Category: News

How AI and machine learning solutions drive value for financial institutions

In an era where technology is reshaping industries, BMO is making waves in the financial sector through its robust artificial intelligence (AI) initiatives and machine learning technologies.

A recent interview with Eric Morrow, Managing Director, Enterprise Data Science & AI, Data & Analytics, and Alex Tait, U.S. Chief Data and Analytics Officer, Data & Analytics, shed light on the transformative power of AI, where increased model performance directly correlates with amplified revenue, reduced costs, and most importantly, enhanced customer experiences.

At BMO, the benefits of broadly applying AI, data science and machine learning are clear. “There’s almost endless opportunity for taking data and applying models to it within a financial services organization,” said Tait. “Potential applications span everything from marketing to defending against cybersecurity threats.”

Driving AI integration at BMO

BMO considers AI an integral part of the bank’s strategy, tightly interwoven with revenue streams and cost-effectiveness. Morrow describes AI integration as a “powerful concept” that can be applied cross-functionally with active engagement across BMO’s lines of business and various Data and Analytics leaders.

“On our mobile app, for instance, you provide personalized insights to the individual, and that’s a powerful thing that really creates that connection with the customer,” he said.

In addition to AI’s application in retail banking, BMO has created new and innovative ways to apply advanced analytics to commercial customers’ needs. Earlier in 2023, Datos Insights, a global advisory firm focused on technology, regulation, strategy, and operations in the financial services industry, presented BMO with a 2023 Impact Innovation Awards in Cash Management and Payments for AI and advanced analytics for its “Digital Workbench” technology.

BMO Digital Workbench provides real-time analytics and reporting in various areas through a cloud-based self-service portal accessible to multiple businesses within the bank. It integrates scattered data sets across different bank systems with an easy-to-use, cloud-based web interface that drives cohesive and accessible analytics, facilitates insightful customer conversations, and transforms pricing and product mix strategies. A suite of data-driven tools with dynamic customer analytics and forecasting capabilities powers the technology.

Yet implementing customer solutions using AI and analytics is only part of the story. BMO supports cutting-edge research to ensure AI solutions provide functionality, accuracy, efficiency, and automation.

Supporting AI’s broader application in financial services

An example is BMO’s sponsorship of Next AI, a Montreal-based founder development network for entrepreneurs looking to solve global challenges with AI-based ventures and technology commercialization. Next AI helps identify and support early-stage ventures, which receive access to resources, mentorship education and the network they need to succeed.

Another notable endeavour illustrating BMO’s commitment to AI excellence is its partnership with the Vector Institute, a collaboration that epitomizes BMO’s dedication to staying at the forefront of AI innovation.

The Vector Institute offers a platform for BMO to explore leading AI research, turning academic insights into practical applications. A past, prominent project involves Natural Language Processing (NLP), a domain critical for a bank dealing with vast amounts of textual data.

According to Morrow, BMO can leverage NLP to help better understand why customers call into contact centres. “Being able to ensure that we’re providing the right level of service and care back to them when there are engagements between the agents is the goal,” says Morrow.

And BMO is making progress towards it. In 2023, Digital Banker recognized BMO with an Outstanding Machine Learning Initiative Award, which focused on leveraging NLP association with a contact centre.

The future of AI at BMO

BMO’s journey into AI and machine learning isn’t just about the present; it’s about building a future where technology seamlessly integrates with customer needs. The bank’s strategic direction emphasizes a digital-first approach and cloud-centricity. This focus on technological integration ensures operational efficiency and positions BMO as a pioneer in the banking industry’s digital transformation, and it starts from within the bank. This past year, more than 3,500 BMO employees participated in deep technical learning and licensing in subjects like AI, Machine Learning and Cloud.

Additionally, BMO is experimenting with new technologies enterprise-wide to develop digital capabilities to advance the bank’s Climate Ambition. Through BMO’s developing Climate Analytics Platform, the bank is using its digital capabilities, and developing the ability to use AI, to help understand the impacts and risks from weather-related events, such as floods, droughts, extreme heat and more. For any company seeking to manage this evolving risk, it is important to identify how these physical climate impacts are expected to change over time and by location, and how those changes intersect with economic systems. For banks like BMO who have a large financing footprint, it is important to identify where climate hazards are projected to manifest, and to manage the risk and capture opportunities associated with this changing future. While these programs are still under development, our technology teams can support innovation within the bank by piloting new and innovative technology driven approaches to climate related analysis.

BMO’s integration of AI is a testament to the bank’s commitment to delivering value through exceptional banking experiences across all its lines of business. Outside the bank, BMO is raising the bar in applying AI and machine learning in the financial services sector by extending that commitment to research and collaboration with esteemed organizations like the Vector Institute. As AI continues to influence the future, BMO stands as a beacon, showcasing how innovative technology can redefine banking, enrich customer interactions, and drive business growth.

The post How AI and machine learning solutions drive value for financial institutions first appeared on IT World Canada.

Cyber Security Today, Jan. 8, 2024 – How a Spanish cellular carrier’s network was knocked offline, and more

How a Spanish cellular carrier’s network was knocked offline, and more.

Welcome to Cyber Security Today. It’s Monday, January 8th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Despite all the money organizations spend on cybersecurity, some continue to shoot themselves by ignoring basic cybersecurity practices. The latest example is last week’s compromise of cellular carrier Orange Spain. How was it done? A threat actor infiltrated the computer of an administrator and stole their login credentials to a regional IP network co-ordination centre called RIPE. Never mind the administrator’s password was ‘ripeadmin,‘ which could have been guessed. Worse is that — according to researcher Kevin Beaumont — this IP network account wasn’t protected with multifactor authentication. Let me repeat that: Login to a service that looks after internet routing of a telecommunications provider had no multifactor authentication protection. By the way, the stolen administrator credential had been available for sale on a criminal marketplace since last August to any threat actor. It isn’t known how the admin’s computer was compromised so the password could be stolen. But they likely fell for a phishing or social media scam, which allowed malware to be planted on their machine. Fortunately all that happened was Orange Spain customers lost connectivity for several hours.

Meanwhile, all telecommunications providers in Europe, the Middle East and Asia that use the RIPE network should note there are thousands of stolen credentials for accessing this system being sold on dark web marketplaces. You have been warned.

A midwife service for expectant mothers in Southern Ontario is notifying women it suffered a data breach last April. CBC News says Midwives of Windsor is telling clients that one of its email accounts was compromised. An unknown number of names, mailing addresses, phone numbers, dates of birth and other personal information of mothers and children may have been copied.

Someone was able to compromise the flight information displays at Beirut International Airport on Sunday and post anti-Hezbollah messages. Hezbollah is an Islamist political party and militant group in the country. According to the Associated Press, those in the airport hoping to see departure and arrival times instead saw a message accusing Hezbollah of putting Lebanon at risk of an all-out war with Israel.

Some organizations are already implementing solutions to protect their encrypted applications from future quantum computer attacks. However, researchers are warning one solution already has a vulnerability that has to be patched. The solution is CRYSTALS, a set of algorithms approved by the National Institute of Standards and Technology (NIST). Within CRYSTALS is a security key encapsulation mechanism called Kyber, and that’s where the problem is. According to Bleeping Computer, researchers found Kyber has two vulnerabilities. One was patched on December 1st, the other on December 30th. If your application uses Kyber as part of its CRYSTALS solution this has to be looked after.

And by the way, if your application handles encrypted sensitive or financial data you need to be investigating quantum-safe solutions now before quantum computers can unscramble them.

Pharmaceutical manufacturer Merck & Co. has reached a settlement with insurers over hundreds of millions of dollars it was claiming for damages in the 2017 NotPetya cyber attack. You may recall that was the cyber attack aimed at Ukraine by compromising an accounting program used in that country. But the destructive worm escaped to ravage unpatched Windows computers around the world, including Merck’s systems. A New Jersey appeal court ruled insurers had to pay Merck about US$700 million for computer damages the company suffered. Last week the insurers were about to fight that decision before the New Jersey Supreme Court. But Bloomberg Law says there was a last-minute settlement. The terms of that settlement are confidential. The appeal court ruled the insurers had to pay under Merck’s all risks property coverage. While the policies basically said there was no payout for damages caused by war-like actions, the appeal court said the wording only applied to traditional forms of war and not cyber attacks. The language for insurance policies is tighter these days.

Five years ago the U.S. seized control and laid charges in the operation of the online xDedic criminal marketplace. Last week the government said its investigation has peaked. Seventeen people were charged. All were convicted. Eleven got sentences ranging from 78 to 12 months in prison. One was sentenced to five years probation. Five others are awaiting sentencing. The marketplace sold stolen login credentials to more than 700,000 servers around the world as well as stolen personal information.

A New York State healthcare provider has agreed to pay US$450,000 and spend US$1.2 million to strengthen its cybersecurity following a ransomware attack two years ago. An attacker claiming to be the Lorenz ransomware gang accessed the data of 250,000 people held by Rafuah Health Centre. New York’s attorney general’s office found the health centre failed to encrypt patient information, failed to use multifactor authentication to protect logins, failed to decommission inactive user accounts, failed to rotate user account credentials and failed to restrict employee’s access to data to only those who needed it..

A San Francisco law firm that specializes in technology now says the personal information of over 630,000 people was copied in a cyber attack it suffered early last year. Originally the firm of Orrick, Herrington & Sutcliffe LLP reported to Maine’s attorney general’s office that 152,000 people were impacted. Then the number rose to 461,000. The attacker got into a file share where certain client files were stored including emails and email attachments. Stolen data could have included peoples’ names, dates of birth, Social Security numbers, government-issued identification numbers, passport numbers, financial account information, medical information and more. Last month the law firm reached a proposed settlement in a class action suit stemming from the data breach.

Finally, do you have an idea of how to detect the use of voice cloning for audio and video crimes? You have until Friday to submit a solution to the U.S. Federal Trade Commission. It’s running a contest to find ways of stopping threat actors from defrauding victims or spreading disinformation. Voice cloning uses text-to-speech technology originally developed to help people who have lost their voices from accidents or illness. But crooks are using it to impersonate people. The contest winner gets US$25,000.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 8, 2024 – How a Spanish cellular carrier’s network was knocked offline, and more first appeared on IT World Canada.

Hashtag Trending Jan.8- Cybersecurity challenges in 2024; Tech companies still cutting back; OpenAI sued for copyright infringement

2024 promises to have more cybersecurity challenges including a continued shortage of cybersecurity workers.  Are tech companies quietly continuing to cut back. OpenAI is sued for copyright infringement – again. 



 

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

As we dive into 2024, cybersecurity experts are sounding the alarm on the evolving tactics of hackers. The emerging threats are not just more sophisticated but are also exploiting new technologies and platforms.

We can expect more of the same in some areas:

– AI-Powered Attacks: Hackers are increasingly leveraging artificial intelligence to automate attacks, making them more efficient and harder to detect.

– Deepfakes and Misinformation: The use of deepfakes to spread misinformation or impersonate individuals is on the rise, posing significant risks to personal and corporate security.

– Crypto and Blockchain Vulnerabilities: Cryptocurrency platforms are becoming prime targets for cyberattacks.

– Supply Chain Compromises: Hackers are focusing on supply chain vulnerabilities, aiming to disrupt entire networks through a single entry point.

But an article in Axios that I read had some haunting comments from Wendi Whitmore, senior vice president of Palo Alto Networks.

She pointed out that data leaks rose exponentially in 2023 as cybercrooks got better at exploiting critical vulnerabilities before companies discovered them.

And in 2023 hackers demonstrated a deep understanding of how businesses work and the way they operate with suppliers – all of this will be fuel for future exploits.

With these challenges, and despite other news that some tech companies are still cutting back, the shortage of cybersecurity workers continues into 2024.

The US has only enough workers to fill 72 per cent of the available cybersecurity jobs according to a report from CyberSeek

So 2024 is just another day in paradise.

Sources include: Axios and CyberSeek

Are tech companies quietly continuing to cut back?

An article in TechPro featured claims from a senior AWS developer about Amazon’s alleged strategy to subtly encourage employees to leave. 

The report suggests that Amazon is creating conditions that subtly nudge employees towards leaving, rather than openly conducting layoffs.

Amazon, like many tech companies, appears to be facing continuing market pressures and economic uncertainties. 

I doubt that this is just Amazon. It appears that the troubles continue in the tech industry, with companies trying to deal with a challenging economic landscape.

That’s despite a critical shortage of cybersecurity workers and unemployment numbers that are the lowest they’ve been in decades. 

We live in strange times.  And they may just get stranger. A recent edX survey of 800 executives and 800 employees has brought to light some startling predictions about the future of workplace skills. Nearly half of the current workforce skills are expected to become obsolete in just two years, primarily due to advancements in artificial intelligence.

About 49 per cent of existing skills in the workforce today are predicted to be irrelevant by 2025.

Over half (56 per cent) of entry-level knowledge worker roles are expected to be eliminated within the next five years because of AI.

47 per cent of C-Suite executives believe that most or all of the CEO role could be automated or replaced by AI, with 49 per cent of CEOs themselves agreeing with this view

92 per cent of executives acknowledge the importance of improving their AI skills within the next one to two years, with 79 per cent fearing they’ll be unprepared for the future of work if they don’t learn to use AI.  And 56 per cent thought their own roles will be completely or partly replaced by AI. 

Sources include: Forbes

Nonfiction authors Nicholas Basbanes and Nicholas Gage have filed a class-action lawsuit against Microsoft and OpenAI, alleging copyright infringement. The lawsuit claims the defendants used the authors’ copyrighted works to develop a billion-dollar AI system. This follows another suit by The New York Times against Microsoft and OpenAI, that happened over the holidays. 

Among the damning evidence that Times produced was a prompt that generated an almost word for word copy of an article from ChatGPT. Talk about getting caught red handed. 

That may be why there are reports that OpenAI is frantically making the rounds and trying to build partnerships with publishers.  

And my favourite story coming back is from Axios where they reported there’s a growing nostalgia for the pre-internet era, especially among those who never experienced it. 

There are interesting relics like pay phones, paper maps, and typewriters.

Shows like Friends and Seinfeld are seeing a resurgence of interest.

Apparently for younger generations who grew up in the internet age, these relics offer a glimpse into a different way of life, fostering a sense of curiosity and nostalgia.

I guess we’re sort of like vinyl records – from when analogue was where it’s at.  

I don’t know. Since I read this article I’m of two minds. One, I’m not sure how I feel about being a relic. But I also keep hearing that old song from Hughie Lewis and the News – it’s hip to be square. 

If you don’t know the song – google it. Or better, buy the album on vinyl.

And that’s what’s trending as we come back for another year. 

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.” 

To those of you who wrote me at jlove@itwc.ca –thanks. With a special shout out to one reader who pointed out some inconsistencies from last year. You know who you are. And thanks. 

You can also leave a comment after the show notes posted on itworldcanada.com

I’m your host Jim Love.  It’s great to be back.  Talk to you tomorrow.

The post Hashtag Trending Jan.8- Cybersecurity challenges in 2024; Tech companies still cutting back; OpenAI sued for copyright infringement first appeared on IT World Canada.

Hacked U.S. healthcare provider’s data archive involved over 900,000 people

Securing archived sensitive data from a data breach is just as important as protecting transactional information, experts say.

The latest example of this is an American medical services provider, Transformative Healthcare, that had to notify just over 911,000 people at the end of December that some of their personal information it had archived from a now-defunct division, Fallon Ambulance Services, was copied by a hacker.

Transformative Healthcare bought Fallon, which operated in Massachusetts, in 2018, but closed the company in 2022. For legal reasons, the parent company has to keep an archived copy of Fallon’s records on its computer systems.

However, as detailed in a regulatory filing with Maine’s attorney general’s office, last April suspicious activity was detected in the Fallon archive. On investigation, it was realized a hacker accessed the data in February. It took the company seven months to determine how many people may have been affected by the compromise.

Data copied could have included people’s names, addresses, Social Security numbers, medical information, including COVID-19 testing or vaccination information, and information provided to Fallon in connection with employment or application for employment.

Attackers may go after an organization’s data archives deliberately, or because they can’t get into production data. Regardless, researchers at Proofpoint argue in a blog, “attackers know that archives have a wealth of information on organization intellectual property, internal messages, and financial data. These data archives are a target for attackers who gain access to high-privilege network accounts or exploit vulnerabilities that give them access to archive data.”

The post Hacked U.S. healthcare provider’s data archive involved over 900,000 people first appeared on IT World Canada.

Cyber Security Today, Jan. 5, 2023 – 23andMe blames poor user password practices for a data breach

23andMe blames poor user password practices for a data breach.

Welcome to Cyber Security Today. It’s Friday, January 5th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Who’s at fault for the recent huge data breach at the genetic testing service 23andMe? Users and their poor password practices, says the company. That’s according to a news story on TechCrunch.  The company is writing people that some customers “negligently recycled and failed to update their passwords,” which led to the data breach. The company denies the attack was the result of 23andMe failing to maintain reasonable security measures. According to the news story, before the data theft the use of multifactor authentication for login protection was optional. Now it’s mandatory. Hackers were able to access the accounts of about 14,000 people by brute-forcing logins with a list of stolen usernames and passwords from other sites. Those accounts held personal information of linked relatives, so the total number of victims added up to 6.9 million people.

In a commentary Ken Westin, field CISO of Panther Labs said blaming victims for a data breach isn’t fair. On the other hand, other IT experts say subscribers to any service have to take some responsibility for their password practices.

Users of the LastPass password manager can’t get away with short master passwords any more. According to Bleeping Computer, the company says subscribers now have to create master passwords of at last 12 characters. Since April that’s been the rule for new users or those resetting their passwords. But older accounts were still able to use short master passwords. As many people say, the longer the better.

Russian hackers were inside the biggest Ukrainian telecom provider for at least seven months before knocking it offline last month. That’s what the head of Ukraine’s cybersecurity agency has told the Reuters news agency. Service to about 24 million users was chopped for days when the attack wiped thousands of the telco’s virtual servers. The official said the incident is a warning to countries around the world that “no one is actually untouchable.”

Canadian mining company Barrick Gold has become the latest business to tell people their data was stolen in the hack of a MOVEit file transfer server. The company notified the Maine Attorney General’s office this week that it is sending letters to over 2,700 victims. It isn’t clear if these are only Americans. Barrick spokespersons didn’t reply to an emailed query for clarification. So far over 2,726 organizations have been victimized directly or indirectly of the hack of MOVEit file transfer systems, resulting in the exposure of data of over 93 million people.

Xerox says some personal information held by its Business Solutions subsidiary was stolen in a recent cyber attack. The incident had no impact on Xerox’s corporate systems, operations or data, the company says.

Finally, Google is expected to soon start publicly testing a version of its web browser that by default deletes third-party cookies. The goal is to improve privacy. According to The Register, an estimated 30 million Chrome users – representing roughly one percent of the user base – will be involved in the test. In the second half of this year a broader phase out of third-party cookies is expected. Chrome users have been able to opt-in to a program of dropping third-party cookies for several months.

Note that because of the holidays there won’t be a Week in Review podcast this afternoon. The show resumes next Friday.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 5, 2023 – 23andMe blames poor user password practices for a data breach first appeared on IT World Canada.

Ransomware gang starts leaking data stolen from Quebec university

The LockBit ransomware gang has started releasing data it says was stolen last month from a Quebec university.

The data is from the University of Sherbrooke, with a student body of about 31,000 and 8,200 faculty and staff. Sherbrooke is a city about a two-hour drive east of Montreal.

Asked in an email to comment on the action by LockBit, university Secretary General Jocelyne Faucher referred to the institution’s Dec. 7 statement that said, “certain data from one research laboratory has been compromised.” The incident has had no impact on the university’s activities, the statement added. An investigation continues.

According to a news report on the French language Radio Canada, the university said last month it had not been hit with ransomware.

The university hasn’t said if the compromised data included personal information or intellectual property.

Threat actors go after the education sector for several reasons: First, they believe public school boards can be pressured into paying to get access back to stolen data about children. Second, they believe post-secondary institutions will be subject to pressure from students to pay for the return of stolen personal and research data.

According to Sophos’ most recent annual ransomware report, the education sector was the most likely to have experienced a ransomware attack in 2022. Eight per cent of educational institutions surveyed said they had been hit. “Education traditionally struggles with lower levels of resourcing and technology than many other industries,” the report says, “and the data shows that adversaries are exploiting these weaknesses.”

In June, Ontario’s University of Waterloo interrupted a ransomware attack after being tipped off by the RCMP. The university’s on-premises email server was compromised, but “only a tiny number of users were impacted,” the institution said. All university IT users had to re-set their login passwords.

One of the most recent cyber attacks on a Canadian university happened in December, when Memorial University’s Grenfell campus in Corner Brook, NL, was hit. According to the CBC, IT services at the Marine Institute were temporarily shut down. The start of the new semester at Grenfell had to be shifted to Monday, Jan. 8 from Thursday, Jan. 4.

All Grenfell faculty, staff and students have to change their login passwords. The university said today it has been told the campus “will likely feel the impacts of this incident for at least a few weeks.” Work includes providing laptops for faculty and staff and securing internet and Wi-Fi hotspots.

In the U.S., recent cyber attacks on the education sector included the forced IT shut down in November at Indiana’s DePauw University and an attack claimed by a ransomware gang in October at California’s Stanford University.

The post Ransomware gang starts leaking data stolen from Quebec university first appeared on IT World Canada.

In surprise move, Intel, DigitalBridge launch enterprise GenAI firm

Intel and global investment firm DigitalBridge Group yesterday announced the formation of Articul8 AI, an independent company offering enterprise customers what was described as a “full-stack, vertically-optimized and secure generative artificial intelligence (GenAI) software platform designed to keep customer data, training, and inference within the enterprise security perimeter.” It will be available in the cloud, on premises, or in a hybrid deployment.

The intellectual property and technology driving the platform were developed at Intel, and in addition, it is also providing Articul8’s first chief executive officer (CEO), Arun Subramaniyan, formerly vice president and general manager in Intel’s data centre and AI group.

According to a release, “the two companies will remain strategically aligned on go-to-market opportunities and collaborate on driving GenAI adoption in the enterprise.”

The move was something Brian Jackson, principal research director at Info-Tech Research Group, did not expect. “We know their chips aren’t ideal for training these large models used for GenAI, and we don’t typically think of Intel for its software development prowess,” he said. “Yet here it is launching a generative AI software platform.

“It looks like they are looking to sell out-of-the-box GenAI solutions to specific industry problems, with several examples listed on the Articul8 website. They focus on positioning the software platform as able to run within a company’s security perimeter. Definitely one of the top concerns we hear from enterprise customers about using GenAI is that data could be exposed to third-party providers, or worse yet used to train a provider’s own large language model.

“That could threaten a company’s business model, so guarantees of privacy and security by virtue of running models on your own infrastructure will appeal to many enterprises, especially those in the critical infrastructure or government category.”

Jackson also sees the logic in DigitalBridge’s involvement, given its investments in managed service providers who could provide enterprises with necessary services, and noted that the spinoff of the unit made sense.

“Intel is also working to mitigate its perceived weaknesses in the GenAI area,” he said. “Articul8 will support NVIDIA processors as well, and being able to work with a competitor’s hardware is probably the main reason Intel felt the need to spin out this business unit.”

But, he added, there’s still a lack of clarity about what Articul8 will actually provide: “Is it about training and customizing models or does it have specific solutions ready to deploy to operations? Is this for developers to get creative about what they want to build, or is it for business leads to get access to GenAI capabilities out of the box?”

In a release, Intel chief executive officer (CEO) Pat Gelsinger said that “with its deep AI and HPC domain knowledge and enterprise-grade GenAI deployments, Articul8 is well positioned to deliver tangible business outcomes for Intel and our broader ecosystem of customers and partners.”

DigitalBridge Ventures is the lead investor in the company, with Intel and a syndicate of other investors including Fin Capital, Mindset Ventures, Communitas Capital, GiantLeap Capital, GS Futures and Zain Group also on board.

The post In surprise move, Intel, DigitalBridge launch enterprise GenAI firm first appeared on IT World Canada.

Hybrid arrangements tripled since 2022, trend far from over, says Capterra

Nearly 70 per cent of Canadian hybrid workers go to the office two to three times a week, a new Capterra report that surveyed 1,021 part- and full-time employees working at least some days from the office has found.

The increased prevalence of hybrid work comes as companies like IBM, Amazon, Disney, Google, and even remote work poster child Zoom have vehemently pushed return to office (RTO) mandates.

Another report from Resume Builder also revealed that 91 per cent of companies will require employees to go to the office on a monthly basis, and 75 per cent will require employees to work from the office weekly.

Companies are even taking it a step further, with 95 per cent saying that employees will suffer consequences if they don’t comply. Their employment, bonuses, and salaries will likely be at risk, Resume Builder says. Reportedly, 80 per cent of companies will also track office attendance in 2024.

The Capterra report says that the RTO trend after COVID-19 restrictions temporarily closed some workplaces was perhaps influenced by employers who don’t want their investments in physical office space to go to waste.

But many organizations requiring employees to come to the office at least sometimes also tout increased productivity, valuable social connections, and higher trust at work, Capterra acknowledged.

However, some businesses perceive such rigid RTO policies to clamp down on things like absenteeism can be perceived as disregarding employees’ well being. Several companies have, in fact, seen employees quit en masse following stringent in-office mandates.

In Canada, only 23 per cent of surveyed employees in Canada report having company-wide mandatory in-office days. The same number of surveyed employees said their department also enforces mandatory in-office days.

But employees should be incentivized back to the office, Capterra says.

Nearly a third of employees who go to the office less than five times a week (32 per cent) said perks like free snacks and coffee would motivate them to come in more often.

“Free food might seem like an oversimplified tactic for boosting office attendance, but it could be a deciding factor for many workers,” said Tessa Anaya, analyst at Capterra, in an interview with ITWC.

She added, “Factors such as social events, a better office location, or even a more diverse and inclusive work environment were selected by far fewer employee respondents, which speaks to the motivational power of a good cup of coffee.”

The Resume Builder report also noted that a whopping 91 per cent of companies say they will provide incentives to employees for going into the office. These incentives include happy hours (52 per cent), catered meals (46 per cent), and upgraded office space (41 per cent). But fewer employers will offer bigger incentives such as raises (40 per cent) and child care benefits (37 per cent).

Other top incentives to increase employee attendance are related to the physical space offered, Capterra noted. Twenty-eight per cent said having private or isolated areas would motivate them to come more often to the office, while 27 per cent said wellness facilities like a gym would have the same effect. These spaces could serve to reduce distractions as well as support mental health in the workplace.

“Everyone is different, however,” added Anaya. “It’s important to keep the preferences of your staff at top of mind when strategizing your RTO efforts. Asking them directly via employee survey may be the best bet to ensure that the amenities your office is providing are well received by your employees.”

The post Hybrid arrangements tripled since 2022, trend far from over, says Capterra first appeared on IT World Canada.

Ontario healthcare providers now face possible fines for ‘severe’ data privacy violations

Healthcare providers covered by Ontario’s privacy law have an extra incentive to follow provincial data protection regulations: They now face administrative fines for serious violations of the provincial law.

As of Jan. 1, the Information and Privacy Commissioner of Ontario can issue penalties of up to a maximum of $50,000 for individuals and $500,000 for organizations that violate the Personal Health Information Protection Act (PHIPA).

Fines — officially called administrative monetary penalties (AMPs) — can be issued to encourage compliance with PHIPA, a statement from the commissioner’s office says. Or, it adds, penalties can be applied to prevent a person from deriving — directly or indirectly — any economic benefit from contravening the law.

“The IPC will not use AMPs as the default response to breaches,” the statement says. “They will generally only be used as an enforcement option for more severe violations of PHIPA, not in cases involving unintentional errors or one-off mistakes.”

“The IPC will take a measured approach in response to PHIPA violations, providing
education, guidance, informal resolution, and recommendations when less severe
violations occur.”

Organizations have known this was coming since 2020, when the Ontario legislature amended PHIPA to give the IPC additional enforcement powers. The new powers didn’t come into effect until Jan. 1, 2024.

Quebec is the only other province that has authorized the levying of administrative monetary penalties as part of its privacy law that covers the private sector. The federal government is currently considering Bill C-27, which would also authorize administrative penalties.

The IPC has issued guidance to organizations on how administrative penalties for healthcare providers will be applied. The commissioner also can issue binding orders requiring individuals or organizations to take specific actions to address data protection shortcomings.

In the vast majority of healthcare data breaches investigated, individuals show a genuine willingness to report, take responsibility for, and remedy errors when they occur, the guidance notes. Incidents often involve inadvertent errors, one-off contraventions with relatively minor impact, or some at-risk behaviours in need of coaching and course correction, the paper says. “In most cases, the individual or organization is highly responsive and co-operative in rectifying the situation. Education, guidance, early resolution, and recommendations for corrective measures are often the only tools the IPC needs to use in such cases.”

Under PHIPA, a health information custodian is prohibited from collecting, using, or disclosing personal health information without a patient’s consent, although under some circumstances, data can be collected indirectly.

The new powers come just as the IPC starts an investigation into the recent ransomware attack that hit five hospitals linked to a common shared IT provider. The commissioner’s office says it plans to make its findings public.

Around the world, hospitals are targets for cybercrooks looking for credit/debit card data to steal, and personal information as leverage for extortion or blackmail from hospital administrators.

For-profit hospitals are better able to fund cybersecurity than those — such as Canadian institutions — that rely on government support. Earlier this year, the Canadian Internet Registry Authority (CIRA), which oversees the .ca domain, said  “lack of focus” of management and lack of money are the biggest factors blocking the improvement of the cybersecurity of Canadian hospitals.

It’s not only hospitals that are targets. Data on 3.4 million Ontario mothers, newborns, and children collected over the past 10 years was stolen earlier this year from the MOVEit file transfer server of the provincially-funded Better Outcomes Registry & Network Ontario, also known as BORN. It was one of more than 2,000 organizations around the world victimized through a zero-day vulnerability in MOVEit Transfer.

Last year, the IPC issued 35 decisions involving complaints of alleged PHIPA violations involving physicians and hospitals. Many involved demands for access or corrections to records.

The post Ontario healthcare providers now face possible fines for ‘severe’ data privacy violations first appeared on IT World Canada.

Cyber Security Today, January 3, 2024 – Prepare for upcoming privacy legislation

Prepare for upcoming privacy legislation

Welcome to Cyber Security Today. It’s Wednesday Janaury 3rd, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



 

Happy New Year. And welcome to the first show of 2024.

This will be a busy year for privacy legislation in Canada and the U.S. In Canada committee hearings will resume this month on the proposed Consumer Privacy Protection Act and the accompanying Artificial Intelligence and Data Act. In the U.S., 10 states have consumer privacy legislation in various stages before their legislatures. In Massachusetts, legislators are dealing with three proposed bills. Here’s a link to the status of privacy legislation in all American states. Not all the proposed bills will pass and be signed into law this year. Remember, this is an election year in the U.S. Meanwhile privacy laws in Texas and Oregon will come into effect on July 1st, and in Montana on October 1st.

Cybercrooks marked the holiday week by celebrating “Leaksmas.” Researchers at Resecurity say on Christmas Eve several threat actors on the dark web dumped tens of millions of pieces of stolen data that could be used in phishing scams and fraud. The biggest chunk of data was 22 million records stolen from a telecommunications provider in Peru. The second biggest chunk involved data stolen from the U.S.

First American Title Insurance, which provides real estate title protection in the U.S., is recovering from a cyber attack last month. In its most recent post the company said several tools for title agents are back online. On December 20th the company disconnected all IT systems from the internet because of the attack. Although it doesn’t use the term ‘ransomware,’ the company says data on some non-production servers was stolen and encrypted.

Speaking of ransomware, researchers at Security Research Labs say they created a decryptor that may help victims hit by the BlackBasta strain of ransomware. However, according to the news site Bleeping Computer, the gang has fixed the bug that allowed the solution to be created so the decryptor may not work with newer attacks.

Researchers at a Singapore cybersecurity company called CloudSEK have figured out how threat actors are exploiting persistent cookies on Google’s platform. The problem is in an undocumented Google OAuth endpoint called MultiLogin. The exploit enables continuous access to Google services even after a user’s has reset their password. Word of the exploit spread after a developer publicly reported it in October and now several threat actors have included it in their information-stealing malware.

Here’s another warning to application developers looking for code to use from the NPM registry: Beware of a package named “everything” posted by a user named gdi2290. They also go by the name PatrickJS. Installing this package will create a mess of your code. Researchers at Checkmarx call this either a prank or digital mischief. Whatever the name, PatrickJS has apologized but so far the package can’t be uninstalled. Nor it be deleted from NPM.

Researchers at McAfee have identified 10 Android apps stuffed with malware. They include a so-called calorie counter, a numerology app and several games. As I’ve said before, just because an app is in the Google Play store or a well-known app store doesn’t mean its safe to download. Be suspicious of an app you take that demands access to Android’s accessibility services unless it’s really needed — and a game won’t need it. Accessibility services are for helping people with disabilities to use smartphones.

Finally, big-name digital camera manufacturers are trying to fight the risk of images being altered by mischief-makers or threat actors using artificial intelligence. PC Magazine reports that Nikon plans to start offering mirrorless cameras with digital authentication technology for professional photographers. Nikon and other camera makers are also backing a tool called Verify people can use to check the authenticity of an image with a digital signature that will show the real creation date, location and other credentials of the image.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, January 3, 2024 – Prepare for upcoming privacy legislation first appeared on IT World Canada.