Sunday, 3 August 2014

Popping the Bubble

Are you living in a bubble?

Now you’re thinking “Bubble?  You what…”

Let me explain.  My experience is that a lot of the time we security types - yes, you and me - don’t actually know what the rest of the departments within the business actually do on a day-to-day basis.  We know they exist and what their purpose is but we don’t appreciate their pain points.  We’ve all heard, way too many times, the quotation from Sun Tzu’s “The Art of War”: “If you know the enemy and know yourself you need not fear the results of a hundred battles.”

I would argue that a lot of us don’t know our own organisation as well as we should, let alone the enemy.

If we consider a typical enterprise organisation it will have departments such as HR, legal, sales, PR, marketing, accounts, IT and many others.  These all have their own objectives, their own stresses and strains and targets to meet – essentially they are in their own little bubble trying to do the best they can with what they have and more often than not information security is the last thing on their minds.

However, it is our job to help elevate their understanding of what we do and, most importantly, how we can help them to work more securely.

So if we are all in our own little bubbles, how can information security departments be effective for their businesses?   As far as I’m concerned, if you work in this field and you don’t step out of your bubble from time to time you won’t be effective in the least and when I talk about effectiveness I mean helping to create a positive and lasting change, that is,  building a strong and permanent culture of security within your organisation.

Yes, you may review third parties, you may assess project risks, get involved with pen tests and attend to incidents - but do you use these experiences to move towards building a more security-conscious work force?  I guess that most of you do not.  In truth, I don’t think most security departments are actually all that effective.  They exist to serve compliance or some other tick-box exercise.  It’s a case of we do our jobs and then we go home.  There’s nothing wrong with that if all we are interested in is hanging onto our jobs but if we actually want to be effective, I mean if we want to change behaviour then we need to change the way we approach our work or else we’ll keep going round in circles forever.

(Maybe, though, we don’t really want to change anything and deep down we think, “what difference does it make to me, ah none really…” Cynical?  Or just a little too near the truth?)In fact, effectiveness isn’t all that difficult.  It means occasionally stepping out of your bubble and making an effort to appreciate the needs and wants of the business you work for.  You need to listen, learn and adapt to what the business actually does on a daily basis. If you can do that, you can then begin to see new ways of working together with your colleagues, understand their difficulties, foresee problems looming ahead and do something to prevent them happening.  

Here’s a few bubble-destroying suggestions.  You might have thought of some of these practices already but if not, why not try them and see what they do for your effectiveness within your organisation?

  • Create a brand for your information security team or department.  Be creative, ask the marketing and PR teams for a little help
  • You should be seen and you should be known outside your own immediate circle.  When was the last time you stood up to give an information security briefing to the business? When was the last time you actually walked around to different teams just to introduce yourself and have a little chat?  Little chats can open the doors to really worthwhile exchanges of information.  Never think of a little chat as mere gossip or a waste of time
  • Have a mission statement.  Look at the corporate mission statement and align yours to that. You could even come up with a snappy slogan.  Whatever it is, it will make you more approachable and approachability is the first step towards increasing your effectiveness within your organisation

To conclude, I would argue that if you’re a CISO/CSO/Head of Information Security or whatever senior security position you hold, building security culture should be your strategy.

So, don’t float - stand up and pop your bubble.


This article was published on Information Security Buzz - You can find it  here

Sunday, 6 July 2014

Look at What I Learnt in Class

The below is my first contribution to The Analogies Project started by Bruce Hallas. When he asked to me contribute I couldn't say no. You can also find it here on the analogies page
One of the best pieces of work experience I've ever had wasn't in IT or information security, in fact, it was Teaching English as a Foreign Language (TEFL) in Spain.
Let me tell you a little story…
Once-upon-a-time I was looking for a bit of a challenge, something different, and something not in the IT field. So I applied for a course that prepared you for becoming a TEFL teacher based in Spain. I passed and was subsequently offered a job with the college based in a small city called Zamora in the North West of Spain.
My job was to create and teach lessons using the course text for juniors, seniors and adults. At first I was a little apprehensive but then I thought to myself this will be easy, I have the text book and I’ll create lessons using the guidance provided on the TEFL course.
What could go wrong?
My first few classes were with the juniors and…well…erm…let’s just say they were no fun!
No one listened, no one paid attention and most importantly no one actually learnt anything.
Why?
I played it wrong. I went in with the attitude that I was the teacher and that I was right. That my lessons were engaging and that they should listen to me.
After a couple of classes and a lot of mockery from the students (I am now well versed in Spanish profanity) I realised that something needed to change. It was me, I needed to change. I had to change the way I was doing things in order for me to get any results. So what did I do? Well…

  • I took salient points from the text book and then I ditched it.
  • I began to chat with the students during the breaks asking them about
  • their likes/dislikes, hobbies, favourite sports etc.
  • I played football with the guys and talked about fashion with the girls
  • I moved the class room desks around so that the atmosphere was less formal
  • I had competitions e.g. guy vs girls

All of the above changed the dynamics of the class and after a few lessons they warmed to me. They listened to what I had to say, began to interact in class, made suggestions on future lessons and even began to ask if we could go over certain topics again. From then on I taught in the same manner and style across all the age ranges with the same results – I managed to get them engaged!
Comments like “your lessons are fun”, “you’re the best teacher” and “please don’t leave” were very flattering but all I had done was to take a different perspective and see things from their point-of-view. My job was then to look at the best way to get them on board.
Essentially, I changed my behaviour to change theirs.
The skills and experience I picked up during my time in Spain I now use in information security. As professionals in this field we need to take the time to understand people, notice the different personalities and the overall picture of the environment, in essence – the organisational culture.

Sunday, 4 May 2014

I have an air conditioned room with leather seats...

Who was I kidding the Tube strike wasn't going to be cancelled! I woke up grumbling like Muttley and made my way across London town.

Once I'd picked up my pass I headed upstairs and although I'd seen the Council Chamber the day before (aka swag bag pack day) when I walked in on Tuesday I was a bit worried. Such a cool room shouldn't really be bereft of people. With the Lightning Track being an on-the-day event it could have ended badly.


However, the four of us; Anne Wood (@fairycakepixie), Glyn Wintle (@glynwintle) and Diarmaid McManus (@hacors) with lots of wrangling and using the line:


..."you see I have an air conditioned room with leather seats" ...managed to keep the room respectably full. Thanks to Glyn for suggesting that line :)


We had talks from Arron Finnon (@f1nux), Matt Summers (@dive_monkey) and at 2pm we had the Women in Security (@womeninsecurity) panel at which @treyford was kind enough to get involved.





We even had an underground talk, a talk about locking picking and one from Kevin Breen (@kevthehermit) on extracting IOC's from RAT's.

The final talk was given by Paul Batson (@lazysecurity) who still had the energy to get up and deliver a talk, kudos!



At the end of the day (when I actually remembered) the lightning shortbread biccies flew out of my hands! After the clean up we all headed to the MWR after party, where a much needed drink was had by all. Thank you MWR.

Being part of the crew you don't really get to see any of the talks but what you do get is a sense of achievement. That you participated. That you helped to make it happen.

The other part of the event is catching up with people you've met before and actually meeting those you've been conversing with virtually - To those I met for the first time, it was a pleasure :)

Massive thanks to Paul (@lazysecurity) and Thomas (@fvt) for being tireless in making the event a success and to all my fellow crew members.

I'm already looking forward to BSides London 2015!







Thursday, 17 April 2014

Bring The Lightning!

Logo by Kev McGuinness (socks84)
It's back!

BSides London is back and this year along with a couple of ex-rookie speakers from 2013 - Anne Wood (@fairycakepixie) and Diarmaid McManus (@hacors) as well as Glyn Wintle (@glynwintle) I'm running the Lightning Track.

What's the Lightning Track you ask? Well it's the unscheduled track - No CfP and no pre-registration. So if you didn't make it through the CfP process, didn't register for the Rookie Track or were just too damn lazy ;) You still have a chance to talk.

Talks can be up to a maximum of 20 minutes and can be about any security or industry relevant topic. This could be projects, personal interests, hacks, ideas or opinion pieces. There are no limitations on the subject matter or content of these talks.


In addition to the lightning talks there will also be Underground Talks. These are intimate lightning talks where people can discuss investigations, findings or things that they may not wish to disclose in a public forum. They will be run in the Lightning Track room. However, access will be controlled and they will follow the Chatham House Rule.

At 14:00 we have a Women in Security (@womeninsecurity) discussion panel. Berta Papp (@bertapapp) will be moderating on individual approaches to professional development for (not just) Women in IT Security. 

The panel line up is:


Raj Patel, UK Operations Security Manager, SocGen
Ioana Tugui, Security Consultant at BAE Systems Applied Intelligence
Ahmed Bengrina, IT Operational Risk & Security Coordinator at SocGen

The Lightning Track is situated in the rather grand Council Chamber and we are lucky to be in there, check out the pics!

So now you know what's happening, where it's happening. How do you get to present? Well when you pick up a swag bag in the morning you'll notice our flyer in there. Fill in the details, tear of the strip and bring it along to the Council Chamber and you'll be added to the list. Simples.

A few of you have said you might be interested. If I don't see your name down to do a talk. I will look for you, I WILL find you and...I..hmm...damn I forgot.

P.S - There will be lightning shaped shortbread biscuits. Made by my own fair hands, they won't be laced with anything. Honest.

Seriously though, as we are an unscheduled track, do come along and take part or else we'll be twiddling our thumbs in a lovely room all on our own.

There's just one more thing....

Bring the lightning!

Sunday, 13 April 2014

Information Security Buzz Article

My first article for InformationSecurityBuzz was published in February. I'm planning my next one and will try and get one out every month, hopefully, maybe ;)

Entitled - From Rookie Speaker To Mentor To Track Organiser – My BSides Journey. Check it out here

Saturday, 4 January 2014

Goodbye 2013 hello 2014

At the beginning of a New Year I usually set myself some goals, If I reach these goals then I reward myself. If I don't reach them well then no goodies for me. This harks back to when I was a child...discipline ruled. Naturally, I didn't like it at the time but in most things there's always some good that one can extract.

The main goal I had for 2013 was to speak at BSides London on the Rookie Track, achievement unlocked! This led on to me being invited out to Oslo by Kai Roer (@kairoer) to speak at the CSA Annual chapter meeting. More info on these below.

Somewhere along the line I noticed I had been included on Tripwire's Infosec's Rising Stars and Hidden Gems series. God only knows how I ended up on there but flattering nonetheless. Cheers to Anthony Freed (@anthonymfreed) at Tripwire.

To my surprise in December Information Security Buzz contacted me via Twitter and asked if I'd like to write for them, so as of January 2014 I shall be a contributing blogger.

If anyone is actually reading this ramble you're probably thinking "so what's the goal for 2014 Mo"...to that I say ask me ;)


All in all 2013 hasn't been too bad a year, I'm looking forward to 2014!

Thank you to all who gave feedback, mentored and inspired.

Mo.