Anthony Dickinson

Anthony Dickinson, Technical Director, GSA Global

As part of Cyber Security Awareness Month, we recently sat down with GSA Global’s Mark Raeburn to explore how cyber security has evolved, why trust continues to be exploited and what more than three decades of responding to cyber incidents has taught him about resilience.

For our next Meet GSA Global conversation, we are taking a look under the bonnet.

We spoke with GSA Global’s Anthony Dickinson about the technical realities behind cyber security: the vulnerabilities organisations continue to overlook, how attackers identify weaknesses, where security controls can fall short and what organisations can do to better understand their cyber exposure.

Anthony, let’s start at the beginning. How did you get into cyber security, and what led you to GSA Global?

My academic training was in chemistry. I studied chemistry at university and then went on to do a PhD in computational chemistry, which involved using computer code to model and understand chemical bonding in molecules.

That was where I really developed my coding skills and became much more interested in computing and technology. From there, my career moved increasingly into technical and systems roles before I joined Sophos.

It was really during my time at Sophos Labs that I became deeply involved in cyber security. That gave me exposure to the technical side of threats, malware, systems and how attacks actually work, and from there my career developed into penetration testing, consultancy, security architecture, risk and leading technical security teams.

What attracted me to GSA Global was the opportunity to apply that experience more broadly. Cyber security here isn’t treated as an isolated technical problem. It sits alongside investigations, vetting, protective security and wider organisational risk, which is increasingly how clients need to think about security.

When you first look at an organisation from a technical security perspective, what are you looking for?

The first thing I’m trying to do is understand the organisation itself.

I want to understand what its key assets are, where its important information sits, what those systems and data are used for, and what would actually matter if they were compromised, unavailable or lost.

For example, for one organisation the critical asset might be customer data held in Microsoft 365. For another it might be an internet-facing application, intellectual property or an operational system that the business simply cannot function without.

From there, you can start to understand the organisation’s risk appetite and what level of protection is appropriate. Only then does it really make sense to look at the technical controls such as identity, endpoints, cloud services, networks, applications, monitoring and so on, and ask whether they are proportionate to the risks the organisation faces.

Without understanding the assets and what is important to the business, it is very difficult to make a meaningful judgement about whether the technical security is actually appropriate.

What are some of the most common technical weaknesses you still find, and are you ever surprised that they remain so prevalent?

Identity and access management continues to be one of the biggest areas.

You still find excessive privileges, old accounts, inconsistent MFA, unmanaged devices and applications that have accumulated permissions over many years.

A good example is an organisation that believes MFA is protecting everybody, but when you look more closely you find an old service account, shared account or legacy system that has been excluded. An attacker only needs to find the exception.

Another common issue is configuration drift. An organisation may have bought very good security technology, but over time exceptions are created, systems change and controls are weakened without anyone necessarily realising it.

The individual weaknesses are rarely surprising. What is surprising is how often relatively simple issues remain unnoticed because everybody assumes somebody else is looking after them.

We hear a lot about sophisticated cyber-attacks. In reality, how often do attackers need to be particularly sophisticated to get in?

Far less often than people might imagine.

There are certainly extremely capable attackers and very sophisticated attacks, but many successful compromises start with something quite ordinary: a reused password, a convincing phishing message, an exposed service, an unpatched vulnerability or a badly configured cloud environment.

You could spend a lot of time trying to exploit a technically complex vulnerability, but if somebody has reused their corporate password on another service and those credentials have subsequently been leaked, the attacker may simply be able to log in.

Attackers are generally pragmatic. If there is an easy route into an organisation, they are going to use it rather than spend weeks developing something technically sophisticated.

That is why getting the fundamentals right remains so important. You want to force an attacker to work hard.

Organisations often have a wide range of cyber security controls in place. What are some of the biggest gaps between how secure an organisation thinks it is and the reality?

One of the biggest gaps is between owning a security product and actually achieving the security outcome that product is supposed to provide.

An organisation might say it has MFA, endpoint protection, backups and device management. The important questions are: does MFA apply to everybody? Are there exceptions? Are all devices actually enrolled? Are security alerts being reviewed? Have the backups ever been restored?

We quite regularly see situations where an organisation believes all of its laptops are managed, for example, but when you actually look at the estate there are devices that have never enrolled correctly or users are still able to access corporate information from unmanaged machines.

The technology itself may be perfectly good. The gap is between what everybody believes has been implemented and what is actually happening.

Finding a vulnerability is one thing. How do you determine whether it represents a genuine risk and how urgently it needs to be addressed?

Technical severity is only part of the picture.

You need to understand what the vulnerability actually exposes, how easy it is to exploit, whether an attacker would need existing access, what other controls are in place and what the business impact would be if it were successfully exploited.

For example, a technically critical vulnerability on a system that is isolated, heavily restricted and contains no sensitive information may be less urgent than a much simpler weakness on an internet-facing system containing customer data.

Equally, something that looks fairly minor in isolation can become much more serious when combined with another weakness. Cyber attacks often involve chaining several relatively small issues together.

Good vulnerability management therefore needs context. The question isn’t simply, “How bad is this vulnerability?” It is, “What could realistically happen to this organisation because of it?”

That is what should drive remediation priorities.

Organisations invest heavily in security products and controls. How can they establish whether those controls are configured correctly and actually doing what they think they are doing?

You have to test them.

That sounds obvious, but there is often an assumption that because a product has been deployed, the control is working.

The key is to test the assumptions you are making about your security. MFA should protect the accounts you expect it to, access controls should prevent unauthorised devices from reaching corporate data, endpoint protection should respond to malicious activity and backups should be recoverable when you need them.

We have seen plenty of controls that look absolutely fine on paper but behave differently when you actually test them.

There should therefore be a combination of configuration review, technical testing, monitoring and periodic independent assurance.

Security controls should be treated like any other important engineering system. You shouldn’t rely purely on the fact that somebody configured them several years ago and nothing has obviously gone wrong since.

From an attacker’s perspective, how important is the information that can be gathered about an organisation before anyone attempts to breach it?

Extremely important.

A surprising amount can be discovered without touching an organisation’s systems.

An attacker can identify employees, technologies, suppliers, email formats, cloud platforms, recruitment activity and sometimes internal projects simply through publicly available information.

A job advert, for example, might tell you that an organisation uses a particular firewall, cloud platform or security product. LinkedIn may then tell you who administers it. Publicly accessible technical information can identify the services the organisation exposes to the internet.

Individually, none of those pieces of information may appear particularly sensitive. Combined, they can give an attacker a remarkably good picture of how an organisation works and where its potential weaknesses might be.

That reconnaissance can also make social engineering much more convincing. A phishing email referring to a genuine supplier, project or colleague is far more likely to succeed than a generic message.

How is AI changing the technical side of cyber security, both for attackers and those trying to defend organisations?

At the moment, I think AI is accelerating existing activity more than completely reinventing cyber attacks.

For an attacker, something as simple as phishing illustrates the change. Historically, badly written language or poor grammar could sometimes be a warning sign. AI can now produce a very convincing email in seconds and tailor it to a particular organisation, role or situation.

It can also help with reconnaissance, scripting and processing large amounts of information, lowering the technical barrier for some activities.

The same applies to defenders. An analyst can use AI to help interpret a large log file, explain an unfamiliar piece of code, identify patterns in data or automate repetitive tasks that previously consumed a lot of time.

The risk is over-reliance. AI can produce a very convincing answer that is completely wrong, so you still need experienced people who understand the technology and can validate the output.

The organisations that benefit most will probably be those that use AI to augment good security teams and processes rather than assuming it replaces them.

If you could get every organisation to address one technical cyber security weakness tomorrow, what would it be and why?

Users.

People are still one of the weakest links in cyber security, because so many attacks ultimately rely on someone clicking the wrong link, approving the wrong login, sharing information they shouldn’t, reusing passwords or being persuaded to bypass a control.

A good example is MFA. MFA is an extremely effective security control, but attackers have adapted. Rather than necessarily trying to defeat the technology, they may repeatedly send authentication requests until the user eventually presses approve, or persuade somebody that a login request is legitimate.

You can have very strong technical security in place, but if users don’t understand the risks or how attackers try to manipulate them, those controls can still be undermined.

So for me, improving user awareness and behaviour has a very broad impact. If you can make users more security-aware, more questioning and better able to recognise when something doesn’t look right, you reduce a huge number of potential attack paths at once.

That doesn’t mean blaming users. Organisations still need good technical controls around them, but well-informed users are a very important part of the security model.

The Question Every Organisation Should Ask

Anthony’s answers highlight an important distinction between having cyber security controls in place and knowing that they actually work.

Technology, threats and attack techniques will continue to change, but organisations can reduce uncertainty by understanding their exposure, identifying weaknesses and regularly testing the assumptions they make about their security.

Cyber Security Awareness Month is a useful reminder to think about cyber risk, but effective security requires organisations to keep asking questions throughout the year.

One question to leave with you:

How confident are you that your organisation’s cyber security works as you expect it to?