Posts

Showing posts with the label NIST

IBM Quantum System One London: Why Every Organisation Should Be Preparing for Post-Quantum Cryptography (PQC)

Image
Walking past IBM's offices on York Road, just a short walk from Waterloo Station , I spotted the IBM Quantum System One on public display. Like many people, I initially wondered whether it was simply a replica or a marketing exhibit. The answer is no. This is a genuine IBM Quantum System One , housed within a sophisticated dilution refrigerator designed to keep its superconducting quantum processor at temperatures only a fraction of a degree above absolute zero. The striking gold structure that catches everyone's attention is not the quantum processor itself. The processor is tiny compared with the surrounding equipment and sits deep inside the system. Much of what you can see exists to cool, control and protect the processor from heat, vibration and electrical interference. It is a fascinating sight and well worth stopping to admire when passing through Waterloo. More Than a Display What many people do not realise is that IBM...

10 Things You Might Not Know About Cyber Essentials

Image
  I ASME  del iv ers Cyber Essentials on behalf of UK  NCSC By Sam Jones | Cyber Tec Security  and Dave Whitelegg What is  Cyber Essentials?  If you are just hearing about the Cyber Essentials scheme, read on as we unpack 10 things you might not know about Cyber Essentials. 1. UK Gov Launched Cyber Essentials in 2014 The UK Government  National Cyber Security Centre (NCSC) published its ‘10 Steps to Cyber Security in 2012' , after the UK Government agencies recognised small-medium sized UK businesses require further cybersecurity guidance and support in order to protect the British digital dependant economy.  This led to the development of five critical 'cyber essentials' technical security controls which provides a minimum level of cybersecurity protection. Assurance of the adoption of these five security controls by an organisation provides a good degree of confidence an organisation is protected against the most common cyber threats, th...

Cyber Security Roundup for October 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, September 2020. COVID-19 wasn't the only virus seriously disrupting the start of the new UK academic year, with ransomware plaguing a number of University and Colleges in September.  Newcastle University was reportedly hit by the 'DoppelPaymer' crime group , a group known for deploying malware to attack their victims, and behind leaking online documents from Elon Musk's SpaceX and Tesla companies. The northeast university reported a personal data breach to the UK Information Commissioner's Office after its stolen files were posted online, along with a Twitter threat to release further confidential student and staff data if a ransom payment was not paid. In a statement, the university said "i t will take several weeks" to address the issues, and that many IT services will not be operating during this period"...

Third Party Security Risks to Consider and Manage

Image
Guest article by Josh Lefkowitz, CEO of Flashpoint   Acceptable business risks must be managed, and none more so than those associated with external vendors who often have intimate access to infrastructure or business data. As we’ve seen with numerous breaches where attackers were able to leverage a weaknesses a contractor or service provider, third-party risk must be assessed and mitigated during the early stages of such a partnership, as well as throughout the relationship.   The following tips can help security decision makers more effectively address the risks posed by relationships with technology vendors.   Do Your Homework Conducting thorough due diligence on a prospective vendor is essential. Organisations could evaluate technical and regulatory risk through due diligence questionnaires, for example, or even on-site visits if necessary. The point is to evaluate not only a third party’s information security risk, but compliance with regulations such as...