Somehow I made it onto Tripwire's list of rising stars and hidden gems! I'll take gem over star any day! It was quite flattering to find out I was on this list.
I did have to ask them to edit it as I'm more of an educator than hacker.
Thank you Tripwire!
A personal information security engagement, awareness, behaviour and culture blog. Opinions are mine and mine alone - Soon to be revamped!
Saturday, 3 August 2013
Sunday, 28 April 2013
BSides London 2013 - The Rookie Track
Well the day has come and gone and this is my Rookie
Track review and BSides London 2013 experience…
Post my talk I spoke to Mike, to give him the lowdown on how it went. He was pleased for me and happy that I didn’t, as I had termed it end up in Rookie Rehab.
It wasn’t long after I’d registered that Robin (@digininja) introduced (over email) me to my mentor Mike (@clappymonkey). At first, I was a bit apprehensive. What with Mike
in Birmingham and me in London town I thought to myself, how is this going to
work?
As I had gone into the process with an open mind it
turned out better than I had expected. We had regular phone chats and as the
day approached we went through a number of dry runs, which really helped. On one occasion he told me that my slides should be
“shiny” and I thought “eh, you what?” He explained that I should try and tell a
story with pictures and have less bullet points - and then I got it.
So I made
it my mission to have the least amount of text on my slides and also to not
have any cue cards. I ended up with only pictures as my slides which I used to
drive the story from my fragile little rookie mind ;)
Through Twitter, I also got offers of advice from
Michael (@catalyst) and Kai (@kairoer) both of which gave me
some good advice during interesting Skype chats.
As the day drew closer I found out that Mike
couldn’t make it to BSides, I was looking forward to meeting him for the first
time and even promised him a few drinks – this will happen, only a little later :)
Arron Finnon (@f1nux) asked me if I wanted a stand
in mentor on the day, someone to be a friendly face and I said sure why not. I was introduced to Wendy Nather (@451Wendy) and
though our little Skype chat was fractured by wireless woes I was looking
forward to meeting her.
Wednesday turned out to be a gorgeous day in London
so I skipped to the venue…ok well I didn’t quite skip…oh you know what I mean
;) When I got to there I picked up my speaker badge, hooked up with Ian
Williams (@fishermansenemy) Mike’s colleague and Wendy. I also found and
introduced myself to @f1nux who kindly directed me to the Rookie Track room.
So now I had two friendly and helpful people, the
rookie room was a nice size and the slides were there – I was good to go!
Until my time to talk came I watched David Rook’s (@securityninja)
talk which was laid out in comic book style and he even had printed copies of
the talk. I was lucky enough to get a signed copy of the comic book with ninja
kisses! lol. I have to thank Wendy for that :)
Then there was the multiple award winning Javvad Malik (@J4vv4d) with his talk, even with a couple of musical mishaps he was awesome.
Then there was the multiple award winning Javvad Malik (@J4vv4d) with his talk, even with a couple of musical mishaps he was awesome.
During the rest of the morning I checked out my
fellow rookies’ talks which were damn good, caught up with some ex work
colleagues, interrupted Brian Honan (@BrianHonan) during his lunch to introduce
myself and mingled.
After lunch I spoke to Mike and he wished me good
luck and gave me a few pre talk tips and before I knew it my time was up!
It was 15:15 gulp! I stepped up to the front of the
room and began to speak…and woosh the fifteen minutes had flown by, it had gone
surprisingly quick. Many thanks to Ian for my five minute marker and to Arron
with his iPhone stopwatch :)
There were a few nerves but overall I think I
performed well. I felt like I kept the room engaged, managed to get a couple of
laughs and even fielded a couple of questions at the end. One of which was
taken outside – for the life of me I can’t
recall the name of the gent that I spoke to, dude if you’re reading this get in
touch – I’ll blame it on Rookie Amnesia.
Wendy smiled, Ian smiled and even Javvad said well
done. I also got a big positive reaction from Frank Morris (@frankmorris)
thanks for that sir :)
The title of my presentation was Information Security Awareness: Making your
staff the strongest link. I explained how I’ve used the experience gained during
my time in Spain teaching English as a foreign language in my information
security career
Post my talk I spoke to Mike, to give him the lowdown on how it went. He was pleased for me and happy that I didn’t, as I had termed it end up in Rookie Rehab.
I finished the day off by checking out the last few
Rookie Talks, mingling and had a really cool chat with David Rook (@securityninja)
As the day drew to a close I really didn’t want to be carrying my laptop around
and seeing as I live in London, I scooted home to drop it off. Then it was time for the after party at the
Archangel – Big thanks to MWR!
There I met up with, Ian Williams (@fishermansenemy)
and Frank Morris (@frankmorris) for some drinks. To be honest I was cream crackered
so wasn’t there for too long.
On the way to the station I caught up with the
lovely Iggy (@GeekChickUK) both heading the same way we had a cool chat about
BSides, the Rookie Track and Infosec.
So that’s my Rookie Track review and BSides London
2013 experience. I hope I haven’t missed anyone out. If so, shout :)
A lot of hard work goes in to organising a day like
that, so as someone who hadn’t been to a real conference before, I really
appreciate the effort. Especially those who organised the Rookie Track.
If you’ve never presented at a conference before,
this is the PERFECT environment – do it!
I’m already looking forward to 2014 :)
Tuesday, 15 January 2013
Continual Self Enhancement
I have always had the motto continual self enhancement it is to this end that along side my book idea I've added a couple of certifications to my skill set namely, the ISO27001 Lead Auditor certification and the Advanced Professional Certificate in Investigative Practice. The Lead Auditor course was to complement my existing experience around the ISO27001 standard.
With regards to the APCIP course, well that was to gain an understanding of the basics of the law when working on investigations. I've been involved in investigations where there wasn't a tried and trusted process and it always made me think, what if the evidence we present is challenged, would it stand up in court?
The course has the following compulsory modules:
As optional modules I chose the below:
With regards to the APCIP course, well that was to gain an understanding of the basics of the law when working on investigations. I've been involved in investigations where there wasn't a tried and trusted process and it always made me think, what if the evidence we present is challenged, would it stand up in court?
The course has the following compulsory modules:
- Law, Evidence, Procedure and Best Practice
- Advanced Statement/Report Writing
- Witness Familiarisation
As optional modules I chose the below:
- DPA
- RIPA
- Securing Electronic Evidence
Saturday, 1 December 2012
My first BSides London!
On a freezing Saturday evening, my brain was whirring with talk of awareness - I really don't know why. I guess I wasn't actually aware hmmm, I blame the cold.
Then it came to me...ping! One of those light bulb moments (energy efficient of course) that next year Security BSides London has a Rookie Track.
Oooh I thought, I could register my interest but at first I was afraid...I was petrified...er hold on back on track..the Rookie Track. The lovely people at Security BSides London have come up with an awesome idea, to get people up and presenting! They've made the presenting time a nice fifteen minutes and best of all if you want you can be allocated a Mentor. Essentially, someone who has been there and done it before to guide you.
Personally I think c'est magnifique!
Why, you ask, well because I'm one those people who has always wanted to present and also be part of the infosec community but didn't quite have the right avenue to do it. This format presents an opportunity, in a friendly (er...you will be nice right?) environment with fellow infosec people to get up and see if I can actually do it.
I've always had a bit of a thing about awareness in that it's basically really badly done...no one actually takes the time to look at their user base and think hmmm how should we sell the infosec message to them. We label them as the weakest links...er that's because no one actually told them what to look out for in a way that was engaging.
I think that if we as information security professionals begin to engage with our users a lot better then that's the first step to gaining their trust. Essentially, what we do is all about communication, so it's ironic that we can't communicate our message effectively.
So I've registered my interest as Security Awareness: Making Your Staff the STRONGEST Link.
Hmmm now I need to...erm...make it so.
Then it came to me...ping! One of those light bulb moments (energy efficient of course) that next year Security BSides London has a Rookie Track.
Oooh I thought, I could register my interest but at first I was afraid...I was petrified...er hold on back on track..the Rookie Track. The lovely people at Security BSides London have come up with an awesome idea, to get people up and presenting! They've made the presenting time a nice fifteen minutes and best of all if you want you can be allocated a Mentor. Essentially, someone who has been there and done it before to guide you.
Personally I think c'est magnifique!
Why, you ask, well because I'm one those people who has always wanted to present and also be part of the infosec community but didn't quite have the right avenue to do it. This format presents an opportunity, in a friendly (er...you will be nice right?) environment with fellow infosec people to get up and see if I can actually do it.
I've always had a bit of a thing about awareness in that it's basically really badly done...no one actually takes the time to look at their user base and think hmmm how should we sell the infosec message to them. We label them as the weakest links...er that's because no one actually told them what to look out for in a way that was engaging.
I think that if we as information security professionals begin to engage with our users a lot better then that's the first step to gaining their trust. Essentially, what we do is all about communication, so it's ironic that we can't communicate our message effectively.
So I've registered my interest as Security Awareness: Making Your Staff the STRONGEST Link.
Hmmm now I need to...erm...make it so.
Subscribe to:
Posts (Atom)


