Intelligent Security: Defending the Digital Business

accenture
Intelligent Security: 
Defending the Digital 
Business 
Defending the 
Digital Business
Executive Summary 
Today 
Key Business Challenges 
•Missing link between business goals and security capabilities 
•Compliance providing a false sense of security 
•Enterprises are reaping the benefits of enhancing business functionality through cloud, mobile, 
and social, but struggle governing the extensions to the enterprise 
•Increasingly sophist security talent to address current security needs 
A new 
tomorrow 
Approach to Intelligent Security 
• Assess the security program’s capability and identify leap-ahead opportunities 
• Manage complexity and integrate the enterprise 
• Become agile 
• Accelerate toward security intelligence 
• Develop end-to-end delivery and flexible sourcing strategies 
How 
to get 
there 
Security Call to Action 
•The first step is assessing current posture and adopting a business-aligned security strategy 
•Retain staff experienced with security architecture planning and design, tools and integration to 
drive successful outcomes 
•Establishing an end-to-end delivery capability, underpinned by a pre-integrated security solution 
set allows organizations to modularly select for their specific threat areas and adoption pace 
•Move to extract more value from the data they already collect and analyze 
Copyright © 2014 Accenture All rights reserved. 2
Key business challenges 
Copyright © 2014 Accenture All rights reserved. 3
Business challenges to security for today’s enterprise 
Despite all the effort and resources that organizations invest in traditional 
information security approaches, many still fall prey to the latest cyber threats, 
or find they are unprepared to deal with rapidly blurring enterprise boundaries 
Five most common issues companies will have taking a proactive security stance 
Keeping 
pace with 
persistent 
threats 
Governing 
the extended 
enterprise 
despite blurring 
boundaries 
Thinking 
outside the 
compliance 
(check) box 
Missing the 
link between 
business and 
security 
Addressing 
the security 
supply/demand 
imbalance 
Copyright © 2014 Accenture All rights reserved. 4
Missing the link between 1 business and security 
Protecting the business should be the first and foremost goal of any security 
program, but most enterprises do not make it a core competency 
• Untethered programs can drift and become 
largely ineffective 
• Some security executives might struggle 
to draw a clear line between the protection 
provided and its impact on the company’s 
customer satisfaction, loyalty and revenue 
• The Security team may lack a logical road 
map for changing the organization’s view of 
the security function as simply an inhibitor 
or cost center 
Business Security 
Copyright © 2014 Accenture All rights reserved. 5
Thinking outside of the compliance (check) box 
2 
Unfortunately, compliance does not ensure security. Instead, enterprises 
should view compliance as the minimum acceptable cyber security “bar” 
they need to clear… 
Compliance 
•Audit centric 
•Controls based 
•Driven largely by regulatory 
requirements 
•Sample based 
•Scope limited by audit domain 
•Evaluated on a quarterly 
or annual basis 
Security 
•Business centric 
•Controls based 
•Driven by business 
requirements 
•Scope is holistic-includes 
enterprise, 3rd parties, 
suppliers, partners 
•Evaluated on near-real 
time basis 
Copyright © 2014 Accenture All rights reserved. 6
Governing the extended enterprise despite 
blurring boundaries 
3 
While business adoption has been widespread and rapid, many security 
organizations struggle to establish the appropriate frameworks, policies 
and controls to protect the expansions and contractions now common in 
extended IT environments 
Typical Day in the Extended Enterprise 
Cloud 
Real-time provisioning of servers to support 
testing of a cloud CRM system 
Mobile 
Granting mobile access to new capabilities 
for field representatives 
Social network 
Rollout of a business social network for 
sales, product and marketing collaboration 
• What are the appropriate 
frameworks and policies? 
• Should I allow personal devices? 
Which devices and do I let 
everyone do it? 
• How do I enable and monitor aaS 
components being introduced to 
my environment? 
• How will I reach my customers with 
the correct messages? 
• What do I need to do to make sure 
exposed by this new enterprise? 
Copyright © 2014 Accenture All rights reserved. 7
4 Keeping pace with persistent threats 
As the threats become more persistent, they become harder to identify 
Most organizations focus on: 
• Monitoring – Difficulty in prioritizing critical events and handling uncertainty 
• Static controls – Standard controls don’t help once the attacker is in 
For which cyber-threat are you prepared? 
Opportunistic Acts Mob Determined actors 
Attacker profile: 
•Will move on if thwarted 
•Will make mistakes 
•Can be creative 
Attacker profile: 
•Emotional and not disciplined 
•Not after the crown jewels 
•Not well backed 
Attacker profile: 
•Failure is not an option 
•Need only one vulnerability 
•Stick with it mentality 
Copyright © 2014 Accenture All rights reserved. 8
5 Addressing the security supply/demand imbalance 
Most organizations lack sufficient security talent 
to address their current needs 
Skill Shortages 
•Lack of the appropriate 
skills to execute required 
tasks 
•Hiring premiums for cyber 
security resources 
Career Development 
•Skilled resources are eager 
to keep skills sharp and 
maintain exposure to new 
technologies 
Firefighting 
•Misalignment of security 
programs to strategic 
business objectives cause 
practitioners to burn-out from 
constant troubleshooting 
Copyright © 2014 Accenture All rights reserved. 9
Net result 
Compliance driven 
(or audit scope driven) 
security scope can 
cause organizations 
to implicitly and 
unknowingly accept 
a significant amount 
of cyber-security risk 
Implicitly accepted risk Enterprise security risk 
Enterprise security risk 
Compliance risk Compliance risk 
Specific regulatory risk Specific regulatory risk 
Perceived Risk Actual Risk 
Copyright © 2014 Accenture All rights reserved. 10
Approach to Intelligent Security 
Copyright © 2014 Accenture All rights reserved. 11
Vision for Intelligent Security 
As organizations shift from a compliance-centered security mindset to an active 
cyber security stance, security teams need to adapt to keep pace with evolving 
business objectives 
• Driven by a comprehensive 
security strategy that is aligned to 
business goals and objectives 
• Core business assets protected by 
robust enterprise security controls 
• Layered on top are extended 
enterprise safeguards focused on 
enabling cloud, mobile and social 
network adoption 
• Advanced analytics incorporate 
cyber threat intelligence to enable 
proactive, accelerated action 
• Security metrics to measure 
enablement of business outcomes 
Copyright © 2014 Accenture All rights reserved. 12
Taking the next steps to address Intelligent Security for 
the digital enterprise 
Leading companies develop effective cyber security measures to handle 
vulnerabilities and mount an active defense calculated to meet and deflect 
attacker advances 
Assess security 
capability, identify 
opportunities 
Determine where 
the organization 
currently stands 
and the level of 
resources required 
to support 
meaningful 
transformation 
Manage 
complexity and 
integrate the 
enterprise 
Evolve the security 
program vision: 
establish an end-to-end 
enterprise 
security program 
and integrate it with 
existing enterprise 
architecture 
processes to reduce 
complexity levels 
and produce 
outcomes valued 
by the business 
Become agile 
Embrace the cloud 
and other emerging 
technologies to boost 
IT agility and reach 
customers faster, 
capitalize on 
efficiency and cost 
benefits and do so 
within risk tolerances 
Accelerate 
toward security 
intelligence 
Adapt to handle new 
threats to the 
enterprise by 
developing threat-centered 
operations 
by developing a 
deep understanding 
of adversaries, their 
goals and 
techniques 
Develop 
end-to-end 
delivery and 
sourcing 
Plan a delivery and 
operational strategy 
for each of the 
security services 
they offer to make 
a clear-eyed 
assessment of 
internal 
competencies for 
designing, building 
and deploying 
elements of a cyber-security 
program 
Copyright © 2014 Accenture All rights reserved. 13
Assess the security program’s capability and identify 
leap-ahead opportunities 
Before leaders can adopt a business-centered cyber security stance, they 
need to determine where their organizations currently stand and the level 
of resources required to support meaningful transformation 
Phase 1 
Threat Understanding 
•Standardize security operational processes 
•Rationalize security tools 
•Implement threat and vulnerability model 
Phase 2 
Contextualize and Detect 
•Map assets to threats and impact, utilizing analytics 
techniques to detect indicators of compromise or attack 
•Optimize and automate both technology and IT process 
•Integrate security analytics and intelligence with security 
operations, align to business outcomes 
Phase 3 
Active Defense and Response 
•Isolate and research threat actor activities 
•Adapt security capability to address evolving threat language 
•Trigger orchestrated, adaptive responses that pre-empt threats 
Copyright © 2014 Accenture All rights reserved. 14
Manage complexity and integrate the enterprise 
Establish an end-to-end enterprise security program and integrate it with 
existing enterprise architecture processes to reduce complexity levels and 
produce outcomes valued by the business 
• Establish a new vision of how security integrates and works with IT and the business, 
effectively creating a security operating model 
• Integrate the security operating model into the overall enterprise architecture, technology 
and processes 
Copyright © 2014 Accenture All rights reserved. 15
Become Agile 
Embrace the cloud and other emerging technologies to boost IT agility and 
reach customers faster, capitalize on efficiency and cost benefits and do so 
within risk tolerances 
Consistently apply technical 
controls for and from the cloud 
to the extended enterprise 
Craft contractual arrangements 
to address third-party service 
provider risk 
Share responsibilities with 
cloud, mobile and social 
providers to improve agility 
in security operations 
1 
2 
3 
Threat-centric 
Strategy 
…drive strategy 
based on how 
the business 
may be attacked 
Threat-centric 
Architecture 
…seek to 
understand the 
shifting threat 
landscape 
Threat-centric 
Operations 
…adapt to 
pre-empt threats 
targeting the 
business 
Copyright © 2014 Accenture All rights reserved. 16
Accelerate toward security intelligence 
Leaders adapt to handle new threats to the enterprise by developing 
threat-centered operations—developing a deep understanding of 
adversaries, their goals and techniques 
• Employ advanced analytics to deliver “context awareness” 
• Assume an active defense stance that increases the level of effort required by an attacker 
and delivers adaptive, intelligent responses 
– Leverage existing instrumentation in the enterprises with threat intelligence feeds and additional 
security event data sources to improve event triage and response performance 
– Identify business initiatives / activities of interest to Threat Actors 
– Incorporation of Threat Management teams in Security Monitoring & Response 
Advanced security analytics 
provide graphic tools to help 
teams analyze large data sets 
visually, supporting rapid, active 
defense responses 
Common User Names – a visualization of the 
top 100 users names used in a brute force attack 
Copyright © 2014 Accenture All rights reserved. 17
Develop end-to-end delivery and flexible sourcing strategies 
Effective security organizations plan a delivery and operational strategy 
for each of the security services they offer 
Considerations 
for Delivery 
and Sourcing 
Determine which services to keep in-house vs. outsource 
to external provider 
Assess the enterprise’s internal competencies for designing, 
building and deploying elements of a cyber-security program 
Justify sourcing decisions based on the overall risk tolerance, 
business case and commercial strategy based on security - 
business alignment 
Selecting partners that will help meet security-business goals 
Dynamic sourcing approach to address security coverage while 
helping leadership focus energy on active defense and proactive 
security capabilities and business enablement 
Copyright © 2014 Accenture All rights reserved. 18
Security call to action 
Copyright © 2014 Accenture All rights reserved. 19
Taking action 
In industries worldwide, security leaders seek effective ways to improve their 
ability to defend against cyber security threats, reduce the risk of inadvertent 
data disclosures, achieve and maintain regulatory compliance, and ultimately 
enhance the value they deliver to their business counterparts and shareholders 
Assess current posture and adopt 
a business-aligned security strategy 
Retain staff experienced with security 
architecture planning and design, tools 
and integration to drive successful 
outcomes 
Establish an end-to-end delivery 
capability, underpinned by a pre-integrated 
security solution set allows organizations 
to modularly select for their specific threat 
areas and adoption pace 
Move to extract more value from the data 
they already collect and analyze 
Focus on managing the risk environment 
instead of concentrating strictly on compliance 
at the expense of strategically securing 
business growth, value and innovation 
Create a clear and complete picture 
of defense strategies and synthesized 
security data to help security leaders make 
rapid, intelligent security decisions based on 
business goals 
Copyright © 2014 Accenture All rights reserved. 20
Visit 
www.accenture.com/IntelligentInfrastructures 
for more information 
Copyright © 2014 Accenture All rights reserved. 21
1 of 21

Recommended

Financial Services - New Approach to Data Management in the Digital Era by
Financial Services - New Approach to Data Management in the Digital EraFinancial Services - New Approach to Data Management in the Digital Era
Financial Services - New Approach to Data Management in the Digital Eraaccenture
5.2K views17 slides
FusionX & Accenture: One Global Security Team by
FusionX & Accenture: One Global Security TeamFusionX & Accenture: One Global Security Team
FusionX & Accenture: One Global Security Teamaccenture
4.1K views10 slides
Cyber Security: Take a Security Leap Forward by
Cyber Security: Take a Security Leap ForwardCyber Security: Take a Security Leap Forward
Cyber Security: Take a Security Leap Forwardaccenture
3.3K views1 slide
Executive Perspective Building an OT Security Program from the Top Down by
Executive Perspective Building an OT Security Program from the Top DownExecutive Perspective Building an OT Security Program from the Top Down
Executive Perspective Building an OT Security Program from the Top Downaccenture
11.2K views11 slides
The Cyber Security Leap: From Laggard to Leader by
The Cyber Security Leap: From Laggard to LeaderThe Cyber Security Leap: From Laggard to Leader
The Cyber Security Leap: From Laggard to Leaderaccenture
6.7K views19 slides
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for... by
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...Accenture Technology
14K views12 slides

More Related Content

What's hot

Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full... by
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...Accenture Technology
5.3K views8 slides
Technology Vision 2016 – Overview by
Technology Vision 2016 – OverviewTechnology Vision 2016 – Overview
Technology Vision 2016 – Overviewaccenture
1.5K views21 slides
Technology Factor: Accelerating Your Journey to As a Service by
Technology Factor: Accelerating Your Journey to As a ServiceTechnology Factor: Accelerating Your Journey to As a Service
Technology Factor: Accelerating Your Journey to As a ServiceAccenture Operations
355 views14 slides
Continuous cyber attacks: Building the next-gen infrastructure by
Continuous cyber attacks: Building the next-gen infrastructure Continuous cyber attacks: Building the next-gen infrastructure
Continuous cyber attacks: Building the next-gen infrastructure Accenture Operations
9.1K views9 slides
The New World of As a Service - Infographic by
The New World of As a Service - InfographicThe New World of As a Service - Infographic
The New World of As a Service - Infographicaccenture
4.3K views1 slide
Corrosion Management by
Corrosion ManagementCorrosion Management
Corrosion Managementaccenture
22.9K views14 slides

What's hot(19)

Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full... by Accenture Technology
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal - Full...
Technology Vision 2016 – Overview by accenture
Technology Vision 2016 – OverviewTechnology Vision 2016 – Overview
Technology Vision 2016 – Overview
accenture1.5K views
Technology Factor: Accelerating Your Journey to As a Service by Accenture Operations
Technology Factor: Accelerating Your Journey to As a ServiceTechnology Factor: Accelerating Your Journey to As a Service
Technology Factor: Accelerating Your Journey to As a Service
Continuous cyber attacks: Building the next-gen infrastructure by Accenture Operations
Continuous cyber attacks: Building the next-gen infrastructure Continuous cyber attacks: Building the next-gen infrastructure
Continuous cyber attacks: Building the next-gen infrastructure
The New World of As a Service - Infographic by accenture
The New World of As a Service - InfographicThe New World of As a Service - Infographic
The New World of As a Service - Infographic
accenture4.3K views
Corrosion Management by accenture
Corrosion ManagementCorrosion Management
Corrosion Management
accenture22.9K views
Harnessing the Power of Entrepreneurs to Open Innovation by Accenture Operations
Harnessing the Power of Entrepreneurs to Open InnovationHarnessing the Power of Entrepreneurs to Open Innovation
Harnessing the Power of Entrepreneurs to Open Innovation
Making the most of Guidewire to transform your insurance organization by Accenture Insurance
Making the most of Guidewire to transform your insurance organizationMaking the most of Guidewire to transform your insurance organization
Making the most of Guidewire to transform your insurance organization
Accenture Learning Academy by accenture
Accenture Learning AcademyAccenture Learning Academy
Accenture Learning Academy
accenture17.4K views
Navigating the Crude Cycle: 4 lines of attack for US E&P energy companies to ... by accenture
Navigating the Crude Cycle: 4 lines of attack for US E&P energy companies to ...Navigating the Crude Cycle: 4 lines of attack for US E&P energy companies to ...
Navigating the Crude Cycle: 4 lines of attack for US E&P energy companies to ...
accenture1.5K views
Mastering Operational Flexibility by accenture
Mastering Operational FlexibilityMastering Operational Flexibility
Mastering Operational Flexibility
accenture10.8K views
Healthcare Payers: 2018 State of Cyber Resilience by accenture
Healthcare Payers: 2018 State of Cyber ResilienceHealthcare Payers: 2018 State of Cyber Resilience
Healthcare Payers: 2018 State of Cyber Resilience
accenture3.7K views
Push to Pull: From Supply Chains to Patient-Centric Value Networks by accenture
Push to Pull: From Supply Chains  to Patient-Centric Value NetworksPush to Pull: From Supply Chains  to Patient-Centric Value Networks
Push to Pull: From Supply Chains to Patient-Centric Value Networks
accenture3.1K views
Intelligent Infrastructures: Unlocking the Digital Business by accenture
Intelligent Infrastructures: Unlocking the Digital BusinessIntelligent Infrastructures: Unlocking the Digital Business
Intelligent Infrastructures: Unlocking the Digital Business
accenture6.6K views
CPG Companies: Evolving Your Analytics-driven Organizations by accenture
CPG Companies: Evolving Your Analytics-driven OrganizationsCPG Companies: Evolving Your Analytics-driven Organizations
CPG Companies: Evolving Your Analytics-driven Organizations
accenture6.6K views
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal by Accenture Technology
Continuous Cyber Attacks: Engaging Business Leaders for the New NormalContinuous Cyber Attacks: Engaging Business Leaders for the New Normal
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal
Accenture Technology25.6K views
The New World of As a Service by accenture
The New World of As a ServiceThe New World of As a Service
The New World of As a Service
accenture94.2K views
Technology Factor: Accelerating Your Journey to As a Service by accenture
Technology Factor: Accelerating Your Journey to As a ServiceTechnology Factor: Accelerating Your Journey to As a Service
Technology Factor: Accelerating Your Journey to As a Service
accenture18.7K views
Security Implications of Accenture Technology Vision 2015 - Executive Report by Accenture Technology
Security Implications of Accenture Technology Vision 2015 - Executive ReportSecurity Implications of Accenture Technology Vision 2015 - Executive Report
Security Implications of Accenture Technology Vision 2015 - Executive Report

Viewers also liked

Its & complex safety by
Its & complex safetyIts & complex safety
Its & complex safetysergey-shchemenok
441 views12 slides
Viyya Ssms Overview 2009 by
Viyya Ssms Overview 2009Viyya Ssms Overview 2009
Viyya Ssms Overview 2009guestee358
381 views19 slides
International Conference on Building Security Capacity by
International Conference on Building Security CapacityInternational Conference on Building Security Capacity
International Conference on Building Security CapacityAustralian Civil-Military Centre
853 views30 slides
120229 Fm Tec Intelligent Security Containers Quick Info 2012 by
120229 Fm Tec Intelligent Security Containers Quick Info 2012120229 Fm Tec Intelligent Security Containers Quick Info 2012
120229 Fm Tec Intelligent Security Containers Quick Info 2012Bindner
471 views14 slides
Seminar ppt...; ) by
Seminar ppt...; )Seminar ppt...; )
Seminar ppt...; )Priya_Srivastava
24.3K views41 slides
Abb85fb57f02f7b85c8eba91f28b7c99 (1) by
Abb85fb57f02f7b85c8eba91f28b7c99 (1)Abb85fb57f02f7b85c8eba91f28b7c99 (1)
Abb85fb57f02f7b85c8eba91f28b7c99 (1)Galina Yaceiko
269 views21 slides

Viewers also liked(6)

Viyya Ssms Overview 2009 by guestee358
Viyya Ssms Overview 2009Viyya Ssms Overview 2009
Viyya Ssms Overview 2009
guestee358381 views
120229 Fm Tec Intelligent Security Containers Quick Info 2012 by Bindner
120229 Fm Tec Intelligent Security Containers Quick Info 2012120229 Fm Tec Intelligent Security Containers Quick Info 2012
120229 Fm Tec Intelligent Security Containers Quick Info 2012
Bindner471 views
Abb85fb57f02f7b85c8eba91f28b7c99 (1) by Galina Yaceiko
Abb85fb57f02f7b85c8eba91f28b7c99 (1)Abb85fb57f02f7b85c8eba91f28b7c99 (1)
Abb85fb57f02f7b85c8eba91f28b7c99 (1)
Galina Yaceiko269 views

Similar to Intelligent Security: Defending the Digital Business

The Open Group - ZT Commandments and Reference Model.pptx by
The Open Group - ZT Commandments and Reference Model.pptxThe Open Group - ZT Commandments and Reference Model.pptx
The Open Group - ZT Commandments and Reference Model.pptxMark Simos
393 views43 slides
New technologies - Amer Haza'a by
New technologies - Amer Haza'aNew technologies - Amer Haza'a
New technologies - Amer Haza'aFahmi Albaheth
361 views54 slides
7 Steps To Developing A Cloud Security Plan by
7 Steps To Developing A Cloud Security Plan7 Steps To Developing A Cloud Security Plan
7 Steps To Developing A Cloud Security PlanEnvision Technology Advisors
919 views15 slides
Security-Brochure by
Security-BrochureSecurity-Brochure
Security-BrochureTyler Carlson
52 views12 slides
Security-Brochure by
Security-BrochureSecurity-Brochure
Security-BrochurePrahlad Reddy
115 views12 slides
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for... by
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...Accenture Technology
857 views1 slide

Similar to Intelligent Security: Defending the Digital Business(20)

The Open Group - ZT Commandments and Reference Model.pptx by Mark Simos
The Open Group - ZT Commandments and Reference Model.pptxThe Open Group - ZT Commandments and Reference Model.pptx
The Open Group - ZT Commandments and Reference Model.pptx
Mark Simos393 views
New technologies - Amer Haza'a by Fahmi Albaheth
New technologies - Amer Haza'aNew technologies - Amer Haza'a
New technologies - Amer Haza'a
Fahmi Albaheth361 views
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for... by Accenture Technology
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
For the CISO: Continuous Cyber Attacks - Achieving Operational Excellence for...
Integrating-Cyber-Security-for-Increased-Effectiveness by Ayham Kochaji
Integrating-Cyber-Security-for-Increased-EffectivenessIntegrating-Cyber-Security-for-Increased-Effectiveness
Integrating-Cyber-Security-for-Increased-Effectiveness
Ayham Kochaji150 views
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal by Accenture Operations
Continuous Cyber Attacks: Engaging Business Leaders for the New NormalContinuous Cyber Attacks: Engaging Business Leaders for the New Normal
Continuous Cyber Attacks: Engaging Business Leaders for the New Normal
Fortify-Application_Security_Foundation_Training.pptx by VictoriaChavesta
Fortify-Application_Security_Foundation_Training.pptxFortify-Application_Security_Foundation_Training.pptx
Fortify-Application_Security_Foundation_Training.pptx
VictoriaChavesta86 views
MCGlobalTech Consulting Service Presentation by William McBorrough
MCGlobalTech Consulting Service PresentationMCGlobalTech Consulting Service Presentation
MCGlobalTech Consulting Service Presentation
William McBorrough447 views
BATbern48_How Zero Trust can help your organisation keep safe.pdf by BATbern
BATbern48_How Zero Trust can help your organisation keep safe.pdfBATbern48_How Zero Trust can help your organisation keep safe.pdf
BATbern48_How Zero Trust can help your organisation keep safe.pdf
BATbern321 views
Cybersecurity Best Practices in Financial Services by John Rapa
Cybersecurity Best Practices in Financial ServicesCybersecurity Best Practices in Financial Services
Cybersecurity Best Practices in Financial Services
John Rapa765 views
Seccuris-Overview-OneSheet-051415 by Kevin Hosey
Seccuris-Overview-OneSheet-051415Seccuris-Overview-OneSheet-051415
Seccuris-Overview-OneSheet-051415
Kevin Hosey66 views

More from accenture

The Industrialist: Trends & Innovations - September 2023 by
The Industrialist: Trends & Innovations - September 2023The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023accenture
178 views12 slides
Accenture Technology Vision - How the trends apply to higher education by
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education accenture
1.7K views25 slides
The Industrialist: Trends & Innovations - July 2023 by
The Industrialist: Trends & Innovations - July 2023The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023accenture
176 views12 slides
Accenture Technology Vision - How the trends apply to higher education by
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education accenture
1.9K views25 slides
Engineering Services: con gli ingegneri per creare valore sostenibile by
Engineering Services: con gli ingegneri per creare valore sostenibileEngineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibileaccenture
1.5K views5 slides
Digital Euro: Implications for the Financial System by
Digital Euro: Implications for the Financial SystemDigital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial Systemaccenture
369 views36 slides

More from accenture(20)

The Industrialist: Trends & Innovations - September 2023 by accenture
The Industrialist: Trends & Innovations - September 2023The Industrialist: Trends & Innovations - September 2023
The Industrialist: Trends & Innovations - September 2023
accenture178 views
Accenture Technology Vision - How the trends apply to higher education by accenture
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
accenture1.7K views
The Industrialist: Trends & Innovations - July 2023 by accenture
The Industrialist: Trends & Innovations - July 2023The Industrialist: Trends & Innovations - July 2023
The Industrialist: Trends & Innovations - July 2023
accenture176 views
Accenture Technology Vision - How the trends apply to higher education by accenture
Accenture Technology Vision - How the trends apply to higher education Accenture Technology Vision - How the trends apply to higher education
Accenture Technology Vision - How the trends apply to higher education
accenture1.9K views
Engineering Services: con gli ingegneri per creare valore sostenibile by accenture
Engineering Services: con gli ingegneri per creare valore sostenibileEngineering Services: con gli ingegneri per creare valore sostenibile
Engineering Services: con gli ingegneri per creare valore sostenibile
accenture1.5K views
Digital Euro: Implications for the Financial System by accenture
Digital Euro: Implications for the Financial SystemDigital Euro: Implications for the Financial System
Digital Euro: Implications for the Financial System
accenture369 views
More deals, less money: the Black founder funding journey by accenture
More deals, less money: the Black founder funding journeyMore deals, less money: the Black founder funding journey
More deals, less money: the Black founder funding journey
accenture3.2K views
The Industrialist: Trends & Innovations - June 2023 by accenture
The Industrialist: Trends & Innovations - June 2023The Industrialist: Trends & Innovations - June 2023
The Industrialist: Trends & Innovations - June 2023
accenture121 views
Reinventing Enterprise Operations by accenture
Reinventing Enterprise OperationsReinventing Enterprise Operations
Reinventing Enterprise Operations
accenture1.3K views
Semiconductor Gender Parity Study by accenture
Semiconductor Gender Parity StudySemiconductor Gender Parity Study
Semiconductor Gender Parity Study
accenture1.7K views
The Industrialist: Trends & Innovations - March 2023 by accenture
The Industrialist: Trends & Innovations - March 2023The Industrialist: Trends & Innovations - March 2023
The Industrialist: Trends & Innovations - March 2023
accenture192 views
Nonprofit reinvention in a time of unprecedented change by accenture
 Nonprofit reinvention in a time of unprecedented change Nonprofit reinvention in a time of unprecedented change
Nonprofit reinvention in a time of unprecedented change
accenture5.7K views
Free to be 100% me by accenture
Free to be 100% meFree to be 100% me
Free to be 100% me
accenture359 views
The Industrialist: Trends & Innovations - February 2023 by accenture
The Industrialist: Trends & Innovations - February 2023The Industrialist: Trends & Innovations - February 2023
The Industrialist: Trends & Innovations - February 2023
accenture218 views
Mundo gamer e a oportunidade de entrada pela abordagem do movimento by accenture
Mundo gamer e a oportunidade de entrada pela abordagem do movimentoMundo gamer e a oportunidade de entrada pela abordagem do movimento
Mundo gamer e a oportunidade de entrada pela abordagem do movimento
accenture752 views
Pathways to Profitability for the Communications Industry by accenture
Pathways to Profitability for the Communications IndustryPathways to Profitability for the Communications Industry
Pathways to Profitability for the Communications Industry
accenture6.4K views
The Industrialist: Trends & Innovations - January 2023 by accenture
The Industrialist: Trends & Innovations - January 2023The Industrialist: Trends & Innovations - January 2023
The Industrialist: Trends & Innovations - January 2023
accenture222 views
Reimagining the Agenda | Accenture by accenture
Reimagining the Agenda | AccentureReimagining the Agenda | Accenture
Reimagining the Agenda | Accenture
accenture30.2K views
Climate Leadership Eleventh Hour | Accenture by accenture
Climate Leadership Eleventh Hour | AccentureClimate Leadership Eleventh Hour | Accenture
Climate Leadership Eleventh Hour | Accenture
accenture2K views
Value Untangled Slideshare by accenture
Value Untangled SlideshareValue Untangled Slideshare
Value Untangled Slideshare
accenture1.9K views

Recently uploaded

Uni Systems for Power Platform.pptx by
Uni Systems for Power Platform.pptxUni Systems for Power Platform.pptx
Uni Systems for Power Platform.pptxUni Systems S.M.S.A.
55 views21 slides
PRODUCT LISTING.pptx by
PRODUCT LISTING.pptxPRODUCT LISTING.pptx
PRODUCT LISTING.pptxangelicacueva6
13 views1 slide
GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N... by
GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...
GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...James Anderson
66 views32 slides
AMAZON PRODUCT RESEARCH.pdf by
AMAZON PRODUCT RESEARCH.pdfAMAZON PRODUCT RESEARCH.pdf
AMAZON PRODUCT RESEARCH.pdfJerikkLaureta
19 views13 slides
Network Source of Truth and Infrastructure as Code revisited by
Network Source of Truth and Infrastructure as Code revisitedNetwork Source of Truth and Infrastructure as Code revisited
Network Source of Truth and Infrastructure as Code revisitedNetwork Automation Forum
25 views45 slides
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf by
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdfDr. Jimmy Schwarzkopf
16 views29 slides

Recently uploaded(20)

GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N... by James Anderson
GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...
GDG Cloud Southlake 28 Brad Taylor and Shawn Augenstein Old Problems in the N...
James Anderson66 views
AMAZON PRODUCT RESEARCH.pdf by JerikkLaureta
AMAZON PRODUCT RESEARCH.pdfAMAZON PRODUCT RESEARCH.pdf
AMAZON PRODUCT RESEARCH.pdf
JerikkLaureta19 views
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf by Dr. Jimmy Schwarzkopf
STKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdfSTKI Israeli Market Study 2023   corrected forecast 2023_24 v3.pdf
STKI Israeli Market Study 2023 corrected forecast 2023_24 v3.pdf
Serverless computing with Google Cloud (2023-24) by wesley chun
Serverless computing with Google Cloud (2023-24)Serverless computing with Google Cloud (2023-24)
Serverless computing with Google Cloud (2023-24)
wesley chun10 views
The details of description: Techniques, tips, and tangents on alternative tex... by BookNet Canada
The details of description: Techniques, tips, and tangents on alternative tex...The details of description: Techniques, tips, and tangents on alternative tex...
The details of description: Techniques, tips, and tangents on alternative tex...
BookNet Canada126 views
Case Study Copenhagen Energy and Business Central.pdf by Aitana
Case Study Copenhagen Energy and Business Central.pdfCase Study Copenhagen Energy and Business Central.pdf
Case Study Copenhagen Energy and Business Central.pdf
Aitana16 views
Piloting & Scaling Successfully With Microsoft Viva by Richard Harbridge
Piloting & Scaling Successfully With Microsoft VivaPiloting & Scaling Successfully With Microsoft Viva
Piloting & Scaling Successfully With Microsoft Viva
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ... by Jasper Oosterveld
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
ESPC 2023 - Protect and Govern your Sensitive Data with Microsoft Purview in ...
Unit 1_Lecture 2_Physical Design of IoT.pdf by StephenTec
Unit 1_Lecture 2_Physical Design of IoT.pdfUnit 1_Lecture 2_Physical Design of IoT.pdf
Unit 1_Lecture 2_Physical Design of IoT.pdf
StephenTec12 views
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院 by IttrainingIttraining
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院
【USB韌體設計課程】精選講義節錄-USB的列舉過程_艾鍗學院
PharoJS - Zürich Smalltalk Group Meetup November 2023 by Noury Bouraqadi
PharoJS - Zürich Smalltalk Group Meetup November 2023PharoJS - Zürich Smalltalk Group Meetup November 2023
PharoJS - Zürich Smalltalk Group Meetup November 2023
Noury Bouraqadi126 views
STPI OctaNE CoE Brochure.pdf by madhurjyapb
STPI OctaNE CoE Brochure.pdfSTPI OctaNE CoE Brochure.pdf
STPI OctaNE CoE Brochure.pdf
madhurjyapb13 views

Intelligent Security: Defending the Digital Business

  • 1. Intelligent Security: Defending the Digital Business Defending the Digital Business
  • 2. Executive Summary Today Key Business Challenges •Missing link between business goals and security capabilities •Compliance providing a false sense of security •Enterprises are reaping the benefits of enhancing business functionality through cloud, mobile, and social, but struggle governing the extensions to the enterprise •Increasingly sophist security talent to address current security needs A new tomorrow Approach to Intelligent Security • Assess the security program’s capability and identify leap-ahead opportunities • Manage complexity and integrate the enterprise • Become agile • Accelerate toward security intelligence • Develop end-to-end delivery and flexible sourcing strategies How to get there Security Call to Action •The first step is assessing current posture and adopting a business-aligned security strategy •Retain staff experienced with security architecture planning and design, tools and integration to drive successful outcomes •Establishing an end-to-end delivery capability, underpinned by a pre-integrated security solution set allows organizations to modularly select for their specific threat areas and adoption pace •Move to extract more value from the data they already collect and analyze Copyright © 2014 Accenture All rights reserved. 2
  • 3. Key business challenges Copyright © 2014 Accenture All rights reserved. 3
  • 4. Business challenges to security for today’s enterprise Despite all the effort and resources that organizations invest in traditional information security approaches, many still fall prey to the latest cyber threats, or find they are unprepared to deal with rapidly blurring enterprise boundaries Five most common issues companies will have taking a proactive security stance Keeping pace with persistent threats Governing the extended enterprise despite blurring boundaries Thinking outside the compliance (check) box Missing the link between business and security Addressing the security supply/demand imbalance Copyright © 2014 Accenture All rights reserved. 4
  • 5. Missing the link between 1 business and security Protecting the business should be the first and foremost goal of any security program, but most enterprises do not make it a core competency • Untethered programs can drift and become largely ineffective • Some security executives might struggle to draw a clear line between the protection provided and its impact on the company’s customer satisfaction, loyalty and revenue • The Security team may lack a logical road map for changing the organization’s view of the security function as simply an inhibitor or cost center Business Security Copyright © 2014 Accenture All rights reserved. 5
  • 6. Thinking outside of the compliance (check) box 2 Unfortunately, compliance does not ensure security. Instead, enterprises should view compliance as the minimum acceptable cyber security “bar” they need to clear… Compliance •Audit centric •Controls based •Driven largely by regulatory requirements •Sample based •Scope limited by audit domain •Evaluated on a quarterly or annual basis Security •Business centric •Controls based •Driven by business requirements •Scope is holistic-includes enterprise, 3rd parties, suppliers, partners •Evaluated on near-real time basis Copyright © 2014 Accenture All rights reserved. 6
  • 7. Governing the extended enterprise despite blurring boundaries 3 While business adoption has been widespread and rapid, many security organizations struggle to establish the appropriate frameworks, policies and controls to protect the expansions and contractions now common in extended IT environments Typical Day in the Extended Enterprise Cloud Real-time provisioning of servers to support testing of a cloud CRM system Mobile Granting mobile access to new capabilities for field representatives Social network Rollout of a business social network for sales, product and marketing collaboration • What are the appropriate frameworks and policies? • Should I allow personal devices? Which devices and do I let everyone do it? • How do I enable and monitor aaS components being introduced to my environment? • How will I reach my customers with the correct messages? • What do I need to do to make sure exposed by this new enterprise? Copyright © 2014 Accenture All rights reserved. 7
  • 8. 4 Keeping pace with persistent threats As the threats become more persistent, they become harder to identify Most organizations focus on: • Monitoring – Difficulty in prioritizing critical events and handling uncertainty • Static controls – Standard controls don’t help once the attacker is in For which cyber-threat are you prepared? Opportunistic Acts Mob Determined actors Attacker profile: •Will move on if thwarted •Will make mistakes •Can be creative Attacker profile: •Emotional and not disciplined •Not after the crown jewels •Not well backed Attacker profile: •Failure is not an option •Need only one vulnerability •Stick with it mentality Copyright © 2014 Accenture All rights reserved. 8
  • 9. 5 Addressing the security supply/demand imbalance Most organizations lack sufficient security talent to address their current needs Skill Shortages •Lack of the appropriate skills to execute required tasks •Hiring premiums for cyber security resources Career Development •Skilled resources are eager to keep skills sharp and maintain exposure to new technologies Firefighting •Misalignment of security programs to strategic business objectives cause practitioners to burn-out from constant troubleshooting Copyright © 2014 Accenture All rights reserved. 9
  • 10. Net result Compliance driven (or audit scope driven) security scope can cause organizations to implicitly and unknowingly accept a significant amount of cyber-security risk Implicitly accepted risk Enterprise security risk Enterprise security risk Compliance risk Compliance risk Specific regulatory risk Specific regulatory risk Perceived Risk Actual Risk Copyright © 2014 Accenture All rights reserved. 10
  • 11. Approach to Intelligent Security Copyright © 2014 Accenture All rights reserved. 11
  • 12. Vision for Intelligent Security As organizations shift from a compliance-centered security mindset to an active cyber security stance, security teams need to adapt to keep pace with evolving business objectives • Driven by a comprehensive security strategy that is aligned to business goals and objectives • Core business assets protected by robust enterprise security controls • Layered on top are extended enterprise safeguards focused on enabling cloud, mobile and social network adoption • Advanced analytics incorporate cyber threat intelligence to enable proactive, accelerated action • Security metrics to measure enablement of business outcomes Copyright © 2014 Accenture All rights reserved. 12
  • 13. Taking the next steps to address Intelligent Security for the digital enterprise Leading companies develop effective cyber security measures to handle vulnerabilities and mount an active defense calculated to meet and deflect attacker advances Assess security capability, identify opportunities Determine where the organization currently stands and the level of resources required to support meaningful transformation Manage complexity and integrate the enterprise Evolve the security program vision: establish an end-to-end enterprise security program and integrate it with existing enterprise architecture processes to reduce complexity levels and produce outcomes valued by the business Become agile Embrace the cloud and other emerging technologies to boost IT agility and reach customers faster, capitalize on efficiency and cost benefits and do so within risk tolerances Accelerate toward security intelligence Adapt to handle new threats to the enterprise by developing threat-centered operations by developing a deep understanding of adversaries, their goals and techniques Develop end-to-end delivery and sourcing Plan a delivery and operational strategy for each of the security services they offer to make a clear-eyed assessment of internal competencies for designing, building and deploying elements of a cyber-security program Copyright © 2014 Accenture All rights reserved. 13
  • 14. Assess the security program’s capability and identify leap-ahead opportunities Before leaders can adopt a business-centered cyber security stance, they need to determine where their organizations currently stand and the level of resources required to support meaningful transformation Phase 1 Threat Understanding •Standardize security operational processes •Rationalize security tools •Implement threat and vulnerability model Phase 2 Contextualize and Detect •Map assets to threats and impact, utilizing analytics techniques to detect indicators of compromise or attack •Optimize and automate both technology and IT process •Integrate security analytics and intelligence with security operations, align to business outcomes Phase 3 Active Defense and Response •Isolate and research threat actor activities •Adapt security capability to address evolving threat language •Trigger orchestrated, adaptive responses that pre-empt threats Copyright © 2014 Accenture All rights reserved. 14
  • 15. Manage complexity and integrate the enterprise Establish an end-to-end enterprise security program and integrate it with existing enterprise architecture processes to reduce complexity levels and produce outcomes valued by the business • Establish a new vision of how security integrates and works with IT and the business, effectively creating a security operating model • Integrate the security operating model into the overall enterprise architecture, technology and processes Copyright © 2014 Accenture All rights reserved. 15
  • 16. Become Agile Embrace the cloud and other emerging technologies to boost IT agility and reach customers faster, capitalize on efficiency and cost benefits and do so within risk tolerances Consistently apply technical controls for and from the cloud to the extended enterprise Craft contractual arrangements to address third-party service provider risk Share responsibilities with cloud, mobile and social providers to improve agility in security operations 1 2 3 Threat-centric Strategy …drive strategy based on how the business may be attacked Threat-centric Architecture …seek to understand the shifting threat landscape Threat-centric Operations …adapt to pre-empt threats targeting the business Copyright © 2014 Accenture All rights reserved. 16
  • 17. Accelerate toward security intelligence Leaders adapt to handle new threats to the enterprise by developing threat-centered operations—developing a deep understanding of adversaries, their goals and techniques • Employ advanced analytics to deliver “context awareness” • Assume an active defense stance that increases the level of effort required by an attacker and delivers adaptive, intelligent responses – Leverage existing instrumentation in the enterprises with threat intelligence feeds and additional security event data sources to improve event triage and response performance – Identify business initiatives / activities of interest to Threat Actors – Incorporation of Threat Management teams in Security Monitoring & Response Advanced security analytics provide graphic tools to help teams analyze large data sets visually, supporting rapid, active defense responses Common User Names – a visualization of the top 100 users names used in a brute force attack Copyright © 2014 Accenture All rights reserved. 17
  • 18. Develop end-to-end delivery and flexible sourcing strategies Effective security organizations plan a delivery and operational strategy for each of the security services they offer Considerations for Delivery and Sourcing Determine which services to keep in-house vs. outsource to external provider Assess the enterprise’s internal competencies for designing, building and deploying elements of a cyber-security program Justify sourcing decisions based on the overall risk tolerance, business case and commercial strategy based on security - business alignment Selecting partners that will help meet security-business goals Dynamic sourcing approach to address security coverage while helping leadership focus energy on active defense and proactive security capabilities and business enablement Copyright © 2014 Accenture All rights reserved. 18
  • 19. Security call to action Copyright © 2014 Accenture All rights reserved. 19
  • 20. Taking action In industries worldwide, security leaders seek effective ways to improve their ability to defend against cyber security threats, reduce the risk of inadvertent data disclosures, achieve and maintain regulatory compliance, and ultimately enhance the value they deliver to their business counterparts and shareholders Assess current posture and adopt a business-aligned security strategy Retain staff experienced with security architecture planning and design, tools and integration to drive successful outcomes Establish an end-to-end delivery capability, underpinned by a pre-integrated security solution set allows organizations to modularly select for their specific threat areas and adoption pace Move to extract more value from the data they already collect and analyze Focus on managing the risk environment instead of concentrating strictly on compliance at the expense of strategically securing business growth, value and innovation Create a clear and complete picture of defense strategies and synthesized security data to help security leaders make rapid, intelligent security decisions based on business goals Copyright © 2014 Accenture All rights reserved. 20
  • 21. Visit www.accenture.com/IntelligentInfrastructures for more information Copyright © 2014 Accenture All rights reserved. 21