Deloitte Luxembourg and EBRC look into the cyber security journey - think early, act effectively and react promptly

fr en de

Most security breaches are still perpetrated by external attackers and the financial services industry is particularly exposed to security incidents with confirmed data loss. This was one of the findings of the Verizon 2014 Data Breach Investigations Report (DBIR), presented at the Cyber Security conference, organised by Deloitte Luxembourg and EBRC.

<< Back
10/06/2014 |
  • Deloitte

It takes less and less time for an attacker to compromise his/her target. Some 60% of security incidents occur within a couple of hours, whereas 62% of incidents are discovered months later

Sebastien Besson, Cyber Security specialist at Deloitte

Attracting close to 50 security and IT professionals, risk managers, internal auditors, among others, the conference aimed to provide the latest updates on the cyber threat landscape and focus on the typical approaches, standards, regulations and capabilities to protect organisations from cyber threats.

The digital revolution is driving business innovation and growth, yet also exposing all organisations to new and emerging threats. Indeed, organisations must face a myriad of threat agents, whose determination and attacking resources may greatly vary from one to another.

Stéphane Hurtaud, Partner at Deloitte Luxembourg explained “The threat landscape has changed, and the need for more mature cyber security is higher than before. In today’s world, addressing cyber security risks with point solutions is clearly unrealistic. Given the complexity of the cyber risk landscape, one must adopt a much more cohesive and structured approach for managing your cyber risks effectively”.

Moving from information security to risk intelligent security
The 2014 DBIR provides information on attackers, their motivation, demography and methods that can help companies to protect their most valuable assets. The latest edition of this report confirms that, whilst most security breaches come from the outside, the main motive of the threat remains financial gain, even if industrial espionage has been rising over the last few years.

Sebastien Besson, Cyber Security specialist at Deloitte, also emphasised that “It takes less and less time for an attacker to compromise his/her target. Some 60% of security incidents occur within a couple of hours, whereas 62% of incidents are discovered months later.”

During the conference, speakers discussed this complex and ever-evolving threat landscape, concluding that organisations need to adopt a cohesive approach to protection from cyber threats, underpinned by 5 key principles:

  • Understand risk exposition and defining the risk appetite
  • Ensure close alignment with business goals
  • Prepare for the worst
  • Share intelligence
  • Instil a broad awareness of cyber security

The prevalence and sophistication of recent cyber attacks on public and private organisations highlight a number of capabilities that are essential to cyber security (from prevention to detection).

Leveraging the National Institute of Standards and Technology (NIST) cybersecurity framework
The speakers also addressed the question of how a company should react towards constant reports of cyber security breaches. 
Régis Jeandin (EBRC, Head of Security Services) confirmed that: “Too often, a pragmatic and structured approach towards cyber security could save time and be cost effective, however, taking the time to step aside and initiate a true reflexion is lacking in many organisations.”

The conference was an opportunity for the audience to review one of the most recent frameworks in cyber security and its three corner stones:

  1. Definition of the core functions (identification, protection, detection, response, recovery)
  2. Definition of the current situation (e.g. profile) and target. This profiling allows companies to identify the gaps and initiate the relevant action plans
  3. Definition of the ‘tiers’ (tier 4 being most secure and tier 1 being least secure),  through which the characteristics of the organisation’s approach to risk is evaluated

Cyber incident response: challenges and solutions
To become more efficient and to better protect valuable IT assets against the continuously evolving cyber threats, information security should adopt a new form, moving from traditional perimeter protection to rapid and advanced detection and response capabilities to a cyber security incident.  

Matthijs van der Wel, Director of the Incident Response department at DataExpert, explained that often, it takes 2 weeks for an organisation to perform computer forensics analysis of one single compromised system in its environment. He further added that companies often lack strong incident response capabilities, enabling them to timely react to an adverse security event. Most of the efforts spent on information security today still focus mainly on preventive measures. Through examples, he showed that latest cyber attacks demonstrate that prevention is not sufficient anymore to ensure the adequate protection of systems and networks.

During his presentation, Matthijs provided an overview of new existing incident response solutions, using specific software agent deployed on corporate computer systems. Such solutions enable organisations to react faster to a security incident, by: 

  1. Performing computer forensics analysis from a remote location
  2. Analysing the state of multiple systems across the company, using a set of various data sources (e.g. network, operating system, application information) to detect any anomaly which could be a potential indicator of a successful security breach
  3. Restoring previous states of a given system back in time, to better pinpoint the timeframe and the source of a security incident
Back to top  | << Back

Communiqués liés

Kda PP
29/05/2024 Personnalités

Kevin d'Antonio joins Strategy&, PwC Luxembourg’s strategy...

Kevin d'Antonio has joined PwC’s strategy consulting business, Strategy& as ne...

PwC Luxembourg
Lunex

LUNEX lance un certificat en Gestion de la Santé en Entrepr...

LUNEX est fier d'annoncer le lancement de son Certificat en Gestion de la Santé...

Lunex
Picture Sylvain Merle
24/05/2024 Personnalités

Sylvain Merle rejoint BCE en tant que CTO

BCE annonce la nomination de Sylvain Merle au poste de Chief Technology Officer ...

BCE
2024-05 Deloitte Luxembourg appoints 11 new Partners and Managing Directors
23/05/2024 Personnalités

Deloitte Luxembourg nomme 11 nouveaux Partners et Managing D...

Déterminé à élever davantage ses ambitions, Deloitte Luxembourg a promu 11 p...

Deloitte
Foyer
23/05/2024

Foyer choisit la plateforme actuarielle Akur8 pour perfectio...

Foyer, le premier assureur luxembourgeois, a choisi de s’allier à Akur8, pour...

FOYER
Pierre Marie
23/05/2024

PwC’s 2024 Barometer unveils key trends and insights into ...

PwC Luxembourg has just released its 2024 Barometer for the previous year’s â€...

PwC Luxembourg

Il n'y a aucun résultat pour votre recherche

We use cookies to ensure the best experience on our website. By accepting you agree the use of cookies. OK Learn more