The NBA alerted fans of potential phishing attacks after a data breach on a third-party newsletter service provider leaked their personal information.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
There’s an on-going battle between competing priorities being waged every day in enterprises globally, and it’s been going on for decades. Cyber security teams are concerned with unpatched vulnerabilities and the breaches they risk, while IT professionals are driven by operational availability, the lack of which jeopardizes the business’ ability to operate.
In a high-stakes chess match, the grandmaster doesn’t win by brute force; they win by observing, anticipating, and exploiting small weaknesses in their opponent’s position. Every move is part of a strategy. This is exactly how cybercriminals operate today.
Data security has increasingly become a key aspect of cybersecurity because of the large amounts of data being generated, stored and shared by both individuals and organizations. The shift from cybersecurity to data security indicates a more holistic approach to protecting sensitive data in organizations.
The past year has shown organizations that uncertainty and a transformed reality are the new normal in business. Organizations have had to respond in real-time to shift their cybersecurity strategies and keep up with an expanding IT infrastructure, the explosion of IoT devices, and a new wave of threats from more sophisticated attackers.
ATM machines have always represented a “soft target” in the minds of criminals. What’s now clear is that the ATM card skimmer scams of years past pale in comparison with what’s possible now with jackpotting scams with cyber criminals turning every ATM they visit into casino slot machines with huge jackpots.
SaaS applications are not going anywhere, and we must face the fact that they have access to our company’s most sensitive data. With SaaS, the shadow IT challenge has expanded and deepened even further.
New iPhone exploit allows anyone to permanently jailbreak by using a USB cable to bypass the bootROM. The exploit compromises all models from iPhone 4S to iPhone X and cannot be fixed with a software update.
Remote work and remote hiring didn’t just change where people sit. They changed how trust is established.
What kind of future can be achieved by focusing on the nexus of information security and data privacy? Better compliance, stronger alignment and greater accountability, just to name a few benefits.










