RadiantLogic-Cisco-Dashboard-Reporting-Hero

Radio LogicEthically Hacking Identity



In this episode of Radio Logic, host Anders Askasen sits down with Samuel, a 20-year-old placement student from Coventry University, one of the only UK universities teaching ethical hacking. Samuel shares how he found cyber during lockdown, why he chose the attacker’s mindset, and what it’s really like rotating through pen testing, identity, SOC, and governance teams at FSP.

Read the Transcript

Anders Askasen: Welcome to Radiologic, the monthly podcast where we break down security concepts and identity into something that is digestible and makes sense. I’m joined today by Samuel. Samuel, you’re with—you have a placement with FSB.

Samuel Omotesho: Yes.

Anders Askasen: That’s right. A little bit about yourself and how you got into security.

Samuel Omotesho: So my name’s Samuel. I’m a placement student from Coventry University. Yes. So Coventry is one of the only unis in the UK, probably the only one in England, that does ethical hacking. So ethical hacking is kind of another word for pen testing, basically. So one day I was just looking for things to do. This was back in lockdown.

Looking for, like, my interest, something I can do as a career. And then stumbled upon a cybersecurity course, and I thought that’s a big thing nowadays because lots of companies are looking for people who are cybersecurity specialists to help them bolster up their security. So I did the course and it was really interesting, especially the main aspect that drew me to it was it’s an ever-growing industry, essentially. So cybersecurity will never ever disappear because there’s always an attacker, always looking to get into a business, and cybersecurity experts are always needed.

So I thought that would be a good thing to get into. So looking into unis, I found an ethical hacking course, and I thought that’s it for me because the best way to learn about cybersecurity would be to learn from an attacker’s perspective.

If you’re hacking into the business, you know how to defend the business. That’s that kind of thing. Yeah, and both ways too.

Anders Askasen: I normally don’t ask my guests how old they are, but what’s your age? You’re young.

Samuel Omotesho: I’m twenty, yeah.

Anders Askasen: You’re twenty? Yeah. So, I read somewhere there was an article that there’s a 4.8 million gap in cyber professionals. And then clearly, it’s a career path—there’s a need for more qualified people. But what would you say to your peers if they’re thinking about something like this? What’s the right way to approach this?

Samuel Omotesho: I would say is to figure out if you’re interested in it because I would say cyber seems like such a small space because everybody just says cybersecurity, cybersecurity, but there’s loads of aspects in cybersecurity. There’s identity, there’s pen testing, there’s a SOC, there’s the governance aspect—there’s literally so much you can do in cyber. And people only look at it as a small field, but it’s a huge field. It’s its own field. It’s separate from, like, computer science or developing. More security is needed. Security is present. And you can see from attacks on Marks and Spencer and Co-op, like, you need it more than ever right now.

Anders Askasen: And how did you figure out what discipline or what field within security was your thing?

Samuel Omotesho: I haven’t.

Anders Askasen: You haven’t. You’re still exploring.

Samuel Omotesho: I’m still exploring, exactly. That’s the main reason why I came to FSP because they were offering me something that I wasn’t finding elsewhere, where I could do a rotational role through different teams, all the different cyber teams in the business. Like, even within the business, people still say, “Oh, cyber is one discipline,” but there’s so many aspects. There’s the SOC team, there’s the identity team, the architecture team, there’s the GRA—governance, risk, and assurance. There’s the pentesting team. There’s so much you can do in cyber. So I’m going through the teams, trying to get a feel of what’s best for me, what I’m most drawn to.

At the moment, it’s still looking like pentesting, but identity is definitely up—

Anders Askasen: At the moment, it’s still looking like pentesting, but identity is definitely up—

As a pentester, and I’ve always enjoyed the field myself, you need to have that curiosity to kind of poke around, figure things out. You know, it’s not like in the movies where you make a quick hack and you’re in. It could take months to figure something out, find that exploit. Do you have that curiosity?

Samuel Omotesho: I would say that I do because I look at a system and I instantly think, “Oh, how does that—what access does that user have? And what if that user wanted more access? Who grants that access? What’s the management structure looking like?”

Is everything configured in the system? How do they configure the system? What applications are they using? So that’s always a thing in the back of my mind, just automatically looking. I want to know how something works when I break it down to individual pieces and then put it back together, just to see if I could, yeah, essentially.

Anders Askasen: So typically, hackers are defined in what color of their hat they’re wearing. That’s true. And obviously, your ethical hacker education and the path that you’re choosing, that puts you on a different spectrum because you have guardrails and regulations and adherence to ethics. Whereas a black hat hacker, they couldn’t care less.

Right? They’re there for a mission. They want to penetrate that system. They want to exfiltrate information, and they can break whatever rules there are.

As an ethical hacker, you don’t really have the same ability to break all the rules. Right?

Samuel Omotesho: That’s true, one hundred percent. I could give you a really good example. So essentially, you can think of it as moving away from cyber in a physical sense.

There’s a business. They have doors, obviously. So they have a security guard in the front door, and then someone walks in, walks towards it, and wants to get into the business and see what they can do inside. So automatically, you know the security guard is not going to let them in.

So they’re going to look for a back door. So with white hat hacking, you’re automatically going to see, “Oh, there’s a back door, but I’ve been told I can’t use that door. I have to use this window instead.” So if you have to try to get in through the window because the scope of procedure says so, then that’s what you have to do.

But it’s a little harder, I would say. It’s not as fully realistic as a black hat hacker who has the option to just go, “Oh, I see a back door unprotected right there. I’m just going to go and try that instead.” That could potentially damage the whole entire infrastructure, but they have the option.

We don’t. However, doing a penetration test, you don’t want to be damaging the whole infrastructure, making sure a company can’t proceed with their usual business. That’s not the way we’re doing it. It’s a lesson to be learned, a lesson to teach them, “Oh, if I can break in this way, someone else can break in this way,” so to improve and bolster the defenses.

Anders Askasen: So to improve and bolster the defenses is—

Samuel Omotesho: Of course it is, of course it is, but there’s only so much you’re allowed to do. You have to keep it—

Anders Askasen: When I embarked on a similar path in my past, you know, it was always about building up that lab environment where you can actually do some creative stuff that you’re not allowed to do. If you’re an ethical hacker, you wouldn’t do it, right? Because ultimately, that’s a consultancy gig, and you’re selling your expertise, and it’s well-defined and scoped.

And that comes with a cost, right? It’s not cheap to set up a lab environment. Is that something that you have the ability to explore, or is that something that FSB gives you that ability?

Samuel Omotesho: I would say there are a plethora of resources out there that you can use to explore and create your own lab environment to see what you can actually do. There’s even things like Hack The Box and TryHackMe, which are applications out there that allow—they create boxes for you to test your skills on. So there would be certain vulnerabilities on the boxes. Let’s say LFI, where you can put a file path in the website description just so you can go into, like, a shadow file or a password file and see what passwords there are in there. There’s certain vulnerabilities that you could exploit, but I would say the amount of resources out there are—there’s so much you can do.

Anders Askasen: And all these services, Hack The Box and TryHackMe, they offer some kind of free tier as well. So people—right?

Samuel Omotesho: Yeah. I would say they don’t get enough recognition because, honestly, before going into uni, I did not know about any of these tools. So I would always say when I entered uni, I felt a bit behind because some people had already found out about these applications and had been doing it for years. But I’d only just started, and I felt like my skills went up to par with everyone else.

But cyber is an evolving field. You learn every single day. In my time at FSP, I’ve learned new things every day. And I would say, as soon as I came into the business, I humbled myself and I learned that you can learn from every single person in all sorts of ways.

Anders Askasen: So if you compare that with university, would you say that you actually learn more doing the empirical work at FSB versus the more academic work at university?

Samuel Omotesho: Not to say I’m against uni because I wouldn’t say that uni is great for some people, but I would say with some courses, practical hands-on experience is the most important thing because you can only learn so much in theory. And even on my course at uni, we do do a lot of practical stuff, which is why it’s one of the best. However, there’s still the aspect of there’s only so much that they can teach you in a two-hour lesson. But working in a real company, seeing the real work that they do, the important work they do—a lot of things you won’t see on the news because they are protected—because cybersecurity is happening in the real world every day. It’s present, and it’s good.

Anders Askasen: I think having that adversarial lens when you engage in securing an enterprise is very important because it allows you to think outside of the box, and that’s often how the adversaries think. They try to exploit something that you haven’t covered. Right?

Anders Askasen: And being able to see it that way, I think, is very important.

I, as you said, at FSB, you’re able to explore the different fields of security.

And I understand that you come across identity, which is, you know, the topic for this podcast—yeah, for all of the episodes. We talk about identity. We talk about it from different lenses. In fact, there’s an operational efficiency aspect to it, there’s a regulatory aspect to it, and there’s a security aspect to it. Tell me, what have you been touching when it comes to identity and your empirical placement at FSP?

Samuel Omotesho: I would say that something I didn’t understand before arriving at FSP, I’d always thought about identity as, “Oh, it’s just MFA,” or, like, what you can access, and that’s all it is. But identity is, I would say, the foundational aspect of cyber because you can’t do anything without access. Like, the principle of least privilege, for example: a user should only have the amount of access they need to do the work they need to do.

If a user had more access than they needed, then an attacker could simply just go, “Oh, this user has more privileges than the job role says they should have. So this is the user that I’m going to go for.” They could spend months just for that user than they would have spent on a regular user and trying to elevate privileges. They could get so much further with just that one user.

Anders Askasen: Are you being taught that at the university, that identity is the new perimeter of security?

Samuel Omotesho: I wouldn’t say so. I would say identity is a field that is not spoken about enough. I would say pen testing is a field that—that’s what everyone sees as, “Oh, that’s cool.”

Anders Askasen: I would—

Samuel Omotesho: I would—a lot of people don’t do it, but they would love to do it. But identity, I haven’t even heard of it in practice or just by word of mouth, really.

Anders Askasen: But I guess if you look at penetration testing and going back to that field, at some point—and this comes from reading, you know, the Verizon breach report and IBM’s reports on the topic—it shows a similar pattern that typically the attackers, the malicious ones, the ones with the black hat or the gray hat, they log in. They already have the credentials. Some have already leaked credentials, and they sell that on the dark web.

Yeah. You use that to kind of gain the first foot in the door, and then you kind of do escalations into nearby accounts. It’s all about access ultimately. So I’m a bit surprised by the universities that they don’t see it that way.

And maybe that’s something that we should pass through the universities, that they need to update their curriculum.

Samuel Omotesho: Definitely. I think so because there’s an aspect to it that’s not looked at, which is the identity aspect: before an attacker can even do anything, they need initial access to the system. Like, it all starts with access, and identity is just not talked about enough.

Anders Askasen: And we’ve obviously been talking about digital identity and tied to access. But being your age, I’m sure you have a social media presence. And how do you think about that, especially when you think about how easy it is to grab your voice, grab some pictures, and that could generate a fake ID or a fake avatar that will trick me, it will trick your mom, it will trick your grandma, and you can potentially, as an adversary, do some really nasty stuff that could put you in trouble, that could exploit who you are, trick your grandparents out of money, etcetera? How do you think about that?

Samuel Omotesho: I would say it’s scary, especially being in this generation knowing that AI is doing crazy things and it’s only getting bigger and bigger every single day. The deepfakes are getting scarily more realistic as well. So I would say it’s definitely something to keep an eye out for because it’s only a matter of time before we start seeing more and more AI being used in pen testing or by the black hat hackers to initially—you said, for example, with identity, that all they need is the initial access—but you could easily use a deepfake, an AI fake, and just be like, “Oh, I’m a user in the system, but I lost my password.” With a simple voice changer or a picture, anything like that, you could deepfake it, and they’ll be like, “Oh, here’s a new password.” Now you have access, and now they can do so much more damage to the business.

Anders Askasen: And that typically boils back to that trigger, which is often social-engineering-driven. Yeah.

Normal social engineering, and there’s been some good names in that category. Kevin Mitnick, that, you know, ultimately went to—before—and unfortunately, he’s no longer with us. But he showcased some fantastic skill sets when it came to social engineering. But now you have something that looks like you, behaves like you, talks like you, and it’s indistinguishable from you. And that puts social engineering in a completely different bucket, doesn’t it?

Samuel Omotesho: It does. It makes it more scary because the physical aspect of social engineering, where you could go into a building, pretend you work there, and just walk in, is now probably a bit more in the background. And now what’s more present is online social engineering.

Someone is going to come in front of you and just be like, “Oh, hi, I’m this person,” and you wouldn’t know if it wasn’t. You couldn’t tell the difference.

Anders Askasen: Do you have conversations with your peers that are not necessarily pursuing the same career as yourself on, you know, think about what you post out there. Think about how you present yourself. Think about how much you expose.

Samuel Omotesho: Personally, me personally, I try not to get too much on social media because of these things, especially working in cyber. I feel I don’t want to put myself out there too much and then possibly risk my career going in the bin before I even start it. So I feel especially with all the AI and the deepfakes, it’s even more scary to want to put yourself out there, knowing that someone is easily just going to take that one picture with that one voice recording and use it to do things that you couldn’t even imagine.

Anders Askasen: So walk me through. You’re at a placement at a security company. You’ll be there for one year. Is that correct?

Samuel Omotesho: That is correct, yes.

Anders Askasen: What happens after that?

Samuel Omotesho: After that, I go back to uni, finish my last year, and hopefully come back to FSP and do some amazing work there. But I would need to decide on a role, in a specific role, and not just rotate through different business units.

Anders Askasen: So once you’re done, you’re looking forward to explore that curiosity. If we wrap things up here, I’m sure there’s a lot of people that are a couple years younger than you, and they’re trying to figure out, “How do I get into this? How do I explore?” Maybe they don’t even have the money to go for a university degree and have the same opportunity. What recommendations would you pass to these young people that want to get into the industry?

Samuel Omotesho: I would say the number one thing is be curious because just search online. You can find so many things. Just search for online courses or these resources. If you’re interested in it, you can find a way to pursue it without going to uni. Uni is something that maybe you could say is a bit more privileged, but I would say you don’t possibly need uni to be successful. You can find courses or resources online that will help you get a job in cyber or at least put your foot through the door. And then from there, you can elevate your privileges.

Anders Askasen: Samuel, it’s been a pure pleasure having you on the podcast, and now we have enough material out there to potentially produce deepfakes of yourself in the future.

Samuel Omotesho: Oh, wow.

Anders Askasen: Just kidding. But I think what Samuel hits in our conversation is quite interesting.

It’s that curiosity, and the fact that universities don’t necessarily connect identity with security is something that I think we’re passing on from this podcast to the universities: they need to elevate that into the curricula. And I think for all the young people out there, to Samuel’s point, there’s so many resources out there. Much of them are free. You can try things out.

You can explore how ethical hacking works with TryHackMe, Hack The Box, etcetera. And that will really propel you into this industry. So if you have that ambition, it’s really something that you should try and explore. Samuel, it’s been a pure pleasure.

Samuel Omotesho: Thank you very much for having me.

Anders Askasen: Thanks for listening to Radio Logic. Subscribe now wherever you get your podcasts.

Listen Anywhere

Listen to Radio Logic using one of many popular podcasting apps or directories: