CYBERSECURITY Situational awareness Franois Thill, Director - - PowerPoint PPT Presentation

cybersecurity
SMART_READER_LITE
LIVE PREVIEW

CYBERSECURITY Situational awareness Franois Thill, Director - - PowerPoint PPT Presentation

CYBERSECURITY Situational awareness Franois Thill, Director Cybersecurity, Ministry of the economy Agenda The actual situation Strategy of the ministry Risk management a common language Some good practice examples 2 The


slide-1
SLIDE 1

CYBERSECURITY

Situational awareness

François Thill, Director Cybersecurity, Ministry of the economy

slide-2
SLIDE 2

Agenda

  • The actual situation
  • Strategy of the ministry
  • Risk management – a common language
  • Some good practice examples

2

slide-3
SLIDE 3

The actual situation

3

… threats are mature – we are too, aren‘t we?

slide-4
SLIDE 4

Convergence

  • Towards a „monoculture“ of systems
  • Everything is connected

Convergence of technologies

http://www.geneticliteracyproject.org

slide-5
SLIDE 5

Vulnerabilities

  • „Zero-Day“
  • Human vulnerabilities (I love you)

Vulnerabilities

Photos by Justin Baeder and Ricardo Martins

slide-6
SLIDE 6

Development of the threat landscape (LU)

Threat actors are mature, highly skilled, with deep pockets

  • 55% crime
  • 40% espionage
  • 5% activism

Michael Surran : http://commons.wikimedia.org/wiki/File:Boy_with_Commodore_Vic_20_%281984%29.jpg

slide-7
SLIDE 7

Subcontractors

  • Service quality of subcontractors (who will you call)

Subcontractors

Jordy Meow: Gunkanjima. A view from the school.

slide-8
SLIDE 8

It is not an individual challenge

Stop fighting alone – it is a societal challenge!

  • We need skills
  • We need to reduce costs and complexity
  • We need to work together and share

Rootology: Rowboat with oars and two passengers.

slide-9
SLIDE 9

Strategy of the ministry

9

… Security for all, together !

slide-10
SLIDE 10

Photo: Alexandre Dulaunoy

  • Democratization of security
  • Manage risks
  • Identify synergies
  • mutualize
  • cooperate
  • Reduction of compliance efforts

Strategy of the ministry

slide-11
SLIDE 11

Risk management makes it possible

Principle of proportionality and necessity

slide-12
SLIDE 12

Deliver reliable results

Risik management must

slide-13
SLIDE 13

Deliver comparable results

Photo: Ionutzmovie

Risik management must

slide-14
SLIDE 14

Be repeatable

Risik management must

slide-15
SLIDE 15

Risk Management – the common language

Definition of scope Definition of risk appetite Definition of primary assets and criticality Identification of secondary assets Identification of asset’s vulnerabilities Identification of threats exploiting asset’s vulns Estimation and evaluation of risk Risk reduction, avoidance, extern., acceptance Risk = Impact x Threat x Vulnerability

slide-16
SLIDE 16

Good practice

  • CASES

: Risk Management

  • CIRCL

: MISP & AIL

  • C3

: Room 42 and so much more

slide-17
SLIDE 17

Good practice - CASES

  • Risk management based upon fobjective metrics
  • Creation of comparable results
slide-18
SLIDE 18

Good practice - CIRCL

  • MISP – Malware Information Sharing Platform
slide-19
SLIDE 19

Good practice - CIRCL

  • AIL – Analysis of Information Leaks
slide-20
SLIDE 20

Good practice – C3

Room 42

slide-21
SLIDE 21

Thank you - François Thill

  • www.securitymadein.lu
  • www.cases.lu
  • www.circl.lu
  • https://monarc.lu
  • CIRCL

: MISP & AIL

  • C3

: Room 42 und soviel mehr