Sunday, 28 April 2013

BSides London 2013 - The Rookie Track

Well the day has come and gone and this is my Rookie Track review and BSides London 2013 experience…

It wasn’t long after I’d registered that Robin (@digininja) introduced (over email) me to my mentor Mike (@clappymonkey). At first, I was a bit apprehensive. What with Mike in Birmingham and me in London town I thought to myself, how is this going to work?

As I had gone into the process with an open mind it turned out better than I had expected. We had regular phone chats and as the day approached we went through a number of dry runs, which really helped. On one occasion he told me that my slides should be “shiny” and I thought “eh, you what?” He explained that I should try and tell a story with pictures and have less bullet points - and then I got it. 

So I made it my mission to have the least amount of text on my slides and also to not have any cue cards. I ended up with only pictures as my slides which I used to drive the story from my fragile little rookie mind ;)

Through Twitter, I also got offers of advice from Michael (@catalyst) and Kai (@kairoer) both of which gave me some good advice during interesting Skype chats.

As the day drew closer I found out that Mike couldn’t make it to BSides, I was looking forward to meeting him for the first time and even promised him a few drinks – this will happen, only a little later :) 

Arron Finnon (@f1nux) asked me if I wanted a stand in mentor on the day, someone to be a friendly face and I said sure why not.  I was introduced to Wendy Nather (@451Wendy) and though our little Skype chat was fractured by wireless woes I was looking forward to meeting her. 

Wednesday turned out to be a gorgeous day in London so I skipped to the venue…ok well I didn’t quite skip…oh you know what I mean ;) When I got to there I picked up my speaker badge, hooked up with Ian Williams (@fishermansenemy) Mike’s colleague and Wendy. I also found and introduced myself to @f1nux who kindly directed me to the Rookie Track room.


So now I had two friendly and helpful people, the rookie room was a nice size and the slides were there – I was good to go!

Until my time to talk came I watched David Rook’s (@securityninja) talk which was laid out in comic book style and he even had printed copies of the talk. I was lucky enough to get a signed copy of the comic book with ninja kisses! lol. I have to thank Wendy for that :)



Then there was the multiple award winning Javvad Malik (@J4vv4d) with his talk, even with a couple of musical mishaps he was awesome.



During the rest of the morning I checked out my fellow rookies’ talks which were damn good, caught up with some ex work colleagues, interrupted Brian Honan (@BrianHonan) during his lunch to introduce myself and mingled.

After lunch I spoke to Mike and he wished me good luck and gave me a few pre talk tips and before I knew it my time was up!

It was 15:15 gulp! I stepped up to the front of the room and began to speak…and woosh the fifteen minutes had flown by, it had gone surprisingly quick. Many thanks to Ian for my five minute marker and to Arron with his iPhone stopwatch :)

There were a few nerves but overall I think I performed well. I felt like I kept the room engaged, managed to get a couple of laughs and even fielded a couple of questions at the end. One of which was taken outside  – for the life of me I can’t recall the name of the gent that I spoke to, dude if you’re reading this get in touch – I’ll blame it on Rookie Amnesia. 

Wendy smiled, Ian smiled and even Javvad said well done. I also got a big positive reaction from Frank Morris (@frankmorris) thanks for that sir :)

The title of my presentation was Information Security Awareness: Making your staff the strongest link. I explained how I’ve used the experience gained during my time in Spain teaching English as a foreign language in my information security career

Post my talk I spoke to Mike, to give him the lowdown on how it went. He was pleased for me and happy that I didn’t, as I had termed it end up in Rookie Rehab. 

I finished the day off by checking out the last few Rookie Talks, mingling and had a really cool chat with David Rook (@securityninja) As the day drew to a close I really didn’t want to be carrying my laptop around and seeing as I live in London, I scooted home to drop it off.  Then it was time for the after party at the Archangel – Big thanks to MWR!

There I met up with, Ian Williams (@fishermansenemy) and Frank Morris (@frankmorris) for some drinks. To be honest I was cream crackered so wasn’t there for too long. 

On the way to the station I caught up with the lovely Iggy (@GeekChickUK) both heading the same way we had a cool chat about BSides, the Rookie Track and Infosec.

So that’s my Rookie Track review and BSides London 2013 experience. I hope I haven’t missed anyone out. If so, shout :) 

A lot of hard work goes in to organising a day like that, so as someone who hadn’t been to a real conference before, I really appreciate the effort. Especially those who organised the Rookie Track.

If you’ve never presented at a conference before, this is the PERFECT environment – do it!

I’m already looking forward to 2014 :)

Tuesday, 15 January 2013

Continual Self Enhancement

I have always had the motto continual self enhancement it is to this end that along side my book idea I've added a couple of certifications to my skill set namely, the ISO27001 Lead Auditor certification and the Advanced Professional Certificate in Investigative Practice.  The Lead Auditor course was to complement my existing experience around the ISO27001 standard.

With regards to the APCIP course, well that was to gain an understanding of the basics of the law when working on investigations.  I've been involved in investigations where there wasn't a tried and trusted process and it always made me think, what if the evidence we present is challenged, would it stand up in court?

The course has the following compulsory modules:

  • Law, Evidence, Procedure and Best Practice
  • Advanced Statement/Report Writing
  • Witness Familiarisation

As optional modules I chose the below: 
  • DPA
  • RIPA
  • Securing Electronic Evidence 
I found it to be enjoyable and very valuable.

Saturday, 1 December 2012

My first BSides London!

On a freezing Saturday evening, my brain was whirring with talk of awareness - I really don't know why. I guess I wasn't actually aware hmmm, I blame the cold.

Then it came to me...ping! One of those light bulb moments (energy efficient of course) that next year Security BSides London has a Rookie Track.

Oooh I thought, I could register my interest but at first I was afraid...I was petrified...er hold on back on track..the Rookie Track. The lovely people at Security BSides London have come up with an awesome idea, to get people up and presenting! They've made the presenting time a nice fifteen minutes and best of all if you want you can be allocated a Mentor. Essentially, someone who has been there and done it before to guide you.

Personally I think c'est magnifique!

Why, you ask, well because I'm one those people who has always wanted to present and also be part of the infosec community but didn't quite have the right avenue to do it. This format presents an opportunity, in a friendly (er...you will be nice right?) environment with fellow infosec people to get up and see if I can actually do it.

I've always had a bit of a thing about awareness in that it's basically really badly done...no one actually takes the time to look at their user base and think hmmm how should we sell the infosec message to them. We label them as the weakest links...er that's because no one actually told them what to look out for in a way that was engaging.

I think that if we as information security professionals begin to engage with our users a lot better then that's the first step to gaining their trust. Essentially, what we do is all about communication, so it's ironic that we can't communicate our message effectively.

So I've registered my interest as Security Awareness: Making Your Staff the STRONGEST Link.

Hmmm now I need to...erm...make it so.