SlideShare ist ein Scribd-Unternehmen logo
1 von 34
@1davidclarke Email cio@vciso.co for list of links
• IBM Interconnect
26th
March 2015
Sunderland Software Centre
"Thank You
to the IBM Team
for puttng this event together.“
http://www.slideshare.net/IBMInterconnect/inter-connect-sunderland-agenda?
qid=cbafb915-e826-4d62-9e21-b1f837afc3fa&v=&b=&from_search=5
Th
@1davidclarke Email cio@vciso.co for list of links
David Clarke
• Created CERT on a Financial Intranet trading $3.5
Trillion a day ,CPNI Member 10 Years.
• Managed Global Managed Security Services with a
$100-$300 million Global install base 500 + Customers
with $3.4 Billion dollar Contracts.
• Created , maintained and improved regulatory and
compliance commitments including Global PCI-DSS,
ISO 27001 (10,000+ Security Devices/Systems ).
@1davidclarke Email cio@vciso.co for list of links
"The 7 Most Important Steps to
Cyber protection for SME's -"
@1davidclarke Email cio@vciso.co for list of links
• "....that can cost less
than a Latte and
could get you
Enterprise Level
Cyber Security !..."
• Updated List of Software /Service
vciso.co/lattesecurity
@1davidclarke Email cio@vciso.co for list of links
Cost Of Latte Around the world
Grande latte in
Oslo cost
jolting $9.83
@1davidclarke Email cio@vciso.co for list of links
@1davidclarke Email cio@vciso.co for list of links
How does this affect Small
Business
• Cyber attacks third biggest risk for UK
firms, as supply chain disruption remains
top concern - See more at: Jan 15th 2015
• http://www.supplymanagement.com/news/2015/cyber-attacks-third-biggest-risk-for-uk-firms-as-supply-chain-
disruption-remains-top#sthash.iHZoSvDS.dpuf
@1davidclarke Email cio@vciso.co for list of links
Impact for Small Business
• To Supply IT services to HMG Compliant
with Cyber Essentials.
• Potentially Suppliers to suppliers will need
to demonstrate cyber security practices
• Suppliers to larger compnanies are
already being asked.
@1davidclarke Email cio@vciso.co for list of links
What can Small business do to
level The playing field.
@1davidclarke Email cio@vciso.co for list of links
1. System Misconfiguration
2. Patch Management
3. Default Passwords
4. Easy to Guess Passwords
5. Lost Devices
6. Disclosure of info via incorrect email address
7. Double Clicking Attachment/URL
@1davidclarke Email cio@vciso.co for list of links
Re- Arrange this List
1. Easy to Guess Passwords
2. Default Passwords
3. Disclosure of info via incorrect email address
4. Patch Management
5. Lost Devices
6. Double Clicking Attachment/URL
7. System Misconfiguration
@1davidclarke Email cio@vciso.co for list of links
Passwords
Two Main Types Types
• Master Passwords
Access to PC's and Servers and Appliances <10
• Constant Use Passwords
Email,Ebay,Dropbox etc >100's
@1davidclarke Email cio@vciso.co for list of links
Master Passwords
If you have this Card nothing to remember Cost One Time <£5.00
https://www.qwertycards.com/
@1davidclarke Email cio@vciso.co for list of links
Constant Use Passwords
If you have this Software nothing to remember Cost Yearly $12.00
Auto Fill
Creates Password
Saves Site
Free
$12/Year for Mobile
@1davidclarke Email cio@vciso.co for list of links
If you have a Large Team
If you have this Software nothing to remember Cost Monthly about $10
Auto Fill
Creates Password
Saves Site
$10/A month
@1davidclarke Email cio@vciso.co for list of links
Email Passwords
• Gmail 2 Stage Authentication
• Password and a text
• Yahoo On time password
• They will text you new password
• If you have this Software nothing to remember FREE
@1davidclarke Email cio@vciso.co for list of links
List 1
1. Easy to Guess Passwords
2. Default Passwords
3. Disclosure of info via incorrect email address
4. Patch Management
5. Lost Devices
6. Double Clicking Attachment/URL
7. System Misconfiguration
@1davidclarke Email cio@vciso.co for list of links
Disclosure of Information
• https://www.prot-on.com/tryIt.html
Basic Version is Free
Easy to use ,Quick
Create a list of people allowed
to see document.
@1davidclarke Email cio@vciso.co for list of links
List 3
1. Easy to Guess Passwords
2. Default Passwords
3. Disclosure of info via incorrect email address
4. Patch Management
5. Lost Devices
6. Double Clicking Attachment/URL
7. System Misconfiguration
@1davidclarke Email cio@vciso.co for list of links
Patch Managment
• http://secunia.com/products/
@1davidclarke Email cio@vciso.co for list of links
List 4
1. Easy to Guess Passwords
2. Default Passwords
3. Disclosure of info via incorrect email address
4. Patch Management
5. Lost Devices
6. Double Clicking Attachment/URL
7. System Misconfiguration
@1davidclarke Email cio@vciso.co for list of links
Lost Devices
• Mobile Phones
• Apple Icloud
• Lock/Phone/Track Phone
• Android
• Lock/Phone/Track Ring, Lock, or Erase AVG/Google
• https://www.avgmobilation.com/
@1davidclarke Email cio@vciso.co for list of links
Lost PC's
• Dropbox
• Sugarsync
• Google Drive
• Real Time Back Up
• Use Cloud encryption
PerfectCloud.io to Encrypt Free Account
@1davidclarke Email cio@vciso.co for list of links
List 5
1. Easy to Guess Passwords
2. Default Passwords
3. Disclosure of info via incorrect email address
4. Patch Management
5. Lost Devices
6. Double Clicking Attachment/URL
7. System Misconfiguration
@1davidclarke Email cio@vciso.co for list of links
Double Clicking Attachment/URL
• Use Gmail/Yahoo to filter out the Worst.
• Panda Security Plugin warns against sites
• http://www.pandasecurity.com/homeusers/downloads/wot/
• Chrome Safe Browsing enabled
@1davidclarke Email cio@vciso.co for list of links
Who are You Going To Call?
• https://www.cert.gov.uk/what-we-
do/responding-to-a-cyber-issue/getting-
help/
@1davidclarke Email cio@vciso.co for list of links
What Are you Going to do?
• https://www.malwarebytes.org/
• http://housecall.trendmicro.com/uk/
Am I really Vulnerable?
https://breachalarm.com
BreachAlarm monitors the Internet for your passwords being
compromised and posted online.
@1davidclarke Email cio@vciso.co for list of links
Appendix
@1davidclarke Email cio@vciso.co for list of links
Bonus Slide
• Kids, Controlling Access.
• http://www.netgenie.net/global/ Around £100
• Free SIEM Security Incident Event Managment
• https://siemless.com/
• Take Credit Cards with Free CC Reader
• https://www.izettle.com/gb/service
• Free Invoicing on The Web
• https://www.waveapps.com/
@1davidclarke Email cio@vciso.co for list of links
• Breach Legislation, IT or Legal?
• " the proposed regulation of up to 5% of
annual worldwide turnover, or €100"
@1davidclarke Email cio@vciso.co for list of links
• Information Sharing , Who,When, How
• "The ICO has imposed a monetary penalty
of £200000 on the British Pregnancy
Advice Service (BPAS) for exposing
thousands of personal"
@1davidclarke Email cio@vciso.co for list of links
• Compliance is the best protection?
• "Resistance is futile" Gartner
• "Brighton and Sussex University Hospitals NHS
Trust fined £325k after hard drives with highly-
sensitive patient data were sold on eBay, - "
@1davidclarke Email cio@vciso.co for list of links
• Best Practice or is this Compliance ?
• "The ICO can issue fines of up to
£500,000 for serious breaches of the Data
Protection Act and Privacy and Electronic
Communications Regulations." ICO
@1davidclarke Email cio@vciso.co for list of links
• Incident Response,Strategy
• "There are two kinds of big companies in the
U.S. Those who’ve been hacked by the Chinese
and those who don’t know they’ve been hacked.”
FBI

Weitere ähnliche Inhalte

Andere mochten auch

Keynote capitals india morning note 08 october-12
Keynote capitals india morning note 08 october-12Keynote capitals india morning note 08 october-12
Keynote capitals india morning note 08 october-12Keynote Capitals Ltd.
 
Fénix BioBio versión english
Fénix BioBio versión englishFénix BioBio versión english
Fénix BioBio versión englishPlanFenixBioBio
 
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta nashloollupjfp
 
Presentacion derechos de autor
Presentacion derechos de autorPresentacion derechos de autor
Presentacion derechos de autorricardo_bf41
 
Daily Life (Cuba)
Daily Life (Cuba)Daily Life (Cuba)
Daily Life (Cuba)guimera
 
Resumen del capítulo 6 (compatible)
Resumen del capítulo 6 (compatible)Resumen del capítulo 6 (compatible)
Resumen del capítulo 6 (compatible)bohabaita4
 
La industria de la privatización en Europa
La industria de la privatización en EuropaLa industria de la privatización en Europa
La industria de la privatización en EuropaCorreos EN Lucha
 
Universidade Lusófona do Porto - Perspetivas de Futuro
Universidade Lusófona do Porto - Perspetivas de FuturoUniversidade Lusófona do Porto - Perspetivas de Futuro
Universidade Lusófona do Porto - Perspetivas de FuturoRicardo Almeida
 
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...Torben Haagh
 
7 Most Significant Underground Projects in Asia Today [Infograph]
7 Most Significant Underground Projects in Asia Today [Infograph]7 Most Significant Underground Projects in Asia Today [Infograph]
7 Most Significant Underground Projects in Asia Today [Infograph]Darwin Jayson Mariano
 
Design Thinking — žádná velká věda
Design Thinking — žádná velká vědaDesign Thinking — žádná velká věda
Design Thinking — žádná velká vědaJan Martinek
 
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana Šumar
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana ŠumarRudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana Šumar
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana ŠumarBobijevi_maturanti
 
Cermet pfc carolina abajo_clemente
Cermet pfc carolina abajo_clementeCermet pfc carolina abajo_clemente
Cermet pfc carolina abajo_clementejhon44444
 
El diseño del suelo (barceloneta) emerson martínez palacios
El diseño del suelo (barceloneta) emerson martínez palaciosEl diseño del suelo (barceloneta) emerson martínez palacios
El diseño del suelo (barceloneta) emerson martínez palaciosEmerson Martínez Palacios
 

Andere mochten auch (20)

Keynote capitals india morning note 08 october-12
Keynote capitals india morning note 08 october-12Keynote capitals india morning note 08 october-12
Keynote capitals india morning note 08 october-12
 
Fénix BioBio versión english
Fénix BioBio versión englishFénix BioBio versión english
Fénix BioBio versión english
 
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta
Luces De Dinamo Para Tu Bicicleta
 
Presentacion derechos de autor
Presentacion derechos de autorPresentacion derechos de autor
Presentacion derechos de autor
 
Daily Life (Cuba)
Daily Life (Cuba)Daily Life (Cuba)
Daily Life (Cuba)
 
Batz Leuchtsysteme Katalog 2007
Batz Leuchtsysteme Katalog 2007Batz Leuchtsysteme Katalog 2007
Batz Leuchtsysteme Katalog 2007
 
Tegaserod 145158-71-0 -api
Tegaserod 145158-71-0 -apiTegaserod 145158-71-0 -api
Tegaserod 145158-71-0 -api
 
Resumen del capítulo 6 (compatible)
Resumen del capítulo 6 (compatible)Resumen del capítulo 6 (compatible)
Resumen del capítulo 6 (compatible)
 
Cpva prezentacija projektu sekme
Cpva prezentacija projektu sekmeCpva prezentacija projektu sekme
Cpva prezentacija projektu sekme
 
La industria de la privatización en Europa
La industria de la privatización en EuropaLa industria de la privatización en Europa
La industria de la privatización en Europa
 
El celular !!!
El celular !!!El celular !!!
El celular !!!
 
Universidade Lusófona do Porto - Perspetivas de Futuro
Universidade Lusófona do Porto - Perspetivas de FuturoUniversidade Lusófona do Porto - Perspetivas de Futuro
Universidade Lusófona do Porto - Perspetivas de Futuro
 
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...
Volvo Cars, Hyundai Motor, GKN Driveline Confirm | Early Bird Discount Ends S...
 
7 Most Significant Underground Projects in Asia Today [Infograph]
7 Most Significant Underground Projects in Asia Today [Infograph]7 Most Significant Underground Projects in Asia Today [Infograph]
7 Most Significant Underground Projects in Asia Today [Infograph]
 
Java com banco my sql
Java com banco my sqlJava com banco my sql
Java com banco my sql
 
Design Thinking — žádná velká věda
Design Thinking — žádná velká vědaDesign Thinking — žádná velká věda
Design Thinking — žádná velká věda
 
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana Šumar
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana ŠumarRudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana Šumar
Rudnik rtanj i planina rtanj kao ambijentalna sredina by Jovana Šumar
 
Evaluation zum Klassenrat in einer 8. Klasse
Evaluation zum Klassenrat in einer 8. Klasse Evaluation zum Klassenrat in einer 8. Klasse
Evaluation zum Klassenrat in einer 8. Klasse
 
Cermet pfc carolina abajo_clemente
Cermet pfc carolina abajo_clementeCermet pfc carolina abajo_clemente
Cermet pfc carolina abajo_clemente
 
El diseño del suelo (barceloneta) emerson martínez palacios
El diseño del suelo (barceloneta) emerson martínez palaciosEl diseño del suelo (barceloneta) emerson martínez palacios
El diseño del suelo (barceloneta) emerson martínez palacios
 

Ähnlich wie Ibm vciso sunderland

Onlinesecurityrecomendations2014 141230081030-conversion-gate02
Onlinesecurityrecomendations2014 141230081030-conversion-gate02Onlinesecurityrecomendations2014 141230081030-conversion-gate02
Onlinesecurityrecomendations2014 141230081030-conversion-gate02amiinaaa
 
Cyber Security Seminar
Cyber Security SeminarCyber Security Seminar
Cyber Security SeminarJeremy Quadri
 
Cyber security for small businesses
Cyber security for small businessesCyber security for small businesses
Cyber security for small businessesB2BPlanner Ltd.
 
Cap Tech Talks Webinar April=l 2020 business email cybersecurity
Cap Tech Talks Webinar April=l 2020 business email cybersecurity Cap Tech Talks Webinar April=l 2020 business email cybersecurity
Cap Tech Talks Webinar April=l 2020 business email cybersecurity Bill Gibbs
 
Protecting Yourself Online
Protecting Yourself OnlineProtecting Yourself Online
Protecting Yourself OnlineGary Wagnon
 
Internet Safety & Privacy
Internet Safety & PrivacyInternet Safety & Privacy
Internet Safety & PrivacyAlexine Marier
 
Home and Business Computer Security 2014
Home and Business Computer Security 2014Home and Business Computer Security 2014
Home and Business Computer Security 2014B2BPlanner Ltd.
 
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...Benedek Menesi
 
Basic_computerHygiene
Basic_computerHygieneBasic_computerHygiene
Basic_computerHygieneEricK Gasana
 
How to data mine your print reports
How to data mine your print reports How to data mine your print reports
How to data mine your print reports Jim Kaplan CIA CFE
 
Cyber Security - Boundary Defense Mechanisms
Cyber Security - Boundary Defense MechanismsCyber Security - Boundary Defense Mechanisms
Cyber Security - Boundary Defense MechanismsJim Kaplan CIA CFE
 
Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Gabriella Davis
 
Office 365 in today's digital threats landscape: attacks & remedies from a ha...
Office 365 in today's digital threats landscape: attacks & remedies from a ha...Office 365 in today's digital threats landscape: attacks & remedies from a ha...
Office 365 in today's digital threats landscape: attacks & remedies from a ha...panagenda
 
Office365 in today's digital threats landscape: attacks & remedies from a hac...
Office365 in today's digital threats landscape: attacks & remedies from a hac...Office365 in today's digital threats landscape: attacks & remedies from a hac...
Office365 in today's digital threats landscape: attacks & remedies from a hac...Benedek Menesi
 
Cheapass.in — presented at JSFoo 2016
Cheapass.in — presented at JSFoo 2016Cheapass.in — presented at JSFoo 2016
Cheapass.in — presented at JSFoo 2016Aakash Goel
 
Personal Internet Security Practice
Personal Internet Security PracticePersonal Internet Security Practice
Personal Internet Security PracticeBrian Pichman
 
Death To Passwords Droid Edition
Death To Passwords Droid EditionDeath To Passwords Droid Edition
Death To Passwords Droid EditionPayPal
 

Ähnlich wie Ibm vciso sunderland (20)

Onlinesecurityrecomendations2014 141230081030-conversion-gate02
Onlinesecurityrecomendations2014 141230081030-conversion-gate02Onlinesecurityrecomendations2014 141230081030-conversion-gate02
Onlinesecurityrecomendations2014 141230081030-conversion-gate02
 
Cyber Security Seminar
Cyber Security SeminarCyber Security Seminar
Cyber Security Seminar
 
Cyber security for small businesses
Cyber security for small businessesCyber security for small businesses
Cyber security for small businesses
 
Cap Tech Talks Webinar April=l 2020 business email cybersecurity
Cap Tech Talks Webinar April=l 2020 business email cybersecurity Cap Tech Talks Webinar April=l 2020 business email cybersecurity
Cap Tech Talks Webinar April=l 2020 business email cybersecurity
 
Protecting Yourself Online
Protecting Yourself OnlineProtecting Yourself Online
Protecting Yourself Online
 
Internet Safety & Privacy
Internet Safety & PrivacyInternet Safety & Privacy
Internet Safety & Privacy
 
Home and Business Computer Security 2014
Home and Business Computer Security 2014Home and Business Computer Security 2014
Home and Business Computer Security 2014
 
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
Office365 from a hacker's perspective: Real life Threats, Tactics and Remedie...
 
Email
EmailEmail
Email
 
Basic_computerHygiene
Basic_computerHygieneBasic_computerHygiene
Basic_computerHygiene
 
How to data mine your print reports
How to data mine your print reports How to data mine your print reports
How to data mine your print reports
 
Cyber Security - Boundary Defense Mechanisms
Cyber Security - Boundary Defense MechanismsCyber Security - Boundary Defense Mechanisms
Cyber Security - Boundary Defense Mechanisms
 
Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017
 
Office 365 in today's digital threats landscape: attacks & remedies from a ha...
Office 365 in today's digital threats landscape: attacks & remedies from a ha...Office 365 in today's digital threats landscape: attacks & remedies from a ha...
Office 365 in today's digital threats landscape: attacks & remedies from a ha...
 
Office365 in today's digital threats landscape: attacks & remedies from a hac...
Office365 in today's digital threats landscape: attacks & remedies from a hac...Office365 in today's digital threats landscape: attacks & remedies from a hac...
Office365 in today's digital threats landscape: attacks & remedies from a hac...
 
Phishing
PhishingPhishing
Phishing
 
Cheapass.in — presented at JSFoo 2016
Cheapass.in — presented at JSFoo 2016Cheapass.in — presented at JSFoo 2016
Cheapass.in — presented at JSFoo 2016
 
Personal Internet Security Practice
Personal Internet Security PracticePersonal Internet Security Practice
Personal Internet Security Practice
 
Death To Passwords
Death To PasswordsDeath To Passwords
Death To Passwords
 
Death To Passwords Droid Edition
Death To Passwords Droid EditionDeath To Passwords Droid Edition
Death To Passwords Droid Edition
 

Kürzlich hochgeladen

2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 

Kürzlich hochgeladen (20)

2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 

Ibm vciso sunderland

  • 1. @1davidclarke Email cio@vciso.co for list of links • IBM Interconnect 26th March 2015 Sunderland Software Centre "Thank You to the IBM Team for puttng this event together.“ http://www.slideshare.net/IBMInterconnect/inter-connect-sunderland-agenda? qid=cbafb915-e826-4d62-9e21-b1f837afc3fa&v=&b=&from_search=5 Th
  • 2. @1davidclarke Email cio@vciso.co for list of links David Clarke • Created CERT on a Financial Intranet trading $3.5 Trillion a day ,CPNI Member 10 Years. • Managed Global Managed Security Services with a $100-$300 million Global install base 500 + Customers with $3.4 Billion dollar Contracts. • Created , maintained and improved regulatory and compliance commitments including Global PCI-DSS, ISO 27001 (10,000+ Security Devices/Systems ).
  • 3. @1davidclarke Email cio@vciso.co for list of links "The 7 Most Important Steps to Cyber protection for SME's -"
  • 4. @1davidclarke Email cio@vciso.co for list of links • "....that can cost less than a Latte and could get you Enterprise Level Cyber Security !..." • Updated List of Software /Service vciso.co/lattesecurity
  • 5. @1davidclarke Email cio@vciso.co for list of links Cost Of Latte Around the world Grande latte in Oslo cost jolting $9.83
  • 7. @1davidclarke Email cio@vciso.co for list of links How does this affect Small Business • Cyber attacks third biggest risk for UK firms, as supply chain disruption remains top concern - See more at: Jan 15th 2015 • http://www.supplymanagement.com/news/2015/cyber-attacks-third-biggest-risk-for-uk-firms-as-supply-chain- disruption-remains-top#sthash.iHZoSvDS.dpuf
  • 8. @1davidclarke Email cio@vciso.co for list of links Impact for Small Business • To Supply IT services to HMG Compliant with Cyber Essentials. • Potentially Suppliers to suppliers will need to demonstrate cyber security practices • Suppliers to larger compnanies are already being asked.
  • 9. @1davidclarke Email cio@vciso.co for list of links What can Small business do to level The playing field.
  • 10. @1davidclarke Email cio@vciso.co for list of links 1. System Misconfiguration 2. Patch Management 3. Default Passwords 4. Easy to Guess Passwords 5. Lost Devices 6. Disclosure of info via incorrect email address 7. Double Clicking Attachment/URL
  • 11. @1davidclarke Email cio@vciso.co for list of links Re- Arrange this List 1. Easy to Guess Passwords 2. Default Passwords 3. Disclosure of info via incorrect email address 4. Patch Management 5. Lost Devices 6. Double Clicking Attachment/URL 7. System Misconfiguration
  • 12. @1davidclarke Email cio@vciso.co for list of links Passwords Two Main Types Types • Master Passwords Access to PC's and Servers and Appliances <10 • Constant Use Passwords Email,Ebay,Dropbox etc >100's
  • 13. @1davidclarke Email cio@vciso.co for list of links Master Passwords If you have this Card nothing to remember Cost One Time <£5.00 https://www.qwertycards.com/
  • 14. @1davidclarke Email cio@vciso.co for list of links Constant Use Passwords If you have this Software nothing to remember Cost Yearly $12.00 Auto Fill Creates Password Saves Site Free $12/Year for Mobile
  • 15. @1davidclarke Email cio@vciso.co for list of links If you have a Large Team If you have this Software nothing to remember Cost Monthly about $10 Auto Fill Creates Password Saves Site $10/A month
  • 16. @1davidclarke Email cio@vciso.co for list of links Email Passwords • Gmail 2 Stage Authentication • Password and a text • Yahoo On time password • They will text you new password • If you have this Software nothing to remember FREE
  • 17. @1davidclarke Email cio@vciso.co for list of links List 1 1. Easy to Guess Passwords 2. Default Passwords 3. Disclosure of info via incorrect email address 4. Patch Management 5. Lost Devices 6. Double Clicking Attachment/URL 7. System Misconfiguration
  • 18. @1davidclarke Email cio@vciso.co for list of links Disclosure of Information • https://www.prot-on.com/tryIt.html Basic Version is Free Easy to use ,Quick Create a list of people allowed to see document.
  • 19. @1davidclarke Email cio@vciso.co for list of links List 3 1. Easy to Guess Passwords 2. Default Passwords 3. Disclosure of info via incorrect email address 4. Patch Management 5. Lost Devices 6. Double Clicking Attachment/URL 7. System Misconfiguration
  • 20. @1davidclarke Email cio@vciso.co for list of links Patch Managment • http://secunia.com/products/
  • 21. @1davidclarke Email cio@vciso.co for list of links List 4 1. Easy to Guess Passwords 2. Default Passwords 3. Disclosure of info via incorrect email address 4. Patch Management 5. Lost Devices 6. Double Clicking Attachment/URL 7. System Misconfiguration
  • 22. @1davidclarke Email cio@vciso.co for list of links Lost Devices • Mobile Phones • Apple Icloud • Lock/Phone/Track Phone • Android • Lock/Phone/Track Ring, Lock, or Erase AVG/Google • https://www.avgmobilation.com/
  • 23. @1davidclarke Email cio@vciso.co for list of links Lost PC's • Dropbox • Sugarsync • Google Drive • Real Time Back Up • Use Cloud encryption PerfectCloud.io to Encrypt Free Account
  • 24. @1davidclarke Email cio@vciso.co for list of links List 5 1. Easy to Guess Passwords 2. Default Passwords 3. Disclosure of info via incorrect email address 4. Patch Management 5. Lost Devices 6. Double Clicking Attachment/URL 7. System Misconfiguration
  • 25. @1davidclarke Email cio@vciso.co for list of links Double Clicking Attachment/URL • Use Gmail/Yahoo to filter out the Worst. • Panda Security Plugin warns against sites • http://www.pandasecurity.com/homeusers/downloads/wot/ • Chrome Safe Browsing enabled
  • 26. @1davidclarke Email cio@vciso.co for list of links Who are You Going To Call? • https://www.cert.gov.uk/what-we- do/responding-to-a-cyber-issue/getting- help/
  • 27. @1davidclarke Email cio@vciso.co for list of links What Are you Going to do? • https://www.malwarebytes.org/ • http://housecall.trendmicro.com/uk/ Am I really Vulnerable? https://breachalarm.com BreachAlarm monitors the Internet for your passwords being compromised and posted online.
  • 28. @1davidclarke Email cio@vciso.co for list of links Appendix
  • 29. @1davidclarke Email cio@vciso.co for list of links Bonus Slide • Kids, Controlling Access. • http://www.netgenie.net/global/ Around £100 • Free SIEM Security Incident Event Managment • https://siemless.com/ • Take Credit Cards with Free CC Reader • https://www.izettle.com/gb/service • Free Invoicing on The Web • https://www.waveapps.com/
  • 30. @1davidclarke Email cio@vciso.co for list of links • Breach Legislation, IT or Legal? • " the proposed regulation of up to 5% of annual worldwide turnover, or €100"
  • 31. @1davidclarke Email cio@vciso.co for list of links • Information Sharing , Who,When, How • "The ICO has imposed a monetary penalty of £200000 on the British Pregnancy Advice Service (BPAS) for exposing thousands of personal"
  • 32. @1davidclarke Email cio@vciso.co for list of links • Compliance is the best protection? • "Resistance is futile" Gartner • "Brighton and Sussex University Hospitals NHS Trust fined £325k after hard drives with highly- sensitive patient data were sold on eBay, - "
  • 33. @1davidclarke Email cio@vciso.co for list of links • Best Practice or is this Compliance ? • "The ICO can issue fines of up to £500,000 for serious breaches of the Data Protection Act and Privacy and Electronic Communications Regulations." ICO
  • 34. @1davidclarke Email cio@vciso.co for list of links • Incident Response,Strategy • "There are two kinds of big companies in the U.S. Those who’ve been hacked by the Chinese and those who don’t know they’ve been hacked.” FBI