SlideShare a Scribd company logo
CYBER SHIELDS UP:
THEY SHALL NOT PASS
Lecture @ Computer Science Department
University of Crete
2 April 2024
Andreas Sfakianakis
Cyber Threat Intelligence Professional
WHO AM I
▪ Proud CEID and CSD Alumni
▪ CTI in Financial, Energy, and Technology sectors
▪ SANS, ENISA, FIRST.org, European Commission
▪ Twitter: @asfakian
Website: www.threatintel.eu
DISCLAIMER
OUTLINE
Anatomy of Cyber
Threats
The Corporate
Cyber Shield
Building the
Cyber Defenders
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
ANATOMY OF CYBER THREATS
Image from bestofspain.es
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
TIMELINE OF IMPORTANT EVENTS IN CTI HISTORY
1989
Cuckoo’s
Egg
2009
Operation
Aurora
2010
Stuxnet
2011
LM Kill
Chain
2013
APT1
Report
2013
Pyramid
of Pain
2013
Snowden
Leaks
2014
Heart
Bleed
2015
ATT&CK
2016
The
Shadow
Brokers /
US
Elections
2017
Wanna
Cry /
Petya
APT Becomes Mainstream
Wider CTI Adoption
WHO ARE THE CYBER
THREAT ACTORS?
https://www.crowdstrike.com/adversaries/
https://cyb3rops.medium.com/the-newcomers-guide-to-cyber-threat-actor-naming-7428e18ee263
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
https://www.fbi.gov/wanted/cyber/apt-40-cyber-espionage-activities/apt-40-fbi-wanted-8-5x11-web-june-2021.pdf
https://www.justice.gov/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and
https://www.justice.gov/opa/pr/six-russian-gru-officers-charged-connection-worldwide-deployment-destructive-malware-and
https://www.fbi.gov/wanted/cyber/irgc-cyber-actors
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
THE HUMAN BEHIND THE KEYBOARD
State Sponsored
https://www.youtube.com/watch?v=KJIqgQKoHYg
HOW DO GOVERNMENTS DO
ATTRIBUTION?
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cybercriminals
WHAT IS THE TOP CYBER
THREAT NOWADAYS FOR
ORGANISATIONS?
https://github.com/cert-orangecyberdefense/ransomware_map/blob/main/OCD_WorldWatch_Ransomware-ecosystem-map.pdf
https://www.coveware.com/blog/2024/1/25/new-ransomware-reporting-requirements-kick-in-as-victims-increasingly-avoid-paying
HOW MUCH IS THE AVERAGE
RANSOM PAYMENT?
https://www.coveware.com/blog/2024/1/25/new-ransomware-reporting-requirements-kick-in-as-victims-increasingly-avoid-paying
HOW LONG DOES IT TAKE TO
GET RANSOMWARED?
https://thedfirreport.com/2024/01/29/buzzing-on-christmas-eve-trigona-ransomware-in-3-hours/
Hacktivists
https://twitter.com/Cyberknow20/status/1760288169952784736
THE CORPORATE CYBER SHIELD
WELCOME TO CYBER SECURITY
https://www.linkedin.com/pulse/cybersecurity-domain-map-ver-30-henry-jiang/
SECURITY OPERATIONS
AND INCIDENT RESPONSE
VULNERABILITY MANAGEMENT
https://www.infotech.com/research/ss/implement-risk-based-vulnerability-management
THREAT INTELLIGENCE
https://www.crowdstrike.com/cybersecurity-101/threat-intelligence/
THREAT HUNTING
https://attack.mitre.org/
RED & PURPLE TEAMING
https://twitter.com/LetsDefendIO/status/1706614342219628912
THE CORPORATE CYBER SHIELD
https://www.linkedin.com/pulse/cybersecurity-domain-map-ver-30-henry-jiang/
BUILDING THE CYBER DEFENDERS
Image from heritage-history.com
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
https://correlatedsecurity.com/cyber-security-analyst-maturity-curve/
KEEPING UP TO
DATE -
SITUATIONAL
AWARENESS
RSS Aggregator (e.g., Feedly)
Twitter
Cyber News Websites
Reddit
Podcasts (e.g., CyberWire)
Newsletter Team (e.g.,TC Dragon News Bytes)
Strategic Sources (e.g., Economist, CFR, etc.)
Weekly Summaries (e.g.This Week in 4n6)
Threat Intelligence Reports
ISACs
Trust Groups (e.g., Slack channels, mailing lists)
Threat Intelligence Vendors
CONTINUOUS
EDUCATION
MINDSET
Self-initiated
CTFs
Academic programs
Certifications
Online training material
Conferences
Books
Audiobooks
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
DON’T UNDERESTIMATE CORE SKILLS
▪Communication
▪Teamwork
▪Emotional Intelligence
▪Business acumen
▪Ethics
FINAL REMARKS
Image from elladocomicodedonquijote.wordpress.com
RECAP
▪Evolving cyber threat landscape
▪Organisations with different threat profiles, business
priorities, and “cyber shields”
▪New generation of cyber defenders and tomorrow’s
leaders
Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete
THANK YOU!
Andreas Sfakianakis
@asfakian
threatintel.eu

More Related Content

PPTX
Trust and the web veria 11 12- 09
PPTX
Cyber Security in the Manufacturing Industry: New challenges in the informati...
PDF
Future-proofing maritime ports against emerging cyber-physical threats
PPTX
Cyber Terrorism
PDF
0857290053.pdf
PPT
Cyberterrorismv1
PDF
Greater China Cyber Threat Landscape - ISC 2016
Trust and the web veria 11 12- 09
Cyber Security in the Manufacturing Industry: New challenges in the informati...
Future-proofing maritime ports against emerging cyber-physical threats
Cyber Terrorism
0857290053.pdf
Cyberterrorismv1
Greater China Cyber Threat Landscape - ISC 2016

Similar to Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete (20)

PPT
Craig wilson
PPTX
Stanford LIFE Festival March 24, 2018 Faking Life: AI, Deception, Blockchain
PDF
Cyber Security - ICCT Colleges
PPTX
Ransomware: Emergence of the Cyber-Extortion Menace
PPTX
Cybersecurity fundamental
PPTX
Hack the Hackers 2012: Client Side Hacking – Targeting the User
PPTX
Cyber terrorism
PPTX
Últimos retos en el ámbito de la Ciberseguridad: Análisis de amenazas Ciberné...
PDF
Agenda PWC Cybersecurity Day - 18 octobre 2016
PDF
Maritime Cyber Security-Κυβερνοασφάλεια και Ναυτιλία
PDF
The Evolution of Cyber Threats: Past, Present, and Future Trends
PPT
Brucon presentation
PPTX
Cyber Security: Trends and Globar War
PDF
Cybersecurity and-cyberwar-singer-en-22186
PPT
C|EH Introduction
PDF
Industrial Control Cybersecurity USA Cyber Senate conference
PDF
Cyber Security All 5 Unit Notes.pptx.pdf
PDF
Cyber Security All 5 Unit Notes.pptx.pdf
PDF
CyberTerrorism - Security in Cyberspace
PPTX
Cyber terrorism
Craig wilson
Stanford LIFE Festival March 24, 2018 Faking Life: AI, Deception, Blockchain
Cyber Security - ICCT Colleges
Ransomware: Emergence of the Cyber-Extortion Menace
Cybersecurity fundamental
Hack the Hackers 2012: Client Side Hacking – Targeting the User
Cyber terrorism
Últimos retos en el ámbito de la Ciberseguridad: Análisis de amenazas Ciberné...
Agenda PWC Cybersecurity Day - 18 octobre 2016
Maritime Cyber Security-Κυβερνοασφάλεια και Ναυτιλία
The Evolution of Cyber Threats: Past, Present, and Future Trends
Brucon presentation
Cyber Security: Trends and Globar War
Cybersecurity and-cyberwar-singer-en-22186
C|EH Introduction
Industrial Control Cybersecurity USA Cyber Senate conference
Cyber Security All 5 Unit Notes.pptx.pdf
Cyber Security All 5 Unit Notes.pptx.pdf
CyberTerrorism - Security in Cyberspace
Cyber terrorism
Ad

More from Andreas Sfakianakis (8)

PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PDF
Spin Your CTI Process Round - FIRST CTI Conference 2023
PDF
Threat Intelligence: State-of-the-art and Trends - Secure South West 2015
PDF
Stop Tilting at Windmills: 3 Key Lessons that CTI Teams Should Learn from the...
PDF
CTI Training on Intelligence Requirements - ENISA CTI Summer School 2019
PDF
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
PDF
Still thinking your Ex(cel)? Here are some TIPs - SANS CTI Summit 2021
PDF
Welcome to the world of Cyber Threat Intelligence
Decoding a Decade: 10 Years of Applied CTI Discipline
Spin Your CTI Process Round - FIRST CTI Conference 2023
Threat Intelligence: State-of-the-art and Trends - Secure South West 2015
Stop Tilting at Windmills: 3 Key Lessons that CTI Teams Should Learn from the...
CTI Training on Intelligence Requirements - ENISA CTI Summer School 2019
Setting Your CTI Process In Motion - ENISA CTI-EU 2022
Still thinking your Ex(cel)? Here are some TIPs - SANS CTI Summit 2021
Welcome to the world of Cyber Threat Intelligence
Ad

Recently uploaded (20)

PDF
LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1
PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPTX
Introuction about WHO-FIC in ICD-10.pptx
PPTX
Digital Literacy And Online Safety on internet
PDF
Cloud-Scale Log Monitoring _ Datadog.pdf
PPTX
CSharp_Syntax_Basics.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxx
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PPTX
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
PPTX
SAP Ariba Sourcing PPT for learning material
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PPTX
innovation process that make everything different.pptx
PDF
Testing WebRTC applications at scale.pdf
PPT
tcp ip networks nd ip layering assotred slides
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1
presentation_pfe-universite-molay-seltan.pptx
RPKI Status Update, presented by Makito Lay at IDNOG 10
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
Job_Card_System_Styled_lorem_ipsum_.pptx
LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Introuction about WHO-FIC in ICD-10.pptx
Digital Literacy And Online Safety on internet
Cloud-Scale Log Monitoring _ Datadog.pdf
CSharp_Syntax_Basics.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxx
WebRTC in SignalWire - troubleshooting media negotiation
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
SAP Ariba Sourcing PPT for learning material
introduction about ICD -10 & ICD-11 ppt.pptx
innovation process that make everything different.pptx
Testing WebRTC applications at scale.pdf
tcp ip networks nd ip layering assotred slides
Module 1 - Cyber Law and Ethics 101.pptx
Introuction about ICD -10 and ICD-11 PPT.pptx

Cyber Shield Up - They Shall Not Pass - Andreas Sfakianakis - Lecture at CSD - University of Crete