Showing posts with label training. Show all posts
Showing posts with label training. Show all posts

Tuesday, March 14, 2017

A Culture of Security - The Best Infection! (repost)




   This week we're relaunching our Security Awareness campaign at work.  In honor of that, I thought we should re-sample a past post on this subject.  Enjoy!



   I was recently reading an interesting article at SearchSecurity entitled Staff infection: IT security education is contagious.  The article notes that security is the responsibility of every individual and that for an organization to have even a semblance of security, there has to be both buy-in and shared action by the members of the organization.

   The article, very correctly, mentions:
Even in today’s world, the general IT worker tends to view security as a barrier and a pain. It is implemented by someone else, and it makes their job harder to perform.
   This is one of the key problems caused by many security programs.  The information security industry often causes problems for itself by being difficult and inflexible.  Security is often viewed as a barrier.  Security is the group that adds extra requirements, delays projects and increases costs.  And with all of that, Security can't guarantee prevention, nor even provide a reliable probability of, an incident or breach.

Tuesday, April 5, 2016

It's Not If, but When

   Have you heard???  2015 was the "Year of the Breach".  Of course, 2014 was the year of the breach.  And, 2013 was the year of the breach.

   2016 is shaping up to be quite a year as well.

   Of course, when we talk about breaches, we're usually talking about someone "stealing" data.  It's not actually "stolen" because you still have it.  It's more accurate to say that in a breach the data is exfiltrated.  This is also called an attack on the confidentiality of the data.

   In security, we talk about the C-I-A triangle, Confidentiality, Integrity and Availability.  Confidentiality is about the secrecy of data.  Integrity is about the accuracy of data.  Availability is about being able to properly access data when it's needed.  A well-rounded security program needs to consider all these aspects.

   What is somewhat different this year is the crypto-/ransom-ware attacks.  In these cases, the attack is a virus that typically gets in as an email attachment.  Someone opens the attachment and the virus executes.  It finds files in network shared directories and encrypts them.  Now, encryption is often a good thing, but that's when you (or your organization) has the decryption key.  In a crypto-ware attack, only the attacker has the key.  That's a problem.  It becomes ransom-ware when the attacker offers to provide the key for a "small" consulting fee, usually paid via the anonymous crypto-currency, bitcoin.
   These are basically attacks to the availability of data.  We've seen instances of hospitals or other organizations temporarily shutting down as a result.  These could also be considered attacks to the integrity of the data - though I think we have not yet seen the real integrity attacks... and they are coming.

Monday, October 26, 2015

The Celebration Continues - Building the Next Generation

  We have arrived at our last week of celebration of US Cyber Security Awareness month!

   I've been posting comments in line with the weekly themes put together by DHS.  This week the theme is Building the Next Generation of Cyber Professionals.

   Whenever information security managers get together, one of the topics is often the talent crunch.  In almost any metro area in the US there is close to zero unemployment in security.  Add to that the coming brain drain as the baby boomers retire, and we have a looming problem.

   On the positive side, we're seeing more university and community college infosec programs.

   But there is more work than people.  The federal government estimates that they need 10,000 new infosec professionals in the coming years.  How is that going to work?

Tuesday, March 24, 2015

GOOD DAY

   I received the following email recently.  Looks too good to be true!  $1.5Million united state dollars!  Maybe I should reply? :-)

   The only thing missing is a link or attachment.

   Of course, there are tons of emails like this around.  And people do respond.

   Would you respond?  How many people at your workplace would respond?  How would you help people recognize this kind of email and not respond?

--------------
From: Dr. Xxxxx Xxxxx
Reply-To: "Dr.Xxxxx Xxxxx"
To:
Date: Fri, Mar 20, 2015 at 6:58 AM
Subject: GOOD DAY

Good day,

How are you doing hoping all is well with you and your family? We know you might have forgotten about this your outstanding compensation payment due to delay on the delivery up till now. We are here by writing to inform you that your payment file was found in our Office and we discovered that your Compensation payment of $1.5Million united state dollars have not been sent to you as it was instructed by The Economic Community of West African States (ECO-WAS)We are here to inform you that your payment has been converted into ATM Visa/Master Card to free it from Expiring, and all the necessary Arrangement for your

ATM VISA CARD Payment worth of $1.5Million United State Dollars has been granted for your payment through Our ATM Card Department Center.Now Your ATM Visa/Master Card is well packaged with every legal documents to convey it having any problem with any Authorities or with your Federal Government therefore we are here by inviting you to our office here in Republic of Benin, Office Address, UNITED BANK OF AFRICA BENIN, Xxx Xxx n,Xxxx Xxxx 2000, to enable us complete the normal formalities and activation process of your ATM Visa Card and issue the Secret PIN CODE/NUMBER to enable

you start using it at any ATM MACHINE worldwide of your choice nearest to you, as soon as it is activated, But if you are unable to come down here in our office in person you will be required to update our ATM Department Center with your contact delivery details as stated below so that they will proceed with

the necessary arrangement for the delivery of your ATM VISA/MASTER CARD.

1. Your Full name, ________________
2. Your home Address, _____________
3. Your telephone number, _________
4. A copy of your ID, _____________
5. Your age/sex, __________________
6. Your occupation, _______________
7. Your country, __________________

Therefore you should contact OUR ATM CARD PAYMENT DEPARTMENT CENTER immediately on their below;

E-mail :( dr.xxxxx.243@gmail.com )
Contact Person;
Dr. Xxxxx Xxxxx
Director Of UNITED BANK OF AFRICA BENIN,
Telephone Number; +229 nnn-nnn-nn
Try to call him immediately to know when your ATM VISA CARD will be delivered to you. I am waiting for you to update us as soon as you have received your

Visa/Master ATM Card.
Thanks and God Bless You.
Yours sincerely

Dr. Xxxxx Xxxxx

Tuesday, September 24, 2013

So You're a New CISO!?

   There are plenty of articles out there about becoming a new CISO.  And what elements you should have in an enterprise security program.

   I'm about to become a new CISO... again.  It's not an entirely unique situation.  I've been a CISO for over 10 years.  I'm starting as a new employee of an organization that has newly created the CISO position.  So I am new, and the CISO position is new, to this organization.

   I read this interesting article entitled 68 Great Ideas for Running the Security Department.  It's a great article, but even as a mathematician, I just can't count that high!  I also love top 10 lists.  But sometimes 10 is too high a number as well.

   Here are the 3 key things I'm going to do as a new CISO:

Tuesday, August 6, 2013

A Culture of Security - The Best Infection!

   I was recently reading an interesting article at SearchSecurity entitled Staff infection: IT security education is contagious.  The article notes that security is the responsibility of every individual and that for an organization to have even a semblance of security, there has to be both buy-in and shared action by the members of the organization.

   The article, very correctly, mentions:
Even in today’s world, the general IT worker tends to view security as a barrier and a pain. It is implemented by someone else, and it makes their job harder to perform.
   This is one of the key problems caused by many security programs.  The information security industry often causes problems for itself by being difficult and inflexible.  Security is often viewed as a barrier.  Security is the group that adds extra requirements, delays projects and increases costs.  And with all of that, Security can't guarantee prevention, nor even provide a reliable probability of, an incident or breach.

Tuesday, April 16, 2013

Bring It On Home

   There have been a number of discussions about the value of Security Awareness training floating around the net.  Some say that even with training, people will still fall for phishing attacks and social engineering, and that networks and servers will still get hacked.  I wrote about this a while back.

   I think there is great value to awareness training.  To me, the content and delivery are key considerations.  If the security messages are the same old, rehashed information then it will be hard to get people to pay attention, care and retain information.  No one wants to see yet another dry review of an organization's security policies.

    But there is a better way...