Download - Brucon Top5 Ways to Destroy a Company [Brucon]

Transcript
Page 1: Brucon Top5 Ways to Destroy a Company [Brucon]

TOP 5 WAYS TO DESTROY A COMPANY

Page 2: Brucon Top5 Ways to Destroy a Company [Brucon]

I’M CHRIS

Page 3: Brucon Top5 Ways to Destroy a Company [Brucon]
Page 4: Brucon Top5 Ways to Destroy a Company [Brucon]

MY CREDENTIALS

Page 5: Brucon Top5 Ways to Destroy a Company [Brucon]
Page 6: Brucon Top5 Ways to Destroy a Company [Brucon]

Shell doesn’t matter

What do companies care about and how do we know?

Top 5

Born from the Fire

Page 7: Brucon Top5 Ways to Destroy a Company [Brucon]

No one cares about your findings!

Page 8: Brucon Top5 Ways to Destroy a Company [Brucon]
Page 9: Brucon Top5 Ways to Destroy a Company [Brucon]
Page 10: Brucon Top5 Ways to Destroy a Company [Brucon]

HOW WE FEEL ABOUT IT

Page 11: Brucon Top5 Ways to Destroy a Company [Brucon]

HOW THEY FEEL ABOUT IT

Page 12: Brucon Top5 Ways to Destroy a Company [Brucon]

You don’t know… Admit it!

WHAT DO THEY CARE ABOUT?

Page 13: Brucon Top5 Ways to Destroy a Company [Brucon]

THE PRODUCT LINE

Page 14: Brucon Top5 Ways to Destroy a Company [Brucon]

THE BRAND

Page 15: Brucon Top5 Ways to Destroy a Company [Brucon]

THE EMPLOYEES

Page 16: Brucon Top5 Ways to Destroy a Company [Brucon]

THE BOTTOM LINE

Page 17: Brucon Top5 Ways to Destroy a Company [Brucon]

You don’t know… Admit it!

HOW TO FIGURE OUT WHAT IS IMPORTANT

Page 18: Brucon Top5 Ways to Destroy a Company [Brucon]

STEP #1 YOUR OPINION DOESN’T MATTER

Page 19: Brucon Top5 Ways to Destroy a Company [Brucon]

STEP #2 THINK LIKE THEM

Page 20: Brucon Top5 Ways to Destroy a Company [Brucon]

STEP #3: DO WORKYea… this is the boring stuff…but u gotta do it….

Page 21: Brucon Top5 Ways to Destroy a Company [Brucon]

• Information that would be severely damaging to the company and brand.Secret

• Information that would impede or cause significant financial damage to the organization if made public or shared internally.

Confidential

• Information generally available to all or most employees but not approved for general circulation outside the organization

Internal Use Only

• Information approved for general circulation outside the organizationPublic

Page 22: Brucon Top5 Ways to Destroy a Company [Brucon]

Confidentiality

Integrity

Availability

Page 23: Brucon Top5 Ways to Destroy a Company [Brucon]

Criticality

Confidentiality

Integrity

Availability

Page 24: Brucon Top5 Ways to Destroy a Company [Brucon]

Risk Factors

Confidentiality Integrity Availability

Patient Data

Credit card Numbers

Marketing Information

Cash

Cus

tom

er A

sset

s

Page 25: Brucon Top5 Ways to Destroy a Company [Brucon]

Risk Factors

Confidentiality Integrity Availability

Patient Data H H HCredit card Numbers H M MMarketing Information L M LCash L M LC

usto

mer

Ass

ets

Legal/ Compliance/ Financial risk

Inconvenience

Possible Image/Brand Effect

Possible profitability loss

Page 26: Brucon Top5 Ways to Destroy a Company [Brucon]

Risk Factors

Confidentiality Integrity Availability SCORE

Patient Data H H H 5Credit card Numbers H M M 4.3Marketing Information M M L 1.6Cash L M L 1.6C

usto

mer

Ass

ets

HIGH 5

MEDIUM 3

LOW 1

X

X

Changed to H after conversation of how it impacts profitability

Changed to L after conversation of how it was already public information

Page 27: Brucon Top5 Ways to Destroy a Company [Brucon]

But we had to do it to make sure we have a PROCESS to let them tell us what they care about……. Even

when they don’t know what it is…

HOLY CRAP!!! THAT WAS BORING

Page 28: Brucon Top5 Ways to Destroy a Company [Brucon]
Page 29: Brucon Top5 Ways to Destroy a Company [Brucon]

THE TOP 5 WAYS TO DESTROY A COMPANY

• Tarnish the brand

• Alter the Product

• Attack the Employees

• Effect financials directly

• **It’s your turn…**

Page 30: Brucon Top5 Ways to Destroy a Company [Brucon]

TARNISH THE BRANDWhat’s in a name?

Page 31: Brucon Top5 Ways to Destroy a Company [Brucon]

TARNISH THE BRAND (WHAT YOU WILL NEED)

• Understanding of the overall brand values

• Identification of key words used in marketing message

• Knowledge of competitor advantages/disadvantages

• Intelligence profiles on the “Keepers of the Brand”

• Executives

• Key personnel

• Entire Marketing/Design Team

• Reverse engineering of the “go to market” strategy

• Identification of the “Customer Feedback” loop

• Identification of the Market’s “Indicators of Quality” and what drives customers to the “product”

Page 32: Brucon Top5 Ways to Destroy a Company [Brucon]

TARNISH THE BRAND (HOW TO DO IT)• Attack the marketing team

• Compromise the marketing process

• Alter marketing communication

• Alter brand messaging (logo/slogans/tone)

• Extend Marketing deliverable times through deletion, alteration, confusion

• Increase Time to market

• Pollute the customer feedback loop

• Take over the “Indicators of quality” and create

• False issues (product misdirection)

• Negative reviews

• Use by non standard customers

• False company response

Page 33: Brucon Top5 Ways to Destroy a Company [Brucon]

ALTER THE PRODUCTOopse… did I do that?

Page 34: Brucon Top5 Ways to Destroy a Company [Brucon]

ALTER THE PRODUCT(WHAT YOU WILL NEED)

• Complete listing of products (or services) depending on the organization

• Chain of command for product development or service integrity

• Historical review of the products timeline

• Understanding of where alteration can cause

• Degradation of the product quality

• Effect to the consumer

• Direct financial loss

• Physical loss

• General Harm

• Loss of competitive advantage

Page 35: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE PRODUCT (HOW TO DO IT)

VERY Company Specific (examples?!)

#1 The Software Company

• Create bugs

• Make backdoors

• Cause errors in function (What if the calculations of a CRM product are off?)

• Add hidden features into their SVN/Software release cycle

• Remove feature tests or other parts of QA process

Page 36: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE PRODUCT (HOW TO DO IT)

VERY Company Specific (examples?!)

#2 The Hospital/Healthcare business

• Change patient diagnosis or history (like allergies)

• Attack HVAC systems to cause heat into Operating rooms

• Disable critical alert functions for disease control

• Attack crashcarts to disable on the fly patient care and records

• Attack Pyxis and automated narcotic dispensing stations

• Alter patient doses through in line network monitored administration devices.

Page 37: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE PRODUCT (HOW TO DO IT)VERY Company Specific (examples?!)

#3 Manufacturing Company

• Alter the production line/process

• Cause the robots to over spray, weld, install wrong parts, go rogue

• Change formulas

• Speed or slow the line

• Create issues causing the company to fall out of compliance (9001/2 etc..)

• Add or remove features of the product

• Decrease quality

• Break shit..... Like a lot…. I mean… like all of it…. Beyond repair…

Page 38: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE EMPLOYEESTonight…..you!

Page 39: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE EMPLOYEES (WHAT YOU WILL NEED)

• Profile who they are

• Find out where they live

• Figure out what “dangers” they may have at the office ;)

• Can you get them sick (attack scada/water/etc)

• Can you attack them with company property (robots!)

• Do they operate anything that could … fail?

• Do they make things that could be dangerous?

• Can you put them in dangerous situations?

Page 40: Brucon Top5 Ways to Destroy a Company [Brucon]

ATTACK THE EMPLOYEES (HOW TO DO IT)

• Figure out their daily routine then MAKE A KIDNAPPING PROFILE

• Use the company against them

• Food?

• Manufacturing equipment?

• General Terrorism

• Releasing the horde?

• Kill their benefits

• Reduce their pay

• Charge their accounts (amex DOS)

Page 41: Brucon Top5 Ways to Destroy a Company [Brucon]

DIRECTLY EFFECT BOTTOM LINE

All your $$$ are belong to me

Page 42: Brucon Top5 Ways to Destroy a Company [Brucon]

DIRECTLY EFFECT THE BOTTOM LINE (WHAT YOU WILL NEED)

• Understanding of the overall of how they make $

• Identify what systems generate income

• Do they take credit cards?

• Do they have cash?

• Do they have other assets that have $$

• Is there a market for their internal information (CI)

• Is there a secret formula?

• Products that they create

Page 43: Brucon Top5 Ways to Destroy a Company [Brucon]

PROCESS

Figure Out What the Company

Thinks is ImportantSteal It !

DIRECTLY EFFECT THE BOTTOM LINE(HOW TO DO IT)

Page 44: Brucon Top5 Ways to Destroy a Company [Brucon]

YOUR TURNWhat is #5

Page 45: Brucon Top5 Ways to Destroy a Company [Brucon]

TRY AND MAKE THE WORLD BURN

Page 46: Brucon Top5 Ways to Destroy a Company [Brucon]

WHAT ELSE?

Page 47: Brucon Top5 Ways to Destroy a Company [Brucon]

KEEP BEATING THEM DOWN

Page 48: Brucon Top5 Ways to Destroy a Company [Brucon]

WHAT DO WE TAKE AWAY FROM THIS

• Shell doesn’t do anything

• Speak in their language

• Remove white/black hat and DO WORK

• Stop trying to rationalize why you are right…and change the game