So thank you for having me here at SAIC and thank you also that I'm able to present in the women and identity slot where in Germany together with Angelica we form a huge community and all the women here and of course all the supporters we'd like to invite you all to be part of our community. With Zero Trust in our organization, I work for PwC as a director, our main PwC purpose is build trust in society and solve important problems. The whole organization is aligned with this goal of building trust and all the portfolios around it, our internal governance and all our leadership model.
Our internal IT has started several years ago, a Zero Trust transformation and our leadership team said, no, our goal is to build trust, you can't start an IT transformation which is called Zero Trust. So think about yourself if this is a contradiction or not, we could speak about this later. I will start with our new reality and our new reality, just look at what's happening in the news, in the newspapers, of course, ongoing persistent cyber threats, threats from various actors, criminals, state actors, attacks and also insiders.
I used to be on a panel with Homeland Security in Germany and he was referring to quite insider attacks as still today underestimated that it's happening. And also the challenge in organization, what we particularly see is upcoming a new regulation, financial sector, for example, the DORA regulation, the Cyber Resilience Act, which is meant to build in security in products which become more and more smart.
I have a smart watch, my car is hopefully driving autonomously and all the smart thingies that you have at home, in your car, in your houses also get more interesting for attackers also to attack. But also all regulations, GDPR, it's still some years when it started to come, but also what I see, it's still a hot topic, especially if you look at the GDPR, which says protect personal identifiable information, have some kind of technical organizational measures around it. And the same measures here could solve also to protect business information.
And geopolitics, also quite a hot topic when it comes to cyber attacks. In spring, I was at the Munich Security Conference and so also people who are involved with NATO and the United Nations were referring to today, when we look at critical infrastructure, it looks like some kind of breakdown, but it could also already be with respect to cyber warfare, hybrid war, it could be already attack, which looks like some kind of breakdown. So that was some kind of message that I took from the Munich Security Conference.
And attackers aiming for stealing intellectual property, having impact on critical infrastructure. And with this kind of further integration of smart and physical products, having more interconnecting, our infrastructure gets more vulnerable as anymore. And new technology, AI, I like AI, I like emerging tech, I like new technology.
However, I work in the risk and threat department, cybersecurity, I'm paid to be paranoid. And also with new technology comes new risk. And also with AI, in one of the last Ike conferences, I gave a talk about what if your digital twin misbehaves. And now my colleagues who work as pen testers use deepfakes to have some kind of deepfake of a CAO, CAO as some kind of awareness measures.
And it's quite easy techniques, what they are using, they only need some kind of snippets of pictures or voice recording, where they are able to deepfake as awareness measures, of course, as pen testing an organization as a fake CAO, fake CAO and so on. Which also means, on the one hand side, we see that IT and security specialists are highly demanded. But also with growing skill sets, they need to know about AI, they need to know about the new risks, they need to know about what the new regulation comes with.
And all this complexity when it comes to interconnection, new technology, emerging technology, new threats, geopolitics means there's some kind of high demand and need for action. And what we see, we do some kind of annual study, annual surveys. And if you look and ask, hey, all the respondents on the sea level, what are you concerning most on threats? And it says, okay, cloud related threats and attacks, hack and leak operations, third party breaches, attacks on connected products, ransomware. And we also ask, how well do you feel prepared on all those attacks?
And you see in all the dimensions, the things they are concerned on, the attacks and threats, they all feel not yet good prepared for all this kind of attacks. And that's also something that I see typically as a security architect. I start with some kind of assessments. And in every assessment that I do, I see gaps when it comes to technology process, organizational preparedness on the cybersecurity poster. And BITCOM also, you see what kind of damage it comes, money-wise, 276 billion euros in 2024. And the attribution is around 70% of organized crimes. So that's the current situation.
I think in this audience, it's not that news. However, how are we going to prepare for this kind of situation? And I started with identity around 2005. Angelica was saying 2010, and still we are in the way to standardize and still not yet finished. So why not? Because our way to work has changed. It has changed a lot. And if you look at this picture, which is some kind of high-level picture of how we work together, home office. This morning, my home office was in the hotel.
I was working in the hotel with my mobile device, connecting to our own corporate infrastructure, however, as a consultant. I'm also a business partner where I connect from home or from home office, from my organization office or client office, to data that could be in a corporate office, but also quite often outsourced in some cloud or other providers' data centers. And on the left-hand side, I try to indicate the users that also connect with mobile devices, other devices, to information data on application servers somewhere.
So from any location with any device, anytime, anywhere, connectivity. And if you start imagining and try to outline, I'm connected from hotel to some application, which could be in a data center. So try to outline your own connectivity and see it could be a kind of messy, messy diagram that comes out. But we have to protect it. We have to protect it from end-to-end, all the information, the data that are in transit. And what I've outlined on the circle means from an organization perspective, all this information that flows across these networks has to comply with the overall strategy.
It has to comply to the regulations in my organization, which could be DORA, NIST 2, whatever you comply to. And it has to be monitored in a unique way. And for this, I recommend to think about the Zero Trust Architecture to tackle those challenges. And the goal is to have, when we look at also how to govern all this kind of infrastructure, to have a resilient security architecture with policies that are automatically enforced. This morning, I was reviewing a policy on a paper, which is still on a paper based on DORA regulation.
However, the goal is, my goal is to enable architecture that we are in a situation that we are able to automatically enforce policies. And it's quite highly relevant. And for this, we need a security concept and zero trust from its principles that don't trust anybody, anything. And the assumption is that there could be no assumption made about trust when accessing networks or resources. And it's based on the principle, never trust, always verify. Every user, every device and component, and every user device component is considered potentially insecure.
And when I work with organizations, especially small, medium organizations or highly regulated public sectors, they say, hey Sylvia, we are a small company, we have a family, we trust our employees, we trust our peers. And as in our own organization, where our leadership can't have a zero trust transformation, why we have building trust as a core principle. Those are the discussions we are tackling. And it requires an integrated solution, several components.
If you look at all the underlying infrastructure that enables this kind of any-to-any communication with any device from anywhere, it must be consistently and integrated. And why are we doing it?
Well, I was explaining the threat landscapes that we have. And the idea is to stop threats, especially the one including the insider threats, to have some kind of highly resilient network and architecture. And the goal is also to reduce tool profileration. So what I see in organization at the moment, I'm an organization energy provider. Some parts are relevant for the critical regulation, some parts are not. Some parts are relevant for German national regulation, some for international regulation.
So organization was tackling this by buying tools to have compliance with the respective regulation. But the idea is also to harmonize on the technology stack to enable a better compliance. And of course, use technology to enhance digitalization, this kind of policy monitoring, enable it by automated policies and create a complete overview. So having said that, the technical components, of course, one is identity. Having identity and access management in a software-defined matter at one of the core piece.
But also if you look at all the network flows that I was motivating, also look at your network because the network is the core autobahn for your information. And also this has to be protected. And look at where the information comes into the network and where it goes out. And look at all the boundaries. And one of the technical means to tackle this in a zero-trust implementation is to implement logical segments and have on the boundaries some kind of facilities to monitor those.
In this interconnected world, look at all the cloud security, cloud security governance, secure cloud network and also secure all your endpoints. And with endpoints, it means the devices, the computers, but also the smart devices. And if you look at industrial securities, also the operational technologies, which is also becoming more and more interconnected with the IT world. And also with my internal colleagues, I have quite a lot of discussion.
Okay, zero-trust, what kind of products do you recommend? Some customers ask me what kind of tools you should buy. And zero-trust is a security architecture principle.
Of course, you need technology to implement it. However, you also have to look at the governance and management perspective of zero-trust because zero-trust verifies everything. It's quite a challenging method in theory. When we implement it, we have some kind of trust levels that we have to look at depending on the risk and the risk appetite organization is taking. And that's not coming with technology, but that's something you have to discuss individually in every organization.
So, don't start inventing it new. There is good guidance out there. In Germany, we have guidance from the BSI and an international look at the core principle. What NIST has published was also all data sources and servers are considered as resources.
So, it has an impact of IT asset management when you implement it. External and internal threats are present at all times.
So, with some of my public sector clients, they have, okay, how long do we have to monitor? Hackers do not stop at five o'clock when business is ending.
So, look at it that threats could occur all the times, which means also from an identity perspective, introduce the least privileged strategy. Never trust, always verify, which means grant access per session. And every device, user network and resource is authenticated and authorized. And access to resources is determined on dynamic policies. And here comes where the tech enablement part comes in when I write policies on paper to be DORA compliant, to be NIST 2 compliant, etc. Look at the toolings that you have, the flexibility to implement and automate all these kinds of policies.
Well, we at our own organization build trust in society. I am, as a security architect, promote the zero trust principle. But trust comes in an interaction, so trust in people. Because how do you feel if I say, okay, you're the weakest link in our organization, I don't trust you, or even worse, I'm the weakest link, I'm not trusting me. What could happen? Monitor users, monitor you. Zero trust of people, don't trust anyone.
Well, I do feel bad about it, potentially you as well. So in all management philosophy and people management, okay, you have to trust your people to take over responsibilities. So when there's lack of trust in people, it leads to less independence and assumption of responsibility. So from a people perspective, zero trust is a principle that couldn't be worse.
However, zero trust is a technical principle where we assume bad things to happen, and with the help of technology, we look how we could solve this.
And which means zero trust architecture from a technical perspective comes with digital ethics to build trust in the people, which means that the people in your organization and some kind of cultural change, that you also have to work on a zero trust transformation, that organization and people take over responsibility, that you build in some kind of digital governance, but you also look at upskilling and training because also here zero trust AI, that the organization and the people are skilled and know what they are doing and why, look at a clear communication and also look at in the event of crisis, because assume breach is one of the core principles of zero trust.
So it still could happen that crisis hacks could occur, so be prepared also on this one. So zero trust from the people perspective means a comprehensive and holistic view, also from the organization and people perspective, balancing the chances and risks that come with digitalization and look at putting the people in the core center of this transformation. And technology is some kind of enabler to implement those. How would I like to start those?
Typical look at what you would like to protect, which means identify all the assets, and the assets could be also in the cloud and the assets that you need to protect and then make some kind of justification how relevant those assets are for your business.
And I do quite often, I also at the moment, I have some kind of international global organization, where they also do some kind of IT asset management with tooling, but still there they do not have the connection between business information and IT information, which means also here is the challenge where we are working at to get the right classification of IT and information that you are able then to protect it according to the level of assurance, level of risk and level of trust you need.
Once you have this kind of ground and hygienic work, start mapping your data flows, which is by the way also some kind of DORA regulation need, and then building the Zero Trust Network on top of it. Start creating the Zero Trust policies, start to implement to automate those, and then also look at, since bad things could happen, that you incorporate the proper and adequate monitoring and maintenance in your network.
So, that's basically the simple thing about Zero Trust and the Zero Trust journey. In our own organization, we have started it a couple of years ago, we are still in this journey.
So, be aware, it's not just done by picking up pieces, picking up some technology, it's a whole transformation and cultural transformation as well, where we also have to incorporate all your work. So, thank you for your attention. I hope you have any questions. I think we still have some time left.
Yes, are there any questions? Yes. Anyone who is implementing a Zero Trust strategy in the room?
Ah, okay. One, at least one. Two people.
Yes, I saw two hands. Well, in the US, it's mandatory for all public service providers. I missed the talk, but I was looking forward to it. I wonder if you wouldn't mind summarizing it in 30 seconds for me. Pardon? I missed the talk, but I was looking forward to it. I wonder if you wouldn't mind summarizing it in 30 seconds. Okay. All right.
So, thank you. Thank you very much. Give applause, please.