Posts

Showing posts with the label Third Party Security

AI Is Moving Faster Than Security Controls

Image
AI is entering organisations faster than the security controls designed to govern it. Artificial intelligence is rapidly becoming embedded across organisations. AI assistants are now writing code, summarising documents, analysing data, and supporting operational decisions. What began as experimentation is quickly becoming operational dependency. For security teams, the challenge is not simply adopting AI. The real challenge is understanding how AI changes the way cybersecurity controls need to be validated. In many organisations, AI tools are already interacting with corporate data, internal systems, and operational workflows. Yet when security leaders ask a simple question “How do we know these AI systems are operating within our control boundaries?” …the answer is often less clear than expected. Why AI Security Controls Are Different Traditional software behaves in predictable ways. Security teams can audit ...

It’s 2026. Why are the basics still being missed?

Written by Katie Barnett, Director of Cyber Security, and Gavin Wilson, Director of Physical Security and Risk, at  Toro Solutions After spending years working with organisations on security, one thing becomes hard to ignore. When something serious happens, the root causes are sadly rarely surprising and there is often a sense of inevitability to them. Access that was never quite tidied up, controls that were written down but not really enforced, multi factor authentication that was recommended but not mandatory or decisions that made sense in the moment and were never revisited. Last year’s headlines about the Louvre brought this into focus. The Louvre Museum, the world’s most visited cultural landmark, faced heavy criticism after investigators revealed that its internal video surveillance system was protected by the password “Louvre.” This came after a daylight heist in which thieves stole French Crown Jewels valued at over $100 million. The striking thing was not how bold the th...

How the Cyber Grinch Stole Christmas: Managing Retailer Supply Chain Cyber Risk

Image
Cyber threats are always a prominent risk to businesses, especially those operating with high quantities of customer information in the retail space, with over 50% of global retailers were breached last year.  BitSight VP, Jake Olcott, has written guidance for retailers, on how to manage their supply-chain cyber risk to help prevent the 'Cyber Grinch' from not just stealing Christmas, but throughout the year, with four simple steps. Cyber risk in retail is not a new concept. Retail is one of the most targeted industries when it comes to cyber-attacks. In fact, over 50% of global retailers were breached in the last year. Given the sensitive customer data these organizations often possess — like credit card information and personally identifiable information (PII) – it’s not surprising that attackers have been capitalizing on the industry for decades. The Christmas shopping season can increase retailers’ cyber risk, with bad actors looking to take advantage of the ...

Third Party Security Risks to Consider and Manage

Image
Guest article by Josh Lefkowitz, CEO of Flashpoint   Acceptable business risks must be managed, and none more so than those associated with external vendors who often have intimate access to infrastructure or business data. As we’ve seen with numerous breaches where attackers were able to leverage a weaknesses a contractor or service provider, third-party risk must be assessed and mitigated during the early stages of such a partnership, as well as throughout the relationship.   The following tips can help security decision makers more effectively address the risks posed by relationships with technology vendors.   Do Your Homework Conducting thorough due diligence on a prospective vendor is essential. Organisations could evaluate technical and regulatory risk through due diligence questionnaires, for example, or even on-site visits if necessary. The point is to evaluate not only a third party’s information security risk, but compliance with regulations such as...

Cyber Security Roundup for July 2018

The importance of assuring the security and testing quality of third-party provided applications is more than evident when you consider an NHS reported data breach of 150,000 patient records this month. The NHS said the breach was caused by a coding error in a GP application called SystmOne, developed by UK based 'The Phoenix Partnership' (TTP). The same assurances also applies to internally developed applications, case-in-point was a publically announced flaw with Thomas Cook's booking system discovered by a Norwegian security researcher . The research used to app flaw to access the names and flights details of Thomas Cook passengers and release details on his blog . Thomas Cook said the issue has since been fixed. The Information Commissioner's Office (ICO) fined Facebook £500,000 , the maximum possible, over the Cambridge Analytica data breach scandal, which impacted some 87 million Facebook users . Fortunately for Facebook, the breach occurred before the General D...

The Ongoing Security Awareness Problem:

Image
Quite often I am sent reports, InfoGraphics and articles to post on this blog, many are too sales orientated or too off topic to consider, but the odd one is well worth sharing. So the following post and InfoGraphic has been provided by the UAB Collat School of Business , focusing on, in my view, the most riskiest and yet most neglected areas of Information Security, staff information security awareness. This is a little US focused, but the findings and advice mirrors what's seen within UK businesses. I've highlighted some very alarming statistics which shows the management 'god complex' attitude towards information security, and the business data leakage to the cloud. Employees and General Information Security Over 80%t of companies say that their biggest security threat is end user carelessness. 75% of companies also believe that employee negligence is their greatest security threat. 3% of all United States full-time employees admitted to using the same col...

SC Congress: POS Breaches, Target & PCI DSS Compliance

Image
I was privileged to speak at the SC Congress in London today. I was asked to talk about my views on Point of Sale (POS) credit card data breaches which had recently occurred stateside, the role of PCI DSS compliance with such breaches, and whether the UK could expect similar breaches despite widespread adoption of Chip & Pin (EMV), and what are the lessons to be learnt.  The following is a summary of what I said. In the United States there has been a number of high profile Point of Sale (POS) credit card data breaches, occurring at around seven shopping chains towards the end of last year. The most provident of these breaches was at Target, where hackers stole an estimated 40 million credit card details.   The hackers managed to load credit card data stealing malware onto Target’s POS systems, in each of Target’s 1800 stores. It is one of the largest and most sophisticated data breaches the payment card industry has ever seen. As Target cashiers swiped cus...

Cloud is the New Security Perimeter

The rise of cloud computing is undeniable and unstoppable, information security professionals have to accept resistance to cloud is futile. The Cisco 2014 Annual Security Report , projects cloud network traffic will grow more than threefold by 2017, with businesses executives eyeing up cloud as the silver bullet in eliminating expensive IT hardware. This cost saving elixir means cloud solutions are often quickly steamrollered in by business, leaving information security playing second fiddle. InfoSec Resistance to Cloud is Futile More and more confidential information is moving towards the cloud, and if Cisco’s projection is correct, we can expect, if not already, vast volumes of information processed and stored by business to be typically cloud based. This data moving trend is the most radical change in information security since the dawn of the commercial Internet, and presents a major shift of the security perimeter. Blindly trusting cloud service providers to deliver a level o...

Implicit Trust of The Cloud & Third Parties

Image
I find 'Implicit trust' fascinating to observe, equally within business information security and within society. 'Implicit trust" can be defined as having no doubts or reservations, being unquestioning.  For example most people implicitly trust their doctor, just because the doctor wears a white coat, exudes authority and has 'Dr' in front of their name. No one ever asks the doctor to validate their medical credentials. Perhaps we should. Implicit trust can be lost and gained, a decade ago most people would implicitly trust bankers, having someone from the banking profession witnessing legal documents and signing passport applications would be seen as a highly thought of and credible witnesses within society, not so these days, and we all know why. Police is another profession which has very interesting polarisations to observe, implicitly trusted by some and implicitlydistrusted by others. Then there is paradox of politicians, nearly everyone distrus...