Carrefour Handed $3.7m GDPR Fine

Carrefour Handed $3.7m GDPR Fine

French retail giant Carrefour and its banking arm have been fined over €3m ($3.7m) by the local data protection regulator for multiple breaches of the GDPR.

French regulator the Commission nationale de l’informatique et des libertés (CNIL) hit Carrefour France with a €2.25m fine and Carrefour Banque received an €800,000 penalty.

CNIL took into account the significant remedial action that had been taken by the firm to address its concerns.

However, the list of these concerns extended to nine key areas, according to compliance experts Cordery.

Information about data protection was too complicated and imprecise, and hidden in lengthy documents alongside other information. Key info on data retention was also missing.

Cookie use was unlawful, the policy for dealing with data subject requests was too restrictive, Carrefour didn’t meet time limits for responding to data subject requests and it transferred data without being fully transparent.

CNIL claimed that a data retention period of four years for customer data after the last purchase was excessive. Plus, it felt there was also insufficient information on data transfers outside the EU and the legal basis for processing on the carrefour.fr website.

“The data transfer element is especially interesting given the issues with the collapse of Privacy Shield and the increased focus on data transfer using Standard Contractual Clauses,” said Cordery.

“It seems that data protection regulators are also focussing on what organizations are saying on their websites about data transfers. Consider therefore reviewing your website to ensure that it meets GDPR transparency standards, especially to meet the required standard with information on data transfers.”

CNIL is one of Europe’s more active GDPR regulators. It was the first to issue a major fine following the introduction of the new legislation: hitting Google with a €50m ($60m) penalty for failing to notify users about how their data is used.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybersecurity Flaws Could Lead to Biological Attacks: Report

Cybersecurity Flaws Could Lead to Biological Attacks: Report

Unwitting scientists may be tricked into creating synthetic viruses and other toxins in their labs, according to Israeli researchers who claim to have discovered a new “end-to-end cyber-biological attack.”

Published in Nature Biotechnology, the research by a team at Ben-Gurion University (BGU) of the Negev describes how criminals no longer need to have physical contact with a dangerous substance to produce and deliver it.

Part of the problem boils down to a weakness in the US Department of Health and Human Services (HHS) guidance for DNA providers which allows screening protocols to be circumvented using a generic obfuscation procedure.

The researchers claimed that, when they used this procedure, 16 out of 50 obfuscated DNA samples were not detected.

The second major factor is insufficient cybersecurity controls on lab computers. In the scenario painted in the report, a bioengineer has her PC infected with a malicious browser-plug-in, which enables a man-in-the-browser attack.

In so doing, attackers are able to change her order of sequences placed with a DNA synthesis company, to malicious sequences.

DNA obfuscation techniques camouflage the malicious nature of the order, which is therefore processed without raising any alarms and returned to the lab.

“This attack scenario underscores the need to harden the synthetic DNA supply chain with protections against cyber-biological threats,” said Rami Puzis, head of the BGU Complex Networks Analysis Lab.

“To address these threats, we propose an improved screening algorithm that takes into account in vivo gene editing. We hope this paper sets the stage for robust, adversary resilient DNA sequence screening and cybersecurity-hardened synthetic gene production services when biosecurity screening will be enforced by local regulations worldwide.”

On the cybersecurity side, the report recommends electronic signatures be placed on orders to improve transparency, and intrusion detection systems be used in labs, featuring heuristics and AI behavioral analysis to identify malicious code on PCs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Remote Workers Admit Lack of Security Training

Remote Workers Admit Lack of Security Training

A third of remote working employees have not received security training in the last six months.

According to a survey by NinjaRMM of 400 remote workers in the UK across multiple industries, while 83% have had access to security best practice training and 88% are familiar with IT security policies, 32% have received no security training in the last six months.

Also, 50% spend two or more hours a week on IT issues, and 42% felt they had to go around the security policies of their organization to do their job.

According to Lewis Huynh, CSO at NinjaRMM, as COVID-19 introduced a seismic change to how security and IT operations are conducted at most businesses, “IT teams have been stretched thin to maintain normal operations and that means things like security training may have taken a lower priority.” He claimed that this is a mistake, as remote work has introduced more threats, not less.

“Ultimately, the decision to deploy security training to staff comes down to leadership, and if there’s one thing we learned from this report it’s that leaders should be doing more to prioritize basic security hygiene,” he said.

Commenting, Tim Mackey, principal security strategist at Synopsys CyRC, said for some organizations, security training is an annual affair that aligns with other compliance training.

“The worrying statistic is the 32% who state their last training was over a year ago, or that it’s not yet happened,” he said. “It is however quite important to recognize that for many businesses the pandemic has required reassessments of spending priorities, with the potential that, for some, training programs of all forms might be viewed as luxuries.”

Regarding the statistic that 42% of respondents said they have to go around the security policies of their organization to do their job, Infosecurity asked if this shows a poor engagement with the workforce, and what could security and the business be doing better?

Huynh said: “Looking at the reasons why employees are breaking the rules can help explain some of this. The top three reasons given for why they broke the rules were that personal accounts were more convenient, the IT department was too slow to respond to their needs and the security policies were too restrictive on their productivity. So, we’re seeing friction between staff and IT that suggests a breakdown in processes is occurring.”

Javvad Malik, security awareness advocate at KnowBe4, agreed that this shows poor engagement or forming of policies, without understanding the users’ needs. “Policies should not be set in stone,” Malik said. “What was a workable policy a few years ago, may not be fit for purpose today. Security departments should regularly engage with the business units of users who are subjected to the policies in order to find out any pain points and work collaboratively with them to find efficient ways of working as opposed to being the ‘department of no.’”

Elsewhere, the report claimed remote working had caused a 39% increase in the use of cloud services, and a 35% increase in the number of devices, while 75% of those polled said their IT security policy covers unapproved software, hardware and cloud services on work devices.

Malik said while it is good to have awareness of policies, it does not mean much if people do not care about them or, as the report states, if 42% are going around the policies, it does not matter if they are aware. “So, organizations should not just make their employees aware of the security policies, but encourage feedback and understand the effectiveness of policies and tweak where necessary.”

Huynh said the statistic that 88% are familiar with IT security policies was “one positive finding from the report as it suggests that security teams have done a good job at making security policies accessible and understandable.”

He added that policies should also cover the use of unapproved software and hardware, which, from this report, we learned that not every policy does. These seemingly small actions are important as the rapid shift to remote work has introduced new risks that require frequent training and continuous improvement of the security policies in place.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Manipulating Systems Using Remote Lasers

Many systems are vulnerable:

Researchers at the time said that they were able to launch inaudible commands by shining lasers — from as far as 360 feet — at the microphones on various popular voice assistants, including Amazon Alexa, Apple Siri, Facebook Portal, and Google Assistant.

[…]

They broadened their research to show how light can be used to manipulate a wider range of digital assistants — including Amazon Echo 3 — but also sensing systems found in medical devices, autonomous vehicles, industrial systems and even space systems.

The researchers also delved into how the ecosystem of devices connected to voice-activated assistants — such as smart-locks, home switches and even cars — also fail under common security vulnerabilities that can make these attacks even more dangerous. The paper shows how using a digital assistant as the gateway can allow attackers to take control of other devices in the home: Once an attacker takes control of a digital assistant, he or she can have the run of any device connected to it that also responds to voice commands. Indeed, these attacks can get even more interesting if these devices are connected to other aspects of the smart home, such as smart door locks, garage doors, computers and even people’s cars, they said.

Another article. The researchers will present their findings at Black Hat Europe — which, of course, will be happening virtually — on December 10.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk