News round-up March 2021 — That horrible Exchange compromise, IOT security threats made real and digital platforms’ latest privacy challenges

25 March 2021

“But has the horse has already bolted?” That’s the question senior US officials want companies who’ve applied patches for the highly publicised Microsoft Exchange security breach to ask themselves.

Read more

elevenM turns five

19 February 2021

elevenM turned five this week. I recall a stat from university that half of all small businesses fail within the first five years. I am not sure if that stat

Read more

News round-up February 2021 — Downplaying data breaches, escalating ransomware tactics and “there’s something in the water”

11 February 2021

Once again, privacy and data breaches are in the news this month, with the OAIC saying that organisations are downplaying them. There’s a general trend of regulators and law enforcement stepping up this month, with historic decisions by the OAIC, the FTC and the Norwegian Data Protection Agency, and a crackdown on the notorious Emotet botnet.

Read more

News round-up Jan 2021 — SolarWinds hack, the need for robust external security assurance, and a community demand for privacy

12 January 2021

While the far-reaching consequences of the SolarWinds-FireEye-US Government hack are only just starting to be understood, a few stand-out lessons are emerging. In this round-up, we also observe oversight bodies in Australia starting to demand external assurance that organisations’ cyber security is robust. The rising swell from consumers demanding improvements in privacy protection also continues, with responses in kind by Apple, Microsoft, and the Australian Competition & Consumer Commission (ACCC).

Read more

End of year wrap: What the Four Seasons Total Landscaping debacle taught us about privacy and security

17 December 2020

It’s been a dumpster fire of a year, and so, for our end-of-year wrap, we looked to the most ridiculously hilarious moment of the year. Here are five lessons we took from the infamous Four Seasons Total Landscaping debacle:

Read more

News round-up Dec 2020 – Escalation in ransomware tactics, world-first privacy settlement and more

1 December 2020

For what appears to be the first time, a privacy settlement has dictated the need for an organisation to consider gender-based privacy risks. We look at the implications of the settlement in this roundup. Believe or not, there’s been yet another escalation in ransomware extortion tactics, while we look at why the Government’s critical infrastructure security bill is causing tech companies to get hot under the collar.

Read more

News round-up Nov 2020 – Privacy Act review, ICO fines British Airways £20m over data breach and more

5 November 2020

Privacy is well and truly in the frame this month – not least because of the Government’s review of the Privacy Act. It’s a big deal and we’ll have a bit to say about it – starting with our summary below. As the number of COVID-19 cases ease, attention is now also shifting towards the privacy provisions of COVID-19 check-in services. And turning to cyber, if you felt ransomware wasn’t nasty enough, attackers have dug deep and found more evil to draw on.

Read more

News round-up Oct 2020 — Update on ServiceNSW databreach, Twitter upping its security game, and more

1 October 2020

It’s in the nature of this game that there’ll always breaches and bungles, so increasingly it matters how you respond. And in our eyes, some recent response actions are worth commending. The NSW Government opened up on how it might have prevented the Service NSW breach, while Twitter laid out how it is upping its internal security game after a hack in July. We also explore if NAB’s step into the world of bug bounties sets a new bar for security maturity.

Read more

News round-up Sept 2020 — Thousands of licence details exposed online, HeathEngine to pay $2.9mil, and more

7 September 2020

It’s a veritable smorgasbord – our latest roundup includes incidents traversing cloud security, phishing, extortion, distributed denial of service attacks and insider threat. We also look at a particularly egregious breach of trust by a healthcare website.

Read more

News round-up July 2020 — European court decision on international data transfers, software vulnerabilities, and more

31 July 2020

This month saw some big plays in the world of privacy – most notably the striking down by a European Court of a mechanism for international data transfers. We look at the implications for Australia organisations coming out of the judgement. This month we’re also reminded of the inherent vulnerability of software via stories about backdoors in Chinese tax software, a flood of critical patches released for popular enterprise software products and, of course, more yarns about ransomware.

Read more