Presentation is loading. Please wait.

Presentation is loading. Please wait.

David Wigley HCC Security Architect Security Trends for 2016.

Similar presentations


Presentation on theme: "David Wigley HCC Security Architect Security Trends for 2016."— Presentation transcript:

1 David Wigley HCC Security Architect Security Trends for 2016

2 Security update Review of 2015

3 Source: PWC report for HM Government

4 42 Undertakings 42 Undertakings 18 Monetary Penalties 18 Monetary Penalties 12 Enforcement Notices 11 Prosecutions Action from the ICO in 2015 Source: ICO website

5 Source: National and Technical Press

6 Source: PWC report for HM Government

7 Human factor Source: PWC report for HM Government

8 2014 123456 password 12345 12345678 qwerty 123456789 1234 baseball dragon football 1234567 monkey letmein abc123 111111 mustang access shadow master michael superman 696969 123123 batman 2015 123456 password 12345678 qwerty 12345 123456789 football 1234 1234567 baseball welcome 1234567890 abc123 111111 1qaz2wsx dragon master monkey letmein login princess qertyuiop solo password starwars Source: SplashData

9

10 Source: PWC report for HM Government

11 1 hour on HPSN2 162M allowed connections from schools 3.9M blocked connections from schools 566 infected web pages blocked 40718 allowed connections to schools 67568 blocked connections to schools Source: HPSN2 monitoring

12 2016 Things to expect

13 Surface web Deep web 4%96% Target personal data Stolen credit or debit card $20 - $35 Bank account login $200 PayPal login $20 - $300 Amazon or Netflix $1 Medical record $350 Source: Technical Press

14 Key user targeted Colleagues identified Fake email sent to target Email passes SPAM filters Target opens fake email Target clicks link or opens attachment Attacker gets in Spear Phishing Attack - Bogus Boss Attack Source: Technical Press

15 Anti-Virus attack Trusted Installed everywhere High privileges on devices Reads everything Sees everything Is controlled by hackers? Source: Technical Press

16 The browser fights back Regular updates Fewer vulnerabilities Phasing out poor encryption for https:// Better visibility of insecure sites Blocking insecure sites Source: Technical Press

17 UK Data Protection Act 1998 EU Data Protection Directive 1995

18 EU Data Protection Regulation 2016 UK Data Protection Act 1998 EU Data Protection Directive 1995

19 Ofsted quote about WCF Online Safety more prominent in the new Ofsted inspection framework

20 Keeping safe Advice and services

21 HCC IT Certified to ISO27001 for Information Security Management HCC Legal Services Schools SLA Advice on Data Protection Law HPSN2 Resilient Internet connection Flexible filtering Next generation firewalling Secure connection to other Schools Not included Protection for 3G/4G Student’s own devices & apps

22 10 Steps to Cyber Security 1.Information governance 2.Secure configuration 3.Network security 4.User privileges 5.User education 6.Incident management 7.Malware protection 8.Monitoring 9.Removable media controls 10.Home and mobile working


Download ppt "David Wigley HCC Security Architect Security Trends for 2016."

Similar presentations


Ads by Google