Cyber Security

Web site scanning without prior permission is very likely illegal, here’s why

It appears that there is a growing wave of SaaS utilities that will either scan websites and internet-based services for you or provide you with access to historical information on sites and services they have already scanned, often for a fee. Unfortunately, using such services can result in your seriously falling foul of the law Read more about Web site scanning without prior permission is very likely illegal, here’s why[…]

The Defence in Depth Security Model Explained

The Defence in Depth Security Model is one of those security concepts I often see incorrectly implemented or not used to its full potential to protect services or systems. There is way more to it than first meets the eye. In this article you will learn: What is the Defence in Depth Security Model? The Read more about The Defence in Depth Security Model Explained[…]

robots.txt Pen Test extension

Given that I’m seeing an increase in unauthorised, and essentially illegal, Pen Tests against business production instances, which only serve to: Test the firewalls around your production instance (rather than testing the application code directly), Put at serious risk the availability of the web service under ‘test’ by consuming resources that should be only used Read more about robots.txt Pen Test extension[…]

Continuous Pen Testing – Pros and Cons

It seems quite a few businesses are resorting to using 3rd parties to implement continuous pen testing for not only their own products but also for online services they also consume – this can be a very bad idea and lead to a false sense of security. In the face of it regularly scanning an Read more about Continuous Pen Testing – Pros and Cons[…]

Singapore’s TraceTogether Token

Singapore has developed a physical token to enable elderly and vulnerable people to easily be contact traced without the need of having the TraceTogether app. The device also overcomes some of the issues that are being faced with the mobile app, including battery drainage and issues when the app is running in the background or Read more about Singapore’s TraceTogether Token[…]

Security Event Logging, why it is so important

Every once in awhile I get asked why detailed event logging is so important when setting up cybersecurity controls at a business. In this article will attempt to explain why this is critically important. To log or not to log, that is question… When it comes to logging security events and being able to make Read more about Security Event Logging, why it is so important[…]

Cyber Security

How much should you spend on an external PenTest?

External Penetration Tests today come in all shapes and sizes, from the rudimentary highly automated scanning to the more detailed and human-driven PenTests, with often widely ranging costs to boot (3 to 4 times difference is not unusual for essentially the same thing). Sometimes it’s difficult to work out what form of external PenTest is Read more about How much should you spend on an external PenTest?[…]

Cyber Crime

Encrypt Email addresses at Rest

It seems not a day goes by without some major data breach occurring on businesses systems. Anywhere from a few thousand records to many millions at a time, containing information ranging from names, addresses, telephones number, dates of birth and account details, etc. One thing I have noticed, that seems to be a constant throughout Read more about Encrypt Email addresses at Rest[…]

Latest print of book is out

This a quick post to say that I have just received the latest print of my book, now updated to cover off recent changes in legislation, plus some changes from feedback given by readers – much thanks! This makes the book even more useful to those looking to properly secure personal information in businesses and Read more about Latest print of book is out[…]

Will the last AU based start-up please turn off the light?

It appears the Australian Federal Government is determined to do a Thelma & Louise and literally drive off a cliff into the abyss over truly mindless and ill-conceived legislation as concerns encryption, privacy and security. It has the potential to make us totally uncompetitive in global information technology markets and cut off at the knees a fledgling Read more about Will the last AU based start-up please turn off the light?[…]

First book published

This a quick post to say that my first book has now been published on Amazon. In total its taken a good 9 months from the initial idea. The book focusses on Personal Information Security and how in business personal information needs to be secured and protected. The book is full of lots of practical Read more about First book published[…]

Personal Information Security

Securing Personal Information in a business is a critical undertaking. Failure to appropriately secure Personal Information can result in information breaches, heavy fines and a loss of business reputation which could impact the long viability of a business. In most countries, it is a requirement when handling Personal Information to abide by privacy regulations. This Read more about Personal Information Security[…]

PII Hacking

Privacy and Security go hand in hand

In our modern world its difficult to comprehend how many systems hold various bits of information on you, it ranges from banks, credit score agencies, dentists, all the way to SaaS providers and your telco. Social networks also have mountains of information on you that they mine to work out your personal preferences, so they Read more about Privacy and Security go hand in hand[…]

API Security – Carefully does it!

API’s are a convenient and handy way to get different computers systems to talk to each other, but often they are also an easy way to get in by the backdoor deep into computer systems. In this article, we look at few of the most common mistakes made and what you can do about it. Read more about API Security – Carefully does it![…]

Code Reviews for Businesses

Are you a business using outsourced software development and you are not sure of the quality of the code being written? Concerned that the code quality won’t be able to support your growing business? Unsure whether the code is secure and following the regulations required for your business sector? Aykira can help you, we are Read more about Code Reviews for Businesses[…]

Australian Privacy Policy

Privacy and Your Business, what are the risks?

Privacy is a big concern if you are running a business, regardless of size. All businesses need to keep sensitive information about their customers, staff, associations and potential customers – all of this will contain information that pertains to individuals which could cause them (and you) harm if illegal accessed or divulged. Further the ability Read more about Privacy and Your Business, what are the risks?[…]

KRACK – Securing Your Wifi Network

Given the release of the KRACK vulnerability, it is becoming very clear you need to take additional steps to make your Wifi network more secure. You should take this as a wake up call to understanding the risks inherent with a Wifi network and just how easily it can be used to gain access into Read more about KRACK – Securing Your Wifi Network[…]