Lean Security Expert Lean Security Expert

Emerging Cyber Security

Latest targets of cyber attacks have been wearables, home automation, and self driving cars.

Latest targets of cyber attacks have been wearables, home automation, and self driving cars.

Emerging Cyber Security.png
Read More
Lean Security Expert Lean Security Expert

Cyber Security Trends and Threats in 2018 (Infograph)

Do you know 54% of companies has experienced one or more successful cyber attacks that compromised their data, this year.

Do you know 54% of companies has experienced one or more successful cyber attacks that compromised their data, this year.

Here are some cyber security trends and threats in 2018 you should know about.

Cyber Security Trends and Threats in 2018.png
Read More
Lean Security Expert Lean Security Expert

DDoS Attacks-Ensure That Your Sensitive Data Stays Secure

Most businesses these days have made a switch to digital technology. Although this move has proven to be quite beneficial for businesses, there are certain problems that businesses face as well

Most businesses these days have made a switch to digital technology. Although this move has proven to be quite beneficial for businesses, there are certain problems that businesses face as well. The biggest of these problems has been an increase in the rate of DDoS attacks.

Distributed Denial Of Service Attacks

Distributed denial of services attacks refer to an online attack, which prevents a website, or a service from running smoothly. It might result in the website not displaying the content available or it might affect the speed of your computer when connected to the internet.

The goal of the hackers in these cases is to steal sensitive information. Therefore, it is imperative that you prevent these attacks from occurring in the first place.

Why Do Such Attacks Succeed

In majority of the cases, companies become victim to this kind of crime because they do not have the tools to prevent these attacks from occurring. Some of the tools that companies use in order to keep their sensitive data safe include:

· Firewalls

· Routers

· Switches

However, none of these tools are effective in case of a DDoS attack. In some cases, they actually result in businesses becoming even more susceptible. For example, a firewall might create bottlenecks, which increase the chances of outages.

Types of DDoS Attacks

There are different kinds of DDoS attacks. Some of them include:

Application Layer

These types of attacks are designed to look like innocent requests. However, their goal is to actually crash the website. Experts measure the magnitude of these kinds of attacks based on the number of requests that are sent per second.

Non-Volumetric

These kinds of attack revolve around protocol attacks. Some of these include:

· SYN floods

· Pings of Death

· Fragmented packet attacks

These kinds of attacks can result in consumption of resources. They do so by overwhelming system memory so that the server ends up crashing.

Volumetric

Some of the attacks that fall under this category include:

· User datagram protocols flood

· ICMP floods

· Spoofed packet floods

The goal of these attacks is to saturate the bandwidth of a specific website. The extent of the damage is measured through bit in a single second.

How To Prevent These Attacks

Picture9.png

There are certain measures that IT personnel within a company can undertake in order to address the issue of DDoS attacks. DDoS mitigation services can help in this regard.

The IT personnel in companies can also develop strategies for countering DDoS attacks and develop mitigation plans in order to strengthen their company’s defences.

Creating a risk profile of the company can also help companies solve this issue. Get in touch with us. We offer mobile application penetration test and services. We can conduct a data assessment and highlight the flaws in your system.

In addition to that, we can also help identify security issues for mobile apps. You can contact us at +61 (0) 2 8231 6635 or visit our website for further information.

Read More
Lean Security Expert Lean Security Expert

The General Data Protection Regulation Guidelines For Businesses In Australia

The General Data Protection Regulation contains details regarding the protection of data within a region. The act will replace the national data protection laws within the region

The General Data Protection Regulation contains details regarding the protection of data within a region. The act will replace the national data protection laws within the region.

The goal is to enhance the trust that customers have in online services and create a legally secure environment for businesses.

Australian Privacy Act 1988

In the past, certain Australian companies were offered coverage by the Australian Privacy act. These companies will need to comply with certain rules of GDPR like having a presence in one of the companies, which are a part of the European Union.

All the information that the company provides needs to be genuine and transparent. Both of these acts require businesses to ensure that they comply with the rules that have been set up regarding privacy.

Considering the similarities between the two acts, it might not be tough for businesses to adjust their practices according to the GDPR.

What comes under GDPR?

All the data processing activities that companies engage in come under GDPR. If the company has a presence in the European Union, it will need to make sure all of the data that has been processed comes under GDPR, even if the data has not necessarily been processed in the region.

Businesses that receive coverage from GDPR but are not active in the European Union will have to appoint an individual who represents the firm in the European Union. The person appointed also needs to be a resident of the European Union.

All the data of the people within the region comes under the GDPR. In this act, additional protection is offered to the data, which has personal categories. These include:

· Race

· Political beliefs

· Religion

· Membership to the trade union

New Requirements

Some of the new requirements that are a part of GDPR include:

Governance And Accountability

The law requires the companies to undertake adequate measures to protect the rights and freedom of all the people who are customers of the business. The policies need to be designed in such a way that they minimize the need to process the data.

In addition to that, the companies need to maintain transparency while processing personal data of their customers. They should also allow the person to monitor the processing of data.

The act also requires companies to take measures to ensure that all of the data of the customers stay safe. Businesses can do so by seeking assistance from companies that offer penetration testing service and conduct network vulnerability assessment.   

Get in touch with us. Our team members can help identify security issues for mobile apps. Y0ou can drop us an email at info@leansecurity.com.au or visit our website for further information.

Read More