UK Government Drafts New Legislation to Force Tech Firms to Tackle Online Abuse

UK Government Drafts New Legislation to Force Tech Firms to Tackle Online Abuse

The UK government has published draft legislation designed to tackle a number of online harms, ranging from child sexual abuse to fraud.

The Online Safety Bill, which formed part of yesterday’s Queen’s Speech during the state opening of Parliament, will place new obligations on social media sites and other services hosting user-generated content or allowing people to talk to others online to remove and limit the spread of illegal and harmful content. This includes child sexual abuse, terrorist material, and suicide content.

The announcement has come amid a substantial rise in online abuse and fraud during the COVID-19 crisis, in which there has been huge shift to digital.

Under the legislation, all these companies will have a duty of care to take “robust” action against illegal abuse on their platforms, which includes hate crimes, harassment, and threats directed at individuals. They will also be required to report child sexual exploitation and abuse (CSEA) content identified on their services to law enforcement.

Additionally, major social media companies, labeled Category 1 services, will have to set out in their terms and conditions how they will address content that falls below the threshold of a criminal offense but is still harmful, such as mis/disinformation.

The UK communications regulator, Ofcom, will be responsible for holding these firms to account, and will have the power to fine those failing to meet their duty of care up to £18m or 10% of annual global turnover, whichever is higher. There will also be a new criminal offense for senior managers, which will initially be deferred.

The new law also looks to tackle fraud by forcing online businesses to take responsibility for fraudulent user-generated content on their platforms, such as social media posts. This includes romance scams, which have surged since the start of the COVID-19 crisis.

Other provisions in the bill are designed to protect free speech online. These include obligations on all in-scope companies to consider and put in safeguards for freedom of expression and the protection of content defined as “democratically important.”

The draft bill will now be scrutinized by a joint committee of MPs before a final version is presented to Parliament.

Home Secretary Priti Patel commented: “This new legislation will force tech companies to report online child abuse on their platforms, giving our law enforcement agencies the evidence they need to bring these offenders to justice.

“Ruthless criminals who defraud millions of people and sick individuals who exploit the most vulnerable in our society cannot be allowed to operate unimpeded, and we are unapologetic in going after them.

“It’s time for tech companies to be held to account and to protect the British people from harm. If they fail to do so, they will face penalties.”

Yesterday, during her address at the CYBERUK 2021 online event, Patel announced there will be a formal review of the Computer Misuse Act this year to ensure law enforcement agencies are properly equipped to tackle online abuse and cybercrime.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#CYBERUK21: Foreign Secretary Sets Out UK’s Global Cyber Vision

#CYBERUK21: Foreign Secretary Sets Out UK’s Global Cyber Vision

During a keynote address at the CYBERUK 2021 online event, UK foreign secretary Dominic Raab explained the UK’s vision to become a global leader in cyberspace through promoting safety and liberal values in technology.

Raab began by celebrating the UK’s strong pedigree in science and technology, which gives the country a “great foundation” to take on this mantle. He added that the UK tech sector has been a major source for good in the world, for example helping boost economic activity in Africa and Asia through initiatives such as providing access to mobile phones.

However, Raab said that “we do need to acknowledge there is a darker side” in tech, which is characterized by “the clash of values” between countries whose values are based on openness and democracy and those that promote authoritarianism.

He noted: “We can see this clash between authoritarian and democratic states playing out very directly right now in cyberspace.” Raab outlined how nations like North Korea, Iran, Russia, and China are using “digital tech to sabotage and to steal, or to control and censor.”

There are numerous examples of state-sponsored actors engaging in activities that are having a major impact on critical services and infrastructure, including allegedly with the recent ransomware attack on the US’s largest fuel pipeline, and the frequent targeting of COVID-19 vaccine development and supply chain.

Raab also revealed that in March this year, around 80 different schools, colleges, and universities in the UK were hit by ransomware attacks, forcing some to delay their reopening following the easing of lockdown.

Additionally, he outlined how democracy has become a prime target for state-sponsored actors, with elections in the Western world hit by misinformation online.

Amid this backdrop, “we’ve got to adapt to that threat, not just to defend our financial interests, but to defend our way of life,” commented Raab. He set out three ways the UK government is looking to do so. Firstly, through building up domestic cyber-defenses, which “is starting to pay off, we’re getting better at detecting, disrupting, and deterring our enemies.” The second is the continued development of offensive cyber-capabilities, as highlighted by the creation of the National Cyber Force. This is designed to disrupt the activities of cyber-gangs as well as be used for military purposes. Raab stated: “We will continue to use these capabilities where necessary, in a proportionate way and in line with international law.”

The third way is a global approach, working with like-minded nations to develop a cyberspace that is “free, open, peaceful, and secure, and which benefits all countries and all people.” This necessitates clarifying and enforcing international laws in cyberspace, such as repercussions for those nations that continually launch attacks.

Raab explained that as well as working with traditional partners, the UK and its allies must look “to win the hearts and minds across the world” for this vision for cyberspace, especially nations in the poorest regions of the world, preventing countries like China and Russia from “filling the multilateral vacuum.” With this in mind, Raab announced a £22m commitment in new funding to support cyber capacity in these vulnerable countries, “particularly in Africa and the Indo-Pacific.”

He concluded by saying: “As global Britain, we’ve got to be agile—we’ve got to work with traditional partners but also new partners.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Home Working Parents and Young Adults Are Most Risky IT Users

Home Working Parents and Young Adults Are Most Risky IT Users

Young adults and parents of young children could be inviting cyber-threats by using work devices for risky personal tasks, according to new research from HP Inc.

The computing giant commissioned two separate global surveys of 8443 adults and 1100 IT decision makers, to compile its Blurred Lines & Blindspots report, which details the threat from the distributed workforce.

It found most (71%) employees are accessing more company data more frequently from home than they did pre-pandemic, with over three-quarters (76%) admitting that working-from-home (WFH) has blurred the lines between their personal and professional lives.

Certain types of home worker appear to be more likely to engage in risky behavior using work devices.

While a third (33%) of respondents are now downloading more to their devices from the internet, the figure rises to 60% for those aged 18-24-years-old. This age group is also more likely (60%) to watch online streaming services, versus the average (36%).

In addition, over two-fifths (43%) of parents of children aged 5-16-years-old admitted to using work devices to play more games today than pre-pandemic. The figure overall is just 27%.

Over half (57%) of this group are also likely to use their work device for homework and online learning, versus an average of 40%.

This matters because threat actors are increasingly looking to target these behaviors, according to separate research by analyst KuppingerCole, cited by HP.

It revealed a 54% increase in malicious actors exploiting gaming platforms between January and April 2020, and found at least 700 phishing websites spoofing streaming services in a single seven-day period in April.

The research also revealed a significant number of home workers are using potentially insecure personal devices for work — to access corporate applications (37%) and networks/servers (32%).

Over half (51%) of IT decision makers have seen evidence of compromised personal PCs being used to access company and customer data over the past year, said Ian Pratt, global head of security for HP’s personal systems division.

He argued that ideally all endpoints should be patched and up-to-date, with anti-malware and endpoint detection agents (EDR), and vulnerability assessment tools running on them to provide IT with visibility.

“However, most organizations can’t enforce an assessment of the security posture of a device before it connects to the network, so it relies on the user to make judgements. Even with policies in place, malware is very adept at evading detection,” he told Infosecurity.

“Devices on the corporate network have the benefit of defences in the corporate network, but are still very much at risk. Attackers know that the easiest way into the enterprise is by targeting the user and tricking them into clicking something to expose their machine to an attack. These attacks are even more likely to be successful if a work device is being shared by others at home.”

The report itself was launched to promote a new set of secure-by-design HP PCs and printers, hardware-enforced endpoint security software and endpoint security services, known collectively as HP Wolf Security.

However, Pratt had further best practice advice for IT security leaders without the budget to spend on a new range of security products and services.

“When enabling remote access for business-critical apps, organizations should enable multi-factor authentication, particularly with authenticator mobile phone apps or other hardware tokens,” he said.

“Overall, users should be advised not to store high value credentials in the browser and to be wary of the risks of sharing work devices with others — this type of behavior, while often innocent, is risky for the business and broadens the attack surface for hackers to exploit.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Fixes Exchange Server Zero-Day in May Patch Tuesday

Microsoft Fixes Exchange Server Zero-Day in May Patch Tuesday

Microsoft fixed 55 vulnerabilities yesterday including three zero-days not thought to have been exploited in the wild, one of which affected the under-fire Exchange Server.

This month’s Patch Tuesday is lighter than many have been in recent months, but there were four critical CVEs for admins to address, alongside the three publicly disclosed bugs.

Top of the priority list should be CVE-2021-31207, which was discovered as part of this year’s Pwn2Own competition, according to Ivanti senior director of product management, Chris Goettl.

“Microsoft Exchange admins have had a rough stretch in the past few months starting with the zero-day exploits targeted by Hafnium followed by the April Exchange update resolving four NSA discovered vulnerabilities,” he said.

“CVE-2021-31207 is only rated as moderate, but the security feature bypass exploit was showcased prominently in the Pwn2Own contest and at some point details of the exploit will be published. At that point threat actors will be able to take advantage of the vulnerability if they have not already begun attempting to reverse engineer an exploit.”

The other two zero-days fixed by Microsoft this month are CVE-2021-31200, a remote code execution (RCE) vulnerability in Common Utilities, and CVE-2021-31204 which is an elevation of privilege flaw in .NET and Visual Studio.

“Both publicly disclosed vulnerabilities are rated as Important, but the disclosure puts them at a higher risk of being exploited,” warned Goettl.

Of the critical CVEs, Qualys research and engineering VP, Anand Paturi, singled out SharePoint RCE bug CVE-2021-31181, and CVE-2021-31166, an HTTP protocol stack RCE vulnerability in Windows.

Also this month, Adobe resolved 42 CVEs, 16 of which are rated critical and one of which is a zero-day being actively exploited in the wild.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of Government Security Incidents Caused by Missing Patches

Half of Government Security Incidents Caused by Missing Patches

Cybersecurity is both a driver and a major barrier to public sector IT modernization, according to new research from BAE Systems Applied Intelligence.

The cyber consultancy polled 250 managers with IT responsibility in UK central governmental organizations, to better understand the interplay between security and digital transformation.

The research revealed that most (60%) UK government departments have digital transformation plans in place and that these have been accelerated in the majority of cases by the pandemic.

Mitigating the risk of vulnerabilities was cited by three-quarters (75%) of respondents as the main reason for driving these legacy upgrades.

This push is being borne out of current experience. Nearly two-thirds (63%) of respondents said they suffered a security incident in the past six months and over half of these (52%) came as a result of missing patches.

The mass exploitation of unpatched Microsoft Exchange Server bugs earlier this year is proof of the potentially disruptive impact of such threats.

Yet security was also cited by 68% of respondents as a barrier to upgrades, second only to integration issues (69%).

According to the report, greater collaboration between IT and security and a recognition of the urgent need for security enhancements in certain areas can give projects a push.

“If anything, the rapid response to the pandemic has proven that red tape can be circumvented and fast-track processes invoked if the need is urgent enough,” it noted.

BAE Systems consultant for central government, Lorna Rea, argued that too often the security function is still the “department of no,” working in isolation from the rest of IT.

To modernize without increasing cyber-risk, public sector organizations must view those risks in terms of business impact, she told Infosecurity.

“For example, in the healthcare sector, the threat of a ransomware attack feels a lot more real if it is described as something that could shut your entire hospital down,” Rea added. “Security teams must be must fully embedded as part of the change process — operational risks can be taken if they are fully understood and mitigations worked through.”

Top of the priority list for IT decision makers in central government is simplifying their security architecture (45%) and reviewing current risk management strategies to ensure they have the right balance between security and productivity (45%), the report concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk