Government Threatens Tech Firms with Fines of 10% of Turnover

Government Threatens Tech Firms with Fines of 10% of Turnover

The UK government will introduce an Online Safety Bill next year which could result in fines higher than the GDPR for companies that allow illegal content to be posted on their platforms.

The plans are nominally aimed at protecting children online by banning things like terrorist content, child sexual abuse material, and anything promoting suicide. Misinformation is also included, if it is deemed to cause major physical or psychological harm.

Regulator Ofcom will be given the power to fine companies up to 10% of global annual turnover or £18 million, whichever is higher, for serious transgressions. It will also be empowered to block such services if they choose not to comply, although it’s unclear exactly how.

So-called Category One companies — like Facebook, Twitter, TikTok and others with a major online presence and “high-risk features” — will face the most stringent requirements, although the majority of firms online fall into lower categories.

However, the law nevertheless places new requirements not only on social media giants but a swathe of online services including messaging, cloud storage, search engines, video games and online forums.

As some of these platforms run end-to-end encryption there are concerns over whether they will be effectively penalized for not being able to monitor content being disseminated by users.

Stephen Kelly, CEO of entrepreneur’s network Tech Nation, welcomed the proposals.

“Given our leadership in the application of ethics and integrity in IT, it should be no surprise that the UK is moving decisively to tackle online harms, one of the biggest and most complex digital challenges of our time,” he argued.

“Equally, it offers the UK the opportunity to lead a new category of tech, such as ‘safetech,’ building on our heritage of regtech and compliance, which already assure global markets and economies.”

However, others were less confident. Adam Hadley, director of the Online Harms Foundation is reported as describing the plans as “at best ineffective and at worst counterproductive.”

“Creating onerous financial penalties on tech companies only incentivises overzealous removal of content, leading to content that is not illegal being removed and pushing conspiracy theorists on to self-owned underground platforms, where their views cannot be challenged or easily monitored,” he argued.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SolarWinds: Our Office 365 Emails Were Compromised

SolarWinds: Our Office 365 Emails Were Compromised

The company at the center of revelations over a widespread Russian information-stealing campaign has said that fewer than 18,000 of its global customers were affected.

SolarWinds produces popular software that helps organizations manage their IT networks and infrastructure. However, it was revealed by FireEye that attacks which compromised the security vendor and US government departments had used the software as a key attack vector.

In a way not dissimilar to the NotPetya attacks of 2017 which began by compromising legitimate Ukrainian accounting software to deliver malware via updates, the attackers appear to have trojanized SolarWinds Orion product.

“FireEye has detected this activity at multiple entities worldwide,” the vendor said on Sunday.

“The victims have included government, consulting, technology, telecom and extractive entities in North America, Europe, Asia and the Middle East. We anticipate there are additional victims in other countries and verticals.”

Exactly how many organizations had been affected by the attacks was a point of speculation up until now. However, an SEC filing by SolarWinds provided some clarity.

Despite the company boasting 300,000 global customers, it claimed that only 33,000 used the Orion product during and after the period the malicious updates are thought to have been issued: March-June 2020.

“SolarWinds currently believes the actual number of customers that may have had an installation of the Orion products that contained this vulnerability to be fewer than 18,000,” it revealed.

“The communication to these customers contained mitigation steps, including making available a hotfix update to address this vulnerability in part and additional measures that customers could take to help secure their environments. SolarWinds is also preparing a second hotfix update to further address the vulnerability, which SolarWinds currently expects to release on or prior to December 15, 2020.”

Another question mark hanging over the firm is how it was compromised in the first place. Although it didn’t clarify whether the incidents were related, the same SEC filing revealed that SolarWinds had been notified by Microsoft that its Office 365 emails had been compromised by an unnamed “attack vector.”

“[They] may have provided access to other data contained in the company’s office productivity tools,” it noted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk