9/20/2017 1
CYBER RISK
What Not-for-Profit Management & Boards Need to Know
John Dougherty IT Director, Unbound johnd@unbound.org Jan Hertzberg Director, BKD jhertzberg@bkd.com September 20, 2017
CYBER RISK What Not-for-Profit Management & Boards Need to Know - - PDF document
9/20/2017 CYBER RISK What Not-for-Profit Management & Boards Need to Know September 20, 2017 Jan Hertzberg John Dougherty Director, BKD IT Director, Unbound jhertzberg@bkd.com johnd@unbound.org 1 9/20/2017 TO RECEIVE CPE CREDIT
John Dougherty IT Director, Unbound johnd@unbound.org Jan Hertzberg Director, BKD jhertzberg@bkd.com September 20, 2017
hours of live webinar
certificates within 15 business days of live webinar
4
ADDITIVE MOTIVATION PROGRESSION LINE
HACKTIVISTS NATION-STATES FRAUDSTERS
THEFT DISRUPTION DESTRUCTION
5
6
2015
Breach of 10,00 donors personal info between 2013–2015
2017
Muncie, Indiana-based not-for-profit organization breached, lost all financial & client data
2016
Breach of data for 550,000 individuals
2014
309,000 university faculty, staff & students
inquiry
alphabetized
than I had hoped for”
underground market
submitted two returns
7
8
9
10
Negative publicity Regulatory sanctions Refusal to share personal information Damage to brand Regulator scrutiny Legal liability Fines Damaged donor relationships Damaged employee relationships Deceptive or unfair trade charges
Diversion of resources Lost productivity
11
Credit Cards Price (2012–2014) Current Price Visa & Mastercard $4 $7 Visa & Mastercard with Track 1 & Track 2 Data $23 (V); $35 (MC) $30 Premium American Express $28 $30 Bank Account Credentials $15,000 for 500 $15,000 for 500 Email Accounts Price (2012–2014) Current Price Popular Email (Gmail, Hotmail, Yahoo) $100 per 100,000 $100 per 100,000 Corporate Email N/A $500 per Mailbox IP Address of Email User $90 $90
12
13
Ponemon 2016 Cost of Data Breach Study
14
15
1934 SEC Act 1996 HIPAA 2000 CFR17 Part 248 Brokers Consumer Protection 2003 California Data Breach Law 2017 Executive Order Strengthening the Cybersecurity of Federal Networks & Critical Infrastructure 2006 Indiana Breach Notification Law 1974 Family Educational Rights & Privacy Act (FERPA) 1999 Gramm- Leach-Bliley Act 2001 Cybersecurity Enhancement Act 2006 PCI DSS 2009 HITECH 2018 General Data Protection Regulation (GDPR) 2013 HIPAA (Omnibus)
16
17
Mastercard, Discover, American Express, JCB), created the PCI DSS in 2006; updated
18
20 What do we consider our most valuable assets? How does our IT system interact with those assets? Do we believe we can fully protect those assets? Do we think there is adequate protection in place if someone wanted to get at or damage our corporate “crown jewels”? If not, what would it take to feel comfortable that our assets were protected? Are we investing enough so our corporate operating & network systems are not easy targets by a determined hacker? Are we considering cybersecurity aspects of our major business decisions, such as mergers & acquisitions, partnerships, new product launches, etc., in a timely fashion?
21
22
23
24
25
27
28
Asset Management Business Environment Governance Risk Assessment Risk Management Strategy Access Control Awareness & Training Data Security Information Protection Processes Maintenance Protective Technology Anomalies & Events Security Continuous Monitoring Response Planning Detection Processes Communications Analysis Mitigation Improvements Recovery Planning Improvements Communications
24
29
30
Phase 1 – Discovery
inventory
protected health information (ePHI), etc.
Phase 2 – Analysis
threats & recover should a breach occur
Phase 3 – Remediation Planning
32
33
34
35
36
The information contained in these slides is presented by professionals for your information only & is not to be considered as legal advice. Applying specific information to your situation requires careful consideration of facts &
before acting on any matters covered BKD, LLP is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE
the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org
FOR MORE INFORMATION
Jan Hertzberg | Director, BKD | jhertzberg@bkd.com John Dougherty | IT Director, Unbound | johnd@unbound.org