Posts

How Business can address the Security Concerns of Online Shoppers

Image
It’s no secret that cybersecurity is an epidemic problem that affects online businesses on a global scale. E-commerce businesses are especially affected by data breaches because it weakens the consumer’s trust in online businesses to protect their personal data. In response to the growing number of breaches, governments and enterprises alike are stepping up to the plate to provide sustainable solutions to the problem. The UK is aiming to become a world leader in cybersecurity by investing a substantial amount of money (to the tune of £70 million) in the Industrial Strategy Challenge Fund . The fund represents the government’s commitment to increase funding in research and development by £4.7 billion over a four year period. One of the primary goals of the investment will be to supply the industry with the money necessary to design and develop state-of-the-art hardware that’s more secure and resilient to common cyber threats. The logic stems from the fact that cybercriminals are constan...

Third Party Security Risks to Consider and Manage

Image
Guest article by Josh Lefkowitz, CEO of Flashpoint   Acceptable business risks must be managed, and none more so than those associated with external vendors who often have intimate access to infrastructure or business data. As we’ve seen with numerous breaches where attackers were able to leverage a weaknesses a contractor or service provider, third-party risk must be assessed and mitigated during the early stages of such a partnership, as well as throughout the relationship.   The following tips can help security decision makers more effectively address the risks posed by relationships with technology vendors.   Do Your Homework Conducting thorough due diligence on a prospective vendor is essential. Organisations could evaluate technical and regulatory risk through due diligence questionnaires, for example, or even on-site visits if necessary. The point is to evaluate not only a third party’s information security risk, but compliance with regulations such as...

Cyber Security Roundup for March 2019

Image
The potential threat posed by Huawei to the UK national infrastructure continues to be played out. GCHQ called for a ban on Huawei technology within UK critical networks , such as 5G networks, while Three said a Huawei ban would delay the UK 5G rollout , and the EU ignored the US calls to ban Huawei in 5G rollouts , while promoting the  EU Cybersecurity certification scheme to counter the Chinese IT threa t, which is all rather confusing.  Meanwhile,  Microsoft Researchers found an NSA-style Backdoor in Huawei Laptops , which was reported to Huawei by Microsoft, leading to the flaw being patched in January 2019. Is Huawei a Threat to UK National Security? Huawei: The company and the security risks   The assessment of the Chinese state as hostile towards Western nations is key in understanding why Huawei is considered a risk  Should we worry about Huawei?  Why has the UK not blocked Huawei? Why Huawei matters in five charts EU Cybersecurity ...

e-Crime & Cybersecurity Congress: Cloud Security Fundamentals

Image
I was a panellist at the e-Crime & Cybersecurity Congress last week, the discussion was titled ' What's happening to your business? Cloud security, new business metrics and future risks and priorities for 2019 and beyond ", a recap of the points I made. Cloud is the 'Default Model' for Business Cloud is now the default model for IT services in the UK; cloud ticks all the efficiency boxes successful business continually craves. Indeed, the 'scales of economy' benefits are not just most cost-effective and more agile IT services, but also include better cybersecurity (by the major cloud service providers), even for the largest of enterprises. I t is not the CISO's role to challenge the business' cloud service mitigation, which is typically part of a wider digital transformation strategy, but to ensure cloud services are delivered and managed to legal, regulatory and client security requirements, and in satisfaction of the board's risk a...

Learning from the Big Data Breaches of 2018

Image
Guest article by Cybersecurity Professionals What can we learn from the major data breaches of 2018? 2018 was a major year for cybersecurity. With the introduction of GDPR, the public’s awareness of their cyber identities has vastly increased – and the threat of vulnerability along with it. The Information Commissioner’s Office received an increased number of complaints this year and the news was filled with reports of multi-national and multi-millionaire businesses suffering dramatic breaches at the hand of cybercriminals. 2018 Data Breaches Notable breaches last year include: 5. British Airways The card details of 380,000 customers were left vulnerable after a hack affected bookings on BA’s website and app. The company insists that no customer’s card details have been used illegally but they are expected to suffer a major loss of money in revenue and fines as a result of the attack. 4. T-Mobile Almost 2 million users had their personal data, including billing information and em...

Deriving value from the MITRE ATT&CK Threat Model

Image
The MITRE ATT&CK knowledge base continues to gain traction as the defacto source for supporting business threat assessing, developing proactive cybersecurity and cyber resilience strategies. ATT&CK provides a defined understanding of the adversaries, their associated tactics, their techniques and procedures (TTPs). The ATT&CK comprehensive knowledge base of adversary tactics and techniques has been built up using real-world observations and is freely available to use.  There are many ways in which organisations can benefit from ATT&CK, often dependant on an organisation's security capabilities and the general security maturity. Steve Rivers, Technical Director International at ThreatQuotient has written guidance on the MITRE ATT&CK stages of maturity, so that any organisation can derive value from it. MITRE ATT&CK Framework: Keep your friends close, but your enemies even closer Steve Rivers, Technical Director International at ThreatQuo...

Cyber Security Roundup for February 2019

The perceived threat posed by Huawei to the UK national infrastructure continued to make the headlines throughout February, as politicians, UK government agencies and the Chinese telecoms giant continued to play out their rather public spat in the media. See my post Is Huawei a Threat to UK National Security? for further details. And also, why DDoS might be the greater threat to 5G than Huawei supplied network devices . February was a rather quiet month for hacks and data breaches in the UK, Mumsnet reported a minor data breach following a botched upgrade , and that was about it. The month was a busy one for security updates, with Microsoft , Adobe and Cisco all releasing high numbers of patches to fix various security vulnerabilities, including several released outside of their scheduled monthly patch release cycles. A survey by PCI Pal concluded the consequences of a data breach had a greater impact in the UK than the United States , in that UK customers were more likely to abando...