It’s finally Spring! This March two members of staff go over key advice for this months’ cyber security newsletter edition. We discuss automated decision-making for quality decisions and phishing trends and indicators to help stay secure and protected.
Kevin Else
Automated decision-making
Would you make a decision based on limited information? What if that decision effects someone’s employment, financial or health status?
While automated decision-making is becoming more prevalent and more accurate, there are still concerns about its value and the potential for unintended consequences of decisions being made by algorithms or other automated processes. I am not just referring to AI powered applications but to all forms of automated processing, which implements decisions based on limited information.
One of the first acronyms I was taught when learning to programme was GIGO, if you put garbage in, you get garbage out. Any decision either made by human or a machine, is totally dependent on the quality of the information available. If nothing else the recent media storm about the information being provided by AI systems has shown that this is still true today. And how many of us have been stuck in a loop with an automated call handling system, or website chat bot.
Security and Data Privacy
But from a security and data privacy point of view, there are several very grey areas around automated decision making. Article 22 of UK GDPR states:
“The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.”
But it does not go on to state what would be considered as a “significant affect”. All decisions which could have an affect need to have a level of human oversight. What that might be is also not discussed within the act, but there is some level of guidance on the ICO’s website. See Guidance on AI and data protection | ICO and the toolkit provided here.
Confidentiality, Integrity and Availability
Information security has always tried to cover the three key areas of confidentiality, integrity and availability. Most security standards and policies take great pains to address the first and the last, but it has only been since the rise in concerns about data privacy that Integrity has been considered. Ensuring in all this mass of data that we now hold, that it is correct is often overlooked and as I said earlier, if you input garbage to any decision, you will enviably get a garbage decision out.
The mantra today should surely be Quality in Quality out.
Clare Stubley
Phishing emails are spiking in 2023
At present, there is a significant rise in Phishing and Business Email Compromise (both terms describe the many different ways in which communications are sent and received; SMS, emails, direct messages on social platforms etc.).
So, what is the trend in phishing?
In Q3 of 2022 The Phishing Activity Trends Report (published by the Anti-Phishing Working Group – www.apwg.org) has indicated that the eight most targeted industries for phishing attacks were:
- Social media 11%
- Logistics / Shipping 6%
- Payment 4%
- eCommerce / Retail 4%
- Telecoms 3%
- Cryptocurrency 2%
- Financial institution 23%
- SaaS/Webmail 17%
- Other sectors 30%
The report also references that attack delivery methods to mobile devices is increasing, that we need to be more aware of (page 5 of the report).
What are the changes in phishing training methods?
The SANS institute have published a blog, titled ‘Phishing – It’s No Longer About Malware (or even email)’ by Spitzner, 2023. This blog really delves into the trends we are seeing now, the common indicators and what experts don’t recommend anymore.
The old methods
Older traditional methods of phishing training may be increasingly irrelevant now.
Screens size:
- The tools we use, to read our personal communications have changed so much in size (think large 30-inch screens, down to tablet screens 12 inches and mobile phones from 8 to 6 inches).
Content methods:
- Misspellings – predictive text has also brought about increased misspellings in emails that this old method to indicate a Phishing email may not apply anymore.
- Hovering the cursor over a weblink – this is no longer a popular method as more people use mobile devices (smaller screens and the use of fingers) have replaced the traditional laptop/desktop model.
Current methods
So, what should we look out for in a phishing email?
In Lance Spitzners blog above, he recommends looking for emotional indicators, such as:
- Urgency – is someone asking you to give away banking details or money in the next 24 hours?
- Pressure – is someone asking you to bypass company policies?
- Curiosity – is the email too good to be true – is the email telling you, you are due a refund, and ‘click on a link to see if you are eligible’?
- Tone – is the email, which is apparently from someone in your organisation, using words they never use?
- Generic – is the email addressed to Dear customer, or the wrong name altogether?
- Personal email address – is a colleague using a personal email address to carry out work on behalf of their organisation? (Verify via a different communication channel that they have intentionally used that email address)
I tend to agree with Spitzner’s recommendations, as it focuses on “the who”, “the what” and “the why” intention of an email that can appear out of the ordinary. It also moves away from the “specifics” of the construction of the bad communications that businesses receive. There are many technical staff around that can deconstruct a bad communication, but the trick is, to encourage staff to spot bad communications as early as possible and provide a welcoming environment for bad communications to be reported to. Some businesses may have internal processes for reporting bad communications, or alternatively, the UK’s National Cyber Security Centre and Action Fraud also provide channels to report phishing emails.
Please see other resources here:
