CCL Opening of its new Digital Forensics Training Academy
www.cclgroupltd.com
I am looking forward to the launch on Thursday 8th October
The opening of this additional 10,000 sq ft building at 34 Cygnet
Court in Stratford upon Avon, for CCL’s Training Academy and additional
space for the growing team of Digital Forensic analysts, is an important
milestone in our 30-year history and celebrates the next phase of our
exciting business growth.
This comes at the same time as our
recent acquisition of another Digital Forensic business (Blackthorn
Technology) based in the centre of London. With an unprecedented
increase in demand for our Digital Data Investigations (DDI) services
and Cyber Consultancy, we are looking to increase our staff to 150 by
the end of 2015 and to over 180 by the end of 2016.
Empowering
our clients with knowledge and skills has been one of the cornerstones
of CCL since its inception and although we have been providing high
quality training for a number of years the NEW CCL Training Academy
places us at the very forefront of technical training providers in the
UK.
Our new facility, which has the capacity to train over 40
delegates per day, offers a range of courses with subjects covering;
Digital Forensics, Cyber Security and Digital Investigations. Ranging
from Python scripting for use in forensics investigation, through to
Dark-Web investigations for intelligence officers, crime and fraud
investigators. Over 80% of the courses have original material content
based on our extensive experience and expertise.
This is my personal blog for issues that I will make comment upon, my own views. Feel free to comment or connect with me. AQL commissioned Ambassador for the Yorkshire Humberside Cyber security Information Sharing Partnership To join follow www.ncsc.gov.uk/CISP
Monday, 5 October 2015
Sunday, 4 October 2015
Reengineering Crime Recording
Reengineering
Crime Recording
There are
many deep questions people ask. What is crime? How is it recorded? What are the
rules for recording? Is it a complete representation of all criminality?
Recent
attention has focused on a change that will dramatically alter the amount of
crime recorded and change the relationship between “normal” crime and its
digital cousin. The Crime Recording system will also alter people’s perception
of what crime is, how it’s recorded and how it’s investigated. These recent
changes have created a debate that no doubt will have at least two sides and probably
no ends.
The vision of Crime Recording in England and Wales is that it is renowned
for being the best crime
recording system in the world: one that is consistently applied; delivers
accurate statistics that are trusted by the public and puts the needs of
victims at its core. A brave statement. The new change should be focused on
those aims.
The rules
for Crime Recording are regularly reviewed and each force is inspected as to
how it then executes and enforces the rules. Individual Force Crime Registrars
are held accountable for crime recording performance. Police and Crime Commissioners
continue to hold Chief Constables accountable for their ability to record crime
accurately, effectively and in compliance of the rules.
All the data
from Crime Recording systems across England and Wales is collated and published
by the Office of National Statistics (ONS) having been removed from the Home
Office to make them appear more independent and therefore reliable.
Over the past
weekend the media announced that the crime statistics from ActionFraud (the UK
response to fraud and computer crime), would be added to National Police Crime figures
published by the ONS. The net result will be a 40% increase in crime overnight.
The announcement, made by the Commissioner of the City of London Police, may not
be great news for those who have heralded a reduction in recorded crime around
the UK.
However
there is little doubt that this will lead to a much more accurate assessment of
criminality in England and Wales. Yet even with the addition of ActionFraud data,
it is unfortunately not the full picture of criminality.
Police Crime Recording still
excludes a small range of data recorded elsewhere, for example:
·
Where the
Serious Fraud Office (SFO) has been solely responsible for an investigation and
arrest of a suspect, although the police charge the suspect and submit papers
to the Crown Prosecution Service on behalf of the agency. The SFO has primacy
of investigation.
·
Where the
police provide information, but no other assistance, to a Department of
Business Innovation and Skills fraud investigation.
·
Where the
police offer custody facilities to customs officials who have apprehended
smugglers and Her Majesty’s Revenue & Customs (HMRC) has primacy of
investigation.
·
Where the
police accompany customs officials in raiding a ship suspected of smuggling and
HMRC has primacy of investigation.
·
The
Department of Work & Pensions (DWP) provides the police with the names of
benefit fraud offenders for intelligence purposes. The DWP has primacy of
investigation.
·
The
police assist DWP officials in surveillance work that leads to the apprehension
of benefit fraudsters. DWP has primacy of investigation
These
examples are cited in the Crime Recording Rules. They all involve operational activity
by Police for which there is no Police Crime Record for national statistics
purposes. Each of the agencies keep separate accounts which need to be
considered alongside “Police Recorded Crime” to get a full picture of
criminality in England and Wales. Until now crime reported to ActionFraud was
also excluded
Some
other crime incidents do not have to be recorded by the Police. For example, if
the National Fraud Intelligence Bureau (NFIB) has recorded an incident, and has
not allocated it for investigation, and determined there are insufficient lines
of enquiry to warrant further investigation. This assessment will be managed by
the NFIB (which currently sits under the remit of the City of London Police).
This data is however used for NFIB briefings with other Departments and Central
agencies as well as industry but is not part of Police Crime Recording.
Most people would
probably accept that incidents of online or cyber-crime (where the offence is
committed within a digital environment rather than merely to perpetrate a
“normal” crime) should be recorded and investigated. That simplistic approach
is slightly frustrated for many reasons which can discourage victims from
reporting incidents to the police such as:
·
Where
there are multiple victims across the globe or in the UK making the
investigation too costly or unmanageable
·
Where
the likelihood that offenders live or operate in countries without mutual
assistance for investigations, or extradition treaties.
·
Where
the embarrassment caused to companies of having been attacked and the
consequential loss of confidence amongst its customers.
·
Where
the victim considers the cost of reporting (staff downtime, disruption etc.) to
exceed the potential loss.
The reality
is that such incidents do not become part of the rich picture of recorded
crime. However, these incidents are sometimes within the knowledge of major
cyber-security companies and of course the victims. There is an argument that
they should all be included in the National Police Crime statistics.
Bringing all
this information together to create a full and accurate picture of cybercrime
and fraud sounds simple. However, unless this data can be collated, analysed
and disseminated within a usable timeframe, it will be of little value. There
has to be a balance between collating all relevant and accurate data about online
criminality, and providing something useful and timely for investigation and
prevention.
The
ActionFraud data will help to provide greater granularity to f criminality in
England and Wales but at the expense of a substantial shift upwards in crime
numbers overall. Such granularity, however, can help to tackle broad national
issues, but unless the data is relevant to locally instigated criminality, and
is available to local officers, it will only be relevant to national agencies. It
is believed the move by ActionFraud will not deliver localised data for all
reports.
Even with
ActionFraud data, the picture of cybercrime and fraud will still be incomplete.
Data on cybercrimes and attacks including hacking and other digital related criminality
is sometimes held by other centrally based Agencies or businesses.
For example,
the UK Computer Emergency Response Team has led a number of Regional Cyber
Information Sharing Partnerships (CISP) to allow industry and business to share
incidents of cybercrime. These incidents, unless they lead to a prosecution or
investigation, will probably not make it to the Police Crime statistics.
Looking at
some recent incidents there are many different cyber focused crimes
Any sporting
or social event can create the opportunity for scams and fraud. The current
Rugby World Cup is no exception. To be able to respond with an effective
investigation or to warn and prevent further offences requires swift and
effective dissemination of intelligence and data through ActionFraud which is what
ActionFraud and National Fraud Intelligence Bureau were established to deliver.
Such advice is regularly provided to Forces and other organisations.
A crime involving
“parcel mules” who steal from major distributors such as Amazon is not strictly
a Cybercrime but is a fraud and/or theft dependent upon how it is executed.
Unlikely to be identified at an early stage and possibly creating a lower level
response from the Police if at all, the most that can be achieved is broad
prevention strategy. Yet, with effective analysis by ActionFraud and the NFIB, offenders
could be brought to justice. Bringing the ActionFraud data into line with
Police Crime Data will make such an outcome much more likely
The need for
prevention advice and swift investigative ability is highlighted by a recent
case
In this
instance using social engineering and digital skills a company was duped into
giving away its data and allowing criminals to escape with £1M. Clearly this is
a serious crime owing to both the substantial financial loss and gain. However,
many much smaller, similar offences could be perpetrated without victims
knowing for some time, or even ever at all. Yet these lesser offences are
possibly held within NFIB or ActionFraud and so bringing them into the main
Crime Recording system is a positive move
In this
digital age you don’t need a sawn off shotgun and a mask to rob people, far
easier to do it from the garden in your far away timeshare with your iPad. Understanding
the difference between the two crime styles and the overlaps is an important
aspect of crime recording and more importantly crime investigation.
Responding
to the many types of online/digital crime and incidents requires the
collection, analysis and dissemination of effective crime data enabling
investigations, both proactive and reactive, as well as prevention campaigns.
England and Wales have the institutions to deliver that including ActionFraud,
CERTs and CISPs in addition to existing Crime Recording systems in police
forces and the National Crime Agency. Bringing the data together, however
unpalatable it will be in the short term, will improve our understanding of online
criminality and help us to prioritise police resources accordingly
No
discussion of crime policy should ignore the current financial restrictions
facing Police Forces. There is no intention to create an additional workload
when there may not be sufficient staff to manage even the current demand. By
bringing the ActionFraud data into mainstream crime recording it will lead to a
massive increase in the total crime recorded, it is suggested that it will be
40%. However, that crime already exists and this is a more open and honest way
or reproducing it. The public will want to have some confidence that these
crimes are being investigated properly or are at least used to prevent further
offending.
If
ActionFraud is operating as it was designed, and the NFIB is disseminating
appropriate crimes for local investigation then crime has not “Increased” by
bringing the data into Police Recorded Crime. It is just that people will have
a better and fuller understanding of online criminality. Additionally it will
allow far greater effort in tackling those crimes that affect people on a daily
basis such as spamming, hacking and identity theft. Having a more open and
transparent approach to crime recording allows policy makers and the electorate
to make much more informed decisions about how public spending should be used.
Further
changes that could make the investigation of cybercrime and fraud much more
effective might include the following
- A much greater emphasis on training in cybercrime and digital forensics for all police officers and staff ( College of Policing is starting to deliver this)
- Greater collaboration between Police and Industry. (The CISPs and other projects as well as Police and Industry led fora are making this relationship closer)
- Tighter legislation to protect against Identity Theft
- Moving ActionFraud within the direct responsibility of the National Crime Agency or more closely to CERTs
- Investing more in Preventative campaigns including those targeting Small and Medium Enterprises and building on the Regional initiatives
- Expanding CISPs to cover all regions and sectors
- Investment in research to consider the impact of preventative campaigns and reduction strategies
- Greater public awareness of specific focus days such as Safer Internet Day
- Greater collaboration internationally between Police and Industry
- A clear joined up strategy between police forces including regional units and national agencies to analyse, investigate and prevent cybercrime.
Thursday, 24 September 2015
Wednesday, 11 February 2015
Safer Internet Day.......Hitting the right buttons reaching to May15
Yesterday was Safer Intenet Day or #SID15
Considerable coverage across a range of media raising awareness in many languages on various fora to issues of safety online. But did it work, and how would we know?
As far as I can see there are no real measures in place of what is success or failure. No stats on # usage, amount of posts or number of people joining in.
Or more importantly what has changed.
It could be argued that the day was not about "Targets" or "Deliverables" but a timely and valuable assessment of how people protect themselves.
Aimed at some real risk and high profile aspects of social media usage, such as sexting, SID15 really sought to transform the activities, particularly risky ones, of young people. Yet are they the right audience? Are silver surfers, or elderly iPaders more or less vulnerable in their digital behaviour at home than a "youth" madly plucking their Samsung on the bus to school, surrounded by "advisers".
Put simply we don't know. We can estimate risk based on reported cases through ActionFraud or police figures, or we can survey and hope people tell the truth. In either case we may be able to secure some consensus of the problem but probably not all.
However the one thing we probably can safely assume is that if we don't raise awareness through SID15 and similar events we run the risk of complete complacency, and that's not a great place to be.
Probably over the next few months we have the chance to raise these issues as we stroll towards the next election.
Here are some questions to ask candidates if you are stuck
What is your party going to do to make all people safe online?
How will you equip police to tackle online abuse, identity theft and cybercrime?
What will you do to protect the national critical infrastructure from hacking?
How will you train people to protect themselves and to manage offending behaviour when they see it? How will you help them secure the evidence?
What can your party do to ensure that digital evidence is secured quickly without disrupting the lives of innocent people?
How will you make ISPs and other industry leaders accountable for protecting our society online?
I am sure there are more
As the BT Share launch once said. Have you seen SID?
Yes I have and was encouraged.
Many people did something. But was it enough and if not how do we use the opportunity of May15 to put it right
Wednesday, 5 November 2014
New Jersey State Police and Heroin Deaths
Last week I had the privilege to vist the New Jersey State Police including their state of the art Regional Operations Intelligence Centre.
One of the presentations was particualrly pertinent in the light of the current comments on drug abuse approaches.
They suffer in the region of 1300 heroin deaths a year and just under 9000 near misses out of a population of 8M which by any UK measure is high. However it has really driven the relationship between Heath and Law Enforcement. Whilst relationships at an operational level are usually excellent, at the strategic level and collaboration level it becomes a little disjointed. Anyone interested in exploring how to make Police and Health work together would do well to consider the approach they have taken. Yes, it does involve sharing data, but not directly personal and it does help to focus attention.
An example of that approach is a willingness to really drive the issue of Heroin abuse as a health issue rather than just, "Arresting" their way out of the issue.
Below is an example of one of the initiatives
http://www.northjersey.com/news/n-j-police-get-ok-to-carry-nasal-spray-that-can-halt-heroin-overdose-1.1036480
For those interested in the tactical equipment end of policing the NJ State Police can show you a wide range of kit.
Wednesday, 10 September 2014
SMILE day 2
We started the day with some exceptional awards for people who had made major contributions to the Police use of Social Media.
Each recipient provided a story of hope and expectation. Hope in the sense that it restored faith in the quality and commitment of Policing across the globe, particualrly in light of much recent negativity. That hope sustaining my belief that the vaste majority of cops do work hard and will deliver.
The expectation is that if these winners can achieve so much, imagine what can be achieved if their stories and accounts are repeated, borrowed with pride and replicated virally.
So the awards impressed. I have to say I am so pleased for Mike Brown. An individual who much deserved his award as Top Cop. He has known the ups and downs of corporate attention, ignorance and support, challenge and authority. I have nothing but respect for the way he has calmly managed all this and it is with great delight that his talents are now being used nationally. He remains a traveller, seeking improvement on his bumpy road. An asset of true value and an ambassador.
His presentation given later was dynamic and well informed, points argued from the head and the heart yet delivered professionally without notes or PowerPoint.
He had the misfortune to follow a highly emotional yet brilliant presentation by Alex and Paul from RCMP New Brunswick. Telling the very recent story of how they managed the death of three colleagues in an informative and well structured manner, was itself an exemplar of the word professional. Holding the audience spellbound, yet imparting learned wisdom and knowledge was an amazing sight. Very powerful yet filled with aspects of the case that inspired. Their colleagues will not be forgotten.
In between the awards and the RCMP Babak Ahghar gave us an incredible insight into the world of the EU. He discussed an array of EU bodies and their respective contributions and initiatives. From CENTRIC to Athena he discussed some of the work he is undertaking at Sheffield Hallam. Highly informative and again well worth following up
Following Mike Browns delivery Hootsuite gave a really useful account of one of the more valuable tools for helping organisations to manage its interaction through Social Media. A tool many use for simply managing separate profile feeds has a great deal more to offer at an organisational level. Hootsuite UK described its connections with UK Police and many other public and private agencies and organisations, helping them to maximise their use of social media.
The theme of professionalism was extended by David Bailey (Staffs Police) painting an image of a Force in control of its Social Media engagement, flexibly grabbing opportunities to share and to answer. Extolling the virtues of a wide range of SM opportunities, providing examples of cases and initiatives across a host of platforms. Very well delivered and informative.
After David came Simon Cole. As Chief of Leicestershire he has driven Socail Media and is an exemplar of a much engaged senior officer, directing, guiding challenging yet "doing" social media. He is amongst a now steadily increasing group of Chiefs who have crossed the rubicon and have embraced the value and potential of social media.
So a very useful day full of excellent speakers topped off with an inquisitive audience.
See #SMILEcon on Twitter for all the links pictures and comments from the presenters and audience
Stuart
Tuesday, 9 September 2014
Some thoughts to make you SMILE
Today was the first day of the SMILE conference.
Social Media Internet Law Enforcement
An opportunity for police and others to consider how Social Media (SM) can be used more effectively. Bringing subject experts, experienced officers and staff, Comms experts and a range of presentations provides everyone with an opportunity to share, learn network and enjoy the benefits and opportunities of SM whilst appreciating the challenges and pitfalls
Some very powerful presentations provided much scope for debate and thought. Chief Constable Chris Sims in his usual straight talking and impactive manner, opened proceedings supported by WMPs PCC David Jamieson. Both were themselves supported by a collection of excellent images of policing over the years.
Ian Hopkins DCC in GMP gave a powerful rendition of the values and integrity that should support SM, but linked it clearly to a range of highly valuable benefits and operational successes. Leadership in SM at its best from the two largest forces outside London.
I enjoyed Dan Bartons input, he is head of Comms in the West Mids Police. He showed exactly what can be achieved by a strategic and integrated approach.
I had never heared of Eau Claire and assumed it was a perfume. In fact it's a great area of Wisconsin policed by some real forward thinking leaders. Kyle Roder gave an impassioned address about their approach to SM. A really impressive delivery.
There then followed a mixed group including West Mids Fire, London Ambulance, and West Mids Police. Again some very personal perspectives on the challenges of making and applying SM strategies.
After the CCL presentation (see next post) we heard from Pascal Renes from Belgium covering the challenges of managing SM across the many separate police forces in Belgium. More creativity much more insight.
Then to top it all a non stop delivery across the web from Peter Sloly of Toronto Police. So many excellent points and issues raised. It would be unfair to summarise in a short paragraph
The total delivery for the day included a whole panoply of issues and ideas. No one can have failed to have been impressed with the variety.
So some thoughts from me
SM cannot just be imposed on staff, they need to feel part of it
You can't wait to give direction about SM to your staff. Your either keep up, or you will lose them
SM benefits are wide and strategic and far outweigh any minor discrepancies
There are however real dangers of officers or staff giving away operation details or becoming corrupted.
No organisation is too small or too big to offer learning to others.
SM is here to stay. It can't be banned or denied, only guided and harnessed.
There does need to be a way to stop stupidity and certainly an approach to prevent criminality
Matching the risk and threat with appropriate response is highlyvaluable
I am certainly looking forward to tomorrow's inputs.
Finally a massive thanks to Lauri Stevens without whose dedication commitment and energy this would fail.
Subscribe to:
Posts (Atom)
Popular Posts in last 7 Days
-
Ransomware Seminar 19th May 09.30-11.30 Ransomware is now one of the biggest threats to industry, charities, health and citizens. Fin...
-
Last week ACPO brought some people together to look at the way we are addressing Social Media. Or should we call it Social Networking? I wi...
-
In the recent drive to create the Big Society there is a risk that we convince ourselves that this is an entirely new concept and so denigr...
-
Last week I had the privilege to vist the New Jersey State Police including their state of the art Regional Operations Intelligence Centre. ...
-
I am helping Leeds University with a business Cybercrime Survey go to www.bit.do/cybersurvey to complete it or use the QR code. Many tha...
-
Today i presented my thoughts at the Security Company SASIG event in Edinburgh. It turned out to be a useful debate and discussion about a r...
-
Last week I became embroiled in an incident that played out on Twittter. The details are not relevant here but suffice to say someone neede...
-
At the Leading Powerful partnerships Course last week the Syndicate I directed created the following response that they have agreed to share...
-
There is a great deal of debate underway on an OJEU notice that WMP and Surrey have posted. The notice was signed by a number of forces wh...
