Copy of 7 CEO cybersecurity actions

Published on Feb 15, 2016

No Description

PRESENTATION OUTLINE

7 CEO cybersecurity actions

1. implement

a culture of tight cybersecurity

PWC 2015 report

50% of boards see it as an I.T. issue

it's not

It's a CEO issue!

2. Ban

USB thumb drives

too hard?

Department of defense banned them in '07

usb

carry viruses and malware

hard to believe

They still exist

I haven't used

one for 9 years

3. get serious

about passwords

top 7 passwords in 2015

  • 123456
  • password
  • 12345
  • 12345678
  • qwerty
  • 123456789
  • 1234

implement, inspect & enforce

a real password policy

14 Characters

special characters, numbers, Capital letters, etc

change them

at least every 90 days

4. Re-certify

every email account

do it

at least semi-annually

5. mandatory

information assurance training

training may be

unpopular but it's effective

6. track & monitor

software patch implementation

patches

close back doors and provide updates for latest threats

7. limit

access to most sensitive data

why

Did Manning & snowden have so much access?

7 actions

  • Implement cybersecurity culture
  • Ban USBs
  • Get serious about passwords
  • Re-certify email accounts
  • Mandatory information assurance training
  • Track & monitor patches
  • Limit access

Today