GDPR Has Had Successes, Requires Public Knowledge of Data Spread

GDPR Has Had Successes, Requires Public Knowledge of Data Spread

The success of the GDPR has been praised, but it is in conflict with the amount of data we create and how we do not consider consent.

Speaking during the Westminster Events Conference on data protection, Dr Subhajit Basu, associate professor of information technology (cyber law) at the University of Leeds and chair of the British and Irish Law Education and Technology Association (BILETA), said while technology drives our lives, the amount of data we create “is growing exponentially.”

He claimed that the number of data protection and privacy laws that have been enacted around the world “is a testament to the importance of data protection globally, or a desire by many countries to qualify trade with the European Union to meet its adequacy requirements.” So after Brexit, the opportunity is there for the UK to become a leading role model for a society empowered by data decisions, but to fulfil this ambition “the UK will have to build a robust legal framework in terms of data protection and cybersecurity.”

The Telecommunications Security bill received its latest reading in the House of Commons this week, and Basu called this “a step in the right direction” as it will propose fines on telcos if they fail to tighten security”, but post Brexit, the UK will need to improve its governance structure for handling data.

“In order to meet this potential, we must find a way to balance the flow of user data, whilst at the same ensuring privacy, security, safety and ethical standards,” he said.

Basu called this a “fundamental” step, as he advocated for a continuation of a strong, user centric data protection law. However, he said that “data governance is just plain complicated” as data protection is often seen as separate from the right to privacy, and the focus is on due process and there are moves to find the best solution.

He went on to say that he has “a lot of faith in the GDPR” as this is the right step towards user empowerment for transparency and control to users when it comes to data sharing. “Data subjects are given more choices on how their information is collected, processed and used,” he said. “But hounding users with more rights means you have a role in protecting their data, but most users continue to hand their over data impatiently, causing this paradox where our concerns are not reflected in our behavior.”

Basu also said he has concerns about “consent in data protection law” as he sees that consent gives an “illusion of control, rather than any meaningful control from a data subject’s point of view.” This is because the process of obtaining consent has become more complicated, and will become more complicated as we move towards using more IoT and AI.

This is also paired with data protection fatigue, as users are asked to read privacy documentations and policy before giving consent and this makes the process tedious. “The sheer number of documents that you need to navigate through is beyond any human capacity,” he said.

He concluded by calling a “lacklustre attitude” to GDPR as being alarming, and pointed at the ICO’s supervisory and adjunct role “without proper demarcation as difficult to accept.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Defining Codes of Conduct to Enable Post Brexit GDPR Compliance

Defining Codes of Conduct to Enable Post Brexit GDPR Compliance

Harmonization of data protection regulation should still be the aim, despite Brexit, to enable companies to trade across Europe.

Speaking during the Westminster Events Conference on data protection, Chris Combemale, CEO of the Data and Marketing Association, said that since the implementation of GDPR in May 2018, the harmonization of data protection “has been put at risk by data protection authorities across Europe” as they applied the legislation “in radically different ways in each country.”

This can affect customer trust, economic growth and job creation in relation to processing and getting to know customers better.

Combemale said data protection authorities (DPAs) should “apply the role as it is written.”

Looking at the code of conduct for GDPR, which he said was intended for relevant sectors and to achieve harmonization across Europe, in the first instance of “co-regulation” by data protection legislation, Combemale explained: “The logic is that a GDPR code of conduct, operated consistently across 27 or 28 countries, via an industry monitoring body, can provide a consistent interpretation of key aspects of GDPR within an industry sector.”

This would be across industry verticals and different types of businesses, as determined by Article 40 of the GDPR. He said the data and marketing industry has been working hard to achieve clarification of GDPR across Europe, through a combination of an EU code of conduct and national codes of conduct.

This has seen a European code of conduct being produced, while the Austrian DPA has approved a code of conduct for the use of third party data, as approved by the Austrian data and marketing association. The Italian DPA has approved a specific code of conduct for business information services, which is in the process of being approved.

In the UK, he said the Data and Marketing Association is working with the ICO to create a data and marketing code of conduct “including recognition of the existing data and marketing commission as the industry monitoring body.

“All these codes of conduct must reflect GDPR text in way it was written and applied through the lens of sector knowledge and expertise,” he said.

The next step is to understand the scope of business legitimate interests and what that is within the text of GDPR. “We will work hard, using our industry expertise, to ensure all approved data and marketing codes of conduct across Europe and for our industry reflect this,” he said, “in order to understand the harmonization and consistency that was intended by GDPR being a regulation rather than a directive.”

If, in a worst case scenario, the UK is denied data adequacy, he concluded that industry codes of conduct can offer a basis for data transfers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DDoS Attacks Against Online Retailers Increase Four-Fold During Pandemic

DDoS Attacks Against Online Retailers Increase Four-Fold During Pandemic

The number of DDoS attacks targeting e-commerce in Europe has increased four-fold over the last eight months.

According to research by Stormwall, between February and October 2020, the number of DDoS attacks targeted at online retail services quadrupled compared to the same period last year.

It claimed the growth in attack number is primarily contributed to the increased competition between online retailers during the global COVID-19 health crisis, and due to attackers extorting money from businesses. “Cyber-criminals use website downtime as a leverage, promising to stop the attack and restore the service operation, once the victim company pays the ransom,” the company said.

Zach Varnell, senior AppSec consultant at nVisium, said: ““DDoS attacks often go hand-in-hand with ransom notes demanding money to stop the attack. If these ransom notes get paid even at a small fraction of their frequency, DDoS operators will be incentivized to continue such schemes. This sometimes includes making good on their promise to attack those who do not pay up.

“Financial services were originally hit hard by these DDoS ransom threats and for obvious reasons as rich targets for cybercrime. Since there are far more online retailers than financial institutions today, and multiplying in their online presence owing to COVID-19, it is highly likely that targeting this industry is now becoming a lucrative source of ransom threats through DDoS attacks.”

He also pointed out that there are more customers shopping online now and therefore plenty of sensitive customer data to breach and exfiltrate, threatening online retailers who have previously not been security savvy.

Asked if he believed attackers are going after online retailers for financial gain, Brandon Hoffman, CISO at Netenrich, said: “They are 100% following the money. There has been a huge surge of online spending due to COVID-19 and a huge surge in furniture and home remodelling purchases. Many speculate that due to COVID-19, people are not able to take vacations so instead they are spending that budget improving their homes where they are essentially stuck more than normal. Coupled with the closing of physical stores worldwide, this explains the attack focus.”

Stormwall also found the number of attacks on online electronics stores had increased five-fold, the number of attacks on online furniture stores increased by eight-fold, while attacks aimed at online renovation stores grew by seven-fold.

“E-commerce has always been an attractive field to cyber-criminals, and during the pandemic, hackers’ interest in the sector developed even more,” said Ramil Khantimirov, CEO and co-founder of StormWall.

“Criminals are actively advancing the methods of DDoS attacks, and retailers are finding it increasingly difficult to defend against them. This is a serious threat. The new trend is that the attackers are attempting to find vulnerabilities that require a small number of requests per second to make a website unavailable. An effective defense system that can shield against this type of campaign needs to have intelligent DDoS protection, like proactive analysis and self-learning.”

Furthermore, the number of DDoS attacks over the HTTP protocol has risen by 296% between February and September 2020, compared to the same period last year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Acronis and World Economic Forum Partner to Combat Global Cybercrime

Acronis and World Economic Forum Partner to Combat Global Cybercrime

Cyber-protection firm Acronis has announced that it is collaborating with the World Economic Forum (WEF) Center for Cybersecurity to address rising cybercrime around the globe.

The WEF Center for Cybersecurity is an independent and impartial global platform focused on fostering international dialogues and collaboration to tackle cybersecurity challenges, convening key stakeholders from public and private sectors.

Through the partnership, Acronis will engage in the Cyber-Risk and Corporate Governance project to help establish a baseline understanding of key cybersecurity issues, while providing guidance on strategies for security and cyber-resiliency.

“The Forum’s most recent Global Risk Report noted that the top five global threats were cybersecurity-related, with cyber-attacks and data theft among the most immediate dangers,” said Acronis founder and CEO Serguei “SB” Beloussov. “Having been at the forefront of the new IT discipline of cyber-protection, Acronis brings a unique, comprehensive perspective to the protection challenges facing today’s institutions. By collaborating with our peers, we can ensure business and government leaders have the tools and frameworks needed to meet their cybersecurity obligations of the modern world.”

René Bonvanie, chairman of the board of Acronis, added: “Cybersecurity is critically important in the digital world, yet every day we witness successful breaches. Acronis uniquely offers a cyber-protection platform that natively integrates the five layers of protection into a single offering: prevention, detection, response, recovery and forensics.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Egregor Ransomware Steps into Maze Group’s Shoes

New Egregor Ransomware Steps into Maze Group’s Shoes

Security experts are warning that a new ransomware group is rapidly escalating threat activity, with double extortion attacks on scores of victims so far in Q4.

The Egregor group first came to light with an attack on Barnes & Noble and video game developers Ubisoft and Crytek back in October, according to Digital Shadows.

In fact, the group has been active since September, when it compromised 15 victims. Then came a massive 240% spike in numbers, with 51 organizations hit the following month. As of November 17, it had added a further 21 victims.

According to the security vendor, a plurality of Egregor victims come from the industrial goods and services sector (38%), and the vast majority so far (83%) have been US-based.

The malware itself has been designed with multiple anti-analysis measures built in, such as code obfuscation and packed payloads, Digital Shadows claimed.

“More specifically, Windows application programming interfaces (APIs) are leveraged to encrypt the payload data. Unless security teams can present the correct command-line argument, then the data cannot be decrypted, and the malware cannot be analyzed,” it added.

“When the correct command-line argument is presented, the malware executes by injecting into iexplore.exe process, encrypting all text files and documents, and enclosing a ransom note within each folder that has an encrypted file. This process includes files on remote machines and servers through checks on LogMeIn event logs.”

Like many groups operating today, the actors behind Egregor maintain a dark web site on which they post data stolen from victims in a bid to force a ransom payment. In this respect it has followed the lead of the infamous Maze group, which ceased operations in October.

For example, it posted 200MB of data on in-game assets from Ubisoft and claimed to have source code from an unreleased title, Watchdogs: Legion. In the case of Crytek, 400MB of data was confirmed stolen related to titles Warface and Arena of Fate, Digital Shadows noted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Spies Urge Firms to Patch MobileIron Bug ASAP

UK Spies Urge Firms to Patch MobileIron Bug ASAP

UK government security experts are urging organizations to rapidly patch a remote code execution flaw in MobileIron products being actively exploited in the wild by nation state groups.

The notice from GCHQ’s National Cyber Security Centre (NCSC) explained that CVE-2020-15505, which affects the mobile device management company’s MobileIron Core and Connector products, could allow a remote attacker to execute arbitrary code on a system.

It also noted that the US Cybersecurity and Infrastructure Security Agency (CISA) pointed out in October that the vulnerability was being chained with the Zerologon bug CVE-2020-1472 in attacks.

Although the identity of the nation state actors was not disclosed, the vulnerability was recently featured on the NSA’s Top 25 list of the most exploited bugs by Chinese attackers.

“A proof of concept exploit became available in September 2020 and since then both hostile state actors and cyber-criminals have attempted to exploit this vulnerability in the UK,” noted the NCSC alert.

“These actors typically scan victim networks to identify vulnerabilities, including CVE-2020-15505, to be used during targeting (T1505.002). In some cases, when the latest updates are not installed, they have successfully compromised systems. The healthcare, local government, logistics and legal sectors have all been targeted but others could also be affected.”

A patch has been available since June, and the NCSC urged any affected organizations to apply it immediately. Those running vulnerable systems should also undertake regular network scans and audits to identify suspicious activity in case they have already been breached, it added.

“Mobile device management servers are by definition reachable from the public internet making them opportune targets. Offering a gateway to potentially compromise every mobile device in the organization, the attraction to attackers is clear,” argued Tom Davison, international technical director of Lookout. 

“This highlights not just the importance of patching open vulnerabilities, but also the criticality of having a dedicated mobile security capability that is distinct from device management infrastructure.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Sopra Steria: Ryuk Attack May Cost Us $60m

Sopra Steria: Ryuk Attack May Cost Us $60m

French IT services giant Sopra Steria has admitted a ransomware attack on its systems last month is likely to cost the company tens of millions of dollars.

The Paris-headquartered firm, which is a supplier to the UK’s NHS, was hit by a new variant of the infamous Ryuk family, forcing systems offline.

In an update yesterday, the firm claimed that the attack would negatively impact its gross operating margin by between €40m ($48m) and €50m ($60m), although €30m will be covered by cyber insurance.

The serious financial impact is due to the extensive remediation and “differing levels of unavailability” of various systems since the attack, it said.

This is despite the company claiming it was able to “rapidly” block the attack on discovery.

“The measures implemented immediately made it possible to contain the virus to only a limited part of the group’s infrastructure and to protect its customers and partners,” it said.

The firm claimed it had not identified any leaked data or damage to customer systems. The slow pace of restoring systems would seem to indicate that it decided not to pay the ransom.

“The secure remediation plan launched on October 26 is nearly complete,” it continued. “Access has progressively been restored to workstations, R&D and production servers, and in-house tools and applications. Customer connections have also been gradually restored.”

The attack is expected to push Sopra Steria’s organic growth for 2020 into negative territory, by between -4.5% and -5%, it said.

This is yet another cautionary tale of the destructive power of human-operated ransomware. It ranks alongside aluminium giant Norsk Hydro ($41m) and IT services firm Cognizant (up to $70m) as one of the most serious from a financial perspective.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk