• HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE

Knowledge Update: 09 February 2018

09-February-2018
-
Blog
-
No comments
-
Posted by Tom Lejava

This week’s Knowledge Update talks about how all NHS trusts have failed their Cyber Essentials, A flaw in TLS/SSL Certificates allowing covert data transfer and businesses with poor cyber security will have to pay fines up to £17m.

All NHS Trust have failed their Cyber Essentials

A parliamentary committee has said that every NHS Trust has failed to meet the recommended data security standards.

Rob Shaw, who is the NHS’s Digital deputy chief executive, has told a Public Accounts Committee hearing that after completing 200 on-site assessments, no Trust had managed to meet the recommendations that were set out by Fiona Caldicott, who is the Chair of the Oxford University Hospitals NHS Foundation Trust.

The national data guardian for health and care had set out 10 data security standards which were confirmed by the government in July 2017. These data security standards include accreditations to the government-backed Cyber Essentials Plus scheme.

Protecting customer data is a legal duty. Cyber Essentials provides a framework, backed by the UK government, for businesses to improve their information security. More information can be found here.

Read more.

A Flaw in TLS/SSL Certificates allows covert data transfers

According to Jason Reaves, who is a threat research principal engineer at Fidelis Security, there’s a new flaw in the way certificates are exchanged which could allow them to be stolen for Command-and-Control (CnC) communications. This process also ends up bypassing common security measures.

Essentially, the certificates will be exchanged during the TLS handshake, before the secure connection is made. This is done by placing arbitrary binary data into the certificates themselves. Jason Reaves has uncovered a system that could be used to send and received different data from both, the client and server perspective.

Implementing DMARC, Encryption and Digital Signatures across your business will secure your sensitive data and reduce phishing attacks. More information on implementing DMARC can be found here or contact the London Digital Security Centre for more information here.

More information on TLS & SSL.

Read more.

Fines up to £17m for firms with poor cyber security

The government has announced that companies who fail to protect themselves effectively online from cyber-attacks are liable to face fines of up to £17m.

Regulators will be able to inspect various cyber-security things that are put in place for companies in various sectors such as Energy, Transport, Water and Health Companies.

However, In August last year, Matt Hancock, who is a former Digital Minister has said that imposing these fines would be a “last resort”.

Margot James, who is our current Minister for Digital has said that “We want our essential services and infrastructure to be primed and ready to tackle cyber-attacks and resilient against major disruption to services”.

Organisations should ensure that staff are appropriately trained in regard to regulations such as the Data Protection Act (a checklist can be found here).

More information on Flaws and the risks they pose can be found here.

Read more.

Tags
Cyber Essentials
Cyber Security
Knowledge Update
NHS
SSL
TLS
£17m fines
← PREVIOUS POST
Knowledge Update: 23 February 2018
NEXT POST →
What Chief Information Security Officers across London want you to know about Cyber Hygiene.
Categories
  • Blog
  • Press Release
Recent Posts
  • Is your business cyber-ready?
  • You’ve Got Mail: 5 Tips to Secure Your Email
  • #OneReset - What could you really lose in a hack?
  • Here’s what GDPR means for your business!
  • Essential Advice for Small Business Cyber Security
London Digital Security Centre

We are a Not for Profit organisation, launched by the Mayor of London as a joint venture with the Metropolitan Police and City of London Police.

Leave a Comment

Your feedback is valuable for us. Your email will not be published.
Cancel Reply

Please wait...
Submit Comment

Related News

Other posts that you should not miss.

Essential Advice for Small Business Cyber Security

09-April-2018
-
Blog

Essential Advice for Small Business Cyber Security Innovate UK is part of UK Research and Innovation, a non-departmental public body funded by a grant-in-aid from the UK …

Read More →
Posted by Tom Lejava
4 MIN READ

Five Top Tips to Keep you Cyber Secure

25-September-2017
-
Blog

Guest blog by Andy Taylor – Lead Cyber Assessor at APMG. Every day we hear of new attacks, new ways of depriving us of money, our information or …

Read More →
Posted by Tom Lejava
4 MIN READ
GDPR

GDPR – so what…?

25-October-2017
-
Blog

…is it? The General Data Protection Regulation (GDPR) comes into force on May 25th 2018. It outlines how organisations should manage and protect personal information. …does it mean? …

Read More →
Posted by Tom Lejava
2 MIN READ
Twitter Follow
Tweets by LondonDSC
Social Connect
News
  • 18-March-2019
    Is your business cyber-ready?
  • 05-February-2019
    You’ve Got Mail: 5 Tips to Secure Your Email
  • OneReset
    23-October-2018
    #OneReset - What could you really lose in a hack?
Contact Us

Company Number : 09639299
Mail to : [email protected]
Address : One Wood Street, London,
United Kingdom, EC2V 7WS.

Built by Cyber Rescue
Privacy   T & C
Copyright London Digital Security Centre (LDSC) 2017
Knowledge Update: 09 February 2018 - London Digital Security Centre
 Logo Header Menu
MENU
  • HOME
  • MEMBERSHIP
  • IN THE COMMUNITY
  • MARKETPLACE
    • SECURITY PRODUCTS
  • ABOUT US
    • PARTNERSHIPS
    • OUR TEAM
  • NEWS & EVENTS
    • EVENTS
    • PRESS RELEASES
    • BLOG
    • MEDIA OVERVIEW
    • GALLERY
  • TIPS & ADVICE