GenCyber Cyber Security Day Presentation

MichaelWHawkinsPMP 74 views 12 slides Apr 30, 2024
Slide 1
Slide 1 of 12
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12

About This Presentation

My presentation at the Lehigh Carbon Community College (LCCC) NSA GenCyber Cyber Security Day event that is intended to foster an interest in the cyber security field amongst college students.


Slide Content

GenCyber Cyber Security Day Presenter: Michael Hawkins President and CEO of Netizen Corp.

Michael Hawkins, founder of Netizen Corporation, a provider of cyber security solutions for government, defense, and commercial markets. U.S. Army Veteran: former Military Police investigator and Information Systems Security Officer (ISSO). Bachelors Degree in Computer Science plus CISSP, PMP, and other industry certifications. Former software engineer, data security/compliance specialist, and program manager for DoD and VA. Supported national initiatives for executives at VA under Secretary Shinseki. Adjunct professor at Lehigh Carbon Community College (LCCC) teaching CIS and related courses. About Me

Awards and Recognition U.S. Department of Labor HIREVets Platinum Medallion award for veteran hiring, retention & support. Lehigh Valley “Top Forty Under 40” award recipient Recognized as an Inc. Magazine nationwide Best Workplace Lehigh Valley “Power 100” list last four years of the most influential and impactful people in the region Lehigh Valley (PA) Veteran Owned Business of the Year (2 awards) An Inc. 5000 Fastest Growing Company at #47 and #185

“There are only two types of companies: Those that have been hacked and those that will be hacked.” – Robert S. Mueller, III Former Director of the FBI

Ransomware is pervasive but there has been an exponential increase in all types of threats. Trends in Cyber Attacks Social engineering and Phishing are becoming increasingly more common & complex leveraging social media platforms. Automation: AI tools to help script and deepfake are powerful. Attacks require less expertise and time but with higher payoffs. Nation states are becoming more involved in targeted disruption of critical resources like hospitals, water, power, transportation, etc. Devices that enable work-from-anywhere are increasingly targets.

Russia-linked group targeted Texas water supply for town of 5,000. Recent Nation State Cyber Attacks Iran-linked group targets and disrupts operations at Boston Children’s Hospital network Western Pennsylvania water authority had Iran-linked group hack it which affected the water supply to the town of Aliquippa. Russia-linked group attacked multiple federal agencies, including the Department of Energy. “Cyber Army of Russia” targeted U.S. water and power authorities.

Costs of a breach are increasing - $164 per record; $5.5M average for all businesses and $120k to $1.4M for small businesses to recover. Costs of Cyber Attacks Average ransomware payment had reached $26,000 in 2023. People continue to pay rather than plan and prevent, making ransomware stay highly profitable. Cost to carry out attacks are down dramatically. Ransomware can be bought for as little as $700; Phishing scam $30; Denial of Service/Bots as little as $5 for a website.

Security-as-a-Service becoming popular. Outsources complex tasks and security testing services to dedicated third parties. Trends in Cyber Defense Leveraging of AI/ML tools to detect anomalous activity faster. SIEM tools growing in popularity even at smaller organizations. Training as a first line defense. Becoming “cyber aware” to detect threats at the source, including insider threats. Focusing on containment as well as prevention – acknowledging that certain attacks are very likely to happen but have a plan. Regulatory requirements are increasing, as are penalties ($$$).

Industry in general is in desperate need of talent, especially technical. Cyber Employment Trends Many different avenues for a cyber career – policy, risk, technology, compliance, training, offensive, defensive, etc. People who can make use of AI/ML tools are needed. People with hands-on technical experience are highly valued. People who can make security seamless (bridging gaps between business and security) are needed. Diversity of backgrounds needed. Up-skilling is necessary – working with colleges, etc. to grow workforce.

What employers are looking for per LinkedIn survey of job postings: Scripting and programming languages Intrusion and threat prevention Risk identification and management Data security and assurance General security operations Threat analysis Communication and critical thinking skills. Cyber Employment Trends

Over 5.5 million people work in cyber globally; highest number ever. Cyber Employment Stats Over 32% growth predicted in the U.S. alone 2022-2032. Median wage for someone with 5 years experience is over $110k. Nearly 100% employment rate in the industry today. Over 3.5 million global vacancies predicted by 2025. Less than 70% of open jobs are filled today, and they take months.

Questions?
Tags