staying one step ahead of evolving threats€¦ · staying one step ahead of evolving threats....

30
ISSA CISO Summit Washington, DC Michael Howard Chief Security Advisor and Practice Manager 1 Staying One Step Ahead of Evolving Threats

Upload: others

Post on 27-Jun-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

ISSA CISO Summit

Washington, DC

Michael Howard

Chief Security Advisor and Practice Manager

1

Staying One Step Ahead of Evolving Threats

Page 2: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global
Page 3: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Risks and costs of unprotectedIT environments…

• Cybercrime

– 92% of Forbes Global 2000 companies report data breaches in the past year1

• Compliance infringement

– Regulatory and legal noncompliance costs global organizations

• Internal threats

– Nearly 65% of breaches are accidental, employee negligence or business process failures2

• Financial loss

– Fines, loss of business,damaged reputation,and class-actionlawsuits

1 Ponemon Institute, “Mega Trends in Cyber Security Expert Opinion Study,” May 2013; 2 Ponemon Institute,“2015 Global Cost of a Data Breach Study”, October 2015.

$7.7MAverage cost to resolve a cyber-crime incident2

©2016 HP, Inc. All rights reserv ed. | The inf ormation contained herein is subject to change without notice. | HP Conf idential3

Page 4: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

25 BILLION “CONNECTED THINGS”BY 2020

Page 5: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

The weakest link

5

Page 6: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

40%

https://www.bloomberg.com/news/articles/2017-01-19/data-breaches-hit-record-in-2016-as-dnc-wendy-s-co-hacked (Identity Thef t Resource Center)

More data breaches in 2016

Page 7: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

AN UNPRECEDENTED AGE OF HACKING

Page 8: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

EMEA PrintOn! 2017

State Actors

Crime as a

service

Hacktivist organisations

Script

Kiddies

Page 9: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

PRINTER HACKS ARE NOT AN EXCEPTION

Page 10: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

10

“I probe around for a multifunction printer and see that it is configured with default passwords. Great I am in” ………..Hackers Playbook by Peter Kim.

“YES! We've compromised a number of companies using printers as our initial foothold, we move laterally from the printer, find Active Directory, query it with an account from the printer and bingo, we hit GOLD”

Page 11: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

11

2011

Page 12: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

12

2015

Page 13: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

13

20162016 April

Page 14: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

More data

Ponemon Institute, “Insecurity of Netw ork-Connected Printers,” October 2015.

Ponemon Institute, “Annual Global IT Security Benchmark Tracking Study,” March 2015.

IT Report Likely Printer Malware

Infection

Had A PrinterData Breach

64% 60%

ITDMs ARE AWARE OF PRINTER THREATS

Page 15: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

BUT FEW ARETAKING ACTION

“IT

PROFESSIONALS

IGNORE PRINTERS

IN THEIR

ENDPOINT

SECURITY

Only 18% of ITDMs

are concerned about

printer security, while

91% are concerned

about PC security

Page 16: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

THE TIME TO BUILD A SENSE OF URGENCY IS

NOW

Page 17: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

134 different Vulnerabilities

Over 50 modules/attacks

250 different Vulnerabilities

Over 400 modules/attacks

Page 18: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

THE FEATURES OF A MFP – CARRY RISK

Vulnerabilities across device, data & document need to be managed

Mobile printing

Input tray

Storage media

CaptureManagement

Output tray

Network

Control panel

BIOS and firmware

Page 19: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

More data

SECURE THE DEVICE

All 500, 600 series enterprise products now include security features

HP Sure StartKeeps the BIOS safe

Run-Time Intrusion Detection

Keeps the memory safe

HP JetAdvantageSecurity Manager

Keeps the fleet secure

WhitelistingKeeps the firmware safe

Page 20: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Drivers – Legal & RegulatoryCompliance

Page 21: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Assessment Focus Areas

Logical Access Governance Physical Security

Asset Management Security Configuration Data Security

Patching & AV Log Management

& Security Incident

Build & Release

Business Continuity Network Security Information Security

Personal Security System Acquisition

& Development

Access Control

Page 22: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Assessment Baseline Score – Initial Assessment.

No. of Controls Yes No % Compliant

Asset Management 6 4 2 66.67%

Security Governance 10 5 5 50.00%

Security Incident & Logging 6 3 3 50.00%

Logical Access 11 2 9 18.18%

Security Config. 8 0 8 0.00%

Patching & AV 5 4 1 80.00%

Build & Release 5 3 2 60.00%

Data Security 6 3 3 50.00%

Information Security 6 4 2 66.67%

63 28 35 Average = 49.06%

Vertical Industry = 65% , Global = 45%

Page 23: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Assessment Baseline Score – 6 months later.

No. of Controls Yes No % Compliant

Asset Management 8 7 1 87.5%

Security Governance 10 8 2 80%

Security Incident & Logging 9 7 2 78%

Logical Access 11 8 3 72%

Security Config. 8 7 1 87.5%

Patching & AV 7 6 1 86%

Build & Release 7 5 2 71%

Data Security 7 6 1 86.00%

Information Security 7 5 2 71.4%

63 28 35 Average = 79.9%

Vertical Industry = 65% , Global = 45%

Page 24: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Control Question

What controls are in place to identify and track each user activity who has privilege user rights across the print infrastructure ?

• HIPAA 164.312(a)(2)(i) Assign a unique name and/or number for Identifying and tracking user identity. Required.

• ISO27001:2013 A.9.2.5 Review of user access rights.

24 HP Conf idential

Page 25: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Control Question

Does an accurate CMDB (List of printer assets) exist which includes all printers noting the firmware version, owners, software, type of use etc.

25 HP Conf idential

• HIPAA Control164.310(d)(2)(iii).Tracking Assets.

• ISO27001:2013 A.8.1 Inventory of asserts, owners, acceptable usage of asset.

Page 26: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Security Control Question

What controls are in place to protect sensitive or private print jobs and scan jobs while in motion ?

• Reference: 164.312(e)(1) Addressable. ISO27001:2013 A.13.2.3

• HIPAA 164.312(e)(1) Transmission Controls.

HP Conf idential26

Page 27: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Recommendation Examples – Security Advisory Service

Page 28: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Suggested Roadmap: Good Better Best

April June October Jan FY18

Date: Roadmap Goals

Agree roadmap priorities

resources/constraints

Identify parallel projects

Unmanaged Printers

Secure MPS Review

Date:

Good

Patching schedule.

Hardware refresh.

HPSM deployment plan.

AD Integration and/or Secret Server Testing.

Review HP Inc. new policy security settings / NIST std.

Vuln Scans reporting project

HPAC Project Plan

Date:

Better

HPAC/Print Fleet Apps Policy Review

Secure MPS Reporting Status

Syslog Plan

Date

Phase 2 Security Governance Reporting

Follow up PSAS

Date

SIEM Correlation

Date

SIEM Plan

Date

Secure MPS Review

Cyber Security/HP Review

Date

SIEM/Collection

Date:

Best

SIEM Reporting

Account Review Reporting

Patching Reporting

Risk Reporting

Hardening Policy Reporting

Vuln Scan Reporting

Secure MPS GoLive

Secure Dashboard Reporting

Good

Better Best

Page 29: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

Thank YouMichael HowardChief Security Advisor and Practice [email protected] 887-0891

Page 30: Staying One Step Ahead of Evolving Threats€¦ · Staying One Step Ahead of Evolving Threats. Risks and costs of unprotected IT environments… •Cybercrime –92% of Forbes Global

30