+ All Categories
Home > Documents > Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets...

Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets...

Date post: 17-Aug-2020
Category:
Upload: others
View: 2 times
Download: 0 times
Share this document with a friend
53
Securing the Organization’s IT Assets Amidst COVID-19 Justin Pineda CISSP, GWAPT, GMOB, CEH Principal Consultant, Pineda Cybersecurity [email protected] https://pinedacybersecurity.com/ 1 Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020
Transcript
Page 1: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Securing the Organization’s IT Assets Amidst COVID-19Justin Pineda CISSP, GWAPT, GMOB, CEH

Principal Consultant, Pineda Cybersecurity

[email protected]

https://pinedacybersecurity.com/

1Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 2: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Discussion Points

• How organizations are affected by COVID-19

• Common cybersecurity issues faced

• Cybersecurity defense against attacks

• Future actions to maintain security posture

2Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 3: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

How organizations are affected by COVID-191 of 4

3Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 4: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Business Impact

• In an Accenture report, they discussed impacts on:• Systems

• Experience

• Operations

• Commerce

• Customers

• Supply Chain

• Leadership

• Workplace

4Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(COVID-19: Managing the human and business impact of coronavirus, Accenture, 2020)

Page 5: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Business Impact

• In an Accenture report, they discussed impacts on:• Systems – system resilience

• Experience – customer behavior

• Operations – business continuity

• Commerce - commerce innovation

• Customers – move at unprecedented speed

• Supply Chain – supply quickly, safely & securely

• Leadership – new patterns of work

• Workplace – shift to remote working, higher rates of SL

5Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(COVID-19: Managing the human and business impact of coronavirus, Accenture, 2020)

Page 6: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Business Impact

• In an Accenture report, they discussed impacts on:• Systems – system resilience

• Experience – customer behavior

• Operations – business continuity

• Commerce - commerce innovation

• Customers – move at unprecedented speed

• Supply Chain – supply quickly, safely & securely

• Leadership – new patterns of work

• Workplace – shift to remote working, higher rates of SL

6Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(COVID-19: Managing the human and business impact of coronavirus, Accenture, 2020)

Page 7: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Business Impact - Systems

• Business continuity risks

• Surge in transaction volumes

• Workforce productivity challenges

• Security risks

7Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

*According to a 2019 Accenture Survey of 8,300 companies as respondents

(COVID-19: Systems resilience in times of unprecedented disruption, Accenture, 2020)

Page 8: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Common cybersecurity issues faced2 of 4

8Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 9: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Attacks on NASA

9Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(NASA sees an “exponential” jump in malware attacks as personnel work from home, ARS Technica, 2020)

Page 10: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Local – BPI Phishing attacks

10Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(BPI warns public about increasing COVID-19 scams, 2020)

Page 11: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Google: 18M Malware & Phishing in 1 Week

11Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(Google saw more than 18 million daily malware and phishing emails related to COVID-19 last week, The Verge, 2020)

Page 12: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Trend Micro: COVID-19 Themed Attacks

12Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(Developing Story: COVID-19 Used in Malicious Campaigns, Trend Micro, 2020)

Page 13: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

COVID-19 Case Tracker filled with Malware

13Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

(Spyware disguised as COVID-19 tracker app actually keeps track of users, SC Media, 2020)

Page 14: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Summary

14Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Increased number of phishing attacks using coronavirus references as bait.

Enhanced risk of cyberattacks on company networks due to reduced IT staffing and/or need to focus on supporting remote access at the expense of security.

Business continuity risks arising from the potential lack of system and connectivity resources to handle surge in remote work, compounded by the heightened risk of cyberattacks that could disrupt operations.

(Coronavirus and Remote Work Heighten Cybersecurity Risks, Jones Day, 2020)

Page 15: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Cybersecurity defense against attacks3 of 4

15Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 16: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

SANS Security Awareness Deployment Guide

16Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

https://www.sans.org/

Page 17: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Securely Working for Home

17Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Periodic Security Awareness reminder for employees

Accessible IT/Cybersecurity team for security incidents

Clear policies and guidelines for employees

Management support in every step of the way

Page 18: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Caveats

• IT/ Security Team

• Common mistake is to manage a lot of risks identified.

• Limit and prioritize risks

• Communications Team

• Explaining the risks and security issues in layman’s term may not be the strongest skill of technical guys.

• Strong partnership with Comms Team is important.

18Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 19: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

3 Core Risks

19Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Social Engineering

Strong Passwords

Updated Systems

Page 20: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Social Engineering

20Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Psychological attack where attackers trick or fool victims.

Key Points:

Train employees what social engineering is

How to spot most common indicators of social engineering

What to do when they spot one

Page 21: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

SANS Social Engineering Free Materials

• Fact Sheets, Posters, Templates -https://ssahub.sans.org/folders/19qytvyc

• Social Engineering Video -https://bit.ly/3aEABUR

21Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 22: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

22Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 23: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

23Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 24: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

24Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 25: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Strong Passwords

25Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Weak passwords continue to be one of the primary drivers for breaches on a global scale.

Four Key Behaviors

• Passphrases

• Unique passwords for all accounts

• Password managers

• MFA (Multi-Factor Authentication)

Page 26: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Use Passphrase

26Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

https://www.useapassphrase.com/

Page 27: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Password Managers

27Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

https://www.lastpass.com/ https://keepass.info/

Page 28: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Multi-Factor Authentication (MFA)

28Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

https://lastpass.com/auth/

https://chrome.google.com/webstore/detail/authenticator/bhghoamapcdpbohphigoooaddinpkbai?hl=en

Page 29: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

29Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 30: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

SANS Password Free Materials

• Fact Sheets, Posters, Templates -https://ssahub.sans.org/folders/b1bslq1y

30Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 31: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Updated Systems

31Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Ensure that applications and OS are running the latest version.

Require enabling automatic updating

Page 32: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Other topics to consider

• Detection/Response

• Wi-Fi (Securing your Wi-Fi Access Point)• Cyber Secure Home:

https://www.sans.org/sites/default/files/2020-03/02-SSA-WorkingFromHome-FactSheet.pdf

• VPN’s

• Working Remotely

• Children/Guests

32Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 33: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

For more details…

33Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

https://www.sans.org/sites/default/files/2020-03/01-SSA-WorkingFromHome-DeploymentGuide_1.pdf

Page 34: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Future actions to maintain security posture 4 of 4

34Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 35: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Specific Security Policies

35Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Create specific and granular password policies to include use of password managers and MFA

Create Policies on Remote Work (VPN, Internet connection, Backup)

Update Acceptable Use Policy to include Remote Work sections.

Page 36: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Security Awareness Roadmap

36Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 37: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Phishing Strategic Planning

37Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Goals

• Reduce Phishing Risk

• Increase Detection Capabilities

Contents

• Executive Summary

• Goals

• Planning

• Keys to Success

• Offenders

• Following-up

• People Reporting Phishing Attacks

• Tiered Phishing Templates

• Metrics and Measurement

Page 38: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Security Awareness Survey

38Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Provides insight into information security awareness within your organization

Consist of questions designed to measure a set of basic characteristics of the organization’s security awareness posture

Some questions collect factual data (role, time in job, etc.)

Some questions collect data about the user’s awareness, attitudes and behaviors

Page 39: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Information Security Ambassador

Responsibilities include:

• Raise awareness to the Information Security Handbook

• Award Handbook Completion Certificate

• Participate in monthly calls with IT/Cybersecurity team to get updates on the latest security incidents and news

• Participate in awareness campaign

• Coordinate topical Brown Bag session

39Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 40: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Metrics

40Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Behavioral Metrics can be difficult especially during WFH. (Ex. Securing Wi-Fi device)

Measure engagement instead

Interaction (questions & suggestions from staff)

Simulations (social engineering exercise)

Page 41: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

References

• COVID-19: Managing the human and business impact of coronavirus

• Link: https://www.accenture.com/ph-en/about/company/coronavirus-business-economic-impact

• NASA sees an “exponential” jump in malware attacks as personnel work from home

• Link: https://arstechnica.com/information-technology/2020/04/nasa-sees-an-exponential-jump-in-malware-attacks-as-personnel-work-from-home/

• BPI warns public about increasing COVID-19 scams• Link: https://www.bpi.com.ph/service-in-the-time-of-covid-19/bpi-

warns-public-about-increasing-covid-19-scams

41Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 42: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

References

• Google saw more than 18 million daily malware and phishing emails related to COVID-19 last week

• Link:https://www.theverge.com/2020/4/16/21223800/google-malware-phishing-covid-19-coronavirus-scams

• Developing Story: COVID-19 Used in Malicious Campaigns

• Link: https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/coronavirus-used-in-spam-malware-file-names-and-malicious-domains

42Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 43: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

References

• Coronavirus and Remote Work Heighten Cybersecurity Risks

• Link: https://www.jonesday.com/en/insights/2020/03/coronavirus-remote-work-cyber-risks

• Cybersecurity Tips for Remote Working & Learning During COVID-19

• Link: https://it.nc.gov/resources/covid-19-resources/cybersecurity-tips-remote-working-learning-during-covid-19

43Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 44: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

References

• Spyware disguised as COVID-19 tracker app actually keeps track of users

• Link: https://www.scmagazine.com/home/security-news/mobile-security/spyware-disguised-as-covid-19-tracker-app-actually-keeps-track-of-users/

• Managing Cybersecurity and Data Privacy Concerns During the COVID-19 Pandemic

• Link: https://www.jonesday.com/en/insights/2020/04/covid19-cybersecurity-and-data-privacy-concerns

44Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 45: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

References

• How to protect yourself from cyberattacks when working from home during COVID-19

• Link: https://www.weforum.org/agenda/2020/03/covid-19-cyberattacks-working-from-home/

• Security Awareness Deployment Guide – Securely Working at Home

• Link: https://www.sans.org/sites/default/files/2020-03/01-SSA-WorkingFromHome-DeploymentGuide_1.pdf

45Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 46: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Further Reading

• Systems Resilience Managing unprecedented disruption with an eye to the future

• Link: https://www.accenture.com/_acnmedia/Thought-Leadership-Assets/PDF-2/Accenture-COVID-19-Systems-Resilience-in-Times-of-Unprecedented-Disruption.pdf

• Cybersecurity During COVID-19 • Link:

https://www.schneier.com/blog/archives/2020/04/cybersecurity_d.html

• Work-from-Home Security Advice• Link: https://www.schneier.com/blog/archives/2020/03/work-from-

home_.html

46Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 47: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Further Reading

• Avoiding Phishing Attacks• Link: https://it.nc.gov/resources/cybersecurity-risk-

management/cybersecurity-awareness/online-safety-tips/avoiding-phishing

47Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 48: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Templates/ Fact Sheets

• Security Awareness Resources• Link:

https://www.dropbox.com/sh/v9y96jet035l6sj/AADFzdVfdXmC5qunzmrXj41Ja?dl=0&lst=

• Creating a Cyber Secure Home• Link: https://ssahub.sans.org/folders/a6r4a4cs

• Malware• Link: https://ssahub.sans.org/folders/esmmm1px

• Passwords• Link: https://ssahub.sans.org/folders/b1bslq1y

• Social Engineering• Link: https://ssahub.sans.org/folders/19qytvyc

48Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 49: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Training Videos

• Social Engineering: https://bit.ly/3aEABUR

• Creating a Cyber Secure Home: https://bit.ly/2Y5xuCS

• Working Remotely: https://bit.ly/3aJIokl

49Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 50: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Company ProfileEstablished in 2017, Pineda Cybersecurity is aManila-based IT consulting company thatprovides cybersecurity instruction and services atreasonable rates. Since then, we haveconducted several cybersecurity workshops,from technical to managerial, for local andmultinational firms. Our diverse portfolio includesgovernment agencies, banks, real estatedevelopers, manufacturing businesses,academe, utilities, law firms, food groups, andtravel agencies. Backed by industryprofessionals with years of experience and astrong grip in the field of information technology,our team is founded to create a culture ofinformation security by sharing our expertise andestablishing networks.

50Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 51: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Company Profile

Apart from workshops, Pineda Cybersecurity also provides consulting services such as

• Regulatory and administrative services

• Data Privacy Compliance

• IT Security Audit

• Risk Management

• Technical services

• Vulnerability Assessment and Penetration Testing (VAPT)

• Open-source security controls implementation.

51Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 52: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Philippine Department of ICT Recognition

We are recognized by the Department of Information and Communications Technology (DICT) as a Cybersecurity Assessment Provider for Vulnerability Assessment and Penetration Testing (VAPT) and Information Security Management System (ISMS).

52Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020

Page 53: Securing the Organization’s IT Assets Amidst COVID-19 · Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020 14 Increased number of phishing attacks

Securing the Organization’s IT Assets Amidst COVID-19Justin Pineda CISSP, GWAPT, GMOB, CEH

Principal Consultant, Pineda Cybersecurity

[email protected]

https://pinedacybersecurity.com/

53Securing the Organization’s IT Assets Amidst COVID-19 v1.0 | J. Pineda | Apr 2020


Recommended