Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Protecting your people

Protecting your people

Presented by Laura Bell (SafeStack) at AUSCERT 2015, Gold Coast (Australia)

Laura Bell

June 03, 2015
Tweet

More Decks by Laura Bell

Other Decks in Technology

Transcript

  1. Security awareness • So we teach? • Who do we

    teach? • What is the message? Security Awareness Education
  2. 1. Learning styles are ignored 2. Teaching outside of the

    work environment 3. Lack of reinforcement to build habit and behaviours 4. Lack of measurement 5. Lack of context
  3. Phish 5 • Good start • Online service • Phishing

    attack simulator Outsourced phishing programmes
  4. Location Time stamps Sender Receiver User agent friends contacts frequency

    aliases profiles Last login Traffic rate Pw Expires? Disabled? Influence
  5. Email attacks that go beyond phishing Email phishing Internal request

    social panic Direct request External request favour authoritative
  6. The URL may be different on different messages. Subject: Security

    Alert: Update Java (*See Kronos Note) Date: February 22, 2013 ********************************************************** ************** This is an automatically generated message. Please DO NOT REPLY. If you require assistance, please contact the Help Center. ********************************************************** ************** Oracle has released an update for Java that fixes 50 security holes, including a critical hole currently being exploited in the wild. The IT Security Office strongly recommends that you update Java as User generated and publicly sourced attacks
  7. Learn more or get involved @avasecure http://avasecure.com open source (GPL)

    https://github.com/SafeStack/ava now with vagrant/ansible