Sunday, 24 November 2013

Good times in Oslo

So most of last week I was in Olso, Norway and without my mittens. Ok I really need to let go of this mitten thing. I don't even own any. I just like the sound of the word...mmmiiittens, hmmm anyway I digress.

I finally met Kai and his business partner Lars who is also a thoroughly nice chap. The evening I landed we all went out for a meal. We talked about security culture and the work The Roer Group is doing around this, specifically the Security Culture Framework.

On the day of my presentation I was speaking after Martin Mckeay who works for Akamai as a Security Evangelist. I've been following his blog and pod casts for a number of years now so I was a little nervous. However, when my time came I felt at ease and I was good to go.

After my BSides talk I knew I could flesh that presentation out for another audience and still make it something that people would be able to relate to and hopefully take something away from. I managed to get through the thirty minutes fairly well and drew a few laughs which is always good as well as answer a couple of questions. Me being me as soon as I sat down I began to think about my delivery, the content and how I could have been better. Kai and Martin gave me some good feedback which I'm very appreciative of.

The evening concluded with a nice meal and awesome company thank you to Akamai for picking up the bill for my meal :)

I saw a little bit of Oslo, made some new friends and managed to survive a thirty minute presentation, I think there's more to come...actually I'm speaking at the OWASP Birmingham Chapter meeting in December...time to practice the brummy accent ;)

Thank you to Kai and Lars for being lovely hosts and to the rest of the people I met over the three days.

I'll be back!

Link to the video here Courtesy of Kai Productions

Tuesday, 5 November 2013

Off to Oslo!


Although I had planned to submit to a CFP somewhere (namely, to the full track at BSides London for 2014) after my BSides London Rookie Track talk, I hadn't anticipated on getting invited to speak at an event. So I was quite flattered when Kai Roer (@kairoer / roer.com) asked me if I'd like to speak at the Cloud Security Alliance annual chapter meeting in Oslo.

I shall be donning my mittens and flying out in a couple of weeks to do an extended and revised version of my BSides talk.

I'll be talking about my Teaching English as a Foreign Language (TEFL) experience and how I brought this in to InfoSec.

Once I've thawed out I shall post an update here.

Saturday, 3 August 2013

Infosec’s Rising Stars and Hidden Gems

Somehow I made it onto Tripwire's list of rising stars and hidden gems! I'll take gem over star any day!  It was quite flattering to find out I was on this list.

I did have to ask them to edit it as I'm more of an educator than hacker.

Thank you Tripwire!

Sunday, 28 April 2013

BSides London 2013 - The Rookie Track

Well the day has come and gone and this is my Rookie Track review and BSides London 2013 experience…

It wasn’t long after I’d registered that Robin (@digininja) introduced (over email) me to my mentor Mike (@clappymonkey). At first, I was a bit apprehensive. What with Mike in Birmingham and me in London town I thought to myself, how is this going to work?

As I had gone into the process with an open mind it turned out better than I had expected. We had regular phone chats and as the day approached we went through a number of dry runs, which really helped. On one occasion he told me that my slides should be “shiny” and I thought “eh, you what?” He explained that I should try and tell a story with pictures and have less bullet points - and then I got it. 

So I made it my mission to have the least amount of text on my slides and also to not have any cue cards. I ended up with only pictures as my slides which I used to drive the story from my fragile little rookie mind ;)

Through Twitter, I also got offers of advice from Michael (@catalyst) and Kai (@kairoer) both of which gave me some good advice during interesting Skype chats.

As the day drew closer I found out that Mike couldn’t make it to BSides, I was looking forward to meeting him for the first time and even promised him a few drinks – this will happen, only a little later :) 

Arron Finnon (@f1nux) asked me if I wanted a stand in mentor on the day, someone to be a friendly face and I said sure why not.  I was introduced to Wendy Nather (@451Wendy) and though our little Skype chat was fractured by wireless woes I was looking forward to meeting her. 

Wednesday turned out to be a gorgeous day in London so I skipped to the venue…ok well I didn’t quite skip…oh you know what I mean ;) When I got to there I picked up my speaker badge, hooked up with Ian Williams (@fishermansenemy) Mike’s colleague and Wendy. I also found and introduced myself to @f1nux who kindly directed me to the Rookie Track room.


So now I had two friendly and helpful people, the rookie room was a nice size and the slides were there – I was good to go!

Until my time to talk came I watched David Rook’s (@securityninja) talk which was laid out in comic book style and he even had printed copies of the talk. I was lucky enough to get a signed copy of the comic book with ninja kisses! lol. I have to thank Wendy for that :)



Then there was the multiple award winning Javvad Malik (@J4vv4d) with his talk, even with a couple of musical mishaps he was awesome.



During the rest of the morning I checked out my fellow rookies’ talks which were damn good, caught up with some ex work colleagues, interrupted Brian Honan (@BrianHonan) during his lunch to introduce myself and mingled.

After lunch I spoke to Mike and he wished me good luck and gave me a few pre talk tips and before I knew it my time was up!

It was 15:15 gulp! I stepped up to the front of the room and began to speak…and woosh the fifteen minutes had flown by, it had gone surprisingly quick. Many thanks to Ian for my five minute marker and to Arron with his iPhone stopwatch :)

There were a few nerves but overall I think I performed well. I felt like I kept the room engaged, managed to get a couple of laughs and even fielded a couple of questions at the end. One of which was taken outside  – for the life of me I can’t recall the name of the gent that I spoke to, dude if you’re reading this get in touch – I’ll blame it on Rookie Amnesia. 

Wendy smiled, Ian smiled and even Javvad said well done. I also got a big positive reaction from Frank Morris (@frankmorris) thanks for that sir :)

The title of my presentation was Information Security Awareness: Making your staff the strongest link. I explained how I’ve used the experience gained during my time in Spain teaching English as a foreign language in my information security career

Post my talk I spoke to Mike, to give him the lowdown on how it went. He was pleased for me and happy that I didn’t, as I had termed it end up in Rookie Rehab. 

I finished the day off by checking out the last few Rookie Talks, mingling and had a really cool chat with David Rook (@securityninja) As the day drew to a close I really didn’t want to be carrying my laptop around and seeing as I live in London, I scooted home to drop it off.  Then it was time for the after party at the Archangel – Big thanks to MWR!

There I met up with, Ian Williams (@fishermansenemy) and Frank Morris (@frankmorris) for some drinks. To be honest I was cream crackered so wasn’t there for too long. 

On the way to the station I caught up with the lovely Iggy (@GeekChickUK) both heading the same way we had a cool chat about BSides, the Rookie Track and Infosec.

So that’s my Rookie Track review and BSides London 2013 experience. I hope I haven’t missed anyone out. If so, shout :) 

A lot of hard work goes in to organising a day like that, so as someone who hadn’t been to a real conference before, I really appreciate the effort. Especially those who organised the Rookie Track.

If you’ve never presented at a conference before, this is the PERFECT environment – do it!

I’m already looking forward to 2014 :)

Tuesday, 15 January 2013

Continual Self Enhancement

I have always had the motto continual self enhancement it is to this end that along side my book idea I've added a couple of certifications to my skill set namely, the ISO27001 Lead Auditor certification and the Advanced Professional Certificate in Investigative Practice.  The Lead Auditor course was to complement my existing experience around the ISO27001 standard.

With regards to the APCIP course, well that was to gain an understanding of the basics of the law when working on investigations.  I've been involved in investigations where there wasn't a tried and trusted process and it always made me think, what if the evidence we present is challenged, would it stand up in court?

The course has the following compulsory modules:

  • Law, Evidence, Procedure and Best Practice
  • Advanced Statement/Report Writing
  • Witness Familiarisation

As optional modules I chose the below: 
  • DPA
  • RIPA
  • Securing Electronic Evidence 
I found it to be enjoyable and very valuable.