Boards are starting to ask the right question about AI risk. Unfortunately, many organizations still don’t have a credible answer.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
UK Police have arrested a 17-year-old suspected Scattered Spider member accused of the MGM hack that disrupted casinos and hotels in Las Vegas on September 12, 2023, costing over $100 million in recovery.
An inquiry into the May 2023 Xplain data breach found that 5% or 65,000 of the 1.3 million files the Play ransomware gang leaked were relevant to the Swiss government.
According to a new FBI warning, hackers are stepping up their attacks on U.S. automotive industry to include ransomware infections, data breaches, phishing attacks, and corporate espionage activities.
A bill establishing a new vulnerability disclosure program for federal contractors has passed the House, and will now move on to the Senate to be reviewed by the Committee on Homeland Security and Governmental Affairs.
An Illinois hospital has attributed its permanent shutdown to a ransomware attack that disrupted healthcare, communication, and IT systems, preventing it from making insurance claims.
Documents leaked to Vice's Motherboard magazine indicate that, between 2018 and 2020, Google fired at least 80 employees for data misuse. At least a few involve employees accessing user accounts and manipulating or deleting the data of other employees.
Credit rating agency Experian's Netherlands branch has been assessed a €2.7 million (about $3.2 million) GDPR fine for improper collection of personal data, which was drawn from multiple public and private sources that data subjects were not necessarily aware of.
Globant SAS confirmed a data breach affecting a "limited" number of customers after Lapsus$ hackers published 70GB of source code allegedly stolen from the company. Screenshots suggested that the leaked customer source code belonged to companies like Apple, Facebook and DHL.
Energy and automation company Schneider Electric has confirmed a ransomware attack that disrupted the Sustainability Business division and leaked company data.










