
Cyber Month is coming to an end, hasn't it absolutely flown by! During this 10th anniversary of cyber month, a plethora of activities have taken place across Europe including conferences, trainings, workshops, webinars, and presentations to promote digital security and cyber hygiene.
The observant reader may now be thinking but 'what about the two central themes that the European Union Agency for Cybersecurity (ENISA) had chosen? Thijs still hasn't actually mentioned them?!'. Until now.
Of course, we're going to explore phishing and ransomware! The fact that these topics are now recurring themes for the month isn't really a surprise as they're both increasingly common, and we're certainly hearing more about them in the news and their consequences. Whilst phishing and ransomware might seem like two different ideas, they're actually linked to each other more than you realise. For instance, a phishing campaign - where someone is hoping you'll take the bait in exchange for your personal data - might trick an employee in an organisation into opening a file and unknowingly opening a door for a hacker, who could then make their next move by blocking certain files and only granting access back to the organisation in return for a large sum of money, AKA a ransom. That said, it doesn't necessarily mean that when phishing is involved, a ransomware attack will also happen - the two aren't mutually exclusive.
Phishing is everywhere, with new campaign styles and themes developing all the time - think about when most of the world was in lockdown and phishers decided to benefit from that. Anyway, I thought it might be worthwhile to give you some pointers on how to recognise most phishing campaigns. If you fancy talking it through in a bit more detail, feel free to give me a call .
Something quick and easy that you can do at first glance: check language use and spelling - is the company name correct? Has the sender attempted to disguise similar looking letters to deceive you (such as nn' for m' or capital Is in place of lower-case Ls?). Regarding language use bear in mind that phishing attempts aren't always constructed logically, with sentence structure occasionally being a bit off. This might imply that the sender has used an online translation for a website which was of limited quality.
Yet another aspect to consider is the URL the criminal wants you to click on. More times than not, the sender's domain won't match the link in the e-mail - so keep a close eye on this!
Consistently within phishing attempts is a sense of urgency; a request that must be actioned within a certain timeframe or face a consequence such as a fine, bad rating, etc. Simply ignore such requests and report the e-mail (as per your organisation's policy) to the responsible team who can then determine whether it is indeed a phishing e-mail and what you need to do, if anything.
Maybe you've already clicked on something in a lapse of concentration that you now think could have adverse consequences? Maybe? Don't be afraid to inform the responsible team, immediately! The sooner the team is informed, the sooner they can take (technical) measures and will be eternally grateful to you and learn from this for the future.
Possibly, this phishing incident could have turned into ransomware. If so, speed (and time!) is of the essence. The faster systems can be (controlled) shut down, the less recovery work will be required.
Besides quick reporting, what else can you do to prevent these kinds of incidents? Well, it may seem obvious, but often employees still use unfamiliar USB devices because it's just a bit more convenient' - FYI, it's not. How do you know that someone hasn't tampered with your USB when you weren't looking? You could plug that into your machine and it be taken over by ransomware or malware that begins ravaging your network. Instead of using USBs for sending or receiving files, use file exchange software provided by your organisation. If your organisation hasn't made these tools available yet, ask for them!
Criminals also simply exploit (known) vulnerabilities in applications, operating systems, and the like. Make sure you keep on top of your updates for these applications, therefore reducing the chance of an attack by criminals. Easy, right?
As a side note, you may remember that I pointed out in a previous blog post that, as an ICT/security team, you cannot entirely rely on colleagues who may or may not (accidentally) click on a link or open a file - you need to deal more in absolutes.
It's important to know and be able to recognise the different types of incidents, events, or scenarios, before they even happen. So go through all the different types, list the corresponding technical measures needed to resolve them, and use this for the basis of your incident response plan.
Think about a good backup and restore strategy (also tested and approved, of course), and make this part of the incident plan too. It's absolutely, and I can't stress this enough, imperative that you go through your incident response plan at least once, so you know whether it works. Let's be honest, we all like surprises from time to time, but not in cyber. Then you avoid surprises as much as possible.
Finally, some thoughts that I'd like to leave you with about preventing incidents:
No single organisation is the oracle. Procedures and measures are often ignored in large-scale cybersecurity incidents because of the stress they cause - don't be reluctant to seek external expertise (as the old saying goes, a problem shared is a problem halved). Make this part of the incident plan as well.
Be as clear, straightforward, and transparent as possible in communicating to your stak
Most recent headlines
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
11/05/2025
Berklee Honors Andr 3000 and Sara Bareilles at 2025 Commencement This years honorary doctorate recipients were recognized for their profound influence as art...
10/05/2025
The National Film and Video Foundation (NFVF), an agency of the Department of Sp...
10/05/2025
NEW YORK During the IAB NewFronts 2025, Samsung Ads announced the debut of STN, the Samsung Television Network, a FAST channel with live content that will be av...
10/05/2025
SEATTLE T-Mobile has announced that it set a new uplink speed record of 550 Mbps in sub-6 GHz spectrum using cutting-edge 5G Advanced tech....
10/05/2025
WASHINGTON Twenty-two U.S. Senators have sent a letter to Federal Communications Commission chair Brendan Carr urging him to modernize ownership caps that are...
10/05/2025
Meet Graduates from Berklees Class of 2025 Members of this years graduating class reflect on their proudest moments at Berklee and look ahead to whats next.
...
09/05/2025
At the Frontline Club in London, a venue long associated with media freedom and ...
09/05/2025
As excitement builds for the annual Eurovision Song Contest, Spotify data offers...
09/05/2025
The National Film and Video Foundation (NFVF), an agency of the Department of Sp...
09/05/2025
In our latest blog, Laura Rognoni dives into the shifting currents of change in the digital entertainment landscape, revealing the trends that will keep viewers...
09/05/2025
LOS GATOS, Calif. Netflix has announced that starting May 19 it will begin rolling out a major upgrade to its user interface and the TV experience it offers str...
09/05/2025
The Walt Disney Co. CEO Bob Iger told analysts the direct-to-consumer ESPN app often referred to as ESPN Flagship will be available to the linear channel'...
09/05/2025
Berklee Online Signs Transfer Articulation with Conservatorio Nacional de M sica The new agreement allows CNM students in the Dominican Republic to transfer i...
09/05/2025
Wooden Camera, a leading innovator in camera accessories, is proud to announce the launch of a new line of products for the Blackmagic URSA Cine Cameras. These ...
09/05/2025
LYNX Technik, provider of modular signal processing solutions is expanding its popular Series 5000 platform with three new 12G-SDI cards. The new cards provide ...
09/05/2025
Pebble, the leading automation, content management and integrated channel specialist, has completed a project to migrate ON TV, the major independent broadcaste...
09/05/2025
NUGEN Audio launches its new speech intelligibility plug-in, DialogCheck. A mono, stereo and multichannel dialog clarity meter, the software provides an objecti...
09/05/2025
Disguise the technology platform and solutions provider that powered MDL Beast Soundstorm 2024, Dubai Expo's Al Wasl Dome and visual displays at the Burj ...
09/05/2025
CVP has announced it will demonstrate its cutting-edge broadcast, live production and studio solutions at MPTS 2025. Taking place at Olympia London from 14th - ...
09/05/2025
Mediagenix, a global leader in smart content solutions to profitably connect the right content to the right audience, and White Peaks Solutions, the prominent e...
09/05/2025
SportsEngine Play, the first-of-its-kind streaming service for youth sports, has agreed to a multi-year extension with AI-automated sports content leader, Pixel...
09/05/2025
Friend MTS, a leading global provider of content protection services, today announced that TOD, the premier sports and entertainment OTT subscription service fo...
09/05/2025
ZEISS announces that it is in development on a new virtual lens technology that will allow visual effects and compositing artists to apply an authentic lens loo...
09/05/2025
At the 2025 Media Production & Technology Show (MPTS), Cerberus Tech will showcase the latest major enhancement to its Livelink IP video delivery platform the...
09/05/2025
Capitol Broadcasting Company welcomed Warren Thomas as the new Vice President an...
09/05/2025
CAMBRIDGE, Mass. Studio Technologies said the Harvard University athletics department has integrated Dante-enabled equipment from the vendor into its broadcast ...
09/05/2025
NEW YORK ITN, a provider of a local linear supply side platform, and Magnite, a independent sell-side advertising company, have announced that they working toge...
09/05/2025
LEEDS, U.K. Nugen Audio has launched a new speech intelligibility plug-in, DialogCheck and offered up quotes from technologists working at places like Netflix p...
09/05/2025
AJA I/O Gear: The Heart of Broadcast Solutions' VEGO Mobile Editing Solution
Brie Clayton May 8, 2025
0 Comments
When working remotely on broadcas...
09/05/2025
What do they teach in an Advanced Adobe After Effects Course?
Roland Kahlenberg May 8, 2025
0 Comments
There aren't many advanced After Effects co...
09/05/2025
Larry Jordan Sits with Trevor Morgan of OpenDrives at NAB 2025
Brie Clayton May 8, 2025
0 Comments
Trevor Morgan, COO of OpenDrives, shares how the co...
09/05/2025
Berklee Popular Music Institute Announces UK Festival Debut and Tour Dates For the first time, BPMI will bring Berklee-affiliated artists and students to the ...
09/05/2025
MLB Sunday Leadoff' 2025: MLB Local Media Pulls the Production, Operational ...
09/05/2025
LTN, Pro Volleyball Federation To Wrap Second Season With Championship Weekend PVF's broadcast coverage has risen 350% from its debut season By Mark J Burn...
09/05/2025
Evertz's Ray Kasprzyk on Meeting the Unique Technological Needs of Massive L...
09/05/2025
With Real Madrid-FC Barcelona, ESPN Preps for Most Ambitious LaLiga Match Covera...
09/05/2025
Friday 9 May 2025
Download images HERE
Episodes are available on Sky Media Vil...
09/05/2025
Back to All News
SO JI-SUB Returns With Cold and Intense Noir Action Series Me...
09/05/2025
Back to All News
Netflix Announces Our First-Ever Nordic Medical Drama Starring...
09/05/2025
New beta programme for Avid Pro Tools users provides versioned backup/archive
M...
09/05/2025
Further to the comments from RT Director-General, Kevin Bakhurst on Wednesday 7th May included below in which he asked the EBU for a discusion on Israel...
09/05/2025
Here is your host, Patrick Kielty!
In the season finale of The Late Late Show, ...
09/05/2025
My Eurovision Party 2025 - join in on the fun with RT Kids!
Eurovision launche...
08/05/2025
A sinister fairy infiltrates a desperate family in Kenneth Dagatan's In My Mother's Skin, which premiered at the 2023 Sundance Film Festival. Photo co...
08/05/2025
As expected, continued weak demand from key sales markets and declining economic...
08/05/2025
A new three-part series is coming to BBC iPlayer and BBC One
(Image: The Christie Archive Trust)
The BBC has announced Agatha Christie's Endless Night, a...
08/05/2025
For skyward-bound operators, training focuses on the unique aspects of flying ISR missions, including the management of onboard surveillance equipment and the e...
08/05/2025
The cable industry has told the Federal Communications Commission it supports the National Association of Broadcasters' proposal to allow broadcasters to us...
08/05/2025
WASHINGTON The Consumer Technology Association has continued its opposition to mandates requiring that NextGen TV/ATSC 3.0 tuners be included in new TV sets, sa...