<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2023-04-25_meeting_notes in Cleveland Chapter Discussion Forum</title>
    <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/2023-04-25-meeting-notes/m-p/58805#M22</link>
    <description>&lt;P&gt;# ISC2 Meeting Notes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Date: 2023/04/25&lt;BR /&gt;Start Time: 5:30 PM EST&lt;/P&gt;&lt;P&gt;Location: TrustedSec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Board Attendees&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-[X] President - Christopher Hartley&lt;BR /&gt;-[X] Treasurer - Ted Kozenko&lt;BR /&gt;-[X] Membership Chair - Troy Sheley&lt;BR /&gt;-[X] Secretary - Geoff Sternecker&lt;BR /&gt;-[ ] Emeritus - Robert Nettgen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Sponsors&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dell - Primary financial sponsor&lt;BR /&gt;TrustedSec - Meeting room &amp;amp; facilities&lt;BR /&gt;Improving - ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Topics&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Chatham House Rule&lt;BR /&gt;* Officer Introductions for 2023&lt;BR /&gt;Five (5) new attendees&lt;BR /&gt;* ISC2 surveys have been sent out from the mothership.&lt;BR /&gt;* ISS upcoming at the IX center, Last Week of October 26th Early Bird is now open.&lt;BR /&gt;* NEO Cyber Security Day, ISC2, ISACA, INFRAGARD at the Galaxy May 12th 300 person limit $65.&lt;BR /&gt;* Budget coverage&lt;BR /&gt;$9,596.79 as of 4.25.23&lt;BR /&gt;Catering, ~$600&lt;BR /&gt;Eventbrite, $15.00&lt;BR /&gt;Carry out containers, $20.00&lt;/P&gt;&lt;P&gt;Summer Family cookout, June $10 per person&lt;BR /&gt;Need volenteers, need raffle items&lt;/P&gt;&lt;P&gt;I think, we should send out a survey. Leaned maybe to yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Security in the wild with Tyler Hudak @secshoggoth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IC3 Annual reports coverage, large numbers may not be reported.&lt;BR /&gt;Investment fraud was the top in 2022.&lt;BR /&gt;180 million in losses reported by companies in Ohio.&lt;BR /&gt;If you have computers or money, you can be a target.&lt;BR /&gt;Not "OT" heavy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 3: Insider threat&lt;BR /&gt;Violence/Sabotage/Databreach &amp;amp; Theft/Attack Collusion&lt;BR /&gt;Someone that falls for a phishing attack is considered an insider threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 2: Ransomware&lt;BR /&gt;The Russia - Ukraine conflict decreased the levels of ransomware.&lt;/P&gt;&lt;P&gt;$8 million is not an unusual cost for a ransomware remediation.&lt;BR /&gt;It is a top tabletop exercise scenario. The attacks go on for months.&lt;BR /&gt;IR will start at 120 hours. Their highest is 300 hours.&lt;BR /&gt;IT and Legal expenses, Communications expenses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 1: BEC, Business Email Compromise&lt;BR /&gt;We changed our account, and then sends out new invoices.&lt;/P&gt;&lt;P&gt;MFA is key, but not foolproof.&lt;BR /&gt;Check if legacy protocols is still enabled on M365.&lt;BR /&gt;Check the enabled applications.&lt;BR /&gt;They set up email rules to hide the emails. Pull everyones email rules and look at forwarding or emails moved to RSS folder.&lt;BR /&gt;Don't delete the rules, disable them. So forensics can evaluate timelines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Speakers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J.R. Cunningham: EVP &amp;amp; Chief Security Officer from nuspire&lt;BR /&gt;"By any measure your industry has failed and continues to fail. I feel bad for you all because you can never get it right."&lt;/P&gt;&lt;P&gt;2017 conversation on a plane with a Top 25 CEO&lt;BR /&gt;Is my industry a failure?&lt;BR /&gt;The history of our Industry and measures of success.&lt;BR /&gt;Bad thing happens, company gets started, money spent. Repeat.&lt;BR /&gt;iPhone changed every regulation in 2007, HIPAA, FISMA, PCI didn't address mobile.&lt;BR /&gt;New things happening every single year from 2018 forward, so the trend didn't change.&lt;BR /&gt;Used SSCMM maturity model for tracking, evaluating.&lt;BR /&gt;Vulnerability management is still the issue, combined with asset inventory.&lt;BR /&gt;Nobody can do DLP, Network segmentation is too difficult, nobody messes with phones.&lt;BR /&gt;Random people from the org buying cloud infrastructure.&lt;BR /&gt;Comparison to the history of fire fighting.&lt;BR /&gt;Where do we go from here slide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## End Time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8:15 PM&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 10:31:02 GMT</pubDate>
    <dc:creator>GeoffS</dc:creator>
    <dc:date>2023-10-09T10:31:02Z</dc:date>
    <item>
      <title>2023-04-25_meeting_notes</title>
      <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/2023-04-25-meeting-notes/m-p/58805#M22</link>
      <description>&lt;P&gt;# ISC2 Meeting Notes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Date: 2023/04/25&lt;BR /&gt;Start Time: 5:30 PM EST&lt;/P&gt;&lt;P&gt;Location: TrustedSec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Board Attendees&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-[X] President - Christopher Hartley&lt;BR /&gt;-[X] Treasurer - Ted Kozenko&lt;BR /&gt;-[X] Membership Chair - Troy Sheley&lt;BR /&gt;-[X] Secretary - Geoff Sternecker&lt;BR /&gt;-[ ] Emeritus - Robert Nettgen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Sponsors&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dell - Primary financial sponsor&lt;BR /&gt;TrustedSec - Meeting room &amp;amp; facilities&lt;BR /&gt;Improving - ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Topics&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Chatham House Rule&lt;BR /&gt;* Officer Introductions for 2023&lt;BR /&gt;Five (5) new attendees&lt;BR /&gt;* ISC2 surveys have been sent out from the mothership.&lt;BR /&gt;* ISS upcoming at the IX center, Last Week of October 26th Early Bird is now open.&lt;BR /&gt;* NEO Cyber Security Day, ISC2, ISACA, INFRAGARD at the Galaxy May 12th 300 person limit $65.&lt;BR /&gt;* Budget coverage&lt;BR /&gt;$9,596.79 as of 4.25.23&lt;BR /&gt;Catering, ~$600&lt;BR /&gt;Eventbrite, $15.00&lt;BR /&gt;Carry out containers, $20.00&lt;/P&gt;&lt;P&gt;Summer Family cookout, June $10 per person&lt;BR /&gt;Need volenteers, need raffle items&lt;/P&gt;&lt;P&gt;I think, we should send out a survey. Leaned maybe to yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Security in the wild with Tyler Hudak @secshoggoth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IC3 Annual reports coverage, large numbers may not be reported.&lt;BR /&gt;Investment fraud was the top in 2022.&lt;BR /&gt;180 million in losses reported by companies in Ohio.&lt;BR /&gt;If you have computers or money, you can be a target.&lt;BR /&gt;Not "OT" heavy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 3: Insider threat&lt;BR /&gt;Violence/Sabotage/Databreach &amp;amp; Theft/Attack Collusion&lt;BR /&gt;Someone that falls for a phishing attack is considered an insider threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 2: Ransomware&lt;BR /&gt;The Russia - Ukraine conflict decreased the levels of ransomware.&lt;/P&gt;&lt;P&gt;$8 million is not an unusual cost for a ransomware remediation.&lt;BR /&gt;It is a top tabletop exercise scenario. The attacks go on for months.&lt;BR /&gt;IR will start at 120 hours. Their highest is 300 hours.&lt;BR /&gt;IT and Legal expenses, Communications expenses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Number 1: BEC, Business Email Compromise&lt;BR /&gt;We changed our account, and then sends out new invoices.&lt;/P&gt;&lt;P&gt;MFA is key, but not foolproof.&lt;BR /&gt;Check if legacy protocols is still enabled on M365.&lt;BR /&gt;Check the enabled applications.&lt;BR /&gt;They set up email rules to hide the emails. Pull everyones email rules and look at forwarding or emails moved to RSS folder.&lt;BR /&gt;Don't delete the rules, disable them. So forensics can evaluate timelines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## Speakers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J.R. Cunningham: EVP &amp;amp; Chief Security Officer from nuspire&lt;BR /&gt;"By any measure your industry has failed and continues to fail. I feel bad for you all because you can never get it right."&lt;/P&gt;&lt;P&gt;2017 conversation on a plane with a Top 25 CEO&lt;BR /&gt;Is my industry a failure?&lt;BR /&gt;The history of our Industry and measures of success.&lt;BR /&gt;Bad thing happens, company gets started, money spent. Repeat.&lt;BR /&gt;iPhone changed every regulation in 2007, HIPAA, FISMA, PCI didn't address mobile.&lt;BR /&gt;New things happening every single year from 2018 forward, so the trend didn't change.&lt;BR /&gt;Used SSCMM maturity model for tracking, evaluating.&lt;BR /&gt;Vulnerability management is still the issue, combined with asset inventory.&lt;BR /&gt;Nobody can do DLP, Network segmentation is too difficult, nobody messes with phones.&lt;BR /&gt;Random people from the org buying cloud infrastructure.&lt;BR /&gt;Comparison to the history of fire fighting.&lt;BR /&gt;Where do we go from here slide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;## End Time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8:15 PM&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:31:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/2023-04-25-meeting-notes/m-p/58805#M22</guid>
      <dc:creator>GeoffS</dc:creator>
      <dc:date>2023-10-09T10:31:02Z</dc:date>
    </item>
  </channel>
</rss>

