Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    FTC Seeks to Hold Drizly CEO Accountable for Alleged Security Failures, Even if He Moves to Another Company

    2022-10-24

    CNBC: In a new proposed settlement, the Federal Trade Commission is seeking to hold a tech CEO accountable to specific security standards, even if he moves to a new company.

    Read more...

    Know Your Breach: Microsoft

    The Target: Microsoft, one of the world’s leading computer hardware and software companies. 

    The Take: Exposure of Personally Identifiable Information belonging to over 65,000 business entities. The data included: names, email addresses, email content, company name, phone numbers, Statement of Work documents, product offers, and more. 

    The Vector: A misconfigured Microsoft server was accessible over the internet to anyone with a connection.

    This breach is a stark reminder that authentication controls are a critical piece in an overall robust cybersecurity posture, including maintaining correct access configurations. In addition, multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    Antony Blinken’s Silicon Valley Visit Underscores US Cybersecurity Concerns

    2022-10-20

    The Guardian: The US secretary of state visited Silicon Valley this week, on a trip that experts say highlights the Biden administration’s growing concerns over cybersecurity and officials’ push to collaborate more closely with the US’s powerful tech industry.

    Read more...

    Banco Santander and Forgepoint Capital Announce Strategic Alliance to Advance Cybersecurity Investment and Innovation Globally

    2022-10-20

    Dark Reading: Banco Santander, one of the largest banks in the world with over 157 million customers, and Forgepoint Capital, one of the world’s leading venture capital firms focused on cybersecurity, announced today a strategic alliance to drive cybersecurity investment and innovation globally.

    Read more...

    Cybersecurity Workforce Gap Grows by 26% in 2022

    2022-10-20

    Infosecurity: The global cybersecurity workforce gap has increased by 26.2% compared to 2021, with 3.4 million more workers needed to secure assets effectively, according the (ISC)2 2022 Cybersecurity Workforce Study.

    Read more...

    Passwords Still Dominate, and Are Causing Headaches for Everyone

    2022-10-19

    ZDNet: While Google, Microsoft and Apple roll out passwordless passkey functionality for their platforms, most people are still dependent on passwords.

    Read more...

    Australia's No. 1 Health Insurer Says Hacker Stole Patient Details

    2022-10-19

    U.S. News: Australia's biggest health insurer said a criminal had apparently stolen customers' medical information as part of a massive breach of data, fuelling concern about a wave of high-profile cyber attacks.

    Read more...

    Ottawa’s Cybersecurity Bill Flawed and Should Be Amended, New Report Warns

    2022-10-18

    Global News: A new research report says federal cybersecurity legislation is so flawed it would allow authoritarian governments around the world to justify their own repressive laws.

    Read more...

    Gen Z, Millennial Workers Are Bigger Cybersecurity Risks Than Older Employees

    2022-10-18

    Dark Reading: A new survey shows Generation Z and millennials, younger workers who have grown up as digital natives, are surprisingly more careless about their employer's cybersecurity than their senior Gen X and baby boomer colleagues. 

    Read more...

    Know Your Breach: Optus

    The target: Optus, an Australian Telecommunications company

    The take: Personal information for up to 10 million customers, including names, email addresses, postal addresses, phone numbers, dates of birth, and some passport numbers, driver’s license numbers and Medicare numbers.

    The attack vector: Reports suggest that an application programming interface (API) was exposed to the public internet and did not enforce any kind of authentication to access customer data.

    Where sensitive data is handled, controls must be put in place to authenticate access, and verify an individual’s authorization to access that data. Failing to ensure that such access is carefully controlled is akin to leaving the window open.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates