In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

22
In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7

Transcript of In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

Page 1: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

In the age of Continuous

Compromise

EXECUTIVE REPORTING

Trey FordGlobal Security Strategist

Rapid7

Page 2: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

AGENDA

•Boardroom Disciplines

•The Security Executive’s Challenges

•What’s Reported – 90 CISOs Point of View

•Affecting Change – Rapid7 Research Project

Page 3: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

BOARDROOM DISCIPLINES

Page 4: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

ESTABLISHED PROFESSIONS

• Medicine

• Law

• Engineering

• Accounting

Page 5: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

BOARDROOM TECHNOLOGYNCR - 1884 IBM - 1911

Page 6: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

SECURITY EXECUTIVE’S CHALLENGES

Page 7: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

INFORMATION SECURITY

NO REAL ‘HOW TO’ GUIDE

Page 8: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

SECURITY STATUS REPORTS

•Accounting has their GAAP

•Legal and Medicine has theirs

•What about Information Security?

Page 9: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

COMMUNICATION FLOW

Data, Verbose Reports

SUMMARIES

WISDOM

KNOWLEDGE

INFORMATION

DATA

Page 10: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

• Uncertainty at the Top

• Executives are Comfortable

• Engineers are NOT Comfortable

• The Secret

• Helping inform a point of view

• The idea may not be right or wrong

CURSE OF KNOWLEDGE

Summaries

Page 11: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

DELIVERING BADNESS

Vulnerability &

External Audit Reports

BURY THEM!?!

Page 12: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

INCIDENTS HAPPEN

Unsafe to Discuss?

Acknowledge bias:Prevention vs. Response

Page 13: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

ACTIVATING INCIDENT RESPONSE

AdmittingFailure?

Insurance Policy?

Page 14: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

Helping your CISO in the Boardroom

All CISOs have to address 3 questions (with EVERYTHING they say)

•What do I need to know?

•Why does this matter / Why do I care?

•What do you need from me?

Simple… and Hard.

Page 15: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

WHAT’S REPORTED

Page 16: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

WHAT’S REPORTED - TENURE

•20% have been in the CISO role less than 12 months

•New focus by Board in Security

•Last CISO was “too much business, not enough security”

•1/5 CISOs are looking for guidance or program validation

Page 17: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

WHAT’S REPORTED – AREA OF FOCUS

•15% report on specific security project status

•20% are concerned about Compliance Audits

•25% are focused on Incident Response

•49% are reporting on Vulnerability Management

Page 18: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

WHAT’S REPORTED – TANGIBLE

•6% report on Volume of Spam Blocked

•12% report no real metrics to their Board

•Also heard “lost laptops”, “stolen iPads”, “blocked websites”

•Many CISOs grasp for topics to catch their boards attention

Page 19: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

AFFECTING CHANGE

Page 20: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

Affecting Change – Rapid7 Research

•A Quantitative and Qualitative SURVEY

•>100 CISOs & non-Security Executives

•What gets reported? (Routine vs. Special Updates)

•Mapping against common Cybersecurity Frameworks

Agreeing on Simple…HARD TO DO!

Page 21: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.
Page 22: In the age of Continuous Compromise EXECUTIVE REPORTING Trey Ford Global Security Strategist Rapid7.

QUESTIONS?

Let’s talk!@treyford -or-

[email protected]