Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Mind The Gap
Articles

Mind The Gap

Professor John WalkerBy Professor John WalkerMarch 16, 2018Updated:June 21, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

I, like many other Cyber Security Professionals have worked at multiples of cross-sector companies, within both vertical and horizontal market sectors – from Oil & Gas and Utilities to Banking, from Insurance to Credit Reference Agencies, and from Local Authorities to Central Government, which includes both the House of Commons and House of Lords. Thus, I feel I have a multilayer appreciative holistic view of the overall delivery of Cyber Security Solutions, and the said operatives who delever the prospect of robust logical protection – which over time has demonstrated that the levels of skill I have observed have ranged from the accomplished, to downright lacklustre of any sense or modicum as to what real Cyber Security represents.

Discoveries and findings are too many to document, but to cover some notables, such as the Scottish Bank Director of IT Security who stated that ‘they did not intend to follow the PCI-DSS route as they did not agree with it!’, or the Credit Reference Agency who did not report the loss of Third Party unencrypted banking records because there was no proof they had been subject to compromise! Not to mention the Utilities Company who lowered the Security Testing level against Smart Meters to ensure they would pass the security assessment. And last, but by no means least, the Big Name Outsourcing Agency whose Digital Investigations and Forensic Team are classified as Accomplished Amateurs who fumble their way through investigative materials with, what seemed to be a complete lack of Investigative Processes, never mind an appreciation of what the rules were around dealing with criminal cases involving peadophillia – and not to mention the Head of Security locating UK Government Sensitive Services within Hostile Environments which were outside the mandated hosting protocol (a National Security Exposure)! With such a Micro view of what may be, a Macro issue, maybe it makes it easier to understand just how so many big-name companies have been compromised, lost data, and have fallen to criminals notwithstanding they are spending huge amounts of cash on Digital/Cyber Security.

As the last Chair of the DTI ISO/IEC 17799 (ISO/IEC 27001) Steering Committee, I am, and have always been supportive of Stadards which drive Governance and Compliance. However, when I see the opinion that to enable GRC (Governance Risk and Compliance) Frameworks are seen to be the silver bullet to accommodate all the security requirments, then I start to get depressed. Of course, you may not agree, but in my opinion, and based on what I have observed first hand, such Governance and Compliance implementations are very much complementary to underpin the pragmatic level of security, and do not in any sense lead the charge – in fact, there have been occasions which I have encountered where the tick-in-the-box to satisfy the ISO Audit has provided the death-blow for a security breach down the digital river.

The bottom line is, in this age of Cyber Insecurity in which the clear majority own an Individual of Corporate Digital Footprint, we must apply more rigour to those who we employ to serve up and support our corporate security profile – and to satisfy the expecations of the great unwashed public who look to the industry to ensure their personal assets of which we may be custodians are fully  protected and of course notified when things do not go to plan.

Certifications are another instrument that may be used to prove, or disprove their skill set of the individual, but does as CISSP Bootcamp mean that the holder of the Certification really understands the depth and underpin of the high-level questions – or do they simply place the tick in the right box after being soaked in the seeing the correct answer? And does the profile of the Certified CISO make sense, or could it be the result of inter-personal collusion of falsified profiles and refences (Trust me, I know at least two individuals who fall into this criterion who have fooled the likes of some big-name companies, to take up high profile roles (but not for long)).

Yes, we are at a juncture at which we must evolve a Cyber Security Professional who can do more that just knock-out a Security Policy, or tick-a-box to prove compliance. We need an industry which can supply operatives who possess the Darker Skill Sets, and who can think as the attacker. We need professionals who can dig into the depth of exploitation of an isolated molecule of Intelligence, and then to extrapolate it out to meaning and thoughtful intelligence which may be leveraged to protect the organisation in real-time.

Granted, many will not agree with my opinion as outlined above – but on the other hand, there are many who do appreciate the approach of Disruptive Thinking which challenges the accepted norm in what would seem to be a landscape of failures – I guess that is why after 30 years I still get invited to speak at some important events, to the likes of the military and other such established. organisations.

Remember two facts, as I always say, ‘Imagination is the only limitation’ and ‘Fear of the new, is acceptance of the past’.

Professor John Walker

John is the Principle at Shadow-Intelligence (Si), partnering with PALISCOPE, BreachAware and iStorage. He is a Visiting Professor at the School of Science and Technology, Nottingham, Trent University (NTU) and holds the appointment of Editor in Chief for the International Journal of Cyber Forensics and Advanced Threat Investigations (CFATI). For the last decade he has delivered training courses in the Middle, and Far East to Commercial, Industrial, the Financial Services Sector, and Military Agencies, including the UAE, US, Pakistan, Saudi Arabia, Malaysia (KL), Singapore, Argentina, and Sao Paulo

He served in the Royal Air Force 22 years’, specialising in Counterintelligence, working with UK Agencies such as GCHQ/CESG, and others in the fields of SIGINT, COMINT and Satellite Communications, holding appointments such as System ITSO for a CIA SCIF.

In the commercials sectors of IT/Cyber he has worked for/with Logica, Bae, T5, GM, Experian, Betfair, Palace of Westminster, House of Lords/Commons, TSol (Treasury Solicitors) and provided Consultancy to the Saudi Arabian MOD, TRA (Telecommunications Authority (Dubai) and the Military Academy of Malaysia (KL) on SOC, CSIRT, Digital Forensics and OSINT. Within the last 5 years he has focused on Geopolitics, with global expertise around the UAE and Russia, Anti-Terrorist Operations (ATO), Cyber-Warfare, Dezinformatsiya (Disinformation) and Maskirovka (Military Deception).

  • Professor John Walker
    China Threat Recap: A Deeper Insight
  • Professor John Walker
    Missing The Point In The Current Age Of Cyber
  • Professor John Walker
    Part 1: Historic To 2022 – The APT And Logical Threats
  • Professor John Walker
    A Hairs Breadth

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}