Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Know Your Breach: Microsoft

      The Target: Microsoft, one of the world’s leading computer hardware and software companies. 

      The Take: Exposure of Personally Identifiable Information belonging to over 65,000 business entities. The data included: names, email addresses, email content, company name, phone numbers, Statement of Work documents, product offers, and more. 

      The Vector: A misconfigured Microsoft server was accessible over the internet to anyone with a connection.

      This breach is a stark reminder that authentication controls are a critical piece in an overall robust cybersecurity posture, including maintaining correct access configurations. In addition, multi-factor authentication, reasonably regular forced password resets, and password length and complexity rules are all effective strategies to mitigate these kinds of breaches to protect a firm’s data.

      Read more...

      Antony Blinken’s Silicon Valley Visit Underscores US Cybersecurity Concerns

      2022-10-20

      The Guardian: The US secretary of state visited Silicon Valley this week, on a trip that experts say highlights the Biden administration’s growing concerns over cybersecurity and officials’ push to collaborate more closely with the US’s powerful tech industry.

      Read more...

      Banco Santander and Forgepoint Capital Announce Strategic Alliance to Advance Cybersecurity Investment and Innovation Globally

      2022-10-20

      Dark Reading: Banco Santander, one of the largest banks in the world with over 157 million customers, and Forgepoint Capital, one of the world’s leading venture capital firms focused on cybersecurity, announced today a strategic alliance to drive cybersecurity investment and innovation globally.

      Read more...

      Cybersecurity Workforce Gap Grows by 26% in 2022

      2022-10-20

      Infosecurity: The global cybersecurity workforce gap has increased by 26.2% compared to 2021, with 3.4 million more workers needed to secure assets effectively, according the (ISC)2 2022 Cybersecurity Workforce Study.

      Read more...

      Passwords Still Dominate, and Are Causing Headaches for Everyone

      2022-10-19

      ZDNet: While Google, Microsoft and Apple roll out passwordless passkey functionality for their platforms, most people are still dependent on passwords.

      Read more...

      Australia's No. 1 Health Insurer Says Hacker Stole Patient Details

      2022-10-19

      U.S. News: Australia's biggest health insurer said a criminal had apparently stolen customers' medical information as part of a massive breach of data, fuelling concern about a wave of high-profile cyber attacks.

      Read more...

      Ottawa’s Cybersecurity Bill Flawed and Should Be Amended, New Report Warns

      2022-10-18

      Global News: A new research report says federal cybersecurity legislation is so flawed it would allow authoritarian governments around the world to justify their own repressive laws.

      Read more...

      Gen Z, Millennial Workers Are Bigger Cybersecurity Risks Than Older Employees

      2022-10-18

      Dark Reading: A new survey shows Generation Z and millennials, younger workers who have grown up as digital natives, are surprisingly more careless about their employer's cybersecurity than their senior Gen X and baby boomer colleagues. 

      Read more...

      Know Your Breach: Optus

      The target: Optus, an Australian Telecommunications company

      The take: Personal information for up to 10 million customers, including names, email addresses, postal addresses, phone numbers, dates of birth, and some passport numbers, driver’s license numbers and Medicare numbers.

      The attack vector: Reports suggest that an application programming interface (API) was exposed to the public internet and did not enforce any kind of authentication to access customer data.

      Where sensitive data is handled, controls must be put in place to authenticate access, and verify an individual’s authorization to access that data. Failing to ensure that such access is carefully controlled is akin to leaving the window open.

      Read more...

      Supply Chain Hacks Are On the Rise. But Most Companies Aren't Prepared

      2022-10-13

      ZDNet: The UK's cybersecurity agency has told firms to do more to protect themselves from attacks on their supply chains. 

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates