Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Is your cyber education program up to scratch?

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Is your cyber education program up to scratch?


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: cio.com

The cyber-attacks on Optus and Medibank recently have brought into focus the devastating impact breaches can have on the reputation of any organisation.

The Optus attack, which was the largest and most high profile in Australian history, has left almost 10 million customers understandably livid that their personal information was stolen.

It is believed that the Medibank attack began when an individual with high-level access to the health insurerโ€™s systems had their credentials stolen by a hacker, who then put them up for sale. Optus had an application programming interface (API) online that did not need authorisation or authentication to access customer data.

The reputational impact of both cyber-attacks will be felt for some time to come. They are a warning shot to Australian businesses that simply canโ€™t be ignored.

Many CISOs will now be taking a closer look at their internal cyber education programs, among other things, to give staff the best chance of not falling victim to cyber-attacks that can severely damage their organisations.

Sarah Sloan, head of government affairs and public policy at Palo Alto Networks, and Matt Warren, director of RMITโ€™s Cyber Security and Innovation Research Centre joined CIO Australiaโ€™s Byron Connolly for a discussion recently on how Australian organisations can improve their cyber education programs. The panel discussion was held during the launch of Palo Alto CyberFit Nation program.

The cyber challenges that businesses face are widely known, a lot of them focused around human and organisational issues. The human aspect of cyber security awareness is such as a complex issue that hackers are looking to exploit from scam attacks to the spreading of malware such as ransomware, says RMITโ€™s Warren.

โ€œWe live in the new cyber normal that organisations are facing as they become greater targets for cyber-attacks. One of the key reasons for this challenge is that organisations cannot manage their increasingly complex systems and it is taking time for them to accept cyber security as a business risk rather than a technical one,โ€ says Warren.

Palo Alto Networksโ€™ Sloan says organisations across Australia are becoming more aware of cyber risks and the importance of educating staff, their customers and even students on how to mitigate these risks.

โ€œMany companies are incorporating cyber security as part of their workplace curriculum and regularly test the effectiveness of that training, for example, via phishing email testing,โ€ she says.

While doing this, organisations should ensure their cyber education programs also incentivise good behaviour, says Sloan.

โ€œThis could include rewarding individuals who identify all the phishing attempts and report them to the organisationโ€™s security operations team. These simple measures can go a long way to creating a security culture and environment where people feel comfortable to come forward if and when they may click on that link,โ€ she says.

When creating training programs, enterprises may also want to look beyond the โ€˜clickโ€™ to identify why an individual has taken certain actions and adjust their responses/training for those people accordingly, says Sloan.

โ€œFor example, did they click on the link because the content of the email has elicited a particular response or because they have been pressured by a sense of urgency?โ€ she asks.

Governments across the world have behavioural policy areas โ€“ such as Australiaโ€™s Behavioural Economics Team within the Department of Prime Minister and Cabinet โ€“ to research why individuals do or do not take certain actions or respond to certain messages, says Sloan.

โ€œSome of this thinking could be applied to the cyber security training and education space to help tailor messaging to particular individuals and ensure better security outcomes,โ€ she says.

But Sloan points out that itโ€™s important to remember that we are all human, we all make mistakes and it only takes one click.

โ€œSo if your organisationโ€™s corporate cyber strategy is that all users will behave in a certain way or comply with certain policies, you really donโ€™t have a corporate cyber strategy.

โ€œEvery organisation must look at preventative measures, ensure they can respond to threats in real-time and leverage automation, as well as understand their cyber security posture through the eyes of the adversary,โ€ says Sloan.

Filling the gaps in cyber training

Cyber safety and cyber security awareness is something that should be taught from school level, says RMITโ€™s Warren.

He says the Office of the eSafety Commissioner does great work at schools raising awareness around cyber safety and maybe cyber security could be combined with that messaging.

Palo Alto Networksโ€™ Sloan adds that the industry is certainly heading in the right direction with several programs helping to raise awareness of cyber issues while providing students with tools to protect themselves.

But more needs to be done to embed cyber security and technology across the school and university curriculums, she says.

โ€œIn the digital era, itโ€™s important that all of our graduates โ€“ our lawyers, accountants, doctors and economists โ€“ understand cyber security risks, mitigations and how they are relevant to their professions.

โ€œRaising awareness across faculties and disciplines will not only lead to better security outcomes, it may also lead to an interest in further study in cyber. This may help us with our cyber security skills shortage,โ€ says Sloan.

However, there is a โ€˜pipeline problemโ€™ at the school level, says RMITโ€™s Warren. If an undergraduate student starts studying cyber security in 2023, they will complete their degree in 2026, he says.

โ€œThe issue is that not all universities offer cyber security and it means that alternative courses such as micro-credentials, and other alternative pipelines need to be developed.โ€

Creating a cyber aware board

From a policy and legislative point of view, Australia has some great foundations to support and enhance cyber security awareness at the board level, says Palo Alto Networksโ€™ Sloan.

There is a range of directorsโ€™ responsibilities when it comes to duty of care and diligence around cyber security, as captured in the Corporations Act. The Australian Government has also elevated cyber security risk to the board through a series of reforms to the Security of Critical Infrastructure Act 2018.

These reforms aim to enhance Australiaโ€™s national resilience by introducing varying security obligations across 11 regulated critical infrastructure sectors, says Sloan.

โ€œOne of the relevant obligations for directors under this Act is that regulated critical infrastructure assets may be required to report to the government annually as part of their risk management programs, which must address cyber security risks.

โ€œThis new obligation is expected to elevate cyber security to boards across Australia,โ€ says Sloan.

From a guidance and education point of view, the Australian Securities and Investment Commission has issued statements on cyber guidance, emphasising the importance of active engagement by the board in managing cyber risk. The Australian Cyber Security Centre (ACSC) has also released guidance on questions that board members can ask about cyber security risk management.

RMITโ€™s Warren adds CEOs need to be aware of what cyber security is and why it should be viewed as a business risk.

โ€œIt is coming to the stage that lack of awareness is no longer an issue. CEOs and their boards also have to understand the complexity of the systems that their organisations are operating, and the risks associated with that complexity,โ€ he says.

Cyberattacks
...



๐Ÿ“Œ Is your cyber education program up to scratch?


๐Ÿ“ˆ 41.32 Punkte

๐Ÿ“Œ Linux from scratch vs docker scratch?


๐Ÿ“ˆ 28.44 Punkte

๐Ÿ“Œ Medium CVE-2020-15164: Scratch-wiki Scratch login


๐Ÿ“ˆ 28.44 Punkte

๐Ÿ“Œ MIT Lifelong Kindergarten Scratch scratch-vm prior 0.2.0-prerelease.20200714185213 serialization/sb3.js deserialization


๐Ÿ“ˆ 28.44 Punkte

๐Ÿ“Œ Iron Man Started His Journey From Scratch & Your Security Awareness Program Can Too


๐Ÿ“ˆ 25.67 Punkte

๐Ÿ“Œ Center for Cyber Safety and Education Begins Program Updates to Increase Impact


๐Ÿ“ˆ 23.6 Punkte

๐Ÿ“Œ Computer Science Education Is Security Education


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ Computer Science Education Is Security Education


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ Medium CVE-2018-17840: Education website project Education website


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ Education Background Check: What Education Verification Shows About You


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ Apple brings coding education to more students for Computer Science Education Week


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ Everything new in Microsoft Teams for Education in April 2023: Viva Connections for Education & more


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ AI's Impact on CS Education Likened to Calculator's Impact on Math Education


๐Ÿ“ˆ 22.56 Punkte

๐Ÿ“Œ SEC's cyber-cops cyber-file cyber-first cyber-fraud cyber-charges


๐Ÿ“ˆ 21.83 Punkte

๐Ÿ“Œ Cyber-warnings, cyber-speculation over cyber-Iran's cyber-retaliation cyber-plans post-Soleimani assassination


๐Ÿ“ˆ 21.83 Punkte

๐Ÿ“Œ Will your glasses fit inside or scratch the lenses of your Oculus Rift S?


๐Ÿ“ˆ 21.22 Punkte

๐Ÿ“Œ Privacy Program Metrics: How to Evaluate Your Privacy Programโ€™s Effectiveness


๐Ÿ“ˆ 19.4 Punkte

๐Ÿ“Œ Google Announces $1 Billion Job Training and Education Program


๐Ÿ“ˆ 19.23 Punkte

๐Ÿ“Œ Flatiron School Selected Again by Amazon as an Education Partner for Career Choice Program


๐Ÿ“ˆ 19.23 Punkte

๐Ÿ“Œ Crossword Wizard 6.4.8 - A premiere education and lifestyle program.


๐Ÿ“ˆ 19.23 Punkte

๐Ÿ“Œ NCSC says cyber-readiness of UKโ€™s critical infrastructure isnโ€™t up to scratch


๐Ÿ“ˆ 18.59 Punkte

๐Ÿ“Œ SOC Analyst โ€“ Cyber Attack Intrusion Training | From Scratch To Advanced


๐Ÿ“ˆ 18.59 Punkte

๐Ÿ“Œ Cyber Monday Deals (90% Off)- Master in Ethical Hacking & Penetration Testing Online Course (CEH)- Scratch to Advance Level


๐Ÿ“ˆ 18.59 Punkte

๐Ÿ“Œ Is your Spotify password up to scratch?


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ How to make sure your companyโ€™s app is up to scratch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Building Your First Power App From Scratch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ 10 React Hooks Explained // Plus Build your own from Scratch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Mind the Gap โ€“ How to Ensure Your Vulnerability Detection Methods are up to Scratch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Why Training Your Own Transformer Language Model from Scratch is (not) Stupid


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Make your own jQuery from scratch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Creating your own ExpressJS from scratch (Part 1) - Basics, Methods, and Routing


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Creating your own ExpressJS from scratch (Part 2) - Middlewares and Controllers


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Build your own Transformer from scratch using Pytorch


๐Ÿ“ˆ 17.72 Punkte

๐Ÿ“Œ Blue-Green Deployment on Single Machines Starting from Scratch, Using Your Dockerfiles: Examples in PHP, Java, and Node.js


๐Ÿ“ˆ 17.72 Punkte











matomo