Understanding and Tackling 'Next-tier Cyber Threats

12
www.cloudsec.com | #CLOUDSEC Understanding and tackling “next-tier” cyber threats Charles Mok Legislative Councillor (Information Technology) @charlesmok

Transcript of Understanding and Tackling 'Next-tier Cyber Threats

Page 1: Understanding and Tackling 'Next-tier Cyber Threats

www.cloudsec.com | #CLOUDSEC

Understanding and tackling “next-tier” cyber threats Charles Mok

Legislative Councillor (Information Technology)

@charlesmok

Page 2: Understanding and Tackling 'Next-tier Cyber Threats

What happened in 2017? Ransomware: Top threat

2

Page 3: Understanding and Tackling 'Next-tier Cyber Threats

IoT vulnerabilities

Email phishing

Social engineering

IoT for DDoS attack

Common types of attacks

Page 4: Understanding and Tackling 'Next-tier Cyber Threats

More vulnerabilities exposed: and not just on PCs

Spyware, malware keeps appearing in app stores

Stealing credentials

Page 5: Understanding and Tackling 'Next-tier Cyber Threats

Targeted

Stealthy

Personalized

Zero-day

The New Threat Landscape

Page 6: Understanding and Tackling 'Next-tier Cyber Threats

#CLOUDSEC

TARGETED

• Critical infrastructure: electric power systems, transport infrastructure, supply chain

• High risk industries: healthcare providers, finance • Others: government, higher education, retail,

travel/hospitality, technology, entertainment

Page 7: Understanding and Tackling 'Next-tier Cyber Threats

Newer attack methods emerging Ransom denial-of-service (RDoS) Destruction of service (DeOS) destroying organisations data and back-up Automation: reused malware + automation by bots to attack new exploits and flaws Sophisticated phishing

Page 8: Understanding and Tackling 'Next-tier Cyber Threats

#CLOUDSEC

Hackers for hire: Attacks-as-a-service • DDoS-as-a-service

• ransomware-as-a-

service

• Fraud-as-a-service

Page 9: Understanding and Tackling 'Next-tier Cyber Threats

hacker ecosystem: spreading tools in the dark web even paid subscription

Page 10: Understanding and Tackling 'Next-tier Cyber Threats

How to tackle new cybercrime scenarios?

10

Page 11: Understanding and Tackling 'Next-tier Cyber Threats

Strengthening defence against newer threats require holistic approach

Training of in-house

personnel

Proactive prevention

and detection

Regularly patch and

update systems

cyber resilience plan for recovery

Trend: Promote cooperation between public and private sector with legislation to protect digital assets

Page 12: Understanding and Tackling 'Next-tier Cyber Threats

www.cloudsec.com | #CLOUDSEC

THANK YOU

Charles Mok

Legislative Councillor (Information Technology)

@charlesmok