Posts

Habitual security

Image
Getting our work colleagues to behave more securely is a lot like breaking old habits and replacing them with new ones. 'Habit' implies several things, most notably t here is stasis, inertia or resistance to change - the very essence of habit - hence directed changes inevitably require both time and energy. Furthermore, o ld habits die hard: they are our well-practiced, comfortable, default behaviors, mostly performed subsconsciously, autonomously, easily, without thinking or apparent effort. In contrast, changing to a different behavior requires conscious thought and deliberate effort, at least at first, until the new behavior itself becomes habitual. In the middle is the 'unfreeze' phase of  Kurt Lewin's classic 3-phase change model , the road-hump separating two distinct behaviors or clusters of activities. Habitual behavior, including addiction, has been studied extensively for decades and is fairly well understood in terms of the psychology and physiology, so w...

Lessons from the aviation industry

Image
The ICAO  Global Aviation Safety Plan 2014-16  (GASP) is an extremely impressive document on so many levels. First off, how about this for an entrance (first paragraph): " Ensuring safety remains paramount Continuous improvement in global aviation safety is fundamental to ensuring air transport continues to play a major role in driving sustainable economic and social development around the world. For an industry that directly and indirectly supports the employment of 56.6 million people, contributes over $2 trillion to global gross domestic product (GDP), and carries over 2.5 billion passengers and $5.3 trillion worth of cargo annually, safety must be aviation’s first and overriding priority." Given everything that's at stake here (and just in case it escaped your notice, those are BIG  numbers), " safety must be aviation's first and overriding priority ".   No ifs or buts, there's absolute clarity of vision for the entire industry.   In other words  th...

Smoke-n-mirrors IBM style

I've just been reading the IBM 2015 Cyber Security Intelligence Index , trying to figure out their 'materials and methods' i.e. basic parameters for the survey, such as population size and nature. All I can find are some obtuse references in the first paragraph: "IBM Managed Security Services continuously monitors billions of events per year, as reported by more than 8,000 client devices in over 100 countries. This report is based on data IBM collected between 1 January 2014 and 31 December 2014 in the course of monitoring client security devices as well as data derived from responding to and performing analysis on cyber attack incidents. Because our client profiles can differ significantly across industries and company size, we have normalized the data for this report to describe an average client organization as having between 1,000 and 5,000 employees, with approximately 500 security devices deployed within its network." Reading between the lines, it appears ...

Are you cyber-prepped?

Image
That deliberately dark, foreboding, dramatic image is just one of the awareness posters in August's brand new awareness module on cybersecurity. Its purpose is to catch people's eyes, intrigue them and make them think. What is a "cyber-prepper"? What are they doing? Are they friend or foe - something to be wary of, or to emulate? The cyber-prepping concept came to me as the awareness materials were being written. While "preppers" are busy digging their underground bunkers, stockpiling water, food and small-arms to survive The Big One, the reality is that modern warfare is likely to be markedly different to the classic nuclear/biological/chemical holocaust scenarios they typically fear. Few cyberweapons make a bang or a flash, let alone a mushroom cloud - in fact, stealth is arguably their most valuable characteristic. If the enemy doesn't even know it has been infiltrated and attacked until its already too late to respond, its IT systems, comms and netwo...

Cut the bleating: how about something positive for a change?

Image
An opinion piece in Forbes by two Cisco people wound me up today. To my jaundiced eye, they were just bleating on about senior management's lack of interest in, concern about, understanding of, and leadership in, IT security .  Seems to me they are naive, misguided, overly-cynical and/or disingenuous. I find overtly negative comments unhelpful and counterproductive. It saddens me that so many security pundits (especially those still locked in the introverted world of IT) continue pointing the accusing finger at senior management as if it's entirely their problem, while offering little if anything in the way of constructive advice or, for that matter, accepting any part of the blame for the situation in which we now find ourselves. Come on guys and gals, we can do better than that. The key question is why :  why should senior management be concerned about information risk? Why is this issue worthy of their attention?  Why is it so important that they show leadership in thi...

Taking the shine off IoT security

Image
Various information security pundits are bleating about the evident lack of security in the Internet of Things, as if we should be both surprised and aghast. G et real guys! Consumers* don't buy IoT products because they are secure.  They buy them because they are shiny. Security is not shiny. It is an afterthought, at best. Worse still, since making IoT products secure means they cost more to manufacture, security is an anti- goal at this time. Companies attempting to sell relatively expensive, relatively secure IoT products now are unlikely to establish the market presence they need to make a success of the business,  unless they are foresighted enough to forgo short-term success in favor of a (long-term, risky) strategic investment.  Meanwhile, there is a premium on being first to market**. In due course, when insecure IoT products have infiltrated our lives and IoT incidents are both frequent and severe enough to become genuine concerns (which they aren't yet), then I...

Employ people who 'get' infosec

Image
Organizations that take information security seriously enough to adopt good practice standards such as ISO27k generally appreciate the need to integrate infosec with HR processes. They have pre-employment screening, on-boarding processes such as security induction sessions, continuous security awareness & training where appropriate throughout employment, and off-boarding/departure activities when the employment or service relationship comes to an end. The key controls are laid out in black and white in section 7 of ISO/IEC 27002:2015 . Most such organizations  have security-related policies and procedures, along with compliance activities plus enforcement and reinforcement. Very few organizations manage without employment or service contracts, codes of conduct etc., often mentioning compliance.  Despite all that good stuff and more, we are repeatedly told that 'people are the weakest links', in other words we're not home and dry. We haven't nailed it yet. Why? What...