I attended this event and it was a great day talking to a lot of people. I wont go into everything but I will mention a few things here:
Met with the UK National Crime Security Centre to discuss what are the current looming threats and concerns for the UK government. One of the biggest challenges still is email phishing. From this user education is paramount and they are working to get small to medium businesses (1-250 employees) certified with Cyber Security Essentials from the NCSC. They have created tools including an escape and a lego game room to help company directors understand the important of cyber security from an easy-to-understand point of view and why it is important to invest early and the risk of security threats to the business.
It seems that employee understanding for small to medium businesses is lacking vastly at the moment leading to phishing scams and ransomware attacks.
I met with Cyber Resilience Centre from the UK government to understand how education in the business is being delivered. They are looking to partner with professionals who can educate and implement security for businesses as they do not have the capacity to help every single business across all sectors because of their staffing level. They have online guides and tools that align with frameworks such as NIST that can help business get started with cyber security for free. They also have assessments which you can sign up for on their website to get started with or to have an initial assessment report done. This is generally for my area which is the west midland in the UK but you can see more at https://www.wmcrc.co.uk
Collaboration is a contention - whether its governments or directors not wanting to divulge information or respondents not having the information to help protect systems. Sharing of information with data ownership issues can hinder an investigation or help out an investigation if the right people are available. But consideration is still needed when information sharing information out, because it is the sharer who is responsible for divulging the information and this can lead to trust issues or misuse of data.
I have to say that this was an interesting topic, with the do's and don'ts of data ownership to the can and can'ts from a data sharer point of view.
Met with Allied Telesis to talk about developments in hardware. They have bought an IP which relates to wifi where the AP’s all talk on 1 subnet and 1 SSID which is private, but provides 0 disconnections with roaming with AP’s – great in factories and production areas when using scanners. More information on this on their website. Their industrial Ethernet switches look OK too - especially compared to Cisco from a cost perspective, knowing you dont have to buy the top of the range model to get a 10gb SFP uplink.
All in all it was a very interesting event