Since these are ransomware groups after all, the retirement announcements may well be FUD to cover strategic retreats and rebrands after an extended period of high-level exposure. But at least for the moment some of the world's most significant threats such as Scattered Spider, ShinyHunters, and Lapsus$ appear to be out of the game.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A skill-based hiring culture enforces the premise that anyone can become a cyber professional with the right training and techniques. Certification training programs can be tailored to allow non-traditional candidates to align their soft skills with impactful cyber roles.
Attackers who are blocked by strong defenses in other areas, are exploiting exposures from mismanaged machine identities to exploit the trust these systems are designed for.
Synthetic identity fraud, which takes advantage of flaws in conventional identity verification systems, has emerged as a major threat to cybersecurity. It is challenging to identify this kind of fraud using traditional techniques since it includes the construction of fictional identities using a combination of true and made-up information.
Recently, we examined some of the challenges that companies face in terms of the evolving privacy and data protection landscape - and how these challenges may require a whole new breed of information security professional. In this second part of the series we unpack the argument for a new role combining Chief Security Officer and Chief Privacy Officer in a rapidly evolving regulatory and threat rich environment. We also chat with Chief Security and Privacy Officer (CSPO) at a Fortune 500 company to get his take on the subject.
Global cyber war no longer seems impossible with state-sponsored cyber attacks mounting around the world and possibility of China, Iran and Russian uniting to go against U.S. in the cyber domain.
Upgrading to the “latest and greatest” technology isn’t always feasible for businesses, given the cost and disruption involved in constantly changing processes and switching solutions. So how can today’s organizations better understand when it makes sense to upgrade—and when it doesn’t?
The focus is now turning to the cybersecurity implications of ChatGPT and other AI/machine learning (ML) platforms especially after the recent OpenAI security incident. What are some of the key security considerations that organizations need to consider before they explore how to utilize new AI/ML solutions?
One of the biggest obstacles enterprises face during their digital transformation journey is operating in a hybrid model that maintains legacy systems while migrating to the cloud. A main issue with hybrid environments is identity management.
As individuals and companies interact with increasingly different online platforms, apps, and services, the demand for a consistent approach to data and information security has expanded enormously across cybersecurity technologies that address the problem of managing security across domains by providing integrated solutions that traverse conventional boundaries.










