Category: Security Advisory Blog

supply chain resilience

Supply Chain Resilience – Who are your Backup Suppliers?

Is your supply chain resilience programme reminiscent of the article image? Aged, poorly maintained, complex, hard-to-untangle. Do you carry out due diligence at the beginning of your engagements? More importantly, do you carry out ongoing governance and oversight? Even more importantly, does supply chain resilience form part of your wider operational resilience strategy or business…
Read more

SWIFT independent assessment

SWIFT independent assessment – have you booked yours?

The SWIFT independent assessment regime will kick in later this year. Have you booked in your assessment? If not, Fox Red Risk has some availability to carry out assessments. Remember the SWIFT payments attacks a few years back? As a reminder In 2015 & 2016, a series of cyberattacks using the SWIFT banking network, which…
Read more

API Security

API Security – Are You Secure from OWASP 2019 Top 10?

Firstly, Happy New Year. 2020 is going to be an exciting year for Fox Red Risk. We have lots of cool new offerings in the pipeline to support businesses large and small in the thankless task of keeping secure. If you have resource gaps and need support, then let us know. Right, back to the…
Read more

security incident

Security Incident Avoidance – Hackers know we’re away for Christmas…

It’s that time of year where many of us will be ensuring our organisations can still deal with a security incident whilst most of the workforce are at home watching Christmas movies like Die Hard – yes, it’s definitely a Christmas Movie. Hackers know businesses are running on skeleton staff during the holiday period so…
Read more

security strategy

Strategy – Can a CISO learn from the 2019 General Election?

Security Strategy – What lessons can CISOs learn from the UK Gerneral Election 2019 when devising and delivering a security strategy? Here are three…

security awareness

Security Awareness Training Dies. My 2020 Prediction

My prediction is that 2020 will be the year security awareness training dies…and not before time…

Cybersecurity Strategy – Organise to Operate

Cybersecurity strategy is being “organised to operate”. A principle that is fundamental to developing an effective cybersecurity programme. Here’s why…

DSAR

DSAR – Help I can’t cope!!! Our Subject Access Request volumes have gone through the roof!!!!

I had an online interaction with a vendor who sells Data Subject Access Request (DSAR) automation software recently. During the ‘pitch’ they highlighted that organisations across London, UK have seen a staggering increase in DSARs since GDPR went live. An article in the Yorkshire Evening Post confirms this is not just a London-centric issue. “In…
Read more

Security Audit - Low Hanging Fruit

Security Audit – Are you a ‘Quiddler’?

Are you a Quiddler? No, this is not some fanboi reference to Harry Potter (I’ll be honest I haven’t read one of the series, I’m a proper muggle!). Quiddling, however, is a very real problem in the world of Security Audit. If you want to know more, keep on reading. You could be one of…
Read more

GDPR Data Retention

Data Retention – A €14.5million fine awaits for Real Estate Data Archive non-compliant with GDPR?

Data retention is always a challenge for organisations. Organisation just love retaining data and well, storage is pretty cheap these days. Whilst the costs of getting retention wrong (e.g. not being able to recover from a ransomware attack) are always high; a recent GDPR fine decision in Germany highlights the data retention problem could get…
Read more