Covid highlighted the need for organizations to fully understand the world of their information and to mature their information governance program. While we are still reevaluating where we work, it is the perfect time to also reevaluate how we work.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
The cover-up the security chief orchestrated was outed in 2017 when Uber appointed a new CEO and an internal investigation into the prior year's data breach was initiated. He was convicted on charges of obstruction of justice and knowing concealment of a felony.
The move toward software-defined vehicles is enabling a wealth of safety, comfort and convenience innovations but this requires an approach to development that always has cybersecurity in mind.
T-Mobile has seemingly had annual data breaches since 2018, but the new FCC settlement addresses just those that took place in the post-Covid period (and that involved the largest total count of customer records).
A new report from Google Threat Intelligence Group (GTIG) and Mandiant warns of a zero-day vulnerability present in Dell RecoverPoint for Virtual Machines since 2024, and that has been actively exploited by Chinese hackers for at least that long.
The National Cybersecurity Strategy Implementation Plan (NCSIP) establishes 65 high-impact initiatives that agencies will be required to meet within set timelines for each. A greater degree of public-private partnership is also being promoted.
Medical companies affected by AMCA healthcare data breach have begun alerting investors and shareholders which may cause them to lose tens of millions of dollars in stock market valuation.
CISA added the Ransomware Readiness Assessment module to the CSET toolset to assist organizations of varying maturity levels to assess their cybersecurity posture against attacks.
As biometrics technology becomes more widespread and sophisticated, there is growing concern about it crossing ethical lines through misuse or fraud.
Cyber espionage hackers target Czech antivirus software company Avast's CCleaner product with more than 435 million users in 68 countries in an attempted supply chain attack.










