Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach...

19
Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. PID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal Maguire

Transcript of Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach...

Page 1: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement.

PID#

Data Breach Investigations Report

Kansas City ISACA

May 10, 2012

Neal Maguire

Page 2: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

2012 Data Breach

Investigations Report A study conducted by the Verizon RISK Team with

cooperation from the Australian Federal Police, Dutch

National High Tech Crime Unit, Irish Reporting &

Information Security Service, Police Central e-Crime Unit,

and United States Secret Service.

Page 3: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 3

2012 DBIR Contributors

Page 4: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 4

Current Threat Environment

• “Industrialization” of Attack Methods

• It’s Not Just About The Money Anymore

• 2011: The Year of the Hacktivist

• Broadening Diversity of Cybercrime Victims

• Identity and Authentication Are Under Assault

• End-user Devices Drawing More Fire

• Still No Evidence That “The Cloud” Is Inherently Bad

Page 5: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 5

Threat Agents

Page 6: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 6

External Threat Agents: Motives

Page 7: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 7

Threat Agents: External

Page 8: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 8

Threat Action Categories: Larger Orgs

Page 9: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 9

Top Threat Action Types: Larger Orgs

Page 10: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 10

Compromised Assets – Larger Orgs

Page 11: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 11

Most Compromised Assets

Page 12: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 12

Compromised Data

Page 13: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 13

Compromised Data

Page 14: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 14

Attack Targeting

Page 15: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 15

Timespan of Events: Larger Orgs

Page 16: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 16

Breach Discovery

Page 17: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 17

Recommendations: Smaller Orgs

Page 18: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 18

Recommendations: Larger Orgs

Page 19: Data Breach Investigations Report - ISACA KCisaca-kc.org/Chapter Meetings/20120510 Data Breach Report.pdfPID# Data Breach Investigations Report Kansas City ISACA May 10, 2012 Neal

Confidential and proprietary materials for authorized Verizon personnel and outside agencies only. Use, disclosure or distribution of this material is not permitted to any unauthorized persons or third parties except by written agreement. 19

Neal Maguire