Category: CISO Blog

Category: CISO Blog

Risk Management – It’s a bit like a hungry baby!
02/07/2020 CISO Blog, DPO Blog, Operational Resilience Blog, Security Advisory Blog EditoratLarge

First things first – I am no parenting expert! Up until very recently, I thought that when a baby cries, they need one of four things…cuddles, feeding, nappy change or medical attention. Now it is still true that when a baby cries they most likely need one [or more] of those things. It is also

Read More
Locard’s Exchange – The Principle every Security Operations Analyst needs to know!
31/05/2020 CISO Blog, Security Advisory Blog EditoratLarge

An organisation can have all the security tools in the world. SIEM, UEBA, SOAR, you name it. Ultimately those tools will end up as shelfware if there isn’t a human being looking at the output. Sure, “AI” (or Machine Learning for non-Marketeers) can do a lot of the heavy lifting if properly configured. BUT at some point,

Read More
Operation CYGNUS – Was the UK’s Coronavirus response a failure based in assumption…?
07/05/2020 CISO Blog, Operational Resilience Blog, Security Advisory Blog EditoratLarge

So much has been discussed about the Tier One Command Post Pandemic planning exercise of 2016. For those who haven’t been part of the discussion, the Public Health England, on behalf of the Department of Health delivered a pandemic planning exercise between 18 to 20 October 2016. The exercise was primarily aimed at assessing high-level

Read More
Application Security – Zoom is a Knife Crime!
17/04/2020 CISO Blog, DPO Blog, Security Advisory Blog EditoratLarge

The news ebbs and flows and so too do people’s attitudes to the world around them. We are all influenced by the media. Take knife crime. In 2019, knife crime was a significant problem in London. So we should ban knives! Knives are dangerous! Knives should not be used under any circumstances. Why are you

Read More
Morrisons NOT vicariously liable for employee data protection breach says UK Supreme Court
01/04/2020 CISO Blog, DPO Blog, Security Advisory Blog EditoratLarge

Firstly – This is legal information of general interest and does not constitute legal advice of any kind. On April 1, 2020, the UK Supreme Court today handed down their judgement in the case of WM Morrisons Supermarkets plc (Appellant) v Various Claimants (Respondent), case UKSC 2018/0213. The Supreme Court unanimously ruled that Morrisons were not

Read More
Coronavirus Load balancing – Understand it can’t be stopped. We’re just smoothing the peaks in demand.
14/03/2020 CISO Blog, Operational Resilience Blog, Security Advisory Blog EditoratLarge

Similar to the way your IT teams will be trying very hard to load balance the impact of all your extra remote working VPN connections, the government is trying to load balance the impact on the health service and the economy…keep calm and read on!

Read More
Calculating Risk – Where’s your Confidence?!
05/03/2020 CISO Blog, DPO Blog, Operational Resilience Blog, Security Advisory Blog EditoratLarge

When helping organisations navigate risk management Fox Red Risk is often faced with the task of determining methods for calculating risk. We prefer to use tried and tested methodologies but what we often find is that organisations, very rarely, are calculating risk properly. A key thing missing from the majority of implementation we see is

Read More
Virtual CISO – Dispelling the Myths!
22/02/2020 CISO Blog, Security Advisory Blog EditoratLarge

The virtual CISO or virtual Chief Information Security Officer is a relatively new concept and with that comes a few misunderstandings of what the client actually gets (i.e. solid cybersecurity protection for your business). The word “virtual” probably doesn’t do us any favours but let’s look at some of the more common misconceptions about a

Read More
Cybersecurity Skills Gap – Who is doing the teaching…and who should provide the funding?
10/02/2020 CISO Blog, Security Advisory Blog EditoratLarge

It seems like every other day there is yet another article highlighting the impending apocalypse of the cybersecurity skills gap. The articles often moan that it is the fault of the employer for wanting qualified personal (who knew) and then try to solve the problem essentially with the advice: Why not hire someone who wants

Read More
Asset Discovery for Cybersecurity & Data Protection – You can’t protect it if you don’t know it exists!
03/02/2020 CISO Blog, DPO Blog, Operational Resilience Blog, Security Advisory Blog EditoratLarge

There is an old management adage that what isn’t measured isn’t managed. It’s so true. Something similar applies to cybersecurity. If you don’t know an asset exists, how on earth can you protect that asset from a cyber-attack or data breach?! Asset Discovery is the number one exercise a new CISO (or Virtual CISO) should

Read More