Updated FFIEC compliance guidelines specifically delineate APIs as a distinct attack surface, shedding light on the amplified risks they introduce. Financial institutions might be on a tighter compliance timeline than anticipated to prioritize fortifying their API security.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Hackers breached UScellular’s retail CRM software and accessed customer data, including PIN and CPNI, and ported some subscribers’ mobile phone numbers to a different carrier.
Australian Clinical Labs reportedly detected the attack not long after it occurred and was contacted by government authorities in March, and were also notified in June that some of the patient data had been found available for sale on the dark web.
Fidelity National Financial disclosed that hackers compromised the data of 1.3 million customers during the November 2023 cyber attack that disrupted operations for a week.
Airbus has confirmed a data breach that exposed confidential business information via a partner airline’s compromised account. Threat actors compromised a Turkish Airlines employee account using the Redline info-stealer malware in August 2023.
A new executive order from the Biden administration addresses a wide range of the potential harms that AI can cause, putting new safeguards in place for everything from biological materials engineering to deepfakes.
Cloud infrastructure provider Digital Ocean severed ties with the marketing automation provider Mailchimp after a security breach exposed its customer email addresses.
Two zero-day vulnerabilities in Ivanti products that were disclosed in January (and patched weeks later) have turned out to be the source of a breach of MITRE, the US government-funded cybersecurity research center. China's nation-state hackers are suspected to be behind the attack given similarities in exploiting these same vulnerabilities in other incidents, but this is not confirmed as of yet.
Insurers have a vital role to play in inoculating organizations against potentially crippling attacks. With cyber insurance premiums forecast to reach $7.5 billion by 2020, how can insurers do their part to leverage this opportunity for the benefit of customers in today’s digital world?
Citing the dangers of “sideloading”, Apple and Google defend themselves by saying their app store policies are necessary to protect their users. But while sideloading can be very risky, it can be done securely through the use of time-tested and effective cybersecurity technologies.










