rsa conference 2016 review

13
RSA Conference 2016 Review AKA “THIS WAS THE ONLY WAY TO GET MY TRAVEL EXPENSES APPROVED”

Upload: norman-w-mayes

Post on 13-Feb-2017

93 views

Category:

Internet


1 download

TRANSCRIPT

Page 1: RSA Conference 2016 Review

RSA Conference 2016 ReviewAKA “THIS WAS THE ONLY WAY TO GET MY TRAVEL EXPENSES APPROVED”

Page 2: RSA Conference 2016 Review

So what did we learn at the RSA Conference this year?

Data Privacy!OR THE LACK OF…

Page 3: RSA Conference 2016 Review

vs

Page 4: RSA Conference 2016 Review

Data Privacy & Breaches

Types of Privacy Data Compromised

Social Security Numbers Credit/Debit Card Numbers Emails/Passwords/User Names Protected Health Information (PHI)

Page 5: RSA Conference 2016 Review

Data Breaches by Category

Insider Theft Hacking Data on the Move Third Party (Subcontractors) Employee Error (Negligence) Accidental Internet Exposure Physical Theft

Page 6: RSA Conference 2016 Review

Data Breaches Galore 2015!

3%10%

0%

20%

67%

2015 Record Breaches

Banking Business Education GovernmentHealthcare

By the Numbers – USA Only:

Banking – 5 Million Records Business – 16 Million Records Education – 750,000 Records Government – 34 Million Records Healthcare – 112 Million Records

Total – 169 Million Records**Report Records

Page 7: RSA Conference 2016 Review

37 Million 22 Million11 Million

80 Million15 Million 330,000

Page 8: RSA Conference 2016 Review

Washington Breaches 2015

Smartlabtoys.com Amazon Password Breach Noble House Hotel and

Resorts – The Commons (20,000)

T-Mobile / Experian (15 Million)

Padklocks4less.com Costco Photo Center SafeandVaultStore.com BigFishGames.com

PeaceHealth Southwest Medical Center

Washington Township Health Care District

PeaceHealth St. John Medical Center

Healthpoint Cancer Care Northwest Premera Blue Cross (11

Million) Providence Hospital St. Joseph

Medical Center

Page 9: RSA Conference 2016 Review

Noble House Hotel and Resorts

Breach Date: Unknown – Detected 9/25/2015Breach Type: ElectronicBreach Category: BusinessRecords Exposed: Yes – 19,472How was it Discovered: Customers were complaining about unauthorized charges on their credit cards.Synopsis: FBI was enlisted and a cyber-security firm examined their payment systems. Malware was detected on the payment card system.Data Breach included Names, Credit Card Numbers, Expiration Date and CVV Numbers.

Page 10: RSA Conference 2016 Review

T-Mobile and Experian

Breach Date: 9/1/2015 – Detected 9/15/2015Breach Type: ElectronicBreach Category: BusinessRecords Exposed: Yes – 15 MillionHow was it Discovered: UndisclosedSynopsis: Experian noticed unauthorized access to a select set of servers and that large amounts of credit data had been downloaded. Experian contacted T-Mobile that a breach had occurred.Data Breach included Names, Addresses, Social Security Numbers, Dates of Birth, Driver License Numbers, Passport Numbers, etc.

Page 11: RSA Conference 2016 Review

Premera Blue Cross

Breach Date: 5/5/2014 – Detected 1/29/2015Breach Type: ElectronicBreach Category: Medical/HealthcareRecords Exposed: Yes – 11 MillionHow was it Discovered: UndisclosedSynopsis: It was reviled that this was the work of a state sponsored espionage group based in China.Data Breach included Names, Addresses, Social Security Numbers, Dates of Birth, Telephone Numbers, Email Addresses, Medical Claims Information and individual Financial Information.

Page 12: RSA Conference 2016 Review

Security Best PracticesOR HOW TO AVOID BEING ON A BREACH LIST IN 2016

Encryption of data at rest, in storage and in transit Enforce effective password management policies Least Privilege User Access Regular Security Design and Code Reviews Penetration and Vulnerability Scans Multi-layer Firewall Protections Mobile Device Management Review Server Certificates Data Breach Response Plan

Page 13: RSA Conference 2016 Review

Questions?

NO ANIMALS WERE HARMED IN THE CREATION OF THIS PRESENTATION