SlideShare a Scribd company logo
1 of 31
Download to read offline
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 1
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
Billions of devices connected to the
Internet.. thousands of sensors in our
(Smart) City..
..IOT Security, System and Network
and Application Security, Malware,
Ransomware..
What could possibly go wrong?
..a brief introduction to the
cybersecurity issues and challenges for
the Smart Cities.
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 2
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 3
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
$ whoami$ whoami
•work:
•penetration testing,
risk assessment,
training, ..
•fun:
•ISACA Venice
•sikurezza.org
•(f|er-|bz-)lug
Speaker:Speaker:
Igor FalcomatàIgor Falcomatà
CEO & founderCEO & founder
ifalcomata@enforcer.itifalcomata@enforcer.it
Partner commerciale:Partner commerciale:
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 4
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 5
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
IntroductionIntroduction
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 6
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
IntroductionIntroductionhttp://www.smart-cities.eu/model.html
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 7
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
TechnologyTechnology
Web 2.0 &
mobile
ICS/
SCADA
(I)IoT/
Custom
Legacy/
Embedded
Smart
City
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 8
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 9
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Smart (?) Cities..Smart (?) Cities..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 10
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Smart (?) Cities..Smart (?) Cities..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 11
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Web 2.0..Web 2.0..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 12
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Mobile..Mobile..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 13
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
IOT..IOT..
The S in IOT
stands for Security
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 14
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
IOT..IOT..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 15
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
OWASP IoT Attack Surface AreasOWASP IoT Attack Surface Areas
Image credits: Dan Miesseler
https://hackaday.com/2016/06/13/iot-security-is-an-empty-buzzword/
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 16
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
ICS/SCADAICS/SCADA
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 17
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
ICS/SCADAICS/SCADA
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 18
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
CyberwarCyberwar
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 19
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 20
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
Remeber:
You’re exposed to
ole-wild Internet
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 21
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
GDPR:
Privacy by design
Security by design
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 22
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
Open standards /
Compliance
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 23
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
“Don’t reinvent
the wheel”
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 24
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
SSDLC
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 25
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
Beware:
Cloud lock-in
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 26
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
“Future proof”
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 27
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
Research / Risk
assessment /
VA / PT / ...
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 28
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
How to minimize the risks?How to minimize the risks?
The bug, the
bounty and
the white
hat..
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 29
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 30
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
ReferencesReferences
OWASP (eg. Top Ten, Testing Project, cheat sheets, IoT Project, ..)
https://www.owasp.org/
CIS Critical Security Controls
https://www.sans.org/critical-security-controls
ISO 27k
https://www.iso.org/isoiec-27001-information-security.html
NIST Cybersecurity for IoT Program
https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program
IoT Security Foundation
https://www.iotsecurityfoundation.org/
GOV.UK - Secure by Design
https://www.gov.uk/government/publications/secure-by-design
Shodan - The search engine for Security ..
https://www.shodan.io/
Thinkst ConCollector (eg. “zigbee”)
http://cc.thinkst.com/
© Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 31
Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano
Agenda
•Introduction
•What are the risks?
•How to minimize the risks?
•References
•Q&A
Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity

More Related Content

Similar to SFScon19 - Igor Falcomatà - Smart Cities vs Cybersecurity

Meeting The Cyber Insurgency Threats From Neighbouring Countires01
Meeting The Cyber Insurgency Threats From Neighbouring Countires01Meeting The Cyber Insurgency Threats From Neighbouring Countires01
Meeting The Cyber Insurgency Threats From Neighbouring Countires01guest446b00
 
Privacy & cyber-physical security in eu cities 2016
Privacy & cyber-physical security in eu cities 2016Privacy & cyber-physical security in eu cities 2016
Privacy & cyber-physical security in eu cities 2016Martin Tom-Petersen
 
WISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, ItalyWISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, ItalyCYBERWISER .eu
 
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...Paolo Nesi
 
White Paper on Smart Cities
White Paper on Smart CitiesWhite Paper on Smart Cities
White Paper on Smart CitiesDAYWATCHER.COM
 
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...Yenlo
 
Towards an IoT Computing Continuum and its Application in Smart Agriculture
Towards an IoT Computing Continuum and its Application in Smart AgricultureTowards an IoT Computing Continuum and its Application in Smart Agriculture
Towards an IoT Computing Continuum and its Application in Smart AgricultureATMOSPHERE .
 
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.FabianWckl
 
3.3. Smart city - dalbir singh cisco
3.3. Smart city - dalbir singh cisco3.3. Smart city - dalbir singh cisco
3.3. Smart city - dalbir singh ciscoChuong Nguyen
 
What to expect at the Tanla Hub at MWC 2023.pdf
What to expect at the Tanla Hub at MWC 2023.pdfWhat to expect at the Tanla Hub at MWC 2023.pdf
What to expect at the Tanla Hub at MWC 2023.pdfTanla Platforms
 
Smart & Connected Communities / Addressing cities challenges with refined dat...
Smart & Connected Communities / Addressing cities challenges with refined dat...Smart & Connected Communities / Addressing cities challenges with refined dat...
Smart & Connected Communities / Addressing cities challenges with refined dat...Mindtrek
 
Data Integration & Beyond. Dimensions & Architectures
Data Integration & Beyond. Dimensions & ArchitecturesData Integration & Beyond. Dimensions & Architectures
Data Integration & Beyond. Dimensions & ArchitecturesBig Data Value Association
 
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020Association for Project Management
 
Securely Deploying Micro Services, Containers & Serverless PaaS Web Apps
Securely Deploying Micro Services, Containers & Serverless PaaS Web AppsSecurely Deploying Micro Services, Containers & Serverless PaaS Web Apps
Securely Deploying Micro Services, Containers & Serverless PaaS Web AppsPriyanka Aash
 
Exponential Roadmap and ICT Climate Impacts
Exponential Roadmap and ICT Climate ImpactsExponential Roadmap and ICT Climate Impacts
Exponential Roadmap and ICT Climate ImpactsICT FOOTPRINT .eu
 
Corporate innovation in the financial industry, banking, insurance by tommaso...
Corporate innovation in the financial industry, banking, insurance by tommaso...Corporate innovation in the financial industry, banking, insurance by tommaso...
Corporate innovation in the financial industry, banking, insurance by tommaso...Tommaso Di Bartolo
 
Overcoming Security Vulnerabilities and Cyberattacks in IoT Environment
Overcoming Security Vulnerabilities and Cyberattacks in IoT EnvironmentOvercoming Security Vulnerabilities and Cyberattacks in IoT Environment
Overcoming Security Vulnerabilities and Cyberattacks in IoT EnvironmentFarah Baharuddin
 
BigData and Cybersecurity for Digital Finance and conclusions
BigData and Cybersecurity for Digital Finance and conclusionsBigData and Cybersecurity for Digital Finance and conclusions
BigData and Cybersecurity for Digital Finance and conclusionsBig Data Value Association
 

Similar to SFScon19 - Igor Falcomatà - Smart Cities vs Cybersecurity (20)

Meeting The Cyber Insurgency Threats From Neighbouring Countires01
Meeting The Cyber Insurgency Threats From Neighbouring Countires01Meeting The Cyber Insurgency Threats From Neighbouring Countires01
Meeting The Cyber Insurgency Threats From Neighbouring Countires01
 
Privacy & cyber-physical security in eu cities 2016
Privacy & cyber-physical security in eu cities 2016Privacy & cyber-physical security in eu cities 2016
Privacy & cyber-physical security in eu cities 2016
 
WISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, ItalyWISER @Ferma Forum, 4-7 October 2015, Venice, Italy
WISER @Ferma Forum, 4-7 October 2015, Venice, Italy
 
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...
Snap4City November 2019 Course: Smart City IOT Dashboard, smart city control ...
 
White Paper on Smart Cities
White Paper on Smart CitiesWhite Paper on Smart Cities
White Paper on Smart Cities
 
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...
WSO2 - Yenlo Integration Summit Stuttgart May 15 2019 - Open Banking APIs and...
 
Towards an IoT Computing Continuum and its Application in Smart Agriculture
Towards an IoT Computing Continuum and its Application in Smart AgricultureTowards an IoT Computing Continuum and its Application in Smart Agriculture
Towards an IoT Computing Continuum and its Application in Smart Agriculture
 
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.
Flasher, the all-in-one high-tech wearable for cyclists and e-scooter riders.
 
3.3. Smart city - dalbir singh cisco
3.3. Smart city - dalbir singh cisco3.3. Smart city - dalbir singh cisco
3.3. Smart city - dalbir singh cisco
 
What to expect at the Tanla Hub at MWC 2023.pdf
What to expect at the Tanla Hub at MWC 2023.pdfWhat to expect at the Tanla Hub at MWC 2023.pdf
What to expect at the Tanla Hub at MWC 2023.pdf
 
Smart & Connected Communities / Addressing cities challenges with refined dat...
Smart & Connected Communities / Addressing cities challenges with refined dat...Smart & Connected Communities / Addressing cities challenges with refined dat...
Smart & Connected Communities / Addressing cities challenges with refined dat...
 
Investigating digital ad fraud spi virtual meeting
Investigating digital ad fraud   spi virtual meetingInvestigating digital ad fraud   spi virtual meeting
Investigating digital ad fraud spi virtual meeting
 
Data Integration & Beyond. Dimensions & Architectures
Data Integration & Beyond. Dimensions & ArchitecturesData Integration & Beyond. Dimensions & Architectures
Data Integration & Beyond. Dimensions & Architectures
 
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020
Secrets of achieving ChPP excellent in financial services webinar, 5 May 2020
 
Securely Deploying Micro Services, Containers & Serverless PaaS Web Apps
Securely Deploying Micro Services, Containers & Serverless PaaS Web AppsSecurely Deploying Micro Services, Containers & Serverless PaaS Web Apps
Securely Deploying Micro Services, Containers & Serverless PaaS Web Apps
 
Exponential Roadmap and ICT Climate Impacts
Exponential Roadmap and ICT Climate ImpactsExponential Roadmap and ICT Climate Impacts
Exponential Roadmap and ICT Climate Impacts
 
Corporate innovation in the financial industry, banking, insurance by tommaso...
Corporate innovation in the financial industry, banking, insurance by tommaso...Corporate innovation in the financial industry, banking, insurance by tommaso...
Corporate innovation in the financial industry, banking, insurance by tommaso...
 
Overcoming Security Vulnerabilities and Cyberattacks in IoT Environment
Overcoming Security Vulnerabilities and Cyberattacks in IoT EnvironmentOvercoming Security Vulnerabilities and Cyberattacks in IoT Environment
Overcoming Security Vulnerabilities and Cyberattacks in IoT Environment
 
IoT security Q3 2020 overview
IoT security Q3 2020 overview IoT security Q3 2020 overview
IoT security Q3 2020 overview
 
BigData and Cybersecurity for Digital Finance and conclusions
BigData and Cybersecurity for Digital Finance and conclusionsBigData and Cybersecurity for Digital Finance and conclusions
BigData and Cybersecurity for Digital Finance and conclusions
 

More from South Tyrol Free Software Conference

SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...South Tyrol Free Software Conference
 
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...South Tyrol Free Software Conference
 
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data HubSFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data HubSouth Tyrol Free Software Conference
 
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...South Tyrol Free Software Conference
 
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...South Tyrol Free Software Conference
 
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...South Tyrol Free Software Conference
 
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelinesSFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelinesSouth Tyrol Free Software Conference
 
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure mattersSFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure mattersSouth Tyrol Free Software Conference
 
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...South Tyrol Free Software Conference
 
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...South Tyrol Free Software Conference
 
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free softwareSFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free softwareSouth Tyrol Free Software Conference
 
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...South Tyrol Free Software Conference
 
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changerSFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changerSouth Tyrol Free Software Conference
 
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...South Tyrol Free Software Conference
 
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation InternetSFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation InternetSouth Tyrol Free Software Conference
 
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...South Tyrol Free Software Conference
 

More from South Tyrol Free Software Conference (20)

SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
SFSCON23 - Rufai Omowunmi Balogun - SMODEX – a Python package for understandi...
 
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
SFSCON23 - Roberto Innocenti - From the design to reality is here the Communi...
 
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data HubSFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
SFSCON23 - Martin Rabanser - Real-time aeroplane tracking and the Open Data Hub
 
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
SFSCON23 - Marianna d'Atri Enrico Zanardo - How can Blockchain technologies i...
 
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
SFSCON23 - Lucas Lasota - The Future of Connectivity, Open Internet and Human...
 
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
SFSCON23 - Giovanni Giannotta - Intelligent Decision Support System for trace...
 
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelinesSFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
SFSCON23 - Elena Maines - Embracing CI/CD workflows for building ETL pipelines
 
SFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open ScienceSFSCON23 - Christian Busse - Free Software and Open Science
SFSCON23 - Christian Busse - Free Software and Open Science
 
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure mattersSFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
SFSCON23 - Charles H. Schulz - Why open digital infrastructure matters
 
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portalSFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
SFSCON23 - Andrea Vianello - Achieving FAIRness with EDP-portal
 
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
SFSCON23 - Thomas Aichner - How IoT and AI are revolutionizing Mass Customiza...
 
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke MeranSFSCON23 - Stefan Mutschlechner - Smart Werke Meran
SFSCON23 - Stefan Mutschlechner - Smart Werke Meran
 
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
SFSCON23 - Mirko Boehm - European regulators cast their eyes on maturing OSS ...
 
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free softwareSFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
SFSCON23 - Marco Pavanelli - Monitoring the fleet of Sasa with free software
 
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
SFSCON23 - Marco Cortella - KNOWAGE and AICS for 2030 agenda SDG goals monito...
 
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changerSFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
SFSCON23 - Lina Ceballos - Interoperable Europe Act - A real game changer
 
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
SFSCON23 - Johannes Näder Linus Sehn - Let’s monitor implementation of Free S...
 
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation InternetSFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
SFSCON23 - Gabriel Ku Wei Bin - Why Do We Need A Next Generation Internet
 
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis MapsSFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
SFSCON23 - Edoardo Scepi - The Brand-New Version of IGis Maps
 
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...SFSCON23 - Davide Vernassa - Empowering Insights  Unveiling the latest innova...
SFSCON23 - Davide Vernassa - Empowering Insights Unveiling the latest innova...
 

Recently uploaded

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetEnjoy Anytime
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 

Recently uploaded (20)

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 

SFScon19 - Igor Falcomatà - Smart Cities vs Cybersecurity

  • 1. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 1 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity Billions of devices connected to the Internet.. thousands of sensors in our (Smart) City.. ..IOT Security, System and Network and Application Security, Malware, Ransomware.. What could possibly go wrong? ..a brief introduction to the cybersecurity issues and challenges for the Smart Cities.
  • 2. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 2 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
  • 3. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 3 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano $ whoami$ whoami •work: •penetration testing, risk assessment, training, .. •fun: •ISACA Venice •sikurezza.org •(f|er-|bz-)lug Speaker:Speaker: Igor FalcomatàIgor Falcomatà CEO & founderCEO & founder ifalcomata@enforcer.itifalcomata@enforcer.it Partner commerciale:Partner commerciale:
  • 4. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 4 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
  • 5. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 5 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano IntroductionIntroduction
  • 6. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 6 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano IntroductionIntroductionhttp://www.smart-cities.eu/model.html
  • 7. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 7 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano TechnologyTechnology Web 2.0 & mobile ICS/ SCADA (I)IoT/ Custom Legacy/ Embedded Smart City
  • 8. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 8 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
  • 9. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 9 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Smart (?) Cities..Smart (?) Cities..
  • 10. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 10 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Smart (?) Cities..Smart (?) Cities..
  • 11. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 11 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Web 2.0..Web 2.0..
  • 12. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 12 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Mobile..Mobile..
  • 13. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 13 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano IOT..IOT.. The S in IOT stands for Security
  • 14. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 14 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano IOT..IOT..
  • 15. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 15 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano OWASP IoT Attack Surface AreasOWASP IoT Attack Surface Areas Image credits: Dan Miesseler https://hackaday.com/2016/06/13/iot-security-is-an-empty-buzzword/
  • 16. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 16 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano ICS/SCADAICS/SCADA
  • 17. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 17 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano ICS/SCADAICS/SCADA
  • 18. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 18 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano CyberwarCyberwar
  • 19. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 19 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
  • 20. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 20 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? Remeber: You’re exposed to ole-wild Internet
  • 21. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 21 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? GDPR: Privacy by design Security by design
  • 22. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 22 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? Open standards / Compliance
  • 23. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 23 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? “Don’t reinvent the wheel”
  • 24. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 24 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? SSDLC
  • 25. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 25 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? Beware: Cloud lock-in
  • 26. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 26 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? “Future proof”
  • 27. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 27 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? Research / Risk assessment / VA / PT / ...
  • 28. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 28 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano How to minimize the risks?How to minimize the risks? The bug, the bounty and the white hat..
  • 29. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 29 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity
  • 30. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 30 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano ReferencesReferences OWASP (eg. Top Ten, Testing Project, cheat sheets, IoT Project, ..) https://www.owasp.org/ CIS Critical Security Controls https://www.sans.org/critical-security-controls ISO 27k https://www.iso.org/isoiec-27001-information-security.html NIST Cybersecurity for IoT Program https://www.nist.gov/programs-projects/nist-cybersecurity-iot-program IoT Security Foundation https://www.iotsecurityfoundation.org/ GOV.UK - Secure by Design https://www.gov.uk/government/publications/secure-by-design Shodan - The search engine for Security .. https://www.shodan.io/ Thinkst ConCollector (eg. “zigbee”) http://cc.thinkst.com/
  • 31. © Igor Falcomatà <ifalcomata@enforcer.it>, alcuni diritti riservati: http://creativecommons.org/licenses/by-sa/2.0/it/deed.en - Page 31 Smart Cities vs (?) Cybersecurity – SFScon 2019 – 15/11/2019 - Bolzano Agenda •Introduction •What are the risks? •How to minimize the risks? •References •Q&A Smart Cities vs (?) CybersecuritySmart Cities vs (?) Cybersecurity