Transport for London (TfL) is responding to a cyber attack that affected its crucial IT systems, disrupting Dial-a-Ride and other services and forcing staff to work from home.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
With more and more organizations providing healthcare data through patient portals, how can they protect themselves from unauthorized access and theft of medical records?
Security teams need to be vigilant - both on what SaaS services employees are connecting to, and whether those platforms are safe and remains safe for use in the organization.
Next year, cybersecurity becomes an AI-driven battleground where trust erodes, deception scales, and the speed of intelligent machines determines who stays secure and who gets left behind.
As attackers use AI and automation to move from access to impact faster than traditional SOC workflows were designed to handle, security teams need technology that can operate at comparable speed.
The 2024 election season is facing an unprecedented challenge: AI-driven disinformation and cyberattacks. As AI’s influence grows, its ability to spread misinformation, create deepfakes, and target election systems becomes more dangerous.
When it comes to web applications, there is no substitute for a thorough penetration test. A comprehensive penetration test also offers visibility into blind spots within the application’s attack surface, giving teams a chance to plan ahead and keep attackers from succeeding.
Given the ongoing prevalence of advanced persistent threat (APT) attacks, organisations have every right to be wary. To prevent APT attacks, they simply need to practise basic cyber hygiene.
It’s clear that the introduction of generative AI to the mainstream is tipping the scales towards a war of algorithms against algorithms, machines fighting machines. For cyber security, the time to introduce AI into the toolkits of defenders is now.
While the transition to passwordless security procedures is already underway, adoption is still limited mainly in larger companies in certain industries. There are many steps that can (and should) be taken to accelerate the authentication journey to make passwordless authentication mainstream.










