The week in security: Revisiting security defences as breaches, BEC losses mount
- 23 July, 2018 10:49
Even as the US FBI warned that business email compromise losses had hit $US12 billion and were continuing to grow, Ticketmaster was warning customers about a payment-card hack after the compromise of a chat-bot tool led to a high-profile compromise.
This sort of event has become more common, highlighting the importance of having an adequate defence against advanced persistent threats (APTs) and consideration of defences against corporate espionage.
Effective security starts from the inside, of course. Yet with small and medium businesses (SMBs) still struggling to get up to speed with adequate security solutions, the message quickly gets more complicated – even around seemingly uncontroversial tools such as single sign-on (SSO) platforms.
Support from the judiciary could help simplify things, with the UK set to open a court in London that specialises in cybercrime.
Yet even as businesses get more options for protection, they also face new threats such as the continuing evolution of complex Internet of Things (IoT) security issues.
IoT has followed, conceptually at least, in the footsteps of cloud computing – whose rapid emergence and evolution has created new security issues as quickly as customers can adopt it.
There were warnings about the adequacy of the security in new WPA3-certified routers, which provide an incremental improvement to data security.
Those seeking to improve security should perhaps consider reading up on tactics for better securing cryptographic keys. And, Microsoft argues, they should also consider upgrading to Windows 10 – which the company credits with stopping a ‘double zero-day exploit’ before anybody was infected.