defending our digital density. - amazon s3€¦ · defending our digital density. new jersey...

22
The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners. NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration. Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell cyber.nj.gov @NJCybersecurity [email protected]

Upload: others

Post on 06-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Page 2: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

NJ Cybersecurity and Communications Integration Cell

Areas of Responsibility

Digital Resilience

Page 3: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Achieving Digital Resilience

• Prioritize information assets based on business risks.• Provide differentiated protection for the most important

assets.• Integrate cybersecurity into enterprise-wide risk

management and governance processes.• Enlist frontline personnel to protect the information assets

they use.• Integrate cybersecurity into the technology environment.• Deploy active defenses to engage attackers.• Test continuously to improve incident response across

business functions.

Page 4: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Critical Infrastructure Taxonomy

• Chemical• Commercial Facilities• Communications• Critical Manufacturing• Dams• Defense Industrial Base• Emergency Services• Energy

• Financial Services• Food and Agriculture• Government Facilities• Healthcare and Public Health• Information Technology• Nuclear Sector• Transportation• Water and Wastewater

Page 5: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Common Threats

1980Worms

1990Viruses

2000Data Breaches

2010Monetized "viruses”

2018Privacy

2020Health, Human Safety

and Quality of Life

Page 6: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

A

NJCCIC GSN ATTACKSGSN Threat Intelligence

Page 7: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Page 8: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

A

RDP Exposed to Internet

Page 9: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

A

WannaCry – NJ Potential Victims

Page 10: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Security Ecosystem

MS-ISAC

NJCCIC

NJCCIC MembershipUSSS FBI DHS

Page 11: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Security Ecosystem

MS-ISAC

Virus Total

NJCCIC

NJCCIC Membership

Possible Account

Compromise

Notification to Schools

383 K12 NJ - Username/Pwd Combinations

Page 12: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

1.4 Billion Username/PwdCombinations

Email Address:Password

Source – Multiple: Compiled from numerous data breaches

over the past several year

Security Ecosystem

Page 13: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Security Ecosystem

Page 14: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Account Takeover

Page 15: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Page 16: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

The New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) is known as the Division of Cybersecurity of the New Jersey Office of Homeland Security and Preparedness (NJOHSP). NJOHSP helps to direct prevention, detection, protection, response, and recovery planning, not only at the State level, but also at the regional and national levels with our varied partners.

NJOHSP is comprised of four Divisions: Intelligence, Policy and Planning, Cybersecurity, and Administration.

Defending Our Digital Density.

New Jersey Cybersecurity & Communications Integration Cell

cyber.nj.gov@NJCybersecurity [email protected]

Beyond Account Takeover

Page 17: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Newer Initiatives

• Election Security Program of Work• Statewide Information Security Manual•NJ Water Quality Accountability Act• Internship/Training Program

Roadmap• Statewide Threat Grid• Risk Tools and Services• Incident Response• NJ Cyber Corps• Smart NJ

Page 18: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Health, Human Safety, Quality of Life

Page 19: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Intelligent Traffic Systems

Page 20: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Page 21: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

GOV. PHILIP D. MURPHY| LT. GOV. SHEILA Y. OLIVER| DIR. JARED M. MAPLES

NJCCICNew Jersey Cybersecurity & Communications Integration Cell

Questions?

Page 22: Defending Our Digital Density. - Amazon S3€¦ · Defending Our Digital Density. New Jersey Cybersecurity & Communications Integration Cell @NJCybersecurity cyber.nj.gov NJCCIC@cyber.nj.gov

This presentation was prepared by the New Jersey Cybersecurity & Communications Integration Cell (NJCCIC) pursuant to its authority under Executive Order No. 178 of 20 May 2015. Information contained in this document is TLP: WHITE and may be distributed without restriction.

TLP: WHITEJune 14, 2018

Connect With NJCCIC

[email protected]

@NJCybersecuritycyber.nj.gov

609-963-6900 x7865@NJCybersecurity

cyber.nj.gov