tomorrow’s cyber risk analyst - rsa conference of tomorrow’s cyber risk analyst #rsac — not...

33
SESSION ID: SESSION ID: #RSAC Jack Jones Tomorrow’s Cyber Risk Analyst PROF-W11 EVP Research & Development RiskLens, Inc. @FAIRiq

Upload: lephuc

Post on 23-Mar-2018

221 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

SESSIONID:SESSIONID:

#RSAC

JackJones

Tomorrow’sCyberRiskAnalyst

PROF-W11

EVP Research & Development RiskLens, Inc. @FAIRiq

Page 2: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Whatwe’llcover…

2

Current state of risk “analysis”

Why change is necessary (and inevitable)

Characteristics of cyber risk analysis

The opportunities

The challenges

Steps you can take…

Q&A

Page 3: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Currentstateofrisk“analysis”

Page 4: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSACHowwouldthesequestionstypicallybeanswered?

4

“How much risk does this audit finding/policy exception request represent?”

“What are our top ten risks?”

“Which should we do first, improve access privilege management or improve the patching process?”

“How much less risk will we have if we invest in the security technology/process you’re recommending?”

Page 5: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSACWhatisthemostcommoncyberriskmodelinuse?

5

Mental models

Page 6: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Inmostorganizations,70%to90%of“HighRisk”issuesaren’thighrisk

Page 7: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

Whyitmatters…Risk

Controls

AssetsThreats Impact

Risk Management

Decisions

Setting Objectives and Expectations

Prioritization

PoliciesResourcesProcessesStrategiesInitiativesTechnology

Intended State of Risk

Execution

Awareness Capabilities Motivation

CommunicationResourcesEnforcement

Actual State of Risk

Monitoring & Testing

Analysis & Reporting

Page 8: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Whychangeisinevitable

Page 9: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Changingrisklandscape

9

Changes in business requirements and technology solutions are happening faster

Budgets are tightening

Risk management requirements are increasing

Page 10: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Theimplications…

10

We need to be able to prioritize extremely well

We need to be cost-effective in our solution choices

We need to be able to justify our recommendations/choices

Page 11: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Seniorexecutivesaregettingtiredof…

11

Andsoaresomeregulators…

Page 12: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

ThisISgoingaway

12

It’s umm… “Medium

risk”

Page 13: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Wouldyoubecomfortablewith…

13

A network architect performing a web application security review?

An identity and access management professional performing forensics on a server?

An auditor writing an encryption algorithm?

Then why should we be comfortable with just anyone waving their wet finger in the air and proclaiming, “It’s high/medium/low risk”?

Page 14: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Characteristicsofcyberriskanalysis

Page 15: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSACCyberriskanalysis—itisn’teveryone’sideaofagoodtime…

15

Complexity

Numbers

Uncertainty

Page 16: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSACCharacteristicsoftomorrow’scyberriskanalyst—noteveryoneneedapply…

16

CriticalThinking

Peopleskills

Understandsbasicprobabilityconcepts

Probabilityofrollinga7=0%

Speaking

Writing

Page 17: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Oh—andonemorething…

17

Thisappliestodoinganalyses…

…aswellasdealingwithpeople/culturalchallengesinyourorganizationandtheprofession

Page 18: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Theopportunities…

Page 19: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Characteristicsofa“perfect”job…

19

Newfield

Payswell

Notboring

Movestheneedle

Page 20: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Examplesofthevalueproposition…

20

Prioritizing well…

Gaining support for critical improvements…

Smart compliance…

PCI

SOX

Page 21: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSACOrganizationsthataretakingriskanalysisseriously…

21

…can’t find enough people with the right skills

Page 22: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Universitiesfocusingonfillingtheneed

22

San Jose State University Preparing economics majors for opportunities in infosec

Examples of universities that include FAIR in their curriculum

Carnegie Mellon

Webster University

Ferris State University

Washington University in St. Louis

Page 23: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Challenges

Page 24: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

Inertia

Lipstick on pigs

Complacency & ignorance

Page 25: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Butexpectationsarechanging…

25

Page 26: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Stepsyoucantake…

Page 27: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Step1—rightnow

27

Ask yourself whether this is something you could enjoy.

Or is it something you’re already responsible for…?

Page 28: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Step2-todayortomorrow

28

Join

FAIR Institute (www.fairinstitute.org) — Global community of professionals focused on evolving risk management — Non-profit, no cost to join — Rich blog resource — Special interest groups (cyber risk, operational risk, cyber insurance, data utilization,

university educators, local chapters)

Check out — Open Group’s OpenFAIR standard and professional certification (www.opengroup.org/

security)

— Society of Information Risk Analysts (www.societyinforisk.org)

Page 29: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Step3—withinthenextweek

29

Evaluate your organization’s risk analysis maturity

Is it all about wet fingers in the air?

Does the organization struggle to measure and communicate risk consistently and effectively?

Are there endless religious debates about whether something is “high risk” or not?

Is risk analysis a distinct specialty in your organization and, if not, should it be?

— And if it is a specialty, are the people doing it qualified?

Page 30: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Step4-withinthenextthreemonths

30

http://www.fairinstitute.org/blog/5-must-read-books-to-jumpstart-your-career-in-risk-management

Startreadingthesebooks

Page 31: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Step4b-withinthenextthreemonths

31

Ifyourorganizationwantstotakecyberriskanalysisseriously,considersponsoringtheeffortatSanJoseStateUniversity

ContactMikeJerbic<[email protected]>

Page 32: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Summary

32

Effective cyber risk analysis is rare today, which has significant implications in an organization’s ability to manage risk

Expectations are changing, and leaning strongly toward more rigorous, quantitative methods

The need for cyber risk analysts is growing and only going to accelerate

If analysis is your cup of tea, and if you want to contribute to the next stage of evolution in our profession, this might be the “perfect job”

Page 33: Tomorrow’s Cyber Risk Analyst - RSA Conference of tomorrow’s cyber risk analyst #RSAC — not everyone need apply… 16 Critical Thinking People skills Understands basic …

#RSAC

Q&AThankyou!