<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: A security company, even they are prone to human behaviour in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29722#M3641</link>
    <description>&amp;gt; Caute_cautim (Community Champion) mentioned you in a post! Join the conversation&lt;BR /&gt;&lt;BR /&gt;&amp;gt; @rsladeI think both myself and the community would be very interested in some&lt;BR /&gt;&amp;gt; additional examples and links, if possible? &amp;nbsp; Thank you &amp;nbsp; Regards &amp;nbsp; Caute_cautim&lt;BR /&gt;&lt;BR /&gt;Well, one of my first *formal* contacts with them ...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://victoria.tc.ca/int-grps/books/techrev/pccill2n.rvw" target="_blank"&gt;http://victoria.tc.ca/int-grps/books/techrev/pccill2n.rvw&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Of course, even at that time they were responsible for one of the first "false"&lt;BR /&gt;viruses ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;There is no conversation more boring than the one where everybody&lt;BR /&gt;agrees. - Michel de Montaigne&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Fri, 08 Nov 2019 09:49:39 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2019-11-08T09:49:39Z</dc:date>
    <item>
      <title>A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29666#M3630</link>
      <description>&lt;P&gt;Interesting that even Trendmicro were subject of an internal human behaviour issue - potentially 12 million people within the database.&amp;nbsp;&amp;nbsp; Potentially another GDPR or privacy prosecution in the making.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.itnews.com.au/news/trend-micro-employee-sold-user-data-to-tech-support-scammers-533573?eid=3&amp;amp;edate=20191107&amp;amp;utm_source=20191107_PM&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=daily_newsletter" target="_blank"&gt;https://www.itnews.com.au/news/trend-micro-employee-sold-user-data-to-tech-support-scammers-533573?eid=3&amp;amp;edate=20191107&amp;amp;utm_source=20191107_PM&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=daily_newsletter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 02:25:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29666#M3630</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-11-07T02:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29672#M3631</link>
      <description>&lt;P&gt;There are relatively few ways to control for rogue insiders 100% effectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A staffer with properly authorised access to data can often take it to sell on.&amp;nbsp; The case of Morrison's in the UK is a case in point, in which the employer is being judged to be vicariously liable for the breach.&amp;nbsp; And for those that suggest DLP is a solution, I've come across staff taking photos of screens, printing out materials and writing details on post it notes.&amp;nbsp; You can do you're background checks, ban smartphones, implement DLP, lockdown&amp;nbsp; removable media, implement VDI and disable cut and paste, install CCTV, closely supervise staff and conduct random physical searches.&amp;nbsp; And still they'll be a residual risk if the data can be monetised.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 09:09:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29672#M3631</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-11-07T09:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29678#M3632</link>
      <description>&lt;P&gt;I agree, this is much like privileged access of all kinds.&amp;nbsp; The risk is always there, and you have to use the fear of getting caught as a mitigating control.&amp;nbsp; All the controls you mentioned, CCTV, etc. need to be VERY visible, and if anyone is caught, it needs to be as public as possible, within the relevant privacy laws and policies, of course.&amp;nbsp; But if everyone knows that John spent 60 days in jail and was fined $10K for selling PII, they are less likely to do it.&amp;nbsp; If everyone is quiet about what happened (Not just what COULD happen, but what DID), then it is far more likely to happen again.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 11:13:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29678#M3632</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2019-11-07T11:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29679#M3633</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/604773865"&gt;@mgorman&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...controls... need to be VERY visible,&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The thing about visible controls (including public executions) is that they also enable the adversary learn how to bypass your controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you ever have the chance to visit Israel, you might contrast &lt;A href="https://www.huffpost.com/entry/what-israeli-airport-secu_b_4978149" target="_blank" rel="noopener"&gt;their approach&lt;/A&gt; to airport security vs the TSA/USA approach.&amp;nbsp; Their focus is geared towards multiple subtle control points, rather than a single "castle wall" that the adversary can surveil for weakness.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 16:36:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29679#M3633</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-11-07T16:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29696#M3636</link>
      <description>&amp;gt; Caute_cautim (Community Champion) posted a new topic in Industry News on&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Interesting that even Trendmicro were subject of an internal human behaviour&lt;BR /&gt;&amp;gt; issue - potentially 12 million people within the database.&amp;nbsp;&amp;nbsp; Potentially another&lt;BR /&gt;&amp;gt; GDPR or privacy prosecution in the making. &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Good point, but I wish you'd used a better example. Trend Micro has *never*&lt;BR /&gt;been my idea of a security exemplar: I have examples of bad behaviour from them&lt;BR /&gt;going back to the earliest days of AV research ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Never regret. If it's good, it's wonderful. If it's bad, it's&lt;BR /&gt;experience. - Victoria Holt&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Thu, 07 Nov 2019 18:33:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29696#M3636</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-11-07T18:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29707#M3638</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;I think both myself and the community would be very interested in some additional examples and links, if possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 19:53:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29707#M3638</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-11-07T19:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29722#M3641</link>
      <description>&amp;gt; Caute_cautim (Community Champion) mentioned you in a post! Join the conversation&lt;BR /&gt;&lt;BR /&gt;&amp;gt; @rsladeI think both myself and the community would be very interested in some&lt;BR /&gt;&amp;gt; additional examples and links, if possible? &amp;nbsp; Thank you &amp;nbsp; Regards &amp;nbsp; Caute_cautim&lt;BR /&gt;&lt;BR /&gt;Well, one of my first *formal* contacts with them ...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://victoria.tc.ca/int-grps/books/techrev/pccill2n.rvw" target="_blank"&gt;http://victoria.tc.ca/int-grps/books/techrev/pccill2n.rvw&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Of course, even at that time they were responsible for one of the first "false"&lt;BR /&gt;viruses ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;There is no conversation more boring than the one where everybody&lt;BR /&gt;agrees. - Michel de Montaigne&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Fri, 08 Nov 2019 09:49:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29722#M3641</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-11-08T09:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: A security company, even they are prone to human behaviour</title>
      <link>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29758#M3644</link>
      <description>&lt;P&gt;It appears more is coming out, with even Twitter having similar problems:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.darkreading.com/attacks-breaches/twitter-and-trend-micro-fall-victim-to-malicious-insiders/d/d-id/1336301?_mc=NL_DR_EDT_DR_daily_20191108&amp;amp;cid=NL_DR_EDT_DR_daily_20191108&amp;amp;elq_mid=94014&amp;amp;elq_cid=23392365" target="_blank"&gt;https://www.darkreading.com/attacks-breaches/twitter-and-trend-micro-fall-victim-to-malicious-insiders/d/d-id/1336301?_mc=NL_DR_EDT_DR_daily_20191108&amp;amp;cid=NL_DR_EDT_DR_daily_20191108&amp;amp;elq_mid=94014&amp;amp;elq_cid=23392365&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2019 03:10:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/A-security-company-even-they-are-prone-to-human-behaviour/m-p/29758#M3644</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-11-09T03:10:46Z</dc:date>
    </item>
  </channel>
</rss>

