Posts

Showing posts from 2018

All I want for Christmas: A CISO's Wishlist!

Image
As Christmas fast approaches, CISOs and cyber security experts around the world are busy putting plans in place for 2019 and reflecting on what could have been done differently this year. The high-profile data breaches have been no secret - from British Airways to Dixons Carphone to Ticketmaster - and the introduction of GDPR in May 2018 sent many IT professionals into a frenzy to ensure practices and procedures were in place to become compliant with the new regulation. What the introduction of GDPR did demonstrate was that organisations should no longer focus on security strategies, which protect the organisation’s network, but instead focus on Information Assurance (IA) which protects an organisation’s data. After all - if an organisation’s data is breached, not only will it face huge fallouts of reputational damage, hits to the organisation’s bottom line and future prospecting difficulties, but it will also be held accountable to regulatory fines - up to as much as €20 million, or...

Why other Hotel Chains could Fall Victim to a ‘Marriott-style’ Data Breach

Image
A guest article authored by Bernard Parsons, CEO, Becrypt Whilst I am sure more details behind the Marriott data breach will slowly come to light over the coming months, there is already plenty to reflect on given the initial disclosures and accompanying hypotheses. With the prospects of regulatory fines and lawsuits looming, assimilating the sheer magnitude of the numbers involved is naturally alarming. Up to 500 million records containing personal and potentially financial information is quite staggering. In the eyes of the Information Commissioner’s Office (ICO), this is deemed a ‘Mega Breach’, even though it falls short of the Yahoo data breach. But equally concerning are the various timeframes reported. Marriott said the breach involved unauthorised access to a database containing Starwood properties guest information, on or before 10th September 2018. Its ongoing investigation suggests the perpetrators had been inside the company’s networks since 2014. Starwood disclosed its own...

Cyber Security Roundup for November 2018

One of the largest data breaches in history was announced by Marriott Hotels at the end of November. A hack was said to have compromised up to a mind-blowing "half a Billion" hotel guests' personal information over a four year period.  See my post,  Marriott Hotels 4 Year Hack Impacts Half a Billion Guests  for the full details.  The Radisson Hotel Group also disclosed its Rewards programme suffer a data compromise . Radisson said hackers had gained access to a database holding member's name, address, email address, and in some cases, company name, phone number, and Radisson Rewards member number. Vision Direct reported a website compromise , which impacted users of their website between 3rd and 8th November, some 16,300 people were said to be at risk  A   fake Google Analytics script  was placed within its website code by hackers.  Eurostar customers were notified by email to reset their passwords following presumably successful a utom...

Marriott Hotels 4 Year Hack Impacts Half a Billion Guests!

Image
A mammoth data breach was disclosed by hotel chain Marriott International today (30 Nov 18), with a massive 500 million customer records said to have been compromised by an "unauthorized party".  The world's largest hotel group launched an internal investigation in response to a system security alert on 8th September 2018, and found an attacker had been accessing the hotel chain's "Starwood network" and customer personal data since 2014, copying and encrypting customer records. In addition to the Marriott brand, Starwood includes W Hotels, Sheraton, Le Méridien and Four Points by Sheraton.  You are at risk if you have stayed at any of the above hotel brands in the last 4 years The Marriott statement said for around 326 million of its guests, the personal information compromised included "some combination" of, name, address, phone number, email address, passport number, date of birth, gender and arrival & departure information. ...

Complexity is the Worst Enemy of Security, Time for a New Approach with Network Security?

Bruce Schneier summed it up best in 1999 when he said " C omplexity is the Worst Enemy of Security" in an essay titled A Plea for Simplicity , correctly predicting the cybersecurity problems we encounter today. The IT industry has gone through lots of changes over the past few years, yet when it comes to cybersecurity, the mindset has remained the same. The current thinking around cybersecurity falls into the definition of insanity, with many organisations doing the same thing over and over again, expecting different results, and are then shocked when their company is the latest to hit the hacking headlines. The current security model is broken and is currently too complex. As Paul German, CEO, Certes Networks , argues, it’s time to strip network security back and focus on the data.  What should Organisations Really be Protecting? Ultimately, by overcomplicating network security for far too long, the industry has failed - which won’t come as a surprise to many. We’ve ...

How Safe and Secure are Wearables?

Image
The ‘wearable technology’ market has been exponentially growing in recent years and is expected to exceed 830 million devices by 2020 . One of the key drivers pushing this rapid expansion are fitness trackers, namely wristband tech and smartwatch apps which monitors our daily activity and health. But as we integrate wearables devices seamlessly into our everyday lives, what are the privacy and security risks they pose? How should wearable manufacturers and app developers be protecting consumers? Insurance company Vitality offers customers a heavily discounted Apple Watch  to customers in return for their fitness routines and health data, the more activity you do each month, the greater your reward through a monthly discount. While t his exchange of information for rewards provides a great incentive for consumers to improve their health, the personal data consumers are sharing in return has a tangible value for the insurance company. However, providing an insurance compan...

Cyber Security Roundup for October 2018

Aside from Brexit, Cyber Threats and Cyber Attack accusations against Russia are very much on the centre stage of UK government's international political agenda at the moment.  The government publically accused Russia's military 'GRU' intelligence service of being behind four high-profile cyber-attacks , and named 12 cyber groups it said were associated with the GRU. Foreign Secretary Jeremy Hunt said, " the GRU had waged a campaign of indiscriminate and reckless cyber strikes that served no legitimate national security interest ". UK Police firmly believe the two men who carried out the Salisbury poisoning in March 2018 worked for the GRU. What is Russia's GRU Intelligence Agency? The risks of cyber-conflict with Russia Russia accused of net hack attacks Russian spy: What happened to the Skripals? The UK National Cyber Security Centre said it had assessed "with high confidence" that the GRU was "almost certainly responsible...

Cyber Security Roundup for September 2018

September 2018 started with a data breach bang, with  British Airways disclosing a significant hack and data loss . 380,000 of the airlines' website and mobile app customers had their debit and credit card details lifted via a maliciously injected script.  The breach even caused BA owners, IAG, to drop in value 4%. And to compound matters, there were several claims made that  the BA website wasn't PCI DSS compliant , implying if they were PCI DSS compliant, their customer's personal and payment card information would still be safe.  For further details about this breach see my blog posts;  British Airways Customer Data Stolen in Website and Mobile App Hack  and  British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected . Facebook continues to make all the wrong kind of privacy headlines after a massive user data breach was confirmed by the social media giant at the end of the month. Facebook said at ...