Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    NBIM Suggests ‘Continuity Venues’ for Bourses After Cyberattacks

    2021-03-22

    IPE: The manager of Norway’s sovereign wealth fund has put forward the idea that the main stock exchanges around the world should be required to have emergency facilities where trading can continue if they suffer a major technological failure or cyberattack.

    Read more...

    Remote Work Makes Cybersecurity A Top Worry for CEOs

    2021-03-22

    ZDNet: UK CEOs have revealed their top concerns after a year that saw remote work become the norm, with accelerated digital transformation and highly visible cyberattacks. 

    Read more...

    Know Your Breach: SendGrid

    The target: SendGrid, a Colorado-based email marketing company.

    The take: 400,000 unique login credentials of: email address, password, IP address, and physical location. 

    The attack vector: The attacker used a combination of previously hacked accounts on the SendGrid platform to send fake Zoom invites. As SendGrid was known as a trusted SMTP provider, the fake messages had a much higher chance of reaching their targets, passing through some email protection.

    This incident highlights the importance of critical thinking as a component of social awareness training for staff. In the event that a trusted account is compromised, analysis of the context of these requests becomes the critical – is a meeting invite expected, does the timeline and subject matter line up with expectations? While messages originating from fraudulent e-mail addresses are easier to spot, they are not the only vector for phishing attacks – each item in the inbox must be approached with the same level of caution.

    Read more...

    Watchdog 'Almost Certain' Microsoft Exchange Security Gap Has Canadian Victims

    2021-03-17

    Yahoo Finance: Canada's main cybersecurity watchdog said Wednesday that it's likely too late to prevent criminals from using a vulnerability in Microsoft Exchange email servers, unless system administrators have already installed software patches that were issued in early March.

    Read more...

    Cybersecurity Requirements Provide New Opportunity for CPAs

    2021-03-17

    Journal of Accountancy: CPAs have a new opportunity to act as third-party assessors of the cybersecurity maturity of U.S. defense contractors as they work to comply with new regulations that have been created to combat cyberthreats.

    Read more...

    29% of Cyber Threats Previously Unknown, HP Research Finds

    2021-03-17

    Zawya: HP Inc. released its new Quarterly Threat Insights Report, providing analysis of real-world attacks against customers worldwide. The report found that 29% of malware captured was previously unknown* – due to the widespread use of packers and obfuscation techniques by attackers seeking to evade detection. 88% of malware was delivered by email into users’ inboxes, in many cases having bypassed gateway filters.

    Read more...

    ‘New Normal’ Requires New Security Measures

    2021-03-17

    IT Web: It goes without saying that the COVID-19 pandemic has been the driver of a massive increase in remote working. This can, in many ways, be viewed as a win-win situation for companies and staff. After all, employees save commuting time while enjoying added flexibility and greater productivity. Meanwhile, organisations reduce both costs and turnover rates.

    Read more...

    Ransomware Attacks On the Rise, IIROC Warns

    2021-03-16

    Investment Executive: In a notice to the industry, the self-regulatory organization said that it has seen an increase in cyber attacks targeting IIROC firms with malware that infects and encrypts devices and demands a ransom for the return of the locked data.

    Read more...

    Private Markets: Cybersecurity Risk In Fund Administration

    2021-03-15

    Funds Europe: Last year’s Sunburst cyber-attack against public and private organisations worldwide acted as a reminder of the growing sophistication of cybercrime and the need for solid cybersecurity.

    Read more...

    UK Plans ‘Full Spectrum’ Approach to National Cyber Security

    2021-03-15

    Computer Weekly: The government is to set out a new “full spectrum” approach to the UK’s national cyber security capabilities in this week’s Integrated Review of Security, Defence, Development and Foreign Policy, which is set to be published.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates