softwareone-logo-blk

4 min to readNews and UpdatesCloud ServicesDigital Workplace

Cyber security update, September

sethunathan-bala-contact
Bala SethunathanDirector, Security Practice & CISO
server-getty-1370578245-blog-hero

It is Cyber Security Awareness month. With cyber-attacks continuing to rise, it’s more important than ever to put the right security measures in place. SoftwareOne’s monthly Cyber security update provides information on the most recent threats, the latest breaches and how to react to them in order to stay on top of malware and ransomware threats. We also have guidance on how to secure Azure following recent information from Microsoft.

Latest security breaches

Recently the Microsoft security team has been receiving signals indicating that some customers' Azure resources are being used for fraudulent activities, which has led to significant unexpected spend in customer subscriptions. In some cases, this was due to accounts not being protected by multi-factor authentication. Learn how to protect yourself.

Australia's second-largest telecoms firm Optus was hit by a data breach that exposed the home addresses, driver’s license numbers and passport numbers of up to 10 million customers. The Singapore Telecoms-owned company has denied accusations that it "effectively left the window open" for hackers.

Samsung has warned of a “cyber security incident” that resulted in the personal details of an undisclosed number of customers being stolen. Information includes names, contact info, dates of birth and product registration information.

US-based transport and storage company U-Haul has warned of a data breach where a misconfigured search tool provided unauthorized access to rental contracts and exposed customers names and driver’s licence details.

UK luxury watch dealer Watchfinder has suffered a breach where customer details have been exposed. The company is warning customers to be on alert for "suspicious correspondence".

Cyber security awareness

The former chief of security at Uber, Joe Sullivan, is facing criminal charges for allegedly failing to properly disclose the 2016 data breach that affected 57 million Uber riders and drivers.

TikTok users should change their passwords and activate multifactor authentication (MFA) in the wake of rumours of a security breach say security experts. However, the company is denying there is any evidence it has been hacked.

Public sector security incidents cost an average of USD 2.07 million each, according to the most recent IBM Cost of a Data Breach report. Cyber attacks in 2018 cost the US government USD 13.7 billion, the report states.

Cyber security intelligence

The FBI is warning about an increase in vulnerabilities in unpatched medical devices. The devices lack embedded security features and are difficult to patch or update, according to the FBI. Vulnerabilities mean attackers could change the actual operation of the device as well as the allowing them to steal confidential data.

Cyber criminals are targeting healthcare payment processors to try to steal payments. The attackers use phishing and social engineering to gain access to patient files and then redirect payments to a third-party bank account.

Hot topic of the month

Why a security culture is as important as security tools

October is Cyber Security Awareness Month, which is the perfect time to evaluate your company’s security culture. Organizations without a built-in culture of security leave themselves open to many more vectors of attack.

In organizations with a good security culture, employees know to always be on the lookout for potential security threats. They report suspicious emails and activity to their security team and understand the importance of vigilance.

What is the security culture of your organization? How would your employees react in the following two scenarios?

What happens when an employee receives a phishing email with grammatical errors and a suspicious link?

  • With a bad security culture: Email is ignored and/or deleted.
  • With a good security culture: Email is reported to the cybersecurity team for investigation.

What happens when a USB device is found on the floor marked ‘Payroll 2022’?

  • With a bad security culture: The USB device is inserted into a computer.
  • With a good security culture: The USB device is given to the cybersecurity team for investigation.

Building a good security culture requires employees to fully understand the implications of a security breach. They need to understand techniques, such as phishing and social engineering, that are commonly used by criminals. They also need to know, understand and follow the overall security policy the organization.

Without a security culture, even with the best security products, human error can allow cybercriminals to penetrate an organization’s network.

Security culture or not, companies are taking security very seriously by spending more on security products than ever before. The global cyber security market is booming, with revenues expected to hit USD 334 billion in 2026, up from USD 220 billion last year, according to data and analytics firm Global Data.

This growth is fuelled by digital transformations, massive uptake in the number of connected internet of things (IoT) devices and a general increase in the adoption of security products. The report warns that Australia, Singapore, the Philippines, Thailand, Japan, India and Taiwan are facing an increase in ransomware, phishing and network attacks.

Smaller businesses and start-ups are already under pressure just keeping their business afloat. Many simply don’t have the resources to focus on cyber security. Unfortunately, cyber criminals are now probing the defense of smaller companies more often and a security breach can be devastating in terms of lost business and reputation. Speak to an expert to help cover your security blind spots while you focus on building your business.

crystals-unsplash-prqqqvpzmlw-cta-banner

Speak to us about your security needs

We help you find security solutions that work for your business and budget. Speak to one of our security specialists and protect your business and your employees.

Speak to us about your security needs

We help you find security solutions that work for your business and budget. Speak to one of our security specialists and protect your business and your employees.

Author

sethunathan-bala-contact

Bala Sethunathan
Director, Security Practice & CISO

Security