Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Philadelphia Indemnity Insurance

    The Target: Philadelphia Indemnity Insurance designs, markets, and underwrites commercial property/casualty and professional liability insurance products.

    The Take: Philadelphia Indemnity launched an investigation and determined by July 9 that the stolen data included names, driver’s license numbers and dates of birth, according to the breach notice.

    The Vector: An unauthorized party accessed customer data during an intrusion discovered between June 9 and June 10, according to the disclosure. The company previously called the incident a network outage, however it said there was no ransomware and no encryption.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Costs of Data Breaches Dropping Globally But Not In Canada: IBM Study

    2025-07-30

    BNN Bloomberg: The average cost of a breach between March 2024 and February 2025 was $6.4 million, down from $6.6 million a year earlier, showed research released from technology giant IBM and the Ponemon Institute, a U.S.-based cybersecurity research centre.

    Read more...

    Australian Firms Unify Cybersecurity as Threats Increase

    2025-07-30

    Yahoo Finance: A growing number of enterprises in Australia are taking a centralized, cloud-based approach to cybersecurity amid rising threats, many of which involve AI, according to a new research report published today by Information Services Group (ISG), a global AI-centered technology research and advisory firm.

    Read more...

    Palo Alto Networks Stock Falls After Announcing $25 Billion CyberArk Deal

    2025-07-30

    CNBC: CyberArk shareholders, for each of their shares, will get $45 cash and 2.2005 shares of Palo Alto. The deal is expected to close during Palo Alto Networks’ fiscal 2026.

    Read more...

    Banks Struggle to Adopt Generative AI as Cybersecurity Concerns Linger

    2025-07-29

    Korea Times: Commercial lenders are finding it difficult to fully integrate generative artificial intelligence (AI) technologies into their financial services, impeded by the current regulation that prohibits the use of full, unencrypted personal credit information, market watchers said.

    Read more...

    AXA XL Launches Exclusive Cybersecurity Assessments In Partnership With Fenix24

    2025-07-29

    PR Newswire: AXA XL, a leading provider of cyber insurance, is proud to announce the launch of a new suite of proactive cybersecurity assessment offerings for its cyber policyholders in North America, in collaboration with Fenix24, a global leader in ransomware response and recovery.

    Read more...

    Allianz Life Discloses Massive Data Breach Linked To Supply-Chain Attack

    2025-07-28

    Cybersecurity Dive: Allianz Life Insurance Company of North America disclosed a massive data breach affecting most of the firm’s 1.4 million U.S. customers, professionals and select employees.

    Read more...

    Trump’s Cybersecurity Cuts Putting Nation At Risk, Warns New York Cyber Chief

    2025-07-28

    TechCrunch: During the first few months of the new Trump administration, the White House slashed cybersecurity budgets, staff, and initiatives. And some, including cybersecurity experts and legislators, are not happy about it.

    Read more...

    Know Your Breach: Ahold Delhaize

    The Target: Ahold Delhaize, one of the world's largest food retail chains. The multinational retailer and wholesale company operates over 9,400 local stores across Europe, the United States, and Indonesia, employing more than 393,000 people and serving approximately 60 million customers each week in-store and online.

    The Take: The company added that the stolen items vary for each affected individual and that the stolen documents contain a combination of personal information such as name, contact information, financial account information, health information and employment-related information.

    The Vector: In a filing with Maine's Attorney General, the retail giant revealed that the attackers behind the November breach stole the data of 2,242,521 individuals after gaining access to the company's internal U.S. business systems on November 6, 2024.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    Canadian Hedge Fund Waratah Capital Reveals Data Breach

    2025-07-23

    Hedge Week: The Globe and Mail report cites the firm as revealing the breach in a letter to investors this week, stating that an unauthorised party accessed data through a third-party IT provider, rather than directly penetrating Waratah’s internal network.

    Read more...

    Rapid7 Launches Automated Patching Solution for Cybersecurity

    2025-07-22

    Investing.com: Rapid7, Inc., a cybersecurity company generating $849 million in annual revenue with healthy gross margins of 71%, announced the release of Active Patching, a new automated patching and remediation solution integrated into its Exposure Command platform. 

    Read more...

    Darktrace Acquires Mira Security for Network Visibility

    2025-07-22

    Dark Reading: Darktrace has acquired Mira Security, a startup that provides network traffic visibility solutions. Financial terms were not disclosed. The acquisition will strengthen Darktrace's network security portfolio through improved insights into encrypted network traffic, the company said.

    Read more...

    Republicans Propose 7% Leaner SEC Budget Compared to Biden’s Era

    2025-07-22

    Cointelegraph: US House Republicans are seeking to cut the Securities and Exchange Commission’s 2026 budget by 7%, while axing funds for enforcing a Biden-era rule that requires public companies to disclose cyber incidents.

    Read more...

    ASIC Sues Fortnum Over Alleged Cyber Failures

    2025-07-22

    Financial Newswire: The Australian Securities and Investments Commission (ASIC) has initiated legal action over Fortnum Private Wealth alleging it failed to properly manage and mitigate cyber security risks. 

    Read more...

    Microsoft Hit With SharePoint Attack Affecting Global Businesses and Governments

    2025-07-21

    CNBC: Microsoft has warned of “active attacks” targeting its SharePoint collaboration software, with security researchers noting that organizations worldwide stand to be affected by the breach.

    Read more...

    Is AI Here to Take or Redefine Your Cybersecurity Role?

    2025-07-21

    CSO Online: That headline ran atop a CSO story published in 2016. Nine years later, the prediction feels closer to coming true — with questions around jobs being replaced or redefined and whether cybersecurity pros should be worried taking on greater nuance, and still hanging in the balance.

    Read more...

    Know Your Breach: Slim CD

    The Target: Slim CD is a provider of payment processing solutions that enables businesses to access electronic and card payments via web-based terminals, mobile, or desktop apps.

    The Take: The types of data that may have been accessed by the unauthorized party include: full name, physical address, credit card number and payment card expiration date.

    The Vector: The firm first detected suspicious activity on its systems this year on June 15. During the investigation, the company discovered that hackers had gained access to its network since August 17, 2023.

    This breach highlights the extreme importance of timely software updates for known software vulnerabilities, not only in systems directly under a firm’s control, but in third-party systems the firm relies upon as well. The longer a firm, or its vendors, hold out on deploying the most up-to-date software for their systems, the greater the chance an attacker will exploit the issue.

    Read more...

    London-Listed NCC Weighs Sale of Cybersecurity Arm

    2025-07-16

    Sky News: Sky News has learnt that NCC has engaged bankers at Rothschild to examine options for its cybersecurity arm, with a sale among the possible options being considered.

    Read more...

    Securing the Budget: Demonstrating Cybersecurity's Return

    2025-07-16

    Dark Reading: Last year, breaches resulting from exploited vulnerabilities increased 180%, while the average cost of a data breach the US topped nearly $5 million

    Read more...

    Cybersecurity Funding Surged Higher In Q2

    2025-07-16

    Crunchbase: Cybersecurity was a hot area for venture investment in the first half of 2025, with total funding to the space hitting its highest level in three years.

    Read more...

    Italian Cybersecurity Firm Exein Sees Defence Boost as it Closes Funding Round

    2025-07-16

    Yahoo Finance/Reuters: Italian tech firm Exein said a pick up in European defence spending was supporting its domestic growth, as it closed a funding round aimed at global expansion.

    Read more...

    Nautic Partners Completes Acquisition of AccessIT Group in Partnership with Management

    2025-07-15

    Business Wire: Nautic Partners, LLC (“Nautic”) is pleased to announce that, in partnership with management, it has closed the acquisition of AccessIT Group, Inc. (“AccessIT”) as a new platform investment. 

    Read more...

    ECB Supervisors Focus on Risks From Tariffs to Cyber Attacks, Central Bank Sources Say

    2025-07-15

    Yahoo Finance/Reuters: European Central Bank supervisors are focusing on issues ranging from tariffs to cyber attacks and a possible dollar shortage as they assess potential risks to the region's banking industry, five senior central bank officials told Reuters.

    Read more...

    Trump Administration to Spend $1 Billion on ‘Offensive’ Hacking Operations

    2025-07-14

    TechCrunch: The Trump administration, through the Department of Defense, plans to spend $1 billion over the next four years on what it calls “offensive cyber operations.” 

    Read more...

    Know Your Breach: Bitcoin Depot

    The Target: Crypto ATM operator Bitcoin Depot

    The Take: Bitcoin Depot said in its notice to customers that the breach involved their name, phone number, driver’s license number and could have also included addresses, birth dates and emails.

    The Vector: On July 18, 2024, the cybersecurity firm finished its investigation and “confirmed that an unauthorized party accessed files containing personal information of certain customers,” according to a spokesperson and the customer notice.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Cyberstarts Launches $300 Million Employee Liquidity Fund to Power the Next Stage of Cybersecurity Startup Growth

    2025-07-09

    Business Wire: Cyberstarts, the leading early-stage cybersecurity venture firm, announced the launch of a $300 million Employee Liquidity Fund.

    Read more...

    Trump Seeks Unprecedented $1.23 Billion Cut to Federal Cyber Budget

    2025-07-09

    CSO Online: Donald Trump's sprawling tax bill, which he signed on July 4, contained a few noteworthy cyber funding items, including $250 million for US Cyber Command to spend on “artificial intelligence lines of effort.”

    Read more...

    Hg Invests in Cybersecurity Compliance Provider A-LIGN

    2025-07-08

    Investing.com: HgCapital Trust plc announced it will invest approximately £48 million in A-LIGN, a provider of cyber compliance services, as part of a larger acquisition by Hg.

    Read more...

    72% of Portfolio Companies Hit by a Cyber Attack in the Past Three Years

    2025-07-07

    Private Equity Wire: Cyber security consulting firm S-RM’s latest study, based on a survey of 100 PE professionals across the UK, Europe, and the US, reveals that 72% of respondents have experienced a serious cyber incident across their portfolios in the past three years – highlighting cyber attacks as systemic risks that span entire investment ecosystems.

    Read more...

    SEC Seeks SolarWinds Settlement in Reversal for Agency Under New Leadership

    2025-07-07

    Cybersecurity Dive: The Securities and Exchange Commission has reached a settlement with SolarWinds and the company’s chief information security officer, Timothy Brown, to resolve charges stemming from the Russian-backed cyberattack on the company’s systems.

    Read more...

    Employee Gets $920 for Credentials Used in $140 Million Bank Heist

    2025-07-07

    Bleeping Computer: Hackers stole nearly $140 million from six banks in Brazil by using an employee's credentials from C&M, a company that offers financial connectivity solutions.

    Read more...

    Ransomware Attack Triggers Widespread Outage at Ingram Micro

    2025-07-07

    Dark Reading: Ingram Micro, one of the world's largest IT distributors, has confirmed it suffered a ransomware attack that sparked a worldwide outage of its services.

    Read more...

    Know Your Breach: Kelly Benefits

    The Target: Kelly Benefits is a provider of benefits consulting, enrollment technology, payroll administration, HRIS, compliance support, and carrier management.

    The Take: The data breach notice sent to impacted individuals informs recipients of the specific data types impacted by the breach, which vary per person. However, the general notice published on the site says that the compromised info may contain full names, Social Security number, tax ID number, date of birth, medical information, health insurance information, and financial account information.

    The Vector: The Maryland-based health and life insurance agency has issued an update on a security incident it suffered last year between December 12-17, when unauthorized actors breached its IT systems and stole files. On April 9, 2025, the company stated that the incident impacted 32,234 individuals. The figure was revised multiple times until the final tally shared with authorities in the U.S. counted 553,660 individuals.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    FBI Cyber Guidance To Lawmakers Falls Short, US Senator Says

    2025-07-02

    Cybersecurity Dive: As commercial spyware proliferates and hackers linked to U.S. adversaries step up their attempts to breach high-profile American targets, one U.S. senator says the FBI isn’t doing enough to help lawmakers protect themselves.

    Read more...

    India’s Max Financial Says Hacker Accessed Customer Data From Its Insurance Unit

    2025-07-02

    TechCrunch: Max Financial Services said its insurance subsidiary Axis Max Life Insurance received communication from an anonymous sender about unauthorized access to its customer data.

    Read more...

    Most Enterprises Can’t Secure AI, Accenture Says

    2025-07-01

    CIO Dive: CIOs are under pressure to move AI projects along faster and demonstrate the corresponding value, but a need for speed doesn’t always translate to sustainable momentum. 

    Read more...

    DOJ Charges 4 North Koreans in $1 Million Crypto Theft From Blockchain Startup

    2025-07-01

    Cointelegraph: Four North Korean nationals were charged in the state of Georgia with wire fraud and money laundering after posing as remote IT workers at US and Serbian blockchain companies and stealing almost $1 million in crypto, prosecutors said.

    Read more...

    Ransomware Reshaped How Cyber Insurers Perform Security Assessments

    2025-07-01

    Dark Reading: The ransomware scourge has forced cyber insurers to re-examine how they use security assessments. While the threat has been around for years, it's only fairly recently that cybercriminals realized how profitable ransomware attacks could be. 

    Read more...

    Global Cybersecurity Market to Worth Over US$ 723.8 Billion By 2033

    2025-06-30

    GlobeNewswire: The global cybersecurity market was valued at US$ 233.4 billion in 2024 and is expected to reach US$ 723.8 billion by 2033, growing at a CAGR of 13.40% during the forecast period.

    Read more...

    Danish Pensions Industry Outlines Proposals to Strengthen Cyber Security

    2025-06-30

    European Pensions: The Danish insurance and pension industries have outlined eight concrete proposals to strengthen cybersecurity, given the country's particular vulnerabilities in this area, according to Insurance and Pension Denmark (I&P Denmark).

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates