cybersecurity: how to protect your businesssouthfloridafpa.org/wp...how-to...presentation.pdf ·...

30
Cybersecurity: How to Protect Your Business Presenter: Craig Watanabe, CSCP Sr. Compliance Consultant Core Compliance & Legal Services, Inc.

Upload: others

Post on 15-Aug-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Cybersecurity:HowtoProtectYourBusiness

Presenter:CraigWatanabe,CSCPSr.ComplianceConsultantCoreCompliance&LegalServices,Inc.

Page 2: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Agenda

q Understandhowtomeetregulatoryexpectationsq Learnhowtodevelopanactionablecybersecurity

planq Explorecyberprotectionsthatarepractical,

economicalandeffective

2

Page 3: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Materialsq Cybersecuritycannotbethoroughlycoveredin50

minutessoextensivematerialshavebeenprovidedastakeawaysv Detailedoutlinewithbestpracticesv CybersecurityReadinessAssessmentToolv UserAwarenessTrainingmemov ITVendorDueDiligenceChecklist

3

Page 4: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Cybersecurityisaregulatoryandbusiness riskthataffectsnearlyallfirms.Formanyfirmscybersecurityistheirnumberonerisk.

4

Page 5: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

UnderstandHowtoMeetRegulatoryExpectations

5

Page 6: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

ExpectationsareArticulatedinRegulatoryGuidance

q SECOCIENationalExamProgramRiskAlert– OCIECybersecurityInitiative(Apr.15,2014)

q SECOCIEExamPrioritiesfor2015(Jan.3,2015)q SECOCIENEPRiskAlert– CybersecurityExamination

SweepSummary(Feb.3,2015)q FINRAReportonCybersecurityPractices(Feb.2015)q SECOCIENEPRiskAlert– OCIE’s2015Cybersecurity

ExaminationInitiative(Sep.15,2015)6

Page 7: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

CaseStudyq IntheMatterofR.T.JonesCapitalEquities

Management,Inc.,SECRel.No.4204(Sep.22,2015)v SECstatesthatR.T.Jonesstoredsensitivepersonally

identifiableinformationofclientsonitswebserverwithoutadoptingwrittenpoliciesandproceduresregardingthesecurityandconfidentialityofthatinformationandtheprotectionofthatinformationfromanticipatedthreatsorunauthorizedaccess

v InJuly2013,thefirm’sserverwasattackedbyanunauthorized,unknownintruderwhogainedaccesstothedataontheserver

7

Page 8: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

CaseStudyq IntheMatterofR.T.Jones(cont’d)

v Asaresultoftheattack,personallyidentifiableinformationofmorethan100,000individualswasrenderedvulnerabletotheftØ CyberattackhadbeenlaunchedfrommultipleIP

addresses,allofwhichtracedbacktoChinaØ Couldnotdeterminethefullextentofthebreach

becausetheintruderdestroyedthelogfiles

8

Page 9: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

CaseStudyq IntheMatterofR.T.Jones(cont’d)

v RemediationeffortsØ ProvidednotificationofbreachtoindividualsØ Appointedaninformationsecuritymanagerto

overseedatasecurityØ AdoptedawritteninformationsecuritypolicyØ EncryptedtheinternalnetworkØ Retainedacybersecurityfirm

FINDINGS:C&D,Censure,CivilPenaltyof$75,000fine

9

Page 10: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

LearnHowToDevelopanActionableCybersecurityPlan

10

Page 11: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

TheFive-StepPlanningModel

1. Gatherinformationtoassessthecurrentsituation2. Defineandquantifyobjectives3. Performananalysis,consideralternatives,formulate

theplan4. Implementtheplan5. Periodicallyreviewandmakeadjustmentsas

necessary

11

Page 12: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

CybersecuritySteps1&2q TheCybersecurityReadinessAssessmentTool

v Thistoolisanalogoustoafinancialplanningdatagatheringchecklist

v 42questionsin6categories

q VulnerabilityAssessmentPerformedbyanIndependentInformationSecurityConsultantv Theassessmentwillidentifyvulnerabilitiesandsuggest

remediation(defineandquantifyobjectives)12

Page 13: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Step3ExploreCyberProtectionsthat

arePractical,EconomicalandEffective

13

Page 14: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

TheFortressModelofCybersecurity

q Fourcomponentsofthefortressmodelv Barriersv Entry/exitsv Locksv Keys

14

Page 15: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

TheLocks(Encryption)areVeryStrong

q Inmostendeavorstheoffensehastheadvantageoverthedefenseandthisisespeciallytrueincybersecurity

q However,oneareawherethedefensehastheadvantageisencryptionv Encryptionispractical,economicalandeffectivev ThecaseofApplevs.theFBIv EdwardSnowden

15

Page 16: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

DefenseinDepth

q Thisisamilitaryprinciplewhichprescribesmultiplelayersofdefense

q Incybersecurityyoudeploymultiplelayersofencryptionv Firewallv Diskorfileencryption

16

Page 17: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

TheKeys(Passwords)aretheWeakestLink

q Althoughencryptionisstrongitcanbedefeatedbystealingthekeys(thepassword)

q Threecontrolstostrengthencontrolstopreventunauthorizedaccessv Strongpasswordpolicyv Utilizepasswordmanagersv Employtwo-factorauthentication

17

Page 18: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

StrongPasswordPolicyq Any8characterpasswordcanbecrackedin15

minutesusingreadilyavailablehackertoolsq A10characterpasswordwouldtakeseveralweeksto

crackq Thekeytopasswordstrengthislengthq Teachthetechniqueofpasswordpaddingtocreate

longpasswordsthatareeasytorememberandeasytotype

18

Page 19: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

UsePasswordManagersq Passwordmanagersallowuserstosetdifferent

passwordsforeachsiteandtheuserneedonlyrememberthemasterpassword

q Passwordmanagersaddconvenienceq Lastpass andRoboform areexamplesofcommon

passwordmanagers

19

Page 20: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Two-FactorAuthentication(2FA)q A2FAprotocolrequiresasecondformof

authenticationinadditiontothepasswordsuchasabiometric,answertoachallengequestionorenteringasecuritytoken

q Thisisakintorequiringeachlocktobeopenedwithtwokeys

q 2FAispractical,economicalandeffective

20

Page 21: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

UserAwarenessTraining

21

Page 22: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

TheHumanElementofCybersecurity

q Accordingtothe2015VerizonDataBreachInvestigationsReport,abouttwo-thirdsofallbreachesentailedacompromiseduser

q Userawarenesstrainingisacriticalcomponentofcybersecurity

q Trainingismosteffectivewhendeliveredinthecontextofhomecomputersandpersonaldevices

22

Page 23: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

UserAwarenessTraining

q Theprinciplesofeffectivetrainingapplytoteachingcyberhygienev Trainingmustberelevantandengagingv Principlesshouldbereinforcedcontinuallywellafter

thetrainingiscompletedv Livetrainingisthemosteffectivefollowedbywebinar

andself-study

23

Page 24: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

WeakControls

24

Page 25: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

IntrusionDetectionMonitoring

q Accordingtoa2015studydonebyTrustwave onover600breaches,over80%wereneverdiscoveredbythevictim

q Thevictimwasoftencontactedbythehackerornotifiedbylawenforcement

q Skilledhackersareveryadeptatavoidingdetectionwitheventhebestsystemsavailable

25

Page 26: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

VendorDueDiligence

q Asignificantpercentageofbreachesoriginatefromathird-partyvendor

q Vendorduediligenceisrecommendedbutnotveryeffective

q Dealingwithvendorsthatarelargeandwell-respectedreducesthedownsideversusasmallvendor

26

Page 27: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

PenetrationTests

q Forsmallfirmsavulnerabilityassessmentismorevaluablethanapenetrationtest

q Vulnerabilityassessmentsaremorecomprehensiveandmorecostlythanpenetrationtests

27

Page 28: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Step4- Don’tProcrastinate!

q Asinfinancialplanning,procrastinationisoneofthebiggestreasonsforfailureincybersecurity

q Developandimplementyourcybersecurityplan!

28

Page 29: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Step5- PeriodicallyReview

q Likefinancialplanning,cybersecurityisnotaone-timeevent,itisanongoingprocess

q Itisabestpracticetoperformannualvulnerabilityassessments

29

Page 30: Cybersecurity: How to Protect Your Businesssouthfloridafpa.org/wp...How-to...Presentation.pdf · Expectations are Articulated in Regulatory Guidance qSEC OCIE National Exam Program

Questions?

30

Craig Watanabe, CFP® AIF® CSCPSr. Compliance [email protected]

Core Compliance & Legal Services, Inc.1350 Columbia Street, Suite 300San Diego, CA 92101Tel: (619) 278-0020www.corecls.com