Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Credit Suisse Faces Fresh Scrutiny Over Culture After Client Data Leaks

    2022-02-22

    CNBC: Credit Suisse is facing fresh scrutiny from Swiss regulators and the European Parliament after leaked data purported to show the bank had served human rights abusers, corrupt politicians and businessmen under sanctions for decades.

    Read more...

    Know Your Breach: Internet Society

    The Target: The Internet Society or ISOC, a non-profit organization whose mission is to keep the internet open source and secure.

    The Take: Exposure of Personally Identifiable Information of 80,000 records including: full names, email addresses, physical mailing addresses, and login information.

    The Vector: A third-party vendor misconfigured a database server, leaving it open and accessible by anyone with an internet connection.

    It is important to employ all-encompassing credential management, user authentication and validation, as much possible, on third-party vendors which have access to a firm’s data. An unprotected point of entry on a key piece of equipment like a server can lead to a breach with a cascading effect on data exposure.

    Read more...

    Record Levels of Investment for UK's £10.1 Billion Cyber Security Sector

    2022-02-17

    Business Telegraph: Britain’s tech sector continues to break records as new government data shows more than 1,800 cyber security firms generated a total of £10.1 billion in revenue in the most recent financial year, a 14 per cent increase from the previous financial year.

    Read more...

    Justice Department Announces First Director of National Cryptocurrency Enforcement Team

    2022-02-17

    The United States Department of Justice: The Justice Department today announced the selection and appointment of Eun Young Choi to serve as the first Director of the National Cryptocurrency Enforcement Team (NCET).

    Read more...

    Hackers to Face 25 Years in Jail for Cyber Attacks on Australia's National Infrastructure

    2022-02-17

    IT Pro: Hackers could face up to 25 years in jail if found guilty of cyber offences against Australia’s critical infrastructure, under proposed changes introduced by the government.

    Read more...

    The Worldwide Cybersecurity Industry is Expected to Reach $346 Billion by 2028

    2022-02-16

    Yahoo Finance: The global Cybersecurity market was valued at USD 149.7 Billion in 2020 and is projected to reach USD 346.0 Billion by the year 2027. The market is expected to register a CAGR of 13.4% during the forecast period.

    Read more...

    Cyber Security Company Securonix Raises $1 Bln in Vista-led Round

    2022-02-15

    Financial Post: Cloud-based security solutions provider Securonix has raised more than $1 billion in a private fundraising round led by private equity firm Vista Equity Partners, the company said.

    Read more...

    Hackers Snagged $36 Million in Crypto in Breach of IRA Financial

    2022-02-15

    Wealth Management: A hack at IRA Financial Trust, which offers self-directed retirement accounts, resulted in the theft of $36 million in cryptocurrency, according to a person familiar with the investigation. 

    Read more...

    Cybersecurity M&A Volume Reaches $77.5 Billion in 2021

    2022-02-14

    ZDNet: In a report on 2021, the firm said 83 cybersecurity company capital raises surpassed $100 million. There were fourteen $1 billion mergers and acquisitions, including deals involving McAfee, Augh0, Mimecast, Thycotic, Proofpoint, and Avast. 

    Read more...

    Know Your Breach: Wormhole

    The Target: Wormhole, a cryptocurrency online trading platform.

    The Take: $322 million ETH currency.

    The Vector: A website vulnerability allowed the attacker to fool the exchange software to release far greater number of the ETH currency than was specified through a temporary token. By altering the conversion, the hacker was able to withdraw far more than the number the entered.

    This breach highlights the importance of locking input forms in a firm’s website, be it a name field, email field, or account field, anywhere the user is sending information to the database is a prime target for threat actors. Regular testing for software vulnerabilities is a key component of upholding robust cybersecurity posture.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates