Strategies to raise the level of awareness in the …...Alerts Specialized training Information...

25
Cabecera aquí Strategies to raise the level of awareness in the health sector Marco Antonio Lozano Merino @marcoalome

Transcript of Strategies to raise the level of awareness in the …...Alerts Specialized training Information...

Page 1: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Cabecera aquí

Strategies to raise the level of

awareness in thehealth sector

Marco Antonio Lozano Merino@marcoalome

Page 2: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

What is INCIBE (Spanish National Cybersecurity Institute)?

Reference entity for the

development of cybersecurity

and the didital confidence of: CitizensCompanies, especially

strategic sectors

Commercial State Company attached to the Ministry of Economy and Business

throught the Secretary of State for Digital Advancement, which leads different actions

for cybersecurity at national and international level.

Page 3: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

What do we do?

Promotion of industry,

R+D+i and talent

Public servicesCybersecurity

• Development of Cybersecurity Technologies• Intelligence in cyberspace• Industrial Control Systems and cybersecurity

• National industry development• Promotion R+D+i• Promotion and identification of talent

• Detection, analysis and response to cyberattacks• Cybersecurity awareness raising

Development ofCybersecurityTechnologies

Page 4: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses
Page 5: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

INCIBE-CERT: services for ICT and cybersecurity professionals

https://www.incibe-cert.es

Alerts Specializedtraining

IncidentsInformation

Security advisories, ICS advisories, vulnerabilities and alert level

Courses of ICS cybersecurity, mobile devices,

basic/advanced for spanishlaw enforcement…

Competent institution in incident resolution for citizens

and companies in Spain

Blogs, guides, studiesand cybersecurity

highlights

Page 6: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Protege tu Empresa: cybersecurity for SMEs

INFORMACIÓN HERRAMIENTAS FORMACIÓN ATENCIÓN A LA PYME

Training ToolsAttention to theentrepreneur

Information

Blogs, newsletters,what are you interested

in?,security advisories

Cybersecurity helpline: 900 116 117, contact form to solve

questions about services and cybersecurity issues, fraud

report

https://www.incibe.es/protege-tu-empresa

Cybersecurity for SMEs, sectorial training videos, rol game,

awareness raising kit, Hackendserious game, guides, workshops,

and online MOOC formicroenterprises and freelancers

Antibotnet service, GDPR, antiransomware service,

catalogue of solutions, riskself-diagnosis tool, company

policies, and trust seals

Page 7: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

INCIBE-CERT: competent CERT for private companies and citizens

• Royal Decree-Law 12/2018, 7 September 2018, Network and Information systems Security, published on 8 September 2018 in the Official State Gazette, establishes INCIBE-CERT as the CSIRT of reference for citizens, private law entities and communities that do not belong to the scope of action of CCN-CERT.

• In case of incident management involving critical private sector operators, INCIBE-CERT is jointly operated by INCIBE and CNPIC.

Page 8: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Collaboration with other entities and CERTs• INCIBE is a member of the main national and international cybersecurity forums and

working groups, actively collaborating with strategic actors that deal with different aspects of cybersecurity, such as incident response, information exchange, awareness raising, policy development or the promotion of standardization, among others.

Page 9: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

What is essential about cybersecurity in the health sector?

Page 10: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Do you know any cases? (I)

Page 11: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Do you know any cases? (II)

Page 12: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

SECURITY BY DEFAULT

Page 13: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Vulnerabilities in medical devices?

Page 14: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

EMPLOYEES, THE MOST IMPORTANT PIECES IN CYBERSECURITY

Page 15: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

• Cybersecurity is a key factor for building trust and for the success of any organization.

• People are the most important pieces and the weakest link.

• Cybersecurity will require a high degree of commitment from people.

Page 16: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Strategies of INCIBE to help us raise our awareness level

Page 17: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Awareness kitSelf-diagnostic tool (ADL)

Interactive itinerariesHackend, game over

MOOC for SMEs and self-employedContact form and helpline

Page 18: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Awareness kit

Page 19: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Self-diagnostic tool (ADL)

https://adl.incibe.es

Page 20: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Interactive itineraries

Page 21: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Hackend, game over

Page 22: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

MOOC for SMEs and self-employed

Page 23: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Cybersecurity helpline

Page 24: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

ANY QUESTIONS?

Page 25: Strategies to raise the level of awareness in the …...Alerts Specialized training Information Incidents Security advisories, ICS advisories, vulnerabilities and alert level Courses

Follow us…

https://www.incibe.es/ Social networks