<

!Google ads have two elements of code. This is the 'header' code. There will be another short tag of code that is placed whereever you want the ads to appear. These tags are generated in the Google DFP ad manager. Go to Ad Units = Tags. If you update the code, you need to replace both elements.> <! Prime Home Page Banner (usually shows to right of logo) It's managed in the Extra Theme Options section*> <! 728x90_1_home_hrreview - This can be turned off if needed - it shows at the top of the content, but under the header menu. It's managed in the Extra Theme Options section * > <! 728x90_2_home_hrreview - shows in the main homepage content section. Might be 1st or 2nd ad depending if the one above is turned off. Managed from the home page layout* > <! 728x90_3_home_hrreview - shows in the main homepage content section. Might be 2nd or 3rd ad depending if the one above is turned off. Managed from the home page layout* > <! Footer - 970x250_large_footerboard_hrreview. It's managed in the Extra Theme Options section* > <! MPU1 - It's managed in the Widgets-sidebar section* > <! MPU2 - It's managed in the Widgets-sidebar section* > <! MPU - It's managed in the Widgets-sidebar section3* > <! MPU4 - It's managed in the Widgets-sidebar section* > <! Sidebar_large_1 - It's managed in the Widgets-sidebar section* > <! Sidebar_large_2 - It's managed in the Widgets-sidebar section* > <! Sidebar_large_3 - It's managed in the Widgets-sidebar section* > <! Sidebar_large_4 - It's managed in the Widgets-sidebar section* > <! Sidebar_large_5 are not currently being used - It's managed in the Widgets-sidebar section* > <! Bombora simple version of script - not inlcuding Google Analytics code* >

Lessons for employers following major data breach

-

A recent data breach at several major firms has left tens of thousands of employees’ personal data exposed to hackers, including contact and bank details.

The breach occurred, in basic terms, via a third-party software vulnerability—which can also be referred to as a supply chain attack.

The software produced by Progress Software (MoveIT) had a ‘Zero Day Vulnerability’ (a vulnerability that has no current mitigation or fix available from the vendor) which was exploited by a suspected Russian-speaking malicious threat actor; Clop. They used the vulnerability to deploy ransomware on several organisations including the BBC, British Airways, Aer Lingus, and Boots.

Alastair Brown, Chief Technical Officer at BrightHR, explains how businesses can limit the risk of such breaches occurring within their workplaces:

“Defending against Zero Day threats can be a challenge. Knowledge is usually scarce given the ever-changing nature of hacker attacks, however, that doesn’t mean that they are impossible to defend against.

“Detection technologies are adaptable, self-learning, and consistently able to detect anomalies and odd behaviour within an environment, which can offer protection against Zero Days. Security vendors react extremely quickly to analyse threat information and release detection and mitigation steps to their customers. But in some cases, this could take 24-48 hours. So, businesses need to have some mitigating steps in place too.

“Employers should ensure they have a good knowledge of the Data Protection Act 2018 and what it means when handling personal data. Train employees on all aspects of data handling, how to identify the risk of a breach and ways to prevent data breaches from happening. Have processes in place requiring employees to notify of any possible data breaches so they can be addressed properly.

“Where a breach occurs, you will probably need to notify the data subjects as well as the ICO. This will be dependent upon the extent of risk caused to the data that has been breached.

“All businesses should have a robust and tested business continuity plan/disaster recovery plan in place, along with a proven and validated endpoint protection solution.

“The take-home message from this most recent attack is that whenever outsourcing any function, employers must ensure that the contracted company meets all their legal obligations and can evidence the robust measures they have in place to protect data.

“Carry out due diligence processes as part of the contracting process to ensure that the provider you choose is the best option. Ask to see the processes in practice. Ultimately, each employer is responsible for ensuring data compliance, so you need to be confident that suppliers are not compromising your business and putting your data at risk.”

Amelia Brand is the Editor for HRreview, and host of the HR in Review podcast series. With a Master’s degree in Legal and Political Theory, her particular interests within HR include employment law, DE&I, and wellbeing within the workplace. Prior to working with HRreview, Amelia was Sub-Editor of a magazine, and Editor of the Environmental Justice Project at University College London, writing and overseeing articles into UCL’s weekly newsletter. Her previous academic work has focused on philosophy, politics and law, with a special focus on how artificial intelligence will feature in the future.

Latest news

Turning Workforce Data into Real Insight: A practical session for HR leaders

HR teams are being asked to deliver greater impact with fewer resources. This practical session is designed to help you move beyond instinct and start using workforce data to make faster, smarter decisions that drive real business results.

Bethany Cann of Specsavers

A working day balancing early talent strategy, university partnerships and family life at the international opticians retailer.

Workplace silence leaving staff afraid to raise mistakes

Almost half of UK workers feel unable to raise concerns or mistakes at work, with new research warning that workplace silence is damaging productivity.

Managers’ biggest fears? ‘Confrontation and redundancies’

Survey of UK managers reveals fear of confrontation and redundancies, with many lacking training to handle difficult workplace situations.
- Advertisement -

Mike Bond: Redefining talent – and prioritising the creative mindset

Not too long ago, the most prized CVs boasted MBAs, consulting pedigrees and an impressive record of traditional experience. Now, things are different.

UK loses ground in global remote work rankings

Connectivity gaps across the UK risk weakening the country’s appeal to remote workers and internationally mobile talent.

Must read

Nick Mabey: Key HR challenges in the age of connection

In 1942, in the midst of World War II,...

Tracey Guest: Government proposals could lead to charities facing employment tribunal claims from volunteers

20.1 million people in the UK volunteered between 2017 and 2018.
- Advertisement -

You might also likeRELATED
Recommended to you

Exit mobile version