Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Drawbridge Sees Strong Growth in 2020

    2020-10-06

    Hedge Week: Drawbridge has continued to invest in its people, technology and customers throughout the year, working closely with clients to help them ensure security, continuity and safety during the unprecedented times that have resulted from Covid-19.

    Read more...

    New Research Finds Bugs in Every Anti-Malware Product Tested

    2020-10-06

    DarkReading: CyberArk tested products from multiple major security vendors, including Kaspersky, Symantec, Trend Micro, McAfee, and Check Point Software Technologies, and says it found vulnerabilities in every single one.

    Read more...

    New Research Shows Companies With Strong Cybersecurity Outperform the Market By Up To 7%

    2020-10-06

    Cision: BitSight, the Standard in Security Ratings, and Solactive, a German index engineering firm, today released new research demonstrating that a company's cybersecurity performance is an indicator of business performance.  Analysis shows that indices composed of well-performing BitSight-rated companies outperform their respective benchmarks by 1% to 2% annually.  For certain sectors, such as U.S. Technology, well-rated companies outperform the benchmark by 7% per year. The findings are an endorsement for today's introduction of the Solactive BitSight Cyber Risk Index, a financial index that will enable investors to invest in companies who are top cybersecurity performers as measured by BitSight.

    Read more...

    SBAI Publishes a Toolbox Memo on Cash Handling & Cyber Security

    2020-10-06

    Institutional Asset Manager: Cyber-enabled fraud attempts are escalating and evolving, and the current remote working environment has created additional vulnerabilities that firms need to address. The memo, produced by the SBAI’s Governance Working Group, provides guidance on key controls that help protect managers’ payment processes. It also can be used as a tool for investors to evaluate these controls during due diligence.

    Read more...

    Six Cybersecurity Threats the Financial Services Sector Faces

    2020-10-05

    Security Magazine: Security teams in the financial services sector are experiencing even more exacting demands as they defend their organizations in a world under a new and unexpected threat — a global pandemic, says a new Accenture report, "2020 Future Cyber Threats: The latest extreme but plausible threat scenarios in financial services."

    Read more...

    Bottomline and Dow Jones Partner to Combat Financial Crime

    2020-10-05

    Institutional Asset Manager: Dow Jones’s risk data, including politically exposed persons (PEPs), sanctions lists and adverse media entities for the UK, Europe and the Asia Pacific, will flow through Bottomline’s cyber fraud and risk management platform. The additional intelligence will help identify internal and external threats and protect against criminal activity. The data inclusion can also help banks and corporates avoid incurring regulatory fines and reputational damage that often accompany fraud incidents by enabling them to identify suspicious transactions and stop payments fast.

    Read more...

    Know Your Breach: BrandBQ

    The target: BrandBQ, a European fashion retailer. 

    The take: 7 million customer records of personally identifiable information including: full names, email addresses, home addresses, date of birth, phone number, and payment records.

    The attack vector: The data was exposed on an unencrypted and unsecured Elasticsearch server meaning anyone with an internet connection could have found the information and downloaded a copy. Along with customer information, an additional 50,000 records of relating to contractors who worked with BrandBQ were also stored on the server, exposing their purchase information and correspondence. Further mixed in were API logs relating to their mobile app, greatly increasing the range of possible exposure to over 500,000 affected users. 

    Credential management and proper security around storage of data is critical for every business. In this case, the mixing of data all kept in one place compounded the severity of the breach as not only were BrandBQ’s customers made into vulnerable phishing targets, but their contractors are now also extremely susceptible to Business Email Compromise scams.

    Read more...

    Companies May Be Punished for Paying Ransoms to Sanctioned Hackers - U.S. Treasury

    2020-10-01

    Reuters: Facilitating ransomware payments to sanctioned hackers may be illegal, the U.S. Treasury said on Thursday, signaling a crackdown on the fast-growing market for consultants who help organizations pay off cybercriminals.

    Read more...

    To Hunt Hackers, FBI Works More Closely with Spy Agencies

    2020-10-01

    National Post: America’s top law enforcement agents and spies are teaming up under one roof as part of a new federal strategy to fight foreign hackers, senior FBI officials said in an interview.

    Read more...

    Anthem to Pay Nearly $40 Mln to Settle Data Breach Probe by U.S. States

    2020-09-30

    Financial Post: Anthem Inc said it would pay $39.5 million as part of a settlement with U.S. states attorneys general following an investigation into a massive cyber-attack at the company in 2015.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates