Your Organizational Security Probably Sucks

28
Your Organizational Security Probably Sucks by Theresa Miller 24x7 IT Connection, LLC

Transcript of Your Organizational Security Probably Sucks

Page 1: Your Organizational Security Probably Sucks

Your Organizational Security Probably Sucks

by Theresa Miller24x7 IT Connection, LLC

www.24x7itconnection.com

Page 2: Your Organizational Security Probably Sucks

Agenda• Memory Lane• Be prepared for “when”• Business Reputation Matters• What can you do? Large and small organization

Page 3: Your Organizational Security Probably Sucks

Memory Lane

Page 4: Your Organizational Security Probably Sucks

Memory Lane

Page 5: Your Organizational Security Probably Sucks

Memory Lane

Page 6: Your Organizational Security Probably Sucks

Memory Lane

Page 7: Your Organizational Security Probably Sucks

It’s no longer “if” it will happen , but how prepared your organization will be “when” it happens.

Page 8: Your Organizational Security Probably Sucks

What has changed?• Technology has been around for some time now• Black Hat Hackers• Financial data – Traditionally sought after• Medical data – Newer Target• http://blogs.citrix.com/2015/04/08/healthcare-past-present-f

uture/• Health data is worth 10 times more than credit card data on

the black market. Predicting $5.6 billion price tag for healthcare breaches this year.

Page 9: Your Organizational Security Probably Sucks

Business Reputation Matters

Page 10: Your Organizational Security Probably Sucks

Forbes http://www.forbes.com/sites/davelewis/2014/12/16/sony-pictures-data-breach-and-the-pr-nightmare/

Page 11: Your Organizational Security Probably Sucks

SC Magazinehttp://www.scmagazine.com/a-look-at-anthems-pr-response-following-the-data-breach/article/396990/

Page 12: Your Organizational Security Probably Sucks

Can we really protect our organizational data?

Page 13: Your Organizational Security Probably Sucks

What Can I do? Large organization•Regular system patching and maintenance•Servers and Workstations• Includes all software that your organization uses•This will cover you for up to 80% of vulnerabilities•What about the remaining 20%?

Page 14: Your Organizational Security Probably Sucks

What can I do? Large organization•Security checks with penetration testing at least twice per year!•Remediate, remediate, remediate

Page 15: Your Organizational Security Probably Sucks

What can I do? Large organization•Retire the really old legacy systems•Typically cannot be patched•Use older security strategies that can be hacked

Page 16: Your Organizational Security Probably Sucks

What can I do? Large organization•Have excellent backups and backups of the backups

Page 17: Your Organizational Security Probably Sucks

What can I do? Large organization•Using more than one technology or a product that includes more than one layer of protection. •Email scanning• Intrusion Detection•Endpoint recording to watch for anomalies•Laptop encryption

Page 18: Your Organizational Security Probably Sucks

What can I do? Large organization•Public Relations and Business Planning•Legal and PR playbook in order

Page 19: Your Organizational Security Probably Sucks

What can I do? Any organization•Educate users to “think before they click”

Page 20: Your Organizational Security Probably Sucks

I am just a small business, I cannotafford a complex security strategy!

Page 21: Your Organizational Security Probably Sucks

What can I do? Small business•Protect your PC’s •Virus and malware scanning

Page 22: Your Organizational Security Probably Sucks

What can I do? Small business•Choose a reputable hosted Service provider•Microsoft or Amazon

Page 23: Your Organizational Security Probably Sucks

What can I do? Small business•Have good backups of data•Modern day attacks can even destroy your backups

Page 24: Your Organizational Security Probably Sucks

What can I do? Small business•Public Relations and Business Planning

• Legal representation• Plan for public communication

Page 25: Your Organizational Security Probably Sucks

There is no such thing as Zero risk

Page 26: Your Organizational Security Probably Sucks

Protect your Organization From..• Advancements in Malware• Blackhat Hackers• Financial Theft• Medical Theft • What we did in the past, will no longer carry Our organizations into the future

Page 27: Your Organizational Security Probably Sucks

Take Action Now!

Page 28: Your Organizational Security Probably Sucks

Questions??