|

Cybersecurity and Aikido

Disclaimer: I am neither a cybersecurity expert nor an Aikido practitioner so apologies in advance for any faux pas or false facts.

I was watching this video recently where it interviews an Aikido masters and he talked about Iai (Iaido), where one is always prepared to draw their sword due to sudden attack, which relates to the point that there is no honour or dishonour in attacking people when they are not ready, opposite to the idea of dueling in the West. Seems harsh but let’s think about it: if you’re a criminal, would you wait for your victim to get ready or not disadvantaged? Criminals have bad intentions anyways, and it seems ludicrous to expect them to follow rules. No honours among thieves, is the saying.

I was then reminded a few months ago when I was involved in a cybersecurity assessment of a product and we were looking at ‘strengthening’ the product through methods or techniques in the cybersecurity standard IEC 62443. The standard is huge and well intentioned but like the concept of Iai, a criminal would in no way ‘follow’ the standard, but will likely just poke and prod until he/she finds a hole or weakness in the chain. So we tried to put ourselves in the position of a criminal or hacker but this has the danger of going to extreme means in order to attack or hack the product. To be fair, IEC 62443 does have rationalisation of how much effort needed to expended based on the possible risk, which is quite useful to justify our action, but sometimes it is not that clear cut.

Maybe I am trying to hard to draw the parallel between the twos but I think cybersecurity is in some sense is martial art, as it is a form of protection, only it is done digitally.

Thank you for reading.

Similar Posts

  • Grass Is Always Greener

    Recently a famous Malaysian who is living in the UK, showed how he manages to buy a trolley of groceries for only GBP 50. But is the groceries in the UK really that cheap? Actually it is not so cheap compared to Malaysia. GBP 50 is roughly RM 300, and you can get a similar…

  • | |

    Imposter and Plateau

    Yesterday I complained to my wife that I don’t really like signalling railway, not the way some of my colleagues or the people I meet in the industry. I then went on that I don’t really adore engineering, either mechanical engineering such as automotive, where some people know the horsepower of the new concept car…

  • View of Years

    A colleague brought a cake to the office today because it was his birthday , something the British does (in Malaysia it’s the other way around, where the office would buy birthday cake for the one who is celebrating). Anyways, people were wishing him happy birthday, and asked his age (something I heard you should…

  • Age Is a Number

    I celebrated my birthday recently. Been contemplating whether to write a post or not about it since if I write it here, I’m leaving a cyber trail and exposing myself to cyber security issues where malicious actors might steal my identity. Then I remember that you can buy a list online (not even on the…

Leave a Reply

Your email address will not be published. Required fields are marked *