Mo Cashman Director, Global Defense Solutions McAfee What builds - - PowerPoint PPT Presentation

mo cashman director global defense solutions mcafee what
SMART_READER_LITE
LIVE PREVIEW

Mo Cashman Director, Global Defense Solutions McAfee What builds - - PowerPoint PPT Presentation

Mo Cashman Director, Global Defense Solutions McAfee What builds Trust? RESILIENCE TRANSPARENCY GOVERNANCE WHY RESILIENCE ? Structured Adversaries HACKTAVIST ORG CRIME NATION-STATE What is Resilience? RESIST FAILURE RAPID RESPONSE


slide-1
SLIDE 1

Mo Cashman Director, Global Defense Solutions McAfee

slide-2
SLIDE 2

What builds Trust?

RESILIENCE TRANSPARENCY GOVERNANCE

slide-3
SLIDE 3

WHY RESILIENCE ?

slide-4
SLIDE 4
slide-5
SLIDE 5

HACKTAVIST ORG CRIME NATION-STATE

Structured Adversaries

slide-6
SLIDE 6

RESIST FAILURE RAPID RESPONSE SURVIVABILITY

What is Resilience?

slide-7
SLIDE 7

Who’s Talking Resilience?

slide-8
SLIDE 8

Stakeholders

Government Industry Service Providers CERTs Standards Orgs

slide-9
SLIDE 9

Smart Grid Challenges

Scale Life Cycle Culture Data Privacy Standards

slide-10
SLIDE 10

Current Grid Environment

slide-11
SLIDE 11

DESIGN GOVERNMENT STRATEGY DEVELOP , ENFORCE CONTROLS STANDARDS

CYBER READINESS MULTI-ZONE DEFENSES INTELLIGENCE- DRIVEN RESPONSE CYBER OPERATIONS

MONITORING, ANALYTICS and CONTROL

INTEGRATED DECISION SUPPORT SYSTEMS

INTELLIGENCE VISIBILITY

GENERATE AWARENESS

Resilience (Cyber) Framework

slide-12
SLIDE 12

ENTERPRISE ENVIRONMENT OPERATIONS ENVIRONMENT SUPPLY CHAIN ENVIRONMENT

Protected Environments

slide-13
SLIDE 13

How important is Response?

6-9 months is average time an adversary maintains a presence on the network before they are detected

slide-14
SLIDE 14

What’s important in a Crisis?

slide-15
SLIDE 15

Response OODA Loop

OBSERVE ORIENT DECIDE ACT

Detect that an incident occurred Rapid Analysis and Comprehension Validate with Intelligence & Context Find, Contain, Fix and Prevent

slide-16
SLIDE 16

How fast can we FIND, CONTAIN and FIX a security breach to contain damage? How fast can we ACQUIRE and INTEGRATE new capability to maintain safety?

Speed = Survivability

slide-17
SLIDE 17

Intelligence is Critical

  • Integrated intelligence and analytics allowed

JSOC to increase hunt missions from a few a week to multiple per night

slide-18
SLIDE 18
slide-19
SLIDE 19
slide-20
SLIDE 20

1

Prevent Something Bad from Happening Proactive Defense

2

Find Something Bad Inside the Network Incident Response

3

Find The Bad Guy Root Cause Investigation

Roles of Intelligence

slide-21
SLIDE 21

Agile Intelligence Sharing

“Speed of Paper” “Speed of the Network”

slide-22
SLIDE 22

Barriers to Intelligence Sharing

Politics Standards Governance Classifications

slide-23
SLIDE 23

Summary of Key Points

Stakeholders Trust Standards Resilience

slide-24
SLIDE 24