Showing posts with label government. Show all posts
Showing posts with label government. Show all posts

Monday, February 08, 2016

What does every UK Cyber Security startup need, that is worth more than gold?

It's not that I'm ungrateful George...
While compiling the next issue of Executive Intelligence, the Cyber Security briefing for UK decision makers, we came across an announcement from Chancellor George Osborne for a £250,000 programme to increase the rate of cyber security startup development in the UK. We aren't sure whether this announcement, made around the 27th January 2016 was something new or just an echo of a previous release from the 17th November last year, but we took the opportunity to study what was being announced more carefully this time.

The 'Cyber Safe' scheme, will offer advice and support to security startups, and will be open to applicants from March. The scheme is designed to increase the rate of new security startup development in the UK, identify new business ideas from the UK's leading security firms and provide support for security entrepreneurs.

While any assistance for startup and early stage technology companies in the UK is welcome, I'd argue that there are more directly beneficial things that could be done to stimulate and grow UK Cyber Security firms, things that would sustain such growth over 5 years, over 10, and beyond.

Startups, starting up, California style
It costs less than ever to move a software businesses from concept to prototype and on to minimum viable product. The UK is already arguably the best place in Europe to start a technology business. With professional social media, it is easy to connect with expertise and experience, to seek advice and assistance from those of us who have done it before in the UK market and abroad. While neither our climate nor the air quality around Silicon Roundabout is conducive to the kind of cafe-culture you'll find on Sand Hill road (come to think of it neither are the pavements) networking here is just as easy.
"Old Street is that way son"

Something less easy to achieve, and far more valuable to the Cyber Security entrepreneur, is the first customer. This is an area where UK Government has far to go.

According to a study last year by TechUK, only 20% of central government IT managers had "an appetite within their department to procure a higher percentage of technology services from SMEs". One can only imagine what percentage of them might be warm to startups. 5%? 2%? Zero?

The model that works in the US, is one where early stage companies can count on government in all its forms (military, intelligence, research, local, national, laboratories, and the rest) to be a customer of their service or product. That is the great thing about starting a Cyber Security firm in the US, long before specialist funding programs or affiliated venture firms appeared, someone, somewhere in US government was pretty much guaranteed to need your Cyber Security product, and to do business with a relatively small, relatively new, yes... relatively parochial firm who had cracked a tough problem. Contrast this with the TechUK study, or your own anecdotal experience.

"Present them with three options, two of which are,
on close inspection, exactly the same,
plus a third which is totally unacceptable.
I once attended a conference where a government procurement officer explained to the audience of his peers how they could carefully construct RFPs, RFIs, and tender documents for the specific purpose of excluding small firms, while staying within "SME friendly" guidelines issued by government. Never let it be said that the civil service is without ingenuity!

A pity, because government can be a great 1st customer and the benefits are not all one-way. The startup gets valuable feedback, real-life testing, requirements prioritisation, introduction to other potential early adopters, and (if all goes well) a reference customer, ignoring for one moment the financial benefit to the startup. The customer gets early access, the ability to shape the product to their needs, all the deployment assistance they could wish for, and more than likely the ability to cut the deal of a lifetime in terms of commercial arrangements.

But don't take my word for it, ask Black Duck, Aventail, Verid, Sanctum, E-Security, or any of the other successful Cyber Security companies that passed my desk at Fidelity Ventures looking for venture capital funding after the US government became an early customer.

Let's hope TechUK repeat their 2015 study this year and extend the survey to include attitudes to startups.

Tuesday, June 18, 2013

A Quick Enumeration Of The PRISM Program

Enumeration of PRISM
As IT security consultants, former representatives at the GSMA, contributors to IETF's "Raven", and one-time employes of the worlds largest ISP, the inevitable questions started coming up in meetings and conversations shortly after the 8th June.




"...two reporters from the Guardian newspaper announced to the world the source of one of the most significant classified-document leaks in history. Edward Snowden, a 29-year-old national-security contractor from Hawaii, revealed that he was compelled by conscience to inform the world about a massive abuse of authority perpetrated by the US National Security Agency. According to the documents Snowden provided, which have been authenticated, the US government has been systematically collecting the phone records and online communications of millions of American citizens for years."

Clients, commentators, and friends all want answers to the same questions:
  1. What are the NSA doing, and how are they doing it?
  2. What does this mean for IT security?
  3. Where does this go next?

While we can expect this story to develop over many months as more information is dripped out,  we can already go some way towards answering question (1). See the 360is enumeration of PRISM possibilities. PDF.

Where will the story go next? That this story will run and run is something of which we can be sure. It has elements of Manning/Wikileaks (an ethically conflicted individual with access to state secrets), of Leeson/Barings (a young man, on the run from authorities in a foreign land), and just enough direct relevance to UK readers through glimpses into the actions our own GCHQ, who are normally more publicity shy than their US counterparts. The UK intelligence services have been relatively fortunate in recent years, suffering  few leaks, disgruntled former employees, or clumsiness. This episode illustrates both the frequency and extent to which intelligence sharing occurs between the UK and US and the fact that occurrences such as the Snowden event can have an impact for both services with unintended consequences that cannot be anticipated easily.

Timing is everything,  the publication of these revelations may have some bearing on future of The Draft Communications Data Bill or "Snoopers Charter" as it is commonly known. With well publicised recent convictions of a number of terrorist individuals and groups, significant good-will had been earned among the UK public. Any poor handling of the existing Snowden disclosures, and further leaks that are yet to come, may diminish this good-will and make introduction of such a bill more difficult in the future. Futhermore, the disclosure of GCHQ's activities around the 2009 G20 summit in London is bound to have an impact at the G8 event currently in-progress in Northern Ireland.

Looking further out, companies and individuals in Europe may seek to engage with services and providers that do not come directly under US law. Apple, Microsoft, and FaceBook (3 out of many providers) have stated that they handed over data from 10000, 32000, and 19000 accounts respectively in 7 months. US cloud providers are already having trouble persuading European enterprise customers that their sensitive (but completely legal) data is safe from US government spying. This leak will only make matters worse. As one journalist put it "Not subject to American law' - the next desirable IT feature?"

All that we need now is a catchy name for this episode. Dotcomgate? igate? How about "Cloudgate"?

360is will be presenting further analysis of "Cloudgate"and advice for UK organisations in the next edition of Executive Intelligence, our quarterly for UK CSOs and Information Security Managers.

Related Postings:
WikiLeak's Lessons For UK Information Security Professionals.

Update Saturday 8 June 2013 18.56 BST: Leaked NSA slides confirm, PRISM includes direct monitoring of fiber cables and collection directly from the servers of MS, Yahoo, Google, and Co.

Tuesday, September 14, 2010

Citrix XenServer Certified at EAL2 Common Criteria

Back in April we discussed XenServer's recent submission to the Common Criteria (CC) scheme. Based upon previous evaluations, we predicted a 6-month end-to-end process. True to form the guys at SiVenture have delivered on time.

As is common with other virtualization technologies that have been through the CC process, the investigation work centered around separation of virtual machines, their memory, virtual disks, and execution on the CPU(s). The method of secure administration was also investigated.

This is good news particularly for those UK Government buyers who need a CC approved virtualization platform that will help to reduce OPEX through lower power consumption and CAPEX though XenServer's lower license cost.

There is going to be a lot more white space on this chart in 2011-2012 than there was in 2007-2008 when it was compiled, so a lower-cost method of virtualization will be a welcome addition to the procurement department's product list.