UEA accidentally sent a spreadsheet with confidential medical information to 320 undergrads. The sheet wasn’t password protected, or encrypted, because... the confidential medical information was stored in a spreadsheet because… the spreadsheet was accessible to be attached to an email because… Please tell me that the GDPR will prompt UK orgs to spend at least … Continue reading News in brief
I was talking to someone about data security yesterday afternoon, and mentioned the Mexican data breach where 93.4m citizen records were left in an unsecured cloud database – and immediately stolen – as an example of the carelessness people seem to experience when taking advantage of cheap web storage and processing. Pretty much while I … Continue reading At least make a token effort
Being involved in cyber-security can be quite depressing. So much of the time we see things that make life better for many people being spoiled by a few bad hats. I can't help feeling this is getting worse, and that our digital future will be more paranoid, more cautious, less global and considerably less convenient … Continue reading Have we passed peak convenience?
I will say this only once. Just because WannaCrypt turned out not to be the end of the world, and Microsoft unexpectedly released patches for unsupported operating systems, and Trump dropped the ball again, and there’s an election in the UK, and you’re bored with cynical marketing emails from IT companies, so you’ve moved on…it … Continue reading Now pay attention
I was having a chat with a journalist over the weekend, talking about what the future looks like for cyber-security risk in the UK. Here’s a transcript: J: Where does it all go from here? BR: Lots of hot air from politicians. Nothing done for months. A massive deal for ATOS or someone to refresh … Continue reading #WannaCrypt #NHSCyberAttacks : what comes next?
Actually, it's more like #globalcyberattack. For those of you who are still hiding in their bunkers in case Trump nukes North Korea, the short version is that some crims have used a nasty bug in Windows to spread ransomware across the globe. It still had to get in via an email, and Microsoft patched the bug … Continue reading #nhscyberattack
I’ve let this one fester for a while – partly because I’ve been angry about other things, and partly because you must be bored with my ranting about the GDPR by now. But I really can’t let this one pass. A key principle – perhaps the key principle – of the GDPR is the requirement … Continue reading Kafka strikes again: GDPR requires consent, but you can’t ask for it