The software supply chain is becoming the new battleground. Trust, once a cornerstone of open-source, is now under scrutiny. Developers need to exercise caution, vetting each package, no matter how reputable the source might seem.
To prepare for any privacy regulation, adopt a core technical framework where privacy controls can be applied to any new or existing system.
In late December last year, Mario Greco, the chief executive of insurance giant Zurich sent shockwaves through the business world when he announced that cyberattacks are set to become uninsurable. Cyber insurance providers are left with no choice but to tighten their policies, or risk going bankrupt.
What are the tools that can help DPOs measure efficacy and progress in improving the risk position and level of compliance across multiple functions of the company?
The nature of phishing attacks and the role of human error in the problem means that it’s unlikely we can completely eliminate this threat. Implementation of behavioral analytics solutions allow security teams to clearly identify irregular or abnormal behaviors and take action to determine if someone with access is a potential threat.
The days of managing from the shadows are long gone for the CISO. Today’s CISO is more than an advisor to the C-suite with 88% of boards of directors viewing cybersecurity as a business risk. The role for the CISO has expanded to encompass advising the entire business and employees on how they can help ensure data security.
A zero-trust framework is essential but is not enough. It needs to be part of a comprehensive cybersecurity solution that is a match for increasingly courageous, sophisticated threat actors.
2020 was a watershed year for data privacy. The new year will see the continuation of some long-time trends with a few notable additions. Here's the top 4.
Two-thirds of breaches are inside jobs. Yet, insider threat programs account for less than 10% of the budget. Are enterprise cybersecurity efforts properly prioritized?
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”) was signed into law on March 15, 2022 and requires covered entities to report “significant” cyber incidents within 72 hours and ransomware payments within 24 hours.










