Although it can be easy to get caught up in the novelty and buzz surrounding new security tools, it isn’t always in a company’s best interest to continue adding to their tech stack before spending time to ensure that the current systems are being utilized to the best of their ability.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Rogue Meta employees and contractors abused an internal tool called "Oops," which is primarily intended for in-house account recovery for employees and business partners. There were some cases of account hijacking for money.
Private Chinese hackers were employed not just for foreign hacking, but also as a part of the government's domestic surveillance program. The document leak indicates that i-Soon may have also hacked domestic targets for the purpose of intelligence-gathering.
A security vulnerability that was initially documented as a Chrome bug is likely part of the attack chain employed by NSO Group's Pegasus spyware, and has been revised as a critical libwebp flaw in a new CVE ID filed by Google.
The DoD has published a strategy and roadmap directing all the department's agencies to migrate to zero trust architecture by 2027. Strategy identified 90 target capabilities and 62 capabilities to achieve “more advanced zero trust.”
AI technology brings benefits and can just as easily be used for malicious ends. Today, both cybersecurity experts and cybercriminals are using AI. Could it pose more of a cybersecurity threat than we think?
There is a tremendous amount of potential for machine learning and cyber security within the enterprise. In order for machine learning to live up to the hype, it will need to offer a fully robust security solution and plenty of organizations are now betting that machines will be up to the task.
If your business is dealing with data then ignoring the peace of mind that cyber liability insurance would provide would be foolhardy. In fact, the very survival of a business that stores and leverages customer data in any way may very well depend on good cyber liability coverage.
The FBI's data handling practices were sharply criticized during a recent DOJ audit, with the OIG noting that the agency is failing to adequately control its storage media and that its disposal methods are potentially exposing sensitive and classified information.
The U.S. Department of Justice has charged five members of the cybercrime gang Scattered Spider for related cyber attacks affecting numerous individuals and organizations, including Okta, Caesars Entertainment, Twilio, DoorDash, MailChimp, Reddit, and Riot Games.










