5 Items to Consider When Choosing a Pen Test Provider

pen test provider

As security professionals with nearly two decades in the industry, we understand the significance of choosing the right penetration testing service provider. It’s important to not only look for testers with the technical skills required but they should be trustworthy highly experienced, credible and deliver on their promises of testing, reporting and remediation. They should […]

Going Beyond Cyber Essentials Plus Certification

Cyber essentials plus

Once you have successfully attained Cyber Essentials Plus (CE+) certification and the celebrations are over, what do you do? Do you just sit back and be happy that CE+ has been achieved or do you build upon it? Well, it all depends on why you undertook to achieve CE+ in the first place. Many companies […]

Amazon Alexa subdomains are not safe for work

Alexa

Amazon Alexa subdomains have been found to be vulnerable to Cross-Origin Resource Sharing and Cross-Site Scripting. Exploiting these would have allowed an attacker to install or remove apps without the user’s knowledge and gather information about the device and the user(s). It would have only required one click from a specially crafted amazon link. IoT […]

What Are the Benefits of Cyber Essentials Plus?

CE Plus Benefits

Certifying to Cyber Essentials Plus Although many organisations pursue Cyber Essentials Plus (CE+) certification in order to meet public sector contract requirements, there are other numerous benefits of Cyber Essentials Plus. These are self-evident to most information security professionals, but in case you’re struggling for words here they are. Reassure customers that you are working […]

Privacy Shield Becomes Invalid

privacy shield

The EU-US Privacy Shield was invalidated on the 16th of July 2020 by a ruling of the EU Court of Justice (CJEU). This ruling was done in the case known as Schrems II (C-3111/18). This case challenged the processes for personal data transfers between the EU and the US on the basis to hold that […]

Team Viewer Password Crack 

A CVE (CVE-2020-13699) was announced in Team Viewer’s Windows Application Successful exploitation of this highlighted vulnerability would allow an attacker to open Team Viewer via a malicious web application. This could then be leveraged to force Team Viewer to send a password to the attacker for cracking. ​ The affected Team Viewer versions are: teamviewer10, […]

Mitigate Application Layer Attacks

Mitigate Application Layer Attacks

Secure your applications to avoid over 43% of breaches Did you know the primary applications used by most businesses are web applications (i.e. websites)? Attacks against web applications are attacks on the application layer. Verizon’s 2020 data breach report suggests web applications were involved in 43% of known breaches. Statistics cannot be used to account […]

How to Choose an UKAS Accredited ISO 27001 Auditor

ISO 27001 Auditing Company

ISO 27001 Accreditation Bodies UK Before choosing an ISO certification body for your ISO 27001 certification you need to understand the reasons for obtaining the certificate. Many clients want the ISO certificate to demonstrate to clients and partners that they take information security seriously. Others have requirements for certification to allow them to bid for […]

Risk-Driven Application Security Testing Services

Risk-Driven Application Security Testing Service

We’re proud to announce this new service.  Risk Crew, the elite group of information security governance, risk & compliance experts, and the forerunners in the design & delivery of innovative & effective solutions, has released Risk-driven Application Security Testing Services.  What is the service for?  The Risk-driven Application Security Testing Service is a proven process […]

Risk Crew