cyber security 101: training, awareness, strategies for small to medium sized business

41
Security 101 Training, awareness, and strategies Stephen Cobb, CISSP Senior Security Researcher ESET NA

Upload: stephen-cobb

Post on 14-Jan-2015

147 views

Category:

Internet


1 download

DESCRIPTION

I developed "Cyber Security 101: Training, awareness, strategies for small to medium sized business" for the second annual Small Business Summit on Security, Privacy, and Trust, co-hosted by ADP in New Jersey, October 2013.

TRANSCRIPT

Page 1: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Security 101Training, awareness, and strategies

Stephen Cobb, CISSPSenior Security ResearcherESET NA

Page 2: Cyber Security 101: Training, awareness, strategies for small to medium sized business

The SMB Sweet Spot for the cyber-criminally inclined

Enterprises

SMB “Sweet Spot”

Consumers

Assets worthlooting

Level of protection

Page 3: Cyber Security 101: Training, awareness, strategies for small to medium sized business

The challenge

• Organizations of every type rely on computers to handle information

• Everyone today is a computer user

• Most have no security training• Lack of security

training leads to problems

Page 4: Cyber Security 101: Training, awareness, strategies for small to medium sized business

How big is the challengeWe asked U.S. consumers if they had ever received any computer security training

No: 68%

Yes:

32%

*Savitz Research for ESET, 2012

Page 5: Cyber Security 101: Training, awareness, strategies for small to medium sized business

68% is sadly consistentWe asked working adults in the U.S. if they had ever received any computer security training

No: 68%

Yes:

32%

*Harris poll for ESET, 2012

Page 6: Cyber Security 101: Training, awareness, strategies for small to medium sized business

73% is even worseWe asked adults in U.S. who use social media if they had ever received online safety training

No: 73%

Yes:

27%

*Harris poll for ESET, 2012

Page 7: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Security training is not yet part of our society*

• This has serious implications for your business

• 93% of American adults say they’ve had no computer security training in the last 12 months

• How many of them work for you, or for your clients, suppliers, etc?

*Savitz Research for ESET, 2012

Page 8: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Some problems that lack of security training can cause

• Unauthorized access to information

• Loss of access to information

• Loss of information

• Corruption of information

• Theft of information

Page 9: Cyber Security 101: Training, awareness, strategies for small to medium sized business

The implications are non-trivial

• Loss of revenue• Loss of business• Fines, lawsuits, headlines• Unbudgeted expenses– Breach costs currently estimated

at around $190 per record exposed*

– 5,263 records = $1 million hit

*Ponemon Institute

Page 10: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Trojan terminates escrow firm

• $1.1 million wired to China and could not be retrieved

• Firm was closed by state law, now in receivership, 9 people out of a job

• So what’s the best weapon for keeping that kind of Trojan code out of your company’s system?

Page 11: Cyber Security 101: Training, awareness, strategies for small to medium sized business

A well-trained workforce

• Knows not to click on suspicious links in email or social media

• Knows to report strange activity (e.g. the two-factor authentication not working)

• Knows to scan all incoming files for malware– Email, USB drives

Page 12: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Does training make a difference?

• Yes• A significant percentage of

problems can be averted, or their impact minimized, if more employees get better security training and education*

*A bunch of different studies in recent years

Page 13: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Security training or awareness

• What’s the difference?• Training makes sure people at

different levels of IT engagement have the right knowledge to execute their roles securely

• Awareness makes sure all people at all levels know what to look out for

Page 14: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Not that kind of actor…

Do your employees know what motivates bad actors?

IMPACTADVANTAGEMONEY

CREDENTIALS

Page 15: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Do you know how the bad guys operate?

Specialization Modularity

Division of labor Standards

Markets

Page 16: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Taken to exploit site

Malware server

PopularAttackTechnique

!?**!

User clicks a link Gets infected/owned

Command & Control

Page 17: Cyber Security 101: Training, awareness, strategies for small to medium sized business
Page 18: Cyber Security 101: Training, awareness, strategies for small to medium sized business
Page 19: Cyber Security 101: Training, awareness, strategies for small to medium sized business

• RAT has full access to victim PC• And its network connections• Search and exfiltrate files• Access to webcam and audio• Scrape passwords• Execute system functions• Chat with victim

Page 20: Cyber Security 101: Training, awareness, strategies for small to medium sized business

What happens next?

Page 21: Cyber Security 101: Training, awareness, strategies for small to medium sized business
Page 22: Cyber Security 101: Training, awareness, strategies for small to medium sized business
Page 23: Cyber Security 101: Training, awareness, strategies for small to medium sized business
Page 24: Cyber Security 101: Training, awareness, strategies for small to medium sized business

So how do we move forward?

Page 25: Cyber Security 101: Training, awareness, strategies for small to medium sized business

The road map: A B C D E F

• Assess your assets, risks, resources

• Build your policy• Choose your controls• Deploy controls • Educate employees, execs,

vendors• Further assess, audit, testA B C D E

FF E D C B A

Technology

Page 26: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Assess assets, risks, resources

• Assets: digital, physical – If you don’t know what you’ve got

you can’t protect it!• Risks–Who or what is the threat?

• Resources– In house, hired, partners, vendors,

trade groups, associations

Page 27: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Build your policy

• Security begins with policy• Policy begins with C-level buy-in• High-level commitment to

protecting the privacy and security of data

• Then a set of policies that spell out the protective measures, the controls that will be used

Page 28: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Choose controls to enforce policies• For example: – Policy: Only authorized employees

can access sensitive data – Controls: • Require identification and

authentication of all employees via unique user name and password• Limit access through application(s) by

requiring authentication• Log all access

Page 29: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Deploy controls, ensure they work

• Put control in place; for example, antivirus (anti-malware, anti-phishing, anti-spam)

• Test control– Does it work technically?– Does it “work” with your work?– Can employees work it?

Page 30: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Educate everyone

• Everyone needs to know –What the security policies are– How to comply with them through

proper use of controls• Pay attention to any information-

sharing relationships – Vendors, partners, even clients

• Clearly state consequences of failure to comply

Page 31: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Who gets trained?

• Everyone, but not in the same way, break it down:– All-hands training– IT staff training– Security staff training

Page 32: Cyber Security 101: Training, awareness, strategies for small to medium sized business

How to deliver training

• In person• Online• On paper• In house• Outside contractor• Mix and match• Be creative

Page 33: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Incentives?

• Yes!• To launch programs, push

agendas• Prizes do work• But also make security part of

every job description and evaluation

Page 34: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Use your internal organs

• Of communication!• Newsletter• Intranet• Bulletin board• Meetings• Company-wide email

Page 35: Cyber Security 101: Training, awareness, strategies for small to medium sized business

How to do awareness

• Make it fun• Make it relevant• Leverage the news• Bear in mind that everyone

benefits from greater awareness, at work and at home

Page 36: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Resources to tap

• Industry associations• FS-ISAC, NH-ISAC, others• CompTIA, SBA, BBB• ISSA, ISACA, SANS, (ISC)2

• Local colleges and universities• Securing Our eCity

Page 37: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Need more motivation?

• Security training is the law– HIPAA– Red Flag Identity Theft Prevention– Gramm-Leach-Bliley, Sarbanes-

Oxley– FISMA

• Or required by industry– PCI Data Security Standard

Page 38: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Or just plain required

• To get that big juicy contract• Many companies now require

suppliers to certify that they have security training and awareness programs in place as a condition of doing business

Page 39: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Further assess, audit, test…

• This is a process, not a project• Lay out a plan to assess security on

a periodic basis• Stay up-to-date on emerging

threats• Stay vigilant around change such

as arrivals, departures, functionalityA B C D E

FF E D C B A

Page 40: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Backup and archive

Firewall and scan:Incoming trafficemailsfilesdevicesmedia

Encrypt

MonitorFilter and

monitoroutbound

Authenticateusers

The Technology Slide

Page 41: Cyber Security 101: Training, awareness, strategies for small to medium sized business

Thank you!

[email protected]• WeLiveSecurity.com• www.eset.com• More info in the lobby