At ENGECO, security has been a priority, in particular to prevent SQL injections. But I'm well aware that all these terms may seem a bit remote to you!
Indeed... Which is why I'd like to talk about Ecole 42! What a nice reference! Can you tell me about your training there and how it prepared you for a career in fullstack development and cybersecurity?
"École 42 offers intensive, practical training that taught me a lot. It taught me how to learn."
Here are some key aspects:
- Project-based learning: each project required a complete solution to the given problem, often with integrated security requirements.
- Collaboration and peer-learning: working with other students on complex projects strengthened my ability to collaborate and share good safety practices, among other things.
- Access to varied resources: I was able to explore various technologies and frameworks used in industry.
- Culture of autonomy: it prepared me to be proactive and to continue to learn independently, including in the field of cybersecurity.
- Practical experience: Hackathons (events where people collaborated intensively on projects over a few days, to create innovative prototypes) and programming exercises that included security challenges.
"The branch specialisation I chose included projects such as redesigning Instagram, Tinder and Netflix".
School 42 ( copyright )
Impressive! And in your opinion, what has been most beneficial for your professional development?
I'd have to say:
- Autonomous learning: my ability to solve problems independently, (a key skill in cybersecurity) has increased.
- Collaboration and networking: working with peers and accessing a vast network of professionals has been more than beneficial.
- Immersion through real-life projects : projects based on real-life situations prepared me for the real-life challenges of development and security.
- Continuous updating : a culture of continuous learning, which is essential in a field as dynamic as cybersecurity.
So, would you be able to tell me what the main cybersecurity threats are today?
The main threats to cybersecurity today include :
- Massive data leaks from large groups holding users' personal information.
- Ransomware attacks. They continue to grow in frequency and sophistication.
- Phishing: an attack technique in which cybercriminals send fraudulent emails to lure victims to fake websites, enticing them to divulge personal information such as login details, passwords or financial details.
- Internal threats: employees can intentionally or unintentionally cause data leaks or security breaches.
- Zero-day attacks : this is typically an attack against which the user cannot protect himself. Exploitation of vulnerabilities not yet known to developers.
- The Internet of Things (IoT): IoT devices, which are often poorly secured, are new targets. Watch out for your computer camera, for example.
- Supply chain attacks: compromising suppliers to reach target companies.
- Library corruption: when a software library in use is compromised by malicious code.
- The notorious "Man in the middle": an attack carried out by intercepting and manipulating communications on public networks.
"Social engineering: you know, that famous phone call where you're led to believe that it's your banker calling because your bank account has been hacked. Then they take advantage of the situation to get our bank details. Well, there you go, jackpot".
The risk in cyber security is the synergy between different types of attack.
It's clear that you don't realise this on a day-to-day basis... Finally, what does Inforca bring to your work? On a day-to-day basis?
Inforca offers a flexible working environment that fosters team cohesion with people of varied backgrounds who are open to discussion. What's more, thanks to the diversity of our clients - institutions and professionals from different business sectors - the assignments we take on are always varied and stimulating. The search for solutions that are best suited to our customers' needs and putting them into practice creates real intellectual stimulation on a daily basis.
Interview by Alisée, Digital Development and Events Manager at Inforca, with Matthieu, fullstack/cybersecurity developer at Inforca.