Site navigation

Scot-Secure 2023 | Delivering Impactful Cybersecurity Workshops

Thom Carter

,

Scot-Secure 2023 | Delivering Impactful Cybersecurity Workshops
Glean’s Head of Engineering, Gwen Diagram, says you don’t have to be a cybersecurity expert to deliver valuable security workshops, nor do you need to work in security to attend. At Scot-Secure 2023 she explained why, on top of offering an assortment of accessible workshop ideas along with actionable advice.

“Security isn’t something that’s only meant for the few,” said Gwen Diagram with a resolute conviction, as she delivered her compelling keynote to over 300 attendees at DIGIT’s Scot-Secure 2023 event in Edinburgh. “Security is something that most people in tech — and outside of tech, too — want to learn about; it’s a mystery to most people.”

The need for sufficient cybersecurity knowledge and awareness is abundantly clear in the contemporary workplace: without it, all staff — at all levels — are susceptible to further facilitating attacks and issues. For instance, according to research undertaken by telecoms giant Verizon in 2022, the human element is the root cause of 82% of data breaches.

Meanwhile, for those working in tech teams themselves, gaining a deeper understanding and working knowledge of security will only ever help them in their own work — whether they’re engineers, developers, or serving in another role.

But what can you — as a founder, a CTO, or just as somebody passionate about bolstering your business’ cyber defences — do to help ensure cybersecurity is better appreciated and understood in your organisation?

Diagram, who’s Head of Engineering at Glean, the personal study tool, is a staunch advocate for anybody interested to deliver cybersecurity workshops themselves — and it’s actually easier to do so than one might think. In her keynote, Diagram herself was wholly transparent in the fact that her expertise largely lies elsewhere — including testing — but that doesn’t stop her from delivering an array of impactful security workshops, and it shouldn’t stop you either. In fact, by delivering cybersecurity-focused workshops at previous organisations like Sky, it’s actually helped Diagram to upskill her own cybersecurity know-how.

Here’s a selection of some of Diagram’s workshop suggestions, as part of her Bringing the Party to Cybersecurity keynote. (And — to clarify — the party? It’s everybody else that you work with.)

Laying the Groundwork for Effective Cybersecurity Workshops

First of all, and before digging into some of the actual workshops you can facilitate, a word of advice: Don’t try creating — and then delivering — cybersecurity workshops on your own. “You can totally do it on your own, but it’s a really great opportunity to train people up,” Diagram suggested.

If you’re sure of your own cybersecurity skills, you can pull in folks to help out, thereby upskilling them. But if you’re underconfident, you can lean on the expertise of your more knowledgeable colleagues. “Some of the people I’ve gotten involved in organising and running these workshops include proper security specialists — who were amazing because they helped me so much — to architects, compliance officers, and even IoT support.”

Once you’ve landed on who’s involved with the organising of the workshop, it’s then time to consider how the workshop is going to take shape and be delivered.

To make the delivery of cybersecurity workshops accessible by and to all people, Diagram’s workshop suggestions have “really minimal setup — and most importantly, for me, required minimal knowledge of the systems at hand, while also providing people with information about how they can improve in the future.”

Here are some (read: a non-exhaustive list) of the workshop ideas she mentioned.

Juice Shop

Diagram’s first suggestion was to have a workshop oriented around Juice Shop — the “modern and sophisticated insecure web application” which “contains a vast number of hacking challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities,” the OWASP Foundation’s website says.

“I cannot express how useful this application is,” Diagram said, authoritatively. “What’s really good about Juice Shop is it’s free and open source, and is really, really easy to install — you can install it from source, as a package, or as a Docker image. It has easy-to-follow instructions, so if there’s someone who’s a little bit less technical, they’ll still be able to do it,” she said.

Further, “it’s self-contained, so it’s not dangerous — which is very important. And it’s self-healing as well, so if you totally trash it, it’s okay; it’ll recover. Also, it has gamification, which is how you get people really excited about it. You can measure progress and check off what vulnerabilities people have found.”

Diagram also stated that Juice Shop is valuable to run at companies where folks are working on several different applications. “I ran this at Sky, and it was really useful because I had people attend from multiple different departments that worked on completely different applications,” she noted.

However, Juice Shop not being application-specific also results in a notable downside. “It’s really fun, and it gives people some skills in being able to hack systems, but often not in the language that people are actually writing in,” Diagram added.

War Games

War games, in this context, are games where competitors are challenged to exploit or defend a vulnerability in an application or system, or gain entry to or prevent access to it.

“This is where I got a compliance officer and IT support engineer involved,” Diagram prefaced, again referring to the fact that creating and delivering impactful cybersecurity workshops often necessitates collaboration. In terms of how the war game was framed, “one of our suppliers had a security breach, and we had the people that came to the workshop pretend that they were dealing with an incident,” Diagram said.

Diagram reflected that war game cybersecurity workshops are particularly good for building deeper bonds with people outside of engineering.

However, she advocates for being really intentional and thoughtful about the scenarios you drop attendees in — a lesson Diagram learned first-hand. “Some of the engineers decided that they didn’t really need to do much about the incident besides telling our customers and resetting passwords if needed, because I had set it up as a supplier. So you might have a better idea for a war game.”

The Elevation of Privilege Card Game

Designed by Adam Shostack and sold by Agile Stationary, Elevation of Privilege is a bespoke card game used to introduce developers to threat modelling — a process where vulnerabilities or a lack of safeguards are identified and assessed, and where remediation methods are then prioritised.

Diagram mentioned that running the game is particularly useful — and “works so much better” — on a real application. “In the past, I’ve run this game using Juice Shop as the software under attack,” she added.

When it comes to Elevation of Privilege’s advantages, Diagram said that it’s a “really fun way for people to think about the application from a great number of threats. When I ran [Elevation of Privilege] on a real application, we found some pretty severe privacy issues […] we wouldn’t have realised without playing this game.”

Cons-wise, some initial clueing-up on how Hearts, the card game, works may be needed — Elevation of Privilege runs on a similar concept to Hearts. Further, “running the game is hard to do at first — you need to practise. […] It’s not the easiest, but it is really useful once you get it to work.”

Also, you’ll want to make sure the deck you buy contains the threat record cards to more effectively tally up the scores, among other benefits. Finally, “there are some really .NET-specific issues in [Elevation of Privilege], and they’re just not relevant to a lot of applications.”

OWASP ZAP

OWASP Zed Attack Proxy (ZAP) is an open-source web application security scanner, used to identify security vulnerabilities during development and testing.

“OWASP ZAP — it’s really cool, but it’s pretty meaty,” Diagram acknowledged. It’s used by experienced penetration testers to perform security testing, perhaps highlighting a certain complexity.

Considering this, if you’re interested in delivering a workshop oriented around ZAP, this is one of the moments where leaning on the expertise of security experts in your team or wider circle comes in handy. “It’s pretty difficult to run a workshop when you don’t know what you’re doing with the error messages,” Diagram noted. “So I got my security specialists to help, which helped me a lot. […] Getting someone who knows what they’re talking about here is really, really useful.”

In terms of pros, “it’s low-hanging fruit using Spider with OWASP ZAP,” Diagram said. Spider is a ZAP addon and tool that’s used to automatically discover new URLs. To boot, “it’s really easy to install.”

However, “to actually use OWASP ZAP properly, you need to use it quite a bit — it’s fast,” Diagram mentioned.


Recommended


Threat Modelling

“Threat modelling is one of the most important things you can do for your application,” stated Diagram, as she began to go deep into the topic of threat modelling, and how to host a cybersecurity workshop around it.

“There are a couple of ways that you can handle [threat modelling workshops]. Either, you can provide the data flow diagrams up front, or you can hold a longer workshop for people to actually consider the data flow models within the application under test. This is a really good opportunity to get your architects involved as they should have a really good understanding of how data moves throughout the application,” Diagram advised.

To really maximise the learning experience and value for workshop attendees, factoring in the evolved STRIDE framework, STRIPED (Spoofing, Tampering, Repudiation, Information disclosure, Privacy, Elevation of privilege, and Denial of service) into your threat modelling-focused workshop is key.

On delivering a threat modelling-oriented workshop, Diagram said: “One of the things that I’ve really loved doing with threat modelling is using personas. […] It’s a great way for people to get in the minds of attackers.”

Speaking to the advantageous elements of such a workshop, Diagram explained: “Some of the pros of threat modelling is that it gives people a way better understanding of the application that they’re working with. It creates a different point of view for people to understand how people could actually attack their application.”

That said, “it’s a lot of work to set this up.” Similarly, one of the other negatives Diagram called out is that “you’ll also need to explain a lot of things to people before getting started, such as STRIPED and personas.” But, Diagram advocates to push through. “I think the cons are worth it though, as it’s definitely one of the most useful workshops that you can create.”

Cybersecurity Is For Everyone

Diagram’s keynote was as informative as it was enthusiastic; and from a vantage point at the back of the Biosphere hall at Edinburgh’s Dynamic Earth, it was undeniably noticeable just how many folks — both cybersecurity experts and those newer to the sector — were enjoying her accessible guide to hosting cybersecurity workshops.

As the talk began to wrap up, Diagram stated: “Overall learnings for this: People want to learn more about security. These [cybersecurity workshops] are the most successful workshops I have ever run, and I would highly recommend running them.”

But what if you’re now highly invested in running cybersecurity workshops, but too time-strapped? Diagram suggests that you “find some loudmouth that likes running workshops,” she said, smiling. “If there’s someone like me at your company, grab them and convince them that running security workshops is great and you’ll support them. […] You can make it as difficult or easy to run as possible. […] Give it a go.”

Ultimately, Diagram’s keynote wasn’t just a succinct, smart lesson in how to create and deliver impactful cybersecurity workshops to groups: it was more than that. By opening up the possibility to attendees that anybody can deliver — and attend — useful cybersecurity workshops, Diagram is inadvertently helping to usher in the next wave of cybersecurity professionals, all while aiding with the upskilling of a range of folks, and further demystifying cybersecurity in general.

Security, indeed, isn’t something that’s only meant for the few.

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data