cybersecurity – DiTech Media https://ditech.media DiTech Media Thu, 29 Apr 2021 13:24:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.7 https://ditech.media/wp-content/uploads/2019/11/favicon.png cybersecurity – DiTech Media https://ditech.media 32 32 From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/ https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/#respond Thu, 29 Apr 2021 11:09:52 +0000 https://ditech.media/?p=8742 Sophisticated security software is no longer reserved for just large enterprises. Today’s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims. Business leaders often understand the impact the right security measures have on consumer trust and brand health but are …

The post From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals appeared first on DiTech Media.

]]>
Sophisticated security software is no longer reserved for just large enterprises. Today’s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims.

Business leaders often understand the impact the right security measures have on consumer trust and brand health but are often uncertain about where to begin. Here are three fundamental web security tips all businesses should put in place to safeguard their websites this year.

Nailing the basics

The most common web security question this year is: ‘What’s my likelihood of getting breached?’ Websites are hacked typically when they’re running vulnerable plugins that aren’t patched.

Despite the all-too-common myth of WordPress Core as a point of vulnerability, it’s the third-party plugin vulnerabilities that represent 55.9% of the known entry points for attacks. However, this only represents half of the equation – the other half is proper management of WordPress accounts, especially through using a Multi-Factor Authentication (MFA) plugin.

The solution is simple: avoid running any more plugins than you need to and ensure the ones you do use have a good history of updates after published vulnerabilities. To tackle the burden of keeping plugins up to date and the risk of mission-critical sites breaking, machine learning and visual testing tools can now even automate plugin updates on a nightly or weekly basis without causing unintended consequences that could result in downtime or lost traffic. Make sure to limit admin access to “must-have” users and make sure they are using MFA.

Bringing the right skills onboard

The shortage of cybersecurity skills is a global issue and Australia is no exception. AustCyber predicts by 2026, the nation will face a skills shortage of 18,000 security experts, which means organizations will not only struggle to hire internal security leaders but also to source external help.

To ensure organizations have the right team in place, leaders should start mapping out the risk profile unique to their business. Identify employees who are experts in WordPress and eCommerce and consider how your industry poses particular challenges, such as websites in the healthcare sector, which have undoubtedly experienced different kinds of traffic surges this past year. For those weighing between hiring and training more in-house staff or bringing on a vendor, revisit the basics of vendor management and how you’re drawing the lines of responsibility, depending on who fits where in your security puzzle. If you’re working with a partner, they will be required to make those investments into skills and technology on your behalf.

Prepping for peaks

Seasonal shopping periods like Valentine’s Day, Christmas, Black Friday, and end of season sales pose a tricky challenge for retailers and eCommerce platforms. Website managers often scramble to meet a high volume of revenue-driving activity on their site while at the same time facing increasing numbers of cyberattacks such as distributed-denial-of-service (DDOS) attacks, which doubled every quarter in 2020. During these lucrative periods for cybercriminals, the Australian Cyber Security Centre regularly updates its guidance for online shoppers

Load testing, which is performance testing that simulates real-world loads on software, applications, or websites, can help answer the question of ‘how many people can visit my site at once?’. Proper load testing can help site managers assess things like scaling capabilities, lifecycle hooks, and susceptibility to DDOS attacks due to high load, automatic code deployment, health checks, and target tracking. Without proper planning and action, retailers are at an increased risk of successful DDOS attacks that lead to a significant revenue loss.

This year, it’s critical that the desire to cash in on the shopping season doesn’t come at the cost of security. Companies need to have basic web security measures in place so that while WordPress Core may be secure, they’re giving the right attention to the plugins they use and are securely managing their WordPress users. They also need to strike the right balance between people, process, es and technology to ensure they have the right skills and staff in place. Finally, they need to plan ahead for key consumer moments and seasonal periods, looking not just for visitor traffic spikes but for different kinds of cyberattacks. The road to recovery in 2021 won’t be easy, but with these steps it’ll be a much smoother ride.

The post From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals appeared first on DiTech Media.

]]>
https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/feed/ 0
Nassec launches “ReconwithMe”, security tool that detects and report security vulnerabilities https://ditech.media/press/english/nassec-launches-reconwithme-security-tool-that-detects-and-report-security-vulnerabilities-2/ https://ditech.media/press/english/nassec-launches-reconwithme-security-tool-that-detects-and-report-security-vulnerabilities-2/#respond Thu, 10 Sep 2020 13:05:45 +0000 https://ditech.media/?p=7847  Nassec today announced “ReconwithMe”, a new cyber security product. ReconwithMe is a SAAS tool that automatically detects and reports security vulnerabilities present in a software application, drastically decreasing the burden of a penetration testing. “ReconwithMe will help businesses prevent cyber attacks as it automatically detects security vulnerabilities present in a software application. It will also …

The post Nassec launches “ReconwithMe”, security tool that detects and report security vulnerabilities appeared first on DiTech Media.

]]>
 Nassec today announced “ReconwithMe”, a new cyber security product. ReconwithMe is a SAAS tool that automatically detects and reports security vulnerabilities present in a software application, drastically decreasing the burden of a penetration testing.

ReconwithMe will help businesses prevent cyber attacks as it automatically detects security vulnerabilities present in a software application. It will also make the vulnerability management process easier and cost effective,” says Ajay Gautam, Head of Security at Nassec. 

Features and benefits of ReconwithMe include.

  • Find security vulnerabilities 
  • Gather preliminary information for manual testing
  • Inbuilt bug tracker to manage vulnerabilities

ReconwithMe will be available for pre-subscription from September 10, 2020 starting from USD 25 per month. However, the full version will only be available after December 10, 2020. The company has announced to give 50% to the first 100 subscribers. For more information on ReconwithMe, visit reconwithme.com.

Nassec is a cyber security firm dedicated to providing vulnerability management solutions. Nassec has been trusted by industries ranging from fintech to blockchain and SAAS to Ecommerce. With cyber attacks rising rapidly, businesses require cyber security solutions more than ever. Nassec offers tailor-made vulnerability management solutions to help prevent cyber attacks.

The post Nassec launches “ReconwithMe”, security tool that detects and report security vulnerabilities appeared first on DiTech Media.

]]>
https://ditech.media/press/english/nassec-launches-reconwithme-security-tool-that-detects-and-report-security-vulnerabilities-2/feed/ 0
Protecting your company’s bottom line after COVID-19 – 6 power moves for risk managers and directors https://ditech.media/news/cybersecurity/protecting-your-companys-bottom-line-after-covid-19-6-power-moves-for-risk-managers-and-directors/ https://ditech.media/news/cybersecurity/protecting-your-companys-bottom-line-after-covid-19-6-power-moves-for-risk-managers-and-directors/#respond Thu, 02 Jul 2020 10:20:03 +0000 https://ditech.media/?p=5486 Thanks to the global pandemic’s impact on organisations, the ‘unknown unknowns’ have really been hammered home. The ground has shifted beneath everyone’s feet. Risk management was among the top conversations at all levels in forward-thinking businesses before COVID-19; now it’s the only conversation worth having. Overcoming doubt and apprehension in companies is a massive issue, …

The post Protecting your company’s bottom line after COVID-19 – 6 power moves for risk managers and directors appeared first on DiTech Media.

]]>
Thanks to the global pandemic’s impact on organisations, the ‘unknown unknowns’ have really been hammered home. The ground has shifted beneath everyone’s feet. Risk management was among the top conversations at all levels in forward-thinking businesses before COVID-19; now it’s the only conversation worth having.

Overcoming doubt and apprehension in companies is a massive issue, so it’s essential that company directors and departmental managers are on board. Their ‘buy-in’ – figuratively and literally – is crucial and in a world where demonstrating accountability matters.

Here are six things, as a risk manager or director, you should be doing right now to best protect your company and its bottom line in a post-COVID-19 world.

1. Flex your communication skills

The direction you are taking and the decisions you make are important. The organisation (and everyone in it) needs you, so talk to your people.

Ask them the right questions: what are their environmental concerns? Are there any social issues that could impact the organisation? What political issues do they feel might impact the company in the coming weeks or months?

Communicate, listen, then act. Let staff know that their voices have really been heard, and that you have taken action based on their insights.

2. Become a storyteller

If you want the board and other executives to fully resource you, you must learn to appropriately frame the message. Find evidence and stories of other organisations that either fell down or rose above the rest – depending on their approach to risk – and contextualise them for your business.

Ask them to take the thought experiment with you: take one risk or risk domain and playout for them what would happen if that risk materialized, and how it would impact the company.

Explain to the board that your company’s success rests on its ability to identify, assess, and consider risk in all aspects of decision making. The key element to this is your skill in acting as a futurist for the company.

3. Know your tech

With cybersecurity now taking over as the leading global business risk, risk managers worldwide have to race to stay ahead of the trends. A serious cyberattack can shut your business down in seconds, so it’s paramount that you have a solid understanding of your digital universe, including internal – people, processes, and technology – as well as all external suppliers and customer touchpoints.

The next tech step is to do your research on software-as-a-service (SaaS) products that can help to leverage your risk approach and also integrate with AI to automate risk identification, assessment and mitigation.

4. Enlist the whole team

There is a key element of current risk review processes that you should lift and insert into your team. The risk owner.

Nominate someone from each department to continuously ‘own’ the risk perspective within their unit. They can monitor risks, report on them, and – crucially – act on them. They look outside and talk with partner organisations and third-party vendors to increase the efficiency of that communication, effectively plugging this straight into your risk pipeline.

5. Invest, educate, and evolve

Don’t just analyze insurable risks, then go ahead and purchase insurance and wipe your hands of the process.

Continue to consider organisational risks and connect your risk management processes to the company’s strategy as a whole. What can you foresee that might have a direct impact on your board’s ability to govern properly?

Check out every company you can find in the risk, compliance and cybersecurity space and subscribe to their newsfeeds and social channels. You may just find a nugget of future tech or opinion that will give you the edge!

Keep investing in your company’s safety and future – its livelihood depends on it.

6. Keep one eye on the horizon

There’s no silver bullet solution for the ‘unknown unknowns’, but the right mindset is as good a place to start as any. The question is, ‘How can we continuously be glancing over the shoulder of our organisation’s present moment and feel confident?’

How you frame your risk attitude and information security largely determines how you will experience it. Keep reading. Stay informed. Subscribe to other knowledgeable sources, and regularly set aside time to research emerging risks. Keep a watchful eye on politics, litigation, product developments and launches, and societal changes to best inform your company’s processes.

To get all your risk profile ‘ducks in a row’, there are plenty of SaaS platforms and cloud tools to help you get there, so make sure you do your research. Be sure to subscribe to one which provides a governance, risk and compliance solution, and has innovation and content ‘baked in’ to ratchet up your capability. It’ll give you a great platform and a much broader multi-domain approach to risk.

The post Protecting your company’s bottom line after COVID-19 – 6 power moves for risk managers and directors appeared first on DiTech Media.

]]>
https://ditech.media/news/cybersecurity/protecting-your-companys-bottom-line-after-covid-19-6-power-moves-for-risk-managers-and-directors/feed/ 0
The missing ingredient: Risk management for 2020 and beyond https://ditech.media/news/cybersecurity/the-missing-ingredient-risk-management-for-2020-and-beyond/ https://ditech.media/news/cybersecurity/the-missing-ingredient-risk-management-for-2020-and-beyond/#respond Thu, 02 Jul 2020 10:16:23 +0000 https://ditech.media/?p=5483 It’s leadership. That’s it! Alright, fine, I’ll expand. Most traditional risk managers will instinctively counsel your organization to be moving into the 2020s as best practice would have always had it be done. While that might have been sound advice in another era, in today’s lightning-paced global digital landscape, conservative intel like this neglects one …

The post The missing ingredient: Risk management for 2020 and beyond appeared first on DiTech Media.

]]>
It’s leadership. That’s it! Alright, fine, I’ll expand.

Most traditional risk managers will instinctively counsel your organization to be moving into the 2020s as best practice would have always had it be done. While that might have been sound advice in another era, in today’s lightning-paced global digital landscape, conservative intel like this neglects one crucial element.

Leadership.

“He who thinks he leads but has no followers is only taking a walk,” American leadership expert, John C Maxwell, famously claimed.

COVID-19 is a massive wake-up call for every business. Globally, the traditional hospitality, leisure, tourism, sports, and retail industries will never be as we once knew them.

How your organization handles the crisis now will not only determine whether or not this moment in time will feature positively in your future risk presentations; it might actually determine whether or not your business survives it at all.

Strong, insightful, and consistent leadership from organizations (no matter the size), from the top-down and the inside out, will be the keys to survival, let alone success. Clarity and cohesion, ingredients that have been missing from the risk assessment process all along, are more important than ever.

Within the broad bandwidth of risk leadership, from the chairperson to department heads, it’s incredible to think that there’s been a key ingredient missing this whole time. Dialogue.

The current modus operandi is not your fault! The traditionally disparate areas within an organization of Governance, Risk, and Compliance Management (GRC), Information Security Management Systems (ISMS), and Cybersecurity haven’t exactly been conducive to risk management progress.

Here, we define three key leadership areas as clearly lacking in risk assessment and management today, and how to improve them.

1. Where’s the humanity? Find it, and bring it back!

Good old-fashioned communication is probably the most important aspect of risk management. Inter and intra-department dialogue are essential, as is finding some measure of consensus about what’s important (and what’s not), and how to move forward.

Every person in your organisation will have both individual and shared experiences of not only the company’s processes, but also the world around them. Our diversity as individuals creates perspectives that are critical to the GRC process. As such, it’s important we spend valuable time with each other (albeit via videoconferencing at the moment), rather than merely collecting data and generating inputs.

A series of numbers on a chart can tell you only so much. Data doesn’t contain nuance or humanity. It’s not subject to whims or emotions and doesn’t carry with it lifetimes of insight gained from experience.

Our job as leaders should be to share multiple perspectives and from those, arrive at some form of agreement about decision-making processes.

2. Teamwork makes the dream work

Secondly, stemming from that first lesson of ‘the human element’, it’s critical for leaders to get input from their teams, and ensure that it’s from as broad a spectrum as possible. Why? It’s the only way to allow for individual and collective perspectives on the likelihood and impact of risks to your business.

Over the last couple of years, the yardstick for accountability means you need to get input from all levels in the organization, which – traditionally – has been a slow and cumbersome process. It’s the technology that has enabled us to communicate as widely, broadly, and as inexpensively as we can right now.

Remote working was dreamless than a generation ago, and modern communications tools have allowed us to streamline the analog processes of gathering information and gaining consensus. Today anywhere from ten to even thousands of people across your business can be connected. Make the most of it.

3. Risk libraries – broadening horizons

Finally, with an increasing breadth of risks to manage, using expertly defined risk libraries is critical to identifying the ‘unknown unknowns’. There are very few people, if any, who have anywhere near enough exposure or understanding of risks across all areas of business and life. That’s where consultants have typically come in to share their pearls of wisdom and insights.

Surely there’s a better way to approach this deficiency, and use technology more effectively? Consultants are also limited by what they know. They’re human, and all humans are limited in the correlations and connections they’re able to make between abstract things.

Technology can help, providing companies with access to hundreds – even thousands – of potential risks, structured into risk libraries, and curated on an ongoing basis.

Good leaders listen to the people who work with, and for, them. How do you achieve that, especially in an environment which in which your workforce is decentralized and/or fragmented? Technology is the answer. Embracing it wholeheartedly is the way forward, and using it to collate as much information as is available will help reinforce the dam before the next disruptive flood takes us all by surprise.

You can’t predict the future, but you can prepare yourself by equipping your organization with the best tools to confront it once it arrives.

The post The missing ingredient: Risk management for 2020 and beyond appeared first on DiTech Media.

]]>
https://ditech.media/news/cybersecurity/the-missing-ingredient-risk-management-for-2020-and-beyond/feed/ 0