Solar Wind Up?
Cognitive dissonance, dental hygiene, and why you should seek out your friendly security gal (or guy).
Persuading people to take dental hygiene seriously is harder than you think. We know we should floss, but we’re lazy and frankly we can’t be arsed with the whole faff that goes with it. We also don’t really want to think about dentists chairs, or drills, or having fillings. It’s called cognitive dissonance. We deal with it by sticking a finger in each ear, shutting our eyes and humming loudly. I know my gums bleed when I brush my teeth but you can sod off with your gingivitis treatment, I’m having another one of those After Eights.
Replace dental hygiene with cyber security and you’ve got the attitude of many of us in the tech world. Maybe you’re a software architect trying to persuade developers to adopt a new service, maybe you’re a data scientist frustrated by how best to get access to all the data you need. You know security is important but the last thing you need is someone getting in the way of what is really important.
Every so often another big data breach or branded vulnerability hits the mainstream press. This week it is the Russians hacking SolarWinds, compromising the code behind their network monitoring product Orion and thereby getting access to some pretty heavyweight government & business organisations – most eye-catchingly the blue chip security firm Fireeye. But we’ve been here before right, I mean Heartbleed & Wannacry came & went didn’t they? (*). The world kept spinning. SolarWinds? Solar Wind Up more like. La la la la la. Anyway back to that project I need to get through without the security jobsworths getting in my way…
I finally went to see my dentist this week, about the same time the SolarWinds story was being picked up by the BBC. I sat in his large scary chair as he examined my frankly manky teeth. With a kind but weary smile he looked at me and said “I don’t mean to be condescending, but how long are you actually spending brushing your teeth every day? Are you flossing?”. I mumbled some half-arsed answer and he continued “ok, let me show you how to brush properly”.
I have been rather earlier to learning about security than dental hygiene though, and have spent most of the past ten years delivering cyber change programmes. I’m still not a “security guy” but I’ve come to value and respect the knowledge that the security gals and guys I work with have. Try it for yourself. Find the team that run your SOC and ask them about the incidents they see every day. Ask a pen tester to show you how attackers can exploit your software. Get time with a threat intelligence analyst and ask them about the latest techniques the cyber criminals are using. Talk to a security architect about what the future of cyber may look like. You’ll be surprised at how much you’ll learn, and how much it will improve you as an IT professional. Oh and book that long over due dental check up.
Footnote (*) no they haven’t gone away. Wannacry still accounts for up to 40% of ransomware attacks this year according to ESET.