Friday, December 25, 2015

Is your shop Secure by Design?



In a recent coffee chat with Jeff Jacobs CISO at IAG he talked about how, their team was making inroads into being ‘Secure by Design’. We reflected on how that advanced thinking re-positioned IT Security into being part of the process and not a milestone to tick.

Jeff went on to explain how his team was involved in all the agile scrum standups as a regular team member. While clearly this created added pressure around resource allocation, you can easily see the benefits of being involved early.

In contrast, where is your shop?


Applying an Agile Framework

In most enterprises there is an increasing focus on using an agile approach to deliver software. The basis of agile is that we build software using an iterative approach, instead of the normal ‘waterfall’ method. During this switch it has been the norm that the actual approach to managing security has not adjusted to this new reality.

The velocity of delivery has fundamentally changed and at the back end, just prior to ‘going live’ there has been pen testing and security review. Clearly this is better than doing nothing, but is not going to be the ideal approach.

Invariably some vulnerabilities and issues will be uncovered and this leaves the business product owner having to either accept a risk or the developer an additional task to figure out if there is a viable workaround. No-one wins and the CISO is the big bad wolf, who doesn’t understand the importance of this business initiative and is getting in the way of progress.


Building Security into the process

The alternative is that we build security into the application and not around the technology. By definition, agile is about being able to morph and change one’s approach – thus this means we have to apply security principles into the actual build process.
This means that stories that are developed as part of the agile process to depict “a day in the life of”, will by default build-in security controls. It places a responsibility for the developers working on user stories to understand the overarching security requirements of the new system.

Taking a practical example this would mean that the software engineer would need to consider all the new components and integration points, including any new cloud technologies. What else does it take to achieve this goal?

Coders are accountable to write “secure code”

Firstly take the onus off the CISO and the security team, instead change the focus so that security is part of the deliverable and the developers are expected to write ‘secure code’. This means that it is no longer acceptable for a software engineer to say that Personal Information, PCI etc is someone else’s responsibility.

Therefore any new software routines needs to be built with security in mind – both secure at rest and in transit.


CISO or delegate are part of the project

Essentially this means you must have a “security expert” on every project. This person is on the team from day 1 and provides a security lense and hopefully is also engaged for their broader business expertise as well.

The advantage is that you bring to bear the security experience to the table and it will ensure that the user stories are robust and include security requirements. This also means that proactively the knowledge of current vulnerabilities and any new potential ones is understood and factored into the new design.

Specifically, there can be attention to security sensitive aspects in relevant user stories. This will include authentication, data entry and manipulation.


Security Testing by pieces

Agile development is iterative by nature and not end-to-end. On the other hand IT security requires a more complete holistic review. Thus integral to this is usually to get evidence of regression and test automation.

The Security professional will be seeking that there is a good validation of the design and a comprehensive review of controls. Thus even with the involvement of security from day 1 it is still going to be a challenge to take the pieces and understand the total picture.

However the critical element is that once a new vulnerability is understood, then an automated test can be developed to ensure that this is never repeated.


A Persona covers all needs


To be ‘secure by design’, means that the customers that we are designing for include the ‘persona’ that one would expect for the new system. In agile development these personas are used as proxies for the customer. By definition a persona is:

“archetypical user of a system, an example of the kind of person who would interact with it” [1]


The customer experience is what every enterprise is striving for. A great or at least good experience and it’s hard to think about a user that would realistically want the system to be insecure by design.


http://www.cso.com.au/article/591067/your-shop-secure-by-design/

All I want for Xmas is to hire some Cyber Security Professionals

As I talk to CISO and Heads of IT Security there is a clear consensus that there is a shortage of cyber security professionals. It is also the case that most of the CISO are resigned to building their own talent, by growing these from internal transfers.

In contrast, Commonwealth Bank have taken the lead with a partnership with UNSW to develop a centre for Cyber Security. CBA have had a industry reputation for having an insatiable appetite and for taking staff from many of their competitors. It is good to see them taking a positive and practical step to address what is an acute shortage.

Yes, all I want for xmas is to find some good security professionals.

 
Demand exceeds Supply

There is a global shortage of information security staff despite the increased focus due to the much public attacks. This shortage is believed to be around 1 million professionals, and this is echoed in Australia with IT salaries being inflated to keep up with demands.

At the same time job insecurity is at an all time high, so we would be also witnessing some conservatism to taking on a new challenge at this time. [1]

In a Greythorn 2015 salary survey security roles were the 4th highest most valuable skill set that hiring managers were looking for, this is after Cloud, BI and Project Management. (Interestingly the next most valuable is Big Data)

I would for one, expect that the ideal candidate is also able to well manage information, and their ability to do analytics would be highly desirable. However in a time of severe shortage, I can’t be that choosey.


Highly paid

We are seeing that getting my Cyber Security staff for xmas is going to be costly and just take a few examples. Senior Security Architects in Australia were paid $160k interestingly the same rate as Network Architects where they have some cross skill opportunities.

IT Security Manager paid up to $170k while Network Manager are only paid $150k. The danger is that we create an elitist group and as this becomes well known and these teams have to work together, the tension will naturally become greater.

Yes, Cyber Security staff are highly paid but the price to pay is worth the cost.
 

I can hire a candidate but it is likely that they will be more expensive and create salary range relativity issues that are hard to address. So taking the harder road is about identifying existing staff and growing my own.

Realistically it can’t be done in a hurry - What’s it take to become a Cyber Security professional?
Well it not about doing a course (not yet anyway despite the CBA initiative). There are some good skills and attributes that will be useful:
  • Network management capability
  • Mobile app development skills
  • PCI knowledge
  • Analytics mindset
  • Curiosity
  • A degree of paranoia
It is fair to say that there is a clear lack of clarity of what good looks like. A good CISO can quickly tell, but it’s hard for HR or a Recruiter to really be able to screen these candidates easily. These lack of standards are not unusual and this situation is also the case in all other IT domains.
Ok, perhaps I will change my wish - All I want for Xmas is no breaches for 2016.

http://www.cso.com.au/article/591062/all-want-xmas-hire-some-cyber-security-professionals/

Who’s blocking the blockchain?

It’s no surprise that the distributed ledger underpinning Bitcoin has caught the attention of both banks and regulators.  The hype around the blockchain is becoming deafening.

Just this week, both Westpac and the Commonwealth Bank have run sessions on the blockchain during the Sydney leg of an international series of conferences on the technology’s potential.

Bitcoin was the genesis of the blockchain. The cryptocurrency uses the technology essentially as a distributed ledger for transactions.  However, around two years ago, there started to appear a number of companies that were working on blockchain-based applications separate from Bitcoin.


Friend or food?

As a virtual, decentralised currency, Bitcoin represents a challenge for governments and regulators.
Banks have a vested interest in the status quo; the system they operate within is highly regulated and it has taken a significant investment to get them to this point of operation.

But now there has developed a clear separation between Bitcoin, which uses the blockchain, and the blockchain, which can be used without Bitcoin.

The blockchain is used to store information about transactions. When you consider this at 10,000 feet, this is essentially what a bank’s core systems have been built to provide.

In essence, the blockchain is both a threat and opportunity for the banks.


Blockchain is digital banking

In some respects the blockchain is employing concepts and technologies that already exist, so what’s really new?
Shared ledger: Systems of record existed before the blockchain.
Cryptography: The basis of current commerce.
Smart contracts: We had this with Workflow technology
Consensus (of the nodes that validate transactions): This is new!

Fundamentally this is taking money and banks into a true digital era. What I mean by this is that most large banks have been innovating on the edges with new interfaces, UX etc.

Blockchain is using all of these technologies together and that is a key difference.The blockchain is all about technologies that are all massively compute-technology-intensive with compliance and auditing built in from scratch.


Jargon

There is significant jargon in this space: Sidechains, coloured coins, smart contracts and more. I’m not going to attempt tackle them in this article.

What should be understood, however, is that there are public and private blockchains. The private ones are permissioned with known participants, while the public ones are what are called permission-less and involve untrusted third parties.

You can store just about any information on a blockchain: Names, addresses, ID, passport, photos. In fact you could store your whole life on this medium and then employ it to validate yourself when you need to fill in forms or identify yourself.

It is expected that employing private blockchain technology to provide point solutions will be the starting point for most of the banks that are interested in the technology.

There will be a natural resistance to tackle public blockchains as this requires much greater coordination and regulatory approval.


Regulators should be friends

Regulators have yet to endorse blockchain, but neither have they condemned it as inappropriate.
There has been a strong belief that this lack of being a declared safe playground held back the technology, with the uncertainty slowing uptake.

However, this no longer the case: There is an explosion of blockchain use cases with more than 50 ways to apply this technology in innovative fashions. Over the last few weeks I’ve heard three to four pitches from new startups that are in this space.

Regulators are naturally conservative, but the power of the blockchain has great potential. Just imagine a bank having a private blockchain system used adjacent to their core banking or payments applications.

Right out of the box a blockchain has a built-in audit trail. You can trace or interrogate the data, and theoretically this would allow a regulator to perform their own searches of the data set.

That is, frankly, a scary thought for many banks but the transparency it could bring would be welcomed by regulators.


A win-win for regulators and banks?

There is a significant cost for every bank to be compliant with growing regulatory requirements – AML, FATCA, APRA and so on. Compliance costs have been a major component of strategic project spend at banks.

It is not a surprise to hear that a major bank spends $100 million to $200 million on regulatory compliance for just one small requirement.
This is clearly required to keep things running effectively, but each new layer of regulatory compliance adds an incredible burden and the required investment doesn’t add a single dollar of profit.

Embracing the blockchain for private in-bank use to replace existing legacy can yield immediate benefits for a bank — and immediate benefits for regulators.

It was my ‘ah ha’ moment that this is a win-win.

We have to be careful when making these kinds of changes — the implications are significant — but it is almost undeniable that the benefits will outweigh the costs both in the short and longer term.

What’s blocking the blockchain?

It is a question of ‘what’ not ‘who’ is blocking the blockchain. The ‘what’ is that adoption will take time; the systems are complex and perhaps a tad fragile. But there are benefits in to be realised when it comes to cost savings and efficiency.

Moreover the banks are embracing this threat. They realise that if they don’t, they will go the way of Kodak.

I’ve heard it said that the blockchain will be as big as the web. If that is the case then we will are witnessing a massive and significant event.

http://www.computerworld.com.au/article/590571/who-blocking-blockchain/

8 minutes to change the way the world banks

minutes to change the way the world banks

David Gee was a judge at the recent Citi Mobile Challenge in Sydney where innovators were given 8 minutes to pitch their mobile apps. He discusses his top picks.
Last week, Citi held the Sydney leg of its Mobile Challenge, which gives FinTech developers worldwide a chance to compete against each other to create innovations that work with existing Citi technology.

The Citi Mobile Challenge in Asia-Pacific is a next-generation accelerator that combines a virtual hackathon with a developer program, and worldwide network of FinTech experts, to help create solutions across more than 100 markets.

There were 17 finalists in the Sydney Citi Mobile Challenge, primarily from Australia but also the US, Spain, and New Zealand. It is interesting to note that there were more finalists at the same events in Bengaluru, Hong Kong, and Singapore. The perplexing question is, does this reflect on the quality of FinTech startups in Australia?

It is always tricky as a judge to work out and calibrate what looks like a slick presentation versus a demo that has real potential with a significant value proposition.
To make this assessment, I was there with 45 other judges to rate pitches (innovators were given a maximum of 8 minutes) using the 5 star evaluation criteria on a mobile app.

This included the following criteria:
  • Benefit for the user
  • Business potential
  • Customer experience
  • Technical functionality
What was trending?


Wealth investment was clearly over represented with Macrovue, Quant Stats, Simply Wall Street, Gold Bean, SAGE and Wealth Projector with variations of investment portfolios.

A few of the presenters added that they had ‘robo-fund’ functionality, which appeared to be the latest buzzword that everybody wants to quote. All of these startups had some differences but it is undeniable that it was a crowded space in this single pitch event.

Wealth Projector used a gamification approach and had a very nice UX. It noted that the average time spent on the app was 18 minutes, which is quite a reasonable active engagement for such a tool. To me it was the pick of this genre of demos.

There was also a strong trend towards no or low cost platforms such as Mclowd, a self managed superannuation fund, and First Step, which operates as a sweep function for putting small change into an investment vehicle. There were clearly a few judges who like the niche market that this was targeted at.


What was unique?

A startup named Capital Preferences was an interesting risk management approach that used game theory to understand investor preferences. This sounds complex but it was executed simply and made into a task of choosing between two different axis constraints that have different paybacks.

Another demo named Citi Rewards was an entertaining approach that used geo zones to make relevant dining offers. We all thought that this sounded good, until you get overloaded with too many offers, and this would become SPAM.

A startup that I mentor, KnowledgeFlux, was also unique (and while I am biased) it clearly had a very rich proposition that was unlike any other. KnowledgeFlux demonstrated the concept of collective intelligence and how this can be applied to integrate loan processes with information and collaboration.



Wearables and FinTech?


Another startup named Strap presented its app, which interfaces to any wearable that you may use using a standard Citi API. In the demo it was all about Citi providing reward points for the more steps that you take. Perhaps not the most realistic use case.

For me, I can that imagine that a life or health company would consider this as an active risk monitoring approach.


Blockchain for smart tenancy contracts
 

One of my favourite innovators was Michael Smolenski from Lend2Fund, which uses private Blockchain technology and has applied this to standard paper contracts to be digitised into smart contracts with real-time settlement.

His use case outlined was around how landlords not receive their monies for a month lag time. (This was previously deposited into a trust account, with a delay on getting your hands on the funds)

With the future advent of “smart contracts” which have additional information about the contract, terms and deposits, payments could be made into a Citi app and the monies are available instantly. Citi is then rewarded with a transaction fee.

But of course, the bank also the opportunity to cross sell for loan products or perhaps reward payments for on time payment.
Smolenski also made reference to the concept of a virtual credit bureau, and he made a startling comment that if this happens, then the current enterprises that do credit services will be challenged:

In the startup world, it is clear that there are major differences in the capability of the different teams and Citi, like any other corporation, is trying to connect with its customers in new ways.

This is clearly a great approach for this international bank to ensure it is exposed to some great talent and innovative ideas.

There were no winners announced at the Sydney event but for most of the startups, the reward was in connections and the network that was at the meeting.

Are ERP ‘dinosaurs’ on the road to extinction?

David Gee asks if the ‘big two’ ERP giants have seen their day and are making way for more nimble enterprise software players.


In a past life I was an IT consultant. During this time, I always found it rather interesting that the vast majority of organisations would invest millions of dollars into enterprise software marketed by the big three – Peoplesoft, SAP, and Oracle (before it bought PeopleSoft).

At the time, there was a constant stream of companies building business cases to make large investments in IT transformations.

Now, these projects were not easy; they were often delayed or not delivered at all. This is not surprising given that enterprise software is a complex beast.

But things have moved on since those days of client/server computing. Everyone’s moving to the cloud and delivering services to their highly mobile user bases.

For the most part, the likes of SAP and Oracle have struggled to keep pace with this change. This begs the question: Are these ERP dinosaurs on the road to extinction?


Will the force awaken?

The release of the latest Star Wars film, The Force Awakens, reminds me that there’s a new force that has woken up and we are now seeing a fresh class of apps that are attacking what was impregnable territory.

Vinnie Mirchandani discusses this in his 2014 book, SAP Nation 2.0: an empire in disarray. We are seeing pure cloud players such as Salesforce, NetSuite, Workday, and Ramco, taking on the ERP behemoths.

We’ve reached a tipping point as these new cloud and mobile-enabled solutions – which operate ‘capital free’ at third-party cloud service providers – gain in popularity.

Most enterprises started using cloud (to cut costs) and mobile (forced by BYOD). There also was a shift within these organisations towards customer experience and digitalisation.

This shift has been kick-started by many organisations that use cloud services for storage (through AWS and Microsoft Azure, etc) and CRMs such as Salesforce.

These are key core enterprise systems, not subsystems. Such change is not going to happen overnight as enterprises have made significant investments and are slowly depreciating old assets.
But there are compelling reasons to stop and look at an alternative world.




Enterprise apps build for cloud and mobility

Recently, I came across a company named Ramco – which is a subscription offering just like Salesforce. The surprising thing was that it is a fully featured ERP and payroll system that operates in the cloud and with ‘mobility by design.’

It is not a point solution but a fully integrated ‘platform-as-a-service’ that provides rich functionality just like SAP and Oracle.

Where it starts to separate itself from the big boys is that it is also quicker to implement and cheaper – we are talking months not years of effort.

But for me the biggest factor was the design, which has mobility built in and it’s not an add-on. One simple example is a concept called Mail it by mailing “AL” to an email address, your annual leave balanced is returned.


Similarly, if I want to request annual leave or a salary slip, it’s all done over email. Or if I want to get a new hire approved, it’s a mobile task on your browser or even SMS.


The concept of Zero UI


By definition, Zero UI is the concept of removing the barrier between user and device, and having a more seamless interaction with technology. It is all about making the experience very intuitive and natural.

A great example is the concept of a timesheet and we all hate to fill these in at the best of times.
Ramco’s mobile app has a location-aware timesheet. It knows where you are and will automatically provide a SIRI-like response to help you through a task that you don’t enjoy.

These are not extra add-ons but ‘out of the box’ functions that you can use or ignore as it comes with a standard subscription product.


Add some machine learning

These products also observe your behaviour and once a pattern is established, they suggest a workflow action using a ‘Prompt it’ button.

An example is a routine approval that a manager makes every week, and you are prompted with options to make a decision. No, it’s not big brother but the system observing what is normal and suggesting a few logical options.

But if you don’t like that you can also control your own screens and processes. This is actually at a
‘user’ level and not a ‘group’ basis. The feature, called “Hub it”, allows you to create your own view of the world.

Does the empire strike back?

Obviously, I don’t know how the next Star Wars movie will unfold because it’s being released near Christmas, but in the case of enterprise apps, the more nimble cloud and mobile players will give the legacy vendors a real run for their money.

In fact SAP, Oracle and others are all trying to play catch-up and create cloud solutions. SAP has just announced its SAP Fiori technology to port applications to mobile devices.

Either way, it is clear that the dinosaurs are trying to survive and the question is, ‘will they be able to thrive over the longer-term?’

Perhaps we will know the answer by the time Star Wars VIII is released.

Are ERP ‘dinosaurs’ on the road to extinction?

Wednesday, November 4, 2015

Digital is the Glue for Business – Cyber Security can make this unstuck




Every business is addressing Digital as the approach to drive a better customer experience and to reduce costs through the introduction of self-serve channels.


In the Digital world, everything is open 24 hours per day and that is the basic expectation. Recently SKYPE had an unexpected outage and all customers received an apology with an offer for a week’s free calls.


We expect systems to work 24x7 and that there be no downtime. I’ve seen myself access closed on weekends for basic maintenance and have to do a double take. Oh yeah that’s correct.

Digital is clearly the Glue for Business, even in Australian Government we are seeing the focus on ‘e’ across all portfolios and there are a series of Digital Disruption Government Conferences that have emerged.

Moving into the Digital era, means often that you require capabilities that are not in-house and therefore have to be acquired. This starts to open the Enterprise Fortress and while, openness is not a bad thing this has significant implications for security.

These partners also become the targets for cyber security hackers, which is sobering and we all have existing vendors that may or may not meet the security requirements that we enforce in the Enterprise. If they don’t then it is clear then that you are accepting that risk whether you realise it or not.


Accenture have noted in a recent Strategy document that: “Downtime is not just costly but untenable. Failures and hostile cyber actions have profound impacts on enterprise performance—even enterprise viability”.


CXO Oversight


In every organisation there are usually two CXO parties that are responsible for Cyber Security. This might be the CISO and CIO \ CMO\ CRO or in many organisations this also includes the CEO.

Cyber Security is all about protecting one’s reputation and in a Digital world this is not a domain that can be delegated. It is becoming too important and every breach that has occurred and is going to occur is going to reinforce this position.

The CEO has to take this onto his personal agenda, if he or she doesn’t then it will result in scenarios like we saw in Target USA and many other organisations.

It is reality that cyber security is no longer a backoffice concern and the expectation of Digital Resilence. Our thought leaders at McKinsey have noted that this shift from cyber security as a control function is in the past.

There is a greater integration of Digital IT with Business Processes (the Glue), and with these raised stakes Cyber Security becomes critical.


Extending the Perimeter

This means that our staff, their families and partners that we work with all become part of the security ecosystem. With this scope it is not really possible to simply extend the security perimeter but we have to find mechanisms to educate and provide safeguards for these players.

It won’t be acceptable for staff or partners not to take cyber security policies as serious and it becomes a dismissible offence.

The CEO will also have to provide the input around risk – resource tradeoffs. To actually assume more risk has a real cost and that’s not just Cyber Security Insurance Premiums but largely reputational risk.

For any Digital business ‘trust’ is a critical element of the transaction. It is assumed that you can trust this organisation with your sensitive and valuable data. Any breach of that trust has a cost that is impossible to fully recover from. Just ask any of the Executive teams from organisations that have had major cyber security incidences.


A growing challenge for CMO

Enterprises will progressively embrace greater sources of data and even in the absence of Big Data, this will be sources of data from objects, such as sensors, drones and devices.

Some cool data, but of this information will be sensitive and private. It will require the CXO – perhaps the CMO to be working with the CISO on understanding cyber security which becomes part of the brand.

​What would you do if you received this message?

​What would you do if you received this message?

This was shared with me, earlier this week. It is a fascinating read……

Let me stop here and let you enjoy this.



So what do you do?
You already have been bombarded with 4 million packets per second and you know that it is only time until your system vulnerabilities will start to be exposed. Actually you don’t really know what will happen, as this is the first time you have witnessed this event happening before your eyes.
Once you have got over the poor English language that has been used in the message, it dawns on you that ‘Houston we have a problem’
So what are your options:
  • Call your Telecom provider and ask for their assistance?
  • Get out that business card and buy a DDOS service?
  • Go online and buy 100 bitcoins?
  • Pray like hell or go straight to the pub?

Option 1 your Telco Provider


This is when you try to call in the favour and get your partner to help.
Of course this all depends on your business scale etc and how long you have been working together. However it is unlikely that they would support you, as the attack will start to effect their own service.

Option 2 Buy DDOS

There is no time to negotiate the rate, so it will be at the top of the range of the price book. It is likely that you will need to escalate the approval as it is outside of normal delegated authority.
You will expect that while this measure will work, that there will be questions asked from Risk Committees, Procurement and others about why this transpired. While you may get the organisation out of trouble, you may have landed in it along the way.

Option 3 Buy Bitcoins

There is never a fast way to acquire Bitcoins, unless you have already traded in the past and have already completed the normal KYC process.
If you do have Bitcoins, then you will also be suspicious that this is not going to be the end of the demands.
Arrhg……


Option 4 - Pray like hell or Go to the Pub

Sorry, this will only serve to soothe you and numb your feelings. But actually not have any added benefit to the situation.
It may be cheaper than 100 bitcoins, but your career may be over and there’s not much that you can do.


The Real Case Study 

In this real life example, that occurred option 2 was chosen by the client.
They actually had a DDOS service that was in-place and they had tested this on a periodic basis. The SLA was 15 minutes and this was nearly met, however there was human judgment involved and that delayed this by a few additional minutes.

As the business was an online mobile based company, any outage would have dire consequences and the hackers chose the perfect time to strike – which happened to be at an expected peak time.

Once the network traffic was diverted via the DDOS provider, the danger was averted and in effect the attack was abandoned………Life reverted to normal.

Some Learnings

At the time of the crisis – a 3rd party organization was engaged to provide the Network and Cyber Security monitoring and they took the necessary and express actions to address the issue. They told me this story and to protect the innocent they have declined to be named or to share their client’s name.

This is even when things actually worked out well.

The other learning was that it was expected that this organization could withstand up to 500MB before the firewalls would start to drop packets and become useless.
However the learning was that the packets that were sent to flood the firewall were designed to maximize damage and the issue kicked in much earlier than expected at 300MB of bandwidth.

It is not impossible but actually very hard to practice such a scenario.