Posts

Showing posts with the label incident response

Another analogy: Incident Investigations and Jawbreaker (gobstopper) candy - IR musings

After a couple of vacations to a country under lockdown due to the novel coronavirus, my first experience taking a SANS course , a bout of (regular strain of) flu, and some consistently busy work weeks, I'm back with yet another analogy. In looking up a reliable reference page to link to describe the jawbreaker candy , I discovered that in the regions outside of North America they seem to be called gobstoppers. If you can't be bothered to follow the above link, here are some salient excerpts: Gobstoppers usually consist of a number of layers, each layer dissolving to reveal a differently coloured (and sometimes differently flavoured) layer, before dissolving completely. Gobstoppers are too hard to bite without risking dental damage (hence the name "jawbreaker"). [snip] As gobstoppers dissolve very slowly, they last a very long time in the mouth, which is a major factor in their enduring popularity with children. Larger ones can take days or even weeks* to ful

Cyber Security Incident Responder as a musical conductor: an analogy

Those who know me personally may be aware that my main extra-curricular, spanning a full decade starting at age 11, was playing the viola in music ensembles which ranged from the intimacy of quintets to the power of 80-piece orchestras. In fact I'd taken piano performance the most seriously (read: via private lessons for eight years with a reputable teacher at the Royal Conservatory of Music) so I never became as proficient in viola. In contrast to the years-long solitary struggle that comprised my endeavour to passably interpret several Beethoven sonatas, a few of Bach's keyboard works, and a Chopin mazurka or two however, my most vivid memories at school are social, involving becoming acquainted with compositions by actively collaborating with my fellow musicians. My love for "classical" (more accurately, baroque to early romantic era) music continues unabated, and a desire to perform has now been channeled instead into haunting the Musikverein and Konzerthaus -

Musings from an IR - Meeting and Parting with Strangers

After nearly two whole months in this Cyber Security Incident Responder role, I remain amused by the universally expressed sentiment from every new person I meet. Specifically, that they're pleased to make my acquaintance, but sincerely hope our interactions are short-lived and that they wish to never need to cross paths with me again, as representative of all people in my role. On the one hand, as a self-professed deep introvert , making cold contact with complete strangers on a daily basis is a draining ordeal, despite my extensive experience with many types of colleagues and clients. What mitigates the fatigue is that firstly, most of the people I interact with are experts in their disciplines, which I appreciate both in principle, and from the delightful side effect of learning a surprising amount about what they care about professionally and what processes they follow. Secondly as they are almost always embroiled in a stressful situation, they appreciate my presence as guid

Thoughts of a fledgling Incident Responder: one month in

As stated in my recent posts, I've made another career switch. This time, I'm dipping my metaphorical toes into the increasingly mission-critical area of most businesses: that of cyber security. The new look that I've applied to this blog, that of a darkened forest, is an analogy that I find apt. In broad strokes, most people are aware of its existence, yet few have explored it to find the diversity of the elements which comprise it.  Being such a neophyte myself I count myself as especially fortunate, to be in a team where there are already experts I could call upon, where we have the potential to leverage powerful, industry-leading tooling, and in an environment where every employee is called upon to actively protect not only our own data and assets, but those we are entrusted with by our clients.  In fact, it was immediately apparent that one has no choice but to take this role seriously if only because my employer's clientele consists mostly of organizations t