Last year, I attended some improv classes. In improv 101s, they often teach the principle of “Yes and…“, and for good reason. Allowing your partner to continue on a line of thought, providing them with enough information and scene would allow a conversation to continue. Functionally, improv classes, like Toastmasters settings (I did Toastmasters for…
“It’s Now or Never!” — 2024 Reflections
“It’s now or never. We are going to do this Toto. We are gonna do this!” Eventually, thanks to a new plan (data-driven), Lewis Hamilton went on to win a race that was originally lost on the first lap. But the plan was only thought to be feasible about 20 minutes ago. My Own “Now…
OT Security 101 Workshop — Some Thoughts on Some Exercises and Extra Miles
When teaching the OT Security 101 Workshop for Div0, one conundrum I had (and in general, for any introductory workshop) is how we can provide enough material for the faster peers amongst us, yet make sure the slower ones can catch up. We do this through the concept of the extra mile. This was first…
Learning from Crowdstrike
On Friday evening, I caught up with a fellow cybersecurity professional over dinner. Luckily none of us had to deal with the meltdown Crowdstrike had caused. But this caused much grief and frenetic hours for our IT administrators around the globe, who had to manually perform workarounds to recover affected Windows servers and clients. Being…
I Was Told HTTP is Unsafe. But Maybe I am Using It After All?!
In April, it was reported that the eScan antivirus update mechanism was targetted by an APT group to distribute GuptiMiner malware. The malware itself is quite sophisticated, but what was baffling to me was the modality of said attack: delivery of the attack vector through HTTP. The “Lock” on the Browser If you had been…
What to Tell Your Friend if They Ask “Can Quantum Cryptography Hack Lava Lamps”? Basics to Cryptographic Algorithms
What do lava lamps have to do with Physics and cybersecurity? Besides the fact that they are all hot (pun intended), they are all related through Cloudflare. This post was inspired by a friend who asked me this: Recently, lava lamps have taken the Internet by storm through suggesting they were useful to improve the…
Cybersecurity Careers > Cracking Code
Recently, I was at the Singapore Airshow to showcase what my firm offers in terms of cybersecurity solutions contextualised to the aviation market. Being a trade show, I was privileged to have met many different partners and stakeholders who would otherwise communicate with us typically via teleconference calls. Being the first huge trade show I…
CISSP Review: What Does it Take to Pass It?
Being my first cybersecurity management certificate (the CISSP), taking this differs from most of my earlier cybersecurity certifications, which focused around various skills in offensive security (penetration testing, exploit development e.t.c.) To some extent, I had to take this with a different approach — one with a stronger foundation in conceptual knowledge, and to a…
I Want to Get into Cybersecurity. But I Know Nothing. What Should I Do?
Last year, I was interviewed by the Straits Times on the future of work. But I did not predict how many people would ask me about a cybersecurity career in 2023. I was once in this position in 2016, after graduating with a Physics degree. Knowing nothing about cybersecurity, I somehow applied for one such…
Six Tasks for (free) ChatGPT. How Did It Fare?
While the ChatGPT hype might not be so fervent anymore, many of us have internalised ChatGPT’s capabilities into our everyday life. I tried to provide it ten different types of tasks, and have provided some commentary on how we “might” get ChatGPT to work better for us. (In this post we play with the free…