Posts

Showing posts with the label DLP

Cyber Security Roundup for February 2021

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, January 2021. Throughout January further details about the scale and sophistication of SolarWinds suspected nation-state hack came to light. A growing number of cybersecurity vendors like CrowdStrike, Fidelis, FireEye, Malwarebytes, Palo Alto Networks, Qualys and Mimecast all confirming as being targeted in the supply-chain espionage attack. The  finger of suspicion is pointing directly at Russia, with the Russian backed hacking group APT29 'Fancy Bear' cited as the culprits by many security researchers and intelligence analysts. US Secretary of State Mike Pompeo and Attorney General Bill Barr both publically stated they believe Moscow are behind the attack, as did the chairs of the Senate and House of Representatives' intelligence committees.  US government investigators and Microsoft have uncovered additional evidence, con...

Data Loss Prevention: Artificial Intelligence vs. Human Insight

Image
The cybersecurity landscape continues to evolve as cybercriminals become ever more sophisticated, and digital security tools accelerate to mitigate the risks as much as possible. 2020 presented even more opportunities for hackers to strike, for example, using email phishing scams such as purporting to be authentic PPE providers, or from HMRC to dupe unsuspecting victims. More recently we have seen how phishers are now using the vaccine rollout to trick people into paying for fake vaccines.  Artificial Intelligence and Machine Learning have been heralded as innovative technologies to help thwart evolving exploits and are a key part of any cybersecurity arsenal. But AI is not necessarily the right tool for every job. Humans are still able to perform intricate decision making far better than machines, especially when it comes to determining what data is safe to send outside of the organisation. As such, relying on AI for this decision making can cause issues, or worse, lead to leaked ...

Check, Please! Adding up the Costs of a Financial Data Breach

Image
Guest article by Andrea Babbs, UK General Manager at VIPRE Reliance on email as a fundamental function of business communication has been in place for some time. But as remote working has become a key factor for the majority of business during 2020, it’s arguably more important than ever as a communication tool. The fact that roughly 206.4 billion emails are sent and received each day means we’re all very familiar with that dreaded feeling of sending an email with typos, with the wrong attachment, or to the wrong contact. But this can be more than just an embarrassing mistake – the ramifications could, in fact, be catastrophic.  Check Please! Within the financial services, layered cybersecurity strategy is essential to keep sensitive information secure In particular, for the financial services industry that deals with highly sensitive information including monetary transactions and financial data, the consequences of this information falling into the wrong hands could mean the los...

The Price of Loyalty, almost half of UK Office Workers are willing to sell Company's Information

Image
A new report  released by Deep Secure revealed 45% of office workers surveyed would sell their company's corporate information. Just £1,000 would be enough to tempt 25% of employees to give away company information, while 5% would give it away for free. 59% of staff admitted at some point to have taken company information from a corporate network or devices, which matches up to known industry trends.  What is the Price of Loyalty?   Common Staff Data Exfiltration Tactics Digital; email, uploading to cloud services and copying to external storage (11%) Using steganography or encryption tools to hide exfiltration (8%) Printing information (11%) Handwriting copying information (9%) Photographing information (8%) Type of Information Taken Personal Work (19%) Customer Information i.e. contact details, confidential market information, sales pipeline  (11%) Company Assets i.e. passwords to subscription services, company benefits (7%) The Mot...