Posts

Showing posts with the label cyber

When insider risk is a wellbeing issue, not just a disciplinary one

Image
Written by Katie Barnett, Director of Cyber Security at Toro Solutions Insider risk is still often framed around intent, with the focus placed on malicious employees, disgruntled contractors, or deliberate misuse of access for personal gain. Those cases exist and they matter, but they are rarely where risk first begins, and they do not reflect how most insider-related incidents actually develop. In reality, many cases take shape slowly and quietly. They are shaped by pressure, fatigue, disengagement, coercion, manipulation or personal strain rather than hostility. The behaviour that later causes harm is often preceded by long periods of stress, isolation, being influenced or unresolved workplace issues. By the time someone is formally labelled an insider threat,the opportunity for early, proportionate support has usually passed, and the organisation is left with far fewer options. This is why treating insider risk purely as a disciplinary or compliance issue consistently falls short. ...

Cybersecurity Is Not A One-Stop-Shop

Image
Cybersecurity is not a One-Stop-Shop Boris Johnson announced the Government’s roadmap to lift Coronavirus restrictions for both businesses and the general public earlier in February, and since then, this has provided a glimmer of hope for many across the country. However, since the start of the pandemic, the way business is conducted has changed permanently, with many workforces wanting to continue to work remotely as lockdowns and restrictions ease over time. So, as companies relax and rules are eased, life is expected to return to a form of ‘new normal.’ But, the issues around cybersecurity are here to stay, and the gas pedal must not be eased – especially with the increased risks associated with continued remote working. If anything, security should be more reinforced now than ever before to ensure all aspects of a business are secure. But this isn’t the case. Steve Law, CTO, Giacom and Kelvin Murray, Threat Researcher, Webroot, detail the importance of embedding a trilogy securi...

The Role of Translation in Cyber Security and Data Privacy

Image
Article by Shiela Pulido Due to our dependence on the internet for digital transformation, most people suffer from the risks of cyberattacks. It is an even greater concern this year due to the trend of remote working and international business expansions. According to  IBM , the cost of cyber hacks in 2020 is about $3.86 million. Thus, understanding how cybersecurity and data privacy plays a priority role in organizations, especially in a multilingual setting. But, what is the relationship of languages in data privacy, and how can a reliable translation help prevent cyber-attacks? The Connection of Translation Company to Data Privacy A lot of people will ask about the clear connection between translations and cybersecurity. In data privacy, conveying important information through effective communications is important. However, with language barriers and complicated jargon in the IT industry, only IT professionals can understand their messages. It is also especially difficult for mu...

Fact vs. Fiction: Film Industry's Portrayal of Cybersecurity

Image
Article by Beau Peters The movie industry is infamous for its loose depictions of hacking and cybersecurity. Hollywood often gets a lot wrong about hacking and digital protections, but what does it get right? The power of film in influencing the future of technology and the experts that create it is immense. Because of this, it is important to assess what the facts are versus movie fiction.  Here, we’ll explore the film industry’s portrayal of cybersecurity. Cybersecurity in Movies From WarGames to Blackhat, hacking and cybersecurity movies have glamorized the world of digital safety and the compromising of said safety. However, each Hollywood outing does so with varying levels of realism, typically embracing excitement over reality.  In the 1983 WarGames movie, a young hacker almost triggers World War 3 These portrayals have led to common tropes and views of the cybersecurity industry in their attempts to prevent and combat hacking attempts. Among these tropes are some of th...

Is AI the Answer to never-ending Cybersecurity Problems?

Image
Paul German, CEO, Certes Networks , talks about the impact and the benefits of Artificial Intelligence(AI) driven cybersecurity. And how AI adoption is helping organisations to stay ahead in the never-ending game that is cybersecurity. Artificial Intelligence (AI) isn’t going anywhere anytime soon. With 20% of the C-suite already using machine learning and 41% of consumers believing that AI will improve their lives , wide scale adoption is imminent across every industry - and cybersecurity is no exception. A lot has changed in the cyber landscape over the past few years and AI is being pushed to the forefront of conversations. It’s becoming more than a buzzword and delivering true business value. Its ability to aid the cybersecurity industry is increasingly being debated; some argue it has the potential to revolutionise cybersecurity, whilst others insist that the drawbacks outweigh the benefits. With several issues facing the current cybersecurity landscape such as a disappearing I...

Cyber Security Conferences to Attend in 2019

A list of Cyber and Information Security conferences to consider attending in 2019. Conference are not only great places to learn about the evolving cyber threat landscape and proven security good practices, but to network with industry leading security professionals and likeminded enthusiasts, to share ideas, expand your own knowledge, and even to make good friends. JANUARY 2019 SANS Cyber Threat Intelligence Summit Monday 21st & Tuesday 22nd January 2019 Renaissance Arlington Capital View Hotel, VA, USA https://www.sans.org/event/cyber-threat-intelligence-summit-2018 AppSec California 2019 (OWASP) Tuesday 22nd & Wednesday 23rd January 2019 Annenberg Community Beach House, Santa Monica, USA https://2019.appseccalifornia.org/ PCI London Thursday 24th January 2019 Park Plaza Victoria Hotel, London, UK https://akjassociates.com/event/pcilondon The Future of Cyber Security Manchester Thursday 24th January 2019 Bridgewater Hall, Manchester, UK https://cybermanc...

The IT Security Expert Blog is 10 Years Old

Image
Ten years ago today I published my first ever blog post about a BBC news story titled " Home Network Security Scrutinised ". A decade ago it was rare to see an IT security or hacking story make the news media, and back then the term 'Cyber Security' would conjure images of Dr.Who's metallically clad arch-villains in most people's minds in the UK. The Face of Cyber Security in 2007 Fast forward ten years, IT security has long been rebadged as 'Cyber Security' and on Friday the top ten news stories  on Sky News were all Cyber Security related, albeit about the same global attack , but how times have changed. 'I found the following article on the BBC news website, which happens to be exactly what I had been talking about in my presentations this week. None of the findings is surprising to me, but I find many people I talk with are in the dark about digital security. Anyway, I thought I'd write this post about it and start my own blog...

Stay Safe from Cyber Crime - Top Ten Tips InfoGraphic

Image
Given I am regularly asked to explain cyber attacks and then advise on how to protect against them, particularly to home users of late, I thought I would try my hand at creating a simple InfoGraphic to help. It was a challenge to create due to the limitation to the amount of space for text, which means you can't cover everything and you can't go into much detail. However concise messaging is kind of the point of infographics, especially when using them as awareness tools.  This InfoGraphic is squarely aimed at the average "home user", it highlights what the bad guys are after, their most popular and most successful attack methods, and then provides 10 tips to help avoid and detect home user cyber attacks, simples. If this InfoGraphic proves popular I'll create some more, starting with one covering home IoT Security advice, another subject I'm regularly asked about at the moment. Download full version here

Why a Cyber Attack can cost a Law Firm an Arm and a Leg

Image
Law firms collect, process and store vast amounts of extremely sensitive data about their clients, this when combined with a poor 'people security' culture and a general lack of digital security know-how, is a recipe that leaves legal companies highly vulnerable to cyber attacks. Given the typical large scope and sensitivity of data held by law firms, cyber attacks in the legal industry can be particularly costly affairs to recover from. Often you will read about regulators imposing considerable data breach fines on companies that have been the subject of a cyber attack. Yet the hidden cost of a data breach recovery in using crisis management services, disruption of critical business operations, contractual penalties, bringing in forensic investigators, and engaging a legal counsel, ironic I know, and the loss of client trust often exceeds the financial penalty figures plastered across the headlines. Emphasising the legal profession's vulnerability to cyber at...

Cyber Security Roundup for September 2016

The theft of over half a billion Yahoo user accounts by hackers has dominated the news headlines in the last couple of weeks. Since announcing the largest hack in history, Yahoo has come in for heavy criticism, given it took two years for Yahoo to notice the massive data theft, talk of lacklustre security behind the scenes at the company, and doubts over Yahoo’s claims the cyber attack was state-sponsored. Lawyers representing users, the US Senate and the UK ICO have all lined up to take pop-shots at Yahoo and are threatening action.    I posted known Yahoo hack information and advice , and Yahoo hack industry analysis Interesting example of Hacktivism after a Russian group called "Fancy Bears" hacked and released the World Anti-Doping Agency medical records of prominent British and American Olympic athletes. The motivate appears to be a revenge protest aimed at causing embarrassment to medal winning Western athletes  following...

Cyber Security Roundup for June 2016

Before Brexit ( Why Brexit will be Business as Usual for Cyber Security & Data Protection in the UK ) dominated the UK parliament agenda, a Commons Committee lambasted the Information Commissioner’s Office for not acting tough enough with TalkTalk in regards to their data breach earlier this year.  The UK parliament also passed the controversial ‘Snoopers Charter’ bill this month. For the fourth month in a row Adobe and Microsoft released critical patches to fix zero day exploited flash vulnerabilities.  A spate of tech company chiefs had their twitter accounts hacked, including Facebook’s Mark Zuckerberg, who was also spotted on an Instagram picture with tape covering his MacBook's webcam. The Ransomware epidemic continues to make headlines and cause issues across all industries, this month saw concern over a new strain of ransomware called RAA, which executes only using JavaScript.  News Microsoft Office 365 hit with Massive Cerber Ransomware Attack...