RSSAmplifier

Blog

Brian Pennington

A blog about Cyber Security, Governance, Risk and Compliance

brianpennington.co.ukRSS feed ↗10 posts

Latest posts

Weak Enforcement and Low Compliance in PCI DSS: A Comparative Security Study

Soonwon Park and John D. Hastings of The Beacom College of Computer and Cyber Sciences, Dakota State University, have produced a paper on how Compliance is enforced across a range of GRC standards. The paper specifically focuses on PCI DSS, HIPAA, NIS2, and GDPR and how the individual standards are enforced and how the enforcement [ ]

Top 10 cyber security stories of 2025

Here are Computer Weekly’s top 10 cyber security stories of 2025. 1. US indicts five in fake North Korean IT contractor scandal 2. NCSC proposes three-step plan to move to quantum-safe encryption 3. NHS asks suppliers to sign up to cyber covenant 4. US cyber agency CISA faces stiff budget cuts 5. Brits clinging to [ ]

The continuing threat from email based attacks

It is relatively easy for cybercriminals to obtains tool and support to instigate a Phishing or Quishing email attack campaign. Their challenge is to find enough targets to make the attacks work and like the other criminals in their space, the spammers, scammers and BECers it is a numbers game and luckily for them there [ ]

A consolidated list of 2025 predictions

Over the years I have consolidated a few “next year” predictions as it is interesting, well at least for me, to see how accurate the predictions are but also how geopolitical and technological developments can impact the security industry and therefore the outcomes of the predictions. If you want to look back in time, my [ ]

The most common Phishing Attacks in one simple Infographic from KnowBe4

A picture paints a thousand words and this useful image from KnowBe4 quickly and simply summarises the current Phishing activities. The main Phishing topic for business based attacks was HR with 42% of the attacks followed by IT related emails at 30%. Outside of HR the usual suspects come into play with Amazon Prime, PDFs [ ]

Instant Expertise: How Interim CISOs fill Critical Leadership Gaps

A blog by Luke Rupnow of Online Business Systems Inc. The demand for Chief Information Security Officers (CISOs) continues to increase due to the rising complexity of cyber threats and the critical role of cybersecurity pertaining to business strategy and operations. According to PwC’s 2024 Global Digital Trust Insights, a significant portion of executives acknowledge [ ]

The ISO 27000 family of protocols and their role in cybersecurity

The ISO 27000 family of protocols represent a series of standards developed by the International Organization for Standardization (ISO) to address various aspects of information security management. These standards provide a framework for organizations to establish, implement, maintain, and continually improve their information security management systems (ISMS). Each standard within the ISO 27000…

Which countries account for the most hacking?

Despite the very detailed analysis by Statista the not identified cyber incidents account for more that the the four usual nations. This could mean the usual suspects are doing a good job of hiding their attacks and they are getting away with a considerable amount of cybercrime or a lot of other more friendly nations [ ]

26 Cyber Security Stats every user should be aware of in 2024

From an article written by Anas Baig and reproduced with permission.

Top 10 Cyber Incidents Report 2023, based on the financial impact and reputational damage

Tokio Marine HCC International Cyber team has published their fourth annual Top 10 Cyber Incidents Report 2023. Here is their Top 10 with the link to the report at the bottom of the post. Link to the Tokio Marine report is here.