logo

NJP

Addressing SEC Cybersecurity Mandates with ServiceNow

Import · Oct 20, 2023 · video

all right yeah let's let's record this one great uh good afternoon everyone uh thank you all for your time and attending today um we're really you know excited to talk about some of the content that we have prepared uh for you all and really just look forward to sharing more about how service now you know is able to help publicly trade organizations meet the incident disclosure mandates recently set forth by the SE c um but you know before we dive into the nuts and bolts of the presentation today we just wanted to quickly take some time to introduce ourselves so my name is Alex cotton and I'm a senior technology workflow Solutions manager here at service now I've been with service now for 18 months give or take uh we've already you know worked with a few dozen different organizations that you know are not only looking to service now to help with things like you know the service operations or Enterprise visibility strategies but um as of late more often than not we've been having a lot of conversations about strengthening posture around security operations um which is what brings us all here together today along with me is David Adler and Shane oasby I'll let them introduce themselves further now um and with that said before I pass the torch I just wanted to mention you know as we're going through today feel free to you know take advantage of the Q&A feature in the in the webinar here and we'll you know address questions there all right thanks Alex hey everyone David Adler thank you so much for joining today I'm a senior SEC op solution consultant here at service now been here just over a year now prior to that I was in the federal government so I am very familiar with the ambiguity and change in process that can come with know new mandates set forth by regulatory agents gencies so I'm really excited to talk through how the platform can help um but I'll pass it over to sha everyone I'm Shaina rasby I'm Al also a solution consultant specializing in SE Ops I've been with service now about year and a halfish now so excited to dive into things with everyone today great thank you yeah so so really you know what brings us here today is this idea you know this is recent news is you know on behalf of investors the SEC has raised the stakes for publicly traded uh us companies and even you know foreign private issue issuers to best better disclose manage and represent uh cyber security risks and incidents um in summary you know the new SEC mandate it does affect you know public us companies and foreign private issuers um really requiring them to dis close material incidents within 4 days uh this disclosure requires a description of any processes that were in place for assessing identifying and managing material risks from cyber security threats um and you know ultimately poor disclosures risk fines you know an impact on stock price an impact on brand and ultimately you know all the financial consequences that come you know from those items so how can service support this how can service now help first from an Enterprise visibility standpoint we can discover Hardware software employees third parties and all relevant data that stitches those things together pull it into a unified system of record and enable organizations to continuously monitor for and respond to security risks in a single system of action um and really this allows organizations to then you know Harden you know those attack Services across software infrastructure clouds applications and you know OT layers even so you know this you know unifies an organization wide incident response and governance practice you know for disclosure workflows really just including you know audit ready compliance reports to the SEC so with that said you know the expected outcomes tend to all boil down to speed and transparency u meaning you know organizations can expect gain efficiencies from streamlined Dynamic processes for risk management incident investigation and compliance disclosure U really you know just looking to support and meet these mandates so you know customers they can ultimately expect faster time to identify respond contain and remediate potentially material incidents and then report on them as needed to protect investors and improve board and customer confidence so you know why were these regulations put into place right it's really the idea around holding companies accountable in order to protect investors and give them an understanding of the security posture of the organizations they're investing in excuse me the 202 22 report that was released by state senator Gary Peters from Michigan showed that upwards of 75% of all ransomware attacks went unreported while the SEC and other Regulators found that of those attacks that were were reported they were reported on an average 80 days after the fact so it was also found that less than 43% of all breaches were reported to the SEC in 2021 and there even was a specific incident that a particular software firm uh they made a misleading disclosure about a ransomware incident so they ended up needing to uh pay out $3 million in the settlements of the secc so you know the repercussions of this can certainly be detrimental um and with that said today we'll be exploring a scenario where an organization uses service now to identify understand and address a ransomware attack that exploits the log for Shell vulnerabilities and you know then ultimately be able to report on this and again you know keep in mind all of this is what you'll see in the demo today is done within service now so with that said I'll turn it over to Shaina yeah so what we really are going to focus on to is just talking over and reviewing kind of the highlights of what is included in this SEC mandate so starting off that really includes the requirement to disclose any cyber security incident that they deem to be material so that could be due to a number of different contexts whether it's a lot of different assets or valuable Assets in the organization being impacted a lot of different people within the organization being impacted But ultimately regardless if this incident is deemed to be material it will have to be disclosed and reported upon within four days on top of of that it's also important for companies with these SEC mandates to be able to describe their risk management process for managing these material effects of the risks from these cybercity threats and any previous cyber security incidents and this has to be disclosed on an annual basis and any information around that will have to be included in those reports on top of that they'll also have to describe the board of directors oversight of risks from these cyber security threats so just really hitting all the points of awareness invisibility and transparency with this reporting so just some top important things that boards will be asking for from executive leadership first off knowing how incidents are tracked and just making sure that the process is also transparent and reported upon so making sure that there's a clear process to determine what makes the material incident or an incident deemed material and when an incident is deemed as material figuring out and Reporting on what the process is and how is ensured that the appropriate documents and necessary time frames are filed also being able to provide an audit in order to have the process laid out and remain compliant with the rules also just making sure that you're prepared for tax and have the right risk and compliance manage management practices in place so again just really making sure to have that visibility and transparency with the entire endtoend security process and then on top of that keeping up to dat when it comes to security and risk which is constantly changing and then of course having the process in place to ensure that the compliance team is engaged when a breach does occur so making sure that the right people have access and visibility so Alex and Shaina did a really great job describing kind of the idea behind the SEC mandate as well as you know what that's going to mean for publicly traded organizations now I want to talk a little bit more about how we can help within the platform and specifically within our security operations offerings now one thing we're one module we're really going to highlight today is major security Incident Management now this already existed within service now security operations but we believe it is purpose-built for this kind of scenario when something really catastrophic happens and we need to bring the organization together to eradicate it as well as report on it to whoever you know we're responsible to including the SEC So within major security Incident Management Shaina is going to show you how at the analyst level we can identify an incident do the investigation to understand the scope of the incident and really make that determination that we are dealing with something material now that's only the beginning of the the puzzle right now that we know that this incident is material we need to really rally the organization um to respond to it and report on it and that's where msim comes in so the analyst can elevate a material incident then from there our incident manager can continue to track the remediation progress but also task out the broader organization so how do we get tasked to it to limit the damage as well as take preventative actions to make sure that you know this doesn't happen again but also understanding that you know this is really a risk and compliance issue we need to bring in our legal PR and risk teams into the war room so to speak so they can track what's going on as well as um under understand what they need to do within the process and we'll see how we can task out and collaborate all within one workspace but you know this whole thing is really about reporting right that's what this SEC mandate is all about that four days to report it's really the biggest piece so we'll we'll also see how once you know all those actions have been taken we can automate the reporting of material incidents directly within this workspace space we can do those for different audiences so of course we can put together a report for our regulatory requirements but since this mandate requires boards to have so much more oversight than they originally were required to we can also build out reporting for our Executives I'm really excited to show you all you know what msim can do for this regulation um but without further Ado I think we'll jump into the fun part I'll hand it back to Shaina for the demo yeah thanks David and really where I want to start our demo off is just by looking at the security incident workspace before a security incident has been escalated to that major security Incident Management workspace that we tou talked about really where it'll start is within the regular security incident response workspace where agents analysts will go in and be able to see a list view in some data visualizations around current security incidents that are active or in remediation within the organization so here we're looking at the home overview and from here we're able to see a couple of data visualizations right at the top and that's going to be a list from starting on the left incidents categorized by priori so we can see how many critical incidents we currently have how many high uh moderate incidents By Priority so again just being able to visualize same goes for incidents by state we can see incidents that are currently in analysis Containment all of those State just being able to look at these in a more broken down visualized view but if we really want to dive into a specific incident and make sure that we're getting all the information around that we can go down to our list of incidents here and in this case it's going to be categorized By Priority so the most critical of high importance incidents are going to be coming up at the top and right at the very top our first one listed here we do see the log Force shell exploit that has come through and has been listed as a priority One critical incident so by clicking into that we're able to get a lot for more information within this pane of glass our overview is going to give us an idea in a quick glance into things like the business impact and also using third party tools threat intelligence as well so just really getting a lot of information in context around the specific incident to allow us to go through the process of figuring out if this is going to be deemed as a material incident and therefore is going to have to be escalated and reported upon so another way we can get information around that is from the related records tab in the related records tab we're going to get a list of things like business impact depending on a number of different criteria so that includes configuration items affected users and even affected services and from here just from looking at a glance on the left without even diving too deep into anything we can immediately tell that a number of things have been impacted by this log for Shell exploit for example we have 25 configuration items that are impacted we have 16 affected users and there is one affected service from this exploit so right off the bat without even diving in we're going to get an idea that this was a pretty major exploit and there have been a number of different things within the organization that have been impacted and as you can see we also have a number of different tabs up here that are going to give us even more context so if we wanted to go for example into the investigation tab this is really going to give us a more technical view into the exploit and the things that are involved in it so right now we're looking at affected users and as that implies we're able to see specifically who may be affected by this exploit whether it's somebody associated with a computer associated with an email that contain something related to the exploit no matter what it's going to be listed here so we get the context and then within Associated observables it's going to give us once again that technical view of specific observables that have been involved and related to this exploit and at the top it's going to list any that have been deemed as malicious and that again is going to give us more context that this is very likely a material incident we have malicious observables and we could even click into this to get even more context if we wanted very specific details around that but we can see based on the finding the scan that was run this was de deemed as malicious and there's another one too so we can really just see there have been a number of problematic occurrences due to this exploit now jumping back to that details tab this is also just going to be where we can get more context and more information and also make any changes to this specific incident that we wanted to but since we've looked into some of these details and some of this information we're really going to get a good idea at this point that this is going to be something we're likely going to have to escalate into a major security incident and of course since this materiality is a little bit vague right now there could be a number of different things that are going to be used in the criteria to deem an incident as material so it'll really come down to what is decided upon to be a part of that what is determined so for example maybe we will use the business impact we might also use something like threat intelligence maybe SLA is being impacted will also cause us to determine this which is something we also have access to from our home area here with the SLA count so really it's going to come down to a number of different criteria But ultimately since we can determine based on the observables that are connected to this the CIS that are impacted the number of people we can deem this as a material incident which means we are going to have to escalate it and there a number of ways we can do that but one way is we have the security tagging feature here where we can add different security tags and we already see the major security instant tag is on this log for Shell exploit but then from the menu here is also where we would be able to escalate this to a major security incident but now that we've gone determined that it is a major security incident escalated it David will show us what it's like to actually deal with that security incident within the major security incident workspace thank you Shana Shaina makes a really great point I just want to kind of highlight that you know while there's a lot of ambiguity around what that term material means um whatever the SEC eventually lands on or your organization lands on the information you'll need to make that determination is really all going to be within the platform you have that thread information that machine information as well as that context from your cmdb to understand you know what it means for your business but as Shaina said um our analyst has ident identified that this incident is material and as a result they've elevated it to a major security incident so since I'm taking the role of our say head of security or incident manager or whoever in your organization is responsible for overseeing widescale incidents I have access to the major security Incident Management workspace where I can see those elevated incidents and you can see here right at the top we have that same elevated log four shell ransomware incident now let's take a look at what we see from our manager perspective so here we are within the overview tab for this major security Incident Management workspace and we'll give this second second to load our visualizations here so since our analyst has elevated this incident I can quickly see that high level information I need to understand the scope of what's happening with this incident so just like my analyst could I could see the number of effected assets users locations I can see the duration of this incident so we're at 6 days here this is going to be helpful information especially when we now have this new 4day timeline to report on incidents coming down to the middle here we can also get a sense of who is part of this response effort even outside of our traditional security incident response teams we also have people brought in from legal public relations and our it or vulnerability te teams to help respond broadly as an organization and these have all been pulled in automatically once this incident has been deemed material we can also track um how they're doing in their tasks over time coming over to the details tab if I as the incident manager want to understand you know what my team has done or get a little more information on exactly what's happening with this incident I can come here to the details tab I have the MSI record which shows me you know when it was first detected when our estimated resolution dat is category and risk information I can also see who on the team has been assigned and right from here I can add or remove people very quickly on the right here the same similar activity stream that our analyst had where we can see all the actions that are taken either by the platform itself or by the different team members for this incident response process now if I'm a a very technical incident manager and I want to see exactly what happened the initial detection I can do that here we'll just give that a second to load and I can see that initial sir record that Shaina was seeing in the analyst workspace so I don't need to go down the hall or send a teams message to ask my analysts exactly what they initially saw I can see that initial record I can also see the activity stream to understand what actions my organization has already taken now we've got gotten an understanding of what kicked off this incident what has been done so far but let's really dive into how we can task out and collaborate the response to this incid so here on the tasking tab we can see a very familiar sort of conon style board where we can generate tasks for our broader response team now any of these are generated automatically once that incident has been elevated but I can create new ones here if need be you'll notice here a lot of these are you know traditional security response tasks rescanning endpoints searching for fishing emails but I can also task out to the broader organization so I can tell my it team to search for any unpatched log for Shell vulnerabilities through service now vulnerability response so we can make sure that this incident stays contained and we're not susceptible to it again in the future I can also task out TKS to my PR or legal teams to draft statements or verify our disclosure requirements so we know we have to disclose the SEC in four days but potentially there are other disclosure requirements we have to report on say you know hippo or PCI if that type of data was affected by this incident now a huge part of the SEC mandate is that we need to show how we have an auditable process right so not just are we responding to these incidents but we also need a place to save any artifacts or work documents that that went in to responding to this incident so we can prove them to Auditors or regulatory bodies in the future that's really what we're doing here on the collaboration tab so through Integrations with SharePoint and Microsoft teams we can quickly create file repositories that are secure and segmented to just the individuals working on this incident where we can save any artifacts from our investigation and with an integration with Microsoft teams we can even create teams channels directly from here which are private and again just for the people involved in this incident on the side we can even see that teams activity as it happens so if I'm head down in msim and I don't have time to jump over and read through all my teams messages I can see all of those right here now the final thing I want to call out actually one more thing shanana called out the kind of incident impact view within the analyst workspace I can get that same thing here as well so again me as the incident manager I don't need to tap my analyst on the shoulder and ask them to give me a report of affected assets I can view all that information here and it's probably not just me that needs this information right when we have to report this to the SEC they're going to want to know the breath of what happened and I can quickly because I have all of my asset information in my cmdb coupled with my security information understand exactly what was affected and I can deliver that information to whoever wants to see it finally last piece and what this is really all about here is that reporting requirement so it's really great that we've been able to identify the incident contain it gather all the necessary folks in our organization across the organization to resident But ultimately we're going to need to report on it so we can do that right here from msim as you'll see here we have two reports that we've already started to draft and we can quickly create new ones here so what you're seeing here are templates that we've already created based on audience we have a technical and executive status report you can think of the executive status report as something we can deliver to our board as part of the oversight requirements they now have with this mandate but we could even build out a report that contains all the information that's necess necessary for this SEC requirement and if we take a look at one here while that generates we can see here on the left we can quickly edit all the parts of the report that we need so we can pick exactly which graphs and visualizations we want to include what sort of textual context we want to provide as well as if we want to share activity information and further lists about information from this incident and that automatically generates a report which contains all the necessary information or information we want to provide so here's timestamps and that same asset information that shows the broader impact of this incident we can even see observable information so so if we want to you know help out the broader community and share out threat information we can do that right here as well so we've seen how the analyst can initially identify an incident make that determination of materiality elevate it to a major or material security incident and then within msim we saw how we can collaborate rally all the troops and ultimately report on this incident all within the service now platform so with that I will hand it back to Alex to wrap up today great yeah thank you David thank you Shaina great demonstration of the the solution here today great content great to see some familiar names and faces here in the audience um definitely look forward to connecting with you all um you know and kind of unpacking some of the things that we uh discussed today if appropriate so don't be shy don't hesitate to reach out more than happy to uh talk about this more and in one-off conversations but I hope everyone you know enjoyed the content and have a great rest of your night thank you

View original source

https://www.youtube.com/watch?v=JtzgyhGkw6s