A recent report of 300 IT professionals revealed 65% expect a serious data breach to hit their business within the next year

 

Cyber attacks and cybersecurity failings have continued to dominate headlines in recent years.

Sony, VTech, Talk Talk, and the Australian Bureau of Statistics are just a small number of high profile organisations exposed to cyber breaches.

Yesterday, Okta (an identity management firm) released a report that highlighted just how concerned IT leaders were with the current cyber situation.

Cyber security systems are, it would appear are losing on the digital battlefield.

Information Age spoke to David Baker, chief security officer at Okta, about this survey and the future of the cybersecurity industry.

 

Were the results of the report shocking, or expected (given increased business connectivity)?

We don’t see the results as shocking, per se. But certainly interesting, especially because the results and trends are analogous to where many similar enterprises in the U.S. were as recently as the last two years.

It is actually very encouraging to see enterprises in the surveyed regions recognise their current challenges with becoming both more agile and more secure with their on-premises IT technology stacks.

Enterprises will recognise how best-of-breed cloud and mobile solutions will address these challenges.

 

How can the risk of breach be reduced through today’s IT technologies?

In simple terms, reducing risk means reducing the number of attack avenues (we use the term “attack vectors”) that are exposed to possible attackers.

Attack avenues are things like servers with outdated software versions, or vulnerable operating systems, misconfigured network devices, and even poor administrator access practices.

The list can be extensive — and justifiably so because deploying and maintaining IT infrastructure is difficult and complex.

The reason to approach cloud services to replace your on-premises IT infrastructure is to remove those attack avenues from your infrastructure.

Best-of-breed cloud services primarily focus on delivering a few key services very well (i.e. box for file collaboration, workday for HR systems, etc.).

Moreover, these services are held to high audit standards such that their infrastructure, personnel, and processes are always under focus and testing.

Attack avenues found in the typical on-premises IT infrastructure have been mitigated and blocked.

Best-of-breed cloud solutions need to be leveraged.

These services will offer the best avenues of feature integration, mobility usage, and service reliability — all while removing the attack avenues and improving cyber security for the enterprise.

 

What is the most common cause of a data breach (human error or external), and how can they be improved?

The most common cause of data breach has been and remains loss of access credentials from human error.

I define human error events to be everything from writing down credentials on notes and reusing weak passwords to falling victim to spear phishing attacks.

Users can be trained to avoid these types of errors.

Providing easy-to-implement and easy-to-use security solutions that protect users’ identities even in the event user credentials are compromised is a key prevention control.
 

Are trends like BYOD having an effect on the compromised security of data?

The answer here is really yes and no.

Users that continue to use antiquated and fragmented Android platforms or old iOS versions, can become an attack vector if they inadvertently install malicious applications on the devices.

That being said, we see that — in large part — most of these types of malware attacks on older mobile devices are targeting users with persistent adware.

Users that are using newer Nexus-based Android devices or maintaining their iOS devices to the latest operating systems and are leveraging good habits in patching apps — and companies with BYOD policies that insist this happens — are not necessarily compromising security.

Source: InformationAge

 

A connected healthcare system could see major benefits for both healthcare professionals and patients. A report from Raconteur has announced that some countries are taking to this quicker than others.

Surprisingly, the UK is lagging behind in adopting connected healthcare technologies compared to other countries. Despite the high access to healthcare in the UK, the integration of healthcare and technology is amongst the lowest with an FHI score of 53.7.

A major barrier on uniting healthcare and technology is the cost of technology adoption and this could be the deterrent for the UK as in 2016 only 8% of the UK's GDP is spent on healthcare.

 

Infographic: Raconteur

For more information , visit Raconteur report 'Lessons in healthcare from around the world'

 

Source: Raconteur

Demand for cyber security professionals grew by almost 70% between 2012 and 2015 – 40% higher than the overall growth rate for IT professionals. This is according to the latest Professional Recruitment Trends report from the Association of Professional Staffing Companies (APSCo).

The insight, based on data from Burning Glass, also indicated that cyber security positions offer higher levels of remuneration than those in other IT roles. On average cyber security jobs advertise salaries of around £48,000, a premium of £12,000 p.a compared to IT salaries overall.

Geographical distribution analysis shows that the highest number of positions are available in London, where there were 25,300 job advertised in 2015. The capital was followed by Reading & Bracknell and Manchester, which saw the number of advertised positons reach 2,400 and 2,000 respectively. A large number of major firms are headquartered in London or Reading & Bracknell, resulting in a high concentration of jobs in these areas.

Ann Swain, Chief Executive of APSCo, commented on the report saying;

“Organisations of all sizes are developing an increased awareness of the implications of a cyber security breach, so it’s no surprise that business leaders across the country are looking to expand their cyber security functions. The high levels of remuneration on offer to these professionals is also unsurprising as not only is their work highly specialised, but also exceptionally valuable as attacks continue to evolve in complexity and become harder to protect against.”

“New cyber risks are developing at an alarming rate and with recent research from the Ponemon Institute indicating that the average cost of a data breach rose to $3.79m in 2014, investment into digital security measures are a becoming a key priority for many businesses. This steep upward trend is one that will undoubtedly continue into the coming months as organisations explore new options to protect against data breaches and expand or establish a cyber security function.”

 

Source: Apsco.org

Certes have been awarded a place on the new Non Medical Non Clinical (NMNC) framework provided by the Crown Commercial Service. The NMNC framework provides access to temporary staff, interim's and contractors in various roles from the most junior to the most senior, including board level roles across Employment Agency and Employment Business. 

July 1st 2015 will see the beginning of a 2 year contract between Certes and NMNC where we will provide contract, permanent and fixed term IT staffing for the NHS, Central Government and to a wider public sector.

Being awarded the NMNC framework, Certes now have access to the NHS and wider public sector in a streamlined procurement vehicle. Candidates who use Certes now have ready made compliance's, and a greater choice of roles to chose from.

Cyber Security is a growing issue in this digital age and affects everyone on a global level. Since dependency on IT technology is so prevalent now than previous years, it's no surprise that cyber crimes have increased with an estimate of 250,000 cyber attacks occurring every day. In the UK alone the average annual cost cyber crimes have on companies has gone from $4.7 million (£3.2 million) in 2013 to $6.3 million ($4.2 million) in 2015, and it is continuing to rise. 

As more technology devices being used continues to soar at a rapid pace, the cyber security market is expected to reach over $170 billion (£116 billion) globally.

 

 

Source: Raconteur

Due to the time of year I have been working with a number of recent Graduates to help them secure their first “real” job.

Recruiting graduates pose a number of unique challenges when compared to experienced hires, they have less experience not only industry related experience but experience of interviews.

There are hundreds of articles detailing interview and CV tips for graduates but I thought I would share some that are particularly relevant to Graduate Developers.

  1. Include examples of projects you have worked on – As a graduate, you may have little or no commercial experience and listing a number of technical skills you have gained from your degree will always pose the questions “how” and “where” you have used these skills. Any extra information or unique projects can set you apart from regular candidates.
  2. Promote your soft skills – This follows on from the first tip, your lack of commercial experience will require you to focus on other skills. Recruiters are particularly interested in your soft skills, teamwork, Time management and communication skills are all required to become a good developer and again as with the first tip provide examples!
  3. Don’t over exaggerate your experience
  4. Promote your interests – Another good way to stand out from you competition and show your passion for the industry. Including self-study, hackathons and personal projects will improve your chances of getting an interview.
  5. Understand your not expected to know everything – This is more of an interview tip rather than a CV tip. Hiring managers understand you won’t have all the technical knowledge and experience in the world, you’re a graduate! They want you to admit when you don’t know understand something. Show your passion for the industry and willingness to learn new things. Admit when you don’t know something. Explain to the hiring manager how you would go about finding a solution. Remember a good developer is a good problem solver!

– Niall

For more information on the Developer market, contact Niall Gibson

Craig has been training diligently to prepare for his 10K run for "Violets in Bloom". This weekend the time has come for him to take up the challenge and dominate the 10K Shenstone Fun Run 2015.

Craig is nearing his goal of £200 but there is still time for you to make a donation to Craig's just giving page and help other families.

From everyone at Certes,

Good luck! 

 

 

Last Friday sites such as Google, Netflix, Twitter and Paypal crashed as a result of a massive DDOS attack on the servers of Dyn a company that controls many of the internet’s DNS servers.

Dyn estimated that the attack had involved “100,000 malicious endpoints”, and the company, which is still investigating the attack, said there had been reports of an extraordinary attack strength of 1.2Tbps.

How did hackers gain access to 100,000 IoT Devices?

IoT devices such as web-enabled security cameras, fridges, ovens and TVs are notoriously easy to hack. All devices that are connected to the internet have an IP address. If something has an IP address it can be found on Google. Once a hacker has the IP address of a device they can attempt to break in, usually with the products default password. How many devices do you think have the username ‘Admin’ and password ‘admin’! Once hackers have access to your device they can add to their botnet.

So who’s to blame? The manufacturer, or the consumer for not changing default passwords? Whilst changing the password on your connected devices won’t make them completely hack proof it certainly makes the process of gaining access more difficult.

The attack on Dyn was a massive wake-up call for everyone. More is needs to be done to make these ‘Smart’ devices secure.

 

– Niall

For more information on the cyber security market, contact Niall Gibson

With the technology of today, Identity theft and compromising sensitive data has become an increasing issue. Information being stored on databases allows for anyone to gain access to a vast collection of data. This could also become an issue for the NHS, General Practitioners and their patients.

While consulting patients, GP’s record the data which then becomes available online. This can be then accessed patients and authorised personnel.

Beverley Bryant, NHS England’s director of strategic systems and technology, said: ‘Practices are required to check and verify people’s identify [sic] before issuing access credentials and guidance has been made available to them through NHS England and the RCGP. In addition, practices should make patients aware of their responsibilities and safeguards they should apply when accessing their records.” But with everything being available online there is potential for the information to be compromised.

Dawn Monaghan, group manager at Information Commissioner’s Office (ICO) public services explained ‘We see very few [breaches] that are, what you would call “malicious security issues”; where somebody deliberately breaches password protocols, cybercrime, those sorts of things… within the health sector.”

NHS England told Pulse “only patients and authorised carers will have access to online records, adding that practices must verify patients’ identities and explain the relevant safeguards.”

Dawn Monaghan also mentioned “I would suggest the cyber-security side of things, the ID-theft side of things, will start to come up the pile in health when we get proper online access to patient records. That is a real danger, and that is where security by design and security in an organised way come in.”

In a day and age where data is becoming more accessible, there is always a fear that sensitive data can be compromised. However, with the right security protocols such attacks can be avoided.

Month-on-month there has been improvements to the demand for IT contractors. October’s results are no different with an index score of 56.3 (score over 50 shows growth over the previous month). Although it still hasn’t reached the heights it once was in January (60.2), it is showing significant recovery and catching up to March results (56.4). To date, this is the highest the demand for IT Contractors has been for 7 months and the highest it has been since Brexit.

 

It’s also important to point out that it’s not only Contractors that are showing growth in demand. “Demand rose for all permanent staff categories during October, but in varying degrees. Engineering maintained its top spot in the table, followed by IT & Computing”. 

Source: SIA

“Despite ongoing uncertainty, the UK jobs market is thriving again in most areas of the UK. Job Vacancies are back to levels not seen since April, and for the third consecutive month recruiters have reported an increase in the amount of people finding permanent jobs”

Kevin Green, Chief Executive of REC