Posts

Showing posts with the label Policies

AI Is Moving Faster Than Security Controls

Image
AI is entering organisations faster than the security controls designed to govern it. Artificial intelligence is rapidly becoming embedded across organisations. AI assistants are now writing code, summarising documents, analysing data, and supporting operational decisions. What began as experimentation is quickly becoming operational dependency. For security teams, the challenge is not simply adopting AI. The real challenge is understanding how AI changes the way cybersecurity controls need to be validated. In many organisations, AI tools are already interacting with corporate data, internal systems, and operational workflows. Yet when security leaders ask a simple question “How do we know these AI systems are operating within our control boundaries?” …the answer is often less clear than expected. Why AI Security Controls Are Different Traditional software behaves in predictable ways. Security teams can audit ...

Check, Please! Adding up the Costs of a Financial Data Breach

Image
Guest article by Andrea Babbs, UK General Manager at VIPRE Reliance on email as a fundamental function of business communication has been in place for some time. But as remote working has become a key factor for the majority of business during 2020, it’s arguably more important than ever as a communication tool. The fact that roughly 206.4 billion emails are sent and received each day means we’re all very familiar with that dreaded feeling of sending an email with typos, with the wrong attachment, or to the wrong contact. But this can be more than just an embarrassing mistake – the ramifications could, in fact, be catastrophic.  Check Please! Within the financial services, layered cybersecurity strategy is essential to keep sensitive information secure In particular, for the financial services industry that deals with highly sensitive information including monetary transactions and financial data, the consequences of this information falling into the wrong hands could mean the los...

How to Prevent Insider Data Breaches at your Business

Guest article by Dan Baker  of  SecureTeam Majority of security systems are installed to try and forestall any external threats to a business’ network, but what about the security threats that are inside your organisation and your network? Data breaches have the potential to expose a large amount of sensitive, private or confidential information that might be on your network. Insider threats are a significant threat to your business and are increasingly being seen as an issue that needs dealing with. SecureTeam are experts in cybersecurity and provide a variety of cybersecurity consultation solutions to a range of businesses. They have used their extensive knowledge of internal network security to write this handy guide to help businesses protect themselves from insider data breaches. Who is considered an Insider Threat? Insider threats can come from a variety of different sources and can pose a risk to your business that you might not have considered. Malicious Insi...

Third Party Security Risks to Consider and Manage

Image
Guest article by Josh Lefkowitz, CEO of Flashpoint   Acceptable business risks must be managed, and none more so than those associated with external vendors who often have intimate access to infrastructure or business data. As we’ve seen with numerous breaches where attackers were able to leverage a weaknesses a contractor or service provider, third-party risk must be assessed and mitigated during the early stages of such a partnership, as well as throughout the relationship.   The following tips can help security decision makers more effectively address the risks posed by relationships with technology vendors.   Do Your Homework Conducting thorough due diligence on a prospective vendor is essential. Organisations could evaluate technical and regulatory risk through due diligence questionnaires, for example, or even on-site visits if necessary. The point is to evaluate not only a third party’s information security risk, but compliance with regulations such as...

All I want for Christmas: A CISO's Wishlist!

Image
As Christmas fast approaches, CISOs and cyber security experts around the world are busy putting plans in place for 2019 and reflecting on what could have been done differently this year. The high-profile data breaches have been no secret - from British Airways to Dixons Carphone to Ticketmaster - and the introduction of GDPR in May 2018 sent many IT professionals into a frenzy to ensure practices and procedures were in place to become compliant with the new regulation. What the introduction of GDPR did demonstrate was that organisations should no longer focus on security strategies, which protect the organisation’s network, but instead focus on Information Assurance (IA) which protects an organisation’s data. After all - if an organisation’s data is breached, not only will it face huge fallouts of reputational damage, hits to the organisation’s bottom line and future prospecting difficulties, but it will also be held accountable to regulatory fines - up to as much as €20 million, or...

Cyber Security Incident Management, Response and Recovery Guidance

Image
Yesterday I spoke at the R3 Summit (Resilience, Response and Recovery) in London, on the topic of Cyber Security Incident Management and response. Given the Q & A and the ensuing discussion after my talk, the attendees were particularly interested in my views on incident containment ahead of recovery. Below is a summary of what I said. Step 1: Incident Management Planning and Preparation The most crucial part of incident management is the preparation, it is important to always consider cyber security incidents as a ‘When’ not an ‘If’ as you plan ahead. So here’s my ‘brain dump’ of an incident management planning strategy: A company Cyber Security Incident Management Policy It must define what the company (aka the board) consider as a cyber security incident Cyber Security Incident notification communications channel or even better a reporting application/system Upon identifying an incident who do staff notify (the incident management team) Staff awareness of how to...

Security by Staff Responsibility instead Enforced IT Controls

Image
Today IT security controls are enforced on the end user without prejudice, all for the purpose of migrating the human risk. These controls, especially endpoint security controls, are typically applied because it is best practice to do so, and not as a result of a risk assessment.  What if the application of technically enforced security controls was taken as an action of last resort? Can human responsibility be be just as affective as an enforced control? Can it be more advantageous in managing the same risk?   These our my thoughts. Lets take a English FA Premier League football match, there is a risk that spectators in the stands will invade the pitch, and impacting on the match and threatening safety  Yet spectators rarely invade football pitches at English matches, even though they aren't fenced in. A fence is an example of an enforced control meant to prevent fans from accessing the pitch.  My argument is the fans are self re...

Evolution of UK Home Banking Security - In progress?

I was featured in an article by MSN Money titled "Online Banking Security gets more Complex" http://money.uk.msn.com/news/crime/articles.aspx?cp-documentid=159017310 Nothing ground breaking, but it would appear UK banking consumers are starting to feel the pain of increased online banking security trade-offs, due to UK banks trying to save money by cutting previously acceptable losses from online account fraud. "One person, one bank: three devices But despite the evidence that new measures are more than just inconvenient, many banks are pressing ahead. Lloyds, Barclays, Cooperative Bank, RBS and Nationwide Building Society all require customers to use a card reader when amendments are made to standing orders, direct debits or when setting up payments. "This is called two-factor authentication," said independent bank security expert Dave Whitelegg. How two-factor authentication works The idea is that no fraudster can access your account, however muc...