Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if...

33
Building the Next-Gen Cyber Professionals Ron Woerner Tuesday, May 16, 2017, 11:00am M100G-H

Transcript of Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if...

Page 1: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Building the Next-Gen Cyber Professionals

Ron Woerner

Tuesday, May 16, 2017, 11:00am

M100G-H

Page 2: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black)

Tweet along: #Sec360 www.Secure360.org

Alternative Title:

Page 3: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

3

R U a H@cker?

I am

Page 4: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Ron Woerner

• InfoSec Architect, Carlson Rezidor Hotel Group

• Professor Cybersecurity Studies, Bellevue University

• >25 years corporate IT, 15+ Security

• CISSP, CISM, & Certified Ethical Hacker

• US CyberPatriot Mentor since 2011

• Mentor of the Year 2013-2014

Tweet along: #Sec360 4 Ron Woerner – Hacking Humans

www.Secure360.org

Page 5: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

• These are my thoughts based on my studies and experiences

• Normal caveats apply

• Comments & questions are welcome any time

Tweet along: #Sec360 5 Ron Woerner – Hacking Humans

www.Secure360.org

Page 6: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Meet Charlie Kilo*

High School Sophomore

Hacker

* Name changed to protect the guilty

Page 7: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 8: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Kids are born to hack

8 Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 9: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

What happens?

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Out of control

curiosity

No safe place to explore

Lacking

Teachers

Page 10: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Leads to Trouble

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 11: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

“Kids today know so much technology”

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

WRONG!

They know about tech.

Most don’t know how it works.

PFM*

* Pure Freakin’ Magic

Page 12: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Test time

How many ways does this have of communicating?

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 13: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Just because I have a degree in Computer Science doesn’t mean I know anything about computers…

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 14: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

IT / Cybersecurity is not a part of standard HS curriculum

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Lack Experience

Lack Resources

No Time

FEAR

Page 15: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

IT / Security People Needed

http://www.rand.org/content/dam/rand/pubs/res

earch_reports/RR400/RR430/RAND_RR430.pdf

Tweet along: #Sec360

Ron Woerner – NextGen Cyber www.Secure360.org

Page 16: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

What’s going well

• Individual teachers & programs

• Job opportunities & Internships

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

• Gen Cyber

• CyberPatriot

• Hour of Code

• Hack4Kidz

• Hacker High School

• High School CTF

Page 17: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Good Things

http://www.hak4kidz.com/

Page 18: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Good things

Page 19: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Good Things

https://www.uscyberpatriot.org/

Page 20: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

What’s the answer?

How do we address the issues and multiply what’s going well?

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org 20

Page 21: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Embrace kids inner hacker

Page 23: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

CyberPatriot Demo

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 24: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Build your own playground

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 25: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

High School CTF

http://hsctf.com/

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 26: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

National Cyber Defense Competition

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

http://www.nationalccdc.org/

Page 27: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

PLEASE HELP!!!!!

1. More teams

2. More teacher coaches

3. The kids need the direction, or else they’ll turn to the dark side

4. You learn a lot

5. Professional mentors get CPEs / find recruits

6. Low $ needed

Page 28: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Volunteer Opportunities

• (ISC)2 Foundation - Safe and Secure Online Program

• (NCSA) National Cyber Security Alliance

• CyberPatriot

• Hackid Conference

• Hacker Highschool

https://www.rsaconference.com/about/rsac-cyber-safety/rsac-cyber-safety-volunteer-opportunities

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 29: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Benefits

Kids

Everyone

You

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

Page 32: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Links & Resources

Tweet along: #Sec360 Ron Woerner – NextGen Cyber

www.Secure360.org

• How To Geek School – http://www.howtogeek.com/school

• Microsoft SysInternals – https://technet.microsoft.com/en-

us/sysinternals/bb795535.aspx

• High School CTF – http://hsctf.com/

• Facebook CTF – https://www.facebook.com/notes/facebook-ctf/facebook-ctf-is-now-

open-source/525464774322241/

• EPIC HowTo Be A Hacker –

https://www.youtube.com/watch?v=tlezBUdD53w

Page 33: Building the Next-Gen Cyber Professionals · Keeping Young Hackers Out of Orange Jumpsuits (even if it's the new black) Tweet along: #Sec360  Alternative Title:

Ron Woerner, CISSP, CISM

@ ronw123

ronw2007 (at) gmail.com

Tweet along: #Sec360 33 Ron Woerner – Hacking Humans www.Secure360.org