Plenary Sessions | Room - Orchid (Ballroom A) @ Sheraton Fiji Resort
Training Track 1 | Room - Frangipani (Ballroom B) @ Sheraton Fiji Resort
Training Track 2 | Room - Gardenia (Ballroom C) @ Sheraton Fiji Resort
Training Track 1 | Room - Frangipani (Ballroom B) @ Sheraton Fiji Resort
Training Track 2 | Room - Gardenia (Ballroom C) @ Sheraton Fiji Resort
Plenary Sessions Room - Orchid (Ballroom A) @ Sheraton Fiji Resort | |
---|---|
09:00 – 09:30 | CH Introduction to Incident Response and Welcome Remarks Dr. Serge Droz (FIRST / FDFA, CH) |
09:30 – 10:30 | US Remediation Ballet: Choreographing Your Team To Victory Simon Freiberg & Jason Solomon (Google, US) |
10:30 – 11:00 | ES Integrating Red Teaming and CSIRT Jordi Aguilà (e-la Caixa CSIRT, ES) |
11:00 – 11:15 | Coffee Break |
11:15 – 12:00 | NZ A Field Guide to Communicating a Security Incident Izzi Lithgow (CERT NZ, NZ) |
12:00 – 12:30 | AU DFIR Acquisition Presentation Sam Bonanno (Australian Cyber Security Centre, AU) |
12:30 – 13:45 | Lunch |
13:45 – 14:45 | US CH The Policy Implications of Incident Response Maarten Van Horenbeeck (Zendesk, US); Dr. Serge Droz (FIRST / FDFA, CH) |
14:45 – 15:15 | TBD |
15:15 – 15:30 | Coffee Break |
15:30 – 16:00 | US Measuring CSIRT Maturity using SIM3 Maarten Van Horenbeeck (Zendesk, US) |
16:00 – 17:00 | NZ Responding to Incidents in Industrial Environments Hinne Hettema (NZ) |
17:00 – 17:30 | CH Dr. Serge Droz (FIRST / FDFA, CH) |
19:00 – 21:00 | Networking Reception - Sandy Court @ Westin Denarau Fiji Resort |
Training Track 1 Room - Frangipani (Ballroom B) @ Sheraton Fiji Resort | Training Track 2 Room - Gardenia (Ballroom C) @ Sheraton Fiji Resort | |
---|---|---|
09:00 – 10:45 | AU Breach Workshop 1: Cyber Extortion Adli Abdul Wahid (APNIC, AU) | CH Breach Workshop 2: Critical Infrastructure Attack Dr. Serge Droz (FIRST / FDFA, CH) |
10:45 – 11:00 | Morning Coffee Break | |
11:00 – 12:30 | AU Breach Workshop 1: Cyber Extortion Adli Abdul Wahid (APNIC, AU) | CH Breach Workshop 2: Critical Infrastructure Attack Dr. Serge Droz (FIRST / FDFA, CH) |
12:30 – 13:45 | Lunch | |
13:45 – 15:45 | NZ Malware Analysis When You're In A Hurry Hinne Hettema (NZ) | CH AU CSIRT Advanced Training - Part 1 Serge Droz (OS-CERT, CH), Adli Wahid (APNIC, AU) |
15:45 – 16:00 | Afternoon Coffee Break | |
16:00 – 18:00 | NZ Malware Analysis When You're In A Hurry Hinne Hettema (NZ) | CH AU CSIRT Advanced Training - Part 1 Serge Droz (OS-CERT, CH), Adli Wahid (APNIC, AU) |
Training Track 1 Room - Frangipani (Ballroom B) @ Sheraton Fiji Resort | Training Track 2 Room - Gardenia (Ballroom C) @ Sheraton Fiji Resort | |
---|---|---|
09:00 – 10:45 | US Maarten Van Horenbeeck (Zendesk, US) | CH AU CSIRT Advanced Training - Part 2 Dr. Serge Droz (FIRST / FDFA, CH); Adli Abdul Wahid (APNIC, AU) |
10:45 – 11:00 | Morning Coffee Break | |
11:00 – 12:30 | US Maarten Van Horenbeeck (Zendesk, US) | CH AU CSIRT Advanced Training - Part 2 Dr. Serge Droz (FIRST / FDFA, CH); Adli Abdul Wahid (APNIC, AU) |
12:30 – 13:45 | Lunch | |
13:45 – 15:45 | US Maarten Van Horenbeeck (Zendesk, US) | CH AU CSIRT Advanced Training - Part 2 Dr. Serge Droz (FIRST / FDFA, CH); Adli Abdul Wahid (APNIC, AU) |
15:45 – 16:00 | Afternoon Coffee Break | |
16:00 – 18:00 | US Maarten Van Horenbeeck (Zendesk, US) | CH AU CSIRT Advanced Training - Part 2 Dr. Serge Droz (FIRST / FDFA, CH); Adli Abdul Wahid (APNIC, AU) |
Izzi Lithgow (CERT NZ, NZ) (NZ)
When preparing for incidents, we’re always hearing “it’s not if, it’s when” so security teams create process and technology solutions that will help rebuild the technical walls when the castle gets breached. But what we don’t often hear about is how we’re going to tell people what’s going on, and how the flow of information to our organisation’s staff, customers and stakeholders will be managed. In fact, we’re all just hoping that it’s not our job to have to tell the CEO or the 6 o’clock news. In this talk Izzi Lithgow from CERT NZ will talk about life as a security communications specialist, and will share insights into the important role of communications when navigating a security incident.
November 5, 2019 11:15-12:00
Adli Abdul WahidAdli Abdul Wahid (APNIC, AU)
Adli Wahid is a Senior Internet Security Specialist at APNIC. He has been involved in the CSIRT community for more than 10 years. His previous role includes leading Malaysia CERT (MyCERT) and working for a CERT in the financial sector. Adli is also serving board member of FIRST.Org
Your organization is held at ransom by a group of seemingly politically motivated activists. You determine a lot of the problem is intractable without leveraging both the relationship building capabilities of your CSIRT, and technical skill.
In this workshop you'll walk through a live incident, and discuss the actions you would take together with Adli Wahid, an incident response specialist from FIRST and APNIC. No incident response experience required, but come with an open mind!
November 6, 2019 09:00-10:45, November 6, 2019 11:00-12:30
Dr. Serge DrozDr. Serge Droz (FIRST / FDFA, CH)
Serge Droz is the Vice President OS-CERT at Open Systems, one of the leading managed security service providers in Europe. He studied physics at ETH Zurich and the University of Alberta, Canada and holds a PhD in theoretical astrophysics. Before joining Open Systems, he worked in academia in Switzerland and Canada, later as a Chief Security Officer of Paul Scherrer Institute, as well as in different security roles at SWITCH for more than 15 years. Serge is a member of the board of directors of FIRST. He also served for 2 years in the ENISA (European Union Agency for Network and Information Security) permanent stakeholder group. Serge is an active speaker and a regular trainer for CSIRT (Computer Security Incident Response Team) courses around the world.
As many countries, yours probably depends to a great degree on having a reliable water supply. What would happen if this daily infrastructure no longer runs reliably? And what if there's some of our technology behind it?
In this workshop you'll walk through a live incident, and discuss the actions you would take together with Serge Droz, an incident response specialist from FIRST and Open Systems. No incident response experience required, but come with an open mind!
November 6, 2019 09:00-10:45, November 6, 2019 11:00-12:30
Dr. Serge DrozDr. Serge Droz (FIRST / FDFA, CH)
Serge Droz is a senior IT-Security expert and seasoned incident responder. After more than twenty years work in different CSIRTs he now works as a senior adviser for the Swiss FDFA. He studied physics at ETH Zurich and the University of Alberta, Canada and holds a PhD in theoretical astrophysics. He has worked in private industry and academia in Switzerland and Canada in different security roles as well as at the national CERT in Switzerland.
Serge is a member of the board of directors of FIRST (Forum for Incident Response and Security Teams), the premier organisation of recognised global leaders in incident response. In this role he actively participates in discussion relating to cyber security at various policy bodies, in particular related to norm building.
Serge is an active speaker and a regular trainer for CSIRT (Computer Security Incident Response Team) courses around the world.
Today incident response often involves analyzing large amounts of data (think log files, output of forensic analysis). Some of the analysis will be repetitive, some will be specific to the incident.
Modern data analysis tools allow conducting this work efficiently and in a documented manner. Jupyter Notebooks using the pandas framework are popular among data scientists but not so much in the security community. We try to change the latter.
In this talk we present a basic intro into Jupyter and pandas, illustrating this with real live examples.
Links:
November 5, 2019 17:00-17:30
Dr. Serge DrozAdli Abdul WahidDr. Serge Droz (FIRST / FDFA, CH), Adli Abdul Wahid (APNIC, AU)
Adli Wahid is a Senior Internet Security Specialist at APNIC. He has been involved in the CSIRT community for more than 10 years. His previous role includes leading Malaysia CERT (MyCERT) and working for a CERT in the financial sector. Adli is also serving board member of FIRST.Org
Serge Droz is the Vice President OS-CERT at Open Systems, one of the leading managed security service providers in Europe. He studied physics at ETH Zurich and the University of Alberta, Canada and holds a PhD in theoretical astrophysics. Before joining Open Systems, he worked in academia in Switzerland and Canada, later as a Chief Security Officer of Paul Scherrer Institute, as well as in different security roles at SWITCH for more than 15 years. Serge is a member of the board of directors of FIRST. He also served for 2 years in the ENISA (European Union Agency for Network and Information Security) permanent stakeholder group. Serge is an active speaker and a regular trainer for CSIRT (Computer Security Incident Response Team) courses around the world.
Already have a CSIRT? Learn how to bring to the next level, including techniques on how to build maturity, how to deal with more sophisticated incidents, manage exercises, and more.
November 7, 2019 13:45-15:45, November 7, 2019 16:00-18:00, November 7, 2019 09:00-10:45, November 7, 2019 11:00-12:30
Maarten Van HorenbeeckMaarten Van Horenbeeck (Zendesk, US)
Maarten Van Horenbeeck is a Board member, and former Chairman, of the Forum of Incident Response and Security Teams (FIRST. Maarten is also Chief Information Security Officer with Zendesk. Prior to this role, he was Vice President, Security Engineering at edge cloud network Fastly and managed the Threat Intelligence team at Amazon. Maarten has a master's degree in Information Security from Edith Cowan University, and a Masters degree in International Relations from the Freie Universitat Berlin. He is also Lead Expert to the Internet Governance Forum’s Best Practices Forum on Cybersecurity.
Learn how to build a Computer Security Incident Response Team, operate it, integrate external information sources, and most importantly, enhance your learning by responding to security incidents.
November 7, 2019 13:45-15:45, November 7, 2019 16:00-18:00, November 7, 2019 09:00-10:45, November 7, 2019 11:00-12:30
Dr. Serge DrozDr. Serge Droz (FIRST / FDFA, CH)
Serge Droz is the Vice President OS-CERT at Open Systems, one of the leading managed security service providers in Europe. He studied physics at ETH Zurich and the University of Alberta, Canada and holds a PhD in theoretical astrophysics. Before joining Open Systems, he worked in academia in Switzerland and Canada, later as a Chief Security Officer of Paul Scherrer Institute, as well as in different security roles at SWITCH for more than 15 years. Serge is a member of the board of directors of FIRST. He also served for 2 years in the ENISA (European Union Agency for Network and Information Security) permanent stakeholder group. Serge is an active speaker and a regular trainer for CSIRT (Computer Security Incident Response Team) courses around the world.
November 5, 2019 09:00-09:30
MD5: 36e34c4c175ee5fa7642cbf1d245ce77
Format: application/pdf
Last Update: June 7th, 2024
Size: 1.56 Mb
Hinne HettemaHinne Hettema (NZ)
Hinne Hettema is the tactical security operations leader at Ports of Auckland.
His strengths are in SOC enablement, intelligence and incident response, as well as intelligence driven security operations and security architecture.
In a previous role, he led the security operations at the University of Auckland and has also worked as security architect. He has experience working in security operations in both ICT and ICS environments, setting and driving strategy and incident response. He studied Theoretical Chemistry (PhD 1993) and Philosophy (PhD 2012). As a theoretical chemist, he played with the supercomputers of the time. His first computer was hacked in 1991, after which he developed an enduring interest in cyber security. He is a blogger for APNIC, and maintains a security blog on his LinkedIn page.
In this half day course you will learn rapid triage of malicious content and next steps. These steps can be taken by a small team when targeted by specific malware. After completion of this process you can hand off to your AV vendor with a summary of your findings and links to any reports that you have generated, as well as put in some protection immediately.
The aim is to complete this process in about 30 minutes, have a definite answer whether something is malware or not, and give your AV vendor enough to go on as a starting point, share your findings with colleagues and clearly inform your business about the threat of this specific malware.
After this course, you will be able to: • Understand and strategise the use of malware analysis tools • Understand aspects of the cybercrime ecosystem and the role played by malware • Be able to model attacks and think strategically about defences • Be able to analyse malware to a high level quickly and securely • Be able to share your conclusions with others The course is targeted to beginners in malware analysis and those who need to make sense of the many tools available in this area.
November 6, 2019 13:45-15:45, November 6, 2019 16:00-18:00
Maarten Van HorenbeeckMaarten Van Horenbeeck (Zendesk, US)
Maarten Van Horenbeeck is a Board member, and former Chairman, of the Forum of Incident Response and Security Teams (FIRST. Maarten is also Chief Information Security Officer with Zendesk. Prior to this role, he was Vice President, Security Engineering at edge cloud network Fastly and managed the Threat Intelligence team at Amazon. Maarten has a master's degree in Information Security from Edith Cowan University, and a Masters degree in International Relations from the Freie Universitat Berlin. He is also Lead Expert to the Internet Governance Forum’s Best Practices Forum on Cybersecurity.
November 5, 2019 15:30-16:00
Simon Freiberg & Jason Solomon (Google, US) (US)
The security industry focuses a great deal on defense against advanced threats, but security incidents are inevitable. Once an attacker is on your network, it’s imperative to be able to detect them and quickly kick them back out! This talk explores how Google performs incident management and remediation at scale, adapting the techniques of disaster management professionals and modern open source tools to achieve lightning-fast, efficient response cycles and push the envelope in the field of Incident Response.
November 5, 2019 09:30-10:30
Large-Scale-Incident-Response.pdf
MD5: 5bc1aeca109bfd9154b0e0f5da3cef9d
Format: application/pdf
Last Update: June 7th, 2024
Size: 796.28 Kb
Hinne HettemaHinne Hettema (NZ)
Hinne Hettema is the tactical security operations leader at Ports of Auckland.
His strengths are in SOC enablement, intelligence and incident response, as well as intelligence driven security operations and security architecture.
In a previous role, he led the security operations at the University of Auckland and has also worked as security architect. He has experience working in security operations in both ICT and ICS environments, setting and driving strategy and incident response. He studied Theoretical Chemistry (PhD 1993) and Philosophy (PhD 2012). As a theoretical chemist, he played with the supercomputers of the time. His first computer was hacked in 1991, after which he developed an enduring interest in cyber security. He is a blogger for APNIC, and maintains a security blog on his LinkedIn page.
November 5, 2019 16:00-17:00
OT_Incident_Response-Hinnie.pdf
MD5: 8c57ccc8eb40e672ff87fe7f6435e2e6
Format: application/pdf
Last Update: June 7th, 2024
Size: 482.86 Kb
Maarten Van HorenbeeckDr. Serge DrozMaarten Van Horenbeeck (Zendesk, US), Dr. Serge Droz (FIRST / FDFA, CH)
Maarten Van Horenbeeck is a Board member, and former Chairman, of the Forum of Incident Response and Security Teams (FIRST. Maarten is also Chief Information Security Officer with Zendesk. Prior to this role, he was Vice President, Security Engineering at edge cloud network Fastly and managed the Threat Intelligence team at Amazon. Maarten has a master's degree in Information Security from Edith Cowan University, and a Masters degree in International Relations from the Freie Universitat Berlin. He is also Lead Expert to the Internet Governance Forum’s Best Practices Forum on Cybersecurity.
Serge Droz is the Vice President OS-CERT at Open Systems, one of the leading managed security service providers in Europe. He studied physics at ETH Zurich and the University of Alberta, Canada and holds a PhD in theoretical astrophysics. Before joining Open Systems, he worked in academia in Switzerland and Canada, later as a Chief Security Officer of Paul Scherrer Institute, as well as in different security roles at SWITCH for more than 15 years. Serge is a member of the board of directors of FIRST. He also served for 2 years in the ENISA (European Union Agency for Network and Information Security) permanent stakeholder group. Serge is an active speaker and a regular trainer for CSIRT (Computer Security Incident Response Team) courses around the world.
November 5, 2019 13:45-14:45
The-Policy-Implications-of-Incident-Response.pdf
MD5: 94caced9f14354dd9e2b3c680fb28108
Format: application/pdf
Last Update: June 7th, 2024
Size: 2.23 Mb