SlideShare a Scribd company logo
1 of 20
CyberSecurity:
Top Issues for Public Institutions
Bo Wandschneider
CIO- University of Toronto
Isaac Straley
CISO โ€“ University of Toronto
How Big is the Problem?
Spotlight: Australia Nation University Breach
Details
Accessed in late 2018, announced June 4
Involves โ€œsignificant amountsโ€ of personal staff, student and visitor data extending
back 19 years, ~200,000 affected
may include โ€œnames, addresses, dates of birth, phone numbers, personal email addresses and emergency contact
details, tax file numbers, payroll information, bank account details and passport details. Student academic records were
also accessed.โ€
As a case study
Tracking ~60 stories, national (AU) and international
4
External Reputation Monitoring
6
Whoโ€™s Responsibility is it to defend
against cyber attacks?
One Team, One Fight โ€“ Our Shared Fate
The โ€œOldโ€ Security Model
End state โ€“ โ€œwe are secureโ€
โ€ข Security is ITโ€™s job
โ€ข Lock it down
โ€ข Plugging the holes
โ€ข A solution in search of a problem
โ€ข Security versus convenience
โ€ข โ€œIf only we had moreโ€ฆโ€ Money,
Time, People
โ€ข See no evil, hear no evil, speak no
evil
The โ€œNewโ€ Security Model
End state โ€“ โ€œManaged riskโ€
โ€ข Security is everyoneโ€™s responsibility
โ€ข Enable the mission and values of
the university
โ€ข Empower individuals and units
โ€ข Resources allocated based on risk
โ€ข Assume you are breached โ€“ find
intruders and kick them out!
How Should we Approach Education and
Awareness
Small, personal, specific
โ€ข https://securityplanner.org
โ€ข https://sec.eff.org/topics
โ€ข https://www.sans.org/security-
awareness-training
โ€ข https://myaccount.google.com/s
ecurity-checkup
Tell us More about Phishing
Why are โ€œtheyโ€ trying to get our
Credentials?
Who are โ€œTHEYโ€?
What are we doing in Higher Education?
Canadian Shared Security Operations Centre (CanSSOC) is:
โ€ข A shared proof of concept project
โ€ข Based in part on a model initiated in the US higher education system
โ€ข Being pursued in partnership with six Canadian universities:
โ€ข The University of British Columbia,
โ€ข University of Alberta,
โ€ข McMaster University,
โ€ข McGill University,
โ€ข Ryerson University,
โ€ข University of Toronto.
โ€ข In Partnership with the National Research & Education Network
โ€ข CANARIE โ€“ federal
โ€ข Cybera - Alberta
โ€ข ORION - Ontario
โ€ข RISQ โ€“ Quebec
โ€ข BCNET โ€“ British Columbia
โ€œTogether we see moreโ€
Global profile
Attracting talent
Economies of scale
Higher Ed focus
Questions

More Related Content

Similar to Wandschneider ischool symposium

Conference Report Final 11.18
Conference Report Final 11.18Conference Report Final 11.18
Conference Report Final 11.18
Nancy J. Brandwein
ย 
Scot Secure 2017
Scot Secure 2017Scot Secure 2017
Scot Secure 2017
Ray Bugg
ย 

Similar to Wandschneider ischool symposium (20)

Education to cyber security
Education to cyber securityEducation to cyber security
Education to cyber security
ย 
UW Cybersecurity Lecture 9 - Social Media
UW Cybersecurity Lecture 9 - Social MediaUW Cybersecurity Lecture 9 - Social Media
UW Cybersecurity Lecture 9 - Social Media
ย 
Risk management assessment, education, and action
Risk management   assessment, education, and actionRisk management   assessment, education, and action
Risk management assessment, education, and action
ย 
How children's fingerprints on the web could mean the end of PII Authenticati...
How children's fingerprints on the web could mean the end of PII Authenticati...How children's fingerprints on the web could mean the end of PII Authenticati...
How children's fingerprints on the web could mean the end of PII Authenticati...
ย 
Building a professional digital identity
Building a professional digital identityBuilding a professional digital identity
Building a professional digital identity
ย 
2021-02-10_CogSecCollab_UBerkeley
2021-02-10_CogSecCollab_UBerkeley2021-02-10_CogSecCollab_UBerkeley
2021-02-10_CogSecCollab_UBerkeley
ย 
Distributed defense against disinformation: disinformation risk management an...
Distributed defense against disinformation: disinformation risk management an...Distributed defense against disinformation: disinformation risk management an...
Distributed defense against disinformation: disinformation risk management an...
ย 
Conference Report Final 11.18
Conference Report Final 11.18Conference Report Final 11.18
Conference Report Final 11.18
ย 
Creating A Diverse CyberSecurity Program
Creating A Diverse CyberSecurity ProgramCreating A Diverse CyberSecurity Program
Creating A Diverse CyberSecurity Program
ย 
Scot Secure 2017
Scot Secure 2017Scot Secure 2017
Scot Secure 2017
ย 
Cybersecurity Risk Perception and Communication
Cybersecurity Risk Perception and CommunicationCybersecurity Risk Perception and Communication
Cybersecurity Risk Perception and Communication
ย 
C3 and digital citizenship
C3 and digital citizenshipC3 and digital citizenship
C3 and digital citizenship
ย 
2019 FRSecure CISSP Mentor Program: Class One
2019 FRSecure CISSP Mentor Program: Class One2019 FRSecure CISSP Mentor Program: Class One
2019 FRSecure CISSP Mentor Program: Class One
ย 
Enhanced Cryptographic Solution for Security Issues Faced by Saudi Arabian un...
Enhanced Cryptographic Solution for Security Issues Faced by Saudi Arabian un...Enhanced Cryptographic Solution for Security Issues Faced by Saudi Arabian un...
Enhanced Cryptographic Solution for Security Issues Faced by Saudi Arabian un...
ย 
Building a professional digital identity
Building a professional digital identity Building a professional digital identity
Building a professional digital identity
ย 
ISACA UW Handbook 2016
ISACA UW Handbook 2016ISACA UW Handbook 2016
ISACA UW Handbook 2016
ย 
UKSG 2023 - Cybersecurity 101: What every librarian needs to know about prot...
UKSG 2023 - Cybersecurity 101:  What every librarian needs to know about prot...UKSG 2023 - Cybersecurity 101:  What every librarian needs to know about prot...
UKSG 2023 - Cybersecurity 101: What every librarian needs to know about prot...
ย 
LASI13 ZA 5 july2013 final 1 Paul Prinsloo
LASI13 ZA 5 july2013 final 1 Paul PrinslooLASI13 ZA 5 july2013 final 1 Paul Prinsloo
LASI13 ZA 5 july2013 final 1 Paul Prinsloo
ย 
Sahela presentation 5 july2013 final
Sahela presentation 5 july2013 finalSahela presentation 5 july2013 final
Sahela presentation 5 july2013 final
ย 
Edla615
Edla615Edla615
Edla615
ย 

More from Stephen Abram

More from Stephen Abram (20)

Hub Design Inspirations for B-Hive Zone
Hub Design Inspirations for B-Hive  ZoneHub Design Inspirations for B-Hive  Zone
Hub Design Inspirations for B-Hive Zone
ย 
Passive Interactive Programming and Surveys 2.pptx
Passive Interactive Programming and Surveys 2.pptxPassive Interactive Programming and Surveys 2.pptx
Passive Interactive Programming and Surveys 2.pptx
ย 
Hub Design Inspiration Graphics for inspiration
Hub Design Inspiration Graphics for inspirationHub Design Inspiration Graphics for inspiration
Hub Design Inspiration Graphics for inspiration
ย 
Hub Design Inspiration Graphics for Community Hubs
Hub Design Inspiration Graphics for Community HubsHub Design Inspiration Graphics for Community Hubs
Hub Design Inspiration Graphics for Community Hubs
ย 
Passive Interactive Programming and Surveys 2.pptx
Passive Interactive Programming and Surveys 2.pptxPassive Interactive Programming and Surveys 2.pptx
Passive Interactive Programming and Surveys 2.pptx
ย 
Hub Design Inspiration Graphics for Brockville Hub
Hub Design Inspiration Graphics for Brockville HubHub Design Inspiration Graphics for Brockville Hub
Hub Design Inspiration Graphics for Brockville Hub
ย 
Hub Design Inspiration Graphics second draft
Hub Design Inspiration Graphics second draftHub Design Inspiration Graphics second draft
Hub Design Inspiration Graphics second draft
ย 
Brockville-Active-Transportation-Full-Plan.pdf
Brockville-Active-Transportation-Full-Plan.pdfBrockville-Active-Transportation-Full-Plan.pdf
Brockville-Active-Transportation-Full-Plan.pdf
ย 
Draft Employment Lands 140530 L&G Front Cover.pdf
Draft Employment Lands 140530 L&G Front Cover.pdfDraft Employment Lands 140530 L&G Front Cover.pdf
Draft Employment Lands 140530 L&G Front Cover.pdf
ย 
BrockvilleHubDesignInspirationGraphics.pptx
BrockvilleHubDesignInspirationGraphics.pptxBrockvilleHubDesignInspirationGraphics.pptx
BrockvilleHubDesignInspirationGraphics.pptx
ย 
Caregiver Presentation and Product Inspirations Sep 2023 PDF.pdf
Caregiver Presentation and Product Inspirations Sep 2023 PDF.pdfCaregiver Presentation and Product Inspirations Sep 2023 PDF.pdf
Caregiver Presentation and Product Inspirations Sep 2023 PDF.pdf
ย 
Caregiver Presentation and Product Inspirations Sep 2023 PPT.pptx
Caregiver Presentation and Product Inspirations Sep 2023 PPT.pptxCaregiver Presentation and Product Inspirations Sep 2023 PPT.pptx
Caregiver Presentation and Product Inspirations Sep 2023 PPT.pptx
ย 
CEEED May 24 2023.pdf
CEEED May 24 2023.pdfCEEED May 24 2023.pdf
CEEED May 24 2023.pdf
ย 
CEEED May 24 2023.pptx
CEEED May 24 2023.pptxCEEED May 24 2023.pptx
CEEED May 24 2023.pptx
ย 
CEED Mindfulness in a time of Turbulence.pdf
CEED Mindfulness in a time of Turbulence.pdfCEED Mindfulness in a time of Turbulence.pdf
CEED Mindfulness in a time of Turbulence.pdf
ย 
CEEED Webinar June 22.pdf
CEEED Webinar June 22.pdfCEEED Webinar June 22.pdf
CEEED Webinar June 22.pdf
ย 
CIL Stats Workshop April1 2022 Abram Silk.pdf
CIL Stats Workshop April1 2022 Abram Silk.pdfCIL Stats Workshop April1 2022 Abram Silk.pdf
CIL Stats Workshop April1 2022 Abram Silk.pdf
ย 
Mindfulness in a time of cholera.pptx
Mindfulness in a time of cholera.pptxMindfulness in a time of cholera.pptx
Mindfulness in a time of cholera.pptx
ย 
Sla canada student nov 25 2021
Sla canada student nov 25 2021Sla canada student nov 25 2021
Sla canada student nov 25 2021
ย 
Sla job finding sites
Sla job finding sitesSla job finding sites
Sla job finding sites
ย 

Recently uploaded

VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
ย 
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
ย 
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our EscortsVIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
sonatiwari757
ย 
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
MOHANI PANDEY
ย 

Recently uploaded (20)

Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...Booking open Available Pune Call Girls Shukrawar Peth  6297143586 Call Hot In...
Booking open Available Pune Call Girls Shukrawar Peth 6297143586 Call Hot In...
ย 
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
ย 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at work
ย 
Climate change and occupational safety and health.
Climate change and occupational safety and health.Climate change and occupational safety and health.
Climate change and occupational safety and health.
ย 
Top Rated Pune Call Girls Wadgaon Sheri โŸŸ 6297143586 โŸŸ Call Me For Genuine S...
Top Rated  Pune Call Girls Wadgaon Sheri โŸŸ 6297143586 โŸŸ Call Me For Genuine S...Top Rated  Pune Call Girls Wadgaon Sheri โŸŸ 6297143586 โŸŸ Call Me For Genuine S...
Top Rated Pune Call Girls Wadgaon Sheri โŸŸ 6297143586 โŸŸ Call Me For Genuine S...
ย 
VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Bhavnagar 7001035870 Whatsapp Number, 24/07 Booking
ย 
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 37 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
ย 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
ย 
Call Girls Service Connaught Place @9999965857 Delhi ๐Ÿซฆ No Advance VVIP ๐ŸŽ SER...
Call Girls Service Connaught Place @9999965857 Delhi ๐Ÿซฆ No Advance  VVIP ๐ŸŽ SER...Call Girls Service Connaught Place @9999965857 Delhi ๐Ÿซฆ No Advance  VVIP ๐ŸŽ SER...
Call Girls Service Connaught Place @9999965857 Delhi ๐Ÿซฆ No Advance VVIP ๐ŸŽ SER...
ย 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
ย 
Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024
ย 
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...Call On 6297143586  Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
Call On 6297143586 Yerwada Call Girls In All Pune 24/7 Provide Call With Bes...
ย 
Top Rated Pune Call Girls Hadapsar โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Se...
Top Rated  Pune Call Girls Hadapsar โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Se...Top Rated  Pune Call Girls Hadapsar โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Se...
Top Rated Pune Call Girls Hadapsar โŸŸ 6297143586 โŸŸ Call Me For Genuine Sex Se...
ย 
2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar
ย 
Just Call Vip call girls Wardha Escorts โ˜Ž๏ธ8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts โ˜Ž๏ธ8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts โ˜Ž๏ธ8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts โ˜Ž๏ธ8617370543 Starting From 5K to 25K ...
ย 
EDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptxEDUROOT SME_ Performance upto March-2024.pptx
EDUROOT SME_ Performance upto March-2024.pptx
ย 
PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)PPT Item # 4 - 231 Encino Ave (Significance Only)
PPT Item # 4 - 231 Encino Ave (Significance Only)
ย 
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our EscortsVIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
VIP Call Girl mohali 7001035870 Enjoy Call Girls With Our Escorts
ย 
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
ย 
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Nanded City Call Me 7737669865 Budget Friendly No Advance Booking
ย 

Wandschneider ischool symposium

  • 1. CyberSecurity: Top Issues for Public Institutions Bo Wandschneider CIO- University of Toronto Isaac Straley CISO โ€“ University of Toronto
  • 2. How Big is the Problem?
  • 3.
  • 4. Spotlight: Australia Nation University Breach Details Accessed in late 2018, announced June 4 Involves โ€œsignificant amountsโ€ of personal staff, student and visitor data extending back 19 years, ~200,000 affected may include โ€œnames, addresses, dates of birth, phone numbers, personal email addresses and emergency contact details, tax file numbers, payroll information, bank account details and passport details. Student academic records were also accessed.โ€ As a case study Tracking ~60 stories, national (AU) and international 4
  • 5.
  • 7.
  • 8. Whoโ€™s Responsibility is it to defend against cyber attacks?
  • 9. One Team, One Fight โ€“ Our Shared Fate The โ€œOldโ€ Security Model End state โ€“ โ€œwe are secureโ€ โ€ข Security is ITโ€™s job โ€ข Lock it down โ€ข Plugging the holes โ€ข A solution in search of a problem โ€ข Security versus convenience โ€ข โ€œIf only we had moreโ€ฆโ€ Money, Time, People โ€ข See no evil, hear no evil, speak no evil The โ€œNewโ€ Security Model End state โ€“ โ€œManaged riskโ€ โ€ข Security is everyoneโ€™s responsibility โ€ข Enable the mission and values of the university โ€ข Empower individuals and units โ€ข Resources allocated based on risk โ€ข Assume you are breached โ€“ find intruders and kick them out!
  • 10. How Should we Approach Education and Awareness
  • 11. Small, personal, specific โ€ข https://securityplanner.org โ€ข https://sec.eff.org/topics โ€ข https://www.sans.org/security- awareness-training โ€ข https://myaccount.google.com/s ecurity-checkup
  • 12. Tell us More about Phishing
  • 13. Why are โ€œtheyโ€ trying to get our Credentials?
  • 14.
  • 16.
  • 17. What are we doing in Higher Education?
  • 18. Canadian Shared Security Operations Centre (CanSSOC) is: โ€ข A shared proof of concept project โ€ข Based in part on a model initiated in the US higher education system โ€ข Being pursued in partnership with six Canadian universities: โ€ข The University of British Columbia, โ€ข University of Alberta, โ€ข McMaster University, โ€ข McGill University, โ€ข Ryerson University, โ€ข University of Toronto. โ€ข In Partnership with the National Research & Education Network โ€ข CANARIE โ€“ federal โ€ข Cybera - Alberta โ€ข ORION - Ontario โ€ข RISQ โ€“ Quebec โ€ข BCNET โ€“ British Columbia
  • 19. โ€œTogether we see moreโ€ Global profile Attracting talent Economies of scale Higher Ed focus

Editor's Notes

  1. We can do aย  quick intro on each of us.ย ย  What our role is and where we are from I will include that I have been at three schools, used to report to the Chief Librarian CUCCIO โ€“ CIO Advisory Group CanSSOC โ€“ Steering groupโ€ฆ
  2. Details https://www.anu.edu.au/news/all-news/data-breach Coverage https://www.abc.net.au/news/2019-06-04/anu-data-hack-bank-records-personal-information/11176788 https://www.smh.com.au/politics/federal/china-behind-huge-anu-hack-amid-fears-government-employees-could-be-compromised-20190605-p51uro.html https://www.news.com.au/technology/online/hacking/hackers-access-19-years-of-anu-data/news-story/706018edc770933c19f003da0e8085f7 https://www.theguardian.com/australia-news/2019/jun/06/china-behind-massive-australian-national-university-hack-intelligence-officials-say https://www.theguardian.com/australia-news/2019/jun/06/china-behind-massive-australian-national-university-hack-intelligence-officials-say https://www.bbc.com/news/business-48508192
  3. 85% of known compromised accounts are students, visitors, alumni, etc. 8% of devices on network have critical vulnerabilities
  4. When to make it mandatory? Consider curated topics Interactive โ€“ but no quiz to pass! Phishing awareness
  5. First, it works - most breaches involve stolen credentials We do not detect well What we have โ€“ research, IP, personal information, financial information
  6. May be redundant โ€“ but maybe go deeper into nation states โ€“ name some of them Talk about importance of travelling safe and how we need more security for certain places. Maybe ask them how many have travelled to China, Iran, Russia โ€“ if so, did they take any precautions Introduce the notion of insiders โ€“ maybe some data on how many incidents are based on insidersโ€ฆ. Get into the issue of our students.
  7. Review use of image
  8. A chance to talk about collective action Bring in the JSP, ONCHK, REN SIEMs Reemphasize point made early the it is a team sportโ€ฆ.joining together will make us stronger, able to do more. Talka bout the interest from CSE and CSIS (ISED)