Miel, LLC Cybersecurity Architecture, Design, and Engineering Cybersecurity architecture is a requirement in today's environment. If you don't address cybersecurity in your organization, there will be problems. Miel, LLC offers architecting and embedded systems hacking services provide proactive cybersecurity services to improve your defenses, so you aren't reactive. Miel, LLC Cybersecurity Architecture, Design, and Engineering 810-701-5511 charles.parker@mielcybersecurity.net
Showing posts with label cybersecurity staffing. Show all posts
Showing posts with label cybersecurity staffing. Show all posts
Saturday, September 22, 2018
Vehicle Cybersecurity Positions are Difficult to Fill
Vehicle Cybersecurity Professionals-Still a Difficult Position to Fill
Charles Parker, II
>_
In the metro-Detroit area, the primary industry and revenue force is the auto industry. This is clearly due to the number and concentration of the vehicle manufacturer headquarters, assembly plants, and admin offices. As these vehicles are designed and engineered, they require cybersecurity testing. This ensures as much as possible the vehicles are safe and secure for being successfully attacks. Cybersecurity for the presently connected vehicles and future autonomous vehicles is paramount. Without this in place and the vehicles being active, directly tested, any vehicle on the road would not be safe itself or from other vehicles which could be hijacked.
To accomplish this vast task, the vehicle manufacturers require qualified people to complete the testing. This does not appear to be a significant issue. There are jobs to fill in a technology area creating a demand for years, and there should be people to fill the open positions. Unfortunately, this is not remotely the case. This is occurring presently in the field for many reasons. The primary reason for this is the available persons with this skill are limited. The persons with the skill and experience to test the cybersecurity of embedded, equipment is rather narrow. Of this narrow field, the applicants need to be vetted not only for their technological prowess but also for their ethics, as there are bad apples present who would not morally do the right thing 100% of the time. Based on this need/demand is far outpacing the demand. This is further exacerbated due to this need being across several industries, not only auto manufacturers.
As an option, the manufacturer may reach out to third parties to complete a portion of the testing. The manufacturer may also incorporate a bug bounty program into their process. Programs like this would pay the cybersecurity persons when they would find a bug in their product. By using a program as such there are a great number of persons reviewing the product and are paid for their time if a bug is found. GM and FCA’s Bug Bounty programs are well known.
There are a limited number of universities and colleges attempting to train persons for this vast need. There are also contests in which high school and college students may apply to be in to learn the basics. This will assist with increasing the pipeline for the cybersecurity talent.
Labels:
AD,
auto,
autonomous vehicle,
bug bounty,
cybersecurity,
cybersecurity staffing,
embedded systems,
vehicle,
vehicle cybersecurity
Saturday, August 25, 2018
AI to Supplement InfoSec
There are currently a minor number of topics creating the press in the computer industry than machine learning (ML) & artificial intelligence (AI). AI has been in process for well over a decade, yet recently has been much more publicized in the press. Most persons may be familiar with ML and AI from the movies (Tron, Her, iRobot, Blade Runner, 2001: A Space Odyssey, and many others) or commercial ventures with security incident and event management (SIEM) applications (Dawson, 2017). These applications have also been implemented with recreational users with the Go game, IBM Watson, and other applications.
InfoSec
InfoSec has many functions, too numerous to detail. These include, but are not limited to, log analysis, spam filter applications, network IDS/IPS, fraud detection, botnet detection, user authentication and validation, and in general monitoring activities (Rossi, 2016). With the vast number of responsibilities, time is of the essence. This is only further exasperated by the mass number of attacks that are present and that will continue to grow.
These attacks have been increasing over time as a function of the increasing attack surface of increasing data and system complexity coupled with the potential revenue to be generated. The amount of data generated from daily operations increases making it difficult to analyze all of the data (Siwicki 2017). This grows, in comparison, from a small to medium, or medium to large sized business. The increased amount of available threats (Stevens, 2018) have subsequently increased the network breaches in the mid-decade (Li, 2015) and recently. Although this is abstract, the reality of the situation incorporates the actual cost to the organization. In 2013, the estimated global cost of cybercrime was $113B (Sanders, 2015). As the number of attacks has grown along with the mass volume of data being targeted daily, the cost has increased rather significantly.
These attacks also have increased in depth. These have moved from the shallow, low hanging fruit to the more in-depth, complex attacks. With the number of new InfoSec tools engineered specifically to compromise systems and these being designed with a GUI for complete ease of use.
The attacks have also increased in criticality. The targets are involved with more criticality. The targets are involved with more critical operations for the organization. The attacks are becoming more concerned with these high-value targets, providing greater attention when compromised.
Current Workforce
In InfoSec, as a general indicator, there have been and continue to be a significant shortage of qualified staff. In cybersecurity, this is much worse. There presently is and will continue to be a severe shortage of cybersecurity professionals throughout the country (Li, 2015). The issue isn’t merely with the number of staff members not being sufficient, but also with experience. The expertise of the staff members also is lacking (Cowley, & Greitzer, 2016).
One area this is specifically problematic is within the automotive cybersecurity field. With the new modules and operations, along with the new push for autonomous drive (AD) vehicles, there is a much larger need for cybersecurity professionals. This demand for the automotive cybersecurity professionals will continue to outpace the supply (Uchill, 2017).
Staffing Limitations
The InfoSec staffing shortage is well-known and published in various mediums, and a challenge (ISACA, 2018). This shortage is not localized, but a global issue (Ollmann, 2016). Within this industry, 59% of cyber- and InfoSec positions are not filled (Zorz, 2018). The same study also noted 54% of respondents say filling an open position generally requires at least three months. This time frame experience is not acceptable.
To further this, 59% of the enterprises responded the organization experienced open security positions (Teitler, 2018). This is as of a limited time span. Over time, this has also been the case. ESG recently conducted their annual global survey focussing on the state of IT. From this survey, the number of organizations claiming a shortage of cybersecurity skills has increased since at least 2014 (Oltsik, 2018). This study indicated the obvious of filling these cybersecurity positions was more difficult in 2018 versus 2017 (Rio, 2018).
Expected Labor Force Shortage
As noted, the past and present shortage of qualified, experienced cybersecurity staff has been growing noticeably (Morgan, 2017). This is the reality for the industry. Looking forward, the shortage of staff is expected to be approximately 1.8M by 2020-2022 (Condon, 2018; Stolte, 2018; MacDonald, 2018; Gil, 2018; Kawamoto, 2017).
AI to the Rescue
The past, present, and future labor shortage is well-known. One discipline which may be of assistance is AI (Rio, 2018). While this is not a panacea and won’t be able to solve all the presented issues (Oliver, 2018), there is a clear benefit to the implementation (Scroxton, 2018). In general, AI will be able to increase human productivity (Reese, 2018). As the beneficial processes are experienced by the organization, the cybersecurity teams will achieve a greater level of understanding (Ismail, 2017). This greater depth of understanding will provide for a faster, better, and less costly cybersecurity program.
This understanding will provide for the upgraded modules to better identify threats, assess the risk, and apply the remediation protocol. Identifying threats has proven to be difficult due to the attack surface and data continuing to grow. There is a limited amount of resources being applied to the network, endpoint protection, applications, cloud services, mobile devices, and other points and processes. Assessing the risk involves correlating the external threat data with the business criticality. This activity along is well-suited for ML and AI applications, along with the added functionality AI provides for. This may be used to assess the security gaps and possible points of breach or compromise.
Trust
For the full implementation of AI into InfoSec, there has to be trust with the system. The humans require a full understanding and appreciation of the system, knowing the risk of an oversight or negligent decision is as close to a null as possible, with the awareness that there will be a rather insignificant level of potential error in the application. No human deiced without an error on some level over decades of work. This confidence in the system is vital (Stilgherrian, 2018).
For the trust to be in place, there need to be two pertinent factors in place. These are operational and data security (Hengstler, Enkel, & Duelii, 2016). The operational safety facet involves the technology itself being reviewed and approved per the appropriate level of governance. The data itself also has to be secure, and not modified. With these fully engaged, the issue of a lack of trust would be marginalized.
Replacing Humans
Another issue noted was the AI system would replace most of the humans, leading to mass unemployment. Users may have the visions from Hollywood of the machine taking over step by step. This will not be the case. The AI systems will work to supplement the workflows, not replace humans, freeing time which may be applied elsewhere on other projects (Rio, 2018).
There are many types of duties and work which AI is not able to do so (Skilton, 2017). Humans have the ability to generalize, reason through issues, and intuition, which would not be able to be fully replaced by code or a machine (Towers-Clark, 2018). From this, clearly, the cybersecurity role is and won’t be targeted (Korolov, 2016).
Regarding job functions, there will be fewer jobs at risk of being affected by automation than previously thought (Vincent, 2018). There will not be the need for humans lessening as the new paradigm shift occurs. This potentially will affect, to the detriment of, low skilled jobs. As an example, there have been in use for over a year AD bus lines on the campus of the University of Michigan-Ann Arbor. These naturally have a limited scope of use, however, have been in place, are actively used, and are trusted by the students and University.
This will be used more to review threats originating from outside of the entity (Needle, 2017), for data protection (Help Net Security, 2018), to detect anomalies in traffic, and to create a more difficult environment for attackers to compromise (Osborne, 2018).
There is a level of faulty reasoning as the AI system will not be usurping the human’s authority and autonomy. The industry and civilization will still need human developers (Merritt, 2018). There is no question as to this use case. Humans will be needed for advancing to tools we have in place presently. Each business is unique in its parameters and application requirements (Allen, Filar, & Seymour, 2017). The humans will be needed to fulfil the varied requests and requirements in a creative manner. While creativity is one of the functions of AI in the long-term, the humans will still need to be directly involved in these endeavours.
The humans will be required to manage the contingencies involved with business operations, incident response, and many other areas. While computing this is a controlled process, the human aspect will be needed as creativity is a required function. The decision process is multi-faceted and still will require a human’s interpretation of events, and rank in the decision matrix.
ML and AI will assist with InfoSec as an effective assistant (Siwicki, 2017). The users are too numerous to enumerate, however, the generalized uses are notable. These include, however, are not limited to:
a. Analyzing the mass amount of data generated daily from operations, AD vehicles, and the myriad of other sources (Graham, 2018),
b. Improving accuracy, which would subsequently increase the human's confidence (Ashford, 2017),
c. Automating initial and secondary false positive review (Morgan, 2017), effectually freeing up a large block of time for the InfoSec team,
d. Improving predictive analytics to possibly identify pre-compromised targets, reviewing the requirements for the InfoSec team to remediate issues,
e. Force multiplying; as this will supplement the InfoSec team’s efficiency, allowing each member of the team to achieve more in different areas, and
f. Training, personalized for each staff member to assist them with their position, goals, and careers.
Supplement and Augment
AI will be a benefit to commercial organizations, consumers, and others involved. In the subject context, the benefits are numerous and too expansive to list for the InfoSec field. This, as the implementation evolves and increases in usage, will become more evident and show not only its promise, however also its potential to make the InfoSec worker more efficient, and multiply their efforts.
This shift in the application will not be quick. This is a needed, as with this level of a technology shift, the steps need to be sure, planned, and executed within a governance model.
References
Allen, C., Filar, B., & Seymour, R. (2017, October 19). Harnessing the power of conversational interfaces in security. Retrieved from https://www.oreilly.com/ideas/harnessing-the-power-of-conversational-interfaces-in-security
Ashford, W. (2017, October 18). McAfee forges ahead with analytics, deep learning and AI. Retrieved from http://www.computerweekly.com/news/450428465/McAfee-forges-ahead-with-analytics-deep-learning-and-AI
Condon, J. (2018, May 8). Survey suggests younger generations, including females, may fill the cybersecurity talent gap. Retrieved from https://www.protectwise.com/post/survey-suggests-younger-generations-including-females-may-fill-the-cybersecurity-talent-gap/
Cowley, J.A., & Greitzer, F.L. (2015). Organizational impacts to cybersecurity expertise development and maintenance. Proceedings of the Human Factors and Ergonomics Society Annual Meeting, 59(1), 1187-1191. doi:10.1177/1541931215591185
Dawson, J. (2017, October 1). Training machine learning for cyberthreats. Retrieved from https://www.afcea.org/content/training-machine-learning-cyberthreats
Gil, L. (2018, March 22). The debate is over: Artificial intelligence is the future for cybersecurity. Retrieved from https://www.scmagazine.com/the-debate-is-ver-artificail-intelligence-is-the-future-for-cybersecurity/article/749603/
Graham, K. (2018, April 13). Managing cybersecurity in the age of artificial intelligence. Retrieved from http://www.digitaljournal.com/tech-and-science/technology/managing-cybersecurity-in-the-age-of-artificial-intelligence/article/519790
Help Net Security. (2018, April 4). Would automation lead to improved cybersecurity? Retrieved from https://www.helpnetsecurity.com/2018/04/04/automation-cybersecurity/
Hengstler, M., Enkel, E., & Duelli, S. (2016). Applied artificial intelligence and trust-The case of autonomous vehicles and medical assistance devices. Technological Forecasting & Social Change, 105(2016), 105-120. doi:http://dx.doi.org/10.1016/j.techforce.2015.12.014
ISACA. (2018). State of cybersecurity 2018: Part I: Workforce development. Retrieved from http://ww.isaca.org/Knowledge-Center/Research/Documents/cyber/state-of-cybersecurity-2018-part_1_res_eng_0418.pad?regnum=441968
Ismail, N. (2017, April 19). The role of AI in cyber security. Retrieved from http://www.information-age.com/role-ai-cyber-security-123465795/
Kawamoto, D. (2017, June 7). Cybersecurity faces 1.8 million workers shortfall by 2022. Retrieved form https://www.darkreading.com/careers-and-people/cybersecurity-faces-18-million-worker-shortfall-by-dd-id/1329084
Korolov, M. (2016, December 2). AI is coming, and will take some jobs, but no need to worry. Retrieved from https://www.csoonline.com/article/3146137/it-careers/ai-is-coming-and-will-some-jobs-but-no-need-to-worry.html
Li, C. (2015). Penetration testing curriculum development in practice. Journal of Information Technology: Innovation in Practice, 14, 85-99. doi:https://doi.org/10.28945/2189
MacDonald, R. (2018, June 18). Working through the cybersecurity skills gap. Retrieved from http://www.helpnetsecurity.com/2018/06/18/working-cybersecurity-skills-gap/
Merritt, T. (2018, May 3). Top 5: Tips for using AI in your business. Retrieved from https://www.techrepublic.com/article/top-5-tips-for-using-ai-in-your-buisness/
Morgan, S. (2017, June 6). Cybersecurity labor crunch to hit 3.5 million unfilled jobs by 2021. Retrieved from https://www.csoonline.com/article/3200029/security/cybersecurity-labor-crunch-tohit-35-million-unfilled-jobs-by-2021.html
Oliver, J. (2018, March 29). Introduction to machine learning (ML) for cybersecurity. Retrieved from http://www.cyberdefensemagazine.com/introduction-to-machine-learning-ml-for-cybersecurity/
Olmann, G. (2016, December 28). How artificial intelligence will solve the security skills shortage. Retrieved from https://www.darkreading.com/operations/how-artificial-intelligence-will-solve-the-security-skills-shortage/a/d-id/1327756
Oltsik, J. (2018, January 11). Research suggests cybersecurity skills shortage is getting worse. Retrieved from https://www.cso.online/article/3247708/security-research-suggests-cybersecurity-skills-shortage-is-getting-worse.html
Osborne, C. (2018, March 21). Artificial intelligence key to do “more with less” in securing enterprise cloud services. Retrieved from http://www.zdnet.com/article/artificial-intelligence-key-to-do-more-with-less-in-securing-enterprise-cloud-services/
Rio, A. (2018, June 21). Will AI help close the skills gap? Retrieved from http://www.clomedia.com/2018/06/21/will-ai-help-close-the-skills-gap/
Rossi, B. (2016, June 20). Bring the noise: How AI can improve cybersecurity. Retrieved from http://www.information-age.com/technology/security/123461b38/bring-the-noise-how-ai-can-improve-cyber-security
Sanders, A. (2015, October 29). Will AI be smart enough to protect us from online threats? Retrieved from https://techcrunch.com/2015/10/29/will-ai-be-smart-enough-toprotect-us-from-online-threats/
Scroxton, A. (2016, January 24). AI is moving towards acceptance in cybersecurity, says Check Point. Retrieved from https://www.computerweekly.com/news/252433705/AI-is-moving-towards-acceptance-in-cyber-security-says-Check-Point
Siwicki, B. 92017, June 29). Artificial intelligence is giving healthcare cybersecurity programs a boost. Retrieved from http://www.healthcareitnews.com/news/artificial-intelligence-giving-healthcare-cybersecurity-programs-boost
Skilton, M. (2017, February 13). Impact of artificial intelligence on cyber security. Retrieved from https://www.huffingtonpost.com/professor-mark-skilton/impact-of-artificial-inte_b_14702160.html
Stevens, G. (2018). How to approach AI-enhanced cybersecurity. Retrieved from https://www.scmagazine.com/how-to-approach-ai-enhanced-cybersecurity/article/761867/
Stilgherrian. (2018, August 1). AI can deliver ‘faster better cheaper’ cybersecurity. Retrieved from https://www.zdnet.com/article/ai-can-deliver-faster-better-chearper-cybersecurity/
Stolte, R. (2018, June 21). Filling the cybersecurity skills gap with artificial intelligence. Retrieved from http://journal.ahima.org/2018/06/21/filling-the-cybersecurity-skills-gap-with-artificial-intelligence/
Teitler, K. (2018, May 1). ISACA workforce development report highlights need for more & more qualified security employees. Retrieved from https://www.misti.com/infosec-insider/isaca-workforce-development-report-highlights-need-for-more-qualified-security-employees
Towers-Clark, c. (2018, April 21). AI will not take our jobs, but it will fundamentally change them. Retrieved from https://www.gigabitmagazine.com/ai/ai-will-not-take-our-jobs-it-will-fundamentally-change-them
Uchill, J. (2017, July 30). Demand for automotive cybersecurity pros outpaces supply. Retrieved from http://thehill.com/policy/cybersecurity/344539-demand-of-automative-cybersecurity-pros-outpaces-supply
Vincent, J. (2018, April 3). AI and robots will destroy fewer jobs than previously feared, says new OECD report. Retrieved from https://www.theverge.com/2018/4/3/17192002/ai-job-loss-predictions-forecasts-automation-oecd-report
Zorz, Z. (2018, April 17). Tech-skilled cybersecurity pros in high demand and short supply. Retrieved from https://www.helpnetsecurity.com/2018/04/17/cybersecurity-pros-high-demand/
Labels:
AI,
artificial intelligence,
cybersecurity staffing,
information security,
InfoSec,
labor shortage
Thursday, July 5, 2018
InfoSec Shortage Continues
There is a mass shortage of InfoSec personnel. The shortage has been well published through many different outlets, academic articles, magazines, and blogs alike. There was a study conducted by Intel Security with the Center for Strategic and International Studies (CSIS). There were 775 IT decision makers in eight countries in the public and private entities.82% of the respondents noted a shortage of cybersecurity skills. Symantec in a recent study estimated the number of open position to 500K to 1M, increasing to 1.5M by 2020 . The global shortage is expected to increase to 1.8M by 2022. InfoSec job postings have also increased by 74%.
Banks have also experienced difficulties in this area in finding cybersecurity personnel to hire. With the finance industry, there may be more of a focus on complying with lending and credit guidelines, in comparison to auditing the cybersecurity processes.
The demand for the people is outstripping the supply. One factor driving the need is the number of black hat attackers. This number while vague continues to grow. The attackers have operationalized the methods to the point where this is a business, following a business model. As the amount of data continues to grow, this gives the attacker yet more targets to focus their attention on. The network and connected devices in place presently produce 277x greater amount of data than people do. The data increasing, along with more devices and IoT, provides an abundance of crown jewels or places to attack. It is simply just difficult for the staff in place to complete the necessary work to ensure the network, data, enterprise, and embedded systems are safe. This is a bit of circular reasoning. There is a massive amount of data, devices, and networks to protect, which continue to increase. This gives the attackers more targets. The already stretch InfoSec teams are not able to adequately review the InfoSec, which gives the attackers more of an opportunity to successfully attack targets.
Diversity appears to be an issue in this industry (Perez, 2016). Diversity is important in that a diverse group brings new ideas, work ethics, processes, experiences, which all lead to better ideas and implementations to better secure the enterprise and specific embedded devices. In 2015, women held 25% of computing roles. In the InfoSec workforce, women only comprise 11%. This ratio is lacking and indicative of the issues that continue.
Methods to Remediate the Issue
The problem is well-known and increasing at an alarming rate, unfortunately for the industry. To again repeat the issue and its underlying driving points would be a disservice for the industry and non-productive. There are many actions to take in order to begin to alleviate the issue. These steps are not a panacea, however, the endeavor will take time and effort.
One action item to implement is to begin cybersecurity education and training earlier. This may begin even in junior high school, if not earlier for the students. The introduction and subsequent materials would need to be age and maturity specific, however the earlier the better. The students are exposed to electronics and learn from these devices in the elementary school systems. This exposure to InfoSec and computer systems may be enough at this age to spark the interest and a life-long career. This allows for a greater level of accessibility in the school systems.
The colleges, universities, and corporations should be present and active at recruiting events. Recruiting events are differentiated from career fairs in that the recruiting events are held in conjunction with other like events. For instance, the organization could use a cybersecurity event as a recruiting grounds with the organization's table. The table would be set up with SWAG to hand out. This gives the business representative the opportunity to meet people and nonchalantly speak with them regarding their background to understand if it may be a good fit and to gauge the person's interest. This allows the entity to look at the person's skills, and not just if they have a degree. These recruiting events, updated for the new workforce, certainly have the potential to assist with the shortages.
The entities experiencing the labor issues in this IT and InfoSec areas may also conduct specialized events to draw the attention and attendance. Overall, these entities may provide the facilities, and operate practice sessions and camps. These may encompass various topics. Banks have been a bit creative and have held coding events.
The workforce in the present cycle looks at different attributes for the workplace. This is a natural progression as the demographics have changed. To reach this stratum of potential, qualified employees, the entities should openly publicize these facets. The new workforce coming up into the ranks is seeking flexible hours. This, when implemented, allow the staff to accomplish other tasks and interact with others.
Within the subject field, which is presently understaffed, the level fo females in the field are drastically low. Although the ratio is terrible, with this subfield there are also targeted actions to take. To assist with this, more females should attend hack-a-thons. With these, the attendees would be able to mentor and teach each other along with being able to assess the knowledge base and skill level.
THere are InfoSec conventions throughout the year, through the US and remainder across the globe. Of these, there is a subset directly related to increasing the number of women in InfoSec. One of these in prior years was TiaraCon, which was focused on increasing the number of females in cybersecurity. Related to this are the camps. Females should attend these to learn from others, as they are mentored if needed. BYU has hosted these in the past.
Looking Forward
The lack of qualified personnel leading to the present and future increasing shortage of persons, there are a number of action items to work on to assist with the issue. The organizations have to be creative in their efforts. The upcoming workforce needs to be attracted to the position, not just a job.
Labels:
cybersecurity staffing,
InfoSec,
security staffing,
staffing
Subscribe to:
Posts (Atom)