• No results found

Future Threat Landscape - How will technology evolve and what does it mean for cyber security?

N/A
N/A
Protected

Academic year: 2021

Share "Future Threat Landscape - How will technology evolve and what does it mean for cyber security?"

Copied!
37
0
0

Loading.... (view fulltext now)

Full text

(1)

James Hanlon

CISSP, CISM

Security Strategist

Office of the CTO

EMEA

Future Threat Landscape -

How will

technology evolve and what does it

(2)

How will cyber

security be

impacted today and

tomorrow?

Think >

Know >

Protect >

How do we need to

address cyber

security moving

forward?

What does the

(3)

3

Digitization

(4)
(5)

5

Everything will be connected more than ever before….

Internet of Everything (IoE) is arising

(6)

6

(7)

Copyright © 2014 Symantec Corporation

7

Machine Learning (AI)

A key future trend

Copyright © 2015 Symantec Corporation

“Google’s Eric

Schmidt believes

that we are at the

cusp of a new age

of AI”

(8)

Copyright © 2014 Symantec Corporation

8

(9)

Copyright © 2014 Symantec Corporation

9

AI Analysis (Astroturfing)

(10)

Copyright © 2014 Symantec Corporation

10

AI & Automation

(11)

Copyright © 2014 Symantec Corporation

11

The promises of nanotechnology

(12)

12

(13)

Copyright © 2014 Symantec Corporation

13

IoE

Nanotechnology

AI & Machine Learning

Future Technology Risk Landscape

(14)

How will cyber

security be

impacted today and

tomorrow?

Think >

Know >

(15)
(16)

Copyright © 2014 Symantec Corporation 16

Cyber

Security

& the

Board

(17)
(18)

ATTACKERS

DEFENDERS

Can focus on one target

Only need to be right once

Attacks can be very complex

Focus only on getting in

Attackers can buy

and test security products

Must defend everything

Need to be right every time

Blocks are expected & complexity is hard

Must balance defense with business impact

Defenders can’t pre-test

targeted malware

(19)

Copyright © 2014 Symantec Corporation

19

Cyber Security is key concern for all new technological

advances!

IoE / Connectivity Era

Security must be “Built-In” to the

devices and cloud services, not

deferred to be added later

(20)

But for every new technology invention today……..

“a cyber hack exists”

(21)

Copyright © 2014 Symantec Corporation

21

So, what can you do about

cyber risks today &

(22)

Think >

Know >

Protect >

How do we need to

address cyber

(23)

Copyright © 2014 Symantec Corporation

(24)

24

It’s getting harder to stay ahead……….

but it is impossible to

conduct a cyber attack without leaving a trace

Network

Server

Endpoint

(25)

C L O U D

25

What if …

Apply

Context

Correlate

& Prioritize

You could collect info from

every endpoint, network

device, and server

You could watch this data

at the

Enterprise

level –

looking for patterns and

anomalies

You could apply knowledge

and learning from across

global

Communities

Indicators

of

Breach

Knowledge

about URLs,

file hashes

Attack

patterns &

actors

Correlation

across

ecosystems

E N T E R P R I S E

D E V I C E S

(26)

This is the promise of big data cyber security analytics

Machine Learning

& Big Data Cyber Security

(27)

Symantec have been a leader in cyber security big data analytics &

machine learning for many years…….

27

1 billion+ systems

Norton & SEP users

200M+

(the biggest source of telemetry)

3.9 trillion rows of

security telemetry

100 billion more/month

14 security ops centers globally;

500+ expert analysts

Blocked 182 million threats

last year

(28)

A Portfolio Built on Big Data Analytics & Machines Learning

Threat Protection

ENDPOINTS

DATA CENTER

GATEWAY

S

• Advanced Threat Protection Across All Control Points • Built-In Forensics and Remediation Within Each Control Point

• Integrated Protection of Server Workloads: On-Premise, Virtual, and Cloud • Cloud-based Management for Endpoints, Datacenter, and Gateways

Unified Security Analytics Platform

Log and Telemetry Collection Unified Incident Management and Customer Hub Inline Integrations for Closed-loop Actionable Intelligence Regional and Industry Benchmarking Integrated Threat and Behavioral Analysis

Information Protection

DATA

IDENTITIES

• Integrated Data and Identity Protection

• Cloud Security Broker for Cloud and Mobile Apps • User and Behavioral Analytics

• Cloud-based Encryption and Key Management

Users Data Apps Cloud Endpoints Gateways Data Center

Cyber Security Services

Monitoring, Incident Response, Cyber Simulation Platform, Adversary Threat Intelligence

(29)

29

“is the organization's capability to

withstand negative impacts due to

known, predictable, unknown,

unpredictable, uncertain and

unexpected threats from activities in

cyberspace”

But security is not all about technology

Acknowledge the shift from 100% Security to Cyber Resilience

100%

Security

Cyber

Resilience

What’s

different

now ?

D

if

fer

en

ce

Accept Bad

things will

happen

D

if

fer

en

ce

Higher level

of business

engagement

D

if

fer

en

ce

From known

threats to

unknown

risks

D

if

fer

en

ce

Detect &

Respond

Faster

D

if

fer

en

ce

Intelligence

& Threat

Sharing

(30)

Understand that means there are two processes to implement

CYBER INCIDENT

RISK MANAGEMENT

INCIDENT RESPONSE

BEFORE

AFTER

(31)

Reactive

& Manual

People basedLack of policyAd-hoc responsesFire fighting

Proactive

Cyber-Resilience

 A fully optimised & integrated

security framework exists

 Policy and processes are

optimised and updated frequently

 Established cyber governance

structure

 External & internal threat

intelligence is gathered, correlated and acted upon

 Partnering in cyber ecosystems

is common

 Organisation demonstrate

proactive cyber agility

Responsive

Cyber-Resilience

 An optimized & integrated

security framework exists

 Processes and policies include

most security requirements

 Improved security visibility  Basic cyber governance is in

operation

 Capability to respond to cyber

incidents exists

Integrated

Policy & Tools

 Partially integrated security

framework exists

 Policies encapsulate some

security requirements

 Security Framework is

internally focused

 Deficiencies still exist, limited

security visibility is common

Disparate

Policy & Tools

 Disparate policy  Disparate tools  Limited processes  Little security visibility

5

4

3

2

1

Next up?

Know where you are and where you want to be?

(32)

,

And Lastly,

Adopt a framework to make the Journey to better resilience

32

PREDICT

RESPOND

PREVENT

DETECT

CYBER-RESILIENCE

(33)

Copyright © 2015 Symantec Corporation 33

What is a good cyber framework to follow?

NIST

(34)

Copyright © 2015 Symantec Corporation

34

But let me leave you with a

(35)

How will cyber

security be

impacted today and

tomorrow?

Think >

Know >

Protect >

How do we need to

address cyber

security moving

forward?

What does the

future of technology

hold for all of us?

(36)

James Hanlon

CISSP, CISM

Security Strategist

Office of the CTO

EMEA

(37)

Endpoint Protection

Data Center Security

Encryption

Cloud Security

Security Response

Incident Response

Malware Analysis

Consulting Services

PREPARE

PREVENT

DETECT

RESPOND

Risk Management

Incident Management

BEFORE

AFTER

Control Compliance

Threat Intelligence

Simulation Platform

Systems Management

Advanced Threat

Protection

Cyber Security

Services

Data Loss Prevention

Cyber Resilience with

References

Related documents

Log and Telemetry Collection Unified Incident Management and Customer Hub Inline Integrations for Closed-loop Actionable Intelligence Regional and Industry Benchmarking

Threat Intelligence Security Market by Solution (SIEM, Log Management, IAM, SVM, Risk Management, Incident Forensics), Service (Managed, Professional), Deployment, Organization

25 Security Analysts Customer Portal Data Warehouse Log Collection Agent Global Threat

(“Research shows that when litigants believe the court process is fair, they are more likely to comply with court orders and the law generally.”)... regarding policing, prosecution,

Continue current actions facing the nearest enemy (Charge?) Advance towards nearest enemy (Charge?).. RF2-5 Withdraw to cover further

Capita deliver a complete network and physical security solution, from design and installation of LAN and WAN networks to telephony and collaboration with physical security, and

Rewrite the sentences by replacing the underlined word or phrase with the correct form of the appropriate phrasal verb:3. Procedures are in place to handle charges of discrimination

Keltner (2016) geeft in zijn boek “de Machtsparadox“aan dat er voor alle relaties en vormen van interactie een nieuw concept van macht moet gelden voor alle contexten waarin