0% found this document useful (0 votes)
4 views30 pages

Cybersecurity Strategies and Insights

The CyberSecurity presentation on April 16th, 2024, emphasizes the importance of creating a safe and interactive environment for discussing cyber threats and solutions. It covers various aspects of cyber security, including common causes of data breaches, ethical hacking, and the significance of a defense-in-depth approach. Key takeaways highlight the inevitability of cyberattacks, the need for preparedness, and the role of transparency and training in enhancing organizational resilience.

Uploaded by

muitjosias25
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views30 pages

Cybersecurity Strategies and Insights

The CyberSecurity presentation on April 16th, 2024, emphasizes the importance of creating a safe and interactive environment for discussing cyber threats and solutions. It covers various aspects of cyber security, including common causes of data breaches, ethical hacking, and the significance of a defense-in-depth approach. Key takeaways highlight the inevitability of cyberattacks, the need for preparedness, and the role of transparency and training in enhancing organizational resilience.

Uploaded by

muitjosias25
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CyberSecurity presentation

April 16th 2024


Let’s Get to know each other
DegroofPetercam in some figures
The rules of the game

• Setup a Safe environment


• Stay mentally and physically present
• Let’s make it interactive – Let’s make it fun J
• Share ideas & ask questions
• There will be difference in opinions
• Attack the problem not the person
• Share your experience (not the others)
• Be free to speak minds without fear of reprisal Join at
[Link]
#9882785
Realtime cyberAttacks

[Link]
cyberAttacks domains

Question:

Lorsque j'entends le mot "CyberSecurity", je pense directement à ...

Join at
[Link]
#9882785
Reponses des etudiants
Frameworks & Standards
cyberSecurity is not only about technology

Cyber security refers to every aspect of protecting an organization and its employees
and assets against cyber threats. As cyberattacks become more common and
sophisticated and corporate networks grow more complex, a variety of cyber security
solutions are required to mitigate corporate cyber risk.
This is called “Defense-in-depth”
Common causes of data breaches

[Link] & co (Vishing, SMShing, ...) [Link] (Lock bit 3.0)


[Link] passwords [Link] systems (Log4j)
[Link] [Link] stuffing (click)
[Link] Application Development [Link] chain vulnerabilities (Juniper)
[Link] threats [Link] persistent threats
Phishing emails
Time it takes a hacker to brute force your password

2023

Sources: [Link]
Vulnerability management: Patch Management
Patch management is the process of distributing and applying updates to software. These patches are often necessary to
correct errors in the software. This process has several add value for the organization:
Security improvement – System Uptime – Compliance – features improvements
Defense in depth approach

Cyber security refers to every


aspect of protecting an
organization and its employees
and assets against cyber threats.
As cyberattacks become more
common and sophisticated and
corporate networks grow more
complex, a variety of cyber
security solutions are required to
mitigate corporate cyber risk.
This is called “Defense-in-depth”
cyberAttacks domains

Question:

Lorsque j'entends parler de Redteam ou Pentesting, je pense à ...?

Join at
[Link]
#9882785
Reponses des etudiants
Ethical Hacking – Pentesting vs Redteam
Ethical Hacking – Kill Chain
Ethical Hacking – Redteam vs Blue Team vs Purple team
Ethical Hacking – Redteam Toolings

LAN Turtle USB Rubber Ducky

Proxmark 3, RFID copier

Raspberry Pi

Wifi PineApple
Flipper zero
A Demo right after ?

Join at
[Link]
#9882785
Ethical Hacking – European Tiber framework

The Red Team’s work is structured in three main phases: an analytical phase, a preparatory phase, and, finally, an implementation phase.
• Analysis of Tactical threat intelligence
• Scenario preparation and development
• Execution of the developed plans
The execution of attacks is the keystone of the Red Team’s work in the development of tests under a TIBER-EU scheme. The objective is to
simulate attack scenarios in which the tactics, techniques, and procedures (TTPs) that are used in real cyber-incidents are captured.
Ethical Hacking – European Tiber framework
Prevent ?
Prevent ?
Detect ?
Prevent ? Detect ? Logged ?
Detect ? Logged ? Blind ?
Logged ? Blind ?
Blind ?

Prevent ? Prevent ? Prevent ?


Detect ? Detect ? Detect ?
Logged ? Logged ? Logged ?
Blind ? Blind ? Blind ?

The Red Team’s work is structured in three main phases: an analytical phase, a preparatory phase, and, finally, an implementation phase.
• Analysis of Tactical threat intelligence
• Scenario preparation and development
• Execution of the developed plans
The execution of attacks is the keystone of the Red Team’s work in the development of tests under a TIBER-EU scheme. The objective is to
simulate attack scenarios in which the tactics, techniques, and procedures (TTPs) that are used in real cyber-incidents are captured.
Ethical Hacking – Bug Bounty

A bug bounty program allows ethical hackers to test your company’s web
applications, enterprise infrastructure, and other digital assets for security
vulnerabilities – often for a financial reward. This modern approach to
cybersecurity has numerous advantages.
Platforms to learn Ethical Hacking

Never try to hack without authorization : Let’s remain Ethical!!!


§ Vulnhub
Key takeaways
Every organization will suffer from a CyberAttack: As a CyberSecurity Specialist, try to f ind your own way:

• It’s a matter of time • Cybersecurity cannot be dissociated from passion


• Mature companies rely more than ever on the defense-in-depth • Certification is not the most important information on a CV
• Increase visibility: You cannot protect what you don’t know • Practice what you have learned (real life use cases)
• Segment your network to contain cyberattack • Avoid Job hopping, build trust around you
• Invest in AI based technology to predict & mitigate Cyber Attacks • Be 100% transparent in your comm towards your Mgt
• Get prepared, • Keep in mind the Vision of the company
• Train the teams & the senior management with crisis Management • You are a business enabler not the FBI
exercises • Choose your battles & find the right balance between
• Perform regular Disaster recovery Plans
• Isolate from human access & Test your backup very frequently
User Experience
Remain cyber resilience !!!
Cyber resilience is a matter of smart business and avoiding disasters. We
read and hear a lot about it but as long it never happened to your business,
you are safe. WRONG! Some business that are being attacked are not able
to recover from it. The damage behind an attack can affect your entire
business.
This is something your business should not be able to recover from it, in the
first place it needs to prevent it. Attacks should not even get the chance to
enter your business. And that’s where cyber resilience can assist your
business with. Security Operation
Last but not Least: try to have FUN !!!
Question ?

Join at
[Link]
#9882785

You might also like