Tim Brown joined Cisco as part of their acquisition of Portcullis for whom he worked for almost 12 years. He is equally happy performing white box assessments with access to source code or where necessary diving into proprietary binaries and protocols using reverse engineering methodologies. Tim has contributed to a number of Cisco’s bespoke methodologies covering subjects as diverse as threat modelling with data analytics, risk and compliance, secure development and host hardening as well as bespoke industry specific technologies in banking and telecomms. This has included improvement in technical capability as well as development of new operational maturity models and practices.
Over the years, he has looked at targets as varied as intelligent transportation in planes, trains and automobiles, threat hunting and red teaming on high-end UNIX and mainframe environments, PLC protocol security and detection engineering in 5G mobility solutions. Tim has also received awards from both Cisco (Global Security Champion) and MEF (Top 5 Contributor) for his contributions to security research.
Outside of the customer driven realm of information assurance, Tim is also a prolific researcher with papers on data analytics, MITRE ATT&CK, Active Directory, UNIX, KDE, Vista and web application security to his name. Tim is credited with over 150 vulnerability advisories covering both kernel and userland, remote and local and has, for the last 6 years, supported ATT&CK's reporting of Linux threats with new sources of intelligence. This latter activity has resulted in the addition and/or improvement of over a dozen techniques. Tim particularly likes to bug hunt enterprise UNIX solutions.
Most recently Tim spoke at CREST's SOC event and BSides London on some of his threat-centric research.
In today’s threat landscape, resilience depends on understanding how your adversaries operate as well as understanding your own environment. Learn about Cisco Threat Modeling today.
Unless you’ve been asleep recently, you’ll probably be aware of MITRE’s ATT&CK framework. This is a game changer for defenders as it maps out the common threats that an enterprise will face. ATT&CK aligns this to protective and detective controls and allows everyone within the enterprise to speak a common language on how attackers might […]
As security consultants, we go into an extraordinary array of organisations’ security environments, all with very differing levels of maturity. Our clients consistently state a common desire: "We need a...
As security consultants, we go into an extraordinary array of organisations with very differing levels of maturity and one thing keeps on coming up: "we need a SOC". Whilst this...
The Team believes that the likelihood of a successful Internet delivered attack by either a malicious insider or via an external actor is high, given the systemic failures identified in these scenarios.
Moving from self-hosted infrastructure to cloud-based environments increases the demand for resiliency and security. Cisco's cloud security solutions give our customers the visibility they desire.
In what was an interesting change to the usual technical and risk/compliance focused consultancy, the Team carried out a War Games exercise - similar to a "Red Team" engagement.