SlideShare a Scribd company logo
ROAR
in Real Life:


Heartbeat
Helper
The Lorenzi Group
The Situation
   Missy Cheevious was an average salesperson at
    Heartbeat Helper Co.
       She made her numbers but wasn’t the best (or worst) on
        the sales team

   Heartbeat Helper is (still) a leading player in the
    Medical Device Industry.

   Heartbeat Helper is seeing new competitors come
    into the market.

   There was no reason to suspect Missy Cheevious
    would leave the company.

   Heartbeat Helper is a ROAR client
The Event
   During the Superbowl, ROAR Analysts are alerted
    that Missy Cheevious had logged into the
    corporate network.

   While logged in, she downloaded confidential
    sales documents, changed the file names, and
    emailed them to a webmail address (hers).

   This was an anomaly because Missy Cheevious:
       Had never logged in on the weekend before
       Logged in during the Superbowl!
       Copied and changed the name of confidential
        documents
       Emailed them to her private webmail address
       Logged in for less than 4 minutes
What did ROAR see?
1.   Someone logging into a user account

2.   Someone going across the network to a
     shared drive

3.   Someone changing the names of the
     files and saving the files locally

4.   Someone opening their email client and
     emailing the files (with names changed)
     to a webmail address
ROAR in Action
1.        ROAR Analyst verified findings
     1.     Webmail addresses belonged to employee

2.        ROAR Analyst contacted client
     1.     Client contacted within MINUTES

3.        Client SHOCKED we were watching system
          during Superbowl (YAY! ROAR exceeded expectations)

4.        Client SHOCKED about employee activity

5.        List of evidence and all files emailed, ftp’d and
          saved to USB for past 30 days sent to client
ROAR Aftermath for Missy Cheevious
   Monday (after the Superbowl)
       Employee called in sick
       Employee access terminated
   Tuesday AM
       Employee admitted to skipping work for job interview
       Missy Cheevious was terminated

Upon termination:
1.  Employee was provided a list of documents
   (including the “Superbowl” documents) that
   Heartbeat Helper considers confidential
2.  Heartbeat Helper informed employee that if any
   information from those documents is used, Missy
   Cheevious and her new employer will face legal
   action.
Wrap Up
   Lorenzi ROAR is a 24x7 monitoring service

   ROAR looks for anomalies

   ROAR is used for:
       Security
       Compliance
       Productivity

   In this matter, there would have been a HIPAA
    compliance issue, had the data been allowed to
    leave Heartbeat Helper.

              ROAR protected Heartbeat Helper
Are YOU
Ready for a FREE Trial of ROAR?

         Robert Fitzgerald

     The Lorenzi Group
           866-632-9880 x123
       www.thelorenzigroup.com
  rfitzgerald@thelorenzigroup.com

More Related Content

More from The Lorenzi Group

ROAR Provides Peace of Mind in Digital Enviroments
ROAR Provides Peace of Mind in Digital EnviromentsROAR Provides Peace of Mind in Digital Enviroments
ROAR Provides Peace of Mind in Digital EnviromentsThe Lorenzi Group
 
ROARing Compliance
ROARing ComplianceROARing Compliance
ROARing Compliance
The Lorenzi Group
 
ROAR in Real Life: Picture Perfect
ROAR in Real Life: Picture PerfectROAR in Real Life: Picture Perfect
ROAR in Real Life: Picture PerfectThe Lorenzi Group
 
ROAR in Pictures: Biking
ROAR in Pictures: BikingROAR in Pictures: Biking
ROAR in Pictures: Biking
The Lorenzi Group
 
DDoS Explained
DDoS ExplainedDDoS Explained
DDoS Explained
The Lorenzi Group
 
Digital Forensics: The Employees' Dilemma
Digital Forensics: The Employees' DilemmaDigital Forensics: The Employees' Dilemma
Digital Forensics: The Employees' Dilemma
The Lorenzi Group
 
Rising Cost of Child Porn Defense
Rising Cost of Child Porn DefenseRising Cost of Child Porn Defense
Rising Cost of Child Porn Defense
The Lorenzi Group
 
Security Analytics for Certified Fraud Examiners
Security Analytics for Certified Fraud ExaminersSecurity Analytics for Certified Fraud Examiners
Security Analytics for Certified Fraud Examiners
The Lorenzi Group
 
So, You Want To Work In Digital Forensics....
So, You Want To Work In Digital Forensics....So, You Want To Work In Digital Forensics....
So, You Want To Work In Digital Forensics....
The Lorenzi Group
 
Digital Forensics: Yesterday, Today, and the Next Frontier
Digital Forensics: Yesterday, Today, and the Next FrontierDigital Forensics: Yesterday, Today, and the Next Frontier
Digital Forensics: Yesterday, Today, and the Next Frontier
The Lorenzi Group
 
Digital Forensics & eDiscovery for the Financial Executive
Digital Forensics & eDiscovery for the Financial ExecutiveDigital Forensics & eDiscovery for the Financial Executive
Digital Forensics & eDiscovery for the Financial Executive
The Lorenzi Group
 
Digital Forensics, eDiscovery & Technology Risks for HR Executives
Digital Forensics, eDiscovery & Technology Risks for HR ExecutivesDigital Forensics, eDiscovery & Technology Risks for HR Executives
Digital Forensics, eDiscovery & Technology Risks for HR Executives
The Lorenzi Group
 
eDiscovery IS Data Security
eDiscovery IS Data SecurityeDiscovery IS Data Security
eDiscovery IS Data Security
The Lorenzi Group
 
Active Network Monitoring brings Peace of Mind
Active Network Monitoring brings Peace of MindActive Network Monitoring brings Peace of Mind
Active Network Monitoring brings Peace of Mind
The Lorenzi Group
 
Introduction to the Epsilon Data Breach
Introduction to the Epsilon Data BreachIntroduction to the Epsilon Data Breach
Introduction to the Epsilon Data Breach
The Lorenzi Group
 
Sex, Crime, & Online Slime
Sex, Crime, & Online SlimeSex, Crime, & Online Slime
Sex, Crime, & Online Slime
The Lorenzi Group
 
Productivity 3.0
Productivity 3.0Productivity 3.0
Productivity 3.0
The Lorenzi Group
 

More from The Lorenzi Group (18)

The Many Faces of SHIELD
The Many Faces of SHIELDThe Many Faces of SHIELD
The Many Faces of SHIELD
 
ROAR Provides Peace of Mind in Digital Enviroments
ROAR Provides Peace of Mind in Digital EnviromentsROAR Provides Peace of Mind in Digital Enviroments
ROAR Provides Peace of Mind in Digital Enviroments
 
ROARing Compliance
ROARing ComplianceROARing Compliance
ROARing Compliance
 
ROAR in Real Life: Picture Perfect
ROAR in Real Life: Picture PerfectROAR in Real Life: Picture Perfect
ROAR in Real Life: Picture Perfect
 
ROAR in Pictures: Biking
ROAR in Pictures: BikingROAR in Pictures: Biking
ROAR in Pictures: Biking
 
DDoS Explained
DDoS ExplainedDDoS Explained
DDoS Explained
 
Digital Forensics: The Employees' Dilemma
Digital Forensics: The Employees' DilemmaDigital Forensics: The Employees' Dilemma
Digital Forensics: The Employees' Dilemma
 
Rising Cost of Child Porn Defense
Rising Cost of Child Porn DefenseRising Cost of Child Porn Defense
Rising Cost of Child Porn Defense
 
Security Analytics for Certified Fraud Examiners
Security Analytics for Certified Fraud ExaminersSecurity Analytics for Certified Fraud Examiners
Security Analytics for Certified Fraud Examiners
 
So, You Want To Work In Digital Forensics....
So, You Want To Work In Digital Forensics....So, You Want To Work In Digital Forensics....
So, You Want To Work In Digital Forensics....
 
Digital Forensics: Yesterday, Today, and the Next Frontier
Digital Forensics: Yesterday, Today, and the Next FrontierDigital Forensics: Yesterday, Today, and the Next Frontier
Digital Forensics: Yesterday, Today, and the Next Frontier
 
Digital Forensics & eDiscovery for the Financial Executive
Digital Forensics & eDiscovery for the Financial ExecutiveDigital Forensics & eDiscovery for the Financial Executive
Digital Forensics & eDiscovery for the Financial Executive
 
Digital Forensics, eDiscovery & Technology Risks for HR Executives
Digital Forensics, eDiscovery & Technology Risks for HR ExecutivesDigital Forensics, eDiscovery & Technology Risks for HR Executives
Digital Forensics, eDiscovery & Technology Risks for HR Executives
 
eDiscovery IS Data Security
eDiscovery IS Data SecurityeDiscovery IS Data Security
eDiscovery IS Data Security
 
Active Network Monitoring brings Peace of Mind
Active Network Monitoring brings Peace of MindActive Network Monitoring brings Peace of Mind
Active Network Monitoring brings Peace of Mind
 
Introduction to the Epsilon Data Breach
Introduction to the Epsilon Data BreachIntroduction to the Epsilon Data Breach
Introduction to the Epsilon Data Breach
 
Sex, Crime, & Online Slime
Sex, Crime, & Online SlimeSex, Crime, & Online Slime
Sex, Crime, & Online Slime
 
Productivity 3.0
Productivity 3.0Productivity 3.0
Productivity 3.0
 

ROAR in Real Like: Heartbeat Helper

  • 2. The Situation  Missy Cheevious was an average salesperson at Heartbeat Helper Co.  She made her numbers but wasn’t the best (or worst) on the sales team  Heartbeat Helper is (still) a leading player in the Medical Device Industry.  Heartbeat Helper is seeing new competitors come into the market.  There was no reason to suspect Missy Cheevious would leave the company.  Heartbeat Helper is a ROAR client
  • 3. The Event  During the Superbowl, ROAR Analysts are alerted that Missy Cheevious had logged into the corporate network.  While logged in, she downloaded confidential sales documents, changed the file names, and emailed them to a webmail address (hers).  This was an anomaly because Missy Cheevious:  Had never logged in on the weekend before  Logged in during the Superbowl!  Copied and changed the name of confidential documents  Emailed them to her private webmail address  Logged in for less than 4 minutes
  • 4. What did ROAR see? 1. Someone logging into a user account 2. Someone going across the network to a shared drive 3. Someone changing the names of the files and saving the files locally 4. Someone opening their email client and emailing the files (with names changed) to a webmail address
  • 5. ROAR in Action 1. ROAR Analyst verified findings 1. Webmail addresses belonged to employee 2. ROAR Analyst contacted client 1. Client contacted within MINUTES 3. Client SHOCKED we were watching system during Superbowl (YAY! ROAR exceeded expectations) 4. Client SHOCKED about employee activity 5. List of evidence and all files emailed, ftp’d and saved to USB for past 30 days sent to client
  • 6. ROAR Aftermath for Missy Cheevious  Monday (after the Superbowl)  Employee called in sick  Employee access terminated  Tuesday AM  Employee admitted to skipping work for job interview  Missy Cheevious was terminated Upon termination: 1. Employee was provided a list of documents (including the “Superbowl” documents) that Heartbeat Helper considers confidential 2. Heartbeat Helper informed employee that if any information from those documents is used, Missy Cheevious and her new employer will face legal action.
  • 7. Wrap Up  Lorenzi ROAR is a 24x7 monitoring service  ROAR looks for anomalies  ROAR is used for:  Security  Compliance  Productivity  In this matter, there would have been a HIPAA compliance issue, had the data been allowed to leave Heartbeat Helper. ROAR protected Heartbeat Helper
  • 8. Are YOU Ready for a FREE Trial of ROAR? Robert Fitzgerald The Lorenzi Group 866-632-9880 x123 www.thelorenzigroup.com rfitzgerald@thelorenzigroup.com