Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Imperva

    The target: Imperva, cyber-security firm based out of California.

    The take: A complete copy of their customer information database.

    The attack vector: Imperva uploaded a snapshot of its customer database for testing. However, in an unrelated incident, they left one of their internal systems publicly accessible on the internet from which the attacker stole key to the recently uploaded database. Using the key, the hacker was able to download a copy of the customer information.

    After Imperva adopted cloud technologies to scale their infrastructure to meet increasing needs, they failed to account for the increased risk of this strategy. Cyber-security diligence applies at all levels of scale including times of expansion and investment in new technology.

    Read more...

    Police Database Flagged 9,000 Cybercrime Reports as 'Security Risk'

    2019-10-24

    The Guardian: Thousands of reports of cybercrime were quarantined on a police database instead of being investigated because software designed to protect the computer system labelled them a security risk.

    Read more...

    61% of Business Leaders Think Hackers Are Winning War Against Cyber Crime… and Many Are Ignoring the Problem, Reveals RSM Study

    2019-10-24

    Cision: A pan European survey of almost 600 successful businesses* has revealed that 61% of business leaders on the board of their company believe that in the war against cybercrime the hackers are more sophisticated than the software developers. 

    Read more...

    Cyber Attack Hits Prominent HedgeFund, Endowment, and Foundation

    2019-10-24

    Institutional Investor: Hackers breached the official email accounts of investment executives at the Kansas University endowment and Community Foundation of Texas late last month. This week, attackers hit hedge fund Arena Investors, sending a malicious phishing email from its chief operating officer’s address.

    Read more...

    Temasek Flags Challenges of Investing in Cybersecurity

    2019-10-24

    Asian Investor: With cybersecurity challenges set to keep mounting, investing into the area seems a sensible move, not least because it offers asset owners a potential inside track to protecting themselves.

    But Asia-based investors looking to do so face several hurdles, in addition to the high current valuations, something Singapore state investor Temasek is well aware of.

    **Article may require free sign-in to read**

    Read more...

    The NCSC Defends Nation Against More Than 600 Cyber Attacks

    2019-10-23

    NCSC: The National Cyber Security Centre (NCSC) has defended the UK against more than 600 cyber attacks in the past year – bringing the total number to almost 1,800, new figures show.

    Read more...

    Europol and Palo Alto Networks Expand Their Cooperation in Tackling Cybercrime

    2019-10-23

    Europol: Europol and Palo Alto Networks have signed a Memorandum of Understanding (MoU) to expand their collaborative efforts in combating cybercrime and working together to make cyberspace safer for citizens, businesses and governments.

    Read more...

    Thwarting Cybersecurity Attacks Depends on Strategic, Third-Party Investments

    2019-10-22

    Homeland Security News Wire: Companies interested in protecting themselves and their customers from cyber-attacks need to invest in themselves and the vendors that handle their data, according to new research from American University.

    Read more...

    Know Your Breach: FireEye

    The target: FireEye, a publicly traded cybersecurity company in California.

    The take: Corporate documents, details on client contracts and licenses, and personal login credentials.

    The attack vector: Attackers used credentials exposed in public data breaches to access the personal accounts of a security analyst employed by FireEye. Once his accounts had been compromised, they were able to exploit his business use of those personal accounts to obtain sensitive information belonging to his employer.

    On an individual level – this attacks highlights the importance of changing passwords and rotating credentials, particularly in the wake of a publicized credential breach. At the firm level - once confidential and sensitive information leaves a firm’s information systems, it’s completely outside of their control. Security policies must reflect zero tolerance for use of personal accounts to communicate on behalf of the firm or store/transfer sensitive and proprietary information.

    Read more...

    Why it Pays Asset Owners to Invest in Cybersecurity

    2019-10-17

    Asian Investor: Cyber criminals continue to develop a variety of smart tools to plot hacking schemes and data breaches in today’s intricately connected digital world, in which almost everyone’s data is stored, processed and accumulated. Anybody can become a target.

    **Article may require free sign-in to read**

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates