How to Choose an UKAS Accredited ISO 27001 Auditor

ISO 27001 Auditing Company

ISO 27001 Accreditation Bodies UK Before choosing an ISO certification body for your ISO 27001 certification you need to understand the reasons for obtaining the certificate. Many clients want the ISO certificate to demonstrate to clients and partners that they take information security seriously. Others have requirements for certification to allow them to bid for […]

Risk-Driven Application Security Testing Services

Risk-Driven Application Security Testing Service

We’re proud to announce this new service.  Risk Crew, the elite group of information security governance, risk & compliance experts, and the forerunners in the design & delivery of innovative & effective solutions, has released Risk-driven Application Security Testing Services.  What is the service for?  The Risk-driven Application Security Testing Service is a proven process […]

Free Webinar – Protect Against Your Biggest Threat — People

Did you know that human error caused 90% of UK data breaches in 2019, according to the ICO? Register for this free webinar and find out how to mitigate this imminent threat with current best practices and training methods for the workplace – whether that is in the office or at home. Plus you’ll get […]

Can I get Cyber Essentials Plus Certification Remotely?

Cyber essentials plus

Many organisations have sought to achieve Cyber Essentials Plus (CE+) certification remotely (as opposed to on-site) due to the Covid-19 Pandemic. As most staff have continued to work from home, this remote assessment option becomes necessary in order to maintain compliance and assure clients/suppliers that baseline security requirements are being met. Simple steps to complete […]

SAP NetWeaver Contains Remotely Executable Code

Over 40,000 SAP customers need to update to the latest version to mitigate risk from remote unauthenticated attackers obtaining complete access to their SAP database. Although there is no evidence it has been exploited yet, it is only a matter of time before malicious attackers take advantage of this. Don’t let them exploit you! The […]

Should I Be Worried About Mobile Phone Hacking?

“But my phone cannot be hacked!” Phrases like this are far too common and can hold significant consequences. For one, those who believe any device they use is impenetrable are unaware of the threats they face. Historically, these statements have a 100% chance of being wrong and have demonstrated that cyber security is a marathon, […]

Critical RCE Vulnerability in F5 BIG-IP Application Security Servers

This vulnerability gives the CVSS score of 10/10, meaning it could result in unpatched users to be completely compromised. The issue is in the TMUI configuration utility and can be exploited by unauthenticated remote attackers via sending a malicious HTTP request to the vulnerable server. In June, there were over 8000 vulnerable devices that were […]

Webinar: Holistic Security Testing in the New Threat Landscape

Have you ever wanted to know what Holistic Security Testing involves and how it can help create a strong defence against the evolving cyber threat landscape? Download this webinar hosted by Geoffrey Bougnague and stay tuned for the last 15 minutes, when he will open the floor to you, to ask him all your security […]

Risk Crew