Skip to main content

Time to get serious in 2015




Security professionals are faced with the on-going problem of stakeholders under-estimating the security flaws within their organisation. In most cases this is not the failing of the security team but depending on the market/vertical, teams are faced with budget constraints, redundancies, or most commonly, companies not taking responsibility that Security starts within. This means educating internal staff to take responsibility from the moment they walk into the office; I.e. The devices they bring, the doors that they open to 'guests',  the confidential conversations they have in open areas and the general ethos. Furthermore, there is the responsibility of your key suppliers and other third parties that you share information with. 

You may have all the IT/Cyber security gadgets and resources you need but what are your suppliers doing with that data? Do they share the same vision for security and are they as vigilant as you? How do you measure that in an efficient way and act upon on it?

Then to the other extreme of external threats. It's not if you get attacked it's when...No matter the size of your company, no one can hide from the inevitable. Whether it's protecting your brand/reputation or the time that squeezes on your employee productivity; It's essential to get the right tools in place and resources to understand your vulnerabilities both an internal and external perspective from the top of the stack to the bottom. 

Cyber Security Insurance

Another point to think and debate on, is the stakeholders decision to attempt to defer the risk; the thought process that some of the external threats and losses are covered by Cyber Risk Insurance. Is that an excuse to relax their internal data governance practises? It only takes one of the below for premiums to rocket. It goes back to my point on educating your organisation, understand the threat. You can't mitigate everything but if you turn into a proactive organisation rather than a reactive organisation; you will be in a better position for the ongoing changes in the cyber world. IT/Cyber Security is not a small part of your business - in my opinion it should lie in the core of how your business operates.

Security teams and professionals alike can work with the budgets and tools that they are given. As horrible as it sounds, security breaches are rife and evermore imminent; these attacks are becoming closer to home than we would like. 

Some of the big security breaches we saw in 2014:

  • Russian Cyber criminal gang stole 1.2 billion usernames and passwords from 420,000 websites by exploiting SQL injection vulnerabilities in web applications
  • Intrusion into JP Morgan Chase’s network and the third-party website that manages its charity race
  • Cyberattack on Sony Pictures Entertainment’s infrastructure
  • Morrisons Suffers Staff Payroll Data Theft
  • Thames Valley Police officer dismissed for selling police information
  • Thousands hit in Tesco.com attack
  • MoonPig.com - Some 3.6 million customer data leaked
  • HeartBleed - undiscovered for more than two years. Attackers could exploit vulnerable versions of the open-source software known as OpenSSL – which runs on millions of web servers – to steal passwords, credit card details, encryption keys and other sensitive data, without leaving any trace.
  • Ebay - Hackers managed to seal personal records of 233 million users. The hack took usernames, passwords, phone numbers and physical addresses compromised.
More large scale attacks can be see here at Informationisbeautiful 

Comments

Popular posts from this blog

Aleksei Burkov Pleads Guilty for running Online Criminal Marketplace

Story : Aleksei Burkov, 29 of St. Petersburg, Russia, has pleaded guilty in a US court to running a site that sold stolen payment card data and administering a highly secretive crime forum that counted among its members, some of the most elite Russian cybercrooks. More Detail : Aleksei, who was extradited to the US from Israel in November, pleaded guilty on Thursday to running a website that helped people commit in credit-card fraud. He is accused of running a website that let people buy stolen credit-card numbers for anywhere from $3 to $60 . People used the numbers to make more than $20 million in fraudulent purchases. Prosecutors say Burkov even offered a money-back guarantee if a stolen card number no longer worked.  Company: Aleksei admitted to running CardPlanet, a site that sold more than 150,000 stolen credit card accounts, and to being the founder and administrator of DirectConnection , an underground community that attracted some of the world’s most-wanted Rus

New Venture

It's good to be back blogging...the last time I posted I worked as a Customer Success Manager for a DNS company. Since then, I have ventured to the CDN world, with the added mix of Cyber Security, WAF. Cyber Security is a true passion of mine and after nearly 10 years in this space, I love seeing how the industry and technology place has progressed and also ironically, stayed the same. I have enjoyed seeing the likes of Jane Frankland prosper in the field and be truly recognised as a thought leader with 'Women in Security' and her bestselling book 'IN Security'. Over the last few years I have met some truly amazing people, connected through the Women in Leadership platform which introduced me to a range of great individuals that broaden my knowledge into work places, diversity and pushing your own voice. Customer Success (CS), as a function is and should be the core of any business, concentrating on retention, relationship, client advocacy, project managing

HCA International fined 200k for Data loss #ITSecurity #DataSecurity #unencrypted

HCA International Ltd, private health firm are the latest to be fined by the ICO.  They have been fined £200,000 for failing to keep data secure after it was found that conversations had by IVF patients were online. Audio recordings of interviews with patients were being sent to a company unencrypted in India for transcription. The Indian company was unable to maintain secure access due to an unsecure server. By failing to ensure its subcontractor had acted responsibly, HCA International failed to comply with the seventh data protection principle. More details on the monetary penalty notice click here Supplier Risk is a huge concern for most companies - You may have all the bells and whistles when it comes to security your infrastructure but your partners may not. Failing to ensure due diligence in the Supply chain costs - with HCA it was £200,000 - next year it would of been much more!! #EUGDPR