<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Biggest cyber risk is complacency not hackers in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54668#M6002</link>
    <description>&lt;P&gt;See both the lack of competency and complacency as being the two biggest factors in the workforce. Otherwise I completely agree.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 18:19:40 GMT</pubDate>
    <dc:creator>Beads</dc:creator>
    <dc:date>2022-10-27T18:19:40Z</dc:date>
    <item>
      <title>Biggest cyber risk is complacency not hackers</title>
      <link>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54647#M6000</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to the John Edwards the UK Information Commissioner, who used to be the New Zealand Privacy Commissioner:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;"The biggest cyber-risk businesses face is not from hackers outside of their company but from complacency within their company"&lt;BR /&gt;&lt;BR /&gt;Great quote from John Edwards -now the UK information commissioner - on the recent £4.4m fine levied against a UK firm:&lt;BR /&gt;&lt;BR /&gt;- "Interserve Group broke data protection law because the company failed to put appropriate measures in place to prevent the cyber-attack"&lt;BR /&gt;&lt;BR /&gt;- "failed to stop a phishing email that an employee downloaded, while a subsequent anti-virus alert was not properly investigated"&lt;BR /&gt;&lt;BR /&gt;- "Interserve used outdated software systems and protocols, had a lack of adequate staff training and insufficient risk assessments"&lt;BR /&gt;&lt;BR /&gt;- Paying a ransom was 'not considered a reasonable step to safeguard data' - “We will not concede that the payment of a ransom to recover data is a mitigating factor"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theguardian.com/business/2022/oct/24/outsourcer-interserve-fined-4-point-4m-cyber-attack-failings-data-breach-personal-information" target="_blank" rel="noopener"&gt;https://www.theguardian.com/business/2022/oct/24/outsourcer-interserve-fined-4-point-4m-cyber-attack-failings-data-breach-personal-information&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/10/biggest-cyber-risk-is-complacency-not-hackers/" target="_blank" rel="noopener"&gt;https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/10/biggest-cyber-risk-is-complacency-not-hackers/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:21:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54647#M6000</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Biggest cyber risk is complacency not hackers</title>
      <link>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54668#M6002</link>
      <description>&lt;P&gt;See both the lack of competency and complacency as being the two biggest factors in the workforce. Otherwise I completely agree.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 18:19:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54668#M6002</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2022-10-27T18:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Biggest cyber risk is complacency not hackers</title>
      <link>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54677#M6003</link>
      <description>&lt;P&gt;Having been with 14 different companies/agencies I see the same repeatable pattern:&lt;/P&gt;&lt;P&gt;1) Poor patch management&lt;/P&gt;&lt;P&gt;2) Outdated IT and Security tools&lt;/P&gt;&lt;P&gt;3) Lack of modernization of infrastructure&lt;/P&gt;&lt;P&gt;4) Poorly trained or (satisfied where they are ) workforce&lt;/P&gt;&lt;P&gt;5) Users, no matter what the security training provided, who will click on an email that entices them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Complacency yes. Not upgrading tools because "What we have is working." "We haven't been hacked yet!" "We're too small. No hacker would want to come after us."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to have bold leadership too that can inspire a workforce. You have to have finance departments willing to spend money BEFORE a breach happens, not just release the purse strings AFTER an event happens.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And if all that fails, if you have a motivated attacker, they can eventually find a way in.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 19:29:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Biggest-cyber-risk-is-complacency-not-hackers/m-p/54677#M6003</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2022-10-27T19:29:15Z</dc:date>
    </item>
  </channel>
</rss>

