Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Australia, UK to Jointly Target State-based Actors and Ransomware Groups

    2022-01-20

    IT News: Australia and the United Kingdom have signed a pact to crack down on state-based actors, ransomware groups and other "malign actors" that use cyber attacks to "undermine freedom and democracy".

    Read more...

    McAfee Enterprise and FireEye Are Now Called Trellix

    2022-01-18

    ZDNet: During 2021, Symphony Technology Group (STG) picked up McAfee Enterprise for $4 billion in March, and followed it up in June with a $1.2 billion purchase of FireEye. With the merger of the two cybersecurity firms completed in October, the companies have been given a new name.

    Read more...

    Ongoing Demand for Cybersecurity Will Boost Megatrend in 2022

    2022-01-18

    Funds Europe: The cybersecurity megatrend is set to continue in 2022 as demand for cybersecurity solutions remain “relatively constant” after some “major hacks” in 2021, according to Christopher Gannatti, global head of research at WisdomTree.

    Read more...

    FBI, US Agencies Look Beyond Indictments in Cybercrime Fight

    2022-01-18

    U.S. News: The FBI and other federal agencies are increasingly looking to counter cyber threats through tools other than criminal indictments, the head of the bureau's cyber division said in an interview with The Associated Press.

    Read more....

    Know Your Breach: FCI

    The Target: Fertility Center of Illinois

    The Take: Exposure of Personally Identifiable Information including: full names, social security numbers, financial information, medical data, and health insurance policy numbers, employee numbers, and passport numbers.

    The Vector: The threat actors were able to access a third-party server where FCI’s data was stored, and as the firm did not employ proper authentication tools, the attackers were able to freely view and download the sensitive information. 

    This breach highlights the critical nature of employing robust practices of credential management, user authentication and validation around all points of access. An unprotected point of entry on a key piece of equipment like a server can lead to a breach with a cascading effect on data security. Furthermore, firms must be aware of where their data is stored, be that on their own sites or a third-party, and take steps to ensure it is secure.

    Read more...

    The Impact of Cybersecurity Regulations on the Financial Services Industry in 2022

    2022-01-13

    JDSUPRA: Following the SolarWinds and the Colonial Pipeline cyberattacks, the Biden Administration emphasized a shift toward mandatory cybersecurity requirements.

    Read more...

    Apple, Amazon Executives to Meet with White House to Discuss Software Security

    2022-01-13

    The Hill: Executives from Apple, Amazon and other top tech firms are meeting at the White House to discuss software security with the administration after major cyberattacks last year. 

    Read more...

    Ransomware, Supply Chain, and Deepfakes: The Top Threats the Finance Industry Needs to Prepare for

    2022-01-12

    Help Net Security: The finance industry is constantly targeted by numerous threat actors, and they are always innovating and trying new techniques (such as deepfakes) to outsmart security teams and breach an organization’s network.

    Read more...

    FCC Proposes Stricter Requirements for Reporting Data Breaches

    2022-01-12

    Tech Crunch: The Federal Communications Commission is the next US regulator hoping to hold companies more accountable for data breaches. Chairwoman Jessica Rosenworcel has shared a rulemaking proposal that would introduce stricter requirements for data breach reporting.

    Read more...

    Last Year Was a Record Year for Attacks, and Log4j Made It Worse

    2022-01-11

    ZDNet: Cybersecurity firm Check Point Research has released new data from 2021 showing that among their customers, there was a significant increase in overall cyberattacks per week on corporate networks compared to 2020.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates