NIS Breakfast Briefing
Thursday 6th September 2018
Secure Your Supply Chain
NIS Breakfast Briefing Secure Your Supply Chain Thursday 6 th - - PowerPoint PPT Presentation
NIS Breakfast Briefing Secure Your Supply Chain Thursday 6 th September 2018 Agenda Welcome David Duke, Gemserv An Introduction to NIS Ian Davis, Gemserv Case Study National Energy Generator and Distributor Andy Green, Aprose
Secure Your Supply Chain
David Duke, Gemserv
Ian Davis, Gemserv
Andy Green, Aprose
Ewan Duncan, Associated British Ports
Gemserv 2
David Duke, Gemserv
Ian Davis, Gemserv
Andy Green, Aprose
Ewan Duncan, Associated British Ports
Gemserv 3
NIS Regulation Breakfast Meeting
Gemserv 5
Gemserv 6
Gemserv 7
Increase in new downloader variants*
Increase in IoT Attacks*
Increase in mobile malware variants*
Overall increase in reported vulnerabilities*
Overall increase in reported vulnerabilities*
Increase in industrial control system (ICS) related vulnerabilities*
*Source: Symantec 2018 Internet Security Threat Report
Gemserv 8
Initial Compromise Intelligence gather Stolen credentials Modify systems Future attack OT
Gemserv 9
State and state-sponsored threats
strategic advantage
Gemserv 10
Gemserv 11
CAF NIS 72 HOURS CAF CAF INCIDENTS OFCOM CRITICAL SYSTEMS
OES THRESHOLDS INCIDENTS CAF FINDINGS
inflexible assessment process
everything an assessor needs to consider
Gemserv 12
judgement
normally need to consider
some cases
across organisations
established
Gemserv 13
14
Gemserv 15
250,000 Consumers 200,000 Consumers 10M+ Passengers Providers of healthcare TLD 2 billion DNS 2M+ IXP 50% DNS 250,000
Suppliers IT & OT Network Physical People Processes ICS Transport Thresholds
Gemserv 16
Other CNI, power, water, transport, DSP Dependencies on sector
Essential Service
Gemserv 17
OT OT
Essential Service
Gemserv 18
Essential Service
Gemserv 19
Objective: essential service
level Criticality, function and processes Tolerable disruption without dependencies Recovery time objective (RTO) Recovery point objective (RPO)
Risk assessment Strategy and priority
Essential Service
Gemserv 21
Essential Service
threat
Gemserv 22
Essential Service
Gemserv 23
capabilities for OT & IT
Essential Service
Gemserv 24
Essential Service
Gemserv 25
Essential Service
suppliers?
Gemserv 26
David Duke, Gemserv
Ian Davis, Gemserv
Andy Green, Aprose
Ewan Duncan, Associated British Ports
Gemserv 27
29
30
31
32
David Duke, Gemserv
Ian Davis, Gemserv
Andy Green, Aprose
Ewan Duncan, Associated British Ports
Gemserv 33
Ewan Duncan Group Head of Security Associated British Ports
NIS R and cyber security.
25/09/2018 35
(ISPS)
NIS R and cyber security.
25/09/2018 36
NIS R and cyber security.
25/09/2018 37
NIS R and cyber security.
25/09/2018 38
Security of Networked and Information Systems
NIS R and cyber security.
25/09/2018 39
Security of Networked and Information Systems
NIS R and cyber security.
25/09/2018 40
ABP’s approach
On track, so far……
NIS R and cyber security.
25/09/2018 41
Have we suffered cyber attacks ?
NIS R and cyber security.
25/09/2018 42
Have we suffered cyber attacks ?
Ewan Duncan Group Head of Security Associated British Ports