Secondly, a keyword attack scanned our network for any file or folder that used certain sensitive keywords in its naming convention, such as ‘passport’ or ‘confidential’, and copied files not just from our corporate networks but also from drives used by staff for personal purposes as permitted under the Library’s Acceptable Use of IT Policy. This policy, and the staff education that accompanies it, will be reviewed in the light of lessons learned from the cyber-attack. The files and folders copied in this way represent around 40% of the copied documents. Oh really? It's going to be reviewed?
Tell you a secret about non-profits, schools, and cultural institutions. Their PII policies are ridiculously lax. And also? Most PCI compliance...isn't.
These places are rife with sensitive data (like, say, donor information) that is incredibly valuable to attackers.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Taggart :donor: (mttaggart@infosec.town)'s status on Saturday, 09-Mar-2024 18:52:59 JSTTaggart :donor: