All posts

Cyber Citizenship at The-C2

Simon Edwards, SE Labs, Speaking at The C2

When a Random Panel Question Nails It

At the end of The-C2 cyber threat intelligence conference, I stood up to summarise and reflect on the talks and break-out discussions enjoyed by the delegates over the previous two days.

Initially I was going to run through each of the talks and pull out a few of the key conclusions. But something unexpected happened. There was one question that came up on the first day’s panel that really grabbed my attention. It stuck in my head, and I ended up fixating on it all evening, and again the following morning.

It’s quite a hard question to understand, on the face of it. So, I didn’t really give it much thought, at least initially. But I was sitting on the panel so I figured I should at least get to grips with it. With some effort I did my best.

The question was: “Do you believe businesses fully understand how their digital supply chains underpin national infrastructure”

The obvious answer is, “no.”

That’s accurate and we can believe it because most businesses don’t have a cyber security plan, which means they are not thinking about cyber security at all. Which also means that the level of sophistication required to visualise and understand a cyber security supply chain is clearly not there. So, no. They don’t understand.

Good Citizens Work Together

When I started writing up my notes for the closing speech of The-C2 I kept coming back to that question. Something about it bothered me. It felt almost profound. And then I realised that the question is really about what it means to be a good citizen.

By ‘good’ I mean as considered to be good in a liberal democracy. In my opinion, being good is where we look after each other rather than climbing over everyone else to score personal wins. We cooperate, in the way that has made human beings the dominant species in the world. For better or worse.

In the non-digital world we expect (and sometimes reward) good behaviour and punish bad behaviour. That really helps foster cooperation.

Culture vs. Law

‘Good’ and ‘bad’ are both cultural and legal concepts. You can do what your people expect or want; and you can follow your government’s law.

These two things do not always align.

I’ve seen enough people ignoring road crossing signs; warnings not to swim; and other examples of low-level non-compliance. I’d say that was cultural. I know people from many cultures around the world, and some are astounded by Londoners’ inability to care about traffic lights. I have personally been shocked at the difference in parental discipline shown by certain groups as I’ve travelled the world.

When you get a culture clash it jars. When someone doesn’t comply with my concept of what it means to be polite, efficient or respectful, there is friction. Cultures require members to comply with ‘normal’, or problems arise. There can be ‘tut’ moments of irritation or mob violence.

As one of The-C2 delegates said during the panel in question, we even have cultural differences when it comes to doing business. Europeans and Americans have, in his experience, quite different approaches to buying and selling. Europeans might be slower to buy, but they might stick with the product longer than a fast-buying American. That’s not very exciting insight for sales teams. It’s a bit too strategic for a salesperson who will not earn a commission for each year that the buyer stays a customer.

Good Law vs. Bad Law

We know there are countries in which people do not enjoy the same levels of freedom that we do in parts of the West. The law of those lands are repressive, we think. And when those people agree, and go against the law, there can be severe repercussions. Iran is the most obvious example in recent months. There have been plenty of others in living memory.

The law requires citizens to comply with the system. There can be formal warnings, arrests or torture.

Decency and Trust

In our society it’s generally considered that people should be responsible and contribute to the system, by paying taxes for example. Then add to that the concept of decency – such as stopping someone stepping out accidentally (or purposefully) into traffic. Noticing when someone drops a bank note and handing it back to them. Using litter (trash) bins (cans) rather than dropping rubbish in the street.

That’s not supposed to be special kindness. That’s baseline good behaviour that we were taught as children. It helps build some level of trust in our community, without which our lives would be much harder and messier.

We sometimes give to charity. That’s considered to be kindness by some, and a duty by others. Maybe larger businesses can show similar kindness to its smaller suppliers and help with the so-called ‘cyber poverty’ that affects most businesses that aren’t in the top 10%.

This is something that came up in one of The-C2’s first day’s breakout sessions and in a great pre-dinner speech on the first night. It’s a growing theme, it seems. There’s a direct self-interested benefit to this ‘charity’, so it doesn’t even have to be altruistic. It could even be tax deductible.

Joint Resilience

It’s probably necessary. The same dinner speaker made the point that resilience is not a solo effort. Humans are a successful species because we cooperate. As hackers continue to win, and AI helps them accelerate, this feels like an opportunity to exercise some of that cooperation.

The-C2, and other meetings like it, play a small part of that. But it needs to be more systemic. Probably culturally, rather than legally.

We reject terrible crimes. We are repelled by those who murder, and we avoid being murderers. For that extreme level of crime there isn’t usually any real conscious thought: “Today I must remember not to murder!”

We don’t like it and so we don’t do it. Most of us can get through a day without trying not to murder someone. It’s not the illegality of murder that stops most of us going on a spree. It’s probably a mixture of how we are brought up and how we evolved.

Herd Benefits

So back to the original point – that question about businesses and their position in the supply chain. This question implies that they have a responsibility to the greater good. Or at least to the other businesses in their immediate ecosystem. There is probably some etiquette too. What does decency look like in cyber security? Our parents and teachers didn’t coach us to install anti-virus for other peoples’ benefit. There is a whole other talk here, on the concept of herd immunity. If enough systems are hardened; if enough people behave in a certain, secure way; then it makes life much harder for the attackers overall.

Even the ignorant benefit from the wider knowledge. We all benefit.

Maybe AI can help with this. Maybe it can make small improvements to security at scale. Certainly some of the cyber security vendor companies are banking on that. Home users don’t care about ‘malware’. But they do care about scams, for example. So we’re seeing ‘anti-scam’ leading the marketing charge now, rather than ‘anti-virus’.

And while AI won’t be perfect, it’s better than what we have – which is zero knowledge for most people and businesses.

Do Your Research

There’s some classic advice that tech journalists always give to help keep you safe with your smartphones. Always install from known stores and (get this) research the product. Who is going to do that? What does that mean? To help, we published a more in-depth guide on how to research a mobile app without being a cyber security expert.

But in general, when we’re asked to do our research, we’re often left in the dark. And then later criticised for believing what we read online.

One of our speakers noted that common advice when deploying AI is to perform a risk assessment. But how? Of what, exactly? We need help. We probably need to be told what to think, many times. Or at least be given information that it’s possible to consume meaningfully.

Another speaker at The-C2 noted that we’re not built to adapt as fast as the current technology. We’ve heard that we’re looking at something like the invention of the printing press, which caused huge disruption and brought down the status quo. The danger today is that, unlike then, power won’t pass to the people but to tech oligarchs.

We’re all in it together. Technology is both powerful and dangerous. Teaching each other and adopting a sense of group responsibility might be the way we win the 21st century.

The-C2, hosted by SE Labs, is a threat intelligence conference that connects multinational business executives with the cutting edge of the cyber security industry. For more information please visit https://the-c2.com/

All posts

Beware fake anti-virus reviews

You need anti-virus and there is a load of advice online about which to buy. Who can you trust?

Vertical image concentrated young African American woman in eyewear using digital touchpad, enjoying web surfing information, working remotely, typing email, planning meeting, communicating distantly.

Some anti-virus reviewers know what they are talking about. Others don’t. Some are just in it for the money. How can you tell which reviews are worth your time?

How to choose anti-virus for your PC and your family

Most people believe that you should run anti-virus on your PC. Independent security experts, governments and every computer journalist on the planet promotes this advice. And they are not wrong. There is no doubt that installing anti-virus is one of the most important things you can do to keep your computer and its data safe.

Continue reading “Beware fake anti-virus reviews”
All posts

Mac anti-virus

All you need to know about anti-virus on the Mac.

At SE Labs we are often asked, “which is the best anti-virus for the Mac?” And, “do you need anti-malware for MacBooks?” For reasons we’ll explain, we’ve not published an endpoint security report for Mac-based products (yet).

But we do have an insight into how Mac threats work and how Apple tries to protect users. In this article we cover everything you need to know.

Continue reading “Mac anti-virus”
All posts

Security planning for normal people

The first security technique you should master!

Security planning for normal people

Security planning can make your life easier to manage. It’s easy to become paralysed when you consider all of the threats that exist and all of the possible solutions. You can’t buy every security product available and you certainly shouldn’t even try.

There are risks that we all face (let’s call those ‘general risks’) and risks that are quite specific to you (‘individual risks’).

Security planning for anyone, whether you are the CEO of a large enterprise or a retired amateur gardener, should take into account what risks you (specifically) face and the consequences of something bad actually happening.

General risks

In this article we’re going to focus on cybersecurity, but the principles apply to any area of your life. In the computing world there are three major threats that we all face:

Continue reading “Security planning for normal people”
All posts

Choose the best security product

By understanding the rules of security testing

choose the best security product

The reports below contain security testing results. You can compare the performance of a variety of products that claim to protect you against online threats. This, in theory, will help individuals and businesses choose the best security product.

Rules of engagement

But these are free reports. How can you trust that the high-scoring vendors didn’t just pay for their ranking? Do you suspect that some low-scoring vendors dropped out of the report? Or asked to be retested until they scored better?

What are the rules behind the scenes in security testing?

Continue reading “Choose the best security product”
All posts

Can general security tests be useful?

Real-world security reports don’t always reflect your real world.

Real-world security reports

What makes a real-world security test useful? Does it need to provide a full assessment of a product or service? An assessment that is directly relevant for all potential customers? Or does it need to give just a taste of how effective a product can be?

The perfect security test

Tests can vary in how they are run and the level of information that they provide. Not all tests are equally reliable or even useful. But one thing they all have in common is that they aren’t perfect. Let’s look at how tests are limited, how you can interpret them and what the future holds.

Continue reading “Can general security tests be useful?”
All posts

3 ways to follow SE Labs

And Facebook isn’t one

3 ways to follow SE Labs

Updated 18th November, 2022: We no longer officially support Twitter

There are lots of ways that you can contact us, watch what we’re doing and keep up to date. But we’re stepping back from one so we can focus better on the others. Find out about the best 3 ways to follow SE Labs.

The 3 best ways to follow SE Labs

While we plan to continue maintaining a basic presence on Facebook, the best way to get the latest news, views and chat with us is to use one or more of the following three services.

Continue reading “3 ways to follow SE Labs”
All posts

What does a breach look like?

Understand what a real hacking attack looks like to the attacker and defenders

breach visualisation

The IT security world is rocked by news of breach after breach, including the shocking disclosure of the SolarWinds attack. Data is stolen, deleted or corrupted and… well you know. It’s a total mess. Journalists focus on basic outcomes, while technical blogs look at esoteric technical details. We’ve explained, in laymen’s terms, what a breach looks like from an attacker’s point of view. And from the position of the defenders.

Continue reading “What does a breach look like?”
All posts

Securing a business from scratch

 

Building and launching a start-up company is a challenge in itself. Securing it when it is new, young and vulnerable is something else. It’s very necessary but also hard if you don’t know what you’re doing. And can you afford a consultant in the early days?

If your new business is IT-based and focused on security then you’re in a stronger position than, say, an organic make-up business or an ethical coffee brand.

Continue reading “Securing a business from scratch”
All posts

Who certifies the certifiers?

At SE Labs we test security software and services methodically, realistically and in great detail. Or, at least, we claim to. But how does anyone really know? Do we follow quality management requirements? And what does that even mean?

Testing can be a very process-driven task. If you are going to be fair to every product undergoing a test you need to be consistent with how you run the test as a whole and how you test each individual product. It’s probably best carried out by well-qualified people, then?

You don’t need to be certified to work here…

We figured that as we certify, so should we be certified. As such, for the last few months we have worked towards having our business certified to an international level for providing consistent security testing services.

Another purpose of quality management is improvement. There is always room for improvement in testing, and we constantly strive to make things more realistic, useful and fair for everyone involved.

Quality management certified

As such I am extremely proud to announce that SE Labs has now achieved compliance with the ISO 9001:2015 standard for quality management systems, specifically relating to “The Provision of IT Security Product Testing”.

That means we do what we say we do, and strive to improve.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us