Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, 21 June 2018

A Market Overview on the Changing Data Landscape



- Alan Jamieson


We live in changing times and data has become a major part of our lives.  With the recent enactment of the General Data Protection Regulation (GDPR) in late May, we have all been inundated with privacy emails from our suppliers emphasizing that we own our data which helps both parties with relevant information, offers etc.

Having data and the rights to opt out are important, but how do we know it’s safe with ongoing, frequent data breaches across the globe? Can we cope with the number of offers sent to us from suppliers who hold our data, and can we be assured that they are using my current and historic personal data?  If data has been collected over weeks, months and even years, the reality is the more data you can analyze, the greater insight can be obtained.

A few years ago, data was expected to increase in volume by 100% annually, which challenged computing infrastructures and brought to light questions such as where is the most cost-effective place to store the data? And, what analytical tools should we be using? Can the tool look at all data types (structured and unstructured)? Do we need to hire data scientists looking to make real-time decisions? Are we aware that running complex queries take time? Today, most data volumes are increasing higher than previously predicted, especially in social media where data volumes can increase by Petabytes of data daily (not solely text but increasingly with video and audio content) and through our adoption of IoT products.

Terminology is also changing, terms such as big data. which had various means based on its context.  Gaining business insights from the increasing volumes of data being held are important to help improve user experiences, drive business efficiency, help fine tune marketing offers, and predict what equipment needs maintenance to avoid unnecessarily outages etc.

While we can protect data through encryption technologies either when data is at rest or in transit, searching for data in databases (on prem or in the cloud), repositories such as Microsoft SharePoint and other documentation types is also a critical challenge. It’s great to collect data but it you can't easily access it, you are incurring unnecessary storage business costs that will not be recovered.

Speaking to enterprise customers and global vendors, there is another change in how we interact with data.  With our widening generation employee bases across most enterprise companies, how we access data is changing.  Our younger global workforce, who have grown up with smartphones, are increasingly looking to request information or data via a voice request and not a keyboard.  Enterprise companies must cater for information or data access via keyboard and/or voice request but only to authorized data requestors. 

We at BOHH Labs address this changing data landscape with a service that provides voice and keyboard access to secure data enabling data analytics to be performed whilst importantly preventing data breaches. We are hoping to lead a shift in how the market both views and interacts with their data. After all, data is a business asset and we are looking to help companies unlock its value.

Tuesday, 8 May 2018

Security, so what is it exactly?


- BOHH CEO Simon Bain

Talking to customers, vendors and the great and the good of the industry, it is no surprise that we seem to have a data security issue at the moment. Maybe though not the obvious one of data being stolen, but one of the description of what security actually is!

These two quotes from Sridhar Muppidi, who serves as VP and CTO IBM Security,
 are taken out of context, but they sum up a large sector of the technology industry’s view on security:

  1. "IBM Security is a division that focuses on keeping the bad guys out and the good guys in, it's as simple as that," Muppidi said. 
  2. "It's a discipline," Muppidi said about security. "It's a discipline that can be morphed into a program, a set of practises, solutions and products."

See them here: http://www.eweek.com/security/ibm-security-cto-details-how-cyber-security-fits-into-ibm-portfolio

While there may not be anything fundamentally wrong with these two statements, I do believe that they totally miss the point and try to turn security of customers’ data, documents, and corporate secrets in to a commodity for IBM to play with, and worse it trivializes the issues.

I do not believe that security is just a discipline. Yes, users do have to learn how to treat data and how to help themselves. But, we in the industry must start to look at security in a different light. Security is privacy and we should help maintain the privacy of data and not just by trying to keep the “bad guys out,” after all, a lot, if not most hacks are insider initiated not external. So, in that case you keep the “bad guy out” by not employing them!

We need to start talking privacy and looking at ways of how we can truly keep data private both from insider threats as well as external ones. 

Threat detection is as good as useless for privacy at the point of attack. It is a great learning resource to work out how to secure data after the fact.

Threat prevention is the only way that can work, but it is multifaceted. We do need to look at keeping “The Bad Guys Out,” but not just out of the network, also out of the data. And, the “bad guys” are not just external people (Guys and Gals’) they may also be inside. So, we need to make sure that the data is secured in such a way that makes it usable, but also completely private and away from prying eyes, whether they be a system admin or someone who has been given admin permissions to do some data cleansing.

Security is not about creating back-to-front detention centers where one group is kept out and another is kept in! It is about privacy of information.

Security must also not get in the way of peoples working tasks. Otherwise, yes, they will circumnavigate it or they cannot do their job and they then find themselves without work.

As such, I believe our job as technologists is to make this possible, not just talk about it, not create long overly lawyered disclaimers, but actually create applications that create a full privacy zone where data can be utilized free from fear that sensitive data will be lost or stolen.

Only time will tell where the industry is headed and how we as a collective group approach security.

Friday, 6 April 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Sears and Delta Airlines customers' payment data exposed by third-party vendor breach

A third-party vendor data breach that took place last autumn exposed payment card information belonging to customers of Delta Airlines; Sears, Roebuck and Company; and possibly additional businesses, according to three separate public disclosures. Read more…

Facebook Will Notify 87M Users Whose Data May Have Been Used By Cambridge Analytica

On Monday, users of Facebook will see a notification at the top of their news feeds. The social media company's under pressure for just how much it let other companies use the information of millions of Facebook users, so it will tell people how to have their information spread to fewer places. Read more…

Here comes the next round of encryption legislation

Another Senate bill that intends to regulate encryption in private devices is in the works. Staffers for the Senate Judiciary Committee have been speaking with representatives of large U.S. technology companies in recent months to receive feedback for potential future legislation. Read more…

Misconfigured Clouds Compromise 424% More Records in 2017

Cybercriminals are increasingly aware of misconfigured systems and they're taking advantage, report IBM X-Force researchers. Insider mistakes like networked backup incidents and misconfigured cloud servers caused nearly 70% of all compromised records in 2017, according to new data research. Read more…



Tuesday, 3 April 2018

Why Data Integrity is the Key to Protecting Corporate Data



In this age of enterprise mobility and competiveness, there is a strong demand to have data and information available anywhere at any time. As a result, the majority of companies have embraced the trend of integrating tools such as Cloud and mobile services, chatbots and IoT devices to meet this demand. However, these applications bring a host of security threats for disclosing or leaking private company information like we have seen weekly over the last several years.

It’s clear data is an asset to businesses and holds a lot of weight to how successful a business can be. That is why it is vital for companies to take a look at how they are protecting data across their entire network.

Traditionally, security professionals within an organization identify the most sensitive information and pick and choose what information should be protected and selectively give access privileges to certain individuals. However, this approach to security is incredibly dated and does not hold up to the new cloud and mobile services companies and users alike are using to access and store data. As such, with the massive amount and constantly changing data that is flowing through a company’s network from various users and applications, it makes it difficult to manage the security of all this data.

With the heavy reliance on an open and integrated cloud environment to access their data, it’s critical for us as security professionals and technologists to look at what security tools are put in place currently and ask ourselves if we are doing it right and providing enough trust and security to enable organizations to allow their customers to use that data correctly. It’s time to take an approach that assumes all data is at risk from internal and external threats and focus on making data security a priority by combining the approach to weave the access to data with security from the start. If we don’t, we are going to lose our data.

What Does This Mean?

To make data security a priority, the core focus must be on protecting the data itself at the foundation level. Regardless of the user, it is important not to assume that every data request that comes in is from a trusted source. As such, at BOHH Labs we use a process that separates out every request from the requestor, and then use a combination of unique keyless end-to-end encryption, Artificial Intelligence technology, Natural Language Processing, and In-Memory Distributed Blockchain Ledger technology, to ensure the request gets checked at all points of vulnerability: the request, processing and backend data stores. This means every data request must be validated at each of these three points before moving forward, and never has direct access to the backend system so anyone coming on to the system is not able to hack their way through. This will allow companies to protect data no matter where it is being stored, accessed or transacted such as on on-premise databases, cloud platforms, IoT devices, mobile services and more.

Data is increasingly a critical part of businesses and consumers’ lives; thus, it’s essential to protect it without hindering the ability to actually use it. As such, at BOHH we believe it is time to revaluate how companies are securing the interaction with their data and make data access and security of it a priority to ensure companies can securely deploy innovative enterprise applications and cloud services without opening them up to massive, widespread, and malicious security threats.

Friday, 30 March 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Under Armour Says 150 Million MyFitnessPal Accounts Hacked

Under Armour Inc., joining a growing list of corporate victims of hacker attacks, said about 150 million user accounts tied to its MyFitnessPal nutrition-tracking app were breached earlier this year. An unauthorized party stole data from the accounts in late February, Under Armour said on Thursday. It became aware of the breach earlier this week and took steps to alert users about the incident, the company said. Read more…

Boeing hit and recovering from possible WannaCry attack

Aerospace manufacturer Boeing is reporting that the company has mitigated what may have been a small outbreak of WannaCry ransomware that hit one of its manufacturing facilities on March 28. Read more…

As Atlanta Seeks To Restore Services, Ransomware Attacks Are On The Rise

Atlanta city officials are not saying whether they were strong-armed into paying the $51,000 ransom to hackers holding many of the municipality's online services hostage, but they did announce progress in restoring networks on Thursday. Read more…

Facebook Could Be Fined Millions for Violating Consent Deal

Former Federal Trade Commission officials say that Facebook Inc. appears to have breached a 2011 consent agreement to safeguard users’ personal information and may be facing hundreds of millions of dollars in fines. The agency could fine Facebook up to $40,000 per violation per day -- which could add up quickly with millions of users involved -- if it finds the social media giant broke its earlier promises to protect user data, they say. Read more…


Friday, 23 March 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Facebook Controversy: What to Know About Cambridge Analytica and Your Data

This week’s uproar over Facebook Inc. started years ago, with the mishandling of user data. Now that incident, and what followed, is at the center of a debate over how well the world’s largest social network protects its trove of user data. Read more…

Atlanta Ransomware Attack Freezes City Business

Ransomware that struck the city of Atlanta early Thursday morning froze internal and customer-facing applications, but officials say backups are in place and they expect to pay city employees on time next week. Read more…

Cryptocurrency mining malware uses five-year old vulnerability to mine Monero on Linux servers

Hackers are using a five-year-old security vulnerability to infect Linux servers with cryptocurrency-mining malware. The cryptojacking campaign exploits CVE-2013-2618, an old vulnerability in Cacti's Network Weathermap plug-in, an open source tool which is used by network administrators to visualise network activity. Read more…

House passes controversial legislation giving the US more access to overseas data

This week, the House of Representatives passed controversial legislation that would clarify and expand how data held overseas can be obtained by law enforcement in the United States. The change is part of the massive omnibus spending bill, and it incorporates measures first submitted earlier this year as the CLOUD Act. Read more…


Friday, 16 March 2018

Weekly News Roundup



Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Cybercriminals spotted hiding cryptocurrency mining malware in forked projects on GitHub

Cybercriminals have found another way to spread their malware: uploading cryptocurrency mining code to GitHub, according to security researchers. Developers 'fork' projects on GitHub, which means making a copy of someone else's project in order to build on it. In this case, the cybercriminals fork random projects and then hide malicious executables in the directory structure of these new projects. Read more…

Bitcoin stealing malware distributed on download.com for nearly a year

Bitcoin stealing malware that swaps user accounts with that of the attacker was found to be hosted on Download.com servers for nearly a year. Read more…

Vengeance by DDoS: No one is immune

In what may catch many by surprise, distributed denial of service (DDoS) attacks are being used against companies, organizations, and individuals as an act of vengeance or revenge. No one is immune; documented victims have included non-profit organizations, community colleges, courts and law enforcement entities. Read more…

Victims can sue Yahoo for massive breaches, federal judge says

Plaintiffs suing Yahoo for failing to protect all of the company’s 3 billion users can move forward with the majority of their case, a federal judge in California ruled on Friday. Read more…

Friday, 2 March 2018

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

23,000 HTTPS certificates axed after CEO emails private keys

A major dust-up on an Internet discussion forum is touching off troubling questions about the security of some browser-trusted HTTPS certificates when it revealed the CEO of a certificate reseller emailed a partner the sensitive private keys for 23,000 TLS certificates. Read more…

Equifax Discloses 2.4 Million More Mega-Breach Victims

Equifax says it identified 2.4 million U.S. consumers whose names and snippets of their driver's license numbers were stolen, adding to what is one of the largest and most sensitive data breaches on record. Read more…

Big banks want to weaken the internet’s underlying security protocol

The tech and financial industries are butting heads over the latter’s push to intentionally weaken a security protocol that underlies how the public securely accesses the vast majority of the internet. Critics are charging that the financial industry is pushing for a weakness in the new version of the Transport Layer Security (TLS) protocol, all for the sake of avoiding the time, effort and resources needed to adapt to the new standard. Read more…

Another massive DDoS internet blackout could be coming your way

A massive internet blackout similar to the Dyn DNS outage in 2016 could easily happen again, despite relatively low-cost countermeasures, according to a new study. The DDoS attack on Dyn took many major web sites offline for most of a day, including Twitter, PayPal, Reddit, Amazon, and Netflix. Millions of compromised IoT devices, belonging to the Mirai botnet, flooded Dyn's DNS service with up to 1.2 TBps of bogus traffic, making it impossible to respond to genuine DNS requests for their customers' websites. Read more…



Tuesday, 10 October 2017

The BOHH Breakdown, Part 6: How BOHH Labs Helps Meet GDPR Requirements


In our last post, we talked about how the ease of implementation when integrating a new cybersecurity tool into your existing infrastructure network can help enhance productivity. Today we will address a situation many companies are facing and trying to beat the clock on: how to comply with GDPR regulations and how BOHH Labs’ security solutions can help organizations successfully address many of the requirements.

The General Data Protection Regulation (GDPR) is the biggest change to European Union (EU) privacy law in over 20 years, and it will have a major impact on how many organizations in the EU and across the globe collect, use, and store personal information about individuals. Although greater data protection is becoming more important than ever, the burden of updating security polices and strategies for organizations to comply with GDPR can be overwhelming and take a considerable amount of time and resources. As the deadline for complete GDPR compliance in May 2018 nears, many companies are scrambling to find solutions and make updates that meet the requirements. 

BOHH Labs’ security solution was built on making data privacy a priority, so we are confident that our security solution will help organizations successfully address GDPR requirements. Our approach to security is to become more dynamic within the existing system and protect data from within. While our security approach focuses on on-premise and Cloud data security, the concept of securing and managing data in certain domains has many parallels with GDPR regulations. 

How we do this?

Unique Encryption
Our approach to security is to encrypt all data in real-time, while still retaining search capabilities, but only providing access to data to authorized parties. Our patented, unique encryption algorithms are proven to secure with no key store or data storage, enabling us to help organizations mitigate data breaches and any associated penalties.

Data Records 
BOHH Labs’ proven security platform helps companies to maintain data records and audit data is available if required (although as part of our data privacy philosophy, we don’t keep historic data today, but it can be stored within an enterprise database).

Infrastructure Agnostic
Our appliance is infrastructure agnostic and is deployed on top of existing systems between the infrastructure, firewalls and transactions with both Cloud and on-premise implementations, so there is automatic backend data protection as data goes in and out of the entire ecosystem. 

Data Masking
GDPR punishes businesses that fail to leverage appropriate protection measures – such as data masking technologies—as a part of their overall security posture. Data masking enables companies to fulfill GDPR requirements to pseudonymize (anonymize) sensitive data that otherwise could directly or even indirectly identify a specific individual.  BOHH’s encryption capability helps companies to protect/mask data from unauthorized users. 

Right to Access
GDPR also introduces the right for data subjects to obtain from the data controller confirmation as to whether personal data concerning them is being processed, where and for what purpose. This means companies must be able to find and produce a copy of an individual’s data quickly among the millions of data they hold. BOHH Labs helps solve this with its patented, secure federated search that enables for one request to perform a simultaneous search across multiple repositories in real-time to return results in under a millisecond. 

As organizations work toward implementing strategies to be compliant with GDPR, BOHH Labs is here to help companies focus on data privacy and provide a simple and quick solution to successfully meet many of the requirements. For more information on how BOHH Labs can help with compliance, reach out to us at info@bohh.io.

Now that we’ve looked at how BOHH Labs’ security solution can help organizations successfully address GDPR requirements, check back in next Tuesday when we will revisit some of the most pressing cybersecurity trends in 2017 we cited at the beginning of the year and track where the industry is at as the end of the year nears. 

Friday, 29 September 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Deloitte hit by data breach

Corporate finance giant Deloitte suffered a cyber-attack that compromised confidential data, including the private emails of some of its clients, the company has confirmed. Its system had been accessed via an email platform and "very few" clients had been affected, Deloitte said. Read more…

Russian hackers targeted election systems in 21 U.S. states

The Department of Homeland Security (DHS) finally notified election officials in 21 U.S. states about Russia trying to hack their election systems before the 2016 election. Read more…

Whole Foods Market Investigates Hack Attack

Upscale supermarket chain Whole Foods Market says it's investigating an apparent payment card data breach that affects facilities located in some of its stores, although none of its checkout lanes. Payment card data stolen from taprooms and restaurants, the supermarket chain says. Read more…

Sonic hit with class action suit over POS data breach

Two Sonic Drive-In customers are taking legal action against Sonic for allowing their payment card data to possibly have been compromised when the fast-food chain's POS system was hacked and are demanding the company pay for credit monitoring services for those affected. Read more…


Wednesday, 20 September 2017

SAP+Google Cloud Intelligent App Challenge Winner, BOHH Labs Delivers Security of Data Transit and Access



At BOHH Labs, we are excited to announce that our secure app solution was selected as a winner of the Intelligent App Challenge, sponsored by SAP & Google Cloud. We are honored to be selected from hundreds of challenge registrants and recognized for our emerging solution that is based on some of today’s most innovative technologies including the use of SAP HANA Express Edition, Google Cloud Platform, Machine Learning, Artificial Intelligence and encryption to address the security of data transport and access for Cloud and Internet of Things (IoT) streamline workflows.

As part of our submission for the Intelligent App Challenge, we demonstrated how our app enables users to search securely across multiple databases and repositories using voice and text commands to find information quickly in real-time.

We combined our BOHH Labs Secure Federated Search application with our Secure BOHH(T) Bot application, running through SAP HANA and Google Cloud Platform, to enable users to not only find data and documents in a secure way off their cloud services (in this case Google Drive), but also to ask the devices they are working on to find and return specific information they are looking for in real-time.

For the challenge, we highlighted how our technology works using an IoT scenario for maintenance on a mechanical device using a hand-held device from Samsung that allows an engineer hands-free ability to access all the data needed to deliver maintenance on a device that needs service in real-time. Before starting the maintenance service, the engineer onsite connects to the BOHH Labs application and asks BOHH to find a drawing of the equipment document repository so he can see the exact location of the part that needs service, as well as the data from the last person who serviced the part and what service was completed. BOHH securely accesses the maintenance databases, the sensor database, stock inventory etc. in real-time and returns the requested data using a patented encryption method and AI technology to manage ports, maintain a secure connection and interact with user requests.

The engineer can continue to ask BOHH to connect him with information needed throughout the servicing of the device until it is completed. After the servicing is completed, the engineer can communicate with the BOHH application and provide an update on what service he did and it will automatically go directly back into the database to record the service.

This example highlights how BOHH can streamline tasks that require real-time data access and streamline workflow without the worry of third-party intervention and hacking, time-wasted looking for data or even loss of data all together. To see a demo of the above scenario on how BOHH Labs’ app works, click here.

If you like to learn more about BOHH labs, we are attending and participating in SAP TechEd 2017 and look forward to speaking to you more on how our technology works. You can also visit us at www.bohh.io for more information.


Tuesday, 19 September 2017

The BOHH Breakdown Part 3: The Philosophy Behind Our Data Security Approach



In the last post, we talked about why BOHH Labs is the next step in securing your organization. Today, we will be discussing the philosophy behind our security approach and how our approach provides greater security than other existing technologies.

Our security approach is built on four principles that we believe are important to adhere to:

  • Usability. The result must be practical and usable, not just another thesis based on theoretical knowledge.
  • Practical. The outcome must be able to be put in to a practical use without too much disturbance to existing systems and leveraging existing database investments.
  • Ownership. The data we were looking to protect initially was usernames, passwords, address details, etc. In other words, data that belongs to us as an individual. So, we set out to make sure that the data not only belonged to us as users and individuals, but that we as individuals were also responsible for its safe keeping. Not that we wanted to pass the onus of the protection away from the organization charged with storing the data, but that, that organization should not be held responsible for the misuse of the data, and they should not be able to access the raw data that a user has requested should be made anonymous.
  • Accessible. From the outset, we decided that having data secured was useless, unless it was also accessible to the data owner. This meant that one of our main goals was to make sure that this data was also searchable.

With these four main points as our foundation, we started looking at how BOHH could improve the entire approach to data security. Our first focus was to address how hacks on data were being carried out. There are a lot of different scenarios, and at the time we were not looking to protect data from every single one, but we were interested in what made it possible for an unauthorized person, or an authorized person with bad intentions, capable of not just extracting the data but also rendering what was seen as encrypted data in to readable and usable text. This was the most important question to be answered, and the answer to which would give us our starting point.
How BOHH Works

With the driving force centered around what made it possible for unauthorized users to get access to “secure” data and use it for exploits, we developed a unique formula using encryption and Artificial Intelligence technologies to protect data and infrastructures from within and invalidate data when accessed by unauthorized users, rendering it useless to the unauthorized party. How does this work?


  1. BOHH cuts off the request from its originator as it enters the system
  2. BOHH then creates a session of containerized encrypted memory
  3. BOHH ensures that the requestor never accesses the end-point applications
  4. BOHH uniquely utilizes AI within the containers to learn from and then remove fraudulent access 

This process enables our core focus to be on protecting the data itself, so this enables BOHH to protect data no matter where it is being stored, accessed or transacted such as on on-premise databases, cloud platforms, IoT devices, mobile services and more. In future blogs, we will address further how our technology protects data in these different areas.
Data is increasingly a critical part of businesses and consumers’ lives; thus, it’s essential to protect data.  Once trust has been broken, it impacts an organization’s profitability with potential data breach fines, brings reputational risk, and more importantly, user/consumer confidence in the impacted organization.

Despite these known impacts, enterprise security continues to be a major challenge for organizations. BOHH Labs offers a new approach to help minimize business risk and disruption. BOHH’s security platform presents a significant opportunity for enterprise customers to leverage existing infrastructure investments to enhance their security strategy, while being confident that their assets (confidential and customer information) is safe against the imminent threat of attack.

Now that we’ve addressed how BOHH Labs approaches data security, come back next Tuesday, when we will take a deeper dive into how BOHH is putting its security to use with a real-life, IoT scenario.


Friday, 15 September 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Billions of Bluetooth devices vulnerable to takeovers, MITM attacks; no user action required

Billions of Bluetooth devices, including those running on Android, iOS, Linux, and Windows, contain major vulnerabilities that can allow malicious actors to remotely execute code, take over devices, and perform man-in-the-middle (MITM) attacks, researchers have reported. Read more…


Equifax confirms Apache Struts security flaw it failed to patch is to blame for hack

Equifax has confirmed that a web server vulnerability in Apache Struts that it failed to patch months ago was to blame for the data breach that affected 143 million consumers. Read more…

FA to increase World Cup cyber security over hacking concerns

The English Football Association will increase cyber security for the 2018 World Cup in Russia after hacking attacks by a group suspected of links to a Russian spy agency, media reports said. Read more…

Apple explains Face ID on-stage failure

Apple has explained why its new facial recognition feature failed to unlock a handset at an on-stage demo at the iPhone X's launch on Tuesday. The company blamed the Face ID glitch on a lockout mechanism triggered by staff members moving the device ahead of its unveil. Read more…



Tuesday, 12 September 2017

The BOHH Breakdown, Part 2: Why BOHH Labs is The Next Step in Securing Your Organization


Last week in our first installment of the BOHH Breakdown, we talked about the increasingly complex world of cyber warfare and outlined the need for the industry to rethink the entire approach to protecting data. Today, we will be addressing how and why BOHH Labs is the next step in securing your organizations’ data and networks and to mitigate the new wave of cyber warfare, while still enabling business productivity and innovation to flourish.

Based on customer demand, business is continually moving towards offering on-demand and digital services, which is enabling trusted interactions between human entities (individuals, communities, enterprises and governments) over multiple channels (mobile networks, the Internet, call centers, face-to-face and others). However, as we discussed last week, the sheer number of methods deployed to carry out cyberattacks, their complex nature, sophistication, and evolving character have made it difficult for institutions to stay protected and keep company and customer data safe across all these channels. Add in the fact that most organizations are adopting digital strategies to increase business productivity while meeting consumer demands, and this leaves most companies in a catch 22 and constant battle for the balance between security, productivity and innovation.

Here enters BOHH Labs. We offer a suite of patented and proven solutions that enable organizations to help minimize risk and disruption to business and innovation.

Security:

BOHH Labs’ security solution was built on making data privacy a priority. Our approach to security is to become more dynamic within the existing system and protect data from within. Our security approach focuses on on-premise and Cloud data security, as well as ensuring the secure transport of data in real-time. We do this using unique encryption algorithms and our own AI security platform that acts as a first line of defense against internal and external intrusion. We encrypt all data in real-time, but only providing access to data to authorized parties. Unlike other security solutions, even in the unlikely event of an unauthorized user accessing data, data protected by BOHH Labs is rendered unusable for that actor. Our patented, unique encryption algorithms are proven to secure with no key store or data storage, enabling us to help organizations mitigate data breaches and any associated penalties. In future blogs, we will address further how our technology protects data in on-premise databases, as well as with interaction on all Cloud, mobile and IoT devices.

Productivity:

While we believe it is invaluable to keep data protected, it also serves no benefit to keep it protected if it is not accessible. BOHH Labs offers a patented, secure federated search that provides users the ability to access data and content securely from anywhere, while still fully encrypted with document-level encryption at rest and in transit for storage and sharing on any device or desktop. Our search enables that one request performs a simultaneous search of your desktop, email, cloud stores and databases in real-time to return results in under a millisecond. This eliminates the worry of third-party intervention and hacking, time-wasted looking for data or even loss of data all together.

Innovation:

Today’s customers demand voice access to their data, rather than simply browsing services to integrate with their digitally connected lives both at work and home. However, with these voice-activated digital services as the primary access channels for users, comes an increased threat for cyberattacks. Built on our security approach outlined above, BOHH offers companies a level of flexibility that enables innovation through our unique Secure BOHH Bot. Our bot is an Artificial Intelligence (AI) voice and messaging interface that delivers seamless and secure transaction of all incoming and outgoing customer data requests in real-time without compromising performance, customer experience or customer accessibility. This allows companies to provide a safe and secure method to offer digital services to their connected customers and enable them 24/7 communication regarding their account information from anywhere on any device. 

The balance and business decision-making between security, productivity, and innovation is becoming increasingly challenging for organizations in 2017. With the BOHH Labs suite of solutions, we can help companies minimize business risk and disruption while innovating secure digital products for their customers. 

Now that we’ve addressed how BOHH Labs enables organizations to prioritize security without jeopardizing innovation, come back next Tuesday, when we will take a deeper dive into BOHH’s security and the philosophy behind our approach.

Tuesday, 5 September 2017

The BOHH Breakdown, Part 1: How to Get Closer to a Cure for Cyber Hacks


In the first installment of the BOHH Breakdown series, BOHH Labs’ CEO and search and security expert Simon Bain, outlines the steps needed for the industry to prepare for the increasingly complex world of cyber warfare.


The incidents of cybercrime continue to rise every day at alarming rates. As ransomware, fraud, Point-of-Sale, phishing, keylogging, and malware-based attacks and more continue to gain traction, organizations are at increased risk of enduring costly hacks that grow more intricate and difficult to prevent each day.

Even though organizations have the industry’s best solutions: firewalls, VPN’s, SSL certificates, encryption, and authentication policies, we still see on a daily basis that millions, and in some cases billions, of records (for example, consumer information, money, and private personal details), are stolen from these so-called secure systems. 

So how do we go about fixing this?


Diagnosing the Problem

What’s wrong with cybersecurity today? Currently, most security solutions are merely analyses of the network that assess network holes and system weaknesses without patching or offering fixes. Simply put, the main focus and financial investment is on support for early detection and minimizing the impact of attacks; however, this does not address the root of the problem. 

In essence, it’s like getting a diagnosis from your doctor without receiving any guidance on treatments: “We noticed that you’re sick and the operation will be costly. Good luck.”

Immunizing the Disease 

Detecting security weaknesses is not enough to keep hackers, bent on stealing resources and consumer funds and information, from winning. 

Security systems need to evolve automatically with each new call; they need to be able to react to situations, like how the human immune system reacts to an incoming disease – much like an immunization can react when germs enter the body, rather than creating feeble and unrealistic goals to prevent the germs spreading disease in the first place. 

Similarly, data must be protected from within. It is up to organizations to try preventive measures initially, to stop the disease – in this case the hack – in the first place and to protect consumer data before there’s a threat.

Rebuilding the “System”

The first step the industry needs to take: Rethink the entire approach to protecting data.

Instead of only securing the network from the outside in, the focus must turn to tools securing the network inside out. This starts by turning a critical eye to the shortcomings of current solutions. 
  • Firewalls help with external hacks, but cannot defend against internal ones and other sophisticated attacks. 
  • Database encryption, perhaps among the most buzzed about solutions today, is also among the most insecure methods in use. 
  • VPNs are of varying effectiveness that are only as good as the users’ knowledge of protocols and public Wi-Fi and password management.
  • Two-Factor Authentication: Though this may seem more secure that just having a password, two-factor authentication technologies actually face many of the same risks as password-driven systems.
  • SSL Certificates: Too often people think simply using SSL certificates protects them from all web security vulnerabilities. While SSL certificates offer an encrypted connection between the client server, many servers are badly configured and often expose data instead of securing it.
Current technologies still have a part to play in security, but they remain unreliable in a vacuum without addressing their vulnerabilities in the first place. 

Creating a Collaborative “Vaccine”

Improving security in 2017 requires industry collaboration. With all the detection solutions being employed currently, organizations must share the insights they learn during the nearly constant stream of hacks they face daily. 

Take virus protection – everyone shares that information publicly and within a few hours the virus is dead. Most organizations do not want to disclose to the public incidents of breaches for fear of damage to their reputation and customer loyalty, but without open communication organizations are not making progress when it comes to security analysis and preventing future hacks. 

While some organizations have started to unite behind closed doors and there are industry regulations emerging on how and when to report a breach, the industry as a whole needs to create a knowledge-sharing standard. The reality is that most hackers collaborate, so organizations should too.

If industry wants to take steps in improving security in 2017, we must reevaluate the approach and commit to investing in security by viewing it as an integral part of an organization’s livelihood and not just a routine, integrated process. 

Now that we’ve addressed how the industry can get closer to a cure, come back next Tuesday, when we will share with you how BOHH Labs is the way forward to secure organizations in the new wave of cyber warfare. 

Friday, 1 September 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Two million customer records pillaged in IT souk CeX hack attack

Second-hand electronics dealership CeX says two million customers may have had their personal information swiped by hackers. Several Reg readers dropped us a line after receiving an email from the Brit biz that informed them their personal details including first name, surname, address, email address and phone number had been illegally accessed by miscreants. Read more…

Trump's cybersecurity advisors resign en masse

Another Trump panel has taken a hit after eight out of 28 of its members resigned en masse. Members of the National Infrastructure Advisory Council (NIAC), which advises Homeland Security on matters of cybersecurity, have dropped out of the panel due to several reasons. In the resignation letter obtained by NextGov, they said the president doesn't give enough attention to the country's cyber vulnerabilities. Read more…

Hurricane Harvey scammers use disaster as phishing bait

As Hurricane Harvey continues to devastate southeast Texas, scammers are taking advantage of the catastrophe by sending phishing emails that can steal sensitive information or infect targeted machines, according to a new warning from US-CERT. Read more…


FBI/IRS-Themed Email Scam Spreads Ransomware

A phishing scam that uses fake FBI and Internal Revenue Service emblems in emails is circulating and attempting to entice users to download ransomware, the IRS warned this week. Read more…


Tuesday, 29 August 2017

Introducing the BOHH Breakdown


We are excited to introduce a weekly, multi-part blog series called the BOHH Breakdown focused on all things security. From on-prem, cloud and mobile security needs to IoT and emerging technologies, this series will offer a security breakdown on the topic of the week and offer insight on how BOHH Labs helps improve your security strategy. 

Each Tuesday we will post a new blog in the series and we look forward to your thoughts.

Keep a lookout for the first installment of the BOHH Breakdown next week on Tuesday, September 5th, as we take a look at the industry approach to security and how we can get closer to a “cure” for hacks.

Friday, 11 August 2017

Weekly News Roundup



Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Oracle Offers API to Link Banks to Fintechs
Oracle Corp. is offering a payments application programming interface based on the ISO 20022 standard that will allow banks to more easily collaborate with fintechs and other third parties. Read more…

UK data protection laws to be overhauled

Britons could obtain more control over what happens to personal information under proposals outlined by the government. Citizens will be able to ask for personal data, or information posted when they were children, to be deleted. Read more…

HBO Data Dumped, Hackers Demand Millions

Attackers who reportedly stole 1.5TB of data from HBO release a second data dump and demand millions in ransom. Hackers behind the recent HBO data breach have dumped a second collection of stolen files and demanded millions in ransom. Read more…

UK calls for smart car cyber protection

A new generation of internet-connected cars will have to be better protected from cyber attackers, under tough new UK government guidance. Read more…


Thursday, 10 August 2017

The Impact GDPR Compliance Will Have Across the Entire Business Ecosystem



Insight on GDPR from BOHH's Becca Bauer

There is now less than a year for organizations collecting, using or working with anyone that handles data regarding citizens in the EU to get their policies in place to comply with the mandated General Data Protection Regulations (GDPR) that go into effect in May 2018.

Although greater data protection is becoming more important than ever as our economies become digitized and the potential for breaches have become a daily norm, the burden of updating security polices and strategies for organizations to comply with GDPR can be overwhelming and take a considerable amount of time and resources. As companies scramble to integrate GDPR-compliant solutions in to its data protection and collection strategy, it is likely to have some profound impacts on how the entire business operates. Below are three ways some of the key changes mandated by GDPR will make an impact on organizations’ entire ecosystem.


Reputation Damage and Strict Penalties


It is no secret that data breaches often bring negative press and a lack of trust among consumers, and while some of these breaches result in settlements, most until now have not had financial penalties. One of the major impacts GDPR will have on organizations is the pressure of strict fines if companies are found to be in breach of GDPR or do not follow the proper procedures following the event of a breach. According to the EU GDPR site (http://www.eugdpr.org), the new regulations have fines of up to 4% of annual global turnover or €20 million, which is enough to not only financially hurt a company, but will also draw attention to them in public for being in defiance of the law and a standard set of security and privacy regulations that organizations must comply with to ensure an individual’s data is protected.


Approach to Data/Technology Management
Much of GDPR centers around how companies are collecting, storing and using individual’s information. Under GDPR, companies must offer individuals, whose data they hold, to the right to be notified if a data breach exposes their information, the right to access their own personal data when they request it, the right to be forgotten, and the right to data portability. These new regulations will have a major impact on the strategies companies use to protect data privacy. This means organizations need to build more flexible architectures that will easily allow them to incorporate innovative technologies and security solutions that meet these new requirements. However, this can quickly become expensive and complex with updates such as legacy to cloud infrastructure overhauls and the addition of at least one or more products to enhance data protection.

Not only does this bring increased costs to how the data privacy strategies work, but it also brings in to question the management of these processes. Collaboration will be crucial when updating these policies. There needs to be coordination among the different departments in the organization from the various IT teams handling how data comes in and out of the company to the marketing department who collects data for analytics purposes. Cross collaboration will be key in ensuring the whole company is complying with GDPR, but it will most likely lead to a costly, complex strategy to update the data management across the whole company ecosystem, as well as a cultural shift in how your employees approach working with data and working and sharing data with other departments.

New Leader on Your Security Team


For companies who operate on a large scale, it will become mandatory to add a new leader to your security team: appointment of a Data Protection Officer. This new team member will have to be an expert on data protection practices, as well as be provided with all the necessary resources to comply with GDPR and maintain their knowledge on the industry. This equates to increased costs to the business with a new salary for an expert senior team member, as well as new technologies and resources needed for the DPO to carry out their job.

As organizations work toward implementing strategies to be compliant with GDPR, it is important they take in to account the implications all these changes will have organization-wide. With the need for increased budgets, personnel and technologies, the effort to become GDPR compliant must take in consideration the impact will have on the whole ecosystem and the amount of time and resources needed.