October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis...

18
October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org | #cybersummitmn October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org | #cybersummitmn

Transcript of October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis...

Page 1: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

October 28–30, 2019 | Minneapolis Convention Center

cybersecuritysummit.org | #cybersummitmn

Page 2: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Pluck Yew!!!

Page 3: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Battle of Agincourt (Failed Strategy)

• Disjointed French Leaders

• Muddy conditions weighed down French knights

• Longbow – more powerful

• French Armor did not protect French casualties severe 10,000

Page 4: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Verizon Data Breach Investigations Report§ In-depth research§ Informative data visualizations§ Just enough Snark

Page 5: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

VERIS• “Consistent,

unequivocal collection of security incident details– Common language for

describing security incidents in a structured and repeatable manner.

– Basis for enumeration

Page 6: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Executive Summary - Victims

Small Business

Page 7: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Executive Summary - Commonalities

Detection

Page 8: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Breach Timeline

Detection

Page 9: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Incident Classification Patterns

Drop POS

Cloud Based Email Servers

Page 10: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

EXIM vulnerabilities

Page 11: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Industry Comparison - Patterns

Web App

IncreaseCyber Espionage

Page 12: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Industry Comparison - Action

Drop in Accommodation

IncreasePublic

Page 13: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Mobile

There is evidence that some actors are expanding fromtraditional user devices and beginning to target mobile

Research points to users being significantlymore susceptible to social attacks theyreceive on mobile devices.

Page 14: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Financially-Motivated Social Engineering (FMSE)• Financial Pretexting• Phishing Attacks

Page 15: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Is the Phishing Training working

Page 16: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Industry Specific Sections

Page 17: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn

Summary• Web Attacks• Cloud Based Email Servers• Privilege Misuse• FMSE• Miscellaneous Errors• Detection is Still slow• Phishing may be decreasing

Page 18: October 28–30, 2019 | Minneapolis Convention Center...October 28–30, 2019 | Minneapolis Convention Center cybersecuritysummit.org| #cybersummitmn Battle of Agincourt (Failed Strategy)

October 28–30, 2019 | Minneapolis Convention Centercybersecuritysummit.org | #cybersummitmn