Worldwide Flight Services Invests to Boost Cybersecurity Monitoring

Worldwide Flight Services Invests to Boost Cybersecurity Monitoring

IT services provider Transputec will provide security for Worldwide Flight Services’ (WFS) aviation cargo and ground handling operations, it has been announced.

Under the agreement, Transputec will work with ThreatSpike Labs to ensure WFS has the technology and services most relevant to its needs and will provide 24/7 monitoring for potential security risks, ensuring resolution is found before they become an issue.

WFS’ aviation cargo and ground handling operations consists of 21,800 employees at 171 stations in 22 countries across five continents. Transputec was deemed the most suitable provider for the firm after emerging top in proof of concept trials.

Sonny Sehgal, CEO of Transputec, commented: “We are excited to be working with such a respected market leader as WFS and pleased to be helping to further improve the company’s security program to increase the value of its services. Our team has already been welcomed as an extension of their IT function and a core part of their security team and will offer specialist help and digital expertise to support the integrity and growth of WFS’ operations around the world.”

Pedro Garcia, group chief information officer for WFS, said: “Safety and security will always be WFS’ top priority to underpin the vital services we provide for our airline customers at airports around the world. We take this responsibility very seriously and are constantly reviewing our systems and processes to ensure they are fit-for-purpose against potential threats and to protect our business continuity. Transputec is providing critical managed services that enable us to improve the resilience, efficiency and security of our global operations, which gives us the peace of mind that any security anomaly or incident will be managed and resolved instantly.”

There has been several security incidents involving airlines this year, including Easyjet revealing that approximately nine million of its customers had their personal data accessed and reports that access to Pakistan International Airlines’ network is being offered for sale on the dark web.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Tax Relief Biz Exposed Personal Info on 100,000 Clients

Tax Relief Biz Exposed Personal Info on 100,000 Clients

A UK business specializing in tax relief for its clients has exposed the personal details of over 100,000 of them via a misconfigured content management system (CMS).

Researchers at Website Planet told Infosecurity exclusively about the privacy snafu, which they discovered on October 13 and notified the firm about the next day.

That company was Marriage Tax Refund, a Wolverhampton-based organization whose business model is to recover marriage tax allowance funds for UK clients.

According to the research team, the firm had misconfigured its WordPress CMS, leaving a directory listing of PDF documents available for public view, with no password protection.

This meant anyone could theoretically have viewed personally identifiable information (PII) on Marriage Tax Refund clients, including: applicants’ full names, gender and home address, plus their partners’ full names and gender, and the refund amount they could request.

Website Planet estimated that in excess of 100,000 clients who signed up to the scheme since the company’s founding in October 2016 could have had their PII exposed in this way.

“A combination of full name, address and marital status are sufficient for nefarious users to conduct identity theft and fraud. Furthermore, personal user details could be used to conduct fraud across other platforms without the victim becoming aware that such activity is occurring,” the researchers warned.

“Therefore, Marriage Tax Refund’s leak could potentially be used to deploy deeper and more damaging scams by sending customized information directly to their target’s addresses, possibly disguised as communication from Marriage Tax Refund, or, disguised as HMRC but referencing the customer’s business with Marriage Tax Refund and thereby gaining the intended target’s trust.”

After notifying both the UK CERT and privacy regulator the Information Commissioner’s Office (ICO), Website Planet finally saw that the misconfiguration had been fixed by the firm on November 6 this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

A Cybersecurity Policy Agenda

The Aspen Institute’s Aspen Cybersecurity Group — I’m a member — has released its cybersecurity policy agenda for the next four years.

The next administration and Congress cannot simultaneously address the wide array of cybersecurity risks confronting modern society. Policymakers in the White House, federal agencies, and Congress should zero in on the most important and solvable problems. To that end, this report covers five priority areas where we believe cybersecurity policymakers should focus their attention and resources as they contend with a presidential transition, a new Congress, and massive staff turnover across our nation’s capital.

  • Education and Workforce Development
  • Public Core Resilience
  • Supply Chain Security
  • Measuring Cybersecurity
  • Promoting Operational Collaboration

Lots of detail in the 70-page report.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk