glenny mexico city april 2016 v2 - sitio.amis.com.mx€¦ · social media networks encryption isps...

55

Upload: others

Post on 06-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 2: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

CRIME

THE STRUGGLE FOR THE INTERNET

ESPIONAGE & INTEL

SABOTAGE & WARFARE

Page 3: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

law enforcement

R (remote) A (access)

T (tool)

data retentionSnowden

press freedom

civil liberties

social engineering

deception software piracy

social medianetworks

encryption

isps

ransomwaredns servers

Int. Telecoms Union

big data

SABOTAGE & WARFARE

malware

ESPIONAGE & INTEL

ChinaRussia

USA

Israel

BritainFrance

hacktivismGermany

CRIME

Page 4: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Communication

Option 2

Page 5: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Communication Threat Awareness

Option 2

Page 6: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Communication Threat Assessment Strategic Security Thinking

Option 2

Communication Threat Awareness Strategic Security Thinking

Option 2

Page 7: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

UNOMICONUMATIC

Page 8: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

COMONUMINTAIC

Page 9: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

CATMUMONIONIC

Page 10: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

COMMUNICATION

Page 11: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

COMMUNICATION

Page 12: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Subject:I love you :)

Page 13: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 14: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 15: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 16: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 17: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 18: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 19: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

© 2013 KPMG LLP, a Canadian limited liability partnership and a member firm of the KPMG network of independent member firms affiliated with KPMG International Cooperative (“KPMG International”), a Swiss entity. All rights reserved.

2

Communicating up-the-chain

Risk provides a common language that enables a broader business conversation about cyber security

39% Think they will be targeted by a cyber-attack

Canadian C-suite view

64% Don’t communicate security risks to exec’s

63% Anticipate a targeted attack within 6 months

Management view

Page 20: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 21: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 22: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

THREAT AWARENESS

Page 23: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 24: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 25: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

STUDY YOUR OPPONENTS AND

LEARN FROM THEM.

Page 26: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 27: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 28: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 29: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 30: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 31: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Cracking  the  international  phone  roaming  system  was  one  of  my  easiest  targets…

SlaYwraCkerIstanbul, Turkey

Page 32: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

So  basically  I  can  send  a  message  from  anybody’s  cell  phone  anywhere  in  the  world  to  anybody  else’s  and  I  write  what  I  want.  I’ve  had  a  lot  of  fun  with  it!

SlaYwraCkerIstanbul, Turkey

Page 33: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

The  great  majority  of  those  carders  who  are  arrested  are  either  young,  naïve  or  careless.

RedBrigadesNew York

Page 34: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

As  far  as  I  know,  none  of  the  powerful  syndicates  selling  dumps  in  bulk  like  the  Russian  group  SMI  have  ever  been  detected  or  arrested…my  sense  is  the  Feds  don’t  even  know  who  they  are.

RedBrigadesNew York

Page 35: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

ReckaMalmö, Sweden

The most basic rule as far as I am concerned is

never, ever touch American cards.

Page 36: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

ReckaMalmö, Sweden

It  is  not  because  American  cards  are  difGicult...no  chip  and  pin  means  that  they  are  the  easiest  in  the  world.

Page 37: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

ReckaMalmö, Sweden

It is because if you do American cards then you are under the jurisdiction of the FBI and the Secret Service. Canadian and European police I can handle. But I prefer to stay away from the Feds.

Page 38: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

We  were  not  born  yesterday.  We  are  serious  operators.  We  have  a  digital  and  we  have  a  human  intelligence  capacity.  The  FBI  and  SOCA  may  be  watching  us.  But  we  are  watching  them  in  return.  We  anticipate  and  we  analyse  all  their  serious  moves.  

RedBrigadesNew York

Page 39: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 40: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 41: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 42: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 43: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 44: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 45: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 46: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

“…had always made concerted and substantial efforts to maintain and improve their data security systems."

Page 47: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

Welcome to Sony Pictures Entertainment.

To log on, please enter your username followed by the password.

For those who have forgotten it,today’s password is Password.

Page 48: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 49: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 50: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

1. Es relativamente fácil (y esencial) para comprobar las defensas digitales de una

empresa.

2. Utilizar ‘penetration testers.’

3. Pagarles bien! Ellos son sus mejores amigos

DIGITAL CHECKS

Page 51: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

1. Los miembros del Consejo deben entender plenamente la necesidad de una estrategia clara

de seguridad cibernética.

2. Tiene que haber una estrategia de comunicación eficaz en toda la empresa

NO BOX TICKING

3. Busque una buena cooperación entre InfoSec y Risk

Management. DESTROY SILOS!

THE HUMAN FACTOR

Page 52: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

1. No pierda el tiempo la protección de los datos inofensivos.

2. Asegúrese de que las joyas de la corona están completamente protegidos.

3. Cuidado con los dispositivos móviles

THE DATA FACTOR

Page 53: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE
Page 54: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE

STUDY YOUR OPPONENTS AND

LEARN FROM THEM.

Page 55: Glenny Mexico City April 2016 V2 - sitio.amis.com.mx€¦ · social media networks encryption isps dns servers ransomware Int. Telecoms Union big data SABOTAGE & WARFARE malware ESPIONAGE