Menu
Sign In
    shutterstock_490960141-1

    Industry News: ESG5

      Companies Should Disclose Cybersecurity Risk Management Efforts

      2019-11-04

      Help Net Security: Research finds that when one company experiences a cybersecurity breach, other companies in the same field also become less attractive to investors. However, companies that are open about their cybersecurity risk management fare significantly better than peers that don’t disclose their cybersecurity efforts.

      Read more...

      Know Your Breach: SingHealth

      The target: SingHealth, Singapore’s largest group of healthcare organizations.

      The take: 1.5 million patient records which included: names, prescriptions, medical records, government registration numbers, addresses and dates of birth.

      The attack vector: The source of the breach according to early reports was a phishing campaign, however, security researcher’s leading hypothesis was that the attack originated through SingHealth’s failure to keep their software updated. The company used an open source penetration testing application called Ruler. However, they ignored an available patch for Ruler which addressed a known vulnerability, and which led to the hackers gaining access.

      Regular and rigorous attention to security updates must be applied to ensure maximum safety of a company’s IT systems – especially where it pertains to tools used to assess the security of internal systems and the effectiveness of technical controls.

      Read more...

      Rachel Wilson: Cyber Cop at Morgan Stanley Wealth Management

      2019-10-31

      Barron's: Wilson would grow up to lead first the National Security Agency’s counterterrorism mission, and later its cyber-exploitation mission. Currently Morgan Stanley Wealth Management’s cybersecurity chief, Wilson talks with Barron’s Advisor about how fraudsters are trying to gain an edge in data theft and how advisors can stay a step ahead. And she reveals how a bunch of cybercriminals “in a basement somewhere in Tehran” drew her to Wall Street.

      Read more...

      Chinese Hackers Intercepted Text Messages, Says Cybersecurity Firm

      2019-10-31

      Independent.IE: Chinese hackers with a history of state-sponsored espionage have intercepted the text messages of thousands of foreigners in a targeted campaign that planted eavesdropping software on a telecommunications provider’s servers, a cybersecurity firm has said.

      Read more...

      Willis Towers Watson Launches Innovative New Cyber Policies for Clients

      2019-10-30

      Global News Wire: Willis Towers Watson (NASDAQ: WLTW), a leading global advisory, broking and solutions company, has launched three new cyber insurance policies for clients across the U.S., Canada, the U.K. and Western Europe. The policies provide innovative, tailored solutions for large enterprise and mid-market clients, enabling them to fully assess, protect and recover losses related to cyber risk. 

      Read more...

      The Future of Cybersecurity VC Investing with Lightspeed's Arif Janmohamed

      2019-10-29

      Tech Crunch: There are two types of enterprise startups: those that create value and those that protect value. Cybersecurity is most definitely part of the latter group, and as a vertical, it has sprawled the past few years as the scale of attacks on companies, organizations, and governments has continuously expanded.

      Read more...

      Cyber Attack on Asia Ports Could Cost $110 Billion: Lloyd's

      2019-10-29

      Reuters: A cyber attack on Asian ports could cost as much as $110 billion, or half the total global loss from natural catastrophes in 2018, a Lloyd’s of London-backed report said.

      Read more...

      Cybersecurity Trumps Political, Reputational Concerns for Companies

      2019-10-29

      Dark Reading: According to its annual "State of Enterprise Risk Management" report, ISACA found that 29% of the 4,625 risk managers polled identify cybersecurity at the top threat to their business, while 15% consider reputational risks and 13% name financial dangers as most critical...

      Read more...

      UniCredit Reveals Data Breach Exposing 3 Million Customer Records

      2019-10-28

      ZDNet: In total, roughly three million records were exposed, revealing the names, telephone numbers, email addresses, and cities where clients were registered. 

      Read more...

      Know Your Breach: Imperva

      The target: Imperva, cyber-security firm based out of California.

      The take: A complete copy of their customer information database.

      The attack vector: Imperva uploaded a snapshot of its customer database for testing. However, in an unrelated incident, they left one of their internal systems publicly accessible on the internet from which the attacker stole key to the recently uploaded database. Using the key, the hacker was able to download a copy of the customer information.

      After Imperva adopted cloud technologies to scale their infrastructure to meet increasing needs, they failed to account for the increased risk of this strategy. Cyber-security diligence applies at all levels of scale including times of expansion and investment in new technology.

      Read more...

      About Castle Hall Diligence

      Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

      Subscribe to Cyber Updates