1/24
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Target data breach (2013)
Hackers stole ~40 million credit/debit card details from Target via a third-party HVAC supplier's stolen credentials
RAM scraper
Malware that reads card data from a system's memory before it gets encrypted
Supply chain attack
Attacking an organization through a trusted third-party vendor instead of directly
How hackers got into Target
Phished an employee at Fazio Mechanical (Target's HVAC supplier) to steal access credentials
Why Target's anti-malware missed the attack
The malware was new/unknown, so none of Target's 40 anti-malware tools could detect it
Target breach - total estimated cost
Around $1-2 billion in losses, plus direct costs of roughly $200 million
Direct payout costs of a cyberattack
Incident response/forensics, victim compensation, regulator fines, legal fees, stolen financial assets
Consequential business loss
Long-term damage like reputation loss and customer churn after a breach
Cyber resilience
An organization's ability to prevent, detect, respond to, and recover from cyberattacks
Cyber Champions
Organizations that balance strong security with business strategy — best at stopping and recovering from attacks
Business Blockers
Organizations that prioritize security so heavily it gets in the way of business goals
Cyber Risk Takers
Organizations that prioritize business growth/speed and accept higher cyber risk
The Vulnerable
Organizations with weak security AND poor alignment to business strategy — worst off
Amateur hacker / script kiddie
Hobbyist hacker with low skill, not motivated by money, often just curious
Hacktivist
Hacker motivated by ideology or political/social causes, not money
Cyber terrorist
Group using cyberattacks to pursue political change through fear or violence
Nation-state / state-sponsored cyberteam
Hacking team funded and directed by a government, often tied to intelligence agencies
Mercenary hacking team
Small group of skilled specialists who sell hacking services (malware, botnets, exploits) to others
Why information security matters to a business
It protects the business's ability to function, its data, its applications, and its technology assets — not just "IT stuff"
Why security is a management issue, not just technical
Because it should be judged by business impact and cost of downtime, and requires ongoing oversight from management, not just IT
CIO (Chief Information Officer)
Senior executive who advises the CEO on strategic planning around managing company information
CISO (Chief Information Security Officer)
Executive responsible for assessing, managing, and implementing information security; usually reports to the CIO
Data owner
Senior manager accountable for the security and use of a specific set of data
Data custodian
Person responsible for the systems that process, store, and transmit data on behalf of the data owner
Data user
Any employee in the organization — everyone shares responsibility for keeping data secure