Managing Risks Simplified

You can't handle the risk

As HMRC remind us, tax doesn’t have to be taxing. Well neither does risk management. In fact, assessing risks is something we learn from a young age. But when we don our suits and enter the corporate world, all sense of how we should manage risk seems to go out of the window.

 
 
 
A typical risk [...]

5 Comments

The need to complicate infosec

Errr which way now dear?

Over the years, information security has moved from being a dark art practised by a few beardies to becoming something most people understand and appreciate. Also, as time has progressed, infosec professionals have become more apt at explaining infosec to the layman in terms they all understand. Additionally security awareness programmes in most companies, coupled [...]

6 Comments

Unlikely Alliances

I'd like to thank this man for helping me and my friends make a lotta money

I’ve been asked many times, mostly by myself, as to the best way to convince business people to open their purse strings and spend some money on security.
It seems as if business people, developers, IT managers, procurement, HR, finance; basically anyone and everyone is only prepared to spend the bare minimum on security features to [...]

5 Comments

Infosec in 10 years time

Even in the future I can't remember my password

Unless you’re a worthless, unemployed lazy bum, you’re more than likely to have come across a process known as an interview.
For you lazy bums out there who’ve never been interviewed, an interview is a bit like what you do when buying your first car. You have little idea of what you want, but you kick [...]

3 Comments

Misunderstanding Cybercrime

Thats a big fingerprint

Information Security used to be easy. I would spend the day emailing friends, wait until my manager hassled me for the 17th time about responding to a users query, make a couple of recommendations attaching a copy of the security policy then go back to emailing pictures which explained why there was only one female [...]

11 Comments

Most Annoying Consultants

Thats all your stinkin policy is good for

Infosec would have a better reputation if all consultants were perfect like me. When speaking to a project manager, we should have completed our research. Scoured the internet, finding out what a particular application does and how many security vulnerabilities are out there. The list goes on, but suffice to say a good consultant always [...]

2 Comments

Most over-hyped security

I don't care if you're an old woman. You're taking your shoes off or I will tazer your wrinkly ass

Whether you call it security theatre or just a sales pitch that sets expectations too high. We’ve had lots of products and processes that have claimed to increase security only to contain enough hot air to propel one of Richard Bransons baloons across the world.
Here’s the cynical breakdown of security that was too hyped up.
Airport [...]

1 Comment

Michael Jackson on Infosec

Wacko Jacko the IT Security Experto

 
After being declared having the best infosec song ever with “Smooth Criminal”, Michael Jackson took some time out of his busy schedule to speak exclusively with the cynic.

Moonwalking its way right onto this site, the full unedited text of how it went down:

IC: Hi Michael, thanks for taking the time out to speak with me [...]

9 Comments

Is Your Firewall A Fire Hazard?

With the economy taking quite a bashing  and the housing market looking pretty miserable the question might be: Where is the silver lining? And I think I may have found it for those poor souls who have just seen their plans of moving to a new house dashed – you don’t have to tidy up! [...]

No Comments

7 ways Infosec can prepare you for Swine Flu

Pandemic flu, virus outbreaks, the end of the world. These are things that a cynic laughs in the face of… but an infosec cynic only raises an eyebrow.
If working in Infosec, which is an industry built on the solid foundations of PC viruses, has taught me anything. Its how to survive a pandemic. I look [...]

2 Comments

5 reasons to love infosec

Infosec sometimes unfairly gets a lot of bad press for being a barrier to business goals and objectives. How infosec professionals don’t understand business needs and drivers. How pouring money into security is about as good as burning it.
But infosec has improved the quality of working and the lives of workers the world over. The [...]

4 Comments

When the Cynic went to Infosec

Day 1 and I was determined to be at infosec nice and early, wanting to cram all the information I could in the one day that I was attending. However, things didn’t start off too well.The trains on the Picadilly line were suspended and took me around 2 hours getting to Earls Court.
Other than the [...]

6 Comments

Cracking Cryptography

How to bypass encryption

I think the cartoon sums it all up! Wikipedia even explains it here.

No Comments

Repenting of your seven deadly sins

SIN! SIN! Most people know sin. Whether you are religious or not, sin is a really useful concept that involves a wrong attitude toward your higher power and results in alienation from it. All major faiths, Islam, Christianity, Judaism have the concept. Even if you are not a believer, you have probably seen movies such [...]

No Comments

8 films that needed more infosec

Many times its difficult to illustrate the benefits of following good information security advice. Company’s tend to keep quiet about their failings so there are few case study’s available to analyse.

But not to fear, the cynic has improvised and analysed 8 movies whose entire outcomes could have been changed had some simple infosec guidelines been [...]

3 Comments

The Cynics guide to information security consultancy

So you want to be an infosec consultant? If you’re like most guys, its better you consider a career in risk management or audit. Or maybe you’ve already got some variation of “security” in your job title but are stuck in a rut. Results are coming slowly and career progression is almost non-existent. What you [...]

4 Comments

Not so good security

fail owned pwned pictures

For the easter weekend, a few reminders of how security doesn’t work… or does it?

No Comments

Prevent terminated employees from accessing sensitive data

Redundancies and corporate re-organisations are an unfortunate reality in today’s economic climate. Too often, businesses leave themselves vulnerable to a data breach or serious security incident during the redundancy cycle by not immediately revoking the network and application access points of terminated employees.
With Companies like RBS announcing massive job cuts, the threats that these companies [...]

No Comments

The Cynical Roundup: The year so far Q1-2009

Obama allowed to keep his blackberry
President 2.0 fought against the Whitehouse’s security policy of no personal emails by lying on the floor of the oval office and crying for 15 minutes until his demands were met.
 
Neither George W Bush not Bill Clinton used e-mail during their presidencies. When asked to comment on blackberry users, George [...]

No Comments

Crashing Cars and Firewall Management

With all the doom and gloom of the past few months and billions of whatever currency you like being poured into the economy I have to report on a ray of hope. I think my son may have hit on the solution completely inadvertently. He’s not a renowned economist, just an honest, hard working car [...]

No Comments