Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts

Thursday, 8 February 2018

Cyber Defence Gains Traction

Whilst the spotlight has been upon implementing GDPR in Europe, things have not been standing still elsewhere.

Singapore has passed a new Cyber Security Bill. This has many positive aspects as it appoints a National CISO to oversee and coordinate measures to protect critical national infrastructure. It also contains important requirements regarding accepted best practice, a duty to report incidents and enables the CISO's staff to investigate and demand standards based improvements.

This does not come a moment too soon as a recent report from AT Kearney and Cisco ( Cybersecurity in ASEAN: An Urgent Call to Action ) indicates that Cyber Security spending in ASEAN countries is at half the global average (0.07% of GDP cf. 0.13%) and much less than European or North American Countries which are typically at around the 0.2 - 0.3% mark.

So for global organisations, now is the time to make sure that their cyber measures are up to standard so that they can contine to operate safely and legally on a global basis.

Friday, 11 November 2016

The IoT Deluge


It was amusing to hear at a conference earlier this year, how one speaker had hacked into an acquaintances home network of smart devices and used this to scare the living daylights out of him one night, just to demonstrate the point that you need to firewall your home networks adequately. However, despite stories about peoples kettles and fridges being harnessed for use in Distributed Denial of Service (DDoS) attacks, the means for implementing Internet of Things (IoT) security frameworks already exist. If you go to any IoT event, someone will be promoting their IoT security platform. It's just that there is some catching up to do with the installed base of old unprotected SCADA systems and first generation "smart devices" to ensure that they are properly protected. As most of them were deployed with scant consideration of security.

Recently, it has become increasingly obvious that reality is beginning to set in about IoT exploitation. Businesses which want to exploit IoT in any meaningful way need to set about heavy duty industrialisation of key capabilities. Depending upon the business scenario in which you wish to exploit IoT, you may or may not have control of the end devices. In most cases you won't. So your solution may need to take into account different APIs for integration and different levels of security. It also needs to take into account that at any point in time, a significant part of the overall population of devices that you are communicating with may not be working for any number of reasons.

You also need to take into account the shear volume of data. IoT exploitation inevitably means large, fast growing volumes of data which has to be captured, sanitized, stored, analysed or exploited and managed according to relevant policies. However, many applications may need to take into account issues to do with geography; network bandwidth is not uniform within a county, let alone between countries. At sea it may be  extremely low compared with land. Legal jurisdictions can impact what is permissable from a privacy or even data export perspective.

However, key to scalability is the means to manage an IoT network. Each IoT device used by your solution will generate large volumes of data itself. Whilst attention to date has been focused on the application data, the volumes of event data for the devices, networks, associated installations and security devices could potentially drown the volumes of application data involved. Managing this data so that you can control the overall performance of the solution and optimise business outcomes, is a problem vastly larger than that which most IT organisations struggle with today. Automation is the only answer. Automation which brings all the data together, intelligently analyses it and visualises it for analysis is needed. IoT adoption, usually means changing your business model to do things differently and more intelligently. This cannot happen if you are not capturing and fixing problems as they happen as well as anticipating problems based on trend analysis. So Automation of monitoring and analysis is key. So automated monitoring is not just a nice thing to have because the DevOps boys told you it is trendy. Automation is key to survival. It has to deal with both operational and security incidents, and it has to be integrated across your whole environment. Point solutions are not good enough.

Fortunately, there is a new generation of tools which do this. They do it across hybrid cloud environments and deal with multiple protocols. Analysis of experience to date indicate that not only do they lead to dramatically shorter resolution times to problems (e.g. quarter to a third of previous times using traditional approaches), but to reductions in incidents (by similar margins) and therefore significantly reduced loss of value when problems occur. 




Friday, 7 October 2016

Cyber, Robots, Digital, Oktoberfest, Gosling and Demming - all in one week

This week was eventful. It started with the announcement that the UK's National Cyber Security Centre had at last opened its doors, see: http://bit.ly/2dpPZJH. This was long announced and is an essential plank in safeguarding the UK's Digital Infrastructure and Capability. My concern is the glacial pace at which progress has been made here and the comparatively small amounts of funding that the Government has assigned to fund it.

Then someone posed a picture of a man shaking hands with a robot at AT Kearney's Digital Business Forum with the caption "Next gen employee greets legacy employee". This displayed typical 1930s thinking about the value of people drawing from the legacy of the original R.U.R. play Rossumovi UniverzálnĂ­ Roboti (Rossum’s Universal Robots) written by the Czech writer Karel Capek in 1920. In the play, a factory owner attempts to replace his high versatile human workers with mechanical machines, totally undervaluing the creativity and inspiration that people bring to the workplace. Digital models are largely about delivering this value not implementing mindless mechanisation. So perhaps the caption should have been about valuable human talent supplanting inappropriate technology.

Anyway, the highlight of this week was the IPexpo event in London. This had a wide array of suppliers and speakers. Notable about the event was the desire to celebrate Oktoberfest complete with free beer and people dressed in Bavarian costumes at 4:00 pm on the first day. Many of the suppliers were also offering beer at other parts of the day. It was a strange example of how modern "fun oriented" culture of digital start up companies is affecting the mainstream and making us weirdly 1960s and modern all at the same time.

James Gosling presented a captivating key note talk on liquid robots covering his current involvement with Marine UAVs used for data collation in remote seascapes and the IoT practices needed to make this work. The UAVs themselves are very cool, capturing wave energy and converting it into propulsion.  The techniques for transferring data from the middle of oceans, where there is very poor bandwidth available even from satellites, were also very interesting with the same data being transfered by differnt networks and routes to increase the reliability and speed of data transport from the UAVs to the place where it is analysed. The interesting point that he made was that Scalability is a relatively trivial issue for IoT. Security and reliable Availability are much more important.

Two other talks were really good. Mathew Skelton (skelton Thatcher Consulting) gave an illuminating talk on anti-patterns for continuous delivery (aka DevOps). He confirmed my viewpoint that typically you need roughly 1 operations person working continuously with each Product Team, to avoid the bottleneck that some traditional ITIL shops have introduced with undersized change management functions.

Derek Weeks also gave a well researched presentation on the use of Opensource software and how modern software product development practices have now become highly analagous with manufacturing and supply chain practices. He presented interesting statistics on how much open source code contains security and legacy debt bugs. His premise being that Deming's (the father of Quality Management) recommendations to reduce the number of suppliers and quality assure bought in products can raise productivity in the adoption and exploitation of Open Software.

Friday, 10 June 2016

Cyber Fear and Digital Defence

How do we deal with the proposition that we are already penetrated?

Ever since the rise of the Advanced Persistent Threat and Socially Engineered Attacks the term Cyber has taken on new meanings and the IT Security industry has become one of the most vibrant sectors of the IT Industry.

At the European Infosec Event this week over 400 vendors were promoting their wares with the expectation that more than £1Bn of orders will result.

I have been to 3 such events recently and the range of issues arising has been phenomenal.

Planning and rehearsing for major events has become de rigeur with CIOs and other senior stakeholders needing to take media training. The industry has responded to Digital Challenges with a range of products providing cloud based security monitoring and encryption. Products similar to Military Battlefield Management Systems provide overarching monitoring, control and simulation systems. There is a high degree of inter-operation between many products and innovative products conduct network discovery and behavioural anomaly detection to track down new attacks using advanced machine learning and statistical analysis. There are even niche products for things such as system administrator control and user recognition via typing pattern recognition at keyboards.

However, one family of products disturbed me. There are now systems for monitoring user behaviour and predicting who is likely to cause a major leakage incident. This sort of big brother system is going to take significant effort to tune so that unfortunate false positives are avoided. Once people are used to them, they will be readily gamed. Whatever happened to actually managing and knowing the people who use your systems?