Archive for May, 2012

Information Commissioner’s Office consults on new anonymisation code of practice

The Information Commissioner’s Office (ICO) has begun a public consultation on a new anonymisationcode of practice. The code will provide guidance on how information can be successfully anonymised and how to assess the risks of identification. The ICO has also launched a tendering process to establish a network of experts to share best practice around the release of data in […]

Rate this:

, , , , , , , ,

Leave a Comment

Database security and SIEM are the top Risk and Compliance concerns

The McAfee report Risk and Compliance Outlook: 2012, has been published and has discovered Database Security and Security Information and Event Management (SIEM) were among the top priorities due to an increase in Advanced Persistent Threats (APT). Database hold the valuable data the criminals are searching for, it therefore follows that Database Security is a growing issue […]

Rate this:

, , , , , , , , , , ,

Leave a Comment

Proposed European wide Data Protection Act – a review

Over the last few months I have attended several conferences and read a lot of research on the proposed upgrade of the European Commission’s 1995 Data Protection Act and have found it fascinating. The rumours, the speeches, the headlines and of course the lack of clarity on how the major issues will be dealt with […]

Rate this:

, , , , , , , ,

14 Comments

Call Centre Security and PCI Compliance

Reblogged from Brian Pennington: Credit Card data is the Crown Jewels for hackers and the financial lifeblood of many companies. An Account Data Compromise, also known as a breach can lead to bad press and a bad reputation, you only need to Google Play.com or Lush to see the impact. With the 18th March 2011 launch […]

Rate this:

Leave a Comment

Survey: 99% rate Security is a major consideration when choosing the Cloud

Intel have produced a very interesting survey on the way businesses perceive the Cloud, what they are looking for whether it is Private or Public and who seems to be the most secure.Below is my summary of the survey’s results. Intel surveyed 200 IT professionals about a wide variety of cloud topics, including the key business and […]

Rate this:

, , , , , , , , , ,

1 Comment

No NHS fines for breaching the Data Protection Act then two come along in quick succession

At the end of April the Information Commissioner’s Office fined The Aneurin Bevan Health Board for breaching the Data Protection Act and today they fined Central London Community Healthcare (CLCH) NHS Trust £90,000. The CLCH breach first occurred in March 2011, after patient lists from the Pembridge Palliative Care Unit, intended for St John’s Hospice, were faxed to the wrong […]

Rate this:

, , , , , ,

3 Comments

Guidance for merchants on how to securely accept mobile payments the PCI way

This has been coming for a while but finally the PCI SSC has published a fact sheet outlining how merchants can securely accept payments using mobile devices such as smartphones or tablets. The “At a Glance: Mobile Payment Acceptance Security fact sheet” provides merchants with actionable recommendations on partnering with a Point-to-Point Encryption (P2PE) solution […]

Rate this:

, , , , , , ,

Leave a Comment

The good old fashion way to breach the Data Protection Act – lose some paperwork

The London Borough of Barnet was fined £70,000 by the Information Commissioner for losing paper records containing highly sensitive and confidential information, including the names, addresses, dates of birth and other details of 15 vulnerable children or young people. A social worker took the paper records home to work on them out of hours and was […]

Rate this:

, , ,

2 Comments

PCI Security Standards Council announces qualified integrators and resellers certification program

The PCI SSC quotes results from the Trustwave 2012 Global Security Report which states that 76% of the breaches they investigated were a result of security vulnerabilities introduced by a third party responsible for system support, development and/or maintenance of business environments. Errors introduced during implementation, configuration and support of PA-DSS validated payment applications by third parties […]

Rate this:

, , , , ,

Leave a Comment

UK Fraud Report 2012

In April Experian released their 2012 review of Fraud in the UK. There are some interesting findings and a summary of the 28 page document is below. Executive Summary of the report Annual fraud losses across the UK are now estimated to now top £70 billion Of this around £3.5 billion is in financial services […]

Rate this:

, , , , , , ,

Leave a Comment

RSA’s April Online Fraud Report 2012

In their April Online Fraud Report RSA reports on the activity of online fraudsters, full summary below. As well as the usual interesting statistics on fraudulent activity this report sheds light on the changes to the Citadel Trojan. Citadel Trojan hooks system processes to isolate bots from AV and security. The Citadel Trojan was first introduced […]

Rate this:

, , , , ,

9 Comments

May is Scam Awareness Month

The Trading Standards Institute (TSI) has launched its Scam Awareness Month to stop the surge in criminals scamming people out of their saving. From fake lottery wins in the post to Microsoft and Anti Virus support on the phones, Prince X trying to get his millions out of the country via email and door-to-door conmen they all […]

Rate this:

, , , , ,

3 Comments

Follow

Get every new post delivered to your Inbox.

Join 977 other followers