total email protection · cloud backup email continuity ai for social engineering account takeover...

24
Total Email Protection Mike Gorman – Senior Systems Engineer

Upload: others

Post on 09-Sep-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Total Email Protection

Mike Gorman – Senior Systems Engineer

Page 2: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Who we are

▪ Barracuda offers industry-leading IT security & data protection solutions that protect 150,000+ organizations worldwide –From SMB to large Enterprise

▪ Based in Silicon Valley, our organization has 1,500+ employees,offices in 15 different countries & 6,500+ resellers worldwide

▪ We’re an Amazon Advanced Technology Partner and a MicrosoftPartner of the Year Winner 2016 (Microsoft Azure certified ISV solution award) having helped several thousand customers transition safely to Office 365 and Azure

Copyright © 2019 Barracuda Networks Inc. (US) All rights reserved.

Page 3: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Our Mission

To be the leading security platform for today’s IT professionals by protecting Applications, Data and

Users anywhere

Page 4: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Why Barracuda?

▪ We provide complete solutions to IT problems, with unprecedented: -

Ease of management

Ease of deployment

Ease of doing business

Customer support

Value

Page 5: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Why Barracuda for Email Protection?

Page 6: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Inte

rtitle

Email-borne risk is an existential threatHow will you secure more than just the gateway?

Page 7: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

93%

Targeted attacks start with email

Social engineering represents 93% of email breaches

- 2018 Verizon DBIR

Page 8: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Email threats 1.0

Spam/malware

Email

Gateway InboxInternet

Legitimate

Mail

Zero Day

Page 9: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Email threats 2.0

Spam/malware

Email

Gateway InboxInternet

Legitimate

Mail

Zero Day

Brand

ImpersonationBusiness

Email

Compromise

(BEC)

Distracted

Emailing

Purchased

Credentials

Personal

Accounts

Conversation

Hijacking

Account

Takeover

(ATO)

Page 10: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Phishing Attacks

• Compromised Account

• Originates from Office 365

• URL points to suspicious

domain – lkdkjfjfjf11.com

Page 11: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Spear Phishing Attacks• Display Name Spoofing

• Making unusual requests

• Engages in Human

conversation

Page 12: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Conversation Hijacking

Page 13: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Traditional security is not enough

Corporate

InboxEmail High Reputation Sender Zero-Day Links No Malicious Payload

Social Engineering

Reputation Filter | Content Filter | Advanced Threat Protection

✓ ✓ ✓

Page 14: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Inte

rtitle

Securing the gateway is still necessary,but no longer sufficient

Page 15: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Next Generation Email Protection

Forensics

and

Incident

Response

O365 | G Suite | Exchange

Inbound/Outbound

Security

Encryption and DLP

for Secure Messaging

Archiving for

ComplianceGateway Defense

Phishing Simulation and TrainingSecurity

Awareness

Resiliency Cloud Backup Email Continuity

AI for Social

Engineering

Account Takeover

Defense

Brand Protection

DMARC ReportingInbox Defense

Page 16: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Co

nte

nt

Barracuda Total Email Protection

Forensics

and

Incident

Response

Gateway Defense

ResilienceBarracuda

Essentials

Security AwarenessBarracuda

PhishLine

Inbox DefenseBarracuda

Sentinel

Page 17: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

BR

AN

D -

Inte

rtitle

Get Your Free EmailThreat Scan

Page 18: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Thank You

Page 19: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

CybersecurityOperationsReporting &Engineering

Page 20: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Origination of the CORE Program

• Consult our clients on the importance of a good security posture

• Use the program to build a strong security culture

• Leverage security standards and best practices NIST, ISO, CSC

• This approach allows us to lower the overall risks, detect, respond, and remediate quickly.

Page 21: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Ohio Data Protection Act(Safe Harbor)

✓ Follow a Security Framework (have a plan)

• NIST, Cybersecurity Framework 1.1, or regulatory (HIPPA, PCI DSS)

• Demonstrate due diligence

Page 22: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Building the CORE Security Program

1. ID: Assets, Regulatory, Risks

2. PR: VM, Training, Managing access (MFA)

3. DE: SOC, Barracuda TEP,

4. RE: Remediation, Communication

5. RC: DR/BCP, Lessons Learned, Maturity

Page 23: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

CORE Program Overview

WISP – Written Information Security

Policy and Framework Development

Vulnerability Management and Reporting

ManagedDetection & Response / SOC-as-a-

ServiceDNS Protection

Identity Management & Multifactor Authentication

Barracuda Total Email Protection

Dark Web Scanning

Page 24: Total Email Protection · Cloud Backup Email Continuity AI for Social Engineering Account Takeover Defense ... Forensics and Incident Response Gateway Defense Resilience Barracuda

Ask me about the FREE Email

Threat Scan and O365 Audit

Thank You!

Thomas Fazio

Director of Cybersecurity

[email protected]