Catch up on the latest information security news with our fortnightly podcast. Also, keep an eye out for webinars and author interviews, where we speak with industry experts about information security, cyber security, data privacy and much, much more.
IT Governance Podcast 20.10.23: Casio, Cisco, MOVEit (again) and the ICC
This week, we discuss a data breach affecting Casio users in 149 countries, two zero-day vulnerabilities in Cisco’s IOS XE web user interface, a slew of legal action against Progress Software following the MOVEit Transfer breach, and an update on last month’s cyber attack on the International Criminal Court.
10/23/2023 • 7 minutes, 1 second
IT Governance Podcast 6.10.23: TikTok, Sony and MOVEit and DarkBeam
This week, we discuss another GDPR fine for TikTok relating to its processing of child users’ personal information, more data breaches caused by MOVEit Transfer, including Sony Interactive Entertainment, and the exposure of a mammoth 3.8 billion data records.
10/6/2023 • 6 minutes, 23 seconds
IT Governance Podcast 22.09.23: MGM Resorts, Microsoft Azure, International Criminal Court
This week, we discuss a cyber attack on MGM Resorts that has allegedly cost the company millions of dollars in revenue even before it began its remediation efforts, the leak of 38 terabytes of Microsoft data and a cyber attack on the International Criminal Court in The Hague.
9/22/2023 • 7 minutes, 31 seconds
IT Governance Podcast 08.09.23: Electoral Commission (again), Meta, Pôle emploi
This week, we discuss security issues at the Electoral Commission, Meta’s appeal against daily GDPR fines, and a breach affecting 10 million users of the French unemployment agency Pôle emploi.
9/7/2023 • 6 minutes, 5 seconds
IT Governance Podcast 25.8.23: Tesla, Duolingo, Lapsus$ trial
This week, we discuss “insider wrongdoing” at Tesla, a data breach affecting 2.6 million Duolingo users and the conclusion of a two-month court case against members of the Lapsus$ gang.
8/24/2023 • 5 minutes, 24 seconds
IT Governance Podcast 11.8.23: Electoral Commission, PSNI, Capita
This week, we discuss data breaches affecting the Electoral Commission and the Police Service of Northern Ireland, and the financial repercussions of Capita’s March ransomware incident.
8/10/2023 • 7 minutes, 12 seconds
IT Governance Podcast 14.7.23: EU-US DPF, UK-US data bridge, MOVEit patches and other security fixes
This week, we discuss the new EU adequacy decision for the US, based on the Data Privacy Framework (plus Max Schrems’s inevitable reaction), and a proposed UK-US ‘data bridge’; fixes for three more vulnerabilities in Progress Software’s MOVEit Transfer app; plus this month’s Patch Tuesday and other security updates.
7/13/2023 • 7 minutes, 40 seconds
IT Governance Podcast 30.6.23: ChatGPT, LetMeSpy and MS Teams, plus Alan Calder on cyber security
This week, we discuss 100,000 compromised ChatGPT credentials, a data breach affecting the LetMeSpy stalkerware app, and a potential security vulnerability in Microsoft Teams that could be exploited to spread malware. Plus, Alan Calder discusses the current cybersecurity and regulatory landscape, and how they affect organisations.
6/29/2023 • 20 minutes, 38 seconds
IT Governance Podcast 16.6.23: MOVEit, LinkedIn, Spotify and Google Bard
This week, we discuss a data breach affecting users of Progress Software’s MOVEit file transfer app, GDPR fines for LinkedIn and Spotify, and the delay of Google Bard’s EU launch because of privacy concerns.
6/15/2023 • 7 minutes, 14 seconds
IT Governance Podcast 2.6.23: Capita, NHS, Meta, GDPR, DPDI Bill and Alan Calder on cyber regtech
This week, we discuss more organisations affected by Capita’s security issues, the security implications of 20 NHS trusts’ use of Meta Pixel, Meta’s €1.2 billion GDPR fine and its potential effects for other organisations, and the progress of the DPDI (No. 2) Bill. Plus, Alan Calder discusses cyber regtech and how organisations can use it to manage their regulatory compliance.
6/1/2023 • 17 minutes, 32 seconds
IT Governance Podcast 19.5.23: Capita, USS, Colchester City Council and Alan Calder’s analysis.
This week, we look at the wider repercussions of the Capita ransomware attack, and how numerous clients have been affected, including the Universities Superannuation Scheme and other pension providers. Plus, accusations of another Capita breach and Alan Calder on what all organisations can learn from the attack and Capita’s response.
5/18/2023 • 16 minutes, 31 seconds
IT Governance Podcast 5.5.23: ChatGPT, LockBit, T-Mobile, Alan Calder on cyber security for boards
This week, we discuss ChatGPT’s restoration in Italy despite wider security concerns, an apology from the LockBit ransomware group and another breach for T-Mobile, and Alan Calder discusses what boards need to do to build their organisations’ cyber defences.
5/4/2023 • 19 minutes, 17 seconds
IT Governance Podcast 21.4.23: Capita, Chrome, LockBit for Macs and Alan Calder on cyber security
This week, we discuss the apparent sale of exfiltrated Capita data by the Black Basta ransomware group, a zero-day Google Chrome vulnerability and the development of a new LockBit ransomware variant targeting macOS, and Alan Calder analyses the new US National Cybersecurity Strategy and explains what all organisations should learn from it.
4/20/2023 • 18 minutes, 11 seconds
IT Governance Podcast 2023-7: Capita, ChatGPT and TikTok (yet again)
This week, we discuss a cyber attack on the outsourcing giant Capita, Italy's ban on OpenAI's ChatGPT chatbot and further bad news for TikTok: a £12.7 million fine from the ICO for breaching UK data protection law.
4/5/2023 • 8 minutes, 54 seconds
IT Governance Podcast 2023-6: Ferrari, Dole, TikTok (again), Android
This week, we discuss ransomware attacks on Ferrari and the Dole Food Company, another TikTok ban – this time by the BBC – and vulnerabilities that allow some Android phones to be hacked with only the victim's phone number.
3/23/2023 • 6 minutes, 51 seconds
IT Governance Podcast 2023-5: WH Smith, the Data Protection and Digital Information Bill, TikTok
This week, we discuss a data breach affecting WH Smith, the latest proposals to reform data protection law in the UK, TikTok's response to being banned by the European Commission and European Parliament, and the proposed US RESTRICT Act, and a woman who has been sentenced for defrauding Luton Borough Council in a cyber attack.
3/9/2023 • 6 minutes, 59 seconds
IT Governance Podcast 2023-4: EU-US Data Privacy Framework, Twitter 2FA, GoDaddy, HardBit 2.0
This week, we discuss the European Parliament Committee on Civil Liberties’s opinion of the EU-US Data Privacy Framework, Twitter’s decision to disable free text-based 2FA, a series of attacks on GoDaddy’s infrastructure and the HardBit 2.0 ransomware group’s negotiation tactics.
2/23/2023 • 9 minutes, 11 seconds
IT Governance Podcast 2023-3: Bank security flaws ranked, ION ransom paid, MP hacked
This week, we discuss a Which? investigation into basic security flaws on banks' websites and apps, a ransomware attack on the financial firm ION Cleared Derivatives, and a phishing attack that compromised the emails of Stewart McDonald MP.
2/9/2023 • 32 minutes, 31 seconds
IT Governance Podcast 2023-2: Mailchimp, fast food, T-Mobile, ice rinks, iOS update and ISO 27001
This week, we discuss the fallout from the latest Mailchimp breach, a ransomware attack on KFC, Pizza Hut and Taco Bell's parent company, another T-Mobile data breach, an incident affecting Planet Ice, and an update for older Apple devices. We also talk to the ISO 27001 expert Steve Watkins about his new pocket guide to the Standard.
1/26/2023 • 30 minutes, 47 seconds
IT Governance Podcast 2023-1: more ransomware attacks on the education sector, and DPC and Meta sued
This week, we discuss a series of ransomware attacks on 30 schools and colleges in the UK, legal action against both Meta and the Irish Data Protection Commission following last year’s massive Facebook GDPR fine, and the third stage of a cyber-defence-in-depth strategy: management.
1/12/2023 • 33 minutes, 26 seconds
IT Governance Podcast Episode 14: Rackspace, Citrix and EU-US adequacy decision
This week, we discuss a ransomware attack on Rackspace, a Citrix zero-day vulnerability, the forthcoming EU adequacy decision in respect of the EU-U.S Data Privacy Framework, and the second stage of a cyber-defence-in-depth strategy: protection.
12/15/2022 • 29 minutes, 42 seconds
IT Governance Podcast Episode 13: $100 million ransomware, Westmount City, Suffolk Police, AI
This week, we discuss the Hive ransomware as a service, the latest developments following the Medibank breach, a Canadian city shut down by ransomware, Suffolk Police's leak of sensitive data and the ethical implications of AI.
11/24/2022 • 35 minutes, 15 seconds
IT Governance Podcast Episode 12: Interserve, Medibank, UPS and Patch Tuesday
This week, we discuss a £4.4 million GDPR fine for the construction company Interserve, a data breach affecting 9.7 million customers of Medibank, an unusual GDPR fine for UPS, and Microsoft’s latest software updates.
11/10/2022 • 6 minutes, 40 seconds
IT Governance Podcast Episode 11: EU-US Data Privacy Framework, ransomware & cyber detection
This week, we discuss the new mechanism for transferring EU residents’ personal data to the US, the first GDPR Data Protection Seal, a new ransomware attack targeting Ukraine and its allies, and the first layer in a defence-in-depth approach to cyber security: detection.
10/27/2022 • 24 minutes, 26 seconds
IT Governance Podcast Episode 10: Data protection reform, Easylife fine, Uber conviction and work
This week, we discuss yet more planned changes to UK data protection law, a £1.35 million GDPR fine for “predatory marketing”, the conviction of Uber’s former chief security officer, and a new book about how to establish an enjoyable career.
10/13/2022 • 28 minutes, 28 seconds
IT Governance Podcast Episode 9: TikTok, American Airlines and Morgan Stanley Smith Barney
This week, we discuss a potential fine of £27 million for TikTok, a data breach caused by a phishing attack on American Airlines and a $35 million penalty for Morgan Stanley Smith Barney LLC after ”extensive” security failures.
9/29/2022 • 5 minutes, 35 seconds
IT Governance Podcast Episode 8: Twitter, Instagram, InterContinental and Cloud security
This week, we discuss allegations of data security failures at Twitter, a €405 million fine for Instagram, a cyber attack on InterContinental Hotels Group, and why Cloud security is so important.
9/15/2022 • 6 minutes, 38 seconds
IT Governance Podcast Episode 7: Apple zero-day, NHS ransomware update and 0ktapus phishing campaign
This week, we discuss two zero-day vulnerabilities affecting Apple devices, the further effects of a ransomware attack on an NHS digital services provider and a large-scale phishing campaign affecting users of secure services such as Okta, Authy and Signal.
9/1/2022 • 4 minutes, 56 seconds
IT Governance Podcast Episode 6: NHS ransomware, Ukraine, Digital Protection and Information Bill
This week, we discuss a ransomware attack on an NHS digital services provider and a huge increase in cyber attacks as a result of the war in Ukraine, and provide an overview of the main reforms to UK data protection law proposed by the Digital Protection and Information Bill.
8/18/2022 • 6 minutes, 5 seconds
IT Governance Podcast Episode 5: Facebook, Twitter, VW, Digital Protection and Information Bill
This week, we discuss a malware campaign targeting Facebook Business users, a breach apparently affecting 5.4 million Twitter users, a €1.1 million GDPR fine for Volkswagen, the new Digital Protection and Information Bill, and why it’s so important to maintain your cyber security through a recession.
8/4/2022 • 27 minutes, 20 seconds
IT Governance Podcast Episode 4: Ransomware advice, MFA phishing and The Art of Cyber Security
This week, we discuss NCSC and ICO advice to the legal profession, a new phishing campaign that bypasses multifactor authentication, and the huge increase in the number of ransomware and phishing attacks this year. Plus, we talk to Gary Hibberd about his new book, The Art of Cyber Security.
7/21/2022 • 23 minutes, 56 seconds
IT Governance Podcast Episode 3: NCSC guidance, Amagasaki breach, Maastricht Uni and the metaverse
This week, we discuss new NCSC guidance on avoiding cyber security “staff burnout”, a data breach affecting a Japanese city's entire population, good news for the ransomware-hit Maastricht University, and the privacy implications of the metaverse.
7/7/2022 • 11 minutes, 44 seconds
IT Governance Podcast Episode 2: Yodel, ransomware, the Data Reform Bill and cyber defence in depth
This week, we discuss a cyber attack that’s disrupted Yodel’s deliveries, new tactics from a ransomware gang, the government’s plans for reforming UK data privacy law, and the importance of a defence-in-depth approach to cyber security.
6/23/2022 • 9 minutes, 54 seconds
IT Governance Podcast Episode 1: Twitter, Beeple, QuickBooks and Hybrid Working Security
This week, we look at a $150 million fine for Twitter, phishing attacks affecting the Twitter followers of the digital artist Beeple and users of the accounting platform QuickBooks, and a massive data breach affecting Pegasus Airlines – plus we talk about security issues facing organisations with a remote or hybrid workforce.
6/9/2022 • 12 minutes, 36 seconds
Brexit And Schrems II | Practical Implications For UK - EU Data Transfers 1
The Schrems II ruling and Brexit mean that UK organisations are required to reconsider the legal basis for the transfer of personal data to and from Europe.
The webinar recording covers:
The Schrems II decision regarding transfers of data;
The implications for UK and EU data controllers regarding data transfers;
The types of data transfers organisations should consider;
Data flows and the legal basis for UK–EU data transfers;
Practical steps organisations can take now; and
What the future holds following Schrems II and Brexit.
3/16/2021 • 1 hour, 29 minutes, 43 seconds
Data Flow Audit And Data Mapping For GDPR Compliance
We take a look at Data Flow Audit And Data Mapping For GDPR Compliance in this webinar recoding
3/16/2021 • 53 minutes, 48 seconds
Introduction To Data Mapping
We take a look at Data Flow Mapping in this webinar recording
3/16/2021 • 1 hour, 3 minutes, 44 seconds
Data Protection By Design And By Default Under The GDPR
The EU General Data Protection Regulation (GDPR) highlights how the principles of ‘privacy by design’ and ‘privacy by default’ are fundamental to ensuring that organisations protect the rights of data subjects.
We take a look at Data Protection By Design And By Default Under The GDPR in this webinar recording
3/16/2021 • 1 hour, 16 minutes, 17 seconds
The First Steps Towards GDPR Compliance
Alan Calder, Founder and CEO of IT Governance discusses the first steps towards GDPR compliance in this webinar recording.
3/16/2021 • 1 hour, 4 minutes, 24 seconds
Weekly podcast: Goodbye!
In our last ever podcast, we discuss Citrix’s data breach, the GDPR and cookie walls, data breach notification, and Patch Tuesday.
3/14/2019 • 6 minutes, 30 seconds
7th March Weekly podcast: Reports galore! DCMS, Microsoft and Cisco
This week, we delve into the government's FTSE 350 Cyber Governance Health Check report, Microsoft's Security Intelligence Report Volume 24, and Cisco's latest Data Privacy Benchmark Study
3/7/2019 • 6 minutes, 12 seconds
28 February Weekly podcast: ICANN, DNS and DNSSEC; credential stuffing, and passwords managers
This week, we discuss ICANN's warning about DNS attacks, the extent of credential stuffing attacks on the retail sector, password managers' responses to recent research into security flaws, and the European Data Protection Supervisor's annual report for 2018.
2/28/2019 • 6 minutes, 54 seconds
21 February Weekly podcast: Password managers, unpatched vulnerabilities, formjacking and Wendy's
This week, we discuss a security flaw affecting 1Password, Dashlane, KeePass and LastPass; the prevalence of historic vulnerabilities in corporate IT systems; the increase in formjacking attacks; and Wendy's $50 million data breach settlement.
2/21/2019 • 5 minutes, 41 seconds
14 February Weekly podcast: Mumsnet, OkCupid and Apple
This week, we discuss a data breach at Mumsnet, no data breach at OkCupid, and a lawsuit against Apple for implementing security measures.
2/14/2019 • 5 minutes, 48 seconds
7 February Weekly podcast: Metro Bank, Student Loans Company, GDPR breaches and seals
This week, we discuss the compromise of Metro Bank's two-factor authentication system, nearly one million cyber attacks on the Student Loans Company, nearly 60,000 GDPR breaches and a surprising discovery for some marine biologists
2/7/2019 • 7 minutes, 13 seconds
31 January Weekly Podcast: Facebook VPN, FaceTime bug, and Internet Explorer 10
31 January Weekly Podcast: Facebook VPN, FaceTime bug, and Internet Explorer 10 by IT Governance
1/31/2019 • 5 minutes, 51 seconds
24 January Weekly podcast: Google GDPR fine, EU-US Privacy Shield and US DNS hijacking attacks
This week, we discuss Google's €50 million GDPR fine, GDPR complaints against eight streaming services, Facebook’s Supreme Court appeal and its potential effects on the EU-US Privacy Shield, and an Emergency Directive from the US Department of Homeland Security.
1/24/2019 • 5 minutes, 37 seconds
17 January Weekly podcast: US government websites, Liberia DDoS attacker and no-deal Brexit
This week, we discuss how the US government shutdown is affecting federal websites' security, the sentencing of a man who knocked Liberia's Internet offline with a botnet, and what a no-deal Brexit means for data protection
1/17/2019 • 7 minutes, 21 seconds
11 January Weekly podcast: German data breach, poor passwords, Marriott, NHS Digital & Patch Tuesday
This week, we discuss a high-profile German data breach, the top worst passwords of 2018, the resignation of NHS Digital’s CISO, and Microsoft’s latest patches.
1/10/2019 • 7 minutes, 20 seconds
14 December Weekly Podcast: 2018 end-of-year roundup
This week, in our last podcast of the year, we revisit some of the biggest information security stories from the past 12 months
12/13/2018 • 16 minutes, 42 seconds
30th November Weekly podcast: Uber, Google, and City of York Council vs RapidSpike
This week, we discuss the latest fines for Uber in connection with its 2016 data breach, GDPR complaints against Google, and the other side of the City of York Council 'hack' story.
11/29/2018 • 7 minutes, 19 seconds
23 November Weekly podcast: Amazon, TalkTalk and City of York
This week, we discuss Amazon's exposure of customer names and addresses, jail sentences for two TalkTalk hackers, and a data breach affecting a City of York rubbish app.
11/22/2018 • 5 minutes, 25 seconds
16 November Weekly podcast: Bank of England, the OPM, Patch Tuesday and Japanese minister
This week, we discuss a Bank of England cyber resilience exercise, the latest cyber security news from the US Office of Personnel Management, the highlights of this month's Patch Tuesday, and a surprising admission by a Japanese cyber security minister
11/16/2018 • 6 minutes, 36 seconds
9 November Weekly podcast: HSBC, Evernote and Apache Struts
This week, we discuss a data breach affecting HSBC's US customers, a XSS vulnerability in Evernote and a critical RCE vulnerability in Apache Struts
11/8/2018 • 5 minutes, 22 seconds
2 November Weekly podcast: Planes, trains and online learning
This week, we discuss BA's update about its recent data breach, the 9.4 million victims of Cathay Pacific's data breach, Eurostar's password reset, and an indictment for the criminals behind an extortion attempt at lynda.com
11/1/2018 • 5 minutes, 45 seconds
26 October Weekly podcast: Supermicro, federal data privacy law and Morrisons
This week, we discuss the stalemate between Bloomberg Businessweek and Supermicro, Apple and Facebook’s call for a federal data privacy law in the US, and what the Morrisons Appeal Court ruling means for every organisation
10/25/2018 • 7 minutes, 59 seconds
19 October Weekly podcast: US Defense Department, MOD and NHS
19 October Weekly podcast: US Defense Department, MOD and NHS by IT Governance
10/18/2018 • 6 minutes, 8 seconds
12 October Weekly Podcast: Google+, Supermicro and Heathrow
This week we discuss the end of Google+, allegations of Chinese motherboard interference, and a £120,000 fine for Heathrow Airport
10/11/2018 • 8 minutes, 14 seconds
5 October Weekly Podcast: Russian cyber crimes, Facebook breach and Tory conference app
This week, we discuss Russian cyber crime, the Facebook breach affecting 90 million users and the Conservative Party's conference app breach
10/4/2018 • 4 minutes, 31 seconds
28 September Weekly podcast: SHEIN, Tesco Bank, UK cyberwarfare unit and Uber
Big numbers this week: we discuss a data breach affecting 6.42 million SHEIN customers, a potential £30 million FCA fine for Tesco Bank, the UK's new £250 million cyberwarfare unit, and a $148 million settlement for Uber
9/27/2018 • 5 minutes, 49 seconds
21st September Weekly podcast: Equifax once more, Bristol Airport, Smeg and Mirai creators
This week, we discuss a record ICO fine for Equifax, cyber attacks on Bristol Airport and Smeg, and the sentencing of the creators of the Mirai botnet
9/20/2018 • 6 minutes, 20 seconds
14th September Weekly podcast: BA, Npower, Lazarus Group and Patch Tuesday
This week, we discuss the continuing fallout from the BA breach, the compromise of 5,000 Npower customers' details, DoJ charges against a North Korean computer programmer, and this month's Microsoft updates
9/17/2018 • 6 minutes, 17 seconds
7 September Weekly podcast: Plusnet, TV Licensing, BEC scams and data breach causes
This week, we discuss a data breach at Plusnet, poor security at tvlicensing.co.uk, why most BEC scams succeed, and what causes most data breaches
9/6/2018 • 5 minutes, 25 seconds
The Periscope Podcast
Welcome to the IT Governance Periscope Podcast: This week’s episode is an investigation into the DPO’s role – who needs one, what they do and their role in a data breach.
9/3/2018 • 7 minutes, 33 seconds
31 August Weekly Podcast: Air Canada, Huazhu Hotels, and West Ham FC
In this week's podcast, we discuss the data breach at Air Canada, Huazhu Hotels, and West Ham Football Club
8/30/2018 • 3 minutes, 23 seconds
24 August Weekly Podcast: Weekly Podcast: Superdrug, Facebook and Twitter, and the ICO
In this week's podcast, we discuss the data incident at Superdrug, Facebook and Twitter removing accounts, and the ICO website being down.
8/23/2018 • 3 minutes, 23 seconds
The Periscope Podcast
Welcome to the IT Governance Periscope Podcast: This week’s episode is an investigation into reporting on staff training, awareness and IT Governance products and solutions for organisations that suffer a data breach
8/20/2018 • 11 minutes, 57 seconds
17 August Weekly podcast: Intel Foreshadow attack, Cosmos cash-out scheme, TLS 1.3 and Patch Tuesday
This week, we discuss a new flaw affecting Intel processors, a $13.5 million cyber attack on an Indian bank, the release of version 1.3 of the Transport Layer Security protocol and the highlights from this month's Microsoft patches.
8/17/2018 • 6 minutes, 4 seconds
August 10 Weekly podcast: ICS attacks, Reddit and SIM swap arrests
This week, we discuss new research into attacks on industrial control systems, Reddit's recent breach, and an apparent crackdown on SIM swap fraud
8/10/2018 • 6 minutes, 39 seconds
3 August Weekly podcast: Dixons Carphone, Fashion Nexus, Yale and Alaska
This week, we discuss the 10 million affected by Dixons Carphone's 2017 data breach, the exposure of hundreds of thousands of clothes shoppers' details, Yale University's ten-year old data breach, and a return to typewriters for government workers in Matanuska-Susitna Borough in Anchorage.
8/3/2018 • 6 minutes, 8 seconds
The IT Governance Periscope Podcast #1
Welcome to the IT Governance Periscope Podcast: This week’s episode is an investigation into cyber incident response management and IT Governance products and solutions for organisations which suffer a data breach.
8/2/2018 • 22 minutes, 17 seconds
27 July Weekly podcast: Chrome and HTTP, British Airways, and Level One Robotics
This week we discuss Google Chrome flagging sites that use HTTP as not secure, BA's GDPR fail, and a massive data breach affecting more than 100 manufacturing companies.
7/27/2018 • 6 minutes, 13 seconds
Client X #2: Physical Technology – Hardware
Welcome to the IT Governance Technology & Media Podcast: Client X. Account Manager Zak Rush joins us again for our second episode. Zak is a Technology & Media sector specialist at IT Governance. It’s his job to identify client obligations, discuss project scope and generally facilitate any and all client needs in the Technology & Media sector.
7/20/2018 • 18 minutes, 29 seconds
20th July Weekly podcast: the IICSA, the EU-US Privacy Shield, data breach costs and Lotto hackers
This week, we discuss a £200,000 fine for the IICSA, a move to suspend the EU-US Privacy Shield, how much a data breach might cost your organisation, and the sentencing of two National Lottery hackers.
7/19/2018 • 6 minutes, 7 seconds
13th July Weekly podcast: banks, Thomas Cook, London cyber court and Facebook
This week, we discuss operational resilience in the banking and financial market infrastructures sectors, a data breach affecting Thomas Cook subsidiaries, London's proposed new court building and the latest development in the Facebook/Cambridge Analytica scandal
7/13/2018 • 6 minutes, 43 seconds
Client X #1: The Information Technology Sector
Welcome to the IT Governance Technology & Media Podcast: Client X. Account Manager Zak Rush joins us for our first episode. Zak is a Technology & Media sector specialist at IT Governance. It’s his job to identify client obligations, discuss project scope and generally facilitate any and all client needs in the Technology & Media sector.
7/12/2018 • 12 minutes, 52 seconds
6 July Weekly Podcast: NHS Digital Breach, Typeform Data Breach, and Noble Design Fine
This week, we discuss the unauthorised sharing of 150,000 patients' confidential health data, the first ripples from the Typeform data breach, and a £4,500 fine for a company that didn't register with the ICO
7/6/2018 • 5 minutes, 33 seconds
29 June Weekly podcast: Exactis, BetVictor, Ticketmaster, and GDPR complaints
This week, we discuss the apparent leak of 340 million data records, a vulnerability that exposed sensitive BetVictor data, a data breach affecting up to 40,000 Ticketmaster customers, and the number of GDPR complaints since 25 May.
6/29/2018 • 6 minutes, 6 seconds
22 June Weekly podcast: BT, Bithumb, Islington Council and World Cup phishing
This week, we discuss a £77,000 fine for BT, Bithumb's loss of £24 million, Islington Council's PCI DSS fail and some topical phishing campaigns.
6/22/2018 • 5 minutes, 22 seconds
8th June Weekly podcast: MyHeritage, PageUp, Rochester Grammar School and, yes, the GDPR
This week, we discuss the compromise of 92 million MyHeritage users' credentials, “unauthorised activity” at PageUp, a missing memory stick at Rochester Grammar School, and the first couple of weeks of the GDPR
6/8/2018 • 5 minutes, 28 seconds
1 June Weekly podcast: Yahoo hacker sentenced, acoustic DoS attack and GDPR compliance fails
This week, we discuss the sentencing of one of the perpetrators of the 2013 Yahoo breach, a new type of denial-of-service attack that can crash computers just using sound and how not to email your customers
6/1/2018 • 4 minutes, 59 seconds
25 May Weekly podcast: the GDPR is here
The General Data Protection Regulation is now in force. Don't panic.
5/25/2018 • 3 minutes, 20 seconds
18 Weekly podcast: myPersonality, train Wi-Fi and Kaspersky Lab
This week, we discuss the exposure of millions of Facebook users' data, security failings in train passenger networks and Kaspersky Lab's relocation to Switzerland
5/17/2018 • 5 minutes, 52 seconds
11 May Weekly podcast: Twitter, Spectre-NG, NIS Directive and patches
This week, we discuss Twitter's password reset, new Spectre CPU flaws, the implementation of the EU's NIS Directive, and patch Tuesday's highlights
5/10/2018 • 5 minutes, 13 seconds
4th May Weekly podcast: NHS upgrade, $242m Equifax loss and prison hacker jailed
This week, we discuss a new deal between the NHS and Microsoft, the financial cost of Equifax's massive data breach, and a jail sentence for a hacker who altered prison records
5/3/2018 • 4 minutes, 39 seconds
26 April Weekly podcast: TSB, hotel locks and NATO exercise
This week, we discuss TSB's chaotic system upgrade, a security flaw in electronic hotel locks and a major NATO cyber security exercise
4/27/2018 • 4 minutes, 38 seconds
Weekly discussion podcast #13: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: www.itgovernance.co.uk/shop/product/…digital-world
4/26/2018 • 4 minutes, 56 seconds
20 April Weekly podcast: Russia warning, RBKC fined and TaskRabbit breached
This week, we discuss an alert from the NCSC, US DHS and FBI, a £120,000 fine for the Royal Borough of Kensington and Chelsea, and a data breach at IKEA's TaskRabbit marketplace.
4/20/2018 • 4 minutes, 56 seconds
Weekly discussion podcast #12: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: www.itgovernance.co.uk/shop/product/…digital-world
4/19/2018 • 5 minutes, 32 seconds
Weekly discussion podcast #11: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: www.itgovernance.co.uk/shop/product/…digital-world
4/13/2018 • 5 minutes, 20 seconds
6 April Weekly podcast: Panera Bread, Grindr and MyFitnessPal
This week, we discuss responses to data breaches at Panera Bread, Grindr and Under Armour's MyFitnessPal
4/6/2018 • 5 minutes, 49 seconds
Weekly discussion podcast #10: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: www.itgovernance.co.uk/shop/product/…digital-world
4/6/2018 • 5 minutes, 30 seconds
Weekly discussion podcast #9: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: www.itgovernance.co.uk/shop/product/…digital-world
3/22/2018 • 4 minutes, 54 seconds
23 March Weekly podcast: National Lottery, Russian cyber warfare and Cambridge Analytica
This week, we discuss a credential-stuffing attack on Camelot, heightened fears over Russian cyber attacks and, inevitably, Cambridge Analytica/Facebook.
3/22/2018 • 5 minutes, 49 seconds
16 March Weekly podcast: ICO GDPR campaign, Gwent Police, Binance and MediaGet
This week, we discuss the ICO's new GDPR campaign for micro businesses, a potential data breach at Gwent Police, a US$250,000 reward from Binance and Windows Defender stops a massive malware campaign
3/16/2018 • 6 minutes, 7 seconds
Weekly discussion podcast: Security in the Digital World
This week’s extract is taken from Graham Day’s book: Security in the Digital World. This must-have guide features simple explanations, examples and advice to help you become security-aware in a developing digital world. Find out more: https://www.itgovernance.co.uk/shop/product/security-in-the-digital-world
3/15/2018 • 2 minutes, 40 seconds
9 March Weekly podcast: Memcached DDoS attacks, Equifax (once again) and Alexa
This week, we discuss the biggest distributed denial-of-service attacks on record, another 2.4 million people affected by the Equifax data breach, and Alexa's sense of humour.
3/8/2018 • 5 minutes, 11 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 6
A vital source of information and thought-provoking insights into potential issues within critical information infrastructure (CII).
3/1/2018 • 3 minutes, 3 seconds
23 February Weekly podcast: Reports galore and more cryptojacking
This week, we discuss new reports from Cisco, McAfee and the CSIS, and Big Brother Watch, and hear more about malicious Monero mining.
2/22/2018 • 5 minutes, 27 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 5
A vital source of information and thought-provoking insights into potential issues within critical information infrastructure (CII).
2/22/2018 • 4 minutes, 52 seconds
16 January Weekly podcast: Browsealoud cryptojacking, Bee Token phishing and Olympic attacks
This week, we discuss the use of cryptocurrency mining software on numerous government websites, a phishing scam that robbed Bee Token investors of $1 million and cyber attacks on the Pyeongchang Winter Olympics
2/16/2018 • 5 minutes, 36 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 4
A vital source of useful information and thought-provoking insights into potential issues within critical information infrastructure (CII).
2/14/2018 • 4 minutes, 6 seconds
09 February Weekly podcast: Grammarly, Infraud and Octoly
This week, we discuss breaches at Grammarly and Octoly, and the arrest of leading members of the Infraud cyber crime group.
2/8/2018 • 5 minutes, 16 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 3
A vital source of useful information and thought-provoking insights into potential issues within critical information infrastructure (CII).
2/7/2018 • 3 minutes, 40 seconds
02 January Weekly podcast: Australian Cabinet Files, Matt Hancock MP's app and Monero mining
This week, we discuss the Australian government's loss of thousands of classified documents, DCMS Secretary of State Matt Hancock's buggy new app and the growing trend of cybercriminals using cryptocurrency miners.
2/1/2018 • 5 minutes, 43 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 2
A vital source of information and thought-provoking insights into potential issues within critical information infrastructure (CII).
1/31/2018 • 3 minutes, 24 seconds
26 Jan Weekly podcast: cyber attacks on UK likely, Trump malware, more Spectre & Meltdown problem
This week, we discuss Norton's new Cyber Security Insights Report, the inevitability of a category one cyber attack on the UK, unofficial PDFs of Fire and Fury spreading malware, and further fallout from the Spectre and Meltdown CPU vulnerabilities
1/25/2018 • 5 minutes, 49 seconds
Weekly discussion podcast: Critical Information Infrastructure, Part 1
A vital source of information and thought-provoking insights into potential issues within critical information infrastructure (CII).
1/24/2018 • 4 minutes, 14 seconds
19 January Weekly podcast: Meltdown and Spectre SCADA problems, Apple text bomb and WEF cyber risks
This week, we discuss further problems caused by patches for the Meltdown and Spectre vulnerabilities, a text bomb that crashes Apple devices and the World Economic Forum's Global Risks Report 2018.
1/18/2018 • 4 minutes, 44 seconds
12 January Weekly podcast: Carphone Warehouse, USB drives, VTech and Patch Tuesday
This week, we discuss a £400,000 ICO fine for Carphone Warehouse, an unfortunate prize from Taiwan's Criminal Investigations Bureau, a $650,000 FTC settlement for VTech and the highlights of this month's Patch Tuesday.
1/11/2018 • 4 minutes, 52 seconds
05 January Weekly Podcast: A recap of the top stories of 2017 and a look ahead to 2018
This week, we look back at the big news from last year, and consider what the next 12 months have in store.
1/4/2018 • 8 minutes, 59 seconds
08 December Weekly podcast: NCSC and Kaspersky, parliamentary passwords and macOS High Sierra
This week, we discuss the NCSC's warning to senior civil servants, the poor password habits of MPs, and a bug in the patch Apple rushed out last week.
12/7/2017 • 6 minutes, 41 seconds
1 December Weekly podcast: Imgur, Uber (again), Apple vulnerability, NHS Digital
This week, we discuss a data breach affecting 1.7 million Imgur users, the 2.7 million UK victims of the Uber breach, a major security flaw in macOS High Sierra, and a new investment in data security from the NHS.
11/30/2017 • 5 minutes, 17 seconds
24 November Weekly podcast: Uber, Tether, Bitcoin and Western Union
This week, we discuss Uber's cover-up of a 2016 breach that compromised 57 million drivers' and customers' personal information, the theft of almost $31 million worth of USDT and more than €100,000 worth of Bitcoin, and good news for victims of Western Union transfer scams.
11/24/2017 • 5 minutes, 38 seconds
17 November Weekly podcast: Jewson, Huddle, Equifax (yet again)
This week, we discuss security breaches at Jewson and Huddle, and Equifax's post-breach losses.
11/17/2017 • 4 minutes, 9 seconds
09 November Weekly Podcast: Ethereum, Maersk, Paradise Papers, Yahoo and Equifax (yet again)
This week, we discuss a vulnerability that's caused $280 million of cryptocurrency Ethereum to be frozen, the cost of NotPetya to AP Moller-Maersk, the data breach at law firm Appleby, and the former Yahoo and Equifax CEOs grilling by Senators.
11/9/2017 • 5 minutes, 32 seconds
03 November Weekly podcast: Hilton breach, WordPress SQL injection and ICO helpline
This week, we discuss Hilton's settlement following breaches in 2014 and 2015, an important WordPress update that fixes a SQL injection vulnerability, and a new phone service to help small organisations prepare for the GDPR.
11/3/2017 • 4 minutes, 56 seconds
27 October Weekly podcast: Bad Rabbit, Kaspersky Lab and the Data Protection Bill
This week, we discuss a new strain of ransomware, Kaspersky’s new ‘comprehensive transparency initiative’, and the latest Data Protection Bill news.
10/26/2017 • 5 minutes, 19 seconds
20 October Weekly Podcast: WPA2 Krack attack, Iranian brute force, pizza and Microsoft
This week, we discuss the WPA2 protocol's susceptibility to attack, claims that Iran subjected the UK's parliamentary email system to a brute-force attack, breaches at pizza vendors, and an alleged security slip-up at Microsoft that exposed a database of unfixed vulnerabilities.
10/20/2017 • 5 minutes, 17 seconds
12 October 2017 - Weekly podcast: Accenture, Disqus and Equifax (yet again)
This week, we discuss the exposure of four unsecured Accenture servers to the Internet, how Disqus handled its data breach, and bad news for Equifax's UK customers.
10/12/2017 • 5 minutes, 25 seconds
06 October Weekly Podcast: Every Yahoo! account breached, Equifax update, Conservative conference
This week, we discuss 3 billion compromised Yahoo! accounts, the latest Equifax news, and Home Secretary Amber Rudd's opinion of technology experts
10/5/2017 • 4 minutes, 51 seconds
29 September Weekly podcast: Deloitte and Equifax breaches
29 September Weekly podcast: Deloitte and Equifax breaches by IT Governance
9/28/2017 • 4 minutes, 28 seconds
21 Sept Weekly podcast: ransomware and its ethics, and the celebrities that endanger your business
This week we discuss the Locky/FakeGlobe ransomware campaign, the moral quandary facing cyber criminals, and the worst celebrities to search for online – from a security point of view, that is
9/21/2017 • 3 minutes, 54 seconds
15 September Weekly podcast: Equifax, Facebook and Kaspersky
This week, we discuss the Equifax data breach, a fine for Facebook and a ban for Kaspersky.
9/14/2017 • 4 minutes, 51 seconds
08 September Weekly podcast: SLC, MacEwan University and the return of the Shadow Brokers
This week we discuss a phishing scam affecting students, a Canadian university’s loss of C$11.8 million, and an increase in data dumps from the Shadow Brokers.
9/7/2017 • 4 minutes, 9 seconds
1 September Weekly podcast: Onliner Spambot, Notts County Council and WikiLeaks
This week, we discuss the exposure of 711 million email addresses by a spambot's server, a £70,000 ICO fine for Nottinghamshire County Council, and a cyber attack on WikiLeaks.
8/31/2017 • 4 minutes, 44 seconds
25 August Weekly podcast: swiftQueue, Neymar and FTSE 350 cyber governance
This week, we discuss an data breach at an NHS contractor, the hacking of FC Barcelona’s Twitter account, and a new government report on cyber security awareness.
8/24/2017 • 4 minutes, 53 seconds
18 August Weekly Podcast: Holyrood attack, NotPetya (again) and retail breaches double
This week, we discuss a brute-force attack on the Scottish Parliament, the ongoing costs of June's NotPetya attacks, and a double in the number of data breaches affecting the retail sector.
8/17/2017 • 5 minutes, 44 seconds
11 August Weekly Podcast: Home Sec duped, NotPetya, MalwareTech nicked, new data protection bill
This week, we discuss a prankster’s email conversation with Amber Rudd, the ongoing effects of the NotPetya malware pandemic, the arrest of WannaCry sinkholer Marcus Hutchins by the FBI, and the launch of a data protection bill to implement the GDPR in the UK
8/10/2017 • 4 minutes, 19 seconds
04 August Weekly podcast: Amazon Echo, Android banking malware and Cardiff billboard
This week, we discuss a vulnerability that could allow attackers to turn your Amazon Echo into a wiretap, a new strain of the Svpeng mobile banking malware and the hacking of a digital billboard to display right-wing messages.
8/3/2017 • 3 minutes, 49 seconds
27 July Weekly podcast: Budapest bug, hackable car wash and Unicredit breach
This week, we discuss the arrest of a well-meaning Hungarian teenager, vulnerabilities in Internet-connected car washes that could cause them to physically attack users, and data breaches at Italy's biggest bank.
7/27/2017 • 3 minutes, 46 seconds
21 July Weekly Podcast: Newcastle City Council, Myspace and Apple
This week, we discuss a data breach affecting adoptees in Newcastle, Myspace's account recovery process, and a security update fixing 47 iOS flaws
7/24/2017 • 4 minutes, 17 seconds
14 July Weekly Podcast: Trump Hotels breach, Microsoft, and the GDPR Report
In this week's podcast, we discuss another breach at Trump Hotels, a change in how Microsoft collects user data, and the GDPR Report 2017.
7/13/2017 • 3 minutes, 44 seconds
Author Podcast: Fundamentals of Information Risk Management Auditing, with Christopher Wright
Christopher Wright, author of 'Fundamentals of Information Risk Management Auditing', sits down with us and talks about his book. Buy this book here: https://www.itgovernance.co.uk/shop/product/fundamentals-of-information-risk-management-auditing
7/7/2017 • 15 minutes, 12 seconds
7 July Weekly podcast: AA (aagaain), NotPetya decrypted? and Bithumb hacked
This week, we discuss another incident response debacle at the AA, the latest move from the NotPetya group, and the hacking of the Bithumb virtual currency exchange.
7/6/2017 • 5 minutes, 36 seconds
30 June Weekly podcast: The AA, MPs’ emails and Petya/NotPetya
This week, we discuss a password reset at the AA, a cyber attack on parliamentary emails and the NotPetya malware attack.
6/29/2017 • 5 minutes, 54 seconds
23 June Weekly podcast: Skype, the $1 million ransom and the Queen
This week, we discuss a DDoS attack on Skype, a ransomware attack on South Korean web hosting firm Nayana, and the UK government's new Data Protection Bill
6/22/2017 • 3 minutes, 43 seconds
16 June Weekly Podcast: Council fined for DPA breach, bumper Patch Tuesday and new Mac malware
This week, we discuss a £100,000 fine for Gloucester City Council, a new set of post-WannaCry patches for unsupported Windows versions, and two new strains of Mac malware
6/15/2017 • 4 minutes, 45 seconds
9 June Weekly podcast: EternalBlue (again), new USB compromise and widening cyber skills gap
This week, we discuss the use of the EternalBlue exploit to distribute new payloads after WannaCry, a vulnerability that will give access to network credentials via locked computers, and news that there will be 350,000 cyber security job vacancies by 2022.
6/8/2017 • 4 minutes, 26 seconds
2 June Weekly podcast: Basildon council, cosmetic surgery clinic hacked, WannaCry not spread by XP
This week, we discuss a £150,000 fine for Basildon Borough Council, a data breach affecting a Lithuanian cosmetic surgery clinic, and news that the recent WannaCry ransomware attack may not have spread via Windows XP.
6/1/2017 • 3 minutes, 50 seconds
Author podcast: ISO27001 in a Windows Environment, with Brian Honan
Brian Honan, author of 'ISO27001 in a Windows Environment', sits down with us and talks about his book. Buy this book here: https://www.itgovernance.co.uk/shop/product/iso27001-in-a-windows-environment-third-edition
This week we discuss a phishing attack target BT customers, a major vulnerability in Twitter, and a vulnerability in the Samsung Galaxy S8
5/25/2017 • 4 minutes, 12 seconds
18 May Weekly Podcast: WannaCry summarised, and DocuSign, Brooks Brothers and Zomato breached
This week we provide an overview of the WannaCry ransomware worm, and discuss a number of recent data breaches.
5/18/2017 • 5 minutes, 38 seconds
12 May Weekly podcast: Guardian Soulmates, Persirai botnet, 'crazy bad' Microsoft RCE vulnerability
This week, we discus a data breach affecting the Guardian Soulmates dating site, a new IoT botnet potentially affecting 120,000 IP cameras, and the worst Windows remote code execution vulnerability 'in living memory'.
5/11/2017 • 5 minutes, 51 seconds
Author podcast: Managing Information Security Breaches, with Michael Krausz
Michael Krausz, author of 'Managing Information Security Breaches - Studies from real life', sits down with us and talks about his book. Buy this book here: https://www.itgovernance.co.uk/shop/product/managing-information-security-breaches-studies-from-real-life-2nd-edition
5/10/2017 • 13 minutes, 38 seconds
05 May Weekly podcast: Google Docs, $100 million phishing campaign, Intel critical vulnerability
This week, we discuss a new Google Docs spam campaign, name the companies involved in a $100 million phishing scam, and discuss a seven-year old Intel vulnerability.
5/4/2017 • 4 minutes, 35 seconds
28 April Weekly podcast: Skype/Spyke, Android MilkyDoor malware and Linksys router vulnerabilities
This week, we discuss a Skype vulnerability called Spyke, new Android malware that gives attackers access to networks via infected devices, and vulnerabilities affecting 25 models of Linksys router
4/27/2017 • 4 minutes, 46 seconds
21 April Weekly podcast: data breaches at InterContinental Hotels, RingGo and Allrecipes
This week, we discuss data breaches affecting customers of InterContinental Hotels, RingGo and Allrecipes, those companies’ handling of the incidents, and how incident handling will be affected by the EU’s new data protection law.
4/20/2017 • 5 minutes, 59 seconds
14 April Weekly podcast: Wonga, prisoners and Agas
This week we discuss a data breach that may have compromised the personal information of more than 250,000 Wonga customers, the enterprising cyber crimes of four Ohio prisoners, and a series of security flaws that could allow anyone to control your Aga.
4/13/2017 • 5 minutes
07 April Weekly podcast: LastPass (again), NHS phishing, garage doors and Samsung smart TVs
This week, we discuss a new vulnerability in LastPass's browser extensions, phishing at the Leeds Teaching Hospitals NHS Trust, Internet-connected garage door opener Garadget, and a new exploit that hacks Samsung smart TVs via radio signals.
4/6/2017 • 5 minutes, 18 seconds
31 March Weekly podcast: Honda and Flybe fined, WoW phishing, Minecraft malware, gift cards attacked
This week, we discuss companies falling foul of existing laws while attempting to comply with the GDPR, problems for Warcraft and Minecraft players, and a bot attack affecting gift cards on nearly 1,000 websites.
3/30/2017 • 5 minutes, 24 seconds
24 March $100 million phishing scam, Yahoo (again), LastPass vulnerabilities, and ICO GDPR report
This week, we discuss the arrest of a Lithuanian man over a $100 million phishing scam, an indictment against the alleged perpetrators of the Yahoo breach that compromised half a billion accounts, a number of vulnerabilities affecting LastPass's browser extensions, and the ICO's warning to local councils to prepare for the GDPR
3/23/2017 • 5 minutes, 15 seconds
17 March - Weekly Podcast - Fraud, phishing and fighting the cyber threat
This week, we discuss new reports from KPMG, Beaming and the NCSC, which cover a huge increase in cyber fraud, the massive business cost of phishing, and how to fight the "significant and growing" cyber threat.
3/16/2017 • 4 minutes, 23 seconds
10 March Weekly podcast: Shamoon, Year Zero and Confide
This week, we discuss the re-emergence of the Shamoon/Disttrack malware, a new trove of CIA documents from WikiLeaks and "numerous security vulnerabilities" in an app used by President Trump's aides.
3/9/2017 • 3 minutes, 53 seconds
Weekly podcast: Cloudflare, Cloudbleed, CloudPets and Yahoo
This week, we discuss the Cloudbleed bug, a breach affecting CloudPets, and the latest news from Yahoo.
3/2/2017 • 4 minutes, 50 seconds
24 February Weekly podcast: Operation BugDrop, Georgia-Pacific and the DHS
This week, we discuss a large-scale cyber-reconnaissance operation, a former system administrator who caused $1 million of damage, and access problems at the US Department of Homeland Security
2/23/2017 • 4 minutes, 54 seconds
17 Feb Weekly podcast: Yahoo breached, university attacked by lampposts & WordPress blogs defaced
This week, we discuss yet another Yahoo breach, a university attacked by its own Internet of Things network, and a WordPress vulnerability that leaves blogs open to defacement.
2/16/2017 • 6 minutes, 12 seconds
10 February Weekly podcast: Sports Direct, fileless malware and remote printer hijacking
This week, we discuss a hack that Sports Direct didn’t tell its staff about, a spate of malware attacks against enterprise networks, and 150,000 printers churning out ASCII robots.
2/9/2017 • 5 minutes, 10 seconds
3 February Weekly podcast: Telemarketing, NHS botnet, charity DPA breaches and goodbye LeakedSource!
This week, we discuss a Florida telemarketing company leaking hundreds of thousands of sensitive files, Google apparently mistaking the NHS network for a botnet, 11 charities breaching the data protection act, and the demise of LeakedSource
2/2/2017 • 5 minutes, 24 seconds
20 January Weekly Podcast: NHS cyber attack, new White House appointment and killer squirrels
This week, we discuss a cyber attack on England’s biggest NHS trust, the appointment of Rudi Giuliani to a White House cyber security committee and new research into the biggest threat to critical infrastructure (hint: for once it’s not cyber attack).
1/19/2017 • 4 minutes, 35 seconds
13th January Weekly podcast: Hello Kitty, school ransomware and airport security concerns
This week, we discuss the reappearance of the exposed Hello Kitty database, a warning from Action Fraud about ransomware attacks on schools, and an unsecured airport system leaking passenger data.
1/12/2017 • 4 minutes, 28 seconds
23 December Weekly Podcast: cyber security in review
This week, we look at the biggest stories of the year.
12/22/2016 • 15 minutes, 45 seconds
16 December Weekly Podcast: Yahoo breached again, plus TalkTalk and Ashley Madison
This week we discuss the compromise of another 1 billion Yahoo records, the sentencing of the boy responsible for the TalkTalk breach, and Ashley Madison's $1.6 million settlement
12/15/2016 • 4 minutes, 57 seconds
9 December Weekly podcast: Dailymotion, Europol and Scotland Yard
This week, we discuss a massive data breach at Dailymotion, a very serious data breach at Europol, and the Met Police's novel way of bypassing iPhone encryption.
12/8/2016 • 4 minutes, 42 seconds
2 December Weekly podcast: National Lottery, Mirai botnet, free rides in San Francisco
This week, we discuss suspicious activity on online National Lottery players’ accounts, 900,000 Deutsche Telekom routers knocked offline by the Mirai botnet, and a ransomware attack on the San Francisco transport system.
12/1/2016 • 3 minutes, 39 seconds
25 Nov Weekly podcast: Remote ATM jackpotting; WordPress; Three mobile customer data compromised
This week, we discuss a jackpotting malware attack that caused cash machines across Europe to spit out cash, a WordPress RCE vulnerability affecting 27% of the web, and a data breach affecting more than 133,000 Three customers.
11/24/2016 • 4 minutes, 31 seconds
17 November Weekly podcast: TalkTalk teen, biggest breach of the year, Tesco Bank again, Adobe fined
This week, we discuss the 17-year-old who admitted to last year’s TalkTalk cyber attack, the compromise of more than 400 million ‘adult’ accounts, further news about the Tesco Bank breach, and a $1 million fine for Adobe Systems.
11/17/2016 • 4 minutes, 58 seconds
Weekly podcast: UK adopts GDPR, £2.5 million stolen from Tesco Bank, youngest Cyber Challenge winner
This week, we discuss the government’s confirmation that the GDPR will apply in the UK, the online theft of £2.5 million from 9,000 Tesco Bank Current accounts, and the youngest ever winner of the Cyber Security Challenge.
11/10/2016 • 3 minutes, 59 seconds
4 Nov Weekly podcast: UK Cyber Security Strategy, malware delays ops & inept cyber criminal caught
This week, we discuss the launch of the UK’s National Cyber Security Strategy for 2016 – 2021, a malware attack on Northern Lincolnshire and Goole NHS Foundation Trust, and how a cyber criminal was caught by the FBI
11/3/2016 • 4 minutes, 38 seconds
28 October Weekly Podcast: Dyn DDoS attack, Mirai botnet and more mega breaches
This week, we discuss theMirai botnet DDoS attack that affected the Dyn Managed DNS service and, with it, many household names, plus mega breaches compromising the personal data of millions of Weebly, Modern Business Solutions and FourSquare users.
10/27/2016 • 3 minutes, 43 seconds
21 Oct Weekly podcast: Get Safe Online Day, Microsoft zero-days, alleged LinkedIn hacker arrested
This week, we discuss new cyber crime statistics released to mark Get Safe Online Day, a handful of zero-day vulnerabilities affecting Windows machines, and the arrest in Prague of a Russian man in connection with a number of high-profile cyber attacks – including the 2012 LinkedIn hack.
10/21/2016 • 6 minutes, 4 seconds
14 October Weekly podcast: American 1 burger ban, gaming currency and DXXD ransomware
This week, we discuss American 1 declining Wendy’s transactions for poor security, criminals using gaming currency to launder money and new strain of ransomware DXXD.
10/13/2016 • 5 minutes, 24 seconds
7 October Weekly Podcast: TalkTalk, Facebook and Yahoo
This week, we discuss a record ICO fine for TalkTalk, new encryption for Facebook, and state surveillance of all Yahoo Mail
10/6/2016 • 4 minutes, 46 seconds
30 September Weekly podcast: i-Dressup breach, Yahoo aftermath and cyber security awareness
This week, we discuss the compromise of 2.2 million teens' i-Dressup accounts, the aftermath of the massive 2014 Yahoo breach, and cyber security advocacy campaigns ECSM and NCSAM.
9/29/2016 • 5 minutes, 7 seconds
23 September Weekly podcast: Cisco, Tesla and cyber insurance
This week, we discuss a new Cisco vulnerability, a remote attack on Tesla cars, and the implications of the new Insurance Act on cyber security insurance policies
9/22/2016 • 4 minutes, 27 seconds
16 September Weekly podcast: Solid-gold cyber crime, the Great British Firewall, & the Federal CISO
This week, we discuss the theft of £88,000 worth of gold by criminal hackers, ambitious plans from the NCSC's new CEO, and the appointment of the first Federal Chief Information Security Officer.
9/15/2016 • 3 minutes, 42 seconds
9 September Weekly podcast: Brazzers, 98 million Russians, and Owen Smith MP
In this week’s podcast, we take a look at two incidents in which credentials from historic data breaches have appeared on the web, and a password mistake by Owen Smith MP.
9/8/2016 • 2 minutes, 33 seconds
2 September Weekly podcast: Dropbox, G20 and financial cyber crime, and electoral fraud
This week we discuss the compromise of 68 million Dropbox accounts, cyber security in the international financial sector, and the illegal hacking of voter registration systems in the US
9/1/2016 • 5 minutes, 1 second
26 August Weekly podcast: Epic Games, Ashley Madison and Jimmy Wales
This week we discuss the Epic Games data breach, Ashley Madison's woeful security, and an exaggerated report about Jimmy Wales's death.
8/25/2016 • 3 minutes, 38 seconds
19 August Weekly podcast: Sage insider, HEI hotels POS malware, and NSA hacked
This week, we discuss a data breach at software company Sage, a malware attack on hotel and resorts chain HEI, and the attempted auction of alleged US "cyber weapons" by hacking group the Shadow Brokers…
8/18/2016 • 3 minutes, 42 seconds
12 August Weekly Podcast: Bug bounty programmes and vulnerable Volkswagen
In this week's podcast, we look at Apple's bug bounty programme, two vulnerabilities in cars and a 19-year-old's recent bug bounty success.
8/11/2016 • 2 minutes, 38 seconds
Author Podcast: The Tao of Open Source Intelligence, with Stewart Bertram
Stewart K. Bertram, author of 'The Tao of Open Source Intelligence', sits down with us and talks about his book. Buy this book here: http://www.itgovernance.co.uk/shop/p-1692-the-tao-of-open-source-intelligence.aspx?utm_source=social&utm_medium=soundcloud
8/10/2016 • 11 minutes, 26 seconds
29 July Weekly podcast: O2 customer data, ransomware, and this month's breaches
This week, we discuss O2 customer data appearing on the dark net, a new affiliate programme for ransomware, and this month’s list of data breaches and cyber attacks.
7/28/2016 • 2 minutes, 51 seconds
21 July Weekly Podcast: Congress, Steemit and Kickass Torrents
This week, we discuss a DDoS attack on the US Library of Congress, a cyber attack that cost Steemit users $85,000, and the arrest of the alleged founder of the world's most visited illegal file-sharing site, Kickass Torrents
7/21/2016 • 3 minutes, 12 seconds
Author Podcast: Beginning your EU GDPR compliance project, with Alan Calder
Alan Calder, the author of EU GDPR – A Pocket Guide, joined us to discuss the GDPR and how organisations should get started.
7/18/2016 • 6 minutes, 48 seconds
15 July Weekly podcast: UK rail cyber attacks, hotel malware, Datadog breach & questions answered
This week, we discuss a series of major cyber attacks on the UK rail network, a malware attack at Omni Hotels & Resorts affecting 50,000 cards and a data breach at SaaS platform Datadog, and answer a listener question about the new EU-US Privacy Shield
7/14/2016 • 4 minutes, 35 seconds
08 July Weekly podcast: Police & healthcare breaches, post-Brexit phishing, and Privacy Shield news
This week, we discuss new analysis of police data breach information, the rise of phishing campaigns capitalising on post-referendum uncertainty, data security incidents in the health sector, and (nearly) answer your question on EU-US data transfers.
7/7/2016 • 4 minutes, 26 seconds
01 July Weekly Podcast: Hard Rock breached, Plymouth teen in court, and terrorist database exposed
This week, we discuss the second breach to hit Hard Rock Hotel & Casino in just over a year, a Plymouth teenager in court for carrying out DDoS attacks, a database of terrorists exposed to the Internet, and what the referendum means for cyber security.
6/30/2016 • 4 minutes, 13 seconds
24 June Weekly podcast: University data breach, US voter data compromised, and questions answered
This week, we discuss a disgruntled former student hacking Greenwich University, the exposure of 154 million American voters’ unprotected personal information, and answer listeners’ questions on data protection legislation.
6/23/2016 • 4 minutes, 25 seconds
03 June Weekly podcast: Windows zero-day, and MySpace account details for sale, and GDPR
This week, we discuss a Windows zero-day vulnerability on sale for $90,000, hundreds of millions of MySpace, Tumblr and LinkedIn account details on the dark web, and consider the implications of the new EU GDPR.
6/2/2016 • 5 minutes, 27 seconds
Author Podcast | Nine Steps To Success: An ISO 27001 Implementation Overview with Alan Calder
Author Podcast | Nine Steps To Success: An ISO 27001 Implementation Overview with Alan Calder by IT Governance
6/2/2016 • 7 minutes, 26 seconds
27 May Weekly podcast: Instagram vulnerabilities, Mumsnet attacker charged, phishing up 250%
This week, we discuss two vulnerabilities in Instagram’s Android app and website, a teenager charged with attacking parenting forum Mumsnet, and a massive increase in phishing attacks. We also ask what you want.
5/26/2016 • 4 minutes, 53 seconds
20 May Weekly podcast: LinkedIn passwords, dodgy doorbells, and security blogger awards
In this week's podcast, we look at a database of LinkedIn login credentials, a smart doorbell with some issues and nominations for the EU Security Blogger Awards 2016
5/19/2016 • 2 minutes, 46 seconds
13 May Weekly podcast: CryptXXX evolution, PerezHilton, Kiddicare, and Bangladesh bank investigation
This week, we discuss the evolution of the CryptXXX malware, two malvertising attacks at PerezHilton.com, a data breach at Kiddicare, and evidence that the criminals who stole $81 million from Bangladesh’s central bank had company…
5/12/2016 • 4 minutes, 11 seconds
Author Podcast: A Manager’s Guide to ISO22301 with Tony Drewitt
May’s book of the month is A Manager’s Guide to ISO22301, which provides a comprehensive, non-technical introduction to business continuity management and the ISO 22301 standard. We recently sat down with the author, Tony Drewitt, and asked him some questions about the book and ISO 22301
5/10/2016 • 19 minutes, 14 seconds
06 May Weekly podcast: Instagram hacked, Pwnedlist pwned, email credentials sold
This week, we discuss the youngest beneficiary of Facebook’s bug bounty programme, a Pwnedlist security flaw that exposed 866 million stolen credentials, and 272.3 million Gmail, Yahoo Mail and Hotmail credentials apparently for sale on the dark web.
5/5/2016 • 2 minutes, 55 seconds
29 April Weekly podcast: Mexican voters, Beautiful People and Minecraft
This week, we look at data breaches affecting the entire Mexican voter database, the exclusive online dating site BeautifulPeople.com, and the Minecraft 'Lifeboat' community...
4/28/2016 • 3 minutes, 36 seconds
Author Podcast: Fundamentals Of Information Risk Management Auditing - Christopher Wright
Christopher Wright, author of 'Fundamentals Of Information Risk Management Auditing' talks to us about his book and why he wrote it.
This week, we consider 400 million vulnerable Android devices, a hosting firm that mistakenly deleted its customers’ websites, a chance to hack the Pentagon, and the sentencing of three Russians on cyber crime charges
4/21/2016 • 3 minutes, 54 seconds
Author podcast: CyberWar, CyberTerror, CyberCrime and CyberActivism with Dr Julie Mehan
Now in its second edition, CyberWar, CyberTerror, CyberCrime and CyberActivism encourages cyber security professionals to take a wider view of what cyber security means, and to make the most of international standards and best practice to create a culture of cyber security awareness that complements technology-based defences.
We recently sat down with the author, Dr Julie Mehan, to find out what encouraged her to write the book.
4/15/2016 • 13 minutes, 19 seconds
15 April 2016 Weekly podcast: EU GDPR, Morrisons lawsuit and a win against ransomware
In this week’s podcast, we discuss the formal approval of the EU GDPR, a lawsuit brought against Morrisons by its own staff, and a tool that recovers encrypted hard drives that have been infected with ransomware
4/14/2016 • 3 minutes, 58 seconds
8 April 2016 Weekly podcast: Personalised phishing, Android Trojan, free pizza & Panama Papers
This week, we examine a phishing scam that includes recipients’ home addresses, an Android Trojan that’s been downloaded 3.2 million times, a vulnerability in Domino’s pizza ordering app, and the big story of the moment: the data breach at Mossack Fonseca.
4/7/2016 • 3 minutes, 17 seconds
1 April 2016 Weekly podcast: Ransomware, Android vulnerability, nuclear submarines & mobile toasters
In this week's podcast, we examine more hospital ransomware attacks, a new Android vulnerability, Trident's cyber security, and a new strain of malware that's making household appliances move
3/31/2016 • 4 minutes, 5 seconds
25 March 2016 Weekly podcast: hospital ransomware, USB trojan and iMessage security
In this week's podcast, we look at another ransomware attacks on hospitals, a new USB trojan and a serious iMessage security flaw.
3/24/2016 • 3 minutes, 44 seconds
Weekly podcast: criminal and legal rewards for hacking, and malvertising
In this week's podcast, we discuss cyber criminals' poor spelling, Google's bug bounty programme and a malvertising spike.
3/17/2016 • 3 minutes, 18 seconds
Weekly podcast: Password security, new JavaScript ransomware, and vulnerable toys
In this week’s podcast, we discuss new statistics on password sharing, a recent spike in ransomware, and a newly discovered vulnerability affecting a children’s tablet
3/10/2016 • 3 minutes, 52 seconds
Weekly podcast: DROWN, Hacking Team and CPS says prosecute Internet trolls
In this week’s podcast, we consider the DROWN vulnerability, the apparent resurrection of Hacking Team, and new CPS guidelines for prosecuting trolls
3/3/2016 • 3 minutes, 4 seconds
Author podcast: ‘Information Security: A Practical Guide’ with Tom Mooney
Published in June 2015, ‘Information Security: A Practical Guide’ sets out to address communicating corporate information security to all of your colleagues.
Alexandra recently sat down with the author, Tom Mooney, to find out what encouraged him to write the book.
2/26/2016 • 13 minutes, 50 seconds
Weekly podcast: MouseJacking, uKnowKids, and Smart Online
This week, we look at a vulnerability affecting wireless mice and keyboards, one firm’s reaction to a security researcher, and the imprisonment of an app developer’s former employee.
Hello, poddlers! This week, we consider the threat of ransomware, the apparent hacking of the Turkish police, a survey of IT professionals, and new security measures for Instagram.
2/18/2016 • 3 minutes, 50 seconds
Weekly podcast: Ransomware, TalkTalk and Privacy Shield
In this week's podcast, we look at a ransomware attack on Lincolnshire County Council, the cost of last year’s TalkTalk's cyber attack and the new EU-US Privacy Shield.
2/4/2016 • 3 minutes, 13 seconds
The Security Consultant’s Handbook
The Security Consultant’s Handbook by IT Governance
1/29/2016 • 17 minutes, 18 seconds
Weekly Podcast: €50 million stolen, medical records lost, bad ads blocked, iPhones crashed.
In this week’s podcast, we look at a €50 million cyber fraud, the loss of nearly one million medical records, Google’s ad blocking efforts, and a bug causing iPhones to reboot
1/28/2016 • 3 minutes, 9 seconds
Weekly podcast: Asda, malvertising and CSI: Cyber
In this week’s podcast, we look at Paul Moore’s discovery of a vulnerability in Asda’s website, malvertising, and the RSA conference’s odd interesting choice of keynote speakers.
1/21/2016 • 3 minutes, 48 seconds
Weekly podcast: why you can’t ignore information security in 2016
In our first podcast of 2016, we explain why information security can't be ignored – by anyone – and consider some recent criminal arrests.
1/14/2016 • 3 minutes, 53 seconds
Weekly podcast: 2015 end-of-year round-up part two
Part two of last week's podcast is now available. Rather than covering the events of the past week, we take a look back at the major information security events of 2015. A transcript of the podcast is available below.
12/21/2015 • 10 minutes, 2 seconds
Weekly podcast: 2015 end-of-year round-up part one
This week's podcast is slightly different. Rather than cover what's happened in the previous week, we take a look back at the major events that have occurred in 2015. A transcript of the podcast is available below.
12/18/2015 • 7 minutes, 36 seconds
VTech, Chinese hackers and hungryhouse
In this week’s podcast, we look at the breach at toy manufacturer VTech, the arrest of the alleged OPM hackers and great information security hygiene at hungryhouse.