Posts

Showing posts with the label Big Data

How to Prevent Insider Data Breaches at your Business

Guest article by Dan Baker  of  SecureTeam Majority of security systems are installed to try and forestall any external threats to a business’ network, but what about the security threats that are inside your organisation and your network? Data breaches have the potential to expose a large amount of sensitive, private or confidential information that might be on your network. Insider threats are a significant threat to your business and are increasingly being seen as an issue that needs dealing with. SecureTeam are experts in cybersecurity and provide a variety of cybersecurity consultation solutions to a range of businesses. They have used their extensive knowledge of internal network security to write this handy guide to help businesses protect themselves from insider data breaches. Who is considered an Insider Threat? Insider threats can come from a variety of different sources and can pose a risk to your business that you might not have considered. Malicious Insi...

Cyber Security Roundup 2016: The Year of the Big Data Hack

A decade ago I was walking into Boardrooms clutching newspaper clippings of half dozen data breaches which had occurred during the previous years, in a bid to warn of future threats and to persuade executives to increase their information security budgets. Those days are long gone, as most executives I encounter tend to be already worried about the cyber threat to their business, all reinforced by the mainstream media which today reports hacks most days. "Big Data" is a recent marketing buzzword used to usher in the age of businesses utilising the vasts amount of data which they process and store for increasing efficiently and profit. The problem is much of this "Big Data" is our personal data, and there are cyber criminals also seeking to profit from it. So here we are in the era of "Big Data Hacks", which sums up 2016 quite well. I have compiled a list of media headlines of data breaches in 2016 below, the volumes involved with these data theft hacks are...

Yahoo's Mind-blowing One Billion Data Theft Hack

Just over three months ago I posted about  Yahoo, The Largest Data Breach in History...so far . It was apt I added "so far" in the post title as in the early hours today, Yahoo announced an even more mind-blowing data theft hack of over One Billion Yahoo user accounts. If you are a concerned Yahoo email account holder 1. Reset your Yahoo account password, make sure your old Yahoo passwords are not used on any other of your online accounts 2. Change your Security Questions and Answers on all accounts with same Q&A as Yahoo, you might have to make up false answers only you know to ensure safety 3. Be extra vigilant, especially with signs of any access to your email account, and receiving scam phishing emails 4. See  My advice to Stay Safe from Cyber Crime Mark Crowther, Associate Director at Cyber Security Specialists Cyberis ( www.cyberis.co.uk ),   has some interesting thoughts on the latest breach at Yahoo, raising serious questions about...

Yahoo's Mindblowing One Billion User Account Data Breach: Industry Analysis

Today I received several interesting cyber security expert views on the Yahoo breach following my blog post yesterday -  Yahoo, The Largest Data Breach in History...so far ,   Broken Security Model? Paul German, VP EMEA at Certes, a specialist in cyber security and encryption, believes the Yahoo hackers were able to steal such vast amounts of account data due to a problem with the cyber security model of 'Protect, Detect and React'. Specifically the time in detecting the protection had been overcome. In Yahoo's case this time lag appears to be months and possibly even years, which allowed the hackers plenty of time to scout around the inside network undetected and extract such huge amounts of data out. To counter this lag, Paul suggests any potential hacker access to the data should be contained, I'm guessing by cranking down on data access control. Here's his full comments below. “The problem lies in the face that once hackers cross a company’s ...

Yahoo, The Biggest Cyber Data Theft in History...so far

Yahoo have just disclosed  over 500 million of its user accounts have been compromised, that's a huge number, think about it for second, that's half a billion people across the globe affected and at risk. This is largest known data breach in history to date. We know the Yahoo account data were stolen in late 2014, said the hack is said to have been orchestrated by state-sponsored actors, although there's no evidence to back this claim up. Yahoo has not disclosed how the data was hacked, or why it has taken almost two years to either discover the breach or disclosure the breach publically. A cynic might say Yahoo delayed informing its massive user base until after it's recent £3.7 billion sale to Verizon was done and dusted. However in late July 2016 hackers were found offering 200 million Yahoo accounts for sale on the dark web ( www.telegraph.co.uk/200-million-yahoo-account-details-for-sale-online ), so it is likely the 2014 data theft was discovered on the back o...

Why Brexit will be Business as Usual for Cyber Security & Data Protection in the UK

So it actually happened, they have gone and done it, its shocked the world, the UK populous have voted to leave the European Union today. Now what? Well we'll have to just get on with it and starting thinking how Brexit will impact C yber Security and Data Protection in the UK from here on in.  I didn't post a word on Brexit despite being asked numerous times during the "debating" season, or as we in the security industry call it, FUD!.  But now its done and dusted, here are my thoughts, which as always on this blog, are completely  my own. Cyber Security Defence The UK is a significant player in the international cyber threat intelligence community, although a highly secretive business, the “snooping” documents leaked by Edward Snowden demonstrated how closely GCHQ works with their American counterpart agencies. When it comes to the business of protecting the UK’s critical national infrastructure, economy and businesses from cyb...

Big Data Intelligence Driven Security at RSAC

Image
A constant theme from this year’s RSA Conference Europe, is the idea of security intelligence collaboration, namely the capture, sharing and data mining of “Big Data’, to detect and prevent security incidents and attacks, but will it ever take off? The concept of gathering and using big data is nothing new, from Google to your supermarket loyalty card; big data mining has been very successfully used commercially for at least a decade, not to mention the alleged big data mining said to be conducted by the NSA. This collaborative led intelligence approach has potential and I believe it could be effective if conceived and built smartly, however I fear the issue will be with the data sharing. Most of the existing big data models in use are covert, and organisations aren’t collaborating, so they do not share their big data analytics. This is a fairly obvious approach, as the whole idea of mining big data in their case is for commercial advantage and gain. So I imagine ...