+ All Categories
Home > Government & Nonprofit > Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Date post: 15-Apr-2017
Category:
Upload: government-technology
View: 66 times
Download: 1 times
Share this document with a friend
12
The Future of Cybersecurity Los Angeles Digital Government Summit 2016 Timothy Lee
Transcript
Page 1: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

The Future of CybersecurityLos Angeles Digital Government Summit 2016

Timothy Lee

Page 2: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Scope – Known Knowns

Known Knowns

Unknown Unknowns

Known

Unknowns

Page 3: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

I. Human Factor Is Key To Cybersecurity

In 2015

• Social Engineering is #1 attack technique (Proofpoint)

• More than 2 billion mobile apps that steal personal data were downloaded (Proofpoint)

• 52% of the root cause of the security breaches are due to human error (CompTIA)

Page 4: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Human Behaviors vs Attack Methods

Human Behaviors

• Trust

• Desire to be helpful

• Fear (unknown, loss, authority)

• Curiosity

• Carelessness

Attack Methods

• Social Engineering (Targeted/Untargeted)

• Water holing

• Trojan / Ransomware

• Social Media / Rogue Apps marketplaces

Page 5: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Recommendation

•User Education and Awareness

•Security Policy and Standards

•Endpoint Security

• Identity and Access Management (IAM)

•Threat Intelligence Service

Page 6: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

II. Collaboration Is Key To Cybersecurity

• On-line, Off-line and Real-time coordination

• Information sharing (one-way / two way)

• Command & Control (C&C)

• Centralized or Distributed

Collaborative Attack vs Collaborative Defense

Page 7: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Recommendation

• Promote Cybersecurity collaboration

• Internal Partners ( SOCs/NOCs; IT Departments)

• External Partners (FBI CyberhoodWatch, NCCIC, ISACs)

• Enhance Situational Awareness (SA) capability (Perception, Comprehension and Projection)

• Establish Threat Intelligence Program (information gathering, analyzing and dissemination)

Page 8: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

III. Digital /Physical Security Convergence

• Stuxnet launched against Nuclear Control Systems, 2007

• Oil Pipeline in turkey explodes in 2008

• Hacking medical devices in 2011

• Blast Furnance in German Steelworks Attacked, 2014

• Blackouts in Ukraine, 2016

Page 9: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Digital Security Model (CIAS)

Digital Security

Confidentiality

Integrity Availability

Safety

• Data (Confidentiality, Integrity and Availability)

• People / Environments (Safety)

Source: Cybersecurity Scenario 2020 Phase 2 – Gartner G00279414

Page 10: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Recommendation

• Identify critical assets and develop a protection strategy

•Promote collaborative culture

•Establish Threat Intelligence progrma

Page 11: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Summary

•User Education and Awareness

•Cybersecurity Program based on Risk Management Framework

•Cybersecurity Collaboration

Page 12: Los Angeles DGS 16 presentation - The Future of Cybersecurity - Timothy Lee

Thank you!


Recommended