Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, 13 September 2018

The Return of the Crackberry

This week, Blackberry held its annual security conference in London. so it was a good time to catch up with what Blackberry is doing now, after the melt down of its original secure corporate phone and email business model. 

Well, it is still in the phone business. Partnering with TCL, who undertakes hardware manufacture and smart phone distribution, blackberry is still designing new smart phones. The new models look very smart and offer a key pad equipped, touch sensitive android phone at a competitive price point, i.e. several hundred notes cheaper than the equivalent Samsung or Apple model. It would be easy to dismiss them as being a choice for someone who is into retro chic or an old school aficionado of key pads. However, there are some subtleties in the product design which are increasingly relevant in the current environment of aggressive cyber crime. The devices are designed and built bottom up to be resilient to infiltration and takeover, combining both hardware and software features for this. Additionally, the thumbprint security control is implemented in a way which allows the user to differentiate between what is private and what is shared. Which coupled with features in Android enabling separation between personal and corporate personas, makes it very much a smart phone of the age.

However, mobile phones are really only a side show and not the main story. Blackberry has built on its global secure telecommunications capabilities to emerge as a leading "Enterprise of Things" (EoT) enabler. Someone described its primary mission as being to "Secure your Communications and your Data". However the vision is one of comprehensively enabling secure IoT exploitation by enterprises, leveraging industry standard to deliver on government quality security in the deployment of Smart Things, or as one of the speakers stated "Moving from Mobile First to Things First".

There's a comprehensive set of products with SDKs which enable OEMs to develop secure smart products and Enterprises to deploy Thing based business models securely, whilst users enjoy a relatively seamless secure access experience across a comprehensive range of products.

Although what was probably the most impressive aspect of the conference was to see representatives from Google, Microsoft, Samsung and Blackberry discuss how they are collaborating to deliver a new generation of products which integrate securely and build the IoT world of the future.


Thursday, 8 February 2018

Cyber Defence Gains Traction

Whilst the spotlight has been upon implementing GDPR in Europe, things have not been standing still elsewhere.

Singapore has passed a new Cyber Security Bill. This has many positive aspects as it appoints a National CISO to oversee and coordinate measures to protect critical national infrastructure. It also contains important requirements regarding accepted best practice, a duty to report incidents and enables the CISO's staff to investigate and demand standards based improvements.

This does not come a moment too soon as a recent report from AT Kearney and Cisco ( Cybersecurity in ASEAN: An Urgent Call to Action ) indicates that Cyber Security spending in ASEAN countries is at half the global average (0.07% of GDP cf. 0.13%) and much less than European or North American Countries which are typically at around the 0.2 - 0.3% mark.

So for global organisations, now is the time to make sure that their cyber measures are up to standard so that they can contine to operate safely and legally on a global basis.

Thursday, 1 February 2018

Asia's Digital Dragons

Asia's Digital Appetite

According to experts in McKinsey, Asia is grabbing the opportunities available from digital to try and leapfrog traditional economic leaders in the west and compensate for historic lack of investment in infrastructure. They single out India, Indonesia and China as the countries with the most energetic approaches and the most innovation. They cite greater appetite for social media take up and openess to mobile and other new technologies as drivers to greater innovation.

This position is supported by Gartner's identification of Asia's 10 leading digital disruptors:

  • Tencent
  • AliBaba
  • Baidu
  • Ant Financial
  • JD.com
  • DiDi
  • Xiaomi
  • Yahoo Japan
  • Naver
  • Lufax

The interesting fact about this list is that it is dominated by Consumer oriented businesses. B2B opportunities are yet to be exploited. Even so, the power house that is AliBaba is reputed to dwarf western giants such as Amazon. So Asia is currently playing to its numbers and culture to establish scale.

Garnter recommends that western enterprises operating in Asia should consider adopting local platforms to guarantee penetration and better customer experience in Asian Markets.

Future Digital Directions in Asia

A recent survey of global CIOs by Logicalis showed that CIOs in the Asia Pacific area have been disappointed by slow progress overall in adopting digital business models. Like CIOs in other parts of the world they have seen typical barriers such as Organisational Culture, Scale of Investment, Legacy Infrastructure, Skills and Security holding them back.

However, overall they are typically planning to address them with moves to simplify and modernise infrastructure, work closely with other business colleagues to address specific opportunities, improve training, invest in culture change and generally increase security investments.

In doing so, they are preparing to lead change and more B2B services are likely to emerge, balancing Asia's digital economy.

Thursday, 25 January 2018

Google puts a SOC in it

Google X

So Google (or Alphabet as the parent is now called) has announced today that they are joining the SOC market with proactive security defence based on capture and analysis of events.

This has come out of their X projects division which aims to rapidly develop new breakthrough products.

What's Google Planning?

Presumably Google aims to provide Machine Learning based measures capitalising on the scale of its services and analysis across customer environments hosted on its GCS platforms. This should give it certain predictive advantages, enabling it to home in on certain types of attack.

What would be good to know is how will Google differentiate between poorly configured devices, failing devices and real attacks. As many APT style in infiltrations will mimick poor configuration and failures to disguise their intents. Also what will they be doing around major incident management, remediation and forensics to provide a complete service?

Details are thin on the ground so far and this is bound to spur me too imitations from AWS and Azure.

SOC Fundamentals still Apply

However, as ever the fundamentals for a working SOC will remain:

  • You need to know what assets you are managing and keep CMS/CMDB accurate, complete and up to date;
  • As far as is practicable, ensure that all assets are implemented with standard configurations, to avoid mis-configuration and creating the noise in which APT infiltration can hide;
  • Use automation and software as infrastructure to implement standardised asset configurations and maintain patching up to date;
  • Then deploy logging, automated monitoring and analysis;
  • Invest in remediation and incident management capability;
  • Use scenario planning and practice exercises to ensure that there are no gaps and you are prepared for problems.

What Else is Google Doing?

The SOC services are only part of the offering. The new business unit called Chronicle will also be offering threat intelligence and products from its VirusTotal acquisition.

Tuesday, 9 January 2018

Does Your SOC Need Darning?

Microfocus (the new owner of much of HPE's former software division) has released the 2017 State of Security Operations Report.

This analyses the findings of analysis of the Maturity Model levels of practice in enterprise Security Operating Centres or SOCs. For those who are uninitiated, SOCs are a relatively new organisational construct within IT and are responsible for assuring that there is ongoing monitoring and analysis of an organisation's IT operations to ensure that vulnerabilities are detected, intrusions are caught and problems are rectified. Although there does seem to be a great deal of diversity in people's interpretation of the exact scope of this remit.

Maturity Models (see CMMI) typically categorises maturity in 5 levels which address process and practice standardisation as well as feedback loop control via metrics and optimisation. 1 is ad hoc, 2 is repeatable, 3 is uniformly standardised and so on. So most organisations will aspire to level 5 as an acceptable level of conformity. Though the actual scope of coverage is important too.

Many enterprises have adopted SOCs to help deal with the ongoing climate of cyber threats arising from things such as simple viruses,  spear pfishing, ransomware and Denial of Service attacks.

The report is quite sobering. Close to a quarter of the assessed organisations failed to achieve a score of even 1. only a fith appear to be making headway and the overall average score is less than 2.

The report finds that much SOC effort is wasted dealing with false positives arising from little standardisation and poor configurations of equipment. This underlines the operational hygiene issues of having accurate CMS data and consistency in build and installation. Knowing what you have and standardising as much as is practicable, does not just make it easier to operate an IT estate, but also to protect it by detecting anomalies and other problems. These are practices which not just ITIL but DevOps considers essential to robust operations and change management.

The report also shows problems with working out the right blend of insourcing and outsourcing as well as skills retention.

Overall there are signs within the report of slow but gradual maturing of approaches as well as better pooling of knowledge within organisations. But t is understandable, given the scale of issues that people face, that Splunk for instance promotes the adoption of a Lean SOC approach and gradual incremental implementation of SOC capabilities to address business priorities, 1 at a time.

Wednesday, 31 May 2017

Post Digital Outsourcing - Going for Value

One of the things which always has frustrated me when dealing with traditional outsourcing companies has been the huge gulf between the Sales Proposition and the Reality of Day-to-Day Service.

Companies usually think they are going to buy the best skills in the market and get access to superlative service from a transformational partner who delivers agility and control, so they can forget about the complexities of running IT. In reality they get bland, slow moving and unimaginative bottom up services which are slow and expensive to change. Where people have looked for partnership, this has usually failed to materialise as relationships descend into "Robust User-Supplier Conflict" (or RUSC). In fact the traditional model has been an anti pattern to progressiveness and this has only been made worse by offshoring to Asia, where extreme cultural differences and expectations have only made things worse.

As I mentioned in a previous blog, The Death of Outsourcing, this model is no longer sustainable in the light of all things digital. So what can a Post Digital Service Provider offer now that XaaS threatens to steal outsourcing's breakfast?

The reality is that, whilst XaaS does a lot to free an enterprise from the Tyrrany of Infrastructure, XaaS introduces new complications as the overall technical environment is much more complex; Digital also means that enterprises need to learn to move quicker with disciplined lean practices that enable continuous change. New IoT based models also bring new challenges of scale.

So the new breed of Digital Service Partner needs to position itself to avoid RUSC and focus on Assured Value, Integration and Speed. Where: 
  • Assurance covers secure and consistent delivery of change and operations;
  • Value focuses on user and customer experience, insight and the right quality at an affordable price;
  • Integration deals with the complexity of identity and integrating multiple sources of XaaS services as well as working with multiple SI partners and in-house development teams to deliver joined up services;
  • Speed addresses agility, continuous change, innovation and responsiveness to changing business and technical opportunities and risks.
Such services are likely to include 3 key elements:

  1. a Foundational Use of IT Access Service - everything needed to deliver a user device centric service, e.g. smart phone, pad, laptop and supporting network, gateway, office automation software, storage, print, peripherals and anti malware based services.
  2. a Service Integration And Application Management Service (SIAM) - which integrates and delivers services on a Hybrid Cloud basis. This is likely to include Architecture Management (AMO), Programme Management (PMO), Service Delivery (SMO), and Security Operations (SOC and Security Operational Processes), as well as Activity Based Costing (along TBM or OBASHI lines).
  3. a Lean System Integration Service - which can provide specialist development and implementation skills, but also embraces partnering with internal and 3rd party partners and provides support for the full range of Agile and DevOps processes needed to deliver continuous change.

Naturally there will be other more specialist services which may come too, e.g. computer forensics and advanced threat intelligence, Fleet Management for IoT devices, or managing innovation communities as innovation goes social. But these will be value adds building on a core foundation.


Tuesday, 27 September 2016

GDPR Bricks and Mortar Defence or Digital Viking's Inspiration

GDPR - the General Data Protection Regulation - is the next wave of personal data privacy regulation from the EU and is expected to go live mid 2018, i.e. pre-Brexit. This generally tightens up privacy requirements in a number of areas and has been a theme of discussion at a number of Cyber Security events this year, including today's InfoSecurity Magazine event.

Anyone interested in "Things Digital" should ask themselves, will this act as a regulatory defensive wall for old fashioned Bricks and Mortar / Industrial Age companies to shelter behind, or is it a new discipline or challenge for digital Vikings to embrace?

A couple of today's speakers made some interesting observations and comments: 
  • GDPR means that you need to know the What, Where and Why of Personal Data, especially customer data;
  • Regulation should not drive data security, Security Should Drive Regulatory Compliance;
  • There is a strong case for Digital Companies to adopt Social Digital Responsibility as Part of their Brand.
In a way, it should be easier for purely Digital companies to do this, as they are mostly starting from scratch with few of the problems of IT Estate Sprawl that many established companies have, with legacy systems, infrastructure and the typical complications inherited from previous defunct strategies as well as mergers and acquisitions. 

Also, in a previous blog, I mentioned that many digital companies actually regard this data as part of their IPR. So addressing GDPR (& other jurisdictional requirements) should be core to their business activity. Although future approaches toward collection and explicit consent may have to be sharpened up to meet the new requirements.

The implication is that Digital company that plans and builds Privacy Protection in from Day 1, will actually be building its own competitive advantage over traditional companies who mainly will be playing catch up.

Tuesday, 16 August 2016

Are You Ready for Digital Disaster?

We all know that we should have a Disaster Recovery / Business Continuity Plan. Yet most of us have worked in businesses where this is a convenient afterthought. Even when businesses have them, active testing of them is often patchy at best. Many businesses aspire to do this at least once a year, fail to meet this target and even if they do, they then brush a lot of things under the carpet.

For many years the key concern has been a major fire, followed by lesser concerns about flooding, terrorist attacks and other major natural disasters. Statistics suggest, that in the UK the typical rate of major fires is around once per hundred years of a data centre's operations. This is actually a very high high rate. Although in actual practice the more frequent major incidents which disrupt operations tend to be caused by more mundane things such as loss of power from the grid, major network switch failures within the the data centre or loss of telecommunications coming into a data centre.

Many businesses have been content to make minimal investment in preparations and accept the risk. They have mostly got away with this despite urban myths about the high percentage of businesses, suffering major incidents, which go out of business. Though if you personally have ever lived through such an incident, you would not want to do so again.

This complacency is looking increasingly out of place as enterprises go digital. For one thing, operations become impossible to deliver with failure, for another the increasing frequency of "Cyber Attacks" means that the old cosy assumptions are no longer valid and not only may operations be disrupted but valuable information or IPR stolen and an enterprise's reputation destroyed along with customer confidence.

The increasing pace of change inherent with modern digital business, based on Agile and DevOps styles of continuous change, also mean that an annual test is laughable as recovery plans will never be up to date if annual refresh thinking continues to dominate. This will also exacerbated by use of multiple SaaS, PaaS and IaaS services. As although each one used may increase the theoretical resilience of the enterprise's systems, it also complicates the inter-dependencies between them.

Business and IT Management Teams need to actively engage in preparing for major disasters and incidents. This means several things need to be addressed:

- capturing all changes to the systems and process lanscape, especially adoption of SaaS services, so that current architecture is documented, understood, risk assessed and continuously revised in recovery plans;
- regular incremental testing of recovery plans to address changes to the systems landscape;
- conduct of scenario "war games" to evaluate responses to different types of threat, taking into account that under Murphy's Law key people may be unavailable when a major incident occurs;
- regular review of major 3rd party services that the enterprise relies upon for the suitability their response capabilities and likely behaviours;
- media training of all senior executives and managers who may be called upon to represent the enterprise in the event of an incident, taking into account that some of them may have been incapacitated by the incident or away from the business.

Not many of us work in enterprises where all this happens, but most of us need this now.

Thursday, 9 June 2016

The End of Digital Adolescence

Are we growing from just talking about it to doing it?

Over the last 18 months I have attended a number of events with CxOs and other senior stakeholders from many different companies.

A key theme has been that we are all being pressed to do something, as we all work in organisations where customers, employees, business partners and senior managers expect us to be doing something and most of us have.

A key concern has been that we are all scared that we have missed something. Is there an "Unknown Unknown" that will emerge to destroy the new value that we are trying to create. We have all been thinking a lot about the subject and I think that collectively we have come to the following conclusions:

The 3 technologies that we have to get to grips with are:
  • Identity Management (and subscription)
  • Encryption
  • Integration
The things that we should worry less about are:
  • Security of the various PaaS and IaaS offerings, as the vendors who supply them spend a lot more time and money securing them than most user enterprises can dedicate or afford;
  • Traditional technology selection approaches and worries about vendor lockin - the richeness, utility and value of the continuously evolving offerings obviates the need.
The things that we need to get good at are:
  • DevOps - so we can move at Digital Clock Speed
  • Service Integration (or SIAM) - so we can run this seamlessly from end-to-end
  • (agile) Enterprise Architecture - so we don't lose track of what we've got (where we are spending money) and what we want to achieve in the future
  • Security Governance - again so that we
The conversations that we have with other stakeholders in our businesses should focus more extensively on Business Value, rather than infrastructure maintenance and "keeping the lights on". But we also need to establish a different approach to projects, applications and investments, as the traditional ROI based Capital Appraisal, Invest and Forget model does not fit the continuous evergreening needed to sustain Digital Assets and keep them relevant in the face of customer demands.

There are plenty of other things as well, each worthy of a blog of its own, but this is the gist of all these discussions and power breakfasts.