Retail News CRM

Tag: cybersecurity

  • Vietnam says Facebook violated cybersecurity law

    Vietnam says Facebook violated cybersecurity law

    Vietnam says Facebook has violated its new cybersecurity law by allowing users to post anti-government comments on the platform. “Facebook had reportedly not responded to a request to remove fanpages provoking activities against the state,” the official said, citing the Ministry of Information and Communication. In a statement, a Facebook spokeswoman said: “We have a clear process for governments to report illegal content to us, and we review all these requests against our terms of service and local law.”

    She did not elaborate. The ministry said Facebook also allowed personal accounts to upload posts containing “slanderous” content, anti-government sentiment and defamation of individuals and organizations, the agency added.

    “This content had been found to seriously violate Vietnam’s Law on cybersecurity” and government regulations on the management, provision and use of internet services, it quoted the ministry as saying.

    Facebook had refused to provide information on “fraudulent accounts” to Vietnamese security agencies, the agency said in Wednesday’s report.

    The information ministry is also considering taxing Facebook for advertising revenue from the platform.

    The report cited a market research company as saying $235 million was spent on advertising on Facebook in Vietnam in 2018, but that Facebook was ignoring its tax obligations there.

    In November, Vietnam said it wanted half of social media users on domestic social networks by 2020 and plans to prevent “toxic information” on Facebook and Google.

  • Global telcos form cybersecurity alliance

    Global telcos form cybersecurity alliance

    Singapore’s Singtel and Japan’s SoftBank have teamed up with UAE-based Etisalat and Spain’s Telefonica to create the first global telco security alliance.

    The new partnership is aimed at providing enterprises with access to a comprehensive portfolio of cyber security services.

    The alliance has a combined 1.2 billion customers with a presence in over 60 countries across APAC, Europe, the Middle East and the Americas, operate 22 security operations centers (SOCs) and employ more than 6,000 security experts.

    Under the agreement, the four operators will share network intelligence on cyber threats and support each other’s customers in allowing them to rapidly respond to cyber threats.

    The operators also plan to develop a joint technology roadmap for creating advanced cyber security applications for the IoT, and consider joint investments in new SOCs, cyber security platforms and startups.

    “We need swift and coordinated global responses to defend enterprises that operate across transnational borders as cyber threats are increasing in frequency, scale and sophistication,” Singtel CEO of global cybersecurity Art Wong said.

    “Singtel and its US-based subsidiary Trustwave are both well-established security leaders across the Asia Pacific, Europe and the Americas. The group’s resources, combined with those of its alliance partners, will provide a robust cyber security platform to protect our global customers, allowing them to thrive in the digital economy.”

    SoftBank head of cloud and cyber security Andrew Schwabecher added that “hackers have well-established and organized communities where they cooperate to produce cyber threats – it’s time that the world’s largest network of operators formed a global alliance to strengthen our defense against these attacks.”

  • China’s cybersecurity law poses major challenges

    China’s cybersecurity law poses major challenges

    The controversial new Cybersecurity Law which came into force at the start of the month in China brings significant change and some uncertainty for companies, but is to be expected in a rapidly evolving environment of new technologies and big data, acording to digital forensics and eDiscovery specialist KrolLDiscovery.

    “Mirroring what is happening all around the world, the Chinese government is becoming more involved with data protection and strengthening enforcement,”  KrolLDiscovery country manager for Shanghai Han Lai said.

    “Up until now, its rules have not been clearly defined or regularly enforced, but this new law is looking to change that, and companies need to be fully up to speed with its requirements, especially network operators managing data.”

    The majority of the new law’s provisions apply to “Critical Information Infrastructure Operators” (CIIO) possessing data critical to China’s security. Industries predominantly targeted in this new definition include financial, transportation, healthcare, utilities and telecommunications.

    The most significant, and controversial, change is that Chinese citizens’ “personal information” and “important data” must now be stored on servers within China. Any companies claiming an exception that is “truly necessary” must undergo a security assessment before information can be released.

    “This will affect the majority of foreign companies that operate in China, in particular those which use their global infrastructure and IT resources to operate their business in China, as the original data collected, including business data and customer data within China will typically be stored directly in the data centres or servers physically located overseas,” Lai said.

    “For example many global companies are still using email servers located outside China for their China operations. Companies need to start thinking and planning ahead to restructure their infrastructure to be in line with the new law.”

    In addition, the new law reinforces the requirement for network operators to obtain their clients’ consent before collecting and disclosing personal information, including the reason for the disclosure, and take measures to ensure the security of personal information.

    “This tightening is commensurate with other developed markets, but will take a while to get used to in China where data on individuals is collected on a mass scale for sales and marketing purposes without proper consent, and probably without awareness of what the risks might be,” remarked Lai.

    From now on, all network providers must also pass a “network security examination.” This includes specific requirements that network operators must follow when purchasing new network systems.

    What is not clear yet, as the law is currently untested, is what the consequences will be of noncompliance, but they are expected to be more severe than in the past, and more rigorously enforced. Cancellation of a business license was one penalty in the previous regulations.

    “The new regulations require CIIO’s to establish violation reporting mechanisms, suggesting that the government is taking the new law very seriously,” noted Lai.

    Lai added, “Companies need to ensure that an appropriate framework is established for collecting and using data, demonstrating that any data collected has a proper purpose and that its use can be explained in detail. Companies should also ensure appropriate security and protection measures are in place to safeguard the data as well as incident response procedures for responding and reporting any breach.”

  • Forbes Japan names Auto-cybersecurity Start-Up Trillium the ‘RISING STAR’ Startup

    Forbes Japan names Auto-cybersecurity Start-Up Trillium the ‘RISING STAR’ Startup

    Forbes Japan, the Tokyo-based edition of Forbes, one of the world’s most authoritative business news medias, celebrated entrepreneurs and Start-ups today at the Annual “JAPAN’S STARTUP” Awards, and the winner of the ‘RISING STAR’ STARTUP OF THE YEAR 2017 Award – Trillium Inc, a Tokyo-based Start-up that has developed a robust, comprehensive cybersecurity solution for the automotive industry.

    The Awards promote start-ups ready to create a ‘New Japan’ – leading the Japanese economy into the next age through innovation and entrepreneurial efforts. Finalists for the ‘RISING STAR’ 2017 were selected by the Forbes Japan editorial team with input from online readers. The winning Start-ups will be featured in the magazine’s Jan 2017 edition, which will appear on Nov 25.

    David Uze, Trillium CEO, an American who has lived in Japan for over 25 years, hopes Trillium can make a valuable contribution to his adopted country. “As autos and electronics are the bedrock of Japan’s prosperity, we believe our cybersecurity solution can help ensure the nation’s economic future. And we are grateful to Forbes Japan for recognizing the importance of our work.”

    “This is another indication that Trillium is on track to emerge as that rarest of creatures, a ‘Made-in-Japan Innovator,’” said Uze. “For automakers, cybersecurity is a mission as urgent as ending hydrocarbon use. Plans for innovation across-the-board depend on digitizing tomorrow’s cars: in emissions, safety, autonomous drive, driving dynamics and infotainment. But until they find an adaptive, multi-layered solution to cyber threats, all plans could come screeching to a halt with one devastating hack. The industry doesn’t yet have a solution – but we do, and we’re ready to go.”

    Trillium’s ‘Made-in-Japan solution’ strongly secures all three key ‘cyber-threat domains’ in the car with a software-based approach that is compatible with any architecture or operating system. More than just robust and comprehensive, it can be implemented for as little as 1/20th the cost of competing solutions – most of which are still under development.

    “Meanwhile, our multi-layered solution is at an advanced stage,” Uze said. “We have moved into the real-world testing phase via partnerships with a legendary Japanese Super GT racing team and a leading maker of automotive semiconductors. And we are now in discussions with a wide range of automakers and tier-one component suppliers. We’re ready to implement whenever they are.”

    Trillium Inc. was founded in 2014 with a team of executives and engineers from Japan, Europe and the U.S. with extensive experience in relevant fields, backed by lead investment from Global Brain Corp, a Tokyo-based venture capitalist.

  • Singtel teams with SIT to train cybersecurity talent

    Singtel teams with SIT to train cybersecurity talent

    Singtel has announced a new partnership with the Singapore Institute of Technology (SIT) to train cybersecurity talent.

    The work-study program will support SIT students in the areas of Information Security and Software Engineering, which is expected to lead to career pathways such as cyber security R&D, product development, and management, cyber analysis and forensics, operations and cyber architects.

    Singtel country CEO and CEO, Group Enterprise Bill Chang said the undertaking aims to address two critical skills needs locally – the short supply of trained software engineers and the growing worldwide threat posed by cyber threats.

    “The economy is in great need for trained cybersecurity professionals,” he said.

    Under the work-study programs, participating students are trainees of the supporting company. They get to gather meaningful work experiences through industry induction, close mentorship, attachments and capstone projects to deepen industry-relevant skills.

    The students would acquire skills and experience relevant to the needs of the company while the company gains a productive contributor and an avenue to recruit, assess, groom and retain talent.

    Singtel has also worked with the InfoComm Development Authority of Singapore (IDA) on the Cyber Security Associates and Technologists Program.

  • Singtel, Inmarsat join forces on maritime cyber security

    Singtel, Inmarsat join forces on maritime cyber security

    SingTel has forged a strategic alliance with Inmarsat to jointly offer cyber security tools for the global maritime industry.

    Under the partnership, Trustwave, the cyber security arm of Singtel, will provide its Unified Threat Management (UTM) managed solution, to be integrated with Inmarsat hardware onboard ships, to protect data reduce cyber risk for maritime companies.

    Singtel said the UTM service offers a suite of cyber security defenses, such as advance firewall, anti-virus, intrusion prevention and web-filtering.

    Singtel and Inmarsat plan to launch the new maritime cyber security service in the second half of 2016, the companies said a joint statement.

    The new service will be delivered through FleetXpress, the highly anticipated high-speed broadband communication service Inmarsat launched in March for maritime and offshore operators.

    Andrew Lim, managing director of business group at SingTel’s Enterprise Group, said the partnership with Inmarsat is important for the company as it marks the first phase in rolling out Singtel cyber security services for Inmarsat.

    “As maritime systems become more digital, it is imperative for the industry to protect data onboard ships against all forms of cyber attacks. Our partnership with Inmarsat will provide maritime companies with a cyber security solution to meet rapidly evolving cyber threats, globally,” the executive said.

    Gary Gagnon, Inmarsat’s senior vice president of global cyber security, said the partnership with Singtel supports the company’s commitment to the market and elevates the benchmark for maritime cyber security.

    “The landscape of shipping is changing. As we move from traditional shipping into the ship intelligence era, the threat of cyber attacks have never been more real,” commented Ronald Spithout, president of Inmarsat Maritime.

    “Risks from malicious attacks and unlawful access to a ship’s intelligence, its system infrastructure and networks cannot be ignored, and the shipping industry needs to take action.”

    The Singtel-Inmarsat collaboration comes a day after Inmarsat announced it will use its new Global Xpress satellite fleet to provide in-flight connectivity services for the airline industry.

  • mCommerce boom raises cybersecurity risk

    mCommerce boom raises cybersecurity risk

    Asia’s mComerce boom is creating a growing target for online fraud and cybersecurity risks, according to fraud consultancy Fico Group.

    Criminals who used to focus on ATM skimming are turning their attention online in an effort to compromise credit and debit card data. These attacks can be far more lucrative, with more details stolen and a lower chance of getting caught, warns Fico.

    “The demographics suggest that this this will soon become a very big data problem.  In the next 15 years, Asia is expected to add another 1 billion internet users, which comes on top of the 700 million it has today, making it the world’s largest market for online consumers.”

    With fraud challenges growing, the issues and technologies needed to address them will be discussed this week in Bali, Indonesia, where Fico will hold its regional Fraud Forum with bank executives from across Asia Pacific.

    The last year alone has seen an average 22 per cent increase in shopping on mobile phones across 13 Asia-Pacific markets, according to a 2015 study from Visa. Indonesia, China and Taiwan reported the highest rates of growth for 2015 at 36 per cent, 34 per cent and 28 per cent respectively.

    With these card-not-present (CNP) transactions, the retailer never sees the customer or their physical card, and the cardholder doesn’t enter their PIN. At last year’s Fico Asia Pacific Fraud Forum in Singapore, 94 per cent of attendees said that cases of online or CNP fraud had increased at their organisation.

    Spotting and finding anomalies in this pool of data requires sophisticated self-learning and adaptive technologies so banks can catch fraud vectors as quickly as criminals exploit them. Fico is currently testing the geolocation abilities of mobile devices and integrating them with the Fico Falcon Platform, which protects 2.5 billion payment cards worldwide. By validating whether a consumer’s phone is in the same place where their card is being used, the system can reduce false positives while focusing on the most likely incidents of fraud. Banks can also send SMS messages to the consumer’s mobile to validate a transaction in real time.

    Maintaining trust in shopping from mobile devices will also require a new approach to cybersecurity. Data breaches at poorly protected retailers can threaten ecommerce sales. Predictive analytics is needed, rather than signature-based solutions, so that so-called “zero day” attacks can be identified and controlled.

    Raed Taji, head of global fraud consulting for Fico in Asia Pacific, said: “We are seeing rapid changes in customer behavior which then open up opportunities for fraud. In Australia, for example, cash withdrawals from ATMs have fallen 20 per cent in three years, thanks to

    tap-and-go card and mobile payment technologies. The focus on online fraud is growing very rapidly, so we must stay nimble to reduce losses.”

    Dan McConaghy, president for Fico in Asia Pacific, added: “Digital disruption to financial services may present fraud challenges, but it also presents opportunities for us to stop criminals. If consumer payments shift toward a new form of payment, fraudsters will seek out the most vulnerable element – which increasingly means a mobile device.

    “By investing in an analytics-based solution, lenders can add a powerful tool to their arsenal to stay ahead of new criminal fraud patterns.”