“Why don’t you ever learn!”, would be a familiar phrase to me as a child as I could never resist the temptation to touch wet paint just to see if it was wet or not. Of course it was wet, but why didn’t I believe it? Every time I’d touch it I’d get a small dot of white gloss on my index finger and then feel bad that I continued to ignore warnings about it being wet.

I’d have to get a bit of paint thinners, turpentine or some other chemical that I really don’t think was doing my skin much good in order to remove this visible symbol of my continuing lack of judgment. Now many decades on have I learned my lesson? Yes, but only just. Even now the temptation to ignore wet paint warnings is very strong.

In another generations time we may collectively have learned our lesson, not in the touching of wet paint, but with cyber security. If you are working at the sharp end of IT it’s unlikely that you get a chance to look back at what has come before and learn from it. IT is mainly about the next upgrade, the next technology, improving speed and efficiency, it is not an industry that is known for much reflective consideration. 

Have we learned our lessons from cyber security? Maybe not as well as we should have done.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

You are more likely to be attacked from the inside by ‘one of your own’ than you are by a distant faceless cyber criminal.

 

In a far-off land, huddled behind a back of glowing computer monitors, there is a criminal gang planning its next great cyber attack. We can only imagine what their ultimate aim is but it’s safe to conclude that money will be a motivating factor.

If the headlines are to be believed then at any moment and without any warning they will strike – ninja like – and your years of hard work building your small business, or progression up the corporate ladder will be undone. But is that reality?

While it’s true that wide-ranging phishing attacks and ransomware are affecting many, there is a far greater chance that a business will suffer an attack from the inside. It’s more likely to be ‘Bob’ from down the corridor then some sophisticated code warrior who can break encryption technologies with nothing no more than a notepad and their overly developed intellect.

The ‘Cyber Insider’, or the ‘Insider Threat’ as it also gets referred to is someone who (knowingly or unknowingly) misuses legitimate access to commit a malicious act or damage their employer. The most notorious of this breed is Edward Snowden who famously copied and leaked classified information from the National Security Agency (NSA) in 2013 without prior authorisation. His motivation was that of a political stance, as he wished to expose wide scale surveillance programs that were being undertaken at the time.

So, what would motivate an ‘insider’ within your business or organisation to commit a cyber crime?

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

The Government has just passed legislation to store twelve months worth of your online activity. 

Look I know you are busy, no doubt knee-deep in tinsel, wrapping paper, food preparation and all the other festive delights that go into making the holiday season work. I’m also aware that by any measure it’s been a heck of a year, so many things have changed, so many things that were unthinkable just twelve short months ago are now a stark reality.

With all of that going on you could be excused for not noticing that the government passed a bill at the end of last month allowing them to keep an eye on and store all your electronic communications, just to make sure that you are not up to anything naughty. I’m guessing you’ve put down that tinsel now as that can come as quite a surprise.

By any stretch of the imagination the Investigatory Powers Act 2016, to give it its full title, has not really hit the headlines in a way that it may have done in the past, as other more colourful news has ensured that its has been relatively buried. You may have heard it mentioned in passing by its stage name of ‘The Snoopers Charter’.

What this law means is that Internet service providers and mobile phone companies are to maintain records of each user’s internet browsing activity (including social media), email correspondence, voice calls, internet gaming, and mobile phone messaging services and store the records for 12 months. Yes, folks 12 months of your online activity from any device, on any communications platform is going to be stored and should it be deemed necessary looked at by ‘the powers that be’. That Twitter rant at 3am in the morning – yep, that will be kept. Those vicious texts you have sent off to somebody you feel has wronged you, or disagreed with – stored safely for posterity. How about those embarrassing social media photos taken on a company away day – yep, kept for viewing on a rainy afternoon if required…

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Cyber security challenges could benefit from an utterly immovable deadline.

How are you with deadlines? Do you meet them head on each and every time, or do issues get in your way, from poor project management, lack of skills or that old bug bear procrastination? Every industry has seen major projects slip, cost overruns, products coming to market months, even years after they were originally promised. It seems that deadlines, even those that were set with the best intention, are flexible.

But what if they were not? What if the deadline for your next major IT project had an immovable date, set in stone, that no individual, company, government or deity could move? Could the collective skills, experience and determination of the IT industry hit it? Yes, it could and it has done in the past. When? Just over 17 years ago.

The Millennium Bug, or Y2K as was also called, threatened global computing systems due to a shortfall in the way it stored dates. Older computer systems stored dates as two-digit numbers instead of the four digits needed to properly represent years. This meant that they would treat the year ’00’ as coming before ’99’, then as the millennium dawned computer systems may think they were in 1900, not 2000 and would potentially crash, or at the very minimum act abnormally…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Will we one day look back and be pleased that cyber security appeared when it did?

Have you ever been told that “Everything happens for a reason”? I know I have, many times. Usually involving some challenging aspect of my life that has cropped up without warning and now requires a huge amount of effort to resolve.

The theory is that for whatever reason these things were ’meant’ to happen in order to allow future events to unfurl with ease.

Don’t’ worry, I’m not going to get all new age on you here, but having pondered on all aspects of the cyber security world for a considerable time now I have concluded that it’s timing is perfect and in years to come businesses and consumers alike will look back on this period of time when, as the RSA Conference called it last week, ‘Peak Cyber’ occurred.

Just to backtrack slightly, have you ever pondered why the bubble of cyber security has occurred? What caused it? Why has it gone from a slightly niche subject in computer science to front page news in a handful of years? Well despite talking to many, many cyber security experts, specialists, consultants and trainers they’ve not been able to say exactly ‘why’. So, I’ll take my own stab at it…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Many of the scientists, hardware engineers and software specialists that I have met are all hoping that their contributions to the wider progress of technology will make the world a much better, nicer and safer place for us all. Sadly, that hasn’t always been the case as the scientific and engineering endeavours of some individuals, that may have been well meaning at the onset, have had to witness their work being implemented in such a way to cause destruction and death.

The weaponisation of the internet continues as countries around the world develop both defensive and offensive capabilities online. Will this lead to the computing pioneers and fathers of modern computing coming to regret their innovations too? Some sadly have already departed and will never bear witness to how cyber security, cyber defence, cyber war and other activities will develop, but will Bill Gates (Microsoft), John Chambers (Cisco), Larry Page and Sergey Brin (Google) and others look back on their technical legacy with any regret?

In the future how will the computing pioneers of today look back on the role they played in the creation of cyber crime?

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

How would you react to seeing a major incident occur in real time right in front of your eyes? 

During the summer of 1993 without any prior warning, I was an eyewitness to a plane crash. Two Mig 29 fighters from Russia were performing an aerobatic display at the Royal International Air Tattoo, held at Fairford in Gloucestershire when they collided in mid-air and came tumbling to the ground in massive fireballs.

Miraculously there were no injuries with both pilots ejecting safely. The official investigation determined that pilot error was the cause after one pilot did a reverse loop and disappeared into the clouds, the other one lost sight of his wingman and aborted the routine.

What sticks in my mind most about this event was how seemingly robust technology, technology that less than 5 years previously had been on the Russian side of the Cold War, was reduced to nothing in a matter of seconds by one single flaw. In this case, the flaw was human. Millions of pounds of hardware investment lay in a pile that was no longer of any significant use. I watched as the wreckage was packed up and shipped off to, I assume, a secret location where military grade aircraft accident investigators would forensically analyse this former adversary’s technology.

Fast forward almost quarter of a century and you can actually watch, in real time, the relentless attempts to compromise the flaws in today’s leading edge technology by cyber criminals. For a couple of years now the team at Kaspersky have been running an interactive cyberthreat map that is almost hypnotic in its illustrations of attempted attacks. 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Accidents can happen, but we need to learn from them.

Despite all the technological advancements of the last few centuries the scientists and engineers of this world have yet to crack the ‘if only I could turn back time by 30 seconds’ that is often needed once you have incorrectly addressed an email.

If that technology had been available, then the National Health Service (NHS) staff member who this week inadvertently sent an email to all 840,000 staff members would have been its biggest fan. As members of NHS staff then “replied to all” they further exacerbated the issue and the email system quickly ground to a halt after no doubt frustrating tens of thousands of hard working individuals in the process.

Any organisation that has a global staff email list that can be accessed by anybody, even accidentally, needs to swiftly review its email usage policies. As a former IT Manager, I often witnessed how such lists were wildly used for the most menial of messages; lost umbrellas, missing office furniture, requests for lifts to and from work, clogged up the Inboxes of everyone. When such messages are sent out to thousands of people, who in turn open and read them, the sheer loss of productivity is a compelling argument enough to apply some restrictive managerial guidelines. Used accidentally, it just cries out that there is a most basic lack of IT awareness within an organisation…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

What effect would the UK leaving the European Union have on cyber security? 

By the end of the year will the United Kingdom of Great Britain and Northern Ireland still be a member of the European Union? David Cameron has been performing a charm offensive, coupled with good old fashioned diplomacy and negotiation in order to develop a refreshed relationship with our continental cousins. Will it work? Will there be a referendum in June? Will we be ‘in’ or ‘out’?

As both the ‘yes’ and ‘no’ camps of this decision, start to develop their communication plans in order to win our vote, will any of them consider what effect our future relationship with Europe may (or may not) have on cyber security. 

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

Cyber security is decimating businesses globally. Cyber crime is syphoning off billions of Pounds, Euros, Yen and Dollars from their respective economies. Hackers and cyber criminals seem to be impervious to capture and prosecution. Who is to blame for all this?

‘Where there's blame there's a claim’ is a phrase that seems to have entered the public lexicon enabling many to believe that failures in all forms are the fault of others. This includes cyber security. Many business leaders with overall responsibility for cyber security would like to find fault with the software vendors who provided their management information systems, ERP systems, or other major infrastructure elements that continually suffer from security compromises. The sad truth is, the person who is to blame for cyber security, if we need to point the finger, is not the vendors, not your IT team, not your external consultants, not the criminals, not even the current business climate, it’s you.

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.