• • • • • Asım Gençer Gökce agencer.gokce@tubitak.gov.tr TÜBİTAK BİLGEM Cyber Security Institute (SGE) Role: Cyber Security Services Unit Manager/Project Manager Targeted Call (CIP Session): • CIP-01-2016-2017: Prevention, detection, response and mitigation of the combination of physical and cyber threats to the critical infrastructure of Europe SMIG2016 - 26-27 January 2016 TÜBİTAK – BİLGEM – SGE Cyber Security Institute Disclaimer: with the submission of this presentation the consent is given by its author for the organisers to distribute the presentation. 1 • National Critical Infrastructure, Asset and Facility Determination, Risk Assessment and Prioritization Project (2015-…) (funded by the Republic of Turkey, Prime Ministry, Disaster & Emergency Management Authority) • National Critical Infrastructure Information Systems Protection Project (2012-2013) (funded by the Republic of Turkey, Ministry of Development) • Projects funded under European Commission FP7 • Managing Threats And Vulnerabilities in the Future Internet (SYSSEC) Project (2010-2014) • Cloud For Europe (C4E) Project (2013-…) • Penetration Testing and Security Assessment for critical public sector organizations, financial institutions, etc. • ISO 27001 Consultancy for critical sector institutions such as the Turkish Atomic Energy Agency. SMIG2016 - 26-27 January 2016 TÜBİTAK – BİLGEM – SGE Previous / on going projects 2 • CIP-01-2016-2017: Prevention, detection, response and mitigation of the combination of physical and cyber threats to the critical infrastructure of Europe • Critical infrastructure assessment methodology, risk analysis methodology formulation, Analysis of Critical Sectors • Security audit checklist development of ICT components in the Industrial Control Systems (ICS). • Vulnerability assessment methodology development of ICSs. • Penetration testing methodology development of web and desktop applications of ICSs. • Determination of fuzzing and reverse engineering methods for ICSs. • Firmware analysis methodology development for ICSs components. • Remote Terminal Unit (RTU) security audits and penetrations testing. • ICSs network security and protocol security formulation. • Hardware security testing method formulation for DCSs (Distributed Control Systems), and PLCs (Programmable Logic Controllers). SMIG2016 - 26-27 January 2016 TÜBİTAK – BİLGEM – SGE Potential partnership activity 3