SLIDE 1
1 2 3 Combining the management and technical streams is something - - PDF document
1 2 3 Combining the management and technical streams is something - - PDF document
1 2 3 Combining the management and technical streams is something new for OWASP and presents me with a dilemma. Now I'll have to speak slower so the techs can keep up. 4 Places what I've worked since 1985. 5 6 Let's have a wallow
SLIDE 2
SLIDE 3
3
SLIDE 4
- Combining the management and technical streams is something new for
OWASP and presents me with a dilemma.
- Now I'll have to speak slower so the techs can keep up.
4
SLIDE 5
Places what I've worked since 1985. 5
SLIDE 6
6
SLIDE 7
- Let's have a wallow in nostalgia.
- Hands up who remembers this film?
7
SLIDE 8
My soon-to-be Operations Manager asked me the fateful question. 8
SLIDE 9
- Another intriguing question, although not one that keeps me up at night.
- At Sun Life of Canada, around 1992, the following conversation took place.
9
SLIDE 10
- Along with the change in title came a change in attitude.
- Now they felt empowered somehow…
10
SLIDE 11
Dependent on where you were in the world. 11
SLIDE 12
Turns out it was another type of PC they wanted to talk to me about. 12
SLIDE 13
- What they were known as then.
- The Atari 400 was introduced in 1979, and manufactured until 1992.
- Based on the 8-bit MOS Technology 6502 CPU, running at 1.79 MHz, the
same processor as used in the Apple II, Nintendo Entertainment System, and Commodore 64. 13
SLIDE 14
Popular as much for gaming as for programming (Atari BASIC). 14
SLIDE 15
15
SLIDE 16
- While also a standalone PC, could emulate an IBM 3270 'dumb' mainframe
terminal.
- Had an IBM PC 5150 for WordPerfect.
16
SLIDE 17
A nod to those early IBM manuals. 17
SLIDE 18
- In early 1996 there were only 100,000 websites.
- The #1 browser was Netscape Navigator (IE a distant second; IE 3
launched 1996). 18
SLIDE 19
The Internet was like the 'Wild Wild West' in those days. 19
SLIDE 20
- A 28.8 kbps modem led to much disappointment!
- An image with "A million psychedelic colours"? Yeah right!
- A 28.8 kbps modem would load the average webpage (@10kb with no
graphics) in around 3 seconds.
- A small, single graphic (@30kb) added around 9 seconds; so 12 seconds
total.
- It was common practice to disable pictures and other graphics, so pages
loaded faster. 20
SLIDE 21
When I returned to NZ in 2003, you were lucky if there were two to three jobs
- n offer.
21
SLIDE 22
More on this later… 22
SLIDE 23
- The last two are interesting.
- People are looking for actual managers now - not simply techs who also
manager. 23
SLIDE 24
20 plus years ago, we had all of these: Now it's all in one gadget … right? 24
SLIDE 25
- What's this say about our modern society?
- I have no idea…
25
SLIDE 26
26
SLIDE 27
- First saw virus this in the UK in the early 90's.
- And it’s not ‘thought to have been’ - it was.
27
SLIDE 28
28
SLIDE 29
29
SLIDE 30
This didn't stop the AV vendors, of course… 30
SLIDE 31
31
SLIDE 32
Although they were around then. 32
SLIDE 33
- It was nasty, okay?
- A user would be hard pressed to recover their data if the virus triggered.
33
SLIDE 34
Fuelled in part by John McAfee, the AV company founder, who predicted that upwards of five million PCs would be infected. 34
SLIDE 35
- The total cost of the work done in preparation for Y2K, worldwide, is
estimated at over US$300 billion.
- It could be as high as US$500 billion.
35
SLIDE 36
Thanks in part to the widespread uptake of AV software before - and after - the event. 36
SLIDE 37
37
SLIDE 38
And my favourite from that time… 38
SLIDE 39
- The whole "Sky is falling!" attitude began to wear very thin.
- We had to seek different, more imaginative ways to get management's
attention.
- Covered in a previous OWASP talk.
39
SLIDE 40
- Was it, is it, or should it be?
- We didn't know what to call ourselves!
40
SLIDE 41
- "I don't have the answer here…"
- Never been called "Computer Security" or "Cyber Security" anything (except
perhaps a 'threat to'), but then I've not worked that often for any government. 41
SLIDE 42
42
SLIDE 43
Hager had used (surprise!) extracts from 475 leaked Brash emails. 43
SLIDE 44
Despite police ruling out a breach of the parliamentary computer system. 44
SLIDE 45
Albeit six years later… 45
SLIDE 46
46
SLIDE 47
- Thing to remember here is: Even, and finally, the Government ‘gets
hackers.’
- Important because, back in the day, the Government almost ignored
InfoSec.
- Infosec now in the public psyche.
47
SLIDE 48
OMG! 48
SLIDE 49
- Who's thinking of the children? President Obama apparently…
- Again: Hackers and InfoSec go 'mainstream.’
49
SLIDE 50
Ranked on projected openings; rate of growth; job prospects; unemployment rates; salary; and job satisfaction. 50
SLIDE 51
Weird how every other one is medical related. 51
SLIDE 52
52
SLIDE 53
53
SLIDE 54
- The media, and some of us too, went hysterical.
- The '5-minute Rule' took me a long time to learn.
54
SLIDE 55
- Reference the Michelangelo virus: This attitude is so last century; learn to
approach a problem from other, more fruitful, angles.
- Fellow worker lesson.
55
SLIDE 56
Learn to accept that others will totally misunderstand what you do or have done, and learn to live with it. 56
SLIDE 57
Accept that your peers, bosses, and those in other fields don't always know what they're talking about. 57
SLIDE 58
- One of Obama's proposed laws means media could be charged with
computer crimes for obtaining documents taken without authorisation from a government computer system by a whistleblower, or for sifting through data leaked online by hackers.
- And let's not mention NSA spying shall we?
58
SLIDE 59
- You started out curious.
- Stay curious; and continue to learn about the industry you're in.
59
SLIDE 60
- Tech is sexy; love the tech - but don't forget other stuff is also important.
- Remember that what we have right now, is firmly based on what we had in
the past. 60
SLIDE 61
My favourite quote… 61
SLIDE 62
- At least a dozen warships stand guard to detect and deter any intruders.
- Like those surrounding the USS Kitty Hawk back in 2007.
62
SLIDE 63
- Don't dismiss the 'tried and true' for the 'latest thing'; lessons from the past
still hold true.
- Also: Legacy systems.
63
SLIDE 64
- Remember Schneier?
- Whether considering security, developing, whatever.
64
SLIDE 65
- The goal should be to define a 'fit-for-purpose' environment.
- First make the people and processes more efficient.
- Then give employees the tools and technology to make them more
effective. 65
SLIDE 66
66
SLIDE 67
67
SLIDE 68
68
SLIDE 69