Respond with agility to evolving cyber threats
Transcript
X-TIMESTAMP-MAP=LOCAL:00:00:00.000,MPEGTS:0 [MUSIC PLAYING] Millions of emails are sent every day from all over the globe while most of these are mundane and perfectly normal, some are not. Some are laced with attempts to breach organizations and attack them for a variety of reasons. One of the most insidious types of attacks are designed to compromise and encrypt devices against an organization's will, forcing them to choose between paying off the attacker or losing access to critical data and devices forever. ServiceNow can help you mitigate ransomware attacks by making your organization's security posture more efficient, automated, and responsive with tools like security incident response, threat intelligence, major security incident management, and vulnerability response, working in conjunction with your existing security assets and collaborating with teams from across your organization. With ServiceNow security incident response, you'll be able to increase the amount of fully assessed attack surface in your IT network. Scale your limited resources and improve operational efficiency. It's typical to see a 40% to 60% reduction in the time to resolve security incidents when converting from a more manual and disparate process. Here, a security analyst sees incidents that are assigned to them or their team. Risk scoring allows the analyst to quickly determine the highest priority incidents that need to be addressed first, such as this ransomware incident. Our security analyst has decided to verify what's going on with this incident and scrutinize the data related to it, as well as notify management that they likely have a major security incident on their hands. The security analyst also wants to find out what threat intelligence exist for this ransomware attack. And to do so, they're going to use the threat intelligence that ServiceNow provides in conjunction with the Miter ATT&CK framework. ServiceNow is now fully integrated with Miter ATT&CK for threat intelligence, which can provide valuable insights that security professionals need to see what known patterns of attack this specific type of ransomware uses, it also provides a quick visual of the current security posture for detecting and defending against each of these attack techniques. Miter ATT&CK can assist security leaders in managing security programs by helping them understand how the various defensive systems are performing and identify where there may be any gaps. Paired up with a fully fleshed out configuration management database, analysts can see the who, where, and what indicators of compromise exists for this event. The security analyst knows that this ransomware attack is going to need a prompt and supervised response across different parts of the organization, including management, legal, and engineering. Major security incidents are created when a security incident is promoted, these options are configurable and can happen in one of two ways. Analysts can propose a security incident be promoted to the major security incident manager or commander, which then triggers an internal review process or analysts can immediately promote if warranted. In this case, we'll choose the latter since we know the organization considers a ransomware attack to be a crisis event. This is the major security incident management workspace. Here, the incident commander can coordinate and direct the entire incident response process. And from here, the commander has access to the entire collection of tools and integrations at the disposal. This gives them the ability to see every aspect of the incident quickly and easily, creating a virtual command center. The overview of the major security incident workspace contains metrics that provide a comprehensive look at the major security incident and its related components, such as tasks, duration, incident impact, and collaboration. And as this incident progresses, these charts and diagrams will continue to populate and update. Major security incident management leverages records from across the platform and outside sources. These records are then attached directly to the incident where the data can be viewed and analyzed to work the incident. Major security incident management also provides a centralized repository to store all of the pertinent file artifacts for the incident. Managers can even perform a variety of file operations directly from the UI, such as creating or deleting files and folders and adding or removing user access. Also, this tool allows teams to collaborate across various functions from your organization's C-suite, legal, management, to your security operation center where analysts and vulnerability response teams can collaborate. While the organization deals with this ransomware incident, they also want to make sure that there aren't any more systems that might be vulnerable to this specific attack. To help them do so, ServiceNow vulnerability response will allow the organization to do just that. Organizations face vulnerabilities in the tens and hundreds of millions and an ever expanding attack surface. ServiceNow vulnerability response helps IT and security teams work together with this data at scale, making it easy to find what matters and act on vulnerabilities in bulk, maximizing efficiency and optimizing and orchestrating enterprise security operations. The vulnerability response application provides a single system of action and engagement, integrating with a wide selection of vulnerability scanners, vulnerability threat intelligence sources for enrichment and supporting archives for additional details on your organization's security posture. Here we can see the organization's vulnerability manager has created a Watch Topic related to what systems and devices are exposed to ransomware attacks that are similar in nature to the one that the security analyst caught earlier. Watch Topics show the types of vulnerabilities and assets that are most important to your organization. Security teams can set up sophisticated Watch Topics that capture specific slices of data and monitor when to act. When the organization is ready to act on a slice of vulnerabilities through the ServiceNow vulnerability response, they can initiate remediation in bulk as well. This is all a lot to take in and track. ServiceNow is driven to make your world of security operations more manageable and coordinated. With ServiceNow, organizations can leverage our analytics to improve their security program on the platform, organizations can create their own reports and dashboards. Our customers appreciate the ability to build dashboards for their teams and leadership. This CISO dashboard is a great example of what customers can rapidly build using our GUI based report engine and drag and drop dashboards. One of the advantages of that ServiceNow has is the ability to bring together data from many groups to provide holistic insights across the board. On this Overview tab, we have information from teams across risk, policy compliant, configuration management, vulnerability response, and security incident response. Dashboard tabs can be created to organize the data. In this example, the tabs provide extra details for the different groups, but they can be arranged in style to however an individual user prefers. This gives your organization the ability to watch big picture trends in their day to day work as they strive to keep your organization secure, including from threats like ransomware. If you'd like to learn more about what you saw today, please contact your account manager or visit us at www.servicenow.com. Thank You. [MUSIC PLAYING]
https://players.brightcove.net/5703385908001/zKNjJ2k2DM_default/index.html?videoId=ref:DEM1520-K22