Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Sunday, December 2, 2012

Australian Federal Police Shut Down Romanian Cybercrime Ring

Australian Federal Police flag


The Australian Federal Police announced on November 29th that it had charged seven people in Romania for "the largest credit card data theft in Australia's history." According to the release, the investigation began in June 2011 based upon a referral from an Australian financial institution, and ultimately involved "numerous international law enforcement partners" including Romanian authorities.

The scope of the data theft is substantial: more than 500,000 credit cards were potentially accessible, with approximately 30,000 being used for "fraudulent transactions amounting to more than $30 million" Australian dollars. The cost of the fraud was apparently not borne by Australian consumers; instead, as in the United States, the issuing banks reimbursed the cardholders for the fraudulent transactions, which were performed throughout the world, including in Europe and the United States.

The case highlights the borderless nature of the Internet and the resulting challenges for law enforcement officials, as well as the significant financial exposure by companies and consumers for international (and local) data breaches and theft.

(Via @mukimu on ZDNet)

Friday, November 30, 2012

Risk Highlight: Syrian Government Turns Off Internet

In the latest salvo between the Syrian government and opposition forces, the government has reportedly used its control over Syria's telecommunications infrastructure to completely cut off the nation's Internet access. (The shut off can be seen in Renesys' Internet traffic graph for Syria, showing the complete cessation of all globally reachable Syrian networks between 10:20 and 10:30 UTC on November 29th:

Renesys Internet Traffic Graph for Syria

In response, other nations and companies have stepped in to try to provide at least limited connectivity to Syrians. Google has reactivated its Speak2Tweet service, although the limited telephone service in Syria may reduce its usefulness, and the U.S. State Department announced that it had previously provided 2,000 communications kits, with computers, telephones and cameras, that are "designed to be independent from and able to circumvent the Syrian domestic network precisely for the reason of keeping them safe, keeping them secure from regime tampering, regime listening, regime interruption."

Beyond the clear local and geopolitical aspects, this latest governmental cutoff of Internet access, as with the outages caused by recent storms in the United States, highlights that the telecommunications infrastructure on which businesses depend is largely out of their control. Effective risk management, involving backup systems, contracts, insurance and other means, must take that reality (and its potential implications) into account.

Friday, November 23, 2012

ABA Adopts New Cybersecurity Policy

The Board of Governors of the American Bar Association ("ABA"), the U.S.' largest legal professional organization, has recently adopted a cybersecurity policy recommended by the association's Cybersecurity Legal Task Force. The ABA hopes that its new effort will guide "the executive and legislative branches" of the government in "making policy determinations for improving cybersecurity for the U.S. public and private sectors."

The ABA's policy consists of five principles:
  • Principle 1: Public–private frameworks are essential to successfully protect U.S. assets, infrastructure, and economic interests from cybersecurity attacks.
  • Principle 2: Robust information sharing and collaboration between government agencies and private industry are necessary to manage global cyber risks.
  • Principle 3: Legal and policy environments must be modernized to stay ahead of or, at a minimum, keep pace with technological advancements.
  • Principle 4: Privacy and civil liberties must remain a priority when developing cybersecurity law and policy.
  • Principle 5: Training, education, and workforce development of government and corporate senior leadership, technical operators, and lawyers require adequate investment and resourcing in cybersecurity to be successful.
Beyond their stated goal of governmental guidance, the ABA's principles also form a useful roadmap for every organization, public and private, considering and implementing cybersecurity efforts. Further, even if an organization is not itself managing network security (for example, if it outsources its IT functions), the new guidelines will assist it in understanding and specifying the level of service it receives from the entity that is responsible for cybersecurity.

The new policy is one of many recent initiatives by the ABA seeking to raise both the awareness and diligence of attorneys and lawmakers about technology's impact on law and legal ethics. While the ABA has no formal enforcement authority, its recommendations can be very influential on state and federal governments as well as courts.