Wednesday, 15 August 2018

Smashing the Stack but for None of the Fun or Profit: The Importance of Wellbeing


I’ve been meaning to write about this topic for a while and have finally found some time. It’s an important one, why?

Well, because it is about our wellbeing. Most of you will know about the paper that Aleph One wrote back in 1996 entitled “Smashing the Stack for Fun and Profit”. That was about stack buffer overflow vulnerabilities and how to exploit them.

However, I’m not talking about that stack. I’m talking about the real stack, our minds and bodies and how we need to look after them...a tenuous analogy but hey it’s allowable right? :) 

Why I think this is important, a personal journey.

Information Security / Cyber Security or whatever we wish to call it today has never been a 9-5 role, no matter what anyone’s contract says and most people in this field genuinely enjoy their work; sometimes time flies! Whilst this can be a good thing, in that, we really are into it and will work long hours, weekends or even holidays (guilty), if we don’t manage ourselves carefully it can begin to have a detrimental effect.

A while back I was working in a role where I was the security resource on more than twenty projects. Over half of those were high profile and at least one had a national media campaign attached to it and all the jazz that goes with that sort of thing.

It was one of those roles where I was here, there and everywhere. You know, the one where everyday you feel like you’re in a pinball machine. At the time I came up with the phrase - the calendar games. That’s another topic altogether but think…all projects are important…except some are more important than others. 

To all the newbies...navigating organisational politics is a skill you need to pick up fast, especially in our field. No one wants to hear “Well infosec signed it off!” when the fish hits the tan. Been there. Badness. Not good!

Anywaaaayyy…

To say that I ran myself ragged was a bit of an understatement; at the end of that role I was mentally exhausted. I made a lot of personal mistakes during that time, namely:

  • Forgot to switch off - I was always on and thinking about work even at home. When I was relaxing, work issues started to creep into my mind and the next thing I knew I had the laptop out.
  • As a consequence of not switching off I didn’t get enough sleep. Which led to not eating properly because I wanted to be in the office extra early “to get ahead of things”.
  • I stopped taking my morning walks and I didn’t take enough breaks during the day.

The work was interesting and I was absorbed. However, by the end of it I looked back and thought “man I can’t work like that again!” Not because of what I was actually doing on a daily basis but how I managed myself. How I let go of my usual routine.

In my opinion your personal stack is your mental and physical wellbeing. Over the long term, if you consistently smash away at these and you don’t manage them with the respect they deserve, then you’ll crash. Sometimes in the worst possible way and a reboot might not fix things. Oh and Last Known Good Configurations? Yeh, nope.

I am sponge.

Here’s another tenuous analogy…think of your mind like a sponge. You’ve got to let it loosen up again and be ready for whatever comes next. Now some of you may be thinking…“a sponge wtf are you on about Mo?!?

Hear me out…

When I’m on a busy, stress-laden piece of work I can get super focussed and with an element of tunnel vision. Like a sponge, soaking everything up, the mind becoming tighter and heavier. If I’m not careful, everything around me can begin to take second place.

Then as the work begins to wind down I slowly return to my normal self, my mind and body returning to its natural form. Relaxed. I find that I have to let my mind be free and loose again so that I can come back refreshed and ready to go.

Look…I know you know what I’m saying so stop smirking!

Ok sponge Mo, I get it. So what’s your routine?

As a visual, these are my fundamentals, where X is my sweet spot:




  • Travel - I always feel better for it. If you have the resources you should travel as much as you can. You don’t have to take out months on end; a long weekend away is also good. Even a day trip can help.
  • Exercise - Something as simple as a long walk helps a lot. I would like to get back into martial arts; this was more about general fitness and the spiritual side of it rather than anything competitive.
  • Creativity - Back in the day I use to while away hours on Fast Tracker 2. However, today the Ableton Push is calling me. I’m still trying to justify the cost and balance it with “Ooh look, another travel option!”
  • Hobbies/interests - Building stuff with our hands and having a tangible end result is immensely satisfying, even if it’s something as simple as Lego. I’m planning on getting back into RC models in particular Tamiya and Kyosho, hands up who remembers The Hornet? The act of building the model was always, in some sense, therapeutic for me.
  • As I’ve got older, being around green stuff and water helps a lot. If you have a park near you, go for a walk in the mornings. I recommended it.
  • Nothing – Yep, sometimes doing nowt, jack all, nada helps you do a lot more. Believe it or not I feel guilty when I’m doing nothing, it’s like we’ve been trained to always be doing something. However, in my experience it is incredibly good for you. Allow yourself a Nothing Day.

Ultimately, you have to allow yourself to rest and rejuvenate or you’ll definitely end up having none of the fun or profit. The profit is your wellbeing and always comes first. It’s the foundation that everything else is built upon - respect it.

Be well, friends.

Monday, 27 June 2016

The Security Culture Conference 2016

A couple of weeks ago I was back in beautiful Oslo (One of my favourite cities - I could definitely live there!) for the Security Culture Conference.

Last year we had around 25 people for the inaugural conference which was held on an island just outside the city - see my write up on that here. This year, however, the conference had grown to just under a 100 participants - that's pretty good going from scratch!

The conference was held at MESH a hub for entrepreneurs and creative minds in the city centre  - it was a great venue and had a really cool vibe. The event drew speakers such as Raj Samani from Intel Security, Rik Ferguson from Trend Micro as well as many others from Europe and the US.


Mingling before the food was served



Some of the views from the restaurant





Woosh!



The sun was still up at around 22:45! 





 Kristina welcomes us all to the conference

Dr Jane LeClair speaking about the challenges she faced and the solutions she found when building security culture at nuclear facilities in USA. 


Bjørn Watne talking about some key actions to take when aligning security culture with the board, management and throughout the organization.


Rune Ask talking about some of the changes coming in the second version of the Security Culture Framework



 Raj Samani on why personal data is the new oil of the Internet


After the conference Kai and the CLTRe team launched the CLTRe Toolkit



There was so much more going on in and around the venue and talks that I didn't manage to snap, such as Rowenna Fielding's great talk titled "Security Culture as a Just Culture". I was on after Rowenna and spoke about smashing silos and building bridges when building security culture in different environments.

Overall it was a great few days in Oslo and I was happy to see the conference has grown and matured.
   
Add the Security Culture Conference to your list of events to attend - It's a great compliment to technical security conferences. Or if you've got something to say keep an eye out for the 2017 CfP.

Thank you to all who made it possible! I'll be going back!

Sunday, 12 July 2015

Steel Con 2015

Last week I presented my "Popping the Bubble" talk at Steel Con - The North's Premier Hacker Con - https://www.steelcon.info/ - I think it went down quite well and there was some spirited discussion after the talk.

Robin (@digininja) and the crew put on a great conference at an amazing price of only £20 - The goodie bag really does have some goodies in it!

One thing that Steel Con does differently to other conferences is that they encourage children to come along as they have a specific "Kids Track". This is a great initiative especially when you see youngsters having fun learning to code, building robots and even making music with vegetables!

I'm looking forward to Steel Con 2016!

Sunday, 28 June 2015

The Security Culture Conference 2015

So the Security Culture conference happened! On an Island…no really…it was on an island…look…


The journey there took about twenty minutes via a ferry and a small boat to get to the island called Lille Herbern. The venue was actually a restaurant – the only one on the island.




The day began with Roar Thon’s key note – He explored what security culture is and what makes it an important tool for organizations. Roar is the Specialist Director at the Norwegian National Security Authority – You can find him on Twitter as: @secdefence




Next up we had Wolfgang Goerlich – He looked at how to apply the Security Culture Framework to a software development team. I think Wolf was about to get he’s Bollywood groove on there. Wolfgang is a Cyber Security Strategist at CBI Inc, his Twitter handle is: @jwgoerlich



The second half of the morning we saw Kai explaining how you can build and maintain a security cutlure using the framework. He’s Twitter handle is: @kairoer




The final talk before lunch was by Waldo Rocha Flores who works for Ernst & Young. He’s work has a lot to do with measuring the behavioural outcomes of security culture. Waldo also held a workshop after lunch. I couldn’t find him on Twitter.




Then it was time for lunch – yum!






Some lunch time conversations and networking…




Waldo’s workshop discussions – after lunch Waldo held a workshop which delved deeper in to his talk.




After the workshop we stretched our legs and got ready for the final part of the day with Shan Lee Head of Information Security for Just Eat. Shan told us about his security culture story at Just Eat, he gave us great insight into what it’s like to build a security within a dynamic company. You can find Shan on Twitter as: @secwaza




Turns out I was last on the list to present, I don’t like being last. Especially when you’re preceded by such quality. I spoke about how you can pop your bubble in the corporate environment. I’m on Twitter as: @infosecmo




With the talks over and everybody ready to chill we headed back to the boat and on to the post conference dinner party – much fun was had here.





I was going write a long post but then I went through the pictures from the day and I think they explain it all. The first Security Culture Conference had speakers with real experience and insight and I think everyone took something useful away at the end. Yes there were a few niggles but no conference out there is ever without those – it’s how you handle things that matters. It was a small and intimate affair with great conversation and a stunning setting.

Thank you to Kai, Eli, Kristina and Lars for making us all feel welcome.

See you all at the next one…I wonder where that will be?



Saturday, 9 May 2015

Book - Build a Security Culture

My good friend Kai Roer has written an easy to digest book on security culture. Anyone who has been in security for a while will know of Kai and his work on security awareness and culture.

He was very kind give me a mention in the book, cheers Kai!

It's a short and accessible book and you can find it here on Amazon.

Thursday, 30 April 2015

Phishy cyber-criminals 'go corporate' with social engineering

I met Doug Drinkwater from SC Magazine at 44Con he asked if I would comment on an article he was writing about phishing. My comments can be found in the article here

Thanks Doug for reaching out to me!.

Saturday, 28 February 2015

Tools Don't Change Behaviour People Do

What makes an information security awareness programme effective? As in most cases the answer is “it depends”.

Let me elaborate; if your goal is simply to obtain that magic compliance tick then maybe you’ll use some form of computer based training (CBT) coupled with some quizzes and possibly a few videos on your intranet page and bingo you’ve ticked the box! As an industry we are still heavily reliant on tools or packages to train or educate staff and make them security aware. However, these are rarely used within a defined and structured manner. Don’t get me wrong CBT’s, quizzes and videos are great tools but they should be used as part of your programme, not be the entirety of it. Actually, I don’t believe most environments need to train or educate their staff on security issues – I think that’s outdated approach. What they need to do is elevate their current level of security awareness to foster a more security conscience approach to their work and ultimately work toward building security culture.

Changing behaviours and building security culture is only possible when you understand and appreciate your existing organisational culture, look at how the different personalities within your organisation work and use a structured and measured approach and building security culture is no exception. Below are a few points that I think are important when you're seeking to influence and affect change:

Buy-in - It's become such a cliché because it's true. You need “the trust from the top” Yes it's about the funds but more importantly it's about the support, the belief that it will make a difference and that ultimately it's about enabling the business.

Understand and respect your current organisational culture - If you step back and think about the different departments in your business, the tone management sets, the different roles and responsibilities, you'll see the different personalities that exist. The key is to appreciate the daily activities that go on, what their key motivations are, what they need to deliver, and what their objectives are. When you appreciate this you can then look at how best to tailor security messages for them.

Know where you want to get to - Look at your current level of security consciousness and think about what's ideal for your environment not anyone else but yours. Define and set achievable goals, use campaigns that you can use as measures of success and target them at a particular department. Ultimately your campaigns can become your programme. A small campaign is easily structured, managed and measured and when that’s a success at you can replicate across different departments

Involve the right people - Odds are that you already have the majority of skills and experience you need in your organisation it's just a case of building relationships, being transparent about your objectives and working together. Seek assistance from departments such as HR, Marketing, PR and Legal these are departments that can help package your activities in line with corporate standards.

Prepare, plan, execute, review and repeat - If you already run projects and maybe even programmes you've already got the skills there to utilise and work with. Odd's are that you already have a security improvement plan of some sort or something similar is about to be launched, it's a great place to start aligning these activities with that

Understanding that it's an ongoing programme of work - When you're building security culture in your organisation be appreciative of the fact that it needs to be a dynamic activity, it should adapt to business and staff needs. If you use the ITIL framework you'll know about Continual Service Improvement think of this activity in the same manner – Continual Security Culture Improvement.

In essence what I’ve described above is the Security Culture Framework it’s been developed by Kai Roer of The Roer Group. It’s an open framework that consists of four elements namely; metrics, organisation, topics and planner you can find out more about it here - https://scf.roer.com/

A company that has been using the Security Culture Framework as part of their awareness activities is Just East. I caught up with their Head of Information Security, Shan Lee at 44Con and we got chatting about awareness, changing behaviour and security culture here's what he had to say:

You absolutely have to tailor any program not only for your organisation, but for parts of the organisation. What works at JUST EAT probably wouldn’t work in a bank, and I don’t speak the same language to our developers that I do to our call centre agents or finance people.

A central theme with a strong message is essential, but it has to be varied according to the target audience, and that theme must be consistently and constantly reinforced through the widest range of media that you can efficiently manage.

Divide the program into manageable chunks, put a clear objective around what each chunk is trying to achieve and find a way to measure its success. You’ll soon know what’s working and what isn’t, then its rinse and repeat.

To summarise, I think we as an industry need to appreciate that what may have worked in the past doesn’t work in the present and definitely won’t work in the future. In fact I think we should ditch the term information security awareness and call it security culture.