The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label Silent Circle. Tampilkan semua postingan
Tampilkan postingan dengan label Silent Circle. Tampilkan semua postingan

Rabu, 22 Januari 2014

Can Elite Combat Teams Teach Cyber Security Teams Anything Useful?

For the last three Suits and Spooks events I've invited retired and former Navy SEALs to speak about which of their skills and training might transfer over to cyber security engineers. After all, they're both in the business of engaging adversaries albeit under very different conditions and rules of engagement, and I know that lots of security engineers are military veterans or have held civilian jobs with the DOD. So the panel's concept made a lot of sense to me. So far, though, it has met with mixed reactions among attendees for a few reasons:

  • Some attendees have trouble relating to what they're hearing for a variety of different reasons
  • Some are looking to apply only the tactical takedown of a target and finding a way to do something similar to a foreign hacker
  • Some wonder why I only have the Navy Special Warfare guys represented (see my answer to that below)

Yesterday's panel, with the addition of an active duty operational SOFer helped me understand the problem better. Here are a few of my observations about why this process of extrapolating useful ideas from one discipline to another may be problematic:

  1. SOFers have a known target to attack. It's rarely that black and white for cyber security folks.
  2. SOFers have very well-defined Rules of Engagement (ROE). We have an out-dated CFAA and no clear-cut policies or understanding on where to draw the line between passive defense and active defense.
  3. SOFers are elite, highly trained individuals who have overcome obstacles that would stop 99% of the rest of us because quitting is not in their DNA. In Cyber, while we have much different obstacles albeit quite difficult ones, I see more and more engineers rationalizing why they can't do something instead of working the problem in different ways until they're successful. 
  4. SOFers know better than to offer excuses or rationalizations about why they can't accomplish their objective. InfoSec folks, ...? Enough said.
  5. SOFers understand the importance of a team, and each man's primary concern is to keep his teammate alive. Cyber security engineers may work together but I doubt that very many believe that their primary mission is to support their colleagues by keeping them motivated, enthusiastic, and always in the fight. Correct me if I'm wrong on that.
Personally, I feel quite lucky to have been able to meet former Team guys who are now doing amazing things related to cyber security like Mike Janke and Vic Hyder who co-founded Silent Circle; David Howe at Civitas Group; and "Woody" who will soon retire after 20 yrs of service and is so eager and passionate about finding a way to embark on a new career in cyber security. 

I feel lucky because they and other Team guys who are personal friends like Rob DuBois and Thomas Dzieran have taught me the importance of (1) developing an iron-hard mental attitude to never quit in the face of difficulty; (2) not to accept or make excuses about why I can't achieve something; (3) the critical importance of building a team of like-minded people; and (4) the equally critical importance of not associating with those who dispute the validity of 1, 2, and 3. 

And please note my use of "SOFer". While my examples all come from the Navy, that's only because those are the guys I happen to know. I haven't met anyone from Delta, SAS, or any other Special Operations Forces units. However, if you come from those units or know ones who do,  please ask them if they'd be interested in participating at a future Suits and Spooks event. I'd love to include them.
Add to Cart View detail

Minggu, 08 Desember 2013

If You Missed Suits and Spooks NY, Here It Is On Video


O'Reilly Media, the publisher of my book Inside Cyber Warfare, has produced a video compilation of our Suits and Spooks event. I'm proud to say that this is the first non-O'Reilly conference that they have produced for sale and it looks great. It doesn't include every speaker because some of the talks were under Chatham House rules, but here are the speakers that are included:
  • The Top 50 Non-state Hacker Groups in the World - Christopher Ahlberg (CEO of RecordedFuture)
  • Out of the Mountains: A Future of Feral Cities, Urban Systems Under Stress, and Increasing Overlaps Between the Real and Virtual Worlds - David Kilcullen (CEO of Caerus Associates)
  • Emerging Bad Actors in the Virtual and Physical Worlds (Jeffrey Carr, Moderator with Dr. David Kilcullen, Jonathan Hutson, Thomas Dzieran, Aaron Weisburd, Peter Mattis, and John Scott-Railton)
  • How to Survive a Surveillance-friendly Environment - Mike Janke (Co-founder, CEO of Silent Circle)
  • Should Defensive Strategies be Specific to the Threat Actor or Generalized for all Threat Actors? (Jeffrey Carr, Moderator with Pierre-Marc Bureau (ESET), Derek Manky (Fortinet), Roel Schouwenberg (Kaspersky), Chris Coleman (LookingGlass), Brian Carrier (Basis Technology))
  • Real-time Depiction of the Global Cyber Threat Landscape - Chris Coleman
  • Icefog: Mercenary Hackers Who Focus on Supply Chain Attacks in Asia - Roel Schouwenberg
  • Joseph Kony, the LRA and Elephant Poaching in Africa - Jonathan Hutson
The complete series is only $149. Here's where to order. We're going to be offering this again for Suits and Spooks DC so please let me know what you think.
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID