Posts

Showing posts with the label nhs

Should Doctors Receive a Cybersecurity Education?

Image
Article by  Beau Peters It is no secret that medical professionals of all levels need to maintain a vast amount of knowledge in their brains at all times. After all, having experience and education is crucial to saving lives and helping patients. But should an understanding of cybersecurity be added to their repertoire? If they want to give the best overall care inside and outside of the clinic, then the answer is yes. As technology has evolved and we have moved to a more remote work environment, it is essential that cybersecurity becomes part of training for everyone in a medical organization, from human resources to the doctors themselves. By knowing the threats and understanding the solutions, doctors can protect their patients and provide advice to keep them safe even after they leave the office. Below are some of the many reasons why doctors should receive a cybersecurity education. Following Privacy Guidelines These days, technology is being used in the medical community mor...

Book Review: Crime Dot Com, From Viruses to Vote Rigging, How Hacking Went Global

Image
I had the great delight of reading Geoff White’s new book, “ Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global ”, I thoroughly recommend it. The book is superbly researched and written, the author’s storytelling investigative journalist style not only lifts the lid on the murky underground world of cybercrime but shines a light on the ingenuity, persistence and ever-increasing global scale of sophisticated cybercriminal enterprises. Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global In Crime Dot Com Geoff takes the reader on a global historic tour of the shadowy cybercriminal underworld, from the humble beginnings with a rare interview with the elusive creator of the ‘Love Bug’ email worm, which caused havoc and panic back in 2000, right up to the modern-day alarming phenomenal of elections hacking by nation-state actors. The book tells the tales of the most notorious hacks in recent history, explaining how they were successfully planned a...

WhatsApp, Microsoft and Intel Chip Vulnerabilities

Quickly applying software updates (patching) to mitigate security vulnerabilities is a cornerstone of both a home and business security strategy. So it was interesting to see how the mainstream news media reported the disclosure of three separate ‘major’ security vulnerabilities this week, within WhatsApp, Microsoft Windows and Intel Processors. WhatsApp The WhatsApp security flaw by far received the most the attention of the media and was very much the leading frontpage news story for a day. The WhatsApp vulnerability ( CVE-2019-3568 ) impacts both iPhone and Android versions of the mobile messaging app, allowing an attacker to install surveillance software, namely,  spyware called Pegasus , which access can the smartphone's call logs, text messages, and can covertly enable and record the camera and microphone. From a technical perspective, the vulnerability ( CVE-2019-3568 ) can be exploited with a buffer overflow attack against WhatsApp's VOIP stack, this makes remote cod...

Cyber Security Roundup for May 2018

I'm sure the release of the GDPR on 25th May hasn't escaped anyone's attention. After years of warnings about the EU parliament's intended tough stance on enforcing the human right to privacy in the digital realm, a real 'game changer' of a global privacy regulation has finally landed, which impacts any organisation which touches EU citizen personal data.  The GDPR's potential hefty financial penalties for breaching its requirements is firmly on the radar of directors at large enterprises and small businesses alike, hence the massive barrage of emails we have all have received in recent weeks, on changes to company privacy statements and requesting consent, many of which I noted as not being GDPR compliant as obtaining "explicit consent" from the data subject. So there is a long way to go for many organisations before they become truly GDPR compliant state based on what I've seen so far in my mailbox. Cybercriminals have been quick to take ...

Cyber Security Roundup for October 2017

State-orchestrated cyber attacks have dominated the media headlines in October, with rogue state North Korea and its alleged 6,800 strong cyber force blamed for several cyber attacks. International intelligence scholars believe the North Korean leadership are using cyber warfare to up the political ante with their ongoing dispute with the United States. The North Koreans, as well as terrible security practices, were directly blamed by the UK National Audit Office for the recent  NHS WannaCry attack  ( despite North Korea denying it ). North Korea was also reported to be implicated in the  stealing US War Plans from South Korea , and for a spear phishing campaign against the US Power Grid . The possible Russian manipulation of the US election with cyber attacks and rogue social media campaigns is still a story not going away, while the Chinese are alleged to be behind the data theft of  Australian F-35 fighter jet, in what is described as an 'extensive' Cyberattack ....

Cyber Security Roundup for May 2017

The WannaCry ransomware outbreak within the NHS dominated the national media headlines earlier this month. Impacting 45 NHS sites in England and Scotland, the massive cyber attack led to cancelled operations and diversions of emergency medical services. The WannaCry outbreak was not just limited to the NHS, as thousands of computers were shut down at companies in almost 100 countries. After an initial infection via a phishing email and file encryption, the ransomware has the added ability to rapidly self-replicate, infecting other networked Windows computers without Microsoft’s March 2017 critical update (MS17-010) installed, this drove the swift spread of the malware within large organisations and across the world. Debenhams had 26,000 customer personal details stolen through its flowers service website, which was operated on Debenhams behalf by a third party company. The data breach has been reported to the ICO. With a year to ago until General Data Protection Regulation (GD...

WannaCry Ransomware Bite Sized Business Prevention Advice

Image
The top three actions to reduce the risk and impact of a WannaCry type Cyber Attack at a business Perform regular Staff Awareness specifically on spotting Phishing Emails Have a robust Patch Management Processes. Ensure all Microsoft Windows systems have Microsoft Critical Updates applied quickly - they are marked as critical for a reason! Have Anti-Virus running on all Microsoft Windows systems, with AV definitions kept up-to-date Security in Depth There are further security risk-reducing steps like filtering web traffic, ensuring data is regularly backed up, security monitoring, and network segmentation, but the above three are the most simple and most effective in terms of prevention against this type of attack, especially within the SMB space where security budgets are limited. Expect further versions of the WannaCry ransomware. The Reasons Behind this Advice (1) The WannaCry ransomware infects an initial system via a phishing email, the user executes the malware within...

The IT Security Expert Blog is 10 Years Old

Image
Ten years ago today I published my first ever blog post about a BBC news story titled " Home Network Security Scrutinised ". A decade ago it was rare to see an IT security or hacking story make the news media, and back then the term 'Cyber Security' would conjure images of Dr.Who's metallically clad arch-villains in most people's minds in the UK. The Face of Cyber Security in 2007 Fast forward ten years, IT security has long been rebadged as 'Cyber Security' and on Friday the top ten news stories  on Sky News were all Cyber Security related, albeit about the same global attack , but how times have changed. 'I found the following article on the BBC news website, which happens to be exactly what I had been talking about in my presentations this week. None of the findings is surprising to me, but I find many people I talk with are in the dark about digital security. Anyway, I thought I'd write this post about it and start my own blog...