Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Entrust

    The Target: Entrust, a digital cybersecurity firm focused on identity management.

    The Take: Sensitive corporate internal data from Entrust’s own IT systems.

    The Vector: The attacker used previously compromised Entrust employee credentials to access their internal systems, posing as an authenticated user. 

    This breach is a critical reminder of the importance of credential authentication and password hygiene. Enforced multi-factor authentication could have prevented the Entrust breach, and enforcing this multi-factor authentication, along with reasonably regular forced password resets, password length and complexity rules, are effective strategies to mitigate these kinds of breaches.

    Read more...

    5 Best Practices to Ramp Up Cybersecurity At Private Equity And VC Firms

    2022-07-27

    Forbes: Private equity (PE) and venture capital (VC) firms have become prime targets for cyberattacks. Perhaps unsurprisingly, cybercriminals tend to gravitate toward money, and there’s a lot of it in private equity. The numbers are mind-boggling: The average midmarket fund encounters more than 10,000 cyberattacks daily.

    Read more...

    Average Data Breach Costs Hit a Record $4.4 Million, Report Says

    2022-07-27

    CNet: The average cost of a data breach rose to an all-time high of $4.4 million this year, according to the IBM Security report released Wednesday. That marked a 2.6% increase from a year ago and a 13% jump since 2020.

    Read more...

    LockBit Claims Ransomware Attack on Italian Tax Agency

    2022-07-26

    Bleeping Computer: Italian authorities are investigating claims made by the LockBit ransomware gang that they breached the network of the Italian Internal Revenue Service (L'Agenzia delle Entrate).

    Read more...

    BlackRock-Backed Round Values Cyber Firm Acronis at $3.5 Billion

    2022-07-26

    BNN Bloomberg: Cybersecurity provider Acronis raised $250 million in new funding from institutional investors earlier this year to expand its business, including through acquisitions and hiring.

    Read more...

    ‘Cryptojacking’ Rises 30% to Record Highs Despite Crypto Slump: Report

    2022-07-26

    Coin Telegraph: New research shows that despite falling digital asset prices, cryptojacking has reached record levels in the first half of 2022.

    Read more...

    Hackers Scan for Vulnerabilities Within 15 Minutes of Disclosure

    2022-07-26

    Bleeping Computer: System administrators have even less time to patch disclosed security vulnerabilities than previously thought, as a new report shows threat actors scanning for vulnerable endpoints within 15 minutes of a new CVE being publicly disclosed.

    Read more...

    T-Mobile Agrees to Pay Customers $350 Million in Settlement Over Massive Data Breach

    2022-07-25

    CNN: T-Mobile has agreed to pay $350 million to settle multiple class-action suits stemming from a data breach disclosed last year affecting tens of millions of people.

    Read more...

    Know Your Breach: Morgan Hunt

    The Target: Morgan Hunt, a British recruitment agency.

    The Take: Exposure of Personally Identifiable Information including: names, contact details, identity documents, proof address documents (bank or building statements, national insurance number, and date of birth.

    The Vector: The attackers breached a third-party software developer of Morgan Hunts who were storing access credentials to their database with no authentication or access controls.

    This breach is a stark reminder that authentication controls are a critical piece in an overall robust cybersecurity posture. Furthermore, all steps should be taken by a firm to ensure any third-party vendor who can access their data is employing the requisite methods. Enforcing multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s customer base.

    Read more...

    Why Data Now Underpins the Future Security of Your Organization

    2022-07-21

    Tech Radar: As the number of different digital touchpoints grows exponentially as hybrid working(opens in new tab) cements itself, so too have the number of attack surfaces available for cybercriminals to exploit. In a world where cybercrime is evolving at a rapid pace and the threat landscape remains unpredictable and constantly shifting, one thing is clear: data increasingly underpins future security.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates