Irrespective of how hard you may personally resist it, evolution keeps on – well, evolving! Call it innovation, research and development or just the desire to make things better, evolution in all aspects of technology is happening right now. 

Security continues to evolve. Take the security of your car for example. My first little car had a key, that you popped in the door, turned it and a little peg like structure popped up so you could get in. Once in the drivers seat I’d have to lean over to the passengers side, pull up the corresponding peg and let in the passenger! – remember? It was not the most secure of locks, as a well placed screwdriver, coat hanger, or other applied mechanical device could circumvent it quite easily. Then along came central locking, pop the key in turn it and all the doors opened. Then before I knew it I had remote central locking, press a button on the key fob and the doors unlocked. Now we have keyless entry and I’m sure the evolution of car security will continue to evolve. 

For a few years now there has been an evolution on IT security, that even though it’s free and readily available to most of us, very few are using it. Most people are still on ‘the keys in the locks and watch the peg pop up approach’, by using a single password – that in so many cases is still ‘password’ or ‘abc123’.

As cyber crime in both professional and personal life continues to grow, now would be a very good time to implement two factor authentication.

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

Are you tired of security procedures punctuating even the simplest of tasks? You are not alone. 

Did you go for a run this morning or last night? How about managing to eat your ‘five a day’ yesterday? or drinking at least eight glasses of water and getting the magical eight hours of sleep! Did you do any of those? Don’t worry, I didn’t either. I know that I should do, I know that it can all add up to me living a healthier and happier life but I’m just suffering from fatigue over it all.

We are bombarded with valid advice on an almost continual basis to the point that we just tire of it all. Health, lifestyle, how to bring up children, how to care for the elderly, the economy, where to go (or not to go) on holiday, what to look for in a partner. Google any of those and reams of advice will blind you into a state of tired submission.

And if you suffer fatigue from the barrage of lifestyle advice then quite understandably when somebody starts banging on about cyber security and all the new hoops that you have to jump through at work, just to possibly prevent some nefarious individual from taking a quick look at your Excel spreadsheet, then you might actually be suffering from security fatigue! Yes, it’s a thing!…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Will we one day look back and be pleased that cyber security appeared when it did?

Have you ever been told that “Everything happens for a reason”? I know I have, many times. Usually involving some challenging aspect of my life that has cropped up without warning and now requires a huge amount of effort to resolve.

The theory is that for whatever reason these things were ’meant’ to happen in order to allow future events to unfurl with ease.

Don’t’ worry, I’m not going to get all new age on you here, but having pondered on all aspects of the cyber security world for a considerable time now I have concluded that it’s timing is perfect and in years to come businesses and consumers alike will look back on this period of time when, as the RSA Conference called it last week, ‘Peak Cyber’ occurred.

Just to backtrack slightly, have you ever pondered why the bubble of cyber security has occurred? What caused it? Why has it gone from a slightly niche subject in computer science to front page news in a handful of years? Well despite talking to many, many cyber security experts, specialists, consultants and trainers they’ve not been able to say exactly ‘why’. So, I’ll take my own stab at it…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

How would you react to seeing a major incident occur in real time right in front of your eyes? 

During the summer of 1993 without any prior warning, I was an eyewitness to a plane crash. Two Mig 29 fighters from Russia were performing an aerobatic display at the Royal International Air Tattoo, held at Fairford in Gloucestershire when they collided in mid-air and came tumbling to the ground in massive fireballs.

Miraculously there were no injuries with both pilots ejecting safely. The official investigation determined that pilot error was the cause after one pilot did a reverse loop and disappeared into the clouds, the other one lost sight of his wingman and aborted the routine.

What sticks in my mind most about this event was how seemingly robust technology, technology that less than 5 years previously had been on the Russian side of the Cold War, was reduced to nothing in a matter of seconds by one single flaw. In this case, the flaw was human. Millions of pounds of hardware investment lay in a pile that was no longer of any significant use. I watched as the wreckage was packed up and shipped off to, I assume, a secret location where military grade aircraft accident investigators would forensically analyse this former adversary’s technology.

Fast forward almost quarter of a century and you can actually watch, in real time, the relentless attempts to compromise the flaws in today’s leading edge technology by cyber criminals. For a couple of years now the team at Kaspersky have been running an interactive cyberthreat map that is almost hypnotic in its illustrations of attempted attacks. 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

What advice does a genuine expert give on cybersecurity?

 

When the political history books are written the comment by the former Justice Secretary, Michael Gove given during the Brexit campaign that “Britain has had enough of experts” may just be his professional epitaph.

I disagree with Mr Gove on this point and that when making decisions of great magnitude the wise course of action to take is to assimilate the facts from experts in the particular field of interest in order to arrive at a satisfactory conclusion.

It is however relatively rare that you get to ask such an expert and when the opportunity arises it has to be taken. Fortunately for me such an opportunity arose earlier this week at the Cheltenham Literature Festival. The annual festival brings together a wide variety of authors, some well knowns, others less so into a ten-day smorgasbord of literary themed events. One such event was titled ‘How Big Is Big Brother’ and covered off the topic of how intelligence agencies have to balance surveillance with civil liberties.

Hosted by the philosopher Julian Baggini, the former Chair of the UK Intelligence and Security Committee, Sir Malcolm Rifkind, explained how this fine balance was struck. Having been in the most senior positions of government, including Secretary of State for Defence, he has intimate knowledge of the threats that the UK faced. Obviously I wondered what his view would be on the current threat from cybercrime, cyber terrorism and other cyber related issues. Sadly, I couldn’t ask him during the Q&A session at the event, but did grab a few words with him afterwards,

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

 

Celebrity culture has a striking similarity to cyber security, in that many wish to avoid it, ignore it and hope it will just go away however its natural tenacity somehow always breaks through and permeates into our everyday life. Rather than ignore the celebrity culture a particular ongoing issue may be able to teach us all a valuable lesson with regard to reputational damage caused when sensitive information leaks out into the public consciousness.

 

Putting a price on the damage caused to an organisation's reputation due to a cyber incident, cyber breach, or other compromise is almost incalculable. Talk Talk, who was lasts years UK poster child for cyber-related incidents, has suffered terribly, even though they have been doing their level best to improve their security, build customer confidence and generally try to put the past behind them. Is it working? Not yet, the name Talk Talk and cyber breach are joined at the hip. It seems that there is nothing they can do, just plug away and hopefully over time, probably a long time, their reputation will improve. For Talk Talk it must feel that it would be far easier to ‘unstir’ jam out of rice pudding than to reobtain the public standing they had less than 12 months ago.

If celebrity culture has taught business one lesson, it’s that no matter what you do when a reputation is damaged due to a ‘data breach’ it stays damaged for a long, long time… 

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

Can you feel it? We are just on the cusp of change. The summer is almost done, the children will soon return to school and the business world will crank back up to full speed.

When you look back on your summer of 2016, those couple of weeks you managed to get away from it all, did you manage a quiet jog along the beach or the seafront and tell yourself that cyber security doesn’t really matter. The connection between cyber security and a quiet seaside town may seem unlikely but in fact, it’s quite the opposite.

A few of our seaside towns are the landing points for the vast undersea cables that physically connect the UK to the rest of the world. The internet, with both its good and bad points, just like invaders and settlers of the past, arrive on the beaches. The locations of these cables are, for obvious reasons, kept as secret as possible so there is precious little chance of you tripping over one, or your youngest offspring chopping through these double-armoured cables with an overly energetic use of a plastic bucket and spade combo. 

These cables are an intrinsic part of the UK national infrastructure, which in itself is a collection of assets, facilities, systems and networks that if lost or compromised would have a major detrimental effect of the integrity and delivery of essential services. At some point in the past, a list was drawn up, scenarios were played out, and protection was put in place accordingly. As the internet is now a critical communications and trading network, it is no surprise that this is as important as other infrastructure assets, such as food supply, energy and emergency services… 

Still trying to get the conversation started on cyber security? Then ask the CPNI for advice. 

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

Oh dear, don’t you just hate it? April 1st is almost upon us, so that gives individuals, businesses and the media carte blanche authority to do their best to trick us into thinking something is true when it isn’t. There is a long list of ‘famous’ April fools, from spaghetti growing on trees through to the introduction of ‘smellyvision’. In the past these can be seen as harmless jokes, but what if there was a more sinister motive behind a 21st century Aprils fool regarding cyber security and its heinous sidekick, social engineering.

Cyber security has long been considered a predominantly technical issue. There are vulnerabilities in technology that are taken advantage of by a range of actors and then the technology catches up through implementation of good practise, the application of patches, the mitigation of viruses and then the circle begins again. The human factor is now as important, if not more so than any technical aspects of cyber security. This point has not been lost on cyber criminals who are now using all the social engineering tools they have to find ways to separate individuals from valuable digital information. 

Nobody likes to be hustled, to be conned, to be made a fool of by social engineers. So don’t let it happen…

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.

A mere six months ago you were a small ‘widget’ manufacturer based in the West Midlands. A family business, now in its third generation. The company had provided well for you and your family for as long as you can remember. You prided yourself on your craft and the high quality of your workmanship. Then something changed.

It’s all a bit of a blur now, but you were approached by a major brand in the USA to make a small well-engineered sensor for a forthcoming market changing gadget. You jumped through all the hoops, all the due diligence and then ramped up production to meet this amazing opportunity.

The problem is that as a sub-contractor for ‘that client’ your company has now attracted the attention of others who are determined to learn the details of your design, understand your contract with ‘the client’ and see if in any way you are a weak link in a supply chain that if compromised would embarrass ‘the client’ who is one of the worlds most respected companies. Their determination has paid off, you have been breached and data that was labelled ‘company confidential’ and contained both your intellectual property and that of ‘the client’ is now starting to surface on the dark recesses of the un-Googled web.

It’s time to come clean, it’s time to admit to this failing, it’s time to let those who need to know : know. But who are you going to tell? And exactly what are you going to tell them? Welcome to the world of crisis communications, the prepared public mouthpiece of a cyber breach.

Suffered a cyber attack? Are you ready to face the music?

 

Read the rest over at Cyber Insights, brought to you by the National Cyber Skills Centre.

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs, Click here.

The advice that was prevalent last year, although valid, has been superseded as the harsh realisation of cyber risks finally permeates the boardrooms across the world. I don’t intentionally keep a diary of the advancement of the cyber security industry, like many others I seemingly get carried along on this wave of innovation, technology, regulation and worry. 

As the cyber security market continues to mature, new tools are being recommended to mitigate the losses of cyber crime. 

Read more over at Cyber Insights, brought to you by the National Cyber Skills Centre 

Certes specialise in IT staffing for all sectors and industries. We are now working with the National Cyber Skills Centre in order to provide staffing to companies in need of cyber security. For cyber security jobs Click here.