Connect with us

Infosecurity

How to Adopt Performance Data in Your Security Strategy for a Safer Data Centre

Published

on

How to Adopt Performance Data in Your Security Strategy for a Safer Data Centre

In the modern data centre, security threats evolve faster than many policies can adapt. Yet, one of the most effective tools for early breach detection is already sitting in your monitoring dashboards: performance data. By integrating performance data in your security strategy, you can transform routine metrics into a powerful early warning system. This approach helps IT teams spot anomalies before they escalate into full-blown incidents.

Security breaches remain a persistent headache for IT professionals. However, standard performance metrics offer a proactive way to safeguard your environment. When you understand what “normal” looks like for your infrastructure, any deviation becomes a red flag. This article explains how to adopt performance data in your security strategy, breaking down key metrics and actionable steps.

Why Performance Data Matters for Security

Historically, data centre professionals have used baseline data primarily for availability and troubleshooting. But this data holds far more value. The main reason many data centres fail to capitalise on it is a lack of understanding which metrics apply to security. With the right approach, you can turn historical and real-time performance readings into a security asset.

Building on this, think of baselines as your security fingerprint. Every environment has unique patterns. When you establish these norms, you can quickly detect when something is off. This is the core of adopting performance data in your security strategy.

CPU and Memory Metrics

Spikes in CPU or memory usage can signal malware infections. Malicious software often consumes processing power or memory as it runs. By monitoring these metrics, you establish a standard performance level. Any sudden, unexplained jump then warrants investigation. This simple practice can catch threats early.

Network Bandwidth Utilisation

A sharp deviation in network traffic often indicates data exfiltration. For example, a sudden surge in outbound traffic could mean someone is stealing data. Traffic monitoring tools like NetFlow, sFlow, or J-Flow track data flows across your network. Familiarising your team with normal traffic patterns makes it easier to spot breaches. This is a fast, effective method for incident detection.

Data Storage Volume

Unexpected changes in data volume—whether increases or decreases—can be tell-tale signs. A sudden drop might indicate data deletion by an attacker. Conversely, a spike could mean data duplication or exfiltration. Monitoring storage metrics helps you identify these anomalies. Additionally, unexplained file movement is another red flag. Track both volume and placement to stay secure.

Building Your Security Strategy with Baselines

Performance metrics do more than just detect breaches. They can form the foundation of a comprehensive security policy. To adopt performance data in your security strategy effectively, follow these steps:

Step 1: Determine Key Metrics and Access

Collaborate with your IT department and business leaders to answer these questions:

  • What are the key data centre performance metrics to analyse?
  • Which departments have access to sensitive data?
  • What level of access is permitted (tablets, smartphones, laptops, applications)?
  • What government policies apply to your business and data handling?

Step 2: Create and Distribute the Security Policy

With this information, draft a clear security policy. Distribute it across the organisation. Ensure everyone understands their role in maintaining security.

Step 3: Establish a Maintenance Schedule

Create an adaptable security maintenance schedule. Regular reviews keep your baselines relevant as your environment changes.

Step 4: Deploy Monitoring Software

Use data centre monitoring software that alerts your team to abnormalities. Tools like SolarWinds Network Performance Monitor can help. Set thresholds based on your performance baselines.

Step 5: Implement Security Procedures

After baselines are determined, implement security procedures on the network and within the data centre. This allows you to evaluate the effects of new measures accurately.

Step 6: Develop Response Plans

Produce fixed response procedures for when abnormalities are detected. Ensure all team leads are familiar with these plans. For more on incident response, check out our guide on building an incident response plan.

Step 7: Train Employees

Train all employees on security policies. Consider running drills to practice responses. This builds muscle memory and refines your approach.

Step 8: Review Baselines Regularly

Review performance baselines with at least one week’s worth of data to maintain validity. This ensures your security strategy stays effective.

Conclusion: Leverage What You Already Have

Adopting performance data in your security strategy doesn’t require expensive new tools. Often, you can use the monitoring system already in place in your data centre. The most successful IT projects recycle existing resources for new purposes. With a disciplined approach, baseline monitoring becomes a cornerstone of your security posture. It empowers your team to develop and execute predetermined response plans when anomalies occur. Start today by reviewing your current metrics and building your baseline. For additional insights, read our article on data centre security best practices.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

UK Fraud Cases Hit Record High in 2026: What’s Driving the Surge?

Published

on

UK fraud cases

UK Fraud Cases Hit Record High in 2026: The Numbers

Fraud in the UK has never been this rampant. Over 220,000 cases were filed with the National Fraud Database (NFD) between January and June — the highest number ever recorded in the first half of a year, according to Cifas. That’s a sobering statistic for consumers and businesses alike.

The non-profit, which runs the NFD and the Insider Threat Database, reports that identity fraud alone rose 9% year-on-year to nearly 130,000 cases. This surge is largely driven by scammers targeting bank accounts and plastic cards, which account for 68% of all identity fraud cases. Impersonation incidents using the victim’s real address also jumped 12% YoY.

While “false identity” filings dropped 35% YoY, mainly in banking and telecoms, the report warns that “intelligence continues to indicate growing concerns around synthetic identities, AI-enabled impersonation and digitally manipulated documentation.”

Account Takeover and SIM Swap Fraud on the Rise

Account takeover cases are another major driver of UK fraud in 2026. Cifas recorded nearly 40,000 such cases, a 5% YoY increase. Online retail incidents soared 84%, and card account cases rose 59%. But the most alarming trend is unauthorized SIM-swap fraud, which skyrocketed 402% to 4,109 incidents — now representing 10% of all filings, up from just 2% a year ago.

This explosion in SIM swapping highlights how criminals exploit mobile networks to bypass two-factor authentication and drain accounts. If you’re not aware of this tactic, it’s worth understanding: fraudsters convince mobile carriers to transfer your number to a SIM they control, then use it to reset passwords and access your financial accounts.

Young Adults: Both Victims and Perpetrators

Identity fraud victims are getting younger. While the 61-and-over age group still accounts for the most cases, the biggest increase came in the 21-30 age bracket, where cases rose by almost a third (32%).

But here’s the twist: people under 30 also represent a majority (57%) of money muling cases, with 17% under 21. Money muling — where individuals let their bank accounts be used to transfer stolen funds — increased 69% annually, with over 13,000 filings. Mule activity now accounts for 30% of all cases of misuse of facility.

Part of this increase stems from better detection and a new filing reason introduced in 2025: “funds received – money muling.” Still, the figures suggest a worrying trend of young people being recruited into fraud networks, often through social media “job ads” that promise easy money.

Why Is Money Muling Growing?

Cifas CEO Mike Haley points out that identity fraud now accounts for three-fifths of all NFD cases, highlighting the value of personal information to scammers. “Whether it is used to open accounts, take over existing facilities or support wider criminal activity, stolen personal data often provides the entry point,” he said.

He also stressed the importance of early intervention: “As criminals continue to evolve their tactics and use digital channels to reach new audiences, education, awareness and prevention remain — particularly for younger people who are increasingly exposed to fraud risks.”

What This Means for Consumers and Businesses

The takeaway is clear: UK fraud is not slowing down. If you’re a consumer, protect your personal data like it’s gold — because to fraudsters, it is. Use unique passwords, enable multi-factor authentication (but be wary of SIM-swap risks), and monitor your bank statements regularly.

For businesses, the rise in account takeover and identity fraud means investing in robust verification systems is no longer optional. Consider biometric checks, device fingerprinting, and real-time fraud monitoring. For more on protecting yourself, check out our guide on how to prevent identity theft and tips for spotting phishing scams.

Looking Ahead: The Future of Fraud Prevention

Cifas’s data paints a grim picture, but it also underscores the importance of vigilance. As AI-enabled impersonation and synthetic identities become more sophisticated, both consumers and institutions must adapt. The record numbers in 2026 are a wake-up call — fraud prevention can’t be an afterthought anymore.

Stay informed, stay skeptical, and remember: if an offer seems too good to be true, it probably is. The fight against fraud starts with awareness.

Continue Reading

Infosecurity

Defense Contractors Report Record-High CMMC Scores — And Admit They Don’t Trust Them

Published

on

CMMC self-assessment accuracy

Record-High Scores, Record-Low Trust

Defense contractors are reporting their best-ever cybersecurity scores under the Pentagon’s CMMC program. They just don’t believe the numbers themselves.

The CyberSheath 2026 State of the DIB Report, released August 20, found the average Supplier Performance Risk System (SPRS) score jumped to +51 — a five-year high, up from +33 in 2025. That was already the first positive score in the report’s history.

SPRS is the self-assessment tool defense contractors use to gauge their cybersecurity maturity under the Cybersecurity Maturity Model Certification (CMMC), the DoD program that governs how companies protect federal contract information and controlled unclassified information.

But here’s the catch: confidence in those scores cratered. Only 65% of contractors said they were extremely or very confident their score was accurate. A year ago, that figure was 89%. In 2024, it was 94%.

That’s a 24-point drop — and it’s the starkest finding in the entire report.

Why Contractors Doubt Their Own SPRS Scores

David M. Schneer, CEO of Merrill Research, which conducted the survey of 302 defense contractors, called the disconnect between rising scores and falling confidence “the most striking finding this year.”

“Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially,” Schneer said. “That tension suggests that measuring progress requires looking beyond the reported score itself.”

The timing isn’t a coincidence. In July 2026, the Trump administration suspended CMMC Phase II, which would have introduced independent verification by Certified Third-Party Assessment Organizations (C3PAOs). Originally set to take effect November 10, 2026, that phase is now on hold.

Without external checks, contractors are left to grade their own homework — and they know it.

Only 1% Feel Fully Prepared

Just 1% of contractors believe they’re completely ready for CMMC certification. That number hasn’t budged since a previous CyberSheath study in October 2025.

So while scores are climbing, actual readiness isn’t. The two metrics are telling different stories.

Money Isn’t the Main Problem

The bottleneck isn’t budget — at least not in the way you’d expect.

  • 53% of respondents said their cybersecurity budgets felt “just right”
  • 24% said they had more than enough
  • Average DFARS compliance spending rose to $155,204 annually

DFARS, the Defense Federal Acquisition Regulation Supplement, is the rulebook that makes CMMC a binding legal requirement for DoD contracts. Contractors assess themselves against 110 security controls from NIST SP 800-171, with a perfect score of 110.

The CyberSheath report argues the real challenge isn’t how much contractors spend, but “how effectively those investments translate into implemented, sustainable and verifiable security.”

Contractors Want Reform — But Not Deregulation

Here’s the twist: even as they struggle with compliance, contractors aren’t asking to ditch the rules.

90% of respondents still support a legal mandate for minimum cybersecurity standards. 77% said DFARS compliance meaningfully improves national security.

What they want is a better path to get there:

  • 74% want easier implementation processes
  • 70% want more vendor options to support compliance

And 52% fear losing contracts due to non-compliance. That fear is real, but it hasn’t soured them on the program’s purpose.

What’s Next for CMMC?

Emil Sayegh, CEO of CyberSheath, points out that most DIB contractors are manufacturers, engineers, and specialized businesses “whose mission is supporting the warfighter, not becoming cybersecurity experts.”

His ask to the federal administration: reform CMMC to “make effective cybersecurity easier to consume while preserving objective, verifiable assurance that the protections are actually in place and working.”

The report’s bottom line is a warning wrapped in a suggestion. Self-reported scores are rising, but if contractors themselves don’t trust them, the numbers are close to meaningless. When CMMC Phase II eventually resumes — and most observers think it will — the C3PAO verification process will be the real test.

Until then, the DIB is flying on instruments it knows are miscalibrated.

Continue Reading

Infosecurity

China and India ran separate spying campaigns against the same Pakistani police force

Published

on

Pakistani police spying

Two rivals, one target: Balochistan Police

For more than two years, hacking groups tied to China and India ran separate, unconnected espionage operations against the same Pakistani police force. Sometimes they even broke into the exact same systems.

That’s the finding from cybersecurity firm SentinelOne, which published research Thursday detailing the parallel campaigns. The activity ran between February 2024 and April 2026, according to the company’s SentinelLabs research arm.

The target: the Balochistan Police, the force responsible for Pakistan’s southwestern province. That region has been the site of a long-running separatist insurgency, making its police networks a rich prize for intelligence agencies.

Why police networks are such a tempting target

Police networks concentrate a government’s internal-security data in one place. That’s the core insight from SentinelLabs. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registrations linked to national identity records, and citizen complaints.

Think about what that means. Anyone with access to those systems could identify police officers, track their movements, and potentially compromise them. They could also monitor the local population in a province already simmering with unrest.

The China connection: protecting CPEC interests

The researchers assess that the China-nexus interest was driven primarily by protecting Beijing’s nationals in Pakistan tied to the China-Pakistan Economic Corridor. That’s the massive infrastructure project that’s a cornerstone of Chinese influence in the region.

The report cites a March 2024 suicide bombing and an October 2024 attack near Karachi’s airport as incidents affecting Chinese workers. Those attacks highlighted the security risks facing Chinese nationals in Pakistan.

According to SentinelLabs, the intrusions reflect an effort to assess the threat independently rather than rely on Pakistani security guarantees. In other words, Beijing wanted its own picture of the danger, not just Islamabad’s assurances.

The India angle: rivalry and insurgency

The India-linked activity was likely tied to the rivalry between the two countries, the report assessed. That’s a fraught relationship, to say the least.

Islamabad accuses New Delhi of backing the Baloch insurgency and describes the Balochistan Liberation Army as an “Indian proxy.” India makes parallel accusations over Kashmir. Both governments deny the other’s claims.

SentinelLabs said access to Balochistan Police data would provide visibility into that conflict. For India, that could mean insight into insurgent activities and Pakistan’s counterinsurgency efforts.

How the hacks worked

The report describes the compromise of the Balochistan Police Complaint Management System, a portal used by officers behind a login and by citizens checking the status of complaints.

Here’s where it gets clever. A China-linked operator planted malware disguised as a portal update. The executable displayed a fake “update complete” message while infecting the visitor’s device.

Because both police and members of the public use the site, the tampered portal exposed both groups. That’s a wide net, catching everyone from officers to ordinary citizens filing complaints.

The researchers said forensic traces in the code, including Chinese-language log strings and developer artifacts, indicated a Chinese-speaking author. That’s a pretty strong signal.

Attribution: clusters, not names

Rather than name specific groups, SentinelLabs sorted the activity into clusters by toolset. That’s a more cautious approach than some firms take.

Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments. The victim pattern also spanned Asian governments and, in one case, Tibetan organizations in Taiwan.

The India-nexus intrusions were tied with lower confidence to an actor the researchers track as TAG-179. That overlaps with clusters others call Bitter and Mysterious Elephant. Part of the evidence: a lure document themed around the repatriation of undocumented foreigners.

The bigger picture: Pakistan’s digitization push

The researchers noted that as Pakistan centralizes and digitizes its policing, supported in part by European modernization programs, it will continue to concentrate high-value data that adversaries may target.

That’s a worrying trend. The more data gets digitized and centralized, the bigger the prize for hackers. And with two nuclear-armed rivals both running espionage campaigns, the stakes are enormous.

Both Pakistan and India are alleged to have conducted cyber espionage campaigns against each other, with attacks targeting Indian government, academic and strategic institutions, as well as Pakistani government agencies and critical infrastructure operators. This latest report shows that the espionage isn’t just about governments — it’s about police forces on the front lines of internal security.

For anyone tracking cyber espionage in South Asia, this is a significant development. It shows that even a provincial police force isn’t off-limits when national rivals are involved.

Continue Reading

Trending