Cyber risk is ready to join the realm of Enterprise Risk Management, and it must in order to prevent the surprise shock of massive financial impact from cyber events.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The U.K.’s Information Commissioner’s Office has fined a South Staffordshire water supplier $1.3 million, following a multi-year data breach that affected more than 630,000 people.
Traditional VDI solutions can be complex and expensive, sacrificing application user experience and performance. By replacing your existing VDI solution with Browser Isolation, you can ensure fast and secure application access for all your users on any device.
A massive brute force password attack involving 2.8 million IP addresses targets VPN devices from various companies including Palo Alto Networks, Ivanti, and SonicWall.
Security researchers discovered a “package planting” flaw that allows malware developers to add respected open-source contributors to malicious NPM packages without notification or approval.
Microsoft has downplayed the issue in official communications, stating that the summaries of the confidential emails were not exposed to anyone that did not already have access to the messages in question. There is always some concern about exactly where information goes once AI tools have ingested it, however.
So how does the United States Air Force with over 5,000 aircraft in its inventory make sure that it’s online security is top notch? It’s simple – it invites people to hack its systems.
Human error accounts for the vast majority of security breaches largely due to successful phishing campaigns. Here are tips on fortifying the human firewall via the Fogg model of behavior design.
As the enforcement date for AB685 approaches and employees return to offices, organizations should look into using their existing SIEM and UEBA technologies for strong contact-tracing systems.
As enterprises work to weather the COVID-19 crisis, they are applying the lessons learned to strengthen their cyber resilience, and to embed data security, privacy and compliance into their IT infrastructure.










