This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

A Crash Course in Getting Your Cybersecurity Right in 2021

Download resources

About this session

Greg Young, vice-president of cybersecurity at Trend Micro and former Gartner analyst, lays out what security teams should actually do in 2021, arguing that plans beyond a twelve-month horizon are rarely actionable. His main point is that the unexciting wins: over 99 percent of exploited vulnerabilities are old, already-patched ones (the most-used in 2019 dated from 2004), so discovering and patching forgotten systems beats hunting zero-days. He reads the Bitcoin price as a predictor of whether crypto-mining or ransomware will dominate, notes that security budgets range from 18 percent of IT spend in banking to 1 percent in manufacturing and that attackers know it, and urges organisations to unload staff before loading them with new tools given the talent shortage. Other themes include the CISO shifting from operator to overseer, multi-cloud as the new normal with IPS blind spots at cloud providers, one dollar in six of IT spend happening outside the CIO organisation, forged barcodes on used medical equipment, and gluing silos together with XDR. He closes with seven takeaways, starting with patch and back up.

In this session, we will take a look at the current real threatscape, consider the cybersecurity challenges and decisions every company needs to face head-on this year as they prepare for next year. He provides 7 clear takeaways that include spending, staffing, multicloud, XDR, and IoT. 

Key takeaways

  • Spend the bulk of effort on discovering and patching known, years-old vulnerabilities across IoT, OT and home devices; shield with IPS signatures where patching is impossible.
  • Benchmark security spend against your vertical (banking near 18 percent of IT, manufacturing near 1 percent) and build the budget case either way.
  • Before adding any new tool to the SOC, decide which task you will remove or automate; do not patch gaps with people.
  • Go find shadow IT and cloud spend in the business units, offer to monitor it with your tools rather than shut it down, then use the finding to justify budget.
  • Move the CISO into oversight of operational groups, and start bridging adjacent silos (sandbox and IPS, firewall and IPS) before attempting full XDR integration.

Speakers

Greg Young
Greg Young
VP Cybersecurity and CorpDev, · Trend Micro
Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of… Read moreRead less

Greg Young is the Vice President of Cybersecurity and Corp Dev for Trend Micro. He has over 35 years of experience in cybersecurity. Greg was a Research Vice President and analyst with Gartner for 13 years, CISO for the Federal Department of Communications, Chief Security Architect for a security product company, headed several large security consulting practices, and as Captain Young served in the military police and counterintelligence branch. Greg received the Confederation Medal from the Governor General of Canada for his work with smart card security. He currently is: Member and former co-chair for the federal government’s Forum on Digital infrastructure Resilience (CFDIR), and a member of the AI Working Group, and the Supply Chain Resilience Working Group, on the federal National Cross Sectoral Forum (NCSF) for Critical Infrastructure, appointed by cabinet of the Government of Barbados as a member of their Cybersecurity Working Group, liaison to the Canadian Security Telecommunications Advisory Committee (CSTAC).

Resources

Tags

More from GoSec 2020

Also from Greg Young

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.