Most businesses are more vulnerable to emerging risks such as malware and ransomware attacks than traditional threats yet there are coverages gaps in their cyber insurance policy.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
INTERPOL’s arrested nearly 1,000 cybercriminals, recovered $130 million from 2,800 accounts linked to proceeds of crime, and closed 1,600 cases in Operation HAECHI III.
NERC, a non-profit regulatory authority that oversees utilities, revealed this week that about 25% of the electric utilities on the North American power grid downloaded the SolarWinds backdoor.
Cybersecurity agencies in U.K. and U.S. warn of APT groups targeting cyberattacks at entities involved in COVID-19 response efforts to gather intelligence and commit espionage.
Spanish multinational fashion retailer MANGO has recently experienced a third-party data breach that exposed customer information from a marketing partner.
A WeChat zero-click attack method could enable a malicious actor to take over the victim’s account or even compromise the device without user interaction.
Cyber insurance companies are choosing to settle things quickly with a ransom payment during ransomware attacks for fear of covering all the business interruption costs and delays of re-booting a company from scratch.
Early authentication relied on simple passwords, which proved vulnerable to brute-force attacks, credential stuffing, and social engineering.
Security researchers have discovered hundreds of federal network devices with exposed management interfaces violating the recently mandated CISA security requirements detailed in the Binding Operational Directive (BOD) 23-02.
One of the few significant holes in Apple's end user security is set to be addressed, as Cupertino has announced plans to introduce end-to-end encryption to iCloud backups. A feature Apple has delayed due primarily to pressure from US federal law enforcement agencies.










