jfsc and sasig directors’ · integrating cybersecurity into the employment lifecycle martin smith...

87
JFSC and SASIG Directors’ Cyber Security Masterclass

Upload: ngotuyen

Post on 25-Apr-2018

223 views

Category:

Documents


5 download

TRANSCRIPT

Page 1: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

JFSC and SASIG Directors’Cyber Security Masterclass

Page 2: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Introduction Martin Smith, Chairman & FounderThe SASIG

Page 3: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Where did it come from?

What do we do?

How do we do it?

Where are we going?

Page 4: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Our SASIG Supporters

Page 5: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

SASIG themes…

2015 – communication

2016 – leadership

2017 - collaboration

Page 6: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Financial Services Sector Nuclear Sector

Legal Services Sector Retail Sector

Manufacturing Sector Regulators’ SASIG

Managing security in the supply chain The Internet of Things

Recovering from a major cyber attack Directors’ Masterclasses

Metrics & measurement of security Cyber economics

Cyber insurance Countdown to GDPR

Strengthening the security of health & care information

SASIG Annual Gala Dinner & Networking Gala Luncheon

SASIG workstreams in 2017

Page 7: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Eugene Kaspersky, CEOKaspersky Lab

Page 8: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 9: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 10: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 11: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 12: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 13: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 14: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 15: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 16: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 17: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 18: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 19: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 20: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 21: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 22: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 23: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 24: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 25: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

• Expert Training

• Awareness Program

• Kaspersky Lab Enterprise

Security Solutions

AND FIGHT

AS YOU TRAIN

TRAIN AS

YOU FIGHT

PREVENT

DETECT

• Targeted Attack Discovery

• Kaspersky Managed

Protection

• Kaspersky Anti Targeted

Attack Platform

RESPOND

• Incident Response

ServicesCLOTHE THEE

IN WAR

ARM THEE IN

PEACE

PREDICT

• Security Assessment

• APT Intelligence Reports

• Tailored Threat Intelligence

KNOW

THYSELF

KNOW

THINE ENEMY

SI VI PACEM

PARA BELUM

• Kaspersky Managed Protection

Page 26: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 27: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 28: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation
Page 29: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Denis Philippe Head of ICT, JFSC

Page 30: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Cyber Security: What Executives Need to Know

Page 31: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› What happens to the JFSC

› Cyber and the Boardroom

› Key cyber risks

› Strategy

› Training

› Certification

› Scope and scale

› Review

› Agenda

Page 32: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

“Commission held information1, in all its forms, written, recorded electronically or printed, will be protected from accidental or intentional unauthorized access, modification, or destruction throughout its life cycle”

1 This includes all information created or owned by the Commission as well as information collected by or provided to the Commission by external parties for the execution of the Commission’s activities

› Cyber-Security Mission Statement

Page 33: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Subjected to approximately 3,800 network security attack attempts DAILY

› Process over 5,000 emails per day with up to 34% of inbound traffic being rejected due to identified threats

› Website screening prevents access to high risk content (< 0.1% traffic)

› What happens to the JFSC

Page 34: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Cyber and the Boardroom

32% of Boards do not receive information security updates

45% of Boards do not believe it is important

Page 35: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Fire Metaphor

FIRE

Opportunistic Threat

Indiscriminate

Exploits vulnerability

Owns everything

Page 36: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› What is important to your business?

› Open or outstanding High Risks

› Incident summary and impact

› Incidents affecting competitors/peers

› Steps to prevent reoccurrence of previous incidents

› What information should you get?

Page 37: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Key Cyber Risks

Page 38: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Definitions of what we protect:

› Private & personal information ›Legal definition versus what people actually value

› What?

GapExtended

Reputational Risk

Page 39: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› People

› Vigilant

› More complex

› Vulnerable

50% of people take some form of confidential information with them when they leave an organisation

Page 40: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Complex interconnected systems

› Up-to-date patching

› Effective change control

› Understand where your data is and how it is being used

› Malware / Zero day protecting/detection

› Ensure good, well tested backups

› Offline backup’s (Ransomware)

› Systems

Page 41: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Why?

› Mitigate Risk – “Data is a commodity of interest to many”

› Extensive investment in providing an interconnected and online mode of stakeholder engagement is being balanced with a significant effort and investment in our security to protect the systems and data we are collecting and holding

Page 42: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Trust, but verify

› Vetting requirements

› Consider contractors etc.

› Don’t forget the cleaners…

› Suppliers

Page 43: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Strategy

Page 44: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Do you have a cyber strategy

› Who owns your cyber strategy?

› Is it aligned with the business strategy?

› Is it realistic?

› Is it being monitored?

Page 45: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Governance

Page 46: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› What if something happens?

› Not all about Detect and Protect

› Ensure that tested incident response plans are in place

› Ensure that people are aware of their responsibilities

› Cyber insurance

› Plan for external support

› Communications plan – Media, Law Enforcement, Regulator

Page 47: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Training & Awareness

Page 48: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Training

› Who is being trained?› User› Board members› Suppliers› Contractors

› How are you training?

› Training lifespan!

› Awareness

› Testing2 Weeks Length of time people

retain information after training!

Page 49: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Awareness

› Vigilance›Phishing / Whaling

›Social engineering

› Sub conscious›Small bite sized chunks of information to supplement training

›Posters

›Screen savers

› Balanced message›Don’t overload people to the point they stop listening

Page 50: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Community

› Building walls is not enough

› Flexibility and collaboration are key

› Improved intelligence will improve detection

› Understand the landscape threats

Page 51: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Certification

Page 52: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Cyber Essentials

› ISO

› NIST

› Blended?

› Organisation

5 Pillars based on a blend of NIST and ISO27001

Identify Protect Detect Respond Recover

This blend of NIST and ISO allows us to speak to other regulators and registries in security terms they understand

Page 53: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Staff training and certification

› Certified Information Systems Security Professional (CISSP)

› Certified Information Security Manager (CISM)

› ISO 27001 Lead auditor

› BCS Certificate in Information Security Management Principles

› Staff

Page 54: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Ensuring suppliers are certified ISO/NIST (or aligned)

› Seek the right to audit as part of contracts

› Add security questions to tender documents

› Vetting of staff and own suppliers

› Suppliers

Page 55: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Scope and scale

Page 56: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Set reasonable objective

› Focus on what is important to you and your customers

› Focus on doing things well

› Cyber hygiene basics

› Don’t boil the ocean

Page 57: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› What about you?

Page 58: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Become part of the solution and show you understand

› Soft targets = weak link in the chain. Bigger prizes at the top

› Cultural evolution through training and secure behaviours

› Lead from the front

People Skills KnowledgeHumanware

2.0

Page 59: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› 40% of daily actions are driven without thinking:› Changing gear› Tying shoe laces› Locking the front door

› Bad habits include:› Writing down passwords› Leaving computers/devices unlocked› Clicking on emails and links without knowing what they are or where they go

› “Evidence has shown that a large number of cyber hygiene issues have become bad habits.” Bikash Barai

› Habits

Page 60: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› IP theft or sabotage for their own benefit or that of others

› Have a training and awareness plan

› Malicious Users

of those who steal data do so in their last month of work

of those who steal data do so two months before leaving

50%

70%

Ref: Dawn Cappelli

Page 61: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Review

Page 62: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Things to spend time on

Ensure you are receiving updates

Support your security team and get trained

Support your strategy

Page 63: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

› Useful links

› https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/385009/bis-14-1277-cyber-security-balancing-risk-and-reward-with-confidence-guidance-for-non-executive-directors.pdf

› https://www.nccgroup.trust/globalassets/resources/uk/ebooks/ebook_cyber-risk-security-guidance-for-non-exec-directorspdf/

Page 64: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Follow us at @JerseyFSC

Like us at Jersey Financial Services Commission

Follow us at Jersey Financial Services Commission Head of ICT Denis Philippe

[email protected]

Page 65: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Martin Smith, Chairman & FounderTHE SASIG

Page 66: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

The Human FactorIntegrating cybersecurity into the employment lifecycle

Martin Smith MBE FSyI

Chairman and Founder

The Security Company (International) Ltd

The Security Awareness Special Interest Group

Page 67: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Who am I?

Page 68: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Some of our clients…

Page 69: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

We need to work the problem

Our secure systems are built to perfection but are being

subjected to massive external attack.

Cybercrime is rapidly increasing, data breaches are

reported in the Press on a daily basis, and IP is at grave risk.

Privacy is considered as “something of the past”.

National infrastructures are under direct threat of attack

from other nation states.

Page 70: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Examine the evidence

The vast majority of breaches and security events occur at the most basic levels of our

defences.

Most attacks succeed by subverting physical security, by exploiting sloppy housekeeping

and errors in systems operations and patching, and by directly targeting people.

Social media makes social engineering easy.

BYOD is emasculating our technical defences.

Human error and ignorance amongst our workforces present an enormous gap in our

fortification.

Our supply chains are massive.

Page 71: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Old crimes, new tricks…?

Page 72: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

We all believe what we are told

Page 73: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Security should influence every stage of

your employment lifecycle

1. Recruitment and the interview process

2. Pre-employment screening, vetting, contracts of employment

3. On-boarding, induction, socialisation, probationary periods

4. Performance management, supervision and staff appraisals

5. Internal movement, promotion and career development

6. Security awareness, training and incentives (the “carrot”)

7. Disciplinary policies and procedures (the “stick”)

8. Termination of employment, exit strategies

9. The integrity of suppliers, contractors and other third parties

Page 74: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Actually, people want to help…

There is an enormous willingness amongst any supply chain to follow good

cyber security practice.

The vast majority of any workforce, including those of our suppliers, is

intelligent, honest, hardworking and sensible.

To win our suppliers’ support, we just need to tell them what it is we want

them to do and why, in language they can understand.

We must explain the benefits of good cyber security management - “What’s

in it for me?”

Page 75: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

The impact we fear the most

Page 76: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

How big is your security and fraud prevention team?

Page 77: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

The elephant in the room…

The “Mark 1 Human Being” remains the greatest and continuing weakness in the entire security regime, but at the same time can be our greatest supporter.

Often it is the breach of trust that we must fear, not the breach of security.

Page 78: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

“Problems are never solved at the same level of awareness that created them…”

Albert Einstein

Page 79: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Questions?

Contact me:

[email protected]

@MartinSmith_TSC

+44 (0) 1234 708456

www.thesecurityco.com

www.thesasig.com

Page 80: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Panel and Q&A SessionFacilitated by Martin Smith, Chairman, The SASIG› Eugene Kaspersky, CEO, Kaspersky Lab› Ian Bishop-Laggett, Internal Security Controls Manager, Schroders › Denis Philippe, Head of ICT, JFSC

Page 81: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Final AddressJohn Harris, Director GeneralJersey Financial Services Commission

Page 82: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

In summary› Directors to ensure that cyber is a priority throughout their

organisations› JFSC is building Island-wide awareness of regulatory

responsibility for cyber security › Cyber security needs to be a collective responsibility and

success for the Island

Page 83: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Jersey is committed to cyber security (dedicated government strategy)

Cyber no longer just about technology -PEOPLE

Core business issues

Leave today with heightened awareness

Page 84: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

The current regulatory approach

› Not a traditional “us and them” relationship – all in this together

› Questionnaire based on ISO and NIST standards – what vulnerabilities and responses?

› Meant to be used as a self-assessment tool. Thought provoking

› No right answers – but seeking proportionality

Page 85: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

The current regulatory approach

› Sample approach – mandatory for those requested / but available to all regulated firms

› Issued end of March› Aggregate report will be compiled

and published – using anonymisedinformation

› Will inform next steps

Page 86: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Closing RemarksMartin Smith, Chairman & FounderThe SASIG

Page 87: JFSC and SASIG Directors’ · Integrating cybersecurity into the employment lifecycle Martin Smith ... Pre-employment screening, vetting, ... Cyber Security Masterclass Presentation

Thank you