avatarBetha Talks

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

6371

Abstract

ete the work, which I multiply by an hourly rate to come up with a price for the project.</p><p id="f43f"><b>Deliverables</b></p><ul><li>The deliverable for training is a class.</li><li>The deliverable for any other project is a report.</li></ul><p id="799b"><b>Project Billing</b></p><p id="eba1">2nd Sight Lab always bills for a project the same way to keep it simple. We require 50% upfront and 50% on the delivery of a report or class. With training, we need to request the upfront payment at least 2–4 weeks prior to the class to cover the cost of work performed before scheduled class dates. The minimum project fee is 8,000 at this time but is often 15,000 and up. Private 40-hour classes with labs start at 25,000 for 10 students.</p><p id="0f1c"><b>Why No Hourly Rates</b></p><p id="cae8">We do not use an hourly-rate billing model and here’s why. First of all, if you don’t know how many hours you’re going to spend you could end up paying a lawyer 1000 to negotiate a contract and the project lasts two hours. You lost money. Secondly, I used to bill hourly through my software company. Tracking and billing time on invoices created a lot of overhead. I’d rather spend that time helping clients. Finally, it takes time to chase down payments. I had a client who consistently argued with me about every. single. bill. I finally just told her to scratch off what she had a problem with on each bill and just pay the rest. She would mark off something like 300 on a 15,000 invoice. It was very stressful and time-consuming. It’s not worth the hassle.</p><p id="369e"><b>About Cash Flow</b></p><p id="51bb">In addition to the problems I already mentioned with hourly rates, there is too much lag when trying to maintain consistent cash flow. One customer pays in advance. Another pays with a term of 60 days. Now you have a window with no cash flow. Gaps in cash flow impact small business owners more than large companies. Last year I took time off to get my house in Seattle ready to sell. The drop in income over that time period caused by my time off and the contractor’s failure to complete work on time affected my ability to get a loan for my new home. I ended up finding a way to pay cash, but it was not ideal. Even though with the sale of my home in Seattle, I had a higher income than ever in my life, banks will only look at business cash flow with their rigid underwriting formulas. All they see is a gap with no income. There’s your mini business lesson on cash flow for the day. It’s one of the number one reasons startups go out of business.</p><p id="7a86"><b>Focused Deliverables</b></p><p id="6d19">Another reason I focus on fixed-rate projects is that I don’t want to waste customers’ time. I did one hourly rate project, and I would spend hours on-site working for someone revising spreadsheets. I don’t think that was a good use of my time. It also tied me up for a long time doing busy work instead of actively solving security problems. That was an interesting project, and I was grateful to participate, but in the end, I felt like I could deliver what I gave to that client in six weeks instead of three months. I like to work on focused deliverables and get them done as quickly as possible. I’m not one for milking clocks.</p><p id="0d8b"><b>A company, not an employee</b></p><p id="6be1">When you hire me, you <b><i>hire my company,</i></b> not me personally. If you’re working on an hourly rate, you’re basically a short-term employee paid an hourly rate. 2nd Sight Lab offers a product — our classes. We also offer analysis services that include a deliverable — a report. Those products are delivered using the processes, tools, and documentation we have developed.</p><p id="762c"><b>Why I don’t want to be an employee</b></p><p id="b861">One of the reasons I choose not to be an employee of a large company is that it comes with too many restrictions and roadblocks to delivering effective security assistance. I was not allowed to say certain things for political reasons or simply ignored. I couldn’t fix things I wanted to fix. When 2nd Sight Lab assists a company, we provide the analysis and deliver a report or training. When the company receives the deliverable, it is up to them to fix the issues. If they don’t, I won’t be caught up as an employee of the company involved in the next big breach over something out of my control to fix. By coming in as an external advisor we can speak truth to power for employees who hire us to improve security. I often work with CISOs prior to pentests and security assessments to deliver the desired message in our report and provide the data to back it up.</p><p id="b969"><b>Who does the work?</b></p><p id="c41a">I’ve never wanted a large company. I had five employees in my previous company, Radical Software, and that was OK. I managed a team of 30 as director of SAAS engineering for a company. I don’t want to do that again. I spent a lot of time dealing with “people issues” (not to mention politics) instead of getting a project delivered. At this moment, I’m doing the majority of the work. Someone I used to work with helped me create some class labs for the first class I delivered when I was in a time crunch. In the past, I hired interns to help with basic penetration testing, class material review, editing, and accounting.</p><p id="50af"><b>Who are the interns and assistants?</b></p><p id="b7bc">In the past, the people helping me most of the time were my nieces and nephews, but they went off to college to be teachers and doctors and got too busy for me. Cybersecurity was not their passion. Now I’m looking into working with local colleges. I reached out to <a href="https://www.savannahstate.edu/">Savannah State University</a> last year to hire an intern. I never heard back from the department where I sent the job description. I may pursue that again later through some different schools. Other than that, I’ve only received help from people I know personally. If a client doesn’t want anyone else to do the work or see their report, we can work that out.</p><p id="fc88"><b>Security for Interns and Employees</b></p><p id="545e">I am working with a human resources company that performs background and reference checks. When I have someone work on a penetration test for 2nd Sight Lab, they get a separate cloud account and must follow our security sta

Options

ndards and instructions. After they finish, we terminate their access to any customer information on that project. Currently, I’m only using interns who are friends or friends’ kids. They are helping me test new cybersecurity training, proofreading documents, and will review books. Employees receive access through our cloud accounts, and that is one of the reasons we can only do projects from the cloud. It limits the exposure of customer data to other systems and networks.</p><p id="28e6"><b>Ownership</b></p><p id="d3be">2nd Sight Lab owns all training materials we produce or use for client training. We often will revise or rearrange our training material for a client to focus on their specific needs. That material contractually remains the property of 2nd Sight Lab and according to our agreement should remain confidential. In addition, any tools, processes, or materials we use on penetration tests or assessments remain the property of 2nd Sight Lab. However, our clients own the report we deliver. We are obligated to keep reports and any client information confidential unless explicitly allowed in our contract. For example, a customer requesting a product assessment of the efficacy of their product may want 2nd Sight Lab to publish our findings, if we find that it solves a particular problem very well.</p><p id="0ccd"><b>How to contact me about a cybersecurity project — LinkedIn</b></p><p id="c4c5">At this time, the best way to reach me for a project is through LinkedIn. I’ve explained this before but using <a href="https://linkedin.com/in/teriradichel">LinkedIn</a> I can see some information about the person with whom I am doing business. I had some very sketchy people contact me while running my past company, <a href="http://radicalsoftware.com/">Radical Software, Inc.</a> I always wondered if they were legitimate or they were having me perform work for a nefarious organization. That is one of the ways I attempt to verify clients, other than those I meet in person or who are referred by someone else. Unfortunately, I cannot provide training to organizations in certain countries at this time.</p><p id="a890"><b>Starting a cybersecurity project</b></p><p id="2089">Once you contact me on LinkedIn, I’ll send you information to set up a call to discuss your project. I only do phone calls, not Zoom or video calls, until after I have a signed contract. Even then, I require a week’s advance notice for video calls as my network is not set up to handled those at this time. After I understand a bit about the scope, you’ll receive a proposal and a contract for review. We may work to revise it to meet your specific needs. We’ll define a schedule and deliverables and payment terms in the contract. If I need to explain how to get set up for a penetration test or class those instructions come after receipt of the upfront payment.</p><p id="a1d9"><b>Completing a cybersecurity project</b></p><p id="2f1a">Prior to signing a contract we’ll discuss arrangements for communication over the course of the project. Often that will be via email for an on-going penetration test. For a security assessment, I will typically include phone interviews to ask questions up front and further discuss findings after reviewing the assessed environment, but this can vary as needed based on customer needs. Once we’ve completed our work, you’ll receive a report. I try to wait a few days before sending the final invoice to make sure the customer received and could open the report.</p><p id="f3be"><b>Additional support after report delivery</b></p><p id="dd74">Once a class is complete 2nd Sight Lab doesn’t generally provide any additional assistance, though in some cases we had a lab fail and provided a working version after class to the client. I have taken many cybersecurity classes in my time and never had another company do that for me. I usually don’t charge extra for a few questions after the report gets delivered. However, extensive questions or support would require an additional fee. Often, customers will ask us to verify their fixes for findings after completion of a penetration test report. We include that on our penetration report contracts at an hourly rate and can cap the time we spend reviewing the findings as needed.</p><p id="8b7a">If you are thinking of hiring a company to perform a cybersecurity assessment, penetration test, research project, or due diligence related to a cybersecurity investment hopefully this information helps you understand how <a href="https://2ndsightlab.com/">2nd Sight Lab</a> operates. You can reach out to me on <a href="https://www.linkedin.com/in/teriradichel">LinkedIn</a> if you have any additional questions about assessments, penetration test, or training.</p><p id="2373">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2022</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:

⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="5a42"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:

❤️ Sign Up my Medium Email List ❤️ Twitter: <span class="hljs-meta">@teriradichel</span> ❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span> ❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange ❤️ Facebook: 2nd Sight Lab ❤️ YouTube: @2ndsightlab</pre></div><figure id="faf5"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>

新屋嶺及太子站並非「fact check」就能解決的問題

[✅✅✅ 已 fact check] 本文寫作原因:眼見太多人以為「fact check」一字係萬能

一則已 fact check ✅的訊息。(網絡圖片,假的)

近日不停有人吹風,話有關新屋嶺同太子站嘅傳聞甚囂塵上,當中假新聞 (fake news) 太多,惹人誤會兼且手法低莊,加上連番討論令民主運動失焦,因此要求大家唔好再討論落去。基於害怕失去支持嘅恐懼心理,收口嘅風向輕易帶起,引來不少人和應。

煽動輿論者,多以外國勢力牌為重心、以往玩開嘅失焦牌為副。「外國人對 fake news 極度反感,再咁落去會失去外國勢力支持」、「外國記者誤報 fake news 中伏後會埋怨香港人」係勸說人唔好再傾新屋嶺同太子站嘅立論裡面,最常見嘅對白。

不過咁,雖然呢種講法愈嚟愈多人認同,但我都只能講一句:Excuse me WTF?

成個講法都好有問題。到底佢哋係想講「關於新屋嶺同太子站嘅 fake news」有問題,定係「討論新屋嶺同太子站事件」呢件事本身就有問題?

不過最壞嘅問題都唔喺呢度,更壞嘅問題係喺邏輯上,原來好多人係連咩係 未經證實嘅消息無法證實嘅消息 都分唔清楚。

係連 未經證實嘅消息無法證實嘅消息 都分唔清楚。

係連 未經證實無法證實 都分唔清楚。

好重要,寫三次。

當然,喺理論裡面嘅完美世界(唔係达哥嗰個),所有消息就好似薜丁格的貓咁,孰真孰假總有方法證實或證偽,所有未證實嘅嘢都係可證實嘅。但嚟到 2019 年嘅香港,事情明顯唔係咁:有啲消息喺當前環境下,係真係證實唔到㗎。

呢度嘅證實唔到,唔只係講緊權威機構(港共、黑警、黨鐵)唔肯扮演「fact checker」嘅角色,去公開證據展示事實,而係講緊上面嘅「權威機構」,喺唔少香港人嘅眼中,已經冇咗呢種一錘定音嘅「權威」。

更甚者對部份人嚟講,佢哋不單只冇咗權威,而係直程變埋燒山咁嘅逆向 indicator。即係「權威」話冇嘅嘢,佢哋就覺得一定有,好似八九六四天安門咁。當然,呢種逆向推理,只係建基於大眾對嗰啲「權威」嘅觀感而存在,並唔能夠證明某件事係咪真確。就好似英國研究咁,雖然大家成日都笑新聞報導嘅英國研究唔可信,但咁唔代表我哋喺認真思考嘅時候,可以用「英國研究」四隻字嚟證偽一個英國研究嘅成果。

而權威出現真空呢件事,換句話講,就係

而家香港已經冇任何 institution 可以幫大家 fact check 新屋嶺有冇死人、有冇輪姦,八三一太子站有冇市民俾警察監生打死喇!

呢個講法對一般人嚟講並唔難理解,但對於好多信奉「fact check 教」嘅網友,可能係一時難以接受。當大家以為 fact check 就係對抗對手 fake news 嘅最大武器,而且一定可以 mythbust 任何謠言嘅時候,現實就話俾大家聽,fact check 呢隻字就同香港法治、英式傳統一樣,係有會被玩爛嘅一日嘅,而且已經爛咗。[1]

「咁既然都冇得 fact check,即係再講幾耐都唔會有結論、唔會有真相出到嚟㗎啦,咁仲唔收口?」錯——而家冇任何機構做到 fact check,並唔代表我哋冇辦法去尋求真相,更唔代表真相本身唔重要。當然,拖得越耐,真相石沉大海嘅可能性就越大啦(不論係市民會遺忘,定係港共有更多時間造假證據去 cover up)。

所以為咗盡量邏原真相,我哋唔可以就此放棄去為新屋嶺同太子站嘅慘劇尋根問柢,反之要放棄嘅係已經被玩爛嘅、對 fact check 呢個字嘅偏執,因為喺而家嘅環境下已經冇人、冇機構有足夠嘅公信力,去為任何聲稱係新屋嶺、太子站真相嘅「fact check」背書。

其實搵真相呢件事呢,本應就一早有傳媒或政黨開始專門跟進嘅。可惜嘅係而家仍未有機構嘗試用盡佢哋比一般市民多嘅途徑,去為新屋嶺同太子站兩宗慘劇還原 full picture。可憐嘅神探們,唯有靠你哋用理性同埋手頭上嘅線索,去推敲返個你認為最接近真相嘅答案,去解答「新屋嶺同太子站發生過咩事」呢個問題喇。當然唔好再亂噏任何流言係已 fact check。

當然唔好再亂噏任何流言係已 fact check。

當然唔好再亂噏任何流言係已 fact check。

當然唔好再亂噏任何流言係已 fact check。

當然唔好再亂噏任何流言係已 fact check。

至於講到 fake news 會呃到記者、令我哋失去外國勢力支持,其實我自己係唔太同意呢種講法嘅。固然大家喺 Twitter、實體連儂牆等用嚟貼「製成品」嘅宣傳、社交平台上面放「fake news」(其實大部份人都只係講啲未證實或無法證實嘅嘢,而冇諗過當佢係一單已證實嘅消息去講 [2]),係會影響到 real news 喺呢啲平台嘅傳播,但記者本職冇記錯就應該唔係不經查證就全盤照抄網上流言作報道,而就算要引用網上消息都應該要先作查證。

如果有記者,係照抄連登或 Facebook 啲料而報咗假新聞嘅,咁問題明顯係出喺相關傳媒自身,而唔係喺香港人度。傳媒自己選擇報道啲自已冇或未能證實嘅嘢,本來就係用緊自己嘅公信力作賭注,我哋唔使代人去做注碼。

至於嗰啲叫人唔好講通靈、好驚推下推下會有記者報、令香港人變成國際笑話嘅人就仲荒謬。會當呢啲 post 嘅內容係理性討論同真憑實據,然後拎去報道嘅記者,專業操守本應就值得質疑。至於話任何靈異嘢都唔好講就仲無稽,咁之前啲「發生乜事係義士顯靈」、「藍絲集會落大雨係皇天擊殺」之說又點嚟?

誠然,將未經證實無法證實嘅消息,當成係已證實嘅堅料四處發佈嘅人,確實係不可饒恕,但我哋亦切忌斬腳趾避沙蟲,以為自行杜絕一切猜測、討論就唔會再有 fake news 出現。共產黨從來都唔需要藉口去製造 fake news 嚟搞大家,大家需要嘅係去學會點樣準確分辦到咩係 可 fact check待 fact check 已 fact check 嘅資訊。連一單消息能否 fact check 都未確定到,就討論單消息 fact check 咗未,係未學行先學走。

另外我真係唔信幾個講新屋嶺同太子站嘅 post 就足以令抗爭失焦囉。啲 iPhone 11 post 同叫春 post 點睇都仲大影響力啦。與其仲討論有冇模糊焦點,不如疊埋心水準備 29 號全球反共同 10 月 1 號一齊同中共開 party 啦。要玩 hashtag,就唔好再 tag #FakeNews,留返嚟 tag #StandWithHK #929GlobalAntiTotalitarianism 啦。

[1] 喂,唔係講笑㗎。當我話你聽之前法新社係用「打電話查詢學校職員」嚟「fact check」「沙田中學生自殺是否牽涉政治原因」一事,你仲笑唔笑得出? [2] 當然,做個負責任網民,未證實、無法證實嘅消息請務必清楚列明。

Hong Kong
香港
Hong Kong Protests 2019
香港政治
反送中
Recommended from ReadMedium