SlideShare a Scribd company logo
Shawn Tuma
Co-Chair, Cybersecurity & Data Privacy
Spencer Fane LLP | @spencerfane
spencerfane.com | @shawnetuma
Cybersecurity is
a Team Sport
Shawn Tuma
Co-Chair, Cybersecurity & Data Privacy
Spencer Fane LLP | @spencerfane
spencerfane.com | @shawnetuma
Cybersecurity is
a Team Sport
Cybersecurity is a Team Sport
Why strategic leadership and an
understanding of roles, personalities, and
psychology is important for building and
managing effective cybersecurity teams.
What is the nature of a CSO / CISO’s role?
From my vantage point
What do you think is the most glaring thing missing
when I look at substantial incidents and data
breaches I have handled over the last 19 yrs?
1. Lack of hardware, services, gadgets, and gizmos?
2. Lack of support from management?
3. Lack of funding?
4. Lack of talent?
5. Lack of skills and knowledge?
6. Lack of strategy?
Strategy.
Sun Tzu
• “If you know the enemy and know yourself, you need not fear the
result of a hundred battles. If you know yourself but not the
enemy, for every victory gained you will also suffer a defeat. If you
know neither the enemy nor yourself, you will succumb in every
battle.”
• “The general who wins the battle makes many calculations in his
temple before the battle is fought. The general who loses makes
but few calculations beforehand.”
• “Strategy without tactics is the slowest route to victory.”
• “Tactics without strategy is the noise before defeat.”
People.
Cybersecurity is no longer just an IT
issue—it is an overall business risk issue.
Psychology & Personality
• Psychology: “the scientific study of the human
mind and its functions, especially those
affecting behavior in a given context.”
• Personality: “the combination of
characteristics or qualities that form an
individual’s distinctive character.”
• How do you tell the difference between an
introvert and extrovert IT guy?
Myers-Briggs Personality Type Indicator
Extraversion (E) Introversion (I)
How people respond and interact with the world
around them.
• (E) turns inward, deep meaning, time alone
• (I) turns outward, social interaction, w/others
Sensing (S) Intuition (N)
How people gather information from the world
around them.
• (S) focus on what learn from senses, facts
• (N) focus on patterns impressions, abstracts
Thinking (T) Feeling (F)
How people make decisions based on the information
they gathered from their sensing or intuition
functions.
• (T) focus on facts and objective data
• (F) consider people and emotions more
Judging (J) Perceiving (P)
How people tend to deal with the outside world.
• (J) prefer structure and firm decisions
• (P) more open, flexible, adaptable
Teams.
Common Questions about Teams
• Who should be on the team and what should they
know?
• What are the team members’ responsibilities?
• How do team members’ personalities affect their roles
and performance?
• How should the team be organized?
• Who is responsible for developing the strategy and
seeing the whole playing field?
• If you have cyber insurance, who is the contact person?
Security Team– Proactive
Key Players Primary Roles Desirable Personality Traits
Incident Response Team – Reactive
Key Players Primary Roles Desirable Personality Traits
Practice.
Incident Response Preparation
• Incident response plan
– Establish The Process
– How long or detailed should it be? -- “Complexity is the enemy of
execution”
• Preparing for unknown unknowns
– You can’t prepare for everything. But, being better prepared equips
you with the skills, ability, and mindset you need to improvise, adapt,
and overcome.
• Owner -- responsible for ensuring team is prepared.
• What is needed:
– Preparation: what helps you understand priorities, even as they
change
– Discipline: hold the course, knowing what you have to do
– Prioritize: quickly assess the highest priority
– Execute – execute that priority, then move on to the next priority
What is a great way to assess your team?
Tabletop exercises
• Team benefits
– Know their role
– Know each other
– Understand role, ask questions, work out uncertainties now, not
in time of crisis
– Preparation leads to more comfort
– Buy-in – get everyone to contribute
• Company benefits
– Evaluate your team
– Practice makes perfect
– Preparation
Lawyers.
Got Privilege?
• Great sales pitch → the magic wand!
• Mature understanding → not so simple!
• Prepare by doing everything possible to ensure the applicability of privileges
but carry out the work as though there will be no privilege.
– Retain experienced cyber counsel to assess cyber risk, develop and lead cyber risk
management program.
– List role in engagement agreement.
– Develop communications protocol at the outset.
• i.e., “if it doesn’t need to be in writing …”
• Counsel must actively lead and stay engaged in the process.
• Counsel should hire, direct, and receive info from consultants.
• If incident, consider multiple tracks:
– proactive risk management;
– normal business investigation;
– Investigation in anticipation of litigation.
Photo credit: dave_7
Link: https://www.flickr.com/photos/daveseven/1910839183/in/photostream/
Got Privilege?
• Great sales pitch → the magic wand!
• Mature understanding → not so simple!
• Prepare by doing everything possible to ensure the applicability of privileges
but carry out the work as though there will be no privilege.
– Retain experienced cyber counsel to assess cyber risk, develop and lead cyber risk
management program.
– List role in engagement agreement.
– Develop communications protocol at the outset.
• i.e., “if it doesn’t need to be in writing …”
• Counsel must actively lead and stay engaged in the process.
• Counsel should hire, direct, and receive info from consultants.
• If incident, consider multiple tracks:
– proactive risk management;
– normal business investigation;
– Investigation in anticipation of litigation.
Laws & Regulations
Types
• Security
• Privacy
• Unauthorized Access
International Laws
• GDPR
• Privacy Shield
• China’s Cybersecurity Law
Federal Laws and Regs
• FTC, SEC, HIPAA
State Laws
• All 50 States
– Privacy + security (some)
• NYDFS, Colo FinServ, CaCPA
Industry Groups
• PCI
• FINRA
Contracts
• 3rd Party Bus. Assoc.
• Privacy / Data Security / Cybersecurity
Addendum
Banks & Financial Institutions
• GLBA
• Dodd Frank
• FFIEC (Federal Financial Institutions
Examination Council)
Without a magic wand, how does
cyber legal counsel help?
Practitioner Editor, Bloomberg BNA – Texas Cybersecurity &
Data Privacy Law
Board of Directors & General Counsel, Cyber Future Foundation
Board of Advisors, North Texas Cyber Forensics Lab
Policy Council, National Technology Security Coalition
Cybersecurity & Data Privacy Law Trailblazers, National Law
Journal
SuperLawyers - Top 100 Lawyers in Dallas (2016)
SuperLawyers (2015-18)
D Magazine - Best Lawyers in Dallas (2014-18)
Officer, Computer & Technology Section, State Bar of Texas
Privacy and Data Security Committee, State Bar of Texas
College of the State Bar of Texas
Board of Directors, Collin County Bench Bar Conference
Past Chair, Civil Litigation Section, Collin County Bar Association
North Texas Crime Commission, Cybercrime Committee
Infragard (FBI)
International Association of Privacy Professionals (IAPP)
Shawn E. Tuma
Spencer Fane LLP
Partner & Co-Chair,
Cybersecurity & Data
Privacy Practice
O 972.324.0317
M 214.726.2808
stuma@spencerfane.com
web: spencerfane.com
blog: shawnetuma.com
@shawnetuma

More Related Content

Similar to Cybersecurity is a Team Sport (SecureWorld - Dallas 2018)

Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Alexandre Sieira
 
Great Learning & Information Security - English edition
Great Learning & Information Security - English editionGreat Learning & Information Security - English edition
Great Learning & Information Security - English edition
Chuan Lin
 
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Shawn Tuma
 
The Human Side of Information Security
The Human Side of Information SecurityThe Human Side of Information Security
The Human Side of Information Security
Rob Arnold
 
Be a Database Marketing Mind Reader
Be a Database Marketing Mind ReaderBe a Database Marketing Mind Reader
Be a Database Marketing Mind Reader
SalesEngine
 
Marketing vs. IT - Let the Battle Begin
Marketing vs. IT - Let the Battle BeginMarketing vs. IT - Let the Battle Begin
Marketing vs. IT - Let the Battle Begin
Connect2AMC
 
RedZone10X: innovation strategy leadership and Transformation
RedZone10X: innovation strategy leadership and TransformationRedZone10X: innovation strategy leadership and Transformation
RedZone10X: innovation strategy leadership and Transformation
RedZone Technologies
 
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1
FRSecure
 
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Shawn Tuma
 
Janitor vs cleaner
Janitor vs cleanerJanitor vs cleaner
Janitor vs cleaner
John Stauffacher
 
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
NataliaKurop
 
4 DX Book Review by Coach Eval
4 DX Book Review by Coach Eval4 DX Book Review by Coach Eval
4 DX Book Review by Coach Eval
Eval Wari, PCC
 
So, you wanna be a pen tester
So, you wanna be a pen testerSo, you wanna be a pen tester
So, you wanna be a pen tester
Adrien de Beaupre
 
The game of research
The game of researchThe game of research
The game of research
Cynthia Calongne
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Stephen Cobb
 
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Kimberley Dray
 
Social engineering
Social engineeringSocial engineering
Social engineering
Robert Hood
 
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor ProgramSlide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
FRSecure
 
Incubate Miami Orientation
Incubate Miami OrientationIncubate Miami Orientation
Incubate Miami Orientation
Gerard Roy
 
Digital Governance in Complex Organisations philly13
Digital Governance in Complex Organisations   philly13Digital Governance in Complex Organisations   philly13
Digital Governance in Complex Organisations philly13
onlineredin
 

Similar to Cybersecurity is a Team Sport (SecureWorld - Dallas 2018) (20)

Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
Reverse Engineering the Wetware: Understanding Human Behavior to Improve Info...
 
Great Learning & Information Security - English edition
Great Learning & Information Security - English editionGreat Learning & Information Security - English edition
Great Learning & Information Security - English edition
 
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
 
The Human Side of Information Security
The Human Side of Information SecurityThe Human Side of Information Security
The Human Side of Information Security
 
Be a Database Marketing Mind Reader
Be a Database Marketing Mind ReaderBe a Database Marketing Mind Reader
Be a Database Marketing Mind Reader
 
Marketing vs. IT - Let the Battle Begin
Marketing vs. IT - Let the Battle BeginMarketing vs. IT - Let the Battle Begin
Marketing vs. IT - Let the Battle Begin
 
RedZone10X: innovation strategy leadership and Transformation
RedZone10X: innovation strategy leadership and TransformationRedZone10X: innovation strategy leadership and Transformation
RedZone10X: innovation strategy leadership and Transformation
 
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1
 
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
Cybersecurity is a Team Sport: How to Use Teams, Strategies, and Processes to...
 
Janitor vs cleaner
Janitor vs cleanerJanitor vs cleaner
Janitor vs cleaner
 
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
Ellwood Atfield: Key Success Factors for Advocates and Advocacy Teams - Genev...
 
4 DX Book Review by Coach Eval
4 DX Book Review by Coach Eval4 DX Book Review by Coach Eval
4 DX Book Review by Coach Eval
 
So, you wanna be a pen tester
So, you wanna be a pen testerSo, you wanna be a pen tester
So, you wanna be a pen tester
 
The game of research
The game of researchThe game of research
The game of research
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
 
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
Co-Presented: YOU are the Alpha and Omega of a Secure Future (Kottova / Dray)...
 
Social engineering
Social engineeringSocial engineering
Social engineering
 
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor ProgramSlide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
 
Incubate Miami Orientation
Incubate Miami OrientationIncubate Miami Orientation
Incubate Miami Orientation
 
Digital Governance in Complex Organisations philly13
Digital Governance in Complex Organisations   philly13Digital Governance in Complex Organisations   philly13
Digital Governance in Complex Organisations philly13
 

More from Shawn Tuma

Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
Shawn Tuma
 
The Dark Side of Digital Engagement
The Dark Side of Digital EngagementThe Dark Side of Digital Engagement
The Dark Side of Digital Engagement
Shawn Tuma
 
Incident Response Planning - Lifecycle of Responding to a Ransomware Attack
Incident Response Planning - Lifecycle of Responding to a Ransomware AttackIncident Response Planning - Lifecycle of Responding to a Ransomware Attack
Incident Response Planning - Lifecycle of Responding to a Ransomware Attack
Shawn Tuma
 
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
Shawn Tuma
 
The Role of Contracts in Privacy, Cybersecurity, and Data Breach
The Role of Contracts in Privacy, Cybersecurity, and Data BreachThe Role of Contracts in Privacy, Cybersecurity, and Data Breach
The Role of Contracts in Privacy, Cybersecurity, and Data Breach
Shawn Tuma
 
Lawyers' Ethical Obligations for Cybersecurity
Lawyers' Ethical Obligations for CybersecurityLawyers' Ethical Obligations for Cybersecurity
Lawyers' Ethical Obligations for Cybersecurity
Shawn Tuma
 
Real World Cyber Risk. Understand it. Manage it.
Real World Cyber Risk. Understand it. Manage it.Real World Cyber Risk. Understand it. Manage it.
Real World Cyber Risk. Understand it. Manage it.
Shawn Tuma
 
The Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should IncludeThe Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should Include
Shawn Tuma
 
Cyber Hygiene Checklist
Cyber Hygiene ChecklistCyber Hygiene Checklist
Cyber Hygiene Checklist
Shawn Tuma
 
Cyber Incident Response Checklist
Cyber Incident Response ChecklistCyber Incident Response Checklist
Cyber Incident Response Checklist
Shawn Tuma
 
Cybersecurity: Cyber Risk Management for Lawyers and Clients
Cybersecurity: Cyber Risk Management for Lawyers and ClientsCybersecurity: Cyber Risk Management for Lawyers and Clients
Cybersecurity: Cyber Risk Management for Lawyers and Clients
Shawn Tuma
 
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial InstitutionsCybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
Shawn Tuma
 
Something is Phishy: Cyber Scams and How to Avoid Them
Something is Phishy: Cyber Scams and How to Avoid ThemSomething is Phishy: Cyber Scams and How to Avoid Them
Something is Phishy: Cyber Scams and How to Avoid Them
Shawn Tuma
 
Cybersecurity Fundamentals for Legal Professionals (and every other business)
Cybersecurity Fundamentals for Legal Professionals (and every other business)Cybersecurity Fundamentals for Legal Professionals (and every other business)
Cybersecurity Fundamentals for Legal Professionals (and every other business)
Shawn Tuma
 
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
Shawn Tuma
 
Cybersecurity Update
Cybersecurity UpdateCybersecurity Update
Cybersecurity Update
Shawn Tuma
 
Effective cybersecurity for small and midsize businesses
Effective cybersecurity for small and midsize businessesEffective cybersecurity for small and midsize businesses
Effective cybersecurity for small and midsize businesses
Shawn Tuma
 
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk SummitThe Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
Shawn Tuma
 
The Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should IncludeThe Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should Include
Shawn Tuma
 
"What Could Go Wrong?" - We're Glad You Asked!
"What Could Go Wrong?" - We're Glad You Asked!"What Could Go Wrong?" - We're Glad You Asked!
"What Could Go Wrong?" - We're Glad You Asked!
Shawn Tuma
 

More from Shawn Tuma (20)

Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
Lifecycle: Responding to a Ransomware Attack - A Professional Breach Guide's ...
 
The Dark Side of Digital Engagement
The Dark Side of Digital EngagementThe Dark Side of Digital Engagement
The Dark Side of Digital Engagement
 
Incident Response Planning - Lifecycle of Responding to a Ransomware Attack
Incident Response Planning - Lifecycle of Responding to a Ransomware AttackIncident Response Planning - Lifecycle of Responding to a Ransomware Attack
Incident Response Planning - Lifecycle of Responding to a Ransomware Attack
 
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
Reimagine Your Company Operating Again After a Ransomware Attack -- The Lifec...
 
The Role of Contracts in Privacy, Cybersecurity, and Data Breach
The Role of Contracts in Privacy, Cybersecurity, and Data BreachThe Role of Contracts in Privacy, Cybersecurity, and Data Breach
The Role of Contracts in Privacy, Cybersecurity, and Data Breach
 
Lawyers' Ethical Obligations for Cybersecurity
Lawyers' Ethical Obligations for CybersecurityLawyers' Ethical Obligations for Cybersecurity
Lawyers' Ethical Obligations for Cybersecurity
 
Real World Cyber Risk. Understand it. Manage it.
Real World Cyber Risk. Understand it. Manage it.Real World Cyber Risk. Understand it. Manage it.
Real World Cyber Risk. Understand it. Manage it.
 
The Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should IncludeThe Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should Include
 
Cyber Hygiene Checklist
Cyber Hygiene ChecklistCyber Hygiene Checklist
Cyber Hygiene Checklist
 
Cyber Incident Response Checklist
Cyber Incident Response ChecklistCyber Incident Response Checklist
Cyber Incident Response Checklist
 
Cybersecurity: Cyber Risk Management for Lawyers and Clients
Cybersecurity: Cyber Risk Management for Lawyers and ClientsCybersecurity: Cyber Risk Management for Lawyers and Clients
Cybersecurity: Cyber Risk Management for Lawyers and Clients
 
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial InstitutionsCybersecurity: Cyber Risk Management for Banks & Financial Institutions
Cybersecurity: Cyber Risk Management for Banks & Financial Institutions
 
Something is Phishy: Cyber Scams and How to Avoid Them
Something is Phishy: Cyber Scams and How to Avoid ThemSomething is Phishy: Cyber Scams and How to Avoid Them
Something is Phishy: Cyber Scams and How to Avoid Them
 
Cybersecurity Fundamentals for Legal Professionals (and every other business)
Cybersecurity Fundamentals for Legal Professionals (and every other business)Cybersecurity Fundamentals for Legal Professionals (and every other business)
Cybersecurity Fundamentals for Legal Professionals (and every other business)
 
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
NYDFS Cybersecurity Regulations - 23 NYCRR Part 500
 
Cybersecurity Update
Cybersecurity UpdateCybersecurity Update
Cybersecurity Update
 
Effective cybersecurity for small and midsize businesses
Effective cybersecurity for small and midsize businessesEffective cybersecurity for small and midsize businesses
Effective cybersecurity for small and midsize businesses
 
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk SummitThe Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
The Legal Case for Cyber Risk Management - InfoSec World Privacy & Risk Summit
 
The Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should IncludeThe Legal Case for Cyber Risk Management Programs and What They Should Include
The Legal Case for Cyber Risk Management Programs and What They Should Include
 
"What Could Go Wrong?" - We're Glad You Asked!
"What Could Go Wrong?" - We're Glad You Asked!"What Could Go Wrong?" - We're Glad You Asked!
"What Could Go Wrong?" - We're Glad You Asked!
 

Recently uploaded

KubeCon & CloudNative Con 2024 Artificial Intelligent
KubeCon & CloudNative Con 2024 Artificial IntelligentKubeCon & CloudNative Con 2024 Artificial Intelligent
KubeCon & CloudNative Con 2024 Artificial Intelligent
Emre Gündoğdu
 
Bangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
Bangalore Call Girls 9079923931 With -Cuties' Hot Call GirlsBangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
Bangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
narwatsonia7
 
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
rtunex8r
 
Decentralized Justice in Gaming and Esports
Decentralized Justice in Gaming and EsportsDecentralized Justice in Gaming and Esports
Decentralized Justice in Gaming and Esports
Federico Ast
 
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
dtagbe
 
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
3a0sd7z3
 
cyber crime.pptx..........................
cyber crime.pptx..........................cyber crime.pptx..........................
cyber crime.pptx..........................
GNAMBIKARAO
 
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
thezot
 
How to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdfHow to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdf
Infosec train
 
Bengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal BrandingBengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal Branding
Tarandeep Singh
 
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
APNIC
 
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
3a0sd7z3
 
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
APNIC
 

Recently uploaded (13)

KubeCon & CloudNative Con 2024 Artificial Intelligent
KubeCon & CloudNative Con 2024 Artificial IntelligentKubeCon & CloudNative Con 2024 Artificial Intelligent
KubeCon & CloudNative Con 2024 Artificial Intelligent
 
Bangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
Bangalore Call Girls 9079923931 With -Cuties' Hot Call GirlsBangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
Bangalore Call Girls 9079923931 With -Cuties' Hot Call Girls
 
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
怎么办理(umiami毕业证书)美国迈阿密大学毕业证文凭证书实拍图原版一模一样
 
Decentralized Justice in Gaming and Esports
Decentralized Justice in Gaming and EsportsDecentralized Justice in Gaming and Esports
Decentralized Justice in Gaming and Esports
 
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
一比一原版(uc毕业证书)加拿大卡尔加里大学毕业证如何办理
 
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
快速办理(新加坡SMU毕业证书)新加坡管理大学毕业证文凭证书一模一样
 
cyber crime.pptx..........................
cyber crime.pptx..........................cyber crime.pptx..........................
cyber crime.pptx..........................
 
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
一比一原版新西兰林肯大学毕业证(Lincoln毕业证书)学历如何办理
 
How to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdfHow to make a complaint to the police for Social Media Fraud.pdf
How to make a complaint to the police for Social Media Fraud.pdf
 
Bengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal BrandingBengaluru Dreamin' 24 - Personal Branding
Bengaluru Dreamin' 24 - Personal Branding
 
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...Securing BGP: Operational Strategies and Best Practices for Network Defenders...
Securing BGP: Operational Strategies and Best Practices for Network Defenders...
 
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
快速办理(Vic毕业证书)惠灵顿维多利亚大学毕业证完成信一模一样
 
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
Honeypots Unveiled: Proactive Defense Tactics for Cyber Security, Phoenix Sum...
 

Cybersecurity is a Team Sport (SecureWorld - Dallas 2018)

  • 1. Shawn Tuma Co-Chair, Cybersecurity & Data Privacy Spencer Fane LLP | @spencerfane spencerfane.com | @shawnetuma Cybersecurity is a Team Sport Shawn Tuma Co-Chair, Cybersecurity & Data Privacy Spencer Fane LLP | @spencerfane spencerfane.com | @shawnetuma Cybersecurity is a Team Sport
  • 2. Cybersecurity is a Team Sport Why strategic leadership and an understanding of roles, personalities, and psychology is important for building and managing effective cybersecurity teams.
  • 3.
  • 4.
  • 5. What is the nature of a CSO / CISO’s role?
  • 6. From my vantage point What do you think is the most glaring thing missing when I look at substantial incidents and data breaches I have handled over the last 19 yrs? 1. Lack of hardware, services, gadgets, and gizmos? 2. Lack of support from management? 3. Lack of funding? 4. Lack of talent? 5. Lack of skills and knowledge? 6. Lack of strategy?
  • 8. Sun Tzu • “If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.” • “The general who wins the battle makes many calculations in his temple before the battle is fought. The general who loses makes but few calculations beforehand.” • “Strategy without tactics is the slowest route to victory.” • “Tactics without strategy is the noise before defeat.”
  • 9.
  • 10.
  • 12. Cybersecurity is no longer just an IT issue—it is an overall business risk issue.
  • 13.
  • 14.
  • 15.
  • 16.
  • 17. Psychology & Personality • Psychology: “the scientific study of the human mind and its functions, especially those affecting behavior in a given context.” • Personality: “the combination of characteristics or qualities that form an individual’s distinctive character.” • How do you tell the difference between an introvert and extrovert IT guy?
  • 18. Myers-Briggs Personality Type Indicator Extraversion (E) Introversion (I) How people respond and interact with the world around them. • (E) turns inward, deep meaning, time alone • (I) turns outward, social interaction, w/others Sensing (S) Intuition (N) How people gather information from the world around them. • (S) focus on what learn from senses, facts • (N) focus on patterns impressions, abstracts Thinking (T) Feeling (F) How people make decisions based on the information they gathered from their sensing or intuition functions. • (T) focus on facts and objective data • (F) consider people and emotions more Judging (J) Perceiving (P) How people tend to deal with the outside world. • (J) prefer structure and firm decisions • (P) more open, flexible, adaptable
  • 19.
  • 20.
  • 22. Common Questions about Teams • Who should be on the team and what should they know? • What are the team members’ responsibilities? • How do team members’ personalities affect their roles and performance? • How should the team be organized? • Who is responsible for developing the strategy and seeing the whole playing field? • If you have cyber insurance, who is the contact person?
  • 23. Security Team– Proactive Key Players Primary Roles Desirable Personality Traits
  • 24. Incident Response Team – Reactive Key Players Primary Roles Desirable Personality Traits
  • 26. Incident Response Preparation • Incident response plan – Establish The Process – How long or detailed should it be? -- “Complexity is the enemy of execution” • Preparing for unknown unknowns – You can’t prepare for everything. But, being better prepared equips you with the skills, ability, and mindset you need to improvise, adapt, and overcome. • Owner -- responsible for ensuring team is prepared. • What is needed: – Preparation: what helps you understand priorities, even as they change – Discipline: hold the course, knowing what you have to do – Prioritize: quickly assess the highest priority – Execute – execute that priority, then move on to the next priority
  • 27. What is a great way to assess your team? Tabletop exercises • Team benefits – Know their role – Know each other – Understand role, ask questions, work out uncertainties now, not in time of crisis – Preparation leads to more comfort – Buy-in – get everyone to contribute • Company benefits – Evaluate your team – Practice makes perfect – Preparation
  • 29. Got Privilege? • Great sales pitch → the magic wand! • Mature understanding → not so simple! • Prepare by doing everything possible to ensure the applicability of privileges but carry out the work as though there will be no privilege. – Retain experienced cyber counsel to assess cyber risk, develop and lead cyber risk management program. – List role in engagement agreement. – Develop communications protocol at the outset. • i.e., “if it doesn’t need to be in writing …” • Counsel must actively lead and stay engaged in the process. • Counsel should hire, direct, and receive info from consultants. • If incident, consider multiple tracks: – proactive risk management; – normal business investigation; – Investigation in anticipation of litigation. Photo credit: dave_7 Link: https://www.flickr.com/photos/daveseven/1910839183/in/photostream/
  • 30. Got Privilege? • Great sales pitch → the magic wand! • Mature understanding → not so simple! • Prepare by doing everything possible to ensure the applicability of privileges but carry out the work as though there will be no privilege. – Retain experienced cyber counsel to assess cyber risk, develop and lead cyber risk management program. – List role in engagement agreement. – Develop communications protocol at the outset. • i.e., “if it doesn’t need to be in writing …” • Counsel must actively lead and stay engaged in the process. • Counsel should hire, direct, and receive info from consultants. • If incident, consider multiple tracks: – proactive risk management; – normal business investigation; – Investigation in anticipation of litigation.
  • 31. Laws & Regulations Types • Security • Privacy • Unauthorized Access International Laws • GDPR • Privacy Shield • China’s Cybersecurity Law Federal Laws and Regs • FTC, SEC, HIPAA State Laws • All 50 States – Privacy + security (some) • NYDFS, Colo FinServ, CaCPA Industry Groups • PCI • FINRA Contracts • 3rd Party Bus. Assoc. • Privacy / Data Security / Cybersecurity Addendum Banks & Financial Institutions • GLBA • Dodd Frank • FFIEC (Federal Financial Institutions Examination Council)
  • 32. Without a magic wand, how does cyber legal counsel help?
  • 33. Practitioner Editor, Bloomberg BNA – Texas Cybersecurity & Data Privacy Law Board of Directors & General Counsel, Cyber Future Foundation Board of Advisors, North Texas Cyber Forensics Lab Policy Council, National Technology Security Coalition Cybersecurity & Data Privacy Law Trailblazers, National Law Journal SuperLawyers - Top 100 Lawyers in Dallas (2016) SuperLawyers (2015-18) D Magazine - Best Lawyers in Dallas (2014-18) Officer, Computer & Technology Section, State Bar of Texas Privacy and Data Security Committee, State Bar of Texas College of the State Bar of Texas Board of Directors, Collin County Bench Bar Conference Past Chair, Civil Litigation Section, Collin County Bar Association North Texas Crime Commission, Cybercrime Committee Infragard (FBI) International Association of Privacy Professionals (IAPP) Shawn E. Tuma Spencer Fane LLP Partner & Co-Chair, Cybersecurity & Data Privacy Practice O 972.324.0317 M 214.726.2808 stuma@spencerfane.com web: spencerfane.com blog: shawnetuma.com @shawnetuma