Showing posts with label Computer Jihad. Show all posts
Showing posts with label Computer Jihad. Show all posts

Saturday, August 05, 2023

Prediction: Another Year of Living Dangerously...

Will this be another year of living dangerously?

Security forces within your organization are busy at work, contemplating a combined strategy to address a continuing barrage of new potential threats. 

2023-2024 could very well be even more dangerous than this past year.

"Enterprise Security Risk Convergence is the "Operational Risk Management" wave of the future."

How these converged entities are forming and how they will arrive at a single focal point is based on what they both have in common. Information-based assets.

“Contingency Planners” shall be more beware. Savvy CIO's and CxO’s recognize that new threats and soaring costs are two factors driving the convergence or integration of traditional and information security functions in a growing number of global organizations.

Operational Risks span the continuum from the physical to the digital environment in our enterprise ecosystems.

Prepare your organization for the day when the efficiencies and the effectiveness of having redundant safety and security responsibilities becomes a new agenda topic at the next executive retreat.

Business desire for contingency professionals who can examine and assess the risks that organizations face as a whole, is one of the tipping points behind the convergence phenomenon.

In the end, the winners will be those contingency planners that realized that all the guards, gates, firewalls and intrusion prevention systems are nothing more than tools.

What they support is the successful implementation of a Risk Management System focused on intelligence information.

The single asset that security organizations have in common is the dynamically changing information in our contingency plans.

As the Operational Risks continue to surround our supply chains to corporate enterprises, it's imperative strategic planners look at where we are spending our money and deploying our resources.

What would happen to our preparedness, readiness and recovery capabilities if we just reallocated 5% of the corporate marketing budget to our protective intelligence and risk management budget?

If we did, then we might find ourselves with fewer calls to the Courthouse, State house or even to the (202) area code...

Thursday, July 27, 2023

Navigator: Speed of Innovation...

When the Netscape Navigator was finally launched here on our planet Earth, much of humanity was just on the verge of an era of massive organizational change.

Working in the IT industry and living through the transition of our communications era of data transfer across and through the digital Internet in the early days was full scale innovation. In more ways than one.

As the desktop devices were rapidly designed for digital storage and computing power and the software industry was now at the dawn of incorporating modems of mbps data exchange, data integrity, data security and data resilience; our global intelligence strategies were still naive.

Deficient in worldly wisdom and informed judgment, it would not be too long until DISA, DARPA and others expanded the processes for the protection and the exploitation of the Internet. Network Solutions, Inc. ICANN and so many others.

Ft. Meade, MD to McLean, VA to Arlington to Quantico to Mt. Weather, VA. This was only the beginning of the late night SCIF meetings in the late 90’s.

The next data wake up call was February 18, 2001 in Foxstone Park near Vienna, VA when Robert Hanssen was finally arrested. His Palm 3 PDA was logged into evidence.

So what!

The light speed of fiber-optic submarine cables communicating our “Zeros and Ones,” Quantum, Hypersonic missiles at Mach 5, is just an example.

Back in July of 2000, a few stories above 1555 Wilson Boulevard in Arlington, a three year old startup company was already crawling the Internet 24/7, downloading Terabytes of open source information (OSINT). It was named Cyveillance then.

Many of these early Cyveillance founders can still remember what was discovered then, and what the value of international online monitoring services would soon become. The exponential growth of just the “Dark Web” was astonishing.

It was just causing a feeling of great wonder among leadership early mornings and late evenings across the National Capital Region (NCR).

The speed of defense and intelligence innovation and the pace of critical response in those days was truly epic.

On May 11, 2017 the President issued an Executive Order (EO) on strengthening the Cybersecurity of Federal Networks and Critical Infrastructure?

The question now is, why did it take us so long? In the mean time, 20+ years had passed.

In April of 2018, the NIST Cybersecurity Framework 1.1 was updated. Now 5+ years later, the journey to CSF 2.0 is in draft.

One of our U.S. greatest vulnerabilities still remains in so many places. The speed of change and our future technology innovation.

Our next few decades are so ready for acceleration, in so many places.
With so many more new young minds, working alongside our people with real leadership experience. 
With so many new inventions of mankind ready for launch…

Onward!

Sunday, October 09, 2022

Mosaic: Launching New Solution Navigators…

There are countless people and organizations who are articulating the problems that exist in your agency, your business or your non-profit.

Some international entrepreneurs are assisting those who have not developed their own concept selection and development team with solving the identified and validated problems.


The challenge in most entities has been enough resources and the correct people dedicated to defining the problem-sets and then applying a proven methodology for creating a solution space with a mission to deliver potential prototypes for testing.


How fast does your organization move from “Problem Definitions” to “Deliverable Solutions” ?


Well that is going to depend on what business or industry you are competing in across your geographic area. Are you in a small business? A regional enterprise. The national leader in ordering stuff online made by someone else and then delivering it to your customers household doorsteps?


Or are you in a services institution that invents and delivers new process designs. New intellectual capital. New creative ideas. New real-time OSINT information.


Moving from a past historical era where “Problem-space to “Solution-space” may take years, now our 2022 world is witnessing this time line whittled down to days, hours or even seconds.


In our current digital environment, utilizing Quantum capabilities, the problem may be solved in a minute or a second or two.


If you are trying to launch the next space craft to the Moon or Mars or beyond, it could take longer.

Yet what does all of this focus on true innovation really mean to “John Q. Citizen”?


So what?


Do you remember the first time you used Mosaic? What about the Netscape Navigator?


If you do remember, then you have a substantial set of real context on the topic of and history of creative innovation. Solving real-problems.


You actually understand and witnessed the speed at which people are capable of creating “New”.


Defining problem-sets to creating new solution-sets was a daily process for all of those "Digital Navigators" with electronic keyboards and modems in the early 1990’s.


Utilizing our Earths new World Wide Web technologies and capabilities, provided so many with the ability to explore, experiment and test, then to deliver new product solutions for those who did not even know they had a problem yet.


For those so interested in the future of our world and so eager to be innovators in 2022, sometimes you just have to study the past for a lesson. Maybe even read up on Mosaic on Wikipedia.


This journey has been epic. Now get out there and “Do” what you have a passion for and that will make a difference on this rock!

Sunday, February 27, 2022

Insider Threat: Web 3.0 Wild West...

The Insider Threat is an Operational Risk that will never go away. It is without a doubt going to be a continuous issue for the Board of Directors, Corporate Management and shareholders for years to come. 

Fortunately, justice has recently sent a clear message about the continuous threats of Intellectual Property Theft and more. Whether you have an unknown system admin working against you because they didn't get a raise last year or the corporate espionage ring selling secrets or identities it will continue to increase over time.

"Economic espionage is the act of stealing company trade secrets with the intent or knowledge that doing so “will benefit any foreign government, foreign instrumentality, or foreign agent.” 18 U.S.C. 1831(a)(1). The Act also prohibits attempts to steal trade secrets with the intent or knowledge that doing so will benefit a foreign government. 18 U.S.C. §1831(a)(4). Typically, economic espionage is directed or sponsored by a foreign power seeking to secure sensitive trade secrets or business information from U.S. based persons or entities."

This has to do with the new generation of new employees who have grown up using the Internet and downloading Apps or open source software. It's still the digital wild wild West and the policies and ethics workshops are nothing more than a compliance officers single strategy of justifying their existence. 

The Web 3.0 is changing these employees attitudes about sharing everything. Many of them come to the organization with a profile on Facebook and don't have any qualms about sharing their own private information. The leaks to the press on major M & A deals should be enough evidence that even good old fashioned ethics are in jeopardy.

The Insider Threat in a Web 3.0 world is not only here to stay. It is just getting started...

Saturday, January 15, 2022

Madison Ave to Llewellyne Ave: Digital Warfare on our Doorsteps…

Complex Irregular Warfare, whether "Asymmetric or Hybrid" will be exponential into the next decade and shall consume our Earth and beyond.

John Q. Citizen who is walking down the street in Syria or Europe, Africa, Asia, South America or Kyiv already is more aware of this fact.

“Hybridity ... is characterized by the interpenetration of a wide range of non-state actors including any combination of insurgent or terrorist networks; organized crime groups; social groups such as clans, tribes or ethnic groups; and ideologically or religiously motivated organizations; all of which may be backed covertly or overtly by states and/or legitimate businesses.” 
Schroefl and Kaufman,
“Hybrid Actors,” pp. 862, 867.

This is still about our digital modern warfare, not focused or about the next variant of a biological weapon.

Asymmetric and hybrid warfare is not new and it has been operating on Main Street USA for a decade or more, yet most people are apathetic or complacent as they walk down the sidewalk starring at their latest digital communicator.

Who knows more about you as a person? The people on Madison Avenue or on Amphitheatre Parkway. These forces working together to better understand you as a behavioral thinking machine and to Win, are beyond your typical John Q. Citizens comprehension.

Now take this Asymmetric or Hybrid foundation and apply this to our next 24 hours and to the next 12 months. What you read and what you hear and what you see on an LCD screen, is the modern digital battlefield. In the USA. In Ukraine. In China. In North Korea. In Iran. In the UK.

The corporate and business battlefield has now spread across our other 16+ Critical Infrastructures, such as energy pipelines and beyond to hospitals, schools and universities, water and electric utilities, local government municipalities and vital federal government agencies.

The attack surface has now spread to our homes, apartments and where ever you may connect your little LCD screen to the Internet, for your Work From Home (WFH) strategy.

You see, that little black or white or blue communications box sitting there on your desk, credenza or table in the storage room, with little blinking lights is actually part of this digital global battlefield. You as a citizen soldier now need to do your part.

The Router/modem/Cable box sitting inside your own domicile or business, is the entry point for our modern global adversaries. It is your Duty of Care and your mission to defend your Family, your Community and your Country.

You can realize your own vulnerabilities in order to respond. To increase your resiliency. To upgrade or update your own digital hardware and software, in order to Deter, Detect and Defend, all those we care for in our daily lives.

The so called “Critical Infrastructure” is in your hand, in your business, in your home, and you and your own family are part of this hybrid warfare. Wake up!

From Madison Avenue, New York City NY to Llewellyn Avenue, Fort Meade MD, to the deepest, darkest parts of the World Wide Internet, a continuous Digital Global War is being waged 86,400 seconds per day…

Saturday, October 09, 2021

Mission Resilience: Our Digital Trust in 2050...

“If we are to prevail as a civil, global society, designing and achieving digital trust is now a necessity. We must find the courage to move beyond what seems to work today but actually is crumbling. We must move beyond merely shoring up our defenses with stronger, more robust spending. Instead, we must begin anew, replacing what is with what needs to be—a robust, dynamic, interconnected, digital space through which we can communicate and live as a global society. In doing so, we can improve our confidence in our decisions and the decisions of our leaders.”—Jeffrey Ritter-Achieving Digital Trust

Our organizations across Corporate and Major Metropolitan areas of the world are at the epicenter of our trust.

It is Cybersecurity Awareness month in the United States in October again and the number of Ransomware incidents is rising on a daily basis. Cryptocurrency is being used on the “Dark Web” to complete transactions that go well beyond the purchase of digital keys, to unlock stolen and encrypted data from those digitally frozen municipalities, hospitals, and other vital corporate Critical Infrastructure entities.

The CIA finally has a “China Mission Center” dedicated to the continuous analysis and proactive geopolitical actions to protect the invisible, yet ever more present digital influence operations across the Internet.

How will the challenges of our "Digital Domains" change from their foundations of open communications and collaboration to major systems disruption and loss of trust?

How might we proceed community-by-community both online and face-to-face, to raise the level of integrity and confidence in our accelerating digital age?

Our future for a trusted and civil global economy will depend upon our respective confidence in the digital world we all have created this past two decades.

The algorithms and the software code have largely been written by humans, who are still so capable of making errors.

The opportunity for us all, is to increase the quality of our digital world and to better manage the forensic initiatives that will still lie ahead of us.

In the Board Room, the GSOC Center and every desktop where humans type on keyboards in a protected building, located off Chain Bridge Road near Georgetown Pike, the challenges will continue to rise.

Writing the descriptive words for an all-source PDB or coding in the syntax and semantic language known as Python, our technology tools remain open to exploit.

Our digital trust relies on the people with decades of hands on experience and the people who will design the software to run our growing infrastructure of tomorrow.

Mission continuity and operational resilience is the next digital wave of innovation required to build trust across our cities and across continents. 

Critical Infrastructure Protection must remain pervasive, engineered into all that we design and deliver with Confidence, Integrity and Assurance

Saturday, December 19, 2020

ITC: Managing Risk for Security Governance...

In our converging world of both Information and Physical Security, there are resilient risk elements for the effective management of Information Technology & Communications (ITC).

Think of it as “Security Governance”.

Security Governance is a discipline, that all of us need to revisit and rededicate ourselves towards. The policies and codes we stand by to protect our critical assets, should not be compromised for any reasons. More importantly, security governance frameworks, must make sure that the management of a business or government entity be held accountable for their respective performance.

The stakeholders must be able to intervene in the operations of management, when these security ethics or policies are violated. Security Governance is the way that corporations or governments are directed and controlled. A significant element that is now being mandated by the Board of Directors, is the role of “Continuous Risk Management” in Security Governance.

ITC Security Governance, like Corporate Governance requires the oversight of key individuals on the Board of Directors. In the public sector, the board of directors may come from a coalition of people from the Executive, Judicial or Legislative branches.

The fundamental responsibility of management, whether in government or the corporate enterprise, is to continuously protect the assets of the organization or entity. Risk and the enterprise are inseparable. Therefore, you need a robust management system approach to continuous Security Governance, not just an annual audit.

If a corporation is to continue to survive and prosper, it must take security risks. A nation is no different. However, when the management systems do not have the correct controls in place to continuously monitor and audit enterprise security risk management, then we are exposing precious assets to the threat actors that seek to undermine, damage or destroy our livelihood.

An organization’s top management must Identify, Assess, Decide, Implement, Audit and Supervise their strategic risks. There shall be a strategic policy at the board level to focus on managing risk for security governance.

The security governance policy should mirror the deeply felt emotions of the organization or nation, to its shareholders and citizens. It should be a positive and trusting culture, capable of making certain that strategic adverse risks are identified, removed, minimized, controlled or transferred.

An enterprise is subject to a category of risk that can’t be foreseen with any degree of certainty. These risks are based upon events that “Might Happen”, but haven’t been considered by the organization. Stakeholders can’t be expected to be told about these risks because there is not enough information to validate or invalidate them.

However, what the stakeholders can demand, is a management system for continuous Security Governance that is comprehensive, proactive and relevant. The management system includes organizational structure, policies, planning activities, responsibilities, practices, procedures, processes, and growing resources.

It is this Security Governance management system that which we all should be concerned and which we seek from our executives, board members and oversight committees to provide. There should be a top management strategic policy to focus on managing risk for continuous security governance.

This risk management system should establish the foundation for ensuring that all strategic risks are identified and effectively managed. The policy should reflect the characteristics of the organization, enterprise or entity; it’s location, assets and purpose. The policy should:

1. Include a framework for governance and objectives
2. Take into account the legal, regulatory and contractual obligations
3. Establish the context for maintenance of the management system
4. Establish the criteria against what risk will be evaluated and risk assessment will   be defined

A process should be established for risk assessment that takes into consideration:

  • Impact, should the risk event be realized
  • Exposure to the risk on a spectrum from rare to continuous
  • Probability based upon the current state of management controls in place

The strategic security risks that the organization encounters will be dynamic. The management system is the mechanism by which the executives identify and assess these risks and the strategy for dealing with them. It is this system which we are concerned about and which we seek to provide in order to achieve our Security Governance.

ITC Security Governance best practices are still rapidly growing and taps the thinking of various standards organizations including OECD, BSI, NIST, ISSA, BSA, ITAA, ASIS and dozens of other bodies of influence and knowledge. However, no matter what best practices an organization attempts to standardize on, beware of the attitudes of the employees and stakeholders.

Unless these stakeholders fully acknowledge what and why, they are being asked to do things, rather than just following the rulebook, the system will fail.

The organization that embraces change and introduces a Security Governance framework that not only manages the foreseen human risks, but also the unforeseen, will have a greater chance of survival.

The role of culture in the risk for security governance, is paramount for several reasons:

1. Any changes in risk management may require changes in the culture
2. The current culture is a dramatic influence on current and future security initiatives

Internal controls can provide reasonable assurance that an organization will meet its intended goals. At the same time, it is the people (Human Factors) who will fail the company in material errors, losses, fraud and breaches of laws and regulations.

This is why the risks the organization is facing are constantly changing and therefore why a management system for continuous security governance is necessary. The management system is there to provide resiliency to the risks it encounters and to control risk accordingly rather than eliminate it forever.

The board of directors will soon realize that managing risk for ITC Security Governance, is just as important to the success and compliance of the organization as Section 404 of Sarbanes-Oxley.

In fact, without effective ITC Security Governance in place, all of the rules won’t matter and the stakeholders will again be asking themselves after a major technology failure or privacy data or intellectual property breach; how could this happen to us?

Saturday, December 05, 2020

Asymmetric Warfare: Computer Jihad...

A person does not have to spend years analyzing and witnessing the phenomenon of the Internet to understand why the pornography industry has flourished.
 
Like other social and religious facets of our global culture, connected by hyper links, web sites and chat rooms, human beings are able to quickly and efficiently discover what they are looking for. Good and bad.
 
If the Internet is just a mirror of society itself, then of course it will have both the positive and humanitarian aspects along with the negative, criminal and evil elements.

Learning new skills and spreading new ideas via the Internet is nothing new. However, one could predict that the acceleration of threats to our youth, families and nations states has been influenced by the proliferation of Apples, Dells, and Androids across the globe.
 
Whether it's in the kitchen, the library, university dorm room or the corner cyber cafe the ubiquitous ICT 5G access now available has increased our operational risks at home, at work and to our economic well being.

When subjects such as this are discussed at length in the Board Room, NOC or War Room the arguments always come back to the same thing. How many people have been killed as a result of cyber-warfare?
 
Justification of spending dollars and allocating resources is in many cases a factor of the risk management exercise, likelihood vs. impact.
 
After all, the Internet seems to be self-healing and resilient to any long term outage. But those who are well versed in 4th Generation Warfare (4GW) sitting around the table know, that computerized jihad is a tactic of a far more encompassing strategy:

"Reflecting Sun Tzu’s philosophy, many recent Chinese writings have focused on asymmetric warfare as a means of defeating a militarily superior enemy. Asymmetric warfare uses political, economic, informational and military power. Military power is the least emphasized."

The silent war being waged each second of each minute of every hour every day, over every week and month of the year is taking place on a vast digital battlefield. Who will be the victor?

Sunday, January 05, 2020

ORM: Pervasive Risk Across Disciplines...

What is the origin of the "Operational Risk Management" (ORM) discipline? Was it derived from the work within the financial services industry from the Basel II initiatives?

The definitions and the actual work towards creating standards of conduct and rule-based design has been evolving for the past few decades.

Operational Risk and the approach to risk that is not otherwise considered to be market or credit risk, is one mind set. The other mind set considers the hazards associated with the threat to our valuable assets.

Either point of view depends on the environment that you operate in and the risks associated with that environment.

To give a quick example, here are a few views into Operational Risk in the United States:

"It didn’t take long—the first attack on a U.S. government website hit on Saturday, a day after the killing of Qassem Suleimani in Baghdad. The fact there was an attack is not a surprise—speculation has been rife. And the style of the attack is consistent with the nature of the primary cyber threat we now face. Hackers claiming to be linked to Iran targeted a low-level domain—the website of the Federal Depository Library Program—defacing its home page, echoing Teheran’s threats of vengeance alongside imagery of President Trump, Ayatollah Khamenei and the Iranian flag" Forbes

"Boeing will still burn more than $1 billion a month even after halting 737 Max production, according to J.P. Morgan.  Boeing’s decision to stop suspend production of the troubled aircraft was made in light of months of cash-draining groundings worldwide, but the company’s internal overhead and labor expenses will remain and will increase cash burn, analyst Seth Seifman wrote to clients."  CNBC

These examples encompass a U.S. government agency and a private sector U.S.-based global aerospace company.  Both are operational risk scenarios that could contribute to losses that will also impact the reputation of the entity involved.

That aspect alone, could be the major factor in why Operational Risk Management is such a growing discipline in our 2020 global landscape.

Some of the earliest origins of the Operational Risk concerns come from the military. The U.S. Navy is one of the branches who has embraced it fully:
  • Purpose. To establish policy, guidelines, procedures, and responsibilities per reference (a), standardize the operational risk management (ORM) process across the Navy, and establish the ORM training continuum.
  • Scope. This instruction applies to all Navy activities, commands, personnel, and contractors under the direct supervision of government personnel.
  • Discussion. Risk is inherent in all tasks, training, missions, operations, and in personal activities no matter how routine. The most common cause of task degradation or mission failure is human error, specifically the inability to consistently manage risk. ORM reduces or offsets risks by systematically identifying hazards and assessing and controlling the associated risks allowing decisions to be made that weigh risks against mission or task benefits. As professionals, Navy personnel are responsible for managing risk in all tasks while leaders at all levels are responsible for ensuring proper procedures are in place and that appropriate resources are available for their personnel to perform assigned tasks. The Navy vision is to develop an environment in which every officer, enlisted, or civilian person is trained and motivated to personally manage risk in everything they do.
If only our major business entities would would fully encompass the following steps with all employees and processes then more lives would be saved, corporate assets would be protected and the enterprise would be ever more resilient:

(1) Identify the hazards;

(2) Assess the hazards;

(3) Make risk decisions;

(4) Implement controls; and

(5) Supervise.
Yet the losses and the potential for loss continues across the organizations who are well equipped to make Operational Risk Management a part of every person and operating divisions daily mind set:

The places change, the numbers change, but the choice of weapon remains the same. In the United States, people who want to kill a lot of other people most often do it with guns.
Public mass shootings account for a tiny fraction of the country’s gun deaths, but they are uniquely terrifying because they occur without warning in the most mundane places. Most of the victims are chosen not for what they have done but simply for where they happen to be.

There is no universally accepted definition of a public mass shooting, and this piece defines it narrowly. It looks at the 172 shootings in which four or more people were killed by a lone shooter (two shooters in a few cases). It does not include shootings tied to robberies that went awry, and it does not include domestic shootings that took place exclusively in private homes. A broader definition would yield much higher numbers.

Whether it is on the deck of an aircraft carrier or within any organizations business facility, operational risk is pervasive. It is up to you and your organization to begin to make a difference...

Saturday, June 22, 2019

Cyber Risk: Human Factors vs. Automation...

Operational Risk Management (ORM) is a growing multi-faceted mosaic comprised of people, processes, systems and external events. The risks to the enterprise are increasing at a dynamic speed and trajectory that requires the use of automated tools.

This is where risk to the enterprise may actually expand as executives and operational management rely on software to provide information assurance. The design and architecture of software needs a human-based fail-safe. It requires a human interface that allows and simultaneously requires human intervention. Has too much automation contributed to our increased levels of vulnerability?

Fortunately, the software designs have allowed for these opportunities and for a human-factor to ask "What if" questions. Those questions that may arise after an automated alert from the system tells us that something is outside the baseline parameters set for the system, the sensor or the alarm.

Now we go back to Operational Risk and the nature of thinking from a security and safety perspective. What is the continued reliance on automated systems doing to the human capital who have been charged with the over all "Standard of Care" for the enterprise?

We believe that they may have lost the ability to ask the right questions, at the right moment and with the correct contextual understanding.

What is the truth? Is it true? What evidence do we have that this is true? How do you know that the evidence is not spoiled or compromised? If we know the truth, then what do we do next? Is the software really telling us the truth?

The security and the safety of the enterprise is counting on you. And more importantly, the enterprise is asking you to question the software. The "rule-sets" that you have chosen as a result of the programmers and architects decisions can no longer be trusted.

Is our system learning? In what capacity is the system learning in context with the human interaction for judgement, intuition and ethical emotions? Are you with us? The next generation of "Cyber Security" Innovators are now at the edge of significant new breakthroughs and solutions.

"Active Defense" has been and is a controversial topic du jour, yet the next few years will be a new age of understanding, cultural bifurcations and significant global collaboration.

Our entire platform of digital trust is at stake and the conversation has finally made its way to the nation state policy levels.

Operational Risk Management (ORM) will remain a key factor in decision points for the enterprise, the consumer and the operators of critical infrastructure across the globe.

Lets work on keeping the human factor in the loop as automation continues to give us a false sense of security and safety...

Saturday, April 13, 2019

Digital Trust: Transparency in a World of Cyber War...

"British police arrested Wikileaks founder Julian Assange on Thursday. He had been hiding in the Ecuadorian Embassy in London since 2012 and was arrested after the Ecuadorian government invited the Metropolitan Police Service into the embassy to remove him. Assange was initially arrested for jumping bail in 2012, but the Metropolitan Police Service subsequently announced that he had been "further arrested on behalf of the United States authorities."

After Assange's arrest, the US Justice Department unsealed its indictment against him. The indictment focuses on Assange's role in helping Chelsea Manning steal classified information from the US military."
  Wikileaks — Julian Assange arrested, charged with conspiracy to hack US computers Assange had been holed up in the Ecuadorian Embassy in London since 2012.  Timothy B. Lee - 4/11/2019, 7:05 AM


Someday in the future, there will be a documentary on the timeline and journey of Julian Assange, beyond what has already been produced about his life and his behavior.

It is going to be years before the U.K. legal system finishes the process it has demonstrated in the past with people and issues such as this one.

Yet transparency remains an important topic here.  Whether you are arguing for greater disclosure on what is going on inside government or within the R&D practices of a Global Fortune 1000 public company, transparent communications to the public and shareholders is vital.

The justice systems will finally have the opportunity to produce the information, that will allow every world citizen, to read about the true facts in the Assange case.

Meanwhile, the use of sophisticated exploit tools by nation states and rogue non-state actors continues to disrupt our international e-commerce.  Many variations of these tools are now in the wild as a result of the actions of Wikileaks and are being utilized in nefarious ways.  Here is just one example:

Canadian Police Raid ‘Orcus RAT’ Author
"Canadian police last week raided the residence of a Toronto software developer behind “Orcus RAT,” a product that’s been marketed on underground forums and used in countless malware attacks since its creation in 2015. Its author maintains Orcus is a legitimate Remote Administration Tool that is merely being abused, but security experts say it includes multiple features more typically seen in malware known as a Remote Access Trojan." Krebs on Security

This latest phase of legal justice is about a digital world that exists underground and unknown to the naive "John Q. Citizen" on the street.  Brian Krebs own transition from journalism at the Washington Post to creating his own blog, is only part of this transparency topic.  The Dark Web and all that is comprised of it, is still growing exponentially.

Remember that only about 4-5% of the world wide web (WWW) is what you are seeing in the searchable "Google" Internet.  The other 95% of the Deep and Dark web, is indeed another virtual world.

The international entrepreneur today who has that new great idea, product or service will be operating on the Internet and the World Wide Web.  No different from years before the Internet when you set up your office/business on Mainstreet, in the skyscraper or in the Mall, yet now your reach is instantaneously global.  Your inventory display, banking, accounting, order entry, distribution and delivery is done with software and global communications networks.

Today and since the dawn of the Internet, every new online entrepreneur has a digital spectrum of Operational Risks that must be addressed as part of your daily business.  Those digital trust factors have created new dimensions of risk and resilience strategies, to counter the size and scope of the expanding cyber crime and terrorism enterprises.

So what?

There are several analogies that could be used here to illustrate the issues associated with selling cyber weapons online or the theft and distribution of those digital weapons in our modern society.  Yet the truth is, international commerce is here to stay and it will require new and more rapid action by business and governments.

Simultaneously, the future of our digital trust and the lack of manpower and enforcement resources is spelled out daily in the public press.  How many times have we heard, that there is a shortage of Cyber Security and Risk professionals in the commercial and government workforce?  There is a reason for this.

Transparency of reporting is vital for the public, so they can make more informed decisions.

Balancing the nightly television news with politics, business earnings reports, weather events and the reality of our expanding "Cyber World War," will soon become the new normal...

Sunday, April 07, 2019

Preemption: An Operational Risk Perspective...

"The global regulation of cybersecurity is one of the most contentious topics on the international legal plane. States, the actors primarily responsible for arranging most other international regulatory regimes, have so far been incapable of reaching a consensus on how to govern international cyberspace. For example, in 2017, the United Nations Group of Governmental Experts, arguably the most promising effort to create international norms for cyberspace, collapsed. In this vacuum, private tech companies are seizing the opportunity to create norms and rules for cyber operations, essentially creating a privatized version of cybersecurity law."  LawfareBlog Ido Ikilovaty

Preemption - A Knife That Cuts Both Ways by Alan M. Dershowitz should be considered for the professional Operational Risk Managers reference library:

Decisions to act preemptively generally require a complex and dynamic assessment of multiple factors. These factors include at least the following:
  1. The nature of the harm feared.
  2. The likelihood that the harm will occur in the absence of preemption.
  3. The source of the harm--deliberate conduct or natural occurrence?
  4. The possibility that the contemplated preemption will fail.
  5. The costs of a successful preemption.
  6. The cost of a failed preemption.
  7. The nature and quality of the information on which these decisions are based.
  8. The ratio of successful preemptions to unsuccessful ones.
  9. The legality, morality, and potential political consequences of the preemptive steps.
  10. The incentivizing of others to act preemptively.
  11. The revocability or irrevocability of the harms caused by the feared event.
  12. The revocability or irrevocability of the harms caused by contemplated preemption.
  13. Many other factors, including the inevitability of unanticipated outcomes (the law of unintended consequences).
Regardless of the agreement or bias of the reader, this book makes you think upside down and sideways about decisions you have made, and will make.

While Mr. Dershowitz takes time to make his own opinions known, his mastery of building the foundation for transformation is unequaled on such a topic; controlling dangerous and destructive human behavior and how to confront terrorism, crime and warfare.

During the course of a single day in the life of the Operational Risk Manager there are dozens if not hundreds of preemptive or preventive decisions to be made.

Private Sector vs. Public Sector is not so much the issue here. Whether you are the Chief Operational Risk Officer at a major banking institution or the Commander in the local Emergency Operations Center, you both have the same dilemma.

A decision must be made quickly and you must be able to live with the implications of either decision.

Sunday, March 24, 2019

Operational Threat Matrix: The Mission Ready Many...

"Five years after the release of the Framework for Improving Critical Infrastructure Cybersecurity, organizations across all sectors of the economy are creatively deploying this voluntary approach to better management of cybersecurity-related risks. The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) issued what is now widely known simply as the “NIST Cybersecurity Framework” on February 12, 2014."

Measuring an incident first requires defining a taxonomy on what an "incident is" and what an "incident is not". In other words, how can you measure something that has not been sufficiently defined in your organization. How do you know when an incident has occurred?

Our corporate assets are under attack by a continuous barrage of new laws, new employees, new competitors and new exploits.

Business survival in the next decade will require a more effective and robust risk strategy to deter, detect and defend against a myriad of new threats to the organization.

Modern day attackers include hackers, spies, terrorists, corporate raiders, professional criminals, vandals and voyeurs. Simply said, these attackers use tools to exploit vulnerabilities. They create an action on a target that produces an unauthorized result. They do this to obtain their objective.

The Mission

The organization shall develop, implement, maintain and continually improve a documented operational risk management system:
  • Identify a method of risk assessment that is suited for the organizations business assets to be protected, regulatory requirements and corporate governance guidelines. 
  • Identify the assets and the owners of these assets. Identify the threats to those assets.
  • Identify the vulnerabilities that might be exploited by the threats.
  • Identify the impacts that losses of confidentiality, integrity and availability may have on the assets.
Assess the risks. Identify and evaluate options for the treatment of risks. Select control objectives and controls for treatment of risks. Implement and operate the system. Monitor and review the system. Maintain and improve the system.

The Take Away

While you were in the Board of Directors meeting, your Operational Risk Profile changed. When you were asleep last night it changed again. The people, processes, systems and external events are interacting to create a new and dynamic threat matrix for your organization.

Who is responsible for Operational Risk Management in your business? Everyone is. You see, if everyone in the organization was able to understand and perform the mission flawlessly, then the business could stay in constant control of how much incidents are costing the enterprise.

Only a guarded few understand the mission of operational risk management in your company. Only a guarded few can do it flawlessly.

If you want to protect your corporate assets better than you do today, then turn those guarded few into the mission ready many.

Saturday, January 12, 2019

4th Generation Warfare: Insider Risk...

Flashback to 2010.  Over 8 years ago, this author discussed the situational awareness and the implications of the "Stuxnet" malware that was being investigated by international authorities. In January 2011, the New York Times published a more detailed set of facts and a hypothesis that the sophisticated "worm code" was tested in Israel:

William J. Broad, John Markoff and David E. Sanger.
The Dimona complex in the Negev desert is famous as the heavily guarded heart of Israel’s never-acknowledged nuclear arms program, where neat rows of factories make atomic fuel for the arsenal.

Over the past two years, according to intelligence and military experts familiar with its operations, Dimona has taken on a new, equally secret role — as a critical testing ground in a joint American and Israeli effort to undermine Iran’s efforts to make a bomb of its own.

Behind Dimona’s barbed wire, the experts say, Israel has spun nuclear centrifuges virtually identical to Iran’s at Natanz, where Iranian scientists are struggling to enrich uranium. They say Dimona tested the effectiveness of the Stuxnet computer worm, a destructive program that appears to have wiped out roughly a fifth of Iran’s nuclear centrifuges and helped delay, though not destroy, Tehran’s ability to make its first nuclear arms.
4th Generation Warfare (4GW) and the implications for global critical infrastructure organizations is obvious. The Operational Risks associated with targeted infiltration of systems that control machines, manufacturing processes and software that manages transportation, has now changed the baseline for where to begin mitigating this asymmetric threat.

Executives then and to this day, realize the continuous requirement for improved focus on the "Insider Threat" to their systems operations. Why?
 
This particular worm was initially delivered by a USB Thumb Drive according to various reports. This means that someone would have to have been inside the facility targeted for the attack, to actually introduce the malware to the actual system controller. A person within the perimeter of the organization with this single device, could set the chain reaction in motion.

Whether you are a major manufacturer or an electric utility doesn't matter. The person you trust to access systems inside the organization, is the basis for mitigating this type of attack. Most important is the scrutiny associated with the extended supply chain of semi-trusted contractors or others known to the organization. 
 
All of the back ground checks and other methods for determining someone's character will not be the major deterrent to a worm introduced internally to an Intranet, with the use of a USB thumb drive.

So what is the answer to address this threat?
 
A TSA-style check, scan and pat down at the entrance to every commercial enterprise that has computers inside with open USB ports? This is very unlikely in the near term for most facilities.

What about disablement of the technology itself, that turns off the ports themselves on each system inside the organization perimeter? This solution is more likely to deter many opportunities for this type of USB style attack to occur, yet still doesn't remove all of the risks against another possible vector to the network through a CD drive as an example.
 
Regardless of the method or the controls you employ to mitigate this risk, it will not eliminate the entire threat from your organization. Even the use of a "Digital Sandbox", Endpoint security measures or other methods to disable ports on systems will entirely lock down your organization.

There is only the ability to create a more resilient and durable environment to survive a significant business disruption. The mind set shift to durability and the latency to recover, now becomes the new strategy for these kinds of risks.
 
Using a strategy for "Business Resilience" is one that requires significant resources, a Global Security Operations Center (GSOC) and a committed management team. The ability to survive is the first part of the process and how soon you return to full operational capability is the metric. How long does it take to bounce back to normal from a major crisis, in your organization?

The ability to manage emerging risks, anticipate the interactions between different types of risk, and bounce back from disruption or crisis, will be a competitive differentiator for companies and countries alike in the 21st century.

Homeland security is often seen as a protective, even defensive, posture. But Maginot lines are inherently flawed. Fences and firewalls can always be breached. Rather, the national focus should be on risk management and resilience, not security and protection.
 
Resilience—the capability to anticipate risk, limit impact and bounce back rapidly—is the ultimate objective of both economic security and corporate competitiveness...

Sunday, November 11, 2018

Veterans Day: The Spectrum of Those Who Serve...

On this Sunday in the United States of America, it is Veterans Day November 11. As you look around your neighborhood, how many others are flying the colors of our American Flag?

Flag of the United States of America
Veterans Day (originally known as Armistice Day) is an official United States public holiday, observed annually on November 11, that honors military veterans; that is, persons who served in the United States Armed Forces.
As the son of a U.S. Marine, the thought of what our country has endured and how people like him loved all that the Flag stands for, brings tears.  This morning, we are the only house on our street with the "Stars and Stripes" on display flying in the wind.  Why?

It is hard to understand and yet most people on the block have never read "Team of Teams" either.   There are millions in the U.S. Armed Forces who have lived their whole career, experiencing when people working with a sense of mission can be so remarkable.

Yet you don't have to be holding your Form DD-214 to understand, that the American people on your block, in your town or across your state, need a clear mission to come together.  A purposeful mission helps most people get out of bed in the morning.  To go to school.  To show up at work.  Are you a leader of people or a leader of a true Team?

Sure, you can use the sports analogies to get the point across.  The Vince Lombardi stories are famous for getting people to understand team work and winning the game.  Yet ask any Veteran, and they will probably say that a game that lasts years, is so much different.  Lombardi coached at West Point at one point in his career, and this had a lasting impact on him.

The new rules of engagement for a complex world, is the name of the game today.  The rapidly advancing tools of conflict are changing from superior geographic positions on the hill with a Combat Controller (CCT), to the stealth of an exploit code software payload.

So what?

Start thinking about the spectrum of digital members of our military who serve our country each day.  Some are behind a keyboard, or working on the front lines of software maintenance to keep the data centers operating at peak efficiency.  Think about all of the professionals in the shadows, who are collecting and analyzing intelligence for us all to better anticipate, prepare and to be more resilient.

The asymmetric conflicts here are going on 24 hours a day, 7 days a week.  Right in your own city or business.  Everyone has their specialty, and each finds there way into the job they are destined to perform.  And they are truly a "Team of Teams"...

Thank you for all that you have done for our country.  Thank you for what you are doing today for us here and in the rest of the world...

Saturday, October 06, 2018

National Security: Cyber Infrastructure Risk...

Is your organization a threat to National Security? That depends on whether you own, install, and maintain Critical Infrastructure. When you hear that term, "Critical Infrastructure" what comes instantly to mind? A bridge, a road or some other shovel ready project?

Yes, the hard leap for many to get their head around is that your cell phone, TV and Internet connection are vital "Critical Infrastructure" and if you are a Verizon, AT&T, Sprint or large cable company in the United States; National Security is a top of mind issue.

Is it possible that our country is at risk because of the same "Risk Management" paradigm that has plagued the Financial Services industry? A lack of resources and focus to deter, detect, defend and document risks to our critical infrastructure, could turn into a systemic and interdependent threat to our national security.

How can you make the case for a 2008 era economic meltdown in the financial services sector, to be similar to the potential failure of the Communications, Information Technology, Water or Energy sector?

It's easy. Look at human behavior and to the motivators of greed, selfishness and just plain blindness to a "risk bubble" just waiting to burst. Who will be the next Bear Stearns, in the Communications Sector?

The truth is, that some Fortune 500 companies marketing departments, may have a larger budget than the information systems, internal audit department and the security department combined. When the nuts and bolts, concrete and plumbing associated with electronic commerce, banking, and just plain mobile communications come to a slow crawl or halt in it's tracks, the government will have to do the same thing all over again.

Bail out or restore the industry and the companies, who are the lifeblood of our Critical Infrastructure.

Our National Security is at stake and the owners and operators are still waiting for the right incentives to invest in robust maintenance and security programs, instead of just more marketing. After all, market share is what shareholders ask about, along with how many new subscribers you won or lost last quarter.

How often do we hear the question at the shareholders meeting, that asks about the amount of downtime, failed systems or customers without service, as a result of a "Glitch" or fried circuit board?

So how does the electronic critical infrastructure really impact National Security?  The Department of Homeland Security (DHS) has the lead.  The mission is to lead the national effort to secure Critical Infrastructure from all hazards by managing risk and enhancing resilience through collaboration with the critical infrastructure community.

"The Office of Infrastructure Protection (IP) leads and coordinates national programs and policies on critical infrastructure security and resilience and has established strong partnerships across government and the private sector. The office conducts and facilitates vulnerability and consequence assessments to help critical infrastructure owners and operators and State, local, tribal, and territorial partners understand and address risks to critical infrastructure. IP provides information on emerging threats and hazards so that appropriate actions can be taken. The office also offers tools and training to partners to help them manage the risks to their assets, systems, and networks."

A culture of risk management is slowly moving it's way into the Board Room conversations and the CEO may be on notice, if the "Tone at the Top" is not focused on Enterprise Business Resilience. However, that "Tone at the Top" needs to go beyond the shareholder value conversation, to the National Security topic.

One only has to look further in a few places on the "Net," to better understand what the offensive cyberwarfare conversation is all about, as the Advanced Persistent Threat (APT) has evolved in the past few years.

Once you understand that many cyber incidents with our U.S. Critical Infrastructure are just a test, then you will realize that U.S. shovel ready projects need a new public service announcement (PSA), with a shock value of texting while driving.

The risk of a specific kind of behavior on the road or the critical infrastructure complacency within the corporate enterprise, can have the same results. We have already nationalized the likes of AIG, Freddie Mac and Fannie Mae after the last financial crisis.

Perhaps it time to do the same for Amazon, Verizon, AT&T, Sprint and others, who are vital assets in our National Security and have them report directly to the Pentagon...think about it.

Sunday, May 06, 2018

IO Convergence: Cyber Warfare Unified Taxonomy...

Information Operations (IO) is an Operational Risk Management priority in both the public and private sector these days. Is it lawful for a U.S. company and U.S. citizens to train and perform cyber warfare activities on behalf of a foreign country?

Flashback to 2012, The Washington Post reports:

By Ellen Nakashima, Published: November 22
"In the spring of 2010, a sheik in the government of Qatar began talks with the U.S. consulting company Booz Allen Hamilton about developing a plan to build a cyber-operations center. He feared Iran’s growing ability to attack its regional foes in cyberspace and wanted Qatar to have the means to respond.

Several months later, officials from Booz Allen and partner firms met at the company’s sprawling Tysons Corner campus to review the proposed plan. They were scheduled to take it to Doha, the capital of the wealthy Persian Gulf state.

That was when J. Michael McConnell, then a Senior Vice-President at Booz Allen and former Director of National Intelligence in the George W. Bush administration, learned that Qatar wanted U.S. personnel at the keyboards of its proposed cyber-center, potentially to carry out attacks on regional adversaries.

“Are we talking about actually conducting these operations?” McConnell asked, according to several people at the meeting. When someone said that was the idea, McConnell uttered two words: “Hold it.”
A common taxonomy was developed years ago for the cyber terms of the computer and network incident domain. Now we need to make sure we all understand what we mean when we say Information Operations policy as it pertains to the digital world.

As an example, in the context of the digital attacker we have Sandia Labs Taxonomy:
  • Hacker
  • Spies
  • Terrorists
  • Corporate Raiders
  • Professional Criminals
  • Vandals
  • Voyeurs
Each is unique and has its own domain or category. We are sure that the same could be used for the context of attackers in the non-digital world, possibly with the exception of Hacker. However, the definition of corporate raider in the off line domains may not be synonymous with the on line domain of cyber incidents.

If we look at the categories that make up the entire "Incident" that Sandia Labs has utilized, we see the following:
  • Attackers
  • Tool
  • Vulnerability
  • Action
  • Target
  • Unauthorized Results
  • Objectives
Without combining the context under each category, we lose the impact of what we are trying to make contextual with regard to an "Incident". We need to make sure that the anti-terrorism taxonomies of the off line and on line domains can be utilized together to describe the attributes of an "Incident". We need to break down the sub-categories as well. For instance, in the Sandia Labs Taxonomy for the Objectives category we have:
  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
When we move to the off line domain and are doing risk mitigation and preparedness exercises for anti-terrorism we utilize another set of words to describe and evaluate infrastructure threats and hazards.  Here are Five factors:
  • Existence addresses the question of who is hostile to the assets of concern?
  • Capability addresses the question of what weapons have been used in carrying out past attacks?
  • History addresses the question of what has the potential threat element (aggressor) done in the past and how many times?
  • Intention addresses the question of what does the potential threat element hope to achieve?
  • Targeting addresses the question of do we know if an aggressor is performing surveillance on our assets?
Two years later, the Washington Post reports:

By Ellen Nakashima, Published: November 14
President Obama has signed a secret directive that effectively enables the military to act more aggressively to thwart cyber­attacks on the nation’s web of government and private computer networks.
Presidential Policy Directive 20 establishes a broad and strict set of standards to guide the operations of federal agencies in confronting threats in cyberspace, according to several U.S. officials who have seen the classified document and are not authorized to speak on the record. The president signed it in mid-October. The new directive is the most extensive White House effort to date to wrestle with what constitutes an “offensive” and a “defensive” action in the rapidly evolving world of cyberwar and cyberterrorism, where an attack can be launched in milliseconds by unknown assailants utilizing a circuitous route. For the first time, the directive explicitly makes a distinction between network defense and cyber-operations to guide officials charged with making often-rapid decisions when confronted with threats.
The policy also lays out a process to vet any operations outside government and defense networks and ensure that U.S. citizens’ and foreign allies’ data and privacy are protected and international laws of war are followed.

“What it does, really for the first time, is it explicitly talks about how we will use cyber-operations,” a senior administration official said. “Network defense is what you’re doing inside your own networks. . . . Cyber-operations is stuff outside that space, and recognizing that you could be doing that for what might be called defensive purposes.”
We believe that as our cultures, countries, agencies and professionals work together on Information Operations (IO) and online counter-terrorism initiatives, we are going to have to develop a solid taxonomy. It will provide the foundation for our clear and accurate risk management methodologies and incident management systems, being developed by relevant organizations in mutual collaboration.

Once we have accomplished this fundamental understanding, then true Critical Infrastructure Protection (CIP) cooperation and coordination will occur.

Sunday, February 18, 2018

Information Warfare: The Future of Trusted Words...

Trust is on the minds of almost every American as they read the Washington Post these days.  Reading a publication that utilizes a set of standards for journalism, may address part of your "Trust Decision" to depend on this source for your information.

Reading this Operational Risk blog, you understand that the words and opinions are not under the same editorial guidelines and grammar rule sets as the authors and journalists at the Washington Post.  The sentences and thoughts are being written freely however, by someone who you may know of, yet how do you really validate that the words were actually written by the assumed author?

At an early age in school, as a young student, your teacher at some point assigns that work called an essay, a short piece of writing that tells a person's thoughts or opinions about a subject.  Regardless of the topic assigned by the teacher, when the work is turned in to the teacher, they are assuming it was written by that particular student.  Unless they have doubts.

The trust you put into the author of words written in an essay for a class, or an article in the established news papers, has for decades relied on the integrity of institutions and the validation of persons true identities. Yet as the typewriter replaced hand written documents, so too did the act of using another person's words or ideas without giving credit to that actual person : the act of plagiarizing something.

When you read this Washington Post article, you assume that the words are actually from the journalist:
Indictment shows how Russians conspired to disrupt U.S. politics — but not how to stop them next time

By Craig Timberg February 16 The Washington Post
"Efforts to reconstruct the Russian conspiracy to sway 2016’s presidential election benefited from the digital trails left behind whenever people travel, make payments or communicate using common technology such as Facebook or Gmail. Such breadcrumbs provided plentiful evidence for Friday’s indictment by the special counsel of the Internet Research Agency and 13 Russian associates.

But even as the disinformation campaign from two years ago finally came into focus, it was far from clear how to prevent future bids to distort American politics.

U.S. intelligence agencies warned this week that the federal government remains ill equipped to combat Russian disinformation even as crucial midterm congressional elections loom this fall. And technology companies, while cooperating with federal investigators, acknowledge that they still struggle to detect and thwart foreign propaganda without impinging on the free-speech rights of Americans."
Now in the age of computing, word processing and the Internet, the integrity of written words by a person is in question?  The origin and authenticity of the actually words that are written by a human on paper, a typewriter or computer such as these, is now in question?

The utilization of various methods for "Information Warfare" is actually well known:
"Information Warfare has three main issues surrounding it compared to traditional warfare: 

The risk for the party or nation initiating the cyberattack is substantially lower than the risk for a party or nation initiating a traditional attack. This makes it easier for governments, as well as potential terrorist or criminal organizations, to make these attacks more frequently than they could with traditional war.


Information communication technologies (ICT) are so immersed in the modern world that a very wide range of technologies are at risk of a cyberattack. Specifically, civilian technologies can be targeted for cyberattacks and attacks can even potentially be launched through civilian computers or websites. As such, it is harder to enforce control of civilian infrastructures than a physical space. Attempting to do so would also raise many ethical concerns about the right to privacy, making defending against such attacks even tougher.


The mass-integration of ICT into our system of war makes it much harder to assess accountability for situations that may arise when using robotic and/or cyber attacks. For robotic weapons and automated systems, it’s becoming increasingly hard to determine who is responsible for any particular event that happens. This issue is exacerbated in the case of cyberattacks, as sometimes it is virtually impossible to trace who initiated the attack in the first place.[5]"
These words are being written by a human being.  His name is Peter L. Higgins.  Or are they?  The art and science of the truth has been evolving for hundreds of years.  What will we invent next, to validate our identities, provide assurance that the words written are actually human, and not of an Artificial Intelligence (AI)?

Whether the words you read are being written by a human-based "troll factory" in St. Petersburg or by a specialized Artificial Intelligence is not the point of this essay.  Then what is the point?

You have to make judgements as a human being about who to trust.  What to trust.  How to trust.  Why to trust.  This is a foundation of our human evolution.  Trust takes time.  TrustDecisions and the decision to trust someone or something, is actually a factor of science, mathematics and history.

Reading, writing and a decision to trust, is an Operational Risk.  True or False?

Sunday, August 13, 2017

Capitol Hill: Zeros and Ones of Resilient Vigilance...

Walking past the Cannon House Office Building this week, on the way to a meeting at the U.S. Capitol, created some reflective thoughts.  As our Capitol came into full view, you have to wonder how many congressman have made that walk since the early 1900's?  How many representatives from across America contemplated whether their work was making a real difference, for their constituents and for our country.

The future of America is bright and our level of resilience as a nation has endured, yet we must remain vigilant.  There are thousands of people who get up every day and travel into the District of Columbia and surrounding suburbs, because they are Patriots and they care so very much about our growing Republic.  You have to see it in their eyes, to realize how much that is true.

Entering the South door on the House side, we proceeded to our meeting room, H-137.  As our small cadre sat down for a light meal, the focus quickly turned to our purpose for gathering.

National Security and Intelligence was the high level reason, yet the dialogue quickly drifted into what was an 80/20.  It seems that the "Cyber" related conversations these days are taking up about 80% of the nuances to Critical Infrastructure Protection (CIP) and for good reason.  The fact is, more than 85% of our nations Critical Infrastructure are out of the direct control and ownership of the government.

Private Sector companies and other non-government entities control 16+ vital sectors of the nations infrastructure assets.   They are the owners and operators of Energy companies, Telecommunications, Financial, Water, Transportation and our Information Technology Sectors and including the Defense Industrial Base to name a few.

What was not mentioned in the room over our 90 minutes, were some of the most sensitive issues confronting those on the front lines of the private sector critical infrastructure protection industry.  "Fancy Bear," "Eternal Blue," "Vault7" were on some peoples mind.  These references mean nothing to many of the "John Q. Citizens" in America who are working using smart phones and lap top computers at home, on the job or in our free lance economy.  Until these electronic tools are no longer functioning correctly.

So what?

Eternal Blue, as the exploit is code-named, is one of scores of advanced NSA attacks that have been released over the past year by a mysterious group calling itself the Shadow Brokers. It was published in April in the group's most damaging release to date. Its ability to spread from computer to computer without any user action was the engine that allowed the WCry ransomware worm, which appropriated the leaked exploit, to shut down computers worldwide in May. Eternal Blue also played a role in the spread of NotPetya, a follow-on worm that caused major disruptions in June.

The owners and operators of Critical Infrastructure across the globe, are now operating on high alert.  The executives and policy-makers in discussion behind closed doors, around the U.S. Capitol understand the magnitude of the current problem-set.  Utilization of these exploit tools will continue by rogue individuals, Crime, Inc., and cyber terrorists that are no different than other examples in the physical world associated with IED's or weapons of mass destruction.

The Private Sector will need to step up its resilience and readiness game in the next few years, if not months.  The capabilities and Return-on Investment (ROI) for non-state actors to play in a whole new league, are becoming ever more apparent.

To continue our resilient vigilance across the nation, we will require a whole spectrum of new capabilities and some, that have worked for years...

Saturday, January 21, 2017

Asymmetric Advantage: Dawn Across Arlington...

One only has to stand behind the "Tomb of the Unknowns" and gaze across the national mall past the Washington Monument to begin to feel the magnitude of the challenges ahead.  As the wind swirls around the grave markers and the sound of sirens and jets are distantly present, you can feel an emotional wave of inspiration.

Today in Washington, D.C., the dawn of a new government administration is waking up and the rest of the world is waiting.  How will the asymmetric problems we face be solved faster?  Why does the decision to use "Solution X" make sense over "Solution Y", to address our nations adaptive Operational Risks?

Why would a U.S. citizen feel inspired this day and from this vantage point in Arlington?  It is because the future will bring new conflicts that are different than years past.  It will bring new opportunities for us to excel.  Every decade that wars occur, there are far less warfighters actually put into harms way.  The number of casualties slows.  Why?

The reason is that the kinetic types of wars are using new inventions and technologies to save lives.  Whether it is MWRAP's or tourniquets built into uniforms, or sophisticated "Geospatial Intelligence", the goal is to keep our warfighters safe and alive.

Now also in parallel, the conflicts are being waged 24 x 7 x 365 in another growing operational domain, where the IO Analyst is navigating electronic networks and complex lines of software code.  Information Operations are full of new challenges and substantial learning curves in order to gain the advantage.

Welcome to the #Virtual Caliphate:
Decades of border disputes, violent conflict, and shifting refugee populations have left millions of Muslims without a clear national identity. ISIL’s virtual caliphate offers them citizenship free from terrestrial constraints, which can be accessed from anywhere in the world.
How the United States responds to this threat of a growing set of virtually-inspired terrorists, who carry out their physical acts in the homeland, remains a substantial problem-set.  What else is in store for our Homeland?

"The U.S. is considered a high-priority intelligence target by many foreign intelligence entities. While traditionally the threat has been to our political, military, and diplomatic interests at home and abroad, the loss of sensitive economic information and technology is a growing threat to our national security. In recent years, economic espionage conducted by foreign intelligence entities, corrupt insiders, and corporate competitors has exploited vulnerabilities in cyberspace that may weaken our economic advantage. Cyber espionage has not replaced traditional espionage as a way to steal secrets, but the ability to focus technology on lesser protected information is a significant and growing threat." DNI.gov Domestic Approach to National Intelligence

The rules will be changing soon.  The tools will be too powerful and the threats too great, for the military to have their hands tied or their legal authorities limited.  The next generation of domestic cyber warfighters will now go into action, side-by-side from CyberCom, Homeland Security, FBI, CIA and a new coalition of advanced private sector contractors.  They will work across the Homeland from SCIFs in every state, with a new enhanced mission and a new unified command.

How will this save lives and give all of our warfighters what they need?

As the billion dollar budgets within the Pentagon shift their focus to platforms such as DIUx, or IARPA, innovative answers will be more apparent.  The growing solutions pipeline will become the basis for rapid deployment to our Operators.  The new Corps of men and women raising their hands from classrooms across the Homeland, will become exponential...they will serve in new roles and in new ways.

The future is bright and the changing of the guard at the "Tomb of the Unknowns", will soon see fewer ceremonies to bury our heroes or even hang another star on a wall in Langley...