SlideShare ist ein Scribd-Unternehmen logo
1 von 42
#44CONNETSQUARE #HITBGSEC2019NETSQUARE
A presentation by Saumil Shah
44CON 2019 London
#44CONNETSQUARE
special thanks to
Dr. Igor Podebrad
Kelly White
Anoop Sethi
Hiren Shah
Thomas Dullien
#44CONNETSQUARE
A TALE OF TWO KEYNOTES
#44CONNETSQUARE
ATTACKS ARE A
TECHNICAL PROBLEM,
DEFENSE IS A
POLITICAL PROBLEM
THOMAS DULLIEN,
"Why we are not building a
defendable Internet" BH ASIA 2O17
#44CONNETSQUARE
DEAR CISO,
WHO ARE YOU MOST
SCARED OF?
SAUMIL SHAH
"The Seven Axioms Of Security"
BH ASIA 2O17
#44CONNETSQUARE
DILEMMA:
ATTACKERS or AUDITORS?
#44CONNETSQUARE
1. CISO - Defend the organization.
2. Threat Intel - Collect Everything.
3. Test Realistically.
4. Can't Measure? Can't Use.
5. Users - One Size Fits NONE!
6. Best Defense = Proactive Defense.
7. Make Defense Visible.
The Seven Axioms of Security
#44CONNETSQUARE
x 3 WORLD 1-1
#44CONNETSQUARE
$2.5M!!
#44CONNETSQUARE
#44CONNETSQUARE
#44CONNETSQUARE
LIFE's A BEACH!
#44CONNETSQUARE
HIGH MEDIUM LOW
#44CONNETSQUARE
LIFE's A BEA*CH!
#44CONNETSQUARE
#44CONNETSQUARE
#44CONNETSQUARE
x 2 WORLD 2-1
DILEMMA: ^C
#44CONNETSQUARE
REGULATORS
BOARD
IT VENDORS
YOUR TEAM
CISO
Understand the relationships
#44CONNETSQUARE
#44CONNETSQUARE
#44CONNETSQUARE
CODE vs TOIL
!
MANUALLY
RUNS SCRIPT
WRITES
SCRIPT
"#
non GEEK
GEEK
MANUALLY
MAKES FUN
OF GEEK'S
COMPLICATED
METHOD
CAN'T
COPE
#44CONNETSQUARE
SHOULDERS OF GIANTS
ANOOP SETHI
formerly BT
KELLY WHITE
formerly Zionsbank
Dr IGOR PODEBRAD
Commerzbank AG
#44CONNETSQUARE
THERE IS A WAY
#44CONNETSQUARE
HAVE NOTS HAVES
Capable of
custom analytics
threat detection
and response
Owning Cyber Security
Sucked up all the talent
Not capable
Cyber Security is a
necessary evil
Purely dependent upon
commercial solutions
CYBERSECURITY ASYMMETRY DILEMMA
#44CONNETSQUARE
BUILD SWARM
INTELLIGENCE
#44CONNETSQUARE
Spiral Dynamics
#44CONNETSQUARE
TRANSPERSONAL
PERSONAL
Survival
Power Gods
control & ego
Kin Spirits
protection
Truth Force
conformity
Strive Drive
achievement
Human Bond
relationships
Flex Flow
adaptability
Whole View
experential
#44CONNETSQUARE
Spiral Dynamics
HIVE MIND
The swarm will learn and
overcome any obstacle
The Leader is the CATALYST
SELECT THE GOALS
WORTH FIGHTING FOR
#44CONNETSQUARE
The Downward Spiral
Cascade Effect
Doesn't take much to de-orbit
It all hinges upon the
LEADER
#44CONNETSQUARE
Nurturing the Spiral
The Leader's Reflection
PROTECT the Swarm
EMPOWER
the Swarm
Form strong
PARTNERSHIPS
#44CONNETSQUARE
Catalyst
Listen more
than you speak
Build capabilities
Strong relationships
with the business
Authoritative
Behave in a superior way
over their team-mates
Fight the business
The "Sky Is Falling"
#44CONNETSQUARE
A CENTRE OF EXCELLENCE FOR
ALL OF TECHNICAL SECURITY
An Independent Consultancy
within the organisation
#44CONNETSQUARE
PROTECT
THE SWARM
Creative Insulation
HONESTY and
OPENNESS
! Happens
Don't throw them
under the bus!
No Blank Cheques
#44CONNETSQUARE
#44CONNETSQUARE
EMPOWER The Swarm
Call you out on your bull!
#44CONNETSQUARE
PARTNERSHIPS
Surround yourself with Smart
people in Small teams
#44CONNETSQUARE
THE TALENT WILL
COME TO YOU
#44CONNETSQUARE
THE CISO'S DILEMMA
YOUR OWN SIDE THE TEAM'S SIDE
#44CONNETSQUARE
THE CISO'S DILEMMA
YOUR OWN SIDE THE TEAM'S SIDE
#44CONNETSQUARE
WHEN YOU'RE
ON YOUR OWN
#44CONNETSQUARE
"I'VE LEFT TWO LETTERS FOR YOU"
@ NOT the GRUGQ
Blame it all on me.
Write two letters.
#44CONNETSQUARE
THANK YOU
@therealsaumil

Weitere ähnliche Inhalte

Ähnlich wie The CISO's Dilemma 44CON 2019

Cyber resilience itsm academy_april2015
Cyber resilience itsm academy_april2015Cyber resilience itsm academy_april2015
Cyber resilience itsm academy_april2015
ITSM Academy, Inc.
 
Cultural Transformations - Lean and Agile
Cultural Transformations - Lean and AgileCultural Transformations - Lean and Agile
Cultural Transformations - Lean and Agile
Gautham Pallapa
 
Business Model Innovation
Business Model InnovationBusiness Model Innovation
Business Model Innovation
César Salazar
 

Ähnlich wie The CISO's Dilemma 44CON 2019 (20)

14 Kotel
14 Kotel14 Kotel
14 Kotel
 
Cyber resilience itsm academy_april2015
Cyber resilience itsm academy_april2015Cyber resilience itsm academy_april2015
Cyber resilience itsm academy_april2015
 
Carbon Black: 32 Security Experts on Changing Endpoint Security - Quotes from...
Carbon Black: 32 Security Experts on Changing Endpoint Security - Quotes from...Carbon Black: 32 Security Experts on Changing Endpoint Security - Quotes from...
Carbon Black: 32 Security Experts on Changing Endpoint Security - Quotes from...
 
Blue Line Operations
Blue Line OperationsBlue Line Operations
Blue Line Operations
 
Influential Business Leaders in Security services | CIO Look
Influential Business Leaders in Security services | CIO LookInfluential Business Leaders in Security services | CIO Look
Influential Business Leaders in Security services | CIO Look
 
Journeyman to Master
Journeyman to MasterJourneyman to Master
Journeyman to Master
 
Cultural Transformations - Lean and Agile
Cultural Transformations - Lean and AgileCultural Transformations - Lean and Agile
Cultural Transformations - Lean and Agile
 
Internet Security - Protecting your critical assets
Internet Security - Protecting your critical assetsInternet Security - Protecting your critical assets
Internet Security - Protecting your critical assets
 
we are weXelerate
we are weXeleratewe are weXelerate
we are weXelerate
 
Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
Tenable: Economic, Operational and Strategic Benefits of Security Framework A...Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
 
How to build a startup SLASSSCOM Talk Aug 2015
How to build a startup SLASSSCOM Talk Aug 2015How to build a startup SLASSSCOM Talk Aug 2015
How to build a startup SLASSSCOM Talk Aug 2015
 
Use open innovation and competitions to accelerate your innovation process
Use open innovation and competitions to accelerate your innovation processUse open innovation and competitions to accelerate your innovation process
Use open innovation and competitions to accelerate your innovation process
 
Astd 2009
Astd 2009Astd 2009
Astd 2009
 
10 Most Influential Leaders in Cybersecurity 2023.pdf
10 Most Influential Leaders in Cybersecurity 2023.pdf10 Most Influential Leaders in Cybersecurity 2023.pdf
10 Most Influential Leaders in Cybersecurity 2023.pdf
 
We Are All Digital Startups Now
We Are All Digital Startups NowWe Are All Digital Startups Now
We Are All Digital Startups Now
 
Technophile CEO's Revamping the Tech October 2020
Technophile CEO's Revamping the Tech October 2020Technophile CEO's Revamping the Tech October 2020
Technophile CEO's Revamping the Tech October 2020
 
Keyless Technologies - NOAH19 London
Keyless Technologies - NOAH19 LondonKeyless Technologies - NOAH19 London
Keyless Technologies - NOAH19 London
 
Technophile CEO's Revamping the Tech October 2020
Technophile CEO's Revamping the Tech October 2020Technophile CEO's Revamping the Tech October 2020
Technophile CEO's Revamping the Tech October 2020
 
Business Model Innovation
Business Model InnovationBusiness Model Innovation
Business Model Innovation
 
New Tech Meetup, Silicon Halton #54
New Tech Meetup, Silicon Halton #54New Tech Meetup, Silicon Halton #54
New Tech Meetup, Silicon Halton #54
 

Mehr von Saumil Shah

Mehr von Saumil Shah (20)

The Hand That Strikes, Also Blocks
The Hand That Strikes, Also BlocksThe Hand That Strikes, Also Blocks
The Hand That Strikes, Also Blocks
 
Debugging with EMUX - RIngzer0 BACK2WORKSHOPS
Debugging with EMUX - RIngzer0 BACK2WORKSHOPSDebugging with EMUX - RIngzer0 BACK2WORKSHOPS
Debugging with EMUX - RIngzer0 BACK2WORKSHOPS
 
Unveiling EMUX - ARM and MIPS IoT Emulation Framework
Unveiling EMUX - ARM and MIPS IoT Emulation FrameworkUnveiling EMUX - ARM and MIPS IoT Emulation Framework
Unveiling EMUX - ARM and MIPS IoT Emulation Framework
 
Announcing ARMX Docker - DC11332
Announcing ARMX Docker - DC11332Announcing ARMX Docker - DC11332
Announcing ARMX Docker - DC11332
 
Precise Presentations
Precise PresentationsPrecise Presentations
Precise Presentations
 
Effective Webinars: Presentation Skills for a Virtual Audience
Effective Webinars: Presentation Skills for a Virtual AudienceEffective Webinars: Presentation Skills for a Virtual Audience
Effective Webinars: Presentation Skills for a Virtual Audience
 
INSIDE ARM-X Cansecwest 2020
INSIDE ARM-X Cansecwest 2020INSIDE ARM-X Cansecwest 2020
INSIDE ARM-X Cansecwest 2020
 
Cyberspace And Security - India's Decade Ahead
Cyberspace And Security - India's Decade AheadCyberspace And Security - India's Decade Ahead
Cyberspace And Security - India's Decade Ahead
 
Cybersecurity And Sovereignty - A Look At Society's Transformation In Cyberspace
Cybersecurity And Sovereignty - A Look At Society's Transformation In CyberspaceCybersecurity And Sovereignty - A Look At Society's Transformation In Cyberspace
Cybersecurity And Sovereignty - A Look At Society's Transformation In Cyberspace
 
NSConclave2020 The Decade Behind And The Decade Ahead
NSConclave2020 The Decade Behind And The Decade AheadNSConclave2020 The Decade Behind And The Decade Ahead
NSConclave2020 The Decade Behind And The Decade Ahead
 
Cybersecurity In India - The Decade Ahead
Cybersecurity In India - The Decade AheadCybersecurity In India - The Decade Ahead
Cybersecurity In India - The Decade Ahead
 
INSIDE ARM-X - Countermeasure 2019
INSIDE ARM-X - Countermeasure 2019INSIDE ARM-X - Countermeasure 2019
INSIDE ARM-X - Countermeasure 2019
 
Introducing ARM-X
Introducing ARM-XIntroducing ARM-X
Introducing ARM-X
 
The Road To Defendable Systems - Emirates NBD
The Road To Defendable Systems - Emirates NBDThe Road To Defendable Systems - Emirates NBD
The Road To Defendable Systems - Emirates NBD
 
Schrödinger's ARM Assembly
Schrödinger's ARM AssemblySchrödinger's ARM Assembly
Schrödinger's ARM Assembly
 
ARM Polyglot Shellcode - HITB2019AMS
ARM Polyglot Shellcode - HITB2019AMSARM Polyglot Shellcode - HITB2019AMS
ARM Polyglot Shellcode - HITB2019AMS
 
What Makes a Compelling Photograph
What Makes a Compelling PhotographWhat Makes a Compelling Photograph
What Makes a Compelling Photograph
 
Make ARM Shellcode Great Again - HITB2018PEK
Make ARM Shellcode Great Again - HITB2018PEKMake ARM Shellcode Great Again - HITB2018PEK
Make ARM Shellcode Great Again - HITB2018PEK
 
HackLU 2018 Make ARM Shellcode Great Again
HackLU 2018 Make ARM Shellcode Great AgainHackLU 2018 Make ARM Shellcode Great Again
HackLU 2018 Make ARM Shellcode Great Again
 
Hack.LU 2018 ARM IoT Firmware Emulation Workshop
Hack.LU 2018 ARM IoT Firmware Emulation WorkshopHack.LU 2018 ARM IoT Firmware Emulation Workshop
Hack.LU 2018 ARM IoT Firmware Emulation Workshop
 

Kürzlich hochgeladen

%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
masabamasaba
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
masabamasaba
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 

Kürzlich hochgeladen (20)

WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security Program
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
Devoxx UK 2024 - Going serverless with Quarkus, GraalVM native images and AWS...
 
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
 
WSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go PlatformlessWSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go Platformless
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
 
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
%in Hazyview+277-882-255-28 abortion pills for sale in Hazyview
 
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
 
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
 
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
WSO2CON 2024 - Navigating API Complexity: REST, GraphQL, gRPC, Websocket, Web...
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
tonesoftg
tonesoftgtonesoftg
tonesoftg
 
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
Direct Style Effect Systems -The Print[A] Example- A Comprehension AidDirect Style Effect Systems -The Print[A] Example- A Comprehension Aid
Direct Style Effect Systems - The Print[A] Example - A Comprehension Aid
 

The CISO's Dilemma 44CON 2019