Posts

Showing posts with the label BEC

Top Cyber Security Challenges Post Lockdown

Image
By Sam Jones | Cyber Tec Security Not too long ago things were looking bleak for the world, still under the dark cloud of the COVID pandemic, but with vaccine rollouts now taking place worldwide, there is finally a light at the end of the tunnel. It’s important to remember, however, as we slowly transition back into some semblance of normality, that there will be new challenges to face in all facets of life, and the Cyber Security sector is no exception. The Rise in Cyber Threat While the COVID pandemic loomed, the world was simultaneously dealing with a slightly different type of pandemic - a cyber one. The number of cyber attacks on businesses rose dramatically over the course of the last year, with estimated increases as high as 90% . Organisations were forced to quickly adapt and move operations out of the office and into home environments, often bypassing best practices for a secure migration. Hackers took advantage of this confusion and chaos and focused on exploiting the vuln...

Cyber Security Roundup for February 2021

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, January 2021. Throughout January further details about the scale and sophistication of SolarWinds suspected nation-state hack came to light. A growing number of cybersecurity vendors like CrowdStrike, Fidelis, FireEye, Malwarebytes, Palo Alto Networks, Qualys and Mimecast all confirming as being targeted in the supply-chain espionage attack. The  finger of suspicion is pointing directly at Russia, with the Russian backed hacking group APT29 'Fancy Bear' cited as the culprits by many security researchers and intelligence analysts. US Secretary of State Mike Pompeo and Attorney General Bill Barr both publically stated they believe Moscow are behind the attack, as did the chairs of the Senate and House of Representatives' intelligence committees.  US government investigators and Microsoft have uncovered additional evidence, con...

Returning to the Workplace and the Ongoing Threat of Phishing Attacks

Image
Guest post by Richard Hahn, Consulting Manager, Sungard Availability Services According to the Office of National Statistics (ONS), approximately 14.2 million people (44% of the total number of working adults) have worked from home during the coronavirus pandemic. To put these figures into perspective, this number stood at around 1.7 million in 2019 , representing just 5% of the total working population. While these statistics are unsurprising, it’s clear that the paradigm of working from home every day was sudden and significant. Few businesses can claim to have anticipated such a scenario, nor to have had the business continuity planning capabilities to contend with its consequences. For example, one of the biggest cybersecurity trends to have emerged in recent weeks is a surge in phishing attacks targeting remote workers. As will be described in this article, phishing thrives on isolation, uncertainty and periods of change, which have all been common characteristics of the working ...

Five Emails you don’t want in your Inbox

Phishing attacks are the most common form of cyber attack. Why? The simplicity of email gives cybercriminals an easy route in, allowing them to reach users directly with no defensive barriers, to mislead, harvest credentials and spread malicious elements. All organisations think it won’t happen to them, but phishing isn’t a trap that only ensnares the gullible or those unacquainted with technology. Far from it. Gone are the days of poorly-worded, patently obvious attempts at scamming users out of their hard-earned cash. Some of today’s most sophisticated phishing attacks are almost indistinguishable from legitimate business communications – they’re well-written, thoroughly researched and establish a thread of communication with the victim before attempting to steal their credentials or bank balance. Email is the single biggest attack vector used by adversaries who employ a plethora of advanced social engineering techniques to achieve their goal. Andy Pearch, Head of IA Services at CORV...

Cyber Security Roundup for October 2019

Image
The UK National Cyber Security Centre (NCSC) released its annual review . The report showcases the NCSC successes with its core mission to make the UK the safest place to live and work online. The NCSC is certainly having a positive impact in helping British businesses of all sizes with their cyber defences, and with their excellent ' CyberFirst ' initiative, which encourages and supports youngsters into the cybersecurity professional. NCSC Annual Review 2019 The NCSC reported it had  "handled" 658 attacks on 900 organisations, including schools, airports and emergency services, with many attacks were "from hostile nation-states ".  The NCSC said cyberattacks from Russia, China, Iran and North Korea pose "strategic national security threats to the UK", and  also warned that "large-scale global cybercrime" was a threat to "our social fabric, our way of life and our economic prosperity", despite often being "low in sop...

Phishing Attacks remains a popular Money-Spinner for Cyber Criminals

F5 Labs’ latest Phishing and Fraud Report  reveals that phishing continues to be one of the most prevalent ways cybercriminals are breaching data and making money in 2019. Over the years, phishing has grabbed the top spot of every report on breach causes, and this trend isn’t likely to go away anytime soon. The main reason is for cybercriminals it’s easy to execute and it’s incredibly effective: there are no firewalls to bypass or finding a zero-day exploit, or encryption to decipher. The hardest part, especially with the rise in employee training, is coming up with a good trick email pitch to get people to click on. The F5 Labs Report highlights: Phishing was responsible for 21% of breaches in there’s a 50% increase in these attacks during the holiday season (October through January) when online shopping is at its most popular The top faked websites used by cybercriminals in 2019 were, in order: Facebook, Autodiscover, Apple, Chase, Office, WhatsApp, Paypal, Amazon, Microsoft, N...

2019 Verizon Data Breach Investigations Report (DBIR) Key Takeaways

Image
The 2019 Verizon Data Breach Investigations Report (DBIR ) was released today, and I was lucky enough to be handed a hot off the press physical copy while at the Global Cyber Alliance Cyber Trends 2019 event at Mansion House, London. For me, the DBIR provides the most insightful view on the evolving threat landscape, and is the most valuable annual “state of the nation” report in the security industry. Global Cyber Alliance Cyber Trends 2019 The DBIR has evolved since its initial release in 2008, when it was payment card data breach and Verizon breach investigations data focused. This year’s DBIR involved the analysis of 41,686 security incidents from 66 global data sources in addition to Verizon. The analysed findings are expertly presented over 77 pages, using simple charts supported by ‘plain English’ astute explanations, reason why then, the DBIR is one of the most quoted reports in presentations and within industry sales collateral. DBIR 2019 Key Takeaways Financial g...