Cyber 3-2-1
Cyber 3-2-1
Sam Glynn
Plain English Cyber through 3 articles, 2 numbers and 1 action. Each weekly episode is recorded by Sam Glynn of Code in Motion (www.codeinmotion.ie). If you prefer to read rather than listen, you can subscribe to the Cyber 3-2-1 newsletter at https://www.codeinmotion.ie/blog.
Cyber 3-2-1: 4th March 2022
This week: Organisations worry about cyber attacks arising from Russia’s invasion of Ukraine, as the Conti Gang that attacked the HSE last year announces their support of the Russian attack, and then learns that it was not its smartest move.This week’s action: 3-2-1 Backup or 3-2-1 Over.Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220304/.
Mar 4, 2022
5 min
Cyber 3-2-1: 25th February 2022
This week: Ireland’s NCSC issues an advisory, as warnings continue about the elevated threat of cyber attacks due to the ongoing crisis in Ukraine. Also this week, how blind faith in an IT system led to one of the largest miscarriages of justice in the UK, and why the phrase ‘Too big to fail’ may soon be joined by the phrase ‘Too big to understand’.This week’s action: Bí Ullamh: Consider the NCSC advisory’s recommendations.Links to all articles, numbers and actions can be accessed from https://codeinmotion.ie/cyber321-20220225/.
Feb 25, 2022
9 min
Cyber 3-2-1: 18th February 2022
This week: What is SIM Swap Fraud? How to reduce account hacks by 50%? How is GDPR driving demand for EU data centres? And how could the need to report an attack result in better cybersecurity?This week’s action: Check MFA is turned on for all accounts, especially those used by IT.Links to all articles are available from https://www.codeinmotion.ie/blog. 
Feb 18, 2022
8 min
Cyber 3-2-1: 11th February 2022
This week: The Central Bank reminds us that cybersecurity has not gone away. The US Justice Department proves that bitcoin does not necessarily mean anonymous. And a Microsoft study makes me bang my head against a wall. This week’s action: Baseline like it’s 2016.Links to all articles are available from https://www.codeinmotion.ie/blog. 
Feb 11, 2022
6 min
Cyber 3-2-1: 4th February 2022
This week: The National Cyber Security Centre has released a ‘Cyber Vitals Checklist’, just as concerns increase that the current tensions over Ukraine may increase the likelihood of a significant cyber attack on the West.This week’s action:  Double-check your defences.
Feb 4, 2022
8 min
Cyber 3-2-1: 28th January 2022
This week: ComReg has a plan to tackle volume of scam calls to Irish mobile users. Google’s trackers are being investigated in the US, while the Austrian Courts have ruled that Google Analytics contravenes GDPR. And the US Federal Reserve starts a discussion about digital currencies.This week’s action: Don’t answer that call.Links:ComReg investigation: https://www.thejournal.ie/ireland-scam-calls-taskforce-establish-comreg-5664923-Jan2022/US investigation of Google cookies: https://www.independent.ie/business/world/american-states-sue-google-over-deceptive-web-tracking-41274142.htmlFathom Analytics: https://www.usefathom.com US Federal Reserve paper on digital currencies: https://www.federalreserve.gov/publications/money-and-payments-discussion-paper.htm via https://www.ben-evans.com/newsletterSurvey about scam calls: https://www.thejournal.ie/scam-calls-irish-numbers-poll-5490391-Jul2021/NOYB investigations: https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-analytics-illegalMy 'Cybersecurity without Insanity' workshop: https://www.codeinmotion.ie/workshop
Jan 28, 2022
9 min
Cyber 3-2-1: 21st January 2022
This week: Could simulated phishing tests really make staff more likely to be fooled by a phishing email in the future? What the Russians have done to one of the world’s most successful ransomware gangs? What has ransomware and cryptocurrency got to do with North Korea? And what the hell is the metaverse anyway? This week's action: Review your approach to phishing test simulations.  Links:ETH Zurich's phishing test simulation study: https://arxiv.org/pdf/2112.07498.pdf, mentioned at https://www.bleepingcomputer.com/news/security/large-scale-phishing-study-shows-who-bites-the-bait-more-often/ . Russia's FSB raids on the REvil ransomware gang: https://therecord.media/fsb-raids-revil-ransomware-gang-members/ What is the metaverse, blockchain, etc? https://www.upi.com/Voices/2022/01/14/metaverse-cryptocurrency-blockchain/7591642169034/ via Ron Immick’s Mind Candy Newsletter (https://www.linkedin.com/pulse/mind-candy-15-january-2022-ron-immink )  North Korean cyber criminals stole $400m in 2019: : https://cointelegraph.com/news/north-korean-hackers-stole-400m-in-2021-mostly-eth-chainalysis via Crypto Curry Club’s Crypto Courier (https://www.cryptocurryclub.com/subscribe)   
Jan 21, 2022
11 min
Cyber 3-2-1: 14th January 2022
This week: How the bad guys get a hold of your password, why the US is so concerned about Huawei equipment, and why do large organisations have a CIO AND a CISO? This week's action: Double-check your two-factor authentication. Links:Passwords: https://www.welivesecurity.com/2022/01/05/5-ways-hackers-steal-passwords-how-stop-them/Huawei:  https://www.bloomberg.com/news/articles/2021-12-16/chinese-spies-accused-of-using-huawei-in-secret-australian-telecom-hackCIO vs CISO: https://www.darkreading.com/careers-and-people/why-cios-should-be-reporting-to-cisos  Credential stuffing statistics: https://www.helpnetsecurity.com/2021/05/20/financial-services-credential-stuffing/ 
Jan 14, 2022
4 min
Cyber 3-2-1: 7th January 2022
This week: The 4 tech trends that we will be reading about in 2022, how to speak to the Board about cyber, and how law firms are getting on with cybersecurity. This week’s action: Keep it simple.
Jan 7, 2022
7 min