mike seddon telecom nz: new zealand internet task force – building trust from the bottom of the...
DESCRIPTION
Mike Seddon, Operational Security Manager, Telecom NZ, and co-founder and Chair of the New Zealand Internet Task Force (NZITF) delivered this presentation at the 2013 Corporate Cyber Security Summit. The event examined cyber threats to Australia’s private sector and focussed on solutions and counter cyber-attacks. For more information about the event, please visit the conference website http://www.informa.com.au/cybersecurityconferenceTRANSCRIPT
![Page 1: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/1.jpg)
New Zealand Internet Task Force
Building Trust at the bo2om of the world Mike Seddon NZITF Chair & Telecom NZ OperaBonal Security Manager
Improving the cyber security posture of New Zealand
![Page 2: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/2.jpg)
Programme
• Who Am I? • New Zealand • The Birth of a Trust Group • The Early Days • Growing Up (coming out) • The Way We Work and What We Have Done • Who’s In and Who’s Out? • An Offer and InvitaKon • Q&A
![Page 3: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/3.jpg)
• $DayJob = OperaKonal Security Manager for Telecom New Zealand
• Chair – NZITF
Who Am I?
![Page 4: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/4.jpg)
New Zealand (Middle Earth)
![Page 5: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/5.jpg)
New Zealand (Middle Earth)
![Page 6: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/6.jpg)
What is the NZITF?
The New Zealand Internet Task Force is a non-‐profit with the mission of improving the cyber security posture of New Zealand
It is a collaboraBve effort based on mutual trust of it’s members
![Page 7: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/7.jpg)
The Birth of a Trust Group
• Following BTF7 and Cyber Storm II cyber exercise in 2008 the NZ Botnet Task Force was formed
• Renamed NZITF early 2009 as the focus evolved and membership expanded
![Page 8: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/8.jpg)
The Early Days • We started small without any big fanfare
• Coordinated by CCIP around other meeKngs
• Shoulder taps and introducKons
• Increasing acKvity levels of NZITF required the need for a Steering Commi`ee to be established in 2009
![Page 9: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/9.jpg)
Growing Up (coming out)
• Formally Incorporated in 2011
• Membership fee structure introduced
• First adverKsed public event
![Page 10: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/10.jpg)
NZITF Board
• Telecom NZ, Mike Seddon (Chair)
• Domain Name Commission, Barry Brailey (Vice Chair)
• Bank of New Zealand, Chester Holmes (Secretary)
• Internet NZ, Dean Pemberton (Treasurer)
• Dept. Internal Affairs, Toni Demetriou
• Vodafone, Steve MarKn
• PWC, Adrian van Hest
![Page 11: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/11.jpg)
What has the NZITF done?
• CoordinaKng technical training • Targeted Threat Workshop • Security Architecture training • Wireless Security Training course • Team Cymru Botnet Forensics
• Honeynet Project and Shadowsever Botnet Defense/Offence courses
• CSIRT introducKon • Open Source Intelligence • Windows Reverse Engineering
![Page 12: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/12.jpg)
What has the NZITF done?
• Support industry and community iniKaKves
• Graduate secondments into industry
• Support research iniKaKves
![Page 13: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/13.jpg)
The Way We Work • Members are nominated and vouched on
• Traffic Light Protocol
• MeeKngs
• Training
• Working Groups
![Page 14: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/14.jpg)
Current NZITF IniBaBves
• NZITF working groups • CREST NZ • Cyber Security Surveying • Cyber Exercising Framework
• Botnet/Malware
• Judiciary Outreach • TRUST.nz • Responsible Disclosure
![Page 15: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/15.jpg)
CREST NZ
• The NZITF set up working group to establish CREST NZ Council of Registered Ethical Security Testers
• No professional voice or representaKon for the penetraKon tesKng industry
• Lack of educaKon and training courses • Skill set shortage in New Zealand • Growing internaKonal cerKficaKon • CREST Australia is now up and running
![Page 16: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/16.jpg)
NaKonal Exercising Framework
• Exercising tests and improves the levels of preparedness for a significant cyber incident
• Develop a framework and schedule for conducKng cyber exercises:
• Scenario Discussions • Table Top Exercises (TTX) • CommunicaKons Checks • NaKonal and InternaKonal Full Play Exercises
![Page 17: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/17.jpg)
Cyber Security Survey
• Limited NZ metrics for decision makers • Want to provide insight into: • Cyber security posture of New Zealand • Impact/cost of cyber crime to New Zealand • What future resources New Zealand requires
• Survey to provide feedback to parKcipants • Conduct annually if valuable
![Page 18: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/18.jpg)
Botnet/Malware
• Assess current NZ infecKon rates • IdenKfy exisKng data sources of botnet infecKons and compromised New Zealand based websites
• Recommend which potenKal miKgaKons would be effecKve in New Zealand and the stakeholders for each
• IdenKfy possible technical and policy based miKgaKons
![Page 19: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/19.jpg)
Judiciary Outreach
• Extending a hand of support and experKse to NZ Judiciary
• Breadth of NZITF membership to draw from
• Training opportuniKes • Expert witnesses
![Page 20: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/20.jpg)
Who’s In and Who’s Out?
![Page 21: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/21.jpg)
An Offer
![Page 23: Mike Seddon Telecom NZ: New Zealand Internet Task Force – Building trust from the bottom of the world](https://reader033.vdocuments.mx/reader033/viewer/2022052820/54c63abd4a795920538b4643/html5/thumbnails/23.jpg)
Improving the cyber security posture of New Zealand