United Kingdom •
Request Pricing
About
Infectiously passionate about privacy and cyber security. It’s personal with me.
The Circle of Failure: Why the Cybersecurity Industry does not work
The cybersecurity industry does not work. Say it out loud and you will feel better. This is a frank assessment of how and why our vendors, service providers and the businesses we work for have failed to meet the fundamental challenges of cyber security. It examines the commercial motives of each of these critical players and how we as consumers are caught in a “circle of failure”. When trying to protect our businesses. It considers what lessons we can learn from these design failures and what we must do to bring about real, meaningful change in our industry.
Vendors...or Attack Vectors?
Do the commercial products we deploy on your systems provide back doors to attackers? Was the Solar Winds breach an anomaly or a harbinger of things to come? Commercial software has become extremely complex. We don’t know what it contains, what it runs, what it’s connects to or, what data it may be exfiltrating. We assume its security integrity but cannot verify it. The problem is one of economic incentives. The market rewards vendors who can quickly launch software with new features. It rewards products that covertly collect and transmit user data. The market does not reward security or privacy. The market does not reward transparency or resiliency. The market prioritises profit over security. Why do we fail to recognise this? This presentation explores our significant reliance on vendors and the premise that the products we purchase from them do not provide attack vectors to our systems. It specifically highlights the vendors we purchase security products from to protect our system
Cybercrime: The Org Chart
To understand the power and professionalism of today’s cybercriminal organisations, we need only take a good look at its organisation chart. This talk deconstructs the modern cybercriminal organisation reviewing the roles, responsibilities and reporting lines associated with 12 key positions in an established CyberCrime.com business. Additionally, it presents the key roles in a cybercriminal “start-up” business to ensure its success. The content of this presentation is based on over 20 years of open-source and dark web available material along with publicly available law enforcement case documentation.
Your perspective matters!
What was it like engaging with Richard?