Continuous security
Kim van Wilgen | Schuberg Philis
nl.linkedin.com/kimvanwilgen kimvanwilgen@gmail.com www.kimvanwilgen.com @kimvanwilgen
Continuous security nl.linkedin.com/kimvanwilgen - - PowerPoint PPT Presentation
Continuous security nl.linkedin.com/kimvanwilgen kimvanwilgen@gmail.com Kim van Wilgen | Schuberg Philis www.kimvanwilgen.com @kimvanwilgen September 2017 Cybercriminals accessed the personal data of 145.5M consumers 209K credit card
nl.linkedin.com/kimvanwilgen kimvanwilgen@gmail.com www.kimvanwilgen.com @kimvanwilgen
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Cybercriminals accessed the personal data of 145.5M consumers
209K credit card credentials were taken $ 300M was paid to victims and $275M in fines
@kimvanwilgen | www.kimvanwilgen.com Continuous security
meantime
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Customer director Schuberg Philis
Head of software development ANVA
Head of IT Klaverblad Verzekeringen
Hello world
6
Mission critical digital transformations Financially independent Started in 2001 300 team members (Dec 2018) EUR 60m revenue Market Quality leader in Business Critical IT Outsourcing Single KPI 100% customer satisfaction
7
8
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Thiago de Faria – Head of solutions engineering, LINKIT
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Static Analyses Security Testing
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Dynamic Application Security Testing
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Eliminate known vulnerabilities
24
We use Jfrog Xray Alternatives
checker
analysis)
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Tsvi Korren - Chief Solutions Architect at Aqua Security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Source: Gartner report on cloud security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Compare the infrastructure with CIS best practices, eg admin account, encryption and patch level
the pipeline
through pull request @securityteam
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Unrelevant / Sast / Dast / RAST / other Train for risks we can’t automate
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Chaos Engineering: Make rare events regular
@kimvanwilgen | www.kimvanwilgen.com Continuous security
Troy Hunt, MVP for developer security and creator of ‘Have I been PWNED”
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
@kimvanwilgen | www.kimvanwilgen.com Continuous security
SAST DAST Dep.check Licensing Evil stories Config as code Immutability Test against CIS config CDN SIEM Train Raise awareness Hack yourself Red teaming SecLead Value based Start small Adapt to context Fix issues Detect change Version control
@kimvanwilgen | www.kimvanwilgen.com Continuous security
https://sdtimes.com/developers/gartners-guide-to-successful-devsecops/ https://cybersecurity.isaca.org/static-assets/documents/State-of-Cybersecurity-part- 2-infographic_res_eng_0517.pdf https://www.sans.org/reading-room/whitepapers/critical/continuous-security- implementing-critical-controls-devops-environment-36552 10 Things to Get Right for SuccessfulDevSecOps, Gartner, 2017, IDG00341371 https://www.gartner.com/doc/reprints?id=1-4TI72Y2&ct=180320&st=sb https://www.thoughtworks.com/radar/techniques https://www.mmc.com/content/dam/mmc-web/Global-Risk-Center/Files/MMC- Cyber-Handbook_2016-web-final.pdf Reimagining Security and IT Resilience for a Cloud-Native DevSecOps World, Gartner, 2018