|
7 members (DaveW, +8Rich, GrumpyPa, Ritchie B, Gordon D, Themorganeer, Stevo666),
245
guests, and
75
robots. |
|
Key:
Admin,
Global Mod,
Mod
|
|
Wales
by Joske Vermeule, September 1
|
|
|
|
|
|
|
|
|
|
|
Forums39
Topics49,861
Posts837,529
Members9,596
| |
Most Online1,063 Jun 14th, 2026
|
|
|
|
Joined: Jul 2007
Posts: 27,813 Likes: 749
Member of the Inner Circle
|
Member of the Inner Circle
Joined: Jul 2007
Posts: 27,813 Likes: 749 |
I own a BEV and two ICE cars. Harry stated the issues clearly for and against. As always he makes sense.
JohnV6 2022 CX Plus Four 2025 Renault Scenic Alpine etech "Yvette"
|
|
|
|
|
Joined: Apr 2008
Posts: 12,257 Likes: 317
Scruffy Oik Member of the Inner Circle
|
Scruffy Oik Member of the Inner Circle
Joined: Apr 2008
Posts: 12,257 Likes: 317 |
Yes, same here, a BEV and two ICE. Harry is always worth taking notice of.
Worth noting that JLR and now Stellantis seem to be getting themselves into deep water through poor IT security practices too. I would hesitate to suggest that the source of the cyber attacks is coming from their competitors, but they surely must be regretting outsourcing core IT functions to companies over which they have no control.
Tim H. 1986 4/4 VVTi Sport, 2002 LR Defender, 2022 Mini Cooper SE
|
|
|
|
|
Joined: May 2014
Posts: 5,442 Likes: 133
Black Rat Charter Member
|
Black Rat Charter Member
Joined: May 2014
Posts: 5,442 Likes: 133 |
Yes, same here, a BEV and two ICE. Harry is always worth taking notice of.
Worth noting that JLR and now Stellantis seem to be getting themselves into deep water through poor IT security practices too. I would hesitate to suggest that the source of the cyber attacks is coming from their competitors, but they surely must be regretting outsourcing core IT functions to companies over which they have no control. Not necessarily, last week an 18 year old was arrested on suspicion of cyber attacks was found to have $200 million in bitcoin type accounts. He was arrested while on bail for similar offences.
Keith 2013 narrow bodied + 4 Ruby.
|
|
|
|
|
Joined: Apr 2008
Posts: 12,257 Likes: 317
Scruffy Oik Member of the Inner Circle
|
Scruffy Oik Member of the Inner Circle
Joined: Apr 2008
Posts: 12,257 Likes: 317 |
Not necessarily, last week an 18 year old was arrested on suspicion of cyber attacks was found to have $200 million in bitcoin type accounts. He was arrested while on bail for similar offences. Either way, it doesn't excuse the companies (also M&S, Co-op, and many more) for not enforcing decent cyber security measures, if anything it makes it worse. There might possibly be a defence to say nobody could withstand a co-ordinated attack from highly skilled state-sponsored bad actors, but if you can't even keep your systems secure from a kid with a laptop? Extremely concerning. And if JLR can't keep their systems secure, what does that say about the security of the software that ends up in the cars? Most of these type of breaches seem to originate from basic social engineering, Phone calls purporting to be from 'Steve in the back office' or emails containing an executable disguised as a spreadsheet. These kinds of attacks frequently get in by targeting poorly trained and paid staff who aren't motivated to look out for the interests of their employer or their clients. I did some work with a Swiss company back in the early naughties, even back then their cyber security team was dealing with attacks and probes measured in the thousands per month. Fortunately their guys were highly skilled and highly paid in-house professionals committed to keep their systems secure. God knows how bad it must be for a company who have outsourced support and are depending on the honesty and integrity of someone in a far-away land being paid peanuts and highly vulnerable to bribery or coercion.
Tim H. 1986 4/4 VVTi Sport, 2002 LR Defender, 2022 Mini Cooper SE
|
|
|
|
|
Joined: Aug 2020
Posts: 3,851 Likes: 400
Talk Morgan Addict
|
Talk Morgan Addict
Joined: Aug 2020
Posts: 3,851 Likes: 400 |
Doesn't really matter whether you are in-house or outsourced IT, a well placed rogue employee can equally screw you from within. I know I used to work in the DWP IT development agency, and it was very hard to control absolutely every thing, especially as they allow greater public access to their systems. It was staggering for a highly vetted workforce. the number of times staff tried to access prohibited personal data and set off the alarm bells . .Issues are created by allowing staff to access their personal IT equipment or emails sent in from outside that carry viruses etc, despite all the fire walls and agreed procedures and practices in place. We had one instance of an internally generated virus hidden in header of a senior managers email which ensured wider circulation, that caused a few problems.
No firewall can keep everything at bay, and criminal gangs will recruit staff to do their dirty work from within.
22 Plus Four KIMI 12 Plus 4 Sport OZZY 08 Roadster FELIX 06 4/4 70th LOKI 77 4/4 SEAMUS 85 4/4 MOLLY
|
|
1 member likes this:
+8Rich |
|
|
|
|
Joined: Dec 2009
Posts: 37,418 Likes: 978
Tricky Dicky Member of the Inner Circle
|
Tricky Dicky Member of the Inner Circle
Joined: Dec 2009
Posts: 37,418 Likes: 978 |
MI6 recruiting from the dark web is a stroke governmental brilliance 🥷😠when they already have a ready trained sleeper/dismantler in Farage to hand imploding the country as we watch.
The most migrant crossings in living history 32,000 so far this year don’t Kare tool boy is assisting him admirably from within 😎
Oh yes forgot he has sent three back though.
2009 4/4 Sport Henrietta 1999 Indigo Blue +8 2009 4/4 Sport Green prev 1993 Con Green +8 prev
|
|
|
|
|
Joined: Apr 2008
Posts: 12,257 Likes: 317
Scruffy Oik Member of the Inner Circle
|
Scruffy Oik Member of the Inner Circle
Joined: Apr 2008
Posts: 12,257 Likes: 317 |
Doesn't really matter whether you are in-house or outsourced IT I would have thought it's a lot more secure to vet, recruit, train, compensate and motivate your own staff rather than those of another company.
Tim H. 1986 4/4 VVTi Sport, 2002 LR Defender, 2022 Mini Cooper SE
|
|
|
|
|
Joined: Aug 2010
Posts: 5,465 Likes: 171
Charter Member
|
Charter Member
Joined: Aug 2010
Posts: 5,465 Likes: 171 |
Doesn't really matter whether you are in-house or outsourced IT I would have thought it's a lot more secure to vet, recruit, train, compensate and motivate your own staff rather than those of another company. Intuitively, I would agree Tim. However, the in house team can become complacent. And they will always promote solutions that make their own jobs more secure. That isn’t necessarily the best for their employer. I am involved with a charity which saved a fortune by outsourcing IT services and their systems are already far more secure. The in-house team did not even know about Cyber Essentials and were reluctant to undergo the training. There is a growing industry of professional IT firms (MSP’s - Managed Service Providers) who are really on top of this stuff and are providing great service to their SME clients.
Paul Costock, UK Plus Four 75th - Furka Rouge - Pip Disco 5 Teddy - 17h1 Irish Draught cross
|
|
|
|
|
Joined: Mar 2009
Posts: 11,529 Likes: 312
Smile, it confuses them Member of the Inner Circle
|
Smile, it confuses them Member of the Inner Circle
Joined: Mar 2009
Posts: 11,529 Likes: 312 |
We saw pro's and con's of both approaches.
Larger teams for outsourcing companies can afford to have dedicated "same day risk" experts who can react to recently found gaps in code. This can be shared across multiple customers. Smaller built-in teams may not have bandwidth.
As the alternative approach if you built it and you own it then hopefully your personal pride means you stay alert, but that does become motivationally (and budget) bound. Motivation nerds is a fun discussion as the character types involved can be quite "variable". For me it remains a staff, training and testing discussion with external validation. I have watched both and always found the "how does that work with respect to...." question highlighted a team still keen to improve. Best sign we could find.
The other issue was "do we renew with the same company every year". Same company, same people, same actions, same results. We advised changing suppliers or getting a different one to at least try and break into things at regular intervals.
The biggest risk that scares me now is hiring and total lack of depth in references and proof being performed. When you hire do you really bother to take solid references? Almost any member of staff, not just IT admins, can introduce a USB drive with a trojan virus which digs outbound to it's evil home. This tunnel allows anyone to walk back in and trigger a melt down. An agent of doom just applies for a job in the business and it's all over.
Everyone loves a Morgan. Even me, unless it's broken again.
|
|
|
|
|
Joined: Aug 2020
Posts: 3,851 Likes: 400
Talk Morgan Addict
|
Talk Morgan Addict
Joined: Aug 2020
Posts: 3,851 Likes: 400 |
Its not just permanent staff vetting, most organisations run lean ships, so when you have a new software installations or major development piece of work especially as the technology platforms change, you can finish up having to bring specialist consultants or contractors in giving them access to your systems.
The worst situation I remember was Y2K when the DWP had over 1500 man years of reprogramming to undertake, with a staff of 500 IT professionals at a time when Y2K demand in the market place was enormous and with it enhanced salaries attracting established staff away, having to be back filled with temporary contractors and a fraught time that created.We were having to send admin staff on intensive programming training course to try and create spare capacity and plug holes.
I remember being in the DWP Y2K control centre with links across the globe with other government agencies, starting with New Zealand as their clock tripped over first.to see what issues arose in their systems. Needless to say it all became a damp squid as the new millennium rolled across the globe............
The DWP systems had to have much higher resilience than the norm in industry. As clearly the risks of civil unrest and rioting on the streets if the benefit payments systems went down was just too great.. No one would miss the Inland Revenue or VAT systems going down too much but not paying out benefits was a whole different ball game.
22 Plus Four KIMI 12 Plus 4 Sport OZZY 08 Roadster FELIX 06 4/4 70th LOKI 77 4/4 SEAMUS 85 4/4 MOLLY
|
|
|
|
|