Posts

PCI London: How the Payment Card Industry could kill PCI DSS

Image
Today (23rd Jan 14) I was a panellist at PCI London 2014, quite a few people were interested in what I had to say, on removing the need for PCI DSS compliance completely by securing the payment cards further. What I said was nothing new, I have been bleating on about this since attending the first PCI SSC meeting back in 2007. Still it is a bold thing to say, especially at a conference where Visa Europe and the PCI Security Standard Council are promoting PCI DSS compliance in the UK, and with event sponsoring vendors promoting their PCI DSS compliance servicing wares.  I'll summarise the views which I expressed at PCI London, which I believe could draw an end to PCI DSS compliance. Introduce Global Chip & Pin (EMV) Chip & Pin provides two-factor authentication, this means in order for the cardholder to make a payment,  the cardholder requires knowledge of a 4 digit number, and possession of the payment card. This is known as a 'cardholder present' transac...

UK Information Security Threat Horizon 2014

I was asked for my views on the Threat Horizon, specifically what attacks and trends do I expect to impact UK businesses in 2014, so I thought I'd share my thoughts.  The following are my own views, and they are not based on any specific studies or reports, but on what I've generally read, discussed and trends I have seen affecting UK businesses in the last couple of years. Cloud Data Protection UK businesses continue the 'Cloud Rush', meaning more and more confidential data is going into the cloud. I don't think this is so much a Snowden privacy revelation issue with government spying, but I see the problem is that UK businesses are being  taken in by the marketing cost saving glitz, and so  are blindly trusting cloud service providers. At the end of the day a cloud service provider is a third party service provider. A cloud service purchased by a business, where the third party is charged with adequately  protecting confidential info...

Printicy: 3D Printer Design Piracy

Image
The sun is rising on the exciting and limitless age of 3D printing. 3D printing technology is really starting to pick up the pace, the latest evolutions of the technology means 3D printers are not only becoming more affordable, but the objects 3D printers can produce are becoming more sophisticated, allowing for all manor of potential object capability and application. Anyone can have their  designs 3D printed through online services   already, and in the coming years we can expect to see 3D printers within many households. P erhaps as part of your weekly shopping visit to your local supermarket, you'll pick up your 3D printed objects from a supermarket 3D printer counter, just as you might do with photograph prints today. 3D Printers for the Home Exciting as the 3D printing is, I foresee the technology will be blighted with piracy problems, along the lines of what we saw with illegal music downloads pre music stores like Apple iTunes, and music streaming services...

Big Data Intelligence Driven Security at RSAC

Image
A constant theme from this year’s RSA Conference Europe, is the idea of security intelligence collaboration, namely the capture, sharing and data mining of “Big Data’, to detect and prevent security incidents and attacks, but will it ever take off? The concept of gathering and using big data is nothing new, from Google to your supermarket loyalty card; big data mining has been very successfully used commercially for at least a decade, not to mention the alleged big data mining said to be conducted by the NSA. This collaborative led intelligence approach has potential and I believe it could be effective if conceived and built smartly, however I fear the issue will be with the data sharing. Most of the existing big data models in use are covert, and organisations aren’t collaborating, so they do not share their big data analytics. This is a fairly obvious approach, as the whole idea of mining big data in their case is for commercial advantage and gain. So I imagine ...

RSA Conference: Anonymity is the Enemy of Privacy

Image
‘Anonymity is the Enemy of Privacy’ was a point stressed by Art Coviello, the Executive Chairman of RSA, in the opening keynote of the RSA Conference Europe 2013.   This point is controversial to say the least, especially to a European audience, with mainly Europeans still rocking in the wake of the massive NSA covert internet surveillance allegations against European leaders, and millions of EU citizens. Many privacy advocates hold a polar opposite view to Art, believing anonymity online is a fundamental ingredient for online privacy. Art's perspective also highlights the difference in attitudes towards privacy harboured between the United States and Europe. The European Union was built on its citizen rights, including the right to privacy, a right the EU wishes to see exercised online, whereas the US view tends to be 'privacy is dead', believing the right to online privacy has been given up and the privacy fight lost.

Identity Theft & How to Protect Yourself from ID Theft

Image
HotSpot Shield have created an Identity Theft InfoGraphic which I'm happy to share. InfoGraphic explains the malicious actors behind ID theft, some of the techniques they use and how to protect yourself.  

RSA Conference Europe 2013 Preview

The keynote speaker at this year's RSA Conference Europe  is certainly of interest. Sir Seb Coe was widely applauded as delivering an outstanding Olympic Games in London last year.  The security of the games was always a great concern from the day after it was announced London was to receive the games back in 2007, but it is the cyber security aspect of the games which interests me. The games were subjected to cyber threats, including a specific cyber threat aimed at taking down power supplies to the games stadiums, so it will be fascinating to learn more about the planning, preparation and the testing of the London 2012 cyber defence. I always recommend the RSA Europe Conference to fellow UK security professionals, especially those new to our busy and complex sector.  It’s a great event to learn about the emerging threats, defences and the latest security thinking, with plenty of quality sessions to choose from. The conference is also a great place to network with fe...