Insider Threats^LJ Its Business Impact and Mitigation v1.pdf

ragsgopalan 11 views 57 slides Aug 01, 2024
Slide 1
Slide 1 of 57
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41
Slide 42
42
Slide 43
43
Slide 44
44
Slide 45
45
Slide 46
46
Slide 47
47
Slide 48
48
Slide 49
49
Slide 50
50
Slide 51
51
Slide 52
52
Slide 53
53
Slide 54
54
Slide 55
55
Slide 56
56
Slide 57
57

About This Presentation

Insider Threats and Business Impact


Slide Content

Raguram Gopalan
Personal Info:
Location: Bangalore, India
Email: [email protected]
LinkedIn: www.linkedin.com/ragsgopalan
Academia & Interests:
•MBA–Systems&Marketing
(UniversityofMadras.GoldMedallist)
•BE–ECEngineering,CIT,Coimbatore
•TBEM(MalcolmBaldridge)Auditor
•Lead-Ethics/POSHCommittee
•Mentor–WomenCareerDevelopment
Initiatives
•MentorforEmergingEntrepreneurs
Volunteering & Hobbies:
•FounderTrustee–AJFoundation,
EducatingUnderprivilegedKids
•Author|Philosophy,Yoga,Pranichealing
&Martialarts.
2003-2004: Mphasis Limited, Bangalore
Head Global Service Delivery (Msource)
2004-2007: TATA BSS Limited, Pune
CIO & VP –Business Excellence
2007-2009: Nortel Networks Limited, Gurgaon
Program Director–Managed Services
Head Consulting Services –APAC, ME
2009-2010: Avaya India Pvt Ltd
Managing Director –APS, APAC
2010-2012: AGC Networks Limited
Sr Vice President –Business Transformation
2012-2018: TATA BSS Limited
Sr Vice President –Business Transformation
CIO & Chief Digital Officer
2018 Onwards:
Founder & Managing partner –Haraa Labs LLC
Principal Partner –Vistas Global
Leadership Roles
Founder & Managing Partner –Haraa Labs LLC
Top 50 Tech Leaders | 2019, Intercon Dubai
Successful career for 27+ years as Business Services leader in multi-
cultural markets like US, Middle East & APAC.
KeySkills:
•Buildprofitablenewrevenuestreams.(Digital|Services).
•LeadChangeManagement&Organizationaltransformation.
•AbilitytodecodeFinancial,Functional,TechnicalandProcess
complexitiesofaContract&itsinterplay.
•AbilitytoBuild,motivateandworkwithmulti-culturalteams
thataresuccessful–BothInternalandExternal.
•“Achiever”asanindividual,“Mentor”inateam.“Change
Agent”inanOrganization&bestasa“Starter”.
SuccessStories:
•16+yearsinleadershippositions.
Havesuccessfully:
•Built4profitableSBUswithnewrevenuestreams.Partofthe
Monetizationprogramfor2ofthem.
•BuiltDigitalaccelerationprogramswithnewproductsand
revenuestreamsadding$30m+revenuesintoplinein2years.
•Lead4Organizationalmergersandtransitionssuccessfully.
•BuiltandLeadan$100m+contract-LargestContactcenter
automationprogramforthelargestTelco.
•19yearsinIT/BPOIndustrywithcreditofdesigning&building
50+OutsourcedContactcentresandVoiceNetworks.

www.haraalabs.co| Middle East, India, US |

























More than 1 per month
68% Organizations felt that the threats are
increasing with time.





• €
• €












•Anthem, had made considerable investments in its
security system (more than $230million) after a 2015
cyber attack.Unfortunately, all these security
improvements couldn’t help in this situation.
•Better Vendor Selection process. Vendor Audits of
Security Policy.


Insider theft exposes data of 18,000 Medicare members











Example of Organized Corporate espionage by Chinese on US Companies
























•Business Ecosystem
•IT Policies & Procedures
•IS Policies & Procedures
•HR Policies & Procedures
•Learning & Development
•Outsourcing Policies
•Supply Chain Management
•Forensic Audits & Investigation
•Communication & Notifications
•Statutory Considerations
•Legal Considerations
Its not an IT or IS Department Problem

Identity and Access Management is one of the Key Improvement Areas




•Subject Attributes:
✓Organization
✓Department / Domain
✓Skill, Skill Level, SOD
✓Employee / 3
rd
party
✓Role / Hierarchy
✓Personal Identification
✓Person / Non-Person
(BOT)














Authentication: Act of Verifying the Subject.
Authorization: Decision to permit/ deny the actions on the Object.


• •

••


•AccessGovernanceincludes
RiskManagement Services,
PeriodicAccessCertification,
andRecommendations for
continuousimprovement.

Independent BOT Controllers








UsernameandPassword,
LDAP, Windows
authentication, RSA,
SecurID, Web SSO,
RADIUS,PKI,Smartcards

India
~1millionscompanieswith~$320bin
paidupcapitalwith30million+
employeesinorganizedsector.There
are~8.5mshops&establishments
with~16memployees.
Worldwide:
~200 millions companies
with ~1.4B employees
US:
~23 millions
companies with
~140m employees















1
trustnow
2
Observe IT
3
Cyber Arc
4
Beyond Trust
FEATURES
Product Comparison with Features
Privileged user’s activity
Single Connection Point
Privileged Session
Management
Privileged Accounts
Management
Risk-based Session Review
Rotate and Randomise
Privileged Credentials
Auto login for connected severs
Privileged user behavior analytics
Threat Detection, Containment
and Analytics
Password vault key management
Safely Store Passwords
Shared user privileges management
Super user accesses based on
workflow rules for a limited
duration
Reports type
Text, OCR, Keylogger
Object logging
Video(Monitor and Record Privileged
Sessions)
All details based on our internal assessment and available data in public domain