New 2020 cyber trends report now out!

The new Recent Cyber Events and Possible Implications for Armed Forces report gives high-level analysis on major 2020 cyber trends - direct link to report here: https://t.co/QRAhG3TXIw
Section 1: Overview of Solarwinds and the extended campaign that resulted in the breach of several US government agencies. A discussion on supply chain security management and how vulnerabilities compounded to make the attack possible (and un-detected).
Section 2: A development of cyber norms and international law. The pandemic, state pronouncements and UN-sponsored processes on international law and cyber, space recognised as a domain & the plans for Tallinn 3.0. See CCDCOE's Cyber Law Toolkit for more: https://t.co/5T4ry5wAK4
Section 3: 5G and supply chain infrastructure - the importance of secure communications with implications for both civilian and military use. Noting the use of legislation and market competitors, the @CCDCOE announced a major research project into 5G rollouts in 2021.
Section 4: The Future of AI and Security. AI-enabled is still relatively immature - but has vast potential capabilities. Fake news and applications in cybersecurity are both pressing areas of focus, as are long-term focuses on interoperability and international collaboration.
Big thanks to our CCDCOE Intern @marguer_ite for her excellent contributions on this topic!
Section 5: Ransomware in 2020. COVID-19 themed email campaigns and an attacker focus on healthcare providers. The @CCDCOE will be releasing the 'Cyber Investigator's Handbook' in 2021 - a guide providing the cyber community with guidelines on managing and handling an incident.
Section 6: Attacks on Critical Infrastructure. The pandemic represents 'perfect storm' for CI attacks- remote management of systems, decentralised workforces, expanded outsourcing and outdated software. Vaccine distribution infrastructure a priority moving forward.
Section 7: Digitalisation and the 'Digital Workspace'. NATO and affiliated Agencies have all had to manage the shift to remote working - raising interesting challenges around interoperability and secure platforms to share information. Trial and error helped the CCDCOE adapt.
That's all folks. For a deeper dive into the content - the full report once again: https://t.co/QRAhG3TXIw. The authors are open to feedback and suggestions - contact details at end of the report.

More from Tech

Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.

You May Also Like

My top 10 tweets of the year

A thread 👇

https://t.co/xj4js6shhy


https://t.co/b81zoW6u1d


https://t.co/1147it02zs


https://t.co/A7XCU5fC2m