This month, we’re talking to Martin Indrek Miller, our Lead Technical Project Co-Ordinator. Martin has had a varied and interesting career in Information Security and works across the globe as an integral part of the Cyber4Dev team.
Could you give us an idea of your education / career background?
I graduated Tallinn Secondary Science School which as name gives some hints is specialized in Math, Physics and Chemistry. In reality STEM topics at the time weren’t really my favorite to say the least. After graduating high school I really didn’t have good idea what I wanted to learn or what sort of career I would like to pursue. I found an interesting topic from Tallinn Technical University that had a Product Development course under Mechanics department.
During the first year of studies I also assembled my very own first computer – not that I really wanted to, but at the time, it was cheaper to buy computer components (Motherboard, CPU, GPU, RAM Memory module, Power supply etc.) and assemble itself. As a student you don’t have much spare money laying around so you optimised your costs. I also didn’t have any knowledge about computer build and at the time there was no YouTube, so I reached to one friend who assisted me via phone on how to assemble a computer. Once I got it working, Heureka! From there I got the bug!

In parallel of studies I started my first position as IT technician in a small company. From there I worked myself up when one of those customers offered me a full time job at their company, which I took and where I ended up after almost 5 years as IT manager. I was offered a job in Deloitte Audit as an IT auditor, knowing nothing about audits, it was learning by doing. Deloitte had many big clients from Telcos and Banking sector and yet again after year and half later one of the Banking clients of Deloitte offered me a full time position in their Internal audit department. It wasn’t a difficult decision for me to take as benefits were pretty generous. The Bank I worked for was the largest financial institution in the Baltics at the time, it had an IT department which had more than 700 employees and if it were a separate company, it would have been the largest IT company in Baltics at the time. After a year in Internal audit I was offered a position in IT risks department who dealt with all sorts of risks related to information security in a bank. We dealt with risks related to users rights in systems, networks, online banking, software development and even physical security and access management in our data centers, plus many more.
What attracted you to Information Security?
This was something quite new at the time and right when I had joined Bank, 2007 famous cyber attacks happened after riots in Tallinn. It was pretty intense time, as I’m also member of voluntary National Defence League, I was called out to defend our presidents official residence and at same time cyber attacks against my employer and Estonian public infrastructure took place. At the end of 2007 I was offered a position in IT risk department and got more focused/interested on different technology and information risks.
What skills do you think that Cyber professionals need to have?
When we talk about in a very broad scale of IT professionals – may it be from IT help desk personnel, software developers, testers, system administrators, network administrators etc. then I think one of the skills necessary is to have a critical mind and ability to see the bigger picture. In Estonia we like to talk about Security by design – which basically means that from the beginning, when a new system is being designed, security must be considered in every step – from design until the system is live in production. And during all of those steps different IT professionals are involved. From a cybersecurity professionals perspective, I see that every major cyber incident has started from a minor mistake or error. Security is like a chain is only as strong as its weakest link.
Why is it important to think about risk?
Essentially every person thinks about risks on a daily basis. Subconsciously we do risks assessment every day – when crossing the street, first we evaluate is it safe or not, and make a decision based on our best ability. When you poor a cup of tea, you subconsciously assess before drinking, is it too hot or not. Some people have bigger risk appetite than others and sometimes they get hurt. The bigger the impact of what we are doing (building complex systems, making significant decision in business or private life etc.), the more we tend to think of risks – problem is that if we don’t do it in systematic way, we might miss some of the significant threats and vulnerabilities we have and eventually might get “hurt” very badly, if we were not prepared for it. Risk audit helps you to prepare for the worst.
Martin, much of your work is focused on advising people about cyber risks. We know that organisations need to manage risk constantly, but sometimes it’s easy to ignore – why is it so important for cyber risks to be prioritised?
IT risk analysis/assessment has been significant part of my job in the past. I also give trainings on IT Risks analysis and assessment based on the simplified model we created years ago in Estonia. I have also trained significant part of Estonian Vital service providers staff in the past on this topic. The importance of prioritizing risks is pretty simple – once you have identified all the known risks, the goal is to minimize the potential damage (impact). As mainly every risk reduction costs money, management needs to make a calculated decision on which risks they will deal with and which they accept – comes back to the Risk appetite.
The past twelve months have changed so much of our lives, how do you think that the last 12 months have reshaped the cyber landscape?
I guess the answer lies already in the question. Majority of us are working from home and it is a challenge for everyone. Online meetings, Online shopping has grown significantly, as well as some specific types of crimes. It also creates a challenge for corporate security as at home there is no real control who has access to your computer and information. Some parents tend to share their computers with kids and thus create even higher risk of downloading malware.
What are the top trends and threats that you foresee coming in the near future?
Malware will get even more complicated and more difficult to detect by antivirus. We will probably see more high profile state sponsored attacks to be discovered. Supply chain attack are becoming more popular to penetrate corporate/state networks.




