Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Missing The Point In The Current Age Of Cyber
Articles Industry Insights

Missing The Point In The Current Age Of Cyber

Professor John WalkerBy Professor John WalkerAugust 9, 2023Updated:August 24, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
000Webhost Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Considering the known-known statistics, we seem to encounter a serious security breach at least once a week – and these are only the events which are notified or discovered. In fact, according to the BreachAware Report issued end July 2023, there were no less than 179,351,301 events involving leaked data, and other such insecurities – which does tend to focus the mind on the exposure that manifests out of, what may only be described a lacklustre cyber defence, which in real terms impact the end user account – AKA People! The question however, which hangs in the air to ponder is why? Given that some of the organisations who have been breached are shiny brands such as British Airways, Easy Jet, and Experian, who one would expect invest heavily in cyber defence to protect their product, and PII they have custodianship over, again another question which hangs in the air is, how can this be?

This last week I was reading up on some past materials I have used over my 35 years in an industry we now call Cyber Security, in which we may encounter those who use the title Cyber Security Expert (AKA operatives who know everything about everything in this vast domain of knowledge). What became very clear when reading back over the previous 35 years was, in comparison to some of the accepted materials of the day, it would seem we may have diluted what were robust Digital Security Skills into texts which seem to avoid the stressful need to appreciate the underlying technical challenges, but instead rely on heavy focus on the subject matter from a Governance, Compliance perspective which at times leans toward achieving some form of evidence skill in the format of a Certification of proven expertise! We may also encounter high level cyber assurance programs which infer that an organisation is robustly secure post performing a high-level review, which may only be described on occasions as a Tick Box exercise. Or maybe there is deep trust in the ISO/IEC 27001 Certification which was found to be adequate on the day of granting the Certificated Status!

As I introduced above, I have been spending some time reading over what may be considered out of date materials such as:

  • The DoD Orange Book
  • DoD Password Management (April 1985)
  • CESG COMPUSEC MANUAL M – Protecting Government Connections to the Internet
  • CESG COMUSEC MANUAL N – Vulnerabilities of the TCP/IP Protocol Suite (June 1996)
  • CESG MEMORANDUM NO. 7 – Re Use/Disposal of Computer Memory and Magnetic Storage
  • CESG INFOSEC MEMORANDUM NO. 13 – Protecting Government Connections
  • CESG INFOSEC MEMORANDUM NO. 14 – Public Key Infrastructure

What becomes obvious when reading the now, considered out-of-date documentation sets is, they are full of valuable knowledge and robust technical direction, and are also in the main still as relevant today as they were on their first publication – as opposed to the lite touch of current initiatives such as Cyber Essentials.

The book I pulled from the bookshelf was Computer Security (Third Edition) by John M. Carroll. What is so evident from this comprehensive publication is the depth which the book dives to, which in its 600 pages + covers domains from the Essentials of Computer Security’ through to Physical Security, Line Security, Transmission Security, Cryptography, though to Threat Assessments to mention but a few. However, what is very clear when reading though this comprehensive work is the technical depth covered which provision valuable technical education.

I touched on Certifications which on numerous occasions are mistakenly taken has proof of hands-on expertise. One example which springs to mind is the young Security Professional who held a CSIM (Certified Information Security Manager) Certification who worked for the Co-Operative Bank in Manchester. However, this candidate, whilst holding the proof of skills, did not have the necessary underpin of hands on, or qualified time practicing the fundamentals, and thus the certified status could be considered flawed – whist at the same time it was a trusted credential by the bank – shortly after that engagement, this operative left the bank and the cyber industry to become a Witch Doctor on the sub-continent (seriously) – see below media clip:

‘But it was all getting rather routine and so he opted for something a little different – heading for South Africa, going without sleep for three days, putting himself in a trance and drinking goat’s blood.

Mr x, 32, has given up his suit, laptop, and his office to train as a witchdoctor.’

There is no doubt that Certifications do serve a valid purpose, but I make this statement with the caveat that, they should be considered as part-and-parcel, conjoined with robust level of evidenced technical skills, understanding commensurate with the role such a party is being placed in.

The world of training can also go a long way to building on the required skillset. However, again there are several training bodies both in the UK, and the Middle East who are offering courses with trainers who have had very little pragmatic expectances relating to the world of cyber, along with courses in which the level the cyber defence pragmatism is based on Governance and Compliance – not to mention, flogging standards as the silver bullet route to a secure delivery of the business and related digital assets.

As a conclusion, in my training courses I have delivered over the past decade to hundreds of delegates and students in the UK, Malaysia, Dubai, Saudi Arabia, I have always stressed that there is a need for all elements to work in concert to accommodate the secure perimeter, and related asset security, thus why it is so very important to set a tipping point to provision a balance – see Fig 1 below from my Cyber Security Training Course materials:

Fig 1 – Tipping Point of Security

There is absolutely no doubt in my mind that the good guys/gals can combat the age of Digital Adversity and win the fight – the only thing that needs to be done is to take the threat seriously, look back at where we came from and apply a level of defence that is appropriate to the aggression – and maybe, just maybe embrace a little more technical cyber savvy.

Professor John Walker

John is the Principle at Shadow-Intelligence (Si), partnering with PALISCOPE, BreachAware and iStorage. He is a Visiting Professor at the School of Science and Technology, Nottingham, Trent University (NTU) and holds the appointment of Editor in Chief for the International Journal of Cyber Forensics and Advanced Threat Investigations (CFATI). For the last decade he has delivered training courses in the Middle, and Far East to Commercial, Industrial, the Financial Services Sector, and Military Agencies, including the UAE, US, Pakistan, Saudi Arabia, Malaysia (KL), Singapore, Argentina, and Sao Paulo

He served in the Royal Air Force 22 years’, specialising in Counterintelligence, working with UK Agencies such as GCHQ/CESG, and others in the fields of SIGINT, COMINT and Satellite Communications, holding appointments such as System ITSO for a CIA SCIF.

In the commercials sectors of IT/Cyber he has worked for/with Logica, Bae, T5, GM, Experian, Betfair, Palace of Westminster, House of Lords/Commons, TSol (Treasury Solicitors) and provided Consultancy to the Saudi Arabian MOD, TRA (Telecommunications Authority (Dubai) and the Military Academy of Malaysia (KL) on SOC, CSIRT, Digital Forensics and OSINT. Within the last 5 years he has focused on Geopolitics, with global expertise around the UAE and Russia, Anti-Terrorist Operations (ATO), Cyber-Warfare, Dezinformatsiya (Disinformation) and Maskirovka (Military Deception).

  • Professor John Walker
    China Threat Recap: A Deeper Insight
  • Professor John Walker
    Part 1: Historic To 2022 – The APT And Logical Threats
  • Professor John Walker
    A Hairs Breadth
  • Professor John Walker
    Security Must Be A Precedent

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}