Monday, May 17, 2021

Sort of a ‘Streisand Effect” attack. Try NOT coming to a hacker’s attention, for any reason.

https://www.databreaches.net/cyberinsurance-giant-axa-hit-by-ransomware-attack-after-saying-it-would-stop-covering-ransom-payments/

Cyberinsurance giant AXA hit by ransomware attack after saying it would stop covering ransom payments

Graham Cluley sets the stage nicely:

Ouch.
One week after the French branch of cyberinsurance giant AXA said that it would no longer be writing policies to cover ransomware payments, the company’s operations in Thailand, Malaysia, Hong Kong, and the Phillippines have reportedly been hit… by a ransomware attack.

Read more on GrahamCluley.com.

[MORE]





A real ethics question.

https://www.bespacific.com/the-new-digital-extortion/

The new digital extortion

Axios: “If you run a hospital, a bank, a utility or a city, chances are you’ll be hit with a ransomware attack. Given the choice between losing your precious data or paying up, chances are you’ll pay.

    • Why it matters: Paying the hackers is the clear short-term answer for most organizations hit with these devastating attacks, but it’s a long-term societal disaster, encouraging hackers to continue their lucrative extortion schemes.

    • Driving the news: Colonial Pipeline paid hackers almost $5 million in ransom to restore its systems and get gasoline flowing again after a ransomware attack held the country’s largest pipeline hostage, which resulted in widespread disruption of gasoline supply.

    • The big picture: “This creates a collective action problem — the bad guys win so they’ll go out and hit someone else,” said Betsy Cooper, director of Aspen Tech Policy Hub at the Aspen Institute…”





Privacy any utility are often considered separately. “We can do this, therefore we should do this!”

https://thenextweb.com/news/apple-airtags-find-my-app-work-because-massive-covert-tracking-network-syndication?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TheNextWeb+%28The+Next+Web+All+Stories%29

Apple AirTags and the ‘Find My’ app only work because of a massive covert tracking network

… For the uninitiated, an AirTag is a small device (similar to a Tile) that can be attached to personal items such as keys, wallets or luggage. The tag periodically sends messages that can be used to track its location, letting you find any lost or missing items with the help of an app.

While clearly useful, AirTags can also potentially be misused. Concerns have been raised they might facilitate stalking, for example.

And there’s also a more fundamental issue with this technology. Its euphemistic description as a “crowdsourced” way to recover lost items belies the reality of how these items are tracked.

What you won’t find highlighted in the polished marketing statements is the fact that AirTags can only work by tapping into an Apple-operated surveillance network in which millions of us are unwitting participants.





We need answers, not more questions.

https://www.zdnet.com/article/ai-is-getting-smarter-fast-when-do-we-start-worrying-about-whether-software-should-have-rights/

AIs are getting smarter, fast. That's creating philosophical questions that we can't answer

… Currently, AIs are narrow in nature, performing tasks like image recognition, fraud detection, and customer service. But, as AIs develop, they will become increasingly autonomous. At some point, they're likely to do wrong. Who's really at fault when AIs make mistakes is a question that's set to trouble businesses and excite lawyers as they struggle to work out who could, and should, be held responsible for any resulting harm.





It strikes me that this is similar to failures in training your dog or your children.

https://venturebeat.com/2021/05/16/4-of-the-worst-ways-to-use-ai/

4 of the worst ways to use AI

As the pandemic further accelerates our digital transformation, companies are relying even more on automation and particularly on artificial intelligence. Two-thirds of CEOs surveyed last year by a major consulting firm said they will use AI even more than before for the creation of new workforce models. Even higher numbers plan to digitize operations, customer interactions, business models, and revenue streams. This huge acceleration and shift will surely bring massive failures, leaving companies — and in some cases even critical infrastructure — vulnerable to loss as critical decision-making is handed off to AI.





Thinking, what a concept. Webinar. (One hour)

https://securityboulevard.com/2021/05/cpdp-2021-moderator-freyja-van-den-boom-rethinking-openness-in-the-context-of-artificial-intelligence/

CPDP 2021 – Moderator: Freyja Van Den Boom ‘Rethinking ‘Openness’ In The Context Of Artificial Intelligence’

https://www.youtube.com/watch?v=0bvAXgL1lKw&feature=emb_logo





Is acting contrary to a tip insider trading?

https://dilbert.com/strip/2021-05-17



Sunday, May 16, 2021

An over-reaction due to panic, or over-sold by a vendor? Probably the result of no plan to guide their response.

https://www.pogowasright.org/privacy-concerns-raised-about-rpis-response-to-data-breach/

Privacy concerns raised about RPI’s response to data breach

Many data breaches result in privacy concerns due to data access or exfiltration. But here’s a case where a school’s incident response is causing a new set of privacy concerns. The original incident was covered on DataBreaches.net, and it appears that Rensselaer Polytechnic Institute has not disclosed anything significant since then. Now more people are demanding answers and protesting one of the school’s new requirements in response to the breach.

Rachel Silberstein reports:

… With RPI systems still down, students, faculty and staff have no access to their emails, RPI websites, dining dollars, or Wi-Fi accounts.
The university is also requiring all students and faculty to download “security software” on any device connected to the university’s network as it begins to partially restore services.

And from that arises privacy concerns and protests.

Students and faculty are organizing on Reddit to push back on the requirement to download the CrowdStrike Falcon program, which they say allows an outside company “kernel-level” access to all parts of the computer — such as apps opened, websites visited, and email communication — creating new security and privacy concerns, the student said.
“In addition, this gives the school the ability to remotely access students’ computers without consent or knowledge at all, allowing them to transfer files between them. This is a huge privacy and student rights concern, and may not work well for contracts involving IP-sensitive material,” the student wrote in a message to the Times Union. “From my research into CrowdStrike Falcon, contents of emails/files are not read, however, it can be at any time without user knowledge.”

Read more on Times Union.





Collateral damage, and a few new resources.

https://www.analyticsinsight.net/another-major-cyberattack-heres-why-security-validation-is-more-important-than-ever/

ANOTHER MAJOR CYBERATTACK! HERE’S WHY SECURITY VALIDATION IS MORE IMPORTANT THAN EVER

Heard the news about Americans suddenly hoarding oil? You would probably be surprised to learn that the reason for that is a cyberattack. The most recent disruption in American oil supply is not the result of low oil production but the forced shutdown of the Colonial Pipeline following a ransomware attack.

After the SolarWinds and Codecov attacks, it is alarming that another high-profile cybercrime has managed to penetrate the defenses of a supposedly technologically advanced country. To make matters worse, it turns out the perpetrators of the attack are saying they didn’t mean to cause problems.

… In its SOCTA 2021 report, the European Union Agency for Law Enforcement Cooperation or Europol rang the alarm on the surge of cybercrimes including attacks on critical infrastructure.

… According to a study reported on Cybercrime Magazine, global cybercrime damages are set to breach the $6 trillion level in 2021.

… Simply put, people and organizations never learn from previous cyber attacks. This is evidenced by something as basic as the refusal to use stronger passwords. A study by NordPass found that the use of shockingly weak passwords was one of the reasons why organizations were successfully attacked.





Perhaps we should be doing this? Is this simple enough?

https://www.researchgate.net/profile/Abdelnasser-Abdelaal/publication/351354214_Grand_Research_Challenges_Facing_Ethically_Aligned_Artificial_Intelligence/links/60934418a6fdccaebd0dd9d9/Grand-Research-Challenges-Facing-Ethically-Aligned-Artificial-Intelligence.pdf

Grand Research Challenges Facing Ethically Aligned Artificial Intelligence

Despite the impressive progress of artificial intelligence, performance of many systems has shown severe bias, horrible discrimination, and fatal errors. These immoral flaws have triggered philosophers, roboticists, futurists who have flooded the community with a proliferation of ethical principles for disciplining these systems. Regardless of the ambiguity and lack of consensus on these principles, the missing block is the translation of suggested normative principles into best practices, measures, regulations, policies, and research agenda. The first objective of this study is to introduce this emerging landscape of ethics to the information system community. The second objective is to reshuffle suggested principles, summarize them, and reproduce them in a form of ten grand research challenges and subfields that may guide future endeavors.





If only I cared…

https://repositorio.comillas.edu/xmlui/handle/11531/55658

Care ethics in the era of Artificial Intelligence

Artificial Intelligence is changing the world of business and that leaves many ethical gaps behind. Nowadays, technology companies mark the rhythm of business and technology innovations as Artificial Intelligence (AI), Big Data, and Business Analytics mark enterprises' rhythm (Wiener et al. 2020). In this scenario, the accelerated pace of science and technology leaves many ethical gaps to address (Jonas 1984; 1985): automation and unemployment (Dodel & Mesch 2020; Kim & Scheller-Wolf 2019; Wright & Schultz 2018), AI and decision-making (Cervantes et al. 2016; Robbins & Wallance 2007), and the like. In this chapter, we proposed the ethics of care as moral grounding for the AI era in business. The chapter's structure is as follows: first, we present the context of the arrival of AI and its ethical implications. Second, we present ethics of care, its main premises, and its application in business ethics and stakeholder theory. Finally, we approach ethical problems in management decision-making from a care ethics perspective, and then we propose a principle for companies. We ended up with some conclusions and future research.





Think of all that free government data in a variety of hard to access formats. What if AI could make in available and comprehensible?

https://www.analyticsinsight.net/harness-agile-analytics-to-turn-big-data-into-big-business/

HARNESS AGILE ANALYTICS TO TURN BIG DATA INTO BIG BUSINESS

… Data is redefining decision-making on every front – from operations, R&D, engineering right through to go-to-market engagement strategies.

The data economy is already a multi-billion-dollar industry, generating employment for millions, yet we are only just beginning to tap its potential. Digital transformation is on the agenda in every boardroom, the majority of businesses use some level of AI and analytics and automation are becoming a routine part of many business areas. The secret to unlocking future prosperity in almost any business, whether established or a digital native, lies with the data.





Perspective. Smart guy saying interesting things.

https://www.theguardian.com/books/2021/may/16/daniel-kahneman-clearly-ai-is-going-to-win-how-people-are-going-to-adjust-is-a-fascinating-problem-thinking-fast-and-slow

Daniel Kahneman: ‘Clearly AI is going to win. How people are going to adjust is a fascinating problem’





You should you know.

https://www.makeuseof.com/reasons-why-start-your-podcast/

7 Reasons Why You Should Start Your Own Podcast

… have you ever thought about starting your own podcast? If you haven't, you might want to consider changing your mind. Here are several reasons why you should start your own podcast.



Saturday, May 15, 2021

Papa spank? Imagine a nation state sponsor expressing displeasure over an unauthorized ransom.

https://krebsonsecurity.com/2021/05/darkside-ransomware-gang-quits-after-servers-bitcoin-stash-seized/

DarkSide Ransomware Gang Quits After Servers, Bitcoin Stash Seized

The DarkSide ransomware affiliate program responsible for the six-day outage at Colonial Pipeline this week that led to fuel shortages and price spikes across the country is running for the hills. The crime gang announced it was closing up shop after its servers were seized and someone drained the cryptocurrency from an account the group uses to pay affiliates.

“Servers were seized (country not named), money of advertisers and founders was transferred to an unknown account,” reads a message from a cybercrime forum reposted to the Russian OSINT Telegram channel.

… In a blog post on the DarkSide closure, cyber intelligence firm Intel 471 said it believes all of these actions can be tied directly to the reaction related to the high-profile ransomware attacks covered by the media this week.

“However, a strong caveat should be applied to these developments: it’s likely that these ransomware operators are trying to retreat from the spotlight more than suddenly discovering the error of their ways,” Intel 471 wrote. “A number of the operators will most likely operate in their own closed-knit groups, resurfacing under new names and updated ransomware variants. Additionally, the operators will have to find a new way to ‘wash’ the cryptocurrency they earn from ransoms. Intel 471 has observed that BitMix, a popular cryptocurrency mixing service used by Avaddon, DarkSide and REvil has allegedly ceased operations. Several apparent customers of the service reported they were unable to access BitMix in the last week.”





Everything you do on the Internet is available to anyone who wants to look. Deal with it.

https://www.pogowasright.org/we-found-joe-bidens-secret-venmo-heres-why-thats-a-privacy-nightmare-for-everyone/

We Found Joe Biden’s Secret Venmo. Here’s Why That’s A Privacy Nightmare For Everyone.

Ryan Mac, Katie Notopoulos, Ryan Brooks, and Logan McDonald report:

BuzzFeed News found President Joe Biden’s Venmo account after less than 10 minutes of looking for it, revealing a network of his private social connections, a national security issue for the United States, and a major privacy concern for everyone who uses the popular peer-to-peer payments app.
On Friday, following a passing mention in the New York Times that the president had sent his grandchildren money on Venmo, BuzzFeed News searched for the president’s account using only a combination of the app’s built-in search tool and public friends feature. In the process, BuzzFeed News found nearly a dozen Biden family members and mapped out a social web that encompasses not only the first family, but a wide network of people around them, including the president’s children, grandchildren, senior White House officials, and all of their contacts on Venmo.

Read more on BuzzFeed.





Politics as the road to riches?

https://www.wsj.com/articles/trump-considers-contenders-to-be-his-new-social-media-outlet-after-big-tech-crackdown-11621013567?mod=djemalertNEWS

Trump Considers Contenders to Be His New Social-Media Outlet After Big Tech Crackdown

Donald Trump, sidelined by Twitter Inc. and Facebook Inc., has been talking with numerous platforms as he seeks a new online megaphone. Jeff Brain, the chief executive of CloutHub, a fledgling social media network that has become popular with conservatives, thinks his company fits the bill.

… The former president is interested in being paid in exchange for the followers he would presumably bring to the new social networks, people familiar with the situation said. Mr. Trump had nearly 89 million Twitter followers.

“He’s not that interested in equity. He wants cash money up front, like a license fee,” said one person familiar with the process.





Webinar

https://securityboulevard.com/2021/05/cpdp-2021-moderator-eleni-kosta-the-use-of-ai-in-state-surveillance-challenges-for-privacy/

CPDP 2021 – Moderator: Eleni Kosta ‘The Use Of Ai In State Surveillance: Challenges For Privacy’

https://www.youtube.com/watch?v=CHhaO8XLYRs





Tools.

https://www.makeuseof.com/how-to-use-measure-app-iphone/

A Step-by-step Guide on How to Use the Measure App

… The Measure app is pre-installed on Apple devices. If you deleted it, simply download it for free from the App Store. Also, make sure that your device is up to date to benefit from the latest features.

… You can tap the measurement to see it in centimeters or inches. Copy the measurement by choosing Copy.

You can also take a screenshot of the object with the measurements using the shutter button in the bottom-right corner.





Tool for faking literacy?

https://www.makeuseof.com/blinkist-alternatives-for-free-book-summaries/

5 Blinkist Alternatives for Free Book Summaries You May Not Have Known

Haven't read a book but still want to look like you read it? Get a free book summary through these apps, podcasts, and YouTube channels.



Friday, May 14, 2021

An awful lot of “hurry up and fix it!” pressure will do this.

https://www.huffpost.com/entry/colonial-pipeline-5-million-ransom_n_609e1a82e4b063dccea7df1a

Colonial Pipeline Reportedly Paid $5 Million Ransom After Hack

The owner of the Colonial Pipeline paid hackers about $5 million in bitcoin to regain access to its data and end a standoff that forced one of the country’s largest energy pipelines offline, multiple media outlets reported Thursday.

Details of the payments were first reported by Bloomberg News and The New York Times, and cited sources familiar with the ransom. The ransom amounted to about 75 bitcoin, a hard-to-trace cryptocurrency.



(Related)

https://www.bbc.com/news/world-europe-57111615

Irish health service hit by cyber attack

Ireland's health service has temporarily shut down its IT system after what it described as a "significant ransomware attack".

The Health Service Executive (HSE) said it had taken the precaution of closing down its systems to further protect them and assess the situation.

Ireland's Health Minister Stephen Donnelly said the incident was having "a severe impact on [the] health and social care services".

… "At this moment we can't access lists of people who are scheduled for appointments on Monday, so we don't even know who to cancel," she said.



(Related)

https://threatpost.com/ransomwares-swindle-triple-extortion/166149/

Ransomware’s New Swindle: Triple Extortion

Ransomware attacks are exploding at a staggering rate, and so are the ransoms being demanded. Now experts are warning against a new threat — triple extortion — which means that attackers are expanding out to demand payments from customers, partners and other third parties related to the initial breach to grab even more cash for their crimes.

Check Point’s latest ransomware report found that over the past year, ransomware payments have spiked by 171 percent, averaging about $310,000 — and that globally, the number of attacks has surged by 102 percent.

… Download our exclusive FREE Threatpost Insider eBook, “2021: The Evolution of Ransomware,” to help hone your cyber-defense strategies against this growing scourge. We go beyond the status quo to uncover what’s next for ransomware and the related emerging risks. Get the whole story and DOWNLOAD the eBook now – on us!





An idea for my Ethical Hacking students: make Alexa sound like Donald Duck.

https://voicebot.ai/2021/05/13/ford-cars-will-embed-amazon-alexa-in-cars-by-over-the-air-update/

Ford Will Embed Amazon Alexa in Cars by Over-the-Air Update

Ford announced that it will integrate Amazon Alexa directly into hundreds of thousands of vehicles this year using its new Power-Up program of Over-the-Air (OTA) updates. The hands-free version of Alexa includes all of the voice assistant’s standard and automotive-specific features, including control over the car’s locks and remote control over smart home devices.





This caught my eye. A labor shortage? Are we no longer teaching our liberal arts graduates how to ask, “Do you want fries with that?”

https://finance.yahoo.com/news/why-mc-donalds-minimum-wage-hike-is-surprisingly-good-news-for-the-stock-163651859.html

Why McDonald's minimum wage hike is surprisingly good news for the stock

… "In this highly competitive market for talent, successful employee recognition, recruitment, and retention is fundamental to drive growth," said McDonald's U.S. President Joe Erlinger in an internal memo obtained by Yahoo Finance.





I know a couple of English teachers who will find this rather distressing. If I write (program) one of these tools, can I claim copyright on all of their output?

https://builtin.com/marketing/copywriting-ai-gpt3

AI WON’T TAKE COPYWRITING JOBS. IT’LL TRANSFORM THEM.

… Many writers — not just neurotic Hollywood scribes — will tell you that the hardest part of the process is getting started.

… Services have arrived on the scene to help these writers conquer the blank page. And they all share something in common: they’re powered by artificial intelligence.

These tools include Copy AI, Conversion AI, Anyword, Copysmith, Writesonic and Shortly AI. They are designed to transform simple human inputs (like brainstorm notes and bullet points) into clean prose — full sentences that pass off as human creativity.

It’s all but inevitable that AI writing assistants will help shape the future of content marketing and copywriting.



Thursday, May 13, 2021

We’ll have to see if any of this can be completed in the time allowed.

https://www.bespacific.com/executive-order-on-improving-the-nations-cybersecurity/

Executive Order on Improving the Nation’s Cybersecurity

May 12, 2021: “Today, President Biden signed an Executive Order to improve the nation’s cybersecurity and protect federal government networks. Recent cybersecurity incidents such as SolarWinds, Microsoft Exchange, and the Colonial Pipeline incident are a sobering reminder that U.S. public and private sector entities increasingly face sophisticated malicious cyber activity from both nation-state actors and cyber criminals. These incidents share commonalities, including insufficient cybersecurity defenses that leave public and private sector entities more vulnerable to incidents. This Executive Order makes a significant contribution toward modernizing cybersecurity defenses by protecting federal networks, improving information-sharing between the U.S. government and the private sector on cyber issues, and strengthening the United States’ ability to respond to incidents when they occur. It is the first of many ambitious steps the Administration is taking to modernize national cyber defenses. However, the Colonial Pipeline incident is a reminder that federal action alone is not enough. Much of our domestic critical infrastructure is owned and operated by the private sector, and those private sector companies make their own determination regarding cybersecurity investments. We encourage private sector companies to follow the Federal government’s lead and take ambitious measures to augment and align cybersecurity investments with the goal of minimizing future incidents…”





Another example of a voting system not designed to produce unimpeachable results.

https://threatpost.com/e-voting-security-flaws/166110/

Researchers Flag e-Voting Security Flaws

A group of election security experts said after a deep dive into Australia’s electronic voting systems that they have “serious problems” with the accuracy, integrity and privacy with elections run by the Australian Capital Territory (ACT) Electoral Commission.

… “Secretive, unverifiable systems like the ones used in the ACT 2020 election make it relatively easy to change the recorded list of votes cast, in a way that observers cannot notice,” they said. “It also makes accidental errors more likely to remain undetected.”





Interesting. Some day there may be a bot for every state! Or the law may require such a tool.

https://www.bespacific.com/privacybot/

PrivacyBot

Berkeley MIMS Final Project 2021 – “PrivacyBot is a free and open-source way to delete your data from an exhaustive list of data brokers and people search sites. The largest statewide privacy law change in a generation, the California Consumer Privacy Act (CCPA) went into effect in January 2020. However, exercising these privacy rights is a tricky business even for privacy experts. A survey we conducted within a few privacy-related subreddits showed that tracking down data brokers is “a huge pain in the [neck]”.

We introduce “PrivacyBot”, a simple way to start exercising your privacy rights. Our deliverables include:

    • A fully open-source local-only system that automatically routes data delete requests to data brokers and people search sites

    • User experience research reports about current CCPA processes and feedback

    • Shareable insights and data visualizations about the request process…”





Naming specific tools is less comprehensive than describing the process.

https://www.pogowasright.org/nyc-council-passes-data-privacy-bill-that-would-impose-rigorous-requirements-on-owners-of-smart-access-buildings/

NYC Council Passes Data Privacy Bill That Would Impose Rigorous Requirements On Owners of “Smart Access” Buildings

Damon W. Silver and Gregory C. Brown Jr. of JacksonLewis write:

As we noted in our last post, there has been a flurry of data privacy and security activity in New York, with the State appearing poised to join California as a leader in this space. Most recently, on April 29, 2021, the New York City Council passed the Tenant Data Privacy Act (“TDPA”), which would impose on owners of “smart access” buildings obligations related to their collection, use, safeguarding, and retention of tenant data.
Under the TDPA, a “smart access” building is one that uses electronic or computerized technology (e.g., a key fob), radio frequency identification cards, mobile phone applications, biometric information (e.g., fingerprints, voiceprints, hand or face geometry), or other digital technology to grant entry to the building, or to common areas or individual dwelling units therein.

Read more on Workplace Privacy, Data Management & Security Report





Systems that automate bias.

https://fpf.org/blog/automated-decision-making-systems-considerations-for-state-policymakers/

AUTOMATED DECISION-MAKING SYSTEMS: CONSIDERATIONS FOR STATE POLICYMAKERS

In legislatures across the United States, state lawmakers are introducing proposals to govern the uses of automated decision-making systems (ADS) in record numbers. In contrast to comprehensive privacy bills that would regulate collection and use of personal information, automated decision-making system (ADS) bills in 2021 specifically seek to address increasing concerns about racial bias or unfair outcomes in automated decisions that impact consumers, including housing, insurance, financial, or governmental decisions.

So far, ADS bills have taken a range of approaches, with most prioritizing restrictions on government use and procurement of ADS (Maryland HB 1323 ); requiring inventories of government ADSs currently in use (Vermont H 0236 ); impact assessments for procurement (CA AB-13 ); external audits (New York A6042 ); or outright prohibitions on the procurement of certain types of unfair ADS (Washington SB 5116 ). A handful of others would seek to regulate commercial actors, including in insurance decisions (Colorado SB 169 ), consumer finance (New Jersey S1943 ), or the use of automated decision-making in employment or hiring decisions (Illinois HB 0053, New York A7244 ).

At a high level, each of these bills share similar characteristics. Each proposes general definitions and general solutions that cover specific, complex tools used in areas as varied as traffic forecasting and employment screening. But the bills are not consistent with regard to requirements and obligations. For example, among the bills that would require impact assessments, some require impact assessments universally for all ADS in use by government agencies, others would require impact assessments only for specifically risky uses of ADS. 





Because I was an Auditor for lots of years and did build some automated audit tools.

https://www.cpomagazine.com/cyber-security/compliance-made-easy-how-to-improve-your-risk-posture-with-automated-audits/

Compliance Made Easy: How To Improve Your Risk Posture With Automated Audits

Compliance standards come in many different shapes and sizes. Some organizations set their own internal policies, while others are subject to regimented global frameworks such as PCI DSS, which protects customers’ card payment details; SOX to safeguard financial information or HIPAA, which protects patients’ healthcare data.

Regardless of which industry you operate in, regular auditing is key to ensuring your business retains its risk posture whilst also remaining compliant. The problem is that running manual risk and security audits can be a long, drawn-out, and tedious affair. A 2020 report from Coalfire and Omdia found that for the majority of organizations, growing compliance obligations are now consuming 40% or more of IT security budgets and threaten to become an unsustainable cost.

The report suggests two reasons for this growing compliance burden. First, compliance standards are changing from point-in-time reviews to continuous, outcome-based requirements. Second, the ongoing cyber-skills shortage is stretching organizations’ abilities to keep up with compliance requirements. This means businesses tend to leave them until the last moment, leading to a rushed audit that isn’t as thorough as it could be, putting your business at increased risk of a penalty fine or, worse, a data breach that could jeopardize the entire organization.





Narrow market, large fine.

https://techcrunch.com/2021/05/13/google-hit-with-123m-antitrust-fine-in-italy-over-android-auto/?guccounter=1

Google hit with $123M antitrust fine in Italy over Android Auto

Google has been fined just over €100 million (~$123M) by Italy’s antitrust watchdog for abuse of a dominant market position.

The case relates to Android Auto, a modified version of Google’s mobile OS intended for in-car use, and specifically to how Google restricted access to the platform to an electric car charging app, called JuicePass, made by energy company Enel X Italia.





Keep learning!

https://www.businessinsider.com/linkedin-learning-popular-free-online-classes-2021

These 10 LinkedIn Learning classes teach the most in-demand skills companies are looking for — and the courses are free until the end of May

… To help gain some insight into what to focus on, LinkedIn just released the top five trending skills based on LinkedIn Learning data from LinkedIn's top 50 companies.

Additionally, LinkedIn made some of its LinkedIn Learning courses to learn these skills completely free through May 31. That means that you can earn a certificate of completion to add to your LinkedIn profile so long as you're signed into LinkedIn and finish the courses before the end of May.