This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Your crown jewels aren’t really yours and there’s probably nothing you can do about it…

Download resources

About this session

Victor De Luca, a sales engineer at Zscaler who started his security career in the Canadian Armed Forces, argues that most organizations cannot actually say where their crown jewels live or who controls them. He walks through the standard security cycle of identify, quantify and mitigate, then shows how a shared-responsibility model (illustrated with AWS's own diagram) applies to nearly every asset, not just cloud infrastructure, citing that 85% of US critical infrastructure sits in private hands. A running startup example (DNS registrar, certificate authority, cloud workloads, customer data agreements, SaaS tools, an MSP with admin access) shows how quickly ownership and control fragment. He proposes a four-team response: leadership should prioritize availability, integrity and confidentiality in that order and publish uncomfortable metrics about exposure; IT should inventory assets and map data flows across integrated SaaS tools; legal should embed access, storage and retention clauses into every contract; and security should accept that attack-surface scanning is often impossible on assets they do not own, pursue automated supply-chain security, and cover all seven common exfiltration channels. He closes citing a real case where a backup tool quietly gained access to seven systems through reused credentials.

The term “crown jewels“ originally referred to the jewels, precious gems, and other valuable items that were part of the heritage or possessions of a reigning monarch or sovereign. The term has now been adopted by IT, risk, security, accounting, and finance professionals to describe an organization's most important assets. Organizations worldwide now spend increasing amounts of time and resources to protect their crown jewels. These crown jewels can be anything from a secret recipe (think Coca-Cola, KFC), a very expensive R&D project (SR-71, Manhattan Project), or even an IT system that keeps the business running (ERP, CRM, ITSM, payment system). However, there’s one thing that has evolved over time: crown jewels are increasingly less owned and operated by the organizations themselves. How can that be possible? How can you protect them? Is it legal? We will explore these questions from a management and technical standpoint. Hop in, this will be a fun ride!

Key takeaways

  • Map the shared-responsibility model for every asset, not just cloud infrastructure; contractors, MSPs and SaaS vendors all carry pieces of control over your crown jewels.
  • Publish uncomfortable exposure metrics to leadership (percentage of crown jewels hosted outside your environment, number of contractors with access) rather than a clean status report.
  • Build an inventory that records asset type, hosting location, data owner and who has access, since 'who has access' is usually the least understood variable.
  • Embed data-handling clauses (who can access it, where it is stored, when it must be deleted) into every vendor and MSP contract; legal is often left out of this work.
  • Cover all seven common exfiltration channels, web, email, SaaS, IaaS, private applications, endpoint and BYOD, since attack-surface scanning frequently cannot reach assets you do not directly own.

Speakers

Victor De Luca
Victor De Luca
Sales Engineer · Zscaler
Having started his career in the Canadian Armed Forces, Victor has worked in the security field for over 10 years and has specialized in information security for the last 8. He holds an M.Eng. in cybersecurity and an MBA. In the private sector, he… Read moreRead less

Having started his career in the Canadian Armed Forces, Victor has worked in the security field for over 10 years and has specialized in information security for the last 8. He holds an M.Eng. in cybersecurity and an MBA. In the private sector, he has assisted numerous organizations in recovering from information breaches and improving their internal controls to reduce information leakage. Victor is primarily focused on helping organizations protect critical systems and sensitive information from attackers. In his spare time, Victor enjoys writing blog posts on Medium and learning about new technologies.

Resources

Tags

More from GoSec 2024

Also from Victor De Luca

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.