Jump to content

Recommended Posts

Posted

https://www.bbc.co.uk/news/education-47805451

 

 

"A test of UK university defences against cyber-attacks found that in every case hackers were able to obtain "high-value" data within two hours."

 

I wonder if primary/secondary schools would fair any better when it comes to penetration testing of IT networks.

Posted
Unsurprisingly, spear phishing was responsible for a large proportion of the attacks. You can have the best defenses in the world, but the biggest risk is always the squishies, they're a lot harder to update and improve!
  • Thanks 1
Posted
I can’t help wondering if some of the blue/green button activity that’s being discussed in the Phishing thread by @FishCustard, etc was started by these “ethical hackers”

 

At first glance I would say "unlikely", given that it seems those ones are coming from spammers. I doubt JISC would have authorised such a scattergun campaign either.

Posted
"Cyber-defences" sounds like something from a crap 80's SciFi flick. However it should include the squishies instead of just being something people instantly think of as firewalls, AV etc.
Posted
"Cyber-defences" sounds like something from a crap 80's SciFi flick. However it should include the squishies instead of just being something people instantly think of as firewalls, AV etc.

 

Some of it did seem to be targeting O365 logins rather than bitcoin payments though.

Posted
"Cyber-defences" sounds like something from a crap 80's SciFi flick.

 

I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron.

Posted
I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron.

 

This makes a packet flood sound very dangerous! :)

Posted
I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron.

 

There was nothing pixelated in Tron, you've managed to imagine a worse version!

Posted
Not read the details, but speed ought not to be interpreted as ease. What might take the likes of Fancy Bear all of 5 minutes might essentially be impossible for 99.999% of other people. The speed is probably less important than the means.
Posted
Harder problem for universities, can't really limit what programs can run as they're writing programs all the time. Have to go with "assume we've been hacked, limit what a hacker can access", stop escalation, limit access to data to minimum required. Keep personal data on a completely different system
Posted (edited)

I’m on one of the JISC security forums and it’s been the main topic of conversation today;

 

JISC themselves replied to us all on the list.

 

 

Good morning all,

 

With regard to the article in the news today. These reports represent a sensationalised take on a serious policy paper that was unfortunately not linked-to in the BBC article. The paper is a high-level overview of well-known threats to the education sector and has sought to bring together a number of themes already widely reported. The main focus of the paper was that cyber risk is a Board responsibility informed by, but not driven by IT. The press release sought to highlight the importance of training and awareness strategies for all staff, as echoed in the cyber security assessment survey which lists phishing as the number one threat faced by the education and research sectors. The policy paper can be found at https://www.hepi.ac.uk/wp-content/uploads/2019/03/Policy-Note-12-Paper-April-2019-How-safe-is-your-data.pdf

 

Regards

 

If the policy paper was linked to the article it would of cast an entirely different light on the situation ... but hey at least it’s not more talk of the B word [emoji848]

Edited by Asgard
  • Thanks 2
Posted
What are their recommendations as to network security design, assuming you'll always find one person to give away their password, how do you still secure the data/network?
Posted
What are their recommendations as to network security design, assuming you'll always find one person to give away their password, how do you still secure the data/network?

 

Only use OAuth, obviously.

Posted
You can't design around it any differently to any other form of defence; it's going to be entirely around mitigation and ensuring people only have access to what they need. That doesn't help much when you're talking higher end staff with access to everything else, but then that's where MFA comes in, 2nd level encryption of confidential documents etc. For instance although a domain admin will be able to access our head teachers documents, emails etc, HR documents it will be necessary for them to have additional security for those areas; typically file level encryption.
Posted
Only use OAuth, obviously.

 

Goes without saying, having another password database would be terrible, people would just use the same password, now there's twice as much chance of it leaking.

  • 4 weeks later...
Posted

Sadly a very large number of education establishments have been targeted recently that are running office 365 and using limited, or low cost (cough free) AV solutions that have not been sufficient to stop these kinds of next gen attacks. The Main reason this has got through is because of budgets. Many schools have scaled back their security offering and spend on these solutions to try and save on cost which has lead to a greater number of breaches and malware outbreaks from spam and Phishing attacks. Often the case is to justify the cost of migrating to 365 and cloud services the AV firewall and mail filtering solutions have been dropped to sign off these projects leading to these attacks getting through the sites defense.

 

Also with GDPR a lot more schools and Colleges are now having to report the breaches which wasn't being done previously.

Posted

Mail filtering is easy, just convert everything to plain text, universities should be at a scale where they can make their own s/mime certs too.

 

Is paid AV better than free AV?

 

Aren't cloud services supposed to save money?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...