(BOOK REVIEW) The Hacker and the State: Cyber Attacks and the New Normal of Geopolitics

Share

BOOK REVIEW: The Hacker and the State: Cyber Attacks and the New Normal of Geopolitics
Author: Ben Buchanan

Reviewed by Peter Tran for The Cipher Brief

In the midst of the coronavirus global pandemic, I can’t help but draw parallels to the cyber
world in that the enemy is invisible, adaptable, pervasive and capable of shaping multiple
dimensions of domestic and international geopolitics. This is exactly what Ben Buchanan
accomplishes in somewhat of a Hitchcock-esque “Rear Window” style of putting the reader in a
front row seat to watch exactly how select nation states use their own home brew cyber hacking
techniques and tactics or what Buchanan calls “Statecraft” to disrupt, manipulate and arguably
change the course of our daily lives.

Although the book takes a scholarly approach in its research and fact finding, I did get a strong
sense this was more than just another cyber conspiracy story rooted in age-old cloak and dagger
politics. Buchanan takes the reader through an extremely relevant, well-articulated and qualified
view of the new realities of where the real battlefield exists in the next frontier of information
technology platforms and how those platforms extend geopolitically to everyday people from
Madison Avenue to Main Street.


What I found intriguing was Buchanan’s approach to espionage and disruption attacks within the
context of hacking with an original view of how the private sector big tech firms such as AT&T,
Google, Facebook, Apple and others hold a considerable burden on their shoulders within the
geopolitical foreign counter intelligence tug-of-war. This makes the reader really think about
whether the enemy of your enemy is really your friend. This made me question who is really
spying on what the book calls, “the backbone of the internet.”


The author then takes a sharp right-hand turn to provide a chilling view of what feels like state
sponsored cyber “street justice” reminiscent of hit men and snipers but with a twist, as the book
brings the reader through a vast and complex world called the Advanced Persistent Threat (APT)
with shadowy state-sponsored hacker subgroups with names such as BYZANTINE HADES,
BIZANTINE CANDOR and hacking the hackers through tailored access operations (TAO)
somewhere in and around Ft. Meade, Maryland. For me, this was an up close and personal replay
back to my days with the former U.S. Department of Defense Joint Task Force Global Network
Operations now the U.S. Cyber Command based out of the NSA. Buchanan does a brilliant job
making this transition to taking the reader as close to the front lines as possible short of being
right on the hacker’s lap and keyboard somewhere in mainland China or North Korea.
In an impacting moment in the book, Buchanan quotes former Director of the NSA, General
Keith Alexander, saying “Iran was an unpredictable adversary because it did not calculate in its
hacking operations but rather ‘will act emotionally’.” This took me even closer to feeling the
adversary’s moves as it brought in the human element rather than treating it like zeros and ones
floating out in cyber space.


The Hacker and The State is direct, no nonsense and strikes to the core of the state-sponsored
hacker’s industrial complex while balancing thought provoking sub themes and challenging
current and future geopolitical integrity, intent and global data privacy expectations. Buchanan
leaves the reader well anchored in qualified facts, true to life use cases and animated experiences
with thought provoking glimpses for the reader to formulate his/her own correlations and
conclusions.

This book earns a prestigious 3.5 out of four trench coats.

Go to the Cipher Brief online to subscribe to get more great reviews and content.

 



The Secret CSO – IDG Connect Interview

Share

IDG Connect Interview with Peter Tran

What was your first job? My first real job as a young adult was as a pathology technician performing autopsy procedures as part of a Harvard Medical School teaching hospital.

How did you get involved in cybersecurity? I became interested in cybersecurity when I was a graduate student in forensic sciences at the George Washington University. I was beginning to see that crime scene trace evidence was going digital and more and more crimes were occurring over computers and networks.

What was your education? Do you hold any certifications? What are they? I hold an undergraduate degree with an emphasis on criminalistics from the University of California Santa Barbara, a Master of Forensic Sciences from the George Washington University and post graduate executive education from MIT in blockchain security/cryptocurrency and the Harvard Kennedy School of Government cyber security technology and policy. I hold the ISC2 CISSP as well as the SANS Global Reverse Engineering Malware (GREM) certifications as well as advanced training from the Department of Defense (DoD), Federal Law Enforcement Training Center (FLETC) and the Federal Bureau of Investigations (FBI) Cyber Training Academy.

Explain your career path. Did you take any detours? If so, discuss. Career growth never happens if you don’t pivot and take detours along the way. I take detours almost every day. That’s how dynamic the cyber security field is no matter what level you are. You learn to wrap your arms around it and learn, adapt, assess, and execute…. everyday!

Was there anyone who has inspired or mentored you in your career? 100% my wife.

What do you feel is the most important aspect of your job? Coaching and Mentorship.

What metrics or KPIs do you use to measure security effectiveness? – Mean time to disrupt, detect, respond, contain and remediate. Command and control disruption KPIs are critical as I characterise them as “pre-weaponized” detection and disruption to determine cyberattack surface volatility index metrics (CASVI).

Is the security skills shortage affecting your organisation? What roles or skills are you finding the most difficult to fill? The security skills shortage is not only affecting my organisation, but it is affecting every industry globally. The highest skill demands are changing to more data science and advanced analytics knowledge and experience.

Cybersecurity is constantly changing – how do you keep learning? I keep learning by looking beyond the obvious security threats and question the quiet times when it may seem the cyber threat actors may be under control.   

What conferences are on your must-attend list? The consumer electronics show. This will give you a better sense of the current and new attack surfaces.

What is the best current trend in cybersecurity? The worst? The best is AI and Machine Learning and the worst trend is SIEM.

What’s the best career advice you ever received? Sometimes stopping to camp is ok when you are trying to climb the mountains of your career as growth occurs in all directions.

What advice would you give to aspiring security leaders? Empower your teams to use their imagination beyond what the tools are capable of.

What has been your greatest career achievement? Starting my own family.

Looking back with 20:20 hindsight, what would you have done differently? I would have become a professional cyclist in Europe.

What is your favourite quote? Dreams Don’t Have Deadlines (DDHD).

What are you reading now? my fortune from as many fortune cookies I can get my hands on….

In my spare time, I like to… build Lego exotic sport cars…..

Most people don’t know that I… used to be a break dancer in a fashion show when I was 13 years old….

Ask me to do anything but… pick up a snake…..