[00:00.000 --> 00:02.960] ...value, and then it really seemed like they had, but that's an idea. [00:03.140 --> 00:03.320] Yeah. [00:03.640 --> 00:06.040] You can hire and fire people, you can change options. [00:06.180 --> 00:08.220] Exactly, you can get a trance for inventory, right? [00:09.960 --> 00:11.580] One or two minutes and stuff. [00:11.980 --> 00:12.560] That's good. [00:12.920 --> 00:13.560] You're all set. [00:15.620 --> 00:16.360] Welcome, everyone. [00:16.580 --> 00:17.300] Sorry for the delay. [00:17.500 --> 00:19.500] Little problem with the last leg. [00:19.900 --> 00:20.960] The amplifiers were off. [00:21.140 --> 00:21.980] Hey, who knew? [00:24.380 --> 00:26.620] We are here on Sunday. [00:27.980 --> 00:29.480] I lost your talk description. [00:30.860 --> 00:31.960] It's in here somewhere. [00:32.200 --> 00:33.280] It's in here somewhere. [00:35.960 --> 00:36.960] That's embarrassing. [00:37.960 --> 00:39.160] Head to right page and everything. [00:40.380 --> 00:43.000] Managing your company's intellectual property. [00:44.300 --> 00:46.440] An introduction to IT security. [00:46.960 --> 00:49.240] By number 35, Daniel Estrada. [00:53.440 --> 00:54.220] Good morning. [00:54.680 --> 00:56.220] Can everybody hear me okay in the back there? [00:56.420 --> 00:56.800] Yeah. [00:57.000 --> 00:57.420] All right, great. [00:58.020 --> 00:59.100] Thanks for coming out this morning. [00:59.260 --> 01:02.120] I've got going to give kind of some backgrounds. [01:02.520 --> 01:14.160] I work with a lot of small businesses, a lot of medium-sized businesses, doing different types of consulting, and working a lot, trying to sort of raise awareness of some of the security issues and some of the business perspectives on those issues. [01:14.640 --> 01:19.980] We have a lot of great technical talks at this conference, and those things are very important. [01:20.700 --> 01:30.920] And it's important to be able to communicate those ideas to managers and business people in a way that they can make sense of it and in a way that they can see the value in some of the things that we know are very valuable and very important. [01:30.920 --> 01:37.520] So just by show of hands, how many non-technical business people here? [01:38.280 --> 01:38.540] Okay. [01:38.760 --> 01:40.720] Any managers, people like that? [01:41.320 --> 01:41.540] Okay. [01:41.540 --> 01:41.580] Okay. [01:42.300 --> 01:45.660] There are a lot of, I think primarily we have consultants. [01:45.760 --> 01:46.640] Any security consultants? [01:46.800 --> 01:47.260] IT people? [01:48.840 --> 01:49.820] How about the rest of you? [01:49.980 --> 01:50.340] Students? [01:51.140 --> 01:52.040] Just here for fun? [01:52.900 --> 01:53.300] Okay. [01:53.880 --> 01:54.720] Too early to answer? [01:54.880 --> 01:55.080] All right. [01:56.540 --> 02:05.400] So I'm going to try to gear this a little bit towards all the different people we have, managers as well as some of the more technical issues. [02:05.600 --> 02:11.040] A lot of this is a very basic overview, and I give this to small businesses, to companies and professionals primarily. [02:11.300 --> 02:16.800] But we can talk about some of the issues that revolve around speaking to them about some of these issues. [02:18.700 --> 02:23.020] First thing we have is data is really the most valuable asset that companies have today. [02:23.020 --> 02:34.060] I don't think a lot of businesses realize this, but data is really the only thing, and intellectual property is really the only thing that you can't get back if it's stolen or if it's corrupted in any way. [02:34.420 --> 02:36.600] You have insurance for inventory and that kind of thing. [02:36.800 --> 02:41.420] So information technology doesn't really provide a strategic advantage for companies anymore. [02:41.660 --> 02:45.640] It's sort of the norm, especially because of all the global competition that we have. [02:46.460 --> 02:55.560] We have computers have become really a commodity, and it's really normal for most companies to be fairly up-to-date with technology, at least to a certain level. [02:57.080 --> 03:05.420] The only way for companies really to exceed the status quo, as we know, is through innovation and using technology to add value to their products and services. [03:05.740 --> 03:10.560] When customers see that there's that added value, that gives them an incentive to do business with one company versus another. [03:13.820 --> 03:16.700] Of course, everybody here knows why security is critical. [03:16.880 --> 03:18.800] We have internal threats, which are actually the most common. [03:18.920 --> 03:24.620] This is a big misconception among business people that external threats are the most common, but that's really not the case. [03:24.860 --> 03:26.440] We do have external threats, obviously. [03:26.680 --> 03:32.000] And then we have some of the ethical and regulatory compliance issues that a lot of companies are facing now. [03:32.100 --> 03:34.020] There's a lot of scrutiny from the government on these issues. [03:34.020 --> 03:36.500] So it's something that businesses are very concerned with. [03:38.580 --> 03:43.740] Security really must be a cultural value of any organization that embraces it. [03:44.680 --> 03:47.880] Companies, especially smaller businesses, try to sort of patch it on. [03:48.000 --> 03:49.760] You know, they buy a firewall and they think they're all set. [03:50.160 --> 03:54.340] You know, they do some password maintenance or something like that, and they think they're in the clear. [03:54.500 --> 04:04.820] But spending should really reflect, if you're going to invest time and money into protecting your most valuable assets, you should spend the time and the money that it takes to actually do that properly. [04:06.120 --> 04:09.740] Processes also need to be adapted to fit that new model of security. [04:09.880 --> 04:13.400] If a company decides to embrace security, it needs to change the way it does business. [04:13.900 --> 04:16.300] And also collaboration between teams. [04:16.560 --> 04:20.720] There's a lot of issues collaborating between an IT department and managers in a company. [04:20.900 --> 04:24.200] So it's very critical that people work to build those relationships. [04:25.700 --> 04:29.620] As I mentioned, security really needs to be part of every step of a process. [04:29.620 --> 04:33.520] It's not an afterthought and it's not sort of the final step that you see. [04:37.980 --> 04:40.280] Training should also be a priority for companies. [04:40.360 --> 04:40.920] This is a big one. [04:41.040 --> 04:46.440] It's very difficult to get companies to spend money on this because it's very difficult for them to measure any sort of return on their investment. [04:46.920 --> 05:02.960] A business owner doesn't want to send his or her employees to an afternoon seminar or something like that on security when he can't measure on a balance sheet where that money is actually helping his business or helping him make more money. [05:03.860 --> 05:08.020] But training does target the biggest security risk that there is and that's people. [05:08.400 --> 05:12.220] People are always, especially internally, the biggest risk for any organization. [05:12.220 --> 05:15.120] And that's something that businesses have a hard time dealing with. [05:16.940 --> 05:26.720] Training also has to be organization-wide and it has to be consistent across different departments and across different levels of the structure of an organization. [05:26.720 --> 05:32.500] It also has to provide enough technical detail to give employees sort of a big-picture overview of what... [05:32.500 --> 05:39.440] how these technology processes work in their business, what they're doing wrong or what they're doing right in sort of a grand scheme idea. [05:39.760 --> 05:44.560] But not too technical that they write it off as something that is someone else's responsibility. [05:44.900 --> 05:52.620] We all know that non-technical people tend to write off IT suggestions because they think that's an IT job. [05:52.740 --> 05:54.100] Security is the job of the IT department. [05:54.180 --> 05:54.900] That's not the case. [05:55.500 --> 05:57.220] It's the job of everyone in the organization. [05:57.460 --> 05:59.080] In fact, the IT department can do all it wants. [05:59.220 --> 06:08.200] If the employees are writing passwords on sticky notes and throwing out confidential information without shredding it, then the best firewall in the world isn't going to help you. [06:11.060 --> 06:13.460] We look at security also as sort of an insurance model. [06:13.580 --> 06:16.180] And this is a way I use to describe it to companies as well. [06:16.920 --> 06:21.660] And this sort of shows them why prevention is actually cheaper than cleanup. [06:23.240 --> 06:25.780] There is a reluctance to spend money on security, as I mentioned. [06:25.780 --> 06:27.980] Because it's difficult to quantify those benefits. [06:28.960 --> 06:32.560] A good example is a recent study I saw done by Gartner. [06:32.820 --> 06:40.360] They said that protecting customer records by encrypting them costs about $6 per record to do. [06:40.660 --> 06:42.540] That's sort of a preventative measure, obviously. [06:43.640 --> 06:50.940] And there's a $90 minimum they found in their study per record for cleaning up any mishandled or lost data. [06:51.280 --> 06:58.500] So it costs the company $84 more to clean up after a breach than it would to actually implement encryption technology at the beginning. [06:59.520 --> 07:03.280] You've probably heard of the stolen VA laptop that was recently recovered. [07:03.840 --> 07:05.200] This is kind of a funny story. [07:05.320 --> 07:13.680] The government is saying, oh, well, we found this laptop and we're happy to report that forensic evidence shows that nobody probably accessed the data. [07:13.960 --> 07:17.020] Well, most of us know that that's not really an accurate statement. [07:17.020 --> 07:20.360] You can't really tell if a hard drive has been copied or something like that. [07:21.300 --> 07:24.880] But there were 26.5 million social security numbers on this laptop. [07:25.720 --> 07:37.720] And if you look at a product like PGP desktop, which costs $199 for one license, this would pretty much let you set up some kind of whole disk encryption so that you can store this big database on this laptop encrypted. [07:38.540 --> 07:48.920] The recovery and investigation costs and forensics, I don't know what they are, but you would have to spend $10,335,000 to send mail to all of the people who lost their information. [07:49.140 --> 07:50.440] So that's just in postage. [07:51.380 --> 07:55.220] I don't know if they pay full rate for the postage, but that's what it would cost. [07:58.480 --> 08:06.120] As far as internal threats go, again, common misconceptions are that external threats are actually the greatest, pose the greatest risk. [08:06.120 --> 08:08.880] And that security is only a technical issue. [08:09.600 --> 08:12.320] The other thing is people think that hackers are the biggest threat. [08:12.660 --> 08:15.380] This is what Bill Gates thinks a hacker looks like, by the way. [08:16.240 --> 08:23.020] And so we see these sort of media images, obviously, of hacking and tech people. [08:23.940 --> 08:27.920] So the reality is that most security threats are internal or they originate internally. [08:29.580 --> 08:31.120] Employee access, obviously, is a big one. [08:31.200 --> 08:33.400] Disgruntled employees, you hear about that kind of stuff all the time. [08:33.940 --> 08:37.240] Intentional or unintentional misuse of that data by employees internally. [08:38.320 --> 08:41.220] And also some of the social engineering weaknesses that we see. [08:41.340 --> 08:42.820] And I'll talk a little bit more about that later. [08:43.480 --> 08:49.000] But these are basically used for data collection and for espionage within a company or from the outside. [08:49.740 --> 08:54.200] And this problem really is purely based on a lack of training and awareness in this area. [08:58.530 --> 09:01.650] Some of the non-technical aspects that are really under-emphasized by businesses. [09:02.330 --> 09:03.710] Training, obviously, as I mentioned. [09:03.990 --> 09:06.930] Implementing good policies and enforcing those. [09:07.270 --> 09:09.630] And auditing and process evaluation. [09:11.830 --> 09:13.950] Some of the external threats that we see. [09:14.070 --> 09:15.450] I'll kind of breeze through this. [09:16.410 --> 09:18.150] You know, technical components that we have. [09:18.310 --> 09:22.270] Obviously, very important passwords, network firewalls, antivirus software and appliances. [09:22.270 --> 09:23.590] And backup devices. [09:23.810 --> 09:26.710] These are critical components to any good security strategy. [09:27.730 --> 09:32.750] You have things that you use to protect against theft or loss of data. [09:32.890 --> 09:33.570] Backup procedures. [09:33.930 --> 09:35.970] Some kind of redundancy where you have an off-site. [09:36.450 --> 09:39.130] Some kind of off-site mirroring going on of your data. [09:39.450 --> 09:41.110] Disaster recovery if there is an issue. [09:42.190 --> 09:45.010] And then security assessments are also really important. [09:45.110 --> 09:48.270] They should be done regularly by experienced ethical people. [09:48.270 --> 09:51.010] And should always include training for employees. [09:51.170 --> 09:53.050] And this should be done on a pretty regular basis. [09:53.050 --> 09:55.150] To keep employees up to date on some of the issues. [09:55.950 --> 09:59.810] Just to give them, again, a big picture overview of what they need to be looking out for. [10:02.010 --> 10:07.290] We've seen, obviously, some cases of ethical issues with privacy and confidentiality. [10:08.130 --> 10:10.610] Some very bad PR for some of these companies. [10:10.930 --> 10:15.110] Citigroup lost 3.9 million pins for debit cards. [10:15.110 --> 10:19.190] They had to cancel transactions all over Europe for a short period of time. [10:19.370 --> 10:20.910] Just because these numbers were stolen. [10:21.370 --> 10:23.530] ChoicePoint is probably the most famous example. [10:23.950 --> 10:27.150] 145,000 personal records were stolen from there. [10:27.290 --> 10:37.170] Actually, they were given out inadvertently to a group or a few people who were going to use them for identity theft reasons. [10:37.170 --> 10:42.790] And card systems, which is a big processor of credit cards, lost 40 million account numbers. [10:44.750 --> 10:49.590] So, there really isn't a better business motivator for companies than these examples. [10:49.710 --> 10:53.010] And this is why we're seeing a big focus on legislation and security issues in the media. [10:53.030 --> 10:54.890] It's because these are very bad. [10:55.250 --> 10:57.690] These are very bad PR issues for these companies. [10:58.670 --> 11:00.290] So, we've seen the government response. [11:00.490 --> 11:01.690] I'm sure you're familiar with some of these. [11:01.690 --> 11:05.590] We have HIPAA, which is the Health Insurance Portability and Accountability Act. [11:05.750 --> 11:14.150] And this is, you know, this has a wide-ranging implications for insurance companies, healthcare providers, anybody who has to do with personal healthcare information. [11:14.810 --> 11:18.510] We have GLBA, which is geared towards financial service companies. [11:18.510 --> 11:21.450] A lot of the same restrictions on how they can use data. [11:22.330 --> 11:24.870] And then we have California's SB 1386. [11:24.870 --> 11:32.170] And this is requiring that any company that loses data about a citizen of California has to report that publicly. [11:32.830 --> 11:36.870] This bill is being considered by a number of other states in different forms. [11:37.310 --> 11:41.570] There are other pending pieces of legislation in pretty much every state. [11:41.790 --> 11:48.130] So, these acts typically have pretty nonspecific requirements, though not a lot of technical detail. [11:48.390 --> 11:50.170] But they are getting less flexible. [11:50.370 --> 11:52.850] And the restrictions and penalties are getting a little bit more severe. [11:53.650 --> 11:58.650] There are also a lot of very stringent requirements for doing business in the EU. [11:59.310 --> 12:07.350] They basically have... the EU has directives that it sets, which set minimum requirements for national laws in EU countries and member states. [12:08.350 --> 12:17.590] These are supposed to enable information sharing between the countries so that there's sort of a guarantee of privacy between countries when they share information in companies in those countries. [12:18.130 --> 12:23.210] And they do have specific requirements on data security as opposed to American legislation, which does not. [12:24.450 --> 12:26.510] As I mentioned, they're pretty strict. [12:26.510 --> 12:29.050] And the enforcement is very bureaucratic. [12:29.070 --> 12:30.830] And it's very, very strict. [12:31.110 --> 12:32.010] Very powerful. [12:33.890 --> 12:43.030] One way for American businesses to do business with EU countries, even though we don't have the same standards as EU countries, is to be a safe harbor organization. [12:43.030 --> 13:00.290] And what this means is it allows countries, it allows American businesses to be on a list of safe harbor organizations which allow them to certify that they have met certain privacy and security requirements imposed by EU countries. [13:01.530 --> 13:02.310] The U.S. [13:02.410 --> 13:10.290] Department of Commerce lists these, and there are seven principles of this security that they have to adhere to. [13:10.710 --> 13:15.370] Notice, choice, onward transfer, security, integrity, enforcement, and access. [13:15.990 --> 13:25.790] And each of these sort of outlines a few requirements about how companies can use data, how it needs to be stored, how it should be transmitted, and how access should be granted and denied to it. [13:28.980 --> 13:30.900] There are certification letters required. [13:31.160 --> 13:33.920] On an annual basis, companies have to renew their certification. [13:34.380 --> 13:40.100] And they have to publish privacy policies which are fairly detailed, just stating that they adhere to these rules. [13:41.220 --> 13:42.840] A little bit more on social engineering. [13:43.200 --> 13:47.520] Really, social engineering revolves around obtaining information that you don't have access to have. [13:47.700 --> 13:56.200] And usually this is used just through very simple means of deceit over the telephone, in person, by email, any of that. [13:57.240 --> 14:02.280] It sort of stems from our willingness to help one another, especially in a business environment. [14:02.280 --> 14:09.700] If you call another department and you complain about a problem that you're having, a lot of people in a company can relate to the same issues. [14:09.960 --> 14:11.440] They hate the same people. [14:11.620 --> 14:14.220] They hate the same bosses and that kind of thing. [14:14.400 --> 14:18.840] So it's easy to manipulate that desire and get people to do what you want. [14:20.580 --> 14:25.800] Useless information, which many employees consider to be unimportant, is often not. [14:26.160 --> 14:31.560] And usually social engineering revolves around obtaining one piece of that information at a time. [14:31.580 --> 14:34.540] So you start building sort of a set of information. [14:34.540 --> 14:40.160] And you can use that information to sound like an employee of the company that you're trying to manipulate. [14:40.160 --> 14:53.720] If you know what the lingo is internally, what some of the numbers are, the identification codes that they use, especially in high security places like banks and healthcare institutions, that can be very valuable. [14:53.940 --> 14:58.620] And so people are easily giving out that information when they shouldn't. [14:59.460 --> 15:02.080] Dumpster diving, I'm sure many of you are familiar with that. [15:02.520 --> 15:05.620] Companies do not do enough to protect their information once they throw it out. [15:06.760 --> 15:10.200] And emotional appeals are really what work best in these situations. [15:10.200 --> 15:12.580] And people are fairly vulnerable to this. [15:12.700 --> 15:16.180] Even the best social engineers are vulnerable to being manipulated in this way. [15:17.520 --> 15:24.460] So the best defense here, again, is training, making employees aware of what information is sensitive and what is not. [15:24.720 --> 15:28.160] There should be policies regarding all the different types of information that exists in an organization. [15:28.160 --> 15:30.700] And this doesn't have to be a very bureaucratic process. [15:30.720 --> 15:35.340] It just needs to be clear and well-defined and well-communicated to employees. [15:36.140 --> 15:40.160] They should be encouraged to always identify people through internal means. [15:40.540 --> 15:44.840] And just training them to realize that technology can't solve the issue again. [15:45.080 --> 15:51.120] Slapping some technology on the problem doesn't really fix the root of that problem. [15:51.120 --> 16:00.880] When I say identify people through internal means, that means call somebody back in an internal extension if they're asking for sensitive information. [16:00.880 --> 16:05.220] Just to verify that they're an employee of the company and that they have the access rights. [16:05.320 --> 16:11.540] Or that you can authenticate them as someone who is authorized to have that information. [16:13.580 --> 16:17.640] The Art of Deception is a great book written by Kevin Mitnick and William Simon. [16:17.900 --> 16:21.140] And it outlines, it has a lot of great stories. [16:21.300 --> 16:22.380] It reads a lot like fiction. [16:22.520 --> 16:23.700] It's a very, very quick read. [16:23.900 --> 16:26.320] A lot of great stories about different social engineering examples. [16:26.500 --> 16:27.140] Why they worked. [16:27.680 --> 16:29.580] What should have been done to prevent them. [16:29.580 --> 16:33.640] And it's an excellent resource really to see. [16:33.860 --> 16:38.080] And there's also a panel today at 2 o'clock in area A, which is on social engineering. [16:38.240 --> 16:39.120] I highly recommend that. [16:39.160 --> 16:40.120] I saw it last time. [16:40.700 --> 16:41.660] And it's very interesting. [16:41.800 --> 16:44.060] I'm sure they'll have some fun experiments there today. [16:46.060 --> 16:48.960] Backup recovery is another big topic for companies. [16:49.400 --> 16:50.900] Backup procedures are pretty standard. [16:51.020 --> 16:52.680] Most people know that you should be running a backup. [16:53.380 --> 16:55.900] But they're not really tested on a regular basis. [16:55.900 --> 16:59.920] And so when they don't work, companies are usually very surprised. [17:00.100 --> 17:02.020] And usually very bankrupt. [17:03.640 --> 17:05.920] Some of the guidelines on backup. [17:06.440 --> 17:09.200] Again, I'll sort of breeze through these because we have a lot of technical people here. [17:09.940 --> 17:13.240] The proper media for the size and kind of data you're storing. [17:13.880 --> 17:15.400] Encryption is very important. [17:15.900 --> 17:18.840] And on-site storage precautions that you would take. [17:19.020 --> 17:21.000] Put backup tapes in a fireproof safe. [17:21.120 --> 17:22.240] You know, something simple like that. [17:22.400 --> 17:23.840] It's a low-cost thing. [17:24.360 --> 17:27.760] You should also have a copy taken off-site on a regular basis. [17:27.940 --> 17:29.980] I always encourage companies to do that at least once a week. [17:30.460 --> 17:33.540] A safe deposit box in a bank or something like that is a good idea. [17:34.240 --> 17:36.080] And also test the scenarios. [17:36.480 --> 17:37.900] What would happen if you had a fire? [17:38.200 --> 17:40.440] Would you be able to recover most of your data? [17:40.520 --> 17:44.200] How many days' worth of data would you lose if, you know, your building burned down? [17:44.200 --> 17:46.800] Or you lost a backup tape or something like that? [17:46.980 --> 17:52.440] So those scenarios really help people visualize how painful it would be if they screwed something up. [17:55.800 --> 17:59.960] Off-site business continuity is also a good idea for large organizations who can afford it. [18:00.620 --> 18:02.120] IBM has a very strong offering. [18:02.360 --> 18:03.240] There are other companies. [18:03.340 --> 18:05.520] HP has an offering in these services. [18:05.780 --> 18:09.820] And this allows companies to mirror their servers and data centers off-site. [18:09.820 --> 18:12.860] So if they go down, there's a disaster, hurricane, that kind of thing. [18:13.020 --> 18:18.700] They can switch over to an off-site data center and be back online in a fairly short period of time. [18:20.700 --> 18:28.920] Also disaster plans are a good idea, especially if you have data centers or sensitive equipment in areas that are prone, tornado areas. [18:28.920 --> 18:33.520] And obviously down south during hurricane season, there's a lot of risk of that as well. [18:35.180 --> 18:36.900] These scenarios should also be tested. [18:37.140 --> 18:39.260] This is pretty important. [18:39.740 --> 18:50.060] And companies really need to leverage their budgets to spend money on the areas that are high risk and spend as much money there as possible and spend less money on areas that are less high risk. [18:50.060 --> 18:58.060] I think companies are reluctant to implement some of these things because they think there is a high cost involved here. [18:58.140 --> 19:00.320] They see the dollar signs in front of all of these things. [19:00.720 --> 19:06.920] And they don't realize that it's not about securing everything as tightly as you can necessarily. [19:07.500 --> 19:11.540] If you have a number of servers in your organization, some of them are going to have more sensitive information than others. [19:11.720 --> 19:16.860] So it's important to just identify what those requirements are and budget appropriately. [19:18.200 --> 19:21.780] Access controls is sort of the last main area that I'll talk about. [19:22.280 --> 19:24.600] We have password guidelines, obviously. [19:24.840 --> 19:26.200] Physical security is very important. [19:26.320 --> 19:31.800] A password is fairly useless if someone has physical access to the machine that they're dealing with. [19:31.900 --> 19:33.420] Or administrative access, obviously. [19:34.780 --> 19:37.160] Enforcing strength requirements is important on passwords. [19:37.380 --> 19:41.960] Forcing employees to second passwords, obviously, everybody knows is a good idea. [19:42.180 --> 19:45.140] And auditing those accounts regularly to make sure that that's actually happening. [19:47.560 --> 19:50.240] Also, there's sort of a practicality aspect to a lot of these things. [19:50.400 --> 19:54.620] And that is, passwords should be easy for employees to remember but hard to crack. [19:55.180 --> 19:59.360] And there is always sort of an issue with that. [19:59.540 --> 20:02.440] Making that practical enough so that your IT department isn't swamped with calls. [20:03.760 --> 20:05.660] I've got network server access. [20:06.680 --> 20:10.380] A little graphic I found online here. [20:10.380 --> 20:13.280] Wireless weaknesses are a big concern. [20:13.460 --> 20:14.800] That's something companies need to be looking at. [20:15.180 --> 20:21.160] Multi-factor authentication like key fobs and that kind of stuff is critical as well for higher security areas. [20:21.940 --> 20:23.000] And physical security. [20:23.180 --> 20:24.620] This is a big one. [20:25.200 --> 20:29.360] If a building is not secure, again, your firewall isn't going to do anything for you. [20:30.360 --> 20:33.040] And we also talk about granularity of permissions. [20:33.340 --> 20:38.820] This is just granting the appropriate level of permission at different levels of the organization or for different employees. [20:39.220 --> 20:44.580] Somebody in the accounting department doesn't necessarily need access to human resource records and vice versa. [20:44.880 --> 20:52.540] So the organization should really define who should have access to what and for what reason and limit that access as much as possible. [20:52.540 --> 20:58.860] As long as it remains practical for the organization to do so, people should only have access to the functional areas in which they're employed. [21:01.920 --> 21:06.740] So we look at some of the ways to maximize the benefits of IT using some of these security issues. [21:07.480 --> 21:11.740] And really the biggest thing is to identify some of those at-risk processes. [21:11.900 --> 21:13.540] What the systems are that are at risk. [21:13.640 --> 21:15.100] What the data looks like. [21:15.340 --> 21:16.280] Where does it go? [21:16.580 --> 21:18.940] How is it transmitted from one place to the other? [21:19.800 --> 21:20.900] Who should have access? [21:20.900 --> 21:23.060] And who really does have access to it? [21:23.280 --> 21:24.720] That there's often a disconnect there. [21:24.840 --> 21:27.660] And that's the problem I see in a lot of companies. [21:29.200 --> 21:31.200] And again, prioritizing spending. [21:31.760 --> 21:33.380] Higher risk should equal higher spending. [21:33.680 --> 21:36.600] And that should be a priority for an organization on a cultural level. [21:36.700 --> 21:39.640] They should really embrace security as a whole. [21:39.780 --> 21:41.720] Not just try to sort of patch it on. [21:43.560 --> 21:47.120] And implementing strong policies is very important. [21:47.260 --> 21:48.460] Publishing and enforcing them. [21:49.220 --> 21:54.840] An acceptable use policy basically states what's an appropriate use of the technology in an organization. [21:55.120 --> 21:56.680] How am I allowed to use my email? [21:56.820 --> 21:58.460] How am I allowed to use my computer? [21:58.600 --> 22:00.740] What am I not supposed to do with those systems? [22:02.680 --> 22:05.360] How is access granted and restricted? [22:05.700 --> 22:08.600] In a data access policy, you would outline that. [22:08.780 --> 22:09.920] Who has access to what? [22:10.060 --> 22:10.420] Why? [22:10.620 --> 22:13.300] How are we limiting or granting access to those systems? [22:16.660 --> 22:17.660] Email policy again. [22:18.360 --> 22:21.860] This can be certain content and security standards for email. [22:22.300 --> 22:23.620] Do certain emails have to be encrypted? [22:23.960 --> 22:26.580] Do emails have to contain a certain type of signature? [22:27.580 --> 22:30.060] Should you use disclaimers at the end of email? [22:30.160 --> 22:31.860] There are a lot of legal disclaimers that can be used. [22:32.360 --> 22:32.800] That kind of thing. [22:32.960 --> 22:34.860] So it's important for companies to look at this. [22:35.500 --> 22:43.620] Writing these policies, the biggest benefit to this is simply to have somebody sit down, write this out, communicate with some of the other departments, and say these are the things that we should be doing. [22:43.620 --> 22:48.360] And that process in itself is the most valuable aspect. [22:48.600 --> 22:50.320] These policies should be kept up to date, obviously. [22:50.540 --> 22:58.720] But saying, just sitting down and outlining this shows companies where some of the issues are, what they need to do about them, and how they need to train their employees. [23:00.900 --> 23:10.480] Data storage policy would outline where and how data is actually stored centrally, locally, how it's distributed, and why it's in those places. [23:11.440 --> 23:14.180] And again, I can't emphasize this enough. [23:14.940 --> 23:19.140] Cost-effective employee training is really the best way to deal with a lot of these situations. [23:20.820 --> 23:25.660] Employees are the biggest risk to a company, and so the money should be spent appropriately in that area. [23:26.160 --> 23:33.020] Buying a better firewall is great, but if you haven't spent money on training, you're probably losing some ground in that. [23:34.240 --> 23:37.920] There's sort of a big-picture overview that employees need to have, as I mentioned. [23:38.480 --> 23:42.340] And they also need to be aware of some of the social engineering risks that they face. [23:43.120 --> 23:46.920] And really, employees should be assuming that everything is confidential. [23:47.440 --> 23:55.780] If you set up an organization where there's a lack of trust between departments, that obviously can be a risky scenario as well. [23:55.780 --> 24:09.060] But there should certainly be a level of caution that employees are exercising when they're giving out information, especially if it's not in person, if it's not someone that they know and whose identity they can verify. [24:10.720 --> 24:13.620] So some of the conclusions that we can make from this. [24:14.380 --> 24:18.640] We shouldn't be surprised that people are the real problem in any technology implementation. [24:20.520 --> 24:26.520] They need to be helped to understand, not just learn what it is that you're trying to teach them. [24:26.600 --> 24:30.480] They need to be given that big-picture overview so they can make these connections on their own. [24:30.700 --> 24:37.840] It's amazing how a little bit of information goes a long way when you have good people in an organization who just don't understand how the processes work. [24:37.840 --> 24:45.740] So teaching them to understand where business fits into technology and vice versa lets them make these connections for themselves. [24:46.000 --> 24:54.040] And then you don't have to give very specific, very technical presentations to them about email or encryption or something like that. [24:54.140 --> 24:55.480] They're really not interested in learning. [24:55.660 --> 24:59.560] So that makes the whole process go a little bit more smoothly and they don't feel like their time is being wasted. [25:01.800 --> 25:04.440] So again, training and awareness should be periodic. [25:04.440 --> 25:12.820] It should be updated on a regular basis based on some of the changing requirements of the organization and what new threats maybe emerge in a particular field. [25:15.340 --> 25:15.820] So... [25:15.820 --> 25:19.520] Policies should be accessible to employees and well communicated, as I mentioned. [25:19.680 --> 25:30.780] And it's important to solicit input from them as well because employees want to feel like they're part of the process, not just being thrown into a training session to be given information that somebody else designed for them. [25:30.780 --> 25:35.420] So, ask employees, what is it, you know, what are some of the things that they're concerned about? [25:35.500 --> 25:36.520] What do they want to know about? [25:36.620 --> 25:38.500] What don't they understand about the organization? [25:38.700 --> 25:41.940] What don't they understand about technology and how it fits into the business? [25:42.420 --> 25:44.780] And you'll probably be surprised with some of the answers. [25:46.180 --> 25:48.020] Auditing and testing is very important. [25:48.180 --> 25:51.860] Policies and procedures should be audited on a regular basis just to make sure. [25:51.920 --> 25:55.820] And again, this sounds like something that's expensive and complicated, but it's really not. [25:55.820 --> 25:59.660] Especially if you have a smaller organization, this doesn't have to be an expensive process. [26:00.420 --> 26:02.020] Backup and recovery should be tested. [26:02.200 --> 26:04.540] Disaster recovery plans should be tested out. [26:05.160 --> 26:11.740] Scenarios, you know, we have fire drills in schools here, but companies don't do that kind of thing for technology, and they really should. [26:12.960 --> 26:15.260] Security processes and obviously the technical aspects. [26:15.400 --> 26:18.380] I mean, auditing your equipment is obviously very critical. [26:18.680 --> 26:25.340] You know, auditing firewalls on a regular basis, making sure that that kind of stuff is kept up to date, firmware, software, antivirus, all that kind of stuff. [26:27.480 --> 26:29.820] And companies really need to be willing to spend money. [26:30.160 --> 26:41.240] Despite the fact that they might not be able to measure their return on investment for some of these things, they have to be willing to say, we're going to spend money on this as a preventative measure, as an insurance cost, and write it off that way, [26:41.300 --> 26:43.280] and, you know, be comfortable with that. [26:43.280 --> 26:48.100] Really, the best way for them to do this is to make wise investments of time for their employees. [26:48.480 --> 26:59.000] Using employees who are already there, who are already being paid to work, you know, providing training to them, having them design policies, having an IT department work with security issues. [26:59.320 --> 27:04.000] This is the best way that companies, and the least expensive ways that companies can use their resources. [27:05.040 --> 27:08.620] This doesn't necessarily require you to buy new equipment or hire expensive consultants. [27:08.920 --> 27:18.820] It just requires you to leverage the employees that you have and make the most out of their current positions and out of their internal knowledge of how the company works. [27:19.000 --> 27:23.800] A consultant is great because he or she can provide sort of a bird's eye view of the organization. [27:23.800 --> 27:29.540] They're not ingrained in the organization, so it's a lot easier for them to identify the problems that exist within an organization. [27:29.540 --> 27:34.680] But they also don't have the years of experience that a workforce brings to a company. [27:34.840 --> 27:36.640] So they're not able to identify those problems. [27:36.780 --> 27:50.640] It's very important that if you have people coming in from the outside who are providing these extra levels of information, that they communicate regularly and directly with the people on the inside and really try to understand how the company works before they start trying to patch solutions. [27:52.220 --> 27:55.960] So with that, I'll take any questions that you might have. [27:56.420 --> 28:01.340] As I said, we can talk about some technical issues or specific business issues. [28:01.600 --> 28:06.520] I know it's a big concern to a lot of IT people to communicate with companies, with managers, that kind of thing. [28:06.620 --> 28:09.060] So if anybody has anything they'd like to ask, do we have a mic? [28:17.080 --> 28:17.640] How are you doing? [28:17.740 --> 28:18.780] Sorry, I kind of walked in late here. [28:18.940 --> 28:19.440] Two questions. [28:19.700 --> 28:19.920] Not a problem. [28:20.120 --> 28:20.200] Yeah. [28:20.640 --> 28:31.680] First is, could you illustrate a little bit more on giving the employee the regular Joe a bit more of a big picture on the IT infrastructure without kind of releasing secrets that could be potentially, you know, threats? [28:32.360 --> 28:32.440] Sure. [28:32.480 --> 28:32.480] Sure. [28:34.320 --> 28:35.920] I guess the best thing... [28:38.160 --> 28:39.800] I guess the best thing you can do... [28:39.800 --> 28:45.100] I mean, if you're talking to an employee, as far as a big picture, what I mean is... [28:45.940 --> 28:49.180] Employees don't have a good concept of what technology is actually doing for their business. [28:49.540 --> 28:57.180] They understand that email is a great thing, but it doesn't really make sense to them that email is a very sensitive technical issue. [28:57.380 --> 29:04.080] And that access to their email isn't just the messages they've been sending to Bob in accounting and, you know, the messages that are flying back and forth. [29:05.460 --> 29:14.280] So giving them a big picture sort of implies showing them, you know, email is this thing that we have either internally or if it's hosted externally. [29:15.380 --> 29:16.920] These are the issues that we see. [29:17.060 --> 29:18.780] You know, we don't want people to have access to this email. [29:18.880 --> 29:20.980] Your password is what actually protects that access. [29:20.980 --> 29:24.500] We have servers and technical means that are used to protect that access. [29:24.940 --> 29:28.000] But your email password is a very, very sensitive piece of information. [29:28.540 --> 29:34.620] Your access to your email, even if it's a laptop at an airport or something like that, is a very sensitive issue. [29:34.780 --> 29:45.680] So that in a big organization, when you have people who lose their laptops, and you have people who have issues with their passwords, they're not writing sticky notes with passwords and that kind of thing, they're made aware of the fact that those things are sensitive, [29:45.840 --> 29:48.340] that they're important to the organization and that they're valued. [29:48.340 --> 29:57.580] And that makes them realize, that makes them make a lot of the connections between how the servers and sort of the data shares that they use, or whatever it is that they use, network drives or anything like that. [29:57.740 --> 30:00.660] How that information is really valuable to the organization as well. [30:00.880 --> 30:05.480] So if you're talking to an employee, I mean, obviously a non-technical dialogue is really important. [30:05.700 --> 30:09.400] But sitting down with them and saying, this is how we use email in the organization. [30:09.520 --> 30:10.580] This is what it does for us. [30:10.920 --> 30:12.540] These are the things that are good about it. [30:12.580 --> 30:14.220] These are the things that are dangerous about it. [30:14.320 --> 30:16.460] And here's why we take these precautions. [30:16.460 --> 30:18.320] And here's why these things are important. [30:18.340 --> 30:19.840] important to our business. [30:20.220 --> 30:30.020] And so they start making those connections on their own and they start realizing that, oh, well, if that password... I mean, this sounds obvious to some of us, but oh, if that password is valuable, maybe these are too. [30:30.420 --> 30:34.860] You know, maybe I shouldn't be leaving my computer in the car overnight, you know, that kind of thing. [30:34.980 --> 30:37.860] And so you don't have to cover every scenario with them. [30:37.940 --> 30:41.320] You don't have to say, here's a huge list of all the things that you can't do. [30:41.320 --> 30:45.440] You just have to say to them, here's why we are protecting this information. [30:45.500 --> 30:48.320] And so they know, you know, and they can make those connections on their own. [30:48.760 --> 30:55.160] And my second question is one battle that we've had for quite some time now, just due to corporate culture. [30:55.420 --> 31:04.260] And the fact is that security is not in the forefront of our CIO, CTO, as well as several other benefactors of the executive label. [31:04.260 --> 31:20.260] And so, you know, we're trying to push policy here and it's real frustrating because, you know, you try to implement some sort of COIA measures so that once shit does hit the fan, excuse my language, but, you know, you're not looked at as, you know, negligible or you were negligent in your duties as, [31:20.260 --> 31:22.160] you know, being a part of the IT personnel. [31:22.160 --> 31:41.760] And I guess, kind of, my question is really more experience in your part is, you know, how do you go about creating a good argument without having to, I say, cover all the bases, be more surgical in pushing policies, you know, creating that real descriptive, [31:41.940 --> 31:44.960] illustrative argument to your, you know, upper heads. [31:44.960 --> 31:52.700] To, you know, explain, you know, this is, you know, exactly what you said in one of your last arguments or statements was the ROI, which is sometimes difficult, especially with security. [31:53.000 --> 31:55.500] It's really more of a countermeasure and being proactive. [31:55.840 --> 31:56.000] Yeah. [31:56.140 --> 31:57.240] Which is what we really need. [31:57.700 --> 31:58.080] Exactly. [31:58.080 --> 31:59.100] Because I'm tired of firefighting. [31:59.560 --> 31:59.680] Yeah. [32:00.380 --> 32:09.380] Yeah, that's probably the hardest thing that you'll have to ever do as an IT person is talk to high-level business people because, yeah, they have a completely different set of priorities. [32:09.380 --> 32:15.080] Their priorities are ROI or, you know, profit and where the revenue is coming from and where it's going. [32:17.000 --> 32:22.640] I think one of the best tools for convincing business people that they need to spend money on security is fear. [32:23.340 --> 32:29.380] They have to be afraid of their information being lost and they have to be made aware of how valuable that actually is. [32:29.660 --> 32:32.900] Like I said, I mean, data is the most important thing that a company has. [32:33.060 --> 32:36.320] You know, if I have a warehouse full of inventory, I can, I have insurance on that. [32:36.320 --> 32:40.560] And if somebody, you know, burns it or steals it, it's gone. [32:40.560 --> 32:44.140] But I'm going to get most of my money back for that inventory and I'm going to be able to recover from that. [32:44.550 --> 32:47.620] Data, once it's gone, you can't replace it, you know. [32:47.820 --> 32:55.420] And ways IT people know how sensitive that really is and how easy it is for that data to actually be lost or stolen. [32:55.580 --> 33:02.060] But as far as communicating those things, like I said, fear is a big motivator for those companies. [33:03.000 --> 33:04.920] Showing them some stats might be helpful. [33:04.920 --> 33:09.260] I don't know if you've seen the FBI CSI survey on information security. [33:09.440 --> 33:10.180] It's a great resource. [33:10.380 --> 33:14.380] They publish it every year and they do a survey of companies across different industries. [33:14.640 --> 33:20.360] And they give some numbers about how expensive it is for the average company to clean up after a data breach. [33:21.040 --> 33:22.260] What companies are doing. [33:22.420 --> 33:23.440] How many of them use encryption. [33:23.580 --> 33:24.780] How many of them use antivirus. [33:24.840 --> 33:25.800] How many of them have firewalls. [33:25.840 --> 33:26.360] That kind of stuff. [33:26.740 --> 33:29.320] To give you sort of an idea of what other people are doing. [33:29.320 --> 33:31.860] And that can be a big motivator for companies too. [33:32.000 --> 33:35.300] To say to a business person, look, in your industry people are doing these things. [33:35.520 --> 33:37.640] And policy is right up there like you're saying. [33:38.700 --> 33:41.100] You know, setting these policies and forcing them is right up there. [33:41.360 --> 33:42.940] Maybe some stats like that would help. [33:42.980 --> 33:43.420] I don't know. [33:43.660 --> 33:45.840] I think it kind of depends on the culture again. [33:45.900 --> 33:49.420] And as you said, the culture that you're describing doesn't seem to really value that stuff. [33:49.420 --> 33:49.760] No. [33:49.880 --> 33:52.360] And I definitely think it comes down to a numbers game. [33:52.620 --> 33:52.820] Yeah. [33:52.880 --> 33:54.260] Where you just have to blast with numbers. [33:54.360 --> 33:54.680] Absolutely. [33:54.840 --> 33:56.240] And everybody's fighting for their budget. [33:56.420 --> 33:56.580] You know. [33:56.680 --> 33:57.760] Especially in a larger organization. [33:57.860 --> 33:58.940] Which it sounds like you're working in. [33:59.300 --> 34:02.720] The IT department is fighting for its budget. [34:02.800 --> 34:04.360] All the other departments are fighting for their budgets. [34:04.440 --> 34:08.230] And it's really just a scramble to see who can get the most money out of the bigwigs. [34:08.360 --> 34:08.480] Right? [34:09.760 --> 34:14.540] So, what you need to do is simply sit down with them and say, look, this is a real problem. [34:14.710 --> 34:15.500] Here are the facts. [34:15.610 --> 34:16.630] Here are the numbers about this. [34:16.760 --> 34:18.070] Here are the companies like ours. [34:18.070 --> 34:22.360] Maybe find some companies in your industry that have had problems with this. [34:22.520 --> 34:24.520] Here's what it cost them to clean this up. [34:24.940 --> 34:27.050] Here's what it would have cost them to prevent it. [34:27.190 --> 34:28.380] And there are some good studies. [34:28.480 --> 34:35.070] As I mentioned, there's a study just done in June by Gartner about the comparison of cost between cleaning up and preventing a breach. [34:35.250 --> 34:39.480] So, I think those stats and those numbers are going to be the best way for you to communicate with them. [34:39.690 --> 34:47.440] Do those numbers also cover, I guess, a wide range of policies and, I guess, standards that could be applied to organizations? [34:47.440 --> 34:48.110] Mm-hmm. [34:48.110 --> 34:48.830] Such as SOX. [34:49.650 --> 34:49.750] Right. [34:49.920 --> 34:51.900] Where, you know, a company will be audited. [34:52.710 --> 34:53.210] Like, are those... [34:53.210 --> 34:56.880] Do you know where I get good stats on when a company does screw up or they get audited? [34:57.440 --> 34:57.460] Mm-hmm. [34:57.460 --> 35:00.520] And where I could find out, you know, what exactly happened to them? [35:00.520 --> 35:06.190] I'm not aware of any place where there are stats on specifically audits like that by the government because SOX is pretty new. [35:06.500 --> 35:06.850] Right. [35:06.850 --> 35:09.230] And, you know, obviously some of that legislation is pretty new. [35:09.570 --> 35:17.570] But companies are getting hammered pretty heavily by, I mean, obviously some of the corporate scandals that have gone on in accounting sort of, you know, forced that. [35:18.040 --> 35:20.020] And a lot of the public relations issues. [35:20.170 --> 35:22.230] Like, you know, I mentioned ChoicePoint, Card Systems. [35:22.480 --> 35:23.850] There are a lot of companies like that. [35:23.960 --> 35:31.710] But I don't know of any place where you can get stats specifically on either different policies or different legislative issues that have caused pain for companies, unfortunately. [35:32.650 --> 35:35.750] But if you come across that, I'd love to take a look at it. [35:36.070 --> 35:36.810] Thank you very much. [35:36.940 --> 35:37.020] All right. [35:37.110 --> 35:37.230] Thanks. [35:42.440 --> 35:42.960] Up here? [35:53.230 --> 35:53.590] Okay. [35:53.790 --> 35:54.370] Yeah, that's fine. [35:54.390 --> 35:54.490] Okay. [35:54.810 --> 35:55.190] I'll start. [35:55.610 --> 35:55.830] All right. [35:55.890 --> 35:59.410] You talked about implementing strong policies for email and data access. [35:59.870 --> 36:07.250] Is there a place where you can find templates so that you don't have to, like, try to start from scratch and think of everything that somebody else already may have thought of? [36:07.370 --> 36:07.590] Thank you. [36:08.050 --> 36:08.190] Yep. [36:08.350 --> 36:08.870] No problem. [36:09.990 --> 36:12.490] The best place I've seen to get some of these... [36:12.490 --> 36:14.410] There are a lot of websites that have these policies. [36:15.050 --> 36:16.670] SANS is a good place to start. [36:17.430 --> 36:19.170] S-A-N-S dot org. [36:20.970 --> 36:23.070] And that is an organization. [36:23.070 --> 36:23.770] They do training. [36:24.070 --> 36:28.370] They have seminars all over the country all year long on different security issues. [36:28.510 --> 36:30.150] They have security certifications that they give away. [36:30.310 --> 36:31.210] GSEC, GIAC. [36:31.330 --> 36:33.310] There are a lot of programs that they do. [36:33.370 --> 36:36.170] And they have on their website, they have a section of white papers. [36:36.170 --> 36:39.330] And they have a section on both policy templates. [36:39.690 --> 36:41.170] What a data access policy should look like. [36:41.290 --> 36:41.770] Or an email policy. [36:41.830 --> 36:42.290] A lot of stuff. [36:42.430 --> 36:42.970] And it's very good. [36:43.090 --> 36:43.710] Very good information. [36:43.910 --> 36:44.050] Yeah. [36:44.130 --> 36:44.670] That should help you. [36:47.490 --> 36:47.890] Go ahead. [36:49.150 --> 36:52.350] My company is pretty good sized. [36:52.710 --> 36:56.030] And we just hired a person to do awareness full time. [36:56.350 --> 36:56.690] Okay. [36:57.070 --> 36:59.850] Our InfoSec department is probably around 50 people. [37:00.070 --> 37:00.370] Okay. [37:00.610 --> 37:10.090] But what alternatives are available for companies that are small or medium size and they can't really afford to hire a person full time to do nothing but computer awareness? [37:10.090 --> 37:12.430] Are there programs that they can take advantage of? [37:13.750 --> 37:16.950] Before this person was on staff, it was sort of like ad hoc. [37:17.110 --> 37:18.010] Somebody would have an idea. [37:18.190 --> 37:19.810] Well, let's do something on passwords. [37:19.970 --> 37:22.470] Let's do something on this, that, and the other thing. [37:22.710 --> 37:22.830] Right. [37:22.910 --> 37:24.170] Can you give us some ideas on that? [37:24.670 --> 37:25.070] Yeah. [37:25.410 --> 37:29.590] That's a tricky one because obviously small businesses have a lot fewer resources. [37:29.590 --> 37:31.190] They don't have the same kinds of budgets. [37:31.350 --> 37:34.910] And they don't prioritize the same things that a big company would prioritize. [37:35.270 --> 37:39.390] So you see a lot of times you see they don't want to bring in consultants because it's very expensive. [37:39.750 --> 37:41.610] Obviously, they don't have the money for full time people. [37:42.350 --> 37:48.730] Very small organizations don't have the money for full time IT people, much less training seminars for their employees, that kind of thing. [37:48.970 --> 37:55.090] The best thing I can say about that, I don't know of any nationwide resources that are available for that sort of training. [37:55.230 --> 38:00.310] I mean, like I said, there are specific technical security training seminars that are given by organizations like SANS. [38:00.310 --> 38:07.210] But you can, you can bring somebody in to do some training on a regular basis and it doesn't have to be that expensive. [38:07.910 --> 38:13.810] But again, nationwide, I'm not aware of any sort of programs that exist, but, or software or anything like that. [38:13.950 --> 38:20.450] There are books and those sorts of things and guides, good templates that are available online for some of the data policies. [38:20.450 --> 38:33.110] But unfortunately, I don't know of anything besides bringing in a consultant just to work with employees every six months or every nine months or once a quarter or whatever it is, for smaller organizations to really have that same level of awareness as a big organization. [38:33.330 --> 38:38.130] But the advantage in a small organization is you have fewer employees, so your training costs should be pretty low. [38:38.670 --> 38:40.770] You know, you're really just talking about a couple of hours. [38:41.070 --> 38:43.990] You know, I would always split training sessions up, obviously. [38:43.990 --> 38:49.870] Do an hour or two at a time and don't do it over a whole day because we all know people zone out. [38:50.030 --> 38:54.150] It's not, you know, it's not conducive to them really picking up as much information as they could. [38:54.330 --> 38:59.070] So, you know, do it over this course of a couple of weeks and do it for a few afternoons at a time. [38:59.170 --> 39:02.830] And that works in a small organization even better than in a larger organization. [39:02.870 --> 39:05.950] Because if you have all your employees at this training seminar, obviously nothing's getting done. [39:06.190 --> 39:12.550] So if you can split it up with smaller groups and do it that way with somebody who you bring in from the outside, I think that's going to be your best bet. [39:13.390 --> 39:15.150] So, sorry, that doesn't really answer your question. [39:19.370 --> 39:20.570] Have you found... [39:23.230 --> 39:24.070] Yeah, that's all right. [39:32.960 --> 39:47.600] It seems like when you talk to, I guess, upper management and you mentioned the word security, they automatically think IT, which is why it's hard to get the funding and get the money to create programs. [39:48.540 --> 39:57.560] I guess through your consulting work, have you found a better way to communicate to upper management that security is just not an IT issue, it's an organization. [39:57.800 --> 40:00.900] You know, like you mentioned social engineering, physical security. [40:01.260 --> 40:05.120] So have you talked to, like, companies to say, you know, this is a corporate thing. [40:05.220 --> 40:06.260] This is not just IT. [40:06.480 --> 40:07.060] Right, right. [40:08.540 --> 40:23.280] One of the best things to do, especially in a large organization who can afford this kind of consulting, is to go into an organization and say, look, you have a certain level of confidence in your IT security, you have a certain level of confidence in your antivirus and your firewalls, [40:23.300 --> 40:23.740] that kind of thing. [40:24.360 --> 40:28.080] Simple pen-testing and that kind of stuff can, you know, see if that's actually effective. [40:28.080 --> 40:36.440] But going into an organization and using a consultant who specializes in social engineering, for instance, and saying, look, we can get this information without even hacking into your systems. [40:36.720 --> 40:41.260] We can, you know, we went into your trash and got these social security numbers. [40:41.420 --> 40:45.420] We found copies of these emails, you know, between high-level execs in your trash. [40:45.420 --> 40:52.160] We walked through your office and collected ten passwords that were written on sticky notes or on monitors or something. [40:52.920 --> 41:04.420] Those kinds of demonstrations are incredibly powerful because that really makes a CEO step back and say, you know, wow, you didn't even have to access our data systems and you got all this information. [41:04.620 --> 41:06.620] Imagine if somebody actually hacked the system. [41:06.800 --> 41:08.720] You know, what would it look like? [41:08.880 --> 41:15.480] So, again, fear is a big motivator and demonstrating to a company that those things can be done is very powerful. [41:15.800 --> 41:17.080] So that would be the best thing I think you can do. [41:17.960 --> 41:20.480] How can you do that without getting thrown in jail? [41:21.640 --> 41:23.240] Well, you have to... [41:23.240 --> 41:23.460] Yeah, go ahead. [41:23.460 --> 41:38.460] A lot of these people that even can show a weakness, they really come down on here like what happened at the New York Times article and other companies that they show them the flaw and they wind up in jail. [41:38.460 --> 41:47.380] And how can you convince the upper management of a company that IT security needs to have more funding directed toward it? [41:47.440 --> 41:52.640] Because most of the problems I encounter is, well, it ain't gonna happen to me. [41:52.980 --> 41:53.380] Right. [41:53.580 --> 41:54.760] And that kind of a thing. [41:55.100 --> 41:55.240] Right. [41:55.520 --> 42:05.280] Yeah, there's a big mentality, I think, in that regard to saying, well, you know, big companies with sensitive credit card numbers, you know, are the most vulnerable or, you know, they're gonna be the companies that are targeted. [42:05.400 --> 42:08.820] Our company, nobody would care what we have, you know, as far as information goes. [42:09.740 --> 42:15.120] But without getting thrown in jail, yeah, that's the best thing I think you can do. [42:15.280 --> 42:19.680] If you're approaching a company to do consulting or you're working internally in a company, obviously, it's a different story. [42:19.860 --> 42:23.040] But if you're approaching a company, obviously, what you don't wanna do is... [42:24.580 --> 42:26.660] Yeah, what if you're a consultant to a company? [42:26.860 --> 42:27.200] You know what I mean? [42:27.220 --> 42:27.400] Right. [42:27.460 --> 42:31.120] You're doing something other than security, like doing a program for them or something like that. [42:31.460 --> 42:39.100] This is especially true for in Hollywood, where I'm down in Hollywood, a lot of these media companies and movie companies and all this, TV companies and stuff like that. [42:39.200 --> 42:41.160] They just have no concept of security. [42:41.300 --> 42:41.420] Right. [42:41.860 --> 42:44.700] Well, the best thing to do is approach them with a confidentiality statement. [42:44.740 --> 42:45.660] That's usually what I do. [42:46.300 --> 42:51.280] Approach them with a confidentiality statement and say, here are, you know, I'd like to take a deeper look into this. [42:51.480 --> 42:55.320] Here is a statement that says, whatever information I find is gonna be kept confidential. [42:55.500 --> 42:56.740] And you have to really get their permission. [42:56.820 --> 42:57.960] I think that's the most important thing. [42:57.960 --> 43:00.580] And how does one get permission from a company? [43:00.720 --> 43:08.560] Like, for instance, if they want me to do a pen-testing, for instance, that really scares me because somebody in that company has to authorize this pen-testing. [43:08.760 --> 43:08.800] Right. [43:08.800 --> 43:19.920] And isn't there, don't you have to go through some type of legal, what is the legal requirements that went to a company to get authorization for pen-testing and the conditions that they might impose therein on that? [43:19.960 --> 43:24.000] Because that's one of the big things that scare me from penetration testing. [43:24.000 --> 43:24.260] Right. [43:24.520 --> 43:28.740] Well, again, that varies from state to state because there's a lot of new legislation, especially when you look at wireless and that kind of thing. [43:28.820 --> 43:33.720] There have been a lot of cases, you know, saying people have been getting thrown in jail for doing wireless pen-testing and that kind of thing. [43:33.820 --> 43:47.300] But if you approach a company, if you get authorization from a company to do whatever you need to do to get into their systems and you are released from liability from that company, basically, you have a release from liability that says, I'm not liable if I bring your systems down. [43:47.300 --> 43:52.600] You know, if we steal this information and we get access to it, you're not going to press charges against us. [43:52.680 --> 43:54.400] That's really the only thing that you can do. [43:54.500 --> 43:57.040] And legally, that covers you pretty broadly. [43:57.300 --> 44:01.860] Is there a boilerplate agreement that one could get on the net somewhere for this kind of stuff? [44:02.740 --> 44:12.660] I'm not sure if SANS has something like that, but I think you should be able to find some kind of standard agreement that does that or otherwise talk to an attorney. [44:12.980 --> 44:14.800] It's a page long document. [44:14.920 --> 44:17.500] It shouldn't take, you know, it shouldn't be very expensive to have an attorney look at. [44:17.640 --> 44:21.540] Or if you get a template, just have an attorney revise it and explain to them what you're doing. [44:21.780 --> 44:24.920] Somebody who works in software and hardware specifically would be a good resource. [44:25.200 --> 44:28.060] But I'm not aware of any sites that have specific templates for that kind of stuff. [44:28.660 --> 44:29.240] I'm finished. [44:29.360 --> 44:29.820] Thank you very much. [44:29.960 --> 44:30.420] Okay, you're welcome. [44:30.480 --> 44:30.700] Thank you. [44:32.280 --> 44:47.700] Do you find it's more effective to have an outside company as a consultant come in and do the penetration testing for management to see that this outside company's come in with no knowledge of the network and they're able to get this information or, I mean, [44:47.740 --> 44:54.480] opposed to having internal IT staff or internal IT security come in and actually do the penetration test. [44:54.820 --> 44:56.860] And it's kind of like, oh, they know the network. [44:57.000 --> 44:57.500] They know this. [44:57.500 --> 45:00.580] You know, obviously we could squeeze more out of it and we could get more data out of it. [45:00.920 --> 45:00.980] Right. [45:01.080 --> 45:05.340] In your experiences, what have you found as the more viable approach? [45:05.480 --> 45:13.120] And if internal IT is actually doing the auditing, you know, how do you present that to people in such a non-biased way? [45:13.340 --> 45:13.860] Right, right. [45:14.320 --> 45:24.860] Well, one of the big things with working with an external consultant is that the IT company or the IT department, there's a certain level of threat that they feel from that company. [45:24.860 --> 45:33.740] Because I've, in an IT department, I've come in and I've set up this system and I've configured my firewalls and I've set up all this AV stuff and I have all this technology in place to keep it secure. [45:34.000 --> 45:36.340] And now somebody is going to come in and try to break that. [45:36.600 --> 45:40.260] And so now my job, or I feel at least that my job is on the line. [45:40.460 --> 45:50.760] And so for a consultant, it's very difficult to go in and say, look, talk to the IT people and say, look, we're here to make your job easier, not to, you know, make you look bad in front of management or anything like that. [45:50.880 --> 45:51.740] So that's a big issue. [45:51.880 --> 46:07.420] But in terms of what companies like to see, I think it's important to have somebody from the outside come in and do it, not just because they are able to demonstrate, like you said, that it can be done from the outside and you don't have to have inside information to do it, [46:07.480 --> 46:11.660] but also because they provide a perspective that the people inside the company don't have. [46:11.880 --> 46:23.440] You know, all of us know, especially if you've done programming or worked in big projects, you know, the more you're in something and you're dealing with it on a daily basis, the harder it is for you to step back from that and look at it with an objective perspective. [46:23.800 --> 46:34.740] So I think in that sense, it's very important to have that outside perspective to say, here are these things that you maybe haven't considered, and these might be some risks that you haven't looked at, and then actually do the pen-test and say, yep, you know, [46:34.820 --> 46:36.000] there were problems here. [46:36.180 --> 46:48.220] So I would recommend a combination of both just because the IT department should be prepared to work with those consultants and say, look, here's what we've done after, I mean, after the pen-test is done, here's what we've done, and here are, you know, [46:48.280 --> 46:59.780] the things that you've found, and now the consultant can say, you know, these are going to be the only things, thank you, these are going to be the only things, these are going to be the things that we're going to look at and focus on the most and work with you to try and solve those issues. [47:00.400 --> 47:01.920] So I think that's... [47:01.920 --> 47:02.300] Thank you. [47:02.500 --> 47:02.800] You're welcome. [47:02.900 --> 47:03.840] Do we have time for one more question? [47:05.460 --> 47:06.520] Okay, go ahead. [47:08.700 --> 47:14.280] A lot of time IT department is wasting a lot of time in answering basic questions. [47:15.120 --> 47:17.460] How do you recommend solving those? [47:18.140 --> 47:19.060] That's a good question. [47:19.200 --> 47:20.420] Resetting passwords and that kind of stuff. [47:22.600 --> 47:24.400] Yeah, that is a good question. [47:25.480 --> 47:26.360] Training is huge. [47:26.880 --> 47:29.940] I know I'm repeating myself here a lot, but training is huge. [47:30.800 --> 47:46.380] If you want to reduce the number of support calls that you get about email or about a particular application, let's say you have an application that you run in-house, and you want to reduce support calls on that, the best thing to do is to set up a couple of seminars with some employees who are... maybe start with a small group and see how it goes, [47:46.600 --> 47:50.340] but set up a seminar that covers some of the issues that you get. [47:50.420 --> 47:54.240] Make a list of all the calls that you get that are the most frequent, like a fact sheet, basically. [47:54.820 --> 47:56.400] These are the things that we get asked about. [47:56.800 --> 47:59.040] People have trouble attaching things in an email. [47:59.180 --> 48:04.400] They have trouble... they don't understand the messages that they're getting from their antivirus software. [48:04.700 --> 48:09.720] They don't... or they have problems with passwords or resetting passwords on a daily basis, that kind of thing. [48:10.480 --> 48:23.260] So maybe you need to just make a list of what those things are that you're seeing most frequently, and then design some training around it, and just say, these are the issues we have to cover in an easy format, and give employees some information. [48:23.420 --> 48:36.060] Maybe make some handbooks or something that gives them some guidelines on how to use those technologies, and just start implementing some of that training on a small scale and see how it goes, because you should see a reduction in the support calls that you get for those issues. [48:36.060 --> 48:37.980] So I think that would probably be the most effective thing. [48:38.560 --> 48:39.260] Thank you. [48:39.360 --> 48:39.720] You're welcome. [48:39.920 --> 48:40.740] Thank you very much.