Tuesday, July 26, 2016

Russian Foreign Policy Turns on a DIME (Diplomacy, Information, Military, Economics): An Interview with Dr. Stephen J. Blank

 

The weather was just the first treat on July 19th when I arrived in Washington, D.C., at the Capitol Hill Club on that cool, dry and sunny morning to hear Dr. Stephen J. Blank deliver an address, Russia’s Global Probes. Like a luxury cruise ship, Dr. Blank navigated his remarks with expert engineering, using sophisticated instruments that work below deck to produce a smooth sail and memorable journey. His talk docked in three parts of the globe – Latin America, the Middle East and Europe. In each port of Russian activity, he delivered his audience reality-checks on Russian history in the region, Vladimir Putin’s objectives, Russia’s intrinsic nature, and the problems for U.S. national security with projecting American values into the interpretation of Russia’s undertakings. With the temporal breadth of a skilled historian of Russian, Soviet and post-Soviet affairs, Dr. Blank portrayed a crisp yet comprehensive snapshot of the world today through the Russian lens. He deftly decoded Russian behavior and Vladimir Putin’s positions, leaving his listeners sobered and empowered with a ready frame of reference for understanding and interpreting Russian diplomatic, information, military and economic operations. 

 
Dr. Blank and I then returned to his office at the American Foreign Policy Council for an interview. His generosity continued. A former professor of Russian National Security Studies and U.S. National Security Affairs at the Strategic Studies Institute of the US Army War College, he rolled up his sleeves and got to work informally as if my viewers were students there with him in his private office hours. Here are excerpts.
 
BERNARD:  I heard U.S. Secretary of State John Kerry assert that "nowhere is there a greater hotbed or incubator for these terrorists than in Syria," as he wrapped up meetings in Moscow with Russian President Putin and Foreign Minister Lavrov exploring U.S.-Russian cooperation to end the five-year civil war there. Reports are conflicting about the outcome of their talks and the possibility at all for military cooperation and intelligence-sharing. As an old Cold Warrior, it's not my first instinct to imagine us "sharing" intelligence with the Russians or "cooperating" militarily. Yet, the Syrian situation is compelling.  What's your take on all this? 
 
 
BERNARD: My clients at SecuritySpeak include global investors, businesspeople and entrepreneurs.  Some are exploring markets and opportunities in the energy and other resource-rich regions of the former USSR.   How stable is Central Asia today?


 
BERNARD: My clients at SecuritySpeak are concerned about threats like North Korean missile strikes and cyber-attacks.  What do you see as the Russian role in these scenarios?
BERNARD: In four months, we Americans will elect ourselves a new President and Commander-in-Chief.  What frame of reference can you offer him or her for advancing American and global security interests?

 
BERNARD:  Thank you, Steve, for your insights, time and energy.  I know you have an interview with Romanian TV journalists at noon and you're only just back from delivering a master class in Brussels last week.  It was a pleasure attending your address this morning at the Capitol Hill Club and speaking with you here now.
 
To arrange a presentation by Dr. Blank for your firm, association or university, contact Lisa Bernard's SecuritySpeak, LLC at 203.293.4741 or LisaBernard@SecuritySpeak.net. 
 


 
 



Sunday, June 19, 2016

Terrorism in America: A Reality Check on the Surreal


 
Sunday, the 12th of June, was surreal.  I was outdoors in the fresh air and morning sunshine reading Holy War on the Home Front: The Secret Islamic Terror Network in the United States in preparation for my interview with its author, Dr. Harvey Wolf Kushner, Director of the Homeland Security and Terrorism Institute at LIU Post.  When I left for work early that morning I had heard about "a shooting" in Orlando.  By lunchtime, I learned that the attack was at an LGBTQ nightclub, had been declared an act of terrorism and the death toll was climbing. News outlets reported that the terrorist declared his allegiance to ISIS at the outset of his rampage.  My heart was racing as I tried frantically to recall where my gay family members said they would be over the weekend.  There were more ironies than I could process, including that I left this book for last in my reading of Dr. Kushner’s publications.  Why?  Because, I reasoned, it was published in 2004 and now it is 2016, and surely things have “changed.”  I would read it – but last and leisurely on the Sunday before the interview.  By the time I got home to hear President Obama’s address to the nation, it was all too clear that Harvey Kushner’s book is still pertinent in 2016.  Words from his Introduction were haunting me, “I chair a department at a university, but I quickly learned that when dealing with terrorists that death is not academic.  Terrorists kill people.  They pull triggers, plant bombs, and blast holes in the NYC skyline.”  
Like so many Americans, I am forlorn and on Tuesday, June 14th, when I walked into Harvey Kushner’s office, I couldn’t hold back.  “These terrorists are playing ‘soft-target roulette’ with us,” I proffered.  “That’s what’s got us feeling anxious.  The Boston Marathon, San Bernardino, and now Orlando …. We get it.  While we are exercising, recreating, and socializing – precisely to blow off stress – we are actually most vulnerable to opportunistic terrorists.  We don’t need to be flying or on the high seas.  That is what is now so unnerving.”  A genial host and gracious respondent, Harvey Wolf Kushner immediately delivered the perspective available only from one with the breadth and depth of counter-terrorism experience his forty-plus years of service provides.  From the 1972 Munich Olympics Massacre, through the bombing of Pan Am Flight 103 at Lockerbie, to the mass shooting in Orlando, Harvey Kushner embodies his book, Encyclopedia of Terrorism.  The walls of his office are alive with commendations and warm letters of appreciation for his service from elected officials, representatives of allied governments, those in law enforcement at all levels, as well as branches of the U.S. military and federal agencies. I couldn’t help but note how fortunate his graduate students are to study with him and the notable faculty he has assembled from among the best professionals actively engaged in counter-terrorism. Congress declared his institute a National Security Center of Excellence. 

I asked for twenty minutes but Harvey Kushner gave me a full afternoon of his time as he responded to my questions and the concerns of my followers at Security Briefs.  I left the interview wiser, more insightful and crystal clear on one thing:  Dr. Harvey Wolf Kushner is, and has been, unabashedly devoted to one goal: keeping civilians safe from terrorists. Here are some excerpts. 

BERNARD:  I read in your 2004 book that "[m]ost say even three years after 9/11, the FBI and related federal intelligence and law-enforcement agencies still don't 'download' real-time-information to local agencies."  I am hearing that very same thing in the analyses of the Orlando Massacre in 2016. Is this so and why?

 

BERNARD:  We heard it with the Tsarnaev brothers, Nidal Hasan and now again with Omar Mateen - they "fell off" the FBI's watch list.  How does such a thing happen in the post 9/11 era and what does this portend for "lone wolf" attacks?


 
BERNARD:  My followers at Security Briefs are educators, retail executives, medical professionals, practitioners in law and accounting, clergy, and other concerned citizens who are responsible for other people - their students, clients, customers, congregants and families.  What steps can they take to make their workplaces and social spaces are more secure?
 
 
BERNARD:  In a Q&A Session with former Newtown Chief of Police, Michael Kehoe, I heard him underscore the importance for local law enforcement to maintain "informal" communication with first responders and emergency management professionals at all levels - county, state and federal.  In short, you need your crisis management allies to be just a cell-phone call away.  Your reaction?

 
BERNARD:  Many of my followers at Security Briefs are professionals in human resources, law, the military, financial services, IT, etc., who are considering applying their expertise in a different capacity in the next phases of their careers.  Others are parents of college-bound kids considering their first-career options.  What are the job and career prospects for those interested in counter-terrorism?


 
BERNARD:  In seven months, we Americans will inaugurate a new President and Commander-in-Chief.  What guidelines would you offer her or him?

 
 
BERNARD:  Harvey Kushner, it is good to know you. Thank you for your service and for your thoughts and candor this afternoon.
 
Lisa Bernard is Founder and President of Lisa Bernard's SecuritySpeak, LLC, a speakers bureau devoted to educating people from all walks of life on matters of national, global and cyber-security.  To discuss your need for a guest speaker, contact her at LisaBernard@SecuritySpeak.net or via phone at (203) 293-4741.

 

 
 

Wednesday, June 1, 2016

Scott N. Schober's HACKED AGAIN Earns its Place on the Permanent Bookshelf


HACKED AGAIN:  It Can Happen to Anyone Even a Cybersecurity Expert, ISBN 978-0-9969022-1-2, by Scott N. Schober, 2016.  Available on Amazon for $14.95 in paperback.
HACKED AGAIN makes a welcome contribution to our cyber-security literacy.  This easy-to-read, Tiger’s Eye of a book, is a must-have and must-keep-handy tool for becoming and staying conversant on cyber-safety matters.  If you head a firm or family, but feel too busy, anxious or uncomfortable to learn about your cyber-security, let Scott N. Schober make your foray manageable.  A software engineer, inventor and CEO of a wireless security tech firm, he writes in personal voice and reveals his own frustrations, curiosity and reflections on the risks of contemporary cyber-spatial life.  He chronicles his own learning curve, from his original vulnerabilities stemming from being human, to the victimization of his firm via the exploitation of technologies by cyber-thieves.   Investigating hacks against himself and cyber-crimes against his firm, Mr. Schober is a modern day Sherlock Holmes working the clues, tools, evidence and psychologies of all the players – hackers, institutions and victims.  He is a clever and humble private eye with the public’s interest at heart.  For each of us with a cyber-spatial footprint, from simple social media profiles to email accounts to complex e-commerce platforms, HACKED AGAIN is more than a primer.  It’s a mentor for learning the lingo and the ropes and replacing the generalized anxiety we have about cyber-security with basic competence.  In less than 200 pages, we non-techies can feel more confident about managing our digital footprints as sensibly and routinely as we protect our brick and mortar offices and homes.   
My recommendation is to start at the end with Mr. Schober’s carefully composed glossary which removes the first obstacle to individual cyber-vigilance – the language barrier.  If you feel that the lexicon of cyber-security is as confounding as the topic itself, rest assured that this glossary demystifies terms from the “bot” to the “TOR.”  A handle on the acronyms and jargon will immediately improve the ease with which you process news, instructions and information on cyber-security matters.  Then I suggest going back to Part I to piggy-back Mr. Schober on his journey.  He grows from ignorance through denial and into reality and reconciliation with what is now, for all of us, the “new normal” of personal, professional and civic life in our cyber-spatial world.  In Part 2, he prescribes behaviors and protocols to minimize one’s vulnerabilities and risks.  He concludes each chapter with useful mini-summaries, one paragraph “Quick-Tips” that you can apply or adopt immediately.   Particularly helpful are those that are counter-intuitive and thereby especially eye-opening and cyber-protective.   One such tip is “Do not click on the bottom of a spam e-mail and ask to be removed from the ‘Do Not E-mail’ list.  You will likely receive more spam because hackers now know you are a real person and will then sell your name for more money to other spammers.”  A reasonable person might think that eliminating their name from such a list is wise and lessens their unintentional digital footprint when, in fact, it expands it and their vulnerability.  They become more likely to be cyber-stalked and have their social media accounts mined for data and clues to their passwords. 
In his latter chapters, Mr. Schober expands his probe to our challenges as a society that shops with credit cards, banks online and works in cyberspace.  In an apolitical and non-judgmental manner, he assesses the dynamics of headline breaches and hacks like those that bedeviled so many at Target, JP Morgan Chase and Sony before moving on to threats we face as a cyber-warrior nation starting with the U.S. government’s Office of Personnel  Management.   Perhaps most meaningful for us laypeople, is that at no time does Mr. Schober lose sight of the human factors or toll as he explains the technological components of these violations and the news coverage of them.  This is among Scott Schober’s most valuable and consistent contributions to this field – he puts a human face on the subject of cyber-security in all its facets.   And it is an accessible and welcome one.  

HACKED AGAIN leaves room for a future edition as Scott Schober nimbly wrestles the next generation of cyber-technologies, schemes and malicious hackers.  Going forward, I hope he adds an index to the book to expedite the many references I see in my copy’s future.   HACKED AGAIN is a hard-copy keeper and will be dog-eared on my bookshelf until its sequel comes along.   

Thursday, May 5, 2016

Get Smart: Learn your Cyber Risk in Under an Hour


 
Do you run a small to mid-sized firm, non-profit or department not yet as focused on cyber security as you need to be?  You’re not alone.  And, help is available.  I’ve been sharing with clients word of the impressive Confidential Cyber Risk Assessment (CCRA) being offered by Marc Groz ‘s firm Right Risk, LLC, and realized how many of my readers here might benefit from exploring this as well.  Marc is an authority on risk and financial markets, with a special focus on cyber and systemic risks.  He brings a unique experience profile to Right Risk, having served in senior risk, technology, and research roles for well-known hedge funds and a multi-billion-dollar asset manager.  I welcomed Marc to my interview seat to get a better sense of Right Risk’s cyber risk assessment for managers like you.  The following are excerpts from our talk. 

BERNARD:  Welcome back to Security Briefs, Marc.  In your promotional material you mention “the experts” at Right Risk involved in your CCRA offer.  Who are these experts and what do they deliver specifically?

 
BERNARD:   You have a powerful team at Right Risk and this is a sophisticated assessment, Marc.   Practically speaking, how does it work?  It sounds like a team of cyber-warriors will descend on the office in Ghost-busters gear and start frantically scanning all the computers and tablets.  Please clarify this for us. 

 
BERNARD:  If my readers want to take advantage of this offer, how do they get started?

 
BERNARD:  Thank you, Marc.  I know you’re speaking today on cybersecurity in salon format at LaunchTalk  so I especially appreciate your time. 

To learn more about Marc Groz and his availability for briefings and presentations see his biographical profile at www.SecuritySpeak.net or email LisaBernard@SecuritySpeak.net.

Wednesday, April 20, 2016

If Only It Were Sci-fi: CEOs, CFOs, COOs and Cell Phone Vulnerabilities

Like many of you, I ease back into the workweek on Sunday evenings getting a jumpstart on things with 60 Minutes in the background giving me a heads-up on developing matters here and abroad.  This Sunday, Sharyn Alfonsi’s segment, Hacking Your Phone, jolted me back to business.  If you missed the program, here’s the takeaway:  your smart phone is defenseless against hacking and executives are particularly targeted.  Watching a U.S. Congressman’s mobile phone hacked in seconds, I reacted childishly – hoping it just wasn’t so.  But when I reached out to my speaker, Robert Bigman, former CISO of the U.S. Central Intelligence Agency – under whose watch the CIA was never hacked – I learned that, in fact, that our mobile phones and their networks are, indeed, entirely vulnerable and for simple reasons.  I asked him what my clients and readers need to know and what they can do to protect the privacy of their calls and their clients' information discussed in those conversations.  He shared:

It has been recognized for some time now that while cell (smart) phone is a new technology, the protocols that it uses to maintain wireless sessions, collect and communicate caller/device meta data and interface with the "wired" world, is decades old software and replete with vulnerabilities.  These "wired" world protocols (collectively known as Signals System 7), lack session authentication/integrity mechanisms and thus, are subject to call spoofing and redirection attacks. 

Cell phone users should also understand that while the "smart" devices contain incredible processing and communication capabilities, they are no more secure than your desktop/laptop computer running Windows or Linux operating systems.  Smart phones, like other computers, lack trusted "boot" protection, are written in coding languages that facilitate vulnerabilities, and allow applications to run that also expose the computer's operating system to memory exploitation. 

Your best bet for securing cell phone conversations (although far from guaranteed) is to use a separate/dedicated phone device with only an encrypted Voice Over IP (VOIP) application that, hopefully, satisfies the Federal standard for system cryptography (NIST FIPS Pub. 140-2).

Here's the link to the story:  http://www.cbsnews.com/news/60-minutes-hacking-your-phone and a link to Bob's full bio at www.SecuritySpeak.net.

 

Saturday, April 2, 2016

As Washington Hosts World Leaders at the Nuclear Security Summit ...



I asked Dr. Paul Bracken, author of the tour de force book, The Second Nuclear Age: Strategy, Danger and New Power Politics, for a comment. He replied:
 
 
The pace of military technology has reached a level not seen since the cold war in the 1950s.  Drones, cyber-war, targeted killings, anti-satellites weapons, hypersonic missiles are coming into the forces not just of the United States but of many countries.  Add to this atomic weapons, and soon, hydrogen bombs for India, Pakistan, Israel, and North Korea.  We are entering a new world of technology, yet the old political order of nation states remains essentially unchanged.  The 2016 Nuclear Security Summit shows the growing tension of a political order that is out of phase with technology advances.  Something has to give, and I don't think it's going to come from a slowdown in technology.
 
 
Scroll down for video of Dr. Bracken speaking to the North Korean missile program, STEM, emerging technologies and other key topics in security.

Security Synonyms: Planning, Preparedness & Perspective - Take One



 
The passing of Andrew Grove hit me personally.  Not that I ever met him, but I quoted his words of wisdom each time I gave a motivational address to professionals in legal, financial planning and accounting services:  “You need to plan the way a fire department plans.  It cannot anticipate fires, so it has to shape a flexible organization that is capable of responding to unpredictable events.”  Years back, in the aftermath of my family’s tragedy, via platform speaking, I prepared professionals to steward their clients through “the unthinkable” - and to do so with clarity, compassion and responsibility.  In other words, keeping their eye on the ball as others panic, grieve and recover.  In this spirit, on Friday 1 April,  2016, I was especially moved to interview Security Professional and ASIS International, Southern CT Chapter’s Co-Chair, Lex Giannini, on practical planning for the real issues at stake during a terrorist attack, natural disaster, or other crisis with human casualties.  Do stay tuned as I share Mr. Giannini’s insights in this space via excerpts over the next weeks.  This interview has resonance for us in our professional, community and family roles.