evolving impact of cybersecurity · evolving impact of cybersecurity nba session 20 may 2016...

12
The information contained herein is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavour to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act on such information without appropriate professional advice after a thorough examination of the particular situation. © 2016 KPMG Advisory N.V., registered with the trade register in The Netherlands under number 33263682, is a member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved. Printed in The Netherlands. The KPMG name, logo and ‘cutting through complexity’ are registered trademarks of KPMG International. Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA

Upload: others

Post on 13-Mar-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

The information contained herein is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavour to provide accurate and timely information,

there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act on such information without appropriate

professional advice after a thorough examination of the particular situation.

© 2016 KPMG Advisory N.V., registered with the trade register in The Netherlands under number 33263682, is a member firm of the KPMG network of independent member firms affiliated with KPMG

International Cooperative (‘KPMG International’), a Swiss entity. All rights reserved. Printed in The Netherlands.

The KPMG name, logo and ‘cutting through complexity’ are registered trademarks of KPMG International.

Evolving impact of Cybersecurity

NBA session 20 May 2016

Prof.dr. Rob Fijneman RE RA

Page 2: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

2

Trends and challenges

Digital

transformati

on

Technology adoption and dramatically expands threat landscape

Future-proofing the omni-connected world

Government

intervention Governments become increasingly interventionist

Laws and regulations in cyber space increase

Beyond

protection Ability to protect is progressively compromised

Moving from protection to detection and response

Source: ISF Threat Horizon 2018, January 2016

Page 3: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

3

Virtualisation and cloud

From on premise,

unless… to cloud, unless…

Adoption

gradually

increased Now a true

upswing

Page 4: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

4

The next generation’s

CISO

Board level

communication

Business

enablement

From “no”,

to “yes, unless…”

Volatile

landscape

Page 5: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

5

Laws and regulations evolve:

Privacy and security

Privacy

classification

EU-US Privacy

Shield

Breach notification

Page 6: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

6

Complex tooling landscape

Page 7: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

7

From prevention to response

Red teaming

Incident readiness

Changing

mindset

Page 8: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

8

• The frequency and severity of cybersecurity attacks are increasing

• Cybersecurity is no longer just an IT issue

• Attacks evolve including their impact on the organization

Evolving impact of cybersecurity

on audits

Page 9: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

9

Marketplace response to Cyber

risk

• Stakeholders/regulators asking questions

• PCAOB asking questions on handling Cyber risks by auditors

• SEC continues to highlight impact

• AFM/DNB questions regarding Cyber risks, monitoring thereof and auditing

Page 10: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

10

Assessment of Cyber maturity

• Auditors can support in developing tools to access and monitor risks

• IT auditors jointly with other audit disciplines

• Maturity assessment is a good concept to support the journey

• Current tool issued by NBA working group is fit for purpose

• Be aware that developments are huge, highly flexible approach is required

Page 11: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

11

A single view on cyber trends and

threats: How to stay relevant

(http://cyber.kpmg.com/#) YOU WANT TO SEE

WHAT’S HAPPENING Be up to date on the latest information

security developments, incidents and

emerging threats. Have situational awareness

in your industry.

YOU WANT TO TAKE

ACTION Don’t miss out on developments. Add value to

your decision making, and enrich your operational

cyber defense processes. Know what can happen

to you, and act upon it.

Page 12: Evolving impact of Cybersecurity · Evolving impact of Cybersecurity NBA session 20 May 2016 Prof.dr. Rob Fijneman RE RA ... and dramatically expands threat landscape Future-proofing

12