Marriott International has approved a $52 million FTC settlement to conclude an investigation into over half a decade of data breaches that rocked the hotel franchise.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Kia Motors America suffered a suspected DoppelPaymer ransomware attack that shut down internal and customer-facing systems. Hackers demanded 404 Bitcoins worth about $20 million.
As an SMB, what can you do to prevent cybersecurity attacks and safeguard your data and critical assets? Hint: Give your data privacy and information security practices a check-up. Get your ISO 27001 certification.
According to Moody’s report, organizations tend to have upped their cybersecurity investments across the board, but with a strong preference for basic measures and cyber insurance.
The true essence of Zero Trust lies in embracing a process-centric approach rather than relying solely on products. CISA has established a set of maturity pillars that guide organizations in their journey toward zero trust. Understanding these pillars is essential for CISOs and CPOs looking to build a robust security framework.
Automation is no longer an office-only reality. How can we ensure security when inviting automation into our homes? Should we be auditing smart home technology in the same way we audit our office automation?
A new study from Chainalysis finds that crypto crimes are proving more lucrative than ever for organized criminal gangs, but that illicit activity overall only saw a slight raise from its record low levels in 2021.
Facebook Messenger phishing campaign targeted millions of business accounts using fake and hijacked personal accounts to trick business owners into installing an infostealer that harvests passwords and cookies before locking them out.
A new source of cyber risk and attack may come from posting instructions that include a ZIP or MOV file name, with that text automatically converted into a URL leading to one of these new top-level domains.
AI agents will change how SOCs work, but they won’t save a broken data foundation. If your telemetry is siloed, your schemas are inconsistent, or your context is missing, you’ll automate noise, not insight.










