Security: more important than ever - Sophos Day Belux 2014

55
1 Analyzing and rethinking security Jorn Lutters, Pre - Sales Engineer for Sophos Security: More important than ever.

Transcript of Security: more important than ever - Sophos Day Belux 2014

Page 1: Security: more important than ever - Sophos Day Belux 2014

1

Analyzing and rethinking securityJorn Lutters, Pre-Sales Engineer for Sophos

Security: More important than ever.

Page 2: Security: more important than ever - Sophos Day Belux 2014

22

Threat trendsand 2014 notable cases

Page 3: Security: more important than ever - Sophos Day Belux 2014

3

Page 4: Security: more important than ever - Sophos Day Belux 2014

4

Page 5: Security: more important than ever - Sophos Day Belux 2014

5

Page 6: Security: more important than ever - Sophos Day Belux 2014

6

Page 7: Security: more important than ever - Sophos Day Belux 2014

7

Page 8: Security: more important than ever - Sophos Day Belux 2014

8

Page 9: Security: more important than ever - Sophos Day Belux 2014

9

Page 10: Security: more important than ever - Sophos Day Belux 2014

10

Page 11: Security: more important than ever - Sophos Day Belux 2014

11

Page 12: Security: more important than ever - Sophos Day Belux 2014

12

42.8 million

Security incidents detected per year.

© PWC Information Security Survey 2015

117,339incoming attacks per day, every day –roughly 1,5 per second

Page 13: Security: more important than ever - Sophos Day Belux 2014

13

MalvertisementsLegitimate websites serving malware

30,000Infections per hour –just for Yahoo alone.That’s roughly 8 computers per second

225%Increase in popularity in 2014 - currently 1 in 5 add providers are compromised

Page 14: Security: more important than ever - Sophos Day Belux 2014

14

Professionalism, Crimeware“Monetization”: Bulk of Threats Are Automated, Coordinated & Professional

50% 75% 88%

Welcome to the Age of Personalized Malware

50% of our detections are based on only 19 malware identities.

75% of unique pieces of malware are targeted attacks (i.e., are not seen beyond the organization targeted).

88% of malware found in fewer than 10 other organizations.

Page 15: Security: more important than ever - Sophos Day Belux 2014

1515

Let’s talk about security

Page 16: Security: more important than ever - Sophos Day Belux 2014

16

Page 17: Security: more important than ever - Sophos Day Belux 2014

1717

Problem 1:

Complexity

Page 18: Security: more important than ever - Sophos Day Belux 2014

18

Page 19: Security: more important than ever - Sophos Day Belux 2014

19

Page 20: Security: more important than ever - Sophos Day Belux 2014

2020

Problem 2:

Security overlap(Compatibility issues)

Page 21: Security: more important than ever - Sophos Day Belux 2014

21

Page 22: Security: more important than ever - Sophos Day Belux 2014

22

Page 23: Security: more important than ever - Sophos Day Belux 2014

2323

Problem 3:

Mind the gap

Page 24: Security: more important than ever - Sophos Day Belux 2014

24

Page 25: Security: more important than ever - Sophos Day Belux 2014

25

Solution A Solution B

Solution C

You are here

Page 26: Security: more important than ever - Sophos Day Belux 2014

2626

Problem 4:

Segmentation

Page 27: Security: more important than ever - Sophos Day Belux 2014

27

Page 28: Security: more important than ever - Sophos Day Belux 2014

28

Page 29: Security: more important than ever - Sophos Day Belux 2014

2929

Problem 5:

Defense in depth

Page 30: Security: more important than ever - Sophos Day Belux 2014

30

Page 31: Security: more important than ever - Sophos Day Belux 2014

31

Page 32: Security: more important than ever - Sophos Day Belux 2014

32

Page 33: Security: more important than ever - Sophos Day Belux 2014

33

Page 34: Security: more important than ever - Sophos Day Belux 2014

3434

SophosSimpleSecurity

Page 35: Security: more important than ever - Sophos Day Belux 2014

35

0 13

8

50

.0

10.0

20.0

30.0

40.0

50.0

60.0

100-499Employees

500-999Employees

1000-4,999Employees

5000-19,999Employees

20,000+Employees

Sophos’ core customers

Challenged by ComplexityLimited by Resources

Page 36: Security: more important than ever - Sophos Day Belux 2014

36

Corporate Owned and

BYOD

Protect My Data

Go Wireless

Users Are Everywhere

What About Securing My

Servers?

Can’t Control Users via

Brute Force

Downtime Unacceptable

“Console Proliferation”

& “Agent Pollution”

Transition to the Cloud

Regulations & Compliance

Help Desk Queries

Page 37: Security: more important than ever - Sophos Day Belux 2014

37

Corporate Owned and

BYOD

Protect My Data

Go Wireless

Users Are Everywhere

What About Securing My

Servers?

Can’t Control Users via

Brute Force

Downtime Unacceptable

“Console Proliferation”

& “Agent Pollution”

Transition to the Cloud

Regulations & Compliance

Help Desk Queries

New Attack Surfaces

(Android, iOS)

250,000 New Threats Will

Appear Today

Polymorphic Threats Affect

Everyone

Macs Are No Longer

Immune

Not Just A “Big Company” Problem

IT Systems Are The Lifeblood

for Any Size Org

Page 38: Security: more important than ever - Sophos Day Belux 2014

3838

Sophos CompleteSecurity

Anti-spam

BYOD solution

Anti-malware

Usage policies

Security Management

Firewall

Encryption

Page 39: Security: more important than ever - Sophos Day Belux 2014

39

Complete Security…

Made Simple.

Network End Users and DevicesServers

Simple Deployment Simple Protection Simple Management

• On premise• Virtual• Cloud• User self provision

• Active Protection – real-time protection powered by SophosLabs

• Live lookups via the Cloud• SophosLabs experts tune the

protection so you don’t have to

Next GenFirewall

Anti-malware and IPS

URLFiltering

NetworkAccess Control

Wireless VPN Anti-Spam EmailEncryption

Anti-Malware

Mobile Encryption PatchAssessment

Application Control

Device Control

Encryption for Cloud

Endpoint WebProtection

Anti-Malware

Webserver Protection

Virtualization

Intuitive consoles: On Premise or

From the Cloud

Backed by expert support

App Control

V-Shield

Page 40: Security: more important than ever - Sophos Day Belux 2014

40

AT HOME AND ON THE MOVE

Mobile Control Endpoint SecuritySafeGuard Encryption

HEADQUARTERS

Endpoint SecuritySafeGuard Encryption

REMOTE OFFICE 1

NextGen Firewall

Secure Wi-Fi

Endpoint SecuritySafeGuard Encryption

Secure Wi-Fi

Secure VPN Client

Mobile Control

Reputation Data • Active Protection SophosLabs Correlated intelligence • Content Classification

Administration

SOPHOS CLOUD

Web Application Firewall

Secure Email Gateway

Secure Web Gateway

Mobile Control

Network Storage AntivirusServer Security

Guest Wi-Fi

UTMNextGen Firewall

Secure Web GatewaySecure Email Gateway

Web Application Firewall

REMOTE OFFICE 2

Secure Wi-Fi

Endpoint SecuritySafeGuard Encryption

Mobile Control

Secure VPN RED

Page 41: Security: more important than ever - Sophos Day Belux 2014

42

HEADQUARTERS

AT HOME

ON THE MOVE

SAMPLES

TELEMETRY

HONEY POTS

HUMAN DECISION MAKING

AUTOMATED LEARNING& AUTOMATION

BIG DATA

ANALYTICSDynamic & Static

SOPHOSLABS

REMOTE OFFICE

Page 42: Security: more important than ever - Sophos Day Belux 2014

43

SophosLabsActive Protection

Malware Data

Website URL Database

HIPS Rules

Reputation Data

MaliciousURLs

Spam Campaigns

Sensitive Data Types

Application Categories

Device Data

Mobile Application Reputation

Anonymizing Proxies

Application Patches

Network Servers Devices

Web EmailNextGen FW

Web App FW

Wifi

Smartphone/Tablet

Workstation/Laptop

Data

Correlated Intelligence

Reputation Data

Content Classification

File

Web

Email

Page 43: Security: more important than ever - Sophos Day Belux 2014

44

Page 44: Security: more important than ever - Sophos Day Belux 2014

45

EFFECTIVENESS

USA

BIL

ITY

“INTEGRATED”PRODUCT

PORTFOLIO

COMPLETE SECURITY

INTEGRATION

POINT SOLUTION

Page 45: Security: more important than ever - Sophos Day Belux 2014

46

“Complex solutions aren’t solutions. We make security for the real world – for the pragmatic enterprise. Simple security is better security.”

Kris Hagerman, CEO Sophos

Page 46: Security: more important than ever - Sophos Day Belux 2014

47

Page 47: Security: more important than ever - Sophos Day Belux 2014

4848

Why they should’ve gone for Sophos

Recent cases and how Sophos can help prevent disaster

Page 48: Security: more important than ever - Sophos Day Belux 2014

49

Page 49: Security: more important than ever - Sophos Day Belux 2014

50

Page 50: Security: more important than ever - Sophos Day Belux 2014

51

SECand UTM Advanced Threat Protection

C&C ServerURL Database

Command & Control Server

Check URL

Contact C&C server

C&CBlock

File checksum

suspicious

Analyze

SXLSend file

Pattern

ATP

IPS

Webproxy

DNS

IP tables

AFC

Page 51: Security: more important than ever - Sophos Day Belux 2014

52

Page 52: Security: more important than ever - Sophos Day Belux 2014

53

SMCand Mobile Encryption

Page 53: Security: more important than ever - Sophos Day Belux 2014

54

Page 54: Security: more important than ever - Sophos Day Belux 2014

55

DLPmet Safeguard encryptie

Page 55: Security: more important than ever - Sophos Day Belux 2014

56© Sophos Ltd. All rights reserved.