CERT.JE - What are you unwrapping this Christmas?

Dear all,At CERT.JE we’ve been putting a lot of effort into security this year – yours as well as ours. After all, we don’t want cyber criminals breaking in to our computers this Christmas and leaving unwelcome gifts of viruses, worms or ransomware.Other gifts of course can be warmly welcomed, but if you unwrap a new phone, laptop, or connected device this Christmas please bear in mind that whilst these can be wonderful tools (or toys!) they are not free of risk, and taking some basic steps can protect you and your family. So as our gift to you, we’re sending you our very own digital Christmas cards – 10 tops tips for a safe and secure Christmas, shared via social media between now and the end of December. Follow CERT.JE on LinkedIn, Twitter, Facebook or Instagram to unwrap them.On a personal level, my family life as well as my professional life over the last year have been very much affected by Russia’s war in Ukraine. This final newsletter of the 2022 is therefore dedicated to those whose most basic security has been taken away, and who have nonetheless proven their personal resilience in the most trying of times. Please do consider supporting them at Side By Side, Jersey | Bailiff's Ukraine Appeal.We move into 2023 with a much stronger cyber capability in Jersey. During Cyber Security Awareness Month we welcomed to CERT.JE Paul Dutot as Head of Cyber Defence, James McLaren as Senior Analyst and Morgan Franklin our Digital Apprentice.We still have a long way to go, and next year will for us be a year of action. I will be hoping it is less eventful - but whatever the world throws at us, this year has shown that we can rise to the challenge and deliver together as one island, and with the support of our partners both locally and internationally.Thank you to everyone who has helped us on this journey so far – we look forward to working with you all in the new year and beyond.Regards,Matt

Season's greetings from CERT.JE! 🎅🤶

Please stay safe online this festive period. Keep an eye on our social media accounts for a series of Christmas cards with ten bits of helpful advice.

Follow CERT.JE on YouTube 🎦📺

The Channel Islands Cyber Security Conference content is now available on CERT.JE's YouTube Channel, with more great content to come.

From around the web

GitHub

CERT.JE is now on GitHub, the code and project collaboration infrastructure. GitHub is used to host useful defensive configurations such as logging and incident response tools. Many CERTs around the world use it for software development with the service providing the distributed version control of Git plus access control, bug tracking, software feature requests, task management, continuous integration, and wikis for every project.

The JPCERT Coordination Center is a great example, with several tools such as SysmonSearch, LogonTracer and EmoCheck.

GitHub also hosts projects that people can contribute to such as bug reports - see here - No responders available to enable in Cortex 3.1.7-1 Web UI · Issue #437 · TheHive-Project/Cortex · GitHub

Help us!

Are you a cyber security professional?

Please help and send us a short clip of yourself so that we can show as many varied careers in our industry as possible.

To raise awareness of the exciting careers possible in cyber security we need video content that can be used repeatedly in schools. The first batch of these short videos will be played as a series in either computing and career lessons or assemblies.

The minimum to include is:

  • What do you do (day to day tasks)

  • Why you like it

  • Any qualifications (if needed)

  • Skills that make a difference

  • What subjects you/your team enjoyed (the more diverse the better)

  • Next steps to get started on their journey

Try to make the video short and not just sat at your desk. Multiple short videos can be used if you have lots to say.

For further tips Digital Jersey's Rory Steel has you covered in this short video - https://www.youtube.com/watch?v=eZ7SfwqxCDw

To upload a video, please place it in this folder: Cyber Security Video Uploads

Resources

Upcoming Events

Local: Christmas Drinks - Channel Islands Information Security and Data Protection with the CIISF, the Channel Islands Data Protection Forum and the BCS Jersey Branch - 15th December 2022

This informal event at CERT.JE will provide an update on what's been happening in 2022 from a cyber security and data protection perspective, plus what we can expect in 2023.

Also available to virtual attendees, on Zoom. Grab a glass of your favourite tipple and join the festivities remotely.

Online: Infosec Jupyterthon with the Open Threat Research Community - 2nd & 3rd December 2022

An open community event for security researchers to share their experience and notebooks with the InfoSec community. Detailed schedule here.

Jobs

COMING SOON AT CERT.JE:

If your interest and expertise is in cyber risk management or industry engagement and you're driven to make a positive difference to our Island, keep an eye out for our final roles with CERT.JE, coming soon.

Ogier - Senior Technical Analyst (Network & Security)

This is a hands-on technical role, you will need to be passionate about the ever changing environment of infrastructure services, particularly the shift towards Cloud computing, as well as technically expert in one or more key Ogier technologies. As a senior role within the IT Infrastructure Network and Security Team you will architect, implement and maintain highly-available and secure IT infrastructure services across the Group.

Standard Bank International - IT Security Head

Design, develop and deliver the IT Security and Logical Access Strategies for International Client Solutions (ICS), ensuring continuous alignment with SBG Group. A sound general knowledge of Information Technology and Cyber Security methodologies is required, alongside good judgement in relation to business and risk situations, specifically in relation to cyber and information risk.

Jersey Financial Services Commission - Cyber Security Officer

To provide day-to-day assistance to the support of the Cyber Security function within the ICT department.

PwC - Cyber Manager, Risk Assurance Services, Advisory

This career within Financial Markets Business Advisory services, will provide you with the opportunity to contribute to a variety of audit, regulatory, valuation, and financial analyses services to design solutions that address our clients’ complex accounting and financial reporting challenges, as well as their broader business issues.

Tool of the month

Fastfinder is a tool to help with incident response, it can be used to find a potentially malicious file at scale across a network.

It also has some nice features such as YARA rule integration plus wildcard searches, and was designed to be used for CSIRTS.

If you’d like to share local resources, jobs or events related to cyber security please do let us know via email to [email protected].