HRreview Header

Some HR and payroll systems could be affected by the Heartbleed bug

-

- Advertisment -

shutterstock_130285649

Security experts have advised that theĀ Heartbleed computer bugĀ risks extend beyond just websites and are warning UK SMBs to check that their HR and payroll software is not at risk. Using vulnerable OpenSSL code which may be found in some SaaS (software as a service) or online web platforms, the widespread bug could enable hackers to compromise systems undetected and collect sensitive personal and financial data and even the decryption keys themselves.

With HR systems holding personal information such as bank details, passport numbers and payroll information, companies need to ensure this data is secure. Paul Beaumont, Managing Director of Octopus HR,Ā says: ā€œIt is vital to know that your software provider takes its responsibility to security seriously and invests accordingly.Ā Octopus HRĀ invests heavily in the security infrastructure around its system and has been unaffected by the Heartbleed bug which, whilst hitting the headlines now, has actually been around for the last two years.ā€

ā€œWhile I’m pleased to say that Octopus HR has not been affected by this security flaw there may, however, be some providers whose software has been vulnerable to an attack. Organisations that use a SaaS HR system are strongly advised to check with their provider whether their HR system is hosted on servers having used any of the affected versions of OpenSSL. If it does, they have been, and still are, vulnerable to hackers.ā€

ā€œCompanies whose providers are using OpenSSL will have been susceptible to an attack so all users with access to the system will need to change their passwords. However, it is important to check that the software provider has implemented all required security patches and revised their SSL certificates first or any new login details will also be at risk.ā€

Organisations can check to see whether their provider uses OpenSSL by pasting the URL used to login to the system (beginning withhttps://) into aĀ free online tool.

Latest news

Just 30% of recruiters say they receive high-quality job applications, research finds

Fewer than one in three hiring professionals say they received high-quality applications for their most recent hire.

Finance professionals ‘expect ESG and DEI focus to decline’

More than half of financial services professionals in the UK believe their company leaders will place less emphasis DEI over the next five years.

Crystel Robbins Rynne: Corporate pride – True LGBTQ+ allyship or meaningless rainbow-washing?

It’s Pride Month, and workplaces around the world are publicising their LGBTQ+ solidarity. Yet the multi-coloured flags get packed away as soon as July arrives.

Tribunal claims related to menopause triple in two years as caseload grows

Menopause-related claims have more than tripled over the past two years. There were 204 tribunal cases referencing menopause in 2024, compared with 64 in 2022.
- Advertisement -

UK workers ‘ready for AI’, but employer support lags behind

British employees are increasingly optimistic about AI in the workplace - but their employers are not keeping up with the hype.

Fiona McCoy, chief people officer at Lowe Rental

Lowe Rental’s chief people officer shares her routine, career journey and insights into HR’s evolving role in a fast-growing global business.

Must read

Nicola Deas: Three scenarios where honesty is the best policy in the workplace

There are many sensitive issues in the workplace that...

Beyond the Buzzword: Defining and attracting top graduate talent

What are the best ways for HR to attract graduate talent that is both diverse and representative?
- Advertisement -

You might also likeRELATED
Recommended to you