SlideShare ist ein Scribd-Unternehmen logo
1 von 14
Cyber 24-7: Sound advice for board
members, the C-Suite and non-
technical executives
Peter O’Dell
peterlodell@gmail.com
http://www.amazon.com/dp/B00IHIQWYK
Book Summary
• Cyber threat is real and unpredictable
• Board and C-Suite need to manage
• The threat extends far beyond the IT group
• Gap between management and IT
• Preparation is critical to incident response
• Outside partners/services key resource
• Incident response must be well executed
• Future threats are emerging
Who should read Cyber 24-7
• Board of Directors, C-Suite, and non-technical execs:
– Understanding impact and risk
– Key strategy elements
– Preparation and response
– Entire organizational view
• IT – CSO, CIO, CISO:
– Comprehend management perspective/responsibility
– Understand entire scope of cyber threat
– Narrow communications gap
– Improve planning and response planning
Table of Contents
• Chapter 1 The Cyber Problem – Where are we today?
• Chapter 2: Cyber: Not your everyday risk!
• Chapter 3: Leadership from the Top – Board and Executive Issues
• Chapter 4: Real time Cyber Intelligence – Preparing and Prevention
• Chapter 5: Attacked and Breached – Now What?
• Chapter 6: Cyber Information Sharing
• Chapter 7: Government Activities in Cyber
• Chapter 8: Information Resources
• Chapter 9: A Standardized Approach can streamline the future
• Chapter 10: The Future of Cyber Security
• Chapter 11: Final Conclusions
• Appendix A: Sample Incident Response Checklist
• Appendix B: Executive Order on Cyber and NIST Framework
Today’s Situation
• Victims of our own success – incredible growth
• Opportunity expands the attack surface:
– Clouds linked to legacy systems
– Internet of Things (IOT) means more entry points
– Bring Your Own Devices (BYOD)
• We’re not doing all we can:
– Boards and C-Suite largely delegating/ignoring
– Poor info sharing even at basic levels, not real-time
– Eliminating/upgrading legacy systems
– “Tone at the Top” by the board and C-Suite
– Government – no legislation since 2002, poor grades
Cyber is not a Normal Risk!
• Cyber defies conventional metrics
– Non-quantifiable
– Non-predictable
– Global, not local
– Can put the entire organization at complete risk
• Examples of normal risks:
– Weather - business interruption
– Employee and customer lawsuits
– Theft of a trailer full of cell phones
Executive Leadership
• Set the organizational “Tone at the Top”
• Responsible for oversight and priorities
• The board sets the risk tolerance level
• People should be vetted and monitored
• Outside resources should be identified
• Cross organization response should be
planned and exercised
• The threat is much broader than just IT issues
What to worry about today
• Customer payment information - Target
• Intellectual property theft – 20 year impact –
Lockheed-Martin
• Malicious insiders - Snowden
• Critical Infrastructure attack – power,
communications
• Emerging threats – important to stay current
• Device loss or theft – multiple scenarios
Board & C-Suite
Preparation/Proactive Efforts
• Set the “Tone at the Top”
• Understand executive vulnerabilities
• Consider a technical board
member/committee
• Hire the right people and partners
• Detailed risk, resilience and plan review
• Exercise the full plan across the enterprise
People – Critical at all Levels
• Industry shortage means higher Bozo % at all
levels
• Validating through outside expertise
• Finding, training, retaining and motivating
• Standing guard 24/7 very difficult
• Great can turn malicious for outside reasons
• 360 degree communications for team success
• Entire organization – this is not just an IT issue
Future Trends
• Threat is expanding with new vulnerabilities
• Mobile, Cloud, and Internet of Things (IOT)
enabling new vulnerabilities
• Sharing is still an under-utilized defense
• Law enforcement will have to improve cross-
jurisdictional investigations and prosecution
• Market of services and solutions growing rapidly
in response to the threat
• Likely will be years before a downturn in risk
About the Author – Pete O’Dell
• Current: author, board member, consultant
• Past: Multiple roles, multiple industries
– President of software division – Autodesk
– CIO: Microwarehouse, Autodesk, UCA
– COO: Online Interactive, Supertracks
– Co-founded Swan Island Networks
• Contact:
– Peterlodell@gmail.com
– Skype: Peterlodell
http://www.amazon.com/dp/B00IHIQWYK

Weitere ähnliche Inhalte

Andere mochten auch

Launching a Highly-regulated Startup in the Public Cloud
Launching a Highly-regulated Startup in the Public CloudLaunching a Highly-regulated Startup in the Public Cloud
Launching a Highly-regulated Startup in the Public CloudPoornaprajna Udupi
 
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1Anup Lakra
 
The Five Habits of High-Performing Boards
The Five Habits of High-Performing BoardsThe Five Habits of High-Performing Boards
The Five Habits of High-Performing BoardsLeading Resources, Inc.
 
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...prosenzw69
 
Board of Directors Best Practices
Board of Directors Best PracticesBoard of Directors Best Practices
Board of Directors Best PracticesRachel Weber
 
Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Amazon Web Services
 
Best Practice Corporate Board Governance
Best Practice Corporate Board GovernanceBest Practice Corporate Board Governance
Best Practice Corporate Board Governancephil_farrell
 
The role of the board of directors in corporate governance and policy making
The role of the board of directors in corporate governance and policy makingThe role of the board of directors in corporate governance and policy making
The role of the board of directors in corporate governance and policy makingClaro Ganac
 
Data Governance: Keystone of Information Management Initiatives
Data Governance: Keystone of Information Management InitiativesData Governance: Keystone of Information Management Initiatives
Data Governance: Keystone of Information Management InitiativesAlan McSweeney
 
The New Economics of Cloud Security
The New Economics of Cloud SecurityThe New Economics of Cloud Security
The New Economics of Cloud SecurityAlert Logic
 
7 cyber security questions for boards
7 cyber security questions for boards7 cyber security questions for boards
7 cyber security questions for boardsPaul McGillicuddy
 
Cloud security and security architecture
Cloud security and security architectureCloud security and security architecture
Cloud security and security architectureVladimir Jirasek
 
Data security in cloud computing
Data security in cloud computingData security in cloud computing
Data security in cloud computingPrince Chandu
 

Andere mochten auch (15)

Launching a Highly-regulated Startup in the Public Cloud
Launching a Highly-regulated Startup in the Public CloudLaunching a Highly-regulated Startup in the Public Cloud
Launching a Highly-regulated Startup in the Public Cloud
 
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1 Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
Wise Men Webinar: Fast Track Implementation of SAP GRC 10.1
 
The Five Habits of High-Performing Boards
The Five Habits of High-Performing BoardsThe Five Habits of High-Performing Boards
The Five Habits of High-Performing Boards
 
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...
UCI Exec. MBA & Forum for Corp. Directors July 2009 - Board Governance: E...
 
Board of Directors Best Practices
Board of Directors Best PracticesBoard of Directors Best Practices
Board of Directors Best Practices
 
Board of Directors: Structure and Consequences - Quick Guide
Board of Directors: Structure and Consequences - Quick GuideBoard of Directors: Structure and Consequences - Quick Guide
Board of Directors: Structure and Consequences - Quick Guide
 
Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices Journey Through The Cloud - Security Best Practices
Journey Through The Cloud - Security Best Practices
 
Best Practice Corporate Board Governance
Best Practice Corporate Board GovernanceBest Practice Corporate Board Governance
Best Practice Corporate Board Governance
 
The role of the board of directors in corporate governance and policy making
The role of the board of directors in corporate governance and policy makingThe role of the board of directors in corporate governance and policy making
The role of the board of directors in corporate governance and policy making
 
It governance & cobit 5
It governance & cobit 5It governance & cobit 5
It governance & cobit 5
 
Data Governance: Keystone of Information Management Initiatives
Data Governance: Keystone of Information Management InitiativesData Governance: Keystone of Information Management Initiatives
Data Governance: Keystone of Information Management Initiatives
 
The New Economics of Cloud Security
The New Economics of Cloud SecurityThe New Economics of Cloud Security
The New Economics of Cloud Security
 
7 cyber security questions for boards
7 cyber security questions for boards7 cyber security questions for boards
7 cyber security questions for boards
 
Cloud security and security architecture
Cloud security and security architectureCloud security and security architecture
Cloud security and security architecture
 
Data security in cloud computing
Data security in cloud computingData security in cloud computing
Data security in cloud computing
 

Mehr von Peter ODell

The global future jan2016
The global future jan2016The global future jan2016
The global future jan2016Peter ODell
 
Cyber threat enterprise leadership required march 2014
Cyber threat   enterprise leadership required  march 2014Cyber threat   enterprise leadership required  march 2014
Cyber threat enterprise leadership required march 2014Peter ODell
 
The global future april 2012
The global future april 2012The global future april 2012
The global future april 2012Peter ODell
 
Interoperable Data Pete Odell
Interoperable Data Pete OdellInteroperable Data Pete Odell
Interoperable Data Pete OdellPeter ODell
 
The Global Future
The Global FutureThe Global Future
The Global FuturePeter ODell
 

Mehr von Peter ODell (6)

The global future jan2016
The global future jan2016The global future jan2016
The global future jan2016
 
Cyber threat enterprise leadership required march 2014
Cyber threat   enterprise leadership required  march 2014Cyber threat   enterprise leadership required  march 2014
Cyber threat enterprise leadership required march 2014
 
The global future april 2012
The global future april 2012The global future april 2012
The global future april 2012
 
Interoperable Data Pete Odell
Interoperable Data Pete OdellInteroperable Data Pete Odell
Interoperable Data Pete Odell
 
World 2.0
World 2.0World 2.0
World 2.0
 
The Global Future
The Global FutureThe Global Future
The Global Future
 

Kürzlich hochgeladen

Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...allensay1
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceDamini Dixit
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesDipal Arora
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangaloreamitlee9823
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756dollysharma2066
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 

Kürzlich hochgeladen (20)

Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 

Cyber 24 7 slideshare march 2014

  • 1. Cyber 24-7: Sound advice for board members, the C-Suite and non- technical executives Peter O’Dell peterlodell@gmail.com
  • 3. Book Summary • Cyber threat is real and unpredictable • Board and C-Suite need to manage • The threat extends far beyond the IT group • Gap between management and IT • Preparation is critical to incident response • Outside partners/services key resource • Incident response must be well executed • Future threats are emerging
  • 4. Who should read Cyber 24-7 • Board of Directors, C-Suite, and non-technical execs: – Understanding impact and risk – Key strategy elements – Preparation and response – Entire organizational view • IT – CSO, CIO, CISO: – Comprehend management perspective/responsibility – Understand entire scope of cyber threat – Narrow communications gap – Improve planning and response planning
  • 5. Table of Contents • Chapter 1 The Cyber Problem – Where are we today? • Chapter 2: Cyber: Not your everyday risk! • Chapter 3: Leadership from the Top – Board and Executive Issues • Chapter 4: Real time Cyber Intelligence – Preparing and Prevention • Chapter 5: Attacked and Breached – Now What? • Chapter 6: Cyber Information Sharing • Chapter 7: Government Activities in Cyber • Chapter 8: Information Resources • Chapter 9: A Standardized Approach can streamline the future • Chapter 10: The Future of Cyber Security • Chapter 11: Final Conclusions • Appendix A: Sample Incident Response Checklist • Appendix B: Executive Order on Cyber and NIST Framework
  • 6. Today’s Situation • Victims of our own success – incredible growth • Opportunity expands the attack surface: – Clouds linked to legacy systems – Internet of Things (IOT) means more entry points – Bring Your Own Devices (BYOD) • We’re not doing all we can: – Boards and C-Suite largely delegating/ignoring – Poor info sharing even at basic levels, not real-time – Eliminating/upgrading legacy systems – “Tone at the Top” by the board and C-Suite – Government – no legislation since 2002, poor grades
  • 7. Cyber is not a Normal Risk! • Cyber defies conventional metrics – Non-quantifiable – Non-predictable – Global, not local – Can put the entire organization at complete risk • Examples of normal risks: – Weather - business interruption – Employee and customer lawsuits – Theft of a trailer full of cell phones
  • 8. Executive Leadership • Set the organizational “Tone at the Top” • Responsible for oversight and priorities • The board sets the risk tolerance level • People should be vetted and monitored • Outside resources should be identified • Cross organization response should be planned and exercised • The threat is much broader than just IT issues
  • 9. What to worry about today • Customer payment information - Target • Intellectual property theft – 20 year impact – Lockheed-Martin • Malicious insiders - Snowden • Critical Infrastructure attack – power, communications • Emerging threats – important to stay current • Device loss or theft – multiple scenarios
  • 10. Board & C-Suite Preparation/Proactive Efforts • Set the “Tone at the Top” • Understand executive vulnerabilities • Consider a technical board member/committee • Hire the right people and partners • Detailed risk, resilience and plan review • Exercise the full plan across the enterprise
  • 11. People – Critical at all Levels • Industry shortage means higher Bozo % at all levels • Validating through outside expertise • Finding, training, retaining and motivating • Standing guard 24/7 very difficult • Great can turn malicious for outside reasons • 360 degree communications for team success • Entire organization – this is not just an IT issue
  • 12. Future Trends • Threat is expanding with new vulnerabilities • Mobile, Cloud, and Internet of Things (IOT) enabling new vulnerabilities • Sharing is still an under-utilized defense • Law enforcement will have to improve cross- jurisdictional investigations and prosecution • Market of services and solutions growing rapidly in response to the threat • Likely will be years before a downturn in risk
  • 13. About the Author – Pete O’Dell • Current: author, board member, consultant • Past: Multiple roles, multiple industries – President of software division – Autodesk – CIO: Microwarehouse, Autodesk, UCA – COO: Online Interactive, Supertracks – Co-founded Swan Island Networks • Contact: – Peterlodell@gmail.com – Skype: Peterlodell