Strength – Ability – Discipline

New Evidence Suggests SolarWinds’ Codebase Was Hacked to Inject Backdoor

As a Cyber Security professional for over 25 years I’ve seen a lot over the years. One thing that stands out is the hack of CCLeaner in 2017. Which appears now to have some similarities to the SolarWinds compromise. The result of the CCLeaner compromise has had lasting effects. Anyone who participates in CyberPatriot knows, CCLeaner is one of the first things to be removed from an image as it’s assumed to be compromised.

With this new evidence, will SolarWinds become the next security tool that’s considered more of a risk to run it than to not?

Read more


Reflections on Risk Management Framework Security Controls Assessment

I’m sitting here in the airport after finishing a 1 week Risk Management Framework (RMF) Security Controls Assessment (SCA) and reflecting on the week. This week the team and I reviewed nearly 30 hosts and over 3000 individual controls. I remember throughout the week there were many times thinking “this is pretty basic stuff, why aren’t they (the client) following the security guidance?”. It underscores the need to get more Information Technology (IT) professionals trained in cyber security. That’s why Cyber Centurion is proud to sponsor Civil Air Patrol NC-162 Squadron's first CyberPatriot Team.

CyberPatriot is the National Youth Cyber Education Program created by the Air Force Association to inspire K-12 students toward careers in cybersecurity or other science, technology, engineering, and mathematics (STEM) disciplines critical to our nation’s future. At the core of the program is the National Youth Cyber Defense Competition, the nation’s largest cyber defense competition that puts high school and middle school students in charge of securing virtual networks.

The cadets on our team, who range in age from 13-16, began practice in April with basic computer skills and cyber hygiene concepts. Over the past several months, they’ve progressed through the basic materials absorbing the information at an incredible pace. They are excited to begin their first scored round and put their knowledge to the test.

Throughout the week, there were many times that I thought: “Gee, I wish ‘R’ was here. He could do this in his sleep” or “Wow ‘E’ would have known what to make this setting”. I highlight these examples because the cadets in this program have at least 7 years before they’re in the workforce. Regardless of what they do in their careers, many will stay close to technology and one thing I am sure of; with these cadets, I know security will be baked into whatever they do!

The competition round begins October 25-27, 2019. If you are so inclined check out the Cyber Patriot website (www.uscyberpatriot.org) or your local Civil Air Patrol (https://www.gocivilairpatrol.com/). Both are great organizations for engaging our youth in Cyber Security and Aerospace Engineering.


Workforce Challenges in Cyber Security

At RSA this year there was a big focus on diversity in the workforce. There were many sessions about how to increase women and minorities in the workforce. Depending on which website you read, the shortage of Cyber professionals is somewhere between 500K and 3.5 Million. That means that Cyber security is one of the few professions today with 0% unemployment. According to investopia.com, “In 2016, there were 1 million job openings, with two openings for every available job candidate.” By 2021 we will exceed that 1.5 million.

As of 2017, there were 780,000 cyber professionals in the U.S. with about 350,000 openings. The sessions talked about increasing the female workforce from 10% to 20% or more, advocating moving from 78,000 women to 156,000 still leaving nearly 200K in unfilled positions. We need to be looking at building the “pipeline” of candidates.

In my mind, one of our biggest challenges is that our career field is 100% in the abstract. Cyber security professionals work in the abstract. How do you attract the upcoming generation to such a boring career? The other part is education; people think that only the smartest can do cyber security “stuff”. Yes, you have to be smart, but we all started at the bottom and worked our way up.

If you’re reading this, chances are you’re a cyber security professional. I encourage everyone who sees this to get involved at the level closest to the children you’re comfortable with. If you’ve got children, get involved. The Girl Scouts have a cyber badge now; your school likely has a CyberPatriot Program (if they don’t, start one).

If you’re a manager of people within your organization, get to know your staff. See what they’re interested in. If they have the drive to move into the cyber security profession, encourage it. One of the many success stories I’ve seen is someone who moved from Administrative Assistant to Information Security Engineer.

The workforce problem isn’t just a one-dimensional problem; as cyber professionals, we need to take the lead and start working with youth to build the pipeline. If your kids are grown, work with the local HS, College, Civil Air Patrol, JROTC, Girl Scouts, Boy Scouts etc.


Lessons from the RSA Conference

I’m sitting here between sessions at the 2019 RSA conference looking at all the marketing materials and listening to the vendors touting their “Market Leading” cyber security tool and I’m wondering if they can all be leaders. The problem many people run into is that they must start with being a good follower and maintain those habits as they move through leadership.

The basic ideal is that followership is fundamental to organizational success. Followership is difficult; it requires self-discipline and the willingness to learn from others. Here are some characteristics sought in effective followers:

  • Positive Attitude
  • Effective Team Member
  • Loyalty to the Leader and Organization
  • Volunteerism at Work
  • Willingness to Accept Assignments
  • Actively Offering Suggestions for Improvement
  • Respectfulness in All Aspects of Work
  • Supporting of Group Decisions

To be successful leaders and to make our leaders successful, we need to set the example and encourage these behaviors in the people who work for us.


Connecting to Public WiFi Safely

We’ve all been tempted to connect to public WiFi connections; whether it’s because of reaching your data plan limit or poor cellular signal, it’s a dangerous decision. Public WiFi is easy for the public to access, meaning administrators rarely put significant security in place to protect users.

Precautions and recommendations when connecting to public WiFi:

  1. Don’t do online shopping, bank, or sensitive activities.
  2. Use 2-factor authentication when logging into sites.
  3. Use HTTPS for websites to encrypt the data.
  4. Turn off file sharing and automatic connections.
  5. Use a VPN service to encrypt your data.

Implementing these steps will ensure that you’re more protected than others on the same network.


The Adventure Race Experience

I competed in a 24-hour Adventure Race designed to test physical, mental, and emotional fortitude. During the race, I learned a lot about myself, my teammate, and leadership.

Key Lessons Learned:

  1. Helping others is always the right thing to do.
  2. Negativity brings everyone down.
  3. Sometimes you have to carry the team.
  4. Sometimes you have to let others take charge.
  5. If conditions change, so should you.
  6. Learn from your mistakes so they aren’t repeated.
  7. Never, never, never give up!

In the end, we didn’t finish the race, which was a disappointment. It was an unbelievable challenge, and I’m glad I tried, because in the end, I learned a lot along the way.


Launch of Cyber Centurion Corporation

I’ve developed a passion for helping clients identify and remediate cyber and systems challenges over the past 22 years. Now, I’m pleased to announce that Cyber Centurion Corporation is open for business! We provide security-focused cyber solutions to ensure mission success.

For more information visit cybercenturioncorp.com or email info@cybercenturioncorp.com.


Managing Risk in Mergers and Acquisitions

In my professional career, I’ve seen several mergers and acquisitions and have learned that it’s the most dangerous time for both organizations’ information and data.

Practical solutions for managing internal threats during M&A activities:

  1. Publish the high-level corporate structure as soon as possible.
  2. Establish a process for validating requests.
  3. Never use unvalidated email or phone numbers.
  4. Train your employees to question all visitors.

Keep vigilant, communicate across the organization and establish rules to validate requests to avoid common pitfalls of data protection during a merger or acquisition.