[01:02.720 --> 01:04.100] All right, hello everyone. [01:04.440 --> 01:06.860] Welcome to our next talk here in track three. [01:07.540 --> 01:09.820] A couple orders of business before we start the talk. [01:10.720 --> 01:13.480] Please be sure to wear your masks in the building. [01:13.660 --> 01:17.860] It's important for us as part of our agreement with ourselves and our code of conduct. [01:18.140 --> 01:20.030] If you can take them off, just step outside. [01:20.380 --> 01:20.960] You can wear them. [01:21.120 --> 01:22.940] You don't have to wear them when you step outside the building. [01:23.120 --> 01:25.300] But we please ask you to keep them on while you're inside the building. [01:25.900 --> 01:27.620] Also, make sure you stay hydrated. [01:27.620 --> 01:28.780] I know it's hot outside. [01:29.540 --> 01:32.920] Stay hydrated so we don't have any medical emergencies while we're here. [01:33.800 --> 01:39.200] And for this talk, Certifications, the Good, the Bad, and the Ugly by Tom Kranz. [01:39.400 --> 01:42.320] We will have a matrix chat running for this at the same time. [01:42.480 --> 01:44.000] There's a matrix chat room dedicated to this. [01:44.200 --> 01:45.740] You can ask questions in the chat room. [01:45.900 --> 01:48.480] Our virtual participants will be asking questions in the chat room. [01:48.740 --> 01:54.880] When we get to the Q&A session, we'll try and do a mix of questions from you as a live audience and questions from the individuals in the chat room. [01:55.100 --> 01:56.560] So with that, enjoy the talk. [01:56.720 --> 01:57.120] Thank you. [01:57.700 --> 01:58.240] Thank you much. [01:59.680 --> 02:00.360] Hi, everyone. [02:00.900 --> 02:01.260] Welcome. [02:01.860 --> 02:05.920] Pleased to see so many people here, especially given how many other great talks there are as well. [02:06.340 --> 02:07.440] I'm Tom Kranz. [02:07.660 --> 02:12.460] I am an English guy with a German name who lives in Italy, and I have a Latvian citizenship. [02:13.660 --> 02:17.930] So I like to give people's profiling algorithms a proper, proper workout. [02:19.560 --> 02:22.680] I'm talking about certifications, cybersecurity certifications. [02:23.020 --> 02:25.280] And the most important thing is, why should you listen to me? [02:25.280 --> 02:30.620] So I've been kicking around the IT and security industry for over 30 years now. [02:31.000 --> 02:32.740] I've run my own consultancy. [02:32.940 --> 02:34.550] I've worked at Big Four consultancies. [02:34.820 --> 02:38.400] I've worked at niche cybersecurity consultancies. [02:39.800 --> 02:50.760] I've spent a lot of time building teams, my own teams, teams for clients, teams for projects, hiring people, interviewing for projects, mentoring people as well. [02:50.760 --> 02:59.500] So over that time, I've built up a good feel for what works and what doesn't when people apply for roles and when you build out teams. [02:59.800 --> 03:01.420] And part of that is certifications. [03:02.240 --> 03:04.420] We'll dig into some history of certifications. [03:04.420 --> 03:06.100] We'll look at what good and bad looks like. [03:06.400 --> 03:12.380] We'll look at the context of certifications within some sort of very generic job roles that the industry has. [03:12.520 --> 03:14.840] And then we'll dig into some specific things as well. [03:14.840 --> 03:29.420] Well, if you're interested in more details about how interviews work and how this ties into the interview process, I'm doing a workshop later on for a couple of hours, which is an interactive dig into how I interview people, how I interview with other organisations, [03:29.800 --> 03:35.620] and tips and tricks that you can use to get through interviews, weed out bad companies, find good gigs, that sort of stuff. [03:35.790 --> 03:43.920] So if there's any interview-related questions that you've got with certifications, the workshop's probably the best idea for that, and we can spend some real time digging into them. [03:45.380 --> 03:46.540] So, kicking off. [03:47.400 --> 03:48.800] History of certifications. [03:49.260 --> 03:59.580] The IT industry, and security in particular, is quite immature, especially when we compare it to other industries like medicine, like civil engineering. [03:59.940 --> 04:02.420] It's very well-defined what a civil engineer is. [04:02.600 --> 04:05.680] It's very well-defined how you certify, how you qualify. [04:06.000 --> 04:08.600] The same for a doctor, the same for nursing, stuff like that. [04:08.700 --> 04:09.600] Security's very different. [04:10.500 --> 04:11.760] Security's still very immature. [04:11.760 --> 04:15.820] People still can't define what a pen-tester does. [04:16.260 --> 04:18.100] For some people, it's writing reports. [04:18.260 --> 04:19.460] For other people, it's running tools. [04:19.730 --> 04:25.200] For other people, it's actually getting your sleeves rolled up and getting stuck in and very manually hacking about with stuff. [04:25.380 --> 04:27.290] There's no real consistent definition. [04:28.200 --> 04:37.290] So, the big problem is, if you're an employer, or if you're a consultancy working for clients, how do you know the people you're hiring are any good? [04:39.240 --> 04:44.520] Similarly, if you're applying for roles, how do you differentiate yourself from everyone else? [04:45.730 --> 04:47.790] I've spent five years doing pen-testing. [04:48.100 --> 04:48.580] Great. [04:48.680 --> 04:50.060] How do you differentiate that on a CV? [04:50.120 --> 04:51.500] How do you stand out in an interview? [04:51.640 --> 04:52.860] How do you make yourself stand out? [04:53.940 --> 04:57.200] So, certifications initially came from the IT industry. [04:57.300 --> 05:02.400] They sprung up in the security industry as well as a way of demonstrating a certain level of experience. [05:02.400 --> 05:08.670] You could say, if I have this certification, I at least have this level of experience, and you can trust I kind of know what I'm doing. [05:09.600 --> 05:12.800] The problem was, it all kind of went a bit wrong. [05:14.300 --> 05:15.590] We've ended up with this. [05:15.860 --> 05:20.170] Now, I'm sure many of you may have seen some of these certification maps. [05:20.940 --> 05:22.180] This one is from 2020. [05:22.290 --> 05:23.850] It's got worse since then. [05:24.090 --> 05:29.240] I'm not going to pick on the guy who wrote this, because he did his best, because all of these maps are completely inaccurate. [05:29.340 --> 05:30.460] They're all nonsense. [05:30.460 --> 05:37.180] I saw one of them saying that TOGAF, an Enterprise Architecture Certification, was an entry-level certification. [05:37.200 --> 05:40.280] If you're a beginner in cybersecurity, you should get TOGAF. [05:40.620 --> 05:41.780] Utter, utter nonsense. [05:42.240 --> 05:54.180] And this is a colossal pain, because if you're trying to get into the industry, if you're trying to progress your career, if you're trying to stand out from everyone else, how do you know on there what's good, what's bad? [05:54.260 --> 06:03.380] Where are you going to waste your time, especially given the cost of going on courses, especially given the cost of exams, especially given the fact we've got a finite amount of time and energy, right? [06:03.380 --> 06:14.560] I'm too busy, and I've got better things to do than consistently sit examinations week after week after week, so my LinkedIn profile can have 200 letters after it, trying to show off how great I am. [06:16.760 --> 06:23.580] At a very high level, generically, many companies have no idea what people in cybersecurity do. [06:23.860 --> 06:24.220] None. [06:24.740 --> 06:29.440] Even the companies with really great cybersecurity departments still have no idea what they do. [06:29.620 --> 06:34.200] So they try and map cybersecurity career progression to what they know. [06:34.400 --> 06:37.940] And this is kind of the generic model that gets used in the industry. [06:38.180 --> 06:42.860] And some of you will immediately look at this and say, where are the security auditors? [06:43.120 --> 06:44.360] Where are the pen-testers? [06:44.560 --> 06:46.100] And that's kind of the problem, right? [06:46.260 --> 06:49.600] People don't know where they fit in to a traditional organizational structure. [06:51.000 --> 06:56.240] At a very sort of high level, most organizations think, okay, an entry level position is an analyst. [06:56.580 --> 07:03.380] They're the people who sit there and they gather information, they gather reports, they gather alerts, they action them, they send it off. [07:04.000 --> 07:06.900] An engineer is the person who implements tools. [07:07.120 --> 07:08.150] They build stuff. [07:08.540 --> 07:10.720] They build the stuff that the analysts use. [07:11.260 --> 07:12.780] Further up the tree, you've got the architects. [07:12.780 --> 07:17.740] The architects design the stuff that the engineers build, that the analysts then use. [07:18.560 --> 07:26.240] And then right at the very top, you've got your chief information security officer, who has zero involvement whatsoever in any of that. [07:26.320 --> 07:38.880] And they spend most of their time, and I say this from bitter experience, most of their time arguing about budgets, arguing about strategy, arguing about why people aren't following their security processes, and then getting shouted at because there's a security breach. [07:39.680 --> 07:40.700] That's the day in the life. [07:41.360 --> 07:43.220] All of this, as well, is complete nonsense. [07:43.720 --> 07:44.080] Right? [07:44.160 --> 07:44.860] I'm a CISO. [07:45.060 --> 07:52.060] On any given day before lunchtime, I've done the work of an analyst, I've done the work of an engineer, and I've done the work of a therapist, as well. [07:52.800 --> 07:54.580] And that's just before lunch, right? [07:54.580 --> 08:03.440] So, this does work as a model, though, for roughly sort of gauging what certifications fit in at which levels. [08:03.920 --> 08:04.440] Right? [08:04.460 --> 08:14.620] If you're an analyst, and you're just starting out in the industry, you do not want to be pursuing a certification that's aimed at an architect who should have five or six years' experience. [08:15.960 --> 08:24.360] Despite what some excellent people on LinkedIn may have you say, if you're an engineer, do not try and present yourself as a CISO. [08:24.580 --> 08:29.720] Because someone's going to come along and say, brilliant, write me a business strategy for security for the next five years. [08:30.180 --> 08:32.260] Engineering skill set is not going to help you there. [08:35.350 --> 08:39.010] So, what does a good or a bad certification look like? [08:39.230 --> 08:41.450] So, again, this is based on me building teams. [08:41.470 --> 08:43.110] This is based on me hiring people. [08:43.290 --> 08:45.490] This is based on me interviewing lots of people. [08:46.730 --> 08:49.290] Bad certifications always pay to play. [08:49.530 --> 09:01.170] Any certification that says, you have to pay to go on our official course before you can sit the exam, it's not about proving knowledge, it's about generating revenue, and it's not generating revenue for you. [09:01.510 --> 09:05.690] Those are valueless certifications, and it stands out really badly in the interview. [09:07.230 --> 09:09.390] Focusing on tools rather than techniques as well. [09:11.230 --> 09:14.190] Everyone in this room is here because you're interested in hacking, right? [09:14.250 --> 09:15.330] You're interested in security. [09:15.770 --> 09:20.370] You can sit down, you can read a manual, you can watch some YouTube videos, you can read a how-to document. [09:20.850 --> 09:23.930] Working out how a tool works is very, very straight forwards. [09:24.970 --> 09:31.290] Paying several thousand euros to go on a course to be taught how to use a tool is a colossal waste of time and money. [09:31.890 --> 09:41.870] Lots of certifications focus purely on, these are tools that hackers use, these are tools that defenders use, write me a big fat check and we'll teach you how to click buttons. [09:42.730 --> 09:49.250] Again, not really great when it comes to demonstrating a skill set, unless you're a parrot. [09:51.050 --> 09:52.850] Any mention of ethical hacking whatsoever? [09:53.210 --> 09:56.130] This is a huge, huge bugbear of mine. [09:56.830 --> 09:59.570] Whenever anyone talks about ethical hacking, who's ethics? [10:00.090 --> 10:00.690] Mine? [10:01.150 --> 10:02.330] You don't want those. [10:02.550 --> 10:03.290] The government? [10:03.990 --> 10:04.930] Some non-profit? [10:05.190 --> 10:06.010] A corporation? [10:06.550 --> 10:06.950] Really? [10:07.290 --> 10:10.830] You're going to take Mad Larry from Oracle's ethics? [10:10.830 --> 10:12.930] Maybe Zuckerberg's ethics from Facebook? [10:13.150 --> 10:14.730] You're going to be an ethical Facebook hacker? [10:14.930 --> 10:16.350] It's a nonsense phrase. [10:16.690 --> 10:22.210] Any certification, any course that talks about ethical hacking is absolute rubbish, right? [10:22.270 --> 10:23.370] There's no such thing. [10:23.590 --> 10:25.750] There is merely, what is it you want to do? [10:25.890 --> 10:26.890] How are you going to defend? [10:27.210 --> 10:28.790] Do you understand how people attack? [10:29.090 --> 10:30.330] That's what it gets down to. [10:30.750 --> 10:32.670] Ethics doesn't come into it, right? [10:32.670 --> 10:43.630] If you're going to go and rip off your employer and pocket a big stack of cash, A, you should be a politician, and B, having a badge that says you're an ethical hacker isn't going to stop you doing that. [10:43.770 --> 10:46.070] It's nothing to do with the certification or what you've been taught. [10:47.530 --> 10:49.730] Vendor-specific certifications as well. [10:50.630 --> 10:53.450] Now, this is the point where I can say you should all be privileged. [10:53.450 --> 10:57.230] You're in the presence of a principal certified Lotus professional. [10:58.110 --> 11:01.850] If you have a problem with CC Mail, I am your man. [11:02.210 --> 11:03.410] Write me a big fat check. [11:03.410 --> 11:07.310] I will fix, especially, CC Mail on OS 2. [11:10.690 --> 11:14.530] Vendor-specific certifications are a waste of time. [11:14.770 --> 11:15.290] Right? [11:15.390 --> 11:17.450] Because technology comes and goes. [11:17.750 --> 11:21.110] CC Mail was last used 25 years ago. [11:21.330 --> 11:23.750] Maybe 20 years ago if you worked at a really bad company. [11:24.210 --> 11:27.770] I've got a whole stack of Sun certifications for Solaris UNIX. [11:28.310 --> 11:29.390] What happened to them? [11:29.470 --> 11:30.670] They've been swallowing up by Oracle. [11:30.670 --> 11:33.670] I've even got some Silicon Graphics certifications. [11:33.690 --> 11:35.330] When was the last time you heard that? [11:35.550 --> 11:35.590] Right. [11:36.430 --> 11:39.990] The other danger with vendor-specific certifications is that they pigeonhole you. [11:41.510 --> 11:47.630] I have a whole stack of Sun Solaris certifications because, at the time, that's what I was doing and that paid my bills. [11:47.950 --> 11:51.670] If I carried on doing that, A, I'd be unemployed because they've been swallowed by Oracle. [11:51.950 --> 11:55.230] But also, I'd be pigeonholed as the Solaris guy. [11:55.530 --> 11:59.010] In the current market at the moment, that's not really a great place to be. [12:00.230 --> 12:09.190] Trying to make the transition from being a Solaris guy who deals with big data centers into AWS Cloud or Azure is difficult. [12:09.450 --> 12:19.530] If you focus too much on vendor-specific qualifications and certifications, you get railroaded down into the path where essentially people say, you're going to be the AWS guy. [12:20.270 --> 12:22.190] Now, that doesn't completely invalidate them, right? [12:22.350 --> 12:31.410] If you're doing a lot of work in AWS or Azure or Google Cloud, it's probably worthwhile to have one or two certifications there to demonstrate the fact you know what you're talking about. [12:32.510 --> 12:43.770] You can see this on LinkedIn where there are people with a gazillion certifications and they're quite happy to showcase them on their LinkedIn profile and say, look at me, I've had 200 certifications for Microsoft Azure. [12:44.390 --> 12:44.850] It's like, brilliant. [12:45.210 --> 12:47.610] And you change jobs and someone's using Google Cloud. [12:47.610 --> 12:48.810] Where does that leave you? [12:50.790 --> 12:58.910] The final sort of red flag for bad certifications is claims about post-certification salary increases. [12:59.990 --> 13:12.890] This is something I particularly hate because you get loads of people saying, oh, I'll take out a loan and I'll spend €7,000 on this course and afterwards I'll increase my earnings by €20,000 or €30,000 a year. [13:13.090 --> 13:13.970] It doesn't happen. [13:14.750 --> 13:15.950] Certifications are there. [13:15.950 --> 13:19.050] They should be there to showcase your experience. [13:19.270 --> 13:24.610] If you don't have the experience and you go for the certification, you're not going to see a jump in salary. [13:24.810 --> 13:34.530] You may get hired by a company, but that company will treat you as essentially a cog in the machine and say, right, you slot in here and you do this job and you're pigeonholed and that's it. [13:35.370 --> 13:48.050] The thing that gets you salary increases is by being able to demonstrate in an interview or to an employer, I have all this experience, I have all this knowledge, I've done all this cool stuff and by the way, I've got a certification as well. [13:48.630 --> 13:51.150] Employers pay you for your experience. [13:51.890 --> 13:57.790] There is a big lie about a certification will give you X amount of salary or Y amount of salary. [13:58.370 --> 14:04.710] It's particularly bad at the moment, especially if you spend time in the U.K. where you see the U.K. government with loads of these great adverts. [14:05.150 --> 14:09.330] So-and-so was a ballerina and we've cut funding to the arts so now everyone is unemployed. [14:09.330 --> 14:12.330] So they're going to retrain at cyber and they're going to earn 50 grand a year. [14:12.950 --> 14:14.210] No, they're going to be unemployed. [14:15.050 --> 14:16.470] You haven't helped them at all. [14:17.590 --> 14:19.530] So what makes a certification good? [14:19.890 --> 14:24.130] Good certification is one that functions as a capstone to your experience. [14:24.410 --> 14:32.630] You can use it to be able to demonstrate I have X years of doing this and I passed the certification as additional proof of that. [14:32.630 --> 14:38.030] It's a way of essentially demonstrating that you know what you're talking about and you took the certification exam. [14:40.410 --> 14:42.910] Ideally, that exam should have a practical component. [14:43.410 --> 14:50.110] It's really, really easy to sit down, chew through 40 multiple choice questions and come out with a bit of paper at the end that says you're certified. [14:50.630 --> 14:51.470] I've done it myself. [14:51.830 --> 14:52.590] I don't have my hand. [14:52.730 --> 14:59.750] I have at least two certifications where I showed up, I spent 15 minutes clicking multiple choice questions and came out with two passes. [15:01.470 --> 15:03.230] Does that demonstrate expertise? [15:03.670 --> 15:04.150] No. [15:04.570 --> 15:11.630] It demonstrates a certain level of arrogance and a certain level of hacking the process but it doesn't demonstrate expertise. [15:11.930 --> 15:14.550] So ideally, your certification should have a practical element. [15:14.830 --> 15:16.810] You should have something where you demonstrate. [15:17.470 --> 15:18.710] I've read this stuff. [15:18.830 --> 15:19.710] I've learned this stuff. [15:19.850 --> 15:20.970] Here's how it works. [15:22.770 --> 15:24.830] There should also be different levels as well. [15:24.950 --> 15:30.630] Going back to that model where we have analysts, engineer, architect, CISO, you know, the career progression based on experience. [15:30.990 --> 15:36.110] There should be different levels of certification as well that test different depths of experience. [15:37.530 --> 15:42.650] And finally, it should have some sort of aspect of continuous development. [15:43.270 --> 15:48.450] My much-coveted Lotus CCML certifications never expire. [15:48.450 --> 15:51.870] The fact that Lotus doesn't exist anymore, it doesn't even matter, right? [15:51.970 --> 15:52.990] They never expire anyway. [15:53.310 --> 15:59.090] For eternity, it will be on my tombstone that I was a principle-certified Lotus professional. [16:00.170 --> 16:03.070] Those certifications are not good ones, right? [16:03.890 --> 16:09.630] Technology moves on a weekly, on a monthly basis, especially in security where attacks are constantly evolving. [16:09.830 --> 16:12.850] A certification that sits there and says, here's your paper. [16:13.010 --> 16:13.650] It's valid forever. [16:13.650 --> 16:14.950] You don't need to do a retest. [16:14.950 --> 16:16.770] You don't need to demonstrate continuous learning. [16:17.390 --> 16:19.490] Again, that's not a good way of demonstrating knowledge. [16:19.910 --> 16:23.410] It's a good way of demonstrating you know how to pass a test. [16:24.950 --> 16:28.910] One thing I haven't mentioned on here is ugly certifications. [16:29.270 --> 16:31.070] And we'll be covering those right at the end. [16:31.170 --> 16:36.150] But when I talk about ugly certifications, I'm talking about ones that have issues with them. [16:36.310 --> 16:37.570] They're not well known. [16:38.450 --> 16:39.770] They're poorly thought out. [16:39.910 --> 16:41.750] They have problems when you go and pass them. [16:41.750 --> 16:42.730] There's some value there. [16:42.910 --> 16:44.130] But it's kind of hidden. [16:44.310 --> 16:45.010] It's a bit difficult. [16:46.210 --> 16:49.110] One certification I'll talk about at the end is Myden Scandal. [16:49.350 --> 16:51.430] And that's kind of devalued the value of it a bit. [16:55.030 --> 16:56.230] So, cracking on. [16:56.370 --> 16:57.510] Cracking on with the good. [16:58.590 --> 17:01.070] So, starting at the entry level, the analyst level. [17:02.230 --> 17:03.190] CompTIA certifications. [17:03.370 --> 17:04.030] Network Plus. [17:04.190 --> 17:05.110] Security Plus. [17:07.630 --> 17:13.490] If you are joining the industry, if you don't have much experience, these are really great certifications to have. [17:13.670 --> 17:15.350] Because they test a breadth of knowledge. [17:16.470 --> 17:18.350] Now, yes, they're multiple choice questions. [17:18.950 --> 17:20.610] Yes, there isn't a practical element. [17:20.850 --> 17:25.710] But when you're starting off, you probably don't have the experience to be able to do a practical test. [17:27.290 --> 17:30.830] And especially the Network Plus, and Security Plus as well, is well thought out. [17:30.990 --> 17:40.990] It covers a broad range of stuff that you're most likely to meet when you're doing an analyst role, when you're working in a security operations centre, when you're working as a junior member of a team. [17:42.270 --> 17:47.570] People I see with these certifications, when they come to interview, they have a good level of grounding knowledge. [17:47.750 --> 17:51.850] They're able to explain how stuff works, which makes them excellent as part of a team. [17:52.030 --> 18:00.130] And it also means that if you've got those certifications, you've got the good foundations to start building on that knowledge and advancing further from there. [18:01.110 --> 18:02.350] Another good entry level one. [18:02.530 --> 18:04.990] And I know I said vendor certifications are bad. [18:04.990 --> 18:07.490] I kind of make an exception for this one. [18:08.110 --> 18:12.510] So Cisco's entry level certification, the CCNA, they have a security component from that. [18:13.150 --> 18:14.950] And again, I rate that quite a lot. [18:15.130 --> 18:20.070] That covers a lot of things about routing and switching and networking and network attacks and network security. [18:20.530 --> 18:23.610] That's all stuff, as an analyst, you're going to be dealing with. [18:24.310 --> 18:29.470] Analysts will be doing stuff like monitoring firewalls, monitoring routers, monitoring network attacks. [18:30.190 --> 18:43.530] If you've got a certification that shows that you've covered that, it gives an interviewer and an employer a certain level of confidence that you have the skills to be able to be dropped in and say, OK, here's our network, go and protect it. [18:44.330 --> 18:47.650] So all three of those are good entry level certifications. [18:48.590 --> 19:01.630] Going a bit above that, looking at sort of a more senior role, ISACA's Certified Information Security Manager, the CISM, appalling, appalling acronym, but there we go. [19:03.610 --> 19:16.110] To demonstrate that you understand wider security issues, to demonstrate that you understand how security works in an organisation, this is a really good certification that, again, is a good way of demonstrating you've got the skills in there. [19:16.450 --> 19:19.750] A lot of security is not about technology. [19:20.030 --> 19:22.030] It's not even about defeating attackers. [19:22.390 --> 19:26.410] It's spending your time talking with people who have no idea what you're talking about. [19:26.410 --> 19:28.390] It's convincing that there's a problem. [19:28.650 --> 19:32.850] It's managing other teams to be able to support you as you try and get fixes in. [19:33.030 --> 19:39.910] It's working with developers, with engineers, with HR, getting policies enforced, all this sort of stuff. [19:41.010 --> 19:44.490] So the ISACA certifications in particular cover lots of areas. [19:44.610 --> 19:49.230] They give you a good test that you've got skills in that area. [19:49.510 --> 19:55.030] And again, because if you see a security attack, the fix is, OK, we implement these firewall rules. [19:55.030 --> 19:55.590] Easy. [19:55.970 --> 19:57.390] Technology is not the problem there. [19:57.990 --> 20:05.350] Convincing other teams that they should have a business outage while you knock out their network connection and apply those firewall rules, that's the difficult bit. [20:05.970 --> 20:17.430] And again, if you've got certification like that where you've been able to demonstrate you know how to talk about security in the context of the wider company, it's a valuable thing to have. [20:18.830 --> 20:23.990] Moving on a bit, going down the list of more deeply technical stuff, the OSCP. [20:25.090 --> 20:28.490] Anyone who's got an OSCP, I instantly want to bring into an interview. [20:28.790 --> 20:33.010] It is a bugger of an exam to pass. [20:33.270 --> 20:34.170] It's practical. [20:34.170 --> 20:35.530] You've got to write a report. [20:35.910 --> 20:37.110] It's very complex. [20:37.130 --> 20:37.950] It's very taxing. [20:38.690 --> 20:39.970] There's literally no mercy. [20:40.270 --> 20:43.550] And whenever you ask for help, everyone laughs at you and says, try harder. [20:43.870 --> 20:45.550] It's a fantastic motto to have. [20:46.850 --> 20:53.770] Anyone who wants to be a pen-tester in any sort of serious capacity, the OSCP is a fantastic way of demonstrating you know what you're doing. [20:54.090 --> 20:59.330] I will take the OSCP over anything else when I'm building an offensive security team. [20:59.470 --> 21:02.070] It is hands down one of the best certifications out there. [21:02.310 --> 21:09.050] And because it's purely practical, it really, really tests your ability not to use tools, but to solve problems. [21:09.350 --> 21:13.810] And that's one of the key things that people who are doing offensive security need to understand. [21:13.810 --> 21:14.850] How do you solve problems? [21:14.950 --> 21:16.490] How do you get to the root cause of something? [21:16.670 --> 21:19.650] And then how do you work to exploit that and then to defend it? [21:20.370 --> 21:21.650] OSCP is great for that. [21:22.910 --> 21:23.970] Finally, CISP. [21:25.070 --> 21:31.130] CISP gets a lot of bad press, largely because people don't understand the context of it. [21:31.550 --> 21:40.070] Now, I know two recruitment agencies in the U.K. who explicitly tell every single candidate to put on their CV that they're studying for the CISP. [21:40.370 --> 21:44.990] You're going for an analyst role, you've got a year's experience, put down your studying for the CISP. [21:44.990 --> 21:45.330] Right? [21:45.490 --> 21:49.310] It's that sort of nonsense that devalues the context of that certification. [21:49.310 --> 21:51.410] You've got to have five years experience. [21:51.970 --> 21:56.290] You've got to have five years experience that someone else has validated on your CV. [21:57.390 --> 22:04.650] And that for me makes it a really, really good certification for an architect to have, for a senior person, a senior engineer. [22:04.970 --> 22:13.230] Because if you get to the point in your career where you've got five, six, seven years experience of doing security in the real world, why would you not take the exam? [22:13.710 --> 22:16.150] It's a great way of demonstrating a skill set. [22:16.350 --> 22:19.610] If you've got that level of experience, it's relatively easy to pass. [22:19.970 --> 22:22.410] People bang on about the CISP being a difficult exam. [22:22.490 --> 22:26.430] And in some ways it is, especially if you don't know your subject matter. [22:26.950 --> 22:30.570] If you do have the experience, it's a great way of demonstrating it. [22:31.190 --> 22:38.210] To the point where if I'm interviewing for senior architect roles, these are roles where the salary is six figures, six figures plus. [22:38.510 --> 22:40.970] These are people who should have 10, 12 years experience. [22:41.290 --> 22:46.790] And I'm dropping them into banks, financial services, critical national infrastructure companies. [22:47.770 --> 22:56.270] Those people I expect to have a CISP because they should have the breadth and depth of knowledge to be able to pass that very easily, to be able to walk the exam. [22:57.150 --> 23:06.470] It's almost to the point where if you have enough experience and you don't have a CISP, that starts to raise red flags in the interviewers because they're saying, why would you not do it? [23:06.490 --> 23:07.630] It's a no-brainer at this point. [23:08.070 --> 23:12.150] The other advantage is, the entire industry knows about the CISP. [23:12.290 --> 23:17.970] You get companies who couldn't spell CISO, but they know what a CISP is and they put it on their job descriptions. [23:18.270 --> 23:19.810] It's very well recognized. [23:20.230 --> 23:27.090] And so therefore if you do have it and you're using it as a way of demonstrating your expertise and your experience, it's a great thing to have. [23:27.230 --> 23:31.130] If you're in a more senior role, if you're looking to progress, absolutely the CISP. [23:31.990 --> 23:35.710] Now the flip side of that is, there's a whole bunch of specializations under there. [23:35.830 --> 23:37.070] There's a cloud specialization. [23:37.270 --> 23:38.130] There's a couple of others. [23:39.170 --> 23:39.290] Meh. [23:40.250 --> 23:42.450] It doesn't really have much value. [23:42.550 --> 23:44.370] It's the main CISP that really matters. [23:45.130 --> 23:45.530] Specializations. [23:46.330 --> 23:51.250] If you have a CISP, I kind of expect you to know what cloud computing is and how to secure that. [23:52.150 --> 23:54.710] Fundamentally, it's not much different from a data center, right? [23:54.770 --> 23:55.510] It's still computers. [23:55.530 --> 23:56.710] It's still got network connections. [23:56.750 --> 23:57.710] It's still running software. [23:57.710 --> 23:58.870] You still need to defend it. [23:59.010 --> 24:00.530] It's all kind of the same stuff. [24:01.730 --> 24:03.050] So, that's the good. [24:04.290 --> 24:05.350] Let's look at the bad. [24:06.650 --> 24:06.990] Right. [24:07.430 --> 24:11.450] Starting off with my personal pet hate, the certified ethical hacker. [24:11.910 --> 24:16.170] This triggers all of my prejudices, right? [24:16.170 --> 24:17.470] It mentions ethical hacking. [24:17.970 --> 24:19.790] You've got to pay to go on their courses. [24:20.010 --> 24:21.970] It teaches you how to use tools. [24:21.970 --> 24:31.590] And the worst thing, the biggest crime of all, is that the EC Council have a huge marketing budget and they've brainwashed people into thinking the CEH is a must-have to land a job. [24:31.770 --> 24:33.610] It absolutely is not. [24:34.150 --> 24:34.650] Right? [24:34.790 --> 24:37.770] If you're thinking about taking it, save your money. [24:38.090 --> 24:38.890] Do something else. [24:39.130 --> 24:41.630] If you've got the CEH, be proud. [24:41.790 --> 24:42.970] You passed the exam. [24:43.230 --> 24:44.390] That's a difficult thing to do. [24:44.850 --> 24:46.090] Don't give them any more money. [24:46.290 --> 24:47.510] Focus on something else. [24:48.350 --> 24:54.110] In fact, while we're slagging off the EC Council, literally everything from them is bad. [24:55.730 --> 24:57.430] Now, there's a couple of reasons for this. [24:57.550 --> 24:59.290] It's not just blind hatred on my part. [24:59.770 --> 25:11.490] Now, firstly, the EC Council and their employees have a history of stealing people's content from books, from blogs, from courses, putting it in their paid-for courses, and they're not compensated for acknowledging it. [25:11.750 --> 25:15.730] Now, I know at least three people have very publicly tried to sue the EC Council over this. [25:15.730 --> 25:18.170] They've tried to have their published content removed. [25:18.270 --> 25:19.710] They haven't even got an apology. [25:20.230 --> 25:20.590] Right? [25:20.670 --> 25:32.390] The EC Council have a long, long history of essentially stealing people's content, charging for it, and then making it as difficult as possible to get you either compensated or have your content removed. [25:33.130 --> 25:37.130] Now, that for me is enough to blacklist any certification from them. [25:37.430 --> 25:45.910] But again, they keep on banging on about your being an ethical hacker, and all of their stuff, even through to their CISO qualification. [25:46.270 --> 25:48.690] How do you qualify someone who's at a business level? [25:48.910 --> 25:48.990] Right? [25:49.970 --> 25:57.330] You don't take a bunch of tests and exams that say, oh, show on this form what a good budget projection looks like. [25:57.510 --> 25:57.630] Right? [25:58.070 --> 25:59.850] It just doesn't work at all. [26:01.430 --> 26:04.410] The other thing as well is that it's always pay-for-play. [26:04.590 --> 26:05.750] All of their certifications. [26:05.970 --> 26:08.170] It's very difficult to get knowledge about it. [26:08.470 --> 26:10.370] The CH has been around for ages. [26:10.370 --> 26:16.450] You'll see a lot of course dumps on The Pirate Bay for the CH because people have ripped off the courses and they've shared it around. [26:17.490 --> 26:24.870] Some of their other courses are going that way as well because they charge an absolute fortune to sit in a classroom and be taught how to use tools. [26:25.330 --> 26:32.710] As you get to the more senior certifications, you get taught to use more expensive tools and to use tools in more complicated ways. [26:34.350 --> 26:36.250] Personally, I can watch a YouTube video for that. [26:36.350 --> 26:38.090] I don't need to fork out a few thousand euros. [26:40.230 --> 26:41.730] Vendor certifications are another one. [26:43.010 --> 26:53.910] Any vendor certification with the context of, as I mentioned earlier, if you're doing some work with a particular cloud provider, yeah, okay. [26:54.130 --> 27:00.210] If your employer is paying for it, if it's easy to take the exam, do it as a way of demonstrating your expertise in that cloud provider. [27:00.910 --> 27:07.910] I would always argue that rather than having a dedicated vendor certification like, I'm going to pick on Juniper. [27:08.210 --> 27:09.570] Juniper firewalls certification. [27:10.050 --> 27:10.370] Great. [27:10.490 --> 27:11.910] You know how to use Juniper firewalls. [27:12.110 --> 27:14.570] You apply for a job whether you use Cisco firewalls. [27:14.890 --> 27:23.130] Suddenly your Juniper firewalls certification is not only useless, it acts against you because people won't shortlist you because they say, well, he's a specialist in Juniper firewalls. [27:23.150 --> 27:24.350] He doesn't know about Cisco stuff. [27:24.450 --> 27:25.490] It's a different operating system. [27:25.610 --> 27:26.750] We won't bring him through to interview. [27:27.710 --> 27:32.250] So rather look at vendor certifications, look at what area that they're working in. [27:32.330 --> 27:37.570] Again, if you're looking about routing, switching, firewalls, Cisco CCNA is probably a better one. [27:37.730 --> 27:38.830] It's a broader reach. [27:38.970 --> 27:41.110] It doesn't teach you how to use Cisco gear. [27:41.290 --> 27:43.530] It teaches you how to secure the network. [27:44.510 --> 27:45.190] Cloud computing. [27:45.510 --> 27:47.010] There's Cloud Security Alliance. [27:47.030 --> 27:48.470] They do some certifications. [27:48.470 --> 27:51.030] That's a good way of saying you understand cloud computing. [27:51.530 --> 28:00.730] Even better is some sort of architecture certification that says you know how to build scalable systems because then that doesn't just cover every single cloud provider. [28:00.910 --> 28:02.410] It covers traditional data centers. [28:02.530 --> 28:03.710] It covers hybrid cloud. [28:03.950 --> 28:06.030] It covers distributed global organizations. [28:06.250 --> 28:06.930] All sorts of stuff. [28:07.690 --> 28:08.350] So have a think. [28:08.550 --> 28:18.230] Before you go down the vendor certification route, take a step back and think, actually, do I want to be certified in a product or do I want to be certified in a type of technology? [28:18.490 --> 28:20.910] And what's more valuable for me as I look at my career? [28:22.570 --> 28:23.690] Anything pay to play? [28:25.150 --> 28:26.590] There's absolutely no reason. [28:26.590 --> 28:27.150] Right? [28:27.250 --> 28:34.150] If you're taking an exam to pass a certification, you should be able to rock up and say, I've got X years experience in this. [28:34.310 --> 28:38.010] I'm going to sit the exam, ace it, and walk away with a bit of paper that shows it. [28:38.250 --> 28:43.210] If you have to pay someone to go on their course, you're generating revenue for that organization. [28:43.650 --> 28:45.650] You're not generating revenue for yourself. [28:45.650 --> 28:48.190] You're not generating any sort of expertise for yourself. [28:48.510 --> 28:52.470] You're literally just printing money for whichever the certification organization is. [28:53.630 --> 28:56.710] And finally, SABSA. [28:56.930 --> 29:00.110] One of the sacred holy cows of the security world. [29:00.650 --> 29:05.110] SABSA is a architecture framework for building security architecture in organizations. [29:07.290 --> 29:08.670] Two problems with that. [29:09.050 --> 29:18.470] The first one is the only way you can get any information on SABSA, even the documentation that goes before the course, you've got to buy it from SABSA. [29:19.090 --> 29:20.590] You want to read the manual on SABSA? [29:20.730 --> 29:21.010] Brilliant. [29:21.150 --> 29:22.050] Cough up some cash. [29:22.350 --> 29:24.250] You want to understand how to train on SABSA? [29:24.370 --> 29:24.630] Brilliant. [29:24.770 --> 29:25.590] Cough up some cash. [29:25.810 --> 29:26.830] You want to take the exam? [29:27.050 --> 29:27.290] Brilliant. [29:27.450 --> 29:28.290] Cough up some cash. [29:28.410 --> 29:29.050] Go on the course. [29:29.630 --> 29:42.630] Now, that's at a knock-on effect because the rest of the industry has said, why are we paying thousands and thousands and thousands of euros to send all of our architects on a Sabsa course when it's just teaching them security architecture and it's costing us a fortune? [29:43.590 --> 29:50.270] So, in the industry, people have stopped asking for Sabsa to be able to prove you can do security architecture. [29:50.910 --> 30:00.150] Instead, organisations have been asking for things like TOGAF, which is from the Open Group, and that's a certification that covers enterprise architecture. [30:01.030 --> 30:02.650] Now, Sabsa is fairly rigid. [30:02.650 --> 30:05.910] It deals with security and it deals with security in a specific way. [30:06.270 --> 30:11.030] Every single organisation I've worked with who have tried to implement Sabsa have failed. [30:11.510 --> 30:14.570] It's a very brittle, non-flexible framework. [30:16.210 --> 30:18.910] TOGAF, on the other hand, you can pick and choose. [30:18.910 --> 30:21.910] You can look at bits of it and say, this makes sense. [30:22.090 --> 30:35.850] I'm going to build out a library of blessed software and blessed components so that whenever people come to build something, they can just go to the TOGAF library and say, this is stuff we've tested, we know it works, we know it's supported, we'll use this stuff. [30:36.050 --> 30:37.470] It's a really great way of doing stuff. [30:37.670 --> 30:43.130] A review of your documentation, the way TOGAF does it, continuous improvement, a very good way of doing it. [30:43.330 --> 30:44.150] It's very flexible. [30:45.250 --> 30:53.290] Organisations I've seen who've used TOGA to do enterprise security architecture have done very well with it because they can pick and choose components. [30:53.650 --> 31:00.350] They can go through and say, this is relevant for us today, this is not relevant for us, but it might be next year or in two years' time or something like that. [31:01.530 --> 31:06.750] So Sabsa stands out as a bad architecture certification. [31:06.750 --> 31:08.790] There are better options out there. [31:09.730 --> 31:12.230] And additionally, it costs a fortune. [31:12.230 --> 31:18.990] And if you go to your employer and say, I would like you to pay for me to be Sabsa certified, the employer's going to laugh at you. [31:19.790 --> 31:29.870] I've not found any employer now who's willing to pony up the cash for Sabsa certification, partly because it's hugely expensive and partly because what does the employer get from the end of it? [31:29.870 --> 31:37.290] So if you know how to build architecture, why do they have to pay thousands to send you on a course to learn how to design architecture? [31:39.850 --> 31:40.490] Right. [31:40.830 --> 31:42.990] Final section, the ugly stuff. [31:44.330 --> 31:45.310] So, SANS. [31:48.090 --> 31:50.470] SANS are a great organisation, right? [31:50.470 --> 31:52.230] I really rate their training courses. [31:52.230 --> 31:54.330] I really rate their certifications. [31:54.710 --> 31:57.610] The GIAC is equivalent to CISP, right? [31:57.610 --> 31:58.990] It's a great certification. [31:59.870 --> 32:06.910] The problem is, all of the SANS certifications sound like my cat throwing up a hairball, right? [32:07.490 --> 32:09.270] It's unfortunate, but it's true. [32:09.930 --> 32:10.410] GIAC. [32:10.790 --> 32:11.270] GISP. [32:11.750 --> 32:12.130] Hick. [32:14.570 --> 32:18.910] You try to go to your boss and say, I want to spend a few thousand pounds on a training course for the GIAC. [32:20.090 --> 32:21.190] It's not going to end well. [32:21.870 --> 32:26.830] The other problem is, SANS have focused a lot on the content of their courses. [32:26.830 --> 32:31.730] They've focused a lot on making sure that if you get a SANS certification, it has value. [32:31.850 --> 32:33.410] It's a good way of demonstrating skills. [32:33.710 --> 32:36.930] The problem is, they haven't spent that much on marketing or convincing anyone else. [32:37.330 --> 32:46.910] So, the number of job postings I see that ask for a SANS certification, or even recognise that there are some SANS certifications that are equivalent to CISP. [32:46.910 --> 32:54.350] I've seen two in the last year, out of several thousand job postings that I've had to trawl through. [32:54.650 --> 32:56.490] It's not widely recognised. [32:57.870 --> 32:59.170] Why is that jumping forwards? [32:59.990 --> 33:17.210] That causes a problem, because, again, if you invest time and money in a certification that showcases your skills and expertise, if you have to explain to someone what that certification is and why it's valuable, you've kind of got an uphill struggle there. [33:18.490 --> 33:20.890] Think about the people who are going to be interviewing you. [33:21.030 --> 33:23.370] Think of the people that you're going to be working with in organisations. [33:23.370 --> 33:29.790] If they don't know the value of the certification, how are they going to know that you're any better than someone else who doesn't have the certification? [33:30.110 --> 33:31.870] How are they going to be able to judge your skill set? [33:32.730 --> 33:34.970] So, SANS have kind of let themselves down a bit from that. [33:36.430 --> 33:41.570] Now, if you get the chance to go on a course, if you get the chance to take a SANS certification, grab it with both hands. [33:41.810 --> 33:43.030] It's great, right? [33:43.090 --> 33:50.210] They're great courses, they're great certifications, but they have problems with visibility and with pronunciation as well. [33:51.810 --> 33:55.310] One that's come up newly is Concordia. [33:55.890 --> 33:57.730] Concordia are a consortium. [33:58.070 --> 33:59.330] They've had funding from the EU. [33:59.790 --> 34:08.710] And essentially, EU has basically said, we've got loads of really shady consultants, people like Tom, who talk nonsense at us and steal our wallets. [34:08.850 --> 34:13.730] We need to know that a cyber security consultant has a certain level of expertise. [34:14.630 --> 34:19.370] So the Concordia consortium is from cyber security firms. [34:19.370 --> 34:23.770] It's from legal firms, it's from universities, and they've pooled their resources. [34:24.070 --> 34:28.630] They went out to the industry in general and said, what are good skills for a consultant to have? [34:28.850 --> 34:30.390] Now, I was part of that. [34:30.570 --> 34:31.950] I took part in the initial stuff. [34:32.190 --> 34:37.090] They've built up a definition that says, okay, a cyber security consultant should have these skills. [34:37.510 --> 34:42.110] Let's build a course to teach those skills, and let's build an exam to test those skills. [34:45.370 --> 34:50.010] The C3 certification has a Coursera component. [34:50.270 --> 34:53.370] We go online, we do some distance learning on Coursera. [34:53.710 --> 35:00.330] It has an interactive lecture component, where you sit down with some experts, and they go into a deep dive into certain areas. [35:00.730 --> 35:05.690] It has a theoretical exam, where you have some questions and answers, fairly standard stuff. [35:05.690 --> 35:10.810] And there's a practical exam, where you have a number of different cyber ranges, and you have to be able to accomplish tasks. [35:11.810 --> 35:14.470] As a certification, it's really, really good. [35:14.790 --> 35:22.530] If you don't have all of the skills, the courses that you take will teach you those skills, and they cover a good breadth of stuff. [35:22.550 --> 35:24.910] It's not just how do you do defence. [35:25.410 --> 35:26.810] It's how do you do attack. [35:27.150 --> 35:28.890] How do you deal with organisational issues? [35:29.070 --> 35:31.450] How do you work out budget issues? [35:31.570 --> 35:34.550] How do you work out if it's worthwhile buying this tool versus that tool? [35:34.550 --> 35:37.250] You know, how do you calculate return on investment? [35:37.410 --> 35:38.750] This is all stuff businesses want. [35:38.850 --> 35:40.670] This is all good, good, solid stuff. [35:42.510 --> 35:45.990] The other really good thing about it is that it's free. [35:47.110 --> 35:48.330] It costs you nothing. [35:50.150 --> 35:53.650] Now, it's on the ugly list, because they're still getting going. [35:53.790 --> 35:56.710] I believe at the moment, they're on the third tranche of people coming through. [35:57.150 --> 36:01.090] They only run three or four of these courses a year. [36:01.370 --> 36:06.530] So even if you sign up to the Coursera course, you have to complete it in a set time limit. [36:06.750 --> 36:10.770] If you don't, it's yanked from Coursera, and it's dormant until it comes up again. [36:10.950 --> 36:15.590] And they have a limited intake as well, because they're not dedicated to doing this certification. [36:16.570 --> 36:24.730] The other downside, apart from limited numbers and limited availability, is that, again, no one really knows about it. [36:24.730 --> 36:31.210] Now, within the cybersecurity organisation in the EU, ENISA, they know about it. [36:31.370 --> 36:32.650] They're trying to promote it. [36:32.810 --> 36:36.650] If you're in the EU, you're going to see this becoming more and more visible. [36:36.870 --> 36:38.590] You're going to see it being asked for more and more. [36:39.070 --> 36:41.270] Outside of that, though, no one's ever heard of it. [36:41.630 --> 36:54.250] No one knows what it is, what it does, which is a shame, because it's genuinely one of the really great certifications that helps you gain some knowledge, helps you demonstrate the knowledge, and it gives you a meaningful certification at the end of it. [36:55.250 --> 36:56.310] Keep an eye out to it. [36:56.830 --> 37:02.890] There should be another tranche of training courses available towards the end of this year, I think October time. [37:03.070 --> 37:04.790] Like I say, it's free. [37:05.190 --> 37:06.270] Jump at that chance. [37:06.750 --> 37:08.330] Free, high-quality training. [37:08.690 --> 37:10.130] Don't often get an option of that. [37:12.190 --> 37:12.630] Degrees. [37:13.570 --> 37:14.930] Degrees as a certification. [37:16.470 --> 37:20.170] I'd be remiss, given that we're in St John's University, not to mention degrees. [37:20.170 --> 37:22.410] Degrees are a form of certification. [37:22.990 --> 37:28.610] The fact that they take several years, as opposed to a couple of weeks, doesn't really matter. [37:28.810 --> 37:33.070] You study some stuff, you pass an exam to show you've got the knowledge, you've got to pay for it. [37:35.790 --> 37:40.730] I've personal experience with degrees from Imperial College and Royal Holloway in London. [37:42.330 --> 37:43.910] Absolutely top-notch degrees. [37:44.230 --> 37:56.750] They don't just teach about cybersecurity, they teach about things like social engineering, they teach things like psychology, so you can understand how attackers work, they teach budgets, they cover the entire spectrum of stuff. [37:57.010 --> 38:04.190] In the U.K. and the U.S., the spy agencies, GCHQ and NSA, have both jumped at this and said, actually, we're going to get involved. [38:04.550 --> 38:11.690] And the spy agencies now validate degree courses to make sure they teach a nice breadth of knowledge so that it's relevant. [38:12.770 --> 38:23.250] Additionally, if you fancy being a spy, GCHQ and NSA, keep an eye on the people who graduate from these and it's quite likely you get a job offer from them. [38:23.610 --> 38:24.690] You want to go and work for the spies? [38:24.930 --> 38:25.790] Great way of doing it. [38:27.030 --> 38:33.210] Luckily, I've checked, St. John's University do an NSA-accredited cybersecurity degree. [38:33.750 --> 38:34.190] Excellent. [38:35.110 --> 38:45.130] Now, it's on the ugly list because there's lots of degrees out there that claim to be cybersecurity degrees and are essentially a three-year CH course. [38:45.370 --> 38:47.850] It's three years of here's a tool. [38:48.050 --> 38:51.890] Let's spend an entire semester learning how Burp Suite works. [38:52.510 --> 38:55.870] Next semester, let's look at Metasploit. [38:56.490 --> 38:56.910] Right? [38:57.470 --> 38:59.570] Again, this is stuff you can teach yourself. [38:59.770 --> 39:01.090] It's stuff you can learn over the weekend. [39:01.090 --> 39:02.370] You can watch YouTube videos. [39:02.590 --> 39:08.290] You don't need to be forking out tens of thousands of dollars a year to be taught how to use tools. [39:09.290 --> 39:12.690] So, look at degrees with a grain of salt. [39:12.930 --> 39:15.510] Some of them, like I say, that are accredited, that have been validated. [39:15.990 --> 39:20.350] Some of them, which have a very good reputation in industry, absolutely worthwhile. [39:20.790 --> 39:23.270] The rest of them, colossal waste of money. [39:23.710 --> 39:27.790] And given the cost of degrees, it's not worth going down a poor degree course. [39:29.150 --> 39:30.970] Now, finally, Crest. [39:31.490 --> 39:38.330] You can't imagine how thrilled I was to have written this slide deck and then rocked up and see there's the guys from Crest with a stand here and they're a sponsor of HOPE. [39:39.030 --> 39:39.510] Excellent. [39:40.750 --> 39:42.570] So, what's the issue with Crest? [39:42.950 --> 39:49.410] Crest was originally developed in the U.K. because the U.K. government was hiring a bunch of pen-testers who did all sorts of weird stuff. [39:49.570 --> 39:52.850] And there was no consistent way of testing U.K. government infrastructure. [39:53.330 --> 39:54.530] So, Crest was formed. [39:54.890 --> 40:08.870] Crest is a non-profit organisation and it was designed to essentially have a level of certification for penetration testing and for security assurance so that government departments in the U.K. could say, I've had a Crest certified audit, I've had a Crest certified pen-test, [40:09.270 --> 40:10.870] we kind of know stuff is okay. [40:12.550 --> 40:13.650] All sounds good. [40:14.310 --> 40:20.650] They're practical exams, they test your skill set, it's a good certification to have. [40:21.050 --> 40:22.230] All sounds really great. [40:23.430 --> 40:28.170] However, in the U.K., there's a very large cyber security firm called NCC. [40:28.750 --> 40:31.790] They do the majority of Crest testing for the government. [40:31.930 --> 40:33.330] They are a big, big organisation. [40:34.230 --> 40:37.910] Their director was the head of the Crest board. [40:38.410 --> 40:58.330] About the time when some people posted a whole bunch of documents up on social media that showed that NCC had run a Crest testing lab in their building and that they had course notes and answers and questions and information dumps on NCC-headed notepaper along with a bunch of emails from NCC internally telling people how to pass the exam. [40:59.090 --> 41:00.910] So it's kind of a problem, right? [41:01.110 --> 41:10.730] If you're dealing with security assurance and it turns out that actually one of your biggest, biggest revenue generators for your organisation has been cheating at the tests. [41:11.650 --> 41:12.570] A bit bad. [41:13.470 --> 41:21.850] Now the problem is how does Crest investigate itself when the director of the company that's been accused of cheating is the head of the board? [41:22.970 --> 41:26.050] Bit of an ethical dilemma there going back to ethical hacking. [41:26.770 --> 41:30.990] So what they did was they brought in a third party, an ex-policeman. [41:31.190 --> 41:32.330] He did a review of it. [41:33.270 --> 41:39.370] There was lots of concern in the industry at the time because let's say I'm Crest certified. [41:39.370 --> 41:44.730] Let's say at the time I was working for a small cyber security company they were going for Crest certification. [41:45.090 --> 41:49.010] It was kind of an open secret that people from NCC have been cheating at this. [41:49.470 --> 41:50.430] But what do you do? [41:50.670 --> 42:03.750] If you go public and say the biggest revenue generator and the head of your board their company has been cheating do you think you're still going to have your Crest certification at the end of the day? [42:04.390 --> 42:05.230] Probably not. [42:05.550 --> 42:22.590] And there was lots of worry in the industry about people speaking out about this because if you're a small consultancy or if you're an individual self-employed and you're generating your income by testing U.K. government infrastructure under Crest if something threatens that certification that means you're going to be out of a job and kind of unemployable. [42:23.090 --> 42:24.870] So lots of people didn't speak out about this. [42:25.530 --> 42:26.490] There was an investigation. [42:28.110 --> 42:31.710] One person came forward voluntarily with information. [42:32.410 --> 42:35.910] Now this is an industry that had hundreds and hundreds of people who were certified. [42:36.370 --> 42:40.570] People had openly been talking about this and social media one person came forward. [42:41.950 --> 42:47.530] The result of the investigation was basically something that we've all heard recently in the newspapers and in the news. [42:47.690 --> 42:49.110] There's a few bad apples. [42:50.810 --> 42:53.930] NCC did not get bollocked in any way at all. [42:54.510 --> 42:58.230] The director was allowed to continue as the head of the board. [42:58.930 --> 43:11.930] And in fact the Crest investigation said that despite the fact that it was using an NCC email system, despite the fact that it was in NCC premises, NCC were only vicariously responsible. [43:12.330 --> 43:13.850] They couldn't have known what was going on. [43:14.730 --> 43:15.930] Now this was a few years ago. [43:16.210 --> 43:18.810] They've redone their testing process. [43:19.270 --> 43:20.670] They've redone their certification. [43:20.930 --> 43:23.870] They've rewritten their T's and C's and their privacy notices. [43:25.650 --> 43:28.170] If it wasn't that bad, why do you need to do all of that? [43:28.710 --> 43:30.990] And if it was that bad, why did no one get punished? [43:31.570 --> 43:39.950] So the problem now is that if you've got a Crest certification, there's this sort of aura of unpleasantness about it. [43:40.090 --> 43:44.770] I know a bunch of people who have decided to not renew their Crest certification. [43:44.770 --> 43:49.650] I know a bunch of organisations who've decided they're going to ditch it and they're going to go for the OSCP instead. [43:50.350 --> 43:51.510] This is kind of a problem. [43:51.790 --> 43:53.830] So the certification itself is good. [43:54.230 --> 43:56.930] It has a bit of a bad reputation, certainly in the U.K. [43:57.530 --> 43:59.090] Now Crest are expanding globally. [43:59.310 --> 44:00.730] That's why the guys are here today. [44:00.930 --> 44:02.530] They're expanding into the U.S. and beyond. [44:03.430 --> 44:04.350] Go and talk to them. [44:04.450 --> 44:06.290] Talk about the certification because it's a good one. [44:06.930 --> 44:11.190] But bear in mind that if you're in the U.K., definitely, there's kind of some problems with it. [44:11.930 --> 44:15.490] Now, running out of time, very quickly, warning about the future. [44:15.670 --> 44:18.430] What does certification look like when it goes bad? [44:18.970 --> 44:23.090] In the U.K., we have the Ministry of Fun and you can imagine why they're called that. [44:23.550 --> 44:26.950] They decided to come up with something called the U.K. Cyber Security Council. [44:27.350 --> 44:35.470] We have in the U.K. two institutes under Royal Charter that are enabled to do essentially chartered engineer status for security people. [44:35.670 --> 44:37.690] There's already an organisation that does this. [44:39.410 --> 44:45.910] The U.K. CSC is headed by a guy who is a career NGO person. [44:46.070 --> 44:47.510] He's never worked in cyber security. [44:47.810 --> 44:51.070] There's one person on their board who's got any cyber security experience. [44:51.330 --> 44:54.090] The rest are academics and career advisors for the government. [44:54.430 --> 45:08.890] They immediately launched a consultation that said, we want to see if people agree with us that there should be mandatory certification for every cyber security professional in the U.K. and there should be a mandatory register for every cyber security professional in the U.K. [45:09.550 --> 45:14.570] Now, we spoke earlier on about the different job tiers and how it's a really crap model. [45:15.190 --> 45:16.850] This falls foul of that immediately. [45:17.490 --> 45:18.450] Am I a CSO? [45:18.510 --> 45:19.170] Am I an architect? [45:19.470 --> 45:30.130] Well, if I've got to put my name on a mandatory register and if I have a mandatory certification that says I'm either a CSO or an architect you've crippled my career chances. [45:30.370 --> 45:31.010] How am I going to change? [45:31.130 --> 45:31.510] How am I going to move? [45:31.630 --> 45:32.630] How am I going to sell my services? [45:33.490 --> 45:39.590] It was essentially a poorly thought out plan by people who don't do the job and all it was about was gatekeeping and control. [45:40.750 --> 45:49.170] The agenda from there was we want a bunch of people who know how to use tools and who could be pigeonholed into an organisation and told what to do. [45:49.670 --> 45:55.970] Which is the complete opposite of what cyber security people and hackers should be doing which is root cause analysis problem solving. [45:56.090 --> 45:57.050] How does this stuff work? [45:57.210 --> 45:58.030] How do I break it? [45:58.210 --> 45:59.070] How do I make it better? [45:59.330 --> 46:00.050] How do I fix it? [46:01.910 --> 46:10.070] As with all politicians and career civil servants just because this consultation was defeated doesn't mean it's gone away. [46:10.310 --> 46:12.370] It's going to come back again and again and again. [46:12.850 --> 46:16.610] And this is the dodgy bit of certification and this is something that we all need to look out for. [46:17.390 --> 46:20.570] Certification again is about proving you have the skills. [46:20.570 --> 46:28.290] It's not about controlling and limiting people in cyber security and stopping people with certain backgrounds from entering the industry. [46:29.510 --> 46:34.550] And on that note running out of time very quickly have we got any questions for anyone? [46:38.190 --> 46:41.230] What about governance and compliance the GRC? [46:42.450 --> 46:43.510] Sorry, I couldn't hear that. [46:44.330 --> 46:48.110] What about governance and compliance of that level? [46:48.250 --> 46:49.110] The GRC? [46:50.050 --> 46:52.150] Yes, I've completely missed GRC. [46:53.350 --> 47:01.510] That could almost be its entire own section to be honest because in the way that offensive and defensive security is kind of like its own industry. [47:01.690 --> 47:03.870] I'd say that GRC is its own industry as well. [47:03.990 --> 47:07.410] You've got auditors, you've got people making policy, you've got people enforcing policy. [47:08.130 --> 47:10.090] It's a very complex mix. [47:10.510 --> 47:18.930] But I would say again the organizations that provide good certifications they will provide good certifications in the GRC space as well. [47:19.470 --> 47:29.350] So ISACA do an auditor CISA one again pretty highly rated comparable with the CISM as well for that sort of stuff. [47:29.550 --> 47:31.110] So there's some comparisons there. [47:31.890 --> 47:33.830] Alright, we've got a quick question from the chat. [47:34.130 --> 47:38.910] What do you think about sitting for an exam like CISSP even if you don't meet all the other qualifications? [47:40.930 --> 47:44.090] What do you think about sitting in the CISSP if you don't meet the qualifications? [47:47.350 --> 47:51.690] Why pay for an exam if you can't get the certification at the end of it? [47:52.010 --> 47:53.610] I mean, that cash is coming out of your own pocket. [47:55.110 --> 47:57.530] I'd rather spend that on rum and ice cream to be honest. [48:01.210 --> 48:07.330] If you take the exam and you pass it how are you going to present that to an employer or in a workspace? [48:07.650 --> 48:10.270] Oh, I took the exam and I passed it but I don't have the qualification. [48:10.790 --> 48:14.090] People are then going to say okay, so you're not certified. [48:15.210 --> 48:15.730] Reject. [48:17.150 --> 48:21.830] You know, the goal is should never be to pass an exam. [48:22.230 --> 48:24.970] The goal should be to demonstrate you've got the knowledge. [48:27.270 --> 48:28.110] Any other questions? [48:30.070 --> 48:32.450] What do you think of renewals or recertification? [48:33.510 --> 48:35.870] What do I think of renewals and recertifications? [48:39.510 --> 48:44.690] On the one hand they're a bit of a pain in the arse because you've got to make sure that your knowledge is up to scratch. [48:44.910 --> 48:45.930] You've got to reset an exam. [48:46.130 --> 48:49.310] You've got to be able to prove that you're constantly being able to educate yourself. [48:49.750 --> 48:54.510] On the other hand it's a really great idea because it forces you to keep up with industry knowledge. [48:54.510 --> 49:07.590] It forces you to keep up With changing technology, it forces you to demonstrate that you haven't just passed an exam and then left it to Mulder, you've continued to educate yourself, and you can demonstrate that by proving you've taken courses, read books, [49:07.710 --> 49:08.570] read articles, whatever. [49:09.310 --> 49:12.690] So, annoying, because I have to do it. [49:14.150 --> 49:24.690] But at the same time, good, because it forces you to continually keep yourself at the cutting edge and continually keep yourself abreast of changes in education and things. [49:26.830 --> 49:28.790] All right, we've got time for one last question. [49:28.970 --> 49:29.510] There we go. [49:29.810 --> 49:30.690] Lucky last. [49:30.910 --> 49:35.890] Iceberg C won't actually let me sit for the CISSP, despite meeting all the requirements. [49:36.310 --> 49:38.790] Can you recommend something that's equivalent but different? [49:39.470 --> 49:40.910] Ooh, equivalent but different. [49:41.070 --> 49:44.610] I would say the SANS GISP. [49:45.910 --> 49:48.890] I would put that firmly as equivalent to the CISP. [49:49.690 --> 49:52.430] Like I said, there's issues about visibility. [49:55.470 --> 50:01.430] But if for whatever reason you're being blocked from actually taking the CISP exam, go for the SANS ones. [50:02.310 --> 50:04.050] People who do know them have a good reputation. [50:04.310 --> 50:12.970] And if people don't know them, it's an opportunity for you in an interview or when talking to people to say, look, you know, there were some issues with the ISC, I couldn't take the CISP, so I took the SANS one instead. [50:13.530 --> 50:14.990] Here's the equivalence of it. [50:16.950 --> 50:17.830] I'd go down that route. [50:19.990 --> 50:20.350] Right. [50:20.350 --> 50:21.070] We've run out of time. [50:21.490 --> 50:21.730] All right. [50:21.850 --> 50:23.290] Thank you, Tom, for the excellent talk. [50:23.530 --> 50:24.190] Thank you very much. [50:28.790 --> 50:35.970] And any materials from the talk that Tom wants to post, we posted in the chat, the Discord chat channel for this talk, so you'll be able to access them. [50:35.970 --> 50:38.610] Come back at three o'clock for the talk. [50:39.490 --> 50:40.930] Hcapsha, profit over people.