Showing posts with label infosec. Show all posts
Showing posts with label infosec. Show all posts

Thursday, 13 August 2015

Infosec? What Country Is That?


By Alina Stancu (Marketing Coordinator, Titania)

About the Author

In this comparative article, Alina Stancu, Marketing Coordinator at Titania, talks about the struggles of discussing information security to outsiders and the similarities she experiences discussing her country of origin, Romania. Alina joined Titania whilst completing her final year studying; Advertising, Marketing and Public Relations at the University of Worcester. Alina has since become a valued member of the marketing team and during her time at Titania has developed an enviable amount of knowledge about the industry and the importance of cyber security.



I am familiar with the pains of discussing information security with “outsiders”, thanks to my Romanian origins. Explaining my country to non-Romanians is not much different to talking to non-technical people about security. Everyone has a vague idea of what it is, everyone knows a couple of standard stereotypes (thank you, Hollywood!), everyone has some expectations of what its inhabitants should look like.

Note: All the questions below have been posed to the author at one point or another, by various friends, acquaintances, strangers on the bus. You always start the conversation with the premise that no one will know what you are talking about, so you must accommodate the interlocutor and provide some context about the information security industry, clarify it’s a self-standing profession, and not to be confused with the more generic IT-support.

Interlocutor 1: So, is Romania a part of Russia?

Alina: No. Part of the former eastern European communist bloc of countries, but that ended in 1989, with the revolution. We’ve been aboard a merry democratic transition ever since…

Interlocutor 1: Ah… so it was part of Russia?

Alina: No

Interlocutor 1: I don’t get it. Sorry, I wasn’t very good at Geography. To be honest I don’t know much about Romania. It’s one of those places that you know they exist, but you don’t really hear much about.

Alina: That’s ok. It wasn’t ever part of Russia. We have lost Moldova (which is occupied by Romanians) to Russia, but Romania was never assimilated.

Interlocutor 1: Is it civilised? Do you have normal amenities?

Alina: What’s a normal amenity?

Interlocutor 1: Don’t know… electricity?

Alina: Mhm. We kinda need it. For, you know, essential living arrangements… like heating, lightning, Internet. Don’t get me wrong, we like living in caves heated by fire, as much as the next guy, but once in a while the iPad runs out of power.

 ***

Then, the dialogue seems to get a little more on track as people start recalling some names, or stories they may have read in the news. Hacking stories are not necessarily the most high-profile, but they do manage to draw some interest, awe or fear. Hollywood does drive some form of cyber awareness, at least. Problem is Hollywood also has a knack for exaggerating.

Interlocutor 2: Ah! Romania… I remember… Ceausescu. And that vampire… Dracula, right? He was some kind of a leader or king in your country, wasn’t he? Was he really a vampire?

Alina: Leader, yes. Vampire, not quite. Hollywood hasn’t got a great track record with sticking to facts and accuracy.

***

Then follow the natural confusions between the bad guys (cyber criminals) and the good guys (ethical hackers). Changing the perception that not all hacking is bad hacking and explaining that there is an actual need for ethical hackers (or penetration testers) to use their knowledge for good is always a challenge.

Interlocutor 3: I read that there are lots of Romanians begging on streets, in many European countries. Doesn’t make your people look very good. You see them in the news. I have to say it is a bit worrying.

Alina: Only a small proportion of the ones reported in media are actually Romanian. However, semantics, misleading information and lack of interest result in a wide-spread confusion outside of Romania’s borders.

Altogether, we have good and bad just like anywhere else, but when you’re an immigrant, you get scrutinised under microscope. Social issues get magnified to suit political agenda, and you find yourself in a very generic box with the label “dangerous” attached to your forehead.

***

Next, you explain the language. The technological lexicon can put off even the most patient, well intended ear. Most of the lack of interest towards cybersecurity stems from the intrinsically discombobulating vernacular attached to the industry. All the while, the more popular siblings such as mobile apps, web clients, social media have entered the colloquial jargon thanks to necessary integration into people’s professional and social lives. You would be hard pressed today for example, to find people not knowing what Microsoft Office is, or how to operate Skype.

Interlocutor 4: What kind of language do you speak in your country?

Alina: Romanian

Interlocutor 4: Is it like Russian, Polish? It sounds a little like it.

Alina: Haha! More like Spanish and Italian rather. Romania is part of the countries speaking 
Romance (or Latin) languages

Interlocutor 4: What did you say it’s called?

Alina: Romanian

Interlocutor 4: I don’t believe you.

Alina: …

***

Finally, gently break the expectancies of what the information security professional should look like. These particular stereotypes are a direct result of media portrayal of “geeks” as socially awkward people, mostly men (which in turn reflects the gender imbalance the industry deals with), that have little else in their lives aside from computers and gizmos. Is there any wonder that future generations may not want to be associated with these negative portrayals?

Interlocutor 5 (knowledgeable in ethnic physiognomy): I like Romanian girls. You don’t really look Romanian.

Alina: What does a Romanian look like?

Interlocutor 5: More blonde, with paler skin… I mean you obviously have a light skin, but you are not blonde, are you?

Alina: No. Neither is a large proportion of my co-nationals. But go on, what else should a Romanian look like?

Interlocutor 5: Don’t know, but they are usually very pretty. Alina leaves pondering over her national identity… and over her hair colour.

***

Much like a state, the information security industry has a different language, interesting people, its own pet hates, achievements, heroes and villains. That is not to say that it should remain marginalised and isolated from the rest of the society. Ignoring computer security is no longer a choice anyone can afford to make.
A country’s need for tourism, foreign policy and defence drives the national brand marketing. For an industry, bridging the communication gap means patience, cutting through the jargon and breaking stereotypes through education.

There is another problem that plagues the industry, and that is the “tired professional”. The IT professionals that after many years spent working with IT illiterates have got fed up with explaining and prefer to keep the strangers outside. Putting this in the same perspective of encountering people from all over the world, should you stop explaining to people where you come from just because they don’t know? Should they stop explaining to you about things you don’t know? Is there any point in harvesting knowledge, if it can’t be shared with others?

Friday, 31 October 2014

#InfosecHeroes Nominate & Donate

What is #InfosecHeroes?

Titania’s CEO, Ian Whiting was recently named this year’s winner of the “Personal Contribution to IT Security” in the Computing Security Awards ceremony. While this has been a great honour for Ian and a very proud moment in Titania's history, it also made us realise how many more hardworking individuals in information security there are out there who deserve recognition for their efforts. That is why we created #InfosecHeroes; because sometimes even a thank you and a mention go a long way to recognise people’s efforts!

How does it work?

You nominate an information security professional that you consider has brought some outstanding achievements to the industry. You share it over Twitter including the hashtag #InfosecHeroes and the name / handle of the elected hero and make a charity donation. Any donations are entirely up to you, but we would be really grateful if you could help us reach our goal of raising £500 for WhiteHatRally.

Have you been nominated? Congratulations – someone somewhere has learnt something from your research, benefited from a tool you developed, or has found your conference talks really inspiring! Why not give something back with a nomination and a donation? 

If you don’t like the idea, that’s fine too, but you might like to be a Barnardo’s hero by making a small donation to WhiteHat Rally. As the industry’s representative charity we decided all funds raised through this campaign should go to them.

We will make the first donation of £25, divided among 5 teams which will take turns in nominating their own #InfosecHeroes! Follow us @TitaniaLimited to find out who we chose…


Thank you, infosec community! 






Monday, 28 April 2014

EU Cyber Directive – Guide for SMEs

Source: wikipedia.com
The new EU cyber directive (officially known as NIS –Network & Information Security) is putting compliance issues at the front of concerns for the information security industry, if the keynote speeches at Infosec Europe are anything to go by. Also more industry-specific seminars have been organised, seeking the help of cyber security experts and information security consultants, in order to understand  how these new reforms and legislation will affect them.

Naturally, SMEs are less excited at the prospect of an extra layer of compliance on top of their administrative regulations. Perhaps worse than the extra layer of mandatory compliance is the extra layer of confusion surrounding the directive. As the penalties announced will hit the budgets of recovering businesses hard, it is only natural that the small and medium business sector will want to understand and adjust to the incoming law. Here is a look at a few key aspects of the legislation that will hopefully shed some light on the issue:

1. Cyber security strategy plan
The UK government gave us a head start with the Cyber Essentials Scheme which, devised to offer best practice guidance, actually does what it says on the tin; by providing help to businesses in a non-intrusive manner. It is also a good anticipative practice to prepare organisations for the more incisive Cyber Directive.

2. The government body
The ICO (Information Commissioners Office) already announced it does not want the extra strain on the budget and no other national authority has come forth to take the responsibility of collecting information from SMEs and reporting back to ENISA. Until the issue gets further clarification, it is only a matter of waiting.

3. Introducing the DPO (Data Protection Officer)
It wasn't long ago that the CISO became a role in business, and it got a fairly begrudging welcome, as some CIO's perceived this new role as a threat to their responsibilities. Now the Cyber Directive will introduce the rise of the DPO – Data Protection Officer, rumoured to have an arching role over both the CIO and CISO in an organisation. The DPO will also take on the less desirable role of the “no” guy within the organisation when any innovative process involving data will be stifled under the “cyber directive” framework.

4. Auditing does not have to be painful
Although audits should happen at least once a year, lack of enforcement and high costs mean that organisations view it about as expectantly as a visit to the dentist. It doesn’t have to be painful though.  If you can’t find anyone who simply loves trawling through compliance policies, keeping up with updates and de-cluttering industry-specific standards, then you could use a compliance auditing tool such as Paws Studio for regular monitoring and a trustworthy penetration tester to check your security twice a year.

5. Better cooperation between management & IT
The relationship between management and IT does need to improve, otherwise (as breach examples happen time and time again) the business and – most importantly – the customers end up suffering.

6. The CERT team
Although it sounds more or less like having a SWAT team hanging around in the IT department, the Computer Emergency Response Team refers to one or more people assigned as the first point of contact when something goes wrong and putting together a mitigating plan. As far as security and compliance policies go, this is a fairly sensible measure. It’s the type of measures that can bring about some sense of control and reactiveness amid the havoc and distress of a cyber-incident.

Source: wired.com
What’s an SME to do?
Unfortunately it does not look as if the law will be bringing in savings of billions to the ones that need it most, though it may bring a better security education and increased awareness. However at least for the time being we must wait and see what the European Parliamentary elections (22 – 25 May 2014) bring forth, and to see if the proposed legislation survives the dissolution of the current Parliament.



Thursday, 20 March 2014

Impressions of CRESTCon & IISP Congress 2014

CRESTCon & IISP Congress 2014 was a great opportunity for our CEO, Ian Whiting, to catch up with industry friends, meet lots of attendees who are keen advocates of our products, as well as speaking to several exhibitors who are also users of our software including HP, Ernst & Young, Nettitude, GDS and BT.

The exhibition was a good opportunity for us to provide inofsec professionals with a preview of some new major features soon to be releases in Nipper Studio. Our stress ball giveaway also proved quite popular with the pentesters – it seems they are a stressed bunch, who would've thought?

But instead of just giving you our own opinion of how the show went, this post brings together the views of those who attended, exhibited and kindly expressed themselves via the live news stream – Twitter. 




...Quite!


Andrea Simmons from HP also highlights in her presentation the amusing results of a much-debated 'study' by VoucherCloud



Adrian Davis (ISC2) makes a valid point about insider threats. Morrison's breach was indeed caused by a disaffected member of staff.




Selex ES steered people towards 'their very own' Robin Frewster security expert:

... and here's the consensus.



The Nettitude team

'Fuzzing' with Andy Davis of NCC Group:



Simon Clow puts it into context...


... and PwC agrees...


... while introducing James Campbell's stories on threat detection and response.


Finally, our own team - Ian Whiting below - shares a word, and a stress ball, with Gotham Digital Science



Hope this has inspired you to book tickets for next year's event. The CRESTCon & IISP Congress is definitely the right place to be for any infosec professional; whether beginners or more experienced, the conference has something to offer everyone.


Monday, 17 March 2014

What Makes CRESTCon & IISP 2014 The Must-Attend Event For Every Infosec Professional?


Source: crestcon.co.uk

The Exhibition

The exhibition brings tools and information to the hands of the visitors, with the chance to experience the products live, try the demos and clarify any questions directly with the providers. 


Source: CRESTCon 2013 via flickr.com


The Conference

The thing that sets CRESTCon apart from other trade shows is that it addresses different audiences via two streams. 

Stream 1 is targeting security consultants, researchers and those directly involved in testing or defending information systems. 

What's the talk of the town?

Some of the security experts presenting will be sinking their teeth in a few new topics. The audience will hear about security cameras and the security risk they can pose if infiltrated by bad actors, from Mike Sloss from Thales. Andy Davis, Research Director at the NCC Group will talk about Zulu, an intuitive and flexible fuzzing tool. 

Point of interest: Simon Clow from Context discusses iLO (Integrated Lights-Out management) and the security considerations for remote management interfaces. 

The rest of the talks are centered around the evolution of cyber crime with consistent provisions of case studies and research repositories.


Source: CRESTCon 2013 via flickr.com


Stream 2 is aimed at the wider public in the infosec community, including management representatives and risk and compliance officers, while featuring talks on career development opportunities. 

What about the career focus?

Ray Stanton (BT) sounds interesting:  "You may not like all that you hear, but Ray will stimulate thought and invoke critical debate". Andrea Simmons, from HP talks about the importance of understanding the breadth and depth of the infosec industry. Undermining it, she emphasises, could pose real risks to the community. 

The evolution of threats, incident-response, security awareness, the talent pool, tips on engaging at board-level and employer perspectives are among other topics. 

Point of interest: Rob Carolina, legal expert with the Origin law firm, tackles the ethical debate stirred in light of the Snowden scandal. 

The great thing about these presentations is that they take a pragmatic approach to security issues, and the speakers talk about their own experience as opposed to theoretical concepts of security. 


The Catch-up


It's nice to be out of the office once in a while, but it's even nicer when you get to meet old acquaintances, people who were colleagues at university, people you worked with, people you shared a beer and a hacking tip with a while back. Industry events are a great way to combine work with a friendly catch up. 


Source: CRESTCon 2013 via flickr.com


Titania's CEO, Ian Whiting and Andy Williams, Head of International Development are getting ready to attend the CRESTCon & IISP Congress on the 19th of March. They can be found in the exhibiting area, so if you are attending, drop by, say hello and watch a demo of our award-winning products Nipper Studio and Paws Studio

Titania is a proud sponsor of the 2014 edition of CRESTCon & IISP.


Source: crestcon.co.uk
Hope to see you there!

Thursday, 27 February 2014

3 Reasons For Which You Shouldn’t Have Missed Vienna 2nd CEE Cyber & Information Security Show

The Vienna Cyber & Information Security Show has taken place without a glitch, aside from an overcast spell maybe. Our team has been there since Tuesday to answer questions, showcase our products and deliver talks on cyber security and compliance auditing. 



So what makes Vienna a show that shouldn’t be missed by infosec professionals as well as those who want to find out about the industry?



1. The People It offers the opportunity to connect and forge relationships across borders and cultures. For those who are looking for networking opportunities and for a way to meet the right connections this is the place to be. Vienna focuses in particular on European partnerships and increasing awareness of cyber security in Central and Eastern Europe.

Not only can you meet the delegates, ask questions and get bespoke advice tailored to your needs, but you also get first-hand knowledge on their products and services, exchange ideas and get feedback.

For those who have been in the business a bit longer, this is a great opportunity to catch up with friends, old colleagues and rekindle business relationships.

2. The Presentations You are not there just to meet old friends and make new acquaintances. The spectrum of organizations and software vendors is wide enough to satisfy all needs and requirements in terms of information. From network security auditing to compliance and forensics; there’s something there for everyone. Each one brings specific knowledge and in-depth expertise to the community.  

Andy Williams, Head of International Development at Titania has talked about cyber security, compliance auditing and the new alignments to PCI-DSS 3.0 along with the recently announced NVD brought by Nipper Studio 2.3.

3.  The Latest Trends As mentioned above, there is a wide range of organizations and individuals who are keen to bring the latest trends to the conversation, by showcasing their products.

Here’s a glimpse of what was on show:

Source: Twitter.com

Source: Twitter.com

Source: Twitter.com












The bonus of course is that it’s all happening on the backdrop of a bohemian European capital. Without losing the goal of the visit, you can always wind down with a coffee on one of Vienna’s cobbled streets.  I hear Café Central, Café Sperl and Kaffee Alt Wien are very popular, but don’t take my word for it; why not go and see for yourself!