Top Banner
Your Organizational Security Probably Sucks by Theresa Miller 24x7 IT Connection, LLC
28

Your Organizational Security Probably Sucks

Feb 20, 2017

Download

Technology

24x7itconnect
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Your Organizational Security Probably Sucks

Your Organizational Security Probably Sucks

by Theresa Miller24x7 IT Connection, LLC

www.24x7itconnection.com

Page 2: Your Organizational Security Probably Sucks

Agenda• Memory Lane• Be prepared for “when”• Business Reputation Matters• What can you do? Large and small organization

Page 3: Your Organizational Security Probably Sucks

Memory Lane

Page 4: Your Organizational Security Probably Sucks

Memory Lane

Page 5: Your Organizational Security Probably Sucks

Memory Lane

Page 6: Your Organizational Security Probably Sucks

Memory Lane

Page 7: Your Organizational Security Probably Sucks

It’s no longer “if” it will happen , but how prepared your organization will be “when” it happens.

Page 8: Your Organizational Security Probably Sucks

What has changed?• Technology has been around for some time now• Black Hat Hackers• Financial data – Traditionally sought after• Medical data – Newer Target• http://blogs.citrix.com/2015/04/08/healthcare-past-present-f

uture/• Health data is worth 10 times more than credit card data on

the black market. Predicting $5.6 billion price tag for healthcare breaches this year.

Page 9: Your Organizational Security Probably Sucks

Business Reputation Matters

Page 10: Your Organizational Security Probably Sucks

Forbes http://www.forbes.com/sites/davelewis/2014/12/16/sony-pictures-data-breach-and-the-pr-nightmare/

Page 11: Your Organizational Security Probably Sucks

SC Magazinehttp://www.scmagazine.com/a-look-at-anthems-pr-response-following-the-data-breach/article/396990/

Page 12: Your Organizational Security Probably Sucks

Can we really protect our organizational data?

Page 13: Your Organizational Security Probably Sucks

What Can I do? Large organization•Regular system patching and maintenance•Servers and Workstations• Includes all software that your organization uses•This will cover you for up to 80% of vulnerabilities•What about the remaining 20%?

Page 14: Your Organizational Security Probably Sucks

What can I do? Large organization•Security checks with penetration testing at least twice per year!•Remediate, remediate, remediate

Page 15: Your Organizational Security Probably Sucks

What can I do? Large organization•Retire the really old legacy systems•Typically cannot be patched•Use older security strategies that can be hacked

Page 16: Your Organizational Security Probably Sucks

What can I do? Large organization•Have excellent backups and backups of the backups

Page 17: Your Organizational Security Probably Sucks

What can I do? Large organization•Using more than one technology or a product that includes more than one layer of protection. •Email scanning• Intrusion Detection•Endpoint recording to watch for anomalies•Laptop encryption

Page 18: Your Organizational Security Probably Sucks

What can I do? Large organization•Public Relations and Business Planning•Legal and PR playbook in order

Page 19: Your Organizational Security Probably Sucks

What can I do? Any organization•Educate users to “think before they click”

Page 20: Your Organizational Security Probably Sucks

I am just a small business, I cannotafford a complex security strategy!

Page 21: Your Organizational Security Probably Sucks

What can I do? Small business•Protect your PC’s •Virus and malware scanning

Page 22: Your Organizational Security Probably Sucks

What can I do? Small business•Choose a reputable hosted Service provider•Microsoft or Amazon

Page 23: Your Organizational Security Probably Sucks

What can I do? Small business•Have good backups of data•Modern day attacks can even destroy your backups

Page 24: Your Organizational Security Probably Sucks

What can I do? Small business•Public Relations and Business Planning

• Legal representation• Plan for public communication

Page 25: Your Organizational Security Probably Sucks

There is no such thing as Zero risk

Page 26: Your Organizational Security Probably Sucks

Protect your Organization From..• Advancements in Malware• Blackhat Hackers• Financial Theft• Medical Theft • What we did in the past, will no longer carry Our organizations into the future

Page 27: Your Organizational Security Probably Sucks

Take Action Now!

Page 28: Your Organizational Security Probably Sucks

Questions??