My cyber security journey – Jack Best
In this article, we interview Jack Best, Securious Cyber Security Consultant, about his role and journey into and through cyber security.
What is your role at Securious, and what does it involve?
I’m a Cyber Security Consultant, so I do a bit of everything – particularly on the Cyber Essentials and penetration testing side of things. I’m also called in to help with ISO 27001 as needed.
Tell us more about your role as a penetration tester?
I’m involved in the whole process, from first meeting the client right down to actually performing the test and doing the reporting. We use a framework with five stages – scoping, reconnaissance, exploitation, cleanup and reporting.
The scoping stage I find really interesting, as some people don’t fully understand what penetration testing is or how it’ll help them – often, they’ve just been told by someone that they need a pentest, so that’s what they ask for, but they aren’t really sure what to expect.
So the initial scoping call might start off with giving them an overview of what pentesting is, how it works and how it’ll help them. I always try and clarify the objectives of the pentest too, to make sure we’re testing the right things. I explain the whole process to them and make sure we’re all on the same page. Sometimes they expect a reward or an outcome from the pentesting – I was once asked whether they’ll get a certificate once it’s done. But it’s not like that – the benefit of pentesting is knowing where the flaws are in your systems so you can fix them.
During that scoping session, we agree on what will be tested and why, and we confirm the technical scope. I need to know exactly what I’m testing and that the client gives permission for me to test it – this is a legal requirement.
Then it comes to the actual testing, which is different for every client. Depending on the scope, it’ll take upwards of a day of my time and up to multiple weeks. This is followed by cleanup, to ensure I don’t leave anything damaged or less secure than when I started; and reporting, which (for the way I gather evidence) involves a great deal of information collation and processing and then an attempt to describe the issues with regular human words without the techno-jargon.
And what about your role in helping clients achieve Cyber Essentials?
Sometimes I review Cyber Essentials level one applications (which are self-assessment questionnaires). This means I look at our clients’ responses and give them feedback on them.
The funny thing is a lot of the time, issues come from questions not being read properly – it’s not always technical things that are wrong. Some people find it hard to understand what the question is actually asking them, so don’t necessarily answer it appropriately. It can make me feel like I’m an English teacher.
Reviewing the Cyber Essentials questionnaires can be frustrating, but very rewarding. Especially when it’s for people who don’t have a huge IT knowledge already. You can see they’re taking things on board, asking questions and learning about the process. You can see someone who isn’t a cyber security professional taking it seriously and doing their best to use the process to improve their systems.
What made you go into cyber security?
When I was thinking about what I wanted to do as a career, I saw Computer and Information Security and knew that it’s employable. And within that, cyber security was something I could see becoming more and more relevant. With the growing use of computers, it just made sense that cyber crime would expand with it. I also knew that there’s no substituting a human brain when it comes to fighting off these attacks – it’s a role that you can only automate to a certain extent and therefore I knew I wouldn’t be replaced by a computer in a few years.
My favourite area during my studies was forensics, which involves looking back and breaking down what an attacker did and seeing how they tried to hide the evidence. It’s really cool and interesting, but surprisingly it doesn’t happen that often – certainly not as much as it should. When there’s a cyber attack on an organisation, usually they’re just focused on getting things back running. Very rarely are they going to try to figure out who did it because it’s just not cost-effective.
What do you like most about your role now?
It’s like you’re presented with a new puzzle toy each week. You get given a Rubik’s cube to solve and as soon as you’re finished they hand you the next puzzle. You’re always having to think in different ways, investigate and figure out how everything works.
Do you have either a piece of advice or a comment on a common vulnerability or issue that you see often in businesses?
Yes. The main piece of advice is that security bolted on is not security. You can’t slap it all at the end, and then call it a day. Well, you can but it’s going to cost you a lot more in the long run. Why would you fully build something, then get it tested and realise it’s broken? It just means that you’ll have to rewrite a lot of things and that’s quite a pain. Security built in as it’s required should the done thing, and it’s crazy to me that it’s not like that.
I had thought that maybe this was a new idea, so it’s just taking time for businesses to adopt it, but the Secure Software Development Life Cycle (which is all about embedding security from the start) was established in the early 2000s. So it’s not a new idea and there’s really no excuse for leaving cyber security as an afterthought.
Could you tell us a little bit about what you do outside of work?
I’m quite boring really. I’ll occasionally play underwater hockey, but COVID stuck around a lot longer than we expected so I’m not as fit as I once was. I’ve been playing badminton and I go to the occasional octopush tournament. I’m also a big fan of eSports and tabletop role playing games. Exciting stuff!
Do you have any final words of wisdom?
There’s always a way you can improve your security. Sometimes I support the team with the Cyber Essentials Plus process (where Securious verifies the responses a client gave on their level 1 self-assessment questionnaire), which involves either going on-site or doing a remote assessment.
This is great for security hardening – even people who have systems in place for patching and dedicated sys admins have vulnerabilities. We’ve only seen one company in the past four years that had no vulnerabilities, and we were gobsmacked. It almost never happens.
One of the interesting things is that often, when people have vulnerabilities, it’s not because they lied on their initial self-assessment questionnaire. They might think they have everything in place they’re meant to, but stuff slips through if you don’t test it. For example, they have all the right antivirus and when you open it up all the settings look good. But when you actually go to test it, you find it’s not working properly and won’t stop malware from being downloaded. And that’s why these external audits are so helpful to people. Because you wouldn’t think to test your antivirus. You’d just make sure all the right settings are there and assume everything’s fine.
It makes you realise that your security hardening doesn’t end and never ends. There’s always something you could do better.