legal disclaimer copyright notice€¦ · © clearwater compliance | all rights reserved clearwater...

45
1 Legal Disclaimer Although the information provided by Clearwater Compliance may be helpful in informing customers and others who have an interest in data privacy and security issues, it does not constitute legal advice. This information may be based in part on current federal law and is subject to change based on changes in federal law or subsequent interpretative guidance. Where this information is based on federal law, it must be modified to reflect state law where that state law is more stringent than the federal law or other state law exceptions apply. This information is intended to be a general information resource and should not be relied upon as a substitute for competent legal advice specific to your circumstances. YOU SHOULD EVALUATE ALL INFORMATION, OPINIONS AND RECOMMENDATIONS PROVIDED BY CLEARWATER IN CONSULTATION WITH YOUR LEGAL OR OTHER ADVISOR, AS APPROPRIATE. Copyright Notice All materials contained within this document are protected by United States copyright law and may not be reproduced, distributed, transmitted, displayed, published, or broadcast without the prior, express written permission of Clearwater Compliance LLC. You may not alter or remove any copyright or other notice from copies of this content. *The existence of a link or organizational reference in any of the following materials should not be assumed as an endorsement by Clearwater Compliance LLC. © Clearwater Compliance | All Rights Reserved

Upload: others

Post on 06-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

1

Legal Disclaimer

Although the information provided by Clearwater Compliance may be helpful in informing customers and others who have an interest in data privacy and security issues, it does not constitute legal advice. This information may be based in part on current federal law and is subject to change based on changes in federal law or subsequent interpretative guidance. Where this information is based on federal law, it must be modified to reflect state law where that state law is more stringent than the federal law or other state law exceptions apply. This information is intended to be a general information resource and should not be relied upon as a substitute for competent legal advice specific to your circumstances. YOU SHOULD EVALUATE ALL INFORMATION, OPINIONS AND RECOMMENDATIONS PROVIDED BY CLEARWATER IN CONSULTATION WITH YOUR LEGAL OR OTHER ADVISOR, AS APPROPRIATE.

Copyright Notice

All materials contained within this document are protected by United States copyright law and may not be reproduced, distributed, transmitted, displayed, published, or broadcast without the prior, express written permission of Clearwater Compliance LLC. You may not alter or remove any copyright or other notice from copies of this content.

*The existence of a link or organizational reference in any of the following materials should not be assumed as an endorsement by Clearwater Compliance LLC.

© Clearwater Compliance | All Rights Reserved

Page 2: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

© Clearwater Compliance | All Rights Reserved

Clearwater Customer Council Meeting

December 17, 2019

Page 3: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

3

© Clearwater Compliance | All Rights Reserved

Welcome

Today’s Agenda

• Introduction – Lori Hessey

• Educational Content

➢George W. Jackson, Jr. | Senior Principal Consultant‘Artificial Intelligence & Cybersecurity : Current State & Future Directions’

• Feedback and Suggestions

Page 4: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

4

© Clearwater Compliance | All Rights Reserved

About your Hosts

Lori Hessey

Director of Customer SuccessJon Stone, MPA, PMP, HCISPP, CRISC

SVP, Product Innovation

• 15 + years of Customer Support and Service in

Healthcare and Human Resources

• 10 + years experience in SaaS Startup Companies

• 10 + years Sales & Business Development

• Proven success managing over 250 national

accounts from BETA testing, implementation

coordination, client education, and final

installation stages of complex proprietary

software in healthcare environment

• Skilled in curriculum design of training programs,

and leadership development

• 25+ years in Healthcare in the compliance,

provider, payer and healthcare quality

improvement fields

• Innovator | Strategic Program Manager |

Consultant | Executive

• 15+ years of strategic leadership for compliance

and Healthcare information technology projects

involving sensitive ePHI for companies such as

CIGNA, Healthways and OPTUMInsight

• PMP, MPA - Healthcare Policy and

Administration

• Business Passion: Driving business and

technology solutions for improving healthcare

operations and outcomes

• Play Passion: Cycling and Oil Painting

Page 5: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

5

© Clearwater Compliance | All Rights Reserved

Purpose of the Customer Community

Where Clearwater customers receive additional value and benefits

Customer Council Meetings• Complimentary educational content• A place for customers interact and learn from each other

Page 6: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

6

© Clearwater Compliance | All Rights Reserved

Meeting Logistics: Audio Control Panel

Where Clearwater customers receive additional value and benefits

• All attendees on mute • Type in Q&A section with a question or

comment• We will be watching the Q&A section like

a hawk and will make sure your comment or question gets addressed!

This Photo by Unknown Author is licensed under CC BY-SA

Page 7: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Artificial Intelligence & Cybersecurity: Current State & Future Directions

Page 8: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

© Clearwater Compliance | All Rights Reserved

• Artificial Intelligence

• Machine Learning and Deep Learning

• Separating Fact from Fiction

• Good AI vs. Evil AI

• Future Trends in AI and Cybersecurity

Today’s Agenda

Page 9: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

9

© Clearwater Compliance | All Rights Reserved

• 30 years’ experience in Information Systems.

• 20 years’ experience in Information Security.

• 10 years’ experience in Healthcare IT Project Management.

• Former VP Information Systems, Alpha-Omega Chemical Company.

• Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control

(CRISC), Healthcare Information Security and Privacy Professional (HCISPP), Project Management Professional

(PMP).

• BS Information Technology Management, MBA Information Technology Management, Doctor of Philosophy in

Information Technology with a specialization in Information Assurance and Cybersecurity. Focus: Medical Device

Cybersecurity.

George W. Jackson, Jr. | MBA, Ph.D., CRISC, HCISPP, CISSP, PMP

Senior Principal Consultant, Clearwater

Today’s Presenter

https://www.linkedin.com/in/georgewjacksonjr/

Page 10: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Artificial Intelligence

Page 11: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

11

© Clearwater Compliance | All Rights Reserved

Overview of Artificial Intelligence

The field of AI research began in the 1940s; however investment and activity in the field has accelerated for the past decade due to the emergence of three factors:• Advances in Big Data• Advances in the field of Machine

Learning • Advances in computer processing

power.

Page 12: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

12

© Clearwater Compliance | All Rights Reserved

Artificial General Intelligence (AGI)

• Artificial General Intelligence (AGI) refers to systems capable of exhibiting human-level intelligence. AGI is still generally thought to be decades away from realization.

• AGI systems will be able to demonstrate multiple competencies across a limitless number of knowledge domains and rival human intellectual capabilities.

Page 13: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

13

© Clearwater Compliance | All Rights Reserved

Artificial Superintelligence (ASI)

• Artificial Superintelligence (ASI) represents the pinnacle of AI.

• Due to advances in cognitive technologies and increases in systems processing speed and power, ASI systems will eventually exceed human capabilities to store, analyze, and synthesize data potentially leading to a scenario popularly referred to as the singularity.

Page 14: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Machine Learning and

Deep Learning

Page 15: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

15

© Clearwater Compliance | All Rights Reserved

Artificial Narrow Intelligence (ANI) and Machine Learning

• Artificial Narrow Intelligence (ANI) refers to algorithms that address specific problem sets like games, image recognition, search and navigation.

• All current AI systems fall into the ANI category. The most prevalent approach to AI being machine learning (ML). ML involves statistical algorithms that replicate human cognitive tasks by deriving their own procedures through the analysis of large data sets.

Page 16: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

16

© Clearwater Compliance | All Rights Reserved

How a Machine Learns Supervised, Unsupervised and Partially Supervised

• During the learning process a computer program is “trained.” One style of learning is called supervised learning where the program is given a “cheat sheet” aid the learning process.

• In the case of unsupervised learning the ML system creates its own statistical models to accomplish a specific task in situations it has not been guided through or previously encountered.

Page 17: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

17

© Clearwater Compliance | All Rights Reserved

Artificial neural networks (ANN)

• Machine Learning reads structured and unstructured data and then forms patterns and clusters of patterns from which its analysis is structured.

• This is achieved programmatically in the form of artificial neural networks (ANN). The goal of an artificial neural network is to mimic how the human brain formulates thoughts and decisions.

Page 18: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

18

© Clearwater Compliance | All Rights Reserved

Deep Learning is Achieved through Deep Neural Networks

• Deep Learning utilizes series of complex ANNs or Deep Neural Networks. ANNs designed to go multiple layers deep. The goal of these complex or deep neural networks are to further mimic the human brain and its ability to formulate thoughts and carry out decision making.

Page 19: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Separating Fact from Fiction

Page 20: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

20

© Clearwater Compliance | All Rights Reserved

AI will Solve all of Our Problems

“77% of CEOs say AI and automation will increase vulnerability and disruption to the way they do business.” Source:

https://www.pwc.com/us/en/services/consulting/library/artificial-intelligence-predictions/responsible-ai.html

Page 21: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

21

© Clearwater Compliance | All Rights Reserved

AI will Solve all of Our Problems (Part 2)

“Gartner predicts that through 2022, 85 percent of AI projects will deliver erroneous outcomes due to bias in data, algorithms, or the teams responsible for managing them.” Source: https://enterprisersproject.com/article/2018/2/state-ai-10-eye-opening-statistics

Page 22: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

22

© Clearwater Compliance | All Rights Reserved

AI will Take Years to Deliver Any Tangible Results

“According to a recent Deloitte survey, 83 percent of the most aggressive adopters of AI and cognitive technologies said their companies have already achieved either moderate (53 percent) or substantial (30 percent) benefits.” Source: https://enterprisersproject.com/article/2018/2/state-ai-10-eye-opening-statistics

Page 23: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

23

© Clearwater Compliance | All Rights Reserved

Artificial Intelligence will Take Away Jobs

“Gartner Says By 2020, Artificial Intelligence Will Create More Jobs Than It Eliminates.”Source: https://www.gartner.com/en/newsroom/press-releases/2017-12-13-gartner-says-by-2020-artificial-intelligence-will-create-more-jobs-than-it-eliminates

Page 24: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

24

© Clearwater Compliance | All Rights Reserved

Weak vs. Strong AI

• Often called Weak AI, many of us already encounter the simplest form of Artificial Intelligence nearly everyday. We do this when we interact with intelligent agents such as Alexa, Siri, and Google Assistant. Also Chat Bots and IVR’s.

• Strong AI, on the other hand, would resemble AGI or ASI as spoken about previously.

Page 25: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Good AI Evil AI

Versus

Page 26: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

26

© Clearwater Compliance | All Rights Reserved

Good AI: Automated Network Analysis

• ML systems are a natural fit for tedious, repetitive tasks such as those found in Network analysis

• ML systems can tirelessly analyze enormous volumes of data thereby enabling organizations to monitor their networks more accurately and reliably.

Page 27: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

27

© Clearwater Compliance | All Rights Reserved

Good AI: Machine Learning for Anti-Malware and Antivirus

• Modern viruses and malware typically evolve over time.

• Organizations need nimble and dynamic approaches to combat this ever-evolving threat landscape.

• ML systems with deep learning can leverage information recorded from previous attacks to build predictive defenses.

Page 28: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

28

© Clearwater Compliance | All Rights Reserved

Good AI: Email Security

• AI-based anti-phishing programs perform deep link inspection, simulating clicks on links within the email and examine those link pages for signs of phishing.

• Natural Language Processing (NLP) can used to determine if grammar (or lack thereof) and/or word choice raise suspicion of a phishing attack.

Page 29: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

29

© Clearwater Compliance | All Rights Reserved

Good AI: Incident Response

• Techniques such as knowledge engineering and case-based reasoning can be used to improve cyber incident response

• AI Tools can aid the creation of incident response playbooks that guide responders on the best course of action. AI can be used to analyze past experiences and modify future approaches to incident response.

Page 30: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

30

© Clearwater Compliance | All Rights Reserved

Good AI: User Behavior Modeling

• AI-based cybersecurity systems can model the behavior network users. This modeling can detect account takeover attacks where an attacker has stolen user credentials to gain access to network resources.

• By analyzing and learning normal user behavior ML systems can detect and respond to anomalies.

Page 31: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

31

© Clearwater Compliance | All Rights Reserved

Good AI: User Behavior Modeling (Part 2)

• AI-based user behavior modeling can also detect insider cybersecurity threats be they malicious or unintended.

• User behavior modeling can enhance machine learning of desirable cybersecurity practices

Page 32: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

32

© Clearwater Compliance | All Rights Reserved

Evil AI: Hackers Have AI Too

• Hackers also have access to AI and can use machine learning to enhance and improve their malware.

• The goal being the creation of malware that can thwart artificially intelligent defenses.

Page 33: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

33

© Clearwater Compliance | All Rights Reserved

Evil AI: Hackers Have Upped Their Game

• Hackers have embraced the tools of machine learning, deep learning and NLP to create potent advanced persistent threats (APT).

• Smart APTs sit on a network and not only learn about network traffic but also learn about end users on the system.

• Thus providing Hackers with more opportunities to access and exploit sensitive data.

Page 34: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

34

© Clearwater Compliance | All Rights Reserved

Evil AI: More Potent and Lethal Insider Threats

• As the Dark Web has made it easier for would be hackers to purchase malware kits and receive online training there is an increased threat that relatively unskilled threat actors can execute sophisticated cyberattacks.

Page 35: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

Future Trends in AI and Cybersecurity

Future Directions

Page 36: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

36

© Clearwater Compliance | All Rights Reserved

Future Trends: Advanced Asset Management

• AI and machine learning will continue to enable advanced asset management software and systems.

• Asset Management tools continue to be built which not only discover, track and monitor assets on the network but also offer extended analytics and cyber defense capabilities.

Page 37: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

37

© Clearwater Compliance | All Rights Reserved

Future Trends: Perimeter and Endpoint Security

Next-generation firewalls have in-built machine learning technology that detects patterns in network packets and automatically blocks activity determined to be a threat.

Unified Threat Management (UTM) will improve perimeter and end-point defense.

ML will improve the detection of zero-day vulnerabilities

Page 38: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

38

© Clearwater Compliance | All Rights Reserved

Future Trends: Process Automation

It is well known there is a shortage of experienced cybersecurity professionals. Given this severe shortage of cybersecurity resources and the sheer volume of data most organizations need to analyze daily, there will be growth in the demand for and the production of AI/ML tools to automate cybersecurity operations and processes.

Page 39: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

39

© Clearwater Compliance | All Rights Reserved

Future Trends: Information Privacy Will Continue to Gain Greater Focus

Data streams can be easily captured and analyzed by machine learning algorithms having access to:

• Mobile device data

• Video and surveillance data

• Biometric data, Facial Recognition data, Protected Health Information

Will continue to see more stringent Privacy Laws.

Page 40: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

40

© Clearwater Compliance | All Rights Reserved

Hackers will continue to Leverage AI

Threat actors will continue to proliferate and “push the envelop” of AI/ML to bypass security controls—especially those defended through the use of AI/ML — leveraging the same technological advances companies are benefiting from in order to hack into those organizations.

Page 41: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

41

© Clearwater Compliance | All Rights Reserved

The Global Implications of Artificial Intelligence

• The Chinese government has announced its plans to be a global leader in AI by 2030.

• Vladimir Putin publicly stated, “Whoever becomes the leader in this field [AI] will rule the world.”

• The U.S. Government has identified artificial intelligence as one of the key technologies will ensure U.S. national defense.

Page 42: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

42

© Clearwater Compliance | All Rights Reserved

Next Generation Cybersecurity

It is obvious that, artificial intelligence and machine learning one of the essential components of the next-generation cybersecurity tools and best practices. Using AI and ML to maintain cyber resilience will help organizations secure their Business and IT environments against today’s ever-evolving threat landscape.

Page 43: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

43

© Clearwater Compliance | All Rights Reserved

Thank you & Question's

George Jackson

[email protected]

Thank you for taking the time to complete the exit survey. We look forward to your input as we appreciate and utilize the feedback received.

Page 44: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

44

© Clearwater Compliance | All Rights Reserved

Upcoming Educational Events

Jan. 15, 202011 am – 12pm CT

Register today! Jon Moore, Chief of Risk Officer and head of Consulting Services for the healthcare cyber risk management company Clearwater, will review the key elements of the legislation and discuss its implications.

* This event is hosted by HFMA & available to HFMA members only.

Jan. 29, 202011 am – 12pm CTJoin Clearwater for a live demonstration of the power of the best tool in the industry used by hundreds of organizations to perform an OCR-quality HIPAA Security Risk Analysis.

Page 45: Legal Disclaimer Copyright Notice€¦ · © Clearwater Compliance | All Rights Reserved Clearwater Customer Council Meeting December 17, 2019

© Clearwater Compliance | All Rights Reserved

www.ClearwaterCompliance.com

800.704.3394

LinkedIn | linkedin.com/company/clearwater-compliance-llc/

Twitter | @clearwaterhipaa