Certified Banking Cybersecurity Frontline Professional – Level 2 instructor: Kevin F. Streff – Founder and managing partner American security and privacy, llc 1 1 Certified Cyber Frontline Professional American Security and Privacy, LLC
Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427
Agenda Cybersecurity Board Member Certification – level 2 3 Module Topic Module 1 Review of Level 1 content Module 2 Understand additional security threats for frontline staff Module 3 Understand additional cybersecurity frontline best practices Module 4 Overview of remote work cybersecurity best practices 3 Certified Cyber Frontline Professional American Security and Privacy, LLC
Module 3 Understand additional cybersecurity frontline best practices 4 Certified Cyber Frontline Professional American Security and Privacy, LLC
Phishing Awareness: Teach frontline staff how to identify and avoid phishing attempts, including emails, phone calls, and messages that appear suspicious or urgent. Password Security: Emphasize the importance of strong, unique passwords and the dangers of sharing credentials. Social Engineering: Educate frontline staff about social engineering tactics, such as pretexting and tailgating, and how to respond to such situations. Data Security: Provide guidance on handling sensitive data, including proper storage, transmission, and disposal methods. Malware Prevention: Teach frontline staff how to recognize and avoid malware, such as viruses, spyware, and ransomware. Incident Response: Outline the steps frontline staff should take if they suspect a cyberattack, including reporting the incident to the appropriate authorities. Frontline Best Practices 5 Certified Cyber Frontline Professional
Unusual activity : Unexpected changes in system behavior or performance. Unauthorized access : Detection of access attempts from unknown or suspicious sources. Data anomalies : Unexplained modifications or deletions of data. Security alerts : Notifications from security tools indicating potential threats. Ideas to Identify Incidents 6 Certified Cyber Frontline Professional
Suspicious emails Suspicious activity from a co-worker Uninvited guests Suspicious people Ransomware letter Computer acting goofy Computer ssssssllllllllllooooooooowwwww Stuff missing Examples 7 Certified Cyber Frontline Professional
Communicate with relevant management right away! If they are not available, contact the Information Security Officer Begin to document what is going on Capture screen shots or get evidence Act quickly and follow a cybersecurity incident response plan to minimize damage and exposure Steps After You Identify An Incident 8 Certified Cyber Frontline Professional
Phishing Awareness T each frontline staff how to identify and avoid phishing attempts, including emails, phone calls, and messages that appear suspicious or urgent. Certified Cyber Frontline Professional 9
Password Security Emphasize the importance of strong, unique passwords and the dangers of sharing credentials. Use strong passwords D o not share accounts or passwords Use passphrases if you can Password vaults are good Do not write them down at work Do not use the common passwords Do not use dictionary words or names Certified Cyber Frontline Professional 10
Social Engineering Educate frontline staff about social engineering tactics, such as pretexting and tailgating, and how to respond to such situations. Certified Cyber Frontline Professional 11
Provide guidance on handling sensitive data, including proper storage, transmission, and disposal methods. Shredding Clean desk policy Remote work policy Public space conversations Talking about accountholders or cardholders Always verify People over the phone People in a branch Vendors Records retention Destruction techniques Data Security 12 Certified Cyber Frontline Professional
Teach frontline staff how to recognize and avoid malware, such as viruses, spyware, and ransomware. Malware is malicious software Spyware Adware Trojan Worm Virus Ransomware Do no disable or mess with you antivirus product Be sure to run an antivirus product at home if using your home machine Malware Prevention 13 Certified Cyber Frontline Professional
Frontline staff must use good security practices when working from the office or from home. 14 Certified Cyber Frontline Professional American Security and Privacy, LLC
Dr. Kevin Streff 15 Certified Cyber Frontline Professional American Security and Privacy, LLC American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com [email protected] 605.270.4427 www.drstreff.com