THE REGION’S LEADING GOVERNMENT AND CORPORATE SECURITY MAGAZINE | www.asiapacificsecuritymagazine.com Issue #1 2019
Educating the security professional
Going beyond the SD-WAN hype in Asia
The weak link in your supply chain
Asia blockchain week 2018
High speed & subterranean transportation Data challenges in digital forensics
Pakistan: Data protection requirements India: The online matrimonial mayhem
ADVANCED PERSISTENT THREATS
APT10 & STRATEGIC OBJECTIVES FOR CHINA $8.95 INC. GST
PLUS
FOCUS ON SECURITY THE 2019 SECURITY EXHIBITION & CONFERENCE:
WHERE YOUR SECURITY NEEDS ARE BROUGHT INTO FOCUS
24-26 JULY 2019 ICC SYDNEY DARLING HARBOUR
Gain insight into the newest innovations that are reinventing the industry. AI, biometrics and tech inventions are moving at lightning speed and smart technology is inspiring new discoveries every day.
EXHIBITION IS FREE REGISTER NOW
Industry leaders, new visionaries and expert users are all joining together to exchange ideas and developments. The Security Exhibition + Conference is Australia’s largest and most established commercial security event that cultivates innovation, solves problems and leads an industry to be the best in the world.
#security2019
2 | Asia Pacific Security Magazine
securityexpo.com.au
LD RS SO EA CE Y N T3 RE AS FE L N HE CO T T U O Cyber Risk Meetup
THE ASIAL SECURITY 2019 CONFERENCE
BUILDING RESILIENCE TO COMBAT CHANGING SECURITY THREATS The ASIAL Security Conference hosts a compelling program of renowned local and international experts, academics and visionaries addressing how to strengthen your capabilities, managing risk, a digital future, emerging technologies and innovations, integration and more. It is your annual opportunity to receive fundamental updates from the organisations shaping today’s security landscape in a program carefully curated by the industry’s peak body. The format and content of the program reflects critical industry updates and challenges on the first day, followed by your choice of streamed executive briefings on the second and third day of the program. Bring your security needs into focus, stay up to date with the latest developments and gain a competitive advantage with proven strategies to tackle a rapidly changing industry.
SECURE YOUR EARLY BIRD TICKET & ENTER THE DRAW
TO WIN A PENTHOUSE HOTEL SUITE DURING THE EVENT!
HEADLINE SPEAKERS
HUGH RIMINTON
NICK ALDWORTH
DR TONY ZALEWSKI
JOHN LOMAX
Author, Television News Presenter, Radio Broadcaster. Conference Moderator
MPA DipPR, National Coordinator Protect & Prepare, Counter Terrorism Policing National HQ, New Scotland Yard
Director, Global Public Safety Pty Ltd
General Manager Asset Protection, The Star
KELLY SUNDBERG
SHARA EVANS
NICK DE BONT
DR LISA WARREN
Associate Professor, Mount Royal University (Canada)
Futurist, Market Clarity
Chief Security Officer, Thales Australia
Clinical/Forensic Psychologist, Clinical Director, Code Black Threat Management
SECURITYEXPO.COM.AU FOR FULL SESSION DETAILS
BOOK NOW TO SECURE YOUR PLACE and take advantage of the early bird discount.
EXHIBITION HOURS
CONFERENCE HOURS
Wed 24 July: 9:30am – 5.00pm
Wed 24 July: 9:00am – 5.00pm
Thurs 25 July: 9:30am – 5.00pm
Thurs 25 July: 9:00am – 2:30pm
Fri 26 July: 9:30am – 3:30pm
Fri 26 July: 9:00am – 2:30pm
Lead Industry Partner
Asia Pacific Security Magazine | 3
APR 9-12
REGISTER TODAY!
2019 PREMIER SPONSOR:
Sands Expo | Las Vegas
www.ISCWest.com
Discover the industry’s latest products, technologies & solutions
Network with 30,000+ Physical, IoT and IT Security Professionals
Direct access to 1,000+ leading exhibitors & brands
COMPREHENSIVE SECURITY FOR A SAFER, CONNECTED WORLD FEATURING:
@
&
SECURITY EXPO
@
85+ SIA Education@ISC Sessions 4 | Asia Pacific Security Magazine
ISCWEST19.COM/MYSECURITYMARKETPLACE
A part of
18 to 20
Transform The Future
JUNE 2019
Asia’s definitive platform for end users across Asia to explore disruptive solutions and specialised technologies by global tech leaders.
MARINA BAY SANDS SINGAPORE
www.NXTasiaExpo.com
Register Now
www.nxtasiaexpo.com/register/ Organised by:
Held Concurrently:
www.Broadcast-Asia.com
Join in the conversation:
www.CommunicAsia.com
#NXTAsia #ConnecTechAsia
Asia Pacific Security Magazine | 5
One destination for all your cybersecurity needs. In today’s cybersecurity, there’s no standing still. The threats are greater, the stakes are higher. That’s why there’s RSAC 2019 Asia Pacific & Japan. Join industry leaders and peers as you explore best practices, get up to speed on new regulations, and stay on top of the latest developments through: •
Informative sessions covering eight tracks
•
Inspiring keynotes that examine where the industry is headed
•
Hands-on demos of cutting-edge products from over 90 companies
•
Innovation in action at RSAC Early Stage Expo and RSAC Launch Pad
•
Networking opportunities that can benefit your company and career
Don’t miss the chance to get all the tips and tools you need to help protect your organization. Register today at: www.rsaconference.com/mysecuritymedia19
Follow us: #RSAC
ENGAGING CO-CREATION TO PREPARE FOR FUTURE SECURITY THREATS 2 - 4 July 2019 Sands Expo & Convention Centre
•
Singapore
www.interpol-world.com
Global Safety Today • Improving Security for Tomorrow • Forecasting and Planning for the Future
Register for INTERPOL World 2019!
INTERPOL World is a global co-creation opportunity which engages the public and private sectors in dialogue and fosters collaboration to counter future security and policing challenges. 30 strategic Co-creation Labs to discuss the challenges and solutions for combating the crimes of the future Exhibition that serves as a business and networking event for 250 manufacturers, distributors, and Research and Development organizations to offer innovative products and cutting-edge technologies
EVENT OWNER
SUPPORTED BY
INTERPOL Working Groups (by invitation only) including the chief innovation officers group, artificial intelligence, drones and the Darknet and cryptocurrency group
INDUSTRY INSIGHTS BY
visitor@interpol-world.com
HELD IN
MANAGED BY
MEDIA CHANNELS Bringing all of the MSM channels together on one platform for the latest and greatest in security, technology and events from across the Asia Pacific and the world. Now available on Apple and Android platforms.
Commenced in November 2017, the Cyber Security Weekly Podcast has surpassed 120 interviews and provides regularly updates, news, trends and events. Available via Apple & Android. Over 55,000 downloads in the first year.
The Australian Security Magazine is the country’s leading government and corporate security magazine. It is published bi-monthly and is distributed to many of the biggest decision makers in the security industry. Provoking editorial and up-to-date news, trends and events for all security professionals.
My Security Media rapidly expanded into the Asia Pacific Region with its sister publication – the Asia Pacific Security Magazine. It is published bi-monthly –. It is available online to read by all and upon every issue release a direct link is sent to a database of subscribers who are industry decision makers.
The region’s newest government and corporate Technology and Security magazine, with a focus on the Southeast Asia region and the 10 ASEAN member nations
The Australian Cyber Security Magazine was launched in agreement with the Australian Information Security Association (AISA) to be focused on AISA’s 3,000 members, nationally and forms part of AISA’s national cyber security awareness and membership communication platform.
Dedicated channel for all things about Drones, Robotics, Autonomous systems, Technology, Information and Communications
Technology channel partner ecosystem platform with a natural focus on Big Data, Internet of Things and fast emerging technologies
Your one-stop shop for all things CCTV, surveillance and detection technologies
The MySecurity TV Channel delivers news and interviews for the Asia Pacific Security Magazine, Australian Security Magazine and Australian Cyber Security Magazine – and from across MySecurity Media channels.
MySecurity Media can facilitate specialist round-table luncheons or breakfast sessions for up to 20 invited guests for high level discussion on Security & Cybersecurity themes, guided by the Vendor’s Leaders and accompanied with published content.
Event opportunities in Sydney, Melbourne, Brisbane & Singapore providing attendees a special experience and additional takeaways, including podcast interviews and print media.
promoteme@mysecuritymedia.com
www.mysecuritymedia.com
The ‘go-to’ tool for leading professionals UP COMING EVENTS COURSES WEBINARS WHITEPAPERS SOFTWARE
promoteme@mysecuritymedia.com
www.mysecuritymarketplace.com
Contents Editor's Desk
11
Educating the security professional
16
The security professional’s best friend: Artificial Intelligence
20
Executive Editor / Director Chris Cubbage
The weak link in your supply chain
24
High speed & subterranean transportation
26
Director / Co-founder David Matrai
Data challenges in digital forensics
28
Cyber risk assessment for critical infrastructures
30
Connecting mission-critical push-to-talk
32
Crime | Security | Risk | Protection
35
Going beyond the SD-WAN hype in Asia: The early evangelists
36
Cyber Combat
38
Art Director Stefan Babij Correspondents Jane Lo Sarosh Bana
MARKETING AND ADVERTISING promoteme@mysecuritymedia.com Copyright © 2019 - My Security Media Pty Ltd GPO box 930 SYDNEY N.S.W 200, AUSTRALIA E: promoteme@mysecuritymedia.com All Material appearing in Australian Security Magazine is copyright. Reproduction in whole or part is not permitted without permission in writing from the publisher. The views of contributors are not necessarily those of the publisher. Professional advice should be sought before applying the information to particular circumstances.
Data protection requirements are need of an hour
Page 16 - Educating the security professional
39
Asia blockchain week 2018
40
India: The online matrimonial mayhem
44
Bitcoin 10 years on …
45 Page 20 - The Security
Report review - Parliamentary inquiry established to determine
professional's best friend
whether there is adequate preparation for the protection of crowded places in Western Australia
46
CONNECT WITH US www.facebook.com/apsmagazine @AustCyberSecMag www.linkedin.com/groups/Asia-PacificSecurity-Magazine-3378566/about
Page 32 - Connecting mission
critical infrastructures
www.youtube.com/user/MySecurityAustralia
OUR NETWORK www.cyberriskleaders.com
www.mysecuritymedia.com
Like us on Facebook and follow us on Twitter and LinkedIn. We post about new issue releases, feature interviews, events and other topical discussions.
Correspondents* & Contributors Page 36 - Going beyond the
SD-WAN hype in Asia www.australiansecuritymagazine.com.au
Jane Lo* www.aseantechsec.com
Dipesh Ranjan
Zafar Ullah
Sarosh Bana*
www.asiapacificsecuritymagazine.com
Also with Lizzie Damiano Lionel Snell www.drasticnews.com
|
www.chiefit.me
|
www.youtube.com/user/ MySecurityAustralia
www.cctvbuyersguide.com
10 | Asia Pacific Security Magazine
David StaffordGaffney
Stephen Rachow
Roderick Hodgson
Page 45 - The online matrimonial mayhem
Editor's Desk
"The Indo-Pacific region has become the epicentre of intensifying great power competition...that's primarily China and the United States moving around.” - Nick Warner, director-general, Australian Office of National Intelligence (ONI)
P
rofessor Graham Allison of Harvard University and Author of Destined for War, studied human history over the last 500 years and found 16 cases of Thucydides trap, where a rising power threatens to displace a ruling power. Twelve of those cases led to war. As China rises to threaten the rule of the USA, it is widely acknowledged we are indeed within a new Thucydides trap. Unless we come to terms with the need to circumvent a deteriorating cycle, the world’s two super powers are heading towards a major conflict, with a historical 75 per cent likelihood of war. Professor Hu Bo of Peking University told the BBC Radio 4 on April 4, “The harder the US push, the greater the China threat will be. The US should be more patient and calm when facing China’s rising. The US should avoid overstating China’s capabilities or judging China’s intentions just on the basis of China’s capabilities. If the US is over reacting based on its own logics and own experience, I think there is a real possibility of selffulling prophecy.” In our podcast discussion with Dr Malcolm Davis of the Australian Strategic Policy Institute, Malcolm explains, “you have a growing assertive confident China that is directly challenging U.S. strategic primacy across the Indo-Pacific region and is seeking to assert itself in and generate a new hegemonic power in Asia and from the Chinese perspective what they're doing is seeking to restore China to its rightful place as the Middle Kingdom in Asia.” “We are most definitely in a period of strategic competition between the established superpower the United States and the rising superpower China. There's talk of the Thucydides trap whereby you have that rising power challenging the established power leading to warfare and conflict. And I think it's quite appropriate to talk about us being in a pre-war phase.” On April 6, Australia’s ONI Director General
Nick Warner confirmed to ABC’s Radio National "Australia is facing some of the most challenging strategic circumstances that it has for decades. The world is more complex and arguably more dangerous than it was." Both the USA and China have already drawn seemingly immovable lines in the sand. And taking away Taiwan’s democratic independence appears most likely to be the line crossed. According to Paul Dibb, Australian National University, “There can be no doubt that China is developing the military means to attack Taiwan decisively. The US assessment is that the People’s Liberation Army is capable of increasingly sophisticated military actions against Taiwan and is overcoming its historical inability to project power across the Taiwan Strait, which is the natural geographic advantage of the island’s defence. Beijing’s options include a maritime blockade, an intense air and missile campaign to degrade Taiwan’s defences, and an outright amphibious invasion to seize and occupy key targets or the entire island. Dr Malcolm Davis refers to us being in Phase Zero, “shaping operations where you can do that at the strategic level through political warfare through influence operations through cyber activities and so forth. I think you're seeing all of those things happening at the moment across the Indo-Pacific region. There's focus obviously on South China Sea but they're also doing it here in Australia in terms of Chinese influence operations against our media against our academic sector against business and even politics itself. So, we are in that pre-war phase leading into the possibility of a major power conflict occurring in the next 10 years. And we need to be ready for that.” In this issue, we cover the broad spectrum of the security domain, from educating the security professional through to how Artificial Intelligence is now the security professional’s best friend. David Stafford-Gaffney provides details
on APT10, among the most motivated and capable criminal groups seeking to gain economic advantage for China through the exploitation of stolen Intellectual Property and how being driven by the strategic objectives of China seek to replicate services and products on the market to improve China’s economic position. In Australia there are several high cost mass transportation plans being considered, such as: Melbourne underground trains ($50 billion), Brisbane Cross River Rail ($5.4 billion), and high-speed rail between Melbourne and Brisbane ($110 billion). Stephen Rachow, currently undertaking a Master of Security Management at Edith Cowan University looks at technology advancements implementing high speed and subterranean mass transportation services for high volume people movement. With this in mind, I provide a critical and sceptical Report Review following Western Australia’s Parliamentary inquiry established to determine whether there is adequate preparation for the protection of crowded places in that state. Jane Lo, our Singapore Correspondent provides reports on a number of significant technology events, including BlockChain Week 2018, Cyber risk assessment for critical infrastructures and Data challenges in digital forensics and we have reports from India, Pakistan and covering the Asia region. And on that note, as always, we provide plenty of thought-provoking material and there is so much more to touch on. Stay tuned with us as we continue to explore, educate, entertain and most importantly, engage.
Sincerely, Chris Cubbage CPP, CISA, RSecP,
Asia Pacific Security Magazine | 11
00
R1 OVE ODES, EPIS ER OV
00 S 0 , 0 5 OAD NL
DOW
www.australiancybersecuritymagazine.com.au 12 | Asia Pacific Security Magazine
PODCAST HIGHLIGHT EPISODES Episode 147 – Pre-War Phase, Warfare & Cyber: Amongst Space, Air, Land, Sea, Time & Perception Interview with Dr. Malcolm Davis, ASPI Whilst in Canberra for the #CyberTaipan National Finals pilot program, we visited the Australian Strategic Policy Institute (ASPI) and met with Dr. Malcolm Davis, Senior Analyst to discuss defence, cyber, space, China, USA, droneswarms, Warfare Tactics in this pre-war phase.
Episode 146 – High-Performance Computing (HPC) and why it matters for Australia: Pawsey Supercomputing Centre Jane Lo, Singapore Correspondent interviews Mark Stickells, Executive Director, Pawsey Supercomputing Centre, based in Perth, Western Australia. Why HPC or Supercomputing – high performance computers that perform at highest operational rate - matters to Australia’s vision for 2030 to be a top tier innovation nation, and the history behind Pawsey, HPC projects, partnerships across the world, and talent development at the centre.
Episode 145 – #GameOn with #OzCyberinUSA2019 - Interview with Michelle Price, CEO, AustCyber in San Francisco for #RSA2019 In San Francisco for the joint AustCyber and Austrade “Australian Cyber Security Mission to the USA”, MySecurity Media's Director Dave Matrai interviews Michelle Price, AustCyber CEO and discusses Australia’s position on the global cyber security stage. The discussion includes how the Australian cyber security industry has changed over the past 3 years and why Australia is an attractive destination for investment into Australian cyber security innovation. Singtel Innov8 and NUS Enterprise to deliver the ICE71 Inspire and ICE71 Accelerate programmes.
Episode 144 – #CyberTaipan joins an International program delivering a critical skills pipeline with #CyberPatriot #CyberCenturian #CyberArabia This interview with Michelle Price, Chief Executive Officer of AustCyber and Diane Miller, Director, Global Cyber Education & Workforce Initiatives for Northrop Grumman provides insight into the CyberTaipan Finals Competition held in Canberra on 16 March 2019 and the program's link to the USA, UK and Saudi Arabia.
Episode 141 – Insights to Illumio Adaptive Security Platform & Micro-Segmentation Interview with Andrew Kay, Systems Engineer with Illumio. The Illumio Adaptive Security Platform® (ASP) secures the inside of any data centre and cloud – running any form of compute – with micro-segmentation enabled by application dependency and vulnerability maps. Illumio ASP delivers micro-segmentation that is enabled by combining vulnerability data with real-time traffic visibility. This combination enables organisations to understand how their applications work, see where they are most vulnerable, and use that visibility to create and enforce microsegmentation policies.
Episode 138 – Cyber Breach Communication Playbook - In-depth interview with author Peter Coroneos This interview starts with a book review but dives into Peter's long and fascinating journey, starting as the CEO of the Internet Industry Association in 1997 and through to his observations of today's contemporary cyber environment and potential for the next cyber crisis - including an existential threat with an apparent escalating Cyber War between the major powers of USA and China. Peter is the CEO of Icon Cyber and the APAC Regional Head for CyAn CyberSecurity Advisors Network.
Episode 139 – Probable not Provable Privacy for Census Data vulnerable to attack - Chief Scientist Optus Macquarie University Cyber Security Hub Interview with Professor Dali Kaafar, Chief Scientist at Optus Macquarie University Cyber Security Hub and Professor at the Faculty of Science and Engineering at Macquarie University. Professor Kaafar and Macquarie University Lecturer Hassan Jameel Asghar, released a paper mid February, titled, ‘Averaging Attacks on Bounded Perturbation Algorithms’ that identifies and demonstrates a vulnerability of the Perturbation Algorithm used by the Australian Bureau of Statistics for its online tool, TableBuilder, that enables querying the Australian Census Data.
Episode 140 – DevOps and the journey to DevSecOps with #OzCyberinUSA2019 - Interview with Paul McCarty of SecureStack Recorded in San Francisco at the RSA Conference and part of #OzCyberinUSA2019, MySecurity Media's Dave Matrai interviews Paul McCarty of SecureStack. This is a great story about an American that’s come to Australia, become an Aussie and is on a mission to take his company back to America! Already working with a number of government clients, Paul discusses his insights into DevOps and the journey he is undertaking as part of CyRise.
www.australiancybersecuritymagazine.com.au Asia Pacific Security Magazine | 13
3-5 SEPTEMBER 2019 | MITEC | KUALA LUMPUR | MALAYSIA
EXHIBIT AT ASIA’S NEW END-TO-END POWER EVENT GAIN VITAL ACCESS TO KEY POWER & ENERGY BUYERS POWER GENERATION
DIGITAL TRANSFORMATION
TRANSMISSION & DISTRIBUTION
PARTICIPATE IN THE REGION’S PREMIER BUSINESS PLATFORM FOR POWER PROFESSIONALS POWERGEN Asia will in 2019 be co-located with the leading smart energy show, Asian Utility Week, as well as DistribuTECH Asia and SolarVision. This one combined show will cover the whole value chain of power - from generation to transmission and distribution to its digital transformation. Attracting attendees from all of the largest and most influential utilities and IPPs, governments and solution providers, it is here that you will discover the future of the Power & Energy industry.
11,000+ Attendees
350+
Leading Exhibitors
Cutting
Edge Content
350+
International Speakers
VISIT WWW.POWERGENASIA.COM OR WWW.ASIAN-UTILITY-WEEK.COM ▪ MAKE A BOOKING ENQUIRY ▪ SEE THE FLOOR PLAN ▪ VIEW THE EVENT PROSPECTUS
Organised by:
Frontline
Overcome pertinent challenges to cyber security management whilst you develop the required security architecture and technology to counter cyber risks and threats
Risk Management: Implement strategies and techniques to integrated into your current strategy
Engage in project exercises with practical tips and advice on planning and implementing an effective strategy
10 REASONS WHY YOU MUST ATTEND THIS MASTERCLASS
Plan and implement an effective cyber security strategy and program
Improve your security architecture design and management
Enhance vulnerability assessment and management for your security operations
Hear recent cyber attack incidents globally and find out how you can prevent similar incidents
Understand how you can manage your cyber security vendors and leverage the most suitable solution
Security Infrastructure Hardening: Best practices and proven techniques Improve security network penetration and application and security testing
Learn how to roll out effective cyber security policies, procedures and frameworks
WHO WILL YOU MEET? This masterclass is designed for Heads, Managers, Engineers, Specialists and Executives from across Energy, Power & Utilities Companies: æ æ æ æ æ
Cyber Security Cyber Risk Management Systems Information Technology Information Infrastructure
æ Smart Grids æ SCADA Systems æ Transmission & Distribution æ Information Security æ Energy Infrastructure
Media Partners:
PHONE +65 6376 0908
Researched & Developed By:
EMAIL enquiry@equip-global.com
WEB http://www.equip-global.com/ Asia Pacific Security Magazine | 15
Frontline
The security professional’s best friend: Artificial Intelligence By Lionel Snell Editor, NetEvents
20 | Asia Pacific Security Magazine
T
here used to be a simple formula for a security debate: hit them with a round up of the year’s worst horror stories – the latest hacks, viruses and how much they cost business – then introduce the latest most sophisticated technology solutions, designed put all that into the past. The recent NetEvents EMEA Press Spotlight Round Table discussion – The Security Professional’s Best Friend: Artificial Intelligence – added greater intelligence to the mix. It was a combination of Artificial Intelligence (AI) and human intelligence – in the form of greater realism, more recognition of the limits to what is possible. Ovum Principle Analyst, Rik Turner, discussed the challenges, the changes and the tech responses. In the 1990s, he explained, everyone was talking about prevention: “preventing the bad guys getting in, preventing malware from penetrating their networks. Their infrastructure could be safe. They could prevent all of those bad things from happening.” Instead, over the last two decades, we have moved towards a new stance. The vast majority of vendors and practitioners now admit that the best we can do at the moment is to detect and mitigate: “detect once someone’s in, move to mitigate as quickly as possible, potentially do some damage limitation, do some quarantining so they can’t run amok within your infrastructure, and then subsequently to remediate, clean them up, get them out, and start again. Until
the next breach”. That, he suggested, is really a defeat for the cyber-security industry. “It reminds me a little bit of the people defending the city of Constantinople when it was still capital of the Byzantine Empire… gradually the siege made it through the first outer walls, and drove them into the inner walls, until eventually they breached the whole thing. Notice that we use the term breach. We’ve adopted it from the world of siege warfare.” What else has changed? The amount of malware being successfully stopped by anti-virus signatures continues to fall. In 2014 Symantec, in The Wall Street Journal, was talking about 45% success: “I now think it’s between 20 and 30%, not much more, across the industry”. Then of course there is the rise of criminal gangs, hacktivists and state-sponsored malware actors with unlimited resources to play with – not to mention the availability of off-the-shelf hacking kits on the Dark Web. What’s more: “The Cloud: that makes it so much easier to go out, rent a few processors from Amazon, test-drive your new exploit before you’ve even launched it, and make sure it works.” Finally, it is not just volume of revealed vulnerabilities, it is the sheer velocity of their exploitation: “People in security always talk about the needle in the haystack. It’s a horrible cliché, but it’s true. [Actually, later in the discussion someone amended this to “its more like finding a needle in a needlestack”]. In this vulnerability space there’s this
Frontline
“It might be your email server suddenly starts to download the entire payroll database. That’s an entity acting a bit dodgy”.
vast number of vulnerabilities [over 15,000 last year] being published but, by the same token, how do you know which ones are actually going to be exploited? …Why waste your time worrying about all the others when there are only 1.9% being exploited?... Also the speed at which the ones going to be exploited are exploited is ever-greater. So you’ve got less time to decide which ones you need to focus on.” Turning from prevent to detect and mitigate, he outlined current approaches. First sandboxing: “You’d rolled a big box in, put it on your network. Anything that looked vaguely dodgy that you could not actually guarantee was malware, you could put it in there, carry out a controlled explosion, and check whether or not it actually was malicious. It was very fashionable for a while, they sold a hell of a lot. Then, the malware guys started writing malware that knew it was in a sandbox, and played dead, effectively, or played good, however you want to put it, so that it was released out into the wilds…” ‘Knowing it is in a sandbox’ sounds like a great example of artificial intelligence – but in the wrong hands. His example of AI learning in the right hands is User and Entity Behavioural Analysis (UBEA), a system that looks at everything done one the network by each user or system, and it learns what is “normal” behaviour. It can then flag a warning about any out-of-the-ordinary behaviour: “It might be your email server suddenly starts to download the entire
payroll database. That’s an entity acting a bit dodgy”. Another information-based response is called “threat intelligence”. It starts with a ton of data and then intelligently narrows it down. He gave the example of a bank branch wanting details of every bank robber alive today, then filtering out those that are currently in prison, and then reducing the field further by singling out those living conveniently close to the branch. Both these information based approaches are best served by AI machine learning that sorts through loads data looking for recognisable patterns – just the sort of data-crunching that becomes incredibly tedious for an intelligent human. Add to that the pressures already mentioned – volume and velocity of vulnerabilities – and this is the sort of process ideally suited to automated AI. AI’s immediate value is that it narrows down the search within a mine of data: like a magnifying glass focused on the most likely area for finding that needle in the needlestack. But can it extrapolate that analysis into useable predictions? “The promise of artificial intelligence down the road is that it might actually get us to some data science where we can start making some realistic predictions about what is the most likely attack on you, what is the most likely vulnerability to be used against you, and those kinds of things. Now, I’m not suggesting for a moment that that’s where we are today, but that’s what people are talking about, and what they are suggesting is possible”. Possible, but is it imminent, or even likely? Jan Guldentops – BA Test Labs’ Director, with some twenty years hands-on security experience on “both sides of the wall” said; “Artificial Intelligence is the next bullshit term… It’s IoT, it’s cloud, it’s something that broad that we understand it, but we don’t really know what it’s about? We’ve been doing machine learning in the security industry for 15 years. Your anti-spam is based on machine learning… The second thing we have to remember is, it’s a tool. It is not magic… we’re 20 years, 30 years away from real artificial intelligence.” Roark Pollock, Ziften’s Marketing SVP, agreed that AI techniques have long played a major part in cybersecurity, but the difference is that the heavy number crunching – the level that once required supercomputers to identify attack signatures – can now take place at the edge. “I can now run artificial intelligence models or machine learning models on those end-points without bringing that device to its knees. I can run machine learning as a security tool on your endpoint, your Apple, your servers, your cloud virtual machines, and it only takes up less than 1% of the device. It doesn’t kill the device from a processing standpoint.” He pointed out that there was no question that signaturebased detection worked, it was just that it was a slow process to identify and broadcast these signatures. Meanwhile, other
Asia Pacific Security Magazine | 21
Frontline
protection was needed to cover that gap. Another sensitive area where AI had a role was around the big increase in fileless attacks, which do not hang around in storage waiting to be discovered, but go straight to memory, without any user action. Secrutiny Founder and CEO, Simon Crumplin said “the reality is, not all threats are risks to organisations. What surprises me about our industry is, we spend so much time talking about malware… But actually, to materially breach an organisation, malware’s just the start, and we spend all our time and focus around this - I call it threat propaganda.” His subsequent argument reminded me of the story of the two blistered barefoot sages trying to solve the world’s problems: the one suggested killing all the cows in the world so that the land surface could be covered with leather, making it more comfortable for walking. The second sage said he’d rather kill just one cow to make leather sandals for their feet. Crumplin suggested that, for all the talk about better technology: “to determine their risk and their risk appetite with the business is the primary thing organisations have got to do and understand. They can then make investments that are meaningful to mitigate just those risks.” A more extreme version of this novel approach came later from the floor: “What we’ve seen over the last three years is a number of research studies highlighting the fact that security breaches, security vulnerabilities, database theft, credential threat, credit card loss, has zero impact on the bottom line of companies, has zero impact on share price.... No one cares about IT security because it has no impact on the business at all. In fact, companies who suffer major breaches, and get substantial amounts of press coverage because of it, actually grow as a result of that business”. This was clearly an overstatement because, as Guldentops and Pollock pointed out, the loss of trust and reputation is bad damage that is not so easy to quantify and dismiss. But it did make a very interesting point. It marked the sort of radical re-thinking that is most needed when technology reaches an impass or crisis point. Is it not time we forgot about leathering the globe and took a closer look at our feet? Jan Guldentops suggested another important role for technology. Whereas people sometimes cry out for more security specialists, what is really needed is more automation: “We need to automate simple things, like configuration management. Like log analysis. Let’s not call it AI yet.” This was made more urgent by the pressures for compliance, as with GDPR where: “First of all, you need to report a data leak within 72 hours. Of my customers, maybe 15% is capable of doing that.” Later commenting: “Code compliance is a perfect area for machine learning and natural language processing”. Pollock took up the latest scary figures for the number of security alerts, saying that this was partly a consequence of the shift from prevention to detection: “One of the reasons we have so many alerts these days is, we’ve got a lot better at identifying issues after they happen… moving from prevention to detection and response. If we’re finding things that are going on, we’re finding more alerts.” The audience Q&A that followed began with a reminder that, in the search for new solutions, we should not forget the traditional perimeter solutions that are still doing a good
22 | Asia Pacific Security Magazine
job. Machine learning is being vaunted all over the place, but there are only so many attack paths actually being used: “there are only so many low-hanging fruits, and criminal hackers are into minimax – having maximum result with minimum effort.” So every old perimeter hurdle still plays some part in deterring them. Otherwise, let’s end with another radical observation from Guldentops that truly reflected what we had heard in this session: “One of the big evolutions between the ‘90s and now is that the security industry has become more modest. In the ‘90s, you could have someone on stage arrogantly saying they had the solution for everything…” The full transcript of this session is available now as well as a short video discussion.
Frontline
Modern workflow without modern risk Dekko is a web-based platform that relies on engineering solutions to provide privacy and security – not anonymity, secrecy, or private cloud infrastructure. Dekko is easy to use, easy to implement and easy to manage. Dekko enables you to navigate:
Threat of intruders Accidental misaddressing Untrusted networks Lack of communication control Protecting your brand reputation Information privacy
Circles
Sharing
Control
Security
Isolate and discuss projects Control visibility
Share files with no size limits Share documents for approval Granular permissions
Branding Data sovereignty
End-to-end encryption Two-factor authentication Completely user-transparent
The Dekko platform tools
DekkoVAULT
DekkoSIGN
DekkoCHAT
DekkoMAIL
www.m ysecurityma r ke tpl ac e .c om / pr oduc ts / de k k os e c ur e
Asia Pacific Security Magazine | 23
Crystal Eye UTM Series 10 Gateway
Illumio Adaptive Security Platform
Enterprise to SMB/Home Office Solutions - Crystal Eye Series 10 - 200
Enterprise Solution
10% Discount off RRP to Marketplace Users:
The Illumio Adaptive Security Platform® (ASP) secures the inside of any data center and cloud – running any form of compute – with micro-segmentation enabled by application dependency and vulnerability maps.
Crystal Eye Deployed Device that is a Unified Threat Management (UTM) next-generation firewall (ngfw) software/hardware solution for your enterprise or home office, protecting it from a variety of threats and risks through a range of integrated services.
Predictions 2019: Cyber Security Key Trends
The Cyber Breach Communication Playbook
Over 2018 the Huntsman team has seen a number of trends develop which may impact your organisation’s operation and exposure to risk; we’ve created a White Paper Predictions 2019 – Looking forward to next year in cyber security to share these with you.
HUNTSMAN SECURITY CYBER SECURITY PREDICTIONS 2019
44 | Asia Pacific Security Magazine
The Cyber Breach Communications Playbook is set out in a straight-forward, easy to understand format that delivers on equipping Boards with a rapid and competent decision making guideline – “asking the right questions is 80% of getting the right solution.”
LISTEN TO OUR AUTHOR PODCAST
Cyber Blockchain Security
Bitcoin 10 years on …
O Jane Lo APSM Correspondant
n January 3rd 2019, it would have been 10 years since Satoshi Nakamoto created the genesis block with the first block reward of 50 bitcoins. Impressive statistics point to the steady and at times dramatic (witness the explosive growth in 2017 when Bitcoin hit the all-time high of $20,000) growth of the network in the last decade: 17 million bitcoins in circulation, 30 million wallet users, 200+ thousand transactions daily, 42 terra hashes generated per second. What also gets many excited is also the potential of Blockchain technology underpinning bitcoin. Malikkhan Kotadia (Co-founder & CEO, Finnovation Labs, Singapore Head, International Business, Singapore Blockchain Industry Association - ACCESS) gave a refreshing take on Blockchain at the 4th ASEAN EXEC-IT 2018 (15th – 16th Nov 2018, Hotel Fort canning). Our understanding of Blockchain is not unlike an elephant and a group of blind men, who having never come across an elephant before, arrived at an understanding of the animal only through his own feeling of one part of the elephant, according to Malik. “Our understanding of Blockchain is also limited to what we hear, and so each of us may not have the same understanding” he added. “One basic Blockchain fact is that it is a means of transfer of value, which does not change though ownership may change.” Handing a $50 Singapore note to a participant, he noted his net worth was down as much as the increase to the recipient; the situation was reversed when the note was re-exchanged. “Many aspects of Blockchain are in fact not new -cryptography, ledgers of record - but it’s how these elements come about that make it exciting,” he said. These elements enable Blockchain’s characteristics: identity, provenance and single source of truth, which found many use cases, including cross-border remittances, with the
potential to become as common as cross border messaging. In fact, just like today’s essentials such as email were not foreseen in the 1990s, tomorrow’s Blockchain use cases could well easily surpass our imagination. One potential scenario is applying Blockchain to disrupt corruption. “At the session, ‘When Machines Fight Machines: Cyber Battles & the New Frontier of Artificial Intelligence’ by Mishaal Ismeer (Director of Sales, South Asia and Southeast Asia, Darktrace), the inevitable question of how cryptocurrencies like Bitcoin have an impact on cyber security arose. Darktrace has observed an abrupt increase of cryptocurrency-related attacks due to the ease of maintaining anonymity and the attackers’ ability to monetize cryptocurrencies”. Indeed, “return on investment”, Malikkhan also stressed, is critical - Blockchain whilst exciting, should be clearly demonstrated to add- value to address an issue. Other challenges that he pointed out included: environmental impact (massive and unviable energy requirement), scalability and costs (10-15 mins to validate a transaction), governance, regulations and public policy (what are the dispute mechanisms? Who regulates and controls a Fork?) But perhaps the biggest quest of all, 10 years on, is uncovering the identity of the pseudonymous creator of Bitcoin Satoshi Nakamoto. Enthusiasts have proposed candidates, ranging from Japanese mathematicians to Irish graduate students, cryptographist, computer scientist or a group of people. This quest remains part romance, part challenge and perhaps part desire to reach a conclusive and ultimate answer to the question: was Satoshi Nakamoto chasing an elusive dream for bitcoin when he envisioned it as “an electronic payment system based on cryptographic proof instead of trust, allowing any two willing parties to transact directly with each other without the need for a trusted third party?”
Asia Pacific Security Magazine | 45
REPORT REVIEW | by CHRIS CUBBAGE WA POLICE FORCE RETICENT, UNACCOUNTABLE AND INADEQUATE: REPORT 4 0 T H PA R L I A M E N T
Community Development and Justice Standing Committee
Report 5
NO TIME FOR COMPLACENCY Final report for the inquiry into the protection of crowded places in Western Australia from terrorist attacks Presented by Mr P.A. Katsambanis, MLA March 2019
NO TIME FOR COMPLACENCY FINAL REPORT FOR THE INQUIRY INTO THE PROTECTION OF CROWDED PLACES IN WESTERN AUSTRALIA FROM TERRORIST ATTACKS Review By Chris Cubbage, Executive Editor
W
A Police Force declined to assist the Review, are unaccountable for millions in spending and are not adequately regulating the security industry. Is public safety at risk? This report is the outcome of a Parliamentary inquiry established to determine whether there is adequate preparation for the protection of crowded places in Western Australia (WA). It was motivated, in part, by the release of Australia’s strategy for protecting crowded places from terrorism (the Strategy) in August 2017.
Background In March 2018, just 12 months away from the Christchurch massacre in New Zealand, in WA a Community Development and Justice Standing Committee was seeking submissions as part of its inquiry into the protection of crowded places in WA from terrorist acts. In particular, the Committee set out to consider the flow of information between agencies and other relevant stakeholders and the WA Parliament’s role in overseeing counter-terrorism arrangements to ensure that it can properly evaluate the: 1. 2. 3.
4. 5.
state-based emergency management framework; implementation of mitigation and protective security measures; relationships between state government departments and agencies and owners and operators of crowded places; capability of the Western Australia Police Force to respond to a terrorist attack on a crowded place; and security licensing, registration, and assurance processes in Western Australia.
In making a submission, it was quite apparent that the terms of reference was too broad. As the inquiry progressed, “the complexity of protecting crowded places quickly became apparent.” One may argue the Committee had limited experience or insight not to realise this at the outset given the scope it set for itself. Not surprisingly, the Committee chose not to consider in detail the other three elements of the PPRR
48 | Asia Pacific Security Magazine
(prevention, preparedness, response and recovery) model and likely targets of terrorism and indeed, crowded places such as the airport or domains in maritime, transport or health were also not examined extensively. Yet despite this, in October 2018, the Committee released an initial report identifying 30 matters they felt required further consideration. This report proclaims the inquiry and outcomes “will not reduce the complexity of both counter-terrorism and the protection of crowded places in WA.” In other words? It will achieve little and tells us much we didn’t already know. However, there is one striking takeaway from the inquiry worthy of note. The WA Police Force isn’t performing, isn’t accountable and isn’t prepared to assist when asked to.
WA Police Force reticent to share information Throughout the inquiry, the Committee struggled to access information and documentation it considered important to fully inform itself about the preparedness of the Western Australia Police Force and Western Australia more generally. The report noted, “It is impossible to determine whether the millions of dollars of government funds directed to WA Police counterterrorism capabilities has actually increased the state’s counter-terrorism preparedness.” “There is a lack of independent oversight in relation to the state’s preparedness for a terrorist attack. The Counter Terrorism and Emergency Response Command of the Western Australia Police Force received over $49 million in 2017–18 and there is currently no third party scrutiny to ensure the people of Western Australia that this money was used effectively, efficiently, and ultimately increased the state’s counter-terrorism preparedness.” “The apparent reticence of WA Police to engage meaningfully with this inquiry was particularly evident when contrasted to some UK police services’ purported responses to recent, independent reviews. The reticence of WA Police to cooperate with the inquiry also differed from the ‘dare to share’ approach to information-sharing that Victoria Police Deputy Commissioner Shane Patton told us he employed.” “The requirement to seek approval from the ANZCTC—a creature of the Council of Australian Governments (COAG) and therefore outside the authority of the WA Parliament—reduces the effectiveness of the traditional vehicles for scrutiny.” “Unlike Victoria or New South Wales, WA does not appear to have developed an up-to-date, publicly available state strategy or coordinated suite of policy documents elucidating the various counter-terrorism
REPORT REVIEW | by CHRIS CUBBAGE roles of government and non government entities. WA has also not developed a protective security advisory capability to support owners and operators to enhance the resilience of their crowded places.”
WA Police Force lacks independent oversight and accountability to auditing and governance “There is an assurance gap, however, in relation to owners and operators of crowded places that are neither the recipients of public funding nor covered by specific regulatory regimes.” Auditor General Caroline Spencer said she preferred for this emergency management assurance role to be legislatively defined and accompanied by appropriate funding to reflect the expansion of her role. She explained the estimated cost of an initial scoping audit of the emergency management sector is $500,000, or just over 8.3 per cent of the total Auditor General 2008 audit budget. Considering the average amount spent on a performance audit is $300,000, the estimated cost of the initial audit is significant. Expecting the OAG to fulfil a permanent assurance role without additional resources risks inadequate consideration of other, equally important, topics. As an example where oversight and auditing is required, the Committee determined that “despite monitoring an industry with over 30,000 active security licences, WA Police issued no infringements in relation to the Security and Related Activities (Control) Act 1996 (WA) between July 2017 and May 2018. While WA Police aims to audit 275 licence holders per year, only 100 people (or 0.003% of the industry), were audited between July 2017 and May 2018. WA Police noted that sometimes the audit target is not reached due to ‘other policing priorities’. In the 2016–17 financial year, WA Police issued only five infringements, one summons, and 86 cautions in relation to the Security and Related Activities (Control) Act 1996. The Queensland Office of Fair Trading has a similar number of active security licences as WA but issued a far greater number of infringements—55 infringement notices and 74 warnings—in the same period. WA Police said there was no reason why it could not also release de-identified compliance information, and pointed out that similar information relating to pawnbrokers and second-hand dealers was already published in the WA Police Force Annual Report. Yet the reason they don’t make this information available is most likely because they’re not actually regulating the industry effectively and one may argue, not at all. Another area WA Police were subjected to criticism was the State CCTV Strategy. Subject to complaints when it was first received (including formal complaints by this author), the Committee stated, "Because of evidence we received early in the inquiry, we raised questions about the effectiveness of the State CCTV Strategy. Some respondents identified specific issues with the CCTV strategy and sharing of data. Concerns were raised, for example, about the cost and technical
difficulties associated with creating and managing a central security information system from which WA Police can monitor CCTV data from multiple cameras.” “SAIWA (Security Agents Institute of WA) said the system may also prove costly for donors of CCTV data as they may have to obtain legal advice, upgrade their equipment to a different standard in order to add their CCTV cameras to any ‘joined-up approach’, and spend money on ongoing maintenance. Further, one local government told us of its reluctance to join the State CCTV Register because of ongoing questions about the governance measures and security of shared data.”
Terrorism is a silo risk – Holistic & Risk Based Approach is needed. “In the course of the inquiry, it became evident that whether or not an attack on a crowded place was terrorism was largely irrelevant from a protective security perspective.” “One document, the State Hazard Plan: Terrorist act, represents the totality of strategic counterterrorism arrangements in WA and embodies an outdated approach to counter-terrorism. This means WA’s counterterrorism preparedness is also largely unscrutinised as terrorist acts are managed under the state emergency management framework along with 26 other hazards identified as posing a risk to WA.” “With neither an up-to-date state strategy nor policy framework to guide counter terrorism efforts in WA, some of the stakeholder groups identified in the Strategy have contested the exact nature and extent of their roles and responsibilities. Some sought to minimise their responsibility for achieving this goal. The strategy is not linked to any legislation or policy framework within WA and is therefore not mandatory.” “Terrorist use of drones is one example of an emerging threat where there are legislative impediments on police use of drones for incident response and other purposes. There is clearly a need for legislative reform. It is inevitable that legislators will have to respond.” “We found there was a clear expectation amongst owners, operators and the public that authorities such as WA Police would take the lead in protecting crowded places. WA Police appeared reluctant to step into this space, however, distancing itself from any overarching responsibility for implementing the Strategy and stressing that it was not the role of WA Police to provide protective advice to private industry.” “WA Police and DPC had different positions about whether WA Police was responsible for implementing the Strategy: while DPC said WA Police is the ‘lead agency for implementing the Strategy in Western Australia’, WA Police said the CPAG is ‘responsible for the implementation of the National Strategy.” “Implementing proportional security and mitigation measures can be costly and—importantly—reduce the profit generated. As one inquiry participant pointed out: Any costs for additional protective security measures have no value in terms of marketability of the venue/ event. In fact, these protective security measures are wherever possible concealed so that attendees are not
consciously aware of the existence of a threat being mitigated.” “The Strategy does not set out a mechanism by which owners and operators can be compelled to fulfil their responsibility to protect their crowded place. This may become a problem should owners or operators weigh the quantifiable costs of implementing security measures against the less well-defined costs arising from non-implementation (i.e. reputational, asset damage, public safety) and decide not to invest in its security. Their preference was instead for the risk-based approach currently advanced by the Strategy.” “As the Queensland Police Service said: identifying a minimum standard of protection would result in the general adoption of that standard. Without a risk-based approach, owners/operators would likely to be either under-protected or would be required to implement unreasonable measures.” “Those indicating support for a prescribed minimum standard tended to be the owners and operators of crowded places who felt they did not have the skills or knowledge to either implement adequate protective security measures or identify consultants who could do it on their behalf.” The Committee reported, “We believe the debate around security standards reinforces the need for owners and operators to be able to identify and engage qualified, experienced and skilled security consultants who will ensure risk assessments (and any subsequent implementation of recommendations) are appropriate and commensurate with the circumstances This standard is a process-based standard of preparation. We can surmise, therefore, that those inquiry participants who preferred a risk-based approach to protective security would support this use of AS/NZS ISO 31000:2009.”
Thanks for the Report – but frankly no change will happen Whilst the Australian Government rams knee-jerk, politically motivated legislation like the Criminal Code Amendment (Unlawful Showing of Abhorrent Violent Material) Bill 2019 through parliament without ‘any’ oversight and informed consideration, actual calls for legislative reform by Parliamentary committees like these are ignored. The national security system which has the ‘intention’ of protecting Australians is in large parts broken, largely unaccountable, overly complex and politically manipulated. There is little that will change this and if a major terrorist attack is successful on Australian soil, the system is inherently designed to allow the blame game to cycle through again.
This committee focused on preparedness. What should have been the first part is prevention. Australia has prevented a number of terrorist incidents from good intelligence and operational policing but for the protection of crowded places it should be how CPTED and a risk based approaches is best applied, the legislation frameworks needed to deal with emerging threats (drones, robotics etc) and how police can be supported by a robust and appropriately regulated security industry.
Asia Pacific Security Magazine | 49
Out Now!
Out Now! Print Post Approved PP100003227
THE COUNTRY’S LEADING GOVERNMENT AND CORPORATE SECURITY MAGAZINE | www.australiansecuritymagazine.com.au
THE MAGAZINE FOR AUSTRALIAN INFORMATION SECURITY PROFESSIONALS | www.australiancybersecuritymagazine.com.au @AustCyberSecMag ISSUE #7 2019
OT Cybersecurity must improve in 2019
Women online: Australia’s e-Safety Commissioner
The Encryption Act
Waking up to the benefits of diversity
Monitoring threat actors
Teaching cyber hygiene in schools
Biometric data and potential for misuse
My journey, from student to cyber security graduate
Cyber risk management in finance
Cybersecurity journey empowered by diversity
Oct – Dec 2018
Many modes of supply chain attacks The dawn of the digital Manager
Biological Protection-In-Depth
Australian-made FLAIM Trainer
How to minimise roulette wheel motion blur
The rise of hashgraph
Cyber Risk Meetup - Wrap-ups & Launches
A cyber week in London – Part 2
Penetrating real-time threat behaviour
BOOK GIVEAWAY Troll Hunting
India’s Supreme Court reins in citizen profiling
$8.95 INC. GST
Resilient organisations begin with resilient people
Migrating to IP video SURVEILLANCE PLUS
Techtime
#BalanceforBetter
THE REGION’S LEADING GOVERNMENT AND CORPORATE SECURITY MAGAZINE | www.asiapacificsecuritymagazine.com Nov/Dec 2018
ALL WOMEN SPECIAL EDITION
Many modes of supply chain attacks The dawn of the digital Manager
India’s Supreme Court reins in citizen profiling Biological Protection-In-Depth
Australian-made FLAIM Trainer
How to minimise roulette wheel motion blur
The rise of hashgraph
Cyber Risk Meetup - Wrap-ups & Launches
A cyber week in London – Part 2
Resilient organisations begin with resilient people
THE MAGAZINE FOR AUSTRALIAN INFORMATION SECURITY PROFESSIONALS | www.australiancybersecuritymagazine.com.au @AustCyberSecMag Issue 3, 2017
The active directory botnet
Mandatory Breach Notifications and the GDPR Effect
$8.95 INC. GST
ROBOTICS GROWTH & OPPORTUNITIES
PLUS
Techtime
Cyber insurance: A buyer’s guide Part 2
Machine Learning in Cyber Security
Know your enemy : Part 2
Honeycutt Social Engineering
DRONES, ROBOTICS, AUTOMATION, SPACE, TECHNOLOGY, INTELLIGENCE, COMMUNICATIONS | www.drasticnews.com
ISSUE #1 2019
Interview with ANZ's Security Team
A New Race: Robotics, Artificial Intelligence & Human Convergence
The RoboCop Continuum
The rise of autonomous vehicles
Cyber data protection in Formula 1
WA’s Capture the Flag Competition
The Security implications of driverless vehicles
- PLUS -
D I V E R S I T Y F E AT U R E S Gender Minorities within STEM | Bridging the Gender Gap | Seeking diversity in Cybersecurity
50 | Asia Pacific Security Magazine
Plus Techtime!