future world: what will cybersecurity look like in … · future world: what will cybersecurity...

45
MAY 20, 2019 Los Angeles, California FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 Los Angeles, California 113 th Annual Conference Learn more by visiting us at gfoa.org #GFOA2019 Mike Bailey Finance Consultant, Municipal Research and Services Center Dan Frye SVP Corporate SecuritySierra-Cedar Cindy Compert Distinguished Engineer and Security CTO, U.S. Public Sector Market CTO, Data Security & Privacy, IBM SecurityIBM

Upload: others

Post on 21-May-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

MAY 20, 2019Los Angeles, California

FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE

FUTURE?

May 19-22, 2019 • Los Angeles, California113th Annual Conference

Learn more by visiting us at gfoa.org • #GFOA2019

Mike BaileyFinance Consultant, Municipal Research and Services Center

Dan FryeSVP Corporate SecuritySierra-Cedar

Cindy CompertDistinguished Engineer and Security CTO, U.S. Public Sector Market CTO, Data Security & Privacy, IBM SecurityIBM

Page 2: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Future World:The Future of Information SecurityDan FryeSenior Vice President, Corporate Securitylinkedin.com/in/danfrye/

Page 3: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

The Cloud has created new opportunities for a decentralized “Things-as-Code” model that will fundamentally change business processes and how security is injected into the organization.

Authentication will be the new perimeter and Identity will be the new firewall.

Security leaders will need to apply supply chain principles to secure the data flows used by the business.

What I want you to remember

Page 4: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://aws.amazon.com/compliance/shared-responsibility-model/

Page 5: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

AWS Security Products

Page 6: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.csoonline.com/article/3200024/cybersecurity-labor-crunch-to-hit-35-million-unfilled-jobs-by-2021.html

Page 7: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

DETECTION & RESPONSE

PREVENTION

PROBLEM

https://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

Page 8: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.esecurityplanet.com/network-security/security-automation-and-orchestration-soar.html

Page 9: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.csoonline.com/article/3390683/how-a-data-driven-approach-to-security-helps-a-small-healthcare-team-embrace-automation.html

Page 10: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Invest in the skills and talent necessary to develop security-as-code, infrastructure-as-code, and business-process-as-code.

Lesson #1

Page 11: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.cnet.com/news/gates-predicts-death-of-the-password/

Page 12: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.cnet.com/news/massive-breach-leaks-773-million-emails-21-million-passwords/

Page 13: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://xkcd.com/936/

Page 14: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

“At Microsoft only 10 percent of our users enter a password on a given day.”

https://www.microsoft.com/security/blog/2019/05/08/3-investments-improve-identity-management-microsoft/

Page 15: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://techcrunch.com/tag/authentication/

Page 16: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Traditional Network Security Model

Page 17: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Zero TrustSecurityModel

Page 18: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://www.centrify.com/education/what-is-zero-trust-privilege/

Page 19: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Organizations have to fundamentally change their approach to identity, access, and authorization.

Lesson #2

Page 20: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual
Page 21: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual
Page 22: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

https://hbr.org/2016/09/bad-data-costs-the-u-s-3-trillion-per-year

Page 23: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

What if someone injected data or

manipulated data in a data source?

Page 24: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Security leaders need to account for data risk. What outcomes could happen if data integrity fails?

Lesson #3

Page 25: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Future World:The Future of Information Security

Dan Fryelinkedin.com/in/danfrye/

Page 26: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Cindy E. Compert, CIPT/M

Distinguished Engineer & Security CTO US Public Sector Market

CTO Data Security & Privacy, IBM Security

@CCBigData

May 20, 2019

Page 27: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Contents

• A little R&R• Scary Attacks• AI and Cloud take flight• More R&R• Advice for working with your

CISO

Page 28: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Making the Shift: R&R

Page 29: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Scary Attacks

29

Page 30: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

From Ransomware… to CryptojackingRouter Fries Egg

https://www.cnet.com/news/this-cryptocurrency-mining-router-was-hot-enough-to-serve-me-fried-eggs-black-hat-defcon/

Page 31: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

31

The Brave Little Toasterbecomes reality

Page 32: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Change is coming..

32

Page 33: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Steps you can take

Cryptojacking:• Train• Patch• Monitor

IoT:• Implement real-time inventory• Patch • Assess entire infrastructure• Isolate infrastructure and network• Consider behavioral monitoring

solutions

https://searchhealthit.techtarget.com/tip/Cryptojacking-emerging-as-a-new-threat-to-healthcare

Page 34: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

AI and Cloud Take Flight

Page 35: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

AI Security Examples

• Approach: Model behaviors and identify emerging and past threats and risks

• Applications: Network, user, endpoint, app and data, cloud

Predictive Analytics

• Approach: Curation of intelligence and contextual reasoning

• Applications: Structured and unstructured (NLP) data sources

Intelligence Consolidation

• Approach: Reason about security events for triage and response

• Applications: Cognitive SOC analyst, orchestration, automation and digital guardian

Trusted Advisors & Response

Example: AI advisorCExample: Threat enrichmentBExample: User Behavior AnalyticsA

Page 36: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

AI: Steps you can take

Understand Identify Use Cases Pilot

Test your hypotheses in a controlled scenario. Get help

from experts. Compare outcomes.

Understand AI capabilities and how they might help you accelerate security

processes

Identify use cases and measure current

processes

Page 37: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Let’s change the way we think about hybrid cloud security

Page 38: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

There are 3 key phases to the cloud adoption journey

© 2019 IBM Corporation

Baseline & Strategy

Formally starting on cloud journey, or just starting to move workloads to cloud

Hybrid Environment

Well into cloud transformation or primarily in a hybrid steady-state operation

Cloud / Multi-Cloud

Full cloud transformation or born-in-the-cloud organizations

Many organizations will be faced with the hybrid reality.

Page 39: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Shared security responsibility model has expectations of the customer

© 2019 IBM Corporation

Customer / Tenant Responsibility Cloud Service Provider Responsibility / Native Controls

ON-PREMISES CLOUD

Cloud Native Controls available

Endpoint Security

Application Controls

Identity & Access Management

Data Protection & Encryption

Network Controls

Operating System

Virtualization Layer

Network Infrastructure

Storage

Physical Infrastructure

Endpoint Security

Application Controls

Identity & Access Management

Data Protection & Encryption

Network Controls

Operating System

Virtualization Layer

Network Infrastructure

Storage

Physical Infrastructure

Page 40: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Hybrid Cloud Security: Steps you can take

Protect data Enhance Productivity Ensure Compliance

Enable compliance visibility and reporting into both your

cloud and on-premises environments

Bring your own security controls to strengthen security of your cloud

service providers

Build security into the design, so you don’t lose

productivity going back and incorporating it later

Page 41: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Only

of security budget allocated to cyber resilience activities

of highly ranked resilient organizations are very confident in their ability to prevent a cyberattack

use automation significantly or moderately

increase in threat sharing from 2017 to 2018

Cybersecurity shifts to resilience

77% of Enterprises Don’t Have a Cybersecurity Incident Response Plan

IBM Security / © 2019 IBM Corporation 41

Page 42: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Practice worst case scenarios

Page 43: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

4 Keys to R.I.S.K.

IdentifyRepeat Sustain KPI’s

Page 44: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

Partner with your CISO• Invest in security according to

value/risk• Know thy data, know thy risk• A security strategy with timelines

is critical• Communicate cyber risk to the

business in specific scenarios

Page 45: FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN … · FUTURE WORLD: WHAT WILL CYBERSECURITY LOOK LIKE IN THE FUTURE? May 19-22, 2019 • Los Angeles, California. 113. th . Annual

[email protected]

@CCBigData

Thank you

IBM Security / © 2019 IBM Corporation 45