Last week I presented my "Popping the Bubble" talk at Steel Con - The North's Premier Hacker Con - https://www.steelcon.info/ - I think it went down quite well and there was some spirited discussion after the talk.
Robin (@digininja) and the crew put on a great conference at an amazing price of only £20 - The goodie bag really does have some goodies in it!
One thing that Steel Con does differently to other conferences is that they encourage children to come along as they have a specific "Kids Track". This is a great initiative especially when you see youngsters having fun learning to code, building robots and even making music with vegetables!
I'm looking forward to Steel Con 2016!
A personal information security engagement, awareness, behaviour and culture blog. Opinions are mine and mine alone - Soon to be revamped!
Sunday, 12 July 2015
Sunday, 28 June 2015
The Security Culture Conference 2015
So the Security Culture conference happened! On an Island…no really…it was on an island…look…
The journey there took about twenty minutes via a ferry and a small boat to get to the island called Lille Herbern. The venue was actually a restaurant – the only one on the island.
The day began with Roar Thon’s key note – He explored what security culture is and what makes it an important tool for organizations. Roar is the Specialist Director at the Norwegian National Security Authority – You can find him on Twitter as: @secdefence
Next up we had Wolfgang Goerlich – He looked at how to apply the Security Culture Framework to a software development team. I think Wolf was about to get he’s Bollywood groove on there. Wolfgang is a Cyber Security Strategist at CBI Inc, his Twitter handle is: @jwgoerlich
The second half of the morning we saw Kai explaining how you can build and maintain a security cutlure using the framework. He’s Twitter handle is: @kairoer
The final talk before lunch was by Waldo Rocha Flores who works for Ernst & Young. He’s work has a lot to do with measuring the behavioural outcomes of security culture. Waldo also held a workshop after lunch. I couldn’t find him on Twitter.
Then it was time for lunch – yum!
Some lunch time conversations and networking…
Waldo’s workshop discussions – after lunch Waldo held a workshop which delved deeper in to his talk.
After the workshop we stretched our legs and got ready for the final part of the day with Shan Lee Head of Information Security for Just Eat. Shan told us about his security culture story at Just Eat, he gave us great insight into what it’s like to build a security within a dynamic company. You can find Shan on Twitter as: @secwaza
Turns out I was last on the list to present, I don’t like being last. Especially when you’re preceded by such quality. I spoke about how you can pop your bubble in the corporate environment. I’m on Twitter as: @infosecmo
With the talks over and everybody ready to chill we headed back to the boat and on to the post conference dinner party – much fun was had here.
I was going write a long post but then I went through the pictures from the day and I think they explain it all. The first Security Culture Conference had speakers with real experience and insight and I think everyone took something useful away at the end. Yes there were a few niggles but no conference out there is ever without those – it’s how you handle things that matters. It was a small and intimate affair with great conversation and a stunning setting.
Thank you to Kai, Eli, Kristina and Lars for making us all feel welcome.
See you all at the next one…I wonder where that will be?
The journey there took about twenty minutes via a ferry and a small boat to get to the island called Lille Herbern. The venue was actually a restaurant – the only one on the island.
The day began with Roar Thon’s key note – He explored what security culture is and what makes it an important tool for organizations. Roar is the Specialist Director at the Norwegian National Security Authority – You can find him on Twitter as: @secdefence
Next up we had Wolfgang Goerlich – He looked at how to apply the Security Culture Framework to a software development team. I think Wolf was about to get he’s Bollywood groove on there. Wolfgang is a Cyber Security Strategist at CBI Inc, his Twitter handle is: @jwgoerlich
The second half of the morning we saw Kai explaining how you can build and maintain a security cutlure using the framework. He’s Twitter handle is: @kairoer
The final talk before lunch was by Waldo Rocha Flores who works for Ernst & Young. He’s work has a lot to do with measuring the behavioural outcomes of security culture. Waldo also held a workshop after lunch. I couldn’t find him on Twitter.
Then it was time for lunch – yum!
Some lunch time conversations and networking…
Waldo’s workshop discussions – after lunch Waldo held a workshop which delved deeper in to his talk.
After the workshop we stretched our legs and got ready for the final part of the day with Shan Lee Head of Information Security for Just Eat. Shan told us about his security culture story at Just Eat, he gave us great insight into what it’s like to build a security within a dynamic company. You can find Shan on Twitter as: @secwaza
Turns out I was last on the list to present, I don’t like being last. Especially when you’re preceded by such quality. I spoke about how you can pop your bubble in the corporate environment. I’m on Twitter as: @infosecmo
With the talks over and everybody ready to chill we headed back to the boat and on to the post conference dinner party – much fun was had here.
I was going write a long post but then I went through the pictures from the day and I think they explain it all. The first Security Culture Conference had speakers with real experience and insight and I think everyone took something useful away at the end. Yes there were a few niggles but no conference out there is ever without those – it’s how you handle things that matters. It was a small and intimate affair with great conversation and a stunning setting.
Thank you to Kai, Eli, Kristina and Lars for making us all feel welcome.
See you all at the next one…I wonder where that will be?
Saturday, 9 May 2015
Book - Build a Security Culture
My good friend Kai Roer has written an easy to digest book on security culture. Anyone who has been in security for a while will know of Kai and his work on security awareness and culture.
He was very kind give me a mention in the book, cheers Kai!
It's a short and accessible book and you can find it here on Amazon.
He was very kind give me a mention in the book, cheers Kai!
It's a short and accessible book and you can find it here on Amazon.
Thursday, 30 April 2015
Phishy cyber-criminals 'go corporate' with social engineering
Saturday, 28 February 2015
Tools Don't Change Behaviour People Do
What makes an
information security awareness programme effective? As in most cases the answer
is “it depends”.
Let me elaborate; if
your goal is simply to obtain that magic compliance tick then maybe you’ll use some
form of computer based training (CBT) coupled with some quizzes and possibly a
few videos on your intranet page and bingo you’ve ticked the box! As an
industry we are still heavily reliant on tools or packages to train or educate
staff and make them security aware. However, these are rarely used within a
defined and structured manner. Don’t get me wrong CBT’s, quizzes and videos are
great tools but they should be used as part of your programme, not be the
entirety of it. Actually, I don’t believe most environments need to train or
educate their staff on security issues – I think that’s outdated approach. What
they need to do is elevate their current level of security awareness to foster
a more security conscience approach to their work and ultimately work toward
building security culture.
Changing behaviours and
building security culture is only possible when you understand and appreciate
your existing organisational culture, look at how the different personalities
within your organisation work and use a structured and measured approach and
building security culture is no exception. Below are a few points that I think
are important when you're seeking to influence and affect change:
Buy-in - It's
become such a cliché because it's true. You need “the trust from the top” Yes
it's about the funds but more importantly it's about the support, the belief
that it will make a difference and that ultimately it's about enabling the
business.
Understand and respect your
current organisational culture -
If
you step back and think about the different departments in your business, the
tone management sets, the different roles and responsibilities, you'll see the
different personalities that exist. The key is to appreciate the daily
activities that go on, what their key motivations are, what they need to
deliver, and what their objectives are. When you appreciate this you can then
look at how best to tailor security messages for them.
Know where you want to get
to - Look at your current level of
security consciousness and think about what's ideal for your environment not anyone else but yours. Define and set achievable
goals, use campaigns that you can use as measures of success and target them at
a particular department. Ultimately your campaigns can become your programme. A
small campaign is easily structured, managed and measured and when that’s a
success at you can replicate across different departments
Involve the right people
- Odds are that you already have the majority of skills and experience you need
in your organisation it's just a case of building relationships, being transparent
about your objectives and working together. Seek assistance from departments
such as HR, Marketing, PR and Legal these are departments that can help package
your activities in line with corporate standards.
Prepare, plan, execute,
review and repeat - If you already run projects and maybe
even programmes you've already got the skills there to utilise and work with.
Odd's are that you already have a security improvement plan of some sort or
something similar is about to be launched, it's a great place to start aligning
these activities with that
Understanding that it's an
ongoing programme of work - When you're building security
culture in your organisation be appreciative of the fact that it needs to be a
dynamic activity, it should adapt to business and staff needs. If you use the
ITIL framework you'll know about Continual Service Improvement think of this
activity in the same manner – Continual Security Culture Improvement.
In essence what I’ve described above is the Security Culture Framework it’s been developed by Kai Roer of The Roer Group. It’s an open framework that consists of four elements namely; metrics, organisation, topics and planner you can find out more about it here - https://scf.roer.com/
A company that has been
using the Security Culture Framework as part of their awareness activities is
Just East. I caught up with their Head of Information Security, Shan Lee at
44Con and we got chatting about awareness, changing behaviour and security
culture here's what he had to say:
“You absolutely have to tailor any program not only for your
organisation, but for parts of the organisation. What works at JUST EAT
probably wouldn’t work in a bank, and I don’t speak the same language to our
developers that I do to our call centre agents or finance people.
A
central theme with a strong message is essential, but it has to be varied
according to the target audience, and that theme must be consistently and
constantly reinforced through the widest range of media that you can
efficiently manage.
Divide
the program into manageable chunks, put a clear objective around what each
chunk is trying to achieve and find a way to measure its success. You’ll soon
know what’s working and what isn’t, then its rinse and repeat.
“
Sunday, 3 August 2014
Popping the Bubble
Are you living in a bubble?
Now you’re thinking “Bubble? You what…”
Let me explain. My experience is that a lot of the time we security types - yes, you and me - don’t actually know what the rest of the departments within the business actually do on a day-to-day basis. We know they exist and what their purpose is but we don’t appreciate their pain points. We’ve all heard, way too many times, the quotation from Sun Tzu’s “The Art of War”: “If you know the enemy and know yourself you need not fear the results of a hundred battles.”
I would argue that a lot of us don’t know our own organisation as well as we should, let alone the enemy.
If we consider a typical enterprise organisation it will have departments such as HR, legal, sales, PR, marketing, accounts, IT and many others. These all have their own objectives, their own stresses and strains and targets to meet – essentially they are in their own little bubble trying to do the best they can with what they have and more often than not information security is the last thing on their minds.
However, it is our job to help elevate their understanding of what we do and, most importantly, how we can help them to work more securely.
So if we are all in our own little bubbles, how can information security departments be effective for their businesses? As far as I’m concerned, if you work in this field and you don’t step out of your bubble from time to time you won’t be effective in the least and when I talk about effectiveness I mean helping to create a positive and lasting change, that is, building a strong and permanent culture of security within your organisation.
Yes, you may review third parties, you may assess project risks, get involved with pen tests and attend to incidents - but do you use these experiences to move towards building a more security-conscious work force? I guess that most of you do not. In truth, I don’t think most security departments are actually all that effective. They exist to serve compliance or some other tick-box exercise. It’s a case of we do our jobs and then we go home. There’s nothing wrong with that if all we are interested in is hanging onto our jobs but if we actually want to be effective, I mean if we want to change behaviour then we need to change the way we approach our work or else we’ll keep going round in circles forever.
(Maybe, though, we don’t really want to change anything and deep down we think, “what difference does it make to me, ah none really…” Cynical? Or just a little too near the truth?)In fact, effectiveness isn’t all that difficult. It means occasionally stepping out of your bubble and making an effort to appreciate the needs and wants of the business you work for. You need to listen, learn and adapt to what the business actually does on a daily basis. If you can do that, you can then begin to see new ways of working together with your colleagues, understand their difficulties, foresee problems looming ahead and do something to prevent them happening.
Here’s a few bubble-destroying suggestions. You might have thought of some of these practices already but if not, why not try them and see what they do for your effectiveness within your organisation?
To conclude, I would argue that if you’re a CISO/CSO/Head of Information Security or whatever senior security position you hold, building security culture should be your strategy.
So, don’t float - stand up and pop your bubble.
This article was published on Information Security Buzz - You can find it here
Now you’re thinking “Bubble? You what…”
Let me explain. My experience is that a lot of the time we security types - yes, you and me - don’t actually know what the rest of the departments within the business actually do on a day-to-day basis. We know they exist and what their purpose is but we don’t appreciate their pain points. We’ve all heard, way too many times, the quotation from Sun Tzu’s “The Art of War”: “If you know the enemy and know yourself you need not fear the results of a hundred battles.”
I would argue that a lot of us don’t know our own organisation as well as we should, let alone the enemy.
If we consider a typical enterprise organisation it will have departments such as HR, legal, sales, PR, marketing, accounts, IT and many others. These all have their own objectives, their own stresses and strains and targets to meet – essentially they are in their own little bubble trying to do the best they can with what they have and more often than not information security is the last thing on their minds.
However, it is our job to help elevate their understanding of what we do and, most importantly, how we can help them to work more securely.
So if we are all in our own little bubbles, how can information security departments be effective for their businesses? As far as I’m concerned, if you work in this field and you don’t step out of your bubble from time to time you won’t be effective in the least and when I talk about effectiveness I mean helping to create a positive and lasting change, that is, building a strong and permanent culture of security within your organisation.
Yes, you may review third parties, you may assess project risks, get involved with pen tests and attend to incidents - but do you use these experiences to move towards building a more security-conscious work force? I guess that most of you do not. In truth, I don’t think most security departments are actually all that effective. They exist to serve compliance or some other tick-box exercise. It’s a case of we do our jobs and then we go home. There’s nothing wrong with that if all we are interested in is hanging onto our jobs but if we actually want to be effective, I mean if we want to change behaviour then we need to change the way we approach our work or else we’ll keep going round in circles forever.
(Maybe, though, we don’t really want to change anything and deep down we think, “what difference does it make to me, ah none really…” Cynical? Or just a little too near the truth?)In fact, effectiveness isn’t all that difficult. It means occasionally stepping out of your bubble and making an effort to appreciate the needs and wants of the business you work for. You need to listen, learn and adapt to what the business actually does on a daily basis. If you can do that, you can then begin to see new ways of working together with your colleagues, understand their difficulties, foresee problems looming ahead and do something to prevent them happening.
Here’s a few bubble-destroying suggestions. You might have thought of some of these practices already but if not, why not try them and see what they do for your effectiveness within your organisation?
- Create a brand for your information security team or department. Be creative, ask the marketing and PR teams for a little help
- You should be seen and you should be known outside your own immediate circle. When was the last time you stood up to give an information security briefing to the business? When was the last time you actually walked around to different teams just to introduce yourself and have a little chat? Little chats can open the doors to really worthwhile exchanges of information. Never think of a little chat as mere gossip or a waste of time
- Have a mission statement. Look at the corporate mission statement and align yours to that. You could even come up with a snappy slogan. Whatever it is, it will make you more approachable and approachability is the first step towards increasing your effectiveness within your organisation
To conclude, I would argue that if you’re a CISO/CSO/Head of Information Security or whatever senior security position you hold, building security culture should be your strategy.
So, don’t float - stand up and pop your bubble.
This article was published on Information Security Buzz - You can find it here
Sunday, 6 July 2014
Look at What I Learnt in Class
The below is my first contribution to The Analogies Project started by Bruce Hallas. When he asked to me contribute I couldn't say no. You can also find it here on the analogies page
One of the best pieces of work experience I've ever had wasn't in IT or information security, in fact, it was Teaching English as a Foreign Language (TEFL) in Spain.
Let me tell you a little story…
Once-upon-a-time I was looking for a bit of a challenge, something different, and something not in the IT field. So I applied for a course that prepared you for becoming a TEFL teacher based in Spain. I passed and was subsequently offered a job with the college based in a small city called Zamora in the North West of Spain.
My job was to create and teach lessons using the course text for juniors, seniors and adults. At first I was a little apprehensive but then I thought to myself this will be easy, I have the text book and I’ll create lessons using the guidance provided on the TEFL course.
What could go wrong?
My first few classes were with the juniors and…well…erm…let’s just say they were no fun!
No one listened, no one paid attention and most importantly no one actually learnt anything.
Why?
I played it wrong. I went in with the attitude that I was the teacher and that I was right. That my lessons were engaging and that they should listen to me.
After a couple of classes and a lot of mockery from the students (I am now well versed in Spanish profanity) I realised that something needed to change. It was me, I needed to change. I had to change the way I was doing things in order for me to get any results. So what did I do? Well…
- I took salient points from the text book and then I ditched it.
- I began to chat with the students during the breaks asking them about
- their likes/dislikes, hobbies, favourite sports etc.
- I played football with the guys and talked about fashion with the girls
- I moved the class room desks around so that the atmosphere was less formal
- I had competitions e.g. guy vs girls
All of the above changed the dynamics of the class and after a few lessons they warmed to me. They listened to what I had to say, began to interact in class, made suggestions on future lessons and even began to ask if we could go over certain topics again. From then on I taught in the same manner and style across all the age ranges with the same results – I managed to get them engaged!
Comments like “your lessons are fun”, “you’re the best teacher” and “please don’t leave” were very flattering but all I had done was to take a different perspective and see things from their point-of-view. My job was then to look at the best way to get them on board.
Essentially, I changed my behaviour to change theirs.
The skills and experience I picked up during my time in Spain I now use in information security. As professionals in this field we need to take the time to understand people, notice the different personalities and the overall picture of the environment, in essence – the organisational culture.
Subscribe to:
Posts (Atom)







