Security policy and user awareness
-
News
20 Sep 2023
Parliament passes sweeping Online Safety Bill but tech companies still concerned over encryption
Ofcom will consult on standards to enforce new powers, but tech companies remain concerned about the impact of the bill’s ‘spy clause’, which could require them to scan encrypted messages Continue Reading
-
News
20 Sep 2023
Organisations failing to proactively address insider cyber risk
Organisations are spending less than 10% of their annual security budgets on trying to solve one of the costliest problems in cyber: insider risk Continue Reading
-
News
14 Dec 2021
Almost half of networks probed for Log4Shell weaknesses
Close to half of corporate networks have already been actively targeted by individuals seeking to exploit the critical Log4Shell Apache bug Continue Reading
-
Opinion
14 Dec 2021
Security Think Tank: We are failing to get the cyber message across to users
Security learning is a career-long process, so as 2021 draws to a close, participants in the Computer Weekly Security Think Tank sum up the most important cyber lessons they’ve taken away from the past 12 months Continue Reading
-
News
13 Dec 2021
What is Log4Shell, and why are we panicking about it?
It’s been described as a ‘design failure of catastrophic proportions’ that threatens the very fabric of the digital world. Find out what the Log4j2 Log4Shell panic is all about, and what you should do about it Continue Reading
-
Opinion
13 Dec 2021
Security Think Tank: There’s much more to do to secure hybrid workers
Security learning is a career-long process, so as 2021 draws to a close, participants in the Computer Weekly Security Think Tank sum up the most important cyber lessons they’ve taken away from the past 12 months Continue Reading
-
News
10 Dec 2021
C-suite’s biggest ransomware fear: Post-attack regulatory sanctions
Exposure to regulatory sanctions such as fines are the biggest worry for C-suite executives in the wake of a ransomware attack Continue Reading
-
News
09 Dec 2021
What are the challenges associated with the MITRE ATT&CK framework?
Businesses sometimes struggle to use the MITRE ATT&CK framework effectively. Learn more about some of the challenges, and how to overcome them Continue Reading
-
News
09 Dec 2021
UK and US to collaborate on privacy innovation contest
Joint UK-US innovation challenge contest centring on privacy-enhancing technology announced at Summit for Democracy in Washington DC Continue Reading
-
Opinion
09 Dec 2021
Security Think Tank: Good documentation could save your bacon
Security learning is a career-long process, so as 2021 draws to a close, participants in the Computer Weekly Security Think Tank sum up the most important cyber lessons they’ve taken away from the past 12 months Continue Reading
-
News
08 Dec 2021
2021 another record-breaker for vulnerability disclosure
More than 50 CVEs were logged every day in 2021, more than at any time since records began, while ethical hackers continue to prove their value Continue Reading
-
News
08 Dec 2021
Russia may be collaborating with US to bring cyber criminals to heel
Trustwave’s SpiderLabs says its analysis of chatter on underground dark web forums suggests cyber criminals are starting to panic that formerly ‘friendly’ governments are on their case Continue Reading
-
News
08 Dec 2021
Number of .uk domain suspensions at record low
Statistics from Nominet show how effective law enforcement action against cyber crime in the UK is paying off Continue Reading
-
News
06 Dec 2021
IT Priorities 2022: Pandemic’s long tail for cyber buyers
Pandemic response has been top of mind for cyber leaders these past 18 months, and as Covid-19 turns two, the TechTarget/Computer Weekly IT Priorities 2022 study shows buyers are still focused on how Covid has upended the workplace Continue Reading
-
Blog Post
02 Dec 2021
Overcome the security talent shortage by addressing your tech stack
This is a guest post by Graham Pearson, vice-president and general manager for ANZ at Lacework Australians will spend approximately $5.6bn on cyber security alone this year, according to AustCyber, ... Continue Reading
-
Opinion
02 Dec 2021
Security Think Tank: Think people, processes and systems
Security learning is a career-long process, so as 2021 draws to a close, participants in the Computer Weekly Security Think Tank sum up the most important cyber lessons they’ve taken away from the past 12 months Continue Reading
-
News
01 Dec 2021
Kaspersky introduces cyber policy for bionic devices
Cyber firm Kaspersky has become one of the first organisations in the world to develop and implement a security policy covering the use of bionic devices and other forms of human augmentation Continue Reading
-
Opinion
01 Dec 2021
A ‘whole of society’ approach to cyber may be on the horizon
Nominet Cyber managing director David Carroll reflects on the NCSC’s latest annual review amid 2021’s fast-evolving threat landscape Continue Reading
-
News
30 Nov 2021
Compliance, device management a challenge for NHS cyber teams
Information gleaned by asset visibility specialist Armis reveals that despite improvements, some daunting security challenges still dog the NHS Continue Reading
-
News
30 Nov 2021
MI6 will ‘open up’ to tech firms to innovate faster than adversaries, says chief Richard Moore
MI6 will use investment fund to back tech companies to develop long-term technologies that will help it to keep pace with China and Russia Continue Reading
-
News
30 Nov 2021
HP patches bugs in over 150 printer models
More than 150 HP multifunction printers are at risk of compromise through a series of newly disclosed vulnerabilities, one of them wormable Continue Reading
-
News
30 Nov 2021
Recovering from ransomware: One organisation’s inside story
In February 2021, French office equipment supplier Manutan fell victim to a DoppelPaymer ransomware hit. IT ops director Jérôme Marchandiau tells the inside story of the incident Continue Reading
-
Blog Post
30 Nov 2021
Why does ransomware still work?
As someone who first encountered ransomware during the last millennium – thankfully at second-hand – and has been writing about it for almost as long, I sometimes find myself amazed by the high ... Continue Reading
-
News
29 Nov 2021
British Army picks Immersive Labs for cyber training
The British Army will make Immersive Labs’ security training platform available to all serving personnel Continue Reading
-
News
29 Nov 2021
Three latest trends and developments around the Mitre ATT&CK framework
Framework is set to receive important updates to help organisations and businesses evolve their cyber security. Learn more about what it offers Continue Reading
-
Opinion
29 Nov 2021
Security Think Tank: Dissecting the true value of SASE is a challenge
As a relatively nascent technology that is getting a lot of publicity, dissecting the true value of SASE is still a difficult proposition, for now Continue Reading
-
News
26 Nov 2021
UK’s surveillance culture may be normalising use of tech for abuse
Intense surveillance of public spaces by UK authorities may be playing a part in the normalisation of cyber stalking in intimate relationships Continue Reading
-
News
25 Nov 2021
UK consumers warned of increase in credit card application fraud
There has been a sharp rise in fraudsters using stolen personal details to open credit card accounts Continue Reading
-
News
23 Nov 2021
NCSC commits to new diversity measures
The National Cyber Security Centre’s second annual report on diversity in cyber security finds room for improvement Continue Reading
-
News
22 Nov 2021
Upcoming holidays prompt ransomware warning from authorities
Ransomware gangs know how calendars work, and may target their attacks around major holidays to take advantage of more people being off work, according to a new alert Continue Reading
-
News
22 Nov 2021
Black Friday cyber warning for 4,000 card-skimming victims
NCSC warns thousands of small retailers that their websites are being exploited to steal customer data Continue Reading
-
News
19 Nov 2021
Why is Emotet back, and should we be worried about it?
The sudden reappearance of Emotet this week has security teams on high alert, but do we need to be worried about its return, and what should we be doing about it? Continue Reading
-
News
19 Nov 2021
GCHQ, NSA chiefs recommit to counter cyber threats
UK and US intelligence services reaffirm a joint commitment to disrupt and deter new and emerging cyber threats Continue Reading
-
Blog Post
18 Nov 2021
Forced on-line by the NHS: to be confused, exploited, ignored, mistreated and/or patronised
All this informed my MSc IT Security final dissertation entitled ‘Inclusion, Confusion and Exclusion – is technology making the Vulnerable more Vulnerable?’ I looked at Social, Financial and ... Continue Reading
-
News
18 Nov 2021
Government to legislate to make APP fraud reimbursement mandatory
UK payments regulator wants to reduce the huge sums of money lost to authorised push payment fraud and is calling on the banking and tech industries to play their part Continue Reading
-
News
17 Nov 2021
Security startups line up on Cyber Runway
Some 108 cyber security startups representing the UK’s most cutting-edge innovators are to join Plexal’s Cyber Runway accelerator Continue Reading
-
News
17 Nov 2021
Zero-days: The next element of the service-based cyber economy?
Digital Shadows researchers have reported on the emergence of zero-days as a service, which could be the next big thing in the cyber criminal underworld Continue Reading
-
News
17 Nov 2021
Out of the shadows: The rise of ethical hackers in 2021
Ethical hackers working on the Bugcrowd platform have saved organisations almost $30bn in risk during the Covid-19 pandemic, as the community sheds old stereotypes Continue Reading
-
News
16 Nov 2021
One-fifth of NCSC-supported cyber incidents linked to Covid-19
National Cyber Security Centre has helped to thwart multiple cyber incidents that could have seriously disrupted the UK’s response to the pandemic Continue Reading
-
News
15 Nov 2021
UK government proposes new rules for digital supply chain security
Proposals could see IT service providers legally required to adhere to the NCSC’s Cyber Assessment Framework, among other things Continue Reading
-
Opinion
15 Nov 2021
Security Think Tank: What to find out before investing in SASE
Petra Wenham of the BCS shares her thoughts on what organisations need to consider as they investigate whether or not to invest in secure access service edge technology Continue Reading
-
News
11 Nov 2021
HPE’s Aruba networking unit hit by cyber attack
Undisclosed threat actor compromised data buckets used to run the Aruba Central cloud environment using a stolen access key Continue Reading
-
News
11 Nov 2021
Scale of crime-as-a-service economy a growing concern, say researchers
The cyber criminal underground continues its evolution towards a service-based economy Continue Reading
-
Opinion
11 Nov 2021
The ICO is right to push back against government meddling
Some criticisms of the ICO are justified, but the answer to that is not to give Whitehall more oversight over the data protection regulator, argues legal expert Edward Machin Continue Reading
-
News
11 Nov 2021
Bank of England loses 161 computing devices in three years
Bank cannot account for phones, laptops and tablets that have gone missing over the past three years Continue Reading
-
Opinion
11 Nov 2021
Zero trust: Now is the time
The cyber security industry has been talking about a zero-trust approach to security for just over a decade, but now it’s time to move towards full implementation because it is more appropriate than ever, and it is rapidly gaining support from suppliers Continue Reading
-
News
10 Nov 2021
November Patch Tuesday drop fixes bugs in Excel, Exchange Server
Another relatively light Patch Tuesday drop from Microsoft addresses 55 vulnerabilities, two of them already being exploited Continue Reading
-
Feature
10 Nov 2021
Digital surveillance of remote workers may increase enterprise risk
From productivity tools to security threats, we explore how digital surveillance is forcing remote workers towards shadow IT Continue Reading
-
Feature
10 Nov 2021
How to manage endpoint security in a hybrid work environment
The future of the workplace is clearly hybrid, but this has untold implications around endpoint security. How can businesses overcome these? Continue Reading
-
Opinion
09 Nov 2021
The Secret IR Insider’s Diary – this is not a fashion show
In the latest pages taken from their diary, the Secret IR Insider reveals why organisations should be worried about every threat, not just the latest and greatest Continue Reading
-
News
09 Nov 2021
US seeks to extradite REvil affiliate who attacked Kaseya
US Department of Justice unseals charges against a Ukrainian national accused of being behind the summer 2021 REvil ransomware attack on Kaseya Continue Reading
-
Blog Post
08 Nov 2021
Shock horror... Humans used for security validation instead of AI/M-L!
As a judge on the Tech Trailblazers awards, I can assure you of two security-related actuality wotsits: The onslaught of security start-ups is anything but slowing down; this year has seen a record ... Continue Reading
-
News
04 Nov 2021
The Netherlands works on resilience with large-scale national cyber exercise
For the Netherlands, the biggest challenge in a large-scale cyber crisis is to maintain speed while exercising due care Continue Reading
-
News
03 Nov 2021
Spyware firm NSO and others added to US banned Entity List
US government bans target Israeli spyware makers and cyber firms in Russia and Singapore Continue Reading
-
News
03 Nov 2021
UK’s Labour Party hit by third-party data breach
Data on Labour Party members was recently compromised in an apparent cyber attack on a third-party data processor Continue Reading
-
Opinion
03 Nov 2021
Security Think Tank: SASE – marketing buzz or the future of security?
SASE architectures promise to prevent multiple types of cyber attacks, but deciding whether SASE is right for your organisation will require understanding whether SASE is a fit for your use cases in IT Continue Reading
-
News
03 Nov 2021
BlackMatter ransomware crew shuts down, leaves victims in a bind
The BlackMatter ransomware gang appears to be winding down its activities, possibly due to pressure from law enforcement Continue Reading
-
News
01 Nov 2021
Businesses and governments urged to take action over Trojan Source supply chain attacks
Businesses and governments have been put on alert to guard against Trojan Source hacking attacks Continue Reading
-
Feature
29 Oct 2021
Online Safety Bill puts user protection onus on platform providers
The Online Safety Bill will place new duties and responsibilities on online platforms accessible from the UK, but as it currently stands, it contains several grey areas Continue Reading
-
News
29 Oct 2021
Facebook rebrands to Meta amid continuing controversies
Facebook has changed its corporate name to Meta to support its work on the next generation of “social technologies”, but concerns around trust and privacy persist Continue Reading
-
News
28 Oct 2021
How ransomware crews pile on the pressure to get victims to pay
Sophos researchers share some of the more common tactics ransomware gangs use to pressurise their victims into paying up Continue Reading
-
News
27 Oct 2021
Government commits millions to security investment
Spending Review adds more than £750m of funding to improve cyber security resilience across government Continue Reading
-
News
27 Oct 2021
Cyber sector growth exacerbating skills shortage
Data from security association (ISC)² shows demand for cyber pros is still outpacing supply as the sector continues an upward growth trajectory Continue Reading
-
News
26 Oct 2021
Cyber experts on how to nobble a Nobelium attack
A recent spate of attempted Nobelium cyber attacks were mostly unsuccessful, but serve as a reminder to pay attention to some more fundamental aspects of security Continue Reading
-
E-Zine
26 Oct 2021
Managing cyber risk by integrating supply chains
In this week’s Computer Weekly, our latest Buyer’s Guide examines the security and IT integration challenges of modern supply chains, especially post-pandemic – while we also talk to the CEO of software provider SolarWinds about how the company overcame its huge supply chain attack. And we look at how a small town in Lancashire was chosen as the HQ for the UK’s new National Cyber Force. Read the issue now. Continue Reading
-
News
21 Oct 2021
Airport operator MAG boosts threat visibility with hybrid SOC
With budget concerns weighing heavy during the pandemic, Manchester Airports Group ditched an impending capex-heavy cyber investment in favour of a hybrid managed/in-house approach. Learn more about its experience Continue Reading
-
News
20 Oct 2021
LightBasin hackers breach 13 telcos in two years
Hackers have obtained an undisclosed volume of subscriber information and call metadata in a sustained campaign against telecommunications firms Continue Reading
-
Feature
19 Oct 2021
Back on the office network: What are the risks for mobile users?
Many people are returning to offices and bringing their mobile devices with them. What are the cyber security implications of this? Continue Reading
-
Opinion
18 Oct 2021
No easy fix for vulnerability exploitation, so be prepared
Vulnerability management and disclosure is a tricky business with ethical and business ramifications for software vendors, CISOs and ethical hackers alike – and CISOs sit right in the middle of this Continue Reading
-
Opinion
15 Oct 2021
Doing the right thing: How CISOs should approach responsible disclosure
Owen Wright, responsible for penetration testing and adversary simulation at Context, part of Accenture Security, advises how CISOs should approach responsible disclosure Continue Reading
-
News
14 Oct 2021
NHS Digital enhances in-house cyber awareness drive
Keep IT Confidential campaign aims to help NHS staff understand more about security threats and learn how to reduce risk Continue Reading
-
Opinion
14 Oct 2021
Encryption protects the marginalised – and it’s under threat
Encryption keeps marginalised groups connected and safe, but new regulatory attempts to break it put them at risk Continue Reading
-
News
13 Oct 2021
FCA warns over future hybrid working security risks
Earlier this week, the Financial Conduct Authority issued fresh guidance to regulated organisations on keeping hybrid workers safe and secure Continue Reading
-
News
13 Oct 2021
Microsoft warns of MysterySnail on October Patch Tuesday
Microsoft has fixed a zero-day that is being actively exploited to deliver a new remote access trojan dubbed MysterySnail to targets Continue Reading
-
News
13 Oct 2021
Former signals intel leader named godfather of UK security
Sixth annual Security Serious Unsung Heroes Awards honours former Royal Corps of Signals colonel and infosec pioneer John Doody Continue Reading
-
News
13 Oct 2021
Australia unveils ransomware action plan
The Australian government has established a task force to address the ransomware menace and is proposing legislation to mandate reporting of ransomware incidents by businesses Continue Reading
-
News
12 Oct 2021
BCS calls on government to retain protections against AI
BCS, the Chartered Institute for IT, wants the government to retain protections that allow people to have decisions about them made by an AI reviewed by humans if needed Continue Reading
-
News
11 Oct 2021
Covid-19 will loom over cyber strategy for years to come
In remarks delivered to a Chatham House conference, NCSC head Lindy Cameron reflects on the security challenges facing the UK, and sets out some plans for the future Continue Reading
-
News
11 Oct 2021
Sensitive documents to stay with whistleblower after deadline for agreement for their return passes
A deadllne to agree the safe return of the sensitive banking details of former and current NatWest Group customers has passed without agreement Continue Reading
-
News
11 Oct 2021
Singapore refreshes cyber security strategy
The city-state updates its national cyber security strategy to shore up the security of critical infrastructure and enterprises while growing its cyber security industry, among other goals Continue Reading
-
News
08 Oct 2021
Craft beer specialist Brewdog fixes serious app vulnerability
Vulnerability in brewer’s mobile app could have resulted in serious consequences for its shareholders and customers Continue Reading
-
News
08 Oct 2021
Fast-moving Ryuk campaign targets healthcare organisations
Newly designated FIN12 gang leverages the work of the cyber criminal ecosystem to conduct lightning-fast ransomware attacks Continue Reading
-
Opinion
07 Oct 2021
Addressing the backup dilemma to ransomware recovery
Everyone knows good backups are essential if one is to recover from a ransomware attack, but using them effectively poses challenges that IT teams need to know about Continue Reading
-
News
07 Oct 2021
ICO expresses concerns over its future independence
In its response to the government’s data protection consultation, the Information Commissioner’s Office has raised worries over its future ability to function independently of government interference Continue Reading
-
News
07 Oct 2021
Twitch data breach investigations continue
Investigations are ongoing into a 125GB data breach that hit livestreaming platform Twitch, apparently the work of hacktivists Continue Reading
-
News
06 Oct 2021
US lawmakers propose ransomware reporting rules
Former presidential candidate Elizabeth Warren lends her support to a bill that would require corporate ransomware victims to disclose more information about their attacks to the authorities Continue Reading
-
Opinion
06 Oct 2021
Security Think Tank: Responsible vulnerability disclosure is a joint effort
By working hand-in-hand, developers and security researchers can both play a vital role in ensuring newly-discovered vulnerabilities are addressed appropriately, writes Paddy Francis of Airbus CyberSecurity Continue Reading
-
News
06 Oct 2021
Gaming service Twitch hacked, data leaked
Users of livestreaming platform Twitch may be at risk after a 125GB torrent of data was leaked Continue Reading
-
News
06 Oct 2021
Apache web server users urged to patch immediately
New zero-day in Apache HTTP Server is already being actively exploited and must be addressed immediately Continue Reading
-
News
06 Oct 2021
Auto-enrolment begins for Google multi-factor authentication
Google has started to turn on multi-factor authentication on consumer accounts by default, and aims to auto-enrol 150 million users by the end of 2021 Continue Reading
-
Opinion
05 Oct 2021
New strategies needed to close the cyber security skills gap
Teaching cyber security in schools is a long-term solution to a present-day problem Continue Reading
-
News
05 Oct 2021
New Python-based ransomware attacks unfold in record time
Sophos researchers detail a new variety of Python-based ransomware attack targeting VMware ESXi-hosted VMs Continue Reading
-
Opinion
05 Oct 2021
Invest in cyber security with confidence using a structured approach
Cyber security has never been more challenging or important in rapidly changing business, regulatory, IT and threat environments. There is a need for a more structured approach to investment Continue Reading
-
News
04 Oct 2021
Two arrests made in European ransomware investigation
Unnamed ransomware operation was disrupted last week in Kiev, Ukraine, following a coordinated investigation Continue Reading
-
Opinion
04 Oct 2021
Security Think Tank: Embracing vulnerability management for the greater good
When it comes to vulnerability management, CISOs should define a responsible disclosure policy so that they can receive and manage identified vulnerabilities transparently, practically and collaboratively, says Paul Watts of the ISF Continue Reading
-
News
01 Oct 2021
Amnesty International exploited in malware campaign
According to new intelligence from Cisco Talos, Amnesty International’s branding and profile is being used as part of a new malware campaign that exploits people’s fears of the notorious Pegasus spyware app Continue Reading
-
News
01 Oct 2021
JVCKenwood hit by Conti ransomware attack
Nearly 2TB of data was stolen from Japanese electronics firm in a Conti ransomware hit Continue Reading
-
News
30 Sep 2021
UK consumers would collectively pay over £1bn a year for control of their data
UK consumers are willing to pay a small fee per month to have control of the data they share with Google and Facebook Continue Reading
-
News
29 Sep 2021
FoggyWeb malware latest tool of dangerous Nobelium APT
Microsoft’s threat intelligence team warns of a new strain of malware being used by the Russia-linked Nobelium APT Continue Reading
-
News
29 Sep 2021
The Security Interviews: How SolarWinds came through its darkest hour
In his first major UK press interview, SolarWinds CEO Sudhakar Ramakrishna tells Computer Weekly how a relentless focus on transparency saw the company safely through a nightmare cyber breach scenario Continue Reading
-
News
28 Sep 2021
How one red team exercise averted a new SolarWinds-style attack
Palo Alto Networks shares details of how its red teamers found and sealed a customer vulnerability that could have led to another SolarWinds-style supply chain attack Continue Reading
-
News
27 Sep 2021
Women and BAME people bear brunt of cyber crime impact
Cyber crime has a disproportionate impact on women and BAME people, according to a new report Continue Reading