The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide...

24
The CEO’s plain English guide to

Transcript of The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide...

Page 1: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

The CEO’s plain English guide to

Page 2: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Learn: WHAT is the risk? WHY does it exist? HOW can we efficiently & effectively respond?

Protect: act now & encourage every business to do the same

Buy Maryland Cyber! Maryland’s outstanding industry can protect us

www.buymdcyber.com

Page 3: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Cyber = Digital Cybersecurity is digital security That’s it!

www.buymdcyber.com

Page 4: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

3 Factors

Page 5: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Cybersecurity RISK = Valuable Digital Assets + Weaknesses + Formidable Threats

www.buymdcyber.com

Page 6: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Risk Factor #1

Page 7: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Stolen sensitive data (employee, customers, operational, financial) & intellectual property

Interrupted operation of systems controlled by computers

Potential damages from compromised assets Earnings loss from lost customers & delayed sales Reputation loss Legal costs

www.buymdcyber.com

Page 8: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Risk Factor #2

Page 9: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Business Equipment 82% website, 87% desktop, 84% laptop, 74% smartphone (NSBA)

Online activity 87% purchasing, 83% banking, 72% pay bills, 59% phone/skype

www.buymdcyber.com

Page 10: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Proliferation of software Vulnerability Types (SANS) Insecure interaction

between components

Risky resource management

Porous defenses

www.buymdcyber.com

… full of holes 2,289 enterprise software products from 539 vendors in 2013 review (Secunia) Vulnerabilities Detected 2,130 highly critical 13,073 total

Page 11: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

US computer & electronic manufacturing exported to Asia to lower costs

Complex networks with many components Diffused, large & complex manufacturing supply

chains Every component carries potential for security risk

www.buymdcyber.com

Page 12: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Lack of situational

awareness Limited knowledge of

what to do/not do Low compliance in

online/offline behavior

www.buymdcyber.com

Page 13: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Risk Factor #3

Page 14: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Criminals, terrorists, hacktivists Readily available tools

Increasingly adept

Strong economic & political incentives

Cost advantage

Darknets

www.buymdcyber.com

Page 15: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

www.buymdcyber.com

Page 16: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Hacking Malware Social Physical

Ranked in order of # 2013 incidents

www.buymdcyber.com

Page 17: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

78% “low” & “very low” difficulty tactics & <1% “high” difficulty 92% of all incidents fit 9 patterns 75% of attacks are opportunistic 76% exploited lost/stolen credentials

Verizon 2013 & 2014 Breach Reports

www.buymdcyber.com

Page 18: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Assets + Weaknesses + Threats We’ve inadvertently enabled a 24/7 relentless global

assault on our valuable assets $500B+/year in financial damages

Funds Intellectual property

Attack frequency, variety & sophistication are increasing. We are losing ground.

www.buymdcyber.com

Page 19: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Here’s what you should do

Page 20: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Internet Users Perception of Security (Pew Institute) 23% “very secure” 46% “somewhat secure” 69% don’t get it 31% “not too secure” or “not at all secure.”

www.buymdcyber.com

Page 21: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

MY business is not a target

The bad guys are too effective to stop

Others will solve it

No idea what to do

No affordable solution This is your company’s problem!

www.buymdcyber.com

Page 22: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Cyberpoint’s CyberVaR value-at-risk calculator Make informed decisions: Evaluating security investments Creating mitigation strategies Purchasing cyber security insurance

www.buymdcyber.com

Page 23: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Identify

Protect (Prevent)

Detect

Respond

Recover NIST cyber framework

www.buymdcyber.com

Page 24: The CEO’s plain English guide to - NMTC · PDF fileThe CEO’s plain English guide to ... Internet Users Perception of Security ... share this presentation & introduce cyber companies

Protect: create & execute a Plan that fits your risk profile

Buy: Maryland Cyber. Create 10,000+ jobs

www.buymdcyber.com

Help Maryland: share this presentation & introduce cyber companies to businesses

www.buymdcyber.com