The UK Information Commissioner’s Office (ICO) has identified eight important areas of computer security that have frequently arisen during their investigations of data breaches.

The eight areas are:-

  1. Software updates
  2. SQL injection (65% of organisations have been breached by a SQL Injection attack)
  3. Unnecessary services
  4. Decommissioning of software or services
  5. Password storage
  6. Configuration of SSL and TLS
  7. Inappropriate locations for processing data
  8. Default credentials

The ICO has provided advice for all eight areas. The report can be found here.