Mark Raeburn

Mark Raeburn, Director of Cyber Security and Resilience, GSA Global

Cyber security continues to evolve, but technology is only part of the challenge. The way people behave, the information they trust, and the decisions organisations make before, during and after a cyber incident can have just as much impact on their organisation’s resilience.

To mark Cyber Security Awareness Month, we sat down with GSA Global’s Mark Raeburn to talk about his career in cyber security, how the threat landscape has changed and some of the challenges he sees organisations facing today.

From social engineering and stolen credentials to trust, human behaviour and incident response, we asked Mark what organisations should be thinking about and what he has learned from his own career in cyber security.

Mark, let’s start at the beginning. After serving in the Army, what first attracted you to security and ultimately cyber security?

I didn’t actually set out to work in cyber security. In 1990, after being referred by a friend, I found myself being offered a job as Physical Security Manager at Coopers & Lybrand.

In the early 1990s, Coopers & Lybrand bought around 2,000 Compaq Luggables, the first ‘laptop’ computers. I remember thinking that we could have all the security in the world protecting our offices, but these computers would now be taken outside. If one was lost or stolen, our clients’ data could potentially go with it.

I had read an article in a security magazine about someone who could break into computers, so I invited him to lunch. His name was Mark Oram, and he showed me how he could get into both one of the Luggables and the computer sitting on my desk.

I went to my boss and explained what I had discovered. His response was pretty simple: “You’re Head of Security. Fix it.”

Needless to say, I bought Mark another lunch.

He started teaching me how people could break into computers and networks, but more importantly, what we needed to do to protect them. I was hooked.

I’ve never considered myself a techie, but I understood what clever technical people could do and, perhaps more importantly, what organisations needed to do to manage the risks that resulted if cyber security was not effective.

That eventually led me to start my own cyber security consultancy with Mark and another highly technical colleague, Sean Leviseur.

You’ve worked in cyber security for more than three decades. What has changed most during that time, and what has remained surprisingly similar?

I’ve been very lucky, and honoured, to have been involved in cyber security, and security more generally, at the right time. When I started, there was no such role as an IT Security Manager or Chief Information Security Officer. There weren’t really university courses in cyber security either, just more general security courses.

The striking thing is that while technology has changed at an increasingly rapid pace, many of the underlying problems remain much the same.

I used to say that the problem is people. Bad people will always want to do bad things, and if they can do those things using a computer, it is often both easier and there is far less likelihood of being caught. My strapline was always: “Computers don’t attack you, people do.”

My strapline was always: “Computers don’t attack you, people do.”

I guess I now have to change that strapline. We have seen the first examples of AI agents deciding on their own to attack organisations.

Change has always been one of the most exciting things about cyber security, but I don’t think it has ever been so quick, or so difficult to see what’s coming next.

Having founded Context Information Security and later led Accenture’s global Incident Response team, what have major cyber incidents taught you about where organisations are most vulnerable?

I’ve been lucky enough to have had a front-row seat on what must be over 1,000 investigations, including some of the very biggest cyber breaches. It’s a much more comfortable position to be advising the victims than being one yourself.

Experiencing a full cyber attack is highly traumatic and can go on for several months. Those that find it easier are, unsurprisingly, the organisations that have thought about it in advance and have a plan that they have practised.

The most vulnerable are often those that haven’t considered which of their assets are most important and what a bad actor could do to disrupt or steal them.

If you come into work on a Monday morning and everything is encrypted, including your backup, that’s a seriously bad day in the office.

Cyber security is often seen as a technology issue. How much of the risk actually comes back to people, behaviour and the decisions they make?

Like I say, I used to be able to say, “Computers don’t attack you, people do,” but maybe not anymore. That said, it’s still mainly people attacking you that you should be worried about.

Most of the big breaches over the last year have involved clever attackers using social engineering techniques to get passwords reset, trick people into clicking on something or persuade them to give away sensitive information.

There is no patch for stupidity, and people remain the weak point that is most often exploited.

What people post on social media these days also astounds me. People seem quite comfortable sharing sensitive information without necessarily considering who else might be looking at it or how that information could be used.

Social engineering, stolen credentials and information available online are increasingly being used to target organisations and individuals. How has this changed the way organisations need to think about cyber security?

Many organisations have learned the hard way, after an incident. It’s a painful and expensive way to learn that you need to be better prepared.

Staff training is clearly important, but it will never be enough on its own. Prevention is obviously the best option, but there is no such thing as completely secure. Even the most advanced organisations can, and have been, breached.

Investing in a balanced programme of prevention, detection and response therefore offers you the best chance of minimising the consequences of a breach.

We talk a lot about trust at GSA Global. Do organisations underestimate how trusted people, relationships, suppliers and access can be exploited by attackers?

Trust is essential in any organisation, but it’s often that trust that is misused to gain access to systems. People are naturally inclined to trust what they hear and read, and AI is becoming particularly good at creating emails and documents that appear entirely trustworthy.

These days, the biggest risk of a breach may not necessarily come directly from within your own organisation. Trusted third-party suppliers or software can often provide attackers with an easier route in.

Understanding who and what you trust, and the access that trust provides, has therefore become an increasingly important part of cyber security.

Having helped organisations respond to major cyber attacks, what separates those that respond well from those that struggle?

Like I said earlier, fail to plan, then plan to fail. Understand the assets you have and the threats you face.

Have a clear understanding of what must be maintained, both data and infrastructure, to ensure the organisation’s survival, and plan in advance how you can make those critical systems and data more resilient.

Have a plan and practise it. The more you practise, the better you get.

Learn from the misfortune of others too. When a new attack is reported, ask how well your plans would cope with a similar event and update them when you identify gaps.

Don’t beat people up for finding those gaps. Celebrate the fact that you’ve found one and have the opportunity to fix it before a real incident does it for you.

You led Accenture’s UK & Ireland Cyber Resilience practice. What does being genuinely cyber resilient look like, and how can an organisation know whether it really is prepared?

The only way to know if you’re ready is to test, test and test again. You are far better finding out what needs fixing during a simulated attack than when you have a bad actor inside your network.

I’ve seen attackers sitting on a compromised network, watching the management team floundering around trying to work out what is going on simply by reading the emails being sent across that same compromised network.

Trying to kick an attacker out when they know what you know is almost impossible.

That’s why testing is so important. It gives you the opportunity to find the weaknesses in your plans, communications and decision-making before you have to rely on them for real.

If you could get every board or senior leadership team to ask themselves one question about their cyber security, what would it be?

Do you understand what an attacker could do to your business, why they might want to do it, and ultimately, are you ready?

Cyber Security Awareness Month is ultimately about encouraging action. What is one thing you would encourage every organisation, and perhaps every individual, to do differently? Questions every organisation should be asking about cyber security.

No matter what level you are at within an organisation, think about what you need to do your job and consider what would happen if it suddenly became unavailable for an extended period. What would you do?

And stop and challenge the trust you place in your communications. We are all used to trusting the emails, messages and information we receive, but increasingly that trust can be exploited.

If you’re not sure, stop and ask.

Mark’s answers highlight an important point: cyber resilience is not simply about the technology an organisation has in place. It also depends on people, processes, leadership and how effectively an organisation can respond when something goes wrong.

Continuing the conversation

Cyber Security Awareness Month provides an opportunity to talk about cyber risk, but these are conversations organisations need to be having throughout the year.

Over the coming months, we will be speaking with more of GSA Global’s specialists about their careers, experiences and the issues they believe organisations should be thinking about across cyber security, investigations, protective security, travel risk management, insider risk and other areas of organisational resilience.

Each conversation will provide an opportunity to get to know the people behind GSA Global, while drawing on their experience to explore some of the challenges facing organisations today.