Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Friday, 19 October 2018

Another Week In AI & Machine Learning

Driveless

So the hot news this week is that people keep crashing into driverless cars. Wired magazine discusses the issue that the way in which the current generation of prototypes being driven on America's roads are experiencing a high level of accidents, apparently because they don't behave is the same way that ones driven by humans do. 86% of collisions in California this year have been due to being rearended or side wiped! Autonomous cars appear to be over cautious and annoy human drivers, not only by stopping unexpectedly but also because they are over compliant with the letter of the law in interpreting situations. So why don't they have signs on the car, just like a learner does to warn drivers that they need to keep clear? It's a pretty similar situation and people do tend to steer as clear as practicable from learners who they know to be unpredictable.

AWS Capability Continues to Grow

AWS also held its AWS Innovate Online Conference. In his "state of the nation" talk, Boaz Ziniman outline current capabilities available Off the Cloud (OTC) rather than Off the Shelf (OTS). Basically, AWS still provides impressive capabilities which allow a developer, data scientist or organisation to just start using AI and scale rapidly. Though they have been adding to this capability with impressively powerful capabilities around visual recognition and voice processing as well as bundled environments which are pretty much deploy and go. this is very liberating, because it provides a readily used Pay as You Go (PAYG) capability, which avoids much of the traditional issues of continuously having to research, select, implement, integrate and tune the suite of tools and infrastructure needed, as well as continuously returning to CAPEX approval and purchase processes for scaling to deal with increasing volumes of performance issues. 

There's a caveat though. Some of the capabilities, e.g. recognising a face in a crowd, which may be useful for security solutions, might also be used as the tools for enforcing a police state or merciless pursuit by paparazzi. Enabling such massive AI at scale, will to some extent be another nail in the coffin of personal privacy.

Early Adopters Surge Ahead

Finally, MIT Sloan and Boston Consulting Group released a report "Artificial Intelligence in Business Gets Real" which surveyed the application of AI in business across the globe. Whilst there were the usual scare stories about China being ahead of the West in adoption and that the gap between pioneers and laggards is growing larger there were some interesting points. The Chinese are deploying to meet efficiency and cost needs. Everyone else is deploying, because AI helps them do more and there was a message that AI will not replace jobs, but it will change the nature of work and the skills needed.

The second key message, was to experiment with something simple and demonstrate the benefits, because business leaders who had seen AI in practice, get it and are prepared to invest more, to the point that AI is almost addictive in the way in which it influences investment appetite once a business has tried it.

The final message was really around AI at scale. If you are planning on building your  future business model around AI, then you need to plan, prioritise long term investments and to get effective data governance in place. This does not just mean establishing once source of the truth, with valid, complete and coherent data. It also means having a good handle on version control. Since, if multiple applications of AI depend on the same data, it needs to be synchronised to avoid unintended problems. So Lean Data practices are fundamental to adopting AI at scale.

Finally, it was interesting to hear how paranoid Chinese companies, adopting AI, are about cyber security. Protecting their data from competitors and the continuing availability of data and AI based solutions becomes increasingly important once a company's business model has evolved to adopt AI. So the principle "Cherish your Data" (see The Way of DAU) is key to successful exploitation.

Conclusion

Human issues, ethics and common sense remain central to AI adoption, an Agile mindset encourages adoption and Data Governance is a key enabler.






Friday, 21 September 2018

The Trivia of IoT

You know that something has become too trendy when you key in the subject and some other random item and find that you get lots of returns. So yesterday, I tried it out with IoT.

So what do you get with IoT and Bathroom? Well a polemic on the bathroom of the future. Yes, we will have smart toilets which are not only eco friendly but diagnose medical conditions: Pregnancy, bacterial conditions, PSA levels, sugar levels etc. Smart showers are already here for the eco-friendly trendy set. They minimise wasted water, go straight to the temperature that you like and give feed back via LED lights on how much water you have consumed. Then there are smart toothbrushes which give you feedback on toothbrushing technique. Finally,  there is the smart mirror. This allows you to catch up on the news and weather forecast, whilst brushing your teeth. You could also monitor any of your smart household devices, such as your smart toaster, at the same time whilst also checking incoming messages. Sounds like hell doesn't it?

So I decided IoT and Underwear would then be a suitably trivial query. Well you get responses on the usual fitness app equipped wearables for monitoring pulse and other vitals whilst exercising. There's also smart yoga pants, which provide feedback to help you form the right posture when exercising. But there is also a quite exciting smart bra device, the iTbra, which can help monitor the wearer for signs of cancer. This has the potential to replace the expensive, stressful and quite uncomfortable process of having mamograms with something which monitors circadian temperature changes to detect abnormal patterns. Apparently this is based on a proven technique which has existed for decades, but was previously too cumbersome to use, due to the need for lots of cables going to instrumentation. IoT does away with the cables and allows for a potentially more accurate test which can be completed within a few hours of monitoring.

So, I then started thinking like a teenager and yes there is a smart tampon. The my.Flow  is there to help avoid the embarassement of blood staining the wearer's clothing, which would be a mortifying experience for anyone. As a man, I don't think that I should comment any further. But moving on to men, yes you can indulge in the smart condom, or i.Con. Actually its not a condom, but a ring you can slip over the top to monitor your performance statisitics during the act of copulation. Do we need it? is it useful? I'll leave it to you to decide.

So what do we learn from this trivia and is there a serious point. Well, its obvious that soon we will not be able to escape the World of Interconnected Smart Things (WIST). It has become pervasive across almost any field that you can think of (including farm fields of course). With it comes the danger of people who want to exploit it perniciously. So we need to start thinking about protecting ourselves and privacy and security in our homes and daily lives. However, this goes beyond the simple steps of securing your WiFi, protecting your passwords and identity, to seriously ensuring that your networked home and persona are well and truly protected in a systematic way and that you have separation of "concerns" and firewalls between your virtual world and the rest of the world.


Thursday, 13 September 2018

Cyber Trends 2018

James McDowell and Camble Murray gave an interesting talk, at the Blackberry Security Conference, on recent trends in cyber security and what we can learn from the last 12 months.

Probably the most quotable aspect was how easy it is to social engineer an attack if the attacker targets people in Sales roles. Apparently, sales people are so eager to make a sale that "they will open anything" on an email attachment. They also claimed, that if the attacker uses "appropriate HR language", then it is quite easy to persuade an HR user to do so too. So there are some communities to focus on with communications and cyber awareness training. It also appears that some security professionals are starting to adopt psychological techniques such as NLP to re-inforce their approaches to building security cultures.

It seems that Ransom Ware and Email targeting for spear fish attacks remain the 2 most prevalent threats, mainly because of the economics of cost and return from such types of attack; generally perpetrators reckon to pick up quite significant returns for relatively modest outlays, given the general availability of many cheap attack kits and the ability to sustain high volumes of attacks, almost guaranteeing that some will succeed.

It also appears that attackers are increasingly using Facebook and other social media platforms to identify individuals who are susceptible to "clicking on things" and profile them for future attacks. So perhaps this is the time to educate people about separating their social media personnae from their work ones, making it much less easy to cross link them.

Th other notable point was the significant number of crypto currency exchanges and wallets which had been targeted for attack. There is something about saying that something is secure that invites the wrong type of attention.

The other big trend is the emergence of the term Cyber Resilience, which is really about how capable a business is in dealing with major security incidents and continuing to operate when under cyber attack. So whilst there is a strong need to deal with security basics systematically, there is also the need to design in security at both an environmental and a project level, when implementing new stuff, there is also the need to have a well oiled and rehearsed approach to managing the response to an attack. 

Friday, 9 February 2018

UK Viewpoint on Digital Trends

At this time of year, Nimbus Ninety publishes its annual survey report on digital trends. What's nice about this is that not only do they provide a UK only perspective on the marketplace, but some of their commentary is contributed by leading practitioners, rather than consultants or journalists.

Anyway, this year shows strong themes around AI as the big disrupter and big data as the continuing big focus of spend. Predictably enough, Blockchain has moved into the picture as one of the future technologies of interest for disrupting business, just leapfrogging IoT by a single percentage point. Cyber defence technology remains one of the top disrupters too.

Culture is still cited as one of the big barriers to success identified by participants. This echoes a concern cited in this month's PM Today magazine that 51% of UK IT Leaders are struggling to secure boardroom consensus on digital transformation objectives (source: Interoute sponsored research).

Overall businesses are driven mainly by the need to meet customer expectations and improve customer interactions, whilst improving the speed and efficiency of processes. Only a third of businesses seem to be thinking about re-inventing their business model, which is still a large number but suggest that many businesses are still thinking short term about what Digital is about. Although half are pursuing Digital to enter new markets or develop new products. 

Put together this suggests that too many businesses are taking a departmental or functional approach to implementing digital and have not got into the One Team One Strategy approach needed for successful and sustainable Digital Evolution into Digital As Usual Businesses.

Interestingly enough though, the survey's respondents seem to rate fear of internet giants entering their markets much greater than fear of new entrants or startups. This mirrors the recently emerging consensus that digital markets tend to favour those who have already built scale, such as the big platform based businesses, e.g. Amazon.

Thursday, 8 February 2018

Cyber Defence Gains Traction

Whilst the spotlight has been upon implementing GDPR in Europe, things have not been standing still elsewhere.

Singapore has passed a new Cyber Security Bill. This has many positive aspects as it appoints a National CISO to oversee and coordinate measures to protect critical national infrastructure. It also contains important requirements regarding accepted best practice, a duty to report incidents and enables the CISO's staff to investigate and demand standards based improvements.

This does not come a moment too soon as a recent report from AT Kearney and Cisco ( Cybersecurity in ASEAN: An Urgent Call to Action ) indicates that Cyber Security spending in ASEAN countries is at half the global average (0.07% of GDP cf. 0.13%) and much less than European or North American Countries which are typically at around the 0.2 - 0.3% mark.

So for global organisations, now is the time to make sure that their cyber measures are up to standard so that they can contine to operate safely and legally on a global basis.

Monday, 17 July 2017

Digital Adoption Framework

A lot get's talked about Digital, but there are few comprehensive approaches to adoption available for reference. 

This is why I was interested when I came across Vadrim's DAF diagram, reproduced below. Enjoy!