Mark Fernandes Principal, Cyber Risk Services + FUTURE OF CYBER - - PowerPoint PPT Presentation
Mark Fernandes Principal, Cyber Risk Services + FUTURE OF CYBER - - PowerPoint PPT Presentation
Mark Fernandes Principal, Cyber Risk Services + FUTURE OF CYBER CYB CYBER SINGU GULAR ARIT ITY How cyber is becoming a key aspect of the ubiquity generation. CYBER SUMMIT More to come 3 2018 Deloitte Cyber Risk Services 4 2018
CYBER SUMMIT
+ FUTURE OF CYBER
CYB CYBER SINGU GULAR ARIT ITY
How cyber is becoming a key aspect of the “ubiquity” generation.
3 2018 Deloitte Cyber Risk Services
More to come
4 2018 Deloitte Cyber Risk Services
NEXT GENERATION CYBER DEFENCE
1 - CYBE YBER SING NGULARIT RITY
What does the future hold for cyber and the role it plays in business modernization.
+ TOPIC 1
2018 Deloitte Cyber Risk Services
The The c cha hanging b busi usine ness a and nd c cyber risk sk la land ndscape
S T E A M E L E CT R I C D I G I T A L H Y P E R - CO N N E CT E D A N D I N T E L L I G E N T
Era of
- f Ubiqu
quity ty
Era of
- f Ris
Risk
Era of
- f Com
Complia liance
7
Era of
- f Infra
rastru ructu ture
1990 - 2002 2002 - 2010 2011 - 2016 2016+
2018 Deloitte Cyber Risk Services
Source: Richard Watson: A Timeline of Emerging Science and Technology
8 2018 Deloitte Cyber Risk Services
Short Fuse Smaller Bang
2.5 3.0 1.5 4.0 0.0 4.0 3.5 4.5 3.5 3.0 2.0 Public Admin & defence Wholesale Trade Manufacturing Arts, Entert. & recreation Professional & Scientific activities Education Transportation & Storage Health & Social Services Accomod. & Food Construction & real estate Admin & support activities Utilities Infocom
Short Fuse Big Bang
Digital Potential & Time to Close the Gap w/ Contribution to Employment
Long Fuse Smaller Bang
Digital Potential (pts)
Low Impact Medium Impact
Long Fuse Big Bang
High Impact
Source :Administrative Records and Labor Force Survey, Manpower Research Statistics Department, MOM (December, 2015) ; Deloitte Global Center for Cyber Innovation Analysis
Time to close the gap (years)
Key sectors in the economy are likely to face significant disruption in the next few years
Retail/Trade FSI/Insurance Admin/Supp
- rt Services
Accommodation and Food
NEXT GENERATION CYBER DEFENCE
2 2 - THR THREAT T LANDSC SCAPE APE
What does the future hold for threats and sophistication of methods.
+ TOPIC 2
10 2018 Deloitte Cyber Risk Services
NEXT GENERATION CYBER DEFENCE
3 3 - NEED ED F FOR R NEX NEXT GENERA NERATIO ION N SOC SOC
Why does the future of cyber and business modernization require fresh thinking in Security Operations.
+ TOPIC 3
2018 Deloitte Cyber Risk Services
Chara racteri eristi tics of a Next Genera eration
- n SOC
Context
Is built on cyber insights and context. Threats are mapped to elements to accelerate value to the business.
Dwell Time
Designed to combat actor dwell time.
Adaptive
Is designed with adaptive capability in mind. That is with the assumption that the adversary (including AI) never sits still.
Frictionless
Designed to support and demonstrate value to the business, whilst driving frictionless enablement.
2018 Deloitte Cyber Risk Services
Red Reducing C Cyber Dwell Tim ll Time
Reduction n of Imp Impact to the he Busi Busine ness ss
1 D 1 Day ay – 96% 96% R Redu eduction 7 D 7 Day ay – 77% 77% R Redu eduction 14 D 14 Day ays – 58% 58% R Redu eduction 21 D 21 Day ay – 40% 40% R Redu eduction 28 D 28 Day ays – 22% 22% R Redu eduction 60 D 60 Day ay – Full B Busines ness I Impac pact
A Next Generation SOC is a key aspect for reducing Dwell time (Dwell time from Aberdeen Group).
2018 Deloitte Cyber Risk Services
Ev Evol
- lution
- n of SO
SOCs Cs
with N Next Generation ion S SOC ( C (illu lustrativ ive c capabilit ility)
Matur urity ty 1 1
Traditio itional S l SOC’s
Exploit Detection Campaign Analysis Alert and Correlation
Traditional SOC models based on NOC centric
- capability. Typically characterized by use case
methods, predominant emphasis on SLA and ticket statistics.
Matur urity ty 2 2
Iterative tive S SOC’s
Hunting Behavior Continuous Threat Content
SOC designed to address an ever changing adversary (typical threat actors). Emphasis on hunting, behavioral profiling, actor attribution etc..
Matur urity ty 3 3
Cont ntinuo nuous us R Readine ness S SOC’s
Continuous Red T eaming Self Defending Enterprise
SOC that operates in a continuous state of readiness. What characterizes this SOC is the employment of “elite” objective testers on an ongoing basis.
NEXT GENERATION CYBER DEFENCE
4 4 - IN IN SUMMA MMARY
The constraint of cyber singularity.
+ TOPIC 1
HUMAN IMAGINATION AND APPLICATION OF INNOVATION IS LIMITLESS
CYB YBER POWERIN ING COMM OMMERCIAL INNOVATION ON
The rate of global disruption, powered by cyber is virtually limitless. Rate is constrained by a number of factors. Some of the key aspects include.
The allocation of resources, innovators, funding and capability to assign to transformation and cyber enabled innovation.
R ESO U R C ES
The ability to comprehend the rate
- f change and how it applies to
their industry, customer and stakeholders.
C O MPR EH EN SIO N
The willingness to embrace change and challenging institutional
- rthodoxy.
W ILLIN G N ESS
The availability of enabling capability to enable innovation.
C A PA B ILITY
01 02 03 04
18 2018 Deloitte Cyber Risk Services
More to come
19 2018 Deloitte Cyber Risk Services