There is an increasing overlap of cyber and physical security breaches, crime and espionage. Cybercriminals slip between the gaps of those tasked with physical, information and cyber security, as they often do not coordinate their activities and see their realms as completely separate.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Ransomware attackers have ambitiously expanded their operations in the past year. Innovation continues as the Ragnar Locker Team is using Facebook Ads to pressure victims into paying up.
A ransomware attack has struck the New York Blood Center, disrupting collection and distribution across 200 hospitals across the Northeast, amid ongoing shortages.
Several New Zealand government agencies were impacted by a ransomware attack on Mercury IT, a 25-employee firm that serves dozens of public and private organizations in the country. New Zealand’s Ministry of Justice and Health New Zealand (Te Whatu Ora) have confirmed being impacted by the cyber incident.
Symantec warned that a Chinese state-sponsored cyber espionage group responsible for hacking a U.S. state legislature and potentially a defense company had renewed interest in the country.
A stronger IoT security posture is critical with a recent Kaspersky report showing a nine-time increase of attacks on IoT devices in the first half of 2019 compared to the first half of 2018.
A zero-trust framework is essential but is not enough. It needs to be part of a comprehensive cybersecurity solution that is a match for increasingly courageous, sophisticated threat actors.
Molson Coors filed a security incident with the Security and Exchange Commission acknowledging a cyber attack that took its systems offline, suggesting a ransomware attack.
Recent data breaches at Under Armour and Panera Bread has been making headlines. But the approach taken to mitigate the threat to consumers could not have been more different. One is a lesson on best practice and the other is a cautionary tale on how not to handle malicious attacks aimed at seizing consumer data.
Payment card services provider American Express has notified authorities and customers of a third-party breach affecting a merchant processor that leaked payment card information.










