The always eagerly awaited Verizon DBIR 2014 was released earlier this year. As always, with a nice cup of coffee and some smooth jazz playing in the background, I will endeavour to distil the essence of this always excellent publication... Well, this year, the DBIR departs from just analysing data breaches to looking at 63,347 confirmed security incidents, of which 1,367 were confirmed data breaches (compared to 621 for 2012) across 95 countries (compared to 27 in 2012). This gives far greater richness to the data set and the insights that can be derived from it (rightly so, the DBIR team notes that incidents need not necessarily result on data loss to have a significant impact on an organisation – I couldn’t agree more!). Also don’t miss the month by month review of the major incidents of 2013 on pages 3 & 4, that’ll get you in the mood...
A blog about information security, payments, risk, fraud, digital innovation and social media... Connect on LinkedIn?
Showing posts with label data security. Show all posts
Showing posts with label data security. Show all posts
10 October 2013
YOUR PROVIDER IS HACKED, YOU'RE ASSURED OF NO FINANCIAL LOSS. BUT ARE YOU SAFE?...
[UPDATED 20th FEBRUARY 2014] In the aftermath of the Santander and Barclays KVM hacks, @GrahamCluley kindly invited me to post my comments on his blog.
A few weeks on, I have some updates which you may find interesting…
A few weeks on, I have some updates which you may find interesting…
Labels:
AFI,
compliance,
Crisis PR,
cybercrime,
Data Breach,
Data Privacy,
data security,
FCA,
Financial Services,
Fraud,
governance,
ICO,
identity theft,
Incident Response,
National Fraud Authority,
OFT,
operational risk
4 April 2013
A CONSOLIDATED VIEW ON DATA BREACHES IN 2012 - PART 2...
Google
It seems that many of you found my previous post of interest, so as promised, here’s the second part. But first, let’s all have a look at this 2min 48s video: Security Threats by the Numbers from the Cisco 2013 Annual Security Report. Unsurprisingly, the Trustwave GSR highlights that e-commerce sites were the most targeted asset, accounting for 48% of all investigations...
It seems that many of you found my previous post of interest, so as promised, here’s the second part. But first, let’s all have a look at this 2min 48s video: Security Threats by the Numbers from the Cisco 2013 Annual Security Report. Unsurprisingly, the Trustwave GSR highlights that e-commerce sites were the most targeted asset, accounting for 48% of all investigations...
27 February 2013
WILFUL BLINDNESS AND WISHFUL THINKING...
Google
Yesterday, an article on CBS Money Watch caught my eye: Businesses deluded about threat of cyber attack. The article was a short introduction to a recent survey conducted by Deloitte. And isn’t it spooky that the same old things keep cropping up everywhere?...
Unsurprisingly, the Deloitte report highlights that 88% of the businesses surveyed believe that they are not really at risk. As you would expect, they also identify lack of employee awareness and third party risks as top security vulnerabilities (46% of organisations don’t evaluate the security and privacy practices of vendors before sharing sensitive or confidential information, according to a recent Experian/Ponemon survey. If you’re not already fed up with trend predictions, see earlier blog post for my 2013 predictions.
But for me, these were not the most interesting points of the study...
Yesterday, an article on CBS Money Watch caught my eye: Businesses deluded about threat of cyber attack. The article was a short introduction to a recent survey conducted by Deloitte. And isn’t it spooky that the same old things keep cropping up everywhere?...
Unsurprisingly, the Deloitte report highlights that 88% of the businesses surveyed believe that they are not really at risk. As you would expect, they also identify lack of employee awareness and third party risks as top security vulnerabilities (46% of organisations don’t evaluate the security and privacy practices of vendors before sharing sensitive or confidential information, according to a recent Experian/Ponemon survey. If you’re not already fed up with trend predictions, see earlier blog post for my 2013 predictions.
But for me, these were not the most interesting points of the study...
28 January 2013
GAZING AT 2013: THE RIGHT FOCUS AND THE RIGHT LANGUAGE...
Google
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Labels:
CISO,
compliance,
Data Breach,
Data Privacy,
data protection,
data security,
DBIR,
EU Data Protection,
Fraud,
GRC,
ICO,
information security,
metrics,
predictions,
risk management,
Social Media,
third party
18 November 2012
DON'T ACCEPT SWEETIES FROM STRANGERS...
Google
[Updated 17th March 2013] Hello
everyone! It’s been a long time since I wrote on this blog and I have to say,
there have been so many interesting things happening that I haven’t really been
able to make my mind up on what to talk about... What spurred me into action was
a combination of various industry discussions and security conferences, the
fact that lots of us are busily preparing for the festive season (or wishing
they were!) and that all the children in my life are SO technically savvy...
22 April 2012
WHO ARE YOU PREACHING TO ANYWAY?...
Google
I recently was
privileged enough to be asked to present at a merchant forum in London. Interestingly,
the intended recipients had been very much in the driving seat since they had
selected the topics themselves. After my previous posts (Part 1 and Part 2) on
connecting the dots between information security, risk and fraud, you can
imagine my pleasure that I, alongside my fellow speakers, were asked to do just
that... A delightfully interactive audience, some very interesting chats at the
breaks and the recent buzz about the value of security conferences prompted me
to share some thoughts on how actively to engage with your stakeholders and get
the results you need...
21 February 2012
UNDERSTANDING CLOUD SECURITY: PART TWO...
Google
I
thank you for your attention on the previous
post where we had a look at security considerations for the three main
cloud service models commonly referred to as SPI (SaaS, PaaS, IaaS). As promised
here’s part two looking at other cloud implementation considerations, namely:
- Cloud deployment model: public vs. private vs community vs hybrid deployments,
- Cloud location: internal vs. external hosting or combined,
8 February 2012
THE TRUTH BEHIND DATA BREACHES...
Google
I was pleased to see the release of the Trustwave
2012 Global Security Report as I find it always a very good source of information! This year’s report analyses 300 data breach investigations across
18 countries and, unsurprisingly, 89% of
the breaches involved the theft of customer records, including payment card
data and other personally identifiable information such as email addresses.
1 February 2012
EU DATA PROTECTION LAWS – WHAT DOES IT ALL MEAN?...
Google
After yesterday’s
post on data protection, I thought it would be logical to follow with some
info on the EU
proposal for new data protection laws...
17 years ago, the EU’s 1995 Data Protection Directive set a
milestone in the history of personal data protection, and whilst its principles
are still valid, the differences in the way that each EU country implements the
law have led to an uneven level of protection for personal data. In addition, the
rules were introduced when the Internet was still in its infancy and the
digital age has brought with it increasing and sometimes unexpected challenges
for data protection. With social networking sites, cloud computing, location-based
services and smart cards, we leave digital traces with every move we make. Evidently,
we now need a new set of rules that is future-proof and fit for the digital age.
Subscribe to:
Posts (Atom)