emerging trends in critical infrastructure protection€¦ · emerging trends in critical...

13
Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist IBM Wednesday, 16 September 4:00 PM - 5:00 PM

Upload: others

Post on 22-May-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Emerging Trends in Critical Infrastructure Protection

Session Facilitator:

Pete Allor

Senior Cyber Security Strategist

IBM

Wednesday, 16 September 4:00 PM - 5:00 PM

Page 2: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Session presenters:

• Denise Anderson, Executive Director, The National Health Information Sharing & Analysis Center (NH-ISAC)

• Catherine Lotrionte, Director, Institute for Law, Science & Global Security, Georgetown University

• Parham Eftekhari, Senior Fellow, Institute for Critical Infrastructure Technology (ICIT)

Page 3: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Emerging Trends in Critical Infrastructure Protection

Twitter: @ICITorg

Page 4: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

About ICIT

• Mission

• Non-Partisan, Advising to House & Senate, Federal Agencies, Critical Infrastructure Sector Stakeholders

• Initiatives

• Legislative Research & Briefings

Twitter: @ICITorg

Page 5: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Fellows

Page 6: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Challenges

• Evolving and Expansive Attack Surface

• Dependency on Archaic Legacy Systems

• Dedicated and Diversified Adversaries

• Turnkey Exploit Kits (MaaS, etc.)

• Absence of Cybersecurity Training

Page 7: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Attack Basics

1. Social Engineering

Collect Intelligence

2. Custom Exploit Kit

3. Spear Phishing Attack

4. Threat Actor Gains Access Moves Laterally to Achieve Higher Levels of Admin Access

5. Data Exfiltration or Manipulation

Page 8: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

What can we do?

People, Process, Technology

Education, Legislation, Technology

Page 9: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Education

• Business Leaders

• Training Employees

• Legislative Community

• Workforce Shortage – H1B Visa Dependency

• Public Awareness – Early Stage Education

• Bottom Line: Cultures of Cybersecurity!

Page 10: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Legislation

• Targeting specific vulnerabilities

• IoT & Manufacturing Standards for Cybersecurity

• Reasonable Encryption Legislation

• Threat Information Sharing

• Re-Building Trust

Legislative Education is Paramount!

Page 11: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Technology

Create a Virtual “Tar-Pit”

• Multi-Factor Authentication

• Biometrics

• Behavioral Analytics + Behavioral Biometrics

• Multilayered Encryption

‒ Encrypt at File, Folder, and Source-code level

Part of Your Holistic Cybersecurity Strategy

Page 12: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Summary

• Attack Surface is Growing (IoT)

• Threat Actors Evolving

• Solution: Education, Strong Legislation, Multi-layered Security

Email: [email protected]

Twitter: @ICITorg

Page 13: Emerging Trends in Critical Infrastructure Protection€¦ · Emerging Trends in Critical Infrastructure Protection Session Facilitator: Pete Allor Senior Cyber Security Strategist

Questions?