The EU's Digital Operational Resilience Act (DORA) entered into force on 16 January 2025. This comprehensive guide translates DORA's seven core requirements into plain English, gives you a 15-item compliance checklist with owners and deadlines, and answers the 17 most common questions UK and Poland financial firms are asking.
Zero Trust is the dominant security architecture for enterprises. For SMEs, the principles are sound — but the implementation needs to be proportionate, not performative.
Enterprise buyers send ever-longer security questionnaires. For SaaS vendors, the compliance burden is becoming a competitive disadvantage. Here is how to manage it.
Passkeys and biometric login promise to eliminate passwords. For most SMEs, the technology is ready — but the migration path is not as simple as vendors claim.
EU data protection authorities issued over €2 billion in fines in 2024. Meta and Amazon dominated the headlines, but smaller penalties signal where enforcement is heading.
EDR is no longer an enterprise tool. Every SME with sensitive data should consider it. Here is how to choose, deploy, and manage EDR without a dedicated security team.
Cyber insurance premiums rose 15% in 2024. Coverage is narrowing, deductibles are rising, and insurers are demanding evidence of controls. Here is what to expect.
The UK National Cyber Security Centre updated its small business guidance. The 2024 edition reflects a new threat landscape — and a new standard for what counts as basic security.
The UK Information Commissioner issued £15 million in fines in 2024. The pattern is clear: repeat offenders, untested backups, and missing data protection officers.
Several countries are considering laws that ban or restrict ransomware payments. For SMEs, the debate is not academic — it directly affects recovery options and insurance coverage.
A single faulty update took down 8.5 million Windows machines. For SMEs, the lesson is not about CrowdStrike — it is about single points of failure in your own supply chain.
Phishing simulations are a valuable training tool. Done badly, they damage trust, create resentment, and reduce reporting. Here is what the research says about effective simulations.
NIST released CSF 2.0 in February 2024. The biggest change is a new Govern function — and a clear signal that cybersecurity is a board-level responsibility.
Image generated by Bing Copilot Artificial intelligence (AI) tools like ChatGPT are revolutionising communication, creating content, and driving innovation. These tools, built on sophisticated language models, can mimic human conversation, generate text, and translate languages at lightning speed. While the potential benefits are undeniable, the impact on cybersecurity is a double-edged sword. On one hand,
The MOVEit Transfer vulnerability exposed data at hundreds of organisations. The real target was not MOVEit itself — it was the companies that relied on it.
As many businesses moved operations to the cloud or to full-remote positions hackers stepped up their game to exploit this relatively new situation. As a result, businesses in Europe had the largest spending in cybersecurity in 2020 than ever before, an increase of 39%. The Hiscox Cyber Readiness report (PDF) shows some growing trends that
The majority of the UK voted to leave the European Union last week. In addition to all political and economic impact that follows Brexit, there is a question about how Information Security and Data Privacy will be affected. Amid the chaos, there is good news in this field: most likely EU data protection will still apply
The recent news that banks in Bangladesh and Vietnam have been successfully hacked is a concerning fact about the level of IT Security in financial services. SWIFT has warned its 11,000 members worldwide about the recent incidents, which allowed hackers to transfer more than a million Euros from TPBank in Vietnam. It seems the malware
Tim Cook refusal to comply with the US Government demand to weaken its security has created such a turmoil on internet. During the investigation of the San Bernardino terror case, the FBI recovered iPhones from the murderers which are encrypted and its information inaccessible. Therefore now they’re asking to create a new version of iOS which
A few days ago the US Federal Financial Institutions Examination Council issued a warning for banks that they should expect ransomware to grow in the following months. Despite the fact that financial institutions are one of the sectors that invest the most in cybersecurity, it seems ransomware is increasing in numbers. Just in case, you really haven’t
One common misconception in many industries is that “our data is of no interest to hackers”. While it is true that certain data might have no much monetary value, in general, personally identifiable information is a gold mine for hackers and should be protected accordingly. On Friday, the Hong Kong-based telephone and toy maker VTech was
Recently I received my invitation to test Let’s Encrypt, a project to create a free, open, automated Certificate Authority. Although the project itself might not have caught many headlines, this promises to be a game-changer for the industry. Firstly, they already passed the stage of a nice, cool idea and are moving into the real world, they received a cross-signature
High-profile hacking events this years is not only directly costing million of Euros to the affected companies, it is also affecting the rest of us. Reuters recently published an article stating that cyber-insurance premiums are on the rise to the point that some companies are struggling to find the money to buy appropriate coverage. Insurance companies are
In the IT Security circles, DNS has been a hot topic for quite a long time. The fundamental problem is that the entire Internet relies on the DNS, the phonebook of the internet. Back in the early 1980’s when DNS was being created, security was not a priority and it has remained an unauthenticated database
Last week was quite a tough one for TalkTalk in the UK. It seems high-profile hacking is getting commonplace and not many sign of improvement. However, more than dwelling on the staggering fact that 4 million records were stolen, what is becoming more appalling is the management of the incident and the lack of transparency. TalkTalk
Here at Metaluxo we prepared a free booklet with an essential guide to cyber-security in Small and Medium Enterprises. IT Security for Small and Medium Enterprises | Free download (PDF 1.5 MB)
Magento is reporting that a large number of websites using Magento haven’t patched and are still vulnerable to the Shoplift Bug. If you are one of the thousand of business using Magento please be aware of this vulnerability and have your IT personnel patch this immediately. Magento has a quite comprehensive list of best security practices
The US government released a new page about cybersecurity for small businesses as part of October the CyberSecurity Awareness Month. This is in recognition that small businesses in the US are particularly at risk of cyber attacks. Although oriented to American businesses, this can be a useful tool for startups and SMB’s worldwide. This site
The New York Post claimed that a teenager was the responsible person for hacking the personal e-mail of CIA Director John Brennan. If proved to be true this is not only a major embarrassment for the CIA but also another warning call to always be vigilant no matter how many security controls are already in
RASend us a messageGoes straight to Roberto×
Message sentRoberto has it. You will get a reply at the address you gave — within 12 hours if this is a live incident.