Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Conduent

    The Target: Conduent is an American business process outsourcing (BPO) company that provides digital platforms and services for governments and enterprises.

    The Take: The data breach notifications state that people's name, Social Security Numbers, full date of birth, health insurance policy or ID number, or medical information was exposed.

    The Vector: An investigation into the scope of the data breach has now determined that the attack impacted millions of people. Furthermore, although the breach was discovered in January 2025, the environment had been compromised much earlier, on October 21, 2024.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    FCC Will Vote to Scrap Telecom Cybersecurity Requirements

    2025-10-30

    Yahoo News: The Federal Communications Commission will vote next month on whether to eliminate cybersecurity requirements for telecom carriers that the commission enacted under its previous leadership following sweeping Chinese government cyberattacks on telecoms.

    Read more...

    AI Security Firm Polygraf Raises $9.5 Million in Seed Funding

    2025-10-29

    SecurityWeek: The funding round was led by Allegis Capital, with participation from Alumni Ventures, DataPower VC, Domino Ventures and others. In addition to enabling Polygraf AI to improve its product, the new investment will be used for go-to-market efforts. 

    Read more...

    Ransomware Attacks Jumped 28% in September

    2025-10-28

    CFO Dive: Salesforce and Dell are among major companies that have reported ransomware attacks this year, according to news reports.

    Read more...

    70% of CISOs Say Internal Conflicts More Damaging Than Cyberattacks

    2025-10-28

    CSO Online: Roughly 70% of security executives believe internal conflicts during a crisis cause more problems than the cyberattack itself.

    Read more...

    CFOs Double Down on AI and Cybersecurity as Tariffs Emerge as Major New Threat

    2025-10-28

    Yahoo News: Tariffs and trade barriers have surged to become a top-five concern for America's Chief Financial Officers (CFOs) in 2025, with 66% expecting negative impacts on their organizations; a dramatic new challenge that wasn't even measured as a distinct priority in 2024. 

    Read more...

    Why Cybersecurity Needs to Be Treated as a Core Value Driver in Every Deal

    2025-10-27

    Mergers & Acquisitions (Opinion Piece):That’s a costly mistake, because in today’s risk landscape, few issues can affect enterprise value as quickly and forcefully as a cybersecurity incident. 

    Read more...

    UN Member States Sign Cybercrime Agreement Despite Industry, Activist Opposition

    2025-10-27

    Cybersecurity Dive: Dozens of countries signed a United Nations anti-cybercrime agreement, moving the accord forward despite concerns from U.S. businesses and human-rights groups about its unintended consequences.

    Read more...

    Know Your Breach: Sotheby’s

    The Target: Sotheby’s is a leading global auction house for fine art and high-value items, as well as an asset-backed lending services provider.

    The Take: According to a filing the organization submitted to Maine’s AG office, the data exposed in the incident includes full names, Social Security numbers (SSNs), and financial account information.

    The Vector: “On July 24, 2025, Sotheby’s became aware that certain Sotheby’s data appeared to have been removed from our environment by an unknown actor,” reads the letter sent to impacted individuals.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    PE Portfolios Have Been Significantly Impacted by Cyber Security, Sustainability, or Geopolitical Risks

    2025-10-23

    European Business Magazine: Over a third of infrastructure private equity portfolios have been significantly impacted by cyber security, sustainability, regulatory, or geopolitical risks in the past three years, according to the 2025 Investor Sentiment Report: Forces of Change, published by global corporate intelligence and cyber security consultancy S-RM.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates