SlideShare a Scribd company logo
1 of 20
Download to read offline
and suddenly I see ...
                            turning security data into information you can rely on.



                            wim remes
                            wremes@gmail.com
                            @wimremes


Tuesday 27 September 2011
about me ...




                                    information security manager
                                            big 4 company
                            incident response/security management/SIEM
                             [running in the 2011 (ISC)2 board elections]



Tuesday 27 September 2011
http://www.infosecmentors.com

                                           http://www.pentest-standard.org




                 http://www.eurotrashsecurity.eu


Tuesday 27 September 2011
BruCON

                 2009       2010     2011




Tuesday 27 September 2011
TOOLS


Tuesday 27 September 2011
Excel ...




                            http://peltiertech.com/WordPress/excel-chart-types/

Tuesday 27 September 2011
Taking the leap...




Tuesday 27 September 2011
MASTERS


Tuesday 27 September 2011
Edward Tufte




                       Stephen Few


Tuesday 27 September 2011
Stephen Few
               13 mistakes you’re no longer allowed to make
                            1. Exceeding the boundaries of a single screen
                            2. Supplying inadequate context for the data
                            3. Displaying excessive detail or precision
                            4. Choosing a deficient measure
                            5. Choosing inappropriate display media
                            6. Introducing meaningless variety
                            7. Using poorly designed display media
                            8. Encoding quantitative data inaccurately
                            9. Arranging the data poorly
                            10. Highlighting important data ineffectively or not at all
                            11. Cluttering the display with useless decoration
                            12. Misusing or overusing color
                            13. Designing an unattractive visual display



                                           http://www.perceptualedge.com/blog/

Tuesday 27 September 2011
Edward Tufte
                                  “Data can be beautiful,
                                  data should be beautiful”




Tuesday 27 September 2011
TIPS
                             and
                            TRICKS

Tuesday 27 September 2011
Infographs




                5   6       7   8 9 10   11   12 13




                 courtesy of ZoneAlarm (by Checkpoint)

Tuesday 27 September 2011
your favorite VM platform


                                                              Vulnerabilities by Severity Level

                                                          5

                                                          4

                                                          3

                                                          2

                                                          1

                                                              0      25      50      75     100


                                  compared to what ?
                                 last year? last month?




Tuesday 27 September 2011
GRC : Sponsored by Crayola   (tm)




Tuesday 27 September 2011
The dark side has ∏




Tuesday 27 September 2011
In other words ...

                                                                                                         DE



                            CN          US           NL            US           US           BE
                                                                              Great Lakes                KEYWEB
                            TimeNet   VolumeDrive   EuroAccess   RoadRunner               ISPSYSTEM-AS
                                                                                Comnet                     AS




Tuesday 27 September 2011
Or if you really want pie ...
                                          NL



                                 CN               BE



                                                   DE




                                         US



Tuesday 27 September 2011
Dashboarding 101




Tuesday 27 September 2011
Key take-aways


                1. Don’t rely on tools
                2. Think outside the box
                3. Simple = Better
                4. It’s not THAT hard




Tuesday 27 September 2011

More Related Content

Similar to And suddenly I see ... IDC IT Security Brussels 2011

Tomatsu Seminar Presentation 110920
Tomatsu Seminar Presentation 110920Tomatsu Seminar Presentation 110920
Tomatsu Seminar Presentation 110920
Chika Watanabe
 

Similar to And suddenly I see ... IDC IT Security Brussels 2011 (9)

Node Stream
Node StreamNode Stream
Node Stream
 
Can Media Queries Save Us All?
Can Media Queries Save Us All?Can Media Queries Save Us All?
Can Media Queries Save Us All?
 
videocourse
videocoursevideocourse
videocourse
 
Web heresies
Web heresiesWeb heresies
Web heresies
 
A Desktop UI with QtQuick
A Desktop UI with QtQuickA Desktop UI with QtQuick
A Desktop UI with QtQuick
 
Project Management and the iPad
Project Management and the iPadProject Management and the iPad
Project Management and the iPad
 
Networks and online journalism
Networks and online journalismNetworks and online journalism
Networks and online journalism
 
Tomatsu Seminar Presentation 110920
Tomatsu Seminar Presentation 110920Tomatsu Seminar Presentation 110920
Tomatsu Seminar Presentation 110920
 
Case Study - Panasonic Europe Powered by Apache Solr
Case Study - Panasonic Europe Powered by Apache SolrCase Study - Panasonic Europe Powered by Apache Solr
Case Study - Panasonic Europe Powered by Apache Solr
 

More from wremes

Crème Brulée :-)
Crème Brulée :-)Crème Brulée :-)
Crème Brulée :-)
wremes
 
Vinnes jayson koken
Vinnes jayson kokenVinnes jayson koken
Vinnes jayson koken
wremes
 
Blackhat Workshop
Blackhat WorkshopBlackhat Workshop
Blackhat Workshop
wremes
 

More from wremes (19)

Distributed Denial Of Service Introduction
Distributed Denial Of Service IntroductionDistributed Denial Of Service Introduction
Distributed Denial Of Service Introduction
 
Intro to Malware Analysis
Intro to Malware AnalysisIntro to Malware Analysis
Intro to Malware Analysis
 
Crème Brulée :-)
Crème Brulée :-)Crème Brulée :-)
Crème Brulée :-)
 
Vinnes jayson koken
Vinnes jayson kokenVinnes jayson koken
Vinnes jayson koken
 
Build Your Own Incident Response
Build Your Own Incident ResponseBuild Your Own Incident Response
Build Your Own Incident Response
 
Secure Abu Dhabi talk
Secure Abu Dhabi talkSecure Abu Dhabi talk
Secure Abu Dhabi talk
 
Collaborate, Innovate, Secure
Collaborate, Innovate, SecureCollaborate, Innovate, Secure
Collaborate, Innovate, Secure
 
Data Driven Infosec Services
Data Driven Infosec ServicesData Driven Infosec Services
Data Driven Infosec Services
 
SOPA 4 dummies
SOPA 4 dummiesSOPA 4 dummies
SOPA 4 dummies
 
Blackhat Workshop
Blackhat WorkshopBlackhat Workshop
Blackhat Workshop
 
SIEM brown-bag presentation
SIEM brown-bag presentationSIEM brown-bag presentation
SIEM brown-bag presentation
 
10 things we're doing wrong with SIEM
10 things we're doing wrong with SIEM10 things we're doing wrong with SIEM
10 things we're doing wrong with SIEM
 
Fosdem10
Fosdem10Fosdem10
Fosdem10
 
OSSEC @ ISSA Jan 21st 2010
OSSEC @ ISSA Jan 21st 2010OSSEC @ ISSA Jan 21st 2010
OSSEC @ ISSA Jan 21st 2010
 
Open Source Security
Open Source SecurityOpen Source Security
Open Source Security
 
Teaser
TeaserTeaser
Teaser
 
Ossec Lightning
Ossec LightningOssec Lightning
Ossec Lightning
 
Brucon presentation
Brucon presentationBrucon presentation
Brucon presentation
 
Pareto chart using Openoffice.org
Pareto chart using Openoffice.orgPareto chart using Openoffice.org
Pareto chart using Openoffice.org
 

Recently uploaded

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 

Recently uploaded (20)

08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 

And suddenly I see ... IDC IT Security Brussels 2011

  • 1. and suddenly I see ... turning security data into information you can rely on. wim remes wremes@gmail.com @wimremes Tuesday 27 September 2011
  • 2. about me ... information security manager big 4 company incident response/security management/SIEM [running in the 2011 (ISC)2 board elections] Tuesday 27 September 2011
  • 3. http://www.infosecmentors.com http://www.pentest-standard.org http://www.eurotrashsecurity.eu Tuesday 27 September 2011
  • 4. BruCON 2009 2010 2011 Tuesday 27 September 2011
  • 6. Excel ... http://peltiertech.com/WordPress/excel-chart-types/ Tuesday 27 September 2011
  • 7. Taking the leap... Tuesday 27 September 2011
  • 9. Edward Tufte Stephen Few Tuesday 27 September 2011
  • 10. Stephen Few 13 mistakes you’re no longer allowed to make 1. Exceeding the boundaries of a single screen 2. Supplying inadequate context for the data 3. Displaying excessive detail or precision 4. Choosing a deficient measure 5. Choosing inappropriate display media 6. Introducing meaningless variety 7. Using poorly designed display media 8. Encoding quantitative data inaccurately 9. Arranging the data poorly 10. Highlighting important data ineffectively or not at all 11. Cluttering the display with useless decoration 12. Misusing or overusing color 13. Designing an unattractive visual display http://www.perceptualedge.com/blog/ Tuesday 27 September 2011
  • 11. Edward Tufte “Data can be beautiful, data should be beautiful” Tuesday 27 September 2011
  • 12. TIPS and TRICKS Tuesday 27 September 2011
  • 13. Infographs 5 6 7 8 9 10 11 12 13 courtesy of ZoneAlarm (by Checkpoint) Tuesday 27 September 2011
  • 14. your favorite VM platform Vulnerabilities by Severity Level 5 4 3 2 1 0 25 50 75 100 compared to what ? last year? last month? Tuesday 27 September 2011
  • 15. GRC : Sponsored by Crayola (tm) Tuesday 27 September 2011
  • 16. The dark side has ∏ Tuesday 27 September 2011
  • 17. In other words ... DE CN US NL US US BE Great Lakes KEYWEB TimeNet VolumeDrive EuroAccess RoadRunner ISPSYSTEM-AS Comnet AS Tuesday 27 September 2011
  • 18. Or if you really want pie ... NL CN BE DE US Tuesday 27 September 2011
  • 19. Dashboarding 101 Tuesday 27 September 2011
  • 20. Key take-aways 1. Don’t rely on tools 2. Think outside the box 3. Simple = Better 4. It’s not THAT hard Tuesday 27 September 2011