SlideShare a Scribd company logo
1 of 30
Opening Keynote at the Operational
Resilience Summit in Financial Services
Measuring
operational resilience & regulatory compliance
to mitigate harm from cyber-attacks on the extended enterprise
Kevin Duffey, CEO, Cyber Rescue Alliance, 19
th
November 2019
Opening Keynote at the Operational
Resilience Summit in Financial Services
Measurement drives maturity
So please participate – anonymously – in today’s measurements
2
#OpRes
About 210 delegates
attended the Summit
on Operational
Resilience in Financial
Services on 18
November 2019.
Delegates interacted
via Slido.
Responses on one
question are shown on
the right.
Opening Keynote at the Operational
Resilience Summit in Financial Services
You’re sitting near some world leaders
in Operational Resilience
Opening Keynote at the Operational
Resilience Summit in Financial Services
Opening Keynote at the Operational
Resilience Summit in Financial Services
You’re sitting near some world leaders
in Operational Resilience
www.slido.com #OpRes
Some world leaders in Operational Resilience
Opening Keynote at the Operational
Resilience Summit in Financial Services
Opening Keynote at the Operational
Resilience Summit in Financial Services
Discussion Paper: July 2018
5
Operational Resilience is the ability to prevent, respond to, recover
and learn from operational disruptions, that might include:
• physical attacks
• cyber attacks
• IT system outages
• third-party supplier failure
• fire, flood, severe weather and pandemic flu
Building the UK financial sector’s operational resilience
Opening Keynote at the Operational
Resilience Summit in Financial Services
Measurement drives maturity
So please participate – anonymously – in today’s measurements
6
#OpRes
About 210 delegates
attended the Summit
on Operational
Resilience in Financial
Services on 18
November 2019.
Delegates interacted
via Slido.
Responses on one
question are shown on
the right.
Opening Keynote at the Operational
Resilience Summit in Financial Services
Sources of Risk to UK Financial System
Future of Finance review by Huw van Steenis – June 2019
Opening Keynote at the Operational
Resilience Summit in Financial Services
Cyber & Technology Resilience: FCA Survey
Research – First published: 27/11/2018 – Last updated:
14/01/2019
3rd Party Failure
Cyber Attack
Opening Keynote at the Operational
Resilience Summit in Financial Services
UK Share of Phishing Attacks, worldwide
National Cyber Security Centre, August 2019
Opening Keynote at the Operational
Resilience Summit in Financial Services
Cyber & Technology Resilience: FCA Survey
Research – First published: 27/11/2018 – Last updated:
14/01/2019
Financial ServicesGrowth in peak size of
“Denial of Service”
cyber attacks
Percentage of targets
of “Denial of Service”
cyber attacks
Opening Keynote at the Operational
Resilience Summit in Financial Services
Opening Keynote at the Operational
Resilience Summit in Financial Services
Richard F Smith, former CEO of Equifax
“The challenge of building a website to
notify consumers proved overwhelming,
and regrettably, mistakes were made.”
Richard F. Smith, 4th Oct 2017
Opening Keynote at the Operational
Resilience Summit in Financial Services
Report on Recovery Plans
European Central Bank – July 2018
Financial Services
The ECB has
concluded
that some
plans "might
be too large to
actually be
used in a
crisis.”
Opening Keynote at the Operational
Resilience Summit in Financial Services
Report on Recovery Plans
European Central Bank – July 2018
Financial Services
Opening Keynote at the Operational
Resilience Summit in Financial Services
Richard F Smith, former CEO of Equifax
Opening Keynote at the Operational
Resilience Summit in Financial Services
March 8th, 2019
Opening Keynote at the Operational
Resilience Summit in Financial Services
March 8th, 2019
Equifax Used What Internal Auditors Called an “Honor System” for
Patching Vulnerabilities.
Equifax had no formalized method of validating the successful installation
of patches. Audit referred to this approach as an “honor system” in which
the IT team would notify the security team once patches were complete.
Opening Keynote at the Operational
Resilience Summit in Financial Services
What does an
“honor system” for
patching look like?
Opening Keynote at the Operational
Resilience Summit in Financial Services
What does an
“honor system” for
patching look like?
Opening Keynote at the Operational
Resilience Summit in Financial Services
What does an
“honor system” for
patching look like?
Opening Keynote at the Operational
Resilience Summit in Financial Services
CQUEST
CQUEST consists of multiple-choice questions covering all aspects of cyber resilience, such as:
• Does the firm have a board-approved cyber security strategy?
• How does it identify and protect its critical assets?
• How does it detect and respond to an incident, recover and learn from the experience?
New cyber resilience assessment from PRA & FCA
21
Opening Keynote at the Operational
Resilience Summit in Financial Services
Measurement of Cyber Risk should be as
objective, timely & dynamic as for Market Risk
Opening Keynote at the Operational
Resilience Summit in Financial Services
Automated measurement drives behaviour
At least monthly, present an objective Security Scorecard showing trends
Overall Grade
Application Security
DNS Health
Network Security
Patching Cadence
Opening Keynote at the Operational
Resilience Summit in Financial Services
Resilience across Extended Enterprise
Regulators have woken up to third party & supply chain cyber risks
24
Entities should review third parties on an ongoing
basis to manage their cyber risks.
Entities should include critical third parties when they
exercise their cyber incident response plans.
What are your expectations of suppliers' security?
How much will you pay extra to a secure supplier?
21 March 2019
Opening Keynote at the Operational
Resilience Summit in Financial Services
Cyber Risk is dynamic
25
Suppliers with a poor cyber score can get much worse very quickly
This supplier
had a very low
score (72) for
most of 2019.
Then
something
happened at
end of June.
Opening Keynote at the Operational
Resilience Summit in Financial Services
Measurement drives maturity
So please participate – anonymously – in today’s measurements
26
#OpRes
About 210 delegates
attended the Summit
on Operational
Resilience in Financial
Services on 18
November 2019.
Delegates interacted
via Slido.
Responses on one
question are shown on
the right.
Opening Keynote at the Operational
Resilience Summit in Financial Services
Cyber Risk is dynamic
27
How quickly should you know that a supplier has been compromised?
An obvious reason their
score has a low score in July
is that its systems were not
just vulnerable: they were
compromised.
Malware was being
distributed from their
systems, starting at the end
of June.
Example Supplier
Opening Keynote at the Operational
Resilience Summit in Financial Services
How to measure cyber risk at Peers?
28
Your security will never be perfect, but you should know if it’s worse than average
Censored Censored Censored Censored Censored
Opening Keynote at the Operational
Resilience Summit in Financial Services
How to measure cyber risk at Suppliers?
29
The greatest risk of your data being breached is via your suppliers
Censored Censored Censored Censored Censored Censored
Opening Keynote at the Operational
Resilience Summit in Financial Services
Let’s work together to build
Operational Resilience
Please connect on LinkedIn to Kevin Duffey

More Related Content

What's hot

How Robo Advisers, Fintech Are Revolutionising Wealth Management
How Robo Advisers, Fintech  Are Revolutionising  Wealth ManagementHow Robo Advisers, Fintech  Are Revolutionising  Wealth Management
How Robo Advisers, Fintech Are Revolutionising Wealth ManagementDinis Guarda
 
Roadmap blockchain nasional australia
Roadmap blockchain nasional australiaRoadmap blockchain nasional australia
Roadmap blockchain nasional australiaRein Mahatma
 
4th Digital Finance Forum, Simon Brady
4th Digital Finance Forum, Simon Brady4th Digital Finance Forum, Simon Brady
4th Digital Finance Forum, Simon BradyStarttech Ventures
 
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...Lesa Moné
 
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...Investorideas.com
 
Fintech regulations presentation
Fintech regulations presentationFintech regulations presentation
Fintech regulations presentationJoseph Rubin
 
Deloitte stay ahed of the game
Deloitte stay ahed of the gameDeloitte stay ahed of the game
Deloitte stay ahed of the gameFranco Ferrario
 
PWC - Global FinTech Report 2017 - startup
PWC - Global FinTech Report 2017 - startup PWC - Global FinTech Report 2017 - startup
PWC - Global FinTech Report 2017 - startup Ian Beckett
 
Hexlant Octet Pitch Deck
Hexlant Octet Pitch DeckHexlant Octet Pitch Deck
Hexlant Octet Pitch DeckWonhoKim17
 
Keeping security relevant amid digital transformation
Keeping security relevant amid digital transformationKeeping security relevant amid digital transformation
Keeping security relevant amid digital transformationSymptai Consulting Limited
 
Asia vc-bamboo-report-ii-2016 q1
Asia vc-bamboo-report-ii-2016 q1Asia vc-bamboo-report-ii-2016 q1
Asia vc-bamboo-report-ii-2016 q1Rein Mahatma
 
2022 Cybersecurity Predictions
2022 Cybersecurity Predictions2022 Cybersecurity Predictions
2022 Cybersecurity PredictionsMatthew Rosenquist
 
PWC - Global FinTech Report 2017
PWC - Global FinTech Report 2017PWC - Global FinTech Report 2017
PWC - Global FinTech Report 2017Ian Beckett
 
FinTech ecosystem playbook
FinTech ecosystem playbookFinTech ecosystem playbook
FinTech ecosystem playbookEY
 
ScotSecure 2020
ScotSecure 2020ScotSecure 2020
ScotSecure 2020Ray Bugg
 
EmergentX Digital Asset Outlook 2022 - Consilience
EmergentX Digital Asset Outlook 2022 - ConsilienceEmergentX Digital Asset Outlook 2022 - Consilience
EmergentX Digital Asset Outlook 2022 - ConsilienceEmergentXDigitalAsse
 
Libor Executive Summary
Libor Executive Summary Libor Executive Summary
Libor Executive Summary Daniel Connor
 
eCrime-report-2011-accessible
eCrime-report-2011-accessibleeCrime-report-2011-accessible
eCrime-report-2011-accessibleCharmaine Servado
 

What's hot (19)

How Robo Advisers, Fintech Are Revolutionising Wealth Management
How Robo Advisers, Fintech  Are Revolutionising  Wealth ManagementHow Robo Advisers, Fintech  Are Revolutionising  Wealth Management
How Robo Advisers, Fintech Are Revolutionising Wealth Management
 
Roadmap blockchain nasional australia
Roadmap blockchain nasional australiaRoadmap blockchain nasional australia
Roadmap blockchain nasional australia
 
4th Digital Finance Forum, Simon Brady
4th Digital Finance Forum, Simon Brady4th Digital Finance Forum, Simon Brady
4th Digital Finance Forum, Simon Brady
 
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
Takeaways from the Financial Action Task Force's Guidance on Virtual Assets a...
 
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...
Speaker Kiersten E. Todt, President and Managing Partner, Liberty Group Ventu...
 
Fintech regulations presentation
Fintech regulations presentationFintech regulations presentation
Fintech regulations presentation
 
Deloitte stay ahed of the game
Deloitte stay ahed of the gameDeloitte stay ahed of the game
Deloitte stay ahed of the game
 
PWC - Global FinTech Report 2017 - startup
PWC - Global FinTech Report 2017 - startup PWC - Global FinTech Report 2017 - startup
PWC - Global FinTech Report 2017 - startup
 
FT Partners Research: The Rise of Challenger Banks
FT Partners Research: The Rise of Challenger BanksFT Partners Research: The Rise of Challenger Banks
FT Partners Research: The Rise of Challenger Banks
 
Hexlant Octet Pitch Deck
Hexlant Octet Pitch DeckHexlant Octet Pitch Deck
Hexlant Octet Pitch Deck
 
Keeping security relevant amid digital transformation
Keeping security relevant amid digital transformationKeeping security relevant amid digital transformation
Keeping security relevant amid digital transformation
 
Asia vc-bamboo-report-ii-2016 q1
Asia vc-bamboo-report-ii-2016 q1Asia vc-bamboo-report-ii-2016 q1
Asia vc-bamboo-report-ii-2016 q1
 
2022 Cybersecurity Predictions
2022 Cybersecurity Predictions2022 Cybersecurity Predictions
2022 Cybersecurity Predictions
 
PWC - Global FinTech Report 2017
PWC - Global FinTech Report 2017PWC - Global FinTech Report 2017
PWC - Global FinTech Report 2017
 
FinTech ecosystem playbook
FinTech ecosystem playbookFinTech ecosystem playbook
FinTech ecosystem playbook
 
ScotSecure 2020
ScotSecure 2020ScotSecure 2020
ScotSecure 2020
 
EmergentX Digital Asset Outlook 2022 - Consilience
EmergentX Digital Asset Outlook 2022 - ConsilienceEmergentX Digital Asset Outlook 2022 - Consilience
EmergentX Digital Asset Outlook 2022 - Consilience
 
Libor Executive Summary
Libor Executive Summary Libor Executive Summary
Libor Executive Summary
 
eCrime-report-2011-accessible
eCrime-report-2011-accessibleeCrime-report-2011-accessible
eCrime-report-2011-accessible
 

Similar to Keynote at Operational Resilience summit - Financial Services - 18th Nov 2019

Quantifi newsletter Insight autumn 2015
Quantifi newsletter Insight autumn 2015Quantifi newsletter Insight autumn 2015
Quantifi newsletter Insight autumn 2015Quantifi
 
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...International Federation of Accountants
 
Cybersecurity In The Cognitive Era: Priming Your Digital Immune System
Cybersecurity In The Cognitive Era: Priming Your Digital Immune SystemCybersecurity In The Cognitive Era: Priming Your Digital Immune System
Cybersecurity In The Cognitive Era: Priming Your Digital Immune SystemIBM Security
 
MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018Match-Maker Ventures
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryCitrin Cooperman
 
Cybersecurity in the Cognitive Era: Priming Your Digital Immune System
Cybersecurity in the Cognitive Era: Priming Your Digital Immune SystemCybersecurity in the Cognitive Era: Priming Your Digital Immune System
Cybersecurity in the Cognitive Era: Priming Your Digital Immune SystemIBM Security
 
The Board and Cyber Security
The Board and Cyber SecurityThe Board and Cyber Security
The Board and Cyber SecurityFireEye, Inc.
 
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019Utility Networks Agile Response Capabilities - New Context at EnergySec 2019
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019Andrew Storms
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security GovernancePriyanka Aash
 
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...CBIZ, Inc.
 
Cybersecurity Risk Management for Financial Institutions
Cybersecurity Risk Management for Financial InstitutionsCybersecurity Risk Management for Financial Institutions
Cybersecurity Risk Management for Financial InstitutionsSarah Cirelli
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursColleen Beck-Domanico
 
Webinar-MSP+ Cyber Insurance Fina.pptx
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptxControlCase
 
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...poore120
 
Approaches to Cyber Resilience and Supply Chain Assurance
Approaches to Cyber Resilience and Supply Chain AssuranceApproaches to Cyber Resilience and Supply Chain Assurance
Approaches to Cyber Resilience and Supply Chain AssuranceLeonardo
 
PCM Vision 2019 Keynote: Gary Miglicco
PCM Vision 2019 Keynote: Gary MigliccoPCM Vision 2019 Keynote: Gary Miglicco
PCM Vision 2019 Keynote: Gary MigliccoPCM
 
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...Taiye Lambo
 
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010ARC Advisory Group
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksColleen Beck-Domanico
 

Similar to Keynote at Operational Resilience summit - Financial Services - 18th Nov 2019 (20)

Quantifi newsletter Insight autumn 2015
Quantifi newsletter Insight autumn 2015Quantifi newsletter Insight autumn 2015
Quantifi newsletter Insight autumn 2015
 
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
 
Cybersecurity In The Cognitive Era: Priming Your Digital Immune System
Cybersecurity In The Cognitive Era: Priming Your Digital Immune SystemCybersecurity In The Cognitive Era: Priming Your Digital Immune System
Cybersecurity In The Cognitive Era: Priming Your Digital Immune System
 
HEMISPHERE SMB Case Study
HEMISPHERE SMB Case StudyHEMISPHERE SMB Case Study
HEMISPHERE SMB Case Study
 
MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018
 
Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services Industry
 
Cybersecurity in the Cognitive Era: Priming Your Digital Immune System
Cybersecurity in the Cognitive Era: Priming Your Digital Immune SystemCybersecurity in the Cognitive Era: Priming Your Digital Immune System
Cybersecurity in the Cognitive Era: Priming Your Digital Immune System
 
The Board and Cyber Security
The Board and Cyber SecurityThe Board and Cyber Security
The Board and Cyber Security
 
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019Utility Networks Agile Response Capabilities - New Context at EnergySec 2019
Utility Networks Agile Response Capabilities - New Context at EnergySec 2019
 
Cyber Security Governance
Cyber Security GovernanceCyber Security Governance
Cyber Security Governance
 
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...
CBIZ Quarterly Manufacturing & Distribution “Hot Topics” Newsletter (Sep-Oct ...
 
Cybersecurity Risk Management for Financial Institutions
Cybersecurity Risk Management for Financial InstitutionsCybersecurity Risk Management for Financial Institutions
Cybersecurity Risk Management for Financial Institutions
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident Occurs
 
Webinar-MSP+ Cyber Insurance Fina.pptx
Webinar-MSP+  Cyber Insurance Fina.pptxWebinar-MSP+  Cyber Insurance Fina.pptx
Webinar-MSP+ Cyber Insurance Fina.pptx
 
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...SecureTech 2014:  Risk, Business Continuity and Cybersecurity - A Resiliency ...
SecureTech 2014: Risk, Business Continuity and Cybersecurity - A Resiliency ...
 
Approaches to Cyber Resilience and Supply Chain Assurance
Approaches to Cyber Resilience and Supply Chain AssuranceApproaches to Cyber Resilience and Supply Chain Assurance
Approaches to Cyber Resilience and Supply Chain Assurance
 
PCM Vision 2019 Keynote: Gary Miglicco
PCM Vision 2019 Keynote: Gary MigliccoPCM Vision 2019 Keynote: Gary Miglicco
PCM Vision 2019 Keynote: Gary Miglicco
 
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
{d1a164b5-f3a5-4840-96b1-16dd83ccdda9}_Wells_Fargo_GIB_Cyber_security_100615_...
 
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010
ARC's Bob Mick Cyber Security Presentation @ ARC Industry Forum 2010
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community Banks
 

More from Kevin Duffey

Cyber Insights from 100 surveys
Cyber Insights from 100 surveysCyber Insights from 100 surveys
Cyber Insights from 100 surveysKevin Duffey
 
Cyber TPRM - the journey ahead
Cyber TPRM - the journey aheadCyber TPRM - the journey ahead
Cyber TPRM - the journey aheadKevin Duffey
 
Ensuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance SectorEnsuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance SectorKevin Duffey
 
Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022Kevin Duffey
 
Best Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveysBest Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveysKevin Duffey
 
Breaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so LowBreaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so LowKevin Duffey
 
Cyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptxCyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptxKevin Duffey
 
Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022Kevin Duffey
 
Breaches Anticipated - because firms have weak cyber security visible to hac...
Breaches Anticipated  - because firms have weak cyber security visible to hac...Breaches Anticipated  - because firms have weak cyber security visible to hac...
Breaches Anticipated - because firms have weak cyber security visible to hac...Kevin Duffey
 
Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022Kevin Duffey
 
Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021Kevin Duffey
 
Cyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and SuppliersCyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and SuppliersKevin Duffey
 
London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018Kevin Duffey
 
Cyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 ExecutivesCyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 ExecutivesKevin Duffey
 
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018Kevin Duffey
 
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Kevin Duffey
 
Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...Kevin Duffey
 
The Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber SecurityThe Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber SecurityKevin Duffey
 
Cyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOsCyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOsKevin Duffey
 
Vodafone security priorities in Greece
Vodafone security priorities in GreeceVodafone security priorities in Greece
Vodafone security priorities in GreeceKevin Duffey
 

More from Kevin Duffey (20)

Cyber Insights from 100 surveys
Cyber Insights from 100 surveysCyber Insights from 100 surveys
Cyber Insights from 100 surveys
 
Cyber TPRM - the journey ahead
Cyber TPRM - the journey aheadCyber TPRM - the journey ahead
Cyber TPRM - the journey ahead
 
Ensuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance SectorEnsuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance Sector
 
Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022
 
Best Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveysBest Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveys
 
Breaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so LowBreaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so Low
 
Cyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptxCyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptx
 
Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022
 
Breaches Anticipated - because firms have weak cyber security visible to hac...
Breaches Anticipated  - because firms have weak cyber security visible to hac...Breaches Anticipated  - because firms have weak cyber security visible to hac...
Breaches Anticipated - because firms have weak cyber security visible to hac...
 
Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022
 
Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021
 
Cyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and SuppliersCyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and Suppliers
 
London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018
 
Cyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 ExecutivesCyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 Executives
 
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
 
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
 
Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...
 
The Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber SecurityThe Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber Security
 
Cyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOsCyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOs
 
Vodafone security priorities in Greece
Vodafone security priorities in GreeceVodafone security priorities in Greece
Vodafone security priorities in Greece
 

Recently uploaded

Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfmuskan1121w
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...lizamodels9
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneCall girls in Ahmedabad High profile
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Serviceankitnayak356677
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxAbhayThakur200703
 

Recently uploaded (20)

Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdf
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
Lowrate Call Girls In Laxmi Nagar Delhi ❤️8860477959 Escorts 100% Genuine Ser...
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptx
 

Keynote at Operational Resilience summit - Financial Services - 18th Nov 2019

  • 1. Opening Keynote at the Operational Resilience Summit in Financial Services Measuring operational resilience & regulatory compliance to mitigate harm from cyber-attacks on the extended enterprise Kevin Duffey, CEO, Cyber Rescue Alliance, 19 th November 2019
  • 2. Opening Keynote at the Operational Resilience Summit in Financial Services Measurement drives maturity So please participate – anonymously – in today’s measurements 2 #OpRes About 210 delegates attended the Summit on Operational Resilience in Financial Services on 18 November 2019. Delegates interacted via Slido. Responses on one question are shown on the right.
  • 3. Opening Keynote at the Operational Resilience Summit in Financial Services You’re sitting near some world leaders in Operational Resilience Opening Keynote at the Operational Resilience Summit in Financial Services
  • 4. Opening Keynote at the Operational Resilience Summit in Financial Services You’re sitting near some world leaders in Operational Resilience www.slido.com #OpRes Some world leaders in Operational Resilience Opening Keynote at the Operational Resilience Summit in Financial Services
  • 5. Opening Keynote at the Operational Resilience Summit in Financial Services Discussion Paper: July 2018 5 Operational Resilience is the ability to prevent, respond to, recover and learn from operational disruptions, that might include: • physical attacks • cyber attacks • IT system outages • third-party supplier failure • fire, flood, severe weather and pandemic flu Building the UK financial sector’s operational resilience
  • 6. Opening Keynote at the Operational Resilience Summit in Financial Services Measurement drives maturity So please participate – anonymously – in today’s measurements 6 #OpRes About 210 delegates attended the Summit on Operational Resilience in Financial Services on 18 November 2019. Delegates interacted via Slido. Responses on one question are shown on the right.
  • 7. Opening Keynote at the Operational Resilience Summit in Financial Services Sources of Risk to UK Financial System Future of Finance review by Huw van Steenis – June 2019
  • 8. Opening Keynote at the Operational Resilience Summit in Financial Services Cyber & Technology Resilience: FCA Survey Research – First published: 27/11/2018 – Last updated: 14/01/2019 3rd Party Failure Cyber Attack
  • 9. Opening Keynote at the Operational Resilience Summit in Financial Services UK Share of Phishing Attacks, worldwide National Cyber Security Centre, August 2019
  • 10. Opening Keynote at the Operational Resilience Summit in Financial Services Cyber & Technology Resilience: FCA Survey Research – First published: 27/11/2018 – Last updated: 14/01/2019 Financial ServicesGrowth in peak size of “Denial of Service” cyber attacks Percentage of targets of “Denial of Service” cyber attacks
  • 11. Opening Keynote at the Operational Resilience Summit in Financial Services
  • 12. Opening Keynote at the Operational Resilience Summit in Financial Services Richard F Smith, former CEO of Equifax “The challenge of building a website to notify consumers proved overwhelming, and regrettably, mistakes were made.” Richard F. Smith, 4th Oct 2017
  • 13. Opening Keynote at the Operational Resilience Summit in Financial Services Report on Recovery Plans European Central Bank – July 2018 Financial Services The ECB has concluded that some plans "might be too large to actually be used in a crisis.”
  • 14. Opening Keynote at the Operational Resilience Summit in Financial Services Report on Recovery Plans European Central Bank – July 2018 Financial Services
  • 15. Opening Keynote at the Operational Resilience Summit in Financial Services Richard F Smith, former CEO of Equifax
  • 16. Opening Keynote at the Operational Resilience Summit in Financial Services March 8th, 2019
  • 17. Opening Keynote at the Operational Resilience Summit in Financial Services March 8th, 2019 Equifax Used What Internal Auditors Called an “Honor System” for Patching Vulnerabilities. Equifax had no formalized method of validating the successful installation of patches. Audit referred to this approach as an “honor system” in which the IT team would notify the security team once patches were complete.
  • 18. Opening Keynote at the Operational Resilience Summit in Financial Services What does an “honor system” for patching look like?
  • 19. Opening Keynote at the Operational Resilience Summit in Financial Services What does an “honor system” for patching look like?
  • 20. Opening Keynote at the Operational Resilience Summit in Financial Services What does an “honor system” for patching look like?
  • 21. Opening Keynote at the Operational Resilience Summit in Financial Services CQUEST CQUEST consists of multiple-choice questions covering all aspects of cyber resilience, such as: • Does the firm have a board-approved cyber security strategy? • How does it identify and protect its critical assets? • How does it detect and respond to an incident, recover and learn from the experience? New cyber resilience assessment from PRA & FCA 21
  • 22. Opening Keynote at the Operational Resilience Summit in Financial Services Measurement of Cyber Risk should be as objective, timely & dynamic as for Market Risk
  • 23. Opening Keynote at the Operational Resilience Summit in Financial Services Automated measurement drives behaviour At least monthly, present an objective Security Scorecard showing trends Overall Grade Application Security DNS Health Network Security Patching Cadence
  • 24. Opening Keynote at the Operational Resilience Summit in Financial Services Resilience across Extended Enterprise Regulators have woken up to third party & supply chain cyber risks 24 Entities should review third parties on an ongoing basis to manage their cyber risks. Entities should include critical third parties when they exercise their cyber incident response plans. What are your expectations of suppliers' security? How much will you pay extra to a secure supplier? 21 March 2019
  • 25. Opening Keynote at the Operational Resilience Summit in Financial Services Cyber Risk is dynamic 25 Suppliers with a poor cyber score can get much worse very quickly This supplier had a very low score (72) for most of 2019. Then something happened at end of June.
  • 26. Opening Keynote at the Operational Resilience Summit in Financial Services Measurement drives maturity So please participate – anonymously – in today’s measurements 26 #OpRes About 210 delegates attended the Summit on Operational Resilience in Financial Services on 18 November 2019. Delegates interacted via Slido. Responses on one question are shown on the right.
  • 27. Opening Keynote at the Operational Resilience Summit in Financial Services Cyber Risk is dynamic 27 How quickly should you know that a supplier has been compromised? An obvious reason their score has a low score in July is that its systems were not just vulnerable: they were compromised. Malware was being distributed from their systems, starting at the end of June. Example Supplier
  • 28. Opening Keynote at the Operational Resilience Summit in Financial Services How to measure cyber risk at Peers? 28 Your security will never be perfect, but you should know if it’s worse than average Censored Censored Censored Censored Censored
  • 29. Opening Keynote at the Operational Resilience Summit in Financial Services How to measure cyber risk at Suppliers? 29 The greatest risk of your data being breached is via your suppliers Censored Censored Censored Censored Censored Censored
  • 30. Opening Keynote at the Operational Resilience Summit in Financial Services Let’s work together to build Operational Resilience Please connect on LinkedIn to Kevin Duffey

Editor's Notes

  1. Measurement provides evidence Evidence sparks insight Insight drives maturity development in operational resilience Measure if you have sprung back from the weekend
  2. EUCR FSCCC FSSCC CREST NSCC BOE PRA FCA Hamilton Series Safe Harbour??
  3. EUCR FSCCC FSSCC CREST NSCC BOE PRA FCA Hamilton Series Safe Harbour??
  4. ”We struggled with remediation” is one of the unfortunate confessions that Richard Smith had to make to Congress, after resigning from Equifax. How did the breach feel for him? Perhaps like it did for Atiur Rahman in Bangladesh…
  5. ”We struggled with remediation” is one of the unfortunate confessions that Richard Smith had to make to Congress, after resigning from Equifax. How did the breach feel for him? Perhaps like it did for Atiur Rahman in Bangladesh…
  6. ”We struggled with remediation” is one of the unfortunate confessions that Richard Smith had to make to Congress, after resigning from Equifax. How did the breach feel for him? Perhaps like it did for Atiur Rahman in Bangladesh…
  7. 10 April 2019 - Joint Advice of the European Supervisory Authorities. Need for legislative improvements relating to ICT risk management requirements in the EU financial sector. Appropriate management of third party risks is an important part of risk management, especially with regard to cloud services. European Central Bank – 28 June 2019: There was general agreement amongst Euro Cyber Resiience Board that third party risk remains a key risk area.