Posts

Showing posts with the label British Airways

10 Things You Might Not Know About Cyber Essentials

Image
  I ASME  del iv ers Cyber Essentials on behalf of UK  NCSC By Sam Jones | Cyber Tec Security  and Dave Whitelegg What is  Cyber Essentials?  If you are just hearing about the Cyber Essentials scheme, read on as we unpack 10 things you might not know about Cyber Essentials. 1. UK Gov Launched Cyber Essentials in 2014 The UK Government  National Cyber Security Centre (NCSC) published its ‘10 Steps to Cyber Security in 2012' , after the UK Government agencies recognised small-medium sized UK businesses require further cybersecurity guidance and support in order to protect the British digital dependant economy.  This led to the development of five critical 'cyber essentials' technical security controls which provides a minimum level of cybersecurity protection. Assurance of the adoption of these five security controls by an organisation provides a good degree of confidence an organisation is protected against the most common cyber threats, th...

Cyber Security Roundup for November 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, October 2020. London's Hackney Borough Council has been tight-lipped about "a serious cyber-attack" which took down its IT systems, impacting its service delivery to citizens. Providing scant information about the attack, but it does have all the hallmarks of a ransomware outbreak. The council says it is working with the UK's National Cyber Security Centre (NCSC) and the Ministry of Housing to investigate and understand the impact of the incident. Ransomware attacks continue to be a major blight for UK public services, with councils to hospitals struggling to defend their IT systems against ransomware. Earlier this year Redcar and Cleveland Borough Council said it had been hit by a ransomware attack, which cost it more than £10m. It looks like the ransomware will continue to pose a major threat to the UK for some time to c...

How Much is Your Data Worth on the Dark Web?

You may not know much about the dark web, but it may know things about you. What is the Dark Web? The dark web is a part of the internet that is not visible to search engines. What makes the dark web, dark? it allows users to anonymise their identity by hiding their IP addresses. This makes those using the dark web nearly impossible to identify. Only 4% of the internet is available to the general public, which means a vast 96% of the internet is made up of the deep web. It’s important to note here, that the dark web is just a small section of the internet but it’s a powerful small sector. How much are your bank details worth? The dark web is full of stolen personal bank credentials. It’s common to see MasterCard, Visa, and American Express credentials on the dark web from a variety of different countries. Credit card data in the US, UK, Canada and Australia increased in price anywhere from 33% to 83% in the time from 2015 to 2018. The average price for a UK Visa or Mastercard ...

Network Security Observability & Visibility: Why they are not the same

Image
Guest article by Sean Everson, Chief Technology Officer at Certes Networks In today’s increasingly complex cyber landscape, it is now more important than ever for organisations to be able to analyse contextual data in order to make informed decisions regarding their network security policy. This is not possible without network observability. Organisations can now see inside the whole network architecture to explore problems as they happen. Observability is a property of the network system and should not be confused with visibility which provides limited metrics for troubleshooting. With observability, organisations can make the whole state of the network observable and those limitations no longer exist. Observability provides the contextual data operators need to analyse and gain new and deeper insights into the network. This enables teams to proactively make more informed decisions to improve network performance and to strengthen their overall security posture because context is now...

Cyber Security Roundup for July 2019

July was a month of mega data privacy fines. The UK Information Commissioners Office (ICO) announced it intended to fine British Airways £183 million for last September's data breach , where half a million BA customer personal records were compromised. The ICO also announced a £100 million fine for US-based Marriot Hotels after the Hotel chain said 339 million guest personal data records had been compromised by hackers. Those fines were dwarfed on the other side of the pond, with  Facebook agreeing to pay a US Federal Trade Commission (FTC) fine of $5 billion dollars , to put the Cambridge Analytica privacy scandal to bed . And Equifax paid $700 million to FTC to settle their 2017 data breach, which involved the loss of at least 147 million personal records . Big numbers indeed, we are seeing the big stick of the GDPR kicking in within the UK, and the FTC flexing some serious privacy rights protection punishment muscles in the US. All 'food for thought' when performing cy...

Learning from the Big Data Breaches of 2018

Image
Guest article by Cybersecurity Professionals What can we learn from the major data breaches of 2018? 2018 was a major year for cybersecurity. With the introduction of GDPR, the public’s awareness of their cyber identities has vastly increased – and the threat of vulnerability along with it. The Information Commissioner’s Office received an increased number of complaints this year and the news was filled with reports of multi-national and multi-millionaire businesses suffering dramatic breaches at the hand of cybercriminals. 2018 Data Breaches Notable breaches last year include: 5. British Airways The card details of 380,000 customers were left vulnerable after a hack affected bookings on BA’s website and app. The company insists that no customer’s card details have been used illegally but they are expected to suffer a major loss of money in revenue and fines as a result of the attack. 4. T-Mobile Almost 2 million users had their personal data, including billing information and em...

Cyber Security Roundup for November 2018

One of the largest data breaches in history was announced by Marriott Hotels at the end of November. A hack was said to have compromised up to a mind-blowing "half a Billion" hotel guests' personal information over a four year period.  See my post,  Marriott Hotels 4 Year Hack Impacts Half a Billion Guests  for the full details.  The Radisson Hotel Group also disclosed its Rewards programme suffer a data compromise . Radisson said hackers had gained access to a database holding member's name, address, email address, and in some cases, company name, phone number, and Radisson Rewards member number. Vision Direct reported a website compromise , which impacted users of their website between 3rd and 8th November, some 16,300 people were said to be at risk  A   fake Google Analytics script  was placed within its website code by hackers.  Eurostar customers were notified by email to reset their passwords following presumably successful a utom...

Cyber Security Roundup for October 2018

Aside from Brexit, Cyber Threats and Cyber Attack accusations against Russia are very much on the centre stage of UK government's international political agenda at the moment.  The government publically accused Russia's military 'GRU' intelligence service of being behind four high-profile cyber-attacks , and named 12 cyber groups it said were associated with the GRU. Foreign Secretary Jeremy Hunt said, " the GRU had waged a campaign of indiscriminate and reckless cyber strikes that served no legitimate national security interest ". UK Police firmly believe the two men who carried out the Salisbury poisoning in March 2018 worked for the GRU. What is Russia's GRU Intelligence Agency? The risks of cyber-conflict with Russia Russia accused of net hack attacks Russian spy: What happened to the Skripals? The UK National Cyber Security Centre said it had assessed "with high confidence" that the GRU was "almost certainly responsible...