Oops! Something went wrong while submitting the form.
Subscribe to our newsletter
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Being responsible - Helping local businesses stay secure
Covid-19 has been referred to as the 'economic tsunami' hitting businesses causing a global recession. Cybersecurity is usually seen as an afterthought or a luxury, and as not having a direct benefit to the business profits.
Covid-19 has been referred to as the 'economic tsunami' hitting businesses causing a global recession. The global economy is shrinking, which is a fact. We are already experiencing a significant contraction in economic activity that will likely last through the first half of the year. When economic times are tough, the first step businesses usually take is to reconsider their budget. This often includes reducing its cybersecurity budgets in an attempt to reduce costs and minimize business losses. Cybersecurity is usually seen as an afterthought or a luxury, and as not having a direct benefit to the business profits.
As a Cyber consulting company, we are witnessing - on social media channels and news - an increased amount of malicious cyber attacks. Unfortunately, many threat actors have started to abuse the panic and discomfort of the pandemic to launch specially crafted malware and phishing attacks worldwide. We have already volunteered our time to help the NHS and public sector with our time and expertise should they need us any time.
Our team is staying vigilant helping local businesses stay secure online. One classic case happened with our co-founder, Arjun Pednekar. This is while booking an online parent-teacher meeting using a portal link emailed to him from his son's school.
"I happen to do my appointment booking online at this portal using my details including DOB and my son's details as well. I couldn't stop myself from noticing how the application was designed. A quick look into the underlying proxy revealed that they could be vulnerable to direct object reference", Arjun said. Following this, and being the responsible parent that he is, a single-digit tweak in his browser resulted in obtaining personal details of other users within the portal.
Arjun says, "I had to stop using this portal, knowing they were vulnerable to something which should be picked if they had conducted a regular penetration testing using certified consultants". He proceeded to immediately notify the software developers based in the UK. The customer care was emailed the details of the vulnerabilities and potential other disclosure within the underlying API that could cause gaining full control of other registered user accounts or launching password guessing against the high privilege user accounts.
Within 24hours the developers reached out to us, notifying that they have:
Conducted their application assessment last year but this issue seems to have been left undetected
Working on the fix to minimize the disclosure
Most importantly, ensuring no unauthorized access to other users personal details were possible
This trivial vulnerability could have been exploited by a malicious threat actor for malicious gains. "Knowing I did my bit to help a business stay secure gives me a decent sleep at night", says Arjun.
We are here to help with our experience in testing a wide range of applications over several years. Web application relies on several technologies that need to be tested as part of any methodology. This includes:
Cyber Security Tips - Remote Working Advice For Individuals and Businesses
Defendza, a cyber security firm specialising in cyber security consulting and training matters, offers cyber security tips for remote workers and businesses. This includes preparing for remote working and protecting from cyberattacks when working from home during COVID-19.
Cyber Security Guidance for Online Retailers (SMEs)
Defendza's checklist-based guidance online retailers especially SMEs to provide with an overview of both basic and advanced cybersecurity measures they should implement. Overall, the guide will enable organizations to improve their cybersecurity posture, reduce security risks, avoid vulnerabilities, and enhance their resilience.
Defendza, a cyber security firm specialising in cyber security consulting and training matters, offers an insight into PSD2 & Open Banking cyber security considerations for third party adopters. This article also explains about the new "The Regulatory Technical Standards" from European Payment Council.
Defendza, a cyber security firm specialising in cyber security consulting and managed services, offers a five-point quick help cheat sheet that would help SME’s tackle the most common cyber-attacks.
Defendza, a cyber security firm specialising in cyber security consulting and managed services, offers a six-point quick help that would help SME’s tackle the most common cyber-attacks.