JD Group confirms data breach

its never nice, but again with the fragmented nature of IT that talented people are working for 15 different contractors, that none of them know whats really going on
AND the limited budgets they have to work with,

and the scarcity of skills

what exactly can people do? not much if you ask me.
you do the best you can with what you have.
This is why advocating for proper training from the janitor to the CEO is important. Data can leak from the strangest places.
 
its never nice, but again with the fragmented nature of IT that talented people are working for 15 different contractors, that none of them know whats really going on
AND the limited budgets they have to work with,

and the scarcity of skills

what exactly can people do? not much if you ask me.
you do the best you can with what you have.
Jip, Im starting to back down as well, limited budgets and people not having the expertise is not my problem.

One person can't stand in for everything.
 
Jip, Im starting to back down as well, limited budgets and people not having the expertise is not my problem.

One person can't stand in for everything.
same ,you can only have empathy up till a point, then it just becomes negligence,
why was X not properly prevented from copying the customer database on a flash drive, why was least security not employed?

oh, because he is doing 10 peoples jobs, well, whose fault is that? the Fat Idiot U v Driving CEO?
no the lowest Keyboard Monkey we can blame.

pathetic really, how IT becomes everybody's priority when breaches like this happen.
 
Then why did you jump on the Fortigate bashing tangent?
Then why did you jump on the Fortigate defending tangent? The vendor of the firewall is immaterial to the theoretical discussion of the problem, but the technology failsafes take precedence over using humans as a mitigation.
The underlying problems is that vendors blame humans as a diversion tactic to cover up their own problems.
In aviation it is probable that a pilot has erred but in many reviews the pilot has been incorrectly and disproportionately blamed for inadequacies of the aircraft manufacturers. In my opinion, in cybersecurity the same problem exists. Until that is addressed the well is poisoned.
I would concede that, go ahead and train the humans if there is acknowledgement that it is a short term mitigation to fix a technology failure. Just be open and transparent to the humans about it and don't treat them like poephols.
 
If that is the case then JD Group can save huge bucks by replacing their Fortigates with Mikrotiks. No need to blow all your money on a 5% firewall condom like Fortinet. :ROFL: Why spent 100% of your budget on 5% of the mitigation? I must use that in my next conversation with firewall admins...
My opinion is that this reasoning is flawed. In most cases admin configure DNS to the local ISP instead of Quad9. The local ISP when lead you to command and control faster than what you can say a Russian and slaptjips. They also probably have hundreds of stale rules and no documentation. Because not documenting what things do is a way to make you more safe so not only do the bad players not know what you doing but also yourself. Irrational, IMO. Then of course they are also using advanced traffic analytics because hacks usually occur with persistence. Weeks before the hack you'll see the Chinese receive the data.
Then of course they are most likely have the 5% condom configured using network attributes instead of identity. Even though they bought the identity license and everything else including the kitchen sink and SD-WAN.
And then the firewall is so good that you don't need micro segmentation and you can get to all your internal IoT devices including cameras and access control directly on the internal network which is just one zone. Because your only need three zones: internal, external and DMZ. The latter is best left empty according to best practice.
Cloud services are indeed not protected by a network firewall from a commercial vendor because they don't want to be hacked. They use Linux's netfilter. Most commercial firewalls are 10 year old forks of Linux or BSD and somehow we are meant to believe they can program the kernel better than the experts. Ja nee well fine.
Most companies with Fortigates push their websites through Cloudflare because inherently they know the their expensive tin sucks. Cloudflare is just Linux netfilter with a web UI that aggregates and orchestrates some sophisticated techniques. Here is a thought, maybe just use the cloud technology at the edge as well???

My point is that there are well over 50 types of IT/cyber security controls which do not fall into the realm of network firewalls. A network firewall or Cloudflare for that matter only protects a small portion of the average SME because the network edge no longer resides on-premise or behind cloud hosted IaaS services.

Things like:
  • Account management (IAM)
  • Anti phishing/spam controls
  • Do you have a backup solution which is resilient against ransomware attacks
  • Do you have a robust asset management to detect rogue devices (even remote ones connecting to say a Onedrive or Sharepoint online account)
  • Do you protect your remote endpoints with AV, EDR, MDM, cloud proxy solutions
  • Secure software development
  • Vulnerability management (this includes cloud misconfigurations like someone accidentally allowing public read access to a cloud storage account - CSPM)
  • Third party risk management
The list goes on and on and a Fortigate firewall is not going to cater for the majority of the items I just mentioned.
If C-level think that installing a firewall (or Cloudflare) is their one ticket solution to cyber security risks then they are in for a rude awakening.
 
My point is that there are well over 50 types of IT/cyber security controls which do not fall into the realm of network firewalls. A network firewall or Cloudflare for that matter only protects a small portion of the average SME because the network edge no longer resides on-premise or behind cloud hosted IaaS services.

Things like:
  • Account management (IAM)
  • Anti phishing/spam controls
  • Do you have a backup solution which is resilient against ransomware attacks
  • Do you have a robust asset management to detect rogue devices (even remote ones connecting to say a Onedrive or Sharepoint online account)
  • Do you protect your remote endpoints with AV, EDR, MDM, cloud proxy solutions
  • Secure software development
  • Vulnerability management (this includes cloud misconfigurations like someone accidentally allowing public read access to a cloud storage account
The list goes on and on and a Fortigate firewall is not going to cater for the majority of the items I just mentioned.
None of which would necessarily defeat any number of scenarios which could have lead to this particular leak/breach.
 
Que?! What's wrong with that sentence?

Read it slowly, if that does not help, ask an English enabled friend, that might enable you to understand.

Edit: Before some other humourless idiot shits himself, I was joking with you with both posts.
 
Last edited:
Now hackers are gonna know what sort of nonsense people are buying at Everyshop etc.
 
My point is that there are well over 50 types of IT/cyber security controls which do not fall into the realm of network firewalls. A network firewall or Cloudflare for that matter only protects a small portion of the average SME because the network edge no longer resides on-premise or behind cloud hosted IaaS services.

Things like:
  • Account management (IAM)
  • Anti phishing/spam controls
  • Do you have a backup solution which is resilient against ransomware attacks
  • Do you have a robust asset management to detect rogue devices (even remote ones connecting to say a Onedrive or Sharepoint online account)
  • Do you protect your remote endpoints with AV, EDR, MDM, cloud proxy solutions
  • Secure software development
  • Vulnerability management (this includes cloud misconfigurations like someone accidentally allowing public read access to a cloud storage account - CSPM)
  • Third party risk management
The list goes on and on and a Fortigate firewall is not going to cater for the majority of the items I just mentioned.
If C-level think that installing a firewall (or Cloudflare) is their one ticket solution to cyber security risks then they are in for a rude awakening.
I'm not trying defend the 5% condom but if it has a pin prick in it someone is going to get pregnant.
 
I just saw that my info was included in the file, just my email and ID number which isn't a lot but still a cause for concern for me who gets paranoid a lot
 
I just saw that my info was included in the file, just my email and ID number which isn't a lot but still a cause for concern for me who gets paranoid a lot

A toothless regulator is the problem. In the rest of the world you’d get some form of compensation such as free credit monitoring etc.
 
Top
Sign up to the MyBroadband newsletter
X