Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Two-Thirds of Organizations Plan to Improve Their Cybersecurity in the Wake of Devastating Ransomware Attacks

    2021-06-02

    KnowBe4: With 81% of organizations believing ransomware attacks will become more prevalent in the second half of 2021, nearly everyone is preparing for the worst to come.

    Read more...

    Security Leaders More Concerned About Legal Settlements Than Regulatory Fines

    2021-06-01

    Help Net Security: An overwhelming 90% of security leaders are concerned about group legal settlements following a serious data breach, compared to 85% who are worried about regulatory fines, Egress reveals.

    Read more...

    Reserve Bank Moves to Address Cyber Vulnerability After KPMG Report

    2021-05-31

    RNZ: A report by consultancy KPMG has uncovered shortcomings in the Reserve Bank's data protection practices, which resulted in it becoming a victim of a cyber-attack on the third-party file-sharing application it used to share and store information.

    Read more...

    Know Your Breach: Bergen Logistics

    The target: Bergen Logistics, a U.S based fulfillment provider.

    The take: Personally Identifiable Information including: names, sur names, city, zip code, addresses, order numbers, email addresses, plain-text passwords to customer accounts.

    The attack vector: An unsecured Elasticsearch database server was left online, meaning anyone with an internet connection was able to connect and download the data.

    The exposure of personal information can lead to highly targeted phishing and fraud attacks. More critical was how this firm stored their customer account passwords in plain text on the server with no encryption or protections. Ensuring credentials are adequately and appropriately protected through encryption is an integral part of maintaining a robust cybersecurity posture.

    Read more...

    US Pipelines Ordered to Increase Cyber Defenses After Hack

    2021-05-27

    Yahoo Finance: U.S. pipeline operators will be required for the first time to conduct a cybersecurity assessment under a Biden administration directive in response to the ransomware hack that disrupted gas supplies in several states this month.

    Read more...

    Canada Post Says 950,000 Customers Exposed in Data Breach

    2021-05-27

    Yahoo Finance: Canada's national mail carrier says a malware attack on one of its suppliers has impacted 44 of its biggest corporate customers across the country, and potentially up to nearly one million people.

    Read more...

    Japanese Government Agencies Suffer Data Breaches After Fujitsu Hack

    2021-05-27

    Bleeping Computer: Offices of multiple Japanese agencies were breached via Fujitsu's "ProjectWEB" information sharing tool. Fujitsu states that attackers gained unauthorized access to projects that used ProjectWEB, and stole some customer data.

    Read more...

    Scammers Taking Advantage of COVID-19 to Target Small Businesses

    2021-05-26

    ASIC: ASIC is urging Australians to be wary of scammers using the COVID-19 pandemic to target small businesses. Scammers often target small business owners as they recognise that they are busy and may have limited resources to keep systems safe. Common scams aimed at small businesses are outlined below.

    Read more...

    Hedge Fund CFOs Say Data Demands Will Drive Up Ops Spend

    2021-05-26

    Hedge Week: New research by Intertrust Group — which quizzed 100 CFOs across the UK, Europe, North America and Asia, from hedge funds collectively representing a total AUM of USD7.3 billion spanning a range of strategies – indicates the growing clamour for greater transparency from investors will place increase burdens on hedge funds’ ops teams.

    Read more...

    Tessian Raises $65M to Accelerate its Mission of Preventing Human Risk in Global Enterprises

    2021-05-26

    Help Net Security: Human Layer Security company Tessian announces that it has raised $65 million in Series C venture capital funding to accelerate its mission of quantifying and preventing human risk in global enterprises, and empowering people to do their best work without security getting in the way.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates