CRIME OF OUR GENERATION – A Look at the TalkTalk Breach
News and information from the Advent IM team.
A review from Advent IM Security Consultant, Chris Cope.
The TalkTalk hack has left another major UK business reeling from a cyber attack and customers angry as, once again, there is a possibility that sensitive information is now in the public domain. The telecommunications company decided to take its own website offline on Wednesday following the presence of unusual traffic, with a ‘Russian Islamist’ hacking group taking responsibility and the Metropolitan Police’s Cyber Crime unit now investigating. Detail on precisely how the attack took place are not yet publicly available, but there are some points that are immediately apparent.
Customer security. The BBC is reporting that personal information and bank account details may have been stored in an unencrypted format and are now available to hacker groups. Some TalkTalk customers have complained about hoax communications already; it is likely that this is just the start. Customers will need to rely on Talk Talk to identify precisely which customers are affected, but in the interim they must monitor their bank accounts closely. Any suspicious activity must be reported to their bank immediately as potential fraud. When the Talk Talk website becomes accessible again, customers should immediately change their passwords, taking care to avoid passwords which are easily guessable.
Undoubtedly this is the crime of our generation as more and more cyber attacks are reported. But organisations should not despair, it is perfectly possible to reduce the risk from cyber attack by following the basic security precautions contained with ISO27001. These can be applied to any organisation, large or small. From what we know of the attack already, there are some specific controls from that standard which become immediately apparent:
As the list of cyber attacks in 2015 grows again, and shows no sign of tailing off any time soon, organisations must look to their own defenses. The threat is varied and very real. Cyber Crime is here to stay, but why make it easy for criminals to succeed? There are steps that can be taken to reduce the risks of compromise and the impact following an incident. Customers are now expecting higher levels of cyber security, if organisations wish to maintain their reputation, they should look to deliver it.