{"id":4768,"date":"2018-09-02T09:52:52","date_gmt":"2018-09-02T08:52:52","guid":{"rendered":"https:\/\/citysecuritymagazine.com\/?p=4768"},"modified":"2018-09-02T19:05:51","modified_gmt":"2018-09-02T18:05:51","slug":"advice-cyber-security","status":"publish","type":"post","link":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/","title":{"rendered":"Cyber security: motive, method, opportunity"},"content":{"rendered":"<h1><strong>Cyber security made simple\u00a0\u00a0\u00a0\u00a0 <\/strong><\/h1>\n<p>Cybercrime, including ransomware, is a growing phenomenon in the developed world where some $80 billion is spent annually countering this multi-trillion dollar threat. However, success can have more to do with awareness than computers and often businesses forget traditional security, including the \u201cMethod, Motive, Opportunity\u201d model.<\/p>\n<p>Expensive, technical security might provide limited protection, given the actual digital threats.<\/p>\n<h6>Understand the Risk<\/h6>\n<p>To allocate budgets, resources and protective measures effectively, cyberthreats should be seen not as alien concepts, but as extensions of threats and risks in the physical world.<\/p>\n<p>First, understand the risk. The risk of attacks, physical or cyber, is defined in ISO 31000 (risk management) and repeated in ISO 27000 series (information assets) as: the Effect of Uncertainty on Objectives. Something unexpected, caused by something we are under-informed about, happening to something we care about: e.g. a hacking attack by overseas criminals on our servers.<\/p>\n<p>Managing such risk means coming to grips with those uncertainties and effects to make our servers safer. The core components are:<\/p>\n<ul>\n<li>Context: for example, the value of the data to our client and the internal processes that protect it.<\/li>\n<li>Identification: for example, theft of intellectual property with consequent loss of revenue.<\/li>\n<li>Analysis: for example, what we know about hostile parties, the damage they could do, how likely such damage is to occur, what our IT controls and human vulnerabilities are, and what resulting levels of risk we face.<\/li>\n<li>Evaluation: what analysis tells us about risk levels (for example, \u2018high\u2019 for hacking because of poor password controls and possible collusion by disaffected insiders) versus our tolerance for risk (for example, \u2018low\u2019 because the client would cancel the contract) and thus how far we need to treat the risk.<\/li>\n<li>Treatment: for example, strengthen password protocols; strengthen vetting and re-vetting regimes; sign-off residual levels of risk.<\/li>\n<\/ul>\n<h6>Apply sound principles<\/h6>\n<p>Despite portrayals of teenagers launching technological attacks on unsuspecting organisations run by behind-the-times adults, some established principles remain valid.<\/p>\n<p>Who has the motive to attack; what methods do they possess; what exploitable opportunities exist?<\/p>\n<p>Analysing attacks in that way underwrites investigatory and preventive techniques, cybercrime included, in many jurisdictions: the Motive x Method x Opportunity approach. To use this formula to reduce risk, we can try to reduce one or more elements as close as possible to zero.<\/p>\n<h6>Motive<\/h6>\n<p>If attackers have enough motive and method, no system is invulnerable. Even if opportunity is almost zero, a combination of motive and method can still be too high for an attack to be withstood. The US-Israeli breach of Iran\u2019s nuclear programme was an example, as the 2016 documentary Zero Hours showed. Insider agents with physical access to Iranian systems were needed to breach their considerable security. Despite low opportunity, the attackers had sophisticated methodology and the overriding motive of preventing Iran developing nuclear weapons.<\/p>\n<p>Few businesses face such extremes, but the principles remain valid: appropriately inexpensive options provide sufficient security to mitigate the threats.<\/p>\n<h6>Method<\/h6>\n<p>Method examines attackers\u2019 tools and their effectiveness, from sophisticated remote hacks (difficult and expensive for the attacker) to spam emails (cheaper but less effective). Cheaper, more effective methods are more likely, so cyber security should respond accordingly.<\/p>\n<p>The company\u2019s risk assessment determines which methods of attack are most likely to succeed, determining the mitigations needed to reduce the method factor acceptably.<\/p>\n<h6>Opportunity<\/h6>\n<p>Insider threats provide opportunity for attackers; GCHQ assesses 75% of attacks are wholly or partly in this category, breaking down roughly as follows:<\/p>\n<ul>\n<li>Employees breaching security for personal gain (malicious insiders);<\/li>\n<li>Employees coerced by bribery or blackmail (vulnerable insiders);<\/li>\n<li>Employees circumventing security to make life easier (WIMPs: Well Intentioned but Misguided People);<\/li>\n<li>Employees unwittingly lured by phishing and other cyber fraud;<\/li>\n<li>Employee and management staff inefficiency, and failure to learn lessons.<\/li>\n<\/ul>\n<p>Insider threats can lead to financial and reputational loss. TalkTalk lost \u00a360 million, 100,000 customers and 20% of share value after a cyber attack in 2015. Staff inattention and failure to comprehend the developing crisis were likely causes of the most impactful consequences.<\/p>\n<p>Different risk profiles exist for each insider type, which need to be approached accordingly. Generic risk profiles are:<\/p>\n<h6>Malicious insider (high motive, high opportunity, low method)<\/h6>\n<p>With some internal grievance, 80% of attackers are already known to management for negative behaviour, and make their highly motivated attacks after admonishment, demotion, or firing (US Government\/Carnegie Mellon report 2005). Opportunity might be high due to insider knowledge, but method might be low, especially if already under preventive control measures.<\/p>\n<p>The best defences are strongly implemented Standard Operating Procedures (SOPs) derived substantially from standard human resources and physical security SOPs.<\/p>\n<h6>Vulnerable insider (moderate motive, high opportunity, high method)<\/h6>\n<p>Bribed or blackmailed, vulnerable insiders tend not to have a history of wrongdoing with the firm, and so are harder to detect. Attackers might exploit gambling or credit debts, a growing problem among young professionals. Method and opportunity are high as the attackers can coerce the insider, whose clean record allows them to act undetected, negating some of the technical security. Motive can be lowered to moderate through employee engagement.<\/p>\n<h6>WIMPS (low motive, moderate opportunity, moderate method)<\/h6>\n<p>By ignoring SOPs, WIMPS create opportunities for attackers. Mitigation is through staff engagement, training and awareness. Identifying how and why SOPs and protocols can be circumvented leads to new policies and procedures to deter attacks.<\/p>\n<h6>Unwitting employees (low motive, high opportunity, moderate method)<\/h6>\n<p>Staff can inadvertently create opportunities for attackers who use scams such as ransomware (computer malware that takes the victim\u2019s data hostage, with demands for money to release it), and various forms of phishing. Two enterprise-level phishing threats are:<\/p>\n<h6>Spear-phishing: directed at individuals and companies to gather information about the target; accounts for most current attacks.<\/h6>\n<p>Clone-phishing: clones an existing legitimate email, replaces its attachment or link with a false version, and re-sends it apparently from the real sender; can spread quickly among duped parties who trust each other. Mitigation is by reducing opportunity and creating a culture of cyber awareness, so staff understand, recognise, and avoid such threats.<\/p>\n<h6>Cyber awareness culture<\/h6>\n<p>Creating awareness is difficult, but can be achieved by training on SOPs and on individual roles in company security; staff who misunderstand the purpose of security can become WIMPs by finding ways to circumvent it. Cyber security is too often based on surveillance, technical complexity, and deliberately keeping information away from staff on a misdirected principle of \u2018need-to-know\u2019. The reverse is usually true:<\/p>\n<ul>\n<li>Empowered employees support security and help identify and eliminate vulnerabilities.<\/li>\n<li>Staff who feel untrusted might see security as directed against them, and find ways to defeat it. Morale, productivity, and staff turnover can be adversely affected.<\/li>\n<li>A better principle is to start with trust, and view staff who cannot be trusted to be part of the company\u2019s security as less valuable employees.<\/li>\n<\/ul>\n<h6>Four principles help create a strong cyber security culture:<\/h6>\n<p>1 Ensure everyone from CEO downwards understands and adheres to SOPs. When managers ignore rules they alienate staff and create opportunities for attackers; note the rising prevalence of CEO and senior management impersonation in emails and online, so-called \u2018whaling\u2019 attacks (where an email or web page targeting a senior manager can purport to come from a known senior internal or external stakeholder, for example with a false claim for compensation or a false client approach).<\/p>\n<ol start=\"2\">\n<li>Make training interactive, with posters, using game-playing techniques, practical exercises, and entertaining media such as \u2018xkcd\u2019 web-comics.<\/li>\n<li>Training should always contain something new and interesting. Any training needs tailoring to the audience, but the aim is to create cyber situational awareness. This includes basic technical education, explaining unfamiliar terms.<\/li>\n<li>Encourage feedback and track the success of specific outputs.<\/li>\n<\/ol>\n<h6>Cyber situational awareness<\/h6>\n<p>Knowing how cyber attacks work reduces method and opportunity. Technical methods can be explained by linking cyber principles and concepts to physical equivalents. For example:<\/p>\n<ul>\n<li>Not logging-off unattended computers or smartphones is like leaving houses or cars unlocked.<\/li>\n<li>Sensitive documents on unprotected network drives is like leaving them in paper form on unattended desks.<\/li>\n<li>Disreputable websites are run by untrustworthy people who misuse or exploit you and your information as if you had engaged them face to face in a disreputable nightclub.<\/li>\n<\/ul>\n<h6>Technical solutions<\/h6>\n<p>Appropriate technical mitigations are also important, with solutions dependent on each company\u2019s unique risk assessment. Examples include:<\/p>\n<ul>\n<li>Controlling access privileges<\/li>\n<li>Encrypting sensitive files<\/li>\n<li>Password security following guidance from GCHQ and the National Cyber Security Centre<\/li>\n<li>Robust physical site security and resilient internal infrastructure<\/li>\n<li>Appropriate firewalls<\/li>\n<li>Secure, snapshot backups<\/li>\n<li>USB dongles<\/li>\n<li>Using social media technology to help screen those who need access<\/li>\n<li>Web-verification tools to protect against specific types of attack<\/li>\n<\/ul>\n<h6>Conclusion<\/h6>\n<p>Cybercrime is a rapidly growing concern with commensurate risks and costs. Most threats have equivalents in the physical workspace and are often best understood and managed as such.<\/p>\n<p>By using the \u2018Motive x Method x Opportunity\u2019 approach within a robust risk assessment framework that complies with acknowledged standards, in particular ISO 31000 and ISO 27000 series, some businesses can save resources and combat cyber threats by focusing less on complex technical solutions and more on physical and human ones.<\/p>\n<p>Supplied by Pilgrims Group Ltd.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber security made simple\u00a0\u00a0\u00a0\u00a0 Cybercrime, including ransomware, is a growing phenomenon in the developed&hellip;<\/p>\n","protected":false},"author":19,"featured_media":4748,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"footnotes":""},"categories":[89,36,2,4164],"tags":[],"class_list":["post-4768","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-advice","category-cyber-security","category-editors-choice","category-pilgrims-group"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.0 (Yoast SEO v25.2) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cyber security: motive, method, opportunity - City Security Magazine<\/title>\n<meta name=\"description\" content=\"Cyber security for businesses can be improved by using the &#039;Motive, Method, Opportunity&#039; approach, focusing more on physical and human solutions.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber security: motive, method, opportunity\" \/>\n<meta property=\"og:description\" content=\"Cyber security made simple\u00a0\u00a0\u00a0\u00a0 Cybercrime, including ransomware, is a growing phenomenon in the developed world where some $80 billion is spent annually\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\" \/>\n<meta property=\"og:site_name\" content=\"City Security Magazine\" \/>\n<meta property=\"article:published_time\" content=\"2018-09-02T08:52:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-09-02T18:05:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1170\" \/>\n\t<meta property=\"og:image:height\" content=\"780\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Contributor CSM\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CitySecuritymag\" \/>\n<meta name=\"twitter:site\" content=\"@CitySecuritymag\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Contributor CSM\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\"},\"author\":{\"name\":\"Contributor CSM\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2\"},\"headline\":\"Cyber security: motive, method, opportunity\",\"datePublished\":\"2018-09-02T08:52:52+00:00\",\"dateModified\":\"2018-09-02T18:05:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\"},\"wordCount\":1509,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg\",\"articleSection\":[\"Advice\",\"Cyber Security\",\"Editor's Choice\",\"Pilgrims Group\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\",\"url\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\",\"name\":\"Cyber security: motive, method, opportunity - City Security Magazine\",\"isPartOf\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg\",\"datePublished\":\"2018-09-02T08:52:52+00:00\",\"dateModified\":\"2018-09-02T18:05:51+00:00\",\"description\":\"Cyber security for businesses can be improved by using the 'Motive, Method, Opportunity' approach, focusing more on physical and human solutions.\",\"breadcrumb\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage\",\"url\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg\",\"contentUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg\",\"width\":1170,\"height\":780,\"caption\":\"Cyber security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citysecuritymagazine.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber security: motive, method, opportunity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#website\",\"url\":\"https:\/\/citysecuritymagazine.com\/\",\"name\":\"City Security Magazine\",\"description\":\"News and advice for security professionals\",\"publisher\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citysecuritymagazine.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#organization\",\"name\":\"City Security Magazine\",\"url\":\"https:\/\/citysecuritymagazine.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg\",\"contentUrl\":\"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg\",\"width\":2048,\"height\":573,\"caption\":\"City Security Magazine\"},\"image\":{\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/CitySecuritymag\",\"https:\/\/www.linkedin.com\/company\/city-security-magazine\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2\",\"name\":\"Contributor CSM\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g\",\"caption\":\"Contributor CSM\"},\"description\":\"City Security magazine is proud to work with contributors from across the security sector and beyond, including police forces, security associations, security providers, consultants and specialists who produce a range of varied and interesting content.\",\"url\":\"https:\/\/citysecuritymagazine.com\/author\/contributor-csm\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Cyber security: motive, method, opportunity - City Security Magazine","description":"Cyber security for businesses can be improved by using the 'Motive, Method, Opportunity' approach, focusing more on physical and human solutions.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/","og_locale":"en_GB","og_type":"article","og_title":"Cyber security: motive, method, opportunity","og_description":"Cyber security made simple\u00a0\u00a0\u00a0\u00a0 Cybercrime, including ransomware, is a growing phenomenon in the developed world where some $80 billion is spent annually","og_url":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/","og_site_name":"City Security Magazine","article_published_time":"2018-09-02T08:52:52+00:00","article_modified_time":"2018-09-02T18:05:51+00:00","og_image":[{"width":1170,"height":780,"url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg","type":"image\/jpeg"}],"author":"Contributor CSM","twitter_card":"summary_large_image","twitter_creator":"@CitySecuritymag","twitter_site":"@CitySecuritymag","twitter_misc":{"Written by":"Contributor CSM","Estimated reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#article","isPartOf":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/"},"author":{"name":"Contributor CSM","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2"},"headline":"Cyber security: motive, method, opportunity","datePublished":"2018-09-02T08:52:52+00:00","dateModified":"2018-09-02T18:05:51+00:00","mainEntityOfPage":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/"},"wordCount":1509,"commentCount":0,"publisher":{"@id":"https:\/\/citysecuritymagazine.com\/#organization"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage"},"thumbnailUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg","articleSection":["Advice","Cyber Security","Editor's Choice","Pilgrims Group"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/","url":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/","name":"Cyber security: motive, method, opportunity - City Security Magazine","isPartOf":{"@id":"https:\/\/citysecuritymagazine.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage"},"thumbnailUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg","datePublished":"2018-09-02T08:52:52+00:00","dateModified":"2018-09-02T18:05:51+00:00","description":"Cyber security for businesses can be improved by using the 'Motive, Method, Opportunity' approach, focusing more on physical and human solutions.","breadcrumb":{"@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#primaryimage","url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg","contentUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/07\/64p7.jpg","width":1170,"height":780,"caption":"Cyber security"},{"@type":"BreadcrumbList","@id":"https:\/\/citysecuritymagazine.com\/cyber-security\/advice-cyber-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citysecuritymagazine.com\/"},{"@type":"ListItem","position":2,"name":"Cyber security: motive, method, opportunity"}]},{"@type":"WebSite","@id":"https:\/\/citysecuritymagazine.com\/#website","url":"https:\/\/citysecuritymagazine.com\/","name":"City Security Magazine","description":"News and advice for security professionals","publisher":{"@id":"https:\/\/citysecuritymagazine.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citysecuritymagazine.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/citysecuritymagazine.com\/#organization","name":"City Security Magazine","url":"https:\/\/citysecuritymagazine.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/","url":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg","contentUrl":"https:\/\/citysecuritymagazine.com\/wp-content\/uploads\/2018\/06\/header-logo-2.jpg","width":2048,"height":573,"caption":"City Security Magazine"},"image":{"@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/CitySecuritymag","https:\/\/www.linkedin.com\/company\/city-security-magazine"]},{"@type":"Person","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/1b424dabf8b3cf40177efb7350e059f2","name":"Contributor CSM","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/citysecuritymagazine.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/267a3b16d581feb77df68e95969d9bcf7cfe93d4e2f5f699b331bf4de6a055b9?s=96&d=mm&r=g","caption":"Contributor CSM"},"description":"City Security magazine is proud to work with contributors from across the security sector and beyond, including police forces, security associations, security providers, consultants and specialists who produce a range of varied and interesting content.","url":"https:\/\/citysecuritymagazine.com\/author\/contributor-csm\/"}]}},"_links":{"self":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/4768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/comments?post=4768"}],"version-history":[{"count":1,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/4768\/revisions"}],"predecessor-version":[{"id":6033,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/posts\/4768\/revisions\/6033"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/media\/4748"}],"wp:attachment":[{"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/media?parent=4768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/categories?post=4768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citysecuritymagazine.com\/wp-json\/wp\/v2\/tags?post=4768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}