SlideShare a Scribd company logo
Cybersecurity Aspects of
Blockchain and
Cryptocurrency
About Me
Tony Martin-Vegue
@tdmv
• 20 years in Technology; last 10 in Cyber Risk
• FAIR practitioner for about 7 years now
• Reside in the Bay Area
Book chapter…
“Cyber Risk
Quantification of
Financial
Technology”
Paradigms
Emerging
Risks
From the “Today Show,” 1994
“What is Internet, Anyway?”
Paradigm Shifts
Cybersecurity aspects of blockchain and cryptocurrency
Users
Databases
Resources
Traditional Defense-In-
Depth
UsersDatabases
Resources New Normal
There is no cloud.
Just someone else’s
computer
…blockchain is just someone
else’s database.
Traditional Defense-In-Depth Beyond the Hard Perimeter
• Clear perimeter
• Policy enforcement points
• Company-controlled
hardware, software, data
• Access-control based trust
models
• Compliance: easy to
define
• Fuzzy or no perimeter
• Enforcement points: not
applicable
• “Ownership” is
decentralized
• Zero-trust
• Still figuring compliance
out
Emerging
Risks
The Strange Case
of Mt. Gox
(or, how forgetting
the fundamentals
can really hurt)
“The One Patch
Most Needed in
Cybersecurity”
Cybersecurity aspects of blockchain and cryptocurrency

More Related Content

PPTX
The Blockchain and the Future of Cybersecurity
PDF
Blockchain Security Issues and Challenges
PPTX
Blockchain and Cybersecurity
PPTX
What is the future of blockchain in cybersecurity
PDF
An Introduction to Blockchain Technology
PPTX
Blockchain
PPTX
Blockchain concepts
PDF
Blockchain: The New Technology and Its Applications for Libraries
The Blockchain and the Future of Cybersecurity
Blockchain Security Issues and Challenges
Blockchain and Cybersecurity
What is the future of blockchain in cybersecurity
An Introduction to Blockchain Technology
Blockchain
Blockchain concepts
Blockchain: The New Technology and Its Applications for Libraries

What's hot (20)

PDF
Blockchain Technology | Blockchain Explained | Blockchain Tutorial | Blockcha...
PPTX
Blockchain Basics
PDF
Blockchain 101 | Blockchain Tutorial | Blockchain Smart Contracts | Blockchai...
PDF
Blockchain and Cryptocurrency for Dummies
PPTX
BLOCKCHAIN
PDF
Blockchain
PDF
Blockchain
PDF
Blockchain Explained | Blockchain Simplified | Blockchain Technology | Blockc...
PPTX
Blockchain in cyber security
PDF
Security in the blockchain
PPTX
Blockchain .pptx
PPTX
Crypto currency
PDF
Blockchain Security and Privacy
PDF
Blockchain Fundamentals - Top Rated for Beginners
PDF
Blockchain, cryptography, and consensus
 
PPTX
Blockchain 101
PPT
Bitcoin au Geekftour
PPTX
Blockchain Introduction Presentation
PDF
Blockchain in Banking, Business and Beyond
PDF
Blockchain Presentation
Blockchain Technology | Blockchain Explained | Blockchain Tutorial | Blockcha...
Blockchain Basics
Blockchain 101 | Blockchain Tutorial | Blockchain Smart Contracts | Blockchai...
Blockchain and Cryptocurrency for Dummies
BLOCKCHAIN
Blockchain
Blockchain
Blockchain Explained | Blockchain Simplified | Blockchain Technology | Blockc...
Blockchain in cyber security
Security in the blockchain
Blockchain .pptx
Crypto currency
Blockchain Security and Privacy
Blockchain Fundamentals - Top Rated for Beginners
Blockchain, cryptography, and consensus
 
Blockchain 101
Bitcoin au Geekftour
Blockchain Introduction Presentation
Blockchain in Banking, Business and Beyond
Blockchain Presentation
Ad

Similar to Cybersecurity aspects of blockchain and cryptocurrency (20)

PDF
Blockchain and Cybersecurity-Liveplex Report.pdf
PPTX
Blockchain Technology + Cyber Security Presentation.pptx
PDF
slides-NPTEL-BlockchainTechnologyApplications.pdf
DOCX
Use case of block chain unit 4 AKTU
PDF
How Blockchain Ensures Data Security & Prevents Cyber Attacks
PDF
Blockchain Technology Investment Thesis
PPTX
Blockchain in 2018 : Beyond the Hype
PDF
The Microsoft vision for Blockchain
PDF
MongoDB Blockchain
PDF
Blockchain Use Cases: Think of a "Public" Pub/Sub Queue
PPTX
What is a secure enterprise architecture roadmap?
PDF
Blockchain based Security Architectures - A Review
PPTX
Blockchain Perspective - Internet of Memorable Things
PPTX
Blockchain Security Unveiled: Risks & Resilience
PDF
2024-Cybersecurity-Outlook for all engineering students
PDF
Blockchain Technology in Cybersecurity.pdf
PPTX
Blockchains: Opportunities & Risks for Law Firms [RelativityFest 2018]
PDF
Blockchain: everyone wants to sell me that - but is that really right for my ...
PDF
Role of Blockchain Technology in Cybersecurity
Blockchain and Cybersecurity-Liveplex Report.pdf
Blockchain Technology + Cyber Security Presentation.pptx
slides-NPTEL-BlockchainTechnologyApplications.pdf
Use case of block chain unit 4 AKTU
How Blockchain Ensures Data Security & Prevents Cyber Attacks
Blockchain Technology Investment Thesis
Blockchain in 2018 : Beyond the Hype
The Microsoft vision for Blockchain
MongoDB Blockchain
Blockchain Use Cases: Think of a "Public" Pub/Sub Queue
What is a secure enterprise architecture roadmap?
Blockchain based Security Architectures - A Review
Blockchain Perspective - Internet of Memorable Things
Blockchain Security Unveiled: Risks & Resilience
2024-Cybersecurity-Outlook for all engineering students
Blockchain Technology in Cybersecurity.pdf
Blockchains: Opportunities & Risks for Law Firms [RelativityFest 2018]
Blockchain: everyone wants to sell me that - but is that really right for my ...
Role of Blockchain Technology in Cybersecurity
Ad

More from Tony Martin-Vegue (10)

PDF
Incentivizing Better Risk Decisions - Lessons from Rogue Actuaries - SIRAcon ...
PPTX
How to Lie with Statistics, Information Security Edition
PPTX
Crowdsourced Probability Estimates: A Field Guide (FAIR Institute)
PDF
Crowdsourced Probability Estimates: A Field Guide
PPTX
Ransomware & Game Theory: To Pay, or Not to Pay?
PPTX
Should I Pay or Should I Go? Game Theory and Ransomware
PPTX
Can cyber extortion happen to you? Practical tools for assessing the threat
PPTX
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
PPTX
How to Lie with Statistics, Information Security Edition
PDF
How to Improve Your Risk Assessments with Attacker-Centric Threat Modeling
Incentivizing Better Risk Decisions - Lessons from Rogue Actuaries - SIRAcon ...
How to Lie with Statistics, Information Security Edition
Crowdsourced Probability Estimates: A Field Guide (FAIR Institute)
Crowdsourced Probability Estimates: A Field Guide
Ransomware & Game Theory: To Pay, or Not to Pay?
Should I Pay or Should I Go? Game Theory and Ransomware
Can cyber extortion happen to you? Practical tools for assessing the threat
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
How to Lie with Statistics, Information Security Edition
How to Improve Your Risk Assessments with Attacker-Centric Threat Modeling

Recently uploaded (20)

PPTX
Who’s winning the race to be the world’s first trillionaire.pptx
PDF
Why Ignoring Passive Income for Retirees Could Cost You Big.pdf
PPTX
EABDM Slides for Indifference curve.pptx
PPTX
Globalization-of-Religion. Contemporary World
PDF
Mathematical Economics 23lec03slides.pdf
PDF
Topic Globalisation and Lifelines of National Economy.pdf
PDF
how_to_earn_50k_monthly_investment_guide.pdf
PDF
Spending, Allocation Choices, and Aging THROUGH Retirement. Are all of these ...
PDF
Chapter 9 IFRS Ed-Ed4_2020 Intermediate Accounting
PDF
illuminati Uganda brotherhood agent in Kampala call 0756664682,0782561496
PPTX
Session 14-16. Capital Structure Theories.pptx
PPT
E commerce busin and some important issues
PPTX
The discussion on the Economic in transportation .pptx
PPTX
Antihypertensive_Drugs_Presentation_Poonam_Painkra.pptx
PPTX
Unilever_Financial_Analysis_Presentation.pptx
PPTX
social-studies-subject-for-high-school-globalization.pptx
PDF
Bladex Earnings Call Presentation 2Q2025
PDF
ssrn-3708.kefbkjbeakjfiuheioufh ioehoih134.pdf
PDF
discourse-2025-02-building-a-trillion-dollar-dream.pdf
DOCX
marketing plan Elkhabiry............docx
Who’s winning the race to be the world’s first trillionaire.pptx
Why Ignoring Passive Income for Retirees Could Cost You Big.pdf
EABDM Slides for Indifference curve.pptx
Globalization-of-Religion. Contemporary World
Mathematical Economics 23lec03slides.pdf
Topic Globalisation and Lifelines of National Economy.pdf
how_to_earn_50k_monthly_investment_guide.pdf
Spending, Allocation Choices, and Aging THROUGH Retirement. Are all of these ...
Chapter 9 IFRS Ed-Ed4_2020 Intermediate Accounting
illuminati Uganda brotherhood agent in Kampala call 0756664682,0782561496
Session 14-16. Capital Structure Theories.pptx
E commerce busin and some important issues
The discussion on the Economic in transportation .pptx
Antihypertensive_Drugs_Presentation_Poonam_Painkra.pptx
Unilever_Financial_Analysis_Presentation.pptx
social-studies-subject-for-high-school-globalization.pptx
Bladex Earnings Call Presentation 2Q2025
ssrn-3708.kefbkjbeakjfiuheioufh ioehoih134.pdf
discourse-2025-02-building-a-trillion-dollar-dream.pdf
marketing plan Elkhabiry............docx

Cybersecurity aspects of blockchain and cryptocurrency

Editor's Notes

  • #2: My portion of the panel Cybersecurity aspects of blockchain and cryptocurrency
  • #3: Quick note about me Been in technology for over 20 years, info sec RISK for the last 10. 7 years in FAIR – quant risk framework– the first couple spent unlearning bad risk habits and absorbing as much as I can Currently work for lending club – a Fin Tech up the street. We are a peer-to-peer loan company Many have called up the first and the largest Fin Tech – Paypal would have an issue with that claim
  • #4: Late Feb, book on fin tech was released. I wrote a book chapter called – Welcome to come leaf through it
  • #5: Purpose of the talk, two things: Talk about the paradigm shift in thinking about cyber security that blockchain and crypto currency represents. we’re all in the middle of right now #2, Talk about emerging risks and give a couple of tips for risk managers to get started on assessing risk
  • #6: https://www.youtube.com/watch?v=UlJku_CSyNg Requires a paradigm shift in thinking, fintech, blockchain, cryptocurrency Few points: Funny now But back then they couldn’t wrap their heads around this concept of the internet Their bewilderment captures what many of us felt at the time Good parallel to blochchain today – blockchaain and crypto currency may be so ubiquitious that we in 20 years from now we’ll be thinking back and laughing Some people knew but most did not know that they were on the cusp on a major cultural and technological change that would irreversibly alter our society
  • #7: with that in mind --want to talk about paradign shifts. force to See things in a different way - cyber security controls or information security, risk assessment You are going to have to grapple with this as risk managers - Common mis-conceptions Block chain is bitcoin or cryptocurrency Public versus private ledger But one of the biggest paradigm shifts we will have to get used to is….
  • #8: …the metaphors we use to describe how we deploy security controls around our technology. The idea here is defense in depth. There’s a single asset – the crown jewels – and attackers have to overcome successive controls. Early lookout posts, Moat, artificial hills, archer towers, 3 rings of walls
  • #9: …and this is how we design our defenses and control frameworks. Attackers on the right – nation state, hackers, organized cyber crime Company assets on the left – users, databases, systems. All protected in the middle with layers of security, control, backup control, etc. all designed around a hard, defined perimeter this paradigm shift started about 10 years ago woth cloud, byod, and continues today with blockchain
  • #10: Today New normal If this give you a headache, that’s my point I call this the “The incredible shrinking perimeter” The concept of the perimeter changed -- users, resources, straddling inside and outside the permiter defenses – the resources are outside the layerd security metaphor - instead of one layer, you had mulptile layers, mulptile controls for each group Thank about how a public blockchain deployment would work, for example – a Payments application like Paypal. The databses are distributed, outside of the company’s perimeter – relying on new/different controls than we would see on a traditional demployment More targets, more surface
  • #11: Old adage
  • #15: Forgeting the fundamentals   Mt. Gox Bitcoin heist in 2014 first and largest Bitcoin exchanges at the time 850,000 Bitcoin 450 million USD. today, the value of 850,000 Bitcoin is $5.8 trillion USD.     How did this happen?   ex-CEO of Mt. Gox blamed hackers for the loss, others blamed the CEO, Mark Karpeles; the CEO even did time in a Japanese jail for embezzlement   There were other issues according to a 2014 story in Wired Magazine, ex-employees described a company in which there was no code control, no test code environment and only one person that could deploy code to the production site: the CEO himself, Mark Karpeles took weeks to deploy security fixes   Fintech’s primary competitive advantage is that they have less friction than traditional financial services able to innovate and push products to market very quickly.   The downside the Mt. Gox case proves is when moving quickly, one cannot forget the fundamentals. Fundamentals, such as code change/version control, segregation of duties and prioritizing security patches should not be set aside in favour of moving quickly.   Risk managers need to be aware of and apply these fundaments to any risk analysis.  
  • #16: Quote from Doug Hubbard Reference to As mentioned many times previously, technology is rapidly evolving and so is the threat landscape. Practices, such as an ambiguous network perimeter and distributed public databases were once unthinkable security practices. They are now considered sound and, in many cases, superior methods to protect the confidentiality, integrity and availability of assets. Risk managers must adapt to these new paradigms and use better tools and techniques of assessing and reporting risk. If we fail to do so, our companies will not be able to make informed strategic decisions. One of these methods is risk quantification. Why we’re hearing more and more about fair – risk quant – OCC has started referencing it as a framework, many others