ISACA International President: The Power of Convenience

Convenience is a great motivator. The search for greater conveniences for businesses and consumers has created game-changing paradigm shifts. ATMs, online banking, movie streaming and even household appliances all transformed businesses. They opened up completely new markets, and at the same time, marked the end for businesses that didn’t innovate.

But each convenience, and each new service and technology comes with new, often uncharted risks. Mobile payments are no exception. The global mobile payment transaction market, including solutions offered by Apple Pay, Google Wallet, PayPal and Venmo, will be worth an estimated US $2.8 trillion by 2020, according to Future Market Insights.

These expectations are impressive and indicate that this is an area of potential growth and worth further exploration. A recent ISACA survey of more than 900 member security professional shows that an overwhelming majority (87%) expect to see an increase in mobile payment data breaches over the next 12 months, yet 42% of respondents have still used this payment method in 2015. The 2015 Mobile Payment Security Study suggests that people who use mobile payments are unlikely to be deterred by security concerns.

Other data from the survey show that cybersecurity professionals are willing to balance benefits with perceived security risks of mobile payments:

  • Only 23% believe that mobile payments are secure in keeping personal information safe.
  • Nearly half (47%) say mobile payments are not secure and 30% are unsure.
  • At 89%, cash was deemed the most secure payment method, but only 9% prefer to use it.

ISACA survey respondents also ranked the major vulnerabilities associated with mobile payments:

  1. Use of public WiFi (26%)
  2. Lost or stolen devices (21%)
  3. Phishing/shmishing (phishing attacks via text messages) (18%)
  4. Weak passwords (13%)
  5. User error (7%)
  6. There are no security vulnerabilities (0.3%)

According to those surveyed, currently the most effective way to make mobile payments more secure is using two ways to authenticate their identity (66%), followed by requiring a short-term authentication code (18%). Far less popular was an option that puts the onus on the consumer—installing phone-based security apps (9%).

All people using mobile payments need to educate themselves so they are making informed choices. You need to know your options, choose an acceptable level of risk, and put a value on your personal information. From my experience, the best tactic is awareness. Embrace and educate about new services and technologies.

Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC
ISACA International President

[ISACA Now Blog]

The Grapes of Career Path—Why Computer Science Graduates Need Cyber Certifications

“Why don’t you go on west to California? There’s work there, and it never gets cold. Why, you can reach out anywhere and pick an orange. Why, there’s always some kind of crop to work in. Why don’t you go there?”

John Steinbeck, “The Grapes of Wrath”

I am one of the lucky ones. After a few twists and turns along the way, I landed a great job in my chosen discipline (cybersecurity)—the field I spent four years of my life studying. Like many recent college graduates, however, I entered the workforce unwittingly unprepared. What I did not realize then is that a college degree was the barest minimum requirement—it was only a ticket to get me inside a hiring manager’s office. When I graduated Stevenson University with my Bachelor of Science degree in Computer Information Systems, I lacked something that cybersecurity mangers place a great deal of emphasis upon: a certification.

Today’s college students are inundated with articles that promise lucrative careers in IT, cybersecurity, and the tech sector. The seemingly wide-open job market, combined with our generation’s affinity for computers and the Internet, makes a computer science degree seem like a logical choice. Many students however, forget to read the fine print . Like Steinbeck’s Dust Bowl tenant farmers, who arrived in California’s Promised Land only to discover a near-hopeless situation, today’s entry-level graduates are smacked with the reality that most tech jobs require several years of experience and certifications.

For some, the best way to earn valuable experience is through a paid (or unpaid) internship at a tech company. It is true that stellar performance at an internship could ultimately lead to a full-time, salaried position. There is another way, however, for savvy job-seeking professionals to overcome some of their relative inexperience; they can earn certifications in their specialized field. Unlike the knowledge gained via college degree, which atrophies over time, cybersecurity certifications show potential employers that a candidate’s skills are current and, most importantly, relevant to the advertised job position.

Most of today’s cybersecurity certifications are designed to reflect current operational realities in the tech world. In particular, ISACA’s recently released CSX Practitioner certification requires candidates to demonstrate more than mere knowledge of advanced cybersecurity concepts; this new certification tests how candidates apply their knowledge and skills against an actual network. This means that a college graduate—who earns the CSX Practitioner certification—can level the playing field by demonstrating the same level of cybersecurity and network proficiency as a more experienced professional.

At first glance, my advice to entry-level graduates might seem unreasonable. Many graduates are already struggling with record levels of student loan debt; for them, the cost of cybersecurity certifications can be overwhelming. However, some federal and state-level programs in the US and similar programs around the world offer grants that cover the cost of cybersecurity certification trainingand testing. Joining an organization such as ISACA can provide reduced fees for cybersecurity certification and training. An added benefit to joining certification organizations is for young job seekers to network more effectively and to become a part of the cybersecurity discussion. ISACA’s local chapters frequently offer announcements for job openings on their respective websites.

Every day, I watch my company’s tech recruiters send out email after email looking for qualified candidates to place in cybersecurity job openings. The job descriptions all have one thing in common: they require some form of cyber certification and/or experience. For recent college grads, the path to cyber employment is not printed on a handbill, and, it does not necessarily lead to Silicon Valley. Nevertheless, earning a cybersecurity certification could make the road to a rewarding career far shorter and straighter.

Adeline Heuchan
Digital Forensics Instructor at TeleCommunication Systems, Inc.

[ISACA Now Blog]

English
Exit mobile version