Say hello to Derek Baillie, Allied’s Cyber Security Specialist. He spends his days monitoring our systems and keeping an eye out for anything ‘cyber-dodgy’ which could pose a threat to our business. We sat down with Derek for a more in-depth look at what his role involves, and got a few tips about to stay safe online in and out of the workplace.
What do you do here at Allied?
It is a bit of everything to be honest. I help make sure we stay safe online every day. That includes keeping our systems updated, managing our cybersecurity training, and running checks to spot suspicious emails.
I also look after all our devices and the tools we use to stay secure. One of the main systems we use collects information from our internal tools, and I go through those alerts to make sure everything is okay.
And how long have you worked at Allied now?
Nine years this year. Before that, I was working with an electrician running data cables and electrical cables and things like that.
You’ve just gained the qualification in cyber security. Tell us a bit about that.
It was a master’s degree in cyber security.
The course itself was quite broad. It covered quite a lot of areas like designing systems with a cyber security first approach, with proper access controls and making sure people aren’t overly permissioned for their role.
It also looked at a lot of historic cyber security events and cryptography, and the way secure data transmissions happen and how certain encryptions are better than others.
Did Allied put you through that or was that something that you did on your own?
It was Steve Faull, our IT Director, who suggested going for it.
We got a day a week to do our studies, and you need to use some of your own time. Because there’s maybe 16 hours of work per week in a module, so you do the coursework parts on the Wednesday and then write your essays at the weekend.
How did studying and getting that qualification change your perspective on cyber security at Allied?
I think by getting taught a bit more about threat intelligence and keeping ahead of what’s going on in the cyber security world, we can be better prepared.
We weren’t too bad with how secure we were before; it was more about tightening everything up and getting everything into policies. There was a lot of on-the-job learning with the journey Allied has been on the last few years, going from not really doing much with the cyber security to doing cyber essentials and ultimately getting ISO 27001 certified.
Allied has invested a lot in tools we need to get to where we are. We now have a lot more overview of what’s going on in the estate, so we can see a lot more security events.
We’ve started running a lot of the disaster recovery scenarios where we sit down and go through a scenario that could potentially affect our lives, and we work out what we would do and how we would respond to that kind of threat.
That must be fun, even if it is for serious reasons, have you been heavily involved in that?
For the most part I’ve been involved as an active subject matter expert and run through scenarios giving ideas of how we would respond to things. Steve’s been the one leading the charge, and Craig Roberts in Internal Audit designs the scenarios and doesn’t tell us what’s coming.
Craig runs the sessions, he asks the questions, and we respond to it. He’s like an evil genius quiz master. It’s a new scenario every time, and we build a playbook based on that scenario, then we put them all together and do some external testing.
We’ve got a company coming in to do penetration testing with us. That’s when we pay a company to test our systems. So, they’ll try and hack in and break stuff and look for vulnerabilities, and they give us a report on everything they find which lets us know what to work on.
And then there’s internal pen-testing, which is giving someone access to our systems and seeing how long it takes us to detect them on the system, and how much damage they could do if they did get in. There’s obviously a lot of trust involved there so we’re working with the Cyber Fraud Centre, Scotland for that.
What would be your top three things that you would say people can do to boost their own cyber security or be more cyber security aware?
The first one is always passwords; making sure you have a secure password or you’re using a password manager. Get a password manager to give you a random password that you wouldn’t ever remember, so you only need to remember the password to your password manager.
Second, the stuff we teach through the cyber security modules is all relevant outside work as well. You can get a dodgy email to your personal email as easily your work email—probably more easily! So being vigilant with that kind of thing helps to protect you.
Finally, 2FA (Two Factor Authentication) is a good one. Whether it’s a 2FA app or biometric, it gives you that extra layer of security.
Those three things are the “something you know, something you are, or something you have” approach, and you should try to have two of the three of those.
Something you know would be your password. Something you have would be a secondary device, like a phone for an authenticator app. Something you are, would be your biometrics like fingerprint or face scan.
Outside of Allied what do you like to do with your free time?
I enjoy going away for the weekend and taking the dog for a walk. I quite like going to Pitlochry; that’s one of my favourite places to take the dog a walk in the countryside, it’s a nice way to get away from technology.
What kind of dog do you have?
He’s a Jackapoo; a Jack Russell Cross Poodle, called Bear. He’s not the size of a bear. He is just a wee fluffy thing.
When you’re not walking Bear, any favourite films, TV shows, books – anything like that?
I’m probably more of a gamer. I’m playing Grounded 2 just now. It’s like Honey I Shrunk The Kids the video game. You get a shrunk to a tiny size and you’re in a park fighting the ants and stuff. It’s really good.
The last one I played was Dredge and Dave the Diver. Dredge was really fun; it was chill but also terrifying.
What is something that not many people in Allied would know about you?
Maybe that I’m vegan? I’ve been vegan for five or six years now.
You went vegan at 33, was it tough to make the switch after so long?
No, not really. I didn’t find the transition that bad. After watching a few documentaries, it put me completely off meat and we went vegetarian for all of a week, until we realized that the milk industry isn’t much better.
I didn’t really eat eggs before that, so that was a fairly easy transition since I already preferred oat milk anyway.
Do you currently have a goal that you’re working towards?
I’ve just finished uni, so nothing in that vein right now. I’m looking at building my own house in a few years. So that’s probably the biggest one. It’s quite a big project.
If you hadn’t ended up in IT, is there another career path that you think you might have followed?
Oh, quite a few. I wanted to be a vet at school, and I did a two-week placement. Then realised how much I hated it because of people putting other people’s dogs down and I just couldn’t cope with it. So, that changed my career.
I think I would have probably qualified as an electrician if I didn’t get the opportunity to come back into IT. But I’ve always been quite mechanically minded as well so I liked engineering, architecture or possibly even mechanic stuff.
I’m a bit of a Jack of All Trades to be fair.
