SlideShare a Scribd company logo
Cybersecurity Aspects of
Blockchain and
Cryptocurrency
About Me
Tony Martin-Vegue
@tdmv
• 20 years in Technology; last 10 in Cyber Risk
• FAIR practitioner for about 7 years now
• Reside in the Bay Area
Book chapter…
“Cyber Risk
Quantification of
Financial
Technology”
Paradigms
Emerging
Risks
From the “Today Show,” 1994
“What is Internet, Anyway?”
Paradigm Shifts
Cybersecurity aspects of blockchain and cryptocurrency
Users
Databases
Resources
Traditional Defense-In-
Depth
UsersDatabases
Resources New Normal
There is no cloud.
Just someone else’s
computer
…blockchain is just someone
else’s database.
Traditional Defense-In-Depth Beyond the Hard Perimeter
• Clear perimeter
• Policy enforcement points
• Company-controlled
hardware, software, data
• Access-control based trust
models
• Compliance: easy to
define
• Fuzzy or no perimeter
• Enforcement points: not
applicable
• “Ownership” is
decentralized
• Zero-trust
• Still figuring compliance
out
Emerging
Risks
The Strange Case
of Mt. Gox
(or, how forgetting
the fundamentals
can really hurt)
“The One Patch
Most Needed in
Cybersecurity”
Cybersecurity aspects of blockchain and cryptocurrency

More Related Content

What's hot (20)

PPTX
Blockchain and Cybersecurity
gppcpa
 
PPTX
BLOCKCHAIN
Nitish sharma
 
PPTX
Cryptocurrency
Rohit Kumar Kashyap
 
PDF
Blockchain Explained | Blockchain Simplified | Blockchain Technology | Blockc...
Edureka!
 
PDF
Blockchain Security Issues and Challenges
Merlec Mpyana
 
PDF
Blockchain in Banking, Business and Beyond
Michael Novak
 
PPTX
Blockchain in cyber security
Prateek Panda
 
PDF
Crypto Wallet Types Explained
101 Blockchains
 
PDF
Blockchain
Frank Calberg
 
PPTX
Blockchain by Aman Thakur.pptx
The NorthCap University
 
PDF
An Introduction to Blockchain Technology
Niuversity
 
PPTX
BITCOIN EXPLAINED
Murlidhar Sarda
 
PPTX
Cryptocurrency and Bitcoin
Utkarsh Singh
 
PDF
Blockchain Technology Fundamentals
Experfy
 
PPTX
Cryptocurrency
YuvarajManimaran1
 
PDF
How does blockchain work
Shishir Aryal
 
PPTX
Crypto wallets
Christian Kameir
 
PPTX
Cryptocurrency
Devashish Gupta
 
PPTX
Blockchain Essentials and Blockchain on Azure
Nuri Cankaya
 
PDF
Blockchain Technology | Blockchain Explained | Blockchain Tutorial | Blockcha...
Edureka!
 
Blockchain and Cybersecurity
gppcpa
 
BLOCKCHAIN
Nitish sharma
 
Cryptocurrency
Rohit Kumar Kashyap
 
Blockchain Explained | Blockchain Simplified | Blockchain Technology | Blockc...
Edureka!
 
Blockchain Security Issues and Challenges
Merlec Mpyana
 
Blockchain in Banking, Business and Beyond
Michael Novak
 
Blockchain in cyber security
Prateek Panda
 
Crypto Wallet Types Explained
101 Blockchains
 
Blockchain
Frank Calberg
 
Blockchain by Aman Thakur.pptx
The NorthCap University
 
An Introduction to Blockchain Technology
Niuversity
 
BITCOIN EXPLAINED
Murlidhar Sarda
 
Cryptocurrency and Bitcoin
Utkarsh Singh
 
Blockchain Technology Fundamentals
Experfy
 
Cryptocurrency
YuvarajManimaran1
 
How does blockchain work
Shishir Aryal
 
Crypto wallets
Christian Kameir
 
Cryptocurrency
Devashish Gupta
 
Blockchain Essentials and Blockchain on Azure
Nuri Cankaya
 
Blockchain Technology | Blockchain Explained | Blockchain Tutorial | Blockcha...
Edureka!
 

Similar to Cybersecurity aspects of blockchain and cryptocurrency (20)

PDF
Profile Of The Worlds Top Hackers Webinar Slides 063009
Lumension
 
PDF
DDoS Attacks
Vitor Jesus
 
PDF
Blockchain presentation v0617
Joaquim Pedro Antunes
 
PDF
Block chain A Paradigm Shift
Ramanan Jagannathan
 
PPTX
Cyber security by Gaurav Singh
Gaurav Singh
 
PPTX
Cyber threat enterprise leadership required march 2014
Peter ODell
 
PDF
Blockchain Security and Privacy
Anil John
 
PDF
20101012 isa larry_clinton
CIONET
 
PPTX
MYTHBUSTERS: Can You Secure Payments in the Cloud?
Kurt Hagerman
 
PPTX
CRI "Lessons From The Front Lines" March 26th Dublin
OCTF Industry Engagement
 
PPTX
Team2Jax_FinalPresentation
Anh Thuc Tran
 
PPTX
Second line of defense for cybersecurity : Blockchain
Ahmed Banafa
 
PPTX
Iurii Garasym. The future crimes and predestination of cyber security. Though...
IT Arena
 
PDF
Cybercrime: Radically Rethinking the Global Threat
NTT Innovation Institute Inc.
 
PPTX
Cyber Security Lessons from the NSA
CipherCloud
 
PDF
The implications of blockchain for the insurance industry - Eurapco Peer Semi...
Vidal Chriqui
 
PPTX
2019 GDRR: Blockchain Data Analytics - Real World Adventures at a Cryptocurre...
The Statistical and Applied Mathematical Sciences Institute
 
PDF
Today's Breach Reality, The IR Imperative, And What You Can Do About It
Resilient Systems
 
PPTX
Blockchain in Healthcare
Alex Tsado
 
PDF
Discover blockchain - WA state thought leader discussion
Mark Mueller-Eberstein
 
Profile Of The Worlds Top Hackers Webinar Slides 063009
Lumension
 
DDoS Attacks
Vitor Jesus
 
Blockchain presentation v0617
Joaquim Pedro Antunes
 
Block chain A Paradigm Shift
Ramanan Jagannathan
 
Cyber security by Gaurav Singh
Gaurav Singh
 
Cyber threat enterprise leadership required march 2014
Peter ODell
 
Blockchain Security and Privacy
Anil John
 
20101012 isa larry_clinton
CIONET
 
MYTHBUSTERS: Can You Secure Payments in the Cloud?
Kurt Hagerman
 
CRI "Lessons From The Front Lines" March 26th Dublin
OCTF Industry Engagement
 
Team2Jax_FinalPresentation
Anh Thuc Tran
 
Second line of defense for cybersecurity : Blockchain
Ahmed Banafa
 
Iurii Garasym. The future crimes and predestination of cyber security. Though...
IT Arena
 
Cybercrime: Radically Rethinking the Global Threat
NTT Innovation Institute Inc.
 
Cyber Security Lessons from the NSA
CipherCloud
 
The implications of blockchain for the insurance industry - Eurapco Peer Semi...
Vidal Chriqui
 
2019 GDRR: Blockchain Data Analytics - Real World Adventures at a Cryptocurre...
The Statistical and Applied Mathematical Sciences Institute
 
Today's Breach Reality, The IR Imperative, And What You Can Do About It
Resilient Systems
 
Blockchain in Healthcare
Alex Tsado
 
Discover blockchain - WA state thought leader discussion
Mark Mueller-Eberstein
 
Ad

More from Tony Martin-Vegue (10)

PDF
Incentivizing Better Risk Decisions - Lessons from Rogue Actuaries - SIRAcon ...
Tony Martin-Vegue
 
PPTX
How to Lie with Statistics, Information Security Edition
Tony Martin-Vegue
 
PPTX
Crowdsourced Probability Estimates: A Field Guide (FAIR Institute)
Tony Martin-Vegue
 
PDF
Crowdsourced Probability Estimates: A Field Guide
Tony Martin-Vegue
 
PPTX
Ransomware & Game Theory: To Pay, or Not to Pay?
Tony Martin-Vegue
 
PPTX
Should I Pay or Should I Go? Game Theory and Ransomware
Tony Martin-Vegue
 
PPTX
Can cyber extortion happen to you? Practical tools for assessing the threat
Tony Martin-Vegue
 
PPTX
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
Tony Martin-Vegue
 
PPTX
How to Lie with Statistics, Information Security Edition
Tony Martin-Vegue
 
PDF
How to Improve Your Risk Assessments with Attacker-Centric Threat Modeling
Tony Martin-Vegue
 
Incentivizing Better Risk Decisions - Lessons from Rogue Actuaries - SIRAcon ...
Tony Martin-Vegue
 
How to Lie with Statistics, Information Security Edition
Tony Martin-Vegue
 
Crowdsourced Probability Estimates: A Field Guide (FAIR Institute)
Tony Martin-Vegue
 
Crowdsourced Probability Estimates: A Field Guide
Tony Martin-Vegue
 
Ransomware & Game Theory: To Pay, or Not to Pay?
Tony Martin-Vegue
 
Should I Pay or Should I Go? Game Theory and Ransomware
Tony Martin-Vegue
 
Can cyber extortion happen to you? Practical tools for assessing the threat
Tony Martin-Vegue
 
Measuring DDoS Risk using FAIR (Factor Analysis of Information Risk
Tony Martin-Vegue
 
How to Lie with Statistics, Information Security Edition
Tony Martin-Vegue
 
How to Improve Your Risk Assessments with Attacker-Centric Threat Modeling
Tony Martin-Vegue
 
Ad

Recently uploaded (20)

PDF
CH 1_Managers and Economics - Introduction.pdf
AhmadM65
 
PDF
Eni 2023 Second Quarter Results - July 2025
Eni
 
PPTX
Commercial Bank Economic Capsule - July 2025
Commercial Bank of Ceylon PLC
 
PPTX
Introduction of Derivatives.pptx dwqdddff
XMenJEAN
 
PDF
Mining Beneficiation as a Catalyst for Broad-Based Socio-Economic Empowerment...
Matthews Bantsijang
 
DOCX
The Political Era of Accountability: A Reflection on South Africa's Past Self...
Matthews Bantsijang
 
PPTX
Econometrics - Introduction and Fundamentals.pptx
skillcipetcsn
 
PDF
PROBABLE ECONOMIC SHOCKWAVES APPROACHING: HOW BAYER'S GLYPHOSATE EXIT IN THE ...
Srivaanchi Nathan
 
PPTX
Presentation on Finance Act 2025 - Applicable from 01.07.2025
MahmoodSaeedChaudhry1
 
PDF
2025 Mid-year Budget Review_SPEECH_FINAL_23ndJuly2025_v5.pdf
JeorgeWilsonKingson1
 
PPTX
Maintenance_of_Genetic_Purity_of_Seed.pptx
prasadbishnu190
 
PDF
Pyramid_of_Financial_Priorities_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PPTX
Agrarian Distress by Dr. S. Malini. ppt.
MaliniHariraj
 
PDF
European Exchange Report 2024 - FESE Statistics
secretariat4
 
PDF
Why Superstitions Still Influence Daily Life in the 21st Century
Harsh Mishra
 
PDF
EPF.PDF ghkvsdnkkxafhjbvcxvuhv ghghhhdsghhhhhhh
Satish Sathyameva Jayathe
 
PPT
The reporting entity and financial statements
Adugna37
 
PDF
The Future of Electricity Regulation in South Africa by Matthews Mooketsane B...
Matthews Bantsijang
 
PPTX
Demand Management jjbdsfjsnfjnodfds.pptx
pparthmurdeshwar
 
CH 1_Managers and Economics - Introduction.pdf
AhmadM65
 
Eni 2023 Second Quarter Results - July 2025
Eni
 
Commercial Bank Economic Capsule - July 2025
Commercial Bank of Ceylon PLC
 
Introduction of Derivatives.pptx dwqdddff
XMenJEAN
 
Mining Beneficiation as a Catalyst for Broad-Based Socio-Economic Empowerment...
Matthews Bantsijang
 
The Political Era of Accountability: A Reflection on South Africa's Past Self...
Matthews Bantsijang
 
Econometrics - Introduction and Fundamentals.pptx
skillcipetcsn
 
PROBABLE ECONOMIC SHOCKWAVES APPROACHING: HOW BAYER'S GLYPHOSATE EXIT IN THE ...
Srivaanchi Nathan
 
Presentation on Finance Act 2025 - Applicable from 01.07.2025
MahmoodSaeedChaudhry1
 
2025 Mid-year Budget Review_SPEECH_FINAL_23ndJuly2025_v5.pdf
JeorgeWilsonKingson1
 
Maintenance_of_Genetic_Purity_of_Seed.pptx
prasadbishnu190
 
Pyramid_of_Financial_Priorities_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
Agrarian Distress by Dr. S. Malini. ppt.
MaliniHariraj
 
European Exchange Report 2024 - FESE Statistics
secretariat4
 
Why Superstitions Still Influence Daily Life in the 21st Century
Harsh Mishra
 
EPF.PDF ghkvsdnkkxafhjbvcxvuhv ghghhhdsghhhhhhh
Satish Sathyameva Jayathe
 
The reporting entity and financial statements
Adugna37
 
The Future of Electricity Regulation in South Africa by Matthews Mooketsane B...
Matthews Bantsijang
 
Demand Management jjbdsfjsnfjnodfds.pptx
pparthmurdeshwar
 

Cybersecurity aspects of blockchain and cryptocurrency

Editor's Notes

  • #2: My portion of the panel Cybersecurity aspects of blockchain and cryptocurrency
  • #3: Quick note about me Been in technology for over 20 years, info sec RISK for the last 10. 7 years in FAIR – quant risk framework– the first couple spent unlearning bad risk habits and absorbing as much as I can Currently work for lending club – a Fin Tech up the street. We are a peer-to-peer loan company Many have called up the first and the largest Fin Tech – Paypal would have an issue with that claim
  • #4: Late Feb, book on fin tech was released. I wrote a book chapter called – Welcome to come leaf through it
  • #5: Purpose of the talk, two things: Talk about the paradigm shift in thinking about cyber security that blockchain and crypto currency represents. we’re all in the middle of right now #2, Talk about emerging risks and give a couple of tips for risk managers to get started on assessing risk
  • #6: https://www.youtube.com/watch?v=UlJku_CSyNg Requires a paradigm shift in thinking, fintech, blockchain, cryptocurrency Few points: Funny now But back then they couldn’t wrap their heads around this concept of the internet Their bewilderment captures what many of us felt at the time Good parallel to blochchain today – blockchaain and crypto currency may be so ubiquitious that we in 20 years from now we’ll be thinking back and laughing Some people knew but most did not know that they were on the cusp on a major cultural and technological change that would irreversibly alter our society
  • #7: with that in mind --want to talk about paradign shifts. force to See things in a different way - cyber security controls or information security, risk assessment You are going to have to grapple with this as risk managers - Common mis-conceptions Block chain is bitcoin or cryptocurrency Public versus private ledger But one of the biggest paradigm shifts we will have to get used to is….
  • #8: …the metaphors we use to describe how we deploy security controls around our technology. The idea here is defense in depth. There’s a single asset – the crown jewels – and attackers have to overcome successive controls. Early lookout posts, Moat, artificial hills, archer towers, 3 rings of walls
  • #9: …and this is how we design our defenses and control frameworks. Attackers on the right – nation state, hackers, organized cyber crime Company assets on the left – users, databases, systems. All protected in the middle with layers of security, control, backup control, etc. all designed around a hard, defined perimeter this paradigm shift started about 10 years ago woth cloud, byod, and continues today with blockchain
  • #10: Today New normal If this give you a headache, that’s my point I call this the “The incredible shrinking perimeter” The concept of the perimeter changed -- users, resources, straddling inside and outside the permiter defenses – the resources are outside the layerd security metaphor - instead of one layer, you had mulptile layers, mulptile controls for each group Thank about how a public blockchain deployment would work, for example – a Payments application like Paypal. The databses are distributed, outside of the company’s perimeter – relying on new/different controls than we would see on a traditional demployment More targets, more surface
  • #11: Old adage
  • #15: Forgeting the fundamentals   Mt. Gox Bitcoin heist in 2014 first and largest Bitcoin exchanges at the time 850,000 Bitcoin 450 million USD. today, the value of 850,000 Bitcoin is $5.8 trillion USD.     How did this happen?   ex-CEO of Mt. Gox blamed hackers for the loss, others blamed the CEO, Mark Karpeles; the CEO even did time in a Japanese jail for embezzlement   There were other issues according to a 2014 story in Wired Magazine, ex-employees described a company in which there was no code control, no test code environment and only one person that could deploy code to the production site: the CEO himself, Mark Karpeles took weeks to deploy security fixes   Fintech’s primary competitive advantage is that they have less friction than traditional financial services able to innovate and push products to market very quickly.   The downside the Mt. Gox case proves is when moving quickly, one cannot forget the fundamentals. Fundamentals, such as code change/version control, segregation of duties and prioritizing security patches should not be set aside in favour of moving quickly.   Risk managers need to be aware of and apply these fundaments to any risk analysis.  
  • #16: Quote from Doug Hubbard Reference to As mentioned many times previously, technology is rapidly evolving and so is the threat landscape. Practices, such as an ambiguous network perimeter and distributed public databases were once unthinkable security practices. They are now considered sound and, in many cases, superior methods to protect the confidentiality, integrity and availability of assets. Risk managers must adapt to these new paradigms and use better tools and techniques of assessing and reporting risk. If we fail to do so, our companies will not be able to make informed strategic decisions. One of these methods is risk quantification. Why we’re hearing more and more about fair – risk quant – OCC has started referencing it as a framework, many others