International Cyber Expo International Cyber Expo

Editor's News

The development of the Cyber Essentials assessment standard was necessary after a call for standards did not offer anything “to make a practical difference and reduce the UK attack surface”.   Speaking at the IT Governance conference in London, Richard Bach, assistant director of cyber security at the Department of Business, Innovation and Skills, said that the concept came from the Cyber Security Strategy to “encourage industry-led standards and guidance” and after viewing 25 submitted...

Read moreDetails

The Cyber Essentials assessment has been described as a good starting point, but it should be seen as the bare minimum and not just an effort to meet Government contracting requirements. Speaking at IT Governance's conference in London, Alan Calder, founder and CEO at IT Governance, said that while he welcomed it, Cyber Essentials was only giving “the minimum level of implementation” but the benefits of implemnentation were survival as most companies do not deal...

Read moreDetails

GCHQ apparently worked on methods to increase website hits, send repeated text messages and find private pictures of targets on Facebook.   According to a release by whistleblower Edward Snowden, some of the schemes are listed as being operational while others are said to be still at the design, development or pilot stages. In a statement, GCHQ told BBC News that it was not at fault, and its policy was not to comment on intelligence...

Read moreDetails

Incident response is often an afterthought and responsibilities are often unclear.   Speaking to IT Security Guru, Christian Toon, head of information risk at Iron Mountain, said that with a quite significant technical data breach, it is often not clear where the responsibility lies.   He said: “There is a gap between intent and action, so organisations know they need to do something but they are not following it through; everyone is struggling regardless of...

Read moreDetails

The Information Commissioner’s Office (ICO) suffered a “non-trivial data security incident” within the last 12 months. In the same week that it released its 2013/2014 annual report, Information Commissioner Christopher Graham said that there was one “non-trivial data security incident” that was treated as a self-reported breach. He said: “It was investigated and treated no differently from similar incidents reported to us by others. We also conducted an internal investigation.” The ICO, which can levy...

Read moreDetails

An efficient Information Commissioner's Office (ICO) that is well prepared for the future with adequate power and funding is needed for the UK.   Speaking at the launch of its 2013/2014 report, which it titled as “effective, efficient and busier than ever”, Information Commissioner Christopher Graham said he felt that the ICO was “doing a good job if it was helping organisations understand and receive a fair and efficient response”.   Graham said that the...

Read moreDetails

The Information Commissioner's Office (ICO) has admitted that an increase in major breaches has led to an increase in amount of work had to be done during the year.   Speaking at the launch of the 2013/2014 report in London, deputy chief executive officer Simon Entwisle said that despite that, there had been an 8.5 per cent in the number of cases cleared in data protection cases as it worked with different organisations in different...

Read moreDetails

A third of organisations experienced more than two “significant” security incidents in the past year. The survey of 1,600 IT information security decision makers in organisations of more than 500 employees, conducted by ForeScout, found that while the majority of IT organisations were aware that some of their security measures were immature or ineffective, only 33 per cent had high confidence that their organisations will improve their less mature security controls. Also on aggregate, one...

Read moreDetails

Hotel guests in the US have been warned about computers that are made available to guests in hotel business centres, which may be infected with keylogging malware.   Advisories have been issued by the US Secret Service to the hospitality industry after arrests were made of suspects who compromised computers within several major hotel business centres in the Dallas/Fort Worth areas, according to Brian Krebs.   “The keylogger malware captured the keys struck by other hotel guests that used...

Read moreDetails

LastPass has confirmed it has patched vulnerabilities in its “bookmarklets” which were exploitable.   In a blog, it confirmed that security researcher Zhiwei Li revealed “novel” vulnerabilities within the LastPass bookmarklets and One Time Passwords (OTPs). “Zhiwei discovered one issue that could be exploited if a LastPass user utilised the bookmarklet on an attacking site, and another issue if the LastPass user went to an attacking site while logged into LastPass, and used their username...

Read moreDetails
Page 269 of 319 1 268 269 270 319