Posts

Showing posts from January, 2019

Information Security no longer the Department of “NO”

Image
The information security function within business has gained the rather unfortunate reputation for being the department of “no”, often viewed as a blocker to IT innovation and business transformation. A department seen as out of touch with genuine business needs, and with the demands of evolving workforce demographic of increasing numbers of numbers Millennials and Centennials. However, new research by IDC\Capgemini reveals that attitudes are changing, and business leaders are increasingly relying on their Chief Information Security Officers (CISOs) to create meaningful business impact. IDC \ Capgemini Study: The Modern, Connected CISO The study bears out a shift in executive perceptions that information security is indeed important to the business. With the modern CISO evolving from that of a responder, to a driver of change, enabling to build businesses to be secure by design. The survey found CISOs are now involved in 90% of significant business decisions, with 25% of busin...

43% of Cybercrimes Target Small Businesses - Are You Next?

Image
Cybercrimes cost UK small companies an average of £894 in the year ending February of 2018. Small businesses are an easy target for cybercrooks, so its little surprise that around about 43% of cybercrime is committed against small businesses. According to research conducted by EveryCloud , there is much more at stake than a £900 annual loss, with six out of ten small businesses closing within six months of a data breach. Damage to a small company’s reputation can be difficult to repair and recover from following a data breach. Since the GDPR data privacy law came in force in May 2018, companies face significant financial sanctions from regulators if found negligent in safeguarding personal information. Add in the potential for civil suits the potential costs start mounting up fast, which could even turn into a business killer.  Case in point is political consulting and data-mining firm Cambridge Analytica, which went under in May 2018 after being implicated with data privacy is...

The Emergence of Geopolitical Fuelled Cyber Attacks

Image
A new breed of cyberattack is emerging into the threat landscape, fuelled by geopolitical tension, there has been a rise in stealthy and sophisticated cyber attacks reported within recent industry reports. Carbon Blacks 2019 Global Threat Report , released on Wednesday (23/1/19), concluded global governments experienced an increase in cyberattacks during 2018 stemming from Russia, China and North Korea, while nearly 60% of all attacks involved lateral movement. 'Lateral Movement' is where an attacker progressively and stealthy moves through a victim's network as to find their targets, which are typically datasets or critical assets. This is an attack of sophistication, requiring skill, resources and persistence, beyond the interest of average criminal hackers, whom go after the lowest hanging fruit for an easier financial return. Carbon Black concluded that as 2018 came to a close, China and Russia were responsible for nearly half of all cyberattacks they detected...

Is AI the Answer to never-ending Cybersecurity Problems?

Image
Paul German, CEO, Certes Networks , talks about the impact and the benefits of Artificial Intelligence(AI) driven cybersecurity. And how AI adoption is helping organisations to stay ahead in the never-ending game that is cybersecurity. Artificial Intelligence (AI) isn’t going anywhere anytime soon. With 20% of the C-suite already using machine learning and 41% of consumers believing that AI will improve their lives , wide scale adoption is imminent across every industry - and cybersecurity is no exception. A lot has changed in the cyber landscape over the past few years and AI is being pushed to the forefront of conversations. It’s becoming more than a buzzword and delivering true business value. Its ability to aid the cybersecurity industry is increasingly being debated; some argue it has the potential to revolutionise cybersecurity, whilst others insist that the drawbacks outweigh the benefits. With several issues facing the current cybersecurity landscape such as a disappearing I...

The Biggest Data Breaches of 2018

Image
Online security label manufacturer Seareach.plc.uk who specialise in asset labels and asset tracking, has collated some of the biggest data breaches of 2018. February 150 million MyFitnessPal app users had their details leaked in a data breach including usernames, email addresses and passwords. March Orbitz had 880,000 customers payment card details, stolen by a hacker, thanks to a security vulnerability in the travel site's legacy booking system. Fifa More than 3.4 terabytes of data and 70 million documents from FIFA, containing numerous allegations of corruption, was leaked to German magazine Der Spiegel by the Football Leaks organisation. Cambridge Analytica harvested data (without user permission) from Facebook, more than 80 million people were affected by the data exposure. April Macy’s and Bloomingdale's online customers may have had their personal information and credit card details exposed to a third party between April 26 and June 12. May Rail Eu...

Microsoft Windows 7 & Windows 2008 End of Life

Image
Microsoft Windows 7 and Windows Server 2008 End of Life is fast approaching. 'End of Life' is the point where the operating system will be no longer supported with security patches, unless you (as a business) take out a rather expensive extended warranty agreement with Microsoft. As a home user, you should upgrade from Windows 7 without delay, as there are significant performance improvements to be gained with Windows 10. I always recommend installing Windows 10 from scratch onto a blank hard disk drive, rather than using the upgrade option. Ideally install onto a new Solid State Drive (SSD), which improves an operating system's performance massively. SSDs have come down in price in recent months, making a decent memory size SSD an affordable option. Always ensure all your important documents and data are backed up at all times, double check before attempting an operating system installation or upgrade. Where as a businesses you have Windows 7 and Windows Server...

Cyber Security Conferences to Attend in 2019

A list of Cyber and Information Security conferences to consider attending in 2019. Conference are not only great places to learn about the evolving cyber threat landscape and proven security good practices, but to network with industry leading security professionals and likeminded enthusiasts, to share ideas, expand your own knowledge, and even to make good friends. JANUARY 2019 SANS Cyber Threat Intelligence Summit Monday 21st & Tuesday 22nd January 2019 Renaissance Arlington Capital View Hotel, VA, USA https://www.sans.org/event/cyber-threat-intelligence-summit-2018 AppSec California 2019 (OWASP) Tuesday 22nd & Wednesday 23rd January 2019 Annenberg Community Beach House, Santa Monica, USA https://2019.appseccalifornia.org/ PCI London Thursday 24th January 2019 Park Plaza Victoria Hotel, London, UK https://akjassociates.com/event/pcilondon The Future of Cyber Security Manchester Thursday 24th January 2019 Bridgewater Hall, Manchester, UK https://cybermanc...

What does Cybersecurity have in store for 2019?

Image
A guest article authored by Tom Kellermann, Chief Cybersecurity Officer, Carbon Black In every intelligence industry there’s often a central aim: predicting the future. We collect and analyse, dissect and interpret, looking for that essential nugget that will give us the edge over our adversaries by indicating what they’ll do next. While this activity goes on 24/7/365, the end of the year encourages us to go public with forecasts to help navigate the choppy waters on the horizon. This year, because all good intelligence involves collaboration, I’ve combined my thoughts with those of our threat analysts and security strategists to give some insight into the TTPs and sectors likely to be top of the list for cyberattackers in 2019. 1. Destructive attacks and nation-state activity continue to ramp up Geo-political tension remained high throughout 2018, bringing with it an associated uplift in cyber insurgency. The US trade war with China is undoubtedly a factor behind the...

Cyber Security Roundup for December 2018

Image
The final Cyber Security Roundup of 2018 concludes reports of major data breaches, serious software vulnerabilities and evolving cyber threats, so pretty much like the previous 11 months of the year. 5.3 millions users of "make your own avatar" app Boomoji had their accounts compromised, after the company reportedly didn't secure their internet connected databases properly. "Question and Answer" website Quora also announced the compromise of 100 million of its user accounts following a hack. A large data breach reported in Brazil is of interest, a massive 120 million Brazilian citizens personal records were compromised due to a poorly secured Amazon S3 bucket . This is not the first mass data breach caused by an insecure S3 bucket we've seen in 2018, the lesson to be learnt in the UK, is to never assume or take cloud security for granted, its essential practice to test and audit cloud services regularly. Amongst the amazing and intriguing space expl...

Cyber Security Predictions for 2019

Image
A guest article authored by Jim Ducharme, Vice President of Engineering and Product Management at RSA 1. Prepare for IOT, the “Identity of Things” From personal assistants, to wearables, smartphones, tablets and more, there is no shortage of connected devices. The explosion of IOT has finally reached a tipping point where the conversation of identity will start to take on a whole new meaning. The billions of new digital identities being created don’t come without risk – including new privacy and cybersecurity vulnerabilities. With businesses and consumers all in on IOT, how do we protect and securely manage the “identity” of the things?  2. Biometrics vs. the Four-Digit Pin Biometrics are under a lot of pressure these days to be the silver bullet of authentication. So how could a simple 4-digit pin, which has at most 10,000 possible combinations, give biometrics like FaceID with a 1 in 50 million entropy a run for its money? The industry will come to realize when 4-digit pin...