October 28, 2015 Cyber Security Awareness Update
2 NATIONAL CYBER SECURITY AWARENESS MONTH Stop. Think. Connect
National Cyber Security Awareness Month –Every October Sponsors –Department of Homeland Security –National Cyber Security Alliance –Multi-State Information Sharing and Analysis Center Goals –Engage and educate the public and private sector –Raise awareness about cyber security –Increase resiliency of the nation in the event of a cyber incident 3
Common Terminology Malware = malicious software –Virus, trojan, worm, spyware, ransomware –“zero day” = no known patch (fix) for the malware/attack Security Incident –Event that compromises the confidentiality, integrity, or availability of an information asset Data Breach –Incident that resulted in confirmed disclosure to an unauthorized party 4
5 DISTRICT CYBER SECURITY TRAINING You are the Target
WHY HACKING EXISTS TypeMotives Cyber Criminal (monetary) ID theft, credit card info, extortion (ransomware, DDoS), click-jacking, Point-of-Sales, ATM skimmers Hacktivists Political, ideological, religious, social reasons (Ashley Madison, WikiLeaks, Eric Snowden) Nation State National offense/defense, espionage, sabotage, intellectual property, counterintelligence Cyberwar/Cyber Terrorism Large-scale disruption/destruction of critical systems (Smart Grid, nuclear, water/wastewater, banking, military) 6
CYBER CRIME EXAMPLES 7
2015 DATA BREACH INVESTIGATION REPORT 8 * Verizon 2015 Data Breach Investigations Report
ATTACKS ON SCADA SYSTEMS Springfield, Illinois –Network breach allowed attackers remote access –Hackers controlled a water pump and burned it out Attack lasted 2-3 months before an operator noticed a “glitch” –Stole credentials Televent (maker of SCADA software) –Network breach allowed malware install –Customer files affected –Project information stolen (OASyS – remote admin tool) –Televent manages 60% if total hydrocarbon movements in North American and Latin American pipelines Australian Wastewater Plant (Maroochy Water Services) –SCADA system attacked for 3 months with a laptop, proprietary radio, and homemade cable –140 sewage pumping stations compromised –Sewage spilled into waterways and canals 9
10 EVWD Security Activity Malware and Web Filter Statistics
RECENT MALWARE ACTIVITY 11
RECENT MALWARE ACTIVITY 12
WEB FILTER 13
SUMMARY OF OTHER TOPICS – is our most common vector for malware Social Engineering and Phishing s –Mobile Devices Privacy, rogue apps, security practices –Tips and Resources Managing Passwords Securing Your Home Network 14
Questions