Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      US Treasury Thwarted Attack by Russian Hacker Group Last Month, Says Official

      2022-11-01

      Malay Mail: The US Treasury last month repelled cyber attacks by a pro-Russian hacker group, but the incident caused little to no disruption and confirmed that the department’s stronger approach to financial system cybersecurity was working, a US Treasury official said.

      Read more...

      Know Your Breach: Thomson Reuters

      The Target: Thomson Reuters, a multi-national media conglomerate.

      The Take: Exposure of sensitive company login credentials, including plain-text passwords to some third-party vendors, corporate and legal information, and logs which contain the email addresses of account holders who recently reset their passwords.

      The Vector: A misconfigured Elasticsearch server was accessible over the internet to anyone with a connection.

      This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture, especially maintaining correct access configurations. The data exposed here can also lead to pivot attacks and targeted phishing. Multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

      Read more...

      Versa Raises $120M for Its Software-defined Networking and Security Stack

      2022-10-27

      Techcrunch: Networking and cybersecurity firm Versa announced that it raised $120 million in a mix of equity and debt led by BlackRock, with participation from Silicon Valley Bank. CEO Kelly Ahuja tells TechCrunch that the proceeds, which bring Versa’s total capital raised to $316 million, will be put toward go-to-market efforts and scaling the company. He demurred when asked what percentage of the financing was equity versus debt.

      Read more...

      Cyber Security: Recession Proof?

      2022-10-27

      Financier Worldwide: Amid ongoing economic and geopolitical challenges, the cyber security sector remains strong, according to a new report from ICON Corporate Finance.

      Read more...

      Cybersecurity Teams Are Reaching Their Breaking Point. We Should All Be Worried

      2022-10-25

      ZDNet: A global study of 1,100 cybersecurity professionals by Mimecast found that one-third are considering leaving their role in the next two years due to stress and burnout.

      Read more...

      The Global Artificial Intelligence in Cybersecurity Market Size Is Expected to Reach $57.1 Billion by 2028, Rising At a Market Growth of 24.5% CAGR During the Forecast Period

      2022-10-25

      Global Newswire: AI-powered systems can be set up to automatically respond to dangers and combat online threats more quickly. Analyzing and improving cyber risks as well as cyber-attacks is no more a task on a human scale as the business attack surface develops and changes. To accurately quantify risk, up to highly-varying signals must be handled, based on the scale of the organization.

      Read more...

      Cybersecurity M&A Bustling Again in Q4 After a Bleak Q3

      2022-10-25

      S&P Global: Global cybersecurity transaction volume dropped to 33 deals between July 1 and Sept. 30, compared to 45 deals in the second quarter and 58 in the third quarter of 2021, according to data from 451 Research.

      Read more...

      Here’s What Regulators Will Want Boards to Know About Cybersecurity

      2022-10-24

      World Economic Forum: New United States Securities and Exchange Commission (SEC) rulemaking makes cyber risk reporting and business resilience planning a key component of effective board governance. 

      Read more...

      FTC Seeks to Hold Drizly CEO Accountable for Alleged Security Failures, Even if He Moves to Another Company

      2022-10-24

      CNBC: In a new proposed settlement, the Federal Trade Commission is seeking to hold a tech CEO accountable to specific security standards, even if he moves to a new company.

      Read more...

      Know Your Breach: Microsoft

      The Target: Microsoft, one of the world’s leading computer hardware and software companies. 

      The Take: Exposure of Personally Identifiable Information belonging to over 65,000 business entities. The data included: names, email addresses, email content, company name, phone numbers, Statement of Work documents, product offers, and more. 

      The Vector: A misconfigured Microsoft server was accessible over the internet to anyone with a connection.

      This breach is a stark reminder that authentication controls are a critical piece in an overall robust cybersecurity posture, including maintaining correct access configurations. In addition, multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates