Presentation for the 2016 National and Chapter Leadership Conference by Bill Murphy

Preview:

Citation preview

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Sponsored By

2016 National and Chapter Leadership ConferenceS e p t e m b e r 2 5 – 2 7 , 2 0 1 6

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Cybersecurity and Protecting Construction Data

By Bill Murphy,President and CEO,

RedZone Technologies

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

•Bill Murphy Short BIO RedZone Technologies: Entrepreneur started and currently manage 4 Companies. Three in Enterprise IT Security. IT Sec

Assessments, Building Roadmaps, Action & Remediation Plans, Helping IT Sec Leaders and their teams with raw tactical execution, risk, governance and corporate Boards.

SU Wash DC Chapter Ambassador – Teach leaders how to leverage Exponential Technologies to help solve Global Grand Challenges. Enterprise, Startups, Associations, Govt

Sept 29th Virtual Reality Salon CIO ExO Leader Mastermind Lean startup methods, experimentation, hands on testing. Recently Published

Downloadable white paper: Win IT Security Conversations in the Boardroom. CIO Review: CIO Driven Innovation Starts with a Strong Security Posture. CIO Today: How to Win the Boardroom Conversation on Security

Linkedin My Blog Podcast Twitter

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Who I am

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Who I am

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored Bywww.redzonetech.net

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

CIO Masterminds (16+Years)

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

I interview leaders who inspire me in the areas of Exponential Technologies, Business Innovation, Entrepreneurship, Thought Leadership, Enterprise IT Security, Neuroscience, Philosophy, Personal Development, and more.

Bill Murphy’s RedZone PODCAST

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Singularity University

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Winning the IT Security Conversation in the Boardroom

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Fara Francis

Cyber threat has ushered in a heightened sense of security for CEOs and their IT leaders as they partner to deliver processes and procedures to protect their business environment. For the construction industry, it is critical that cybersecurity is addressed, since an attack could mean – significant delays in business operations and consequently delays in delivering on work to our customers. Cybersecurity should be a business and strategic concern, not just an IT concern. This session presented by a security expert, will provide timely information on this important topic and the tools necessary for protecting your business environment.

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

• How to invest in IT security areas that matter versus throwing money at products alone• What employee training has the most significant positive impact on cyber security

posture• How you develop longer term investment roadmaps for it security spending• How to talk to the COO, CFO, CEO and Board so they will understand.• Review how to present to the business and what visualization methods have the best

impact.• Review what types of data present the highest risk to a contractor• How to turn cyber security into a competitive advantage in the bidding process.• How to have risk based conversations that a business person can understand• Renting IT Security Outcomes – Ways to avoid hiring the W2 position when you can

obtain the same outcome by renting the tools and expertise you need

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Strategy versus Tactics

Offense versus Defense

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Where you are today?

Where you want to be in the Future?

What kinds of Risk do you want to absorb?

DEFENSE

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored ByRedZone Confidential

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored ByRedZone Confidential

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Security Defense StrategyWhack-a-Mole?! …NO!

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Could you recover from a Crypto-locker Malware?

When does IT Security become strategic for you?

When does IT Security become Disaster Recovery?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

1. How to talk to the COO, CFO, CEO, and Board so they will understand? (Common Language)

2. How to present to the business and what visualization methods have the best impact?

3. How to have a risk-based conversations a business person can understand?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

• Debits and Credits• Income Statement and Balance Sheet

COMMON LANGUAGE of BUSINESS

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Does your VP of Sales guarantee revenue?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Audit/Compliance

Regulators/Regulations

FFIEC, PCI, DoD,HIPPA, etc

Standards

Staff

GARTNER -Eg

Vendors

Consultants

CSO

CIO/CSOCEO

CFO

CEO

Winning the IT Security Conversation in the Boardroom

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

CFO & CEO & Board Confidence what do they expect?

Debits, credits, AICPA Standards, GAP Principles

Controller& Accounting Manager

Audits, SOX, Sarbanes, etc

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

The Role of Transparency

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Frameworks

• What happens when you lose your CFO or Accounting Manager?

Versus

• What happens when you lose your CIO, CISO, VP IT, Manager IT, etc

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Governance and Risk

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Security Portfolio & Risk Balance

Investment Cost $

Breach Costs

Minutes Months

Optimal

RedZone Confidential

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Premiums to Mitigate Risk

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

When you spend a $ What boats are effected?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

EXECUTION PLAN – IT ROADMAP - PRIORITIZATION

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Demonstrate ActionBalanceInvestment OptionsAnalysisOverlapping TechnologiesMove Away from Top 10 ListsDemonstrate Strategy

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

OFFENSE VERSUS DEFENSE

How to invest in IT Security areas that matter vs. throwing money at products alone?

How do you develop long-term investment roadmaps for IT Security spending?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

RedZone Technologies Slide Here

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Where Did It Begin for Me?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

IT Security Strategy is all about managing risk?

How Many of you approach IT Security from a Risk Perspective?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Cutting Corners?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Do you have the right tools?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Short Shovel vs Long Shovel

Getting things done for a little effort?Waste of time?Worker laziness?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Bury Stumps to Save Money ?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

IT Security Governance

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Is the (Compliance and Audit) Tail Wagging the Dog?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Digitization of Everything

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Protect plans for government and critical infrastructure building

Telecom, Dams, Bridges, Army, Airforce, City, Town, etc

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

BIM SLIDE

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

• Blueprint + Autocad files edit numbers to make security weak spots• Competition? • Bids and proposals• Offshore pitches of cheaper materials + systems with backdoors

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Employee Data Security

The Personnel Certifications Database

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Regulations

PII

HIPPA

DoD

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

HR + Training

What employee training has the most significant positive impact on cyber security posture?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

“In the absence of security education orexperience, people (employees, users,

customers, …) naturally make poor security

decisions with technology” - Hugh Thompson, RSA Conf 2013

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

IT Staff vs Entire company as a security partner

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

• Complexity knot

• Growth of Data (BIM)/ Big Data

• IoT

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Contracts Requirements

DOD, Federal, Government – almost all have security clauses in contract

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

ARE YOU A THIRD PARTY RISK TO SOMEONE?

What types of data present the highest risk to a contractor?Who are you a third party to?

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Exponential Technology and IT Security

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

OFFENSE

• How to turn cybersecurity into a strategic and competitive advantage in the bidding process? • Keep unnecessary costs down• Proves to Primes that you have your act together

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

Sponsored By

Data Governance

BYOD, Dropbox Replacement, Private Filesynch, workflow, collaboration, high availability,

disaster recovery and privacy.

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

ACTIONABLE THINGS YOU CAN DO NOW• How to measure risk and address the question why/ if a business person should

care?

• Renting IT Security Outcomes- Ways to avoid hiring the W2 position when you can obtain the same outcome by renting tools and expertise you need.

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

2016 National and Chapter Leadership Conference | Washington, D.C.

Sponsored By

• Notes (from call with Fara)Session : 1:15 -2:15pm

• Downloads

• Q&A

Catalyst+Spark

-”C” Suite Conversation

- Members etc

- Training Employees

- Chapter Leaders

- 100 Leaders – Breakout

- IoT devices complexity

- Cyber Security Plan

Avoid Technical Education

CEO or Chapter Leaders – Board Members: Risk Measuring

Groundwork:

a. What is Cybersecurity?

b. What is important for addressing IT baseline

c. Construction

Recommendation:

1. as a part of B vs. … ;

2. Scorecard

Recommended