Showing posts with label talktalk. Show all posts
Showing posts with label talktalk. Show all posts

Thursday, 5 November 2015

Have TalkTalk breached the Data Protection Act ? Certainly a possibility..........

With admirable gusto TalkTalk have answered the above question on their own website by saying "No, this is a criminal attack. We have notified the ICO and we will work closely with them over the coming weeks and months".

There we are - no need for any type of judicial system we can all simply decide for ourselves if we have complied with legislation.

In the real world (and given the sanctions from the ICO that TalkTalk has received previously) it is not likely to be as simple as that.

Principle 7 of the Data Protection Act states that "Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."

If reports are true that the attack on TalkTalk was based on SQL injection then, given that Input Validation methods will prevent this, a company the size of TalkTalk would not appear to have taken appropriate measures.

No doubt a commercial decision was taken somewhere within TalkTalk that the cost of defending against an SQL type attack was not justified and that the risk was acceptable.

The problem perhaps is that TalkTalk were trusted to keep customer data safe and had they asked the customer base to decide between staff bonuses or slightly better protection against having all their data stolen the decision would probably have been the latter.

Until we know the nature of the attack and whether appropriate measures had been taken to prevent it it is too early say if a breach has occurred.


Tuesday, 27 October 2015

Talk Talk gets the Tyson treatment

As Mike Tyson once memorably pointed out "Everybody has a plan until they get hit. Then, like a rat, they stop in fear and freeze"

Common sense suggests that Talk Talk as one of the UK's major ISP's would have a good sense of the risks online poses. In fact, in a truth is stranger than fiction moment, Talk Talk Business offer security related services. which really does suggest all is not right with Talk Talk.

The news therefore that a 15 year old boy in Ireland was arrested for suspected offences under the Computer Misuse Act relating to Talk Talk and subsequently bailed until November is a mixed blessing for Dido Harding and her team of cyber security experts.

On one hand it is good news if the attack is now over as the news cycle will roll on and other matters will come to the forefront. On the other hand if this is the work of a 15 year old acting alone (and probably using easily available / free brute force type cyber weapons) it does suggest that the Talk Talk digital front door was not just unlocked but off its hinges.

In fairness when Richard Ledgett, Deputy Director of the NSA comments on the Today programme "If you are connected to the internet you are vulnerable" he does frame the problem in an honest way.

The online attack surface for Talk Talk is huge with multiple points of potential vulnerability. Given that information security is such a broad church with multiple standards (ISO, SANS, NIST, OWASP, Crest, IASME, Cyber Essentials etc) populated by a mix of ex law enforcement, IT people , self categorised "Black Ops" and others it is understandable that a busy CEO gets caught out by some of the flagrant rubbish that gets bandied about. My personal favourite is that all cyber crime is carried out by ruthless gangs of organised criminals. I am sure this exists - but perhaps mainly to add glamour to the job of dealing with it.

Realistically companies are going to need to allocate increased budgets to online security and try to ensure that those budgets are managed by people with a genuine understanding of the new ecosystem to avoid being made to look foolish (and losing 10% of their share price) by a teenager with a broadband connection and £250 laptop (and maybe a white cat ?).