Cybersecurity Pros Name Their Price as Hacker Attacks Swell
bloomberg.com
bloomberg.com
As for the most "needed" areas of Cyber, it comes down to education. Not your bachelors degree, but educating and raising awareness to your business, your IT staff, and even your development teams. It's extremely tricky to measure your return on investment, but almost always it comes down to a lack of knowledge causing one massive hole in the fence, leading to a breach.
No amount of controls will stop someone truly motivated and skilled, so you're better off raising the fence a bit higher and hoping that it deters the truly malicious.
Disclosure: I run Vulnerability Management and Assessments globally for one of the largest companies in the world, so my answer may be a bit bias :)
Correct me if I'm wrong, but If there's no holes in the application/web stack to be exploited, then there's no getting in. Right? It's not about hacker/pirate skill. It's about whether or not the target has plugged all their holes or not.
Right. But there's a saying. "Nothing in unhackable". There in lies the problem. If you can build an unhackable system you literally can get whatever salary you want. If you can convince someone that such a thing is possible. But I'm pretty sure that'd count as fraud.
They both will never exist with the proper 'adversary'.
Does it have to be useful?
On a more serious note, similarly to being able to break RSA in ‘little’ time, having that kind of skill would not result in financial wealth but a huge risk to your physical and mental/emotional well-being. Imagine who would come knocking on your door (assuming they won’t straight out abduct you), and trying to tell them no.
It may be possible to write a software component that is not vulnerable to exploits, but any non-trivial system built of many components will almost certainly be exploitable.
As much as people say they value security, they also value delivery of working software.
Additionally, as others have said, no system is invulnerable from the CIA, NSA, KGB, etc. Someone knows the passwords (or where the passwords are stored) for your system. They may be vulnerable to bribery, blackmail, torture, etc.
All your software vendors?
How likely are you to get malware on an employee laptop?
Phish employee credentials?
Have somebody sneak into your office late at night and install keyloggers on everyone's keyboards?
Kidnap an employee's family and blackmail them into giving you access?
Go through your recruiting pipeline and join as an employee with the motive to steal your data?
Get two people to do the same and bypass peer review controls?
Of course those are getting outlandish and unlikely, but that depends how "motivated and skilled" your attacker is.
Not sure where OP was coming from. It’s virtually impossible to protect yourself against a dedicated advanced persistent threat group.
If we want to be pragmatic about the discussion, then it’s all about your threat model. In that sense, OP is right. If you’re a mom and pop shop selling a catalog of hardware, your LAMP stack isn’t going to face the same scrutiny as a “GooFacePayZon”. According to how he defines his threat model, he can call himself ‘secure’.
Are you secure if your admin's child is kidnapped and the ransom demand is for network access? Are you secure from the Secret Police wanting to hijack your service for their purposes?
Once you accept you CAN'T stop truly all attacks you can be comfortable with acceptable risk and work to mitigate realistic risks.
So unless you advocate for no secured data, you are vulnerable to a sufficiently sophisticated attack (I.e. hypnodrones hijack your mind)
Can’t remember how I did it but my former coworkers still tell stories about it. Lol.
Similarly if a ship is unsinkable the passengers will never drown. Easier said than done.
Or if they're not SuperMicro, then you'll buy hardware with a https://en.wikipedia.org/wiki/The_Thing_(listening_device) in it
Then there are the security holes that exist and are known about by select groups which they sit on and use for big plays...
https://gallery.technet.microsoft.com/Cloud-Red-Teaming-b837...
This is rice's theorem.
More practically, you can simply assume that for an arbitrary program of 'reasonable size' with a moving codebase there are effectively infinite exploitable vulnerabilities.
The bar can be raised quite high.
You're not exactly wrong, but you're assuming something that's impossible. How do you know where all the holes are? You (I'm using the generic you here, as though speaking to a CIO) cannot even inventory all the net-connected software and hardware you own, and even if you could the list would be out of date in 24 hours. But let's say you had that fictional inventory. How do you find its vulnerabilities? You might be able to design an automated process to look at your source code and match against the CVE database. Whoops! You don't have source code for most of your resources because they're proprietary and came from outside vendors. So maybe you look at object code. There are tools that do that. Whoops! A lot of the code is in ROM and you cannot extract it. Even if you could extract all your object code and analyze it against CVEs (which you can't), that's only going to catch known vulnerabilities. What about the unknown ones?
Oh and now we have to talk about all the stuff that's not net-connected which is vulnerable to employees plugging in USB drives...
So no, you can't know where all the holes are so there's no way to patch them all. This doesn't mean security is impossible. It just means there's no such thing as perfect security and there are no magic bullets. Security is a necessary, expensive, and mostly boring part of any company's day-to-day business operations, like, say, accounting and the legal department. But that's not quite right, because most of your employees probably don't need to know much about accounting or the law. But they do need to understand the basics of safe computer use, so ongoing training should be a fat budget line item.
Anyway security is a process, not a thing you can just buy a little of from a vendor. You ignore the security process at your peril.
An asset could be ephemeral cloud infrastructure, an uncompiled piece of code, an API endpoint, a server, a compiled application, a third party vendor, a group of microservices, a fax machine, an employee, a filing cabinet with sensitive information, a virtually defined CI/CD pipeline, and a million other things. At what point do you cross line from paranoia to proper asset inventory, tracking, triaging, remediation, etc. How do you find commonality between all of these devices, critical infrastructure, and data?
Bonus points of trickiness, how do you manage inventory when it changes constantly like cloud, like a third party, a web app, etc. Things like certificate management get extremely dicey. Where do you cross the line between data management, asset management, etc. It's currently the most open area of IT and Cyber that there is, and no one, in my opinion, has a grip on it.
We'll be building it at: https://secquity.com or if anyone has any specific questions, feel free to reach out at info@secquity.com
HIPPA Compliance Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc quam urna, dignissim nec auctor in, mattis vitae leo.
GDPR Compliance Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc quam urna, dignissim nec auctor in, mattis vitae leo.
PCI Compliance Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc quam urna, dignissim nec auctor in, mattis vitae leo.
In the 90s I used the word to describe an instant messenger version of "phone sex" and I haven't been able to take anyone that uses the term seriously after that, but I never really took the goverment or academia seriously to begin with.
“Information security” is too broad as it covers more than technological systems—sensitive information often exists on paper, for example.
A close plain English name would probably be something like “information systems security” and I have heard some people use that, but it’s kind of a mouthful.
I guess I wonder why people get so upset and offended by the word cyber. Sure it’s a made up word, but all words are made up. IMO a lot of the resistance to using it comes down to weird cultural signaling like “I’m too smart or informed to use this dumb word.” It’s just a word, and even people who complain about it know what it means.
While I absolutely agree that it's a pointless discussion, I don't believe it's completely insignificant.
This is where 'cyber' comes from. It's not "stupid".
Think of it like front end web development in the 90s. Webmasters ended up with a lot of independence and cash, because the company had to get on the information superhighway.
Language fires the imagination. This is mostly a good thing. Sometimes it's also stupid, but not necessarily bad for it.
> No amount of controls will stop someone truly motivated and skilled, so you're better off raising the fence a bit higher and hoping that it deters the truly malicious.
I also want to second this. As angering as this statement is its entirely true. You cannot stop someone forever. You can just increase the difficulty of their tasks to beyond a reasonable or obtainable threshold. A "secure" network with ineffective monitoring can quickly become worse than a terribly insecure network that is tirelessly monitored. Complacency is a killer.
[0]: https://youtu.be/Civy151wAH4
(sorry, youtube and B-movie but hey... analogy!)
StatiDyn - Stability in Motion
Marshaling the latest innovations in AI, ML and self-driving infrastructure, we protect your company with time-tested compromise-free MIL-SPEC IT solutions!
60000% more secure than Palantir, 134% more secure than AWS Government Cloud, according to "Fair and Balanced" independent testing.
Free yourself from the Cloud! Guaranteed physical isolation of mission-critical assets; armed guards 24/7 in front of your dedicated StatiDyn Security Cell; biometric six-factor authentication using the Gillette's Razor™ protocol.
...one could go on but angel round first. :-)
The truly interesting bits are on what to investigate/automate, what to report from it - and how.
If you're really good, I recommend to focus your long-term efforts into usability. Security gets a bad rap because far, far, FAR too often increasing security of <something> means reducing that thing's usability. But if you can find a way to improve <something> in a way which makes it more secure and more usable, you can't keep people away.
Fact of life: people gravitate towards convenience.
[0] https://medium.com/netflix-techblog/message-security-layer-a...
That’s definitely not the norm though - security engineers are typically classified the same as an SDE for payroll purposes, and tend to have less negotiating leverage than high level SDEs who build and ship products, except maybe some very rare exceptions. But most companies also don’t have their security engineers actually write shipping code.
I think this article, like every security related article from bloomberg, is pretty much BS.
Also, they use the example of CISO at a large company. CISOs aren’t actually security experts in the vast majority of companies. They’re usually business people or outright frauds, disappointingly. The people who hire and interview them have no way to validate them.
The article makes a case for why CISOs are worth a lot, justifying the cost of a breach. The problem is that CISOs have virtually no impact on whether or not you get breached, and they usually bear no responsibility for it. It doesn’t matter who you pay how much - it isn’t going to affect the outcome much. Alex Stamos is one of the few that actually has any background in security at all, and look what good that did Yahoo and Facebook. Not much. The other problem is CISOs rarely get any actual authority over product, and when they try to flex, they just get pushed out. The ones who survive are simply master politicians who manage their messaging and their image.
The real reason for this article, I suspect, which appears to be primarily sourced from a security recruiting firm, is that they take a cut of every position they fill. It’s very much in their best interest to pump up the value to justify their fees.
Most security money is very poorly spent. I think part of the problem is that hackers are usually bad managers, and tend to be less interested in playing corporate politics. So the manager jobs go to someone else, who has to make decisions they don’t understand. The higher up you go, the more this gets amplified. For every breach you hear about, that company likely has a few competent security folks saying, “see, I told you...”
The people telling you security talent commands a premium are not lying and they're not wrong.
There is a general instinct people have to push back on "look at these high salaries" data points because, not to put too fine a point on it, they're not good negotiators and get second-tier offers. That includes a lot of people with truly extraordinary talent; negotiating skill and delivery skill are, of course, orthogonal. But even that is changing; all you have to do is keep your ear to the ground to know that the standard SFBA SDE salary is not the market clearing rate for (e.g.) software security.
It’s about as difficult to answer that as it is to answer what the market rate is for SDEs. They vary wildly. Like hundreds of thousands in variation. And even the same role at the same level varies wildly depending on negotiated initial offer and performance bonuses/discretionary equity grants. Facebook in particular gave out $1M in DE to their top performing SDEs, even at lower pay grades.
Also, appsec tends to be distinct from IT security (who tend to be classified as IT/SRE/Ops or similar), and often outside of the CISO/CSO scope, but not always.
I have first hand experience at SFBA tech companies, and if you don’t think they are overwhelmingly classifying them the same as SDEs, you’re simply wrong. You haven’t worked inside of one, so that alone is likely going to limit your understanding quite a bit.
This has nothing to do with my own salary either (and I have received an offer from netflix, not that it means anything).
It's fine if we just agree to disagree; I just can't let the claim you made stand without rebuttal.
Might not be the case everywhere but was certainty the norm in the consulting world.
We talked pretty openly about salary. Also, managers, or anyone involved in setting pay, had a spreadsheet of all the engineers salaries for level setting purposes.
I work at an SF company and routinely field offers from other companies that I can view on levels.fyi, and my colleagues in eng are open with me about their salaries so I have lots of datapoints to compare to.
To your other comment:
> I seriously question whether you understand how mediocre the mean security engineer actually is, even at top tier companies
This seems equally true for eng.
"security" seems to be a very wide notion. Can you give some highlights of what that specific skillset is and what is your job actually consists of.
I can say that the trend at companies that pay well is that you will be able to pass an eng interview. More and more, it'll basically be "we expect you to be as good as an eng around your level, maybe one level less" and "we also expect you to be an expert at threat modeling", plus whatever is specific to your niche; for me it's detection and response, so I'm expected to understand operating system services, how attackers go about taking over a computer, the traces they leave behind, etc.
I was a CSO at a large technical company and we were successful in separating the role of Security Engineer from regular Engineer with HR.
With regard to corporate politics, you have hit on an interesting aspect of the problem. Why is it that politics should trump the actions taken to prevent breaches?
The CSO/CISOs that I know all have this stress of knowing what the risks are and the difficulty of moving the organization, incrementally, towards a safer posture. Successful ones know how to navigate whatever the culture is and somehow produce a solution.
The underlying causes of breaches really come down to 1. the corporate culture, 2. the technical competence of the organization, top to bottom, and 3. the strength of the security team. If the security team up through the CSO is very good and the culture is not so good (recent breaches will give you names), or the technical competence of the company is low (e.g., putting a breach response site on the internet disconnected from your root domain), then the effectiveness of the CSO is not very good.
There is a fundamental tension between spewing off features to win market share and producing quality, secure software.
A wise company will find a CSO who can help move the culture and influence the technical practices. Those folks are very rare, and as such will have very high pay.
But there is a massive shortage in motivated experts that ensure packages are up to date and fluent enough in code spelunking to ensure the app isn't trusting user input or allowing privilege escalation.
There's also a shortage in technology leaders willing to spend money on the mundane aspect of security. It requires regular work, not compliance effort and periodic audits/pentests that check off boxes.
I disagree, I see a number of large corporations starting to standardize either 1) their entire development stack from IDE all the way to how the code is deploy 2) Reengineering entire languages to have one language be used e.g Quartz at BofA 3) at the very least, companies are starting to standardize their middleware stacks, to at least avoid the configuration related issues of having a development team managing that.
While I do agree, that the complexity of third party libraries has exploded and is increasingly difficult to manage, I'd say companies are well on their way to standardizing that, with tools like Nexus, SonaType, Blackduck, etc.
We're obviously a long ways away from being even 75% effective across the board, but to say nobody is managing the complexity is a bit short sighted :)
My current job in a nutshell.
It's like handling children (No, you can't add a new technology because you want something fancy on your resume)
People still run Windows XP because there’s a piece of software that never got updated to run on Windows 7, much less Windows 10.
There’s those Java apps that are stuck on Java 6. Websites that still need IE6. Things that use the unsafe versions of stuff like HTTPS...because Visual Basic 6 doesn’t support them out of the box.
But it still works. So it keeps going.
It feels like some people are actively applying the (historical?) Wordpress security model to Kubernetes for expediency.
Then every time we finish building a new publicly accessible system we send it off to "the security company" to pen test it. I am always very jealous about this.
Besides that, there are a ton of great online courses such as PWK/OSCP, and labs (HacktheBox).
If you want to be in the serious end, which doesn't necessarily pay more than any other software job but can be really interesting work, I would suggest learning about anti-virus and similar attacks (there are books and tutorials) and generally making your server software game as strong as possible. Then get a job with a security company at whatever level and bust your ass looking for challenges. You can rise very quickly if you can move the dial for the customers, and "smart and gets things done" plus "gives a shit about security" is a rarer combination than you'd think.
The service part, e.g. your pen-test company, is going to be much more mercenary. Great experience if you can get it, and probably a good space to start your own company in, but of very limited value in the big world. Security companies will have huge annual contracts, pen-testers and the like will be called in occasionally to check off a box on a security audit. Either one can work for you, but it's best to know what you're getting into.
The fake end of course is companies promising something they won't actually deliver, or will deliver with gross violations of ethics and/or the law. Obviously avoid these as best you can -- for the more serious companies, having your name associated with "SEO" or other spammers can permanently blacklist you from employment at least in the US, obviously the dodgier the play the greater risk of blacklisting. Hiring managers worth their salt have a nose for this, since Ethics is way more important than Skillz for any serious security job.
In case the black-hat part isn't obvious: in many places word gets around if a talented hacker is interested in security. Mafia is mafia even for us nerds. If something sounds suspicious, I strongly suggest you don't take the meeting. (This may be less of an issue in the US.)
Best of luck to you! The world needs more smart people working for a safer Internet!
There's a lot of not-security work to be done in the security industry, and it's not all work that gives you security-specific experience. I like to think I'm good at what I do, but it's not security, even though it's to help security people.
This is because many of us have very specific domain knowledge which probably doesn't map to a layperson's expectation of "security expert" -- and while I don't see much "Impostor Syndrome" I would assert that most branches of Security will humble you if you really know your shit, so a great indicator of someone who doesn't is their readiness to claim broad expertise.
Yes, most of the work in "security" is just "software engineering" -- but my own experience has been that for people who care about the security angle, plenty of domain knowledge accrues over time. You might not even realize how much you have, but others do: for me there is a huge difference between working with an ops person who has internalized the adversarial worldview of Security and one who is "just a sysadmin."
If you're in bug hunting, do it in leisure time. it takes lot of time, patience and can't pay bills always. OWASP u can do as additional not as primary.
Easiest way i think to enter in security with guarantee to pay bills is via networking domain.
ICs at FAANG get FAANG-level comp. Consultants gladly take dumb money's budget.
"Cybersecurity Pros" get the standard NDA and noncompete.
Until there's a breach.
https://arstechnica.com/information-technology/2017/10/a-ser...
And when that is the problem you have to deal with, it's more about executive buy in and management than it's about any sort of security expertise, and that seems fairly difficult to do at most companies with really large systemic security culture issues such as that.
They deserve what they get. If you underfund critical parts of your infrastructure that you don't even realize are critical, what do you expect? Pay for talent. End of story.
I would imagine most sites on the internet could be exploited by someone targeted and ultimately relying on the fact that their data/site isn't valuable enough to attack in the first place.
- Health experts
- Education specialists
- Productivity gurus
- Security specialists
Everyone wants to do security but no one knows what security means so they just cut a fat check and pretend like it is working.
Unless you're doing software for airplanes, ain't noone formally proofing anything being done.
I don't usually write proofs at work but I do work with formal models of critical sections in our systems.
Although on the side I am working on bootstrapping Lean's ecosystem so we can write more proof-carrying code in more places.
The world of info sec is so massive that saying you are a expert in 'Security' is useless.
I would like this job. Please post the job link ;)
A lot of their job is protecting the company from lawsuits, usually because someone somewhere did something dumb.
Source: worked closely with a corporate controller for many years.
That could be backend development, but even then there's different languages and tools: MongoDB, MSSQL, Oracle. Even the server languages can differ vastly: Java, .NET Core, Python, Ruby, that list goes on.
Add "full stack" to that list and now it could include desktop software (Windows forms, WPF, etc), javascript frameworks, or mobile platforms (which can include swift, C, java, or some of the cross platform frameworks).
Sure, all these skills are in demand, but good companies will explain what their interpretation of "Software developer" means in the job description.
Then you, an expert in a few of those languages, will pick and choose what jobs to apply for. I don't see why the security field has to be any different.
> Nationally, there were 301,873 cybersecurity job openings in the private and public sectors during the 12-month period between April 2017 and March 2018. This included 13,610 openings in the public sector.
The numbers don’t always reflect how many positions they actually have the budget for, or whether they’re willing to pay a realistic rate.
Arguably, if they were willing to pay market rates there couldn’t be any vacancies, because supply and demand.
In introductory economics, it's just two lines crossing somewhere. In reality though, companies still have to make a buck, so there is a definite limit on how much a company can pay a "security professional" and still be profitable.
And worse, if we are talking about a labor shortage across an industry or country, price doesn't really come into it at all. Price is only a competitive factor, it doesn't create or destroy individual developers. If one employer "scoops" an employee for a higher price, the shortage moves to where he just left.
Sucking in talent from other industries or countries also has its limits. And on top of all of that there seems to be some anti-competitive effects preventing wage-wars.
If there is enough law enforcement and enough self-protections by civilians (companies), criminals should get demotivated and the overall level of activity should die down, just like "real" crime. We're far from that though.
I'd love to hear/learn about someone's experiences if it exists.
If you are interested in learning more about SynAck and it's model shoot me an email: i@willcode.it I can try and setup some contacts from their side that are working full time on platforms like it
I would caution anyone thinking about this to do it as a side hustle for at least six months if not a year to test the waters, understand the subculture a bit, and take a few rounds on the roller coaster.
I would say only 10-15% of our reports were from folks in the USA and I don't recall any being full time. The dedicated folks were mostly from eastern europe and middle east...i'm guessing that has changed a bit over the past few years.
Not a lot of hackers care about Android app security so there's barely any hackers participating and little competition. Most apps have never had anybody do a security review.
Additionally the scope of the program is so wide that you can look through hundreds of apps from companies that have no security posture at all. Finding bugs is easy and payouts are more than generous.
...which might still be 0.2x of an average Google salary in Mountain View, as noted above.
The fact that you even mention "home country" pretty much requires that you give us specifics if you want us to take the claim seriously.
Misleading reporting. The whole stock market went down since then, and banks particularly so.
Most of my fellow students simply decided to go into this field because of the high monetary compensation and expect salaries starting from 60k€ upwards with a Bachelors.
> Compliance.