info@foxredrisk.com

Category: Security Advisory Blog

Cyber Security - Resilience - Data Protection

Calling time on time-based billing – use service-based billing if you want to save £££

When pitching for consultancy work, many of our clients are [initially] surprised we at Fox Red Risk do not price any of our services based on a daily rate model. It seems the majority of consulting organisations, small and large, price their jobs based on some form of time-based billing. This billing approach may be…
Read more

Cube

Complexity & Data Subject Access Requests

According to the 2020/21 ICO annual report, around half of the [46% of ~40k] complaints the regulator receives are related to subject access. Fulfilling DSARs is clearly an area where Data Controllers are facing challenges with data subject satisfaction. In a previous article, I wrote about coping with DSAR volumes, suggesting methods to bring such high numbers…
Read more

Colonial Ransomware Attack: It’s time to rethink your backup & restoration strategy.

No doubt, if you’re following the news, you may have seen an uptick in the number of ransomware attacks doing the rounds. There have been quite a few. In particular, the Colonial Pipeline attack. It’s beginning to seem a lot like Groundhog Day! You would think, after seeing how the ransomware attack in January 2020 crippled…
Read more

Denial of Suez: What can we learn about risk assessing SPOF?

Single points of failure (SPOF) creep into many business processes. Often unintentionally. Some exist from the outset but were simply not assessed, or were assessed and deemed low risk. That legacy server running a critical piece of code wasn’t legacy at the beginning. That retiring SME, the one who wrote the code, had just started.…
Read more

Virtual CISO – Running a Business. Thinking Differently about Security!

It’s Monday morning and I have already been up for a while. I have had a few cups of tea. I have answered a few emails. I have written and submitted a proposal for a new piece of work. It’s a great client too. When I submitted the proposal I had a sense of relief…
Read more

EU/UK GDPR Lawful Bases – Getting accountability right

Working out the lawful bases for your processing activities can be a challenge. Whilst the ICO has guidance and a useful tool to help organisations determine the lawful bases of processing, the final decision will always rest on the Controller organisation to defend. A Controller thus needs to document their lawful bases properly because if…
Read more

stinky-socks

Is your Managed SOC starting to smell a bit fruity? Here’s what to do if it is

Remember a couple of years ago (when life was so very different). Remember reaching that point in your security maturity journey where you needed a way of detecting security events without the help of the BBC News letting you know? Remember looking at all those complex SIEM solutions? Remember deciding the time and effort involved…
Read more

Adequate

EU has drafted its adequacy decision on the UK…and it seems we’re adequate.

As predicted in an article I wrote earlier this year, the EU are on the cusp of finding the UK’s data protection regime adequate. The draft decision has been published and so you don’t have to read the whole 87 page document I took one for the team and have summarised the bits I thought might be of interest,…
Read more

Brexit Deal and GDPR – Adequacy will follow [shortly]

The information contained in this article is provided for informational purposes only, and should not be construed as legal advice on any subject matter So…it’s here! Despite many saying it was not possible, a free trade deal has been done. Whether it’s a good deal or a bad deal for the UK is yet to…
Read more

Policy Folders

We need to talk about Information Security Policy…

I’m sure you’re already well on the way to planning your 2021…what it’s December already? Yup, the annus horribilis that is 2020 is coming to an end. With multiple vaccines in the pipeline, 2021 should [hopefully] be a year where we can get things back to normal. Well, a new normal! Whilst 2020 has placed a number of restrictions…
Read more