Sunday, 22 September 2024

The Global Forum for Cybersecurity Excellence (GFCE)

 I got an invite to speak on a panel at the Global Forum for Cybersecurity Excellence's Annual Meeting last week. It was my first time in DC since I went on a trip there with Air Cadets in the 1980s, so it was an exciting prospect. More so when I saw it was going to be taking place in the Organization of American States' building.

Attending these things is a high wire act for me as it looked like I was going to have to self fund my way there, but then the OAS's Cybersecurity directorate got in touch and asked if I'd sit on one of their emerging technology panels for the region of the Americas pre-GFCE meeting too, so I got hotel and flights covered.

I got in on Sunday and my hotel was in Georgetown, so I got out and about and soaked up some Washington area history - the place is thick with it! 

That night I met up with Dr Juan from Mexico who I did a presentation with in June and we enjoyed some Potomac wings at the local Irish pub (as you do) and caught up. The last time I'd seen him was as we passed through US customs on our way back from Ghana last year, so we had a good chat. The opportunity to solidify these connections was impressed upon me as an important consideration later in the week. Never underestimate the appreciation inherent in making an effort to see people live, especially post-pandemic.

Day 1

The next morning, after breakfast at the Fairmont (!), we walked to the Organization of American States building only to discover it was the wrong one. We ran into Alex from Ghana who was on the OAS panel with me later that morning and he knew where we needed to go, so we backtracked four blocks to where we should have been in the first place.

I got there sweaty (DC got up to about 30°C each day) but cooled off and our talk that morning about emerging technology impacting cybersecurity was wide ranging. Kerry-Ann, our moderator, surprised me with a question about how approaching cyber challenges as a technician gives me a different (and valuable thanks to how she framed the question) insight into the rapidly changing state of things.

Talking to engineers and the legal experts doing policy is one thing, but talking to the trades people who do the operational work of keeping the lights on does offer an interesting angle. I'd been expecting to talk about quantum technology emergence, but an opportunity to speak about the value of hands-on, applied skills in the field was appreciated and well received.


Many of the panels focused on the clear and present danger in cyber at the moment: artificial intelligence. From the automation of big data analysis that humans never excelled at on the defensive side to how criminals are leveraging GenAI to produce customized phishing material well beyond grammatically incorrect emails (stretching to include deepfake video, voice, photos and other digital media), these talks were designed to assist policy makers with understanding what has come out of Pandora's box of AI.

One theme that resonated with me was how people don't want deep technical explanations of these emerging technologies. What they want is an easy to grasp explanation of how these technologies will impact the digital spaces they work in. This remains a problem in cybersecurity and an even bigger one in the quantum world where I just finished my secondment. The urge for academics to obfuscate and complicate their explanations of these rapidly emerging technologies doesn't make them ideally suited for presenting on them, especially to the operations and policy people who are entirely focused on real world impacts and couldn't care less how the maths looks.

I've gotten a lot of static for how I've simplified deep technical details in quantum in order to get concepts across, but you honestly don't need to start neck deep in linear algebra any more than you need to have knowledge of the metallurgy involved in casting your car's engine in order to drive it. Guess what background is really helpful in bridging this information divide: 22+ years as a teacher! Early in my career I came across a quote that described teachers as, "public facing intellectuals" and took that to mean we're not about ivory towers and knowing more and more about less and less, but about the democratization of knowledge. Part of that comes with knowing what to keep out of the mix in order to help people get a handle on emerging technologies.

My age is also handy. Being a genuine digital immigrant who remembers a time before personal computers and the internet (I got my first PC, a Vic 20, in 1979 when I was 10), I have a big picture outlook that those who have always lived in this chaos find helpful. My other secret weapon is a university background focused on thinking and communications (philosophy & English).

After the OAS event we had an evening meet and greet at the Museum of the Americas right behind the main building, which had a permanent collection of powerful pieces looking at colonialism and culture. Upstairs they had a Spanish diaspora collection featuring the people who fled Spain during the Franco period; powerful stuff.

At the meet and greet I got to introduce Juan to Michelle and Nina from CyberLite, one of my favourite international cyber education organizations. We did an around the world webinar with them for Safer Internet Day in February, but it's always nice to see people in 3d rather than on a screen, and introductions like this are what GFCE is all about.

Another good example of this networking was running into Christina from Global Affairs Canada. From our talks I've come to understand the complexities and difficulties of international cyber policy. I'm also particularly aware of how important it is to shed better light on the work our federal government does internationally. Some of this needs to be kept on the down low for security reasons, but much of it (and especially on the diplomacy side) needs more media coverage so Canadians better understand the work that their representatives are doing on their behalf. Being purely insular and defensive doesn't work in sport and it won't work in cybersecurity either. If we can help other countries develop better cyber capacities, we all win, and that starts by doing the hard work and developing trust.

Day 2

The next day we were up early again and this time took an Uber to the right building (kind of, it still took us to the wrong one first), and began the Global Forum for Cybersecurity Expertise Annual Meeting.

Our panel came up quickly and Juan brought in a fantastic angle focusing on the Global South and the formation of a 'quantum divide' that will, like the digital one, further separate developed countries from everyone else. I've seen this happening with tightening restrictions on public facing quantum education resources. In some cases this may be under the auspices of national security, but the end result remains: countries that have the resources to develop quantum technologies will have capabilities that the others can only dream of.

There is also an academic ownership of quantum that favours those with the resources to spend most of their lives in post-secondary. Quantum mechanics is how the universe works, yet most schools stick to Newtonian physics because it's intuitive and easier to deliver, except that Newtonian truth is a fiction caused by our scale. If you look closer, it is (as Brian Cox says) quantum all the way. We need to demystify our best understanding of how the universe works so that everyone can grasp the technologies that are emerging out of this science.

Our panel couldn't have happened without a secure internet because our moderator was virtual in Europe and one of the panelists was in Central America. This highlights the importance of the awareness I've been doing in Canada and beyond around quantum encryption readiness in cybersecurity. In a few years that secure internet may be a thing of the past.. After we wrapped up our panel I showed Juan the William Gibson quote about the future already being here, but not evenly distributed.

The idea of a growing quantum divide is another indicator of the state of maturity of rapidly improving quantum computers. I'm motivated to continue my 'technology literacy for all' approach (which includes quantum and AI) because no one should make the technologies that have the best chance of helping us save ourselves from ourselves proprietary. I also have a nagging urge to help everyone reach their maximum potential regardless of how much they have in their bank accounts.

The end of day event on day two was both uplifting (it was a retirement party for founding GFCE president, Chris Painter), but also profoundly insightful. When someone with extensive, top draw international research resources tells me that they aren't worried about AI taking us down because climate collapse will get us first, I listen. Moments like this make me vividly aware of just how fragile the house of cards we're standing on is. If we don't come together to make it accessible, secure and safe, that house of cards is coming down.

This observation feels even more perilous because of the book a colleague suggested that I'm two-thirds through. Advocating for long term thinking in human societies that only reward short term gain is a challenge, but the most recent chapter is about how all civilizations collapse. Historically this happened regionally (Roman Empire, etc), but the global civilization we've built this time is going to crash harder, and when it collapses we're going to be wishing we had made some of Asimov's Foundations in order to recover more quickly (assuming we don't make our only habitable planet uninhabitable in the process). That's the thing about attending a GFCE event - it makes you reflect on the big things (kinda like Tamara's book recommendations).

Day 3

All of the delegates from dozens upon dozens of countries coming together in DC to make digital transformation secure and accessible.

Day three began with the women in cybersecurity breakfast. The moderator at our table told hair raising stories of her being in the first female engineering cohort in South Africa and the overt sexism they faced. I told them about Canada's tragic history with this kind of sexism, which the table found astonishing - Canada is considered forward thinking until we're a bit more forthcoming about the dark currents in our history. I also told the story of the quiet sexism that made founding the first all-female cybersecurity team in our school so difficult. It amazes me that half our population experiences these systemic prejudices and that equality isn't something we're likely to get to before the 22nd Century.

These GFCE events are thick with insights and opportunities that lift your head out of your personal context and prompt you to consider the big problems we face. I've tried to cover the main pieces here, but there are so many more that I'm still subconsciously noodling on.

The emerging tech panel on AI towards the end of the day was another of those eureka moments. The policy expert from France's advanced technologies department had a good response to my question about how we devise policy for near future AIs that will have the agency and resources to ignore them, not out of spite, but because even considering them isn't in their programming. She referenced the US Section 230 law that let social media run rampant and pointed out that if we recognized this cautionary tale we'd be able to better direct AI use now. A sharp response, but I think the AI horses are out of the barn and will shortly have the capabilities to do real damage to our digital infrastructure. I remain curious as to when AI policy to try and restrict development turns into defensive policies designed to mitigate the damage that self-directed AIs will do to our piecemeal global network.

I ended the event having lunch with Abdul, my swimming buddy from Accra, and Juan, my co-conspirator. What do you talk about at a Nigerian/Canadian/Mexican table? Abdul told me he is in 'legacy mode', which is a great way of framing your closing professional years. I enjoyed our talks in the pool at Accra City Hotel because Abdul always seems to see beyond the horizon. Taking a minute to soak up that wisdom is never wasted time. He was going to see his friend's grave and visit his cousin after the event. These seemingly technical meetings can be profoundly human, if you let them be.


We wrapped up our time at the OAS HQ, but we weren't quite done yet. At the museum event Monday night we met a Spanish attaché and that prompted an invite to the embassy for a Wednesday evening networking event. It was a short walk from the hotel and I talked to a lot of people but really got into it with Jose Manuel who runs telecoms and startups in Spain including a new one that helps you park your boat in a marina you haven't visited before. Besides travel, work life balance and entrepreneurship, we also had a good chat about the innovative quantum key distribution research around mesh networking QKD into live networks that he is in the vicinity of. I'm hoping to follow up and develop some transatlantic connections that move us all forward.

***

I must have covered 20+ kms on foot over the week (in dress shoes!), but I have no regrets about the schlepping or having to self fund some of this. Hope is hard to find in 2024, but the GFCE exhales it like plants give off oxygen. Just as the GC3B in Ghana did last fall, my mind is left turning over the complex challenges and opportunities that this meeting highlighted. If you're looking for organizations that improve your practice, expand your context, and challenge (and enable!) you to take on the seemingly insurmountable global issues we face, meeting the OAS and experiencing my second live GFCE event has done just that.

DC looking like a postcard on the ascent out of Reagan Airport.

Just over 500kms as the crow flies from DC, I was back in The Six before I knew it!

Sunday, 15 September 2024

The Serious Play Conference and a Canadian Solution to Cyber-Education

The Serious Play Conference took place in August at University of Toronto's Mississauga (Erindale) campus. Even though I'd fallen off the end of my secondments, gamification has also been a central tenant of my teaching practice and I've been actively researching cyber-education using immersive simulations for the past four years, so I took this opportunity to present what I'd found.

Paul Darvasi runs this conference. I met him last summer when we did a quantum training week together at UBC in hopes of building a quantum game that takes the academic privilege out of how the subject is presented. That hasn't yet come to be, but I did manage to recently get our quantum arcade idea funded (from Finland because finding that kind of support for emerging technology education in Canada isn't easy). Canada likes to be surprised by emerging technology in education rather than getting in front of it.


Games have played a central role in my life. I got into Dungeons & Dragons in a big way in my teens and my first long distance road trips were with friends to GENCON in Milwaukee in the late 1980s (where I got to play a tournament round of D&D with Gary Gygax!!!). As a result my teaching practice has always been informed by those early years dungeon mastering. If I have an opportunity to create a simulation or immersive gaming experience in my classroom, I'll go out of my way to arrange that rather than falling back on worksheets peddling dimensionless knowledge transmission. My experience has shown me that suspension of disbelief can be a powerful learning tool if the gamified learning experience is pedagogically viable.

My presentation at Serious Play was specifically about how immersive simulation can help learners tackle subjects that might scare them into disengagement. By using suspension of disbelief, subjects like cybersecurity can be approached without out the risk aversion prompted by worries about breaking technology almost no one understands because we seem to have given up on modern media literacy about two decades ago.

I've put students on Field Effect's Cyber Range in classrooms across Canada. In some cases they were competitive CyberTitan teams containing students with the top 1% of digital skills in the country, but in most cases it was with the other 99% who had never touched cybersecurity at any time in their learning journey. With the right scaffolding and support even the newest of n00bs can get their hands dirty iteratively learning essential cyber skills in this digital sandbox:

Engaging Canadian education with cybersecurity remains an uphill struggle, but cyber sandboxes like Field Effect's Cyber Range offer a solution.

The Serious Play Conference had a wide range of educators working in digital and analogue simulation across a staggering range of subject areas. From museums engaging patrons to a think tank designing war games for the Canadian Forces, it was a tour de force of what immersive simulation and gaming can do to engage and teach in every learning context.

I was absolutely thrilled to learn that our all Canadian made simulation that offers a key to cyber-education - one that is more advanced than the systems we use when our CyberTitans take part in CyberPatriot south of the border because it allows for interactive networking between virtual machines instead of just putting students into isolated desktop VMs - won the gold medal for K12 immersive learning simulation.

ICTC and Field Effect have worked hard to get this world class immersive learning opportunity in front of Canadian students. The trick now, as it has always been, is to get insular Canadian education systems who have taken a head-in-the-sand approach to cyber education to pick up this federally funded, world-class tool we've built and use it to get past their own fear and ignorance and begin teaching essential defensive 21st Century digital skills.

***

Sign up for CyberTitan, Canada's national student cybersecurity competition, is open until October. Teams of girls and other under represented groups in the field are fully funded. The early rounds are on individual virtual machines through CyberPatriot in the US, but if you push on you eventually get to Field Effect's Cyber Range and get a taste of the future of cyber-education.


Check out the interactive team signup map here. You can ask yourself questions like, why one of Canada's smallest provinces (New Brunswick) has more student teams than Ontario and Quebec combined, or wonder why Saskatchewan and Nova Scotia have no teams at all. Perhaps they don't use the internet?


The vast majority (over 90%) of cyber attacks on Canadian systems depend on user ignorance to succeed. We can't build a secure Canada if oblivious Canadians keep opening the doors and letting criminals and foreign state actors into our house. You don't have to pretend it isn't happening, building this essential media literacy can start here now:

Join the competition and sign up student teams of 4-6.
There are middle and high school divisions and community groups are also welcome to participate.

Friday, 6 September 2024

Turtles all the way Down

What have I learned from working inside the AI black box with Aman & Henry?

I've been working with generative artificial intelligence with students in my computer technology program since 2018 when we were fortunate to get a new grade 9 whose dad was on the team that brought IBM Watson to Jeopardy. That got us connected to IBM cloud and building AI chatbots five years before the "AI revolution" everyone has been caught out by.

That wasn't our first point of contact with AI though. I'd been keeping an eye on AI dev as far back as 2015 because we launched our gamedev course then and getting handle on building intelligent responses to player actions in our games immediately became our biggest challenge. Thanks to Gord and IBM we were able to get our juniors familiar with AI prior to asking them to take on significant software engineering challenges with it in the senior grades.

I presented on AI use in the classroom at the ECOO conference pre-COVID in fall of 2019. Gord from IBM even came all the way down to Niagara Falls to offer world class suppport. The room was all but empty:

This is how many Ontario educators (already interested in edtech because this is ECOO!) you get in an introduction to gnerative AI in 2019 (yes, it was four in an otherwise empty room). Ahead of our time (again)? Four years later it's an emergency and suddenly there are education AI experts everywhere. I wonder where they were in 2019.

If you ever wonder why education always seems two steps behind emerging technologies that will have profound impacts on classrooms, here's a fine example. Except you won't even see four people sitting in an empty room in 2024 because all edtech conferences like ECOO focused on teacher technology integration have evaporated in Ontario.

***

OK, so I've been banging my head against pedagogically driven AI engagement in education for almost a decade only to see it swamp an oblvious education system anyway, so what's happening now? I'm ressearching the leading edge of this technology to see if we can't still rescue a pedagogically meaningful approach to it.

In the summer Katina Papulkas from Dell Canada put out a call for educators interested in action research on AI use in learning. I've been talking to Aman Sahota and Henry Fu from Factors Education over the past year looking for an excuse to work on something like this, so I pitched this idea: De-blackboxing AI technology and using it to understand how it works.

Our plan is to use the Factors AI engine that Henry himself has built and Aman administrates to build custom data libraries that will support an AI agent that will interact with students and encourage them to ask questions to better understand how generative AI works. As mentioned before on Dusty World, GenAI isn't intelligent and it's important that people realize what it is and how it works to demystify it and then apply it effectively. Getting misdirected by the marketing driven AI hype isn't helpful.

So far we've built modules that describe the history and development of AI, how AI works and the future of AI. In the process of doing this I've come across all sorts of public facing research material that breaks down generative AI for you (like Deep Learning from MIT Press), but it's technically dense and not accessible to the casual reader.

During the last week of August Factors had a meeting with interested educators through UofT OISE (their AI system came out of the OISE edtech accelerator). I demonstrated in the presentation how the AI engine might be used to break down a complex article for easier consumption through agent interaction. The example was WIRED's story on how Google employees developed the transformers that moved generative AI from a curiosity to real world useful in the late teens. I picked this one because it explains some of what happens in the 'blackbox' that AI is often hidden in.

With some well crafted prompting and then conversational interaction, students can get clear, specific answers to technical details that might have eluded them in the long form article. The reading support side of GenAI hasn't been fully explored yet (though WIRED did a recent interesting piece on cloning famous authors to become AI reading buddies as you tackle the classics which is in the ballpark).

What have I learned from working in the engine room (BTW, that image at the top is Adobe Firefly's AI image generator) building an AI data library and then tuning it? AI isn't automatic at all. It demands knowledgable people providing focus and context to aim it in the right direction and maximize productive responses with users. An interesting example of this was finding documents that provided relevant data on the subjects we wanted the AI to respond to. When I couldn't find specific ones Henry suggested using Perplexity, an AI research tool that coalates online sources and then gives you concise summaries along with a bibliography of credible sources.

I thought I was being perverse asking Factors to design an AI that expalins AI using AI, but Henry's always a step ahead. His suggstion is to use an AI to build a library of information to feed the AI engine that then uses AI to interact with the user... about AI. It's turtles all the way down!

Saturday, 4 May 2024

Stay With Me, this is Going to Get Quantum Weird

 This was originally posted on the Canadian Cybersecurity Network's CyberVoices page: Stay With Me, this is Going to Get Quantum Weird 

CyberVoices is well worth a look if you want to get a sense of cybersecurity in Canada from many different perspectives in 2024. It gets you away from the goverment / business / marketing talk about cyber which tends to contain a lot of self-interested spin.

Canadian Cybersecurity Network's CYBERVOICES.

***

Science and technology were making great strides at the end of the nineteenth century, to the point where we were beginning to discover problems with the reality we thought we lived in. Newtonian physics does a great job of describing what we see around us, but it turns out this is an illusion created by the scale at which we operate. It’s like thinking the earth is flat because it looks that way, but it only looks that way because we’re not big enough to see it; reality is in the eye of the beholder.

What we discovered as we looked closer with better technology was that the universe isn’t a deterministic machine. The double slit experiment caused great confusion because it looked like light was both a wave and a particle. Rutherford’s gold foil experiment suggested that the recently discovered atom was almost entirely empty space. Most of what you breathe in is vacuum! The universe is much stranger than we first thought, and it isn’t deterministic at all, but very much probabilistic. Einstein hated this ‘spooky action at a distance’ quantum nonsense, but through the 20th Century we’ve come to understand that this is how the universe works.  Most people don’t know this because education finds teaching science in a Newtonian way easier. Professor Brian Cox has a good quote in his book, The Quantum Universe: “It’s not Newton for big things and quantum for small things, it’s quantum all the way.”

This emerging quantum awareness created the first quantum revolution. Once we recognized that quantum effects happen around us all the time, we started designing technology that made use of these newly discovered natural phenomena. If you think this is only for exotic university labs, you’re wrong. The flash memory that you’re likely reading this through depends on quantum tunnelling to work, as do lasers, MRIs and super conductors.

So, what’s all this talk about quantum computing and what the heck does this have to do with cybersecurity? In the 1970s many researchers started theorizing about quantum computing and Richard Feynman put it together in the early 80s, then the race was on to build the theory. What’s the difference between this and passive 20th Century quantum technology? We’ve developed the technology and theory now to engineer quantum outcomes rather than just using what nature gives us. As you might imagine, this is incredibly difficult.

I had an intense chat with Dr. Shohini Ghose, the CTO of the Quantum Algorithms Institute at the end of our quantum cybersecurity readiness training day this week in BC. She was (quite rightly) adamant that we can’t know quantum details without observing them and when we observe them, we change them, but my philosophy background has me thinking that I’m going to try anyway. An unobserved universe is entirely probabilistic. It only becomes the reality we see when we perceive it. It reminds me of the crying angels in my favourite Doctor Who episode. This bakes most people’s noodles, but the math clearly indicates that in measuring a photon’s location we can’t also know its velocity and direction – that’s the uncertainty principle in action. I’m probably wrong about all of that, but I’d rather people take a swing at understanding this strangeness rather than being afraid of being wrong.

Alright, we’re halfway through this thing and you haven’t mentioned anything cyber once! If you think about the electronic systems we use, they’re entirely Newtonian. They reduce information to ones and zeroes and produce the kind of certainty we all like, but this is a low-resolution approach that is about to hit its limit. We’re building transistors so small now that electrons are tunnelling through the nanometer thick walls (atoms are mainly empty space, remember?) between transistors, rendering future miniaturization impossible; we’re nearing the limits of our Newtonian illusion. That means the end of Moore’s Law! Panic in the disco!

Quantum computers don’t use electronics as a common base. A quantum computer processor might be ionized particles, or photons, or nanotech engineered superconductors, and those are just a few of the options. By isolating these tiny pieces of the cosmos away from the chaos of creation and applying energy to them in incredibly intricate ways, we can create probability engines that use astonishing mathematics to calculate solutions to problems that linear electronic machines could never touch, but unlike classic computers we need to do this without observing the process or all is lost. Imagine if you had to design the first microprocessors in the dark and you’re a fraction of the way towards understanding how difficult it is to build a quantum computer, but it’s happening!

We’re currently in what’s called the NISQ (noisy intermediate scale quantum) computing stage. We’re still struggling with applying just enough energy to get a particle to polarize how we want it to, all while keeping the noise (heat, radiation) of reality out. That’s why you see quantum computers in those big cylinders as a chandelier. The cylinders are radiation shields and containers to cool everything down to near absolute zero (gotta keep that thermal noise out), and the chandelier is to keep the electronic noise of the control systems (old school electronics) away from the quantum processor.

My favourite quote from the PhDs I’ve talked to is, “a viable quantum computer is five years out. And if I’m wrong, it’s four years.” What does that mean for ICT types? Quantum computers don’t do linear. When you give them a problem, they leverage that state of being everywhere at once to produce massively parallel computing outcomes completely foreign to what we’re familiar with in our multi-core processors. Quantum algorithms are designed to blackbox the calculation, so observation doesn’t spoil quantum processes and then spit out answers as probabilities.

What does that mean for cybersecurity? Peter Shor came up with an elegant idea in the mid-90s that uses a Quantum Fourier Transformation to calculate the periodicity in prime number factoring. If you can calculate the period of two large, factored primes (there is a repeating pattern), you can reverse engineer those primes. In RSA encryption or anything else that uses factoring you could calculate the private key and tear apart the encrypted transport layer handshakes rendering secure internet traffic a thing of the past. From there you could imitate banks or governments or simply decrypt traffic without anyone knowing you’re there. You won’t see cybercriminals doing this because the tech’s too tough, but nation states will, though you won’t see them either because they will be quietly collecting all of that encrypted online data Imitation Game style. This process may already have begun with harvest now, decrypt later (HNDL).

There is much more to quantum technologies in cybersecurity than the encryption panic though. Recent research suggests that instead of running into limits with electron tunnelling in transistors, our new quantum 2.0 engineering could leverage this quantum effect to create Qtransistors magnitudes smaller and much faster than what we have now. Cybersecurity will have to integrate that technology as it evolves. Quantum communication is another challenge. NIST is making mathematical quantum resistant algorithms as I type this, but you could also leverage quantum entanglement itself to create quantum key encryption. China has an entire network of satellites testing these hack proof comms links now. There could be quantum locked portions of the internet in 15 years where high security traffic goes. Guess who is going to have to manage those secure networks.

If you’re in cybersecurity there is much more to quantum than panicking about encryption. Anyone in the field would be well served by digging in and researching this fascinating technological emergence. My colleague, Louise Turner, and I presented at the Atlantic Security Convention on this in April. Give our presentation a look. There are lots of links to fascinating resources. It’s time to free your mind, Neo.

Friday, 8 March 2024

Little Cyber Skills Bonfires Across Canada

 It's been one of those months when possibilities for the future keep going in and out of focus. My secondment ends in August. There might be a possibility of an extension, but there are questions around whether or not I'm allowed to do it contractually. There are also questions around whether or not I want to go back into the classroom at all. Here are some of the things that have happened in the past few weeks that have me up at 5am after a14+ hour work day that should have knocked me out for a full night of sleep...

I did a ten day run across the Maritimes a couple of weeks ago. This involved a teacher PD day in Nova Scotia on a Saturday and then in class enhanced technology training days in schools across New Brunswick which mainly focused on trying to leverage the national CyberTitan cyber range competition images from previous years with students with varying backgrounds in cybersecurity. This isn't edtech as you know it, it's leading edge technology being leveraged to teach complex, interdisciplinary ideas that we can't usually get anywhere near in the classroom.

The first day in Fredericton was frustrating due to technical difficulties and pedagogical challenges. Using state of the art cloud based cyber range simulations is always going to be a stretch in classrooms. Doing it on the IT infrastructure in schools is like trying to drive a Formula One car on a dirt road. The range of student skill made it impossible to sufficiently differentiate in order to land everyone in Vygotsky's zone of proximal development and technical issues only complicated matters further. I finished the day exhausted and frustrated.

Day two completely restored my faith in this experiment. Oromocto High School has a brilliant computer technology instructor who has built a strong community of CyberTitans and the computer lab we were in was fit for purpose. We had a great day on the range where I got to see students grasp concepts that even CyberPatriot can't address due to it's old-school desktop virtual machine approach. On top of that I learned I am not alone! Blair, who runs the program at OHS is also Cyber Operations qualified, making us the only two I know of in Canada. Teachers like to invent their own certifications (and degrees) for education technology rather than explore relevance with what everyone else is doing, so it was nice to meet another willing to take on the challenge of a globally recognized industry cert.

Over the week I got to iterate with schools with little to no CyberTitan experience and even a middle school. There are edge cases around exceptional teachers where this kind of enhanced learning is not only possible but essential if we're to develop students capable of surviving the very technologically disruptive future we all face. One of my key takeaways in that week was to emphasize the importance of tending to these unicorns, they are few and far between.

I wrapped up the trip in Charlottetown where our local partner and I had a great chat with CBC radio about how to build genuine cyber-fluency. This is like starting a fire with wet wood. It takes skill, determination and collaboration to make it work, and none of these things are easily found in Canadian education. Having now taught in classrooms from BC to Newfoundland, I've been fortunate enough to experience the wildly inconsistent landscape of Canadian education (there is no such thing, we are the only developed country in the world without a national educaiton strategy), but there are commonalities, like the staggering lack of digital skills we graduate students with. Nurturing local expertise is a way to scale this up. I hope administrators from coast to coast recognize and focus on that.

I finally cracked the TV egg and found myself on CBC Compass. The final question there was a big one, but I stand by my answer: we need to be teaching meaningful digital literacy so that our students can operate safely and effectively in an increasingly technology dependant world. We indeed face global challenges that threaten our future. If we don't start learning the tools at our disposal effectively, we're not going to solve them.

The frozen sea on an empty PEI shore...


Saturday, 25 November 2023

What You Need To Work in Cybersecurity: the secret sauce

I see a lot of rules based 'quick fix' learning opportunities in cybersecurity. These are usually boot camp style condensed programs that promise to turn an accounting or science student into a cybersecurity practitioner in a single semester by showing them how to use tools in a formulaic manner. They treat cybersecurity as though it's an office job: we show you the cybersecurity rules and you follow them. You can see how well this is working by the ongoing shortage Canada faces in finding and retaining cybersecurity professionals.

I got into cybersecurity with my students in 2017 when we started chasing CyberTitan, but I brought something with us that is atypical in the world of STEM: a willingness to hack. I don't like the word hack, it has negative connotations to it in English that have been encouraged by the self appointed masters of STEM (the S&M part), but that willingness to iterate and work outside expected outcomes is the secret sauce in cybersecurity that many ignore, and a major reason for why I've taken to it like I have.

'Necessity is the mother of invention' has been the motivating factor in my relationship with technology since the beginning. I moved quickly from off-the-shelf to customized solutions based on experimentation and need. Within six months of owning my first home computer (a VIC20), I'd figured out how to copy software using a sufficiently low noise audio deck. My first x86 PC was purchased but quickly modified as I came to need more memory and processing power. By the mid-90s I was building my own computers at a time when many people didn't own one.

This process was initially powered by curiosity, which many training programs eclipse with a promise to provide the initiative so you don't have to - something that has never appealed to me and a major reason why I didn't start collecting technical certifications until 2001 (I'd been working in IT for a decade at that point). Schools are bad at nurturing enthusiasm for self-exploration too. Many educators feel that it is their job to impart knowledge in a regimented format (that's why we call them disciplines!) and assess student understanding through a system of providing both the questions and the answers to minimize any frustration. Assessment success is often a measure of compliance rather than cultivating enthusiasm and curiosity.  Many in education call this approach rigorous and disciplined - it's how they demonstrate credibility, and a reason why I haven't continued pursuing academia.

Indians have a term for austere innovation: jugaad (non-conventional, frugal innovation) which doesn't have the pejorative connotations of the English 'hack'. Jugaad celebrates common sense with a solutions focused approach to creative problem solving without needless bureaucracy. It emphasizes an applied approach to making technology work that is especially needed in an industry like cybersecurity where practitioners are often facing edge cases that the people who designed the network never thought of (which is why we're having a cyber problem). WIRED recently did an article on a Ukrainian technologist who demonstrated this start-up/rapid response approach in the war with Russia. There is even an event in cyber that is all about extreme edge cases: the dreaded zero day vulnerability. Jugaad will get you much further than any amount of system think during a zero day attack.

Kintsugi has played a part in my motorcycling.
There is also a term in Japanese that takes the derision found in English out of making old things work. I've long enjoyed the concept of 'kintsugi' or 'golden joinery', which is the repairing of old things using gold to embellish the fix rather than trying to hide it. In typical Japanese fashion it raises what is seen as banal work in the West to an artform. A concept that combines jugaad's celebration of a fix beyond rules based approaches with kintsugi's raising of that fix to an artform is where a good candidate for work in cybersecurity should find themselves inspired. When I started in cyber I found my  IT background helped in terms of understanding the mechanics of what was happening, but my kintsugi powered jugaad approach is what has allowed me to thrive.

This 'secret sauce' is often ignored in education and especially in cybersecurity adult retraining. There are some disciplines that tend to attract rules focused types, but that fixation on systemic order blinds them in the edge cases where cybersecurity often operates. Rather than retraining an accountant or rigorously compliant STEM student, I suspect that those exploring subjects like detective work in policing or creatives in the arts would find the skills they've honed more effective, but that doesn't stop everyone from demanding a computer science degree for any job in cyber.

In 2019 after the Terabytches went to CyberTitan nationals we got invited on the local radio station to talk about the experience. The interviewer asked me a good question about our DIY approach to computer tech. I was annoyed at the lack of resources, but he suggested it might be what gave us an edge. He was right, we'd been jugaading and it made us mighty!

There are many jobs in cybersecurity. People who lean toward the jugaad end where they can problem solve without restrictions can find a comfortable fit in operational cybersecurity where they are monitoring real time threats, penetration testing where they are attempting to exploit a client's system to highlight vulnerabilities, or threat intelligence which focuses on gathering reconnaissance data on threat actors. But even in the policy and compliance work, a willingness to consider and understand threats and solutions that are outside the box is a necessity. The need to nurture and respect those out of the box thinkers working in unexpected end of the cyber-workforce is essential for management. Those industries that thrive on status quo compliance are the ones you see being hacked most often because they don't respect the skillset.

This map of cybersecurity domains gives you an idea of the many specializations that the field offers, though I would argue that in all of them (even those up the compliance end) an ability to work from your own initiative and experience rather a rule book is essential.


Sam Sheepdog & Ralph Wolf know the score.
I sometimes describe cybersecurity types as sheepdogs. I think many in law enforcement also fit this description. You can't send a goat to fend of wolves, but having a wolf of your own will do the trick. Early on in my transition from IT into cybersecurity I found myself leaning on IT administrative habits that don't work in cyber, and came to realize that the jobs are very different, though the technology is the same. If you have an IT person running your cybersecurity you're likely to be constantly surprised by the attacks you face because they tend to see systems in an architectural way rather than as an opportunity to be compromised.


It would be easy to say something silly like, 'there are no rules in cybersecurity!' but that's pointlessly reductive. It would also be easy to describe all the people in it as hackers, but this isn't true either, though a mentality that tackles problems from a place of curiosity and jugaad is far better than a rules compliant myopic who can't see beyond the framework they maintain. At the end of all this I firmly believe that you need a bit of the wolf in you if you want to consider a career in cybersecurity. I wish more cybersecurity training and especially adult retraining would emphasize that when looking for candidates rather than demanding STEM grads often missing these skills. If it's a formulaic job that you're looking for, cyber isn't it.

STEM students are often missing skills which "include teamwork, collaboration, leadership, problem-solving, critical thinking, work ethic, persistence, emotional intelligence, organizational skills, creativity, interpersonal communication, and conflict resolution." Adding an 'A" to STEM doesn't fix this, incorporating an iterative, resilient, interrogative, team-based problem solving mindset into STEM subjects would, but that doesn't tend to be how we teach it.


Another piece of Canada's cybersecurity puzzle came into focus from the last post on how our cybereducation system is broken. In response to that, Francois Guay from the Canadian Cybersecurity Network followed up with the observation that the cybersecurity talent pipeline in Canada is also in tatters.

I've been thinking about that post and believe all of the responses from both new cybersecurity practitioners and veterans are valid. It would appear that when you try to fix a talent shortage with rushed retraining based on incorrect assumptions about the skillsets needed in cybersecurity, no one trusts the results. Problems such as absurd requirements for entry level positions like asking for 5 years of experience on a tool that only came out last year or demands for that vaunted yet irrelevant computer science degree continue to strangle entry level workers coming into the field, even though they have hacked (cough) their way through our broken cyber education system to do it.

Not to sound hopelessly jugaad, but the simple solution would be to introduce cybersecurity apprenticeships that give a more diverse set of potential candidates the opportunity to see if cybersecurity is a field of study that suits them. Those with the right combination of fearless curiosity, critical thinking and tenacity might find their way into it instead of continually opening the doors to STEM grads who are good at being told what to do and enjoyed the privilege growing up of being able to handle the enormous homework loads STEM subjects demand as part of their compliance regime. Students with a background in science and technology might be familiar with the medium that cybersecurity operates in, but that doesn't mean they'll be able to handle the stochastic demands that resonate across cybersecurity work. It's better to find those with the right jugaad mentality; technical familiarity will build quickly powered by enthusiastic initiative and tenacious problem solving.

I've always told my students that if they can bring a willingness to explore, experiment and a fearlessness in breaking things in the process of figuring them out, they don't need to sweat the technicalities, I can teach them those by harnessing the curiosity they bring with them. I've had strong technical students struggle in cyber because they lean on formulaic approaches to computing (they are often maths strong coders) that let them do the bare minimum. If your natural talents in mathematics and computer science have blessed you with a compliance based work ethic, cyber with its changeable success criteria isn't for you. Another favourite adage of mine in the classroom is, 'if you're looking for a way to do less, you'll usually find it.' Those that want to work in a framework often do it so that they can delineate where they can stop; in other words it's used as a way to limit their involvement. That's no way to approach cybersecurity. If solving a problem is a nine to five gig for you, go find work elsewhere.



Much of this comes back to the reductive way we have approached digital skills development (when we're not ignoring them entirely). Cyber Education is the hidden, much larger part of the digital skills iceberg.