Archivist Liz · @archivist_Liz
259 followers · 87 posts · Server digipres.club

Thinking from , I wish IT in more institutions would be more transparent about how many cyber attacks they deal with. We get training on phishing attacks, but we don’t ever receive information about how many attacks are received (and hopefully thwarted). Making clear that you’re facing cyber security threats and managing them instills more trust than being a black box…

#DPCcyber

Last updated 2 years ago

Archivist Liz · @archivist_Liz
259 followers · 86 posts · Server digipres.club

Klaus Rechert at on some of the advantages but also risks of and . Even where the risks are well managed, a challenge may be how to provide meaningful access to users without compromising security.

#emulation #virtualization #DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 255 posts · Server digipres.club

"Users are dangerous, by definition" says Klaus Rechert at
Yes they are!
But also kind of necessary, I suppose. :-D
The evils we live with.

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 252 posts · Server digipres.club

"clean" Polyglots in the wild - examples given by @Ange at :

- hybrid ISOs (ISO & MBR)
- self-extracting archives (executable+archive)
- hybrid PDF (PDFs with embedded OpenOffice doc)

Check out ange's MITRA tool for some polyglot generation:
github.com/corkami/mitra

#wtfPDF #DPCcyber

Last updated 2 years ago

Archivist Liz · @archivist_Liz
259 followers · 86 posts · Server digipres.club

@mickylindlar @Ange The expression file format messology!

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 251 posts · Server digipres.club

And now at it's @Ange - always my favorite speaker when it comes to scaring the life out of preservationists worldwide!

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 250 posts · Server digipres.club

How can we improve security?

David Batho says:
- know your infrastructure: what are critical assets?
- KNOW YOUR BACKUPS! ensure you have robust backup & recovery methods
- ensure vulnerability & pactch management policies are in place
- ensure logging & monitoring of key servies are in place (early detection)
- use defence in depth --> multi-factor (incl. consistent anti-virus; awareness traning of staff & students)

...it all sounds like a no-brainer but it's so often neglected.

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 248 posts · Server digipres.club

Attacks on Education UK sector in 2022:

(...)
Q3:
- 3 major incidentes (Microsoft Exchange server compromise)
- 62 DDoS attacks targeting 24 insts

Q4:
- 5 major cyber incidents (2 FE unable to operate, HE disruption to service & BAU, student & business data exposed)

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 247 posts · Server digipres.club

Attacks on Education UK sector in 2022:

Q1:
- 4 major incidents (ransomware attacks, all via insecure remote access servies)
- 84 DDoS attacks targeting 37 insts

Q2:
- 8 major incidents (remote access, unpatched critical vulnerabilities, aabsent multi-factor authentification)
- 85 DDoS attacks targeting 28 insts

(...)

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 246 posts · Server digipres.club

"you're never going to detect a threat or an attack if you don't have effective monitoring" says David Batho at
Another great parallel to digital preservation. The resistance I often here when it comes to monitoring continues to baffle me.

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 245 posts · Server digipres.club

ransomware dates back to 1980s, becaome widespread in 2000s; main route to compromise is still phishing and social engineering; common forms are scareware, encrypting and screen locking

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 243 posts · Server digipres.club

David Batho at : Increase of cyber crime during COVID pandemic has seen a 600% increase! 90% of cyber attacks are start from a phishing incident. 3.1 billion phishing emails are sent EVERY DAY. In 2022 there was a ransomware attack every 11 seconds ... not by script kiddies, but well-trained and highly skilled experts who know how to move quickly in organizations.

Education is now one of the most targeted sectors.

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 242 posts · Server digipres.club

Listeing to these presentations makes me regret my career choice .... should have gone the pen testing route ;-P

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 238 posts · Server digipres.club

Tim Gollins considers Ransomware the currently overwhelmingly biggest security and preservation risk we have today.

Curious if people agree.

#DPCcyber

Last updated 2 years ago

Micky · @mickylindlar
194 followers · 236 posts · Server digipres.club

At Tim Gollins is talking about "The A's of Computer Security" in the 1980s, the concepts that cyber security was centered on for a long time:

- Authentication -> proving who you are
- Authorization -> proving you have right
- Access Control -> allowing you to get to information
- Availability -> you can get information when you need it
- Audit -> recording what you did and when
- Assurance -> gaining confidence in the functionality
- Accreditation -> demonstrating things are secure

#DPCcyber

Last updated 2 years ago

Sharon McMeekin · @sharonmcmeekin
138 followers · 31 posts · Server digipres.club

And tomorrow, 16 Dec, we'll be continuing the conversation with a Watch Party and live discussion from 1300-1500 AEDT/UTC+11.

dpconline.org/events/eventdeta

#DPCcyber

Last updated 2 years ago

Sharon McMeekin · @sharonmcmeekin
138 followers · 30 posts · Server digipres.club

This afternoon, we're getting ready to welcome participants and speakers along to our much anticipated & Cyber Security Event which starts in less than an 1 hour at 1400 UTC.

Follow along using :
dpconline.org/events/eventdeta

#digipres #DPCcyber #digitalpreservation

Last updated 2 years ago