News
IT governance
-
May 20, 2025
20
May'25
Rio Tinto overhauls IT operations with platform model
Rio Tinto’s head of technology platforms outlines the mining giant’s move to an IT platform model designed to escape a reactive cycle of critical incidents and improve service quality for internal and external customers
-
May 19, 2025
19
May'25
Chinese cyber spooks lure laid-off US government workers
A Washington DC-based think tank has published evidence that Chinese intelligence services have been running a network of digital ‘front’ companies targeting laid-off government workers as recruits
-
May 19, 2025
19
May'25
Legal Aid Agency breach may encompass millions of people
Legal Aid Agency says the data of anybody who applied for legal aid over the past 15 years has been compromised in a cyber attack
-
May 16, 2025
16
May'25
The Security Interviews: David Faugno, 1Password
David Faugno, co-CEO of 1Password, discusses how his background led to him joining the company and why maintaining profitability is a key factor in overcoming the challenges of switching markets.
-
May 15, 2025
15
May'25
NHS asks suppliers to sign up to cyber covenant
NHS digital and security leaders call on their suppliers to commit to a cyber security charter as the health service works to improve its resilience in the face of growing threat levels
-
May 14, 2025
14
May'25
Scattered Spider retail attacks spreading to US, says Google
Google’s threat intel analysts are aware of a number of in-progress cyber attacks against US retailers linked to the same Scattered Spider gang that supposedly attacked M&S and Co-op in the UK
-
May 14, 2025
14
May'25
Enisa launches European vulnerability database
The EU’s new vulnerability database is designed to offer a broader, more transparent source of information on new cyber vulnerabilities
-
May 14, 2025
14
May'25
Why we must reform the Computer Misuse Act: A cyber pro speaks out
Britain’s outdated hacking laws are leaving the UK’s cyber practitioners hamstrung and afraid. Security professional Simon Whittaker reveals how he nearly ran afoul of the Computer Misuse Act, and why he’s speaking out for reform
-
May 14, 2025
14
May'25
UK government outlines plan to surveil migrants with eVisa data
Electronic visa data and biometric technologies will be used by the UK’s immigration enforcement authorities to surveil migrants living in the country and to ‘tighten control of the border’, attracting strong criticism from migrant support groups
-
May 14, 2025
14
May'25
BBVA creates ChatGPT Store and expands use of the GenAI tool
Data reveals that bank employees are saving an average of almost three hours every week by using ChatGPT
-
May 13, 2025
13
May'25
May Patch Tuesday brings five exploited zero-days to fix
Microsoft fixes five exploited, and two publicly disclosed, zero-days in the fifth Patch Tuesday update of 2025
-
May 13, 2025
13
May'25
M&S forces customer password resets after data breach
M&S is instructing all of its customers to change their account passwords after a significant amount of data was stolen in a DragonForce ransomware attack
-
May 13, 2025
13
May'25
NHS trust cloud plans hampered by Trump tariff uncertainty
Essex NHS wants to move some capacity to the Nutanix cloud, but can’t be certain prices will hold between product selection and when procurement plans gain approval
-
May 08, 2025
08
May'25
Government will miss cyber resiliency targets, MPs warn
A Public Accounts Committee report on government cyber resilience finds that the Cabinet Office has been working hard to improve, but is likely to miss targets and needs a fundamentally different approach
-
May 08, 2025
08
May'25
Preparing for post-quantum computing will be more difficult than the millennium bug
The job of getting the UK ready for post-quantum computing will be at least as difficult as the Y2K problem, says National Cyber Security Centre CTO Ollie Whitehouse
-
May 08, 2025
08
May'25
US tells CNI orgs to stop connecting OT kit to the web
US authorities have released guidance for owners of critical national infrastructure in the face of an undisclosed number of cyber incidents
-
May 08, 2025
08
May'25
UK Digital Services Tax survives US trade negotiations
The UK will retain its Digital Services Tax on tech giants in a landmark US trade agreement that paves the way for a future digital tech deal
-
May 07, 2025
07
May'25
Meta awarded $167m in court battle with spyware mercenaries
WhatsApp owner Meta is awarded millions of dollars in damages and compensation after its service was exploited by users of mercenary spyware developer NSO’s infamous Pegasus mobile malware
-
May 07, 2025
07
May'25
Chaos spreads at Co-op and M&S following DragonForce attacks
No end is yet in sight for UK retailers subjected to apparent ransomware attacks
-
May 07, 2025
07
May'25
Oxford Uni adds cyber resilience module to MBA programme
Oxford University’s Saïd Business School is working with cyber response specialist Sygnia to help future business leaders get on top of security
-
May 06, 2025
06
May'25
Data issues cost Australian businesses nearly A$500k annually
Research reveals Australian organisations are losing an average of nearly half a million dollars annually due to poor data integrity, hindering their ability to leverage AI and eroding their competitive edge
-
May 02, 2025
02
May'25
Retail cyber crime spree a ‘wake-up call’, says NCSC CEO
The National Cyber Security Centre confirms it is providing assistance to M&S, Co-op and Harrods as concerns grow among UK retailers
-
May 02, 2025
02
May'25
Government and Ofcom disagree about scope of Online Safety Act
MPs heard different views from the online harms regulator and the UK government about whether and how the Online Safety Act obliges platforms to deal with disinformation
-
May 01, 2025
01
May'25
Harrods becomes latest UK retailer to fall victim to cyber attack
Harrods confirms it is the latest UK retailer to experience a cyber attack, shutting off a number of systems in an attempt to lessen the impact
-
April 30, 2025
30
Apr'25
Current SaaS delivery model a risk management nightmare, says CISO
JPMorgan Chase security chief Patrick Opet laments the state of SaaS security in an open letter to the industry and calls on software providers to do more to enhance resilience
-
April 30, 2025
30
Apr'25
Co-op shuts off IT systems to contain cyber attack
A developing cyber incident at Co-op has forced the retailer to pull the plug on some of its IT systems as it works to contain the attack
-
April 30, 2025
30
Apr'25
AI in national security raises proportionality and privacy concerns
AI could enable investigations to cover far more individuals than was ever previously possible, which is why oversight is needed
-
April 29, 2025
29
Apr'25
Gov.uk One Login yet to meet government cyber security standards for critical public services
The government’s flagship digital identity system still does not fully conform to key national security standards three years after launch, while questions remain over whether historic security problems have been resolved
-
April 25, 2025
25
Apr'25
UK MoJ crime prediction algorithms raise serious concerns
The Ministry of Justice is using one algorithm to predict people’s risk of reoffending and another to predict who will commit murder, but critics say the profiling in these systems raises ‘serious concerns’ over racism, classism and data inaccuracies
-
April 25, 2025
25
Apr'25
M&S suspends all online sales as cyber attack worsens
M&S shuts down online sales as it works to contain and mitigate a severe cyber attack on its systems
-
April 24, 2025
24
Apr'25
M&S systems remain offline days after cyber incident
M&S is still unable to provide contactless payment or click-and-collect services amid a cyber attack that it says has forced it to move a number of processes offline to safeguard its customers, staff and business
-
April 24, 2025
24
Apr'25
Data breach class action costs mount up
Organisations exposed to the US market paid out over $150m in class action settlements in just six months. Security leaders must do more to address cyber gaps, respond better to incidents and demonstrate compliance
-
April 24, 2025
24
Apr'25
Interview: Daniele Tonella, CTO, ING
The bank’s global CTO has been in the role for less than a year and in that time has been working his way through four layers of tech
-
April 23, 2025
23
Apr'25
Financially motivated cyber crime remains biggest threat source
Mandiant’s latest annual threat report reveals data on how financially motivated cyber criminals, such as ransomware gangs, dominate the cyber security landscape
-
April 23, 2025
23
Apr'25
Amid uncertainty, Armis becomes newest CVE numbering authority
Amid an uncertain future for vulnerability research, exposure management company Armis has been given the authority to assign CVE IDs to newly discovered vulnerabilities
-
April 22, 2025
22
Apr'25
Cyber attack downs systems at Marks & Spencer
A cyber attack at Marks & Spencer has caused significant disruption to customers, leaving them unable to make contactless payments or use click-and-collect services
-
April 22, 2025
22
Apr'25
Secure Future Initiative reveals Microsoft staff focus
IT security is now a metric in the Microsoft employee appraisal process
-
April 22, 2025
22
Apr'25
Ofcom bans leasing of Global Titles to crackdown on spoofing
Telco regulator Ofcom is cracking down on a loophole being exploited by cyber criminals to access sensitive mobile data
-
April 17, 2025
17
Apr'25
Tariff turmoil is making supply chain security riskier
Many businesses around the world are taking the decision to alter their supplier mix in the face of tariff uncertainty, but in doing so are creating more cyber risks for themselves, according to a report
-
April 17, 2025
17
Apr'25
Standard Chartered grounds AI ambitions in data governance
The bank’s group chief data officer, Mohammed Rahim, outlines how the bank is modernising its data infrastructure and governance practices to support its AI initiatives
-
April 16, 2025
16
Apr'25
CISA extends Mitre CVE contract at last moment
The US Cybersecurity and Infrastructure Security Agency has ridden to the rescue of the under-threat Mitre CVE Programme, approving a last-minute, 11-month contract extension to preserve the project’s vital security vulnerability work
-
April 16, 2025
16
Apr'25
CVE Foundation pledges continuity after Mitre funding cut
With news that Mitre’s contract to run the world-renowned CVE Programme is abruptly terminating, a breakaway group is setting up a non-profit foundation to try to ensure the project’s continuity
-
April 15, 2025
15
Apr'25
Mitre warns over lapse in CVE coverage
Mitre, the operator of the world-renowned CVE repository, has warned of significant impacts to global cyber security standards, and increased risk from threat actors, as it emerges its US government contract will lapse imminently
-
April 15, 2025
15
Apr'25
Hertz warns UK customers of Cleo-linked data breach
Car hire giant Hertz reveals UK customer data was affected in a cyber incident orchestrated via a series of vulnerabilities in Cleo managed file transfer products
-
April 11, 2025
11
Apr'25
AI surveillance towers place migrants in ‘even greater jeopardy’
The use of autonomous surveillance towers throughout the English coast forces migrants into increasingly dangerous routes and contributes to their criminalisation
-
April 11, 2025
11
Apr'25
Met Police to deploy permanent facial recognition tech in Croydon
The Met Police is set deploy permanent live facial recognition cameras on street furniture in Croydon from summer 2025, but local councillors say the decision – which has taken place with no community input – will further contribute the ...
-
April 10, 2025
10
Apr'25
Google bets on unifying security tools to ease CISO pain
At Google Cloud Next in Las Vegas, Google launches its Unified Security platform with the goal of bringing together disparate security solutions to help cyber leaders and practitioners address their most keenly felt pain points
-
April 10, 2025
10
Apr'25
Companies House goes live with One Login ID verification
People can verify their identity with Companies House using Gov.uk One Login as the central government body becomes the 36th service to start using the digital identity system
-
April 08, 2025
08
Apr'25
NCSC issues warning over Chinese Moonshine and BadBazaar spyware
Two spyware variants are being used to target the mobile devices of persons of interest to Chinese intelligence, including individuals in the Taiwanese, Tibetan and Uyghur communities
-
April 08, 2025
08
Apr'25
Over £18m stolen from Santander UK customers in first three months of year
Bank’s latest quarterly report on scams said over £18m was stolen from its UK customers by scammers