for external partners/customers/ suppliers/vendors Require third parties (including outsourcing vendors) to comply with our privacy policies Incident response-process to report and handle breaches to third parties that handle data Inventory of all third parties that handle personal data of employees and customers Conduct compliance audits of third parties that handle personal data of customers and employees Risk assessments on third-party vendors // 10

11 Banks have sustained large losses both in dollars and in public confidence as a result of successful attacks on interrelated third parties, such as major retailers, said Thomas J. Curry, US Comptroller of the Currency, at a recent Risk Management Association (RMA) conference. I ve been heavily focused on this particular type of operational risk because of the pace at which it is increasing and because of its potential to undermine confidence in our institutions. 3 Monitoring and detecting unauthorized activity by third parties and supply chains can be difficult because their employees often have trusted access to a financial firm s facilities, systems, and data. The situation becomes particularly hazardous when the security capabilities of third parties do not meet the stringent requirements of the financial services firm. It s a risk that is familiar to many financial firms participating in our survey. This year, 41% of respondents say they detected security incidents perpetrated by current and former service providers, contractors, consultants, and suppliers. While many financial services companies have detected third-party compromises, most have done very little to protect themselves. Consider, for instance, that fewer than two-thirds (62%) of respondents have established security baselines and standards for external partners, suppliers, and vendors. Just 59% require business partners to comply with their privacy policies. In essence, these firms have not taken even the most basic steps to ensure third-party security. Only 34% of financial services respondents say they have assessed the security of third-party outsourcers over the past 12 months. Roughly the same number (33%) report that they began monitoring fourth-party relationships over the past year. If the security practices of third-party partners are lacking, those even farther down the chain may represent an event more dangerous unknown. We believe that increased investment in third-party security is critical to closing this security gap. Yet when we asked respondents to name their top security spending priorities for the coming year, only 43% said they would boost budgets for monitoring and testing of business partners and vendors. While this suggests that financial firms are starting to understand the importance of third-party security, it s also worth noting that it represented the least-cited spending priority. 3 Office of the Comptroller of the Currency, remarks by Thomas J. Curry, Comptroller of the Currency, May 8, // 11

12 The number of incidents attributed to insiders current and former employees, in particular increased substantially this year, even as the readiness of financial firms to manage these risks diminished. 28% 44% Almost half (44%) of respondents attribute security incidents to existing staff, making current employees the most cited source of incidents; the second most frequently mentioned perpetrator is former employees, at 28%. The increase in insider incidents portends potentially serious implications. In the US State of Cybercrime Survey, we found that almost one-third (32%) of respondents said insider crimes are more costly or damaging than incidents perpetrated by outsiders. 4 In part, that s because internal threat actors hold the advantage since they are more likely to know where valuable data is stored and what processes and technologies are in place to protect this information. It s not that financial services employees are overwhelmingly careless or malicious, however. Increasingly, external threat actors leverage social engineering to steal credentials of employees with privileged access to data and networks, then use that information to infiltrate the financial firm s networks. More universal deployment of tools to monitor user access and activity would help organizations detect this type of compromise. Insider cybercrimes get less attention in the press, and they also appear to be off the radar of financial services companies. Many firms do not have an insider-threat program in place, which leaves them unprepared to ent, detect, and respond to insider threats. Employees and managers are critical to an insider-threat management program because they are often in a position to notice suspicious behavior or risk indicators. Consequently, employee training forms the spine of an effective security program. So it s a bit alarming that the percentage of respondents who say their organization has an employee training and awareness program dropped to 57%, from 66% the year before. It s good news, however, that almost half of respondents (49%) say they plan to increase their investment in employee awareness in the coming year. 4 US State of Cybercrime Survey, co-sponsored by CSO magazine, CERT division of the Software Engineering Institute at Carnegie Mellon University, PwC, and US Secret Service, March April // 12

13 Tools to manage insider threats 63% 60% 60% 59% 57% Conduct personnel background checks Unauthorized use/accessmonitoring tools Security strategy for employee use of personal devices on the enterprise User-activity monitoring tools Employee security awareness training program 57% 56% 53% 53% 48% Audit/monitor user compliance with security policy Data loss ention (DLP) tools Security technologies supporting Web 2.0 exchanges such as social networks, blogs Security strategy for social media Behavioral profiling and monitoring // 13

14 Many financial services firms view technology solutions as the best bet to protect their networks and data. Truth is, sophisticated cyber adversaries are often in the vanguard of innovation, and are constantly working to circumvent technologies as solutions vendors develop them. Essential governance and operational processes 71% 69% 59% 58% 57% 57% 57% 56% 80% That s why financial services organizations should ensure that technology solutions are deployed on top of a foundation of sound governance, operational processes, and people skills.consider, for instance, detection and analysis of cyber threats. Tools to identify and analyze threats are critical, but timely mitigation of incidents will also demand up-to-date response processes and properly trained personnel. 52% 60% 40% Acting upon alerts triggered by technology tools will require that key stakeholders receive immediate reports that enable them to proactively and quickly respond. An effective response will be best accomplished through the development of prepared responses, or playbooks, that provide step-by-step guidelines on roles, responsibilities, and actions. These playbooks should be frequently tested so that security and operational personnel are wellprepared to quickly mitigate incidents. Incidentmanagement response process Classification of business value of data Risk assessments on internal systems Program to identify sensitive assets Incident response-process to report & handle breaches to third parties Procedures dedicated to protecting intellectual property Security audits In an era in which cyber compromise is virtually certain, a coordinated approach to incident response is critical to the bottom line, as well as reputation and compliance. So it s a bit surprising to find that 29% of survey respondents have no incident response process. It s also worrisome that one-third say they have no business continuity/disaster recovery plans to ensure operations are quickly returned to normal with minimum disruption. Risk assessments on third-party vendors Governance, risk, and compliance tools // 14

15 As incidents continue to proliferate, it s becoming clear that cyber risks can never be completely eliminated. Protective measures remain important, of course, but processes and tools to detect, analyze, and respond to incidents are key to cyber resiliency and to the ongoing success of any financial services business. To make this adjustment, financial services firms should reposition their security strategy by more closely linking technologies, processes, and tools with the firm s broader riskmanagement activities. Doing so will result in a cyber-resilient program that can effectively manage risks based on the business s tolerance for risk. Five questions you should ask How much revenue would we lose if our business processes were impacted by a cyber event? Do we have capabilities to quickly respond to a cyber attack? Have we identified our most critical business assets and do we understand their value to our adversaries? Do we know where to invest to reduce cyber risks? Is the business resilient enough to survive a cyber attack? // 15

16 To have a deeper conversation about cybersecurity, please contact: United States Shawn Connors Principal shawn.connors@us.pwc.com Christopher Morris Principal christopher.morris@us.pwc.com Joe Nocera Principal joseph.nocera@us.pwc.com Stephen Russell Managing Director stephen.j.russell@us.pwc.com Andrew Toner Principal andrew.toner@us.pwc.com Prakash Venkata Managing Director prakash.venkata@us.pwc.com // PwC helps organisations and individuals create the value they re looking for. We re a network of firms in 157 countries with more than 184,000 people who are committed to delivering quality in assurance, tax and advisory services. Tell us what matters to you and find out more by visiting us at This publication has been prepared for general guidance on matters of interest only, and does not constitute professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice. No representation or warranty (express or implied) is given as to the accuracy or completeness of the information contained in this publication, and, to the extent permitted by law, PwC does not accept or assume any liability, responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it. PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Please see for further details. The Global State of Information Security is a registered trademark of International Data Group, Inc. // 16

20+ At risk and unready in an interconnected world

20+ At risk and unready in an interconnected world At risk and unready in an interconnected world Key findings from The Global State of Information Security Survey 2015 Cyber attacks against power and utilities organizations have transitioned from theoretical

More information

Improving cyber readiness in an interconnected world Key findings from The Global State of Information Security Survey 2015

Improving cyber readiness in an interconnected world Key findings from The Global State of Information Security Survey 2015 Improving cyber readiness in an interconnected world Key findings from The Global State of Information Security Survey 2015 organizations tend to have comparatively robust and mature cybersecurity programs.

More information

Driving cybersecurity advances in an interconnected world Key findings from The Global State of Information Security Survey 2015

Driving cybersecurity advances in an interconnected world Key findings from The Global State of Information Security Survey 2015 Driving cybersecurity advances in an interconnected world Key findings from The Global State of Information Security Survey 2015 Technology advances like telematics, networked manufacturing tools, and

More information

Defending yesterday. Financial Services. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Financial Services. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015

Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 If the recent string of high-profile cyber attacks has proved anything, it s that

More information

The promise and pitfalls of cyber insurance January 2016

The promise and pitfalls of cyber insurance January 2016 www.pwc.com/us/insurance The promise and pitfalls of cyber insurance January 2016 2 top issues The promise and pitfalls of cyber insurance Cyber insurance is a potentially huge but still largely untapped

More information

www.pwc.co.uk Cyber security Building confidence in your digital future

www.pwc.co.uk Cyber security Building confidence in your digital future www.pwc.co.uk Cyber security Building confidence in your digital future November 2013 Contents 1 Confidence in your digital future 2 Our point of view 3 Building confidence 4 Our services Confidence in

More information

Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015

Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 Cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 Over the past year, the phrase data breach has become closely associated with

More information

www.pwc.com Cybersecurity and Privacy Hot Topics 2015

www.pwc.com Cybersecurity and Privacy Hot Topics 2015 www.pwc.com Cybersecurity and Privacy Hot Topics 2015 Table of Contents Cybersecurity and Privacy Incidents are on the rise Executives and Boards are focused on Emerging Risks Banking & Capital Markets

More information

Healthcare cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015

Healthcare cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 Healthcare cybersecurity challenges in an interconnected world Key findings from The Global State of Information Security Survey 2015 Healthcare payers Technology is not the only agent of change. Innovations

More information

White Paper on Financial Industry Regulatory Climate

White Paper on Financial Industry Regulatory Climate White Paper on Financial Industry Regulatory Climate According to a 2014 report on threats to the financial services sector, 45% of financial services organizations polled had suffered economic crime during

More information

Managing cyber risks with insurance

Managing cyber risks with insurance www.pwc.com.tr/cybersecurity Managing cyber risks with insurance Key factors to consider when evaluating how cyber insurance can enhance your security program June 2014 Managing cyber risks to sensitive

More information

January IIA / ISACA Joint Meeting Pre-meeting. Cybersecurity Update for Internal Auditors. Matt Wilson, PwC Risk Assurance Director

January IIA / ISACA Joint Meeting Pre-meeting. Cybersecurity Update for Internal Auditors. Matt Wilson, PwC Risk Assurance Director January IIA / ISACA Joint Meeting Pre-meeting Cybersecurity Update for Internal Auditors Matt Wilson, Risk Assurance Director Introduction and agenda Themes from The Global State of Information Security

More information

Why you should adopt the NIST Cybersecurity Framework

Why you should adopt the NIST Cybersecurity Framework www.pwc.com/cybersecurity Why you should adopt the NIST Cybersecurity Framework May 2014 The National Institute of Standards and Technology Cybersecurity Framework may be voluntary, but it offers potential

More information

Italy. EY s Global Information Security Survey 2013

Italy. EY s Global Information Security Survey 2013 Italy EY s Global Information Security Survey 2013 EY s Global Information Security Survey 2013 This year s survey our 16th edition captures the responses of 1,909 C-suite and senior level IT and information

More information

Cybersecurity The role of Internal Audit

Cybersecurity The role of Internal Audit Cybersecurity The role of Internal Audit Cyber risk High on the agenda Audit committees and board members are seeing cybersecurity as a top risk, underscored by recent headlines and increased government

More information

www.pwc.com The data breach lifecycle: From prevention to response IAPP global privacy summit March 6, 2014 (4:30-5:30) Draft v8 2-25-14

www.pwc.com The data breach lifecycle: From prevention to response IAPP global privacy summit March 6, 2014 (4:30-5:30) Draft v8 2-25-14 www.pwc.com The data breach lifecycle: From prevention to response IAPP global privacy summit (4:30-5:30) Draft v8 2-25-14 Common Myths 1. You have not been hacked. 2. Cyber security is about keeping the

More information

Do you know your privacy risks? How new technologies, changing business models, and emerging regulations are changing the data-protection landscape

Do you know your privacy risks? How new technologies, changing business models, and emerging regulations are changing the data-protection landscape January 2013 Do you know your privacy risks? How new technologies, changing business models, and emerging regulations are changing the data-protection landscape At a glance Threats to data security both

More information

PwC Cybersecurity Briefing

PwC Cybersecurity Briefing www.pwc.com/cybersecurity Cybersecurity Briefing June 25, 2014 The views expressed in these slides are solely the views of the presenters and do not necessarily reflect the views of the PCAOB, the members

More information

Global State of Information Security Survey 2015

Global State of Information Security Survey 2015 www.pwc.ch/cybersecurity Global State of Information Security Survey 2015 The risks and repercussions of security incidents continue to rise as preparedness falls. Agenda Methodology Key findings Focus

More information

US cybersecurity: Progress stalled Key findings from the 2015 US State of Cybercrime Survey

US cybersecurity: Progress stalled Key findings from the 2015 US State of Cybercrime Survey www.pwc.com/cybersecurity US cybersecurity: Progress stalled Key findings from the 2015 US State of Cybercrime Survey July 2015 About the 2015 US State of Cybercrime Survey The 2015 US State of Cybercrime

More information

Information Technology in the Automotive Aftermarket

Information Technology in the Automotive Aftermarket Information Technology in the Automotive Aftermarket March 2015 AASA Thought Leadership: The following white paper consists of key takeaways from three AASA surveys conducted in 2014, which focused on

More information

Cybersecurity and internal audit. August 15, 2014

Cybersecurity and internal audit. August 15, 2014 Cybersecurity and internal audit August 15, 2014 arket insights: what we are seeing so far? 60% of organizations see increased risk from using social networking, cloud computing and personal mobile devices

More information

WRITTEN TESTIMONY OF

WRITTEN TESTIMONY OF WRITTEN TESTIMONY OF KEVIN MANDIA CHIEF EXECUTIVE OFFICER MANDIANT CORPORATION BEFORE THE SUBCOMMITTEE ON CRIME AND TERRORISM JUDICIARY COMMITTEE UNITED STATES SENATE May 8, 2013 Introduction Thank you

More information

Cyber Risks in the Boardroom

Cyber Risks in the Boardroom Cyber Risks in the Boardroom Managing Business, Legal and Reputational Risks Perspectives for Directors and Executive Officers Preparing Your Company to Identify, Mitigate and Respond to Risks in a Changing

More information

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors Overview for Chief Executive Officers and Boards of Directors In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed

More information

Answering your cybersecurity questions The need for continued action

Answering your cybersecurity questions The need for continued action www.pwc.com/cybersecurity Answering your cybersecurity questions The need for continued action January 2014 Boards and executives keeping a sustained focus on cybersecurity do more than protect the business:

More information

Protecting against cyber threats and security breaches

Protecting against cyber threats and security breaches Protecting against cyber threats and security breaches IBM APT Survival Kit Alberto Benavente Martínez abenaventem@es.ibm.com IBM Security Services Jun 11, 2015 (Madrid, Spain) 12015 IBM Corporation So

More information

PRIORITIZING CYBERSECURITY

PRIORITIZING CYBERSECURITY April 2016 PRIORITIZING CYBERSECURITY Five Investor Questions for Portfolio Company Boards Foreword As the frequency and severity of cyber attacks against global businesses continue to escalate, both companies

More information

Addressing APTs and Modern Malware with Security Intelligence Date: September 2013 Author: Jon Oltsik, Senior Principal Analyst

Addressing APTs and Modern Malware with Security Intelligence Date: September 2013 Author: Jon Oltsik, Senior Principal Analyst ESG Brief Addressing APTs and Modern Malware with Security Intelligence Date: September 2013 Author: Jon Oltsik, Senior Principal Analyst Abstract: APTs first came on the scene in 2010, creating a wave

More information

Into the cybersecurity breach

Into the cybersecurity breach Into the cybersecurity breach Tim Sanouvong State Sector Cyber Risk Services Deloitte & Touche LLP April 3, 2015 Agenda Setting the stage Cyber risks in state governments Cyber attack vectors Preparing

More information

Defending yesterday. Retail & Consumer. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Retail & Consumer. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

fs viewpoint www.pwc.com/fsi Threat smart: Building a cyber resilient financial institution

fs viewpoint www.pwc.com/fsi Threat smart: Building a cyber resilient financial institution fs viewpoint www.pwc.com/fsi 3 9 4 22 25 Point of view Competitive A framework How PwC Appendix intelligence for response can help Threat smart: Building a cyber resilient financial institution Executive

More information

Cybercrime and Regulatory Priorities for Cybersecurity

Cybercrime and Regulatory Priorities for Cybersecurity NRS Technology and Communication Compliance Forum Cybercrime and Regulatory Priorities for Cybersecurity Copyright 2014 by K&L Gates LLP. All rights reserved. Sean P. Mahoney sean.mahoney@klgates.com K&L

More information

CYBERSECURITY IN FINANCIAL SERVICES POINT OF VIEW CHALLENGE 1 REGULATORY COMPLIANCE ACROSS GEOGRAPHIES

CYBERSECURITY IN FINANCIAL SERVICES POINT OF VIEW CHALLENGE 1 REGULATORY COMPLIANCE ACROSS GEOGRAPHIES POINT OF VIEW CYBERSECURITY IN FINANCIAL SERVICES Financial services institutions are globally challenged to keep pace with changing and covert cybersecurity threats while relying on traditional response

More information

Five keys to a more secure data environment

Five keys to a more secure data environment Five keys to a more secure data environment A holistic approach to data infrastructure security Compliance professionals know better than anyone how compromised data can lead to financial and reputational

More information

fs viewpoint www.pwc.com/fsi

fs viewpoint www.pwc.com/fsi fs viewpoint www.pwc.com/fsi June 2013 02 11 16 21 24 Point of view Competitive intelligence A framework for response How PwC can help Appendix It takes two to tango: Managing technology risk is now a

More information

CYBERSECURITY BEST PRACTICES FOR SMALL AND MEDIUM PENNSYLVANIA UTILITIES. second edition

CYBERSECURITY BEST PRACTICES FOR SMALL AND MEDIUM PENNSYLVANIA UTILITIES. second edition CYBERSECURITY BEST PRACTICES FOR SMALL AND MEDIUM PENNSYLVANIA UTILITIES second edition The information provided in this document is presented as a courtesy to be used for informational purposes only.

More information

FFIEC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool Overview In light of the increasing volume and sophistication of cyber threats, the Federal Financial Institutions Examination Council 1 (FFIEC) developed the Cybersecurity Tool (), on behalf of its members,

More information

State Agency Cyber Security Survey v 3.4 2 October 2014. State Agency Cybersecurity Survey v 3.4

State Agency Cyber Security Survey v 3.4 2 October 2014. State Agency Cybersecurity Survey v 3.4 State Agency Cybersecurity Survey v 3.4 The purpose of this survey is to identify your agencies current capabilities with respect to information systems/cyber security and any challenges and/or successes

More information

CYBER SECURITY, A GROWING CIO PRIORITY

CYBER SECURITY, A GROWING CIO PRIORITY www.wipro.com CYBER SECURITY, A GROWING CIO PRIORITY Bivin John Verghese, Practitioner - Managed Security Services, Wipro Ltd. Contents 03 ------------------------------------- Abstract 03 -------------------------------------

More information

Cyber Resilience Implementing the Right Strategy. Grant Brown Security specialist, CISSP @TheGrantBrown

Cyber Resilience Implementing the Right Strategy. Grant Brown Security specialist, CISSP @TheGrantBrown Cyber Resilience Implementing the Right Strategy Grant Brown specialist, CISSP @TheGrantBrown 1 2 Network + Technology + Customers = $$ 3 Perfect Storm? 1) Increase in Bandwidth (extended reach) 2) Available

More information

Defending yesterday. Technology. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Technology. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

WILLIS SPECIAL REPORT: 10K DISCLOSURES HOW RETAIL COMPANIES DESCRIBE THEIR CYBER LIABILITY EXPOSURES

WILLIS SPECIAL REPORT: 10K DISCLOSURES HOW RETAIL COMPANIES DESCRIBE THEIR CYBER LIABILITY EXPOSURES WILLIS SPECIAL REPORT: 10K DISCLOSURES HOW RETAIL COMPANIES DESCRIBE THEIR CYBER LIABILITY EXPOSURES This special report examines the cyber risk disclosures made by the retail sector of the Fortune 1000.

More information

CYBER4SIGHT TM THREAT INTELLIGENCE SERVICES ANTICIPATORY AND ACTIONABLE INTELLIGENCE TO FIGHT ADVANCED CYBER THREATS

CYBER4SIGHT TM THREAT INTELLIGENCE SERVICES ANTICIPATORY AND ACTIONABLE INTELLIGENCE TO FIGHT ADVANCED CYBER THREATS CYBER4SIGHT TM THREAT INTELLIGENCE SERVICES ANTICIPATORY AND ACTIONABLE INTELLIGENCE TO FIGHT ADVANCED CYBER THREATS PREPARING FOR ADVANCED CYBER THREATS Cyber attacks are evolving faster than organizations

More information

US cybercrime: Rising risks, reduced readiness Key findings from the 2014 US State of Cybercrime Survey

US cybercrime: Rising risks, reduced readiness Key findings from the 2014 US State of Cybercrime Survey www.pwc.com/cybersecurity US cybercrime: Rising risks, reduced readiness Key findings from the 204 US State of Cybercrime Survey June 204 As cybersecurity incidents multiply in frequency and cost, the

More information

Cyber security Time for a new paradigm. Stéphane Hurtaud Partner Information & Technology Risk Deloitte

Cyber security Time for a new paradigm. Stéphane Hurtaud Partner Information & Technology Risk Deloitte Cyber security Time for a new paradigm Stéphane Hurtaud Partner Information & Technology Risk Deloitte 90 More than ever, cyberspace is a land of opportunity but also a dangerous world. As public and private

More information

Cybersecurity: A View from the Boardroom

Cybersecurity: A View from the Boardroom An Executive Brief from Cisco Cybersecurity: A View from the Boardroom In the modern economy, every company runs on IT. That makes security the business of every person in the organization, from the chief

More information

New York State Department of Financial Services. Report on Cyber Security in the Banking Sector

New York State Department of Financial Services. Report on Cyber Security in the Banking Sector New York State Department of Financial Services Report on Cyber Security in the Banking Sector Governor Andrew M. Cuomo Superintendent Benjamin M. Lawsky May 2014 I. Introduction Cyber attacks against

More information

PROPOSED INTERPRETIVE NOTICE

PROPOSED INTERPRETIVE NOTICE August 28, 2015 Via Federal Express Mr. Christopher J. Kirkpatrick Secretary Office of the Secretariat Commodity Futures Trading Commission Three Lafayette Centre 1155 21st Street, N.W. Washington, DC

More information

PACB One-Day Cybersecurity Workshop

PACB One-Day Cybersecurity Workshop PACB One-Day Cybersecurity Workshop WHAT IS CYBERSECURITY? PRESENTED BY: JON WALDMAN, SBS CISA, CRISC 1 Contact Information Jon Waldman Partner, Senior IS Consultant CISA, CRISC Masters of Info Assurance

More information

Defending yesterday. Telecommunications. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Telecommunications. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

Global trends in information security

Global trends in information security Global trends in information security Trends on the following topics are discussed in this newsflash: leadership behavior incidents and privacy tools safeguards related to people Introduction LinkedIn,

More information

By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015

By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015 Community Bank Auditors Group Cybersecurity What you need to do now June 9, 2015 By: Gerald Gagne MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C. Cybersecurity

More information

Developing National Frameworks & Engaging the Private Sector

Developing National Frameworks & Engaging the Private Sector www.pwc.com Developing National Frameworks & Engaging the Private Sector Focus on Information/Cyber Security Risk Management American Red Cross Disaster Preparedness Summit Chicago, IL September 19, 2012

More information

Web application security Executive brief Managing a growing threat: an executive s guide to Web application security.

Web application security Executive brief Managing a growing threat: an executive s guide to Web application security. Web application security Executive brief Managing a growing threat: an executive s guide to Web application security. Danny Allan, strategic research analyst, IBM Software Group Contents 2 Introduction

More information

Experience the commitment WHITE PAPER. Information Security Continuous Monitoring. Charting the Right Course. cgi.com 2014 CGI GROUP INC.

Experience the commitment WHITE PAPER. Information Security Continuous Monitoring. Charting the Right Course. cgi.com 2014 CGI GROUP INC. Experience the commitment WHITE PAPER Information Security Continuous Monitoring Charting the Right Course May 2014 cgi.com 2014 CGI GROUP INC. During the last few months of 2013, six federal agencies

More information

www.pwc.nl/cybersecurity Cyber security Building confidence in your digital future

www.pwc.nl/cybersecurity Cyber security Building confidence in your digital future www.pwc.nl/cybersecurity Cyber security Building confidence in your digital future 2015 Contents 1 Confidence in your digital future 2 Our point of view 3 Building confidence 4 Our services Confidence

More information

Threat smart: Building a cyber resilient financial institution - an East Cluster perspective

Threat smart: Building a cyber resilient financial institution - an East Cluster perspective 3 10 15 23 Point of view Competitive intelligence A framework for response How PwC can help 26 Appendix Threat smart: Building a cyber resilient financial institution - an East Cluster perspective Executive

More information

Assessing the strength of your security operating model

Assessing the strength of your security operating model www.pwc.com Assessing the strength of your security operating model May 2014 Assessing the strength of your security operating model Retail stores, software companies, the U.S. Federal Reserve it seems

More information

CYBER SECURITY AND RISK MANAGEMENT. An Executive level responsibility

CYBER SECURITY AND RISK MANAGEMENT. An Executive level responsibility CYBER SECURITY AND RISK MANAGEMENT An Executive level responsibility Cyberspace poses risks as well as opportunities Cyber security risks are a constantly evolving threat to an organisation s ability to

More information

Stay ahead of insiderthreats with predictive,intelligent security

Stay ahead of insiderthreats with predictive,intelligent security Stay ahead of insiderthreats with predictive,intelligent security Sarah Cucuz sarah.cucuz@spyders.ca IBM Security White Paper Executive Summary Stay ahead of insider threats with predictive, intelligent

More information

Defending yesterday. Power & Utilities. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Power & Utilities. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

Cyber4sight TM Threat. Anticipatory and Actionable Intelligence to Fight Advanced Cyber Threats

Cyber4sight TM Threat. Anticipatory and Actionable Intelligence to Fight Advanced Cyber Threats Cyber4sight TM Threat Intelligence Services Anticipatory and Actionable Intelligence to Fight Advanced Cyber Threats Preparing for Advanced Cyber Threats Cyber attacks are evolving faster than organizations

More information

Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014

Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014 Remarks by Thomas J. Curry Comptroller of the Currency Before the New England Council Boston, Massachusetts May 16, 2014 It s a pleasure to be with you back home in Boston. I was here just six weeks ago

More information

Managing IT Security with Penetration Testing

Managing IT Security with Penetration Testing Managing IT Security with Penetration Testing Introduction Adequately protecting an organization s information assets is a business imperative one that requires a comprehensive, structured approach to

More information

Anthony J. Albanese, Acting Superintendent of Financial Services. Financial and Banking Information Infrastructure Committee (FBIIC) Members:

Anthony J. Albanese, Acting Superintendent of Financial Services. Financial and Banking Information Infrastructure Committee (FBIIC) Members: Andrew M. Cuomo Governor Anthony J. Albanese Acting Superintendent FROM: TO: Anthony J. Albanese, Acting Superintendent of Financial Services Financial and Banking Information Infrastructure Committee

More information

Getting real about cyber threats: where are you headed?

Getting real about cyber threats: where are you headed? Getting real about cyber threats: where are you headed? Energy, utilities and power generation companies that understand today s cyber threats will be in the best position to defeat them June 2011 At a

More information

FREQUENTLY ASKED QUESTIONS

FREQUENTLY ASKED QUESTIONS FREQUENTLY ASKED QUESTIONS Continuous Monitoring 1. What is continuous monitoring? Continuous monitoring is one of six steps in the Risk Management Framework (RMF) described in NIST Special Publication

More information

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS

CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS CYBER & PRIVACY INSURANCE FOR FINANCIAL INSTITUTIONS 1 As regulators around the world move to tighten compliance requirements for financial institutions, improvement in cyber security controls will become

More information

Internal audit of cybersecurity. Presentation to the Atlanta IIA Chapter January 2015

Internal audit of cybersecurity. Presentation to the Atlanta IIA Chapter January 2015 Internal audit of cybersecurity Presentation to the Atlanta IIA Chapter January 2015 Agenda Executive summary Why is this topic important? Cyber attacks: increasing complexity arket insights: What are

More information

Cyber Governance Preparing for the Inevitable Perimeter Breach

Cyber Governance Preparing for the Inevitable Perimeter Breach SAP Brief SAP Extensions SAP Regulation Management by Greenlight, Cyber Governance Edition Objectives Cyber Governance Preparing for the Inevitable Perimeter Breach Augment your preventive cybersecurity

More information

Cyber and Data Risk What Keeps You Up at Night?

Cyber and Data Risk What Keeps You Up at Night? Legal Counsel to the Financial Services Industry Cyber and Data Risk What Keeps You Up at Night? December 10, 2014 Introduction & Overview Today s Discussion: Evolving nature of data and privacy risks

More information

www.pwc.com Surviving Contact with Reality Crisis exercises as a key element of cyber incident and crisis management response.

www.pwc.com Surviving Contact with Reality Crisis exercises as a key element of cyber incident and crisis management response. www.pwc.com Surviving Contact with Reality Crisis exercises as a key element of cyber incident and crisis management response. What Happened to the Dinosaurs Avoiding the Extinction- Level Event Corporations

More information

National Cyber Security Policy -2013

National Cyber Security Policy -2013 National Cyber Security Policy -2013 Preamble 1. Cyberspace 1 is a complex environment consisting of interactions between people, software and services, supported by worldwide distribution of information

More information

THE CYBER SECURITY PLAYBOOK WHAT EVERY BOARD OF DIRECTORS SHOULD KNOW BEFORE, DURING, AND AFTER AN ATTACK SECURITY REIMAGINED

THE CYBER SECURITY PLAYBOOK WHAT EVERY BOARD OF DIRECTORS SHOULD KNOW BEFORE, DURING, AND AFTER AN ATTACK SECURITY REIMAGINED THE CYBER SECURITY PLAYBOOK WHAT EVERY BOARD OF DIRECTORS SHOULD KNOW BEFORE, DURING, AND AFTER AN ATTACK SECURITY REIMAGINED THE CYBER SECURITY PLAYBOOK 2 03 Introduction 04 Changing Roles, Changing Threat

More information

Nine recommendations for alternative funds battling cyber crime. kpmg.ca/cybersecurity

Nine recommendations for alternative funds battling cyber crime. kpmg.ca/cybersecurity Nine recommendations for alternative funds battling cyber crime kpmg.ca/cybersecurity Cyber criminals steal user names and passwords and use it to conduct financial trading activity illicitly. Hackers

More information

Where insights lead Cybersecurity and the role of internal audit: An urgent call to action

Where insights lead Cybersecurity and the role of internal audit: An urgent call to action Where insights lead Cybersecurity and the role of internal audit: An urgent call to action The threat from cyberattacks is significant and continuously evolving. One estimate suggests that cybercrime could

More information

Logging In: Auditing Cybersecurity in an Unsecure World

Logging In: Auditing Cybersecurity in an Unsecure World About This Course Logging In: Auditing Cybersecurity in an Unsecure World Course Description $5.4 million that s the average cost of a data breach to a U.S.-based company. It s no surprise, then, that

More information

10Minutes. on the stark realities of cybersecurity. The Cyber Savvy CEO. A changed business environment demands a new approach:

10Minutes. on the stark realities of cybersecurity. The Cyber Savvy CEO. A changed business environment demands a new approach: 10Minutes on the stark realities of cybersecurity The Cyber Savvy CEO Highlights Business leaders must recognise the exposure and business impact that comes from operating within an interconnected global

More information

OCIE Technology Controls Program

OCIE Technology Controls Program OCIE Technology Controls Program Cybersecurity Update Chris Hetner Cybersecurity Lead, OCIE/TCP 212-336-5546 Introduction (Role, Disclaimer, Background and Speech Topics) SEC Cybersecurity Program Overview

More information

Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom. kpmg.bm

Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom. kpmg.bm Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom kpmg.bm Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom 1 Connecting the dots:

More information

ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES

ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES ASSUMING A STATE OF COMPROMISE: EFFECTIVE DETECTION OF SECURITY BREACHES Leonard Levy PricewaterhouseCoopers LLP Session ID: SEC-W03 Session Classification: Intermediate Agenda The opportunity Assuming

More information

Security Overview. BlackBerry Corporate Infrastructure

Security Overview. BlackBerry Corporate Infrastructure Security Overview BlackBerry Corporate Infrastructure Published: 2015-04-23 SWD-20150423095908892 Contents Introduction... 5 History... 6 BlackBerry policies...7 Security organizations...8 Corporate Security

More information

A NEW APPROACH TO CYBER SECURITY

A NEW APPROACH TO CYBER SECURITY A NEW APPROACH TO CYBER SECURITY We believe cyber security should be about what you can do not what you can t. DRIVEN BY BUSINESS ASPIRATIONS We work with you to move your business forward. Positively

More information

defending against advanced persistent threats: strategies for a new era of attacks agility made possible

defending against advanced persistent threats: strategies for a new era of attacks agility made possible defending against advanced persistent threats: strategies for a new era of attacks agility made possible security threats as we know them are changing The traditional dangers IT security teams have been

More information

THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS

THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS THE DIGITAL AGE THE DEFINITIVE CYBERSECURITY GUIDE FOR DIRECTORS AND OFFICERS Download the entire guide and follow the conversation at SecurityRoundtable.org Detection, analysis, and understanding of threat

More information

Cybersecurity..Is your PE Firm Ready? October 30, 2014

Cybersecurity..Is your PE Firm Ready? October 30, 2014 Cybersecurity..Is your PE Firm Ready? October 30, 2014 The Panel Melinda Scott, Founding Partner, Scott Goldring Eric Feldman, Chief Information Officer, The Riverside Company Joe Campbell, CTO, PEF Services

More information

CYBERSECURITY EXAMINATION SWEEP SUMMARY

CYBERSECURITY EXAMINATION SWEEP SUMMARY This Risk Alert provides summary observations from OCIE s examinations of registered broker-dealers and investment advisers, conducted under the Cybersecurity Examination Initiative, announced April 15,

More information

NIST Cybersecurity Framework & A Tale of Two Criticalities

NIST Cybersecurity Framework & A Tale of Two Criticalities NIST Cybersecurity Framework & A Tale of Two Criticalities Vendor Management & Incident Response Presented by: John H Rogers, CISSP Advisory Services Practice Manager john.rogers@sagedatasecurity.com Presented

More information

Cybersecurity: Considerations for Internal Audit. IIA Atlanta Chapter Meeting January 9, 2015

Cybersecurity: Considerations for Internal Audit. IIA Atlanta Chapter Meeting January 9, 2015 Cybersecurity: Considerations for Internal Audit IIA Atlanta Chapter Meeting January 9, 2015 Agenda Key Risks Incorporating Internal Audit Resources for Internal Auditors Questions 2 Key Risks 3 4 Key

More information

Perspectives on Cybersecurity in Healthcare June 2015

Perspectives on Cybersecurity in Healthcare June 2015 SPONSORED BY Perspectives on Cybersecurity in Healthcare June 2015 Workgroup for Electronic Data Interchange 1984 Isaac Newton Square, Suite 304, Reston, VA. 20190 T: 202-618-8792/F: 202-684-7794 Copyright

More information

Privilege Gone Wild: The State of Privileged Account Management in 2015

Privilege Gone Wild: The State of Privileged Account Management in 2015 Privilege Gone Wild: The State of Privileged Account Management in 2015 March 2015 1 Table of Contents... 4 Survey Results... 5 1. Risk is Recognized, and Control is Viewed as a Cross-Functional Need...

More information

Securing the Microsoft Cloud

Securing the Microsoft Cloud Securing the Microsoft Cloud Securing the Microsoft Cloud Page 1 Securing the Microsoft Cloud Microsoft recognizes that trust is necessary for organizations and consumers to fully embrace and benefit from

More information

Improving Cyber Security Risk Management through Collaboration

Improving Cyber Security Risk Management through Collaboration CTO Corner April 2014 Improving Cyber Security Risk Management through Collaboration Dan Schutzer, Senior Technology Consultant, BITS Back in March 2013, I wrote a CTO Corner on Operational and Cyber Risk

More information

Defending yesterday. Key findings from The Global State of Information Security Survey 2014

Defending yesterday. Key findings from The Global State of Information Security Survey 2014 www.pwc.com/security Defending yesterday While organizations have made significant security improvements, they have not kept pace with today s determined adversaries. As a result, many rely on yesterday

More information

Cyber Threat Intelligence Move to an intelligencedriven cybersecurity model

Cyber Threat Intelligence Move to an intelligencedriven cybersecurity model Cyber Threat Intelligence Move to an intelligencedriven cybersecurity model Stéphane Hurtaud Partner Governance Risk & Compliance Deloitte Laurent De La Vaissière Director Governance Risk & Compliance

More information

Security and Privacy Trends 2014

Security and Privacy Trends 2014 2014 Agenda Today s cyber threats 3 You could be under cyber attack now! Improve 6 Awareness of cyber threats propels improvements Expand 11 Leading practices to combat cyber threats Innovate 20 To survive,

More information

CYBERSECURITY: Is Your Business Ready?

CYBERSECURITY: Is Your Business Ready? CYBERSECURITY: Is Your Business Ready? Cybersecurity: Is your business ready? Cyber risk is just like any other corporate risk and it must be managed from the top. An organization will spend time monitoring

More information

Access is power. Access management may be an untapped element in a hospital s cybersecurity plan. January 2016. kpmg.com

Access is power. Access management may be an untapped element in a hospital s cybersecurity plan. January 2016. kpmg.com Access is power Access management may be an untapped element in a hospital s cybersecurity plan January 2016 kpmg.com Introduction Patient data is a valuable asset. Having timely access is critical for

More information