Cybersecurity: The Real Risks for GLAMIR Organisations
Cybersecurity can be intimidating to keep up with, yet risky to ignore. So what should organisations in the culture sector be aware of?
Thanks to our partners at REANNZ, we invited cybersecurity experts James Fitzsimons and Dean Pemberton from Bastion Security Group / Cassini and Aaron Murrihy from REANNZ to give us the lowdown on the current state of cybersecurity.
Jump to:
00:00 Introductions and housekeeping
06:17 Explanation of a core security concept: The CIA Triad (Confidentiality, Integrity, Availability)
06:37 What is Confidentiality?
08:18 What is Integrity? Including an explanation of a Hacktivist
10:37 What is Availability?
11:33 The New Zealand Threat Landscape: What types of malware do we see in New Zealand?
13:25 Recent trends in cyberthreats in New Zealand
15:35 Types of threat actors are targeting NZ organisations, threat actors naming conventions explained
17:02 Threat actors targeting the GLAM sector
20:01 Ransomware-as-a-Service (RaaS) explained
21:18 Case study: The British Library Cyber Attack
25:39 What should you start doing to protect your organisation from Cyber attacks?
28:37 Proactive defensive measures to put in place
32:30 Network protection capability from Cassini and REANNZ
35:33 How to secure your global routing information
35:40 What is Route Hijacking and how does it work? What are the consequences?
37:39 What is Spoofed Source Addressing and how does it work? What are the consequences?
39:23 What can we do to secure our routing information? Introduction to MANRS.
41:04 Using RPKI to add crypto to global routing
42:45 What are the targets for DDOS / Denial of Service Attacks?
45:40 What can you do to protect your organisation form DDOS attacks?
48:00 Thank you messages
49:28 Answer to audience question: How do you propose managing sync of offline backups and ensuring when you do sync them, you're not copying over tools to compromise that backup?
54:08 Recommended resources for cybersecurity information
Resource links:
CERT NZ: https://www.cert.govt.nz/business/
The National Cyber Security Centre: https://www.ncsc.govt.nz/ British Library case study (pdf): https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf
Learn more:
https://www.reannz.co.nz/
https://bastionsecurity.co.nz/
https://www.cassini.nz/home/
https://www.ndf.org.nz/