Cyber 3-2-1: Recent Episodes

Sam Glynn

Plain English Cyber through 3 articles, 2 numbers and 1 action. Each weekly episode is recorded by Sam Glynn of Code in Motion (www.codeinmotion.ie). If you prefer to read rather than listen, you can subscribe to the Cyber 3-2-1 newsletter at https://www.codeinmotion.ie/blog.

View Details

This week: In the last episode of the show in 2023, I find a way to connect internal auditors, pigs, and Ronseal.

Links to all articles mentioned this week are available at https://codeinmotion.ie/cyber321-20231217/.


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: A few stories to bring cyber security a little closer to home:

3 – Cyber security concerns at the world’s largest store of plutonium.

2 – Cyber security attacks on our water supply.

1 – One cyber attack that impacted at least 80 law firms, and delayed house purchases.

Glass Half Full: To put a positive spin on all of these stories: If things aren’t going well for you this December, at least you don’t work in a nuclear plant, a water treatment plant, or a company that now faces difficult questions from at least 80 legal firms!

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20231210/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week:

3 – Backups are important even when you use the cloud.

2 – You need to check all of your doorways.

1 – Why the pain of DORA will be worth it.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20231203/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: As many of you may currently be finalising your income generation strategies for 2024, here’s the Top 3 from the world of cyber crime:

  • A new entry at #3: Using the regulators.
  • Back at #2: Using cyber attacks.
  • But still at #1, for the 1197th week in a row: Using your staff!

Links to this week's articles are accessible from https://codeinmotion.ie/cyber321-20231124/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: What the world of cyber security can tell us about the Individual Accountability Framework (IAF), and why CISO may stand for ‘Career is Sadly Over’. PLUS Why your execs are special!Links to this week's articles are accessible from https://codeinmotion.ie/cyber321-20231117/.


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: A ransomware attack on China’s biggest bank; Don’t just worry about your regulators. Worry about your insurers; And if you are going on a BOOKING.COM holiday, watch out for the phish.

Links to this week's articles are accessible from https://codeinmotion.ie/cyber321-20231110/.


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: Why do they rob IT providers / SaaS services / legal firms? Because that’s where the data / money / reputations are.

Links to all articles are provided at https://codeinmotion.ie/cyber321-20231020/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: Insider threat is becoming a bigger threat; don’t forget your website, and what Noodles the Pooch can teach us about cyber security training.Links to all articles are available from https://codeinmotion.ie/cyber321-20231013/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: The 10 signs that your IT partner is just not into you, why your insurance policy may increase the likelihood of a cyber attack, and new Microsoft Teams but same old security risks.

Links to all articles are available from https://codeinmotion.ie/cyber321-20231006/


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: CISA launches ‘Secure Our World’, a UK logistics firm closes with 730 job losses after suffering a ransomware attack, and why a recently-discovered flaw with Apple devices is actually a good news story.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230929/.


Hi, I'm Sam Glynn, founder of Code in Motion.

Code in Motion helps organisations demonstrate that they have taken reasonable steps to manage cyber security risk.

To learn more, go to https://www.codeinmotion.ie


View Details

This week: Microsoft stops charging extra for seatbelts; Your User account is still an attacker’s BFF; and many UK business leaders talk about the importance of cyber security but do not prioritise it.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230724/.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: I am joined by guest, Pádraig Mac Donnchadha, as we discuss the mesmerising effect of a real-time cyber attack map, a vulnerability in a popular WordPress plugin, ChatGPT and tin foil as effective security measures.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230707/.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Deepfakes are going mainstream, UK law firms have been warned about an increase in cyber attacks, and Irish SMEs need to close their front doors.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230630/.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Australia’s largest law partnership is attacked, Capita faces a legal battle, and UK banks want social media platforms to pay for online fraud.

PLUS An interview with Carina Myles of Eisner Amper on how firms should approach DORA compliance.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230623/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: A look at the 2023 Verizon Data Breach Investigation Report: 95% of attackers are financially-motivated. Ransomware is one of their favourites, and email continues to be the most common way in.

You can download the VBIR report at https://www.verizon.com/business/resources/reports/dbir/ 


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: It's a big week in cyber security world, as the 2023 Verizon Data Breach Investigations Report has just been published. I’ll talk about its key findings next week (but here’s a sneak peak – “74% of breaches involve the human element”). In the meantime, news about a cyber attack in Mazars in Brazil, how 0.1% of emails may be the cause of 66% of all breaches, and the 5 most common ways that Irish people are fooled by cyber criminals.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230609/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: It’s a bank holiday weekend here in Ireland, and for some strange reason, the sun is also out. So, I was planning to keep this week’s Cyber 3-2-1 light-hearted. But now that I look at the stories I’ve picked – insider threats; 16,000 victims of cyber fraud; and warnings about our children becoming money mules – I’m not so sure. Anyway, I hope it’s sunny wherever you are.

Links to all articles are available from https://codeinmotion.ie/cyber321-20230602.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Ransomware encryption is so 2022, Microsoft 365 login pages are destined for Greatness, and we need to be politely paranoid.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Irish doctors are terrified about ransomware, Australian firms are under attack, and the Swedish regulator issues a €75 million sanction.

For links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230519/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Phishing remains the biggest threat to businesses, the board is having the wrong conversations about cybersecurity, and navigating the content of the DORA regulation just got easier.

Links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230512/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: AI could mean bye-bye to your account security, the future of passwords is passkeys, and what the Central Bank of Ireland has to say about DORA.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: I interview Jason Scanlon to discuss the psychological impact of a cyber attack. Also in the news this week, there’s no silver lining for Google’s Cloud Services, your new car may be a risk to your privacy, and medical devices need cyber security (Ain’t that a surprise!).


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Some terrible news for many vulnerable people. An attack on a HR provider results in a system outage. And phishing is still the most common way for a ransomware attacker to gain access to European organisations.


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: $300k for not keeping software up-to-date, and the need to consider the human element in our security strategy. We ain’t clueless – We’re just overwhelmed.

Links to all articles are available at https://codeinmotion.ie/cyber321-20230414/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Western Digital suffers a cyber attack that takes many of its cloud services offline, a patient’s nude photos are published by cyber attackers, and even CNN’s Donie O’Sullivan is now talking about cyber security.

Links to all articles are available at https://codeinmotion.ie/cyber321-20230407/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week:Two more fines from the DPC and now even EUROPOL is worried about ChatGPT.

Links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230331/


Hi, I'm Sam Glynn.

I help firms with a low risk appetite to manage cyber risks and regulations without losing their sanity.

I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: Bank failure, cyber fraud, security scorecards, and DORA: Just another day in cyber paradise!

Links to all articles mentioned this week, go to https://codeinmotion.ie/cyber321-20230324/


Hi, I'm Sam Glynn.

I help financial services firms that have a low appetite for regulatory attention to manage cyber risks and regs.
I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: This week's episode was recorded on Saint Patrick’s Day. While some people in Ireland may spend the day complaining to their friends in the local pub about the disgraceful stereotype of Ireland as a country full of drinkers, here are a few stories to keep us sober. Sláinte!

Links to all articles mentioned this week are provided at https://codeinmotion.ie/cyber321-20230317


Hi, I'm Sam Glynn.

I help financial services firms that have a low appetite for regulatory attention to manage cyber risks and regs.
I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: What have a €60,000 fine, a €100,000 fine, and Multi-Factor Authentication (MFA) got in common? They are all mentioned in the 2022 Annual Report that has just been published by Ireland’s Data Protection Commission.

Links to all articles are provided at https://codeinmotion.ie/cyber321-20230310/


Hi, I'm Sam Glynn.

I help financial services firms that have a low appetite for regulatory attention to manage cyber risks and regs.
I interpret Cybersecurity Risks and Regulations into Actionable Advice, so you don’t burn Time, Money, or Sanity trying to keep up!

To learn more, go to https://www.codeinmotion.ie

View Details

This week: What are the cybersecurity lessons from Russia’s invasion of Ukraine, why a small business paid a $150k ransom, and why you can no longer trust a phone call.

Plus a roundup of the other articles I've published this week.

Links to all articles are available at  https://codeinmotion.ie/cyber321-20230303/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Another issue laiden down with news about recent cyber attacks, including against a UK financial advisory firm with some very interesting high-value clients.

The action: The 5 steps you need to take right now to avoid the worst-case scenario of a ransomware attack. Plus an offer to ease my conscience.

Links to all articles are provided at https://codeinmotion.ie/cyber321-20230224/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: ENISA predicts the future, a future when even teddy bears need to be cyber aware. And we get a clear answer to the question ‘What did the NCSC ever do for us?’

Links to all articles are available from https://codeinmotion.ie/cyber321-20230217/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Love is in the air, an Irish university responds to a ransomware attack, and CROs believe cyber risk is a higher priority than credit risk.

Links to all articles are available from https://codeinmotion.ie/cyber321-20230210/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: What have traffic lights, JD Sports, and Microsoft OneNote got in common? They all star in this week’s Cyber 3-2-1. Also this week, a reminder as to why regulators are so keen for us to get better at third-party risk management, especially when it comes to our IT service providers.

Links to all of the other articles mentioned this week are available from https://codeinmotion.ie/cyber321-20230203/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: PayPal and Norton breaches, predictions of imminent cyber catastrophe, and taser-equipped drones. What more could you ask for?

The action this week: If you're concerned about your alignment to regulatory guidance in cybersecurity, try my new self-service scorecard. It takes 2 minutes and provides immediate results to show you how you align to some of the Central Bank of Ireland's guidance - You can try it at https://codeinmotion.ie/RegulationScore

Links to all of the other articles mentioned this week are available from https://codeinmotion.ie/cyber321-20230127/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Attacks don’t just happen to valuable targets. Telling staff “Don’t click bad links” isn’t working. And why we need to worry about LockBit. The action this week: If you want to learn more about the past, present, and future of cybersecurity and regulatory compliance, then I have a webinar for you.

Links to all of the other articles mentioned this week are available from https://codeinmotion.ie/cyber321-20230120/


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: There’s one for everyone in the audience, including the board of directors and anyone who relies on an IT MSP to manage their cloud systems. The two numbers this week remind us why invoice fraud is so rampant – Because that’s where the money is!

The thing to think about this week? Take two minutes to try my new toy AND find out your cybersecurity score at the same time. It’s a win-win!

Links to all of the other articles mentioned this week are available from https://codeinmotion.ie/cyber321-20230113


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Happy New Year. If you are an email subscriber, you know I’ve been talking a lot this week about how it’s not so happy for LastPass users, so I will not linger too much on that carnage. Instead, let’s talk about what Ukraine’s Cyber Police, the UK’s NCSC, and Ireland’s DPC have been up to while we’ve been eating too much chocolate.

Here are my recent articles on LastPass:

  • https://codeinmotion.ie/lastpass-security-breach-do-this-now/
  • https://codeinmotion.ie/lastpass-security-breach-q-and-a/
  • https://codeinmotion.ie/password-managers-are-still-recommended/

Links to all of the other articles mentioned this week are available from https://codeinmotion.ie/cyber321-20230106.


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: An outsourced HR provider reports a breach 60 days after it was identified, the European Commission agrees a new directive to oblige service providers to do better, and what the data protection regulators think about security.

Links to all of the articles mentioned this week are available from  https://codeinmotion.ie/cyber321-20221216.


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week:Cyber criminals favour ZIP files, RAR files, and PayPal. Even the big firms are moving to the cloud. And CISA shows us how one security layer may not be enough to protect us.

Links to all of the articles mentioned this week are available from  https://codeinmotion.ie/cyber321-20221209.


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Microsoft and Proofpoint remind us of the value of some simple security measures. The problem with Android security patches. And why the theft of millions of phone numbers from WhatsApp may get our attention, but our local laptop repair shop may be a more immediate concern.

Links to all of the articles mentioned this week are available from  https://codeinmotion.ie/cyber321-20221202.


If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

As a first step, use my 'Secure Foundation Scorecard' to get your Security Score and see how your current security protects you.

It's free, it takes two minutes and you get tailored advice immediately.

We can then schedule a 30 minute call to review your security gaps and identify quick things you can do right now to improve your defences.

GET YOUR SCORE at https://score.codeinmotion.ie.

View Details

This week: Surveys by INTERPOL, the Bank of England, and by Northwave Security on the mental impact of an attack. Plus: Anti-virus software is proven to block ransomware. But only if it’s actually running and up-to-date.

Links to all of the articles mentioned this week are available from  https://codeinmotion.ie/cyber321-20221125.

If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

Give me 30 minutes of your time, and I will show you - No jargon, no upsell. Just independent advice to help you keep your sanity.

Click here to book your Cyber Sanity Call.

View Details

This week: What have Howard Hughes and Liverpool FC got to do with cybersecurity? Plus: Health data of 5 million Australians has been leaked on the dark web. And I polish my graphic design skills to explain why passwords are bad and MFA is good.

This week’s action is inspired by James Clear of Atomic Habits - Is your issue a lack of information or a lack of action?

Links to all of the articles mentioned this week are available from  https://codeinmotion.ie/cyber321-20221118.

If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

Give me 30 minutes of your time, and I will show you - No jargon, no upsell. Just independent advice to help you keep your sanity.

Click here to book your Cyber Sanity Call.

View Details

This week: “It will never happen” is a bold claim. “It will _probably_ never happen” is a more realistic and achievable position. Plus: LinkedIn, the ICO, and comedy gold from Seinfeld.

Links to all articles are available from https://codeinmotion.ie/cyber321-20221111

If you are accountable for IT and cybersecurity but you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

Give me 30 minutes of your time, and I will show you - No jargon, no upsell. Just independent advice to help you keep your sanity.

Click here to book your Cyber Sanity Call.

View Details

This week: Don’t worry about zero-days. Don’t worry about passwords. And don’t worry about your code (if you’re a software company).

This week’s action:Do you share the concerns of 48% of Board-level cyber experts?

Links to all articles mentioned in this week's episode are available at https://codeinmotion.ie/cyber321-20221104

If you are accountable for IT and cybersecurity, especially if IT is not your area of expertise and you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

Give me 30 minutes of your time, and l will prove it to you - No jargon, no upsell. Just independent advice.

Click here to book your Cyber Clarity Call.

View Details

This week: Pig butchering, LinkedIn profile culls, and law firm cyber.

This week’s action: Are you prepared to bet your professional reputation on one decision?

Links to all articles mentioned in this week's episode are available at https://codeinmotion.ie/cyber321-20221028

If you are accountable for IT and cybersecurity, especially if IT is not your area of expertise and you rely on a third-party to manage all of this for you, I can help you ensure you have reasonable security in place to defend against the most common cyber attacks.

Give me 30 minutes of your time, and l will prove it to you - No jargon, no upsell. Just independent advice.

Click here to book your Cyber Clarity Call.

View Details

This week: How a 15 year old stole $24m. Don’t worry about deepfakes - Worry about phishing emails. And it’s not impossible to defend against ransomware attacks.

This week’s action: Don’t trust your phone company with your house keys.

Links to all articles mentioned in this week's episode are available at https://codeinmotion.ie/cyber321-20221021

View Details

This week: What has the HSE cyber-attack got to do with skyscrapers, and how hackable are you?

This week’s action: If you work for yourself and have concerns about a cyber attack, I may have a solution for you.

Links to all articles mentioned in this week's episode are available at https://codeinmotion.ie/cyber321-20221014

View Details

This week: This month and last month, Ireland’s police, government and national cybersecurity agency have warned SMEs about the ever-increasing threat of cyber attacks. And yet executives and boards will continue to deliberately ignore this risk until their valuables have been stolen.

This week’s action: You are choosing your own adventure. Make sure you are comfortable with your choice.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20221007

View Details

This week: 58% of cyber incidents start with a phishing email. Plus: North Face, LastPass, and Uber: 3 breaches; many lessons.

This week’s action: On the internet, we’re all Capricorns.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220923.

View Details

This week: A password manager breach, ransomware triple extortion, cybersecurity for startups, and why the gamer in your life may be a risk in your life.

This week’s action: Love your children. But don’t trust them.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220916/.

View Details

This week: Cyber insurance cover continues to reduce, Bank of America begins training high schoolers to be cybersecurity experts, and a security flaw in a WordPress plugin exposes 140,000 websites.

This week’s action: Who is minding your shop front?

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220909/.

View Details

This week: The bad guys are after your money and your phone is their way in (part 1 and 2). And in future, you can’t trust the sound of someone’s voice or their image on a screen.

This week’s action: SMS-based MFA is better than Sweet-FA. But Authenticator apps are better than SMS.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220902.

View Details

This week: Police warn SMEs about the increasing threat of ransomware, an Amazon security director reminds us about the basics, and it hasn’t been a good week for Apple.

This week’s action: Keep up-to-date on software updates by subscribing to my alert list.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220826

View Details

This week: Criminals are using Google Drive and Dropbox to avoid detection, Microsoft names-and-shames a cyber broker, and Apple announces a Lockdown Mode to defend against sophisticated attacks.

This week’s action: Ask for evidence that your applications are being kept up-to-date.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220819.

View Details

This week: Another ransomware attack on an Irish firm, how scammers are increasingly using SMS text messages to get us to part with our money, and how the departure of KBC and Ulster Bank from Ireland isn't helping the situation.

This week’s action: Don’t trust that SMS message.

Links to all articles mentioned this week are listed at  https://codeinmotion.ie/cyber321-20220812.   

View Details

This week: Why browsers are a key part of your security defences, why Uber has done a deal with the US Department of Justice, and why I tend to use quotes around the phrase “crypto investment opportunities”.

This week’s action: If it sounds too good to be true, it probably is.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220805.

View Details

This week: University of Limerick is a victim of invoice redirection fraud; self-driving cars remind us that humans are still useful, and DeFi security continues to defy logic.

This week’s action: Come to Limerick. Fly from Shannon. Just don’t use a self-driving car to get here.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220729/

View Details

This week: A ransom payment won’t prevent a data protection penalty, LinkedIn is the scammers’ favourite brand, and some of the latest lures used in phishing emails.

This week’s action: It’s time for some cybersecurity refresher training.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220722/

View Details

This week: Multi-factor authentication, multi-factor authentication, 1 billion stolen records, and multi-factor authentication.

This week’s action: Yep, you guessed it: Multi-Factor authentication.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220715/

View Details

This week: 80% of Irish firms hit by ransomware pay the ransom, the US Department of Defense wants to be hacked, but their rewards are peanuts compared to the jackpot of zero days.

This week’s action: Use a safe phone book.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220708

View Details

This week: $100m of Crypto Craziness, €800k of romance fraud, social engineering lessons, and why your backups may no longer save you.

This week’s action: Check your auto-forwarders.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220701/ 

View Details

This week: Some useful reminders that patches are not just for Windows. And while Carlsberg don’t do social media scams, Heineken is not so lucky.

This week’s action: Take a deep breath and pay attention to the devices around us.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220624/.

View Details

This week: Ukraine’s responses to Russian cyber attacks remind us of the value of an incident response plan, why DuckDuckGo is not as privacy-centric as you might think, and why paying a ransom may only mean you’ll be paying one again, and sooner than you may think. 

This week’s action: Reduce the need for an incident response plan by writing one.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220617.

View Details

This week: MFA may be worth Sweet FA, cybersecurity bootcamps may not get you a cybersecurity job, what an Enduring Power of Attorney may teach us about the advisors we trust, and crypto continues to provide plenty of reasons why TradFi is also MoreSecureFi.

This week’s action: Remind staff why their password and MFA security codes are just like their toothbrush.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220610.

View Details

This week: Why a contract doesn’t matter until it’s the only thing that matters. Why the US Department of Defence wants you to do as they say, not do as they do. And why colleges may need to attend a Security 101 class.

This week’s action: Check up on those ‘Access All Areas’ account holders.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220603.

View Details

This week: MFA applies to your Tesla too, cyber insurance is covering less and costing more, and 24% of ransomware payments do not enable the victim to recover their data.

This week’s action:It’s time to test that your backup is more useful than a chocolate teapot.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220527.

View Details

This week: It’s time for hugs: Today is ‘Hug Your IT Provider’ Day. Wednesday was ‘Hug Your Data Protection Officer’ Day. And some day soon, it may be time to hug Microsoft.

This week’s action: Check that your browser is up-to-date.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220520.

View Details

This week: Getting a good night’s sleep is now a little harder. The ransom payment is the least of your worries. And what is appropriate security anyway?

This week’s action: Check that Windows is being kept up to date.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220513.

View Details

This week: Is the end of passwords in sight? Why is a bank warning us about taxis? Why worry about smart glasses? And why do bad guys love crypto wallets and Android devices?

This week’s action: It’s time to do a health check on your Android devices.

Links to all articles are accessible from https://codeinmotion.ie/cyber321-20220506.

View Details

This week: Insurer says solicitors are driving up the cost of cyber insurance, and the SEC says it wants to know what cyber expertise is in the boardroom.

This week’s action: Check your children aren’t roaming the mean streets of the online world.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220429.

View Details

This week: A DeFi platform enables the perfect crime, CISA discovers cyber sabotage tools aimed at US energy sector, and a reminder that we need to keep all software up to date, not just Windows.

This week’s action: Tell your staff about the brands the bad guys love.

Links to all articles are accessible from  https://codeinmotion.ie/cyber321-20220422.

View Details

This week: How Apple AirTags are a stalker’s dream and modern superyachts are a pirate’s dream.

This week’s action:Remind staff that attackers love the Easter holidays.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220415.

View Details

This week: Have you recovered from World Backup Day? Are you running an infected website? And do you know how many people are on a rugby team?

This week’s action: Check your shopfront.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220408.

View Details

This week: The White House advises us all to act now to protect against cyberattacks. A HubSpot breach may have exposed the customer information of crypto firms. And why you should be using a password manager.

This week’s action: When your staff are suspicious, make sure they can get a second opinion.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220401.

View Details

This week: A UK law firm has been fined 98k for not having appropriate security controls to prevent a ransomware attack. A South African insurance firm’s password is no match for cyber attackers who gained access to the data of 54 million customers. And 75% of Irish consumers are concerned about security when they shop online, but only 4% of Irish SME’s have trained their staff in cybersecurity best practice.

This week’s action: Don’t be the 96%: Train, test and support your staff.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220325.

View Details

This week: BNP Paribas blocks Russian staff from its global computer network, your website contact form could be the first step in a cyber attack, and the HSE is about to contact people who data was stolen in last year’s cyber attack.

This week’s action: Remind staff that the first email is not the only one to look out for.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220318.

View Details

This week: Ukrainian internet service provider is attacked, cyber insurance will get more expensive, and what board members should know about cybersecurity. This week’s action: The 7 questions that board members should ask about cybersecurity.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220311.

View Details

This week: Organisations worry about cyber attacks arising from Russia’s invasion of Ukraine, as the Conti Gang that attacked the HSE last year announces their support of the Russian attack, and then learns that it was not its smartest move.

This week’s action: 3-2-1 Backup or 3-2-1 Over.

Links to all articles can be accessed from https://codeinmotion.ie/cyber321-20220304/.

View Details

This week: Ireland’s NCSC issues an advisory, as warnings continue about the elevated threat of cyber attacks due to the ongoing crisis in Ukraine. Also this week, how blind faith in an IT system led to one of the largest miscarriages of justice in the UK, and why the phrase ‘Too big to fail’ may soon be joined by the phrase ‘Too big to understand’.

This week’s action: Bí Ullamh: Consider the NCSC advisory’s recommendations.

Links to all articles, numbers and actions can be accessed from https://codeinmotion.ie/cyber321-20220225/.

View Details

This week: What is SIM Swap Fraud? How to reduce account hacks by 50%? How is GDPR driving demand for EU data centres? And how could the need to report an attack result in better cybersecurity?

This week’s action: Check MFA is turned on for all accounts, especially those used by IT.

Links to all articles are available from https://www.codeinmotion.ie/blog. 

View Details

This week: The Central Bank reminds us that cybersecurity has not gone away. The US Justice Department proves that bitcoin does not necessarily mean anonymous. And a Microsoft study makes me bang my head against a wall.

This week’s action: Baseline like it’s 2016.

Links to all articles are available from https://www.codeinmotion.ie/blog. 

View Details

This week: The National Cyber Security Centre has released a ‘Cyber Vitals Checklist’, just as concerns increase that the current tensions over Ukraine may increase the likelihood of a significant cyber attack on the West.

This week’s action:  Double-check your defences.

View Details

This week: ComReg has a plan to tackle volume of scam calls to Irish mobile users. Google’s trackers are being investigated in the US, while the Austrian Courts have ruled that Google Analytics contravenes GDPR. And the US Federal Reserve starts a discussion about digital currencies.

This week’s action: Don’t answer that call.

Links:ComReg investigation: https://www.thejournal.ie/ireland-scam-calls-taskforce-establish-comreg-5664923-Jan2022/

US investigation of Google cookies: https://www.independent.ie/business/world/american-states-sue-google-over-deceptive-web-tracking-41274142.html

Fathom Analytics: https://www.usefathom.com

US Federal Reserve paper on digital currencies: https://www.federalreserve.gov/publications/money-and-payments-discussion-paper.htm via https://www.ben-evans.com/newsletter

Survey about scam calls: https://www.thejournal.ie/scam-calls-irish-numbers-poll-5490391-Jul2021/

NOYB investigations: https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-analytics-illegal

My 'Cybersecurity without Insanity' workshop: https://www.codeinmotion.ie/workshop

View Details

This week: Could simulated phishing tests really make staff more likely to be fooled by a phishing email in the future? What the Russians have done to one of the world’s most successful ransomware gangs? What has ransomware and cryptocurrency got to do with North Korea? And what the hell is the metaverse anyway?

This week's action: Review your approach to phishing test simulations.

Links:ETH Zurich's phishing test simulation study: https://arxiv.org/pdf/2112.07498.pdf, mentioned at https://www.bleepingcomputer.com/news/security/large-scale-phishing-study-shows-who-bites-the-bait-more-often/ .

Russia's FSB raids on the REvil ransomware gang: https://therecord.media/fsb-raids-revil-ransomware-gang-members/

What is the metaverse, blockchain, etc? https://www.upi.com/Voices/2022/01/14/metaverse-cryptocurrency-blockchain/7591642169034/ via Ron Immick’s Mind Candy Newsletter (https://www.linkedin.com/pulse/mind-candy-15-january-2022-ron-immink )

North Korean cyber criminals stole $400m in 2019: : https://cointelegraph.com/news/north-korean-hackers-stole-400m-in-2021-mostly-eth-chainalysis via Crypto Curry Club’s Crypto Courier (https://www.cryptocurryclub.com/subscribe)

View Details

This week: How the bad guys get a hold of your password, why the US is so concerned about Huawei equipment, and why do large organisations have a CIO AND a CISO?

This week's action: Double-check your two-factor authentication.

Links:

Passwords: https://www.welivesecurity.com/2022/01/05/5-ways-hackers-steal-passwords-how-stop-them/

Huawei:  https://www.bloomberg.com/news/articles/2021-12-16/chinese-spies-accused-of-using-huawei-in-secret-australian-telecom-hack

CIO vs CISO: https://www.darkreading.com/careers-and-people/why-cios-should-be-reporting-to-cisos 

Credential stuffing statistics: https://www.helpnetsecurity.com/2021/05/20/financial-services-credential-stuffing/ 

View Details

This week: The 4 tech trends that we will be reading about in 2022, how to speak to the Board about cyber, and how law firms are getting on with cybersecurity. This week’s action: Keep it simple.