Cyber Resilience: Is it a case of preparing for the inevitable?

Slides:



Advertisements
Similar presentations
5 th March Scale of ambition International is centre stage Transition to a low(er) growth environment Emphasis on process and service.
Advertisements

Working for Warwickshire – Competency Framework
THE STRATEGIC COUNCIL LEADERSHIP TRUST AND ENGAGEMENT NEW FUNDING SOURCES AND NEW DELIVERY VEHICLES Appendix 1 NEW FUNDING SERVOURCES AND NEW DELIVERY.
Risk and Resilience Delivered by Alba
CIPD Profession Map Sarah Koppen Profession Map Project Executive
Managing Your ALMO Members Survey. Survey Questions 1.Board Structure 2.Performance Management 3.Annual Delivery Plan 4. and 5.Services in the MA or SLAs.
A Covenant University Presentation By Favour Femi-Oyewole, BSc, MSc (Computer Science), MSc (Information Security) Certified COBIT 5 Assessor /Certified.
Technical Review Group (TRG)Agenda 27/04/06 TRG Remit Membership Operation ICT Strategy ICT Roadmap.
Business Crisis and Continuity Management (BCCM) Class Session
How to better protect the business - Introduction based on findings of SUPPORT Delft, May 9, 2012 Henk van Unnik Senior advisor, Securitas Maritime & Logistics.
1 Continuity Planning An Overview…. 2 Continuity Planning Bill Scott CBCP Contingency Planning Coordinator Great Lakes Educational Loan Services, Inc.
Organisational Change Management Services: Insight and Capabilities
Heat Network Partnership
Service Reviews Tranche 2 1. Largest ever cuts in local government funding At least 33% reduction in Government Grant in the 7 years up to 2017/18 Big.
BOTSWANA NATIONAL CYBER SECURITY STRATEGY PROJECT
1.  1.1. Identify purpose of the business plan  1.2. Identify and review the essential components of the business plan  1.3. Identify and document.
Mandy Forrest VAS/ Anne Giller SCC Commissioning for the Terrified.
Introduction to SEPA The Scottish Environment Agency For CaSPr Waste Workshop Glasgow 19 October 2006 Claudette Hudes NetRegs Team Leader.
Collaboration and Localism Sara Blake Head of Localities and Communities.
Develop your Legal Practice using “Cloud” applications, but … Make sure your data is safe! Tuesday 17 November 2015 The Law Society, London Allan Carton,
Personal Leadership Serving Customers Managing Resources Leadership Serving Customers Serving Customers Managing Resources Managing Resources Working for.
S3.1 session day 3 1 training delivered by Oxfam GB, RedR India and Humanitarian Benchmark; January 2012, Yangon, Myanmar approved by the Advisory.
Three Rivers District Council Corporate Peer Challenge Feedback from the peer challenge team September
“TWO HEADS ARE BETTER THAN ONE” AN EXAMINATION AND ANALYSIS OF THE ROLE OF THE DEPUTY PRINCIPAL IN IRISH PRIMARY SCHOOLS TERRY ALLEN.
INTERNAL AUDIT BRIEFING Business Objectives Business Objectives: What are they and how are they used?
RESOURCES AND CORPORATE DEVELOPMENT SCRUTINY COMMITTEE Tuesday 17 th June 2003 RESOURCES DIRECTORATE Julie Alderson Executive Director Resources.
Prevent - Stopping People Becoming Terrorists or Supporting Terrorism Detective Chief Superintendent Alan Lyon National Coordinator Prevent
Cyber Security Phillip Davies Head of Content, Cyber and Investigations.
Deborah Connor President Diabetes New Zealand 26 November 2016
Procurement Development Programs
Business Briefing Security Service Providers
Download this presentation from
SIPR: International Policing Conference
Successful Integration is a result of good governance – getting the wiring right Integrated care as an aspiration is simple, and simplest if one begins.
The Internal Audit Role in assessing Cybersecurity
Risk Management Policy & Procedures
Care Act – Strategic Partner Engagement
Senior Management Leadership Programme Review and next steps
CES Locality working and enabling communities
National Cyber Security Programme Local : Building Resilience Together
Kate Yorke, Project Manager – MECC
Crisis Management Team Overview
ACTIONS FOR LOCAL LEADERS
Cyber Security in Ports Business as Usual?
Managing Change and Other Keys to Successful Implementation
Kate Yorke, Project Manager – MECC
Housing Support and Personalisation
Technology Enabled Care and Support in Devon
Developing an integrated approach to identifying and assessing Carer health and wellbeing ADASS Yorkshire and The Humber Carers Leads Officers Group, 7.
Sustainability & Transformation Plans (STP)
Selecting a new grant management system
Cyber security Policy development and implementation
Cyber Security Culture
Susan Johnson CFOA Director Performance & Improvement
Joint inspections and co-operation in Scotland
Neil Kirton and Zoë Newman
Building a sustainable health and wellbeing programme
A framework for professional development
Social prescribing in County Durham
Direct Payments Engagement Group (DPEG) – Financial Pressures
Youth Homelessness in the North East
Plan your journey.
Jake Atkinson Chief Officer, LRALC
Mike Dailly SHR Board member
IT and Audit Building a Security Aware Culture
CEng progression through the IOM3
WORKSHOP Establish a Communication and Training Plan
Introductions & Icebreaker
Presentation transcript:

Cyber Resilience: Is it a case of preparing for the inevitable? Stephen Baker Chief Executive Suffolk Coastal & Waveney District Councils [SOLACE spokesperson on Emergency Planning and Cyber Resilience]

“…the thing is, it’s probably inevitable that your organisation will suffer some breach, some attack, at some point. Of course, do all you can you prevent it, but also prepare for when it happens…”

What is the threat? Where will it come from? What will it do to my systems, my organisation, my services? What shape or profile will it have, and what will it seek to achieve?

What has happened elsewhere? Several local authorities have suffered attacks Loss of access [for days] Loss of data and historical files [forever?] Impact on services Impact on staff What can I learn from these? There will be breaches we’re not told about

What is the risk? Understand the risk: Responding to the risk issue of scale visibility (different to other threats) recognising change when it happens Responding to the risk Rationalising the threat [am I a target?] Complexity of local systems Vulnerability: understanding ‘why they do it’ our services and users

Environmental Management Electoral Registration Homeless Housing Options NLPG Grants HR / Payroll Building Control Planning Housing Online self service Eco Dev & Regen Land Charges EDMS Corporate Website Intranet CRM Payments Portal Legal CMS Asset Management Environmental Management Licensing Electoral Registration Coastal Management Environmental Health Digital Mapping Committee Admin Revs and Bens Auto Cad Business Analytics Corporate Finance

Can I prevent it? Technical Response Organisational response Management response Leadership response

Response Constraints Other priorities, immediate pressures … Skills, knowledge and experience Lack of understanding/awareness Complexity [partnerships/systems/users] Difficult to quantify the risk Reticence to quantify the impact “Alarm avoidance” (denial!) “Someone else’s issue” (usually ICT!) Political interface

What would the impact be? Immediate disruption to the organisation, services, customer/resident Financial cost Service development and strategic planning Loss of confidence impact on digitisation, both implementation and ambition mindful of user demographic Reputational damage Political dimension

Impact: can we apply a time line? Loss of Confidence Reputation / corporate memory Political Political Political Impact Impact on Digitalisation Service Disruption Strategic Planning Service Development Immediate Long Term

Impact: why would anyone do it? Cause disruption to IT systems Financial gain/personal gain Kudos – ‘because I can’ Curiosity – ‘can I?’ Access to emails between staff … … or access to emails between Leader and Deputy Leader? None of the above

Support System NCSC MHCLG Cabinet Office LGA SOLACE SOCITM LRFs Mutual Aid Suppliers and Partners

Communities and Stakeholders The provider/customer and user relationship Features of an effective digitised service: Security / Accessibility / Transparency …. Community leadership - provision of advice and guidance - how far should support go? Stakeholders: Shared systems Confidence (works both ways)

Do an exercise … test your team A plea to colleagues Do an exercise … test your team

Management Response Take responsibility Recognise the risk Access the skills necessary for adequate defence [ICT, business continuity etc] Train and educate – raise awareness Delegate, but not abdicate “Get real”

Leadership Response Officer role Political role A sustained strategic response Mutual support across agencies/councils etc A common, albeit unknown, enemy Where does the buck stop?

Conclusion Do what we can to reduce our vulnerability Prepare as best we can in case it happens ….let’s hope it’s not inevitable…!