NCSC urges organisations to secure supply chains

The UK’s National Cyber Security Centre (NCSC) has today published new guidance to encourage organisations to work in tandem with others in their supply chains to identify and address security issues, following a marked rise in incidents. Cyber attacks originating from within supply chains have become widespread in the past 18 months to two […]

Read more
French Supreme Court rejects EncroChat verdict after lawyers question secrecy over hacking operation

France’s Supreme Court has referred a criminal case that relies on evidence from the hacked EncroChat encrypted phone network back to the court of appeal after finding that prosecutors failed to disclose sufficient information about the hacking operation. The Cour de Cassation in Paris found that French investigators and prosecutors had failed to supply […]

Read more
Microsoft fixes lone zero-day on October Patch Tuesday

Microsoft has issued fixes for a total of 85 newly discovered common vulnerabilities and exposures (CVEs) in its October Patch Tuesday drop, among them a single zero-day vulnerability, but has not yet moved to patch two other zero-days discovered in Exchange Server in September, raising eyebrows in the community. The two vulnerabilities in Exchange […]

Read more
ICO selectively discloses reprimands for data protection breaches

The Information Commissioner’s Office (ICO) has issued reprimands to seven public and private organisations over failures to respond to requests for personal information, but experts have questioned why the regulator chooses to publicly disclose some reprimands and not others. Under the UK Data Protection Act 2018 (DPA 18), the ICO has the power to […]

Read more
Meta presents vision for business metaverse

Meta, the parent company of Facebook, WhatsApp and Instagram, used the start of its Meta Connect conference to showcase new hardware and its vision for the business metaverse. The overall aim is to offer a collaborative workspace capable of combining virtual reality (VR), augmented reality (AR) and online video conferencing in an immersive collaborative […]

Read more
The basics of zero-trust network access explained

In organizations with remote employees, productivity depends on secure, reliable access to applications, services and data over the internet from any device, at any location or time. Yet the internet can expose IP addresses and create security risks due to implicit trust and a wealth of vulnerabilities. This is where zero-trust network access (ZTNA) […]

Read more
Reducing the cyber stack with API security

In a see-sawing economy, it can be difficult to determine how best to invest, which is why Forrester’s latest Planning guide 2023: Security and risk report is seen as providing a much-needed steer. It suggests that CISOs should prioritise by focusing on technologies that improve the customer experience or increase revenue, but at the […]

Read more