Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,160,442 members, 7,843,351 topics. Date: Tuesday, 28 May 2024 at 11:39 PM

Arik Air Hacked:3 Key Things African Every Organization Can Learn From This Hack - Crime - Nairaland

Nairaland Forum / Nairaland / General / Crime / Arik Air Hacked:3 Key Things African Every Organization Can Learn From This Hack (410 Views)

Lawan Campaign Organization Appoints Kalu DG, FFK, Others Named In Committee / FAAN Arrests Arik Air Worker For Seeking Bribe From Passenger / Blue Water Boys Hack Accounts With Voters' Card, Drivers' Licence, Debit Alerts (2) (3) (4)

(1) (Reply)

Arik Air Hacked:3 Key Things African Every Organization Can Learn From This Hack by zyonnista(f): 3:16pm On Nov 02, 2018
Source: SheSecureshttps://shesecures.org/arik-air-hack/

Yes, Arik Air was hacked. On Tuesday, the 30th of October 2018, twitter went crazy. What happened: a cyber security expert Justin Payne made a public disclosure that shook a lot of African organizations. No, not just african organizations but industry experts.

It has left a lot of discussions on the minds of people. Some blaming Arik Air for not responding swiftly. Others of the opinion that it was of no risk.

In Africa there’s been quite a number of breaches over recent years. From the breach in South Africa and now a data leak in Nigeria. African Cyber security professionals and experts from various cities can’t stop emphasizing how much African companies ought to start taking vulnerability disclosures seriously and act on them as fast as possible.

But, really. Where does this leave organizations. African or global organizations. What can they learn from this leak? But first, how did Arik get its data leaked.

How did Arik Air Get Hacked?

On the 6th of september, Justin Payne began his scan for vulnerable amazon s3 buckets. Paine, who is the head of trust and safety at Cloudflare, said his attempt to alert the company to the exposed data was not acknowledged until September 24. So on the 30th, Justine went on to disclose his findings on twitter


3 things Organizations Can learn from Arik Air Hack & Data Leak

1. Embrace Responsible Disclosure Culture: Organizations in Africa need to know this; so long as your organization or business is online. You will remain a target to hackers. Your product, your employees, and everything about you is like a hot menu waiting to be tried out in the restaurant. First, organizations need to set up a distinct unit or department that deals with incident response and responsible disclosure. This can be done by creating a platform (website or email) where vulnerabilities can be reported to without the researcher being reported or arrested for breach.

2. Don’t rely on outdated Technologies: Most security breaches occur due to ignored technology (oversight) that’s in use or outdated technologies. For example, Deloitte was reportedly hacked. How did this happen? According to guardian, At the time of the hack, Deloitte did not have multi-factor authentication As a result of this, hackers could get into the system through the administrator’s account. Outside hacking can be malicious and the cost of such attacks is costlier when compared to data breaches through system glitches and human errors.

3. Reduce Delay in Response and Reporting: So, notice a data breach, or someone suggested there might be one. There should be no hesitation and such extraction of personal data by hackers should be addressed immediately without delay before it spreads across the entire customer base or get’s noticed by hackers willing to trade it on the dark web. As cyber-attacks become common, it is important for CEOs or CTOs of organizations to address the issue of cybersecurity diligently and create a protected environment.

What more can be done to keep organizations on their toes.

1. Heavy sanctions from the regulator should be a starting point. This would set up some real sense of responsibility infused into these organizations concerned. If there is a hack, and nothing is done to inform users or mitigate the damage. There should be a sanction for that.

2. There should be a Data Protection (DP) regulation a dedicated DP authority that specifically deals with these organizations.

Read more on what you can do as a user to protect yourself and your data.. https://shesecures.org/arik-air-hack/

(1) (Reply)

Wife Kills Hubby, 3 Children In Benue / Finnish Policewoman Attempts Suicide After Swindled By Nigerian / Twitter User Mocks Wicked Teacher Who Is Now Uber Driver

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 12
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.