Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - All TalkTalk And No Action
Articles

All TalkTalk And No Action

ISBuzz TeamBy ISBuzz TeamOctober 8, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It seems staggering that a technology provider like TalkTalk should resort to ignorance as it’s line of defence and yet that’s just what the company did when faced with the results of the investigation by the Information Commissioner’s Office.  The company ‘did not know’ the vulnerable web pages subjected to at least three separate SQL attacks existed and was ‘unaware’ that the installed database software had not been patched for three and a half years that it inherited from Tiscali.

What’s interesting is that the fine was levied as the result of an attack – and no doubt that’s the tack TalkTalk was taking when it sought to defend itself as the victim – but the ICO as having none of it, saying the fine should act as “a warning to others that cyber security is not an IT issue, it is a boardroom issue.” This time around, TalkTalk would not be talking itself out of trouble.

What is clear is that the probing and reconnaissance carried out by the SQL attacks launched against TalkTalk in July, September and finally October 2015, can and should have been prevented. There was a clear lack of due diligence at the time of the Tiscali takeover, followed by poor auditing of the information estate, and finally poor security monitoring and patch management as an ongoing activity.

SQL injection is by no means a complex attack and is very common. It essentially sees the attacker execute a malicious payload of SQL statements to the web application’s backend database in a bid to access the data housed there. It’s simple to avoid this type of attack by ensuring web application developers adhere to some simple guidelines as stated by OWASP.

Poor coding aside, there’s also the option of automated network monitoring and detection that should have spotted these attempts and triggered an alarm. But only if that database had been included in the company assets and this illustrates just why this is not an IT issue: what was missing here was a basic failure to properly integrate one company’s assets with those of another and that has to be down to the fundamental way the company was run.

It’s also worth noting that the ICO investigation itself was limited to the failure of TalkTalk to adhere to the Data Protection Act. There’s simply no knowing, therefore, what level of security monitoring was in place nor whether there were other issues regarding the management of the information estate at this stage.

What is clear is that it’s this lack of a holistic approach to security that is proving to be the undoing of many organisations. We have the technology at our disposal to monitor these networks and even perform advanced network monitoring to ensure anomalous actions are logged but without anyone to oversee that, this information becomes useless. Without the human in the machine, cyber security cannot function effectively. There needs to be a cultural change in these organisations that enables the CEO to have visibility of the information estate, security controls and remediation so that security doesn’t get sidelined.

The £400,000 fine is the biggest issued by the ICO to date but it pales into insignificance compared to the other costs to the company. TalkTalk has already shelled out £35million in costs attributed to remediation and loss of revenue and then there’s the costs in terms of reputation to consider. The company’s handling of the incident was less than ideal, with many jittery customers told they were bound to their contracts and by January, that strategy had backfired with the company losing seven percent of its customer base.

For the members of the board, the story doesn’t end there though as the Metropolitan Police are also running a separate criminal investigation. That could well mean there will be further repercussions for the individuals involved.

[su_box title=”About ” style=”noise” box_color=”#336588″][short_info id=’87646′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}