Tuesday, March 17, 2015

Your guide to finding good IT security talent

Information security is a career field full of many challenges.  One of the greatest strategic challenges most organizations face is finding qualified information security talent.  This is partially due to a shortage of qualified and experienced labor, but also partially due to the difficulty in assessing candidates during the interview process.  My thoughts on this topic in my latest piece in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/human-resources/2015/03/your-guide-to-finding-good-it-security-talent.html.  Hope you enjoy.

Wednesday, March 11, 2015

Don't Forget the Rest of the World

I've always found it interesting how in a global company, the security program can be overwhelmingly focused on the home geography of the company.  It's important to remember the rest of the world, especially in security operations: http://www.securityweek.com/security-operations-dont-forget-rest-world.  I hope you enjoy this piece and find it helpful.

Monday, March 9, 2015

Videos of the Narrative-Driven Model

People often ask me to elaborate on the topic I am the most passionate about: "Security Operations: Moving to a Narrative-Driven Model".  Of course, there is my piece in SecurityWeek on the topic (http://www.securityweek.com/security-operations-moving-narrative-driven-model), but that merely scratches the surface of a deep topic.  I am always more than happy to discuss the topic at length, but there are also a few recordings of talks I've given on the topic that are available.  Each of the talks targets a different audience, and as such, they vary in length and technical depth.

Video of my talk on "Security Operations: Moving to a Narrative-Driven Model" at the 4th Annual Cyber Security Conference, Tel Aviv, Israel, September, 2014: https://www.youtube.com/watch?v=m0BO_NlFtkA

Video of my talk on "Security Operations: Moving to a Narrative-Driven Model" at DeepSec 2014, Vienna, Austria, November, 2014: https://vimeo.com/117110626

Video of my talk on "Security Operations: Moving to a Narrative-Driven Model" to the CU Boulder Master of Infosec Colloquium, Boulder, CO, USA, March, 2015: https://echo360.colorado.edu:8443/ess/echo/presentation/36beff23-8aad-40b5-ab65-d4623e7d80d0

I hope that the videos do justice to what I consider to be an important concept for the future of security operations.

Tuesday, March 3, 2015

Good Things Come in Small Packages

Recently, during a discussion on Twitter, Richard Bejtlich asked me to blog about my experiences working with the Estonian Cyber Defence League (Eesti Küberkaitseliit).  I visited them for a week back in 2009, and I was quite impressed with what I saw then.  I have no doubt that they have made great progress in the six years since.

The lesson I would take from my time in Estonia is that good things come in small packages.  Small, technologically advanced countries enjoy a few advantages in information security.  Here are just a few of them:

Being Nimble: Information security moves at a relentlessly torrid pace.  The threat landscape changes constantly.  A hulking bureaucracy has no chance.  A nation that is small, while having fewer resources, can also be quite agile and use those resources more efficiently.

Recruiting: Small countries generally have small information security communities.  And within these communities, everyone usually knows everyone — or at least everyone worth knowing.  This can lend a huge advantage to recruiting efforts for a Cyber Defence League.  It reduces the time and expense of finding the right people, as well as the risk of making the wrong call in recruiting.

Training and Education: Small countries generally have much more centralized education systems at all educational levels.  This lends itself well to both influencing curriculum, as well as to identifying talent.  Facing a shortage of skilled information security professionals?  Grow them organically.  This is much easier done in a small country than a large one.

Visibility: Before a given asset can be protected, we have to know where it is. Because smaller countries have fewer assets in general, it is much easier to keep track of them.  Want to protect all of the electrical substations or network ingress/egress points in a small country?  Probably doable.  In a large country?  Good luck finding all that stuff.

Humility: Small countries generally understand that they cannot go it alone.  As such, they are much more likely to learn from others and work collaboratively as part of the larger information security community.  They are also much less likely to have a “not invented here” syndrome.  This comes in quite handy when building and operating a Cyber Defence League faced with the tall order of protecting the nation’s critical infrastructure.

Implementing Changes: In a small country, once a decision has been made to implement a change, it is generally much easier to do so.  There is simply less bureaucracy, friction, and inertia to overcome.  That can make it much easier to bring about meaningful change within a realistic amount of time.

These are just a few of the many reasons good things come in small packages.  Although larger countries have more resources than smaller countries, they can learn a lot from their smaller counterparts.  Something to think about if you are involved in cyber defense in your home country, wherever that may be.

Tuesday, February 24, 2015

The House Always Wins

Why is it that all we ever hear from security organizations is good news, yet problems and challenges still persist within those same organizations?  It's the same reason we hear all about Las Vegas wins, yet the casinos stay in business.  Curious what I'm getting at?  Have a look at my latest piece in Security week entitled "The House Always Wins": http://www.securityweek.com/house-always-wins.

Thursday, February 19, 2015

Penny-Wise, Pound-Foolish

It often amazes me how many people don't understand the value in building and maintaining long-term relationships built on trust.  To some people, if there is a dollar to be made in the moment, or a favor to be extracted at the current time, that trumps all.  Of course, behaving this way erodes trust and sacrifices any chance of an enduring relationship.  It's a penny-wise, pound-foolish way to behave.

In the information security realm, this is all the more true.  Most of us spend years building and maintaining long-term relationships because we understand that the information security community is built on trust.  It can often be tempting to sacrifice this trust for a short-term monetary return or a favor.  But, in the long run, this is a foolish way to behave.  After all, at the end of the day, our relationships and our reputations are essentially our careers.

As the old saying goes: Fool me once, shame on you; fool me twice, shame on me.  There is much truth in this.  We all know what happens when someone optimizes for the short-term.  The next time that person calls, no one answers the phone.  We are all human, and we all err from time to time.  When we err in this manner, we should own up to it when called on it.  Believe it or not, that actually helps restore trust.  Certainly moreso than dancing around the truth or trying to distract those who are questioning us.  That seldom fools anyone, despite how politely they may behave in reaction to these tactics.

The information security community is close and tight-knit.  None of us can afford to have no one answer the phone the next time it rings.  It pays to think about that the next time we consider substituting short-term gain for long-term trust.  It's penny-wise, pound-foolish.

Tuesday, February 17, 2015

5 ways cyber threat intelligence can improve your security

My latest piece in The Business Journals entitled "5 ways cyber threat intelligence can improve your security" is out.  Threat intelligence is a hot topic these days, but how can organizations wade through the hype and into the intelligence sea?  How can we make order out of the chaos?  My thoughts in this latest piece: http://www.bizjournals.com/bizjournals/how-to/technology/2015/02/how-cyberthreat-intelligence-can-improve-security.html.  Hope you enjoy.