Posts

Showing posts with the label ibm

The Role of Translation in Cyber Security and Data Privacy

Image
Article by Shiela Pulido Due to our dependence on the internet for digital transformation, most people suffer from the risks of cyberattacks. It is an even greater concern this year due to the trend of remote working and international business expansions. According to  IBM , the cost of cyber hacks in 2020 is about $3.86 million. Thus, understanding how cybersecurity and data privacy plays a priority role in organizations, especially in a multilingual setting. But, what is the relationship of languages in data privacy, and how can a reliable translation help prevent cyber-attacks? The Connection of Translation Company to Data Privacy A lot of people will ask about the clear connection between translations and cybersecurity. In data privacy, conveying important information through effective communications is important. However, with language barriers and complicated jargon in the IT industry, only IT professionals can understand their messages. It is also especially difficult for mu...

Cyber Security Roundup for May 2018

I'm sure the release of the GDPR on 25th May hasn't escaped anyone's attention. After years of warnings about the EU parliament's intended tough stance on enforcing the human right to privacy in the digital realm, a real 'game changer' of a global privacy regulation has finally landed, which impacts any organisation which touches EU citizen personal data.  The GDPR's potential hefty financial penalties for breaching its requirements is firmly on the radar of directors at large enterprises and small businesses alike, hence the massive barrage of emails we have all have received in recent weeks, on changes to company privacy statements and requesting consent, many of which I noted as not being GDPR compliant as obtaining "explicit consent" from the data subject. So there is a long way to go for many organisations before they become truly GDPR compliant state based on what I've seen so far in my mailbox. Cybercriminals have been quick to take ...

Application Development GDPR Compliance Guidance

Last week  IBM developerWorks released a three-part guidance series I have written to help  Application Developers develop GDPR compliant applications. Developing GDPR Compliant Applications Guidance Part 1: A Developer's Guide to the GDPR Part 2: Application Privacy by Design Part 3: Minimizing Application Privacy Risk The GDPR The General Data Protection Regulation (GDPR) was created by the European Commission and Council to strengthen and unify Europe's data protection law, replacing the 1995 European Data Protection Directive. Although the GDPR is a European Union (EU) regulation, it applies to any organizations outside of Europe that handle the personal data of EU citizens. This includes the development of applications that are intended to process the personal information of EU citizens. Therefore, organizations that provide web applications, mobile apps, or traditional desktop applications that can indirectly process EU citizen's personal data ...

Cyber Security Roundup for April 2018

The fallout from the F acebook privacy scandal rumbled on throughout April and culminated with the closure of the company at the centre of the scandal, Cambridge Analytica . Overview of Facebook and Cambridge Analytica Facebook's Zuckerberg faces formal summons from MPs Facebook to contact 87 million users affected by data breach Canada data firm AIQ may face legal action in UK Facebook to vet UK political ads for May 2019 local elections Facebook to exclude billions from European privacy laws Ikea was forced to shut down its freelance labour marketplace app and website 'TaskRabbit'  following a 'security incident'. Ikea advised users of TaskRabbit   to change their credentials if they had used them on other sites, suggesting a significant database compromise. TSB bosses came under fire after a botch upgraded to their online banking system , which meant the Spanished owned bank had to shut down their online banking facility, preventing usage by over 5 mi...

Scan your app to find and fix OWASP Top 10 - 2017 vulnerabilities

Following the updated release of OWASP Top Ten (2017) , I have updated my IBM developerWorks article " Scan your app to find and fix OWASP Top 10 - 2017 vulnerabilities ", which was released  on the  IBM Developer Works website  today

Cyber Security Roundup for September 2017

A massive data breach at Equifax dominated the UK media finance headlines this month, after 143 million customer records were compromised by a cyber-attack, 400,000 of which were UK customer accounts. Hackers took advantage of Equifax’s negligence in not applying security updates to servers. The data breach has already cost the CEO, CIO and CISO their jobs. In the UK Equifax faces investigations and the prospect of significant fines by both the Financial Conduct Authority and the Information Commissioner's Office over the loss of UK customer financial and personal data respectively. Hackers stole a quarter of a million Deloitte client emails , follow the breach Deloitte was criticised by security professional for not adopting two-factor authentication to protect the email data which they hosted in Microsoft’s Azure cloud service. September was an extremely busy month for security updates, with major patches releases by Microsoft , Adobe , Apache , Cisco and Apple to fix a...

Combating IoT Cyber Threats Article

My updated article on  Combating IoT cyber threats  post released on the  IBM Developer Works website  today. This article outlines the best practices for secure coding techniques and security functions that will help development teams to produce resilient IoT applications that mitigate IoT security risks.

Why a Cyber Attack can cost a Law Firm an Arm and a Leg

Image
Law firms collect, process and store vast amounts of extremely sensitive data about their clients, this when combined with a poor 'people security' culture and a general lack of digital security know-how, is a recipe that leaves legal companies highly vulnerable to cyber attacks. Given the typical large scope and sensitivity of data held by law firms, cyber attacks in the legal industry can be particularly costly affairs to recover from. Often you will read about regulators imposing considerable data breach fines on companies that have been the subject of a cyber attack. Yet the hidden cost of a data breach recovery in using crisis management services, disruption of critical business operations, contractual penalties, bringing in forensic investigators, and engaging a legal counsel, ironic I know, and the loss of client trust often exceeds the financial penalty figures plastered across the headlines. Emphasising the legal profession's vulnerability to cyber at...

Cyber Security Roundup for October 2016

Cyber security experts have long predicted that thousands of vulnerable Internet of Things (IoT) devices such as internet-connected CCTV systems would be hacked on mass and directed to perform huge DDoS attacks. That’s exactly what happened on 21 st October when 152,000 IoT devices infected with malware were remote controlled by hackers and then used to orchestrate a 1Tb DDoS attack, the largest in history. A tsunami of network traffic was directed at a company called Dyn, a major domain name registrar, and it impacted their client’s web services, including Twitter, Yammer, PayPal, Starbucks, The Guardian, PlayStation, Wix, CNN, Spotify, Github, Weebly and Reddit. Those IoT developers may want to read up on my IoT guidance on the IBM developersWorks website -  Combating IoT cyber threats  Top security best practices for IoT applications The UK National Cyber Security Centre HQ went operational, which is part of the UK government's 5 year £1.9 billion cyber defence s...

How to Protect Against Mobile Malware

Image
IBM Security recently released a white paper on the mobile malware threat, which included general guidance on managing the mobile threat and an overview of IBM’s MaaS360 Mobile Threat Management tool, I thought it was good advice and well worth sharing. Mobile is the New Playground for Thieves: How to Protect against Mobile Malware According to Arxan Technologies. 97% and 87%t of the top paid Android and iOS apps, respectively, have been hacked and posted to third-party app stores. Mobile Security Guidance (by IBM Security) Educate Employees about Application Security: Educate employees about the dangers of downloading third-party applications and the potential dangers that can result from weak device permissioning . Protect BYOD devices: Apply enterprise mobility management capabilities to enable employees to use their own devices while maintaining organisational security. Permit Employees to download from Authorised App Stores Only : Allow employees to download ap...

Top security best practices for IoT applications - Combating IoT cyber threats

I have written the following article for IBM which was published today on  IBM Development Works . https://www.ibm.com/developerworks/library/iot-security-best-practices-iot-apps/ The Internet of Things is changing the way that businesses operate, especially in the areas of warehousing, transportation, and logistics. These changes make the security of IoT devices even more crucial, given the time and money that is required if a hacker breaks through the defenses. This article outlines the best practices for securely developing robust IoT solutions.