Posts tonen met het label cyber. Alle posts tonen
Posts tonen met het label cyber. Alle posts tonen

zondag 8 december 2013

Stepping up cybersecurity

We love hypes and in our profession cybersecurity is a hype that doesn't stop to be a hype. The #ditchcyber campaign is started to help busting the hype. Well, allright, let's just add to the hype.

Here are some links to documents that may help you deal with cybersecurity.

Confused? Just pick the 9 steps ebook (by Dejan Kosutic). He clearly shows that cybersecurity is just a subset of Information security.

Enjoy.

dinsdag 1 oktober 2013

Get your #ditchcyber #wegmetcyber certification

You may have read my rant about the misuse of the word cyber, but I am not the first nor the only person to condemn the cyber misuse. Chris Baraniuk posted an interesting article about the history of the misuse of Cyber. Recommended! And of course, as mentioned in Chris' article not every use of Cyber is bad. Cyberspace, cybercafé, cybersex, cyberpunk, I don't mind you using those combinations. Trouble starts when politicians use the term without a knowledge about or vision towards security. In those cases the purpose of using cyber is to create FUD, fear, uncertainty and doubt. It's also a great recipe for really saying nothing: "Cyber is such a perfect prefix. Because nobody has any idea what it means, it can be grafted onto any old word to make it seem new, cool -- and therefore strange, spooky. ["New York" magazine, Dec. 23, 1996]" (source).
I call onto the responsible politicians, military and police officials to not use the word cyber anymore. You should address the risks that you can ifdentify. If you can't identify a risk or a threat it's just not there. And if you live by fearing the unknown, you will be a threat to others. As we witness everyday.
If you feel the same, join the #ditchcyber or #wegmetcyber campaign. It looks like the blog entry that I posted earlier last week had an interesting spin-off. The post is now being used a manifesto for the @cyberxpert community. This new Twitter account is the official speaking voice of cyber experts who support the #ditchcyber (or #wegmetcyber in Dutch) campaign. In a few days the @cyberxpert Twitter account attracted several dozens of followers. Nothing special perhaps, that happens a lot these days. But these followers are allowed to add one of the @cyberxpert titles to their Twitter handle to show that they are the real cyber experts. We use 2 different titles: people can add RCX and/or CCX to their name. RCX is the abbreviation of Registered CyberXpert, CCX means Certified CyberXpert. One can use the title only by following the @cyberxpert twitter account and by supporting the #ditchcyber or #wegmetcyber campaign. So join the #ditchcyber campaign, follow @cyberxpert and show your support!

donderdag 29 augustus 2013

Ditch Cyber campaign

A few weeks ago I started my #ditchcyber campaign, or #wegmetcyber in Dutch. The reason for doing this is that in my opinion the word cyber is misused a lot. Right now cyber is connected to almost every event that is happening on the internet, in the cloud, in datacenters, at home and in the office. In many cases cyber, followed by another term, has a very negative meaning, if someone uses the word Cyber it's about trouble. War, crime and we need cyber security, a cyber army and cyber police to help us against these cyber threats.
And now this means that the audience only knows about cyber where it has this special negative meaning. Cyber requires special cyber forces to guard us from risk.

And what is really the case? It's about information security. It's about professionalism. It's nothing more than managing bits and bytes. But we are just too lazy to do it right, or we just spend too little money to make it secure. And then when something bad happens, a data leak, or a ddos attack, or whatever crosses your mind, then there is the big CYBER excuse.

Well excuse me, you don't hide stupidity in empty words.

I don't want to be rude, but most incidents are of our own doing, they are human errors. Nothing new. Data leakage, like Manning's, happen because of lousy access control and bad logging. Hack attempts because of lacking configuration and patch management. Ddos because of bad architecture. Priviliged account misuse because of social engineering. Identity theft because of lacking awareness. Fraud because of lacking segregation of duties, lack of governance. Foreign intelligence acting hostile? Because of our own lacking governance and our being pennywise.

Did I mention cyber? Sorry, no way. Nothing new, just the same old errors. But since we call everything Cyber, we obfuscate our own lack of responsibility and lack of accountability. Makes it so easy...

So here I am, a lonely cyber warrior, ditching cyber. Feel free to join the campaign.

And please lookup the real meaning of cyber everything on wikipedia.

#ditchcyber (@alcyonsecurity came up with this translation, thanks!)
#wegmetcyber