So it’s happened. You really had hoped that it wouldn’t, but hope has let you down and you have run out of luck. A cyber breach has occurred, data has gone, you are not sure how, when or by whom. Your mind now starts to wonder if this was an attack, or perhaps a disgruntled employee? – after all you have just completed the latest round of HR reviews and some people were disappointed with the pay rise that was offered – What’s going to happen now? Do you tell your customers? Do you tell your suppliers? Should you be drafting a statement to put on your website? Perhaps you need to gather all the staff and talk to them, but then what will they say? Damn, you had been warned this might happen. It’s a mess and it’s going to get messier.

If that happened to you, what would you do? Have you ever wondered? Many companies have a critical incident policy in place that can be acted on should the worst happen, but precious few have one in place for cyber. 

So, who would you call in to investigate it? 

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

In 1964 as the then Cassius Clay beat the fearsome Sonny Liston, his eyes became bright and his voice pushed out a message that was compelling. “I shook up the world”, he cried, “I shook up the world”. From here he changed his name to Muhammad Ali and continued to change the world. He was a disruptor, loved by many, loathed by others, but there is no doubt about how he changed things.

In 2004 Muhammad Ali appeared in an IBM commercial, regarding Linux, encouraging those who adopted this ‘new’ open source operating system to go and do something great, go and disrupt, go and push technology forward for all humanities sake. This cry, this call to arms is never more relevant than today. We need some serious technology disruption in order to stem the increasing threat from cyber crime, but where is it going to come from? 

The world needs a technology disruptor to shake up the world and become the Uber of cyber security.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Well done, you’ve done it. You have made security a priority in the product and services you provide. You have continuously reinforced to your customers that you will uphold and not compromise their privacy. They can trust you. Then the FBI knocks on your door and asks in the strongest possible terms if you would be willing to break your own security and let them in through the back door to see what one of your customers has been up to. What are you going to do? 

This is the dilemma facing Apple right now in a story that has been all over the press in the last few days. The overview is that the FBI recovered an iPhone from a terrorist who killed 14 people and injured 22 in San Bernardino in 2015. This iPhone was locked with the regular 4-digit passcode that the FBI didn’t know, as the terrorist was shot and killed. The FBI have tried and failed to get into the phone so are now attempting to force Apple to circumvent their own security in order to gain access to it’s contents. Should Apple comply with their request? There are questions over the legality of this request. There are questions over if the request is technically possible: and there is a seemingly never ending stream of questions and opinions on the moral issues of this story.

What would you do if the FBI came knocking at your door asking for data? Are you prepared?

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

If you could sit down and have a face to face open conversation with a cyber criminal what do you think they would tell you?

 

How did it all start?

I can’t say that it was a planned career move or anything like that, in fact quite the opposite. Maybe more a case of ‘right place at the right time?’ But even that sounds wrong. Perhaps myself and the others are just members of the disenfranchised millennials who found that traditional IT work was relatively mundane and our more modern technical skill sets were totally undervalued in the offers of employment we had, so we looked elsewhere.

What you have to remember is that so much of cyber crime goes unreported due to its relatively low value. I mean companies can lose £200 here, £1000 there, it’s not going to bring them down, but the time and effort it will take them to investigate it, report it, is too much for the value of what they have lost. Is this just ‘luck’ on their part? Of course not, it’s designed that way. Our focus is not about stealing £100,000,000 from one company, but a few thousand pounds from a few thousand companies. The beauty of cyber crime is that it scales…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

How many times will you suffer from a cyber attack before you actually take real action? The answer is probably three.

“How many times have I got to tell you to stop doing that before you will learn?” would often be heard around my childhood home, as I’m sure it was in yours and probably in your children’s if truth be known.

Like you and probably like your children too, I didn’t listen. I decided to learn in my own way, under my own misplaced guidance. Somehow I had to find out for myself, irrespective of the consequences, which in many childhood instances would be cuts, bruises and a wide collection of grazes!

It seems that no matter how much advice we are given, how many people who are more learned than ourselves give us practical and insightful assistance, we still like to find out for ourselves, even if the costs are high. 

While in discussions at the National Cyber Skills Centre this week, it was mentioned that these childhood desires to ‘find out for ourselves’ continues into modern business life and more notably cyber security. Despite cyber security costing companies many millions, despite millions of individuals losing personal data, despite the headlines of notable brands suffering major hacks and data breaches, it still is not enough to spur many into action…

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Accidents can happen, but we need to learn from them.

Despite all the technological advancements of the last few centuries the scientists and engineers of this world have yet to crack the ‘if only I could turn back time by 30 seconds’ that is often needed once you have incorrectly addressed an email.

If that technology had been available, then the National Health Service (NHS) staff member who this week inadvertently sent an email to all 840,000 staff members would have been its biggest fan. As members of NHS staff then “replied to all” they further exacerbated the issue and the email system quickly ground to a halt after no doubt frustrating tens of thousands of hard working individuals in the process.

Any organisation that has a global staff email list that can be accessed by anybody, even accidentally, needs to swiftly review its email usage policies. As a former IT Manager, I often witnessed how such lists were wildly used for the most menial of messages; lost umbrellas, missing office furniture, requests for lifts to and from work, clogged up the Inboxes of everyone. When such messages are sent out to thousands of people, who in turn open and read them, the sheer loss of productivity is a compelling argument enough to apply some restrictive managerial guidelines. Used accidentally, it just cries out that there is a most basic lack of IT awareness within an organisation…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Supply chain management within a business is a complex and highly skilled disciple. It’s a two-way street, companies provide products and services to their customers, but also provide information to third parties who are providing them with products and services. Should that supply chain break due to a cyber attack, breach, or criminal activity, then its much harder for a business to recover in comparison to me just switching coffee shops.

It doesn’t take long as a business starts its cyber journey to realise that having a cyber secure supply chain in as important as having strong cyber controls in place at ‘HQ’. Imagine the scenario, you decide to utilise the services of a third party marketing company, or a telesales company, to do a seasonal campaign to boost sales. This isn’t something you do very often, so there has not been a compelling business need to have this facility in house. You hand over your data to this third party and they lose, leak or misplace it, or worse still they get hacked. That’s a breach and you are liable for it…

All it takes is one weak link in your supply chain and you have a cyber breach on your hands.

 

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

How many cars does Uber own in order to maintain its current value of over $60 billion? How many rooms does AirBnB own? The answer to both is zero. In this day and age utilising the skills and equipment of a wider community is cutting-edge business thinking. This crowd source approach, which was spearheaded by KickStarter and then morphed into the sharing economy with Uber and AirBnB, can teach those who are wrestling at the sharp end of cyber security a thing or two.

 

Software has vulnerabilities in it : Bugs; legacy code, shortfalls are all hidden away in there. Why? Because it is still primarily hand written, crafted by individuals and teams who are forever adding new functionality to capture our imagination. All of this software running on your desktop, laptop, mobile or tablet is not finished, not yet. It’s good enough for release and as and when issues are found the software company will issue updates in the form of software patches. This process relies on those bugs being reported, logged, evaluated, verified and then assigned to usually a relatively small team of engineers who will labour to their best of their ability in order to resolve them.

Companies who integrate many different software platforms, from firewalls and virus control to their choice of email service or cloud provider, equally has collective vulnerabilities. Their corporate software ‘footprint’ will be unique to them. A combination of hardware and software that will not be replicated exactly anywhere else. Hence their vulnerabilities will be equally unique. Here again a relatively small team of engineers will be diligently working to maintain uptime on all systems, patching where needed, keeping their own IT monster under control…

There are thousands of highly skilled engineers out there willing to squash bugs and plug security holes – for a price! 

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

Cyber security is decimating businesses globally. Cyber crime is syphoning off billions of Pounds, Euros, Yen and Dollars from their respective economies. Hackers and cyber criminals seem to be impervious to capture and prosecution. Who is to blame for all this?

‘Where there's blame there's a claim’ is a phrase that seems to have entered the public lexicon enabling many to believe that failures in all forms are the fault of others. This includes cyber security. Many business leaders with overall responsibility for cyber security would like to find fault with the software vendors who provided their management information systems, ERP systems, or other major infrastructure elements that continually suffer from security compromises. The sad truth is, the person who is to blame for cyber security, if we need to point the finger, is not the vendors, not your IT team, not your external consultants, not the criminals, not even the current business climate, it’s you.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Many of the scientists, hardware engineers and software specialists that I have met are all hoping that their contributions to the wider progress of technology will make the world a much better, nicer and safer place for us all. Sadly, that hasn’t always been the case as the scientific and engineering endeavours of some individuals, that may have been well meaning at the onset, have had to witness their work being implemented in such a way to cause destruction and death.

The weaponisation of the internet continues as countries around the world develop both defensive and offensive capabilities online. Will this lead to the computing pioneers and fathers of modern computing coming to regret their innovations too? Some sadly have already departed and will never bear witness to how cyber security, cyber defence, cyber war and other activities will develop, but will Bill Gates (Microsoft), John Chambers (Cisco), Larry Page and Sergey Brin (Google) and others look back on their technical legacy with any regret?

In the future how will the computing pioneers of today look back on the role they played in the creation of cyber crime?

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.