[wroclaw #3] 50 shadows of company's infosec

22

Upload: owasp

Post on 15-Apr-2017

64 views

Category:

Internet


1 download

TRANSCRIPT

Page 1: [Wroclaw #3] 50 shadows of company's infosec
Page 2: [Wroclaw #3] 50 shadows of company's infosec

50 Shadows of Company's

InfoSec - Going Inside

Igor Beliaiev

Page 3: [Wroclaw #3] 50 shadows of company's infosec

whoami

Security Engineer

OWASP Lviv memberIgor Beliaiev

Page 4: [Wroclaw #3] 50 shadows of company's infosec

Red Teaming

A red team is an independent group that challenges an organization to improve its effectiveness.

Penetration testers assess organization security, often unbeknownst to client staff. This type of Red Team provides a more realistic picture of the security readiness than announced assessments.

(c) Wikipedia

Page 5: [Wroclaw #3] 50 shadows of company's infosec

Red Teaming … of the airport security

95% failure rate67 out of 70

Page 6: [Wroclaw #3] 50 shadows of company's infosec

%companyname

Page 7: [Wroclaw #3] 50 shadows of company's infosec

Compliance vs Security

Page 8: [Wroclaw #3] 50 shadows of company's infosec

Attack planning

The weakest part in security?

The security level of the system is

determined by its most insecure element

The most valuable information in company?

PEOPLEMONEY CLIENTS

Choosing targetsFinance

IT(backups, access, data)

AccountingInfrastructure Legal

Page 9: [Wroclaw #3] 50 shadows of company's infosec

Risks analysis

Technological risks:

Malware/viruses/intrusions

Cyber attacks

Service provider failure

Physical security (f.e. loss of devices)

Data related vulnerabilities

Phishing

Human risks:

Human error/mistakes

Insider sabotage/theft

Lack of skills

Lack of knowledge

Lack of guidance

Page 10: [Wroclaw #3] 50 shadows of company's infosec

What is Social Engineering?

Page 11: [Wroclaw #3] 50 shadows of company's infosec

Social Engineering Works

Page 12: [Wroclaw #3] 50 shadows of company's infosec
Page 13: [Wroclaw #3] 50 shadows of company's infosec

Ask to use your USB flash

Page 14: [Wroclaw #3] 50 shadows of company's infosec

Is it a feature?

Page 15: [Wroclaw #3] 50 shadows of company's infosec

Acting like IT Support

Page 16: [Wroclaw #3] 50 shadows of company's infosec

Accounting

Page 17: [Wroclaw #3] 50 shadows of company's infosec

Finance

Page 18: [Wroclaw #3] 50 shadows of company's infosec

IT support

Page 19: [Wroclaw #3] 50 shadows of company's infosec

Change in mindset needed

Page 20: [Wroclaw #3] 50 shadows of company's infosec
Page 21: [Wroclaw #3] 50 shadows of company's infosec

going inside…SoftServe

Page 22: [Wroclaw #3] 50 shadows of company's infosec

[email protected]: ghost-bel