Skip to main content

Posts

Showing posts with the label IT Security

2016 Cyber attacks review #Throwback #Lookout2017

2016 has been an interesting year for Cyber Crime with companies like Yahoo, LinkedIn, Lynda.com, TalkTalk (again), Ashley Maddison (being fined $1.6 million for 2015 data breach), KFC, Wells Fargo, MailChimp, AdultFriendFinder, MichaelPage; to name a few.  It's Christmas time and I don't want to be the bearer of bad news however it will get worse as the months/years go on and as companies we can only be prepared and react at our best ability. But a word to the wise; learn from others mistakes. Communication is the key here with customers and suppliers; that is internally and externally. Many bury their head in the sand but making sure you have a robust and up-to-date Incident response plan, Governance Risk and Compliance, Runbooks, Security awareness training, Solutions are being used, or needed etc.  EU GDPR will come into force by 2018 which gives another year to get the ducks in a row . Which could lead to fines of up to €20 million or 4% of global annual turnover f...

Wendy's hit by massive #Cyberattack #Databreach

The company reported suspicious activity earlier this year, but the scale of the breach is far bigger than first anticipated. At least 1,025 of its restaurants were targeted - with debit and credit card information stolen. The company did not speculate how many people may have been affected, though it did say all of the locations were in the US. Malware - malicious software - had been installed on point-of-sale systems in the affected locations. The chain said it was confident the threat had been removed, and was now offering help to customers who may have been affected. Help includes the offer of one year of "complimentary" fraud protection services. In a statement outlining the details of the attack, Wendy's said the malware could have been operational in its restaurants from as early as Autumn 2015. Suspicious activity was noticed in February of this year. The company went public with this discovery in May - saying it believed around 300 restaurants...

ICO Referendum response plus UK Gov recommendations to #DataBreaches and University gets suffers Second #DataBreach

ICO Referendum result response An ICO spokesperson said: “The Data Protection Act remains the law of the land irrespective of the referendum result. “If the UK is not part of the EU, then upcoming EU reforms to data protection law would not directly apply to the UK. But if the UK wants to trade with the Single Market on equal terms we would have to prove 'adequacy' - in other words UK data protection standards would have to be equivalent to the EU's General Data Protection Regulation framework starting in 2018. “With so many businesses and services operating across borders, international consistency around data protection laws and rights is crucial both to businesses and organisations and to consumers and citizens. The ICO’s role has always involved working closely with regulators in other countries, and that would continue to be the case. “Having clear laws with safeguards in place is more important than ever given the growing digital economy, and we will be s...

Human Error, a common theme in the ICO data breach findings #UK #ICO

The ICO recently carried out a study of the recent security incidents that have been reported or notified to the ICO. It's no shock that data breaches are on the rise with two-thirds of sectors studied reporting an increase in the first quarter compared with the same time a year ago, according to new ICO figures. The data protection watchdog, ICO have shown findings for the period 1 January – 31 March 2016 and uncovered some worrying statistics. Below are the key data security issues for each sector:  Data security incidents by type: The main data security issues within the health sector were: Data being posted or faxed to an incorrect recipient – 22% of incidents. Loss or theft of paperwork – 20% of incidents. The main issues for local government were: Data being posted or faxed to an incorrect recipient – 23% of incidents. Failure to redact data – 16% of incidents. Loss of theft of paperwork – 14% of incidents. The main issues for education were: Los...

Top 5 Considerations for Effective Security Awareness #ITSecurity #SecurityAwareness #PeopleIssue

"If you want to change attitudes, start with a change in behaviour"  This quote was taken by William Glasser, an American psychiatrist. I think it's really relative to this subject, as a user, you may be fully aware of IT/Cyber Security and how your actions can reflect on the company you work for...However it doesn't mean it is going to change the way you work. As a company you need to start to change users   behaviours ... The below is taken from the company I work for ZeroDayLab  blog, which I feel, are the key components to Security Awareness/Behaviour Training. Top 5 are below (part 2 to follow) Interested in the datasheet? please let me know... Security, The Risk of Human Error...& a Tricky Thing Called Motivation… Top 10 Considerations for Truly Effective Security Awareness Training Even though 52% of breaches are attributed to human error, security awareness is still quite a new thing for many companies....

Time to get serious in 2015

Security professionals are faced with the on-going problem of stakeholders under-estimating the security flaws within their organisation. In most cases this is not the failing of the security team but depending on the market/vertical, teams are faced with budget constraints, redundancies, or most commonly, companies not taking responsibility that Security starts within. This means educating internal staff to take responsibility from the moment they walk into the office; I.e. The devices they bring, the doors that they open to 'guests',  the confidential conversations they have in open areas and the general ethos. Furthermore, there is the responsibility of your key suppliers and other third parties that you share information with.  You may have all the IT/Cyber security gadgets and resources you need but what are your suppliers doing with that data? Do they share the same vision for security and are they as vigilant as you? How do you measure that in an effici...

Police need more money to fight cyber-crime, finds report

Money is urgently needed from the Government's £860 million National Cyber Security Programme to plug big holes in the police's ability to combat cyber-crime, which is now reaching crisis levels. That's the key finding from an authoritative new  survey   by PA Consulting which finds that only 30 percent of UK police analysts believe they have the skills and tools to effectively combat cyber-crime. “The UK has reached a ‘tipping point' on cyber-crime and tackling the challenges is now urgent,” the report reads. PA Consulting finds that one-third of the 185 analysts questioned from 48 law enforcement organisations have been unable to share information about the cyber-threat, and just five percent believe they have ‘considerable knowledge' of cyber-crime. The respondents predict that the time they will spend analysing cyber-crime will treble over the next three years – yet they already have limited scope to deal with the problem, spending only 10 percent of th...

DNS provider hit by 'massive' DDoS attack on Cyber Monday

DNSimple says that it was hit by a ‘massive' DDoS attack, believed to be the work of Chinese hackers, on Cyber Monday. The Florida-based company revealed on  Twitter  that it had been targeted by a volumetric DDoS attack overwhelming DDoS defences, and was working with its network provider to restore service. After first posting it was seeing a ‘system-wide' DNS outage, the firm added: “We are experiencing a massive DDoS. We are working with our network provider to mitigate it. Apologies.” In a series of posts later on Monday and early Tuesday morning, the firm revealed that it was working with its network provider to mitigate the volume of UDP traffic, including increasing service capacity. Most servers at data centres were fully operational briefly on Tuesday morning, only for attackers to return to target the US west coast data centre before ‘ramping' up DDoS attacks internationally. Cited and more on this story at SC Magazine

'Let's Encrypt' aims to drive adoption of HTTPS

Some of the world's biggest security companies are working together to develop 'Let's Encrypt' - a new certificate authority (CA) offering free and automatically renewable HTTPS web encryption. Due to launch next summer,  Let's Encrypt  has been established by Mozilla, Cisco, Akamai, the Electronic Frontier Foundation, IdenTrust as well as researchers at the University of Michigan  - who are working through the California-based Internet Security Research Group (ISRG). The aim is for the CA to drive the adoption of HTTPS web encryption and to do this by making obtaining the SSL certificate as easy as clicking a button or issuing a simple shell command. The accreditation is free to anyone who owns a web domain, certificates can be reviewed for transparency, while the security companies behind the project say that the management software installed on web servers proves that the domain holder controls the website, has obtained a browser-trusted certificate and h...