Cyber insurance premiums have jumped 73% in the U.S alone. Greater specificity over what is (and what is not) covered has become a feature of many updated policies, as has the expectation that companies need to have greater cybersecurity hygiene in place in order to qualify for insurance.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Organizations need a new security approach designed for the modern world that automatically validates security for continuous resilience instead of assuming Defense in Depth is accurate. Every Defense-in-Depth design requires Validation-in-Depth at its core.
15 year-old flaw in a default python module introduces supply chain vulnerability to over 350,000 open source projects and the applications that use them, including SDKs, AI/ML, security, management, and developer tools.
The long-running Qakbot malware botnet was disrupted by international law enforcement action in August, but its operators appear to still have some capability and are continuing to run spam email campaigns that attempt to pass ransomware.
The Qantas breach appears to be isolated to a third-party contact center that the airline uses for customer service queries. Unusual activity was detected on June 30, leading to discovery of the data breach and "immediate" actions to contain it, and up to six million customers may be impacted.
A new poll from Deloitte finds there is an immediate and significant cyber risk from "harvest now decrypt later" (HNDL) attacks, in which attackers steal encrypted information and simply sit on it until quantum computing advances make it trivial to crack.
Concrete steps to address the threat quantum computing poses to current cryptographic standards have been taken by NIST, as it has selected four algorithms for future use.
The biennial cyber exercise for the first time brings the U.S., Asia and Europe financial industry together for a sort of "war game" that simulates a major financial institution being taken out by a ransomware attack.
A Quantum ransomware attack on Professional Finance Company (PFC) impacted 657 healthcare organizations and leaked sensitive patient data for millions of patients.
Quora suffered a massive data leak, exposing their password database with 100 million passwords. But the passwords were securely stored and are next-to-useless to criminals.










