Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare...

31
0 Into Warriors! Simple lessons to fill the knowledge gap within your staff Turning Your Cybersecurity Toddlers… @shambanIT Shira Shamban Dome9 Security

Transcript of Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare...

Page 1: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

0

Into Warriors!

Simple lessons to fill the knowledge gap within your staff

Turning Your Cybersecurity Toddlers…

@shambanIT

Shira ShambanDome9 Security

Page 2: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

1

Page 3: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

2

Page 4: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

3

Page 5: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

4

Page 6: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

5

Page 7: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

You and your staffAre NOT going to

keep up with Technology

@shambanIT

Page 8: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Today, Enterprises Average…

ZDNet – “Security landscape plagued by too many. Nov. 2016

different security vendors installed in their company to solve problems

@shambanIT

Page 9: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was
Page 10: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

ALERT!!!!ALERT!!!!

ALERT!!!!ALERT!!!!

ALERT!!!!ALERT!!!!

ALERT!!!!ALERT!!!!ALERT!!!!

ALERT!!!!

You and your staffAre NOT going to

keep up with Technology

@shambanIT

Page 11: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was
Page 12: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

11 @shambanIT

Page 13: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Top 5 Causes of Data Breaches in Healthcare

The elephant in the figures is the number of incidents where the

discovery was measured in months or years….

12

Protected HealthInformation DataBreach ReportVerizon – March 2018

#1. Human Error: 33.5%

#2. Misuse: 29.5%

#3. Physical (mostly theft): 16.3%

#4. Hacking: 14.8%

#5. Malware: 10.8%

@shambanIT

Page 14: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Top Three Causes – JDL Group – January 2018

#3. Human ErrorReuters reports 73% of data breaches happen because of the people operating machines

14

#2. Ransomware & Malware

#1. Password Problems 63% of investigated breaches involved weak, stolen or default password

Verizon recently reported ransomware is the fifth most common type of malware.

@shambanIT

Page 15: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

15

Why So Much Phishing? It Works...

@shambanIT

Page 16: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

16

We All Have a Dave…

@shambanIT

Page 17: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Understanding the Basics of CD/CR Security

17 @shambanIT

Page 18: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

We Don’t Need Faster Horses

“If I had asked people what they wanted, they would have said faster horses.”

19

― Henry Ford

@shambanIT

Page 19: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

So, what is the secret ingredient?

Page 20: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Understanding the Basics of CD/CR Security

21

• Don’t monitor the logs, monitor the unusual findings“I don’t need logs, I have an AV”“I keep all of my logs…“I use the default AWS configuration”• 80% of the problems repeat themselves

• Whatever it is that you’re doing with your logs – It’s not working – time for a change

21

I think”

@shambanIT

Page 21: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was
Page 22: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Logs Provide…

Page 23: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Your Logs are the Secret Ingredient● How Long to Keep?

● Sources and Variety?

● Scalability

○ Easily add new (future) sources

● Detection Algorithms Used

○ How detailed/granularity

● Supporting User Interface

The Secret Recipe…

@shambanIT

Page 24: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Phishing email User clicked link

Username and password stolen

Criminal hacker has privileged

access to AWS

Criminal hacker deployed bitcoin

mining assets

Awareness program

URL scanning for email Enforce 2FA Least privilege

principleGive very specific policies to users regarding assetsprevent

Detection tool Detection tool Monitor login patterns

detectMonitor activity patterns and unusual events, like

creating of new keys, users etc

Monitor activity patterns and unusual events like

new assets, unusual billing, CPU, DNS requests

Money loss!

Typical Attack Vector

A Complete 360 Degree View Is Impossible…

Without Logs!

@shambanIT

Page 25: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

PII breach, including emails and passwords

User re-used password for AWS account

Criminal hacker has privileged

access to AWS

Criminal hacker moves around the VPC, looking for

sensitive DB

Criminal hacker encrypted DB,

asking for ransom

Enforce strong password policy awareness

Enforce 2FA, least privilege least privilege Backup!

haveibeenpwnedMonitor login

patternsMonitor Internal port scan, failed login attempts

Monitor activity patterns and unusual events, like

creating of new keys, users etc

Monitor unusual account activity

prevent

detect

Money loss, reputation, compliance

Remember! Logging is For EVERYONE

Typical Attack Vector

@shambanIT

Page 26: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Love Your Logs!

Page 27: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

30

Focus On The Big Rocks First

Page 28: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Automate Remediation

31

Repetitive problems are easier to remediate

Hire Expert(s) to Create Cluster- Address the Top 10 Recurring Problems

Hire Expert(s) to Prepare Appropriate Solutions

Allow Machine to Label Each ProblemIf Yes – Auto RemediateIf No – Escalate to Human

@shambanIT

Page 29: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

33

I have a problem Other people have that problem (or similar)

I wonder how they solved it

I will share my solution with the community

ow they solved it

Others will share their own solutions, we exchange

knowledge

Security is improved!

Remediation – What’s The Future…Crowdsourcing

@shambanIT

Page 30: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

Free Your Warriors!

34 @shambanIT

Page 31: Turning Your Cybersecurity Toddlers…Into Warriors! · Top 5 Causes of Data Breaches in Healthcare The elephant in the figures is the number of incidents where the discovery was

35

Thank YouAny Questions? I Dare You!

Shira ShambanHead of Security Research

@[email protected]

@shambanIT