While the wheels of digital transformation were set in motion much earlier, the pandemic accelerated their speed. It significantly impacted how organisations approach their IT ecosystem and security. Today’s landscape, with no perimeter, requires a Zero Trust approach.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Over 2.6 million people may have been affected by a massive supply chain attack leveraging over 35 compromised Chrome extensions to take over Facebook Ad accounts.
Much of the new cybersecurity strategy addresses critical infrastructure companies, which were already in the administration's crosshairs, but software creators are also facing the prospect of a much greater degree of liability than in the past.
Given that compromised credentials are a leading cause of cyber attacks, many cyber insurance underwriters are looking for robust privileged access management (PAM) and multifactor authentication (MFA) controls before pricing out their policies.
Companies with significant amounts of sensitive stored data – whether stored on site or in the cloud -- should begin to invest in emerging quantum-resistant data storage, key management, and multiple encryption technologies.
Keeping special accounts safe is really important. With more cyber dangers around, companies need strong ways to check who's logging in and to keep their important info safe. One way to do this is called "just-in-time" (JIT) setup, which helps make sure special accounts stay secure.
In addition to five new state privacy laws, 2024 is expected to bring not only an amplified number of cyberattacks but also increasingly sophisticated attacks, including using emerging technologies such as artificial intelligence (AI), in what is a quickly and continuously evolving threat landscape.
Newly uncovered cyber espionage scheme shows Iranian hackers using unpatched VPN vulnerabilities as a point of entrance into the networks of government and private sector organizations.
There's a common misconception that the AI label automatically makes a cybersecurity solution better when that's far from the truth. Organizations don't need AI or ML tools to improve cybersecurity.
Why despite the fact that businesses and governments spend billions of dollars to fight cyber attacks are businesses continuing to fall prey to data breaches? Companies must build and sustain a strong security culture.










