Top Banner
Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus September 9 th 2016
45

Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Jun 03, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Bringing cyber to the Board of Directors & C-level

and keeping it there

Dirk Lybaert, Proximus

September 9th 2016

Page 2: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Dirk Lybaert

Chief Group Corporate Affairs

Page 3: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

We constantly keep people connected to the world so they can live better and work smarter.

Page 4: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 5: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

5

€ 6 billion

Underlying Revenue

€ 1,7 billion

Underlying EBIDTA

€ 1,53 billion

Contribution to the Belgian state

€ 1 billion

Investments

14,000 FTE’s

Page 6: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

6

Towards the best mobile experience and seamless connectivity

Secure sharing with our own Cloud and Security

expertise

A full range of Communication &

Collaboration platforms

Rich and varied content available on all screens

A superior customer experience through all channels:website, contact centers, retail outlets, email and social media

Page 7: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

WAN-LANConnectivity

Network-basedCommunications

Professional Services

Datacenter Infrastructure

Network-enabledServices Internet of Things

Telco IT

Communication& Collaboration

Security

Page 8: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 9: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Cyber Security has always been a priority for Proximus

Manage risks

Protect customer’s information & company assets

Business continuity

Legal & regulatory compliance

Offer safe & secure solutions

Securityportfolio

Safe & secureservices

&

Page 10: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 11: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

September 16th , 2013

Page 12: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

29 August 2016 Sensitivity: Internal use only 12

It started 2,5 months earlier

when we detected a malware

Page 13: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

In close collaboration with the authorities

Page 14: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

2 months

200 people

26,000 systems scanned

Page 15: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Successful clean-up operation

Minutely precision

One weekend

Page 16: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

You have no other choice

Strong involvement of top management

Page 17: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

You must be prepared

Page 18: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

CSIRT

Fast response

Page 19: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Cross-functional crisis management team

Steering bytopmanagement

Collaboration with key stakeholders

Page 20: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Communication is key

Multiple stakeholders

Intensive preparation

Timely & transparent

Based on known & verified elements

Don’t enter into speculations (the press will do for you…)

Preserve legal investigation

Page 21: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 22: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

and real accelerator

Turning this experience into learnings

Page 23: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

A strong response

Page 24: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Innovation

Company Culture

Competitive Market Dynamics

Business Model Evolution

Product & Serviceperformance

Customer Experience

Long term Ambitions VsShort Term Return

Legal/ Regulatory

Equipment & Technology

Employees Skills &Motivation

HR cost & flexibility

Environmental Liability

Macro- Economic factors

Partnership & M&A

Image & Brand perception

Compliance & data privacy

Hacking & Cyber attacks

Disasters

Supply Chain

Political Evolution

0102030405060708090

100

Hacking & Cyber attacks

Reviewed by ExCo & Audit Committee

Page 25: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Proximus cyber security program

Purpose

46 million € investment 2014-2017

reduce risks on information security

detect faster the incidents and provide

an effective response

Company transversal approach

Steering by ExCo & regular reporting to Board of Directors

Page 26: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

5 pillars

Culture

Governance IT Telco Cyber Defense

1 2 3 4

5

Page 27: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Policies

Architecture

Compliance

Organization

Strategy

Risk management

Security in development lifecycle

Security testing

Suppliers

Page 28: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Awareness campaigns

Education

Proximus Cyber Security

Convention

Page 29: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Cyber Security Week

Page 30: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

29 August 2016 Sensitivity: Unrestricted 30

Creating awareness among our staff

Page 31: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

ExCo& Chairman of the Board@ Proximus Cyber Week

Page 32: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Limit entry points

Limit propagation

Limit risks of theft

Patching/updates

Access control for devices & users

And much more…

Segmentation

Administrator access

Encryption

Page 33: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Monitoring 24/7

Incident response & containment

Threat intelligence

Forensic research

International collaboration

Page 34: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Leveraging our internal expertise to help customers

CSIRT as a service

Response

Readiness

Breach

investigation

Incident

Response

Proactive

diagnosisMonitoring

Page 35: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 36: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Proximus CEO launches the Cyber Security Coalition

Page 37: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Academic

Enterprises

Authorities

Joining forces

Belgium European Telco’s Key stakeholders

Page 38: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,
Page 39: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

We are subject to strict regulation

EU General Data Protection Regulation (2016)

European Framework Directive 2009/140/EC-> Belgian Telecom Law (2005)

Privacy Act (1992)

Page 40: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Looking from a business risk perspective

What if your contract would be

leaked?

Page 41: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Demonstrating our company & top management commitment

Page 42: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

“If the rate of change on the outside exceeds the

rate of change on the inside, the end is near”

Jack Welch

Page 43: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

29 August 2016

Sensitivity: Confidential

43

Security as Enabler for Business Transformation

New Way of Working

Big Data

Internet of Things

Enabling Company

Page 44: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,

Security as business objective and enabler for business transformation - 3 drivers

& &Offer safe & secure solutions

Securityportfolio

Safe & secureservices

Certification

Enable business transformation

New Way of Working

Big Data

Internet of Things

Enabling Company

Manage risks

Protect customer’s information & company assets

Business continuity

Legal & regulatory compliance

Insurance coverage

Page 45: Bringing cyber to the Board of Directors & C-level · Bringing cyber to the Board of Directors & C-level and keeping it there Dirk Lybaert, Proximus ... website, contact centers,