There are two pieces of legislation already in front of Congress that would set reporting requirements for ransomware payments, each proposing different time windows for different industries and company sizes. A third now seeks a 48-hour limit.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Microsoft announced a breach where they uncovered misconfigured security rules in one internal database that exposed 250 million customer service records for almost whole of December.
Officials have warned that the NHS patient data stolen in the University of Manchester cyber attack could become publicly available with potential ramifications. The incident impacted UoM, which holds patient information of 1.1 million patients across 200 hospitals.
A two-day international summit held in the UK has concluded with an agreement on AI safety, with 28 countries that represent most of the leading forces in AI development getting on board.
While organizations should prepare for a passwordless authentication-based future, in the interim, companies need to implement a strategy that utilizes as few passwords as possible, including products such as a password manager for business, federation, and privileged access management (PAM).
Shift to remote working has contributed to an unrelenting cybersecurity emergency. Here are three cybersecurity lessons from the pandemic that every organization should learn as they prepare for the future of hybrid work.
Phishing is a massive cyber security threat and very much still plagues the healthcare industry. What are the email security setbacks faced by the healthcare providers which make them vulnerable?
Single Sign-On (SSO) is a technology layer that enables users to access multiple applications with one set of credentials.
No matter how boring or clichéd this might sound, information security policies and procedures are the pillars successful organizations are built on, setting the stage for a sound security culture and helping to create a foundation for a truly resilient organization.
While AI and Quantum may be powerful tools, don’t get distracted. As organizations race to unlock their potential, it’s easy to lose sight of the basic truth: your cybersecurity foundation matters more than ever.










