Top Security Threats to Your Organization€¦ · top security threats to your organization andrew...

35
TOP SECURITY THREATS TO YOUR ORGANIZATION ANDREW YSASI, MS, FIP, FIIM, CIPM, CIPP, CISM, PMP, CRM, IGP, CIP VICE PRESIDENT, ADVOCACY ARMA Florida Sunshine Conference February 21, 2020 Copyrighted Andrew Ysasi. All Rights Reserved. 2020.

Transcript of Top Security Threats to Your Organization€¦ · top security threats to your organization andrew...

Page 1: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

TOP SECURITY THREATS TO YOUR ORGANIZATION

ANDREW YSASI, MS, FIP, FIIM, CIPM, CIPP, CISM, PMP, CRM, IGP, CIP

VICE PRESIDENT, ADVOCACY

ARMA Florida Sunshine ConferenceFebruary 21, 2020

Copyrighted Andrew Ysasi. All Rights Reserved. 2020.

Page 2: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

DISCLAIMER

No endorsements are made by me and especially Vital Records Control (VRC). Logos and information can be found online at the respective source organization’s website. Information may have changed by the time it was researched. Andrew is not an attorney and does not provide legal advice.

Andrew is a past member of the Board of Directors of i-SIGMA (PRISM/NAID) the ICRM.

Page 3: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

ABOUT ANDREW…• Advocacy = MELV (Mentoring, Educating, Lobbying, Volunteering)

• ICRM Parts 1-6 Mentor

• Writer for ARMA’s Information Governance Body of Knowledge (IGBOK) and Information Governance: Concepts, Strategies and Best Practices - Wiley

• Former Adjunct Instructor at Davenport University

• Global Project Management and Technology Capstone

• ICRM Exam Development Committee – 2012-2017

• i-SIGMA (PRISM/NAID) International Board Member – 2016-2019

• Inside the Record Room guest personality

• Founder IG GURU: Information Governance News

• Masters in Administration from Central Michigan University

Page 4: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

(ILA) I LOVE ACRONYMS!

FIP – Fellow of Information Privacy (IAPP)

FIIM – Fellow Institute of Information Management (IIM-Africa)

CIPM – Certified Information Privacy Manager (IAPP)

CIPP – Certified Information Privacy Professional (IAPP)

CISM – Certified Information Security Manager (ISACA)

PMP – Project Management Professional (PMI)

CRM – Certified Records Manager (ICRM)

IGP – Information Governance Professional (ARMA)

CIP – Certified Information Professional (AIIM)

Security+, CDIA+, Project+, A+, MCTS, MCSA, ITIL

Page 5: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Criminal Hackers

Page 6: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Ransomware

Page 7: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

IOT and Hardware

Page 8: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Phishing

Page 9: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

RogueGovernmentCyberAttacks

Page 10: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Software Updates –Supply Chain Attacks

Page 11: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Vendors

Page 12: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Cloud Technology

Page 13: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Employees

Page 14: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Social Engineering

Page 15: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Drones

Page 16: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Unknown TechnologyAssets

Page 17: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Old RiskProfile

Page 18: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Data Leaks

Page 19: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Where do we go?

Page 20: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Skills

Page 21: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Training andAccountability

Page 22: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

DigitalEcosystem

Page 23: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

UpdateControls &Audit

Page 24: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy
Page 25: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

Courtesy of Chris Roberts via LinkedIn.com

Page 26: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

“No one entity can really tackle this issue alone (cyber threats)” –Special Agent M.K. Palmore - FBI

Page 27: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

ARMA IGBOK

• Covers variety of topics:• RIM & IG

• Privacy

• Academic Research

• Technology/E-Discovery

• Information Governance

Page 28: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

IG GURU

• Educational Resource for Information Governance Professionals

• www.igguru.net

• Free to sign up!

Page 29: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

IG WORLD MAGAZINE

• Covers major facets of IG, uniting them under the umbrella of a common vision

• https://infogovworld.com/

Page 30: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

FOR YOUR RIM/IG LIBRARY

Page 31: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

FOR YOUR OTHER LIBRARY

Page 32: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

COMPANY OVERVIEW

Vital Records Control was founded in Memphis, Tennessee in 1988. Since then, we’ve grown to become a national leader in information management with more than 60 locations nationwide.

Page 33: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

INFORMATION MANAGEMENT

DOCUMENT STORAGE

DOCUMENT DESTRUCTION

IMAGING & HOSTING

RELEASE OF INFORMATION

Page 34: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

GRACIAS!

E-mail: [email protected]

Twitter:

@andrewysasi @vitalrecordctrl@admovio @1gguru

LinkedIn: www.linkedin.com/in/andrewysasi/

Twitter: www.twitter.com/andrewysasi

Page 35: Top Security Threats to Your Organization€¦ · top security threats to your organization andrew ysasi, ms, fip, fiim, cipm, cipp, cism, pmp, crm, igp, cip vice president, advocacy

SOURCES

• 7 mobile security threats you should take seriously in 2019 - https://www.csoonline.com/article/3241727/7-mobile-security-threats-you-should-take-seriously-in-2019.html

• 9 biggest information security threats through 2018 - http://www.cio.com/article/3046760/security/9-biggest-information-security-threats-through-2018.html -Retrieved 08/08/2017

• Top 10 Security Predictions Through 2020 - https://www.forbes.com/sites/gartnergroup/2016/08/18/top-10-security-predictions-through-2020/#3f9235ba5b39 –Retrieved 08/08/2017

• Gartner 7 Top Security Predictions for 2019 - https://www.information-age.com/gartner-security-and-risk-management-trends-123480056/

• 5 Trends in Cyber Security for 2017 and 2018 - http://www.gartner.com/smarterwithgartner/5-trends-in-cybersecurity-for-2017-and-2018/

• SANS Institute Survey Finds ICS Security Risks Continue to Rise and Evolve - https://www.sans.org/press/announcement/2017/07/05/1 - Retrieved 08/08/2018

• RSA 2019: SANS shares top new security threats – and what to do about them - https://www.healthcareitnews.com/news/rsa-2019-sans-shares-top-new-security-threats-%E2%80%93-and-what-do-about-them

• DNS Photo - https://www.znetlive.com/blog/wp-content/uploads/2016/04/domains-imaes.png