Posts

Awareness module on hackers and hacking

Image
We've just completed and delivered  our security awareness and training module about hackers - a topic we haven’t covered specifically for a few years, although most of the awareness modules at least touch on hacking – some more than others, The hacking risks have changed perceptibly in that time. The rise of state-sponsored (spooky!) hacking is of great concern to those of us who care about critical national infrastructures, human society and world peace. The United Nations is due to meet in a couple of weeks to discuss the possibility of reaching agreement on the rules of cyberwarfare, mirroring those for conventional, nuclear and biological warfare. Let’s hope they manage to align the ~200 countries represented at the UN – a tough task for the diplomats, politicians and cyberwar experts. That aspect gives a distinctly sinister tinge to the awareness module, and yet I hope we’ve succeeded in keeping the materials reasonably light, interesting and engaging as ever, a del...

Hacking awareness module

Image
September's security awareness module is rapidly falling into place with lots of juicy content for all three streams already: For the general/staff audience, we'll be giving an overview, an outline of the main information risks and information security controls, and promoting ethics;  For professionals, there's a bit more technical content, still without giving too much away (we're trying to encourage people to control against, not commit, hacking!); For management, we've updated the anti-hacking policy template to mention the bug bounty idea; All three streams emphasize the need for detective and corrective controls, supplementing the preventive controls because they are fallible.  The sheer variety of risks and controls is overwhelming, so we'll pick out a few topical aspects to discuss, such as using  bug bounties as a technique to both encourage (ethical) disclosure  and  improve information security, a nice combination.  Hardware hacking will make an a...

20 creative ways to use looping PowerPoint intros

Image
Yesterday I promised to share some ideas for looping intros on your PowerPoint presentations, primarily but not exclusively for security awareness seminars and the like.  Rather than wasting the time between opening the door and starting the session, it's a mini awareness opportunity you can exploit. Here  are 20 ways to use your loopy intros: Show short security awareness videos , maybe ‘talking heads’ clips of people talking about current threats, recent incidents, new policies etc .; Quotes from attendees at past awareness events, possibly again as video or audio clips or written quotations in their own words ; A slide-show of still photos from previous awareness and training events, preferably showing people having a good time and enjoying a laugh; Awareness posters : you do have plenty of these, right?; Clips from your intranet Security Zone  - just a few headline items, not whole pages, with the Zone 's URL; Clips from your security policies and procedures – litt...

Subversive metrics (surrogation)

Image
Don't let metrics undermine your business  by Harris and Taylor is a thought-provoking piece in the wonderful Harvard Business Review. It concerns a tough old problem, that of metrics themselves  becoming the focus of attention within the organization rather than the objects of measurement and, more importantly still, the business activities for which the metrics are intended to support improvement. "Every day, across almost every organization, strategy is being hijacked by numbers ... It turns out that the tendency to mentally replace strategy with metrics — called  surrogation  — is quite pervasive. And it can destroy company value." According to  Wikipedia , Charles Goodheart advanced the idea in 1975, although I suspect people have been manipulating metrics and duping each other pretty much since the dawn of measurement.  My eyes were opened to the issue by Hauser and Katz in  Metrics: you are what you measure!  Krag Brotby and I wrote about...

Policy and compliance

Image
This morning, "PS" asked the ISO27k Forum for advice about reviewing access rights. " I just got a minor NonConformity for not showing compliance with review of user access rights control. At present, a report containing leavers is reviewed by servicedesk to ensure removal of access. This process supplements the leaver process owned by department managers. But an auditor has insisted that we should retrieve all access reports and review them. So question is how do demonstrate compliance with this control in your organisation? Appreciate your guidance ..." Some respondents duly mentioned typical controls in this area, while some of us spotted an issue with the issue as described. Why did the auditor raise a minor non-conformity? On what basis did the auditor insist that they should ‘retrieve and review all access reports’ - if in fact he/she did? With a little creative/lateral thinking, it turns out there are several  intriguing possibilities in the situation descri...

End of an era

Image
Friends, Romans, customers, lend me your screens.  I come to bury NoticeBored, not to praise it. Sadly, the time has come to draw a lengthy chapter in our lives to a close. Our monthly  security awareness and training subscription service will cease to be early next year. As of April 2020,  it will be no more.  It will be pushing up the daisies.  We'll be nailing it to the perch and sending it off to the choir invisibule. Beautiful plumage though. The final straw and inspiration for the title of this piece was yet another exasperating phisher: ... and the realisation that suckers will inevitably fall for scams as ridiculous as that, no matter what we do. There will always be victims in this world. Some people are simply beyond help ... and so too, it seems, are organizations that evidently don't understand how much they need security awareness and training. "It's OK, we have technology" they say, or "Our IT people run a seminar once a year!" and sure en...

Cyber-insurance standard published

Image
We are delighted to announce the birth of another ISO27k standard :  ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance The newest, shiniest member of the ISO27k family nearly didn't make it into this world. Some in the insurance industry are concerned about this standard muscling-in on their territory. Apparently, no other ISO/IEC standards seek to define categories of insurance, especially one as volatile as this. Despite some pressure not to publish, this standard flew through the drafting process in record time thanks mostly to starting with an excellent ‘donor’ document and a project team tightly focused on producing a standard to support and guide this emerging business market. Well done I say! Blaze that trail! This is what standards are all about. ‘Cyber’ is not yet a clearly-, formally- and explicitly-defined prefix, despite being bandied about willy-nilly, a solid-gold buzzword. It is scattered like confetti throughout but unfortunately...