Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 10 November 2021

PassW0rd – 10 November 2021

Play

Speaker A: This program is brought to you by Resonance FM. If you like what you hear, please support our work by making a donation at resonancefm.com/donate.

Speaker B: Hello and welcome to Password with me, Peter Warren. In this month’s programme, we look at the cybersecurity skills shortage, an issue that is apparently now so bad that it is threatening our high-tech world because an inability to protect personal data could inhibit the growth of our blossoming digital economy. According to one report launched this week by the global recruitment company Harvey Nash Group, a specialist in technology recruitment, cybersecurity is now rated as the scarcest technology technology skill in the world. In our new COVID-scarred world of remote working, developing AI, and big data analysis, cybersecurity is a skill that is essential to keeping the hybrid world of offline and online turning. Yet, for over a decade, reports have indicated that in Europe alone there is a shortfall of half a million jobs. Just as our data-driven, social media-excited existences are not understood by many of the population, the world of cybersecurity is also something of a mystery. Yet without it, the data breaches would pile up against Facebook and its new Meta project to build a digital twin of the world, and the fines imposed for losing customer data would bring social media crashing down. For most of us, cybersecurity is a shadowy world that relies on a vague definition culled from the media and Hollywood of criminal hackers and computer programmers relentlessly pursuing each other on frantically tapped keyboards in the wilderness of cyberspace. The reality is surprising and possibly shocking, because cybercrime is not the domain of some spotty schoolboy in their bedroom anymore. It is now a massive, many, many billion-pound industry that is constructed like any other sector, though its purpose is simply to steal either money, intellectual property, or data that can be used to make money. A veritable dark version of the world that has led some technologists to suggest that while the good guys were building Silicon Valley, the cybercriminals were just as industriously digging out a Silicon Hell with no skill shortages. So why the difference? Why, in a world dependent on data security, are some of the best-paid jobs in the economy going unfilled? The answer, as always, is not straightforward. Here’s information security professor Keith Martin of London’s Royal Holloway, the UK’s first university to set up a cybersecurity course in the 1990s.

Speaker C: I suppose it depends what you mean by cybersecurity shortages. I mean, we’ve had skills shortages, we’ve been hearing about this for an awful long time. And at one level, there’s a cybersecurity skills shortage across the entire population. I mean, we could actually solve a lot of cybersecurity problems if everybody was a bit more savvy about cybersecurity. And in fairness, certainly here in the UK, the government has been investing in quite a lot of programs to try and upskill and advise young people, people of all ages, about cybersecurity, just to try and get us a little bit more streetwise in cyberspace. But I think these cyber skills shortages are much more commonly referred to in the sense that there’s a feeling there are job openings for specialist skills and there’s nobody with those skills applying. And I’m always a little bit surprised about this because I don’t think there’s a shortage of people looking for jobs. But I know that the employment with people with cybersecurity skills is healthy because our graduates, for example, coming off Royal Holloway’s Master’s in Information Security program, they all get employment. Avoid eventually, and some mostly very quickly. But the one thing we do see is some, some students, for example, who I would say are now not the ones with past experience, the ones who are entering the profession, they sometimes have a little bit of trouble getting that first job. And I’m always a bit irritated when I hear there’s a cybersecurity skills shortage because I’m thinking, well, here’s someone who’s qualified. At least they’ve got some broad cybersecurity skills because they’ve done a university degree and they have the big picture. And yet we’re told this person is struggling to get a job. And I think sometimes this is just maybe a gap between what employers are willing to consider the skills they need for roles and the supply, if you like. And I do sometimes think, and I’m not saying it’s always true, but I do sometimes think that some employers are placing too great an expectation on the skills of people coming in. They essentially want them trained and ready to go, and they’re reluctant to invest developing and growing people to fill the roles that they need. So I think sometimes there’s a mismatch of expectations which can lead to that. I’m not saying there isn’t a shortage of qualified people, but I do think sometimes this is made worse by, by people expecting too much of particularly new people entering the profession for the first time.

Speaker D: That’s been a criticism of the technology industry generally for a very long time, that they want people but they want them with 3 years of experience or something. Do you think that there’s a need for apprenticeships?

Speaker C: I think apprenticeships are one solution. So apprenticeships are a solution to a slightly different problem. I think the apprenticeships are really about allowing people fast routes into professions without going through the sort of university sort of degree stage thing, and they can be very successful there. And so I definitely think apprenticeships are a good thing. So that is one, that is one way you could move people through the system a bit more. But also I think more willingness to support on-the-job training and developing skills in the workplace is another, another way around this. And certainly we have— we see students on our programs coming from what I would regard as quite enlightened employers who are actually using the university degree as part of their professional upskilling of graduates coming on to their programs. So as part of whichever cycle of training they’re putting them through, they’re utilizing things like university degrees funding the students and giving them the time to acquire a university degree as part of the, the general skills they’re giving to these, these people as they join the organization. And that, that I think is a very enlightened approach. And you can see the enthusiasm actually that the students in that position tend to have for their learning, because they, they have a professional role already, so they can— they’re immediately applying the knowledge they’re learning. But also, I think actually generally their enthusiasm for their employer because they really appreciate that they’ve been given that opportunity.

Speaker B: But the world that Professor Martin describes is changing fast because of both technological innovation, a response to climate change, and currently, most importantly, COVID. And those changes have begun to be reflected in the world of cybersecurity. Dr. Jessica Barker, co-founder of the cybersecurity awareness company Cygenta and author of Confident Cybersecurity, A book which sets out some of the skills needed to get into cybersecurity agrees with Professor Martin that the industry is not only blocking many of those who want a career in cyber, but also thinks that there is a need for a new sort of tech apprenticeship.

Speaker A: I think there’s a, there is a gap, there is a blocker. I’m not sure it is the kind of gap that people often refer to. People will say there’s a shortfall, which there is. There’s also a lot of people clamoring to get their first job or to progress in the industry. And sometimes I think there is a— there needs to be more joining up of that. So, I know lots of people who are looking to get a job, who are looking to get that first opportunity, and I know lots of people who are looking to hire. But sometimes I think hiring expectations can be too high. Sometimes organizations don’t have the time to invest in people, to give them the training that they need, the time to develop their skills. And so, sometimes the requirement coming from organizations can be quite hard. There can be this huge requirement to have a string of certifications and multiple years of experience, which sometimes just is, is not realistic. And so it’s partly, I think, on us in the security industry to communicate with hiring managers, to communicate with HR over what we actually want, and the fact that we need to hire people, not CVs. We need to hire people who have the right mindset, and that might mean investing in them. It might mean giving them training opportunities. It might mean giving them mentorship, but that will pay off in the long term. So we definitely need to look at why this gap really exists and what we can do to join up the people who want to work in this industry with the people who need people to fill roles.

Speaker D: So does the government need to do something there? Do you need to, in a sense, to have some sort of exam where you can assess people for those qualities that you’ve just mentioned, that curiosity, that thoughtfulness?

Speaker A: I think much more can be done. Certainly the government and various industry bodies are trying to take action on this. Of course, it takes time, but there is definitely a drive to increase apprenticeships to help people develop their skill set, initiatives like the Cyber Challenge, like Teen Tech, looking to help people understand a bit more about the industry and hone their skills. So there are, there’s good work being done. I think we just need more of it and we need that to happen quicker. But of course it takes time.

Speaker D: Okay. Now, one of the things that some people have said to me A lot of this in cybersecurity, a lot of log analysis, things like that. And log analysis being looking at what, what has actually happened on a computer, whether the, the computer’s behavior, for want of a better phrase, has changed, and which would indicate that somebody’s trying to interfere with it. That those jobs could be done by an AI system, and not a particularly sophisticated AI system, just a deep a learning system that says, this is the behavior that we normally see. This is not the behavior that we normally see. So therefore we should look at it. So they’re saying that at some point AI will take over the work of cybersecurity. Is that true?

Speaker A: I don’t think it will take over the work of cybersecurity. I think it will augment it. Absolutely. There are already tools on the machine learning side of things, at least, if not AI. That help support analysts in that way, in that kind of threat intelligence, threat detection manner. But of course, we need people to continue building those tools. We need people to make sure those tools themselves are secure. We need people to interpret the results, to interpret them to know which alerts are actionable, which need action, which actually are false positives. And then we need people to interpret those results for the business. So absolutely, there are technical tools and they’ll continue to be growth of technical tools, for example, using machine learning that will help support people working in cybersecurity. But we’re always going to need people. The tools don’t make themselves.

Speaker D: And then the machines don’t attack machines by themselves. Honesty. The word honesty has come up In this context, what is the role of honesty?

Speaker A: Honesty is incredibly important because in cybersecurity we are in a very trusted position. Organizations will rely on us to operate with integrity, to not take advantage of our role, of the information that we see and are privy to. So being honest is is really important. Being trustworthy is incredibly important. Trust is very valuable in cybersecurity, and it’s something that people will use as a factor to hire people on. They will use it as a factor as to whether they want to work with certain consultants, with third parties. So operating with honesty and integrity is a crucial value if you want to work in cybersecurity.

Speaker D: It’s interesting, isn’t it? Because one of the things that has been occurring because of AI and the development of AI and this thinking about the role of AI is that technology is driving increased ethics, that we are going to be— at the moment, people are talking about regulating AI, for example. So they’re talking about putting ethics into machines at a level at which they wouldn’t expect people to actually do it, which is an interesting idea. We’re going to to see, as we’re seeing with the progression of the Online Harms Bill at the moment, this attempt to push ethics onto companies. Ethics is becoming an increasingly important thing, and it’s very important in technology.

Speaker A: It is, and it’s really important in the creators of technology because, of course, the ethics that the creator has will inevitably go into the technology they are creating. The bias that they have can go into the technology that they are creating. We’ve seen so many examples of this over the years. So it’s incredibly important that we make sure people have a good grounding in ethics, in bias, in how to challenge their own bias. And this is partly why we need diversity and inclusion in cybersecurity and in technology as a whole to ensure that actually we’re bringing in different mindsets, we’re bringing in different backgrounds, and that we are trying to balance human bias as much as possible.

Speaker B: Dr. Jessica Barker, who trained as a sociologist. According to Professor Martin, one of the major issues with a career in cybersecurity has been caused by the relative youth of the industry and the fact that the career paths have not been as well formed as those in other professions such as the law, medicine, and economics. Professor Martin again.

Speaker C: Yeah, I think there will be an increase in the number of paths, but I’m not sure I agree with you that these paths you refer to have been that well defined in the past either. I mean, we certainly have talked about roles like that, and people do advertise for roles like that, but a, but a student, particularly a new student entering this profession coming through the university, isn’t always very clear, for example, what they should be doing to embark on these And I think this is an area where there’s a lot of work going on at the moment within UK government and elsewhere to more clearly define pathways. But pathways, yeah, for, for job roles that you’ve described there, but also for other ones. I mean, I, I think there is an exercise at the moment where they’re standing back and saying, what are the, what are the main roles that currently exist, and therefore what are the qualification pathways that would take people there? And I think that, that is a change we’re seeing at the moment, and one which I hope will be for the better because it will add a bit of clarity for people entering the field, which perhaps was previously a little bit obfuscated.

Speaker D: That is absolutely necessary, isn’t it? Because, you know, in fairness to cybersecurity, it’s a very young industry. But because it is so young, many of the people that we’ve interviewed seem to have fallen into cybersecurity and then become cybersecurity professionals. And they seem to be trying to define it after the event. What really does need to happen is, as you say, clarity over, over what it is and what it means, because then of course people can decide what they want to do.

Speaker C: I think that’s fair, and I can’t echo enough what you said. The number of people I have met who fell into the profession by extraordinary routes, and that makes it— in a way that’s good because they bring in experiences and it makes great at-the-dinner-table conversations. But, but I suppose in terms of overall professionalization other professions like the medical profession might look at that a little bit in horror. And I think it is important to bring in diversity and bring in diversity of disciplines as well as diversity in all its broader senses. That is very powerful. But also professionalisation is important. So having brought these perspectives in, training people for roles is important. And I suppose the trick is really to make sure we don’t pigeonhole people too much. But then again, we look at professions like the medical profession and no one really complains about the pigeonholing and expertise training the same thing that happens there. If you, if you need some radiology, you definitely want a qualified radiologist there, not someone who sort of got there by accident because they golfed with somebody at the right moment and there was a job opportunity available. So, so maybe we are, maybe we are just moving into that slightly more professionalized, mature situation, which will bring a lot of benefits, I think.

Speaker D: But that is something that is definitely needed. One of the things we’ve talked about, ethics, for example, Business ethics and technology ethics to do with data use is going to be very, very necessary. We’ve seen that already in the online harms evidence given by Frances Haugen. We’ve seen that in what happened with Cambridge Analytica. There is a need for people to understand what’s right and wrong with data use.

Speaker C: Yeah, I think so. That, and that is, I suppose, something really that is being developed at the moment. I, I don’t suppose you could guarantee you would get a straight answer or the same answer from a number of different people if you ask them what the right ethical principles should be regarding data use. And I think we’re getting there, so I think there’s a lot of work going into that at the moment. But I mean, I recently was actually searching around the internet for a different reason, for various ethics statements to do with university courses, and I could actually— there was a huge diversity of things people were putting up there in that domain. And I think getting to a more mature and established notion of what is ethical is really important. And so that, yeah, there’s, there’s work going into that at the moment and that’s very welcome.

Speaker D: It’s very interesting, almost philosophical point, isn’t it? Because what we’re actually seeing in cybersecurity is hackers being unethical with data and other people trying to say what ethical use of data is.

Speaker C: Yeah, I suppose we are. That flags, I suppose, that in some aspects of this issue we’re also dealing with very subjective notions as well as to what would be ethical. And, you know, you only need really to look at the word privacy to see that in more, in sort of greater light, because you could see that no two people, or no one person, agrees what privacy means, because we all make different contextual decisions about privacy, not just about different kinds of data, but possibly on different days of the week depending on how we’re feeling or what opportunities we see that we might take by giving up some privacy. So we’re not desperately consistent in our own personal approaches to words like privacy. And so cyberethics sounds even worse. I mean, this is something that the human race is learning, I suppose, on the job, because this technology that we’re now using and is infiltrating our lives is a new thing for us, actually. And we’re having to sort of work out what the ethical rules might be. And I think it’s not easy.

Speaker B: Professor Martin’s points about defined career paths in cyber is an issue currently being considered by the Cyber Security Council, an umbrella organization that has pulled together 16 of the cyber industry’s former accreditation and governing bodies into what the UK government hopes will eventually become the professional body for cyber security. It’s a bold and some would say overdue step. One of the issues that bedevils the technology sector is the sheer number of often overlapping organizations that have emerged to represent different concerns and issues in information technology that range from computing, AI regulation, the internet, data, privacy, and mobile technology. And soon we’ll be joined by another area of concern: the Internet of Things, which is the potential for the items in your house connected either by Wi-Fi or Bluetooth to represent a threat to you. The Cybersecurity Council now faces its first true challenge in an industry as famed for its pedantry as the law. Defining what cybersecurity is. Once it has done that, it can then move into what may be slightly calmer waters and define career paths without setting them in stone. What could be easier? Once that is done, the industry should open up, something that Saab Sembly, one of the UK cybersecurity pioneers, says is happening already. Sambi says that the emergence of people like Dr. Barker is typical of the person that is helping the role lose its geeky image and making cyber one of the most satisfying careers now on offer. But as Sambi says, words have haunted an industry that started out as computer security, became information security, and now is cybersecurity?

Speaker E: Cybersecurity involves integrity, confidentiality, and availability, and it is all of those things, and it does extend beyond that as well. So if we stick to those for the moment, when we’re talking about availability, then it’s talking about responding to things like ransomware. When we’re talking about integrity, we’re talking about people not altering our credit ratings or our health records in a way that maybe I’m blood group O and somebody changes it to B and things like that. And then you’ve got the confidentiality in terms of our passwords, our data that is ours personally, so it’s not spread out all over the internet. So really, information security is the original main term that we used to use, and when we talked about information security, a lot of people used to get lost in what it meant, whereas using the word cybersecurity people tend to think they understand because it’s something that’s wider than just pure information.

Speaker D: OK, now we’ve got this shortage. What does somebody who wants to get into cybersecurity, what do they need to know? It would appear that at the moment anybody is being taken. English graduates are being taken, philosophy graduates have been taken, as well as those people who’ve got computer certification.

Speaker E: Absolutely, and I think that’s a good thing, and that’s something that the profession and the government realized, that technology is something that can be taught. What they’re looking for are people who are inquisitive, who’ve got the right aptitude to explore and question, because the traditional thinking by outsiders has been, oh, I can’t get into that because you know, cybersecurity is too technical for me and I’d find it too boring. And there are a lot of people that are getting into cybersecurity from a variety of different angles, and it’s really, really good because we’re finding people who’ve got fantastic skills in people skills who are coming along and using those people skills to raise awareness. We’re finding people who’ve got accountancy skills coming along doing auditing, and they wouldn’t have— never have thought of themselves as being technical and what the aspects and the skills that they’re bringing are skills that we don’t have as technology people. So it’s really good that we are now beginning to draw more people from outside. There’s certainly not enough, that’s, that’s for sure. But we are now beginning to draw more people who haven’t got technical skills because those technical skills can be taught on basic courses, more advanced courses as time goes on. But those people skills that we need and interpersonal skills, they are often hard to come by. It’s interesting because my background is varied. I mentioned earlier on that before coming into cybersecurity, I was in software development. Way before that, I was a management consultant and I specialized in diagnosing organizational culture. When I left that to retrain into technology, I thought to myself, well, this is the last time I’ll be using these skills. And the strange thing is In cybersecurity, I’ve used them often because understanding culture is absolutely vital to try to understand what it is that we could and should be doing to raise awareness about what we need to be doing about the various risks that are out there and various parts of the organization. Where is it we need to try and impact that we haven’t yet impacted? So all of those skills are, are those skills that are currently not in cyber in the way, in, in the levels that we need them. So it’s really good that we are drawing people from outside.

Speaker D: Okay, so you mentioned courses. Somebody wants to get into cyber, where are these courses?

Speaker E: Okay, it depends on where they’re at at the moment in terms of their age, in terms of their background, in terms of what they can offer. So if they’re early part of their career, they might be thinking, all right, and there are several clubs around the UK with the Girl Guides, with Cub Scouts. So there’s things like that. While people— if people are still in school, if they’re still in school and doing A-levels, they might even think about doing a degree. And there are certainly more degrees around now than there ever have been. If they’ve gone slightly beyond that, as long as they’ve got an interest— I mean, so many CISOs, if we look at the events that have been out there before COVID many, many events, a lot of Chief Information Security Officers would come to events and they’d be talking about the fact that they would be happy to take on people who were interested and had something that they could offer other than technical skills. And these people, some who’ve got degrees, some who haven’t got degrees, and they’re in other professions, but what they’re looking for is someone who’s actually passionate and interested in finding out more and can bring something to the table at the same time.

Speaker D: When you mention age, can— so anybody at any age can suddenly get a career in cyber? Somebody who is in their late 50s, 50s, in their early 60s?

Speaker E: That’s a really good question. Again, there’s a lot of work being done right now with lots of professional bodies, including Cybersecurity Council of UK, where they’re trying to make sure that they are drawing diversity and inclusion policies that are actually bringing people in of all ages. And there are some projects that I’ve been aware of where they’re bringing in 50s and 60s. Again, it’s bringing in other skills to bring on to the cybersecurity skills. And, and there are various projects around for those other age groups. And really, because there is such a shortage, I guess CISOs are interested. But even if there wasn’t, the recognition is that it’s always good to have these other skills that are harder to come by and bring them into the profession and share, because the diversity inclusion of the profession has been quite limited and we want to widen it because there’s so much more that we can learn from those other professions. And, and I think if you look at many technical roles, one of the things that many of them lack is business knowledge and business experience. And anyone that can bring those other skills has got a lot to offer cybersecurity.

Speaker B: Saab Senby, one of the pioneers of cybersecurity. So what is cybersecurity? What is this world that they are battling in? Here’s Magni Sigurdsson of Siren, a company that specializes in preventing the phishing attacks that fill our email inboxes with messages from Nigeria offering access to fortunes, and the emails containing the viruses dressed as real communications that designed to trick you into clicking on an attachment that will covertly take over your computer. Siren recently headed off an attack on America’s largest bank, Chase, that tried to steal customers’ identities. The attack flooded inboxes with emails apparently from Chase, based on the premise that many people receiving the emails would have an account, and were part of a massive rise in cyberattacks attacks designed to take advantage of the change in working practices caused by the coronavirus. According to Sigurdsson, the Chase emails increased 300% in 4 months, but underlying them is a criminal attempt to gather data on an industrial scale in which the attackers have formed particular roles: phishers who steal ID and account data, and then sell it in verified batches. Data matchers who buy the data and add it to other stolen data to discover if there is more value in particular individuals, either financially or in terms of the jobs that they do. Then finally, the sophisticated hackers who buy that data and use it to attack companies, either to steal intellectual property or to use it for ransom attacks, which encrypt the company’s computer systems and which can only be freed up if they pay a large sum in cryptocurrencies. These attacks, known as ransomware, are the fastest growing crime trend in cyberspace.

Speaker F: What we discovered also from the Chase phishing attacks is the credit card number dumps that are being sold also on the dark web. Specific Chase credit card numbers And that’s where the hackers are, or attackers are verifying that the credit cards are actually working. They give you, if you’re going to buy the dump from them, you get an example and assurance that these credit cards are working. So they have charged the credit cards with a small fee that will go unnoticed by the bank. And the customer usually a dollar before you buy the dumps for a few hundred dollars or something like that.

Speaker D: Okay, so what we’re talking about is a sort of an industry, aren’t we? First of all, there’s the data breach that’s putting together the lists of numbers, and there’s a data breach that’s putting together the credit card numbers. Then you’ve got the people who are selling that information on to the other people who are going to exploit it. And that is often sold enormously cheaply, isn’t it? How much is it for 100 numbers? How much is it for 100 email addresses?

Speaker F: Well, it’s, it’s very different. You see, you see these lists being sold for maybe a couple hundred dollars. But like you said, you can’t really trust the person who is selling this. He might have sold someone else it as well. So, and we’re also seeing cases where someone has bought a list and is then reselling it to others for less money. So it’s, and that’s the same story with the phishing kits that are being sold They are being sold for, we’re seeing from $25 and up to $200. And what we saw on some Telegram channels that we were looking at where these kits were being sold, the guys who were selling these were accusing each other of stealing each other’s kits, modifying them, and reselling them. So It’s a very gray, gray area and, and very hard to, to like find out who’s the real owner of, of every fishing kit out there because the code is so widely reused and they’re sold— same kit is sold many, many times.

Speaker D: When you say kit, just define a kit for us.

Speaker F: Okay, so usually these kits are delivered by the creator in a zip file, and what you get is basically just the backend to the phishing site, so the HTML code, the PHP code, and all the functions that send the stolen data. To the attacker. So what you receive is, yeah, basically the backend to the phishing site. So what you have to do then is upload that to your web host, and yeah, that’s it. And usually there’s a configuration file where you can modify how you want the phishing site to act. Where to send the credentials, if the credentials should be stored on the web server, if it should only allow users visiting from mobile devices, only users from the US, and so on.

Speaker D: And so you buy your database, you go to the phishing site, you load in the database that you’re after, and then You press a button.

Speaker F: So the phishing kits and, and the attacks where the phishing emails are being sent out are, are usually separated. You have the backend, but then you need to send out the emails or the text messages by some other, other way. The phishing kit is not responsible for that. So you can, you can go on the dark web, buy your database of email addresses, and then you can use one of these mass mailer tools that you can find online to send out the emails, or you can contact a service that is selling this kind of service, sending out these emails. Via botnet, for example, pretty, pretty cheap. You can, for $50, send out maybe tens of thousands of emails, different kinds of people or different email addresses. So what you need to do is just provide the email you want them to send out with the link to your phishing site.

Speaker B: The world of the dark web, as outlined by the anti-phishing company Siren’s Magni Sigurdsson. It is a world of smoke and mirrors that, according to Colonel John Doody, the former head of the listening agency GCHQ’s Communications Electronic Security Group, which was responsible for protecting the UK from cyber intrusion, is now a sophisticated battleground that is growing ever more complex and fascinating.

Speaker G: There’s two aspects there. There’s your corporate data and there’s your personnel data, and they both have a very high price. And we’ve seen a lot lately of organizations being attacked by ransomware and companies willingly paying out a lot, a lot of money to get rid of the ransomware. And it’s highlighted how easy it is to attack and hold people to ransom. And we need the people, the tools, and the skills to defend against attacks like that. And what is, what is sad that 1 in 10 companies that get attacked by ransomware go to the dust.

Speaker D: One of the very interesting points has come out of the research for this program is that this is the one of the few worlds where you can actually meet and digitally rub shoulders, for want of a better expression, with shameless criminals. You, you can actually go into the dark web and see people shamelessly being criminal and being, in a sense, honest about it, insofar as criminals can be honest.

Speaker G: That’s very true. I think the, the biggest challenges in getting people into the profession is having some very attractive offerings, a training career, the right courses, the right influencers, the right skills on offer to make it more easier to attract people. And I have to say, the National Cyber Security Centre have done a lot of work in in the skills level, in recruitment, in university engagement. They’ve done a brilliant job, but the cyber domain is growing every day. The attacks are not stopping, they’re increasing. They’re increasing by nation-state attacks, they’re increasing by criminal attacks, and they’re increasing by the, the nosy hacker that sits in his bedroom and just wants to cause trouble. Now they require some very, very great skills, and having the right skill sets on offer to potential people that want to join cyber is very, very important.

Speaker D: So what sort of people What is the industry looking for then?

Speaker G: They’re looking for people with common sense. That’s the bottom line. They’re looking for people who have some qualifications. They have said early, you don’t necessarily need qualifications to come in the profession. You can learn on the job. It’s not difficult. And if you look, look at everybody today, they have computing skills. Permanently on their iPhone, they’re permanently on the computer, they’re pretty savvy in IT in general, and in that respect, it’s not a difficult transition to go from day-to-day working on your computer and your iPhone to doing something more complex. It won’t happen straight away, but people that have the right, the right impetus, the right urgency to get into this business. It is a very well-paid business, and I can’t emphasize that enough.

Speaker D: And it’s going to be because you mentioned the word complexity. We’re moving into this AI world. We’re moving into this world of big data. It’s increasingly going to become an incredibly important job because you have to protect that data, because if it’s poisoned, polluted in any form or way, then it’s going to have very real-world implications. So this is not only a, as you say, a massively changing job, it’s a very important job.

Speaker G: Yeah.

Speaker B: The—

Speaker G: some of the challenges that we face in, in, in the cyber world We have these systems that are evolving technically, they’re evolving in software terms, they’re evolving in what the customer needs at his fingertips to do his business or to run his life. And they are becoming increasingly attractive for the enemy, so to speak. And they will not stop at anything to get either money or data from you. Intellectual property, that’s been a big thing in the past, stealing intellectual property that has a big impact on our economy. But what is relevant is it costs a lot of money to defend, doesn’t cost very much to attack. And I think the challenge for young people coming into the business is to give a refreshing outside-of-the-box look. How can we change that ratio of making it very expensive to attack and not so expensive to defend? And that needs bright people. It’s a utopian world that I don’t think we’ll ever reach, but it’s some sort of target to give to people that come into the profession.

Speaker B: That was Colonel John Doody, a 79-year-old veteran who this year was awarded the title of Industry Godfather for the 63 years he has worked in cybersecurity. Something he documents in a recently published autobiography, From the Stripes to the Stars, about his journey from the lowly ranks of the Army to the Royal Signals Regiment and GCHQ. I’m Peter Warren with Password on Resonance FM. After this, you can hear DJ Ritu with A World in London. Colonel Doody’s account of a changing world meshes with that of the others interviewed for this program. It is in part due to the influx of women and people from other disciplines into a space that is mirroring our world. As we found out in previous episodes of Password, where computer graphics companies like Nvidia aim to create digital twins of our world. To find out more about Nvidia’s Omniverse, go to our website, www.futureintelligence.co.uk. More importantly, it is a recognition that not only is technology mainstream, but also that the decisions taken using technology are now becoming highly controversial. Controversial and often ethically challenging, as we have seen with the scandal involving Cambridge Analytica. An escalating ethical debate that is also comprehensively covered on the Future Intelligence website, and one that MIT Media Lab lecturer Beth Porter, the co-founder of Esmu Learning, says is inevitable because of the role of big data analysis in our world. According to Porter, Esme Learning now uses AI to teach company executives about cybersecurity, AI, and data ethics because they want to understand the risks they may pose to their businesses and to enhance their career prospects.

Speaker H: I think another thing there is really just about AI specifically. So we’ve been talking about data, but I think AI has another sort of important component, which is around, you know, the attestation of, or even proof, right, verification that the AI is doing the thing that it’s meant to do. Not that you get to peer inside and see the secret sauce that develops that AI, but, you know, just this idea that you’re transparent about what goes in, what comes out, how it gets used, and how that gets refined over time. There was a failed attempt to create an Algorithmic Accountability Act in the United States, but I think these will, these will keep resurfacing as notions until we get something that’s actually legally enforceable, which, which that one wasn’t.

Speaker D: I mean, let’s just look to this idea of regulation stifling technological innovation. It’s one of the big claims of the Information Technology Innovation Forum. They say that if nobody can think of every unintended consequence from technology, from AI, so if we put these regulations in place, that the brakes are going to go on the technological train. There’s another thing with specific reference to cyber, which is that for a long time, the person who has been involved in cyber has been seen as a pedantic geek policeman who says no.

Speaker H: Well, a long time ago also, the pedantic geeks were the only ones using cell phones and personal instruments and things like that. And then it became an instrument of choice for all humans everywhere. And so I think it’s just a matter of technical evolution where early adopters are almost always those people who you look at, they say, oh wow, they’re just using technology I could never get my hands on. Like VR now is sort of like this far away thing for a lot of people, like I’m never going to put that on my face, I’m never going to use that, that’s crazy technology, I’m not interested, right? It’s got this geeky component, but fast forward 10 years from now and this will be common tech, just like cell phones used to not be common but are. And it’s going to take, I think, some socialization that hasn’t happened, as it did with other new technologies that emerged in the marketplace. It’s going to be something where having the early education process is going to help a lot. Educating people who are currently in workplaces is harder than it is to educate kids. If you put cybersecurity and data and privacy and security, all that kind of stuff into the same kind of programming bucket as you put literacy into today, then it would be a heck of a lot easier for the next generation of students coming through who then become the next wave of workers to see it as a core value because it’s been done from the beginning. Now, that’s not— we’re not going to wait 20 years for that group of people to mature. So what do you do now? I think what you do now is you acknowledge that it is not a sacred domain for only people who are nerds. It’s not a, it’s not a thing that only people who have technical career paths should care about. It is literally something that everybody should care about. And if it’s not socialized that way inside of businesses, that this is really core value and has to come from the top, and it has to be socialized from the bottom, that this is a core value of the organization to become smart about cybersecurity, and it’s existential to the business then that’s, that’s where a company really fails. If they put it into a corner and say, yeah, only, you know, nerdy people over here care about it and you can just keep working as usual, that’s definitely the wrong approach.

Speaker D: What you’re saying is that there’s an evolution that’s necessary and that everybody should be aware of the fact that cybersecurity is important to them. So this is, this is every employee should be aware and everybody should be aware. It’s almost as though cybersecurity isn’t a role just for one person.

Speaker H: No, it’s a role for every single person in the entire organization. If you get a machine, if you have a laptop, if you have a phone, if you have any kind of an intersection with a device or data, particularly consumer data, but not just that, right? All the business data, then, then literally you have a job in cybersecurity. That’s it, right? Everybody does. It’s like air and water.

Speaker D: In this new hybrid world, what we’re saying is that the hybrid world is evolving new attitudes, that what we’re doing is essentially becoming sensible and responsible citizens in the cyber world. We should know what our kids are doing. We should know what’s happening at work. We should know what’s happening what’s happening on the cyber street.

Speaker H: Yeah, and in some ways, our kids are actually smarter than we are because they’re digital natives and we’re, many of us are sort of digital laggards, right? This is a, we had to learn it as adults with coming in with a different sensibility and become socialized to a world in which technology plays a central role. That’s not to say that kids, you know, don’t need supervision and they don’t need education around cybersecurity. I’m simply saying that they’re dealing with a different set of issues because they’re digital natives and because they take it for granted that they’re going to have a cell phone pasted to their side of their bodies forever and ever, right? This is just part of their, their working lives. We’re taking a lot, you know, people who are in my generation are taking a lot longer to appreciate how pervasive data collection is, how pervasive AIs are, how pervasive security risk is. And so we need a So there’s got to be an even more ardent and rapid march toward education in people who have not come up as digital natives and have not grown up with the technologies.

Speaker B: Beth Porter of ESMEE Learning pointing out that it is not only company executives from sectors outside of traditional tech who need to know more about the systems that underpin our 21st century world.

Speaker G: Do.

Speaker B: And if we are to be able to do that seamlessly, then cybersecurity will also have to move towards our world and shed some of the relatively pointless tech terms that it loves, which often render the sector incomprehensible and deliberately unapproachable. My personal favorite is POTS—Plain Old Telephony Service. But there are many others. Indeed, it is an industry so littered with TLAs—three-letter acronyms—that a conscious effort is being made to remove them like the plastic waste in the Great Pacific Garbage Patch, a point made in no uncertain terms by Jamie Smith, head of cybersecurity at the technology intelligence company SRM.

Speaker I: What at SRM, what we, what we, we really look for is less experience is more these core competencies. And so I think that I, I actually think that the skills gap in cybersecurity that people talk about can be a little bit of a misnomer. And yes, there aren’t enough people working in cyber, but actually I think there are a lot of people out there who have very relevant cyber skills. But they’re just put off from going into the cyber industry by thinking it’s, it’s too technical or too complicated.

Speaker D: Okay, so what are those core skills?

Speaker I: So what we really look for are the raw consulting skills. It’s about problem-solving skills, it’s about communication skills, and really what we see is those who have these core skills, often when overlaid with those technical skills which can be learned, that’s really when you get the best cybersecurity consultants. It’s much more difficult to learn raw analytical or communication skills than some of the technical skills.

Speaker D: You almost remind me of something that somebody said to me about rugby, that, uh, nobody can teach good hands. You can teach everything else in rugby but not good hands. So what you’re essentially saying is that so long as you’ve got a curious and inquiring mind, then that really is the basis for cybersecurity. It is something unusual’s happened, why has it happened? Yeah, exactly.

Speaker I: It’s about thoughtfulness. It’s about critical thinking. And as I said, it’s about It’s about being able to communicate what you have found and communicate it to stakeholders that matter. Right.

Speaker D: And does it matter your age? Is that a factor? And does it matter about your previous employment or your previous qualifications? Presumably, if, as you say, you’re just looking for curious and inquiring people, this can come from I really do believe that, actually.

Speaker I: And again, some of the best cyber consultants that we have at SRM now have come from very different backgrounds— non-technical backgrounds, arts backgrounds. So I really don’t think it, it does matter in terms of, in terms of age. And actually, what you’re seeing, what you’re seeing now is you’re seeing a lot more people coming in from a junior point of view. So because there are degrees at university, which you can do, which are relevant, but what we’re also seeing is a lot of people retraining. And there’s some, there’s some, some very good companies out there who are helping people retrain from other professions into cybersecurity. I do think about the concept of this actual gap being a bit of a misnomer. I’m not sure there is a skills gap. I think it’s the I think it’s the fault of the cybersecurity industry in general. Cybersecurity industry likes to make things sound very technical. They use lots of acronyms to make things sound very, very complicated, and it ultimately puts people off. And I almost think that this is almost done subconsciously on purpose because it’s a way of kind of cyber professionals protecting their own livelihood, really. I.e., if we make it sound complicated, then others won’t come in into the market and do and take our jobs sort of thing. So I do think a lot of fault does lie in the cybersecurity industry in general in terms of putting people off who should be going into cybersecurity actually coming into the profession, if that makes sense.

Speaker D: There’s also a tremendous pedantry about the cybersecurity industry, isn’t there? There is always this because if anybody ever says something, then there’s always somebody who’s going to say, ah yes, but what about— and then they come out with a 3-letter acronym. That can be very irritating.

Speaker I: Yeah, you’re preaching to the converted. I couldn’t agree more. And as I said, I think it’s the— these acronyms just overcomplicate things. When people start using acronyms, which in the cybersecurity industry is full— is absolutely full of them. Other people switch off because, because you don’t know what they’re talking about. But again, I think it’s completely unnecessary, but I do think it’s just adding to and creating this supposed skills gap.

Speaker B: That was Jamie Smith, whose degree is in law and French, on why cybersecurity companies must shed their geeky image and ponderous language if they are to solve their skills shortage problems and make their issues more accessible to the hybrid world of the street and the internet superhighway. That’s all for this month from Password on Resonance FM, produced by Blue Buffery and written and presented by me, Peter Warren. Tune in next month for more on the impact of technology on society, or if you can’t wait that long, go to our website www.futureintelligence.co.uk to find out more about the issues we have presented to the EU, the French Senate, and the Houses of Parliament, and that have, via our reports, gone viral on the internet. Thanks for listening and goodbye.

Speaker A: This program has been brought to you by Resonance FM. If you like what you heard, please support our work by making a donation at resonancefm.com/donate.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00