Showing posts with label security and risk online. Show all posts
Showing posts with label security and risk online. Show all posts

Thursday, January 12, 2017

Online Fraud Detection: Nobody seems to know what Rudy Giuliani's cybersecurity firm actually does.


Rudy Giuliani has been tapped to "lend expertise" and to advise the Trump administration on cybersecurity.

The former New York mayor "will be sharing his expertise and insight as a trusted friend concerning private sector cybersecurity problems and emerging solutions developing in the private sector," said a brief statement from the incoming Trump administration.

But details about Giuliani's role were not immediately available.
Trump's pick of Giuliani for this position isn't all too surprising to security circles. It's widely known that he is the chief executive of his own private-sector cybersecurity venture, Giuliani Partners.

Giuliani spent much of his time consulting after leaving office as mayor of New York at the end of 2001. His venture claims to offer "a comprehensive range of security and crisis management services." His consulting firm has hired controversial staffers, and has worked for questionable clientele, reports have said.

Yet, even his cybersecurity venture's website, filled with clunky Flash components and "cyber" stock imagery throughout, doesn't advertise what it does.

For the past few months while Giuliani's name was floated for positions for the Republican's presidential campaign, we've tried to find out exactly what his company does, or can do better than any other security firm -- to no avail. (If you have information relating to Giuliani's company, there are a number of ways to contact me securely. We want to know, and we think others do as well.)

Yet, the company has made millions of dollars in contracts with various organizations, including the 2016 Olympic Committee.

Giuliani was most recently a guest speaker at the BlackBerry Security Summit earlier this year -- the day after his bizarre appearance at the Republican National Committee -- to give an equally unhinged speech comparing cybercrime to cancer and hackers to the "Mafia."

The former phone maker BlackBerry just last week announced that Giuliani's company would "assess infrastructures, identify potential cyber security vulnerabilities, address gaps and secure endpoints with the goal of offering another channel to bring customers to a new standard of security."

So clearly the company is doing something right. Right?

It's not known what Giuliani can or will bring to the table. We've reached out to the presidential transition team for more and will update if we hear back.

But right now there are more questions than answers over Giuliani's involvement, given the lack of a clear and transparent directive on what his company does or how it (if at all) will benefit the transition team and the country.

Monday, December 26, 2016

Security and Risk Online on Amazon Opens Data Centers to Boost U.K. Cloud Services

(Bloomberg) -- Amazon Web Services, the cloud-hosting arm of Amazon.com Inc., opened new data centers in the U.K. as it seeks to stay abreast of competitors in offering cloud computing services to government and health-care customers.

The new data centers, announced in a statement on Wednesday, follow decisions by IBM and Microsoft Corp. in the past two months to expand their cloud computing infrastructure in the U.K.

The U.K. data region, which comprises two zones, each consisting of multiple data centers, is the 16th Amazon Web Services operates worldwide and it’s third in Europe. A fourth in France has already been announced and will open next year.

Governments are increasingly moving computing functions into the cloud. But they are often required for regulatory and security purposes to hold data within their national borders. The same applies for sensitive health-care information. Meeting these demands is one reason cloud providers are rushing to open more data centers around the globe.

"This is a great enabler for data that has to remain in the U.K., like health-care," Chris Hayman, who manages Amazon Web Services’ British government accounts, said in an interview.

Liam Maxwell, the U.K.’s national technology adviser, said in a statement that the government had saved 3.5 billion pounds ($4.4 billion) so far by choosing to host data in the cloud rather than on its own servers.

Financial-service firms are also often concerned with minimizing the time it takes to connect to trading venues, another reason to expand in the U.K., said Teresa Carlson, vice president for worldwide public sector operations for Amazon Web Services. “The U.K. is a really important part of the world, being a center of the financial industry,” she said.

The decision to build new data centers in the U.K. predates the country’s June vote to leave the European Union, Carlson said. But giving customers the ability to store data in the U.K. has taken on increased importance since the Brexit vote as clients worry about whether British data privacy rules will diverge from European standards. “Now, whether the U.K. is in Europe or not, they have their own region,” she said.

Amazon Web Services declined to specify exactly how many facilities it operates in the country, how many people will be employed or how much money it will invest.

Karen Bradley, U.K. Secretary of State for Culture, Media and Sport, said in a statement that Amazon’s action “is a strong endorsement of our approach to the digital economy” and “shows a clear confidence in the U.K. being open for business and one of the best places in the world for technology companies to invest in and grow.”

Thursday, November 24, 2016

Online Fraud Detection on How and why people commit efraud

Pressure, opportunity and rationalization form the fraud triangle, which information technology security experts now believe are reasons why people commit electronic fraud.

Also, the people factor in e-payment fraud is increasing, with greed said to be responsible for 67% of fraud cases in 2015, while other causes included problems from debts and gambling, according to Dele Adeyinka, chief digital officer, Wema Bank Plc.

In a presentation, at 7th annual payment systems & fraud conference held in Lagos recently, Adeyinka, said that explanation behind fraud needs to take account of various factors, particularly, from the fraudster’s perspective.

He cautioned that individuals, financial institutions, other corporate bodies and the Government, must take serious the motivation of potential offenders; conditions under which people can rationalize their prospective crimes away and opportunities to commit crime(s); technical ability of the fraudster and expected and actual risk of discovery after the fraud has been carried out, as practical steps to nib in the bud e-payment frauds.

“A common model that brings together a number of the reasons why people commit fraud is the Fraud Triangle. This model is built on the premise that fraud is likely to result from a combination of three factors: perceived pressure; opportunity and rationalization.

“Perceived Pressure: typically based on either greed or need. Greed is said to be responsible for 67% of fraud cases in 2015. Other causes included problems from debts and gambling.

“Opportunity: Fraud is more likely in companies where there is a weak internal control system, poor security over company property, little fear of exposure and likelihood of detection, or unclear policies with regard to acceptable behaviour. Research has shown that some employees are totally honest, some are totally dishonest, but that many are swayed by opportunity. Rationalization: Some people may be able to rationalize fraudulent actions as: necessary– especially when done for the business; harmless –because the victim is large enough to absorb the impact and justified- because ‘the victim deserved it’ or ‘because I was mistreated,’” he said.

Also speaking, Kyari Bukar managing director of CSCS, highlighted the need for the industry to take a closer look at the block chain Technology, Internet of Things (IoTs) and big Data analysis.

He averred that the future of payment lies in harnessing the benefits these latest technologies bring, especially in the fight against fraud.

Speakers at the conference which had over 200 high level participation from top industry experts and public sector including the Nigerian Naval Force, FRSC, members of CeBIH, ISSAN, CCCOBIN, E-PPAN, commercial banks, E-payment providers, media houses, IT organizations, research firms, academia, audit firms, mobile payment service providers, government agencies, etc, agreed that to tackle e-payment fraud, emphasis must be on the ‘people, process and technology’.