Narrowing the Response Gap

In terms of response gaps in dealing with attacks, there are several implications in how to deal with them and a number of complex reasons for the response gap. Many relate back to an organisation’s structural set-up, including how much investment is given to response, and how the associated tasks, roles, and responsibilities are allocated, resourced, and supported. The four major reasons are: attacks are detected but not actioned appropriately; attacks are detected but the organization doesn’t have the right technology to respond; attacks are detected but the cyber skills shortage impedes an organisation’s response and; attacks are not detected at all.

Incidence Response Teams

Once a cyber-attack incident is confirmed and a compromise detected, a common misstep is pulling the power cable. While shutting off power may seem a good thing from a containment standpoint, it makes the job of the responder much harder. If the attack is wholly memory-resident, shutting that host down can completely remove the evidence of how the attacker accessed the endpoint, and impedes gathering intelligence on the attack’s origins and potential objectives. This policy should be continually communicated to all employees. Another critical importance is that of identifying the main contacts for incident response teams.

See how your Cyber Security stacks up

Many companies in Europe are at the forefront of managing their cyber security needs and nearly 2000 cyber security leaders and influencers across the region shared with F-Secure their companies’ cyber security priorities, challenges, strategies and budgets for 2020, and beyond.

The Potential Dark Side of Synched Accounts

Synched accounts (e.g Apple ID, Google Account, etc.) have been around for several years now and the use of them has grown rapidly with the convenience that they offer in keeping all of your personal information in one place. This includes aspects such as passwords, browsing activities, personal likes and favourites, device tracking, and other data which is all stored in the cloud.

Trending News

World’s 2nd largest laptop manufacturer hit by Ransomware
The Taiwanese electronics company Compal that manufactures laptops for Acer, Apple, Dell, HP, Fujitsu, Lenovo and Toshiba among others, was hacked by a Ransomware attacker earlier this month. The responsibility for the breach is believed to be the DoppelPaymer ransomware gang, according to a screenshot of the ransom note shared by Compal employees with reporters at ZDNet.

Software AG down after ransomware attack
The second-largest software vendor in Germany and one of the largest in Europe, Software AG was hit by a Clop ransomware attack in October, infiltrating the company’s systems that compromised their employee information and company files.

British Airways fined over R400M over cyberattack
British Airways was recently fined £20M (over R400 million) by the UK’s Information Commissioners’ Office (ICO), a data protection watchdog, for a breach during a cyber-attack in 2018 that compromised the personal and financial details of over 400 000 customers.

Cybercriminals arrested in Lagos, Nigeria
Three Nigerian citizens suspected of being members of an organized cybercrime group behind distributing malware, carrying out phishing campaigns, and extensive Business Email Compromise (BEC) scams were arrested by Interpol in the city of Lagos on 25 November 2020 according to Hacker News.

Manchester United football club falls victim to cybercrime
The Manchester United football club in the United Kingdom has confirmed that the team fell victim to a cyberattack on its systems recently. Although the club mentioned that the attack was apparently a sophisticated operation by very well organised cyber-criminals, they also claimed that personal data associated with fans or customers was not breached.

Be sure to consider some of the cyber threats out there and consider these tips for protecting yourself and your devices. Until our next mailer, you can check out all the great resources we have available on our website.

The Cybervision Team