Top Banner
© 2017 SPLUNK INC. Splunk @ ABN AMRO Floris Ladan | Sr. Security Analyst | ABN AMRO Bank N.V.
20

SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

Jan 28, 2018

Download

Technology

Splunk
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Splunk @ ABN AMRO

Floris Ladan | Sr. Security Analyst | ABN AMRO Bank N.V.

Page 2: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

▶ Background to ABN AMRO▶ Our Security Operations Center▶ What we are facing▶ How we work▶ What’s next

Agenda

Page 3: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Background to ABN AMRO• Leading Bank in NL• 5Mln Retail and 300k Business Customers• Operational Income last year 8.5 Bln Euro

Page 4: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Who am I?

Page 5: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

The Security Operations Center in ABN AMRO

▶ ECS • Transactions and electronic channels

▶ SOC• IT security and operational security

▶ SIM • Business process fraud and malicious

insiders

Corporate information Security Office (CISO)

Page 6: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

But what are we facing?

Page 7: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

The Usual Suspects

Page 8: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

The Professional

Page 9: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

The Nation-State

Page 10: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

The Hacktivist

Page 11: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

So what did we start with?A SOC grasping for data

Page 12: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Our first Splunk Setup:“200 Gb/day ought to be enough for anybody”

Page 13: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Use-Case 1Drowning in Phishing mails

Page 14: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

14

Use-Case 2(D)DoS attack detection

Page 15: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

15

Use-Case 3Detecting the unknown Malware dialing home

Page 16: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

Bonus Use-caseSo how is my SOC doing?

Page 17: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

TheRoadAheadAutomatedTriageNextgenerationSecurityOperationsCenter

Page 18: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

1. The threats facing your organisation are susceptible to change, prepare to change with them.

2. People love Splunk, prepare your infrastructure (and datamodels) for growth.

3. Splunk yourself!

Key Takeaways

Page 19: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.

“Never attribute to malice that which is adequately explained by stupidity”— Robert Hanlon

Page 20: SplunkLive! Stockholm 2017 - ABN AMRO Customer Presentation

© 2017 SPLUNK INC.© 2017 SPLUNK INC.

THANK YOU