itSMF Bulletin itSMF Bulletin September 2018 | Page 5

numbers, millions of individual and smaller businesses were also compromised and are not being reported.

The increased frequency and sophistication of cyber-attacks means that it’s no longer a case of if you will suffer a cyber-attack, but when?! Let me give you some examples of how your information could easily be compromised.

It all starts with a click

No doubt you’ve heard of GDPR (General Data Protection Regulation)? The GDPR sets out a number of requirements for anyone who controls personal data (website owner) to lawfully process that data. You would have noticed that if you currently visit websites, it says “Hey we use cookies. Are you ok with this?” Once you click “ok” and use their site, you now feel safe with nothing to worry about. Hang on! Why is it so important you are forced to click “ok”, to use their site?

When you click “ok”, you are giving them the right to collect a treasure-trove of data all about you!

Making money in big business is all about organisational value which resides in “data plus people”. The more data they collect, the more money they can make. Most pages you visit will have scripts running on them to collect data. For example, if you were reading the news on news.com.au the front page has 18 “trackers” that collect various pieces of information.

What this means is the website owner will collect whatever they can about you and "share it" with third parties. They receive money from “sharing” the data and will continue to do so until they can no longer

make money from it. Keep in mind this is only one of 18 trackers on just one webpage! It’s almost impossible to know how much information these companies are collecting from you, and how far your information can be trafficked. Information trafficking makes you a product.

The most I’ve encountered is a massive 79 trackers on one page. The most common defence I hear from uninformed people when I tell people about these trackers is, “I’ve got nothing to hide, so I have nothing to fear”.

As Edward Snowden said, “Saying you don’t care about the right to privacy because you have nothing to hide, is no different to saying you don’t care about the freedom of speech because you have nothing to say! This is a deeply antisocial principal, because rights are collective, not just individual, and what may not have value to you today, may have value to an entire population or way of life in the future! And if you don’t stand up for your privacy, who will?”

This paragraph is a powerful statement, and if you don’t get it, you will almost certainly be compromised.

You don’t need to get off the internet right now, or become a cyber security expert to navigate today’s internet. All that is required is some common sense, a good framework to follow (RESILIA processes) and some readily available tools, to ensure the processes you implement will protect you.

5