Top European football clubs find themselves in the relegation zone for cybersecurity
Football and cyber security don’t often get mentioned in the same sentence, but with billions of pounds invested into the richest football leagues in the world, and football clubs possessing vast swathes of data, their valuation can be massively impacted following a data breach. Everything from sponsorship deals, personal player data, youth teams training plans, health and performance statistics, salaries of players and all club staff through to fan members’ personally identifiable information, the impact of a breach could be devastating for the club both financially and reputationally.
What do the standings look like?
SecureScorecard recently conducted research on three of the richest football leagues in Europe*, the English Premier League, German Bundesliga and Spain’s La Liga, assessing their security posture and comparing it to their football standing. To do this we looked closely at ten elements of the league’s security posture. These include: network security; DNS health; patching cadence; endpoint security; IP reputation; web application security; cubit score; hacker chatter; leaked credentials; social engineering.
Through doing so, we revealed an inverse relationship between the success of teams in sport, their digital exposure and resulting cyber risk. By analysing each team’s external digital footprint, we discovered that the top teams across the three leagues all find themselves languishing at the bottom of their respective tables as the larger the digital footprint, the lower their cyber risk score is. At the other end of the table, those teams with a smaller digital footprint find themselves topping the table and are ultimately viewed as being more secure.
Overall, Bundesliga came out on top in terms of security, being awarded with an ‘A’, which is impressive considering it actually has 3x the digital footprint exposure of the Premier League. La Liga’s digital footprint is the smallest. Nevertheless, across all three leagues the most common security issues were weak encryption and web application issues, followed by high severity patching issues and susceptibility to email spoofing.
Surprisingly, we also discovered that only one team in the Premier League would currently meet the requirements of GDPR and be classed as compliant, whilst none of the teams in either the Bundesliga or La Liga meet the legislation
The ongoing challenge
The biggest challenge still facing organisations, whether they are a football club or a financial institution, is the disconnect between the board level executives and the IT teams. With no common language for companies and their partners to communicate, understand, and improve their cyber security and cyber risk posture, we will forever be at this impasse. To develop the enterprise risk framework which all parties can understand when discussing cyber security and risk, there are three basic points that need to be considered:
- Build cyber security into the Enterprise Risk Frameworks and Regulatory Compliance
- Establish metrics to demonstrate program maturity and comparative benchmarking
- Build your business case around people, processes and technology to demonstrate ROI
A final note
Football is not just about the camaraderie of the players and turning up to play on match days. It is very much a business with multi-billion-pound deals and reputations on the line, all of which come under fire if they suffer a data breach. We’ve already seen FIFA and teams like West Ham, Real Madrid and Barcelona falling victim to breaches or their social media profiles being hacked. Overall, the findings show that being in the Champions League in sport does not mean football teams are Champions League level for cybersecurity. But it is also important to note that just like sport standings change every day, so do cyber standings.
Industry: Cyber Security News
- CIAM Architect Azure B2C
We are seeking a highly skilled and experienced Azure B2C CIAM Architect for a contract starting on Jan 2024. As an Azure B2C CIAM Architect, you will be responsible for designing, implementing, and deploying an new Azure B2C Solution . Responsibilities: Design and implement an Azure B2C-based CIAM solution that meets the needs of our clients organization. Maintain and support the Azure B2C-based CIAM solution. Provide training and support to our employees on the use of the CIAM solution. Background designing, implementing, and maintaining CIAM solutions. Experience with cloud-based identity and access management (IAM) solutions. Experience with OAuth, OpenID Connect,and SAML. Excellent written and verbal communication skills
- Senior IAM Consultant
- Upto €110,000 depending on level of position
Senior IAM Consultant is needed to help lead and deploy IAM Projects for this expand IAM Consultancy The ideal candidate will have a deep understanding of IAM concepts and technologies, as well as experience in deploying and managing complex IAM solutions. Responsibilities Lead the deployment of IAM solutions for our clients Work with clients to understand their IAM requirements and design solutions that meet their needs Configure and implement IAM solutions using best practices Integrate IAM solutions with other enterprise systems Provide training and support to clients on the use of IAM solutions Stay up-to-date on the latest IAM technologies and trends We are looking for an experieneced IAM Consutlatn with: Strong understanding of IAM concepts and technologies,including identity lifecycle management,access control,and authentication Experience in deploying and managing complex IAM solutions Experience with IAM products and solutions,such as SailPoint,One Identity Manager,and Azure Active Directory Excellent communication and interpersonal skills Ability to work independently and as part of a team Fluent in German Candidates witll need to live and have the right to work within Germany to be considered.
- Security Architect - SOC Design - Outside IR35 London. SC / DV cleared
- Outside IR35
Security Architect - With in-depth SOC Design experience needed for Outside IR35 London. SC / DV cleared. 6 month rolling Immediate Experience delivering technical Security Architecture design / assurance of security design with mobile network experience. HLD / LLD Current SC Clearance a must. Willingness to undertake DV. London 3 days a week Immediately interviewing.
- Cyber Security Risk Consultant. UK. Hybrid. Home | Work balance
- United Kingdom
Cyber Security Consultancy - done the right way. Seeking a passionate Cyber Security Risk Consultant who enjoys helping clients make a different to their business. Warning- if you want a large, slow moving, high politics, high travel security consultancy that demands their a pound of flesh this is NOT for you. A successful individual will have experience working with clients to identify business cyber security risk. This is a remote first opportunity which means you will spend the majority of your time working remotely. You will however spend some time meeting clients as well as meeting up with the team on a monthly basis.. Some of the nice to have certifications. CRISC, ISO27001 Lead implementer, CISA, CISM, CISSP Along with dedicated training budgets, unlimited holiday and a structured career path, this opportunity will give a much needed work life balance. Unable to offer Visa sponsorship now or in the future. Apply and book a call in my diary with the below