BeyondCyber: Recent Episodes

bruno

How to get into Cyber Security and be successful

View Details

Unlock the secrets to impenetrable security as industry expert Jane Doe joins us to dissect the crucial role of administration in access control systems. Through our exploration, you'll gain essential knowledge on crafting a fortress of digital security that stands firm against the onslaught of cyber threats. We delve into the nuances of user account management, the enforcement of unyielding password policies, and smart account lockout strategies that can mean the difference between safety and compromise. Jane's proficiency shines as we navigate the intricacies of defining roles, assigning permissions, and adhering strictly to the least privilege principle, crafting a shield that minimizes vulnerabilities at every turn.

Jane also illuminates the often-overlooked importance of precise access termination, outlining why prompt revocation of rights is pivotal in averting unauthorized entry and the ensuing security breaches that can cripple an organization. Grasp the full spectrum of implications that stem from lackadaisical termination protocols, including staggering non-compliance fines and unchecked security risks. Embrace the insights on how a robust termination protocol not only enhances audit ability but also fortifies the very pillars of your organization's security posture. This episode promises to arm you with the administrative acumen needed to maintain a security framework that ensures operational integrity and efficiency without compromise.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Unlock the secrets to a fortress-like security system with guidance from our expert guest, a renowned security architect. This episode offers you a clear, step-by-step journey into creating an impenetrable access control plan. We start by dissecting the anatomy of your organization to identify what truly needs guarding, transitioning seamlessly into setting objectives that align with your security goals. Whether it's securing sensitive data or enhancing user productivity, we've got you covered.

Our conversation evolves into an actionable blueprint, detailing the selection of the most suitable access control model for your business—be it DAC, MAC, RBAC, ABAC, or a crafty hybrid. But we don't stop there; we meticulously explore the integration of this system with your existing IT infrastructure, ensuring every policy and protocol is not just a theoretical concept but a living, breathing part of your organization's defense. By the end of our discussion, you'll have the tools to not only deploy but also maintain an access control system that stands vigilant against threats, keeping your assets secured and your compliance unchecked. Join us for this enlightening episode that promises to bolster your organization's shield against the digital onslaught.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Unlock the door to digital safety and navigate the complexities of Identity and Access Management (IAM) with our expert guest. Together, we unveil the power of IAM frameworks that keep digital identities secure, manage user accounts and permissions, and enhance security through advanced authentication processes. Get ready to unravel the marvels of Single Sign-On (SSO), a game-changer in user access that consolidates sign-in processes and shields against password threats. And don't miss the critical layers of defense that Multi-factor Authentication (MFA) adds to your security arsenal, ensuring that even if passwords fall, your data stands strong.

Step into the exclusive domain of Privileged Access Management (PAM) and discover its essential role in protecting your organization's most sensitive resources. Our conversation goes in-depth, examining the mechanisms of session management and the impact of regular access reviews to maintain tight, relevant permissions. Learn how access management transcends security, becoming a pivotal player in compliance with rigorous industry regulations and standards. Hear firsthand the strategies and tools savvy organizations deploy to make auditing and compliance efforts not just effective, but seamless. Tune in to transform your understanding of cybersecurity and access management into actionable knowledge.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Unlock the secrets of cybersecurity's frontline defense with our latest episode, where we dissect the critical role of access control in guarding against some of the most notorious data breaches shaping our digital era. Step into the world of digital fortification with our cybersecurity expert guests as we scrutinize the infamous collapses of giants like Equifax, Facebook, and Marriott International. Through these cautionary tales, we illuminate the stark consequences of access control failures and reveal the indispensable security practices that could have made a difference.

Tune in for a revealing look at the banking sector's battle against cyber threats, spotlighting the chilling Citibank data breach of 2020. Learn how the simple principle of minimum necessary access can be a game-changer in protecting customer data, and why continuous vigilance is non-negotiable in the high-stakes domain of financial security. Our experts provide a playbook on robust authentication methods, shedding light on the proactive steps banks and customers alike must embrace. This episode is an unmissable masterclass for anyone keen on safeguarding their digital assets against the ever-evolving tactics of cyber adversaries.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

“Secure-by-Default” means products are resilient against prevalent exploitation techniques out of the box without additional charge. These products protect against the most prevalent threats and vulnerabilities without end-users having to take additional steps to secure them. Secure-by-Default products are designed to make customers acutely aware that when they deviate from safe defaults, they are increasing the likelihood of compromise unless they implement additional compensating controls.

  • A secure configuration should be the default baseline. Secure-by-Default products automatically enable the most important security controls needed to protect enterprises from malicious cyber actors, as well as provide the ability to use and further configure security controls at no additional cost.
  • The complexity of security configuration should not be a customer problem. Organizational IT staff are frequently overloaded with security and operational responsibilities, thus resulting in limited time to understand and implement the security implications and mitigations required for a robust cybersecurity posture. Through optimizing secure product configuration—securing the “default path”— manufacturers can aid their customers by ensuring their products are manufactured, distributed, and used securely in accordance with “Secure-by-Default” standards.

Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Default | Cyber.gov.au

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Secure-by-Design” means that technology products are built in a way that reasonably protects against malicious cyber actors successfully gaining access to devices, data, and connected infrastructure. Software manufacturers should perform a risk assessment to identify and enumerate prevalent cyber threats to critical systems, and then include protections in product blueprints that account for the evolving cyber threat landscape.

Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Default | Cyber.gov.au

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Default | Cyber.gov.au

Technology is integrated into nearly every facet of daily life. Internet-facing systems are connected to critical systems that directly impact our economic prosperity, livelihoods, and even health, ranging from personal identity management to medical care. As only one example, cyber breaches have resulted in hospitals cancelling surgeries and diverting patient care globally. Insecure technology and vulnerabilities in critical systems may invite malicious cyber intrusions, leading to serious potential safety[1] risks.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

  • Excellent evidence: Testing a control with a simulated activity designed to confirm it is in place and effective (e.g. attempting to run an application to check application control rulesets).
  • Good evidence: Reviewing the configuration of a system through the system’s interface to determine whether it should enforce an expected policy.
  • Fair evidence: Reviewing a copy of a system’s configuration (e.g. using reports or screenshots) to determine whether it should enforce an expected policy.
  • Poor evidence: A policy or verbal statement of intent (e.g. sighting mention of controls within documentation).

guidance on the eight essential mitigation strategies from the Australian Cyber Security Centre (ACSC)’

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Upon concluding assessment activities, assessors will need to determine whether mitigation strategies were implemented effectively or not. This determination requires a combination of judgement and consideration of the following factors:

  • adoption of a risk-based approach to the implementation of mitigation strategies
  • ability to test the mitigation strategies across an accurate representative sample of workstations (including laptops), servers and network devices
  • level of assurance gained from assessment activities and any evidence provided (noting the quality of evidence)
  • any exceptions, including associated compensating controls, and whether they have been accepted by an appropriate authority as part of a formal exception process.

Assessors should use the ACSC’s standardised assessment outcomes which are:

  • Effective: The organisation is effectively meeting the control’s objective.
  • Ineffective: The organisation is not adequately meeting the control’s objective.
  • Alternate control: The organisation is effectively meeting the control’s objective through an alternate control.
  • Not assessed: The control has not yet been assessed.
  • Not applicable: The control does not apply to the system or environment.
  • No visibility: The assessor was unable to obtain adequate visibility of a control’s implementation.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Stages of an assessment

At a high-level, assessments are comprised of four stages:

  • Stage 1: The assessor plans and prepares for the assessment.
  • Stage 2: The assessor determines the scope and approach for the assessment.
  • Stage 3: The assessor assesses the controls associated with each of the mitigation strategies.
  • Stage 4: The assessor develops the security assessment report.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Stage 1: Assessment planning and preparation

Assessment planning

Prior to commencing an assessment, the assessor should conduct assessment planning activities. These activities require the assessor to discuss with the system owner:

  • system classification and assessment scope (see further detail below)
  • access to low and high-privileged user accounts, devices, documentation, personnel, and facilities
  • intended assessment approach and any approvals required to run scripts and tools (see further detail below)
  • evidence collection and protection, including any requirements following the conclusion of the assessment
  • where the security assessment report will be developed (e.g. on an assessor’s device or on an alternative device)
  • approach to stakeholder engagement and consultation (including key points of contact)
  • whether any managed service providers or other outsourced providers manage any aspects of the system (including appropriate points of contact)
  • access to any relevant prior security assessment reports for the system
  • appropriate use, retention and marketing of the security assessment report by both parties.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Stage 2: Determination of assessment scope and approach

Determine assessment scope

In determining the assessment scope, assessors should first clarify the target maturity level with the system owner, noting that the Essential Eight is required to be implemented and assessed as a package. For example, if a system owner has not previously had an assessment demonstrating that they have implemented Maturity Level One, they should not begin an assessment against Maturity Level Two until they have done so, and likewise for Maturity Level Two before being assessed against Maturity Level Three.

Having identified a suitable target maturity level, the assessor should familiarise themselves with the requirements for that maturity level as it will impact the components or aspects of the system within scope of the assessment. At this time it may also be useful to request an approximate percentage breakdown of the operating systems used on workstations and servers for the system.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Stage 3: Assessment of controls

The assessment of each mitigation strategy is performed by reviewing and testing the effectiveness of controls. This section provides guidance on the approach to assessing each mitigation strategy at a given target maturity level, along with relevant assessment considerations. Guidance on determining the effectiveness of the controls within each mitigation strategy is also provided within this section.

Assessment guidance for maturity levels in this section is cumulative. For example, the guidance provided in the Maturity Level Two section is focused on unique requirements above those of Maturity Level One. Likewise, the guidance provided in the Maturity Level Three section is focused on unique requirements above those of Maturity Level Two. This aligns with the manner in which assessments should be conducted against target maturity levels.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

The focus of this maturity level is adversaries who are content to simply leverage commodity tradecraft that is widely available to gain access to, and control of, a system. For example, adversaries opportunistically using a publicly-available exploit for a security vulnerability in an unpatched internet-facing service, or authenticating to an internet-facing service using credentials that were stolen, reused, brute forced or guessed.
The Essential Eight

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Patch applications

Context

Most vendors of internet-facing services regularly release updated versions of their applications to fix security vulnerabilities. Applications that exist on a system can be compared to the latest versions available from the vendor to determine whether existing versions are the latest, and if not, how long-ago updates were made available by the vendor, based on release dates and patch notes

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Configure Microsoft Office macro settings

Context

All users should be denied the ability to execute Microsoft Office macros by default unless they have a specific business requirement. If certain users are required to run Microsoft Office macros, they should be restricted to only the specific applications required (rather than all Microsoft Office applications). In addition, a record of their business requirement and associated approvals should be kept. This record should align with the list of users within the Active Directory group that have permission to run Microsoft Office macros. Note, once a business requirement can no longer be demonstrated by a user, permission to run Microsoft Office macros should be revoked

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Restrict administrative privileges

Context

Policies, processes and procedures for managing privileged access to systems should be documented and enforced within organisational workflows. In doing so, privileged access to systems and applications should be requested via a form, service desk ticket or email from users, and require approval from a supervisor or application owner, to maintain a record of all such requests. System owners should also maintain a list of all applications on their system that require privileged access.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Adversaries are known to indiscriminately use ‘malvertising’ in their attempts to compromise systems. Blocking web advertisements using web browser add-ins or extensions, or via web content filtering, can prevent the compromise of a system.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Context

Operating system vendors regularly publish updates to address security vulnerabilities. In addition, unsupported and out-of-date operating systems of internet-facing workstations and servers are a common target for adversaries.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Regular backups

Context

Backup and retention frequencies should be defined by the system owner in accordance with their organisation’s business continuity and disaster recovery requirements. In doing so, it is important that restoration of systems and data from backups be tested as part of regular (at least annual) disaster recovery exercises and not left to after the first major security incident is experienced.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

The guidance below outlines the requirements to be assessed in addition to the requirements of the previous maturity level. In doing so, assessments against Maturity Level Two should focus on the delta between Maturity Level One and Maturity Level Two.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Application control is implemented on workstations and internet-facing servers.Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.Allowed and blocked execution events on workstations and internet-facing servers are logged.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

A vulnerability scanner is used at least daily to identify missing patches or updates for security vulnerabilities in internet-facing services.

A vulnerability scanner is used at least weekly to identify missing patches or updates for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for security vulnerabilities in other applications.

Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Microsoft Office macro antivirus scanning is enabled.

Microsoft Office macros are blocked from making Win32 API calls.

Microsoft Office macro security settings cannot be changed by users.

Allowed and blocked Microsoft Office macro execution events are logged.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Web browsers do not process Java from the internet.

Web browsers do not process web advertisements from the internet.

Internet Explorer 11 does not process content from the internet.

Web browser security settings cannot be changed by users.

Microsoft Office is blocked from creating child processes.

Microsoft Office is blocked from creating executable content.

Microsoft Office is blocked from injecting code into other processes.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Privileged users use separate privileged and unprivileged operating environments.

Privileged operating environments are not virtualised within unprivileged operating environments.

Unprivileged accounts cannot logon to privileged operating environments.

Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

Administrative activities are conducted through jump servers.

Credentials for local administrator accounts and service accounts are long, unique, unpredictable and managed.

Privileged access events are logged.

Privileged account and group management events are logged.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

A vulnerability scanner is used at least daily to identify missing patches or updates for security vulnerabilities in operating systems of internet-facing services.

A vulnerability scanner is used at least weekly to identify missing patches or updates for security vulnerabilities in operating systems of workstations, servers and network devices.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Backups of important data, software and configuration settings are performed and retained with a frequency and retention timeframe in accordance with business continuity requirements.

Backups of important data, software and configuration settings are synchronised to enable restoration to a common point in time.

Backups of important data, software and configuration settings are retained in a secure and resilient manner.

Restoration of important data, software and configuration settings from backups to a common point in time is tested as part of disaster recovery exercises.

Unprivileged accounts cannot access backups belonging to other accounts.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Multi-factor authentication is enabled by default for non-organisational users (but users can choose to opt out) if they authenticate to an organisation’s internet-facing services.

Multi-factor authentication is used to authenticate privileged users of systems.

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

Successful and unsuccessful multi-factor authentication events are logged.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

FBI Director Christopher Wray announced the Bureau’s new strategy for countering cyber threats in remarks at the National Cybersecurity Summit 

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.

Only privileged users responsible for validating that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.

Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.

Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis.

Microsoft Office macros in files originating from the internet are blocked.

Microsoft Office macro antivirus scanning is enabled.

Microsoft Office macros are blocked from making Win32 API calls.

Microsoft Office macro security settings cannot be changed by users.

Allowed and blocked Microsoft Office macro execution events are centrally logged.

Event logs are protected from unauthorised modification and deletion.

Event logs are monitored for signs of compromise and actioned when any signs of compromise are detected.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

ACSC or vendor hardening guidance for web browsers, Microsoft Office and PDF software is implemented.

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.

Windows PowerShell 2.0 is disabled or removed.

PowerShell is configured to use Constrained Language Mode.

Blocked PowerShell script execution events are centrally logged.

Event logs are protected from unauthorised modification and deletion.

Event logs are monitored for signs of compromise and actioned when any signs of compromise are detected.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Administrative activities are conducted through jump servers.

Credentials for local administrator accounts and service accounts are long, unique, unpredictable and managed.

Windows Defender Credential Guard and Windows Defender Remote Credential Guard are enabled.

Privileged access events are centrally logged.

Privileged account and group management events are centrally logged.

Event logs are protected from unauthorised modification and deletion.

Event logs are monitored for signs of compromise and actioned when any signs of compromise are detected.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Backups of important data, software and configuration settings are performed and retained with a frequency and retention timeframe in accordance with business continuity requirements.

Backups of important data, software and configuration settings are synchronised to enable restoration to a common point in time.

Backups of important data, software and configuration settings are retained in a secure and resilient manner.

Restoration of important data, software and configuration settings from backups to a common point in time is tested as part of disaster recovery exercises.

Unprivileged accounts cannot access backups belonging to other accounts.

Privileged accounts (excluding backup administrator accounts) cannot access backups belonging to other accounts.

Unprivileged accounts are prevented from modifying and deleting backups.

Privileged accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Introduction

The Australian Cyber Security Centre (ACSC) has developed prioritised mitigation strategies, in the form of the Strategies to Mitigate Cyber Security Incidents, to help organisations protect themselves against various cyber threats. The most effective of these mitigation strategies are the Essential Eight.

The Essential Eight has been designed to protect Microsoft Windows-based internet-connected networks. While the principles behind the Essential Eight may be applied to cloud services and enterprise mobility, or other operating systems, it was not primarily designed for such purposes and alternative mitigation strategies may be more appropriate to mitigate unique cyber threats to these environments. In such cases, organisations should consider alternative guidance provided by the ACSC.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Multi-factor authentication

Context

Multi-factor authentication is one of the most effective controls an organisation can implement to prevent adversaries from gaining access to a system, service or application. When implemented correctly, multi-factor authentication can also make it significantly more difficult for adversaries to steal legitimate credentials to facilitate further malicious activities.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Application control

Context

Application control assessments can be done without tools but efforts will be severely limited in their effectiveness and are likely to miss edge cases that adversaries would look to exploit using higher levels of tradecraft. For example, adversaries may use custom tools to scan for weak or vulnerable paths on a system. This could be achieved with a Microsoft Office macro.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Overview

Assessments against the Essential Eight are conducted using the Essential Eight Maturity Model. This maturity model describes three target maturity levels (Maturity Level One through to Maturity Level Three) which are based on mitigating increasing levels of adversary targeting and tradecraft. The maturity model also includes Maturity Level Zero which exists for capturing instances in which the requirements of Maturity Level One are not met.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

The Australian  cyber security principles

Purpose of the cyber security principles

The purpose of the cyber security principles is to provide strategic guidance on how an organisation can protect their systems and data from cyber threats. These cyber security principles are grouped into four key activities: govern, protect, detect and respond.

Govern: Identifying and managing security risks.

Protect: Implementing controls to reduce security risks.

Detect: Detecting and understanding cyber security events to identify cyber security incidents.

Respond: Responding to and recovering from cyber security incidents.

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

We will explore why hands-on experience is important in cyber security.

Firstly, hands-on experience helps to develop practical skills. Learning cyber security concepts in a theoretical manner is not enough to address the dynamic cyber threats that organizations face today. Practical knowledge gained through hands-on experience help to develop technical proficiency and problem-solving skills needed to combat cyber threats in real-time situations. By working on real-world scenarios and simulations, cyber security professionals can learn how to identify and mitigate vulnerabilities, detect and respond to security incidents.

Secondly, hands-on experience provides exposure to various systems and tools. The field of cyber security is vast

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

Happy international Women's day. Let's face our fears and let nothing hold us back from progressing forward. 

Beyond Cyber 101 mentorship into cybersecurity and beyond.

View Details

A good example of  a Cyber Security Framework 
The South Australian Cyber Security Framework (SACSF) is a cabinet approved, whole of government policy framework which draws on international best practice for riskbased cyber security management. While the SACSF applies to all government agencies and their suppliers, it is not a one-size-fits-all or compliance approach to cyber security. Rather the SACSF reinforces the need for cyber security to be an enabler for government and drives this via a risk-based approach. This approach helps ensure risks are managed in a way that is commensurate with the risk appetite of the agency.

View Details

It's incredibly important to make a good impression when you are interviewing for a job, as you will probably be spending days or weeks meeting with the interviewer.
Try to be on time for your interview and arrive well-dressed and well-groomed. You should also be prepared to answer questions about your work experience, what you're looking for in a job, what you know about the company, and what you can offer.

View Details

It’s easy to give up when you fail, but that's the wrong approach. Instead, it’s important to keep trying and never give up. Failure is how we learn and grow, and through it we can find new opportunities to make progress. You may eventually succeed if you don't give up - even if it takes many attempts. It's also important to recognize failure as an opportunity for growth. It can help us become better informed about what works and what doesn't in a particular situation. Keep pushing forward, stay positive, and never lose hope - you might be surprised at the results!

View Details

Reflecting on the past year, I am reminded of both the successes and obstacles I have faced. While I am proud of what I have accomplished so far, this journey has taught me to appreciate and value the work that I do. As we enter a new year, my motivation to love what I do is stronger than ever. In addition to that, there are opportunities for growth and development available through mentorship programs that can help you and I expand  skillset and network. With determination and passion, the possibilities are endless. Wellcome back to beyond cyber

View Details

Welcome to 2023

Ransomware, phishing scams, and data breaches are projected to be the top three cyber security threats of the year. To protect yourself, always update your software with any available security patches, reinvest in cyber security solutions to ensure maximum protection, and regularly back up your data on a separate drive. Additionally, you should use strong passwords for all accounts and be aware of suspicious emails or websites for further prevention. With these proactive steps you can keep ahead of cyber criminals and stay safe online in 2023.

Australia is an attractive target for cybercriminals due to its high level of online connectivity, affluence and investment structures. During 2021–22 financial year a range of criminal activity including fraud, identity theft and business email compromise (BEC) have been prominent with malicious actors using various methods such as 'spear phishing' to gain access. As the landscape shifts quickly, Australia's risk exposure remains ever-increasing - reflecting how all aspects of the digital environment continue evolving along with criminals seeking new ways to profit in our nation.

As cyber security threats continue to evolve in 2023, protecting yourself from ransomware is more important than ever. Ransomware is a type of cyber attack that encrypts your data then provides you with instructions for payment in exchange for the key to unlock it. Taking proactive steps to protect yourself from this form of cyberattack can help prevent or minimize the damage if your computer does get infected. You should ensure your operating system, device drivers, and applications are all updated regularly, use strong passwords and two-factor authentication methods when available, back up your information frequently, use anti-virus software and encryption programs to protect personal files, be wary of suspicious emails and websites, and avoid downloading potentially malicious software. By taking these precautions, you can greatly reduce the chances of being hit by a cyber threat in 2023.

View Details

The most important aspect of taking responsibility for your life is to acknowledge that your life is your responsibility. No one can live your life for you. You are in charge. No matter how hard you try to blame others for the events of your life, each event is the result of choices you made and are making.

View Details

How to get into the cyber security Industry?
How to plan to get into cyber security.
Steps to plan and get into cyber security. 

View Details

A biography, or simply bio, is a detailed description of a person's life. It involves more than just the basic facts like education, work, relationships, and death; it portrays a person's experience of these life events.

View Details

Metamorphosis the process of transformation from an immature form to an adult form in two or more distinct stages

View Details

Critical thinking is the analysis of available facts, evidence, observations, and arguments to form a judgement. The subject is complex; several different definitions exist, which generally include the rational, skeptical, and unbiased analysis or evaluation of factual evidence. Critical thinking is self-directed, self-disciplined, self-monitored, and self-corrective thinking. It presupposes assent to rigorous standards of excellence and mindful command of their use. It entails effective communication and problem-solving abilities as well as a commitment to overcome.

View Details

Lets plan for success.  

View Details

What to do during  a cyber security incident. Some wisdom from the Godfather of cyber.

View Details

“Fit and chemistry must be considered when pairing the mentor and the protégé.
If the two don't get along, it matters little what each can offer the other
in terms of knowledge and skills.”

—Michael Zey, Building a Successful Formal Mentor Program

View Details

Definitely. It's one of those things. Look, this guy who created this relentless.com, that person is fully relentless. They keep going. No one can tell them no. And they've changed the world. They they've changed the entire world of commerce from what  they've created. So, Go, go ahead be Relentless too.

View Details

Your identity is as important as your environment for success. Your identity influences the way you look at things, the way you perceive and approach life, the way you react to your environment, the way you act and behave. All of which have a huge impact on creating your reality.

View Details

Re-uploaded Lost original mentorship Episode. Find a mentor. 

View Details

Fear should not stop you.  no not today. Look through your fears. Let me be the hunter, not the hunted, one way or the other, when we wake up in the morning, we are all going to have to run.

View Details

Grit is defined as ‘the perseverance and passion for long-term goals.’ A study by Angela Duckworth, professor of psychology, concluded that grit is a better predictor of success than intelligence.

View Details

Life must be managed and run as a Business. You are in business, you are the business.  The place you work for, like most of us, we work for somebody, the place you work for. The people you work for are your customers.

View Details

It's one of those crazy things that the CEO told me. I found it amazing , "change is inevitable. 
Change is coming. Change here and now. So What will you do to make the move into Cyber or a new Career. And he added on a sentence. "Success is optional".  Change is inevitable

View Details

The Process:
What is the process? How do I get started? This  podcasts is built in such a way that my desire is that you see the end and the process.  I walk through this process steps weekly. These are the fundamentals  of the routes available within cyber.

View Details

How to get started with Cyber security. Join the booming cyber security industry. how to plan for success in cyber security and more.