Fewer than half of IT professionals report feeling confident about their organisation’s cybersecurity since the pandemic. So, what are the biggest digital risks lying in wait for businesses looking ahead to working in a post-COVID world?
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
According to the new U.S. Worldwide Threat Assessment, both Russia and China are capable of launching cyber attacks against critical infrastructure targets in the U.S. Moreover, say top U.S. intelligence officials, both Russia and China appear to be aligning their operations in cyberspace.
Users are still not trusting secure authentication methods like biometric recognition despite their fear of increasing cyber threats during COVID-19 pandemic outbreak.
Companies are looking for new solutions to prevent, detect, and eliminate fraud. And machine learning seems to be the best answer to financial fraud. How does it work, what are the benefits, and who uses it?
The US Department of Transportation has suspended the TRANServe benefits system to address a security breach impacting 237,000 current and former federal employees.
Extortion Attempt on Samsung Leads to Data Breach, Leak of Bootloader and Authentication Source Code
Samsung says that no personal information was lost in the data breach and that it does not expect customers to be impacted, but the source code could lead to serious vulnerabilities.
Security researchers found more than 500,000 stolen employee credentials from leading gaming companies circulating on the dark web, exposing the companies to potential data breaches and ransomware.
Toyota has confirmed a third-party data breach that leaked 240 GB of sensitive information on the dark web, but says the cybersecurity incident was grossly misrepresented.
While organizations should prepare for a passwordless authentication-based future, in the interim, companies need to implement a strategy that utilizes as few passwords as possible, including products such as a password manager for business, federation, and privileged access management (PAM).
The Cisco network breach was traced back to an employee's personal Google account. It was protected by multi-factor authentication (MFA), but the attacker tried a number of different voice phishing attempts.










