Posts

Showing posts with the label application security

How Businesses Can Utilise Penetration Testing

Image
Understand your security vulnerabilities Article by  Beau Peters The basic approaches like  phishing simulations are good, but they tend to have limited reach. This is why more agile methods, penetration testing among them, have been getting increasing attention. In essence, this sees experts with a background in ethical hacking utilizing the techniques of cybercriminals to breach a business’ systems. This also receives a certain amount of hesitancy — business owners are often unsure about the idea of letting somebody hack their systems in the name of cybersecurity. As always, there is more to this issue. So, let’s explore what penetration testing is, why businesses should engage with it and how they can do so to get the most impact. What are the Benefits? Penetration testing requires a significant amount of trust. Therefore, it’s important to look at what the payoffs of this approach are as opposed to ostensibly safer techniques. Some of the key benefits include: Ascertai...

Security Threats Facing Modern Mobile Apps

Image
We use mobile apps every day from a number of different developers, but do we ever stop to think about how much thought and effort went into the security of these apps? It is believed that 1 out of every 36 mobile devices has been compromised by a mobile app security breach. And with more than 5 billion mobile devices globally, you do the math. The news that a consumer-facing application or business has experienced a security breach is a story that breaks far too often. As of late, video conferencing apps like Zoom and Houseparty have been the centre of attention in the news cycle. As apps continue to integrate into the everyday life of our users, we cannot wait for a breach to start considering the efficacy of our security measures. When users shop online, update their fitness training log, review a financial statement, or connect with a colleague over video, we are wielding their personal data and must do so responsibly. Let’s cover some of the ways hackers access sensitive informa...

How Safe and Secure are Wearables?

Image
The ‘wearable technology’ market has been exponentially growing in recent years and is expected to exceed 830 million devices by 2020 . One of the key drivers pushing this rapid expansion are fitness trackers, namely wristband tech and smartwatch apps which monitors our daily activity and health. But as we integrate wearables devices seamlessly into our everyday lives, what are the privacy and security risks they pose? How should wearable manufacturers and app developers be protecting consumers? Insurance company Vitality offers customers a heavily discounted Apple Watch  to customers in return for their fitness routines and health data, the more activity you do each month, the greater your reward through a monthly discount. While t his exchange of information for rewards provides a great incentive for consumers to improve their health, the personal data consumers are sharing in return has a tangible value for the insurance company. However, providing an insurance compan...

Cyber Security Roundup for October 2018

Aside from Brexit, Cyber Threats and Cyber Attack accusations against Russia are very much on the centre stage of UK government's international political agenda at the moment.  The government publically accused Russia's military 'GRU' intelligence service of being behind four high-profile cyber-attacks , and named 12 cyber groups it said were associated with the GRU. Foreign Secretary Jeremy Hunt said, " the GRU had waged a campaign of indiscriminate and reckless cyber strikes that served no legitimate national security interest ". UK Police firmly believe the two men who carried out the Salisbury poisoning in March 2018 worked for the GRU. What is Russia's GRU Intelligence Agency? The risks of cyber-conflict with Russia Russia accused of net hack attacks Russian spy: What happened to the Skripals? The UK National Cyber Security Centre said it had assessed "with high confidence" that the GRU was "almost certainly responsible...

Cyber Security Roundup for September 2018

September 2018 started with a data breach bang, with  British Airways disclosing a significant hack and data loss . 380,000 of the airlines' website and mobile app customers had their debit and credit card details lifted via a maliciously injected script.  The breach even caused BA owners, IAG, to drop in value 4%. And to compound matters, there were several claims made that  the BA website wasn't PCI DSS compliant , implying if they were PCI DSS compliant, their customer's personal and payment card information would still be safe.  For further details about this breach see my blog posts;  British Airways Customer Data Stolen in Website and Mobile App Hack  and  British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected . Facebook continues to make all the wrong kind of privacy headlines after a massive user data breach was confirmed by the social media giant at the end of the month. Facebook said at ...

Application Development GDPR Compliance Guidance

Last week  IBM developerWorks released a three-part guidance series I have written to help  Application Developers develop GDPR compliant applications. Developing GDPR Compliant Applications Guidance Part 1: A Developer's Guide to the GDPR Part 2: Application Privacy by Design Part 3: Minimizing Application Privacy Risk The GDPR The General Data Protection Regulation (GDPR) was created by the European Commission and Council to strengthen and unify Europe's data protection law, replacing the 1995 European Data Protection Directive. Although the GDPR is a European Union (EU) regulation, it applies to any organizations outside of Europe that handle the personal data of EU citizens. This includes the development of applications that are intended to process the personal information of EU citizens. Therefore, organizations that provide web applications, mobile apps, or traditional desktop applications that can indirectly process EU citizen's personal data ...

Scan your app to find and fix OWASP Top 10 - 2017 vulnerabilities

Following the updated release of OWASP Top Ten (2017) , I have updated my IBM developerWorks article " Scan your app to find and fix OWASP Top 10 - 2017 vulnerabilities ", which was released  on the  IBM Developer Works website  today

Science of CyberSecurity: Reasons Behind Most Security Breaches

As part of a profile interview for  Science of Cybersecurity  I was asked five questions on cyber security last week, here's question 2 of 5. Q. What – in your estimation – are the reasons behind the many computer security breaches/failures that we see today? Simply put insecure IT systems and people are behind every breach, insecure IT systems are arguably caused by people as well, whether it is poor system management, lack of security design, insecure coding techniques, and or inadequate support, it all boils down to someone not doing security right. For many years seasoned security experts have advocated that people are the weakest link in security, even hackers say ‘amateurs hack systems, professionals hack people’, yet many organisations still focus most of their resources and funds heavily on securing IT systems over providing staff with sustained security awareness. Maybe this is a result of an IT security sales industry over hyping the effectiveness...

A developer's guide to complying with PCI DSS 3.2 Requirement 6 Article

My updated article on " A developer's guide to complying with PCI DSS 3.2 Requirement 6 " was released on the  IBM Developer Works website  today. This article provides guidance on  PCI DSS requirement 6, which breaks down into 28 further individual requirements and sits squarely with software developers who are involved in the development of applications that process, store, and transmit cardholder data.

Combating IoT Cyber Threats Article

My updated article on  Combating IoT cyber threats  post released on the  IBM Developer Works website  today. This article outlines the best practices for secure coding techniques and security functions that will help development teams to produce resilient IoT applications that mitigate IoT security risks.

Cyber Security Roundup for October 2016

Cyber security experts have long predicted that thousands of vulnerable Internet of Things (IoT) devices such as internet-connected CCTV systems would be hacked on mass and directed to perform huge DDoS attacks. That’s exactly what happened on 21 st October when 152,000 IoT devices infected with malware were remote controlled by hackers and then used to orchestrate a 1Tb DDoS attack, the largest in history. A tsunami of network traffic was directed at a company called Dyn, a major domain name registrar, and it impacted their client’s web services, including Twitter, Yammer, PayPal, Starbucks, The Guardian, PlayStation, Wix, CNN, Spotify, Github, Weebly and Reddit. Those IoT developers may want to read up on my IoT guidance on the IBM developersWorks website -  Combating IoT cyber threats  Top security best practices for IoT applications The UK National Cyber Security Centre HQ went operational, which is part of the UK government's 5 year £1.9 billion cyber defence s...

How to Protect Against Mobile Malware

Image
IBM Security recently released a white paper on the mobile malware threat, which included general guidance on managing the mobile threat and an overview of IBM’s MaaS360 Mobile Threat Management tool, I thought it was good advice and well worth sharing. Mobile is the New Playground for Thieves: How to Protect against Mobile Malware According to Arxan Technologies. 97% and 87%t of the top paid Android and iOS apps, respectively, have been hacked and posted to third-party app stores. Mobile Security Guidance (by IBM Security) Educate Employees about Application Security: Educate employees about the dangers of downloading third-party applications and the potential dangers that can result from weak device permissioning . Protect BYOD devices: Apply enterprise mobility management capabilities to enable employees to use their own devices while maintaining organisational security. Permit Employees to download from Authorised App Stores Only : Allow employees to download ap...