<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CrowdStrike Archives - Quayside Technical Services</title>
	<atom:link href="https://www.qts-ltd.com/tag/crowdstrike/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.qts-ltd.com/tag/crowdstrike/</link>
	<description>Delivering effective IT &#38; telecoms services &#38; support across Devon &#38; The South West.</description>
	<lastBuildDate>Tue, 24 Sep 2024 21:29:45 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.0.12</generator>

<image>
	<url>https://www.qts-ltd.com/wp-content/uploads/2019/07/cropped-quayside-favicon-32x32.png</url>
	<title>CrowdStrike Archives - Quayside Technical Services</title>
	<link>https://www.qts-ltd.com/tag/crowdstrike/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Data Centres Now ‘Critical National Infrastructure’</title>
		<link>https://www.qts-ltd.com/data-centres-now-critical-national-infrastructure/</link>
					<comments>https://www.qts-ltd.com/data-centres-now-critical-national-infrastructure/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Sat, 21 Sep 2024 09:30:21 +0000</pubDate>
				<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Bruce Owen]]></category>
		<category><![CDATA[CNI]]></category>
		<category><![CDATA[Critical National Infrastructure]]></category>
		<category><![CDATA[CrowdStrike]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[Cyber Security and Resilience Bill]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data centres]]></category>
		<category><![CDATA[DC01UK]]></category>
		<category><![CDATA[Department for Science Innovation and Technology]]></category>
		<category><![CDATA[DSIT]]></category>
		<category><![CDATA[emergency]]></category>
		<category><![CDATA[Equinix]]></category>
		<category><![CDATA[financial sector]]></category>
		<category><![CDATA[Hertfordshire]]></category>
		<category><![CDATA[National Cyber Security Centre]]></category>
		<category><![CDATA[NCSC]]></category>
		<category><![CDATA[NHS]]></category>
		<category><![CDATA[Peter Kyle]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[technology secretary]]></category>
		<category><![CDATA[UK government]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128664</guid>

					<description><![CDATA[<p>Prompted by the effects of the global IT outage caused by CrowdStrike, the UK has moved to protect UK data centres by classing them as ‘Critical National Infrastructure’ (CNI). CrowdStrike  Back in July, a global IT outage caused by a faulty update impacting Windows systems, from the cybersecurity firm CrowdStrike significantly affected multiple sectors in [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/data-centres-now-critical-national-infrastructure/">Data Centres Now ‘Critical National Infrastructure’</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Prompted by the effects of the global IT outage caused by CrowdStrike, the UK has moved to protect UK data centres by classing them as ‘Critical National Infrastructure’ (CNI).</p>
<h5><strong>CrowdStrike </strong></h5>
<p>Back in July, a global IT outage caused by a faulty update impacting Windows systems, from the cybersecurity firm CrowdStrike significantly affected multiple sectors in the UK, including data centres, the NHS, and the financial industry. It led to widespread disruptions and, although it was not a cyberattack, it does appear to be a motivating factor for the UK government’s announcement of a change classification of UK data centres.</p>
<h5><strong>Not Just Protection against Cyber Criminals </strong></h5>
<p>Although the CrowdStrike effects may have been a major catalyst for the new classification of data centres, their classification as CNI should also help create provision to give them more protection from major environmental disasters and other IT blackouts.  This new classification is part of a wider movement to give them the special protection they merit. As highlighted in the government’s announcement, much of the data housed and processed in UK data centres, from photos taken on smartphones to patients’ NHS records and sensitive financial investment information, could be considered as <em>“powering the economy”.</em></p>
<h5><strong>How does the New Classification Compare? </strong></h5>
<p>The idea to now classify UK data centres as CNI will mean that in terms of added protection, they have been put on an equal footing to water, energy and emergency services systems. This means that they can, as the government says: <em>“now expect greater government support in recovering from and anticipating critical incidents, giving the industry greater reassurance when setting up business in UK and helping generate economic growth for all.” </em></p>
<p>Also, as Technology Secretary Peter Kyle says: <em>“Bringing data-centres into the Critical National Infrastructure regime will allow better coordination and cooperation with the government against cyber criminals and unexpected events.” </em></p>
<p>More specifically, the government says this <em>“support”</em> will mean:</p>
<ul>
<li>The setting up of a dedicated CNI data infrastructure team of senior government officials who will <em>“monitor and anticipate potential threats, provide prioritised access to security agencies including the National Cyber Security Centre, and coordinate access to emergency services should an incident occur”. </em></li>
<li>The government intervening, for example in the event of an attack on a data centre hosting critical NHS patients’ data. In this event, with the new classification of data centres, the government says it will <em>“ensure contingencies are in place to mitigate the risk of damage or to essential services, including on patients’ appointments or operations.” </em></li>
<li>The UK is already home to the highest number of data centres in western Europe. Giving CNI status to data centres in the UK could increase business confidence in investing in data centres in the UK, an industry which already generates an estimated £4.6 billion in revenues a year.</li>
</ul>
<h5><strong>Deterrent? </strong></h5>
<p>It appears that the government believes that the status will also deter cyber criminals from targeting data centres that may house vital health and financial data, minimising disruption to people’s lives, the NHS, and the economy. Presumably, this deterrent effect would come from increased penalties, greater cybersecurity investment, and enhanced monitoring and better threat detection efforts.</p>
<h5><strong>Just in Time </strong></h5>
<p>With the UK government recently welcoming a proposed £3.75 billion investment in Europe’s largest data centre, DC01UK in Hertfordshire, and with this expected to create over 700 local jobs and support 13,740 data and tech jobs across the country, the new CNI status for data centres appears to have been given just in time.</p>
<h5><strong>The Cyber Security and Resilience Bill Too</strong></h5>
<p>As an additional measure, earlier this summer the government’s Department for Science, Innovation and Technology (DSIT) also announced it will be introducing the Cyber Security and Resilience Bill. It is thought that this will strengthen the country’s cyber defences by enhancing incident reporting requirements, helping safeguard vital sectors such as healthcare and finance, ensuring stronger protections against cyber threats like ransomware, and <em>“mandating that providers of essential infrastructure protect their supply chains from attacks”. </em></p>
<h5><strong>Support </strong></h5>
<p>Support for the re-classifying of data centres as CNI has come from several key data centre industry players. For example, Bruce Owen, UK Managing Director of digital infrastructure provider Equinix, said: <em>“We welcome today’s announcement by the government which recognises the critical nature of data centres and digital infrastructure to the economy and society.” </em></p>
<h5><strong>What Does This Mean For Your Business? </strong></h5>
<p>The reclassification of UK data centres as CNI is a strategic response to immediate threats, like the CrowdStrike outage, and a forward looking move to secure the country’s digital infrastructure. By placing data centres on par with essential services like energy and emergency systems, the government appears to be trying to recognise their pivotal role in supporting the digital economy and vital public services such as the NHS.</p>
<p>As CNI, data centres now gain access to increased government resources, including the support of the National Cyber Security Centre (NCSC), and a dedicated CNI data infrastructure team to monitor and anticipate threats. This could ensure quicker responses to vulnerabilities and a stronger defence against cyberattacks, particularly for centres hosting critical data, such as health and financial information. The new classification also aims to protect against broader risks, such as natural disasters or IT blackouts, which could severely impact businesses and public services alike, thereby trying to provide protection that takes account of any serious eventuality.</p>
<p>The government’s commitment to boosting this sector is clear, as evidenced by the approval of a £3.75 billion investment in Europe’s largest data centre project in Hertfordshire. The new status, could, therefore encourage further investments, reinforcing business confidence and supporting sustainable growth in the tech industry. The Cyber Security and Resilience Bill, expected to be introduced soon, may also further strengthen these protections by enforcing stricter incident reporting and ensuring supply chain security for essential services.</p>
<p>Support from industry leaders reflects the importance of securing the country’s digital infrastructure, as more businesses rely on data centres to manage sensitive information. This reclassification is not just a reactive measure, but many would argue it is a necessary step in ensuring the continuity of services that millions rely on daily.</p>
<p>By classifying data centres as CNI, the UK is laying the groundwork for a more secure and resilient digital future. With increased investment, enhanced government support, and forthcoming legislative measures, this decision may help position the UK as a leader in digital infrastructure protection, helping to safeguard its economy, public services, and reputation as a global hub for technological innovation.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/data-centres-now-critical-national-infrastructure/">Data Centres Now ‘Critical National Infrastructure’</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/data-centres-now-critical-national-infrastructure/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>‘Networkless’ Attacks?</title>
		<link>https://www.qts-ltd.com/networkless-attacks/</link>
					<comments>https://www.qts-ltd.com/networkless-attacks/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Fri, 26 Apr 2024 09:10:57 +0000</pubDate>
				<category><![CDATA[Tech Insight]]></category>
		<category><![CDATA[Adversary in The Middle phishing]]></category>
		<category><![CDATA[AiTM]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[CrowdStrike]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[EDR]]></category>
		<category><![CDATA[endpoint detection and response]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi factor authentication]]></category>
		<category><![CDATA[Oktajacking]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SAMLjacking]]></category>
		<category><![CDATA[Single Sign On]]></category>
		<category><![CDATA[SSO]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=128109</guid>

					<description><![CDATA[<p>In this article, we look at why and how networkless attacks, which target cloud apps and identities, have created new opportunities for attackers and new risks for businesses, as well as what your business can do to mitigate these risks. The Move To SaaS and Cloud  In the rapidly evolving digital landscape, one of the [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/networkless-attacks/">‘Networkless’ Attacks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In this article, we look at why and how networkless attacks, which target cloud apps and identities, have created new opportunities for attackers and new risks for businesses, as well as what your business can do to mitigate these risks.</p>
<h5><strong>The Move To SaaS and Cloud </strong></h5>
<p>In the rapidly evolving digital landscape, one of the key drivers enabling attackers to compromise an organistaion without needing to touch the endpoint or conventional networked systems and services is the increased reliance on cloud based services and software as a service (SaaS) applications, to drive efficiency and innovation. This shift, while beneficial, has also created new cybersecurity challenges for businesses, primarily due to the decentralisation of ‘digital identities’ and the interconnected nature of cloud services.</p>
<h5><strong>The SaaS Revolution and Its Impact on Security </strong></h5>
<p>The proliferation of SaaS applications is a direct result of the digital transformation that has reshaped the business world. For example, companies can now be using hundreds, if not thousands of cloud applications to perform daily operations, from customer relationship management to financial operations. This shift is driven by the convenience and scalability of SaaS solutions, however it comes with inherent security risks.</p>
<p>The new risk that businesses are facing is that each application potentially serves as an entry point for malicious actors, and the interconnectivity between these apps can allow a breach in one service to cascade through to others.</p>
<h5><strong>Why Digital Identities Are The New Security Battleground </strong></h5>
<p>As the traditional network perimeter dissolves, digital identities become the new security frontier. Put simply, a digital identity can be a user account created for services that someone in the business has signed up for using a username or email and password. More broadly, it can also mean other personal data used to identify and authenticate users online.</p>
<p>These digital identities, which provide access to a myriad of cloud applications, are now central targets for attackers. Securing them has become increasingly complex due to the sheer number of them that businesses may be using and their dispersion across various cloud platforms, each with its own security environment. This decentralisation not only makes consistent security policies harder to enforce but also increases the complexity of monitoring these identities for potential breaches.</p>
<h5><strong>How Attackers Are Exploiting Vulnerabilities in Cloud Identities </strong></h5>
<p>Attackers have adapted to this new environment by developing sophisticated techniques to exploit vulnerabilities in cloud identities without ever touching the physical endpoints or traditional networked systems.</p>
<p>Examples of techniques include AiTM (Adversary in The Middle) phishing, SAMLjacking, and Oktajacking, all of which exploit weaknesses in the authentication processes and session management of cloud services.</p>
<p>AiTM phishing involves intercepting and manipulating real time data during a session to steal credentials or manipulate transactions. SAMLjacking and Oktajacking focus on manipulating Single Sign On (SSO) processes to gain unauthorised access.</p>
<p>Security stats now reveal increasingly that attackers are deliberately targeting cloud services as a way into organisations. For example, malware used to be one of the main threats, but CrowdStrike figures show that three out of four attacks last year were malware free, and that the targeting of cloud services has increased 110 per cent. This helps to illustrate why cloud identities are the new digital perimeter and that cloud apps and identities now give attackers the same result as old style attacks without them having to try and breach a network perimeter via the endpoint.</p>
<h5><strong>The Security Gap in Identity Management </strong></h5>
<p>Despite advances in cybersecurity, it’s clear to see why many businesses are now vulnerable to identity based attacks. Traditional security measures like endpoint detection and response (EDR) systems and firewalls, for example, are less effective in a cloud centric world where applications are accessed primarily through web browsers. This gap is exacerbated by the reactive nature of many security strategies, which focus on mitigating threats after they have been detected rather than preventing them proactively.</p>
<h5><strong>What Does This Mean for Your Business? </strong></h5>
<p>For UK businesses, their move to the cloud and the usage of a wide range and complicated combination of SaaS apps, digital identities, and the interconnection and decentralisation of these have meant that they are now vulnerable to networkless attack techniques, perhaps without realising it until now. The shift to cloud computing has not only expanded the attack surface but also highlighted the inadequacies of traditional security models in protecting digital identities. This means that UK businesses must now take a much closer look at the security of these identities as part of their overall cybersecurity strategy.</p>
<p>To mitigate the risks associated with networkless attacks, businesses should perhaps consider adopting a zero trust security model, which assumes that threats could be internal or external and verifies each identity and device continuously, regardless of their location. Additionally, enhancing visibility across all cloud services and implementing advanced security measures like multi factor authentication (MFA), behavioral analytics, and more sophisticated identity and access management (IAM) solutions could help.</p>
<p>In short, as these networkless attacks continue to evolve, UK businesses must be proactive with security, stay vigilant and adapt their security strategies. By understanding the vulnerabilities associated with digital identities and cloud services, and implementing security measures accordingly, businesses can safeguard their assets in the cloud era.</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/networkless-attacks/">‘Networkless’ Attacks?</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/networkless-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AnyDesk Hacked</title>
		<link>https://www.qts-ltd.com/anydesk-hacked/</link>
					<comments>https://www.qts-ltd.com/anydesk-hacked/#respond</comments>
		
		<dc:creator><![CDATA[staff]]></dc:creator>
		<pubDate>Wed, 07 Feb 2024 15:40:44 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stop-Press]]></category>
		<category><![CDATA[AnyDesk]]></category>
		<category><![CDATA[CrowdStrike]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cyber-attack]]></category>
		<category><![CDATA[cyber-security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[hacking]]></category>
		<guid isPermaLink="false">https://www.qts-ltd.com/?p=127815</guid>

					<description><![CDATA[<p>AnyDesk, the remote desktop application company has reported that it recently suffered a cyberattack where hackers gained access to its production servers. It has been reported that source code and private code signing keys were stolen. AnyDesk said in a statement that on discovering the breach it activated a successful remediation and response plan involving [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/anydesk-hacked/">AnyDesk Hacked</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div>
<p><a href="https://anydesk.com/en">AnyDesk</a>, the remote desktop application company has reported that it recently suffered a cyberattack where hackers gained access to its production servers.</p>
</div>
<div>
<p>It has been reported that source code and private code signing keys were stolen.</p>
</div>
<div>
<p>AnyDesk said in a statement that on discovering the breach it activated a successful remediation and response plan involving cyber security experts CrowdStrike. AnyDesk says: <i>“To date, we have no evidence that any end user devices have been affected. We can confirm that the situation is under control, and it is safe to use AnyDesk.”</i></p>
</div>
<p>The post <a rel="nofollow" href="https://www.qts-ltd.com/anydesk-hacked/">AnyDesk Hacked</a> appeared first on <a rel="nofollow" href="https://www.qts-ltd.com">Quayside Technical Services</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.qts-ltd.com/anydesk-hacked/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
