Recycling Your Jumper
Swedish clothing retailer, H&M, in conjunction with the Hong Kong Research Institute of Textiles and Apparel (HKRITA) has introduced the first jumper-cycling machine to one of its Stockholm stores.
Environmental Impact
Reducing the constant need for new-fibre garments is an important way in which the clothing industry can reduce carbon footprints and its impact on the environment. For example, fashion clothing accounts for 10% of human carbon emissions, dries up water sources, and pollutes rivers and streams with plastic fibres. Also, it is staggering to think that 85 percent of all textile production ends up being dumped each year.
Recycling Agenda
With reducing this terrible environmental toll in mind, H&M is one clothing retailer that aims to be carbon positive by 2040, helped by focusing on the recycling of what its customers already have in their wardrobes. Before lockdown, H&M customers could already hand in used clothes at most H&M stores for recycling. Also, the H&M Foundation HKRITA has developed a method for separating cotton and polyester in blended garments and has already started building an industrial-scale facility for this operation.
The Jumper Recycling Machine
Then new machine which has evolved from the first ‘Mini Mill’ jumper recycling machine is a way for a customer to witness ‘live’ recycling of their old jumper into yarn and thereby to understand the possibilities of recycling. The yarn from their old jumper can then be knitted into a either a sweater, a baby blanket, or a scarf.
The machine is a container-sized system with a multi-step process that offers a significantly lower environmental footprint than producing garments from scratch. Following the sanitising, opening, cleaning, and spinning of the yarn, it can then be doubled, twisted, and knitted into a new garment.
The H&M Foundation says about the Mini Mill, “we believe we have a role to play to educate, inspire and nudge people into new habits. This is why we sponsor the Mini Mill”.
Award-Winning
The Mini Mill received the Red Dot Award back in 2019 (an international award for those who distinguish their business activities through design) and was a finalist in Fast Company’s Innovation by Design Awards.
What Does This Mean For Your Business?
Pollution in the oceans and rivers and the environmental impact of fast fashion and other waste producing consumption are now hot topics among more environmentally aware consumers and among governments with environmental targets to meet. Like other companies, having a foundation that works on and donates environmental projects and ways to improve lives in different parts of the world is a constructive way to offset negative impacts of the business and create good PR, but also to genuinely raise awareness and bring about positive change. Using technology to educate and show new possibilities are ways in which businesses can add value, give something back, and differentiate themselves from other high street competitors in a way that shows an ethical and caring side that is now more valued by consumers who are more interested in the origins and impact of their product choices, and how it reflects upon their view of themselves. Also, being seen to support positive, green values is becoming more important where social media profiles contribute to feelings about ‘self’.
Buy Products Directly From YouTube
It has been reported that YouTube (owned by Google) is testing a feature that will enable viewers of YouTube videos to directly purchase products that they see featured in the video they are watching.
Back in 2015
The idea was originally announced as far back May 2015 when YouTube announced that it had introduced “shoppable cards” within videos called “TrueView” for brands to sell products directly to individuals. The feature was designed to allow a person to make an impulse purchase of something they saw in a YouTube video.
Fast-forward a bit further to May 2019, and as part of a re-vamp of Google Shopping, Google announced that people would have the chance to buy products shown on YouTube videos i.e. purchase the items featured in the videos.
The Present Day
The latest reports appear to have emerged via Bloomberg which reported that YouTube had been asking creators to tag and track the products used in their videos. It is understood that the data is being sent to Google to help improve its analytics, to shopping tools on YouTube, and possibly being used to contribute to a future integration with Shopify, which is a competitor to Amazon. Shopify is a (Canadian) e-commerce, online platform with more than 1 million merchants globally who use Shopify’s technology for their own independent, decentralised stores.
Bloomberg also reports that a YouTube spokesperson has confirmed that the feature is being tested with some YouTube video channels, and that creators can decide which products appear as being available for sale.
Video Builder Too
Back in April, as a way that to remind users of the value and scope of its suite of business services, YouTube announced the launch of its (beta) Video Builder, a free tool that enables businesses to easily make short video adverts. YouTube said that the new tool would be of value because businesses of all sizes have limited time and resources and that in-person video shoots “are no longer practical in many countries”. The YouTube Video Builder was also introduced with brands or agencies in mind who may want to experiment and create supplemental, lightweight videos, and to smaller businesses and businesses with less creative experience, who need an efficient, low-resource way to create videos. YouTube suggested that the completed videos could be used for advertising campaigns, on websites or in emails.
What Does This Mean For Your Business?
As demonstrated by YouTube influencers, the engaging power of video can make it a potent sales tool and Google’s YouTube is the leading video platform. Having the power to catch and direct customers straight to a sale when they are at their most engaged and enthused with a product is likely to be a tool that many marketers and businesses would really value and want. Introducing this feature would see YouTube moving into shopping and competing directly with Amazon. An integration with Shopify would also be another competitive move against Amazon.
Google has clearly augmented its platforms with more features recently, and the addition of this feature would help Google to attract more marketers to YouTube and to leverage its store of user data and business relationships to help those marketers reach the right audiences and generate sales through a new, direct route.
New ‘Breakout Rooms’ For Google Meet Users
Users of the Google Meet, Enterprise for Education video-communication service (formerly part of G Suite) will soon be able to divide meeting participants into Breakout Rooms.
Greater Engagement
The feature, which started its gradual roll-out on 8th October will allow groups of students to split off into smaller groups for discussions which Google says is a way of offering more engaged distance learning.
Moderators move between the different breakout rooms to monitor and participate in discussions but (in a similar way to walking into a physical classroom) they won’t be able to the see chat messages that were exchanged when they were not in the room.
Create and Move
The event creator can create breakout rooms during the call and although call participants are then randomly and equally distributed across the rooms, event creators can also manually move people into different rooms.
Google says that 100 breakout rooms can be created in a call and that anyone with a Google account that is joining (from the web or through the Meet app) can be a participant.
Instructions for using the new feature can be found on Google’s website here: https://support.google.com/meet/answer/10099500
Google Meet
At a time when Zoom (especially) and Microsoft Teams have experienced huge new daily user numbers because of the remote working required during the pandemic lockdown, distance learning has become a necessity. In the UK for example, with jobs being lost and the Chancellor suggesting that people ‘retrain’ there has also been a push to promote adult education. In addition to localised restriction in parts of the UK, there is now the threat of further winter lockdowns. High profile competitor Zoom also offers a breakout rooms feature, albeit for up to 50 separate sessions.
It is against this backdrop that Google has found a way to compete with online video conferencing rivals and make a timely release announcement for this feature, which is likely to be in demand in many countries facing the same educational challenges that COVID-19 has created.
100+ Daily Users
Google Meet, which is now a free video conferencing service for all, announced back in April that it was getting 3 million new users each day, had seen a thirty-fold increase in usage since January, and that there were 100 million daily Meet meeting participants. Zoom, for example, has grown its daily user numbers from 10 million before the lockdown to an estimated 300 million.
What Does This Mean For Your Business?
For Google, this announcement is a way to raise the profile of ‘Meet’ and differentiate its service by focusing on education and offering more breakout rooms than Zoom at a time when there is fierce competition in the video-conferencing market. This competitive move builds upon Google’s April announcement that it would be making its ‘Google Meet’ premium video conferencing service free for everyone rather than leaving it as part of its paid-for G Suite.
For educators, this feature may add value and make the Google Meet platform more attractive and for larger businesses especially, this means that there is now even more choice for video conferencing options.
Learning From the WisePay Attack
In the wake of the recent attack on the WisePay website which saw some parents unwittingly making school payments to cyber-criminals, we look at how to spot whether personal data may have been compromised and how to protect personal information going forward.
WisePay
WisePay is a payment services provider to UK schools and academies offering a SaaS (Software as a Service) model. Its school payments software services mean that parents and guardians can make secure, cashless payments to their school or college for bursaries, trips, meals, school clubs and more. The company, started by Sarah Phillips, joined forces with leading US-based education-tech company ‘Community Brands’ back in January 2018.
WisePay also offers a digital ‘parental engagement’ and forms manager service where it deals with emailing, texting, forms, and data collection on behalf of its school and academy customers.
Website Hack and Spoof Page
WisePay estimates that an attack on their website occurred at some time between Friday 2nd and Monday 5th October. Cyber-criminals were able to hack the WisePay website and re-direct the payment gateway page to a different URL of a spoof payment page that they controlled. This kind of attack is known as ‘URL manipulation/ URL rewriting’. In this way, parents who went to the right website to pay their UK school fees were still able to be duped into paying their money to the cyber-criminals.
The hack was quickly discovered (on Monday morning) and parents of the schools affected were informed just days after the attack.
After the Attack
The attack is thought to have affected around 300 schools and because it happened over just a weekend, it is likely that not many people (relatively) will have been affected. Parents and guardians were informed that following the attack, WisePay had taken its website offline to deal with the incident and that it was taking steps to implement additional security measures to stop a recurrence of that kind of attack. Also, WisePay notified the UK’s Information Commissioner (as they were required to under GDPR) and notified UK law enforcement.
Forensic Investigation
Parents/guardians at the affected schools were also informed that their payment card data may have been unlawfully disclosed, asked to contact the school, and informed that WisePay had engaged a computer forensics expert and that there was a forensic investigation which is ongoing. WisePay, via the school, recommended that those likely to be affected should be cautious regarding personal financial arrangements and should take prompt steps to pause or cancel the payment card was used to pay via WisePay during the period at the beginning of the month.
Echoes of Form-Jacking Attacks of 2019
The WisePay attack is reminiscent of the high-profile form-jacking attacks from the beginning of last year, such as those on BA and Ticketmaster who were targeted by the ‘Magecart’ hacking group. In the Ticketmaster attack, the hackers first compromised a chatbot that was used for customer support on Ticketmaster websites and this chatbot provided the ‘way in’ for the Magecart attackers, enabling them to alter the JavaScript code on Ticketmaster’s websites so that payment card data from customers could be siphoned off.
It is not yet known, however, what was the root cause of the WisePay attack.
How Do You Know If Your Personal Data Has Been Compromised?
As identified by WisePay in its communication (via schools) following the attack, in addition to following the advice to cancel the card used to pay, those who believe they may be affected by this kind of attack should look out for the following indicators:
– Any suspicious transactions shown on payment card statements and/or funds missing from a bank account.
– Receipt of ransomware messages or fake antivirus messages.
– The appearance of unwanted browser toolbars or unexpected software installs.
– An unfamiliar search history in a browser.
– Re-directions of internet searches and frequent, random popups onscreen.
– Reports that friends have received social media invitations that have not been sent.
– Online passwords not working.
– The mouse moving between programs and making selections.
Vigilance
After a cyber-attack, it is not uncommon for the victims to be targeted quickly again by those pretending to be helping them to recover from the attack, with a view to stealing money and details. For example, attackers in this case may target affected parents/guardians pretending to be from the school, the police, or Action Fraud, and may ask for personal details to help with their enquiries. Those who have/may have been victims of a recent cyber attack should, therefore, be extra vigilant for this kind of social engineering and fraudulent activity.
Further Steps
There are steps that we can all take as individuals and businesses to protect our personal data from cyber-criminals, particularly if we suspect that our details may have been stolen in an attack. These steps could include:
– Regularly reviewing financial account statements and credit reports, and reporting any suspicious activity to the financial institution/company concerned, the police, and Action Fraud. It may be useful to obtain a free copy (30-day free trial) of your credit report from the major credit reporting agencies e.g. Equifax, to help spot any unusual activity.
– Consider placing a fraud alert on your credit report. It is free and will stay on your credit file for at least 90 days. An alert keeps creditors informed of any possible fraudulent activity within your report and requests that the creditor contact you prior to establishing any accounts in your name.
– Consider placing a security freeze to stop any new credit from being opened in your name without a special security freeze PIN, and to stop others from accessing your credit report without your consent.
– Check whether your email address has been compromised in any known previous attacks by going to https://haveibeenpwned.com/.
Plans In Place
For businesses, in addition to taking steps to maintain day-to-day cyber defences, it is important to have realistic, workable plans in place such as a Cyber Resilience Plan to prepare for, respond to and recover from cyber-attacks. Business continuity planning and disaster recovery plans can mean the difference between the life and death of a business after a serious attack.
Looking Ahead
URL manipulation/URL rewriting and form-jacking attacks are becoming more frequent and educational institutions along with other large organisations are likely to be considered to be lucrative, softer targets. The hackers involved had to find a way into the website in order to manipulate the URL and, as previous (similar) attacks have shown, this can be through chatbots, previously compromised accounts, phishing attacks and other means. Businesses and organisations therefore need to take a holistic approach and make sure that security measures are taken and maintained across the board as one small incident or loophole can sometimes lead to much bigger and successful attacks.
The Challenge of User Access Permissions
Employees being given too much access to privileged, sensitive company data can put an organisation in danger. In this article, we explore the issues around this subject and how businesses can minimise the risk.
Survey
In a recent survey of 900 IT professionals commissioned by IT security firm Forcepoint, it was revealed that 40 per cent of commercial sector respondents and 36 per cent of public sector respondents said they had privileged access to sensitive company data through their work. Also, 38 per cent of private sector and 36 per cent of public sector respondents said that they did not need the amount of access they were given to complete their jobs. The same survey showed that 14 per cent of respondents believed that their companies were unaware of who had what access to sensitive data.
The results of this survey confirm existing fears that by not carefully considering or being able to allocate only the necessary access rights to employees, companies may be leaving open a security loophole.
Risks and Threats
The kinds of risks and threats that could come from granting staff too many privileges in terms of sensitive data access include :
Insider Threats
Insider threats can be exceedingly difficult to detect and exact motives vary but the focus is generally to gain access to critical business assets e.g. people, information, technology, and facilities. Insiders may be current or former full-time employees, part-time employees, temporary employees, contractors/third parties, and even trusted business partners. The insider may be acting for themselves or for a third party. Information or data taken could be sold e.g. to hackers or to representatives of other organisations/groups or used for extortion/blackmail. An insider could also use their access for sabotage, fraud, social engineering or other crimes. An insider could also cause (unintentional) damage.
The insider threat has become more widely recognised in recent years and in the U.S., for example, September is National Insider Threat Awareness Month (NIATM).
Intrusions From Curiosity
The digitisation of all kinds of sensitive information, and digital transformation, coupled with users being given excessive access rights, has led to intrusions due to curiosity, which can lead to a costly data breach. One example is in the health sector where, in the U.S., data breaches occur at the rate of one per day (Department of Health and Human Services’ Office for Civil Rights figures). Interestingly, Verizon figures show that almost 60 per cent of healthcare data breaches originate from insiders.
Accidental Data Sharing
Some employees may not be fully aware of company policies and rules, particularly at a time when the workforce has been dispersed to multiple locations during the lockdown. A 2019 Egress survey, for example, revealed that 79 per cent of employers believe their employees may have accidentally shared data over the last year and that 45 per cent sent data to the wrong person by email. Unfortunately, the data shared or sent to the wrong person may have been sensitive data that an individual did not need to have access to in order to do their job.
Hacking
If hackers and other cybercriminals are able to obtain the login credentials of a user that has access rights to sensitive data (beyond what is necessary) this can provide relatively easy access to the company network and its valuable data and other resources. For example, cybercriminals could hack or find lost devices or storage media, use social engineering, or use phishing or other popular techniques to get the necessary login details.
How Does It Happen?
The recent Forcepoint and the Ponemon Institute survey showed that 23 per cent of IT pros believe that privileged access to data and systems are given out too easily. The survey results suggest that employees can end up having more access rights than they need because:
– Companies have failed to revoke rights when an employee’s role has changed.
– Some organisations have assigned privileged access for no apparent reason.
– Some privileged users are being pressured to share access with others.
How To Stop It
Stopping the allocation of too many privileged access rights may be a holistic process that considers many different aspects and activity from multiple sources, including:
– Incident-based security tools. Although these can alert the organisation to potential problems and can register logs and configuration changes, they can also give false positives and it can take a prohibitively long time to fully review the results, find and plug the breach.
– Trouble tickets and badge records.
– Reviews of keystroke archives and video.
– User and entity behaviour analytics tools.
– The challenge is that many organisations lack the time, resources, and expertise to piece all these elements together in a meaningful way.
Looking Forward
It appears that where there is a disconnect between IT managers and staff, and where access rights are not regularly monitored or checked, a whole business or organisation can end up being in danger. Some security commentators suggest that the answer lies in easy-to-use technology that incorporates AI to help monitor how data flows and is shared to bring about the necessary visibility as regards who has access and what they’re doing with that access. Always seeking verification and never acting simply on trust is a key way in which organisations can at least detect malicious activity quickly.
Cyber Security Top of List for Digital Transformation
A recent survey appears to have shown that changes brought by the pandemic have meant that IT buyers from companies working on digital transformation now value cybersecurity the most.
Survey
The survey, conducted among IT business leaders attending the all-virtual Digital Transformation Expo (DTX), DTX: NOW this month showed that 26 per cent of respondents put IT security at the top of their digital transformation list. A close second place was the cloud at 21 per cent.
Pandemic Accelerated Digital Transformation
As shown in survey results published last month by Studio Graphene, the need to quickly shift staff to working from home because of the lockdown appeared to be a driver and an accelerator of digital transformation for businesses. The survey showed that nearly half (46 per cent) of business leaders said that said Covid-19 had driven the most pronounced digital transformation that their businesses had experienced.
Adapt
The distribution of the workforce/staff working from home which the pandemic lockdown caused has meant that not only have businesses have been forced to adapt their cloud strategy, but also their cybersecurity measures, and their business cultures to ensure that their businesses function as well as possible.
Challenges and Gains
The survey found that the biggest challenges to digital transformation projects were identified as being changes in the scope, reduced budgets, and changes in team structures. At the same time, the survey results revealed that the need to ensure that all employees could work from home revealed IT issues that may not otherwise have been addressed, thereby helping the business to modernise and realise which areas needed investment going forward.
New Ways of Working
With further restrictions, local lockdowns, the possibility of new, stricter restrictions ahead and a decidedly uncertain near future for traditional office-based working, the pandemic has driven diversification of work methods and structures. Flexible, smarter, hybrid working, involving different location looks to be a reality for businesses as we try to gain more control in an increasingly unpredictable world and businesses environment.
What Does This Mean For Your Business?
The results of the survey appear to support the idea that necessity has driven digital transformation. The pandemic lockdown has been a catalyst that has moved many aspects of businesses forward and led them to clearly and quickly see the importance of cybersecurity, where weaknesses are, where investment is needed next and has shown them that new, more flexible models of work can benefit employer and employee. Whilst changes have been difficult, and people and their organisations have been forced to adapt to changes quickly, the lessons learned in digital transformation may have boosted confidence within organisations that they have the in-built flexibility, creativity, experience and ability to weather the storm and reinvent how they work according to prevailing conditions.