For companies in all sectors, installing the right kind of information security leader could be the difference between sinking and swimming. AFP
For companies in all sectors, installing the right kind of information security leader could be the difference between sinking and swimming. AFP
For companies in all sectors, installing the right kind of information security leader could be the difference between sinking and swimming. AFP
For companies in all sectors, installing the right kind of information security leader could be the difference between sinking and swimming. AFP

Amid coronavirus, how to not fall victim to a cybercrime


  • English
  • Arabic

If you get into difficulty in a swimming pool, who do you want rescuing you? Someone who understands the rules on the sign at the entrance but who cannot swim? Or someone who is prepared to dive in?

Just as in water, if you are drowning in a cyberattack, theory is not your priority.

Companies are realising that they need to hire a new kind of information security leader – people who not only know the rules, but who also understand hacking, the criminal mind, and the value of creativity. Finding and attracting them will not be easy.

Many organisations get into trouble as a result of hacks and data breaches – crisis moments when operations go haywire and reputations hang in the balance. These often occur when risk and confusion are heightened in other ways – such as now, during the Covid-19 pandemic, when attacks have increased as hackers look to take advantage of this global crisis and the resulting surge in remote working.

Although it is invisible to the naked eye and does not produce smoke or fire, the online threat landscape is a battlefield where people exploit fear and fight over real assets through their computers.

Historically, businesses have entrusted security leadership to theoreticians rather than practitioners. Getty Images
Historically, businesses have entrusted security leadership to theoreticians rather than practitioners. Getty Images

Historically, businesses have entrusted security leadership to theoreticians rather than practitioners. The typical chief information security officer, or Ciso, has had a lawyerly quality: fluent in terminology, strong on policy and strict on checklists.

But this stereotype must change. No rulebook or college certificate can repel a hacker armed with the latest weaponised malware or free a system hijacked by a state-backed gang. A Ciso without a grasp of gritty detail is like a lifeguard who cannot swim.

What must the new generation information security leaders look like?

First, they will need outstanding technical facility – especially, in the dark arts of hacking. It is vital that a Ciso knows where attacks come from, how they spread through networks and how to stop them. They should believe that “attack is the best form of defence”. Good Cisos will be those who roll up their sleeves to meet threats head-on rather than sitting in wait.

Second, they will need to understand assailants’ motives. Classifying threats in neat typologies obscures the diversity of the characters behind them. Hackers try to infiltrate systems for all sorts of reasons – from the criminal to the moralistic. Some do it just for fun. Understanding why an attack could be perpetrated often provides clues to defence and resolution.

Third, they will need to be creative. Those who stick to case studies and guidelines will stumble when unfamiliar threats emerge. In some crises, tried-and-tested methods will work. In others, risky improvisation may be the only alternative to catastrophe. Future Cisos will benefit from a maverick streak based on lateral technical thinking.

On top of all this, ideal security leaders will need to function effectively in corporate environments. Communication skills are critical. As digital perils proliferate, high-level executives – or the C-Suite – will require a dynamic map of the changing terrain. The Ciso must provide this, translating complicated jargon into plain language so that bosses can effectively balance risk against cost.

Job interview with candidate in modern office
Job interview with candidate in modern office

Unfortunately for businesses, candidates fulfilling this description will be tricky to find.

For one thing, elite technical talent is dispersed. The internet has created a cosmopolitan community of hackers, programmers and coders. Controlling for economic development, the concentration of people with exceptional computer skills in a given place is generally proportionate to population size. But sometimes, a company will require unique abilities which are unavailable locally. Tapping into a fluid global marketplace to find exactly the right candidate is a challenge employers must overcome.

Moreover, below the surface, the internet has a confusing culture of anonymity. This anarchic quality is what attracts many people. But it also creates problems for would-be recruiters who, without the help of highly customised tools, can get lost in the murky world they are sifting through.

Perhaps the most important question is why an elite hacker with a non-conformist personality would want to work for a business at all.

On the face of it, our ideal future Ciso might find adjustment to a life of meetings, conference calls and regular hours quite difficult. But it is wrong to think that there is no overlap.

The practice of “ethical hacking”, in which companies actively seek skilled hackers to expose weaknesses in their systems, points to a potential solution.

Most people who excel at hacking are not inherently opposed to working in corporate roles. It is just that many companies need a culture shift to make the most of their unorthodox talents

Manipulating computer code is not inherently bad – and in fact, in many cases, it is useful and beneficial. It is the destructive consequences of hacking that are bad, and these result from unaccountability and malign motives. Most people who excel at hacking are not inherently opposed to working in corporate roles. It is just that many companies need a culture shift to make the most of their unorthodox talents.

The real challenge is therefore for companies to build a professional environment that appeals to the new generation of security leaders in the first place: by incentivising them to do what they do best for the right reasons, and not suffocating them within backward-looking work structures. This will take a new approach.

For companies in all sectors, the cost of installing the wrong kind of information security leader could be high. Those that have fallen victim to cybercrime even while the Covid-19 crisis rages around them have learnt this the hard way. But what are the benefits of doing it right? It could be the difference between sinking and swimming.

Nathan Swain is the chief information security officer at ADS Securities in Abu Dhabi

Student Of The Year 2

Director: Punit Malhotra

Stars: Tiger Shroff, Tara Sutaria, Ananya Pandey, Aditya Seal 

1.5 stars

Citadel: Honey Bunny first episode

Directors: Raj & DK

Stars: Varun Dhawan, Samantha Ruth Prabhu, Kashvi Majmundar, Kay Kay Menon

Rating: 4/5

UAE currency: the story behind the money in your pockets
COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3EName%3A%20%3C%2Fstrong%3ESmartCrowd%0D%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2018%0D%3Cbr%3E%3Cstrong%3EFounder%3A%20%3C%2Fstrong%3ESiddiq%20Farid%20and%20Musfique%20Ahmed%0D%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EDubai%0D%3Cbr%3E%3Cstrong%3ESector%3A%20%3C%2Fstrong%3EFinTech%20%2F%20PropTech%0D%3Cbr%3E%3Cstrong%3EInitial%20investment%3A%20%3C%2Fstrong%3E%24650%2C000%0D%3Cbr%3E%3Cstrong%3ECurrent%20number%20of%20staff%3A%3C%2Fstrong%3E%2035%0D%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%20%3C%2Fstrong%3ESeries%20A%0D%3Cbr%3E%3Cstrong%3EInvestors%3A%20%3C%2Fstrong%3EVarious%20institutional%20investors%20and%20notable%20angel%20investors%20(500%20MENA%2C%20Shurooq%2C%20Mada%2C%20Seedstar%2C%20Tricap)%3C%2Fp%3E%0A
CABINET%20OF%20CURIOSITIES%20EPISODE%201%3A%20LOT%2036
%3Cp%3E%3Cstrong%3EDirector%3A%20%3C%2Fstrong%3EGuillermo%20del%20Toro%3Cbr%3E%3Cstrong%3EStars%3A%3C%2Fstrong%3E%20Tim%20Blake%20Nelson%2C%20Sebastian%20Roche%2C%20Elpidia%20Carrillo%3Cbr%3ERating%3A%204%2F5%3C%2Fp%3E%0A
2.0

Director: S Shankar

Producer: Lyca Productions; presented by Dharma Films

Cast: Rajnikanth, Akshay Kumar, Amy Jackson, Sudhanshu Pandey

Rating: 3.5/5 stars

Monster Hunter: World

Capcom

PlayStation 4, Xbox One

ABU%20DHABI'S%20KEY%20TOURISM%20GOALS%3A%20BY%20THE%20NUMBERS
%3Cp%3EBy%202030%2C%20Abu%20Dhabi%20aims%20to%20achieve%3A%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%2039.3%20million%20visitors%2C%3C%2Fstrong%3E%20nearly%2064%25%20up%20from%202023%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%20Dh90%20billion%20contribution%20to%20GDP%2C%3C%2Fstrong%3E%20about%2084%25%20more%20than%20Dh49%20billion%20in%202023%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%20178%2C000%20new%20jobs%2C%3C%2Fstrong%3E%20bringing%20the%20total%20to%20about%20366%2C000%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%2052%2C000%20hotel%20rooms%2C%3C%2Fstrong%3E%20up%2053%25%20from%2034%2C000%20in%202023%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%207.2%20million%20international%20visitors%2C%3C%2Fstrong%3E%20almost%2090%25%20higher%20compared%20to%202023's%203.8%20million%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3E%E2%80%A2%203.9%20international%20overnight%20hotel%20stays%2C%3C%2Fstrong%3E%2022%25%20more%20from%203.2%20nights%20in%202023%3C%2Fp%3E%0A
Martin Sabbagh profile

Job: CEO JCDecaux Middle East

In the role: Since January 2015

Lives: In the UAE

Background: M&A, investment banking

Studied: Corporate finance

FA%20Cup%20semi-final%20draw
%3Cp%3ECoventry%20City%20v%20Manchester%20United%C2%A0%3C%2Fp%3E%0A%3Cp%3EManchester%20City%20v%20Chelsea%3C%2Fp%3E%0A%3Cp%3E-%20Games%20to%20be%20played%20at%20Wembley%20Stadium%20on%20weekend%20of%20April%2020%2F21.%C2%A0%3C%2Fp%3E%0A
Pharaoh's curse

British aristocrat Lord Carnarvon, who funded the expedition to find the Tutankhamun tomb, died in a Cairo hotel four months after the crypt was opened.
He had been in poor health for many years after a car crash, and a mosquito bite made worse by a shaving cut led to blood poisoning and pneumonia.
Reports at the time said Lord Carnarvon suffered from “pain as the inflammation affected the nasal passages and eyes”.
Decades later, scientists contended he had died of aspergillosis after inhaling spores of the fungus aspergillus in the tomb, which can lie dormant for months. The fact several others who entered were also found dead withiin a short time led to the myth of the curse.

'Avengers: Infinity War'
Dir: The Russo Brothers
Starring: Chris Evans, Chris Pratt, Tom Holland, Robert Downey Junior, Scarlett Johansson, Elizabeth Olsen
Four stars

Veil (Object Lessons)
Rafia Zakaria
​​​​​​​Bloomsbury Academic

THE SPECS

Engine: 4.4-litre V8

Transmission: Automatic

Power: 530bhp 

Torque: 750Nm 

Price: Dh535,000

On sale: Now