As post-quantum cryptography (PQC) becomes integrated into mainstream information technology (IT) products and services, financial services institutions must begin to execute their transition strategies.
This document provides actionable guidelines to incorporate quantum safety into existing risk management frameworks by assessing the ‘Migration Priority’ based on the ‘Quantum Risk’ and ‘Migration Time’ of business use cases and highlighting opportunities for immediate execution. A critical first step is to inventory all business use cases that rely on public key cryptography.
Read more…
Source: Europol
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- British Airways breach caused by the same group that hit Ticketmaster
September 11, 2018
A cyber-criminal operation known as Magecart is believed to have been behind the recent card breach announced last week by British Airways. The operation has been active since 2015 when RisqIQ and ClearSky researchers spotted the malware for the first time. The group’s regular mode of operation involves hacking into online stores and hiding JavaScript code that steals payment card information entered ...
- Forget WannaCry, staff themselves pose a risk to healthcare data
September 3, 2018
More than half of all healthcare data breaches reported during 2017 could be traced back to people on the inside of victim organisations, according to an annual study by Verizon. The company’s latest Protected Health Information Data Breach Report (PHIDBR) looked at 1,368 mostly US examples, identifying 782 (57.5 per cent) as having an insider element. A ...
- Side-Channel Attack Allows Remote Listener to ‘Hear’ On-Screen Images
August 27, 2018
A stealthy side-channel tactic for digital surveillance has been uncovered, which allows an attacker to “hear” on-screen images. According to a team of academic researchers from Columbia University, the University of Michigan, University of Pennsylvania and Tel Aviv University, inaudible acoustic noises emanating from within computer screens can be used to detect the content displayed on ...
- Superdrug hack: Data thieves claim to have information on 20,000 customers
August 22, 2018
Superdrug has been targeted by hackers claiming they had access to tens of thousands of customers’ personal details including dates of birth and phone numbers. The high street chain it had been contacted by someone who claimed that they had obtained the details of approximately 20,000 customers. The company confirmed that 386 of the accounts had been compromised and said ...
- Philips Vulnerability Exposes Sensitive Cardiac Patient Information
August 17, 2018
The unpatched flaw would allow a bad actor to execute information-exfiltrating malware, backdoors, ransomware or any other kind of bad code he or she chose. A vulnerability in the Philips IntelliSpace Cardiovascular (ISCV) line of medical data management products would allow privilege escalation and arbitrary code execution – opening the door for an attacker to siphon ...
- Australia plans law for tech firms to hand over encrypted private data
August 14, 2018
Australia on Tuesday proposed a new law requiring technology firms such as Alphabet Inc’s Google, Facebook and Apple to give police access to private encrypted data linked to suspected illegal activities. The measure, which targets platforms the Australian government says could be used for criminal activities or to plan a terror attack, would require police to ...
