I am very pleased to be able to post a guest blog from a very good friend of mine who is a non-security expert, but still very ‘computer savvy’ compared to most.

This is in response to my post; “If You Want More Privacy, Stay Off The Internet“.

If someone as ‘privacy aware’ as this still has these issues, you can image how bad things are for the majority.

Finally, thank you so much for this [friend who will remain anonymous] 🙂

As a parent of three (20, 19 and 17) who live and die on their smart phones and tablets, and play games on the TV using the internet via their X-box 360s and PS3’s I suppose, as a non technical person, I’ve probably given more thought to Personal Information Security than most.  Add into that mix the fact that I am married to a Military Man, that I, myself was a serving member of HM Forces and worked for the Government overseas, then I should be able to sit here and say, hand on heart, that I take all reasonable measures to protect my personal information and understand easily what failing to follow basic guidelines can lead to.  So imagine my displeasure when a few simple Google searches both reassured, and horrified me. 

 
First, I tried my name – this returned results of a Swedish glamour model and her twitter accounts, and there in 6th place my LinkedIn profile – that’s OK, I actually WANT that audience to find me.  I added my middle initial to the search and down near the bottom of my page is a www.192.com listing from an address lived in previously.  Should I worry about this? Perhaps, perhaps not, I mean after all it is information that is publicly available via the Electoral Roll and the Census, it lists my husband as a co-habitant at that address, but on this page, it is a generic listing that gives only the town location – to get further details and to see if I have any county court judgements against me, you have to sign up and register. Thanks but I’ll pass.
 
So that’s not so bad is it? 
 
OK – take my daughter, she is heavily into her computer technology, her gaming community and live bands and gigs.  She routinely uses twitter, Facebook, Google plus, YouTube and many other forms of social media, the list is endless.  Again a simple Google search with our town name tagged on the end of her name returns nothing of great surprise and she’s actually got a 192.com listing at our current location which shows us all as co-occupants in the house (me, my husband and her two sisters).  Again its generic info, but we are all there.  Also returned are her YouTube channel, her Facebook and twitter accounts etc.  
 
My eye is drawn half way down the search results, in the image table of the six photos that appear on the search result, three of them are of my daughter.  Hmm interesting,– so I follow the images link to see what else I can recognise as hers.  And there I am, with my husband, in London on a day out – how the heck did that get there?, the hyperlink says it’s a plus.google.com image.
 
I run a couple more searches based on old email prefix’s and avatar nick names that I used in the late 90s when I was actively involved in  MSN communities helping women world wide (and maybe no so security savvy as the internet was a brand new, shiny and unknown beast to me back then).  I thought that MSN had scrapped all the pages, they certainly told us they were doing so, but no, lo and behold, there are a few of my old rambling posts for all to see, and all the other alternatives sites that we used that we tried to use to substitute for MSN Communities, yup – I’ve found all my old user names and some hilarious posts from back in the day when I was trying to learn graphics in Photoshop and PaintShopPro.
 
This got me thinking, if little old me, with my very limited IT knowledge can find all this stuff out in 10 minutes from mucking about in Google, what can someone do if they find this limited information and actually see tenable links.  If they had a clever programme that linked me and my family, and then actually got a proper account at 192.com and worked out that as a family we have had three homes in the last 5 years – that’s very powerful information.  If that person then thought a little bit (and not much) deeper and interrogatedancestary.com looking for family ties, they would soon have my mothers maiden name…. well we all know how powerful that information is when put with addresses of the last 5 years.
 
This is not new news to the probable audience of this blog, but I bet my children haven’t thought about it in this way, despite me and my hubby imploring them to share nothing personal on the internet.  Indeed, I ‘thought’ I had deleted all those old accounts.  I was fairly certain there was harmless stuff out there on the web, but really who is interested in me? Is there anything more I could do?
 
Well I supposed I could rid myself of the technology around me, but would it make a difference? Of course it wouldn’t. I could become paranoid and withdraw from the social media arena, but I like it, and then if I do that the bad guys who would be unscrupulous and mean with my information have won – and I don’t like the little man being persecuted.  
 
My employer, the tax man, DVLC, my bank, none of these organisations are going to walk away from using IT in the day-to-day, and in my opinion, nor should I.  So I can be cautious, and not put things like the obvious out there for the bots to find, but I also have to put my trust in the system, and hope that my Government is arming itself and doing all the things the bad guys are doing, not to exploit my citizenship and be big brother, but to protect me.  I will continue to shield my personal info online using the means available to me, and trust that the clever buggers out there with the know how on the good side of the fence, will outsmart and learn new ways to stop those toe rags on the bad side of the fence in their tracks.
Anyone have any their own thoughts on this?

Transformational change has been defined as; “A shift in the business culture of an organization resulting from a change in the underlying strategy and processes that the organization has used in the past.

But this assumes that everyone in the organisation knows what the “underlying strategy” actually is, and what process(es) they should be following!

In the absence of active leadership, employees will tend to focus almost entirely on their day to day tasks without much thought as to how those tasks fit into the overall vision or success of the organisation. Lessons learned are lost, skills and innovation stagnate, and inefficiency is justified by “We’ve always done it this way.”

The old cliche; ‘Knowledge is Power’, is as true now as it’s ever been, but how that knowledge is gathered and shared is radically different. What was once accessible only to those with the passion and dedication to go get it, is now in your pocket. Information in context is knowledge, success however is in the correct application of that knowledge.

It follows therefore, that those with the most accurate information, and the greatest ability to apply it to a significant demand, will be the most successful. So why does this information sit on systems that receive little in the way of attention, care, or priority?

The answer lies in our nature; We tend to take for granted what’s always available. We don’t question running water, power, or access to the internet from our mobile phones, so the unbelievable mechanics of HOW those things happen are ignored in favour of enjoying the benefits of them.

Until they’re not there.

Information security, done properly, involves the mapping of every business process, every system/application/person, and every piece of information related to how an organisation does its business. It then goes on to suggest procedural efficiencies, accessibility improvements, and above all, how to keep it safe, and therefore relevant.

Change is happening faster and faster, and unless your business can keep up, you will be left behind.

In Daniel Burrus’s excellent article; “It’s Time to Change Your Outlook on Change” he states;

However, did you know that most of those changes that come “out of nowhere” are actually very visible months or even years before the change hits? You just didn’t notice it because you were too busy protecting and defending, too busy in the status quo, and too busy putting out fires. In fact, you were so busy that you didn’t spend any time looking into the visible future—the part of the future you can see.

The better your information assets are organised, the faster you can redirect them strategically, the easier you can absorb and correlate new information, and the better you are able to bring the resulting knowledge to bear on your future plans. Competitive advantages, especially in technology, are now numbered in the weeks and months, not years, so the most adaptable will invariably win.

Inspired leadership will always involve an element of foresight. Those with it will keep their organisation ahead of the competition, those without it will follow the latest buzz-words until their business is irrelevant.

Information security has always been seen as something that prevents innovation, slows down sales, and stifles growth. It’s time everyone saw it for what it is; a business enabler that protects the most important thing an organisation has…

Knowledge.

I can’t resist dramatic titles, but I’m not actually going to badmouth the SSC, PCI, or ‘Just-QSAs’ (see Heads-Up to the Just-QSAs, It’s Time to Diversify), I’m simply going to state my opinion on why every QSA has at some point had to cut significant corners in the assessment process, and written their reports accordingly. If they didn’t, their clients would, quite literally, never have achieved compliance.

Here’s a ridiculous analogy; If every PCI requirement was a tennis ball, you could very easily carry them all from a weight perspective, but it’s impossible to hold them all together without some kind of container (Tennis ball = DSS Requirements, Container = Security Programme). In other words, the requirements themselves are basic, but completely out of context from a ongoing management, business, or even good security practice perspective.

The PCI DSS is 350-odd MINIMUM security controls, that must be in place across all systems, applications, and processes at all times. Even though the individual controls themselves are very reasonable, and SHOULD be mostly in place anyway, there is no way in any environment (that warrants an onsite assessment) that 100% compliance can be maintained at all times. Not without considerable expense anyway.

For example; 1) PCI does not REQUIRE centralised logging, but try complying with 10.5.X without it. 2) You don’t HAVE to use 3rd party penetration testers, but do you really want to employ that skill-set in-house? 3) The paperwork aspect of policies is easy, but it take years and a significant change in corporate culture to put them properly into effect. And so on.

What this leads to is organisations either giving up and accepting ‘tick-in-the-box’ compliance, or spending way too much money on things that provide little value to the overall organisation.

The business must never be changed to fit into PCI compliance alone, the INTENT of PCI must be fit into business to the benefit of both.

As I’ve said countless times, it’s not that the DSS is a bad standard, it’s just that it doesn’t start in the right way, doesn’t finish where it matters, and only covers one specific data type. The outcome of this is that no business is going to make the necessary expense to attempt letter-of-the-law compliance. Nor should they in my opinion, which means that QSAs MUST be … errrr pragmatic in their enforcement.

Which brings up one of the biggest flaws of PCI; The QSA is held accountable to enforce the standard as written, but is also under commercial pressure as a vendor. There are hundreds of other QSA companies just waiting in the wings to ‘help’ businesses achieve compliance if you’re not pragmatic enough for their liking.

The conflict of interest is undeniable, and ruins the objectivity required to conduct the assessment. Not to mention that the price compression associated with this competition has, over time, massively eroded the level of service that can be provided at a reasonable profit.  Junior ‘Just-QSAs’, are the only way to make money in PCI if you don’t sell them other things on the side.

Finally, QSAs are allowed to interpret the DSS to a large degree, as well as make decisions on what constitutes a compensating control. There is very little official guidance, or standardisation in this regard, and the card brands themselves will always refer questions back to the QSA. There have been some very good trainers at the SSC, and some very poor ones, and the far from optimal training program itself just exacerbates the problem faced by businesses looking to do the right thing. That is, the right for PCI compliance, but also the right thing for their business. You can guess which takes priority.

In the end, the right thing is to just do security properly. The benefits far outweigh the costs, and your PCI compliance will be good enough for what it represents.

We’ve all seen these signature blocks;

[Name], CISSP, CISM, CISA, QSA, CRISC, CGEIT, PCIP, ISO LA, ITIL, Prince II, blah, blah….

These acronyms belong in two places; your LinkedIn [and equivalent] profile, and your CV/Resume/Bio. They have no place in your email signatures, nor on your business cards.

It’s not like we studied for a number of YEARS to get a MSc, or PhD. We read a book, and passed a multiple choice exam. We didn’t even have to know how to IMPLEMENT what we learned, we just had to memorise and regurgitate. Most questions end up being a 50/50 guess anyway if you don’t actually know the right answer.

I’m not saying certifications are totally meaningless, they are a great beginning for those trying to break into the cybersecurity industry, but once in, it’s your experience that needs to do the talking for you. Or better yet, the clients you helped do the talking for you. Your certifications show that you have some commitment, and who knows, maybe you’ll even learn a couple of things that are useful. But these things don’t help you much when you’re face-to-face with a real client asking for your guidance, and all you can do is read from a book.

Learning anything new is messy. You’re clumsy at first, you make LOTS of mistakes, and you may begin to doubt yourself. But get past that first client, the one who you helped …eventually, the one who actually thanked you afterwards, and THAT’S when your learning really starts. You EARNED that, and it’s not a feeling you’ll ever get from an acronym or a book.

With security, there are no certification that really get to the fundamental point, the meaning behind all of this. I guess CISSP gets the closest because its 10 Common Bodies of Knowledge (CBKs) cover things from Risk Management to Business Continuity, but no-one really cares about that stuff at senior leadership level, it’s just detail.

What’s important is STAYING in business, growing, going international, going public, shareholders and so on, and not one certification out there helps you explain to the CEO how IT and IT security can help get them there. No certification ever will, it’s something you have to learn for yourself, and something that will change with every client with whom you work.

There are no certifications for, or shortcuts to, being a consultant who ‘gets it’.

I have likened security to insurance, but that’s not really fair. Selling security is like selling insurance, but in the end insurance is just risk mitigation, security is business enablement. Security is not the goal, and it’s easy to get caught up in the moment and forget why we are really there in the first place.

So, as for your signature blocks, far better I think is to have the number of years you’ve been in cybersecurity, and the number of clients you’ve helped. Something like;

David Froud

Years In Cybersecurity: 17, Clients Helped: Hundreds

Think it’ll catch on? 🙂

[If you liked this article, please share! Want more like it, subscribe!]

While this is most likely true in every industry, it is VERY true in cybersecurity.

Most organisations above the ‘corner store’ size have some form of ‘in-house’ IT support, even if it’s just the CEO’s brother-in-law, but only the larger organisation will have dedicated in-house security expertise. It’s simply too expensive.

However, most organisations need security expertise – usually when it’s too late unfortunately – so it’s crucial that they are able to define their specific needs in such a way as to attract the right suppliers of those services. Unfortunately, and all too often, the wrong questions lead to the wrong suppliers who provide the wrong services. If they gave you what you asked for, whose fault is it?

Instead, it makes sense to outsource the choice of your security services to someone best placed to judge; a security expert unhindered by organisational or employment commitments. i.e. they are not employed by a security company and are 100% ‘vendor neutral’ in terms of service or product ‘recommendations’.

Of course, you still have the problem of where to find this person, and ensure that they are the right person to make these choices on your behalf, and the responsibility for this due diligence must begin with the person most accountable. Whether this is the CEO, COO, or IT Manager or whatever, the individual who understands the business goals of the organisation needs to be the one asking the questions.

Many large organisations make the curious choice of allowing their purchasing departments to run the vendor selection process, often without specialist security input beyond the most basic of initial requirement definitions. This leads to an RFP that not only asks all the wrong questions, but also to reviews of the responses by people who don’t understand the answers. The choice is then often based on price and not capability turning the whole thing in a debacle.

You don’t allow your dentist to choose which law firm you use to represent you, why would you have anyone other than a security expert define your security solutions?

Even your in-house security team is under certain limitations, and cannot be truly objective with regard their choices. Whether it be pressure from above, fear of making a mistake, or vendor preference / bias, the choices are rarely the optimal result for the organisation. Nothing nefarious, just human nature.

The development of an overarching security program has many moving parts, and every step must be with a view to the end goals, the current needs (risk priorities), and the bit that’s often neglected; how each piece integrates with the next. The purchase of security services, and especial products/technology must be based on not only cost, but of how it will be installed, maintained, managed, monitored, and measured.

This can only be performed by a Governance function that has access to, and guidance from, a true security expert.

I can’t say that I’ve come across a service like this, perhaps I’ll start my own…

[If you liked this article, please share! Want more like it, subscribe!]