Securing Azure Virtual Desktop

The Jisc Cloud team has penned another security-related post that readers may be interested in: https://cloud.jiscinvolve.org/wp/2021/06/23/securing-azure-virtual-desktop/ In this post, Neil Sayer, Jisc’s Azure Solutions Architect, explains some of the ways that you can secure Azure Virtual Desktop deployments (or Windows Virtual Desktop as it used to be called). The post recommends the following points: * […]

Remote access and Zero Trust

For those of you who aren’t also following Jisc’s Cloud Blog, you may not have seen a post from Richard Jackson (Jisc’s Lead Cloud Security Specialist) on Remote access and Zero Trust. The post at https://cloud.jiscinvolve.org/wp/2021/06/16/973/ delves into how organisations should handle remote access securely and contains useful advice that can help mitigate against some […]

Top 10 tips for DNS Resilience

Andy Davis has been virtually touring the country recently providing advice and guidance to Heads of IT groups on DNS resilience, so I’ve asked him to share his top ten tips: (1) Keep your nameservers patched and running on supportable DNS platforms (OS and DNS application). (2) Review your Business Continuity Plans (BCP) – Do […]

Categories
Uncategorized

GEANT webinar on DDoS attacks

Between the 8th and 17th of February 2021 GEANT are running a series of webinars on DDoS attacks, including Introduction to DDoS attacks Details of specific attacks Detecting attacks Mitigating attacks Participation is free of charge to all NRENs and their constituents. The courses are aimed at network and system administrators, as well as security […]

Cyber security awareness month

Have you spent the last few months wondering: How can I create a strong password? What is smishing? How could ransomware impact me? What are the signs of a phishing email? Well this year GÉANT joins the European Cyber Security month, an initiative launched by ENISA, EC DG CONNECT and a variety of partners to […]

Certificate, protocol & cipher management

Online services and remote access platforms have become common place, with more and more sensitive information being made accessible via these tools, it is more important than ever to protect these services from interception, manipulation and impersonation; the primary control in this space is ensuring only services intended for public use are exposed to the […]

GEANT courses on client privacy and security

Later this month GEANT will be running a series of five webinars which are open to all of Jisc’s members. These are particularly relevant to systems and network administrators, but may be of general interest to a wider audience. Web browsers Security & Privacy – secure surfing with less traces: 21/09/2020 Email Security & Privacy […]

A morning in the life of a Cyber Essentials assessor

Grabbing my morning coffee, I log in to the Jisc Cyber Essentials Pervade portal and see I have 3 Cyber Essentials assessments to mark today https://www.jisc.ac.uk/cyber-essentials. That shouldn’t take me too long, if the applicants have been clear and detailed in their responses. I need to have a good understanding of their estate to award […]

Hitting DMARC! Phishing emails can easily spoof University and College domains: DMARC and NCSC Mail Check are here to help

Guest post by Tom S Academia lead – The Mail Check Team NCSC Active Cyber Defence Cyber security is improving in many areas, but the adoption of DMARC anti-spoofing is still too low. NCSC tools and tips gathered from around the community can help as this guest post from Tom S, Academia lead in NCSC’s Active […]

Ransomware in the Education Sector

Throughout 2020 we have seen different types of ransomware utilising various attack methods and operational techniques to infiltrate networks. The types seen include: RYUK, Ouroboros, Cryakl, rEvil, Mapo and Corona-lock. One common initial infection vector has been malware such as TrickBot (commonly seen within a triple threat vector alongside Emotet and RYUK). While infection via […]