it security awareness - trent university · 2018-02-28 · • overview of security landscape in...

26
Tales from the Trenches at Trent University IT Security Awareness

Upload: others

Post on 29-May-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Tales from the Trenches at Trent University

IT Security Awareness

Page 2: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Overview of security landscape in higher education• Current measures and controls• Awareness efforts • Phishing Simulation• Challenges• Next steps

Agenda

1

Page 3: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Growing Threats - Nature of the business• Advanced Persistent Threat

• Students? • FIPPA / PIPEDA • ISO 27001, SANS 20 (CIS)

2

Current Information Security Climate

Page 4: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Students – Part time and full time, residence and off campus.• Staff – Fairly typical • Faculty – Full time, part time

3

Understanding our Demographics

Page 5: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Students – Access to their own student data, wireless network (their own wireless networks), network accounts, desktop access.

• Faculty – Access to personal student information, network and desktop access.

• Staff – Access to a large amount of personal student information, network and desktop access.

4

The Risks

Page 6: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• They’re busy!• They’re scared to “bother” support staff• Wide range of devices

5

Student Challenges

Page 7: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Changing Technology • Budget Difficulties • Access to large amounts of data• Technology Knowledge – Mechanisms for keeping up with technology

change.

6

Staff Challenges

Page 8: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Traveling – Not fixed to a single location• Periods of not teaching – Summer, Sabbatical leaves, Research trips • Part-time status

7

Faculty Challenges

Page 9: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Phishing• Information Theft • Information Loss (or improper disclosure)• Data Integrity • Malware• DOS / DDOS

8

Specific Problems

Page 10: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing
Page 11: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing
Page 12: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing
Page 13: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Don’t Take the

Bait__________________

_Trent IT will NEVER

ask you for your username and

password in an email request.

Page 14: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Is your data backed up?

___________________

Backup your files to Google Drive or OneDrive today

Page 15: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

When you send me your username and

password__________________

_

If it sounds too good to be true, it always is.

Yours free!

Page 16: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Does your computer have pending updates?___________________

Updates fix critical vulnerabilities in your computer. Unpatched systems are the easiest

way for hackers to infect your computer with

malware. Install updates today!

Page 17: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Your photos are your memories.

Keep them safe by backing up your phone to Google Photos today___________________

Unlimited Space with your Trent account!

Page 18: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

Don’t be caught without a backup plan

Backup your data___________________

Google Drive for Students

Microsoft OneDrive for Staff

Page 19: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing
Page 20: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• May 2017 – PhishingBox.com was contracted to provide a platform to launch simulated phishing on staff and faculty accounts and report on the results.

• 5 phishing tests of varying complexity have been completed. • Individual users are not identified

19

Simulated Phishing

Page 21: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

20

The bait

Page 22: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

21

The bait

Page 23: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

22

The bait

Page 24: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

23

Results

Test Link Clicked Full Submit

Easy 4.5 3.3

Moderate 2.8 1

Difficult 6 3

Page 25: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• “Just fix it” • Getting people in for training • Policy• Mobility • Changing Enviornments

24

Challenges

Page 26: IT Security Awareness - Trent University · 2018-02-28 · • Overview of security landscape in higher education • Current measures and controls • Awareness efforts • Phishing

• Security Survey • Training for “higher risk” users• More distance sessions• Cyber Security Awareness Month

25

Next Steps