August Cyber Security Insights

August Cyber Security Insights

Written by tdrayson

New EU - US data privacy framework

The new framework supersedes Privacy Shield and gives the USA adequacy status as providing an equivalent level of data protection to the GDPR allowing personal data to flow from the EU to participating USA companies.

All the European Court of Justice concerns have been addressed by introducing new binding safeguards including:

  • limiting the access of US intelligence services to EU data to what is necessary and proportionate. Interestingly USA citizens data was already safeguarded in this way.
  • a new Data Protection Review Court to which EU citizens can appeal to redress how US law enforcement and intelligence services have accessed and used EU citizens personal data.
  • USA companies that wish to participate in the framework commit to comply with a detailed set of data privacy principles, such as the GDPR's 7 data privacy principles.

EU individuals will benefit from several redress avenues in case their data is wrongly handled by US companies. This includes free of charge independent dispute resolution mechanisms and an arbitration panel.

What's next?

  • Max Schrems has already announced he will challenge the new framework in the Court of Justice of the EU.
  • This does not apply to the UK as we have left the EU. There is no news of a similar agreement between the UK and the US.

Governance of Artificial Intelligence

The last 10 months has seen a frenzy in the AI world with the release of Chat GPT and other large language models and machine learning technology.

What is AI?

AI is not a single technology but an umbrella which includes:

  • machine learning - the use of data and algorithms to imitate the way that humans learn, gradually improving its accuracy.
  • computer vision - enabling computers to identify and understand objects and people in images and videos.
  • natural language understanding - uses syntactic and semantic analysis of text and speech to determine the meaning of a sentence. NLU also establishes a relevant ontology: a data structure which specifies the relationships between words and phrases.
  • natural language generation - NLG is the process of producing a human language text response based on some data input.
  • robotics - Robotics is a branch of engineering and computer science that involves the conception, design, manufacture and operation of robots. The objective of the robotics field is to create intelligent machines that can assist humans.

The Governance of AI

Any new technology needs regulation and governance frameworks at the national and international level. Even the CEO's of AI technology companies agree that AI needs regulation. The EU AI Act is expected to be in force in 2025 whilst the US and China are even further behind that.

Governance of AI in Companies

Before we use a governance framework for AI we should undertake a risk analysis and understand the risks AI bring to our organisation. There are some well known generic risks:

  • systemic bias results from AI models being fed with biased data preventing the AI model from performing their intended purpose effectively.
  • statistical and computational bias occurs when the sample is not representative of the population These biases are generally found in data sets or the algorithms used for the development of AI applications.
  • human bias results from the systematic errors in human thinking. This bias is often dependent on human nature and tends to differ based on the individual’s or group’s perception of the information received. Examples of human bias include behavioural bias and interpretation bias.

Fortunately, there are already AI governance frameworks we can adopt in our organisation's governance framework such as:

  • US National Institute of Standards and Technology AI Risk Management Framework - praised by IBM, Amazon and Google.
  • ISO 23894 AI - Guidance on Risk Management published February 2023.

At the heart of these is a lifecycle.

  1. Govern - clarify the roles and responsibilities of those involved in the governance of AI
  2. Map - define and document processes for operator and practitioner proficiency with AI. Also to define relevant technical standards and certifications.
  3. Measure - analyses, assesses, monitors and benchmarks AI risk
  4. Manage - risk monitoring and response efforts.

Implementing AI in our organisations can help to automate and help to increase the efficiency and effectiveness of mundane processes giving the human operator and more meaningful role. The effective governance of AI in the organisation will help to assure that the use of AI is fair, transparent, there is accountability, explanations of automated decisions and inclusivity.

Cyber Security

Cyber attacks during 2023 continue to increase with business email compromise (BEC) attacks being a focus. Email continues to be the main communication forum for businesses so it is a ripe attack vector for the threat actors. Microsoft investigated 35 million BEC attempts in the last year, an average of 156k per day.

We are seeing successful BEC attacks that are collateral damage of some of the biggest cyber attacks in the UK this year.

What should I do to protect my email account? Use a password manager to generate a unique secure password and implement 2 factor authorisation on the account.

We also partner with J2 Software who provide a Microsoft 365 monitoring service in conjunction with ThreatLocker. If you would like more details get in touch.

Cyber Security Insurance

We are seeing companies who make a claim against their insurance policy being asked to prove they were compliant with the policy when the attack started.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right