I first wrote on this subject in May 2012 (The social media side of incident response).
Today, it is still my most popular entry on this blog with 5,430 unique views as I write. This means that in any given day since I published it, 6 people somewhere in the world have read that post... I am at once flattered and amazed that some musings derived from the good, bad and ugly of how businesses have tackled crisis communications in the past few years still very much resonate with a lot of you. So here’s the 2014 version...
A blog about information security, payments, risk, fraud, digital innovation and social media... Connect on LinkedIn?
Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts
9 February 2014
THE SOCIAL MEDIA SIDE OF INCIDENT RESPONSE... (2014 Edition)
Labels:
brand,
Crisis PR,
cybercrime,
Data Breach,
Data Privacy,
facebook,
identity theft,
Incident Response,
Infographic,
LinkedIn,
Media Response,
phishing,
Reputation Management,
Social Media,
twitter
10 October 2013
YOUR PROVIDER IS HACKED, YOU'RE ASSURED OF NO FINANCIAL LOSS. BUT ARE YOU SAFE?...
[UPDATED 20th FEBRUARY 2014] In the aftermath of the Santander and Barclays KVM hacks, @GrahamCluley kindly invited me to post my comments on his blog.
A few weeks on, I have some updates which you may find interesting…
A few weeks on, I have some updates which you may find interesting…
Labels:
AFI,
compliance,
Crisis PR,
cybercrime,
Data Breach,
Data Privacy,
data security,
FCA,
Financial Services,
Fraud,
governance,
ICO,
identity theft,
Incident Response,
National Fraud Authority,
OFT,
operational risk
11 August 2013
I AM WHO I AM... OR AM I?
Google
I have spent the last 18 months pondering on the whole sphere of identity and authentication and a number of things have happened:
The analysts continue to tell us that lax password management and policies continue to put individuals and organisations at risk (according to the Trustwave Global Security Report 2013, Welcome1 is the most commonly used password by count - followed closely by STORE123 and Password1 - whereas Password1 is still most widely used when looking at % of unique active directory samples, followed closely by password1 and Welcome1)
I have spent the last 18 months pondering on the whole sphere of identity and authentication and a number of things have happened:
The analysts continue to tell us that lax password management and policies continue to put individuals and organisations at risk (according to the Trustwave Global Security Report 2013, Welcome1 is the most commonly used password by count - followed closely by STORE123 and Password1 - whereas Password1 is still most widely used when looking at % of unique active directory samples, followed closely by password1 and Welcome1)
4 April 2013
A CONSOLIDATED VIEW ON DATA BREACHES IN 2012 - PART 2...
Google
It seems that many of you found my previous post of interest, so as promised, here’s the second part. But first, let’s all have a look at this 2min 48s video: Security Threats by the Numbers from the Cisco 2013 Annual Security Report. Unsurprisingly, the Trustwave GSR highlights that e-commerce sites were the most targeted asset, accounting for 48% of all investigations...
It seems that many of you found my previous post of interest, so as promised, here’s the second part. But first, let’s all have a look at this 2min 48s video: Security Threats by the Numbers from the Cisco 2013 Annual Security Report. Unsurprisingly, the Trustwave GSR highlights that e-commerce sites were the most targeted asset, accounting for 48% of all investigations...
27 February 2013
WILFUL BLINDNESS AND WISHFUL THINKING...
Google
Yesterday, an article on CBS Money Watch caught my eye: Businesses deluded about threat of cyber attack. The article was a short introduction to a recent survey conducted by Deloitte. And isn’t it spooky that the same old things keep cropping up everywhere?...
Unsurprisingly, the Deloitte report highlights that 88% of the businesses surveyed believe that they are not really at risk. As you would expect, they also identify lack of employee awareness and third party risks as top security vulnerabilities (46% of organisations don’t evaluate the security and privacy practices of vendors before sharing sensitive or confidential information, according to a recent Experian/Ponemon survey. If you’re not already fed up with trend predictions, see earlier blog post for my 2013 predictions.
But for me, these were not the most interesting points of the study...
Yesterday, an article on CBS Money Watch caught my eye: Businesses deluded about threat of cyber attack. The article was a short introduction to a recent survey conducted by Deloitte. And isn’t it spooky that the same old things keep cropping up everywhere?...
Unsurprisingly, the Deloitte report highlights that 88% of the businesses surveyed believe that they are not really at risk. As you would expect, they also identify lack of employee awareness and third party risks as top security vulnerabilities (46% of organisations don’t evaluate the security and privacy practices of vendors before sharing sensitive or confidential information, according to a recent Experian/Ponemon survey. If you’re not already fed up with trend predictions, see earlier blog post for my 2013 predictions.
But for me, these were not the most interesting points of the study...
28 January 2013
GAZING AT 2013: THE RIGHT FOCUS AND THE RIGHT LANGUAGE...
Google
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Labels:
CISO,
compliance,
Data Breach,
Data Privacy,
data protection,
data security,
DBIR,
EU Data Protection,
Fraud,
GRC,
ICO,
information security,
metrics,
predictions,
risk management,
Social Media,
third party
18 November 2012
DON'T ACCEPT SWEETIES FROM STRANGERS...
Google
[Updated 17th March 2013] Hello
everyone! It’s been a long time since I wrote on this blog and I have to say,
there have been so many interesting things happening that I haven’t really been
able to make my mind up on what to talk about... What spurred me into action was
a combination of various industry discussions and security conferences, the
fact that lots of us are busily preparing for the festive season (or wishing
they were!) and that all the children in my life are SO technically savvy...
24 July 2012
THE UNBEARABLE RISKINESS OF BEING... SOCIAL
Google
[Updated 4th August 2012]
The inevitability of social media in both our private and professional lives is undeniable. With social networks transforming the rules of business engagement, many businesses think the biggest risk of social media is the brand and reputational damage that could result from negative interactions or the potential disclosure of proprietary or sensitive information...
The inevitability of social media in both our private and professional lives is undeniable. With social networks transforming the rules of business engagement, many businesses think the biggest risk of social media is the brand and reputational damage that could result from negative interactions or the potential disclosure of proprietary or sensitive information...
9 May 2012
CLOSE ENCOUNTERS OF THE THIRD (PARTY) KIND...
Google
Phew... The last month was absolutely hectic, with all those conferences falling within the same short period of time! With all that, I was privileged enough to have been asked to speak at both Internet World and Infosecurity Europe. Two very different experiences... Whilst it is expected to be talking about security at an infosec conference, it is always welcome to be asked to present about security matters at an event with a different focus - in this instance, everything digital... (see my previous post on the subject). It was nevertheless surprising, walking the show floor at Internet World, talking to vendors and poring over the agendas in the various theatres, how little security featured. With everything about the show related to "cyber", not many had made the obvious leap to "cybercrime"... So, on the way to our Devil's Tower, our quest is still to find our curwen hand signs to communicate with the third (party) kind...
Phew... The last month was absolutely hectic, with all those conferences falling within the same short period of time! With all that, I was privileged enough to have been asked to speak at both Internet World and Infosecurity Europe. Two very different experiences... Whilst it is expected to be talking about security at an infosec conference, it is always welcome to be asked to present about security matters at an event with a different focus - in this instance, everything digital... (see my previous post on the subject). It was nevertheless surprising, walking the show floor at Internet World, talking to vendors and poring over the agendas in the various theatres, how little security featured. With everything about the show related to "cyber", not many had made the obvious leap to "cybercrime"... So, on the way to our Devil's Tower, our quest is still to find our curwen hand signs to communicate with the third (party) kind...
21 February 2012
UNDERSTANDING CLOUD SECURITY: PART TWO...
Google
I
thank you for your attention on the previous
post where we had a look at security considerations for the three main
cloud service models commonly referred to as SPI (SaaS, PaaS, IaaS). As promised
here’s part two looking at other cloud implementation considerations, namely:
- Cloud deployment model: public vs. private vs community vs hybrid deployments,
- Cloud location: internal vs. external hosting or combined,
19 February 2012
UNDERSTANDING CLOUD SECURITY: FINDING THE BOUNDARIES...
Google
It
seems that my previous
post on compliance and third parties struck a chord with a few of you... So
I guess it’s about time I dedicated some time to “The Cloud” specifically! Over
the past couple of years, we have seen a lot of hype and confusion as to what
The Cloud really means and what it can do for you. I think we have now reached
the stage where there is perhaps a bit of disappointment that The Cloud, due to
inflated expectations, is perhaps not a miracle...
1 February 2012
EU DATA PROTECTION LAWS – WHAT DOES IT ALL MEAN?...
Google
After yesterday’s
post on data protection, I thought it would be logical to follow with some
info on the EU
proposal for new data protection laws...
17 years ago, the EU’s 1995 Data Protection Directive set a
milestone in the history of personal data protection, and whilst its principles
are still valid, the differences in the way that each EU country implements the
law have led to an uneven level of protection for personal data. In addition, the
rules were introduced when the Internet was still in its infancy and the
digital age has brought with it increasing and sometimes unexpected challenges
for data protection. With social networking sites, cloud computing, location-based
services and smart cards, we leave digital traces with every move we make. Evidently,
we now need a new set of rules that is future-proof and fit for the digital age.
Subscribe to:
Posts (Atom)