There’s an on-going battle between competing priorities being waged every day in enterprises globally, and it’s been going on for decades. Cyber security teams are concerned with unpatched vulnerabilities and the breaches they risk, while IT professionals are driven by operational availability, the lack of which jeopardizes the business’ ability to operate.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Stolen passwords from over 100,000 data breaches circulating on the dark web has reached 15 billion, a number that has risen by 300% within the last two years.
The cover-up the security chief orchestrated was outed in 2017 when Uber appointed a new CEO and an internal investigation into the prior year's data breach was initiated. He was convicted on charges of obstruction of justice and knowing concealment of a felony.
A new CISA-NSA joint report follows many calls by both members of the cybersecurity industry and government agencies for a transition to memory-safe languages like Rust, Ruby, Java and C# due to their inherent minimization of memory-related classes of vulnerabilities.
Microsoft says Russia conducted a cyber espionage campaign against Ukraine's allies, mainly NATO members, to collect crucial information in parallel with the ground invasion.
Acadian Ambulance Services suffered a Daixin cyber attack that disrupted certain computer systems and leaked the personal and protected health information of 10 million people.
NSA primarily conducts intelligence gathering and hacking against foreign adversaries. It does raise questions about to what degree the government is now planning to embrace Mythos AI in cyber operations and would appear to be a powerful confirmation of the system's cyber capabilities.
User activity monitoring and insider threat detection is evolving to get ahead of the ever increasing threat to user data. Providing advanced analytics, insightful intelligence, and effective response mechanisms, it addresses three critical components of data security in 2019.
SEC's new rule for public companies to report data breaches within four days is a significant step towards transparency, cybersecurity preparedness, and standardizing reporting practices. Since news of the law broke, many security professionals have however expressed conflicting opinions.
About 26 Million Fortune 1000 Employee Credentials Available on the Dark Web, Password Reuse Rampant
SpyCloud found about 26 million Fortune 1000 employee credentials circulating on the dark web. Password reuse, weak passwords, and infostealers were responsible for the leaks.










