Redscan - Insider threat case study

Post on 08-Jan-2017

566 views 0 download

transcript

Redscan Managed Security ServicesManaging Information Security Risk

The Insider ThreatDate: 14/10/15

Team of technical information security experts

Redscan Ltd - Environment

13 Years managed security services experience

24/7 UK Security Operations Centre

21 Staff Members

What we do to protect ourselves

Started with:

Risk Assessment

Policies

Processes

Procedures

What we do to protect ourselves

Resulted in:

Certifications:

ISO9001

ISO27001

Cyber Essentials – just about to get Cyber Essentials +

PCI-DSS Compliant

What we do to protect ourselvesResulted in:

Improved background checks – 6 years:

Employment Evidence of employment References

Residential Evidence of residence References

Qualification checks

Credit checks

Criminal record checks

Social media checks/Internet presence

What we do to protect ourselves

Resulted in:

Assumption of permanent breach/malicious activity

Hardened internal systems

Defence in Depth

Recording logs for forensic purposes

Internal vulnerability scans

Internal Penetration Tests

Redscan’s ThreatDetect service

Thank You