The CSIRT methodology

The CSIRT methodology

If you have read my blog carefully, the article about the C4ISR Methodology will surely stick in your mind. Many of the military procedures we can take for our plan – to build a functioning SOC / CSIRT / forensics team of course with some changes. Let’s define the necessary elements: SOC (according to English Wikipedia, italic: according to my methodology) A Security Operations Center (SOC) is a central unit that deals with security issues at the organizational and technical levels. […]

C⁴ISR: What we can learn from the military

C⁴ISR: What we can learn from the military

C⁴ISR stands for command and control, communications, computers, intelligence, surveillance, and reconnaissance. Since 2005 I have been building or reorganizing SOC’s (Security Operation Centers) and establishing CSIRT’s (Cyber ​​Security Incident Teams), among others for Saudi Telekom and Saudi Aramco (during my time in Saudi Arabia) and at RadarServices GmbH in Vienna as Global SOC Manager, with up to 30 SOC employees in 24×7 operation or Follow the Sun (at 3 locations in the world with 8h difference each) principle. What […]

Security Issue Employees – Awareness is a must

Security Issue Employees – Awareness is a must

As shown in the previous blog post already in detail and hopefully haunting, awareness can defend many attacks successfully. To do this, companies need to develop an awareness strategy to successfully motivate employees to recognize and ward off social engineering. In this context, I recommend anyone who is in IT security, but also the management, Kevin Mitnick’s book – The art of deception – ISBN 0-471-23712-4 – to read. Who has the opportunity to attend one of his lectures, it is […]

How I take over your business

How I take over your business

In 1987, I brought despair to my instructor at Comparex, where I used a simple security hole on a 3270 screen controller for terminals attached to a /370 mainframe. Batch files were higher in precedence than executable files. So I constructed a batch file that produced a ripple print on the screen and kept outputting “I’m a little virus” in an endless loop. A batch command that was executed copied a bunch of other batch files with the names of […]

Why cyber-security is not effectively lived (in European) companies and organizations

Why cyber-security is not effectively lived (in European) companies and organizations

Most European companies have not taken cyber-security seriously in recent years and now get a wake-up call from the EU, which is not without reason: 4% as a penalty of global sales are finally something to think about. I understand this as a long necessary “shot in front of the bow”, because whatever market investigation I look at, it concludes that around 60% of the companies are underperforming. The question is why? In the case of SMEs, security must not […]

Introduction to this blog

Introduction to this blog

The pressure on European companies is significantly tightened by the German legislator and the EU with regard to cybersecurity – rightly so – because in the past decades most companies have neglected to ignore the latest methods of attack on their digital knowledge. Product data, patents, procedures and other company secrets were often stolen in Cyber-Attack. It is not just the companies that are at fault, but the lack of advice, failures of the legislator, insufficient education at universities, the insufficient […]