News round-up March 2021 — That horrible Exchange compromise, IOT security threats made real and digital platforms’ latest privacy challenges
25 March 2021
“But has the horse has already bolted?” That’s the question senior US officials want companies who’ve applied patches for the highly publicised Microsoft Exchange security breach to ask themselves.
elevenM turns five
19 February 2021
elevenM turned five this week. I recall a stat from university that half of all small businesses fail within the first five years. I am not sure if that stat
News round-up February 2021 — Downplaying data breaches, escalating ransomware tactics and “there’s something in the water”
11 February 2021
Once again, privacy and data breaches are in the news this month, with the OAIC saying that organisations are downplaying them. There’s a general trend of regulators and law enforcement stepping up this month, with historic decisions by the OAIC, the FTC and the Norwegian Data Protection Agency, and a crackdown on the notorious Emotet botnet.
News round-up Jan 2021 — SolarWinds hack, the need for robust external security assurance, and a community demand for privacy
12 January 2021
While the far-reaching consequences of the SolarWinds-FireEye-US Government hack are only just starting to be understood, a few stand-out lessons are emerging. In this round-up, we also observe oversight bodies in Australia starting to demand external assurance that organisations’ cyber security is robust. The rising swell from consumers demanding improvements in privacy protection also continues, with responses in kind by Apple, Microsoft, and the Australian Competition & Consumer Commission (ACCC).
End of year wrap: What the Four Seasons Total Landscaping debacle taught us about privacy and security
17 December 2020
It’s been a dumpster fire of a year, and so, for our end-of-year wrap, we looked to the most ridiculously hilarious moment of the year. Here are five lessons we took from the infamous Four Seasons Total Landscaping debacle:
News round-up Dec 2020 – Escalation in ransomware tactics, world-first privacy settlement and more
1 December 2020
For what appears to be the first time, a privacy settlement has dictated the need for an organisation to consider gender-based privacy risks. We look at the implications of the settlement in this roundup. Believe or not, there’s been yet another escalation in ransomware extortion tactics, while we look at why the Government’s critical infrastructure security bill is causing tech companies to get hot under the collar.
News round-up Nov 2020 – Privacy Act review, ICO fines British Airways £20m over data breach and more
5 November 2020
Privacy is well and truly in the frame this month – not least because of the Government’s review of the Privacy Act. It’s a big deal and we’ll have a bit to say about it – starting with our summary below. As the number of COVID-19 cases ease, attention is now also shifting towards the privacy provisions of COVID-19 check-in services. And turning to cyber, if you felt ransomware wasn’t nasty enough, attackers have dug deep and found more evil to draw on.
News round-up Oct 2020 — Update on ServiceNSW databreach, Twitter upping its security game, and more
1 October 2020
It’s in the nature of this game that there’ll always breaches and bungles, so increasingly it matters how you respond. And in our eyes, some recent response actions are worth commending. The NSW Government opened up on how it might have prevented the Service NSW breach, while Twitter laid out how it is upping its internal security game after a hack in July. We also explore if NAB’s step into the world of bug bounties sets a new bar for security maturity.
News round-up Sept 2020 — Thousands of licence details exposed online, HeathEngine to pay $2.9mil, and more
7 September 2020
It’s a veritable smorgasbord – our latest roundup includes incidents traversing cloud security, phishing, extortion, distributed denial of service attacks and insider threat. We also look at a particularly egregious breach of trust by a healthcare website.
News round-up July 2020 — European court decision on international data transfers, software vulnerabilities, and more
31 July 2020
This month saw some big plays in the world of privacy – most notably the striking down by a European Court of a mechanism for international data transfers. We look at the implications for Australia organisations coming out of the judgement. This month we’re also reminded of the inherent vulnerability of software via stories about backdoors in Chinese tax software, a flood of critical patches released for popular enterprise software products and, of course, more yarns about ransomware.