Compass IT Compliance Blog

Insider Threats – Your Employee May Be Your Greatest Risk

Office Employees

In February of 2018, Ashley Liles was working as an IT Security Analyst at an Oxford based company that suffered a ransomware attack. Ashley jumped at the opportunity, not to help the company, but to enrich himself by piggybacking on the initial ransomware attack and attempting to tri …

Read Story

Vishing: Over-the-Phone Scamming

Vishing Phone Call

It's always scam season, so it helps to stay vigilant all year round. Cyberattackers scarcely rest. They are constantly developing novel approaches for stealing confidential information and vast sums of money from businesses worldwide, disrupting operations and causing considerable da …

Read Story

Different Types of Social Engineering Attacks Explained

Social Engineering

What Are Social Engineering Attacks Social engineering attacks are a common method used by cybercriminals to manipulate people into divulging sensitive or confidential information about themselves or taking actions that may cause harm to themselves or their organization. Social engine …

Read Story

Tug-of-War: Balancing Security and Efficiency

Tug of War

I find it helpful when explaining principles to think in extremes. So, when it comes to the principle of securing a system, what is the most secure? Let us use this computer I am typing on as an example. Off. That is the most secure. Let us even take the battery out, unplug everything …

Read Story

Smishing: Text Messages from Scammers

Smishing

Like most people, you have probably received a text message from a phone number that seemed a little “fishy”. The message may have claimed to be from your bank, asking you to verify your account information, or it may have promised you a gift card if you clicked on a provided link.

Read Story

MIME Sniffing: What Is It? What Are the Security Implications?

Mime Sniffing

Multipurpose Internet Mail Extension (MIME) sniffing has been in use for decades to allow a browser to render content when there is some question about what type of data the content contains. However, MIME sniffing can also open your organization and end users up to serious cybersecur …

Read Story

Subscribe by email