There’s a cybersecurity workforce gap. Adopt the Ted Lasso approach and shift from focusing on hiring security specialists to instead recruiting leaders and coaches to help bridge the DevSecOps divide that keeps development and security from seeing eye to eye.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The infamous attack on Hugging Face has been traced back to a hidden message board that was created by OpenAI agents, one that about 1,200 found their way to and eventually used to plan and coordinate their actions.
Security incidents happen; that’s just reality. But how a company decides to handle an event says more about their values and priorities than their product. The recent Okta compromise reminds us of the damage inflicted when there is a lack of transparency between a security vendor and its customers.
There is more to pandemic burnout than just wanting the world to go back to the way that it used to be. Pandemic burnout is directly contributing to a variety of cybersecurity problems.
New 4iQ report indicates that data breaches were up by over 420% from 2017, exposing a total of almost 15 billion identity records. Small businesses are being targeted much more frequently than previously thought and that even relatively tiny businesses are now on the menu for sophisticated hackers.
The increasing reliance on third parties brings with it potential risks that must be identified and remediated across the supplier’s relationship lifecycle. AI can help procurement teams evaluate business risks far more quickly by identifying and prioritizing those risks.
After the breach of Kaseya and thousands of clients downstream from it by REvil ransomware, the perpetrators disappeared abruptly but Kaseya appears to have received a decryption key nearly three weeks into the attack.
With many security communities providing information sharing, how should cybersecurity professionals in the healthcare industry choose to ensure their community time is well-spent?
Why do we, in 2021, far too often still see security not being baked into all aspects of the software development lifecycle and instead added as some kind of tack-on component way down the line?
Daily fantasy sports and gambling platform DraftKings has confirmed that numerous user accounts were compromised following a series of credential stuffing attacks.










