Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Value of personal information - a cybersecurity perspective

InfoNexus
February 05, 2016
120

Value of personal information - a cybersecurity perspective

Presented by Anton Stiglic, Corporate Director Information Security (CISO) at Loto-Quebec, at InfoNexus 2016 in Montreal, Canada. Visit http://info-nexus.org/ for more detail.

InfoNexus

February 05, 2016
Tweet

Transcript

  1. Anton Stiglic, M.Sc, MBA The Value of Personal Information A

    Cybersecurity Perspective February 2016
  2. 2 Outline • Cyber Threats • Data Breaches in Numbers

    • Value of Stolen Data • Target and TJX Incidents • Hacktivism • Denial of Service Attacks • Recommendations
  3. 3

  4. 5 • Intrusion into a private network leading to a

    data breach – Theft of data transmitted in the network – Theft of documents in fileservers and databases • Insider attacks – Disclosure of specific information • Denial of service and Web defacing – Hacktivism, for political and social reasons
  5. 6 What are the motivations behind cyberattacks ? • Financial

    gain • Political and social activism • Industrial or state espionage
  6. 8 In 92 % of breaches, the attack was initiated

    externally, 55 % of cases, organized crime was involved. 12 % of breaches were initiated internally.
  7. 9 Hacking 52 % Malware 40 % Physical 35 %

    Social engineering 29 % Abuse or errors 13 %
  8. 12 Average per capita cost of a breach 201 $US

    Average customer churn rate after a breach 3,3 %
  9. 14

  10. 16 Value of Data Data Price Social insurance 30 $

    Health insurance 20 $ Visa or MasterCard 4 $ American Express 7 $ Discover credit 8 $ Credit card with magnetic strip « chip data » 12 $ Bank account (balance 70 000 $ to 150 000 $) 300 $ or less Complete identity 1 200 $ to 1 300 $
  11. 19 TJX Breach • Intrusion into their network during an

    18 month period, starting mid 2005 • Data of over 45 million credit cards was stolen • Public announcement on January 2007
  12. 20 TJX Breach • Costs related to the breach: –

    Client assistance (5 $ per call, 20 % would request credit monitoring) • 1240 M$ – Legal advice • 12 M$ per year – Public relations • 3,4 M$ – Internal investigations • 8,1 M$ – Regulatory fines • 1,5 M$ – Class action lawsuits in 41 states • 45 M$ ~ 1,6 milliards $ or 35 $ per credit card holder
  13. 21 TJX Breach 17 January 2007 TJX announces the breach

    Stock price: 14,82 $ 17 January 2008 Stock price: 14,52 $ Sales increase: 4 % S&P 500
  14. 22

  15. 23 Hacktivism The act of hacking, or breaking into a

    computer system, for a politically or socially motivated purpose.
  16. 26

  17. 27

  18. 28