• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Giant Umbrella

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #21
    Originally posted by Paralytic View Post

    If you squint enough, a ransomware attack is a technical difficulty (assuming it has locked them out of their systems).

    But, this was pure conjecture on my part, based on absolutely no evidence (although the widespread system outages does fit the model).
    Turns out your conjecture was right.

    https://www.contractoruk.com/news/00...re_attack.html

    Comment


      #22
      Originally posted by Andy Hallett View Post
      I am sure we can read all about it in the ICO report when it is published!
      Why? If you look at Giant's latest statement all data was encrypted so hasn't been stolen.

      From their FAQs.... FAQ's September 2021 (giantpay.co.uk)
      Has any of my data been compromised?

      To give you reassurance, all of your data is held on Pure Storage arrays, which is automatically encrypted.
      merely at clientco for the entertainment

      Comment


        #23
        Has any of my data been compromised?

        To give you reassurance, all of your data is held on Pure Storage arrays, which is automatically encrypted.
        Well if Giant's data centre was ram-raided and they stole all the hard disks this might actually make a difference.

        Unfortunately there is much misunderstanding about data encryption - in the main, the methods used by most firms don't do anything to help protect your data, apart from mark an auditors tick-box.

        Another way of putting it - data has to be unencrypted to be usable. If your website / local network is owned, the data is available to anyone with the relevant access.

        There are exceptions to implementing data encryption correctly - but in 95% of cases its more effort than it is worth.

        Comment


          #24
          Originally posted by eek View Post

          Nope it’s a paperwork audit, to describe it as a financial audit would be an insult to audits.
          I've sent you a mail eek. I am arranging a podcast with Phil Pluck at some point. Can either introduce you directly to his for a chat or send me a list of questions.
          https://uk.linkedin.com/in/andyhallett

          Comment

          Working...
          X