Using ISO 27001 to guide your GDPR breach response plan

Among the many changes GDPR will usher in, one of the biggest for many organisations will be mandatory breach reporting. From May 25, all organisations holding personal data about European Union residents must disclose a breach if it is “likely to result in risk to personal data”. What’s more, organisations must report such breaches within […]

Security newsround: May 2018

We round up reporting and research from across the web about the latest security news and developments. This month: police success against cyber villains, the value of personal data, IoT security, a new ransomware strain, a new security framework and Gmail goes for 2FA. Law’s long arm collars cyber crooks Police forces scored three big […]

Permission slip: what consent means and where it really applies to GDPR

As data protection and privacy professionals, we use terms from data protection legislation daily and they roll off the tongue as if we were born knowing what the words mean. The problem is, GDPR contains words that have both a legal meaning and a different semantic meaning. Talking with consumers and clients, I realise that […]

10 steps to better security awareness part 2: apply lessons learned

In the first part of this blog, we looked at how to develop an effective simulated phishing test. Now, we’re covering the five steps to ensure everyone in the organisation absorbs the right lessons from those exercises. As before, the advice is courtesy of David Prendergast, who has joined the BH Consulting team as a […]

Meeting the security skills gap (hint: don’t exclude half the potential workforce)

Getting skilled people into cybersecurity roles continues to be a challenge. In a Ponemon survey from earlier this year, security leaders said their biggest security concern for the coming year was a talent gap. Commenting at the time, Brian Honan wrote in the SANS newsletter that the best way to tackle a skills shortage is to […]

10 steps to better security awareness part 1: prep your phishing test

Last month, we blogged about how security awareness training can help to improve an organisation’s defences. Since then, there’s been more evidence showing just how lucrative phishing can be for attackers – and why it’s important to teach users to watch for it. In one recent simulation test, the security company Positive Technologies sent more […]

Security newsround: April 2018

We round up reporting and research from across the web about the latest security news. This month: privacy palaver at Facebook, a cyberattack with explosive intent, securing the IoT, sportswear maker uncovers data breach, and authorities arrest an alleged cybercrime mastermind. Facebook shook by reverberations and revelations The worlds of privacy and security collided last […]

Ransomware reminders force focus on prevention and planning

Ransomware reared its ugly head again recently, with some stark reminders that it’s still a serious business risk. A household name suffered what seemed a major infection, while it emerged that many victims never get their data back. Last week, Boeing narrowly avoided a tailspin after a senior engineer alerted colleagues of a WannaCry infection. […]

Here’s how to get the most from a cybersecurity assessment

Would your organisation pass a cybersecurity assessment? Not one of 200 UK NHS trusts did, after the Department of Health checked them following the WannaCry ransomware outbreak. The NHS trusts’ complexity meant the assessments set a high bar. But for many SMEs, the assessments identify opportunities to improve, rather than obstacles to overcome. They show […]

Teach staff to steer clear of phishing hooks with awareness training

One of the most important steps for improving security is to understand where you’re starting from first. That covers technical questions like what systems you run or where you store data. Then there’s the all-important human factor: how much do the organisation’s people know about security risks like phishing and malware? Research repeatedly tells us […]