Posts

2016 Cyber Security Predictions

In 2015 saw the rise of hackers motivated to steal data for the purpose of public extortion and public shaming. The Ashley Madison data breach was one highest profile examples, where the hackers attempted to blackmail the company to close down its infidelity website operations. When the company failed to comply with hacker's demands, the hackers released millions of Ashley Madison members account details online. In 2016 I think we will see more company sensitive user databases targeted for the purpose of blackmail by cybercriminals, and for the purpose of public shaming by hacktivists, hell bent on causing reputational damage to any companies they take a dislike to. 2016 will finally see the demise of arguably the greatest user inconvenience and 'Achilles Heel' in cyber security, the humble password. In the coming year more organizations will embrace ‘no password’ authentication models, using authentication alternatives to a password, such as biometrics, picotograp...

What is Tor and Should your website block Tor users?

Image
Great infographic by State of the Internet which raises an interesting question, should websites block Tor users?  Certainly one for debate, my view is it depends on your website 'marketplace', function and risk, in other words perform a risk assessment, a lazy answer I know. But i f like me you find yourself often explaining what Tor is to business folk, so they can perform those risk assessments properly, you'll find this infographic comes in quite handy. As it does a simple job of explaining Tor; who uses it, how it provides anonymity  online, and how cyber criminals are embracing the tool for various illicit purposes. I recommend checking out the  State of the Internet website  for further info, statistics and reports on Web and DDoS attacks, which continue to blight the Internet.

TalkTalk Hacked (again) - Consumer Advice

A lot of TalkTalk customers have been contact with me today asking for my advice following TalkTalk's announcement of yet another major data breach . The TalkTalk press release states "there is a chance that some of the following data may have been accessed: Names Addresses Date of birth Phone numbers Email addresses TalkTalk account information Credit card details and/or bank details" And given TalkTalk are unable to confirm whether any of this data was encrypted when assessed, if you are a TalkTalk customer you should take this statement seriously and assume your personal information, bank account and/or credit card details you held with TalkTalk are now in the hands of cyber criminals and fraudsters. What to Do In summary all TalkTalk customers must be extra vigilant in checking their bank and credit card accounts for fraudulent transactions, and for attempts of fraud by covert cyber criminals using their personal information against them. Statement Che...

Top security best practices for IoT applications - Combating IoT cyber threats

I have written the following article for IBM which was published today on  IBM Development Works . https://www.ibm.com/developerworks/library/iot-security-best-practices-iot-apps/ The Internet of Things is changing the way that businesses operate, especially in the areas of warehousing, transportation, and logistics. These changes make the security of IoT devices even more crucial, given the time and money that is required if a hacker breaks through the defenses. This article outlines the best practices for securely developing robust IoT solutions.

To Firewall or not to Firewall – Trusted & Untrusted Networks

The big danger of firewall deployments within a complex dynamic network infrastructure (a typical enterprise) is you end up with placebo network security. It is a problem that creeps in with each firewall rule change over the course of time. No one ever seems to be concerned when adding a new rule to a firewall ruleset, but removing a rule is a fearful business, so often it is not risked, so not to break anything.  The g eneral adhoc adding of rules without first understanding the entire ruleset is what seriously weakens firewall security, it makes rulesets hard to understand and can mushroom into an ineffective firewall configuration. So instead of allowing a network range through on specific set of ports as a single rule, you end up with tens of rules allowing individual IPs each on a specific port. I have seen firewall rulesets with thousands of unnecessary individual rules, caused by a combination of poor firewall management, lack of change control...

Enviable Business Cloud Adoption & Cloud Security

I was quoted in an interesting discussion type article on Business Cloud Adoption at  CIO.com   How Line Of Business Is Driving The Move To The Cloud I have picked out my quotes which underlines my view that IT and Security functions must be agile and accommodating to the business cloud wants. While the business in turn must be careful not be so bamboozled by the efficiency & cost saving gains, and all those sexy sales buzzwords, they neglect the security question when procuring cloud services. On Cloud Adoption “Quite often businesses adopt cloud services outside the IT function whether is it Sales using Salesforce or HR using LinkedIn for recruitment, or general staff using Dropbox,” said UK-based Information Security Expert Dave Whitelegg. “The traditional internal-facing IT department can be quickly left behind by buy-and-go cloud service adoption" On Cloud Security “Cloud data security concerns should be addressed by IT carrying out ...

Security Today - Cyber Information Security News Stream & Alerts Twitter Feed

Image
I was an early adopter to Twitter, opening my  @securityexpert  account back in October 2008, I found Twitter has been an excellent tool for picking up and sharing information security news, articles, major breaches and critical vulnerability alerts. As well as making my own contributions I often retweet tweets of InfoSec interest, education and intrigue, however I have always had a strict policy of never allowing my  @securityexpert  account to send any automated tweets, every tweet is manually sent or is retweeted by yours truly. Once you go down that road the personal nature of the account goes. I recognise that many of  followers of the account are interested are in the latest news, so with that in mind I have launched a new Twitter account to provide a more comprehensive and more regular stream of InfoSec news. @securitytoday  has been launched  to just tweet cyber information security related new...