This month we look at:
At the start of August there was a plethora of data loss incidents. The Electoral Commission lost 40 million voters information who registered to vote between 2014 and 2022 to a hack. All the other incidents were where organisations posted files to the internet containing personal information:
The one common thread in all of these incidents is that human error was blamed for each incident.
Whilst an unfortunate human being did make a mistake and will forever regret that mistake I argue it was process failure. In each incident, if a review stage was included in the process each incident could have been prevented from occurring. The objective of the review stage would have been to review the file in which the data was included to make sure a data loss incident was not about to occur.
AI is the buzzword of 2023 with the launch of generative AI models like ChatGPT. What are the risks of using such AI models?
AI is another system. At a high level it works as in the below diagram. The person submitting the query to the chatbot can choose the refine the query depending on the output.

In the meantime AI will be advancing rapidly with the probability that any laws will already be struggling to be relevant when they come into force.
Whilst we are all aware of ChatGPT how many of us have heard of FraudGPT and WormGPT. These are AI tools in the threat actors world, the Dark Web.
FraudGPT helps threat actors to perfect phishing emails in any language, even suggesting where to put the malicious link in the email. It could also create fake websites to collect visitors personal information. Other functionality includes creating malicious code, develop "undetectable" malware, find vulnerabilities and identify targets.
WormGPT, like FraudGPT, has no ethical boundaries or limitations. WormGPT writes malicious software. AI cyber security firm SlashNext's researchers got WormGPT to create a business email compromise (BEC) phishing lure to encourage employees to pay a fake invoice. The results were unsettling with WormGPT creating an email that was not only remarkably persuasive but also strategically cunning, showcasing its potential for sophisticated phishing and BEC attacks.
The UK is looking to introduce a new law (Online Safety Bill) and update an existing one (Investigatory Powers Act) which could have global consequences for end to end encryption in messaging apps.
What both laws are attempting to do is to enable law enforcement agencies to combat child sexual abuse, criminal activity and terrorism. The method of doing this is to require big tech to scan all our messages before they are encrypted, i.e. create a back door into the messaging apps, such as WhatsApp, Signal and Apple's FaceTime and Messages apps.
I do not think that anybody disagrees with the sentiment of these laws but the risks are:
What is going to happen? Big tech are taking on the UK Government and saying that they will stop the WhatsApp, Signal, FaceTime and Messages service in the UK.
The laws are also giving the wrong signal for tech investment in the UK with the tech companies saying there is not an innovative culture and environment to warrant investing in the UK.
As I said above I am sure no-one disagrees with the sentiment of both laws but surely we cannot turn the UK into a technology backwater?
