WEF's newly-released principles for board governance of cybersecurity offer a base of best practices for dealing with increasing cyber risk, with a new element being an emphasis on an organization-wide focus.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
2K Games accounts used for online games may have received unexpected messages from the helpdesk system claiming to be a response to a request. The messages look authentic, but conclude with a link to RedLine malware.
Choosing whether to pay ransom isn’t a moral or ethical decision. It is always a business decision based on risk reduction and protecting the interests of an organization’s customers, employees and key stakeholders.
Preparing for a ransomware attack is by far the most effective way of minimizing the risk of becoming a victim. Herer are steps that can help tip the balance of power against potential attackers:
The Office of the Attorney General of New York has recorded 1.1 million compromised accounts. The stolen logins were put to use in credential stuffing attacks against a variety of "well-known" online retail, food and delivery businesses.
UN data breach appears to stem from an employee login that was sold on the dark web. The attackers used this entry point to move farther into the organization's networks and conducted reconnaissance between April and August.
As our vehicles become increasingly smarter and an extension of our mobile phones, users' security and privacy is being threatened by car hacking. Luckily, there are relatively simple measures you can take to protect your vehicle data, safety and security.
Distributed applications across multi-cloud and edge environments are emerging quickly, what are the three key issues that need to be addressed in order to secure them?
Account takeover fraud is on the rise, and businesses and banks are bearing the costs. Because ATO fraud looks like activity by a trusted customer, detection can be difficult – but it is possible. Here's what businesses need to know to fight takeover attacks without declining good orders.
Recent cyber attacks that have done damage to critical infrastructure could be a pretext for a "real shooting war," according to Joe Biden, as the president addressed the growing threats to national security in the cyber sphere.










