When Security Meets Innovation: a Cross-Team Love Story

62
CRAIG DAVIES HEAD OF SECURITY ATLASSIAN @CRDAVIES SecOps, a Love Story How Atlassian’s Security Team works together ANDREW WURSTER T/L ATLASSIAN @YOURCISCOKID

Transcript of When Security Meets Innovation: a Cross-Team Love Story

Page 1: When Security Meets Innovation: a Cross-Team Love Story

CRAIG DAVIES HEAD OF SECURITY •

ATLASSIAN @CRDAVIES

SecOps, a Love StoryHow Atlassian’s Security Team works together

ANDREW WURSTER T/L • ATLASSIAN @YOURCISCOKID

Page 2: When Security Meets Innovation: a Cross-Team Love Story

It’s a big bad world out there

Page 3: When Security Meets Innovation: a Cross-Team Love Story

Build trust with every team.

Page 4: When Security Meets Innovation: a Cross-Team Love Story

Remove Barriers

Page 5: When Security Meets Innovation: a Cross-Team Love Story

Be Transparent

Page 6: When Security Meets Innovation: a Cross-Team Love Story

Be Consistent

Page 7: When Security Meets Innovation: a Cross-Team Love Story

Meet the Security Team

Page 8: When Security Meets Innovation: a Cross-Team Love Story
Page 9: When Security Meets Innovation: a Cross-Team Love Story

We handle (allthethings) security

Trust@Atlassian

Detect and respond Secure by Design

Scale

Page 10: When Security Meets Innovation: a Cross-Team Love Story

ATX SYDMTV

Page 11: When Security Meets Innovation: a Cross-Team Love Story

Security Engineering Security Intelligence

Page 12: When Security Meets Innovation: a Cross-Team Love Story

Information is key to Cyber Security Test, Test, Test:

Plan for the worst:

Data must be useful:Don’t look at everything, look at what matters

We work through scenarios, what could happen?

We test everything, from threats to our incident plans.

Page 13: When Security Meets Innovation: a Cross-Team Love Story

Everything is Connected

Intel Hub

Page 14: When Security Meets Innovation: a Cross-Team Love Story

A Day in the Life

Page 15: When Security Meets Innovation: a Cross-Team Love Story

Active Bitbucket users

increase wk / wk

25%

Page 16: When Security Meets Innovation: a Cross-Team Love Story
Page 17: When Security Meets Innovation: a Cross-Team Love Story

Incident Investigation

False Positive OR

Low Priority

Not so fast… create a JIRA

True Positive AND

High Priority

New Incident

BAU Task

Page 18: When Security Meets Innovation: a Cross-Team Love Story

The Playbook

Page 19: When Security Meets Innovation: a Cross-Team Love Story

Logging PipelineOther IncidentsEmail Ingestion JIRA Service Desk

New Security Incident

Industry Groups

Page 20: When Security Meets Innovation: a Cross-Team Love Story

• Big cool statistic

• 2,569

• Add-Ons in Marketplace

Phase 1: Detect and Analyze

Page 21: When Security Meets Innovation: a Cross-Team Love Story
Page 22: When Security Meets Innovation: a Cross-Team Love Story
Page 23: When Security Meets Innovation: a Cross-Team Love Story

Security Playbook

Page 24: When Security Meets Innovation: a Cross-Team Love Story
Page 25: When Security Meets Innovation: a Cross-Team Love Story
Page 27: When Security Meets Innovation: a Cross-Team Love Story

Active Bitbucket users

increase wk / wk

25%

Page 28: When Security Meets Innovation: a Cross-Team Love Story

Create tasks in JIRA,

track bigger stuff in Confluence

Page 29: When Security Meets Innovation: a Cross-Team Love Story

• Big cool statistic

• 2,569

• Add-Ons in Marketplace

Establish Comms

Page 30: When Security Meets Innovation: a Cross-Team Love Story

Phase 2:Contain, Eradicate, Recover

Page 31: When Security Meets Innovation: a Cross-Team Love Story

• Big cool statistic

• 2,569

• Add-Ons in Marketplace

Allocate work

Page 32: When Security Meets Innovation: a Cross-Team Love Story

all users

IT Team

Understanding the problem: Investigation workflow

Page 33: When Security Meets Innovation: a Cross-Team Love Story

Active?2FA Enabled?

Successful?

IT Team

all users

Page 34: When Security Meets Innovation: a Cross-Team Love Story

Active?2FA Enabled?

Successful?

>1m failed

IT Team

all users

Page 35: When Security Meets Innovation: a Cross-Team Love Story

Active?2FA Enabled?

Successful?

successful

>1m

~100k

failed

IT Team

all users

Page 36: When Security Meets Innovation: a Cross-Team Love Story

Active?2FA Enabled?

Successful?

successful

>1m

~100k

failed

IT Team

~= 90k active users

all users

Page 37: When Security Meets Innovation: a Cross-Team Love Story

Span and Control: how can we contain it?

Page 38: When Security Meets Innovation: a Cross-Team Love Story

bad actors

Page 39: When Security Meets Innovation: a Cross-Team Love Story

3rd party breach data

Page 40: When Security Meets Innovation: a Cross-Team Love Story

3rd party breach data

hunter2

[email protected]

Page 41: When Security Meets Innovation: a Cross-Team Love Story
Page 42: When Security Meets Innovation: a Cross-Team Love Story
Page 43: When Security Meets Innovation: a Cross-Team Love Story

legit requests

Page 44: When Security Meets Innovation: a Cross-Team Love Story

bad requests

Page 45: When Security Meets Innovation: a Cross-Team Love Story

Apply Filter

Page 46: When Security Meets Innovation: a Cross-Team Love Story

Contain and Eradicate

Page 47: When Security Meets Innovation: a Cross-Team Love Story

By the books: Block a Malicious IP

Play / Policy: How to block …

Page 48: When Security Meets Innovation: a Cross-Team Love Story

Config Repo

git PR

By the books: Block a Malicious IP

Policy

Page 49: When Security Meets Innovation: a Cross-Team Love Story

By the books: Block a Malicious IP

Config Repo Live Config

deploy

Page 50: When Security Meets Innovation: a Cross-Team Love Story

• Big cool statistic

• 2,569

• Add-Ons in Marketplace

Allocate work

Recovery

Page 51: When Security Meets Innovation: a Cross-Team Love Story
Page 52: When Security Meets Innovation: a Cross-Team Love Story

Phase 3: Review

Page 53: When Security Meets Innovation: a Cross-Team Love Story

The Incident is over You’ve survived

Time for PIR

Page 54: When Security Meets Innovation: a Cross-Team Love Story

Post Incident Review

Page 55: When Security Meets Innovation: a Cross-Team Love Story

Helping you

Page 56: When Security Meets Innovation: a Cross-Team Love Story

Trust.atlassian.com

Page 57: When Security Meets Innovation: a Cross-Team Love Story
Page 58: When Security Meets Innovation: a Cross-Team Love Story
Page 59: When Security Meets Innovation: a Cross-Team Love Story

megabytes

terabytes

Page 60: When Security Meets Innovation: a Cross-Team Love Story

0.0001%

Page 61: When Security Meets Innovation: a Cross-Team Love Story

Are you ready?

People:

Process:

Data:Would you know if you had an attack?

Test everything - dry runs

Encourage open discussion and don’t be driven by rules

Page 62: When Security Meets Innovation: a Cross-Team Love Story

Thank you!

CRAIG DAVIES HEAD OF SECURITY •

ATLASSIAN @CRDAVIES

ANDREW WURSTER T/L • ATLASSIAN @YOURCISCOKID