Business runs on information technology. The tools and devices that make up your IT infrastructure must provide you with a competitive advantage. And the same applies to your IT personnel.

Here are 5 reasons why IT hiring managers should partner with IT staffing firms in 2015.

1. You need a trusted partner
Many hiring managers only interview and hire a handful of candidates a year, so it can be difficult to know how to begin evaluating prospects. A trusted staffing partner can provide insight into the current candidate pool in multiple markets, provide competitive salary information, and help differentiate the traits of a good versus great candidate. This greatly improves your ROI.

2. The gap for IT talent is wide…and is getting wider
A staffing partner looks for specialized candidates 24 hours a day, 365 days a year. They fulfill positions as needed while adding hundreds of candidates to their proprietary databases. This provides access to candidates not found on job boards, and their relationships can help a frustrated hiring manager find those diamonds in the rough.

3. IT impacts all parts of your business
You want skilled IT resources to effectively lead your important initiatives. A staffing partner that has driven IT initiatives for hundreds of clients has access to accurate performance models, and knows how to build an effective staff to produce maximum effectiveness while reducing unnecessary costs.

4. Access to proven foreign national providers
There are more than 10,000 companies in the U.S. that sponsor foreign nationals for temporary IT work, so it can be difficult to tell which firms provide the most qualified candidates. Other concerns include fraudulent CV'S, cultural and language barriers, and lack of accountability. You want a staffing partner with a tiered vetting process to ensure that foreign national sponsor companies provide consistently qualified IT talent.

5. Enhance your career prospects
According to the U.S. Department of Labor, the average worker stays at the same job for 4.7 years. In fact, with the dynamic changes occurring in technology, job-hopping is the new normal for Millennials. An effective staffing partner can help IT contributors at all levels find out if the grass is in fact greener with a new position or company. Staffing partners understand dynamics like culture, the organizational hierarchy, and what a company values in its leaders.

Original Source: pomeroy.com

 

To gain the benefit of working with a dedicated IT and recruitment service, visit Certes 

and see how we can help you.

 

 

 

 

I was recently discussing with West Mercia Police the current state of cyber security awareness amongst the general public. West Mercia, like many other Police forces, are currently undertaking an outreach campaign of education and online crime prevention. The two highly experienced officers I spoke with were very open on how much work there is to do in order to help the public understand that they are at risk.

As ‘traditional’ crime falls, online crime is soaring. The ONS recently published figures stating that 6,000,000 crimes were committed in the UK last year that related to cyber crime or online fraud. That means we are now living in an era where 1 in 10 people have suffered at the hands of cyber criminals. 

In order to reduce the likelihood of becoming a cyber crime statistic just ask yourself a couple of questions.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

It's vital to plan and develop some key focus areas around business risk when implementing an IT strategy.

By now, we all know the fallout from an IT security crisis can be extremely serious. Businesses at the sharp end of high-profile problems, such as Sony and Carphone Warehouse, are still picking up the pieces. 

Even after the security flaw has been addressed and functionally operations are in a better shape than before, the business impact can linger. 

Here are five reasons why businesses need to focus on the business risk of IT security.

 

1. Assume the worst could happen – even if it never does

The business risk of an IT security failure is very real. We have all read about the very high-profile attacks, mistakes and disasters that have been particularly damaging because of their sheer scale or because there’s a well-known brand involved.

But many organisations continue to assume they are unlikely to be the subject of an attack, breach or outage. Applying that mentality to other areas of business risk, such as insurance, would be inconceivable. 

Most people, thankfully, have never been at a place of work which has been affected by fire or flooding – that doesn’t mean they shouldn’t work to prevent it.

There are undoubtedly many more examples where the risks have turned into a reality that never make the news. The healthiest approach is to plan on the basis that the risk is real for you, in your circumstances and in your organisation, and take action to plan accordingly.

 

2. Fully assess what is at risk

But where do you start? Planning to protect is a big enough challenge even when the breadth of IT and data assets are understood. Unfortunately, many organisations don’t audit or have a grip on their entire IT infrastructure, making it more difficult.

To protect your network perimeter properly you need to understand the risks across the entire IT environment – the technology that exists within the business and the areas of potential exposure when working with external partners. Don’t forget it’s also a wider discussion than just data – technology risk assessments should include all IT assets wherever they reside.

Risk assessments can be a challenge, and many organisations could do a lot to improve. It’s not uncommon, for example, for the individual responsible for assessing risk to download a checklist template from the internet and tick off against it, assuming it will cover all the possibilities. 

In most cases, these are simply too generic and not fit for purpose – risk assessments need to be comprehensive and bespoke.

As more organisations begin to implement private and public cloud technologies, a company’s network perimeter widens and the risk assessment and security considerations broaden. Organisations need to remember that any element of an outsourced security strategy needs to be considered as a point of risk.

 

3. Give responsibility to the right people

In every organisation, someone needs to take responsibility for IT security risk and strategy. For any business with an IT leader or team, the obvious approach is to place responsibility with them. They understand IT, so they are the logical people to understand IT security.

But to be truly effective, an approach to data risk and security needs to be impartial. Risk assessments need to adopt a brutally honest ‘warts ‘n all’ approach to inform the subsequent security strategy in the most effective way.  That job should be allocated to another business or security expert outside of the IT team, irrespective of the size of the organisation.

This can present a range of challenges. Many businesses don’t have dedicated IT staff, or leaders with the right level of experience or knowledge to focus on risk and security. Even for those organisations with greater resource, finding and retaining people who can act as the impartial expert is difficult, given the current high levels of demand for their services.

Technology partners can resolve this challenge and play a vital role, given their specialised experience and the advantage they present by doing the job all day, every day. Every organisation should aim for an appropriate level of impartiality, whether that comes from their own staff or from a trusted third party.

 

4. Plan for rapid recovery

Most organisations, quite rightly, focus on prevention. Very few look beyond that point and put a strategy in place to help the business recover as quickly as possible when a security problem has occurred. 

For the most high-profile attacks, the time and cost of repair can be very significant – Sony, for example, released figures to counter some estimates that their 2014 security breach could eventually cost up to $100 million.  The correct amount, according to Sony, was only $35 million – still a large sum for any organisation.

Part of the problem lies in organisations lacking the systems and skills in place to recover as quickly as possible from a security crisis, irrespective of its scale.  It’s important for businesses to factor in the business risk associated with recovery into their planning, and to have an infrastructure in place that can adapt quickly to a security breach to allow the business to return to normal trading without undue delay.

 

5. View strong risk management and security as an enabler

IT risk and security failures are generally seen as something to mitigate against. The best outcome that can be expected is that the risks never turn into reality. 

But for those who have taken the most advanced approach to the security issue, risks can begin to turn into opportunities. Combine that with the ability to demonstrate excellence in risk management and IT security becomes a differentiator and an area of competitive advantage. In our connected economy, businesses with a superior approach to IT risk and security will score points over a rival who does the bare minimum.

Ultimately, protection against IT risk is a question of degree – no one claims that we are close to solving IT security challenges once and for all. But adopting an approach which focuses on business risk can allow businesses to move forward more confidently than before.

 

Source: Information Age

The acceleration of innovation combined with the lack of attention given to security and privacy only increase the likelihood of these attacks

Cyber attackers have an abundance of opportunities to steal or modify data and disrupt business services – and their playground grows bigger and more diverse every day as the world becomes increasingly more digital.

Going into 2016, a number of new attack targets are expected to be in the headlines, drawing everyone’s attention to the lack of privacy and security in our interconnected world.

While data breaches are common news today, below are the top hacks that are likely to affect your life in a variety of ways in 2016.

 

1. Fantasy sports

There’s big money in fantasy sports. According to the Fantasy Sports Trade Association, Americans spend about $15 billion playing fantasy sports. That’s about 32 million Americans each spending $467.

Consider that each of those 32 million Americans also provide their name, address, email address, billing and/or credit card information, and you’re also looking at a truckload of customer data that could turn a reasonable profit on the black market.

Fantasy sports have not been immune to security threats. About two years ago application security testing firm NT OBJECTives discovered a vulnerability in Yahoo’s Fantasy Football mobile app. If exploited, attackers could change team lineups and post imposter comments on message boards.

More recently, a DraftKings employee admitted to accidentally posting confidential data, which led to accusations of insider trading. This type of activity is likely to reoccur, if not in the realm of fantasy sports than perhaps in the world of financial trading, where traders trade in other accounts so they don’t get caught.  

At any rate, hackers will no doubt target one of the leading fantasy sports sites – FanDuel or DraftKings – in 2016. Attackers will be looking to steal customer data or manipulate results to win big pools, which can total hundreds of thousands of dollars.

 

2. Presidential candidate

Four years is a long time when it comes to technological innovation. Consider social networks: CIO reports that candidates in the 2016 U.S. presidential election use more social networks than politicians of the past.

No one could’ve guessed in 2012 that Facebook and Twitter would be joined by the likes of Snapchat, Pinterest and Instagram as mainstream social networks. And there’s no telling what digital technologies will impact future presidential campaigns.

However, one thing is for certain: with every campaign, more of the candidates’ personal information is online. In 2016, at least one candidate is likely to get hacked.

But that’s not all. The unveiling of confidential or private information will change the course of the election. With so much personal data available, extortion and blackmail-type schemes are likely to increase in 2016 as well.

 

3. Planes, trains and automobiles?

In July 2015, software engineers Charlie Miller and Chris Valasek demonstrated how they could remotely exploit a zero-day vulnerability to send commands through a Jeep Cherokee’s entertainment system to its dashboard functions, steering, brakes and transmission.

To make matters worse, automobile manufacturers aren’t being forthright about hacker and privacy threats as a result of connected systems. Not only will we see more proof-of-concept scenarios in the coming year, but hackers will be looking to target major transport manufacturers, with serious implications for personal safety.

 

4. Drones

With drones becoming more widely available, they are also tipped to play a role in next year’s hacking activities. Researchers are already at work building software that can be loaded onto a drone and can penetrate consumer devices and networks, as well as enterprise networks.

It won’t take long before an attacker uses this software (one system is already available on GitHub) to conduct a large-scale cyber attack. Healthcare and government organisations will be prime targets because of the type and value of information they hold. Alternatively, attackers will begin to target the drones themselves to achieve remote control.

 

5. Major sporting event

The World Cup, Summer Olympics or Super Bowl 50 – one of these major sporting events will likely be a cyber event in 2016. It’s not too difficult to imagine a nation state tampering with Olympic timing machines, for example, to help its athletes win in a split-second race, or hackers tampering with scores to win large bets. Such an attack could have a significant impact on international politics as well as the popular culture associated with the event.

Even as these new attacks take front-and-centre stage in the coming year, organisations will continue to see activity from tried-and-true attacks that are still going strong. For example, banking trojans and spear phishing continue to be effective campaigns.

There will also continue to be activity from Nuclear, which has been around since 2011 and remains the most successful exploit kit available. Attackers continue to use SQL injection attacks as well to put malware on small websites as a repository.

It is more important than ever that going into the New Year both companies and individuals take great care to protect themselves.

Source: Information Age

 

Much of the negative chatter about cloud security is unfounded, and is simply an extension of what is already being dealt with across physical infrastructure 

Businesses regularly ask whether transition to the cloud is secure. The question is understandable, as there has been a lot of fear, uncertainty and doubt across the industry over the past few years.

Gartner thinks that cloud computing, by its very nature, is uniquely vulnerable to the risks of myths. So here are some common statements against cloud, and why they are better classified as myths than truths.

 

1. Cloud is riskier than traditional IT

An organisation’s infrastructure isn’t necessarily more secure just because it is located on-premise. Data breaches, data loss, account hijacking and denial of service attacks have been concerns since the invention of the mainframe computer back in the 1960s.

And while it is true that improperly configured cloud resources can result in these types of vulnerabilities, the same can be said of improperly configured physical infrastructure.

The key to a secure cloud implementation is working with a competent, experienced provider that makes investing in the strongest forms of networking security, intrusion detection and monitoring services core to their business.

In many cases, the security controls an experienced provider can handle may go well above and beyond an in-house IT team’s capabilities.

 

2. You can’t control where your data resides in the cloud

Heavily regulated industries such as healthcare and finance have controls that dictate where personally identifiable information (PII) and protected health information (PHI) can reside.

For these types of organisations, it may be (incorrectly) assumed that cloud isn’t a viable option due to the assumption that the location of data cannot be controlled. This cloud myth is easily discredited by understanding that organisations can choose to work with a provider that operates out of specific data centres in specific geographic regions.

Highly regulated organisations can also leverage a private cloud deployment model that provides them with increased control and governance versus the public cloud.

 

3. The cloud is not suitable for compliant workloads

Organisations with compliant workloads can still leverage the cloud, but a private or hybrid cloud deployment model may be better suited to their needs. A private cloud allows organisations to enjoy the flexibility and scalability benefits of the cloud, while still keeping data secure and in their control.

A hybrid model provides the added benefit of being able to “burst” to a public cloud for non-compliant workloads such as development and testing.

 

Source: Information age

Evolution is a part of nature. To survive we evolve. Technology is the best to evidence this as in short periods of time technology have seen drastic changes. Broadbean has decided to take a quick look at the big changes in technology that have made BDAS possible.    

           

Manual to Automated

The first big change in HR and Talent Analytics that had to happen for BDAS to exist was the shift from manual technologies to automated ones. Back office tasks used to be run by IT folks, who might see improvements in employees but couldn’t necessarily quantify or measure them. As more automated products became available, companies were able to take advantage of the benefits of not requiring as much manual input in order to work. Alan Hall, Senior Vice President of IT at Jacobus Consulting, Inc., offers us a good example of how businesses took advantage of automated systems. 

"One example of the quick improvements the company has made: Monthly financial closings had always been a challenge, but a two-week, largely manual process has been slashed in half. What's more, people have been freed up to focus on customer interactions instead of back-office tasks, enabling the company to sign a number of new and extended customer contracts it hadn't planned on addressing yet.” Alan Hall, Senior Vice President of IT at Jacobus Consulting, Inc.

Automation has become such a large part of business now that 72% of HR people say a lack of automation hinders their business success. It’s a large part of how many businesses have been able to make their business work, and couldn’t get on without it today.

 

Onsite to On the Cloud 

As companies around the world became better connected through the internet, cloud-based storage was simply a matter of time. Today companies can use cloud-based storage to keep all of their information in one location, accessible by all no matter what time zone they live in. Moving to this kind of storage has also been a source of savings. In 2015, companies plan to reduce their in-house IT spending from 54% to 37%, while increasing their cloud usage from 38% to 45%. 

Making information this accessible has made for a few minor concerns, however. Companies wary of adapting cloud-based storage are wary of the security risks placing all of a company’s information in one place would pose. They’re also concerned about properly integrating it into their business, as well as the difficulty of measuring the ROI on switching to cloud-based storage. As the technology continues to catch on, the problems should give way to better solutions that will allow companies to work with all their employees to a better degree. 

 

Products to Services 

The latest, but no less profound, change in the talent analytics space is the switch from products to services. Rather than selling a single product as-is, then updating that product and expecting customers to purchase it again, companies have begun selling their software as a service (giving rise to the acronym SaaS), and providing support and having customers subscribe to using that software. This allows companies to provide constant updates to their tech in order to better serve their customers. 

The change to services is a boon to companies, but customers are also more inclined to try something provided as a service. 60% of adults would consider paying for an online service if they were offered a trial. Both sides are willing to adapt to a changing market, as long as it offers them benefits to both. Customers don’t have to worry about their software being outdated, while companies are free to provide updates on an incremental basis rather than worry about cramming updates into a single package on a regular basis.

 

Source: Dominic Barton at Broadbean

What are you up to today? Anything nice? When the alarm went off at silly o'clock this morning did you jump out of bed, run 5 miles, eat a perfectly balanced breakfast and then get into the office early to continue your journey up the career ladder? If you did, then congratulations I’m right behind you. What about your boss, what get's them up and moving this morning? Or your work colleagues, or your friends? Essentially what is your motivation?

Although many will find it difficult to admit the motivation is usually money. Making enough money to live a relatively comfortable life – depending on what your definition of that is. You will put up with a few stresses, annoyances and complications just as long as at the end of the month your pay packet arrives. Did you know that a cyber-criminal is motivated by the same? The vast majority of cyber-crimes are financially motivated. Sure there are those intent on a morale crusade, and there are the state-sponsored attacks but scour any statistical report that is looking into the motivation behind cyber-attacks and it all comes down to making money.

Cyber criminals are more motivated to steal from you, then you are to prevent them. 

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

So it’s happened. You really had hoped that it wouldn’t, but hope has let you down and you have run out of luck. A cyber breach has occurred, data has gone, you are not sure how, when or by whom. Your mind now starts to wonder if this was an attack, or perhaps a disgruntled employee? – after all you have just completed the latest round of HR reviews and some people were disappointed with the pay rise that was offered – What’s going to happen now? Do you tell your customers? Do you tell your suppliers? Should you be drafting a statement to put on your website? Perhaps you need to gather all the staff and talk to them, but then what will they say? Damn, you had been warned this might happen. It’s a mess and it’s going to get messier.

If that happened to you, what would you do? Have you ever wondered? Many companies have a critical incident policy in place that can be acted on should the worst happen, but precious few have one in place for cyber. 

So, who would you call in to investigate it? 

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

If you could sit down and have a face to face open conversation with a cyber criminal what do you think they would tell you?

 

How did it all start?

I can’t say that it was a planned career move or anything like that, in fact quite the opposite. Maybe more a case of ‘right place at the right time?’ But even that sounds wrong. Perhaps myself and the others are just members of the disenfranchised millennials who found that traditional IT work was relatively mundane and our more modern technical skill sets were totally undervalued in the offers of employment we had, so we looked elsewhere.

What you have to remember is that so much of cyber crime goes unreported due to its relatively low value. I mean companies can lose £200 here, £1000 there, it’s not going to bring them down, but the time and effort it will take them to investigate it, report it, is too much for the value of what they have lost. Is this just ‘luck’ on their part? Of course not, it’s designed that way. Our focus is not about stealing £100,000,000 from one company, but a few thousand pounds from a few thousand companies. The beauty of cyber crime is that it scales…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

In 1964 as the then Cassius Clay beat the fearsome Sonny Liston, his eyes became bright and his voice pushed out a message that was compelling. “I shook up the world”, he cried, “I shook up the world”. From here he changed his name to Muhammad Ali and continued to change the world. He was a disruptor, loved by many, loathed by others, but there is no doubt about how he changed things.

In 2004 Muhammad Ali appeared in an IBM commercial, regarding Linux, encouraging those who adopted this ‘new’ open source operating system to go and do something great, go and disrupt, go and push technology forward for all humanities sake. This cry, this call to arms is never more relevant than today. We need some serious technology disruption in order to stem the increasing threat from cyber crime, but where is it going to come from? 

The world needs a technology disruptor to shake up the world and become the Uber of cyber security.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.