Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Women In Cybersecurity Think Equality Will Take At Least 10 Years

    2021-03-04

    Beta News: The poor state of diversity in the cybersecurity industry is shown by a new report in which 57 percent of women working in the industry believe it will take at least a decade for them to be treated as equals to men, with 20 percent believing it will never happen.

    Read more...

    Information Shield Enables Cyber Insurance Portfolio Risk Measurement

    2021-03-04

    Cision: Information Shield - a leading provider of cyber security compliance software – today announced support for the new Cyber Insurance Risk Framework. Using the ComplianceShield ™ platform and Cyber Risk Score ™ methodology, insurance providers can gain measurable insight into the cyber posture and inherent risk of their insured base. The new framework was created by the New York Department of Financial Service (NYDFS) to help reduce systematic cyber risk across the insurance industry.

    Read more...

    Most Phishing Emails Are After Credentials

    2021-03-04

    KnowBe4: 57% of phishing emails in 2020 were designed for stealing credentials, according to Cofense’s most recent Annual State of Phishing Report. Meanwhile, just 12% of phishing attacks last year were used for delivering malware. Cofense believes this is because credential phishing emails are better at bypassing email security filters than emails with malicious attachments or download links. Likewise, conversational phishing attacks, like business email compromise (BEC), have grown more popular.

    Read more...

    Data Extortion Ransomware Attacks On Financial Sector Up 350 Percent During Covid-19 Pandemic

    2021-03-04

    Institutional Asset Manager: Data from the CrowdStrike Intelligence team reveals a surge in ransomware attacks during the pandemic, with data extortion becoming the most used attack method for all sectors – with 1,430 incidents reported globally in 2020.

    Read more...

    MAS, Banks Association Issue Paper On Mitigating Remote Working Risks

    2021-03-02

    The Straits Times: Extensive remote working arrangements open up financial institutions to multiple risks - some of them related to daily operations and information security and technology, and others to fraud and staff misconduct.

    Read more...

    Microsoft, NSA Advocate Zero Trust Cybersecurity Model

    2021-03-01

    IT Pro Portal: The zero trust approach, which operates under the assumption that the network has already been breached and that every device and app needs authorization, is said to be the most efficient way to tackle advanced cybersecurity threats.

    Read more...

    Know Your Breach: West Bengal Health and Welfare Department

    The target: The Health and Welfare Department of West Bengal, India

    The take: 8 million COVID-19 test results including personally identifiable information such as: name, age, address, and positive or negative test results.

    The attack vector: The breach revolves around the health authority’s reporting system, whereby individuals who had been tested for COVID-19 received links by SMS with a unique URL to access their test results by web. It was discovered that there was no authentication in place on the reporting system, and that by incrementing the ID number included in the URL, anyone with internet access could access all test results for the state.

    This example serves once again to highlight the huge risks of adopting a ‘security by obscurity’ model. When administering a public facing portal which provides access to sensitive information, authentication controls are not optional – it is simply inadequate to make all records publicly available and trust that the uniqueness of the URL will protect the sensitive data of organizations or individuals.

    Read more...

    HYAS Closes $16 Million Series B Funding Round Led by S3 Ventures for Cyberattack Intercept Technology

    2021-02-25

    GlobeNewswire: HYAS, a leader in threat intelligence, adversary infrastructure, and network defense, today announced that it had closed a $US16 million round of funding led by Austin, TX based, S3 Ventures. The funds will be used to accelerate product development and global market expansion for the company’s cyber attack infrastructure identification and blocking technology.

    Read more...

    Hundreds of Workers At Cybersecurity Agency Vote to Strike

    2021-02-24

    CBC: Hundreds of workers at Canada's foreign signals intelligence agency have voted to strike — a move that comes as the threat of state-sponsored cyber attacks related to the pandemic appears to be rising.

    Read more...

    The World Is Facing A 'Global Cybercrime Pandemic'

    2021-02-24

    Tech Radar: The world is facing a cybercrime pandemic, a new report on the Covid-19 security landscape suggests. According to research from security firm Check Point, more than 100,000 malicious websites are currently active each day, as well as 10,000 different malware strains. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates