Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Friday, 21 September 2018

The Trivia of IoT

You know that something has become too trendy when you key in the subject and some other random item and find that you get lots of returns. So yesterday, I tried it out with IoT.

So what do you get with IoT and Bathroom? Well a polemic on the bathroom of the future. Yes, we will have smart toilets which are not only eco friendly but diagnose medical conditions: Pregnancy, bacterial conditions, PSA levels, sugar levels etc. Smart showers are already here for the eco-friendly trendy set. They minimise wasted water, go straight to the temperature that you like and give feed back via LED lights on how much water you have consumed. Then there are smart toothbrushes which give you feedback on toothbrushing technique. Finally,  there is the smart mirror. This allows you to catch up on the news and weather forecast, whilst brushing your teeth. You could also monitor any of your smart household devices, such as your smart toaster, at the same time whilst also checking incoming messages. Sounds like hell doesn't it?

So I decided IoT and Underwear would then be a suitably trivial query. Well you get responses on the usual fitness app equipped wearables for monitoring pulse and other vitals whilst exercising. There's also smart yoga pants, which provide feedback to help you form the right posture when exercising. But there is also a quite exciting smart bra device, the iTbra, which can help monitor the wearer for signs of cancer. This has the potential to replace the expensive, stressful and quite uncomfortable process of having mamograms with something which monitors circadian temperature changes to detect abnormal patterns. Apparently this is based on a proven technique which has existed for decades, but was previously too cumbersome to use, due to the need for lots of cables going to instrumentation. IoT does away with the cables and allows for a potentially more accurate test which can be completed within a few hours of monitoring.

So, I then started thinking like a teenager and yes there is a smart tampon. The my.Flow  is there to help avoid the embarassement of blood staining the wearer's clothing, which would be a mortifying experience for anyone. As a man, I don't think that I should comment any further. But moving on to men, yes you can indulge in the smart condom, or i.Con. Actually its not a condom, but a ring you can slip over the top to monitor your performance statisitics during the act of copulation. Do we need it? is it useful? I'll leave it to you to decide.

So what do we learn from this trivia and is there a serious point. Well, its obvious that soon we will not be able to escape the World of Interconnected Smart Things (WIST). It has become pervasive across almost any field that you can think of (including farm fields of course). With it comes the danger of people who want to exploit it perniciously. So we need to start thinking about protecting ourselves and privacy and security in our homes and daily lives. However, this goes beyond the simple steps of securing your WiFi, protecting your passwords and identity, to seriously ensuring that your networked home and persona are well and truly protected in a systematic way and that you have separation of "concerns" and firewalls between your virtual world and the rest of the world.


Friday, 17 August 2018

Cyber Aggression versus Authenticity

In a week when EU officials expressed the fear that "British Agents may have bugged Brexit Planning Sessions", it is interesting to note that President Trump has decided to reverse a previous Obama administration framework for controlling the launch of cyber attacks by the US.

Sabine Weyand expressed the EU officials' fears following an incident in which Britain requested that slides from an briefing meeting should not be released to press. this has led to all mobile devices and ipads being banned from meetings, in case they are used to spy on them or leak secrets. Trump's move undoes measures designed to ensure co-ordinated and considered response by the US's intelligence community to perceived threat. The exact reasons for this have not been disclosed, but given the president's penchant for action, the political pressure that he has suffered following allegations that Russian organisations may have interfered with the presidential election and the fact that a considerable number of potential foes may be looking for ways to hit back at the US following sanctions placed on Turkey, Russia and Iran, it is not surprising that he might want to be able to react quickly without engaging multiple layers of decision making and delay.

At the same time in an almost polar opposite direction, key operators in the digital world are emphasising the need for "brand authenticity" in the way in which they market and sell their products to today's modern consumer. This is discussed in some detail in this quarters magazine from Nimbus Ninety, an organisation focused the London Digital Ecosystem. They also discuss some interesting thoughts from academia about how Socrates railed against the idea of writing things down and how this would damage young people's minds, in a strikingly similar way to which modern social media is being accused of damaging generation Z's cognitive attention spans. Plus ca change, plus ca meme chose.

Thursday, 8 February 2018

Cyber Defence Gains Traction

Whilst the spotlight has been upon implementing GDPR in Europe, things have not been standing still elsewhere.

Singapore has passed a new Cyber Security Bill. This has many positive aspects as it appoints a National CISO to oversee and coordinate measures to protect critical national infrastructure. It also contains important requirements regarding accepted best practice, a duty to report incidents and enables the CISO's staff to investigate and demand standards based improvements.

This does not come a moment too soon as a recent report from AT Kearney and Cisco ( Cybersecurity in ASEAN: An Urgent Call to Action ) indicates that Cyber Security spending in ASEAN countries is at half the global average (0.07% of GDP cf. 0.13%) and much less than European or North American Countries which are typically at around the 0.2 - 0.3% mark.

So for global organisations, now is the time to make sure that their cyber measures are up to standard so that they can contine to operate safely and legally on a global basis.

Thursday, 25 January 2018

Google puts a SOC in it

Google X

So Google (or Alphabet as the parent is now called) has announced today that they are joining the SOC market with proactive security defence based on capture and analysis of events.

This has come out of their X projects division which aims to rapidly develop new breakthrough products.

What's Google Planning?

Presumably Google aims to provide Machine Learning based measures capitalising on the scale of its services and analysis across customer environments hosted on its GCS platforms. This should give it certain predictive advantages, enabling it to home in on certain types of attack.

What would be good to know is how will Google differentiate between poorly configured devices, failing devices and real attacks. As many APT style in infiltrations will mimick poor configuration and failures to disguise their intents. Also what will they be doing around major incident management, remediation and forensics to provide a complete service?

Details are thin on the ground so far and this is bound to spur me too imitations from AWS and Azure.

SOC Fundamentals still Apply

However, as ever the fundamentals for a working SOC will remain:

  • You need to know what assets you are managing and keep CMS/CMDB accurate, complete and up to date;
  • As far as is practicable, ensure that all assets are implemented with standard configurations, to avoid mis-configuration and creating the noise in which APT infiltration can hide;
  • Use automation and software as infrastructure to implement standardised asset configurations and maintain patching up to date;
  • Then deploy logging, automated monitoring and analysis;
  • Invest in remediation and incident management capability;
  • Use scenario planning and practice exercises to ensure that there are no gaps and you are prepared for problems.

What Else is Google Doing?

The SOC services are only part of the offering. The new business unit called Chronicle will also be offering threat intelligence and products from its VirusTotal acquisition.

Tuesday, 9 January 2018

Does Your SOC Need Darning?

Microfocus (the new owner of much of HPE's former software division) has released the 2017 State of Security Operations Report.

This analyses the findings of analysis of the Maturity Model levels of practice in enterprise Security Operating Centres or SOCs. For those who are uninitiated, SOCs are a relatively new organisational construct within IT and are responsible for assuring that there is ongoing monitoring and analysis of an organisation's IT operations to ensure that vulnerabilities are detected, intrusions are caught and problems are rectified. Although there does seem to be a great deal of diversity in people's interpretation of the exact scope of this remit.

Maturity Models (see CMMI) typically categorises maturity in 5 levels which address process and practice standardisation as well as feedback loop control via metrics and optimisation. 1 is ad hoc, 2 is repeatable, 3 is uniformly standardised and so on. So most organisations will aspire to level 5 as an acceptable level of conformity. Though the actual scope of coverage is important too.

Many enterprises have adopted SOCs to help deal with the ongoing climate of cyber threats arising from things such as simple viruses,  spear pfishing, ransomware and Denial of Service attacks.

The report is quite sobering. Close to a quarter of the assessed organisations failed to achieve a score of even 1. only a fith appear to be making headway and the overall average score is less than 2.

The report finds that much SOC effort is wasted dealing with false positives arising from little standardisation and poor configurations of equipment. This underlines the operational hygiene issues of having accurate CMS data and consistency in build and installation. Knowing what you have and standardising as much as is practicable, does not just make it easier to operate an IT estate, but also to protect it by detecting anomalies and other problems. These are practices which not just ITIL but DevOps considers essential to robust operations and change management.

The report also shows problems with working out the right blend of insourcing and outsourcing as well as skills retention.

Overall there are signs within the report of slow but gradual maturing of approaches as well as better pooling of knowledge within organisations. But t is understandable, given the scale of issues that people face, that Splunk for instance promotes the adoption of a Lean SOC approach and gradual incremental implementation of SOC capabilities to address business priorities, 1 at a time.

Friday, 26 May 2017

CIOs - Don't Go To Switzerland!

The 2017 survey, Navigating Uncertainty, conducted by Harvey Nash and KPMG contained many data points on a significant number of current issues. One of the surprising themes, however, was a general conclusion that CIOs in Switzerland may be having a rough time.

One of the few positive indicators was the fact that very few Swiss CIOs have changed job in the last year, which may have a negative interpretation too, if there are no opportunities to go to. Apart from that there were some rather challenging statistics.

Switzerland is bottom of a table of 24 countries for CIOs receiving pay increases. Only 14% received an increase.

Swiss CIOs are very likely to increase the level of outsourcing, sitting 8th out of 28 countries. Over 50% are likely to do this, incurring constraints on successfully pursuing a digital model.

Only some (just under a third) have received budget increases, placing Switzerland 25th out of 28 countries. Again makinf it dificult to pursue a transformational digital model.

At the same time, Switzerland ranks one from bottom in terms of the level of major Cyber attacks experienced by their businesses with over 50% having been attacked in the last 2 years. Additionally, Swiss CIOs rank above the global average in expecting political turbulence to affect their plans. This sits well above any Brexit influence.

One has to ask, what is going on in Switzerland and why?

Friday, 7 October 2016

Cyber, Robots, Digital, Oktoberfest, Gosling and Demming - all in one week

This week was eventful. It started with the announcement that the UK's National Cyber Security Centre had at last opened its doors, see: http://bit.ly/2dpPZJH. This was long announced and is an essential plank in safeguarding the UK's Digital Infrastructure and Capability. My concern is the glacial pace at which progress has been made here and the comparatively small amounts of funding that the Government has assigned to fund it.

Then someone posed a picture of a man shaking hands with a robot at AT Kearney's Digital Business Forum with the caption "Next gen employee greets legacy employee". This displayed typical 1930s thinking about the value of people drawing from the legacy of the original R.U.R. play Rossumovi UniverzálnĂ­ Roboti (Rossum’s Universal Robots) written by the Czech writer Karel Capek in 1920. In the play, a factory owner attempts to replace his high versatile human workers with mechanical machines, totally undervaluing the creativity and inspiration that people bring to the workplace. Digital models are largely about delivering this value not implementing mindless mechanisation. So perhaps the caption should have been about valuable human talent supplanting inappropriate technology.

Anyway, the highlight of this week was the IPexpo event in London. This had a wide array of suppliers and speakers. Notable about the event was the desire to celebrate Oktoberfest complete with free beer and people dressed in Bavarian costumes at 4:00 pm on the first day. Many of the suppliers were also offering beer at other parts of the day. It was a strange example of how modern "fun oriented" culture of digital start up companies is affecting the mainstream and making us weirdly 1960s and modern all at the same time.

James Gosling presented a captivating key note talk on liquid robots covering his current involvement with Marine UAVs used for data collation in remote seascapes and the IoT practices needed to make this work. The UAVs themselves are very cool, capturing wave energy and converting it into propulsion.  The techniques for transferring data from the middle of oceans, where there is very poor bandwidth available even from satellites, were also very interesting with the same data being transfered by differnt networks and routes to increase the reliability and speed of data transport from the UAVs to the place where it is analysed. The interesting point that he made was that Scalability is a relatively trivial issue for IoT. Security and reliable Availability are much more important.

Two other talks were really good. Mathew Skelton (skelton Thatcher Consulting) gave an illuminating talk on anti-patterns for continuous delivery (aka DevOps). He confirmed my viewpoint that typically you need roughly 1 operations person working continuously with each Product Team, to avoid the bottleneck that some traditional ITIL shops have introduced with undersized change management functions.

Derek Weeks also gave a well researched presentation on the use of Opensource software and how modern software product development practices have now become highly analagous with manufacturing and supply chain practices. He presented interesting statistics on how much open source code contains security and legacy debt bugs. His premise being that Deming's (the father of Quality Management) recommendations to reduce the number of suppliers and quality assure bought in products can raise productivity in the adoption and exploitation of Open Software.

Tuesday, 16 August 2016

Are You Ready for Digital Disaster?

We all know that we should have a Disaster Recovery / Business Continuity Plan. Yet most of us have worked in businesses where this is a convenient afterthought. Even when businesses have them, active testing of them is often patchy at best. Many businesses aspire to do this at least once a year, fail to meet this target and even if they do, they then brush a lot of things under the carpet.

For many years the key concern has been a major fire, followed by lesser concerns about flooding, terrorist attacks and other major natural disasters. Statistics suggest, that in the UK the typical rate of major fires is around once per hundred years of a data centre's operations. This is actually a very high high rate. Although in actual practice the more frequent major incidents which disrupt operations tend to be caused by more mundane things such as loss of power from the grid, major network switch failures within the the data centre or loss of telecommunications coming into a data centre.

Many businesses have been content to make minimal investment in preparations and accept the risk. They have mostly got away with this despite urban myths about the high percentage of businesses, suffering major incidents, which go out of business. Though if you personally have ever lived through such an incident, you would not want to do so again.

This complacency is looking increasingly out of place as enterprises go digital. For one thing, operations become impossible to deliver with failure, for another the increasing frequency of "Cyber Attacks" means that the old cosy assumptions are no longer valid and not only may operations be disrupted but valuable information or IPR stolen and an enterprise's reputation destroyed along with customer confidence.

The increasing pace of change inherent with modern digital business, based on Agile and DevOps styles of continuous change, also mean that an annual test is laughable as recovery plans will never be up to date if annual refresh thinking continues to dominate. This will also exacerbated by use of multiple SaaS, PaaS and IaaS services. As although each one used may increase the theoretical resilience of the enterprise's systems, it also complicates the inter-dependencies between them.

Business and IT Management Teams need to actively engage in preparing for major disasters and incidents. This means several things need to be addressed:

- capturing all changes to the systems and process lanscape, especially adoption of SaaS services, so that current architecture is documented, understood, risk assessed and continuously revised in recovery plans;
- regular incremental testing of recovery plans to address changes to the systems landscape;
- conduct of scenario "war games" to evaluate responses to different types of threat, taking into account that under Murphy's Law key people may be unavailable when a major incident occurs;
- regular review of major 3rd party services that the enterprise relies upon for the suitability their response capabilities and likely behaviours;
- media training of all senior executives and managers who may be called upon to represent the enterprise in the event of an incident, taking into account that some of them may have been incapacitated by the incident or away from the business.

Not many of us work in enterprises where all this happens, but most of us need this now.

Friday, 10 June 2016

Cyber Fear and Digital Defence

How do we deal with the proposition that we are already penetrated?

Ever since the rise of the Advanced Persistent Threat and Socially Engineered Attacks the term Cyber has taken on new meanings and the IT Security industry has become one of the most vibrant sectors of the IT Industry.

At the European Infosec Event this week over 400 vendors were promoting their wares with the expectation that more than £1Bn of orders will result.

I have been to 3 such events recently and the range of issues arising has been phenomenal.

Planning and rehearsing for major events has become de rigeur with CIOs and other senior stakeholders needing to take media training. The industry has responded to Digital Challenges with a range of products providing cloud based security monitoring and encryption. Products similar to Military Battlefield Management Systems provide overarching monitoring, control and simulation systems. There is a high degree of inter-operation between many products and innovative products conduct network discovery and behavioural anomaly detection to track down new attacks using advanced machine learning and statistical analysis. There are even niche products for things such as system administrator control and user recognition via typing pattern recognition at keyboards.

However, one family of products disturbed me. There are now systems for monitoring user behaviour and predicting who is likely to cause a major leakage incident. This sort of big brother system is going to take significant effort to tune so that unfortunate false positives are avoided. Once people are used to them, they will be readily gamed. Whatever happened to actually managing and knowing the people who use your systems?


Sunday, 5 June 2016

The End of Outsourcing?

Most of us who have been in the trenches dealing with Outsourcing Partners in the last few years are puzzling over where it all is going. 3 major forces are changing the current model as we know it:

(A) Exhaustion of the Indian (or Off-Shore Labour Arbotrage) Value Proposition;
(B) The move to Everything as a Service (XaaS) as new players offer different types of service;
(C) The death of Monolithic Service contracts, as enterprises pursue increasingly complex Multi-sourcing models.

The original attraction of the Indian model was access to a large pool of well qualified talent which was artificially cheap as a consequence of exchange rate differences. As the offshoring model was pursued, the "Unseen Hand of the Market" has moved to erode the price benefits through year-on-year wage inflation and adverse currency movements. Additionally, as demand has risen, the talent has "followed the money" impatiently pursuing promotions, increased status and the opportunity to only work with the latest technology. This has led to unfettered job hopping, resulting in the loss of knowledge and the failure of individuals to develop deep experience. This has eroded the value proposition around talent. On top of this long distance relationships carry a heavy overhead in building them up and maintaining them, and the off shore players have developed business models and practices which assume that demand will continue to build at the same aggressive rate as previously. Many enterprises are actively taking things back on shore or in house.

The move to XaaS means that many of the traditional "box shifting and box running" services which were foundational to classic outsourcing are redundant. The traditional outsourcing players are losing the core "economy of scale" type services which they used to provide to IaaS and PaaS providers. Further more, the opportunities around traditional application based services are being eroded by SaaS providers. So although there are some niche opportunities where things like European data protection legislation or defence contracting requirements offer some opportunities, most of the market is moving to platforms such as those offered by Amazon and Microsoft. 

The continuous move to multi-sourcing started in the late 90s and has gradually built up steam over the last 20 years, especially as XaaS is now becoming the norm. This should also offer opportunity to move up the food chain to offer more value added services around Service Integration. Yet there is little evidence that any of the main outsourcing giants understand Service Integration or that there is appetite within customers to pay for it.

When I look at it, even in the area of Cyber where Security Operating Centre (SOC) services are in increasing demand, it seems that new entrants from the Aerospace and Defence industry have recognised and pursued the opportunities more aggressively, building both technical capability and market credibility.

So if you are looking at your service and sourcing strategy, it's time to think about what your model is, what kind of suppliers you need and to quiz them on their vision and direction. Otherwise you may be lumbered with a failing partner.