New NIST Privacy Framework together with its existing Cybersecurity Framework provide a road map on cyber industry security, data handling standards and best practices for organizations.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Citizen Lab reports that the new Pegasus spyware zero-click zero-day impacts the most recent version of iOS (16.6) and likely prior versions dating back to the iPhone 8. As with the prior Pegasus attack vector, victims only need to receive a iMessage to be compromised; they do not need to open the message or interact with it.
In a recent Pew research study where thousands of Americans were asked 10 questions related to digital security and privacy, majority could not even answer half of the questions correctly.
Insurance giant Marsh & McLennan is leading a “Cyber Catalyst” program involving top cyber insurance companies to provide seal of approval for top-rated cybersecurity products. How will this impact consumers and the cyber insurance industry?
Qantas has announced a new compensation policy that reduces executive bonuses for the CEO and their team when damaging cybersecurity incidents take place. The recent data breach will cost Qantas CEO Vanessa Hudson AUD 250,000 of her expected total annual compensation of AUD 6.3 million.
A new ransomware reporting bill introduced to the House of Representatives proposes putting new requirements on financial institutions, some of which are likely to be controversial. Any payment of over $100,000 would require the victim to first obtain special permission from the US Treasury.
New report from the Information Security Forum (ISF) demonstrates that open source security continues to be a substantial risk even as organizations of all sizes are increasingly leaning on open source software for convenience and financial savings.
Only 18% of businesses recently surveyed said they have comprehensive cyber insurance coverage, however the gap is not closing with only 27% of insurers having the technological capability to provide a plan to cover cyber risks.
Spammers are stepping up their game in the phishing ecosystem with premade tools such as phishing templates, infrastructure and tutorials made widely available on underground forums.
Nothing much seems done to fix IoT security issues over the years with latest ISE report showing 125 CVEs, Common Vulnerabilities and Exposures, which has increased from 52 since 2013.










