technology security information digital privacy personal data device – DiTech Media https://ditech.media DiTech Media Thu, 29 Apr 2021 13:24:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.7 https://ditech.media/wp-content/uploads/2019/11/favicon.png technology security information digital privacy personal data device – DiTech Media https://ditech.media 32 32 From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/ https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/#respond Thu, 29 Apr 2021 11:09:52 +0000 https://ditech.media/?p=8742 Sophisticated security software is no longer reserved for just large enterprises. Today’s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims. Business leaders often understand the impact the right security measures have on consumer trust and brand health but are …

The post From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals appeared first on DiTech Media.

]]>
Sophisticated security software is no longer reserved for just large enterprises. Today’s cyber attackers are highly skilled and have a growing number of resources available to aid their crusades, making businesses of all sizes potential victims.

Business leaders often understand the impact the right security measures have on consumer trust and brand health but are often uncertain about where to begin. Here are three fundamental web security tips all businesses should put in place to safeguard their websites this year.

Nailing the basics

The most common web security question this year is: ‘What’s my likelihood of getting breached?’ Websites are hacked typically when they’re running vulnerable plugins that aren’t patched.

Despite the all-too-common myth of WordPress Core as a point of vulnerability, it’s the third-party plugin vulnerabilities that represent 55.9% of the known entry points for attacks. However, this only represents half of the equation – the other half is proper management of WordPress accounts, especially through using a Multi-Factor Authentication (MFA) plugin.

The solution is simple: avoid running any more plugins than you need to and ensure the ones you do use have a good history of updates after published vulnerabilities. To tackle the burden of keeping plugins up to date and the risk of mission-critical sites breaking, machine learning and visual testing tools can now even automate plugin updates on a nightly or weekly basis without causing unintended consequences that could result in downtime or lost traffic. Make sure to limit admin access to “must-have” users and make sure they are using MFA.

Bringing the right skills onboard

The shortage of cybersecurity skills is a global issue and Australia is no exception. AustCyber predicts by 2026, the nation will face a skills shortage of 18,000 security experts, which means organizations will not only struggle to hire internal security leaders but also to source external help.

To ensure organizations have the right team in place, leaders should start mapping out the risk profile unique to their business. Identify employees who are experts in WordPress and eCommerce and consider how your industry poses particular challenges, such as websites in the healthcare sector, which have undoubtedly experienced different kinds of traffic surges this past year. For those weighing between hiring and training more in-house staff or bringing on a vendor, revisit the basics of vendor management and how you’re drawing the lines of responsibility, depending on who fits where in your security puzzle. If you’re working with a partner, they will be required to make those investments into skills and technology on your behalf.

Prepping for peaks

Seasonal shopping periods like Valentine’s Day, Christmas, Black Friday, and end of season sales pose a tricky challenge for retailers and eCommerce platforms. Website managers often scramble to meet a high volume of revenue-driving activity on their site while at the same time facing increasing numbers of cyberattacks such as distributed-denial-of-service (DDOS) attacks, which doubled every quarter in 2020. During these lucrative periods for cybercriminals, the Australian Cyber Security Centre regularly updates its guidance for online shoppers

Load testing, which is performance testing that simulates real-world loads on software, applications, or websites, can help answer the question of ‘how many people can visit my site at once?’. Proper load testing can help site managers assess things like scaling capabilities, lifecycle hooks, and susceptibility to DDOS attacks due to high load, automatic code deployment, health checks, and target tracking. Without proper planning and action, retailers are at an increased risk of successful DDOS attacks that lead to a significant revenue loss.

This year, it’s critical that the desire to cash in on the shopping season doesn’t come at the cost of security. Companies need to have basic web security measures in place so that while WordPress Core may be secure, they’re giving the right attention to the plugins they use and are securely managing their WordPress users. They also need to strike the right balance between people, process, es and technology to ensure they have the right skills and staff in place. Finally, they need to plan ahead for key consumer moments and seasonal periods, looking not just for visitor traffic spikes but for different kinds of cyberattacks. The road to recovery in 2021 won’t be easy, but with these steps it’ll be a much smoother ride.

The post From ineffective to impassable: The fundamentals of safeguarding your online platform from cyber criminals appeared first on DiTech Media.

]]>
https://ditech.media/news/from-ineffective-to-impassable-the-fundamentals-of-safeguarding-your-online-platform-from-cyber-criminals/feed/ 0
To be applied… New apps, new laws. https://ditech.media/news/digital-defence/to-be-applied/ https://ditech.media/news/digital-defence/to-be-applied/#respond Mon, 01 Jun 2020 09:07:36 +0000 https://ditech.media/?p=4902 Monitoring or stalking? There are countries where an application for tracking people with COVID-19 has been launched, and the list of such countries keeps growing. Do governments learn something new about their citizens? Probably not, as they could know their location and communication details before. But now it became even easier for them. Government always …

The post To be applied… New apps, new laws. appeared first on DiTech Media.

]]>
Monitoring or stalking?

There are countries where an application for tracking people with COVID-19 has been launched, and the list of such countries keeps growing. Do governments learn something new about their citizens? Probably not, as they could know their location and communication details before. But now it became even easier for them.

Government always collects information (Taxpayer Identification Number, registration, insurance number, etc.). Private companies own much more detailed information, and government often tries to access it imposing various rules.

For example, Apple and Google integrate their technologies Contact Tracing API to track contacts of those who caught the illness and there is no doubt that this information will be turning more and more interesting for some. The technology modifies iOS and Android. Considering that the majority of devices are based on these systems, tracking will cover the whole world.

The benefit is obvious – epidemiologists will receive an instrument for epidemic location. But risks are apparent. Besides epidemiologists, who else could make use of the data collected by the system? Are there any vulnerabilities in the technology through which it can be hacked? Would the companies keep the backdoor open for some of those willing to access the information?

There are many scenarios of how the misuse of such data can harm people. Although tech giants deny spying purpose and functions in the protocol, the code is not an open-source one which renders specialists full of skepticism.

The principle that companies apply was generated about 10 years ago, but these technologies couldn’t be implemented when the time was serene. But today many initiatives are given the green light. “Never let a good crisis go to waste,” said Churchill.

New privacy limits

All the government practices can be roughly reduced to two approaches. The first one is when countries try to hamper the development of technologies which threaten people’s privacy. The second one is quite the opposite – when a state is against the technologies which increase privacy protection. Usually countries discuss the practicability of each approach, so the implementation of both is negotiable in any state.

There are reasons for these approaches. “A good citizen has nothing to hide,” says any country. USA have been developing the EARN IT Act which might forbid end-to-end encryption within the borders.

Society reacts in different ways. Some states put CCTV everywhere and everyone is completely fine with it. According to Pew Research Center, U.S. citizens are almost equally divided – one part, 52%, supported the idea of tracking people who caught the virus, and another part, 48%, appeared to be against such a monitoring.

Will the control be loosened after the pandemic? Or will we face a global digital surveillance covering each and every one? It will depend on the already established culture and patterns of various countries. But the measures can’t and won’t be lifted or forgotten because people’s tolerance tends to grow back to the level required for maintaining an habitual life.

Dedigitisation, which became central for some futurologists, will not spread across all spheres and industries. Countries don’t want to lose the opportunity to enforce through technology.

The quarantine will be cancelled one day, and the world will have to think where to put the limits of individual privacy. Nearly every constitution mentions the sanctity of a private life. Although, at the time these laws were written, the technologies didn’t impress so much. Moreover, many consider digitisation as something which is not clear enough making the threat ensuing from it blurred as well, thus people are not very demanding when it comes to protecting their opinion. That is why new rules and standards should be created. We need to step out of the quarantine knowing exactly the limits of our personal freedom.

The post To be applied… New apps, new laws. appeared first on DiTech Media.

]]>
https://ditech.media/news/digital-defence/to-be-applied/feed/ 0