Information Security Tabletop Exercise: Malware &

Published  . 0 views
↓ Download
Information Security Tabletop Exercise: Malware &
1 / 1
Information Security Tabletop Exercise: Malware & - slide 1 of 21 Information Security Tabletop Exercise: Malware & - slide 2 of 21 Information Security Tabletop Exercise: Malware & - slide 3 of 21 Information Security Tabletop Exercise: Malware & - slide 4 of 21 Information Security Tabletop Exercise: Malware & - slide 5 of 21 Information Security Tabletop Exercise: Malware & - slide 6 of 21 Information Security Tabletop Exercise: Malware & - slide 7 of 21 Information Security Tabletop Exercise: Malware & - slide 8 of 21 Information Security Tabletop Exercise: Malware & - slide 9 of 21 Information Security Tabletop Exercise: Malware & - slide 10 of 21 Information Security Tabletop Exercise: Malware & - slide 11 of 21 Information Security Tabletop Exercise: Malware & - slide 12 of 21 Information Security Tabletop Exercise: Malware & - slide 13 of 21 Information Security Tabletop Exercise: Malware & - slide 14 of 21 Information Security Tabletop Exercise: Malware & - slide 15 of 21 Information Security Tabletop Exercise: Malware & - slide 16 of 21 Information Security Tabletop Exercise: Malware & - slide 17 of 21 Information Security Tabletop Exercise: Malware & - slide 18 of 21 Information Security Tabletop Exercise: Malware & - slide 19 of 21 Information Security Tabletop Exercise: Malware & - slide 20 of 21 Information Security Tabletop Exercise: Malware & - slide 21 of 21
Description: Information Security Tabletop Exercise: Malware DDOS Attack COMPANY NAME FACILITATORMODERATOR NAME DATE Agenda Welcome Introductions About a Tabletop The Learning Exercise After Action Discussion About a Tabletop Tabletop

Related Topics

Download Presentation

"Information Security Tabletop Exercise: Malware &" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Information Security Tabletop Exercise: Malware & DDOS Attack [COMPANY NAME]
[FACILITATOR/MODERATOR NAME]
[DATE]<br>
slide2. Agenda Welcome /Introductions
About a Tabletop
The Learning Exercise
After Action Discussion<br>
slide3. About a Tabletop Tabletop Exercises are designed to help ensure that your program and plans can be effectively executed and that all participants understand their role.
This is your opportunity to validate that your plans will enable the firm to effectively continue business in the short-term and then efficiently recover and return to business as usual.<br>
slide4. Exercise Objectives Coordination: Improve the coordination among the various members of Crisis Team.
Communications: Evaluate the communication process among team members and with other groups.
Decision Making: Assess the decision-making processes and activation of the team.<br>
slide5. Guiding Principles Training and learning exercise – not a test!
There are no “hidden agendas” or trick questions.
It’s not about the scenario; it’s about the response.
There are no single or simple solutions.
Open and interactive discussion – there may be more than one response to the crisis.
The end goals:
Understand the process
Identify gaps
Develop team readiness to respond<br>
slide6. Questions?<br>
slide7. Information Security Scenario at [company name]<br>
slide8. Location [company location]
[specific building]
[modify picture at right]<br>
slide9. The Incident Begins Time: 10:05 AM
The Information Security Manager notices some one has attempted to access multiple IT services from within the company firewall.
On investigation it is determined that it may be an unauthorized access via a Senior Manager’s laptop.
The Information Security Manager reports this to his manager.<br>
slide10. Based on this information: Is this situation a threat?
What actions should happen next?
What should IT Management do with this information?
Is there a process or plan in place for these events?
What's the highest level in the company that might be notified of this systems breach?<br>
slide11. Event Continues – 11:50 AM Further investigation shows that access was gained to one of the file storage servers that contains sensitive client data and Personal Identifiable Information (“PII”).
IT is now trying to determine if data was copied and stolen.<br>
slide12. Based on this information: Who is in control and managing this situation?
What are the protocols for informing the owner of the affected laptop?
How sensitive is this issue?
Will the client be informed? If so, how will this be managed?
What actions are being taken by the IT Department at this time?
Will this incident be reported to law enforcement?<br>
slide13. Event Continues – 1:45 PM The IT Networking Team reports a slowdown of networking traffic and raise an incident ticket to report the issue.
Simultaneously, an incident ticket is raised by the IT helpdesk regarding calls from employees working remotely complaining that they can’t access the employee portal using the internet.
The Information Security Manager quickly realizes that the firm is under a Distributed Denial of Services attack (“DDOS attack”)<br>
slide14. Based on this information: There are now two events occurring, what teams are in control and managing each of the situations?
What actions are IT taking to manage the DDOS attack?
As the DDOS attack is affecting remote computing for employees and access to the website, what protocols are in place to manage the situation?
What team is now managing the response?
What affect does this have on the company’s reputation?<br>
slide15. Event Continues – 4:45 PM A client calls her account manager and informs them that they have received a call from Russia and are being blackmailed. The caller is demanding $500,000 in Bitcoin to stop the release of secret information stolen from your servers.
The client has informed the FBI and their legal team.<br>
slide16. Based on this information: Who is in control of the entire situation with the data breach, the client issue and the DDOS attack?
Could all of these events be connected?
What is IT doing about the data breach and the DDOS attack? What are the tactical and strategic issues?
How will the Client, FBI and legal team be managed?
If it’s determined that you need to pay the ransom, how will you do so in Bitcoin?<br>
slide17. Event Continues – 5:30 PM The Information Security Manager determines the original security breech occurred when the senior manager opened a link in a malicious email and loaded a Trojan virus onto his machine.
The Denial of Service attack has slowed and network traffic flow has returned to a normal level.
The FBI is working directly with the Client to resolve the blackmail attempt.<br>
slide18. Based on this information: How can this type a data breech be avoided in future?
What was the full impact of the DDOS attack and how was this mitigated?
Is the crisis over?<br>
slide19. Additional Considerations IT Security events happen quickly and can have an immediate and long-term impact on operations and reputation.
The impact of these events will be felt throughout the company, potentially affecting reputation and client trust.<br>
slide20. After Action – How Did You Do? List at least three things that the team did well during this exercise.
List any gaps you recognized.
List three action items to implement that will improve your ability to effectively respond.<br>
slide21. Tabletop Resource Guide View the Webinar: 4 Reasons Your Next Cybersecurity Tabletop Exercise Will Flop
Download the Business Continuity Guide
Download the Disaster Recovery Plan Template<br>