Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their...

9
NEWS WINTER 2017 Page 1 - Why You Should Hire “Good Guys” to Hack Your Systems Page 6 - BOMA Insider Page 7 - Striving to be BOMA BEST Page 8 - Filling the Void TOC Why You Should Hire “Good Guys” to Hack Your Systems T he owner of the shopping mall was shocked – a cyber intruder had taken control of the building management system. They were able to access security cameras, disable the alarm system and key cards, and freeze the elevators. The entire build- ing was at the mercy of an anonymous face behind a remote keyboard. The scenario is a worst-case nightmare come true for any business. Fortunately for the shopping mall owner, it was only a simulated attack completed by a trained professional. The incident is an eye-opening example of why penetration testing is an integral part of security planning for every organization. What You Can Learn from Penetration Testing Penetration testing, also known as pen testing or ethical hacking, is used to discover and remediate vul- nerabilities before a real attacker has the opportunity to breach an organization’s information technology. It involves conducting authorized, simulated cyberattacks on computer systems, networks, web applications, mobile, hosts and/or other Internet-connected devices. By uncovering gaps in existing cybersecurity controls, the organization can then deploy solutions to reduce the risk of a potential breach. Many organizations are overconfident in the cybersecu- rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals may be, without frequent testing it is impossible to guarantee the security of any system. When participating in penetration testing for the first time, many are surprised to learn their enter- prise systems have numerous areas of exposure. Some common issues include unsupported operating systems and software, third-party applications that have not been regularly updated, insecure network protocols, unpatched systems and the widespread use of default credentials. If left unchecked, these can greatly under- mine an organization’s security. When conducted by trained, experienced security professionals, penetration testing can be an invaluable confirmation of what you are doing right, while also uncovering potentially serious problems. After receiving a documented report of objective findings and rec- ommendations, your team can use the information to remedy any serious issues. General Approach to Penetration Testing A penetration test takes a standard vulnerability assessment a step further by seeking out and attempt- ing to exploit vulnerabilities. This helps to evaluate how By Eugene Ng, CISSP

Transcript of Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their...

Page 1: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

1

NEWSWINTER 2017

Page 1 - Why You Should Hire “Good Guys” to Hack Your Systems

Page 6 - BOMA Insider

Page 7 - Striving to be BOMA BEST

Page 8 - Filling the VoidTOC

Why You Should Hire “Good Guys” to Hack Your Systems

The owner of the shopping mall was shocked – a cyber intruder had taken control of the building management system. They were able to access

security cameras, disable the alarm system and key cards, and freeze the elevators. The entire build-ing was at the mercy of an anonymous face behind a remote keyboard.

The scenario is a worst-case nightmare come true for any business. Fortunately for the shopping mall owner, it was only a simulated attack completed by a trained professional. The incident is an eye-opening example of why penetration testing is an integral part of security planning for every organization.

What You Can Learn from Penetration TestingPenetration testing, also known as pen testing or

ethical hacking, is used to discover and remediate vul-nerabilities before a real attacker has the opportunity to breach an organization’s information technology. It involves conducting authorized, simulated cyberattacks on computer systems, networks, web applications, mobile, hosts and/or other Internet-connected devices. By uncovering gaps in existing cybersecurity controls, the organization can then deploy solutions to reduce the risk of a potential breach.

Many organizations are overconfident in the cybersecu-rity protection provided by their in-house or outsourced

IT team. Regardless of how skilled or knowledgeable the professionals may be, without frequent testing it is impossible to guarantee the security of any system.

When participating in penetration testing for the first time, many are surprised to learn their enter-prise systems have numerous areas of exposure. Some common issues include unsupported operating systems and software, third-party applications that have not been regularly updated, insecure network protocols, unpatched systems and the widespread use of default credentials. If left unchecked, these can greatly under-mine an organization’s security.

When conducted by trained, experienced security professionals, penetration testing can be an invaluable confirmation of what you are doing right, while also uncovering potentially serious problems. After receiving a documented report of objective findings and rec-ommendations, your team can use the information to remedy any serious issues.

General Approach to Penetration Testing

A penetration test takes a standard vulnerability assessment a step further by seeking out and attempt-ing to exploit vulnerabilities. This helps to evaluate how

By Eugene Ng, CISSP

Page 2: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

2

easy it would be to circumvent or defeat existing security features before a serious breach can occur.

Security professionals will start by identifying your company’s goals and pri-orities for the testing to determine the best approach to your unique business. Once the penetration test is approved, testers will attempt to gain a foothold in your infrastructure. When successful, they will attempt to penetrate further to gain access to related systems.

Throughout the penetration testing process, security consultants gather evidence and take screenshots documenting each phase of their attempted breach. This information is compiled into a report for senior management which details testing outcomes, including descriptions of verified vulner-abilities, their root causes, likelihood of a breach and potential impact. The report also includes recommendations for reducing or eliminating high-risk vulnerabilities. You and your technical team can use this road map to prioritize patches and steps to secure systems.

Once an organization has undertaken remediation efforts, the consultants can retest to validate results. As needed, they can also provide guidance to further bolster cyber defences, known as “security posture.”

Regular penetration testing can help maintain the security integrity of your company. At a minimum, it is prudent to conduct testing when there are any significant changes to the external or internal business environment. Ulti-mately, this will continue strengthening security and provide peace of mind for your management and IT teams.

Eugene Ng, CISSP, is the Eastern Canada cyber security leader at MNP, one of Canada’s leading accounting, tax and consulting firms. As a member of the firm’s Enterprise Risk Services team, he works with organizations to improve awareness and implement effective cybersecurity strategies.

BOMA Calgary NewsBOMA Calgary News is a co-publication of BOMA Calgary and Business in Calgary.

Business in Calgary 1025, 101 - 6 Ave. SW, Calgary, AB T2P 3P4Tel: 403.264.3270 • Fax: [email protected]

BOMA CalgarySuite 225, 550 11th Avenue SW, Calgary AB, T2R 1M7Email: [email protected] • Web: www.boma.caTel: 403.237.0559 • Fax: 403.266.5876

Communications CommitteeJon Holmes, Chair, Camfil Canada Inc.

Kelsey Johannson, TransCanada Corporation

Danielle Smith-Deveau, Strategic Group

Christine White, Oxford Properties Group

Samantha Kalanchey, BOMA Calgary

Rita Borrow, Brookfield

Aydan Aslan, BOMA Calgary

Board of DirectorsCHAIRChris Nasim, GWL Realty AdvisorsCHAIR-ELECTLee Thiessen, MNP LLPSECRETARY TREASURERRichard MordenPAST CHAIRKen Dixon, Strategic GroupEXECUTIVE DIRECTORLloyd Suchet, BOMA Calgary

DirectorsJay de Nance, RioCan Management Inc.Steve Walton, Oxford Properties GroupTodd Throndson, Avison YoungGuy Priddle, Cadillac Fairview Marina Nagribianko, Allied REITRob Blackwell, Aspen Properties Art Skow, Bentall Kennedy Canada LPLaura Newcombe, GWL Realty Advisors

The Building Owners and Managers Association of Calgary publishes BOMA Calgary News quarterly. For advertising rates and information contact Business in Calgary. Publication of advertising should not be deemed as endorsement by BOMA Calgary. The publisher reserves the right in its sole and absolute discretion to reject any advertising at any time submitted by any party. Material contained herein does not necessarily reflect the opinion of BOMA Calgary, its members or its staff.

© 2015 by BOMA Calgary.Printed in Canada.

Today’s high highs were generated by the low lows of 2006-08 and of 2012.

LET US ANALYZE AND REPORT ON YOUR HOME, OFFICE OR BUILDING WITH A COMPREHENSIVE ASSESSMENT!

Our primary focus is indoor air quality; mould, asbestos, lead and hazardous materials. We are trying to make a difference in peoples lives by making their homes and work places healthier and a safer environment.

AIR QUALITY EXPERTS

104, 6330 12 Street SE Calgary, AB | Toll Free: 855-668-3131 | dftechnical.ca

Clie

nt:

SE

RV

AD

: JH

Job

Nu

mb

er:

S

ER

V1

00

5

Jo

b N

am

e:

CA

LGA

RY

SO

UTH

ED

MO

NTO

N S

OU

THS

IDE

PR

INT

D

ate

Pro

du

ce

d:

08

/03

/20

17

P

ub

lica

tio

n:

N

/A

Liv

e A

rea

: 6

.87

5”

X

9.7

5”

Trim

: 7

.87

5”

X

10

.75

B

lee

d:

8

.37

5”

x 1

1.2

5”

Co

lor:

4C

Services in Canada provided by independently owned & operated franchises of SERVPRO International, LLC.

FOR EVERYTHING THAT CAN GO WRONG UNDER YOUR ROOF, THERE’S THE NUMBER THAT LIVES UNDER OURS. Fifty percent of businesses may never re-open after a disaster. That’s why knowing the easiest way to

contact SERVPRO® is so important. Because the sooner you get in touch with us, the quicker we can

start to minimize the damage, as well as the cost. Just contact SERVPRO of Calgary South or SERVPRO

of Edmonton Southside to activate the cleanup team that’s faster to any-sized disaster. We’re a leader

in giving control back to homeowners, property managers and even entire communities after the

ravaging effects of water and � re. So whether you’re responsible for 1,000 square feet or 100,000 –

it’s your decision to call on the very best. Your trusted, local SERVPRO professional.

Page 3: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

3

Today’s high highs were generated by the low lows of 2006-08 and of 2012. C

lien

t: S

ER

V

A

D:

JH

Jo

b N

um

be

r:

SE

RV

10

05

Job

Na

me

: C

ALG

AR

Y S

OU

TH E

DM

ON

TON

SO

UTH

SID

E P

RIN

T

Da

te P

rod

uc

ed

: 0

8/0

3/2

01

7

Pu

blic

ati

on

:

N/A

L

ive

Are

a:

6.8

75

” X

9

.75

Tr

im:

7.8

75

” X

1

0.7

5”

Ble

ed

:

8.3

75

” x

11

.25

C

olo

r: 4

C

Services in Canada provided by independently owned & operated franchises of SERVPRO International, LLC.

FOR EVERYTHING THAT CAN GO WRONG UNDER YOUR ROOF, THERE’S THE NUMBER THAT LIVES UNDER OURS. Fifty percent of businesses may never re-open after a disaster. That’s why knowing the easiest way to

contact SERVPRO® is so important. Because the sooner you get in touch with us, the quicker we can

start to minimize the damage, as well as the cost. Just contact SERVPRO of Calgary South or SERVPRO

of Edmonton Southside to activate the cleanup team that’s faster to any-sized disaster. We’re a leader

in giving control back to homeowners, property managers and even entire communities after the

ravaging effects of water and � re. So whether you’re responsible for 1,000 square feet or 100,000 –

it’s your decision to call on the very best. Your trusted, local SERVPRO professional.

Page 4: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

Paladin Calgary’s

paladinsecurity.comInterested in joining the network of DISC properties? Contact:

300 - 7101 5th Street SE Calgary, AB T2H 2G2Email: [email protected]

Tel: +1 (403) 508-1888

Our Downtown Integrated Security Community (DISC) program protects over 10 million square feet of Calgary’s downtown core and offers your property protection that no one else can match.

Join Paladin’s industry leading security program and become part of DISC’s Safe Zone.

Our award winning program includes:

• Concierge & Ambassador Programs

• Customized training programs that are catered to our client’s needs

• Tenant Seminars

• Emergency Preparedness Exercises & Education

• Security Program Management & Ongoing Reassessment

• Unmatched support, allowing our people to deliver exceptional results for our clients

Downtown Integrated Security Community

Page 5: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

Paladin Calgary’s

paladinsecurity.comInterested in joining the network of DISC properties? Contact:

300 - 7101 5th Street SE Calgary, AB T2H 2G2Email: [email protected]

Tel: +1 (403) 508-1888

Our Downtown Integrated Security Community (DISC) program protects over 10 million square feet of Calgary’s downtown core and offers your property protection that no one else can match.

Join Paladin’s industry leading security program and become part of DISC’s Safe Zone.

Our award winning program includes:

• Concierge & Ambassador Programs

• Customized training programs that are catered to our client’s needs

• Tenant Seminars

• Emergency Preparedness Exercises & Education

• Security Program Management & Ongoing Reassessment

• Unmatched support, allowing our people to deliver exceptional results for our clients

Downtown Integrated Security Community

Page 6: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

6

BOMA Insider Welcome New BOMA Member Companies!Beedie Development Group – Jesse Buhler

Epic Building Services – Jane Paek

Aztec Renovations & Refit Inc. – Mark Ballard

35th Annual BOMA Golf Classic sold out in 5 minutes and raised $13,950 for the BOMA Calgary Foundation! Special thanks to our Golf Committee and many fantastic sponsors who made it all possible!

Golf Classic Co-Title Sponsor

BOMA MeMBers At the eNMAX BOMA GOlf ClAssiC

BOMA stAff At the eNMAX BOMA GOlf ClAssiC (l-r JessiCA MCGlAshiNG, llOyd suChet, AydAN AslAN, sAM KAlANChey)

BOMA CAlGAry MeMBers At the BOMeX 2018 GAlA iN tOrONtO

dAle ZAwyruChA frOM AspeN prOperties shOt his first ever hOle-iN-ONe ON rAveN #15. the hOle-iN-ONe wAs AlsO the first ever At A BOMA GOlf ClAssiC. dAle piCKed up his priZe – A Cheque fOr $25,000 At the BOMA OffiCe After the tOurNAMeNt. CONGrAtulAtiONs dAle!

rOB BlACKwell, seNiOr vp, iNvestMeNts & Asset MANAGeMeNt, AspeN prOperties wAs Our Guest speAKer At the BOMA OCtOBer luNCheON

Page 7: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

7

A year ago, I used this space to talk about BOMA BEST, Canada’s largest environmental assessment and certification program for existing buildings.

In the past year, the program has continued to thrive – as spelled out in the release of the 2017 BOMA BEST National Green Building Report. This success is a result of a focus on things a building manager can control by providing a consistent framework for assessing environ-mental performance and management.

Continuous improvement remains the cornerstone of BOMA BEST. A building is a long-term asset, and being able to make incremental improvements over time has a significant impact on environmental performance, and by extension operating costs. The data from the report reveals that when a building re-certifies, its score gener-ally improves by 34 per cent, which is truly a testament to the program.

The data also shows interesting industry trends. Waste and recycling is front of mind here in Calgary as the city moves forward on another initiative for both residential and commercial buildings. The report shows that indeed we are seeing improved waste diver-sion rates year over year. This is particularly evident in buildings that had more rudimentary waste and recycling programs as the report shows a 24 per cent increase in the number of buildings with diversion rates between 30 and 59 per cent. It is also notewor-thy that enclosed shopping centres score the highest of all buildings in the waste diversity and site enhance-ment category. Shopping centres tend to produce a wide array of waste and recycling materials by virtue of their tenant mix, and their programs serve as help-ful models for other asset types.

Another trend worth keeping an eye on is the jump in light-industrial buildings that have received BOMA BEST certification. Light-industrial properties now represent 32 per cent of all certified buildings, which is more than double the prior year. This increase is correlated with the introduction of the BOMA BEST Portfolio stream that provides a low-cost, high-volume certification track for both light-industrial and open-air retail properties. A great example of the value BOMA BEST certification can bring to an industrial property is Rangewinds Busi-ness Park, managed by Bentall Kennedy. The property’s robust environmental framework was recognized in

receiving BOMA BEST certification, all of which contrib-uted to Rangewinds winning the Outstanding Building of the Year (TOBY) Award from BOMA International in 2015.

BOMA Canada and the 11 local BOMA associations continue to improve the program. The Canadian mar-ket has been a huge supporter of BOMA BEST with continued growth in the program. But there are also very exciting developments outside of Canada. BOMA Canada has been working tirelessly to make BOMA BEST available to a number of target international markets. This is good news for the program and for certified buildings as it means BOMA BEST will be recognized around the world.

To learn more about how BOMA BEST promotes sustain-ability in commercial real estate, visit bomabest.com.

By Lloyd Suchet, Executive Director, BOMA Calgary

Striving to be BOMA BEST

2014 BOMA Canada National Pinnacle Award - Customer Service

4 0 3 . 2 6 3 . 8 1 7 0 w w w . S e r V a n t a g e . c a rOB BlACKwell, seNiOr vp, iNvestMeNts & Asset MANAGeMeNt, AspeN prOperties wAs Our Guest speAKer At the BOMA OCtOBer luNCheON

Page 8: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

8

By David Parker

All reports from the major commercial real estate companies suggest the industrial sector is back on track with CBRE stating in its 2017 Q3 figures that

the overall sentiment of tenants and investors continues to improve with the strongest quarter absorption over the last two years.

Iain Ferguson, executive vice president at CBRE, has sold 25 acres of industrial land on the former Mac-donalds Consolidated site south of 42 Avenue SE – the largest piece within city limits with buildings totalling 475,000 square feet – to a Calgary developer. And then he promptly leased a 90,000-square-foot building at the location to Dot Foods as a distribution centre.

Another significant industrial development within city limits was the recent opening of the SAIT Crane and Ironworks 30,000-square-foot facility in Point Trotter Industrial Park.

Jon Mook and Casey Stuart of Barclay Street Real Estate brokered the land and quarterbacked the design and tender of SAIT’s new mobile crane training program.

Mook and Stuart also represented Two Amigos in its move into Icon Business Park on Smed Lane, moved Altadore Gymnastics Club into 32,245 square feet in Eastlake Industrial Park, and are expanding an existing office and warehouse in Great Plains Industrial Park to add drive-thru service bays.

Filling empty spaces is good news although it doesn’t add to the total city inventory. But Colliers reports the 244,000-square-foot Sears Canada lease in Great Plains that was assigned to Indigo is a plus.

Cushman & Wakefield has been very busy completing the Calgary three-building portion of the $34-million PIRET portfolio across Western Canada.

Good news for the city, but apart from lands to the north of the airport, most of the action continues to be in Rocky View County.

Calgary and area has become a major distribution hub and thanks to competitive land pricing, lower construc-tion costs and tax advantages as well as easy access to major highways, Balzac has become the prime location for large occupancy requirements.

The High Plains Industrial Park along Highway 566 east of CrossIron Mills shopping centre is already home to huge warehouse facilities for Smucker Foods, Gordon Food Services and Sobeys. Now, showing lots of confi-dence in our local economy, Bentall Kennedy along with locally-owned Highfield Investment Group and Texas-based Hillwood Investment Properties has announced the additional construction of a 400,000-square-foot speculative development in the area.

Charged with leading the marketing of the facility that has been designed to allow for future expansion to more than 600,000 square feet is CBRE’s Iain Ferguson, who says he is very optimistic in leasing it fairly quickly.

The closeness of the CN Logistics Park in Conrich is also a big asset for Calgary business and employment. Marshall Toner, executive vice president of JLL, says he is having a good year and was responsible for helping Whirlpool select a 425,000-square-foot Tribal Partners building in the CN park.

The market in the industrial sector is moving in the right direction, and new construction in it bodes well for Calgary.

Living and Working in the Core

Tel: 403.984.9448 • [email protected]

TOTAL BUILDING & LEED COMMISSIONINGRETRO & RE-COMMISSIONING

FACILITIES MANAGEMENT SUPPORT

We’ve MovedContact us for lunch and learns. We will come to you or you can come to see our new space.

OUR SERVICES:• Energy Audits• BOMA BESt Certification Management• Building Automation Systems Consulting Services• Re & Retro Commissioning• New Building Commissioning

CFMS Alberta Ltd., has been providing independent commissioning services to the construction and building industry; working together every step of the way since 2003.

New Address: 228, 6715 – 8th St. NE, Calgary, AB T2E 7H7

Janitorial Services | Sanitization Plus Program | Carpet Cleaning | Window Cleaning | Disaster Recovery

Specialty Services | Technical Trade Services & Energy Management

they

servprocleaning.com | | 403.520.7777

Maid Service | Carpet Cleaning | Furnace & Duct Cleaning | Window Cleaning | Specialty Cleaning

we got this.

*MAIDS *CARPET *WINDOWS *FURNACE

Give the gift of clean.

*GIFT CERTIFICATES AVAILABLE IN $50 INCREMENTS

Stuck for the perfect gift?

Page 9: Why You Should Hire “Good Guys” to Hack Your Systems · rity protection provided by their in-house or outsourced IT team. Regardless of how skilled or knowledgeable the professionals

Janitorial Services | Sanitization Plus Program | Carpet Cleaning | Window Cleaning | Disaster Recovery

Specialty Services | Technical Trade Services & Energy Management

they

servprocleaning.com | | 403.520.7777

Maid Service | Carpet Cleaning | Furnace & Duct Cleaning | Window Cleaning | Specialty Cleaning

we got this.

*MAIDS *CARPET *WINDOWS *FURNACE

Give the gift of clean.

*GIFT CERTIFICATES AVAILABLE IN $50 INCREMENTS

Stuck for the perfect gift?