Posts

Cyber Security Roundup for May 2016

The business impact of under investing in IT security was felt by TalkTalk, their profits were halved after 160,000 customers walked away from using the company’s services following their recent high profile data breach. TalkTalk received wide criticism for poorly handling their customer data breach which further damaged TalkTalk's reputation with customers.  Hugh volumes of stolen user credentials taken from the likes of LinkedIn, Tumblr and MySpace were dumped onto the dark web.  Spear phishing continues to be a problem across all industries, with one attack costing the job of a CEO and CFO at a German aircraft company.  The ICO publicly fined two NHS trusts and the Kent police following personal data breaches. One ICO £185,000 fine was due an emailed newsletter, the email “to” field displayed the email addresses of individuals infected with HIV to all recipients of the newsletter email. An issue simply prevented by using the BCC field instead of “To” or “C...

Cyber Security Roundup for April 2016

The European General Data Protection Regulation (GDPR) was finally approved by the European Parliament this month. Coming into force in 2018, the GDPR has serious teeth with an up to 4% global turnover fine for non-compliance, and 72 hour mandatory data breach reporting amongst ground breaking data protection changes geared at improving EU citizen's privacy rights. The new data protection regulation will have significant impact all businesses in UK, even if the UK votes to leave the EU.  An updated version of PCI DSS was also released; there are a number of minor changes to requirements within V3.2 which PCI DSS compliant businesses need to be aware of in order to avoid being caught out during compliance assessments.  There were several huge data breaches from around world, with entire country populations personal data being compromised.  There was what could be a very defining UK lawsuit by 6,000 Morrisons staff against their company, after an employee stole and ...

Cyber Security Roundup for March 2016

Ransomware attacks continue soar across all UK industry sectors, Trustwave SpiderLabs provided a excellent overview of how one of the most prolific ransomware strains works in  How the Locky Ransomware Works .  March saw media headlines dominated by Apple refusal to co-operate with the FBI in breaking the iPhone’s security, which concluded with the FBI successfully hacking iPhone via an anonymous third party, sparking the old but much needed Privacy V Security debate.  There were also notable hacks of Law Firms and a major ‘Cyber Heist’ at the Federal Reserve Bank of New York by hackers. Another major TLS vulnerability named ‘DROWN’, highlights the importance of patching OpenSSL and not using weak crypto. News DrownAttack could break TLS for a Third of Websites MassiveCyber Heist pulled on Bangladesh's Central Bank NY Fed Account USteam find Zero Day to hack Apple iCloud photo NatWest online banking suffers SMS 'smishing'scams FBIcracks iPhone, no longer need...

Cyber Security Roundup for February 2016

This month saw the trend in Spear Phishing and Ransomware cyber attacks continues across all industry sectors. Snapchat disclosed their CEO had fallen victim to a spear phishing attack which led to disclosure of Snapchat employee payroll information.  Two German hospitals were victim to ransomware after a member of staff opened a malware infected email attachment. The ransomware crippled X-ray machines and email systems for two weeks, underlining the business risk ransomware presents. News Snapchat got whaled, employee payrollreleased Ransomware holds data hostage in two Germanhospitals Cyber attackers demand ransom from GuernseyBusinesses Ukra ine Cyber-Attacks 'could happen to UK’ Nissan Leaf security flaw exposed by Security Expert IS hackers target small Solar UK firm inCyber Attack BlackEnergyAPT Attacks in Ukraine employ spear phishing with Word documents Reports PwC Economic Crime Survey: A quarter of UKcompanies hit by Cyber-Attack Mandiant M-Trends 2016 Re...

The Internet is Fast running out of IP Addresses - IPv6 V IPv4

Image
The explosion in the number of connected devices on the Internet, as fuelled with more users worldwide getting cheap access to net, now over 3.2 billion users, and the rapid growth of the Internet of Things (IoT), means the Internet is fast running out of IP addresses. IP addresses are important on the World Wide Web and every internet-enabled device has at least one IP address. Unfortunately, the current IP addressing system has a limited number of IP addresses, which means they’ll soon be running out. This outdated system, IPv4 was deployed more than three decades ago and it is still in use. IPv6 is an improvement on IPv4 and it’s seen as its replacement since it offers almost an infinite number of IP addresses. The New Jersey Institute of Technology has created and asked I share an excellent Infographic on How Engineers can insure the web doesn't run out of IP Addresses, comparing IPv4 to IPv6 .   To learn more, checkout the New Jersey Institute of Technol...

10 Steps to Building a Secure Network Infrastructure

Image
Irish based Exigent Networks has produced the following Infographics on Building a Network Infrastructure.  The graphic outlines the steps that need to be taken in building a network infrastructure, detailing each part of the process, while also advising as to the benefits of having a quality network infrastructure in place, and provides security tips. Considering all the security requirements at the design stage is far cheaper, and indeed results in a more secure network infrastructure, as opposed to trying to bolt on security to a poorly designed network. Also remember keeping the network infrastructure secure is an ongoing process, vulnerability testing, patching systems and devices, including switches, firewalls and routers, requires a continued process.   http://www.exigentnetworks.ie/solutions/managed-services/ .

2016 Cyber Security Predictions

In 2015 saw the rise of hackers motivated to steal data for the purpose of public extortion and public shaming. The Ashley Madison data breach was one highest profile examples, where the hackers attempted to blackmail the company to close down its infidelity website operations. When the company failed to comply with hacker's demands, the hackers released millions of Ashley Madison members account details online. In 2016 I think we will see more company sensitive user databases targeted for the purpose of blackmail by cybercriminals, and for the purpose of public shaming by hacktivists, hell bent on causing reputational damage to any companies they take a dislike to. 2016 will finally see the demise of arguably the greatest user inconvenience and 'Achilles Heel' in cyber security, the humble password. In the coming year more organizations will embrace ‘no password’ authentication models, using authentication alternatives to a password, such as biometrics, picotograp...