News, info & events

28 Nov
Six ways to strengthen your organisation’s cybersecurity culture

Cybersecurity awareness is the first, and most important, line of defence against cyber threats. Whilst it is important to focus on the physical aspects of cybersecurity, such as hardware and software, it is also important to engage your employees in order to create, and strengthen, your organisation’s cybersecurity culture.

EnterpriseRed have collated six steps to help start strengthening your organisation’s cybersecurity culture:

27 Nov
Webinar: GDPR Myths and Responsibilities

The 25th May has come and gone but the need to be compliant with GDPR, and the myths and complexity surrounding it, still remains.

EnterpriseRed, in partnership with CySure, are holding a webinar looking at GDPR and the challenges it poses to businesses. Becoming compliant need not be complicated, or expensive, and this webinar will provide insight into the myths and responsibilities of GDPR.

The webinar will be on December 11th 2018 at 4pm and will run for 45 minutes. The following areas will be covered:

Background on the number of data breaches reported to the UK’s Information Commissioner’s Office and why they happened

How to effectively utilise your employees as a first line of defence

The simple and effective measures that can be implemented to provide security continuity as staff and contractors change

How to identify a skills gap and when to hire consultants.

If you are interested in this webinar, please register here.

21 Nov
The Cybersecurity implications of driverless cars

As the age of the fully autonomous vehicle draws closer with developing technology, cybersecurity is going to be a key consideration for this new era. 

driverless cars

With an increase in the frequency and severity of cyber-attacks affecting large organisations such as Equifax and British Airways, the difficulty to defend against cybercrime in an increasingly digital world is evident and begs the question; how will driverless cars address this issue?

The concept of the driverless car is one which echoes convenience and it seems inevitable, with the rate in which technology is developing, that these will soon be a reality. Before they have been implemented, however, there is the issue that they could likely be seen as a target for hackers, especially as they require millions of lines of code. This addition to the Internet of Things arena poses a significant threat to cybersecurity as the number of connections will inevitably rise as fully autonomous vehicles will need to communicate with each other and objects around them such as traffic lights and junctions.

The biggest cyber concern surrounding fully autonomous vehicles is the risk of third parties being able to hack into the system and control the car, and its functions, remotely. In 2015, two hackers conducted an experiment on a Jeep Cherokee in which they proved they could hack into the car’s entertainment system to take over the car’s dashboard, steering, brakes and transmission functions.

Alongside the risk of a driverless car being hacked, is the risk that hackers could retrieve an individual’s personal information if they gained access to the car’s system. The biometric information that would be used to lock and unlock the vehicle, such as facial recognition, could be used for other applications such as online banking or even connected devices in the home that use this technology.

Cybersecurity should be a priority for any organisation producing, acquiring or working with fully autonomous vehicles. The UK government has introduced the ‘Autonomous and Electric Vehicles’ Bill, and guidelines for ‘The Key Principles of Cyber Security for Connected and Automated Vehicles’ which is an excellent start. However, the organisations in which consumers will be putting their trust need to prove they take cybersecurity seriously and have robust protections in place.

If you have any questions regarding cybersecurity please don’t hesitate to contact us.

15 Nov
EnterpriseRed’s exciting new partnership with CySure!
PRESS RELEASE – London, UK, November 2018

CySure appoints cyber specialists EnterpriseRed as a new security and compliance reseller partner in the UK

Collaborative partnership to help organisations improve compliance and cybersecurity awareness amongst workforce

Cybersecurity specialist CySure Ltd has appointed EnterpriseRed as a specialist reseller partner in the UK further extending Cysure’s international network of partners across the Republic of Ireland, South Africa, the USA and the UK. The Berkshire-based cybersecurity experts will resell CySure’s information security management system, Virtual Online Security Officer (VOSO).

After conducting a review of their solution portfolio, EnterpriseRed identified a gap for an information security management system to assist with compliance. CySure’s VOSO solution was chosen as it enables customers to manage and demonstrate their compliance with the General Data Protection Regulation (GDPR) simply and effectively. VOSO incorporates both US NIST and UK CE cybersecurity standards to guide enterprises through the compliance process ensuring the right steps are taken to keep data secure and organisations compliant.

Ian Kennedy-Compston, CEO of EnterpriseRed said, “There is a lot of misinformation about GDPR and the cost and complexity of becoming compliant. CySure’s solution cuts through the fog, with clear guidance and support for organisations throughout the process. We see VOSO as adding significant value to the GDPR process spreadsheet completion and envisage this product will significantly assist our customers going forward.”

CySure has been accepted onto the UK Government’s G-Cloud 10 digital marketplace.  As part of that process the security component of the GDPR was mapped into VOSO, providing an easy to follow, staged approach to GDPR along with all the policies and training videos necessary to complete the compliance process.

Read More “EnterpriseRed’s exciting new partnership with CySure!”

14 Nov
Stay one step ahead of hackers with DarkBeam

Are you wondering how the DarkBeam platform can be used as part of your organisation’s regular cyber health check in order to prevent a cyber-attack? Read this case study of an organisation who left it too late. 

DarkBeam missed opportunity
A missed opportunity

Imagine a situation where one of your employees is working on a laptop, or PC, and as they’re doing so there is an unknown person monitoring their every move; recording their every mouse click, every website they visit, and more importantly every keystroke they make. This includes their usernames and passwords to your organisation’s systems and databases.

The unknown person watching them type, studying their working practices, and getting to know your organisation’s tools, methods and procedures is not part of your management team. They are a hostile attacker who a few weeks prior sent a well crafted spear phishing email to your employee encouraging them to click on a link. One single click on that link has allowed a bad actor into your network to embed a keylogger virus. The attacker now has all the access they need, and on a large scale are harvesting your confidential material, your client database – including logins and passwords – and have free rein to disrupt your service. It may be months before you even know you’ve had an intrusion, by which time it’s too late. The damage is done, your reputation has taken a hit, and you are of course considering the financial penalties under GDPR.

For the attacker to successfully have mounted this attack they started by conducting hostile reconnaissance against your organisation. They surveyed your organisation’s security posture, examined your organisation’s digital footprint, and selected their target. They then registered a domain that looks very similar to your organisation’s domain, possibly with just one letter wrong or missing, or perhaps more ominously only created a mail server that looks remarkably similar to your domain. The attacker has then crafted a bespoke email to your employee having found their email address exposed online, and with the research they have conducted against you they have peppered their email with pertinent facts that at first glance makes the email seem genuine. Their email compels your employee to urgently click on the link, and that’s all it took. One click and the attached malicious software was active.

Read More “Stay one step ahead of hackers with DarkBeam”

Sidebar: