SlideShare a Scribd company logo
1 of 15
Download to read offline
Our mission is to simplify the complexities of security
information management:
   Focus on the core group of security assessment services you need
   Take the time to understand your business and then optimize our approach for
    your unique situation
   Deliver reports and guidance that are easily understood and acted on by both
    management and technical personnel
   Base your assessment and recommendations on trusted, “open” (non-
    proprietary, non-vendor specific) guidance to simplify the process of
    operating and maintaining your Information Security Management System
    after we leave
   10+ Years purely focused on Information Assurance
    • Information Security Management System Assessment (35%)
         Design Reviews/Gap Assessments /ISO27001/ Compliance
          Testing
         Experienced with dozens of standards/frameworks
    • Penetration Testing/Ethical Hacking (40%)
       Network/Application/Database/Physical/Social Engineering
    • Security Information Event Management (25%)
    • Regional Focus/National Reach
Experience
   • Hundreds of Security Assessment engagements
   • Personnel Security Experience (12+ years on average ~ 6 years as a team)
   • Education & Certification (all major certifications relevant to our focus)

Results
   • Focus on communicating results in an understandable/actionable manner
   • Demonstrable body of success

Integrity
   •   Commitment to doing what is right
   •   Pride in our work product
   •   Respect for our “extended” team
   •   Independence (we sell no products)

Intent
   • Focus on mutual benefit
   • Straight Talk -- Always
   City of New York:                      Verizon Wireless
    •   Financial Services                 Depository Trust & Clearing
    •   Taxi and Limousine Commission       Corporation (DTCC)
    •   City Time
    •   Electronic Justice Project
                                           Bank of New York
                                           Savient Pharmaceuticals
   Wyndham Worldwide
                                           County of Sussex (NJ)
   Oklahoma Gas & Electric
                                           Pennsylvania Power & Light
   Barnes & Noble                         National Student
   Time Warner Cable                       Clearinghouse
   Bristol Myers Squibb                   Woodbridge Township (NJ)
   NJ Motor Vehicle Commission            Banco Estado of Chile
   Philadelphia Parking Authority         Target
   System Certification &           Incident Response
    Accreditation (NIST 800-37)       • Forensics
   PCI Compliance                   Security Assessments
   Sarbanes Oxley                    • Vulnerability Assessments
                                      • Penetration Testing
   Identity Theft                        Internal / External
   Third Party Attestation               Application
                                          Physical Penetration
    • ISO 27001/27002
                                      • Social Engineering
    • BITS
    • SAS70                          Design Reviews
    • HIPAA                           • Application
                                          Code Review
   Risk Assessment                   • Network
                                      • Database
                                      • Systems
   Information Technology/Security professionals that
    became auditors (not accountants)
   Highly experienced – average 12+ years
   Highly certified – ISO 27001, CISA, CISSP, CEH,
    CHFI, MCSE, CCNA, OCP, etc.
   Core team has been together ~ 6 years

              Consistent commitment to excellence –
              we are passionate about what we do
   Concerns: Protect Critical Data
    • Passenger Credit Card Data
    • Passenger, Drivers, & Owners Privacy
    • Advertising, Entertainment, & PSA Feed
   Key Challenges
    • Highly Complex Solutions
         In-Cab Architecture
         Wireless & GPS Architecture
         Multiple Data Centers                                 Taxicab Security Presentation
                                                             http://s.pvtpt.com/TaxicabSecurity
         Web Applications to service TLC, Drivers, Owners
    • A “moving” target (13K of them)
    • 4 Unique Vendor Solutions
    • Accountability
for leading US Electrical Utility Company
“The problem wasn’t a lack of guidance, rather it was an overabundance of guidance.”
                                                     -John Verry, Principal Consultant

   Over 20 Standards to Consider
   Testing of Hard to Secure Distributed Environments
         Radio Networks
         Smart Meters
         In-Home Devices
         Command Response
         SCADA Systems

      Electrical Utilities: Information Security Blackout
      http://s.pvtpt.com/InfoSecBlackout
   Major PA Electrical Utility
    • SIEM Solution Implementation (Novell Sentinel)
   Major Regional Transmission Organization (RTO)
    • Network, Application & Physical Vulnerability Assessments / Penetration
      Testing
    • WLAN Assessments
   Burlington County Bridge Commission (NJ)
    • Concerns: Segregation and Protection from EZ-Pass Systems
    • Vulnerability Assessments / Network Architecture Assessments
   NYC Financial Information Services Agency (FISA)
    • Concerns: Security of Personally Identifiable Information (PII) of NYC’s
      400k Employees
    • eHire: Implementation of PeopleSoft Recruiting Software Across all NYC
      Agencies
   NYC Department of Finance (DOF)
    • Concerns: Security of an $8 Billion eCommerce Application with Payment
      Card Industry (PCI) Compliance
    • NYCSERVE: Online Payment System
   Sussex County (NJ)
    • Concerns: Managing Personally Identifiable Information (PII) and HIPAA
      Regulations for New Jersey Consumer Affairs
    • Vulnerability Assessments / Penetration Testing
    • ISO 27001 Gap Analysis & Implementation Leading to ISO 27001
      Certification
   Woodbridge Township & Board of Education (NJ)
    • Concerns: Collapsing Network Infrastructure and Protecting from
      Malicious Individuals
         Education
         Law Enforcement
         Taxes
         Etc.
    • Incident Response / Vulnerability Assessments / Penetration Testing
   Testing of Hard to Secure Distributed Environments
        Radio Networks
        Smart Meters
        In-Home Devices
        Command Response
        SCADA Systems
   New Jersey Based
   New Jersey SBE Type 2
   Backdrop Services Contracts
    • NY State OGS
    • NJ Administrative Office of the Courts
    • WSCA (Western States Contracting Alliance)
   90% of Projects $6-30k, Falling Under Direct Purchasing Authority (DPA)
An Introduction To Pivot Point Security

More Related Content

Recently uploaded

(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607dollysharma2066
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchirictsugar
 
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!Doge Mining Website
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024Adnet Communications
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Pereraictsugar
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditNhtLNguyn9
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCRashishs7044
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Riya Pathan
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCRashishs7044
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africaictsugar
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckHajeJanKamps
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy Verified Accounts
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfrichard876048
 

Recently uploaded (20)

Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)Japan IT Week 2024 Brochure by 47Billion (English)
Japan IT Week 2024 Brochure by 47Billion (English)
 
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
(Best) ENJOY Call Girls in Faridabad Ex | 8377087607
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
Marketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent ChirchirMarketplace and Quality Assurance Presentation - Vincent Chirchir
Marketplace and Quality Assurance Presentation - Vincent Chirchir
 
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!
Unlocking the Future: Explore Web 3.0 Workshop to Start Earning Today!
 
TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024TriStar Gold Corporate Presentation - April 2024
TriStar Gold Corporate Presentation - April 2024
 
Kenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith PereraKenya Coconut Production Presentation by Dr. Lalith Perera
Kenya Coconut Production Presentation by Dr. Lalith Perera
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal audit
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR
 
Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737Independent Call Girls Andheri Nightlaila 9967584737
Independent Call Girls Andheri Nightlaila 9967584737
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
8447779800, Low rate Call girls in Uttam Nagar Delhi NCR
 
Kenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby AfricaKenya’s Coconut Value Chain by Gatsby Africa
Kenya’s Coconut Value Chain by Gatsby Africa
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deckPitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
Pitch Deck Teardown: Geodesic.Life's $500k Pre-seed deck
 
Buy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail AccountsBuy gmail accounts.pdf Buy Old Gmail Accounts
Buy gmail accounts.pdf Buy Old Gmail Accounts
 
Innovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdfInnovation Conference 5th March 2024.pdf
Innovation Conference 5th March 2024.pdf
 
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
No-1 Call Girls In Goa 93193 VIP 73153 Escort service In North Goa Panaji, Ca...
 

Featured

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
 

Featured (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

An Introduction To Pivot Point Security

  • 1.
  • 2. Our mission is to simplify the complexities of security information management:  Focus on the core group of security assessment services you need  Take the time to understand your business and then optimize our approach for your unique situation  Deliver reports and guidance that are easily understood and acted on by both management and technical personnel  Base your assessment and recommendations on trusted, “open” (non- proprietary, non-vendor specific) guidance to simplify the process of operating and maintaining your Information Security Management System after we leave
  • 3. 10+ Years purely focused on Information Assurance • Information Security Management System Assessment (35%)  Design Reviews/Gap Assessments /ISO27001/ Compliance Testing  Experienced with dozens of standards/frameworks • Penetration Testing/Ethical Hacking (40%)  Network/Application/Database/Physical/Social Engineering • Security Information Event Management (25%) • Regional Focus/National Reach
  • 4. Experience • Hundreds of Security Assessment engagements • Personnel Security Experience (12+ years on average ~ 6 years as a team) • Education & Certification (all major certifications relevant to our focus) Results • Focus on communicating results in an understandable/actionable manner • Demonstrable body of success Integrity • Commitment to doing what is right • Pride in our work product • Respect for our “extended” team • Independence (we sell no products) Intent • Focus on mutual benefit • Straight Talk -- Always
  • 5. City of New York:  Verizon Wireless • Financial Services  Depository Trust & Clearing • Taxi and Limousine Commission Corporation (DTCC) • City Time • Electronic Justice Project  Bank of New York  Savient Pharmaceuticals  Wyndham Worldwide  County of Sussex (NJ)  Oklahoma Gas & Electric  Pennsylvania Power & Light  Barnes & Noble  National Student  Time Warner Cable Clearinghouse  Bristol Myers Squibb  Woodbridge Township (NJ)  NJ Motor Vehicle Commission  Banco Estado of Chile  Philadelphia Parking Authority  Target
  • 6. System Certification &  Incident Response Accreditation (NIST 800-37) • Forensics  PCI Compliance  Security Assessments  Sarbanes Oxley • Vulnerability Assessments • Penetration Testing  Identity Theft  Internal / External  Third Party Attestation  Application  Physical Penetration • ISO 27001/27002 • Social Engineering • BITS • SAS70  Design Reviews • HIPAA • Application  Code Review  Risk Assessment • Network • Database • Systems
  • 7. Information Technology/Security professionals that became auditors (not accountants)  Highly experienced – average 12+ years  Highly certified – ISO 27001, CISA, CISSP, CEH, CHFI, MCSE, CCNA, OCP, etc.  Core team has been together ~ 6 years Consistent commitment to excellence – we are passionate about what we do
  • 8. Concerns: Protect Critical Data • Passenger Credit Card Data • Passenger, Drivers, & Owners Privacy • Advertising, Entertainment, & PSA Feed  Key Challenges • Highly Complex Solutions  In-Cab Architecture  Wireless & GPS Architecture  Multiple Data Centers Taxicab Security Presentation http://s.pvtpt.com/TaxicabSecurity  Web Applications to service TLC, Drivers, Owners • A “moving” target (13K of them) • 4 Unique Vendor Solutions • Accountability
  • 9. for leading US Electrical Utility Company “The problem wasn’t a lack of guidance, rather it was an overabundance of guidance.” -John Verry, Principal Consultant  Over 20 Standards to Consider  Testing of Hard to Secure Distributed Environments  Radio Networks  Smart Meters  In-Home Devices  Command Response  SCADA Systems Electrical Utilities: Information Security Blackout http://s.pvtpt.com/InfoSecBlackout
  • 10. Major PA Electrical Utility • SIEM Solution Implementation (Novell Sentinel)  Major Regional Transmission Organization (RTO) • Network, Application & Physical Vulnerability Assessments / Penetration Testing • WLAN Assessments
  • 11. Burlington County Bridge Commission (NJ) • Concerns: Segregation and Protection from EZ-Pass Systems • Vulnerability Assessments / Network Architecture Assessments  NYC Financial Information Services Agency (FISA) • Concerns: Security of Personally Identifiable Information (PII) of NYC’s 400k Employees • eHire: Implementation of PeopleSoft Recruiting Software Across all NYC Agencies  NYC Department of Finance (DOF) • Concerns: Security of an $8 Billion eCommerce Application with Payment Card Industry (PCI) Compliance • NYCSERVE: Online Payment System
  • 12. Sussex County (NJ) • Concerns: Managing Personally Identifiable Information (PII) and HIPAA Regulations for New Jersey Consumer Affairs • Vulnerability Assessments / Penetration Testing • ISO 27001 Gap Analysis & Implementation Leading to ISO 27001 Certification  Woodbridge Township & Board of Education (NJ) • Concerns: Collapsing Network Infrastructure and Protecting from Malicious Individuals  Education  Law Enforcement  Taxes  Etc. • Incident Response / Vulnerability Assessments / Penetration Testing
  • 13. Testing of Hard to Secure Distributed Environments  Radio Networks  Smart Meters  In-Home Devices  Command Response  SCADA Systems
  • 14. New Jersey Based  New Jersey SBE Type 2  Backdrop Services Contracts • NY State OGS • NJ Administrative Office of the Courts • WSCA (Western States Contracting Alliance)  90% of Projects $6-30k, Falling Under Direct Purchasing Authority (DPA)