By truly understanding the service level agreements of a cloud service provider, enterprises can ensure that the joint responsibility of securing data, applications and processes is maintained, allowing IT teams to create a comprehensive cybersecurity strategy.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Denmark Weathered Wave of Cyber Attacks on Energy Infrastructure in May, Industry Non-profit Reveals
Denmark's energy infrastructure was bombarded by cyber attacks in May of this year. Report says 16 energy infrastructure companies were targeted and 11 were compromised immediately, the other five only apparently dodging a breach because the attackers were sloppy in their technique.
U.S. Department of Defense requires all defense contractors to complete a cybersecurity certification before submitting proposals by 2026, starting with higher-level contractors this June.
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”) was signed into law on March 15, 2022 and requires covered entities to report “significant” cyber incidents within 72 hours and ransomware payments within 24 hours.
U.S. Department of Homeland Security aims to help software developers and security researchers eliminate common software vulnerabilities by releasing a list of top 25 most dangerous software errors.
Desorden group hacked Centara Hotels & Resorts again after negotiations for ransom payment collapsed and the hotel recovers part of the databases stolen in the first data breach.
The battle against Log4Shell is proceeding very slowly due to a confluence of factors. It remains buried in a number of assets, particularly legacy systems that are tougher to address. But it also continues to affect organizations via new devices.
A large chasm of cultural disconnect remains in the realm of security. Employee engagement is a particular problem, with less than half saying that they were very likely to report a cybersecurity incident.
As AI continues to accelerate how quickly attacks can change, defenses built on static assumptions will continue to fall behind. Detecting intent does not eliminate that challenge, but it offers a way to keep pace by focusing on the one thing attackers cannot easily randomize. The path they have to take.
Montenegro is dealing with a brutal ongoing campaign of ransomware attacks that appears to be coming from criminal groups in Russia. Government agencies in Chile have also been hit by a new form of ransomware that targets Linux servers.










