Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De...

13
Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1

Transcript of Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De...

Page 1: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

Hit by a Cyberattack

Lessons “Learned”

Miguel De Bruycker

1

Page 2: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

Introduction

• Belgian Defence 2006 Cyber Defence project

– Protect, Detect & Respond

• Expertise

– Malware detection

– Malware analysis

– Incident handling

2

Page 3: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

3

For some networks you

Need “more security”

Page 4: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

“More” security?

• “Good” security, but sexy

• Long time undetected

– AV is good, but…

• “Strong” Counterparts

4

Page 5: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

5

The CEO handles the incident

Page 6: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

“We” take care of this

• Management makes decisions

• Evaluate the risks fast

• Bring in “real” experts

• Your ICT get the fame

6

Page 7: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

7

Talk about it …

When the time is right

Page 8: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

Communication plan

• Control your communication• Involve Legal

– File a complaint?– Maintain a list– Make liable– Prepare a clear message

• Share IOC ?

8

Page 9: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

Diagnosis?

• Identification• Diagnosis• Intervention

– Narcosis– Surgery– Wake up

• Recover• Follow up

Silent (no media, no action)

Protect forensics & evidence

Plan clean up, communication, post Ops

Counterpart will try

(Steal last crown jewels)

Erase all traces

Install backdoor

Page 10: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

10

It’s better to detect yourself

Page 11: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

All intrusions leave traces

• Monitor (do it, check it)

– Install IDS

– Log & check

– Detect at the first stage

– But protection = step 1

• Periodic Board Report

• Have IH procedures

11

Page 12: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

12

There are seldom lessons “learned”

We mostly have lessons “Identified”

Page 13: Hit by a Cyberattack Lessons “Learned”...Hit by a Cyberattack Lessons “Learned” Miguel De Bruycker 1 Introduction •Belgian Defence 2006 Cyber Defence project –Protect,

THANK YOU

Miguel De Bruycker

13