Just Unsecure: Recent Episodes

Babz & OO

JU focus is on Information and Cyber Security with discussions on related topics. e.g. News, regulations, threats, education, advisory, interviews and so on focusing on Africa. This is a platform to connect Security Professionals, Managers, Executives and enthusiasts for knowledge sharing and advisory

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series, we will be discussing the roles of CISO vs BISO, who wins? Is it really a competition?

1.W hat is the difference between a CISO and a BISO
2.  Is it time for a dedicated BISO? 
3. CISO Vs BISO
4. BISO Responsibilities
5. BISO Role in the Security Function
6. BISO Soft Skills
7. Is the BISO role still necessary?

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

JustUnsecure , #CISO , #BISO  #cybersecurity, #cloudsecurity, #informationsecurity, #risk , #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series, we will be discussing Achieving Data Residency in Africa

  1. What is Data Residency
  2. Difference between Data residency and Sovereignty 
  3. Why is Data Residency Important to Africa and its businesses
  4. How can you ensure data remains in Africa

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

JustUnsecure , #dataresidency ,  #cybersecurity, #cloudsecurity, #informationsecurity, #risk , #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will be discussing the   Best Way to Organize and run a GRC Programme.

  1. What is governance, risk and compliance (GRC)?
  2. Core GRC principles
  3. Why is GRC important today?
  4. GRC strengths and limitations
  5. GRC software and tools
  6. GRC maturity model
  7. Do's and Don'ts

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

JustUnsecure , #Governanceriskcomplaince ,  #GRC , #Compliance , #cybersecurity, #cloudsecurity, #informationsecurity, #risk , #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we talk about passwords, are they going away soon?

Removing passwords is a solid goal as they are fraught with vulnerability issues – reuse, common construction patterns and the almighty leaked password problem. 

Reasons why most organizations are not ready to abandon on-premises Active Directory and move towards a cloud-only model.  
Reason 1: Hybrid directory will continue to dominate 
Reason 2: Passwordless methods still rely on passwords in the background 
Reason 3: Cybersecurity risks associated with passwordless

Do not neglect password security

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

JustUnsecure #passwordless, #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO , #identitytheft , #Africa

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we have a discussion on Blockchain and Identity Management with a Software development and engineering  manager with over 15 years of experience and one of the pioneers in  identity management in Nigeria. His areas of interest  spans different sectors.

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

blockchain,  #identitymanagement, #Smart contract , #DLT , #Didtributed Ledger transaction , #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO , #identitytheft , #Nigeria

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Deep Fake: New Cyber Security Warfare?

Deepfakes (a portmanteau of "deep learning" and "fake"[1]) are synthetic media[2] in which a person in an existing image or video is replaced with someone else's likeness. While the act of faking content is not new, deepfakes leverage powerful techniques from machine learning and artificial intelligence to manipulate or generate visual and audio content with a high potential to deceive.

We look at 
1. Hyper-Connectivity Provides Opportunity
2. Deepfakes Present a Major Security Threat
3. Audience Manipulation
4.  Role of  Security Leaders

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

#Deepfake #warfare #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Prioritizing Patching in Cybersecurity

Just an overview that  FortiGuard Labs has found that very few vulnerabilities see widespread exploitation in the wild. Among all exploits logged by their sensors over the last two years, only 5% were detected by more than 10% of organizations. Three out of four exploits didn’t reach one in 1,000 firms.
What to do lets go through this 

  1. Asset Inventory 
  2. Risk assessment 
  3. Exploit and Vulnerability being exploited in the wild
  4. Patch Internet/Public  facing
  5. Industry compliance requirement 

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

#patching #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about CISO & Deep Dark Web

  1. What is the difference in the type of web
  2. How is the Dark Web Relevant to a CISO?
  3. What to do within the dark web
    4.. Some examples of how Dark Web intelligence could be relevant to your security operations:
    -Tracking the development and sale of malware and exploit kits
    -Monitoring data dumps that could contain your IP
    -Finding stolen credentials such as login passwords belonging to your organization
    -Discovering vendors on the Dark Web actively selling access to corporate networks and MSPs
    -You require Combatting Cyber Fraud that might directly affect your customers or the business that you support. E.g. recent trojan targeted at android users to steal their banking details.

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

#Darkweb #cybersecurity, #cloudsecurity, #informationsecurity, #web, #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Active Directory Security

  1. Agree on a Frame work categories.
  2. Establish Priorities
  3. Develop the Strategy and Projects as a Team

  4. Keep Your Strategy Flexible

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

#enterprise security #Activedirectory #cybersecurity, #cloudsecurity, #informationsecurity, #NIST, #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we wrap-up 2021 and look at some highlights and what to expect for 2022.

informationsecurity,#cybersecurity,#infosec,#InformationSecurity,#CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about User friendly Security

We look at the current Security Myth
If the interface is easy to use, it’s less secure.
If it’s secure, it’s more difficult to use.

and some steps to take in ensuring user friendly security  
1. Involve a UX designer  
2. Get Stakeholders Involved in UX Security Early
3. Design Methods for Security Solutions
4. Build for Trust: End to End Encryption
5. Authentication
6. Enhance User Privacy and Data Privacy
7. Remove Unnecessary Security Obstacles
8. Secure Against Social Engineering
.

In Conclusion,
Consider and respect users when designing, implementing and operating any security solution or programs. Remember the WEAKEST LINK!

UXSecurity  #enterprise security #phising #cybersecurity, #cloudsecurity, ,#informationsecurity, #cybersecurity, #infosec,

InformationSecurity, #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about antidotes to ransomware
Agenda
1. What is Ransomware
2. Antidotes to ransomware such as
   A. Enterprise Protection
   B. Minimize the Impact 
   C.SEGMENTATION & ISOLATION 
   D. Understand how Ransomware works (Breaking the Cyber Kill Chain)
   E. RESPONSE

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

Ransomware #enterprise security #phising #cybersecurity, #cloudsecurity, ,#informationsecurity, #cybersecurity, #infosec,

InformationSecurity, #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Zero trust architecture design principles and how we view each principles by the United Kingdom's  National Cyber Security Center.

To know more you cango to  https://www.ncsc.gov.uk/collection/zero-trust-architecture

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

Zerotrust #Zerotrustprinciples #architectcture #cybersecurity, #cloudsecurity, ,#informationsecurity, #cybersecurity, #infosec, #NCSC,

InformationSecurity, #CISO

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about a national cyber security policy and strategy with a pioneer and advocate for cyber security in Nigeria. He is no other than Olusegun Olugbile , the DG/CEO Araba Technologies Ltd (an emerging technology solution provider),
Executive Chairman of Data Analytics Privacy Technology Ltd - Owner of NDPR365-SaaS Brand, President, Global Network for Cybersolution Ltd/gte - Driver of Africa Digital Alliance (afrida),
Member, Board of Directors, International Centre for Emerging Technology-FUT Minna
Member, National Cybercrime Advisory Council, Presidency (2015 till date)
Member, National Committee on the Review and Development Cybersecurity Policy Strategy. 2014 & 2020
Former Member United Nation Internet Governance Multistakeholders Advisory Group to UN Secretary General.
Member/Fellow on Digital Economy, Abuja Chambers of Commerce & Industry, and International Chambers of Commerce Nigeria Chapter.

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

Nigeria #Cyberpolicy #cybersecurity, #cloudsecurity, ,#informationsecurity, #NIST, #cis, #iso, #CISO, #cis, #isms, #securityawareness, ##ITsecurity

cybersecurity, #infosec,

dataprotection, #Cybercrime,

cyberattacks, #digitalsecurity,

riskmanagement, #databreach,

passwords, #networksecurity,

netsec, #cybersecurityawareness,

InformationSecurity, #dataprivacy, #GDPR,

infosecurity ,#hacking,

CISO ,computing…

SHOW LESS

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Cloud Access Security Broker (CASB)

Gartner defines the cloud access security broker market as products and services that address security gaps in an organization’s use of cloud services. Especially designed to protect and control access to data that’s stored in someone else’s systems, CASBs deliver differentiated, cloud-specific capabilities that generally aren’t available as features in traditional security products.

We will focus on the follwoing 
1. The Core functionalities of CASB
2. CASB Vendors
3. Integration to CASB
4. Advanced CASB features
5. What to avoid when selecting CASB

Remember to SUBSCRIBE, SHARE , LIKE and COMMENT

CASB #CloudAccessSecurityBroker #Informationsecurity #Cloudsecurity

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about OWASP TOP 10 Draft review 2021 focusing on the following

  1. What is New in OWASP TOP 10 2021
  2. What's behind the decision to review it
  3. How it affects developers and organizations
  4. Mitigations to con spider

Listen, Like, Subscribe and Share

OWASPTOP10 #cybersecurity, #cloudsecurity, #informationsecurity, #CISO,

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we are honored to have our guest speaker, Foster Kplomdo, discuss NIST Cyber Security Framework.

As an experienced technology and security professional, He has worked in leadership roles across multiple technology disciplines in several multinational companies, as an instructor with some of the reputable academic institutions in the country and as a consultant to several businesses. 

With over 17 years of progressive experience in the technology industry, a knack for research and drive for process optimization and knowledge sharing, Foster knows how to concretely define problems, prescribe solutions and execute them towards  helping  businesses and professionals maximize their potentials.

Hope you enjoy the session like we did. 

Remember to SUBSCRIBE, LIKE and SHARE

NIST #NISTCSF #informationsecurity #cloudsecurity ##cybersecurity #infosecurity #africacybersecurity # Riskmanagment  #securityassessment #Ghana #infosecAfrica

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about August security news and HOT TOPIC -How to prepare for Security Audit in your organisation
Top Cybersecurity News in August are
1. An Inside Look at Soliciting Employees to Deploy DemonWare
https://abnormalsecurity.com/blog/nigerian-ransomware-soliciting-employees-demonware/

  1. Google and Microsoft said they are pledging to invest a total of $30 billion in cybersecurity advancements over the next 5 years.
    https://thehackernews.com/2021/08/microsoft-google-to-invest-30-billion.html

  2. Telecom giant T-Mobile recently suffered yet another data breach.
    https://thehackernews.com/2020/03/hackers-compromise-t-mobile-employees.html

There are mainly 11 Key steps when preparing for a security audit
Step 1: Scope and Gap Analysis - Audit Standard Selection (ISO, PCIDSS, GDPR, IT Audit or Statutory Audit) and interfaces
Step 2:Create an IT Asset Inventory
Step 3: Risk Assessment
Framework for Risk Assessment - NIST 800:53 or Specific policy requirement. Template and Procedure
Step 4: Close Gaps
Step 5: Review findings from Previous Audits
Step 6: Review and Create IT Policies and Procedures - (Operating Standard) as well as
create a List of Controls and Safeguards
Step 7: Perform a Self-assessment
Step 8: Schedule Tests or Deliverables
Step 9: Ask Your Auditor for a Document/Procedure Checklist
Step 10: Be Prepared for Anything

NOTE: ENSURE TO TALK ABOUT THE RESULTS AND AGREE ON THE REPORT BEFORE BEING PRESENTED IN THE CLOSING MEETING TO MANAGEMENT

SUBSCRIBE, LISTEN and SHARE

Securityaudit #audit #CyberSecurity,#informationsecurity #cloudsecurity ##cybersecurity #infosecurity #africacybersecurity #NIST # Riskmanagment #policies #procedures #certification #securityassessment #ISO27001 #ISMS

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about  the BEST Cyber Security Framework for your organisation. We will talk about

  1. What is a framework
  2. Types of Frameworks
  3. Cybersecurity Frameworks
          -NIST Cybersecurity Framework.
          -ISO 27001 and ISO 27002
          -Clod Control Matrix (CCM)
          -Payment Card Industry Data Security Standard (PCI DSS)
          -Center of Internet Security

SUBSCRIBE, LISTEN and SHARE

CyberSecurity,#informationsecurity #cloudsecurity #ISO27001#NIST #Cloudcontrolmatrix #CCM #PCIDSS #CIS #Centerofinetrnetsecurity#cybersecurity #infosecurity #africacybersecurity #owaspsecurity,#healthcaresystem,#privacyprotection,#databreach

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about  some security news ,  events and HOT TOPIC

  1. July 2021 Patch Tuesday: Greatest Number of Updates for Ongoing Zero-Day Vulnerabilities Year-to-Date 
    https://www.crowdstrike.com/blog/patch-tuesday-analysis-july-2021/ 

  2. LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries
    https://9to5mac.com/2021/06/29/linkedin-breach/

  3. China Sets Up New Worrying Vulnerability Disclosure Rules
    https://www.bitdefender.com/blog/hotforsecurity/china-sets-up-new-worrying-vulnerability-disclosure-rules 

  4. Kaseya obtains decryption key for vicitims of massive Ransomware Attack
    https://www.cyberscoop.com/kaseya-ransomware-russia-revil/

  5. HOT TOPIC - API SECURITY
    https://owasp.org/www-project-api-security/

https://github.com/OWASP/API-Security/raw/master/2019/en/dist/owasp-api-security-top-10.pdf

SUBSCRIBE,LISTEN and SHARE

View Details

This is all about driving, measuring and management of Security culture in an organization. Our guest Richard  Uhunmwagho is a seasoned cybersecurity & data privacy leader with years of experience across various sectors, leveraging my knowledge and expertise across diverse geographical regions, sectors, and regulated industries.

Professional focal points include Information Security/IT Risk management, IT Governance (GRC), Regulatory Compliance Assurance, Data Privacy and Protection, Business continuity & Operational Resiliency, Internal Audit, Security Awareness & Training and successfully managing enterprise risk management programs - end-to-end.

He has helped organizations set up and run effective security awareness programs with the intended objectives in changing human behaviours and habits in dealing with cyber threats.

Enjoy the session like we did and do not forget to LIKE , SUBSCRIBE, LISTEN and SHARE 

SecurityAwareness #SecurityinOrganisations #SecurityCulture

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security news , events hot topics such as the

VULNERABILITIES

  1. New Chrome 0-Day Bug Under Active Attacks – Update Your Browser ASAP!
    https://thehackernews.com/2021/06/new-chrome-0-day-bug-under-active.html

  2. Vulnerabilities Expose Fortinet Firewalls to Remote Attacks
    https://www.securityweek.com/vulnerabilities-expose-fortinet-firewalls-remote-attacks

  3. Fastly's global outage: Here's what went wrong
    https://www.zdnet.com/article/fastlys-global-outage-heres-what-went-wrong/

  4. Attackers are hunting for this critical VMware vCentre flaw
    https://www.zdnet.com/article/patch-now-attackers-are-hunting-for-this-critical-vmware-vcentre-flaw/

BREACHES

  1. Largest password data breach in history has been leaked online
    https://techxplore.com/news/2021-06-largest-password-breach-history-leaked.html

  2. Hackers Steal Wealth of Data from Game Giant EA
    https://www.vice.com/en/article/wx5xpx/hackers-steal-data-electronic-arts-ea-fifa-source-code

  3. Exclusive: NATO Classified Cloud Platform Compromised
    https://ddosecrets.substack.com/p/exclusive-nato-classified-cloud-platform

ATTACKS

  1. New TLS Attack Lets Attackers Launch Cross-Protocol Attacks Against Secure
    https://thehackernews.com/2021/06/new-tls-attack-lets-attackers-launch.html

9.Al Jazeera repels cyber-attacks that sought to disrupt media network
https://portswigger.net/daily-swig/al-jazeera-repels-cyber-attacks-that-sought-to-disrupt-media-network

MALWARE

  1. This data and password-stealing malware is spreading in an unusual way
    https://www.zdnet.com/article/this-data-and-password-stealing-malware-is-spreading-in-an-unusual-way/

ARREST

  1. Feds seize two domains used by SolarWinds intruders for malware spear-phishing op
    https://www.theregister.com/2021/06/02/feds_seize_nobelium

UPDATES and POLICIES
12. DOJ recovers pipeline ransom, signals more aggressive approach to cybercrime
https://blog.malwarebytes.com/malwarebytes-news/2021/06/doj-recovers-pipeline-ransom-signals-more-aggressive-approach-to-cybercrime/

  1. NIST Publishes Ransomware Guidance
    www.infosecurity-magazine.com/news/nist-publishes-ransomware-guidance

GOOGLES GOOD DEEDS

Google Expands Open Source Vulnerabilities Database

https://github.com/google/osv

https://osv.dev/list

Google open-sources tools to bring fully homomorphic encryption into the mainstream
https://github.com/google/fully-homomorphic-encryption

Thanks for listening and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE

Security News #cybersecurity #InformationSecurity #cloudsecurity #cloud #Change

vulnerabilities #securityawareness #datasecurity #Breach

cybernews #cybersecurityafrica #cyberattack #Securitynews

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk to a special guest on Business Security Architecture

He is Oluwaseyi Ojo. An alumnus of John F. Kennedy School of Government, Executive Education Program of the prestigious Harvard University. A seasoned Business Security Architect with passion and focus on Governance, Quality, Risk and Compliance and deep competencies in Cybersecurity Management, Business Security Architecture, Enterprise Architecture, Enterprise Risk Management, IT Governance, Project Management, Business Continuity Management, Cyber Threat Intelligence, Network Security, Cloud Security, Digital/Cloud Forensics, Solution Architecture, Information Security and Assurance. 

BusinessSecurityArchitecture #informationsecurity #SecurityArchitecture #cybersecurity #Africa #CyberAfrica #CybersecurityAfrica

Thanks for Listening and do not forget to SUBSCRIBE, LISTEN and SHARE

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about  some security events, news , hot topics  such as the 

-Cisco HyperFlex web interface has critical flaw 
-Nagios IT monitoring vulnerabilities 
-Canada Post reveals supplier data breach
- Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices 
-FBI issues warning about Fortinet vulnerabilities after APT group hacks local gov’t office 
-Over 40 Apps With More Than 100 Million Installs Found Leaking AWS Keys
-Experts warn of a new Android banking trojan stealing users' credentials
-CISA used new subpoena power to contact US companies vulnerable to hacking
-UK funds new African cybercrime office
-Top 10 Services that should not be exposed to the Internet directly
-FBI to share compromised passwords with Have I Been Pwned
-WARNING!!!
Nobelium (The Hackers known for Solarwinds hack) launched this week’s attacks by gaining access to the Constant Contact account of USAID.

Thanks for watching and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE

cybersecurity #InformationSecurity #cloudsecurity  #cloud

vulnerabilities #securityawareness  #datasecurity #Breach

cybernews #cybersecurityafrica #cyberattack

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk to a special guest on adapting Security Operations to the new realities - DevSecOps.

She is a certified InfoSec&GRC professional with an MSc in Computer Security and Audit and an MBA in HRM. She is  currently working for one of the biggest UK retailers. 

She is one of the early certified CISSP in Nigeria. Her name is Aijay Okani 

Thanks for watching and do not forget to SUBSCRIBE, LISTEN and SHARE

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about  some security events, news , hot topics  such as the 

-Security Researcher Dan Kaminsky is dead
-F5 Big-IP Vulnerable to Security-Bypass Bug
-NSA: Top 5 vulnerabilities actively abused by Russian govt hackers
- Checklist for Offboarding Remote Employees 
-REvil ransomware gang claims it stole top-secret tech designs 
-Hundreds of customer networks hacked in Codecov supply-chain attack
-Password manager Passwordstate hacked to deploy malware on customer systems
-Tiki app aims to hand ownership of personal data back to the individual

Thanks for watching and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE

View Details

Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about  some security events  such as the 

-FBI, CISA warn Fortinet FortiOS vulnerabilities are being actively exploited
-NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers
-Four in 10 South African ransomware victims pay the criminals 
-Security pro seizes expired DR Congo top-level domain, takes over 50% of DNS traffic
-Major BEC Phishing Ring Cracked Open with 3 Arrests
-CISA releases tool to review Microsoft 365 post-compromise activity

Thanks for watching and do not forget to follow us on Twitter, LinkedIn, Spotify, Google and Apple podcast.

View Details

Hello and welcome to our Podcast on Information and Cyber Security , This episode we will talk about the following

  1. Who we are
  2. Why now
  3. What is Just Unsecure and Purpose
  4. Biggest lessons so far
  5. Pitfalls
  6. Security Topic of the week. Our own Opinions on the Topics below.
    • Mobile and Privacy Security -Both iOS and Google Android Privacy issues.
    • Supplier risk management - The SolarWinds compromise
  7. Vulnerabilities
    • Microsoft Exchange Server vulnerability (Proxy Logon
  8. WHAT WILL YOU DO (Question for Us)
    • You receive a document from a third party vendor that you are to fill out in regards to your company's security processes, tools, etc.   Upon opening the document you realize that it is already filled out with another companies details. You now have the Head of IT and Security's full details. The companies policies, processes, list of tools etc.

The other company is located  in Europe. What should I do and who should I report to?

Thanks for listening