New Code to Force Tech Giants to Provide Greater Data Transparency and Choice

New Code to Force Tech Giants to Provide Greater Data Transparency and Choice

The UK government has unveiled plans to develop a new statutory code for tech companies that is designed to give customers more choice and control over their data.

The Department for Digital, Culture, Media and Sport (DCMS) said that a dedicated Digital Markets Unit will work alongside regulators such as Ofcom and the Information Commissioners Office (ICO) to create and enforce the code, which will govern the behavior of digital platforms, including those funded by digital advertising currently dominating the market, such as Google and Facebook. Measures are likely to include forcing such firms to be more transparent about how they are using customer data and to offer consumers a choice on whether they’d like to receive personalized advertising.

Another important aim of the code is to harness more competition within the online publishing industry by helping ensure smaller businesses aren’t disadvantaged by tech giants. This could include ensuring small businesses have fair access to platform services that help them grow their online business, such as digital advertising.

The unit, which will be part of the Competitions and Markets Authority (CMA), will begin operating from April 2021, and may have the power to suspend, block and reverse decisions made by tech firms as well as impose financial penalties for non-compliance.

Issues surrounding the use of data online have come into sharper focus this year, with the COVID-19 pandemic leading to a huge rise in digital users, including the sharing of creative content and advertising of small businesses’ products and services.

Digital secretary Oliver Dowden commented: “I’m unashamedly pro-tech and the services of digital platforms are positively transforming the economy, bringing huge benefits to businesses, consumers and society.

“However, there is growing consensus in the UK and abroad that the concentration of power among a small number of tech companies is curtailing growth of the sector, reducing innovation and having negative impacts on the people and businesses that rely on them. It is time to address that and unleash a new age of tech growth.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SMB Skills Gaps and #COVID19 Imperil Cyber-Resilience

SMB Skills Gaps and #COVID19 Imperil Cyber-Resilience

Skills gaps and mass remote working are the biggest security challenges facing small- and medium-sized businesses (SMBs) today, according to new research from Infosecurity Europe.

The organizers behind the number one cybersecurity event in the region canvassed opinion from nearly 3700 industry experts via a Twitter poll.

A plurality (42%) cited a lack of security expertise as the number one challenge to cyber-resilience facing SMBs, while COVID-related lockdowns came second top with 34%.

According to the latest global figures, industry skills shortages have come down since last year, from 4.07 million to 3.12 million. However, while many are joining the industry, the narrowing gap can partly be explained by job losses during the pandemic.

SMBs often find it hardest to recruit and have fewer resources to spend on training. That’s a concern considering half (50%) of respondents claimed small firms are mainly responsible for in-house education and training.

SMBs are also often hardest hit by recession. A recent study from O2 and the Center for Economic Business Research (CEBR) claimed that small businesses would be hit six-times harder than after the financial crash of 2008.

Unsurprisingly, a quarter (24%) of small businesses said they are spending less because of the pandemic, with only 18% spending more to improve cyber-resilience. Perhaps reassuringly, over two-fifths (43%) said “little has changed” financially.

“Typical challenges such as lack of budget, staff being stretched thin and a changing threat environment have all been amplified in 2020. For many small businesses, the focus was on making sure they could still operate, and concerns like cyber-resilience were not necessarily a priority,” says Heidi Shey, principal analyst at Forrester Research.

“If business is down, cuts have to come from somewhere. Harder-hit sectors like retail or travel had to make different choices than those in a more fortunate position. Most spending was reactive; to support remote work, many had to make investments in things like laptops, VPNs and collaboration applications.”

Infosecurity Europe is scheduled to take place June 8-10 2021 at London’s Olympia.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One in Seven #BlackFriday Emails Are Malicious

One in Seven #BlackFriday Emails Are Malicious

More than one in seven emails sent on Black Friday today could be a scam, security experts have warned.

Vade Secure claims to protect one billion inboxes around the world with AI-powered security for Microsoft 365. Its Current Events tracker has detected a predictable spike in malicious messages containing text about the shopping discount extravaganza today.

It said 9% of US emails and 15% in Europe were malicious — spoofing big-name retail brands such as Lidl, Sephora, Target and, most popular, Amazon.

“We are issuing an alert about the Black Friday event in order to warn ISPs and businesses using Microsoft 365 to help them protect customers and clients from malicious emails. Seasonal threats of this nature can be predicted and monitored more easily than surprise attacks, so sysadmins should be aware of the surge in Black Friday email exploits,” explained Vade Secure’s chief product and services officer, Adrien Gendre.

“The rise of online shopping and home working has created new vectors for attackers, so security professionals need to guard carefully against new threats as they emerge. The best way to defeat email threats is to use complementary layers of protection involving both tech and humans.”

The United States Cybersecurity and Infrastructure Security Agency (CISA) also issued an alert today, warning that criminals may be looking to cash-in both online and in-person.

“Malicious people may be able to obtain personal information (such as credit card numbers, phone numbers, account numbers and addresses) by stealing your wallet, overhearing a phone conversation, rummaging through your trash (a practice known as dumpster diving) or picking up a receipt at a restaurant that has your account number on it,” it claimed.

“If a thief has enough information, he or she may be able to impersonate you to purchase items, open new accounts or apply for loans.”

The agency urged shoppers to check company privacy policies, monitor their bank statements, use passwords and other security features where available and to avoid sharing personal information online.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NHS Error Exposes Data on Hundreds of Patients and Staff

NHS Error Exposes Data on Hundreds of Patients and Staff

Hundreds of NHS patients and staff have had their personal data exposed to strangers after internal process failures, it has emerged this week.

Human error at NHS Highland earlier this month led to the personal information of 284 patients with diabetes being shared via email with 31 individuals, according to local reports.

Although details of medical history were not in the spreadsheet accidentally sent to the 31 people, it did apparently include names, dates of births, contact information and hospital identification numbers.

That’s more than enough to craft convincing follow-on phishing emails.

The affected patients have been contacted and the Information Commissioner’s Office (ICO) notified, although it is not the first time the trust has been found wanting. In 2018 it apparently exposed the names of over 30 patients with HIV.

“Due to the fact that the information was stored on a spreadsheet and easily emailed out serves as a reminder that even if organizations have good security controls, they will not be effective unless there is a culture of security and staff understand the importance of securing data,” argued KnowBe4 security awareness advocate, Javvad Malik.

“It is an organization’s responsibility to inform staff of the importance of cybersecurity and provide the tools, training and processes needed to keep information secure.”

The second breach was reported at Basingstoke hospital, run by Hampshire Hospitals NHS Foundation Trust in southern England.

Although reported to the ICO in July, it has only just come to light in papers published by the trust, according to local media.

This time a spreadsheet containing personal information on 1000 members of staff at the hospital was shared with senior managers.

The same hospital suffered another breach the following month, after details of a woman who suffered a stillbirth were apparently published online.

The healthcare sector suffered 214 reported data incidents in Q1 2020-21, more than any other and accounting for about 15% of the total for the period, according to the ICO.

Human error accounted for a large number of these incidents. For example, incidents involving  data emailed, posted or faxed to incorrect recipients and incorrect use of BCC comprised nearly a third (30%) of the total.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Friday Squid Blogging: Diplomoceras Maximum

Diplomoceras maximum is an ancient squid-like creature. It lived about 68 million years ago, looked kind of like a giant paperclip, and may have had a lifespan of 200 years.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Undermining Democracy

Last Thursday, Rudy Giuliani, a Trump campaign lawyer, alleged a widespread voting conspiracy involving Venezuela, Cuba, and China. Another lawyer, Sidney Powell, argued that Mr. Trump won in a landslide, the entire election in swing states should be overturned and the legislatures should make sure that the electors are selected for the president.

The Republican National Committee swung in to support her false claim that Mr. Trump won in a landslide, while Michigan election officials have tried to stop the certification of the vote.

It is wildly unlikely that their efforts can block Joe Biden from becoming president. But they may still do lasting damage to American democracy for a shocking reason: the moves have come from trusted insiders.

American democracy’s vulnerability to disinformation has been very much in the news since the Russian disinformation campaign in 2016. The fear is that outsiders, whether they be foreign or domestic actors, will undermine our system by swaying popular opinion and election results.

This is half right. American democracy is an information system, in which the information isn’t bits and bytes but citizens’ beliefs. When peoples’ faith in the democratic system is undermined, democracy stops working. But as information security specialists know, outsider attacks are hard. Russian trolls, who don’t really understand how American politics works, have actually had a difficult time subverting it.

When you really need to worry is when insiders go bad. And that is precisely what is happening in the wake of the 2020 presidential election. In traditional information systems, the insiders are the people who have both detailed knowledge and high level access, allowing them to bypass security measures and more effectively subvert systems. In democracy, the insiders aren’t just the officials who manage voting but also the politicians who shape what people believe about politics. For four years, Donald Trump has been trying to dismantle our shared beliefs about democracy. And now, his fellow Republicans are helping him.

Democracy works when we all expect that votes will be fairly counted, and defeated candidates leave office. As the democratic theorist Adam Przeworski puts it, democracy is “a system in which parties lose elections.” These beliefs can break down when political insiders make bogus claims about general fraud, trying to cling to power when the election has gone against them.

It’s obvious how these kinds of claims damage Republican voters’ commitment to democracy. They will think that elections are rigged by the other side and will not accept the judgment of voters when it goes against their preferred candidate. Their belief that the Biden administration is illegitimate will justify all sorts of measures to prevent it from functioning.

It’s less obvious that these strategies affect Democratic voters’ faith in democracy, too. Democrats are paying attention to Republicans’ efforts to stop the votes of Democratic voters ­- and especially Black Democratic voters -­ from being counted. They, too, are likely to have less trust in elections going forward, and with good reason. They will expect that Republicans will try to rig the system against them. Mr. Trump is having a hard time winning unfairly, because he has lost in several states. But what if Mr. Biden’s margin of victory depended only on one state? What if something like that happens in the next election?

The real fear is that this will lead to a spiral of distrust and destruction. Republicans ­ who are increasingly committed to the notion that the Democrats are committing pervasive fraud -­ will do everything that they can to win power and to cling to power when they can get it. Democrats ­- seeing what Republicans are doing ­ will try to entrench themselves in turn. They suspect that if the Republicans really win power, they will not ever give it back. The claims of Republicans like Senator Mike Lee of Utah that America is not really a democracy might become a self-fulfilling prophecy.

More likely, this spiral will not directly lead to the death of American democracy. The U.S. federal system of government is complex and hard for any one actor or coalition to dominate completely. But it may turn American democracy into an unworkable confrontation between two hostile camps, each unwilling to make any concession to its adversary.

We know how to make voting itself more open and more secure; the literature is filled with vital and important suggestions. The more difficult problem is this. How do you shift the collective belief among Republicans that elections are rigged?

Political science suggests that partisans are more likely to be persuaded by fellow partisans, like Brad Raffensperger, the Republican secretary of state in Georgia, who said that election fraud wasn’t a big problem. But this would only be effective if other well-known Republicans supported him.

Public outrage, alternatively, can sometimes force officials to back down, as when people crowded in to denounce the Michigan Republican election officials who were trying to deny certification of their votes.

The fundamental problem, however, is Republican insiders who have convinced themselves that to keep and hold power, they need to trash the shared beliefs that hold American democracy together.

They may have long-term worries about the consequences, but they’re unlikely to do anything about those worries in the near-term unless voters, wealthy donors or others whom they depend on make them pay short-term costs.

This essay was written with Henry Farrell, and previously appeared in the New York Times.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DTX Cybersecurity Mini Summit: How CISOs Can Transform an Organization’s Cyber-Capabilities

#DTX Cybersecurity Mini Summit: How CISOs Can Transform an Organization’s Cyber-Capabilities

The ways in which CISOs should go about transforming the cybersecurity capabilities of an entire organization was discussed during the DTX Cyber Security Mini Summit by Michael Jenkins MBE, CISO at Brunel University.

Jenkins previously spent a long career in the military including positions in counter-intelligence, and also played a major role in planning security for the 2012 London Olympics. In 2017, he was tasked with turning Brunel University’s cybersecurity capabilities into one of the best in the entire sector, through a five-year strategy. “Ultimately, the goal is taking a business from a low level of maturity in cyber-resilience right the way through to the best in the sector,” he noted.

Around three years into the plan, Jenkins discussed the approach he has taken to try and fulfil this ambitious target. He said the first step was inspiring everyone in the organization, including researchers, staff and students, “to care about data, probably more than the criminal cares to steal it from us.”

This was achieved by engaging in regular conversations with people on campus, helping them to learn about how cyber-criminals operate and “to see that its a very credible goal that we needed to achieve together.” Jenkins added that it was also important for him to understand the work of academics and students at the institution to allow him to “help secure their data in a way that is acceptable to them but is also acceptable to us as a community.” This enables them to understand why particular security measures were in place, and be accepting of it.

The next element was developing the right strategic team and partners, including a small knit of vendors who are well versed with the individual needs of Brunel University and its cybersecurity strategy. This strategy included the development of compartmentalized “safe data havens” and the ability to monitor access control for threats in the network. Jenkins explained: “I had to mould that and balance it to the business that we were – we aren’t a bank, insurer or top end government department, we’re a university, so it’s all about proportionately and sensible risk-based intelligence driven activity.”

Such a capability has now been built, and is leading towards a zero-trust model at the end of the five years. He emphasized how important it has been to ensure everyone understands this end goal, and why it is needed in the face of the threats the university faces. He noted that major universities such as Brunel are a major target of sophisticated threat actors such as organized crime gangs and nation states.

To help get this buy-in from IT staff and the executive board, Jenkins utilizes regular simulated attack exercises to demonstrate just how damaging a successful attack could be. “It all goes back to everybody understanding the why – why do we want to do things this way,” he said. “One of the great things we’ve developed over the last couple of years is providing situational awareness to all our IT practitioners and major leaders and staff in how an attacker enters a network, their lateral movements, how they get the elevated privileges, how they conduct their actions on the objective – the entire end-to-end kill chain.”

There have been many advantages to such simulated exercises, according to Jenkins, and in particular, these are greater buy-in from the staff and board, as well as identifying weaknesses within the business. He added: “It gives confidence to the board that their money is being well spent.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk