Posts

Showing posts from November, 2019

Tips for Brits to stay Secure on Black Friday

As Brits plan to go to extreme lengths to grab a bargain this Black Friday but are leaving themselves exposed to cyber-criminals? Brits are gearing up to grab a bargain this Black Friday and Cyber Monday, with 17% already considering pulling a sickie. Over half of UK online shoppers will use a mobile device to shop for deals, but more than one in five (21%) will shop on unsecured smartphones or using open wifi networks (19%). F-Secure is warning people to install security software on any devices they’re shopping online with as last year the average count of spam increased by 45% during Cyber Monday. Brits are one and a half times more likely to be affected by financial fraud than people in other countries with 26% of people reporting they or someone in their family has been affected by credit card fraud, compared to an average 17% in other countries. New research highlights the lengths Brits will go to grab a bargain online, even though they may be leaving themselves vulnerable t...

The Challenges of UK Cyber Security Standards

Article by Matt Cable, VP Solutions Architect and MD Europe, Certes Networks Public sector organisations in the UK are in the midst of changing cyber security regulations. In mid-2018, the Government, in collaboration the NCSC, published a minimum set of cyber security standards. These standards are now mandated, along with a focus on continually “raising the bar”. The standards set minimum requirements for organisations to protect sensitive information and key operational services, which – given the way in which these services are increasingly dispersed – is driving significant changes in public sector network architecture and security. In addition to setting today’s ‘ minimum’ standards, however, the guidance also sets a target date of 2023 by which public sector organisations will be expected to have adopted a ‘gold-standard ’ cyber security profile. Matt Cable, VP Solutions Architect and MD Europe, Certes Networks, therefore outlines the essential considerations that will help orga...

How Much is Your Data Worth on the Dark Web?

You may not know much about the dark web, but it may know things about you. What is the Dark Web? The dark web is a part of the internet that is not visible to search engines. What makes the dark web, dark? it allows users to anonymise their identity by hiding their IP addresses. This makes those using the dark web nearly impossible to identify. Only 4% of the internet is available to the general public, which means a vast 96% of the internet is made up of the deep web. It’s important to note here, that the dark web is just a small section of the internet but it’s a powerful small sector. How much are your bank details worth? The dark web is full of stolen personal bank credentials. It’s common to see MasterCard, Visa, and American Express credentials on the dark web from a variety of different countries. Credit card data in the US, UK, Canada and Australia increased in price anywhere from 33% to 83% in the time from 2015 to 2018. The average price for a UK Visa or Mastercard ...

GTP Security: Securing 5G Networks with a GTP Firewall

Anthony Webb, EMEA Vice President at A10 Networks It is often written that 5G will usher in the Fourth Industrial Revolution and change the economy. The speeds and capacity that 5G network promises to bring has the potential to be an indispensable technology. Verizon estimated that by 2035, 5G “will enable £10.5 trillion of global economic output and support 22 million jobs worldwide . Therefore, 5G is not only important because it has the potential to support millions of devices at ultrafast speeds, but also because it has the potential to transform the lives of people around the world. But with this new opportunity also comes higher security risks as cyberattacks grow in sophistication and volume and use lightly protected mobile and IoT devices in their botnets or targeted attacks. GTP today Since the early days of 3G or 2.5G, GPRS Tunnelling Protocol (GTP) has been used to carry traffic and signalling through mobile networks and has continued to do so in 4G/LTE and recent 5G non-s...

A UK Small Business is hacked every 19 seconds

Image
Small UK businesses bear the brunt of cyberattacks according to the latest industry reports. SecureTeam have crunched the numbers and put together an InfoGraphic which depicts how cybercrime is impacting UK small business. They have concluded UK small businesses are targeted with 65,000 cyberattacks per day, with one small business hacked every 19 seconds! As expected, email is by far the most commonly used attack vector, and the security posture of small businesses is not sufficiently robust enough to withstand cyberattacks, knowledge which the cybercriminals clearly understand.

Combating the Accidental Insider Data Leakage Threat

Article by Andrea Babbs, UK General Manager, VIPRE SafeSend Cybercrime has rapidly become the world’s fastest growing form of criminal activity, and is showing no sign of slowing down with the number of attacks on businesses rising by more than 50% in the last year alone. While most corporates have made significant efforts to invest in cybersecurity defences to protect their organisations from the outside threat of cybercrime, few have addressed the risk of breaches that stem from the inside in the same way. Insider threats can come from accidental error, such as an employee mistakenly sending a sensitive document to the wrong contact, or from negligence such as an employee downloading unauthorised software that results in a virus spreading through the company’s systems. We’re all guilty of accidentally hitting send on an email to the wrong person, or attaching the wrong document; but current levels of complacency around email security culture are becoming an ever greater threat. F...

Broken Security? Most Business Leaders aren't confident about their Cybersecurity

Cybersecurity is a critical battleground for UK businesses today, as the digital footprints of individuals and enterprises continue to grow. However, according to a new study commissioned by VMware in partnership with Forbes Insights , only a quarter (25%) of business leaders across EMEA are confident in their current cybersecurity practices, with UK spending without adequate assessment of the needs of organisations now commonplace. VMware research reveals British businesses battle sophisticated security threats with old tools and misplaced spend Key findings of the Study 78% of UK business and IT security leaders believe the cybersecurity solutions their organisation is working with are outdated (despite 40% having acquired new tools over the past 12 months to address potential threats) 74% reveal plans to invest even more in detecting and identifying attacks in the next three years, despite having a multitude of products already installed – a quarter (26%) of business...

For Caught in the Crossfire of Cyberwarfare

Authored by Dr Sandra Bell, Head of Resilience Consulting EMEA, Sungard Availability Services   PDF edition of this article The 2019 National Cyber Security Centre’s (NCSC) Annual Review does not shy away from naming the four key protagonists when it comes to state-based cyber threats against our country. The review sites China, Russia, North Korea and Iran as being actively engaged in cyber operations against our Critical National Infrastructure and other sectors of society. That being said, the main cyber threat to businesses and individual citizens remains organised crime. But with the capability of organised crime matching some state-based activity and the sharing (if not direct support) of state-based techniques with cyber criminals, how are we expected to defend ourselves against such sophisticated cyberattack means? The answer offered by Ciaran Martin, CEO of the NCSC, in his Forward to the 2019 Review only scratches the surface of the cultural change we need to embr...

Labour Party DDoS Cyber Attacks

Image
It was just a matter of time before cyberattacks were catapulted into the forefront of the UK 2019 General Election campaign, with two cyber-attacks on the Labour Party in the last two days. It was reported the Labour Party was targeted by two separate Distributed Denial of Service (DDoS) attacks. Labour have not publically disclosed which of its digital systems were targetted by the DDoS attacks, but it is understood cyber attacks impacted the speed of their election and campaigning tools on Monday. A Labour spokeswoman said: “We have ongoing security processes in place to protect our platforms, so users may be experiencing some differences. We are dealing with this quickly and efficiently.” Following reports of a second cyber-attack, a Labour Party spokesperson said: "We have ongoing security processes in place to protect our platforms, so users may be experiencing some differences. We are dealing with this quickly and efficiently." The National Cyber Security Cen...

Cyber Security Businesses: Solving Challenges Through New Technologies

From everyday transactions to transport planning, as our world becomes more dependent on technology, cybersecurity risks are becoming more common, and more dangerous.  Luckily, there’s a range of cybersecurity businesses and start-ups attempting to solve this issue through innovative new technologies. We look at some recent projects and partnering opportunities tackling cybersecurity challenges.  Antivirus Software From Japan Established in 2007, a Japanese company has developed security software to detect unknown threats. They have developed a heuristic application consisting of five engines to detect malware and protect users. These engines include ; Static analyses Sandbox runs programs on a virtual environment Dynamic analyses (monitors the behaviour of currently running programs) Machine learnings Vulnerability attack protection The advantage of this technology is that it does not depend on pattern files. So far, the programs have detected several major threa...

Five Emails you don’t want in your Inbox

Phishing attacks are the most common form of cyber attack. Why? The simplicity of email gives cybercriminals an easy route in, allowing them to reach users directly with no defensive barriers, to mislead, harvest credentials and spread malicious elements. All organisations think it won’t happen to them, but phishing isn’t a trap that only ensnares the gullible or those unacquainted with technology. Far from it. Gone are the days of poorly-worded, patently obvious attempts at scamming users out of their hard-earned cash. Some of today’s most sophisticated phishing attacks are almost indistinguishable from legitimate business communications – they’re well-written, thoroughly researched and establish a thread of communication with the victim before attempting to steal their credentials or bank balance. Email is the single biggest attack vector used by adversaries who employ a plethora of advanced social engineering techniques to achieve their goal. Andy Pearch, Head of IA Services at CORV...

Why Cybersecurity Breach Survivors are Valued Assets

Guest article By Ewen O’Brien, VP of Enterprise, EMEA at BitSight No one wants to talk about their failures, especially in the cybersecurity realm where the stakes are high. But  new insight from Symantec and Goldsmiths, University of London, finds that security professionals who have lived through a cybersecurity attack or breach could be the answer to protecting your organisation against future threats. The report reveals that just over half of the 3,000 CISOs surveyed believe that learning from failure is incredibly valuable and a vital part of improving corporate cybersecurity postures. Indeed, these professionals may very well be your company’s best line of defence in the face of a potential cyberattack. The Value of “Cybersecurity Breach Survivors” Security professionals who have lived through an avoidable breach possess a unique mindset. They are less likely to experience burnout, are less indifferent to their work, less likely to think about quitting their job, feel les...

Researchers find security flaws in ‘Amazon’s Ring Video Doorbell Pro’ IoT device

Image
Bitdefender researchers have discovered an issue in ‘ Amazon’s Ring Video Doorbell Pro ’ IoT device that allows an attacker to intercept the owner’s Wi-Fi network credentials. During the configuration stage, the mobile app sends the Wi-Fi network credentials in plaintext to the Ring Video Doorbell Pro. This then allows the hacker to sniff the packets and find out the sensitive data it needs to connect to the user’s WiFi. Once in possession of a user’s WiFi password, an attacker has full access to the network. And it’s no secret that an internal network can be very lax. In fact, many devices such as Smart TVs allow interaction without any authentication whatsoever – even if a device was under attack, there is no trace left and users will have no idea they were even a victim. Examples of possible things an attacker might do without your knowledge: Interact  with all devices within the household network  Intercept network traffic and run ‘man-in-the-middle’ attacks ...

Eliminating the Social Media Cyber Security Blind Spot

Guest article by Anthony Perridge, VP International, ThreatQuotient More than three billion people around the world use social media each month, with 90% of those users accessing their chosen platforms via mobile devices. While, historically, financial services (FinServ) institutions discouraged the use of social media, it has become a channel that can no longer be ignored. FinServ institutions are widely recognised as leaders in cybersecurity, employing layers of defence and highly skilled security experts to protect their organisations. But as the attack surface expands with the growing use of social media and external digital platforms, many FinServ security teams are blind to a new wave of digital threats outside the firewall. Social media is a morass of information flooding the Internet with billions of posts per day that comprise text, images, hashtags and different types of syntax. It is as broad as it is deep and requires an equally broad and deep combination of defences to id...

Microsoft Ignite Cyber Security Takeaways

Image
Microsoft's annual flagship 'Ignite' conference  is underway, amongst the hundreds of announcements and content  covered, there are a number of interesting security-related updates and new releases by Microsoft, highlighted below. Microsoft Ignite Microsoft Defender Advanced Threat Protection (ATP) https://www.microsoft.com/security/blog/2019/11/04/further-enhancing-security-microsoft Microsoft is extending their endpoint detection and response capability in Microsoft Defender ATP to include MacOS, now in preview. Microsoft is planning to add support for Linux servers. Application Guard for Office https://www.microsoft.com/security/blog/2019/11/04/further-enhancing-security-microsoft Now available in preview, Application Guard for Office provides hardware-level and container-based protection against potentially malicious Word, Excel, and PowerPoint files. It utilises Microsoft Defender ATP to establish whether a document is either malicious o...

Cyber Security Roundup for October 2019

Image
The UK National Cyber Security Centre (NCSC) released its annual review . The report showcases the NCSC successes with its core mission to make the UK the safest place to live and work online. The NCSC is certainly having a positive impact in helping British businesses of all sizes with their cyber defences, and with their excellent ' CyberFirst ' initiative, which encourages and supports youngsters into the cybersecurity professional. NCSC Annual Review 2019 The NCSC reported it had  "handled" 658 attacks on 900 organisations, including schools, airports and emergency services, with many attacks were "from hostile nation-states ".  The NCSC said cyberattacks from Russia, China, Iran and North Korea pose "strategic national security threats to the UK", and  also warned that "large-scale global cybercrime" was a threat to "our social fabric, our way of life and our economic prosperity", despite often being "low in sop...