04
Every Morning at ERASE HQ<br>
05
Culture (www.dictionary.com) –
a particular form or stage of civilization, as that of a certain nation or period: Greek culture.
the behaviors and beliefs characteristic of a particular social, ethnic, or age group
2014 Study – over 75% of a 5,000 person group surveyed stated that they “routinely” violate their company’s CyberSecurity policies CyberSecurity is more a Cultural Issue than a Scientific Issue<br>
06
“The Internet is the largest experiment involving anarchy in history” The New Digital Ageby Eric Schmidt & Jared Cohen<br>
07
“So, will this transfer of power to individuals ultimately result in a safer world, or a more dangerous one?”
“The future will be shaped by how states, citizens, companies and institutions handle their new responsibilities” The New Digital Ageby Eric Schmidt & Jared Cohen<br>
08
It is a Global Issue<br>
09
Who is Using the Internet<br>
10
data credit - www.internetworldstats.com Who is Using the Internet<br>
11
Who is Using the Internet<br>
12
Who is Using the Internet<br>
13
The International Telecommunication Union (May 2014). Mobile Phones in the World<br>
14
Office of the United States Trade Representative 2015 Special 301 Report<br>
15
Watchdog for violations of Intellectual Property Rights (IPR)
Priority Watch List – 10 countries
China, India, Russia, -------
Countries with highest number of Internet users
China, USA, India, Brazil, Japan, Russia
Watch List – 26 countries Office of the United States Trade Representative 2014 Special 301 Report<br>
16
In regards to Greece – “The lack of adequate governmental resources to combat piracy over the Internet has exacerbated this growing problem.” Office of the United States Trade Representative 2014 Special 301 Report<br>
17
Britain – 17% of APT’s (Advanced Persistent Threats)
Germany – 12% of APT’s
Saudi Arabia – 10% APT’s
APT’s
Typically state-backed or sophisticated criminal
Long term information gathering operation
Human element required, not just auto code
Command & Control source commonly in USA
Targets are in strong economic environments Most Commonly Targeted Countries<br>
18
Who Are the Threat Actors?<br>
19
Intimidation
Extortion
Financial Gain
Terrorism
Economic Espionage
Harassment
Data Vandalism
Crimes against Persons and Property The Motives for CyberSecurity Threats<br>
20
Software as a Criminal Service (SaaCS)
Dark Web
Tor Browser required – can run from a flash drive
PII for Sale in List Form
Long Term Strategic Criminal Business Plans with a Marketing & Sales element
SaaCS Bulletin Boards
DDoS Attacks
APT’s
Harassment campaigns Financial Gain - All about the $$$<br>
21
Anonymous took down the ISIL Social Media Servers in four countries for 3 days in retaliation for the sanctioned hit on Charlie Hebdo in Paris, France However, do not underestimate those motivated by ideology<br>
22
Culture
Economic Disadvantage
Control of Natural Resources
Deficiencies in CyberSecurity Education
Insider Threat due to Non Compliance
Displacement of the Workforce by Technology
No judicial jurisdiction for criminal acts
Justice systems worldwide are overwhelmed Barriers to a Cyber Safe World<br>
23
Range from Online Dating Intimidation to Cyber-Spy and War Operations
Reported Data Breaches – January 1 through Oct 13, 2015 (Identity Theft Resource Center-ITRC)
606 separate breaches
Number of records exposed 175,492,082
PII (Personally Identifiable Information) involved
System Design & Discovery Reconnaissance Recent Incidents<br>
24
Category of Breach<br>
25
Zero Day Hack on NATO and Ukraine
Flaw is in all MS OS except XP
Windows OLE Vulnerability
MSFT released patch MS14-060 (Oct 14 2014)
Exploit was used for Espionage Purposes with attempted cover as criminal enterprise
Poor operational security (OPSEC) allowed discovery of Russian language on command server in Germany
Also used against Infrastructure targets in Europe Recent Incidents<br>
26
Use of Current News or Social Occurrence to Exploit Operator Behavior
Ebola Email Spam from “WHO”
Standard Phishing campaign
Installs
Keylogger
Image and Sound Capture
Remote Access Recent Incidents<br>
27
White House Breach (unclassified)
Appears to be operated by Russian Govt
Accessed Passwords, VPN data, email
Most likely part of attempt to identify gateways to classified systems
USA was notified by ally of breach!
Office of Personnel Management
4.2 million current and past government employee background investigation files stolen
PII for individual x 10 others minimum loss Recent Incidents<br>
28
LexisNexis
Distributed Denial of Service Attack (DDoS)
October 27, 2014
Began at approximately 2 am and continued until 4pm
Upstream ISPs, DDoS Mitigation partner, IT Dept all working simultaneously, with Incident Response Team
Consider the impact
Background History Systems
Credit Systems
Litigation Systems
PII to the 9th degree! Recent Incidents<br>
29
What the Future Holds<br>
30
Economic Espionage is up 53% from January 1, 2015 until October 1, 2015
Majority of incidents have a CyberSecurity factor involved
Foreign attacks combine international operations with domestic activities
Actors are both US citizens and foreign nationals
FBI has produced “The Company Man” video for the private sector to increase awareness What the Future Holds<br>
31
Continued attempts by the United Nations to gain control of the Internet
International Telecommunication Union
Effort supported by
China
Russia
India
Brazil
Iran
Saudi Arabia What the Future Holds<br>
32
More Business Email Compromise
Increase in Ransomware
Targeted Spear Phishing
Increase in Attacks on Government Systems
OPM
IRS
New FISMA Report (Federal Information Security Management Act)
Attacks on Vendors for Re-direct Attacks What the Future Holds<br>
33
15.6 million new workers in the next 10 years who don’t know anything about CyberSecurity
Threats and Vectors that change faster than CyberSecurity undergrads can graduate
Employees need to be educated and trained on CyberSecurity Awareness and Response
Affective training
Cognitive training on the do’s and don’ts before and after an exposure
Perceptive penalty for non-compliance Educational Countermeasures<br>
34
Monitor your systems, be aware your perimeter and defenses are being tested
Data Loss Prevention software
Black listing URLs on the Internet
Penetration (PEN) Testing
Train, educate and then enforce your policies and practices (make sure they are realistic)
Ensure that management teams know that IT is not CyberSecurity. You need both, but they are not the same! Management Focused Countermeasures<br>
35
Develop a Consequence Management model for your high threat / loss areas
How will you continue to operate with minimal or no loss if you are penetrated
Neutralizing the motive(s) of the attacker(s)
Defense in Depth and Need to Know apply
This process must be developed and led by the elements of your firm that make revenue Consequence Management Countermeasures<br>
36
Thank you!Kevin MellottERASE Enterprises214-501-5175kevin@erase.comwww.erase.com<br>