Posts

Showing posts with the label web application security

Achieving PCI DSS Compliant Firewalls within a Small Business

Image
The most important and integral part of any data security begins with having firewalls installed in the environment. Not just that, installing firewalls is an essential requirement of the Payment Card Industry Data Security Standard (PCI DSS ). However, simply installing a firewall on the network perimeter will not make your organization PCI DSS compliant. PCI DSS draws out specific requirements pertinent to firewalls under requirement 1 and its sub-requirements on how firewalls should be installed, updated, maintained along with other firewall rules. Elaborating more on this, we have explained in this article basic PCI DSS firewall requirements, and the need for small businesses to install firewalls. But before getting into the details of it, let us first understand the meaning of a PCI DSS compliant firewall. What is a PCI DSS Compliant Firewall? Firewalls are used to segment or isolate networks and are an essential component to   limit cyber threats and protect internal networks...

Which is more Important: Vulnerability Scans Or Penetration Tests?

Image
Which Is Better? A Vulnerability Scan Or A Penetration Test? Vulnerability scanning and penetration tests are two very different ways to test your system for any vulnerabilities. Despite this, they are often confused about the same service, which leads to business owners purchasing one service when they are really in need of the other. In an effort to help these business owners tell the difference between the two services and understand which is best suited to their needs, SecureTeam , a cybersecurity consultancy, has written this guide to explain vulnerability scans vs. penetration testing. In a brief summary, a vulnerability scan is an automated, high-level test that looks for and reports potential vulnerabilities in your system. A penetration test, on the other hand, is a detailed hands-on examination by a cybersecurity professional that tries to detect and exploit weaknesses in your system. Now, let’s look a little deeper at the two services. What is a Vulnerability Scan? Vulnerabi...

What Website Owners Should Know About Terms and Conditions

Image
All website owners should consider terms and conditions (T&Cs) to be a form of legal protection as they establish the responsibility and rights of the involved parties. T&Cs provide full security should anything go amiss and they also help you settle any disputes quickly without having to resort to the courts. Is it a legal requirement to include T&Cs? No, but it’s always best to include terms and conditions on your website as they will enable you to reduce your potential liabilities. It is essential that you let your customers or visitors know about their rights; if you’re not clear about your policies, they may dispute matters such as cancellation options, item returns and other rights, putting your company at a disadvantage. Additionally, if areas are unclear in your terms and conditions or even not mentioned, it may mean that you are liable to give your customer additional rights than are given under statutory. Do you have to include GDPR provisions? Website owner...

UK Pub Chain 'Greene King' Gift Card Website Hacked

Image
Major UK pub chain, Greene King (Bury St. Edmunds), had its gift card website ( https://www.gkgiftcards.co.uk ) compromised by hackers. The personal data breach was discovered on 14th May 2019 and confirmed a day later. The pub, restaurant and hotel chain informed their impacted customers by email today (28th May 2019). Greene King said the hackers were able to access: name email address user ID encrypted password address post code The pub chain did not disclose any further details on how passwords were "encrypted", only to say within their customer disclosure email " Whilst your password was encrypted, it may still be compromised".  It is a  long established good industry coding practice for a website application's password storage to use a one-way 'salted' hash function, as opposed to storing customer plaintext passwords in an encrypted form . No details were provided on how the hackers were able to compromise the gift card website, but th...

How Business can address the Security Concerns of Online Shoppers

Image
It’s no secret that cybersecurity is an epidemic problem that affects online businesses on a global scale. E-commerce businesses are especially affected by data breaches because it weakens the consumer’s trust in online businesses to protect their personal data. In response to the growing number of breaches, governments and enterprises alike are stepping up to the plate to provide sustainable solutions to the problem. The UK is aiming to become a world leader in cybersecurity by investing a substantial amount of money (to the tune of £70 million) in the Industrial Strategy Challenge Fund . The fund represents the government’s commitment to increase funding in research and development by £4.7 billion over a four year period. One of the primary goals of the investment will be to supply the industry with the money necessary to design and develop state-of-the-art hardware that’s more secure and resilient to common cyber threats. The logic stems from the fact that cybercriminals are constan...

Cyber Security Roundup for June 2018

Dixons Carphone said hackers attempted to compromise 5.9 million payment cards and accessed 1.2 million personal data records . The company, which was heavily criticised for poor security and fined £400,000 by the ICO in January after been hacked in 2015 , said in a statement the hackers  had attempted to gain access to one of the processing systems of Currys PC World and Dixons Travel stores. The statement confirmed 1.2 million personal records had been accessed by the attackers. No details were disclosed explaining how hackers were able to access such large quantities of personal data, just a typical cover statement of "the investigation is still ongoing".  It is likely this incident occurred before the GDPR law kicked in at the end of May, so the company could be spared the new more significant financial penalties and sanctions the GDPR gives the ICO, but it is certainly worth watching the ICO response to a repeat offender which had already received a record ICO fine this...

Cyber Security Roundup for March 2018

In the wake of the global political fallout over the Salisbury nerve agent attack, there are reports of a growing threat of Russian state or Russian state-affiliated hacking groups conducting cyber attack reprisals against UK organisations, government officials have directly warned bosses at electricity, gas and water firms, Whitehall departments and NHS hospitals to prepare for a state-sponsored cyber assault .  Russian group Fancy Bear (APT28) were suspected of being behind an unsuccessful attack against the UK anti-doping agency , and China tied hacking group APT15 were found to have infiltrated a UK government contractor’s computer systems by NCC researchers . Large-scale data breaches were disclosed with Under Armour’s Fitness App MyFitnessPal (1.5 million personal records compromised) , Orbitz (880k payment cards at risk) , and at a Walmart partner (1.3 million personal records compromised) . The latter was caused when an AWS S3 bucket holding a Walmart dat...