Cybersecurity Canon Review: “Exponential Organizations”

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

 

Executive Summary

Exponential Organizations is not a must-read for all cybersecurity professionals. You do not need the information in this book to do your day-to-day cybersecurity job today, and I am not recommending it as a Cybersecurity Canon candidate. However, it is a must-read for business leaders as a roadmap for what we all might be facing in the next 10 to 15 years. The authors describe how some future-thinking companies are taking advantage of an information-processing-capability phenomenon whereby the number of calculations per second, per $1,000 has been doubling since the early 1900s. This phenomenon of doubling compute power has manifested exponentially in such research areas as artificial intelligence, robotics, biotech, nanotech, medicine, neuroscience, energy, and computing. All of these technologies have been doubling in price-performance every couple of years.

This kind of rapid growth is changing the standard business problem of managing and selling scarcity, like oil, to managing and selling abundance, like energy. The implications are staggering both in terms of how the world will change and in terms of what future businesses will look like. This book is about how organizations are already taking advantage of this notion of “exponential organizations” and how you might evolve your current organization into this new framework.

 

Introduction

In 2014, Jeremiah Owyang, a founding partner at Kaleido Insights, noticed that a number of companies had emerged across multiple verticals that were completely disrupting the marketplace. These companies, like Airbnb and Uber, were outperforming the competition by a factor of four or more by staying small and flat but leveraging the information provided by their customer base. In other words, they were destroying their competition by operating counter to what every other business in the world was doing. Owyang coined this phenomenon the “collaborative economy.” [1] In that same year, Ismail, Malone, and Geest published this book, Exponential Organizations, which characterizes the kinds of companies that have had success with this new way of thinking. [2]

In Exponential Organizations, the authors describe how some future-thinking companies are taking advantage of an information-processing-capability phenomenon that has been noticed by the likes of Gordon Moore, Intel’s founder, and famous futurist Ray Kurzweil. Moore predicted in 1965 that the number of components on integrated circuits would double every year. [3] Kurzweil went further back and noticed the same doubling pattern as far back as the early 1900s. [4] Kurzweil came up with an interesting metric to track the behavior: what is the number of calculations per second, per $1,000. In 1900, with Charles Babbage’s mechanical Analytical Engine, the number of calculations was extremely small at 0.000005821. [4] But every five to ten years, that numbered doubled. By 1949, the number was 1.837, and we were off to the races. By 1977, the number was 26,870. By 1998, the last year in the study, the number was 133,300,000. [4]

This phenomenon of doubling compute power has manifested exponentially in such research areas as artificial intelligence, robotics, biotech, nanotech, medicine, neuroscience, energy, and computing. All of these technologies have been doubling in price-performance every couple of years. What the authors of Exponential Organizations say is that this kind of rapid growth is changing the standard business problem of managing and selling scarcity, like oil, to managing and selling abundance, like energy. [5] For example, they predict that within 10 years, because of this exponential doubling in the renewable energy space alone, there will be enough solar power available to produce five times what is needed in the world today. Energy will become essentially free and entrepreneurs in those markets will have to figure out how to profit in a new environment where the value of the “thing” is essentially zero.

The implications are staggering both in terms of how the world will change and in terms of what future businesses will look like. This book is about how organizations are already taking advantage of this notion “exponential organizations” and how you might evolve your current organization into this new framework.

 

Body

Ismail, Malone, and van Geest define the key attribute of an exponential organization as “a minimum 10x improvement in output over four to five years.” [2] That is a metric that is easy to detect, and the authors describe how the organizations that attain those metrics are different from the traditional business. One of the authors of Exponential Organizations, Salim Ismail, is the founding executive director of Singularity University, whose mission is to train visionary entrepreneurs to use these exponential ideas to solve some of the world’s intractable problems. [6] He believes that, if you don’t transform your own organization into an exponential organization in the very near future, your competition will start to sprint away from you by leaps and bounds. [2] I have said similar things about the DevOps movement, and I believe that most exponential organizations in the future will have embraced DevOps as the key development strategy to attain their goals. [7]

As the authors point out, most traditional organizations fail to see the doubling effect in their own industries. They project linearly as to what the future will hold. “That is: x amount of work takes y amount of resources, 2x needs 2y, and so on of ever-greater arithmetic magnitude.” [2] But, exponential organizations work by reducing staff and hierarchy and informationally enabling their company. They enlist their customer base and their communities for every aspect of the business. “They float atop the existing infrastructure rather than try to own it.” [2] An x amount of work takes less than y resources but the impact on growth is 2n (exponential). And these are just some of the recognizable companies that have managed to pull this off:

  • Airbnb: 90x more listings per employee
  • GitHub: 109x more repositories per employee
  • Valve: 30x more market cap per employee
  • Tesla: 30x more market cap per employee

Source: [2]

 

The authors note that successful exponential organizations tend to have three key components:  a Massive Transformative Purpose (MTP) statement, some key external attributes of SCALE (staff on demand, community & crowd, algorithms, leveraged assets, and engagement), and some key internal attributes of IDEAS (interfaces, dashboards, experimentation, autonomy, and social).

An MTP is kind of a vision statement, but it has more definition and is way more aspirational. It is not like a mission statement that states what an organization does. The MTP is more about what the organization desires to accomplish. It should be so well-crafted that it starts a cultural movement within the community. Here are some example MTPs of exponential organizations [8]:

  • TED: “Ideas worth spreading.”
  • Google: “Organize the world’s information.”
  • X Prize Foundation: “Bring about radical breakthroughs for the benefit of humanity.”
  • Tesla: “Accelerate the transition to sustainable transportation.”
  • Palo Alto Networks: “To protect our way of life in the digital age by preventing successful cyberattacks.
  • Unit 42 – Palo Alto Networks intelligence team: “Stop bad guys from winning.”

 

Conclusion

Exponential Organizations is not a must-read for all cybersecurity professionals. You do not need the information in this book to do your day-to-day cybersecurity job today. I am not recommending it as a Cybersecurity Canon candidate. However, it is an important book for business leaders as a roadmap for what we all might be facing in the near future, say 10 to 15 years. In other words, how we flip our business away from a scarcity mindset and toward an abundance mindset might very well determine if our organizations survive. How we information-enable our organizations so that we break free of the traditional shackles of linear thinking toward exponential thinking will determine if we remain competitive in the marketplace.

There is one thing to note: transforming into an exponential organization is radical change for most organizations. As the authors points out, change from the status quo is almost immediately attacked by the organization’s immune system – an immune system that will fight any change that deviate from its current path. Organizations that have had success here build black ops teams that operate on the fringe of the organization and which report to the CEO only. This gives the black ops team some breathing room to make things happen without the constant pressure from the organization’s immune system.

That is what happened when Palo Alto Networks helped build the Cyber Threat Alliance: an alliance of security vendors dedicated to sharing adversary playbook intelligence with each other so that our common customers do not have to develop the intelligence themselves. When we began, there were many people within the Palo Alto Networks organization who thought it was nuts to give away our intelligence for free and complete insanity to share it with our greatest competitors. But the CEO gave the mission to a team on the fringe who could operate freely and gave them resources to accomplish the task. Today, the Cyber Threat Alliance is a non-profit company that consists of security vendors who share threat intelligence with each other every day as a best practice.

 

Sources

[1] “The Exponential Enterprise: Your Most Feared Competitor Now Has A Name,” by Giovanni Rodriguez, Forbes, 31 October 2014, last visited 8 May 2018,

https://www.forbes.com/sites/giovannirodriguez/2014/10/31/the-exponential-enterprise-your-most-feared-competitor-now-has-a-name/#15e8bef42b4d

https://www.forbes.com/sites/giovannirodriguez/2014/10/31/the-exponential-enterprise-your-most-feared-competitor-now-has-a-name/#15e8bef42b4d

[2] Exponential Organizations, by Salim Ismail, Michael S. Malone, Yuri van Geest, 14 October 2014, Diversion Books,

https://www.goodreads.com/book/show/22616127-exponential-organizations?from_search=true

[3] “Cramming more components onto integrated circuits,” by Gordon E. Moore, Electronics, Volume 38, Number 6, 19 April 1965, last visited 4 July 2018,

https://drive.google.com/file/d/0By83v5TWkGjvQkpBcXJKT1I1TTA/view

[4] “Exponential Growth in Computing,” by Ray Kurzweil, The Singularity is Near, last visited 8 May 2018,

http://www.singularity.com/charts/page70.html

[5] “Exponential Organizations,” by Salim Ismail, at USI, 9 July 2015, last visited 8 May 2018,

https://www.youtube.com/watch?v=FNQSM4ipZog

[6] “Hi, We’re Singularity University; We prepare you to seize exponential opportunities,” Singularity University, last visited 10 July 2018,

https://su.org/about/

[7] “The Cybersecurity Canon: Site Reliability Engineering: How Google Runs Production Systems,” by Rick Howard, 26 September 2017, last visited 11 July 2018,

https://researchcenter.paloaltonetworks.com/2017/09/cybersecurity-canon-site-reliability-engineering-google-runs-production-systems/

[8] “The Motivating Power of a Massive Transformative Purpose,” by Alison E. Berman, Singularity Hub, 8 November 2008, last visited 11 July 2018,

https://singularityhub.com/2016/11/08/the-motivating-power-of-a-massive-transformative-purpose/#sm.0004irhsuffef1g10hp1eldfklb29

[8] “Analytical Engine: COMPUTER,” by Paul A. Freiberger and Michael R. Swaine, Encyclopedia Britannica, last visited 11 July 2018,

https://www.britannica.com/technology/Analytical-Engine

 

References

 

“How 20-Year-Old Kylie Jenner Built A $900 Million Fortune In Less Than 3 Years,” by Natalie Robehmed, Forbes, 11 July 2018, last visited 11 July 2018,

https://www.forbes.com/sites/forbesdigitalcovers/2018/07/11/how-20-year-old-kylie-jenner-built-a-900-million-fortune-in-less-than-3-years/

 

“What is Moore’s Law?” by Lee Bell, 28 August 2016, last visited 8 May 2018,

http://www.wired.co.uk/article/wired-explains-moores-law

 

“Abundance: The Future Is Better Than You Think,” by Peter H. Diamandis and Steven Kotler, Free Press, 2012, Last Visited  9 May 2018

https://www.goodreads.com/book/show/13187824-abundance?ac=1&from_search=true

 

Exponential Organizations by Salim Ismail,” by Sheldon Nesdale, 21 December 2015, last visited, 8 May 2018,

https://www.marketingfirst.co.nz/2015/12/exponential-organizations-by-salim-ismail-michael-s-malone-yuri-van-geest/

 

“Organizations of the Future,” by Mark Looi, Medium, 9 May 2017, last visited 8 May 2018,

https://medium.com/@marklooi/organizations-of-the-future-8f08caf9f067

 

“Salim Ismail – Exponential Organizations,” USI Blog, 8 December 2015, last visited 8 May 2018,

https://blog.usievents.com/salim-ismail-exponential-organizations/

 

The Singularity is Near: When Humans Transcend Biology, by Ray Kurzweil, Penguin, 2006,

https://www.goodreads.com/book/show/83518.The_Singularity_is_Near?ac=1&from_search=true

[Palo Alto Networks Research Center]

The Cybersecurity Canon – CISO: Desk Reference Guide; A Practical Guide for CISOs Volume 2

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

 

Executive Summary

I recommend “CISO: Desk Reference Guide; A Practical Guide for CISOs volume 2” be included in the Cybersecurity Canon Hall of Fame candidate list alongside its first volume companion. These two books will provide any CISO – newbie or ragged veteran – the reference material to build and improve their security programs. The authors present the essentials and represent the perfect example of what a desk reference guide should be: a collection and starting point for topics that all current and aspiring CISOs should know about. The content may not be the final word on many of these subjects, but it is a fantastic place readers can start to think about their own ideas regarding what the role of a CISO is and will be in the next decade. Where they take that knowledge from there is on them.

 

Introduction

Full disclosure: I have known Gary Hayslip, one of the three authors of this guide, for a number of years. He is a no-nonsense network defender, and his wisdom expressed at the various security conferences we all attend has been, in many cases, the sole reason to go. He brings that same sensibility to volume two of the CISO’s Desk Reference Guide. Gary and his fellow authors, Bill Bonney and Matt Stamper, published volume one back in 2016; and Canon Committee member, Ben Rothke, recommended it as a Cybersecurity Canon Candidate at the end of last year. Rothke said that the book is “an excellent example” of what a desk reference guide should be: a collection and starting point for topics that all current and aspiring CISOs should know about. It may not be the final word on many of these subjects, but it is a fantastic place to start so that readers can begin thinking about and developing their own ideas regarding what the role of a CISO is.

 

Topics Covered

In volume one, they specifically covered these topics:

  • Office of the CISO organization
  • Policy and audit
  • Information classification
  • Third party-risk
  • Metrics
  • Board management
  • Risk management
  • Tools

For this volume, the authors complete the picture by including:

  • Finding talent
  • Cyber awareness training
  • Basic cyber hygiene
  • Monitoring
  • Threat intelligence
  • Continuity planning
  • Incident response
  • Recovery
  • Forensics
  • Strategic planning

 

This is not a book you read cover-to-cover; rather, you have it on your desk to refer to when you need a pointer or two. When I was in the U.S. Army, we called these things our “smart books,” and they contained bits and pieces of knowledge that we learned through the school of hard knocks. The best thing about these volumes is that you have three seasoned professionals giving us their notes so that we don’t have to go through the pain of discovery ourselves.

 

Picking Some Nits

As with any reference book on a topic as complex as this one, there are a few things here that might have used more detail or I felt didn’t explore certain sides of an issue.

In the talent section, the authors rightfully point out that there is a giant shortfall of qualified personnel for the over 2 million open positions in the industry today. Their general suggestions about how to fill your open positions are spot on. I was disappointed that they did not mention the diversity issues also prevalent in our industry. Minorities and women are severely underrepresented, and whatever your strategy is to hire for your team, it had better include a healthy dose of diversity and inclusion.

In the hygiene section, the authors make the case that basic common-sense actions to protect themselves will go a long way in preventing cyber adversaries from being successful. I was disappointed that they did not discuss the recent DevOps or DevSecOps movement, whereby the entire community is moving toward automating these kind of hygiene items.

In the threat intelligence section, the authors do a good job of defining what threat intelligence is; how it is not a one-size fits all; and that you have to build the kind of intelligence your organization needs based on your culture, your senior leadership’s desires, and what you think are the basic intelligence needs for your organization. They lay out the benefits of information sharing and describe a number of potential sharing organizations that any CISO might consider joining. I was pleased to discover a mention of the Palo Alto Networks open source intelligence sharing tool, MineMeld, that organizations can use to connect to one API, collect and reformat information, and redirect it to another API. But I was disappointed that they did not describe the intelligence life cycle. For any intelligence program to be effective, intelligence professionals continuously work their way through a four-stage cycle.

First, they define the CEO/CSO Information Requirements (CIRs). These are the high-level questions the leadership wants the intelligence team to work on. Second, they evaluate their sources of information through the lens of “can the intelligence team answer the CIRs.” If they can, fine. If they can’t, they need to seek additional intelligence sources. Third, they need to transform the raw information into intelligence reports. This is the actionable intelligence that you have heard everybody in our industry talk about. Lastly, they have to deliver those reports to the right customers to take action.

 

Conclusion

Like I said, I’m just picking some nits. I recommend that this book be included in the Cybersecurity Canon Hall of Fame candidate list, along with its first volume companion. These two books, alongside a Hall of Fame winner, “Winning as a CISO,” by Rich Baich, will provide any CISO, newbie or ragged veteran, the reference material to build and improve their security programs. All three books represent a block of material that is a great place to start. The block is not complete by any means. If it were, it would be over a thousand pages long and instantly out-of-date the day the authors published it. To misquote Ferris Bueller, “[Things] moves pretty fast. If you don’t stop and look around once in a while, you could miss it.” But these books present the essentials. Where you from there is on you.

 

References

“The Cybersecurity Canon – CISO Desk Reference Guide: A Practical Guide for CISOs Volume 1,” book review by Ben Rothke, 28 December 2017, last visited 14 March 2018,

https://researchcenter.paloaltonetworks.com/2017/12/cybersecurity-canon-review-ciso-desk-reference-guide-practical-guide-cisos/

 

“Winning as a CISO,” book review by Rick Howard, 12 January 2015, last visited 14 March 2018,

https://researchcenter.paloaltonetworks.com/2015/01/cybersecurity-canon-winning-ciso/

[Palo Alto Networks Research Center]

The Cybersecurity Canon – American Kingpin: The Epic Hunt for the Criminal Mastermind Behind the Silk Road

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

 

Executive Summary

American Kingpin: The Epic Hunt for the Criminal Mastermind Behind the Silk Road doesn’t qualify as a “must read” for all cybersecurity professionals, but it is a very interesting and entertaining book.  American Kingpin is about the rise and fall of the Dread Pirate Roberts (DPR), the criminal head of the notorious, illicit online marketplace, the Silk Road, where drugs, guns, and even human body parts were available for sale anonymously. At a deeper level, however, American Kingpinfollows two stories. First, it tracks Ross Ulbricht, a twenty-something libertarian who created the Silk Road, grew it from a cottage website to a multi-million-dollar illegal marketplace and transformed himself from naïve grad school dropout to criminal overlord DPR.

Additionally, American Kingpin follows the federal investigation, arrest, and conviction of DPR, weaving this thread throughout the entire book. Far from a highly organized federal investigation, the hunt for DPR begins by resembling a keystone cop’s episode as various individuals from different federal law enforcement agencies (DEA, DHS, FBI, IRS, etc.) jump on the case, buy drugs, arrest low-level dealers and drug buyers, and follow leads in pursuit of the Silk Road kingpin. Eventually, these individuals discover each other and cooperate on finding the Dread Pirate Roberts. While their collaboration leads to several dead ends, they eventually put their heads together, piece together all their individual breadcrumbs, and takedown DPR.

American Kingpin is well-researched and written in an easy-to-read style that grabs and holds on to the reader from start to finish. This book is highly entertaining as it exposes the cybercriminal underground and links it to an individual whom no one suspected of being anything other than a misguided young man. Despite not being a Canon candidate, I do highly recommend this book for those cybersecurity professionals interested in cybercrime, law enforcement, and an old-fashioned cops-and-robbers story.

 

Review

Like the last book I reviewed for the Cybersecurity Canon (The Dark Net), American Kingpin, doesn’t really qualify as a “must read” book for all cybersecurity professionals. Admittedly, you won’t enhance your skills or advance your career by reading this book. That said, cybersecurity isn’t about network packets, malicious code, and software vulnerabilities alone. No, cybersecurity also includes some basic philosophical and human issues around the use of technology as good versus evil. There is a fundamental question in what we do: Why do some people use their technical skills to breaking the law while others dedicate their lives to countering these threats?

American Kingpin explores this question by following Ross Ulbricht, a seemingly normal person who came up with the idea to create a website for selling illicit drugs online. Ross could have never imagined that this initial, misguided decision would lead to a multi-million-dollar organized criminal enterprise and an international manhunt. Ross’s relatively innocent website became the infamous Silk Road while Ross himself turned from happy-go-lucky twenty-something to the criminal Dread Pirate Roberts.

One of the things I really liked about American Kingpin is it is a book with two interwoven stories:

  1. The picaresque story of Ross Ulbricht before, during, and after his fateful decision to develop and operate the Silk Road.
  2. The story of a loosely coupled law enforcement posse that discovers and investigates the Silk Road website and the criminals behind it.

These two stories coalesce at the book’s conclusion as Ulbricht is discovered, arrested, tried, and sentenced.

Story #1 opens with young Ross with his family in his hometown of Austin, Texas. Ross seems like an average American kid – good home, boy scout, college graduate, etc. Ross is considered an exceptionally bright kid, albeit a bit quirky and disorganized.

As this story develops, we also learn a bit more about Ross when he enters graduate school. Ulbricht is a free spirit who participates in drum circles, lives a pauper’s existence, and wears the same clothes for days on end. Ross is also somewhat of a partier, drinking and smoking marijuana with close friends.  Despite his outward Bohemian appearance, however, Ross is also highly intelligent and passionate in his opinions. He is especially committed to his politics, maintaining a strong libertarian belief system. At Penn State, he participates in political debates, always arguing that the government has no business getting involved in citizens’ private and personal life choices.

Soon, Ross leaves graduate school and moves back to Austin with his girlfriend. It is during this time frame that Ross rents a low-rent apartment for the express purpose of growing magic mushrooms.  When Ross takes his girlfriend to see his mushroom farm, he tells her that he plans to create a website to sell these illicit goodies online. His timing is not accidental; it coincides with the right technology underpinnings for this type of endeavor: the emergence of Bitcoin, an anonymous crypto-currency and TOR (aka: the onion router), an internet browser and global network infrastructure that anonymizes user and source IP identities.

As a demonstration of Ross’s intelligence and perseverance, Ross teaches himself software coding and launches his new website. He names his website after an ancient network of trade routes that connected the East and West from the Korean peninsula and Japan to the Mediterranean Sea: the Silk Road.

Of course, Ross has no idea whether anyone will even notice the Silk Road, so he takes the time to find related chat sites and post marketing references to the Silk Road to get the word out. Much to his surprise, the site’s popularity grows, and Ross is contacted by others who also want to sell illegal drugs via Silk Road. Over a short time frame, the Silk Road grows exponentially as hundreds of vendors join and use the website as a dark web drug bazaar. Revenue also escalates. Ross can’t believe it when site sales climb into the thousands of dollars per month, but it doesn’t take long before these numbers rise to millions of dollars per month.

Ross realizes that he can’t possibly maintain the Silk Road by himself, so he recruits a group of like-minded participants to help with software development, enhance security, and perform various administrative tasks. As the Silk Road transformed from a mom-and-pop website to an online drug superstore, Ross Ulbricht decided he needed a criminal alias. One of his criminal co-conspirators suggested that he call himself the Dread Pirate Roberts (DPR), a fictional character from the movie, The Princess Bride. In this film, many different people assume the identity of DPR, adding to the intrigue and power of the character. Ross immediately realizes that this model could apply to his role in the Silk Road as well. He could become DPR himself and then pass the identity to others when he decided to move on and return to the real world.

Thus, the Dread Pirate Roberts was born and just like in the movie, the character assumes mythical and sinister reputation – a ruthless pirate who heads an international drug market and rules his kingdom with an iron fist. Henceforth, Ross behaves like a syndicated crime boss, punishing those who get in his way while plotting his eventual getaway when the law catches up with him.

The success of the Silk Road remained hidden until June 2011, when the site was featured in a Gawker blog, labeling the Silk Road as an underground version of Amazon.com. This article effectively put a bull’s-eye on the Silk Road, first with U.S. Senator Chuck Schumer, D-N.Y., and then with the federal law enforcement community.

This brings me to the second thread throughout American Kingpin: the federal investigation that leads authorities to capture and convict DPR. It’s well-known that Ross Ulbricht was arrested in October 2013 and was convicted in 2015, but the details of the federal investigation beyond this were relatively obscure. Nick Belton does a great job researching and describing how the actual investigation played out. Far from the well-organized endgame, in this case, the investigations began when various law enforcement officers in the DEA, DHS, FBI, and IRS learned about the Silk Road and pursued their own separate investigations. This wide-ranging cast of characters used their own methods, followed their own leads, and had no idea that anyone else in federal law enforcement was pursuing a parallel inquiry.

Eventually, these unaffiliated individuals come together as an interdepartmental unit, and each group brings its own puzzle pieces to the overall case. This collaboration eventually leads to a breakthrough, and, while federal law enforcement eventually gets its man, some within the law enforcement community are exposed as profiteers who used the investigation to pad their own pockets. Human triumph and tragedy coalesce.

It is worth noting that, aside from telling two exciting stories, the style of this book is also compelling.  Many cybersecurity books require a reader with patience and perseverance, willing to peruse long chapters chock full of cryptic acronyms and technical details – not American Kingpin. I estimate that the longest chapter in this book is no more than seven pages. This writing style makes the book easy to read and hard to put down. I spent hours on this book and read the whole thing in just over four days.

 

Conclusion

Like the last book I reviewed (The Dark Net), American Kingpin does not meet the Cybersecurity Canon definition of a “must read” book for all cybersecurity professionals. Notwithstanding the Cybersecurity Canon definition, I highly recommend American Kingpin to cybersecurity professionals looking to better understand the culture and tactics of the cybercrime underground, and how law enforcement investigates, pursues, and eventually finds cybercriminals at large. American Kingpin was an extremely entertaining book and a true “page turner.” For those reasons, curious cybersecurity professionals should put this book high on their reading list.

[Palo Alto Networks Research Center] 

The Cybersecurity Canon: The Seventh Sense: Power, Fortune, and Survival in the Age of Networks

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Dr. Mansur Hasib, CISSP, PMP, CPHIMS: The Seventh Sense: Power, Fortune, and Survival in the Age of Networks (2016) by Joshua Cooper Ramo, Little, Brown, and Company: New York.

Executive Summary

Our hyperconnected world, comprised of myriad networks – both machine and human – has brought us to the precipice of a fundamental revolution and redefinition of the human experience and our socio-political and military world order. This is what author Joshua Cooper Ramo wants us to grasp in the book The Seventh Sense: Power, Fortune, and Survival in the Age of Networks.

The Industrial Revolution was a similar event. The advent of the personal computer, which replaced the typewriter, and the subsequent era of enterprise networks were others. Then came the internet era. Now we exist in a mesh of networks, which feature both concentration and distribution, and remarkable levels of persistence and resilience. The old definitions and practices of information security and governance, cybersecurity, and business strategy, developed in the era of the past no longer work.

Failure of executives to grasp this pivotal change, and their concomitant failure to tailor organizational and business strategy to the new reality, is the primary cause of organizational malaise and the massive cybersecurity breaches we have experienced. The author calls for a new breed of digital-native executive leaders who will inherit the problems and need to develop lasting solutions for the future.

We have experienced such revolutions in the past. Each time a new world order was created, decision-making and practices of the old world order ceased to function. Organizations and leaders who practiced outdated thinking were quickly wiped out or reduced to irrelevance. Each new world order also realigned the centers of power.

British imperial power and the subjugation of wide swaths of the world were fueled by superior technology, naval power, and education. Then, when the rest of the world began to innovate for a new era, there was a fundamental realignment of power. Today terrorism, war, cybersecurity, privacy of data, and even human relationships are being redefined by the network.

As the author states, “…networking something fundamentally changes its function.” Executives need to recognize that – yet they are not doing so because they lack the appreciation and understanding of the new networked world order and are still making decisions using models of the past, and both making decisions and developing strategy with the thinking of a bygone era.

Review

I have noticed political and business executives making seriously flawed decisions using models of the past. I have observed them being completely baffled by the hyperconnected new world. The book The Seventh Sense: Power, Fortune, and Survival in the Age of Networks (2016) by Joshua Cooper Ramo helped me understand why. The author helps us understand why we critically need cybersecurity leadership and digital strategy of a new kind.

The book has three parts, which I have broken down for you herein.

Part One explains the nature of the current age. This section explains why hyperconnectivity and the networking of everything, including human relationships, through networks and digital connections needs to be viewed differently. This is similar to recognizing that the world of analog systems and analog networks is gone. Analog thinking is anachronous in a digital world. Similarly, failure to recognize the new hyperconnected era, and failing to adapt to the exigencies of this new world order, can result in existential threats to leaders, organizations, and nations.

Part Two discusses what the author calls “The Seventh Sense,” which is a new way to view everything. Connectivity, as the author states, changes the very nature of everything. Thus, a networked heart monitor or pacemaker cannot be regarded as just a heart monitor or a pacemaker anymore. Similarly, terrorism, crime, pornography, bullying, forensics, and warfare conducted through the digital signals of a global network cannot be dealt with using the knowledge and models of the past. Executives need to think differently.

Humans have developed an intuition for dealing with events and circumstances of the past; some have called this the sixth sense. The author calls upon everyone – especially executives in charge of making consequential decisions – to develop a seventh sense to make strategic decisions relevant for a digitally hyperconnected new world. Business organizations, countries, and societies that fail to adapt to this new world are in real danger of becoming irrelevant.

There are numerous examples of previously powerful business organizations, nations, and societies that dominated in an older world order, but were rendered irrelevant and powerless in a new world – simply because they failed to anticipate, recognize, and adapt as the world around them changed. The author shares examples of such companies as Google and Uber that not only anticipated, embraced, and shaped the new world but were able to find gaps and unfulfilled opportunities, which allowed them to redefine the new world order in a way that benefited them. In doing so, they also became existential threats to organizations that were still living in the old world order.

The author shares how strategic leaders like Steve Jobs were able to imagine the future of smartphones, music consumption, and even movie production in a hyperconnected digital world, while many other contemporary leaders were still dabbling in an analog world. Leaders need to be able to recognize when the playing field has changed. Leaders cannot afford to play chess on a two-dimensional board when the board itself has morphed into multiple dimensions.

They cannot denigrate the new dimensions either – but must embrace them. I still remember the time in the late 1980s and early 1990s when we were building email systems and enterprise networks to replace the mainframes; people in the mainframe world called these systems a passing fad. Today, these very email systems and enterprise networks have become obsolete as new forms of human communications and hyperconnected business networks have become the new normal.

Yet, many enterprise technology organizations and executives have not adapted to the new world and are still focused on perimeter security in a world where there is no perimeter. They wish to control endpoints in a world where these endpoints do not belong to them. These executives are still discussing and demanding security as a static desired state when there is no such thing as absolute security anymore.

Cybersecurity is certainly not synonymous with security. Rather cybersecurity is a process of dynamic, continuous innovation and dynamic, continuous risk management – full of opportunities as well as pitfalls.

Part Three discusses how the power structure is being redefined in this new world. The author details several historical shifts in global power. Control of rivers, water supplies, and other land-based routes determined power during an era. At some point, it was replaced by control of the global waterways. Global naval superiority determined the British dominance of the globe. This was replaced by the rise of American global power through an unprecedented rate of innovation, which led to global domination in air power, military might, and economic strength. Sheer technological and financial superiority powered by an unprecedented pace of innovation unleashed by capitalism replaced all other forms of power.

Today, global power centers are in the process of realignment. A lot of power now resides in knowledge and information, as well as the control and sharing of such knowledge and information. Power will also be determined by the ability to understand and control the protocols and networks used for transmission. In a hyperconnected world, especially with unimaginable amounts of information being fed into the network, false information with rapid dissemination mechanisms can have dramatic consequences. Therefore, Facebook and Twitter have far more consequential relevance in this new world than traditional communication media, such as newspapers and TV.

In such a world, personal and corporate brands, and messaging, can shape people’s beliefs about reality. Once an affiliation with a brand is established, that brand can shape reality through messaging disseminated rapidly using new forms of communications. Failure of leaders to appreciate and harness the power of new forms of communications and develop the strategies, rules, regulations, and even laws that cater to the modern era can have massive implications in determining the winners and losers in the new world order.

Conclusion

The need for executives to think differently and have a digital strategy is acute. Author Joshua Cooper Ramo provides an easy to understand explanation of the new world, along with an analysis of the major epochal shifts we have seen in the past several hundred years.

Personal computers and the network were invented in the United States. In the past, as nations fought for domination of the land, water, air, and space dimensions – since the cost barrier for domination of these dimensions were extremely steep – the economic might of the United States allowed it to quickly overwhelm other nations in these dimensions.

However, global hyperconnectivity has created a completely new dimension, and the cost barrier for entry into this dimension is very low. In addition, the United States has done very little to restrict global open access into its systems. Readily available, low-cost access to technology has democratized the power of communications, influence, and even warfare into the hands of individuals. Therefore, a small band of malicious actors can cause massive damage on a global scale. Most often, their acts are not even regarded as acts of war. While international treaties related to conventional or even nuclear and chemical weapons exist, such treaties related to cyberweapons are non-existent.

In the past, in order to influence political outcomes in foreign countries or expand global power, nations had to fight wars, conduct espionage, and even resort to assassinations. Now, such actions can take a different form. Character assassinations through negative ads (frequently with no basis in fact), and false stories as well as pictures and videos are just as effective as actual assassinations – sometimes more so.

Information war and cyberwarfare are also incredibly cheap. Since laws and international agreements in these new areas are non-existent, foreign nations can influence political outcomes in countries as powerful as the United States or France without even being accused of warfare or crime. They do not have to use bombs to blow up communication systems, roads, or bridges; they can target networks controlling information media, or the networks controlling the national critical infrastructure, and exact far more consequential damage without the expense, stigma, or loss of lives created by conventional warfare.

Large swaths of people and even politicians and governments do not even view such actions as acts of war. Clouded by the thinking of the past, they use mild terms, such as “meddling” or “interference.” Even the active participation of a political campaign to support or benefit from foreign acts of cyberwarfare is viewed mildly and accepted by many as “opposition research.” If the same actions had taken place in a different dimension, such as a land attack, a sea attack, or an air attack, the language used would have been completely different.

Information-based decision-making at both the personal and organizational level is no longer possible using decision-making models of the past. Most of these models are not capable of differentiating between true and fake information. Decisions based on fake information will be seriously flawed.

Whether we call it The Seventh Sense or a new industrial revolution, or a completely new epoch, the old world is gone – and will never return. Executives who recognize, embrace, adapt, and rapidly develop a strategy to address this new world will leap ahead in the future power structure of this new world order. Joshua Cooper Ramo’s book The Seventh Sense: Power, Fortune, and Survival in the Age of Networks is a Cybersecurity Canon nominee for providing us a succinct and convincing analysis of a new world order that we all must understand in order to survive and thrive in it.

[Palo Alto Networks Research Center]

The Cybersecurity Canon: How to Measure Anything in Cybersecurity Risk

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Steve Winterfeld: How to Measure Anything in Cybersecurity Risk (2016) by Douglas W. Hubbard and Richard Seiersen

Executive Summary

How to Measure Anything in Cybersecurity Risk is a book that reads like a college statistics textbook (but the good kind you highlight a lot). It is a book anyone who is responsible for measuring risk, developing metrics, or determining return on investment should read. It is grounded in classic quantitative analysis methodologies and provides a good balance of background and practical examples. This book belongs in the Cybersecurity Canon under Governance Risk and Compliance (GRC).

Review

As I said, this book reads like an education in quantitative modeling and how to apply the methodology to cybersecurity. It truly challenges the current common practices in use to develop expert opinion-based risk frameworks. Here is a snippet from the book:

“So let’s be clear about our position on current methods: They are a failure. They do not work. A thorough investigation of the research on these methods and decision-making methods in general indicates the following: There is no evidence that the types of scoring and risk matrix methods widely used in cybersecurity improve judgment. On the contrary, there is evidence these methods add noise and error to the judgment process. Any appearance of “working” is probably a type of “analysis placebo.” That is, a method may make you feel better even though the activity provides no measurable improvement in estimating risks (or even adds error). There is overwhelming evidence in published research that quantitative, probabilistic methods are effective. Fortunately, most cybersecurity experts seem willing and able to adopt better quantitative solutions. But common misconceptions held by some—including misconceptions about basic statistics—create some obstacles for adopting better methods. How cybersecurity assesses risk, and how it determines how much it reduces risk, are the basis for determining where cybersecurity needs to prioritize the use of resources. And if this method is broken—or even just leaves room for significant improvement—then that is the highest-priority problem for cybersecurity to tackle!”

The authors lay out the book in three sections:

  • Part I sets the stage for reasoning about uncertainty in security. It outlines terms on things like security, uncertainty, measurement and risk management. Plus, it argues against toxic misunderstandings of these terms and why we need a better approach to measuring cybersecurity risk and, for that matter, measuring the performance of cybersecurity risk analysis itself. Finally, it introduces a simple quantitative method that could serve as a starting point for anyone, no matter how averse the person may be to complexity.
  • Part II delves further into evolutionary steps we can take with a simple quantitative model. It explains how to add further complexity to a model and how to use even minimal amounts of data to improve those models.
  • Part III describes what is needed to implement these methods in the organization. It addresses the implications of this book for the entire cybersecurity “ecosystem,” including standards organizations and vendors.

The cybersecurity community suffers from not having standard evaluation metrics, like earnings before interest, taxes, depreciation and amortization (EBITDA). The authors try to bring some discipline to terms by offering standard definitions coming from the quantitative analytics field. From the book:

  • Definitions for Uncertainty and Risk, and Their Measurements Uncertainty: The lack of complete certainty, that is, the existence of more than one possibility. The “true” outcome/state/ result/value is not known. Measurement of Uncertainty: A set of probabilities assigned to a set of possibilities. For example: “There is a 20% chance we will have a data breach sometime in the next five years.” Risk: A state of uncertainty where some of the possibilities involve a loss, catastrophe, or other undesirable outcome. Measurement of Risk: A set of possibilities, each with quantified probabilities and quantified losses. For example: “We believe there is a 10% chance that a data breach will result in a legal liability exceeding $10 million.”

They also walk the reader through established methodologies like: Monte Carlo simulations, Bayesian interpretation, risk matrix, loss exceedance curve, heat maps, chain rule tree, beta distribution changes, regression model predations, analytics maturity mode, power law distribution, subjective probability, calibration, dimensional modeling, expected opportunity loss, bunch of guys sitting around talking, expected value of prefect information, NIST and ISO. They explain how, in Excel, so they are truly practical. They also lay out survey results from attitudes toward quantitative methods, global information security workforce study, and stats literacy and acceptance studies.

This work follows other work like Factor Analysis of Information Risk (FAIR) which is a well-recognized value at risk (VaR) framework. They outline another Monte Carlo–based methodology and tools like those developed by Jack Jones and Jack Freund. Another similar work is The Wisdom of Crowds by James Surowiecki.

Finally the book has some great online resources. You can find eight sample downloads of the methods explained, as well as webinar/blog info.

Conclusion

How to Measure Anything in Cybersecurity Risk is an extension of Hubbard’s successful first book, How to Measure Anything: Finding the Value of “Intangibles” in Business. It lays out why statistical models beat expertise every time. It is a book anyone who is responsible for measuring risk, developing metrics, or determining return on investment should read. It provides a strong foundation in qualitative analytics with practical application guidance.

Bottom line: The authors lay out a solid case for why other industries with the similar challenges of lack of quantifiable, standardized or historical actuarial table-like data are able to use classic statistical modeling and methodologies to measure risk in a qualified, repeatable way. Definitely worth considering.

[Palo Alto Networks Research Center]

English
Exit mobile version