<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/information-security-infosec"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Information-security-infosec ]]></title>
                <link>https://www.itpro.com/uk/tag/information-security</link>
        <description><![CDATA[ All the latest information-security-infosec content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Wed, 12 Mar 2025 09:30:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Cybersecurity teams face unparalleled pressure, but they’re stepping up to the plate ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cybersecurity-workload-targets-tines</link>
                                                                            <description>
                            <![CDATA[ While cybersecurity teams are contending with rising workloads and chronic staffing issues, new research shows practitioners are still charging ahead and meeting targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sbytbSydo5VrKL4qiTHKMN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DqZJsi3tuDU6vRzDEmT7Q6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Mar 2025 09:30:00 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Mar 2025 11:47:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DqZJsi3tuDU6vRzDEmT7Q6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity team members discussing strategy in an open plan office space, with male and female practitioners standing and others sitting at desks.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity team members discussing strategy in an open plan office space, with male and female practitioners standing and others sitting at desks.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity team members discussing strategy in an open plan office space, with male and female practitioners standing and others sitting at desks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DqZJsi3tuDU6vRzDEmT7Q6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>teams are contending with rising workloads and <a href="https://www.itpro.com/security/the-cyber-security-skills-shortage-what-skills-are-missing">chronic staffing issues</a>, new research shows practitioners are still charging ahead and meeting targets. </p><p>In a new <a href="https://www.tines.com/access/whitepaper/voice-of-security-2025/" target="_blank">study from Tines and IDC</a>, 88% of <a href="https://www.itpro.com/security/infosec-spends-a-lot-of-time-talking-about-the-dangers-of-burnout-heres-how-you-can-actually-tackle-the-problem">InfoSec leaders</a> said their teams are exceeding targets, and a key factor here lies in the adoption of new <a href="https://www.itpro.com/technology/artificial-intelligence/ai-tools-critical-thinking-reliance">AI tools</a> and automation. </p><p>The study found that six-in-ten leaders work with teams consisting of 10 practitioners or fewer. However, 72% said that they'd been expected to take on more work over the last year, and a quarter said they'd had to work evenings or weekends.</p><p>Virtually all were enthusiastic about AI, with only one-in-twenty worried about their job. Notably, they want to see AI and automation eliminate business siloes, with nearly all looking to connect these tools across security, IT, and <a href="https://www.itpro.com/devops/28097/what-is-devops">DevOps</a> functions. </p><p>The most common AI use cases so far include manipulating security data, with around a third of teams using AI for summarization, threat intelligence analysis, or threat detection.</p><p>If they were only able to use AI and automation to free up more time, 43% said they'd use it to focus more on security policy development, with a similar number saying they'd do more on training and development, and 38% on incident response planning.</p><p>That’s easier said than done, however. Tines’ study revealed a third of security leaders are worried about the time required to train their teams on AI, with a quarter citing compliance as a problem. </p><p>Other hurdles included AI hallucinations, secure AI adoption, and slower than expected implementation times. </p><p>"Security professionals, who already face an unprecedented threat landscape in 2025, are met with the daunting task to integrate AI across their workflows," said Matt Muller, field <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> at Tines. </p><p>"Our research shows that security teams are stepping up. However, organizations must take a flexible approach to automation and <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to ensure it remains secure and effective."</p><h2 id="tool-sprawl-remains-a-problem-in-cybersecurity">Tool sprawl remains a problem in cybersecurity</h2><p>A key barrier to productivity in security teams is tool sprawl, according to the study from Tines. More than half of teams typically manage 20 to 49 tools, while 23% use fewer than 20, and 22% use 50 to 99. </p><p>But only a third of security leaders said they were satisfied with their team’s tools, with a quarter struggling with poor integration, and a third reckoning their stack lacks key functionality. </p><p>"Siloed automation across departments complicates managing security programs and creates vulnerabilities, especially as less technical employees adopt these technologies," said Christopher Kissel, research vice president, security and trust products at IDC Research, which carried out the research. </p><p>"The <a href="https://www.itpro.com/technology/artificial-intelligence/five-essential-insights-into-generative-ai-for-security-leaders">security leaders</a> we surveyed are strongly in favor of embracing shared automation between security and closely-knit business units like IT and DevOps to improve collaboration, strengthen security posture, streamline operations, and reduce complexity."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PVTgVkPVjkmkdMPBJBtHH7" name="Secure cloud best practices" caption="" alt="Secure cloud best practices" src="https://cdn.mos.cms.futurecdn.net/PVTgVkPVjkmkdMPBJBtHH7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/secure-cloud-best-practices"><em>Strengthen your organization's cybersecurity function</em></a></p></div></div><p><a href="https://www.itpro.com/business/business-strategy/software-developers-security-experts-and-even-investment-bankers-all-report-that-tool-sprawl-is-burning-budgets-and-wasting-employees-time">Tool sprawl is a frequent complaint among IT professionals</a>, with a report last year from Google Workspace finding that teams with ten or more security tools <a href="https://www.itpro.com/security/adopting-more-security-tools-doesnt-keep-you-safe-it-just-overloads-your-teams-and-creates-greater-risks">experienced more incidents than those with a consolidated tech stack</a>.</p><p>That didn't stop IT leaders from introducing them, however, with nearly two-thirds admitting to adding new security tools as they go along.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cybersecurity-skills-what-can-be-done">Cybersecurity skills: Addressing the gaps and challenges</a></li><li><a href="https://www.itpro.com/security/msps-are-struggling-with-cyber-security-skills-shortages">MSPs are struggling with cyber security skills shortages</a></li><li><a href="https://www.itpro.com/security/cybersecurity-is-the-fastest-growing-tech-occupation-in-the-uk-but-its-still-not-enough-to-dent-the-growing-industry-skills-shortage">Cybersecurity is the fastest growing tech occupation in the UK</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Developers can't get a handle on application security risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/developers-cant-get-a-handle-on-application-security-risks</link>
                                                                            <description>
                            <![CDATA[ Research by Legit Security shows a majority of organizations have high risk applications in developer environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KswjyhQumKAedmYzdi6iVg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5yGtf3BGCcwp7j3BDuWPc8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jan 2025 11:10:54 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jan 2025 16:23:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5yGtf3BGCcwp7j3BDuWPc8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Application security concept image showing a digitized padlock placed upon a digital platform.]]></media:description>                                                            <media:text><![CDATA[Application security concept image showing a digitized padlock placed upon a digital platform.]]></media:text>
                                <media:title type="plain"><![CDATA[Application security concept image showing a digitized padlock placed upon a digital platform.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5yGtf3BGCcwp7j3BDuWPc8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Application development infrastructure is full of <a href="https://www.itpro.com/security/these-three-critical-sectors-are-riddled-with-high-risk-vulnerabilities"><u>significant security risks</u></a>, with research by Legit Security finding high or critical risks in the developer environments of every company it examined. </p><p>The security company's <a href="https://info.legitsecurity.com/state-of-application-risk" target="_blank"><u>report into the state of application risk</u></a> found flaws in applications but also the "software factories" that make them. The report is based on data from its own platform, looking at a range of organizations from large to small, across various industries. </p><p>Legit said application security is no longer simply about spotting flaws in source code, noting that the attack surface for applications has grown and diversified. </p><p>"With <a href="https://www.itpro.com/software/development/software-development-is-faster-with-ai-but-industry-not-totally-transformed">software development that is faster</a>, more automated, more dynamic, and highly reliant on third parties, new opportunities to introduce risk abound."</p><p>According to the report, 89% of companies have pipeline misconfiguration issues and 46% are using<a href="https://www.itpro.com/technology/artificial-intelligence/majority-firms-using-generative-ai-related-security-incidents"><u> AI models in source code in a risky way</u></a>. Notably, security teams are actually unaware where AI is in use, making the booming technology an emerging threat for application security.</p><p>"Our research uncovered great risks everywhere throughout the development process," said Liav Caspi, Legit CTO and co-founder. </p><p>"These results highlight that teams are overlooking risks in their development environments and CI/CD pipelines, and are inviting the next supply chain attack by neglecting critical security hygiene."</p><h2 id="leaking-secrets">Leaking secrets </h2><p>The report found that all organizations on its platform had three or more application risks, but only two-thirds had public repositories with two or more risks. Those included exposed information that should have been secret, like cloud keys, <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> personal access tokens, and even personal information such as credit card numbers. </p><p>Such data was often found in source code that could be accessed by any user with access to a repository, such as an external supplier or anyone if it was made public.  </p><p>But a third of that information was actually outside source code and found in documentation and collaboration tools like Confluence or in ticketing systems. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nEogaAvbGcxhbCmsFUNXTh" name="Compliant security with CDW" caption="" alt="Compliant security with CDW" src="https://cdn.mos.cms.futurecdn.net/nEogaAvbGcxhbCmsFUNXTh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/compliant-security-with-cdw"><em>Ensure no threat slips through unnoticed</em></a></p></div></div><p>Legit advised companies not to hard-code "secrets" into source code by using a <a href="https://www.itpro.com/software/368049/best-password-managers-for-business">password manager</a> or environment variable. </p><p>"To prevent exposed secrets, focus first on <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a> services keys (e.g., <a href="https://www.itpro.com/security/cyber-security/368964/vast-majority-mobile-apps-leaking-aws-credentials-ios">AWS access keys</a>), since if code is leaked, credentials to SaaS services are immediately usable if they are valid, whereas internal credentials require attackers to also have network connectivity," the report added. </p><p>Another challenge is giving too much access: the report found 85% of development teams are over-permissioned, while 23% of repositories across organisations have external suppliers or collaborators with admin privileges in places they shouldn't. </p><h2 id="the-wrong-tools">The wrong tools</h2><p>The study also found that most companies use inefficient application security scanning, with 78% using duplicate software composition analysis scanners that would produce the exact same results, and 39% having duplicate static application security testing scanners. </p><p>Legit pinned this on developers working in different parts of the business using free versions of scanners, noting that would be exacerbated by mergers and acquisitions.</p><p>"To make an analogy, it’s as if they are preparing delicious, innovative dishes, in a kitchen with rusty, dirty, malfunctioning equipment," Caspi added. </p><p>"Most security teams today don’t have the visibility or the context they need to identify risk outside of source code or to effectively triage AppSec findings."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISOs are gaining more influence in the boardroom, and it’s about time ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/CISO-boardroom-influence-growing</link>
                                                                            <description>
                            <![CDATA[ CISO influence in the C-suite and boardrooms is growing, new research shows, as enterprises focus heavily on cybersecurity capabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">79f6pFKMKDhXrRuVL7eYNb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 10:48:25 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jan 2025 15:58:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:description>                                                            <media:text><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:text>
                                <media:title type="plain"><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The role of the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> is growing in status as <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> becomes an increasingly pressing issue for enterprises globally, new research shows. </p><p>A recent study from <a href="https://www.itpro.com/business/business-strategy/our-job-is-not-to-screw-up-cisco-ceo-chuck-robbins-vows-to-make-splunk-better">Splunk</a> shows security execs are being granted more powers to make strategic decisions for the business and are fostering closer collaborative ties with the boardroom and CEO.</p><p>More than eight-in-ten CISOs now report directly to the <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a>, a huge increase from 47% in 2023. Meanwhile, 83% participate in board meetings somewhat often or most of the time. </p><p>However, while six-in-ten acknowledge that board members with cybersecurity backgrounds have a more powerful influence on security decisions, only 29% say their board includes at least one member with cybersecurity expertise. </p><p>"As cybersecurity becomes increasingly central to driving business success, CISOs and their boards have more opportunities to close gaps, gain greater alignment, and better understand each other in order to drive digital resilience,” said Michael Fanning, chief information security officer at Splunk. </p><p>“For CISOs, that means understanding the business beyond their IT environments and finding new ways to convey the ROI of security initiatives to their boards. For board members, it means committing to a security-first culture and consulting the CISO as a primary stakeholder in decisions that impact enterprise risk and governance."</p><h2 id="cisos-on-the-board-builds-strong-security-practices">CISOs on the board builds strong security practices</h2><p>Splunk’s research found that board members with a security background reported stronger relationships with security teams, and felt more confident about the organization’s security posture. </p><p>They were much less likely than other board members to express concern they weren't doing enough to protect the organization.</p><p>Working relationships where a board member had a security background were particularly good when it came to setting and aligning on strategic cybersecurity goals, with CISOs on the board delivering a three-fold improvement.</p><p>Other areas to benefit included communicating progress against milestones and security goal achievements, along with budgeting adequately to meet goals. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CQVbgM8Vp6xdYdQJG2NW3T" name="Securing tomorrow_ Maximising the value of technology in an evolving defence sector.jpg" caption="" alt="Securing tomorrow: Maximising the value of technology in an evolving defence sector" src="https://cdn.mos.cms.futurecdn.net/CQVbgM8Vp6xdYdQJG2NW3T.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Intel)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/securing-tomorrow"><em>Defence firms must consider this when implementing new tech</em></a></p></div></div><p>There were, though, differences in priorities. More than half of CISOs thought innovating with emerging technologies was a priority, compared with just a third for board members. A similar proportion of CISOs prioritized <a href="https://www.itpro.com/business/careers-and-training/cyber-security-professionals-admit-knowledge-gaps-have-led-to-serious-security-blunders">upskilling</a> or reskilling security employees, versus only 27% for boards.</p><p>"As the role of the CISO grows more complex and critical to organizations, CISOs must be able to balance security needs with business goals, culture, and articulate the value of security investments," commented Shefali Mookencherry, chief information security and privacy officer at the University of Illinois Chicago.</p><p>"By establishing strong relationships across various departments and stakeholders, CISOs can provide guidance and leadership to propel cybersecurity and privacy programs."</p><h2 id="cisos-face-regulatory-challenges">CISOs face regulatory challenges</h2><p>As regulatory environments have become more complex, expansive, and punitive, CISOs are having to deliver <a href="https://www.itpro.com/security/security-incident-recovery-times-are-over-7-months-on-average">faster incident reporting</a>, and are <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">facing more liability</a>.</p><p>However, only 15% of CISOs ranked compliance status as a top performance metric, a significant contrast to 45% of boards. Nearly a quarter (21%) of CISOs said they'd been pressured not to report a compliance issue, although 59% said they would become a whistleblower if their organization was ignoring compliance requirements.</p><p>Meanwhile, cyber budgets reflect inconsistent support and misalignment, with three-in-ten CISOs saying they receive the appropriate budget for cybersecurity initiatives and accomplishing their security goals, compared with four-in-ten board members who think budgets are adequate. </p><p>Other woes included concerns that they're not doing enough, with 18% revealing they were unable to support a business initiative because of budget cuts in the last 12 months. Nearly two-thirds said that lack of support led to a cyber attack. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How MSSPs can leverage dark web intelligence to counter emerging threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/how-mssps-can-leverage-dark-web-intelligence-to-counter-emerging-threats</link>
                                                                            <description>
                            <![CDATA[ Dark web intelligence can be a vital tool for MSSPs to bolster security and counter emerging threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HJANMTDBYbkzo8PuGCPQNV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Aug 2023 10:15:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:40:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ben Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/PxLoEXSvhz3MToMZ4pQ7YG.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A web structure imposed on a black background]]></media:description>                                                            <media:text><![CDATA[A web structure imposed on a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A web structure imposed on a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8TbsahzKZ53F2B5cCVYakE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Security Service Providers (MSSP) are at the forefront of emerging market trends, meaning they need to identify and adopt the latest technology to best protect their customers and keep step with competitors. </p><p>The demand for dark web intelligence has skyrocketed over the past few years, as organizations grow ever more aware that cyber attacks originate in marketplaces, forums, and sites they cannot see. It is therefore not surprising that <a href="https://www.slcyber.io/press/report-how-mssps-are-using-dark-web/"><u>most MSSPs</u></a> have already started to address customer demands for dark web threat insights.</p><p>But despite many MSSPs already undertaking dark web monitoring, our latest <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a> identified that 35% of MSSPs believe that dark web monitoring is too complex, while nearly one-third (29%) believe it isn’t relevant to their service offering, and 18*+% are yet to be convinced they will be able to sell it.</p><p>With 34% of MSSPs not seeing value in dark web monitoring tools, some providers are potentially missing out on providing essential insights into an online criminal underworld where cyber criminals discuss and plan future attacks. </p><p>MSSPs, therefore, have an opportunity to harness the power of dark web intelligence to protect their customers from cyber threats.</p><h2 id="dark-web-intelligence-and-the-x201c-cyber-kill-chain-x201d">Dark web intelligence and the “cyber kill chain”</h2><p>When we talk about <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a>, most of a security team’s resources and tools are focused on the late stages of “cyber kill chain” (the sequence of actions a cybercriminal has to take to execute their attacks). </p><p>For instance, email security tools sit at the ‘delivery’ phase of a cyber attack, whilst endpoint, network, and <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>antivirus security solutions</u></a> focus on identifying the subsequent activity as the attacker makes their way across an organization’s infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5bgDiwE8NhRmYj2TybQ4Dk" name="workplace_diversity_GettyImages-1396315043 (1).jpg" caption="" alt="Female business colleagues in meeting discussing project" src="https://cdn.mos.cms.futurecdn.net/5bgDiwE8NhRmYj2TybQ4Dk.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/addressing-the-gender-divide-in-the-channel">Addressing the gender divide in the channel</a></p></div></div><p>As cyber criminals continue to evolve their capabilities and skill sets to be able to bypass existing security solutions, preventing an attack is not always as simple as not clicking a <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> link. To give the best chance of disrupting a cyber criminal’s operation in clients systems, MSSPs need to “shift left” and act as early in the cyber kill chain as they can on behalf of their customers. </p><p>Dark web intelligence allows MSSPs to investigate the ‘reconnaissance’ stage, right at the beginning of the “kill chain” when threat actors are planning their cyber attacks on <a href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been"><u>dark web hacking forums</u></a>, and buying the exploits and tools they need on malicious marketplaces. </p><p>By starting this early, MSSPs can make a dent in an attack plan and advise their clients on how to take preventative action that stops their network from being breached in the first place. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6ioYHWRxniA3Ra8werZ8nX" name="Thwart cyberthreats_listing.jpg" caption="" alt="eBook cover with green title text over image of business man wearing glasses and smiling at a workstation" src="https://cdn.mos.cms.futurecdn.net/6ioYHWRxniA3Ra8werZ8nX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><em>See why peers are looking to AI and machine learning to transform their cyber security processes.<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/thwart-cyberthreats-fast-with-security-operations-ai-ops">DOWNLOAD FOR FREE</a></p></div></div><p>MSSPs’ position in the market requires them to be early adopters, able to identify the latest tools and technologies to protect their customers. It is no surprise then, that <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>56% of MSSPs</u></a> already undertake dark web intelligence, recognising the benefit. </p><p>Companies of all sizes are increasingly conscious of dark web threats and the opportunity dark web intelligence holds for helping them identify the early warning signs of attack. </p><p>This has created an opportunity for MSSPs to use dark web intelligence as a basis to deliver the analysis, expertise, services, and solutions that help their customers act on the dark web risk they have heard so much about.</p><h2 id="meeting-customer-demand">Meeting customer demand</h2><p>According to our <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a>, customer interest in the dark web has been increasing, with 65% of MSSPs stating that their customers have asked for threat intelligence from the dark web. </p><p>Why is that? Well, there are three main reasons for this demand. Firstly, as visibility in cyber security is key, customers want to identify vulnerabilities affecting their organization. Secondly, they want to know if they or their competitors are currently being targeted on the dark web. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="crxdBq2iAVPqTy96onEXeH" name="business_deal_handshake_GettyImages-692570400 (1).jpg" caption="" alt="Two business women shaking hands" src="https://cdn.mos.cms.futurecdn.net/crxdBq2iAVPqTy96onEXeH.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-msps-can-create-a-lead-generation-program-that-delivers-results">How MSPs can create a lead generation program that delivers results</a></p></div></div><p>Thirdly, they want to own and act upon intelligence on threat groups including ransomware gangs that are active in the threat environment.</p><p>So, as the topic of dark web monitoring grows in prominence, those MSSPs that have started to build out their capabilities, data sources, and understanding will be able to benefit as more customers look for guidance on the dark web, giving them an advantage in the competitive market of managed security services.</p><h2 id="unlocking-benefits-for-mssps">Unlocking benefits for MSSPs</h2><p>Aside from striking benefits for customers, MSSPs can also take advantage of dark web intelligence from a commercial perspective. When asked about the benefits of using dark web intelligence, <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>37% of MSSPs</u></a> reported that it helps them identify customer details on the dark web, closely followed by giving them new products and services to sell to customers and making their current services more efficient.</p><p>By “shifting left” in the cyber kill chain, MSSPs are enabled to move from reacting to threats to proactively preventing them from happening in the first place. This makes good business sense as it means MSSPs can document and demonstrate value based on attributes exposed and/or being discussed on the dark web. </p><p>It also means that MSSPs don’t have to wait for their clients to be breached before they can prove their worth – they can often find threats that could impact the organization, from day one.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EXeL4hPNVaTQPuTt2HGWAF" name="Brain_Evolution_Stock_GettyImages-1436010616.jpg" caption="" alt="Digital generated image of multi coloured gear wheels connected together in shape of brain on grey background" src="https://cdn.mos.cms.futurecdn.net/EXeL4hPNVaTQPuTt2HGWAF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/how-to-bring-your-people-on-your-digital-evolution-journey">How to bring your people on your digital evolution journey</a></p></div></div><p>According to <a href="https://www.slcyber.io/whitepapers-reports/a-guiding-light-in-the-dark-how-mssps-are-using-dark-web-threat-intelligence/"><u>research</u></a>, the most common use for threat intelligence is to inform pentests and security audits (35%) followed by informing incident response (34%). The MSSPs which use dark web intelligence in one-off engagements are missing a trick in integrating dark web intelligence into their value proposition and hence recurring revenues, where they could be capitalizing month-on-month. </p><p>A huge opportunity lies in MSSPs wrapping dark web monitoring into their Managed Security and SOC services to provide customers with an ongoing view of their dark web risk over time and alert them as soon as a serious situation emerges.  </p><p>The turbulent nature of criminal activity means that the dark web shifts and changes at an even faster rate than the clear web. Marketplaces, forums, and criminal groups appear out of nowhere, rise to prominence, jostle with other criminals and law enforcement, and disappear just as quickly as they came. </p><p>Dark web threat prevention is, therefore, not something that can be done on a six monthly or yearly basis. If organizations want to truly understand their threat risk on the dark web, they need their MSSPs to continuously monitor and deliver meaningful insights for effective cyber security protection and healthy cyber posture.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘AI Cyber Challenge’ shows US gov is already acting on its national security ambitions ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/ai-cyber-challenge-shows-us-gov-is-already-acting-on-its-national-security-ambitions</link>
                                                                            <description>
                            <![CDATA[ The $20m challenge will include support from major industry players, such as OpenAI and Google ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">86YbLbnbD7aMNnRnkkMdU6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/txHP4ubwTVaRXqwjQDunPi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Aug 2023 11:13:27 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Aug 2023 12:28:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/txHP4ubwTVaRXqwjQDunPi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[US AI Cyber Challenge: President Biden stood at a lectern in the White House]]></media:description>                                                            <media:text><![CDATA[US AI Cyber Challenge: President Biden stood at a lectern in the White House]]></media:text>
                                <media:title type="plain"><![CDATA[US AI Cyber Challenge: President Biden stood at a lectern in the White House]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/txHP4ubwTVaRXqwjQDunPi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US government is underlining its willingness to foster a collaborative relationship with private enterprise and the open source community on AI and security with the launch of its newest scheme. </p><p>On Wednesday, the Biden administration unveiled plans to launch a major government-backed competition aimed at exploring the use of artificial intelligence (AI) to support national cyber security. </p><p>The ‘AI Cyber Challenge’ will offer up to $20 million in prizes and help “drive the creation of new technologies to rapidly improve the security of computer code”, which the White House said is among the country’s most “pressing challenges”. </p><p>In addition, the scheme will involve close collaboration with a host of top companies operating in the AI space, including Google, Microsoft, OpenAI, and Anthropic.</p><p>“The Biden-Harris Administration today launched a major two-year competition that will use artificial intelligence to protect the United States’ most important software, such as code that helps run the internet and our critical infrastructure,” the White House said in a statement. </p><p>“It marks the latest step by the Biden-Harris Administration to ensure the responsible advancement of emerging technologies and protect Americans.”</p><p>The move from the government appears to build on its intention to foster closer ties with the private sector, the open source community, and major industry players as part of its broader <a href="https://www.itpro.com/business/policy-and-legislation/us-says-national-cybersecurity-strategy-will-focus-on-market-resilience-and-private-partnerships"><u>National Cybersecurity Strategy</u></a>. </p><p>Last month, the White House published an outline of its first actions through the strategy, which included the creation of a comprehensive framework aimed at reducing the risk of <a href="https://www.itpro.com/security/cyber-attacks/top-12-most-exploited-security-vulnerabilities-revealed-by-national-cyber-security-agencies"><u>vulnerable software</u></a> in critical infrastructure. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE </div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MWQ5EXYvybsMQ98bHL3rk3" name="MWQ5EXYvybsMQ98bHL3rk3.png" caption="" alt="Whitepaper cover with title and images of multiple screens and users interacting with them" src="https://cdn.mos.cms.futurecdn.net/MWQ5EXYvybsMQ98bHL3rk3.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>AI for customer service</strong></p><p class="fancy-box__body-text"><em>Learn about the conversational AI landscape, three most common use cases and customer pain points, as well as real-world success stories from clients.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/customer-experience-cx/368445/ai-for-customer-service">DOWNLOAD FOR FREE</a></p></div></div><p>The government said that, under the framework, the “biggest, most capable, and best-positioned” organizations across both the public and private sectors should assume a “greater share of the burden for mitigating cyber risk”. </p><p>Creating a closer relationship with the private sector works to the government’s advantage in this regard, enabling it to draw on the country’s significant expertise and expansive technology ecosystem. </p><p>With the AI challenge scheme, the situation is no different and could help the administration accelerate the use of AI systems to bolster national security amid a period of escalating threats. </p><h2 id="open-source-commitments">Open source commitments</h2><p>A key talking point within the announcement this week is the requirement that participating organizations make their materials and solutions open source. </p><p>“AI companies will make their cutting-edge technology – some of the most powerful AI systems in the world – available for competitors to use in designing new cyber security solutions,” the White House said in a statement. </p><p>The Open Source Security Foundation (OpenSSF), part of the Linux Foundation, will also serve as an advisory figure on the challenge. </p><p>As part of its involvement in the scheme, the foundation will help “ensure that the winning software code is put to use right away protecting America’s most vital software”. </p><p>This desire to involve the <a href="https://www.itpro.com/software/28109/what-is-open-source"><u>open source</u></a> community in the scheme aligns closely with the government’s general position on the ecosystem of late. </p><p>Last month’s announcement confirmed that the Cybersecurity and Infrastructure Security Agency (CISA) will work with both the private sector and the open source community to accelerate the development of secure-by-design software moving forward. </p><p>Creating a welcoming environment for the open source ecosystem is an aspect of the US’ current strategy that has been hailed in recent months. </p><p>At the launch of the cyber strategy in March this year, the Biden administration was <a href="https://www.itpro.com/security/370185/us-national-cyber-strategy-allays-fears-liability-for-open-source-vulnerabilities"><u>commended for its position on open source innovation</u></a>, which comes in stark contrast to what has been seen in the European Union (EU) across the same period. </p><p>The union has been repeatedly <a href="https://www.itpro.com/software/open-source/whats-the-eus-problem-with-open-source"><u>criticized for its stonewalling of the open source ecosystem</u></a> on both AI development and security, with critics describing the approach as highly inhibitive and creating a “chilling” effect across the community. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Royal, Hive, Black Basta ransomware gangs ‘collaborating on cyber attacks’ ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/royal-hive-black-basta-ransomware-gangs-collaborating-on-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Affiliates from the now-defunct Hive ransomware group could be seeking opportunities with other major dark web players ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nqgraHpRDnyfztn3YSYsAN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Aug 2023 12:25:06 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 11:09:21 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based attacks]]></media:description>                                                            <media:text><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based attacks]]></media:text>
                                <media:title type="plain"><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of major ransomware gangs could be sharing intel and conferring over attack techniques, according to Sophos. </p><p>Researchers at the security firm analyzed connections between three of the most notorious ransomware outfits over the past year, including the Royal, Hive, and Black Basta gangs. </p><p>There were “distinct similarities” between techniques employed during four different incidents at the beginning of 2023, analysis showed, raising questions over whether the gangs have been collaborating. </p><p>“Despite Royal being a notoriously closed off group that doesn’t openly solicit affiliates from underground forums, granular similarities in the forensics of the attacks suggest all three groups are sharing either affiliates or highly specific technical details of their activities,” Sophos said. </p><p>These “unique similarities” included using the same usernames and passwords when attackers seized control of victims’ systems, the company said. These striking similarities included:</p><ul><li>Hive – first incident: Adm01/Adm02 | Pa$$w0rd991155 and AdminBac | P@ssW0dDP@ssW</li><li>Royal – second incident: Adm04 | Pa$$w0rd12321 and AdminBac | P@ssW0dDP@ssW </li><li>Black Basta – third incident: Adm066 | Pa$$w0rd11225 and WDAGUtilityAccount | P@ssw0rd123456789 </li></ul><p>In addition, similar techniques employed by all three included delivering payloads in .7z archives named specifically after the victim organization, as well as “executing commands on infected systems with the same batch scripts and files”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8Hych4XJRfHkUY47d64Qg8" name="State of ransomware readiness 2022_listing.jpg" caption="" alt="Whitepaper cover with red and white title over a black and white image of a businessman stood looking out of an office window" src="https://cdn.mos.cms.futurecdn.net/8Hych4XJRfHkUY47d64Qg8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>State of ransomware readiness 2022</strong></p><p class="fancy-box__body-text"><em>Explore the business implications and personal impacts of ransomware.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/state-of-ransomware-readiness-2022"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Andrew Brandt, principal researcher at Sophos said traditional <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service"><u>ransomware-as-a-service</u></a> models require significant involvement from outside affiliates to conduct attacks. As such, there’s often crossover in tactics, techniques, and procedures they use. </p><p>But the similarities here were striking, and could point to a deep degree of cross-communication, as well as the reliance on established affiliates for gangs like Royal.</p><p>“In these cases, the similarities we’re talking about are at a very granular level,” he added. “These highly specific, unique behaviors suggest that the Royal ransomware group is much more reliant on affiliates than previously thought.”</p><p>The attacks Sophos observed include a high-profile attack Hive instigated in January. The group, however, was <a href="https://www.itpro.com/security/cyber-crime/369952/fbis-landmark-takedown-hive-ransomware-unlikely-significant-impact"><u>taken down in a landmark operation</u></a> conducted by the FBI and Europol later that month. </p><p>Law enforcement infiltrated Hive’s operations networks in mid-2022, with the takedown hailed as a rare occasion in which the FBI used offensive security tactics to cripple the organization. </p><p>The sting bore similarities to the joint international law enforcement <a href="https://www.itpro.com/security/ransomware/361480/three-revil-ransomware-gang-members-arrested-following-international"><u>takedown of the REvil ransomware gang</u></a> in 2021, which prevented more than $100 million worth of ransomware payments being made, according to the FBI. </p><p>Sophos’ analysis suggested some of the corroborating techniques observed this year could point toward the use of Hive affiliates by other existing groups, specifically Royal. </p><p>“This operation could have led Hive affiliates to seek new employment – perhaps with Royal and Black Basta – which would explain the similarities in the ensuing ransomware attacks,” researchers said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BAE Systems grows cyber and intelligence business, raises profit forecasts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/bae-systems-grows-cyber-and-intelligence-business-raises-profit-forecasts</link>
                                                                            <description>
                            <![CDATA[ A worsening threat landscape has prompted many nations to invest in cyber more heavily ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DptKVpatisGLu5oEtGVipe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ugxZeq5KxioxiVZPisFWXi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Aug 2023 11:57:31 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Aug 2023 12:19:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ugxZeq5KxioxiVZPisFWXi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The BAE Systems logo at an exhibition]]></media:description>                                                            <media:text><![CDATA[The BAE Systems logo at an exhibition]]></media:text>
                                <media:title type="plain"><![CDATA[The BAE Systems logo at an exhibition]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ugxZeq5KxioxiVZPisFWXi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>BAE Systems has reported accelerated growth in its cyber business as nations look to double down on cyber security, amid strong financials for the first half of 2023.</p><p>The firm’s Cyber & Intelligence business reported revenue of £1.15 billion ($1.47 billion) in H1 2023, with external customer revenue in Cyber alone having grown 30% across the period to £759 million. </p><p>The domain was the main driver for Cyber & Intelligence, representing 69% of its external customer revenue against the smaller contributions of air, maritime, and land.</p><p>Overall BAE <a href="https://www.londonstockexchange.com/news-article/BA./half-year-report/16066177" target="_blank">reported</a> 13% year-on-year revenue growth in its H1 2023 results, topping £11 billion ($14.06 billion). Operating profit hit £1.2 billion ($1.53 billion), up 20% year-on-year.</p><p>The firm linked growth in its Cyber & Intelligence business to an increase in systems integration and classified intelligence work, as well as a “sharp” uptick in national security cyber sales outside the US market. </p><p>Customers in central government, national security agencies, militaries, telecoms, and law enforcement continue to invest in BAE services. It serves clients around the world such as the US Department of Defense, with 10,700 employees in Cyber & Intelligence in total.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="vMQbcmCDCe9hr6G4ojHPPg" name="Anticipate_FP_listing.jpg" caption="" alt="Whitepaper: Anticipate, prevent, and minimize the impact of business disruptions, with image of two male colleagues in coats looking at a mobile phone" src="https://cdn.mos.cms.futurecdn.net/vMQbcmCDCe9hr6G4ojHPPg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Anticipate, prevent, and minimize the impact of business disruptions</strong></p><p class="fancy-box__body-text"><em>Learn how your organization can establish effective governance and prioritize business services.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/anticipate-prevent-and-minimize-the-impact-of-business-disruptions"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Both the public and private sectors employ BAE for mission-critical work, against the backdrop of the National Cyber Security Centre’s (NCSC’s) <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>recent warning</u></a> that new Russian groups seek to destroy critical national infrastructure.</p><p>Sales across the business increased by 7% across the period, with a single contract to support critical operations for a government customer having brought in $457 million (£371 million) in March.</p><p>The firm stated that it is now using <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai"><u>artificial intelligence (AI)</u></a> at an increasing level across all business areas, such as in manufacturing and design work. <a href="https://www.itpro.com/security/369813/cyber-attacks-on-uk-organisations-surged-77-in-2022-new-research-finds"><u>Increasing cyber attacks</u></a> continue to drive revenue across its cyber division in the UK and US.</p><p>"We&apos;ve delivered a strong financial performance in the first half of the year, thanks to the outstanding efforts of our employees,” said Charles Woodburn, CEO at BAE Systems.</p><p>"Our global footprint, deep customer relationships, and leading technologies enable us to effectively support the national security requirements and multi-domain ambitions of our government customers in an increasingly uncertain world.”</p><h2 id="what-does-bae-provide">What does BAE provide?</h2><p>BAE Systems is Europe’s largest defense contractor, and is based in London. It specializes in cyber security and intelligence services, as well as the production of munitions and equipment for use in land, air, and maritime combat.</p><p>Its worldwide workforce comprises more than 93,000 employees, with the majority of these based in the UK, US, Saudi Arabia, and Australia.</p><p>Since 2008 the company has heavily invested in cyber security, rapidly expanding its portfolio in the space through a string of acquisitions.</p><p>BAE provides risk advisory and incident response services for its clients, alongside more extensive design work on cyber defense for nation-states. It also provides operational expertise on advanced cyber threats, as well as software and hardware to protect against electronic warfare.</p><p>In 2022, BAE was <a href="https://www.itpro.com/security/cyber-attacks/362196/foreign-office-cyber-attack-confirmed"><u>hired by the UK Foreign Office</u></a> for urgent data remediation following a cyber security incident. The same year, the <a href="https://www.itpro.com/server-storage/high-performance-computing-hpc/368551/bae-systems-lands-699-million-us-army-hpc"><u>US Army awarded BAE a $699 million</u></a> (£567 million) contract to provide support for its high-performance computing (HPC) supercomputer work.</p><p>The firm has profited greatly from <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far"><u>Russia’s invasion of Ukraine</u></a>, both through increased sales of traditional hardware and munitions by Ukraine’s allies as well as through increased investment in cyber defenses by countries in the wake of <a href="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine"><u>booming Russian cyber attacks</u></a>.</p><p>BAE’s order backlog now stands at £66.2 billion ($84.63 billion), following £21.1 billion in order intake across H1 2023. This included new and renewed orders on fighting vehicles for the Czech Republic, UK nuclear submarines, and fighter jets for Saudi Arabia.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SEC data breach rules branded “worryingly vague” by industry body ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/sec-data-breach-rules-branded-worryingly-vague-by-industry-body</link>
                                                                            <description>
                            <![CDATA[ The new rules announced last week leave many questions unanswered, according to security industry experts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JrFez3tGLgcQbgz5WV73aB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g96PUz2PvH6RSUx5msaEJf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Jul 2023 10:17:14 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 13:24:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g96PUz2PvH6RSUx5msaEJf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SEC: U.S. Securities and Exchange Commission building in Washington, DC]]></media:description>                                                            <media:text><![CDATA[SEC: U.S. Securities and Exchange Commission building in Washington, DC]]></media:text>
                                <media:title type="plain"><![CDATA[SEC: U.S. Securities and Exchange Commission building in Washington, DC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g96PUz2PvH6RSUx5msaEJf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New data breach reporting rules introduced by the Securities and Exchange Commission (SEC) last week have been described as “worryingly vague” and may create a harmful operating environment for security professionals, according to (ISC)2. </p><p>Tara Wisniewski, EVP for advocacy, global markets, and member engagement at the security non-profit, challenged the new scheme, warning that many aspects of the new framework are open to interpretation. </p><p>While Wisniewski broadly welcomed the changes, she suggested that the announcement could create confusion for professionals in the industry.  </p><p>“While we support the fundamental principles of public disclosure to inform and protect shareholders, customers, and other constituents, the SEC ruling is worryingly vague. It poses more questions than answers, and may create ambiguity for cyber professionals.”</p><p>Under the new rules, public companies will be held to a higher standard of reporting, with firms required to <a href="https://www.itpro.com/business/policy-and-legislation/sec-passes-rules-compelling-us-public-companies-to-report-data-breaches-within-four-days"><u>disclose security incidents within four days</u></a>. </p><p>The ‘Form 8-K’ requirement means companies will have to report any security incident they deem ‘material’ within this timeframe and provide information on the timing of the attack, its scope, and the potential impact on the business and customers. </p><p>However, the terminology used by the SEC is a point of serious contention for (ISC)2 and could be left “open to interpretation”. </p><p>This, the organization said, could lead to over-reporting of security incidents, placing greater pressure on overworked staff. Similarly, (ISC)2 warned the framework could prompt a trend of under-reporting, which in the long term might leave <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> practitioners personally liable for incidents. </p><iframe width="100%" height="352" frameborder="0" allow="autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture" data-lazy-priority="high" data-lazy-src="https://open.spotify.com/embed/episode/1h7qanHtmMZVjeKtXeUHKy?utm_source=generator&t=0"></iframe><p>As such, the organization called for a clearer definition of what constitutes an incident under the new guidelines. </p><p>“There are no concrete definitions for which cyber incidents must be disclosed, or what the SEC means by ‘material impact’. There are millions of attempts on businesses daily, some unsuccessful, others partially so,” said Wisniewski.</p><p>“Without clearer definitions, the rules are open to interpretation which could either lead to over-reporting, distracting cyber professionals from their main task of network protection, or under-reporting, which could expose cyber professionals to personal liability.”</p><h2 id="overburdened-security-professionals">Overburdened security professionals</h2><p>Another point of contention raised by (ISC)2 centers around new board oversight requirements outlined in the SEC’s recent changes. Under the new rules, businesses will be required to disclose annual reports on their security risks, <a href="https://www.itpro.com/security/34049/how-to-build-a-comprehensive-cyber-security-strategy"><u>cyber strategy</u></a>, and governance practices.</p><p>Annual 10-K reports will be required to outline specific measures taken by organizations to identify and mitigate security threats, as well as insights on executive oversight of company security practices. </p><p>Wisniewski said that these new rules “do not go far enough”, adding that the guidelines are ambiguous and could lead to increased pressure on practitioners as executives rely on staff for advice and guidance. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Qv3e3HStkjSBUoN8GGkznR" name="Automation antidotes for the top poisons in cybersecurity management_listing.jpg" caption="" alt="Whitepaper cover with green title text over iage of hands working at a laptop with graphs on screen" src="https://cdn.mos.cms.futurecdn.net/Qv3e3HStkjSBUoN8GGkznR.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Automation antidotes for the top poisons in cyber security management</strong></p><p class="fancy-box__body-text"><em>Address top cyber security challenges that happens because of new technologies, increasing regulations, and supply chain vulnerabilities. </em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/automation-antidotes-for-the-top-poisons-in-cyber-security-management">DOWNLOAD FOR FREE</a></p></div></div><p>As a result, the non-profit has called for the establishment of a “more formal framework for board oversight responsibilities”. </p><p>“The ambiguity only creates more burden for overworked and under-staffed cyber security professionals, as boards and corporate leaders will increasingly rely on them for interpretation of the guidance,” she said. </p><p>“So while we support collaborative efforts to protect consumers, the importance of cyber threats and the complexity of management requires very clear guidelines with detailed definitions so cyber professionals do not inadvertently fall afoul of well-intentioned regulation,” Wisniewski added. </p><p>“Cyber professionals are looking for clarity, and this ruling falls short in that regard.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Deloitte denies Cl0p data breach impacted client data in wake of MOVEit attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/deloitte-denies-cl0p-data-breach-claims-in-wake-of-moveit-attack</link>
                                                                            <description>
                            <![CDATA[ Deloitte was the third of the 'Big Four' professional services firms to have appeared on the ransomware group's 'wall of shame' victim blog ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Vq37bnb3vxuvymmnGVZCgP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ANkB7KcLjDMevLieGtQG9P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Jul 2023 08:54:53 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Jul 2023 10:09:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ANkB7KcLjDMevLieGtQG9P-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Deloitte logo pictured on a sign outside the company&#039;s offices in London]]></media:description>                                                            <media:text><![CDATA[Deloitte logo pictured on a sign outside the company&#039;s offices in London]]></media:text>
                                <media:title type="plain"><![CDATA[Deloitte logo pictured on a sign outside the company&#039;s offices in London]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ANkB7KcLjDMevLieGtQG9P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Deloitte has refuted claims that the Cl0p ransomware gang has breached its systems and stolen client data amid speculation online. </p><p>The accountancy firm was cited as a victim on Cl0p’s breach disclosure blog, sparking concerns that clients at the consultancy could be at risk. </p><p>In its disclosure, Cl0p claimed “the company doesn’t care about its customers” and that it “ignored their security”.</p><p>The claims come amid a flurry of breach disclosures from Cl0p in the wake of the <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack">MOVEit breach</a>, which so far has affected hundreds of companies globally. </p><p>Last month, the group claimed to have compromised systems at EY and PwC, two of the other ‘Big Four’ accountancy firms. </p><p>At the time of writing, Cl0p still has both companies listed on its blog along with an array of download options for files the cyber criminal outfit claims to have stolen from them.</p><p>However, in a statement given to <em>ITPro</em>, Deloitte has denied suggestions that it had suffered a breach off the back of the global security incident. </p><p>A spokesperson for the firm said in the aftermath of the attack it took immediate action to apply security updates according to the vendor’s guidance and has mitigated risks to clients. </p><p>“Immediately upon becoming aware of this zero-day vulnerability, Deloitte applied the vendor’s security updates and performed mitigating actions in accordance with the vendor’s guidance." </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2nNdcPL9CGTu8jwiuvm3GK" name="State of Email Security 2023_thumb.jpg" caption="" alt="Black whitepaper cover with strapline and image of man's face overlaid looking in different directions" src="https://cdn.mos.cms.futurecdn.net/2nNdcPL9CGTu8jwiuvm3GK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The state of email security 2023</strong></p><p class="fancy-box__body-text"><em>Get the latest insights from 1,700 CISOs and other IT professionals as they present a realistic picture of the steps they are taking to protect their organizations</em></p><p class="fancy-box__body-text"><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/the-state-of-email-security-2023">DOWNLOAD FOR FREE</a></p></div></div><p>Deloitte also said that it conducted an investigation into the possibility of a breach in the wake of the MOVEit incident, but has thus far determined that no client data has been impacted. </p><p>The spokesperson noted that the firm’s use of the file transfer software was “limited”. </p><p>“Our analysis determined that our global network use of the vulnerable MOVEit Transfer software is limited,” they said. “Having conducted our analysis, we have seen no evidence of impact to client data.”</p><p>Deloitte&apos;s page on Cl0p&apos;s website does not yet feature download links for files. This could indicate that Deloitte&apos;s assessment is correct and Cl0p has not managed to access client data.</p><p>It could also mean that Cl0p is still waiting to negotiate a payment from Deloitte for any data it was able to steal during an attack. Deloitte said client data is believed to be unaffected but in multiple recent Cl0p-associated incidents, data stolen from victims has concerned internal staff rather than clients.</p><p>Cl0p has also been linked with the earlier <a href="https://www.itpro.com/security/data-breaches/370409/the-goanywhere-data-breach-explained">GoAnywhere breach</a> which saw the <a href="https://www.itpro.com/security/ransomware/370329/pension-protection-fund-confirms-employee-data-exposed-goanywhere-breach">Pension Protection Fund</a> also lose data related to current and former staff, but not current members.</p><h2 id="moveit-attack-what-happened">MOVEit attack - what happened?</h2><p>News of the MOVEit attack emerged in late May amid speculation that a zero-day vulnerability in the transfer software had been exploited by threat actors. </p><p>Security researchers at Microsoft <a href="https://www.itpro.com/security/data-breaches/microsoft-says-it-knows-who-was-behind-cyber-attacks-on-moveit-transfer">quickly identified Cl0p as the group behind the attack</a>, and the incident began to spiral out of control.</p><p>Within days, several major organizations globally revealed they had been impacted by the breach, including payroll provider Zellis.</p><p>This sparked a series of subsequent breaches at a host of major organizations globally, with the number of victims rising to 513 at the time of writing, according to <a href="https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/" target="_blank">Emsisoft&apos;s figures</a>.</p><p>To date, hundreds of organizations spanning a number of industries have been affected by the breach. </p><p>Cl0p has added nearly 50 victims to its list in the last week alone, including Toyota’s European subsidiary and Virgin Pulse. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Female representation in UK cyber drops amid growing skills demand ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/female-representation-in-uk-cyber-drops-amid-growing-skills-demand</link>
                                                                            <description>
                            <![CDATA[ While firms are accelerating efforts to recruit more women, an industry shortfall still remains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8juy4yGTzH7rJtCsyJ5N5H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Waw5uyPEzd9eCdtEYtFQZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jul 2023 11:29:03 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 11:36:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Waw5uyPEzd9eCdtEYtFQZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female cyber security analyst with glasses working on computer]]></media:description>                                                            <media:text><![CDATA[Female cyber security analyst with glasses working on computer]]></media:text>
                                <media:title type="plain"><![CDATA[Female cyber security analyst with glasses working on computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Waw5uyPEzd9eCdtEYtFQZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of women working in the UK cyber security industry has decreased, sparking concerns that efforts to improve diversity in the space are falling flat. </p><p>A report from the UK government on cyber security skills across the labor market found that only 17% of the cyber sector workforce is female, marking a decrease from 22% last year and on par with 2021 and 2020 statistics. </p><p>The study found that just 14% of senior roles are filled by women across the industry, a figure that’s risen steeply since 2021’s result of just 3%, but one that still underlines a clear imbalance of power.</p><p>The report noted that the proportion of women in the cyber workforce has remained “broadly consistent” in recent years. The results from 2021, for example, showed that 16% of the cyber workforce was female, indicating only a very small improvement in the space of two years.</p><p>“Although there were signs of an upward trend last year, this has not been sustained,” it said. </p><p>The dip in female representation comes at a critical time in the <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a> space, with demand for skills rising steeply in recent years. </p><p>The report said there is an estimated shortfall of 11,200 people in the industry, and while this does mark a dip from 14,100 in 2021, this is largely due to slower growth in the sector. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ctD3aHRmTxusoAysAD8xxN" name="Teaching good cyber security behaviors_listing.jpg" caption="" alt="Dark blue whitepaper cover with white title and green people icons with a  green check and green cross above" src="https://cdn.mos.cms.futurecdn.net/ctD3aHRmTxusoAysAD8xxN.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Teaching good cyber security behaviors with Seinfeld</strong></p><p class="fancy-box__body-text"><em>Overcome the employee engagement challenge in security awareness training.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/teaching-good-cyber-security-behaviors-with-seinfeld"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Around 50% of all UK businesses were found to have a “basic cyber security skills gap” while one-third (33%) have an “advanced” security skills gap. </p><p>This aligns with previous estimates from 2022 and 2021, and highlights that firms across the country are still contending with an acute skills shortfall amid a period of rising threats. </p><p>An analysis of cyber security job postings in the last year shows that firms are seeking to bolster security-related skills within their workforce.</p><p>160,035 job postings were recorded last year, but 37% of these vacancies were reported as “hard to fill” by businesses, the report said. </p><h2 id="what-x2019-s-being-done-to-improve-diversity">What’s being done to improve diversity?</h2><p>The report noted that businesses are accelerating efforts to <a href="https://www.itpro.com/business/business-strategy/369818/how-to-implement-an-effective-diversity-and-inclusion-strategy"><u>improve workforce diversity</u></a>. </p><p>Nearly half (40%) of cyber firms said they had taken action to “adapt their <a href="https://www.itpro.com/business-strategy/recruitment/363725/it-pro-panel-tackling-technical-recruitment"><u>recruitment processes</u></a> or carried out specific activities” to attract and encourage applications from diverse groups. </p><p>38% also said they have accelerated efforts to recruit more women and bolster gender diversity within the workforce.</p><p>Across all “diverse groups” - which spans women, people from ethnic minority backgrounds, neurodiverse, and physically disabled people - women were “slightly more likely” to have been targeted in recruitment drives.</p><p>Amanda Finch, CEO at The Chartered Institute of Information Security (CIISec) said that her organization’s own research shows firms can still do more to attract female talent and encourage women to enter the industry. </p><p>“Often the security industry is stereotyped as something of a ‘boys only club’. CIISec’s latest state of the industry report highlighted the progress the industry still needs to make on this,” she said. </p><p>“38% of organizations have not implemented development programs to attract women to join the profession or promote those already in it, and a further 5% have tried but failed.”</p><h2 id="alternative-routes-into-cyber">Alternative routes into cyber</h2><p>Employers also revealed they are exploring alternative routes into the cyber workforce for diverse groups. However, the report noted that this is typically focused on entry-level roles. </p><p>“Hiring through non-degree routes” was identified as a key approach among many, with ‘capture the flag’ tests used to “identify raw talent”. </p><p>Similarly, firms revealed they are also working with third-sector organizations to improve support for diverse groups within the workforce talent pool. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Weekly cyber attacks reach two-year high amid ransomware resurgence ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/weekly-cyber-attacks-reach-two-year-high-amid-ransomware-resurgence</link>
                                                                            <description>
                            <![CDATA[ The surge in attacks comes amid a period of resurging ransomware activity and concerns over vulnerability disclosures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HWWme2yxnuMmPr6xmnMpRf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Jul 2023 11:24:49 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jul 2023 12:23:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber attacks: Digital cloud and network security. 3D computer hardware illustration.]]></media:description>                                                            <media:text><![CDATA[Cyber attacks: Digital cloud and network security. 3D computer hardware illustration.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber attacks: Digital cloud and network security. 3D computer hardware illustration.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5TwUgdWivXfZZjJxeWEgiM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The average weekly volume of cyber attacks reached a two-year high in the second quarter of 2023 amid a spike in activity among ransomware groups. </p><p>Analysis from Check Point Research (CPR) found that the frequency of attacks increased by 8% in Q2, with organizations globally facing an average of 1,258 attacks each week. </p><p>A key factor in this surge lies in the evolution of “new evasive tactics”, combined with an increase in hacktivist-based attacks and increased ransomware group activity, the firm said. </p><p>Despite a reduction in attacks compared to the year prior, the education and research sector still remained the most-targeted industry during the second quarter, CPR noted. </p><p>The average number of attacks per organization stood at 2,179, although this marked a 6% decrease compared to the same period in 2022. </p><p>UK-based academic institutions have faced a barrage of attacks so far during 2023. In June, the University of Manchester experienced a <a href="https://www.itpro.com/security/data-breaches/nhs-data-leak-raises-serious-questions-about-manchester-university-cyber-attack"><u>highly disruptive cyber attack </u></a>that exposed research data belonging to more than 1.1 million NHS patients. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bBCW7mSoZuzjDPGyRGZQVg" name="The Threat Prevention Buyer’s Guide_listing.jfif.jpg" caption="" alt="Whitepaper cover with title and logo over image of female worker wearing glasses with digital screens reflected in them and workstations in the background" src="https://cdn.mos.cms.futurecdn.net/bBCW7mSoZuzjDPGyRGZQVg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The threat prevention buyer&apos;s guide</strong></p><p class="fancy-box__body-text"><em>Find the best advanced and file-based threat protection solution for your organization.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management/the-threat-prevention-buyers-guide"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The healthcare industry has been a key recurring target for cyber criminals in recent years, with the sector experiencing a significant year-on-year increase in attacks during Q2. </p><p>Organizations operating in the sector faced an average of 1,744 attacks per week, marking a YoY increase of 30%. </p><p>Earlier this month, Barts NHS Trust, which serves more than 2.5 million patients across several hospitals, fell victim to the <a href="https://www.itpro.com/security/cyber-attacks/western-digital-refuses-to-negotiate-with-hackers-as-alphv-offers-final-warning"><u>ALPHV ransomware gang</u></a>. </p><p>The group claimed to have stolen more than 70 terabytes of data, which it said marks the largest breach of healthcare data in the UK to date. </p><h2 id="ransomware-resurgence-raises-concerns">Ransomware resurgence raises concerns</h2><p>A resurgence in activity among high-profile ransomware groups has raised concerns among security researchers in recent months, CPR said. </p><p>Alternative <a href="https://flashpoint.io/blog/cyber-threat-intelligence-index-june-2023/"><u>analysis from FlashPoint</u></a> found that LockBit and Cl0p alone accounted for nearly 40% of all recorded ransomware attacks across June, with nearly half (47.5%) of these directly targeted US-based organizations.  </p><p>Both groups have been highly aggressive in recent weeks, with Cl0p claiming responsibility for the devastating <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack"><u>MOVEit supply chain attack</u></a>. </p><p>The file transfer platform is used by thousands of organizations globally, and initially impacted several UK firms including British Airways, Boots, and the BBC. </p><p>This incident prompted a domino effect of incidents worldwide following a breach at HR and payroll provider, Zellis. </p><p>LockBit has also been highly active, claiming responsibility for an <a href="https://www.itpro.com/security/ransomware/tsmc-faces-dollar70-million-lockbit-ransom-demand-following-hardware-supplier-breach"><u>attack on a third-party supplier</u></a> for Taiwanese chipmaker, TSMC. The group listed the chipmaker on its dark web blog and set a ransom at $70 million, marking one of the largest ever. </p><p>Continued threats for healthcare organizations may also raise concerns amid the increase in LockBit attacks highlighted by Flash Point. The ransomware group has traditionally targeted organizations operating in the sector. </p><p>In August last year, the group claimed responsibility for an attack on a French hospital that saw sensitive patient data leaked after its $10 million ransom was refused. </p><p>The observations on the leading ransomware organizations come against a backdrop of rising attacks generally across the industry.</p><p>A report published earlier this month noted a <a href="https://www.itpro.com/security/cyber-crime/cyber-insurance-costs-fall-in-2023-despite-steep-rise-in-ransomware-attacks"><u>48% year-on-year increase in attacks</u></a>.</p><p>Chainalysis’ annual <em>Crypto Crime </em>report, also published earlier this month, noted that ransomware affiliates have returned to their old habits of <a href="https://www.itpro.com/security/ransomware/big-game-ransomware-tactics-return-as-attackers-eye-lucrative-payouts"><u>targeting larger organizations</u></a>.</p><p>Ransomware criminals have for years switched between targeting organizations of different sizes, with efforts from the past few years thought to have been focused more on smaller firms with comparatively less robust defenses than larger enterprises.</p><h2 id="overlooked-vulnerabilities">Overlooked vulnerabilities</h2><p>Running in parallel to a surge in cyber attacks, FlashPoint research highlighted a concerning trend of overlooked or missing vulnerability disclosures in June. </p><p>1,828 new vulnerabilities were reported across the month. However, 395 of these were missed by the Common Vulnerabilities and Exposures (CVE) program. </p><p>More than one-third (35%) of these were rated as high or critical vulnerabilities, which the firm warned is putting organizations at heightened risk. </p><p>“If exploited, these issues could pose a significant security risk”, the firm said in a <a href="https://flashpoint.io/blog/cyber-threat-intelligence-index-june-2023/"><u>blog post</u></a>. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TSMC faces $70 million LockBit ransom demand following hardware supplier breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/tsmc-faces-dollar70-million-lockbit-ransom-demand-following-hardware-supplier-breach</link>
                                                                            <description>
                            <![CDATA[ While TSMC has confirmed the breach, it has refuted claims that company operations have been disrupted by the incident ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">abftQ2pv4FYA9o7UqgyrDh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/94UJgGK3E7T2UUGoeHewne-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jun 2023 11:59:05 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Jul 2023 13:56:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/94UJgGK3E7T2UUGoeHewne-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TSMC: Signage for Taiwan Semiconductor Manufacturing Co. (TSMC) during the company&#039;s annual shareholder meeting in Hsinchu, Taiwan.]]></media:description>                                                            <media:text><![CDATA[TSMC: Signage for Taiwan Semiconductor Manufacturing Co. (TSMC) during the company&#039;s annual shareholder meeting in Hsinchu, Taiwan.]]></media:text>
                                <media:title type="plain"><![CDATA[TSMC: Signage for Taiwan Semiconductor Manufacturing Co. (TSMC) during the company&#039;s annual shareholder meeting in Hsinchu, Taiwan.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/94UJgGK3E7T2UUGoeHewne-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Taiwanese chipmaker TSMC could be facing one of the largest ransom demands in history amid reports that threat actors have gained access to sensitive company information. </p><p>An affiliate group of LockBit’s ransomware as a service offering, known as National Hazard Agency, claims to have gained access to TSMC network entry points as well as staff login details following a breach at <a href="https://www.itpro.com/security/cyber-attacks/borderline-irresponsible-attitude-to-third-party-risks-must-change-says-expert">third-party IT supplier</a> Kinmax. </p><p>LockBit has officially listed TSMC on its dark web blog, setting the ransom demand at $70 million. </p><p>The blog listing from LockBit fails to provide additional information on the extent of the data compromised in the breach, nor does it provide samples to confirm what has been stolen. </p><p>LockBit has threatened that “in the case of payment refusal” it will publish stolen information on network entry points, as well as login details. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">National Hazard Agency, a sub-clique of Lockbit ransomware group, has ransomed TSMC (Taiwan Semiconductor Manufacturing Company).The company has an estimated annual revenue of $57,220,000,000.National Hazard Agency is ransoming them for $70,000,000. pic.twitter.com/bXjzQ7SSXU<a href="https://twitter.com/vxunderground/status/1674664082065043456">June 30, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>In a statement, Kinmax confirmed it had suffered a security breach, revealing that its “internal specific testing environment” had been compromised. </p><p>“The leaked content mainly consisted of system installation preparation that the company provided to our customer as default configurations,” Kinamax said. </p><h2 id="tsmc-operations-x201c-not-affected-x201d-by-breach">TSMC operations “not affected” by breach</h2><p>TSMC told <em>ITPro </em>that it was aware that an IT hardware supplier had experienced a security incident, confirming that leaked data pertained to “server initial setup and configuration”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZcmGPrUjmR5jKB3uiLmEEn" name="Supply chain as kill chain_listing.jpg" caption="" alt="Colleagues in a tech lab all looking at a laptop" src="https://cdn.mos.cms.futurecdn.net/ZcmGPrUjmR5jKB3uiLmEEn.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Supply chain as kill chain</strong></p><p class="fancy-box__body-text"><em>Learn more about data hygiene, supply chain security, and omni-channel retail</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370164/supply-chain-as-kill-chain"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>However, the Taiwanese semiconductor giant has refuted claims that the attack has impacted its operations, adding that no customer information had been compromised in the breach. </p><p>“This incident has not affected TSMC’s business operations, nor did it compromise any TSMC customer information,” the firm said in a statement. </p><p>Upon discovery of the Kinmax incident, TSMC said it “immediately terminated” its data exchange with the supplier in accordance with company security protocols. </p><p>The firm is also working with law enforcement following the discovery. </p><p>“TSMC remains committed to enhancing the security awareness among its suppliers and making sure they comply with security standards,” the firm said. </p><p>“This cyber security incident is currently under investigation that involves a law enforcement agency.”</p><p>This latest LockBit ransom demand marks one of the largest ever from a hacker group, putting it on par with REvil’s infamous demand in the wake of the <a href="https://www.itpro.com/security/ransomware/360122/up-to-1500-organizations-compromised-in-kaseya-ransomware-attack"><u>Kaseya breach</u></a>. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Top 5 Highest Ransom Demands 📈🔘 Hive: MediaMarkt - $240m🔘 REvil: Acer - $100m🔘 REvil: Kaseya - $70m🔘 LockBit: TSMC - $70m 🆕🔘 LockBit: Pendragon - $60mHonourable mention:🔘 EvilCorp: CNA Financial - $40m (Paid)<a href="https://twitter.com/BushidoToken/status/1674693662595325952">June 30, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>The hefty ransom also eclipses previous demands made by LockBit, specifically the <a href="https://www.itpro.com/security/ransomware/369376/pendragons-zealous-response-to-lockbit-ransomware-breath-of-fresh-air">Pendragon breach</a> in 2022 that was set at $60 million. </p><p>In March 2021, <a href="https://www.itpro.com/security/ransomware/358969/acer-ransomware-attack"><u>Acer was targeted by REvil</u></a>, the group that used to occupy the role of the most prolific ransomware organization, with a ransom set at a maximum $100 million.</p><p>The price was originally set at $50 million, a sum that REVil promised to increase sharply if it wasn’t paid quickly.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS data leak raises ‘serious questions’ about Manchester University cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/nhs-data-leak-raises-serious-questions-about-manchester-university-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ NHS patient data used for research purposes is believed to have been compromised in the June attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3wk4vmDGYLMfAiz3bGwQnX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V8a67keCNEqeQhdAtKjFxN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jun 2023 11:24:09 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Jul 2023 13:50:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V8a67keCNEqeQhdAtKjFxN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NHS: Healthcare professional using a tablet denoting a link between technology and the healthcare industry]]></media:description>                                                            <media:text><![CDATA[NHS: Healthcare professional using a tablet denoting a link between technology and the healthcare industry]]></media:text>
                                <media:title type="plain"><![CDATA[NHS: Healthcare professional using a tablet denoting a link between technology and the healthcare industry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V8a67keCNEqeQhdAtKjFxN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have raised concerns about the risks posed to NHS patient data in the wake of the University of Manchester cyber attack. </p><p>A report from the <em>Independent</em> claimed that data belonging to more than one million NHS patients may have been compromised in the June attack. </p><p>Data accessed by threat actors during the incident is believed to pertain to trauma patients and people treated for injuries sustained in terror attacks. </p><p>The data sets, gathered for research purposes by the university, included NHS numbers and the ‘first three letters’ of patients’ postcodes, according to leaked documents <a href="https://www.independent.co.uk/news/health/nhs-patient-data-attack-b2364202.html"><u>seen by the publication</u></a>. </p><p>The university has since informed <a href="https://www.itpro.com/outsourcing/31153/nhs-england-s-330m-cost-cutting-deal-with-capita-put-patients-at-risk"><u>NHS England</u></a> of the data breach, but a notice to the healthcare provider warned that it is still unclear whether affected patients&apos; names have been compromised.  </p><p>This prompted the university to issue a warning that there is potential for “NHS data to be made available in the public domain”. </p><p>Similarly, university officials warned that some affected patients may not even know they are on the database as they were not required to provide consent. </p><p>Deryck Mitchelson, field <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISO</u></a> at Check Point and former CISO at NHS National Services Scotland, said the incident should serve as a stark warning over the potential risks of data sharing between private organizations and public services. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zcgryVGkujpbfYJvspEN6b" name="Three ways to evolve your security operations_listing.jpg" caption="" alt="Red whitepaper cover with image of office building from the ground up" src="https://cdn.mos.cms.futurecdn.net/zcgryVGkujpbfYJvspEN6b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Three ways to evolve your security operations</strong></p><p class="fancy-box__body-text"><em>Why current approaches aren’t working, plus three new methods to consider</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/three-ways-to-evolve-your-security-operations"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“The questions we need to be asking is why has the university, as a private commercial organization, had access to personal identifiable information from the NHS,” he said. </p><p>“How many other universities have this type of data stored on their own servers?”</p><p>Mitchelson said the university must provide clarity on a number of key lingering questions, such as whether the data was obfuscated or de-identified, whether these data sets were segmented from others, and what safeguards the university had in place for the use of research data. </p><p>“Where patient information is being used for research, there should be as much openness and transparency about that use as possible,” he said. </p><p>“All of this opens up far more concerning conversations around data sharing between public and private organizations which needs to be addressed.”</p><p><em>ITPro</em> has approached the University of Manchester for comment on the matter.</p><h2 id="university-of-manchester-attack-what-happened">University of Manchester attack: What happened?</h2><p>In early June, the university <a href="https://www.itpro.com/security/cyber-attacks/university-of-manchester-admits-cyber-incident-likely-led-to-data-theft"><u>revealed it had experienced a “cyber incident”</u></a> and confirmed that some systems had been accessed by an unauthorized third party.  </p><p>In the wake of the breach, staff were advised not to download files from university systems in an attempt to back them up.</p><p>University officials said that data had “likely been copied” during the breach and the institution was working with authorities to identify the source of the issue. Last week, the university confirmed that data had been stolen. </p><p>The incident was initially believed to be linked to a breach at payroll provider Zellis in the wake of the <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack"><u>MOVEit cyber attack</u></a>. However, the university refuted these claims. </p><p>To date, the university says it is yet to establish the identity of the threat actor or actors behind the attack. </p><p>In recent weeks, students and staff members at the university have complained that they have received emails from the culprits threatening to sell or leak their personal data unless a ransom is not paid. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Standardized information sharing framework 'essential' for improving cyber security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/standardized-information-sharing-framework-essential-for-improving-cyber-security</link>
                                                                            <description>
                            <![CDATA[ Companies are already weathering the cyber storm, but more can be done to help recovery, experts say ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ktokouncQAgGgH3oo3hMbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Jun 2023 11:21:20 +0000</pubDate>                                                                                                                                <updated>Wed, 21 Jun 2023 15:26:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cyber security insurance and risk management mockup. A person&#039;s hands and torso shown using a laptop, which is seen from behind, as a digital graphic of information and an umbrella icon hover above the keyboard.]]></media:description>                                                            <media:text><![CDATA[A cyber security insurance and risk management mockup. A person&#039;s hands and torso shown using a laptop, which is seen from behind, as a digital graphic of information and an umbrella icon hover above the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[A cyber security insurance and risk management mockup. A person&#039;s hands and torso shown using a laptop, which is seen from behind, as a digital graphic of information and an umbrella icon hover above the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HtMzNHSiMiAUAvku5ChTxa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have called for improvements in how private sector organizations share threat intelligence data with the wider industry.</p><p>It’s believed that better cross-organizational collaboration would improve cyber resiliency in the face of cyber attacks that continue to rise in frequency and develop ever more sophisticated.</p><p>“I think this is one of the ways in which the private sector can work with governments around the world, and each other across sectors, industries, and regions,” said Jen Ellis, co-chair at the Institute for Science and Technology’s Ransomware Task Force.</p><p>Government agencies such as the UK’s Information Commissioner’s Office (ICO) or the US’ Cybersecurity and Infrastructure Security Agency (CISA) enforce strict reporting deadlines around data breaches, but companies often report the minimum required information.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zcgryVGkujpbfYJvspEN6b" name="Three ways to evolve your security operations_listing.jpg" caption="" alt="Red whitepaper cover with image of office building from the ground up" src="https://cdn.mos.cms.futurecdn.net/zcgryVGkujpbfYJvspEN6b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Three ways to evolve your security operations</strong></p><p class="fancy-box__body-text"><em>Why current approaches aren’t working</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/three-ways-to-evolve-your-security-operations"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The designated cyber security authorities in the UK and US enforce strict reporting deadlines around data breaches and this is seen as a positive step. </p><p>However, victims often report the minimum required information which in turn reduces other organizations’ ability to learn from, and potentially prevent, follow-on attacks.</p><p>The panel spoke at Infosecurity Europe 2023, discussing the topic of a so-called ‘catastrophic cyber storm’ that businesses currently face.</p><p>Nick Prescot, CISO at Norgine B.V, noted that there already is a great deal of information sharing in the industry, but much of the information is shared through private channels and the public’s perception of that exchange is limited.</p><p>“It’s easy to say that we can talk to everyone and every organization can talk to each other,” said Cedric Mallia, CISO at Play’n GO.</p><p>“In practice, that’s way more complex, because sometimes you have to share information with your competitors or with entities that could use that information to extrapolate things you don’t want them to.”</p><p>Mallia also noted that sometimes data shared can give an inaccurate picture of how an attack was carried out or handled.</p><p>“It is nearly a legal issue to know what to say, without giving away information that you don’t wish others to know. And that makes it very, very difficult.”</p><p>Some smaller organizations may currently lack the relevant resources or knowledge to react to an attack in the best way and could benefit from data sharing with larger organizations, particularly those that have weathered similar attacks.</p><p>But many fear exposing proprietary information by being too open around attacks, and security teams may be concerned that public insight into defensive strategies could open them up to further attacks down the line.</p><p>Dr. Fene Osakwe, group head of digital and technology assurance at the Wellcome Trust, suggested that legislation or guidelines could be drawn up for what data to share.</p><p>“It’s difficult to share without a framework that governs what is allowed to be shared, and what exactly is being classified as intelligence,” he said.</p><p>“I think that it’s important for a trusted, independent party whether it’s the government or an NGO, to create that framework that states under what conditions, how, and with who information will be shared and what it will be used for.”</p><p>Osakwe further suggested that it should be the responsibility of executives, rather than security teams, to ensure that these channels of communication are maintained.</p><h2 id="x201c-arrogance-x201d-to-try-to-avoid-the-storm">“Arrogance” to try to avoid the storm</h2><p>Mallia branded the attitude of some companies “arrogance”, and argued that those that still believe they can avoid becoming involved in the current threat landscape altogether could cause their own downfall.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dtzryvF42B8M2aazM4PbyS" name="The top zero trust use cases_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over an image of male colleague at a workstation in a warehouse, with dotted blue patter overlayed" src="https://cdn.mos.cms.futurecdn.net/dtzryvF42B8M2aazM4PbyS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The top zero trust use cases</strong></p><p class="fancy-box__body-text"><em>The challenges organizations solve to reduce risk and cost</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-top-zero-trust-use-cases"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“It is a storm at the end of the day, but we have the ability and knowledge to weather it out,” he continued. </p><p>“Those who are resilient will come out the other side.”</p><p>For many businesses, the ‘storm’ of cyber attacks has arrived in full force. <a href="https://www.itpro.com/security/369813/cyber-attacks-on-uk-organisations-surged-77-in-2022-new-research-finds"><u>Cyber attacks on UK organizations rose 77% in 2022</u></a>, and new ransomware strains like <a href="https://www.itpro.com/security/ransomware/370386/new-rorschach-ransomware-almost-twice-as-fast-as-lockbit"><u>Rorschach</u></a> continue to raise the threat ceiling.</p><p>International police forces have <a href="https://www.itpro.com/security/cyber-crime/latest-arrest-places-lockbit-firmly-in-the-crosshairs-of-international-cyber-police"><u>set their sights on LockBit</u></a>, the notorious ransomware as a service operator, but attempts to stamp out threats continue to play second fiddle to defensive and remediation efforts.</p><p>The panelists urged attendees to consider their security contingencies, as attacks are bound to occur but businesses are made or broken by their preparedness to quickly recover.</p><p>“It’s about making it harder for attackers, every time,” said Ellis.</p><p>“It’s about raising that bar, making it more expensive and inconvenient for them. We’re never going to be this mythical thing of ‘secure’, but we can continue to make progress.”</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="geopolitical-awareness-needed">Geopolitical awareness needed</h2><p>All panelists made the case for companies to heighten awareness of the worldwide cyber security and geopolitical landscape to improve their threat posture.</p><p>“People think that the ‘big bad countries’ are going to flyswat small countries,” said Prescot.</p><p>“But with cyber it’s different, it’s very asymmetric,” he said, and cited <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack"><u>Cl0p’s MOVEit supply chain attack</u></a> as a recent example of the kind of smaller, possibly state-backed groups with which companies are having to contend.</p><p>Osakwe gave the example of an African company with whom he had worked, which was targeted by a politically-motivated cyber attack based on a rumor that it had worked with an opposition party.</p><p>“When that information came, it gave the security team a lot more perspective of what to do,” said Osakwe.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Toyota customers in Asia & Oceania at risk following recent data leak ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/toyota-customers-in-asia-and-oceania-at-risk-following-recent-data-leak</link>
                                                                            <description>
                            <![CDATA[ The incident marks the third data leak in the space of a year for Toyota ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X9VMNBQS9caxGgHXxL2XBk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 May 2023 11:11:14 +0000</pubDate>                                                                                                                                <updated>Wed, 31 May 2023 12:14:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg">
                                                            <media:credit><![CDATA[Yiuchi Yamazaki/AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:description>                                                            <media:text><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:text>
                                <media:title type="plain"><![CDATA[Toyota logo pictured outside the Japanese car maker&#039;s headquarters in Tokyo, Japan.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uA28QY8bdyYK55RqhffdiP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data belonging to Toyota customers in Asia and Oceania may have been “publicly accessible” between October 2016 and May 2023 due to a cloud misconfiguration, the company has revealed. </p><p>In an advisory, the car manufacturer revealed exposed data includes names, addresses, phone numbers, email addresses, vehicle identification numbers, and registration details.</p><p>Critical data, such as credit card information, was not exposed in the leak, the manufacturer insisted.</p><p>Toyota said the leak was caused by a cloud misconfiguration as a result of human error, adding that the flaw has since been remediated. </p><p>“Some of the files that TC (Toyota Connected Corporation) manages in the cloud environment for overseas dealers&apos; maintenance and investigation of systems were potentially accessible externally due to a misconfiguration,” the company <a href="https://global.toyota/en/newsroom/corporate/39241625.html" target="_blank"><u>said in a statement</u></a>. </p><p>“After this matter was discovered, we took steps to block access from outside the company.”</p><p>Toyota did not disclose the exact number of customers affected. It also said a preliminary investigation found no evidence any of the exposed data had been accessed or maliciously exploited. </p><p>“We have also investigated whether, with this incident, there was any secondary use or if third-party copies remain on the internet, and no evidence of such has been found. At present, we have not confirmed any secondary damage,” it said.</p><h2 id="recurring-toyota-data-leaks">Recurring Toyota data leaks</h2><p>This latest disclosure follows an investigation into a similar data leak in early May in which data belonging to more than 2.15 million customers in Japan was <a href="https://www.itpro.com/cloud/cloud-security/cloud-system-error-left-toyota-customer-data-exposed-for-ten-years"><u>left accessible for nearly a decade</u></a>. </p><p>At the time, Toyota said a worker at the firm was believed to have set a cloud system’s access level to ‘public’ instead of ‘private’, meaning that data pertaining to vehicle locations and identification numbers was exposed. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L47gbigPjNi8zfgWvSgmk3" name="L47gbigPjNi8zfgWvSgmk3.png" caption="" alt="Whitepaper cover with title, text, and SWOT analysis chart" src="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Magic quadrant for Security Information and Event Management (SIEM)</strong></p><p class="fancy-box__body-text"><em>Assessing the current solutions in the market for threat detection, investigation, and response capabilities</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>This incident sparked a probe at the car manufacturer to improve monitoring of its internal systems and bolster employee data protection practices. Toyota said it has since introduced new rules and processes to monitor cloud configurations across its global operations. </p><p>“As we believe that this incident also was caused by insufficient dissemination and enforcement of data handling rules, since our last announcement, we have implemented a system to monitor cloud configuration,” the company revealed. </p><p>“Currently, the system is in operation to check the settings of all cloud environments and to monitor the settings on an ongoing basis. In addition, we will work closely again with TC to explain and thoroughly enforce the rules for data handling.”</p><p>This is also the third data breach of its kind in the space of a year for Toyota. In October 2022, the manufacturer revealed that data <a href="https://www.itpro.com/security/data-breaches/369292/toyota-discovers-five-year-old-email-leak-risks-phishing-attacks"><u>belonging to nearly 300,000 customers was exposed online</u></a>. </p><p>An access key was found to have been left publicly available on <a href="https://www.itpro.com/software/development/359246/how-to-download-from-github">GitHub</a> for nearly five years. This particular incident affected Toyota’s T-Connect service and allowed access to a server containing customer email addresses. </p><p>The incident prompted Toyota to warn customers that they could face an onslaught of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> threats in the wake of the leak.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Data Protection Act 2018? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/data-protection/34061/what-is-the-data-protection-act-2018</link>
                                                                            <description>
                            <![CDATA[ The relationship between the UK's Data Protection Act and GDPR: An in-depth look ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d9XwTaeRrkVs1rENSrCjmi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ac4YQsZyHatCHishgE9mFi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jul 2019 12:59:00 +0000</pubDate>                                                                                                                                <updated>Sat, 27 Jul 2024 14:05:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ dale.walker@futurenet.com (Dale Walker) ]]></author>                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dale Walker is the Managing Editor of ITPro, and its sibling sites CloudPro and ChannelPro. Dale first joined ITPro in 2016 as an intern, and gone on to hold a variety of different positions across the brand, including a Staff Writer role where he developed a keen interest in IT regulations, data protection, and cyber security. He spent a number of years reporting for ITPro from numerous domestic and international events, including IBM, Red Hat, Google, and has been a regular reporter for Microsoft&#039;s various yearly showcases, including Ignite. Dale is also the Editor of &lt;a href=&quot;https://www.itpro.com/itpro-2020&quot;&gt;ITPro 20/20&lt;/a&gt;, a monthly digital magazine providing a snapshot of the stories and themes shaping the business tech world.&lt;/p&gt;
&lt;p&gt;Prior to joining ITPro, Dale secured a Masters degree in Magazine Journalism from the University of Sheffield, where he also won a number of awards for his design and concept work, including BBC Worldwide Best New Magazine Brand at the 2016 Magazine Academy awards.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ David Howell ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ac4YQsZyHatCHishgE9mFi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock on a circuit board in a dark room]]></media:description>                                                            <media:text><![CDATA[A padlock on a circuit board in a dark room]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock on a circuit board in a dark room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ac4YQsZyHatCHishgE9mFi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Data Protection Act 2018 (DPA 2018), designed to update existing data protection laws and regulations, came into force on 23 May 2018 as the third generation of the UK&apos;s data protection environment.</p><p>Based on the EU&apos;s <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>General Data Protection Regulation</u></a> (GDPR), the DPA 2018 is designed to consider advancements in data use in the modern age and how personal information is collected by online platforms for various legitimate and illegitimate purposes.</p><p>The DPA 2018 was introduced to replace the earlier <a href="https://www.itpro.com/data-protection/28085/what-is-the-data-protection-act-1998"><u>Data Protection Act 1998</u></a>. It outlines the legal extent to which data can be collected, processed, and used within the UK and sets out several penalties for those who breach these laws. More specifically, the framework laid out by the DPA 2018 governs the steps businesses and individuals must take when handling data. It also provides data owners, known as data subjects, with a clear guideline for their rights and protections concerning personal information.</p><p>The DPA 2018 was required in order for the UK to maintain a similar level of data protections to that of the EU - known as adequacy status. This allows the UK to process data owned by EU citizens. However, the DPA 2018 adds to and goes beyond the rules of GDPR. Instead of just copying GDPR into UK law, the DPA 2018 included the EU Law Enforcement Directive, which protects data used by the police and other law enforcement agencies.</p><h2 id="why-do-we-need-dpa-2018-when-we-have-gdpr">Why do we need DPA 2018 when we have GDPR?</h2><p>Although there are similarities between the two, the DPA 2018 and the EU&apos;s GDPR differ in several key areas:</p><p>When it came into force, GDPR automatically applied to all EU member states but allowed individual nations to create their own provisions to extend their reach depending on their particular needs. This flexibility enabled member states to implement data protection laws that complemented their existing regulations.</p><p>Most of the UK&apos;s data processing was governed by <a href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other"><u>GDPR until Brexit</u></a>, though a few regulatory issues were specific to the UK and handled only by domestic laws. Examples include <a href="https://www.itpro.com/policy-legislation/32783/activist-groups-win-right-to-challenge-immigration-data-exemption"><u>immigration issues</u></a> and processing <a href="https://www.itpro.com/policy-legislation/30218/what-is-a-freedom-of-information-foi-request"><u>freedom of information</u></a> (FOI) data. The DPA 2018 also includes several national security exemptions. While GDPR sets a broad framework for data protection across the EU, it allows individual member states to tailor specific provisions to fit national contexts. The DPA 2018 addresses data protection needs and issues unique to the UK.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">What is the Information Commissioner’s Office (ICO)?</a> </p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit: How will one affect the other?</a> </p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/general-data-protection-regulation-gdpr/31795/government-faces-legal-challenge-over-immigrant-data" data-original-url="/general-data-protection-regulation-gdpr/31795/government-faces-legal-challenge-over-immigrant-data">Government faces legal challenge over immigrant data rights</a></p></div></div><p>Also, the DPA 2018 integrates and updates the UK&apos;s previous data protection laws, ensuring they are compatible with GDPR while addressing purely domestic concerns. This includes exemptions and rules specific to the UK&apos;s regulatory environment. The DPA 2018 provides clear legal guidelines and enforcement mechanisms within the UK context. It defines the roles and responsibilities of the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico"><u>Information Commissioner&apos;s Office</u></a> (ICO) and sets out penalties for non-compliance, thereby ensuring robust data protection enforcement within the UK.</p><p>For example, under the DPA 2018, the Home Office and other organisations processing immigration data can reject access requests to personal data if they believe it could harm "effective immigration control".</p><p>However, this exemption faced challenges from human and digital rights campaigners. The Open Rights Group and the3million launched a <a href="https://www.itpro.com/policy-legislation/32783/activist-groups-win-right-to-challenge-immigration-data-exemption"><u>legal challenge in January 2019</u></a>, arguing that the immigration data exemption was unlawful. The High Court ultimately rejected this challenge in October 2019.</p><p>The DPA 2018 also includes provisions not directly applied to GDPR in UK law. For instance, the <strong>legal age for consent to process personal data is 16 under GDPR</strong>, but in the UK, <strong>it is 13</strong>. Additionally, the DPA 2018 allows for automated decision-making or profiling on legitimate grounds with appropriate safeguards, while GDPR ensures individuals have the right to avoid such processes.</p><h3 class="article-body__section" id="section-brexit"><span>Brexit</span></h3><p>Despite voting to leave the EU in 2016, the UK remained bound by EU legislation, including GDPR, until 31 January 2020. GDPR was incorporated into UK law via the European Union (Withdrawal) Act 2018. The DPA 2018 ensures the smooth flow of data from the EU to the UK post-Brexit. After leaving the EU on 31 January 2020, the UK entered a transition period, during which agreements on data adequacy were to be formalised. This agreement confirmed that UK laws provided adequate data protection.</p><p>Any organisation with customers in the EU must adhere to GDPR rules, regardless of the UK&apos;s EU membership status. Therefore, having domestic policies aligned with GDPR benefits companies by allowing them to comply with UK and EU data handling requirements without conflicting systems.</p><p>On 19 February 2021, the EU Commission published its draft adequacy decision, confirming that UK law was adequate for data transfers without additional safeguards. The EU Commission formally declared on 28 June 2021 that the UK ensures sufficient data protection for personal data transferred under GDPR from the EU to the UK.</p><p>This ruling is expected to last until June 2025, with a decision in 2024 on whether to extend it for another four years. However, it does not apply to data transferred to the UK for immigration-related issues, which have different requirements. At the moment, the House of Lords European Affairs Committee, chaired by Lord Ricketts, is considering the extension, <a href="https://www.parliament.uk/business/lords/media-centre/house-of-lords-media-notices/2024/march-2024/inquiry-into-data-adequacy-and-its-implications-for-the-uk-eu-relationship-launched-by-lords-committee/" target="_blank">with Lord Ricketts stating</a>:</p><p>"The free flow of data between the UK and EU is vital for trade and economic relations, and for effective law enforcement cooperation. Currently, the transfer of commercial and criminal investigation data is based on an EU adequacy decision which expires next year. Without it, maintaining data flows between the UK and the EU could become less straightforward for businesses and, therefore, have an impact on the UK economy. It could also have an impact on UK-EU security cooperation as it could lead to restrictions on the flow of data for law enforcement purposes between the UK and the EU."</p><p>Ricketts concluded: "My Committee has therefore decided to examine the way the current arrangement works, the factors that will influence a future data adequacy decision, and the implications should that decision be negative. The Committee encourages anyone with expertise in or experience of the matters under consideration in this inquiry to submit written evidence. The wider the range of evidence we receive, the more firmly based will be our conclusions."</p><h3 class="article-body__section" id="section-efforts-to-reform-gdpr"><span>Efforts to reform GDPR</span></h3><p>The previous Conservative government had indicated that the GDPR may be partially or entirely replaced with new data protection legislation. On 8 March 2023, the government presented the latest version of the <a href="https://www.gov.uk/government/publications/data-protection-and-digital-information-bill-impact-assessments/data-protection-and-digital-information-no-2-bill-european-convention-on-human-rights-memorandum"><u>UK Data Protection and Digital Information Bill No.2</u></a>, designed to alleviate the cost and administrative burden businesses in the UK feel complying with GDPR as it stands today in UK law.</p><p>Also, the Bill has components to govern and regulate <a href="https://www.itpro.com/strategy/29848/is-artificial-intelligence-safe"><u>artificial intelligence</u></a> (AI), which was not a distinct part of GDPR when it came into force. The UK&apos;s new version of GDPR also connects to the Artificial Intelligence (Regulation) Bill, which was designed to define the secure application of these burgeoning systems that will impact every business process, including how <a href="https://www.itpro.com/business/policy-and-legislation/the-uk-government-wants-to-upskill-regulators-in-the-age-of-generative-ai"><u>workforces</u></a> use tools like <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>Generative AI</u></a>.</p><p>Speaking at the time, then Conservative Secretary of State for Digital, culture, media and Sport (DCMS) Michelle Donelan, said: "Our plan will protect consumer privacy and keep their data safe whilst retaining our data adequacy, so that businesses can trade freely. Our new data protection plan will focus on growth, on common sense, on helping to prevent losses from cyberattacks and data breaches, while also protecting data privacy."</p><p>Julian David, TechUK CEO, also commented: "TechUK welcomes the new, targeted package of reforms to the UK&apos;s data protection laws, which builds on ambitions to bring organisations clarity and flexibility when using personal data. The changes announced today will give companies greater legal confidence to conduct research, deliver basic business services and develop new technologies such as AI, while retaining levels of data protection in line with the highest global standards, including data adequacy with the EU."</p><p>The current Information Commissioner has also stated: "I welcome the reintroduction of the Data Protection and Digital Information Bill and support its ambition to enable organisations to grow and innovate whilst maintaining high standards of data protection rights. Data protection law needs to give people the confidence to share information to use the products and services that power our economy and society. The Bill will ensure my office can continue to operate as a trusted, fair and independent regulator. We look forward to continuing to work constructively with the government to monitor how these reforms are expressed in the Bill as it continues its journey through Parliament."</p><p>There is little doubt that a new form of GDPR will be enacted into UK law to reflect how businesses collect and manipulate data. The final draft of the Bill is expected in 2025. The new Act will give organisations more control over the data they collect and move the regulations away from the top-down, prescriptive approach that GDPR currently takes and reflects what can be unique ways data is collected, manipulated and shared today.</p><p>For more information on the various ways in which leaving the EU effects GDPR, head to our <a href="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other" data-original-url="https://www.itpro.com/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other">GDPR and Brexit</a> in-depth guide.</p><h2 id="definition-of-personal-data-under-dpa-2018">Definition of personal data under DPA 2018</h2><p>The <a href="https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-information-what-is-it/what-is-personal-data/what-is-personal-data/"><u>ICO</u></a> defines personal data as: "any information relating to an identified or identifiable natural person (&apos;data subject&apos;); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."</p><p>Personal data comprises anything that may be used to identify an individual and has even extended to include details such as a person&apos;s <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address"><u>IP address</u></a> in modern times.</p><h2 id="what-has-changed-since-the-dpa-1998">What has changed since the DPA 1998</h2><p>The latest legislation is designed to bring <a href="https://www.itpro.com/data-protection/28020/data-protection-principles"><u>data protection</u></a> to modern standards in light of the growth of massive internet companies and how data is collected, processed, and monetised in gigantic quantities. The DPA 2018 introduced far more <a href="https://www.itpro.com/security/29897/ico-only-20-of-uk-citizens-trust-companies-with-their-data"><u>protections for citizens</u></a> and improved the protections and rights initially outlined in the legislations previous iteration.</p><p>Under the new regime, organisations are required to be <a href="https://www.itpro.com/data-protection/32148/apple-launches-privacy-focused-website-for-data-transparency"><u>more transparent</u></a> about how and why they handle, collect, and process the data – much of this about their customers’ behavior. Data collection can only happen if an entity has an explicit and legitimate reason to do so.</p><p>Businesses must also consider several conditions when processing data, including:</p><ul><li><strong>the data subject's consent</strong></li><li><strong>legal obligation</strong></li><li><strong>contractual obligations</strong></li><li><strong>public interest</strong></li><li><strong>vital interest</strong></li><li><strong>and legitimate interests</strong></li></ul><p>One of the most significant changes has been in the way consent is viewed in the eyes of the law, with the threshold for consent raised significantly. Under the DPA 2018, user consent must be explicit for data processing about specifically outlined purposes, as opposed to blanket consent, as was sought previously.</p><p>More significant requirements have also been put on organisations to keep data accurate and up-to-date and immediately remove anything from inaccurate systems on request when such issues are flagged.</p><p>Processing data, meanwhile, is now limited entirely to the specific purposes for which it was collected, which differs from how organizations interpreted provisions in the 1998 DPA. Previously, companies could process data in any way provided it wasn&apos;t "excessive" to the original purpose.</p><h2 id="how-the-data-protection-act-structured">How the Data Protection Act structured?</h2><p>The DPA 2018 enforces <a href="https://ico.org.uk/media/2614158/ico-introduction-to-the-data-protection-bill.pdf" target="_blank"><u>four distinct data protection frameworks</u></a>, each relating to a specific category of data processing.</p><ul><li>Within the scope of GDPR</li><li>Outside the scope of GDPR</li><li>By competent authorities for law enforcement purposes</li><li>By the intelligence services</li></ul><p>The Act is also split into seven parts, each containing multiple schedules. Following an introductory section and critical terms, Part 2 covers various aspects of the general processing of personal data, Part 3 covers law enforcement, Part 4 relates to intelligence service processing, Part 5 covers the powers of the Information Commissioner&apos;s Office (ICO), Part 6 outlines the scope of enforcement powers, and Part 7 covers additional provisions that do not fall under the previous categories.</p><p>Special provisions are set out for law enforcement processing, including the processing of personal data by the police, prosecutors, and similar criminal justice bodies. Similar provisions exist for processing by intelligence services, which aim to bring UK standards in line with international standards. The frameworks also ensure the smooth flow of data internationally to tackle crime while ensuring data protection is upheld.</p><h2 id="fines-for-breaching-the-data-protection-act-2018">Fines for breaching the Data Protection Act 2018</h2><p>Like <a href="https://www.itpro.com/general-data-protection-regulation-gdpr/31025/gdpr-fines-how-high-are-they-and-how-can-you-avoid">GDPR fines</a>, the DPA 2018 gives the ICO the power to levy far tougher fines than anything seen in the past. Under the 1998 Act, the maximum possible fine was £500,000.</p><p>Under the DPA 2018, serious breaches of the data protection principles, or failing to report a data breach within 72 hours, can result in a fine of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.</p><p>It remains to be seen how the UK Data Protection and Digital Information Bill No.2 will continue to evolve. What is clear is that the UK government is set on a trajectory to change the current implementation of GDPR and how this relates to DPA 2018.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>