Prepare and Secure Critical Infrastructure for the Future of Digitalization
Télécharger les ressourcesÀ propos de cette session
Tim Nedyalkov, responsable de la sécurité de l'information technologique à la Commonwealth Bank of Australia, présente un modèle en trois phases et neuf étapes pour sécuriser les infrastructures essentielles à l'heure de la convergence des TI et des TO. Il explique d'abord pourquoi le problème est difficile : systèmes hérités conçus sans sécurité, réseaux plats, mots de passe par défaut tirés des manuels du fabricant, accès à distance non gérés, années sans correctifs, criminels indifférents à la cote d'une vulnérabilité. La phase de préparation aligne les parties prenantes sur une mission commune centrée sur la santé, la sécurité et la continuité des procédés, recense les engagements contractuels, réglementaires et calendaires, dresse l'inventaire des actifs avec des schémas réseau vérifiés et une analyse du trafic, et arrime le risque cyber au cadre de gestion des risques existant. La phase de sécurisation traite de la confiance avec les gens d'affaires, de la sensibilisation, de la formation croisée TI-TO, d'un modèle de maturité fondé sur le cadre NIST, de feuilles de route de 12 à 18 mois et de rapports d'une page aux dirigeants. La dernière phase : rester pertinent grâce à des scénarios bâtis sur les incidents des concurrents.
Digitalization is here to stay, and critical infrastructures are not an exception. Even before the pandemic, we have seen an increased number of connected OT systems to the Internet. It leads to no separation of IT & OT networks due to the increase in data, connectivity, complexity and costs. What makes the protection for the digitalization of critical infrastructure complex is the convergence between IT & OT. Threats that commonly impact IT can move between cyber and physical environments. Therefore, cyber security is a key factor for the success of digitalized critical infrastructure. Successful long-term protection includes understanding stakeholder expectations, establishing a core cross-functional engagement model, building a roadmap of strategic initiatives and staying relevant with the latest security threats. The presentation will share key principles and guidelines that I developed and refined over the years working in several industries. The application of the principles has helped prepare and secure critical infrastructure for the future of digitalization holistically and consistently. Session Overview: ● How to set the foundations for the future of digitalized critical infrastructure ● What the key initiatives are, and how to effectively identify and execute them ● How to ensure long-term protection of digitalized critical infrastructure
À retenir
- Amorcer tout mandat de sécurité TO en convenant d'une mission commune avec les parties prenantes (aucun tort à la santé, à la sécurité ou à l'environnement, aucune interruption imprévue, aucune perte de productivité) et évaluer chaque action prévue à cette aune.
- Remettre en question tout schéma réseau de plus de trois ans, lui attribuer un propriétaire et analyser le trafic pour repérer les connexions inattendues, comme un équipement qui accède à Internet.
- Intégrer le risque cyber au cadre de gestion des risques existant (par exemple la matrice 5x5) avec des impacts tangibles sur les opérations, les coûts, la réputation et les relations avec les régulateurs, plutôt qu'une échelle cyber à part.
- Planifier les correctifs en feuilles de route de 12 à 18 mois, exécuter à fond pendant dix mois, puis réévaluer et accepter d'arrêter ou de suspendre ce qui ne livre pas la valeur attendue.
- Faire rapport aux dirigeants en une page ou trois diapositives, alignées sur les cinq fonctions du cadre NIST, et s'en tenir aux faits; l'objectif d'un créneau de cinq minutes au conseil est d'en obtenir davantage la prochaine fois.
Conférenciers
Dr. Tim Nedyalkov brings over 18 years of multi-industry experience in Information Technology and Cyber Security across Europe, the USA, Australia, and the Middle East. He is a Technology Information Security Officer at the Commonwealth Bank of… Lire la suiteRéduire
Dr. Tim Nedyalkov brings over 18 years of multi-industry experience in Information Technology and Cyber Security across Europe, the USA, Australia, and the Middle East. He is a Technology Information Security Officer at the Commonwealth Bank of Australia and Executive Member of the CyberEdBoard Global Community. Most recently, he established the cyber security practice for the $24 Billion Riyadh Metro transport network, one of the world's largest public transport infrastructure projects. He holds a doctorate in Cyber Security/Information Assurance from the University of Fairfax, and a master's in Information Technology Management from the University of Sydney. His certifications include C|CISO, CISSP, CCSP, CEH, CISA, CISM, CRISC, CGEIT, CDPSE, ISO 27001 LA, and Agile PM. Dr. Nedyalkov has been a frequent keynote speaker and panelist at over 30 industry-leading conferences. In addition, he is an active contributor to cyber security industry publications, white papers and community initiatives. He was featured in Top Cyber Magazine, Industrial Cyber, RSA Conference, BankInfoSecurity, InfoRiskToday, and CyberEdBoard Profiles in Leadership. Dr. Nedyalkov has been globally recognized as Cybersecurity Influential Voice and 40 under 40 in Cybersecurity. In addition, he was nominated for the Cyber Security Professional of the Year 2019 in Australia.