Cybercrime is a growing threat

Cybercrime

Most government and industry experts agree that cybercrime is set to grow massively over the next few years. In order for individuals and companies to understand how to deal with it, they must first understand the nature of the threat, and what measures can be to prevent it.

Ransomware

The recent spate of cyberattacks, including the one on Travelex, highlights the growing use of ransomware as the preferred crime of choice. Ransomware attacks are becoming more and more common, and are not simply aimed at big companies and corporations anymore.

Many ransomware attacks are aimed at hospitals, local and national government bodies, large and small businesses as well as private individuals.

Cybersecurity refers to a number of measures that can be taken by any organisation or individual that can help to prevent this type of threat, as well as all other types of cybercrime.

Information theft 

A lot of cybercrime involves trying to fraudulently obtain money from individuals or businesses, and it often includes theft of information or personal data. Such information is usually highly sensitive, and any type of data breach is a serious issue for organisations, both legally and financially.

Most organisations hold a significant amount of information about their customers and clients, which is potentially at risk from any type of cyber attack. Data protection has become a necessity for any businesses, who must operate under the framework of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

Cyber Essentials

In addition to knowing how to protect customer data, it is crucial that any business knows the basics of how to protect themselves against a cyber attack. Cyber Essentials is a UK Government initiative that provides detailed guidance on how a business can develop an effective cybersecurity programme.

It covers areas such as securing an internet connection, how to secure hardware and software, controlling access to data and devices, protection from viruses and malware and how to make sure this is updated on a continual basis.

Cyber Essentials Plus

The government also offers a program known as Cyber Essentials Plus, which allows an individual or business to receive certification from an independent body, that they are fully compliant with the principles of cyber essentials.

This verification can have real benefits for any business. Aside from being listed in a government directory of compliant organisations, it sends a message to existing and new customers that the business takes its cybersecurity responsibilities extremely seriously.

IASME

The Cyber Essentials program is delivered by the government with a partner consortium, the IASME. They oversee the certification process, and have a wealth of experience in helping a number of industries, including healthcare and defence, develop effective cybersecurity initiatives and programmes.

They also have extensive experience in helping develop cybersecurity defences for internet-enabled devices (IoT), where many of the future threats to cybersecurity will come from.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Is GDPR going stateside?

GDPR going stateside

The introduction of the General Data Protection Regulation – a.k.a. GDPR – was introduced in 2018. This new framework standardised and updated data protection law across the European market and most importantly gave consumers more say over how their data is handled, stored and shared.

However, considering how quickly data collection and analysis technologies are developing, this legislation wasn't a one-size-fits-all solution. Subsequently, there are a few grey areas that left many organisations feeling confused – which is risky, considering the size of the potential fines.

Now, it seems that similar legislation with its own unique nuances will appear in the United States, adding a whole new layer of data privacy legislation for companies to navigate. Here, we discuss what American data privacy law is likely to bring going into 2020.

GDPR USA – What to expect

Although data privacy is a global issue, every region is developing its own distinct regulations. Although it's likely there will be similarities between GDPR and American data privacy legislation, currently, there are no plans for a comprehensive, nation-wide GDPR USA. Instead – much to the dismay of many international companies – every state is drawing up its own plan. Currently, the two major ones businesses need to be aware of are California’s Consumer Privacy Act (CCPA) and the SHIELD Act.

CCPA

California’s Consumer Privacy Act, or CCPA, came into force as of 1 January 2020. The legislation has similarities with GDPR, however, there are important differences. For instance, under GDPR users must opt-in to third-party data sharing whereas, under CCPA, they need to opt-out. This means companies will have to have customised terms and conditions forms for Californian users. That said, the good news is that CCPA isn't as far-reaching as GDPR. If your company turnover is less than $25 million and you don't handle the data of more than 50,000 then the rules don't apply.

SHIELD Act

In July 2019 New York State passed the Stop Hacks and Improve Electronic Data Security Act (SHIELD), which will come into effect on 21 March 2020. Similarly to GDPR, this law is designed to standardise data privacy requirements. However, this is where it can get confusing; the wording of the legislation is suitably vague, with statements such as "data security should be appropriate for the size and complexity of the small business, the nature and scope of the small business’s activities, and the sensitivity of the personal information the small business collects from or about consumers." To add to the bill's cryptic nature, if companies are already in compliance with historic data protection laws like HIPAA and the GLBA, they may already be compliant.

Get globally data compliant

Legislation like GDPR has global implications. With so many different laws emerging all over the world, it's critically important that companies with international operations seek advice on data compliance and certification. Just look at some of the fines that have been dished out under GDPR – and legislation like CCPA empowers American states to enforce even heftier fines. Cyber Smart are the experts in cybersecurity compliance, and with IASME’s GDPR Readiness certification we can help your business ensure full GDPR compliance and the proper processes and policies are in place. Wherever your business operates, contact us to ensure you're fully compliant.

Data privay toolbox

Why your fridge could be a cyber security threat

CyberSmart Mum

It might seem absurd, but today, everyday objects like fridges, doorbells, light switches, thermostats, and even children's toys can pose a cybersecurity risk. This is because nowadays, it's not only computers and smartphones that are connected to the Internet. Instead, even the most mundane household objects are likely to have some sort of smart capability, leaving them vulnerable to data loss or cyber-attacks.

This huge range of connected devices is referred to as the Internet of Things or "IoT". Although this network facilitates many exciting and useful things, it also creates numerous new access routes for cyber attackers. Therefore, it is essential that businesses of every scale have the proper cybersecurity precautions in place – or risk compromising company and customer data. Here, we discuss the growing risk and what you can do to prevent a cyber attack.

Why the IoT presents a growing risk

In a recent report, cyber security researchers shared some alarming statistics about cyber attacks on IoT devices. According to research, attacks are up 300% in 2019, with a staggering 2.9 billion recorded events. A common strategy by cyber attackers is honeypots, where decoy servers disguise themselves as operational hardware. Often, IoT devices are left vulnerable due to ageing firmware or irregular data security updates.

What you can do to prevent attacks

These statistics are worrying, especially for small and medium businesses. As consumers become increasingly concerned about data privacy, cybersecurity becomes a matter of reputation as much as anything else. For instance, a recent report from the Internet Society identified 'the trust opportunity'. Essentially, companies should leverage an excellent cybersecurity record to differentiate themselves from the competition.

However, many SMEs worry that they can't afford sophisticated IoT cybersecurity measures. Thankfully, this isn't the case – certification standards like Cyber Essentials and Cyber Essentials Plus from IASME ensure that businesses are compliant, even with their IoT devices. 

Good cybersecurity is good business

With threats from the IoT network growing every day, it is essential that businesses of all sizes have a proper cyber security strategy. At Cyber Smart, we can help you implement GDPR and cyber protection programmes to ensure your business's defences are up to scratch. Customers buy from businesses they trust. With proper cybersecurity certification, you can make sure you're their first choice.

Cyber Essentials in 2020: The evolution of the scheme

Cyber Essentials in 2020

Cyber Essentials has gone from strength to strength since its inception and is an important element of the NCSC’s mission to “make the UK one of the safest places to live and do business online”.

The success of the Cyber Essentials scheme led the NCSC to the decision that the scheme must evolve to meet the cybersecurity challenges of the future and continue its successful journey to protect businesses up and down the country. So, what should expect from Cyber Essentials in 2020?

2020 and IASME's partnership appointment

IASME, one of the UK's leading cyber certification bodies, has been appointed as the Cyber Essentials partner for NCSC from 1 April 2020. So what does this mean?

Before 1st April 2020: The five current accreditation bodies and their associated certification bodies are able to issue Cyber Essentials certificates as before. The scheme will remain in its current form until the end of March.

After 1st April 2020: Only certification bodies associated with IASME will be able to issue certifications. The CyberSmart platform is aligned with IASME and will continue to allow you to achieve and re-certify for Cyber Essentials certification.

The NCSC has made the following statements:

  • there will be an introduction of an expiry date on certificates (12 months)
  • costs will remain accessible and affordable
  • there are no plans to change the technical standard

CyberSmart Active Protect is fully aligned with the accreditation body IASME and will allow you to achieve Cyber Essentials and Cyber Essentials Plus certification today and renewal. We will always maintain support for the latest standard and keep ahead of the changes so you don't have to. With streamlined renewals, we'll remind you and automatically pre-populate the questionnaire each year ready for certification - prompting you for any additional information required.

Looking to improve your cybersecurity but not sure where to begin? Start by getting certified in Cyber Essentials, the UK government scheme that covers all the fundamentals of cyber hygiene.

CTA button

Four ways you can protect your customers

The information age has given businesses a new set of responsibilities for customer data that just didn't exist before, including anything from basic name and address details all the way through to legally sensitive details, medical records and serious financial data. This has enabled major advances in everything from logistics to advertising and healthcare, but it's also a major burden for companies - so how can you make sure you're doing your best?

Change behaviours

While the tricks and tools that hackers use to get at your data are genuinely becoming ever more sophisticated, by far the most popular way to steal from you is with the good old fashioned confidence trick. Fake email solicitations, clones or mirrored websites and even the impersonation of trusted contacts can get your staff to hand over data voluntarily - so make sure a culture of suspicion is built into your workforce. Set up a secure inbox that staff can forward suspicious emails to, so IT can safely dispose of them, and make sure to train staff regularly to spot fraud.

Layer your defences

The holy grail of any hacker's attacks is to get at not only the target of their crime but all your other data as well. While one file may not be enough to cause harm, it can be linked to other files that can be used cumulatively to carry out more serious attacks on people like identity fraud, so make sure you have several layers between other areas of your systems so one breach doesn't cascade into several. It can also help to restrict access on a need to know basis, so accidental breaches simply can't happen or ban things like portable disk drives just in case.

Trust the experts

While it's totally possible to fashion your own defences, it's hard to give your customer true peace of mind without some official credentials to back it up. Using software with IASME backed certification like Cyber Essentials or Cyber Essentials Plus ensures that you have the industry's gold standard protection in place, and with the GDPR Readiness standard you can become GDPR compliant and showcase your efforts to world-class customer data security, which in turn can open doors to new contracts with companies who insist on only working with the most secure firms.

Keep your patches up to date

Another sadly common way that hackers access your systems is through known back doors in software that has been fixed but isn't the latest version with repairs included. These obvious flaws are like gold dust to hackers who can just stroll right in, so it's a good idea to get software like CyberSmart Active Protect that automatically detects old versions of operating systems as well as software vulnerabilities. Find out more.

Latest Kaspersky Security Bulletin confirms online risk

The latest release of The Kaspersky Security Bulletin has confirmed that the online world has never been more dangerous, with both the quantity and variety of threats increasing by 13% in the last year. So what are the new threats and how have last year's threats moved on? We take a look at the key findings from the report, and what it means for your safety.

Web skimming is on the rise

Web skimming attacks, and the malware that enables them, make up a considerable part of the 13% rise - shooting up by a shocking 187%. Web skimming is the practice of introducing malware onto the payment pages of unprotected websites to steal the payment data of the victims who pay using the site, and it is just one of several forms of Trojan attack that has been on the rise against banking and shopping sites in recent years. The rise has been so dramatic that Skimmers are now the tenth most serious threat overall, as hackers turn to skimming after other methods of attack become less profitable, thanks to new initiatives like GDPR.

Malicious URLs remain the biggest threat

While new and exotic methods of attack continue to grow in response to security changes, the most common form of attack remains the malicious URL - representing 85% of security breaches. These URLs fool users into thinking they are visiting the correct site when they have actually been redirected to a fake clone, an extortion site or a site infected with malware designed to steal information. According to the report, this is largely driven by a desire from hackers to directly profit from users' money, rather than simply stealing their information to sell on, due to the increasing risks of their criminality. Businesses that achieve cybersecurity certification are much less likely to suffer such attacks.

Miners on the decline

One of the positives to come out of The Kaspersky Security Bulletin was the report of a fall in the prevalence of 'local' miners who secretly hijack users' computers via the Internet in order to use their processing power to mine cryptocurrencies - thanks to the crypto companies' attempts to make the technology safe for users concerned about the virtual currencies' security vulnerabilities. The difficulty in executing such attacks has made them much less profitable, and they have fallen by 59%.

What's coming up in the world of cyber security?

cyber security future

The world of cybersecurity moves quickly, as new viruses, scams and malware are created as well as increasingly sophisticated tricks and traps used to deploy them. So what's on the horizon for the next 12 months? We take a look at a few trends that will be making headlines in 2020.

Consolidation, consolidation, consolidation

There are a dizzying variety of items in most businesses' IT portfolios in 2019 that wouldn't have been anywhere near their radar a decade ago, from air conditioning units to waste bins, to go alongside the traditional bevvy of computers, phones printers and other hardware, that it's an increasing challenge to keep on top of it all. In order to ensure that everything in the organisation has equal protection, and to cut down on the number of bulky and power-hungry servers needed on-site, many IT professionals are increasingly moving their data and systems to the Cloud. This allows them to remove old legacy systems and software that can be replaced with Cloud-based alternatives, better comply with GDPR rules on security, and better organises the data that is moved across so it's more useable.

BYOD is the new threat

While there was initial resistance in the IT world to Bring Your Own Device requests that allow staff to do business on their own phones and tablets, it's increasingly becoming a key part of their strategy to cut spending on hardware and to bake the 'work anywhere' principle into the way the organisation functions. While it's very convenient, it's also a major new danger for companies whose employers have a wide range of tech-savviness and level of protection on their devices. Watch out for scammers going after staff-owned devices, and consider what you might do if an employee's phone is compromised. Getting a certification to show your organisation is compliant with Cyber Essentials or Cyber Essentials Plus, created by IASME, is a great way to get peace of mind if the worst does happen.

Governments under fire

2019 saw a worrying surge in the number of cyberattacks against local Government targets, such as the UK's NHS, which historically has been less proactive than private companies on cybersecurity. Stretched budgets have left security funds depleted, which is bad news if you're a member of the public affected or one of the many thousands of businesses who supply local Governments and come into contact with their IT. It might be a good idea to beef up your procedures with items and emails received from your public sector clients, and consider what you might do if you suffered an attack.

Survey paints positive picture of education in cybersecurity

Cyber Security Education

There has been some good news from the world of information security, as the latest survey from the Joint Information Systems Committee (JISC) has found that colleges and universities across the UK are beefing up their investment in cybersecurity.

More investment

The group, which exists to highlight the challenges and opportunities in the UK information security sector, has found that not only are higher education facilities more likely to have staff in roles dedicated to promoting and providing cybersecurity, they are also investing more in training and technical solutions than ever before. Particularly encouraging was the news that there has been a 14% increase in the number of institutions implementing industry recognised security standard Cyber Essentials, to 40% of the further education sector.

Alongside this encouraging data, the report also found that 97% of universities and 75% of colleges now use third-party security services to bolster their defences and that 66% of institutions now have a dedicated lead on cybersecurity within their IT staff - all large increases on the same time last year. Despite this, the overall fear of cyber-attacks has grown, probably due to high-profile instances of attacks in the global media and the unsettling effect of new regulations like GDPR.

Protecting your business

Achieving certification in Cyber Essentials with a compliant body like IASME is a big step for any higher education institution, and demonstrates a solid commitment to tackling the problem of security threats within the IT and higher education industries, and is a serious escalation of an institution's security posture in the face of increasing threat from online criminals. Compliant organisations are much less likely to suffer attacks or to take serious damage from security breaches, and Cyber Smart software can decrease the chances of suffering loss by up to 80%. With a baffling array of threats out there, threats which are constantly changing and evolving, it can seem like a full-time job keeping up with the latest news on what the bad guys are up to - never mind implementing measures to deal with them.

That's where CyberSmart, delivering Cyber Essentials and Cyber Essentials Plus certifications come in. As government recognised standards, you'll have the peace of mind that is backed by the knowledge you are at the cutting edge of the industry standard where protecting your business is concerned, not only ensuring that the latest technology is in place to protect you, but that your staff are trained to the highest standards to help mitigate threats before they happen.

Facing the realities of cybersecurity

Data breaches have become increasingly commonplace for both businesses and consumers. Consumers face worries about the safety of their data, while many businesses seem to be failing to keep up with protection against cyber-attacks. A 2019 report from Bitdefender revealed that six out of ten businesses had been a victim of a data breach in the last three years. As threats continue to grow, it is becoming more and more important for businesses to ensure they prioritise funnelling their budget and resources into cybersecurity.

How worried should I be about a data breach?

Despite IT professionals working to stay on top of cybersecurity and feeling confident with the protection they provide, the reality is that businesses continue to face security breaches. Honest IT professionals have admitted that their business could be being breached without them even realising. The largest threats facing companies' cybersecurity are thought to be phishing, whaling attacks, Trojans or Ransomware. Cyber-attacks can be incredibly difficult to achieve efficient protection against, which is due to the complex and ever-evolving landscape of attackers and methods used.

As businesses grow and navigate the current economic climate, lower budgets and cuts to training can be a common occurrence. Unfortunately, this can mean inadequate training for cybersecurity teams, insufficiently educated employees, and consequently businesses that are under-protected against attack. Now more than ever, it is vital that businesses invest time and money into their cybersecurity resources, or they risk facing an attack that could be detrimental to the whole business

How can I prevent an attack?

As threats to cybersecurity continue to evolve in their sophistication and complexity, it can be tough for businesses to prepare themselves adequately from attack. There are constant improvements being made in the industry of cybersecurity, and changes in regulations that businesses are expected to comply with. A great idea to protect against a data breach is to educate your employees on cybersecurity, the potential threats and the steps that should be taken to best avoid an attack. There are many well-qualified companies that offer thorough cybersecurity training from skilled professionals.

Furthermore, the most significant step businesses can take to improve their data protection is to invest in cyber-protection software that prevents the maximum amount of attacks, meets current government standards and automatically works to ensure employee devices are compliant. Cybersmart offers a range of certification such as Cyber Essentials and Cyber Essentials Plus, as well as CyberSmart’s applications, providing you, your business and your customers with peace of mind and assurance that your data is well-protected.

CyberSmart speak at StartupGrind in Georgia

CyberSmart took part in this year’s StartupGrind Eurasia Connect event, hosted in Tbilisi, Georgia. The event, part of StartupGrind,  the largest independent startup community, was aimed at bringing together world-class startups, founders and investors to look at exploring the frontier markets of Eastern Europe and Central Asia.

It was great to be invited to the event and have the opportunity to take onto the main stage to discuss CyberSmart but also to inspire the adoption of essential cybersecurity measures to secure Georgia, a country at the epicentre of trade, culture and geopolitical interest, dating all the way back to the Silk Road days. 

Aiming to inspire

At CyberSmart we continue to grow the capabilities of our technology, not only to secure businesses and their supply chains but now with the added potential to support an entire nation with the design, deployment and enforcement of information security capabilities. During the event, CyberSmart presented certOS™, our certification operating system, creating the capability for nations to design, deliver and enforce information security standards.

Our main stage session and indeed all the networking opportunities were filled with information and education surrounding how cyber threats are all around us but there are solutions to thwart them, starting from the basics of cybersecurity for consumers and businesses. 

‘We are very grateful to StartupGrind, GITA, DIT and the British embassy for providing us with the opportunity to help to make the world a safer place.’ said Thomas S. Head of partnerships at CyberSmart.

Thank you 

StartupGrind did a great job of hosting one of the largest startup events in the world. The team approached this challenge with exemplary professionalism and unparalleled hospitality. For CyberSmart this event was key to demonstrate its capability to support governments on their missions to secure their nations against global cyber threats, connect to international investors and to ultimately give back to the wider ecosystem. 

Thank you to StartupGrind, DIT and government stakeholders from both Georgia and the UK.