Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      UK Businesses Hardest Hit Financially by Fallout from Cyber Attacks, Research Shows

      2020-09-03

      ComputerWeekly: UK businesses were among those worst hit financially by the fallout from cyber attacks during 2020, according to research from insurance provider Hiscox.The firm’s annual Cyber readiness report highlights the vertical markets across the UK, the US, Spain, Germany, France, Belgium, Ireland and the Netherlands that are considered highest risk of falling victim to cyber attacks.

      Read more...

      How to Ensure Cybersecurity and Business Continuity Plans Align

      2020-09-02

      SearchCIO: News reports on ransomware attacks, distributed denial-of-service (DDOS) attacks, phishing and virus attacks occur on a regular basis. Fortune 500 organizations, such as Facebook with 540 million affected records and Capital One Bank with 80,000 affected bank accounts and 140,000 Social Security numbers, have sustained significant losses and damage to their reputations from these cyber incidents. And threats of attacks from well-known cybersecurity threat actors such as Russia, China and Iran pose an ongoing threat to many U.S. organizations.

      Read more...

      10 Things the C-Suite Needs to Understand About Cybersecurity

      20020-09-01

      Foresite: Executive involvement is a critical component to any organization’s cybersecurity. Why?  The IT department may not have all of the knowledge about what data could have a critical impact on the business if it was lost or exposed, IT can recommend security controls, but may not have all of the financials to computer Return on Investment (ROI) or the level of risk tolerance that the executive team/Board is comfortable with.

      Read more...

      NZX Website Hit by Fresh Cyber Attack

      2020-08-31

      itnews: The New Zealand stock market was hit by a fifth day of cyber attacks, crashing its website, but maintained trading after switching to a contingency plan for the release of market announcements.

      Read more...

      CRA's Handling of COVID-19 Benefit Cyberattacks 'Reprehensible,' Alleges Proposed Class-action Lawsuit

      2020-08-31

      CBC: The lawsuit alleges that a series of "failings" by the government and the Canada Revenue Agency (CRA) allowed at least three cyberattacks between mid-March and mid-August, but the public wasn't alerted until CBC News broke the story on Aug. 15.

      Read more...

      Know Your Breach: Freepik

      The target: Freepik, a website providing high quality free photos and graphic design. 

      The take: 8.3 million records of personally identifiable information including: emails, usernames, and passwords.

      The attack vector: An SQL injection was used to breach Freepik’s systems and allowed attackers to dump their user information. Attacks of this nature take advantage of poor controls in text input fields to send malicious instructions to the target database.

      Any field where a user can submit text in web applications should be sanitized as a secure coding best practice to ensure these kinds of malicious commands cannot be submitted.

      Read more...

      New Zealand Spy Agency Investigating 'Severe' Cyberattack On Stock Exchange

      2020-08-28

      CNN: New Zealand has ordered one of its spy agencies to investigate a cyberattack that originated overseas and disrupted the country's financial markets for a fourth consecutive day on Friday.

      Read more...

      NCSC Departing Boss Reflects on China, Russia and Trust in Tech

      2020-08-27

      BBC: As the official in charge of defending the UK against cyber-threats, he knew enough to spot a scam. But it was also a sign he was unlikely to have a quiet end to his time as the first head of the National Cyber Security Centre (NCSC).

      Read more...

      How CISOs Can Play a New Role in Defining the Future of Work

      2020-08-27

      DARKReading: When the COVID-19 pandemic began, every CISO across every industry scrambled to get their teams up and running. When we left our physical office space, we left our traditional security strategy behind with it. The theme of remote security has stayed top of mind since March: Cybersecurity experts correctly predicted that cybercrime in a virtual workforce would be a central topic at the recent Black Hat conference, and CISOs have had to rethink 2020 strategy with remote work leading the way.

      Read more...

      Global Pandemic Opening Up Can of Security Worms

      2020-08-25

      ZDNet: Caught by the sudden onslaught of COVID-19, most businesses lack or have inadequate security systems in place to support remote work and now have to deal with a new reality that includes a much wider attack surface and less secured user devices. Many also have had to adapt and adopt digital tools quickly, taking on new technology that may not be adequately secured.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates