
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
A comprehensive security and privacy compliance framework for high-risk biometric surveillance systems (CCTV, Facial Recognition Technology, and centralised contact tracing), including comparative framework analysis (ISO 27001, Cyber Essentials, NIST CSF 2.0, COBIT) and a detailed incident response case study analyzing the 2025 Oracle E-Business Suite CVE-2025-61882 breach.
This assignment addresses critical challenges in deploying high-risk biometric surveillance systems while maintaining compliance with UK GDPR, implementing layered security controls, and establishing robust incident response capabilities.
Proposed Solution Components:
Key Challenges:
Data Protection by Design and Default must be treated as an engineering and governance requirement, not a "compliance afterthought". For systems combining CCTV, FRT, and centralised contact tracing, DPbD must be:
Privacy-Aware Secure Development Lifecycle (SDLC)
1. By Design (Integrate throughout processing)
2. By Default (Only necessary data)
3. Data Minimisation
4. Purpose Limitation & Anti-Function Creep
5. Pseudonymisation & PETs
6. Transparency & User Control
7. Access Limitation (Least Privilege)
8. Integrity & Confidentiality
9. Storage Limitation
10. DPIA as Living Control
UK GDPR is principles-led, requiring organizations to demonstrate:
Security and governance frameworks help convert GDPR's high-level obligations into actionable controls, but they do not replace GDPR compliance.
ISO/IEC 27001
Cyber Essentials
NIST CSF 2.0
COBIT 2019
Recommended Approach:
GDPR (+ DPbD) as compliance "north star"
ISO/IEC 27001 as assurance backbone
NIST CSF 2.0 as operational security roadmap
Cyber Essentials as baseline control set
COBIT as governance overlay
Key Principle: GDPR defines what must be protected and why, while frameworks define how protection is executed, measured, and evidenced.
Defense-in-Depth Model across:
1. Identity & Access Management
2. Data Protection
3. Network Segmentation
4. System Hardening
5. Real-Time Threat Detection
6. Forensic Readiness
Aligned to NIST SP 800-61 & ISO/IEC 27035
Lifecycle Phases:
Preparation
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
Article 33 UK GDPR: Controller must notify supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of notifiable breach.
Article 34 UK GDPR: If breach likely to result in high risk to individuals' rights and freedoms, communicate to affected individuals without undue delay.
Required Capabilities:
Campaign Name: CL0P-branded extortion campaign
Target: Organizations running on-premises Oracle E-Business Suite (EBS)
Vulnerability: CVE-2025-61882 (Critical zero-day)
Attack Type: Data theft for extortion (non-ransomware)
CVE-2025-61882 Characteristics:
Why This is Dangerous:
Primary Impact: Confidentiality loss through mass data exfiltration
Impact Categories:
Operational Disruption & Recovery
Regulatory & Legal Exposure
Direct Financial Loss
Reputational Damage
Example Victim: Korean Air's catering/duty-free unit
Campaign Characterization: Data-theft extortion via mass exploitation (not traditional ransomware)
1. Initial Access
2. Social Engineering Amplification
3. Execution & Persistence
XDO_TEMPLATES_B and XDO_LOBS4. Discovery, Collection & Exfiltration
Three Systemic Failures:
Attack Surface Exposure
Patch Latency & Version Lifecycle Risk
Detection Gaps
1. Emergency Patching + Exposure Reduction (PREVENT)
Actions:
Framework Mapping: ISO 27001 (change/patch governance); NIST CSF (Protect)
Evidence: Oracle security alert, NHS England assessment
2. Compromise Hunting & Eradication (ASSUME BREACH)
Actions:
XDO_* table anomaliesFramework Mapping: NIST CSF (Detect/Respond); ISO 27001 (logging/monitoring, incident management)
Evidence: Mandiant guidance on database-resident payloads
3. Least Privilege, Segmentation & Credential Hardening (LIMIT BLAST RADIUS)
Actions:
Framework Mapping: Cyber Essentials (access control, secure config); ISO 27001 (access control); NIST CSF (Protect)
4. Telemetry & Detection Engineering (REDUCE DWELL TIME)
Actions:
Framework Mapping: NIST CSF (Detect); COBIT (KPIs/KRIs oversight)
5. Governance Controls for Extortion Pressure (MANAGE CRISIS)
Actions:
Framework Mapping: COBIT (governance objectives); NIST CSF (Govern/Respond)
Effectiveness: Prevents rushed, uninformed decisions under pressure
Model: Likelihood (1-5) × Impact (1-5) = Risk Score
Risk Categories:
Top Priority (Critical Risks)
Close Initial Access Path
Assume Compromise & Eradicate Persistence
Lock Down Privilege & Stop Bulk Theft
Harden Governance & Response Readiness
Secondary Priority (High Risks)
Reduce Blast Radius
Improve Detection
Enhance Resilience
Supplier Assurance
This risk treatment approach directly supports:
Comprehensive table mapping:
Detailed analysis of:
Against UK GDPR principles:
Recommendations for:
Complete lifecycle aligned to:
Including:
Comprehensive study covering:
Module: SEC7000 - Information Security
Institution: Cardiff Metropolitan University
School: Cardiff School of Technologies
Program: MSc Advanced Cyber Security
Academic Year: 2025/2026, Term 1
Module Leader: Dr Liqaa Nawaf
Data Protection by Design & Default
Framework Integration
Security Implementation
Incident Response
Real-World Application
Immersive Labs Modules Completed:
Skills Gained:
UK GDPR & Data Protection:
Security Frameworks:
Incident Response:
Threat Intelligence:
Vulnerability Databases:
Sid Ali Bendris
Student ID: 20238021
MSc Advanced Cyber Security
Cardiff Metropolitan University
Cardiff School of Technologies
Module Leader: Dr Liqaa Nawaf
This project is developed for academic purposes as part of the MSc Advanced Cyber Security program at Cardiff Metropolitan University.
Project Status: Completed Academic Assessment
Submission Date: Term 1, Academic Year 2025/2026
Assessment Type: Written Assignment (Individual)
Word Count: Compliant with module requirements
Key Themes: Data Protection, GDPR Compliance, Biometric Surveillance, Incident Response, Risk Management, Security Frameworks, Breach Analysis
| Phase | DPbD Requirements | Controls | Evidence |
|---|
| Requirements | Define purposes, lawful basis, special category processing | Purpose statements, DPIA initiation | DPIA document, legal basis assessment |
| Design | Defaults enforce data minimisation, purpose limitation | Camera zoning/masking, restricted FRT triggers, separated data flows | Architecture diagrams, privacy test cases |
| Build & Test | Privacy/security as testable requirements | RBAC with least privilege, MFA, encryption, immutable logs | Test results, security configs |
| Operations | Continuous monitoring, vendor assurance, change control | Access reviews, retention enforcement, anti-function creep controls | Audit logs, governance KPIs |
| GDPR Principle | ISO/IEC 27001 | Cyber Essentials | NIST CSF 2.0 | COBIT 2019 |
|---|
| Lawfulness, fairness, transparency | Partial (governance, policies) | Limited | Partial ("Govern") | Partial (governance) |
| Purpose limitation | Partial (scope, change control) | Limited | Partial ("Govern/Identify") | Strong (prevents function creep) |
| Data minimisation | Partial (risk-based design) | Limited | Partial (inventory, risk controls) | Partial (enforces decisions) |
| Accuracy | Partial (quality management) | Limited | Partial (monitoring) | Partial (metrics, assurance) |
| Storage limitation | Strong (retention, deletion, audit) | Limited | Partial ("Protect/Recover") | Partial (KPIs, audits) |
| Integrity & confidentiality | Strong (security controls) | Strong (baseline) | Strong (Protect/Detect/Respond) | Strong (governance) |
| Accountability | Strong (ISMS, documentation) | Partial (evidence baseline) | Strong ("Govern" function) | Strong (decision rights, KPIs) |
| GDPR Obligation | Why Frameworks Don't Cover It | Required GDPR-Specific Controls |
|---|
| Lawful basis + special category conditions | Frameworks don't determine legal basis | Document lawful basis, special category condition, alternatives/opt-out, records |
| Necessity & proportionality | Focus on "how to secure", not "should we do this" | Necessity assessment, strict purpose statements, approval gates, re-justification |
| DPIA lifecycle | Not a security standard requirement | DPIA pre-deployment, updates on change, DPO input, escalation process |
| Transparency | Don't specify notice content or signage | Layered privacy notices, CCTV/FRT signage, rights messaging |
| Individual rights | Don't define DSAR workflows | DSAR process, identity verification, retrieval/redaction, erasure handling |
| Fairness/accuracy in FRT | Don't require bias testing | Accuracy thresholds, bias testing, human-in-the-loop, error escalation |
| Data minimisation by default | Don't impose "minimum necessary" as legal default | Default minimised collection/retention/access, design constraints |
| Breach reporting | Cover incident response, not GDPR thresholds | Breach assessment workflow, 72-hour notification process, evidence pack |
| Severity | Typical Triggers | Immediate Actions | Escalation | External Reporting | Timeline |
|---|
| SEV 1 Critical | Confirmed exfiltration of tracing DB/biometric templates; ransomware; active unauthorized admin access | Activate IR; isolate systems; disable accounts; preserve evidence | CISO, DPO, Legal, Senior leadership, Comms | ICO notification if personal data breach threshold met (≤72 hrs) | 0-1hr: containment; <4hrs: exec engagement; <24hrs: risk assessment |
| SEV 2 High | Large-scale unauthorized access; privileged credential compromise; suspected data export | Contain; rotate keys; force MFA reset; forensic triage | DPO, Legal, Business owner, Comms | Likely ICO notification depending on risk | 0-2hrs: lockdown; <8hrs: forensics; <24hrs: regulator pack |
| SEV 3 Medium | Malware on single endpoint; minor misconfiguration; suspicious access attempts | Fix, patch, verify logs | Security manager, DPO if data exposure possible | Usually not reportable unless threshold met | Same day: remediate; <48hrs: lessons learned |
| SEV 4 Low | Port scan; blocked brute-force; phishing reported; minor outage | Triage, record, tune controls | IT security if pattern repeats | No external reporting | <24hrs: close ticket; weekly/monthly trend review |
| SEV 5 Informational | Benign alerts, false positives | Document outcome | None unless emerging risk | None | As needed |
| Date | Event |
|---|
| July-Aug 2025 | Suspicious activity observed; exploitation assessed as early as 9 Aug 2025 |
| 29 Sep 2025 | Multiple organizations receive extortion emails claiming EBS compromise |
| Early Oct 2025 | Security vendors and national agencies issue alerts |
| Oct 2025 | Oracle publishes security alert identifying CVE-2025-61882 |
| Oct-Nov 2025 | CL0P leak site expands; dozens of alleged victims; significant datasets exposed |
| Asset Type | Threat Scenario | Key Vulnerability | L | I | Score | Targeted Mitigation |
|---|
| Internet-facing Oracle EBS | Pre-auth RCE via CVE-2025-61882 | Internet exposure + patch latency | 5 | 5 | 25 Critical | Emergency patching, remove direct exposure, WAF/allowlisting, upgrade EOL versions |
| EBS database + BI Publisher templates | Payload persistence in DB tables | Insufficient DB auditing, weak integrity monitoring | 4 | 5 | 20 Critical | Threat hunting per Mandiant; DB audit logging; integrity checks; restrict template authoring |
| Privileged identities (admins, DBAs) | Privilege misuse for data export | Excess privilege, weak MFA/PAM, shared accounts | 4 | 5 | 20 Critical | PAM + MFA; least privilege; break-glass controls; rotate secrets/keys |
| Sensitive data stores (HR/finance/PII) | Mass theft for extortion | Over-broad access, weak segmentation, weak DLP | 4 | 5 | 20 Critical | Data classification; DLP; segmented access; encryption; query/export controls; bulk access monitoring |
| Network segmentation & perimeter | Pivot from EBS to internal systems | Flat network, permissive east-west traffic | 3 | 5 | 15 High | Zero Trust access; micro-segmentation; restrict DB/admin ports; egress controls |
| Logging/SIEM & detection | Long dwell time / stealthy theft | Missing app-aware telemetry | 3 | 4 | 12 High | Centralise EBS/DB logs; alert on anomalous template creation, bulk exports, suspicious admin activity |
| Patch & vulnerability management | Repeat exposure to future zero-days | Incomplete asset inventory, slow emergency patching | 4 | 4 | 16 Critical | Patch SLAs by severity; asset ownership; continuous scanning; emergency change process |
| Admin endpoints / jump hosts | Credential theft → privileged access | Weak hardening, local admin rights | 3 | 4 | 12 High | Hardened jump hosts; EDR; block credential dumping; remove local admin; device posture checks |
| Backups & recovery systems | Secondary ransomware/extortion | Untested restores, backup exposure | 3 | 4 | 12 High | Immutable backups; offline copies; regular restore testing; separate backup credentials |
| Third parties (EBS support, hosting) | Supply-chain access or delayed patching | Unclear shared responsibilities, weak assurance | 3 | 4 | 12 High | Contractual security clauses; patch responsibility matrix; vendor assurance reviews; audit rights |