Managed Service Providers: Pwn One and Done

Presented at DerbyCon 2.0 Reunion (2012), Sept. 29, 2012, 1 p.m. (30 minutes)

Managed Service Providers deliver varying degrees of Information Technology (IT) support to many clients. Some range from fully outsourced IT to on-demand assistance. However, one thing they all have in common, due to the nature of the sensitive access they may have, is the risk they can pose to their clients if they are not careful. I will explorer some of these risks and mitigation strategies.


Presenters:

  • Damian Profancik (integrisec)
    Damian Profancik is an Information Technology Architect and Security Consultant/Researcher at Apparatus division where he helps lead, design and implement security services. Damian has over 12 years of Information Technology consulting experience in designing and implementing server/network infrastructure and information security solutions for clients ranging in size from small-business to the enterprise. He holds the credential of Certified Information Systems Security Professional (CISSP) from ISC2. In addition, he is involved in the security community through, speaking engagements, the Open Web Application Security Project (OWASP), and a local Indianapolis Information Security group, IndySec.