"Mom,,, I had Nightmare!! I dreamt of a Hacker!”
Dr. Reem Faraj AlShammari
CyberSecurity Woman of Arab World2024 &CyberSecurity Woman Barrier Breaker 2023. Ranked#1@CyberSecurity-IFSEC Global Influencers2019. ???? ????? ????????? ????? ???????????????? ??????? ??????????? ????? ?????????????
~~~~ A glance from CISO+Mom's diaries....Episode#4 ~~~~
This is not a joke or a line quoted from a Sci-Fi book. It is a real-time line quoted from a CISO+Mom life when my 6 yrs old "tootaa" came to me at 3 am after having what I have thought of a normal bad dream.
At the beginning she was trying to wake me up saying “Mom, I'm scared!! I had a Nightmare!”; and For those types of bad dreams/Nightmares, I have my Nightmare PlayBook (#NPB) set with all the #Use-Cases built throughout the years, ready to kick in once the MOM’s Nightmare Response (#NR) is activated.
{{And just for the record, this #Nightmare Playbook supersedes by far any other IR Playbooks out there in the market!}}
So as I was in middle of running the NPB, following the steps of hugging + Carrying her back to her Bed while telling her that its alright, it's just a bad dream and it will all go away once she's tucked into her bed again. She Suddenly raises her head..gives me the "Seriously Mom!" Look “which floats on her face surface whenever I misinterpret what she says”; and she says:
“Mom!! I’m so scared, I can't go back to bed... I dreamt of a HACKER!!" with the "it's all your fault" tone of voice.
In that moment, I felt like an employee's Win60w$ Machine rebooting on a Monday morning "after installing bunch of batches all weekend". I actually heard her very clearly, but my #Subconsciousness Mind refused for a Nano-Second to process it! And I DON'T blame it. I had Never Ever seen that coming, not to Me, not to my Kid!"
Being a Mom for a quite long time (+10yrs), I have seen it all. Or at least I thought I did, till that night came along.
<<REWIND>>
Going back couple of hours Earlier that day, I had a very long day at work and I was so eager to witness that clock reaching 9 p.m., where everyone is tucked into their beds. And then my 2-3 Free Hours Break starts before I also go to bed theoretically (as I’m known for being a light sleeper, keep waking up every couple of hours doing my Night #Patrol (kids & Cyber Community). That night, I decided to skip the Free-Hours #Cadeau "#treat" and sleep early, I needed that badly.
So, one hour later from giving up my treat, tootaa comes to me, calling me, 'Mom!! I’m scared... I had a nightmare!!"
<<Fast Forward>>
“Mom!! I’m so scared, I can't go back to bed... I dreamt of a HACKER!!"
I’m used to deal with these situations at work, among colleagues in Cyber Community. But taking the battle it into my Kid's Dreamland!! This breaks all the Game Rules and Drastic measures will be taken accordingly!
The Subconsciousness Mind had made it back (after wasting 1 whole Nano-Second!) and had given the orders to my Conscious Mind to change Hats immediately...No More Mom's Hat and CISO's Hat is ON through a smooth quick handover.
Thus, The HQ's location had shifted from the #MOC (Mother's Operations Center) to the SOC (Security Operations Center) and Incident Response “#IR” was then activated; while the NR got deactivated. IR Playbook kicked in swiftly following the 1-10-60 Rule:
- 1 Minute to Detect By realizing my little Girl’s Dreamland had been compromised (which was completed in less than 30 seconds) as tootaa always runs to me like "Road-Runner" when ever she has a bad dream, and we all know how fast Road-Runner is! :)
- 10 Minutes to Investigate the source of this compromise, so when I started asking her what does she mean by a Hacker? What did he look like?. “He wears the Mask Mom! you know,, the Hackers mask! just like those masks worn in our National Day Parade in February” She answers. I knew what she meant, yes it’s the Anonymous Mask. I then asked her to tell me "what has he done? Did he break into your Roblox Game Account and took all your Robux R$ credits? Or did they take your Harley Quinn Character "the one you did your Hairstyle in Eid's Al-Adha similar to hers?!”....... She looked at me furiously realizing that I'm being sarcastic, and with her #Body Language she had made it clear it’s not Funny and that she is still scared. While asking her, my CISO guts was trying to figure out which vulnerability was compromised to sneak into my kido's Dreamland?..... Then it Stroke Me! Being the Youngest, She is very well known in the family of being my Shadow everywhere, she always follows me around and sets close to me. Lately, I had been very busy and had been doing lots of urgent work calls while I’m at home, tootaa (as usual) was laying on the couch next to me playing with her Techie Gadget (while her #SubconsciousnessMind was recording it all, Transcripting it into Nightmare scenarios with some #Marvel flavored additions). Voila! Vulnerability was identified in less than 8 mins thanks to the CISO+Mom's hunch that magnifies those Forensics skills (just like #PoPEYE and his Spinach Rush).
- Now, Moving to the 60 Minutes to Remediate and Respond, as a CISO+Mom I already started remediating while investigating the Incident (and here is the Beauty of Mother-Hood, We exceed expectations). So, successfully I have #Isolated the Infected Host (by pulling her to my lap and surrounding her with my arms), and started a Psychological #Sweep on her Dreamland ensuring if any #Lateral Movements were made, and 0-Day Nightmares were dropped in any of her Neural Dreamer Cells. I collected the Indicator of Compromise (#IOCs) "The Mask" of the bad Criminal Hackers who invaded tootaa’s Dreamland and started replacing them with Good ones. I started showing her the Pictures of my Good Hacker Friends. Telling her "Those are the ones who will always help you out whenever the Bad ones try to compromise your Dreamland, they are Powerful and Kind!". And told her that couple of them are coming on 24 & 25th Aug. 2019 to present in the #KOC CyberSecurity Summit, and that she will have the chance to meet them in person. In less than 30 mins, She began to Smile her Angelic Smile and got so Excited about meeting the “Good Hackers” @Chris Roberts, @Rob M. Lee, @Mohammed Al-Doob and @Maher Yamout.
Gentlemen,,, you owe tootaa a #Selfie when she comes to meet the Awesome Good Hackers..You! :)
With a Smiley-Yawn she stretched her arms, announcing to her CISO+Mom the Stand-Down of IR, and that her #Dreamland is safe and clean now as she is ready to be tucked into her bed and go back to sleep happy and looking forward meeting Mom’s Cool Hacker friends!
#Lessons Learnt :
*** Be Careful when you work from home and got urgent serious matters. Ensure your little ones are away so their Marvel imagination won't kick in after Midnight.
*** I’m glad I have many brilliant, ethical, smart, and great Hackers within my circle of friends and colleagues. I believe the stereotype of marking hackers always as bad guys is Not fair nor right. Hackers, in general, are those Ethical Researchers with bright minds, their free souls is always hungry to explore and invent. And they are Totally different from the Cyber Criminals, who for unknown reasons misuse their Cyber intelligence and great knowledge to harm other fellow humans.
*** I believe Organizations need #Allies like those Ethical Hackers in order to use their Super Powers to raise their #Cyber Defenses, and likewise, Ethical Hackers need to assist those entities so they could enjoy making a positive impacts to their societies.
*** More Media campaigns to promote this concept is needed. I was so delighted “much much more than Chris Roberts even!” when I read @Joseph Marks’s article on The #Washington Post stating titled "Hackers are going after medical devices — and manufacturers are helping them", noting the fact that hackers are helping to identify vulnerabilities in medical devices that could be used to harm people using these devices. I always believed that the Essence of our Strength as CyberSecurity Community is by #Uniting, #Sharing, #Supporting each others without waiting for something in return.
We are indeed #StrongerTogether.
--im the girl that had a nightmare about A HACKER when u was 6 ??
1 年I agree,i had a very creative and thoughtful mind haha?? but i think im the only one that has a dream like that when i was 6 ??
Fractional CISO for Scale-Ups | vCISO Mentor | Advisor | Author | Coffee Nerd
5 年Love this! Excellent writing and storytelling! I'm going to show this to my kids in fact! ??
Rebooting <youth.hiring> Founders Game [ON]
5 年????? ???? ????? ?? ??? ! This is one of a kind! Absolutely Creatively Mesmerizing transcript whose words hooked my imagination in nanosecond to next level. For proving a powerful point -the choice of words, the organization of reader's thought process & the collaboration of humour+technicals were charming. I have never met you hence, this write up gave me first insight to know how talented you are, MashaAllah!!! Keep up Dr.!
Girl Dad | vCISO for 15+ Companies | Acquisition Entrepreneur and member/mentor of InfraGard (FBI OPS), EO and YPO
5 年This is amazing, sharing!
Driving 5X Email Response Rates for Business Leaders with AI-Powered, Personalised Outreach.
5 年Good job but how many Infosec's would be and to do what you did or if a non infosec partent experienced this. The mask or hoodie is the defacto faceless boogie man, now threatening children's on line presence as well as real life? Mental health advocates please take note.