The Emperor’s New Clothes 2.0

Exposing the malware that is killing cybersecurity.

By Eh’den Biber

 

 

Malware

In the past years a new malware has been slowly yet steadily taking over our world. It spreads like wildfire throughout our society, corporate and governmental world, and by doing so it increases the probability of our annihilation. It morphed and evolved, most of our infrastructure is now compromised, and yet most people don’t even recognise their infrastructure is as well.

 

This is the story of the malware, which started in 1837…

Continue reading

No Expert, No Cry

Why you shouldn’t trust (awareness) experts, what should you trust instead, and my new year resolution.

By Eh’den Biber

(see the end of the post with the update…)

Prologue – SANS

During the SANS European awareness summit, I’ve ended up in an interesting debate on twitter with one of the attendees (John Scott). The debate was on the observation I made that science was not part of the agenda in this major awareness summit. There was not a single scientist on stage to talk about their breakthrough research, and none of the tweets about the event (#SecAwareSummit) included any science in them.

My observations didn’t go that well with John, who seems to have taken it a bit personal. To show me I was  wrong he mentioned that Jessica Barker gave a talk. Yes, she did, and yes: she’s a (civil design) doctor, and I barely finished Kindergarten.

When SANS finally posted the slides from the event (including the workshops that occurred before), it seems that the only one who provided external references in their slides was Jess (well done). She mentioned 5 academic papers (from 1996, 1999, 2008, 2008, 2009), one reference to TED talk (2012) and one book (2017). Only one of the research mentioned was focused on information security (2009, Self-efficacy in information security: Its influence on end users’ information security practice behaviour), it used social cognitive theory, and the results suggested that simply listing what not to do and penalties associated with a wrong doing in the users’ information security policy alone will have a limited impact on effective implementation of security measures.

I’ll let Iago express my feelings about that one:

Show Me the Science

Continue reading

Uber and Under the Breach

Everything you need to know about the Uber data breach, Why Uber is the Chris Brown of the cyber economy, and much more…

[Updated 23th Nov 2017 – see “Cover-up?” Section + afterthoughts]

Sleep

Darn, I really wanted to sleep, I really did! I had to work on something till late tonight, already got total upset by 4pm, and when I finally ended it near midnight, I checked twitter and darn, Uber been hacked. “What the heck, they fired Joe Sallivat, their head of Information security and Craig Clark, (the?) director of legal? Wow, I must write about it”. Luckily tomorrow I need to wake up early then usual. Darn lucky.

But this is important.

Flashback – I think it’s 2013. I’m speaking with Alex Hutton during a BruCON break. At some point Alex tells me something, that for some reason got engraved in my mind forever: “If you’re will not know how to measure risk and communicate it to the board you will not be CISO for long.”

Darn right.

Continue reading

#CyberBlind

Ridiculous information security salaries are the symptom of a bigger problem. Why salaries and job ads are superb indicators to your organisation cyber security maturity, how it can be improved, and why your organisation won’t do anything to fix it.

By Eh’den Biber

October been an extremely hectic month for me. It’s been a while since I travelled and worked in so many countries, that at some point I slept in 5 different places during one week. Amazing and exhausting at the same time, see post photo which was taken along the way.

When I came back, I decided to see if I can identify any shift in the job market, to see if I can make my wife happier by finding a role which doesn’t requires me to travel so much. Sadly, the results are grim.

Over the years I’ve developed a sort of a mentalist skill, and after 5 minutes into the job interview I could already tell the interviewer things I shouldn’t have known, such as the fact they recently experienced a severe breach, auditors’ blues, or simply someone just left in a hurry.

This brings us to the question – why? How come the responsibility and accountability of a person who takes such a role is not being rewarded in the right manner?

HR

HR in most cases have no clue about the role they asked to recruit for, and yet they are supposed to filter for the hiring manager. They then subcontract the hiring to a group of agencies, some of which have no clue what they are hiring. I’ve been asked recently by a recruitment agency manager “What is a CISO?”. Enough said.

Take home message to hiring manager: Speak with the recruitment agencies, ask for recent references, meet them, or use the ones you trust.

Continue reading

GDPR “Unknown Unknowns”

The art of privacy, and why what you don’t know (about the GDPR) WILL kill you.

By Eh’den Biber

 

Introduction

A few years ago, I had a colleague that was about to depart on a flight to a lovely vacation with his wife. As the airplane was waiting for the signal to lift off, my colleague wife started to scream. I mean REALLY scream. As my colleague wife had taken many flight before, my colleague had no idea what the fuck is going on (forgive my French). Long story short – airplane went back to the terminal, my colleague and his wife were being taken off the airplane, severe sedatives were used, and instead of a lovely vacation my colleague spent the next few days in a mental institute seeing his loved one going via hell. This whole thing followed a long recovery process, and almost broke him to pieces as well. Continue reading