Video | Agriculture | Confidence | Economy | Energy | Employment | Finance | Media | Property | RBNZ | Science | SOEs | Tax | Technology | Telecoms | Tourism | Transport | Search

 

InternetNZ weighs in on Z Energy data breach

28 June 2018

InternetNZ believes the Z Energy data breach provides a useful lesson for them, and other organisations.

Ben Creet, Policy Manager at InternetNZ and author of New Zealand’s guidelines of security vulnerability disclosure says, “Once the media get involved in a security breach like Z Energy have had, there has been a failure of processes to disclose and fix a vulnerability.”

Firstly, this is a data breach. That’s why it’s important that the Privacy Bill and it’s mandatory data breach reporting regime is enacted. New Zealand needs to collectively lift it’s game when data breaches happen. The default position should be to tell your customers when a breach occurs.

If people are finding vulnerabilities and data breaches in New Zealand organisations websites and services you should report to CERTNZ, they are the experts and have the mana to get organisations attention. You can report a vulnerability to CERT here: https://www.cert.govt.nz/it-specialists/guides/reporting-a-vulnerability/

Additionally, we think that more New Zealand organisations should have their own vulnerability disclosure policies. The New Zealand Internet Task Force released guidelines about how to report, and receive information about security problems in 2013: http://www.nzitf.net.nz/pdf/NZITF_Disclosure_Guidelines_2014.pdf

We run a disclosure policy for the .nz registry (here) and organisations like SkyTV, Vend and even the Office of the Privacy Commissioner have their own policies to encourage reporting directly to their security experts.

InternetNZ will be reaching out to Z Energy on how they can implement a disclosure framework so that vulnerabilities are identified and fixed in a safe, collaborative timely manner.


ends

© Scoop Media

 
 
 
Business Headlines | Sci-Tech Headlines

 

Brands Sale To RJ's: Nestle Job Losses “A Bolt From The Blue”

E tū has about 200 members at the plant, where up to 55 workers could lose their jobs... Well-known Kiwi brands affected by the sale include Mackintosh’s, Heards, Black Knight liquorice, Life Savers and Oddfellows. More>>

ALSO:

'Sanctuaries': New Seabed Mining Project Threatens Endangered Species

Greenpeace is shocked to discover that a new seabed mining exploration permit has been awarded inside a Marine Mammal Sanctuary, and is calling on the Government to reject all attempts to mine the seabed. More>>

ALSO:

RMA, Building Offences: Record Sentence For Property Developer

The unprecedented sentence handed down to a property developer in the Auckland District Court is a strong warning to others who would consider this type of offending. More>>

Other Real Estate Crimes:

Tourism: Guest Nights Up 1.6 Percent In May

Over 2.5 million nights were spent in commercial accommodation in May 2018, Stats NZ said today. This number is up 1.6 percent from May 2017. More>>

ALSO: