Tuesday, November 27, 2012

Cyber Security Challenge announces second round competitions

The UK national Cyber Security Challenge has announced four face-to-face competitions for the next round of the current challenge.  

Cyber Security Challenge UK runs a series of national inspirational competitions aimed at attracting talented people to the profession and informing them about cybersecurity careers and training.

In the latest round of competitions, professional cyber teams from Orange, Prodrive, (ISC)2, the SANS Institute, QinetiQ and Sophos will test more than 100 qualifiers from the virtual first-round competitions over the coming months to determine the 40 finalists for the Masterclass grand finale in March 2013.

The Orange and Prodrive Risk Analysis challenge will pit candidates against a real-life motorsport set-up, complete with Aston Martin Racing car, pit crew, technical team and a complex ICT infrastructure that connects them all.

Candidates will work as security architects to deliver a practical security solution that protects the team’s intellectual property (IP) and confidential information from its rivals in preparation for Le Mans, the biggest date in the international racing calendar.

“Cyber security is a growing issue in professional racing, where the IP of the car and the information relayed between the team during races is vital to the performance on the track," said Michael Cloete, Prodrive head of IT said. "It’s fundamental business-to-business security and risk analysis, looking at how much vulnerability you allow before you put the organisation at risk or how secure you need to be before you run over budget and impede the team.”

The SANS Net Wars challenge will give candidates the opportunity to demonstrate their skills on one of the world’s most recognised cyber training platforms.

Currently used by used by professionals at some of the largest companies and government organisations in the world, this is the first time NetWars has been incorporated into the Cyber Security Challenge UK.

During two hours of gaming, participants will be tasked with recovering a number of targets from a virtual environment, with scores displayed on a real-time scoreboard to show their progress.

In the Sophos Malware Hunt, candidates will take on the role of forensics and defence specialists working for the UK Government. They will face the nastiest creations of both cyber criminal gangs and nation states as they run rampant in a virtual environment.

The candidates' mission will be to gather and analyse evidence of attacks on the systems, and identify the attackers’ motives, skill levels and likely origins. Finally, candidates will present their findings and make recommendations on the actions to be taken.

In the QinetiQ and (ISC)2 Command and Control challenge, teams of candidates will be responsible for securing the IT systems protecting a simulated top-secret facility. They must identify, fix and exploit vulnerabilities in command software systems and work to anticipate security breaches to avoid attack.

The challenge will provide first-hand experience of what it takes to secure software systems and the critical effect cyber attacks can have on the security and safety of an organisation, its people and its assets.

“Secure software development is a significant new area of focus for information security professionals, with application vulnerabilities increasingly identified as the number one threat to organisations," said John Colley, managing director for Europe at (ISC)2.

“For too long software that underpins business and much of our most critical national infrastructure has been written without enough appreciation for how easily it can be exploited or manipulated. We hope this competition will both educate software developers as to the importance of embedding security from first principles in the systems they write, and also attract some of the most gifted and security minded candidates over to work in a new exciting field where their skills are very much sought after. ”

Cyber Security Challenge UK CEO Stephanie Daman said: “This year’s face-to-face competitions have broadened the range of skills we are testing in a bid to more accurately represent those needed most by the range of employers which support us.”

As well as identifying talented people who can move straight into unfilled jobs, she said the four face-to-face competitions will open the eyes of more than 100 talented amateurs who might never have considered how exciting a job in this sector could be.

Image: Hemera/Thinkstock


Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy$("a#eproductLogin").attr('href', function(i) { return $(this).attr('href') + '?fromURL=' + regFromUrl; });

computer

windows

UK rail ticketing services get next-generation facelift with AWS cloud

Rail Settlement Plan (RSP), the company that provides IT and retail services to UK rail operators, is upgrading its systems with AWS cloud to provide a next-generation ticket issuing systems as a growing number of commuters adopt the “click and collect” model.

The system will provide the rail industry with a flexible, high-availability cloud-based service. This will support ticketing on departure, where users collect rail tickets from self-service ticket machines after purchasing them earlier on the web.

The automated, on-demand infrastructure will enable train operating companies to support large fluctuations in demand for tickets during peak periods.

“Rail ticketing demand goes through seasonal and daily peaks and troughs, which makes it a great use case for cloud computing,” said Neil Miles (pictured), managing director at Smart421, the UK IT consultancy firm that will design, build and manage the new system for RSP.

RSP has signed a five-year contract to Smart421 to design a live sales management system using Amazon Web Services’ cloud platforms.

The AWS cloud implementation will begin in December this year with the new system ready in early 2014. But the contract includes a five-year 24/7 support service. The financial terms of the deal were not disclosed.

The cloud-based system can be scaled up to a billion tickets per annum by 2018 without more capital investment in computer hardware.

RSP can also scale it back during the off-peak times, saving it costs for itself and for the rail operators, which include Eurostar, Chiltern railways, East Coast, First Great Western, Virgin Trains, South West Trains and Scot Rail among others.

Among other benefits, it will allow RSP to support future delivery channels such as mobile and smartcards, as customers’ adopt these channels.

The new cloud-based sales management system is part of RSP’s IT modernisation plan to meet the demands of rail travellers who want the convenience that comes with mobile ticketing and systems such the London Underground Oyster card, Miles said told Computer Weekly.

“One of the key challenges the new system addresses is providing flexibility to the growing number of ticketing systems and retailers,” Miles said.

The new infrastructure will provide the basis for interoperability where a ticket can be sold through one channel, collected through a second and validated through another, he said.

It will also help the company upgrade the system to support new generations of ticketing technology that rail franchises may use in the future when issuing passenger tickets.

The RSP live sales management system will be built on a range of technologies in the AWS cloud, including: Amazon Elastic Compute Cloud (Amazon EC2), Amazon Simple Storage Service (Amazon S3) and Amazon Elastic Map Reduce (EMR).

Smart421 will use AWS as the cloud computing platform to deliver support for business processes, including deferred ticket delivery and sales reconciliation.

The system will receive, validate and store records in a secure repository, check the correct rail card has been used and deliver reporting on all transactions from all areas of the system.

It also integrates leading open source technologies such as an identity and access management platform (ForgeRock) and reporting database and reports server (Infobright and Jaspersoft) with the core transaction process and routing platform (RedHat).

To overcome the data security issues of cloud computing and all-time high-availability challenges, the system will be built across multiple availability zones in the AWS European region.

“We have taken security very seriously. Starting with the basics, we are taking advantage of a highly secure environment in the AWS Cloud that is ISO 27001 certified,” Miles said. 

The security layering of the new system will include measures to minimise any attack surface and tightly manage access via Identity & Access Management (IAM) controls. Smart421 will also apply the security design patterns that best exploit the security measures already built into the AWS cloud, Miles said.

While it provides a flexible, secure and highly-available ticketing system for rail operators to serve their customers, what does it bring to RSP’s infrastructure?

One of the challenges RSP’s IT team faced with the old system was ensuring lower total cost of ownership, protecting revenue and opening up systems without compromising customer data security.

Cloud computing’s utility-based computing model will help it minimise infrastructure costs – one of the key advantages in a time of shrinking IT budgets.

“This live sales management project will deliver high-quality service at reasonable cost which is good news for all industry stakeholders,” said Steve Howes, managing director at RSP. “We realise that this project will be watched very carefully because of its importance to RSP and the train operating companies we serve.”

The AWS-based sales management system is also vital to updating RSP’s business services over the next few years and is the first step in the company’s IT modernisation programme.

The AWS cloud infrastructure will allow RSP’s IT team to focus on serving the train operating companies rather than on managing and scaling internal technology infrastructure, Miles said.


Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy$("a#eproductLogin").attr('href', function(i) { return $(this).attr('href') + '?fromURL=' + regFromUrl; });

computer

windows

Cyber attack reporting will boost defence capability, says Neelie Kroes

The European Commission (EC) is considering making it mandatory for companies to report cyber attacks to harness the benefits of open dialogue, says vice-president Neelie Kroes.

Despite industry opposition, open discussion about cyber threats is vital to enable organisations to learn and improve understanding of the issue, she told the German publication Süddeutsche Zeitung.

Details of the EU’s plans are likely to be revealed later this year with the publication of the its cyber security strategy.

Kroes, who is responsible for the EU’s Digital Agenda, believes cloud computing may give new impetus to the faltering economy, provided people are confident that the new model is reasonably secure.

The EC predicts that cloud computing could boost European economic output by €160bn a year because of increased efficiencies and lower cost access to resources by smaller companies.

Kroes believes that increased use of cloud technologies will also create 2.5 million jobs by 2020 and help redress high unemployment among youth across Europe.

In January, Kroes called on public authorities, industry, cloud buyers and suppliers to come together in a European cloud partnership.

Calling for action to support the speedy uptake of cloud computing in Europe at the World Economic Forum in Davos, Switzerland, Kroes said the main obstacles to cloud adoption like standards, certification, data protection, interoperability, lock-in, and legal certainty needed to be addressed.

The EC has established a working group to address the need for common technical standards to support and grow the cloud computing industry.

The working group is set to tackle thorny issues such as what happens to organisations’ data after the cloud services contract expires.

In early November, the steering board of the new European Cloud Partnership (ECP) met in Brussels to kick off the process of building an EU Digital Single Market for cloud computing.

The board aims to make the most of the public sector's buying power to shape the growing market for cloud computing services.

The ECP will develop common computing procurement requirements for use by EU member states and create a common framework for cloud computing across Europe.

The ECP is also tasked with stimulating the migration of public IT to the cloud by resolving barriers to cloud computing adoption in the public sector.


Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy$("a#eproductLogin").attr('href', function(i) { return $(this).attr('href') + '?fromURL=' + regFromUrl; });

computer

windows

Half of companies lack cyber threat knowledge

Half of companies worldwide lack knowledge about potential security threats they may face, a global IT risks survey has revealed.

Almost a third of more than 3,000 IT professionals, including 200 from the UK, polled by security firm Kaspersky Lab, admitted they had never heard of any of the cyber epidemics that recently posed direct threats to their organisations.

A further 58% highlighted a lack of resources into both staffing and improving IT security systems, reducing the organisations' ability to cope with cyber security threats. This was mainly due to poor understanding among senior managers of the reasons why IT departments exist.

The survey also revealed that 35% of companies have insufficient personnel trained to deal with IT threats.

According to Kaspersky Lab, this problem cannot be dealt with simply by hiring new employees; existing staff also need to be educated. 

Teaching staff the basics of IT security should be no less important than installing the latest software

Kaspersky Lab

The research report said this is emphasised by the low level of computer literacy among employees, which can lead to confidential information leakages, and to the infection – or even total disablement – of a company’s IT infrastructure.

The report concludes that teaching staff the basics of IT security should be no less important than installing the latest security software.

Commenting on the survey’s findings, Eugene Kaspersky, CEO and co-founder of Kaspersky Lab, said: “Companies should not underestimate global cyber threats.”

He said although organisations are starting to take this issue seriously and have increased the proportion of IT staff dedicated to security to around 40%, these people are not always sufficiently trained and competent to protect businesses from the most pertinent threats.

“Increasing the level of computer literacy among staff is an essential element of security, while senior management needs to be fully aware of the potential consequences of cyber threats and understand that reliable protection of the corporate network is vital in ensuring the effective development of a company’s IT infrastructure,” said Kaspersky.

IT security, he said, is important not only to individual companies, but to whole economies, because cyber criminals can destroy the normal business environment; they could prevent future global development and bring on economic and even political collapse.

“We are here to stop this happening, and are confident of doing so,” said Kaspersky.

Image: Hemera/Thinkstock


Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy$("a#eproductLogin").attr('href', function(i) { return $(this).attr('href') + '?fromURL=' + regFromUrl; });

computer

windows

BBC management gains tighter cost control with dashboards

BBC managers are gaining tighter cost control with SAP Business Objects Web Intelligence dashboards.

Simon Griffiths, data and reporting improvement manager at the BBC, presented the corporation’s home services management information (MI) strategy at the recent SAP UK and Ireland user group meeting in Manchester. 

Simon Griffiths said the BBC MI strategy goal was to focus managers more on decision-making for future programmes and less on manipulating data.

The dashboard project began in December 2011, and has become part of a Finance Effectiveness programme, headed by John Turner, programme change director at the organisation.

Griffiths initially carried out a proof of concept dashboard, on cost centre reporting, to get the project started, “without involving consultancies”. 

His is a “relatively small team”, consisting of six data warehousing and business intelligence (BI) professionals, with three other contractors from the finance effectiveness effort.

He is a trained accountant with a background in engineering. He joined the BBC in 2006 as a continuous improvement consultant. Though more on the business side of the organisation, he said that he knows enough about the detail of the technology to know when he does not know enough. 

And the challenge, he said, is to knit together those who know how to grab and filter the data with those who know what to present to which end-user group. 

“It is difficult to find people who can take the data all the way from the data warehouse to the dashboard," said Griffiths.

He recommended the approach of getting stuck in to real data and proving the value fast. 

“Don’t sit back and do an involved cost-benefit analysis. You can do a proof of concept for free. It doesn’t have to be SAP. I’ve used QlikView, too. The tools are much of a muchness," he said.

His team is now creating one dashboard per month. The core idea is to provide a dashboard targeted for each audience inside the business. The dashboards are spread across 1,300 cost centres and 600 managers are using them. 

“We’ve got managers asking for them, and that is new," Griffiths said.

Managers can now see things like top 10 expenses, and can quickly see what is in policy or not. But the dashboards are not just for finance. Dr Who is but one programme run as a project in an SAP environment, he said.

Griffiths said that his team has “good statistics on take up, coupled with good anecdotal evidence [of interest]."

The dashboards are at the end of “a long chain”, stretching from a BW warehouse through business objects to web intelligence, where the data is modelled.

The dashboards are proving their worth, he said, in cutting down on training. 

“It’s more efficient to have one system, rather than three or more. New starters are used to buying stuff on Amazon and it is as easy as that. The dashboard knows who the manager is. And the manager can write notes within the dashboards, which is an aid to working more effectively with colleagues."

The next stage is mobile access, delivering dashboards on tablets. “The business case for mobility remains a challenge," said Griffiths. 

"It is almost an act of faith. I’ve not seen one killer application for that, but it would improve the user experience”.


Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy$("a#eproductLogin").attr('href', function(i) { return $(this).attr('href') + '?fromURL=' + regFromUrl; });

computer

windows