<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exeter Science Park CyberGuides</title>
	<atom:link href="https://exetersciencepark.cyberguides.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://exetersciencepark.cyberguides.org</link>
	<description>Cyber security tips and advice for Exeter Science Park tenants</description>
	<lastBuildDate>Mon, 28 Jun 2021 09:51:55 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://exetersciencepark.cyberguides.org/wp-content/uploads/2021/04/cyber-guides-icon-150x150.png</url>
	<title>Exeter Science Park CyberGuides</title>
	<link>https://exetersciencepark.cyberguides.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Supply chain cyber security</title>
		<link>https://exetersciencepark.cyberguides.org/supply-chain-cyber-security/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Fri, 25 Jun 2021 10:03:17 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=111</guid>

					<description><![CDATA[Why is supply chain security important? Well, unfortunately, cyber criminals have started to target businesses that provide critical services to other organisations. This allows them to increase the impact of their attack and their potential for financial gain. This is because many organisations rely on external suppliers to provide a variety of core services, products&#8230;]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;">Why is supply chain security important? Well, unfortunately, cyber criminals have started to target businesses that provide critical services to other organisations. This allows them to increase the impact of their attack and their potential for financial gain.</span></p>
<p><span style="font-weight: 400;">This is because many organisations rely on external suppliers to provide a variety of core services, products and systems. For example, your business will likely be reliant on an external IT company, accountancy firm, cloud service provider, website developer, digital marketing agency, or payment provider. </span></p>
<p><span style="font-weight: 400;">Each of these external suppliers will, in turn, be relying on external parties themselves, creating a network of co-joined organisations. The net result is a large, complex supply chain. </span></p>
<p><span style="font-weight: 400;">Somewhere in this network, there could be a potential system flaw, a disgruntled member of staff or a number of vulnerabilities that could potentially lead to an incident or event, which would affect anyone in this supply chain. Often, we refer to this being the weakest link.</span></p>
<h2><span style="font-weight: 400;">For example: </span></h2>
<h3><span style="font-weight: 400;">Fastly </span></h3>
<p><span style="font-weight: 400;">Fastly are a cloud computing company that offers a content delivery network. Their customers include a number of high-profile websites including Amazon, Reddit, PayPal and Spotify. This meant that when Fastly’s system failed, all those websites could not retrieve their data and were forced offline. It would appear that the cause was a software bug that one of their customers triggered. The consequences could have been potentially more significant than downtime.</span></p>
<h3><span style="font-weight: 400;">Target</span></h3>
<p>A vulnerability in Target&#8217;s supply chain affected them back in 2013.<span style="font-weight: 400;"> This was a payment card breach through the refrigeration company Fazio Mechanical, who had access to Target’s systems to carry out maintenance. It is understood the supplier received an email containing Malware, which stole credentials to the online portal they used for Target.</span></p>
<h3><span style="font-weight: 400;">British Airways </span></h3>
<p><span style="font-weight: 400;">More recently, an attacker gained access to BA’s network through login credentials provided to a third-party provider of cargo services. From here, the attacker was able to gain access to other parts of BA’s network and access log files containing 108,000 payment card details. This was part of a testing feature that someone had not disabled. The attackers also managed to gain access to the BA website through files they accessed containing code, and then redirect customer payment card data to a different website.</span></p>
<h3><span style="font-weight: 400;">Ticket Master </span></h3>
<p><span style="font-weight: 400;">Ticket Master was using a chat-bot feature on its website, hosted by a third party, on its online payment page. This gave an attacker access to customer financial details. This potentially affected 9.4m of Ticketmaster’s customers across Europe, with 60,000 payment cards belonging to Barclays bank customers being subjected to known fraud.</span></p>
<h2>Service providers and cyber security risk</h2>
<p><span style="font-weight: 400;">The cyber security risks to the service providers businesses use become their own cyber security risks. This risk could be anything from a business email compromise through to credential stuffing.</span></p>
<p><span style="font-weight: 400;">If a cyber criminal wants to attack a larger organisation, often the easier route is to go through their suppliers, because this is normally an easier target. Their cyber defences are often nowhere near as well funded as those of larger organisations.</span></p>
<p><span style="font-weight: 400;">Suppliers can provide a route to a larger organisation’s supply chain. This means security is part of the onboarding requirement for contractors working with Government-controlled organisations. The MOD, NHS, local authorities, and increasingly, larger organisations who have identified supply chain risk within their risk management require proof of good security from their suppliers.</span></p>
<h2>Supply chain requirements</h2>
<p><span style="font-weight: 400;">The requirements for supply chain are normally determined by the perceived risk and the classification of data that the external organisation could potentially access. It might be a self-assessed <a href="https://securious.co.uk/get-cyber-essentials-cyber-essentials-plus/">Cyber Essentials</a>, an externally verified <a href="https://securious.co.uk/cyber-essentials-cyber-essentials-assisted-or-cyber-essentials-plus/">Cyber Essentials Plus</a>, <a href="https://securious.co.uk/iso-27001-certification-best-practice-approach-to-information-security/">ISO 27001</a>, a <a href="https://securious.co.uk/penetration-testing/">pentest</a>, or proof of <a href="https://securious.co.uk/pci-dss-compliance/">Payment Card Industry compliance</a> &#8211; or any combination thereof. It is a requirement to have a <a href="https://securious.co.uk/soc-security-operations-centre-logging-monitoring/">SOC/ SIEM solution</a> in place for critical national infrastructure providers, for example.</span></p>
<p><span style="font-weight: 400;">In addition, since the <a href="https://securious.co.uk/gdpr-and-achieving-gdpr-compliance/">GDPR</a> came into force in May 2018, supply chain due diligence has become part of the accountability of a data controller. This has led to a ream of third party security questionnaires asking for evidence of controls, numerous policies and assurance. </span></p>
<p><span style="font-weight: 400;">Ultimately, if the data controller has not carried out due diligence on their supply chain, they could be ultimately to blame for any breach that originated from the third party that affected their data, as in the example of BA and Ticketmaster.</span></p>
<h2><span style="font-weight: 400;">So where do you start?</span></h2>
<p><span style="font-weight: 400;">You need to map out which third party suppliers you use. Which classification of data do they have access to? And consider not only carrying out your own security checks, but also a full risk analysis of the impact an incident originating with them could have on your organisation. Could it be critical to your operations? Could it affect your customers’ data? Or could it affect your ability to operate?</span></p>
<p><span style="font-weight: 400;">Understand what ‘appropriate technical and organisational controls’ are in place, and bear in mind that this could be subjective. It may sound harsh, but can you really trust the reassurances you have been provided? Is there any third-party independent assurance or testing that you can rely on?</span></p>
<p><span style="font-weight: 400;">Though Cyber Essentials and Cyber Essentials Plus are great certifications, they are only a moment in time. So how do you know they are maintaining these standards throughout the year, between assessments? Also consider whether a self-assessed Cyber Essentials is the appropriate level of certification required for your risk assurance. Or would an independent verification provide more substantial assurance?</span></p>
<h3>Ongoing supply chain security</h3>
<p><span style="font-weight: 400;">As far as ongoing supply chain assurance, consider looking for that UKAS certified ISO 27001 (International Standard for Information Security). This is a risk-based management system of continual improvement for information security.</span></p>
<p><span style="font-weight: 400;">Web apps, websites, supplier sites etc could be independently pentested to ensure they do not contain vulnerabilities that could effectively leave a door open for an attacker, who could then use it as a route to your data.</span></p>
<p><span style="font-weight: 400;">Has the supplier put in place robust training and staff awareness around GDPR and Cyber security? And can they evidence this is their training records?</span></p>
<p><span style="font-weight: 400;">Also consider how, if a supplier needs to access your systems, you can ring fence that access to the minimum they need to carry out that function, for the minimum time. Where possible, you should set up multi-factor authentication rather than rely on just a username and password. If you have an outsourced IT company that needs to access your system remotely, make sure this is not a continually open door, but just for an authorised, pre-arranged moment in time. </span></p>
<p><span style="font-weight: 400;">Check out the <a href="https://www.ncsc.gov.uk/collection/supply-chain-security/principles-supply-chain-security" target="_blank" rel="noopener">NCSC Principles of Supply Chain Security</a>. This is effectively about identifying the supply chain, understanding the risks and putting measures in place to mitigate these.</span></p>
<h2><span style="font-weight: 400;">Final thoughts on supply chain security</span></h2>
<p><span style="font-weight: 400;">Everyone should be bearing in mind supply chain security nowadays. It doesn’t matter how much resource you put into making sure your cyber security is in good shape. If you are reliant on an external provider that doesn’t take it quite so seriously, it could have a significant impact on your operations and bottom line. </span></p>
<p><span style="font-weight: 400;">It’s also worth looking at gaining accreditations yourself, as a means of helping differentiate yourself from your competition. Increasingly, larger organisations require their suppliers </span><span style="font-weight: 400;">to have measures in place to prove they’re secure, so get ahead of the game, and your competitors, by achieving recognised security accreditations.</span></p>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Pen testing &#8211; UK executive guide</title>
		<link>https://exetersciencepark.cyberguides.org/pen-testing-and-vulnerability-scans-uk-executive-guide/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Wed, 28 Apr 2021 10:40:20 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=71</guid>

					<description><![CDATA[What is penetration testing?  Penetration testing is an attempt to safely exploit your IT systems to determine whether they’re vulnerable to attack. It includes a series of tests, carried out by a specialist penetration tester, who looks for vulnerabilities in your systems that cyber criminals could exploit. Why would I want penetration testing? Ensure your&#8230;]]></description>
										<content:encoded><![CDATA[<h2><span style="font-weight: 400;">What is penetration testing? </span></h2>
<p><span style="font-weight: 400;">Penetration testing is an attempt to safely exploit your IT systems to determine whether they’re vulnerable to attack. It includes a series of tests, carried out by a specialist penetration tester, who looks for vulnerabilities in your systems that cyber criminals could exploit.</span></p>
<h2><span style="font-weight: 400;">Why would I want penetration testing?</span></h2>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Ensure your critical assets/data are secure by identifying vulnerabilities so you can protect your environment from malicious attacks by mitigating critical threats, which reduces the likelihood of a breach </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Evidence that your systems have been tested to demonstrate to customers, business partners and stakeholders that it takes security seriously</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">It may help you meet regulatory compliance requirements (like PCI DSS)</span></li>
</ul>
<h2><span style="font-weight: 400;">What happens during a penetration test?</span></h2>
<p><span style="font-weight: 400;">We start with a scoping call, identifying the boundaries we’re working within. We’ll agree on the requirements and outcomes of the testing, before moving on to testing your systems. Our penetration testers follow a proven methodology with a series of simulated tests to identify any weaknesses in your defences &#8211; whether internally or externally. We adhere to an agreed set of rules of engagement before, during and after every penetration test.</span></p>
<p><span style="font-weight: 400;">Often it is the combination of a series of weaknesses in your systems that allows attacks, rather than a single vulnerability. That&#8217;s why our tests combine a series of lower-risk exploits in a particular sequence, to determine whether they would have any effect.</span></p>
<p><span style="font-weight: 400;">We test against the <a href="https://owasp.org/www-project-top-ten/" target="_blank" rel="noopener">OWASP top 10</a> and detail the penetration test findings in a report that includes guidance around the vulnerability, impact, threat and the likelihood of a breach within your organisation. It highlights the potential risks and recommends where additional resources should be applied to protect your systems.</span></p>
<p>We will provide a comprehensive combined technical and summary report, detailing our findings and any remediation points, and will go through these at the planned debrief within five days of pentest completion.</p>
<h2><span style="font-weight: 400;">What does a tester need to know before starting?</span></h2>
<p><span style="font-weight: 400;">Typically, penetration testers will want to know at least the following:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The list of targets, in detail</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">What the targets are (Network Infrastructure, Web Application, API, etc.)</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">In the case of a web application or API, a rough approximation to the number of endpoints/pages</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The sensitivity of the data on the systems in scope</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Where the systems are situated</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">If there are any third parties (web hosts, managed service providers)</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Who these third parties are, with written permission allowing testing</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The level of access you would like the testers to have</span></li>
</ul>
<h2><span style="font-weight: 400;">How often should we pentest?</span></h2>
<p><span style="font-weight: 400;">Penetration testing should be performed on a regular basis. This ensures that you can detect and respond to any newly discovered threats or emerging vulnerabilities that could lead to a system compromise by attackers.</span></p>
<p><span style="font-weight: 400;">Furthermore, penetration tests should also be carried out whenever:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Significant changes to your infrastructure have taken place</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Additional locations or branch offices are opened</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">You suspect or have fallen victim to an attack</span></li>
</ul>
<h2><span style="font-weight: 400;">What are the different types of penetration tests?</span></h2>
<h4><span style="font-weight: 400;">What is Black Box Testing?</span></h4>
<p><span style="font-weight: 400;">Black box testing, in the context of penetration testing, is a method of vulnerability assessment whereby the tester attacks a target with the same level of knowledge and permissions as a genuine malicious actor might have. Typically, this means the test begins with the tester receiving no information on internal workings, and no credentials or permissions.</span></p>
<p><span style="font-weight: 400;">While black box testing can offer valuable insight by using the same methodologies that a real attacker might, it is important to understand that the expected result from such a test is unlikely to include details of the potentially-critical vulnerabilities that could be detected during a white box test.</span></p>
<h4><span style="font-weight: 400;">What is White Box testing</span></h4>
<p><span style="font-weight: 400;">Conversely, white box testing involves the provisioning of a tester with the very knowledge and permissions denied from black box testers. This provides the assessor with the ability to probe the target for vulnerabilities present within the application’s core; an area hidden from a black box tester.</span></p>
<p><span style="font-weight: 400;">Performing this type of testing allows organisations to more accurately understand the risks present in their applications and services by revealing vulnerabilities that are presented only to end users with permissions greater than nil, and real attackers who have managed to crack the outermost layer of security.</span></p>
<p><span style="font-weight: 400;">Crucially, white box testing is not exclusive of black box testing; meaning a white box assessment includes everything involved with a black box test, but also includes testing of otherwise unreachable areas.</span></p>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
<p><em><strong><a href="https://securious.co.uk/penetration-testing/">Click here</a> to learn more about our penetration testing services</strong></em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>ISO 27001 &#8211; UK executive guide</title>
		<link>https://exetersciencepark.cyberguides.org/iso-27001-uk-executive-guide/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Wed, 28 Apr 2021 10:36:54 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=65</guid>

					<description><![CDATA[What is ISO 27001? ISO 27001 is the international standard for Information Security. It provides a framework for an information security management system. This enables organisations to manage the security of assets like finance information, intellectual property, employee details or information entrusted by third parties. Who is ISO 27001 for? ISO 27001 is a great&#8230;]]></description>
										<content:encoded><![CDATA[<h2><span style="font-weight: 400;">What is ISO 27001?</span></h2>
<p><span style="font-weight: 400;">ISO 27001 is the international standard for Information Security. It provides a framework for an information security management system. This enables organisations to manage the security of assets like finance information, intellectual property, employee details or information entrusted by third parties.</span></p>
<h2><span style="font-weight: 400;">Who is ISO 27001 for?</span></h2>
<p><span style="font-weight: 400;">ISO 27001 is a great tool for organisations of any size and in any sector to use to keep their information assets more secure. It allows the business to demonstrate that it complies with current international best practice, and that it is effectively securing information assets and managing the risks around them. It also ensures that the organisation constantly improves its systems and processes to fit evolving needs.</span></p>
<h2><span style="font-weight: 400;">Why would I want it?</span></h2>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Use as a tool to manage <a href="https://securious.co.uk/gdpr-and-achieving-gdpr-compliance/">GDPR compliance</a></span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Prove you have a system in place to continually review and improve your information security. This improves credibility with customers, business partners and staff</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Bid for contracts with larger organisations who require the certification</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Minimise the evidence required for larger organisation to complete their due diligence</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Identify your information assets and their value, so you can make informed decisions to mitigate risks and ensure efficient spending</span></li>
</ul>
<h2><span style="font-weight: 400;">What does it involve?</span></h2>
<p><span style="font-weight: 400;">There are several steps involved in achieving ISO 27001:</span></p>
<p><span style="font-weight: 400;">Firstly, it’s important to have a solid understanding of ISO 27001. This includes what it is, and the importance of managing your assets, risks and incidents. At this stage, it is important to determine your scope and understand the <a href="https://www.hse.gov.uk/managing/plan-do-check-act.htm">Plan, Do, Check, Act approach</a> (which you may be familiar with through HSE).</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The next step covers the importance of leadership and identifying your Information Security Management System (ISMS) team, allocation of resources, competence, and communication.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Then we can move on to the planning stage, creating objectives and deciding how we’ll achieve them</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The planning stage also includes identifying information assets and building an asset register so that you can move on to identifying the risks to these assets.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Risk assessment is also part of the planning stage, including risk methodology, risk assessments and building the risk register</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">The final part of the planning involves determining risk treatment to mitigate the risks to an acceptable level.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">At this stage we also create the Statement of Applicability. This takes all the controls in Annexe A of ISO 27001 and determines whether they are applicable</span></li>
<li aria-level="1">Once you understand what you are protecting and the controls you have identified, you can implement the plans to mitigate risks that your information assets may be exposed to.</li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Performance Evaluation and improvement helps us to check that what we have put in place is working and then feed this back into opportunity for improvement. This will include a full internal audit, and feedback into the ISMS Team.</span></li>
</ul>
<h2>About implementation</h2>
<p><span style="font-weight: 400;">The implementation will involve completion of relevant policies, procedures and forms and the ISMS manual to communicate how to maintain the Information Security Management System. We normally phase these within the levels so that this is not simply a document completion exercise, but something that fulfils the need at that particular stage.</span></p>
<p><span style="font-weight: 400;">Once implementation is complete then you are ready for a stage one audit to determine that you have an ISMS in place.</span></p>
<p><span style="font-weight: 400;">This is followed by a stage two audit which then checks to see if the ISMS is working.</span></p>
<p><span style="font-weight: 400;">Once the accreditation body is satisfied that you have met the standard, they will issue you with your certification.</span></p>
<p><span style="font-weight: 400;">The most important goal for us is to share knowledge and ensure that the organisation implementing ISO 27001 is competent and confident to maintain this system as part of their business as usual.</span></p>
<h2><span style="font-weight: 400;">How long does it take?</span></h2>
<p><span style="font-weight: 400;">We have managed to implement ISO 27001 within a 12 week process for some clients. However generally an implementation takes around 3-6 months (sometimes longer depending on resource availability and scope of the organisation)</span></p>
<h2><span style="font-weight: 400;">How much does it cost?</span></h2>
<p><span style="font-weight: 400;">We tailor our <a href="https://securious.co.uk/iso-27001-certification-best-practice-approach-to-information-security/">ISO 27001 consultancy</a> service to your individual needs and circumstances. So please get in touch and we&#8217;ll provide you with a quote based on your situation and requirements.</span></p>
<p><span style="font-weight: 400;">Alternatively, we&#8217;ve pioneered the  <a href="https://securious.co.uk/bespoke-iso-27001-academy/">Securious ISO 27001 Academy</a>. We work with businesses in a series of online workshops, for just £2,895 +VAT which includes all the necessary templates.</span></p>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Essentials and how to get it</title>
		<link>https://exetersciencepark.cyberguides.org/cyber-essentials-and-how-to-get-it/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Wed, 28 Apr 2021 10:27:11 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=61</guid>

					<description><![CDATA[Here’s our ultimate guide to Cyber Essentials, what it is, why you should want it and how you get it. First, we&#8217;ll give an overview of the scheme, its purpose and value, then we&#8217;ll run through the 5 areas Cyber Essentials covers so you get a much clearer grasp of what’s involved. So what is&#8230;]]></description>
										<content:encoded><![CDATA[<p><strong>Here’s our ultimate guide to Cyber Essentials, what it is, why you should want it and how you get it. First, we&#8217;ll give an overview of the scheme, its purpose and value, then we&#8217;ll run through the 5 areas Cyber Essentials covers so you get a much clearer grasp of what’s involved.</strong></p>
<h2>So what is Cyber Essentials?</h2>
<p>Cyber Essentials is a great first step towards making your systems more secure. It also helps you prove to suppliers that you are taking cyber security seriously.</p>
<p>Cyber Essentials certifications are suitable for organisations of all sizes. They are <a href="https://www.gov.uk/government/publications/cyber-essentials-scheme-overview" target="_blank" rel="noopener">backed by the government</a> and <a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank" rel="noopener">supported by The National Cyber Security Centre</a> and <a href="https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/" target="_blank" rel="noopener">the Information Commissioner</a>.</p>
<h2>And why should you want it?</h2>
<p>Cyber Essentials helps you guard against 80% of the most common forms of cyber-attacks and includes automatic cyber liability insurance.</p>
<p>It is increasingly required if you want to provide services to large clients so they can be sure you aren’t a weak link in their supply chain.</p>
<h2>What about Cyber Essentials Plus?</h2>
<p>This is the big brother version and it covers the same controls as Cyber Essentials, only a third party (like us) verifies that the responses on the self-questionnaire are correct. This means it has considerably more credibility with third parties, which is why it’s increasingly required of any supplier to the Ministry of Defence, and encouraged for those working with government departments, local authorities and large organisations. <a href="https://securious.co.uk/get-cyber-essentials-cyber-essentials-plus/" target="_blank" rel="noopener">Read more about Cyber Essentials Plus here</a></p>
<h2>Ok, so how do you get it?</h2>
<p>Cyber Essentials consists of a simple self-assessment questionnaire that asks you about what you have in place to protect your business from cyber threats. It covers 5 specific ‘controls’ that have been produced by the government and industry bodies.</p>
<p>To understand these better, let&#8217;s run through them:</p>
<h3>1) Keep your devices and software up-to-date</h3>
<p>Ensuring that all your devices’ operating systems and applications are up-to-date is very important, because manufacturers and developers regularly release patches to address security vulnerabilities that have been discovered. Cyber Essentials will enable you to identify if you are running unsupported software, and if your supported applications / operating systems are up-to-date.</p>
<p><em>If your devices and software aren’t up to date, it’s like having no cyber front door at all</em></p>
<h3>2) Protect yourself from viruses and other malware</h3>
<p>Protecting your systems with anti-virus software, intrusion detection/prevention systems would be akin to having CCTV or a security guard at your entrance, alerting you to potential threats and even stopping them on your behalf. Most popular operating systems include effective virus and threat protection… if all the modules are enabled. How is your configuration?</p>
<p><em>Having no anti-virus or intrusion protection is like leaving your cyber front door wide open</em></p>
<h3>3) Control who has access to your data and services</h3>
<p>Would you let everyone you know have a key to your home? No way! Cyber Essentials helps you take control of who has access to your data and services. Often clients don’t understand the significance of administrator and standard user accounts, and yet getting this wrong could result in an intruder having access to far more than you’d like.</p>
<p><em>Having no access controls is like leaving your cyber security front door ajar</em></p>
<h3>4) Use secure settings for your devices and software</h3>
<p>Most devices and software applications are supplied with default configurations that make getting started easy for the user. However, as above, leaving default settings can make it easier for cyber attackers to gain access to your data. Sharing user accounts and login credentials and having weak passwords also represents a significant risk.</p>
<p><em>Not using secure settings on devices and software is like leaving your cyber front door closed, but on the latch</em></p>
<h3>5) Use a firewall to secure your internet connection</h3>
<p>Do you have a firewall? Of course, you do! A larger organisation may have a bespoke firewall device, a smaller company or home worker will have a software firewall built into the hub or router provided by their ISP. But have you changed the default password on your firewall/router? No?</p>
<p><em>A misconfigured firewall is like leaving your cyber front door closed, but not locked</em></p>
<h2>Cyber Essentials is not difficult!</h2>
<p>So there you have it. There’s nothing scary involved and once you have achieved Cyber Essentials, not only are you likely to be more secure, you can also use it to open new opportunities and differentiate yourself from your competitors.</p>
<h2>How much does Cyber Essentials cost?</h2>
<p>The cost of the certification scheme is limited by the Government to just £300 (+ vat). The cost of Cyber Essentials Plus is from £1,620 (+ vat).</p>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
<p>&nbsp;</p>
<p><a href="https://securious.co.uk/cyber-essentials-and-cyber-essentials-plus/"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-3415 size-large" src="https://securious.co.uk/wp-content/uploads/2021/04/How-to-get-Cyber-Essentials-Ultimate-Guide-Securious-Exeter-Devon-UK-1024x154.png" alt="How to get Cyber Essentials Ultimate Guide - Securious cyber security Exeter, Devon, UK" width="1024" height="154" /></a></p>
<p>&nbsp;</p>
<p><strong><em>Read more cyber security guides:</em></strong></p>
<p><a href="https://securious.co.uk/supply-chain-compliance-and-cyber-security-accreditation-for-new-business-and-procurement/" target="_blank" rel="noopener">Supply chain compliance and cyber security accreditation for new business and procurement – ultimate UK guide</a></p>
<p><a href="https://securious.co.uk/siem-solutions-and-socs-a-guide-for-better-cyber-security-and-compliance/" target="_blank" rel="noopener">SIEM solutions and SOCs: a UK guide for better cyber security and compliance</a></p>
<p><a href="https://securious.co.uk/pci-compliance-uk-ultimate-guide/" target="_blank" rel="noopener">PCI Compliance UK – ultimate guide</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>UK Guide to SIEM Solutions and SOCS</title>
		<link>https://exetersciencepark.cyberguides.org/uk-guide-to-siem-solutions-and-socs/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Wed, 28 Apr 2021 10:24:23 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=58</guid>

					<description><![CDATA[Overview &#8211; a UK guide to SIEM solutions and SOCs SIEM solutions and SOCs (Security Operations Centres) offer UK organisations the opportunity to improve their cyber security and compliance, with standards such as PCI DSS, ISO 27001 and Cyber Essentials. This guide explains what they are, how they work, and how they help keep UK&#8230;]]></description>
										<content:encoded><![CDATA[<h2>Overview &#8211; a UK guide to SIEM solutions and SOCs</h2>
<p>SIEM solutions and SOCs (Security Operations Centres) offer UK organisations the opportunity to improve their cyber security and compliance, with standards such as PCI DSS, ISO 27001 and Cyber Essentials. This guide explains what they are, how they work, and how they help keep UK organisations more secure.</p>
<h2>SIEM solutions</h2>
<h3>What is a SIEM solution?</h3>
<p>SIEM stands for Security Information and Event Management. A SIEM solution works by collecting logs from multiple devices across a network and amalgamating the data into a usable form. This includes identifying activity that is abnormal.</p>
<h3>What does a SIEM solution do?</h3>
<p>SIEM solutions enable the monitoring and analysis of data from a wide range of sources. They help you cut through the noise and make the data useful. For example, they can identify vulnerabilities and suspicious activity. SIEM solutions also keep a record of all activity in case forensic analysis is required.</p>
<h3>How are SIEM solutions useful?</h3>
<p>SIEM solutions help security teams (often described as a Security Operations Centre &#8211; see below) to identify and address vulnerabilities, as well as responding quickly to potential threats and accessing key information from the past for the purposes of forensic analysis &#8211; or to achieve compliance requirements more easily.</p>
<h3>How do SIEM solutions work?</h3>
<p>SIEM solutions undertake a number of key functions in order to deliver the information required by security teams.</p>
<ol>
<li><strong>Collect data.</strong> SIEM solutions use collection agents to collect log data from a variety of sources in the client environment. These may include devices, servers, firewalls and other equipment.</li>
<li><strong>Store data.</strong> SIEM solutions store some or (for example in the case of Monikal) all log data. This enables extensive analysis and historical review where this is required.</li>
<li><strong>Understand what is ‘normal’.</strong> SIEM solutions ‘learn’ their environment through a combination of data collection and added rules or policies. This means a user can tell the SIEM solution what normal would look like so it can identify and alert staff if something unusual takes place.</li>
<li><strong>Consolidate and correlate.</strong> SIEM solutions are able to analyse a wide range of data from a large number of sources and make sense of it, including flagging the severity of potential incidents.</li>
</ol>
<h3>Examples of how SIEM solutions help improve cyber security and compliance</h3>
<p>A SIEM solution could help you identify or respond to the following situations:</p>
<ul>
<li>A member of your team downloads your whole client database onto a USB stick</li>
<li>Someone logs into your CEO’s email account from China and then, just five minutes later, your CEO logs in from London</li>
<li>A junior member of your team escalates their privileges and gains access to confidential data</li>
<li>An intruder within your systems changes a system event log in an attempt to cover their tracks</li>
<li>Any of your systems are not correctly time synchronised – important for forensic analysis etc.</li>
<li>Detection of attacks at system boundary (firewall etc.)</li>
<li>Employees are attempting to visit blocked websites which may host malware etc.</li>
<li>There is an increase in user account lockouts, indicating possible brute force authentication attacks</li>
<li>There is an increase in successful authentication user sessions via remote access, this could be an indicator of possible insider threats etc.</li>
<li>The status of backup activities, prolonged failures could impact disaster recovery readiness</li>
<li>There is a change to protected asset access, changes could indicate malicious activity</li>
<li>There are an excessive amount of out-of-hours remote access attempts, excessive attempts could be an early indicator of things such as industrial espionage</li>
<li>Critical or high vulnerabilities exist on systems and have not yet been patched</li>
</ul>
<h3>Choosing a SIEM solution &#8211; why Monikal?</h3>
<p><a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> is the first SIEM solution designed in the UK specifically for the needs of mid-level organisations.</p>
<p>It is built on world-leading technology from <a href="https://assuria.com/" target="_blank" rel="noopener">Assuria</a> &#8211; a supplier to enterprise-level organisations and governments around the world. So <a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> is right up there in terms of its technology. However, everything we have done in developing <a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> has been designed to meet the needs of mid-level and growing organisations. From the onboarding to the pricing to support, we understand businesses that might not traditionally have been in the market for an enterprise-level SIEM solution, but need and deserve the same benefits. <a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> is for those kinds of companies and organisations.</p>
<h3>Benefits of the Monikal SIEM</h3>
<p><a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> has a number of significant benefits including:</p>
<ul>
<li>Ability to detect and respond to cyber threats</li>
<li>Increased resilience to external and internal threats</li>
<li>Identification of criminal or negligent behaviours</li>
<li>Insight and intelligence about user behaviours</li>
<li>Full recording of all network activities</li>
<li>Regular cost-efficient vulnerability scanning</li>
<li>Monitoring and reporting in line with PCI DSS requirements</li>
<li>Reports on the 5 security controls required for Cyber Essentials Plus</li>
<li>Forensic capabilities in the event of an incident</li>
<li>Hosted in a Tier 1 UK data centre</li>
<li>UK-based support</li>
</ul>
<p>In addition to this, <a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> meets all the requirements recommended by the National Cyber Security Centre in the <a href="https://www.ncsc.gov.uk/guidance/security-operations-centre-soc-buyers-guide" target="_blank" rel="noopener">SIEM solution buying guide.</a></p>
<h2>What is a SOC (Security Operations Centre)</h2>
<p>A Security Operations Centre (or SOC) is a team responsible for security within an organisation. In this context, a SOC will be the team responsible for monitoring and responding to issues identified by the SIEM solution, which they will use to optimise the cyber security and compliance needs of the organisation.</p>
<h3>How does a SOC work?</h3>
<p>The way a SOC (Security Operations Centre) works will depend on the size and needs of a particular organisation. While an enterprise level organisation may have a full in-house team of specialist analysts, a smaller mid-level organisation may look to out-source the requirements of monitoring and responding to security incidents identified by a SIEM.</p>
<h3>Examples of how a SOC can help cyber security and compliance</h3>
<p>An effective SOC should mean a dedicated focus on an organisation’s security. For example:</p>
<ul>
<li>A SIEM might detect unusual login attempts and the SOC team will examine these. Then, they&#8217;ll identify if they are legitimate and, if not, can put in place additional procedures to minimise the likelihood of a breach</li>
<li>A SIEM might show that certain devices &#8211; eg those of employees now working from home &#8211; have not had the latest software patches and as a result are now a security risk. The SOC team can then undertake these as a matter of urgency.</li>
<li>A SIEM might show attempts to access the user account of an ex-employee &#8211; then the SOC team can investigate where these are coming from and ensure these and any related accounts from the same ex-employee are deactivated.</li>
<li>A SIEM could be configured to show that an employee clicked on a malicious link in a phishing email. Despite safeguards being in place to prevent the download, the SOC team can address any training requirements to minimise the chances of this happening in future.</li>
<li>A SIEM might show internal threat actors such as an employee who is logging onto their account and downloading data out of work hours. The SOC team can run reports to highlight this unusual activity and notify the client to investigate further.</li>
</ul>
<h3>Why the Securious Managed SOC solution is ideal for mid-level organisations?</h3>
<p>Working in conjunction with our SIEM solution Monikal, Securious offers <a href="https://securious.co.uk/soc-security-operations-centre-logging-monitoring/">a managed SOC service</a> especially tailored to smaller but ambitious and growing mid-level organisations in the UK.</p>
<p>Typically, these companies will have an IT director or CISO (chief information security officer). They may also have an in-house or managed IT service, but these will not be security specialists. Additionally, the senior personnel will not have the time available to monitor SIEM activity on a daily basis.</p>
<p>This is where the <a href="https://securious.co.uk/soc-security-operations-centre-logging-monitoring/">Securious Managed SOC service</a> uniquely fills a gap. Securious will monitor the <a href="https://monikal.co.uk/" target="_blank" rel="noopener">Monikal</a> dashboard and respond to alerts of abnormal activity or vulnerabilities. They will notify the client when action is required with clear recommendations on what needs to be done.</p>
<p>The net result is a much more secure and compliant organisation. And this comes at a fraction of the spend of having a full-time in-house team.</p>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
<p><a href="https://securious.co.uk/soc-security-operations-centre-logging-monitoring/">Click here to learn more about our managed SOC services</a></p>
<p><a href="https://monikal.co.uk/" target="_blank" rel="noopener">Click here to learn more about the Monikal SIEM solution</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>UK Guide to PCI Compliance</title>
		<link>https://exetersciencepark.cyberguides.org/uk-guide-to-pci-compliance/</link>
		
		<dc:creator><![CDATA[wptony]]></dc:creator>
		<pubDate>Wed, 28 Apr 2021 10:13:03 +0000</pubDate>
				<category><![CDATA[Guide]]></category>
		<guid isPermaLink="false">http://exetersciencepark-cyberguides-org.stackstaging.com/?p=55</guid>

					<description><![CDATA[What is PCI compliance? To achieve PCI compliance means to meet the standards of the Payment Card Industry Data Security Standard (PCI DSS). This standard contains a set of requirements designed to increase data security and protect merchants and customers when taking and making payments by debit or credit card. The PCI Security Standards Council (PCI SSC)&#8230;]]></description>
										<content:encoded><![CDATA[<h2>What is PCI compliance?</h2>
<p>To achieve PCI compliance means to meet the standards of the Payment Card Industry Data Security Standard (PCI DSS). This standard contains a set of requirements designed to increase data security and protect merchants and customers when taking and making payments by debit or credit card.</p>
<p>The <a href="https://www.pcisecuritystandards.org/" target="_blank" rel="noopener">PCI Security Standards Council</a> (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.</p>
<p>The Council was founded in 2006 by American Express, Discover, JCB International, MasterCard and Visa Inc.</p>
<p>The current standard is <a href="https://www.pcisecuritystandards.org/document_library?category=pcidss&amp;document=pci_dss" target="_blank" rel="noopener">PCI DSS 3.2.1</a></p>
<h2>Is PCI compliance necessary in the UK?</h2>
<p>Yes!</p>
<p>All UK merchants and service providers that process, transmit or store payment card data must be PCI DSS compliant.</p>
<p>For merchants: if you accept payment by debit or credit card for goods or services, you must be PCI DSS compliant, even if you use a third-party organisation or platform to process the payment (see below).</p>
<p>For service providers: if you are involved in processing, storing or transmitting cardholder data on behalf of another party, you must be PCI DSS compliant.</p>
<h2>Do I need PCI compliance if I use a payment provider like Stripe or SagePay?</h2>
<p>Yes!</p>
<p>If you use a payment service provider, PCI compliance becomes a shared responsibility between yourself as the merchant and the payment provider.</p>
<p>Using a payment service provider will normally mean you, as the merchant, have no need to see or have any access to the card holder’s information. This makes it much easier to meet your PCI compliance requirements, but it does not remove them.</p>
<h2>What could be the consequences of not being PCI compliant?</h2>
<p>The main consequence of not being PCI compliant is that you may not be protecting cardholder data. This means you could be responsible for a breach and that could be enormously costly for your business and your customers.</p>
<p>A data breach could result in both financial and identity theft from your customers. This will need to be reported to the <a href="https://ico.org.uk/" target="_blank" rel="noopener">Information Commissioner</a> (and your customers) and you could be liable to financial penalties that could be significant under the GDPR (General Data Protection Regulation), as well as the card brands.</p>
<p>In addition, your bank may set considerable (and costly) requirements for you to be able to continue accepting card payments after the breach. For example, if you have been subject to a cardholder data breach, you will be required to conduct a PCI council-approved forensic investigation and then achieve the highest level of compliance (Level 1 – see below) regardless of the number of payments you take.</p>
<p>Beyond these fines, the impact of a cardholder data breach on your reputation could be catastrophic.</p>
<p>Even in the absence of a breach, failure to be PCI DSS compliant means you are likely to be liable for fines and additional transaction charges from your bank. They may also withdraw the facility to take payment by credit and debit card if you continue to be non-compliant.</p>
<h2>How much could I be fined if I am not PCI compliant?</h2>
<p>If you continue failing to meet your PCI compliance requirements, in the worst circumstances your acquirer could withdraw your facoility for accepting payment cards.</p>
<p>You could also be subject to increased fees for every card payment you take. One company we recently engaged with was paying over £1,000 per month in non-compliance fees when the issue was resolvable with a one-off investment of around £3,000.</p>
<p>On top of this, you can incur fines costing as much as tens of thousands of pounds depending on the level of breach and cardholder data stolen.</p>
<h2>What are the PCI compliance levels?</h2>
<p>There are four levels of merchant based on the number and type of transactions they take. Level 1 concerns those merchants that take the highest number of transactions (or who have had a data breach previously) and Level 4 concerns those merchants who take the fewest number of card payments.</p>
<p>The specific criteria for each compliance level are:</p>
<h3>Level 1</h3>
<p>Merchants who process over 6 million payment card transactions a year (or those who have suffered a cardholder data breach in the past).</p>
<h3>Level 2</h3>
<p>Merchants processing between 1 million and 6 million payment card transactions a year.</p>
<h3>Level 3</h3>
<p>Merchants processing between 20,000 and 1 million payment card transactions a year.</p>
<h3>Level 4</h3>
<p>Merchants processing fewer than 20,000 payment card transactions a year.</p>
<p>See more from <a href="https://usa.visa.com/support/small-business/security-compliance.html" target="_blank" rel="noopener">VISA </a>and Mastercard.</p>
<h2>What does it take to be PCI compliant?</h2>
<p>PCI DSS compliance covers three main areas:</p>
<ul>
<li>Handling card data: ensuring card holder data is collected and transmitted securely</li>
<li>Storing data securely: ensuring that if you store card data, the payment environment meets a series of specific requirements into terms of the technology, people and processes involved – see the 12 steps of PCI DSS below</li>
<li>Annual validation: for all levels, an annual validation via form – an SAQ or Self Assessment Questionnaire – is required. However, the specific requirements depend on a number of factors and vary by level of merchant and acceptance channels (see below). In addition, any organisation that needs to be PCI DSS compliant may need to validate that to payment processors, suppliers or clients, and customers.</li>
</ul>
<h2>What are the 12 steps PCI DSS version 3.2.1?</h2>
<p>These 12 steps are the main security controls or requirements for achieving PCI compliance, broken into six objectives:</p>
<h3>Build and maintain a secure network and systems</h3>
<p>1) Install and maintain a firewall configuration to protect cardholder data</p>
<p>2) Do not use vendor-supplied defaults for system passwords and other security parameters</p>
<h3>Protect cardholder data</h3>
<p>3) Protect stored cardholder data</p>
<p>4) Encrypt transmission of cardholder data across open or public networks</p>
<h3>Maintain a vulnerability management programme</h3>
<p>5) Protect all systems against malware and regularly update anti-virus software</p>
<p>6) Develop and maintain secure systems and applications</p>
<h3>Implement strong access control measures</h3>
<p>7) Restrict access to cardholder data by business need to know</p>
<p>8) Identify and authenticate access to system components</p>
<p>9) Restrict physical access to cardholder data</p>
<h3>Regularly monitor and test networks</h3>
<p>10) Track and monitor all access to network resources and cardholder data</p>
<p>11) Regularly test security systems and processes</p>
<h3>Maintain an information security policy</h3>
<p>12) Maintain a policy that addresses information security for all personnel</p>
<h2>What are the PCI compliance validation requirements by level?</h2>
<p>The different levels (see above) require a different set of validation procedures which can be summarised as follows:</p>
<h3>Level 1</h3>
<p><strong>Annually</strong></p>
<ul>
<li>File a ROC (Report on Compliance) by a Qualified Security Assessor (QSA – see below) or an internal assessor if signed by a company officer</li>
<li>Submit an AOC (Attestation of Compliance) Form submitted</li>
</ul>
<p><strong>Quarterly</strong></p>
<ul>
<li>Network scan conducted by an Approved Scan Vendor (ASV)</li>
</ul>
<h3>Level 2</h3>
<p><strong>Annually</strong></p>
<ul>
<li>File a ROC (Report on Compliance) or SAQ (Self Assessment Questionnaire) by a Qualified Security Assessor (QSA – see below) or an internal assessor if signed by a company officer</li>
<li>Submit an AOC (Attestation of Compliance)</li>
</ul>
<p><strong>Quarterly</strong></p>
<ul>
<li>Network scan conducted by an Approved Scan Vendor (ASV)</li>
</ul>
<h3>Level 3</h3>
<p><strong>Annually</strong></p>
<ul>
<li>Complete an SAQ (Self-Assessment Questionnaire – see below) signed by a company officer</li>
<li>Submit an AOC (Attestation of Compliance)</li>
</ul>
<p><strong>Quarterly</strong></p>
<ul>
<li>Network scan conducted by an Approved Scan Vendor (ASV</li>
</ul>
<h3>Level 4</h3>
<p><strong>Annually</strong></p>
<ul>
<li>Complete an SAQ (Self-Assessment Questionnaire – see below) signed by a company officer</li>
<li>Submit an AOC (Attestation of Compliance)</li>
</ul>
<p><strong>Quarterly</strong></p>
<ul>
<li>Network scan conducted by an Approved Scan Vendor (ASV</li>
</ul>
<h2>What is an SAQ (Self Assessment Questionnaire)?</h2>
<p>A Self-Assessment Questionnaire (SAQ) is a self-validation tool to assess security for cardholder data. It’s suitable for smaller merchants and service providers who are not required to submit a Report on Compliance.</p>
<p>The Self-Assessment Questionnaire includes a series of yes-or-no questions for the security requirements. If an answer is no, your organisation may need to specify what you will do to achieve the required level and by when.</p>
<p>There are a series of nine different SAQs available from the PCI Security Standards Council to meet different types of merchant and service provider requirements.</p>
<p>See more from the <a href="https://www.pcisecuritystandards.org/pci_security/completing_self_assessment" target="_blank" rel="noopener">PCI Security Standards Council</a></p>
<h2>What is a PCI QSA (Qualified Security Assessor)?</h2>
<ol>
<li>Qualified Security Assessor (QSA) companies are independent security organisations that have been qualified by the PCI Security Standards Council to validate an organisation’s compliance with PCI DSS.</li>
<li>QSA employees are individuals who are employed by a QSA Company and have satisfied and continue to satisfy all QSA Requirements.</li>
</ol>
<h2>Common PCI compliance myths</h2>
<p>There are many myths and misunderstandings about PCI compliance. These are some we encounter on a regular basis:</p>
<h3>MYTH – PCI compliance is only ‘a thing’ for big businesses.</h3>
<p>If you’ve read this guide you will be clear that every merchant that takes payment by credit or debit card needs to be PCI DSS compliant and can face significant consequences if they aren’t.</p>
<h3>MYTH – We use Sage Pay/Stripe/Paypal etc and they are fully PCI compliant so we don’t need to be.</h3>
<p>As explained above in this guide, every merchant who takes payment by card needs to be PCI compliant. Using a payment provider like Sage Pay or Stripe or Paypal may make it much easier to achieve and demonstrate that you are PCI compliant, but it does not in any way make you exempt.</p>
<h3>MYTH – I do not need to be PCI compliant because it is not a legal requirement.</h3>
<p>This is not the case, but it is required by the payment card companies and banks. Failure to comply means they can both remove the option for a merchant to take credit card payments and charge them much more for doing so. Should an organisation face a breach of cardholder data and not be PCI DSS compliant, the penalties are likely to be more severe.</p>
<h3>MYTH – I can just answer ‘Yes’ to all the questions on the Self-assessment Questionnaire (SAQ).</h3>
<p>This is an extremely dangerous position to take because the SAQ has to be signed by an officer of the company. If they answer ‘Yes’ to a question when they aren’t adequately meeting that control, the banks and payment card companies will take that very seriously. If a card data breach occurs and it becomes clear the merchant was never actually compliant, the consequences for the organisation could be extremely serious.</p>
<h3>MYTH – I never committed to being PCI compliant and I can wait until the bank asks me to.</h3>
<p>This is a common misunderstanding and another very dangerous one. The terms signed when a merchant opens a bank account will state that PCI compliance is required and you will not be allowed to operate a merchant account if you are not PCI compliant.</p>
<h2>How much does it cost to achieve PCI compliance?</h2>
<p>The cost of PCI engagement will depend on scope which includes a number of different scenarios. For example: number of transactions, type of transactions (e.g. face to face, ecommerce), payment environment and so on.</p>
<p>It will also depend on where you are and how much work is needed to meet the appropriate compliance levels.</p>
<h2>How can Securious help me get or maintain PCI compliance?</h2>
<p>Securious has been a PCI QSA company since 2016 and has two fully qualified and highly experienced PCI QSAs.</p>
<p>We are based in Exeter, Devon but undertake PCI QSA work nationally and internationally.</p>
<p>Our mission is to build cyber security confidence and when it comes to PCI DSS compliance, we will work with you to make the process as efficient as possible, helping you understand what you need to do, and why.</p>
<p>Typically, we approach PCI QSA engagements as follows:</p>
<ul>
<li>We start by assessing your situation to determine the scope and what level you need to be reporting at. Then, we conduct a gap analysis, looking at what you already have in place against the requirements, so we can determine the additional measures you need to implement to achieve compliance.</li>
<li>We will then advise and assist with any remediation work needed to meet the standard.</li>
<li>Finally, we will carry out your assessment and complete the necessary reports and questionnaires as required.</li>
</ul>
<h2><span style="font-weight: 400;">What should I do next?</span></h2>
<p>If you need any help, feel free to contact the team at <a href="http://securious.co.uk">Securious, the South West’s leading cyber security company</a>. They have provided the content on this site and are passionate about helping businesses and organisations understand and improve their cyber security.</p>
<p>If you have any questions, a member of the team would be more than happy to speak with you &#8211; just fill in the contact form below, or get in touch with them on 01392 241110, or <a href="mailto:info@securious.co.uk">info@securious.co.uk</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
