Monday, 2 October 2023

Stereotypes, context and situational awareness.

One of the things most likely to put me into a strop is being told that "you can't do that!", particularly when such a statement is accompanied by absolutely no rationale as to why not. One common example of this is whenever I am told, or hear, or read, blanket statements about what CISOs (or other senior leaders) are, or are not, interested in.  "You can't say that to a CISO, they're just not interested". Oh really?

I have a few issues with such a blanket statement. Firstly, lived experience. I'm not a great fan of being told that some of the things I've done didn't happen. Secondly though, don't you think it's a bit simplistic to stereotype all CISOs as having the same interests, with the organisations that they work for all being in the same position with the same dynamics?  Consider the simple chart below:


You probably already know where I'm going with this. You can plot both individuals and organisations against these axes. There's also a time dimension - for example, a CISO may need to come in to fix a broken security function before then settling into a steady state. Individuals will often be more comfortable in specific quadrants - some folks love the challenge of driving difficult change, others love maintaining order.  There are no value judgments here. Likewise organisations: some will be in a good state and looking to keep things ticking over as they are, others will be in the middle of the churn of a fundamental transformation. It helps when you have a match between the leaders and the organisation! But that's a different topic. Anyway. Depending upon where the CISO is sitting at the time of your conversation then you may well find that they are interested in different topics. Clearly, going to a meeting with an assurance-focussed CISO, comfortable with the status quo in a stable and mature organisation, and trying to talk about the practicalities of moving towards zero trust, security by design or devsecops is unlikely to go well. Mention of DAST, SAST and SBOMs may well induce a few eye rolls. However, if you're talking to a CISO that has staked their personal reputation on delivering just such a transformation, don't you think they may have at least a little interest in how they could protect that reputation by talking through the "how" of how such a transformation can be achieved in the real-world? I'm not suggesting we have to talk 0000s and 11111s, raw TCP/IP or any other deep technical jargon relating to security transformation (although some modern CISOs have grown-up in the industry and it's not necessarily an alien tongue to them), but we certainly don't have to limit ourselves to platitudes and quotes by our favourite analysts.  Yes, there are some commonalities in the role of a CISO; the need to be able to manage upwards, the need to be able communicate with (and influence) business stakeholders, the need to be able to manage budgets, the need to be able to nurture and shield your team etc. However, if you find yourself being told that "the CISO won't be interested in that", then try asking the person telling you that whereabouts on the chart they'd place the individual CISO they have in mind. They may be right. But they may not be. It's probably worth finding out.

Friday, 14 April 2023

Zero Trust - a little light grumbling.

I think I've reached the conclusion that if I haven't annoyed at least 5% (arbitrary figure) of my audience when talking about Zero Trust then I haven't done my job properly. Too many competing definitions, too many strongly held sacred beliefs. Naturally the next step is to see how many folks I can annoy on the Internet :). So, definitions for starters - I use NIST SP800-207 and the CISA ZT Maturity Model (now at v2) as my baseline. Vendor-agnostic. Analyst-agnostic. Wide in scope. Great fun for annoying folks who insist that ZT is purely focused on Identity or the Network*.  I do then try to simplify the topic:


⁌ every access request starts from a position of zero trust (applies to all entities - humans, devices, services)
⁌ authorisation is granted based on dynamic context (risk-based)**, ideally per request
⁌ assume breach - of user ID (including machine or application service ID), access device, transport network.

What does this give you? Well, you've done away with the arbitrary distinction between "inside" and "outside". You now need to do something about those legacy flat networks. Reduce your blast radius! You can also now give your users access to the business applications they need, wherever they (or those business applications) may be located.

You've also now got to do something about your machine (OT, IoT) and workload (VMs, cloud instances, containers, applications) entities so that a compromise of such entities doesn't mean easy traversal.

You're assuming breach, this means you should be embedding observability into your in-house developed apps and configuring everything else to generate the signals you need to automate and orchestrate those dynamic authorisation decisions.

In short, improved access for legitimate users, dynamic per request authorisation based on current context (including risk) for all entities and better visibility across your IT ecosystem, enabling faster detection and response.

I'm not sure why delivering those security outcomes remains a little controversial. Perhaps Zero Trust is just another one of those labels (like cloud) that rubs folks up the wrong way. Look past the label. Oh, and don't get too attached to specific definitions. Except the ones I like. Those ones are fine. 😇

*both key pillars to be sure, but not the sole focus.
**dynamic context - which is why your network microsegmentation is not really Zero Trust.

Thursday, 6 April 2023

Growing pains?

An interesting story here on the legal status of relying upon US-owned cloud services for the processing of law enforcement data - https://www.computerweekly.com/news/365534023/Scottish-police-tech-piloted-despite-major-data-protection-issues.  The conflict of such processing with the obligations stated within Part 3 of the UK Data Protection Act 2018 is something that Owen has been raising for a long time now [Disclaimer: I’ve known Owen for years – he knows his onions] and it is good to see these issues now being explored more widely.

For me though, this is part of a wider re-evaluation of the usage of the cloud hyperscalers. Consider also the context of financial services regulators across the globe expressing increasing concern about systemic risk and how the reliance on a small number of hyperscale cloud providers impacts upon the current push to improve operational resilience across that sector.  Speaking of resilience, how comfortable should we be with quite so much of our public sector and other providers of Critical National Infrastructure (CNI) services being fulfilled by the same limited pool of US-owned services?  There is increasing discussion of Sovereign Cloud approaches (e.g. https://www.capgemini.com/insights/research-library/cloud-sovereignty/) however, in reality, can such sovereign solutions compete with the hyperscalers? The experience of UKCloud, an early entrant into the UK cloud market suggests it is a rough ride for smaller players (they were placed into compulsory liquidation in October last year).  Should pure commercial considerations be put aside and Government subsidies made available to provide safe, legal sovereign cloud services?  Can any of the hyperscalers derive ownership structures that provide genuine confidence that their “sovereign” solutions offer sufficient protection from US over-reach via the Cloud Act?

So, am I saying that we should avoid the hyperscalers? As ever, it’s more complicated than that (is that framing taking over from “it depends” as the consultant’s phrasing of choice?). The advantages of cloud services remain – for many the infrastructure, security and physical hosting services offered by the likes of AWS, Azure and GCP surpass those available using existing technologies and skillsets.  They have greater budgets for innovation, greater elasticity and, these days, a growing pool of certified talent able to deliver value to cloud consumers – at pace. I do however think that there is a growing conflict between the needs of individual organisations and the needs of wider sectors, their regulators and wider society.  The former (quite rightly!) want the best bang for their buck whilst the latter are more worried about the “severe, but plausible” events that may lead to catastrophic consequences.  I remain a big fan of the capabilities that the likes of Microsoft, Amazon and Google offer their consumers.  I remain of the view that, in the majority of cases, a new, well-configured, cloud-native solution will likely be more secure than a solution delivered through legacy alternatives. But there are tensions.  Looks like we are approaching the point where those tensions need to be properly explored and informed actions taken by both regulatory authorities and governments to better balance risk and reward for the societal needs that they are there to protect and serve.  Thoughts?

Friday, 3 April 2020

Security hysteria - time and a place...

...which is not now.

Originally posted this on Facebook but it's probably more of a blog post!

I see a few people worrying about cybersecurity at the moment due to increased use of tools like Zoom. Let me give you a bit of context.

When a service suddenly becomes more popular (hello Zoom), it draws the attention of the security research community. Bug hunters find bugs. If having security bugs means you don't want to use a tool, I've got some very bad news about the other apps on your PC/Phone that haven't yet been subjected to (public) scrutiny...

Is Zoom "safe"? It's likely as privacy-safe as other Internet services - I'm typing this on Facebook for God's sake. Are you a national government? Are you a big bank? International criminal? No? Then if you find it useful you should make a decision based on whether you believe employees at Zoom will have any interest in eavesdropping on your friend group... but adopt usual Internet good behaviours: don't click on links unless you are confident they are safe, only download any client software from official sites, put passwords on your meetings so you don't get bombed, apply patches as they are released.  Am I guaranteeing that Zoom HQ will not get hacked? That the Zoom client will never get backdoored? Of course not. But at this point in time, I'd suggest seeing some friendly faces is perhaps worth a little risk?

Sunday, 9 December 2018

On Hybrid Warfare


Inspired by a couple of posts I've seen on my own social media feeds, I think we, as a cyber security industry, need to do more to explain what we mean when we talk about "hybrid warfare".

I thought I'd use the Paris riots as a demonstration of how hybrid warfare works in practice. Lots of people will claim that the Russians are simply making up falsehoods to cause division. That is emphatically not true. The #GiletsJaunes protests are a great example of their tactics, following on from previous operations around Black Lives Matter in the States and, of course, our very own Brexit. The social problems and divisions around BLM, Brexit and Gilets Jaunes are real - no-one should use the activities of hostile actors to pretend that the underlying grievances are not genuine. However - and this is the important bit - what the Russians do is to take those divisions and use them as a lever to further weaken their targets. How?  They'll produce propaganda, seed it on the Internet and social media and hope "useful idiots" pick it up and start to amplify the content by sharing it. Ask yourself where all of the pictures of the rioters are coming from (RT anyone?), the memes of protesters being water cannoned, pictures of troop carriers with an EU flag outlined in red etc etc. Some of those pictures will be 100% genuine. Most will be tinkered with or complemented by a set narrative destined for one side of the debate or the other.  Anything to further polarize opinion and discourage rationality. Why is it called hybrid warfare? Because it's not all on-line; you may find a few Russian operatives or their agents at these protests agitating for more aggressive behaviour - someone needs to make sure that the relevant photo opportunities arise.

The sole aim of these operations is to cause division - you can see how effective it is by the effective hollowing out of the political centre across the West.  Why do this?  Because it leaves the West weak and fighting amongst itself rather than looking for more practical fixes to social issues and global trouble spots (hello Ukraine and Yemen btw).

Pet theory time - feel free to disagree :)  As the western world increasingly focuses on whether QAnon or the Canary are the sole sources of truth and enlightenment, it means that there is no concerted effort to tackle climate change - the real and present danger to our species and our planet.  Ask yourself, what draws together the US Right, Putin and the Saudis into their current close alliance? It's not a love of crochet. They profit hugely from fossil fuels. All of the division and conflict in the world offers a number of opportunists the chance to push their own local agendas, be that racial hatred, nationalism or disaster capitalism, but the alliance between those driving the division is much more basic - simple human greed for wealth and power.  Some will happily see the world burn so long as they are paid to provide the fuel.

What to do about it?  Don't share divisive nonsense you find on the Internet - you're only pushing the interests of enemies of the United Kingdom. Stick to verifiable facts.  Follow people whose opinions you disagree with - do not get stuck in your own filter bubble. Go to the source materials.  Find trustworthy journalists rather than propagandists.  If anyone is telling you that they have easy answers, find other sources, you're being played.  To conclude, if you think you're too smart to fall for psyops operations such as these then I'm afraid to tell you this but you're likely their perfect mark...

Friday, 16 February 2018

On Brexit

Yes, I know.  Nobody needs more writings on Brexit.  However, there are some thoughts I need to express and I hope to do so in a calm, rational and inoffensive manner.   Why now?  After Boris Johnson's abortive attempt to win over those who wish to remain within the EU, I got to thinking as to how he perhaps could have offered some reassurance that the future is not as bleak as many of us believe it to be.  Will many of us ever be convinced that leaving the EU is a wise choice?  No - but some of us could be convinced that Government is managing the departure competently should they wish to step away from bland statements of desire towards practical realities.  Let's have some examples.

1. "Deep and Special partnership".

The PM likes to talk about establishing a new deep and special partnership with our European friends. Clearly the shape of that partnership is dependent upon the outcome of the Phase Two negotiations and any subsequent trade deal.  Now "deep and special" sounds suspiciously like a unique set of concessions agreed between two trading entities.  The exact kind of thing that the WTO Most Favoured Nation obligations are there to prevent! [In short, WTO members are not able to offer preferential terms to individual trading partners - outside of the types of free trade arrangements that we seem determined to exit.   Any favourable terms offered to one trading entity must be offered to all WTO members].  Consider this the next time people talk about frictionless, tariff-free, trade: the UK may be willing to go tariff-free with the EU (and so must offer similar terms to every other member of the WTO), the EU may have more of a desire to maintain tariffs and so protect their industrial base.   What could Government do to convince remainers of the bright future on offer?  Talk more openly about what WTO rules mean in practice.  Or indeed about the WTO in general - given the dismissal of the EU as a bureaucratic nightmare, I'd be extremely keen to hear how the WTO is any better following the collapse of the Doha trade round and the US's current refusal to ratify two judges needed to adjudicate trade disputes.  Oh, and did anyone mention that WTO relies on unanymity? You thought getting 27 nations to agree on things was bad, try over 160.

2. Northern Ireland
Any hard border separating Northern Ireland from Ireland is likely to violate the terms of the Good Friday Agreement.  You cannot have two different customs regimes without border controls - which is why the UK commited to maintaining full regulatory alignment in the Phase One agreement.  I can see no way of reconciling the Good Friday Agreement with the UK government's desire to exit the Custom Union.   If Remainers are to be convinced this is in hand then let's be honest about things - you can keep Northern Ireland in the Union and stick with the committed Phase One backstop or you can accept that Northern Ireland will leave the Union in order to maintain the lack of a border on the island of Ireland.  Or NI stays in the UK, we get a border and a return to the Troubles.  You cannot have both no customs union and no border.  Time for Government to make that choice clear.

[The EU must maintain a border, in part because of the MFN obligations I've already mentioned.  Claiming any erection of a border by the EU would be their choice is extremely disingenous.]

3.  Regulatory bodies
Due to the Prime Minister's self-imposed red-line of no ECJ jurisdiction post-Brexit we have no choice but to leave regulatory bodies such as Euratom.   Euratom looks after the safe treatment of radioactive materials - think nuclear fuel, waste and medical isotopes.   Current government policy tends to be ostrich-like - it'll all just be fine.  It won't.  Other nations will abide by international agreements.   We need to face facts and cost-up re-building our own versions of any number of regulatory bodies and agreeing competence and alignment with our trading partners.   Otherwise we'll find ourselves without access to radioactive materials, global airspace, european law enforcement information (SISII) and countless other things we take for granted.  Come on Boris, tell us how this is all in hand?  Tell us how walking away in the No Deal scenario will not impact any of these sectors.  And show us how and why, not just bland "it'll all be fine if we just muddle through being British about it".

4.  Trade agreements
We currently benefit from ~50 trade agreements with countries like Japan, Canada and South Korea via the EU.  The UK government has written to those countries asking them to roll-over the agreements so that we can benefit from them post-Brexit - telling them that we will not be changing much and that they should therefore treat us the same.   Whilst telling the UK that we'll be taking back control and diverging as we wish.  Which is it?  Foreign governments are not blind, they can sense the dishonesty.   Which is why the mock outrage about the EU suggesting punishment mechanisms for the UK backtracking on agreements was so misplaced.  As our negotiations have been conducted in bad faith so far, all potential trading partners will want punishment mechanisms to encourage sticking to commitments.   So again, I'd ask the government to be clear on current status of roll-over of agreements and clarification of self-contradictory positions.

5. Practicalities
Leaving the EU will require major investments in UK infrastructure and supporting IT infrastructure (customs, border, those regulatory bodies I mentioned earlier).  It will take time to build port infrastructures to take on the load currently handled by Rotterdam on our behalf (for example).   Have you seen this process starting?  Land purchased? Contracts tendered?   The IT systems clearly cannot be implemented until we know what they need to do.  All this will be ready by March next year will it?  Again, a bit of honesty and clarity about the timescales would not go amiss!

I haven't even touched on border controls or freedom of movement - it's an area with which I have personal experience.  Suffice to say we have always had the legal right to control our borders, successive governments have simply failed to enforce them.

Now, I am a staunch Remainer but I do accept that a managed Brexit (e.g. Flexcit) would be possible over the course of a decade or so.   That's not currently on offer - and there's been no practical discussion of how just walking away would resolve any of the issues I've raised above.  With less than 10000 hours until we leave, isn't it time to cut through all of the nonsense and try a little honesty?

So, to finish off.  Yes, I do believe a Final Say referendum is necessary - a clear choice between the deal on offer and the deal we currently have.   No-one can claim that they knew what they voted for when that final position is still being negotiated now and could yet be anything from full customs alignment to WTO-only.  Claiming that a direction set in 2016 when neither the starting point nor destination was honestly or clearly laid out is unalterable despite the emergence of new evidence is clearly irrational and undemocratic.  And I place equal blame on the Remain side for that lack of clarity by the way.

In the meantime, if the government genuinely cares about bringing Remainers like me on board then it's time to stop trotting out the same old claims we didn't buy during the campaign.  Tell us why the things that seem on inspection to be utterly incompatible (e.g. leaving the Customs Union whilst maintaining no border on the island of Ireland) are in fact deliverable.  Oh, and if all of the Treasury forecasts are wrong, how about telling us how they are wrong - that's the nice thing about models, they come with assumptions, dependencies etc.  Claiming they are wrong because they did not consider models that are not on offer or unfeasible is just a dereliction of duty.  Brexiters have had 40 years to come up with a model.  It's time to show it and open it up to challenge.  I'm not buying a black box any time soon.

Friday, 30 October 2015

The Value of Peer Comparisons

I've recently developed a bit of a problem with the misuse of benchmarking and peer comparisons in the field of cyber security - in particular by senior executives and Board Members who see being "in the pack" in terms of relative investment in security as a safe place to be.  

I've been guilty of similar thinking in the past; I've regularly used the analogy of the friends walking in the woods who stumble across an angry bear... you know the one.  You don't have to be able to outrun the bear to survive, you only need to be able to outrun one of your friends!    Of course, this analogy only works if there isn't a reason for the bear to specifically target you despite your relative sprinting ability...   Perhaps your rucksack includes some particularly aromatic and tempting foodstuffs?   Tempting enough for the bear to leave alone the easier targets?

Which brings me on to one of my beefs with the misuse of peer comparisons - the assumption that most attackers will target you and your peers equally.   Is that really the case?  Perhaps for some categories of threat actor, e.g. nationstates that may want to get into defence firms or major financial institutions.   But outside of that?   I'd argue that you're more likely to be specifically targeted because of some perceived activity or insult to the attacker than you are because you happen to share a field of business... notable exceptions here obviously, e.g. animal research, big oil and gas, financial services etc.  But even here, I'd still suggest that there will often be specific reasons for your organisation to be targeted.  So, if there are specific reasons for you to be targeted (and there will be, e.g. unflattering news stories, particular assets you own or activities you undertook, a specific customer upset by one of your customer services team etc) then why do you look to your peers for guidance on what's an appropriate amount to spend on security?  

Let's have another beef.   Do you base all of your business strategy on what your competitors do? The old "67% of successful generals bombard hills" example of Simon Wardley comes into play here - see http://blog.gardeviance.org/2013/11/without-map-you-have-no-strategy.html.  Just because your peers do something doesn't mean it's the right thing to do.   What if they are also all just looking around at their peers for guidance?   At which point where's the linkage between the peer group and reality?  What happens if there's some form of risk that the peer group is unaware of?   It's a simple race to just above the bottom but there's no guarantee that "the bottom" is sufficient!   Do what's right for you based on where you are, where you want to go and what you want to do to get there.   Let others look after themselves...  Of course you don't want to over-invest in security (the cash may be better used elsewhere) but using your peers as a baseline to make that decision is foolhardy.    I'm not even going to get started on what happens if some of the peers are in the cloud and others still on-premises... (the validity of the methodology used to derive the benchmarks and their relevance to your particular position would be a separate post).

Which brings me on to my final beef for now - the public relations aspect.  I can understand and, as a security professional who likes to get paid, sympathise with the view that you don't want to be found to be spending considerably less on security than your peers.   That would be terribly embarrassing if you suffered an incident.   However, being in the pack alone is not enough to spare your blushes in the event of an incident.    Let's look at the recent Talk Talk compromise - how much of the media coverage has been concentrating on their position relative to their peers?   Do we think Talk Talk are out of step with their peers?   Do the media, their customers and their shareholders care?   

So, in summary, sure it can be nice to know what your peers are up to.   A peer comparison can be useful to justify a business case for further investment for example.   But drawing comfort from the fact that you're "in the pack" is not something that I would recommend - be more comfortable that you have a solid grasp of your own risks and are doing something about the ones you care about.  Be comfortable with your own competency rather than assuming that of your peers...