Who is Working at Your Provider

Who is Working at Your Provider

Recent news about the hack at UK's Ministry of Defence has been a huge news item and for good reason. There are some calling out China, which they deny, and the mention that the service in question is outsourced to an external provider.

This led to go back to some comments on an earlier breach notice, let me explain.

In my opinion, one of the key differentiators at J2 Software is that we only use our own full-time staff to provide services to our customers. This is because we believe and look after our team. There is a heightened level of trust after a long verification and background process, we have ongoing monitoring and complete visibility.

Recently, #NCSC had an announcement calling out Chinese threat actors doing reconnaissance against email of members of parliament and compromising the UK Electoral Commissions systems years earlier.

NCSC Announcement

Among the comments was an individual that is an IT Consultant & contractor who complained he was not getting paid enough and had "ZERO sympathy for any firm or even govt department that skimps on IT..." - SO, he believes they deserve to be compromised? Clearly stating his position on the matter.

Contractor Comment 1

Further along the same contractor he once again mentions pay and then he goes on to tell us how amazing the dark web vendors and #ranswomware gangs support is, touting their GREAT customer support and training. Which team is he on here? My opinion - the cyber criminals.

Contractor Comment 2

I then had a look at his work history to understand who or what sort of infrastructure he looks into or "protects". The last 4 work experiences listed has this potentially unscrupulous individual, who loves the work of the dark web and ransomware vendors, was for the NHS, A council, Met Police and UK Civil Service.

Contractor Work Experience

How are these background checks done, what ongoing monitoring of individuals working in critical government (or corporate) environments that would allow this.

The problem that we all need to understand is that not everyone works from the same place of principle that you do, there will always be those among us who want more and more or feel they deserve it. Many to a point where they will take it. People are both the key to staying safe and also our weakest point.

Would you trust this person to protect your business?

How are you managing your #insider #risk?

Take care out there.

#letstalk

Cheers for now

John


要查看或添加评论,请登录

John Mc Loughlin的更多文章

  • The Insider Threat – Human Risk Management Requires a No-Blame Approach

    The Insider Threat – Human Risk Management Requires a No-Blame Approach

    In the realm of cybersecurity, the insider threat remains a significant concern. Despite the common narrative, it’s…

    1 条评论
  • It’s not like it’s a motor car, its more valuable than that

    It’s not like it’s a motor car, its more valuable than that

    Nobody will want to target us, we have nothing to steal. We are not important enough.

    14 条评论
  • They've Stolen Your Session & Credentials

    They've Stolen Your Session & Credentials

    A few weeks ago there was yet another (one of hundreds) of attempts to get me to take the bait. With the help of…

  • 18 YEARS - FROM HONEYDEW TO THE WORLD

    18 YEARS - FROM HONEYDEW TO THE WORLD

    18 years ago, I walked to our desk in the warehouse section of our good friends at E-Bis and the J2 Software journey…

    68 条评论
  • Why Hesitate? Cyber Resilience Makes Business Sense

    Why Hesitate? Cyber Resilience Makes Business Sense

    A successful cyber attack takes several weeks to recover from. So let’s be conservative and ask ourselves a few…

  • 'Tis the Season to be Scammed

    'Tis the Season to be Scammed

    It was just yesterday that most of the world was in lockdown, then today we look up and it is half way through November…

    1 条评论
  • Insider Risk Equals Financial Risk

    Insider Risk Equals Financial Risk

    Do you have the visibility? I am continually amazed at how many companies talk about their comfort with their…

  • What have you been doing John?

    What have you been doing John?

    I am constantly seeing and hearing more talk about the risk posed by #insiders when it comes to business #risk. The…

    1 条评论
  • Make sure you pay the CEO

    Make sure you pay the CEO

    Make sure you pay the CEO Over the last month the J2 Software team have noticed an increase in an evolved method in…

  • Beware of the Post Office Scam

    Beware of the Post Office Scam

    We have recently seen an increase in these types of cyber attacks. The cyber criminal bypasses your email security by…

社区洞察

其他会员也浏览了