MISSION-ESSENTIAL INTELLIGENCE AND CYBER SOLUTIONS
|
|
|
- Nickolas Jefferson
- 10 years ago
- Views:
Transcription
1 Presentation to the Cyber Security & Critical Infrastructure Protection Symposium March 20, 2013 PREPARED REMARKS BARBARA ALEXANDER, DIRECTOR OF CYBER INTELLIGENCE TASC INFRASTRUCTURE PROTECTION AND SECURITY GROUP Thank you very much for the invitation to speak to you today. This is an august indeed, a bit intimidating group of cyber professionals. I find that when I am in the presence of engineers and scientists I want to wear one of those T-shirts with a complicated equation that states, This is why I majored in English or in my case, political science. I spent my career as an intelligence officer and have come to the cyber world not as a network defender or solution developer, but as someone who seeks to support those on the front lines of cybersecurity with actionable, responsive information. I m also honored to be here with some of the premier thought leaders working across the many aspects of cybersecurity today. The speakers who have already presented have been insightful and raised critical challenges that we face across government, industry, the private sector and the public. The breadth of backgrounds and perspectives represented here illustrate the scope of the problem. Go to any symposium and ask what cyber includes and whose responsibility it is - and you are likely to get the answer, Yes. Yes it is a federal issue. Yes it is a state and local issue. Yes it is an intelligence issue. Yes it is a defense issue. Yes it is a commercial issue. Yes it impacts business decisions. Yes it impacts IT operations. Yes it is a policy matter. Yes it has legal repercussions. Yes it affects foreign policy. Yes it involves the global supply chain. Yes it is an education and training matter. 1 TASC WHITE PAPER 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
2 Yes it requires a public-private sector partnership. The fact is this domain touches every one of these areas - and only an interdisciplinary, holistic approach and a focus on prevention will provide secure and resilient cybersecurity. There is widespread agreement that the threat is real, and that there are a variety of actors nation states, organized crime, insiders, hacktivists, terrorists and even mischief makers. There is agreement that the theft of intellectual property and trade secrets as a result of cyber attacks is in the hundreds of billions of dollars. General Keith Alexander, director of the NSA, has called this theft the greatest transfer of wealth in history. Shawn Henry, former executive assistant director of the FBI, once called the cyber threat an existential one, meaning that a major cyber attack could potentially wipe out whole companies. It could shut down our electric grid or water supply. It could cause serious damage to parts of our cities, and ultimately even kill people." I think it s time we agree that our response must be multi-faceted - a collaboration between network defenders and system engineers, intelligence specialist and law enforcement, policymakers and lawyers, people in government and people in private industry. To be successful we must bring all of our insight and expertise into the fold. Do you remember the Rubik s cube? The cyber domain is like a Rubik s cube all aspects must be worked together. Change one and the effect impacts others, sometimes with unintended consequences. For many years, network defenders focused on keeping intruders out and attacks at bay. They wanted to catch-and-patch and didn't really care about who was attacking the system or if there was a pattern in the attacks. The trouble with this approach as a standalone solution is that it s reactive. A signature-based system will only stay ahead until the next version of malware surfaces. It is a never-ending, reactive cycle that is vitally important and, at the same time, painfully limiting. I think this is changing and there is more awareness that it s not enough to stop the attack at the door. But where the catch and patch approach still exists, it s important to move beyond reaction. We must push the boundaries of protection beyond responding and recovering by adopting a multifaceted, layered defense - which is where cyber-intel comes into the picture. Intelligence is helping with the prevent and protect side of the Rubik s cube. If through solid and responsive threat intelligence we can effectively push the border of cyber defense out, away from our networks, the network defenders have more time and better opportunity to secure the cyber domain. Intelligence helps in four distinct ways. 1. Intelligence provides context. When I was at DHS, one of my cyber intelligence experts spoke to a gathering of CIKR sector folks who are heavily dependent on SCADA systems. He 2 TASC PRESENTATION 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
3 explained to them why a particular nation state was attempting to get into their networks it wasn t to shut them down, it was to learn about the specific methods the United States uses to produce that form of energy because they were developing similar ones. We know, of course, that theft of intellectual property is a huge component of the cyber threat. But his explanation to the audience was more than just the what of the attack, it was the background and the economic explanation of the why. The information he gave them had little to do with cyber methods and everything to do with a broad understanding of the perpetrator and the target. My TASC CISO reminded me of how he uses information like this: understanding the context allows him to act on the intelligence by saying, I need to look for these guys where I store my engineering documents, not my control centers. Context allows him to better defend the networks by focusing on what the attackers look for. The point is that enemy intent is as important as enemy capability. Intelligence analysts looking at trends of attacks by the collective Anonymous, for example, concluded that DDoS attacks generally followed media reports about actions that the group disagreed with. Knowing the pattern of behavior enabled preventive action. 2. Intelligence provides indications and warnings. Sometimes a network defender s best defense is to allow an actor to remain in a network to see the pattern of behavior. And warning is important across networks if activity is occurring on a military network, for example, it could also be occurring on a corporate network, and vice versa. We need government and industry to share information with each other. Hold this idea I m going to come back to it in a minute. 3. Intelligence provides a more complete picture full situational awareness, if you will. An intelligence analyst uses all sources of information: the traditional INTs HUMINT, GEOINT, SIGINT, MASINT, and OSINT, or open source, as well as data sources from IDS, or information gathered during law enforcement investigations. There is a danger of approaching cybersecurity with a single-source mentality. Often, intel analysts hear from the private sector or operators let me see the raw intel and I will be able to defend my networks better. The problem is that raw intel is just that unevaluated, unexamined. Take for example the purported hack of an Illinois water system in Raw, unconfirmed data that was leaked to the media indicated the system was hacked by actors in Russia. In fact, after a detailed intelligence analysis, DHS and the FBI concluded was that there was no malicious or unauthorized traffic from Russia or any other foreign location instead, an authorized employee logged onto the system while vacationing abroad. Use of a single source of data had led to the wrong conclusion. But you have to remember that intelligence isn t always fast or perfect. As we move into the cyber domain as a whole, it is essential that we understand the adversary's planning process. This is what the military calls the intelligence preparation of the battlefield. For the 3 TASC PRESENTATION 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
4 cyber threat, preparation involves the threat actors collecting information, developing a strategy, ensuring the capability all before executing it. Intercepting the elements of this planning process is an area where intelligence plays an important role, but it takes time to gather accurate, actionable information. 4. Intelligence provides the information that allows better decisions. Decisions on cybersecurity are rarely made by the CISO or network defenders. They re made in the board room by the CEO and the business lines. Intelligence helps inform those decisions by enabling understanding of the threat, and helping to develop a comprehensive risk assessment. Vulnerability alone doesn t make the business case but articulating the threat in a holistic manner threats to the global supply chain, threats from insider attacks, threats from actors performing industrial espionage, and threats from actors probing for weaknesses as part of operational planning allows better decisions about resource allocation and risk analysis. In other words, intelligence helps reduce uncertainty for the decision maker. Together, the CIO, CTO, CISO and intelligence professionals make the case to the decision maker. For intelligence professionals to deliver mission-essential information, the network defenders need to provide crisp requirements. We don t always know what the user needs. In the DHS Office of Intelligence and Analysis, we developed a comprehensive list of Standing Information Needs. When we first went to our customers back in 2004 or 2005, we asked What intelligence information do you need to do your mission? We got the response I don t know whaddya got? To be effective in the realm of cybersecurity or any domain intelligence needs to know the specific requirements from the beneficiaries of that intelligence. For example: Requirements What cyber data are anomalous? Where do they come from? What specific questions do you need answered? And in what timelines? This should be an iterative discussion between the intelligence providers and the users. Data The relationship between the network operators and defenders and the intelligence providers is a symbiotic one. Intelligence analysts take data from operational sensors and logs and fuse them with all-source intelligence information to arrive at a comprehensive threat analysis and provide information about trends, tactics, techniques and procedures back to the customer. That information in turn informs the IDS which provide data back. Common understanding A dialogue with network defenders to understand what is possible and what is not possible; to understand the legal requirements and restrictions with regard to the protection of privacy; to understand the difference between law enforcement activities and intelligence; and to understand what is doable in a short timeframe versus what can be accomplished in a longer term. Additionally, the users have to be willing to accept the intelligence information without visibility into protected sources 4 TASC PRESENTATION 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
5 and methods. This willingness especially when we talk about government and private sector relationships develops as trust increases. All this leads me back to the concept of information sharing. The new executive order on cybersecurity and the accompanying presidential policy directive on critical infrastructure security and resilience recognize that both the public and private sectors hold complementary information that must be made available in both directions if we are to truly secure our cyberspace. Under the order, federal agencies are required to produce unclassified reports of threats to relevant U.S. companies in a timely manner. The challenge here is not so much sharing the data, but rather sharing it in a way that makes connections intelligence personnel are trained to meet this challenge, provided that they know what the operators need and that they can deliver actionable and tailored information. There have already been some successes in this area the DIB pilot and the FS-ISAC have demonstrated sharing relationships which, while not perfect, are examples of what we can look toward. The intel community needs to become more transparent and provide the necessary information in a way that is timely, useful and actionable without revealing their sources and methods. Speaking from experience, I can say we often speak to ourselves, rather than getting information about the threat to the user. Hopefully the dialogue sparked by the new EO and, ultimately, by legislation, will facilitate this sharing of essential information. There s an important point to make here. In the changing world of cyber intelligence, we have to recognize that our approaches can be impractical. In the intelligence world, a study can take months to get through the review and publication process. By the time a report reaches the operator, the information is useless. We have to quickly assess what information is operational, get it out and get it out fast. US-CERT bulletins are a good example of operational reports that need to be shared widely and quickly. There are other policy questions as well that must be answered what triggers a move from DEFCON3 to DEFCON1? When does corporate espionage or even the theft of intellectual property merit a counterattack? Our government leaders need to define the policies and protocols for monitoring, assessment and appropriate response. But policy and doctrine aren t the missions of the intelligence officer, so I just leave these as questions the cybersecurity community all parts of it needs to address. Our shared goal is quite clear: provide a policy platform and operational structure that ensures robust and resilient cybersecurity for government and industry. Our digital infrastructure is a national strategic asset, and its protection is a national security priority. With a more holistic and collaborative approach that integrates a complete picture of the cyber-scape from focused and tailored intelligence with the catching and patching of network defenders, we can push the cyber border further out from our networks and do 5 TASC PRESENTATION 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
6 more to prevent attacks, rather than focus primarily on response, mitigation and recovery. In the dynamic cyber environment, success does require incredibly sophisticated technical savvy - those complicated equations on that t-shirt that I don t understand. But success also requires that we apply the insight and expertise of a broad spectrum of stakeholders. Only by working in strong partnership across the intelligence community, network defenders and government and corporate leaders will we keep our cyber enemies at bay. Thank you. About TASC Founded in 1966, TASC, Inc., helps solve complex national security and public safety challenges by providing advanced systems engineering, integration and decision-support services to the Intelligence Community, Department of Defense and civilian agencies of the federal government. With about 5,000 employees in 40 locations, TASC generates more than $1.5 billion in annual revenue. For more information and career opportunities, visit our website 6 TASC PRESENTATION 4801 Stonecroft Boulevard Chantilly, VA TASC.COM
The Comprehensive National Cybersecurity Initiative
The Comprehensive National Cybersecurity Initiative President Obama has identified cybersecurity as one of the most serious economic and national security challenges we face as a nation, but one that we
The Senior Executive s Role in Cybersecurity. By: Andrew Serwin and Ron Plesco.
The Senior Executive s Role in Cybersecurity. By: Andrew Serwin and Ron Plesco. 1 Calling All CEOs Are You Ready to Defend the Battlefield of the 21st Century? It is not the norm for corporations to be
Middle Class Economics: Cybersecurity Updated August 7, 2015
Middle Class Economics: Cybersecurity Updated August 7, 2015 The President's 2016 Budget is designed to bring middle class economics into the 21st Century. This Budget shows what we can do if we invest
CYBER4SIGHT TM THREAT INTELLIGENCE SERVICES ANTICIPATORY AND ACTIONABLE INTELLIGENCE TO FIGHT ADVANCED CYBER THREATS
CYBER4SIGHT TM THREAT INTELLIGENCE SERVICES ANTICIPATORY AND ACTIONABLE INTELLIGENCE TO FIGHT ADVANCED CYBER THREATS PREPARING FOR ADVANCED CYBER THREATS Cyber attacks are evolving faster than organizations
Cyber4sight TM Threat. Anticipatory and Actionable Intelligence to Fight Advanced Cyber Threats
Cyber4sight TM Threat Intelligence Services Anticipatory and Actionable Intelligence to Fight Advanced Cyber Threats Preparing for Advanced Cyber Threats Cyber attacks are evolving faster than organizations
Applying machine learning techniques to achieve resilient, accurate, high-speed malware detection
White Paper: Applying machine learning techniques to achieve resilient, accurate, high-speed malware detection Prepared by: Northrop Grumman Corporation Information Systems Sector Cyber Solutions Division
Cyber Threats Insights from history and current operations. Prepared by Cognitio May 5, 2015
Cyber Threats Insights from history and current operations Prepared by Cognitio May 5, 2015 About Cognitio Cognitio is a strategic consulting and engineering firm led by a team of former senior technology
Lessons from Defending Cyberspace
Lessons from Defending Cyberspace The Challenge of Addressing National Cyber Risk Andy Purdy Workshop on Cyber Security Center for American Studies, Christopher Newport College 10 28-2009 Cyber Threat
CYBER SECURITY GUIDANCE
CYBER SECURITY GUIDANCE With the pervasiveness of information technology (IT) and cyber networks systems in nearly every aspect of society, effectively securing the Nation s critical infrastructure requires
Gregg Gerber. Strategic Engagement, Emerging Markets
Government of Mauritius Gregg Gerber Strategic Engagement, Emerging Markets 2 (Advanced) Persistent Targeted attacks 2010 2011 2012 Time 1986-1991 Era of Discovery 1992-1998 Era of Transition 1999-2005
WRITTEN TESTIMONY OF
WRITTEN TESTIMONY OF KEVIN MANDIA CHIEF EXECUTIVE OFFICER MANDIANT CORPORATION BEFORE THE SUBCOMMITTEE ON CRIME AND TERRORISM JUDICIARY COMMITTEE UNITED STATES SENATE May 8, 2013 Introduction Thank you
COUNTERINTELLIGENCE. Protecting Key Assets: A Corporate Counterintelligence Guide
COUNTERINTELLIGENCE O F F I C E O F T H E N A T I O N A L C O U N T E R I N T E L L I G E N C E Protecting Key Assets: A Corporate Counterintelligence Guide E X E C U T I V E Counterintelligence for the
The virtual battle. by Mark Smith. Special to INSCOM 4 INSCOM JOURNAL
The virtual battle by Mark Smith Special to INSCOM 4 INSCOM JOURNAL For many, the term cyberspace conjures up images of science fiction, the stuff of novels and movies. In fact, in 1994 this was the term
Cybersecurity: Mission integration to protect your assets
Cybersecurity: Mission integration to protect your assets C Y B E R S O L U T I O N S P O L I C Y O P E R AT I O N S P E O P L E T E C H N O L O G Y M A N A G E M E N T Ready for what s next Cyber solutions
THE 411 ON CYBERSECURITY, INFORMATION SHARING AND PRIVACY
THE 411 ON CYBERSECURITY, INFORMATION SHARING AND PRIVACY DISCLAIMER Views expressed in this presentation are not necessarily those of our respective Departments Any answers to questions are our own opinions
US-CERT Year in Review. United States Computer Emergency Readiness Team
US-CERT Year in Review United States Computer Emergency Readiness Team CY 2012 US-CERT Year in Review United States Computer Emergency Readiness Team CY 2012 What s Inside Welcome 1 Vison, Mission, Goals
Cybersecurity Delivering Confidence in the Cyber Domain
Cybersecurity Delivering Confidence in the Cyber Domain With decades of intelligence and cyber expertise, Raytheon offers unmatched, full-spectrum, end-to-end cyber solutions that help you secure your
DoD Strategy for Defending Networks, Systems, and Data
DoD Strategy for Defending Networks, Systems, and Data November 13, 2013 Department DoDD of Defense Chief Information Officer DoD Strategy for Defending Networks, Systems, and Data Introduction In July
Working with the FBI
Working with the FBI WMACCA Data Privacy & Security Conference September 17, 2014 Individuals Organized Crime Syndicates Hacktivist Groups Nation States Nation-States Individuals Industry Law Enforcement
Cyber-Security Risk- IP Theft and Data Breaches Protecting your Crown Jewels Internally and with Your Key Third Parties
Cyber-Security Risk- IP Theft and Data Breaches Protecting your Crown Jewels Internally and with Your Key Third Parties Pamela Passman President and CEO Center for Responsible Enterprise And Trade (CREATe.org)
THE SECURITY EXECUTIVE S GUIDE TO A SECURE INBOX. How to create a thriving business through email trust
THE SECURITY EXECUTIVE S GUIDE TO A SECURE INBOX How to create a thriving business through email trust FORWARD Today the role of the CISO is evolving rapidly. Gone are the days of the CISO as primarily
Federal Bureau of Investigation
Federal Bureau of Investigation SSA John Caruthers Cyber Criminal Section SSA Kenneth Schmutz Cyber National Security Section April 11, 2012 FBI Mission Cyber Threats FBI Response 1. Protect the United
(U) Appendix D: Evaluation of the Comprehensive National Cybersecurity Initiative
(U) Appendix D: Evaluation of the Comprehensive National Cybersecurity Initiative (U) Presidential Directive NSPD 54/HSPD 23, Cybersecurity Policy, established United States policy, strategy, guidelines,
Keynote: FBI Wednesday, February 4 noon 1:10 p.m.
Keynote: FBI Wednesday, February 4 noon 1:10 p.m. Speaker: Leo Taddeo Special Agent in Change, Cyber/Special Operations Division Federal Bureau of Investigation Biography: Leo Taddeo Leo Taddeo is the
ITAR Compliance Best Practices Guide
ITAR Compliance Best Practices Guide 1 Table of Contents Executive Summary & Overview 3 Data Security Best Practices 4 About Aurora 10 2 Executive Summary & Overview: International Traffic in Arms Regulations
STATEMENT BY DAVID DEVRIES PRINCIPAL DEPUTY DEPARTMENT OF DEFENSE CHIEF INFORMATION OFFICER BEFORE THE
STATEMENT BY DAVID DEVRIES PRINCIPAL DEPUTY DEPARTMENT OF DEFENSE CHIEF INFORMATION OFFICER BEFORE THE HOUSE OVERSIGHT AND GOVERNMENT REFORM COMMITTEE S INFORMATION TECHNOLOGY SUBCOMMITTEE AND THE VETERANS
Testimony of Matthew Rhoades Director Cyberspace & Security Program Truman National Security Project & Center for National Policy
Testimony of Matthew Rhoades Director Cyberspace & Security Program Truman National Security Project & Center for National Policy House Committee on Homeland Security Subcommittee on Cybersecurity, Infrastructure
STATEMENT OF MR. THOMAS ATKIN ACTING ASSISTANT SECRETARY OF DEFENSE FOR HOMELAND DEFENSE AND GLOBAL SECURITY OFFICE OF THE SECRETARY OF DEFENSE;
STATEMENT OF MR. THOMAS ATKIN ACTING ASSISTANT SECRETARY OF DEFENSE FOR HOMELAND DEFENSE AND GLOBAL SECURITY OFFICE OF THE SECRETARY OF DEFENSE; LIEUTENANT GENERAL JAMES K. MCLAUGHLIN DEPUTY COMMANDER,
Cyber Security. BDS PhantomWorks. Boeing Energy. Copyright 2011 Boeing. All rights reserved.
Cyber Security Automation of energy systems provides attack surfaces that previously did not exist Cyber attacks have matured from teenage hackers to organized crime to nation states Centralized control
Cyber Watch. Written by Peter Buxbaum
Cyber Watch Written by Peter Buxbaum Security is a challenge for every agency, said Stanley Tyliszczak, vice president for technology integration at General Dynamics Information Technology. There needs
Preventing and Defending Against Cyber Attacks June 2011
Preventing and Defending Against Cyber Attacks June 2011 The Department of Homeland Security (DHS) is responsible for helping Federal Executive Branch civilian departments and agencies secure their unclassified
Cyber Information-Sharing Models: An Overview
PARTNERSHIP Cyber Information-Sharing Models: An Overview October 2012. The MITRE Corporation. All rights reserved. Approved for Public Release. Case Number 11-4486. Distribution Unlimited. Table of Contents
Who s Doing the Hacking?
Who s Doing the Hacking? 1 HACKTIVISTS Although the term hacktivist refers to cyber attacks conducted in the name of political activism, this segment of the cyber threat spectrum covers everything from
Microsoft s cybersecurity commitment
Microsoft s cybersecurity commitment Published January 2015 At Microsoft, we take the security and privacy of our customers data seriously. This focus has been core to our culture for more than a decade
White Paper: Leveraging Web Intelligence to Enhance Cyber Security
White Paper: Leveraging Web Intelligence to Enhance Cyber Security October 2013 Inside: New context on Web Intelligence The need for external data in enterprise context Making better use of web intelligence
RETHINKING CYBER SECURITY
RETHINKING CYBER SECURITY Introduction Advanced Persistent Threats (APTs) and advanced malware have been plaguing IT professionals for over a decade. During that time, the traditional cyber security vendor
Managing the Unpredictable Human Element of Cybersecurity
CONTINUOUS MONITORING Managing the Unpredictable Human Element of Cybersecurity A WHITE PAPER PRESENTED BY: May 2014 PREPARED BY MARKET CONNECTIONS, INC. 14555 AVION PARKWAY, SUITE 125 CHANTILLY, VA 20151
Cyber/IT Risk: Threat Intelligence Countering Advanced Adversaries Jeff Lunglhofer, Principal, Booz Allen. 14th Annual Risk Management Convention
Cyber/IT Risk: Threat Intelligence Countering Advanced Adversaries Jeff Lunglhofer, Principal, Booz Allen 14th Annual Risk Management Convention New York, New York March 13, 2013 Today s Presentation 1)
Critical Infrastructure & Supervisory Control and Data Acquisition (SCADA) CYBER PROTECTION
Critical Infrastructure & Supervisory Control and Data Acquisition (SCADA) CYBER PROTECTION ALBERTO AL HERNANDEZ, ARMY RESERVE OFFICER, SOFTWARE ENGINEER PH.D. CANDIDATE, SYSTEMS ENGINEERING PRESENTATION
AB 1149 Compliance: Data Security Best Practices
AB 1149 Compliance: Data Security Best Practices 1 Table of Contents Executive Summary & Overview 3 Data Security Best Practices 4 About Aurora 10 2 Executive Summary & Overview: AB 1149 is a new California
CHAPTER 3 : INCIDENT RESPONSE THREAT INTELLIGENCE GLOBAL THREAT INTELLIGENCE REPORT 2015 :: COPYRIGHT 2015 NTT INNOVATION INSTITUTE 1 LLC
: INCIDENT RESPONSE THREAT INTELLIGENCE 1 THREAT INTELLIGENCE How it applies to our clients, and discuss some of the key components and benefits of a comprehensive threat intelligence strategy. Threat
Cyber Security Strategy
NEW ZEALAND S Cyber Security Strategy 2015 A secure, resilient and prosperous online New Zealand Ministerial Foreword The internet and technology have become a fundamental element in our lives. We use
FBI AND CYBER SECURITY
FBI AND CYBER SECURITY SSA John Caruthers SSA Ken Schmutz SSA Tom Winterhalter Mission The FBI is the only U.S. agency charged with the authority to investigate both criminal and national security investigations.
Confrontation or Collaboration?
Confrontation or Collaboration? Congress and the Intelligence Community Cyber Security and the Intelligence Community Eric Rosenbach and Aki J. Peritz Cyber Security and the Intelligence Community The
Cybersecurity Enhancement Account. FY 2017 President s Budget
Cybersecurity Enhancement Account FY 2017 President s Budget February 9, 2016 Table of Contents Section 1 Purpose... 3 1A Mission Statement... 3 1.1 Appropriations Detail Table... 3 1B Vision, Priorities
Testimony of. Mr. Anish Bhimani. On behalf of the. Financial Services Information Sharing and Analysis Center (FS-ISAC) before the
Testimony of Mr. Anish Bhimani On behalf of the Financial Services Information Sharing and Analysis Center (FS-ISAC) before the Committee on Homeland Security United States House of Representatives DHS
Big Data and Security: At the Edge of Prediction
Big Data and Security: At the Edge of Prediction Mark Seward Splunk Inc. Fred Wilmot Splunk Inc. Session ID: Session Classification: SPO2-T17 Intermediate The Way Cyber Adversaries Think Where is the most
An Overview of Large US Military Cybersecurity Organizations
An Overview of Large US Military Cybersecurity Organizations Colonel Bruce D. Caulkins, Ph.D. Chief, Cyber Strategy, Plans, Policy, and Exercises Division United States Pacific Command 2 Agenda United
Cybersecurity Primer
Cybersecurity Primer August 15, 2014 National Journal Presentation Credits Producer: David Stauffer Director: Jessica Guzik Cybersecurity: Key Terms Cybersecurity Information security applied to computers
Preventing and Defending Against Cyber Attacks November 2010
Preventing and Defending Against Cyber Attacks November 2010 The Nation s first ever Quadrennial Homeland Security Review (QHSR), delivered to Congress in February 2010, identified safeguarding and securing
CYBER SECURITY Audit, Test & Compliance
www.thalescyberassurance.com CYBER SECURITY Audit, Test & Compliance 02 The Threat 03 About Thales 03 Our Approach 04 Cyber Consulting 05 Vulnerability Assessment 06 Penetration Testing 07 Holistic Audit
Into the cybersecurity breach
Into the cybersecurity breach Tim Sanouvong State Sector Cyber Risk Services Deloitte & Touche LLP April 3, 2015 Agenda Setting the stage Cyber risks in state governments Cyber attack vectors Preparing
Cybersecurity in SMEs: Evaluating the Risks and Possible Solutions. BANCHE E SICUREZZA 2015 Rome, Italy 5 June 2015 Arthur Brocato, UNICRI
Cybersecurity in SMEs: Evaluating the Risks and Possible Solutions BANCHE E SICUREZZA 2015 Rome, Italy 5 June 2015 Arthur Brocato, UNICRI UNICRI s Main Goals The United Nations Interregional Crime and
WHITE PAPER. Attack the Attacker HOW A MANAGED SECURITY SERVICE IMPROVES EFFICIENCY AND SAVES COST
WHITE PAPER Attack the Attacker HOW A MANAGED SECURITY SERVICE IMPROVES EFFICIENCY AND SAVES COST Table of Contents THE SECURITY MAZE... 3 THE CHALLENGE... 4 THE IMPORTANCE OF MONITORING.... 6 RAPID INCIDENT
Myths and Facts about the Cyber Intelligence Sharing and Protection Act (CISPA)
Myths and Facts about the Cyber Intelligence Sharing and Protection Act (CISPA) MYTH: The cyber threat is being exaggerated. FACT: Cyber attacks are a huge threat to American lives, national security,
Testimony of. Doug Johnson. New York Bankers Association. New York State Senate Joint Public Hearing:
Testimony of Doug Johnson On behalf of the New York Bankers Association before the New York State Senate Joint Public Hearing: Cybersecurity: Defending New York from Cyber Attacks November 18, 2013 Testimony
NATIONAL CYBERSECURITY STRATEGIES: AUSTRALIA AND CANADA
NATIONAL CYBERSECURITY STRATEGIES: AUSTRALIA AND CANADA JOÃO MANUEL ASSIS BARBAS Coronel de Artilharia. Assessor de Estudos do IDN INTRODUCTION Globalization and information and communication technologies
Department of Homeland Security
Department of Homeland Security Cybersecurity Awareness for Colleges and Universities EDUCAUSE Live! July 24, 2014 Overview Dramatic increase in cyber intrusions, data breaches, and attacks at institutions
CLOSING THE DOOR TO CYBER ATTACKS HOW ENTERPRISES CAN IMPLEMENT COMPREHENSIVE INFORMATION SECURITY
CLOSING THE DOOR TO CYBER ATTACKS HOW ENTERPRISES CAN IMPLEMENT COMPREHENSIVE INFORMATION SECURITY CLOSING THE DOOR TO CYBER ATTACKS Cybersecurity and information security have become key challenges for
September 20, 2013 Senior IT Examiner Gene Lilienthal
Cyber Crime September 20, 2013 Senior IT Examiner Gene Lilienthal The following presentation are views and opinions of the speaker and does not necessarily reflect the views of the Federal Reserve Bank
Written Testimony. Dr. Andy Ozment. Assistant Secretary for Cybersecurity and Communications. U.S. Department of Homeland Security.
Written Testimony of Dr. Andy Ozment Assistant Secretary for Cybersecurity and Communications U.S. Department of Homeland Security Before the U.S. House of Representatives Committee on Oversight and Government
How To Create An Insight Analysis For Cyber Security
IBM i2 Enterprise Insight Analysis for Cyber Analysis Protect your organization with cyber intelligence Highlights Quickly identify threats, threat actors and hidden connections with multidimensional analytics
CyberSecurity Solutions. Delivering
CyberSecurity Solutions Delivering Confidence Staying One Step Ahead Cyber attacks pose a real and growing threat to nations, corporations and individuals globally. As a trusted leader in cyber solutions
A Primer on Cyber Threat Intelligence
A Primer on Cyber Threat Intelligence AS ADVERTISED 2 BUZZWORD BINGO! 3 TODAY S CYBER SECURITY CHALLENGES CISOs finding it difficult to define security ROI to executives Short shelf life for CISOs Vastly
Knowing Your Enemy How Your Business is Attacked. Andrew Rogoyski June 2014
Knowing Your Enemy How Your Business is Attacked Andrew Rogoyski June 2014 Why Cyber is the New Security 1986: Lawrence Berkeley NL discovers attempt to copy US Government Information on Arpanet 1988:
Cyber-Crime, Cyber-Espionage, Cyber-War, & Cyber-Threats: An Exploration of Illegal Conduct & Warfare in the Cyber-World
Cyber-Crime, Cyber-Espionage, Cyber-War, & Cyber-Threats: An Exploration of Illegal Conduct & Warfare in the Cyber-World Moderator: Panelists: Honorable Preet Bharara, United States Attorney, Southern
Cyber Resilience Implementing the Right Strategy. Grant Brown Security specialist, CISSP @TheGrantBrown
Cyber Resilience Implementing the Right Strategy Grant Brown specialist, CISSP @TheGrantBrown 1 2 Network + Technology + Customers = $$ 3 Perfect Storm? 1) Increase in Bandwidth (extended reach) 2) Available
POTOMAC INSTITUTE FOR POLICY STUDIES. Revolution in Intelligence Affairs: Transforming Intelligence for Emerging Challenges
Revolution in Intelligence Affairs: Transforming Intelligence for Emerging Challenges Synopsis Seminar #3 : Domestic Information Challenges and Tactical vs. National Requirements Who Should Do Domestic
Covert Operations: Kill Chain Actions using Security Analytics
Covert Operations: Kill Chain Actions using Security Analytics Written by Aman Diwakar Twitter: https://twitter.com/ddos LinkedIn: http://www.linkedin.com/pub/aman-diwakar-ccie-cissp/5/217/4b7 In Special
Presidential Summit Reveals Cybersecurity Concerns, Trends
Portfolio Media. Inc. 860 Broadway, 6th Floor New York, NY 10003 www.law360.com Phone: +1 646 783 7100 Fax: +1 646 783 7161 [email protected] Presidential Summit Reveals Cybersecurity Concerns,
Cyber Defence Capability Assessment Tool (CDCAT ) Improving cyber security preparedness through risk and vulnerability analysis
Cyber Defence Capability Assessment Tool (CDCAT ) Improving cyber security preparedness through risk and vulnerability analysis An analogue approach to a digital world What foundations is CDCAT built on?
Actions and Recommendations (A/R) Summary
Actions and Recommendations (A/R) Summary Priority I: A National Cyberspace Security Response System A/R 1-1: DHS will create a single point-ofcontact for the federal government s interaction with industry
S. ll IN THE SENATE OF THE UNITED STATES
OLL0 TH CONGRESS ST SESSION S. ll To secure the United States against cyber attack, to improve communication and collaboration between the private sector and the Federal Government, to enhance American
Cyber Security: Confronting the Threat
09 Cyber Security: Confronting the Threat Cyber Security: Confronting the Threat 09 In Short Cyber Threat Awareness and Preparedness Active Testing Likelihood of Attack Privacy Breaches 9% 67% Only 9%
The promise and pitfalls of cyber insurance January 2016
www.pwc.com/us/insurance The promise and pitfalls of cyber insurance January 2016 2 top issues The promise and pitfalls of cyber insurance Cyber insurance is a potentially huge but still largely untapped
Hearing before the House Permanent Select Committee on Intelligence. Homeland Security and Intelligence: Next Steps in Evolving the Mission
Hearing before the House Permanent Select Committee on Intelligence Homeland Security and Intelligence: Next Steps in Evolving the Mission 18 January 2012 American expectations of how their government
CYBER SECURITY INFORMATION SHARING & COLLABORATION
Corporate Information Security CYBER SECURITY INFORMATION SHARING & COLLABORATION David N. Saul Senior Vice President & Chief Scientist 28 June 2013 Discussion Flow The Evolving Threat Environment Drivers
The FBI Cyber Program. Bauer Advising Symposium //UNCLASSIFIED
The FBI Cyber Program Bauer Advising Symposium October 11, 2012 Today s Agenda What is the threat? Who are the adversaries? How are they attacking you? What can the FBI do to help? What can you do to stop
Developing a Mature Security Operations Center
Developing a Mature Security Operations Center Introduction Cybersecurity in the federal government is at a crossroads. Each month, there are more than 1.8 billion attacks on federal agency networks, and
Cyber Incident Annex. Cooperating Agencies: Coordinating Agencies:
Cyber Incident Annex Coordinating Agencies: Department of Defense Department of Homeland Security/Information Analysis and Infrastructure Protection/National Cyber Security Division Department of Justice
Secure Software Development Trends in the Oil & Gas Sectors. How the Microsoft Security Development Lifecycle helps protect critical industries
Secure Software Development Trends in the Oil & Gas Sectors How the Microsoft Security Development Lifecycle helps protect critical industries Secure Software Development Trends in the Oil & Gas Sectors
Retail Security: Enabling Retail Business Innovation with Threat-Centric Security.
Retail Security: Enabling Retail Business Innovation with Threat-Centric Security. 2015 Cisco and/or its affiliates. All rights reserved. This document is Cisco public information. (1110R) 1 In the past
