Data security and cybersecurity are often conflated but require distinct approaches. Traditional cybersecurity, focused on access control and encryption, overlooks the complexities of data consumption.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
WHO was hit by a cyber espionage attempt with more than double the usual number of cyber attacks including an attempt to set up a fraudulent site to compromise internal email system.
Retailer WH Smith suffered a cyber attack that leaked employee data, including names, dates of birth, and National Insurance Numbers. The incident leaked the data of current and former employees, but customer data was unaffected.
How can an organization prevent unauthorized people from looking over their remote employee's shoulders? By utilizing an identity confirmation solution that combines biometrics, object recognition, and AI, businesses will ensure only approved employees view sensitive data.
Ransomware attack campaign targeted an old (and previously patched) vulnerability in VMware servers, and that it has grown to become the largest attack of its type, compromising at least 3,200 VMware servers.
Octo Tempest has gradually stepped up from data theft, to data extortion, and now to ransomware as of this summer (becoming an affiliate of the ALPHV/BlackCat group). The cybercriminals are entirely financially motivated and nearly always leads with either a phishing email/message or a social engineering call. It also looks to execute SIM swap attacks.
There are two pieces of legislation already in front of Congress that would set reporting requirements for ransomware payments, each proposing different time windows for different industries and company sizes. A third now seeks a 48-hour limit.
After more than a year of turmoil and tension, how can cybersecurity leaders keep their teams alert, convince other stakeholders to stay committed, and overcome the natural human tendency to begin relaxing defenses?
By searching the internet, hackers have begun hijacking smart building access control systems to recruit these IoT devices into botnets for launching DDoS attacks.
Internet of Medical Things (IoMT) brings significant benefits to the delivery of patient healthcare services and internal operations, but healthcare delivery organizations tend to struggle with implementing effective cybersecurity measures.










