Posts

Showing posts from May, 2017

How to Stay Safe in the Cloud

Image
No business or individual should ever assume 'Cloud Services' are sufficiently secure to protect their data and their cloud service provision. There are always elements of cloud service security responsibility which sit squarely with the service buyer (business) and users. Sage  have put together a simple to understand InfoGraphic on  Staying Safe in the Cloud , which neatly highlights the threats and the security pitfalls to be aware of when adopting cloud services.

WannaCry Ransomware Bite Sized Business Prevention Advice

Image
The top three actions to reduce the risk and impact of a WannaCry type Cyber Attack at a business Perform regular Staff Awareness specifically on spotting Phishing Emails Have a robust Patch Management Processes. Ensure all Microsoft Windows systems have Microsoft Critical Updates applied quickly - they are marked as critical for a reason! Have Anti-Virus running on all Microsoft Windows systems, with AV definitions kept up-to-date Security in Depth There are further security risk-reducing steps like filtering web traffic, ensuring data is regularly backed up, security monitoring, and network segmentation, but the above three are the most simple and most effective in terms of prevention against this type of attack, especially within the SMB space where security budgets are limited. Expect further versions of the WannaCry ransomware. The Reasons Behind this Advice (1) The WannaCry ransomware infects an initial system via a phishing email, the user executes the malware within...

The IT Security Expert Blog is 10 Years Old

Image
Ten years ago today I published my first ever blog post about a BBC news story titled " Home Network Security Scrutinised ". A decade ago it was rare to see an IT security or hacking story make the news media, and back then the term 'Cyber Security' would conjure images of Dr.Who's metallically clad arch-villains in most people's minds in the UK. The Face of Cyber Security in 2007 Fast forward ten years, IT security has long been rebadged as 'Cyber Security' and on Friday the top ten news stories  on Sky News were all Cyber Security related, albeit about the same global attack , but how times have changed. 'I found the following article on the BBC news website, which happens to be exactly what I had been talking about in my presentations this week. None of the findings is surprising to me, but I find many people I talk with are in the dark about digital security. Anyway, I thought I'd write this post about it and start my own blog...

WannaCry Global Cyber Attack Killing the NHS Explained & Help

Image
A large-scale cyber-attack has impacted organisations around the world today, including badly affecting NHS services, with at least 25 NGS organisations hit by a mass ransomware outbreak. The ransomware responsible is known as WanaCrypt0r 2.0, WannaCry or WCry2, once it infects a system not only does it encrypt data on the host system, but it attempts to infect other computers over the local network.  This aggressive malware uses an exploit method named EternalBlue, details of which was posted online by the Shadow Brokers dump of NSA hacking tools on April 14th, 2017 . WannaCry exploits this Windows vulnerability (CVE-2017-0145)  to enable it to spread quickly over the network (i.e. Worm malware), the vulnerability was security patched by Microsoft on 14th March 2017. More specifically, the vulnerability lies within the  SMB protocol, which is used for network file sharing, which the WannaCry malware exploits to replicate itself to other vulnerable Windows devices al...

Cyber Security Roundup for April 2017

In April the National Cyber Security Centre (NCSC) briefed major UK businesses about a significant Chinese Cyber-Espionage Threat called APT10, also known as Stone Panda, which I have featured in a separate blog post - Detecting & Preventing APT10 Operation Cloud Hopper . The InterContinential Hotel Group, a hotel giant best known for the Crowne Park Plaza and Holiday Inn in the UK, reported data breaches within 12 of its hotels, however, Brian Krebs, the investigative journalist who first broke the story , reckons that there could be more than 1000 locations affected. A statement released on the hotel's website says that the malware, which infected the hotels' card payment systems, was identified between 29 September and 29 December 2016. Payday loan firm Wonga reported a data breach which may affect up to 245,000 of its UK customers. The information stolen includes names, addresses, phone numbers, bank account numbers and sort codes. A BBC Click investigation ha...