1
00:00:06,510 --> 00:00:08,250
- In this lesson 6.2,

2
00:00:08,250 --> 00:00:09,083
we're gonna focus

3
00:00:09,083 --> 00:00:11,940
on third-party and
supply-chain threat vectors.

4
00:00:11,940 --> 00:00:13,620
Now, in the last lesson, 6.1,

5
00:00:13,620 --> 00:00:15,630
we looked internally
at operational vectors.

6
00:00:15,630 --> 00:00:18,810
Here we're looking at our third
parties, our fourth parties,

7
00:00:18,810 --> 00:00:20,223
and our supply chain.

8
00:00:21,420 --> 00:00:23,580
So what is a third party?

9
00:00:23,580 --> 00:00:25,500
Third parties include vendors,

10
00:00:25,500 --> 00:00:28,620
managed service providers
we refer to as MSPs,

11
00:00:28,620 --> 00:00:32,010
business partners,
consultants, and contractors

12
00:00:32,010 --> 00:00:36,423
that in some way interact with
our systems or with our data.

13
00:00:37,350 --> 00:00:38,970
Now, fourth parties are vendors

14
00:00:38,970 --> 00:00:41,190
that a third party sources through.

15
00:00:41,190 --> 00:00:42,690
And there are a number

16
00:00:42,690 --> 00:00:45,180
of pathways to exploit that are inherent

17
00:00:45,180 --> 00:00:47,460
in our third- and
fourth-party relationships.

18
00:00:47,460 --> 00:00:48,810
And they manifest, really,

19
00:00:48,810 --> 00:00:52,080
as really significant
risk to the organization.

20
00:00:52,080 --> 00:00:53,640
What can be the consequences?

21
00:00:53,640 --> 00:00:58,260
Financial loss, reputational
damage, inefficient operations,

22
00:00:58,260 --> 00:01:01,920
a data breach or data
exfiltration, service disruption,

23
00:01:01,920 --> 00:01:04,203
and regulatory non-compliance.

24
00:01:05,100 --> 00:01:05,933
What we want to include

25
00:01:05,933 --> 00:01:08,340
in our discussion also, our supply chain.

26
00:01:08,340 --> 00:01:10,890
A supply chain is the entire ecosystem

27
00:01:10,890 --> 00:01:13,130
of organizations, processes, people,

28
00:01:13,130 --> 00:01:17,438
and resources involved in
providing a product or service.

29
00:01:17,438 --> 00:01:19,890
Pre-pandemic, many of us didn't pay a lot

30
00:01:19,890 --> 00:01:21,720
of attention to the supply chain,

31
00:01:21,720 --> 00:01:23,430
but boy, we learned some hard lessons

32
00:01:23,430 --> 00:01:26,850
in the pandemic about
supply chain disruptions

33
00:01:26,850 --> 00:01:28,443
and other supply chain issues.

34
00:01:29,820 --> 00:01:32,520
That supply chain represents
the steps it takes

35
00:01:32,520 --> 00:01:36,600
to get a product or service
from inception to the end user.

36
00:01:36,600 --> 00:01:40,080
That end user could be a
consumer or an organization.

37
00:01:40,080 --> 00:01:42,030
One of the biggest challenges

38
00:01:42,030 --> 00:01:45,480
in trying to manage or
understand the supply chain is

39
00:01:45,480 --> 00:01:50,480
that an organization very
inoften has a direct relationship

40
00:01:50,520 --> 00:01:53,760
with supply chain vendors or components,

41
00:01:53,760 --> 00:01:57,000
or have a communication
conduit to their supply chains

42
00:01:57,000 --> 00:01:58,140
and really are dependent

43
00:01:58,140 --> 00:02:00,723
upon the vendors that
have those relationships.

44
00:02:03,690 --> 00:02:04,523
So we're gonna start

45
00:02:04,523 --> 00:02:06,930
with a third party threat vector survey,

46
00:02:06,930 --> 00:02:09,000
and then we're gonna dive
deep just like we did

47
00:02:09,000 --> 00:02:09,990
in the last lesson.

48
00:02:09,990 --> 00:02:13,320
We're gonna dive deep into each
one of those threat vectors.

49
00:02:13,320 --> 00:02:16,770
So issues, lack of support,
end of life and end of support.

50
00:02:16,770 --> 00:02:18,120
We talked about that in the last lesson

51
00:02:18,120 --> 00:02:19,320
and we're gonna talk about it again,

52
00:02:19,320 --> 00:02:21,150
because it is so important.

53
00:02:21,150 --> 00:02:24,330
Proprietary configurations, system sprawl,

54
00:02:24,330 --> 00:02:27,600
undocumented assets,
supply chain dependency,

55
00:02:27,600 --> 00:02:32,073
supply chain disruption, and
supply chain non-conformance.

56
00:02:34,470 --> 00:02:37,320
So lack of support from a third party

57
00:02:37,320 --> 00:02:41,760
or ultimately a fourth party
is really a significant issue.

58
00:02:41,760 --> 00:02:42,631
The lack of support stems

59
00:02:42,631 --> 00:02:45,330
from either getting an inadequate service

60
00:02:45,330 --> 00:02:48,660
from that vendor or
unknowledgeable support personnel

61
00:02:48,660 --> 00:02:49,710
at that vendor,

62
00:02:49,710 --> 00:02:51,600
or there's a deficient warranty,

63
00:02:51,600 --> 00:02:55,230
or they're just plain old unresponsive.

64
00:02:55,230 --> 00:02:56,400
What's the impact?

65
00:02:56,400 --> 00:02:58,650
Well, we have downtime, potentially,

66
00:02:58,650 --> 00:03:00,600
we get problems that aren't resolved,

67
00:03:00,600 --> 00:03:02,853
and vulnerabilities that aren't addressed.

68
00:03:03,840 --> 00:03:05,610
So what should be our response?

69
00:03:05,610 --> 00:03:07,050
Well, first of all, due diligence,

70
00:03:07,050 --> 00:03:11,190
which is the investigation of
a vendor or any relationship

71
00:03:11,190 --> 00:03:15,030
before we enter into a contract
or any type of of agreement.

72
00:03:15,030 --> 00:03:18,720
And then we wanna continue to
do that investigation, right?

73
00:03:18,720 --> 00:03:21,480
And analysis really through
the life of the relationship

74
00:03:21,480 --> 00:03:24,150
and particularly at any type
of contract renewal time.

75
00:03:24,150 --> 00:03:25,830
And then having SLAs

76
00:03:25,830 --> 00:03:28,920
or service level agreements
to codify service

77
00:03:28,920 --> 00:03:32,010
and support requirements and expectations.

78
00:03:32,010 --> 00:03:33,360
Again, both of these topics

79
00:03:33,360 --> 00:03:34,350
are things we're gonna be talking

80
00:03:34,350 --> 00:03:35,700
about in just a little bit.

81
00:03:37,590 --> 00:03:40,230
Next, we're gonna talk about
end of life and end of support.

82
00:03:40,230 --> 00:03:42,630
Now, I know we've already
talked about this already

83
00:03:42,630 --> 00:03:44,550
but this is such an important topic

84
00:03:44,550 --> 00:03:46,710
with such significant ramifications

85
00:03:46,710 --> 00:03:49,350
that it's worth talking about again.

86
00:03:49,350 --> 00:03:50,370
So what's the issue?

87
00:03:50,370 --> 00:03:52,230
The issue is that we
have a product or service

88
00:03:52,230 --> 00:03:56,100
that's either at EOL, end of
life, or EOS, end of support.

89
00:03:56,100 --> 00:03:58,080
The EOL, end of life, is the date

90
00:03:58,080 --> 00:03:59,070
when a product, service,

91
00:03:59,070 --> 00:04:02,070
or subscription is
determined to be obsolete.

92
00:04:02,070 --> 00:04:04,560
So no new features or new
functionality is going

93
00:04:04,560 --> 00:04:06,510
to be developed for that product.

94
00:04:06,510 --> 00:04:08,460
End of support is the last day

95
00:04:08,460 --> 00:04:12,270
to receive applicable service and support.

96
00:04:12,270 --> 00:04:13,980
So you can't call for help anymore.

97
00:04:13,980 --> 00:04:15,840
And really importantly,

98
00:04:15,840 --> 00:04:18,300
there will be no more
vulnerability management going on,

99
00:04:18,300 --> 00:04:21,120
no more patches being released.

100
00:04:21,120 --> 00:04:22,620
So what's the impact?

101
00:04:22,620 --> 00:04:24,570
Well, we could have problems not resolved,

102
00:04:24,570 --> 00:04:26,670
no new features or functionalities,

103
00:04:26,670 --> 00:04:28,560
and vulnerabilities not addressed.

104
00:04:28,560 --> 00:04:29,790
And that's the big one.

105
00:04:29,790 --> 00:04:31,860
Vulnerabilities not addressed.

106
00:04:31,860 --> 00:04:34,170
End of life and end of support systems

107
00:04:34,170 --> 00:04:38,250
are absolutely opportunistic
targets, right?

108
00:04:38,250 --> 00:04:42,240
If this attacker knows that
you're running something

109
00:04:42,240 --> 00:04:44,280
at end of life or end of support,

110
00:04:44,280 --> 00:04:48,003
that's really a fabulous
pathway for them to attack you.

111
00:04:49,920 --> 00:04:53,550
So the response, having good
agreements and contracts,

112
00:04:53,550 --> 00:04:55,590
having refresh policies and standards.

113
00:04:55,590 --> 00:04:56,820
Refresh policies really refer

114
00:04:56,820 --> 00:04:58,350
to how often are we going to refresh

115
00:04:58,350 --> 00:05:02,190
or turn over our devices,
our hardware, our software.

116
00:05:02,190 --> 00:05:03,990
And then resource management

117
00:05:03,990 --> 00:05:05,880
and of course budgeting appropriately.

118
00:05:05,880 --> 00:05:07,803
So having the right budget allocation.

119
00:05:10,320 --> 00:05:12,877
But so often in the field I hear,

120
00:05:12,877 --> 00:05:14,287
"Why can't I just continue

121
00:05:14,287 --> 00:05:16,867
"to use the software or hardware,

122
00:05:16,867 --> 00:05:19,597
"even though it's post EOL or EOS,

123
00:05:19,597 --> 00:05:22,147
"if it's meeting the organization's needs

124
00:05:22,147 --> 00:05:23,850
"and it's functioning properly?"

125
00:05:23,850 --> 00:05:25,177
It's like, "I love this software,

126
00:05:25,177 --> 00:05:26,670
"why can't I keep using it?"

127
00:05:26,670 --> 00:05:28,875
Or, "This hardware is working great,

128
00:05:28,875 --> 00:05:31,197
"why can't we keep using it?"

129
00:05:32,490 --> 00:05:33,810
Well, here's why you can't,

130
00:05:33,810 --> 00:05:35,430
and here's the message you need to deliver

131
00:05:35,430 --> 00:05:37,050
in your organizations.

132
00:05:37,050 --> 00:05:39,450
The adversaries will continue to identify

133
00:05:39,450 --> 00:05:41,280
and exploit vulnerabilities.

134
00:05:41,280 --> 00:05:43,500
And almost every regulation requires

135
00:05:43,500 --> 00:05:47,100
that organizations take reasonable
steps to protect the data

136
00:05:47,100 --> 00:05:49,140
and systems that are under its control.

137
00:05:49,140 --> 00:05:52,680
And not doing so would be
a compliance violation.

138
00:05:52,680 --> 00:05:54,600
You'd also have exposure to litigation

139
00:05:54,600 --> 00:05:57,270
for not upholding the
standard of due care.

140
00:05:57,270 --> 00:06:01,740
Due care is really defined as
kind of reasonable actions.

141
00:06:01,740 --> 00:06:03,180
You would've risk of downtime

142
00:06:03,180 --> 00:06:06,360
due to lack of support
or service resolution,

143
00:06:06,360 --> 00:06:09,810
and really likely would be incompatibility

144
00:06:09,810 --> 00:06:14,010
with newer operating systems,
applications and hardware.

145
00:06:14,010 --> 00:06:17,240
So we absolutely wanna discourage
using any type of hardware

146
00:06:17,240 --> 00:06:22,240
or software post-EOL or
at very worst post-EOS.

147
00:06:24,510 --> 00:06:25,530
Another issue we face

148
00:06:25,530 --> 00:06:28,470
in organizations is
proprietary configurations.

149
00:06:28,470 --> 00:06:31,290
We may have hardware, software devices

150
00:06:31,290 --> 00:06:34,020
inside our infrastructure
that we don't own

151
00:06:34,020 --> 00:06:35,010
and we don't manage.

152
00:06:35,010 --> 00:06:38,370
And those configurations
are considered proprietary

153
00:06:38,370 --> 00:06:40,680
if in fact we can't manage them.

154
00:06:40,680 --> 00:06:42,480
We're the user organization.

155
00:06:42,480 --> 00:06:45,120
And so the impact could
be unknown exposures

156
00:06:45,120 --> 00:06:48,000
or vulnerabilities that aren't addressed

157
00:06:48,000 --> 00:06:49,440
in a timely manner

158
00:06:49,440 --> 00:06:52,920
and also an inability
to update those systems.

159
00:06:52,920 --> 00:06:56,670
So our response, agreements and contracts.

160
00:06:56,670 --> 00:06:58,620
We wanna have right-to-audit agreements,

161
00:06:58,620 --> 00:07:01,247
we wanna have interconnection
security agreements,

162
00:07:01,247 --> 00:07:03,030
ISAs that we use

163
00:07:03,030 --> 00:07:06,630
to document technical
requirements and responsibilities.

164
00:07:06,630 --> 00:07:08,227
So an ISA agreement says, "Okay,

165
00:07:08,227 --> 00:07:11,767
"who is responsible for
managing this device?

166
00:07:11,767 --> 00:07:13,837
"Who is responsible for patching it?

167
00:07:13,837 --> 00:07:17,437
"Who is responsible for
configuring or reconfiguring it?

168
00:07:17,437 --> 00:07:19,957
"Who is responsible for
fixing it if it breaks?

169
00:07:19,957 --> 00:07:24,957
"Who is responsible for replacing
it if it's not fixable?"

170
00:07:25,530 --> 00:07:26,640
All of that would be

171
00:07:26,640 --> 00:07:30,123
in our ISA, our Interconnection
Security Agreement.

172
00:07:32,310 --> 00:07:34,380
Another issue is system sprawl.

173
00:07:34,380 --> 00:07:37,860
System sprawl is often the
result of non-standardization

174
00:07:37,860 --> 00:07:40,890
or decentralization where
we have multiple vendors

175
00:07:40,890 --> 00:07:42,210
who are installing stuff,

176
00:07:42,210 --> 00:07:44,790
we have departments working
with different vendors.

177
00:07:44,790 --> 00:07:48,120
We may end up with incompatible platforms

178
00:07:48,120 --> 00:07:51,000
and we may just have
some unmanaged growth.

179
00:07:51,000 --> 00:07:53,820
The impact of systems sprawl
would be a support burden

180
00:07:53,820 --> 00:07:57,870
and the inability to enforce
our security requirements.

181
00:07:57,870 --> 00:08:02,160
Our response, having really
good vendor security strategy

182
00:08:02,160 --> 00:08:05,310
and standards and of course
configuration management.

183
00:08:05,310 --> 00:08:06,300
Have you noticed how many

184
00:08:06,300 --> 00:08:09,483
of these things have come back
to configuration management?

185
00:08:10,860 --> 00:08:12,720
Next is undocumented assets.

186
00:08:12,720 --> 00:08:15,810
These are assets that
are in our environment

187
00:08:15,810 --> 00:08:18,510
but we don't have any record of them.

188
00:08:18,510 --> 00:08:20,040
So undocumented assets

189
00:08:20,040 --> 00:08:23,220
are not inventory recorded or tracked.

190
00:08:23,220 --> 00:08:26,340
It may be that a user
brought something in,

191
00:08:26,340 --> 00:08:28,440
it may be that a vendor
brought something in,

192
00:08:28,440 --> 00:08:30,030
so our third party who's working

193
00:08:30,030 --> 00:08:33,210
inside our organization maybe
brings their own laptop,

194
00:08:33,210 --> 00:08:35,070
it's an undocumented asset.

195
00:08:35,070 --> 00:08:38,580
So it's not inventory recorded or tracked.

196
00:08:38,580 --> 00:08:40,560
The impact the assets aren't included

197
00:08:40,560 --> 00:08:43,320
in our anti-malware processes,

198
00:08:43,320 --> 00:08:45,570
in vulnerability, or configuration,

199
00:08:45,570 --> 00:08:47,700
or change management processes.

200
00:08:47,700 --> 00:08:50,433
Totally is out of our line of sight.

201
00:08:51,540 --> 00:08:53,757
The response, a contractual obligation

202
00:08:53,757 --> 00:08:56,670
to document any assets that you'd be using

203
00:08:56,670 --> 00:08:57,810
in our network or connecting

204
00:08:57,810 --> 00:09:00,810
to our network using
network access control, NAC,

205
00:09:00,810 --> 00:09:01,770
which has pre-admission

206
00:09:01,770 --> 00:09:04,200
and post-admission policies
to evaluate a system

207
00:09:04,200 --> 00:09:05,670
before it's allowed on our network.

208
00:09:05,670 --> 00:09:07,620
We'll be talking about that later on.

209
00:09:07,620 --> 00:09:09,427
Network mapping to be able to say, "Okay,

210
00:09:09,427 --> 00:09:11,160
"what assets are out there?"

211
00:09:11,160 --> 00:09:14,403
And vulnerability scanning
to identify our assets.

212
00:09:16,980 --> 00:09:19,020
Now we're gonna turn our
attention to the supply chain.

213
00:09:19,020 --> 00:09:21,930
And I wanna look at three
supply chain issues,

214
00:09:21,930 --> 00:09:25,440
Supply chain dependency,
supply chain disruption,

215
00:09:25,440 --> 00:09:28,020
and supply chain non-conformance.

216
00:09:28,020 --> 00:09:31,080
Supply chain dependency is
when we have, generally,

217
00:09:31,080 --> 00:09:33,720
a single source or sole-source dependency

218
00:09:33,720 --> 00:09:35,160
on a supply chain vendor.

219
00:09:35,160 --> 00:09:36,930
And when they can't deliver something,

220
00:09:36,930 --> 00:09:38,910
everything comes to a halt.

221
00:09:38,910 --> 00:09:40,890
Supply chain disruption is

222
00:09:40,890 --> 00:09:42,420
when there is a disruption, generally,

223
00:09:42,420 --> 00:09:45,294
in the delivery of supply chain items.

224
00:09:45,294 --> 00:09:48,810
So it could be like we had at
the ports during the pandemic.

225
00:09:48,810 --> 00:09:50,370
They all got overloaded, right?

226
00:09:50,370 --> 00:09:52,170
And just couldn't deliver.

227
00:09:52,170 --> 00:09:55,260
Or it could be a disruption
because of weather,

228
00:09:55,260 --> 00:10:00,150
or it could be a disruption
because of a political issue.

229
00:10:00,150 --> 00:10:01,680
But something's happened, right?

230
00:10:01,680 --> 00:10:04,740
That the supply chain can't deliver.

231
00:10:04,740 --> 00:10:07,110
And then supply chain
non-conformance is when they're not

232
00:10:07,110 --> 00:10:10,470
in conformance with your
expectations, your contracts,

233
00:10:10,470 --> 00:10:12,783
or your regulatory obligations.

234
00:10:14,400 --> 00:10:17,760
The impact on all of these
is the inability to operate

235
00:10:17,760 --> 00:10:19,980
and or deliver a service or product.

236
00:10:19,980 --> 00:10:22,320
We could have negative
stakeholder response,

237
00:10:22,320 --> 00:10:24,150
we could end up with regulatory actions,

238
00:10:24,150 --> 00:10:26,403
and certainly a financial impact.

239
00:10:27,750 --> 00:10:28,920
So what do we do?

240
00:10:28,920 --> 00:10:32,400
We're really trying to
identify our supply chain.

241
00:10:32,400 --> 00:10:34,260
Who is in our supply chain?

242
00:10:34,260 --> 00:10:36,960
Working to diversify our supply chain

243
00:10:36,960 --> 00:10:40,110
so we don't have a dependency
on just one vendor.

244
00:10:40,110 --> 00:10:41,850
And then being really good

245
00:10:41,850 --> 00:10:44,340
about monitoring supply chain activities

246
00:10:44,340 --> 00:10:46,800
and including our supply chain,

247
00:10:46,800 --> 00:10:48,930
all our supply chain
vendors and relationships

248
00:10:48,930 --> 00:10:51,123
in our risk management processes.

249
00:10:53,910 --> 00:10:56,490
That my friends, brings us to
our three-second challenge.

250
00:10:56,490 --> 00:10:57,450
Are you ready?

251
00:10:57,450 --> 00:10:59,160
Five challenge questions,
three seconds each.

252
00:10:59,160 --> 00:10:59,993
Let's do it.

253
00:11:01,380 --> 00:11:03,000
The ecosystem of organizations,

254
00:11:03,000 --> 00:11:06,150
processes and people
and resources involved

255
00:11:06,150 --> 00:11:08,223
in providing a product or service.

256
00:11:09,330 --> 00:11:10,320
What is this called?

257
00:11:10,320 --> 00:11:12,093
1, 2, 3.

258
00:11:13,080 --> 00:11:16,230
This is our supply chain question.

259
00:11:16,230 --> 00:11:17,802
Question two, agreement

260
00:11:17,802 --> 00:11:21,903
that documents technical
requirements and responsibilities.

261
00:11:24,000 --> 00:11:26,250
1, 2, 3.

262
00:11:26,250 --> 00:11:27,840
That's gonna be our ISA,

263
00:11:27,840 --> 00:11:30,033
our Interconnection Security Agreement.

264
00:11:31,590 --> 00:11:33,630
Number three, the last date

265
00:11:33,630 --> 00:11:35,973
to receive product service and support.

266
00:11:37,620 --> 00:11:39,543
1, 2, 3.

267
00:11:40,620 --> 00:11:43,143
That's gonna be EOS or end of support.

268
00:11:44,340 --> 00:11:48,303
Number four, sole-source
reliance on a vendor.

269
00:11:50,280 --> 00:11:52,683
1, 2, 3.

270
00:11:53,670 --> 00:11:55,020
That would be dependency.

271
00:11:55,020 --> 00:11:56,490
And if it's in our supply chain,

272
00:11:56,490 --> 00:11:58,413
it would be supply chain dependency.

273
00:12:00,420 --> 00:12:02,220
And lastly, number five,

274
00:12:02,220 --> 00:12:05,290
the term used to describe unmanaged growth

275
00:12:06,450 --> 00:12:10,110
or when things just get outta
control, they get too big.

276
00:12:10,110 --> 00:12:11,610
What's the term we're using?

277
00:12:11,610 --> 00:12:13,053
1, 2, 3.

278
00:12:13,950 --> 00:12:15,603
That's gonna be system sprawl.

279
00:12:16,920 --> 00:12:18,690
Hey, I hope you did well on this.

280
00:12:18,690 --> 00:12:21,840
We're gonna do a Security-in-Action
about EOL and EOS.

281
00:12:21,840 --> 00:12:24,030
Why, Because it's such an important topic.

282
00:12:24,030 --> 00:12:25,683
I wanna keep talking about it.

283
00:12:26,850 --> 00:12:30,840
Your boss just loves her
old laptop running Windows 7

284
00:12:30,840 --> 00:12:32,460
and doesn't wanna give it up,

285
00:12:32,460 --> 00:12:33,330
even though support

286
00:12:33,330 --> 00:12:36,843
for Windows 7 ended on January 10th, 2023.

287
00:12:37,710 --> 00:12:38,640
As a side note,

288
00:12:38,640 --> 00:12:41,250
Microsoft actually always
tells us the end of life

289
00:12:41,250 --> 00:12:44,550
and the end of support date
when they release a product.

290
00:12:44,550 --> 00:12:46,860
So we've known this date for a long time,

291
00:12:46,860 --> 00:12:48,360
but your bossman loves

292
00:12:48,360 --> 00:12:51,063
that windows 7 device and
doesn't wanna give it up.

293
00:12:51,990 --> 00:12:53,400
So you're preparing for a meeting

294
00:12:53,400 --> 00:12:56,610
to explain why immediately
upgrading her laptop

295
00:12:56,610 --> 00:12:59,610
and the operating system is essential.

296
00:12:59,610 --> 00:13:01,680
So what key points are you gonna make

297
00:13:01,680 --> 00:13:03,150
to convince her to upgrade?

298
00:13:03,150 --> 00:13:05,880
Go ahead and put me on
pause, jot down some notes

299
00:13:05,880 --> 00:13:08,630
then we'll come back and talk
about reasons to upgrade.

300
00:13:11,820 --> 00:13:14,730
First reason, Microsoft no
longer provides security updates

301
00:13:14,730 --> 00:13:18,093
or technical reports for the
Windows 7 operating system.

302
00:13:18,960 --> 00:13:22,740
Our antivirus software may have
limited effectiveness on PCs

303
00:13:22,740 --> 00:13:25,290
that don't have the
latest security updates.

304
00:13:25,290 --> 00:13:27,930
So her laptop could be at risk.

305
00:13:27,930 --> 00:13:29,460
And when her laptop
connects to the network,

306
00:13:29,460 --> 00:13:31,510
we're putting the entire network at risk.

307
00:13:32,910 --> 00:13:36,090
More and more apps and
devices aren't going to work

308
00:13:36,090 --> 00:13:37,140
with Windows 7.

309
00:13:37,140 --> 00:13:39,430
They're expecting a later operating system

310
00:13:41,580 --> 00:13:44,790
And every time she connects
to the corporate network,

311
00:13:44,790 --> 00:13:49,410
she's putting the organization
at operational, compliance,

312
00:13:49,410 --> 00:13:53,880
legal, financial, and reputational risk.

313
00:13:53,880 --> 00:13:55,184
Hopefully that'll be
enough for her to say,

314
00:13:55,184 --> 00:13:57,000
(laughs) "Okay, I'm done."

315
00:13:57,000 --> 00:13:59,730
But if not, we have more arguments still.

316
00:13:59,730 --> 00:14:02,490
She's acting contrary to company policy,

317
00:14:02,490 --> 00:14:04,950
assuming that you have a
company policy that says

318
00:14:04,950 --> 00:14:07,950
that you can't be using
systems past end of support,

319
00:14:07,950 --> 00:14:09,840
and hopefully you do.

320
00:14:09,840 --> 00:14:13,410
And lastly, let her know that her new PC,

321
00:14:13,410 --> 00:14:15,930
it'll be faster, it'll be more fun,

322
00:14:15,930 --> 00:14:19,770
and it'll definitely be a
more enjoyable experience.

323
00:14:19,770 --> 00:14:21,360
So even if nothing else worked,

324
00:14:21,360 --> 00:14:24,090
hopefully that last bullet will.

325
00:14:24,090 --> 00:14:26,580
Being able to have this
conversation with your boss,

326
00:14:26,580 --> 00:14:28,080
being confident and really being able

327
00:14:28,080 --> 00:14:31,530
to explain it and moving the needle,

328
00:14:31,530 --> 00:14:33,573
that, my friends, is security in action.

329
00:14:35,340 --> 00:14:37,020
There's your word cloud.

330
00:14:37,020 --> 00:14:39,090
You know what to do, make sure
you know all of these terms,

331
00:14:39,090 --> 00:14:39,923
you can explain it.

332
00:14:39,923 --> 00:14:42,720
If not, go back through the lesson again.

333
00:14:42,720 --> 00:14:45,210
Now I do recognize that
in the response section,

334
00:14:45,210 --> 00:14:48,060
I introduced a lot of topics
we haven't talked about yet.

335
00:14:48,060 --> 00:14:49,110
But we will be talking

336
00:14:49,110 --> 00:14:51,900
about all of them throughout this course.

337
00:14:51,900 --> 00:14:52,740
All right, when you're ready,

338
00:14:52,740 --> 00:14:54,340
I'll see you at the next lesson.
