Upcoming AIA/ISA Webinars Information Sharing Modern Technology and - - PowerPoint PPT Presentation

upcoming aia isa webinars
SMART_READER_LITE
LIVE PREVIEW

Upcoming AIA/ISA Webinars Information Sharing Modern Technology and - - PowerPoint PPT Presentation

Aero Webinar Series September 24, 2009 The Financial Impact of Cyber Risk 50 Questions Every CFO Should Ask The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask Page 1 A publication of the American National Standards


slide-1
SLIDE 1

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 1

Aero Webinar Series

September 24, 2009

The Financial Impact of Cyber Risk 50 Questions Every CFO Should Ask

slide-2
SLIDE 2

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 2

Upcoming AIA/ISA Webinars

  • Information Sharing — Modern Technology and Legal Structures featuring

Jeff Brown,Director, Infrastructure Services and CISO Information Technology,

  • Raytheon. To be presented on 10/22/09
  • Testing In A “Real” Environment Leads to Faster Cyber Security

Innovation featuring General (Ret.) Charles “Charlie” Croom, Vice President of Cyber Security Solutions, Lockheed Martin Information Systems & Global Services and Curt Aubley, Chief Technology Officer CTO, Lockheed Martin Operations & Next Generation Solutions. To be presented on 11/5/09

  • Supply Chain Issues in Cyber Security — A Framework for Moving

Forward featuring Scott Borg, Director and Chief Economist (CEO) at the U.S. Cyberconsequences Unit. To be presented on 11/19/09

  • Legal Framework for Securing Unified Communications featuring Jeffrey

Ritter, President, Waters Edge Consulting.

slide-3
SLIDE 3

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 3

Presenters

  • Moderator

– Ty R. Sagalow, Chief Innovation Officer, Zurich North America, ISA/ ANSI Financial Risk Project Leader

  • Panelists

– Joe Buonomo, President, Direct Computer Resources, ISA/ANSI Financial Risk Project Leader – Harry Oellrich, Managing Director, Head of the Cyber, Technology and Intellectual Property Practice, Guy Carpenter & Company, LLC – Rick Kam, President, ID Experts – Regan Adams, Esq., CIPP, Founder & CEO , Cyber Security Assurance, LLC

slide-4
SLIDE 4

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 4

The Financial Impact of Cyber Risk 50 Questions Every CFO Should Ask

slide-5
SLIDE 5

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 5

Agenda

  • Background: Setting the Scene
  • Development of an Action Guide to analyze, manage,

and transfer financial risk for cyber security

  • Role Play
  • Questions and Answers
slide-6
SLIDE 6

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 6

Background Setting the Scene

  • Cyber security is vital to the economic well-being
  • f the U.S.
  • What does cyber security really mean?

– No standard definition, but one interpretation is the protection of any computer system, software program, and data against unauthorized disclosure, transfer, modification, or destruction, whether accidental or intentional – Cyber security attacks can come from internal networks, the Internet, or other private or public systems

slide-7
SLIDE 7

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 7

Background (continued)

  • Cyber-Security is a private-public partnership

– Government at all levels use interconnected networks connected internally and externally and experiences the same issues as that of the private sector – Government can be a role model for effective cyber security and use its procurement position to motivate best practices in the private sector – Government can play both traditional regulatory role as well as a provider/supporter of incentives

slide-8
SLIDE 8

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 8

Background (continued)

  • Organizations use cyber systems for multiple purposes

– Real-time tracking of supply chains – Inventory management – Improvement of employee efficiency – Generation of on-line commerce

  • Twenty-five percent of America’s economic value –

up to $3 trillion a day – moves over network connections each day

slide-9
SLIDE 9

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 9

Background

  • While organizations appreciate the benefits of the

Internet, they have often failed to properly account for its financial risks

– 50% of Senior Executives said they did not know how much money was lost due to an attack – Congressional Research Service estimates that the economic impact of cyber attacks on business has grown to over $226 billion annually – Total average cost of a data breach grew to approximately $200 per record compromised in 2007

slide-10
SLIDE 10

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 10

Background

  • There is a substantial body of work dealing with the

technical standards of cyber security

  • Plenty of attention paid to important technical issues,

such as data encryption and best-in-class security technologies

  • BUT...to date, there has not been any comprehensive

methodology for understanding and mitigating the financial losses associated with cyber risk

slide-11
SLIDE 11

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 11

Net Financial Risk Formula

slide-12
SLIDE 12

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 12

What Are Some of the Costs?

  • Failure of security can have costly consequences

– Civil and criminal lawsuits – Lost trade secrets/governmental secrets – Breach of contract, breach of privacy – Reputation damage – Business interruption, lost income – Increase likelihood of a terrorist attack

slide-13
SLIDE 13

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 13

Development of Financial Risk Action Guide

  • To promote understanding of financial risk, the American

National Standards Institute’s (ANSI) Homeland Security Standards Panel (HSSP) and the Internet Security Alliance (ISA) launched a workshop

slide-14
SLIDE 14

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 14

Development of Financial Risk Action Guide

  • The Goal

– Create an Action Guide to analyze, manage, and transfer financial risk for Cyber Security

  • The Team

– More than 30 industry leaders and governmental partners

  • The key to understanding the financial risks of cyber

security is to fully embrace its multi-disciplinary nature, covering many areas of a company

slide-15
SLIDE 15

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 15

Resolve: Multidisciplinary Feed to CFO

  • A CFO needs to know the key questions to ask to the

major stakeholders in all corporate domains, including:

– General Counsel – Chief Risk Officer – Chief Compliance Officer – Chief Technology Officer – Heads of Corporate Communications, Investor Relations, and Customer Service – Head of Human Resources

slide-16
SLIDE 16

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 16

Time Table

  • The Timetable

– First Workshop held in March 2008 – Draft Action Guide prepared by teams representing the different disciplines – Subsequent Workshops held in May and July – Action Guide finalized in early August – Publication was released in October 2008 “National Cyber Awareness Month”

slide-17
SLIDE 17

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 17

Action Guide: How to get it

The Financial Impact of Cyber Risk 50 Questions Every CFO Should Ask Release date: October 20, 2008 Free electronic copy of the document available at: webstore.ansi.org/ cybersecurity

slide-18
SLIDE 18

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 18

Ongoing Effort: Development of Financial Risk Answer Guide

  • The American National Standards Institute’s (ANSI) Homeland Security

Standards Panel (HSSP) and the Internet Security Alliance (ISA) launched a Phase II initiative to further inform and guide the C-suite community regarding the economics of cyber risk

  • While Phase I focused on providing questions organizations/CFOs should

be asking and provided guidance on the identification and quantification

  • f the financial risk associated with cyber security, Phase II focuses on

developing an implementation strategy/process for the Phase I questions. Additionally, this initiative is filling out that framework to the C-suite community make better informed decisions related to cyber risk from an economic standpoint.

slide-19
SLIDE 19

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 19

Time Table

  • The Timetable

– First Workshop held in July 2009 – Draft Action Guide prepared by teams representing the different disciplines – Subsequent Workshops held in August and September – Answer Guide to be finalized in October – Publication release scheduled for November 2009

Email bfoer@isalliance.org to pre-order a free electronic copy

slide-20
SLIDE 20

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 20

Role Play

Played by Rick Kam, President, ID Experts Played by Ty R. Sagalow, Chief Innovation Officer, Zurich North America Insurance Company Played by Regan Adams, Esq., CIPP, Founder & CEO , Cyber Security Assurance, LLC

Corporate Counsel

CEO

Communications Officer Chief Information Officer

Played by Joe Buonomo, President, Direct Computer Resources Played by Harry Oellrich, Managing Director and Head of the Cyber, Technology and Intellectual Property Practice, Guy Carpenter & Company, LLC

Risk Manager

slide-21
SLIDE 21

The Financial Impact of Cyber Security 50 Questions Every CFO Should Ask A publication of the American National Standards Institute and the Internet Security Alliance Page 21

Questions & Answers

Played by Rick Kam, President, ID Experts Played by Ty R. Sagalow, Chief Innovation Officer, Zurich North America Insurance Company Played by Regan Adams, Esq., CIPP, Founder & CEO , Cyber Security Assurance, LLC

Corporate Counsel

CEO

Communications Officer Chief Information Officer

Played by Joe Buonomo, President, Direct Computer Resources Played by Harry Oellrich, Managing Director and Head of the Cyber, Technology and Intellectual Property Practice, Guy Carpenter & Company, LLC

Risk Manager