News
IT governance
-
April 24, 2025
24
Apr'25
M&S systems remain offline days after cyber incident
M&S is still unable to provide contactless payment or click-and-collect services amid a cyber attack that it says has forced it to move a number of processes offline to safeguard its customers, staff and business
-
April 24, 2025
24
Apr'25
Data breach class action costs mount up
Organisations exposed to the US market paid out over $150m in class action settlements in just six months. Security leaders must do more to address cyber gaps, respond better to incidents and demonstrate compliance
-
April 24, 2025
24
Apr'25
Interview: Daniele Tonella, CTO, ING
The bank’s global CTO has been in the role for less than a year and in that time has been working his way through four layers of tech
-
April 23, 2025
23
Apr'25
Financially motivated cyber crime remains biggest threat source
Mandiant’s latest annual threat report reveals data on how financially motivated cyber criminals, such as ransomware gangs, dominate the cyber security landscape
-
April 23, 2025
23
Apr'25
Amid uncertainty, Armis becomes newest CVE numbering authority
Amid an uncertain future for vulnerability research, exposure management company Armis has been given the authority to assign CVE IDs to newly discovered vulnerabilities
-
April 22, 2025
22
Apr'25
Cyber attack downs systems at Marks & Spencer
A cyber attack at Marks & Spencer has caused significant disruption to customers, leaving them unable to make contactless payments or use click-and-collect services
-
April 22, 2025
22
Apr'25
Secure Future Initiative reveals Microsoft staff focus
IT security is now a metric in the Microsoft employee appraisal process
-
April 22, 2025
22
Apr'25
Ofcom bans leasing of Global Titles to crackdown on spoofing
Telco regulator Ofcom is cracking down on a loophole being exploited by cyber criminals to access sensitive mobile data
-
April 17, 2025
17
Apr'25
Tariff turmoil is making supply chain security riskier
Many businesses around the world are taking the decision to alter their supplier mix in the face of tariff uncertainty, but in doing so are creating more cyber risks for themselves, according to a report
-
April 17, 2025
17
Apr'25
Standard Chartered grounds AI ambitions in data governance
The bank’s group chief data officer, Mohammed Rahim, outlines how the bank is modernising its data infrastructure and governance practices to support its AI initiatives
-
April 16, 2025
16
Apr'25
CISA extends Mitre CVE contract at last moment
The US Cybersecurity and Infrastructure Security Agency has ridden to the rescue of the under-threat Mitre CVE Programme, approving a last-minute, 11-month contract extension to preserve the project’s vital security vulnerability work
-
April 16, 2025
16
Apr'25
CVE Foundation pledges continuity after Mitre funding cut
With news that Mitre’s contract to run the world-renowned CVE Programme is abruptly terminating, a breakaway group is setting up a non-profit foundation to try to ensure the project’s continuity
-
April 15, 2025
15
Apr'25
Mitre warns over lapse in CVE coverage
Mitre, the operator of the world-renowned CVE repository, has warned of significant impacts to global cyber security standards, and increased risk from threat actors, as it emerges its US government contract will lapse imminently
-
April 15, 2025
15
Apr'25
Hertz warns UK customers of Cleo-linked data breach
Car hire giant Hertz reveals UK customer data was affected in a cyber incident orchestrated via a series of vulnerabilities in Cleo managed file transfer products
-
April 11, 2025
11
Apr'25
AI surveillance towers place migrants in ‘even greater jeopardy’
The use of autonomous surveillance towers throughout the English coast forces migrants into increasingly dangerous routes and contributes to their criminalisation
-
April 11, 2025
11
Apr'25
Met Police to deploy permanent facial recognition tech in Croydon
The Met Police is set deploy permanent live facial recognition cameras on street furniture in Croydon from summer 2025, but local councillors say the decision – which has taken place with no community input – will further contribute the ...
-
April 10, 2025
10
Apr'25
Google bets on unifying security tools to ease CISO pain
At Google Cloud Next in Las Vegas, Google launches its Unified Security platform with the goal of bringing together disparate security solutions to help cyber leaders and practitioners address their most keenly felt pain points
-
April 10, 2025
10
Apr'25
Companies House goes live with One Login ID verification
People can verify their identity with Companies House using Gov.uk One Login as the central government body becomes the 36th service to start using the digital identity system
-
April 08, 2025
08
Apr'25
NCSC issues warning over Chinese Moonshine and BadBazaar spyware
Two spyware variants are being used to target the mobile devices of persons of interest to Chinese intelligence, including individuals in the Taiwanese, Tibetan and Uyghur communities
-
April 08, 2025
08
Apr'25
Over £18m stolen from Santander UK customers in first three months of year
Bank’s latest quarterly report on scams said over £18m was stolen from its UK customers by scammers
-
April 08, 2025
08
Apr'25
UK authority’s search for answers over deleted Julian Assange emails comes too late to retrieve data
The Crown Prosecution Service has finally searched for information about the destruction of emails from the WikiLeaks founder’s lawyer – but too late to retrieve data about the deleted documents
-
April 07, 2025
07
Apr'25
UK SMEs losing over £3bn a year to cyber incidents
A lack of access to technology, little to no staff training, and competing priorities are losing UK SMEs up to £3.4bn to cyber incidents every year
-
April 07, 2025
07
Apr'25
Fintech body calls on government for national anti-fraud centre
Industry body says a national anti-fraud centre could be the vehicle required to effectively fight fraud through data sharing
-
April 02, 2025
02
Apr'25
Tech sector still failing to rid supply chains of forced labour
KnowTheChain’s latest benchmark analysis of the IT sector’s efforts to address forced labour in supply chains shows there has been very little improvement in their due diligence practices over the last half decade
-
April 01, 2025
01
Apr'25
Gmail ‘bubble’ encryption may be an S/MIME killer, says Google
Marking the 21st anniversary of Gmail, Google is preparing to roll out an end-to-end encryption standard for its email service in hopes of democratising encryption and leaving old standards in the dust
-
April 01, 2025
01
Apr'25
Post Office Capture and Ecco+ users asked to make contact with Scottish statutory body
Scottish statutory body attempting to contact people that might have been wrongly convicted of crimes based on the Post Office’s flawed systems
-
April 01, 2025
01
Apr'25
Scottish support group for Post Office scandal victims launched
Support group calls on former subpostmasters in Scotland who have been affected by Horizon errors to come forward
-
March 31, 2025
31
Mar'25
Top 1,000 IT service providers in scope of UK cyber bill
The government’s proposed Cyber Security and Resilience Bill is set to include regulatory provisions covering both datacentre operators and larger IT service providers
-
March 31, 2025
31
Mar'25
Understanding of ‘black box’ IT systems will reduce Post Office scandal-like risk
A Parliamentary committee has reported that leadership teams need to understand the ‘black box’ IT systems that underpin their organisations
-
March 31, 2025
31
Mar'25
Reassessing UK law enforcement data adequacy
Computer Weekly takes stock of proposed changes to the UK’s law enforcement data protection rules and how it could affect data adequacy with the European Union
-
March 31, 2025
31
Mar'25
UK law enforcement data adequacy at risk
The UK government says reforms to police data protection rules will help to simplify law enforcement data processing, but critics argue the changes will lower protection to the point where the UK risks losing its European data adequacy
-
March 27, 2025
27
Mar'25
UK public expresses strong support for AI regulation
Most of the UK public have experienced an AI-related harm and say they want laws introduced to regulate the technology, according to national survey by the Ada Lovelace and Alan Turing Institutes
-
March 26, 2025
26
Mar'25
Advanced Software fined £3m over LockBit attack
The ICO has issued a £3m fine to software provider Advanced in the wake of security failings that led to significant disruption to NHS customers in a ransomware attack
-
March 25, 2025
25
Mar'25
ETSI launches first post-quantum encryption standard
European telco standards body launches its first post-quantum cryptography cyber standard, covering the security of critical data and communications
-
March 25, 2025
25
Mar'25
Scottish police hold almost no data on facial recognition use
It is currently impossible to assess Police Scotland’s use of retrospective facial recognition for efficacy and fairness because the force does not collect meaningful information that would enable a proper evaluation
-
March 20, 2025
20
Mar'25
NCSC proposes three-step plan to move to quantum-safe encryption
The NCSC urges service providers, large organisations and critical sectors to start thinking today about how they will migrate to post-quantum cryptography over the next decade
-
March 19, 2025
19
Mar'25
Clop resurgence drives ransomware attacks in February
The exploitation of two new vulnerabilities in a popular file transfer service saw the Clop ransomware gang soar in February, according to NCC
-
March 19, 2025
19
Mar'25
DeepMind founder warns of compounding AI agent errors
Artificial general intelligence may be years away, but in the meantime, organisations are being urged to adopt agent technology
-
March 19, 2025
19
Mar'25
Former subpostmaster to sue Post Office and Fujitsu for judgment ‘obtained by fraud’
Lee Castleton, one of a group of seven former subpostmasters who began the fight against the Post Office in 2009, triggers ‘seismic’ shift in Post Office scandal
-
March 18, 2025
18
Mar'25
Largest ever cyber deal reflects Google’s CNAPP ambitions
In a signal of its future ambitions, Google lays down $32bn to acquire cloud-native application protection platform Wiz, reflecting the increasing need to secure multicloud environments
-
March 18, 2025
18
Mar'25
IR35: Research highlights rise in outside IR35 engagements among contractors
Qdos research shows 'tide is turning' on company attitudes towards hiring outside IR35 contractors
-
March 17, 2025
17
Mar'25
Online Safety Act measures come into effect
Regulator Ofcom is now able to take enforcement action against platforms under the Online Safety Act if they fail to proactively safeguard against content such as terrorist or child sexual abuse material
-
March 17, 2025
17
Mar'25
Who takes responsibility? Birmingham’s ERP extraordinary meeting
Council members took the opportunity to raise their concerns during the Birmingham City Council ERP meeting, which took place on 11 March
-
March 14, 2025
14
Mar'25
AI Action Summit review: Differing views cast doubt on AI’s ability to benefit whole of society
Governments, companies and civil society groups gathered at the third global AI summit to discuss how the technology can work for the benefit of everyone in society, but experts say competing imperatives mean there is no guarantee these visions will...
-
March 14, 2025
14
Mar'25
Can a future digital NHS survive another change?
Computer Weekly looks at the prime minister’s decision to abolish NHS England and the potential impact on the progress of digitising the NHS
-
March 13, 2025
13
Mar'25
US Congress demands UK lifts gag on Apple encryption order
Apple and Google have told US lawmakers that they cannot tell Congress whether they have received technical capability notices from the UK
-
March 13, 2025
13
Mar'25
SuperBlack ransomware may have ties to LockBit
Forescout researchers report on a new ransomware gang that appears to be keeping the legacy of the notorious LockBit crew alive
-
March 13, 2025
13
Mar'25
HMRC looks to upgrade SOC with advanced SIEM tech
HMRC issues a request for information notice ahead of opening up bids for a new security information and event management project that aims to reinforce its ability to respond to cyber threats
-
March 13, 2025
13
Mar'25
Driving licence data could be used for police facial recognition
The government’s Crime and Policing Bill could allow police to access the UK driving licence database for use in facial recognition watchlists, but the Home Office denies biometric data would be repurposed in this way
-
March 12, 2025
12
Mar'25
iPhone, iPad update fixes critical WebKit flaw
iPhone and iPad users are advised to update their devices as Apple addresses an out-of-bounds write issue in the WebKit browser engine that appears to have been exploited in targeted cyber attacks