8669820477?profile=original

 

Defining The Scope

  • Embedding human security as a part of organization culture
  • Empowering and enabling every individual

 

 

Understanding The Attack Surface & Risks

  • Expansion of attack surface due to merging of official and personal spaces
  • Non-obvious attack surface – IoT, BYOD
  • Agentless malware
  • Spear phishing
  • Management is more vulnerable
  • Identity theft
  • 3rd and Vendor’s people risk
  • APT/Ransomware
  • Insider threats
  • Complacency as a major cause

 

 

Strategies / Principles

  • Getting management alignment …and budget
  • Utilize Training budget
  • Define responsibilities set the KRAs/KPIs
  • Specialized training especially for the top management

 

 

Framework (In PPT)

Parameters include Identify, Protect, Detect, Respond, Recover

8669820852?profile=original

 

Identify

  • Process
    • Identify most vulnerable users and key person
    • Compromise assessment
    • Red teaming with social engineering
    • Take audit and incident inputs
    • Metrics Program
  • Technology
    • Phishing simulating technology
    • Vulnerability/Threat scanning for users, bad domains, spear phishing
    • Regular measurement and reporting

 

Protect

  • DMARC/DKIM/SPF
  • Awareness/Training
  • Anti-APT
  • Anti-Spear phishing solutions
  • MFA

 

 

Detect

  • Detect incidents
  • UEBA/UAM
  • Honeypots/Deception
  • SOC/SIEM
  • Actionable Threat intel (Internal+External)
  • Email security solutions
    • Sandboxing, AI, Threat intel sources, ease of management,Spam filters, Geo-tagging
    • Ease of reporting/Multi channel
  • Web filtering

 

 

Respond & Recover

  • Crisis management training+playbook+simulations
  • Breach reporting and compliance reporting
  • BCP/DR testing
  • IR playbooks specific to human centrics attacks
  • Continuous Backups+resotration
  • Email forensics
  • Compromise assessment
  • Cyber insurance

 

 

Detailed Presentation

 

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (Monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

6 City Round Table On "New Guidelines & CISO Priorities for 2025" (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    We are pleased to invite you to an exclusive roundtable series hosted by CISO Platform in partnership with FireCompass. The roundtable will focus on "New Guidelines & CISO Priorities for 2025"

    Date: December 1st - December 31st 2025

    Venue: Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata

    >> Register Here

  • Created by: Biswajit Banerjee

Fireside Chat With Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.)

  • Description:

    We’re excited to bring you an insightful fireside chat with Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.) and Erik Laird (Vice President - North America, FireCompass). 

    About Sandro:

    Sandro Bucchianeri is an award-winning global cybersecurity leader with over 25…

  • Created by: Biswajit Banerjee
  • Tags: ciso, sandro bucchianeri, nab