Training Young Hackers To Stop Cybercrime

At the heart of a police operation to defend Britain from attack by cybercriminals, a 14-year-old boy was honing his skills to thwart hackers linked to a rogue state.

Ben Abrahmason was among a group who gathered at a military base in Wiltshire to counter fictional but sophisticated cyber-attacks. Police chiefs and intelligence officers hope young people like Ben will become the latest recruits in the rapidly evolving war. “A lot of it is like normal forensics. There are fingerprints, DNA, except it’s digital,” said Ben, from Leicestershire. “You examine phones, laptops, hard drives: the data on them can help you solve crimes.”

He had passed rigorous online tests to be selected to spend the day being tutored by experts from the National Crime Agency. Police say it is important for them to woo talented hackers who might be tempted, out of boredom or greed, to target companies or even work for criminals.

Colin Lobley, chief executive of Cyber Security Challenge UK, which organises a series of national competitions to identify the best potential “cyber-defenders”, said: “They might be phenomenally talented, but not old enough for us to offer them anything so we have to keep them interested and prevent them going to the dark side.”

He was referring to the network of cybercriminals which Europol has warned is responsible for launching 4,000 ransom attacks a day and whose technological capability threatens critical parts of the financial sector.

The government’s National Cyber Security Centre, in its 2017 annual review, revealed it had responded to 590 significant incidents including attacks on key national institutions such as the health service and the British and Scottish parliaments.

Christopher Williams, 18, from south London, is another who wants to help defend the UK’s critical infrastructure from cyber-attack.

“Anyone who’s a good citizen wants to help their country. It’s exciting to know you can still help protect your community and your country, to defend the UK using forensic skills to provide support for British troops overseas and the likes of MI6,” Williams said .

There was another pressing reason for Friday’s event: a gaping skills shortage threatens the rapidly expanding cybersecurity sector. Robert Hannigan, the former head of GCHQ, the intelligence and security agency, has predicted a “huge skills shortage” by 2025.

Craig Jones, head of preparing cyber-capability at the National Crime Agency, warned that if the UK failed to recruit top-level talent it would not be able to keep pace with criminals. “It’s simple: we are going to struggle. We need the best people to progress, though we also need to recognise that people are not going to stay for a 30-year career in law enforcement,” said Jones.

One area where recruitment must improve is in attracting more women to the sector. On Friday only three of the 30 contestants were women, a ratio that broadly mirrors the UK sector as a whole. Only about 8% of jobs in cybersecurity are filled by women compared with 11% globally.

One of the female contestants, Rhiannon Eason, 23, from Oxford, said: “I have always been interested in forensics and law enforcement, but until recently I had never thought of cybercrime. I’d like to do either forensics or ‘red team’ penetration, where you are an external attacker to test defences. I’m happy to play either side.”

Del Rattenbury joined the National Crime Agency in 2014 and explained that becoming a cybersecurity investigator could make the difference between life and death.

She said that one of her operations had helped reduce deaths from the synthetic opioid, fentanyl, which had been linked to particular drug producers in China and suppliers on the dark web. Other investigations had identified women who had been trafficked.

“You are protecting some of the most vulnerable people in society, saving lives,” she said.

The Guardian:

You Might Also Read:

Cybersecurity Training For High School Students

« Why Mainframe Security Risks Are Largely Unrecognized
The Best Security Is Based On Zero Trust »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Certification Europe

Certification Europe

Certification Europe (now Amtivo Ireland) is an accredited certification body which provides ISO management system certification, including ISO 27001.

QASymphony

QASymphony

QASymphony software testing and QA tools help companies create better software by improving speed, efficiency and collaboration during the testing lifecycle.

British Insurance Brokers’ Association (BIBA)

British Insurance Brokers’ Association (BIBA)

BIBA is the UK’s leading general insurance intermediary organisation. Use the ‘Find Insurance‘ section of the BIBA website to find providers of cyber risk insurance in the UK.

Forensic Control

Forensic Control

Forensic Control specialise in providing simple & straightforward Cyber Security to organisations, helping them assess, prevent and respond to cyber threats.

Scout Ventures

Scout Ventures

Scout Ventures is an early stage venture capital firm that is making the world a better, safer place by cultivating standout frontier technologies.

BullGuard

BullGuard

BullGuard is an award-winning cybersecurity company focused on providing the consumer and small business markets with the confidence to use the internet in absolute safety.

LogicalTrust

LogicalTrust

LogicalTrust security testing specialists find the weakest points in your company and show you how to fix them step-by-step, as well as how to improve your security.

Eleos Labs

Eleos Labs

Eleos Labs' suite of security tools prevent Web3 cyber attacks, reduce economic risks, and protect digital assets.

ArmorPoint

ArmorPoint

ArmorPoint redefines the traditional approach to cybersecurity by combining network operations, security operations, and SIEM technology in one platform.

Sababa Security

Sababa Security

Sababa Security is the first Italian innovation cyber security vendor, that provides security products, training, and managed services to protect diverse IT and OT environments.

SecurEnvoy

SecurEnvoy

SecurEnvoy are a leader in designing zero access trust solutions using the latest cutting-edge technologies, to protect your users, devices and data, whatever the location.

Kolide

Kolide

Kolide ensures that if a device isn't secure, it can't access your apps.

C/side (cside)

C/side (cside)

At c/side, we're creating the ultimate delivery, performance and detection mechanism for browser-side fetched 3rd party Javascript.

NinjaOne

NinjaOne

The NinjaOne Platform was built to help IT and MSP teams efficiently manage, patch, and support all endpoints.

GoCloud Systems

GoCloud Systems

GoCloud is an IT consulting firm. We provide IT strategy and cloud adoption services to the New Zealand Government, Non-Profit Organisations and private industry.

Triovega

Triovega

Triovega are a leading provider for production security and efficiency. Our solutions enhance OT security, and reduce production downtime.