Copy

Regional Cyber Briefing

Tweet
Share
Forward

Current Threats




Island Hopping

Attackers will look to infiltrate target organisations through smaller companies that work with the target. The term refers to a military tactic where smaller entities are captured and leveraged in order to get to an original target.

Island Hopping is effectively a Supply Chain attack. Attackers are banking on the assumption that smaller companies will be easier to compromise, and from there they can take advantage of any shared systems and/or the trust between organisations.

Advice

> Understand the security risks involved with your supply chain
Build a picture of who your suppliers are and what their security looks like. Do you know what needs to be protected and why? 

> Raise awareness of security with your supply chain
Communicate your needs to your suppliers, build it into your contracting processes, and meet your own security responsibilities both as a consumer and supplier. For example, the government backed Cyber Essentials scheme can be an indicator that companies have a commitment to cyber security, and have taken steps to guard themselves against the most common cyber threats. Details about the scheme can be found at https://www.cyberessentials.ncsc.gov.uk/

> Seek continuous improvement of security within your supply chain, and build trust with your suppliers

> Educate and train staff to defend against Phishing attacks
For advice on how to spot and defend against phishing, see the NCSC's guide on this at https://www.ncsc.gov.uk/phishing

The Take Five campaign is a national campaign encouraging people to stop and think about whether a situation is genuine. Visit the website at
https://takefive-stopfraud.org.uk/advice/

> Device security
As a minimum, organisations need to ensure that devices are always fully patched and have anti-malware/anti-virus software in place. This should apply to ALL of your devices, including phones/tablets/printers/routers/internet enabled cameras/IoT devices etc.

> Reporting
If you've been affected by this or any other type of cyber crime, report the details to Action Fraud (0300 123 2040 / www.actionfraud.police.uk). Always keep an eye out for any suspicious follow up activity as well.

Events


Tourism Leaflet Exchange (South Somerset District Council) - Westlands Entertainment Venue, Yeovil, 2nd April

We'll be on hand to promote cyber security at this exhibition for tourism professionals - come along and take advantage of our free advice and resources.
https://www.eventbrite.co.uk/e/the-south-west-regional-cyber-crime-security-event-tickets-56556022586

Lego: The latest tool in your arsenal against Cyber Attack! - Yeovil Innovation Centre, Yeovil, 18th April

Places are going fast at another of our interactive cyber security workshops, this time in Yeovil. Find out more and secure your place at https://www.yeovilchamber.org/events/chamber/cyber-attacks---an-interactive-workshop-to-make-your-business-better-prepared.htm

News

Hackers hijacked ASUS software updates to install backdoors on computers.
The Taiwan-based tech giant ASUS is believed to have pushed the malware to hundreds of thousands of customers through its trusted automatic software update tool . (Read more at
https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers).
Hold the phone! The Threats lurking behind a missed call and other forms of telecom fraud.  TA press release from Europol highlighting cybercriminals exploitation of electronic devices and telecommunications technology. (Read more at https://www.europol.europa.eu/newsroom/news/hold-phone-threats-lurking-behind-missed-call-and-other-forms-of-telecom-fraud).

Useful Links

Supply Chain Security Guidance
A series of 12 principles, designed to help you establish effective control and oversight of your supply chain. See the article at https://www.ncsc.gov.uk/collection/supply-chain-security.
Subscribe to this mailing list
Copyright © 2019 SW Regional Cyber Crime Unit, All rights reserved.


Want to change how you receive these emails?
You can
update your preferences or unsubscribe from this list.

Email Marketing Powered by Mailchimp