Category: Security Advisory Blog

GDPR & CCPA: Two Nations Divided by a Common Language

CCPA & GDPR: Two Nations Divided by a Common Language

With six months to go before the California Consumer Privacy Act CCPA goes live in California, it seems we are progressively moving towards common ground when it comes to international privacy law…or are we…?

BeCyberSafe: Like Charity, Cyber-Security Begins at Home

Should organisations do more to help their users protect themselves against cybercrime at home? Should an internal awareness programme include some key things users could do at home which would reduce the chances of their employees succumbing to a fraudster? Do awareness programmes raise awareness of the cybercrime problem but ultimately neglect to educate users…
Read more

Are Organisations Getting their Pen Test BADLY Wrong?!

The whole point of penetration testing (pen testing) is to identify how vulnerable an organisation’s technology infrastructure is to attack. I suspect, however, anecdotally, that a lot of organisations have lost sight of this goal and are now opting for a; vendor-led, paint-by-numbers pen test consisting of maybe one of two high-profile Internet-facing applications. I’m not saying this is a systemic issue but from my observation over the last few years, it seems this approach to pen testing is pretty widespread and I think we desperately need a return to pen testing’s ethical hacking roots…

GDPR – 7 Things encryption won’t solve

There are lots of reasons to use encryption and other cryptographic techniques when it comes to mitigating the risks associated with protecting the rights and freedoms of Data Subjects under GDPR. There are however a lot of things that encryption won’t solve too. In this brief article, we will look at 7 of those things encryption is just never going to solve.