当前位置:首页 > 报告详情

税务管理中的网络弹性.pdf

上传人: Seven****onds 编号:709738 2025-05-17 17页 1.98MB

1、Cyber Resilience in Tax AdministrationDefending Trust,Data,and RevenuePresented byLysandra Capella20 February 2025Secure tomorrow,todayLets Talk.Email:InfoCheckmateCyberCPhone:+599 9 5100902Principal Consultant:Lysandra E C Founder Checkmate Cyber Consultancy Over 10 Years experience working in cybe

2、rsecurity in Dutch Caribbean,Europe,Middle East and US.SME for SANS Institute Research focused on Cloud security,Incident Response,Cybersecurity Posture improvement Passion for continuous learning:40+Certifications in Cybersecurity,Forensics,Incident Response,Cloud Security,Pentest,Cyber Defense 343

3、434If Criminals Can Hack a Museum,They Can Hack Your Tax SystemMovie clip:Oceans 834What happens when Hollywood fiction becomes reality?$100 MillionCost Cyberattack MGM Resorts34Now imagine this wasnt a movie but real world1Collect information on MGM Resorts and its employees2Look for employees on L

4、inkedIn who may have high privileged accounts.Call the MGM IT helpdesk and pretend to be the user.Requesting for the password and MFA to be reset.3Attack the privileged accounts and later on the other accounts4Extract confidential information from MGM servers.56Encrypt more than 100 servers,causing

5、mass service interruption34Why Are Tax Administrations Prime Targets?Massive Data HoldingsLarge Financial TransactionsLegacy IT SystemsTax System Trust Dependency1234341.Visit https:/ in your Personal or Business email3.Look at the resultWas Your Information In A Breach?341Gathered personal informat

6、ion about taxpayers from various sources outside the IRS(like social media,public records and previous breaches)Exploiting IRS Get Transcript Service(Weak Authentication)2Use stolen data to answer the identity verification questions correctly3View and download complete tax transcripts and use for us

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要探讨了税务管理中的网络安全问题。演讲者Lysandra Capella拥有超过10年的网络安全经验,在多个地区包括荷兰加勒比海、欧洲、中东和美国工作。她强调了税务管理成为攻击目标的原因,包括大量的数据持有、大额金融交易、遗留的IT系统以及公众对税务系统的信任依赖。文中提到了MGM Resorts和IRS的网络安全事件,以及 Bulgarian National Revenue Agency的数据泄露事件,指出攻击者通常利用身份验证薄弱和过时的安全政策。 Capella提出了加强网络安全弹性的措施,包括加强数据库安全、定期进行漏洞评估、强制实施多因素身份验证(MFA)、开展税务机构网络安全审查、提升人工智能和欺诈检测能力、进行网络攻击模拟演习等。她强调,网络安全不仅是IT部门的责任,而是需要高层领导承担的战略风险。通过这些措施,可以提高税务系统的抵御能力,保护纳税人信息,维护公众对税务系统安全的信任。
"如何防范税务系统的网络攻击?" "税务部门如何应对深度伪造技术?" "如何确保税务数据的安全与弹性?"
客服
商务合作
小程序
服务号
折叠