Wake Up Call to MBA Schools: Security & Privacy Concepts

[Español] Ya hace más de un año que finalicé mi Executive MBA en una conocida escuela de negocios, que fue una experiencia interesante y enriquecedora, y por otro lado llevo en el mundo de la seguridad informática muchos años en los que he visto casi de todo. Por eso he pensado que para este post sería interesante comentar una carencia que tienen la mayoría de programas MBA en relación con mi carrera profesional.

[English] It has been more than a year since I did finish my Executive MBA at a well-known business school, being an interesting and rewarding experience, and on the other hand I have been working in the world of computer security for many years where I’ve seen almost everything. That is why I thought that for this post it would be interesting to discuss an existing gap in most MBA programs related to my professional career.

En las diferentes asignaturas ves de forma rápida multitud de conceptos sobre operaciones, finanzas, marketing, estrategia, RSC, emprendedores, etc. y si es una escuela moderna seguramente también un curso de tecnología. Es en esta asignatura donde echo en falta algo más de contenido  sobre seguridad y privacidad para los tiempos que corren.

In the different subjects you quickly view multitude of concepts from operations, finance, marketing, strategy, CSR, entrepreneurship, etc. and if it is a modern school maybe a technology course. It is in this subject where I miss something about security and privacy concepts for the times we are in.

Las escuelas de negocios proclaman que crean a los líderes del mañana pero en la mayoría de casos estos líderes no salen preparados para abordar un tema como es la seguridad y privacidad. Unos conocimientos básicos son igualmente necesarios que en otras áreas como finanzas, estrategia o marketing para que la compañía goce de una buena salud.

Business schools claim that they create the leaders of tomorrow, but in most cases these leaders do not come prepared to address a topic such as security and privacy. A few basic skills are equally required as other areas such as finance, strategy and marketing for the company to enjoy a good health.

Nadie puede negar que prácticamente todas las empresas del mundo utilizan la tecnología de forma diaria mediante correos electrónicos, blog corporativos, navegación por Internet, redes sociales, dispositivos móviles o la mítica Nube, incluso muchas empresas utilizan la tecnología como palanca de innovación.  Sin embargo a pesar de todo este uso la seguridad y privacidad suelen ser temas olvidados por la alta dirección, grave error.

No one can deny that almost all the companies in the world use technology on a daily basis through e-mails, corporate blogs, browsing the Internet, social networks, mobile devices or the mythical Cloud, even many businesses use technology as a lever for innovation. But despite all this security and privacy issues are being neglected by top management, big mistake.

Si algo hemos aprendido en 2011 es que nadie está a salvo de ser atacado: empresas como RSA, HBGary o Sony han caído victimas de grupos como Anonymous u otros atacantes mediante ataques muy sencillos y ampliamente conocidos. Estos ataques podrían haber sido evitados si las compañías contaran con los recursos apropiados, y para ello los que toman las decisiones tienen que tener la información necesaria.

If we have learned anything in 2011 is that nobody is safe from being attacked: companies such as RSA, HBGary or Sony have fallen victims of groups such as Anonymous or other attackers using very simple and widely known attacks. These attacks could have been avoided if companies had the appropriate resources and for that those who take decisions must have all the necessary information.

Es cierto que existen MBA enfocados a tecnología o específicos en seguridad que cubren esta área, pero no es suficiente. En mi opinión todas las escuelas de MBA deberían contener una sección con conceptos sobre seguridad y privacidad, ya que es fundamental que la alta dirección entienda y ejerza buenas prácticas de seguridad.

It is true that there are MBA focused on technology or even security specific covering this area but this is not enough. In my view all MBA schools should contain a section with security and privacy concepts, given that it is essential that senior management understand and exercise good security practices.

La información al igual que los empleados son posiblemente los dos activos más valiosos de cualquier empresa pero demasiadas veces no se saben identificar, valorar o cuantificar, y  ambos activos quedan tocados si la seguridad de la empresa se ve comprometida con el robo de información: malestar entre los empleados y daño de la imagen corporativa, lo que deriva en daños económicos que ahora sí se podrán cuantificar y que podrían afectar a la PyG.

Similarly, Information and employees are possibly the two most valuable assets of any company that too often are not correctly identified, assessed or quantified, and both assets suffer if the company’s security is compromised with the theft of information: employees discomfort and damage to corporate image, resulting in economic damage that now can be quantified and could affect the P&L.

Las escuelas de negocios hacen un buen trabajo formando líderes, pero con este artículo hago un llamamiento a que incorporen conceptos de seguridad y privacidad en su oferta académica para tener organizaciones más preparadas, de arriba abajo.

Business schools do a good work forming leaders but with this article I appeal to incorporate security and privacy concepts in their academic offerings to have more prepared organizations, from top to bottom.

— Simon Roses Femerling

Posted in Business, Economics, Hacking, Security, Technology | Tagged , , , | Leave a comment

Cyber Warriors Factories

[Español] Hoy en día muchas naciones conscientes de las amenazas en Internet están creando ciber guerreros para poder combatir en este nuevo frente. Aunque la información es escasa algunas de estas naciones han hecho público parte de su plan de ciberguerra y han creado centros de entrenamientos y operaciones. También algunas empresas privadas y universidades ya empiezan a ofrecer este nuevo perfil del siglo XXI, aunque está claro que aún queda un largo camino por recorrer.

[English] Today many nations aware of threats on the Internet are creating Cyber Warriors in order to fight on this new front line. Although information is scarce some of these nations have made public part of their cyber warfare plans and are creating training and operations centers. Also some private companies and universities are beginning to offer this new role of the 21st century although clearly there is still a long way to go.

En este artículo estudiaremos algunas naciones que ofrecen la posibilidad de formarse y/o trabajar como ciber guerrero (Computer Network Operations, CNO), aunque debemos tener en cuenta que al ser un tema sensible generalmente requiere ser ciudadano de ese país para acceder a esta formación y/o trabajo.

In this article we will study some nations offering the possibility of education and/or working as a Cyber Warrior (Computer Network Operations, CNO), although we must bear in mind that due to the sensitive subject it is generally required being a citizen of that country to access this training and/or work.

EE.UU. / USA

Como no podía ser de otra manera EE.UU. dispone de diferentes opciones pero requieren ser ciudadano estadounidense.

As it could not be otherwise USA offers different options, but you need to be a U.S. citizen.

Sector público / Public Sector

Existen más opciones de las aquí presentadas pero hemos intentado resaltar las más significativas.

There are more options of the presented here but we have tried to highlight the most significant.

Sector Privado / Private Sector

El sector privado en USA ha creado una amplia oferta de formación y puestos de trabajo creados por empresas dedicadas a defensa.

The private sector in USA has created a wide range of training and jobs mostly created by companies involved in defense.

Corea del Sur / South Korea

Reino Unido/ UK

 España / Spain

OTAN / NATO

  • La OTAN desde su centro de NATO Cooperative Cyber Defence Centre of Excelence (CCDCOE) ofrece diversos cursos en CNO.
  • NATO from its NATO Cooperative Cyber Defense Centre of Excellence (CCDCOE) offers various courses in CNO.

Países como China, Israel, Francia, Rusia, Alemania, Brasil, India e Irán han anunciado públicamente la creación de unidades de ciberguerra y de centros de entrenamientos militares y/o académicos aunque no existe demasiada información pública al respecto.

Podemos apreciar que hoy en día existe una conciencia por crear estos perfiles en muchas naciones y que algunos países destacan en este campo como son los EE.UU., China o Israel. Sin duda los países que quieran sentirse “ciber seguros” tendrán que hacer grandes esfuerzos.

Si conoces más formación en ciberguerra / CNO o empresas en este campo, por favor envíame un correo con la información :)

¿Te gustaría ser un ciber guerrero o lo has sido? Cuéntanos tu experiencia! 

Countries such as China, Israel, France, Russia, Germany, Brazil, India and Iran have publicly announced the creation of cyber warfare units and training facilities both in the army and/or universities although there is not much public information about it.

We can see that today there is an awareness to create these roles in many nations and some countries stand out in this field such as the United States, China or Israel. Certainly the countries which want to feel “cyber safe” will have to make great efforts.

If you know more training courses in Cyber Warfare / CNO or companies in this area, please send me an email with the information :)

Would you like to be a Cyber Warrior or you’ve been one? Tell us your experience!

— Simon Roses Femerling

Posted in Hacking, Pentest, Security | Tagged , , , , , | Leave a comment

APT Article Published

[Español] Este mes la revista Red Seguridad incluye mi artículo sobre APT (Amenazas Persistentes Avanzadas) basado en mi experiencia personal en el trabajo donde hemos encontrado varias veces este tipo de amenazas.

[English] This month the magazine Red Seguridad includes my article about APT (Advanced persistent threats) based on my personal experience at work where we frequently discover this type of threat.

Sin duda los APT son un tema caliente y en el artículo detallo en qué consisten, casos reales de ataques, por qué se producen y son tan exitosos, así como algunas recomendaciones de cómo las empresas deberían protegerse.

No doubt APT are a hot topic and the article details what they are, cases studies of real attacks, why they occur and why they are so successful as well as some recommendations on how companies should protect themselves.

Por desgracia el artículo solo está en español pero si algún lector extranjero está interesado se lo puedo enviar para que lo traduzca con Bing :)

Unfortunately the article is only in Spanish but if a foreign reader is interested I can send a copy so he can translate it with Bing :)

No os perdáis otros artículos que escribo de forma frecuente en revistas de seguridad y mis servicios, que quizás sean de tu interés ;)

Como siempre un placer y ahora a seguir analizando la inseguridad…

Do not miss other articles that I usually write in security magazines and my services, which may be of interest to you ;)

My pleasure, as usual, and now on to keeping analyzing insecurity…

— Simon Roses Femerling

Posted in Hacking, Pentest, Security | Tagged , , , , , | Leave a comment